Compliance Questions


OWA using SelfSSL and Certificate Services removal
Hey there… I am curretly running Exchange 2003 on W2k3 member server. I installed Certificate Services and produced my own certificate and all works well with OWA. I recently found out that SelfSSL is available but not quite as robust, which would probably be good. I removed Cert services and was getting ready to install [...]

Answer Question   |  August 5, 2005  12:41 PM
Application security, Certificates, Compliance, configuration, CRM, Database, Desktop security, Disaster Recovery, Encryption, Exchange, Exchange 2003, Instant Messaging, Internet Security Systems, Managed security services, Outlook, Outlook Mobile Access, patching, PEN testing, Platform Security, Policies, Risk management, Secure Coding, Security, Security management, Security products, Security Program Management, vulnerability management
asked by:
0 pts.

module moves on i5
I wanted to check on a possible solution for a problem we have run into with our module moves. Cause of audit requirements we can’t have pgmr’s in the productions systems. So as a work around I have them creating their code in sourclib on the test partition then I have operations copying it into [...]

Answer Question   |  August 3, 2005  10:40 AM
Application security, Auditing, Compliance, CRM, Database, Development, Disaster Recovery, Encryption, Exchange, Instant Messaging, Networking, Policies, Risk management, Secure Coding, Security Program Management, Tech support
asked by:
0 pts.

Block IE or Internet access with group policy
Is there any way to block Internet access with group policy? I am setting permissions for some of the machines locally to only allow certain users access to the IE executable, but that is a pain in the butt. I have: Win2k3 single domain with 2 DC’s approx 50 XP Pro workstations. I’m guessing this [...]

Answer Question   |  April 18, 2013  9:25 AM
Compliance, CRM, DataCenter, Disaster Recovery, Microsoft Windows, Networking, Policies, Risk management, Security, Security Program Management
asked by:
0 pts.

Are FIPS and other NIST InfoSec standards and criteria accepted commercially?
I know that information security decision makers and policy makers within the Federal government rely heavily on standards such as FIPS certification from the National Institute of Standards and Technology (NIST). How much weight is there placed on a product or service that has met certification requirements from NIST in non-government verticals? For example, would [...]

Answer Question   |  July 26, 2005  1:35 PM
CIO, Compliance, Financial services applications, Laws, Regulations, Security, Security management, Security products, standards, Vendors
asked by:
0 pts.

Fortinet All in One Security Appliance
Hi, Anyone familiar with Fortinet Aplliance? They claim to be leading vendore providing Firewall, IPS , Intrusion detection, VPN etc. solution in one single unit at low cost. Although our security engineer is pushing for the proiduct but i have many reservation about the integraity and fear of unknown issues that may be presented in [...]

Answer Question   |  August 24, 2005  9:24 AM
backdoors, Compliance, CRM, Current threats, Disaster Recovery, Hacking, human factors, Intrusion management, Networking, Policies, Risk management, Security, Security Program Management, Spyware, Trojans, Viruses, worms
asked by:
0 pts.

IT Tech Assistant/No Admin Rights
I have hired a new IT support person, and I wanted to give him access to restart services ex: Print services, in my absense which occasionally needs resetting. Is their a way to give someone strict access to only restart services?

Answer Question   |  July 14, 2005  2:52 PM
Auditing, Compliance, CRM, Database Management Systems, DataCenter, Disaster Recovery, Hardware, Help Desk, Information risk management, Networking, Policies, Risk management, Security management, Security Program Management, Tech support, Third-party services
asked by:
0 pts.

Certificates
I am pretty new to the 2003 Microsoft world, but I am NT 4 MCSE. My setup: 2 W2K3 DC’s 1 Exchange 2K3 member server 1 W2K3 member server–web server about 60 users–single domain some of my users want to use Outlook Web Access to get their mail from home (approx. 10-15) Everything is set [...]

Answer Question   |  July 5, 2005  11:45 AM
Compliance, CRM, DataCenter, Disaster Recovery, Information risk management, Intrusion management, Policies, Risk management, Security, Security management, Security Program Management, VPN, Vulnerability Assessment & Audit
asked by:
0 pts.

Printer problem plz help
having a printer ,connected to a LAN but it not being a net work print just it’s connected to one of the hosts on the net work and it’s shared ,then the problem with its is that at anytime it prints by it self ,and it prints some sort of code in the head of [...]

Answer Question   |  June 24, 2005  7:25 AM
Compliance, CRM, DataCenter, Desktop management applications, Disaster Recovery, Intel, LANDesk, Microsoft Systems Management Server, Networking, Policies, Risk management, Security, Security management, Security Program Management, Software Quality Assurance, Systems management software
asked by:
0 pts.

