http://www.rsa.com/blog/rssfeed.aspx Speaking of Security, the RSA Blog and Podcast http://www.rsa.com/blog/ Speaking of Security is the RSA Blog and Podcast. It features a group of experts in identity management, encryption, privacy, policy, and enterprise security standards. Security http://www.rsa/blog/images/small_blog_logo.gif http://www.rsa.com/blog/ 144 36 Speaking of Security A Podcast for Security Professionals A weekly look at RSA's – and the industry's – issues-of-the-moment. RSA, The Security Division of EMC en-us no RSA, The Security Division of EMC podcast@rsa.com Copyright 2005 - 2008 RSA Security Inc. Follow-up on RSA Conferenceblog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1281Tue, 13 May 2008 00:00:00 GMTblog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1281It was another great <a href="http://www.rsaconference.com/">RSA Conference</a> this year, with interesting workshops, great exhibitor activity, informative sessions and lots of time to network with customers, partners and fellow employees. My flight was cancelled on Sunday, so I missed the <a href="http://www.projectconcordia.org/index.php/Concordia_workshop_RSA_2008_notes">Concordia Workshop</a> on Monday, but the <a href="http://projectliberty.org/news_events/events/workshop_identity_federation_web_services_happening_today_enabling_tomorrow">Liberty Alliance Workshop</a> was very interesting. <a href="http://www.geisinger.org/">Geisinger Health System</a> had a very nice presentation on how they are using federation to provide improved information to health care providers to improve patient care, particularly in emergency room visits. <b>RSA also made a number of exciting <a href="http://www.rsa.com/press_release.aspx?id=9300">announcements</a>...</b>Speaking of Security Podcast #104blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1280Mon, 12 May 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1280<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1280">Click to Listen/Download (10:14)</a><br><br clear="all" />Paul Joyal interview's the President of Corporate Integrity, <a href="http://www.corp-integrity.com/about/bio_michael_rasmussen.html" target="_blank">Michael Rasmussen</a>, about &quot;Developing a Sustainable and Cost Effective IT Compliance Program.&quot; For the companion white paper, <a href="https://www.rsa.com/go/wpt/wpindex.asp?WPID=9338" target="_blank">click here</a>. Other RSA resources on this approach can be found at <a href="https://www.rsa.com/compliance">www.rsa.com/compliance</a>.<br>Speaking of Security Podcast #103blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1279Mon, 05 May 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1279<div align="center"><a href="http://www.rsa.com/blog/blog_entry.aspx?id=1279"><img src="http://www.rsa.com/blog/bimgs/080505/may_vid_podcast.jpg" alt="Click to Play" width="340" height="289"></a></div> <br clear="all" /> <strong>EMC PowerPath Encryption with RSA</strong><P> Happy Cinco de Mayo and welcome to the latest Speaking of Security video podcast. Today Host Paul Joyal speaks with Colin Bailey of EMC and Katie Curtin-Mestre of RSA, The Security Division of EMC, about this new scalable solution that leverages RSA Key Manager for the Datacenter.<br><br></p>Is it safer to fly or drive? (and why you can't do one without the other)blog@rsa.com (Kevin Bowers)http://www.rsa.com/blog/blog_entry.aspx?id=1278Thu, 01 May 2008 00:00:00 GMTblog@rsa.com (Kevin Bowers)http://www.rsa.com/blog/blog_entry.aspx?id=1278Kevin Bowers is a Research Scientist at RSA Laboratories. Here are his views on the controversy surrounding REAL ID. What do you think? <p><hr size="1" noshade></p> I'm getting married this summer and my family will be traveling to the wedding. In order to make the trip, my parents recently renewed their passports. Not because I'm getting married at an exotic destination, but because they live in Montana and have to fly to the wedding. Like several other states, Montana has refused to comply with the requirements of the REAL ID Act of 2005. The Department of Homeland Security (DHS) had threatened to prevent residents from those states from using their state-issued driver's licenses as identification at airport security, effective May 11th. <b>As it happens, the DHS recently granted all states an extension to the May 11th deadline, allowing them additional time to become REAL ID compliant. </b>Speaking of Security Podcast #102blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1277Mon, 28 Apr 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1277<a href="http://www.rsa.com/blog/blog_entry.aspx?id=1277">Click to listen or download</a> (6:39) <br /> <br> Paul Joyal interview's RSA's Paul Davilman on What is Sarbanes-Oxley &amp; How is it Applicable to IT Security? For additional information on SOX and IT Security, <a href="http://rsa.com/node.aspx?id=3192" target="_blank">read more here</a>.<br>U.S. Congress should pass cyber-crime legislation this year -- when will the House of Representatives finally act?blog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1276Wed, 23 Apr 2008 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1276As I mentioned in a <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1236">blog post</a> in late October 2007, the IT industry and other stakeholders have been calling for the U.S. Congress to pass legislation that would help empower law enforcement to more effectively investigate and prosecute cyber criminals -- while updating penalties in U.S. criminal code so that the punishment fits the crime. <b>It's stunning to me that the Congress has not yet sent legislation to the President for his signature to address this important issue...</b> Speaking of Security Podcast #101blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1275Tue, 22 Apr 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1275<a href="http://rsa.edgeboss.net/download/rsa/2008/blogpodcasts/080421_security_podcast.mp3">Click here to download/listen</a> (11:23).<br><p> In a recent RSA Web Seminar, Juniper Networks' <a href="http://www.rsa.com/node.aspx?id=3458" target="_blank">Smitha Murthy</a> and RSA's <a href="http://www.rsa.com/node.aspx?id=2994" target="_blank">John Masotta</a> discussed the benefits of an SSL VPN and how best to secure its access with strong authentication. Hear a snippet in this week's podcast or check out the <a href="https://www.rsa.com/go/wpt/wpindex.asp?WPID=9273" target="_blank">entire replay of the event</a>.<br></p>Older and wiserblog@rsa.com (Uriel Maimon)http://www.rsa.com/blog/blog_entry.aspx?id=1274Mon, 21 Apr 2008 00:00:00 GMTblog@rsa.com (Uriel Maimon)http://www.rsa.com/blog/blog_entry.aspx?id=1274Today (the date I'm writing this entry) is my birthday. Birthdays are a time of quiet contemplation for me (and quiet desperation for my mother). As I think about the past year and the progress I've made (things are looking good for my long-term goal of spending my old age miserable and alone), I keep thinking of change and how people and things advance. The past year has shown much progress. Women have rejected me, technology products have been launched, iPhones were purchased and even the world of financial crime has not been silent. The Rock Phish group is a phishing gang believed to be based out of Russia -- and, by some accounts, is <b>responsible for roughly 50% of phishing attacks by volume</b>...RSA Conference 2008 - A Week to Rememberblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1273Thu, 17 Apr 2008 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1273I have been attending RSA Conferences since early this decade. The U.S. version of the Conference has been around since 1991 and it's grown from 50 attendees (all cryptologists) to around 17,000 participants annually from the private and public sectors including security professionals, business executives, lawyers, academics, privacy advocates, regulators, and journalists. For the first-time attendee it can be absolutely overwhelming because there are so many speakers, so many issues, so many events during the week, and if you go to the show floor, literally hundreds of organizations showing their wares. <P> Well, being a veteran RSA Conference attendee, I thought I was ready for another busy but ultimately manageable week despite the multiple commitments and responsibilities that I had to balance. <B>Well, that theory was turned on its head, starting on Sunday...</b> Speaking of Security Podcast #100!blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1272Wed, 16 Apr 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1272<div align="center"><a href="http://www.rsa.com/blog/blog_entry.aspx?id=1272"><img src="http://www.rsa.com/blog/bimgs/080416/apr_vid_podcast.jpg" alt="Click to Play" width="340" height="289"></a></div> <br clear="all" /> <strong>The Challenges of Identity Assurance with Marc Gaffan</strong><P> In Speaking of Security's blockbuster <b>100th security podcast</b> we talk to Marc Gaffan, Director Product Marketing, about Identity Assurance and its importance to enterprise-level security and compliance. <br><br></p>Your Suggestions to Transform Security from a Roadblock to a Catalyst for Business Innovationblog@rsa.com (Blog Editor)http://www.rsa.com/blog/blog_entry.aspx?id=1271Wed, 09 Apr 2008 00:00:00 GMTblog@rsa.com (Blog Editor)http://www.rsa.com/blog/blog_entry.aspx?id=1271Yesterday at the RSA Conference Art Coviello addressed how security fears have stifled innovation at organizations large and small around the world. IDG Research reports that 80 percent of IT, security, and business executives surveyed admit that their organizations have shied away from business innovation opportunities because of information security concerns. <P> RSA is committed to countering this trend by starting an industry-wide conversation about smart ways to manage information risk. As we mentioned in yesterday's blog posting, we were able to pick the brains of 10 top security executives from global enterprises in a variety of industries and get THEIR suggestions. <B>But we'd like to hear from you...</b>Secretary Michael Chertoff, Department of Homeland Security to Speak at RSA Conference Todayblog@rsa.com (Blog Editors)http://www.rsa.com/blog/blog_entry.aspx?id=1269Tue, 08 Apr 2008 08:00:00 GMTblog@rsa.com (Blog Editors)http://www.rsa.com/blog/blog_entry.aspx?id=1269His keynote will begin at 11:30 AM. Let us know if you're going to be there and leave us your impressions. Art Coviello on "Thinking Security"blog@rsa.com (Blog Editor)http://www.rsa.com/blog/blog_entry.aspx?id=1270Tue, 08 Apr 2008 00:00:00 GMTblog@rsa.com (Blog Editor)http://www.rsa.com/blog/blog_entry.aspx?id=1270This morning at Art Coviello, Executive Vice President, EMC Corporation and President, RSA, The Security Division of EMC, gave his yearly keynote at the RSA Conference in San Francisco. Art uses this venue each year to present a "state of the industry"--reviewing major security developments--and to share his ideas on where security is going in the coming year. <P> Here is a transcript of the talk: <a href="http://www.rsa.com/innovation/docs/coviellokeynote2008.pdf" target=_blank>http://www.rsa.com/innovation/docs/coviellokeynote2008.pdf</a> <P> <B>It's a good read, with a lot of interesting insights...