Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Warrantless Searches of Computers | Main | Top 25 Most Dangerous Programming Errors »

Role of Vulnerability Assessment in Compliance

We've just posted a new article in the Digital Library on vulnerability assessment and compliance. Here is a excerpt:

Government and industry regulations continue to change in response to the dynamics of cybercrime, the expectations of citizens and consumers, and the ability of IT professionals to better manage risks. In 2009, new regulations are expected from the Commonwealth of Massachusetts to require improved data loss protection practices of organizations maintaining information about Massachusetts residents. The Federal Trade Commission (FTC) will begin enforcing the "Red Flag Rule" for creditors and financial institutions to implement measures to mitigate the risk of identity theft. Vulnerability assessment will play a role in these compliance areas as well as with existing regulations.

Financial and government organizations as well as retailers are already subject to regulations that directly require vulnerability assessment or are supported by them. Vulnerability assessment systems support compliance in several ways:

  • Identifying known vulnerabilities in unpatched software
  • Detecting improper configurations that might be compromised by attackers
  • Generating reports showing status of vulnerabilities in applications and networks
This article examines some of the ways vulnerability assessment tools can support compliance requirements directly as well as complement other procedures to improve overall security.

Get the full article here.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/1012

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net