Email Alerts
-
VoIP security strategy helps WNS tackle cross-party risk
Indian BPO major WNS ensures robust risk management and PCI-DSS compliance through simple VoIP security solution, despite outdated client infrastructure. Case Study
-
Airtel's ISO 27001 certification tale: Benefits, challenges & lessons
Leading Indian telecom player Bharti Airtel’s ISO 27001 implementation is one of the largest in the world. Join us, as we take a peek under the hood. Case Study
-
HDFC Bank’s ISO 27004 compliant security metrics a boost toward GRC
An ISO/IEC 27004 compliant metrics program is a rarity in the Indian infosec circuit. Indian BFSI major HDFC Bank’s ISMS has been there, done that. Case Study
-
Network security assessments: India Inc. is going beyond routine
As network security assessments become essential hygiene, security experts at Indian enterprises are honing in to specifics. Some tips, insights and advice. Feature
-
Vodafone India’s PCI DSS compliance journey: A dissection
With Vodafone India’s PCI DSS compliance journey in its third iteration, we share practical PCI DSS tips and ground realities from the telecom major. Feature
-
India Inc guns for SIEM tools as maturity, viability drive growth
SIEM tool adoption in India is rising, spurred by growth in maturity of both SIEMs and organizations. We take a broad status check of the Indian SIEM space. Feature
-
nullcon Tritiya’s infosec conference: Day 1 walkthrough
Join us, as we take a look at the third installment of annual information security conference nullcon 2012. Photo Feature
-
Airtel’s DLP technology rollout makes data egress a thing of the past
Airtel’s DLP technology implementation, India’s largest, went live in December 2010. Join us in exploring its inner workings, even as it is poised for bigger things. Feature
-
BYOD security: Where does India Inc stand?
With the proliferation of smart devices, BYOD security is a major concern for enterprises today. Find out how the leaders are coping with BYOD security. Feature
-
The IT (Amendment) Act 2008 Guide: Mapping India’s infosec revolution
Starting with the establishment of the Information technology (Amendment) Act 2008, we chart the timeline of how Indian infosec has seen regulation. Tutorial
- See more Essential Knowledge on Business compliance management
-
PCI Council: Risk assessment methodology unique to company environment
The PCI Risk Assessment Special Interest Group concludes that risk assessments are based on a company's unique risk tolerance and environment. News | 19 Nov 2012
-
ISACA to revamp IS Audit and Assurance Standards
Risk and compliance knowledge provider ISACA issues an exposure draft of IS audit standards; seeks feedback from Indian technology professionals. News | 01 Nov 2012
-
Users neglect enterprise mobile device security measures, survey finds
Some employees are failing to enable security capabilities on their smartphones and tablets, putting corporate email and other sensitive data at risk. News | 23 Oct 2012
-
Application vulnerability disclosures rise, Microsoft finds
The Black Hole attack toolkit is fueling many of the exploits targeting the vulnerabilities, according to Microsoft. News | 11 Oct 2012
-
Age-old vulnerabilities, attack techniques consistently trip enterprises
Windows security has improved, but longstanding Unix and network vulnerabilities remain an easy target for determined attackers. News | 02 Oct 2012
-
CISOs struggle with visibility, complexity in enterprise risk management
McAfee says organizations must juggle visibility, system complexity challenges when balancing compliance-driven priorities with the threat landscape. News | 29 May 2012
-
P2P encryption for mobile is not an technology endorsement, says PCI Council
The PCI Council will continue to issue recommendations for mobile payment security, according to Bob Russo, general manager of the PCI SSC. News | 25 May 2012
-
PCI Council urges P2P encryption for mobile payments
A PCI Council guidance document requires merchants to use a validated PIN entry device or secure card reader to accept payments using mobile devices. News | 16 May 2012
-
Android security model doing best to enable mobile malware spread
At Information Security Decisions 2012, Dan Guido put the mobile malware focus on the Android security model and Google’s mobile app vetting process. News | 16 May 2012
-
PCI virtualization compliance still a challenge
No black and white when it comes to PCI compliance in virtualized environments, experts say. News | 09 May 2012
- See more News on Business compliance management
-
Audits and compliance requirements for cloud computing
Even as India Inc experiments with the cloud, security concerns play spoilsport. These cloud computing audit and compliance tips will make your journey easier. Tip
-
PCI validation: Requirements for merchants covered by PCI DSS
Mike Chapple details the PCI validation requirements for merchants covered by PCI DSS. Tip
-
Five data classification mistakes you must avoid at all costs
Optimal data classification is a robust foundation to ensure efficacy of infosec initiatives. Here’s the Indian organizations’ checklist on what not to do. Tip
-
Leading Indian banking portals contain glaring security lapses
Even as Internet banking portals transform the way Indians bank, vulnerabilities exist in banking websites like SBI, Citibank India, HDFC Bank and ICICI Bank. Tip
-
How to comply with updated NIST incident response guidelines
NIST recently updated its incident response guidelines. Find out how to comply with these changes and incorporate them into an incident response plan. Tip
-
Tips to overcome information rights management implementation challenges
Information rights management provides foolproof protection for information, but lack of awareness in India often prevents successful IRM implementation. Tip
-
Vulnerabilities in JavaScript: Secure coding insights and tips
JavaScript vulnerabilities are on the rise in India with the entry of HTML5 and faster JavaScript engines. Here are some key problem areas along with antidotes. Tip
-
Limitations of two factor authentication (2FA) technology
The common two factor authentication (2FA) techniques used In India have several shortfalls. We take a look at security risks associated with 2FA solutions. Tip
-
Information security controls for data exfiltration prevention