</b>Speaking of Security Podcast #99blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1268Mon, 31 Mar 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1268<a href="http://rsa.edgeboss.net/download/rsa/2008/blogpodcasts/080331_security_podcast.mp3">Click here to download/listen</a> (11:15).<br><p> Part 2: Paul Joyal speaks with award-winning <em>USA Today</em> journalists, <a href="http://content.usatoday.com/community/tags/reporter.aspx?id=88" target="_blank">Byron Acohido</a> and <a href="http://content.usatoday.com/community/tags/reporter.aspx?id=321" target="_blank">Jon Swartz</a>. They are the co-authors of <em>Zero Day Threat: The Shocking Truth of How Banks and Credit Bureaus Help Cyber Crooks Steal Your Money and Identity</em>, which is scheduled for an April 2008 release. Byron and Jon talk about the inspiration for their book and more in part two of this two-part interview. See Byron, Jon and Paul next week at the <a href="http://www.rsaconference.com/2008/US/home.aspx" target="_blank">RSA&reg; Conference 2008</a>, registrations are still being accepted!<br> </p> The New Wave In Virtual Private Network Authenticationblog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1267Fri, 28 Mar 2008 00:00:00 GMTblog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1267While RSA, The Security Division of EMC has evolved into a broad organization focusing on Information-Centric Security through Information Risk Management, securing Virtual Private Networks (VPNs) is still a significant portion of our business. The main use case for RSA SecurID, in its various forms, continues to be supporting the needs of the mobile workforce. As organizations mature, <strong>they are now extending beyond the VPN power user to additional (and often very large) populations ...</strong>Speaking of Security Podcast #98blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1266Mon, 24 Mar 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1266<a href="http://rsa.edgeboss.net/download/rsa/2008/blogpodcasts/080324_security_podcast.mp3">Click here to download/listen</a> (10:35).<br><p>Part 1: Paul Joyal speaks with award-winning <em>USA Today</em> journalists, Byron Acohido and Jon Swartz. They are the co-authors of <em>Zero Day Threat: The Shocking Truth of How Banks and Credit Bureaus Help Cyber Crooks Steal Your Money and Identity</em>, which is scheduled for an April 2008 release. Byron and Jon talk about the inspiration for their book, the state of cybercrime, and more in part one of this two-part interview. Tune in next week for part two!<br></p>Bush Administration to set up national cyber security center; taps Silicon Valley entrepreneur to lead the groupblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1265Thu, 20 Mar 2008 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1265Another announcement related to the Bush Administration's Cyber Security Initiative is expected in the next day or so and it is likely that an entrepreneur from Silicon Valley will head a new interagency group that will coordinate cyber defenses across the federal government. As reported today by Brian Krebs of the Washington Post, "...Sources in the government contracting community said that the White House is expected to announce as early as today the selection of Rod A. Beckstrom as a top level adviser to be based in the Department of Homeland Security." <P> View <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/03/19/AR2008031903354.html?wpisrc=newsletter">Krebs' entire article</a>. <P> The Bush Administration has been ratcheting up its focus on information security over the past year, <B>but is starting to roll out its cyber security initiative...</B> Speaking of Security Podcast #97blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1264Mon, 17 Mar 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1264<a href="http://rsa.edgeboss.net/download/rsa/2008/blogpodcasts/080317_security_podcast.mp3">Click here to download/listen</a> (04:13).<br><p> Tim Mather, Chief Security Strategist for RSA Conferences, talks about the role of the Chief Security Officer and how that role might evolve in the years to come. <a href="http://www.rsaconference.com/2008/US/home.aspx">RSA&reg; Conference 2008</a> is where you can hear more from leading information security professionals at the world's largest industry conference and expo when it comes to San Francisco, CA, April 7-11. For a free RSA Conference 2008 Expo Pass, courtesy of RSA, The Security Division of EMC, email <a href="mailto:podcast@rsa.com" target="_blank">podcast@rsa.com</a> with your request before April 4 and we'll send you a special registration code.<br> </p>Speaking of Security Podcast #96blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1263Mon, 10 Mar 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1263 <a href="http://rsa.edgeboss.net/download/rsa/2008/blogpodcasts/080310_security_podcast.mp3">Click here to download/listen</a> (06:01).<br><p> <strong>What's the Buzz?</strong> <a href="http://www.rsaconference.com/2008/US/home.aspx">RSA&reg; Conference 2008</a> is the world's largest information security industry conference and expo and it comes to San Francisco, CA, April 7-11. Paul Joyal talks to Sandra Toms LaPedis, Area Vice President and General Manager of RSA Conferences, about what makes this event so special and what's new for this year's attendees. AND for a free RSA Conference 2008 Expo Pass, courtesy of RSA, The Security Division of EMC, email <a href="mailto:podcast@rsa.com" target="_blank">podcast@rsa.com</a> with your request before April 4 and we'll send you a special registration code.<br></p>Speaking of Security Podcast #95blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1262Wed, 05 Mar 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1262<div align="center"><a href="http://www.rsa.com/blog/blog_entry.aspx?id=1262"><img src="http://www.rsa.com/blog/bimgs/080305/mar_vid_podcast.jpg" alt="Click to Play" width="340" height="289"></a></div> <br clear="all" /> <strong>New Developments in Online Fraud with Joram Borenstein</strong><P> In Speaking of Security's newest video podcast we talk to Joram Borenstein, Senior Product Manager, about the latest strategies of online fraudsters. <br><br></p> Speaking of Security Podcast #94blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1261Mon, 25 Feb 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1261 <a href="http://rsa.edgeboss.net/download/rsa/2008/blogpodcasts/080225_security_podcast.mp3">Click here to download/listen</a> (07:52).<br><p> RSA, The Security Division of EMC, RSA is pleased to invite you to our first global technical user conference hosted at EMC World 2008 in Las Vegas, May 19-22, 2008. <a href="http://www.rsaxchange.com">RSA Xchange</a> brings together a rich community of like-minded security professionals with an interest in learning from each other, partners and RSA product and engineering experts. Cathy Long joins Paul Joyal to talk about this new and unique opportunity.<br></p>Speaking of Security Podcast #93blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1260Mon, 11 Feb 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1260 <a href="http://rsa.edgeboss.net/download/rsa/2008/blogpodcasts/080211_security_podcast.mp3">Click here to download/listen</a> (07:54).<br><p> UPEK&reg; Inc., a leading brand of secure biometric fingerprint solutions, <a href="http://www.upek.com/news/press/2008/02.04.08.asp">recently announced</a> a <a href="http://www.rsa.com/rsasecured/guides/solutions/UPEKSolutionsBrief.pdf">joint technology solution</a> combining the convenience and security of biometrics in millions of existing notebook computers with the market-leading strong authentication solution from RSA. Matt Buckley talks with Brian DeGonia from UPEK about this solution. <br><Br>Please note, we'll be taking a short winter break next week in honor of President's Day - but watch for our next episode on February 25.<br></p>Speaking of Security Podcast #92blog@rsa.com (Video Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1259Tue, 05 Feb 2008 00:00:00 GMTblog@rsa.com (Video Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1259<div align="center"><a href="http://www.rsa.com/blog/blog_entry.aspx?id=1259"><img src="http://www.rsa.com/blog/bimgs/080205/feb_vid_podcast.jpg" alt="Click to Play" width="340" height="289"></a></div> <br clear="all" /> <strong>RSA Channel Strategy with Joe Gabriel</strong><P> In Speaking of Security's second video podcast we talk to Joe Gabriel, Manager, Channel Marketing, about RSA's strategy for channel enablement. <br><br></p> Borderline Securityblog@rsa.com (Dr. Ari Juels)http://www.rsa.com/blog/blog_entry.aspx?id=1258Tue, 29 Jan 2008 00:00:00 GMTblog@rsa.com (Dr. Ari Juels)http://www.rsa.com/blog/blog_entry.aspx?id=1258The U.S. Passport card or <a href="http://www.uspasscard.com/">PASS (People Access Security Service)</a> card, a new travel document, is slated for issue by the federal government in the spring of this year. A poor cousin to the standard passport, it's more compact and less expensive, but valid only at land and sea points of border entry into the United States, not for air travel. The PASS card emerged as part of the <a href="http://travel.state.gov/travel/cbpmc/cbpmc_2223.html">Western Hemisphere Travel Initiative</a> (WHTI), which phases out drivers' licenses as border-crossing documents for the U.S. <P><strong> I've heard two starkly contrasting opinions on the security of the PASS card...</strong> Speaking of Security Podcast #91blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1257Mon, 28 Jan 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1257<a href="http://rsa.edgeboss.net/download/rsa/2008/blogpodcasts/080128_security_podcast.mp3" target="_blank">Click here to download/listen</a> (07:55).