<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xml:base="http://blog.solidcore.com/public/" version="2.0"><!--

MyST Blogsite® RSS Web Feed | Powered by MySmartChannels™ Weblog Application Server

MyST Blogsite and MySmartChannels are services of MyST Technology Partners, Inc.
For more information, including standard terms of service, see:
http://myst-technology.com and http://blogsite.com

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Customize this feed by adding any of the following URL parameters:

  description=none|summary|full (default=full)
  channelDescription=none|summary|full (default=value of 'description' parameter)
  itemDescription=none|summary|full (default=value of 'description' parameter)
  enhanced=true|false (default=false)
  limit=n (default=15)
  score=none|emoticon|simple|stars|text (default=text)
  smartPoints=true|false (default=true)
  sortKey=CreateTime|ModifyTime|Name|...any MyST-ML child element... (default=CreateTime)
  sortOrder=ascending|descending (default=descending)
--><channel>
     <title>PCI | Whitelisting | File Integrity Monitoring | Solidcore Blog</title><link>http://blog.solidcore.com/public/blog/183014</link><description>Recent News &amp; Stories from Solidcore</description><language>en-us</language><copyright>Copyright (C) 2009 Solidcore--All Rights Reserved -- This channel is part of the Solidcore Blog blogsite--Powered by MyST Blogsite®.</copyright><pubDate>Thu, 13 Sep 2007 23:45:19 -0400</pubDate><lastBuildDate>Fri, 15 May 2009 08:30:59 -0400</lastBuildDate><generator>MySmartChannels V3.0 (MyST Web Service Platform V6.00.0627)</generator><image><url>http://blog.solidcore.com/styles/blogsite/SolidCore/images/rss.jpg</url><height>31</height><width>88</width><link>http://blog.solidcore.com/public/blog/183014</link><title>PCI | Whitelisting | File Integrity Monitoring | Solidcore Blog</title><description>Solidcore: Change Management and Change Control Solutions</description></image>
       <category>IT Compliance</category><category>PCI compliance</category><category>IT management</category><category>IT infrastructure</category><category>IT change control</category><category>IT Data Center</category><category>IT Service</category><category>IT response time</category><category>Service availability</category>
       
       
      
