<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.91">
<channel>
<title><![CDATA[whitepapers.msexchange.org/Security/Auditing]]></title>
<description><![CDATA[An Information Technology (IT) audit or information systems (IS) audit is an examination of the controls within an entity&#39;s Information technology infrastructure. These reviews may be performed in conjunction with a financial statement audit, internal audit, or other form of attestation engagement.]]></description>
<link>http://whitepapers.msexchange.org/security/security/</link>
<item>
<title><![CDATA[Leveraging Automation to Quickly Reveal Vulnerabilities]]></title>
<link>http://whitepapers.msexchange.org/whitepaper218/</link>
<pubDate>2007-04-16 22:07:10</pubDate>
<description><![CDATA[With web applications constantly evolving, finding vulnerabilities is a challenging, costly and time-consuming undertaking.&nbsp; Find out how Cenzic&#39;s powerful security solutions help information security teams quickly identify problems, regularly assess web application security strength and ensure regulatory compliance.]]></description>
</item>
<item>
<title><![CDATA[Content Security: Blocking Spam and Unwanted Traffic]]></title>
<link>http://whitepapers.msexchange.org/whitepaper427/</link>
<pubDate>2007-04-30 12:37:08</pubDate>
<description><![CDATA[The Internet and email have stimulated huge productivity gains for employees. Workers quickly and easily access volumes of research on the Web and correspond with a mouse click. Unfortunately, businesses taking advantage of these tools are increasingly faced with daily onslaughts of spam and unwanted Web traffic.]]></description>
</item>
<item>
<title><![CDATA[Enforcing IT Change Management Policy]]></title>
<link>http://whitepapers.msexchange.org/whitepaper456/</link>
<pubDate>2008-07-10 14:28:55</pubDate>
<description><![CDATA[Discover how high-performing IT organizations are able to create a culture that supports and uses change management to their advantage, facilitating enterprise business goals.]]></description>
</item>
<item>
<title><![CDATA[Controlling, Delegating, Logging and Auditing Root Actions with Symark PowerBroker]]></title>
<link>http://whitepapers.msexchange.org/whitepaper615/</link>
<pubDate>2007-09-11 12:40:55</pubDate>
<description><![CDATA[The purpose of the document is to demonstrate the value of Symark PowerBroker as a tool for eliminating or reducing risk in environments where information security and risk avoidance are considered important.]]></description>
</item>
<item>
<title><![CDATA[Keeping Up Your SOX Compliance and Turning IT into a High Performer by Improving Change Control]]></title>
<link>http://whitepapers.msexchange.org/whitepaper630/</link>
<pubDate>2008-07-10 14:31:01</pubDate>
<description><![CDATA[This paper covers the implementation, disclosure and ongoing evaluation of internal controls for SOX compliance with a focus on the role of IT, as well as the penalties for non-compliance.]]></description>
</item>
<item>
<title><![CDATA[EvolveWare’s S2T Technology - Automated Software Analysis, Documentation & Transformation]]></title>
<link>http://whitepapers.msexchange.org/whitepaper706/</link>
<pubDate>2008-04-01 10:00:58</pubDate>
<description><![CDATA[Software analysis, documentation, migration, upgrades or replacements are daunting and risky endeavors because they are primarily manual and time-consuming. EvolveWare&rsquo;s S2T Technology provides a solution to these problems with tools that automate the process up to 90%, thus reducing the time and cost of such initiatives by as much as 40-60%.]]></description>
</item>
<item>
<title><![CDATA[Automated Penetration Testing: Completing the Vulnerability Management Framework]]></title>
<link>http://whitepapers.msexchange.org/whitepaper707/</link>
<pubDate>2007-04-13 13:41:05</pubDate>
<description><![CDATA[Recent regulatory  additions require that companies take proactive measures like penetration  testing to enforce data privacy and integrity.&nbsp; By deploying a distributed model  companies can execute testing from different security levels which is important  in challenging posture based on level of access. ]]></description>
</item>
<item>
<title><![CDATA[Securing Web Applications: The Time Is Now]]></title>
<link>http://whitepapers.msexchange.org/whitepaper719/</link>
<pubDate>2007-04-16 22:08:33</pubDate>
<description><![CDATA[Enterprises need to utilize software testing that can automatically review applications for security problems. This document examines the market drivers and technology associated with software security code review products and discusses how Cenzic is addressing this urgent need.]]></description>
</item>
<item>
<title><![CDATA[How One Company Conquered the Audit Challenge]]></title>
<link>http://whitepapers.msexchange.org/whitepaper724/</link>
<pubDate>2008-06-16 12:59:53</pubDate>
