<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: reinforces]]></title>
    <link>http://securityratty.com/tag/reinforces</link>
    <description></description>
    <pubDate>Thu, 13 Dec 2007 09:37:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[BitDefender Tops Latest Rootkit Detection Test by AV-Test.org]]></title>
      <link>http://securityratty.com/article/7695d5336702bb1003e7091358fde805</link>
      <guid>http://securityratty.com/article/7695d5336702bb1003e7091358fde805</guid>
      <description><![CDATA[MOUNTAIN VIEW, CA(Marketwire - May 27, 2008) - BitDefender , an award-winning provider of antivirus software and data security solutions, announced today that BitDefender Internet Security Suite 2008,...]]></description>
      <content:encoded><![CDATA[<p>MOUNTAIN VIEW, CA&#8211;(Marketwire - May 27, 2008) -  <a href="http://www.bitdefender.com/">BitDefender</a>®, an award-winning provider of antivirus software and data security solutions, announced today that BitDefender Internet Security Suite 2008, running on Microsoft Windows XP, received top rootkit detection results in a test conducted by AV-Test.org last month. On Microsoft Windows Vista Ultimate, BitDefender was also one of the top three products.</p>
<p>The tests, running on Microsoft XP Home Edition and Microsoft Vista Ultimate Edition, pitted 60 active malware samples (both rootkits and malware hidden using rootkits) against a selection of antivirus software packages.</p>
<p>While the results of the test showed that detection and removal of running rootkits is a problem for most major antivirus companies, BitDefender Internet Security 2008 managed to remove 23 rootkits and 27 hidden malware programs, a success which BitDefender CTO Bogdan Dumitru partly attributed to the B-HAVE pro-active detection technology developed by BitDefender.</p>
<p>&#8220;The results of tests conducted by independent organizations like AV-Test.org, reinforces BitDefender&#8217;s success as we strive to improve our proactive detection technologies,&#8221; said Bogdan Dumitru, BitDefender&#8217;s CTO.</p>
<p>For further details on the results of this test, please visit AV-Test.org (<a href="http://www.av-test.org/">http://www.av-test.org</a>). Details on the company&#8217;s testing techniques can also be obtained <a href="http://www.av-test.org/index.php?sub=Papers&amp;menue=1&amp;lang=1">here</a>.</p>
<p>Jordan the SpywareBiz mascot highly recommends BitDefender for your XP and Vista machines.</p>
<p>Visit <a title="SpywareBiz.com" href="http://www.spywarebiz.com" target="_blank">SpywareBiz.com</a> to purchase this great product.</p>
]]></content:encoded>
      <pubDate>Tue, 27 May 2008 09:28:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/microsoft vista">microsoft vista</category>
      <category domain="http://securityratty.com/tag/bitdefender">bitdefender</category>
      <category domain="http://securityratty.com/tag/microsoft windows">microsoft windows</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/detection">detection</category>
      <category domain="http://securityratty.com/tag/microsoft windows vista">microsoft windows vista</category>
      <category domain="http://securityratty.com/tag/test">test</category>
      <category domain="http://securityratty.com/tag/bitdefender internet security">bitdefender internet security</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=465">BitDefender Tops Latest Rootkit Detection Test by AV-Test.org</source>
    </item>
    <item>
      <title><![CDATA[PayPal denies plan to block Safari]]></title>
      <link>http://securityratty.com/article/11bb1a49dd421edad0a6c0e6095f4fca</link>
      <guid>http://securityratty.com/article/11bb1a49dd421edad0a6c0e6095f4fca</guid>
      <description><![CDATA[PayPal has denied claims it plans to lock Safari users out of its online payments service as it reinforces its protections against online credit...]]></description>
      <content:encoded><![CDATA[PayPal has denied claims it plans to lock Safari users out of its online payments service as it reinforces its protections against online credit fraud.]]></content:encoded>
      <pubDate>Sun, 20 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/online payments service">online payments service</category>
      <category domain="http://securityratty.com/tag/lock safari users">lock safari users</category>
      <category domain="http://securityratty.com/tag/online credit fraud">online credit fraud</category>
      <category domain="http://securityratty.com/tag/paypal">paypal</category>
      <category domain="http://securityratty.com/tag/reinforces">reinforces</category>
      <category domain="http://securityratty.com/tag/plans">plans</category>
      <category domain="http://securityratty.com/tag/claims">claims</category>
      <category domain="http://securityratty.com/tag/protections">protections</category>
      <source url="http://www.networkworld.com/news/2008/042108-paypal-denies-plan-to-block.html?fsrc=rss-security">PayPal denies plan to block Safari</source>
    </item>
    <item>
      <title><![CDATA[Cisco reinforces physical security family]]></title>
      <link>http://securityratty.com/article/7a8573c1d1e48f155f9389f786462a65</link>
      <guid>http://securityratty.com/article/7a8573c1d1e48f155f9389f786462a65</guid>
      <description><![CDATA[Cisco upgrades physical-security product line, with the Cisco High Definition 1080P Intelligent Camera for indoor use and the introduction of the Cisco Physical Access Manager for electronic-access...]]></description>
