3ami MAS v7 bridges the USB data loss gap

New version of employee monitoring tool puts organisations in control of the who, when, what and where of data transference to memory sticks

Manchester, June 2009 (Omarketing) - 3ami has unveiled Monitoring & Audit System (MAS) v7, which enables businesses to monitor and audit employee usage of USB devices on company computers. Like all versions of MAS, MAS v7 also captures and securely stores a record of all user activity on every application, including email, word processing, spreadsheet applications, instant messaging and online. The monitoring capability of MAS has been extended in version seven to prevent employees from downloading confidential company files onto personal USB sticks and removing them from the premises without permission.

With MAS v7, organisations can ensure only authorised employees use official USB memory sticks, which can be encrypted with biometric fingerprint-scanning authentication to ensure that the data on the USB stick cannot be accessed by anyone except its authorised user (a useful feature in the event that the USB stick gets lost).

Each memory stick is audited so that leaks and losses can be traced back to the original culprit. Certain users can be restricted so that no USB devices will work for them, and certain users can be authorized to use any USB storage device on any computer. The software can be used to block all USB storage devices, such as cameras, flash drives, mobile phones and iPods.

MAS strives to help employers hold themselves and others accountable for irresponsible, dangerous and illegal computer activity in the workplace. MAS enables employers to prevent breaches of confidentiality and to hold both mobile and home business users accountable for their actions within the office's computer network, hence freeing businesses to create safe and secure digital workplaces.

"In the event of wrong-doing, it is essential to know, with certainty, which employee did the wrong-doing," said Tim Ellsmore, managing director of 3ami. "If you don't monitor your network, you are saying that you do not take responsibility and accountability seriously. If something goes wrong, you have no one to blame but yourself."

In other words, without monitoring it is impossible for companies to hold individuals accountable for their actions on company computers. When secrets are leaked, the companies who do not monitor are left pointing fingers and looking for someone to blame.

For example: "James," an employee at a major UK department store, was fired last month for charging his iPod at work. (James is a pseudonym; the employee is appealing his termination and has asked to remain anonymous). When James' superiors saw James charging his iPod, they accused him of "slurping," or using an iPod to download tens of thousands of company files per hour. James's employers had no physical evidence of wrongdoing (the store does not use MAS v7), so they framed their argument on grounds of mistrust. In the end, James was fired not because of misconduct, but because his company lacked the ability to prove, with certainty, whether he was innocent.

In certain cases, such as the above, it can actually be ethically questionable for a company not to monitor its computers. However, as an increasing amount of information moves to computers, and as mobile devices such as iPods and smart phones become ubiquitous, it is imperative that organisations safeguard their networks from reckless, irresponsible and damaging activity. It is equally imperative to account for such activity, if it does take place.

MAS v7 enables employers to prevent breaches of confidentiality and to hold individuals accountable for their actions on company computers, hence freeing businesses to create safe and secure digital workplaces for employers and employees alike.

3ami Monitoring & Audit System (MAS) is simple to install across a network and easy to run and maintain so managers can monitor employee's computer activity, separately from general network administration. It has been designed to be monitored and maintained by non-IT staff, and integrates with popular IT products. For more information, please visit: www.3ami.com

<>

Experts warn firms for code audit as Windows XP enters extended support at Microsoft

Fortify warns firms of need for code audit as Windows XP enters extended support at Microsoft

Fortify Software, the application vulnerability specialist, is advising anyone working on customised or new applications running under Windows XP to beef up their code auditing procedures.

The advice comes as Microsoft has moved its support programme for Windows XP into extended support mode, meaning that the software giant is stepping its support for the still-popular operating system down a notch or two.

"Extended support for Windows XP will continue until April 2014, but this month's support move means that smaller firms will find it more difficult to get telephone support for Windows XP," said Barmak Meftah Senior Vice President Products & Technologies for Fortify.

"Microsoft has said it will continue to patch the operating system in response to code vulnerabilities as they are discovered, as well as issue hot fixes as and when required," he added.

According to Meftah, as well as continuing to security code audit any new and updated Windows XP applications, companies should also review their patching procedures, and ensure that security testing forms an integral part of their software development processes.
Because Microsoft is continuing to issue hot fixes for Windows XP, he explained, this means that some of the kernel code for the operating system could be changed in the future, so it is important that any company using customised or new XP-driven software is aware of the heightened need for auditing their program code.

