Risk //

Compliance

Compliance Is A Start, Not The End

100%
0%

Regulatory compliance efforts may help you get a bigger budget and reach a baseline security posture. But "compliant" does not necessarily mean "secure."

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
The Integrator
50%
50%
The Integrator,
User Rank: Apprentice
6/29/2015 | 3:55:49 AM
We need to move to continuous adaptive compliance
Current compliance regiemes are labourious, provide a snapshot of compliance and offer little value for the effort.

We need to move to automation where evidence is gathered automatiacally and once for every aspect we need to report on, so we are not manually taking screenshots for PCI, SOX, HIPPA etc.  Setup once, gather as needed and report non compliance for investigation, that way you will be as close to full compliance most of the time.

Compliance does not equal security
shalivaha
50%
50%
shalivaha,
User Rank: Apprentice
6/8/2015 | 2:59:37 AM
Re: Pending Review
yes its not the end
ramesh kumar13
50%
50%
ramesh kumar13,
User Rank: Apprentice
6/8/2015 | 2:35:56 AM
Re: Checkbox security
Noble thoughts, to be sure. But who in the Dark Reading community can honestly say that their company does not practice check box security at least some of the time?
UTIWARI
50%
50%
UTIWARI,
User Rank: Apprentice
10/24/2014 | 12:13:54 PM
Re: Checkbox security
While "checking the box" is often a requirement and companies cannot get away with not focusing on "checking the box", it may be helpful to include "checking the box" as part of overall risk management strategy and look at the compliance activity from risk lense and not overlook other aspects that may take you beyond checkbox thinking and actually take care of risks that your company is better off not being exposed to.
Marilyn Cohodas
100%
0%
Marilyn Cohodas,
User Rank: Strategist
10/22/2014 | 8:46:14 AM
Checkbox security
Noble thoughts, to be sure. But who in the Dark Reading community can honestly say that their company does not practice check box security at least some of the time? My guess -- it's closer to 50 percent of checkbox security practices.  Am I right or wrong?
Weaponizing IPv6 to Bypass IPv4 Security
John Anderson, Principal Security Consultant, Trustwave Spiderlabs,  6/12/2018
'Shift Left' & the Connected Car
Rohit Sethi, COO of Security Compass,  6/12/2018
Why CISOs Need a Security Reality Check
Joel Fulton, Chief Information Security Officer for Splunk,  6/13/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-1061
PUBLISHED: 2018-06-19
python before versions 2.7.15, 3.4.9, 3.5.6 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.
CVE-2018-1073
PUBLISHED: 2018-06-19
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
CVE-2018-12557
PUBLISHED: 2018-06-19
An issue was discovered in Zuul 3.x before 3.1.0. If nodes become offline during the build, the no_log attribute of a task is ignored. If the unreachable error occurred in a task used with a loop variable (e.g., with_items), the contents of the loop items would be printed in the console. This could ...
CVE-2018-12559
PUBLISHED: 2018-06-19
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The mount target path check in mounter.cpp `mpOk()` is insufficient. A regular user can consequently mount a CIFS filesystem anywhere (e.g., outside of the /home directory tree) by passing directory traversal sequ...
CVE-2018-12560
PUBLISHED: 2018-06-19
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. Arbitrary unmounts can be performed by regular users via directory traversal sequences such as a home/../sys/kernel substring.