 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Answers &#187; Vulnerability Assessment &amp; Audit</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/tag/security/vulnerability-assessment-audit/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers</link>
	<description></description>
	<lastBuildDate>Thu, 23 May 2013 10:00:33 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Website monitoring suggestions?</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/website-monitoring-suggestions/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/website-monitoring-suggestions/#comments</comments>
		<pubDate>Thu, 16 Dec 2010 21:21:55 +0000</pubDate>
		<dc:creator>NewnanIT</dc:creator>
				<category><![CDATA[Network security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Vulnerability Assessment & Audit]]></category>
		<category><![CDATA[Website maintenance]]></category>
		<category><![CDATA[Website security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Question Edited by MTidmarsh]]></description>
				<content:encoded><![CDATA[Question Edited by MTidmarsh]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/website-monitoring-suggestions/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security advisories</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/security-advisories/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/security-advisories/#comments</comments>
		<pubDate>Thu, 24 Sep 2009 14:50:34 +0000</pubDate>
		<dc:creator>Michael Morisy</dc:creator>
				<category><![CDATA[Application security]]></category>
		<category><![CDATA[Vulnerability Assessment & Audit]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Does a security research firms track record of vulnerabilities and exploits published make you trust them more, or more likely to hire them?]]></description>
				<content:encoded><![CDATA[<p>Does a security research firms track record of vulnerabilities and exploits published make you trust them more, or more likely to hire them?</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/security-advisories/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Shares Baseline Security Information</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/shares-baseline-security-information/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/shares-baseline-security-information/#comments</comments>
		<pubDate>Fri, 05 Aug 2005 06:02:19 +0000</pubDate>
		<dc:creator>ITAudit</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[configuration]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[PEN testing]]></category>
		<category><![CDATA[Platform Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security products]]></category>
		<category><![CDATA[Vulnerability Assessment & Audit]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Hello, I use the Microsoft Baseline Security Analyser 2.0 to retrive information about shares in some local servers. I can not understand the diference between the information give in the report, about authorizations in the column Share ACL and Directory ACL. If some one can help me, Thank you PPG]]></description>
				<content:encoded><![CDATA[<p>Hello,</p>
<p>I use the Microsoft Baseline Security Analyser 2.0 to retrive information about shares in some local servers. </p>
<p>I can not understand the diference between the information give in the report, about authorizations in the column Share ACL and Directory ACL.</p>
<p>If some one can help me,</p>
<p>Thank you<br />
PPG</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/shares-baseline-security-information/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>aaa authorization ?</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/aaa-authorization/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/aaa-authorization/#comments</comments>
		<pubDate>Fri, 22 Jul 2005 09:45:56 +0000</pubDate>
		<dc:creator>EngineerIT</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Application security]]></category>
		<category><![CDATA[Architecture/Design]]></category>
		<category><![CDATA[Biometrics]]></category>
		<category><![CDATA[Cabling]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Data analysis]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Desktop vs network-based firewalls]]></category>
		<category><![CDATA[Digital certificates]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Features/Functionality]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Hubs]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[Instant Messaging]]></category>
		<category><![CDATA[Intrusion management]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Product/Service evaluation]]></category>
		<category><![CDATA[provisioning]]></category>
		<category><![CDATA[Routers]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security tokens]]></category>
		<category><![CDATA[Service and support]]></category>
		<category><![CDATA[Single sign-on]]></category>
		<category><![CDATA[Switches]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Vulnerability Assessment & Audit]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Which of the following authorization commands are valid? (we have to choose 2 correct) A. aaa authentication exec home radius B. aaa accounting exec home radius C. aaa authorization default none D. aaa authorization exec home radius E. aaa authorization network default enable F. aaa authorization network default local]]></description>
				<content:encoded><![CDATA[<p>Which of the following authorization commands are valid? (we have to choose 2 correct)</p>
<p>A. aaa authentication exec home radius<br />
B. aaa accounting exec home radius<br />
C. aaa authorization default none<br />
D. aaa authorization exec home radius<br />
E. aaa authorization network default enable<br />
F. aaa authorization network default local</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/aaa-authorization/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IM Blocking and URL Filtering</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/im-blocking-and-url-filtering/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/im-blocking-and-url-filtering/#comments</comments>
