Security News

Learn the art of malicious compliance: doing exactly what you were asked, even when it's wrong
2023-02-13 08:28

Now, as for the job itself, Steve was in the "Salesman support/office/data processing section." The computer system in use at the time was an IBM system 3, with tub files of 96-hole punch cards for sales order processing, inventory management, and reporting. Steve tells us "The punch cards were kept with the sales orders until order completion/delivery, or pickup, with some orders awaiting on-order inventory for later pickup."

As regulations skyrocket, is compliance even possible anymore?
2023-02-13 05:00

Let's face it, security teams are only as good as the next problem they face. Why is keeping up so difficult? New/evolving requirements, lengthy/confusing acronyms, and countless moving parts plague compliance regulations.

The future of vulnerability management and patch compliance
2023-02-01 04:38

IT departments continue to face immense pressure to get vulnerability and patch management right as threat actors use new and old methods to exploit network endpoints. Are we ready for what's next? As vulnerabilities continue to increase, what strategies should security professionals use to gain visibility into these threats, prioritize them, and manage the ongoing risk to endpoints? What will the vulnerability landscape look like in 2023, and what new challenges will security and IT teams face?

Using the Wazuh SIEM and XDR platform to meet PCI DSS compliance
2023-01-31 15:05

An example of a solution that helps meet PCI DSS compliance requirements is Wazuh. Wazuh helps implement PCI DSS compliance by performing log analysis, file integrity checking, configuration assessment, intrusion detection, real-time alerting, and automated response to threats.

Guide: How MSSPs and vCISOs can extend their services into compliance readiness without increasing cost
2023-01-18 10:32

Compliance services are emerging as one of the hottest areas of cybersecurity. This is a major opportunity for providers of virtual CISO services assuming they can broaden their offerings to encompass compliance.

Guide: How virtual CISOs can efficiently extend their services into compliance readiness
2023-01-10 03:45

Compliance services are emerging as one of the hottest areas of cybersecurity. As large businesses adopt cybersecurity and compliance frameworks and agree to certain standards, they impose similar demands on their suppliers.

Why automation is critical for scaling security and compliance
2022-12-09 04:30

This is where automation is critical to scale security and compliance. Automation enables compliance and security standardization.

How compliance leaders can encourage employees to report misconduct
2022-12-08 04:00

As Chief Compliance Officers continue to face challenges in restoring employee misconduct reporting to pre-pandemic levels, there are three strategies they should implement to increase confidence in their processes among employees, according to Gartner. "There are clearly structural challenges that have impaired effective misconduct reporting, ranging from new working models, to higher employee turnover, and increased societal polarization," said Chris Audet, VP, research, in the Gartner Legal, Risk & Compliance practice.

14 PCI Compliance security best practices for your business
2022-11-24 13:38

PCI compliance is a structure based on requirements mandated by the Payment Card Industry Security Standards Council to ensure that all companies that process, store or transmit credit card information maintain a secure operating environment to protect their business, customers and confidential data. The PCI SSC was created by Visa, MasterCard, American Express, Discover and Japan Credit Bureau to administer and manage the PCI DSS. Companies which adhere to the PCI DSS are confirmed PCI compliance and thus trustworthy to conduct business with.

14 PCI compliance security best practices for your business
2022-11-24 10:04

PCI compliance is a structure based on requirements mandated by the Payment Card Industry Security Standards Council to ensure that all companies that process, store or transmit credit card information maintain a secure operating environment to protect their business, customers and confidential data. The PCI SSC was created by Visa, MasterCard, American Express, Discover and Japan Credit Bureau to administer and manage the PCI DSS. Companies which adhere to the PCI DSS are confirmed PCI compliance and thus trustworthy to conduct business with.