Nominate the LogBlog!

Love this blog?  Tell the folks at CMP with a nomination for the Second Annual Blog-X Awards.  Simply follow these instructions.  Go LogBlog!

Click to nominate:  http://www.techweb.com/blogawards/nominate2.html#nominate

Title of Blog:  LogLogic's LogBlog

URL:  http://logblog.blogs.com/log_management_for_compli/loglogic_news/index.html

Covers:  Networking

LogLogic at SANS Network Security Conference

It was standing room only today at the SANS Network Security Conference in Los Angeles.  More than 100 students attended LogLogic's Lunch & Learn entitled "Log Management for the IT Professional."

Chima Njaka, LogLogic's systems engineer dazzled the crowd with a log management product presentation including a live demo.  Want to learn more about LogLogic events?  Click here.

More on our partnership with BlueCoat

SOX Compliance Journal has more on our partnership with BlueCoat. We're providing advanced support for the Blue Coat ProxySG family of appliances, which include the ability to provide ah-hoc, real-time reports on Web caching and Web surfing activity extracted from ProxySG log data. And, you can aggregate, archive, and quickly search unaltered Blue Coat logs to ensure compliance with requirements from Sarbanes-Oxley and HIPAA, as well as legal inquires if needed. Search-filter alerts from Blue Coat logs can also be set up to warn administrators of suspicious or unusual behavior.

LogLogic on the Cover of Secure Convergence Journal

Wow!  The October, 2005 issue of Secure Convergence Journal features a cover story written by LogLogic's very own Dominique Levin entitled "Using Log Data to Manage Operational Risk."  Be sure and check it out. 

Secure CJ Cover

Data Leakage in NY

Expect to see this more and more....

Information Leaks Leave University Students Vulnerable

By Eleazar David Meléndez
Spectator Staff Writer  October 05, 2005

A harmless act of procrastination by a Queens College law student inadvertently uncovered what has become a massive headache for hundreds of City University of New York students, employees, and affiliates.
The university rushed to inform CUNY students last week that a security foul-up had compromised their confidential information. As New York Newsday first reported on Tuesday, the student, Googling her own name at a computer in the school’s library, found a set of documents that revealed the sensitive personal information of over 300 students. She told Newsday she recalled screaming, “What the hell is this?” in the middle of the library.

CERT Pushes for Standard Malware Names

Newsfactor Network is reporting that CERT Pushes for Standard Malware Names
The U.S. Computer Emergency Readiness Team (US-CERT) has kicked off
an initiative to create common names for Internet worms and threats.
The Common Malware Enumeration (CME) initiative aims to reduce confusion with the general public that is caused by disparate naming schemes for Internet threats.

A recent worm that used a known vulnerability in the Windows operating system, for instance, was referred to as Zotob.E by Symantec, W32/IRCbot.worm!MS05-039 by

Currently, Internet worms are often named using information about the virus or follow a description the author entered when crafting the malware. The new naming scheme uses a CME-number, with the first virus being called CME-1 and so forth.

Tell Your Friends: Vote for LogLogic

Log Vote 2006

The 2006 SC Magazine Awards nominations are in and LogLogic needs your vote.  LogLogic is nominited in two categories.  Vote today.  No time to wait!  Voting ends October 28, 2005.

SC Awards 2006

Compliance Tips from the Pros

SearchSecurity today has some tips to streamline and spearhead your compliance efforts.   

While many of you have undergone the rigors of meeting compliance requirements for Sarbanes-Oxley, some of you are new to the role, or are associated with companies that are just going public and have not previously been subject to this legislation. For those of you lucky enough to have drawn the assignment, the task may seem quite daunting. However, there are a few steps you might want to consider that could help slice sizeable task into manageable servings.

Personal Data Breach Study

Two recent articles site stastics from New York-based global law firm of White & Case LLP who just released the results of a national survey on data security breach notification.   Computerworld's piece says

In a national survey of more than 1,000 victims of personal data security breaches, nearly 20% said they had already terminated their relationships with companies that maintained their data, while another 40% said they might do so. And nearly 5% of those surveyed said they had hired lawyers to seek legal recourse after their data was put at risk.

This SearchSecurity piece states

The goal in all of these laws is to ensure consumers know when they're at risk of fraud and identity theft. But such a measure does not come without consequences. Rather than be grateful for the notice, consumers are angry that the messages are densely written or void of details, and they're terminating relationships and even seeking damages in court.

SOX Deadline

Are you ready?  Forty-five percent of IT executives responding to an August poll said their companies are unlikely to meet the message retention requirements of Sarbanes-Oxley by the July 2006 deadline