DECEMBER 2003

The Best
Celebrating security's best...










COLUMNS
Positively The Best
EDITOR'S NOTE It's easy to overlook all the positive ways security is changing the fundamental landscape of business and government.
by ANDREW BRINEY

Breaking the Silence
ON THE LIGHTER SIDE Enterprises must rob would-be hacktortionists of their most effective weapon: secrecy.
by LAWRENCE M. WALSH

Security is Personal
CURMUDGEON'S CORNER We're dropping the ball on today's most important infosecurity issue.
by JAY HEISER

Randomly Safe Ports
ASK THE LINUX GURU Switching a vulnerable daemon to a randomly chosen port can slow or even thwart an attacker.
by JAY BEALE

The "Best" Make Business Better
LOGOFF Forget security for security's sake. Take your cue from the People, Policies, Processes and Products that help your company succeed.
by STEVE HUNT




DEPARTMENTS
Viewpoint
Readers sound off on iptables firewalls, reformed hackers, Check Point's products and SSL VPN's



Constantly Playing "Patch Up"
PATCH MANAGEMENT Persistently vulnerable software has enterprises searching for better remediation solutions.
by ANNE SAITA

Virus Writer Wanted-Alive
CYBERCRIME Image-tarnished Microsoft offers cash bounty to bring malware writers to justice.
by SHAWNA MCALEARNEY

Collaboration Concerns
INFORMATION SHARING New project aims to make grid computing commercially acceptable.
by ANNE SAITA

Kaminsky Refines Stateless Scanning
SECURITY TOOLS Scanrand becomes more adept at sorting intelligence from chaos.
by LAWRENCE M. WALSH

Uniting Menaces
SPAM Spammers, hackers and virus writers unite to find new ways to bombard enterprises with unwanted offers.
by SANDRA KAY MILLER

Coming Soon: Standard for COTS
OPEN-SOURCE SECURITY IEEE tackles security for COTS operating systems.
by SHAWNA MCALEARNEY



Painless PGP
TEST CENTER PGP Corp. delivers practical PKI deployment for securing e-mail with PGP Universal.
by FRED AVOLIO

SecureSpan
HOT PICK
by NEIL ROITER

Product Reviews
SPI Dynamics' WebInspect Enterprise Edition 4.0
Fiberlink's Dynamic Network Architecture & Extend360
Sygate Technologies' Security Portal
Lancope's StealthWatch 3.1
NetScreen Technologies' Deep Inspection Firewall & Security Manager 2004
Teros' Secure Application Gateway
Permeo Technologies' Application Security Gateway 5.0
GeoTrust's True Credentials
Check Point Software Technologies' VPN-1 Edge


Using the Common Criteria for IT Security Evaluation
SECURE READS
by PETE LINDSTROM