Welcome to Exaprotect's monthly online bulletin – the culmination of our merger with Solsoft – bringing you news, views and opinion on issues that matter to you.
Security Management News is unique in that it is compiled and edited by leading industry journalists. Our aim is to deliver fresh and informative content, plus industry comment from experts. We want this to be a tool that helps you in your job and gives you a better understanding of security.
Please tell us what you think - and what else you'd like us to cover in this bulletin.
For those involved in IT security, one of the most frustrating tasks can be attempting to convince the board of the very real business threats posed by IT risk (the combination of an abnormal event or failure of your IT systems and the potential impact upon the business). A major challenge lies in effectively communicating to the board members the fact that IT risk is an organizational issue rather than merely an IT concern.
» Read more
Good corporate governance depends on the effective management of internal controls and on the availability, confidentiality and integrity of information. Corporate reputation, brand preservation and financial results all depend on the defence of business processes and on compliance with a growing array of legislation and regulation. For companies listed on US exchanges, the Sarbanes-Oxley Act of 2002 (‘SOX’) is of overriding importance and information security has a crucial role to play in achieving compliance.
» Read more
The Washington Post reports that the FBI are investigating allegations that Unisys Corp failed to detect a number of hacking attacks on the Department of Homeland Security from a Chinese language website and then attempted to cover this up.
» Read more
A new survey highlights a major gap in leading financial institutions between awareness of the problems posed by information security and support for the various solutions.
» Read more
I imagine that most people would consider the chances of an attacker guessing a privileged account name and password in two or three guesses to be astronomical. Unfortunately, nothing could be further from the truth. Breaking into corporate networks, and thereby corporate information, has never been easier. Why? Firstly, access to systems (usually Windows) at the desktop is universal. Secondly, most people, including IT staff, don’t appear to know how to select adequately secure passwords.
» Read more
A recent survey casts doubt over the ability of organizations adopting IPv6 transport to duplicate the features and support they currently experience when using IPv4.
» Read more
Four out of five companies have suffered from corporate fraud in the past three years, according to the findings of the Kroll Global Fraud Report. Even in the tech-savvy technology, media and telecoms sector over 75% of companies have been the victim of this type of fraud.
» Read more
New research from BT and the University of Glamorgan, Edith Cowan University in Australia and Longwood University in the USA has revealed that a significant number of hard disks available on the second-hand market contain sensitive company and personal information.
» Read more
The International Security Forum (ISF) is highlighting the latest security risks and threats as it runs executive briefings across 13 cities and ten countries around the world during October, November and December.
» Read more
The recent Information Security Solutions Europe (ISSE) conference in Warsaw saw the announcement of plans to make national identity card services transferable across member states in the European Union by 2010.
» Read more