      <content:encoded><![CDATA[Cisco upgrades physical-security product line, with the Cisco High Definition 1080P Intelligent Camera for indoor use and the introduction of the Cisco Physical Access Manager for electronic-access control for existing door readers, locks and biometric devices.]]></content:encoded>
      <pubDate>Tue, 01 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cisco">cisco</category>
      <category domain="http://securityratty.com/tag/cisco upgrades">cisco upgrades</category>
      <category domain="http://securityratty.com/tag/product line">product line</category>
      <category domain="http://securityratty.com/tag/door readers">door readers</category>
      <category domain="http://securityratty.com/tag/biometric devices">biometric devices</category>
      <category domain="http://securityratty.com/tag/indoor">indoor</category>
      <category domain="http://securityratty.com/tag/locks">locks</category>
      <category domain="http://securityratty.com/tag/introduction">introduction</category>
      <category domain="http://securityratty.com/tag/control">control</category>
      <source url="http://www.networkworld.com/news/2008/040208-cisco-reinforces-security.html?fsrc=rss-security">Cisco reinforces physical security family</source>
    </item>
    <item>
      <title><![CDATA[Gartner IT GRC Predictions]]></title>
      <link>http://securityratty.com/article/64c31fd2355dee979fae931011887c69</link>
      <guid>http://securityratty.com/article/64c31fd2355dee979fae931011887c69</guid>
      <description><![CDATA[I just had a chance to take a look at some recent research put out by Gartner on the IT Governance, Risk &amp; Compliance Management space (IT-GRC

They do an artful job laying out the customer desired...]]></description>
      <content:encoded><![CDATA[I just had a chance to take a look at some recent research put out by Gartner on the IT Governance, Risk &amp; Compliance Management space (IT-GRC).<br /><br />They do an artful job laying out the customer desired capabilities and scoping the size of the market opportunity.<br /><br />A couple key points to soak in:<br /><ul><li>IT GRCM products provide functions that address needs expressed by<span style="font-weight: bold;"> 75% of the Gartner client base</span>.</li><li>Gartner estimates that software license revenue for vendors...was $73million for 2007, and we project a growth rate of <span style="font-weight: bold;">70% for 2008.<br /></span></li></ul>This reinforces previous posts with hard numbers that 2008 is indeed the year of IT Risk Managment.  Here are links to those previous posts...<br /><br /><ul><li><a href="http://www.security-works.com/blog/2008/01/2008-year-of-it-risk-management.html">2008 - The Year of IT Risk Management</a></li><li><a href="http://www.security-works.com/blog/2008/01/2008-year-of-it-risk-management-part-2.html">2008 - The Year of IT Risk Management, Part 2 - Rise of IT GRC</a></li><li><a href="http://www.security-works.com/blog/2008/01/2008-year-of-it-risk-management-part-3.html">2008 - The Year of IT Risk Management, Part 3 - More and more GRC oriented predictions</a></li></ul>                                                                                                                                                                                                                        <br />I highly recommend heading up to Gartner's website and reading each report;<br /><ul><li><a href="http://www.gartner.com/DisplayDocument?id=600315&amp;ref=g_fromdoc">MarketScope for IT Governance, Risk and Compliance Management, 2008</a></li><li><a href="http://www.gartner.com/DisplayDocument?id=600307&amp;ref=g_fromdoc">Critical Capabilities for IT GRCM Tools<span style=";font-family:Times New Roman;font-size:100%;"  > </span></a></li></ul> Then come take a look at how Securityworks can help solve your IT-GRC needs by accomplishing those defined needs and capabilities.<img src="http://feeds.feedburner.com/~r/PracticalRiskManagement/~4/234508923" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 13 Feb 2008 14:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gartner">gartner</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/grc">grc</category>
      <category domain="http://securityratty.com/tag/gartner client base">gartner client base</category>
      <category domain="http://securityratty.com/tag/previous posts">previous posts</category>
      <category domain="http://securityratty.com/tag/compliance management">compliance management</category>
      <category domain="http://securityratty.com/tag/compliance management space">compliance management space</category>
      <category domain="http://securityratty.com/tag/reinforces previous posts">reinforces previous posts</category>
      <source url="http://feeds.feedburner.com/~r/PracticalRiskManagement/~3/234508923/gartner-it-grc-predictions.html">Gartner IT GRC Predictions</source>
    </item>
    <item>
      <title><![CDATA[Users continue to ignore security policies, while security organizations are overlooking non-technical controls]]></title>
      <link>http://securityratty.com/article/3a71307a63d6fe7ed6067de0f36e1683</link>
      <guid>http://securityratty.com/article/3a71307a63d6fe7ed6067de0f36e1683</guid>
