Home > Information Security Magazine
EMAIL THIS
Information Security Magazine

  CURRENT ISSUE  

  FEATURES  

  COLUMNS  

  HOT PICK & PRODUCT REVIEWS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 
Information Security Magazine
This Month
Sign up for Information Security RSS feeds
NOVEMBER 2009
FEATURES

Integrated change management reduces security risks

Metasploit Project acquisition ups ante for penetration testing market

Enterprises must treat Insider risk as they do external threats

VIEW FEATURES FOR ALL MONTHS
COLUMNS

Schneier-Ranum Face-Off: Is antivirus dead?

Standards compliance does not equal sound information security risk management

Time is now for pandemic flu planning

VIEW COLUMNS FOR ALL MONTHS

HOW WE GRADE PRODUCTS
Read more from Information Security magazine in our back issues.

October 2009

September 2009

July 2009

June 2009

May 2009

April 2009

March 2009

VIEW ALL BACK ISSUES

2007 Features

VIEW FEATURES FROM PREVIOUS YEARS::  

2009   |   2008   |   2007   |   2006   |   2005
November 2007

Product review: Seven integrated endpoint security products
by Ed Skoudis & Matt Carpenter
Information Security magazine evaluates seven integrated endpoint security suites on their management capabilities, reporting, ability to detect and block malware, detecting and thwarting exploit attempts, and integration of the various desktop security capabilities in one package.

Remote computer access to files and systems must secure
by Lisa Phifer
Organizations are overhauling strategies to meet the challenges of the mobile workforce. Companies need to be strategic when evaluating the best secure remote computer access technology they deploy.

Web 2.0 application development techniques introduce new information security risks
by Justin Gehtland
Ajax, Java and other dynamic application coding methods have pulled computing power over to the client, introducing new risks and resurrecting old ones.

Honeyclients bring new twist to honeypots
by David Strom
Honeyclients are unpatched web browsers that actively seek malicous websites.
October 2007

Security 7 Award winners successfully integrate security and business
The 2007 Information Security magazine Security 7 Award winners demonstrate how their strategies for integrating their security programs into the overall business.

Log management reins in security and network device data
by David Strom
Learn how to manage log data from security and network devices in order to manage security events in real time.

Knoppix-NSM removes complexity of Snort-based network security monitoring
by Russ McRee
Open source Knoppix-NSM is a complete network security monitoring system on a single CD.
September 2007

Rootkit detection and removal know-how
by Greg Hoglund
Get advice on how to detect malware and rootkits and the best ways to achieve rootkit removal and prevent hacker attacks.

What CISOs need to know about computer forensics
by Marcia Savage
With computer forensics needed for civil litigation, human resources investigations and criminal cases, organizations need to ensure they're prepared and evidence is preserved. This feature details steps involved in computer forensics, common missteps, and forensics resources.

Logical, physical security integration challenges
by Mark Diodati
Integrating physical and IT security can reap considerable benefits for an organization, including enhanced efficiency and compliance plus improved security. But convergence isn't easy. Challenges include bringing the physical and IT security teams together, combining heterogenous systems, and upgrading a patchwork of physical access systems.

Consolidation's impact on best-of-breed security
by Michael S. Mimoso
Standalone security vendors are attractive targets for large infrastructure players such as EMC. This feature looks at the consolidation in the security market and the potential for best-of-breed security to eventually disolve into a mashup of suites and services by big vendors like EMC, IBM, Microsoft, and HP.
July 2007

Office Politics
by Marcia Savage
Success requires skills in business, technology and people.

Securing Extranets
by Paul Korzeniowski
Is perimeter security viable with Swiss cheese networks?

Protecting Your Brand
by Amy Rogers Nazarov
Customer confidence is at risk when a breach occurs.

Emerging Technologies: How to secure new products
by Lisa Phifer
New business initiatives mean new threats.
June 2007

Security services firms: When and how to choose the right consultant
Learn when to hire a security services firm, how third-party consultants can help managers, how much it should cost and how to choose the right firm.

Product review: Unified threat management (UTM) devices
Unified threat management devices consolidate several network security functions into one product. This article evalutes six UTM appliances; each had to act as a firewall and virtual private network and provide antivirus, Web content filtering, intrusion prevention and antispam protection.

SIMs maturing and suitable for mid-market
Security information management systems (SIMs) tools have expanded with more capabilities such as active threat response. The broadening of the technology will provide security managers with a sharper view of their overall security posture.

Encryption key management blunders can render deployments useless
Encryption sounds like an ideal way to protect data but key management, including accountability, training, and enforcement of password complexity, are challenging.
May 2007

Intellectual property protection do's and don'ts
by Russell L. Jones & Rena Mears
Theft of intellectual property is a growing problem but many companies are not prepared to deal with this security threat. Learn about the risk involved with trade secrets, why companies are failing to protect intellectual property and tips for data protection, including risk assessment, encryption, and corporate governance.

