• Login
  • Become a member
  • RSS
  • Part of the TechTarget network
SearchSecurity.com
  • News
    • Latest Headlines
      • Sourcefire updates malware detection, malware analysis capabilities
      • DDoS attack trends highlight increasing sophistication, larger size
      • May 2013 Patch Tuesday fixes IE8 zero day; Adobe tightens ColdFusion
      • View All News
    • Featured
      • Information Security Magazine

        The information security pro’s resource for keeping corporate data, applications and devices secure

        Download Now!
  • Premium
    Editorial
    • E-Books
      • Technical guide to secure collaboration software
      • Technical guide on PCI: Global compliance trends
      • Technical guide to Web security gateways
      • View All E-Books
    • E-Zines
      • Information Security magazine
      • Information Security magazine archives
      • Information Security magazine subscription/renewal
      • Information Security magazine calendar
      • View All E-Zines
    • E-Handbooks
      • Network security best practices and essentials
      • Threat management: Devising a new strategy to tackle today's cyber attacks
      • Strategies for tackling BYOD: How to ensure mobile security
      • View All E-Handbooks
  • Multimedia
      • Videos
      • Podcasts
      • Screencasts
      • Webcasts
      • Slideshows
  • Security
    Topics
    • Topics
      • Enterprise Data Protection
      • Application and Platform Security
      • Enterprise Identity and Access Management
      • Government IT Security Management
      • Information Security Threats
      • Information Security Careers, Training and Certifications
      • Security Audit, Compliance and Standards
      • Security for the Channel
      • Enterprise Network Security
      • Information Security Management
    • Hot Topics
      • Security Management Strategies for the CIO
      • Security patch management and Windows Patch Tuesday news
      • PCI Data Security Standard
      • Disk Encryption and File Encryption
  • Tutorials
    • Advice & Tutorials
      • Security School Course Catalog from SearchSecurity.com
      • Information Security Learning Guides
      • Information security book excerpts and reviews
      • Wireless Security Lunchtime Learning with Lisa Phifer
      • Information security podcasts
      • Screencasts: On-screen demonstrations of security tools
      • View All Tutorials
    • Technology Dictionary
      • Find definitions and links to technical resources
      • Powered by WhatIs.com
  • Expert
    Advice
    • Tips
      • Using network flow analysis to improve network security visibility
      • Exploit kits evolved: How to defend against the latest attack toolkits
      • Five common Web application vulnerabilities and how to avoid them
      • View All Tips
    • Answers
      • Goals for how to become a CISO if you're a security technologist
      • Information Sharing and Analysis Centers: Getting started with ISACs
      • Using EMET to harden Windows XP and other legacy applications
      • View All Answers
    • Ask a Question
      • Get help from our technical community
      • Powered By ITKnowledgeExchange.com
  • White
    Papers
    • Research Library
      • White Papers
      • Business Webcasts
      • Downloads
      • Powered by Bitpipe.com
    • Product Demos
      • Try out software demos
      • Powered By 2020Software.com
    • Resource Centers
      • View All Resource Centers
  • Blogs
    • Blogs
      • More Security Blogs
      • Security Corner with Ken Harthun
      • Security Wire Weekly
      • More Security Blogs
      • Powered By ITKnowledgeExchange.com
  • Certification
    Central
      • CISSP Practice Test
      • Earn CPE Credit
  • Home
  • Ask the Experts
  • Submit your questions about infosec threats

    Nick Lewis is standing by to give you free, unbiased advice on information security threats.

  • Submit your questions about IAM

    Randall Gamby is standing by to give you free, unbiased advice on identity and access management.

  • Submit your questions about application security

    Michael Cobb is standing by to give you free, unbiased advice on application security.

  • Meet All Experts

Submit a question to our experts

Expert Answers

  • How a security technologist can become a CISO

    Security technologists aspiring to become CISOs must develop a variety of business skills, as Joe Granneman explains in this Ask the Expert Q&A.

  • What are the basic requirements to join an ISAC?

    Joe Granneman explains how ISACs enable cybersecurity information sharing and the basic requirements for joining an ISAC.

  • How to harden legacy applications with Microsoft's EMET

    Expert Michael Cobb details how using EMET, a free tool from Microsoft, can harden Windows XP and other legacy applications.

  • Analysis: How BlackBerry 10's password blacklist works

    Expert Michael Cobb reacts to the BlackBerry 10 password blacklist and determines whether enterprises could adopt it to further secure passwords.

  • Google Play Private Channel: Better than app stores?

    Is the Google Private Channel a more secure option than building an internal enterprise app store? Expert Michael Cobb discusses.

  • How to mitigate Adobe Shockwave Player security issues

    Expert Michael Cobb discusses Adobe Shockwave security issues highlighted by US-CERT, and details how a Web security gateway is one way to allay them.

  • Validating Web app security: Pen test or code review?

    For Web application security testing, if cash is tight, should a penetration test top an application code review? Michael Cobb explains his choice.

  • Virtual security gateways: Hype or necessity?

    Matthew Pascucci discusses virtual security gateway appliances and whether they are a virtual data center necessity or just an overhyped product.

  • Effects of the cloud on network security skills

    Will the ongoing adoption of cloud technology affect the skills that network security engineers need in the future? Matt Pascucci discusses.

  • Assessing the security of fiber optic networking

    Matthew Pascucci discusses the potential security risks associated with fiber optic networking.

  • Where to start when designing a secure network

    When designing a secure network segmentation, monitoring, logging and encryption should be a priority. Matt Pascucci explains in this expert Q&A.

  • What to do when agents email credit card numbers

    Emailing unencrypted credit card numbers is a violation of PCI DSS. Learn how to stop customer service agents from practicing this dangerous act.

