<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
<title>InfoRiskToday.co.uk  RSS Syndication</title>
<link>http://www.inforisktoday.co.uk/rssFeeds.php?type=main</link>
<description>InfoRiskToday.co.uk RSS News Feeds on info risk today news, regulations, blogs and education</description>
<pubDate>Mon, 28 May 2012 06:45:22 -0500</pubDate>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/inforisktoday/uk" /><feedburner:info uri="inforisktoday/uk" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
			<title>Preparing for IPv6</title>
			<link>http://www.inforisktoday.co.uk/preparing-for-ipv6-a-4804</link>
			<guid>http://www.inforisktoday.co.uk/preparing-for-ipv6-a-4804</guid>
			<description>&lt;img src="http://docs.inforisktoday.com/files/images_articles/4804_curran_john_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;What You Need to Know for Secure Implementation&lt;/b&gt;&lt;br&gt;IPv4 - the protocol the Internet originally was built on - is quickly running out of addresses, and organizations must prepare for IPv6. What should they consider, and what steps can they take now?</description>
			</item>
			<item>
			<title>Attack Highlights Third-Party Risks</title>
			<link>http://www.inforisktoday.co.uk/attack-highlights-third-party-risks-a-4801</link>
			<guid>http://www.inforisktoday.co.uk/attack-highlights-third-party-risks-a-4801</guid>
			<description>&lt;img src="http://docs.inforisktoday.com/files/images_articles/4801_artid_4801_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Hack of Online Billing Provider May Have Exposed 500,000 Cards&lt;/b&gt;&lt;br&gt;The hack of online billing provider WHMCS may have exposed 500,000 payment cards. Experts say the incident highlights the persistent risks third parties pose in cardholder data security.</description>
			</item>
			<item>
			<title>Tips for Contracting Cloud Services</title>
			<link>http://www.inforisktoday.co.uk/tips-for-contracting-cloud-services-a-4797</link>
			<guid>http://www.inforisktoday.co.uk/tips-for-contracting-cloud-services-a-4797</guid>
			<description>&lt;img src="http://docs.inforisktoday.com/files/images_articles/4797_gilbert_francoise_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;What Organizations Need to Consider Choosing a Vendor&lt;/b&gt;&lt;br&gt;Cloud services contracts often provide little to no wiggle room. What steps do organizations need to take before signing any contract? IT security lawyer Françoise Gilbert offers some key strategies.</description>
			</item>
			<item>
			<title>Social Engineering: Mitigating Risks</title>
			<link>http://www.inforisktoday.co.uk/social-engineering-mitigating-risks-a-4795</link>
			<guid>http://www.inforisktoday.co.uk/social-engineering-mitigating-risks-a-4795</guid>
			<description>&lt;img src="http://docs.inforisktoday.com/files/images_articles/4795_omurchu_liam_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Symantec Recommends Mix of Tech, Education&lt;/b&gt;&lt;br&gt;Why are socially engineered schemes causing so many headaches? Symantec's new Internet Security Threat Report shows attacks are growing. Here's a list of Symantec's recommendations to thwart risks.</description>
			</item>
			<item>
			<title>ENISA: Cybersecurity Aspects in the Maritime Sector</title>
			<link>http://www.inforisktoday.co.uk/agency-releases/enisa-cybersecurity-aspects-in-maritime-sector-r-2619</link>
			<guid>http://www.inforisktoday.co.uk/agency-releases/enisa-cybersecurity-aspects-in-maritime-sector-r-2619</guid>
			<description>ENISA has published the first EU report ever on cybersecurity challenges in the Maritime sector. This principal analysis highlights essential key insights, as well as existing initiatives, as a baseline for cybersecurity. Finally, high-level recommendations are given for addressing these risks.</description>
			</item>
			<item>
			<title>ENISA: Guidelines on Incident Reporting</title>
			<link>http://www.inforisktoday.co.uk/agency-releases/enisa-guidelines-on-incident-reporting-r-2611</link>
			<guid>http://www.inforisktoday.co.uk/agency-releases/enisa-guidelines-on-incident-reporting-r-2611</guid>
			<description>ENISA has issued guidelines to national telecom regulatory authorities about the implementation of Article 13a, in particular, the two types of incident reporting mentioned in Article 13a: the annual summary reporting of significant incidents to ENISA and the European Commission and ad hoc notification of incidents to other NRAs in case of cross-border incidents.</description>
			</item>
			<item>
			<title>ENISA: Technical Guidelines on Minimum Security Measures</title>
