Data Security

News

AusCERT 2013: Visibility critical when selling IT security to execs, says Foxtel CSO

By David Braue | 24 May, 2013 11:20

Hard-to-find security skills and the rapid pace of malware evolution make a strong relationship with a managed security services (MSS) provider as important as maintaining the internal tools to keep business executives apprised of IT-security risk, Foxtel information security manager Kevin Shaw has advised.

AusCERT 2013: Big data skills help beat the bad guys, says HP

By Richard Chirgwin | 22 May, 2013 20:44

HP's Colin Henderson believes the security industry needs to become more adept at understanding the role of big data in security analysis, to try and stay ahead of an increasingly sophisticated and collaborative “black hat” world.

Banks must innovate around IT-security regulatory hurdles: NAB

By David Braue | 14 May, 2013 11:24

Budget and ROI requirements, tempered by increasingly tight privacy and regulatory controls, are forcing companies to consider new approaches to data-security protections, the head of IT security for the National Australia Bank (NAB) has advised.

Data separation ensures privacy, security in eBay's petabyte-scale data warehouse

By David Braue | 08 May, 2013 14:04

In running one of the largest data warehouses in the world, online retailer eBay has faced down some unique challenges in delivering big-data analytics capabilities – not the least of which is ensuring that its more than 6,000 business users and analysts are tightly managed to prevent data privacy and security compromises.

OAIC gets cracking on raising awareness of new privacy laws

By David Braue | 30 April, 2013 16:48

The Office of the Australian Information Commissioner (OAIC) has kicked off a targeted campaign to raise awareness on the new privacy laws before take effect next March.

Reviews

Review: Secure Flash Drives

By Ashton Mills | 13 September, 2012 09:00

USB flash drives are the modern floppy, albeit considerably larger and faster. They make our lives easy for taking data on the road, sharing with colleagues over sneakernet, and given their rapidly increasing size even acting as backup devices. They're also darn handy for installing software from ISO images.

Review : Clearswift SECURE Web Gateway 2.5

By Matt Hackling | 20 March, 2012 13:35 | 2 Comments

We were eager for this box to arrive from Clearswift, this kind of kit gets us excited. We were expecting a hardware appliance to be shipped to us, but when opened the box, all we found was a 1RU Dell Server.

USB Secure Flash Drive Product Review

By Enex Testlab | 24 August, 2011 12:04 | 3 Comments

A vast majority of today’s workforce use USB memory sticks, they offer unequalled convenience for transferring data. In most situations, if the data is not confidential, a standard USB stick quite acceptable, but what do you use if your data is sensitive?

The security suite guide 2010

By Frank J. Ohlhorst | 18 August, 2010 08:54

Just a few short years ago, all a PC needed for protection was a basic antivirus program to guard against any malware that arrived via an e-mail attachment, embedded in a shareware application or piggy-backed on a floppy disk.

Slideshows

AISA National Conference: In pictures

By Zennith Geisler | 11 November, 2011 10:39

- Amazon, Apple and Google know more about you than your doctor or lawyer - and Commbank is jealous as hell. - Don’t trust an organisation that doesn’t have a face - because then you can’t punch it in when they screw up, said Marcus Ranum. - 78 percent of the world’s population doesn’t have access to a computer or the internet and therefore avoid all IT security problems.

Destroying data to protect against fraud

By Neerav Bhatt | 18 October, 2011 07:39

Destroying data to protect against fraud.

USB devices: The big hole in network security

By Ellen Messmer | 24 August, 2011 12:42

Ponemon Institute asked 745 information-technology and security managers whether USB drives were important for business use, and if they were secure. What did the survey find?

Laptop losers hall of shame

By Carolyn Duffy Marsan | 26 May, 2008 10:40

The 10 worst security breaches of all time from unencrypted data.

20 useful IT security Web sites

By Jon Brodkin | 08 April, 2008 09:50

Bookmarking these sites will help you protect your network, comply with government regulations and stay ahead of all the latest threats.

