| Top cybersecurity concerns: Malicious code, employees run amok | Hackers stole Google SSL certificate, Dutch firm admits | ||||||||||
| Network World Security: Identity Management | ||||||||||
XACML-based directory server WHITE PAPER: Kaseya Why Corporations Need to Automate IT Systems Management In today's competitive business environment, corporations across all industries are looking to provide quality products and services while at the same time cutting costs, saving energy and doing more with less. Automated IT systems management is the ultimate facilitator for achieving these goals and more. Read now In this Issue
WHITE PAPER: GFI Software Why Customers Love VIPRE Business Selecting an antivirus solution for your organization is an important decision. VIPRE Antivirus Business is a high-performance solution that delivers fast, memory-efficient endpoint security with all the necessary functionality you need and nothing you don't ensuring an optimal end user performance experience. Read now! Top cybersecurity concerns: Malicious code, employees run amok Hackers stole Google SSL certificate, Dutch firm admits WHITE PAPER: GFI Software Email Security in Small and Medium-sized Businesses No organization can afford to operate without an email security strategy. The risk landscape is constantly changing with new threats surfacing every day. This white paper looks at email security in small and medium businesses, the solutions available and what features SMBs cannot do without. Read now Android Devices Exposed: 7 Ways to Thwart Hackers Trend Micro: Virtualization changing our anti-malware business big time WHITE PAPER: HP & Intel A Vision for Emerging Customer Requirements Learn how HP's Converged Storage strategy, including HP 3PAR Utility Storage, powered by Intel Xeon processors, establishes HP's unique approach to storage going forward. Read now Google says Gmail attack focused on Iranian targets VMworld: Security, regulatory concerns still a challenge in virtualization Five Things CIOs Need to Know about Anonymous 5 misconceptions about file transfer security | ||||||||||
| ||||||||||
GOODIES FROM MICROSOFT SUBNET SLIDESHOWS The world's geekiest license plates MOST-READ STORIES
| ||||||||||
| Do You Tweet? You are currently subscribed to networkworld_security_identity_management_alert as security.world@gmail.com. Unsubscribe from this newsletter | Manage your subscriptions | Subscribe | Privacy Policy To contact Network World, please send an e-mail to customer_service@nww.com. Copyright (C) 2011 Network World, 492 Old Connecticut Path, Framingham MA 01701 ** Please do not reply to this message. If you want to contact someone directly, send an e-mail to customer_service@nww.com. ** | ||||||||||
Everything related to Computer Security - Security Audits, Security Vulnerabilities, Intrusion Detection, Incident Handling, Forensics and Investigation, Information Security Policies, and a whole lot more.
Search This Blog
Wednesday, August 31, 2011
XACML-based directory server
WindowsNetworking.com - Cisco ASA 5500 Series SSL/IPsec VPN Edition - Voted WindowsNetworking.com Readers’ Choice Award Winner - Firewalls & VPN Hardware
Hi Security World,
Title: Cisco ASA 5500 Series SSL/IPsec VPN Edition - Voted WindowsNetworking.com Readers' Choice Award Winner - Firewalls & VPN Hardware
Author: The Editor
Link: http://www.WindowsNetworking.com/news/WindowsNetworking-Readers-Choice-Award-Firewalls-VPN-Hardware-Cisco-ASA-5500-Series-SSL-IPsec-VPN-Edition-Jul11.html
Summary: Cisco ASA 5500 Series SSL/IPsec VPN Edition was selected the winner in the Firewalls & VPN Hardware category of the WindowsNetworking.com Readers' Choice Awards. Juniper Networks NetScreen and SonicWALL NSA E5500 were runner-up and second runner-up respectively.
Visit the Subscription Management (http://www.techgenix.com/newsletter/) section to unsubscribe.
WindowsNetworking.com is in no way affiliated with Microsoft Corp.
For sponsorship information, contact us at advertising@windowsnetworking.com
Copyright © WindowsNetworking.com 2011. All rights reserved.
