|
Four key vulnerabilities of data security |
PDF |
| Print | |
E-mail |
|
Why do businesses fall victim to attacks on their customer data and IP by trusted insiders and / or criminal hackers? This article analyzes four key vulnerabilities of business data. |
|
Read more...
|
|
|
Data loss threat modeling |
PDF |
| Print | |
E-mail |
|
There is currently no commonly accepted, standard, vendor-neutral methodology and security metrics available to quantify and valuate potential impact of internal threats and vulnerabilities and generate a financial justification for an extrusion prevention/data leakage prevention system. This is a symptom of a much larger problem in the entire computer security industry that relies on fear, uncertainty and doubt to sell security products. |
|
Read more...
|
|
Introduction to data loss prevention |
PDF |
| Print | |
E-mail |
Published in Extrusion Part 1: Trusted Digital Insider Theft MARCH, 2004 (COMPUTERWORLD) Trusted insider theft continues to lead as the number one source of economic loss due to computer crime. Even organizations that have deployed a wide range of security technologies fall victim to significant losses. ...the percentage of incidents that are reported to law enforcement agencies remains low. ...attackers may reasonably infer that the odds against their being caught and prosecuted remain strongly in their favor. CSI/FBI 2003 Computer Crime and Security Survey |
|
Read more...
|
|
Extrusion Prevention (Hebrew) - Part 3 |
PDF |
| Print | |
E-mail |
|
The Hebrew language version of the Introduction to Extrusion Prevention - Part III - The role of the regulator. |
|
Read more...
|
|
Data Security and compliance |
PDF |
| Print | |
E-mail |
|
Regulation - drives business into taking action. Is regulation more than just a trigger to management action? Data security requires both management and technology controls. The trigger to implementation often lies in government regulation. This article examines the relevance of regulation in the US and in Europe. |
|
Read more...
|
|
Extrusion Prevention (Hebrew) - Part 1 |
PDF |
| Print | |
E-mail |
|
The hebrew language version of Extrusion Prevention - Part 1 - Introduction to Data Leakage |
|
Read more...
|
|
Extrusion Prevention (Hebrew) - Part 2 |
PDF |
| Print | |
E-mail |
|
The hebrew language version of Extrusion Prevention - Part 2 - How do you deal with trusted insiders and Data Leakage Threats? |
|
Read more...
|
|
Data loss prevention shoppers guide |
PDF |
| Print | |
E-mail |
Published in Extrusion: The story of 'trusted' digital insider theft OCTOBER 28, 2004 (COMPUTERWORLD) - The essence of effective security countermeasures is "To be able to do something before it exists, to sense before it becomes active and see before it sprouts." The Book of Balance and Harmony (Chung-ho chi). This article discusses the threats that drive the business makers to buy and the industry players that provide the solutions. The shoppers guide will hopefully help you choose the solution that best fits your business and your threat profile. |
|
Read more...
|
|
Data security - 10 common mistakes |
PDF |
| Print | |
E-mail |
|
Take a leadership role in the board room instead of waiting for vendor proposals in your office Learn how to make that happen at our online workshops on data security starting this Thursday September 17, 2009, 10:00 EST 14:00 GMT, 16:00 CEST 17:00 IST 18:00 MT. |
|
Read more...
|
|
Novel phishing attack on personal information |
PDF |
| Print | |
E-mail |
|
The IRS is not the only ones after your money. A new e-mail phishing scam poses as a message from the U.S Internal Revenue Service (IRS) and notifies recipients of a refund waiting for them at the IRS website. According to Sophos security, this scam exploits the vulnerable security configuration of a secondary government website. A link provided in the deceptive e-mail redirects surfers to a legitimate looking website where any personal information entered, such as credit card details and social security numbers, will be completely exposed. For the full report see The Register |
|
Data Leakage Prevention Check List |
PDF |
| Print | |
E-mail |
|
Conventional security systems take an indirect approach by focusing on controlling user behavior through access control and authentication. This indirect method places a heavy burden on security staff and does not scale well in today's large, global service operations. Unlike indirect methods that focus on preventing unwanted users from getting in, a direct approach of protecting the data helps prevent breach of confidentiality and integrity of valuable digital assets. |
|
Read more...
|
|
Protecting data on laptops |
PDF |
| Print | |
E-mail |
|
Not USB, not email - but mobile computers are main vulnerability to customer data and IP.
