Fashioned after online self-assessment tools used by authorities to assess vulnerabilities at airports, the Department of Homeland Security on Friday unveiled software it developed to let officials identify vulnerabilities and assess the security at stadiums with large seating capacity. . The vulnerability self-assessment tool, which is accessible through a Web portal, incorporates industry safety and security best practices for critical infrastructure to assist in establishing a security baseline for each stadium. Once a baseline is established, the tool identifies the strengths of existing security programs as well as areas in need of improvement, letting authorities prioritize vital improvements to a stadium's security. The new tool is designed for the more than 400 large-capacity stadiums that seat more than 30,000 people. Later this year, the tool will be made available to operators of arenas, convention centers, and performing arts centers. "Our goal is to encourage stadium managers to integrate this tool into their standard planning process and use it throughout the year," Frank Libutti, undersecretary of information analysis and infrastructure Protection, said in a statement. The link for this article located at Eric Chabrow is no longer available. . The application assists event coordinators in pinpointing safety advantages and development zones, boosting protective measures.. Stadium Security, Vulnerability Assessment, Infrastructure Protection. . Joe Shakespeare
The security industry has matured quickly over the past few years with penetration testing becoming one of the norms for organisations adopting best-practice processes. Loosely defined as the process of actively assessing an organisations security measures and completely reliant on consultancy services, security manufacturers have been eager to bridge the gap between product and service and more importantly to reap the benefits of additional profits. Not surprisingly, we have seen the emergence of the automated penetration test with a number of providers springing up to fill the sector. . . .. The security industry has matured quickly over the past few years with penetration testing becoming one of the norms for organisations adopting best-practice processes. Loosely defined as the process of actively assessing an organisations security measures and completely reliant on consultancy services, security manufacturers have been eager to bridge the gap between product and service and more importantly to reap the benefits of additional profits. Not surprisingly, we have seen the emergence of the automated penetration test with a number of providers springing up to fill the sector. The main advantages cited by these providers are that they are faster and significantly cheaper than traditional security assessments performed by consultants using a range of tools. With such promises, it has been little wonder that the security industry has seen a new trend evolving and a movement away from the traditional approach to the automated one has become apparent. However, although the benefits sound reasonable enough it is arguable that in fact those organisations pursing this fashion have actually acquired a solution that provides only part of the penetration testing process; they have in truth bought into a false sense of security. In these times of limited budgets and cost constraints, anything that reduces outlay has been welcomed, but obviously only if it's actually fulfilling the requirement. So when considering the meritsof both automated and traditional penetration testing, organisations must begin by considering the range of activities available via either approach. These days, penetration testing (or more accurately, security assessment) covers a range of activities, with the full spectrum of prior knowledge (white-box), from none to complete and all the combinations in-between. A thorough security assessment also includes elements of architectural review, security policy, firewall rulebase analysis, application testing, and general benchmarking against industry and manufacturer best practise. This will result in a comprehensive report that is tailored to the specific requirements of the organisation that has commissioned the project. The link for this article located at ebcvg.com is no longer available. . Automated penetration testing is efficient and cost-effective, but over-reliance on it can create a false sense of security, risking significant vulnerabilities.. Penetration Testing, Automated Security Assessments, Risk Evaluation, Security Consulting. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.