Data Security
News
- +
Facebook simplifies privacy settings, calls them too complex 02/07/2009 05:48:00
The social-networking site is also getting ready to let members share content with anyone on the InternetFacebook will simplify the way in which it offers privacy options to its users, as it gets ready to give its members for the first time the option to make the content they post on their profiles available to anyone on the Internet. - +
The Pirate Bay will let users delete accounts ahead of sale 02/07/2009 05:44:00
The planned sale of the torrent-tracking site has prompted users to worry about the security of their personal dataThe operators of The Pirate Bay will allow users to delete their accounts on the torrent-tracking site, a feature many users have requested since a deal to sell the site was announced Tuesday. - +
Internet cafe company offers $US7.8 million for The Pirate Bay 30/06/2009 22:40:00
Users cry foul, and label founders as sell-outsThe owners of The Pirate Bay have agreed to sell the site to a Swedish Internet cafe operator for 60 million Swedish kronor (US$7.8 million), the company said on Tuesday.Global Gaming Factory X (GGF) said it wants to find ways to pay content providers and copyright holders when their content is downloaded via The Pirate Bay, which tracks who is sharing files over the BitTorrent peer-to-peer service. - +
Blind phone hacker gets 11-year sentence 30/06/2009 08:24:00
Known as 'Little Hacker,' he'd use the 911 system to send SWAT teams to victims' housesA blind Boston-area teenager was sentenced to more than 11 years in prison Friday for hacking into the telephone network and harassing the Verizon investigator who was building a case against him. - +
Michael Jackson death spurs spam, viruses 27/06/2009 09:20:00
Michael Jackson spam and malware appeared minutes after news of his deathLess than 24 hours after Michael Jackson's death, fraudsters are exploiting public interest with their attempts to spread spam and malware. Security researchers say they've observed hundreds of cases of malicious messages masquerading as information about Jackson's death. Some of them, they say, popped up within minutes of the news. - +
Post-acquisition, MessageLabs harmonizes with Symantec 25/06/2009 04:21:00
Symantec is tapping MessageLabs' expertise in software as a service to develop more hosted productsSymantec has taken a relatively hands-off approach with its integration of hosted messaging provider MessageLabs since its acquisition of the company in November 2008, according to MessageLabs' former CEO. - +
EC proposes creation of centralized security data agency 25/06/2009 04:04:00
Passport, visa and fingerprint data are to be housed under one roof for startersThe European Commission took a big step toward creating an enhanced pan-European system of security and surveillance Wednesday when it launched a proposal to set up a new independent agency to manage massive IT systems used by border control authorities. - +
Dutch antipiracy organization takes aim at Pirate Bay 25/06/2009 04:34:00
The Pirate Bay founders were summoned using Facebook and TwitterThe Pirate Bay is the target of yet another legal case -- the Dutch antipiracy organization BREIN wants to close the file-sharing site in the Netherlands, and wants to see its founders appear in the Amsterdam district court on July 21, it said Tuesday. - +
Antivirus testing outfit: Windows Security Essentials makes the grade 25/06/2009 08:04:00
Rivals ding Microsoft's free antivirus software, but AV-Test.org says it's 'very good'Microsoft's free security software passed a preliminary antivirus exam with flying colors, an independent testing company said today. - +
Adobe issues update for Shockwave Player 25/06/2009 06:16:00
The patch fixes a vulnerability that is remotely exploitableAdobe Systems has released a patch for its Shockwave Player to fix a critical vulnerability, the company wrote on its security blog on Tuesday. - +
Fraudsters try to scam security expert on eBay 23/06/2009 03:23:00
The first buyer of his laptop used a hacked account, the second tried to trick him into sending it without paymentWhen security expert Bruce Schneier tried to sell a used laptop on eBay, he thought it would be easy. Instead, a sale was aborted twice -- first by a scammer using a hacked eBay account and then by a buyer who tried to trick Schneier into sending her the laptop after she cancelled payment. - +
Biometrics sweep NSW gaols 17/06/2009 14:56:00
Iris scanners, fingerprinting deployed in 32 prisonsThe NSW Department of Corrective Services will implement mandatory iris scanning and fingerprinting across its 32 prisons to help verify visitor identities. - +
Microsoft update removes rogue antivirus program 10/06/2009 04:12:00
Internet Antivirus Pro has been a growing problem since AprilMicrosoft has taken aim at a rogue antivirus program called Internet Antivirus Pro. - +
Poll: Companies still worried about open-source security 09/06/2009 09:37:00
But security concerns about SaaS are diminishing, according to a new Forrester studyBusinesses in North America and Europe remain broadly worried about the security of open-source software, according to new data from Forrester Research. - +
'Google-like' tool aids network security 04/06/2009 04:27:00
A Massachusetts startup's new tool turns network sessions into searchable XML documentsNetwork administrators and security specialists have long had tools and software for analyzing the streams of traffic that course through company systems, but now a Marlborough, Massachusetts, startup wants to make the process a lot easier.
