SEARCH RESULTS
 
Showing 1-10 of 210 records
 
Expand article

Ask the Auditor: Who is Responsible for Information Security?

2007-12-29 06:24:50 by Editor in Security Links
 
...responsible for information security By Dan Swanson A Reader Asks: Who is responsible for information security The Auditor Responds: In short, the board of directors, management (of both staff and business lines), and internal audit functions all have significant roles in auditing information security. The big question for many companies is...
 
 
 
 
 
Expand article

Responsible-ish Disclosure

2008-05-08 20:50:57 by Chris Eng in Zero in a bit
 
...responsible. But look at the code its completely generic, just a textbook example of what it looks like when you forget to check a return value after calling operator new. Sure, Core gives you the exact offsets into the executable, but so what? If I have the binary, then its not going to be too hard to find the vulnerability anyway. Its not...
 
 
 
 
 
Expand article

Sensitive Milwaukee County information posted to Web

The Article has images
2008-02-13 17:06:24 by Evan Francen in The Breach Blog
...Responsible Government Network Victims Persons involved with the county Number Affected Unknown Types of Data patient and legal records Breach Description Milwaukee County officials released a copy of their "county spending database" to the activist group Citizens for Responsible Government Network that contained sensitive personal...
 
 
 
 
 
Expand article

NERC CIP Rules Out - Logs In!

2008-01-24 13:06:00 by Dr Anton Chuvakin in Anton Chuvakin Blog -
 
...Responsible Entity shall establish methods, processes, and procedures that generate logs of sufficient detail to create historical audit trails of individual user account access activity for a minimum of ninety days and R6.4. The Responsible Entity shall retain all logs specified in Requirement R6 for ninety calendar days R6.5. The...
 
 
 
 
 
Expand article

Some Comments on PayPal's Security Vulnerability Disclosure Policy

2007-11-27 18:07:00 by Security Retentive in Security Retentive
 
...responsible side of the line From Don's post I got a creepy feeling about actually trusting the statement. I will probably never attempt to test the security of PayPals site, but for those who do I would hate for the disclosure statement to change suddenly As I said earlier, we do believe the policy is a work in progress. We will modify it...
 
 
 
 
 
Expand article

New Banking Code shifts more liability to customers

2008-04-09 14:08:49 by Steven J. Murdoch in Light Blue Touchpaper
 
...responsible for all losses on your account. If you act without reasonable care, and this causes losses, you may be responsible for them. (This may apply, for example, if you do not follow section 12.5 or 12.9 or you do not keep to your accounts terms and conditions Clauses 12.5 and 12.9 include some debatable advice about anti-virus software...
 
 
 
 
 
Expand article

Service Canada employee loses flash drive

The Article has images
2008-06-28 23:18:19 by Evan Francen in The Breach Blog
...responsible for the security of some very sensitive personal information belonging to thousands (maybe millions) of Canadians. As such, the people that are permitted to access (assuming that role-based access control is enforced at Service Canada) confidential information must be properly trained and made constantly aware of the risks...
 
 
 
 
 
Expand article

Colorado Division of Motor Vehicles cited in audit report

The Article has images
2008-07-11 09:18:07 by Evan Francen in The Breach Blog
...responsible for security Evan] Or is it no one is responsible for security High turnover - 60 percent of entry-level workers leave during their first year - and low, $26,280-a-year starting salaries make fraud more attractive and management more difficult, DMV officials said Evan] This is another problem that contributes significantly to the...
 
 
 
 
 
Expand article

Partial Disclosure - The Good, Bad, and Ugly

2008-10-21 13:58:00 by Tyler Shields in Zero in a bit
 
...Responsible Disclosure whereby the security researcher responsibly discloses the discovered vulnerability to the vendor and works in a cooperative fashion in an effort to minimize the risk to the general user populous. This has worked well in the vast majority of cases that I have had the pleasure of managing the disclosure process Partial...
 
 
 
 
 
Expand article

Deloitte & Touche and IKON lose confidential information

The Article has images