Auditing Cookies

by May 05th 2012 Virtual CISO

A cookie is a small file saved locally on a computer by a web browser. The cookie contains details that websites place on their visitors. computers, and despite the relatively small size of the cookie, it can reveal a wealth of information website visitors may not be eager to share. The Information Commissioner.s Office (ICO) provides specific guidance on the Privacy and Electronic Communications Regulations acts compliance and recommends that a cookie audit is performed.

read the full article

Googling for Files

by May 13th 2012 Scripts

Googling for files: filetype:rtf | filetype:ppt | filetype:pptx | filetype:csv | filetype:xls | filetype:xlsx | filetype:docx | filetype:doc | filetype:pdf ["your_search_term" OR "your_search_term"] [site:yourdomain.com OR site:yourdomain.co.uk] intitle:”index of $something” (your_search_term1 , your_search_term2 , your_search_term3 , your_search_term4 , etc) [site:yourdomain.com OR site:yourdomain.co.uk]

read the full article

Googling for Pastebins

by May 13th 2012 Scripts

Googling Pastebins [your_search_term(s)] inurl:commitcode.com [your_search_term(s)] inurl:clippy.tk [your_search_term(s)] inurl:codepad.org [your_search_term(s)] inurl:codetidy.com [your_search_term(s)] inurl:www.codeupload.com [your_search_term(s)] inurl:diffboard.com/ [your_search_term(s)] inurl:dpaste.com [your_search_term(s)] inurl:dpaste.org [your_search_term(s)] inurl:dragbox.org/ [your_search_term(s)] inurl:dumpz.org/ [your_search_term(s)] inurl:gist.github.com/ [your_search_term(s)] inurl:hastebin.com/ [your_search_term(s)] inurl:hpaste.org [your_search_term(s)] inurl:ideone.com [your_search_term(s)] inurl:jsbin.com [your_search_term(s)] inurl:kpaste.net [your_search_term(s)] inurl:mathb.in [your_search_term(s)] inurl:mathbin.net [your_search_term(s)] inurl:meetog.com [your_search_term(s)] inurl:mysticpaste.com [your_search_term(s)] inurl:defuse.ca/pastebin.htm [your_search_term(s)] inurl:likecode.ru [your_search_term(s)] inurl:ourway.ir/pastebin [your_search_term(s)] inurl:paste.frubar.net [your_search_term(s)] inurl:paste.info.tm [your_search_term(s)] inurl:paste.kde.org/ [your_search_term(s)] [...]

read the full article

Do you fear the auditor more than the attacker

by May 03rd 2012 Virtual CISO

Do you fear the auditor more or the attacker? It is a key question for IT leaders thinking of dabbling in on-demand computing provision through the cloud. For many information security officers, there is only one answer, particularly for firms operating in highly regulated sectors: A lot of companies fear the auditor more. If you [...]

read the full article

Optimising Information Security in an Outsourced Environment

by May 03rd 2012 Virtual CISO

The outsourcing of IT infrastructure and applications within business is growing in popularity primarily with the growth of .cloud. computing and its ability to increase flexibility, access and speed as well as the reduction in operation costs. Information security within these environments must be placed within the context of the overall businesses. information security program. This program should include risk and incident management, continuity planning and compliance/governance management, each directly aligned to the overall outsourcing strategy adopted by the business. Doing so will require the combined efforts of everyone within the business with an emphasis on the key stakeholders ensuring the security of the outsourced IT systems and information repositories.

read the full article

Human Side of Security

by April 19th 2012 Virtual CISO

In 2009 Peter Bassill, then the Chief Information Security Officer for Gala Coral Group, wrote that one of the hot topics for many information security officers and almost all suppliers within the IT security industry the was reducing the potential for Data Loss. Today we are in 2012 and over the last four years not [...]

read the full article