to help enterprise security across Europe
The resource centre for busy senior executives seeking the latest insights into IT Compliance & Privacy issues for major organizations
 
sarbaines oxley ofcom communications regulator
Latest Resources      data protection register
compliance resources privacy resource center

Breaking Global News
Global Compliance and Privacy News
- Breaking News, updated every 30 minutes
•   Compliance, Privacy and Security
•  Money Laundering
•  Phishing
•  Regulatory Issues
•  SOX, Basel 2, MiFID


You Tell Us:
S
S
L

T
E
C
H
N
O
L
O
G
Y
We use SSL Technology for web data entry points:

Always
Sometimes
Never
What is SSL?

News
Are Smartphones Endangering Security? - Wick Hill
Dealing with Internet Security Threats - Ian Kilpatrick
How the New EU Rules on Data Export Affect Companies in and Outside the EU - Thomas Helbing
Farmers' Data Leak Highlights Old Technology Use - Wick Hill
Saving Money with SFTP - Wick Hill
UK Information Commissioner targets firm selling vetting data - Eversheds e80
12 Key Steps to Internet Security - Wick Hill
Telephone Monitoring Legality in the UK - Dechert
Firewall or UTM - Wick Hill
UK Information Commissioner demands mobile device encryption - Eversheds e80
Data loss - liability, reputation and mitigation of risk - Eversheds e80
Phorm, Webwise and OIX - BCS Security Forum
The challenges of PCI DSS compliance - Thales, Russell Fewing
"Quality" Data Vendor Spams us! Editor astounded!
National Gateway Security Survey 2008 - Wick Hill
Unified Threat Management - Watchguard Technologies

news archives
:
0 | 1 | 2 | 3 | 4 | 5 |
6 | 7 | 8 | 9 | 10 | 11 |
12 | 13
[What is this?]

Industry Blogs
Tim Berners Lee's Blog
Tim Callan's SSL Blog
Davis Wright Tremaine's Privacy & Security Law Blog
Emergent Chaos Blog
Michael Farnum's Blog
Phillip Hallam-Baker's Blog - The dotFuture Manifesto: Internet Crime, Web Services, Philosophy
Stuart King's Security and Risk Management Blog
David Lacey's IT Security Blog
Metasploit Official Blog
Jeff Pettorino's Security Convergence Blog
Jeff Richards's Demand Insights Blog
David Rowe's Risk ManagementBlog
Bruce Schneier's Security Blog
Larry Seltzer's Security Weblog
Mike Spinney's Private Communications Blog
Richard Steinnon's Threat Chaos Blog
The TechWeb Blog
Tim Trent's Marketing by Permission Blog
Rebecca Wong 's DP Thinker Blog

Newsletters
23 February Newsletter
Newsletter Archives are located in "News"

Industry Update
Internet Security Intelligence Briefing - November 2005
Find out the latest trends in e-commerce, web usage & the latest threats from adware/Spyware

Reports
Phorm, Webwise and OIX
- BCS Security Forum

'The Any Era has Arrived, and Everyione has Noticed' - Stratton Sclavos - VeriSign
Identity Security - Time to Share
Malicious code threats - iDefense
Public Alerts - updated as they happen from Stopbadware.org
Public Alerts - updated as they happen from Websense
Public Advisories - updated as they happen, from iDefense
Phoraging - Privacy invasion through the Semantic web: a special report by Mike Davies of VeriSign

Legislation
Privacy Laws & Business International E-news, Issue 57
Privacy Laws & Business UNited Kingdom E-news, Issue 60

Security Reviews
February 2007 - VeriSign Security Review
The security review archive is here

Case Studies
Finance Industry
Case Study Example

A case study on a Finance industry company.

