<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.91">
<channel>
<title><![CDATA[whitepapers.scmagazine.com/Security/Application Security]]></title>
<description><![CDATA[Application Security encompasses measures taken to prevent exceptions in the security policy of an application or the underlying system (vulnerabilities) through flaws in the design, development, or deployment of the application.]]></description>
<link>http://whitepapers.scmagazine.com/security/security/</link>
<item>
<title><![CDATA[The Benefits of Identity & Access Management]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper214/</link>
<pubDate>2008-01-23 15:24:25</pubDate>
<description><![CDATA[Download this white paper to learn how IAM projects can be practical, affordable and provide quick ROI for companies of all sizes. ]]></description>
</item>
<item>
<title><![CDATA[Leveraging Automation to Quickly Reveal Vulnerabilities]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper218/</link>
<pubDate>2007-04-16 22:07:10</pubDate>
<description><![CDATA[With web applications constantly evolving, finding vulnerabilities is a challenging, costly and time-consuming undertaking.&nbsp; Find out how Cenzic&#39;s powerful security solutions help information security teams quickly identify problems, regularly assess web application security strength and ensure regulatory compliance.]]></description>
</item>
<item>
<title><![CDATA[Cenzic Software:  Identity Theft Laws And Application Security]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper219/</link>
<pubDate>2007-04-16 22:05:40</pubDate>
<description><![CDATA[The Cenzic Hailstorm&reg; solution helps companies comply with AB 1950, allowing companies to use automated processes to manage their security. Hailstorm is a key tool for preventing breaches.]]></description>
</item>
<item>
<title><![CDATA[Turning the Tide: Why New Strategies are Urgently Needed to Counter the Surge in Online Video Piracy]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper234/</link>
<pubDate>2008-02-22 14:02:31</pubDate>
<description><![CDATA[Now that millions of ordinary, non-geeky families are routinely downloading TV shows and movies without a second thought, digital piracy has clearly gone mainstream.&nbsp; Download this paper to learn methods for preventing video piracy.]]></description>
</item>
<item>
<title><![CDATA[The Value of Enterprise SSO to HIPAA Compliance]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper410/</link>
<pubDate>2007-09-17 12:38:55</pubDate>
<description><![CDATA[When the U.S. Congress passed the Health Insurance Portability and Accountability Act (HIPAA) of 1996, among the law&#39;s many provisions was the establishment of formal regulations designed to protect the confidentiality and security of patient information. In addition to mandating new policies and procedures, the HIPAA security regulations require mechanisms for controlling access to patient data on healthcare providers&#39; information technology (IT) systems. ]]></description>
</item>
<item>
<title><![CDATA[Virus Prevention Without Signatures]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper424/</link>
<pubDate>2007-04-24 17:39:48</pubDate>
<description><![CDATA[Viruses have been on the attack for more than 20 years, and the cost of dealing with them is escalating. Too many malcode (malicious code) attacks by viruses, worms, Trojans and the like are breaking through today&#39;s most prevalent system defenses: Antivirus (AV) programs. This whitepaper will discuss the full impact of virus disasters and what historically has been done to combat the problem.]]></description>
</item>
<item>
<title><![CDATA[Vulnerability Assessment for the Security Operations Center]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper466/</link>
<pubDate>2007-09-11 11:48:14</pubDate>
<description><![CDATA[This white paper explains the evolving needs for vulnerability assessment, the special requirements inherent within large enterprises, and how SecureScout SP from netVigilance meets those needs.]]></description>
</item>
<item>
<title><![CDATA[Information Security Obligations Under UK Law]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper500/</link>
<pubDate>2007-04-27 08:52:27</pubDate>
<description><![CDATA[The law in the United Kingdom has various influences on organizational information security policy.  As well as protecting the rights of individuals and organizations, it also imposes many duties and responsibilities.  For organizations to meet their legal obligations a number of technical controls can be put in place.]]></description>
</item>
<item>
<title><![CDATA[PKWARE Enterprise Security and Compression Solutions]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper507/</link>
<pubDate>2007-04-27 10:50:59</pubDate>
<description><![CDATA[The Butler Group provides a technology audit on PKWARE&#39;s SecureZIP cross-platform data file security software.]]></description>
