Feb 11 2012

Intel IT’s New Information Security Strategy

Category: Security organizationDISC @ 11:52 am

Intel IT – Protect to Enable: Learn about Intel’s IT best practices and Intel’s new information security strategy…. a new architecture that is designed to increase productivity, agility and innovation, while actually decreasing risk.


Feb 07 2012

A successful ISO27001 cert case study and benefits rendered

Category: ISO 27kDISC @ 11:39 am

Check out the ITG site for details

London Pensions Fund Authority (LPFA) achieves ISO27001 and ISO14001 certifications six months ahead of deadline

The London Pensions Fund Authority (LPFA), based at Royal Mint Court, London, is today announcing a remarkable achievement in standards compliance. A leader in the provision of pension administration for the Local Government Pension Scheme, and with its own pension fund worth £4.1bn, LPFA is leading the way in the City of London by recently becoming certified to the ISO27001 Information Security and ISO14001 Environmental Management System standards – six months ahead of project schedule, and with a near-perfect score.

These prestigious awards are the culmination of a fast-track project supported by professional services firm IT Governance, a leader in international standards compliance and best practice, serving clients in the UK public and private sectors.

In the highly competitive global market for pension fund administration, cost-effectiveness and efficiency are vital components for success. LPFA is, therefore, a cost-conscious and well-run organisation, but also one that is aware of its responsibilities when it comes to protecting the security of data and taking a leadership position in improving the organisation’s environmental impact. For these reasons, the LPFA Board adopted international standards and achieved compliance with the ISO27001 Information Security and ISO14001 Environmental Management Standards.

For LPFA, Les Higgs, LPFA’s Programme and ICT Manager, comments: “Our thanks go to IT Governance, whose consultant, Nick Orchiston, enabled us to achieve certification in record time, and – on a personal note – to Lauren McHugh, who has worked so diligently to inform and successfully engage our colleagues at LPFA. The results speak for themselves: after rigorous assessment, the BSI auditor found only three minor non-conformities in the implementation of two weighty international standards. They certificated LPFA to ISO27001 and ISO14001 standards on our first attempt, six months ahead of our project completion date.”

Mike Taylor, LPFA’s Chief Executive, said: “I am delighted that LPFA has managed to achieve ISO accreditation six months ahead of deadline. Key elements, such as enhanced data security and environmental considerations, have become part of life across the whole organisation. This accreditation should give confidence to all Fund members and clients that their information is in good hands. The process had total commitment from the project team, IT Governance and all staff, and it was this that led to a successful implementation.”

“For IT Governance, Steve Watkins, Director, Training & Consultancy, said: “ISO27001 compliance, when approached correctly, provides clear commercial benefits. The risk-based approach means that it is the sensitive information – for example, personal information, bank details, contracts and other confidential material – which is appropriately protected, thereby minimising the risk of reputational damage and providing reassurance to clients, whilst also ensuring the information is available as and when it is needed. Further, certification to ISO27001 demonstrates to clients, staff and stakeholders that the organisation has a systematic approach to managing the security of information, considering the implications of people, processes and technology. We believe that by adopting this standard and seeking accredited certification, financial companies can demonstrate their commitment to respecting clients’ sensitive data.”

The certification pathway to ISO27001 involved extensive risk management evaluation, business resilience planning and ensuring data security standards set by client companies are met and exceeded by delivering industry-leading IT protocols. LPFA will be independently inspected every six months to ensure it is up to speed with the latest data protection and industry requirements – with strong and effective measures to help to protect confidential data and prevent fraud.

The ISO14001 Environmental Management System has helped LPFA to be more environmentally friendly, providing managers with guidance on how to measure consumption and reduce waste. An effective programme to reduce, re-use and recycle has produced top and bottom line benefits by making tangible cost savings, reducing environmental impact and enhancing the organisation’s environmental credentials, winning more business: a fact demonstrated by LPFA’s success in securing commercial tenders as a result of the organisation’s certification in 2011.

IT Governance offers an integrated professional services approach to standards adoption, project development and compliance. The UK-based company provides consultancy advice, coaching and mentoring, knowledge transfer, training programmes and an extensive range of documentation toolkits, software, e-learning and self-help publications designed to speed up compliance projects.


