Security Management

69fd9498e442aafd4eb04dfdfdf245c6

Managing My Company’s Security is a Nightmare

May 17, 2013 Added by:Luis Corrons

IT Departments are very often one step behind users, and unfortunately in most cases there is no real control over all devices on the corporate network. Despite perimeter solutions still being a necessity, the corporate perimeter must now expand to include new devices (mainly smartphones and tablets) that also handle confidential corporate information.

Comments  (0)

Ffc4103a877b409fd8d6da8f854f617e

Complimentary IT Security Resources [May 13, 2013]

May 13, 2013 Added by:InfosecIsland News

As an Infosec Island reader, we are pleased to offer you the following complimentary IT security resources for the week of May 13, 2013.

Comments  (0)

5c549756b3c0b3d5c743158a72ce3809

Do You Have a Vendor Security Check List? You Should!

May 09, 2013 Added by:Michael Fornal

A security check list is a list of security controls that a vendor or application must meet. These controls can range from how storage back up is to be done, to password complexity requirements. Having a checklist can help you in deciding if the application or vendor conforms to your company’s security requirements.

Comments  (0)

219bfe49c4e7e1a3760f307bfecb9954

Three Reasons Why a One-Size-Fits-All Secure SDLC Solution Won’t Work

May 08, 2013 Added by:Rohit Sethi

Forcing a security process on development teams that doesn’t take into account the way they develop software is a recipe for disaster. A good goal to have for secure SDLC is to minimize the impact on the team’s existing software development practice.

Comments  (0)

Af2769c2480db78c589b811b428782b0

Bore Them With Death-by-Awareness: That’ll Teach em!

May 08, 2013 Added by:Lee Mangold

As security professionals, we have to understand that not everyone has a passion for security. In fact, most people don’t. Given that we know “they” don’t share our passion, and we know they are the most vulnerable attack vector, why do we continue to bore them with homogenous and irrelevant training?

Comments  (0)

44a2e0804995faf8d2e3b084a1e2db1d

On Dutch Banking Woes and DDoS Attacks

April 25, 2013 Added by:Don Eijndhoven

If you don't live in the Netherlands or don't happen to have a Dutch bank account, you can certainly be forgiven for not having caught wind of the major banking woes that have been plaguing the Dutch.

Comments  (0)

219bfe49c4e7e1a3760f307bfecb9954

Raising the Bar on Application Security Due Diligence

April 24, 2013 Added by:Rohit Sethi

Many automated scanning solutions are outstanding in their cost effectiveness and ability to find certain classes of vulnerabilities. For example, a properly-configured static analysis solution may help you find every instance of potential SQL injection in your software.

Comments  (0)

8a958994958cdf24f0dc051edfe29462

Google: Black Hat or White Hat?

April 23, 2013 Added by:Larry Karisny

Google has a perfect opportunity to be a leader in cybersecurity. Google’s recent network -- and acquisitions and hires -- in Austin, Texas, is an opportunity to do security right the first time.

Comments  (1)

0a8cae998f9c51e3b3c0ccbaddf521aa

Deconstructing 'Defensible' - Too Many Assets, not Enough Resources

April 19, 2013 Added by:Rafal Los

In just about every organization (with little exception) there are more things to defend than there are resources to defend with. Remember playing the game of Risk, when you were a kid? Maybe you still have the game now... amazing how close to that board game your life in InfoSec is now, isn't it?

Comments  (0)

5e402abc3fedaf8927900f014ccc031f

Into the Breach

April 16, 2013 Added by:Allan Pratt, MBA

One day, you come into the office and discover that your network has been breached. To make matters worse, your customer data has been stolen. What do you do?

Comments  (0)

8e6e3972318ff74b194801340248199e

DLP and Business Needs

April 16, 2013 Added by:Scott Thomas

Most non-IT people know about DLP only when the IT organization contacts them to let them know they did something they shouldn't have. For those of us that have to deal with the policies, the alerts, and sending those notices, it can be more complicated.

Comments  (0)

Cb9aade927a0abf5b0bbdd2a4aaf8716

Don’t Let Your Guard Down: Tragedies Pave Way for Phishing Attacks

April 16, 2013 Added by:Jake Garlie

Tragic events such as what happened during the Boston Marathon creates an opportunity for attackers in the digital world as well. With everyone scrambling for more information, the success rate of a phishing attack at this time can skyrocket.

Comments  (0)

36317a78f97d1d6d7a02333ad01186fa

New Approaches for Blocking Zero-Day Exploits to Prevent APTs

April 16, 2013 Added by:George Tubin

Cybercriminals continue to develop new methods to bypass security controls in order to install malware on corporate endpoints. An endpoint protection approach that provides both effectiveness and manageability must begin with an understanding of the attack vectors that require mitigation.

Comments  (1)

Bd07d58f0d31d48d3764821d109bf165

Are We Ready to be Consumers of Security Intelligence?

April 15, 2013 Added by:Tripwire Inc

Security teams need the right skills in order to ‘ready’ themselves for action, and before we get to engage in some some really advanced security intelligence, big data analysis, haddop, threat intelligence and a myriad of other buzz words, we will need to be able to accomplish the basics first.

Comments  (0)

Bd07d58f0d31d48d3764821d109bf165

Momma Said “Risk is Like a Box of Chocolates…”

April 10, 2013 Added by:Tripwire Inc

In the movie Forrest Gump, the main character comments, “life is like a box of chocolates – you never know what you’re gonna get.” I think the same can be said for risk.

Comments  (1)

6d117b57d55f63febe392e40a478011f

Enter the CISO: Torchbearer of Security and Risk Management

April 06, 2013 Added by:Anthony M. Freed

In a convergence culture, accountability for risk is accepted across the organization, and when that happens, risk management becomes a priority to the business, informing strategy and objectives. By helping identify and mitigate risk across finance, operations and IT, the CISO puts security in context of what could affect profit.

Comments  (0)

Page « < 1 - 2 - 3 - 4 - 5 > »