Email Alerts
-
Can secure FTP services protect sensitive data from hackers?
Does secure FTP services protect against hackers and attacks? In this expert response, Michael Cobb explains why using a secure FTP service is vital for handling sensitive data transfers. Ask the Expert
-
What patch management metrics does Project Quant use?
In this Q&A, expert Michael Cobb reviews the open patch management metrics model called Project Quant. Ask the Expert
-
Are Web application penetration tests still important?
Web application penetration tests continue to be an important part of the secure software development lifecycle process in order to reduce the number and severity of security-related design and coding errors. Ask the Expert
-
How to detect input validation errors and vulnerabilities
Expert John Strand reviews how to spot input validation flaws on your websites. Ask the Expert
-
Is attack code valuable for vulnerabilities or just a publicity stunt?
If a security company has developed attack code for a particular vulnerability, there will always be critics that cry "PR stunt." Expert Michael Cobb explains why the vulnerabilities should always be taken seriously. Ask the Expert
-
Is a Master Boot Record (MBR) rootkit completely invisible to the OS?
Whether or not we see widespread attacks that use MBR rootkits will depend upon two factors. Platform security expert Michael Cobb explains them both. Ask the Expert
-
Can threat modeling help enterprises?
In this expert response, Ed Skoudis explains how threat modeling can determine an organization's greatest threats and associated risks. Ask the Expert
-
Can dynamic and static verification secure a platform?
The best software testing approach is to use a combination of static and dynamic verification tools that continually check for technical and logical vulnerabilities during the development cycle. Expert Michael Cobb examines each testing procedure in ... Ask the Expert
-
Do the Common Vulnerabilities and Exposures protect applications?
When discussing today's many security holes, security professionals can use the Common Vulnerabilities and Exposures (CVE) dictionary to make sure that they refer to the same flaw. But what can the list do for home-grown Web application software? Exp... Ask the Expert
-
Are penetration tests essential for enterprise network security?
Penetration testing can provide valuable information on the state of your security defenses, but it's quite expensive. In this expert Q&A, Mike Chapple explains whether an organization should make the move. Ask the Expert
Security Management Strategies for the CIO