Posts Tagged ‘compliance’

facebook, cutia pandorei?

Accesul angajaților la rețelele de socializare precum Facebook, MySpace, Twitter a devenit, pe bună dreptate, tot mai controversat. Teama actuală față de rețelele de socializare este cauzată de aspecte de securitate și productivitate. Din punct de vedere al securității avem de-a face cu scurgerea informațiilor confidențiale pe de o parte și pe de altă parte [...]

Read the rest of this entry »

the UNprotected

Bad news. You failed the database audit. the UNPROTECTED – episode 1 from Application Security, Inc. on Vimeo. the UNPROTECTED – episode 2 from Application Security, Inc. on Vimeo. the UNPROTECTED – episode 3 from Application Security, Inc. on Vimeo. the UNPROTECTED – episode 4 from Application Security, Inc. on Vimeo. the UNPROTECTED – Episode [...]

Read the rest of this entry »

PCI DSS overview

Sursa. 1) Install and maintain a firewall configuration to protect data. 2) Do not use vendor-supplied defaults for system passwords and other security parameters. 3) Protect stored data. 4) Encrypt transmission of cardholder data and sensitive information across public networks. 5) Use and regularly update anti-virus software. 6) Develop and maintain secure systems and applications. [...]

Read the rest of this entry »

iloveyou

Conform unui articol din The New York Times: Mr. Shulman and his company examined a list of 32 million passwords that an unknown hacker stole last month from RockYou, a company that makes software for users of social networking sites like Facebook and MySpace. Imperva found that nearly 1 percent of the 32 million people [...]

Read the rest of this entry »

ISO/IEC 27004 Released

ISO/IEC 27004 – has just been published. http://www.itgovernance.co.uk/products/2858 Thie standard provides guidance on the development and use of measures and measurement in order to assess the effectiveness of an ISMS. It also provides guidance on the measures and measurement for controls or groups of controls. All of the advice and guidance within ISO/IEC 27004:2009 is [...]

Read the rest of this entry »