|

Issue
January 2008
Welcome to the first edition of 2008 of BH
Consulting's Security Watch Newsletter. In this month's issue we
provide some updates to what has been going on in BH Consulting, alert you to
some upcoming events in 2008. We also provide you with some links to
information we on extending Active Directory, talk about permissions within
Windows, provide an overview of the Ubuntu version of Linux and talk about how
to configure transport rules within Microsoft Exchange Server to ensure
compliance with various regulations.

Support
Focus Ireland
If you have found any items in our
Security Watch Newsletter to be of use to you we ask that you
make a donation to
Focus Ireland who
work tirelessly supporting the homeless throughout Ireland. Focus Ireland
aims to advance the right of people-out-of-home to live in a place they call
home through quality services, research, and advocacy. The objectives of
Focus Ireland are to respond to the needs of people out-of-home and those at
risk of becoming homeless, through a range of appropriate high quality services,
to provide emergency transitional and long-term accommodation for people
out-of-home, to campaign and lobby for the rights of people out-of-home
and the prevention of homelessness. No sum is too small and all is
put to excellent use.
About BH Consulting
BH Consulting was founded in answer to demands for an independent consulting
firm to assist clients gain a competitive edge by achieving IT Operational
excellence in deploying, managing and securing their IT infrastructure. With
over 20 year’s experience, we provide you with access to in-depth expertise,
experience and technical know-how. Backed with our quality processes and
commitment to deliver, BH Consulting provides clients with quality solutions at
cost effective rates.
BH CONSULTING NEWS
"Managing
Information Security with ISO 27001" Training Course
Further to the recent success of the
“Managing Information Security with the ISO 27001
Information Security Standard” course
that we hosted with the
Centre for Software Engineering,
additional dates have been scheduled for the New Year. If you are interested in attending or
require more information you can
contact us or find details on the course
on the
Centre For Software Engineering’s website.
Security Watch Blog Nominated for Irish Blog Awards.
For
the second year in a row our
Security Watch Blog
has been nominated in the category for Best Business Blog in the
Irish Blog Awards. A sincere thank
you to those of you who nominated us and to the judges who felt our Blog worthy
of being entered into round 2 of the competition.
BH CONSULTING WEBSITE UPDATE
We strive at BH Consulting to provide information that is
relevant and useful in securing and running your business. To this end we
provide a range of free whitepapers available for download
free from our
white papers page.
LATEST THREAT LEVELS
Get more information on the latest updates on current threats at
our online resources page;
FEATURES
SANS Training Coming To Dublin
SANS is returning to
Dublin in April 2008 to provide three training courses.
The event will run from April the 7th to the
12th. This year's event was very successful. Not only is the quality
of the training superb, the networking opportunities to meet with information
security professionals from all around Europe, and indeed the World, are
fantastic.
SANS Dublin 2008 should be even better, and with the current euro to
dollar rate the courses are particularly good value for those of us based in
Europe.
Second Annual Irish Cyber Crime Survey
Launched
The
Irish Chapter of the
Information Systems Security Association and
UCD
have launched the second “ISSA
/ UCD Irish Cybercrime Survey“. This is a joint project between the
Irish Chapter of the
Information Systems Security Association and the
Centre for
Cybercrime Investigation at
UCD.
Last year was the first time a survey of this nature was conducted to focus on
the information security challenges faced by organisations in Ireland. The
results of that survey have proven to be very informative, sobering and
effective in helping raise awareness regarding information security issues.
With the importance of cybercrime research reinforced by
constant publicity of security breaches throughout 2007 and an increasing demand
for data on the impact of security breaches, the ISSA and UCD would like your
help in ensuring a strong response to this year’s expanded
survey.
Please do take the time to complete the
survey. The information you provide will be
vital in getting an accurate profile of cyber crime activity within Ireland and
help us all to develop better ways to combat cyber crime.