  • How to address PCI compliance in the cloud

    Expert Mike Chapple offers advice on how to address PCI compliance when moving systems to the public cloud.

  • Criteria for evaluating PCI consultants

    PCI consultants can help organizations achieve PCI DSS compliance, but first you must choose the right one.

  • Social media compliance and security tips

    Expert Mike Chapple offers regulatory compliance advice regarding the management of enterprise social media accounts.

  • Compliance teams and the request for proposals process

    Procurement personnel should know when to include the compliance team in the request for proposals process.

  • Security controls for the Foreign Corrupt Practices Act

    Expert Mike Chapple explains the Foreign Corrupt Practices Act and the security controls required for compliance.

  • How to avoid disaster when devices are lost or stolen

    Mike Chapple explains how enterprises can help lessen the impact of lost or stolen devices as part of HIPAA compliance training.

  • How to stop DNS resolver abuse, DDoS amplification

    Expert Nick Lewis details how misconfigured DNS resolvers can be used for DDoS DNS attacks and how organizations can secure them.

  • Managing security vulnerabilities with compliance

    Should security vulnerabilities be prioritized based on compliance needs? Mike Chapple discusses this approach to vulnerability management.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
More from Related TechTarget Sites
  • Cloud Security
  • Consumerization
  • Financial Security
  • SMB Security
  • Security AU
  • Security IN
  • Computer Weekly
  • Cloud Security
    • Can self-managed cloud security controls ease enterprise concerns?

      Expert Dave Shackleford details how enterprises can increasingly manage their own cloud security controls with private virtual cloud offerings.

    • How to use PCI SSC supplement to achieve PCI compliance in the cloud

      Ed Moyle examines highlights of the recently released PCI SSC information supplement that offers new details on achieving PCI compliance in the cloud.

    • Cloud API security risks: How to assess cloud service provider APIs

      The CSA says cloud API security is a top threat to cloud environments. Expert Dave Shackleford explains how to assess the security of providers' APIs.

  • Consumerization
    • What's new with the BB10 OS, BES 10 and more

      If you're wondering what all of BlackBerry's new products do, such as the BB10 OS, Hub, Balance and BES 10, this FAQ should clear things up.

    • How limited mobile device support can help IT handle consumerization

      To deal with consumerization, some companies limit mobile device support to specific devices because it makes management and app development easier.

    • BlackBerry, VMware deliver dual persona features for mobile devices

      BlackBerry's Secure Work Space for iOS and Android will help heavily regulated companies or those searching for extra security to better support BYOD.

  • searchFinancialSecurity
    • PayPal CISO: Laws must foster better cybersecurity information sharing

      PayPal's Michael Barrett says many firms fear misuse of shared cybersecurity data. He also discusses the evolution of PCI DSS and mobile payment security.

    • Cybergang plans to use Trojan against U.S. banks

      A cybergang in Eastern Europe revealed plans to attack U.S. banks with a Gozi-like Trojan, according to RSA.

    • Improved Shylock Trojan targets banking users

      The latest variant of the banking Trojan is causing numerous problems, Symantec said.

  • searchMidmarketSecurity
    • Windows Phone 7 security: Assessing WP7 security features

      Windows Phone 7 security features are proving to be a mixed bag. Sam Cattle assesses the enterprise security pros and cons of the latest Windows mobile platform.

    • Choosing the best security certifications for your career

      Whether starting your career or planning your next step as an IT security professional, this tip will guide you toward the best certifications for your interests and experience.

    • Midmarket security tutorials

      SearchMidmarketSecurity.com’s tutorials offer IT professionals in-depth lessons and technical advice on the hottest topics in the midmarket IT security industry. Through our tutorials we seek to provide site members with the foundational knowledge needed to deal with the increasingly challenging job of keeping their organizations secure.

  • searchSecurityAU
    • Exploit kits evolved: How to defend against the latest attack toolkits

      Expert Nick Lewis details how automated exploit kits are evolving and offers mitigations for the latest methods employed by these attack toolkits.

    • May 2013 Patch Tuesday fixes IE8 zero day; Adobe tightens ColdFusion

      The software giant's May 2013 Patch Tuesday update permanently fixes the IE8 zero-day flaw found in the Dept. of Labor website attack.

    • Can self-managed cloud security controls ease enterprise concerns?

      Expert Dave Shackleford details how enterprises can increasingly manage their own cloud security controls with private virtual cloud offerings.

  • Information Security
    • BYOD: Securing the risk to access the cost benefits

      Bring-your-own-device schemes offer businesses the opportunity to cut the costs and improve user experiences, but benefits can be dwarfed by the risks.

    • A CIO's five-point plan for managing endpoint security

      Niel Nickolaisen offers a five-point solution for managing endpoint security for the hyper-connected enterprise -- starting with data governance.

    • Microsoft offers 'fix' for latest Internet Explorer zero day

      Microsoft released a temporary fix to mitigate attacks using the most recent Internet Explorer 8 zero day vulnerability.

  • Computer Weekly
    • Pearson integrates Google Enterprise and Office 365

      Publisher Pearson – which owns the Financial Times – uses cloud-based collaboration using Google and Microsoft products

    • What's on an enterprise's checklist when seeking a datacentre provider?

      Is it energy efficiency? Is low cost or low latency the deal maker? Top enterprises disclose their checklists for datacentre providers

    • How will Indian IT services firms evolve and prosper?

      Indian IT services firms need to reshape their businesses to continue growing as traditional markets and service offerings reach maturity

All Rights Reserved,Copyright 2000 - 2013, TechTarget
  • About Us
  • Contact Us
  • Site Index
  • Privacy policy
  • Advertisers
  • Business partners
  • Events
  • Media kit
  • TechTarget Corporate site
  • Reprints
  • Archive
  • Site map