• Login
  • Become a member
  • RSS
  • Part of the TechTarget network
SearchSecurity.com
  • News
    • Latest Headlines
      • Case study: CDI launches aviation company DLP program on short runway
      • Sourcefire updates malware detection, malware analysis capabilities
      • DDoS attack trends highlight increasing sophistication, larger size
      • View All News
    • Featured
      • Information Security Magazine

        The information security pro’s resource for keeping corporate data, applications and devices secure

        Download Now!
  • Premium
    Editorial
    • E-Books
      • Technical guide to secure collaboration software
      • Technical guide on PCI: Global compliance trends
      • Technical guide to Web security gateways
      • View All E-Books
    • E-Zines
      • Information Security magazine
      • Information Security magazine archives
      • Information Security magazine subscription/renewal
      • Information Security magazine calendar
      • View All E-Zines
    • E-Handbooks
      • Network security best practices and essentials
      • Threat management: Devising a new strategy to tackle today's cyber attacks
      • Strategies for tackling BYOD: How to ensure mobile security
      • View All E-Handbooks
  • Multimedia
      • Videos
      • Podcasts
      • Screencasts
      • Webcasts
      • Slideshows
  • Security
    Topics
    • Topics
      • Enterprise Data Protection
      • Application and Platform Security
      • Enterprise Identity and Access Management
      • Government IT Security Management
      • Information Security Threats
      • Information Security Careers, Training and Certifications
      • Security Audit, Compliance and Standards
      • Security for the Channel
      • Enterprise Network Security
      • Information Security Management
    • Hot Topics
      • Security Management Strategies for the CIO
      • Security patch management and Windows Patch Tuesday news
      • PCI Data Security Standard
      • Disk Encryption and File Encryption
  • Tutorials
    • Advice & Tutorials
      • Security School Course Catalog from SearchSecurity.com
      • Information Security Learning Guides
      • Information security book excerpts and reviews
      • Wireless Security Lunchtime Learning with Lisa Phifer
      • Information security podcasts
      • Screencasts: On-screen demonstrations of security tools
      • View All Tutorials
    • Technology Dictionary
      • Find definitions and links to technical resources
      • Powered by WhatIs.com
  • Expert
    Advice
    • Tips
      • IT certification guide: Vendor-specific information security certifications
      • Introduction: Vendor-neutral security certifications for your career path
      • SearchSecurity.com's IT security certifications guide
      • View All Tips
    • Answers
      • Boosting information security budgets: How to get the funds you need
      • Open source security tools: Getting more out of an IT security budget
      • Goals for how to become a CISO if you're a security technologist
      • View All Answers
    • Ask a Question
      • Get help from our technical community
      • Powered By ITKnowledgeExchange.com
  • White
    Papers
    • Research Library
      • White Papers
      • Business Webcasts
      • Downloads
      • Powered by Bitpipe.com
    • Product Demos
      • Try out software demos
      • Powered By 2020Software.com
    • Resource Centers
      • View All Resource Centers
  • Blogs
    • Blogs
      • More Security Blogs
      • Security Corner with Ken Harthun
      • Security Wire Weekly
      • More Security Blogs
      • Powered By ITKnowledgeExchange.com
  • Certification
    Central
      • CISSP Practice Test
      • Earn CPE Credit
  • Home
  • Ask the Experts
  • Submit your questions about infosec threats

    Nick Lewis is standing by to give you free, unbiased advice on information security threats.

  • Submit your questions about IAM

    Randall Gamby is standing by to give you free, unbiased advice on identity and access management.

  • Submit your questions about application security

    Michael Cobb is standing by to give you free, unbiased advice on application security.

  • Meet All Experts

Submit a question to our experts

Expert Answers

  • Are BIOS attacks worth defending against?

    Expert Nick Lewis analyzes the risk of a BIOS attack in juxtaposition to the irritation and expense of securing a network against this threat.

