• Login
  • Become a member
  • RSS
  • Part of the TechTarget network
SearchSecurity.com
  • News
    • Latest Headlines
      • Patch Tuesday September 2013: Critical bulletins for Office, SharePoint, IE
      • Damballa adds HTTP request profiling to its ATP platform
      • NYT cyberattack neatly sidestepped by big data
      • View All News
    • Featured
      • Information Security Magazine

        The information security pro’s resource for keeping corporate data, applications and devices secure

        Download Now!
  • Premium
    Editorial
    • E-Books
      • Technical guide to secure collaboration software
      • Technical guide on PCI: Global compliance trends
      • Technical guide to Web security gateways
      • View All E-Books
    • E-Zines
      • Information Security magazine
      • Information Security magazine archives
      • Information Security magazine subscription/renewal
      • Information Security magazine calendar
      • View All E-Zines
    • E-Handbooks
      • Developing your endpoint security management transition plan
      • Emerging threat detection techniques and products
      • Enterprise network security visibility: Beyond traditional defenses
      • View All E-Handbooks
  • Multimedia
      • Videos
      • Gary McGraw Silver Bullet Podcast
      • Screencasts
      • Webcasts
      • Podcasts
      • Slideshows
  • Security
    Topics
    • Topics
      • Enterprise Data Protection
      • Application and Platform Security
      • Enterprise Identity and Access Management
      • Government IT Security Management
      • Information Security Threats
      • Information Security Careers, Training and Certifications
      • Security Audit, Compliance and Standards
      • Security for the Channel
      • Enterprise Network Security
      • Information Security Management
    • Hot Topics
      • Security Management Strategies for the CIO
      • Security patch management and Windows Patch Tuesday news
      • PCI Data Security Standard
      • Disk Encryption and File Encryption
  • Tutorials
    • Advice & Tutorials
      • Security School Course Catalog from SearchSecurity.com
      • Information Security Learning Guides
      • Information security book excerpts and reviews
      • Wireless Security Lunchtime Learning with Lisa Phifer
      • Information security podcasts
      • Screencasts: On-screen demonstrations of security tools
      • View All Tutorials
    • Technology Dictionary
      • Find definitions and links to technical resources
      • Powered by WhatIs.com
  • Expert
    Advice
    • Tips
      • A decade later: SOX program management best practices
      • Using a next-gen firewall to determine application access policies
      • IT security frameworks and standards: Choosing the right one
      • View All Tips
    • Answers
      • The 2013 OWASP Top 10 list: What's changed and how to respond
      • Does Content-Agnostic Malware Protection improve Chrome security?
      • Do two-factor authentication vulnerabilities outweigh the benefits?
      • View All Answers
    • Ask a Question
      • Get help from our technical community
      • Powered By ITKnowledgeExchange.com
  • White
    Papers
    • Research Library
      • White Papers
      • Business Webcasts
      • Downloads
      • Powered by Bitpipe.com
    • Product Demos
      • Try out software demos
      • Powered By 2020Software.com
    • Resource Centers
      • View All Resource Centers
  • Blogs
    • Blogs
      • More Security Blogs
      • Security Corner with Ken Harthun
      • Security Wire Weekly
      • More Security Blogs
      • Powered By ITKnowledgeExchange.com
  • Certification
    Central
      • CISSP Practice Test
      • Earn CPE Credit
  • Home
  • Ask the Experts
  • Submit your questions about infosec threats

    Nick Lewis is standing by to give you free, unbiased advice on information security threats.

  • Submit your questions about IAM

    Randall Gamby is standing by to give you free, unbiased advice on identity and access management.

  • Submit your questions about application security

    Michael Cobb is standing by to give you free, unbiased advice on application security.

  • Meet All Experts

Submit a question to our experts

Expert Answers

  • How to destroy data on a hard drive to comply with HIPAA regulations

    Looking to destroy HIPAA data on a hard drive? Learn the best way to destroy a hard drive to comply with HIPAA regulations in this expert response from David Mortman.