<description><![CDATA[The Marine Corps Community Services (MCCS) manages a global network that serves Marines and their families. MCCS chose a managed service to conduct comprehensive vulnerability assessments and prioritize patches and fixes.]]></description>
</item>
<item>
<title><![CDATA[Don't Dread that Network Audit: Compliance with Government Regulation and Industry Standards]]></title>
<link>http://whitepapers.msexchange.org/whitepaper725/</link>
<pubDate>2008-06-16 12:59:05</pubDate>
<description><![CDATA[Security administrators need to be more proactive about preventing attacks, making vulnerability assessments a crucial tool in their portfolio.]]></description>
</item>
<item>
<title><![CDATA[Privacy, Compliance, and International Data Flows]]></title>
<link>http://whitepapers.msexchange.org/whitepaper759/</link>
<pubDate>2007-04-13 11:55:58</pubDate>
<description><![CDATA[Mandatory compliance requirements often vary or conflict. Discover the major issues and appropriate actions organizations must take today to protect the privacy of information and meet legal and contractual requirements.]]></description>
</item>
<item>
<title><![CDATA[Cenzic:  Application Security for Financial Institutions]]></title>
<link>http://whitepapers.msexchange.org/whitepaper768/</link>
<pubDate>2007-04-16 22:06:05</pubDate>
<description><![CDATA[The Cenzic Hailstorm&reg; solution helps financial institutions comply with GLBA and other laws by automating risk assessment, checking for vulnerability to the injection of malicious code into Web servers, automating the testing of code and key controls during the software development process, and helping them respond to new vulnerabilities in the software development lifecycle.]]></description>
</item>
<item>
<title><![CDATA[The Banking Data Warehouse and the Sarbanes-Oxley Act]]></title>
<link>http://whitepapers.msexchange.org/whitepaper799/</link>
<pubDate>2007-06-06 09:33:40</pubDate>
<description><![CDATA[This white paper outlines the components of the Banking Data Warehouse (BDW) and how they assist financial institutions in addressing the data modeling and data consolidation issues relating to the SOX regulations. ]]></description>
</item>
<item>
<title><![CDATA[IBM's Banking Data Warehouse and Basel II]]></title>
<link>http://whitepapers.msexchange.org/whitepaper806/</link>
<pubDate>2007-06-06 09:31:37</pubDate>
<description><![CDATA[This white paper will outline the components of the Banking Data Warehouse (BDW) and how they assist financial institutions to address the data modeling and data consolidation issues relating to the Basel II Capital Accord.&nbsp;]]></description>
</item>
<item>
<title><![CDATA[Risk Assessment & Compliance: A Management Tool for the IT Security Infrastructure]]></title>
<link>http://whitepapers.msexchange.org/whitepaper830/</link>
<pubDate>2007-04-27 10:56:10</pubDate>
<description><![CDATA[Risk assessment is the cornerstone of security.&nbsp; The risk assessment process includes gathering information about the assets of the organizations, including all information assets, and all physical assets.]]></description>
</item>
<item>
<title><![CDATA[Going Beyond Standard Windows Auditing & Logging]]></title>
<link>http://whitepapers.msexchange.org/whitepaper841/</link>
<pubDate>2007-04-29 16:52:57</pubDate>
<description><![CDATA[In lieu of Sarbanes-Oxley, HIPAA, and other regulations, one of the main concerns in the IT industry today is security. In this white paper, we take a deeper look at the security concerns, the available solutions, their drawbacks, and a new complementary way of addressing today&#39;s security issues. ]]></description>
</item>
<item>
<title><![CDATA[Leveraging Lifecycle Management for Software and Business Adapt Ability]]></title>
<link>http://whitepapers.msexchange.org/whitepaper845/</link>
<pubDate>2007-06-27 13:33:20</pubDate>
<description><![CDATA[In this white paper, you&#39;ll learn how to clearly define business requirements, align them with testing, and evolve development processes to prevent defects. ]]></description>
</item>
<item>
<title><![CDATA[CA Access Control for Windows]]></title>
<link>http://whitepapers.msexchange.org/whitepaper866/</link>
<pubDate>2008-08-21 09:08:51</pubDate>
<description><![CDATA[Learn how CA Access Control, a independent security system, complements the native Windows operating system and can enable a strong defense-in-depth security practice for your organization.]]></description>
</item>
<item>
<title><![CDATA[Evaluating a Storage Security Solution]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1082/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Company data is vulnerable to threats from - insiders, unauthorized access to data, data backup, off-site mirroring - just to name a few. Encrypting data at rest, on tape or disk, significantly mitigates these threats. This document provides guidance into some of the factors a company should consider when evaluating storage security technology and solutions.]]></description>
