<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.91">
<channel>
<title><![CDATA[whitepapers.msexchange.org/Security/Firewalls]]></title>
<description><![CDATA[A Firewall is a piece of hardware and/or software which functions in a networked environment to prevent some communications forbidden by the security policy, analogous to the function of firewalls in building construction. A firewall is also called a Border Protection Device (BPD), or packet filter in BSD contexts. A firewall has the basic task of controlling traffic between different zones of trust.]]></description>
<link>http://whitepapers.msexchange.org/security/security/</link>
<item>
<title><![CDATA[Leveraging Automation to Quickly Reveal Vulnerabilities]]></title>
<link>http://whitepapers.msexchange.org/whitepaper218/</link>
<pubDate>2007-04-16 22:07:10</pubDate>
<description><![CDATA[With web applications constantly evolving, finding vulnerabilities is a challenging, costly and time-consuming undertaking.&nbsp; Find out how Cenzic&#39;s powerful security solutions help information security teams quickly identify problems, regularly assess web application security strength and ensure regulatory compliance.]]></description>
</item>
<item>
<title><![CDATA[The Positive ROI of Managing Vulnerabilities with Automated Penetration Testing]]></title>
<link>http://whitepapers.msexchange.org/whitepaper296/</link>
<pubDate>2007-08-20 10:55:39</pubDate>
<description><![CDATA[This paper will demonstrate how real-world case studies reveal a significantly positive ROI, making the purchase decision easily justified. Since IT and security budgets are tight, to justify product acquisitions many organizations undertake an ROI analysis for new software purchases.]]></description>
</item>
<item>
<title><![CDATA[Maximizing Your Network Security Budget]]></title>
<link>http://whitepapers.msexchange.org/whitepaper464/</link>
<pubDate>2007-08-21 15:59:57</pubDate>
<description><![CDATA[Managing network vulnerabilities will be the biggest challenge for C-Level executives in the coming years. Intrusions are more frequent and more malicious, so the security of corporate networks, and therefore the security of the entire corporation are dependent on the ability to quickly identify, prioritize and remediate vulnerabilities in the network.]]></description>
</item>
<item>
<title><![CDATA[Unknown Attacks:  A Clear and Growing Danger]]></title>
<link>http://whitepapers.msexchange.org/whitepaper570/</link>
<pubDate>2007-05-07 09:06:53</pubDate>
<description><![CDATA[Unknown attacks are quickly becoming the next great information security challenge for today&#39;s organizations.  Get up to speed on what these threats really are and learn what security measures are available to keep your network safe from these attacks.]]></description>
</item>
<item>
<title><![CDATA[Intelligent Defense for Enterprise Assets: The Need for Host Intrusion Prevention]]></title>
<link>http://whitepapers.msexchange.org/whitepaper620/</link>
<pubDate>2007-06-06 09:46:51</pubDate>
<description><![CDATA[Businesses today are under intense pressure to open up their networks, comply with increasingly rigorous regulatory requirements, AND ensure their IT assets are protected from attacks. This white paper explores these security challenges and explains how host-based Intrusion Prevention Systems&nbsp; play a critical role in an organization&#39;s overall security strategy.]]></description>
</item>
<item>
<title><![CDATA[The New Threat: Attackers That Target Healthcare Organizations (And what you can do about it)]]></title>
<link>http://whitepapers.msexchange.org/whitepaper621/</link>
<pubDate>2007-06-06 09:48:04</pubDate>
<description><![CDATA[Healthcare organizations are being targeted by financially motivated attackers that steal and sell valuable data, including identities and computing resources.  This white paper defines the new threat, and outlines three important steps that providers can take to protect their critical systems.]]></description>
</item>
<item>
<title><![CDATA[On-Demand Vulnerability Management]]></title>
<link>http://whitepapers.msexchange.org/whitepaper675/</link>
<pubDate>2008-06-16 13:00:13</pubDate>
<description><![CDATA[Learn how to start your own self-auditing process by setting goals and answering key questions about your infrastructure. This podcast examines what to look for in a self-audition solution, how to use vulnerability management to ease the pain and why your software solution really matters.]]></description>
</item>
<item>
<title><![CDATA[Security Design Principles]]></title>
<link>http://whitepapers.msexchange.org/whitepaper718/</link>
<pubDate>2007-04-25 00:21:21</pubDate>
<description><![CDATA[This white paper is an overview of the Nixu Security System and the various security principles it encompasses.&nbsp; Topics discussed include security design, application security, OS hardening, patch management, and more.]]></description>
</item>
<item>
<title><![CDATA[Securing Web Applications: The Time Is Now]]></title>
<link>http://whitepapers.msexchange.org/whitepaper719/</link>
<pubDate>2007-04-16 22:08:33</pubDate>
