<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.91">
<channel>
<title><![CDATA[whitepapers.msexchange.org/Security/Security Policies]]></title>
<description><![CDATA[A Security Policy is a plan of action for tackling security issues, or a set of regulations for maintaining a certain level of security. It can span anything from the practices for securing a single computer, to building/premises security, to securing the existence of an entire nation-state.]]></description>
<link>http://whitepapers.msexchange.org/security/security/</link>
<item>
<title><![CDATA[Leveraging Automation to Quickly Reveal Vulnerabilities]]></title>
<link>http://whitepapers.msexchange.org/whitepaper218/</link>
<pubDate>2007-04-16 22:07:10</pubDate>
<description><![CDATA[With web applications constantly evolving, finding vulnerabilities is a challenging, costly and time-consuming undertaking.&nbsp; Find out how Cenzic&#39;s powerful security solutions help information security teams quickly identify problems, regularly assess web application security strength and ensure regulatory compliance.]]></description>
</item>
<item>
<title><![CDATA[Cenzic Software:  Identity Theft Laws And Application Security]]></title>
<link>http://whitepapers.msexchange.org/whitepaper219/</link>
<pubDate>2007-04-16 22:05:40</pubDate>
<description><![CDATA[The Cenzic Hailstorm&reg; solution helps companies comply with AB 1950, allowing companies to use automated processes to manage their security. Hailstorm is a key tool for preventing breaches.]]></description>
</item>
<item>
<title><![CDATA[3 Reasons to Archive Email]]></title>
<link>http://whitepapers.msexchange.org/whitepaper240/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Compliance, capacity management and e-policy enforcement. Which factors are driving email archiving at your organization? And how do you pick a solution that solves your specific problems without breaking the bank? There are many internal and external forces driving the need to archive.]]></description>
</item>
<item>
<title><![CDATA[Compliance Multi-Tasking: Today's Security Priority]]></title>
<link>http://whitepapers.msexchange.org/whitepaper311/</link>
<pubDate>2008-02-22 14:22:33</pubDate>
<description><![CDATA[Driven by increasing regulatory scrutiny and the need to protect key corporate assets, concerns about compliance and data leakage have risen to the top of the priority list for today&#39;s corporate executives. This paper discusses multiple policies, procedures and processes corporations must consider to remain secure and compliant. ]]></description>
</item>
<item>
<title><![CDATA[Content Security: Blocking Spam and Unwanted Traffic]]></title>
<link>http://whitepapers.msexchange.org/whitepaper427/</link>
<pubDate>2007-04-30 12:37:08</pubDate>
<description><![CDATA[The Internet and email have stimulated huge productivity gains for employees. Workers quickly and easily access volumes of research on the Web and correspond with a mouse click. Unfortunately, businesses taking advantage of these tools are increasingly faced with daily onslaughts of spam and unwanted Web traffic.]]></description>
</item>
<item>
<title><![CDATA[Controlling the Use of Instant Messaging and Peer-to-Peer Applications]]></title>
<link>http://whitepapers.msexchange.org/whitepaper428/</link>
<pubDate>2007-04-24 13:36:31</pubDate>
<description><![CDATA[Use of instant messaging applications-like AOL Instant Messenger, Yahoo! Messenger, MSN Messenger and ICQ-and peer-to-peer applications has grown significantly. Although the benefits of real-time communication offer a productivity benefit to corporate environments, instant messaging and peer-to-peer applications add significant vulnerabilities and risks to an enterprise&#39;s security posture.]]></description>
</item>
<item>
<title><![CDATA[Single Sign-On / Focal Point Evaluator's Guide]]></title>
<link>http://whitepapers.msexchange.org/whitepaper485/</link>
<pubDate>2007-04-25 12:38:30</pubDate>
<description><![CDATA[To successfully deploy Single Sign-On today, most organizations have a set of key requirements that must be met. Here are some tips on how focal Point can help organizations seeking Single Sign-On meet those requirements.]]></description>
</item>
<item>
<title><![CDATA[FISMA Compliance: Making the Grade]]></title>
<link>http://whitepapers.msexchange.org/whitepaper538/</link>
<pubDate>2008-06-16 12:59:21</pubDate>
<description><![CDATA[A Qualys Guide to Measuring Risk, Enforcing Policies, and FISMA compliance regulations.]]></description>
</item>
<item>
<title><![CDATA[E-Policy Best Practices Guide]]></title>
<link>http://whitepapers.msexchange.org/whitepaper605/</link>
<pubDate>2007-04-30 13:26:15</pubDate>
<description><![CDATA[Download this information-packed white paper by Nancy Flynn, Executive Director of the ePolicy Institute, for a no-nonsense look at the business risks and legal liabilities associated with employee misuse of the Internet, email, instant messaging (IM), and peer-to-peer (P2P) file-sharing technology. ]]></description>
