CoreTrace WhiteSpace

The Application Whitelisting and Security Weblog

Application Whitelisting Momentum – Meeting NERC CIP-007 Requirements

Last week I blogged about the general momentum around application whitelisting citing our meetings with Neil MacDonald from Gartner and a recent post from George Kurtz of McAfee.

This week, I want to speak more specifically about using application whitelisting to both meet the letter and the spirit of NERC CIP-007 compliance requirements. This is an area where application whitelisting is gaining significant momentum as a supplement or alternative to traditional blacklist antivirus. There are many reasons why the energy industry is ahead of the general curve in adopting whitelisting technologies. ( Read More… )

Please use the comment form and leave your thoughts!

Application Whitelisting Gaining Momentum for Endpoint Protection

Application Whitelisting is Gaining MomentumWe are having a great week where we are seeing more evidence than ever for the value of application whitelisting in providing both endpoint protection and application control. Earlier this week we met with Gartner analyst Neil MacDonald and got his perspective on the future of application whitelisting. He had many good insights about the state of the industry and we particularly agreed with his perspective on the importance of “trusted change” to the success of any application whitelisting solution. ( Read More… )

Most recent comment:   Application Whitelisting Momentum – Meeting NERC CIP-007 Requirements

[...] week I blogged about the general momentum around application whitelisting citing our meetings with Neil MacDonald from Gartner and ...

Time For an Update of PCI Antivirus Requirements: Take a lesson from NERC CIP

Time For an Update of PCI Anti-Virus Requirements: Take a lesson from NERC CIPPCI requirements have come under scrutiny lately. A number of high profile security incidents resulting in the exposure of hundreds of thousands of credit cards have, fairly or unfairly, brought attention to the companies who suffered these attacks and yet were PCI compliant at the time. The highest profile incident was that of Network Solutions where over a half a million credit cards were compromised.

The culprit? Unauthorized code on their servers resulted in the exposure of the credit card data. Despite the protections employed to protect the card data on servers, they were done in by simple malware on a system in their infrastructure.


( Read More… )

Most recent comment:   PCI Council Moves to Accept Application Whitelisting to Address Malware in Requirement 5

[...] more prevalent in the future. We are happy to see that our call to action in our recent post ...

Conficker – A botnet on autopilot

Conficker: A botnet on autopilotI came across a good article today from internetnews.com detailing the latest stats for the Conficker botnet. Over 5.5 million PCs are actively infected and a part of this botnet according to the Conficker Working Group. Clearly Conficker continues to be a threat despite approaching its first year anniversary this October. ( Read More… )

Most recent comment:   Time For an Update of PCI Anti-Virus Requirements: Take a lesson from NERC CIP

[...] to botnets. We recently blogged about two botnets formed by the new clampi trojan and the older conficker malware. ...