Infrastructure

Network Security & Continuity

Read the headlines - security is by far the highest profile issue of the new millennium. Keep up to date on the latest IT security threat vectors and learn how to protect against and mitigate their effects.


Stay on top of emerging technologies and changes in the IT landscape. Learn which technologies are right for your organization, and develop the best strategy for implementation.

Forecast - Trends & Predictions

Eliminate Security Threats with Advanced Security Management Solutions
Eliminate Security Threats with Advanced Security Management Solutions

Advanced security management solutions are an important next step in the ongoing fight against IT security threats. Info-Tech survey data shows that enterprises of all sizes understand this message and intend to adopt these solutions. Enterprises that have not yet investigated these solutions need to do so sooner rather than later.

Security Spending Exceeds 7% of IT Budgets
Security Spending Exceeds 7% of IT Budgets

Security is a ubiquitous topic with IT managers today. This note helps build understanding of how much of the IT budget is being allocated to security and further divides this expenditure into technology acquisition (i.e. purchases) and operational expenditures, of which the largest is staffing.

External IT Security Threats Continue to Grow
External IT Security Threats Continue to Grow

The prevailing opinion in regards to security threats is that the most significant ones originate from within the enterprise, and yet external threats are simply not going away. Malware continues to exist, vulnerabilities continue to be found, and e-mail threats continue to circulate. While enterprises must protect themselves from insider threats, they cannot ignore external threats to do so.

Understand - Technology Insights

Adaptive Security: An Improved Security Framework
Adaptive Security: An Improved Security Framework

Info-Tech Research Group has developed a better way of addressing enterprise security through a model called Adaptive Security. This model goes beyond not only traditional security tools, but also recently proposed endpoint security frameworks. Adopting the Adaptive Security framework for security management will yield more consistent and higher levels of IT security.

A Route to SIMple Security and Compliance Management
A Route to SIMple Security and Compliance Management

By integrating with all aspects of the enterprise’s IT infrastructure, Security Information Management (SIM) provides a comprehensive view of enterprise security. This integration also allows the tool to more efficiently and accurately provide the information necessary for regulatory compliance audits. Mid-sized and larger enterprises, particularly those that are regulated, must investigate this...

IDP: A Digital Alarm on the Doors of the Network
IDP: A Digital Alarm on the Doors of the Network

Intrusion Detection and Prevention (IDP) continues to mature and is becoming an essential component of the corporate IT security infrastructure. Picking the right IDP solution is the key to achieving the greatest performance at the best price.

Information Risk Management: Leaping Beyond IT Security
Information Risk Management: Leaping Beyond IT Security

Information Risk Management (IRM) is the evolution from disparate IT security and compliance initiatives towards a more holistic approach to the protection of information assets and business continuity. Enterprises that continue to attack IT security issues in a purely tactical manner will find it increasingly difficult to manage the often complex and interrelated compliance, intellectual...

Microsoft Security Strategy a Misstep for Larger Enterprises
Microsoft Security Strategy a Misstep for Larger Enterprises

Microsoft’s focus and commitment to the security space is evidenced by the breadth and depth of its security strategy. While the tool set is capable, its focus is currently limited to Microsoft applications and networks so it is unsuited for deployment in mid to large sized enterprises. These organizations should not move on Microsoft’s vision yet, but should be mindful as coverage and...

SSL VPNs: Flexibility, Security, and Simplified Management
SSL VPNs: Flexibility, Security, and Simplified Management

An increasingly mobile workforce, partners, and contractors require remote connectivity to files and applications that reside behind the corporate firewall. Secure Socket Layer (SSL) VPN solutions provide enterprises with flexible, easy to manage, secure access to corporate resources, and should be on the network manager’s radar today.

Cisco and Microsoft: An Unlikely Partnership in the Network Access Control Market

Cisco and Microsoft have released the long-awaited architectural details on interoperability between their respective Network Access Control...

Deep Freeze Puts Workstation Mods on Ice

Public computers, such as those in libraries, are more vulnerable than most. They are constantly compromised by the usual viruses, malware, and...