</item>
<item>
<title><![CDATA[Fighting the Hidden Dangers of Internet Access]]></title>
<link>http://whitepapers.msexchange.org/whitepaper606/</link>
<pubDate>2008-02-22 15:12:15</pubDate>
<description><![CDATA[Download this white paper from St. Bernard Software to read about a variety of contemporary, Internet-borne threats that are making it foolhardy for any business to provide unfettered Internet access for its users.]]></description>
</item>
<item>
<title><![CDATA[Compliance in the Mobile Enterprise]]></title>
<link>http://whitepapers.msexchange.org/whitepaper613/</link>
<pubDate>2007-04-30 11:35:38</pubDate>
<description><![CDATA[This paper provides guidance on how companies should rethink their existing management and security strategy to effectively secure mobile solutions in the workforce, over a wide array of devices, connections and applications. It details why mobile security must be included as a mission critical component of any enterprise strategy and implemented on a pro-active basis before any major security breach has the opportunity to negatively affect the enterprise. ]]></description>
</item>
<item>
<title><![CDATA[Bringing UNIX/Linux Networks into Sarbanes-Oxley Act]]></title>
<link>http://whitepapers.msexchange.org/whitepaper614/</link>
<pubDate>2007-04-30 11:45:49</pubDate>
<description><![CDATA[This document demonstrates how Symark PowerPassword-UME and PowerBroker work in tandem to protect the integrity of data across heterogeneous UNIX/Linux systems to help bring your system into compliance with FDA Regulation 21 CFR Part II requirements.]]></description>
</item>
<item>
<title><![CDATA[Controlling, Delegating, Logging and Auditing Root Actions with Symark PowerBroker]]></title>
<link>http://whitepapers.msexchange.org/whitepaper615/</link>
<pubDate>2007-09-11 12:40:55</pubDate>
<description><![CDATA[The purpose of the document is to demonstrate the value of Symark PowerBroker as a tool for eliminating or reducing risk in environments where information security and risk avoidance are considered important.]]></description>
</item>
<item>
<title><![CDATA[PCI Compliance: Are You Onboard?]]></title>
<link>http://whitepapers.msexchange.org/whitepaper629/</link>
<pubDate>2008-03-28 13:00:32</pubDate>
<description><![CDATA[This paper covers the basic requirements of PCI, with a focus on the administrative and technical elements of the program. It also reviews the validation requirements of the standard and potential sanctions for failure to comply.]]></description>
</item>
<item>
<title><![CDATA[Tokens Aren't Always the Answer: 4 Cases for Identity-Based Solutions]]></title>
<link>http://whitepapers.msexchange.org/whitepaper635/</link>
<pubDate>2008-02-22 14:00:41</pubDate>
<description><![CDATA[Authentication technologies such as tokens and smart cards help meet the challenges of protecting sensitive data and securing application access. This white paper presents four cases in which an identity-based solution provides a compelling, low-cost alternative or complement to strong authentication technologies.]]></description>
</item>
<item>
<title><![CDATA[Total Data Protection for the Mobile Workforce]]></title>
<link>http://whitepapers.msexchange.org/whitepaper638/</link>
<pubDate>2007-06-06 09:54:31</pubDate>
<description><![CDATA[In this modern business environment, data assets are increasingly vulnerable as mobile computing has become ever more widespread. Click here to download information on how SafeGuard Easy implements and enforces IT security policies at a low total cost of ownership. ]]></description>
</item>
<item>
<title><![CDATA[A Virtual Hard Drive That's Like an Electronic Vault For Your Confidential Files]]></title>
<link>http://whitepapers.msexchange.org/whitepaper642/</link>
<pubDate>2007-06-06 09:50:09</pubDate>
<description><![CDATA[The success of an information security technology relies upon user acceptance. If users don&#39;t use the technology, the data will become vulnerable. Read why SafeGuard PrivateDisk is easy to use and accepted by users as well as administration alike. ]]></description>
</item>
<item>
<title><![CDATA[SafeGuard SecurE-mail Gateway: The Intelligent Software for Email Security]]></title>
<link>http://whitepapers.msexchange.org/whitepaper644/</link>
<pubDate>2007-06-06 09:53:16</pubDate>
<description><![CDATA[Current studies show that less than 10 percent of electronic mail traffic is encrypted. Even when encryption capability exists, most organizations do not or cannot enforce security policies and rely too heavily on individual users to manually encrypt each message.]]></description>
</item>
<item>
<title><![CDATA[On-Demand Vulnerability Management]]></title>
<link>http://whitepapers.msexchange.org/whitepaper675/</link>
<pubDate>2008-06-16 13:00:13</pubDate>
<description><![CDATA[Learn how to start your own self-auditing process by setting goals and answering key questions about your infrastructure. This podcast examines what to look for in a self-audition solution, how to use vulnerability management to ease the pain and why your software solution really matters.]]></description>