</item>
<item>
<title><![CDATA[Using GFI LANguard Network Security Scanner to Secure Your Internal Network]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1148/</link>
<pubDate>2007-08-31 11:21:06</pubDate>
<description><![CDATA[This document shows you how to use GFI LANguard N.S.S. to identify vulnerabilities on your network (excerpt from manual).]]></description>
</item>
<item>
<title><![CDATA[How to Perform Network-Wide Security Event Log Management]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1150/</link>
<pubDate>2007-06-14 13:42:08</pubDate>
<description><![CDATA[]]></description>
</item>
<item>
<title><![CDATA[Configuration Audit and Control: 10 Critical Factors for CCM Success]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1200/</link>
<pubDate>2008-07-10 14:22:32</pubDate>
<description><![CDATA[In this whitepaper, you will learn how configuration audit and control can be used effectively to ensure system management productivity, and help reduce costs and sustain configuration viability within the bounds of operational, security and regulatory standards.]]></description>
</item>
<item>
<title><![CDATA[UNIX Host Access Management with CA Access Control]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1239/</link>
<pubDate>2008-08-21 09:21:51</pubDate>
<description><![CDATA[UNIX and Linux systems have inherent security issues that pose high risk to the business objectives of complying with regulations and data protection.&nbsp; To reduce security risks, you need full superuser containment and the ability to enforce strict access control to critical system resources through centralized and automated policy management across different platforms.]]></description>
</item>
<item>
<title><![CDATA[Ensure the Integrity of your Content: ProofMark System Technical Overview]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1244/</link>
<pubDate>2008-01-30 09:14:06</pubDate>
<description><![CDATA[This paper details the processes by which ProofMark tags electronic records with a self-validating cryptographic seal that acts as a &quot;tamper indicator&quot; based on a true and provable time-reference datum.&nbsp; With this it is able to provide instantaneous and irrefutable proof of authenticity, no matter where the data resides or who has controlled it. ]]></description>
</item>
<item>
<title><![CDATA[The Total Economic Impact of the Tripwire Enterprise Solution]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1248/</link>
<pubDate>2008-07-10 14:24:56</pubDate>
<description><![CDATA[Hear from a leading industry analyst how your company can quickly enjoy a substantial return on investment from implementing Tripwire&rsquo;s configuration audit and control solution.]]></description>
</item>
<item>
<title><![CDATA[e-Life Sciences 2010:  Enabling a Trusted Electronic Value Chain]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1275/</link>
<pubDate>2007-08-07 10:18:00</pubDate>
<description><![CDATA[This white paper presents a solution framework for Life Science Organizations that want to implement enterprise digital trust management to protect their electronic value chain. ]]></description>
</item>
<item>
<title><![CDATA[Understanding and Managing Security Audits]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1289/</link>
<pubDate>2007-08-17 08:41:40</pubDate>
<description><![CDATA[Better preparation means better results &ndash; Learn how to prepare for an audit; how to develop a self-audit process; how to develop a security template; and much more.]]></description>
</item>
<item>
<title><![CDATA[Practical Guide to Sarbanes-Oxley Compliance]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1292/</link>
<pubDate>2007-08-17 08:32:21</pubDate>
<description><![CDATA[Learn about the Sarbanes-Oxley regulatory background and its impact on IT departments. This document provides information pertaining to access issues, change documentation, disaster recovery planning and illustrations of key audit-ready reports.]]></description>
</item>
<item>
<title><![CDATA[Monitor System Changes And User Activity]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1371/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Learn how to meet regulatory requirements for system change and user activity monitoring with NetIQ Change Guardian for Windows, without the need for performance-hindering native auditing. ]]></description>
</item>
<item>
<title><![CDATA[Secure Remote Vendor Access to the Enterprise Data Center]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1378/</link>
<pubDate>2008-01-17 09:14:56</pubDate>