Guide to Secure Web Services

The US National Institute of Standards and Technology (NIST) released a "Guide to Intrusion Detection and Prevention Systems (IDPS)" in February...

IAM: The Cure for User Access Management Issues

Identity and Access Management (IAM) improves enterprise security operations by improving password usage and by providing easier user management with...

Social Networking Friends Are Network and Security Foes

The meteoric rise of social networking sites such as MySpace, Facebook, and YouTube has been great for social networkers, but these sites are...

Unified Threat Management Not on the SME Radar

All-in-one security appliances, while attractive to small companies with few resources, are not enjoying great interest or adoption. Seriously...

USB-Based Password Management a Flawed Solution

Password management software stores login information so that it doesn't have to be retyped by the user. USB-based versions have been touted as a way...

Vista and Microsoft's New Security Landscape

Microsoft Vista introduces a variety of security capabilities not present in previous Microsoft operating systems. If these new security capabilities...

Wireless Intrusion Detection Defends the Enterprise Airspace

A critical component of a secure enterprise Wireless LAN (WLAN) is a Wireless Intrusion Detection System (WIDS). A WIDS is necessary for enterprises...

Yoggie: Smarter Than Your Average Security Solution

When it comes to endpoint devices, particularly mobile ones such as notebooks, enterprises must take as many precautions as they can to protect the...

Microsoft EFS: Laptop Encryption for All!

While Microsoft’s Encrypting File System (EFS) may not be the most feature rich encryption solution available, it offers sufficient functionality for...

Cisco Releases Router-Integrated Video Surveillance Solution

Cisco’s approach to branch office video surveillance, namely the integration of monitoring and management capabilities within its own network...

Data Leakage Protection Not the Silver Bullet

Data Leakage Protection (DLP) is a useful weapon in the fight to protect the enterprise’s information assets. It is not however the silver bullet...

Strategize - Strategy & Planning

Adaptive Security: Plan Today, Adopt Tomorrow
Adaptive Security: Plan Today, Adopt Tomorrow

Info-Tech Research Group’s Adaptive Security model improves the security of the enterprise while facilitating regulatory compliance. To achieve this, changes in the enterprise’s processes, technologies and organization are all required. Breaking the effort into a series of phases simplifies the work and spreads the cost, but requires careful planning. Start that planning today in order to begin...

Desktop Virtualization Offers Alternative for Remote Access and Business Continuity
Desktop Virtualization Offers Alternative for Remote Access and Business Continuity

Providing remote access to corporate resources for business continuity and disaster recovery scenarios has evolved in the past few years. For many enterprises, SSL VPNs are the ideal technology platform for remote access. However, SSL VPNs alone do have some limitations, and desktop virtualization options are available that warrant attention.

Essential Strategies for Laptop Encryption Projects
Essential Strategies for Laptop Encryption Projects

Laptop encryption is an extremely important security project that realistically should be undertaken by every organization that uses these extremely portable computers. A number of factors exist that will influence this decision and therefore must be carefully considered. Making the right decisions will allow the enterprise to achieve the most security, both today and tomorrow, for the fewest...

Five Defining Factors of Vista Migration
Five Defining Factors of Vista Migration

Microsoft released its Windows Vista operating system at the tail end of 2006. Many organizations opted to wait until Microsoft released Service Pack 1 for Vista, before considering adoption. On the eve of SP1’s general release, Info-Tech queried early adopters about the motivating factors for Windows Vista adoption. Understand the factors that are influential to peer organizations before...

Get the Knack of Cisco's NAC
Get the Knack of Cisco's NAC

Cisco’s Network Admission Control (NAC) is an integral component of the Cisco Self-Defending Network strategy. It provides access, endpoint, and network security through either a comprehensive framework or standalone appliance. Enterprises considering implementing Cisco NAC must evaluate their existing infrastructure to see if it can support this comprehensive NAC framework.

IDP: A Three-Step Decision to Deployment
IDP: A Three-Step Decision to Deployment

Intrusion Detection and Prevention (IDP) systems can be valuable security tools. Getting the most out of one requires careful implementation, which in turn requires a significant amount of planning. Understanding how to deploy sensors, where to place them, and how to monitor for alerts are three elements essential to a successful IDP implementation.

