April 2007

Issue 40

[ Tell a Colleague ]  

 Feature Story

Can You Prove You're Ready for Your Next Audit?

How to have an effective configuration auditing process

by Meryl K. Evans, Editor, The Remediator Security Digest

When a business is faced with an internal or external IT compliance audit, a number of fears and uncertainties can arise at all levels of the organization. To prepare for the audit, executive members of the organization begin asking the questions that IT administrators dread having to answer.


 

 Editorial Corner

In compliance? Safe security ... When the employee steps away

SOX. HIPAA. Gramm-Leach-Bliley. What do these regulations have in common? They require affected companies to comply or face punishment. Staying in compliance is a big job, but with security configuration auditing, you can stay on track.

Ever lead a horse to water, but couldn't make it drink? That's how we feel about encouraging users to practice safe security. See what readers suggest to address this problem. Have you ever been donutted? It happens when you step away from the cubicle without locking your computer, and another employee sneaks in and types an email in your name or changes the words in your open document. How do you deal with this predicament?

Our feedback form is short 'n' snappy, and we read every word, so please let us know how we’re doing. For taking the time to complete the survey between meetings and emergencies, we'll enter your name in a drawing for a 256MB MP3 player.

Best,

Meryl K. Evans
Editor, The Remediator Security Digest

To unsubscribe instantly or change your preferences, see links at the bottom
 

 Subscription

Privacy Policy
Enter your email address.


Add Remove
 

 Reader Survey

“The Academy” is a Web site supporting the security community with video-based instruction on how to install, configure and troubleshoot some of today's most popular security technologies. Visit the site at: www.theacademy.ca
 

 Spotlight

President and CEO Mark Shavlik's Computer
Security Blog

 

Partners

Shavlik drives patch management solutions for these companies:


 

 Resources

Shavlik Forums

PatchManagement.org

ISSA

SANS

Computer Security Institute
 

 Archives

Spring 2009
March 2009
Vol. 1 Issue 62
Issue 46
October 2008
Vol. 1 Issue 46
Issue 45
July 2008
Vol. 1 Issue 45
Issue 44
May 2008
Vol. 1 Issue 44
Issue 43
January 2008
Vol. 4 Issue 3
Issue 42
October 2007
Vol. 4 Issue 2
Issue 41
July 2007
Vol. 4 Issue 1
Issue 39
January 2007
Vol. 3 Issue 9
Issue 38
October 2006
Vol. 1 Issue 38
Issue 37
September 2006
Vol. 1 Issue 37
Issue 36
August 2006
Vol. 1 Issue 36
Issue 35
July 2006
Vol. 1 Issue 35
Issue 34
June 2006
Vol. 1 Issue 34
Issue 33
May 2006
Vol. 1 Issue 33
Issue 32
April 2006
Vol. 1 Issue 32
Issue 31
March 2006
Vol. 1 Issue 31
Issue 30
February 2006
Vol. 1 Issue 30
Issue 29
January 2006
Vol. 1 Issue 29
Issue 28
December 2005
Vol. 1 Issue 28
Issue 27
November 2005
Vol. 1 Issue 27
Issue 26
October 2005
Vol. 1 Issue 26
Issue 25
September 2005
Vol. 1 Issue 25

[MORE]

 Security Resources

Gartner Report: Patch Management Best Practices (PDF)

Published: August 17th, 2006 by Mark Nicolett and Ronni J. Colville
 

 Announcement

2.1 Now Available!
Shavlik NetChk Compliance

The simplest way to automate policy and security configuration management!

See how we help you manage regulatory compliance with the following new capabilities:

  • Scanning for patch and spyware policies

  • Overview of policy with the Shavlik Policy Dashboard

  • New coverage for FISMA and NIST 800-53 controls

  • New filter options to create, view and report policy for audits, enforcement and monitoring

  • System checks for the Microsoft Windows® Vista operating system

 for more information.


 

 What's Your Best Advice?

Last Issue's Security Dilemma:

How do you motivate users to practice safe security?

More security and computer-related problems stem from users doing dumb things than from intense external attacks. How do you inspire your users/clients to practice "safe security?"

— Meredith, IT Specialist

Read the best advice from readers of The Remediator Digest
 


This Issue's Security Dilemma:

How do I deal with "Just a quick trip away from the desk" users?

Sometimes our users create undue risk. For example, leaving their login session open while going to the printer to grab a printout, they get distracted and end up away from their desk talking with a coworker for half an hour.

In a situation like this, it's too easy for another person to sneak onto their computers and do something inappropriate. While many people within the organization regularly lock their stations, some forget. I'm concerned about the risk this poses to the network.

Should I make changes to the network so it automatically logs off users after five minutes of inactivity, or just issue another reminder about the importance of security?

— Barbara, Manager

Can You Help? Share your experience. You could win a 256 MB MP3 Player.
Congratulations to this quarter's winner of a 256 MB MP3 Player: Sheri Rusk, owner of Black Rose Friesians, LLC.

 

 The Pointy-Haired Boss

Know how to get what you need:

How to Deal with a Bad Boss

Beat the number one reason for unhappiness at work
by Alexander Kjerulf - Chief Happiness Officer

 

Meetings Make You Stupid

Science proves meetings are worthless
by Christopher Null - Yahoo! Tech

 

 Stayin' The Alpha Dog

Take charge of your career:

Nine Ways to Resolve Workplace Conflict

Understand the causes to implement the solutions
by ArLyne Diamond, PhD - Expert Access

 

The Hot Technology Skills for 2007

Project management, security and architecture skills are tops
by Denise Dubie - NetworkWorld

 

 In Your Down Time

For a well-deserved breather:

Struggling to Enjoy Down Time after Working over 16 Hours?

It might be time to switch to something other than java
by Staff - BBC News

 

Transferring Old Memories from VHS to Disc

Can this product be the answer?
by David Pogue - TechNewsWorld

 

Shavlik Footer
about shavlik / careers / contact us / international     
     INFORMATION RISK MANAGEMENT     SECURITY PRODUCT     SUPPORT     PARTNERS     NEWS
Sponsored by Shavlik Technologies
Copyright © 2007 InternetVIZ, LLC. All rights reserved.
[ Tell a Colleague ]
Powered by IMN