Blog Archives

2026

February

  • Finally migrated to my own site

    With the help of Gemini CLI, I’ve finally migrated all my 20 over years of blogs from https://mengchow.wordpress.com/ to this new https://brightstove.net site. All done in less than three hours....

2025

June

March

2023

August

February

2021

December

  • On risk, uncertainty, and impact

    Risk management is an approach that is commonly used across many industries. However, the language of risk has not been consistent or easy to understand across existing risk literatures. In...

2018

May

  • 《响应式安全:构建企业信息安全体系》

    三年多年前与中国电子出版社和清华段海新教授启动了翻译《Responsive Security》这本书终于在几个星期前圆满完成出版在中国亚马逊和其它网络书店了。中文书名《响应式安全:构建企业信息安全体系》与英文书名有点差别。主要是为了方便读者搜索关键词能更容易找到这本书。不然的话,更正确的书名应该是《响应式安全:有备无患》。

2017

May

  • 台北讲云安全

    两周前在台北的(ISC)2 SecureTaipei 会议上讲了些云安全的想法。台北IT Home的记者同一天就把主要内容刊登到其网上了。有兴趣的朋友们可以到那儿去看看:http://www.ithome.com.tw/news/114072.

2016

July

  • Fear when it is dark, fear when there is light

    We have fear of the dark because we can’t see what is in the dark. Many of us probably have similar experience of walking up or down an unlighted stairwell...
  • Brief thought on IoT security 

    There will be things that are security capable, things that are not security capable, and things that are somewhere in between. What those things can do, and how much an...

January

  • When our guard is down

    We don’t normally feel the reality of a criminal attack on the Internet (or so called Cybercrime attack in the Cyberspace these days) until someone we know, especially when a friend,...

2015

January

  • Blog series on Responsive Security

    I have recently published a five parts series on the captioned topic, based on my book of the same title, at Cisco’s Security Blog site. For convenience of the readers...

2014

October

  • A Black Swan on the ATM system

    This past week’s news headlines have once again been filled with a number significant cyber security incidents. Data breaches in JP Morgan, Bash shell vulnerability in a number of Unix/Linux...

August

  • REMOTE - Office not required - a brief review

    Working remotely is a practice that is familiar to many, especially in where I work today, so much so that we often take for granted its benefits, without even realizing their...
  • Hard and soft bacon

    Last week at the 14th RAISE Forum meeting in Bangkok, the hotel served breakfast every morning. Among the wonderful selection of western and eastern dishes were two choices of bacon,...

January

  • Be ready for the Year of the Wooden Horse

    Today marks the start of a new year on the Lunar calendar. As the Chinese saying goes, as the spring season arrives, happiness and prosperity follow. I would like to...

2013

October

  • Responsive Security - Be Ready to Be Secure

    After much anticipation, my new book, “Responsive Security - Be Ready to Be Secure”, is finally published today. Thanks to Prof Pauline Reich of Waseda University, and Chuan Wei Hoo,...

April

  • 12th RAISE Forum Meeting at Jinan, Shandong

    Talking about Shandong in the previous blog (“Before the ashes turn cold”) yesterday, in fact, I just came back from our 12th RAISE Forum meeting which was held at Jinan,...
  • Before the ashes turned cold

    Bruce Schneier wrote an interesting piece recently about the use of technology for political purposes and suggests that we need “more research into how to circumvent these technologies”: https://www.schneier.com/blog/archives/2013/04/it_for_oppressi.html

February

  • A real sense of insecurity

    Our office at the new business park is an attraction in many regards. There are massage chairs in the lobby area, free flow of coffee and tea in the open...

2012

August

  • Changing season

    This is a post that I have drafted roughly about two years ago, when I was still living in Beijing at that time, on an early autumn day. As we...
  • 11th RAISE Forum Meeting

2011

October

  • Buckle up before you drive

    Walking past a row of cars parked alongside the street next to my apartment this morning, I noticed that a number of them have their safety belts already buckled. They...

May

  • What would you do with a magic wand for security?

    Recently, I had the opportunity to speak with several senior information security practitioners on various areas of information security risk management to get their insights and learn about their experiences...

April

  • Taipei - 9th RAISE Forum Meeting

    April 1st marked the successful completion of the 9th RAISE Forum meeting hosted by the Information and Communication Security Technology (ICST) Institute in Taipei city. The two-day meetings, as in...
  • Berlin Walls - Reflecting the 9th WG 4 meeting

    It has been six months since the Berlin meeting in October 2010. It was my first trip to Berlin then, brought about by the SC 27/WG 4 convenorship. The trip was...
  • Keep left, walk right

    I have been jogging outdoor whenever I’m in Singapore due mainly to the warmer weather and cleaner environment there. During my jogs, I have observed the drainage covers that are lined...