New Types of Computer Crime: Combating malware, botnets, phishing
by Lenny Zeltser
The days of thrill-seeking script kiddies are over. Organized criminals are launching new types of computer crime, including browser malware, targeted email attacks and voice-based phishing, and using botnets to launch DDoS attacks.

Are you putting information at risk by using contractors?
by Paul Rohmeyer
Contractors can become the source of a security breach. This feature looks at the risk management steps, including access control and policies, that organizations should take when hiring contractors. A sidebar examines how a health care company uses NAC to control contractor access.

Role-based access controls
by Shon Harris
Identity management is a critical security challenge, but without viable standards for access control, your best efforts may be just a drop in the bucket.
April 2007

2007 Readers' Choice Awards
Methodology

Selecting the 2007 Readers' Choice Awards

Antimalware: McAfee VirusScan Enterprise and AntiSpyware Enterprise
2007 Readers' Choice Awards Desktop and gateway enterprise antimalware products.

Application Security: 2007 Readers' Choice Awards
2007 Readers' Choice Awards Source code and web application scanners and appliances

Authentication: 2007 Readers' Choice Awards
2007 Readers' Choice Awards Digital identity verification

Database security, software appliances review: Readers Choice Awards
In this Readers Choice Award product review of database security products and software appliances, learn about pricing and ratings on Symantec, AppDetective and Imperva SecureSphere products and appliances.

Endpoint Security: 2007 Readers' Choice Awards
2007 Readers' Choice Awards Pre- and post-connection network access control

Identity and Access Management product reviews: Readers Choice Awards
In this Reader's Choice Award product review of identity and access management and provisioning products, learn about security features and get pricing info on Novell, RSA and Oracle IAM and provisioning products.

Intrusion Detection/Prevention
2007 Readers' Choice Awards Network intrusion detection/prevention appliances and software

Messaging
2007 Readers' Choice Awards Email, IM and VoIP secuirty

Network Firewalls
2007 Readers' Choice Awards Network firewall appliances and software

Risk and Policy Management
2007 Readers' Choice Awards Risk, policy, configuration and vulnerability management

Secure Remote Access
2007 Readers' Choice Awards Secure remote access products

Security information, event management systems: Readers Choice Awards
Get the Information Security Readers Choice Award results for security information management system (SIMs) products from vendors like Archsight, Check Point and NetIQ.

UTM
2007 Readers' Choice Awards Unified threat management products

Vulnerability Management: QualysGuard Enterprise (2007)
2007 Readers' Choice Awards Vulnerability assessment, management

Wireless
2007 Readers' Choice Awards Wireless security products

Emerging Technologies: 2007 Readers' Choice Awards
2007 Readers' Choice Awards Innovative and effective solutions to tough security problems

Prospective Buyers Want Answers
by Alan Paller
SANS WhatWorks The SANS Institute's WhatWorks program identifies three critical areas of concern for security managers.
March 2007

Product review: Six removable device control security products
by Sandra Kay Miller
Six removable device control security products that provide centrally managed granular control over ports, interfaces and storage devices are reviewed. This review evaluates: DeviceLock 6.0 from SmartLine, Sanctuary Device Con-trol 4.0 from SecureWave, Endpoint Access Manager 3.0 from ControlGuard, Device-Wall 4.5 from Centennial Software, Safend Protector 3.1 from Safend and Protect Mobile from Workshare.

Prioritizing compliance and information security
by George V. Hulme
Have compliance demands refocused and weakened information security efforts?

Enterprise UTM products differ from all-in-one SMB appliances
by Lisa Phifer
UTM appliance struggle to find their niche in the enterprise as large companies prefer best-in-breed security products.

Thin clients a malware-free desktop option
by George V. Hulme
A Maine health care provider sheds its spyware-ridden, burdensome PCs for a safer, more manageable thin client environment.
February 2007

Going Global
by Jody R. Westby
Organizations sending data abroad must be prepared to comply with a slew of privacy and security regulations.

Encrypt It
by W. Curtis Preston
Unencrypted data at rest is data at peril.

Information security blueprint for architecture and systems
by Michael S. Mimoso
A formalized security architecture diagrams how you should handle the changing threat and regulatory environments.

IPS by the Numbers
by Joel Snyder
Choosing the right intrusion prevention technologies and products is a complex task, but following these six steps will make it simpler.
January 2007

Who's There?
by David Strom
Enterprises have a pressing need for endpoint security, but choosing a system that screens PCs before allowing them network access requires careful consideration.

Virtual Threats
by Dennis Fisher
Virtual machines save you money in the data center, but can you ignore their security implications any longer?

Mixed Signals
by Mark Baard
RFID gives businesses-and bad guys-an easy way to track and change information.

How to setup and configure syslog to view and filter data
by Eric Cole
Your network devices are trying to tell you that you're under atta ck. Syslog helps you sort through the data overload and get the message.




TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts