http://www.rsa.com/blog/rssfeed.aspx Speaking of Security, the RSA Blog and Podcast http://www.rsa.com/blog/ Speaking of Security is the RSA Blog and Podcast. It features a group of experts in identity management, encryption, privacy, policy, and enterprise security standards. Security http://www.rsa/blog/images/small_blog_logo.gif http://www.rsa.com/blog/ 144 36 Speaking of Security A Podcast for Security Professionals A weekly look at RSA's – and the industry's – issues-of-the-moment. RSA, The Security Division of EMC en-us no RSA, The Security Division of EMC podcast@rsa.com Copyright 2005 - 2008 RSA Security Inc. Security When Things Go 'Boom' Part III - Returning to Normalblog@rsa.com (John McDonald )http://www.rsa.com/blog/blog_entry.aspx?id=1487Wed, 01 Jul 2009 00:00:00 GMTblog@rsa.com (John McDonald )http://www.rsa.com/blog/blog_entry.aspx?id=1487<p>OK, we're in the home stretch - this is the final entry in my 'Security and Disaster Recovery' series. So far we've covered security incidents as disasters, <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1440" target="_blank">DR for security controls</a> and the <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1481" target="_blank">security of your DR environment</a>. The last area of consideration is what happens when you need to return to normal operations. The disaster has occurred, you've successfully moved to your DR environment, and things have been humming along. Now the damage to your primary site has been repaired and you're ready to move back - how does this impact security? </p>The Birth of the Virtual Datacenter Administrator blog@rsa.com (Nirav Mehta)http://www.rsa.com/blog/blog_entry.aspx?id=1486Wed, 01 Jul 2009 00:00:00 GMTblog@rsa.com (Nirav Mehta)http://www.rsa.com/blog/blog_entry.aspx?id=1486<p>I recently spoke at a VMware user group conference about securing virtualization. The audience comprised datacenter administrators and managers who are at the center of their organization's virtualization initiatives.&nbsp; I was fortunate to be able to talk with several of them at length about their experiences in virtualizing datacenters.&nbsp; There are several trends to note.</p>The expanding complexity of 'insiders': what you need to take into accountblog@rsa.com (Nicki Wallace)http://www.rsa.com/blog/blog_entry.aspx?id=1485Tue, 30 Jun 2009 00:00:00 GMTblog@rsa.com (Nicki Wallace)http://www.rsa.com/blog/blog_entry.aspx?id=1485<p>At the April 2009 <a href="http://www.rsaconference.com/2009/us/index.htm" target="_blank">RSA Conference</a>, over 500 speakers discussed the most pressing information security issues organizations face today. I was very interested to hear the <a href="http://www.sei.cmu.edu/" target="_blank">Carnegie Mellon University Software Engineering Institute (SEI)</a> talking about best practices for mitigating insider threat. (As discussed in my previous blog, this is the aspect of insider risk dealing with insiders who deliberately exploit security vulnerabilities to cause harm or for personal gain.) </p>ISO-ishblog@rsa.com (Todd Graham)http://www.rsa.com/blog/blog_entry.aspx?id=1484Thu, 25 Jun 2009 00:00:00 GMTblog@rsa.com (Todd Graham)http://www.rsa.com/blog/blog_entry.aspx?id=1484<p>The conversation develops with such consistency and regularity I've begun to wonder why I still ask. But I do. Without fail, at every customer I meet I utter the question &quot;do you use any frameworks to help with your governance, risk, and compliance?&quot;</p>Insider risk and insider threat: what's the difference and why does it matter?blog@rsa.com (Nicki Wallace)http://www.rsa.com/blog/blog_entry.aspx?id=1482Tue, 23 Jun 2009 00:00:00 GMTblog@rsa.com (Nicki Wallace)http://www.rsa.com/blog/blog_entry.aspx?id=1482<p>What does the term 'insider risk' mean to you? Does it make you think about employees sabotaging systems, or stealing confidential information for their own benefit?</p>Speaking of Security Podcast #151blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1483Mon, 22 Jun 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1483<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1483">Click to Download/Listen</a> <br> <br /> Roland Cloutier, VP and CSO of EMC joins us on this week's Speaking of Security podcast.Security When Things Go 'Boom' Part II - Securing Your DR Environmentblog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1481Thu, 18 Jun 2009 00:00:00 GMTblog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1481<p>Sorry for the delay in updating my blog - for some reason Q2 seems to be the event season, and we've been pretty busy here at RSA supporting HIMSS, RSA Conference, MS TecEd, EMC World and a bunch of other events. Anyway, it's time to continue our discussion of the relationships between security and disaster recovery. In this entry we'll take a look at what needs to be considered to ensure your DR environment itself remains secure.</p>The more things change the more they seem to stay the same. When are we going to learn?!?!?!blog@rsa.com (Ken Tyminski)http://www.rsa.com/blog/blog_entry.aspx?id=1480Thu, 11 Jun 2009 00:00:00 GMTblog@rsa.com (Ken Tyminski)http://www.rsa.com/blog/blog_entry.aspx?id=1480<p>Recently there has been a lot of chatter about how security teams need to get out ahead of the latest technology advances. There is talk about how cloud computing and virtualization are going to take business to new levels and enable new relationships. On top of this social networking is finding its way into the business environment and raising concern that with mounting financial pressures businesses won&rsquo;t be prepared to address the increased risks these technologies introduce.</p>The Security Apartheid: The beginning of the end?blog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1478Tue, 09 Jun 2009 00:00:00 GMTblog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1478<p>Security has been notably absent from earlier evolutions in the computing industry. For long, the industry has evolved through two parallel universes: 1) The IT infrastructure universe creating innovative techniques to compute, communicate and store information with little to no security consideration and 2) the IT security universe trying to solve the security problems newly created by IT innovators.</p>Speaking of Security Podcast #150blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1479Tue, 09 Jun 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1479<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1479">Click to Download/Listen</a> <br> <br /> This week marks the 150th edition of the Speaking of Security podcast. We discuss the recent release of President Obama's 60- day cyber security review and the creation of a "cyber coordinator" position in his administration. We also have news on the 2009 Gartner Magic Quadrant for Security Information and Event Management. RSA/EMC is positioned in the leader's quadrant for the sixth consecutive year.The Security-aware Cloudblog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1477Fri, 05 Jun 2009 00:00:00 GMTblog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1477<p>To build security into the IT infrastructure demands much more than secure software. It is also about having the IT infrastructure products deliver intrinsic security value as a core capability of the product and fully integrated in terms of management and enforcement with the other non-security related capabilities of that product.</p>PCI Certified Products???blog@rsa.com (Brad Davenport )http://www.rsa.com/blog/blog_entry.aspx?id=1476Tue, 02 Jun 2009 00:00:00 GMTblog@rsa.com (Brad Davenport )http://www.rsa.com/blog/blog_entry.aspx?id=1476<p>Recently, I&rsquo;ve been receiving inquiries from customers, asking if a certain product is <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI DSS </a>&ldquo;compliant,&rdquo; &ldquo;certified,&rdquo; or &ldquo;validated&rdquo;.</p>Generational Conflict, Security and an "Information Bill of Rights"blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1475Mon, 01 Jun 2009 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1475<p>In my college days, I would go into the wonderful old mills of <a href="http://en.wikipedia.org/wiki/Umass_Lowell" target="_blank">UMass Lowell</a>.&nbsp; I remember seeing signs on the walls that were old and, I suppose, historical pieces.&nbsp; One of them always struck me: it said &ldquo;no singing, eating or dancing.&rdquo;Speaking of Security Podcast #149blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1473Tue, 26 May 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1473<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1473">Click to Download/Listen</a> (11:05) <br> <br /> This week's Speaking of Security podcast features a discussion on securing personally identifiable information with Jon Oltsik, Principal Analyst for Enterprise Strategy Group.There Is No Spoonblog@rsa.com (Todd Graham)http://www.rsa.com/blog/blog_entry.aspx?id=1474Tue, 26 May 2009 00:00:00 GMTblog@rsa.com (Todd Graham)http://www.rsa.com/blog/blog_entry.aspx?id=1474<p>Over the last 12 months we&rsquo;ve been hearing more and more from our customers about Governance, Risk, and Compliance (commonly known under the acronym &ldquo;GRC&rdquo;). Sam Curry began to dive into the subject with his blog entry <em><a href="http://www.rsa.com/blog/blog_entry.aspx?id=1464" target="_blank">Will the Real GRC Please Stand Up?</a> </em>and did a great job of summarizing the emerging attitudes from some of the market analysts. </p>Nothing Can Come of Nothingblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1472Fri, 22 May 2009 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1472<p>Two things amuse me when they are misunderstood in security, and they really are axioms of the industry.&nbsp; Folks involved in security should know and think about these two principles, and part of me is putting this out there in the hope that folks will take issue with this!</p>Conspiracy Theoryblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1470Wed, 20 May 2009 00:00:00 GMTblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1470<p>Don't you just love conspiracy theories? Here's a new one for you.</p> <p><strong>April 21, 2009: F35 Fighter Jet Program Breached</strong></p> <p>The <a href="http://online.wsj.com/article/SB124027491029837401.html" target="_blank">Wall Street Journal</a> reported a data breach in the F35 Joint Strike Fighter Jet program. According to the report, someone allegedly hacked into one of the program's databases &ndash; perhaps run by a third party involved in the project &ndash; and siphoned off an unknown amount of sensitive information. The breach was apparently in an area connected to the Internet and databases segregated from the Web were not affected.</p>Little Orange Line &ndash; Breaking Out of the Zero Sum Security Curveblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1471Wed, 20 May 2009 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1471<p>I went to <a href="http://www.courion.com/courion-identity-access-management.html" target="_blank">Courion&rsquo;s</a> <a href="http://converge.courion.com/home/" target="_blank">Converge</a> conference, where they bring their customers together to share wisdom around Identity Management and tips-and-tricks and the like &ndash; this is a lot like the early spirit of the <a href="http://www.emcworld.com/" target="_blank">EMC World</a> and in fact like many user groups.&nbsp; </p>Speaking of Security Podcast #148blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1469Mon, 18 May 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1469<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1465">Click to Download/Listen</a> (7:15) <br> <br /> This week's Speaking of Security podcast features a topical discussion on business continuity planning. Recent global concerns regarding a potential Swine Flu pandemic have organizations looking at possible operational and business disruptions. Sam Curry, VP of Product Management for RSA is our guest.A Security Engineering Training Frameworkblog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1468Tue, 12 May 2009 00:00:00 GMTblog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1468<p>If there is one topic on which most security practitioners agree, it is the fact that employee training must be part of your organization&rsquo;s security strategy.</p>Speaking of Security Podcast #147blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1465Mon, 11 May 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1465<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1465">Click to Download/Listen</a> (14:00) <br><br /> This week's Speaking of Security podcast presents a lively conversation with Shannon Kellogg, Director of Information Security Policy for EMC's Office of Government Relations on security related activity in Washington, DC.Ground-Up SharePoint Governanceblog@rsa.com (Dave Howell)http://www.rsa.com/blog/blog_entry.aspx?id=1466Mon, 11 May 2009 00:00:00 GMTblog@rsa.com (Dave Howell)http://www.rsa.com/blog/blog_entry.aspx?id=1466<p>In case you hadn't noticed,&nbsp;SharePoint is everywhere (a bit like pig flu hysteria).&nbsp; It's a great success story for Microsoft, and the release of MOSS 2007 added a ton of features that inspired businesses to either roll out the platform or upgrade.&nbsp; Once SharePoint is made available, there is no turning back... good luck wrestling a site out of the hands of a department that's come to rely on it.</p>Mr. President, it's Time to Make Cyber Security a National Priorityblog@rsa.com (Shannon Kellogg )http://www.rsa.com/blog/blog_entry.aspx?id=1467Mon, 11 May 2009 00:00:00 GMTblog@rsa.com (Shannon Kellogg )http://www.rsa.com/blog/blog_entry.aspx?id=1467It is vitally important to national security and economic security that President Barak Obama fulfills a pledge that he made on the campaign trail concerning the security of our nation&rsquo;s information infrastructure.&nbsp; During the 2008 presidential campaign, Mr. Obama compared cyber security threats with other 21st century national security challenges such as biological and nuclear weapons.&nbsp; He said at the time that he would declare the country&rsquo;s critical infrastructure a national asset and that he would appoint a cyber advisor that would report directly to him.Will the Real GRC Please Stand Up?blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1464Tue, 05 May 2009 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1464<p>Ok &ndash; I have to say that I am getting pretty tired of GRC as an abused acronym. This is <em>Governance, Risk and Compliance</em> for the very few of you who haven't had the good fortune to see it actually spelled out; or &quot;Grick&quot; if you haven't had the opportunity of hearing someone pronounce an acronym without a vowel in it.&nbsp;&nbsp; </p>Remote Access Critical in Contingency Planningblog@rsa.com (Sam Curry )http://www.rsa.com/blog/blog_entry.aspx?id=1463Mon, 04 May 2009 00:00:00 GMTblog@rsa.com (Sam Curry )http://www.rsa.com/blog/blog_entry.aspx?id=1463<p>I have seen an interesting phenomenon in the last 24 hours: a lot of folks are calling and asking for sudden, urgent help with remote access.&nbsp; The cause is apparently related to <a href="http://en.wikipedia.org/wiki/Swine_influenza" target="_blank">Swine Flu</a>, but the root cause is both a fear for real people in our companies and a concern about maintaining business functions in a time of doubt, worry and fear.</p>What is RSA Anyway?blog@rsa.com (Sam Curry )http://www.rsa.com/blog/blog_entry.aspx?id=1461Wed, 29 Apr 2009 00:00:00 GMTblog@rsa.com (Sam Curry )http://www.rsa.com/blog/blog_entry.aspx?id=1461<p>At the RSA Conference, I was asked a lot about what we &ldquo;are&rdquo; as the security division of EMC.&nbsp; I think I&rsquo;ve come up with a pretty clean and clear way to answer that in a few simple statements.