Checkout a comprehensive ISO 27001 ISMS Toolkits from IT Governance


Jan 31 2012

Top nine cyber security threats for 2012

Category: cyber security,ISO 27kDISC @ 12:37 pm

1. Cyber security decisions will be based on security, rather than regulations. The growing infrastructure of hackers and data breaches will mean businesses will be protecting themselves out of necessity, rather than regulation
2. The rise of ‘cyber brokers’. There will be an increasing supply and demand for compromised machines containing sensitive data.
3. An increase in hackers automating social media attacks
4. Time will be wasted as IT professionals profess regulation of end-user devices and cloud data access, instead of controlling data at the source
5. There will be inadequate security around big data (NoSQL) inhibiting integration as third party components within companies.
6. Organizations will have to look for tools to protect and control access, as internal collaboration suites (such as Microsoft Sharepoint and Jive) might be deployed in ‘evil twin’(external) modes.
7. In regards to DDoS, attackers will increase sophistication and effectiveness by shifting from network level to application level attacks (even business logic level attacks), citing increasing exploitation of SQL injection vulnerabilities as one of the modes.
8. The HTML 5 standard will enable hackers to exploit vulnerabilities in the browser’s themselves to install malware.
9. There is currently a rise in attacks which target the worldwide infrastructure that supports SSL. Imperva expect these attacks to reach a tipping point in 2012 which, in turn, will invoke a serious discussion about real alternatives for secure web communications.

Source: Imperva, Works Management
To help you combat cyber threats, you can download free white paper ‘Cyber Security: A Critical Business Risk’ here >>>

The best way to protect you and your business for 2012 is to implement ISO 27001; the international best practice for an Information Security Management System (ISMS).
The easiest way to do this is with this ISO27001 toolkit


Jan 29 2012

How to tackle cybersecurity

Category: cyber securityDISC @ 10:08 pm

By SEN. KAY BAILEY HUTCHISON, SEN. CHUCK GRASSLEY, SEN. SAXBY CHAMBLISS and SEN. LISA MURKOWSKI @ POLITICO

The Senate is about to consider cybersecurity legislation. Ensuring the integrity and safety of our nation’s critical infrastructure is a bipartisan issue that Congress and President Barack Obama must work together to tackle.

There is a right way and a wrong way to address cybersecurity. The right way is for the government and private sector to work together to solve problems, help the free flow of information between network managers and encourage investment and innovation in cybersecurity. The wrong way is new, heavy-handed, costly regulation and further expansion of government bureaucracy that will slow our nation’s response to cyberthreats and increase vulnerabilities.

First, the government must do a better job of protecting its own systems. These networks contain some of our most sensitive data and control some of our most important facilities. To improve network security, there are two areas in which Congress could legislate immediately.

The first is reforming the Federal Information Security Management Act. This law, crafted to improve the security of government information systems, is a decade old and should be updated with a real-time monitoring system.

The second critical component is leveraging our key federal research institutions — including national laboratories, the National Science Foundation and the Defense Advanced Research Projects Agency — to maintain U.S. global leadership in cybersecurity innovation. By developing leading-edge cybersecurity technologies, the United States can stay one step ahead of cyberthreats, whether from hackers, terrorists or nation-states.

Though improving the security of government systems is a crucial first step, it is not enough. The federal government does not own the overwhelming majority of the infrastructure that could be the target of cyberthreats.

For example, more than 1,800 entities own or operate components of our nation’s electrical grid. To secure critical infrastructure, we should focus on strengthening our existing oversight frameworks instead of creating duplicative regulatory regimes that give additional agencies, such as the Department of Homeland Security, broad new authorities to regulate.

In fighting cyberthreats, forewarned is forearmed. The single most effective way of advancing cybersecurity is sharing cyberthreat information between the government and industry, as well as within the private sector. Yet this collaborative relationship is undermined by our laws and policies — which put the government and private entities at a severe disadvantage in proactively identifying and countering cyberthreats.

The government often collects valuable information about potential threats that can and should be shared with private entities — without compromising national security. Companies should be free from legal barriers and constraints that prevent or deter them from voluntarily sharing cyberthreat information with their peers or with the government.

As a government, we should work with the private sector to help them respond to cyberthreats. Not punish them for being victims of cyberattacks or for working with others to prevent future attacks.

In addition, our nation’s criminal laws must be updated to account for the growing number of cybercrimes. We support legislation to clarify and expand the Computer Fraud and Abuse Act — including increasing existing penalties, defining new offenses and clarifying the scope of current criminal conduct.

