- What is SharePoint 2010? Vision and Reality
view comments - Myths & Realities of Drupal
view comments - Knowledge Management in 2012? Probably Dead
view comments - iPad 3 vs. New Samsung Tablet: War Starts in February
view comments - iPad 3 to be Unveiled by Apple in Early March
view comments - 5 Signs Your Company Doesn't Get Social Business
view comments - 5 Critical Steps to SharePoint Information Architecture Planning
view comments - Knowledge Management Meets Social Business: KM is Dead, Long Live KM!
view comments
GRC Roll Up: Compliance gets DUSTy, RSA and VMWare Offer Help
Compliance, compliance, compliance. It's not that companies don't want to be compliant. They do. It's more that there are many things that complicate the process, like vendors with too much access to private information and virtual environments. Two recent surveys highlight these issues.
Outside Vendors Create Inside Challenges
A survey conducted by Goodwin Procter and the International Association of Privacy Professionals (IAPP) found that 60 percent of information privacy professionals say their organizations have more than 10 vendors with access to personal information.
Because of many new state rules, like those in Massachusetts, which can impose significant requirements on entities possessing personal information of state residents, companies are facing some challenges complying with data security rules.
And it isn't cheap. The survey also showed that complying with the new regulations is costing 33 percent of respondents more than US$ 50,000, with another 12 percent of those surveyed saying their organizations have spent between US$ 10,000 and US$ 50,000 and 44 percent spending more than 100 hours in compliance activities.
Mobile Security Goes to DUST
The Compliance Research Group (CRG), an industry analyst firm focused on IT risk management and compliance, has developed a new mobile security model to help organizations define and manage compliance requirements for wireless devices and services.
The DUST Model, as it is referred to, includes Devices, Users, Sessions, Transactions and provides guidelines for complete wireless security for corporate IT and vendor community.
There's no denying that access to enterprise computing networks via remote smartphones is growing and the technology supporting it needs to be secure. The DUST Model aims to provide just that.
In a layered approach, it boasts being the first end-to-end model for mobile security and strongly asserts that the mobile environment cannot be fully secured without protecting its four major elements.
Five Ways to Control Virtual Environments
So now that you're struggling to reign in access your vendors have and manage the security of your mobile environments, it can feel like you're fighting an uphill battle. Fortunately, RSA and VMware are here to help.
The security division of EMC and the global leader in virtualization solutions has recently released five best practices for locking down virtual environments and meeting compliance requirements.
The best practices address the intersection of compliance and security and work to "see good, strong, auditable controls that provide both" in a virtualized environment. A very brief overview of the five steps include:
- Platform-hardening: Configure the virtualization platform, both the hypervisor and administrative layer, with secure settings, eliminate unused components and keep up-to-date on patches.
- Configuration and change management: Extend your current change and configuration management processes and tools to the virtual environment, as well.
- Administrative access control: Server administrators should have control over virtual servers and network administrators, over virtual networks, and need to be trained in virtualization software in order to avoid misconfiguration of systems.
- Network security and segmentation: Deploy virtual switches and virtual firewalls to segment virtual networks, and use your physical network controls in the virtual networks as well as change management systems.
- Audit logging: Monitor virtual infrastructure logs and adapt automated tools and SIEM systems to integrate logs from both environments.
Featured Events View all
| Add event
|
RSS
- Feb 22, 2012 – Intelligent Content Palm Springs 2012
- Feb 26, 2012 – SPTechCon - Sharepoint Conference San Francisco 2012
- Feb 28, 2012 – (Webinar) How to Build Great Mobile Websites
- Mar 6, 2012 – Get Social with Microsoft & Telligent in Dallas
- Mar 8, 2012 – Get Social with Microsoft & Telligent in New York
Who's Hiring? View all
| Post a job
|
RSS
- Web Content Manager in Newport Beach at Orange County Museum of Art
- Principal Business Consultant in Paris at Saba
- Director of Customer Success Management in Nova Scotia at Radian6
- Software Engineer -- Media Solutions in Bucharest at Adobe
- Technical Writer in Charleston at Blackbaud
- Interaction Designer in Maryland at Inmedius
- Project Manager in London at Brandworkz
- Sales Director, Consumer Electronics at Synacor

Receive
the Free CMSWire Newsletter
Email It