Microsoft Outlook Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 19 August 2009

Compliance does not guarantee security

Posted on 10:30 by Unknown
Tufin: compliance does not guarantee security

(Eskenzi PR) News reports that some of the firms who have experienced data breaches in recent months were PCI-compliant highlights the fact that - even if a company has passed must on the regulatory front - this does not guarantee the integrity of their IT security systems, says Tufin Technologies, the security lifecycle management specialist.

"Complacency is the IT manager's worst enemy, especially when it comes to IT security," said Reuven Harrison, Tufin's chief technology officer.

"This fact was brought home quite clearly at last week's Black Hat security briefings in Las Vegas, at which researchers revealed company after company - and technology upon technology - whose IT security could be compromised," he added.

According to Harrison, as witnessed by the comments of Douglas Merrill, former VP of engineering with Google at Black Hat, if senior managers can become frustrated with an IT architecture, then the same thing can happen further down the management chain.

And when that happens, he says, the firm becomes a breeding ground for IT workarounds that allow staff to work more efficiently, but also allow them to circumvent their own security systems.

As a result of these pressures, having systems in place that check any and all IT security configuration changes for compliance with corporate policies, he explained, is rapidly becoming a critical competent of an efficient security regime.

You can also expect to see these pressures to work more efficiently increase as the effects of the economic situation that many companies now find themselves, said the Tufin CTO.

As a result, he noted, you can begin to understand why, if a company is PCI compliant - as was the case with Heartland Payment Systems - they can still be hit by a data breach.

"Regulatory compliance and best practice certifications are excellent indicators of management quality, but when it comes to security, the acid test is whether multiple layers of security are installed, and are reviewed - as well as tested - on a regular basis," he said.

"This is what security lifecycle management is all about. IT security has now become a state of mind and needs a holistic approach if management is stand a chance of beating the security demons," he added.

For more on PCI/IT security compliance issues: http://preview.tinyurl.com/l56jfj

For more on Douglas Merrill's comments at Black Hat: http://preview.tinyurl.com/mzmwon

For more on Tufin Technologies: http://www.tufin.com

<>
Read More
Posted in | No comments

Tuesday, 18 August 2009

Staff&Line Partners with ProServ

Posted on 10:35 by Unknown
by Michael Smith (Veshengro) & C8 Consulting

St Albans, August 2009 – Staff&Line, a European leader in IT management solutions, has announced today that it has signed a new partner ProServ, an Amman, Jordan-based professional services firm specialising in IT process optimisation.

ProServ has been appointed as a Professional VAR for the Middle East and will resell EasyVista, Staff&Line’s fully integrated software suite for IT Asset and IT Service Management.

Well-established in this region, ProServ covers 16 countries which include Libya, Egypt, Sudan, Jordan, Saudi Arabia, Yemen, Oman, United Arab Emirates, Bahrain, Qatar, Kuwait, Iraq, Lebanon, Syria and Iran. ProServ also has sub reseller relationships with companies in Egypt, Saudi Arabia and UAE.

Staff&Line has invested heavily in its indirect channel strategy in the past 12 months and has a tiered partner programme that comprises Affiliates, Select, Professional and Elite VARs.

Gregory Lefort, VP Business Development comments: “We have a direct presence in France, Italy, Spain and Portugal and work with partners throughout the International region, USA, Asia Pacific and the Middle East. In fact in many areas, like the Middle East for example, we believe that a 100 percent channel strategy is the best way to develop our presence.”

“I am delighted that ProServ has joined our partner programme and believe that it has the breadth and depth to really extend our reach and we see many opportunities coming out of these countries. ProServ is a specialist in ITIL best practice and training and this really complements our offering.”

Staff&Line has over 3,300 clients within Europe currently utilising its EasyVista solution, and has been described as “Visionary” by Gartner Group. The company provides an integrated and modular solution covering all IT management requirements: inventory, audit, asset management for information technology and other types of assets (telecommunication equipment, furnishings, etc.), incident, problem and change management, providing an interface between users and the IT department via an online portal.

Emad Ghattas, Managing Director for ProServ, says: “EasyVista fits perfectly with our IT Service Management portfolio as it completes ProServ’s service offering of designing, creating, optimising, and implementing ITIL v3 policies and procedures. With a robust and comprehensive asset management system that is integral to EasyVista, our clients will realise tremendous benefits including reduction in software and hardware management and maintenance cost including better control on SLAs, SLOs, and contracts.”

