Wednesday | 3 December, 2008
CSO

Identity Management

News
  • +

    US border patrol screening to require air travelers to fork out more info 27/10/2008 09:14:00

    Birth date, gender to be included in Secure Flight validation program
    Starting early next year, air travelers will have to provide their birth date and gender, as well as their full names to the airline when making flight reservations.
  • +

    Palin hacking charge flawed, lawyers say 09/10/2008 07:28:00

    Case considered a misdemeanor offence not a felony.
    David Kernell is facing five years in prison for allegedly hacking into Alaska Governor Sarah Palin's Yahoo e-mail account, but lawyers watching the case say that the felony charge against him is a bit of a stretch.
  • +

    US man indicted for hacking Palin's e-mail account 09/10/2008 10:00:00

    David C. Kernell was indicted on a single charge of accessing a protected computer.
    A 20-year-old Tennessee man has been indicted for hacking into an e-mail account of U.S. vice presidential candidate Sarah Palin, according to court records.
  • +

    US Terror threat system crippled by technical flaws 28/08/2008 09:53:00

    US Congress charges that US$500m project to prevent another 9/11 is a complete failure.
    A US House subcommittee is charging that a US$500 million IT project intended to "connect the dots" on terrorists and help prevent another 9/11 is a failure; it can't even handle basic Boolean search terms, such as "and, or and not."
  • +

    Identity overload: complacency breeding fraudster paradise 20/05/2008 12:27:12

    A generation risk having their identities devalued.
    The next time you relinquish your personal identity to simply enter a venue or purchase something, spare a thought for how the information might be stored, transmitted and used in the future. Such an overload of identity information may lead to a dramatic escalation in fraud, claims one legal eye.
  • +

    New Zealand gov't ID plan lacks 'terrorism bug' infection 07/05/2008 10:02:11

    Australian ID-scheme critic says NZ is getting it right
    International experts in Wellington for a conference on identity last week expressed admiration for the New Zealand government's igovt identity information management scheme and the policy behind it.
  • +

    Sydney club secures $50M with off-the-shelf firewall 23/04/2008 12:37:47

    Single roll out secures gaming machines, public hotspot.
    A prominent Sydney club has deployed a network firewall solution to protect its gaming rewards system, which can potentially hold $50 million.
  • +

    Chemical giant set to begin identity management rollout 06/02/2008 08:02:59

    System analysis and design underway
    BMC Australia has won a deal with explosives, chemicals and paint making giant Orica to provide automated employee identity management to accelerate the productivity of new employees.
  • +

    Barclays 'chairman' scams his own bank 11/01/2008 12:28:04

    Fraudster poses as bank’s chairman, withdraws £10,000
    Barclays bank in the UK has found itself at the centre of another security scam, this time around someone posed as the bank's chairman and scammed £10,000 out of his personal account.
  • +

    Yahoo tests support for OpenID 10/01/2008 08:26:13

    Yahoo appears close to implementing OpenID, a Web authentication standard that relieves people of the need to remember multiple passwords.
    Yahoo appears close to implementing OpenID, a Web authentication standard that relieves people of the need to remember multiple passwords to log into different Web sites.
  • +

    Top Gear host publishes bank details, loses money 09/01/2008 09:00:54

    Jeremy Clarkson ‘donates’ £500 to diabetes charity
    The BBC presenter Jeremy Clarkson has lost £500 after publishing his bank details in a British newspaper in a naive attempt to prove that the UK's largest ever data breach was a storm in a tea cup.
  • +

    IBM digs into security management 08/01/2008 10:04:54

    Big Blue claims it is on track to becoming a top provider of security operations
    IBM is aggressively expanding its security portfolio in hopes of becoming the de facto source of advice and technology for businesses looking to adopt high-level IT governance and risk management strategies -- a transformation among customers that officials at Big Blue cite as both ongoing and inevitable.
  • +

    IBM upgrades identity management software 13/12/2007 08:00:47

    Big Blue bolstering its network security presence
    IBM upgraded its identity management capabilities with tools to help customers manage user access to sensitive information, the company said Wednesday.
  • +

    UK Government stands by security of ID cards data plans 23/11/2007 09:18:28

    In the wake of Britains largest ever security breach, the government stands by its ID card scheme despite doubts
    The government has defended security measures for its £5.6 billion ID cards scheme in the wake of the data loss crisis at HM Revenue and Customs.
  • +

    Microsoft gives interoperability progress report 25/10/2007 10:20:20

    Announcement is "a way of taking stock after a year of fairly intensive activity," according to Microsoft GM
    Microsoft is offering updates on the progress of interoperability initiatives, including the Interoperability Executive Customer Council (IEC) and the Interop Vendor Alliance (IVA).
Features
  • +

    Six essential steps to secure academia 16/09/2008 11:18:00

    Networks in the academic world mirror the Wild West, where data protection is an uphill battle. CISO Stan Gatewood explains how he pulls it off in six essential steps
    Computer networks in the academic world are a lot like the Wild West: It's hard to tell the good guys from the bad, and the sheriff's ability to maintain order is severely limited.
  • +