IT Strategies Info Center: Compliance
Hey everyone, I’m an assistant editor for SearchDataCenter, and was curious what our users think of the Info Center we have on compliance. Has anybody checked it out? Is it useful? Any suggestions? Are there any topics you’d like to see more coverage on? If you haven’t seen it, here’s a link: http://searchdatacenter.techtarget.com/infoCenter/0,,sid80_iid2652,00.html Thanks, and [...]

Answer Question   |  June 28, 2005  2:54 PM
California Security Breach Information Act, Can Spam Act, Compliance, Do Not Call Lists, Gramm-Leach-Bliley Act, HIPAA, ISO 17799, Laws, Regulations, Sarbanes-Oxley Act, standards, USA Patriot Act
asked by:
190 pts.

Active Dir. Web Based Password Reset Tool?
We run a native 2003 Active Directory. We have many remote users who have an AD account (without an Exchange account). Quite often we get emailed from users who are requesting password resets, or account unlocks (since we have a 5-try account lockout policy in effect on the domain). Obviously, given the size of our [...]

Answer Question   |  February 13, 2012  5:23 AM
Compliance, CRM, DataCenter, Desktop security, Disaster Recovery, IT architecture, Networking, Policies, Risk management, Security, Security management, Security Program Management, Servers, Vendors, Windows, Windows client administration and maintenance, Windows Server 2003, Windows XP
asked by:
0 pts.

SYSVOL Sharing across network concern
Good morning to all. First off, let me thank everyone for their past help and support I have received from this search2000 group. I have a concern about a folder being shared across my network called SYSVOL. I know it is related to the Domain controller and maybe for scripts that have been added. In [...]

Answer Question   |  June 7, 2005  9:51 AM
Compliance, CRM, DataCenter, Disaster Recovery, Policies, Risk management, Security, Security management, Security Program Management, Tech support
asked by:
0 pts.

Stop Error (C000021a)
I am receiving this stop error(C000021a) “windows logon process system process terminated unexpectedly” with win 2000 server. Safe mode and Last Known Good Conf. works fine. Is there any solution without reformating the HDD? I have ERD with me. Will that help me? Any advise on this would be highly appreciated. Thanks

Answer Question   |  June 23, 2008  3:29 AM
Biometrics, Call Centers, CIO, Compliance, CRM, Customer relationship management applications, Data analysis, Data center operations, Data mining/analysis, Data warehousing applications, DataCenter, Desktop management applications, Desktop security, Desktops, DHCP, Digital certificates, Disaster Recovery, DNS, E-mail applications, ERP, Exchange, Graphical User Interfaces, Hardware, Help Desk, IBM, Identity & Access Management, Implementation, Information risk management, Installation, Intel, Intel PC hardware, IT architecture, LANDesk, Microsoft Systems Management Server, Microsoft Windows, Networking, Networking Products, Networking services, Operating system platforms, PeopleSoft, Performance/Tuning, Physical security, Policies, Power management, provisioning, Registry, Risk management, Security, Security management, Security products, Security Program Management, Security tokens, Servers, Single sign-on, System utilities, Systems management software, Tech support, Third-party services, Vendor support, Vendors, Windows, Windows 2000 desktop, Windows 2000 Server, Windows client administration and maintenance
asked by:
10 pts.

asked by:
0 pts.

Resticting Members of BuiltinAdministrator to just be able to create Domain Trust
In windows 2000/2003, Can we restrict a BuiltinAdministrators member to have just enough rights so that he/she can only create/delete domain Trust. The requirement that we have is to be programmatically create trust with all the domains in a given forest. The other part of the requirement is to maintain the created trusts (i.e. recreate [...]

Answer Question   |  May 11, 2005  7:09 PM
Administration, Biometrics, Compliance, CRM, Development, Digital certificates, Disaster Recovery, Identity & Access Management, Installation, Management, Policies, provisioning, Risk management, Security, Security management, Security Program Management, Security tokens, Single sign-on
asked by:
0 pts.

Data vs. perimeter vs. network security
A short time ago, author Wes Noonan wrote some tips for SearchWindowsSecurity.com about <a href=http://searchwindowssecurity.techtarget.com/originalContent/0,289142,sid45_gci1007026,00.html>deperimeterization</a>. He explained how security is always pitted against business needs, and perimeters have become porous because businesses require traffic from SMTP, HTTP or VPNs to pass through the firewall. He then offered techniques for keeping data safe in spite of [...]