</item>
<item>
<title><![CDATA[Network Faxing and the Health Insurance Portability and Accountability Act (HIPAA)]]></title>
<link>http://whitepapers.msexchange.org/whitepaper679/</link>
<pubDate>2007-06-06 09:26:12</pubDate>
<description><![CDATA[Easily implemented and integrated with electronic medical record systems, network fax servers can play a valuable role in supporting HIPAA objectives, offering a standardized, enterprise-wide faxing solution, and helping to maintain a high standard of security, efficiency and organization.]]></description>
</item>
<item>
<title><![CDATA[Reduce the Risk of Costly Data Breaches:  Three Pillars of Data Protection]]></title>
<link>http://whitepapers.msexchange.org/whitepaper691/</link>
<pubDate>2007-12-10 11:52:00</pubDate>
<description><![CDATA[Iron Mountain Digital advocates Three Pillars of Data Breach Protection to serve as a guide for customers establishing a PC security program: Policy Management and Control; Threat Monitoring and Response; and Data Backup and Restoration. This paper provides an overview of PC encryption and how to address the Three Pillars of Data Breach Protection.]]></description>
</item>
<item>
<title><![CDATA[Securing Your Apache Web Server with a thawte Digital Certificate]]></title>
<link>http://whitepapers.msexchange.org/whitepaper704/</link>
<pubDate>2007-04-29 16:25:23</pubDate>
<description><![CDATA[Find out how to test, purchase, install and use a thawte SSL web server certificate on your Apache web server with our step-by step guide. Throughout the guide, best practices for setup are highlighted to help you ensure efficient ongoing management of your digital certificates.]]></description>
</item>
<item>
<title><![CDATA[Securing Your Microsoft IIS Web Server with a thawte Digital Certificate]]></title>
<link>http://whitepapers.msexchange.org/whitepaper705/</link>
<pubDate>2008-02-22 13:56:42</pubDate>
<description><![CDATA[Find out how to test, purchase, install and use a thawte SSL web server certificate on your Microsoft IIS web server with our step-by -step guide. Throughout the guide, best practices for setup are highlighted to help you ensure efficient ongoing management of your digital certificates.]]></description>
</item>
<item>
<title><![CDATA[Automated Penetration Testing: Completing the Vulnerability Management Framework]]></title>
<link>http://whitepapers.msexchange.org/whitepaper707/</link>
<pubDate>2007-04-13 13:41:05</pubDate>
<description><![CDATA[Recent regulatory  additions require that companies take proactive measures like penetration  testing to enforce data privacy and integrity.&nbsp; By deploying a distributed model  companies can execute testing from different security levels which is important  in challenging posture based on level of access. ]]></description>
</item>
<item>
<title><![CDATA[Securing Web Applications: The Time Is Now]]></title>
<link>http://whitepapers.msexchange.org/whitepaper719/</link>
<pubDate>2007-04-16 22:08:33</pubDate>
<description><![CDATA[Enterprises need to utilize software testing that can automatically review applications for security problems. This document examines the market drivers and technology associated with software security code review products and discusses how Cenzic is addressing this urgent need.]]></description>
</item>
<item>
<title><![CDATA[How One Company Conquered the Audit Challenge]]></title>
<link>http://whitepapers.msexchange.org/whitepaper724/</link>
<pubDate>2008-06-16 12:59:53</pubDate>
<description><![CDATA[The Marine Corps Community Services (MCCS) manages a global network that serves Marines and their families. MCCS chose a managed service to conduct comprehensive vulnerability assessments and prioritize patches and fixes.]]></description>
</item>
<item>
<title><![CDATA[Symantec Backup Exec 11d for Windows Servers: New Encryption Capabilities]]></title>
<link>http://whitepapers.msexchange.org/whitepaper736/</link>
<pubDate>2007-06-06 09:46:15</pubDate>
<description><![CDATA[Security and compliance risks are greater than ever, and businesses depend on their data being protected when stored internally and taken offsite. New encryption capabilities offered by Backup Exec 11d for Windows Servers offer secure protection from unauthorized access. Learn more about encryption capabilities in Backup Exec 11d.]]></description>
</item>
<item>
<title><![CDATA[Privacy, Compliance, and International Data Flows]]></title>
<link>http://whitepapers.msexchange.org/whitepaper759/</link>
<pubDate>2007-04-13 11:55:58</pubDate>
<description><![CDATA[Mandatory compliance requirements often vary or conflict. Discover the major issues and appropriate actions organizations must take today to protect the privacy of information and meet legal and contractual requirements.]]></description>
</item>
<item>
<title><![CDATA[Leveraging Managed Service to Automate Security Assessment]]></title>
