Passive network analysis can reveal OS, service, and even vulnerabilities--just by sniffing the network.
Continue reading "Passive Network Fingerprinting; p0f Gets Fresh Rewrite"
Why haven't user interfaces for security products taken advantage of human movement technologies?
Continue reading "Where's My 'Minority Report' Dashboard?"
'Fingerprinting' evolving to protect device IDs
Continue reading "The Value Of Device Authentication"
Organizations need to know what constitutes a breach of identity data according to state laws and how to respond
Continue reading "The Mechanics Of Breach Notification "
What security folks need to learn from RIM's rapid and accelerating downfall...
Continue reading "Looking Over The RIM And Into The Chasm"
State and Federal laws require notification when a breach of protected information occurs. You need to know which laws apply and how to comply
Continue reading "Breach Notification: Know The Rules"
If you're a customer-facing organization, then security can't take second place behind your services
Continue reading "We Make Widgets -- Let Someone Else Handle Security"
Data is the new bit of lost clothing you left behind on that road trip -- and two-factor authentication VPN is the way to go mobile
Continue reading "I Left My Data In El Segundo"
Limited government support of intellectual property helps, but not the strong protections in SOPA/PIPA
Continue reading "A Firsthand Piracy Experience"
While we need to monitor our employees to protect organization secrets, there's no need to turn the workplace into a bad episode of Big Brother
Continue reading "How To Monitor Employees Without Being A Perv"
Distinguishing between identity and authentication
Continue reading "Identity Versus Authentication"
After a rough 2011 for many large organizations, here's a look at what the world of advanced threats will bring in in 2012
Continue reading "2012 Will Be The Year Of The..."
Regulations require organizations to periodically assess security and compliance practices; the key is to understand how to do so effectively -- without breaking the bank
Continue reading "Partner Management 3: How To Assess Prospective Partners"
When software tokens are as strong as hardware ones
Continue reading "More About Software Tokens"
Using DAM as a security proxy
Continue reading "Database Security Proxies"
SSL will evolve to meet requirements for ecommerce and mobile
Continue reading "SSL's Future "
You can't protect what you can't see. Use these tools to learn how, and where, your data is at risk.
Continue reading "Take Off The Data Security Blinders"
Protecting secret keys or seeds in software without the risk of being stolen is crucial
Continue reading "Will Software Authentication Survive?"
One policy manages many security tools
Continue reading "Data Security, Top Down "
Vigilance against card fraud a 7x24 process, even at the grocer
Continue reading "Criminals Make Sure You're Never Really Alone, Even In Self-Checkout Lanes"
Imagine a modern-day plot for a James Bond movie and how mobile would make his task a whole lot easier
Continue reading "For Your Mobile Only"
Partner management is a key element to any compliance program. Assessing a partner’s ability to meet your compliance requirements is critical to managing these relationships. The first step is to determine the partner’s understanding of its responsibility and ensuring that it is capable of meeting it.
Continue reading "Partner Management: Assessing Compliance Capability And Willingness"
Expanding DAM's reach to applications.
Continue reading "ADMP: DAM For Web Apps"
As we look towards 2012, it's time to have more fun at work. Integrating some fun, games, and contents into your security program may pay dividends.
Continue reading "Work And Play In Security"
Are confickers links to stuxnet and the Iranian nuclear program without merit?
Continue reading "Debunking The Conficker-Iranian Nuclear Program Connection"