5 Good Cybersecurity Lessons Learned From FTC Law Enforcement Actions

Several years ago, the Federal Trade Commission (FTC) released a good video that is still highly relevent today. The video explains how companies can leverage NIST's Cybersecurity Framework to greatly improve security in their organization ...
Read More

NIST SP 800-128: Security-Focused Configuration Management of Information Systems Guidelines

The National Institute of Standards and Technology (NIST) has issued new Security-Focused Configuration Management of Information Systems guidelines (SP 800-128). The Special Publication (SP) 800-128 provides updated guidance to help organizations securely configure (or “harden”), ...
Read More

NISTIR 8228: Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks

The National Institute of Standards and Technology (NIST) has released a new Interagency/Internal Report (NISTIR) 8228, that includes guidelines for organizations in managing IoT cybersecurity and privacy risks. The NISTIR 8228 report titled “Considerations for ...
Read More

NIST SP 800-177 Revision 1: “Trustworthy Email”

The National Institute of Standards and Technology (NIST) has released its Security Publication (SP) 800-177 Revision 1, that includes security recommendations for achieving "Trustworthy Email." SP 800-177 Rev 1 includes updated guidelines for securing email ...
Read More

NIST SP 1800-4: Mobile Device Security

The National Institute of Standards and Technology (NIST) has released its Security Publication (SP) 1800-4, that includes security guidelines for mobile device security in cloud and hybrid environments. SP 1800-4 document titled "Mobile Device Security: ...
Read More

NIST SP 800-37 Rev. 2: Risk Management Framework for Information Systems and Organizations

The National Institute of Standards and Technology (NIST) has released a new risk management framework guideline. NIST has named the document Security Publication (SP) 800-37 Rev. 2: "Risk Management Framework for Information Systems and Organizations: ...
Read More

Many organizations lacking adoption of key CIS controls

A recent survey conducted by Tripwire revealed organizations are not fully adopting security controls from key benchmarks, such as the Center for Internet Security (CIS). CIS established the "top 20" set of critical security controls ...
Read More
/ CIS, SANS, Standards & Guidelines

PCI DSS 3.2.1 Security Standard update

The PCI Security Standards Council (PCI SSC) has published a minor revision to the PCI Data Security Standard (PCI DSS) for organizations that handle branded credit cards from the major card networks. The latest version ...
Read More

New CIS Controls V7 released

The Center for Internet Security (CIS) has released its next revision (Version 7) of the top 20 Critical Security Controls.  The CIS controls are a recommended set of cyber defense actions that provide detailed and actionable ways to ...
Read More

PCI security standards for mobile point of sale

The PCI Security Standards Council (PCI SSC) announced a new PCI Security Standard for software-based PIN entry on commercial off-the-shelf devices (COTS), to include smartphones and tablets. According to the press release on Wednesday, the PCI Software-Based PIN ...
Read More