1-888-373-0680

IT Security. Risk Management. Business Intelligence.
Our Foundation, Your Advantage.

CSO Online

09/08/2010

Moving day: How to protect your company during a relocation

Whether you're moving to a new headquarters or opening a new location or store, you'll need to keep tabs on a wide variety of assets. Careful planning will secure your business and get you back up and running quickly.

Read More


09/08/2010

Mozilla fixes Firefox's DLL bug

Mozilla on Tuesday patched 15 vulnerabilities in Firefox, 11 of them labeled critical.

Read More


09/08/2010

Symantec: Hacking victims blame themselves

Just under two-thirds of all Internet users have been hit by some sort of cybercrime, and while most of them are angry about it, a surprisingly large percentage feel guilt too, according to a survey commissioned by Symantec.

Read More


09/07/2010

Enterprise risk management: Get started in six steps

Daunted by the ambition of enterprise risk management? Here's a straightforward exercise to get started delivering ERM's business value.

Read More


09/07/2010

Microsoft investigates two-year-old IE bug

Microsoft is looking into a long-known vulnerability in Internet Explorer (IE) that could be used to access users' data and Web-based accounts.

Read More


Webcasts

Unifying Enterprise Management - IT Search

How to choose the right software-based security, systems and process management solutions that help organizations gain deeper visibility into, and control over, their existing processes and infrastructure.

How to get real-time visibility into the health of critical assets, and provide administrators a powerful array of tools to quickly analyze and respond to critical health or performance issues.

Integrating NETWORK MANAGEMENT
Review management solutions that combine the power of advanced event correlation and policy enforcement with network and asset management.

Other Topics of Discussion:

  • VOIP and Convergence
  • Network and System Management
  • Information Security
  • Compliance and Log Management

 To view this webcast, click on the following link:

https://www1.gotomeeting.com/register/477233817

 
To view the presentation from the webinar, click on the slides below:



Application Security Course for Executives

Information Security Latest Trends

  • Convergence onto Security Platforms: Endpoint, Email security gateway, Web security gateway, and Next-generation firewall
  • Virtualization: Virtualization of security controls will alter the information security landscape.
  • Cloudification: How to enforce an enterprise security policy in the cloud age?
  • Externalization: How to be open, social and encourage secure collaboration with external entities?
  • Consumerization: Increasingly, employees want to use their consumer technology (systems and software) for business use.
  • Operationalization: Need a strategy / R&D and an operational component to security. The strategy / R&D team needs to have time and resources to tackle the new and emerging threats.

Application Security

  • Methodology 
  • Threats, Attacks, Vulnerabilities, and Countermeasures
  • Application Threats / Attacks
  • Mobile Application Security
  • Security testing for applications
  • Security standards and regulations

Information Risk Management

  • Understanding your risk
  • Measuring and quantifying your risk
  • Managing your risk
  • Optimizing expenses

To view this webcast, click on the following link:

https://www1.gotomeeting.com/register/344426752


Presented by: Security Art
Security Art is an information security and risk management consulting and advisory boutique. They use a multi-disciplinary approach with years of hands-on experience giving businesses the strategic path to address all their information security and risk management needs.

 
To view the presentation from the webinar, click on the slides below:



 

Measuring Risk – What Works and What Doesn’t

Regardless of how quantitative your environment might be, be a skeptic about how your organization assesses decisions and risks – ask how they know it works (and consider the consequences if it doesn’t). Whether your current method is your judgment or some more formal method, it has a performance that can – and must – be measured.

The topics for this webinar include:

  • The Problem – Why your method may be a “management placebo” and why that is the biggest risk you have
  • Problems that many methods ignore – and problems some methods introduce
  • What Does Work – Studies reveal some methods show consistent, measurable improvements on the forecasts and decisions of managers
  • Examples of Real Improvements
  • Overview of Applied Information Economics (AIE) Process
  • Common Objections to quantitative methods and the misconceptions behind them
  • Questions & Answers

Considered against the size and risk of decisions, better risk analysis will be one of the best investments in your organization.

Presented by: Doug Hubbard
Mr. Hubbard is the inventor of the powerful Applied Information Economics (AIE) method. He is the author of the #1 bestseller in Amazon’s math for business category titled How to Measure Anything: Finding the Value of Intangibles in Business (Wiley 2007). His latest book is titled The Failure of Risk Management: Why It’s Broken and How to Fix It (Wiley 2009).

To view this webcast, click on the following link:

www1.gotomeeting.com/register/772701473



To view the presentation from the webinar, click on the slides below:



Application Security - Ethical Hacking

 

In the race to develop online services, networked hosts and underlying applications have often been deployed with minimal attention to security risks. The result is that most corporate sites are surprisingly vulnerable to hacking or industrial espionage. To test this, Ethical Hacking (sometimes referred to as Penetration Testing) is performed in conjunction with vulnerability scanning. We have a team of ethical hackers that can perform an in-depth analysis of identified potential high-risk vulnerabilities with the primary objective to gain access to sensitive data assets within the organization environment as a practical demonstration of what a malicious individual could accomplish. Many vulnerabilities, when viewed independently, do not pose a great risk to the organization. When these weaknesses are combined and placed in the hands of a skilled attacker, the result is often a breach. Understanding and resolving configuration and security issues helps prevent the organization from experiencing and having to disclose a real attack in the future.

