Get up-to-the-minute news and opinions, plus access to a wide assortment of IT security resources that will keep you current and informed.

Keep me logged in Forgot your password?

Please wait...

Please wait...

Global Payments working to again validate its PCI compliance

May 02, 2012

For the first time, breached processor Global Payments disclosed on Tuesday that a number of card brands have removed the company from their approved list of service providers.
 

Can't we just ignore PCI DSS?

Mark Kedgley, chief technical officer, New Net Technologies May 01, 2012

Adopting PCI DSS is a sensible thing to do from a security perspective, says New Net Technologies' Mark Kedgley.
 

A room of her own: Philips Electronics North America and Wisegate

April 05, 2012

A privacy officer at a global company found a way to collaborate efficiently at a top level, while ensuring the protection of company assets, reports Greg Masters.
 

Will Bill C-11 make backups illegal in Canada?

Steven Rodin, CEO of Storagepipe Solutions April 02, 2012

Canada's Bill C-11 leaves us with a few concerns and unanswered questions when it comes to rules and restrictions on the process of data backup.
 

Manage your risk, not somebody else's

Ben Tomhave, principal consultant, LockPath April 02, 2012

The primary driver for security should be to cut risk rather than attempting to churn through an unending string of audit and compliance exercises.
 

Sponsored Video: Greg Fitzgerald of Fortinet on data management

Eric Green, program director, SC Magazine March 05, 2012

Fortinet's Greg Fitzgerald discusses major vulnerabilities, data management, and privacy and compliance issues in the industry at this year's RSA Conference 2012 in San Francisco.
 

RSA Conference 2012: Risk management in the enterprise faces challenges

March 02, 2012

A panel discussion on risk management hovered around issues of balancing the scientific element of data gathering with the art of interpreting the information.
 

Defining a DLP strategy

Jeffrey Brown, global information security program manager, GE Capital • March 01, 2012

DLP solutions remain fairly immature, but the need to protect and monitor sensitive information is greater than ever.
 

Why big business is dealing with big security concerns

Jeremiah Grossman, chief technology officer, WhiteHat Security • February 23, 2012

Businesses are forced to implement specific security mandates even if they don't support their actual security goals.
 

An educated decision: Network smarts at WVU

February 03, 2012

West Virginia University was looking to protect student and staff data. It found a software solution to assist in the process, reports Greg Masters.
 

Campus relief: Kilgore College and Viewfinity

January 20, 2012

A community college in Texas found a tool that enabled it to fend off viruses while coming into compliance, reports Greg Masters.
 

Getting serious about health care security

Peter Spier, manager of professional services, Fortrex Technologies December 06, 2011

Health care providers and their patients both have parts to play in the high-stakes game of protecting sensitive medical information, especially as technology becomes easier to implement and enforcement of regulations intensifies.
 

Security spending to increase in 2012, survey shows

November 22, 2011

While the nation's economy remains in the tank, the information security market appears to be avoiding a major slowdown.
 

Best Enterprise Security Solution & Best Regulatory Compliance

November 08, 2011

Throughout the day, SC Magazine will be announcing the finalists from each of its 32 award categories. Now, let's turn to our Excellence section.
 

Check Point adds Dyanasec for governance, risk, compliance

October 31, 2011

Check Point Software Technologies bolstered its portfolio Monday with the acquisition of privately held Dynasec, a 7-year-old, Israel-based provider of governance, risk management and compliance solutions.
 

Overcoming America's lost decade of IT security

Anup Ghosh, founder and chief scientist, Invincea October 10, 2011

An overreliance on compliance and limited information sharing between the federal government and the private sector have resulted in attackers holding a firm edge over security professionals. How do we take back a decade of losing?
 

FISMA compliance to require monthly reports

September 19, 2011

Beginning in October, federal agencies will be required to report on their information security posture on a monthly basis, instead of annually.
 

Keys to the city: Richmond, Va. and PacketSentry

August 18, 2011

The city of Richmond, Va. found a solution to help prevent trojans from entering the gates, reports Greg Masters.
 

Something borrowed: Benefits of PCI

Stephen Lawton July 01, 2011

The prescriptive nature of the Payment Card Industry Data Security Standard, often referred to as PCI, can benefit even those companies not processing credit card transactions.
 

