Risk management Questions


Reporting domain/workgroup membership on your LAN using PERL
This is more of an FYI. I just posted a perl script that I use to generate a daily report of all Workstations and Servers located on our LAN. This report is sorted by domain/workgroup membership and includes any visible shares on the machine. If anyone is interested you can read it here: http://frankenrouter.homeip.net/System+Admin+Articles/111.aspx Thanks, [...]

Answer Question   |  August 23, 2005  12:13 PM
Active Directory, Compliance, CRM, Desktops, DHCP, Disaster Recovery, DNS, Ethernet, IPv4, Lotus Domino, NetBIOS, Networking, Networking services, Policies, Risk management, Security, Security Program Management, Vulnerability Assessment & Audit
asked by:
0 pts.

Secure Email Delivery Applications
I am currently searching for the best application or service to provide end to end security for delivering encrypted emails from one company to another accross the Internet. I need the solutions to provide Smime, PGP, TLS, SSL, etc. My goal is to some how have the app or user decide if the email needs [...]

Answer Question   |  March 4, 2005  9:21 AM
Application security, Compliance, CRM, Database, Disaster Recovery, E-mail applications, Encryption, Exchange, Instant Messaging, Policies, Risk management, Secure Coding, Security, Security Program Management
asked by:
0 pts.

iseries Client Access does not allow third parties applications to open the login screen to change password when it’s expired.
Hello all: I will apreciate any help about this problem. I am a system administrator (mainly Active Directory) now dealing with this ISeries Client Access Problem in my 400 workstations. There are e few applications in the company, developed in FoxPro and Visual Basic, accesing the AS/400 (now a new 810) throwh ODBC. With older [...]

Answer Question   |  October 20, 2009  7:41 PM
AS/400, Compliance, CRM, Disaster Recovery, Policies, Risk management, Security Program Management
asked by:
0 pts.

ChoicePoint CISO says breach not an information security issue
The CISO of ChoicePoint says the theft of private information on 145,000 from its databases isn’t an information security issue because conmen used fraud, not hacking tools or techniques, to get the information. Anyone agree with that? Check it out: http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1062076,00.html

Answer Question   |  March 8, 2005  5:29 PM
Compliance, CRM, Disaster Recovery, Policies, Risk management, Security, Security Program Management
asked by:
0 pts.

Authorization in MIGO
I would like to grant a user authorization to object S_TCODE MIGO (Goods Receipt specifically for Purchase Order (movement type 101) where they could then enter any related data but restrict their activity to HOLD. A subsequent user would have the authorization to POST the document. I have checked SU24 but fail to see any [...]

Answer Question   |  February 27, 2005  1:52 PM
Application security, Biometrics, Compliance, CRM, Database, Development, Digital certificates, Disaster Recovery, Encryption, Exchange, Identity & Access Management, Instant Messaging, Policies, provisioning, Risk management, Secure Coding, Security Program Management, Security tokens, Single sign-on
asked by:
0 pts.

asked by:
0 pts.

asked by:
0 pts.

asked by:
10 pts.

Data Visibility in RBAC and Rule-based systems issues
Actually, I have two questions: 1) are there known solutions of how to control access to data ( database records ) in RBAC system where business policy states, e.g., that data belonds to the users in certain geographical are may be viewed by users located in the same area? This is quite actual issue for [...]

Answer Question   |  January 16, 2005  2:28 PM
Biometrics, Compliance, CRM, Digital certificates, Disaster Recovery, Identity & Access Management, Information risk management, Policies, provisioning, Risk management, Security, Security management, Security products, Security Program Management, Security tokens, Single sign-on
asked by:
0 pts.

Security COncern, Files deleted from Server
Good morning to all, and hope everyone is dooing well. I have a security issue, and need help solving this. Someone in my company within Engineering staff deleted an entire group of folders. Unfortunately it was on a project that ended, and it was discovered this morning. I have luckily a back up tape of [...]

Answer Question   |  January 24, 2005  10:21 AM
Auditing, Compliance, CRM, DataCenter, Disaster Recovery, Hardware, Intrusion management, Managed security services, Policies, Risk management, Security, Security management, Security Program Management
asked by:
0 pts.