White Papers
VeriSign® Intelligent Infrastructure for Security
VeriSign® Intelligent Infrastructure: An Overview
Identity Protection Fraud Detection Service - description of the service
Life of a Threat - Video on Threat Management Lifecycle
Optimizing Enterprise Information Security Compliance - Dealing with all the audits
For a full list of all whitepapers, visit our Whitepaper library

Legal Notices
Privacy Policy
Terms of use

basel 2 sarbanes oxley
    legislation
data controller notification binding corporate rules BCR data transfer third countries third part data transfer basel 2 regualtor regulation regulate FSA banking network security RSA encryptin algorithm Bits sacked bank staff
Blogs compliance Reports compliancy Legislation Data Protection Case Studies data privacy White Papers data protection act News information commissioner Events security standards Links information security iDefense
Retail Solutions

ISPA on Spam. Block port 25 says Trend Micro

compliance and privacy

Current News Updates

ISPA on Spam. Block port 25 says Trend Micro

An article in silicon.com today is headlined "Spam storm needs ISP action, urges security chief", and so it does. ISPs have the ability to secure mail servers, making it next to impossible for spammers to exploit the weakness attributed to an unsecured mail server running in port 25, the port of choice for spammer attacks.

But the article also highlights David Rand, CTO of security company Trend Micro, who told silicon.com: "I absolutely believe this is the ISPs' responsibility. Yet top ISPs still aren't doing anything."

Rand said: "It's not like the ISPs can't tell this is going on. They can see all this on their networks."

So far so good. He's right. And it is obviously not lack of knowledge that stops the ISP from killing SPAM. But Rand is also quoted as saying that the blocking of port 25 will pretty much solve this problem. The article says:

Many leading ISPs currently refuse to take measures such as blocking port 25 traffic, a move which Rand claimed would affect very few users sending legitimate email, while blocking the port used to relay email via the internet on compromised machines.

But blocking port 25, the way, for example Now! Wireless Broadband does simply aggravates users who work form home and need to log in to the office's mail server to send mail, or who have multiple legitimate mail servers to which they need to go in order to send their email correctly. Experts tell Compliance and Privacy that "Blocking port 25 is naive in the extreme. Mail servers should be properly secured instead of blocking port 25"

Apart from this area, one which should concern everyone who uses the corporate email server from home (with no VPN or other system), or presumably on the move, from hotels, from wieless hotspots, the article has a great deal of validity. We commend it to you. But not the Port 25 part!


ISPA to Give Evidence on Personal Internet Security

The Internet Services Providers' Association (ISPA UK) - the UK's leading Internet trade association – has been called upon to give evidence to the House of Lords Science and Technology Committee.

ISPA will aid the Committee in their Personal Internet Security inquiry.  The inquiry has been prompted by increasing home computer use, broadband take-up and the growth of eCommerce and Internet banking.

ISPA Council members James Blessing, Chief Operating Officer at Entanet; Matthew Henton, Head of Marketing at Brightview and Camille de Stempel, Director of Policy at AOL, will be giving evidence to the committee on March 14th 2007.

The UK Internet industry has an excellent track record of making the ‘net safer through self-regulation. ISPA members regularly invest in educating customers by providing advice and guidance on Internet security issues, such as avoiding viruses, preventing their PCs from being hacked, and limiting and reporting spam.

Since the Committee's call for evidence in 2006, ISPA has submitted written evidence to the inquiry and held a Parliamentary Advisory Forum event in January 2007 on Personal Internet Security.  The discussion was attended by Parliamentarians, government officials, law enforcement representatives and leading figures from industry, highlighting ISPA's commitment to a multi-stakeholder approach addressing the economic, technological and social issues of online security.

ISPA is currently drafting a series of Best Current Practice (BCP) documents advising ISPA members on various issues.  Each BCP represents what ISPA considers to be best practice at the time of publishing.

Jessica Hendrie-Liaño, Chair of ISPA Council said “Tackling personal Internet security must be a joint effort between the Internet industry, the Government and significantly end-users.  It is important that the nature of the Internet is understood and the success of the industry's hard work to date is acknowledged.”

 


This site is independent of all its sources
The contents of the site are sourced from across the industry. All copyrights are acknowledged.