<br><p>Speaking of Security Blogger <a href="http://rsa.com/blog/blog.aspx?author=kline">Sean Kline</a> talks with Paul Joyal about his top 5 intriguing ideas for authentication for 2008.How to fraudulently elect a president blog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1256Wed, 23 Jan 2008 00:00:00 GMTblog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1256As most know, the United States is in the midst of primary elections for presidential candidates. I live in New Hampshire, so woke at around 5:00am a couple of Tuesdays ago eager to participate in the democratic process (I went early because I had a flight the same day to Germany...more on that later). After getting to the front of the line, the pleasant elderly volunteer proceeded to authenticate me so that I could vote. The authentication method she used was name and address. She had a three ring binder with everyone's name printed in an easily readable large font size. The only problem was that she exposed the credential type, the name and the address for me to misuse as I pleased! Now I know that I am not the first to bring this up or write about it. Even so, it boggles my mind that <strong>after having to go to the Supreme Court the last time we went through this exercise to select our president, we would not take more care with the voting process... </strong>Speaking of Security Podcast #90blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1255Mon, 21 Jan 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1255<a href="http://rsa.edgeboss.net/download/rsa/2008/blogpodcasts/080121_security_podcast.mp3" target="_blank">Click here to download/listen</a> (08:52).<br><p> Matt Buckley interviews <a href="http://www.enterprisestrategygroup.com/OurTeam/TeamBio.asp?TeamMemberID=8" target="_blank">Jon Oltsik</a>, Senior Analyst, Enterprise Strategy Group, about his paper and thoughts on an <a href="http://www.rsa.com/node.aspx?id=3151" target="_blank">information-centric security</a> architecture. <br><br></p>Speaking of Security Podcast #89blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1254Mon, 14 Jan 2008 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1254<a href="http://rsa.edgeboss.net/download/rsa/2008/blogpodcasts/080114_securitypodcast.mp3" target="_blank">Click here to listen/download</a> (09:40).<br><br>Speaking of Security Blogger <a href="http://www.rsa.com/blog/blog.aspx?author=kellogg">Shannon Kellogg</a> talks with Matt Buckley about the state of information security from a Washington, D.C. point of view. <br><br>Speaking of Security Podcast #88blog@rsa.com (Video Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1253Mon, 07 Jan 2008 00:00:00 GMTblog@rsa.com (Video Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1253<iframe src="http://flashplayer.streamos.com/flvplayer.php?url=http://rsa.edgeboss.net/flash/rsa/2008/vblog/smaller_january_vidcast.flv&autoplay=false&skin=haloSkin_3" width="600" height="300" frameborder="0" align="left" marginwidth="0"></iframe> <BR clear="all"/><P>Welcome to a new year of RSA's Speaking of Security Podcast. Today we introduce our first Video Podcast!<P> This week RSA Compliance Specialist, Dave Howell, offers his view on the future of the Payment Card Industry Data Security Standard and the evolution of online fraud. <br><br></p> Speaking of Security Podcast #87blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1252Wed, 19 Dec 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1252<a href="http://rsa.edgeboss.net/download/rsa/2007/blogpodcasts/071217_securitypodcast.mp3" target="_blank">Click here to listen/download</a> (11:15).<br><p>This is our final broadcast for 2007. This week's topic is Information Risk Management, an information-centric strategy that provides the most effective means of recognizing, assessing and mitigating the risk that information is exposed to throughout its lifecycle. Hear from a recent RSA Web Seminar conducted in collaboration with TowerGroup, on how financial institutions can leverage a sound IRM strategy. A companion <a href="https://www.rsa.com/go/wpt/wpindex.asp?WPID=8739">white paper</a> on the subject is also available.<br><br></p>Federal Information Security and Management Act -- Five Years Onblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1251Tue, 18 Dec 2007 02:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1251An anniversary recently passed amid a heightened focus in Washington, D.C. on the status of federal information security: the Federal Information Security and Management Act (FISMA) just completed its fifth year on the books as a federal law. <P> As the follow up to the Government Information Security Act of 2000, FISMA established an updated legal framework for federal information security, including baseline security standards for federal agencies. I remember that the information security community was excited about FISMA and its promise. <P> <strong>So, what's the verdict five years later? In my opinion it's a mixed bag.</strong> On one hand, FISMA has arguably increased awareness of, and focus on, federal information security...She could totally be mine...blog@rsa.com (Uriel Maimon)http://www.rsa.com/blog/blog_entry.aspx?id=1250Tue, 18 Dec 2007 00:00:00 GMTblog@rsa.com (Uriel Maimon)http://www.rsa.com/blog/blog_entry.aspx?id=1250I was sitting with my friend R. in a bar. My friend was completely ignoring me (a rather stimulating treatise on how my failure with women is caused by millions of years of human evolution. I've entitled this thesis "Nature or nurture, culture or genes: Pick any one -- or all of the above"), and was focusing on a girl on the other side of the bar. <P> "She could be your daughter," I told R. He continued ignoring me, and said, "She could totally be mine..." <P> "Perhaps, but she won't," I said. "You're 38, you have a girlfriend and you were telling me the other day you were thinking of proposing to her."... In response to &quot;Soft tokens aren't tokens at all&quot;blog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1249Tue, 11 Dec 2007 00:00:00 GMTblog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1249<i>This blog entry is in response to <a href="http://securology.blogspot.com/2007/11/soft-tokens-arent-tokens-at-all.html">this post</a> in the Securology blog.</I> <P> You raise some interesting points on which I would like to comment. First, RSA believes that there are always tradeoffs between strength of security, cost and ease of use. The key (no pun intended) is matching the right means of authentication to the right level of risk. This is why we have such a broad range of authentication types and form factors. <P> To some of your specific points, RSA SecurID hardware and software authenticators are both forms of multi-factor authentication. In the case of hardware authenticators, they are based on something you have (the physical authenticator) and something you know (your password or Personal Identification Number). <strong>Software authenticators work the same way depending on the form factor and can include other factors.</strong>... Speaking of Security Podcast #86blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1248Mon, 10 Dec 2007 17:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1248<p><a href="https://www.rsa.com/blog/podcasts/071210_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (08:39).</p><p> This week Paul Joyal speaks with Tom Corn, Vice President of Data Security Products for RSA, about Data Loss/Leakage Prevention (DLP) and RSA's approach to the issue along with how it differs from other players. <br><br></p>Top Five Intriguing Ideas for Authentication in 2008 blog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1247Mon, 10 Dec 2007 00:00:00 GMTblog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1247<OL><LI><B> Controls as part of a broader strategy</B><BR /> Organizations still make decisions on how to authenticate requests (often users) based on individual applications, infrastructure deployments or regulatory requirements. This is one of the contributors to a "quilt of security doilies", to paraphrase the CTO of a top bank who I met recently. Point security solutions have proliferated throughout organizations making it very difficult and costly to manage. In 2008, organizations will increasingly adopt frameworks like Information Risk Management to assess which threats to mitigate, inventory the types of controls (including authentication) that they need and take a more holistic approach to implementing their strategy... </LI></OL>Speaking of Security Podcast #85blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1246Mon, 03 Dec 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1246<p><a href="https://www.rsa.com/blog/podcasts/071203_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (07:15).</p><p> This week, hear from Ari Juels, <a href="http://www.rsa.com/blog/blog.aspx?author=juels">Speaking of Security blogger</a> and Chief Scientist for <a href="http://www.rsa.com/rsalabs/" target="_blank">RSA Laboratories</a>. Ari tells us about some projects that his team is working on including &quot;Proofs of Retrievability&quot; and the WARP token for wireless authentication.<br><br></p>Massive data loss by key U.K. government agency could affect millions of British citizensblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1245Mon, 26 Nov 2007 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1245Not since the infamous U.S. Veterans Administration breach, when a laptop containing information on 26.5 million veterans was stolen in 2006, have we seen a breach of sensitive data like the one that occurred in the United Kingdom last week. According to news reports, two disks containing the records of 7.25 million families and around 25 million people were lost by Her Majesty's Revenue and Customs agency as they were being transferred to the UK's National Audit Office.Is the Bush Administration Getting Serious About Information Security?blog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1244Fri, 16 Nov 2007 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1244Earlier this month, President Bush requested $154 million in FY2008 funding for expanding cyber security initiatives at the Department of Homeland Security (DHS) and other federal agencies. The majority of the initial budget request (which would shift current government fiscal year money from other projects) will reportedly be focused on expanding DHS's <a href="http://www.fcw.com/print/13_16/news/102730-1.html?type=pf" target="_blank">&quot;Einstein&quot; program</a>, which is run by the <a href="http://www.uscert.gov/" target="_blank">U.S. Computer Emergency Readiness Team</a>. See this Federal Computer Week story by Jason Miller titled <a href="http://www.fcw.com/online/news/150721-1.html" target="_blank">White House officials ask for $154 million in new cybersecurity spending</a> for more background.Focus on software assurance increases in U.S., U.K. and other marketsblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1243Thu, 15 Nov 2007 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1243I traveled quite a bit during the month of October - which was National Cyber Security Awareness month here in the U.S. - and there was one issue that came up frequently during my various business trips to locations around the U.S. and one to London: software assurance. It's really a continuation of a theme that I have come across during the course of the last couple of years: as breaches of information security have become more and more frequent - whether perpetrated by cyber-criminals looking to make a fast buck; or by nefarious actors breaking into systems to commit espionage; or in the case of entire countries (e.g. Estonia) that have seen their critical infrastructure attacked via cyberspace - governments have become increasingly focused on product security. <B>The issue of security within products that are integral parts of systems or networks is clearly gaining the attention of government decision makers around the world...