These changes will ensure that our criminal laws keep pace with the ever-evolving threats posed by cybercriminals.

This approach should lead to significant strengthening of our nation’s cybersecurity and quickly gain bipartisan support in Congress. Unfortunately, the administration’s proposal would create new, massive and ill-defined regulatory burdens — forcing many private companies that work with digital networks to be regulated by DHS.

Such broad new regulatory powers will, in turn, require a dramatic and costly expansion of the federal bureaucracy and its regulatory reach. This expansion will not help secure America’s networks and will harm both innovation in cybersecurity and our nation’s already suffering economy.

Now is not the time to increase the size and cost of the federal bureaucracy. We need to focus instead on reforming existing federal government entities, streamlining and targeting regulatory efforts, looking for efficiencies and strengthening our nation’s capacity to deal with cyberattacks.

The administration’s proposal is ultimately a costly and heavy-handed regulatory approach. It will not work and it won’t pass Congress. We hope the president will work with us on a more collaborative approach between government and business to effectively address the critical issue of cybersecurity.


Jan 17 2012

An Introduction to Hacking & Crimeware

Category: CybercrimeDISC @ 10:06 am

An Introduction to Hacking & Crimeware: A Pocket Guide

Cybercrime is on the rise. Unchecked, it could destroy the entire global cyber infrastructure and wipe out many businesses. We need to defend ourselves against it, and we must fight back.
Know your enemy

An Introduction to Hacking & Crimeware is a comprehensive guide to the most recent and the more serious threats. Knowing about these threats will help you understand how to ensure that your computer systems are protected and that your business is safe, enabling you to focus on your core activities.

Download your eBook copy today!


Jan 17 2012

The Big Shift to Cloud-based Security

Category: Cloud computingDISC @ 8:58 am

Keeping IT systems secure and running within regulatory compliance mandates, especially for mid-sized and even small businesses, seems next to impossible. There are many reasons for this — but fortunately, several recent technological trends show that it doesn’t have to be this way.

This paper covers how small and medium-sized organizations can manage their IT risks and maintain regulatory compliance with minimal staff and budget.

Download Paper Now

Managing Risk in the World of Cloud Computing


Jan 15 2012

The Mobile Security Show: Improving Mobility Infrastructure Security Standards

Category: Mobile Security,Smart PhoneDISC @ 10:40 pm

For more episodes of The Mobile Security Show, visit http://techchannel.att.com/showpage.cfm?Mobile-Security-Show

A discussion on Mobility Standards moves towards a rousing conversation about mobility and privacy. Originally recorded at NYU Poly on November 16, 2011.

Topic: “Dealing With Exploitable Mobile Device Vulnerabilities”
Hosts:
Veronica Belmont – Technology Video Host
Dino Dai Zovi – Information Security Professional & Researcher

Panelists:
Edward Amoroso, AT&T Inc., Chief Security Officer
Martin Roesch, Sourcefire, Founder and CTO
Uma Chandrashekhar, Bell Labs, Alcatel-Lucent, VP Security, Reliability, & Eco-Environmental Eng.
Justin Cappos, NYU-Poly, Assistant Professor, Computer Science & Engineering


Dec 26 2011

Tackle cyber security in 2012 with this eBook

Category: cyber securityDISC @ 7:46 pm

2011 will be remembered as the year of the hacker. Large, well know brands were targeted like never before causing a media frenzy and major concern for consumers around the world.
Make your New Years-Resolution to tackle Cybersecurity. Get a head-start. Buy this book and let the master strategists show you how to fight the information war!

Tis the season to be jolly,
Put an eBook in your trolley,
In the warm without a brolly,
Don’t miss out – you could be sorry!”

Assessing Information Security: Strategies, Tactics, Logic and Framework
by Andrew Vladimirov, Konstantin Gavrilenko and Andriej Michajlowski.


RRP: $69.99

Price: $49.95
You Save: $20.04



Dec 20 2011

ISO/IEC 27001 – BSI interviews Henk de Vries

Category: ISO 27kDISC @ 9:59 am

BSI and Rotterdam school of management, Erasmus university conducted a research study about ISO/IEC 27001 Information technology. Security techniques. BSI interviewed Henk de Vries who is one of the experts behind the study.