</item>
<item>
<title><![CDATA[Using SecureZIP to Deliver Strong Security on a Mainframe]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper509/</link>
<pubDate>2007-04-27 10:53:22</pubDate>
<description><![CDATA[A security breach on a workhorse platform like a mainframe could be disastrous. Find out why PKWARE&#39;s SecureZIP is ideal for providing file security for data stored and transferred on mainframes.]]></description>
</item>
<item>
<title><![CDATA[Tips to Deploy Web Services Security]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper543/</link>
<pubDate>2007-04-29 13:17:58</pubDate>
<description><![CDATA[This white paper discusses the three critical Web services deployment issues-security, provisioning connections, and operations. As each is owned by different factions within an enterprise, each can become a &#39;show stopper&#39; to Web services deployment initially, and every time a change must be made.]]></description>
</item>
<item>
<title><![CDATA[Unknown Attacks:  A Clear and Growing Danger]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper570/</link>
<pubDate>2007-05-07 09:06:53</pubDate>
<description><![CDATA[Unknown attacks are quickly becoming the next great information security challenge for today&#39;s organizations.  Get up to speed on what these threats really are and learn what security measures are available to keep your network safe from these attacks.]]></description>
</item>
<item>
<title><![CDATA[Controlling, Delegating, Logging and Auditing Root Actions with Symark PowerBroker]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper615/</link>
<pubDate>2007-09-11 12:40:55</pubDate>
<description><![CDATA[The purpose of the document is to demonstrate the value of Symark PowerBroker as a tool for eliminating or reducing risk in environments where information security and risk avoidance are considered important.]]></description>
</item>
<item>
<title><![CDATA[The New Threat: Attackers That Target Healthcare Organizations (And what you can do about it)]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper621/</link>
<pubDate>2007-06-06 09:48:04</pubDate>
<description><![CDATA[Healthcare organizations are being targeted by financially motivated attackers that steal and sell valuable data, including identities and computing resources.  This white paper defines the new threat, and outlines three important steps that providers can take to protect their critical systems.]]></description>
</item>
<item>
<title><![CDATA[On-Demand Vulnerability Management]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper675/</link>
<pubDate>2008-06-16 13:00:13</pubDate>
<description><![CDATA[Learn how to start your own self-auditing process by setting goals and answering key questions about your infrastructure. This podcast examines what to look for in a self-audition solution, how to use vulnerability management to ease the pain and why your software solution really matters.]]></description>
</item>
<item>
<title><![CDATA[Breaking Through the Dissimilar Hardware Challenge]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper683/</link>
<pubDate>2007-06-06 09:45:08</pubDate>
<description><![CDATA[IT administrators need to minimize downtime for critical IT services by rapidly recovering entire systems to dissimilar hardware platforms or virtual environments. Symantec Backup Exec System Recovery Server Edition combines the speed and reliability of disk-based, bare-metal Windows system recovery with dissimilar hardware restoration and lights-out operation.]]></description>
</item>
<item>
<title><![CDATA[Protecting Client Systems from the Crimeware Invasion]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper685/</link>
<pubDate>2007-06-06 09:45:36</pubDate>
<description><![CDATA[The IT threat landscape has changed from individual hackers disrupting network operations to organized crime stealing confidential information. Antivirus technology must be joined by a coordinated, multilayered defense that includes proactive vulnerability-based intrusion prevention, file-based intrusion prevention, and inbound and outbound traffic control.]]></description>
</item>
<item>
<title><![CDATA[Secure Online Data Transfer with SSL]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper703/</link>
<pubDate>2008-08-27 15:26:15</pubDate>
<description><![CDATA[A guide to understanding SSL certificates, how they operate and their application. By making use of an SSL certificate on your web server, you can securely collect sensitive information online, and increase business by giving your customers confidence that their transactions are safe.]]></description>
</item>
<item>
<title><![CDATA[Security Design Principles]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper718/</link>
<pubDate>2007-04-25 00:21:21</pubDate>
<description><![CDATA[This white paper is an overview of the Nixu Security System and the various security principles it encompasses.&nbsp; Topics discussed include security design, application security, OS hardening, patch management, and more.]]></description>