  • Exploring Google Chrome Frame security

    Can legacy Web applications benefit from the Google Chrome Frame security and interoperability capabilities? Nick Lewis gives his take.

  • How to protect a website from malware redirects

    Malware redirects are a serious hazard in the jungle of infiltration exploits; Nick Lewis explains how they can be avoided.

  • RTP attacks: Prevent enterprise data exfiltration

    How big of an issue are RTP attacks in the context of all attacks via covert channels? Nick Lewis looks at tunneling for enterprise data exfiltration.

  • Thwarting Telnet security risks

    The inherently insecure Telnet protocol shouldn’t be used on modern networks. Learn why and what to use in its place.

  • Change default RDP port for virus protection?

    Using nonstandard ports for the RDP protocol blocks the Morto worm. But is changing port numbers a virus prevention best practice?

  • Is it possible to prevent DDoS attacks?

    A distributed denial-of-service (DDoS) attack can consume all your network bandwidth. Learn how to prevent a DDoS attack in this expert response.

  • SCIM identity management: Is outsourcing now viable?

    Randall Gamby outlines the SCIM identity management standard and offers identity management for those enterprises considering outsourcing.

  • Best practices for implementing dynamic authorization

    Randall Gamby discusses the advantages of dynamic authorization vs. other access management strategies and implementation best practices.

  • Time to consider image-based authentication?

    Randall Gamby addresses the criticisms of image-based authentication and considers if it's a viable enterprise alternative authentication method.

  • Can the cloud replace passwords?

    Expert Randall Gamby details key strategies for SaaS access management and contemporary single sign-on technology that's truly interoperable.

  • Can Android virtual patching thwart malware attacks?

    Application security expert Mike Cobb weighs the pros and cons of Android virtual patching to thwart Android malware attacks.

  • Explaining how trusted and forged SSL certificates work

    Web security relies on valid, trusted SSL certificates, but as Michael Cobb explains, forged SSL certificates undermine the model for trusted Web connections.

  • Software security lifecycle: Gaining executive support?

    Recent BSIMM3 study results provide guidelines for why executive support for the software security lifecycle is so important. Michael Cobb explains.

  • BIOS management best practices: Patches and Updates

    Amid growing concern over BIOS threats, expert Mike Cobb discusses how organizations should manage BIOS patches and BIOS updates.

  • Dangerous apps: Should enterprises ban IE, Adobe?

    CSIS says five dangerous applications are to blame for 99% of malware. Is it time to ban Internet Explorer, Flash and the others in the enterprise?

  • Enterprise user de-provisioning best practices

    Misplaced or stagnant employee access can be dangerous; Randall Gamby details user provisioning best practices for setting up a system to combat this risk.

  • How to manage information security legal issues

    Dealing with lawyers is often a challenge. Ernie Hayden offers advice for CISOs dealing with enterprise information security legal issues.

  • How to make an enterprise RBAC implementation easier

    Learn the benefits of role-based access control based on job functions of network accessing employees, and how to make an RBAC implementation easier.

  • Minimum password length best practices

    Should all enterprises mandate 14-character passwords, or are passwords alone not enough? IAM expert Randall Gamby offers his minimum password length best practices.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
More from Related TechTarget Sites
  • Cloud Security
  • Consumerization
  • Financial Security
  • SMB Security
  • Security AU
  • Security IN
  • Computer Weekly
  • Cloud Security
    • AWS FedRAMP certification fast-tracks Amazon cloud for U.S. government

      AWS becomes the biggest cloud provider to earn FedRAMP certification, easing the transition to AWS for U.S. government agencies.

    • For cloud backup and disaster recovery, bandwidth proves problematic

      When it comes to cloud backup and disaster recovery, organizations are holding back due to insufficient bandwidth and lengthy recovery times.

    • Can self-managed cloud security controls ease enterprise concerns?

      Expert Dave Shackleford details how enterprises can increasingly manage their own cloud security controls with private virtual cloud offerings.

