Information Security Magazine April 2009

Information Security Magazine April 2009

Information Security
magazine, April issue


Download the entire April issue of Information Security magazine here in PDF format.

Here's a sneak peek at our April issue:

In this issue of Information Security, our cover story looks at data loss prevention, separating myths from the truths of real-world DLP deployments.

Expert Rich Mogull, founder of consultancy Securosis, examines how organizations in different industries are using data loss prevention technologies. He churns out eight lessons these users learned that you can use to avoid some common pitfalls and derive maximum value from this important, and often, misunderstood technology.

In another article this month, we look at a new take on log management and how it's no longer good enough to understand only what happened, but now you need to know who is involved in an incident in order to satisfy compliance mandates and shorten incident response cycles.

Finally, speaking of incident response, we have an in-depth look at a tabletop exercise conducted last October by the state of Delaware's Dept. of Technology and Information. This is the fourth such exercise conducted by the state agency, but the first to include a functional, hands-on component. Read on to see how they did.

TABLE OF CONTENTS

Features
Get Real: Data loss prevention benefits in the real world
Cover storyDLP promises strong data protection via content inspection and security monitoring, but real-world implementations can be complex and expensive.

Whodunnit?: Tying log management and identity management shortens incident response
Learn how compliance has mandated organizations determine not only when incidents occurred, but who is responsible for unauthorized access.

This is Only a Drill: Tabletop exercises sharpen security and business continuity
Learn how simulated cyberattacks and incident response exercises help organizations prevent future attacks and maintain business continuity.

Columns
No Free Lunch: Sell the business on virtualization security
Learn how virtualization can help you position security as a business enabler.

Embrace SaaS: You have no choice
Like it or not, software-as-a-service and cloud computing is the future.

Beefed-up Browsers Cannot Contend with Human Element
Hackers continue to bore holes in Web browsers, exploiting users with social engineering tricks to gain unauthorized access to systems and data.

This was first published in April 2009