Email Alerts
-
Readers' Choice Awards 2011
null
-
Best Antimalware Products 2011
null
-
How to manage security risks in vendor contracts
Financial institutions face numerous regulatory requirements for managing vendor risk. Learn what financial firms need to include in their vendor contracts in order to conform with regulatory guidance and industry best practices for vendor risk manag... Learning Guide
-
Security on a budget: How to control access to a WLAN
WPA and WPA2-Enterprise provide robust WLAN access control, but deploying 802.1X can be overwhelming for companies with limited IT staff and budget. From outsource to open source to preshared keys, this tip describes several less complex or costly al... Security School
-
Corporate Mergers and Acquisitions Security Learning Guide
Mergers and acquisitions are common occurrences in today's information security market. In this SearchSecurity.com Learning Guide, a panel of experts breaks down M&A security priorities and explains the best ways to manage disparate security staffs, ... Learning Guide
-
Information Security announces finalists for 2007 Readers' Choice awards
This year more than 1,500 readers weighed in on nearly 350 products. Preview the list of finalists; winners will be revealed in the April 2007 issue of Information Security. Information Security
-
More from SearchSecurity.com -- November 2006
Highlights from November edition of Information Security magazine Information Security maga
-
Building network security: Evolution and vendor consolidation
Through both vendor consolidation and evolution, security capabilities are increasingly being woven into the network fabric. In this lesson, Mike Rothman, president and principal analyst of Security Incite, will help attendees understand the network/... Identity and Access Manag
-
Become compliant without breaking the bank
Information Security maga
-
Merger madness: What to do when your infosec vendor gets acquired
When your favorite security vendor merges or is acquired, the only thing you can expect for certain is change. This article outlines the pros and cons of vendor mergers and acquisitions, and how customers can influence their future with the new compa... Information Security maga
- See More: Essential Knowledge on Vendor Management: Negotiations, Budgeting, Mergers and Acquisitions
-
BeyondTrust acquires eEye Digital Security for vulnerability management
Analysts say eEye’s vulnerability and configuration management capabilities are a good fit with BeyondTrust’s privilege management and AD integration. News | 10 May 2012
-
TIBCO to acquire SIEM vendor LogLogic
TIBCO, an integration software company with little security experience, will purchase one of the few remaining viable standalone SIEM vendors. Terms were not disclosed. News | 04 Apr 2012
-
Thoma Bravo sells next-gen firewall, UTM vendor SonicWall to Dell
Dell’s security portfolio expands with purchase of unified threat management and next generation firewall vendor SonicWall from private equity firm. News | 13 Mar 2012
-
Trustwave acquires M86 Security for SaaS, managed security services
The company, which has made many acquisitions in the last five years, faces integration challenges as it moves more broadly into SaaS, managed security services, analyst says. News | 06 Mar 2012
-
Twitter acquires Dasient in security buying spree, Android platform focus
Web-based antimalware vendor Dasient is the second security firm acquired by Twitter in recent months. In November, Twitter acquired Android security vendor, Whisper Systems. News | 24 Jan 2012
-
Black Hat 2011: NetWitness CSO Eddie Schwartz on SecurID attack detection
Michael Mimoso talks to NetWitness Corp., CSO Eddie Schwartz live from Black Hat 2011. Schwartz talks about NetWitness’ involvement in detecting the SecurID attack against RSA, as well as the hacktivism revival. News | 04 Aug 2011
-
New Veracode technology seeks to speed up SQL attack detection
The new Veracode technology, Dnyamic MP, is said to be able to scan thousands of websites simultaneously to spot an SQL attack or other attack types. News | 02 Aug 2011
-
Citrix patches severe XenDesktop, XenApp security flaw
The virtualization vendor says a severe XenDesktop and XenApp security flaw needs immediate patching, or else an attacker may execute arbitrary code. News | 28 Jul 2011
-
WhiteHat acquires static code analysis technology
Move to acquire Infrared Security will add static code analysis to WhiteHat’s dynamic vulnerability testing platform. News | 23 Jun 2011
-
New Adobe sandbox hardens Acrobat family, adds Protected View
Protected View builds on Adobe Reader X Protected Mode, isolating processes to make it more difficult for malicious code to access the underlying operating system. News | 16 Jun 2011
- See More: News on Vendor Management: Negotiations, Budgeting, Mergers and Acquisitions
-
Cisco MARS: What third-party lockout means for SIEM products
Now that Cisco's MARS SIEM product no longer supports third-party product integration, should enterprises migrate away from the product? In this tip, network security expert Anand Sastry discusses how MARS works and whether the technology is still go... Tip
-
Handling mergers and acquisitions: Career success tips for infosec pros
