The Experts below are selected from a list of 2580 Experts worldwide ranked by ideXlab platform
Miles Clement - One of the best experts on this subject based on the ideXlab platform.
-
endpoint security issues in endpoint security
Network Security archive, 2007Co-Authors: Miles ClementAbstract:This article forms the second part of an investigation into the controls that organisations should consider enforcing on endpoint computing devices such as desktops and laptops. The controls are based on a research project performed by the information security forum that identified ten key areas that organisations need to focus on.
Andy Jones - One of the best experts on this subject based on the ideXlab platform.
-
the information security forum
Infosecurity Today, 2006Co-Authors: Andy JonesAbstract:For almost 300 major organizations, including half of the Global 500 and many of the world's largest corporations and public sector organizations, the information security forum (ISF) plays a significant role in the fight against growing threats to their information. The ISF's Andy Jones writes.
Benjamin M Burns - One of the best experts on this subject based on the ideXlab platform.
-
a performance analysis of snort and suricata network intrusion detection and prevention engines
International Conference on the Digital Society, 2011Co-Authors: Benjamin M BurnsAbstract:Recently, there has been shift to multi-core processors and consequently multithreaded application design. Multithreaded Network Intrusion Detection and Prevention Systems (NIDPS) are now being considered. Suricata is a multithreaded open source NIDPS, being developed via the Open information security forum (OISF). It is increasing in popularity, as it free to use under the General Public Licence (GPL), with open source code. This paper describes an experiment, comprising of a series of innovative tests to establish whether Suricata shows an increase in accuracy and system performance over the de facto standard, single threaded NIDPS Snort. Results indicate that Snort has a lower system overhead than Suricata and this translates to fewer false negatives utilising a single core, stressed environment. However, Suricata is shown to be more accurate in environments where multi-cores are available. Suricata is shown to be scalable through increased performance when running on four cores; however, even when running on four cores its ability to process a 2Mb pcap file is still less than Snort. In this regard, there is no benefit to utilising multi-cores when running a single instance of Snort.
Agrawal Vivek - One of the best experts on this subject based on the ideXlab platform.
-
information security Risk Management Practices: Community-Based Knowledge Sharing
'Norwegian University of Science and Technology (NTNU) Library', 2018Co-Authors: Agrawal VivekAbstract:information security risk management (ISRM) is an integral part of the management practice and is an essential element of good corporate governance. ISRM helps to identify and manage potential problems that could undermine key business initiatives or projects. There are several challenges associated with conducting ISRM tasks successfully in an organization. Knowledge sharing is an essential part of an organization in exploiting benefits concerning performance, decision making, and transparency. Thus, it is also important to share knowledge related to ISRM practices. Sharing and reuse of knowledge can improve both quality and the process cost-effectiveness of ISRM. A decision-maker can make a valid decision and reduce risks in an organization by receiving the right information at the right time from different sources. Organizations can be in a better position to counter attacks or risk by sharing knowledge related to attackers and methods of attacks. The thesis aims to enhance knowledge sharing practice to solve the challenges faced by the information security Practitioners (ISPs) through the establishment of a working electronic community of practice (eCoP), UnRizkNow. Online questionnaires were designed to understand the factors that affect their participation and willingness to share knowledge on eCoP. ISPs affiliated with information security forum (ISF) and ISACA - Norway chapter were involved in the process of data collection. The responses collected from the ISPs give an insight into their present level of participation in eCoP and the details of various factors that influence them to share or hoard their knowledge on eCoP. The study shows that the members of eCoP are reluctant to participate actively and share knowledge with other community members. Members often fear that they possess valuable and sensitive knowledge in the community and it may ruin their reputation or normal functioning if the other members misuse the knowledge. Several theories were studied to understand the knowledge sharing behavior of an individual and in a community-based knowledge sharing settings. The research revealed that the findings of the initial research comply with the well-known theories such as the social exchange theory, the theory of planned behavior, the social presence theory, and the perceived trust theory. This thesis also explores the theoretical and practical issues in establishing UnRizkNow community for the ISPs. The thesis employs the Design Science Research Method (DSRM) in applying the existing theories and models from the domain of information sharing, information security, behavioral science, and risk management to understand the significant factors that are necessary to establish a working eCoP and encourage the sharing of the knowledge among ISPs. A novel approach of assessing the risk in establishing and maintaining UnRizkNow community was evaluated based on the idea of human factors. Hence, the CIRA method was employed to assess the human-related risks the community may face because of the conflicts in the interests of the involved stakeholders. This study showed how the various incentives of the members and the organizer of UnRizkNow community might conflict with each other and create potential risk in the community. Furthermore, a treatment plan was developed based on the guideline of the CIRA method to mitigate the identified risk. Moreover, the study aims to understand the ISPs perspective concerning the preferred knowledge sharing features on an eCoP. A quantitative approach was employed to carry out the research, and an online questionnaire is created to communicate with the ISPs in Norway. A knowledge sharing model based on the purpose, motivation, preference, and the facilitating condition was developed for UnRizkNow community. Furthermore, an online questionnaire was designed to cover the questions related to the elements and sub-elements of the knowledge sharing model. The participants of the online questionnaire were the ISPs working as a full-time in Norway. The data collection activity revealed various factors that are imperative in establishing UnRizkNow community platform. The features of the UnRizkNow were designed such that the information accessible in the platform will help the members to search the information easily and quickly, get up-to-date information quickly, get more relevant content, establish reputation in the community, identify the members/ post that is trustworthy, and get information in a more collected way. The survey shows that the ISPs were willing to share their knowledge with the members of the electronic community. However, ISPs fear that the community members may misuse the sensitive information shared on the community. The communities that fail to provide a secure way of sharing the knowledge of the member also fail to improve knowledge sharing practices. The study identifies that the present benchmarking system in the information security domain faces several security-related challenges. The benchmarking system does not ensure the confidentiality of the shared information and security during the calculation of benchmarking results. Therefore, a novel approach of encouraging participation on benchmarking task and sharing of knowledge on UnRizkNow platform is proposed in this thesis. A secure benchmarking system was proposed using the electronic voting approach. The concepts of the benchmarking system is mapped to the concepts of the electronic voting system. The secure benchmark system inherits the security properties from the electronic voting system and ensures the confidentiality of the shared information, and the identity of the members. The proposed solution will be helpful to engage UnRizkNow members in sharing sensitive knowledge through the secure benchmarking system
Delucia Jennie - One of the best experts on this subject based on the ideXlab platform.
