Security Wire Weekly http://itknowledgeexchange.techtarget.com/security-wire-weekly The cybersecurity industry’s premier podcasts featuring the latest information security news, interviews and information. Thu, 24 May 2012 20:29:36 +0000 http://wordpress.org/?v=2.6.2 en ©SearchSecurity.com editor@searchsecurity.com (SearchSecurity.com) editor@searchsecurity.com(SearchSecurity.com) cybersecurity news 1440 Security, Information Security, Security flaws, security vulnerabilities, hacking techniques, hackers, security compliance, data security breach A SearchSecurity.com Podcast Information security news and interviews with information security experts and professionals. SearchSecurity.com SearchSecurity.com editor@searchsecurity.com No no http://media.techtarget.com/digitalguide/images/podcast/sSec_sww.jpg Security Wire Weekly http://itknowledgeexchange.techtarget.com/security-wire-weekly 144 144 P2P encryption for mobile is not an endorsement, says PCI Council http://itknowledgeexchange.techtarget.com/security-wire-weekly/p2p-encryption-for-mobile-is-not-an-endorsement-says-pci-council/ http://itknowledgeexchange.techtarget.com/security-wire-weekly/p2p-encryption-for-mobile-is-not-an-endorsement-says-pci-council/#comments Thu, 24 May 2012 19:44:12 +0000 Robert Westervelt http://itknowledgeexchange.techtarget.com/security-wire-weekly/p2p-encryption-for-mobile-is-not-an-endorsement-says-pci-council/ The PCI Security Standards Council recently urged merchants to use certified point-to-point encryption hardware when swiping credit card payments with a mobile device. But Bob Russo, general manager of the PCI SSC insists that the PCI Council is not endorsing the technology. In this interview, Russo discusses the state of the PCI special interest groups (SIGs) and addresses why no Mobile SIG exists.

]]>
http://itknowledgeexchange.techtarget.com/security-wire-weekly/p2p-encryption-for-mobile-is-not-an-endorsement-says-pci-council/feed/ 10:45 The PCI Security Standards Council recently urged merchants to use certified point-to-point encryption hardware when swiping credit card payments with a mobile device. But Bob ... The PCI Security Standards Council recently urged merchants to use certified point-to-point encryption hardware when swiping credit card payments with a mobile device. But Bob Russo, general manager of the PCI SSC insists that the PCI Council is not endorsing the technology. In this interview, Russo discusses the state of the PCI special interest groups (SIGs) and addresses why no Mobile SIG exists. PCI,DSS,,PCI,SSC,,mobile,device,security,risks,,mobile,security,,Mobile,platform,security SearchSecurity.com no No
Costly business logic flaws require manual testing http://itknowledgeexchange.techtarget.com/security-wire-weekly/costly-business-logic-flaws-require-manual-testing/ http://itknowledgeexchange.techtarget.com/security-wire-weekly/costly-business-logic-flaws-require-manual-testing/#comments Tue, 08 May 2012 19:11:32 +0000 Robert Westervelt http://itknowledgeexchange.techtarget.com/security-wire-weekly/?p=1034 Business logic flaws are costly to detect but even more costly if they are exploited, says application security expert Dan Kuykendall, CTO of NTOBJECTives Inc. Manual testing can detect the issues before cybercriminals can take advantage of the flawed functionality.

