BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Filter:
PBIS-resized-600

Center for Digital Strategies And Securing The Perimeter Within

Posted August 4, 2011    Peter McCalister

With our focus on managing the perimeter within we think a lot about the role of human and organizational behavior as well as technology in managing the insider threat. So it was great to discover that he folks at Center for Digital Strategies at the Tuck School of Business at Dartmouth College are doing a lot of great research on human element of IT security.

Categories:
Vulnerability Management
sql-injection

Treat The Symptom Or Cure The Disease

Posted August 3, 2011    Peter McCalister

When virus outbreaks, data thefts and other security breaches impact an organizations computing systems, most will treat the symptoms instead of curing the disease. Treating the symptoms might include updating security software or policies, adding additional layers of security technology, and possibly locking down users so tightly that their productivity suffers.

Categories:
Privileged Account Management
anonymous

Hacker Popularity Overshadows Insider Attacks

Posted August 2, 2011    Peter McCalister

Anonymous and LulzSec attacks have been making a splash across news headlines this summer. It should come as no surprise that hacker attacks are far more publicized than insider attacks. In fact, according to the 2011 CyberSecurity Watch Survey conducted by CSO Magazine and Deloitte, 70 percent of insider incidents are handled internally without legal action.

Categories:
Vulnerability Management
TLA

3 Reasons POS Should Give A DAM

Posted August 1, 2011    Peter McCalister

Just when you thought we exceeded our TLA (three letter acronym) quota for the year, up pops this idea for a blog based on a recent discussion with a national retailer, and I couldn’t resist the play on acronyms and the potential for multiple interpretations. But don’t let the TLAs scare you. This is actually a serious topic that does effect any of you who are responsible for compliance across remote sales locations.

Categories:
General

Data Governance – Why and How?

Posted July 30, 2011    Morgan Holm

In my first blog post I talked about proving and maintaining compliance for data governance rules defined for file system resources in the enterprise. This post will continue the discussion of data governance, reviewing some of the reasons organizations are implementing these policies and processes as well as the main challenges associated defining the rules…

Categories:
Privileged Account Management
Tags:
, , , , , , ,
villain trio

Intent Versus Actions And Least Privilege

Posted July 29, 2011    Peter McCalister

Insider threats are a global phenomenon. Every company in every part of the world is subject to some level of insider threat. And guess what? Insider villains are just as unidentifiable in the UK as they are in the US. They appear just as innocuous in Poughkeepsie as they do in Perth.

Categories:
Privileged Account Management
game theory

Game Theory, Audit Logs And Corporate Governance

Posted July 28, 2011    Peter McCalister

Game theory and audit logs are two topics you don’t frequently see linked. But some recent research from the Center for Digital Strategies at the Tuck School of Business at Dartmouth College linked the two topics and showed that technology can play a critical role in reinforcing the human elements of good security.

Categories:
General
governance

If You Can’t Change It, You Can’t Govern It

Posted July 27, 2011    Peter McCalister

Corporate governance ensures accountability across the extended enterprise. It facilitates staying competitive and satisfying ever-changing government regulations while providing mechanisms and controls to reduce the inefficiencies that arise when individuals misuse privileges granted to them.

Categories:
Security Research
Tucks

The Outside Insider Threat

Posted July 26, 2011    Peter McCalister

Gone are the days when insider threats meant you either had a malicious employee or someone made a mistake; in today’s world the insider threat is far more complex, often starting from the outside and working its way in.

Categories:
Vulnerability Management
os lion

How To Truly Support Mac OS X Lion

Posted July 25, 2011    Peter McCalister

Supporting Mac OS X 10.7 Lion means more than just checking a box on a list of supported platforms. It means that you’ve engineered your product to take full advantage of the features of Lion, and deliver a seamless end-to-end experience for users and administrators.

Categories:
Vulnerability Management