Technology, security, analytics and innovation in the world of audit and business.
Wednesday, April 30, 2008
SaaS and Security: Is Your Data Safe?
Software as a Service (SaaS) applications involve using applications resident on the web and often storing our data there as well. SaaS has been big the past several months, but it raises many security and privacy issues along with loss of control over applications and service and support. This means companies using SaaS need to take precautions. This article summarizes some of them. SaaS and Security: Is Your Data Safe?
Tuesday, April 29, 2008
Information Assurance Revolution - By Peter A. Buxbaum - Military Information Technology
The US Department of Defense has launched a new approach to systems assurance. A considerable change from the previous approach, this new one, acronymed "DIACAP", decreases the documentation of system security and takes a system life cycle approach to security evaluation. It also requires annual assessments and continuous system monitoring, something that will become standard in many industries in the future. Information Assurance Revolution - By Peter A. Buxbaum - Military Information Technology
Friday, April 25, 2008
IT Security Skills Falling Short
It's well known that there is a serious shortage of IS personnel. Young people, for whatever reason, just are not going into the area in sufficient numbers. Add to this the fact that those who are working in IS security functions are extremely busy and you have a real problem. A recent study by the Computing Technology Industry Association shows that security professionals just don't have the time to keep up to date with recent trends and techniques in the area. That's not a good sign, given the importance of strong security both for systems integrity and to protect personal privacy. IT Security Skills Falling Short
Monday, April 21, 2008
Downloadable Research Reports - The Institute of Internal Auditors
The Internal Auditors Association (IIA) has long carried out good research. On their website at the following link is a list of downloadable research. It includes a variety of studies, including one on research opportunities in Internal Audit along with a supplement for IT systems. It's a good resource. Downloadable Research Reports - The Institute of Internal Auditors
Friday, April 18, 2008
Web 2.0 Expo Preview: Businesses Waking Up To Web-Enabled Apps -- InformationWeek
We've heard a lot about Web 2 and the Semantic Web. Business has not embraced its potential as yet, partly and maybe mostly because of privacy and security concerns. Business use of the Semantic web would involve making use of web based applications, which have lots of potential both for systems scalability and for grave privacy and security problems. However, there is some thought out there that business is beginning to look more carefully at the potential for good, and how the bad side of it can be controlled. Web 2.0 Expo Preview: Businesses Waking Up To Web-Enabled Apps -- InformationWeek
Virtualization
Virtualization has been a hot topic in IT management recently. It is an extension of the old virtual memory days, where usable memory is created that is not tied to a particular platform. Apply that concept to data, servers, networks, etc and you have a powerful tool for sharing resources and optimising usage. The paper referenced below explores virtualization and its impact on systems, and makes the observation that it can be a help to security as well, because it shields specific resources from the eyes of hackers. It is hard for them to tell which resource they have compromised. Virtualization
Wednesday, April 16, 2008
Cybercrime is in a state of flux
Fast Flux is the new way for cybercriminals to cover their tracks. Somewhat illustrated in the movie "Untraceable" the technique involves fast changing of DNS records on servers and using Peer to Peer rather than command and control, along with encryption to interact with the bots planted in infected PCs. It makes it all but impossible to find and shut down the illicit sites/servers, which translates into higher rates of cybercrime in the future. Cybercrime is in a state of flux
Subscribe to:
Posts (Atom)