A company merger or acquisition is always a tumultuous time, and can be even more nerve wracking if you're concerned that your position might be eliminated. In this tip, career experts Lee Kushner and Mike Murray give proactive strategies you can use... Tip
-
McAfee update problem: Dealing with bad antivirus DAT files
While buggy antivirus DAT files are the exception rather than the rule, downloading them can cause just as much turmoil as a potential DDoS attack. In this tip from expert Ernie Hayden, learn how to prepare your enterprise network for any sort of maj... Tip
-
How to buy an IPS: Features, testing and review
If you're considering IPS for your enterprise, make sure you know what to look for in the products you're reviewing. In this tip, network security expert David Meier describes how to conduct an IPS comparison and review of various features, including... Tip
-
Security on a budget: How to make the most of authentication tools
Working on an identity and access management project can be hard enough without having to worry about sufficient funding. In this tip, learn how to leverage existing identity and access management tools and software to keep your budget lean and your ... Tip
-
How to look past information security vendor rhetoric
Security professionals are bombarded with messages from vendors (and their marketing messages) heralding sure-fire cure-alls for compliance and information security woes. So what's the best way to differentiate between a useful product and a useless ... Tip
-
Security awareness training: Stay in, or go out?
So you've decided you need security awareness training. Now what? In this tip, Joel Dubin offers a primer on in-house vs. outsourced security awareness training, and guidelines to help an organization decide which choice is best for its needs. Tip
-
Enterprise security in 2008: Building trust into the application development process
The Storm botnet, launched a year ago, proved that malicious hackers were developing more sophisticated botnets -- and more sophisticated business strategies. As Michael Cobb explains, it's just one reason why application security pros need to keep a... Tip
-
How to buy security products: Eight steps to not losing your shirt
Companies don't often purchase new information security products, so when they do, it's critical that they get the right product for the best price. In this tip, contributor Mike Rothman explains common mistakes in the security product purchase proce... Tip
-
Mergers and acquisitions: Building up security after an M&A
Mergers and acquisitions are common headlines in today's information security world, and that's great news for malicious hackers and data thieves. When companies join forces, they often leave themselves open to attack. In this tip, contributor Ed Sko... Tip
- See More: Tips on Vendor Management: Negotiations, Budgeting, Mergers and Acquisitions
-
Advice for developing a vendor compliance checklist for a vendor review process
Charles Denyer offers advice for developing a vendor compliance checklist to support a vendor review process or a third-party vendor audit. Answer
-
Will independent endpoint protection review improve products?
ICSA Labs recently announced a new endpoint security certification. Could it help improve endpoint security products? Answer
-
Merger management: How to handle potential merger threats to security
During a merger, management of information security becomes even more crucial in order to mitigate threats, including the many new insiders and attentive attackers that want to take advantage of holes in the companies' infosec integration. Ask the Expert
-
UTM appliances: How to choose among UTM vendors
Choosing a UTM appliance is a big job, as testing can take months and the costs aren't negligible. In this expert response, get advice on how many UTM devices to test, and what to consider during the testing process. Ask the Expert
-
Cisco network appliance security: Does 'self-defending' network stack up?
Cisco has for years touted its concept of a "self-defending" network, but what does it actually entail? In this expert response, Anand Sastry explains what "self-defending" means (at least, according to vendors), and whether it's really possible. Ask the Expert
-
Changing information security plans in an economic downturn
In an economic downturn, it may be necessary to reevaluate security budgets. Should security managers change information security plans from Web application security assessments to an enhanced data protection project for 2009? Ask the Expert
-
Comparing cheap security products and appliances to costly appliances
Security appliances range widely in cost and capability, so what's the best way to decide the right appliance for your enterprise? In this security management expert response, learn how to work with vendors to get the security tools you need. Ask the Expert
-
What vendors would you recommend for software write-blockers?
In a forensics investigation, a software write-blocker can be very helpful. But which vendors offer the best blockers? Security management expert Mike Rothman explains what to look for. Ask the Expert
-
Is there a market for standalone antivirus products?