]]>
http://itknowledgeexchange.techtarget.com/security-wire-weekly/costly-business-logic-flaws-require-manual-testing/feed/ 20:35 Business logic flaws are costly to detect but even more costly if they are exploited, says application security expert Dan Kuykendall, CTO of NTOBJECTives Inc. ... Business logic flaws are costly to detect but even more costly if they are exploited, says application security expert Dan Kuykendall, CTO of NTOBJECTives Inc. Manual testing can detect the issues before cybercriminals can take advantage of the flawed functionality. web,application,security,,Security,Wire,Weekly,,secure,software,development SearchSecurity.com no No
2012 Verizon DBIR lessons overshadowed by hype http://itknowledgeexchange.techtarget.com/security-wire-weekly/2012-verizon-dbir-lessons-overshadowed-by-hype/ http://itknowledgeexchange.techtarget.com/security-wire-weekly/2012-verizon-dbir-lessons-overshadowed-by-hype/#comments Wed, 25 Apr 2012 20:40:57 +0000 Robert Westervelt http://itknowledgeexchange.techtarget.com/security-wire-weekly/2012-verizon-dbir-lessons-overshadowed-by-hype/ In this edition of Security Squad, the editors discusses the 2012 Verizon DBIR findings that have been hyped and misconstrued and why only 8% of organizations make a breach discovery with internal technologies. Also, a discussion on how the message delivered at a recent conference by several security luminaries fell flat.

]]>
http://itknowledgeexchange.techtarget.com/security-wire-weekly/2012-verizon-dbir-lessons-overshadowed-by-hype/feed/ 26:47 In this edition of Security Squad, the editors discusses the 2012 Verizon DBIR findings that have been hyped and misconstrued and why only 8% of ... In this edition of Security Squad, the editors discusses the 2012 Verizon DBIR findings that have been hyped and misconstrued and why only 8% of organizations make a breach discovery with internal technologies. Also, a discussion on how the message delivered at a recent conference by several security luminaries fell flat. Verizon,DBIR,2012,,Security,Wire,Weekly,,Security,Squad SearchSecurity.com no No
Mobile device security policy essential to BYOD security http://itknowledgeexchange.techtarget.com/security-wire-weekly/mobile-device-security-policy-essential-to-byod-security/ http://itknowledgeexchange.techtarget.com/security-wire-weekly/mobile-device-security-policy-essential-to-byod-security/#comments Thu, 12 Apr 2012 20:11:36 +0000 Robert Westervelt http://itknowledgeexchange.techtarget.com/security-wire-weekly/mobile-device-security-policy-essential-to-byod-security/ Do you think you need a mobile device management platform? Think again, said Darrin Reynolds, vice president of information security at Diversified Agency Services. A formal policy should come first. Reynolds explains that security essentials can be done with existing systems.

]]>
http://itknowledgeexchange.techtarget.com/security-wire-weekly/mobile-device-security-policy-essential-to-byod-security/feed/ 15:03 Do you think you need a mobile device management platform? Think again, said Darrin Reynolds, vice president of information security at Diversified Agency Services. A ... Do you think you need a mobile device management platform? Think again, said Darrin Reynolds, vice president of information security at Diversified Agency Services. A formal policy should come first. Reynolds explains that security essentials can be done with existing systems. mobile,device,protection,,Security,Wire,Weekly,,mobile,device,security,,mobile,security SearchSecurity.com no No
Expert advocates for more effective penetration tests http://itknowledgeexchange.techtarget.com/security-wire-weekly/expert-advocates-for-more-effective-penetration-tests/ http://itknowledgeexchange.techtarget.com/security-wire-weekly/expert-advocates-for-more-effective-penetration-tests/#comments Tue, 03 Apr 2012 12:47:43 +0000 Robert Westervelt http://itknowledgeexchange.techtarget.com/security-wire-weekly/expert-advocates-for-more-effective-penetration-tests/ Dave Kennedy, CSO of Diebold Inc. and a noted penetration tester talks about the need for enterprises to have more effective penetration tests and to stop buying the latest security technology. It doesn’t work, he told attendees at the 2012 InfoSec World Conference and Expo. Kennedy said businesses should base their pen testing requirements from the Penetration Testing Execution Standard (PTES) and hold pen testers responsible for meeting the standard.