</b> Speaking of Security Podcast #84blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1242Mon, 12 Nov 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1242<p><a href="https://www.rsa.com/blog/podcasts/071112_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (07:27).</p><p> Paul Joyal speaks with Dan Wilson, Vice President and Co-Founder of <a href="http://accuvant.com" target="_blank">Accuvant</a>, one of RSA's key channel partners about their business, their information-centric strategy for security, and a <a href="http://www.rsa.com/press_release.aspx?id=8857">recent award that they received</a>. Please note that we will be taking a short break for the U.S. Thanksgiving holiday, but will be back with another podcast for the week of December 3, 2007.</p>Speaking of Security Podcast #83blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1241Mon, 05 Nov 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1241<p><a href="https://www.rsa.com/blog/podcasts/071105_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (09:56).</p><p> Matt Buckley speaks with EMC Vice President of Technology Alliances, Chuck Hollis, about Security and Virtualization. Read more from Chuck at <a href="http://chucksblog.emc.com">chucksblog.emc.com</a>.<br></p>Fish, Subprime Mortgages, and Data Storageblog@rsa.com (Ari Juels)http://www.rsa.com/blog/blog_entry.aspx?id=1240Fri, 02 Nov 2007 00:00:00 GMTblog@rsa.com (Ari Juels)http://www.rsa.com/blog/blog_entry.aspx?id=1240In his <i>Histories</i>, Herodotus tells the story of Polykrates, overlord of the island of Samos. The king of Egypt counseled Polykrates to throw away some possession of great value, lest a surplus of good fortune bring him tragedy. Heeding this advice, Polykrates pitched his most prized possession, an emerald ring, into the sea. Several days later, a fisherman brought Polykrates a fish as tribute. When the fish was cut open, it was discovered to contain the fatal ring. (Polykrates was, of course, brutally murdered soon afterward.) Herodotus's story (and book) was crafted as a parable about hubris. <strong>It is also a good parable about banking--and more generally about <a href="http://www.rsa.com/node.aspx?id=3364">risk</a>...</strong>Smart Cards and Risk blog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1238Mon, 29 Oct 2007 00:00:00 GMTblog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1238One of the concepts that RSA and EMC are starting to focus on more is <a href="http://www.rsa.com/node.aspx?id=3364">risk</a>. For some, risk has a negative connotation, such as the chance of suffering some type of loss or damage. From a finance perspective, risk is perhaps a more neutral term in that with increased risks (there is a relationship to volatility), one expects a greater return. This has relevance in information-centric security as well...Speaking of Security Podcast #82blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1239Mon, 29 Oct 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1239<p><a href="https://www.rsa.com/blog/podcasts/071029_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (08:07).</p><p>Last week's <a href="https://www.rsaconference.com/2007/europe">RSA Conference Europe</a> is over but you can hear from some of last week's expert speakers, like <a href="https://www.csialliance.org/about_csia/csia_team/bio_marikakonings/" target="_blank">Marika Konings</a>, Director of European Affairs for the Cyber Security Industry Alliance, in the <a href="http://www.rsaconference.com/2007/europe/Agenda_and_Content/Conference_Podcasts.aspx">Conference Podcasts</a> section of <a href="https://www.rsaconference.com/2007/europe">www.rsaconference.com/2007/europe</a>. Paul gets an event recap from the Conference Manager, Linda Lynch, and we share part of an interview with Marika from the show floor in this week's podcast.</p>Speaking of Security Podcast #81blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1235Mon, 22 Oct 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1235<p><a href="https://www.rsa.com/blog/podcasts/071022_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (07:07).</p><p>This week we revisit a recent <a href="www.rsa.com/webseminars" target="_blank">RSA web seminar</a> held in late September. <a href="http://www.rsa.com/node.aspx?id=3361" target="_blank">Nick Selby</a>, Security Research Director from the analyst firm, The 451 Group, shares some key tips for securing web portals, by providing the right protection and level of access to information for trusted identities. To review the entire 9/25 webcast replay, visit <a href="http://www.rsa.com/webseminars" target="_blank">www.rsa.com/webseminars</a>.<br></p>Hey, do I know you?blog@rsa.com (Uriel Maimon)http://www.rsa.com/blog/blog_entry.aspx?id=1234Mon, 22 Oct 2007 00:00:00 GMTblog@rsa.com (Uriel Maimon)http://www.rsa.com/blog/blog_entry.aspx?id=1234My friends have gotten tired of hearing me talk about how dreadful it is to be single. One of my friends S. (who has four children and a mortgage) suggested that I take over looking after his kids while *he* wakes up with a hangover next to a half-empty bottle of Jack Daniels and photos of a wild party and the younger sister of one of my work colleagues (Hi M!). Another friend, R, asked me why I don't frequent the singles bar scene. I replied that I'm looking for <a href="http://www.lyricsdepot.com/the-beautiful-south/good-as-gold.html">a sun-drenched wind-swept Ingrid Bergman kiss</a>, a heart touching romance and a soul companion -- not some sordid meaningless fling. He sagely nodded his head and voiced his hopes that I enjoy the rest of my long life looking forward to dying alone...U.S. House Passes Resolution on Cyber Securityblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1237Fri, 19 Oct 2007 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1237As issues around cyber security continue to heat up in the wake of several high profile data security breaches in the public sector -- and with increasing concern about cyber vulnerabilities in our nation's critical infrastructures, the U.S. House of Representatives passed a resolution this week recognizing the importance of the issue. The resolution, H. RES. 716, was introduced by Congressman Jim Langevin (D-RI) with strong bi-partisan support. The purpose of the Resolution was for: "Expressing the sense of Congress with respect to raising awareness and enhancing the state of computer security in the United States, and supporting the goals and ideals of National Cyber Security Month."...IT Industry to Congress: Help Needed to Fight Cyber-crimeblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1236Tue, 16 Oct 2007 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1236On October 16th, in the bowels of the U.S. Capitol Building, the <a href="http://www.bsa.org/globalhome.aspx">Business Software Alliance</a> organized a briefing on cyber-crime issues that was attended by congressional staff members, industry experts and media representatives. Art Coviello, President of RSA, The Security Division of EMC, delivered the industry keynote; U.S. Representative Steve Chabot (R-OH) provided remarks from a congressional perspective. Congressman Chabot is a co-sponsor of H.R. 2290, the Cyber Security and Enhancement Act of 2007, along with U.S. Representative Adam Schiff (D-CA). <strong>H.R. 2290, if passed, would include changes to law that would: criminalize malicious botnet attacks...</strong>Speaking of Security Podcast #80blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1233Fri, 12 Oct 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1233<p><a href="https://www.rsa.com/blog/podcasts/071015_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (08:07).</p><p>October is <a href="http://www.staysafeonline.info/events/index.html" target="_blank">National Cyber Security Awareness Month</a>. We celebrate by speaking with <a href="http://www.csis.org/component/option,com_csis_experts/task,view/type,34/id,111/" target="_blank">James A. Lewis</a>, Director and Senior Fellow, Technology and Public Policy Program at the <a href="http://www.csis.org/" target="_blank">Center for Strategic and International Studies</a> in Washington, D.C., about cyber security in the federal government and around the world.</p>Speaking of Security Podcast #79blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1232Mon, 08 Oct 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1232<a href="https://www.rsa.com/blog/podcasts/071008_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (10:39).<br><Br><a href="http://www.mckeay.net/secure/2007/08/repeat_after_me_the_cissp_is_n.html" target="_blank">Martin McKeay</a>, among others, have recently blogged about the value of the <a href="https://www.isc2.org/cgi-bin/content.cgi?category=97" target="_blank">CISSP</a> (Certified Information Systems Security Professional) certification. Paul Joyal speaks with leading IT author, <a href="http://logicalsecurity.com/" target="_blank">Shon Harris</a>, about the CISSP and other certifications that IT Security Professionals seek to add to their credential lists and knowledge-bases. <br>National Cyber Security Month Kicks Off at the National Press Clubblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1230Wed, 03 Oct 2007 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1230<I>This month, I'll be posting blogs several times a week given that this is National Cyber Security Awareness Month. To kick off this year's campaign, the 2007 National Cyber Security Awareness Summit was held at the National Press Club in Washington, D.C. on October 1st.<P> Below, you will find a post from the Summit:<P></I> I was encouraged by the strong turnout at the inaugural National Cyber Security Awareness Summit, the 4th time that October has been recognized officially as National Cyber Security Awareness Month. <B>You know that you are going to have good event when the room is half full 30 minutes before start time. </b><P> I thought that Assistant Secretary Greg Garcia captured the heightened interest in the topic...Speaking of Security Podcast #78blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1229Mon, 01 Oct 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1229<a href="https://www.rsa.com/blog/podcasts/071001_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (06:12).