<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
<title>CareersInfoSecurity.co.uk  RSS Syndication</title>
<link>http://www.careersinfosecurity.co.uk/rssFeeds.php?type=main</link>
<description>CareersInfoSecurity.co.uk RSS News Feeds on careers information security news, regulations, blogs and education</description>
<pubDate>Thu, 31 May 2012 13:12:48 -0500</pubDate>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/careersinfosecurity/uk" /><feedburner:info uri="careersinfosecurity/uk" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
			<title>Breach Info Sharing Tool Enhanced</title>
			<link>http://www.careersinfosecurity.co.uk/breach-info-sharing-tool-enhanced-a-4805</link>
			<guid>http://www.careersinfosecurity.co.uk/breach-info-sharing-tool-enhanced-a-4805</guid>
			<description>&lt;img src="http://docs.careersinfosecurity.com/files/images_articles/4805_intid_1412_175x175_1_.jpg" align=right hspace=4&gt;&lt;b&gt;Consortium Offers Free Framework for Vulnerability Reporting&lt;/b&gt;&lt;br&gt;The Industry Consortium for Advancement of Security on the Internet has introduced an enhanced version of its free security vulnerability reporting framework designed to ease the sharing of breach information.</description>
			</item>
			<item>
			<title>Tips for Contracting Cloud Services</title>
			<link>http://www.careersinfosecurity.co.uk/tips-for-contracting-cloud-services-a-4797</link>
			<guid>http://www.careersinfosecurity.co.uk/tips-for-contracting-cloud-services-a-4797</guid>
			<description>&lt;img src="http://docs.careersinfosecurity.com/files/images_articles/4797_gilbert_francoise_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;What Organizations Need to Consider Choosing a Vendor&lt;/b&gt;&lt;br&gt;Cloud services contracts often provide little to no wiggle room. What steps do organizations need to take before signing any contract? IT security lawyer Françoise Gilbert offers some key strategies.</description>
			</item>
			<item>
			<title>Responding to Insider Fraud</title>
			<link>http://www.careersinfosecurity.co.uk/responding-to-insider-fraud-a-4782</link>
			<guid>http://www.careersinfosecurity.co.uk/responding-to-insider-fraud-a-4782</guid>
			<description>&lt;img src="http://docs.careersinfosecurity.com/files/images_articles/4782_ponemon_larry_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Ponemon Study Sheds New Light on Internal Risks&lt;/b&gt;&lt;br&gt;"You need to educate people, and you need to have the right control procedures in place to ensure that people are aware of insider fraud," says Larry Ponemon, offering tips to reduce insider risks.
&lt;p&gt;
In an interview about the insider threat, Ponemon discusses:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Key findings from this new research;&lt;/li&gt;
&lt;li&gt;What needs to be communicated to C-level executives;&lt;/li&gt;
&lt;li&gt;Tools to detect and prevent inside attacks.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;</description>
			</item>
			<item>
			<title>Breaking Down a Hacktivist Attack</title>
			<link>http://www.careersinfosecurity.co.uk/breaking-down-hacktivist-attack-a-4757</link>
			<guid>http://www.careersinfosecurity.co.uk/breaking-down-hacktivist-attack-a-4757</guid>
			<description>&lt;img src="http://docs.careersinfosecurity.com/files/images_articles/4757_rachwald_rob_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Learn How a DDoS Assault Went Down, and Was Prevented&lt;/b&gt;&lt;br&gt;Security firm Imperva had the opportunity to watch a hacktivist attack play out. Learn what the three phases of the attack were and how it was stopped.</description>
			</item>
			<item>
			<title>2012 Cloud Security Agenda: Expert Insights on Security and Privacy in the Cloud</title>
			<link>http://www.careersinfosecurity.co.uk/webinars/2012-cloud-security-agenda-expert-insights-on-security-privacy-in-cloud-w-276</link>
			<guid>http://www.careersinfosecurity.co.uk/webinars/2012-cloud-security-agenda-expert-insights-on-security-privacy-in-cloud-w-276</guid>
			<description>What are organizations' top cloud security concerns, and how are security leaders addressing these concerns through policy, technology and improved vendor management?
