- +
Ticked Off at Tick the Box Mentality 04 February, 2008 13:01:15
Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
- +
Adobe launches hosted services, adds Flash to Acrobat 03 June, 2008 09:02:44
Adobe to launch Web site offering users free hosted services for document creation, sharing and storageAdobe this week is set to unveil the next version of its Adobe Acrobat software, which adds support for the company's Flash multimedia technology. The company also plans to launch a new Web site offering users free hosted services for document creation, sharing and storage.
The Australian National Audit Office (ANAO) says federal government agencies experiencing growing frustration in dealing with e-mails from private addresses must adopt a strategic approach to e-authentification to overcome identity verification issues.
And it says agencies should consider conducting a risk assessment of each type of e-mail request to determine those that are low risk, and can be replied to via e-mail.
In the just released Better Practice Guide Agency Management of Parliamentary Workflow, Auditor-General Ian McPhee notes agencies face a significant issue in dealing with the growing number of e-mails from private addresses.
"Agencies have reported difficulty, and frustration, in deciding how to deal with this correspondence," the guide says. "In the interests of efficiency and speed, agencies wish to be able to use electronic means to respond to many e-mails from correspondents, but it is difficult to be sure of the correspondent's identity if they are not already known to the agency. An e-mail address does not give reliable information about identity."
The answer lies in part with the Australian Government Authentication Framework, it says, an initiative that aims to overcome identity verification issues by providing a set of principles for government to use in e-authentication and guidelines as to when it is safe to interact with unknown identities. The guide notes the AGAF recognizes different types of transactions require different levels of e-authentication, depending on the degree of risk involved, and recommends agencies develop a strategic approach to e-authentication for each type of transaction where users must present an e-authentication credential appropriate to the level of risk of their transaction.
"In line with AGAF principles, agencies can consider conducting a risk assessment of each type of e-mail request to determine those that are low risk, and can be replied to via e-mail," the guide says. "The ANAO notes that ministers generally take a precautionary approach to use of e-mail to reply to correspondents in the public domain, confining it to addresses that are known to them. Until a reliable authentification system is established that includes individuals, it is better practice for agencies to continue to use hardcopy and postal communication with most ministerial correspondents.
"Agencies can also consider undertaking a generic AGAF risk assessment to review all types of correspondence (both e-mail and hardcopy) and their associated risks. This would inform judgements about the risk category of e-mails the agency receives, what level of authentication is needed, and what type of response is appropriate."
The ANAO recommends agencies seek the correspondent's physical mail address, reconcile this with existing address records, and reply by hardcopy letter when e-mail correspondence is assessed to be in a high-risk category. As an alternative it says agencies can respond to the e-mail highlighting the sensitivity of the request and ask the correspondent to submit their request in writing.
"If, however, the request fits into a low-risk category, the subject matter is not sensitive, or covered by privacy or other information protection legislation, agencies may consider it appropriate to provide an e-mail reply. Responses should be included in a PDF format to reduce changeability," it says.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
Four security lessons from the World Bank breach 15 October, 2008 07:39:00
The World Bank is making headlines after a disputed report claims hackers managed to access their secure network for over a year. One security pro offers takeaways that everyone can learn from the breachAccording to a report from Fox News, several servers at the World Bank Group, an organization that offers economic assistance to developing countries around the globe, were repeatedly compromised and breached over the course of the last year. - +
Anonymous proxy servers: Necessary or evil? 15 October, 2008 07:13:00
Some security experts believe anonymous proxy servers are only necessary if you're up to no good, while others see them as a legitimate tool for research, pen testing and the like. Who's right?If there is truly a gray zone in the struggle between online good and evil, anonymous proxy servers live there. - +
Cutting Through the Spin of Recent Vulnerability Disclosures 13 October, 2008 10:53:00
The FUD surrounding the ClickJacking and TCP/IP vulnerabilities has the world seemingly frozen in fear. But once you cut through the spin, the vulnerabilities aren't all that they were made out to be.There are a few highly publicised vulnerabilities at the moment which haven't completely been disclosed and which, it is claimed, could threaten the whole Internet as-we-know-it. Only, when the vulnerabilities are finally disclosed, it seems that the whole incident has been somewhat Chicken Little. - +
PCI app security: Who's guarding the data bank? 13 October, 2008 11:09:00
Compliance strategies for PCI's new application security requirementsWhile Willy Sutton never really said it, the truth is that people rob banks because that is where the money is. Today's criminals don't walk into banks with loaded guns and get-away drivers. Rather they connect from a remote location using a browser and are armed with hacking tools and spyware. - +
Data-center security tools to not overlook 10 October, 2008 11:37:00
With the rise of security suites, it's time to consider some emerging security tools and rethink othersProtecting a corporate data center is like trying to keep an elephant safe from a swarm of flies. Despite your best efforts, bites happen. As the staples of security -- such as firewalls, antivirus software, spam and spyware filters -- come together in suites of products that allow for sophisticated management, there are other security tools either emerging or worth a rethink.
Polaris Installs Massive Generators 15 October, 2008 11:30:00
Netapp first to announce support for native FCoE storage 15 October, 2008 10:02:00
Verizon Business Helps Companies Improve Performance of Key Applications, Enhance Bandwidth Usage 15 October, 2008 10:00:00
m.Net Chosen to Build Fox Sports Mobile Site 15 October, 2008 09:51:00
Carbonite Release 3.7 Features Enhancements Suggested by Carbonite User Base 15 October, 2008 09:49:00
|
||
|
||
|
|
||
|
Still Sneaking In: The Threats Your Security Tools Aren't Telling You About
Web 2.0 applications are all the rage, offering us tremendous value when it comes to collaboration and communication. They also open us up to new kinds of attacks however, and can cause problems in keeping systems and data secure. Read on to learn about the new attack methods and how you can defend yourself and your business.