]]>
http://itknowledgeexchange.techtarget.com/security-wire-weekly/expert-advocates-for-more-effective-penetration-tests/feed/ 18:09 Dave Kennedy, CSO of Diebold Inc. and a noted penetration tester talks about the need for enterprises to have more effective penetration tests and to ... Dave Kennedy, CSO of Diebold Inc. and a noted penetration tester talks about the need for enterprises to have more effective penetration tests and to stop buying the latest security technology. It doesn't work, he told attendees at the 2012 InfoSec World Conference and Expo. Kennedy said businesses should base their pen testing requirements from the Penetration Testing Execution Standard (PTES) and hold pen testers responsible for meeting the standard. security,spending,,Security,Wire,Weekly,,pen,testing SearchSecurity.com no No
Is your firm reviewing your logs? SIEM’s second life http://itknowledgeexchange.techtarget.com/security-wire-weekly/is-your-firm-reviewing-your-logs-siems-second-life/ http://itknowledgeexchange.techtarget.com/security-wire-weekly/is-your-firm-reviewing-your-logs-siems-second-life/#comments Thu, 29 Mar 2012 14:46:17 +0000 Robert Westervelt http://itknowledgeexchange.techtarget.com/security-wire-weekly/is-your-firm-reviewing-your-logs-siems-second-life/ Chris Petersen founder and CTO of LogRhythm talks about the SIEM market, the challenges for enterprises to get beyond compliance and shares his thoughts on the future of SIEM with deeper analytics. The interview was conducted last month at RSA Conference 2012.

]]>
http://itknowledgeexchange.techtarget.com/security-wire-weekly/is-your-firm-reviewing-your-logs-siems-second-life/feed/ 15:56 Chris Petersen founder and CTO of LogRhythm talks about the SIEM market, the challenges for enterprises to get beyond compliance and shares his thoughts on ... Chris Petersen founder and CTO of LogRhythm talks about the SIEM market, the challenges for enterprises to get beyond compliance and shares his thoughts on the future of SIEM with deeper analytics. The interview was conducted last month at RSA Conference 2012. SIEM,,Security,Wire,Weekly,,Log,management SearchSecurity.com no No
Verizon DBIR 2012 overview, attack mitigation strategies http://itknowledgeexchange.techtarget.com/security-wire-weekly/verizon-dbir-2012-overview-attack-mitigation-strategies/ http://itknowledgeexchange.techtarget.com/security-wire-weekly/verizon-dbir-2012-overview-attack-mitigation-strategies/#comments Thu, 22 Mar 2012 19:35:53 +0000 Robert Westervelt http://itknowledgeexchange.techtarget.com/security-wire-weekly/verizon-dbir-2012-overview-attack-mitigation-strategies/ Christopher Porter of Verizon explains some of the findings from the Verizon 2012 Data Breach Investigations Report. This year, hacktivists had a big impact on the numbers. Attacks are mainly less sophisticated and more automated in nature, Porter said.

]]>
http://itknowledgeexchange.techtarget.com/security-wire-weekly/verizon-dbir-2012-overview-attack-mitigation-strategies/feed/ 17:37 Christopher Porter of Verizon explains some of the findings from the Verizon 2012 Data Breach Investigations Report. This year, hacktivists had a big impact on ... Christopher Porter of Verizon explains some of the findings from the Verizon 2012 Data Breach Investigations Report. This year, hacktivists had a big impact on the numbers. Attacks are mainly less sophisticated and more automated in nature, Porter said. Verizon,DBIR,2012,,Verizon,DBIR,,data,breach,,data,breach,management SearchSecurity.com no No
Big data or big security buzz word? http://itknowledgeexchange.techtarget.com/security-wire-weekly/big-data-or-big-security-buzz-word/ http://itknowledgeexchange.techtarget.com/security-wire-weekly/big-data-or-big-security-buzz-word/#comments Thu, 08 Mar 2012 13:10:50 +0000 Robert Westervelt http://itknowledgeexchange.techtarget.com/security-wire-weekly/big-data-or-big-security-buzz-word/ Pete Lindstrom of Spire Security joins the editorial team in a discussion about the themes that emerged at RSA Conference 2012. Big data resonated at this year’s conference, but what does it mean? Also, the team talks about the specter of mobile security and whether application security gets overshadowed at the annual event.

