• Login
  • Become a member
  • RSS
  • Part of the TechTarget network
SearchSecurity.com
  • News
    • Latest Headlines
      • Users may remain vulnerable despite Oracle Java patch release
      • Enterprise BYOD offers mixed bag for enterprise endpoint security
      • CEO: Symantec strategy to emphasize endpoint security, partnerships
      • View All News
    • Featured
      • Information Security Magazine

        The information security pro’s resource for keeping corporate data, applications and devices secure

        Download Now!
  • Premium
    Editorial
    • E-Books
      • Technical guide to secure collaboration software
      • Technical guide on PCI: Global compliance trends
      • Technical guide to Web security gateways
      • View All E-Books
    • E-Zines
      • Information Security magazine
      • Information Security magazine archives
      • Information Security magazine subscription/renewal
      • Information Security magazine calendar
      • View All E-Zines
    • E-Handbooks
      • Enterprise network security visibility: Beyond traditional defenses
      • Network security best practices and essentials
      • Threat management: Devising a new strategy to tackle today's cyber attacks
      • View All E-Handbooks
  • Multimedia
      • Videos
      • Gary McGraw Silver Bullet Podcast
      • Screencasts
      • Webcasts
      • Podcasts
      • Slideshows
  • Security
    Topics
    • Topics
      • Enterprise Data Protection
      • Application and Platform Security
      • Enterprise Identity and Access Management
      • Government IT Security Management
      • Information Security Threats
      • Information Security Careers, Training and Certifications
      • Security Audit, Compliance and Standards
      • Security for the Channel
      • Enterprise Network Security
      • Information Security Management
    • Hot Topics
      • Security Management Strategies for the CIO
      • Security patch management and Windows Patch Tuesday news
      • PCI Data Security Standard
      • Disk Encryption and File Encryption
  • Tutorials
    • Advice & Tutorials
      • Security School Course Catalog from SearchSecurity.com
      • Information Security Learning Guides
      • Information security book excerpts and reviews
      • Wireless Security Lunchtime Learning with Lisa Phifer
      • Information security podcasts
      • Screencasts: On-screen demonstrations of security tools
      • View All Tutorials
    • Technology Dictionary
      • Find definitions and links to technical resources
      • Powered by WhatIs.com
  • Expert
    Advice
    • Tips
      • PCI e-commerce compliance guidelines for third-party payment processors
      • How key MDM features affect mobile security policy management
      • Intro to two-factor authentication in Web authentication scenarios
      • View All Tips
    • Answers
      • Reframing discussions about return on security investment
      • The effects of secure application development practices
      • IT security risk training for executives: How to get started
      • View All Answers
    • Ask a Question
      • Get help from our technical community
      • Powered By ITKnowledgeExchange.com
  • White
    Papers
    • Research Library
      • White Papers
      • Business Webcasts
      • Downloads
      • Powered by Bitpipe.com
    • Product Demos
      • Try out software demos
      • Powered By 2020Software.com
    • Resource Centers
      • View All Resource Centers
  • Blogs
    • Blogs
      • More Security Blogs
      • Security Corner with Ken Harthun
      • Security Wire Weekly
      • More Security Blogs
      • Powered By ITKnowledgeExchange.com
  • Certification
    Central
      • CISSP Practice Test
      • Earn CPE Credit
  • Home
  • Ask the Experts
  • Submit your questions about infosec threats

    Nick Lewis is standing by to give you free, unbiased advice on information security threats.

  • Submit your questions about IAM

    Randall Gamby is standing by to give you free, unbiased advice on identity and access management.

  • Submit your questions about application security

    Michael Cobb is standing by to give you free, unbiased advice on application security.

  • Meet All Experts

Submit a question to our experts

Expert Answers

  • Will a bootkit thwart the security of Windows 8 UEFI?

    With the release of a proof-of-concept bootkit for the Windows 8 platform, expert Michael Cobb assesses the potential threat to UEFI security.

  • Making security preparations for Windows RT devices

    How should enterprises prepare for securing Windows RT devices? Expert Michael Cobb discusses the security differences between Windows RT and 8.

  • Analysis: Danger posed by Apple UDID security leak

    Expert Michael Cobb details Apple's Unique Device Identifiers, plus why iOS users should be concerned about the Anonymous UDID security leak.

  • Reexamine Windows password hints in security policies

    Researchers have revealed potential Windows user password hint vulnerabilities. Expert Michael Cobb discusses how to address such attacks in policies.

  • How to choose an auditing firm

    Expert Mike Chapple advises enterprises on how to choose an external auditor, focusing on four major qualities to look for in an auditing firm.

  • New MasterCard Level 2 merchant validation requirements

    Expert Mike Chapple breaks down how Level 2 merchants can comply with MasterCard's new requirement for PCI self-assessments.

  • COBIT 5 training: What is required for certification?

    Expert Mike Chapple offers advice for understanding COBIT and what it takes to acquire COBIT 5 certification.

  • Preparing for various DDoS attack scenarios

    Expert Matthew Pascucci suggests four key questions to ask yourself when developing distributed denial-of-service attack mitigation tactics.

  • Firewall policy management for 5-tuple firewalls

    Matt Pascucci explains how to implement firewall policy management for 5-tuple firewalls when ports must be kept open for business reasons.

  • Security risks of outsourcing network management

    Is network management outsourcing the future of network security or too great a risk? Matthew Pascucci discusses the risks and rewards.

  • The insecure WEP protocol still widely used, but why?

    Expert Matthew Pascucci weighs in on why so many enterprises still use the insecure wireless encryption protocols -- WPA and WEP.

  • Understanding 'big data' security issues

    In this Ask the Expert video, Ernie Hayden answers the question of what 'big data' is and outlines big data security issues in this video.

  • Should enterprises worry about NFC security risks?