</p>Speaking of Security Podcast #146blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1462Tue, 28 Apr 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1462<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1462">Click to Download/Listen</a> (8:37) <br><br /> On this week's podcast, Forrester's Rob Koplowitz talks about the growth of Microsoft SharePoint in enterprises and the importance of putting governance around SharePoint as the platform becomes more strategic to companies.RSA Answers the Call To Armsblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1459Mon, 27 Apr 2009 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1459<p>In Art&rsquo;s keynote last week at RSA Conference, he made a clear call to the industry.&nbsp; We have to be <u>more organized</u>, <u>more coordinated</u> and <u>more collaborative</u> than either the enemy or than the industry has a history of being.&nbsp; Art had three calls to action:</p> <ol> <li>Integrate and Interoperate</li> <li>Create and Adopt Standards</li> <li>Share Technology</li> </ol>Who is the Man in the Middle?blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1460Mon, 27 Apr 2009 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1460<p>So, at RSA Conference, I think I met the <em>actual</em> <u>Man-in-the-Middle</u>.&nbsp; He was pretty tall and was smoking a cigar outside the Moscone center.&nbsp; He was hanging out with a sort of shady-looking guy with a nondescript accent, covered in tattoos. This man was the <em>actual</em> <u>Man-in-the-Browser</u>. </p>The Goby and the Shrimpblog@rsa.com (Nirav Mehta)http://www.rsa.com/blog/blog_entry.aspx?id=1455Thu, 23 Apr 2009 00:00:00 GMTblog@rsa.com (Nirav Mehta)http://www.rsa.com/blog/blog_entry.aspx?id=1455<p>What if virtualization makes security more effective and eficient?<br> What if virtualization actually reduces the cost of security?</p> <p>The relationship between virtualization and security is indeed symbiotic. It reminds me of the endearing mutualism between the <a href="http://en.wikipedia.org/wiki/Goby" target="_blank">goby fish</a> and the pistol shrimp.</p>What do RSA's Announcements at Conference mean for Europe?blog@rsa.com (Andrew Moloney)http://www.rsa.com/blog/blog_entry.aspx?id=1458Thu, 23 Apr 2009 00:00:00 GMTblog@rsa.com (Andrew Moloney)http://www.rsa.com/blog/blog_entry.aspx?id=1458 <p>RSA Conference in San Francisco is unusually &ldquo;hot&rdquo; this week. With temperatures reaching record highs outdoors, in the second of my posts from Conference, I thought I&rsquo;d take shelter inside and consider the announcements delivered by RSA at the show, and specifically my thoughts on their impact for us over in EMEA.</p>PCI Compliance and Virtualization: Feedback from QSAsblog@rsa.com (Brad Davenport)http://www.rsa.com/blog/blog_entry.aspx?id=1457Wed, 22 Apr 2009 00:00:00 GMTblog@rsa.com (Brad Davenport)http://www.rsa.com/blog/blog_entry.aspx?id=1457<p>So the <a href="http://www.rsaconference.com/2009/us/about-rsa-conference-2009.htm" target="_blank">RSA Conference</a> is off to great start.&nbsp; It&rsquo;s definitely one of my favorite times of the year given the tremendous amount of information security interest and expertise in one place.</p> RSA Conference 2009: An EMEA Perspectiveblog@rsa.com (Andrew Moloney)http://www.rsa.com/blog/blog_entry.aspx?id=1454Wed, 22 Apr 2009 00:00:00 GMTblog@rsa.com (Andrew Moloney)http://www.rsa.com/blog/blog_entry.aspx?id=1454<p>Greetings from RSA Conference 2009 in San Francisco. As the only RSA blogger currently based in Europe, I&rsquo;ve given myself the challenge of trying to use my blog to bring a EMEA perspective to the thoughts, themes and announcements from this year&rsquo;s show.</p>Learning lessons (at RSA Conference) the easy wayblog@rsa.com (Sam Curry )http://www.rsa.com/blog/blog_entry.aspx?id=1456Wed, 22 Apr 2009 00:00:00 GMTblog@rsa.com (Sam Curry )http://www.rsa.com/blog/blog_entry.aspx?id=1456<p>On Monday April 20th, I had the pleasure of speaking at and taking part in two forums: <a href="http://projectconcordia.org/index.php/April_20_pre-conference_workshop" target="_blank">"Harnessing the Power of Digital Identity: 2009 and the Promising Road Ahead"</a> sponsored by Project Concordia and the Liberty Alliance, and the RSA Conference<a href="https://365.rsaconference.com/community/efraudnetwork;jsessionid=C1581C0C04A9BC1DF3C7807474C1EA79" target="_blank"> eFraudNetwork Forum</a>.</p>Why is Risk-Based, Adaptive Authentication so Important in Providing Choice?blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1447Tue, 21 Apr 2009 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1447<p>Consider two gunslingers &ndash; we&rsquo;ve all seen this one on TV and in the movies.&nbsp; One has his gun drawn, the other has a gun in his holster.&nbsp; Some witty dialog ensues.&nbsp; Eventually, the one with his gun in his holster goes for the draw&hellip;and gets shot and dies.&nbsp; </p>The RSA Share Project: A Software Security Developer Communityblog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1453Tue, 21 Apr 2009 00:00:00 GMTblog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1453<p>This week, RSA, the Security Division of EMC, launched the <A href="http://www.rsashare.com/" title="http://www.rsashare.com/" target="_blank">RSA Share Project</A> -- &nbsp;an important milestone for those of us interested in advancing the adoption of security practices across the software developer community.&nbsp; According to the <A href="http://rsa.com/press_release.aspx?id=10098" title="http://rsa.com/press_release.aspx?id=10098" target="_blank">press release</A>, the project is &ldquo;designed to bring world-class security tools within reach of corporate and independent software developers&rdquo; and &ldquo;features the launch of a new online community designed to provide support, answers and strategies from security experts as well as no-cost access to technology from RSA&rdquo;.</p>Speaking of Security Podcast #145blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1449Tue, 21 Apr 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1449<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1449">Click to Download/Listen</a> (7:06) <br><br /> The Speaking of Security Podcast is providing extensive coverage of RSA news during RSA Conference week. We will be presenting two podcasts. The first is an overview of all the product and solution announcements made by RSA this week. The second (featured here) is a podcast discussing an addition to the authentcation solution portfolio.Speaking of Security Podcast #144blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1448Mon, 20 Apr 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1448<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1448">Click to Download/Listen</a> (6:49) <br><br /> The Speaking of Security Podcast is providing extensive coverage of RSA news during RSA Conference week. We will be presenting two podcasts. The first (featured here) is an overview of all the product and solution announcements made by RSA this week. The second is a podcast discussing an addition to the authentcation solution portfolio.<em>Tetraktys</em>: A Cryptographic Thriller Novelblog@rsa.com (Dr. Ari Juels)http://www.rsa.com/blog/blog_entry.aspx?id=1445Mon, 20 Apr 2009 00:00:00 GMTblog@rsa.com (Dr. Ari Juels)http://www.rsa.com/blog/blog_entry.aspx?id=1445<p>My cryptographic thriller novel <em><a href="http://www.tetraktysnovel.com/" target="_blank">Tetraktys</a></em> is slated for official release in July. My publisher is launching it this week, however, in a pre-release event at the <a href="http://www.rsaconference.com/2009/us/index.htm" target="_blank">RSA Conference</a>. </p>The Downfall of Chao: Behind the Scenes of an Online Fraudster's Arrestblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1451Mon, 20 Apr 2009 00:00:00 GMTblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1451<p>When Chao was arrested in September 2008, something in the veil of anonymity surrounding cyber crime was lifted. This blog will reveal previously undisclosed information regarding this case.