Problems with Automated IT Inventory and Audit Tools

Jason Keogh, CTO and Founder of iQuate
Traditional IT inventory and audit packages are invaluable for analyzing risk across the IT estate. In effect they widen the audit universe. However, how much trust can be placed in the data they gather? These tools can form the foundation for expensive IT business decisions (license management, infrastructure refreshes, etc.) however if the information is incomplete, out of date or inaccurate they bring their own set of risks. This session will discuss problems with traditional audit tools and potential controls and alternatives
May 14 2009
49 mins
Problems with Automated IT Inventory and Audit Tools

Webinars and videos

  • Live and recorded (1059)
  • Upcoming (47)
  • Date
  • Rating
  • Views
  • Cosa sta DAVVERO succedendo? Il Security Threat Report
    Il Security Threat Report fornisce una panoramica e un'analisi di attività delle minacce a livello mondiale nel 2012. Dai dati della Global Intelligence Network, esperti di Symantec analizzano le tendenze emergenti negli attacchi, nelle vulnerabilità e negli obiettivi.
    Inoltre, l’ultima ricerca “Cost of a Data Breach Report 2013” traccerà gli impatti economici per le organizzazioni nel caso di attacchi informatici
    Partecipa a questo webcast per avere un aggiornamento sul panorama delle minacce e della sicurezza nel 2013 e sulle conseguenze nel business.
  • Pour limiter les risques d’une cyber-attaque, la politique de sécurité doit comprendre la mise en place d’une politique de supervision incluant la surveillance des vulnérabilités, la corrélation des événements de sécurité, les procédures de réponse en cas d’attaque… Lors de ce webcast, nous vous invitons à faire le point sur les solutions de SOC, SSIEM, Services Managés et leurs bénéfices.
  • Virtualization, cloud computing, hybrid environments and BYOD are here to stay. When implemented successfully, these solutions can transform the way businesses operate and lower the OPEX and CAPEX costs of IT departments. However, these major IT trends cannot be considered separately: virtualization and cloud are often linked, and needs for anytime anywhere connectivity and mobile workforce enablement won't wait. This is why it's essential to have a holistic approach and address the business, technology and financial implications of today for tomorrow's needs.


    Dell has quickly become one of the largest and fastest growing networking providers in the world by leveraging its extensive expertise in the data center to build a complete portfolio of switches that are designed to be open, flexible, powerful and economical.
  • Don't be caught off guard when your auditors show up and start asking internal control questions that you can't answer. In this roundtable session, listen, learn, and share your experiences around managing your internal control system with your ERP system and what to be prepared for BEFORE the auditors show up. There are always tips to learn from others in the compliance area and this session traditionally has lively dialogue, so don't miss this opportunity to prepare for your next audit.
  • Live from HP Discover 2013, Frank Nishimori, Technical Consultant, will be announcing new HP products as they're released and the vision of where storage is headed.
  • Establishing PCI DSS compliance can be extremely resource intensive. For medium to large organizations, the many tasks involved in documenting, tracking and auditing network security procedures manually can take days. With an automated firewall operations, auditing and compliance solution, companies can substantially reduce the time and cost of PCI DSS compliance as it applies to the management of firewalls, routers and related network security infrastructure. Learn how to reduce the amount of time required for audit preparation by more than 50%, while enabling continuous compliance with the PCI standard.
  • Even the most successful MSP’s find it hard to build and manage an effective sales force. Are you recruiting the right sales people, with the right skills, managing their performance effectively, providing them with the correct sales tools, and pointing them at the right target markets in line with your range of products and services?

    Without a sale, there is no business. Without a sales team your growth will be limited.

    Steve Potts, Paul Fileman and Adam Harris from Transmentum will explain how to go about recruiting, training, motivating and retaining an effective sales team.

    Join the webinar and learn how to:

    - Recruit sales people that represent your business professionally
    - Run effective sales meetings that both hold people to account and motivate your sales team
    - Know the difference between hunters and farmers – and why you need both
    - Create an effective sales process that drives profitable business growth
  • Jan Teichmann, our SAP HANA Mobility expert, will present how you can develop mobile applications in the cloud with SAP HANA One in only 20 minutes. Learn from our expert and be ready to build your own mobile SAP HANA apps by the end of this session.