EasyVista 2009, comes in two options – EasyVista Classic and EasyVista.com. EasyVista Classic is the traditional licensed option, installed on the customer’s site, while EasyVista.com means that the product is now available in SaaS (Software as a Service) mode.

Additionally, EasyVista has recently completed the PinkVERIFY certification of ITIL v3 compatibility for Service Management solutions. 11 processes were verified as being compatible with ITIL.

ProServ is a leading process excellence solutions’ provider in the Middle East with demonstrable experience in the financial services and manufacturing sectors. By aligning processes with business initiative, ProServ plays an integral role in reducing inefficiencies & waste and optimising productivity & profitability of its clients. Our partnership with iGrafx, IT Process Maps, MKS, and Staff&Line provides us access to a wealth of expertise and best of practices to assist organizations achieve process excellence, ITIL, CMMI initiatives, and improve IT governance. More information about ProServ can be found at www.i-proserv.com.

At Staff&Line they turn to good account 20 years of expertise as a pure player in the IT Management space in order to ‘Make IT Easy’. Their EasyVista solution is easier to deploy, use and maintain than other products in the market, without any compromise to features and functionality or its performance.

EasyVista, which is available in SaaS mode or license mode, is ITIL v3 compatible certified on 11 service management processes and covers all aspects of IT Management (IT Service Management, IT Asset Management, CMDB, automatic inventory, user portal) in a single, integrated and modular solution.

With over 60 certified partners worldwide Staff&Line has a direct presence in 6 countries (France, UK, USA, Italy, Spain, Portugal) and the company boasts over 3300 customers in practically every vertical sector including: banking, insurance, financial services, public sector, retail, healthcare, utilities, telecoms managed service providers and IT consulting).

For more information visit www.staffandline.co.uk

<>
Read More
Posted in | No comments

Monday, 17 August 2009

Microsoft announces Office 2010 web applications

Posted on 08:26 by Unknown
Software giant to put free office applications online for Windows Live users

by Michael Smith (Veshengro)

Microsoft has announced plans to put free applications from its forthcoming Office 2010 software on the web.

In a move that pits it against Google’s free office document suite (Google Docs) the software giant said users of its Windows Live services and software such as calendars and instant messaging, will be able to use light-weight versions of many Office applications.

So what we are going to be seeing is yet another battle as to who can do it better and while MS has been doing office applications as software for ages Google has been in the clud with it longer.

Recently Google and Microsoft have been competing in each other’s dominant area. Last month, Microsoft released a new search engine, Bing, to challenge Google.

And Google hit back by announcing a move into the operating system arena with Chrome OS. This extension of its Chrome web browser is expected to be released next year.

I do not think, though, that Google will have to fear much from Bing, or whatever else a silly name MS might like to give its search engine. Unless it is going to be better than MSN Search which became Live Search and now Bing, it is not going to be any competition to Google whatsoever.

Web based office 2010 applications will include Excel, One Note, Power Point and Word. But the company warned they will have reduced functionality compared to the full installation of Office.

The full version of Office 2010 will include new features such as an image-processing tool and an enhanced cut-and-paste function for Word.

To give more ‘oomph’ to Power Point presentations the company has also included a video-processing tool. Microsoft also plans to include tools to deal with email management in Outlook.

Office 2010 will be released in the first half of next year and can be installed on PCs running Windows XP with service pack 3, Vista, and the yet-to-be-released Windows 7 operating system.

But Office 2010 is, once again, going to be, for PC installation, a rather costly piece of software and I cannot understand why the majority of users would want to bother forking out vast sums for something they can get for free in the form of Open Office, the Open Source software equivalent to Office.

I have been using Open Office now for years and have not looked back. No loopholes no exploits; just software that works. Thanks!

As for online documents; I guess I stick with Google Docs, thanks!

© 2009
<>
Read More
Posted in | No comments

Weak cloud password security highlights strength of local storage

Posted on 08:24 by Unknown
by Michael Smith (Veshengro)

Basingstoke, August 2009 – Reports that researchers at the Black Hat security briefings in Las Vegas drove an electronic steamroller through password recovery systems on Amazon's EC2 and Microsoft's Online Office services come as no surprise, says Andy Cordial, Origin Storage's managing director.

"Password resetting and other security mechanisms in the cloud are always going to be a weak link, as long as user-friendliness comes ahead of security in the cloud computing beauty stakes," he said.

