SearchSecurity provides immediate access to breaking industry news, virus alerts, new hacker threats and attacks, security certification training resources, security standard compliance, webcasts, white papers, podcasts, Security Schools, a selection of highly focused security newsletters and more -- all at no cost. Nowhere else will you find such a highly targeted combination of resources specifically dedicated to the success of today's IT-security professional.
View the complete archive of Enterprise Information Security news, research and expert advice.
Go to SearchSecurity.comRecently on SearchSecurity.com
Using EMET to harden Windows XP and other legacy applications
Expert Michael Cobb details how using EMET, a free tool from Microsoft, can harden Windows XP and other legacy applications.
-
More Highlights
-
With EMET, Microsoft ranges beyond mitigation security technology
The Enhanced Mitigation Experience Toolkit is designed to help improve your e...
-
Windows ASLR: Investing in your secure software development lifecycle
Implementing Windows ASLR can be a worthwhile investment in your enterprise’s...
-
Microsoft offers 'fix' for latest Internet Explorer zero day
Microsoft released a temporary fix to mitigate attacks using the most recent ...
-
-
Definitions
-
distributed denial-of-service attack (DDoS)
On the Internet, a distributed denial-of-service (DDoS) attack is one in whic...
-
Federal Information Security Management Act (FISMA)
The Federal Information Security Management Act (FISMA) is United States legi...
-
computer forensics (cyber forensics)
Computer forensics is the application of investigation and analysis technique...
-
Browse Security Topics
- Enterprise Data Protection
- Application and Platform Security
- Enterprise Identity and Access Management
- Government IT Security Management
- Information Security Threats
- Information Security Careers, Training and Certifications
- Security Audit, Compliance and Standards
- Security for the Channel
- Enterprise Network Security
- Information Security Management
-
Enterprise Data Protection
In an era when data theft and security breaches are daily occurrences, secure data storage is a key component of a security infrastructure. This introduction to enterprise data ... More about Enterprise Data Protection
-
Recent Definitions
-
enhanced driver's license (EDL)
- An enhanced driver's license (EDL) is a government-issued permit that, in addition to the standard features of a driver's license,... -
offensive security
- Offensive security is a proactive and antagonistic approach to protecting computer systems, networks and individuals from attacks. -
targeted attack
- A targeted attack is one that seeks to breach the security measures of a specific individual or organization. Usually the initial attack is conducted to g...
-
-
Highlights
-
More Enterprise Data Protection Topics
-
Application and Platform Security
-
Recent Definitions
-
distributed denial-of-service attack (DDoS)
- On the Internet, a distributed denial-of-service (DDoS) attack is one in which a multitude of compromised system... -
virtual patching
- Virtual patching is the quick development and short-term implementation of a security policy meant to prevent an exploit from occurring as a result of a ... -
mobile app security
- Mobile app security is the extent of protection that mobile device application programs (apps) have from malware and the activities of crackers and ...
-
-
Highlights
-
More Application and Platform Security Topics
Secure SaaS: Cloud services and systems
Operating System Security
Enterprise Vulnerability Management
Virtualization Security Issues and Threats
Securing Productivity Applications
Software Development Methodology
Web Security Tools and Best Practices
Application Firewall Security
Application Attacks (Buffer Overflows, Cross-Site Scripting)
Database Security Management
Email Protection
Open Source Security Tools and Applications
Social media security risks and real-time communication security
-
Enterprise Identity and Access Management
-
Recent Definitions
-
smart label
- A smart label is a slip of paper, plastic or other material on a product that contains an RFID tag in addition to bar code data. -
PIN lock
- The PIN lock is an authentication measure for mobile phones that requires the entry of a personal identification number (PIN) code before a device can be used. -
risk-based authentication (RBA)
- Risk-based authentication (RBA) is a method of applying varying levels of stringency to authentication processes based on the like...
-
-
Highlights
-
More Enterprise Identity and Access Management Topics
-
Government IT Security Management
Government IT security management news and analysis covering information security in the federal government and its agencies as well as state and local governments, national ini... More about Government IT Security Management
-
Recent Definitions
-
Federal Information Security Management Act (FISMA)
- The Federal Information Security Management Act (FISMA) is United States legislation that defines a ... -
Computer Security Incident Response Team (CSIRT)
- A Computer Security Incident Response Team (CSIRT) is a group of professionals that receives reports of s... -
National eGovernance Plan (NeGP)
- National eGovernance Plan (NeGP) is an initiative by the government of India to combine various e-governance systems around the c...
