SearchSecurity
New & Notable
News
Android Security Rewards are more than bug bounties
Google launches new Android Security Rewards program that goes beyond traditional bug bounties and offers monetary rewards for security development.
Get Started
Be sure your Wi-Fi deployment is secure
A Wi-Fi deployment is the preferred method for network access for most enterprises; it’s the InfoSec’s job to make that Wi-Fi secure.
News
Can White House cybersecurity stop future breaches?
As the estimated number of current and former federal employees affected by the OPM data breach triples, the White House pushes new government cybersecurity changes to avoid another breach.
Manage
How to reduce the risk of rogue administrators
Doling out too many admin privileges can lead enterprises astray when it comes to privileged identity management, but there are ways they can take back control.
Trending Topics
-
Emerging threats News
CVSS scores may be aided by social media, study claims
A new study claims social media may be a useful indicator of vulnerability risk and lead to more accurate CVSS scores and prioritization.
-
Windows Security: Alerts, Updates and Best Practices Manage
Not patching carries more risk than auto-update flaws
Recent malware issues with Lenovo's automatic update system have some worried about the risks associated with automatic updates. Experts say secure update processes are better than ever and result in less risk than waiting to patch vulnerabilities.
-
PCI Data Security Standard Get Started
PCI DSS 3.0 changes are not an option anymore
Organizations need to review the PCI DSS 3.0 requirements and prepare for the mandatory changes coming in June 2015. Expert Mike Chapple explains how to prepare for the deadline.
-
Disk Encryption and File Encryption Evaluate
Full-disk encryption (FDE) tools: A buyer's guide
Learn how to evaluate and buy the right full-disk encryption product for your organization with this FDE buyer's guide.
-
Market trends and predictions Manage
Shearer: The future of security rests with young people
(ISC)2 executive director David Shearer responds to criticisms about the organization's lack of introductory certifications within its global academic program.
-
CISSP Certification Get Started
Vendor-specific information security certifications
Newly updated, experts Ed Tittel and Mary Kyle guide you through the crowded field of vendor-specific information security certifications.
Topics Covered
-
Application and Platform Security (13) +
- Application Attacks (Buffer Overflows, Cross-Site Scripting)
- Application Firewall Security
- Database Security Management
- Email Protection
- Enterprise Vulnerability Management
- Open Source Security Tools and Applications
- Operating System Security
- Secure SaaS: Cloud services and systems
- Securing Productivity Applications
- Social media security risks and real-time communication security
- Software Development Methodology
- Virtualization Security Issues and Threats
- Web Security Tools and Best Practices
-
Enterprise Data Protection (7) +
-
Enterprise Identity and Access Management (3) +
-
Enterprise Network Security (6) +
Government IT Security Management
-
Information Security Careers, Training and Certifications (3) +
-
Information Security Management (12) +
- Business Management: Security Support and Executive Communications
- Disaster Recovery and Business Continuity Planning
- Enterprise Compliance Management Strategy
- Enterprise Compliance Tools
- Enterprise Risk Management: Metrics and Assessments
- Information Security Incident Response-Information
- Information Security Laws, Investigations and Ethics
- Information Security Policies, Procedures and Guidelines
- News and analysis from IT security conferences
- Security Awareness Training and Internal Threats-Information
- Security Industry Market Trends, Predictions and Forecasts
- Vendor Management: Negotiations, Budgeting, Mergers and Acquisitions
-
Information Security Threats (13) +
- Application Attacks -Information Security Threats
- Denial of Service (DoS) Attack Prevention
- Email and Messaging Threats-Information Security Threats
- Emerging Information Security Threats
- Enterprise Vulnerability Management
- Hacker Tools and Techniques: Underground Sites and Hacking Groups
- Identity Theft and Data Security Breaches
- Information Security Incident Response
- Malware, Viruses, Trojans and Spyware
- Security Awareness Training and Internal Threats
- Smartphone and PDA Viruses and Threats
- Web Application and Web 2.0 Threats-Information Security Threats
- Web Server Threats and Countermeasures
-
Security Audit, Compliance and Standards (10) +
Security for the Channel
Have a question for an expert?
Please add a title for your question
Get answers from your peers on your most technical Information Security challenges.
Meet all of our Information Security experts
Find Solutions For Your Project
-
Evaluate
Are security operations centers a must-have for enterprises?
Security operations centers (SOCs) can help enterprises gain better visibility into their environments. Expert Eric Cole explains how to get the most out of SOCs.
-
Tales of incident response madness
-
Data loss prevention products: What are the enterprise benefits?
-
How Certificate Transparency can improve CA trust
-
-
Problem Solve
How to reduce the risk of rogue administrators
Doling out too many admin privileges can lead enterprises astray when it comes to privileged identity management, but there are ways they can take back control.
-
Improve compliance control management with Adobe CCF
-
Crimeware: What it's after and how to fight back
-
Windows Server 2003 end of life is here -- what's next?
-
-
Manage
Standalone vs. integrated data loss prevention products
Expert Bill Hayes details usage scenarios for deploying data loss prevention: standalone suites, integrated tools and standalone/integrated DLP combined.
-
Shearer: The future of security rests with young people
-
Block chain startups signal new approaches to data integrity
-
Endpoint threat detection gets more response
-
-
E-Zine | June 2015
Malware analysis beyond the sandbox
Download -
E-Handbook | May 2015
Buyer’s Essentials: What to look for in user behavioral analytics tools
Download -
E-Handbook | May 2015
Fighting crimeware, RAM scraping and other modern mischief
Download -
E-Zine | May 2015
New boundaries: Four strategies for perimeter network security
Download -
E-Handbook | April 2015
Ways to secure Web apps: WAFs, RASP and more
Download
Information Security Basics
-
Get Started
Standalone vs. integrated data loss prevention products
Expert Bill Hayes details usage scenarios for deploying data loss prevention: standalone suites, integrated tools and standalone/integrated DLP combined.
-
Get Started
Fingerprinting: User identifier or privacy inhibitor?
Browser and device fingerprinting create cookies that users cannot prevent nor delete. Expert Michael Cobb explains how to address the threat.
-
Get Started
Data loss prevention products: What are the enterprise benefits?
Data loss prevention (DLP) can help any organization where the loss of sensitive information could seriously impact continued operation, explains Bill Hayes.
Multimedia
-
News
View All -
Identity Theft and Data Security Breaches
Can White House cybersecurity stop future breaches?
As the estimated number of current and former federal employees affected by the OPM data breach triples, the White House pushes new government cybersecurity changes to avoid another breach.
-
Enterprise Data Governance
Physical and data safety are keys to Gartner's IoT view
Gartner predicts that by 2020 the rise of the Internet of Things will have far reaching effects on information security, including IoT security forcing better planning in physical safety and data handling.
-
Web Application and Web 2.0 Threats
U.S. government, Apple jump on HTTPS bandwagon
News roundup: The call for ubiquitous HTTPS has grown stronger as of late; the White House and Apple are hoping to help push the movement. Plus: The cost of cybersecurity management to rise 38%; a 165% ransomware increase; gender salary gap closes?
SearchSecurity Definitions
- web server security
- ISSA (Information Systems Security Association)
- Microsoft Schannel (Microsoft Secure Channel)
- card-not-present fraud (card-not-present transaction)