<description><![CDATA[Enterprises need to utilize software testing that can automatically review applications for security problems. This document examines the market drivers and technology associated with software security code review products and discusses how Cenzic is addressing this urgent need.]]></description>
</item>
<item>
<title><![CDATA[There's a Hole in Your Network: Vulnerability Management Is No Mystery]]></title>
<link>http://whitepapers.msexchange.org/whitepaper723/</link>
<pubDate>2008-06-16 13:01:13</pubDate>
<description><![CDATA[Learn how vulnerability management allows you to keep on top of these problems by identifying an organization&#39;s greatest security vulnerabilities and proactively recommending fixes.]]></description>
</item>
<item>
<title><![CDATA[Cenzic:  Application Security for Financial Institutions]]></title>
<link>http://whitepapers.msexchange.org/whitepaper768/</link>
<pubDate>2007-04-16 22:06:05</pubDate>
<description><![CDATA[The Cenzic Hailstorm&reg; solution helps financial institutions comply with GLBA and other laws by automating risk assessment, checking for vulnerability to the injection of malicious code into Web servers, automating the testing of code and key controls during the software development process, and helping them respond to new vulnerabilities in the software development lifecycle.]]></description>
</item>
<item>
<title><![CDATA[Dude!  You Say I Need an Application Layer Firewall?!]]></title>
<link>http://whitepapers.msexchange.org/whitepaper956/</link>
<pubDate>2008-01-28 14:05:23</pubDate>
<description><![CDATA[This industry white paper takes the mystery out of the key differences in the main classes of firewall architectures. It was independently written by Marcus J. Ranum, a world-renowned expert on security system design and implementation. It includes fundamental lessons about building application layer firewalls, technical examples, and concludes with predictions about the future of firewall technology.]]></description>
</item>
<item>
<title><![CDATA[Selecting the Right Host Intrusion Prevention System: 12 Key Questions to Ask]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1110/</link>
<pubDate>2007-06-06 09:47:04</pubDate>
<description><![CDATA[This white paper identifies twelve critical questions that organizations need to consider when selecting a Host Intrusion Prevention System product. These questions relate to protection, manageability, integration and speed.]]></description>
</item>
<item>
<title><![CDATA[Solving the Firewall/NAT Traversal Issue of SIP]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1115/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Session Initiation Protocol (SIP) represents the third wave of Internet usage after SMTP (email) and HTTP (Web). Download this free guide now and learn why all firewalls will need to be SIP capable in order to support the wide-scale deployment of enterprise person-to-person communications.]]></description>
</item>
<item>
<title><![CDATA[Intrusion Defense: Is Your Castle Protected?]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1209/</link>
<pubDate>2007-10-04 12:16:10</pubDate>
<description><![CDATA[Read this interesting comparison about designing an intrusion defense strategy that identifies the value of business processes, and implements appropriate strategies to protect these systems using a layered defense approach is not only a good security practice, but also a regulation in many cases.]]></description>
</item>
<item>
<title><![CDATA[Vulnerability Management 101: What’s a Risk and How Can I Mitigate as Many as Possible?]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1210/</link>
<pubDate>2007-10-04 12:16:53</pubDate>
<description><![CDATA[What is the difference between a risk, a threat, a vulnerability and an exploit? Which product or solution can be employed to address my institution&rsquo;s information security and compliance needs? This paper provides some clarity on the first question, and in the process, it should help to offer an answer to the second question, one of aligning concerns with solutions with vulnerability management.]]></description>
</item>
<item>
<title><![CDATA[Malicious Software Defense: Have We Moved Beyond Anti-Virus and Spyware Protection Software?]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1212/</link>
<pubDate>2007-10-04 12:16:23</pubDate>
<description><![CDATA[With the decrease in the total number of viruses, some have theorized that the need for virus protection is becoming less and less necessary. The purpose of this paper is to help individuals understand the scope of the problem, and specific strategies available to combat this continually changing threat.]]></description>
</item>
<item>
<title><![CDATA[The Book On Malicious Websites]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1213/</link>
<pubDate>2007-10-04 12:16:36</pubDate>
<description><![CDATA[Before Microsoft released Microsoft XP Service Pack 2 (SP2), most attackers would compromise a computer system by simply attacking it with known vulnerabilities or &quot;bugs&quot; that could allow the attacker to gain some level of control over the system. Newer attack methods were starting to be seen where the attacker would take advantage of vulnerabilities within the Internet browser itself.]]></description>
</item>
<item>