</item>
<item>
<title><![CDATA[Securing Web Applications: The Time Is Now]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper719/</link>
<pubDate>2007-04-16 22:08:33</pubDate>
<description><![CDATA[Enterprises need to utilize software testing that can automatically review applications for security problems. This document examines the market drivers and technology associated with software security code review products and discusses how Cenzic is addressing this urgent need.]]></description>
</item>
<item>
<title><![CDATA[Fresh Approaches to Solving the Malware Problem]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper763/</link>
<pubDate>2007-05-07 09:04:41</pubDate>
<description><![CDATA[Organizations need to be protected from both known and unknown threats, and all the varieties and forms that sophisticated malware can take.&nbsp; Learn about the changing nature of malware attacks and how the Webwasher Anti-Malware from Secure Computing can provide a highly effective defense against malicious content.]]></description>
</item>
<item>
<title><![CDATA[Application Security: No Room for False Positives]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper765/</link>
<pubDate>2008-02-22 14:19:23</pubDate>
<description><![CDATA[Enterprises are responding to new threat on communication protocols by hardening Web applications, and they are increasingly turning to Web application security assessment tools to improve the security of their applications. This report examines why high accuracy is critical to the effectiveness of the tools, and it discusses how Cenzic Hailstorm addresses this problem.]]></description>
</item>
<item>
<title><![CDATA[Web Application Security:  The Overlooked Vulnerabilities]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper766/</link>
<pubDate>2007-06-06 09:48:21</pubDate>
<description><![CDATA[This white paper identifies critical vulnerabilities that most organizations overlook when they secure their web applications. It also introduces host intrusion defense with deep packet inspection as a new, effective&nbsp; approach for shielding these vulnerabilities.]]></description>
</item>
<item>
<title><![CDATA[Cenzic:  Application Security for Financial Institutions]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper768/</link>
<pubDate>2007-04-16 22:06:05</pubDate>
<description><![CDATA[The Cenzic Hailstorm&reg; solution helps financial institutions comply with GLBA and other laws by automating risk assessment, checking for vulnerability to the injection of malicious code into Web servers, automating the testing of code and key controls during the software development process, and helping them respond to new vulnerabilities in the software development lifecycle.]]></description>
</item>
<item>
<title><![CDATA[What's Missing from SEM? Security Management is More than Event Management]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper813/</link>
<pubDate>2007-04-13 11:57:12</pubDate>
<description><![CDATA[This white paper identifies what is required for a comprehensive and integrated security management solution and examines the difference between SEM, SIM and SIEM and the challenges of enterprise level security monitoring.]]></description>
</item>
<item>
<title><![CDATA[Web 2.0 Security Risks. Are you protected?]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper854/</link>
<pubDate>2007-05-07 09:07:09</pubDate>
<description><![CDATA[This paper outlines these new threats and discusses the limited effectiveness of reactive legacy Web security solutions against those threats.&nbsp; The paper then outlines the new reputation based, proactive security paradigm that is necessary for securing Web 2.0 applications.]]></description>
</item>
<item>
<title><![CDATA[CA SiteMinder: Security for Enterprise Web Applications]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper870/</link>
<pubDate>2008-09-25 10:26:17</pubDate>
<description><![CDATA[This technical white paper explains how CA SiteMinder provides all the essential security services required to meet the challenge of building and managing secure websites, while also including management features and technical capabilities that can reduce the total cost of ownership.]]></description>
</item>
<item>
<title><![CDATA[Dude!  You Say I Need an Application Layer Firewall?!]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper956/</link>
<pubDate>2008-01-28 14:05:23</pubDate>
<description><![CDATA[This industry white paper takes the mystery out of the key differences in the main classes of firewall architectures. It was independently written by Marcus J. Ranum, a world-renowned expert on security system design and implementation. It includes fundamental lessons about building application layer firewalls, technical examples, and concludes with predictions about the future of firewall technology.]]></description>