Features
- +
New scam email uses Australian Federal Police to gain victims' trust 03/07/2009 10:49:00
Fake offers of free AFP monitoring service to stop "cybernetic attacks"Cyber criminals have changed tack in their ongoing scam campaign against banks, moving to the use of government agencies to gain the trust of unsuspecting email recipients. - +
AFP hits $6 million identity fraud syndicate 03/07/2009 08:25:00
$500,000 of goods per week purchased with fake credit cardsThe Australian Federal Police (AFP) claims to have struck a major blow to a multi-million identity fraud syndicate. - +
DR a growing concern for A/NZ CIOs: Symantec 02/07/2009 09:16:00
Mission critical apps and cost of down-time major driversCIOs in Australia and New Zealand are increasingly getting involved in the disaster recovery planning of their organisations, according to a new survey from Symantec. - +
Gov't official: We're serious about cybersecurity this time 02/07/2009 01:30:00
The nation is ready for new cybersecurity policies, a U.S. cybersecurity official saysThe U.S. White House is determined to follow through on its efforts to make cybersecurity a top priority, despite earlier government efforts that have fallen flat, a top official said Wednesday. - +
Seven deadly sins of social networking security 01/07/2009 03:05:00
To users of LinkedIn, Facebook, Myspace, Twitter or all of the above: Are you guilty of one of these security oversights?Admit it: You are currently addicted to social networking. Your drug of choice might be Facebook or Twitter, or maybe Myspace or LinkedIn. Some of you are using all of the above, and using them hard, even IT security practitioners who know better. - +
5 steps to secure a new PC 30/06/2009 00:19:00
Just unwrapped a brand-new PC? Security pros share their secrets for making your system Internet-safe.A common misconception is that a shiny new computer is more or less secure because it hasn't yet been exposed to the Internet's sinister underbelly. But the truth is, these machines come out of the box needing scores of patches, some basic security software downloads and the disabling or replacing of items security pros don't typically trust. - +
System security: how to improve your defenses against attack 30/06/2009 04:29:00
A former US Air Force CIO highlights practical ways to improve system and network securityGaining attention for advocating a practical shift in how IT leaders think about security, the Consensus Audit Guidelines offer 20 controls to measure and monitor IT-system and network security. Though worries about increased cost often accompany any notion of improving security, John Gilligan, a consultant who developed the guidelines, says he implemented a subset of the controls when he was the Air Force CIO (from 2001 to 2005) and saved money on IT and risk management. - +
Pirate Party finds France fertile territory 27/06/2009 01:26:00
Third copy of the hit party takes to the InternetSweden's Pirate Party won 7.13 percent of the vote in elections earlier this month. Its campaign for the respect of privacy, the reform of copyright law and the abolition of the patent system earned it a seat in the European Parliament, and it may yet gain another seat there, if planned changes to the number of seats attributed to each country win approval. - +
China remains spam haven due to 'bulletproof' hosting 27/06/2009 03:07:00
Chinese hosting companies and registrars sometimes ignore complaints, which perpetuates fraud and spamAn overwhelming majority of Web sites promoted through spam are hosted in China at service providers that many times choose to ignore complaints and allow illegal activity, according to research from the University of Alabama. - +
Top 10 reasons the firewall guy's hair is on fire 26/06/2009 23:58:00
The firewall is a mature technology, right? Then why do those who manage it feel like they're running a daycare overrun with little savages?Firewalls are a mature technology, right? Most companies have at least one, if not several. And since an established knowledge base exists to tap for issues and PCI DSS 1.1 and 1.2 are pretty clear cut, firewall management shouldn't be much of an issue, right? No one is going to suffer the brunt of managing the significant infrastructure change these regulations are bound to bring more than the security operations team, correct? - +
Online banking device reads information from a screen 26/06/2009 02:07:00
Card reader could relieve some of the frustration in completing online banking transactions in Germany, Gemalto saysAs German banks layer more security into their online banking procedures, security vendor Gemalto has launched a device it says makes completing transactions easier. - +
