詳細検索
Avatar

菊池

How difficult is a personal information protection officer? Tips for passing the exam taught by active analysts and practical advantages

How difficult is a personal information protection officer? Tips for passing the exam taught by active analysts and practical advantages

An active security analyst thoroughly explains the difficulty of the personal information protection professional certification exam, learning points, and "real value" that will be useful in practice. Why is there a need for people who can make decisions not only in the field but also in the field? This is a must-see exam experience for PMS and ISMS management personnel. |Colorkrew Security

What is an effective part of phishing email training? Explanation of themes with high success rates

What is an effective part of phishing email training? Explanation of themes with high success rates

Introducing effective phishing email training and specific sample examples. Based on actual attack trends such as HR, accounting, and IT notifications, we will explain practical training methods using Microsoft 365 Defender. |Colorkrew Security

Introduction to CSIRT for Small and Medium-sized Enterprises|Incident response system starting with minimal configuration

Introduction to CSIRT for Small and Medium-sized Enterprises|Incident response system starting with minimal configuration

Practical explanation of how to create a minimum CSIRT configuration that can be realized even by small and medium-sized enterprises, starting from role division, external collaboration, and initial maintenance points|Colorkrew Security

How and what to do with CSIRT-led ransomware exercises

How and what to do with CSIRT-led ransomware exercises

We will explain the purpose, scenario design, implementation procedure, and output organization of the ransomware attack exercise led by the CSIRT with specific examples to help strengthen our response capabilities|Colorkrew Security

Why do companies need CSIRT now? Why don't you personalize incident response?

Why do companies need CSIRT now? Why don't you personalize incident response?

Why do companies need CSIRT now? Against the backdrop of increasing attack sophistication and limitations in person-to-person response, the role, necessity, and relationship between CSIRT and management risk are explained in an easy-to-understand manner|Colorkrew Security

Steps and Practical Points for CSIRT Construction - To avoid ending with a team that only forms -

Steps and Practical Points for CSIRT Construction - To avoid ending with a team that only forms -

Explain specific steps and practical points for successful CSIRT construction. We will introduce system design that does not become a formality, role definition, training, and improvement in accordance with practical work. |Colorkrew Security

Sysmon Goes Standard with Windows: How Will Enterprise Security Operations Change?

Sysmon Goes Standard with Windows: How Will Enterprise Security Operations Change?

Experts explain in detail why Sysmon is included as standard in Windows and its specific impact on attack detection, SIEM analysis, and forensics|Colorkrew Security

Internal information leaks are on the rise|Risks and countermeasures faced by companies from the IPA survey

Internal information leaks are on the rise|Risks and countermeasures faced by companies from the IPA survey

The risk of internal information leakage has skyrocketed. According to an IPA study, trade secret leaks have increased more than sixfold in the past five years. Not only technical defenses are essential, but also measures against employee "motivations" and "justifications". In this article, we will explain the specific internal fraud measures that companies should take. |Colorkrew Security

What is EPSS? How to predict the probability of vulnerability exploitation and improve response efficiency

What is EPSS? How to predict the probability of vulnerability exploitation and improve response efficiency

With the ever-increasing number of vulnerabilities, it's impossible to keep up with everything. In this article, we will explain how to efficiently manage vulnerabilities with limited resources by utilizing EPSS (Exploit Prediction Scoring System), which predicts the likelihood of exploitation. We also introduce the differences from CVSS and tips for using it together. |Colorkrew Security

What is DAST? Explain the importance of web application security and implementation steps

What is DAST? Explain the importance of web application security and implementation steps

Explains the basics, importance, typical tools, and implementation procedures of DAST (Dynamic Application Security Testing) in an easy-to-understand manner. This is a must-see for those who want to efficiently combat vulnerabilities in web applications. |Colorkrew Security

The latest phishing attacks of Direct Send exploits and how to effectively combat them in Microsoft 365

The latest phishing attacks of Direct Send exploits and how to effectively combat them in Microsoft 365

Phishing attacks exploiting Microsoft 365's Direct Send are on the rise. In this article, we will explain the modus operandi, the latest trends, and specific countermeasures (using SPF/DKIM/DMARC/Defender) in an easy-to-understand manner. |Colorkrew Security

What is OSINT? Thorough explanation of the role and risks in cyber attacks

What is OSINT? Thorough explanation of the role and risks in cyber attacks

What is OSINT (Open Source Intelligence)? In this article, we will explain how to use it in cyberattacks, the risks, and OSINT countermeasures that companies should take. This is a must-read guide to help prevent information leakage and strengthen security. Colorkrew Security