</item>
<item>
<title><![CDATA[CA SiteMinder 100 Million User Project: Cost-Effective Access Management for Large-Scale Enterprise]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper1229/</link>
<pubDate>2008-09-25 10:26:06</pubDate>
<description><![CDATA[This paper describes CA SiteMinder performance and scalability in a 100 million user deployment, the test environment, tests conducted and their results, and important conclusions and recommendations.]]></description>
</item>
<item>
<title><![CDATA[How Can Identity and Access Management Help Me with PCI Compliance While Improving Overall Security?]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper1728/</link>
<pubDate>2008-09-25 10:29:17</pubDate>
<description><![CDATA[PCI Compliance has become a business requirement for any company involved in the processing of credit card information. It requires strong security controls over all systems and applications that process or store cardholder information. These controls serve to manage vulnerabilities and to control access to all confidential information. ]]></description>
</item>
<item>
<title><![CDATA[GoToMeeting Security White Paper]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper1884/</link>
<pubDate>2008-02-01 09:25:28</pubDate>
<description><![CDATA[This document provides a technical description of the security features built into GoToMeeting. It has been written for technical evaluators and security specialists who are responsible for ensuring the safety of their company&rsquo;s network and the privacy and integrity of business communications.]]></description>
</item>
<item>
<title><![CDATA[Meeting the PCI Application Security Requirements: Building Compliance In]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2134/</link>
<pubDate>2008-07-22 09:30:13</pubDate>
<description><![CDATA[The PCI DSS is demonstrably becoming a de facto standard of due care for any organization responsible for the privacy and integrity of data. The increased focus on application security in the latest revisions of the PCI DSS can be traced directly to many of the recent high profile breaches, where insecure applications have proved to be the point of access for hackers, and the source of data loss.]]></description>
</item>
<item>
<title><![CDATA[Secure at the Source: Implementing Source Code Vulnerability Testing in the Development Life Cycle]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2135/</link>
<pubDate>2008-07-22 09:30:26</pubDate>
<description><![CDATA[Organizations should implement source code analysis tools as part of the software development life cycle to find and fix the highest number of security issues early in the project. This will result in a higher-quality product and lower overall application life cycle costs. Countless studies and analyst recommendations suggest the value of improving software security during the development life cycle (SDLC) rather than trying to address security vulnerabilities in software discovered after widespread adoption and deployment. ]]></description>
</item>
<item>
<title><![CDATA[The Path to a Secure Application:  A Source Code Security Review Checklist]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2136/</link>
<pubDate>2008-07-22 09:31:12</pubDate>
<description><![CDATA[The path to application security begins by rigorously testing source code for any and all vulnerabilities, to ensure the application will not compromise, or allow others to compromise, data privacy and integrity. This paper outlines the steps to secure source code development practices, and presents a source code security review checklist.]]></description>
</item>
<item>
<title><![CDATA[Trust, But Verify:  How to Manage Risk in Outsourced Applications]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2137/</link>
<pubDate>2008-07-22 09:31:36</pubDate>
<description><![CDATA[This paper will discuss the need for addressing security concerns in outsourced applications, outline a framework for addressing those concerns, explore the role of source code review to assess and certify outsourced applications, and provide a sample contract addendum for including secure code requirements in RFP&#39;s and outsourcing contracts.]]></description>
</item>
<item>
<title><![CDATA[Why Application Security is Crucial and What Companies Are Doing About It]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2396/</link>
<pubDate>2008-04-09 09:28:34</pubDate>
<description><![CDATA[Today, many organizations are increasingly reliant on software application development to deliver them competitive edge. Simultaneously, they are progressively opening up their computer networks to business partners, customers and suppliers and making use of next-generation programming languages and computing techniques to provide a richer experience for these users. However, hackers are refocusing their attention on the vulnerabilities and flaws contained in those applications. ]]></description>