<description><![CDATA[Enabling IT equipment vendors to perform remote service on your data centers helps maximize uptime and lower TCO&mdash;but at what risk? Dial-up modems and VPNs introduce security vulnerabilities and lack sufficient auditing capabilities&mdash;making it virtually impossible to track external access and maintain data center security. Download this white paper to learn how you can manage security risks, lower service-related costs, achieve regulatory and internal compliance, and more.]]></description>
</item>
<item>
<title><![CDATA[Pre-Test DR & Business Continuity Plans]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1600/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Effective IT disaster recovery and business continuity planning is essential for every business. All businesses depend on their IT services for moment-to-moment operations. It is vital to ensure that those services are not disrupted due to any disaster. Pre-test your plans in a simulated network.]]></description>
</item>
<item>
<title><![CDATA[Effectively Delegate Administrative Privileges]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1609/</link>
<pubDate>2007-11-27 14:33:25</pubDate>
<description><![CDATA[Learn how delegating administrative privileges can aid in improving administrative productivity, system availability and security, while satisfying the demands of auditors.&nbsp; Read this new white paper from NetIQ today.]]></description>
</item>
<item>
<title><![CDATA[Email and IM Prep for Your Next Regulatory Audit]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1618/</link>
<pubDate>2008-03-10 14:53:24</pubDate>
<description><![CDATA[A millisecond of downtime can mean millions of dollars. Maintaining compliance while ensuring your firm has the required speed and uptime can be daunting. Learn what you can do with your email and instant messages to prepare for your next regulatory audit.]]></description>
</item>
<item>
<title><![CDATA[Prepare for Successful Audits: A Change Management Manager Checklist]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1749/</link>
<pubDate>2008-01-24 16:02:36</pubDate>
<description><![CDATA[This IT audit checklist guide includes advice on assessing the effectiveness of change management in a variety of areas.&nbsp;&nbsp; As companies grow more dependent on interdependent IT systems, the risks associated with untested changes in development and production environments have increased proportionately. ]]></description>
</item>
<item>
<title><![CDATA[Identifying Critical Change Control Failure Points]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1751/</link>
<pubDate>2008-01-24 16:12:27</pubDate>
<description><![CDATA[Identifying critical change control failure points in your infrastructure can help reduce the threat of costly downtime, potential security breaches, and compliance weaknesses. Read this paper for guidelines on how to identify and categorize systems that have characteristics which heighten risk. ]]></description>
</item>
<item>
<title><![CDATA[Improving SOX Compliance Efforts with Self-Service Auditing]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1753/</link>
<pubDate>2008-01-24 16:19:12</pubDate>
<description><![CDATA[This paper lays out the challenges with complying with SOX and suggests a radical solution: build a self-service, automated IT control framework in which all the information required to verify compliance is available in a single reporting system. ]]></description>
</item>
<item>
<title><![CDATA[40% PCI Non-Compliance? How to Beat The Stats Without Breaking a Sweat]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1789/</link>
<pubDate>2008-03-28 12:32:34</pubDate>
<description><![CDATA[New report issued by Fortrex, Emagined Security and Solidcore reveals the cost of PCI compliance is justified. These PCI requirements exist to protect sensitive data - yet, research indicates that these are among the least satisfied requirements across Level 1 merchants, with almost 40% non-compliance.&nbsp; ]]></description>
</item>
<item>
<title><![CDATA[Ensuring SOX Compliance via Enhanced Change Management]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1790/</link>
<pubDate>2008-01-24 16:09:39</pubDate>
<description><![CDATA[Assure SOX compliance and address key questions asked by SOX auditors with simple change management enhancement. ]]></description>
</item>
<item>
<title><![CDATA[Winning the PCI Compliance Battle: A Guide for Merchants and Member Service Providers]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1997/</link>
<pubDate>2008-06-16 13:02:30</pubDate>
<description><![CDATA[This white paper reviews the basics of PCI, including who must comply, compliance requirements, validation requirements and penalties. It also examines key things to look for when selecting a PCI network testing service and introduces QualysGuard PCI.]]></description>
</item>
<item>
<title><![CDATA[Meeting the PCI Application Security Requirements: Building Compliance In]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2134/</link>
<pubDate>2008-07-22 09:30:13</pubDate>