<title><![CDATA[Secure Remote Vendor Access to the Enterprise Data Center]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1378/</link>
<pubDate>2008-01-17 09:14:56</pubDate>
<description><![CDATA[Enabling IT equipment vendors to perform remote service on your data centers helps maximize uptime and lower TCO&mdash;but at what risk? Dial-up modems and VPNs introduce security vulnerabilities and lack sufficient auditing capabilities&mdash;making it virtually impossible to track external access and maintain data center security. Download this white paper to learn how you can manage security risks, lower service-related costs, achieve regulatory and internal compliance, and more.]]></description>
</item>
<item>
<title><![CDATA[Top 10 Strategies to Fortify Your IT Infrastructure]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1619/</link>
<pubDate>2008-03-10 14:58:51</pubDate>
<description><![CDATA[Ten straightforward, proactive strategies to optimize your computers, network and systems for their best possible performance -- ensuring that your IT operation doesn&#39;t fail.]]></description>
</item>
<item>
<title><![CDATA[eConceal: a Futuristic Firewall]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1663/</link>
<pubDate>2007-12-12 10:46:42</pubDate>
<description><![CDATA[A Firewall is designed to prevent unauthorized access to a computer or network that is connected to the Internet. Firewall software provides stealth capability to your computer on the network, hiding it from hackers who scour the Internet looking for vulnerable computers that they can gain access to.]]></description>
</item>
<item>
<title><![CDATA[A Layered Approach to Securing Remote Maintenance Consoles]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1777/</link>
<pubDate>2008-06-26 13:16:42</pubDate>
<description><![CDATA[Availability and security of networks at remote locations are tied together. Due to requirements to keep the network operating, you need fast access to equipment in case of an outage or problem.&nbsp; This white paper discusses a layered approach to securing your system while maintaining the highest possible efficiency.]]></description>
</item>
<item>
<title><![CDATA[The Distributed Enterprise: Access and Management of Remote Office IT Infrastructure]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1778/</link>
<pubDate>2008-06-26 13:17:32</pubDate>
<description><![CDATA[While the proliferation of branch and remote offices is a positive sign of company growth, it can be a challenge for IT staffers. While many IT staffers use remote access software to diagnose and repair branch office problems, these tools are only useful if the OS and network are functioning. If the network or OS is down, additional costs in travel, time, and lost business might be incurred.]]></description>
</item>
<item>
<title><![CDATA[Security for the Wireless Network]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1793/</link>
<pubDate>2008-06-17 13:49:18</pubDate>
<description><![CDATA[Wireless is becoming less an option and more of a standard corporate communication strategy.&nbsp; Learn how to keep to keep it secure with this white paper. ]]></description>
</item>
<item>
<title><![CDATA[Unified Threat Management: How to Stop Spyware, Spam, Viruses, and Other Malicious Attacks]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1794/</link>
<pubDate>2008-06-17 13:49:27</pubDate>
<description><![CDATA[Strong network security is multi-layered security. This white paper shows you how to ensure your network has defenses from all forms of malware.]]></description>
</item>
<item>
<title><![CDATA[Intelligent Layered Security: True Zero Day Protection from Known and Unknown Threats]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1795/</link>
<pubDate>2008-06-17 13:48:37</pubDate>
<description><![CDATA[The biggest differentiator in network security solutions is the ability to proactively protect the network from the latest threats. This white paper lays out the strategy for having the right kind of defenses in place as new attacks emerge.]]></description>
</item>
<item>
<title><![CDATA[Extending Robust UTM Protection to the Edges of a Network]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1796/</link>
<pubDate>2008-06-17 13:48:21</pubDate>
<description><![CDATA[Read how one international company was able to ensure that their remote offices had the same level of comprehensive protection as the corporate headquarter.]]></description>
</item>
<item>
<title><![CDATA[Protecting a Large Distributed School Network from Without and Within]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1797/</link>
<pubDate>2008-06-17 13:49:08</pubDate>
<description><![CDATA[Schools have stringent demands placed on them when it comes to protecting their networks and the students in their care. Learn how this school district got exactly what it needed for complete protection.]]></description>
</item>
<item>
<title><![CDATA[Producing Your Network Security Policy]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1798/</link>
<pubDate>2008-06-17 13:48:59</pubDate>
<description><![CDATA[Get sound advice from the network security experts at WatchGuard on how to easily build and maintain a network security policy. ]]></description>
</item>
<item>
