SEARCH RESULTS
 
Showing 1-10 of 45 records
 
Expand article

Who should do your security audits? Or, how do you organize the security department?

2008-02-07 22:25:32 by Steve Riley in Steve Riley on Security
 
...compare the results against what the state should be, and show where we are out of compliance. Essentially, audits help us know that we are indeed doing what we say we're doing Audits are the natural outcomes of implementing good policies and following effective procedures. It makes no sense to spend time developing policies and without...
 
 
 
 
 
Expand article

Symantec + Vontu: A Marriage Made In Heaven?

2007-11-13 08:55:35 by Thomas Raschke in Security & Risk Management
 
...compare please tune into our ILP Wave Update which will become available in mid-Q1 2008 Thomas Raschke
 
 
 
 
 
Expand article

Ask the Auditor: Who is Responsible for Information Security?

2007-12-29 06:24:50 by Editor in Security Links
 
...compare current organizational practices with industry practices to discern whether their organization is operating comparable to others Ensuring that information security systems and management are subject to audit and review by qualified professional reviews and audits, corporate leaders advance the goal of overseeing the organizations...
 
 
 
 
 
Expand article

How effective is the wisdom of crowds as a security mechanism?

2007-12-21 15:26:10 by Tyler Moore in Light Blue Touchpaper
 
...compare to the feeds maintained by specialist website take-down companies hired by the banks? Well, we compared PhishTanks feed to a feed from one such company, and found the companys feed to be slightly more complete and significantly faster in confirming phishing websites. This is because companies can afford employees to verify their...
 
 
 
 
 
Expand article

What Does SHA1 is Broken Mean?

2007-12-12 07:35:00 by Eric Marvets in The Security Samurai
 
...compare against our stored value Its also useful for ensuring the integrity of data. When a message is sent over an unsecured channel, a hash of the message can also be used to check the message once it reaches its destination. If the message does not match the hash, then we assume it was modified in transit Designed Strength of SHA1 When...
 
 
 
 
 
Expand article

Locked Call Boxes and Banned Geiger Counters

2008-01-18 07:44:31 by schneier in Schneier on Security
 
...Compare this with a proposed law in New York City that will require people to get a license before they can buy chemical, biological, or radiological attack detectors: The legislation which was proposed by the Bloomberg administration and would be the first of its kind in the nation would empower the police commissioner to decide whether to...
 
 
 
 
 
Expand article

The Authorities Have Your Skeleton On File

2008-02-12 00:30:03 by Editor in Digg / Security
 
A new patent, issued on Friday, covers a system that would scan some, or all, of your skeleton and compare it with a database of skeletons. The database would also pull up data such as your name, address, social security number, and passport number. Worst of all, you might not even know your skeleton is being scanned from a distance
 
 
 
 
 
Expand article

The First Step on the Road to More Secure Software is admitting you have a Problem

2008-02-21 14:26:00 by sdl in The Security Development Lifecycle
 
...compare RedHat to Mac OSX to Ubuntu to Windows Vista, because let's face it, no-one can agree on any measurement of security without getting knotted up. So let's just ignore the comparison stuff. Measuring security is a real challenge, and while we may debate the merits of vulnerability counts, right now it's the only concrete metric we have...
 
 
 
 
 
Expand article

Best practices - notification of a breach

2008-02-07 16:29:00 by Manu Namboodiri in Data Protection, Management and Leakage
 
...compare and contrast two styles of letters to customers - interesting stuff. How does one provide details without overwhelming the reader who may not understand everything? Does one mention steps beign taken, other breaches in the industry I wonder how many folks within the company (as well as lawyers, PR folks) might be involved in this...