Enterprises may be amazed to discover how valuable their data is to attackers. Learn five information security controls to prevent data exfiltration. Tip
-
Multiple compliance management fundas from Bank of India
Optimize the management of multiple compliance frameworks in your organization with these tips from Bank of India’s CISO Sameer Ratolikar. Tip
- See more Tips on Business compliance management
-
Security vs. compliance: Moving beyond a 'checkbox security' mentality
Mike Chapple discusses the compliance vs. security challenge and why a "checkbox security" mentality may actually be a good thing. Answer
-
Securing big data: Architecture tips for building security in
Expert Matt Pascucci advises a reader on securing big data with tips for building security into enterprise big data architectures. Answer
-
Paladion
Paladion Networks is a Bengaluru, India-based provider of information security products and services. Definition
-
Mahindra Special Services Group (MSSG)
Mahindra Special Services Group (MSSG) is a corporate security consultancy firm. Definition
-
Network Intelligence India Pvt. Ltd. (NII Consulting)
Network Intelligence India Pvt. Ltd. (NII Consulting) is an Indian provider of information security services and products. Definition
-
knowledge process outsourcing (KPO)
Knowledge process outsourcing (KPO) is the allocation of relatively high-level tasks to an outside organization or a different group within the same organization. Definition
-
Highlights from PwC’s State of Information Security Survey, India 2013
We bring you excerpts from PwC’s India survey on the state of information security as part of this photofeature. Photo Story
-
Adopting BYOD culture sans chaos: An Indian perspective
The bring your own device (BYOD) concept is changing security and cost paradigms. We look at BYOD considerations for Indian businesses in this series. Photo Story
-
Compliance reporting forces risk management, security evolution
In this podcast, analyst Chris McClean discusses how increasingly complex compliance reporting requirements force closer scrutiny of risk management and security processes. Podcast
-
The effects of PCI DSS, compliance requirements on the security industry
Paul Judge of Barracuda Networks and Joshua Corman of the 451 Group discuss whether compliance hinders the creation of innovative security technologies. Discussion
-
Default deny security: How to implement a positive security model
What is 'default deny' security? How difficult is the implementation process, and how could you sell it to executives? In this video, expert Mike Rothman explains how a positive security model works and how to decide if it's right for your enterprise... Video
-
GRC tools high on HDFC Bank’s infosec priorities for 2011
HDFC Bank lists governance, risk and compliance as its top information security priority for 2011. Investments in GRC tools on the charts for next year. Video
-
Face-off: Information security awareness and when not to reveal information
Can the security industry learn from the Transportation Security Administration? It may seem like an odd pairing, but both struggle with the challenges of protecting those in their care while maintaining usability and personal privacy. Video
-
Risk management in information technology
Get advice on creating a strategy for mitigating information security risk from expert Nick Frost of the Information Security Forum. Video
-
The future of PCI DSS
Bob Russo, General Manager of the PCI Security Standards Council, discusses upcoming changes to the PCI DSS, including what new changes might be mandated, and when they might go into effect. Video
-
Metasploit and software vulnerability testing
Metasploit is a free tool that can be used to pen test for new and potentially damaging vulnerabilites. In this interview, H.D. Moore, creator of Metasploit, explains how the tool works and what it can contribute to software security. Video
- See more Multimedia on Business compliance management
-
Audits and compliance requirements for cloud computing
Even as India Inc experiments with the cloud, security concerns play spoilsport. These cloud computing audit and compliance tips will make your journey easier. Tip
-
Highlights from PwC’s State of Information Security Survey, India 2013
We bring you excerpts from PwC’s India survey on the state of information security as part of this photofeature. Photo Story
-
PCI validation: Requirements for merchants covered by PCI DSS
Mike Chapple details the PCI validation requirements for merchants covered by PCI DSS. Tip
-
VoIP security strategy helps WNS tackle cross-party risk
Indian BPO major WNS ensures robust risk management and PCI-DSS compliance through simple VoIP security solution, despite outdated client infrastructure. Case Study
-
PCI Council: Risk assessment methodology unique to company environment
The PCI Risk Assessment Special Interest Group concludes that risk assessments are based on a company's unique risk tolerance and environment. News
-
Five data classification mistakes you must avoid at all costs
Optimal data classification is a robust foundation to ensure efficacy of infosec initiatives. Here’s the Indian organizations’ checklist on what not to do. Tip
-
ISACA to revamp IS Audit and Assurance Standards
Risk and compliance knowledge provider ISACA issues an exposure draft of IS audit standards; seeks feedback from Indian technology professionals. News
-
Users neglect enterprise mobile device security measures, survey finds
Some employees are failing to enable security capabilities on their smartphones and tablets, putting corporate email and other sensitive data at risk. News
-
Leading Indian banking portals contain glaring security lapses
Even as Internet banking portals transform the way Indians bank, vulnerabilities exist in banking websites like SBI, Citibank India, HDFC Bank and ICICI Bank. Tip
-
How to comply with updated NIST incident response guidelines
NIST recently updated its incident response guidelines. Find out how to comply with these changes and incorporate them into an incident response plan. Tip
- See more All on Business compliance management
About Business compliance management
Learn how to leverage information security readiness for business and regulatory compliance. Craft comprehensive compliance risk management strategies and explore compliance management best practices. Leverage security and compliance frameworks for business growth.