Cyber Security Risk: A Conversation with Richard Clarke about Threats to Enterprise Software
[ Source: Veracode ]
May 2012-
Join Richard Clarke, author and former White house advisor to the Bush and Clinton administrations as he discusses the changing cyber threat environment, the evolving cyber legislation landscape and their ramifications on your information security program. <br><br>
In a conversation with Veracode CTO, Chris Wysopal, Mr. Clarke will discuss: <br><br>
• How software vulnerabilities have become the leading cause of attacks against the private and public ...
Top 10 Mobile Application Risks
[ Source: Veracode ]
May 2012-
With the DroidDream malware discovery in March, and then Pandora's vulnerabilities identified in April, the inevitable happened: 2011 become the "year of mobile malware". All the pieces of the malware ecosystem puzzle that researchers have been warning about are falling into place. Modern mobile applications run on devices that have the functionality of a desktop or laptop running a general-purpose operating system. While many of the risks are similar to those of traditional spyware, ...
Five Steps to Managing Third-Party Application Security Risk
[ Source: Veracode ]
May 2012-
How secure is your 3rd party code? What are the major security vulnerabilities present in SDLC today? <br><br>
Can you trust that the code delivered to you was tested for security risks?
3rd-Parties are the Achilles' Heel in the Software Supply Chain. 40% of all software submitted at the request of large Enterprises is from third parties, but very little security testing is ever performed on this software. <br>&...
The Data is the New Perimeter
[ Source: Voltage Security ]
April 2012-
Most companies place a high premium on IT security, and believe they have ironclad protection. However, the toll from cyber-attacks continues to climb. That's because there are gaping vulnerabilities in the way defenses are deployed - firewalls, endpoint security and even protected storage can all be bypassed by attackers. Learn how a data-centric security approach can make data useless to data thieves.
Establishing a Data-Centric Approach to Encryption
[ Source: Voltage Security ]
April 2012-
Many data breaches occur at companies that already have a data security policy in place. What is the problem? Typically, intrusion detection and other technologies designed to keep intruders out of your system are built to protect against previously known hacking strategies. This approach exposes your IT systems to great risk as new methods of intrusion are constantly being devised. Learn how to protect corporate data with a data-centric encryption strategy.
Streamlining Info Protection through a Data-Centric Security Approach with Voltage SecureData
[ Source: Voltage Security ]
April 2012-
Compared to past approaches Voltage SecureData offers distinct advantages. In addition to the security advantages of FPE and tokenization, integration efforts are reduced to hours and days, instead of months or years as in the past. De-identification of data for testing or other purposes leverages the same data protection used in production. As a true enterprise platform, clients can start with simple applications and expand the use of Voltage SecureData across any number of applications ...
Forrester Report: Killing Data for Security and Risk Professionals
[ Source: Voltage Security ]
April 2012-
As cybercriminals have become more skillful and sophisticated, they have eroded the effectiveness of our traditional perimeter-based security controls. The constantly mutating threat landscape requires new defensive measures, one of which is the pervasive use of data encryption technologies. In the future, you will encrypt data - both in motion and at rest - by default. By encrypting, and thereby devaluing, your sensitive data, you can make cybercriminals bypass your networks and look for less ...
Splunk, Big Data and the Future of Security
[ Source: Splunk ]
April 2012-
Today's information security teams increasingly rely on security systems with big data capabilities. In order to seek out and detect today's complex advanced persistent threats you need to monitor network, host and application behavior across your organization's IT data. <br><br>
Read this white paper to understand the evolving security landscape and how advanced persistent threats and sophisticated malware have fundamentally changed the way security teams must think about these new ...
Privileged Password Sharing: The Root of All Evil
[ Source: Quest Software ]
April 2012-
Discover Safe and Secure Privileged Account Management <br><br>
With today's security and compliance concerns, effective management of privileged accounts is more important than ever. In this SANS white paper sponsored by Quest Software, gain a deeper understanding of all the risks involved with privileged account management - and how to mitigate them.
The Case for Security Information and Event Management (SIEM) in Proactive Network Defense
[ Source: Solarwinds ]
March 2012-
It's widely accepted that Security Information and Event Management (SIEM) systems are excellent tools for regulatory compliance, log management and analysis, trouble-shooting and forensic analysis. What's surprising to many is that this technology can play a significant role in actively defending your network.<br><br>
Download this white paper to learn about SIEM technology that:<br>
- detects and prevents blended threats<br>
- delivers effective, affordable ...