Latest Posts

59d9b46aa00c70238bb89056cfeb96c0

Compliance: Twenty Questions Directors Should Ask

June 01, 2011 Added by:Thomas Fox

The questions are not intended to be an exact checklist, but rather a way to provide insight and stimulate discussion on the topic of compliance. The questions provide directors with a basis for critically assessing the answers they get and digging deeper as necessary...

Comments  (0)

69dafe8b58066478aea48f3d0f384820

Governments Escalate Cyber Warfare Rhetoric

June 01, 2011 Added by:Headlines

“We must plan, train, exercise and operate in a way which integrates our activities in both cyber and physical space. We will grow a cadre of dedicated cyber experts to support our own and allied cyber operations and secure our vital networks...”

Comments  (0)

0a8cae998f9c51e3b3c0ccbaddf521aa

The Most Important Security Question Ever Asked

June 01, 2011 Added by:Rafal Los

I've been learning a lot lately from one of my senior colleagues who's been doing this software security assurance thing much longer than I have, and the more time I spend with him the more I understand that it all comes down to one very simple question: Why?

Comments  (5)

65be44ae7088566069cc3bef454174a7

HHS: HIPAA Privacy Rule Accounting of Disclosures

June 01, 2011 Added by:Rebecca Herold

Covered entities and business associates would need to account for disclosures of PHI in electronic health records that are part of a designated record set for treatment, payment and health care operations in addition to the existing requirements for accounting for access to PHI...

Comments  (0)

69dafe8b58066478aea48f3d0f384820

Lockheed Systems on Lock Down After Cyber Attack

June 01, 2011 Added by:Headlines

“As a result of the swift and deliberate actions taken to protect the network and increase IT security, our systems remain secure. No customer, program or employee personal data has been compromised...”

Comments  (0)

850c7a8a30fa40cf01a9db756b49155a

Improvised Cyber Exploitation Devices

May 31, 2011 Added by:J. Oquendo

It should come as no surprise that ModSecurity is not an offensive tool. Far from it however, I am going to use it as a method to redirect my targets over to my Metasploit machine. My goal is to explain the use a of defensive tool for offensive purposes...

Comments  (0)

7fef78c47060974e0b8392e305f0daf0

Enemy of the State

May 31, 2011 Added by:Infosec Island Admin

You have the right to privacy in your papers and your domicile, but does this actually apply to digital papers, computers, hard drives, and anything you pass over telco lines to the cloud? Or is it considered public domain like your trash being placed at the end of your driveway?

Comments  (0)

F29746c6cb299c1755e4087e6126a816

Five Issues With Obama’s Breach Notification Policy

May 31, 2011 Added by:Kelly Colgan

The proposed bill is nothing more than an outdated, bandwagon approach that creates more red tape for businesses, weakens state law, and overprotects small- to medium-sized companies that suffer data breaches. Bottom line: It offers little, meaningful help to the consumer...

Comments  (0)

69dafe8b58066478aea48f3d0f384820

AlienVault Releases SCADA SIEM for Critical Infrastructure

May 31, 2011 Added by:Headlines

"We have a solution that can address the security and compliance needs of customers in process control industries including electric power utilities, public works and oil & gas. You just cannot get that level of capability, reliability and integration with legacy IT or ICS solutions..."

Comments  (0)

0dc5fdbc98f80f9aaf2b43b8bc795ea8

Ten Steps To A More Secure Password

May 31, 2011 Added by:Global Knowledge

I make a point to preach password security to most co-workers I supported – especially those who dealt with personnel records, credit card info, and other potentially sensitive documents. Below are some tips that will make your passwords a hundred times harder to hack...

Comments  (2)

69dafe8b58066478aea48f3d0f384820

Pentagon: Cyber Attacks Considered Act of War

May 31, 2011 Added by:Headlines

The report concludes that the Laws of Armed Conflict should also extend to the cyberspace field of operations. "If you shut down our power grid, maybe we will put a missile down one of your smokestacks," said an unidentified military official...

Comments  (0)

69fd9498e442aafd4eb04dfdfdf245c6

Freedom versus Security

May 31, 2011 Added by:Luis Corrons

In a few years’ time, besides protecting ourselves against cyber-attacks we will also have to look for mechanisms that guarantee our rights against government abuse of power. Some people are talking about the introduction of “Internet passports” to identify Internet users...

Comments  (3)

4ed54e31491e9fa2405e4714670ae31f

Weaponizing the Nokia N900 Part 3.8: Backtrack 5

May 31, 2011 Added by:Kyle Young

You could setup your N900 on a victim network and have ssh listing on your public IPv6 address and then log in to your N900 from an outside network over IPv6. You wouldn’t even have to do any port forwarding on the victim’s firewall/gateway/router...

Comments  (0)

69dafe8b58066478aea48f3d0f384820

Hackers Deface PBS Site in WikiLeaks Protest

May 31, 2011 Added by:Headlines

"Last night there was an intrusion to PBS' servers. The erroneous information on the PBS NewsHour site has been corrected. We're notifying stations and affected parties to advise them of the situation..."

Comments  (0)

43559f6a0465c923b496a260211995c0

SecurID: No Need for the Seed!

May 30, 2011 Added by:Pascal Longpre

An attacker who has installed the target's VPN client and configuration patiently waits for the user to authenticate. When the user begins to enter its 6 digit SecurID password, the Trojan captures the characters entered and immediately sends them through SSL to the attacker's machine...

Comments  (1)

5d3b9af5a870b9a89f8fa51fb390d488

Onsite Personnel "Don't Need No Stinkin' Badges" for PCI

May 30, 2011 Added by:Joe Schorr

To truly improve their security posture, companies should create (and enforce) a mandatory ID Badge policy for visitors and employees. An effective policy coupled with good security awareness training will go a long way to closing up this particular gap in PCI-DSS 2.0...

Comments  (2)

A7290c5bd7bc2aaa7ea2b6c957ef639b

FTC Enforcement Update: Virtual Worlds Settles

May 30, 2011 Added by:David Navetta

The FTC complaint alleged that the sites collected children’s information, including ages and email addresses, during registration and then enabled children to publicly post their full names, email addresses, instant messenger IDs, geographic location and other information...

Comments  (0)

Ebb72d4bfba370aecb29bc7519c9dac2

On Gartner's SIEM Magic Quadrant 2011

May 29, 2011 Added by:Anton Chuvakin

I think the concept of Magic Quadrant is brilliant. However, many wrong SIEM purchase decisions I’ve seen made usually stem from the decision maker’s own ignorance and not from whatever document or market visualization he has in his possession. Keep this in mind…

Comments  (1)

A966b1b38ca147f3e9a60890030926c9

Security and Due Diligence

May 28, 2011 Added by:Chris Blask

Behind all the technology and corporations and globe-spanning markets and networks there are individual human beings. The actions and intent of those individuals shines through the layers between them and the rest of us like arc lights through kleenex. There is no replacement for intent...

Comments  (0)

F520f65cba281c31e29c857faa651872

Open Your Box of IT Innovation

May 28, 2011 Added by:Rahul Neel Mani

Innovation and doing more with less are not just buzzwords. That doesn't mean having Systems up and running can take a back seat either. David Awcock, Head of Technology Standard Chartered Bank, shares his ideas in an interview with Minu Sirsalewala Agarwal, on how he manages both...

Comments  (0)