IT Audit — News

The week in security: Google fights app malware, long-term PCI compliance plummets

Government requests for Facebook continued to grow in the second half of 2014, the company's latest transparency report has confirmed. And, speaking of transparency, some vendors were worried by findings by Verizon that 80 percent of PCI DSS-compliant firms fail to stay compliant in the year after their certifications – leading some to push the PCI Council to accept software-based encryption]] as well as the current hardware-based encryption it requires.

David Braue | 23 Mar | Read more

The human firewall has a soft spot: you

For all the talk about the importance of new security technologies, the importance of staff buying into corporate security strategies is often underestimated. In every case, the predictable result is the same: a strong technological barrier whose effectiveness is immediately compromised once a legitimate user, with legitimate access to internal resources, clicks on a phishing email designed to load malware onto their computer.

David Braue | 12 Mar | Read more

The week in security: FREAKing out as bug joins human, nation-state threats

Even as DDoS attacks were outed as the biggest security concern for a range of businesses, the FREAK vulnerability spawned all sorts of puns and had security pundits concerned about the integrity of secure connections between computers and Web sites. CSOs were encouraged to check if they were vulnerable to the bug, while Apple moved quickly to squash it in its latest version of iOS and Microsoft confirmed that Windows is also vulnerable.

David Braue | 11 Mar | Read more