		<pubDate>Thu, 07 Jul 2005 03:18:13 +0000</pubDate>
		<dc:creator>EngineerIT</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Application security]]></category>
		<category><![CDATA[Architecture/Design]]></category>
		<category><![CDATA[Availability]]></category>
		<category><![CDATA[Benchmarking]]></category>
		<category><![CDATA[Biometrics]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Digital certificates]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Features/Functionality]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Host-based IDS/IPS]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[IDS/IPS management]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[Instant Messaging]]></category>
		<category><![CDATA[Internet Security Systems]]></category>
		<category><![CDATA[Intrusion management]]></category>
		<category><![CDATA[Managed security services]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Network monitoring]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[Network testing]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Protocol analysis]]></category>
		<category><![CDATA[provisioning]]></category>
		<category><![CDATA[Routers]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security tokens]]></category>
		<category><![CDATA[Service and support]]></category>
		<category><![CDATA[Service contracts]]></category>
		<category><![CDATA[Service evaluation]]></category>
		<category><![CDATA[Single sign-on]]></category>
		<category><![CDATA[TCP]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Vulnerability Assessment & Audit]]></category>
		<category><![CDATA[Wireless]]></category>
		<category><![CDATA[Yahoo]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[We have Pix515E which is gateway to Internet. We also got IWSS Proxy(Trend Micro) along with URL filtering module. Domain users get directed to IWSS proxy (GPO settings) and restrictions about URL filterings can be imposed as per company&#8217;s policy. Those users who are not on the domain, they can not get GPO settings and [...]]]></description>
				<content:encoded><![CDATA[<p>We have Pix515E which is gateway to Internet.<br />
We also got IWSS Proxy(Trend Micro) along with URL filtering module.<br />
Domain users get directed to IWSS proxy (GPO settings) and restrictions about URL filterings can be imposed as per company&#8217;s policy.<br />
Those users who are not on the domain, they can not get GPO settings and they do not get IWSS as there proxy. Hence they can browse any site they want.<br />
My question is how to restrict the browsing for those users who are not on the domain.<br />
Is it possible to redirect all HTTP traffic to IWSS to check before it is out?<br />
Or is there any other way to solve this issue?</p>
<p>2nd MAJOR problem is: blocking MSN messanger and Yahoo messanger in the company&#8217;s network&#8230;.<br />
If we are blocking one particualr port, it still works&#8230;<br />
MSN messenger to be blocked for domain users and for other users who are not on the domain.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/im-blocking-and-url-filtering/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Certificates</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/certificates/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/certificates/#comments</comments>
		<pubDate>Wed, 29 Jun 2005 11:45:40 +0000</pubDate>
		<dc:creator>TheVyrys</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[CRM]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Information risk management]]></category>
		<category><![CDATA[Intrusion management]]></category>
		<category><![CDATA[Policies]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Vulnerability Assessment & Audit]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I am pretty new to the 2003 Microsoft world, but I am NT 4 MCSE. My setup: 2 W2K3 DC&#8217;s 1 Exchange 2K3 member server 1 W2K3 member server&#8211;web server about 60 users&#8211;single domain some of my users want to use Outlook Web Access to get their mail from home (approx. 10-15) Everything is set [...]]]></description>
				<content:encoded><![CDATA[<p>I am pretty new to the 2003 Microsoft world, but I am NT 4 MCSE.<br />
My setup:<br />
2 W2K3 DC&#8217;s<br />
1 Exchange 2K3 member server<br />
1 W2K3 member server&#8211;web server<br />
about 60 users&#8211;single domain</p>
<p>some of my users want to use Outlook Web Access to get their mail from home (approx. 10-15)</p>
<p>Everything is set up and running fine.<br />
My question is, do I need Certificates to be secure? with this small amount of users it hardly seems necessary, but being new to the 2003 world, I just don&#8217;t know.<br />
If I do need certificates, can I do them myself without ANY other vendors involved?</p>
<p>Thanks to all of you for helping us and each other out&#8230;this is a great website.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/certificates/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Files and directory access loging</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/files-and-directory-access-loging/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/files-and-directory-access-loging/#comments</comments>
		<pubDate>Tue, 28 Jun 2005 12:51:20 +0000</pubDate>
		<dc:creator>Zbanoon</dc:creator>
				<category><![CDATA[Auditing]]></category>
		<category><![CDATA[IT auditing software]]></category>
		<category><![CDATA[Vulnerability Assessment & Audit]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[one of my clients is asking about a daily report contains all files and directories accessed every day and who is accessing it (time and mode:delete ,read ,write.) on a spicific share. so i tried using a script to filter out all events regarding files access but that looks time consuming method . so please [...]]]></description>