And whilst major companies can still obtain customised support for Windows XP for Microsoft - at a premium charge - this type of support is not normally open to smaller companies.

This means such companies may have to turn to third-party firms for Windows XP support, where previously they used Microsoft support on a pay-as-you-go or subscription basis.

"This all adds an extra layer of risk to the integrity of the program coding process and companies need to be aware of this. Adding code auditing to the software development lifecycle can be a lower-cost option than using premium support services," he added.

"And companies should also be aware that a multi-layered approach to IT security can also reduce any risks, but code auditing definitely now needs to be higher up the IT security agenda," he added.

For more on Microsoft support changes for Windows XP: http://preview.tinyurl.com/6rhd9n

For more on Fortify Software: http://www.fortify.com

Source: Eskenzi PR
<>

73% of companies believe they are vulnerable to hacking

June 2009 – Seventy three percent of IT professionals admit their software applications are still vulnerable to hackers, only an eight percent reduction on last year’s startling discovery. In a repeat of its survey conducted amongst IT security professionals, Fortify Software – the application security specialists, has learned that, this year, forty six percent think that hacking at the application level is the easiest way into a company - an increase on a third compared with last year’s Fortify survey. Worryingly five percent report that between 76% and 100% of hacks are targeted at applications.

External vs Internal

A third of respondents believe that buying external applications pose a greater security threat than writing them in house. That said, thirty five percent don’t consider checking externally procured applications for flaws and vulnerabilities. When examining how concerned respondents were about application security, fifty five percent of respondents disclosed they were worried because it hadn’t been made a priority for the developers. A further twenty one percent were rightly disturbed because it is at the bottom of everyone’s mind.

Barmak Meftah, Senior Vice President Products & Technologies, from Fortify Software said “Although pleased by a reduction in respondents who admit their software applications are vulnerable to attack, eight percent simply isn’t good enough. Today, such an informed audience shouldn’t be citing security concerns as bottom of anyone’s mind or worse not considered a priority. Businesses really should be looking to alleviate the security risks in their applications and achieve software security assurance so that they don’t have to face the expense and embarrassment of being hacked.”

Other Factors

The survey also confirms that the economic downturn is having an impact on organisations’ security with twenty three percent reporting an increase in hacking attempts since the economy went into freefall.

Twenty six percent have been victim to at least one instance of hacking in the last twelve months.

The Fortify Application Security Survey was first carried out at Infosecurity Europe 2008 amongst 300 IT security professionals, who were drawn from mainly 1000+ employee sized companies and repeated at this years event amongst 282 visitors.

Fortify® Software products protect companies from the threats posed by security flaws in business-critical software applications. Its software security suite —Fortify 360 — drives down costs and security risks by implementing threat intelligence, automating key processes of developing and deploying secure applications. Fortify Software's customers include government agencies and FORTUNE 500 companies in a wide variety of industries, such as financial services, healthcare, e-commerce, telecommunications, publishing, insurance, systems integration and information management. The company is backed by world-class teams of software security experts and partners. More information is available at www.fortify.com.

Source: Eskenzi PR
<>

Infosecurity Adviser applauds forensics lab training facilities at key UK university

London, UK. May 2009: Infosecurity Adviser, Infosecurity Europe’s online community for the information security industry, has published a revealing behind-the-scenes report on the University of Bedfordshire's new digital security and forensics laboratory.

According to Mike Barwise, contributor on Infosecurity Adviser, “as law enforcement gets to grips with electronic crime, digital forensics has become an integral part of corporate incident management. Despite this, many prosecutions are still thwarted by inappropriate evidence handling on the part of inexperienced front line response teams. That's why I feel the new facility at the University of Bedford has so much to offer in training up a new echelon of qualified entrants to the profession," he added.

The new lab and training facilities at the university - which runs IT forensics courses for undergraduates and postgraduates - has very impressive facilities.

With 15 high-specification quad-core PCs, each of which has 2.5 terabytes of storage and a range of very high quality IT forensics software, the IT investigation facilities of the labs are second to none in the UK at the moment, says Barwise.

This, he explained, is notable in a segment of the IT industry that is still very much in is infancy in terms of training and general expertise, despite a surge of interest amongst commercial organisations.