"Expecting regular Joes to whip out a two-factor authentication device for use with a cloud-driven service just isn't realistic. It's not going to happen," he added.

According to Cordial, whose company specializes in secure storage of the bricks and mortar variety, developing a transparent security system for use in the cloud is going to be a seriously uphill task for developers.

Even if the developers succeed in creating a viable and transparent authentication system that can be used on a notebook in a coffee shop in the real world, getting that technology to be accepted on a widespread scale is going to take time, he explained.

On the other hand, he said, installing a user-transparent but high-security hard drive or cluster of hard drives, in an office environment is very easy to implement.

So easy, he noted, that most users need not be aware of the fact their data is being encrypted - and decrypted - to military standards in the background and on-the-fly.

"Secure cloud computing will definitely be the norm for most users in about ten years' time. Until then, encrypted local storage will meet users' needs," he said.

"And the encrypted hard drive technology that is available today can also be acquired for a lot less than you might think," he added.

The biggest problem in all of password security, and especially as regards to “in the cloud” is the human factor.

As Andy Cordial, Origin Storage's managing director said, expecting regular users, the “regular Joes”, to whip out a two-factor authentication device for use with a cloud-driven service just isn't realistic. It's not going to happen. Also strong passwords made up of special signs and such are not going to happen either.

We may have come a little further than “password” for the password but that is about all. We have not gotten much further though, of that we can be certain.

Encrypted hardware technology, as in terra firma hard drives, is still the best choice. Also you can be guaranteed, unless the HDD in fact goes belly up or you really forget the password and have no way of getting at the data, that you can get to your data and that it is 100% your data.

Personally I have looked at “in the cloud” storage but have found all services, especially here the free ones, lacking in a number of ways, not the least of them being that the EULA of many of them state that as a user I would hand over copyright of all materials stored on their drives to them for use as and when they please. Sorry, pardon me? My material is my material, and that's it. I share the copyright with no one.

So, to sum up in the spirit of this: get yourself some good terra firma storage media in the form of external hard drives, servers, and such like and keep the data in house, regardless of the size of your enterprise and even for the home user.

For more on the Black Hat cloud (in)security revelations: http://preview.tinyurl.com/nmm9an

For more on Origin Storage: http://www.originstorage.com

This article was produced from a press release supplied by Eskenzi PR.

© 2009
<>
Read More
Posted in | No comments

Thursday, 13 August 2009

Peru makes a big statement about reusing rather than recycling of electronics

Posted on 12:34 by Unknown
by Michael Smith (Veshengro)

A lot is being talked about how reusing items is usually greener than recycling, and the more an item can be reused, the better.

This is definitely the case for electronics, since throwing them out or even trying to recycle them leads to environmental harm. One nation, it would appear, may just be a leader for this green practice, and that nation is Peru in South America.

Electronics shipped off to developing nations for "recycling" are often still perfectly good and usable, and often end up being broken up in a manner that is neither healthy for the environment nor for those doing the breaking up, the recycling.

A study called "Product or Waste? Importation and End-of-Life Processing of Computers in Peru," and reported at Greener Computing, found that that in Peru imported electronics do not go straight to e-waste dumps to be broken up for recycling but rather 85% of discarded computers sent to the country are reused instead of recycled.

While many countries certainly do not practice this kind of sorting and reuse, it is a practice that could certainly help mitigate the impacts of e-waste in developing nations and should be encouraged – alongside, of course, far better reuse, repair, and recycling practices in the developed nations where the e-waste shipments originate.

Why can we not for that at the country of origin, so to speak? Why can we not refurbish and reuse those computers wherever they are sent from? This could indeed be possible if we would not rely on Microsoft Windows and its need to have lots of memory and powerful processors but instead would migrate over to Open Source operating systems that are not power hungry such as Linux in it various guises.

It is my belief that such e-waste should first of not be seen as waste and secondly should be repaired and refurbished, where necessary, for reuse in the developed nations themselves. It can be done but we must rethink our use and our attachment to proprietary software.

The United States is the primary source of used PCs imported to Peru. Analysis of shipment value (as measured by trade statistics) shows that 87−88% of imported used computers had a price higher than the ideal recycle value of constituent materials. The official trade in end-of-life computers is thus driven by reuse as opposed to recycling.