IDP Total Cost of Ownership Calculator
IDP Total Cost of Ownership Calculator

Intrusion Detection and Prevention (IDP) systems are an invaluable component of the security toolbox. While firewalls lock the doors, IDP systems act as network burglar alarms when the door is bypassed. The ITA Premium IDP Total Cost of Ownership Calculator can be used to determine the approximate Total Cost of Ownership (TCO) of an IDP implementation according to various models.

Premium IDP Deployment Decision Guide
Premium IDP Deployment Decision Guide

Intrusion Detection and Prevention (IDP) systems are complex security tools that cannot just be bought and installed. To be effective, a significant amount of planning must be invested before systems can even be purchased. This tool can help in this process. Essentially, this decision guide can be used to determine how many IDP sensors are appropriate for a given enterprise and where those...

Realize the Cost Savings and Benefits of SSL VPNs
Realize the Cost Savings and Benefits of SSL VPNs

Enterprises that need to provide secure network connectivity for remote employees, guests, partners, and contractors should evaluate SSL VPN solutions. For new VPN remote access deployments, or upgrading existing IPSec or PPTP VPN implementations, SSL VPN technology provides the most attractive TCO of all currently available remote access solutions.

Shift to IP Surveillance Calls for More IT Accountability
Shift to IP Surveillance Calls for More IT Accountability

With more organizations migrating from legacy Closed Circuit TV (CCTV) security monitoring to IP-based video surveillance, the IT function is taking on an increasingly critical role when it comes to physical security. To minimize the operational impact on IT, prepare for future changes by working closely with facilities teams towards an appropriate solution.

Top-Down Planning for Effective IT Security
Top-Down Planning for Effective IT Security

Many enterprises complicate business-critical application security by failing to identify and apply suitable end-to-end security measures on a per application basis. IT executives should consider using a top-down approach to security based on information derived from corporate security policy, business application importance, and potential liability.

Deploy Tiered Anti-Malware Tools to Cut Enterprise Threats
Deploy Tiered Anti-Malware Tools to Cut Enterprise Threats

Even though malware has been surpassed as the most significant threat that enterprises face, it has not been eliminated and continues to grow. Enterprises must remain vigilant when it comes to protecting themselves from this threat. To achieve the needed protection, thorough planning and careful deployment of a set of tiered tools must be undertaken.

A Checklist for PCI Compliance

Complying with the Payment Card Industry (PCI) Data Security Standard (DSS) is mandatory for all merchants and service providers. The process for...

Building a Secure E-Mail Gateway

Securing the e-mail gateway is the most effective option for protecting the network from malicious code. Take steps today to avoid headaches tomorrow.

Data Classification Guide

For enterprises to be able to properly retain and secure their information assets, they must first classify them to establish relative value. Once...

Fighting Click Fraud

Almost 15% of all clicks on online ads are a result of click fraud, costing the enterprise money without providing any benefit. Unfortunately, click...

Hinder Web Server Attacks: Mask HTTP Headers

Attacks against enterprise Web servers often need to know the type and version of Web server software installed. Web servers often broadcast this...

Include Remote Connectivity in Business Continuity Planning

Providing remote connectivity for key users is an essential component of any complete business continuity plan. Evaluate the existing plan to ensure...

IP Surveillance: Prepare for New Demands on Network Operations

An IP-based surveillance deployment introduces new challenges for IT leaders, particularly in the area of network management. Engage network teams in...

SIM-plify Enterprise Security Management

Security Information Management (SIM) improves enterprise security operations by integrating with all aspects of the infrastructure and gathering...

Virtual Desktops Reduce Branch Office IT Burden

Virtual Desktop Infrastructure (VDI) has the potential of making branch office computing much easier to manage. Multi-site enterprises stand to...

Successfully make the key technology acquisition decisions for your organization. Choose the right products and negotiate the best deal.

