Search the Library
 
Home >

Security

>

Access Control

Access Control includes authentication, authorization and audit. It also includes additional measures such as physical devices, including biometric scans and metal locks, hidden paths, digital signatures, encryption, social barriers, and monitoring by humans and automated systems. Authorization may be implemented using role based access control, access control lists or a policy language such as XACML.

Results 1 - 25 of 114 matches Sort Results By : Published Date | Title | Company name
Effective Email Policies: Why Enforcing Proper Use is Critical to Security
By : Sophos Published Date: May 07, 2008
The unmonitored and unguarded use of email by employees poses a multitude of risks to organizations. The distribution of inappropriate or offensive content, malicious emails, and the risks of data leakage all threaten working environments, IT resources and an organization's reputation. A comprehensive, transparent and enforceable email acceptable use policy (AUP), combined with robust email security solutions, dramatically reduces exposure to these risks.
Download Now
Sophos
Federation Products 2008
By : Burton Group Published Date: Jan 02, 2008
The identity federation market enjoys an exceptional supply of products. With well over a dozen products available to enterprise customers, most architects have more choices than time will allow for evaluation. This abundance of products is partly the result of the inherent difficulty of developing a truly multipurpose federation server. Although federation products are similar in name, each has its own personality and idiosyncrasies that make it suitable for certain environments but insufficient in others.
Download Now
Burton Group
How Can Identity and Access Management Help Me with PCI Compliance While Improving Overall Security?
By : CA Published Date: Dec 31, 2007
PCI Compliance has become a business requirement for any company involved in the processing of credit card information. It requires strong security controls over all systems and applications that process or store cardholder information. These controls serve to manage vulnerabilities and to control access to all confidential information.
Download Now
CA
Managing Access in a Virtualized Environment
By : CA NVM Published Date: Oct 01, 2006
To reduce virtualization security risks, an independent access enforcement technology must be employed in conjunction with system security measures. This white paper discusses ways to reduce virtualization security risks, to learn more, download this white paper today.
Download Now
CA NVM
NAC at the Endpoint: Control Your Network Through Device Compliance
By : Sophos Published Date: May 23, 2008
Protecting IT networks used to be a straightforward case of encircling computers and servers with a firewall and ensuring that all traffic passed through just one gateway. However, the increase in mobile workers, numbers and type of device and the amount of non-employees requiring network access, has led to a dissolving of that network perimeter.
Download Now
Sophos
On-Demand Vulnerability Management
By : Qualys Published Date: Aug 08, 2006
Learn how to start your own self-auditing process by setting goals and answering key questions about your infrastructure. This podcast examines what to look for in a self-audition solution, how to use vulnerability management to ease the pain and why your software solution really matters.
Download Now
Qualys
Physical Security in Mission Critical Facilities
By : APC-MGE Published Date: Feb 07, 2005
Before investing in equipment, IT managers must carefully evaluate their specific security needs and determine the most appropriate and cost-effective physical security measures for their facility. This paper presents an overview of the principles of personnel identification and describes the basic elements and procedures used in security systems.
Download Now
APC-MGE
PCI DSS Compliance with Tripwire
By : Tripwire Published Date: Jun 28, 2007
Find out step-by-step what it takes to become compliant with the Payment Card Industry (PCI) Data Security Standard (DSS), and how Tripwire can help your company achieve and maintain PCI compliance.
Download Now
Tripwire
There's a Hole in Your Network: Vulnerability Management Is No Mystery
By : Qualys Published Date: Aug 08, 2006
Learn how vulnerability management allows you to keep on top of these problems by identifying an organization's greatest security vulnerabilities and proactively recommending fixes.
Download Now
Qualys
The PCI Data Security Standard
By : Tripwire Published Date: Feb 01, 2007
Learn about the validation requirements of the payment card industry's data security standard (PCI DSS), including administrative and technical elements of the program, and the potential sanctions for failure to comply.
Download Now
Tripwire
The Total Economic Impact of the Tripwire Enterprise Solution
By : Tripwire Published Date: Jan 10, 2007
Hear from a leading industry analyst how your company can quickly enjoy a substantial return on investment from implementing Tripwire’s configuration audit and control solution.
Download Now
Tripwire
Unauthorized Applications: Taking Back Control
By : Sophos Published Date: Dec 11, 2007
Employees installing and using unauthorized applications like Instant Messaging, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. This paper looks at why it is important to control such applications, discusses the various approaches, and highlights how integrating this functionality into malware protection is the simplest and most cost-effective solution.
Download Now
Sophos
Best Practices: LAN Security and 802.1X
By : Nevis Networks Published Date: Jun 22, 2007
While 802.1X has a growing presence, it's still immature and may not provide all the policy enforcement features commonly required in most organizations. This white paper focuses on the 802.1X standard for authentication and access control and how it compares to the Nevis approach for LAN security.