<br><Br><a href="http://www.rsa.com/press_release.aspx?id=8804" target="_blank">RSA announces its solution</a> for <a href="http://www.rsa.com/node.aspx?id=3364" target="_blank">Information Risk Management</a> for financial services organizations worldwide this week at <a href="http://www.swift.com/index.cfm?item_id=58077" target="_blank">SIBOS</a> in Boston. Listen to Ann King, Senior Manger for Solutions Marketing, talk about this approach to following information within a financial institution throughout its lifecyle -- revealing where the risks lie to present a holistic view of risk related to information across the enterprise. <br>Another 'shoe' drops -- DHS cyber security breach top of news this weekblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1227Tue, 25 Sep 2007 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1227On the cyber security front, the nation's capital is abuzz this week about breaches of information systems at the U.S. Department of Homeland Security (DHS). In a Washington Post <a href="http://www.washingtonpost.com/wp-dyn/content/article/2007/09/23/AR2007092301471.html">article</a> on Monday, September 24, writers Ellen Nakashima and Brian Krebs reported that the "...FBI is investigating a major information technology firm with a $1.7 billion Department of Homeland Security contract after it allegedly <strong>failed to detect cyber break-ins traced to a Chinese-language Web site</strong> and then tried to cover up its deficiencies, according to congressional investigators."Speaking of Security Podcast #77blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1228Mon, 24 Sep 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1228<a href="https://www.rsa.com/blog/podcasts/070924_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (10:27).<br><Br>This week we welcome back two previous guests, Dave Howell and Peter Beardmore. First, we share information about the <a href="http://www.rsa.com/node.aspx?id=2745" target="_blank">PCI DSS</a> (Payment Card Industry Data Security Standard) from a recently commissioned <a href="http://www.rsa.com/press_release.aspx?id=8781" target="_blank">survey by Forrester</a>. And we also talk about <a href="http://www.rsa.com/press_release.aspx?id=8756" target="_blank">unified credential management</a> in the enterprise.U.S. Ratcheting up Cyber Defenses in Wake of High Profile Cyber Attacks in 2007?blog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1226Fri, 21 Sep 2007 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1226Finally, the cyber security issue may just be getting the attention that it deserves at the national leadership level in the United States. In an RSA Speaking of Security <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1201">blog post</a> in early July, I asked the question: Will the recent cyber attacks on Estonia be a wake up call for European and U.S. leaders? I noted in that post that the answer in Europe was apparently yes and referenced quotes in a June 30th <a href="http://www.reuters.com/article/internetNews/idUSL3044463420070630">Reuters story</a> from European Information Society Commissioner Vivian Reding: <strong>"Estonia was a wake up call...If people do not understand the urgency now, they never will."</strong>... Security is Everybody's Jobblog@rsa.com (Jamie Barnett)http://www.rsa.com/blog/blog_entry.aspx?id=1225Tue, 18 Sep 2007 00:00:00 GMTblog@rsa.com (Jamie Barnett)http://www.rsa.com/blog/blog_entry.aspx?id=1225It was blasphemy at the time. At the 2007 RSA Conference in San Francisco, our President, Art Coviello, made the claim that the standalone security market was not long for this world. Some in the audience must have thought he was Looney Tunes, making a claim like that at a longtime venue dedicated to all things security. In my role driving integrated solutions of RSA technology and EMC products, I speak with security, IT, and storage professionals regularly to understand their requirements and preferences for integrating security into information infrastructure products. <strong>The single biggest common thread between them is this: security seems to be everybody's job these days.</strong> These things tie: security-baked-in and security-as-everybody's-job... Speaking of Security Podcast #76blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1224Mon, 17 Sep 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1224<a href="https://www.rsa.com/blog/podcasts/070917_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (07:41).<br><Br>Online fraud is becoming more like a traditional industry. Researchers at the <a href="http://www.rsa.com/node.aspx?id=3020" target="_blank">RSA Anti-Fraud Command Center</a> are hard at work as they learn more and more about how the underground world of online fraud works and how security professionals can get one step ahead. This week, Jens Hinrichsen, Senior Product Marketing Manager in RSA's <a href="http://www.rsa.com/node.aspx?id=2683" target="_blank">Identity and Access Assurance Group</a>, takes us deeper into this world. Learn even more on the 9/18 Web Seminar: <a href="https://www.rsa.com/go/webcast/WebSeminarRegistration.asp?ID=Event_W_Crimeware_Panda_FA_Q307&source1=blog" target="_blank">A VIEW OF THE GROWING CRIMEWARE THREAT IN ACTION</a>.<br>Increased Interest in Device-Specific Strong Authentication blog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1223Fri, 14 Sep 2007 00:00:00 GMTblog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1223Customers are expressing an increased interest in having strong authentication mechanisms on a variety of client devices. Service providers, also, are interested in ensuring that end users are able to employ their mobile phones for two-factor authentication. Such organizations may also play the role of outsourcer and are concerned with the provisioning of credentials and new support models. Some of the drivers for this are longstanding, such as increased proliferation of mobile devices to remote employees, partners and consumers. <P> Ericsson<sup><span style="text-size:8px">1</span></sup> predicts that global mobile subscriptions will reach 5.5 billion by 2012. Since people are used to carrying phones, these mobile devices become very convenient containers for strong authentication credentials needed for secure remote access. <strong>Others drivers are more visionary...</strong>Speaking of Security Podcast #75blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1222Mon, 10 Sep 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1222<a href="https://www.rsa.com/blog/podcasts/070910_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (09:58).<br><Br>Paul Joyal talks with <a href="http://www.rsa.com/node.aspx?id=1004" target="_blank">Bret Hartman</a>, RSA's CTO, about the Common Security Platform, the process that integrates EMC and RSA technologies. And Matt Buckley introduces our newest <a href="http://www.rsa.com/blog/blog.aspx">Speaking of Security</a> blogger, <a href="http://www.rsa.com/blog/blog.aspx?author=mude">Manju Mude</a>, Senior Compliance Analyst at RSA.<br>Speaking of Security Podcast #74blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1221Mon, 27 Aug 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1221<a href="https://www.rsa.com/blog/podcasts/070827_SecurityPodcast.mp3">Click here to listen/download</a> (10:38).<br><Br>As a follow-up to the <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1216">Aug. 13 podcast</a>, we present an excerpt from the Aug. 15 RSA web seminar: &quot;<a href="https://info.rsasecurity.com/2007Am/webcast/070815SEA/online_RSAweb.html">Combining Network Access Control (NAC) with Strong Authentication</a>.&quot; Denzil Wessels, technical marketing manager, <a href="http://www.juniper.net/">Juniper Networks</a>, takes us through what a NAC solution provides to an IT infrastructure. <a href="https://www.rsa.com/go/wpt/wpindex.asp?WPID=8670&source1=podcast">Click here for the entire replay of the webcast</a> and/or <a href="https://info.rsasecurity.com/2007Am/webcast/070815SEA/webcast_slides.pdf">download the accompanying slide deck</a>. The Podcast Team will take Sept. 3 off for the U.S. Labor Day holiday but will return on Sept. 10 with a new edition.<br>A Data Security Philosophy, According to Sisyphusblog@rsa.com (Chris Parkerson)http://www.rsa.com/blog/blog_entry.aspx?id=1220Wed, 22 Aug 2007 00:00:00 GMTblog@rsa.com (Chris Parkerson)http://www.rsa.com/blog/blog_entry.aspx?id=1220In Greek mythology, <a href="http://en.wikipedia.org/wiki/Sisyphus">Sisyphus</a> was a king who was extremely crafty and dishonest, and the punishment brought down upon him from the gods was to roll a very large boulder up a hill. each time Sisyphus attempted to do this, the boulder would escape him before he was able to reach the top, and so he had to begin the task all over again... This continued throughout eternity. This analogy has been applied to many problems over the course of history, including within the world of IT - where no matter how many resources are employed to solve a particular problem, it can be quite typical for the issue at hand to remain either largely or completely unsolved, and just as daunting as it had been before. <strong>While I don't think we have quite reached a "Sisyphean state" in data security, an RSA survey conducted by Forrester Consulting...</strong>Speaking of Security Podcast #73blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1218Mon, 20 Aug 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1218<a href="https://www.rsa.com/blog/podcasts/070820_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (08:06).<br><Br>Matt Buckley discusses the state of data security with <a href="http://forrester.com/ER/Research/List/Analyst/Personal/0,,1045,00.html" target="_blank">Paul Stamp</a>, Principal Analyst, Forrester Research. Paul is a leading expert on enterprise security technology, focusing on security architecture, and data security technologies, such as enterprise encryption.<br>Should Employees Carry So Much of the Heavy Burden of Security?blog@rsa.com (Chris Parkerson)http://www.rsa.com/blog/blog_entry.aspx?id=1217Wed, 15 Aug 2007 00:00:00 GMTblog@rsa.com (Chris Parkerson)http://www.rsa.com/blog/blog_entry.aspx?id=1217Over the past year we have witnessed a significant increase in the number of data breach incidents due to mistakes by internal employees at many respected companies. These incidents run the gamut from missing or stolen laptops, vanishing BlackBerry's and disappearing USB drives. The typical response from companies that have suffered these sorts of breaches is: "Our policy prohibits employees from putting unencrypted sensitive company information on laptops, PDAs, and other devices." While you will get no argument from me that this is a good policy, how much of the responsibility for ensuring this policy is followed as intended should really fall on the employee's shoulders? <strong>Is it really possible to expect employees to be educated enough about such policies to always do the right thing?</strong>... Speaking of Security Podcast #72blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1216Mon, 13 Aug 2007 17:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1216<a href="https://www.rsa.com/blog/podcasts/070813_SecurityPodcast.mp3">Click here to listen/download</a> (09:24).