Welcome to Exaprotect's monthly online bulletin – the culmination of our merger with Solsoft – bringing you news, views and opinion on issues that matter to you.
Security Management News is unique in that it is compiled and edited by leading industry journalists. Our aim is to deliver fresh and informative content, plus industry comment from experts. We want this to be a tool that helps you in your job and gives you a better understanding of security.
Please tell us what you think - and what else you'd like us to cover in this bulletin.
The problems of putting sensitive information on an easy-to-lose medium such as disks - and not backing up internal policies with good security practice - were brought sharply into focus by the news that the UK’s HM Revenue and Customs has been involved in one of the world’s biggest ID protection failures.
» Read more
As risk management matures and develops, reputational risk is gripping the imagination of many CEOs. A series of recent surveys illustrate that boards not only consider that reputational risk exposure is increasing, but that it is now the most serious threat to their company.
» Read more
A 19-year-old man from Uppsala in Sweden has been found guilty of gaining unauthorized access to the computer networks of several Swedish universities and colleges. He was given a suspended sentence and ordered to pay total damages of 181,467 kronor ($28,100) to several of the colleges and universities.
» Read more
What can run but never walks,
Has a mouth but never talks,
Has a bed but never sleeps,
Has a head but never weeps?
» Read more
As independent consultants our advice is often sought by clients about security vendors and their products. Sometimes we participate in the evaluation and buying process overtly, sometimes covertly.
» Read more
The Information Security Forum (ISF) has announced a new diagnostic tool aimed at helping security professionals to understand how to meet business requirements and manage a security function.
» Read more
A new report by security researcher David Litchfield claims that thousands of database servers are not sufficiently protected, making them vulnerable to attack via the Internet.
» Read more
This is the first in a series of short articles on the theme of ‘security measurement’, all based on a presentation given by Dan Geer at the recent Usenix Security Symposium in Boston. This first article will focus on the role of security metrics in supporting risk management.
» Read more
Two recent pieces of research have highlighted the security threats posed by an organization’s own end users, particularly in relation to their use of mobile devices.
» Read more
In previous issues of this newsletter we’ve looked at some of the general issues associated with data retention requirements. Here we will focus on a very specific data retention requirement that relates to a regulatory compliance issue in the pharmaceutical industry.
» Read more
Manhattan District Attorney Robert M. Morgenthau has announced the indictment of seventeen individuals and one corporation, Western Express International, on charges related to global trafficking in stolen credit card numbers, cybercrime, and identity theft.
» Read more