			<link>http://www.inforisktoday.co.uk/agency-releases/enisa-technical-guidelines-on-minimum-security-measures-r-2610</link>
			<guid>http://www.inforisktoday.co.uk/agency-releases/enisa-technical-guidelines-on-minimum-security-measures-r-2610</guid>
			<description>ENISA has issued guidance to national telecom regulatory authorities about the implementation of Article 13a, in particular about the security measures that providers of public communications networks must take to ensure security and integrity of these networks.</description>
			</item>
			<item>
			<title>ENISA Launches Guide on Building Effective IT Security Public Private Partnerships</title>
			<link>http://www.inforisktoday.co.uk/agency-releases/enisa-launches-guide-on-building-effective-security-public-r-2567</link>
			<guid>http://www.inforisktoday.co.uk/agency-releases/enisa-launches-guide-on-building-effective-security-public-r-2567</guid>
			<description>The European Network and Information Security Agency has released a new guide on building effective IT security public private partnerships.</description>
			</item>
			<item>
			<title>Synovus Bank Eliminates Cybercrime - A Case Study</title>
			<link>http://www.inforisktoday.co.uk/webinars/synovus-bank-eliminates-cybercrime-case-study-w-277</link>
			<guid>http://www.inforisktoday.co.uk/webinars/synovus-bank-eliminates-cybercrime-case-study-w-277</guid>
			<description>Synovus Bank, one of the largest community banks in the southeast, offers Online Cash Management services to its commercial clients with a simple pledge: "The freedom to manage your cash position anytime, anywhere." After witnessing relentless cyber-attacks on the endpoints of end users, Synovus Bank knew that meeting this pledge required them to take action. The bank's Product Development team carefully selected an endpoint security solution that met their requirements:&lt;p&gt;&lt;ul&gt;
&lt;li&gt;Satisfying FFIEC Guidelines&lt;/li&gt;
&lt;li&gt;Low customer impact/Ease of installation&lt;/li&gt;
&lt;li&gt;Proven effective, quick to implement and easy to manage&lt;/li&gt;
&lt;li&gt;Complement the bank's two tier security architecture&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;
Hear how Synovus Bank proactively prevents fraud. Kevin Gibson, Director of Product Development at Synovus Bank, explains the challenges they faced, why Trusteer Rapport was the right fit, and its ease-of-deployment. He also discusses how Trusteer's layered security helps them protect against cybercrime, as well as Trusteer's role in enabling compliance with the latest FFIEC guidance. Trusteer's Director of Product Marketing, Oren Kedem will describe Trusteer's Cybercrime Prevention Architecture and how it stops online banking fraud.</description>
			</item>
			<item>
			<title>2012 Cloud Security Agenda: Expert Insights on Security and Privacy in the Cloud</title>
			<link>http://www.inforisktoday.co.uk/webinars/2012-cloud-security-agenda-expert-insights-on-security-privacy-in-cloud-w-276</link>
			<guid>http://www.inforisktoday.co.uk/webinars/2012-cloud-security-agenda-expert-insights-on-security-privacy-in-cloud-w-276</guid>
			<description>What are organizations' top cloud security concerns, and how are security leaders addressing these concerns through policy, technology and improved vendor management?
&lt;p&gt;&lt;p&gt;
This is the key question posed by the 2012 Cloud Security Survey.
&lt;p&gt;
No longer just an emerging technology practice, cloud computing today is embraced globally as a means of gaining efficient access to critical applications, processes and storage. It's now common for organizations to rely on cloud service providers for functions and business applications such as customer relationship management, messaging or storage via a public, private or hybrid cloud. Further, industry-specific cloud-based applications such as electronic health records or mobile banking and payment applications are emerging at an unprecedented pace.
&lt;p&gt;
But these engagements come with questions about risks:
&lt;ul&gt;
&lt;li&gt;What are your cloud service provider's security and privacy measures, and have they been audited?&lt;/li&gt;
&lt;li&gt;Where geographically is cloud data being stored, and how do operational practices comply with government, industry and organizational privacy regulations?&lt;/li&gt;
&lt;li&gt;How is a multi-tenant cloud environment managed, and in the event of system compromise - what will be the incident response escalation process?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
Yes, cloud computing is about efficiencies and new technologies, but it's also about security, privacy and an organization's reputation.
