SecurityRatty :: tag: mitigation
Featured Articles :: Anonymizer acquired by risk-mitigation firm :: Have you googled, HR security breaches lately? :: Autorun: good for you? :: Malware Infected Hosts as Stepping Stones :: CFIUS 2 - M&A 0 :: How do you spell R-E-L-I-E-F? :: Security Incident Strikes and You are on the Hot Seat.. :: We did not get sufficient budget for security program.. :: Top 3 conclusions about IT Risk Management we like hearing :: Is Risk-Based Security Really Possible?
Herndon, Va.,-based risk-mitigation firm Abraxas Corp. announced it has acquired, for an undisclosed price, San Diego-based Anonymizer, which makes products that shield a user's identity online
...mitigation terms in their contract, Colt Express announced that it was in financial difficulty. So Google has had to pay for financial reporting and other compensation to its own employees, even though Google did nothing wrong
Third, a Google representative stated "We take the security of our employees very seriously and require outside...
...mitigation. At a recent conference I was surprised at the number of folks who haven't considered the risks of leaving it enabled. Surely by now most of you have heard about how certain music CDs can spread rootkits in your network. Yeah, holding down the [Shift] key when inserting a CD-ROM or USB drive will bypass the autorun.inf file -- but...
...mitigation approaches
In typical proxybot infections we investigate proxy servers are installed on compromised machines on random high ports (above 1024) and the miscreants track their active proxies by making them "call home" and advertise their availability, IP address, and port(s) their proxies are listening on. These aggregated proxy...
...mitigation agreement. As I wrote about last week, 3Com and company had offered to spin off Tipping Point to remove any potentially sensitive technology from the deal. I guess that wasn't enough for those free trade dudes at CFIUS. So the 3Com-Bain deal joins the Checkpoint-Sourcefire deal as being shut down by the government. 3Com's stock...
...mitigation proposals including the selling off of Tipping Point
In my mind the question is: Will that be enough? Is it only the Tipping Point stuff that causes the issue? Does 3Com have other sensitive technology. I don't know, but I am sure the recent arrest of 4 Chinese people on espionage type of charges did not help the Bain position....
...mitigation plan for this newly known vulnerability going forward
Scenario 3: The vulnerability that resulted in the incident was ignored. Remediation: Deal with the incident and revisit why the vulnerability was chosen to be ignored in the first place. It may be possible that you end up making a decision of not ignoring this vulnerability
...
Security manager often complain about the budget allocation to the security program. Is it true that senior management does not give a hoot about security? More likely than not the security manager has not communicated the value of the security program (Please. refer: Mike Rothman's Pragmatic CSO Section 4:Communicate your Value
1. Track metrics...
...mitigation, balanced controls and frameworks are also necessary in order to provide complete risk management capabilities
Management should consider implementing a continuous risk assessment process