SANS Forensics Blog
Great resource for the latest for legal issues, tools, and ideas about forensics and e-discovery.
One of the stories (the Zeus trojan) reminds me of a previous engagement with a company. They had a number of consistent compromises of internal systems and then also external (non-employee) brokers that used our systems and became compromised. During the SEC investigation they found that the company was responsible for inadequate security controls on the brokers systems, and that the SEC held them responsible for allowing insecure computers to connect to financial systems. So keep that in mind, your customer's security may be your business.
Great resource for the latest for legal issues, tools, and ideas about forensics and e-discovery.
One of the stories (the Zeus trojan) reminds me of a previous engagement with a company. They had a number of consistent compromises of internal systems and then also external (non-employee) brokers that used our systems and became compromised. During the SEC investigation they found that the company was responsible for inadequate security controls on the brokers systems, and that the SEC held them responsible for allowing insecure computers to connect to financial systems. So keep that in mind, your customer's security may be your business.
Comments