This starkly underscores both the wastefulness of the US when it comes to electronics, and the great benefits of reusing products instead of recycling them. If other areas where electronics are recycled in toxic ways are helped to create a system for tracking incoming electronics as Peru has developed, perhaps we would see a drastic reduction in e-waste and pollution associated with unregulated e-waste processing.

I am also certain that we can find the same in other developed countries such as Britain and Germany, as an example. That is to say that perfectly good computers and peripherals are being sent abroad as e-waste simply because they have become, thanks to Microsoft and other proprietary software makers, “obsolete”.

But what does being “obsolete” mean as far as computers are concerned?

Primarily it means that those computers can no longer run the latest proprietary software from either Microsoft or other companies and hence upgrades are necessary and, as it is often cheaper, for companies and government at least, to buy new rather than to have refurbished those computers end up in the trash.

The same machines can, however, still can run full tilt and work well also in industry and government with Open Source software in general and operating system specifically and there is no need to discard them.

But very few companies and agencies seem to be prepared to go and use Open Source and hence we end up with all those waste PCs and such.

Time to rethink...

© 2009
<>
Read More
Posted in computer recycling, green computing | No comments

FSA £3m fine on HSBC could easily have been avoided

Posted on 12:31 by Unknown
Cyber-Ark: FSA £3m fine on HSBC could easily have been avoided

(Eskenzi PR) – The three million pounds-plus fine imposed on three of HSBC's divisions for failing to adequately protect customer data could easily have been avoided if the banking group has made use of digital data vaulting technology, says Cyber-Ark.

~Reports that the FSA has hit HSBC's Life UK, Actuaries and Consultants plus Insurance Brokering divisions with heavy-duty fines are the direct result of the bank not using a secure mechanism to allow distributed access to customer's data," said Mark Fullbrook, UK and Ireland Director with the data integrity and security specialist.

"Data vaulting takes the best of encryption and IT security technologies to create data silos into which data can be stored, accessed on a shared basis and edited on a controlled - and auditable - basis," he added.

According to Fullbrook, data vaulting technology is at the heart of Cyber-Ark's Inter Business Vault (IBV) which not only allows data to be stored securely on a fully auditable basis, but also permits the information to be shared collaboratively between users.

The result with IBV is that files can be shared as easily and effectively as some of the cloud-based systems currently available, but with the important proviso that the data remains secure and under full control of the originating organisation concerned.

Most data security systems, he explained, are a trade-off between ease of access and the level of security involved, but IBV offers the best of both worlds, since it offers high levels of encryption and security plus relatively easy shared access.

The HSBC group has been criticised by the FSA for being careless about losing data on more than 180,000 of its customers that could fall into the hands of criminals, the Cyber-Ark Director said.

"If the bank had made a modest investment in IBV technology then it could have prevented this embarrassing - and expensive - situation occurring," he said.

"And you can probably guess who will end up paying for this mistake in the longer term - that's right, the bank's customers," he added.

For more on HSBC FSA fine: http://preview.tinyurl.com/mht6rk

For more on Cyber-Ark: http://www.cyber-ark.com

<>
Read More
Posted in | No comments

Tuesday, 11 August 2009

Twitter down again - another attack?

Posted on 12:15 by Unknown
Breaking News...

Tuesday 08/11/2009
Time 1910 Zulu

Twitter down again, it seems, and cannot be reached. I would guess another cyber attack on the system. Watch out for Facebook and other applications.

1926 Zulu systems working again though wobbly.

MVS
Read More
Posted in | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Open Source Software in Business & Government
    by Michael Smith (Veshengro) Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still...
  • Infosecurity Europe 2011 Hall of Fame nominations now open
    London UK, February  2011 – The time is ripe to elevate the greatest movers and shakers in the world of information security as nominations ...
  • Tufin unveils new functionality & updated PCI DSS 2.0 compliance reporting
    TUFIN TECHNOLOGIES UNVEILS enhanced firewall operations management functionality and UPDATEd pci dss 2.0 compliance reporting New Perm...
  • Web 2.0 services are the next security hurdle says 360°IT – The IT Infrastructure Event
    Planning is are now well under way for the first 360°IT – The IT Infrastructure Event, due to take place at London's Earls Court this co...
  • Safer Internet Day - The role of Security within Social Networks
    Amichai Shulman – CTO and co-founder of Imperva Last week researchers unveiled a “ dating database ” consisting of 250,000 users. This was...
  • ISACA’s EuroCACS Examines Data Protection, Cloud Computing and Social Networking
    ISACA’s EuroCACS Examines Data Protection, Cloud Computing and Social Networking 20-23 March 2011, Manchester, UK Rolling Meadows, IL,...
  • Experts warn about risks of multi-tasking on new iPhone 4.0 OS
    Fortify Software warns companies to beware multi-tasking aspects of new iPhone 4.0 operating system Following a rash of news reports about...
  • Experts says trashed hard drive fiasco at Pfizer could have been avoided with Encryption
    Credant says trashed hard drive at Pfizer would not have happened if data had been encrypted Credant Technologies says that a security gaffe...
  • IT services provider, FORT, brings AVG to Irish market
    by Michael Smith (Veshengro) ISP customers to benefit from complete Internet security solution London, UK – AVG, the world’s most downloaded...
  • Lieberman Software and Q1 Labs Partner to stop insider threats
    Joins Q1 Labs Security Intelligence Partner Program London – February 1, 2011 Organisations seeking to eliminate the potential for anony...

