Click here

Security Best Practices: Archive: March 2002 

New Enterprise Focus: Building Security Teams

Security spending at most organizations accounts for somewhere between 2% and 20% of the total IT budget, according to Giga Information Group, and more of this money is being spent on personnel.

Clinton Worm is No Anna

Two versions of the MyLife.B virus that hit last Friday apparently were done in by their own flaws.

Rise of the Chief Security Officer

Even before Sept. 11, many companies were hiring a top executive specifically to oversee their IT security needs. Since the attacks, that trend has accelerated.

CERT Warns of Instant Messaging Attacks

The CERT Coordination Center says users of Instant Messaging and Internet Relay Chat services are vulnerable to social engineering ploys that can turn their systems into platforms for distributed denial of service attacks.

Chief Security Officers' Pay Varies Widely

CSOs in the financial services industry can expect to earn significantly more than their counterparts in utilities, manufacturing and other fields, a new report shows.

Oracle Servers Overrun With Security Flaws

The Computer Emergency Response Team Coordination Center (CERT/CC) Friday warned of nearly 20 vulnerabilities discovered in Oracle servers.

Bush Security Chief Lays Out Cyber Security Agenda

The federal government should work with industry, academia, government agencies and other nations to devise a means of protecting critical infrastructures and punishing those who commit cyber crimes, according to the vice chair of the president's Critical Infrastructure Board.

Network Security Management Market Heats Up

The market for centralized security management products will be subject to a shakeout over the next few years as larger players enter the fray and acquisitions change the landscape.

U.S. to Triple Information Security Spending

Federal government spending on information security systems and services will increase from $1.3 billion last year to more than $4.1 billion in 2006, according to a report released Wednesday.

Web Services Security in .NET

The proliferation of Web services and their universal acceptance makes them vulnerable to security threats. In this article, software consultant Mansoor Ahmed Siddiqui examines the security features in .NET.

That Microsoft 'Security Update' May Be A Virus

Security firms Wednesday warned that another virus began making its rounds on the Net this week, and this one is masquerading as a Microsoft security update.

Task Force To Explore IT's Role In National Security

Media research group Markle Foundation is joining forces with two Washington think tanks to form a task force to determine how information and technology can enhance national security.

It's Baaack: Virulent Worm Set to Return

E-mail worm Klez.E, the second most-active virus in the world, is expected to wreak havoc in networks across the globe Wednesday.

Vulnerabilities Found in Popular Web Scripting Language

A vulnerability in the PHP scripting language, which is commonly used in Web site development, could enable attackers to execute code that crashes or disrupts Web servers.

Security Experts to IT Pros: Know Your Enemy

IT managers must think like hackers to stop them. That's the premise behind a week-long seminar coming to Boston on Monday. In its fourth year, Ernst & Young's Xtreme Hacking focuses on host and network security defense.