ISO27001 (ISO 27001) ISMS Requirements (Download now)

ISO27002 (ISO 27002) Code of Practice for ISM (Download now)

To Download a copy of ISO27003 – Implementation Guidance

To Download a copy of ISO27004 – Information Security Metrics

ISO27005 (ISO 27005)ISRM Standard (Download now)

ISO/IEC 27006 ISMS certification guide (Download now)

Tags: iso 27001, iso 27002, iso 27003, ISO 27004, iso 27005, iso 27006


Dec 15 2011

To Be or Not to Be CyberSecurity Expert

Category: cyber securityDISC @ 12:32 pm

History has taught us: never underestimate the amount of money, time, and effort someone will expend to thwart a security system. It’s always better to assume the worst. Assume your adversaries are better than they are. Assume science and technology will soon be able to do things they cannot yet. Give yourself a margin for error. Give yourself more security than you need today. When the unexpected happens, you’ll be glad you did. – Bruce Schneier

Realise the benefits of Internet technologies, while ensuring your company is protected from the associated risks.

If you want to make the Internet work for your business, you need to take the right precautions – Buy this book today!

Realize the benefits of Internet technologies, while ensuring your company is protected from the associated risks!

An effective risk management strategy is vital to your company s survival
Internet technologies have revolutionized the way that business is conducted. However, these innovations expose your business to various risks. Inadequate security can lead to the theft of customer data and, in the event of technological failure or a cyberattack, your business could lose its ability to function altogether. An effective risk management strategy is, therefore, vital to your company s survival.

Understand the origins of cyber risks and develop suitable strategies for their management
Cyber Risks for Business Professionals: A Management Guide is a general guide to the origins of cyber risks and to developing suitable strategies for their management. It provides a breakdown of the main risks involved and shows you how to manage them. Covering the relevant legislation on information security and data protection, the author combines his legal expertise with a solid, practical grasp of the latest developments in IT to offer a comprehensive overview of a highly complex subject.

Expert guidance examining the operational and technological risks
Drawing on interviews with experts from Clifford Chance, Capgemini and Morgan Stanley amongst others, the book examines the operational and technological risks alongside the legal and compliance issues. This book will be invaluable to lawyers and accountants, as well as to company directors and business professionals.


Dec 06 2011

vsRisk The Ultimate Cyber Security Risk Assessment Tool

Category: ISO 27k,Security Risk AssessmentDISC @ 11:05 am

With over 10 years in the market and 2,500 global downloads, vsRiskTM has been helping organizations all over the world carry out successful risk assessments.
Risks assessment is the core competence of cyber security management. Every decision you make must be proportionate to the actual risk your organization faces. You must therefore assess risks on a structured asset-by-asset basis – and experience proves you need to save time and money with a risk assessment tool that automates and simplifies this process.
vsRisk is the definitive ISO27001:2005-compliant risk assessment tool which will help you become cybersecure

vsRisk – The Definitive Cyber Security Risk Assessment Tool
The vsRisk Assessment Tool has been designed with the user in mind to effectively identify, analyze and control their actual information risks in line with their business objectives. Key features of vsRisk include:
• Assessing key areas such as Groups, Assets and Owners
• Capturing your IS policy, objectives and ISMS scope
• In-built audit trail and comparative history
• Assessesing attributes on Confidentiality, Integrity, and Availability, in relation to Business, Legal, Contractual
• Comprehensive reporting and gap analysis

Alan Calder, CEO of Vigilant Software, talks you through the risk assessment process using vsRisk
Watch the video now >>>

This unique risk assessment tool helps you get on top of the critical risk assessment phase of your ISMS project and, most importantly, sets you up for future risk assessments as well.
Join the professionals and orders your today >>>

vsRisk and Security Risk Assessment


Dec 02 2011

How to get certified against ISO 27001?

Category: ISO 27kDISC @ 11:39 am

ISO27001 ISMS Requirements (Download now!)

By Dejan Kosutic

You have been implementing ISO 27001 for quite a long time, invested quite a lot in education, consultancy and implementation of various controls. Now comes the auditor from a certification body – will you pass the certification?

This kind of anxiety is normal – you can never know whether your ISMS (information security management system) has everything the certification body is asking for. But what is it exactly the auditor will be looking for?