Compare - Product Comparison

Intrusion Detection & Prevention Appliances
Intrusion Detection & Prevention Appliances

Intrusion Detection and Prevention (IDP) is an essential weapon in an organization’s IT security arsenal. However, knowing exactly which solution to choose for the organization can be a complex issue. This comparison of ten top solutions simplifies that process by outlining the features to look for and indicating key decision making criteria.

Security Information Management Solutions
Security Information Management Solutions

Though generally being pitched at larger enterprises, Security Information Management (SIM) solutions have definite value for mid-market companies. Selecting the right solution from those available requires thorough understanding of enterprise needs and goals to ensure alignment with tool capabilities. While ArcSight and Symantec are the clear winners in this comparison, few of the evaluated...

New SSL Support Accelerates WAN Optimization Market

A general lack of support for Secure Sockets Layer (SSL) traffic acceleration has slowed the penetration of WAN optimization appliances into...

Evaluate - Product Evaluation

Intrusion Detection & Prevention Appliances: Cisco's IPS 4200 Series
Intrusion Detection & Prevention Appliances: Cisco's IPS 4200 Series

The Info-Tech Research Group recently completed a comparison of eleven top Intrusion Detection and Prevention (IDP) appliances. One of the solutions that achieved Competitor Zone placement is Cisco’s IPS 4200 Series. A deeper evaluation of this product examines its specific strengths and weaknesses to determine to what degree it would make a good choice for an organization implementing an IDP...

Intrusion Detection & Prevention Appliances: Forescout's ActiveScout
Intrusion Detection & Prevention Appliances: Forescout's ActiveScout

The Info-Tech Research Group recently completed a comparison of ten top Intrusion Detection and Prevention (IDP) appliances. One of the solutions that achieves Competitor Zone placement is ForeScout’s ActiveScout. A deeper evaluation of this product examines its specific strengths and weaknesses to determine to what degree it would make a good choice for an organization implementing an IDP...

Intrusion Detection & Prevention Appliances: Intrusion's SecureNet
Intrusion Detection & Prevention Appliances: Intrusion's SecureNet

The Info-Tech Research Group recently completed a comparison of ten top Intrusion Detection and Prevention appliances. One of the solutions that achieves Competitor Zone placement is Intrusion’s SecureNet. A deeper evaluation of this product examines its specific strengths and weaknesses to determine to what degree it would make a good choice for an organization implementing an IDP solution.

Intrusion Detection & Prevention Appliances: Juniper Networks' IDP
Intrusion Detection & Prevention Appliances: Juniper Networks' IDP

The Info-Tech Research Group recently completed a comparison of ten top Intrusion Detection and Prevention (IDP) appliances. One of the solutions that achieves Competitor Zone placement is Juniper Networks' IDP. A deeper evaluation of this product examines its specific strengths and weaknesses to determine to what degree it would make a good choice for an organization implementing an IDP solution.

Intrusion Detection & Prevention Appliances: NFR Security's Sentivist
Intrusion Detection & Prevention Appliances: NFR Security's Sentivist

The Info-Tech Research Group recently completed a comparison of ten top Intrusion Detection and Prevention (IDP) appliances. One of the solutions that achieves Competitor Zone placement is NFR Security’s Sentivist. A deeper evaluation of this product examines its specific strengths and weaknesses to determine to what degree it would make a good choice for an organization implementing an IDP...

Intrusion Detection & Prevention Appliances: NitroSecurity's NitroGuard IPS
Intrusion Detection & Prevention Appliances: NitroSecurity's NitroGuard IPS

The Info-Tech Research Group recently completed a comparison of ten top Intrusion Detection and Prevention (IDP) appliances. One of the solutions that achieves Competitor Zone placement is NitroSecurity’s NitroGuard Intrusion Prevention System (IPS). A deeper evaluation of this product examines its specific strengths and weaknesses to determine to what degree it would be a good choice for an...

Intrusion Detection & Prevention Appliances: Radware's DefensePro
Intrusion Detection & Prevention Appliances: Radware's DefensePro

The Info-Tech Research Group recently completed a comparison of ten top Intrusion Detection and Prevention (IDP) appliances. One of the solutions that achieves Competitor Zone placement is Radware’s DefensePro. A deeper evaluation of this product examines its specific strengths and weaknesses to determine to what degree it would make a good choice for an organization implementing an IDP solution.

