Peter Stephenson,CeRNS,

Recent articles by Peter Stephenson,CeRNS,

Review: BindView Control Compliance Suite

Review: BindView Control Compliance Suite

The BindView Compliance Control Suite includes bv-Control for Windows, bv-Control for Internet Security and Compliance Center. This is a very complex suite of products and is part of a complete compliance and assessment toolkit that offers virtually every view necessary of the security compliance status of an enterprise. This very strength makes configuration and use of the product difficult at first.
Peter Stephenson,CeRNS, Feb 1 2006 12:00AM Security
Review: Core Impact

Review: Core Impact

Core Impact is different in that while it performs vulnerability assessment, it is primarily a penetration testing tool. It behaves like a hacker, performing vulnerability and port scans then attempting to penetrate the target using the vulnerabilities it finds. There are real benefits to this approach.
Peter Stephenson,CeRNS, Feb 1 2006 12:00AM Security
Review: GFI LANGuard Network Security Scanner

Review: GFI LANGuard Network Security Scanner

This is a straightforward vulnerability scanner that also manages patch deployment. It can push patches and service packs out to target computers by means of a patch agent installed on the target. We found it generally competent and straightforward to install on our Windows 2000 notebook.
Peter Stephenson,CeRNS, Feb 1 2006 12:00AM Security
Review: Nessus/NeWT

Review: Nessus/NeWT

Nessus has been a mainstay of vulnerability scanning since the Nessus Project was started by Renaud Deraison in 1998. The Nessus website claims that over 75,000 organizations worldwide use the program.
Peter Stephenson,CeRNS, Feb 1 2006 12:00AM Security
Review: NeXpose

Review: NeXpose

As an appliance, NeXpose fits into our category of fully featured products, but it is also available as software only. Uniquely, Rapid 7 also offers a managed service for organizations with limited resources.
Peter Stephenson,CeRNS, Feb 1 2006 12:00AM Security
Review: SAINT Scanner

Review: SAINT Scanner

Saint is a venerable product with its roots in the earliest days of automated vulnerability assessment. It has been dressed up in a new suit of clothes since becoming a commercial product, but retains its strong Unix roots.
Peter Stephenson,CeRNS, Feb 1 2006 12:00AM Security
Innovation still exists

Innovation still exists

I just attended the Computer Security Institue’s 32nd Annual Conference and this year there were rumblings on the show floor about the lack of anything new.
Peter Stephenson,CeRNS, Jan 11 2006 10:11PM Security
Defend against cyberwarfare

Defend against cyberwarfare

Most of the national and international TV news is taken up with the “war on terror” or the “war in Iraq.” In our area (metro Detroit), these stories have their own logos and intense theme music. Depending upon the political bent of the news source, these “wars” either are the right or wrong thing to do. We are either winning or we are not.
Peter Stephenson,CeRNS, Dec 15 2005 7:41PM Security
Review: SecureDoc

Review: SecureDoc

SecureDoc is a competent full disk encryptor that uses the AES algorithm and SHA-2 hashing. It works with a token to which the user can save the key file, rather than saving it on the computer. This adds significant extra security – if the user does not store the USB token in their laptop case. The product also supports basic password security and quite a wide range of third-party pre-boot authentication products.
Peter Stephenson,CeRNS, Nov 20 2005 12:00AM Security
Open doors and open eyes

Open doors and open eyes

Peter Stephenson,CeRNS, Nov 11 2005 11:01AM Security
Without clarity you will fail

Without clarity you will fail

Peter Stephenson,CeRNS, Oct 21 2005 4:23PM Security
Opinion - Without clarity you will fail

Opinion - Without clarity you will fail

Some readers will recall that I can be a bit picky when using terms to describe things. We run into confusion when we are vague about terms and descriptions. This can be especially troublesome when we are handling an incident and adrenaline is running high.
Peter Stephenson,CeRNS, Oct 10 2005 6:11PM Security
Review: Disk Protect

Review: Disk Protect

Disk Protect from Becrypt is a competent hard disk encryption that looks very good on paper.
Peter Stephenson,CeRNS, Oct 3 2005 12:00AM Security
Review: DiskCrypt

Review: DiskCrypt

DiskCrypt from Digisafe is unique among these products. Rather than being a software product that you use to encrypt your hard disk, DiskCrypt is a hard disk that comes pre-encrypted.
Peter Stephenson,CeRNS, Oct 3 2005 12:00AM Security
Review: Encryption Plus Hard Disk

Review: Encryption Plus Hard Disk

This had the most promise of all the products tested. It is easy to install, has lots of nice administrative options and is robust and well-certified.
Peter Stephenson,CeRNS, Oct 3 2005 12:00AM Security
Review: OfficeLock

Review: OfficeLock

This is not a disk encryptor like most of the products on test, because it encrypts individual document files transparently. Indeed, it was designed and intended completely for enterprise use, and requires an external copy of Microsoft SQLServer in order to install.
Peter Stephenson,CeRNS, Oct 3 2005 12:00AM Security
We must all play our part

We must all play our part

Peter Stephenson,CeRNS, Aug 26 2005 2:25PM Security
The next generation is here

The next generation is here

I recently attended the graduation of the latest class of Norwich University's Master of Science in Information Assurance program. It was one of the high points of my lengthy career. In the spirit of full disclosure, I've been teaching in this program, for mid-career adults, since its inception. This was the second graduation in the 18-month program.
Peter Stephenson,CeRNS, Jul 22 2005 2:32PM Security
We are dead wrong about risk

We are dead wrong about risk

Peter Stephenson,CeRNS, Jul 1 2005 2:02PM Security
Is risk an overused buzzword?

Is risk an overused buzzword?

Peter Stephenson,CeRNS, Jun 21 2005 11:10AM Security

Log In

  |  Forgot your password?