JUNE 2003

Turning the Network Inside Out
DEFENSE-IN-DEPTH   We challenged networking and firewall vendors to design an enterprise that's secure from the perimeter to the core. Their responses give us a glimpse into the future of network security.
by Joel Snyder

Roadblocks to Defense-In-Depth
SIDEBAR   We found six barriers to pushing firewall technology to the port level.



FEATURES

Limited Impact
TEST CENTER   Numerous mistakes tarnish the benefits of CORE Security's automated pen testing tool.
by Scott Sidel

Certifiable
CERTIFICATIONS   A newly minted CISSP gives you the inside scoop on infosecurity's most coveted--and controversial--certification.
by Andrew Briney

Candidate Comments
Frustrating Questions
Stack O' Reading





CISO Strategies: The Risk Lifecycle

Rinse & Repeat
ROUNDTABLE   Four CISOs explore practical strategies for managing enterprise risk--from classification to assessment to monitoring to response.
moderated by Andrew Briney

The Risk Lifecycle
SIDEBAR   IT security risk management is best approached as a "lifecycle" of activities, one step logically leading to the next.

State of Confusion
LAW & REGS   California's new privacy law is full of ambiguity, but if you do business there, you'd better get your guard up.
by Randy Sabett

Turnover at the Top
SECURITY MANAGEMENT   How to keep the security program on track...even when there are cracks in the corporate ladder.
by Anne Saita

Security Governance
SURVEY   Turnover in the "C-Suite" may disrupt the continuity of the infosecurity program.



COLUMNS

Security Gets Smart
NOTE   There's some cool stuff rolling off the production line that's raising the security IQ.
by Andrew Briney

Sexy Keystrokes
ON THE LIGHTER SIDE   Matrix heroine's hacking tool turns on security geeks.
by Lawrence M. Walsh

Nmap's Silent Partner
COOL TOOLS   POF is an OS fingerprinting tool for the good guys.
by Marcus Ranum

Securing the Core
ASK THE LINUX GURU   Advice on practical RBAC and secure Linux configuration.
by Jay Beale

Practical Boredom
LOGOFF   Never underestimate the power of a few minutes of downtime.
by Dana W. Paxson



DEPARTMENTS
Viewpoint
Readers sound off on Mitnick's executive conference and cyberlitigation.

News & Analysis
Cyber Corps' Failing Grades
ISO Considers Infosecurity Certifications
OWASP's CodeSeeker Puts Sting Into Web App Security
Alert Overload
@work: Summertime Blues


Products
Hot Pick
Nauticus Networks' N2000 security switch

Reviews
SilentRunner's Enterprise Edition and Mobile Forensic Analyst, VeriSign's Trusted Gateway, Citadel Security Software's Hercules 2.0, RSA Security's ClearTrust 5.0, Eset Software's NOD32 2.0, Sygate Technologies' Sygate Security Enterprise, Threat Focus' Diligence, and Sun Microsystems' iForce IDS.

Secure Reads
Matt Bishop has set a new standard for infosec textbooks with Computer Security: Art and Science.
reviewed by David Bianco

Happenings
CALENDAR OF EVENTS
A calendar of upcoming security conferences, trade shows and training events.