]]>
http://itknowledgeexchange.techtarget.com/security-wire-weekly/big-data-or-big-security-buzz-word/feed/ 35:06 Pete Lindstrom of Spire Security joins the editorial team in a discussion about the themes that emerged at RSA Conference 2012. Big data resonated at ... Pete Lindstrom of Spire Security joins the editorial team in a discussion about the themes that emerged at RSA Conference 2012. Big data resonated at this year's conference, but what does it mean? Also, the team talks about the specter of mobile security and whether application security gets overshadowed at the annual event. RSA,Conference,2012,,RSA,2012,,Security,Squad SearchSecurity.com no No
RSA 2012 Andy Purdy on critical need to address SCADA woes http://itknowledgeexchange.techtarget.com/security-wire-weekly/rsa-2012-andy-purdy-on-critical-need-to-address-scada-woes/ http://itknowledgeexchange.techtarget.com/security-wire-weekly/rsa-2012-andy-purdy-on-critical-need-to-address-scada-woes/#comments Fri, 02 Mar 2012 08:39:08 +0000 Robert Westervelt http://itknowledgeexchange.techtarget.com/security-wire-weekly/rsa-2012-andy-purdy-on-critical-need-to-address-scada-woes/ Andy Purdy, chief cybersecurity strategist at CSC shares his views on SCADA vulnerabilities and sharing threat intelligence data at RSA Conference 2012. A member of the team that developed the U.S. National Strategy to Secure Cyberspace in 2003, Purdy later served as cybersecurity czar overseeing the NCSD in the Department of Homeland Security and the US-CERT.

]]>
http://itknowledgeexchange.techtarget.com/security-wire-weekly/rsa-2012-andy-purdy-on-critical-need-to-address-scada-woes/feed/ 00:01:01 Andy Purdy, chief cybersecurity strategist at CSC shares his views on SCADA vulnerabilities and sharing threat intelligence data at RSA Conference 2012. A member of ... Andy Purdy, chief cybersecurity strategist at CSC shares his views on SCADA vulnerabilities and sharing threat intelligence data at RSA Conference 2012. A member of the team that developed the U.S. National Strategy to Secure Cyberspace in 2003, Purdy later served as cybersecurity czar overseeing the NCSD in the Department of Homeland Security and the US-CERT. SCADA,,Security,Wire,Weekly SearchSecurity.com no No
RSA Preview - The Erosion of Digital Trust http://itknowledgeexchange.techtarget.com/security-wire-weekly/rsa-preview-the-erosion-of-digital-trust/ http://itknowledgeexchange.techtarget.com/security-wire-weekly/rsa-preview-the-erosion-of-digital-trust/#comments Wed, 15 Feb 2012 23:02:58 +0000 Robert Westervelt http://itknowledgeexchange.techtarget.com/security-wire-weekly/?p=1019 The SearchSecurity team previews the 2012 RSA Conference. Hacktivism and numerous high-profile attacks, including the RSA SecurID breach could take center stage at this year’s conference. Targeted attacks, SCADA system weaknesses and mobile security challenges are likely to be the emerging topics in San Francisco.

]]>
http://itknowledgeexchange.techtarget.com/security-wire-weekly/rsa-preview-the-erosion-of-digital-trust/feed/ 23:54 The SearchSecurity team previews the 2012 RSA Conference. Hacktivism and numerous high-profile attacks, including the RSA SecurID breach could take center stage at this year's ... The SearchSecurity team previews the 2012 RSA Conference. Hacktivism and numerous high-profile attacks, including the RSA SecurID breach could take center stage at this year's conference. Targeted attacks, SCADA system weaknesses and mobile security challenges are likely to be the emerging topics in San Francisco. RSA,Conference,2012,,Security,Squad SearchSecurity.com no No