<br><br>Last week RSA, The Security Division of EMC, <a href="http://www.rsa.com/press_release.aspx?id=8631">announced its intent</a> to acquire Tablus Inc., a leading provider of data loss prevention solutions based in San Mateo, California. This acquisition should significantly expand RSA's Data Security Strategy, adding key technologies to help discover, classify and protect sensitive information. Tom Corn, Vice President of Products for RSA's Data Security Group tell us more. And the RSA Web Seminar Series presents &quot;<a href="https://info.rsasecurity.com/2007Am/webcast/070815SEA/online_RSAweb.html">Combining Network Access Control (NAC) and Strong Authentication</a>&quot; on with technology partner, <a href="http://www.juniper.net/" target="_blank">Juniper Networks</a>. Listen to a preview of what you could learn during this event on August 15 or on the replay.The Return on Investment for Securing Informationblog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1215Mon, 13 Aug 2007 00:00:00 GMTblog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1215There have been quite a few blogs written about the Return on Investment (ROI) of security. <a href="http://techbuddha.wordpress.com/about/">Amrit Williams</a> has several links in his recent discussion of the topic. This reminds me of some work that I did with BearingPoint on the ROI of a Services-Oriented Architecture (SOA), a similarly challenging area in which to quantify value. The framework we used for justification involved underlying business initiatives, traditional ROI metrics and overall strategic drivers. The difficulty in quantifying a business initiative, like extending services through new distribution channels via federation, may be relatively low. Quantifying traditional ROI metrics, on the other hand, may range in difficulty. The value of risk reduction may be more amorphous...Summer School on Trusted Infrastructureblog@rsa.com (Burt Kaliski)http://www.rsa.com/blog/blog_entry.aspx?id=1214Tue, 07 Aug 2007 00:00:00 GMTblog@rsa.com (Burt Kaliski)http://www.rsa.com/blog/blog_entry.aspx?id=1214One of many examples of the broader research opportunity RSA now has as part of EMC (as I described in <a href="http://www.rsa.com/blog/entry.asp?id=1191">my podcast</a> on my new role) is this month's 1st <a href="http://www.aptiss.org/">Asia-Pacific Summer School on Trusted Infrastructure Technologies</a>, which will be held in Guangdong, China. Dr. Wenbo Mao, who recently joined EMC to lead our new research center in Beijing, and his team have put together an excellent international program. Just as significant is the emphasis they've placed on providing sponsorships so that top students can attend...Speaking of Security Podcast #71blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1213Mon, 06 Aug 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1213<p><a href="https://www.rsa.com/blog/podcasts/070806_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (06:06).</p><p>Listen to how <a href="http://www.bankofthewest.com" target="_blank">Bank of the West</a>, the second largest bank based in California, has met the <a href="http://www.rsa.com/node.aspx?id=2970" target="_blank">FFIEC guidance for providing multi-factor authentication</a> to help further protect bank customers, their funds and personal information when banking online. The combination of deploying <a href="http://www.rsa.com/node.aspx?id=3018" target="_blank">behind-the-scenes protection as well as visible site-to-user authentication</a> is designed to provide strong security that involves bank customers in a user-friendly way, reassures them and boosts their confidence online, while not hindering their banking experience. Paul Joyal talks to CIO Donald Duggan about this <a href="http://www.rsa.com/press_release.aspx?id=8593">initiative</a>.</p>Speaking of Security Podcast #70blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1212Mon, 30 Jul 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1212<p><a href="https://www.rsa.com/blog/podcasts/070730_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (10:15).</p><p>October's <a href="http://www.rsaconference.com/2007/europe/home.aspx" target="_blank">RSA Conference Europe</a> promises to be bigger and better than ever! In this podcast we talk with two of the conference's movers and shakers from RSA's U.K. headquarters. And we also welcome our newest <a href="http://www.rsa.com/blog/">Speaking of Security</a> Blogger, <a href="http://www.rsa.com/blog/index.asp?author=kline">Sean Kline</a>, and learn some of his thoughts for the RSA blog and what security topics he plans to tackle.</p>New Blogs on RSA Conference siteblog@rsa.com (Blog Editor)http://www.rsa.com/blog/blog_entry.aspx?id=1211Fri, 27 Jul 2007 00:00:00 GMTblog@rsa.com (Blog Editor)http://www.rsa.com/blog/blog_entry.aspx?id=1211Take a moment to review the new blog available over at <a href="http://www.rsaconference.com/Security_Topics/Business_Trends_and_Impact/Blog.aspx">RSA Conference</a>. Recently hired Tim M. Mather, Chief Security Strategist, RSA Conference, offers his insights into the business of security--including mergers and acquisitions. <blockquote> TechDirt, a well respected technology blog, is posing an interesting question: "Will Security Software Mergers and Acquisition Continue?" To me, the simple answer is 'yes'. </blockquote>Speaking of Security Podcast #69blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1210Tue, 24 Jul 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1210<p><a href="https://www.rsa.com/blog/podcasts/070723_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (10:55).</p> <p>Speaking of Security Blogger, <a href="http://www.rsa.com/blog/index.asp?author=kellogg">Shannon Kellogg</a>, interviews Hord Tipton, former <a href="http://www.doi.gov/ocio/security/index.html" target="_blank">CIO of the U.S. Department of Interior</a>. Hord shares a bit about how he led the reorganization and development the Department's IT infrastructure across eight major bureaus and how his focus moved more and more toward information security initiatives.</p> Phish and Foulblog@rsa.com (Ari Juels)http://www.rsa.com/blog/blog_entry.aspx?id=1209Fri, 20 Jul 2007 00:00:00 GMTblog@rsa.com (Ari Juels)http://www.rsa.com/blog/blog_entry.aspx?id=1209"<a href="http://www.rsa.com/glossary/default.asp?id=1037">Phishing</a>," as you probably know, is a form of online con game. Users are lured by e-mail messages to legitimate-seeming but criminal sites--typically falsified versions of their real banking sites--and encouraged to enter password information. Having harvested this information, the operators of the criminal sites use it to break into victims' accounts. (As the term suggests, most "phishing" e-mail goes wide of the mark, arriving as spam unconnected with the recipient's bank. A phishing expedition, though, can be profitable with only a few successes.) The remedies offered by the security community are numerous. Most prevalent are various types of red flags...Out of the Boxblog@rsa.com (Uriel Maimon)http://www.rsa.com/blog/blog_entry.aspx?id=1208Thu, 19 Jul 2007 00:00:00 GMTblog@rsa.com (Uriel Maimon)http://www.rsa.com/blog/blog_entry.aspx?id=1208I went on a date the other night. She was a "set-up" from a new acquaintance at the office who did not know me well enough not to set me up on dates. So here I am sitting across from this blonde beauty, in a tapas bar, and she is gorgeous: her soft golden tresses frame a pale heart-shaped face and her curves are paralleled only by the desperately bored look in her glazed ice-blue eyes, through her drooping eye-lids. Now I'm as socially astute as anyone who has ever written network device drivers...Speaking of Security Podcast #68blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1206Mon, 16 Jul 2007 09:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1206<p><a href="https://www.rsa.com/blog/podcasts/070716_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (11:01).</p> <p>The Speaking of Security Podcast is back and offers an in-depth interview with Senior Product Marketing Manager, Jens Hinrichsen, regarding the evolution of phishing attacks. Big upticks of spear phishing and "man-in-the-middle" attacks. Also discusses the difference between Phishing and Crimeware/Malware. For more, check out the monthly <a href="http://www.rsa.com/phishing_reports.aspx/">RSA Online Fraud Intelligence Report</a>.</p>Managing Security Event Informationblog@rsa.com (Blog Editors)http://www.rsa.com/blog/blog_entry.aspx?id=1207Mon, 16 Jul 2007 06:21:00 GMTblog@rsa.com (Blog Editors)http://www.rsa.com/blog/blog_entry.aspx?id=1207Recently EMCer Chuck Hollis addressed the challenges of managing and mining event data from network devices. <blockquote>"A while ago, I opined that IMSPs (information management service providers) might be hampered by corporate information security mandates. At the time, I had started to meet customers who wouldn't consider using a service provider for backup, archiving, etc. simply because they (or their security officer) couldn't get over the idea of sending their important information to a third party for safekeeping. Since then, the tide seems to have turned. I see more and more customers who are actively pursuing strategies to move more and more of the information management burden to specialized service providers. I guess they're getting more comfortable with the security provisions of these offerings..."</blockquote>Convergence of Access and Information Policiesblog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1202Tue, 10 Jul 2007 00:00:00 GMTblog@rsa.com (Sean Kline)http://www.rsa.com/blog/blog_entry.aspx?id=1202It has been a year since EMC announced its acquisition of RSA and it is very interesting to observe how our worldview has evolved. While we were not the first to report the deterioration of perimeters as a means to protect information, the industry still appears to operate in a very segmented fashion. I spoke at the <a href="http://www.netapps.org/events/apr07/apr07confabstract.htm">Network Applications Consortium Spring Conference</a> and there was great industry participation and discussion around Enterprise Authorization Management. The model that most people described at the conference still segments authentication from authorization and does not tend to talk about policy on the information itself...Will the recent cyber attacks on Estonia be a wake up call for European and U.S. leaders?blog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1201Mon, 02 Jul 2007 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1201Will the recent cyber attacks on Estonia be a wake up call for European and U.S. leaders? According to a <a href="http://www.reuters.com/article/internetNews/idUSL3044463420070630">Reuters story</a> on Friday, June 30th, the answer is apparently yes &ndash; at least on the other side of the Atlantic Ocean. What about the U.S.?Speaking of Security Podcast #67blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1200Mon, 25 Jun 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1200<p><a href="https://www.rsa.com/blog/podcasts/070625_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (08:35).