How an audit can shore up your security strategy

Information security audits are on the rise, as organizations look to not only bolster their security postures, but demonstrate their efforts to other parties such as regulators.Audits, which are measurable technical assessments of systems, applications and other IT components, can involve any number of manual and automated processes. Whether conducted by internal auditors or outside consultants, they are an effective way for companies to evaluate where they stand in terms of protecting data resources.The high-profile data breaches of recent years have forced many organizations to take a closer look at their security technologies and policies, experts say.To read this article in full or to leave a comment, please click here

Go inside a security operations center

Walk into a security operations center (SOC) and the first impression you get is of an immense war room, with large screens across the entire front wall displaying a world map and endless rows of tabular data.Analysts sit in rows facing the screens as they scrutinize streams of data on their own monitors. Most of the light comes from the wall screens, creating a cavelike atmosphere. The overall feel is one of quiet efficiency.[ Deep Dive: How to rethink security for the new world of IT. | Discover how to secure your systems with InfoWorld's Security newsletter. ] Welcome to Alert Logic’s 24/7 security operations center in Houston, Texas. This is where Alert Logic’s analysts monitor customer applications and networks, hunting for signs of an attack or a breach. For organizations with limited budgets and a small (or not) dedicated security team, working with a managed security services provider like Alert Logic helps close the security gap.To read this article in full or to leave a comment, please click here(Insider Story)

Ransomware rising

Ransomware is a familiar plague in the online world – it has existed for more than 25 years and become increasingly common during the past decade.But, until recently, it has been aimed more at organizations or individual computers than devices. And that is changing. With the explosive growth of the Internet of Things (IoT) – estimates of how many connected devices will be in use by 2020 range all the way up to 200 billion – experts say it is about to get much more common at the consumer level. An attack surface that broad and that vulnerable is irresistible to cybercriminals.[ ALSO: Many ransomware victims plead with attackers ]To read this article in full or to leave a comment, please click here

Outdated payment terminals exempted by Mozilla from SHA-1 certificate ban

Less than two months after a ban came into effect for new SSL/TLS certificates signed with the weak SHA-1 hashing algorithm, exemptions are already starting to take shape.Mozilla announced Wednesday that it will allow Symantec, which runs one of the world's largest certificate authorities, to issue nine new such certificates to a customer in order to accommodate over 10,000 payment terminals that haven't been upgraded in time.According to a discussion on the Mozilla security policy mailing list, Worldpay, a large payment processor, failed to migrate some of its SSL/TLS servers to SHA-2 certificates. As a result of an oversight, the company also didn't obtain new SHA-1 certificates for those servers before Dec. 31, 2015, when it was still allowed to do so.To read this article in full or to leave a comment, please click here

SDN Warriors All-In-One VM

SDN Warriors open community Facebook group today is releasing All-In-One VM v1.0, a Virtual Machine that anyone can run in PC or laptop to learn SDN & NFV skills. The VM runs Ubuntu OS and contains pre-installed OpenStack, OpenFlow network simulated by mininet with OpenDaylight controller, physical router simulated by dynamips, simple web portal and Network Manager written in python created by Riftadi SDN Warriors group admin. The VM is not created nor endorsed by Cisco, Canonical, ONF, Linux Foundation or OpenStack community, so please don’t ask for any support whatsoever from them. One way to use the VM is: by using only a single click in web portal we can provision automatically new vrouter VNF as OpenStack VM, configure OpenFlow network to connect physical router and vrouter, then configure OSPF routing in both physical and vrouter. You can start with this simple use case, then expand it as part of your learning. The VM is free to download and available here: https://facebook.com/groups/sdnwarriors/


With few options, companies pay hush money to data thieves

There's a disturbing new angle to cyberattacks that has become more common over the last year, and it is proving costly for organizations: extortion.Over the last year, companies have at times paid more than US$1 million in hush money to cyberattackers who have stolen their sensitive data and threatened to release it online, said Charles Carmakal, a vice president with Mandiant, the computer forensics unit of FireEye, in an interview on Wednesday."This is where a human adversary has deliberately targeted an organization, has stolen data, has reviewed that data and understands the value of it," Carmakal said. "We have seen seven-figure payouts by organizations that are afraid for that data to be published."To read this article in full or to leave a comment, please click here

Docker networking 101 – User defined networks

image In this post, I’d like to cover some of the new Docker network features.  Docker 1.9 saw the release of user defined networks and the most recent version 1.10 added some additional features.  In this post, we’ll cover the basics of the new network model as well as show some examples of what these new features provide.

