Security: Regulations & Standards


Best Practices for Watching the Watchers

Four questions that promote security and regulatory compliance in your enterprise

Security: Don't Believe the (SAS 70) Hype

Confusion about the efficacy of SAS 70 seems to be more the rule than the exception. A new report suggests that a SAS 70 reality check is long overdue.

Q&A: Why Compliance is the Best Friend and Worst Enemy of Good Security

Compliance efforts will also affect the security of your data. We explore the connection and what IT can do to protect its information assets.

Removing the Risks of SSL -- Part 2 of 2

To address the security risks of SSL, we look at how transparent SSL proxies work and how they are used in enterprises today.

Removing the Risks of SSL -- Part 1 of 2

Despite its name, Secure Sockets Layer isn't totally secure. We explain the risks that arise from increased use of SSL within enterprise networks.

Report Profiles Top Software Security Coding Errors

Study lists oversights that can lead to denial-of-service attacks, data theft, or control of a system by hackers.

Q&A: Assessing Cybersecurity's Past, Planning for the Future

Where is cybersecurity headed? We look at how regulation, social networking, and popular technologies (such as cloud computing) will impact your enterprise’s security management.

Bridging Security Gaps to Prevent Data Breaches

Today’s cybercriminal is especially aggressive about penetrating networks to gain access to valuable data. We explain what steps you must take now to protect your systems.

Health-care Providers Racing to Comply with New Security Safeguards

Health-care providers are once again racing to ensure compliance with another set of information security safeguards.

Five Best Practices for Mitigating Insider Breaches

These five best practices will help you reduce the risk of internal data misuse and accidental data leakage.

Are Financial Industry Security Administrators Losing the War?

In the online banking segment, some industry watchers warn, the bad guys are winning the war against unsuspecting account holders.

Data Protection Guidelines for the Obama Administration

Although considerable sweat and tears have gone into data protection standards, it's time to spur discussion about how our data protection thinking and schemes might benefit from new ideas and technologies.

Spam Levels Continue to Surge, MessageLabs Reports

Spam levels surged in May, but technologies such as traffic and connection management helped reduce or rein-in the volume of malicious traffic.

Business Executives Don't Tie Disaster Recovery Efforts to Business Success, Study Reveals

There's a significant disconnect between IT and business executives when it comes to disaster recovery preparedness.

Q&A: Administrator Rights and Enhanced Security

Administrator rights let users do everything on a system, but these rights are also the target of malware and other vulnerabilities.

The Mainframe Security Paradox

Mainframe operators know which controls to implement, but auditors -- who frequently come from the distributed side of the divide -- don’t.

Overcoming Security Objections to a Virtual Infrastructure

Proper planning that includes addressing security will help you reap the benefits of virtualization and satisfy those who ensure business continuity and protect corporate data.

Enterprises Throw Out Wi-Fi Welcome Mat to Attackers, Study Finds

A recent report by AirTight Networks finds financial services firms are all but throwing out a welcome mat to wireless attacker

A Tempest in a Twitter

Unless you employ appropriate safeguards, a minor Twitter problem could easily turn into a tempest.

Data Security Trends: Staying Ahead of the Bad Guys

What you can do now to stay a step ahead of the changing vulnerability landscape.