Quantcast
Channel: CSO Online - Stories by By Mathias Thurman RSS feed
Browsing all 15 articles
Browse latest View live

A checklist for SaaS vendors

Our manager’s company uses a lot of third-party vendors, and some of these relationships have been in place for years. What will happen when he goes back to assess their security risks?

View Article



In pursuit of HIPAA, a new compliance gap arises

Meeting requirements can be exhausting, but the business payoff can make it all worthwhile.

View Article

Stop Passing Around Those Passwords!

The company has sanctioned the use of an online password vault, so why is there a spreadsheet making the rounds that contains scores of passwords to servers that contain sensitive data?

View Article

The post-acquisition blues

The company calls in our manager to take a look around at a small software company it’s acquiring — after the deal has been signed.

View Article

Let the budget games begin!

Even when top management is enlightened about the importance of good security practices, a security manager needs to go into the budget meeting prepared.

View Article


Using compliance as a tool for change

Our manager leverages gaps in security compliance to enhance the security program.

View Article

SaaS risks come into focus

Sometimes, security risks are hiding in plain sight.

View Article

Trouble spotted on the network

No sophisticated SOC? You can still be pretty sure that you’re aware of anything potentially troublesome.

View Article


A nudge from ransomware

Our manager needs to get remote users’ PCs backed up without forcing them to connect to the network, which they rarely have to do these days to do their jobs.

View Article


Just a test? If only!

The DDoS attack against DNS provider Dyn finds our manager without a backup plan. That’s painful, especially when the plan had been to test incident response soon.

View Article

Putting security risks on simmer with Chef

A bit of automation can ease the PCI compliance burden.

View Article

The trouble with third-party assessments

If you let one customer perform security tests against your applications and network, you let yourself in for a lot of headaches.

View Article

Getting buy-in to combat risk

A risk council with stakeholders from across the company could be an effective way to get needed resources to mitigate the worst security risks.

View Article


RSA Conference is a timesaver

For our manager, the annual security gathering is a great way to get quality time with vendors.

View Article

Email, email, in the cloud

The transition from on-premises to cloud-based email is an opportunity to tighten security controls.

View Article

Browsing all 15 articles
Browse latest View live




Latest Images