Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
ComputerWorldNetwork WorldCIO CanadaCIO Canada Governments' ReviewJobUniverse Canada
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Unlock the potential of data with the right data warehouse solutionUnlock the potential of data with the right data warehouse solution read more
IBM Multiform Master Data Management: The evolution of MDM applicationsIBM Multiform Master Data Management: The evolution of MDM applications read more
Closing the data privacy gap: Protecting sensitive data in non-production environmentsClosing the data privacy gap: Protecting sensitive data in non-production environments read more
Yuk it Up
Featured White Paper
Desktop virtualization may be the answer to your company's remote access and business continuity/disaster recovery challenges. Learn about the key technologies and options currently available in the market - the pros and cons - through a whitepaper report from experts Info-Tech Research Group. This whitepaper - Desktop Virtualization: Compelling Option for Remote Access and Business Continuity - explains some options you might want to consider as your desktop virtualization solution. The report is complimentary with your registration. It is sponsored by Citrix Systems Inc.
In need of an IT security strategy, but don't know where to look? The Payment Card Industry's (PCI) Data Security Standard (DSS) guide is a great resource. Info-Tech Research Group's whitepaper - Need a Security Clue? The Answer is in the Cards - breaks down the key elements of the DSS guide in simple and most straightforward terms. Info-Tech Research Group's whitepaper - Need a Security Clue? The Answer is in the Cards - breaks down the DSS guide into its simplest and most straightforward elements. Highlighted in this whitepaper is an outline of the 12 control objects of the DSS guide and explains the essential requirements of each. The report has a value of $150 but is complimentary with your registration. It is sponsored by Citrix Systems Inc.
The need for application speed is paramount in today's business. There's little tolerance for even the slightest measure of network slowdown or performance impediment. Your applications and business processes must deliver when they're needed. The Info-Tech Research Group report - App Performance Management Rollout: "Big Bang" a Big Mistake - offers recommendations in how you might seek to approach application performance management (APM) and ensure the highest level of business readiness. The report has a value of $150 but is complimentary with your registration. It is sponsored by Citrix Systems Inc.
How can IT organizations protect sensitive data, including employee and customer information, as well as corporate confidential data and intellectual property? Industry analysts recommend "de-identifying" or masking data as a best practice for protecting privacy. This white paper explains the importance of closing the data privacy gap in non-production environments, and provides guidance on effective data masking. Complimentary with registration. Sponsored by IBM.
Featured IT Quiz
IT Quiz: Test yourself to see if you have the knowledge to fit into the open source world, and compare yourself with the rest of the respondents.
Featured Product Review
MailFrontier, Sophos, Symantec, and Trend Micro deploy effective spam combatants. Spam is such a significant problem these days that even the federal government has gotten involved, passing legislation such as the CAN-SPAM Act. Meanwhile, a wide variety of companies has collaborated on an authentication scheme called the Sender ID Framework, aimed at making e-mail fraud even harder to perpetrate. Realistically, though, neither CAN-SPAM nor e-mail-sender authentication is likely to do much to stem the flood of mail. Fortunately, anti-spam products continue to evolve and improve.
Sign-Up for
Security
eNewsletter Delivered Weekly
Click here
Page 1 of 1

Raising the red flag on Web 2.0

Advertisement

The move towards Web 2.0 technologies may well be another race between functionality and security, and for now at least, security seems to be at the tail end.

Security professionals are raising the red flag on the increasing pervasiveness of Web 2.0 technologies in the enterprise, saying that while it offers the benefit of rich applications, the risks associated with Web 2.0 can no longer be overlooked.

In the enterprise, for instance, a Web 2.0-enabled architecture involves applications built as Web services that provide cross-platform access and functionalities for users. “Like submitting a record to a database or changing a piece of data (for example),” says Oliver Lavery, a consultant with Toronto-based IT security firm Security Compass.

“The problem is that what’s being exposed there are very detailed, technical procedure calls — Web service calls — using all these new technologies that haven’t really been tested and [the industry doesn’t] have a lot of experience securing them,” Lavery says.

The increasing use of these new tools, without proper understanding of the security issues that may arise as a result, is giving attackers new avenues to explore, says Lavery.

Web 2.0-enabled social networking sites present another attack vector for the bad guys, as well. Web sites such as MySpace and Facebook have allowed people to actively interact and connect in real-time in ways they have never been able to before.

On the surface, the Web 2.0 craze may seem like a consumer phenomenon. But many security experts agree that its pervasiveness is going beyond people’s homes and into the workplace, as employees access these sites from their office computer.

“The most dangerous part of any computer system are the people who run it,” says University of Calgary professor Tom Keenan.

Advertisement

The use of mobile devices, like laptops that typically travel back and forth between the home and office, is not helping the situation either, added Keenan, who is also the IT security spokesperson for the Canadian Information Processing Society. 071496

Page 1 of 1
Send to a Friend  Rate This Page  Print This PageAdd a new comment

Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields


Related Content
Articles

Events

Special Advertising Partners
IDC Case Study: Identity And Access Management Buying Criteria.
IDC analyses IAM buying criteria and deployment at Coppin State University. Coppin State replaces "first generation" IAM solution to obtain benefits needed for today's agile enterprise: ease of integration, rapid deployment, simplified compliance, flexibility.
White Papers
Closing the data privacy gap: Protecting sensitive data in non-production environments
How can IT organizations protect sensitive data, including employee and customer information, as well as corporate confidential data and intellectual property? Industry analysts recommend "de-identifying" or masking data as a best practice for protecting privacy. This white paper explains the importance of closing the data privacy gap in non-production environments, and provides guidance on effective data masking. Complimentary with registration. Sponsored by IBM.
Unlock the potential of data with the right data warehouse solution
Once you've made the decision to implement a new data warehouse, you want to make sure you choose the one that's right for your organization. This buyer's guide provides checklists for starting points that you can use when evaluating vendors and their products. Complimentary with registration. Sponsored by IBM.
Prepare for a more efficient SAP implementation: Take data issues off the critical path
This white paper outlines how the Preliminary Data Assessment Appliance (PDAA) from IBM can help address the challenges of integrating data from different operational applications across the enterprise to an SAP platform. Complimentary with registration. Sponsored by IBM.
Address IT costs and streamline operations with IBM service request and asset management solutions.
This brochure describes how IBM service request and asset management solutions help IT integrate incident, problem, change and release management. Complimentary with registration. Sponsored by IBM.
Identify and leverage your existing service life cycles.
This executive brief illustrates the progression of service managemen