    Security expert Nick Lewis explores the emerging security risks posed by NFC technology and discusses their effect on enterprise BYOD policy.

  • Video Ask the Expert: Why security conscience matters

    Every firm needs a security conscience, according to expert Ernie Hayden, who says it is critical among key CISO responsibilities.

  • How to clean booter shells from compromised servers

    Expert Nick Lewis discusses the importance of fully cleaning a compromised server and how to detect and remove booter shells and other remnants.

  • How to avoid the unseen danger of iFrame attacks

    How can enterprises and users protect themselves from malicious content embedded in iFrames? Expert Nick Lewis explores iFrame attack mitigations.

  • How to defend against cache poisoning attacks via HTML5

    Expert Nick Lewis explains how the HTML5 offline application cache exposes users to the threat of cache poisoning and provides mitigation options.

  • Performing APT detection amid hidden network traffic

    Is it possible to detect APT attacks when malicious traffic is hidden? Expert Nick Lewis details how the Elirks backdoor connection hides APT traffic.

  • How to engage employees in compliance best practices

    Mike Chapple offers four tips for improving employee collaboration and creativity with an enterprise's compliance program.

  • PCI compliance requirements for mobile payment networks

    Mike Chapple discusses what the PCI compliance requirements might look like for mobile payment networks such as Merchant Customer Exchange (MCX).

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
More from Related TechTarget Sites
  • Cloud Security
  • Consumerization
  • Financial Security
  • SMB Security
  • Security AU
  • Security IN
  • Computer Weekly
  • Cloud Security
    • Gartner: Negotiate cloud contracts with detailed security, control

      When negotiating with cloud providers, enterprises must demand cloud contracts with specific security and control provisions, Gartner analysts say.

    • Cloud data breach notification: Defining legal obligations

      Francoise Gilbert provides a cloud data breach notification overview for enterprises concerned about placing personal information in the cloud.

    • Are FedRAMP security controls enough?

      Cloud service providers are working with authorized third-party auditors to meet FedRAMP security controls. The 3PAOs tell us how it’s going, so far.

  • Consumerization
    • How to choose the right enterprise mobile, cloud and social tools

      IT departments need to evaluate vendors for social tools, such as mobile and cloud. Without a secure plan, IT risks an unsecure liability.

    • Office Mobile for iPhone requires Office 365

      Microsoft released Office Mobile for iPhone but it requires an Office 365 subscription and isn't made for iPad.

    • NSA surveillance leads to tighter data privacy policies

      Knowledge of the National Security Agency's surveillance has led some companies to revamp their data privacy policies.

  • searchFinancialSecurity
    • PayPal CISO: Laws must foster better cybersecurity information sharing

      PayPal's Michael Barrett says many firms fear misuse of shared cybersecurity data. He also discusses the evolution of PCI DSS and mobile payment security.

    • Cybergang plans to use Trojan against U.S. banks

      A cybergang in Eastern Europe revealed plans to attack U.S. banks with a Gozi-like Trojan, according to RSA.

    • Improved Shylock Trojan targets banking users

      The latest variant of the banking Trojan is causing numerous problems, Symantec said.

  • searchMidmarketSecurity
    • Windows Phone 7 security: Assessing WP7 security features

      Windows Phone 7 security features are proving to be a mixed bag. Sam Cattle assesses the enterprise security pros and cons of the latest Windows mobile platform.

    • Choosing the best security certifications for your career

      Whether starting your career or planning your next step as an IT security professional, this tip will guide you toward the best certifications for your interests and experience.

    • Midmarket security tutorials

      SearchMidmarketSecurity.com’s tutorials offer IT professionals in-depth lessons and technical advice on the hottest topics in the midmarket IT security industry. Through our tutorials we seek to provide site members with the foundational knowledge needed to deal with the increasingly challenging job of keeping their organizations secure.

  • searchSecurityAU
    • Exploit kits evolved: How to defend against the latest attack toolkits

      Expert Nick Lewis details how automated exploit kits are evolving and offers mitigations for the latest methods employed by these attack toolkits.

    • May 2013 Patch Tuesday fixes IE8 zero day; Adobe tightens ColdFusion

      The software giant's May 2013 Patch Tuesday update permanently fixes the IE8 zero-day flaw found in the Dept. of Labor website attack.

    • Can self-managed cloud security controls ease enterprise concerns?

      Expert Dave Shackleford details how enterprises can increasingly manage their own cloud security controls with private virtual cloud offerings.

  • Information Security
    • Security tech market set to grow 8.7% in 2013, says Gartner

      The worldwide security technology and services market will reach $67.2bn in 2013, up 8.7% from 2012, according to research firm Gartner

    • A malicious charger could hack Apple devices easily, claim researchers

      A modified phone charger or battery could be used to hack Apple devices, say researchers from Georgia Tech

    • How to reduce IT security risk with IT asset management

      IT asset management expert Barb Rembiesa explains how ITAM best practices like IT asset standardization and rationalization reduce IT security risk.

  • Computer Weekly
    • BT CEO Ian Livingston quits to become government minister

      BT chief executive Ian Livingston is leaving the telecoms giant in September to become a government minister

    • Virtualisation and the LUN: Storage configuration for VMs

      Virtualisation and the LUN: Storage admins used to match LUNs to physical servers, but that’s all changed. Find out how in this guide to the basics of VM storage

    • G8 publishes Open Data Charter

      The G8 nations have committed to open data, with a promise to produce action plans for the release of government information

All Rights Reserved,Copyright 2000 - 2013, TechTarget
  • About Us
  • Contact Us
  • Site Index
  • Privacy policy
  • Advertisers
  • Business partners
  • Events
  • Media kit
  • TechTarget Corporate site
  • Reprints
  • Archive
  • Site map