Intrusion Detection & Prevention Appliances: Sourcefire's Intrusion Sensor
Intrusion Detection & Prevention Appliances: Sourcefire's Intrusion Sensor

The Info-Tech Research Group recently completed a comparison of ten top Intrusion Detection and Prevention (IDP) appliances. One of the solutions that achieves Competitor Zone placement is Sourcefire’s Intrusion Sensor. A deeper evaluation of this product examines its specific strengths and weaknesses to determine to what degree it would make a good choice for an organization implementing an IDP...

Intrusion Detection & Prevention Appliances: Top Layer's IPS 5500
Intrusion Detection & Prevention Appliances: Top Layer's IPS 5500

The Info-Tech Research Group recently completed a comparison of ten top Intrusion Detection and Prevention (IDP) appliances. One of the solutions that achieves Competitor Zone placement is Top Layer’s IPS 5500. A deeper evaluation of this product examines its specific strengths and weaknesses to determine to what degree it would make a good choice for an organization implementing an IDP solution.

Intrusion Detection & Prevention Appliances: McAfee's IntruShield
Intrusion Detection & Prevention Appliances: McAfee's IntruShield

The Info-Tech Research Group recently completed a comparison of ten top Intrusion Detection and Prevention (IDP) appliances. One of the solutions that achieves Leader Zone placement is McAfee’s IntruShield. A deeper evaluation of this product examines its specific strengths and weaknesses to determine to what degree it would make a good choice for an organization implementing an IDP solution.

Intrusion Detection & Prevention Appliances: TippingPoint's IPS
Intrusion Detection & Prevention Appliances: TippingPoint's IPS

The Info-Tech Research Group recently completed a comparison of ten top Intrusion Detection and Prevention (IDP) appliances. One of the solutions that achieves Leader Zone placement is TippingPoint’s Intrusion Prevention System (IPS). A deeper evaluation of this product examines its specific strengths and weaknesses to determine to what degree it would make a good choice for an organization...

Security Information Management Solutions: ArcSight ESM
Security Information Management Solutions: ArcSight ESM

For organizations looking to implement a full-featured Security Information Management (SIM) solution, ArcSight ESM is difficult to beat. Though the company is smaller, it is well focused and has a solid ability to deliver. The product itself is feature-rich, highly scalable, and part of a well-designed and integrated family of products.

Security Information Management Solutions: CA Security Command Center
Security Information Management Solutions: CA Security Command Center

For organizations looking to implement a broadly capable Security Information Management (SIM) solution, CA’s Security Command Center makes a solid choice. The company is well established and the product is capable, though the solution is held back due to a high price.

Security Information Management Solutions: IBM Tivoli Security Operations Manager
Security Information Management Solutions: IBM Tivoli Security Operations Manager

For organizations that already use Tivoli software and are looking to implement a Security Information Management (SIM) solution, Tivoli Security Operations Manager (TSOM) makes a solid choice. For all others, it is acceptable at best. While the product itself is not the highest regarded solution, the company’s size and stability alone mean the solution will maintain viability.

Security Information Management Solutions: Intellitactics Security Manager
Security Information Management Solutions: Intellitactics Security Manager

Organizations looking to implement a Security Information Management (SIM) solution should consider Intellitactics’ Security Manager cautiously. While the product offers good pricing and solid capabilities, the risks of its low market penetration may make it inappropriate for some enterprises.

Security Information Management Solutions: netForensics nFX Open Security Platform
Security Information Management Solutions: netForensics nFX Open Security Platform

Though netForensics nFX Open Security Platform (nFX OSP) is an established and mature product, it is difficult to recommend it given the greater applicability shown by its competition in the marketplace. Those looking for a high-end solution would be better served investigating an alternate solution.

Security Information Management Solutions: NetIQ Security Manager
Security Information Management Solutions: NetIQ Security Manager

While NetIQ is an established and well funded company, it has relatively poor focus in the Security Information Management (SIM) market. Furthermore, its Security Manager product simply has too many negatives to be recommended. Those looking for a SIM solution would be better served with an alternate tool.