Cisco, VMware expand collaboration
| Cisco, NEC team up on LTE networks | Xsigo has a fabric to go up against Cisco, others | ||||||||||
| Network World Cisco | ||||||||||
Cisco, VMware expand collaboration WHITE PAPER: Quest Software Accelerate Recovery Time After a Disaster In this Quest Software white paper authored by the Data Management Institute, learn the key challenges in designing an effective disaster recovery plan. Then discover how a solution based on continuous data protection can rapidly restore your critical applications and get your business running again with virtually no downtime. Read Now! In this Issue WEBCAST: Cymphonix Gain Complete Control Over Internet Bound Traffic The Cymphonix Network Composer is the only network appliance that provides comprehensive clarity into all internet bound network traffic and simply powerful tools to manage that traffic with a holistic approach. Learn More Today! Cisco, NEC team up on LTE networks WHITE PAPER: Kaseya How to Launch a Successful IT Automation Initiative In this paper, we'll look at IT automation from the corporation's perspective, and discuss the steps organizations should take before launching such an initiative. We'll hear from companies that successfully implemented computer automation platforms, what their early steps were and what they would do differently if they could repeat the process. Read now Xsigo has a fabric to go up against Cisco, others WHITE PAPER: CA Technologies Three steps to agile change Comprehensive IT change configuration and release management (CCRM) continues to confound and frustrate both IT and the business units for which it provides services. But by first instituting the appropriate foundational processes and supporting tools, many enterprises are experiencing renewed CCRM success. Read Now How the network supports cloud computing Five Things CIOs Need to Know about Anonymous | ||||||||||
| ||||||||||
GOODIES FROM MICROSOFT SUBNET SLIDESHOWS The world's geekiest license plates MOST-READ STORIES
| ||||||||||
| Do You Tweet? You are currently subscribed to networkworld_cisco_alert as security.world@gmail.com. Unsubscribe from this newsletter | Manage your subscriptions | Subscribe | Privacy Policy To contact Network World, please send an e-mail to customer_service@nww.com. Copyright (C) 2011 Network World, 492 Old Connecticut Path, Framingham MA 01701 ** Please do not reply to this message. If you want to contact someone directly, send an e-mail to customer_service@nww.com. ** | ||||||||||
WindowSecurity.com - August 2011 Newsletter
WindowSecurity.com Newsletter of August 2011
Sponsored by: ManageEngine <http://www.manageengine.com/products/eventlog/?utm_source=wownsec&utm_medium=newsletter&utm_campaign=textlinkELA&utm_term=aug11>
-------------------------------------------------------
Welcome to the WindowsSecurity.com newsletter by George Chetcuti, BSc in Computing & IS (Honors), CISA, MCP, HP Certified. Each month we will bring you interesting and helpful information on the world of Security. We want to know what all *you* are interested in hearing about. Please send your suggestions for future newsletter content to: gchetcuti@windowsecurity.com
1. Building a security entity within your organization
-------------------------------------------------------
Internet access is a necessary evil simply because any organization would not survive without it. The very moment you connect your assets, whether they are mobile devices, desktop computers or whole setups to the Internet, you inherit a threat which needs to be mitigated. Organizations may end up with out-of-the-box setups that were overlooked or ignored during routine security checks but these low priority assets may expose the organization's other critical resources. For instance, an unprotected and unpatched Windows server or client has backdoors and can be scanned within a few hours or minutes if it is connected to the Internet. Even well planned and secure assets can pose a risk to an organization.
In an environment where security is dealt with due diligence, risks are minimized but still present. We all know that you can never achieve a 100% secure environment. Assume that your IT infrastructure is not likely to suffer from data theft, break-ins or loss of data but what if it is taken offline due to some DoS attacks or unplanned service provider downtime? Downtime costs big money and organizations in some business sectors (such as, selling low cost items) consider availability of their online shops more vital than top-notch security!