A key example of this, he says, is KPMG, which has recently enhanced its UK IT forensics operation - one of the fastest growing of its practice areas - with the addition of new facilities and boosting staffing numbers to a total of 150.

"Last year KMPG generated revenues of 60 million pounds from its UK forensics division and noted that - alongside traditional fraud prevention and detection services - other related services, such as data analytics, are rapidly expanding as well," he said.

It's against this backdrop, says Barwise, that the creation of the impressive facilities at the University of Bedfordshire is to be applauded, as there is a growing need for rapid first line response to IT incidents that require investigation by forensics specialists.

For more on Mike Barwise's report on the University's forensics' facility: http://www.infosecurityadviser.com/view_message?id=116

Infosecurity Adviser is a unique community portal representing information security industries and users, organized in association with Infosecurity Europe. It offers advice from industry experts and bloggers as well as end user product reviews. It also contains information on qualifications, career paths and jobs from all the major accreditation bodies. It is supported by the Information Security Awareness Forum.

Source; Inforsecurity PR
<>

Impressions of an ASUS Eee PC 900

by Michael Smith (Veshengro)

I have now owned – yes, I bought this one and it is not a review sample of any kind – an ASUS Eee PC 900 Netbook with Linux operating system for about six months and I must say that I am rather in love with this little computer.

The Eee PC 900 Netbook of mine has one idiosyncrasy in its Linux operating system (OS) though and that is that it will overwrite an old file if a new one created has the same name without, as do other operating systems, warning the user that this is about to happen. So, users beware!

Furthermore I have two serious complaints, if I may call it thus:

The first one is that the battery just does not live up to the claim of three hours life or such. If one can get an hour and a half out of it then that could be considered good, I would say.

The second problem is that SD memory cards are not recognized when inserted into the SD card slot provided.

Otherwise, however, you will have to prise this netbook out of my cold, dead hand before I would give it up.

I find that the Eee PC 900 Netbook of mine is the notebook kind of computer that I use most. My bigger Fujitsu Siemens Amilo laptop rarely comes out of the desk drawer where it lives. My definite first choice of computer on which to do my writing is the Eee PC 900 or the my Ubuntu PC that I have for the writing use.

The above mentioned Fujitsu Siemens laptop, on the other hand, is about to become the replacement for my rather aging and ailing, methinks, Compaq Evo Desktop with Windows XP.

My Eee PC is an ASUS Eee PC 900 with a 16GB SSD hard drive and 1GB of RAM.

Probably because of the fact that it runs ASUS' own version of Linus it opens fast and is a pleasure to use.

I do need my reading glasses, though, for the 8.5inch screen but that would be the case also with a 10inch screen.

In fact, I do believe that the Eee PC 900 Netbook is just the right size for a Netbook and there is naught wrong with the size of the screen or the keyboard either. I can type faster on the ASUS Eee PC 900 keyboard than that of the Fujitsu Siemens laptop of mine and about the same as – if not better also even – on the keyboard of a desktop PC. So where people seem to get the problem from as regards the 900's keyboard size beats me. Yes, it needs a little getting used to but that is by-the-by.

How do I rate it, you, the reader will want to know now, I guess.

Overall: good
Design: Great
Battery life: Oh dear!
Weight: Light
Linux Operating System: Very good bar the little problem with the file overwrite without warning.

Summary: 7 out of 10 and that because of the battery life and the non-working SD card slot, plus the file overwrite problem.

If that could be remedied then this would be the absolute best, I think, netbook about.

I have seen – though not (as yet) – tested the newest versions of the Eee PC netbooks with the 10inch screen and the new keyboard but I think the 900 will take a lot of beating were it not for the above problems.

© 2009
<>

Touch the Light Fantastic

ASUS Launch U Series with Light-in-Motion Technology and Intel® CULV Processor

On May 27, 2009, ASUS have announced the launch of their new thin and light range of notebooks which combine Intel’s latest notebook processor technology with a stylish and light-inspired design.

