Articles

  • 4 Types of Insiders Who Threaten IT

    CERT Report Identifies Insider Patterns Jeffrey Roman - February 3, 2012
    4 Types of Insiders Who Threaten IT

    Although insider-threat incidents within organizations tend to be different case-by-case, says Carnegie Mellon University's Dawn Cappelli, there are similarities and patterns that organizations can look for when mitigating their risks. What are some of the common characteristics among insiders, and how can...

  • Verisign Breached Several Times in 2010

    Company: Data Accessed, But Net Root Name Servers Unaffected Eric Chabrow - February 3, 2012
    Verisign Breached Several Times in 2010

    Verisign, operator of two of the 13 root name servers that route traffic on the Internet, has revealed that outsiders attacked its computer network several times in 2010, but top management did not learn of the incidents until September 2011.

  • Risk Management Requires Innovation

    Part 2: Professionals Thinking Outside of the Box Jeffrey Roman - February 3, 2012
    Risk Management Requires Innovation

    Risk-management professionals must think outside of the box in terms of innovation, research and development and partnerships.

  • 7 Steps to Improve Security Incident Handling

    New NIST Guidance Targets Computer Incident Response Eric Chabrow - February 2, 2012
    7 Steps to Improve Security Incident Handling

    Establishing an effective security incident response program is a key component of an information risk management strategy. And NIST has issued draft guidelines to help organizations implement such a program.

  • House Panel Approves Cybersecurity Bill

    The Precise Act Gives Lead Role to DHS on Non-Defense IT Security Eric Chabrow - February 1, 2012
    House Panel Approves Cybersecurity Bill

    Rep. Dan Lungren, the bill's chief sponsor, contends the regulatory approach taken by his bill would be less intrusive on the private sector than proposed Senate legislation and a plan by President Obama.

  • New Guidance on Payments Processing

    FDIC Stresses Due Diligence, Transaction Monitoring Tracy Kitten - February 1, 2012
    New Guidance on Payments Processing

    The FDIC has issued revised guidance describing potential risks associated with relationships to third-party payment processors. What are regulators' new risk-management expectations of banks?

  • Iran Poses Cyber-Intel Threat to U.S.

    Intel Chief: Foreign Intrusions of American Networks Go Undetected Eric Chabrow - January 31, 2012
    Iran Poses Cyber-Intel Threat to U.S.

    "Iran's intelligence operations against the United States, including cyber capabilities, have dramatically increased in recent years in depth and complexity," National Intelligence Director James Clapper says.

  • Congress to Google: Explain Yourself

    Lawmakers Questions Google's New Privacy Policy Eric Chabrow - January 31, 2012
    Congress to Google: Explain Yourself

    "These changes might not otherwise be troubling but for one significant change to your terms of service: Google will not permit users to opt out," the leaders of a House panel say in a letter to Google CEO Larry Page.

  • University Breach Lawsuit Settled

    96,000 Receiving Credit Monitoring, Restoration Services Jeffrey Roman - January 30, 2012
    University Breach Lawsuit Settled

    The University of Hawaii has agreed to settle a class action lawsuit involving data breaches affecting about 96,000. It agreed to provide those affected two years of free credit monitoring and credit restoration services.

  • Symantec: Malware Pushed onto Androids

    Downloads Raise Concerns for Organizations that Adopt BYOD Eric Chabrow - January 30, 2012
    Symantec: Malware Pushed onto Androids

    IT security provider Symantec says it identified multiple publisher identifications on the Android Market that are being used to push out Android.Counterclank, which it characterizes as a bot-like threat that can receive commands to carry out certain actions, as well as steal information from the device.

ARTICLE Human Element of Info Risk Management

People, as much as anything else, are a critical aspect of information risk management, and...

Latest Tweets and Mentions

ARTICLE Human Element of Info Risk Management

People, as much as anything else, are a critical aspect of information risk management, and...

The ISMG Network