    Capabilities of Full-Fledged Role Management Systems 09/09/2008 10:34:00

    Today's role management solutions include several or all of the following capabilities, according to Burton Group analyst Kevin Kampman
    Role mining and discovery: The ability to collect user access and authorization information from a variety of resources, associate this data with candidate roles and responsibilities, propose alternative roles and leverage decisions made about the data on an ongoing basis.
  • +

    Who's Who in Role Management? 09/09/2008 10:31:00

    Burton Group breaks the market down into two important segments
    The role management software vendor community is relatively young, and as such, Burton Group says there is no clear market leader. Vendors can be categorized into two segments: general purpose solutions and embedded solutions.
  • +

    How secure is secure enough? 29/07/2008 07:44:00

    Are your information security plans too big, too small or just right? Here are five steps to help you decide.
    If there is a Holy Grail in the information security industry, it surely is the answer to the question, "How secure is secure enough?"
  • +

    12 ways to visualize network security 15/07/2008 10:26:48

    Is enterprise security like a stack of Swiss cheese? Or is it more like a Dirty Harry movie?
    Remember the old M&M analogy - security is like an M&M candy, hard shell on the outside, soft on the inside. In other words, put up firewalls, built a strong perimeter and you're good to go. Of course, nobody believes that M&M-type security is sufficient in today's world of insider threats, data leakage, mobile workers, thumb drives and sophisticated malware. So, what's the new metaphor? We asked around and came up with a number of interesting and useful ways to think about enterprise security.
  • +

    Stupid hacker tricks: The folly of youth 06/05/2008 18:28:18

    Tech-savvy delinquents set the Net aflame with boneheaded exploits that earn them the wrong kind of fame
    Ah, youth. Ready to take on the world, today's generation of dynamic, tech-immersed youngsters have grown up alongside the Internet. Firsthand, and sometimes single-handedly, they have advanced some of today's hottest technology trends, from peer-to-peer networking, to massively multiplayer online games, to social networks and instant messaging. And along the way, a small, sociopathic number of them have behaved very, very badly.
  • +

    Two-factor authentication: Hot technology for 2008 15/01/2008 12:12:09

    Where there’s a will, there’s a way
    We've known for a long time that requiring just a user name and password to get on the network or to access personal information on a Web site isn't the tightest security posture, but there weren't a lot of good alternatives, and there wasn't that much pressure to change.
  • +

    Security design: Why UAC will not work 14/01/2008 07:25:52

    Pinning all your end-point security hopes on UAC assumes that criminals are not as smart as they really are
    It's security's dirty little secret: Not having your users logged in as root or administrator will not stop malware.
  • +

    Entitlement management: Access control on steroids 04/12/2007 10:47:33

    Entitlement management tools bring fine-grained access control to another level
    Faced with looming regulations such as the Health Insurance Portability and Accountability Act and the Sarbanes-Oxley Act, Craig Shumard, chief information security officer for healthcare provider Cigna, knew he needed better tools for role-based access control.
  • +

    Federating identity for the Web 04/12/2007 11:20:10

    User-centric innovations CardSpace and OpenID may finally bring the promise of federation within reach
    Federated identity has long been a goal of many IT organizations. One look at the promise of federation, and it is easy to see why. After all, empowering one organization to serve as an identity provider for another frees IT from having to manage the identities of partnering organizations' employees and customers, thereby facilitating the pursuit of competitive-advantage projects. In this era of increasing enterprise decentralization, thanks in large part to the Web, establishing a federated identity framework is fast proving as essential as it is hard to pull off.
Interviews
  • +

    Data breaches remain a huge concern for '08 24/11/2007 10:07:19

    But Dean Turner, Director of Symantec's Global Intelligence Network, has some advice
    Dean Turner, Director of Symantec's Global Intelligence Network says data breaches and ID theft will continue dominate the threat landscape next year. He also outlines practical steps companies and consumers can take to protect themselves, in this interview with ITBusiness.ca editor, Joaquim P. Menezes.
Opinions
  • +

    Good security in recessionary times 20/10/2008 08:21:00

    A rough economy can be a good opportunity for your company to pay attention to the basics of IT security. Getting the essentials right today means your network can help your company succeed when the economy improves
    If you've had any money in the stock market, it's been a bloodbath the last few weeks. It's hard to remember that any 10-year period in stock market history has always ended up with better returns than any other investment. As financial analysts argue over whether we are already in or just headed into a deep global recession, we are facing a rough, contracting period. People with good jobs are holding on to them tighter than ever.
  • +

    Five lessons learned about computer security 16/07/2008 11:15:22

    How a hacker turned an illegal hobby into a useful career.
    Reformed hacker-turned-security-consultant Kevin Mitnick served five years in federal prison for breaking into phone and software company networks. He talks about his past hacking exploits, computer security, and how he turned an illegal hobby into a useful career.
  • +

    Forget your password? Use your eyes to open your computer, car or front door 05/12/2007 12:27:48

    Use your iris to unlock your PC, access secure buildings or open your door
    An Australian researcher is developing technology that would let you use your eyes - or more specifically your iris - to unlock your PC, access secure buildings or open your front door.
  • +

    Deploying NAC: Challenges and alternatives 31/07/2007 14:30:57

    What are some of the challenges in deploying NAC? What are the alternatives for LAN security?
Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
 
Sponsored Links