Reporters find Northrop Grumman data in Ghana market 25/06/2009 06:42:00
Data included contracts with TSA, NASA and Defense Intelligence AgencyA team of journalists investigating the global electronic waste business has unearthed a security problem too. In a Ghana market, they bought a computer hard drive containing sensitive documents belonging to U.S. government contractor Northrop Grumman. - +
Phoenix Freeze auto-locks laptops via smartphone 25/06/2009 00:17:00
A new product from Phoenix Technologies, called Freeze, lets you use BlackBerry or iPhone Bluetooth to tell a PC that you're leaving the area and want it to lock up. When you return, Phoenix Freeze can also automatically unlock the machine so it's ready for you. However, it only works on Windows PCs, doesn't support 64-bit platforms, disables all other Bluetooth peripherals and seems to be a bit buggy for an official release. Phoenix Freeze for BlackBerry and iPhone - +
Experts only: time to ditch the antivirus? 25/06/2009 06:50:00
It's definitely not the right move for the average computer user, but some security experts claim they have found better security by disabling the AV and relying on other controls and behaviors.To the average IT security practitioner, the idea of disabling antivirus on new machines might seem blasphemous. After all, weren't we all told in IT Security 101 that everyone needs AV to keep the malware and data thieves at bay? - +
Merchants struggle to comply with PCI security in economy 25/06/2009 23:58:00
With the recession drying up compliance budgets, merchants send PCI Security Standards Council General Manager Bob Russo a letter asking for help (includes audio).The heads of seven business organizations sent PCI Security Standards Council General Manager Bob Russo a cry for help earlier this month, saying the recession is making it "increasingly difficult" for merchants to meet the requirements of the Payment Card Industry's Data Security Standard (PCI DSS).
Case Studies
- +
Employment firm trains staff in compliance with network management kit 05/03/2008 12:03:13
Console keeps 350 Windows machines in checkEmployment and training firm CVGT has installed a network management toolkit to enforce compliance and protect the financial and personal data of its 40,000-plus apprentices and trainees. - +
Uni fortifies Western Front with IDS 22/02/2008 20:11:00
Nurtured NAC keeps malware outThe University of Western Sydney (UWS) has today gone live with a managed Intrusion Detection System (IDS) for its 5000 users.
Interviews
- +
Five Ways To Survive a Data Breach Investigation 16/04/2009 09:11:00
When the digital forensics crew comes in to investigate a possible data breach, company execs often make matters worse by not being prepared. Here are five ways to keep it from happening to youSecurity experts say it all the time: If a company thinks it has suffered a data security breach, the key to getting at the truth unscathed is to have a response plan in place for what needs to be done and who needs to be in charge of certain tasks. And, as SANS Institute instructor Lenny Zeltser advised in CSOonline's recent How to Respond to an Unexpected IT Security Incident article, "ask lots and lots of questions" before making rash decisions. - +
Four Questions On Google App Security 18/12/2008 12:27:00
Two members of Google's application security team explain why the future belongs in the computing cloud -- and how Google Apps is dealing with the constant barrage of security threatsTwo members of Google's application security team explain why the future belongs in the computing cloud -- and how Google Apps is dealing with the constant barrage of security threats. - +
CPO & CISO: A Comprehensive Approach to Information 04/12/2008 08:42:00
GE CPO Nuala O'Connor Kelly advocates greater CPO/CISO cooperation to place the right value on information assets.GE CPO Nuala O'Connor Kelly advocates greater CPO/CISO cooperation to place the right value on information assets. - +
Why Cybercrime is Thriving 27/11/2008 11:52:00
A new Symantec report reveals just how large and sophisticated the online underground economy has grownA new Symantec report reveals just how large and sophisticated the online underground economy has grown. - +
Chris Hoff on Virtualization and Cloud Computing 20/11/2008 10:55:00
Chris Hoff, chief security architect for the systems and technology division at Unisys and an advisor on the Skybox Security customer advisory board, is one of the biggest critics of virtualization security out there. Not because it isn't important - but rather because it is vital and needs to mature rapidly. - +
How IT Helped Catch the Jewellery Thief 13/11/2008 11:52:00
