| 1. |
Outsourcing Security Benefits, Costs, Provider Selection (3 Pages)
by Jim McLendon
Apr 11, 2002 Abstract : It's the middle of the night. A shadowed figure crouches by the window. He retrieves a menacing instrument and begins fiddling with the lock. But the intruder won't get far: the homeowners have contracted a security provider to monitor a tight alarm system-or so they thought... Benefits of Outsourcing Security Without effective security, companies risk losing money and customer trust. With good security, companies have the power to maintain stakeholder value, customer loyalty, and competitive advantage. Faced with the complexity of providing effective security, many companies are turning to outsourcing. Measuring The Cost of Such an Outsourcing Evaluating the cost of outsourcing can be challenging because most organizations cannot fully estimate the financial impact of such a decision. Selecting a Managed Security Services Provider Guidelines for selecting a dependable managed security services provider.
|
| 2. |
The Whys and Hows of a Security Vulnerability Assessment ( Pages)
by L. Taylor
Aug 9, 2000 Abstract : TEC outlines the reasons for having a Security Vulnerability Assessment done, how a security vulnerability assessment is performed, what can be gained by enlisting the Security Vulnerability Assessment process, and what you should expect to see in a Security Vulnerability Assessment report. After all, the most important reason for having a Security Vulnerability Assessment performed is to enable corrective action. How can you know what to secure if you don't know what is insecure?
|
| 3. |
Bootcamp for the Pros; Why Ernst & Young Will Lead Security Auditing Standards ( Pages)
by L. Taylor
Jan 19, 2002 Abstract : Original News & Educational Review Course Summary Ernst & Young, has put together the quintessential course for security engineers looking to improve their ability to protect their organization's website, systems, and network. Dubbed eXtreme Hacking, and carrying a price tag of $5,000 a slot, this course is for anyone but hacks. With an impressive course book that fills a two-inch thick binder, leading Ernst & Young security engineers take you step-by-step through all the ways that bad guys try to subvert your mission critical servers and network configurations. Using dual-bootable NT-Linux laptops, and an accompanying network setup for practicing subversive attacks and exploits, attendees will leave the course with an entire new bag of tools and tricks that help them understand how bad guys identify target IP addresses, collect information about the systems they plan on compromising, and exploit weaknesses without being noticed. The idea is to learn how to figure out what the weaknesses are in your organization's network before the bad guys do.
|
| 4. |
HIPAA-Watch for Security Speeds Up Compliance Part One: Vendor and Product Information ( Pages)
by Laura Taylor
Aug 27, 2004 Abstract : HIPAA-Watch for Security is a tool designed to guide organizations through the risk analysis required by the Health Insurance Portability and Accountability Act (HIPAA) compliance process (US). Relevant Technologies, a leading security research and advisory firm, evaluated HIPAA-Watch for Security to verify how well it performed in guiding organizations through the HIPAA security risk analysis process.
|
| 5. |
Security Risk Assessment and Management in Web Application Security ( Pages)
by Caleb Sima
Jun 6, 2008 Abstract : Corporations are at risk because Web applications and servers make them susceptible to hackers and cyber crooks. However, companies can perform security risk assessments that mitigate risk by applying security risk management policies designed to protect a company’s data.
|
| 6. |
Outsourcing Security Part 3: Selecting a Managed Security Services Provider ( Pages)
by Jim McLendon
Apr 11, 2002 Abstract : As the final article in a three-part series on outsourcing security, the following article provides guidelines for selecting a dependable managed security services provider.
|
| 7. |
Security Risk Assessment and Management in Web Application Security ( Pages)
by Caleb Sima
Jan 27, 2006 Abstract : Corporations are at risk because Web applications and servers make them susceptible to hackers and cyber crooks. However, companies can perform security risk assessments that mitigate risk by applying security risk management processes that valuate and prioritize IT assets.
|
| 8. |
HIPAA-Watch for Security Speeds Up Compliance Part Two: Phase III and IV, and Product and User Recommendations ( Pages)
by Laura Taylor
Aug 28, 2004 Abstract : Once the user defines compliance case boundaries and establishes the data criteria in Phases I and II, the HIPPA-Watch for Security tool begins Phase III by launching the risk analysis engine, and concludes with Phase IV, which generates the report. Using the HIPPA-Watch for Security tool can help an organization comply with the Final Security Rule and help companies understand which safeguards can generate a greater return on investment.
|
| 9. |
Study Shows: FBI Alienates Industry Security Experts ( Pages)
by L. Taylor
Aug 21, 2000 Abstract : A comprehensive study done by TechnologyEvaluation.Com has shown that, for years the FBI has been alienating industry security experts. Some of the best industry security professionals want nothing to do with helping the FBI resolve cybercrime. Recently, one of the leading Department of Justice attorneys general, well-known for expertise in successfully prosecuting cybercrime, asked TechnologyEvaluation.Com why so many security and information technology professionals snub their noses at law enforcement agencies that exist to protect our nation's vital assets - private and public. TechnologyEvaluation.Com went behind the scenes to find o
|