The Smart Grid, It's All About Security
March 12, 2010
By Brian Monkman

All too often you read about security breaches that cost firms millions of dollars or hit individuals with loss of personal data or both. But all this pales in comparison when you consider the implications of a security breach somewhere on the electrical grid.
 
Plausible scenario #1
 

Comments

Post new comment

Malware – It keeps going, and going and going…
March 11, 2010
By Andrew Hayter

Would it not be enough for you to worry about picking up a malware infection via an e-mail, infected program or social media Web site.  Now consumers have to worry about every intelligent device they plug into your computer. This is not new news. We have already seen reports of infected digital picture frames, GPS devices, etc. The latest non-techie device to spread malware is a battery recharging unit.  Yup, that’s right – battery recharging unit. The Duo Charger, USB-powered battery recharger contains malicious code.

Comments

Post new comment

Why a Test Lab Needs to be Wary of Commercial Exploit Packet Captures
February 23, 2010
By Jack Walsh

When it comes to testing coverage protection for their network intrusion prevention system (IPS), enterprise end users may use a commercial tool that contains and replays many exploit packet captures.[1]    

Comments

Post new comment

White Paper Issued: "Third-Party Assurance as a Component of the Enterprise Product Selection Process"
February 19, 2010
By Al Potter

I hinted in the reply to a comment on one of my earlier postings (Looking to make certified products a proposal requirement?

Comments

Post new comment

ICSA Labs Making News Again
February 15, 2010
By Al Potter

Well, looks like Andy and I are making news again! I have an opinion piece on a familiar topic just published in Government Security News and Andy is featured in SC Magazine.

Take a look and let us know what you think.

Comments

Post new comment

Happy Valentines Day -- here’s your malware.
February 11, 2010
By Andrew Hayter

Pick a holiday, any holiday, and get ready for targeted, malicious email.  

Comments

Post new comment

Looking to make certified products a proposal requirement? Look here for sample language.
January 6, 2010
By Al Potter

Today (January 6) we issued a press release (available here www.icsalabs.com/press-release/icsa-labs-offers-tips) with tips on how business and government agencies can use independent product assurance from a third party to simplify the Request for Proposal (RFP) process. 

Comments

only applicable to consortia

only applicable to consortia or certification programs that are in existence. Not applicable to Security Information Event Management Solutions, MPLS End to End Application Security Products, Telecommunications, Call Data Recording Applications, Telecommunication Firewalls.

Full whitepaper in the works...

Very True, and a good point. There is a full whitepaper in the works which will deal with the topic at hand in more detail. It touches on this and other issues. You can get a glimpse of this in the words I supplied in the table. (paraphrased): If programs exist and map well to your requirements, require products to have gone through them. IF NOT, leverage what you can in terms of existing 3rd party results (ours and others) and favor those with credible 3rd party assurance.

Post new comment

ICSA Labs Issues Report that Exposes Common Flaws Among Security Products
November 16, 2009
By George Japak

Welcome to the launch of the ICSA Labs Blog.  We are excited about the opportunity to use our new blog as a forum for greater interaction with the security community at large, especially those with a vested interest in computing security.  

Comments

Post new comment