Features

Secure USB Drives Not So Secure

By Joan Goodchild | 07 January, 2010 06:16

Several hardware-encrypted USB memory sticks are now part of a worldwide recall and require security updates because they contain a flaw which could allow hackers to easily gain access to the sensitive information contained on the device.

Is Compliance in the Cloud Possible?

By Jim Hietala | 07 January, 2010 06:47

There is no doubt that cloud computing is dominating today's IT conversation among C-level security executives. Whether it's due to the compelling cost saving possibilities in a tough economy, or because of perceived advantages in provisioning flexibility, auto-scaling, and on-demand computing, CSOs are probing the capabilities, costs and restrictions of the cloud. At the same time, security and compliance concerns are at the forefront of issues potentially holding large enterprises back from capitalizing on the benefits that cloud computing has to offer.

Best Practices For IT Availability

By Stephanie Balaouras | 17 December, 2009 04:40

Forrester often gets inquiries such as, "What requirements should we keep in mind while developing our disaster recovery plans and documents?" and, "Which strategies work best for managing our disaster recovery program once it's in place?"

A Practical Approach to Protecting Trade Secrets

By Russell Beck and Matt Karlyn | 12 November, 2009 05:22

Trade secrets are increasingly becoming a company's most valuable assets, and not surprisingly, threats to those assets have increased concomitantly. The greatest threat to company data is, of course, not outsiders but a company's own employees A company's ability to protect against rogue employees (as well as against unintentional harm) is governed by both federal and state laws, which vary by jurisdiction and, worse, are in a state of flux in many of those jurisdictions.

Facebook, Twitter provide sensitive info for criminals

By Tony Bradley | 28 August, 2009 06:48

Social networking services like Facebook and Twitter foster a false sense of security and lead users to share information which can be used by cybercriminals and social engineers. The very concept of social networking is based on connecting and sharing, but with who?

Tutorials

10 tech-management tips

By Julie Bort | 18 January, 2007 13:19

Ten simple tips to manage your enterprise technology.

Opinions

Three Facts of Data Security Legislation for the Cloud

By Puneet Kukreja | 19 December, 2012 12:49

Over the last 2-3 years cloud computing has promised, and in many instances delivered, a lower total cost of ownership. This has helped organisations return the focus of operation to their core activities—reducing the effort spent on managing IT infrastructure and applications.

Putting the 'A' in availability

By Matt Hackling | 28 November, 2012 13:49

After the debacle that has been Click Frenzy, I'm going to focus on availability. Click Frenzy was a coordinated advertising promotion with a large number of Australian online shopping websites. This sounded like a great idea, and many retailers paid good money to be part of it. The problem was that the click frenzy website struggled under the load and so did a few of the online retailers, resulting in a vicious backlash on social media.

Is anything private in Web 2.0?

By Olan Ahern | 23 November, 2012 10:17

The answer to this question is simple: no. With the developments in social media and two-way communication channels such as Twitter, Facebook and YouTube, it has made social privacy somewhat non-existent.

Exposing insider threats

By Stuart Meyers | 13 November, 2012 10:10 | 1 Comment

Insider threats — for example, data theft, intellectual property loss, privacy breaches and financial fraud — can be the most challenging IT risks for an organisation to address because they may or may not be happening. But if an insider threat occurs, it could no doubt hurt financially and/or publically. So how do you implement early detection to discover and expose these threats?

Security complexity threatens enterprises

By Gordon Makryllos | 23 April, 2012 16:35

Information security is one of the biggest challenges facing enterprises this year. Being hacked by criminals is becoming depressingly familiar for a many businesses. A roll call of prominent brands has succumbed to what is an unprecedented number of attacks. Increasing threats, regulations and complexity have catapulted network security up the corporate agenda. Considering billions are being spent on cyber security each year, why are businesses continuing to fall victim to cyber attacks?

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Webroot Web Security

Proactive web security that blocks threats in the cloud before they reach users’ machines, or enter customers’ networks.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.