Access to security log in Windows 2000
In my company we want to give full access to the security log of Windows 2000 only to the security manager, but we want to give only read access to the support people, Is there how to do it ?

Answer Question   |  January 12, 2005  3:29 PM
Biometrics, Compliance, configuration, CRM, DataCenter, Digital certificates, Disaster Recovery, Identity & Access Management, Managed security services, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Security, Security management, Security Program Management, Security tokens, Single sign-on, Tech support, vulnerability management
asked by:
0 pts.

DOS attack, DNS question
My question has two parts, first: today at the place where i work we lost the internet, and after checking the firewall (sonicwall, this is a non profit organization so they cant afford the best stuff) i discovered it was more than likely a DOS attack. nobody could access the internet, and i could not [...]

Answer Question   |  January 13, 2005  6:07 PM
Compliance, configuration, CRM, Disaster Recovery, Firewalls, Forensics, Incident response, Information risk management, Intrusion management, IT architecture, Managed security services, Network security, Networking, patching, PEN testing, Platform Security, Policies, Product/service procurement, Risk management, Security, Security management, Security products, Security Program Management, Tech support, VPN, vulnerability management, Wireless
asked by:
0 pts.

Restricted access to win XP professional
I have a small WORKGROUP with windows 2000 server and 5 windows XP professional systems. All computers can read/write each other. Now I want to make one XP client secure/restric access, so that no other computer can access that except only other XP computer. How can I do that? Please advise. Thanks in advance!

Answer Question   |  December 29, 2004  2:48 AM
Administration, Application security, Compliance, CRM, Database, DataCenter, Desktop management applications, DHCP, Disaster Recovery, DNS, Encryption, Exchange, Firewalls, Forensics, Help Desk, Implementation, Incident response, Information risk management, Instant Messaging, Intrusion management, Management, Network monitoring, Network security, Networking, Networking services, Physical security, Policies, Remote management, Remote users, Risk management, Secure Coding, Security, Security management, Security Program Management, Servers, System utilities, Tech support, Third-party services, VPN, Windows, Windows 2000 Server, Wireless
asked by:
10 pts.

Information Security
1. Could you please send me a portal policy template as we are about to rollout same. Thanks 2. Please send me FTP policy template. I wil then customize it to our environment

Answer Question   |  December 16, 2004  6:53 AM
Compliance, CRM, Disaster Recovery, Incident response, Policies, Risk management, Security, Security Program Management
asked by:
0 pts.

Lost QSECOFR Password and DST QSECOFR is disabled.
I have a 170 at V5R1 and I have lost the QSECOFR password, and the DST QSECOFR has been disabled. I do have access to other DST profiles and can access SST, which allow me to modify the MI code if I wish. Anybody have any suggestions as to how I can regain access to [...]

Answer Question   |  March 12, 2010  5:10 PM
Compliance, CRM, Disaster Recovery, Policies, Risk management, Security Program Management
asked by:
0 pts.

Network UserID Creation/Change
Looking for White Papers, Best Practices, Your Practice…on UserIDs What should a Network UserID look like for strong security? I don’t believe it should contain any part of the user’s legal name. Agree? So what do you use to create a UserID? Should a user be able to change their UserID? Thanks for your input.

Answer Question   |  September 27, 2004  11:46 AM
Administration, Architecture/Design, Biometrics, Compliance, CRM, Digital certificates, Disaster Recovery, Identity & Access Management, Management, Policies, provisioning, Risk management, Security management, Security Program Management, Security tokens, Service and support, Single sign-on
asked by:
0 pts.

Wireless Security
We are running an NT4 network in one building with about 50 users. I have recently installed a LinkSys WAP with a 32-bit WEP encryption key, so when our sales guys come in with their Thinkpads, they don’t have to fight for network points. I have programmed the encryption key into their laptops, so they [...]

Answer Question   |  November 22, 2004  9:00 AM
Compliance, CRM, Disaster Recovery, Intrusion management, Policies, Risk management, Security Program Management
asked by:
0 pts.