</p>The Greatest Internet Generation...or Threat 2.0?blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1452Mon, 20 Apr 2009 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1452<p>On the plane out to RSA Conference this weekend, I thought about some not-so-obvious results of the recent economic downturn.&nbsp; I was watching a movie that involved WWII and the effect of de-mobilization on the U.S. economy in post-war years.&nbsp; This is a positive example of what a large group of organized, motivated people can do: what Tom Brokaw termed &ldquo;<a href="http://en.wikipedia.org/wiki/Greatest_Generation" target="_blank">the greatest generation</a>&rdquo;&nbsp; </p>"My software is secure, I use encryption!"blog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1450Fri, 17 Apr 2009 00:00:00 GMTblog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1450<p>&ldquo;My software is secure, I use encryption!&rdquo; How many times have we, software security practitioners, heard this when engaging with software development teams?<br>PCI DSS Compliance and Virtualization: Guidance Neededblog@rsa.com (Brad Davenport)http://www.rsa.com/blog/blog_entry.aspx?id=1444Thu, 16 Apr 2009 00:00:00 GMTblog@rsa.com (Brad Davenport)http://www.rsa.com/blog/blog_entry.aspx?id=1444<p>Earlier this week, I was meeting with a customer, discussing how some of their strategic IT projects they are undertaking in 2009 would impact their efforts around PCI DSS compliance.&nbsp; This customer is a manufacturer for the consumer market and is classified as a Level 1 Merchant.&nbsp; Like many organizations in today&rsquo;s environment, their overarching goal in 2009 is &ldquo;doing more with less.&rdquo;</p>Not with a whimper but with a bang*blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1446Wed, 15 Apr 2009 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1446<p>We&rsquo;ve had a lot of activity at RSA around hosted services, and the tremendous potential of things like <a href="http://www.emc.com/products/category/virtualization.htm" target="_blank">Virtualization</a> and <a href="http://www.rsa.com/products/consumer/datasheets/9984_PANIPV_DS_0109.pdf" target="_blank">Cloud Computing</a> have naturally come up given the EMC and VMware emphasis on these subjects.&nbsp; Some of the recent activity has come in wake of a spike in interest in the financial services vertical specifically for the SaaS version of RSA <a href="http://www.rsa.com/node.aspx?id=3018" target="_blank">Adaptive Authentication</a>, which continues to experience a growth in interest in the past few quarters.&nbsp; DLP and Voodoo Metricsblog@rsa.com (Katie Curtin-Mestre)http://www.rsa.com/blog/blog_entry.aspx?id=1443Mon, 13 Apr 2009 00:00:00 GMTblog@rsa.com (Katie Curtin-Mestre)http://www.rsa.com/blog/blog_entry.aspx?id=1443<p>About two weeks, I had the opportunity to deliver a keynote at the CSO Executive Seminar Series on DLP.&nbsp; After my &ldquo;15 minutes of fame&rdquo;, I had the opportunity to sit in on one of the DLP talks from one of the other vendors.&nbsp; The speaker shared a Ginormiacous (free drinks from me at RSA Conference for the first person to correctly identify this cultural reference) quantity of data that drove home the point that a lot of sensitive data is getting lost and that this is costing organizations lots of money.</p>Speaking of Security Podcast #143blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1441Tue, 07 Apr 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1441<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1441">Click to Download/Listen</a> (7:42)<br><br /> This week's Speaking of Security podcast features Part Two of a discussion on the latest online fraud trends.A Recipe for a Successful Software Security Assurance Initiativeblog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1442Tue, 07 Apr 2009 00:00:00 GMTblog@rsa.com (Eric Baize)http://www.rsa.com/blog/blog_entry.aspx?id=1442Having the responsibility for securing a portfolio of more than 100 products, I have dealt with thousands of engineers, product managers and other stakeholders across EMC and RSA to get them to adopt security development best practices.Security When Things Go 'Boom' - DR for Security Controlsblog@rsa.com (John McDonald )http://www.rsa.com/blog/blog_entry.aspx?id=1440Mon, 06 Apr 2009 00:00:00 GMTblog@rsa.com (John McDonald )http://www.rsa.com/blog/blog_entry.aspx?id=1440In the previous two installments of my blog we discussed some of the considerations when evaluating security in the context of disaster recovery, and drilled down a bit into the specific area of security as a disaster. Now let&rsquo;s look at another aspect of the relationship between security and disaster recovery (DR) - making sure your security controls are available when a disaster occurs.Should PCI Standards Be Scrapped?blog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1438Wed, 01 Apr 2009 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1438<p>The heightened focus on cyber security and cyber crime issues in Washington, D.C. continued today with a hearing in the House of Representatives Homeland Security Committee. &nbsp;Entitled &ldquo;<a href="http://homeland.house.gov/Hearings/index.asp?ID=185" target="_blank">Do the Payment Card Industry Data Standards Reduce Cybercrime</a>,&rdquo; the hearing was convened by the <a href="http://homeland.house.gov/about/subcommittees.asp?subcommittee=12" target="_blank">Subcommittee on Emerging Threats, Cyber Security, and Science and Technology</a>, which is chaired by U.S. Rep. Yvette Clarke (D-NY). &nbsp;</p>Speaking of Security Podcast #142blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1439Wed, 01 Apr 2009 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1439<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1439">Click to Download/Listen</a> (11:00) <br><br /> This week's Speaking of Security podcast features a discussion of the latest online fraud issues and trends. <br>Understanding the Crowd Part II: You Must Think Like a Thiefblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1436Thu, 26 Mar 2009 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1436<p>At the end of my <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1435" target="_blank">last blog</a> entitled <em>Understanding the Crowd: To Catch a Thief (Part I) </em>posted on&nbsp; March 23rd, I referred to a formula that <a href="http://techbuddha.wordpress.com/" target="_blank">Amrit Williams</a> and I have created for assessing the likelihood of a given method of security attack&rsquo;s launch over the Internet and the relative probability that an exploit will occur. </p>Understanding the Crowd: To Catch a Thief (Part I)blog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1435Mon, 23 Mar 2009 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1435<p>Last week, <a href="http://techbuddha.wordpress.com/" target="_blank">Amrit Williams</a> and I presented the results of our research paper at <a href="http://www.sourceconference.com/" target="_blank">SOURCE Conference</a> that we&rsquo;ve been working on and thinking about for over a decade now.&nbsp; It started when I did Malware research at a previous company, and watching the ebb and flow of malware (and the related FUD). This reminded me of watching the tide rise on a shore, or perhaps a slightly more intelligent phenomenon like the movement of a flock of birds or a school of fish.&nbsp; We&rsquo;ve all seen flocks of birds, and the sudden changes come about that cause a curtain-like ripple throughout the flock.&nbsp; I couldn&rsquo;t escape the feeling that there was a pattern here among the samples that could be both modeled and predicted.