  • Prevent meet-in-the-middle attacks with TDES encryption

    Don't let meet-in-the-middle attacks decrypt your sensitive data. Learn how to use the triple DES encryption algorithm to prevent such attacks, with expert Randall Gamby.

  • How to provide access to Web content (while ensuring network security)

    A reader asks expert Michael Cobb how healthcare organizations should allow Web access without compromising network security.

  • How to use single sign-on (SSO) for a server configuration

    Using SSO for a server configuration can be done a few different ways. Learn more in this expert response from Randall Gamby.

  • Technology to automate SOX compliance according to COBIT frameworks

    How effective are automated compliance solutions at easing a enterprise's compliance burden? In this expert response, learn what resources can be most helpful for your enterprise when complying wit...

  • Disaster recovery risk assessment for cyberterrorism attacks

    In recent days, the threat of cyberterrorism attacks seems to loom darker. In this expert response, learn whether cyberterrorism threats should be feared and how to prepare for them.

  • Choosing management for Active Directory user provisioning

    Who's in charge of Active Directory user provisioning at your organization? Learn how to choose the most effective user provisioning management method from expert Randall Gamby.

  • How to protect employee information in email paystubs

    Many companies are moving to a system of paperless paystubs. Learn how to protect the information contained in these email paystubs with the use of secure email in this expert response.

  • LDAP signing requirements for various directory configurations

    While there is no longer a standard directory configuration, it is still possible to implement LDAP signing in most environments. Learn more about LDAP signing requirements from IAM expert Randall ...

  • Can malware source code be used to stop a virus or worm?

    Source code is a valuable tool to stop malware, and it can make malicious code analysis more effective and successful.

  • Do Facebook URL security concerns justify blocking social networks?

    Michael Cobb explains why the privacy concerns with Facebook URLs are not a serious threat to the enterprise.

  • What is the best database patch management process?

    Michael Cobb reviews how to handle database patches in the enterprise.

  • How to secure USB ports on Windows machines

    A readers asks expert Michael Cobb about which product can best secure USB ports.

  • What is an encryption collision?

    Michael Cobb reviews how encryption collision attacks on cryptographic hash functions could compromise the security of all kinds of digital systems.

  • Should developers create libraries of common cryptographic algorithms?

    In this expert response, Michael Cobb explains why developers don't need to create their own cryptolibraries.

  • User account best practices for an investment management website

    When creating online user accounts for an investment management website, security is key. Learn user account best practices from IAM expert Randall Gamby.

  • How to determine password strength for a website

    Strong passwords are essential for an enterprise's online security, but how can you determine password strength? Learn more in this IAM expert response from Randall Gamby.

  • The pros and cons of implementing smart cards

    Most infosec pros agree that smart cards create a higher level of enterprise security than passwords alone. Learn how to weigh the pros and cons of smart cards to know if they're right for your ent...

  • Keep files from being deleted by assigning read and execute permission

    What's the best way to keep employees from deleting important files and folders? Learn more from IAM expert Randall Gamby.

  • Is credit card tokenization a better option than encryption?

    Platform security expert Michael Cobb reviews alternatives to encryption that will help protect sensitive data.

  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
More from Related TechTarget Sites
  • Cloud Security
  • Consumerization
  • Financial Security
  • SMB Security
  • Security AU
  • Security IN
  • Computer Weekly
  • Cloud Security
    • Echopass achieves PCI Level 1 certification; CISO offers PCI guidance

      On the heels of Echopass achieving PCI Level 1 certification, CISO Dennis Empey offers PCI guidance for other cloud providers navigating the process.

    • SearchCloudSecurity's Cloud computing security certification guide

      Certification expert Ed Tittel examines the growing number of cloud computing security certifications, both vendor-neutral and vendor-specific.