*What further steps do we need to take after securing our IT environment?*
In large organizations a Computer Security Incident Response Team (CSIRT) is responsible for receiving, reviewing and responding to computer security incidents. They are full time security experts handling security incidents but in order to be proactive they need to perform additional duties such as continuous examination of incident reports for possible future threats, research studies, and implement monitoring tools. While a large organization may afford the budget to maintain a security team (or may be obliged to maintain one due to regulatory compliance), a smaller organization can either implement a cut-down version of a CSIRT with reduced functionality or outsource these services. What are the basic elements you need in place to implement such an entity?
* A clear mission statement - in large entities this would take the form of a security strategy developed with the participation of all stakeholders, however, in smaller setups the support and commitment of senior management is crucial to the success of this vision. Security operations in an organization with blurred or weak organizational structures may fail due to lack of authority. Therefore, a mission statement or declaration of intent issued by senior management is an excellent starter.
* Define a basic framework - apart from the definition of elements that make up the framework, such as policies, security classification, process flows, etc., it should include properties that allow the framework to be updated from time to time. In other words, you should build a dynamic framework that caters for changes in threat vectors and business objectives. It is a common mistake that people build a set of rules without updating them over time as new challenges emerge.
* Perform a risk assessment - analyze your environment carefully and make sure that you involve all stakeholders. A common mistake is to assess risks from the technology point of view. In many cases, systems' vulnerabilities may pose the greatest threats; however, criticality of assets should be viewed from the business point of view. Get senior management to sign-off this exercise. Remember to update your framework according to the risk assessment results!
* Implement an incident handling mechanism - whether you implement a fully fledged system or a documented manual process, the success factor is always how much users are willing to do and follow it! You should focus on a user friendly mechanism that captures the most important information artifacts. Another important process element in an incident handling system is the information manipulation capabilities such as, reporting and trend analysis.
Building a security response entity and achieving results depends on the reputation such an entity acquires as it goes along. Putting in place practical security polices, having an excellent incident handling management system and clear strategy in place does not guarantee success. The ultimate goal has to be the effective resolution of security incidents and the greatest asset in all this is training. Make sure that any security staff delegated with incidents is well trained and is able to get help from other experts. In fact, a recommended additional requisite for effective CSIRTs is to establish contacts with other teams. Support from security experts would give your entity a broader knowledge and will keep you updated with the latest trends. I suggest looking for any national entity such as, national CSIRTs that may exist in your country. Surely, the added benefits are many as such teams can provide you with the required expertise and current threats from the data collected throughout their region.
Training does not end with the security experts. End users must have their fair share as well. Security awareness programs reduce the number of incidents--and remember that small things often prevent great disasters. Security awareness programs for end users should be seen as a preventive tool, however, the end users' cooperation is a big asset when it comes to collecting evidence.
To conclude this month's newsletter I would like to recap, mentioning the most important objectives of an organization's security entity. A security entity, whether it is a formalized team such as, CSIRT or an ad hoc team such as individuals from an IT department, must be based on both reactive and proactive services. The reactive services include vulnerability handling alerts, incident and artifacts handling while the proactive include security audits and announcements, secure configurations and routine maintenance, amongst others. Additionally, if enough funds are available, I would suggest security tools such as intrusion detection, supervisory control, and data acquisition tools that would make your proactive service more complete. Security quality can be enhanced further by adding other layers to the reactive and the proactive services. These are continuous risk analysis and disaster recovery plans. When an incident scenario has a devastating effect and is considered as a major crisis then your life saver would be a well-thought BCP (Business Continuity Plan).
