Newsletter:

Skip Navigation LinksHome > Whitepapers

Search the Library
 
Home >

Security

>

Auditing

An Information Technology (IT) audit or information systems (IS) audit is an examination of the controls within an entity's Information technology infrastructure. These reviews may be performed in conjunction with a financial statement audit, internal audit, or other form of attestation engagement.

Results 1 - 25 of 59 matches Sort Results By : Published Date | Title | Company name
Software Assurance - An Executive Discussion on Securing the Enterprise
By : Fortify Published Date: Nov 19, 2008
While investments to secure the enterprise continue to rise, breaches into company systems and data are skyrocketing. These cyber crimes are consistently debilitating organizations operations, reputations and ultimately, viability. Today’s CEOs are demanding aggressive strategies to protect their business. CIOs and CSOs are working together to employ proven Business Software Assurance approaches across the enterprise to stay ahead of constant threats.
Download Now
Fortify
Extracting Value from Enterprise Log Data
By : ArcSight Published Date: Oct 31, 2008
This whitepaper will outline the drivers for log management as well as their underlying challenges and drive towards a common set of requirements for evaluation of log management tools.
Download Now
ArcSight
4 Key Steps to Automate IT Security Compliance
By : Qualys Published Date: Oct 31, 2008
This paper provides a detailed discussion of the internal and external regulatory challenges now faced by organizations, the scope of these challenges, and 4 key ways in which they can be addressed through better business processes and automation.
Download Now
Qualys
Sending, Receiving, and Tracking Large Files Securely
By : YouSendIt Published Date: Oct 20, 2008
In this datasheet, discover how it’s now possible to send large files in a way that’s safer and more affordable than FTP, courier services, and email attachments.  Learn how to beat the security challenges that come with global collaboration and data sharing; avoid crippling data transfer problems like partial file delivery or network delays; and know where your file is every step of the way, from sendoff to final destination. Download your copy now.
Download Now
YouSendIt
How Europe's largest e-commerce business secures its applications
By : Fortify Published Date: Sep 15, 2008
Adrian Asher, Chief Security Officer at Betfair, an online UK betting exchange explains how he manages a “culture of security” and protects the Betfair brand in this 20-minute candid interview.
Download Now
Fortify
A CISO's Guide to Securing Open Source Software
By : Fortify Published Date: Aug 15, 2008
For a CISO, open source introduces a new source of risk and unique security challenge: how do you influence developers over whom you have no direct management control? Jennifer Bayuk, former CISO of Bear Stearns, provides insight on best practices for evaluating, deploying and managing open source code.
Download Now
Fortify
The Best PCI Audit of Your Life: Are You Ready?
By : Preventia Published Date: Jul 21, 2008
This white paper will detail a strategy that enables companies to painlessly gain PCI compliance and ensure effective security. By mapping technical controls to PCI standards and by continuously monitoring, assessing and reporting the status of your environment, Lumension’s Security Suite will make your PCI audit the most efficient and actionable of your life.
Download Now
Preventia
CA Siteminder Web Access
By : CA Published Date: Jul 15, 2008
CA SiteMinder Web Access Manager provides policy based authentication and authorisation, supports multiple advanced authentication techniques, identity federation, and single sign on for Web applications. Traditionally, access management infrastructure has been developed separately for each Web application, leading to duplication and limited control and audit capability. SiteMinder provides centralised capabilities plus extensive additional facilities. Butler Group is impressed with its fine-grained authorisation capabilities, support for advanced authentication techniques, support for a good range of user directories, identity federation based on established standards, and the scalable architecture. Overall, SiteMinder is an impressive solution for mid-sized and large companies who use numerous Web applications to deliver sensitive or business critical data.
Download Now
CA
Server Resource Protection: A Critical Element of IT Security
By : CA Published Date: Jul 08, 2008
This white paper analyzes common vulnerabilities in protecting server resources and suggests a solution based on Server Access Management and Auditing. Working together, server access management and auditing can improve regulatory compliance and data privacy, provide greater IT accountability, partition access to superuser and root accounts, assign more granular responsibilities to individual IT people, monitor activities, and correlate actions across multiple systems.
Download Now
CA
Optimizing Infrastructure Control
By : Tripwire Published Date: Jun 06, 2008
This paper outlines the nature of infrastructure integrity, change auditing, and compliance solutions. It describes how an investment in configuration assessment and change auditing solutions can stabilize IT operations, lowering the operational costs associated with the IT infrastructure; be a force multiplier; and provide a solid foundation that increases the effectiveness of the investment in information security.
Download Now
Tripwire
Proving Compliance with McAfee Total Protection for Data
By : McAfee Published Date: May 01, 2008
Companies feel a sense of security from encrypting data stored on corporate systems on desktops, laptops and mobile devices. They believe this act will protect their intellectual property, and sensitive customer information will remain safe and secure from unauthorized access.  But that is not enough. Simply encrypting this information doesn’t help you prove compliance with external regulations or internal controls during a financial audit or legal discovery process.
Download Now
McAfee
Patch Management 2.0- Evolving Your Patch Management Technology
By : Preventia Published Date: Apr 14, 2008
The realities of security and compliance have changed considerably since patch management faced its first big paradigm shift some years ago. At that time many organizations wrestled with the transition from manual patching and remediation to an automated process. Of course, nothing in security is ever static, so it is no surprise that patch management has continued to evolve since then. Though still automated, today’s best patch management tools and techniques are significantly different from their predecessors.
Download Now
Preventia
Gene Kim's Practical Steps to Mitigate Virtualization Security Risks
By : Tripwire Published Date: Mar 28, 2008
Tripwire founder/CTO Gene Kim provides seven practical steps that IT organizations can take to mitigate the unique security challenges of virtualization. While some are directed specifically at virtualized environments, many of these steps are solid best practices that apply to both physical and virtualized environments.
Download Now
Tripwire
Howard Schmidt, Former CSO for Microsoft and eBay and Former White House Cyber Security Czar
By : Fortify Published Date: Jan 15, 2008
With an extensive background in police, military, government, and industry security, Howard Schmidt explains how to respond to the changing landscape of cyber threats and how business leaders are helping set the standards for application security. He then profiles industry role models who are setting the standard for application security.
Download Now
Fortify
Ensuring SOX Compliance via Enhanced Change Management
By : Solidcore Published Date: Jan 10, 2008
Assure SOX compliance and address key questions asked by SOX auditors with simple change management enhancement.
Download Now
Solidcore
40% PCI Non-Compliance? How to Beat The Stats Without Breaking a Sweat
By : Solidcore Published Date: Jan 07, 2008
New report issued by Fortrex, Emagined Security and Solidcore reveals the cost of PCI compliance is justified. These PCI requirements exist to protect sensitive data - yet, research indicates that these are among the least satisfied requirements across Level 1 merchants, with almost 40% non-compliance. 