We've been tracking trends since 2005, when almost half of all identity data breaches where due to stolen hardware (notebooks or backup media). The situation has not improved since then and one of our Far East clients reports that their field service engineers lose at least one notebook a month.
|
|
Read more...
|
|
Paris Hilton T-mobile hack boosts sales |
PDF |
| Print | |
E-mail |
|
Data loss prevention is not just about trusted insiders blowing the whistle on their employer or stealing valuable chip design documents. A data loss event is any unauthorized network transfer of sensitive information - information like Paris Hilton's T-Moble Sidekick cell phone address book. SQL injection has turned out to play a central role in the extrusion of Hilton's T-Mobile Sidekick account, which resulted in her star-studded address book, photos, e-mail messages, and voice mail being posted for public consumption on the Internet. SQL injection enabled a password reset; a hole that is just one of hundreds, or even thousands, of similar SQL injection flaws in the mobile provider's Web site that could provide easy access to hackers and a wide-open door for future customer record extrusion exploits. Despite the vulnerabilities in T-Mobile's Web site, the company is not complaining - verifying the old saying that bad publicity is better than no publicity - T-Mobile Sidekicks are flying off the shelves. For the full story - Click here |
|
Why is data security like Candy? |
PDF |
| Print | |
E-mail |
|
"Corporate networks are like candy bars: hard on the outside, soft and chewy on the inside," says Rich Mogull, a security analyst at Gartner Research. After having spent billions on defenses against external threats of virii and hackers - Internal Security is now taking off after years of neglect following a series of well publicized data leakage events over the past 4 years and increasing pressure for compliance from laws like Sarbanes-Oxley and GLBH. Gartner's lead analyst Rich Mogull and others say that 2008 is the year of data leakage prevention technology and no one wants to make headlines for extrusion of sensitive data. You may be required by law to disclose a data leakage event, but it certainly isn't something you're proud of. In many cases, the attitude of the company management is that the less eyeballs looking at the problem - the better off they are. - Sep '04 - credit-software company Teledata employee pleads guilty to federal fraud charges of stealing the financial identities of over 30,000 people
- June '04 AOL - An employee was arrested for allegedly stealing 92 million screen names and selling them.
- Feb '04 - 4.5 million subscriber names, phone numbers, postal addresses, email addresses and 4.5 million subscriber names, phone numbers, postal addresses, email addresses and Yahoo Japan IDs were leaked from Softbank Corp., the largest provider of broadband access in Japan. Toyko police arrested four insiders suspected of stealing the confidential data and demanding a payment from Softbank to avoid it being leaked. Softbank's CEO Masayoshi Son accepted responsibility, apologized and took a 50% salary cut for 6 months.
|
|
Read more...
|
|
Attaining PCI DSS certification - an introduction |
PDF |
| Print | |
E-mail |
|
I was talking with a colleague in the UK a few weeks ago, discussing UK trends in information security. He reflected that many UK firms are slow to adopt IPS (Intrusion Prevention Systems) and that SOX projects are dominated by the big accounting firms, leaving little space for smaller consultants. However, he mentioned that PCI compliance is increasingly a must-have for his UK and EU clients. This article discusses how to comply with PCI DSS 1.1 and how to sustain consistent ongoing enforcement using extrusion detection technologies. |
|
Read more...
|
|
Data security - practical ways of building the business case |
PDF |
| Print | |
E-mail |
|
How to justify information security spending. Not so long ago - it was possible to sell information security technology with FUD (fear, uncertainty and doubt). Is FUD and ROI dead for Information security justifications? This opinion piece was published by Danny Lieberman in Computer World Online, March 17, 2005. |
|
Read more...
|
|
|
|
|
<< Start < Prev 1 2 Next > End >>
|
|
Page 1 of 2 |