First, the auditor will perform the Stage 1 audit, also called the “Document review” – in this audit, the auditor will look for the documented scope, ISMS policy and objectives, description of the risk assessment methodology, Risk Assessment Report, Statement of Applicability, Risk Treatment Plan, procedures for document control, corrective and preventive actions, and for internal audit. You will also have to document some of the controls from Annex A (only if you found them applicable in the Statement of Applicability) – inventory of assets (A.7.1.1), acceptable use of assets (A.7.1.3), roles and responsibilities of employees, contractors and third party users (A.8.1.1), terms and conditions of employment (A.8.1.3), procedures for the operation of information processing facilities (A.10.1.1), access control policy (A.11.1.1), and identification of applicable legislation (A.15.1.1). Also, you will need records of at least one internal audit and management review.

If any of these elements are missing, this means that you are not ready for Stage 2 audit. Of course, you could have many more documents if you find it necessary – the above list is the minimum requirement.

Stage 2 audit is also called the “Main audit”, and it usually follows a few weeks after Stage 1 audit. In this audit the focus will not be on the documentation, but if your organization is really doing what your documentation and ISO 27001 say you have to do. In other words, the auditor will check whether your ISMS has really materialized in your organization, or is it only a dead letter. The auditor will check this through observation, interviewing your employees, but mainly by checking your records. The mandatory records include education, training, skills, experience and qualifications (5.2.2), internal audit (6), management review (7.1), corrective (8.2) and preventive (8.3) actions; however, the auditor will be expecting to see many more records as a result of carrying out your procedures.

Please, be careful here – any experienced auditor will notice right away if any part of your ISMS is artificial, and is being made for the purpose of audit only.

OK, you knew all this, but it still happened – the auditor found major non-conformity and told you that ISO 27001 certificate will not be issued. Is this the end of the world?

Certainly not. The process goes like this – the auditor will state the findings (including the major non-conformity) in the audit report, and give you the deadline until which the non-conformity must be resolved (usually 90 days). Your job is to take appropriate corrective action; but you have to be careful – this action must resolve the cause of the non-conformity, otherwise the auditor might not accept what you have done. Once you are sure the right action is taken, you have to notify the auditor and send him/her the evidence of what you have done. In the majority of cases, if you have done your job thoroughly, the auditor will accept your corrective action and activate the process of issuing the certificate.

There you go – it took some time, but now you are a proud owner of the ISO/IEC 27001 certificate. (Be careful though – the certificate is valid for three years only, and can be suspended during that period if the certification body identifies another major non-conformity on the surveillance visits.)


Nov 25 2011

Secretary of Defense William S Cohen on the 3 Main Threats

Category: cyber securityDISC @ 10:41 pm

Secretary of Defense William S Cohen on the 3 Main Threats Facing the United States, secretary Cohen emphasis cyber threat is the most dangerous out of three. Click the link above to watch his video on three main threats.

Famous quotes from Secretary Cohen:
While we are not and cannot become the world’s policeman, neither can we become a prisoner of world events, isolated and tucked safely away in a continental cocoon.

There is no foolproof security that we can provide. But to say that we can’t protect against everything doesn’t mean that we shouldn’t protect against those that can cause us catastrophic harm.

For while the threat of nuclear holocaust has been significantly reduced, the world remains a very unsettled and dangerous place.

Terrorism is escalating to the point that Americans soon may have to choose between civil liberties and more intrusive means of protection.

We will not win the war on terror through military action. The sharing of information and intelligence will be vital to protecting our country.

The more reliant we become upon computers and information systems, the more vulnerable we become to cyber-terrorists who will conceive unlimited ways to cripple our infrastructure, our power grids, our banking systems, our financial markets, our space based communications systems.

Related books by Secretary of Defense William S Cohen


Nov 18 2011

Protection of credit card and ATM/debit card transactions

Category: Cybercrime,pci dssDISC @ 1:16 pm


By Azie Amini
Protection of credit card/ATM card transactions and the latest trends in banking, credit card or internet fraud.

• As we go towards the end of the year, one by one report each credit card missing and get a new one with a new account number (make sure you ask for a new account number, sometimes they send a new card with the same number). When you get each one, call the other credit card company and report the other one missing. Do this for each card so that when you start the new year with new credit cards. (The reason for it is that often thieves want to collect many stolen credit cards and then they sell a batch of hundreds of thousands of credit cards to a buyer. They often wait a year or two to collect many credit cards so often your credit card number is stolen sitting in their files without you knowing. All of a sudden they sell their large list of stolen credit cards and within a few days you will get hit with many transactions so your card is maxed in a very short time) and you will have the headache of having to report each transaction as false and hope your bank will not charge you. So change all your credit cards at least once a year to be safe.