In search of a global network security standard

Shaul Efraim, vice president of marketing and business development, Tufin Technologies June 27, 2011

A government-adopted and enforced global benchmark for network security may lend value, and borrowing from the PCI DSS playbook could help in its creation.
 

Internet security an early focal point for new government

May 31, 2011

Internet security vaulted into the spotlight as an early focal point for Prime Minister Stephen Harper's new government, on both the domestic and international fronts
 

Thoma Bravo buys Tripwire after it drops IPO plans

May 11, 2011

Private equity investment firm Thoma Bravo has bought Tripwire, a year after the compliance maker had planned an IPO.
 

Diversity breeds system resilience

Ed Amoroso, SVP and CSO for AT&T Services May 02, 2011

IT managers should consider the benefits of non-interoperable platforms, says AT&T's Ed Amoroso.
 

Education Dept. proposes new privacy, data sharing rules

April 08, 2011

As part of a broad effort to better safeguard student privacy, the U.S. Department of Education hired its first ever chief privacy officer.
 

Scaled down, armored up: Small and midsized business protection

April 01, 2011

For many small and midsize businesses, neglecting IT security is a thing of the past, reports Angela Moscaritolo.
 

SC Magazine's CSO of the Year

March 01, 2011

SC Magazine has recognized Scott Sysol of CUNA Mutual Group as CSO of the Year for his work around data privacy, risk reduction, enterprise-wide IT controls and tapeless backup.
 

2011: A security manager's wish list

A. N. Ananth, CEO, Prism Microsystems January 18, 2011

This year, thanks to a renewed focus on the insider threat, the longings of the security professional may come to fruition.
 

Cybersecurity update fails with "don't ask, don't tell" vote

December 10, 2010

Senate Republicans on Thursday shot down an attempt to repeal the military's "don't ask, don't tell" policy that bars gays from serving openly, likely the death knell to a bill that also would have brought major changes to the way the federal government handles information security. A U.S. Senate procedural vote on Thursday to continue debating the National Defense Authorization Act of 2011 failed to garner the 60 votes necessarily to move forward. The bill, passed by the House of Representatives in May, contains provisions to update to the Federal Information Security Management Act (FISMA) and establish a cybersecurity office within the Executive Office of the President. — AM
 

Senate votes to exempt lawyers, doctors from Red Flags

December 02, 2010

Lawyers, doctors and accountants may avoid having to comply with the Federal Trade Commission's new identity theft rule.
 

Eight questions CIOs should ask on cloud security

Lucius Lobo, director of security consulting, Tech Mahindra November 12, 2010

As more organizations continue migrating to the cloud, what should information leaders at organizations be asking of their provider?
 

Legal matters: Aon Corp. and Mitratech

September 24, 2010

Brokerage services provider Aon Corp. found help in streamlining its network operations throughout its global reach into 120 countries, reports Greg Masters.
 

PCI Council: P2PE simplifies PCI DSS compliance

September 23, 2010

The group responsible for managing payment security rules plans to release two new guidance documents early next month assessing the impact of emerging data security technologies on payment card security.
 

IBM buys compliance software firm OpenPages

September 16, 2010

IBM on Wednesday announced that it has agreed to acquire Waltham, Mass.-based risk and compliance management software provider OpenPages for an undisclosed sum. In a news release, IBM said the acquisition will expand its ability to help businesses address risk management and compliance challenges. OpenPages, which will be integrated within IBM's Business Analytics software portfolio, offers solutions to assist organizations with internal audits, vendor risk management and IT risk and compliance management. The company has more than 200 clients, including Barclays, Duke Energy and Carnival Corp. — AM
 

HP to buy ArcSight for $1.5 billion

September 13, 2010

Another IT security company was gobbled up by an IT bellwether when HP on Monday announced plans to acquire Cupertino, Calif.-based SIEM provider ArcSight for $1.5 billion.
 

Is there a silver bullet to the payment industry's data security woes?

Ulf Mattsson, CTO, Protegrity September 02, 2010

Security professionals must consider all the options available to them to secure cardholder data.
 

Control corporate financial risk

Colleen Kulhanek, director of marketing, Shavlik Technologies August 26, 2010

Entitlement reporting can help organizations control risk and meet compliance mandates, while accounting for employee access.
 

PCI Council unveils expected changes for DSS guidelines

August 13, 2010

The body that manages PCI guidelines has released a summary of expected changes, but merchants will not find any mention of emerging data security technologies.
 

