Windows Security You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. Articles Using Modern.ie to test Web browser compatibility with applications Managing Windows Server audit logs to cover your assets Six endpoint management lessons from POS security breaches Steering your career as a desktop admin in the mobility age Don't ignore Windows 8 security when reviewing desktop vulnerabilities ...
Continue Reading...Web application and mobile app security You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. Articles The developer's role in application security strategy Finding and fixing security flaws in third-party software that you don’t have control over Setting and achieving your application security goals Why most application security measures fail and what must be done about it Miscommunication ...
Continue Reading...Information security tools and testing You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. Articles What to expect during your next penetration test Following up on your vulnerability and penetration testing Low-hanging security fruit you can’t afford to overlook Three Actionable Steps To Take Following Your Penetration Testing Are you making this mistake with your phishing awareness campaign? ...
Continue Reading...Information security policies You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. Articles Security policies matter, but only so much Security’s new focus: defensibility Why you have to look past security policies for real improvements When security policies are bad for business People are violating your security policies and here's why Best practice tips for your password policy ...
Continue Reading...Information security management You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. Articles 8 ERP security best practices to implement now How CIOs can build cybersecurity teamwork across leadership The CIO’s role in strengthening cybersecurity Top 4 information security strategy essentials CIOs need Security policies matter, but only so much Seven keys to success when working with information ...
Continue Reading...Database security You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. Articles Ten hacker tricks to exploit SQL Server systems Do you need to harden SQL Server 2008 R2? Meet compliance requirements with improved database security practices Common oversights with SQL Server audits The ultimate SQL Server security faux pas: Overlooked systems Password cracking tools for SQL Server ...
Continue Reading...Information security compliance You may need to do a quick third-party registration to access certain ones. Resources without a hyperlink are no longer published/posted. Articles Understanding the Cybersecurity Maturity Model Certification (CMMC) PCI DSS compliance across retail and financial services Considerations for addressing the new PCI SSL/TLS requirements Going beyond addressable with HIPAA and doing what’s right with data encryption How security intelligence can support HIPAA compliance Why PHI access ...
Continue Reading...Kevin's Books Kevin's blogs and columns Principle Logic blog Ziff Davis' Toolbox.com Rapid7's blog TechTarget's websites Kevin's articles, podcasts, and webcasts Careers Cloud security Compliance Database security Incident response and contingency planning IoT security Malware Management Messaging security Mobile and wireless network security Passwords Policies Physical security Social engineering and phishing Storage security and backups Tools and testing Voice over IP security Web and application security Windows security Kevin's downloadable ...
Continue Reading...Security Assessments Network Vulnerability and Penetration Testing Network security assessments are great for discovering technical weaknesses that exist in your broader group of network hosts. Using well-known and widely-accepted commercial tools as well as in-depth manual analysis I will look at your external and/or internal systems (including Internet of Things/IoT devices, medical devices, and Operational Technology/OT systems) from the perspective of an untrusted outsider, trusted insider, or both. I can ...
Continue Reading...Back in 2007 I wrote a blog post on what's it going to take to encrypt laptop hard drives. After seeing this recent story about Children's Hospital Los Angeles, I can't help but shake my head.The 0 comments on this article says a lot as society is becoming immune to these breaches...I think I've heard it called breach fatigue - it's not unlike presidential politics as of late! In 2007, these ...
Continue Reading...