A jewellery store chain is having much better luck catching burglars in real time, thanks to a little help from the IT side of the house.A jewellery store chain is having much better luck catching burglars in real time, thanks to a little help from the IT side of the house. Loss Prevention Manager Dennis Thomas explains how the company built its high-tech command center from scratch. - +
Cisco CSO says security is growing up 07/08/2008 07:51:10
Interview: CSO John Stewart admits Cisco made mistakes in suing a researcher for exposing router flaws three years ago at Black HatJohn Stewart doesn't talk like your typical corporate executive. He said that his company, Cisco Systems, has been lucky when it comes to security and that his company's Self-Defending Network marketing push has painted "a big bull's-eye" on its products. - +
Cybercrime Convention will benefit Australia, says proponent 19/05/2008 09:36:30
Countries that have complied with the Convention have considerably strengthened their cybercrime legislation.The Convention on Cybercrime is the work of the Council of Europe and is aimed at facilitating international cooperation in the investigation and prosecution of computer crimes. Since the Convention came into being in 2001, the COE has been working to address the growing international concern over the threats posed by hacking and other computer-related crimes. - +
Head of PCI council sees security standard as solid 17/04/2008 10:40:46
GM Bob Russo defends payment card rules but acknowledges that 'interpretation issues' remainThe PCI Security Standards Council was established in the US by the major credit card companies in September 2006 as an independent organization to manage the Payment Card Industry Data Security Standard. In an interview, general manager Bob Russo talks about the council's efforts to administer the PCI standard amid continuing concerns about credit and debit card security. And he defends the standard, despite the recent data breaches at Hannaford Bros. and Okemo Mountain Resort.
Opinions
- +
Data Security: Whose Job Is It Really? 02/04/2009 08:35:00
Forrester believes CISOs must revisit the need to centrally control data security.Forrester believes CISOs must revisit the need to centrally control data security. - +
Avoiding Pitfalls in Log Management Planning 26/03/2009 10:25:00
Key considerations include scalability and references at comparable organizations, says ArcSight's Ansh Patnaik.Key considerations include scalability and references at comparable organizations, says ArcSight's Ansh Patnaik. - +
Good FUD Vs. Bad: Is There Really A Difference? 19/03/2009 09:12:00
A couple security bloggers suggest Bill Brenner spreads FUD in a column that's supposed to be anti-FUD. Why he agrees -- to a point.A couple security bloggers suggest Bill Brenner spreads FUD in a column that's supposed to be anti-FUD. Why he agrees -- to a point. - +
Effects of corporate social media on network security 13/03/2009 08:04:00
Organizations must raise awareness of safe data handling practices their usersIn today's increasingly communicative world, businesses face a dilemma. They have to find ways to be more engaging and communicate more directly to their customers and the public, while retaining close control of sensitive information. - +
Laid-off Workers as Data Thieves? 25/02/2009 08:28:00
A Symantec/Ponemon report points to an ominous byproduct of the economic crisis: laid-off employees stealing data in acts of vengeance. Bill Brenner is skeptical of this report's news value.A Symantec/Ponemon report points to an ominous byproduct of the economic crisis: laid-off employees stealing data in acts of vengeance. Bill Brenner is skeptical of this report's news value. - +
SOA What? Why You Need SOA Governance Framework 04/12/2008 08:32:00
Adopting services oriented architecture (SOA) in your enterprise without thinking through IT governance can cause something like the Gold Rush in the 1800s; extreme rates of growth and minimal law and order which produce unexpected outcomes. - +
Who Pushed Vendors Toward Better Security? 04/12/2008 09:38:00
Hint: It had something to do with pressure from customers and government agencies, writes Oracle CSO Mary Ann DavidsonHint: It had something to do with pressure from customers and government agencies, writes Oracle CSO Mary Ann Davidson. - +
Hard times mean more problems with insider security 05/11/2008 09:07:00
Given stressful situations, people are more likely to partake in risky activity, malicious, criminal or otherwise.Does my company need to be more proactive about insiders during hard times? - +
How to prevent cyber espionage 23/10/2008 12:06:00