Dealing with compliance: Interview with Michael Thelander, product marketing manager at Tripwire

July 27, 2010

SC Magazine Deputy Editor Dan Kaplan sits down with Tripwire's Michael Thelander to learn whether compliance remains a driver for organizations, especially as new regulations pop up and existing mandates become more stringent. Thelander also touches on compliance in the cloud, and whether it can be achieved.
 

IBM buys IT management provider BigFix

July 01, 2010

IBM on Thursday announced plans to acquire BigFix, an Emeryville, Calif.-based provider of security management solutions. Specifically, BigFix software offers a single IT management platform that allows organizations the ability to manage applications for vulnerabilities, systems lifecycle, configuration and compliance. Terms of the deal were not disclosed, but a Bloomberg report valued the transaction at $400 million. IBM's last security-related acquisition was last fall when it picked up database security firm Guardium for a reported $225 million. — DK
 

Security budgets stable or increasing at financial firms

June 18, 2010

Drivers such as compliance and insider threats are helping to keep information security budgets at financial institutions alive and well, according to a new study.
 

Today's CISO can sink or swim

Emeric Miszti, VP of customer enterprise information protection strategy, Verdasys June 01, 2010

Leave behind technological baggage and build business, says Verdasys' Emeric Miszti.
 

PCI Council releases new PIN security standard

May 13, 2010

The group responsible for managing payment security rules has released version 3.0 of the PIN Transaction Security (PTS) standard. The new version replaces the PIN Entry Device (PED) standard in an effort to streamline point-of-sale security guidelines to also cover unattended payment terminals, such as fuel dispensers, and hardware security modules, which are nonuser facing devices used in PIN translations. The update "simplifies the testing process and eliminates overlap of documentation," according to the PCI Security Standards Council. The council also plans to release updates to its Payment Application Data Security Standard and flagship PCI Data Security Standard later this year. — DK
 

New PCI internal assessor training program

April 30, 2010

The PCI Security Standards Council, tasked with managing the Payment Card Industry Data Security Standard (PCI DSS), on Friday announced a new training program designed to educate internal security personnel on conducting assessments. The three-day course, to be led by PCI Council experts, either will enable security departments to better work with with third-party assessors or allow them to conduct their own assessments, Bob Russo, the council's general manager, told SCMagazineUS.com. Merchants that process more that six million annual transactions are required to conduct annual on-site PCI DSS assessments. Classes will be held in multiple locations. For more information, including pricing, visit here. — DK
 

Study finds businesses spending too much on compliance

April 06, 2010

A new report from Forrester Research's consulting arm reveals that organizations are focusing too much on compliance and not nearly enough on protecting valuable proprietary information.
 

Two-day SC Magazine PCI econference continues today

March 23, 2010

Join us Tuesday and Wednesday for our special two-day SC eConference and Expo: Complying with PCI.
 

Solid state: A new state data breach regulation

March 01, 2010

A new privacy regulation in Massachusetts evokes anxiety for many, but getting in line may prove to be no big deal, reports Greg Masters.
 

Forty percent using compensating controls to meet PCI

March 01, 2010

Forty-one percent of merchants are relying on compensating controls to meet Payment Card Industry Data Security Standard (PCI DSS) requirements, according to a survey released Monday by the Ponemon Institute and commissioned by encryption firm Thales. The survey, which polled 155 qualified security security assessors, who are charged with confirming a company's adherence to PCI. Compensating controls "may be considered for most PCI DSS requirements when an entity cannot meet a requirement explicitly as stated, due to legitimate technical or documented business constraints," according to the PCI Security Standards Council. — DK
 

Is increased government regulation the answer to increased privacy protection?

Glen Kosaka, director of marketing, Trend Micro February 25, 2010

Data breaches involving privacy information continue to increase despite the costs, embarrassment and negative publicity associated with them.
 

Security spending, DLP projects to increase

February 23, 2010

Information security budgets will get a boost at many organizations in 2010, according to a study released Tuesday by IT research company TheInfoPro. The study, based on interviews of 259 security decision makers at Fortune 1000 and mid-size organizations, found that 40 percent of enterprises are planning to increase their 2010 security budgets. Data leakage prevention topped the list of projects planned for 2010, followed by identity management and compliance initiatives. — AM
 

Six years later, CAN-SPAM Act leaves spam problem unresolved

Martin Lee, senior software engineer, Symantec Hosted Services February 16, 2010

In 2004 at the World Economic Forum, Bill Gates proclaimed: "Two years from now, spam will be solved." Six years later there is no indication that the spam problem will ever be solved. So what went wrong?
 

