Virtualization changed the IT environment in such a way that boundaries and resources become elastic, machines are files and all is based on software. Standards and tools for securing these virtualized infrastructures exist, so make good use of them! Virtualization is everywhere and thanks to virtualized IT environments; businesses can rely on scalable, cost...
Read more »
Tags: infrastructure, IT environment, virtualized
Posted in Security Governance, Virtualization | No Comments »
There are some good practices organizations can do to help out in securing cyber space! The most obvious good practice is to follow well established security standards and controls! If you are purchasing a new vehicle, most probably you will want to purchase one with the best safety features including seat belts, air bags,...
Read more »
Tags: Best Practices, cyber, cyber security, standard
Posted in Security Governance | No Comments »
Get an overview of how PGP digitally signs an email message, what is Symmetric (Secret-key) and Asymmetric (Public-Key) Cryptography, and how can you be sure that the Public key of the recipient is the real one. PGP combines the best features of Symmetric and Asymmetric schemes and includes additional methods to further secure data. Read...
Read more »
Tags: Asymmetric, Cryptography, PGP, Symmetric
Posted in Security Governance | No Comments »
Volume 12 of the Microsoft Security Intelligence Report which covers from July till December of 2011 contains a deep analysis of trends found in more than 100 countries around the world and offers suggestions to help manage risks to your organization, software, and people. It provides in-depth perspectives on software vulnerabilities and exploits, malicious...
Read more »
Tags: exploit, malicious, Microsoft, phishing, Security report, vulnerability
Posted in Security Governance | No Comments »
The recent trend of employees bringing their mobile devices to work and connect them to corporate resources is a risk that organizations need to be aware of. It is described as Bring Your Own Device (BYOD) but I prefer to call it Bring Your Own Unsecure Device (BYOUD). While, mobile devices can be easily...
Read more »
Tags: bring your own device, BYOD, BYOUD, encryption, mobile, mobile devices, mobile strategy, policy, risk, Strategy
Posted in Security Governance | No Comments »
What is SSL? Secure Sockets Layer (SSL) is a protocol that provides secure communications over networks, including the Internet. The protocol allows client-server applications to communicate with each other and preventing third-parties from spying and interfering in these communications. The successor of SSL is Transport Layer Security (TLS). Why it is used? As already...
Read more »
Tags: client-server, man-in-the-middle, protocol, secure connection, SSL, TLS, vulnerability
Posted in Security Governance | No Comments »