-
Creating a High Level Incident Response/Forensics Policy by Complying with State and Federal Regulations
RIT Scholar Works, 2006Co-Authors: Delucia JennieAbstract:With the increasing number of threats involving organization\u27s today, i.e., identity theft, fraud, and embezzlement, it\u27s imperative that companies have an incident response/forensic policy in place in order to successfully retain and preserve potential evidence. Organizations need to not only combat current problems, but to prevent them from reoccurring. Organizations should not feel alone in this battle. The federal government along with state governments have passed legislation that mandates an incident response/forensic policy be implemented in order to comply with the newly passed regulations, such has Sarbanes-Oxley (SOX), Health Insurance Portability and Accountability Act (HIPAA), and Gramm-Leach Bliley (GLBA). Also taken into account are guidances, frameworks, and standards that are the building blocks that many organizations have used to create their incident response/forensic policies and procedures. But how do organizations know what to document in these policies? How do they know if their policies comply with the ever growing number of regulations? How do they know that the information they are retrieving is not considered personally identifiable information that may have not been obtained legally? They do so by complying with the redundant, common criterion that is found in these regulations, standards, frameworks, and guidances. Before creating an incident response/forensic policy, organizations need to identify privacy provisions as well as pertinent regulations, standards, frameworks, and guidances. After the latter have been identified, the incident response/forensics requirements need to be identified as well. Many organizations are now realizing the commonality/redundancies when reviewing these regulations, standards, frameworks, and guidances. By identifying these requirements and eliminating the redundancy, organizations can create and maintain a doctrine of documents that ensure that they are in compliance. When new regulations, standards, frameworks, and/or guidances are drafted and released, organizations are inconsistent when trying to comply with the specified timelines instead of integrating them or identifying how they already fit with the current environment. Understanding the current computer incident state and federal laws is equally important, but this expertise is expected of the legal department and law enforcement. Such laws include The Compute Fraud and Abuse Act, The Computer security Act of 1987, The US Privacy Act of 1974, The Electronic Communication Privacy Act of 1986, the Economic Espionage Act of 1996, The National information Infrastructure Protection Act of 1996, USA PATRIOT Act of 2001, and the Homeland security Act of 2002. Only law enforcement, legal departments, and state and federal district attorneys can determine whether or not the incident has the acceptable amount of evidence to prosecute at the state or federal level. For the purposes of this paper, the proceeding laws will not be analyzed. This paper will give a high level overview of the regulations, standards, frameworks, and guidances chosen for an incident response/forensics cross-mapping matrix. In addition, once the appropriate requirements have been identified, new common language requirements will be created, and the identified regulations, standards, frameworks, and guidances will be mapped to them. Once the mapping is complete, the requirements will be written as policy statements, which will create a high level policy that is in compliance with the noted regulations, standards, frameworks, and guidances. Although redundant requirements will have been eliminated, there is still not a standardize computer forensics/incidents handling policy, procedure or process for commercial organizations. When trying to establish a standardized process, circumstances that need to be taken into account are the size of the organization: people, resources, and budget. The latter are the three biggest restraints for organizations to move forward with an incident management program, so creating a standard will only force companies to either not have a process or have to expend above and beyond the resources they have to offer. Although there are many regulations, standards, frameworks, guidances, and requirements mandated and implemented by organizations today, the following standards (ISO 17799:2005, FFIEC information security Handbook, Basel II), regulations (HIPAA, Privacy and security Rule, GLBA Privacy and Safeguard Rule, California information Practice Act (CA SB 1386), NY State security Breach and Notification Act (NY AB 4254), and Sarbanes-Oxley (SOX) Section 301, 302, 404, 409, and 806), frameworks and guidances (Control Objectives for information and related Technology (COBIT), The Committee of Sponsoring Organizations of the Treadway Commission (COSO), The information security forum (ISF March 2005), and VISA/MC Payment Card Industry (PCI) requirements will be the focus for this research. All requirements associated with the latter will be listed and then common language will be extracted to and mapped within a matrix