				<content:encoded><![CDATA[<p>one of my clients is asking about a daily report contains all files and directories accessed every day and who is accessing it (time and mode:delete ,read ,write.) on a spicific share.<br />
so i tried using a script to filter out all events regarding files access but that looks time consuming method .<br />
so please if any one have a better idea or  a software name.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/files-and-directory-access-loging/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>ping from outside</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/ping-from-outside/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/ping-from-outside/#comments</comments>
		<pubDate>Fri, 13 May 2005 00:51:35 +0000</pubDate>
		<dc:creator>Redrose</dc:creator>
				<category><![CDATA[Application security]]></category>
		<category><![CDATA[Biometrics]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[CRM]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Digital certificates]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Ethernet]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Instant Messaging]]></category>
		<category><![CDATA[Intrusion management]]></category>
		<category><![CDATA[IPv4]]></category>
		<category><![CDATA[Network Interface Cards]]></category>
		<category><![CDATA[Network Management Systems]]></category>
		<category><![CDATA[Network testing]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Networking Equipment]]></category>
		<category><![CDATA[Policies]]></category>
		<category><![CDATA[provisioning]]></category>
		<category><![CDATA[QoS]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Routers]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Security tokens]]></category>
		<category><![CDATA[Servers]]></category>
		<category><![CDATA[Single sign-on]]></category>
		<category><![CDATA[TCP]]></category>
		<category><![CDATA[Tech support]]></category>
		<category><![CDATA[Vulnerability Assessment & Audit]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[hi, could you please tell me which command in cisco routers prevent them from being ping from outside networks. and also how can i prevent terminals inside a network to ping outside ips(group policies etc??). thanks]]></description>
				<content:encoded><![CDATA[<p>hi,<br />
    could you please tell me which command in cisco routers prevent them from being ping from outside networks. and also how can i prevent terminals inside a network to ping outside ips(group policies etc??).</p>
<p>   thanks</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/ping-from-outside/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Data vs. perimeter vs. network security</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/data-vs-perimeter-vs-network-security/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/data-vs-perimeter-vs-network-security/#comments</comments>
		<pubDate>Wed, 04 May 2005 16:36:33 +0000</pubDate>
		<dc:creator>RobynLorusso23</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Application security]]></category>
		<category><![CDATA[Architecture/Design]]></category>
		<category><![CDATA[backdoors]]></category>
		<category><![CDATA[Biometrics]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[configuration]]></category>
		<category><![CDATA[CRM]]></category>
		<category><![CDATA[Current threats]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Desktop vs network-based firewalls]]></category>
		<category><![CDATA[Digital certificates]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Features/Functionality]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Host-based IDS/IPS]]></category>
		<category><![CDATA[human factors]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[IDS vs IPS]]></category>
		<category><![CDATA[IDS/IPS management]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[Instant Messaging]]></category>
		<category><![CDATA[Intrusion management]]></category>
		<category><![CDATA[Managed security services]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[Network-based IDS/IPS]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Outsourcing/Managed services]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[PEN testing]]></category>
		<category><![CDATA[Platform Security]]></category>
		<category><![CDATA[Policies]]></category>
		<category><![CDATA[Product evaluation]]></category>
		<category><![CDATA[provisioning]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security products]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Security tokens]]></category>
		<category><![CDATA[Service and support]]></category>
		<category><![CDATA[Signature updating/Management]]></category>
		<category><![CDATA[Single sign-on]]></category>
		<category><![CDATA[Software vs appliance]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Vulnerability Assessment & Audit]]></category>
		<category><![CDATA[vulnerability management]]></category>
		<category><![CDATA[Wireless]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[A short time ago, author Wes Noonan wrote some tips for SearchWindowsSecurity.com about &#60;a href=http://searchwindowssecurity.techtarget.com/originalContent/0,289142,sid45_gci1007026,00.html&#62;deperimeterization&#60;/a&#62;. He explained how security is always pitted against business needs, and perimeters have become porous because businesses require traffic from SMTP, HTTP or VPNs to pass through the firewall. He then offered techniques for keeping data safe in spite of [...]]]></description>
				<content:encoded><![CDATA[<p>A short time ago, author Wes Noonan wrote some tips for SearchWindowsSecurity.com about &lt;a href=http://searchwindowssecurity.techtarget.com/originalContent/0,289142,sid45_gci1007026,00.html&gt;deperimeterization&lt;/a&gt;. He explained how security is always pitted against business needs, and perimeters have become porous because businesses require traffic from SMTP, HTTP or VPNs to pass through the firewall. He then offered techniques for keeping data safe in spite of the activity at your perimeter.</p>