Should you have any ideas for content in future editions of the WindowSecurity.com newsletter or would like to ask questions, you're more than welcome to e-mail me at george.chetcuti@windowsecurity.com
See you next month! - George
2. WindowSecurity.com Articles of Interest
----------------------------------------
* Hunt Down and Kill Malware with Sysinternals Tools (Part 1)
<http://www.windowsecurity.com/articles/Hunt-Down-Kill-Malware-Sysinternals-Tools-Part1.html>
* Building a Malware Analysis Lab
<http://www.windowsecurity.com/articles/Building-Malware-Analysis-Lab.html>
* Applocker: Scenarios for Use and Deployment
<http://www.windowsecurity.com/articles/Applocker-Scenarios-Use-Deployment.html>
* Security Issues when Connecting Computers to Cellular Networks
<http://www.windowsecurity.com/articles/Security-Issues-when-Connecting-Computers-Cellular-Networks.html>
* Disk Encryption - The Next Generation (Bitlocker Administration and Monitoring)
<http://www.windowsecurity.com/articles/Disk-Encryption-Next-Generation-Bitlocker-Administration-Monitoring.html>
3. Tip of the Month
-----------------------------------------------
Check this additional information about Security Emergency Response Teams:
CSIRT FAQ
http://www.cert.org/csirts/csirt_faq.html
FIRST Community
http://www.first.org/
4. Latest Security Exploits and Concerns
-------------------------------------------
* Social Engineering
<http://blogs.windowsecurity.com/chetcuti/2011/07/21/social-engineering/>
* The risks and benefits of shortened URLs
<http://blogs.windowsecurity.com/chetcuti/2011/07/26/the-risks-and-benefits-of-shortened-urls/>
* Password Reset Disks
<http://www.windows7library.com/blog/problems/password-reset-disks/>
* Spear-phish cyber attacks
<http://blogs.windowsecurity.com/chetcuti/2011/08/05/spear-phish-cyber-attacks/>
Monitoring Files and Folders
<http://www.windows7library.com/blog/security/monitoring-files-and-folders/>
The Rustock Botnet
<http://www.itinfomag.com/security-governance/the-rustock-botnet/>
Cyber-war test lab!
<http://blogs.windowsecurity.com/chetcuti/2011/08/10/cyberwar-test-lab/>
5. Ask George a question
--------------------------
QUESTION:
What is a National CSIRT?
ANSWER:
As nations get more and more dependent on IT systems, the underlying technology infrastructure has become vital to the economy. Fraud may be the major cyber threat; however, there are other possible disruptions such as, organized attacks on a country's IT infrastructure as we have seen couple of years ago! To ensure security and economic vitality, governments are legislating frameworks that manage cyber security and a National CSIRTs is one element of that framework.
A National Computer Security Incident Response Team (National CSIRT) coordinates incident management and facilitates an understanding of cyber security issues for national community. It also provides the specific technical competence to respond to cyber incidents of national interest. An important function within a national CSIRT is the dissemination of information throughout the country's industries and other entities. They become a focal point for a national discussion on cyber security.
TechGenix Sites
----------------------------------------------------------------
ISAserver.org <http://www.isaserver.org/>
MSExchange.org <http://www.msexchange.org/>
VirtualizationAdmin.com <http://www.virtualizationadmin.com/>
WindowsNetworking.com <http://www.windowsnetworking.com/>
----------------------------------------------------------------
Visit the Subscription Management (http://www.techgenix.com/newsletter/) section to unsubscribe.
WindowSecurity.com is in no way affiliated with Microsoft Corp.
For sponsorship information, contact us at advertising@windowsecurity.com
Copyright c WindowSecurity.com 2011. All rights reserved.