-
-
Highlights
-
Information Security Threats
-
Recent Definitions
-
Shamoon
- Shamoon, also called W32.Disttrack, is a computer virus that has been used for cyber espionage, particularly in the energy sector. -
business logic attack
- A business logic attack is an exploit that takes advantage of a flaw in programming managing the exchange of information between a user interface... -
search engine results page (SERP)
- A search engine results page (SERP) is the list of results that a search engine returns in response to a specific word or phras...
-
-
Highlights
-
More Information Security Threats Topics
Malware, Viruses, Trojans and Spyware
Smartphone and PDA Viruses and Threats
Emerging Information Security Threats
Information Security Incident Response
Hacker Tools and Techniques: Underground Sites and Hacking Groups
Denial of Service (DoS) Attack Prevention
Security Awareness Training and Internal Threats
Application Attacks -Information Security Threats
Web Server Threats and Countermeasures
Identity Theft and Data Security Breaches
Enterprise Vulnerability Management
Email and Messaging Threats-Information Security Threats
Web Application and Web 2.0 Threats-Information Security Threats
-
Information Security Careers, Training and Certifications
... More about Information Security Careers, Training and Certifications
-
Recent Definitions
-
network intrusion protection system (NIPS)
- A network intrusion protection system (NIPS) is an umbrella term for a combination of hardware and software system... -
Certified Information Systems Auditor (CISA)
- The Certified Information Systems Auditor (CISA) is a certification issued by the Information Systems Audit and... -
security clearance
- A security clearance is an authorization that allows access to information that would otherwise be forbidden.
-
-
Highlights
-
More Information Security Careers, Training and Certifications Topics
-
Security Audit, Compliance and Standards
-
Recent Definitions
-
Cyber Intelligence Sharing and Protection Act of 2011 (CISPA)
- The Cyber Intelligence Sharing and Protection Act (CISPA) of 2011 is a proposed Unite... -
PCI DSS 12 requirements
- PCI DSS 12 requirements is a set of security controls that businesses are required to implement to protect credit card data and comply with th... -
PCI DSS 2.0
- PCI DSS 2.0 (Payment Card Industry Data Security Standard Version 2.0) is the second version of the Payment Card Industry Data Security Standard (PCI DSS).
-
-
Highlights
-
More Security Audit, Compliance and Standards Topics
-
Security for the Channel
Browse the articles and tips in this section for the latest information on how to deal effectively with resellers of the latest security tools. More about Security for the Channel
-
Enterprise Network Security
-
Recent Definitions
-
distributed denial-of-service attack (DDoS)
- On the Internet, a distributed denial-of-service (DDoS) attack is one in which a multitude of compromised system... -
computer forensics (cyber forensics)
- Computer forensics is the application of investigation and analysis techniques to gather and preserve evidence from a parti... -
egress filtering
- Egress filtering is a process in which outbound data is monitored or restricted, usually by means of a firewall that blocks packets that fail to meet cer...
-
-
Highlights
-
More Enterprise Network Security Topics
-
Information Security Management
-
Recent Definitions
-
four eyes principle
- The four eyes principle is a requirement that two individuals review and approve some action before it can be taken. In a business context, the two ... -
confidentiality, integrity, and availability (CIA)
- Confidentiality, integrity, and availability (CIA) is a model designed to guide policies for informati... -
mobile security (wireless security)
- Mobile security is the protection of smartphones, tablets, laptops and other portable computing devices, and the networks th...
-
-
Highlights
-
More Information Security Management Topics
Security Industry Market Trends, Predictions and Forecasts
Enterprise Risk Management: Metrics and Assessments
Enterprise Compliance Tools
Business Management: Security Support and Executive Communications
Enterprise Compliance Management Strategy
Disaster Recovery and Business Continuity Planning
Information Security Policies, Procedures and Guidelines
Information Security Laws, Investigations and Ethics
Vendor Management: Negotiations, Budgeting, Mergers and Acquisitions
Information Security Incident Response-Information
Security Awareness Training and Internal Threats-Information
News and analysis from IT security conferences