05/17/2012 | Identity & Access Management
Passwords are a controversial topic within the information security community. One side argues that passwords are “broken” and need a serious overhaul. The reasons are myriad; users hate remembering them, they can be lost or easily forgotten, users tend to share them or write them down (especially when complex), etc. The other side of the community points out that there’s a time
05/17/2012 | Identity & Access Management
The Identity and Access Management (IAM) track at the IANS New York Metro Forum was a new addition to IANS’ curriculum. Historically a very popular topic with IANS clients, Faculty members Diana Kelley and Ed Moyle morphed their previous Application Security sessions to reflect what’s being requested by clients. This document outlines some of the key insights from the IAM track
05/16/2012 | Infrastructure Security
Cloud-based security offerings have steadily increased in number over the last several years. These products range fairly widely in terms of scope and capability, plus represent a diverse set of categories within the general information security space. This paper will explore some of the major categories of Security-as-a-Service (SecaaS), explain what they are along with the
05/15/2012 | Incident Response & Investigations
The Incident Response and Planning track at the IANS Twin Cities and New York Metro Forums built on ideas presented earlier in the quarter. Marcus Ranum offered delegates his thoughts around how to better prepare for and thwart an incident. Like at the Mid-Atlantic Forum, Twin Cities and New York delegates wanted to discuss with peers ways they and their teams can break down what
05/14/2012 | Infrastructure Security
Most of the identity management problems that enterprises work to address in cloud applications are not new problems; rather the move to the cloud accentuates some of the drawbacks in current approaches to identity, such as point to point and proprietary identity. This document will examine some of the ways enterprises can successfully plan their cloud identity management (IDM)
05/14/2012 | Network Security
As difficult as it has been for many to accept, the computer security industry has finally conceded that focusing all efforts in securing endpoints is now futile. There has therefore been a recent emergence of network forensics tools and techniques to help with monitoring and analysis of network activity for gathering information, determining intrusions, and collecting data as
05/10/2012 | Vulnerability & Threat Management
Please click through the slides along with the audio portion of IANS' May End User Client Briefing by Hart Rossman. The last few years have seen the rise of SCADA security not only within the security community, but also in public consciousness. What has been an under-explored area of the information communications technology space has been catapulted into the limelight through a
05/09/2012 | Vulnerability & Threat Management
The last few years have seen the rise of SCADA security not only within the security community, but also in public consciousness. What has been an under-explored area of the information communications technology space has been catapulted into the limelight through a combination of events, namely the growing sensitivity by governments of the role IT plays in critical infrastructure
05/08/2012 | Security Operations
If the FBI shows up at your corporate headquarters to alert you of an ongoing attack on your network, it’s a good bet that your IT incident and alert program isn’t getting the job done. Most companies want to make sure the “FBI moment” never happens and, to accomplish this, have spent significant time and effort planning and building a security operations center (SOC). Merely
04/24/2012 | Security Management
In Q1 2012 IANS End User Clients submitted 119 Ask an Expert queries that were answered by IANS Faculty and/or a peer or peer group. This document details the 119 (anonymized) submitted Ask an Expert queries. Look for more granular information on many of these topics in subsequent Faculty Insights and Event Insights reports to be published later this year.