The objectives of this webcast are to:

  • Present current up to date vulnerabilities deriving from web application security.
  • Explain why each of these vulnerabilities are important to be dealt with.
  • Recommend the best way of dealing with these attacks.

A list of topics for this webcast is:

  • Cross-Site Script (XSS)
  • SQL Injection
  • Broken Authentication and Session Management
  • Insecure Direct Object References
  • Cross-Site Request Forgery (CSRF)
  • Un-validated Redirects and Forwards (ie. Phishing and Content Spoofing)
  • Browser Security
  • Smart D.O.S.
  • 0-day Presentation

To view this webcast, click on the following links:

Part 1: https://www1.gotomeeting.com/register/423408464
Part 2: https://www1.gotomeeting.com/register/637212089

 

 To view the presentation from the webinar, click on the slides below:


Infrastructure and IT Storage Assessments

Company infrastructures are continually adapting to rapidly changing technological and business requirements. As a result, Information Technology infrastructures often operate in a less-than-ideal state. Unless they have been properly planned and are correctly managed, these IT infrastructures will deliver sub-optimal performance and value.

New technologies often bring higher densities of equipment, which can overload cooling systems, place heavy demands on power distribution systems, and create cabling nightmares. The exponential growth in data generation and data retention creates an unprecedented need for increased storage capacity. And, inadequate levels of staffing often lead to poor planning and execution, which can cause organizations to lag behind rather than get ahead of the game.

Aliado Accesso and its infrastructure assessment partners will evaluate all facets of your infrastructure and storage systems, from the facility to the disk farm to the server, using a holistic approach. Then, we will help you create a plan to manage, without turmoil, your current infrastructure and future growth in capacity. We have put together a team that can provide you with a single source of infrastructure and storage assessment, planning, and remediation. Our experienced team can take you from the green field to the completed data center, providing you all the requirements for a successful IT implementation.

Webinar topics include:

  • Facilities Assessment: address fundamental issues surrounding basic data center space, power, and cooling.
  • Wiring Assessment: addresses cabling issues.
  • Storage Assessment: current and future storage needs and integration.
  • Monitoring Assessment: the advantages of a monitored and managed facility.

To view this webcast, click on the following link:


https://www1.gotomeeting.com/register/568420672

 

To view the presentation from the webinar, click on the slides below:


Writing Secure Applications - Maximizing ROI through CBT

 

Faced with building tomorrow’s software, development efforts focus on innovation and speed to be competitive, but developers must also ensure they focus appropriately on security. The greatest threat from a hacker is the exploitation of insecurities baked into applications during the development process when security can be overlooked or misunderstood.

Training developers to code securely is the number one most effective way to secure your enterprise for tomorrow. Leveraging the power of CBT’s can maximizes this effectiveness. Using a foundation of knowledge from experts in the field, our CBT’s combine the knowledge of real world threats with the proven approaches that have been honed in classroom settings. The training uses clear objectives, easy to understand case videos, engaging learning games, and comprehension assessments to ensure students understand the key values of the instruction.

The objectives of this webinar are to:

  • Understand how CBT’s can achieve objectives
  • Explain how the training offerings can be used as the basis, or reinforcement, for your development efforts
  • Detail the cost to benefit over traditional classroom instruction

A list of topics for this webinar is:

  • Overview of Developer PCI DSS Awareness
  • Overview of OWASP Top Ten Case Studies
  • Overview of Secure Java Coding for Developers
  • Overview of Secure .NET Coding for Developers
  • Overview of Security Testing
  • Overview of Reporting
  • Overview of Customization

To view this webcast, click on the following link:


https://www1.gotomeeting.com/register/215990273


To view the presentation from the webinar, click on the slides below:

To view a demo of a CBT, click on the following link:

http://symosis.com/Newdemo/Index.html

 


Introduction to FAIR

 

Factor Analysis of Information Risk (FAIR) is an easy to understand, effective methodology and toolset for risk analysis, risk management, root cause analysis, and decision making.

Learn how to better articulate risk to upper management and examine a methodology used to produce defensible quantitative risk analysis.

Learn to facilitate a clear understanding of:

  • What is my current risk posture?
  • What is my desired state?
  • What are my control opportunities?

By using FAIR for your risk assessment, you will have timely and dependable data with a strategic advantage. FAIR provides a common language, vocabulary and framework for understanding risk. FAIR enables technologists to articulate information security and risk in a way that can be understood by all stakeholders.


To view this webcast, click on the following link:


http://www1.gotomeeting.com/register/300933993

To view the presentation from the webinar, click on the slides below:



© 2010 Aliado Accesso LLC