Boaz Gelbord, who heads the OWASP Security Spending Benchmarks project, explains the survey results. Also, Ivan Arce of Core Security Technologies talks about smartphone threats and penetration testing.
In the latest edition of “Hot Type: Security Books in Audio,” author Jim Stickley reveals just how easy it is for a cybercriminal to get access to your employees’ passwords.
Security expert Lenny Zeltser gives tips on how to appropriately respond to a security incident. Also, a discussion on the relaunch of L0phtCrack password cracking tool with Chris Wysopal of Veracode.
(SOURCE Boston 2009) Botnets are being used more frequently to silence political dissenters, explains Jose Nazario of Arbor Networks. Nazario has been studying the rise of botnets as a tool used in cyberwarfare.
No matter how much security awareness training employees get, some of them will still store sensitive data in insecure places. As a security manager, finding that data becomes of paramount importance — but how to do it? In this tip, John Soltys offers advice on ways to find insecurely stored data.
PCI Council general manager Bob Russo and Council chairman Lib de Veyra talk about the PCI Council’s goals in 2009. Russo is frank about the latest data breaches. Also a discussion about virtualization security with Steve Herrod of VMware.
Cryptography expert Taher Elgamal of Axway Inc. defends SSL in the wake of research that bypasses it. Elgamal’s research led to the development of SSL.
Inappropriate content has always been a problem for enterprise security teams. What are some best practices for blocking adult content and websites from systems? In this security management tip, learn strategies for keeping users’ Web habits in check.
Secure coding expert Chris Wysopal talks about dynamic and static testing and the state of secure software development tools. Wysopal also explains why he’s a big proponent of the SANS/CWE Top 25 Dangerous Programming Errors List.
Gary McGraw of Cigital explains why the CWE/SANS Top 25 dangerous programming errors list will fail to have a major effect on secure software development.
Listen to the top security experts and learn about the latest cybersecurity research. Whether it’s the spread of malware, the explosion of spam or hackers exploiting flaws to steal sensitive data, this podcast series aims to find the right ways to defend against ongoing attacks to your systems.