Big Steps Toward Managing Security and Compliance for Virtual Infrastructure

This week, the industry celebrates one of the most influential and explosive technologies influencing the world of information systems: Virtualization. At VMWorld 2010, the focus on virtualization across the enterprise and cloud computing highlights some of the most interesting and impactful technologies that our industry is utilizing. We have had…

Author Ira Winkler talks security – Podcast #197

This week’s Speaking of Security podcast features an interesting discussion with Ira Winkler, a well-known expert on internet security and information-related crime investigation.

The Cloud has a Silver Lining

Talking with customers every day, I hear constant concerns about lack of visibility into (and control over) security and compliance in the virtual infrastructure, lack of guidance and orchestration tools and the high cost and difficulty of meeting audits and achieving compliance.

Popularity of automated stores in the black market increase as source code is traded in “kits”

In my last post, I discussed the trend of automated credit card stores proliferating in the fraudster underground. In addition to the reasons I listed…

RSA Archer eGRC Road Show – Podcast #196

This week’s Speaking of Security podcast discusses the upcoming RSA Archer eGRC Road Show. We also debut the Speaking of Security Newswire, featuring the latest security and technology headlines.

Only You Can Prevent (Internet) Forest Fires: driving online safety and security home

There’s an important Messaging Convention around online consumer safety and security that wrapped up this month, put on by the National Cyber Security Alliance (NCSA), Anti-Phishing Working Group (APWG) and member organizations including RSA around communicating the central role of people in protecting themselves and, frankly…

Payment Security Insight from the Verizon 2010 Data Breach Investigations Report

This week, Verizon released their 2010 Data Breach Investigations Report. The report is a treasure trove of statistics that illuminate all facets of what’s happening in recent compromises. I wanted to focus on the insight around the current state of payment card data breaches, which continue to make up a majority of the breaches (54%) that Verizon’s RISK team investigates and writes about.

Nation States and Mobile Devices: It’s Time to Listen

The motivations, instincts and needs of Nation States, regardless of rhetoric, are largely the same for Akkadia, Sumeria, Rome and ancient Judea as they are for the modern USA, China or European state. The theaters in which nations can act and the tools and trade-offs among tactics are very different, and this has come to light recently with some activity and demands around features and requests for mobile endpoints.

The Dog Days of Summer – Podcast #195

The dog days of summer mean a chance to reflect on some hot industry topics with Sam Curry, Chief Technologist for RSA.

Automated Credit Card Stores and the Business of Trading in the Fraud Underground

Innovation and evolution are two words that are not hard to find in blog posts and news articles about fraud. It seems that almost every day security researchers uncover new features and improvements in fraudsters’ tools and infrastructure. Many of these innovations stem from the availability of new services in the underground.