HOW TO BUILD SECURE APPLICATIONS

In this lesson, learn how to build security into the software development lifecycle, implement a practical, efficient change management system and test your applications using a black-box or white box technique.
About the author:
Diana Kelley is a partner with consulting firm SecurityCurve.
This lesson also features special guest Ed Moyle, QSA and partner with SecurityCurve. LEARN MORE: HOW TO BUILD SECURE APPLICATIONS
MITIGATING WEB 2.0 THREATS

As companies look to cut costs, Software as a Service has gained ground in the enterprise. Similarly, social networking sites like Facebook and LinkedIn are must-haves in today's workplace. David Sherry reviews how to secure these services and defend against a variety of Web 2.0 threats.
About the author:
David Sherry is chief information security officer at Brown University. LEARN MORE: MITIGATING WEB 2.0 THREATS
DATA LOSS PREVENTION

Every CSO knows the importance of protecting sensitive data, but it is still a challenge to actually implement tools that will do the job. This lesson provides an overview of how data loss prevention tools can protect intellectual property and confidential data.
About the author:
Rich Mogull is the founder of Securosis LLC, an independent security consulting practice. LEARN MORE: DATA LOSS PREVENTION
E-DISCOVERY AND SECURITY IN THE ENTERPRISE

The new Federal Rules for Civil Procedure now allow a judge to request electronically stored information, and the inability to respond can be costly.
In this lesson, learn about updates to the FRCP and how to prepare for ligitation, and understand the technologies that can assist in the process.
About the expert:
Frank Lagorio, JD, is principal analyst for Contoural Inc. LEARN MORE: E-DISCOVERY AND SECURITY IN THE ENTERPRISE
DATABASE DEFENSES FOR A NEW ERA OF THREATS

All too often, precious corporate databases containing customer records and other sensitive data are forgotten or ignored. This lesson offers an overview of the basic tools needed to secure a company's databases against today's emerging and most dangerous threats.
About the author:
Rich Mogull is the founder of Securosis LLC, an independent security consulting practice. LEARN MORE: DATABASE DEFENSES FOR A NEW ERA OF THREATS
EXECUTING A DATA GOVERNANCE STRATEGY

Today data is often siloed in many applications and databases with no documentation on how trusted it is and the relationships among applications that capture and use it. In this lesson, learn how you can remedy these issues with a mature data governance strategy.
About the author:
Russell L. Jones is Partner AERS - Security & Privacy Services with Deloitte & Touche. LEARN MORE: EXECUTING A DATA GOVERNANCE STRATEGY
ENTERPRISE STRATEGIES FOR PROTECTING DATA AT REST

Many of today's data security breaches can be attributed to lost data. While security pros often focus on network soft spots, storage and e-discovery practices are often overlooked. This lesson will outline e-discovery services and how to ensure successful storage-security teamwork.
About the author:
Perry Carpenter is a security practitioner with a large telecommunications firm. LEARN MORE: ENTERPRISE STRATEGIES FOR PROTECTING DATA AT REST
DATA ENCRYPTION DEMYSTIFIED

Recent user-friendly advances have been made in "practical cryptography," but there are still many security considerations when it comes to data encryption, including data classification and how to ensure information can be accessed across multiple applications.
About the author:
Tom Bowers is managing director of consulting firm Security Constructs. LEARN MORE: DATA ENCRYPTION DEMYSTIFIED
PREVENTING DATA LEAKS

Today's most devastating security breaches often originate from within. This lesson will examine essential data loss prevention policies, processes and technologies for combating this growing threat.
About the author:
Richard Bejtlich is the founder of consulting firm Tao Security. LEARN MORE: PREVENTING DATA LEAKS
|