• If any credit card company or bank calls you to report suspicious activities on one of your cards, do NOT give them your card number just tell them to read the number they have and you just say Yes or No. Also if they asked for the 3 digits on the back of your card, do NOT give it to them. They should tell you what info they have and all you say is Yes or No, nothing more. With me when I get calls like that, I tell them that I prefer to dial their toll free telephone number to talk to their fraud dept and see what may be the problem. Always suspect that the person calling is not really from your bank or credit card company but is a crook.

• Frequently check the balance of each banking account you have, as there are a lot of “Wire Transfer” fraud and often you only have 24 hours to stop a wire transfer, if you notice it later your bank may NEVER pay you back even though you did NOT authorize the wire transfer. (I know this sounds strange but I have talked to many lawyers whose clients lost their savings on unauthorized wire transfers and there is NO law to protect the person, the money is GONE). Check your bank balance daily.

• When you look for something on Internet, say using “Google” and you see a website that has all kinds of things posted on it; e.g. airplane tickets, charity stuff, news about movies, etc. Do NOT click on any links, these strange websites that have everything interesting on them are often set up by very smart crooks, very smart, and the links will direct all kinds of spyware (keyboard collection tools say to collect your banking user name and Passwords) loaded into your PC. Just exit and do NOT click on any links!

• Alway download the lastest Microsoft browser, word, Adobe updates, etc. These companies constantly try to add security features to their software. The moment you get an update from Microsoft or Adobe, load it asap. They sent you the updates because they have just fixed a security issue.

• Next time you order checks, do NOT put your first name and just have your initial and last name on them. If someone takes your check book they will not know if you sign your checks with just your initials or your first name but your bank or credit union will know how you sign your checks.

• When you are writing checks to pay on your credit card accounts, DO NOT put the complete account number on the “For” line. Instead, just put the last four or five numbers. The credit card company knows the rest of the number and anyone who might be handling your check as it passes through all the check processing channels won’t have access to it.

• Put your work phone # on your checks instead of your home phone. If you have a PO Box use that instead of your home address. Never have your Social Security Number printed on your checks!. You can add it if it is necessary.

• Place the contents of your wallet on a photocopy machine, do both sides of each license, credit card, etc. You will know what you had in your wallet and all of the account numbers and phone numbers to call and cancel. Keep the photocopy in a safe place. Also, carry a copy of your passport when traveling anywhere.

Very important, when you know your credit cards are stolen do this:
• Call the three national credit reporting organizations immediately to place a fraud alert on your name and Social Security number.
The alert means any company that checks your credit knows your information was stolen and they have to contact you by phone to authorize new credit.
Here are the phone numbers to contact:
Equifax: 1.800.525.6285
Experian: 1.888.397.3742
Trans Union: 1.800.680.7289
Social Security Administration (fraud line): 1.800.269.0271

Related articles and Books

Credit Card Scams II

Fraud Prevention Techniques for Credit Card Fraud

100% Internet Credit Card Fraud Protected


Nov 15 2011

Top 10 Cyber Scams During Holiday Season

Category: cyber security,CybercrimeDISC @ 10:49 am

By Paul C Dwyer

“Tis the season to get scammed!”

Phishing Scams: PCD Says “Beware of emails that appear to be from charities. Not all will be real and bogus sites could steal your credit card details. These “Phishing” emails can also pretend to be banks, telephone companies and even the revenue commissioners. There is even now a category of “recession based” scams which involve targeting consumers with products such as pre approved loans etc. There is also an increase in “Smishing” attacks, that is phishing messages sent out by text.”

PBX / Telephone Fraud: PCD Says “This is the time of year when SME’s and indeed large enterprises phone systems often get hacked. Hackers penetrate the phone system and can reroute Euro 1,000’s of calls through the companies phone system. The criminals often sell call cards openly in markets and on the streets which operate off these hacked phone systems. The first the company know about it is when they return after Christmas to a massive phone bill. Consider having a security audit on your phone system.”