  • Consumerization
    • What to look for in business cloud storage and file-sharing services

      Picking business cloud storage and file-sharing services is tough, but there are a lot of options to choose from, including on-premises services.

    • Citrix XenMobile combines MDM, MAM, file-sharing for mobile management

      Citrix users say the company's unified enterprise mobility management product, XenMobile, may make it easier to deliver business applications to on-the-go users.

    • Mobile adoption still lags behind vendor hype

      Mobility management is evolving by leaps and bounds, but some companies haven’t even put their mobile adoption plans in place.

  • searchFinancialSecurity
    • PayPal CISO: Laws must foster better cybersecurity information sharing

      PayPal's Michael Barrett says many firms fear misuse of shared cybersecurity data. He also discusses the evolution of PCI DSS and mobile payment security.

    • Cybergang plans to use Trojan against U.S. banks

      A cybergang in Eastern Europe revealed plans to attack U.S. banks with a Gozi-like Trojan, according to RSA.

    • Improved Shylock Trojan targets banking users

      The latest variant of the banking Trojan is causing numerous problems, Symantec said.

  • searchMidmarketSecurity
    • Windows Phone 7 security: Assessing WP7 security features

      Windows Phone 7 security features are proving to be a mixed bag. Sam Cattle assesses the enterprise security pros and cons of the latest Windows mobile platform.

    • Choosing the best security certifications for your career

      Whether starting your career or planning your next step as an IT security professional, this tip will guide you toward the best certifications for your interests and experience.

    • Midmarket security tutorials

      SearchMidmarketSecurity.com’s tutorials offer IT professionals in-depth lessons and technical advice on the hottest topics in the midmarket IT security industry. Through our tutorials we seek to provide site members with the foundational knowledge needed to deal with the increasingly challenging job of keeping their organizations secure.

  • searchSecurityAU
    • Exploit kits evolved: How to defend against the latest attack toolkits

      Expert Nick Lewis details how automated exploit kits are evolving and offers mitigations for the latest methods employed by these attack toolkits.

    • May 2013 Patch Tuesday fixes IE8 zero day; Adobe tightens ColdFusion

      The software giant's May 2013 Patch Tuesday update permanently fixes the IE8 zero-day flaw found in the Dept. of Labor website attack.

    • Can self-managed cloud security controls ease enterprise concerns?

      Expert Dave Shackleford details how enterprises can increasingly manage their own cloud security controls with private virtual cloud offerings.

  • Information Security
    • BYOD: Securing the risk to access the cost benefits

      Bring-your-own-device schemes offer businesses the opportunity to cut the costs and improve user experiences, but benefits can be dwarfed by the risks.

    • A CIO's five-point plan for managing endpoint security

      Niel Nickolaisen offers a five-point solution for managing endpoint security for the hyper-connected enterprise -- starting with data governance.

    • Microsoft offers 'fix' for latest Internet Explorer zero day

      Microsoft released a temporary fix to mitigate attacks using the most recent Internet Explorer 8 zero day vulnerability.

  • Computer Weekly
    • Government reveals failing projects

      Government has published a report detailing the status of 191 major projects worth £353bn, in which eight projects were red flagged

    • Bolton and Wigan get PSN in £47m outsourcing deal

      Bolton and Wigan councils have signed a seven-year £47m outsourcing contract, which will deliver a ‘PSN ready’ network to the region.

    • SAP’s Sikka takes innovation lead as SuccessFactors founder departs

      SAP has announced a leadership reshuffle in line with its agenda of in-memory database Hana, cloud and mobile. Sikka steps up, SuccessFactors’ Dalgaard steps down

All Rights Reserved,Copyright 2000 - 2013, TechTarget
  • About Us
  • Contact Us
  • Site Index
  • Privacy policy
  • Advertisers
  • Business partners
  • Events
  • Media kit
  • TechTarget Corporate site
  • Reprints
  • Archive
  • Site map