Security Information Management Solutions: Novell Sentinel
Security Information Management Solutions: Novell Sentinel

For enterprises looking to implement a full featured Security Information Management (SIM) solution, Novell Sentinel is a viable choice. Though there may be concerns about the stability of the company, Novell appears to have turned the corner and the solution itself is both mature and capable of high levels of performance.

Security Information Management Solutions: Symantec Security Information Manager
Security Information Management Solutions: Symantec Security Information Manager

For any enterprise planning to implement Security Information Management (SIM), Symantec’s Security Information Manager represents a very good choice. The solution is feature rich, attractively priced, and will serve enterprises of every of size. The present diffusion of company focus and the fact that the solution is only in its second revision are the only things keeping this tool from being...

Security Information Management Solutions: TriGeo Security Information Management
Security Information Management Solutions: TriGeo Security Information Management

For organizations looking to implement a simple SIM solution, TriGeo Security Information Management is ideal. The small size of the company does raise some concerns, but the clear focus of the solution on the mid-market and the excellent price point makes it a great choice for smaller enterprises.

Data, Not Platforms, the Focus of Symantec Security 2.0

Symantec recently announced its new initiative, Security 2.0, which targets consumers and enterprises. At the enterprise, Security 2.0 is about...

Network Chemistry Helps Secure the Mobile Edge

Network Chemistry's RFprotect Endpoint is not a silver bullet, but it helps security-conscious enterprises get one step closer to securing the mobile...

Protect Data in Flight with Symantec Information Foundation

As the threat landscape changes, the security solutions that the enterprise deploys must change as well. With threats now targeting enterprise data...

Symantec Heats Up Its Core Offerings

With Symantec Endpoint Protection, Symantec is moving beyond basic anti-virus protection for the enterprise’s servers and workstations into what it...

Take Route1 to Mobile Worker Bliss

The popularity of remote working continues to increase due to the infrastructure savings that it can impart. All is not rosy, however, as security...

Select - Selection Advice

Managed IDP Evaluation Questionnaire
Managed IDP Evaluation Questionnaire

When comparing specific Managed Security Services Providers (MSSPs) price should be one of the last factors considered as it’s often a case of “you get what you pay for.” Info-Tech’s ITA Premium “Managed IDP Evaluation Questionnaire” is a document that outlines imperative questions to ask of MSSPs when evaluating potential partners.

Managed Security Services Providers: Don't Let Price Dictate Your Decision
Managed Security Services Providers: Don't Let Price Dictate Your Decision

Using a Managed Security Services Provider (MSSP) for Intrusion Detection and Prevention (IDP) services can be a cost-effective choice when compared to a self-managed infrastructure. When comparing specific providers however, price should be one of the last factors considered as it’s often a case of “you get what you pay for.” Other criteria become far more important once the decision to use an...

Vendor Landscape: Inject the Right Anti-Virus Solution
Vendor Landscape: Inject the Right Anti-Virus Solution

No matter how large or small the enterprise, anti-virus (AV) is a solution that must be deployed. Even though the market is commoditized, sufficient variability exists between the available products for every enterprise to choose the one most appropriate to its needs. Weighing features, platform coverage, and price is essential to that choice.

Vendor Landscape: Wireless Intrusion Detection/Prevention Systems
Vendor Landscape: Wireless Intrusion Detection/Prevention Systems

With the rapid proliferation of Wireless LANs (WLAN) in the enterprise, the demand for Wireless Intrusion Detection/Prevention Systems (WIPS) is growing in kind. Enterprises considering augmenting the security features of the existing WLAN with a pure-play WIPS should scrutinize vendor technology partnerships as well as features and functions.

Caymas Systems: Integrating Capabilities Yields Better Security

Network Access Control is a hot topic in the IT security world. Building upon that already potent technology, Caymas Systems has added Identity...

Policy Compliance Tools Essential for Regulated Enterprises

Policy Compliance Management (PCM) is designed to allow enterprises to efficiently determine and demonstrate their policy compliance posture for...