Free iPad’s: PCD Says “Offers of free iPads and similar gadgets are included in most cyber scams lists at the moment. Victims are often requested to participate in some sort of basic quiz or supply their mobile telephone number. In many cases their mobile phone is then “subscribed” to some sort of service that costs Euro X per week.”

Fake Delivery Services Invoices: PCD Says “Over the Christmas period, cyber criminals will email fake invoices and delivery notifications appearing to come from legitimate courier companies. The emails will indicate that they were unable to deliver a package to your address and of course ask you to confirm your address and provide credit card details pay for delivery.”

Smartphone App Scam: PCD Says “Malicious spyware is disguised in a game or an application, which is then marketed to users. If downloaded, the malware steals data from the phone, such as passwords and financial details. Always check a developer is legitimate and review comments regarding the app.”

Fake Goods: PCD Says “Don’t be stupid, if the offers looks too good to be true it probably is. Beware of imitation goods for sale, most are sub standard, many are dangerous and in some cases lethal. Be especially careful when buying computers good such as laptops etc, we have come across a number “preloaded” with key logging software. There are also lots of fake auctions and classified ad sites appear that over Christmas, make sure you are dealing with a genuine business.”

Social Networking Friend Requests: PCD Says “Scammers take advantage of this social time of year by sending out authentic looking friend requests via email. You should not click on the links in the email but sign into your social networking site and look there for friend requests. If you click on a link it could install malware on your computer. Beware of related scams such as “Help I’ve been Mugged!”, this is when you receive a fake distress message from someone in your network requesting money as they have been robbed whilst traveling.”

Fake Christmas Cards: PCD Says “Be careful if clicking on a Christmas E-card or Gift Cards. This method is used to install Malware and other bad stuff. Many E-cards look genuine and authentic so be very careful when considering click on them. If you use an E-Card service obviously make sure it is a reputable one.”

PC Support Fraud: PCD Says “Criminals will attempt to gain access to your computer by calling up and saying you have a problem with your computer. They often claim to be from large legitimate corporations and will either ask for a payment to fix your computer or ask you to download a software patch. In the first case they will steal your credit cards details and in the second instance they will infect your machine with spyware or malware that will provides access to your machine bandwidth to support other attacks.”

Social Network Virus: PCD Says “This is very basic and involves a friend posting a link on your social network wall page or in the status update. This gives the impression that the site is a safe site to visit. However, in some cases it is the result of malware and could result in the download of viruses on your machine.”

Shopping smart and avoid scams: financial literacy during the holiday season: hearing before the Committee on Banking, Housing


Nov 12 2011

A guide to the realities of the subversive multi-vector threats

Category: CybercrimeDISC @ 9:07 pm

Cybercrime and Espionage

A guide to the realities of the subversive multi-vector threats (SMTs) now emerging as potential bearers of doom for organisations and countries

This guide will enlighten you to the dangers posed by SMTs like cyber crime and espionage in the 21st Century. Forewarned is forearmed, and this is what this book will help you to achieve by having the knowledge of these threats so you can prevent them affecting your organisation or country.

The goals of these SMTs are many, but below listed are some of the potential consequences posed by these threats:

> The sale of intellectual from one organisation to a competitor
> Compromise of financial data and systems
> Undermine the security posture of a nation by another nation

These threats are very real, and as more people and nations become connected to the Internet the dangers increase.

In addition to what you’d expect from a book covering cyber crime and espionage, this book also delves into the psychological profiles of those perpetrating these crimes or attacks.

Key Features and Benefits:

  • A guide to SMTs that provides you with the knowledge necessary to defend against them. The knowledge you’ll glean from this book will help you to keep your company or nation’s systems safe and secure.
  • Covers not only corporate white-collar crime but also international espionage i.e. threats to national security. This book is particularly ideal for those in large public organisations where national security is a priority.
  • Written by two highly experienced information security professionals, they have extensive experience in both the private and public sectors having worked for such organisations as the CIA, McAfee and IBM to name a few.
  • To buy -> Cybercrime and Espionage: An Analysis of Subversive Multi-Vector Threats


    Nov 10 2011

    Cloud services breached via Google code search

    Category: Cloud computingDISC @ 10:32 pm

    Researchers at Stach & Liu, a security consulting firm, have advised organizations against storing critical information on the public cloud until there are better intrusion detection systems available for cloud services, the Dark Reading website reports.