In this SearchSecurity.com Q&A, Ed Skoudis says that there is still a market opportunity for standalone antivirus products -- but the window is shrinking. Ask the Expert
-
What are the security risks of a corporate divestiture?
Security management expert Mike Rothman discusses the data protection issues involved with a corporate divestiture . Ask the Expert
- See More: Expert Advice on Vendor Management: Negotiations, Budgeting, Mergers and Acquisitions
-
snake oil
In cryptographic and other computer products, snake oil is a negative term used to describe exaggerated claims made by vendors who are overly optimistic or purposely seeking to take advantage of consumers who do not have the expertise to judge a prod... Definition
-
Video: Inside the Verizon Data Breach Investigations Report 2011
Verizon's Wade Baker previews the 2011 Verizon Breach Investigations Report and shares surprising insight from the 2010 report on tactics that do and don't help prevent breaches. Video
-
Part 2: Marcus Ranum on the state of information security
At Information Security Decisions 2009, Marcus Ranum analyzes the late golden age of information security and how venture capital (or lack thereof) has dramatically changed the vendor landscape. Video
-
Part 4: Marcus Ranum on the state of information security
At Information Security Decisions 2009, Marcus Ranum explains the effect vendor consolidation will have on technology integration and the need for feature awareness. Video
-
Countdown: Top 5 most important questions to ask endpoint security vendors
After the endpoint security assessment is over and it's time to go talk to vendors, how can you tell between a song and a dance, and what you can truly expect out of a product? Podcasts
-
Virtualization: Disruptive technologies part 4
Is there a future for vendors offering security solutions for virtualized environments, or will security eventually be almost entirely built-in? Experts Chris Hoff, Rich Mogull and Dino Dai Zovi discuss. Video
-
Countdown: Top five ways to sell NOC/SOC integration
NOC/SOC integration offers enterprises a number of benefits, but time and trouble of making the conversion is enough to make executives wary. In this podcast, learn key insights about the business value gained by fostering NOC/SOC integration. Some o... Podcast
-
Top 5 questions to ask when shopping for a compliance product
The Podcast featured here examines what it takes to implement an effective security and compliance framework. Podcast
-
BeyondTrust acquires eEye Digital Security for vulnerability management
Analysts say eEye’s vulnerability and configuration management capabilities are a good fit with BeyondTrust’s privilege management and AD integration. News
-
TIBCO to acquire SIEM vendor LogLogic
TIBCO, an integration software company with little security experience, will purchase one of the few remaining viable standalone SIEM vendors. Terms were not disclosed. News
-
Thoma Bravo sells next-gen firewall, UTM vendor SonicWall to Dell
Dell’s security portfolio expands with purchase of unified threat management and next generation firewall vendor SonicWall from private equity firm. News
-
Trustwave acquires M86 Security for SaaS, managed security services
The company, which has made many acquisitions in the last five years, faces integration challenges as it moves more broadly into SaaS, managed security services, analyst says. News
-
Twitter acquires Dasient in security buying spree, Android platform focus
Web-based antimalware vendor Dasient is the second security firm acquired by Twitter in recent months. In November, Twitter acquired Android security vendor, Whisper Systems. News
-
Advice for developing a vendor compliance checklist for a vendor review process
Charles Denyer offers advice for developing a vendor compliance checklist to support a vendor review process or a third-party vendor audit. Answer
-
Readers' Choice Awards 2011
null
-
Best Antimalware Products 2011
null
-
Will independent endpoint protection review improve products?
ICSA Labs recently announced a new endpoint security certification. Could it help improve endpoint security products? Answer
-
Black Hat 2011: NetWitness CSO Eddie Schwartz on SecurID attack detection
Michael Mimoso talks to NetWitness Corp., CSO Eddie Schwartz live from Black Hat 2011. Schwartz talks about NetWitness’ involvement in detecting the SecurID attack against RSA, as well as the hacktivism revival. News
- See More: All on Vendor Management: Negotiations, Budgeting, Mergers and Acquisitions
About Vendor Management: Negotiations, Budgeting, Mergers and Acquisitions
Get advice from the experts on vendor management and all vendor communications, such as negotiations, budgeting and merger and acquisitions (M&A). Learn how to get security tools and investments at the best price.
Security Management Strategies for the CIO