Answer Question   |  May 4, 2005  4:36 PM
Administration, Application security, Architecture/Design, backdoors, Biometrics, Compliance, configuration, CRM, Current threats, Database, Desktop vs network-based firewalls, Digital certificates, Disaster Recovery, Documentation, Encryption, Exchange, Features/Functionality, Firewalls, Forensics, Hacking, Host-based IDS/IPS, human factors, Identity & Access Management, IDS vs IPS, IDS/IPS management, Incident response, Installation, Instant Messaging, Intrusion management, Managed security services, Management, Network security, Network-based IDS/IPS, Networking, Outsourcing/Managed services, patching, PEN testing, Platform Security, Policies, Product evaluation, provisioning, Risk management, Secure Coding, Security, Security management, Security products, Security Program Management, Security tokens, Service and support, Signature updating/Management, Single sign-on, Software vs appliance, Spyware, Trojans, Viruses, VPN, Vulnerability Assessment & Audit, vulnerability management, Wireless, worms
asked by:
0 pts.

Stuck with WEP – will increasing key lengths help harden WLAN?
I have potential security issues on my wireless LAN because my equipment is older and I can?t use WPA. I’m worried that my data is vulnerable. If I increase my WEP key length from 40 to 128 or greater, will this help?

Answer Question   |  May 4, 2005  7:15 AM
Biometrics, Compliance, CRM, Digital certificates, Disaster Recovery, Identity & Access Management, Intrusion management, Policies, provisioning, Risk management, Security Program Management, Security tokens, Single sign-on
asked by:
225 pts.

A graduate student in need of help – I would like to know your professional opinion on information security.
I am graduate student at the School of Information Studies at Syracuse University and am conducting research to gather empirical data on the subject of information security. My goal is to gain a better understanding of what IT professionals believe is an adequate level of information / network security. In other words, I am seeking [...]

Answer Question   |  May 5, 2005  2:32 AM
Compliance, CRM, Disaster Recovery, Policies, Risk management, Security, Security management, Security Program Management
asked by:
0 pts.

asked by:
0 pts.

Found Trojan.ByteVerify on my computer
Hi All, Symantec recently discovered Trojan.ByteVerify on my computer. I run system checks weekly and am always cautious about the e-mails I open, the web sites I go to and what I click on, so I was pretty surprised to find I had a Trojan. It was quarantined and removed, but I’m worried about what [...]

Answer Question   |  June 24, 2010  10:20 AM
Administration, Architecture/Design, backdoors, Compliance, configuration, CRM, Current threats, Disaster Recovery, Documentation, Features/Functionality, Firewalls, Forensics, Hacking, human factors, IDS/IPS management, Incident response, Installation, Intrusion management, Management, Network security, patching, PEN testing, Platform Security, Policies, Risk management, Security, Security Program Management, Service and support, Signature updating/Management, Spyware, Trojans, Viruses, VPN, vulnerability management, Wireless, worms
asked by:
0 pts.

Internet Explorer vs. Firefox
Hello, I’m the Assistant Editor on SearchWindowsSecurity.com. I’m looking to start a discussion about what browser people are using and why. Also, is anyone considering switching from IE to Firefox, or are your plans to stay with IE? Here’s some food for thought… As of Feb. 2005, an estimated 35 million users had switched from [...]

Answer Question   |  June 29, 2012  2:14 PM
Addamark, Administration, Aladdin Knowledge Systems, Application security, AppSec, Architecture/Design, ArcSight, Bindview, Biometrics, Caymas, CipherTrust, Compliance, Computer Associates, configuration, Courion, CRM, Cylant, Database, DataCenter, Desktop management applications, Desktops, Digital certificates, Disaster Recovery, Documentation, e-Security, Emerging technologies, Encryption, Enterasys Networks, Entrust, Exchange, Features/Functionality, GuardedNet, Hardware, Host-based IDS/IPS, IBM/Tivoli, Identity & Access Management, IDS vs IPS, IDS/IPS management, Imprivata, Installation, Instant Messaging, Intellitactics, Internet Security Systems, Intrusion management, Juniper Networks, KavaDo, M-Tech, Magnifire, Managed security services, Management, Maxware, Microsoft Windows, Netegrity, NetForensics, NetIQ, Network Associates, Network-based IDS/IPS, NFR Security, NGS Software, Novell, Ounce Labs, Outsourcing, Outsourcing/Managed services, Passlogix, patching, PEN testing, Platform Security, Policies, Product evaluation, Product/Service evaluation, provisioning, Risk management, RSA Security, Sana Security, Secure Coding, Security, Security management, Security Program Management, Security tokens, Servers, Service and support, Service contracts, Service evaluation, Single sign-on, Snort/Sourcefire, SPI Dynamics, StillSecure, Tech support, Teros, Thor, Tripwire, TruSecure, Vendors, VeriSign, VPN, VSecure, Vulnerability Assessment & Audit, vulnerability management, Watchfire, Waveset/Sun Micro, Windows, Windows XP
asked by:
0 pts.