<link>http://whitepapers.msexchange.org/whitepaper769/</link>
<pubDate>2008-03-05 10:46:20</pubDate>
<description><![CDATA[With web applications constantly evolving, finding vulnerabilities is a challenging, costly and time-consuming undertaking.&nbsp; The solution is automated security assessment products that leverage stateful processing to comprehensively examine web applications and reveal vulnerabilities in hours rather than weeks.&nbsp; Find out how Cenzic&#39;s ClickToSecure solution can help you secure your applications.]]></description>
</item>
<item>
<title><![CDATA[IBM DB2 Anonymous Resolution: Knowledge Discovery without Knowledge Disclosure]]></title>
<link>http://whitepapers.msexchange.org/whitepaper802/</link>
<pubDate>2007-06-06 09:31:02</pubDate>
<description><![CDATA[This white paper will examine the potential of a technological breakthrough to reduce trust-based risks and change the way organizations reach a harmonious balance between consumer privacy and information sharing. ]]></description>
</item>
<item>
<title><![CDATA[IBM's Banking Data Warehouse and Basel II]]></title>
<link>http://whitepapers.msexchange.org/whitepaper806/</link>
<pubDate>2007-06-06 09:31:37</pubDate>
<description><![CDATA[This white paper will outline the components of the Banking Data Warehouse (BDW) and how they assist financial institutions to address the data modeling and data consolidation issues relating to the Basel II Capital Accord.&nbsp;]]></description>
</item>
<item>
<title><![CDATA[What's Missing from SEM? Security Management is More than Event Management]]></title>
<link>http://whitepapers.msexchange.org/whitepaper813/</link>
<pubDate>2007-04-13 11:57:12</pubDate>
<description><![CDATA[This white paper identifies what is required for a comprehensive and integrated security management solution and examines the difference between SEM, SIM and SIEM and the challenges of enterprise level security monitoring.]]></description>
</item>
<item>
<title><![CDATA[The Integration of Information Security, Integrated Systems Security & Physical Security]]></title>
<link>http://whitepapers.msexchange.org/whitepaper835/</link>
<pubDate>2007-02-21 11:37:15</pubDate>
<description><![CDATA[The single most important trend in security in the next ten years will be the integration of various security elements such as information security, physical security and integrated systems security into a single security function.]]></description>
</item>
<item>
<title><![CDATA[Best Practices for Wireless Network Security and Sarbanes-Oxley Compliance]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1083/</link>
<pubDate>2007-06-06 09:55:53</pubDate>
<description><![CDATA[This white paper will explore what security challenges wireless networks present, suggest best practices to ensure Wireless LAN security, and demonstrate how AirDefense Enterprise, a Wireless Intrusion Detection and Prevention System, can help you define, monitor and enforce your wireless security policy. ]]></description>
</item>
<item>
<title><![CDATA[3 Steps for Bullet-Proof Wireless LAN Security & Management]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1085/</link>
<pubDate>2008-02-22 14:09:57</pubDate>
<description><![CDATA[This paper outlines the specific elements of wireless LAN security (perimeter control, access control, date protection, and monitoring) and WLAN management (configuration, fault diagnostics, network usage, and policy enforcement). Reader will gain a keen understanding of how to effectively lockdown a wireless LAN and manage it for peak performance.]]></description>
</item>
<item>
<title><![CDATA[Wireless Security: Ensuring Compliance with HIPAA, GLBA, SOX, DoD 8100.2 & Enterprise Policy]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1087/</link>
<pubDate>2007-06-06 09:56:35</pubDate>
<description><![CDATA[This white paper is designed to guide network administrators and security managers to design, implement, and enforce wireless LAN security policies that enable every organization to fully reap the benefits of wireless LANs without experiencing undue management pains and security holes.]]></description>
</item>
<item>
<title><![CDATA[PCI DSS made easy: Addressing the Payment Card Industry (PCI) Data Security Standard]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1131/</link>
<pubDate>2008-03-28 13:02:47</pubDate>
<description><![CDATA[This white paper examines the requirements to adhere to the Payment Card Industry Data Security Standard (PCI DSS), the implications of non-compliance and how effective event log management and network vulnerability management can help achieve compliance.]]></description>
</item>
<item>
<title><![CDATA[Pod Slurping: An Easy Technique for Stealing Data]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1153/</link>
<pubDate>2007-06-14 14:21:23</pubDate>