</p> <p>We end our listener appreciation month with a discussion with Michael Farnum, a Security Engineer with <a href="http://accuvant.com/index_f.html" target="_blank">Accuvant</a> and prolific security blogger: <a href="http://infosecplace.com/blog/">An Information Security Place</a> and for <a href="http://www.computerworld.com/blogs/farnum">Computerworld</a>. He talks about how performing a security assessment is like a trip to the dentist, about how educational organizations deal with security, and what he thinks are the hot issues in security for the second half of 2007. Please note that your Speaking of Security podcast team will be on hiatus for the next two weeks. Tune in on July 16 for our next edition. In the meantime, tell us what you think by taking our short <a href="http://www.rsa.com/go/podcast" target="_blank">survey</a>.</p>Speaking of Security Podcast #66blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1199Mon, 18 Jun 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1199<p><a href="https://www.rsa.com/blog/podcasts/070618_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (12:19).</p><p>RSA's annual Wireless Survey Results are in: &quot;<a href="http://www.rsa.com/press_release.aspx?id=8451">Wireless security highest in London; but one-fifth of business networks remain unsecured in all surveyed cities</a>&quot;. Learn more from RSA Product Marketing Manager, John Masotta. And we share an excerpt from one of our popular <a href="http://www.rsa.com/blog/entry.asp?id=1180">past podcasts</a>: an interview with &quot;The Security Career Guy,&quot; <a href="http://www.episteme.ca" target="_blank">Mike Murray</a>.We also invite listeners to complete a <a href="http://www.rsa.com/go/podcast">short survey</a> as part of Speaking of Security Podcast Listener Appreciation Month for a chance to win a $100 American Express Gift Card (<a href="http://www.rsa.com/go/contestrules" target="_blank">Official Contest Rules</a>). </p>REAL ID continues to have 'real' challengesblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1198Mon, 18 Jun 2007 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1198I have been meaning to write something about "REAL ID" for a while now, so will attempt to provide an update on what's happening with this initiative and some additional food for thought. What is REAL ID you say? Well, for those of you who haven't managed to hear about this identity card mandate, it started with the 9/11 Commission's recommendations (Recommendation #14 in fact) and became a matter of law in 2005 as the "REAL ID Act." The authors of the 9/11 recommendation and the subsequent legislation all were ostensibly aiming for the same thing: preventing the use of a fraudulent driver's license by terrorists through the development of safeguards that would help prevent tampering and use of such a document for false identification -- and that would also enable more effective and trustworthy authentication of individuals for purposes such as boarding a plane...Anti-Phishing Educationblog@rsa.com (Burt Kaliski)http://www.rsa.com/blog/blog_entry.aspx?id=1196Tue, 12 Jun 2007 00:00:00 GMTblog@rsa.com (Burt Kaliski)http://www.rsa.com/blog/blog_entry.aspx?id=1196<a href="http://www.informatics.indiana.edu/markus/">Markus Jakobsson</a> -- a former RSA Labs scientist now leading a research program at Indiana University -- has pointed me to some great new cartoons developed together with Sukamol Srikwan that educate users on how to avoid phishing attacks. See <a href="http://www.SecurityCartoon.com">www.SecurityCartoon.com</a>. <P align="center"><a href="http://www.SecurityCartoon.com"><img src="http://cgi.cs.indiana.edu/~markus/cartoon/comic.php?c=20070528"></a></p>Speaking of Security Podcast #65blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1197Mon, 11 Jun 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1197<a href="https://www.rsa.com/blog/podcasts/070611_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (11:59).<p>On today's program, we hear from RSA's <a href="http://www.rsa.com/node.aspx?id=1004" target="_blank">Chief Technical Officer</a> in an interview recorded on-site at the recent <a href="http://www.emc.com/news/emcworld/" target="_blank">EMC World</a> event in Orlando, Florida. We also get a review of last week's <a href="http://gartner.com/" target="_blank">Gartner</a> IT Security Summit held in Washington, DC. And we continue through June with <a href="http://www.rsa.com/blog/index.asp?keyword=Podcasts">Speaking of Security Podcast</a> Listener Appreciation Month, so listen in for a chance to win special prizes as offered in this week's podcast (<a href="http://www.rsa.com/go/contestrules" target="_blank">Official Contest Rules</a>). </p>Speaking of Security Podcast #64blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1195Mon, 04 Jun 2007 17:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1195<p><a href="https://www.rsa.com/blog/podcasts/070604_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (10:25).</p><p>June is <a href="http://www.rsa.com/blog/index.asp?keyword=Podcasts">Speaking of Security Podcast</a> Listener Appreciation Month! What does this mean? Listen all month long for the chance to win special prizes and participate in unique listener opportunities. Also this week, Matt Buckley speaks with Marc Gaffan, RSA's Director of Product Marketing, about <a href="http://www.rsa.com/press_release.aspx?id=8405" target="_blank">EMC's acquisition</a> of <a href="http://www.verid.com/" target="_blank">Verid, Inc.</a> and how Verid's <a href="http://www.verid.com/general.php?category=Solutions&headline=Knowledge+Based+Authentication" target="_blank">knowledge-based authentication</a> (KBA) solutions will enhance and extend RSA's current suite of <a href="http://www.rsa.com/node.aspx?id=3017" target="_blank">consumer authentication solutions</a>.</p>Factoring Newsblog@rsa.com (Burt Kaliski)http://www.rsa.com/blog/blog_entry.aspx?id=1194Mon, 04 Jun 2007 13:00:00 GMTblog@rsa.com (Burt Kaliski)http://www.rsa.com/blog/blog_entry.aspx?id=1194The <a href="http://blogs.wsj.com/numbersguy/">Numbers Guy</a> has provided a clear and informative explanation of the recent factorization of the 1039th Mersenne number. I've add just a few comments on his recent <a href="http://blogs.wsj.com/numbersguy/when-307-digits-arent-enough-116/">blog entry</a>, which I've said is otherwise "faultless" (continuing an earthquake metaphor introduced at the conclusion of his post):<UL><LI> Mersenne numbers, because of their special form, are especially shaky. They fall much more quickly to factoring methods than the "tested and approved" counterparts of the same length used in cryptography - which is the reason that Mersenne numbers are often targeted in factoring research.</UL>...White House issues updated guidance to federal agencies for safeguarding sensitive informationblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1193Wed, 30 May 2007 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1193On May 22, 2007, the U.S. Office of Management and Budget (OMB) issued new guidance to federal agencies for both safeguarding sensitive data and responding to a data breach if one occurs. The memo, entitled <a href="http://www.rsa.com/blog/bimgs/070530/OMB Data Security Memo 07-16.pdf" target=_blank>Safeguarding Against and Responding to the Breach of Personally Identifiable Information</a>" was sent by Clay Johnson, Deputy Director of Management at OMB, to the heads of executive departments and federal agencies. The May 2007 guidance follows the release of the <a href="http://www.idtheft.gov/reports/StrategicPlan.pdf" target=_blank>President's Identity Theft Task Force Strategic Plan</a> in late April 2007 and several high profile data breaches at federal agencies this year. How will federal agencies respond to the updated guidance? Time will tell...The Cipher on the Wallblog@rsa.com (Ari Juels)http://www.rsa.com/blog/blog_entry.aspx?id=1192Thu, 24 May 2007 00:00:00 GMTblog@rsa.com (Ari Juels)http://www.rsa.com/blog/blog_entry.aspx?id=1192"The writing is on the wall for 1024-bit RSA," one trade publication has <a href="http://www.theregister.co.uk/2007/05/22/unreadable_writing_is_on_the_wall/">declared</a> in response to the recent announcement of the successful factoring of a 307-digit (1017-bit) number. As 1024 bits is the length of many RSA keys used in practice today, a short journalistic leap of fancy raises the specter of imperiled retail transactions on the Web. If there is writing on the wall for 1024-bit RSA, though, what's written is in cipher--and it's wholly unclear how long the cryptanalysis will take.Speaking of Security Podcast #63blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1191Tue, 22 May 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1191<p><a href="https://www.rsa.com/blog/podcasts/070521_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (07:30).</p><p>Our feature interview is with Speaking of Security Blogger, <a href="http://www.rsa.com/blog/index.asp?author=kaliski">Burt Kaliski</a>, now director of the <a href="http://www.emc.com/news/emc_releases/showRelease.jsp?id=5064" target="_blank">EMC Innovation Network</a>. Burt talks about the creation of the Network and about his transition from Director and Chief Scientist of <a href="http://www.rsa.com/rsalabs/" target="_blank">RSA Laboratories</a>. We also announce that June is <a href="http://www.rsa.com/blog/index.asp?keyword=Podcasts">Speaking of Security podcast</a> listener appreciation month. Be sure to listen to the podcast during June for opportunities to win special prizes. Next week, we'll take a break for the U.S. Memorial Day holiday, and will return with a new edition on June 4. </p>Putting all one's eggs in a single basketblog@rsa.com (Uriel Maimon)http://www.rsa.com/blog/blog_entry.aspx?id=1189Mon, 21 May 2007 00:00:00 GMTblog@rsa.com (Uriel Maimon)http://www.rsa.com/blog/blog_entry.aspx?id=1189I was crawling my way through the <a href="http://en.wikipedia.org/wiki/Series_of_tubes">series of tubes</a> that is the internet, when I ran into this <a href="http://www.finextra.com/fullstory.asp?id=16750">news article</a>. It seems a certain large financial institution's consumers were hit by a banking <a href="http://www.rsa.com/glossary/default.asp?id=1076">Trojan</a>. This financial institution had deployed tokens to all its online banking customers, but the Trojan managed to bypass this protection by combining two fraud techniques: <a href="http://www.rsa.com/glossary/default.asp?id=1074">Pharming</a> and man-in-the-middle (<a href="http://www.rsa.com/glossary/default.asp?id=1082">MITM</a>).Author Correctionblog@rsa.com (Blog Editors)http://www.rsa.com/blog/blog_entry.aspx?id=1190Mon, 21 May 2007 00:00:00 GMTblog@rsa.com (Blog Editors)http://www.rsa.com/blog/blog_entry.aspx?id=1190The blog entry from Monday, May 21 by Uriel Maimon was originally published as the work of another RSA blogger. Our apologies for the mistake.Speaking of Security Podcast #62blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1187Mon, 14 May 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1187<p><a href="https://www.rsa.com/blog/podcasts/070514_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (10:21).