Encompassing more than 10 years of ASUS notebook innovation, the U Series combines their most elegant design yet with the most advanced notebook technology for the thin and light platform, setting new benchmarks for overall performance, functionality and design.
Key Features: model dependent, please see specifications
* LED Backlit displays from 12.1” to 15.6” (frameless HD on UX)
* Range of processors inc Intel® CULV (Consumer Ultra Low Voltage)
* Light-in-motion: ambient light sensors auto-adjust screen brightness
* Illuminated MosaicGlow chiclet keyboard
* HDMI Output, Altec Lansing stereo speakers & SRS Surround Sound
* High performance graphics options
* 4GB RAM memory and Up to 500GB HDD
* Wi-Fi (802.11 a/b/g/n), Gigabit Ethernet and Bluetooth 2.1
* Express Gate V2
* Genuine Windows Vista® Home Premium & support for Windows 7®
* Global 2-year Collect & Return warranty
* From £799 and £999 SRP

POWER
Key power-saving features offer a greener and more cost effective computing solution for users, without compromising performance:

Processor: The U20 and UX50 models integrate the latest and innovative Intel® CULV (Consumer Ultra Low Voltage) processor, designed specifically for high performance within a slim-casing whilst retaining power efficiency.

LED: The backlit LED display not only offers 50% less power consumption compared with traditional LCD panels, but are free from mercury and eco-friendly.
Battery: Combined with the above features the robust Li–Ion Battery pack provides users up to 12 hours of continuous operation*.

COMFORT
Users can enjoy greater levels of comfort and ease of working in different environments with innovative light sensor features:
Ambient screen: The Light-in-Motion technology automatically adjusts the screen brightness according to the ambient light. In brighter environments the screen brightness will increase to improve visibility whilst in lower light conditions (such as whilst travelling by plane) the screen will dim in order to reduce the glare on the users eyes to provide excellent usability and safety.

Backlit Keyboard: The MosaicGlow chiclet keyboard features a discreet backlight function where keys are subtly highlighted in low light environments, making it easy for users to see what they are typing without having to strain and adding a stylish ‘glow’ to the notebook whilst working.

PERFORMANCE
At home or on-the-move, users can enjoy immersive and top performance multimedia whatever the need - for movies, gaming or music:

Top performance graphics: The U50 and UX50 deliver NVIDIA® GeForce® G105M graphics, offering full HD 1080p playback, with 5x the performance of mainstream graphics and 8 powerful CUDA™ cores to accelerate performance.

Versatile graphics options: In addition the UX50 allows users to switch between discreet and onboard graphics without rebooting, offering higher control and performance across tasks.
HD playback: All U and UX series notebooks feature HMDI outputs allowing High Definition playback for a superb visual image.

Surround sound : Each notebook integrates Altec Lansing speakers with SRS surround sound to deliver crystal clear, high quality audio.

SPEED
Seamless quick connectivity keeps users productive anywhere they go:

Multiple connectivity options: Whilst delivering high performance and style, the U and UX series is still equipped with a host of features to enable users to stay connected and productive though day to day tasks, including Wi-Fi (802.11 a/b/g/n) and Bluetooth 2.1.

Fast connection: Express Gate V2 offers boot up in around 8 seconds (depending on system usage) in order for users to speedily access commonly used applications such as the Internet, Instant Messenger, Skype and Music.

DESIGN
A unique, slim and innovative design ensures users can feel stylish and reassured they are using a robust and reliable device:

The U and UX series notebooks are truly chic in appearance with a thin exterior blended with a high gloss ‘piano finish’.

The ASUS innovative design and manufacturing processes ensure the U and UX series notebooks are not just pretty on the outside, but are also well-thought out in their planning for a robust and efficient result. Despite the incredibly slim size they are able to dissipate heat efficiently and extremely quietly, ensuring users are not disrupted by noise.
Consumers experience a computing solution that is high quality, stylish, fast, power-saving and packed with great features yet still affordable:

PRICING & AVAILABILITY
Prices for the U/UX series will start from £799 for the U20 and £999 for the U50/UX50. All three models will be available from early July 2009.

Pricing and availability for the U80 to be confirmed.