<title><![CDATA[Building a Threat Model for Small and Medium Sized Businesses]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1880/</link>
<pubDate>2008-02-06 18:58:37</pubDate>
<description><![CDATA[It is important for businesses to have a plan in place that addresses the changing threat landscape.&nbsp; This podcast discusses various items for businesses to consider when developing an IT threat model. ]]></description>
</item>
<item>
<title><![CDATA[Lock Down Applications for PCI DSS Compliance]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1947/</link>
<pubDate>2008-03-28 12:56:24</pubDate>
<description><![CDATA[The Payment Card Industry Data Security Standard requires merchants and transaction processors to protect customer data, and firewalls play a major role in the process.&nbsp; This paper was written by Matt Sarrello, CISSP, contributing editor at Ziff Davis Enterprise and Michael Steinhart, senior editor at Ziff Davis Enterprise.]]></description>
</item>
<item>
<title><![CDATA[The Right Tool for the Right Job: An Application Security Tools Report Card]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2431/</link>
<pubDate>2008-07-22 09:31:23</pubDate>
<description><![CDATA[During the 80s, war dialing and phone phreaking were the attacks that garnered all the headlines. In the 90s it was all about web defacement and the ubiquitous email virus. The last seven years have given rise to identity data theft and privacy concerns. For the past twenty years, organizations have focused on protecting the network; but in the last ten years it has become clear that the core threat is not, nor really ever was, access to the network. ]]></description>
</item>
<item>
<title><![CDATA[The Greatest Risk to Your Website: 30% of Database-Driven Sites Vulnerable to SQL-Injection]]></title>
<link>http://whitepapers.msexchange.org/whitepaper3370/</link>
<pubDate>2008-09-08 18:26:53</pubDate>
<description><![CDATA[Let&rsquo;s assume for a moment that you have your firewall configuration dialed in impeccably, that your patchmanagement server never rests, and that your state-of-the-art IDS lets you sleep peacefully at night, as it continuouslyidentifies any irregularities from the network&rsquo;s accepted traffic patterns. Even your web-server contains no knownvulnerabilities, and it is responsibly segmented from the internal network and into a distinct security zone.]]></description>
</item>
<item>
<title><![CDATA[The Extraordinary Failure of Anti-Virus Technology: Why Whitelisting Succeeds Where AV Has Failed]]></title>
<link>http://whitepapers.msexchange.org/whitepaper3479/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Anti-virus technology fails to prevent computers from virus infections. And because it fails, it inadvertently assists many security woes that plague the computer population. Fortunately, whitelisting technology has emerged in recent years. Whitelisting technology takes a different approach to the malware problem, recording all valid programs and preventing others from executing. Because of this approach, it can be and is used to prevent other ills, such as spyware, adware, unlicensed software or any other kind of unauthorized software. Whitelisting can be applied to device control as well, which prevents the attaching of unauthorized devices to corporate PCs and laptops.]]></description>
</item>
<item>
<title><![CDATA[UK - Government Connect Secure Extranet (GCSx)]]></title>
<link>http://whitepapers.msexchange.org/whitepaper3498/</link>
<pubDate>2008-09-29 11:26:48</pubDate>
<description><![CDATA[Get the facts you need to know about how the collection, management and analysis of log data are integral to meeting many GCSx requirements. Read this whitepaper to learn more&hellip;]]></description>
</item>
<item>
<title><![CDATA[How to disappoint your HIPAA auditors and gain the respect of your board of directors]]></title>
<link>http://whitepapers.msexchange.org/whitepaper3548/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[With HIPAA audits now randomized, you must be prepared for them every day. And with state regulations requiring compliance-breach reporting, you must become your own auditor. HIPAA is the Health Insurance Portability and Accountability Act, the 1996 federal regulation that mandated health-data privacy.This regulation requires compliance by all insurers and health care providers, including physician&rsquo;s offices, hospitals, health plans, employers, public health authorities, life insurers, clearinghouses, billing agencies, information systems vendors, service organizations, and universities.But that&rsquo;s not all.]]></description>
</item>
<item>
<title><![CDATA[Meet PCI Compliance using Security Information and Event Management (SIEM)]]></title>
<link>http://whitepapers.msexchange.org/whitepaper3578/</link>
<pubDate>2008-10-03 12:06:03</pubDate>
<description><![CDATA[Simply deploying a security solution cannot guarantee meeting every Payment Card Industry (PCI) requirement in full. This whitepaper discusses the challenges of PCI compliance and how security information and event management (SIEM) provides the data visibility, log management, end-point security and active response needed to demonstrate and meet each of the 12 PCI compliance requirements.]]></description>
</item>
</channel>
</rss>