</p>What Cisco's UCS means to RSAblog@rsa.com (Paul Stamp)http://www.rsa.com/blog/blog_entry.aspx?id=1433Tue, 17 Mar 2009 00:00:00 GMTblog@rsa.com (Paul Stamp)http://www.rsa.com/blog/blog_entry.aspx?id=1433<p>So Cisco launched their <a href="http://www.marketwire.com/press-release/Cisco-NASDAQ-CSCO-961593.html" target="_blank">Unified Computing System</a> this morning. This has some big implications for EMC, and <a href="http://chucksblog.emc.com/chucks_blog/2009/03/brave-new-thinking-from-cisco.html" target="_blank">Chuck Hollis</a> has gone into great detail on this. In a nutshell, Unified Computing System looks to create a single, virtualized&nbsp; architecture for the data center, managed from top to bottom by a single set of tools. Sounds cool, eh? But what does that mean for us lowly security folks?</p>Speaking of Security Podcast #141blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1434Tue, 17 Mar 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1434<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1434">Click to Download/Listen</a> (9:50)<br><br /> This week's Speaking of Security podcast features an update from Washington, DC on cyber security issues and pending legislation. <br />PCI Compliance: SIEMblog@rsa.com (Brad Davenport)http://www.rsa.com/blog/blog_entry.aspx?id=1431Mon, 09 Mar 2009 00:00:00 GMTblog@rsa.com (Brad Davenport)http://www.rsa.com/blog/blog_entry.aspx?id=1431<p>During a recent customer meeting, I was asked to highlight key capabilities necessary to satisfy <a href="https://www.pcisecuritystandards.org/education/docs/Prioritized_Approach_PCI_DSS_version1_2.xls" title="https://www.pcisecuritystandards.org/education/docs/Prioritized_Approach_PCI_DSS_version1_2.xls" target="_blank">PCI&rsquo;s</a> Security Information and Event Management (SEIM) requirements.&nbsp; I explained to the customer that if their goal was merely to meet PCI Requirement 10, the solution used here &ndash; either purchased, outsourced or home grown &ndash; must posses a modest set of baseline capabilities.&nbsp; Some of these include enabling audit trails, reconstructing simple events, and securely storing audit trails for at least a year. </p>Speaking of Security Podcast #140blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1430Mon, 09 Mar 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1430<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1430">Click to Download/Listen</a> (7:23)<br><br> The week's Speaking of Security podcast discusses the release of RSA enVision 4.0, the premier platform for Secuity Information and Event Management/Log Management.enVision 4.0 goes liveblog@rsa.com (Paul Stamp)http://www.rsa.com/blog/blog_entry.aspx?id=1432Fri, 06 Mar 2009 00:00:00 GMTblog@rsa.com (Paul Stamp)http://www.rsa.com/blog/blog_entry.aspx?id=1432<p>We&rsquo;re pretty pumped here at RSA, since today we&rsquo;re releasing our latest and greatest version of RSA enVision.</p> <p>RSA enVision 4.0 has some really cool new features, and should be a boon for anyone trying to get a better handle on using log data to deal with any bad stuff that may be going on in their IT environment.</p>PCI Compliance: A Prioritized Approachblog@rsa.com (Brad Davenport)http://www.rsa.com/blog/blog_entry.aspx?id=1429Wed, 04 Mar 2009 00:00:00 GMTblog@rsa.com (Brad Davenport)http://www.rsa.com/blog/blog_entry.aspx?id=1429<p>On March 3, 2009 the PCI Security Standards Council <a href="https://www.pcisecuritystandards.org/news_events/docs/pr_090302PrioritizedApproach.pdf" target="_blank">announced</a> a new resource to promote adoption of the PCI DSS.&nbsp; According to the Council, the &ldquo;<a href="https://www.pcisecuritystandards.org/education/docs/Prioritized_Approach_PCI_DSS_1_2.pdf" target="_blank">Prioritized Approach</a>&rdquo; provides six security milestones that will help merchants and other organizations incrementally protect against the highest risk factors and escalating threats while on the road to PCI DSS compliance.&nbsp; As I <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1363" target="_blank">previously mentioned</a>, this announcement has been anticipated since the 2008 Council Meetings. </p>Using a SIEM to identify the *really* important stuffblog@rsa.com (Paul Stamp)http://www.rsa.com/blog/blog_entry.aspx?id=1428Mon, 02 Mar 2009 00:00:00 GMTblog@rsa.com (Paul Stamp)http://www.rsa.com/blog/blog_entry.aspx?id=1428<p>Many people buy a SIEM system looking for a tool that will spot things they might not on their own, or things that a single data source might not. Here&rsquo;s an example of correlation that will work - given the right input, an analytic engine and some expert knowledge.</p>Speaking of Security Podcast #139blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1427Mon, 23 Feb 2009 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1427<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1427">Click to Download/Listen</a> (7:29) <br><br /> RSA Conference '09 is fast approaching. This week's Speaking of Security podcast provides an update on what to expect at this year's event. <br>Fraudsters Exploit eCommerce Website to Check if Stolen Credit Cards are Validblog@rsa.com (RSA FraudAction Research Lab)http://www.rsa.com/blog/blog_entry.aspx?id=1426Mon, 23 Feb 2009 00:00:00 GMTblog@rsa.com (RSA FraudAction Research Lab)http://www.rsa.com/blog/blog_entry.aspx?id=1426<p>The RSA FraudAction Research Lab has recently traced a new tool designed by criminals that validates compromised payment cards (e.g. credit cards) that are illegally obtained through the underground fraud supply chain. Fraudsters usually test the viability of illegally obtained payment cards before they are used, and to this end, they use a variety of &quot;card checkers&quot; &ndash; which are fraudster services or tools that enable them to check the accuracy of compromised payment card data.</p>Speaking of Security Podcast #138blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1425Tue, 10 Feb 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1425<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1425">Click to Download/Listen</a> (8:37) <br><br /> This week's Speaking of Security podcast features a discussion with Roland Cloutier, VP and CSO of EMC on the release of the new Security for Business Innovation Council report examing the information security challenges created by the current economic crisis. <br>PCI Compliance: The end game or just a starting point?blog@rsa.com (Brad Davenport)http://www.rsa.com/blog/blog_entry.aspx?id=1424Mon, 09 Feb 2009 00:00:00 GMTblog@rsa.com (Brad Davenport)http://www.rsa.com/blog/blog_entry.aspx?id=1424As I am sure many of you have heard, <a href="http://www.heartlandpaymentsystems.com/" target="_blank">Heartland Payment Systems </a>recently disclosed that it suffered a credit and debit card data breach in 2008.&nbsp; At this point, little is known beyond the &nbsp;<a href="http://www.snl.com/irweblinkx/file.aspx?IID=4094417&FID=7231254" target="_blank">announcement</a> that &ldquo;after being alerted by Visa&reg; and MasterCard&reg; of suspicious activity surrounding processed card transactions, Heartland enlisted the help of several forensic auditors to conduct a thorough investigation into the matter...There's No Business Like Snow Businessblog@rsa.com (Andrew Moloney)http://www.rsa.com/blog/blog_entry.aspx?id=1423Thu, 05 Feb 2009 00:00:00 GMTblog@rsa.com (Andrew Moloney)http://www.rsa.com/blog/blog_entry.aspx?id=1423<p>For those of you who live in colder climes you must have had a little chuckle to yourselves watching us over here in the UK trying to deal with a few inches of snow &nbsp;recently! The transport network pretty much ground to a halt, the Federation of Small Businesses estimated that 20% of the UK's working population, or 6.4 million people, around the country would not make it to work. </p>Speaking of Security Podcast #137blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1422Tue, 03 Feb 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1422<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1422">Click to Download/Listen</a> (8:45)<br><br />This week RSA takes a deeper look into the RSA/Microsoft partnership and explores how the value of building security into business applications can create flexible, consistent and adaptable information security for today's organizations.