      <description><![CDATA[IT Compliance Institute had an article posted this morning that reinforces the point; &quot;it's not the software/hardware/infrastructure/etc but the people and processes that expose the biggest risks to a...]]></description>
      <content:encoded><![CDATA[<a href="http://www.itcinstitute.com/display.aspx?ID=4648">IT Compliance Institute had an article posted this morning that reinforces</a> the point; "it's not the software/hardware/infrastructure/etc but the people and processes that expose the biggest risks to a company.<p>The article doesn't reveal who/where the survey was taken but it does highlight some key security items that people usually cut corners on.<br /></p><ul><li>Fifty-six percent said they had accessed office e-mail via a public wireless hotspot</li><li>52 percent said they had accessed office e-mail via a public computer. </li><li> Eight percent admitted to having lost a mobile device containing corporate information. </li><li> Sixty-three percent admitted to sending corporate documents to their personal e-mail addresses so they could work at home.</li></ul>There are security technologies out their (e.g., encryption, data leakage) that can help with each item but the challenge is keeping up with other IT technologies being deployed and business demands/challenges the users are trying to productively solve. Bottom line, you can't bypass making sure you have the right policies, procedures and education in place for your users (aka non-technical controls).<br /><br />After reading this I decided to do some searching around for some type of survey numbers around technical vs. non-technical controls. I didn't see much out there but did come across this ("<a href="http://csdl2.computer.org/comp/mags/sp/2007/01/j1036.pdf">Is Information Security Under Control</a>') from IEEE Computer Society published in early 2007.<br /><br />The survey focused in on 80 of the highest quality security controls as determined by a group of experts. From that list of 80 their wasn't a place that specifically counted the number of non-technical vs. technical controls BUT, there were two very interesting graphs.<br /><br />The first one (figure 2 in the article. - see below) showed the top 10 with the highest level of quality implementation. It revealed that 6 are technical controls and 4 are non-technical controls. Meanwhile, the second graphic (figure 3 in the article - see below) showed the bottom 10 related to quality of implementation. It revealed that 3 are technical while 7 were non-technical.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.security-works.com/blog/uploaded_images/bottomqualitycontrols-760776.jpg"><img style="cursor: pointer;" src="http://www.security-works.com/blog/uploaded_images/bottomqualitycontrols-760772.jpg" alt="" border="0" /></a>  <a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.security-works.com/blog/uploaded_images/topqualitycontrols-768992.jpg"><img style="cursor: pointer;" src="http://www.security-works.com/blog/uploaded_images/topqualitycontrols-768989.jpg" alt="" border="0" />    </a><br /><br />So just running crude number here shows 11 of those 20 were non-technical controls while 9 were technical controls.  The articles goes on to make the statement "...we found that of all 80 practices surveyed, management controls (non-technical controls) had substantially lower implementation ratings then controls in the technical and operational categories... Organizations must realize that a large proportion of information security problems extend far beyond technology and learn to appreciate the role that less technical controls, such as policy development, play in minimizing security breaches' impact on mission-critical operations.<br /><br />So this begs the question, "when was the last time your security group considered software products that help with managing these non-technical controls instead of just technical controls?"  I've talked with numerous enterprises that have installed or are investigating various software products like Vulnerability Assessment, Patch/Configuration Management, Antivirus, SEIM, data leakage, etc.  Maybe it's time to do something for your non-technical controls also and consider adding IT-GRC products to that 2008 budget/priority list.<img src="http://feeds.feedburner.com/~r/PracticalRiskManagement/~4/199743638" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 13 Dec 2007 09:37:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/non-technical controls">non-technical controls</category>
      <category domain="http://securityratty.com/tag/technical controls">technical controls</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/controls">controls</category>
      <category domain="http://securityratty.com/tag/aka non-technical controls">aka non-technical controls</category>
      <category domain="http://securityratty.com/tag/non-technical">non-technical</category>
      <category domain="http://securityratty.com/tag/quality">quality</category>
      <category domain="http://securityratty.com/tag/quality security controls">quality security controls</category>
      <category domain="http://securityratty.com/tag/technical">technical</category>
      <source url="http://feeds.feedburner.com/~r/PracticalRiskManagement/~3/199743638/users-continue-to-ignore-security.html">Users continue to ignore security policies, while security organizations are overlooking non-technical controls</source>
    </item>
  </channel>
</rss>