<description><![CDATA[In this white paper, we explore how the uncontrolled use of portable storage devices such as iPods, USB sticks, flash drives and PDAs, coupled with data theft techniques such as &lsquo;pod slurping&rsquo;, can lead to major security breaches.]]></description>
</item>
<item>
<title><![CDATA[The Threats Posed By Portable Storage Devices]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1154/</link>
<pubDate>2007-06-14 14:22:33</pubDate>
<description><![CDATA[This white paper examines the nature of the threat that devices such as iPods, USB sticks, flash drives and PDAs present and the counter-measures that organizations can adopt to eliminate them.]]></description>
</item>
<item>
<title><![CDATA[FISMA Prescriptive Guide]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1174/</link>
<pubDate>2008-04-03 11:34:28</pubDate>
<description><![CDATA[Discover how to achieve and maintain FISMA compliance to ensure security of systems and data.]]></description>
</item>
<item>
<title><![CDATA[Automated Event Log Management for PCI DSS Compliance]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1182/</link>
<pubDate>2008-03-28 12:33:29</pubDate>
<description><![CDATA[This white paper highlights why organizations need to implement event log auditing as an integral part of their security policy to meet industry standards such as the Payment Card Industry Data Security Standard (PCI DSS).]]></description>
</item>
<item>
<title><![CDATA[Where Online Hackers Are Headed in 2007]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1211/</link>
<pubDate>2007-10-04 12:17:06</pubDate>
<description><![CDATA[Click here and get a head start on these Hackers by learning how they are turning their attention to new ways to deliver viruses, crash unsuspecting users&rsquo; computers, and steal social security numbers, passwords, bank account numbers, etc.]]></description>
</item>
<item>
<title><![CDATA[UNIX Host Access Management with CA Access Control]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1239/</link>
<pubDate>2008-07-01 12:01:10</pubDate>
<description><![CDATA[UNIX and Linux systems have inherent security issues that pose high risk to the business objectives of complying with regulations and data protection.&nbsp; To reduce security risks, you need full superuser containment and the ability to enforce strict access control to critical system resources through centralized and automated policy management across different platforms.]]></description>
</item>
<item>
<title><![CDATA[Guide to Effectively Remediate Network Vulnerability and Policy Compliance]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1300/</link>
<pubDate>2008-06-16 12:59:31</pubDate>
<description><![CDATA[Consistent, ongoing execution of vulnerability management and policy compliance is difficult, if not impossible to do on a manual basis. There are simply too many &quot;moving parts&quot; to juggle and act on in a timely and cost-effective manner. This guide provides a step-by-step guide for automating the vulnerability and compliance workflow process.]]></description>
</item>
<item>
<title><![CDATA[LAN Security: Identity-Based Solution Guide]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1374/</link>
<pubDate>2008-02-22 15:47:30</pubDate>
<description><![CDATA[The ability to monitor, track and report usage based on actual user identity and applications provides for quicker reaction time, easier reporting for compliance, as well as more visibility into the network. Learn about a complete line of solutions for effective identity-based policy enforcement. ]]></description>
</item>
<item>
<title><![CDATA[Reducing the Burden of Administration for Email Content Control, Compliance & Policy Enforcement]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1507/</link>
<pubDate>2008-01-28 14:06:50</pubDate>
<description><![CDATA[Email compliance, security and content policy enforcement is a growing priority for all organizations.&nbsp; Email content control solutions provide real-time scanning of email traffic and provide the foundation for proactive enforcement of regulatory and corporate policies.&nbsp; However, the administrative burden associated with policy management imposed by most such products is significant. ]]></description>
</item>
<item>
<title><![CDATA[Minimizing the Burden of PCI Compliance: A New Approach to Credit Card Encryption]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1674/</link>
<pubDate>2008-03-28 12:59:31</pubDate>
<description><![CDATA[This paper describes a new approach to managing encrypted data that significantly strengthens an organization&#39;s security posture, while minimizing the cost and effort of PCI compliance. Read this white paper and find out more about how to comply with PCI compliance requirements.]]></description>
</item>
<item>
<title><![CDATA[NAC: Managing Unauthorized Computers]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1700/</link>
<pubDate>2008-06-30 20:01:34</pubDate>