Security expert Gadi Evron has plenty of experience helping governments fight cyber attacks. In this column, he offers a roadmap companies can use to prevent computer espionageSecurity expert Gadi Evron has plenty of experience helping governments fight cyber attacks. In this column, he offers a roadmap companies can use to prevent computer espionage. - +
How to minimize the impact of a data breach 01/10/2008 08:54:00
ID Experts' Rick Kam describes a customer-centric action planThirty-one percent of customers--nearly one-third of a company's client base and revenue source--are terminating their relationship with organizations following a data breach, according to a recent study by the Ponemon Institute. - +
Sarah Palin demonstrates the peril of webmail 18/09/2008 12:35:00
A hacked webmail account highlights the risk of trusting too much information to a service that may not be as secure as you.If you needed any more reminders about why it isn't a good idea to use external mail services to conduct critical business, the recent break-in to US Republican Vice-Presidential candidate Sarah Palin's gov.palin@yahoo.com Yahoo inbox should be it. Of note is that following the disclosure of the inboxes the compromised address and another address, gov.sarah@yahoo.com, have been suspended. - +
'Whaling' threats target the big fish of the corporate world 10/09/2008 14:50:00
Whaling has increasingly been in the news thanks to the ingenious ways a new breed of phishermen collect data to carry out scams and the move towards targeting business networking sites.The proliferation and popularity of collaborative Web 2.0 sites – there are around 250,000 new registrations to Facebook everyday – has changed the threat landscape and the way businesses need to think about security. Each year, newer technologies and weapons are being unleashed to leave Web users surprised, annoyed and at greater risk.‘Whaling’ or ‘spear phishing’, is one such threat and refers to phishing scams which specifically target high-worth individuals. - +
Information security governance: Centralized vs. distributed 05/09/2008 10:15:00
Should security policies, procedures and processes be managed within a central body, or distributed at an individual level? You need to find the middle ground.The management of information risk has become a significant topic for all organizations, small and large alike. But for the large, multi-divisional organization, it poses the additional challenge of determining how to deploy an information security governance program among what are often disparate business units. Should the policies, procedures, and processes that define the program be developed and managed within a central, corporate body? Or perhaps responsibility would be better placed at the individual unit level? Is there a workable middle-ground? - +
Security ROI: Fact or Fiction? 03/09/2008 08:32:00
Bruce Schneier says ROI is a big deal in business, but it's a misnomer in security. Make sure your financial calculations are based on good data and sound methodologies.Return on investment, or ROI, is a big deal in business. Any business venture needs to demonstrate a positive return on investment, and a good one at that, in order to be viable. - +
Information Security and the Importance of Context 01/09/2008 10:00:00
Those entrusted with information security must raise their contextual awarenessWhen the US Transportation Security Administration (TSA) was first created, it created a sudden need for tens of thousands of screeners. Getting a job as an airport screener was a pretty easy process. It seemed as though if you had a pulse, you were in. Jump forward to 2008 and becoming a screener is a bit harder as the TSA has instituted background checks, has upped the educational requirement to include a high school diploma or GED, and added other significant requirements.
Additional Resources
Market Place
CSO Online Member Login
Get real time traffic updates from Nokia’s Ovi Maps for mobile devices and for web 2009-07-03 10:34:00+10
Get real time traffic updates from Nokia’s Ovi Maps for mobile devices and for web 2009-07-03 10:34:00+10
2X Enhances Children’s IT Education Through Free Software Offer 2009-07-02 19:38:00+10
Fortinet Beefs Up Enterprise Security Management Capabilities 2009-07-02 15:42:00+10
Treasure your memories with new Lexar Media Full-HD Video Memory Cards 2009-07-01 19:00:00+10
Whitepaper
The business justification for data security
In the information security world we face two major types of threats: "noisy" threats which directly interfere with our ability to do business and "quiet" threats which cause real damage, but don't necessarily prevent people from doing their jobs. Read on to discover how to combat both types of threats and to justify the use of data security within your business.
Sponsored Links