    The firm made the recommendation after discovering that access codes and passwords to thousands of public cloud services could be found via a simple Google search. The firm first reported the results of their cloud services security research at the Hacker Halted conference in October in Miami, according to Dark Reading.

    “It is not a good idea to put sensitive data out in the cloud right now — at least not until there are intrusion-detection systems that would let users see these types of searches on their cloud services,” Fran Brown, managing director of the firm, told Dark Reading.


    Nov 08 2011

    Looking for a secure USB stick with hardware encryption

    Category: Access Control,data securityDISC @ 10:55 pm

    CESG Approved USB Stick
    CESG is the UK Government’s National Technical Authority for Information Assurance

    Over 1 million SafeSticks are now in use in the NHS helping to keep patient data and other confidential data secure! Buy your SafeStick today!

    SafeStick is a secure USB stick with AES 256 bit hardware encryption and is FIPS 197 certified.

    SafeStick includes brute force attack lockdown protection. This means should the password to your SafeStick be entered incorrectly a number of times, the SafeStick is disabled or the data on it wiped.

    The antivirus and anti-mailware software available for SafeStick (at an extra cost) prevent any nefarious software from spreading on your SafeStick. With one in four virus or mailware attacks now spread by USB sticks, this is an essential control to have in place.

    Key Features and Benefits:

  • Uses AES 256 (FIPS 197 certified) hardware encryption to protect your data – this makes it highly unlikely that, should a drive be lost, that anyone would be able to access the data.
  • This stick is the one that was chosen for use by the UK’s National Health Service (NHS). To date over 1 million SafeSticks are now in use in the NHS helping to keep patient data and other confidential data secure!
  • SafeStick is a fully manageable enterprise solution when used in partnership with SafeConsole (available at an extra cost). SafeConsole allows you to kill a stick if it has gone missing. It also enables you to enforce group policies, allowing you to enforce such policies as allowing certain file types to be put on the drive whilst denying others. You can also reset passwords using SafeConsole.

    SafeStick is tough, durable, waterproof, heat resistant, crush proof. It can take anything you can throw at it.

    SafeStick is compatible with Windows 7, Vista, XP, 2000, 2003, 2008, Mac OSX, Linux and Citrix in an ultra small form factor and can be used as a either a standalone or enterprise solution.

    Simply plug in a SafeStick and within minutes you can be up and running. All you need do is set a password and any data placed on the SafeStick is encrypted.

    Order your SafeStick today!!!

    BlockMaster SafeStick 1G Encrypted USB Flash Drive

    BlockMaster SafeStick 2G Encrypted USB Flash Drive

    BlockMaster SafeStick 32G Encrypted USB Flash Drive


    Nov 03 2011

    Knowledge Management finally gets it’s own book: WKIDM

    Category: Data mining,data securityDISC @ 9:11 am

    by Melanie Watson
    That’s right, Knowledge Management finally has it’s own book: Information Lifecycle Support: Wisdom, Knowledge, Information and Data Management (WKIDM).

    The primary role of Knowledge Management is to “improve the quality of decision making” by making sure that information throughout the Service Lifecycle is accurate, reliable and trustworthy. This book covers all four areas of knowledge: data, information, knowledge and wisdom.

    This book, (endorsed by the OGC – the creators of the ITIL methodology) provides a comprehensive and much-needed source of information on data and information management. It examines the effective production, coordination, storage, retrieval, dissemination and management of information from internal and external sources.

    Information Lifecycle Support: Wisdom, Knowledge, Information and Data Management (WKIDM)

    Tags: it service management, ITIL, ITSM


    Nov 02 2011

    Inside IT: Cloud Computing & Security

    Category: Cloud computingDISC @ 2:13 pm

    IT Best Practices: The IT organization is undergoing rapid change. Changes like virtualization and consumerization present new opportunities for business, and new challenges for IT. Cloud computing shifts IT to more of a creator and distributor of services, but brings with it increased security concerns. In this podcast, Alan Ross, who leads the Security Architecture and Technology Development Team at Intel IT, talks about data security, application security, compliance, privacy, and other issues around these evolving technologies.




    Securing the Cloud: Cloud Computer Security Techniques and Tactics


    Cloud Security: A Comprehensive Guide to Secure Cloud Computing


    The Cloud Security Rules: Technology is your friend. And enemy. A book about ruling the cloud.


    « Previous PageNext Page »