<description><![CDATA[Unauthorized endpoint computers pose significant security risks to organizations. Where underlying network-based enforcement is available, network access control (NAC) solutions provide detection and implementation of security policies to minimize these risks. However, in some environments the network cannot provide this enforcement.]]></description>
</item>
<item>
<title><![CDATA[Producing Your Network Security Policy]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1798/</link>
<pubDate>2008-06-17 13:48:59</pubDate>
<description><![CDATA[Get sound advice from the network security experts at WatchGuard on how to easily build and maintain a network security policy. ]]></description>
</item>
<item>
<title><![CDATA[Strengthening Network Security with On Demand Vulnerability Management & Policy Compliance]]></title>
<link>http://whitepapers.msexchange.org/whitepaper1998/</link>
<pubDate>2008-06-16 13:00:34</pubDate>
<description><![CDATA[Despite defensive efforts with firewalls, intrusion detection, antivirus and the like, criminals, careless employees and contractors have exposed more than 158 million digital records of consumers&#39; personally identifiable information since 2005. This security guide describes the requirements and on demand software-as-a-service (SaaS) solution called QualysGuard for effective vulnerability management and policy compliance.]]></description>
</item>
<item>
<title><![CDATA[Meeting PCI DSS Merchant Requirements with a WatchGuard Firebox]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2124/</link>
<pubDate>2008-06-17 13:48:50</pubDate>
<description><![CDATA[While some firewall companies may claim their products are &ldquo;PCI Compliant,&rdquo; there&rsquo;s no such thing. Compliance requires more than just plugging in a security appliance and calling it good: you need a network design with physical and logical boundaries that allow you to segregate and monitor your PCI-compliant operating environment.]]></description>
</item>
<item>
<title><![CDATA[Secure at the Source: Implementing Source Code Vulnerability Testing in the Development Life Cycle]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2135/</link>
<pubDate>2008-06-16 13:23:00</pubDate>
<description><![CDATA[Organizations should implement source code analysis tools as part of the software development life cycle to find and fix the highest number of security issues early in the project. This will result in a higher-quality product and lower overall application life cycle costs. Countless studies and analyst recommendations suggest the value of improving software security during the development life cycle (SDLC) rather than trying to address security vulnerabilities in software discovered after widespread adoption and deployment. ]]></description>
</item>
<item>
<title><![CDATA[The Path to a Secure Application:  A Source Code Security Review Checklist]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2136/</link>
<pubDate>2008-06-16 13:23:21</pubDate>
<description><![CDATA[The path to application security begins by rigorously testing source code for any and all vulnerabilities, to ensure the application will not compromise, or allow others to compromise, data privacy and integrity. This paper outlines the steps to secure source code development practices, and presents a source code security review checklist.]]></description>
</item>
<item>
<title><![CDATA[Trust, But Verify:  How to Manage Risk in Outsourced Applications]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2137/</link>
<pubDate>2008-06-16 13:24:00</pubDate>
<description><![CDATA[This paper will discuss the need for addressing security concerns in outsourced applications, outline a framework for addressing those concerns, explore the role of source code review to assess and certify outsourced applications, and provide a sample contract addendum for including secure code requirements in RFP&#39;s and outsourcing contracts.]]></description>
</item>
<item>
<title><![CDATA[Are Your Secrets Safe? Policy, Strategy and Technology for Ensuring Outbound Email Content Security]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2201/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Email has revolutionized how businesses communicate. But email also makes it easy to transport confidential information and valuable intellectual property outside your organization &mdash; without anyone knowing until it&#39;s too late. To combat these threats, enterprises must develop clear policies for outbound email content and should adopt technology to monitor and enforce such policies. ]]></description>
</item>
<item>
<title><![CDATA[Assessing Endpoint Security Solutions- Why Detection Rates Aren't Enough]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2284/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Evaluating the performance of competing endpoint security products is a time-consuming and daunting task. Enterprise decision-makers have to rely on independent competitive comparisons, performance benchmarks, and detection certifications, all covering different solutions and criteria, providing conflicting results.]]></description>