Unmanaged Mobile Storage Device Encryption a Big Mistake

Free, localized data encryption solutions for mobile storage devices should not be used in place of managed, enterprise-wide solutions. Problems...

Optimize your IT department for maximum efficiency and productivity.

Implement - Implement & Integrate

Better Security Starts with Implementing a Better Password Policy
Better Security Starts with Implementing a Better Password Policy

Passwords. Just saying the word invariably makes both users and administrators cringe. Whether they arise from forgotten passwords, compromised passwords, weak passwords or a number of other issues, problems exist. The most important step in resolving these issues is using a rigorous password policy.

Endpoint Security: When Models Compete, Do We All Win?
Endpoint Security: When Models Compete, Do We All Win?

Endpoint security has become the new frontier in protecting IT assets from vulnerabilities and threats. A number of competing, yet eerily similar, models have been proposed by some of the biggest names in IT to address this issue. Ensure appropriate alignment of security spending by understanding the principles of endpoint security.

Four Steps for Implementing a Security Policy
Four Steps for Implementing a Security Policy

Creating a formal enterprise security policy can be a lot of work, but until that policy is implemented, it will provide no benefit. While that implementation process can be time-consuming, it does not have to be overly complex. Make clear decisions now to save hours of aggravation later.

Implement Virtual Desktop Infrastructure for Remote Access and Business Continuity
Implement Virtual Desktop Infrastructure for Remote Access and Business Continuity

Historically, delivering virtual desktops to remote users required a separate connectivity and virtualization infrastructure, but that is starting to change. VMware recently announced its VMware Desktop Manager (VDM) add-on to its Virtual Desktop Infrastructure (VDI) product offering, which will help ease implementation headaches.

Security Policy Implementation Guide
Security Policy Implementation Guide

Creating a security policy can be a lot of work, but until that policy is implemented, it will provide no benefit. While that implementation process can be time-consuming, it does not have to be overly complex. Use this tool to determine the order with which changes should be implemented.

When Creating Security Policies, Use a Structured Approach
When Creating Security Policies, Use a Structured Approach

An enterprise security policy is a document of too much importance to be without. It defines not only the overall stance that the enterprise will take in protecting its assets, but also the methods it will use to enforce that stance. The creation of such a document can be a time consuming process. By first developing a framework, under which the policy creation will occur, the work can be...

Deploying PKI in a Microsoft Environment
Deploying PKI in a Microsoft Environment

Public Key Infrastructure (PKI) is an important encryption technology as it ensures trust between unknown parties. It also allows the enterprise a greater level of control over internal encryption processes. Though long considered scary, implementing a PKI does not have to be complicated due to the inherent facility within Microsoft Windows Server 2003. Using these guidelines, any enterprise can...

Active Directory Topology: Seeing the Trees in the Forest

Implementing a properly designed Active Directory infrastructure requires careful and thoughtful planning. Understanding the differences between...

Establishing Secure Wireless with IEEE 802.11i

The U.S. National Institute of Standards and Technology (NIST) released "Establishing Wireless Robust Security Networks: A Guide to IEEE 802.11i" in...

How to Build a Secure DMZ

A De-Militarized Zone (DMZ) on the corporate network is a necessity for enterprises hosting public-facing servers. Building a DMZ is relatively easy...

Protect Clients and the Enterprise: Implement a Strong Data Security Policy

Compliance protocols and heightened consumer awareness have emphasized the importance of data protection, and yet we often hear about a significant...

Secure Your IP Telephony Deployment: Control Network Access

Security planning and preparation for an enterprise IP telephony deployment can be overwhelming, and potentially very costly. Focus initial security...

Secure Your IP Telephony Deployment: Protect the Perimeter

Due to the damaging consequences of phone service interruptions, enterprises deploying IP Telephony (IPT) must further elevate their existing...

Up to 30% of Handheld Devices Lost: Implement Data Protection Now

As handheld data devices such as the BlackBerry and the Treo become more common, managing and protecting the data stored on them becomes a primary...

