<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Information Defense &#187; cyber security risk assessment</title>
	<atom:link href="http://www.cybersecurityinformation.com/tag/cyber-security-risk-assessment/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cybersecurityinformation.com</link>
	<description>Cyber Security and Risk Management Blog</description>
	<lastBuildDate>Mon, 14 Nov 2011 02:28:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>Balancing The Information Security Program</title>
		<link>http://www.cybersecurityinformation.com/2010/08/27/balancing-the-information-security-program/</link>
		<comments>http://www.cybersecurityinformation.com/2010/08/27/balancing-the-information-security-program/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 13:51:27 +0000</pubDate>
		<dc:creator>Martin Walker</dc:creator>
				<category><![CDATA[Info D News Releases]]></category>
		<category><![CDATA[Information Security News]]></category>
		<category><![CDATA[Risk Management News]]></category>
		<category><![CDATA[cyber security risk assessment]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[information compromise]]></category>
		<category><![CDATA[Information Defense]]></category>
		<category><![CDATA[it & cyber security risk management]]></category>
		<category><![CDATA[vishing]]></category>

		<guid isPermaLink="false">http://www.cybersecurityinformation.com/?p=924</guid>
		<description><![CDATA[The ability to create, transmit, and store information far exceeds the ability to secure it.  The continued assault on information assets is being perpetrated through sophisticated scams devised by organized crime, foreign government espionage groups, employees, contractors and others. The largely accepted view and standard is that the protection of information assets is a technology [...]]]></description>
			<content:encoded><![CDATA[<p>The ability to create, transmit, and store information far exceeds the ability to secure it.  The continued assault on information assets is being perpetrated through sophisticated scams devised by organized crime, foreign government espionage groups, employees, contractors and others.</p>
<p>The largely accepted view and standard is that the protection of information assets is a technology function and hence in many organizations all &#8220;controls&#8221; are within the area of Information Technology.</p>
<p>While technology is an important aspect of any information security program strategy, it is at best only one of three legs of the footstool. Many information compromises start with threats that arise from weak procedures, and may include intentional or unintentional human acts.</p>
<p>Social engineering is the act of obtaining confidential information through the “art of deception”.  Most people have heard of or experienced phishing attacks through email.  The email entices the recipient to visit a website that downloads malicious software to the user PC or tricks the individual into providing sensitive information such as login credentials to business or personal accounts.</p>
<p>Vishing attacks, which are social engineering exploits delivered by phone, are frequently launched against customer service departments, help desks, and other business functions within corporations.  With caller identification easily spoofed and displaying the desired inbound number on the recipient’s display, the attacker poses as someone they are not in attempt to extract sensitive information.    The goal of the attacker may be to gain access to the company’s infrastructure, bank accounts, personal and private information or a variety of other reasons.  It is hard to image how technology can prevent such attacks if the employee is unaware and untrained.</p>
<p>Organizations that fail to look at risk to their information assets from a global perspective by analyzing business processes, identifying potential exposures, and determining the necessary controls to protect their information assets run a high risk of repeat and long-term compromise by both insiders and external attackers.</p>
<p>A well-balanced plan integrates risk management principles and focuses on a blend of preventative, detective and response measures across people, process and technology.   Establishing a plan starts with awareness at the business leadership level, analysis of the threats, and the development robust business-centric mitigation strategies.    While all compromises cannot be prevented, an organization that prepares will detect malicious activity sooner, limit exposure, protect its brand, and recover in a precise preplanned manner</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cybersecurityinformation.com/2010/08/27/balancing-the-information-security-program/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information &amp; Cyber Security Threat Assessment &amp; Risk Mitigation &#8211; Bay Area, San Francisco &amp; Silicon Valley</title>
		<link>http://www.cybersecurityinformation.com/2009/11/23/information-cyber-security-threat-assessment-risk-mitigation-bay-area-san-francisco-silicon-valley/</link>
		<comments>http://www.cybersecurityinformation.com/2009/11/23/information-cyber-security-threat-assessment-risk-mitigation-bay-area-san-francisco-silicon-valley/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 13:43:39 +0000</pubDate>
		<dc:creator>Martin Walker</dc:creator>
				<category><![CDATA[Info D News Releases]]></category>
		<category><![CDATA[Information Security News]]></category>
		<category><![CDATA[bay area]]></category>
		<category><![CDATA[cyber security risk assessment]]></category>
		<category><![CDATA[cyber threat risk mitigation]]></category>
		<category><![CDATA[san francisco]]></category>
		<category><![CDATA[silicon valley]]></category>

		<guid isPermaLink="false">http://www.cybersecurityinformation.com/?p=647</guid>
		<description><![CDATA[Information Defense has been assisting a variety of organizations in the San Francisco Bay and and Silicon Valley Areas of California fortify their security postures through its comprehensive information security solutions. We have been helping a variety of Bay Area organizations prepare for PCI compliance initiatives, strengthen the security of their applications and networks, as [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Information Defense has been assisting a variety of organizations in the San Francisco Bay and and Silicon Valley Areas of California fortify their security postures through its comprehensive information security solutions.</strong></p>
<p>We have been helping a variety of Bay Area organizations prepare for PCI compliance initiatives, strengthen the security of their applications and networks, as well as to implement various risk mitigation strategies including comprehensive threat assessments against the organization’s digital assets.</p>
<p>We are seeing Silicon Valley companies begin to take steps to address internal network and application vulnerabilities and a growing comprehension of the negative consequences that can stem from these internal issues.</p>
<p>Information Defense offers a variety of solutions such as risk assessments, vulnerability and penetration testing, compliance advisement, incident response, and forensic investigations.</p>
<p>Organizations must not underestimate the threats that exist from both internal and external vectors and must ensure that they continue to build on the organization’s ability to <a href="http://www.cybersecurityinformation.com/incident-response-planning/">prepare</a>, <a href="http://www.cybersecurityinformation.com/loss-prevention/">prevent</a> and <a href="http://www.cybersecurityinformation.com/incident-response/">respond</a> to theft of information assets.</p>
<p><a href="http://www.cybersecurityinformation.com/contact-us/">Contact us</a> to understand more how our expert team can assist your organization.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cybersecurityinformation.com/2009/11/23/information-cyber-security-threat-assessment-risk-mitigation-bay-area-san-francisco-silicon-valley/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

