Eric H. Goldman

Security Researcher and Professional
CISA, Security+, & ITILv3 Certified

Eric Goldman is a security professional with experience in the banking and manufacturing sectors. His primary interest is in security policy, compliance, and human factors. His research focuses on how IT teams can improve security and move towards a proactive security mindset. His research has been showcased in academic journals as well as professional journals. Eric also authors and contributes to security/software projects to help end users make informed decisions and protect their identity and security.

Recent Articles

Push the Button: Making Security Training Fun and Interactive

As humans, we are all constantly trying to find the signal in the noise. Unfortunately, the topics and behaviors that we, as corporate security trainers, are trying to explain, teach, and reinforce are often seen as noise to those whom we are targeting. Therefore, to achieve our goals we need more than pertinent information and slick graphics; we need to find ways to stand out, capture people's attention, and find a way to cement our desirable security behaviors with positive associations. An effective strategy to stand out, make your message more memorable, and to build a positive reputation for your security team is to incorporate interactive exhibits and activities in your security training program.

Security » #human factors #training #security awareness #journal article

Encryption in the Hands of End Users

Organizations are increasingly investing in encryption capabilities. One form of encryption that is seeing increased deployment is end-user managed encryption; however, such deployments present many challenges for the enterprise. Such tools typically lack centralized management and control capabilities, either forcing or allowing users to make security decisions on their own. This makes monitoring and enforcement of proper usage difficult and leaves doubts over whether users are using encryption properly, if at all. In addition, monitoring and data loss prevention tools are often rendered mute because most solutions lack escrow and security infrastructure integration. In this article we will discuss some of the challenges and risks in deploying end-user managed encryption and will also evaluate alternative centralized solutions and their benefits.

Security » #encryption #human factors #zip #siem #journal article