    Teichman's blog on mobile development with the Android SDK and SAP HANA received 55k hits in the first week it was published. Join our session and see:
    - How to deploy the Android SDK on SAP HANA One
    - Actual code samples and step by step instructions for building mobile SAP HANA apps
    - How HANA One will simplify your environment creating one place where you can easily build and run your mobile app in the cloud
  • Software Defined Storage. Is it just another buzzword or can the concept bring meaningful change to the way storage is acquired, implemented and used? As vendors race to jump on the "software defined" bandwagon, Storage Switzerland set out to explain the term, provide users with an understanding of how software defined storage can solve many of their current storage challenges and provide a way to decide which vendors are really delivering a software defined storage future.
  • Companies are looking to accelerate sales and marketing processes to drive revenue growth. To become hyper-competitive, companies have dropped fax and paper and are moving to the cloud to enable collaboration, finalize agreements and get digital signatures. In a mobile world, companies must collaborate easily and securely, anywhere, on any device, and gain instant insight into where an agreement stands. See how companies are using Box and DocuSign to accelerate revenue, enhance visibility, and get business done at lightning speed.
You might also like: Guard Your Business When Disaster Strikes
  • Channel
  • Channel profile
Up Down
  • Big Data: Privacy Threat or Business Strategy? Sep 12 2013 2:00 pm UTC 60 mins
    Big data has the potential to unlock data analytics to a whole new level. With more data comes more targeted predictive analytics, marketing, security measure and more. However, as you collect more data, especially about people, privacy becomes an issue. How much data about one person is too much data? Where do we draw the line between good business practices and invasion of privacy?

    Attend this webinar as this panel of experts discover where that line lands and which questions should you and should you not be asking from big data.
  • SSD vs. HDD - Risks and Side Effects of Flash Technology Aug 15 2013 2:00 pm UTC 45 mins
    Storage technology is trending towards solid state drives (SSD) across all platforms from mobile devices all the way to the data center. Regardless of the user perception that SSD/Flash is safer and more robust than traditional HDD, a recent survey compiled by Kroll Ontrack amongst 500 IT professionals reveals that 57 percent of respondents had experienced data loss with SSD/Flash technology.

    Peter Böhret, VP Europe, Kroll Ontrack will discuss the risks and technical considerations relating to the use of SSD/Flash technology in a disaster recovery scenario, from the viewpoint of the world’s leading specialist in data recovery. The presentation will cover an overview of key technology differences HDD vs. SSD, highlight disaster recovery challenges in SSD infrastructures, outline SSD data security considerations and provide guidance about SSD usage based on real life data loss scenarios.
  • Maintaining Security In an Always-On World Jul 18 2013 4:00 pm UTC 45 mins
    In this post-PC era, people work from outside the office on smart phones, tablets and laptops. They use unsecured Wi-Fi at airports, coffee shops and hotels. And the rise of cloud-based applications has enabled employees to access critical data without connecting back to headquarters through a VPN. As the lines between when, where and how work gets done continue to blur, and IT continues to lose visibility and control, security risks increase. Yet, despite the rapidly shifting technological landscape, exploding device diversity, and the rising work-anywhere culture, security solutions still focus on how to secure corporate networks. This session will discuss how businesses can leverage the cloud to seamlessly deliver security to users, wherever they choose to work.
  • Enhancing MDM's to Protect User Privacy through App Reputation Jul 17 2013 5:00 pm UTC 45 mins
    Today’s MDM solutions are effective at lost device and malicious app protection, ensuring passwords are used and separating and securing both personal and corporate information on the same device – but what about protecting against apps with shady privacy practices? For instance, apps whose developers monetize through imbedded advertising engines which pay based on the amount of user data collected. Or, apps which insecurely store, access and/or transmit user data. How can IT admins protect against the choices users are making when installing 3rd party apps? From a security perspective, this area needs to be addressed before corporate and personal data is compromised. As a result, a mobile application reputation service for Android and iOS platforms is required to specifically address the issues of shady apps. By analyzing dozens of key metrics, app reputation analysis greatly assists in the decision making process when it comes to a user installing a new app. By being able to immediately alert the user to the potential security risks, or poor security practices, it provides an informed opportunity for them to compare the app against other similar, yet more secure, apps.
  • The Irresistible Force of BYOD – How to Get it Running Securely Jul 16 2013 5:00 pm UTC 45 mins
    From increasing productivity to reducing operational costs, it's time for companies to look at how they be more effective with BYOD. Join Marco Nielsen, VP of Services at Enterprise Mobile, as he shares how to optimize your BYOD strategy and execution, how to make the most of your existing management solutions and how to address security challenges that have arisen from a much more diverse mobile device and application landscape.
  • Panel: Is BYOD Security An Oxymoron? Jul 16 2013 4:00 pm UTC 45 mins
    Bring Your Own Device (BYOD) policies have led to the consumerization of IT in the enterprise that delights business users, but creates security challenges for IT departments.
    This panel discussion will discuss the security challenges that personal smartphones and tablets can bring to organizations. It will also examine what can be done to strengthen the security posture of a company with a BYOD policy. Topics that will be discussed include:

