Thursday, August 27, 2015

takeaways from a lunch and learn on security which was at work today

  1. SIEM is pronounced "sim" and stands for Security Incident and Event Monitoring Suite and Splunk is a not-quite example on a SIEM.
  2. Airwatch allows device events to be recorded and it can tell if your employees are password protecting their smartphones.
  3. In PCI 3.1, SSL will not be allowed and TLS must be used instead and not just any TLS. The first two versions are seen as weak (I think).
  4. Sarbanes–Oxley makes corporate executives legally liable for their reporting. SSAE 16/SOC1 seems to be a standard for reporting.
  5. ITIL is Information Technology Infrastructure Library and is a set of good practices.
  6. SSO stands for Single Sign On.
  7. EU Safe Harbor is a standard for keeping data secure.

 
 

Addendum 9/30/2018: IT by itself is Information Technology. Duh.

No comments:

Post a Comment