Change is constant - so is compliance

Jonathan Sander, IAM/Security analyst, Quest Software February 16, 2010

Organizations must reconsider how they respond to compliance requirements.
 

Solutionary teams up with Singapore-based e-Cop

February 01, 2010

Solutionary, provider of managed security services, has teamed up with Singapore-based e-Cop to offer a suite of security and compliance services. The companies will offer customers common security monitoring, management and compliance services and in-country support in more than 20 languages.
 

Trustwave, Symantec make acquisitions

January 12, 2010

Compliance management vendor Trustwave announced on Tuesday the acquisition of data encryption vendor BitArmor. Trustwave plans to integrate BitArmor's file- and full-disk encryption technology into its current data leakage prevention and endpoint security solution to help clients comply with regulations that are increasing the demand for encryption. Meanwhile, Symantec on Tuesday announced plans to buy Gideon Technologies, provider of IT risk automation, to better serve public-sector customers. Terms of both deals were not disclosed. — AM
 

The death of security assessments?

Steve Dauber, vice president of marketing, RedSeal Systems January 08, 2010

After breaches such as at Heartland Payment Systems, the time may have come for organizations to stop relying on security assessments in favor of potentially more effective risk management tactics.
 

EMC buys Archer Technologies for GRC tools

January 04, 2010

EMC on Monday acquired arguably the most successful pure-play GRC provider, Archer Technologies.
 

Recognizing the payment industry achievements of 2009 and looking ahead

Lib de Veyra, chairman, PCI Security Standards Council December 02, 2009

The chairman of the PCI Security Standards Council shares his thoughts on the payment industry's 2009 successes and looks forward to what is on the horizon to ensure the protection of credit card information.
 

Breached restaurateurs suing point-of-sale provider

December 02, 2009

The restaurants, located in Louisiana and Mississippi, are seeking millions of dollars in damages from Georgia-based point-of-sale vendor Radiant Systems and its distributor Computer World.
 

Compliance 2010: Turning regulatory lemons into compliance lemonade

John Capobianco, president and CEO, Lumigent Technologies November 24, 2009

Looking into my crystal ball for 2010, it looks like more companies will be making the most of a difficult regulatory situation.
 

Mass. data law finalized

November 06, 2009

The Massachusetts Office of Consumer Affairs and Business Regulation this week filed a finalized version of its data security regulations, scheduled to take effect March 1, 2010. The requirements must be followed by companies handling the personal data of Bay State residents. The final version clarifies the deadline by which companies must impose the provisions on their third-party providers. Existing contracts with these third parties must include safeguard rules by March 1, 2012, but new or updated contracts must meet the March 1, 2010 deadline. -- DK
 

FTC allows eight more months for Red Flags compliance

November 02, 2009

Enforcement of the Red Flags Rules has been put off again -- this time until next summer, at the request of Congress.
 

New ID theft rules may not pertain to small businesses

October 22, 2009

A new bill, passed unanimously by the U.S. House of Representatives this week, would exclude health care, accounting and legal firms with 20 or fewer employees from complying with the Red Flags Rules.
 

Visa creates guidance for merchants wanting to encrypt

October 05, 2009

Visa has taken a leading role in establishing best practices for end-to-end encryption implementation.
 

PCI Council examines merits of new technologies

September 25, 2009

Merchants, desiring an easier path to PCI compliance, may soon be encouraged to consider a number of nascent technologies that can help protect cardholder data.
 

Privacy groups blast new health care notification rule

September 22, 2009

Privacy advocates are questioning a provision of the new health care breach notification rule, which states that organizations only need to alert victims if they believe disclosure of the information "poses some harm."
 

Merchants encouraged to crack down on skimming

August 25, 2009

The organization charged with administering credit card security guidelines is offering tips to avoid "skimming" attacks.
 

Small businesses largely not PCI compliant

August 12, 2009

Though 83 percent of small businesses are familiar with the PCI DSS, just 62 are compliant, according to a recent survey.
 