    Malware, rooted devices, & remediation
    Policies & policy enforcement
    Mobile Device Management (MDM)
    Digital containers for enterprise data
    BYOD security best practices
  • To BYOD or Not to BYOD, That is the Question… Jul 16 2013 10:00 am UTC 45 mins
    A 2012 global survey reported that 88% of consumers use a personal mobile device for work. This year, Gartner has gone further, predicting that 50% of employers will stop providing devices by 2017, requiring employees to bring their own. If a bring your own device (BYOD) programme doesn’t already exist in your organisation, you need to start thinking now of the risks and if and how they can be managed. This webinar will discuss the continuing BYOD and mobile device in the workplace trend and offer an information-centric approach to assessing and managing the associated risks. It will provide insight and guidance on the implementation of BYOD programmes and in particular, discuss how to:

    · Take a risk-based approach to implementing BYOD projects

    · Identify the risks and threats posed by employee-owned devices connecting to the organisation’s systems

    - Conduct analysis of the business impacts that BYOD incidents could present

    · Assess the organisation’s vulnerabilities to those threats

    · Adopt and learn from BYOD leading practices

    The audience for this webinar is Chief Information Officers (CIOs), Chief Information Security Officers (CISOs), executives responsible for BYOD programmes, their direct reports, and all others participating in committees or working groups responsible for managing BYOD programmes.
  • The Consumerisation of Corporate IT - Stories from the Front Line Jul 16 2013 9:00 am UTC 45 mins
    Synopsis:
    Cool technologies show up for the consumer market before they're available to the business market. Employees are either going to figure out ways around the corporate security rules, or they're going to take another job with a more trendy company. Either way, senior management is going to tell security to get out of the way. It might even be the CEO, who wants to get to the company's databases from his brand new iPad, driving the change. It's going to be harder and harder to say no. Peter Wood looks at what firms are doing to answer this challenge and offers some pragmatic advice

    About the speaker:
    Peter is a world-renowned security evangelist, speaking at conferences and seminars on ethical hacking and social engineering. He has appeared in documentaries for BBC television, provided commentary on security issues for TV and radio and written many articles on a variety of security topics.

    Peter has worked in the electronics and computer industries since 1969. He has extensive experience of communications and networking, with hands-on knowledge of many large-scale systems. He founded First Base Technologies in 1989, providing information security consultancy and security testing to commercial and government clients. Peter has hands-on technical involvement in the firm on a daily basis, working in penetration testing, social engineering and awareness.
  • Are You Googling Your Clients’ Privacy Away? Jul 11 2013 6:00 pm UTC 45 mins
    This presentation addresses how various services offered by Google can become a threat to your companies’ privacy and confidentiality policies.

