CIOs face more complexity than ever as an array of new technologies, from social media to cloud computing, open up new opportunities - and vulnerabilities. In ensuring that their businesses aren't exposed to new threats while charging into these new frontiers, IT security teams are essentially helping to enable emerging business models. Whether that means training employees on social media or pressuring cloud vendors to disclose their security practices, IT security will continue to evolve from its historic focus on protecting IT systems to playing a more entrepreneurial role in business. - Video Content....
As Microsoft pushes out two Patch Tuesday security updates for Windows and Office Excel, the company warns that attackers are targeting a vulnerability in Internet Explorer that can be used to hijack machines. - Microsoft issued a warning March
9 for Internet Explorer users as the company pushed out its monthly round of
patches to cover security holes in Windows and Microsoft Office Excel.
In an advisory, the company warned
that a new vulnerability was being targeted in attacks
against Internet Explore...
The Apple iPad is scheduled to hit U.S. stores April 3. Though a consumer device, it's a safe bet that like the iPhone and iPod before it, the iPad will make its way into the enterprise. Before it does, enterprises need to think about the security implications of yet another consumer device touching their networks. What security features should they ask for from Apple? What about protecting data accessed on the device? These questions and more should be on the minds of administrators planning ahead for the device, security pros say. At eWEEK, we have gathered ideas on what enterprises should consider regarding the iPad, and what should be on their Apple security wish list. - ...
Google Apps Premier and Education now offer limited security and policy controls over ActiveSync-enabled mobile devices, allowing companies using Gmail services to enforce a little bit of control over devices in the field. Policy controls are extremely limited and reporting capabilities are practically nil, but what's there works adequately and the price is right. - ...
At the RSA security conference, cloud security was top of mind for many, and none more so than the Cloud Security Alliance. Founded last year, the CSA is promoting best practices for securing cloud environments and educating users as to how the cloud can help secure other forms of computing. To that end, the CSA has a list of the seven biggest security hurdles for enterprises looking to adopt cloud technologies. Though not quite the seven deadly sins, any of these can send an enterprise to a purgatory of data breaches, notifications and lawsuits. Here is the CSA's list of the security challenges and what do to about them. - ...
A Trojan hidden within software for the Energizer Duo USB battery charger may have been around since May 2007, according to Symantec. The software, which affects Windows machines, has been taken off the market by Energizer. Fortunately, the Trojan can be fought with a few easy fixes. - The backdoor Trojan bundled with software
for the Energizer Duo USB battery charger may have been active for nearly
three years, security researchers have found.
According to Symantec's
analysis, there is evidence that the Trojan dates back to May 10, 2007.
quot;It's really impossible to say...
Companies that store credit card data expose themselves to a great deal of risk, whether they want to or not. If a risk assessment process is implemented, then the risks and exposures are identified. A plan can be put into place to help reduce or minimize a data breach attempt. As Knowledge Center contributor Mark Johnson explains here, to remove the risks associated with storing credit card data, companies are turning to trusted third parties who have demonstrated data security as a core competency. - Companies that follow best practices in data security have a risk assessment program. As outlined by the United States General Accounting Office (GAO), risk assessments quot;provide a basis for establishing appropriate policies and selecting cost-effective techniques to implement these policies. Si...
At the RSA conference in San Francisco, Trend Micro CTO Raimund Genes discusses the company's plans for building private clouds within public clouds. - For Trend Micro CTO Raimund Genes, talking about the cloud is nothing new. But now, things
are slightly different; instead of talking about Trend
Micro offering security services in the cloud, the company is examining the
concept of securing the cloud infrastructure that enterprises are expected ...
Cloud security was a key buzz phrase at this year's RSA conference in San Francisco this past week. But just what security concerns were top of mind - and how organizations should grade those risks - can be difficult to answer. - Most would agree cloud computing has become one of the catch phrases of this years RSA's conference in San Francisco.
The overall theme: Security may make or break cloud computing efforts as businesses look to balance the needs of regulations, access management and data protection with the busi...
SecureWorks researcher Joe Stewart revealed details of his research into a Russian botnet that has taken the unusual step of targeting Russian banks - a change from the typical focus on snaring victims in the West. The botnet also has a plug-in architecture that allows attackers to extend its abilities without writing new source code. - Like the sequel to a
successful movie, the botnet behind the distributed denial of service attacks
that hit the country
of
Georgia during its conflict with Russia in 2008 has been updated.
This time though, the idea
isnt hacktivism its stealing financial data and, unlike in the case of oth...