Application Security — Features

NEWS FOCUS: Cyber-espionage attacks threaten corporate data in new unrelenting ways

By Ellen Messmer | 08 August, 2011 20:26

Stealthy, sometime long-term cyber-espionage attacks to steal sensitive proprietary information -- what some now call "advanced persistent threats" (APT) -- have become a top worry for businesses.

NEWS FEATURE: Debate rages over how to manage personal mobile devices used for work

By Ellen Messmer | 28 July, 2011 06:47

Increasingly, businesses accept the idea that employees should be able to use their personal mobile devices, such as smartphones and tablets, for work. But debate is raging as to whether these employee-owned devices should be managed and secured exactly as corporate-owned devices might be.

5 open source security projects to watch

By Rodney Gedda | 20 January, 2011 11:23 | 1 Comment

Data security is always top of mind for CIOs and CSOs, and there is no shortage of challenges when it comes to picking the right tool for the job. With network and software vulnerabilities growing at a perpetual rate, good security software can help defend against many of the large-scale threats that occur locally and from all over the Internet. In this edition of 5 open source things to watch, we take a look at security products that will guard against threats without robbing your kitty.

5 'Great' Open-source Desktop Security Applications

By Joseph Guarino | 01 April, 2010 05:12

Contributions from free and open software makers can be found throughout the tech world. From your datacenter to the desktop and everywhere in between; there's an open solution to your computing needs. This is no less true in information security. My focus in this article is the several outstanding information security desktop tools that personify the innovation and ingenuity of the FOSS (Free and Open Source Software) world. Please keep in mind that all of these applications (except one) are cross-platform so you can find appropriate versions on whatever you run (BSD, Mac OSX, Linux or Windows). The examples herein, however, will be catered to the largest install base (statistically): Microsoft Windows.

Windows 7 Tips: Best Security Features

By Shane O'Neill | 04 February, 2010 04:52

For both enterprises and consumers, one of the big draws of Windows 7 has been its tighter security features.

Cloud Security: Ten Questions to Ask Before You Jump In

By Tim Brown | 28 January, 2010 07:08

The hype around cloud computing would make you think mass adoption will happen tomorrow. But recent studies by a number of sources have shown that security is the biggest barrier to cloud adoption. The reality is cloud computing is simply another step in technology evolution following the path of mainframe, client server and Web applications, all of which had -- and still have -- their own security issues.

Why traditional security doesn't work for SOA

By Chris Clark | 19 January, 2010 07:38 | 1 Comment

Many organizations are embracing SOA as a way to increase application flexibility, make integration more manageable, lower development costs, and better align technology systems to business processes. The appeal of SOA is that it divides an organization's IT infrastructure into services, each of which implements a business process consumable by users and services.

Plumbers' Co-operative filters out spam deluge

By Rodney Gedda | 26 November, 2009 11:09 | 1 Comment

With spam hampering staff productivity and increasing helpdesk calls, Sydney-based plumbing suppliers company Plumbers' Supplies Co-operative Ltd has replaced an open source e-mail security solution with an network gateway appliance.

Facebook Tips: Staying Safe While Using Games and Apps

By Kristin Burnham | 13 November, 2009 10:34 | 5 Comments

If you're one of the 63.7 million people playing the popular Farmville game on Facebook, you've probably noticed a change in how you earn points. FarmVille's parent company, Zynga, agreed last week to remove deceiving mobile subscriptions and "scammy" offers that lure players to register for services in exchange for game currency, which helps players to advance in the game.

Researchers advise cyber self defense in the cloud

By Dan Nystedt | 12 October, 2009 21:16

Security researchers are warning that Web-based applications are increasing the risk of identity theft or losing personal data more than ever before.

Careless downloading makes BlackBerry users spy targets

By Dan Nystedt | 08 October, 2009 01:15

IPhone lovers and other smartphone users should take heed: A security researcher showed ways to spy on a BlackBerry user during a presentation Wednesday, including listening to phone conversations, stealing contact lists, reading text messages, taking and viewing photos and figuring out the handset's location via GPS.

Windows attack code out, but not being used

By Robert McMillan | 07 October, 2009 07:21

It has been a week since hackers released software that could be used to attack a flaw in Windows Vista and Server 2008, but Microsoft and security companies say that criminals haven't done much with the attack.

Cloud security: time to smoke another one?

By Bill Brenner | 01 September, 2009 04:19

Chris Hoff, one of the most respected voices on the topic of virtualization and cloud security, once told me in an interview that people should shut up about securing the cloud because, in his opinion, there's no such thing as cloud security.

Five lessons from Microsoft on cloud security

By Robert Lemos | 26 August, 2009 05:00

While Google, Amazon and Salesforce have gotten the most attention as cloud service providers, Microsoft-with its 300 products and services delivered from its data centers-has a large cloud bank all its own.

Cloud hype peaks, but IT concerns increase

By Thomas Wailgum | 27 August, 2009 06:51

Apparently the everpresent cloud computing marketing messages aren't working quite well enough: Tech buyers still have major concerns regarding cloud-based benefits and security issues, many of which have not eased during the past year.

CIO and CSO should take a follow the money approach to security: IBM X-Force

By Tim Lohman | 27 August, 2009 10:15

CIOs and CSOs could do well to consider the monetisation cost and overall profitability of security risks when considering how to safe guard their organisations, according to the findings of a new report from IBM’s Internet Security Systems X-Force research and development team.

Is your PC bot-infested? here's how to tell

By Robert Vamosi | 25 August, 2009 02:32

As fireworks boomed on the Fourth of July, thousands of compromised computers attacked U.S. government Web sites. A botnet of more than 200,000 computers, infected with a strain of 2004's MyDoom virus, attempted to deny legitimate access to sites such as those of the Federal Trade Commission and the White House. The assault was a bold reminder that botnets continue to be a massive problem.

Survey: Facebook, Twitter banned by most employers

By Joan Goodchild | 20 August, 2009 03:33

Employers are increasingly putting the brakes on employee use of social networking sites on the job, according to a new survey. The research, released Wednesday by ScanSafe, a provider of SaaS Web security, said its data shows more employers are blocking sites such as Facebook and Twitter. The results run counter to a story published by CSO in March 2009 that cites research which found most employers do allow access to Web 2.0 in the office.

SOA security: good enough and getting better

By Randy Heffner | 20 August, 2009 05:35

Security is not a reason to stay away from SOA. Although full SOA security maturity is yet to come, 30 percent of organizations now use SOA for external integration with customers and partners. For standard Web services using SOAP, WS-Security has achieved critical mass as a foundational standard. On the other hand, advanced SOA security - involving federation among partners, nonrepudiation, and propagation of user identities across multiple layers of service implementations - is in its early days.

5 lessons from dark side of cloud computing

By Robert Lemos | 07 August, 2009 05:28

While many companies are considering moving applications to the cloud, the security of the third-party services still leaves much to be desired, security experts warned attendees at last week's Black Hat Security Conference.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

NetIQ iSeries Security

The NetIQ iSeries Security Solutions helps you eliminate security risks and maintain business continuity

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.