Source: Tru-PR/ASUS
<>

Survey Reveals Workaholics now working 2-6 hours a week in bed

Survey uncovers a staggering number of obsessed workers are taking their laptops to bed, much to their partners annoyance

London, May 2009 - Over a quarter of UK employees are so work obsessed they can’t resist using a mobile device such as a laptop in bed before they go to sleep according to a survey released today by CREDANT Technologies – the endpoint data protection specialists. The survey discovered that of those people who do work in bed, 57% do so for between 2 and 6 hours every week, little wonder that the survey also found that the majority of their bed companions found their partners’ obsession with their mobiles “a very annoying habit”. A staggering 8% of people admitted that they spend more time on their mobile devices during the evening than talking to their partners!

The survey into “Laptop use in bed and the security implications” was conducted amongst 300 city workers who were interviewed to determine whether the UK has become a nation of work obsessed, laptop dependent, key tappers and to highlight the security implications of unsecured mobile devices. Almost half the respondents (44%) admitted they are holding important work documents on their mobile devices of which 54% were not adequately secured with encryption. This will sound alarm bells for the many in-house IT departments who are tasked with trying to secure an ever increasing mobile workforce who are using data on the move and consequently losing more unsecured data than ever before.

Additionally snooping neighbours or even malicious infiltrators could hack into the devices that are being used in bed, as a fifth of people are not using a secure wireless network as they busily tap away under their duvets.

Michael Callahan, Vice President at Credant Technologies explains “This survey confirms that there is a growing population that is no longer restricted by working hours or confined to the office building itself. People are mobile and will work anywhere – even in bed. Therefore, when sensitive and valuable data is being held on these devices and they get lost, it can have pretty detrimental and far-reaching consequences to both the worker and their employer.”

“With increasing pressures on companies to comply with regulations, such as the Data Protection Act, we all have to respect our customers and employers by protecting the data held on our mobile devices, where ever we may be.”

The most favoured way to connect to the Internet, and subsequently back to the office, whilst lying in bed is via a wireless network (87%). Disturbingly, almost a fifth of people spoken to are using a wireless network that they know is insecure, with 56% down/uploading company information.

When staying in hotels, people are happy to connect to the hotel’s wireless network, expecting the hotel to ensure it’s secure. 47% admit that they do so without even considering the security implications.

When asked “What is the last thing you do before going to sleep” it is reassuring to learn that, for 96% of the people questioned, it is kiss their partners goodnight. For the other 4%, (71% of which are male), who confess to completing work and checking their emails it would be advisable for them to take a long hard look at their gadget obsessed lives.

Five Tips When Engaging In Electronic Pillow Talk

Credant recommends the following simple hints and tips to ensure data remains secure, especially when working in your pyjamas :

Tip One : If your laptop or mobile device contains important / sensitive data relating to your employer, especially clients’ information, then the data protection act requires it be adequately protected. Ask your IT department to encrypt the mobile device.

Tip Two : Always use a strong password - combining numbers, letters and symbols, to access your device or network. Don’t make exposure easy.

Tip Three : Be aware of all the points of connection and access so you don’t risk disclosure.

Tip Four : Don't leave your mobile device open to access (e.g. leaving Bluetooth or WiFi turned on) somewhere visible and unsecured.

Tip Five : Finally, use your bedroom for what it’s designed for. And, if you’re not feeling sleepy, your laptop is the last thing you should be turning to!

The survey referred to was conducted in the City of London, amongst 300 city workers during April 2009 for Credant Technologies.

CREDANT Technologies is the market leader in endpoint data protection solutions.

CREDANT’s data security solutions mitigate risk, preserve customer brand, and reduce the cost of compliance, enabling business to “protect what matters.”

CREDANT Mobile Guardian is the only centrally managed endpoint data protection solution providing strong authentication, intelligent encryption, usage controls, and key management for data recovery. By aligning security to the type of user, device, and location, CREDANT permits the audit and enforcement of security policies across all computing endpoints. Strategic partners and customers include leaders in finance, government, healthcare, manufacturing, retail, technology, and services.

CREDANT has been recognized by Inc. magazine as the #1 fastest growing security software company in 2008 and 2007; was selected by Red Herring as one of the top 100 privately held companies and top 100 Innovators; and was named Ernst & Young Entrepreneur of the Year 2005. Austin Ventures, Menlo Ventures, Crescendo Ventures, Intel Capital (NASDAQ:INTC), and Cisco Systems (NASDAQ:CSCO) are investors in CREDANT Technologies. For more information, visit www.credant.com.

Source: Eskenzi PR
<>