Google one of many victims in SSL certificate hack
| Cisco, VMware expand collaboration | Apple suppliers accused of environmental damage | ||||||||||
| Network World Daily News AM | ||||||||||
| Google one of many victims in SSL certificate hack WHITE PAPER: Xsigo Systems Guide: Converged Infrastructure for the Private Cloud This guide discusses the infrastructure challenges of the next-gen private cloud. Traditional networks limit flexibility and increase your workload. Read this 24-page guide to learn about new fabric architectures that virtualize connectivity to increase efficiency and accelerate management by 100X. Read now! In this Issue
WHITE PAPER: Fujitsu A New Look at Energy-Efficient Servers The family of PRIMERGY® Intel® Architecturebased servers offers a wide range of capacities, performance, and configurations to fit almost any application service requirements. Read now! Cisco, VMware expand collaboration Apple suppliers accused of environmental damage Amazon could 'easily' sell 5M of its expected tablets in Q4, Forrester says WHITE PAPER: CA Technologies The Arrival of Cloud Thinking Much is being made of the "the cloud." The money it will save. The agility it will bring to computing. What is less obvious is how IT departments are actively employing cloud services today. How they are reacting to both public and private cloud initiatives. What it will mean over the next couple of years for IT decision makers and implementers. Learn More WikiLeaks cable: Apple slow to counter Chinese fakes Top cybersecurity concerns: Malicious code, employees run amok BlackBerry 7 compatible apps: 10 free downloads WHITE PAPER: GFI Software Economics of Spam Email security threats do not discriminate. Whether you're an organization with 50 employees or a global corporation with 50,000, the reality is that spam and viruses can wreak havoc on your business, drain users' productivity and take a major toll on IT resources. Read now MillerCoors goes social to retain female workers Akamai employee tried to sell secrets to Israel Why you shouldn't buy a discounted TouchPad tablet Salesforce.com revs up mobile strategy with HTML5 | ||||||||||
| ||||||||||
GOODIES FROM MICROSOFT SUBNET SLIDESHOWS The world's geekiest license plates MOST-READ STORIES
| ||||||||||
| Do You Tweet? You are currently subscribed to networkworld_daily_news_alert as security.world@gmail.com. Unsubscribe from this newsletter | Manage your subscriptions | Subscribe | Privacy Policy To contact Network World, please send an e-mail to customer_service@nww.com. Copyright (C) 2011 Network World, 492 Old Connecticut Path, Framingham MA 01701 ** Please do not reply to this message. If you want to contact someone directly, send an e-mail to customer_service@nww.com. ** | ||||||||||
Mobile contact center moves to the cloud
| BlackBerry 7 Compatible Apps: 10 Free Downloads | New AT&T app blocks SMS junkies from texting while driving | ||||||||||
| Network World Wireless | ||||||||||
Mobile contact center moves to the cloud WHITE PAPER: Citrix Systems Cutting Costs with a Virtual Workforce This Forrester paper describes how businesses could lower costs across labor, facilities and travel by implementing a virtual workforce and validates the points with survey data from both the US and China. Read More In this Issue
WHITE PAPER: Akamai Technologies, Inc. Akamai Cloud Optimization for Amazon EC2 The emergence of public cloud platforms and services has IT organizations thinking about which applications they want to keep in-house and which they can build within the cloud. Read more BlackBerry 7 Compatible Apps: 10 Free Downloads New AT&T app blocks SMS junkies from texting while driving Sprint's mysterious Oct. 7 event fuels more iPhone, LTE speculation WHITE PAPER: Fujitsu New TPC-E Benchmark Results Revealed A "glue-less" design, where no additional hardware is necessary to run all eight CPUs and all memory slots enable the shortest route between processors, memory modules and I/O hubs inside a single chassis. It's just one of the many reasons Fujitsu servers are leading the way in TCP-E benchmarks and overall price/performance. Read now! Verizon LTE net will cover 185M people by yearend, says CTO Irene's wrath leaves 6,500 cell towers out, FCC says Groups ask FCC to rule against BART's mobile phone shutdown WHITE PAPER: Xsigo Systems Building a Flexible Private Cloud Datacenter This quick case study examines how a VMware vCloud services provider increased VMware performance and got 17 times more VMs per server with a converged infrastructure. Get insights on VMware best practices from a company that runs VMware for a living. Read now! Isis carriers pump in $100M for mobile wallet plan Driving LTE into the enterprise UPDATED: Android app connects city goers, green transport | ||||||||||
| ||||||||||
GOODIES FROM MICROSOFT SUBNET SLIDESHOWS The world's geekiest license plates MOST-READ STORIES
| ||||||||||
| Do You Tweet? You are currently subscribed to networkworld_wireless_alert as security.world@gmail.com. Unsubscribe from this newsletter | Manage your subscriptions | Subscribe | Privacy Policy To contact Network World, please send an e-mail to customer_service@nww.com. Copyright (C) 2011 Network World, 492 Old Connecticut Path, Framingham MA 01701 ** Please do not reply to this message. If you want to contact someone directly, send an e-mail to customer_service@nww.com. ** | ||||||||||