&lt;p&gt;&lt;p&gt;
This is the key question posed by the 2012 Cloud Security Survey.
&lt;p&gt;
No longer just an emerging technology practice, cloud computing today is embraced globally as a means of gaining efficient access to critical applications, processes and storage. It's now common for organizations to rely on cloud service providers for functions and business applications such as customer relationship management, messaging or storage via a public, private or hybrid cloud. Further, industry-specific cloud-based applications such as electronic health records or mobile banking and payment applications are emerging at an unprecedented pace.
&lt;p&gt;
But these engagements come with questions about risks:
&lt;ul&gt;
&lt;li&gt;What are your cloud service provider's security and privacy measures, and have they been audited?&lt;/li&gt;
&lt;li&gt;Where geographically is cloud data being stored, and how do operational practices comply with government, industry and organizational privacy regulations?&lt;/li&gt;
&lt;li&gt;How is a multi-tenant cloud environment managed, and in the event of system compromise - what will be the incident response escalation process?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
Yes, cloud computing is about efficiencies and new technologies, but it's also about security, privacy and an organization's reputation.
&lt;p&gt;
The 2012 Cloud Security Survey was crafted with assistance from leading experts in cloud computing, security and privacy, with a mission to:
&lt;ul&gt;
&lt;li&gt;Chart the latest cloud trends, including types of cloud implementations most common by industry and region;&lt;/li&gt;
&lt;li&gt;Gauge organizations' top cloud security concerns, from vendor security to data governance and breach preparedness;&lt;/li&gt;
&lt;li&gt;Predict the top areas of investment for organizations most concerned about cloud security.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;
This webinar will draw upon survey results and expert insight from a special roundtable panel to discuss:
&lt;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Top Security Concerns&lt;/b&gt; - Are organizations more concerned about where their data is stored, or whether a malicious insider might be a threat to it?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Success Factors&lt;/b&gt; - On a scale with cost savings and availability of services, how does security now rank among elements critical to a successful cloud computing implementation?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Protective Measures&lt;/b&gt; - What are some of the practices organizations are employing, from instituting more stringent contracts to enforcing third-party audits and even participating in mock security exercises with cloud service providers?&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>2012 Faces of Fraud Survey: Complying with the FFIEC Guidance</title>
			<link>http://www.careersinfosecurity.co.uk/webinars/2012-faces-fraud-survey-complying-ffiec-guidance-w-270</link>
			<guid>http://www.careersinfosecurity.co.uk/webinars/2012-faces-fraud-survey-complying-ffiec-guidance-w-270</guid>
			<description>A follow-up to ISMG's 2011 Faces of Fraud Survey, this webinar looks not only at the latest fraud trends and how institutions are fighting back, but also at their progress in putting together layered security controls in conformance with the FFIEC Authentication Guidance.
&lt;p&gt;
&lt;p&gt;
Given the persistence of fraud threats and the demands of the FFIEC Authentication Guidance, the 2012 Faces of Fraud Survey is crafted with assistance from leading experts in fraud detection and prevention, with a mission to: 
&lt;ul&gt;
&lt;li&gt;Chart the latest fraud trends, including account takeover, skimming and payment card breaches;&lt;/li&gt;
&lt;li&gt;Gauge institutions' preparedness to conform to the FFIEC Authentication Guidance, including where they are prioritizing their efforts;&lt;/li&gt;
&lt;li&gt;Predict the top areas of focus for 2012, from real-time fraud monitoring tools to new layered security controls.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>Using the NIST HIPAA Security Rule Toolkit for Risk Assessments</title>
			<link>http://www.careersinfosecurity.co.uk/webinars/using-nist-hipaa-security-rule-toolkit-for-risk-assessments-w-262</link>
			<guid>http://www.careersinfosecurity.co.uk/webinars/using-nist-hipaa-security-rule-toolkit-for-risk-assessments-w-262</guid>
			<description>The National Institute of Standards and Technology, a non-regulatory agency of the Department of Commerce, is responsible for providing standards and technology to protect against threats to the confidentiality, integrity and availability of information and information systems. NIST's Computer Security Division is positioned to ensure that new technologies are selected, deployed and operated in a manner that reduces risk.
