Risk Assessment

Know thyself, or risk being known by attackers

Know thyself, or risk being known by attackers

Understanding your organization's security posture can mean the difference between data that's protected from attackers and a breach that can result in major financial and reputational harm.

Managing policy and risk requires sophisticated tools

Managing policy and risk requires sophisticated tools

By

Risk is a multilayered function derived from threat, vulnerability and impact.

Tightening the fed's belt: Government Roundtable

Tightening the fed's belt: Government Roundtable

By

At a recent SC Magazine Roundtable, gov't security pros bemoaned the difficulty in obtaining resources. But instead of crying over spilled milk, they traded ideas for mitigating risk in a down economy.

GAO calls on feds to better address supply chain risk

GAO calls on feds to better address supply chain risk

By

The GAO, which performs audits, evaluations and investigations on behalf of Congress, examined four agencies whose duties involve national security: the Energy, Homeland Security, Justice and Defense departments.

Making risk management more manageable

Making risk management more manageable

Most businesses don't understand how to manage risk, yet, we live in a world full of risks, says Guidance Software's Anthony Di Bello.

Check Point adds Dyanasec for governance, risk, compliance

By

Check Point Software Technologies bolstered its portfolio Monday with the acquisition of privately held Dynasec, a 7-year-old, Israel-based provider of governance, risk management and compliance solutions.

NERC CSO departs for newly created DHS role

NERC CSO departs for newly created DHS role

By

Mark Weatherford, former CSO of the North American Electric Reliability Corp. (NERC), has been appointed to a newly created position at the U.S. Department of Homeland Security. Serving as deputy under secretary for cybersecurity within the National Protection and Programs Directorate (NPPD), the DHS component charged with reducing risk, Weatherford will focus on ensuring strong cybersecurity operations and communications for the department. He is expected to start in mid-November. Prior to his role at NERC, Weatherford was CISO of the state of California. A former naval cryptologic officer, Weatherford also previously led the Navy's computer network defense operations.

NIST releases continuous monitoring guidance

By

The National Institute of Standards and Technology late last week published new guidance to help organizations develop and implement an information security continuous monitoring (ISCM) program. This initiative can help companies better provide ongoing awareness of threats and vulnerabilities, assess the effectiveness of deployed security controls and support risk management decisions, according to the 80-page guidance document. A mature ISCM program, which requires the use of both automated and manual processes, will enable companies to move from compliance-driven to data-driven risk management.

Benefits of DIY risk assessment

Benefits of DIY risk assessment

Enterprises can achieve ROI by doing an in-house risk assessment, says Kris Rowley, CISO of the state of Vermont.

DHS unveils new programs for software security

By

Software buyers may soon have access to more secure offerings, thanks to a new scoring system that will allow end-users to demand more assurance.

Post-WikiLeaks: Back to basics

Post-WikiLeaks: Back to basics

Dust off your company's risk assessment process and make sure it is up to date because this is where your approach to defending against a WikiLeaks type of threat is going to start.

Sign up to our newsletters

POLL