<br>Skip Hindsight, Prepare Ahead of Timeblog@rsa.com (Charlotte Breen)http://www.rsa.com/blog/blog_entry.aspx?id=1421Fri, 30 Jan 2009 00:00:00 GMTblog@rsa.com (Charlotte Breen)http://www.rsa.com/blog/blog_entry.aspx?id=1421<p>When dealing with Data Loss Prevention (DLP) issues, much has been made of the very real importance of true positives and false positives. As important as these are, less quantifiable is the status of false negatives, or those elements that should have been caught by software, but for some reason or another are not. This false negative element exists in all fields of knowledge work: it&rsquo;s the element &ldquo;not considered.&rdquo; Or, to paraphrase a former Secretary of Defense, it&rsquo;s the &ldquo;we don&rsquo;t know what we don&rsquo;t know.&rdquo;</p>Why content is king when it comes to SIEMblog@rsa.com (Paul Stamp)http://www.rsa.com/blog/blog_entry.aspx?id=1420Wed, 28 Jan 2009 00:00:00 GMTblog@rsa.com (Paul Stamp)http://www.rsa.com/blog/blog_entry.aspx?id=1420<p>There are two big parts to a SIEM or log management system. Both are really important - but most people choosing a SIEM have a tendency to look carefully at one while giving the other scant attention.</p>Speaking of Security Podcast #136blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1419Tue, 27 Jan 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1419<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1419">Click to Download/Listen</a> (9:38)<br><br />Ari Juels from RSA Labs has written a new suspense novel that presents a collision between ideas in the world of cryptology and the world of ancient Greece. Hear all about it on this week's Speaking of Security podcast.<br />Speaking of Security Podcast #135blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1418Mon, 19 Jan 2009 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1418<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1418">Click to Download/Listen</a> (10:08)<br><br />This week's Speaking of Security podcast features a discussion on data protection and security event management issues with a principal from Deloitte & Touche, one of RSA's key alliance partners.The three big buckets of compliance, and why SIEM is important to all of themblog@rsa.com (Paul Stamp)http://www.rsa.com/blog/blog_entry.aspx?id=1417Mon, 12 Jan 2009 00:00:00 GMTblog@rsa.com (Paul Stamp)http://www.rsa.com/blog/blog_entry.aspx?id=1417<p>Too often we vendors go to clients and talk about compliance, and then throw up a slide showing an alphabet soup of regulations and standards, with no context about what they mean or how their product can help. Not only is it confusing, it shows a lack of understanding to customers, who are generally well educated about what these regulations and standards mean. I know this is basic stuff, but it's useful to recap once in a while.</p>Online Fraudsters Prey Upon the Media and Public Interest in Current Events to Launch "Cease-Fire Trojan Attack" blog@rsa.com (RSA FraudAction Research Lab )http://www.rsa.com/blog/blog_entry.aspx?id=1416Thu, 08 Jan 2009 00:00:00 GMTblog@rsa.com (RSA FraudAction Research Lab )http://www.rsa.com/blog/blog_entry.aspx?id=1416<p>Yesterday morning, the RSA FraudAction Research Lab discovered a social engineering scam designed to lure people, via an email spam attack, to a fake news website designed to look like CNN.com. This &ldquo;Cease-Fire Trojan Attack&rdquo; attempts to bait readers leveraging recent news and &ldquo;graphic and striking&rdquo; images regarding the Israel-Hamas conflict in Gaza. <strong>Today, RSA is initiating the shutdown process to take down this attack. </strong></p>PCI Compliance: Customer's frequently asked questionsblog@rsa.com (Brad Davenport )http://www.rsa.com/blog/blog_entry.aspx?id=1414Wed, 07 Jan 2009 00:00:00 GMTblog@rsa.com (Brad Davenport )http://www.rsa.com/blog/blog_entry.aspx?id=1414<p>Over the past few weeks multiple merchants, banks and service providers have asked me the following three questions.&nbsp; Since there seems to be some confusion, I figured I&rsquo;d post a short FAQ...</p>Speaking of Security Podcast #134blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1415Wed, 07 Jan 2009 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1415<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1415">Click to Download/Listen</a> (10:26)<br><br /> The first Speaking of Security podcast of 2009 features Jon Oltsik from the Enterprise Strategy Group. Jon shares his perspective on trends in information security for the new year.New Phishing Kits Hit the Market: Trojan HTML Injections Now for Saleblog@rsa.com (RSA FraudAction Research Lab)http://www.rsa.com/blog/blog_entry.aspx?id=1410Tue, 06 Jan 2009 00:00:00 GMTblog@rsa.com (RSA FraudAction Research Lab)http://www.rsa.com/blog/blog_entry.aspx?id=1410<p>The economic lifecycle of the underground fraud community functions very similarly to the world of legitimate business. Online fraudsters have supply chains, third-party outsourcers, vendors, and online forums where people with skills and people with opportunities to commit fraud can find each other. The underground fraud supply chain is becoming more technically and operationally sophisticated, and we&rsquo;ve coined this &ldquo;Fraud-as-a-Service&rdquo; or &ldquo;FaaS&rdquo;. FaaS consists of services for advanced hosting, Trojan infection kits and cashout services &ndash; all for sale within the fraudster underground. </p>Taking the Pain out of Secret Writingblog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1413Mon, 05 Jan 2009 00:00:00 GMTblog@rsa.com (John McDonald)http://www.rsa.com/blog/blog_entry.aspx?id=1413Encryption is one security control that's showing up a lot more frequently these days; in many cases the choice to implement encryption isn't optional. PCI requires it, state PII protection laws are starting to demand it, and many other government and industry regulations imply it as a requirement. The other thing that's changing the way we look at encryption is that it's becoming ubiquitous - many of the hardware and software products we buy that touch information now have encryption built in. All of these factors are combining to make encryption one of the fastest growing areas of security. So what's the downside? Five Steps Congress May Take on Information Security in 2009blog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1412Mon, 05 Jan 2009 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1412<p>Well, it&rsquo;s that time of year again: lots of prognosticators making predictions for 2009 as they take a look at 2008 in the rearview mirror and try to figure out what&rsquo;s in front of us in the New Year. So, I&rsquo;ll join the legions of IT experts guessing what may be in store in the coming months as we raise our glasses to 08 and toast 09 with anticipation, hope and given the current economic climate, with consternation as well. Since I am a creature of Washington and have the opportunity to work with the U.S. Congress, I&rsquo;ll focus on what steps we might expect our national legislature to take in 2009 as it relates to information security and privacy issues.</p>A Real New Year's Hashblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1411Thu, 01 Jan 2009 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1411<p>The New Year has just arrived and I'm reminded how, globally, we are all connected in ways that would have been impossible 20 years ago: it's almost hackneyed to say it again, but thanks to an amazing combination of infrastructure and technology, we can live, work and play from Mumbai to London and from Tokyo to New York City as one world in real-time. Of course, a lot of this is dependent on some of the basic building blocks we use being sound, and in the last few days one of these building blocks has come under attack: MD5 is on its last legs as a tool in the cryptographic toolbox.</p>Locard's Exchange Principle, Applied to eCrimeblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1409Mon, 22 Dec 2008 00:00:00 GMTblog@rsa.com (Sam Curry)http://www.rsa.com/blog/blog_entry.aspx?id=1409<p>I love crime shows: Law &amp; Order SVU, Inspector Morse, CSI:, the occasional episode of Monk, and others. (OK &ndash; I&rsquo;ll admit I like some of these for the drama as well!).