&lt;p&gt;&lt;p&gt;
The Health Insurance Portability and Accountability Act Security Rule establishes national standards to protect individuals' electronic personal health information that is created, received, used or maintained by a covered entity. Covered entities include hospitals, physician groups, health plans and claims clearinghouses. Soon, the rule also will apply to business associates - business partners that have access to sensitive patient information. The Security Rule requires appropriate administrative, physical and technical safeguards to ensure the confidentiality, integrity and security of electronic protected health information. 
&lt;p&gt;
To help organizations better understand the requirements of the HIPAA Security Rule, implement those requirements, and assess those implementations in their operational environments, NIST has developed a HIPAA Security Rule Self Assessment Toolkit.
&lt;p&gt;
In this session, Kevin Stine, manager of the Security Outreach and Integration Group within NIST's Computer Security Division, will:
&lt;ul&gt;
&lt;li&gt;Introduce participants to NIST and its role in information security;&lt;/li&gt;
&lt;li&gt;Provide a detailed overview of the toolkit application;&lt;/li&gt;
&lt;li&gt;Discuss how the toolkit can be used to support an organization's risk management process, help improve security safeguards and aid security assessment and compliance activities; and &lt;/li&gt;
&lt;li&gt;Identify additional NIST information security resources, such as risk assessment and security control guidelines, which can help organizations to manage risk and safeguard health information.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>Risk Assessment Framework for Online Channel: Learn from an Expert</title>
			<link>http://www.careersinfosecurity.co.uk/webinars/risk-assessment-framework-for-online-channel-learn-from-expert-w-261</link>
			<guid>http://www.careersinfosecurity.co.uk/webinars/risk-assessment-framework-for-online-channel-learn-from-expert-w-261</guid>
			<description>Risk assessments are the foundation of risk management and information security, and since 2005 U.S. banking regulators have urged institutions to conduct periodic risk assessments of their online banking products and services.
&lt;p&gt;
But institutions failed to follow that guidance, and as a result they and their customers were victimized by sophisticated schemes such as ACH/Wire fraud and corporate account takeover.
&lt;p&gt;
These high-profile fraud incidents helped inspire 2011's updated FFIEC Authentication Guidance, which re-enforces regulators' expectations of periodic risk assessments. Specifically, the guidance says:
&lt;p&gt;
"Financial institutions should review and update their existing risk assessments as new information becomes available, prior to implementing new electronic financial services, or at least every twelve months. Updated risk assessments should consider, but not be limited to, the following factors:
&lt;ul&gt;
&lt;li&gt;Changes in the internal and external threat environment, including those discussed in the Appendix to this Supplement;&lt;/li&gt;
&lt;li&gt;Changes in the customer base adopting electronic banking;&lt;/li&gt;
&lt;li&gt;Changes in the customer functionality offered through electronic banking; and&lt;/li&gt;
&lt;li&gt;Actual incidents of security breaches, identity theft, or fraud experienced by the institution or industry."&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;
&lt;p&gt;
In this session, Joe Rogalski, VP and information security officer at New York's First Niagara Bank ($44 billion in assets), will detail how his institution conducts period risk assessments, including:
&lt;ul&gt;
&lt;li&gt;An overview of the FFIEC guidance and what examiners will expect to see in your approach to risk assessments;&lt;/li&gt;
&lt;li&gt;How to conduct an effective risk assessment, including qualitative and quantitative approaches;&lt;/li&gt;
&lt;li&gt;What to do about risks, vulnerabilities and threats identified in your assessments.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>Five Application Security Tips</title>
			<link>http://www.careersinfosecurity.co.uk/interviews/five-application-security-tips-i-1571</link>
			<guid>http://www.careersinfosecurity.co.uk/interviews/five-application-security-tips-i-1571</guid>