<description><![CDATA[The PCI DSS is demonstrably becoming a de facto standard of due care for any organization responsible for the privacy and integrity of data. The increased focus on application security in the latest revisions of the PCI DSS can be traced directly to many of the recent high profile breaches, where insecure applications have proved to be the point of access for hackers, and the source of data loss.]]></description>
</item>
<item>
<title><![CDATA[Host Access Management with CA Access Control]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2161/</link>
<pubDate>2008-03-28 18:45:48</pubDate>
<description><![CDATA[Your organization relies on servers to store and access to your most critical information resources. CA Access Control is a product that&nbsp;centralizes control and distributed enforcement of appropriate role-based access to sensitive server resources.]]></description>
</item>
<item>
<title><![CDATA[10 Reasons your RADIUS Server Needs a Refresh]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2287/</link>
<pubDate>2008-03-24 11:12:34</pubDate>
<description><![CDATA[For over a decade now, RADIUS servers have been a mainstay of dial-up and VPN access control. The rather inconspicuous RADIUS server, perhaps better known as that beige, general-purpose PC collecting dust in the corner of your data center, has proved sufficient for performing basic duties like validating passwords and granting network access. ]]></description>
</item>
<item>
<title><![CDATA[Gene Kim's Practical Steps to Mitigate Virtualization Security Risks]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2347/</link>
<pubDate>2008-07-10 14:29:08</pubDate>
<description><![CDATA[Tripwire founder/CTO Gene Kim provides seven practical steps that IT organizations can take to mitigate the unique security challenges of virtualization. While some are directed specifically at virtualized environments, many of these steps are solid best practices that apply to both physical and virtualized environments.]]></description>
</item>
<item>
<title><![CDATA[Best Practices for Audit and Compliance Reporting for IBM AS/400 (System i)]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2915/</link>
<pubDate>2008-06-19 12:28:25</pubDate>
<description><![CDATA[Compliance with regulations such as Sarbanes-Oxley, PCI, HIPAA and GLBA requires regular audit reporting against critical information technology (IT) assets. This whitepaper outlines the key items that need to be reviewed on AS/400 (System i) for both configuration data and transactional log information from the audit journal.&nbsp; The white paper also provides guidance on integrating the AS/400 with Security Information Management (SIM) solutions.]]></description>
</item>
<item>
<title><![CDATA[Managing Privileged Users on the IBM AS/400 (System i)]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2916/</link>
<pubDate>2008-06-19 12:31:52</pubDate>
<description><![CDATA[One of the most common security lapses uncovered in AS/400 (System i) audits is too many users with privileged access to data. Read this white paper to learn about managing, limiting, and auditing privileged and powerful user accounts on the AS/400 and discover answers to the following questions: What are the security exposures from powerful user accounts with SECOFR user class and special authorities such as *ALLOBJ? What are your auditors looking for? How can you configure your AS/400 system to comply with IT frameworks such as COBIT and ISO 27002 (17799)?]]></description>
</item>
<item>
<title><![CDATA[Optimizing Infrastructure Control]]></title>
<link>http://whitepapers.msexchange.org/whitepaper3064/</link>
<pubDate>2008-07-08 12:36:25</pubDate>
<description><![CDATA[This paper outlines the nature of infrastructure integrity, change auditing, and compliance solutions. It describes how an investment in configuration assessment and change auditing solutions can stabilize IT operations, lowering the operational costs associated with the IT infrastructure; be a force multiplier; and provide a solid foundation that increases the effectiveness of the investment in information security.]]></description>
</item>
<item>
<title><![CDATA[Proving Compliance with McAfee Total Protection for Data]]></title>
<link>http://whitepapers.msexchange.org/whitepaper3182/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Companies feel a sense of security from encrypting data stored on corporate systems on desktops, laptops and mobile devices. They believe this act will protect their intellectual property, and sensitive customer information will remain safe and secure from unauthorized access.&nbsp; But that is not enough. Simply encrypting this information doesn&rsquo;t help you prove compliance with external regulations or internal controls during a financial audit or legal discovery process. ]]></description>
</item>
</channel>
</rss>