&lt;p&gt;
The 2012 Cloud Security Survey was crafted with assistance from leading experts in cloud computing, security and privacy, with a mission to:
&lt;ul&gt;
&lt;li&gt;Chart the latest cloud trends, including types of cloud implementations most common by industry and region;&lt;/li&gt;
&lt;li&gt;Gauge organizations' top cloud security concerns, from vendor security to data governance and breach preparedness;&lt;/li&gt;
&lt;li&gt;Predict the top areas of investment for organizations most concerned about cloud security.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;
This webinar will draw upon survey results and expert insight from a special roundtable panel to discuss:
&lt;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Top Security Concerns&lt;/b&gt; - Are organizations more concerned about where their data is stored, or whether a malicious insider might be a threat to it?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Success Factors&lt;/b&gt; - On a scale with cost savings and availability of services, how does security now rank among elements critical to a successful cloud computing implementation?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Protective Measures&lt;/b&gt; - What are some of the practices organizations are employing, from instituting more stringent contracts to enforcing third-party audits and even participating in mock security exercises with cloud service providers?&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>2012 Faces of Fraud Survey: Complying with the FFIEC Guidance</title>
			<link>http://www.inforisktoday.co.uk/webinars/2012-faces-fraud-survey-complying-ffiec-guidance-w-270</link>
			<guid>http://www.inforisktoday.co.uk/webinars/2012-faces-fraud-survey-complying-ffiec-guidance-w-270</guid>
			<description>A follow-up to ISMG's 2011 Faces of Fraud Survey, this webinar looks not only at the latest fraud trends and how institutions are fighting back, but also at their progress in putting together layered security controls in conformance with the FFIEC Authentication Guidance.
&lt;p&gt;
&lt;p&gt;
Given the persistence of fraud threats and the demands of the FFIEC Authentication Guidance, the 2012 Faces of Fraud Survey is crafted with assistance from leading experts in fraud detection and prevention, with a mission to: 
&lt;ul&gt;
&lt;li&gt;Chart the latest fraud trends, including account takeover, skimming and payment card breaches;&lt;/li&gt;
&lt;li&gt;Gauge institutions' preparedness to conform to the FFIEC Authentication Guidance, including where they are prioritizing their efforts;&lt;/li&gt;
&lt;li&gt;Predict the top areas of focus for 2012, from real-time fraud monitoring tools to new layered security controls.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>BYOD: Manage the Risks and Opportunities</title>
			<link>http://www.inforisktoday.co.uk/webinars/byod-manage-risks-opportunities-w-266</link>
			<guid>http://www.inforisktoday.co.uk/webinars/byod-manage-risks-opportunities-w-266</guid>
			<description>From home computers and laptops to cellphones and PDAs, employees have always lobbied to introduce consumer technologies in the workplace.
&lt;p&gt;
&lt;p&gt;
But with the advent of smart phones, tablets, portable storage and a variety of laptops - powerful computing devices that often rely on unsecured wireless networks - the push today is even greater. Example: Intel, the global computer technologies manufacturer, reports that connected mobile devices grew from 10,000 to 30,000 over the first 10 months of 2011. And by 2014, Intel expects 70% of its employees to use personal devices for some aspect of their job.
&lt;p&gt;
So, it's no longer a question of whether to allow employees to use their own devices - no corporate policy can stem the tide of consumerization. The questions now are about:
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Inventory&lt;/b&gt; - How do you properly account for all of the consumer devices introduced by your employees? Know how to lock down your corporate wireless networks and desktop computers, so you'll also know when employees are trying to access corporate resources via connecting new devices.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Security&lt;/b&gt; - How do you protect your systems and data from unauthorized access - and in the event of lost or stolen devices? From identification to proper authentication, appropriate access control, data storage and detecting un-authorized activities - all controls implemented by an organization on 'corporate-owned' resources over the last decade can potentially be rendered useless on an employee-owned device. Learn the importance of each control and the implementation challenges in a large-scale environment.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Privacy&lt;/b&gt; - The controls you place on an employee-owned device could potentially compromise the individual's privacy (knowing which sites they visit, or whom they e-mail in their off-hours, for instance). How do you achieve the right balance to protect the enterprise's security and the employee's privacy?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Compliance&lt;/b&gt; - Certain international regulations and standards spell out standards for how data is collected and stored, as well as how it must be made available for legal requests. Are you prepared to address these and other top-level compliance issues when it comes to employees storing enterprise data on their own devices? Learn how to weigh the risks and benefits.