Access "Poor development practices lead to continued security problems"
This article is part of the November 2008 issue of Security researchers on biometrics, insider threats, encryption and virtualization
How is it that in spite of all the work we've done, all the research we've performed, all the best practices we've developed, all the clever technology we've created and all the awareness we've raised, important systems vital to daily life are still suffering fatal security failures? A researcher recently announced that SCADA systems actually are pretty easy to hack, and it would be a bad idea to connect them to the Internet. Well, this doesn't come as any news. We've also learned that an access control technology used for the London transport fare card system is vulnerable to attack. Equally unsurprising, a July research report from a group at UC Santa Barbara describes multiple concerns about the integrity of voting machines from two different manufacturers. According to the group's carefully reasoned document, "knowledge of basic security concepts, their application, and defensive programming practices should be prerequisites for the developers of critical systems such as an electronic voting system." This idea undoubtedly seems like common sense to ... Access >>>
Premium Content for Free.
Diverse mobile devices changing security paradigm
Enterprises must develop more creative strategies for enabling business use of smartphones and PDAs, including those that cannot be fully managed and secured.
Layoffs, Mergers Put Focus on Data Protection
As banks fold, or are acquired, companies need to be vigilant about access controls and provisioning.
Host-based intrusion prevention addresses server, desktop security
HIPS is used for everything from traditional signature-based antivirus/antispyware and host firewalls to behavior analysis.
Product Review: Deepdive's DD300
Deepdive's DD300 appliance helps you identify and discover data on your network.
Security services: Fiberlink's MaaS360 Mobility Platform
The MaaS360 Mobility Platform service handles remote device updates, such as OS patches.
Product Review: Shavlik's NetChk Compliance
Shavlik's NetChk Compliance automates compliance and provides control by actively managing system and security settings and allows the IT manager to identify and mitigate risks.
- Diverse mobile devices changing security paradigm
TrueCrypt an open source laptop encryption choice for SMBs
TrueCrypt eases security and privacy concerns. The open source security software encrypts a dedicated space on your hard drive, a partition or the whole disk, as well as removable storage devices.
Product Review: GuardianEdge Data Protection Platform
The GuardianEdge Data Protection Platform addresses the challenge of securing data wherever it resides, with centrally managed security on computers, mobile devices and portable storage.
Using a managed file transfer for secure data transmission, exchange
Managed file transfer (MFT) products meet the increasing security, compliance and operational demands of data in motion.
Security researchers leading way in biometrics, insider threats, encryption and virtualization
Carnegie Mellon University's CyLab is blazing trails in biometrics, insider threats, key exchange, virtualization and more.
Product Review: Symark PowerADvantage 1.5
Symark's Symark PowerADvantage allows Unix hosts to become member servers of an AD forest and leverage AD's centralized user management and authentication capabilities.
- TrueCrypt an open source laptop encryption choice for SMBs
Poor development practices lead to continued security problems
Critical systems continue to fail because security specialists haven't established themselves as valuable professionals.
Maintaining a strong security program during a recession, layoffs
Learn to maintain security during tough economic times and budget cuts when big corporations such as Merrill lynch, Wachovia and Chase, B of A are doing layoffs.
Collaboration with auditors will benefit information security programs
Security professionals should appreciate their relationships with internal auditors, who by pointing out security areas that need improvement, head off failures with external auditors.
Interview: Former L0pht hacker and current Grand Idea Studio owner Joe Grand
Known as a hardware security wizard, Grand is now a sought-after trainer and one of the hosts of a new show on Discovery Channel called Prototype This! about building unusual projects on a tight budget and schedule.
- Poor development practices lead to continued security problems
More Premium Content Accessible For Free
Deploying data protection technologies properly requires a lot of time and patience. While most firms can get started by using preconfigured policies...
The bring your own device (BYOD) movement, which has flooded the enterprise with employee-owned smartphones, tablets, phablets and purse-sized ...
For so long penetration testing meant hiring an expert to use skill and savvy to try to infiltrate the company system. But, as with most ...