Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Continuous Compliance and Effective Audit Preparation for the Cloud
Threaded  |  Newest First  |  Oldest First
TechnologiesHive
100%
0%
TechnologiesHive,
User Rank: Apprentice
8/25/2017 | 11:04:37 AM
Very useful article about Cloud Audit preparation
Thanks for very deatiled post regarding effective audit preparation, was a good read!
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/27/2017 | 4:31:59 PM
Re: Very useful article about Cloud Audit preparation
I agree, it is a good paper providing good information.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
8/27/2017 | 9:43:59 AM
Tools
There are a lot of good tools out there (if used properly and if their limits are understood) for maintaining compliance with IT/security policies. Relatively few tools, alas, exist for data governance frameworks or global legal compliance frameworks. Most organizations still operate manually in this regard.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/27/2017 | 4:33:37 PM
Re: Tools
"Most organizations still operate manually in this regard." Good point. Most of these operations are mainly manual for many companies.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/27/2017 | 4:34:36 PM
Re: Tools
"There are a lot of good tools out there" One of them is Tripwire I had experience with, good security intelligence tool.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
8/28/2017 | 4:17:53 PM
Re: Tools
@Dr.T: Interesting. Can you share a bit more about your experience w/ TripWire -- your use cases, etc.?
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/27/2017 | 4:31:18 PM
Continuous auditing
Continuous compliance requires continuous auditing, that can only be achieved with the proper tools.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/27/2017 | 4:38:54 PM
ISO 27001
ISO 27001 is one of the international standards as an information security management system that certifies organizations adhering to proper security rules and commonly accepted best practices.
Joe Stanganelli
100%
0%
Joe Stanganelli,
User Rank: Ninja
8/28/2017 | 4:19:01 PM
Re: ISO 27001
Dr.T: It's also a component referenced in the NIST Cybersecurity Framework at various layers.

The problem, of course, is that so few people know what it actually, er, says...because of its proprietary nature. :/


COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/14/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-17637
PUBLISHED: 2020-07-15
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
CVE-2020-7292
PUBLISHED: 2020-07-15
Inappropriate Encoding for output context in McAfee Web Gateway (MWG) prior to 9.2.1 allows remote attacker to cause MWG to return an ambiguous redirect response via getting a user to click on a malicious URL.
CVE-2020-14511
PUBLISHED: 2020-07-15
Malicious operation of the crafted web browser cookie may cause a stack-based buffer overflow in the system web server on the EDR-G902 and EDR-G903 Series Routers (versions prior to 5.4).
CVE-2020-4100
PUBLISHED: 2020-07-15
"HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded natively at runtim...
CVE-2020-5765
PUBLISHED: 2020-07-15
Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during scan configuration. An authenticated, remote attacker could potentially exploit this vulnerability to execute arbitrary code in a user's session. Tenable has implemented additional i...