    
     <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/WhatsNewSolidcoreBlog" type="application/rss+xml" /><item><title>McAfee to Acquire Solidcore</title><link>http://blog.solidcore.com/public/item/232225</link><description>Advance Endpoint Security and Risk Management&lt;p&gt;&lt;font face="verdana,arial,helvetica,sans-serif" size="2"&gt;Today, at McAfee's May 15th Investor Day meeting in New York City, McAfee announced they will acquire &lt;a href="http://www.solidcore.com/"&gt;Solidcore&lt;/a&gt;. Through this acquisition, McAfee will expand its reach into new markets, secure new platforms and strengthen its hold as the leader in the $6 billion endpoint security market.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="verdana,arial,helvetica,sans-serif" size="2"&gt;By continuing to innovate, McAfee is staying one step ahead of customer needs and competitive offerings. With McAfee and Solidcore joined, we will bring together best-in-class technologies and extend the current McAfee security portfolio beyond signature-based anti-malware. McAfee will combine dynamic whitelisting and application trust technology with leading McAfee antivirus, antispyware, host intrusion prevention, policy auditing and firewall technologies, to help customers more readily mitigate the risks associated with vulnerable or malicious applications downloaded by employees.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="verdana,arial,helvetica,sans-serif" size="2"&gt;For more information, please visit the &lt;a href="http://www.mcafee.com/us/about/corporate/mcafee_Solidcore.html" target="_blank" title="McAfee to Acquire Solidcore"&gt;McAfee acquisition web page&lt;/a&gt;.&lt;br /&gt;&lt;/font&gt; &lt;/p&gt;</description><guid isPermaLink="true">http://blog.solidcore.com/public/item/232225</guid><pubDate>Fri, 15 May 2009 08:30:59 -0400</pubDate>
        <category>acquire</category><category>antivirus</category><category>mcafee</category><category>solidcore</category><category>whitelisting</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Going to the Doctor may expose more than you think</title><link>http://blog.solidcore.com/public/item/231799</link><description>Cryptoviral Extortion and other breaches continue to hit healthcare&lt;div align="left"&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;font face="verdana,arial,helvetica,sans-serif"&gt;Going to the doctor may expose more than you think with recent news about breach notifications from &lt;a title="UC Berkeley data breach announcement" target="_blank" href="http://datatheft.berkeley.edu/"&gt;University Health Services at Berkeley&lt;/a&gt; and the breach with extortion threat at &lt;a title="Breach News on Virginia Data records" target="_blank" href="http://www.informationweek.com/news/security/attacks/showArticle.jhtml?articleID=217201397&amp;amp;subSection=Cybercrime"&gt;Virginia Dept. of Health Professions&lt;/a&gt;&lt;/font&gt;&lt;/font&gt;. Not only are health records at stake which often times requires a Social Security number for identification but also CHD (Card Holder Data) facilitating the co-pay and billing of services. Another example where electronic data is no longer just the bits and bytes or 1's and 0's we were taught about in school but seemingly the lifeblood for cybercriminals. They will do almost anything to get their fix so the prescription is to be prepared and vigilant with real-time file integrity monitoring, dynamic whitelisting and get inoculated against malware.&amp;nbsp; &lt;br /&gt;&lt;/p&gt; &lt;/div&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://datatheft.berkeley.edu/" target=%quot;_blank%quot;&gt;Data Theft announcement at UC Berkeley Health Services&lt;/a&gt;&lt;br/&gt;Data Theft announcement at UC Berkeley Health Services&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.informationweek.com/news/security/attacks/showArticle.jhtml?articleID=217201397&amp;subSection=Cybercrime" target=%quot;_blank%quot;&gt;Virginia Dept. of Health Professions data leak&lt;/a&gt;&lt;br/&gt;Virginia Dept. of Health Professions cryptoviral extoration&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.solidcore.com/public/item/231799</guid><pubDate>Fri, 08 May 2009 14:33:10 -0400</pubDate>
        <category>antivirus</category><category>breach</category><category>healthcare</category><category>HIPPA</category><category>malware protection</category><category>PCI</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Unparalled Endpoint Protection Claim is Unrealistic</title><link>http://blog.solidcore.com/public/item/231632</link><description>One whitelisting company may have gone overboard in oversell..&lt;p&gt;&lt;font size="2"&gt;&lt;font face="verdana,arial,helvetica,sans-serif"&gt;Let's face facts it is a competitive market out there and as times get rough there are those who aim to make noise in the market with oversell. Whitelisting as a general technology is an alternative and positive approach to providing protection to endpoints and devices. But as the common saying among Security Professionals go - the only really secure system is one that is turned off. This claim would be true only if the unparalled protection was compared to no attempt at endpoint protection at all or doing nothing. &lt;/font&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;font face="verdana,arial,helvetica,sans-serif"&gt;Another false claim is that whitelisting alone provides some sort of system lock-down. This would be like saying having a closed campus for high school is the same experience as a correctional facility.&amp;nbsp; It may have seemed like it for me when I was in high school but as any resourceful teenage can prove it's not hard to be creative and find ways to come and go on campus without detection. &lt;/font&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;font face="verdana,arial,helvetica,sans-serif"&gt;Full endpoint security or lock-down is more than just whitelisting. SC Magazine recently reviewed endpoint security solutions in a &lt;a href="Endpoint%20Security%20Group%20Test" target="_blank" title="http://www.scmagazineus.com/Group-Test-Endpoint-security/GroupTest/170/"&gt;group test&lt;/a&gt;. The test looked at the following features&lt;/font&gt;&lt;/font&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;System Security: antivirus/spyware, firewall capabilities and encryption &lt;br /&gt;&lt;/li&gt; &lt;/ul&gt; &lt;ul&gt; &lt;li&gt;Port Management: blocking the ability to add devices or read\write data to and from USB/CD/DVD/wireless devices&amp;nbsp;&lt;/li&gt; &lt;li&gt;Host Intrusion Protection: blocking registry changes, privilege escalation, copy/paste features and kernel event management&lt;br /&gt;&lt;/li&gt; &lt;/ul&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;font face="verdana,arial,helvetica,sans-serif"&gt;Solidcore provides both application and configuration whitelisting but our technology also has the ability to actually lock-down systems providing Runtime Control. Host intrusion protection and read/write protection of critical data on the systems does not come with standard whitelisting solutions. Port management is considered a key feature to endpoint security to minimize the unauthorized data access, installation or tampering of pre-set communications on the system. Again application whitelisting alone will stop any new code but won't provide data protection.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;Even though we did not participate in the endpoint protection test we have gone through independent testing with &lt;a href="http://nsslabs.com/" target="_blank" title="NSS Labs website"&gt;NSS Labs&lt;/a&gt; verifying our claims on being able to provide 100% system integrity. &amp;nbsp; &lt;br /&gt;&lt;/p&gt; &lt;p&gt; &lt;/p&gt; &lt;p&gt;&lt;font size="2"&gt;&lt;font face="verdana,arial,helvetica,sans-serif"&gt;&lt;br /&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.scmagazineus.com/Group-Test-Endpoint-security/GroupTest/170/" target=%quot;_blank%quot;&gt;Endpoint Security Testing&lt;/a&gt;&lt;br/&gt;SC Magazine Endpoint Security Group Test&lt;/li&gt;&lt;li&gt;&lt;a href="http://nsslabs.com/" target=%quot;_blank%quot;&gt;NSS Labs&lt;/a&gt;&lt;br/&gt;NSS Labs&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.solidcore.com/public/item/231632</guid><pubDate>Tue, 05 May 2009 19:57:26 -0400</pubDate>
        
        
        
        
        
       
        
        
        
        
        
       </item>
    </channel></rss>