2010

October

  • Insecure Wi-Fi networks

    Nearly five years ago, I blogged about how the laws are not going to help secure wi-fi networks, and asserted that home wi-fi networks would be the weak link if...

April

  • Return from the old Portuguese Town

    Yet another week of SC 27 Working Group (WG) meeting has gone by. Melaka, or Malacca as I know it since my childhood days, also well known as the old...
  • Arriving at Malacca

    It is the time of the year for yet another ISO/IEC JTC 1/SC 27 Working Group and Plenary meeting. The host for the next nine days is the Malaysian national...

March

February

2009

November

  • Of haze and fog and the visibility of risks

    The hazy fog in Beijing has triggered many local radio stations and TV news to constantly remind drivers to slow down, turn on the head lamps, and drive with extra...
  • Progress at Redmond

    This is not about Windows 7 or Microsoft, but to have a tail to the head that I started while at Redmond in early November 2009, about the progress of...
  • 7th meeting of WG 4 at Redmond, WA

    Six months have passed since the Beijing meeting. This week, we commence the 7th meeting of the ISO/IEC JTC 1/SC 27/WG 4 at Redmond, Washington, USA. The meeting is hosted...

October

July

  • Superman inside

    Have not been running for more than a week now, though I did had a few swims in the period, and feeling a little lethargic late afternoon, I decided go...

June

  • WG 4 Progress in Beijing

    The 6th WG 4 meeting in Beijing has closed since May 8, 2009. It has been a while for me to find some time to report the meeting outcomes and...

May

April

March

  • Passing destination

    I managed to get up early this morning and went for a jog around the hotel area. My destination was a palace building nearby. According to my colleague, it was about...
  • Flight delayed, arrival nearly on schedule

    I had my second trip to our Shanghai office and engineering center this week. Unlike the previous trip last month, the weather was fine most of the days--truly a feeling...

February

  • Skiing lesson

    My family and I went to NanShan (南山), a man-made snow mountain at the edge of Beijing for our first lesson and experience in skiing on the fifth day of...

January

  • Beware of pirated software, even on non-Windows systems

    In an earlier entry, I blogged about how users of non-geniune software secure their systems, and mentioned about IDC's analyst reporting the link between malicious/trojan software and non-geniune software. It seems that...
  • Why not localize your password

    Having moved to a new residence over the weekend, the first thing that happened then was to also move the broadband connectivity so that I could continue to have a...
  • How users of non-genuine software secure their systems

    Happy new year! As I checked through the list of "draft" blogs that I have left unfinished in 2008, one particular entry looks like something that I should complete for...

2008

November

  • Local food, local foreign food, foreign food, foreign local food, foreign foreign food

    Dinning at a Vietnamese restaurant yesterday evening and it occurred to me that we (my family and I) actually didn’t try any Vietnamese food before while living in Singapore in...
  • Losing heart earned data

    I haven’t been running for the past two weeks due to the numerous short trips and started with the treadmill at the gym yesterday, which covered a nice 6 km...
  • Two-way communications

    While it is often a challenge to achieve two-way communications in a typical conference setting, even with the use of new communication tools such as mobile short messages (SMS), as...
  • Two-way communication

    Conferences, in general, is a one-way communication platform, where a series of speakers get up to the stage and deliver their messages. While there are often opportunities for Q&A, they...

October

  • Protecting yourself in the Cyberspace

    A while back, I blogged about some findings on users' experiences of security breaches. This morning, just come across this new site, known as Security Garden, that is providing "Tip of...
  • Leaving Limassol

    Another week has gone by, closing off the 5th ISO/IEC JTC 1/SC 27/WG 4 meeting at Limassol, Cyprus.  There were some fun during the week, but more importantly, work-wise, significant...
  • Limassol

    Yet another security standards meeting this week. This may sound like a boring thing, and I guess that's why our host in Cyprus (like many other hosts of SC 27...

September

  • Knowing the ground

    Sep 11, 2008 - After struggling through the time zone change and jet lag for three nights, I finally got back my rhythm and able to get up early enough...
  • Joy of technology

    It often excites me when new technology is made available to make my daily work and lifestyle more digitally enabled. The Personal Information Manager (PIM) devices are one of those...