Download Now
Solidcore
Ensure the Integrity of your Content: ProofMark System Technical Overview
By : ProofSpace Published Date: Dec 17, 2007
This paper details the processes by which ProofMark tags electronic records with a self-validating cryptographic seal that acts as a "tamper indicator" based on a true and provable time-reference datum.  With this it is able to provide instantaneous and irrefutable proof of authenticity, no matter where the data resides or who has controlled it.
Download Now
ProofSpace
Prepare for Successful Audits: A Change Management Manager Checklist
By : Solidcore Published Date: Dec 13, 2007
This IT audit checklist guide includes advice on assessing the effectiveness of change management in a variety of areas.   As companies grow more dependent on interdependent IT systems, the risks associated with untested changes in development and production environments have increased proportionately.

Download Now
Solidcore
Meeting the PCI Application Security Requirements: Building Compliance In
By : Ounce Labs Published Date: Nov 15, 2007
The PCI DSS is demonstrably becoming a de facto standard of due care for any organization responsible for the privacy and integrity of data. The increased focus on application security in the latest revisions of the PCI DSS can be traced directly to many of the recent high profile breaches, where insecure applications have proved to be the point of access for hackers, and the source of data loss.
Download Now
Ounce Labs
A Guide to Proactively Managing Endpoint Risk
By : Preventia Published Date: Nov 15, 2007
In this whitepaper, Patrick Clawson, Chairman & CEO of Lumension Security, will outline the importance of adopting a Positive Security Model that combines the power of vulnerability management, automated remediation, and whitelist application and device control to eliminate the risk of the unknown threat.
Download Now
Preventia
10 Reasons your RADIUS Server Needs a Refresh
By : Identity Engines Published Date: Oct 15, 2007
For over a decade now, RADIUS servers have been a mainstay of dial-up and VPN access control. The rather inconspicuous RADIUS server, perhaps better known as that beige, general-purpose PC collecting dust in the corner of your data center, has proved sufficient for performing basic duties like validating passwords and granting network access.
Download Now
Identity Engines
Host Access Management with CA Access Control
By : CA Published Date: Sep 13, 2007
Your organization relies on servers to store and access to your most critical information resources. CA Access Control is a product that centralizes control and distributed enforcement of appropriate role-based access to sensitive server resources.
Download Now
CA
Secure Remote Vendor Access to the Enterprise Data Center
By : Axeda Corporation Published Date: Sep 05, 2007
Enabling IT equipment vendors to perform remote service on your data centers helps maximize uptime and lower TCO—but at what risk? Dial-up modems and VPNs introduce security vulnerabilities and lack sufficient auditing capabilities—making it virtually impossible to track external access and maintain data center security. Download this white paper to learn how you can manage security risks, lower service-related costs, achieve regulatory and internal compliance, and more.
Download Now
Axeda Corporation
Effectively Delegate Administrative Privileges
By : NetIQ Corporation Published Date: Aug 27, 2007
Learn how delegating administrative privileges can aid in improving administrative productivity, system availability and security, while satisfying the demands of auditors.  Read this new white paper from NetIQ today.
Download Now
NetIQ Corporation
Identifying Critical Change Control Failure Points
By : Solidcore Published Date: Aug 27, 2007
Identifying critical change control failure points in your infrastructure can help reduce the threat of costly downtime, potential security breaches, and compliance weaknesses. Read this paper for guidelines on how to identify and categorize systems that have characteristics which heighten risk.

Download Now
Solidcore
 
Results 1 - 25 of 59 matches Sort Results By : Published Date | Title | Company name
Home >

Security

>

Auditing

<< Start < Previous 1 2 3 Next > End >>

More Security Topics
Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security
SUBSCRIBE FORM
Receive an email alert whenever new research is added into:
Auditing
Enter your email below:

RELATED TOPICS
Best Practices
264 Documents
Business Management
233 Documents
Compliance
313 Documents
Enterprise Software
123 Documents
Governance
36 Documents
HIPAA Compliance
60 Documents
High Availability
114 Documents
IT Management
369 Documents
Project Management
89 Documents
Sarbanes Oxley Compliance
78 Documents
Security
399 Documents
Security Management
225 Documents
Software Compliance
36 Documents

Search the Library
This Weeks Most Popular Reports Most Popular Topics Vendor Directory
White Papers
   Auditing facts
   Learn about lead generation opportunities and list your white papers