SEARCH RESULTS
 
Showing 1-10 of 56 records
 
Expand article

Welcome to the Platform Club! :-)

2008-02-15 14:59:00 by Dr Anton Chuvakin in Anton Chuvakin Blog -
 
...broad: from mundane server troubleshooting to forensics to attesting to compliance mandates (and everything in between and around To add more substance to this, let's review some of the key requirements for a log management platform Overall platform requirements (good intro here ): having an access API is central to this Data access: in case...
 
 
 
 
 
Expand article

Some Burning Logging Questions - Answered!

2008-04-23 16:20:00 by Dr Anton Chuvakin in Anton Chuvakin Blog -
 
...broad a question, so here are a few pointers logging affects performance much more on some types of systems compared to other types: most painful examples are databases where some people (can't find a link...sorry) report performance loss of up to 40% if logging all SELECT statements and other data retrieval commands (you need to log...
 
 
 
 
 
Expand article

The NIC | Portal to Disaster? (Step 1 - Part 2)

2006-09-22 15:29:29 by Editor in Endpoint Security: Translating Policy Into Reality
 
Below is a non-exhaustive listing of network enumeration tools. I have purposefully included a broad range of useful and popular tools comprising multiple price ranges (from freeware to expensive
 
 
 
 
 
Expand article

In response to "Soft tokens aren't tokens at all"

2007-12-11 00:00:00 by Sean Kline in Speaking of Security, the RSA Blog and Podcast
 
...broad range of authentication types and form factors To some of your specific points, RSA SecurID hardware and software authenticators are both forms of multi-factor authentication. In the case of hardware authenticators, they are based on something you have (the physical authenticator) and something you know (your password or Personal...
 
 
 
 
 
Expand article

RFID: Menace in the Far North

2007-01-05 00:00:00 by Ari Juels in Speaking of Security, the RSA Blog and Podcast
 
...broad term for wireless microchips. During a recent discussion about the convenient RFID (tap-and-go) transit cards recently introduced in the Boston area, a colleague of my wife asked why I care about RFID privacy so much. He added, "I don't. I've got nothing to hide
 
 
 
 
 
Expand article

Review of My 2007 Security Predictions: Too Wimpy

2007-12-23 15:46:00 by Dr Anton Chuvakin in Anton Chuvakin Blog -
 
...broad, diverse and rich to be solved by a single technology or even a single vendor (corollary: if somebody is trying to sell you such a technology that claims to do exactly that on its own, then - well, you know what to do Status Check II: This one was kind of a no-brainer and way too safe a prediction. Of course, it didn't emerge! It is...
 
 
 
 
 
Expand article

Common Criteria and answering the question 'Is it Safe'

2007-12-20 16:57:00 by sdl in The Security Development Lifecycle
 
...broad acceptance and recognition in the private sector or in any community beyond government agencies. Microsoft has been very vocal in the CC community on suggestions as to why that is and how to modify CC for broader commercial acceptance, and so I thought Id share some of those thoughts here. Currently, Common Criteria fails to meet...
 
 
 
 
 
Expand article

On Religion; Security One, Of Course

2008-02-05 07:26:00 by Dr Anton Chuvakin in Anton Chuvakin Blog -
 
...broad security trends, which main centers around the following: should you use security measures that are trivial to defeat (like NIDS or NIPS)? Is the incremental increase of security (e.g. vs amateur attackers) worth the headache of deployment efforts? Or does it create a false sense of security instead? It was also phrased as incremental...
 
 
 
 
 
Expand article

What is GRC vs. IT GRC - How does it help IT Security mature to the next level?

2008-02-04 13:27:00 by Ryan Shopp in practical risk management
 
...broadly defined space - very broad! To gain a better understanding and appreciation for that, here is a newly released map that identifies various areas and their relationships Another AMR Research note talks about the current maturity point of Enterprises implementing GRC So where does Securityworks play in this "GRC Ecosystem?" We are...