</item>
<item>
<title><![CDATA[The Right Tool for the Right Job: An Application Security Tools Report Card]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2431/</link>
<pubDate>2008-07-22 09:31:23</pubDate>
<description><![CDATA[During the 80s, war dialing and phone phreaking were the attacks that garnered all the headlines. In the 90s it was all about web defacement and the ubiquitous email virus. The last seven years have given rise to identity data theft and privacy concerns. For the past twenty years, organizations have focused on protecting the network; but in the last ten years it has become clear that the core threat is not, nor really ever was, access to the network. ]]></description>
</item>
<item>
<title><![CDATA[Software Security Governance in the Development Lifecycle]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2432/</link>
<pubDate>2008-07-22 09:30:43</pubDate>
<description><![CDATA[There are many key drivers for application security, such as managing the high levels of complexity in rapidly changing IT environments as well as regulatory and compliance demands. With recent high profile breaches and their consequences in the headlines, the direct line between insecure software and data insecurity has never been more clear. As a result, organizations with a strong commitment to data integrity and privacy are taking concrete, measurable steps to ensure the software systems that control data are developed securely.]]></description>
</item>
<item>
<title><![CDATA[Preventing Your Next Microsoft Exchange Outage]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2533/</link>
<pubDate>2008-05-07 17:06:30</pubDate>
<description><![CDATA[Messaging has rapidly become the one, true business critical application in use today by many, probably most, enterprises. Even more so than Enterprise Resource Planning or other cross-business applications, any failure in the messaging system is noticed by, and affects everyone. If a person cannot get an e-mail to or from another person then they are immediately in contact with the help desk to report the problem. Users are far less inclined to be forgiving when it comes to an e-mail outage; they just expect it to work. ]]></description>
</item>
<item>
<title><![CDATA[Stop Spam, Viruses and Spyware: Endpoint and Perimeter Malware Guide]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2599/</link>
<pubDate>2008-05-09 10:14:24</pubDate>
<description><![CDATA[IT systems are under constant, increasingly sophisticated attack. Today&#39;s cyber criminals are using highly evolved, blended malware to access corporate and customer data at an alarming rate. Additional layers of protection at the perimeter are essential to combat the sheer volume of this increasing threat and to prevent networks from being clogged by spam.]]></description>
</item>
<item>
<title><![CDATA[State of Internet Security Report: Protecting Business Email]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2600/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Business dependence on email is greater than ever before and the volume of threats has spiked dramatically. For the SOIS report, Webroot surveyed 1,500 email security product decision makers in companies across seven countries. The report finds that close to 80% of U.S. businesses surveyed experienced a spam attack last year while half also experienced spyware, virus and phishing attacks. ]]></description>
</item>
<item>
<title><![CDATA[Spyware: A Clear and Present Danger]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2601/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[In the past, a virus would tear through computer systems worldwide within days and garner global headlines before an antidote was created and distributed with similar alacrity. Now, silent and far more deadly code is in play, which, if it&rsquo;s working right, will never be noticed. The new malware is spyware, but it&rsquo;s not the mere annoyance that first appeared on the scene. In the past several years, spyware has morphed from an irritant into a powerful tool for serious cyber criminals.]]></description>
</item>
<item>
<title><![CDATA[Identifying & Thwarting Malicious Intrusions]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2686/</link>
<pubDate>2008-08-21 14:05:26</pubDate>
<description><![CDATA[Rootkits, Trojans, ransomware, Denial-of-Service and much more &ndash; this newly released white paper from MX Logic covers the everchanging security threat landscape. Learn what malicious intrusions are out there, how to identify them and how to keep your network safe. ]]></description>
</item>
<item>
<title><![CDATA[What's the Big Deal with Managed Security Services?]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2687/</link>
<pubDate>2008-08-21 14:05:33</pubDate>