</item>
<item>
<title><![CDATA[Vulnerability Management for Dummies: How to Implement a Successful Vulnerability Management Program]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2468/</link>
<pubDate>2008-06-16 13:01:44</pubDate>
<description><![CDATA[As a business owner, or someone responsible for network security within your organization, you need to understand how to prevent attacks and eliminate network weaknesses that leave your business exposed and at risk. Vulnerability Management for Dummies arms you with the facts and shows you how to implement a successful Vulnerability Management program.]]></description>
</item>
<item>
<title><![CDATA[Automate Deactivation of Graduates' User Accounts]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2473/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[At the end of an academic year, many thousands of students may permanently leave a school or university system. Once these users graduate, discontinue their education, or perhaps simply move away, IT administrators are left with a huge number of accounts that must be marked as inactive and then dealt with according to system policies. ]]></description>
</item>
<item>
<title><![CDATA[IT Departments on Data Security: A Research Concepts Survey]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2494/</link>
<pubDate>2008-04-24 09:19:11</pubDate>
<description><![CDATA[A survey of 185 IT professionals finds that, although computer and data security are high priorities, they are surprisingly unprepared to prevent data breaches and computer theft. 1 out of 4 organizations surveyed had a data breach in the past year. Preventative measures are found to be consistently undermined, with only 1 in 100 employees consistently following security policy. This white paper explores the survey findings.]]></description>
</item>
<item>
<title><![CDATA[Proactively Reduce Risk and Improve IT Security in Physical and Virtual Environments]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2532/</link>
<pubDate>2008-04-28 12:56:22</pubDate>
<description><![CDATA[Learn more about the security risks and vulnerabilities faced by organizations, and the elements of a proactive security approach. Then find out how Tripwire helps organizations attain and maintain a good security posture using industry-leading configuration assessment and change auditing to harden systems against security breaches, automate compliance with security standards and policies, identify configuration changes, and resolve vulnerabilities.]]></description>
</item>
<item>
<title><![CDATA[Stop Spam, Viruses and Spyware: Endpoint and Perimeter Malware Guide]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2599/</link>
<pubDate>2008-05-09 10:14:24</pubDate>
<description><![CDATA[IT systems are under constant, increasingly sophisticated attack. Today&#39;s cyber criminals are using highly evolved, blended malware to access corporate and customer data at an alarming rate. Additional layers of protection at the perimeter are essential to combat the sheer volume of this increasing threat and to prevent networks from being clogged by spam.]]></description>
</item>
<item>
<title><![CDATA[State of Internet Security Report: Protecting Business Email]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2600/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Business dependence on email is greater than ever before and the volume of threats has spiked dramatically. For the SOIS report, Webroot surveyed 1,500 email security product decision makers in companies across seven countries. The report finds that close to 80% of U.S. businesses surveyed experienced a spam attack last year while half also experienced spyware, virus and phishing attacks. ]]></description>
</item>
<item>
<title><![CDATA[What's the Big Deal with Managed Security Services?]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2687/</link>
<pubDate>2008-06-11 14:54:15</pubDate>
<description><![CDATA[In this recent report, the Aberdeen Group&rsquo;s research revealed that 100% of Best-in-Class companies consume some managed security services as part of their security strategy. The most widely deployed and easiest to implement managed security service is email security. ]]></description>
</item>
<item>
<title><![CDATA[Eurekify Enterprise Role Manager for CA Identity Manager]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2699/</link>
<pubDate>2008-07-01 09:22:08</pubDate>
<description><![CDATA[Organizations are facing an explosion in the number of users of all types - employees, customers, partners and contractors - all of which need access to applications, data and other resources. While trying to provide access to the resources each user needs as quickly as possible, the organization must also ensure users do not have access to things they do not need.]]></description>
</item>
<item>
<title><![CDATA[NAC at the Endpoint: Control Your Network Through Device Compliance]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2839/</link>