</p><p>Paul Joyal checks in with our man in Washington, blogger <a href="http://www.rsa.com/blog/index.asp?author=kellogg">Shannon Kellogg</a>, about the doings on the hill as well. EMC encourages all amateur movie-makers to enter You-Tube-like shorts for <a href="http://www.emc.com/iva" target="_blank">Inforati Video Awards</a> (IVA) contest. The best entries in three categories will earn prizes (not to mention fame and bragging rights) for their creators, with the winners announced at <a href="http://www.emcworld2007.com/" target="_blank">EMC World</a> in Orlando May 21-24.</p>Speaking of Security Podcast #61blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1186Mon, 07 May 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1186<p><a href="https://www.rsa.com/blog/podcasts/070507_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (07:24).<br><br><a href="http://rsa.com/node.aspx?id=3182" target="_blank">Security Information and Event Management</a> (SIEM) is an increasingly hot topic across the Enterprise and is something RSA considers as one of the core foundations for its <a href="http://rsa.com/node.aspx?id=1002" target="_blank">information-centric approach to security</a>. Matt Buckley speaks with <a href="http://451group.com/about/bio_detail.php?eid=272" target="_blank">Nick Selby</a>, Senior Analyst and Director of the Enterprise Security Practice for <a href="http://451group.com/" target="_blank">The 451 Group</a> about SIEM in this week's podcast. (<em><font size="-3">Neither Nick Selby nor The 451 Group has been directly compensated for Mr. Selby's participation in this recording</font></em>.)</p>President's ID Theft Task Force issues strategic plan -- does it go far enough?blog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1185Wed, 02 May 2007 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1185The President's Identity Theft Task Force released <a href="http://www.idtheft.gov/reports/StrategicPlan.pdf" target=_blank>Combating Identity Theft: A Strategic Plan</a> on April 23rd in Washington, D.C. The <a href="http://www.idtheft.gov/about.html" target=_blank>Task Force</a>, which is co-chaired by U.S. Attorney General Alberto Gonzales and Federal Trade Commission (FTC) Chairman Deborah Majoras, was established by an executive order from President Bush in May 2006. Attorney General Gonzales and Chairman Majoras released the plan in coordination with a national FTC forum on identity protection and authentication issues: <a href="http://www.ftc.gov/bcp/workshops/proofpositive/index.shtml" target=_blank>Proof Positive -- New Directions for ID Authentication</a>.Speaking of Security Podcast #60blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1184Mon, 30 Apr 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1184<p><a href="https://www.rsa.com/blog/podcasts/070430_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> 11:13).<br><br>Jonathan Young, <a href="http://www.earthlink.net/about/">EarthLink</a>'s VP of Security Software, Subscription and Services, talks about <a href="https://www.rsa.com/press_release.aspx?id=8134">expanding anti-phishing protection services</a> for its customers. We also hear from <a href="http://www.burtongroup.com/AboutUs/Bios/PrintBio.aspx?Id=215" target="_blank">Diana Kelley</a>, VP and Service Director, Burton Group, about the <a href="http://www.rsa.com/pci">PCI Data Security Standard</a> and how businesses are responding to this &quot;cookbook&quot; of guidance. She also takes part in RSA's 5-part <a href="http://info.rsasecurity.com/2007Am/webcast/070417PCI/online_RSAweb.html">PCI Perspectives 2007 Web Seminar Series</a> this week.</p>Speaking of Security Podcast #59blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1183Mon, 23 Apr 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1183<p><a href="https://www.rsa.com/blog/podcasts/070423_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (10:00).<br><br>Last week's <a href="http://www.irs.gov/individuals/article/0,,id=155344,00.html">U.S. Federal Income Tax Returns</a> were due and with that deadline we've seen an increase in phishing attacks by fraudsters on unsuspecting filers. Paul Joyal speaks with Jens Hinrichsen, <a href="http://rsa.com/node.aspx?id=3017">Product Marketing Manager</a>, RSA, The Security Division of EMC, about this and other prevalent crimeware threats that are proliferating our inboxes, web browsers, and telephones.</p>Speaking of Security Podcast #58blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1182Mon, 16 Apr 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1182<p><a href="https://www.rsa.com/blog/podcasts/070416_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (06:44).</p><p>Created by the major payment card brands, the <a href="http://www.rsa.com/glossary/default.asp?id=1093">Payment Card Industry Data Security Standard</a> (PCI DSS) is global in scope, and designed to ensure the security of consumer credit card data throughout the information lifecycle. Recently, an <a href="http://www.rsa.com/press_release.aspx?id=8123">RSA survey</a> asked businesses for opinions on issues related to PCI DSS including rates of compliance, perceptions of the standard, and motivations and challenges in meeting the PCI DSS requirements and we discuss the findings with RSA&#8217;s Dave Howell, <a href="http://www.rsa.com/pci">PCI Solutions</a> Marketing Manager, in this week&#8217;s podcast.</p>Speaking of Security Podcast #57blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1181Mon, 09 Apr 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1181<p><a href="https://www.rsa.com/blog/podcasts/070409_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (09:18).<br><br>The <a href="http://www.smartcardalliance.org/pages/activities-next-conference" target="_blank">6th Annual Smart Cards in Government Conference</a> takes place this week in Washington, D.C. We speak with Cathy Medich from the sponsoring organization, <a href="http://www.smartcardalliance.org/" target="_blank">Smart Card Alliance</a>, about how FIPS 201 PIV (Personal Identity Verification) Cards are being used for both physical and logical access. Peter Beardmore of RSA also shares some information about how different agencies' HSPD-12 deployments are being handled.</p>Speaking of Security Podcast #56blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1180Mon, 02 Apr 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1180<a href="http://www.rsa.com/blog/podcasts/070402_SecurityPodcast.mp3">Click here to listen/download</a> (09:57). Information security is an ever-changing and evolving industry and those of us who work in it sometimes have trouble feeling "secure" in our career choice. This week, Mike Murray <a href="http://www.episteme.ca">www.episteme.ca</a>, a security blogger, podcaster, and writer <a href="http://www.forgettheparachute.com">www.forgettheparachute.com</a>, speaks with Paul Joyal about this--and other security-related topics.Can Congress Help Stop Identity Theft?blog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1179Wed, 28 Mar 2007 00:00:00 GMTblog@rsa.com (Shannon Kellogg)http://www.rsa.com/blog/blog_entry.aspx?id=1179If you read Ira Winkler's March 26, 2007 <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=286666&pageNumber=1">op-ed at Computerworld.com</a> the resounding answer appears to be a 'yes'. Winkler seems to say that all Congress has to do is pass legislation that includes very specific requirements aimed at current threats in cyberspace (primarily Botnets); that Congress should make ISPs "knock bot PCs off their networks"; and that others should take certain steps. He also argues that Congress should "...Make end users liable if losses are incurred as a result of outdated security software." Speaking of Security Podcast #55blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1177Mon, 26 Mar 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1177<p><a href="https://www.rsa.com/blog/podcasts/070326_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (06:04).<br><br> <a href="http://www.myspace.com/vintageredband" target="_blank">Steve Dolnack</a> is a Security Practice Manager for <a href="http://www.mtm.com/" target="_blank">MTM Technologies</a>, a leading provider of innovative IT solutions and services based in Stamford, CT. Steve speaks with Paul Joyal about using <a href="http://www.rsa.com/node.aspx?id=3182">SIEM</a> (Security Information Event Managerment) to aggregate massive amounts of network and security data while improving visibility into networks for compliance reporting, security forensics, and more.Building the Security "In" is the Way to Goblog@rsa.com (Chris Parkerson)http://www.rsa.com/blog/blog_entry.aspx?id=1178Sun, 25 Mar 2007 00:00:00 GMTblog@rsa.com (Chris Parkerson)http://www.rsa.com/blog/blog_entry.aspx?id=1178Last week, Seagate Technology <a href="http://www.siliconvalley.com/mld/siliconvalley/business/special_packages/16886071.htm">announced</a> that it had begun shipping disk drives with built-in encryption technology for data stored on its disks. Such an implementation ends up transparent to the end user because it takes advantage of advances in encryption hardware to encrypt and decrypt information "on-the-fly" - which means that it is done while written and read from the disk...Speaking of Security Podcast #54blog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1176Mon, 19 Mar 2007 00:00:00 GMTblog@rsa.com (Podcast Producers)http://www.rsa.com/blog/blog_entry.aspx?id=1176<a href="https://www.rsa.com/blog/podcasts/070319_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (08:53).<br><br>What are some of the key strategies and solutions available that address corporate concerns and enable organizations to protect confidential data from unintended exposure? Paul Joyal interviews Security Analyst <a href="http://www.enterprisestrategygroup.com/OurTeam/TeamBio.asp?TeamMemberID=8" target="_blank">Jon Oltsik</a> of <a href="http://www.enterprisestrategygroup.com/" target="_blank">Enterprise Strategy Group</a> to get some answers. You may also catch Jon on an RSA Web Seminar: <a href="http://www.rsa.com/webseminars">Real-World Strategies for Protecting Your Data</a> for more helpful information.