August

  • Who should be doing what for Cybersecurity

    The Los Angeles Times reported yesterday that "Public, private sectors at odds over cyber security". It seems that there are high expectation in the US that the government should play a central...
  • Read and run

    I was browsing thru' Amazon Kindle's catalogue of e-books about 3 or 4 weeks ago and stumbled upon "What I talk about when I talk about running" by Haruki Murakami,...
  • Why standards matter

    I was at the SPRING Singapore's Quality and Standards 2008 (QS2008) conference on Aug 20, 2008 and at the keynote was Mr John Wilson, Lead Economist of the World Bank....
  • Less is more

    If you travel a lot like me, you will probably be one of the readers of inflight magazines, which are the most freely available magazines you can get hold of...
  • Superwomen at the Beijing Olympic 2008

    After watching the super long celebration of the Beijing Olympic 2008 opening last night -- four hours on the couch, accompanied by three pots of Pu Er tea, I was...

July

June

  • Announcing the 7th RAISE Forum Meeting

    In my previous updates on the completion of the 6th RAISS Forum Meeting proceedings, I promised further updates, but I keep forgetting about it. Finally, through a conversation with a...

May

  • X.1207 approved

    X.1207 "Guidelines for Telecommunication Service Providers and End-users for Addressing the Risk of Spyware and Potentially Unwanted Software" was determined and undergone a six months review by ITU-T members from...
  • Revolving security

    Revolving restaurants are often a hit for children. They are also attractions for adults, but mostly during special occasions. Otherwise, they are often expensive places to dine in. However, the two...
  • What is Cybersecurity

    While a a new standard on "Guidelines for Cybersecurity" (27032) is being developed in ISO/IEC JTC 1/SC 27/WG 4, the question of "what is cybersecurity" continues to be asked and...

April

  • Proceedings of 6th RAISS Forum meeting published

    This round, we did not have the proceedings printed. However, the entire volume still undergone the copy writing process, with the PDF version of the contents laid out in ready-to-print...

March

February

  • ISO/IEC 24762 published

    Finally, after more than two years of development, the ISO/IEC 24762 on "Guidelines for ICT Disaster Recovery Services" is now completed and published. It is now available for purchase at...
  • Big Italian bank says 'Google your password to see if it is good'

    Don't ever try this! It is always dangerous when people get addicted to something (in this case, search engine). Sunbelt Blog: Big Italian bank says "Google your password to see...
  • Internet Safety for Everyone who uses the Internet

    I was in Hongkong before the Lunar New Year and read from the press about a 14 years old teenager who was arrested for hacking into a school network. As...

January

  • 中国地图

    Windows Live has recently released publicly a new Beta version of an online searchable map of China. See http://ditu.live.com, which is 地图@live.com. This should help those who are visiting places...
  • Rocks or rubbish

    Some issues are rubbish, while other are stones, or rocks. When we walk along a street and see some rubbish, it is alright for us to help clear it and...
  • Taxi Communicator 2

    Like all popular movies, they quickly become a series, with new twists to the original story, and also new casts of characters. Sometimes they turn out to be more interesting,...
  • On whether the entire AV industry been wrong since its start

    Have not been using Windows Live Writer for a while since trying out the beta version. On running it again today, after installing the release version, then discovered that I...
  • Taxi Entrepreneur

    While the taxi drivers in Hongkong are technologically geared to receive more calls and communicate better to improve their livelihood, those in the Taipei city are taking a different approach,...
  • Calmness hazard

    I was reviewing some of the photographs that I have taken in the past months during the many trips I had abroad and within China, and found one (below) amongst...
  • Waterfree - you can actually buy it

    I remained curious as to why "Waterfree" was printed on the label above the urinal in the male toilets at the Beijing International airport, and did a search (invoking Windows Live of...

2007

December

  • Waterfree - Relax, it's time to get serious

    An ex-classmate in London used to refer to toilet as the Thinking Room. In fact, it is often a place where one gets the ultimate solitude to reflect, especially when...

November

  • Car as an analogy

    The (ISC)2 Japan organized an informal meeting today with several CISSP constituents, including a few course instructors in Tokyo during lunch time for Ed Zeitler, Executive Director of (ISC)2 and...
  • A difference in trust

    Sep 20, 2007 - Yin Chuan (银川) - At the 2nd China Computerworld FSI Security conference today, during the keynote address, Dr Ren JinQian, Chief Engineer of a government body, spoke...
  • A blog of Microsoft security blogs

    The Microsoft's Chief Securty Advisor for Italy, Feliciano Intini, has recently compiled this page in his blog, collating all the current Microsoft-related security blogs in one page, which is probably...

