- +
Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15
Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients? - +
Strategies for Dealing With IT Complexity 24/12/2007 10:30:47
Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business. - +
Your World. . . Hacked 02/10/2007 10:51:23
As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to competeThe call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network
Read up on the latest ideas and technologies from companies that sell hardware, software and services. How to Beef Up Your Sales Pipeline
Wireless LANs: Is my enterprise at risk?
Enterprise Wireless WLAN Security
Understanding Email Marketing: A Guide for SMBs
Realizing the Value of Unified Communications
Choices in Storage Architecture for Oracle Environments
Solve Exchange Storage Problems Once and For All: A New Approach without Stubs or Links
Why Security SaaS Makes Sense Today
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
Even with identity theft making front-page news, many IT executives fail to understand the risks inherent in conducting business online. And for those who do, addressing those risks can seem an arduous challenge given how complex Web sites and Internet apps have become.
With Watchfire WebXM 4.0, however, leaving Web channels out of your overall security strategy is a thing of the past. The solution has evolved from a strong Web quality and accessibility reporter to an all-inclusive application that analyzes sites for more than 245 compliance and security troubles. More than just give visibility into problems via executive dashboards, WebXM allows managers to assign and track specific issues that affect an enterprise's Web presence.
WebXM 4.0 is built around a core Windows .Net application -- with which you schedule scans of your Web environments -- and the reporting engine. Using the hosted version of this solution, I first conducted an automated inventory of several large sections of a corporate site and five international Web sites in their entirety. Setting up scans is quick, with a wizard asking what types of data you want collected. Similarly, "Web spaces" can be effortlessly grouped and given permissions in any way you desire. For example, I placed international sites within logical geographical folders and set user permissions to allow each region's Web manager to view statistics pertaining only to his or her site.
The default Asset Management reports show the expected facts, such as number of pages, technical details about domains and servers, and page age. Yet, the unusual clarity of reports helps you quickly take action. For example, displaying a Network Inventory revealed several servers with SSL certificates close to expiring -- and other sites that had weak, 40-bit certificates when they should have 128-bit encryption.
Digging deeper into the page reports, I had no trouble spotting duplicate pages, nor did I have difficulty finding pages with obsolete information. WebXM's user interface makes it easy to drill down from the overview report to specific pages so that remedial action can be taken to rectify any problems that come up.
To look for more serious issues, I turned to several of the seven optional modules: Security, Privacy, Compliance, Quality, Accessibility, Corporate Standards, and Brand Monitoring. Giving you insight into broken links and slow pages, the Quality module helps you keep visitors returning to your site. Perhaps more important, the Accessibility module performs more than 170 accessibility checks to help you meet the US Section 508 guidelines and the UK's Disability Discrimination Act, though there are no details yet about assistance with acts under Australian laws.
WebXM 4.0 hits its stride helping organizations meet privacy and security regulations. The Compliance module, for example, points out Web forms that don't have proper opt-out language. Other reports inventory third-party links that lack proper disclosures, improper privacy practices, and pages that don't meet specific legislation. This information is essential for e-business, marketing, legal, and other executives accountable for compliance.
There's no overstating the importance of Web application security. Yet the cost of manual and outsourced security testing can be prohibitive -- and still miss risks. For those reasons, I was most impressed with WebXM's Security module. First, reports highlighted potential security glitches that would have to be fixed to meet, for example, Sarbanes-Oxley legislation. The system provides detailed information for each issue it finds, details your risk exposure, and offers steps to fix it. That sort of help extends to addressing basic weaknesses, such as cross-site scripting and SQL injection. Even more, I liked the depth of help available, such as links to online resources about particular problems.
The Corporate Standards and Brand Monitoring modules were unavailable for testing, but they appear useful. For example, corporate identity managers should be able to determine whether intranet sites have copyright statements and proper link naming. Plus, brand managers can detect trademark and brand infringement across the Internet. Trying to find the latter incidents of cybersquatting and other types of false affiliation would otherwise be difficult.
Watchfire also planned to introduce in August its Intranets Standards module, which identifies sensitive and insecure content inside the firewall -- such as health, HR, and financial data -- to help organizations meet additional compliance regulations. The company will also deliver a Banking Compliance module that maps the system's general content analysis to specific federal consumer protection requirements.
Managers can then track the improvement of issues detected by any of WebXM's modules, marking them as open, fixed, or in progress. Although WebXM's integration with third-party defect-tracking systems is elementary, Watchfire representatives say the company is working to make this stronger.
I'd also like more extensive report export functions. You can convert dashboard results to an Excel file -- and save individual report data as an XML file. But the latter function means writing the transformation code to view the data; Watchfire professional services will perform this step, but that shouldn't be necessary.
Finally, I have some concern about performance. The setup Watchfire provided scanned slowly, requiring 45 minutes to evaluate a 2000-page site. (The company indicated that it's possible to have scan and report agents run on additional application servers to improve speed.)
On balance, however, Watchfire XM 4.0 delivers very good value. Deep Web content scanning and analysis gives content owners new insight into their Web properties and how they can be improved to meet specific compliance requirements. The Security module is especially notable, exposing failings in server configuration and coding that, left unchecked, could permit phishing attacks, ID theft, and site defacements.
Watchfire WebXM 4.0
Watchfire, watchfire.com
Very good
Cost: Starts at $US3500 per month for hosted service or $US35,000 for software licence
Platforms: Installed application runs on Microsoft Windows Server
Bottom line: WebXM scans large Web sites and generates interactive Web-based reports that detail a range of online risk and compliance issues. Enterprises can select from various modules, including Security, Compliance, and Quality. New security component pinpoints weaknesses that could result in identity theft and related losses. Integrated issue management helps prioritize and track critical changes.
Computerworld Member Login
Prioritizing Services with IT Service Management (ITSM)
Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)
To be repeated on:
Thursday 4th, September 2008
11:00am EST (Sydney Australia)
Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.
Attend and discover:
- How to deliver value to your business through ITSM
- Best practice ITSM implementation
- Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
- If service-oriented ITSM is best for your business
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Viva la Verticals! Key to Vendor Growth is Through Vertical Market Opportunities, Says IDC 2008-09-05 11:05:00+10
F-Secure delivers fastest protection in the online world 2008-09-04 16:50:00+10
NETGEAR expands ProSafe team as business-class products take off in SME market 2008-09-04 16:27:00+10
Rogue security apps dominate Fortinet's Aug 2008 IT threat report 2008-09-04 16:00:00+10
Adaptec Intelligent Power Management Reduces Storage Power Consumption Up to 70 Percent 2008-09-04 11:28:00+10
Radicati Market Quadrant 2008 on Corporate Web Security
An Analysis of the Market for Corporate Web Security Solutions, revealing Top Players, Mature Players, Specialists and Trail Blazers. Read on to discover who makes the grade.