			<description>Many organizations aren't devoting enough resources to ensure that applications for &lt;a href=" http://www.healthcareinfosecurity.com/mobility-c-212"&gt;&lt;b&gt;mobile devices&lt;/b&gt;&lt;/a&gt; are secure, says security expert Jeff Williams. He offers five tips for adequately addressing mobile &lt;a href=" http://www.healthcareinfosecurity.com/application-security-c-205"&gt;&lt;b&gt;application security&lt;/b&gt;&lt;/a&gt;.</description>
			</item>
			<item>
			<title>Understanding Electronically Stored Info</title>
			<link>http://www.careersinfosecurity.co.uk/interviews/understanding-electronically-stored-info-i-1570</link>
			<guid>http://www.careersinfosecurity.co.uk/interviews/understanding-electronically-stored-info-i-1570</guid>
			<description>For years, David Matthews, Deputy CISO of the City of Seattle, has been immersed in securing electronically stored information. Now he's written the book on the topic. What are the key themes addressed?</description>
			</item>
			<item>
			<title>Why Boards of Directors Don't Get It</title>
			<link>http://www.careersinfosecurity.co.uk/interviews/boards-directors-dont-get-it-i-1569</link>
			<guid>http://www.careersinfosecurity.co.uk/interviews/boards-directors-dont-get-it-i-1569</guid>
			<description>IT risk management, cyber insurance, privacy - these are hot topics for security leaders, but not for their boards of directors. Why do senior executives still fail to see IT risks as business risks?</description>
			</item>
			<item>
			<title>How to Respond to Hacktivism</title>
			<link>http://www.careersinfosecurity.co.uk/interviews/how-to-respond-to-hacktivism-i-1568</link>
			<guid>http://www.careersinfosecurity.co.uk/interviews/how-to-respond-to-hacktivism-i-1568</guid>
			<description>Hacktivist attacks will increase, and researcher Gregory Nowak says organizations can take proactive steps to reduce exposure and protect brand reputation. Why, then, are many organizations failing?</description>
			</item>
			<item>
			<title>Fighting Hackers With Public Relations</title>
			<link>http://www.careersinfosecurity.co.uk/blogs/fighting-hackers-public-relations-p-1278</link>
			<guid>http://www.careersinfosecurity.co.uk/blogs/fighting-hackers-public-relations-p-1278</guid>
			<description>&lt;b&gt;Understanding Hacktivists' Goals is Key to Thwarting Attacks&lt;/b&gt;&lt;br /&gt;By understanding the motivations behind hacktivism, organizations can learn why good public relations can play an important role in thwarting attacks or minimizing their impact.</description>
			</item>
			<item>
			<title>The Facts on Occupational Fraud</title>
			<link>http://www.careersinfosecurity.co.uk/blogs/facts-on-occupational-fraud-p-1276</link>
			<guid>http://www.careersinfosecurity.co.uk/blogs/facts-on-occupational-fraud-p-1276</guid>
			<description>&lt;b&gt;How to Detect and Prevent Insider Crime&lt;/b&gt;&lt;br /&gt;The statistics revealed in the ACFE's new 2012 Report on Occupational Fraud and Abuse are all very real. Here are my insights on occupational fraud and steps leaders can take to detect these crimes.</description>
			</item>
			<item>
			<title>The Business Case for Continuity Planning</title>
			<link>http://www.careersinfosecurity.co.uk/blogs/business-case-for-continuity-planning-p-1272</link>
			<guid>http://www.careersinfosecurity.co.uk/blogs/business-case-for-continuity-planning-p-1272</guid>
			<description>&lt;b&gt;Small, Mid-Size Enterprises Especially Need to Develop Strategy&lt;/b&gt;&lt;br /&gt;Why do so many small and mid-sized enterprises continue to believe that business continuity planning is just for the big guys? And how do we go about convincing them otherwise? Here are some tips.</description>
			</item>
			<item>
			<title>Can You Define Cybersecurity?</title>
			<link>http://www.careersinfosecurity.co.uk/blogs/you-define-cybersecurity-p-1267</link>
			<guid>http://www.careersinfosecurity.co.uk/blogs/you-define-cybersecurity-p-1267</guid>
			<description>&lt;b&gt;Answering That Question Isn't So Easy&lt;/b&gt;&lt;br /&gt;The lack of common definitions, understandings and approaches among countries may hamper international cooperation on cybersecurity, a need acknowledged by most countries.</description>
			</item></channel></rss>

