05/17/2012 | Identity & Access Management
Passwords are a controversial topic within the information security community. One side argues that passwords are “broken” and need a serious overhaul. The reasons are myriad; users hate remembering them, they can be lost or easily forgotten, users tend to share them or write them down (especially when complex), etc. The other side of the community points out that there’s a time
05/09/2012 | Vulnerability & Threat Management
The last few years have seen the rise of SCADA security not only within the security community, but also in public consciousness. What has been an under-explored area of the information communications technology space has been catapulted into the limelight through a combination of events, namely the growing sensitivity by governments of the role IT plays in critical infrastructure
05/08/2012 | Security Operations
If the FBI shows up at your corporate headquarters to alert you of an ongoing attack on your network, it’s a good bet that your IT incident and alert program isn’t getting the job done. Most companies want to make sure the “FBI moment” never happens and, to accomplish this, have spent significant time and effort planning and building a security operations center (SOC). Merely
04/24/2012 | Security Management
In Q1 2012 IANS End User Clients submitted 119 Ask an Expert queries that were answered by IANS Faculty and/or a peer or peer group. This document details the 119 (anonymized) submitted Ask an Expert queries. Look for more granular information on many of these topics in subsequent Faculty Insights and Event Insights reports to be published later this year.
04/09/2012 | Network Security
Faculty member Kevin Johnson answers the question, "With all the press around hacktivism and Anonymous, what do we need to know, and what do we need to do differently?"
03/28/2012 | Security Strategy
Security awareness training is a topic that never goes out of favor with IANS clients. Because our environments and the threats to them are always changing, information security teams must look for new, fresh ways to keep users engaged, knowledgeable, and prepared for an incident. In this document, Mike Saurbaugh offers some practical advice for security teams looking to improve
03/28/2012 | Mobile Security
In this first IANS Solution Provider Briefing, Faculty Kevin Johnson presents how BYOD is affecting organizations and provides an overview of why solution providers should care about end user adoption.
03/26/2012 | Security Management
When it comes to working with law enforcement, most people’s initial reaction is to start thinking about all the hassle that is sure to ensue. At an organizational level, common perception is that dealing with legal entities means jumping through hoops and waiting on permissions. During his March 2012 ECB presentation, Randy Sabett explains why perception is not reality and why
03/26/2012 | Network Security
The majority of today’s organizations detect and internally report on threats by relying on the static based signature protections provided by their security vendors. With the volume of high profile data breach headlines over the past couple of years and the detailed sophistication of many of these attacks, it is obvious that signature based protections are no longer adequate for
03/20/2012 | Vulnerability & Threat Management
The last few years have seen the rise of SCADA security not only within the security community, but also in public consciousness. What has been an under-explored area of the information communications technology space has been catapulted into the limelight through a combination of events, namely the growing sensitivity by governments of the role IT plays in critical infrastructure