<pubDate>2008-06-30 20:01:20</pubDate>
<description><![CDATA[Protecting IT networks used to be a straightforward case of encircling computers and servers with a firewall and ensuring that all traffic passed through just one gateway. However, the increase in mobile workers, numbers and type of device and the amount of non-employees requiring network access, has led to a dissolving of that network perimeter.]]></description>
</item>
<item>
<title><![CDATA[Effective Web Policies: Ensuring Staff Productivity and Legal Compliance]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2840/</link>
<pubDate>2008-06-30 20:00:52</pubDate>
<description><![CDATA[Employees increasingly expect to use the internet at work for their own personal use in return for longer hours, working from home and interrupting vacations. This has a number of security, productivity, bandwidth and legal ramifications that require organizations to create and implement a web usage policy that is backed up by effective web filtering tools.]]></description>
</item>
<item>
<title><![CDATA[Effective Email Policies: Why Enforcing Proper Use is Critical to Security]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2842/</link>
<pubDate>2008-06-30 20:00:42</pubDate>
<description><![CDATA[The unmonitored and unguarded use of email by employees poses a multitude of risks to organizations. The distribution of inappropriate or offensive content, malicious emails, and the risks of data leakage all threaten working environments, IT resources and an organization&#39;s reputation. A comprehensive, transparent and enforceable email acceptable use policy (AUP), combined with robust email security solutions, dramatically reduces exposure to these risks.]]></description>
</item>
<item>
<title><![CDATA[Stopping Data Leakage- Exploiting your Existing Security Investment]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2987/</link>
<pubDate>2008-06-24 14:47:28</pubDate>
<description><![CDATA[As attitudes to work and information continue to evolve away from those of the past, organizations are become more aware of the acute need to control the information that flows into, through and out of their networks. This paper demonstrates the need for a high-profile acceptable use policy to prevent data leakage, gives practical guidance on how to use current investments in IT security technologies at the gateway and endpoint to support this policy, and describes where new investment should realistically be made.]]></description>
</item>
<item>
<title><![CDATA[Effective Email Policies- Why Enforcing Proper Use is Critical to Security]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2988/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[The unmonitored and unguarded use of email by employees poses a multitude of risks to organizations. The distribution of inappropriate or offensive content, malicious emails, and the risks of data leakage all threaten working environments, IT resources and an organization&#39;s reputation. A comprehensive, transparent and enforceable email acceptable use policy (AUP), combined with robust email security solutions, dramatically reduces exposure to these risks.]]></description>
</item>
<item>
<title><![CDATA[Effective Web Policies- Ensuring Staff Productivity and Legal Compliance]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2989/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Employees increasingly expect to use the internet at work for their own personal use in return for longer hours, working from home and interrupting vacations. This has a number of security, productivity, bandwidth and legal ramifications that require organizations to create and implement a web usage policy that is backed up by effective web filtering tools.]]></description>
</item>
<item>
<title><![CDATA[NAC at the Endpoint- Control Your Network Through Device Compliance]]></title>
<link>http://whitepapers.msexchange.org/whitepaper2990/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Protecting IT networks used to be a straightforward case of encircling computers and servers with a firewall and ensuring that all traffic passed through just one gateway. However, the increase in mobile workers, numbers and type of device and the amount of non-employees requiring network access, has led to a dissolving of that network perimeter.]]></description>
</item>
<item>
<title><![CDATA[The Essential Elements of Secure Remote Access...without the Management Headaches]]></title>
<link>http://whitepapers.msexchange.org/whitepaper3053/</link>
<pubDate>2008-07-07 14:29:08</pubDate>
<description><![CDATA[While IPSec VPN implementation has traditionally been viewed as expensive and time-consuming for large organizations, Quocirca has found that the next generation of IPSec VPN technologies has addressed these management headaches through automation, integrated security policy management, and centralized control.]]></description>
</item>
</channel>
</rss>