October

  • The Three Little Pigs numbered

    A good news I've gotten from the SC27 Secretariat yesterday morning. In the national bodies (NB) ballot process for the three new projects in WG4, the title has already included...
  • X.1207 Determined

    X.1207 "Guidelines for Telecommunication Service Providers and End-users for Addressing the Risk of Spyware and Potentially Unwanted Software" - This ITU-T Recommendation (which is ITU's term for "standards") has finally...

September

  • Bye-bye password

    MSN and Windows Live login now has an integration with Windows Cardspace. Yes, the concept of Information Card is now alive, no longer just a concept! A step nearer to...
  • Three little pigs crossed the JTC1 bridge

    The three new work items proposals in WG4 (part of ISO/IEC JTC 1/SC 27) passed the JTC1 balloting this week. So the three new projects -- (1) ICT Readiness for Business Continuity;...
  • On ISO 27001 Report: ISO 2703n: Latest Developments

    Just read some reports on the roadmap and numbering of the ISO/IEC 2700x series of standards at the ISO 27001 Report blog site: "ISO 27001 Report: ISO 2703n: Latest Developments"....

August

  • Taxi communicator

    28 Aug 2007 I had an interesting sight of a taxi driver this evening in Hongkong. I think the term "taxi communicator" suits this driver as he seemed to be really into modern communication technology. A...

May

  • Football match in Mandrogi, Russia

    As part of the ISO/IEC JTC 1 19th SC 27 and 2nd WG4 meetings, which was held on board the Motor Ship "Lenin", cruising from Moscow to St. Petersburg, we...
  • Talking about the Windows Live Messenger campaign

    I heard about this i'm program recently, but didn't really understand how it works until now, when I accidentally bumped into the i'm web site. This program allows all of us to...

April

March

  • First week in Beijing

    March 5, 2007 - Today marks the beginning of my second week in Beijing. One interesting observation over the past seven days is the weather here in Beijing. When I...

February

  • Is ISMS relevant to SME and Non-Profit Organizations?

    I often get asked about the relevance of an Information Security Management System (ISMS), such as the ISO/IEC 27001:2005, to small and medium enterprises (SME) given that such a practice...
  • Yet another flight delay :-(

    February 9, 2007 - This is the third trip in a row over the last five weeks that I have on a Silkair flight. The first was to Trivandrum, which was...
  • Trivandrum to Kochi

    January 17, 2007 - Today is another one of those travelling days, but a very long journey on the road though. There's no flight from Trivandrum to go back to...

2006

November

  • Game Park

    I was in Glenburn, South Africa, week before last for the 1st ISO/IEC JTC 1/SC 27/WG4 meeting. Our South African host organized a tour of the game park, cum dinner...
  • Unusual day

    Today (Nov 5, 2006) is one of those unusual day. Unusual not in that everything goes wrong, but everything seems to behave/response differently. Fortunately, the unusual-ness started in the evening,...

September

August

June

  • Baseball Lesson

    Had a chance to watch a baseball game in Seattle earlier this month when I was there. The game was between Seattle Mariners and the Twins (from another State in...

May

  • A bull fight in Madrid

    The ISO/IEC JTC1 SC27 18th Plenary meeting was held in Madrid from May 16-17, 2006. It set forth the new structure with formal agreement of two new working groups--one on "Security...

March

February

  • The Role of Technology

    Was in Hanoi earlier this week for a privacy symposium, speaking on the role of technology in information privacy protection. The focus was that privacy is only as strong as the weakest...

January

  • We trust you

    I was having a second look at the photo taken at the Honey Stall along New Zealand motorway during the family vacation and found that in many ways, it is...
  • Watching signs

    Warning signs are often employed by authorities to remind people against undesirable behaviors. They are believed to be most effective when posted in or near areas where the undesirable behaviors...

2005

December

  • Traffic jam opportunity

    In Manila this week, and have to travel between two cities every day, passing through and tagging along lines of heavy traffics. The higher than average humility, and the frequent...
  • Warning signs and vandalism

    Road crimes in the Kiwi land seems to be a major concern (perhaps at least to the authority.) As in many other places, trust in people is also a diminishing...
  • Action speaks louder

    The Kiwi land that I just came back from is indeed beautiful and very scenic, with clear blue skylines that look like the artworks of those fine watercolor paintings, and natural greens...
  • Safety signs along New Zealand roads - a learning for security messages

    Just returned from a 10 days family vacation from the Kiwi land - the New Zealand. This is my first trip to the place, and the general impression is positive,...

November

October

  • Issue of repeated messaging

    In CNA news channel in the morning of Oct 15, there's a documentary on the impact of terrorism in S.E. Asia to foreigners living and working in this region, especially in places...