Energy companies say NERC standards inadequate

August 05, 2009

Updated: Respondents in a recent survey noted a number of issues with NERC's cybersecurity standards, including ambiguity over what they require and a need for further strengthening.
 

Red Flags delay

July 30, 2009

The Federal Trade Commission on Wednesday announced that it will, for the third time, push back the enforcement deadline of the Red Flags Rule, which requires financial institutions and creditors to develop identity theft prevention programs. The new enforcement deadline is Nov. 1. In addition, the FTC will ramp up its efforts to educate small businesses about how to comply because many are still confused about their obligations, the FTC said. — AM
 

IBM buys source-code security firm Ounce Labs

July 28, 2009

IBM has acquired Waltham, Mass.-based Ounce Labs, a maker of enterprise source-code security testing software systems.
 

The convergence of eDiscovery and eCompliance

Karthik Kannan, VP, marketing and business development, Kazeon July 24, 2009

Due to the confluence of legal and compliance regulations and IT management issues, the perfect ESI storm has emerged -- and with it, the confluence of both eDiscovery and eCompliance.
 

Health care organizations unprepared for digital transition

July 22, 2009

Most health care organizations do not have data loss prevention technologies or a CISO, while, for many, tight security budgets and required third-party interactions pose additional challenges, according to a new study by Deloitte.
 

Report finds OMB must have bigger role in agency infosec

July 20, 2009

A new government report claims that U.S. federal government agencies' information security management programs are not approved or disapproved annually, as they should be under the Federal Information Security Management Act of 2002.
 

PCI clarifies procedures to secure Wi-Fi

July 17, 2009

With a new guidance document, the Payment Card Industry Security Standards Council aims to clarify what retailers must do to secure their Wi-Fi networks.
 

Final settlement reached in CVS HIPAA violation suit

June 25, 2009

CVS Caremark must implement an information security program and obtain assessments of its effectiveness every other year for 20 years to settle federal charges.
 

FTC releases FAQs on Red Flags Rules

June 12, 2009

A new frequently-asked-questions document aims to clear up some of the confusion around the Red Flags Rules.
 

Bank sues Savvis over 2005 CardSystems breach

May 28, 2009

Utah-based Merrick Bank claims to have lost $16 million as a result of a 2005 breach of payment card processor CardSystems Solutions and is now seeking legal restitution.
 

Study finds IT security pros cheat on audits

May 27, 2009

IT security professionals might think of auditing as a pain, but some are actually cheating to get audits passed, according to a study released Wednesday.
 

GAO report finds security lagging at federal agencies

May 21, 2009

Federal agencies continue to be lax in their implementation of information security programs, according to a new report from the Government Accountability Office.
 

McAfee acquires Solidcore

May 15, 2009

McAfee today announced the acquisition of dynamic whitelisting vendor Solidcore for approximately $33 million. The acquisition advances McAfee's endpoint security and risk management portfolio. Specifically, Solidcore enables McAfee to now provide security for automated teller machines (ATMs), point-of-sale (POS) systems, multifunction printers (MFPs), supervisory control and data acquisition (SCADA) systems, as well as mobile and other embedded devices. In addition, it will strengthen McAfee's virtualization solutions, the company said in a news release. — AM
 

Cloud computing providers require strong audits

May 11, 2009

Companies must develop better ways of evaluating the security and privacy practices of the cloud services they utilize, according to a report by Forrester released Friday.
 

Heartland again PCI compliant

May 01, 2009

Breached payment card processor Heartland Payment Systems has been again certified compliant with the Payment Card Industry Data Security Standard (PCI DSS), the company announced Friday. In March, two months after the breach was disclosed, Visa removed Heartland from its list of compliant service providers. Some experts questioned whether the removal meant merchants risked being fined for doing business with Heartland, but Visa issued a statement saying this was not true. Heartland said it is expects to rejoin the Visa-approved list on Monday. — DK
 

PCI DSS compliance: You can't just check the boxes

Brian Eberhardy, senior consulting engineer for SenSage May 01, 2009

Recent breaches at organizations that were certified as PCI DSS compliant, continue to prove that compliance doesn't completely eliminate the risk of a data breach.
 

RSA: The fundamental challenge of security versus privacy

April 22, 2009

A fundamental tension exists in balancing individual privacy rights and the collective right to security, Gary McGraw, CTO of application security vendor Cigital said at the RSA Conference Tuesday.
 