&nbsp; I also love a really good &ldquo;Who Dunnit?&rdquo; novel &ndash; usually with a good twist or two, of which <a href="http://en.wikipedia.org/wiki/Jeffrey_Deaver">Jeffrey Deaver</a> is quite the modern master.&nbsp; </p>Securing Your Enterprise in an Insecure Economyblog@rsa.com (Sarah Hamilton)http://www.rsa.com/blog/blog_entry.aspx?id=1408Mon, 22 Dec 2008 00:00:00 GMTblog@rsa.com (Sarah Hamilton)http://www.rsa.com/blog/blog_entry.aspx?id=1408<p>As companies everywhere seek to reduce capital and operational expenses in a troubled economy, they ask themselves, <em>How can we spend as little as necessary today to minimize additional costs throughout the next year?</em> IT and security professionals relate to this as their goal is to never have to withdraw from the <em>Contingency Reserves </em>(or similar) budget item. <em>Contingency Reserves</em> is finance-speak for the allocation you must set aside to accommodate potential financial ramifications resulting from IT security breaches. These breaches occur when sensitive information leaks into the wrong hands, most frequently as a result of inadvertent internal error. </p>PCI DSS: How to Do More With Lessblog@rsa.com (Brad Davenport)http://www.rsa.com/blog/blog_entry.aspx?id=1407Thu, 18 Dec 2008 00:00:00 GMTblog@rsa.com (Brad Davenport)http://www.rsa.com/blog/blog_entry.aspx?id=1407<p>My colleague, <a href="http://www.rsa.com/blog/blog.aspx?author=stamp" target="_blank">Paul Stamp</a>, <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1405" target="_blank">recently shared</a> his thoughts on the global economic downturn and the fact that it is making many organizations concerned that their IT security budgets will be cut.&nbsp; Echoing Paul&rsquo;s observations, almost all the customers I&rsquo;ve spoken with have not seen their PCI budgets cut, but that is not to say they aren&rsquo;t concerned.&nbsp; Many have expressed a desire to stretch their dollars further, asking the question, &ldquo;When it comes to PCI and my other security and compliance initiatives, how can I do more with less?&rdquo; </p>Speaking of Security Podcast #133blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1406Wed, 17 Dec 2008 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1406<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1406">Click to Download/Listen</a> (15:01)<br><br />This week's Speaking of Security podcast features part two of an interesting discussion with Uri Rivner, Head of New Technologies for RSA. Uri talks about what organizations can do to combat fraudsters. Through a layered security approach, organizations can stay one step ahead to mitigate the risk of fraudsters targeting their business.<br />Budgets seem to be holding up, but more justification neededblog@rsa.com (Paul Stamp)http://www.rsa.com/blog/blog_entry.aspx?id=1405Thu, 11 Dec 2008 00:00:00 GMTblog@rsa.com (Paul Stamp)http://www.rsa.com/blog/blog_entry.aspx?id=1405Also at the IANS conference, we talked extensively about enterprises' budgets. Apart from a few notable exceptions, most agreed that budgets hadn't been significantly cut...yet. It stands to reason &ndash; nobody buys security because it&rsquo;s cool, or because they have extra cash in their pockets. On the other hand, few thought their budgets&rsquo; were immune to being cut in the near future either, though. Either way, just about everyone was finding that they needed extra justification for their security purchases.Asking the Right Questions When Implementing a Data Loss Prevention Policyblog@rsa.com (Meena Raju)http://www.rsa.com/blog/blog_entry.aspx?id=1403Wed, 10 Dec 2008 00:00:00 GMTblog@rsa.com (Meena Raju)http://www.rsa.com/blog/blog_entry.aspx?id=1403Okay, raise your hand if you are scared of the word &ldquo;policy.&rdquo; Policy is sometimes an overused word that sounds simpler than the complex thing it actually is, and if not properly thought out, can be a headache to implement.&nbsp;RSA&rsquo;s Information Policy and Classification team spends a lot of time focusing on the accuracy of Data Loss Prevention (DLP) policies. This week, we&rsquo;re giving some hints for success and best practices that we&rsquo;ve learned by working with both early adopters and some of the world&rsquo;s largest companies.&nbsp;We know from experience that you can have the most accurate policy and it still may not be the<em> right</em> policy for your organization. Here&rsquo;s how to figure it out...Where did my vendor go?blog@rsa.com (Paul Stamp )http://www.rsa.com/blog/blog_entry.aspx?id=1402Tue, 09 Dec 2008 00:00:00 GMTblog@rsa.com (Paul Stamp )http://www.rsa.com/blog/blog_entry.aspx?id=1402 <p>I had the pleasure of attending the <A title="http://www.ianetsec.com/" href="http://www.ianetsec.com/" target="blank">Institute of Applied Network Security</A> (IANS) conference in San Francisco last week. For anyone not familiar with this organization, they&rsquo;re a peer to peer research organization where security practitioners come together to talk about the issues du jour. It&rsquo;s a real good way for us vendors to get a pulse on what people are worried about, and what they think about what we&rsquo;re doing to support them.</p>Speaking of Security Podcast #132blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1404Tue, 09 Dec 2008 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1404<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1404">Click to Download/Listen</a> (11:13)<br><br />This week's Speaking of Security podcast features a preview of the latest edition of Vantage, RSA's magazine on information security news and trends and the first segment of a two-part discussion on how the fraudster underground operates much the same as real-world businesses. Uri Rivner, Head of New Technologies at RSA is our guest.<br />Securing Cyberspace for the 44th Presidency - An Introduction to the Commissionblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1400Mon, 08 Dec 2008 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1400Later today the final report of the <A title="http://www.csis.org/tech/cyber/" href="http://www.csis.org/tech/cyber/" target="blank">CSIS Commission for the 44th Presidency</A> will be officially released on Capitol Hill in Washington, D.C. The co-chairs of the Commission are: U.S. Representatives Jim Langevin (Democrat, Rhode Island) and Michael McCaul (Republican, Texas), and senior industry executives Scott Charney of Microsoft and retired Air Force Lt. General Harry Raduege of Deloitte.The Dreaded "C" Wordblog@rsa.com (Katie Curtin-Mestre)http://www.rsa.com/blog/blog_entry.aspx?id=1399Thu, 04 Dec 2008 00:00:00 GMTblog@rsa.com (Katie Curtin-Mestre)http://www.rsa.com/blog/blog_entry.aspx?id=1399Let&rsquo;s face it.&nbsp; The &ldquo;C&rdquo; word, commoditization, is a word that those of us in the IT community both love and hate.&nbsp; We hate it when the &ldquo;C&rdquo; word is applied to the products that we offer, but at the same time we secretly hope that someone else&rsquo;s products will be commoditized so that customers will have more of their budget to spend on our wares.Speaking of Security Podcast #131blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1398Wed, 03 Dec 2008 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1398<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1398">Click to Download/Listen</a> (08:21)<br><br />Social engineering is the art of manipulating people into performing actions or divulging confidential information. This week's Speaking of Security podcast features a discussion on this topic with a leading expert on security and terrorism.