    It deals with Google’s capabilities to capture and aggregate information with or without user knowledge. Special attention is given to Google’s key offerings such as:

    * Google Searches
    * GMail
    * Orkut
    * Google Toolbar
    * Google Desktop
    * Android
    * Chrome Browser
    * Case Studies from around the world
  • Know When To Say When – Proactive Risk Management Jul 11 2013 4:00 pm UTC 45 mins
    When is the very worst time to make a commitment? When we know the very least. How can we make sensible commitments while also reducing risks? By using Proactive Risk Management. Niel Nickolaisen developed Proactive Risk Management in order to do two things – properly and concisely profile and mitigate risk and align commitments as to what and when with risk mitigation. This method encourages iterative risk management while also satisfying stakeholders as to what must be true before the team can make a concrete commitment.
  • Cloud, Social Networking and BYOD Collide! Jul 11 2013 9:00 am UTC 45 mins
    Synopsis:
    The hot topics for 2013 are still cloud security, social networking and ‘bring your own device’ (BYOD). Peter Wood explores what happens when these three trends collide and the effect on the security of a typical large organisation. Pete believes that conventional security thinking has failed to address these challenges – so how do we deal with this brave new world and what can you do to manage the risks?

    About the speaker:
    Peter is a world-renowned security evangelist, speaking at conferences and seminars on ethical hacking and social engineering. He has appeared in documentaries for BBC television, provided commentary on security issues for TV and radio and written many articles on a variety of security topics.

    Peter has worked in the electronics and computer industries since 1969. He has extensive experience of communications and networking, with hands-on knowledge of many large-scale systems. He founded First Base Technologies in 1989, providing information security consultancy and security testing to commercial and government clients. Peter has hands-on technical involvement in the firm on a daily basis, working in penetration testing, social engineering and awareness.
  • Antivirus Software: Understand Detection Methods Before you buy Jul 10 2013 5:00 pm UTC 60 mins
    Before you choose an antivirus solution it's important to understand how it goes about detecting malware in the first place. Join us as we discuss:
    - Security in the News
    - Modern threat categoreis and attack vectors
    - Endpoint risks, infection methods, payloads
    - Detection with signatures and hueristics
    - Zero Day Risk
    - Technologies that protect removeable storage devices
    - Best Practices
  • Guard Your Business When Disaster Strikes Jun 26 2013 4:00 pm UTC 60 mins
    Fires, tornadoes, and hurricanes. Viruses, malicious attacks, and human error. Today's CTO must be part strategist, part superhero in his effort to achieve an always on infrastructure.
  • Why Your Current Endpoint Security Is Doomed to Fail Jun 25 2013 5:00 pm UTC 45 mins
    Join guest speaker Chris Sherman, researcher at Forrester Research, Inc., serving security & risk professionals, and learn why a new approach is needed to protect your enterprise against advanced threats.

    Attend this webcast and learn:

    -Why traditional security solutions-such as antivirus-are increasingly ineffective against the relentless tide of today's advanced threats and targeted attacks
    -How real-time visibility, forensics and signature-less detection on endpoints and servers are the keys to reducing your organization's threat surface
    -The benefits of integrating endpoint/server security with network security for comprehensive protection
  • Best Practice or Compliance – Preparing for Data Breaches Jun 18 2013 10:00 am UTC 45 mins
    Synopsis:
    Whether or not your business is at high risk of an attack, appropriate action must be taken in the event of a data breach. The procedure must ensure that the business is not compromised while still preserving necessary forensic evidence.
    There are currently no data breach notification regulations in force - but if there were, how would your business fair with them? Is your business using best practices before it has to comply?
    This session will explore some of the best practices to follow in dealing with breaches before EU Data Protection Regulations require data breach notification and response to data subjects in the event of a breach.