Download Now
Nevis Networks
Best Practices for Deploying LAN Security and NAC
By : Nevis Networks Published Date: Apr 23, 2007
Companies are yearning for a solution to guard their network from security risks such as external or untrusted users, and unmanaged endpoints on their internal LAN. NAC technology works well, but a strategic solution is required to fully address the problem of the dissolving network perimeter.

Download Now
Nevis Networks
Change Control: Learn How to Address the Insider Threat
By : NetIQ Corporation Published Date: Jan 10, 2007
Learn why organizations need to limit IT administrator power to ensure operational integrity and assure compliance and how to implement robust change control processes and tools with this white paper.
Download Now
NetIQ Corporation
Effectively Delegate Administrative Privileges
By : NetIQ Corporation Published Date: Aug 27, 2007
Learn how delegating administrative privileges can aid in improving administrative productivity, system availability and security, while satisfying the demands of auditors.  Read this new white paper from NetIQ today.
Download Now
NetIQ Corporation
Evaluate NAC for your Enterprise
By : Symantec Published Date: May 30, 2008
Looking for a network security solution? Whether you've already adopted NAC for your enterprise or are researching options, download this helpful survey presented by IDC about NAC benefits and vendor overviews.
Download Now
Symantec
Monitor System Changes And User Activity
By : NetIQ Corporation Published Date: Jul 11, 2007
Learn how to meet regulatory requirements for system change and user activity monitoring with NetIQ Change Guardian for Windows, without the need for performance-hindering native auditing.

Download Now
NetIQ Corporation
The Value of Enterprise SSO to HIPAA Compliance
By : Imprivata Published Date: Nov 02, 2005
When the U.S. Congress passed the Health Insurance Portability and Accountability Act (HIPAA) of 1996, among the law's many provisions was the establishment of formal regulations designed to protect the confidentiality and security of patient information. In addition to mandating new policies and procedures, the HIPAA security regulations require mechanisms for controlling access to patient data on healthcare providers' information technology (IT) systems.
Download Now
Imprivata
10 Reasons your RADIUS Server Needs a Refresh
By : Identity Engines Published Date: Oct 15, 2007
For over a decade now, RADIUS servers have been a mainstay of dial-up and VPN access control. The rather inconspicuous RADIUS server, perhaps better known as that beige, general-purpose PC collecting dust in the corner of your data center, has proved sufficient for performing basic duties like validating passwords and granting network access.
Download Now
Identity Engines
5 Keys to a Successful Identity and Access Management Implementation
By : CA Published Date: Dec 11, 2007
Identity and Access Management (IAM) is a core element of any sound security program. But IAM is also difficult to implement because it touches virtually every end user, numerous business processes as well as every IT application and infrastructure component. As such, successful projects require input and cooperation from many internal groups, an effort that can be difficult to organize.
Download Now
CA
Why Web Services Security Should Be a Key Part of Your Web IAM Security Strategy
By : CA Published Date: Jul 25, 2007
Too many organizations are considering their Web services security architectures separately from their IAM and security management strategies. This is a mistake.
Download Now
CA
Wiegand Security Compromised
By : Borer Data Systems Ltd. Published Date: Oct 26, 2007
At the Defcon security conference on August 2007, a hacker and Defcon staffer who goes by the name Zac Franken, showed how a small homemade device he calls "Gecko", which can perform a hack on the type of access card readers used on office doors throughout the country.
Download Now
Borer Data Systems Ltd.
Winning the Battle Against Inside Threats: Actionable Strategies for Safeguarding Critical Data
By : netForensics Published Date: Nov 28, 2007
To manage threats to the enterprise and successfully meet compliance challenges, organizations need a comprehensive security strategy that can successfully do battle with inside as well as outside threats. Today, companies are increasingly leveraging security information management (SIM) solutions to build a clean, concise, and manageable process for dealing with the tremendous volumes of raw security information from disparate devices, applications, and databases.
Download Now
netForensics
Windows Host Access Management with CA Access Control
By : CA Published Date: Jun 05, 2007
During the course of regular operations, administrators of all roles operate in close proximity to sensitive data, processes or applications running on a Windows infrastructure. In the standard structure of a Windows and Active Directory deployment, these IT and security administrative functions are tightly coupled with one another. While this may not necessarily affect IT system administration, it can severely impact the integrity of security policy enforcement. Effective separation of these duties requires an independent, fine-grained access enforcement and auditing solution.
Download Now
CA