    • CSA exec: Cloud defense demands intelligent security strategy

      Video: Cloud Security Alliance COO John Howie discusses the 'intelligent security' strategy necessary for cloud providers to defeat targeted attacks.

  • Consumerization
    • Apple's free iWork suite provides alternative to Office for iOS

      Apple's free iWork is considered a Trojan horse, since it gives new iOS device users an office productivity suite ahead of Microsoft Office for iOS.

    • Consumer cloud services: Friend or foe?

      IT and workers alike can reap benefits from using the consumer cloud, but admins have to get past the concerns over data security first.

    • Notebooks or tablets: Which to choose for mobile workers

      A mobile workforce that uses the cloud needs their company to think about end-user segmentation to determine the best devices for their needs.

  • searchFinancialSecurity
    • PayPal CISO: Laws must foster better cybersecurity information sharing

      PayPal's Michael Barrett says many firms fear misuse of shared cybersecurity data. He also discusses the evolution of PCI DSS and mobile payment security.

    • Cybergang plans to use Trojan against U.S. banks

      A cybergang in Eastern Europe revealed plans to attack U.S. banks with a Gozi-like Trojan, according to RSA.

    • Improved Shylock Trojan targets banking users

      The latest variant of the banking Trojan is causing numerous problems, Symantec said.

  • searchMidmarketSecurity
    • Windows Phone 7 security: Assessing WP7 security features

      Windows Phone 7 security features are proving to be a mixed bag. Sam Cattle assesses the enterprise security pros and cons of the latest Windows mobile platform.

    • Choosing the best security certifications for your career

      Whether starting your career or planning your next step as an IT security professional, this tip will guide you toward the best certifications for your interests and experience.

    • Midmarket security tutorials

      SearchMidmarketSecurity.com’s tutorials offer IT professionals in-depth lessons and technical advice on the hottest topics in the midmarket IT security industry. Through our tutorials we seek to provide site members with the foundational knowledge needed to deal with the increasingly challenging job of keeping their organizations secure.

  • searchSecurityAU
    • NYT cyberattack neatly sidestepped by big data

      Big data analysis of IP addresses performed by OpenDNS kept some 50 million users from falling prey to the hijacking of The New York Times website.

    • How to assess cloud risk tolerance

      Assessing risk tolerance is a key part of a cloud risk management strategy. In this tip expert Ed Moyle explains how to assess cloud risk tolerance.

    • TPM security overview: Defining the benefits of TPM devices

      The nearly ubiquitous TPM device is an often-overlooked tool in an infosec pro's arsenal. Expert Michael Cobb details the benefits of TPM security.

  • Information Security
    • Android-based mobile malware rises – but what is the risk to Indian businesses?

      Mobile-dependent Indian businesses must secure networks against viruses as McAfee reports a large jump in Android-based malware

    • Dropbox can be hacked, say security researchers

      Security researchers say they bypassed the security of cloud-based storage service Dropbox and gained access to private user files

    • Android mobile malware rebounds in Q2, reports McAfee

      Android-based malware has grown 35% in the second quarter, according to the latest threat report from security firm McAfee

  • Computer Weekly
    • Cyber insurance: Understanding the legal language

      CIOs worried about cyber risk are increasingly turning to cyber insurance to offset risk. But is the cover as black and white as it first seems?

    • After virtualising IT estate, Jaguar Land Rover now eyes cloud computing

      Jaguar Land Rover's IT team takes its newly virtualised infrastructure to the next stage of IT evolution by adopting cloud-based services

    • Will the iPhone 5S’s fingerprint technology help enterprise security?

      A fingerprint sensor has been built into Apple's latest iPhones. Computer Weekly looks at what this means for enterprise security

All Rights Reserved,Copyright 2000 - 2013, TechTarget
  • About Us
  • Contact Us
  • Site Index
  • Privacy policy
  • Advertisers
  • Business partners
  • Events
  • Media kit
  • TechTarget Corporate site
  • Reprints
  • Archive
  • Site map