JULY 2003


Watch Your Step
SECURITY RESOURCE PLANNING   Managing risk across an enterprise is a delicate balancing act. We looked at three "security resource planning" solutions that bring order to the process.
by Pete Lindstrom

SRP Evaluation Criteria

Who's Who in IT Risk Management

Think Like an Attacker



FEATURES

Ron Gula
PROFILE   He rocked the IDS world with Dragon. Now he's trying to catch Lightning in a bottle.
by Anne Saita

Controlling Servers
TEST CENTER   Configuresoft's ECM 4.5 puts security and automated compliance in configuration management.
by Scott Sidel

Hitting the Sweet Spot
HONEYPOTS   Cool new technologies are pushing honeypots closer to prime time.
by Lance Spitzner

Avoiding Sticky Legal Traps
SIDEBAR   Hackers have rights, too. How can you deploy honeypots without running afoul of the law?
by Richard P. Salgado

Minding the Storage
SECURE STORAGE   SAN technology has burst out of the data center, exposing its insecurities to the world.
by Vijay Ahuja

IP Changes the Rules



COLUMNS

Hype, Hype, Hooray!
NOTE   Et tu, Gartner?
by Andrew Briney

Cyberspace Needs McGruff
ON THE LIGHTER SIDE   School children need to know the consequences of hacking.
by Lawrence M. Walsh

The New Risk Rules
CURMUDGEON'S CORNER   Be careful what you wish for. You just might get it.
by Jay Heiser

The Firewall Physical
JUST THE BASICS   How do you know if your firewall is "healthy"?
by Fred Avolio

A Hacker's-eye View
LOGOFF   Hping gets you inside an attacker's head, and shows you how to defeat him.
by Don Parker



DEPARTMENTS
Viewpoint
Readers sound off on CISSP exam, infosec jobs, product survey and intrusion prevention.

News & Analysis
Capital Crunch
Feds Lower Cybersecurity's Profile
Vulnerable Discussion
Linux's Sinking Security
Chat Room: A good virus?
Questions, Poor Perceptions Dog MSRC
@work: Manager's Top Priority


Products
Hot Pick
14 South Networks' IntraLock

Reviews
Arbor Networks' Peakflow X, Check Point Software Technologies' Check Point NG with Application Intelligence, CYA Technologies' CYA Secure Collaboration Suite, Ecora Software's Total Configuration Management Suite, Foundstone's FS1000 & Foundstone 3.0, Gold Wire Technology's Formulator, Netegrity's IdentityMinder eProvision Edition, Pointsec Mobile Technologies' Pointsec for Pocket PC 2.0, Rainbow Technologies' Netswift iGate 2.2, and SonicWALL's SOHO TZW

Secure Reads
Tim Crothers offers a confusing, incomplete view of the intrusion detection world in Implementing Intrusion Detection Systems.
reviewed by Patrick Mueller

Happenings
CALENDAR OF EVENTS
A calendar of upcoming security conferences, trade shows and training events.