-
Will a bootkit thwart the security of Windows 8 UEFI?
With the release of a proof-of-concept bootkit for the Windows 8 platform, expert Michael Cobb assesses the potential threat to UEFI security.
-
Making security preparations for Windows RT devices
How should enterprises prepare for securing Windows RT devices? Expert Michael Cobb discusses the security differences between Windows RT and 8.
-
Analysis: Danger posed by Apple UDID security leak
Expert Michael Cobb details Apple's Unique Device Identifiers, plus why iOS users should be concerned about the Anonymous UDID security leak.
-
Reexamine Windows password hints in security policies
Researchers have revealed potential Windows user password hint vulnerabilities. Expert Michael Cobb discusses how to address such attacks in policies.
-
How to choose an auditing firm
Expert Mike Chapple advises enterprises on how to choose an external auditor, focusing on four major qualities to look for in an auditing firm.
-
New MasterCard Level 2 merchant validation requirements
Expert Mike Chapple breaks down how Level 2 merchants can comply with MasterCard's new requirement for PCI self-assessments.
-
COBIT 5 training: What is required for certification?
Expert Mike Chapple offers advice for understanding COBIT and what it takes to acquire COBIT 5 certification.
-
Preparing for various DDoS attack scenarios
Expert Matthew Pascucci suggests four key questions to ask yourself when developing distributed denial-of-service attack mitigation tactics.
-
Firewall policy management for 5-tuple firewalls
Matt Pascucci explains how to implement firewall policy management for 5-tuple firewalls when ports must be kept open for business reasons.
-
Security risks of outsourcing network management
Is network management outsourcing the future of network security or too great a risk? Matthew Pascucci discusses the risks and rewards.
-
The insecure WEP protocol still widely used, but why?
Expert Matthew Pascucci weighs in on why so many enterprises still use the insecure wireless encryption protocols -- WPA and WEP.
-
Understanding 'big data' security issues
In this Ask the Expert video, Ernie Hayden answers the question of what 'big data' is and outlines big data security issues in this video.
-
Should enterprises worry about NFC security risks?
Security expert Nick Lewis explores the emerging security risks posed by NFC technology and discusses their effect on enterprise BYOD policy.
-
Video Ask the Expert: Why security conscience matters
Every firm needs a security conscience, according to expert Ernie Hayden, who says it is critical among key CISO responsibilities.
-
How to clean booter shells from compromised servers
Expert Nick Lewis discusses the importance of fully cleaning a compromised server and how to detect and remove booter shells and other remnants.
-
How to avoid the unseen danger of iFrame attacks
How can enterprises and users protect themselves from malicious content embedded in iFrames? Expert Nick Lewis explores iFrame attack mitigations.
-
How to defend against cache poisoning attacks via HTML5
Expert Nick Lewis explains how the HTML5 offline application cache exposes users to the threat of cache poisoning and provides mitigation options.
-
Performing APT detection amid hidden network traffic
Is it possible to detect APT attacks when malicious traffic is hidden? Expert Nick Lewis details how the Elirks backdoor connection hides APT traffic.
-
How to engage employees in compliance best practices
Mike Chapple offers four tips for improving employee collaboration and creativity with an enterprise's compliance program.
-
PCI compliance requirements for mobile payment networks
Mike Chapple discusses what the PCI compliance requirements might look like for mobile payment networks such as Merchant Customer Exchange (MCX).
-
Submit your questions about infosec threats
Nick Lewis is standing by to give you free, unbiased advice on information security threats.
-
Submit your questions about IAM
Randall Gamby is standing by to give you free, unbiased advice on identity and access management.
-
Submit your questions about application security
Michael Cobb is standing by to give you free, unbiased advice on application security.
Security Management Strategies for the CIO