<br />Make Sure to Cover Your SaaSblog@rsa.com (Will Redfield )http://www.rsa.com/blog/blog_entry.aspx?id=1397Tue, 02 Dec 2008 00:00:00 GMTblog@rsa.com (Will Redfield )http://www.rsa.com/blog/blog_entry.aspx?id=1397Software as a Service (<a href="http://en.wikipedia.org/wiki/Software_as_a_service">SaaS</a>) on-demand applications are single-instance multi-tenant applications which are centrally and professionally managed and delivered as a service over the internet. SaaS customers use the same application engine which is partitioned into separate customer access accounts.&nbsp; These accounts may be set-up differently but the core application engine is the same platform that every other customer has access to.Focussing on FUD - What a waste of an opportunity to realise efficiency gains!blog@rsa.com (Andrew Moloney)http://www.rsa.com/blog/blog_entry.aspx?id=1396Tue, 02 Dec 2008 00:00:00 GMTblog@rsa.com (Andrew Moloney)http://www.rsa.com/blog/blog_entry.aspx?id=1396I had the pleasure of presenting at the EMC EMEA Analysts meeting this week. Some people hate talking to gatherings like this, because unlike most audiences they tend to be much less reticent in providing contrary views to those which you are presenting &ndash; often right there in the middle of your pitch, having the potential (on a really bad day!) to really derail you from the point you wished to make and generally to put you on the back foot.What You Don't Know CAN Hurt You!blog@rsa.com (John McDonald )http://www.rsa.com/blog/blog_entry.aspx?id=1395Mon, 01 Dec 2008 00:00:00 GMTblog@rsa.com (John McDonald )http://www.rsa.com/blog/blog_entry.aspx?id=1395<p>Here's a quick quiz for all of you security professionals out there:</p> <p> </p> <p>1. What's a 'SAN'?<br> 2. What's a 'LUN' on a Fiberchannel SAN?<br> 3. What are the differences between iSCSI, NAS and Fiberchannel SANs?<br> 4. How does data de-duplication work?<br> 5. What are the different types of 'stores' supported by Microsoft Exchange?</p>Speaking of Security Podcast #130blog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1394Mon, 24 Nov 2008 00:00:00 GMTblog@rsa.com ()http://www.rsa.com/blog/blog_entry.aspx?id=1394<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1394">Click to Download/Listen</a> (08:53)<br><br />Now that the 2008 US Presidential and Congressional elections are behind us, what can we expect from the new Administration and the 111th Congress on Cyber Security? The Speaking of Security podcast has a report direct from Washington, DC.<br />Big Bank Does Well Financially&mdash;Really!blog@rsa.com (Satchit Dokras )http://www.rsa.com/blog/blog_entry.aspx?id=1393Fri, 21 Nov 2008 00:00:00 GMTblog@rsa.com (Satchit Dokras )http://www.rsa.com/blog/blog_entry.aspx?id=1393<p>What a refreshing conversation it was&mdash;a Global 100 bank&rsquo;s senior IT executive was gushing on how he was in the money. No, really! And even better, amidst today&rsquo;s financial fiascos, he had selected to tell me about how he was financially ahead by deploying some state-of-art security solutions.<br><br>Fraudsters Have Had a Rough Monthblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1392Tue, 18 Nov 2008 00:00:00 GMTblog@rsa.com (Uri Rivner)http://www.rsa.com/blog/blog_entry.aspx?id=1392<p>I attended RSA Conference Europe late last month, which &ndash; as always &ndash; is an amazing event. The theme of the Conference was focused on Alan Turing, who is often called the father of modern computer science. One particular perk at the venue was the public display of the <a href="http://www.rsaconference.com/2008/Europe/Agenda/Enigma_Machine_Display.aspx" target="_blank">Enigma machine</a> &ndash; believed by the German forces during WWII to be impenetrable. </p>PCI Compliance: Visa Announces Global Deadlinesblog@rsa.com (Brad Davenport)http://www.rsa.com/blog/blog_entry.aspx?id=1391Tue, 18 Nov 2008 00:00:00 GMTblog@rsa.com (Brad Davenport)http://www.rsa.com/blog/blog_entry.aspx?id=1391<p>In response to the <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1324">complex and global</a> threats faced by the cardholder ecosystem, <a href="http://www.visa.com/globalgateway/gg_selectcountry.html?retcountry=1">Visa Inc</a> recently announced <a href="http://corporate.visa.com/md/nr/press873.jsp">worldwide deadlines for PCI DSS Compliance</a>.&nbsp; &quot;Compliance with PCI DSS is vital to ensuring the integrity of the global payments system,&quot; said Eduardo Perez, head of global data security, Visa Inc.&nbsp; &quot;Aligning compliance programs across the Visa regions is the latest step in our commitment to safeguarding cardholder data.&quot; </p>Speaking of Security Podcast #129blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1389Mon, 17 Nov 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1389<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1389">Click to Download/Listen</a> (08:34)<br><br />This week's Speaking of Security podcast features an on-the-scene report from the Gartner Identity and Access Management Summit, one of the key shows on the security event calendar. The Summit was held last week in Orlando, Florida. <br />Events per Second &ndash; the difference between a target and an assuranceblog@rsa.com (Paul Stamp)http://www.rsa.com/blog/blog_entry.aspx?id=1390Mon, 17 Nov 2008 00:00:00 GMTblog@rsa.com (Paul Stamp)http://www.rsa.com/blog/blog_entry.aspx?id=1390<p>We&rsquo;ve been getting a good few questions recently about how many Events Per Second a SIEM product support. Well, that depends on a few factors:</p> <ul> <li><strong>The transport</strong> &ndash; processing Syslog events takes up a heck of a lot less processing power than collecting from a Windows box. Same with collecting data over an ODBC connection.</li> </ul>RSA&reg; BSAFE&reg; &mdash; Security A Billion Times Overblog@rsa.com (Satchit Dokras)http://www.rsa.com/blog/blog_entry.aspx?id=1388Sun, 16 Nov 2008 00:00:00 GMTblog@rsa.com (Satchit Dokras)http://www.rsa.com/blog/blog_entry.aspx?id=1388RSA has marked a McDonald&rsquo;s-like landmark, quietly&mdash; over one billion applications and devices are now embedded with RSA<strong> &reg; </strong> BSAFE<strong>&reg; </strong>security software. No numbers changed under ubiquitous golden arches to mark this monumental achievement, but it did get me thinking on how deep an impact RSA BSAFE has had in the broad industry sectors as well as at EMC in particular&hellip;What should we expect from the Obama Administration and the 111th Congress on Cyber Security?blog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1387Fri, 14 Nov 2008 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1387<p>Given the seriousness of the financial crisis, growing job losses and the continued meltdown of global stock markets, it&rsquo;s hard to imagine that the incoming Obama Administration or new U.S. Congress will be able to focus on much else during the first several months of 2009.&nbsp; When they do tackle other issues, healthcare reform, tax policy and energy policy are likely to emerge at the top along with national security priorities.&nbsp; Not to mention that many FY2009 spending bills still need to be approved by Congress and signed by the President as well, although that is expected to happen by March 2009 at the latest.</p> <p><em>So where does this leave cyber security issues?&nbsp;</em></p>Innovation In Security--Lessons from TelePresence and Cloudblog@rsa.com (Satchit Dokras)http://www.rsa.com/blog/blog_entry.aspx?id=1386Wed, 12 Nov 2008 00:00:00 GMTblog@rsa.com (Satchit Dokras)http://www.rsa.com/blog/blog_entry.aspx?id=1386<p>Innovation in Security is a theme that we at EMC and RSA strongly believe in&mdash; it was central to my <a href="http://www.ncanet.com/SatchitDokras.php">keynote</a> speech at the NCA Security and Technology Conference in Seattle on the 29th of October. Yet, as the day progressed, I could not help but think of how extensively we need to innovate in our security deployments, to enable vibrant new information exchange capabilities, and to sustain the rapid changes in our information-centric lifestyles.<br /> <br /> <strong>And are we being hit with Change!</strong><br /> Carlos Dominguez, the SVP at Cisco, spoke to <B>the profound impact of Web 2.0 and TelePresence [TP] technologies on our business and social lifestyles...</b>