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Policy&lt;/b&gt; - Beyond making employees aware of your policy, how do you enforce it? Awareness is key - make sure employees understand your policies around device usage, access, software licensing and other critical issues. But you also need to articulate specific areas of non-compliance and then monitor appropriately for violations subject to disciplinary action, including termination.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Opportunity&lt;/b&gt; - Beyond securing devices, BYOD is an opportunity to improve data and access security in the enterprise, web, mobile, and SaaS applications. The opportunity is for organizations to still have strong security and authentication, but in a way that is "outsourced" to the device owner for all of their applications. This outsourcing can save the company IT budget, as well as reduce help desk support.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;
In this session, mobile security experts will discuss these topics and more, sharing insights on how today's leading-edge organizations are embracing BYOD as a means of improving employee productivity and creating new business value.</description>
			</item>
			<item>
			<title>Why Boards of Directors Don't Get It</title>
			<link>http://www.inforisktoday.co.uk/interviews/boards-directors-dont-get-it-i-1569</link>
			<guid>http://www.inforisktoday.co.uk/interviews/boards-directors-dont-get-it-i-1569</guid>
			<description>IT risk management, cyber insurance, privacy - these are hot topics for security leaders, but not for their boards of directors. Why do senior executives still fail to see IT risks as business risks?</description>
			</item>
			<item>
			<title>How to Respond to Hacktivism</title>
			<link>http://www.inforisktoday.co.uk/interviews/how-to-respond-to-hacktivism-i-1568</link>
			<guid>http://www.inforisktoday.co.uk/interviews/how-to-respond-to-hacktivism-i-1568</guid>
			<description>Hacktivist attacks will increase, and researcher Gregory Nowak says organizations can take proactive steps to reduce exposure and protect brand reputation. Why, then, are many organizations failing?</description>
			</item>
			<item>
			<title>4 Security Priorities for Banks</title>
			<link>http://www.inforisktoday.co.uk/interviews/4-security-priorities-for-banks-i-1566</link>
			<guid>http://www.inforisktoday.co.uk/interviews/4-security-priorities-for-banks-i-1566</guid>
			<description>From mobile and the cloud to DDoS attacks and risks surrounding big data, what should banks and credit unions do now to mitigate exposure? Gartner's Anton Chuvakin offers his top recommendations.</description>
			</item>
			<item>
			<title>Intelligent Defense Against Intruders</title>
			<link>http://www.inforisktoday.co.uk/interviews/intelligent-defense-against-intruders-i-1565</link>
			<guid>http://www.inforisktoday.co.uk/interviews/intelligent-defense-against-intruders-i-1565</guid>
			<description>Imagine a computer network that can fool intruders into seeing configurations that in reality don't exist, making it hard for them to invade the system. That's what Scott DeLoach is trying to figure out how to do.</description>
			</item>
			<item>
			<title>The Facts on Occupational Fraud</title>
			<link>http://www.inforisktoday.co.uk/blogs/facts-on-occupational-fraud-p-1276</link>
			<guid>http://www.inforisktoday.co.uk/blogs/facts-on-occupational-fraud-p-1276</guid>
			<description>&lt;b&gt;How to Detect and Prevent Insider Crime&lt;/b&gt;&lt;br /&gt;The statistics revealed in the ACFE's new 2012 Report on Occupational Fraud and Abuse are all very real. Here are my insights on occupational fraud and steps leaders can take to detect these crimes.</description>
			</item>
			<item>
			<title>The Business Case for Continuity Planning</title>
			<link>http://www.inforisktoday.co.uk/blogs/business-case-for-continuity-planning-p-1272</link>
			<guid>http://www.inforisktoday.co.uk/blogs/business-case-for-continuity-planning-p-1272</guid>
			<description>&lt;b&gt;Small, Mid-Size Enterprises Especially Need to Develop Strategy&lt;/b&gt;&lt;br /&gt;Why do so many small and mid-sized enterprises continue to believe that business continuity planning is just for the big guys? And how do we go about convincing them otherwise? Here are some tips.</description>
			</item>
			<item>
			<title>Measuring the Immeasurable: IT Security</title>
			<link>http://www.inforisktoday.co.uk/blogs/measuring-immeasurable-security-p-1271</link>
			<guid>http://www.inforisktoday.co.uk/blogs/measuring-immeasurable-security-p-1271</guid>
			<description>&lt;b&gt;A Year After Its Debut, Index of Cybersecurity Rises by 30 Percent&lt;/b&gt;&lt;br /&gt;Factors driving up the index vary from month to monthly, but the clear takeaway of the survey of IT security practitioners is that they're getting more apprehensive about safeguarding IT.</description>
			</item>
			<item>
			<title>Can You Define Cybersecurity?</title>
			<link>http://www.inforisktoday.co.uk/blogs/you-define-cybersecurity-p-1267</link>
			<guid>http://www.inforisktoday.co.uk/blogs/you-define-cybersecurity-p-1267</guid>
			<description>&lt;b&gt;Answering That Question Isn't So Easy&lt;/b&gt;&lt;br /&gt;The lack of common definitions, understandings and approaches among countries may hamper international cooperation on cybersecurity, a need acknowledged by most countries.</description>
			</item></channel></rss>