How the recession is affecting IT spending

April 20, 2009

Despite the financial crisis, companies are still putting forth money for IT security efforts while overall IT spending is less of a priority, according to a new survey conducted by strategy and business advisory firm MetroSITE Group, and Pacific Crest Securities, a technology investment bank.
 

Lumension takes Securityworks

April 20, 2009

Endpoint security solutions vendor Lumension announced on Monday its acquisition of Securityworks, an IT security, risk and compliance solutions vendor. The acquisition will enable Lumension to help organizations improve their overall security and risk posture, optimize IT resources, increase operational efficiency and reduce the cost and complexity of demonstrating compliance the company said in a news release. The IT governance, risk management and compliance (GRC) software market is expected to grow from $590 million in 2006 to $1.3 billion by 2011, according to Forrester Research. — AM
 

Be careful with the Rockefeller-Snowe bill

Luther Martin, chief security architect, Voltage Security April 16, 2009

Some parts of the Rockefeller-Snowe bill make sense, while other parts may cause unexpected consequences.
 

SANS report shows security logs no longer "geek toys"

April 07, 2009

Organizations use security log data to a greater extent than ever before, according to the 2009 Annual Log Management Survey from the SANS Institute.
 

Heartland: Visa won't fine you for doing business with us

March 24, 2009

As Heartland works to become compliant again with the PCI standard, Visa plans to hold off on issuing fines.
 

Insecure smart grid technology could result in utility attacks

March 23, 2009

Development of the smart grid faces a number of uphill climbs -- such as customer adoption and interoperability -- but security could prove of the most difficult tasks.
 

Visa risk chief: Reports of PCI's death exaggerated

March 19, 2009

Criticisms of the PCI DSS will hurt the security of payment systems, Visa's chief risk officer said Thursday at the card brand's Security Summit in Washington, D.C.
 

Visa: Heartland, RBS WorldPay no longer PCI compliant

March 13, 2009

Visa has removed Heartland Payment Systems and RBS WorldPay -- two payment processors that have announced massive data breaches in recent months -- from its list of service providers compliant with payment industry guidelines.
 

How should you ensure PCI DSS compliance?

Gretchen McCoy, Senior VP of the Technology Management Division for Visa International, Retired; Strategic Advisory Board member, Rohati Systems March 09, 2009

Most IT professionals know that firewalls and anti-virus solutions aren't the only technologies needed to address the PCI Council's mandates.
 

Background investigator settles with FTC over ID theft

March 05, 2009

An organization that sells consumer information, including names, Social Security numbers, credit card numbers and credit histories, has settled Federal Trade Commission charges that it failed to properly screen potential customers, leading to the sale of at least 318 reports to ID thieves.
 

Group unveils first-of-its-kind standard to secure patient data

March 02, 2009

An unprecedented health care common security framework seeks to raise patient trust, while enabling organizations to more effectively meet compliance mandates -- especially as they move toward electronic records.
 

PCI council offering "milestones" for compliance

February 27, 2009

The PCI Security Standards Council next week plans to release guidance on how companies should approach complying with the payment security requirements.
 

Netezza buys Tizor

February 26, 2009

Netezza, makers of data management products, has acquired database auditing and monitoring firm Tizor Systems for $3.1 million, according to a filing with the federal Securities and Exchange Commission. The deal will enable Netezza users "to track, store and perform forensic analysis" to help them more readily meet compliance demands, the company said in a release. — DK
 

Visa confirms another payment processor breach

February 23, 2009

Visa has confirmed that yet another payment processor has been hit by hackers.
 

Data protection lawyer appointed to lead DHS privacy efforts

February 19, 2009

A lawyer specializing in data security has been appointed chief privacy officer at the U.S. Department of Homeland Security.
 

CVS to pay $2.25 million to settle HIPAA violation

February 18, 2009

CVS Caremark has agreed to pay nearly $2.3 million for violating federal privacy laws regarding the protection of patient information.
 

NetForensics buys High Tower

February 17, 2009

NetForensics on Monday announced it has acquired High Tower Software, formerly a competitor that provided log management solutions to mid-size businesses. The deal -- terms of which were not disclosed -- enables netForensics and its managed security services provider (MSSP) partners to provide security compliance offerings throughout the lifecycle, including security information and event management, database activity monitoring and log management. High Tower reportedly had closed in November due to poor sales. — DK