<description><![CDATA[In this recent report, the Aberdeen Group&rsquo;s research revealed that 100% of Best-in-Class companies consume some managed security services as part of their security strategy. The most widely deployed and easiest to implement managed security service is email security. ]]></description>
</item>
<item>
<title><![CDATA[Effective Web Policies: Ensuring Staff Productivity and Legal Compliance]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2840/</link>
<pubDate>2008-10-01 23:37:06</pubDate>
<description><![CDATA[Employees increasingly expect to use the internet at work for their own personal use in return for longer hours, working from home and interrupting vacations. This has a number of security, productivity, bandwidth and legal ramifications that require organizations to create and implement a web usage policy that is backed up by effective web filtering tools.]]></description>
</item>
<item>
<title><![CDATA[Web Application Security: Too Costly to Ignore]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2870/</link>
<pubDate>2008-08-12 14:37:25</pubDate>
<description><![CDATA[Download this free whitepaper from HP Software to learn about the gaps in most application security programs and how to incorporate application security across the lifecycle.]]></description>
</item>
<item>
<title><![CDATA[Effective Web Policies- Ensuring Staff Productivity and Legal Compliance]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper2989/</link>
<pubDate>2008-10-01 23:23:59</pubDate>
<description><![CDATA[Employees increasingly expect to use the internet at work for their own personal use in return for longer hours, working from home and interrupting vacations. This has a number of security, productivity, bandwidth and legal ramifications that require organizations to create and implement a web usage policy that is backed up by effective web filtering tools.]]></description>
</item>
<item>
<title><![CDATA[Understanding Web Application Security Challenges]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper3248/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[As businesses grow increasingly dependent upon Web applications, these complex entities are becoming more difficult to secure. Most companies equip their Web sites with firewalls, Secure Sockets Layer (SSL), and network and host security, but the majority of attacks are on applications themselves.]]></description>
</item>
<item>
<title><![CDATA[Web Application Security: Automated Scanning Versus Manual Penetration Testing]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper3249/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[There are many ways to uncover Web application vulnerabilities. This white paper examines a few of these vulnerability detection methods &ndash; comparing and contrasting manual penetration testing with automated scanning tools. What you&rsquo;ll discover is that neither of these methods are an exhaustive method for identifying Web application vulnerabilities.]]></description>
</item>
<item>
<title><![CDATA[The Greatest Risk to Your Website: 30% of Database-Driven Sites Vulnerable to SQL-Injection]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper3370/</link>
<pubDate>2008-09-08 18:26:53</pubDate>
<description><![CDATA[Let&rsquo;s assume for a moment that you have your firewall configuration dialed in impeccably, that your patchmanagement server never rests, and that your state-of-the-art IDS lets you sleep peacefully at night, as it continuouslyidentifies any irregularities from the network&rsquo;s accepted traffic patterns. Even your web-server contains no knownvulnerabilities, and it is responsibly segmented from the internal network and into a distinct security zone.]]></description>
</item>
<item>
<title><![CDATA[An Intelligent Approach to Application Security]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper3587/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Forget about phrases like &ldquo;guaranteed&rdquo;, &ldquo;absolute integrity&rdquo;, &ldquo;assured&rdquo;. There is really only one thing that you need to know about all those systems that you are currently running, mission-critical or not &ndash; absolutely all applications are insecure. The certainty of this statement was shown by fundamental research in computability from the legendary code-breaker Alan Turing. ]]></description>
</item>
<item>
<title><![CDATA[Mitigating the Risk from Application Vulnerabilities – Without Breaking the Bank]]></title>
<link>http://whitepapers.scmagazine.com/whitepaper3589/</link>
<pubDate>0000-00-00 00:00:00</pubDate>
<description><![CDATA[Businesses must adapt quickly to realize new opportunities and maximize value from their critical information assets. However traditional security controls are no longer sufficient, as the enemy can now gain control of your database using novel, customized and highly personal attacks. Vulnerabilities in your applications are now the weakest link.]]></description>
</item>
</channel>
</rss>