Upcoming Event - IISF February Meeting
The Irish
Information Security Forum are hosting their next meeting on February
the 7th at 11:00 a.m. at the
Four Seasons Hotel, Ballsbridge, Dublin. This
month’s meeting is an open meeting, .i.e. those not members of the
IISF
are welcome to attend. If attending please reserve your space by contacting the
IISF.
The Agenda is as Follows:
11.00 IISF February meeting commences, with an Introduction by IISF
Chairman, Jim Smith.
11:05
Andy Harbison,
Deloitte: ‘Responding to E-Discovery requests’
Andrew Harbison leads the IT Forensics and Litigation Support
practice at Deloitte, Dublin. He has provided support to companies and
litigators in over 200 cases. He has written extensively on IT Forensics,
Computer Fraud and Incident Management, and is a co-author of the Law Society’s
Practice Guides in Computer Fraud and Electronic Discovery. He has advised many
of Ireland’s largest financial services firms on information security incident
response planning.
11.40
Michael Coady,
CA
: ‘How to identify key business/financial benefits of Identity & Access
Management’
Michael Coady is a Global Vice President with CA Inc. He has
led several Forensic/Security investigations both in the public and private
sector. He has developed an enterprise security methodology and using this
methodology, has managed the implementation of Identity and Access Management
technologies within large corporations. He is a renowned National Speaker for
Privacy and Security as it relates to HIPAA, GLBA and SOX compliance. He has
managed over 60+ Health Insurance Portability and Accountability Act (HIPAA), EU
Privacy Directive (EUPD), Gramm-Leach-Bliley Act (GLBA), Sarbanes Oxley (SOX)
engagements nationwide for clients in the public and private sector.
12.30 Networking and finger-buffet lunch in Four
Seasons hotel
I hope to see you there.
Extending the Bountiful Goodness of Active
Directory Across Platforms
Some machines just don’t die. You know this, especially if you
deal with any UNIX or Linux systems. And maybe you know some UNIX guys and gals
whose motto was “mess with my UNIX system over my dead body.” Those guys are
still around, too. But compliance requirements are altering their jobs and
yours, especially if your IT department manages across platforms. Now the word
from above is “extend Active Directory to UNIX and Linux... Click
Here for more.
Problems with Permissions
The Server service has been part of Windows NT–based OSs since day one, and the
vast majority of Windows servers are file servers. You’d think that we IT
professionals and Microsoft would have this file-server thing ironed out by now.
Unfortunately, that’s not the case. I’ve heard from countless business clients
(and these aren’t mom and- pop shops) that IT still isn’t configuring file
servers right. And Microsoft isn’t... Click
Here for more
7 Months with Ubuntu
About a year ago, Microsoft released Windows Vista, its most ambitious desktop
platform to date. It's a great improvement over Windows XP primarily because it
brings better security to the overall OS. Makers of Linux platforms are
improving their desktop OSs too. One company making huge leaps forward is
Canonical, the company behind Ubuntu. In April 2007, Canonical released Ubuntu
7.04, code-named Feisty Fawn. Prior to the release of...
Click
Here for more
Exchange 2007 Transport Rules
Executive Summary: Microsoft Exchange Server 2003’s and Microsoft
Exchange 2000 Server’s messaging architectures make compliance with legislation
and other regulatory requirements difficult. Microsoft Exchange Server 2007’s
transport rules feature makes... Click
Here for more
FREE SECURITY SCAN
In partnership with
Qualys, BH Consulting
are offering a for a free Network Security Scan so you can check how healthy
your network is. To find out more about what this service can do for you, visit
our free
Network Security Scan.

Alternatively contact
us or visit our website to get more details on our
risk assessment service.
This issue of Security Watch is being brought to you by BH Consulting.
If you have found this issue to be of use please support our drive to raise funds
for
Focus Ireland.
Each
Security Watch eNewsletter, and the special Security Alert issues, are produced
independently by the Windows IT Pro Custom Media Group and is distributed by
various Microsoft security partners. Each eNewsletter contains up-to-date
information about security strategies, technologies, and alerts. Each Security
Alert contains the latest information about security threats.
Additional news courtesy of
Silicon Republic,
Cnet,
Silicon and
Zdnet
To update your subscription to our newsletter
click
here. To unsubscribe click
here
|