    About the speaker:
    Sarb Sembhi is a Principal Security Consultant with “Incoming Thought”, a security consultancy. Sarb is a regular speaker at Information Security Conferences around the world, including at CxO Summits, Gartner Summits, InfoSec Europe, RSA Europe, HITB, BCS, ISACA, IIPSec, IT Directors Forum.
    Sarb is also the immediate past President of ISACA (London Chapter), Chair of the ISACA Region 3 Government and Regulatory Agencies Sub-committee, a member of ISSA Advisory Board, Eurim, Infosecurity Magazine Editorial Board, Infosecurity Advisory Council 2009, and an individual member of the Parliamentary IT Committee.
  • HIPAA and FTC Health Breach Law: Correcting The Perils Of Lax Security Recorded: Jun 13 2013 49 mins
    Join Raj for a complete regulatory overview including:

    - HIPAA Omnibus Update
    - FTC Health Breach Rule
    - Top 5 reasons organizations FAIL Security Assessments
    - Case Studies
    - Guidance
    - Success Stories
  • What You Need to Know Before the Auditors Ask Recorded: Jun 13 2013 47 mins
    Don't be caught off guard when your auditors show up and start asking internal control questions that you can't answer. In this roundtable session, listen, learn, and share your experiences around managing your internal control system with your ERP system and what to be prepared for BEFORE the auditors show up. There are always tips to learn from others in the compliance area and this session traditionally has lively dialogue, so don't miss this opportunity to prepare for your next audit.
  • Securing Mobile Apps: Old School Know How For the New World Order Recorded: Jun 13 2013 58 mins
    Mobile devices and applications are redefining business, revolutionizing productivity and driving competitive advantage. But as the volume of mobile applications increases, so too are mobile exploits. In the rush to enter the mobile software market, are we taking shortcuts that force us to repeat sins of the past? Like caching sensitive data, incomplete encryption and simple mistakes in coding? Don't let old-school vulnerabilities allow hackers to resurrect previously obsolete malware and exploits. With the experience of more than 1,400 incident response investigations, thousands of penetration tests and hundreds of application security tests, Trustwave SpiderLabs' Charles Henderson will show IT, security and development teams how to make sure they're not leaving sound security practices and due diligence behind as they develop new mobile applications.
  • HIEs & HIXs: What’s in Store for a New Class of Business Associates Recorded: Jun 13 2013 49 mins
    The HITECH Act created new categories of business associates that included health information organizations (HIO), these days referred to as HIEs, and health insurance exchanges (HIX). OCR is preparing to make sure these business associates follow the HIPAA rules.

    The omnibus rule compliance date is rapidly approaching. If you’re an HIE or an HIX, it’s time to make sure all of those policies are in place, the workforce is trained and all of those other tasks that pave the road to HIPAA compliance. This also includes, among other things, reaching out to all of your covered entity customers and negotiating that business associate agreement, testing security incident response plans and that business continuity plan. You will walk away with a solid understanding of the not-so-new privacy and security requirements and practical information you can use to ramp up your compliance efforts in preparation for the September 23, 2013 omnibus rule compliance deadline.
  • Business Driven Continuous Compliance Recorded: Jun 13 2013 40 mins
    While a key driver for adapting security technologies, compliance is still a huge burden for most organizations. In the presentation we will discuss novel approaches to both lower the cost of compliance and derive relevant business value from the process. Changing the compliance process from a periodical manual process into a continuous automated process ensures real time visibility into your compliance posture as well as the ability to react in real time to compliance issues rather than just after the fact. By overlaying the information collected with your enterprise IT asset model, the real time compliance information can also contribute to business driven risk management and help in making the right investment decisions in information security.
trends, developments, and technology
Increasing expectations for good governance, effective risk management and complex demands for legislative and regulatory compliance are presenting a growing challenge for organizations of all sizes. Tune in to live and recorded presentations by respected luminaries in the fields of governance, risk and compliance. Their thought leadership will provide you with practical advice on how to implement successful GRC strategies and processes for your organization.
You might also like: Active Defense: How to Think Outside the Box

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: Problems with Automated IT Inventory and Audit Tools
  • Live at: May 14 2009 1:00 pm
  • Presented by: Jason Keogh, CTO and Founder of iQuate
  • From:
Your email has been sent.
or close
You must be logged in to email this