So what’s new?  Well – lots.  To start with, let’s take a look at a Docker host running the newest version of Docker (1.10). 

Note: I’m running this demo on CentOS 7 boxes.  The default repository had version 1.8 so I had to update to the latest by using the update method shown in a previous post here.  Before you continue, verify that ‘docker version’ shows you on the correct release.

You’ll notice that the Docker CLI now provide a new option to interact with the network through the ‘docker network’ command…

image 
Alright – so let’s start with the basics and see what’s already defined…

image

By default a base Docker installation has these three networks defined.  The networks are permanent and can not be modified.  Taking a closer look, Continue reading

Arizona county attorney to ditch iPhones over Apple dispute with FBI

Apple’s refusal to help the FBI unlock an iPhone 5c used by one of the terrorists in the San Bernardino, California attack on Dec. 2 has prompted the Maricopa County attorney’s office in Arizona to ban providing new iPhones to its staff.“Apple’s refusal to cooperate with a legitimate law enforcement investigation to unlock a phone used by terrorists puts Apple on the side of terrorists instead of on the side of public safety,” Maricopa County Attorney Bill Montgomery said in a statement on Wednesday.MORE: iPhone7 Rumor RollupTo read this article in full or to leave a comment, please click here

Arizona county attorney to ditch iPhones over Apple dispute with FBI

Apple’s refusal to help the FBI unlock an iPhone 5c used by one of the terrorists in the San Bernardino, California attack on Dec. 2 has prompted the Maricopa County attorney’s office in Arizona to ban providing new iPhones to its staff. “Apple’s refusal to cooperate with a legitimate law enforcement investigation to unlock a phone used by terrorists puts Apple on the side of terrorists instead of on the side of public safety,” Maricopa County Attorney Bill Montgomery said in a statement on Wednesday. Montgomery described as a corporate public relations stunt Apple’s positioning of its refusal to cooperate on privacy grounds. The evidence obtained through searches using warrants to unlock encrypted smartphones, including iPhones, have proven critical to the investigation and prosecution of defendants charged with drug trafficking, sexual exploitation, murder and other serious offenses, he added.To read this article in full or to leave a comment, please click here

Tim Cook: The FBI is asking us to write the software equivalent of cancer

Tim Cook has said the U.S. government is requiring Apple to write "the software equivalent of cancer" by demanding that it help unlock an iPhone used by one of the San Bernardino terrorists.“What’s at stake here is, can the government compel Apple to write software that we believe would make hundreds of millions of customers vulnerable around the world -- including the U.S. -- and also trample civil liberties,” Cook said.+ ALSO Apple v. FBI – Who’s for, against opening up the terrorist’s iPhone +To read this article in full or to leave a comment, please click here

Tim Cook: The FBI is asking us to write the software equivalent of cancer

Tim Cook has said the U.S. government is requiring Apple to write "the software equivalent of cancer" by demanding that it help unlock an iPhone used by one of the San Bernardino terrorists. “What’s at stake here is, can the government compel Apple to write software that we believe would make hundreds of millions of customers vulnerable around the world -- including the U.S. -- and also trample civil liberties,” Cook said. He made his remarks in a 30-minute interview that aired on ABC News Wednesday evening. The CEO was pressed repeatedly on why Apple shouldn't make an exception for a single iPhone that was used by a terrorist.To read this article in full or to leave a comment, please click here

Truly Understanding Microsoft’s Azure Stack

This past month, Microsoft released a public preview of Azure Stack, which I downloaded, fiddled with, and put together this blog post to share what this thing is all about. As with all my blog posts, this is not merely a regurgitation of Microsoft’s announcement or a simple opinion of what I conceptually “think” about the thing, but this is an actual commentary after a few weeks of hardcore fiddling with Azure Stack to truly understand the power and capability of the solution.What is Azure Stack?To start with, “what is Azure Stack?” Azure Stack is effectively Microsoft’s Azure cloud brought into an organization’s own datacenter. True, under the hood Azure Stack is running Microsoft’s Hyper-V and Windows, as well as Linux and Microsoft networking and storage, but when you stop and think about it, you are “running Microsoft’s Azure in your datacenter!”To read this article in full or to leave a comment, please click here