Categories

  • ASUS
  • AVG Link Scanner
  • BeCrypt
  • book review
  • Brocade
  • Codenomicon
  • Columbian USB stick loss
  • computer recycling
  • Conficker worm
  • Credant Technologies
  • cyber crime
  • Cyber-Ark
  • Cyber-Ark®
  • Data Center
  • data encryption
  • DeviceLock
  • Digital Pathways
  • diskGenie
  • Eclypt
  • Eee PC
  • Eee PC Seashell 1008HA
  • F5 Networks
  • Facebook
  • Finjan
  • Finjan Inc.
  • Finjan MCRC
  • Firewall Management
  • Fortify
  • Fortify 360
  • Fortify Software
  • Fortify® Software
  • gadgets
  • Google
  • Google Chrome
  • green computing
  • green IT
  • IBM
  • Infosec
  • Infosec Europe 2009
  • Infosecurity Adviser
  • Infosecurity Europe
  • Infosecurity Europe 2009
  • Internet privacy
  • iStorage
  • iStorage diskGenie
  • iStorage Ltd.
  • Juniper Networks
  • Lakeland
  • Lapdesk
  • LLC
  • Logitech
  • malware
  • ManageEngine
  • McAfee International Ltd
  • MI6
  • MI6 data loss
  • Microsoft
  • MiFi™ 2352
  • Mio
  • Mobile Broadband
  • MS Office
  • National Cybersecurity Advisor
  • Navman
  • Navman Spirit
  • Netac
  • Novatel
  • Novatel Wireless Intelligent Mobile Hotspot 2352
  • OneClick IntelliPanel Desktop
  • online social media
  • open source
  • OpenOffice.org
  • Optenet
  • Origin Data Locker
  • Origin Storage
  • PNDs
  • product review
  • Red
  • SaaS
  • Sat Nav
  • saving energy
  • Security
  • Shavlik Technologies
  • SIS
  • spam
  • Stonewood Group
  • Storage Area Networks
  • Storage Expo
  • Storage Expo 2009
  • Sun Microsystems
  • Swine Flu
  • Syphan Technologies
  • Throwing Sheep in the Boardroom
  • Tufin Technologies
  • Twitter
  • U256
  • Unisys Security Index
  • USB drives
  • Vektor
  • VisionRacer
  • VisionRacer VR3
  • VMware
  • Weast
  • Web Apps Security
  • WebFilter PC Solution
  • WebSpy
  • XSS-driven attacks

Blog Archive

  • ▼  2012 (1)
    • ▼  January (1)
      • Cool Stand – Product Review
  • ►  2011 (67)
    • ►  December (1)
    • ►  April (1)
    • ►  March (14)
    • ►  February (30)
    • ►  January (21)
  • ►  2010 (192)
    • ►  December (20)
    • ►  November (22)
    • ►  October (19)
    • ►  September (5)
    • ►  August (8)
    • ►  July (5)
    • ►  June (22)
    • ►  May (13)
    • ►  April (11)
    • ►  March (13)
    • ►  February (27)
    • ►  January (27)
  • ►  2009 (240)
    • ►  December (25)
    • ►  November (9)
    • ►  October (21)
    • ►  September (19)
    • ►  August (30)
    • ►  July (35)
    • ►  June (30)
    • ►  May (21)
    • ►  April (42)
    • ►  March (8)
Powered by Blogger.

About Me

Unknown
View my complete profile