<p>I realize you have a variety of options when it comes to choosing a Windows line of defense, but I&#8217;m trying to get a sense of how many people actually lock down Windows at the data level. Do you invest most of your protection efforts at the data, perimeter or network level? What measures do you take to keep your Windows data secure even if the perimeter is compromised? Do you have data protection plans or products in place?</p>
<p>Another issue is that networks and applications are often treated as separate entities that never interact. This may be because they have different people maintaining them, unique security policies, etc. Is this the case in your shop? </p>
<p>I&#8217;m collecting this information for possible technical tips or a trends article on SearchWindowsSecurity.com. </p>
<p>Thanks for your time and attention. I hope to hear from you soon.</p>
<p>Best regards,<br />
Robyn Lorusso<br />
Editor<br />
SearchWindowsSecurity.com</p>
<p>http://searchwindowssecurity.techtarget.com/</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/data-vs-perimeter-vs-network-security/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Is Windows security an afterthought?</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/is-windows-security-an-afterthought/</link>
		<comments>http://itknowledgeexchange.techtarget.com/itanswers/is-windows-security-an-afterthought/#comments</comments>
		<pubDate>Tue, 19 Apr 2005 15:00:40 +0000</pubDate>
		<dc:creator>RobynLorusso23</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Application security]]></category>
		<category><![CDATA[Architecture/Design]]></category>
		<category><![CDATA[backdoors]]></category>
		<category><![CDATA[Biometrics]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[configuration]]></category>
		<category><![CDATA[CRM]]></category>
		<category><![CDATA[Current threats]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Digital certificates]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[Features/Functionality]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[human factors]]></category>
		<category><![CDATA[Identity & Access Management]]></category>
		<category><![CDATA[IDS/IPS management]]></category>
		<category><![CDATA[Incident response]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[Instant Messaging]]></category>
		<category><![CDATA[Intrusion management]]></category>
		<category><![CDATA[Managed security services]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[PEN testing]]></category>
		<category><![CDATA[Platform Security]]></category>
		<category><![CDATA[Policies]]></category>
		<category><![CDATA[Product evaluation]]></category>
		<category><![CDATA[Product/Service evaluation]]></category>
		<category><![CDATA[provisioning]]></category>
		<category><![CDATA[Remote users]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Secure Coding]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security management]]></category>
		<category><![CDATA[Security products]]></category>
		<category><![CDATA[Security Program Management]]></category>
		<category><![CDATA[Security tokens]]></category>
		<category><![CDATA[Service and support]]></category>
		<category><![CDATA[Signature updating/Management]]></category>
		<category><![CDATA[Single sign-on]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Trojans]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[Vulnerability Assessment & Audit]]></category>
		<category><![CDATA[vulnerability management]]></category>
		<category><![CDATA[Wireless]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[As the editor of SearchWindowsSecurity.com, I often speak with users about their Windows security responsibilities. One senior systems analyst in particular sent me an interesting note recently&#8230; To give you some background, he&#8217;s in charge of configuring and administering desktop systems (primarily Win2000 and XP)for a large company, and he developed many of the security [...]]]></description>
				<content:encoded><![CDATA[<p>As the editor of SearchWindowsSecurity.com, I often speak with users about their Windows security responsibilities. One senior systems analyst in particular sent me an interesting note recently&#8230; To give you some background, he&#8217;s in charge of configuring and administering desktop systems (primarily Win2000 and XP)for a large company, and he developed many of the security policies and procedures in place for those desktops. However, even with those seemingly important tasks on his plate, he said he took over Windows security only because no one else had. </p>
<p>He specifically said: &#8220;I ended up taking over the security functions because no one else was looking after them. I&#8217;ve learned a lot (enough to know there&#8217;s so much more to learn), earned my CISSP and started specializing in MS Windows security. I never really set out to do that though.&#8221;</p>
<p>Does this sound familiar to you? Were you recently or temporarily assigned Windows security responsibilities because they weren&#8217;t being handled? Did you choose to take over Windows security on your own? How long have you been working at it, or plan to?</p>
<p>Any feedback is appreciated. I will include comments in a story for SearchWindowsSecurity.com. I&#8217;m just trying to get a sense of how people got into the Windows security field, how long they&#8217;ve been in charge of securing Windows systems and if they plan to stay there. </p>
<p>You may contact me publicly or privately. Thanks for your time and attention!</p>
<p>Best regards,<br />
Robyn Lorusso<br />
Editor<br />
SearchWindowsSecurity.com</p>
<p>http://searchwindowssecurity.techtarget.com/</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/itanswers/is-windows-security-an-afterthought/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/22 queries in 0.033 seconds using memcached
Object Caching 1611/1729 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-23 12:36:58 -->