Operate - Operate & Optimize

Hatch a Patch Plan to Keep IPT Deployments Secure
Hatch a Patch Plan to Keep IPT Deployments Secure

Given the frequency with which vendors can release critical fixes, a structured approach to applying new firmware and software updates within an enterprise IP Telephony (IPT) deployment is essential. Protect against IPT vulnerabilities with a comprehensive patch management plan.

Tiered Data Center Organization Enhances Security and Performance
Tiered Data Center Organization Enhances Security and Performance

Businesses continue to benefit by offering shared access data centers to partners, suppliers, and clients. The issue in this method of organization is ensuring that each category of user has access only to appropriate and authorized data. Create a tiered data center structure to provide physical and logical layering and to offer efficiencies and security that more distributed structures do not...

Active Directory Topology: Cultivating Forests

Using multiple forests in an Active Directory (AD) implementation adds complexity and cost. Ensure they’re employed for the right reasons and in the...

A Process for Protecting "Remote" Information

The White House recently released a memo that admonished agency directors to "safeguard our information assets while using information technology."...

Autumn Is Ripe for Directory Harvest Attacks

Although the media hype over spam has subsided in 2006, spam still accounts for as much as 60% to 80% of all e-mail traffic. A tactic often used by...

Build Security Documents the Right Way

Developing a comprehensive and cohesive set of security documents is an essential task for every enterprise. Even those that have such documents can...

Get the Most Out of Windows Software Update Services

Updating enterprise systems incorrectly can have a negative impact greater than the threat the patch means to prevent. Windows Software Update...

How to Build a Secure FTP Server

Building a File Transfer Protocol (FTP) server is a relatively straightforward process in most cases. Ensuring the FTP server is secure is another...

How to Secure Windows Remote Access

SSL encrypted VPNs, Remote Web Workplace, Outlook Web Access and Remote Desktop Protocol provide remote access for millions of workers. However, the...

Info-Tech's Acceptable Use Policy for Removable Media

Employees everywhere routinely use USB-based memory devices and other removable media types such as CDs and DVDs to store data, back it up, and move...

National Vulnerability Database: A Valuable Security Resource

The National Vulnerability Database (NVD) is a free search engine provided by the National Institute of Standards and Technologies (NIST) containing...

Protect Employees from Wi-Fi Hotspot Vulnerabilities

The lure of cheap or free Wi-Fi access from the local coffee shop is often too much to resist for increasingly mobile employees. But these easy...

Refresh Your Internet Acceptable Use Policy

All enterprises should guide the productive use of Internet services through an Internet Acceptable Use Policy. Keep the Policy up-to-date to ensure...

Untangle the Gateway to Improve Security

Enterprise IT security is an issue that all organizations should be taking seriously. For those that feel they either don’t have the money or the...

Manage - Management & Staffing

Assigning Dedicated Security Roles within Your IT Group
Assigning Dedicated Security Roles within Your IT Group

As the importance of IT security continues to grow, every enterprise will benefit from assigning dedicated security responsibilities. Recognizing which skills are required and the order in which they are needed is essential to building the security team in the most efficient and cost-effective manner.

Mandate Security Training to Safeguard Your Mobile Fleet
Mandate Security Training to Safeguard Your Mobile Fleet

Providing the appropriate employees with mobile devices and remote access capabilities typically has a positive effect on workforce productivity and overall business operations. However, a growing fleet of mobile devices operating outside of the enterprise perimeter can represent a significant security concern. Establish a high level of mobile security awareness across the user base to minimize...

Know Data Breach Laws by State

Identity theft costs consumers and businesses nearly $60 billion per year in the US alone. New laws aimed at reducing the impact of identity theft...

Perform Background Checks According to Best Practices

Screening employees and performing background checks is an important step in the recruitment process, especially for IT positions where individuals...

Protecting the Executive Suite from Corporate Espionage

US enterprises lost approximately $100 billion from the theft of trade secrets last year, with over half of the losses coming from small and...

Use This Free Trial to Build Better Security Documents

While creating a complete set of security documents is not necessarily a difficult job, it can be time consuming and, for those with minimal...