Compliance alone should never be the only goal
Continue reading "Manage Risk As A Strategy, Comply With Regulations As A Tactic"
When suffering from compliance fatigue, you may have only one option to getting the funding you need to do your job
Continue reading "Time To Deploy The FUD Weapon?"
Subsite of Dark Reading will look at collection and analysis of data on emerging threats
Continue reading "Dark Reading Launches New Tech Center On Threat Intelligence"
In tough times, compliance efforts may seem optional
Continue reading "Screw Compliance, We're Trying to Survive"
Do some 'ethical hackers' really have your best interest at heart, or are they more interested in making your private information public?
Continue reading "Where In Hacking The Ends Justify The Means"
Analysis reveals mobile apps designed to protect things like photos and passwords do a poor job, often storing them in plain text with no encryption at all.
Continue reading "Analyzing Android, iOS Apps For Weak Data Protection, Cleartext Passwords"
When it comes to mounting a successful defense in what is a fast-changing threat environment, best practices require consistent execution
Continue reading "Effective Security Policy: Emphasis On Execution"
To remain compliant, your approach must grow in scale with your business
Continue reading "What Works For One Does Not Work For Two"
Cloud, appliance, software? If you were planning on developing a security monitoring platform, which architecture would you use?
Continue reading "How Would You Architect A New Security Monitoring Product?"
Oracle's recent patch contained exploit code
Continue reading "Security Bugs And Proofs Of Concept"
Is Visa's program to eliminate the requirement for assessments in lieu of EMV (chip and pin) transactions the death knell for PCI? Not yet, but the writing is on the wall
Continue reading "PCI: Dead Man(date) Walking?"
Just because smartphone rail ticketing is a first here in the states doesn't mean mobile malware writers aren't already paying attention
Continue reading "Coming Soon to Your Smartphone: Mobile Ticketing That Keeps Your Transactions Safe"
How the increased level and sophistication of of targeted attacks since 2008 may impact this year's U.S. Presidential election campaigns
Continue reading "2012 U.S. Election And Targeted Attack Predictions"
Compliance is about being better and not just proving you are right
Continue reading "You Need Help, Not An Accomplice"
While enterprise-level breaches often get the attention of C-level suite executives and the members of their IT staff, industry research shows it actually falls to rank and file employees to apply best practices and exercise sound judgment in order to properly contain them
Continue reading "The Benefits Of Top-Down Security"
Do we need logging standards, or should we just follow the leaders to help direct our logging efforts?
Continue reading "Log Standards: Put Up, Shut Up, Give Up, Or Throw Up?"
As soon as you train your colleagues about compliance, noncompliance is back in charge
Continue reading "Your Compliance Is Decaying Every Day"
A look at database monitoring and reverse proxies
Continue reading "Using Reverse Proxies To Secure Databases"
Compliant systems do more than prevent problems -- they help solve problems that happen
Continue reading "Be Ready To Clean Up That Mess"
Proactively applying private or public-key encryption coupled with access control won't eliminate data breaches. But it will make it harder for the bad guys to take advantage of you
Continue reading "Utah Medicaid Breach Exemplifies Value Of Encryption And Access Control"
At what point does turning a blind eye to the loss of revenue spark the inevitable conversation: 'Maybe we should be monitoring this infrastructure more closely?'
Continue reading "How Much Money Do You Need To Lose Before You Start Monitoring?"
How to compile, copy, and run mac-robber on jailbroken iOS devices
Continue reading "Quick-Start Guide: Compiling Mac-Robber For iOS Vuln Research"
A look at some free tools to help tackle database security
Continue reading "Database Security On The Cheap"
How to compile, copy, and run mac-robber on rooted Android devices
Continue reading "Quick-Start Guide: Compiling Mac-Robber For Android Vuln Research"
Intro to a unique approach for vulnerability research on mobile apps using traditional PC forensic tools
Continue reading "Forensic Approach To Mobile App Vulnerability Research"