You are here  IT Management Risk Management

Information Security magazine highlights January 2007

Wednesday 31 January 2007 12:00


Information Security magazine's January issue takes a deep dive into the security issues you need to be proficient with today--like endpoint security and strong authentication-- and what you'll need to keep an eye on for tomorrow--RFID and securing virtual machines.

Wide world of endpoint security
Network perimeters have dissolved as your employees, contractors and partners access data from virtually anywhere. All of those endpoints introduce risk to your network. Expert David Strom hosts a webcast Jan. 17 at noon ET, that will explain what makes up a successful endpoint security strategy and how evolving vendor partnerships are affecting NAC product sets.
>>Register for thiswebcast.

FFIEC Crash Course
Financial institutions that offer online banking are required by the Federal Financial Institutions Examination Council (FFIEC) to implement strong authentication to secure transactions. Now that the first FFIEC deadline has passed, keep this crash course on FFIEC and strong authentication handy as a resource guide.
>>ReviewTwo-factor authentication and the FFIEC: A crash course


RFID primer
Is RFID in your company's future? Expert Joel Dubin explains some of the security issues that exist and would need to be resolved before RFID becomes a mainstream tracking technology for your supply chain.
>>ReviewRFID tags: Do they have a secure future?

Snort and syslog
Snort is probably the most popular network intrusion detection system in deployment, but admittedly, it doesn't do a good job with syslog traffic, expert Mike Chapple says. In this tip, he points you to some of the best alternatives for monitoring Snort log data.
>>ReadCan Snort read multi-platform syslogs?

Zero Hour
This list lays out zero-day flaws in Windows that were discovered in 2006 and when they were patched:

MonthFlawAppearedPatchedPatchPayload
JanuaryWMFDec. 28, 2005Jan. 5MS06-01Spyware infections, spam relays
MarchIE createTextRangeMarch 22April 11MS06-013Remote code execution
MayWord malformed object pointerMay 10June 13MS06-027Remote code execution
JuneExcel document processingJune 16July 11MS06-037Remote code execution
JulyPowerPoint malformed shape container or recordJuly 12Aug. 8MS06-048Remote code execution
SeptemberIE Vector Markup Language buffer overflowSept. 18Sept. 26MS06-055Botnet; remote code execution
 PowerPointSept. 27Oct. 10MS06-058Remote code execution
 WordSept. 2Oct. 10MS06-060Remote code execution
NovemberVisual Studio Object Broker ActiveX controlNov. 1Dec. 12MS06-073Remote code execution
 XML Core Services XMLHTTP 4.0 ActiveX controlNov. 3Nov. 15MS06-071Remote code execution
DecemberWordDec. 5Unpatched Remote code execution
 Windows Media PlayerDec. 7Dec. 12MS06-078DoS; remote code execution
 WordDec. 10Unpatched Remote code execution

PING
In this exclusive interview with Information Security magazine Nikk Gilbert, IT security and telecom director reviews the obstacles he encountered when placed at the helm of an enterprise that didn't have a dedicated security team and what enterprise security professionals can do secure their network.
>>Read the interview withNikk Gilbert




HIGHLIGHTS ARCHIVES
December 2006November 2006October 2006September 2006August 2006July 2006
June 2006May 2006April 2006March 2006February 2006January 2006
December 2005November 2005October 2005September 2005August 2005July 2005