SEARCH RESULTS
 
Showing 1-10 of 275 records
 
Expand article

Updated Microsoft Security Assessment Tool

2008-12-02 04:13:03 by Steve Riley in Steve Riley on Security
 
...resources may assist you in keeping you aware of specific tools and methods that can help change the security posture of your IT environment There are two assessments that define the Microsoft Security Assessment Tool Business Risk Profile Assessment Defense in Depth Assessment (UPDATED The questions identified in the survey portion of the...
 
 
 
 
 
Expand article

Actns/Swif.T virus found in YouTube videos

2008-12-02 10:51:00 by Russ McRee in HolisticInfoSec.org
 
...resources I use to analyze (or have the analysis done for me, to be more concise) malicious Flash or JavaScript I grabbed the evil .swf in question from the URL below via command-line on my trusty Ubuntu box wget hxxp://www.youtube.com/v/O7tB1pYSNuE&rel=1 I then fed l.swf to Adops Tools and Wepawet The results from each analysis are below for...
 
 
 
 
 
Expand article

The Economics of Finding and Fixing Vulnerabilities in Distributed Systems

2008-11-18 22:47:55 by Gunnar Peterson in 1 Raindrop
 
...resources invested in Cisco, network admins, etc Host: all the resources invested in Unix, Windows, sys admins, etc Applications: all the resources invested in developers, CRM, ERP, etc Data: all the resources invested in databases, DBAs, etc Tally up each layer. If you are like most business you will probably find that you spend most on...
 
 
 
 
 
Expand article

Ask the Auditor: Who is Responsible for Information Security?

2007-12-29 06:24:50 by Editor in Security Links
 
...resources to allow controls to be effective 2) The board of directors must provide oversight at a level above other business managers. The directors role in information security is to ask managers the right questions and encourage the right results. Directors must set the right tone at the top, communicating to executive management the...
 
 
 
 
 
Expand article

Personal information stolen from Georgia DHR

The Article has images
2008-03-27 15:51:45 by Evan Francen in The Breach Blog
...Resources Victims Current and former employees Number Affected Unknown Types of Data names, social security numbers, birth dates, home contact and federal tax information Breach Description The Georgia Department of Human Resources is taking extensive measures to alert current and former employees of a breach of confidential records that...
 
 
 
 
 
Expand article

Virtual Security = Virtual Performance Challenge

2008-02-14 18:24:44 by John Peterson in Security In The Virtual World
 
...resources have been UNDER utilized. People have traditionally bought a server to host an application and those applications are not always in use. Many times they sit idle while other servers are maxed out and could use the help of those idle CPU's on the server in the next rack. So, by sharing CPU/Memory resources virtualization allows for...
 
 
 
 
 
Expand article

Virtual Security = Virtual Performance Challenge

2008-02-14 18:24:44 by John Peterson in Security In The Virtual World
 
...resources have been UNDER utilized. People have traditionally bought a server to host an application and those applications are not always in use. Many times they sit idle while other servers are maxed out and could use the help of those idle CPU's on the server in the next rack. So, by sharing CPU/Memory resources virtualization allows for...
 
 
 
 
 
Expand article

Security Consultant Hacks: Size Matters

2007-12-20 05:16:07 by Bill in Grumpy Security Guy
 
...resources within their specialities. Typically these are 1-5 person shops that are fairly niche focused, maybe they specialize in Web Application Security , secure development, or PCI audits Advantages : If you are using them in an engagement that is their speciality you are going to get a lot of bang for your buck. Prices are generally in...
 
 
 
 
 
Expand article

Measuring Vulnerability

The Article has images
2008-04-14 14:31:38 by JonesJ in RiskAnalys.is
...resources to defeat the applications security This works as a quick-and-dirty solution, and in many cases is good enough. Read on if youre interested in a somewhat more involved approach Uncertainty Unfortunately, in the real world we usually dont know Which threat agent is going to act next What their capabilities are, or What our resistance...
 
 
 
 
 
Expand article

A horse's ass approach to virtualization security - Part 3 - Data is the "constant"

2008-10-23 20:51:00 by Manu Namboodiri in Data Protection, Management and Leakage