<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>The Qualys® Newsletter</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/" />
    <link rel="self" type="application/atom+xml" href="http://news.qualys.com/atom.xml" />
    <id>tag:news.qualys.com,2008-02-21://3</id>
    <updated>2008-11-13T18:16:19Z</updated>
    
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type Personal 4.1</generator>

<entry>
    <title>Qualys Selected as One of the Fastest Growing Companies in North America</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/11/qualys-named-to-deloitte-touch.html" />
    <id>tag:news.qualys.com,2008://3.65</id>

    <published>2008-11-12T18:22:21Z</published>
    <updated>2008-11-13T18:16:19Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Company News" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="Deloitte_TF500.gif" src="http://news.qualys.com/images/Deloitte_TF500.gif" class="mt-image-none" style="" height="66" width="270" /></span><br /><br />Qualys has been chosen as one of Deloitte's 2008 Technology Fast 500, a ranking of today's fastest growing technology, media, telecommunications and life sciences companies in North America. This industry distinction comes just several weeks after the company's most recent achievement as a Deloitte Silicon Valley Fast 50 where Qualys ranked #37 by demonstrating a five-year growth rate of 492 percent from 2003-2007. The five-year growth rate criteria was also used in selecting the Fast 500 companies placing Qualys as # 307 on the expanded list of industry notables.<br /><br /><i>"Being recognized as one of the fastest growing companies in North America is an honor that we share with our customers who from the beginning believed in our Software-as-a-Service solution for IT security and compliance management," said Philippe Courtot, Qualys CEO.&nbsp; "We thank Deloitte for the ranking that underscores our efforts to help organization worldwide get a clear view on their IT security and achieve compliance."<br /><br /></i><a href="http://www.qualys.com/company/newsroom/newsreleases/usa/?view=20081113" target="blank">Read More</a><i><br /></i>]]>
        
    </content>
</entry>

<entry>
    <title>Microsoft Patch Tuesday: November 2008 Security Bulletin</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/11/microsoft-patch-tuesday-novemb.html" />
    <id>tag:news.qualys.com,2008://3.64</id>

    <published>2008-11-12T17:58:28Z</published>
    <updated>2008-11-12T21:32:59Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Security Alerts" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://www.icvclients.com/qualys/QualysNovember1108.mp3" target="blank"><img alt="Security-Alert-WK+AS.gif" src="http://news.qualys.com/images/Security-Alert-WK%2BAS.gif" class="mt-image-none" style="" height="200" width="466" /></a></span><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><br /><br />Qualys®
Vulnerability R&amp;D Lab has released new vulnerability checks in
QualysGuard® to protect organizations against 2 new vulnerabilities
present in Microsoft Windows. Customers can immediately audit their
networks for these and other recent vulnerabilities by accessing their
QualysGuard subscription.<br /><br />Microsoft released on November 11, 2
security patches to fix newly discovered flaws in Microsoft Windows.
The Qualys Vulnerability R&amp;D Lab has released the following checks
for these new vulnerabilities:<br /><br /></span><blockquote>- Microsoft SMB Could Allow Remote Code Execution<br />- Microsoft XML Core Services Remote Code Execution Vulnerability<br /></blockquote><a href="http://www.qualys.com/research/alerts/view.php/2008-11-11" target="blank">Read Alert</a><br /><a href="http://www.icvclients.com/qualys/QualysNovember1108.mp3" target="blank">Listen to Podcast</a><br /><br /><b>Related Coverage:</b> <br /><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9119852&amp;intsrc=hm_list" target="blank">Microsoft Patches Long-Known Windows Bugs</a>, by Gregg Keizer, Computerworld <br /><a href="http://www.scmagazineus.com/Microsoft-doles-out-two-patches-for-four-flaws/article/120840/" target="blank">Microsoft Doles Out Two Patches for Four Flaws</a>, by Dan Kaplan, SC Magazine<br /><span class="headline"><a href="http://www.internetnews.com/security/article.php/3784331/Teed+Up+for+November+Office+Windows+Fixes.htm" target="blank">Teed Up for November: Office, Windows Fixes</a>, by Andy Patrizio,</span> InternetNews.com ]]>
        
    </content>
</entry>

<entry>
    <title>Vulnerability Management That Works</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/11/vulnerability-management-that.html" />
    <id>tag:news.qualys.com,2008://3.63</id>

    <published>2008-11-12T17:53:34Z</published>
    <updated>2008-11-12T21:32:25Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Industry News" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="InformationWeek-VAP.gif" src="http://news.qualys.com/images/InformationWeek-VAP.gif" class="mt-image-right" style="margin: 0pt 0pt 20px 20px; float: right;" height="197" width="254" /></span>InformationWeek discovers how IT can implement an effective vulnerability management program that works. &nbsp;<br /><br />For an effective vulnerability management that works -- apply risk management principles and logic relative to the business value. IT must also engage across business units to determine a company-wide security posture that is within acceptable risk tolerance levels, create operational processes that address the computing environment as a whole, and select the right technology platforms to bolster those processes.Critical steps to break the cycle of ineffectiveness:<br /> <br /><b>&nbsp;&nbsp;&nbsp;&nbsp;Step 1: Integrate Data Collection <br />&nbsp;&nbsp;&nbsp;&nbsp;Step 2: Prioritize <br />&nbsp;&nbsp;&nbsp;&nbsp;Step 3: Continue to Refine<br /></b><br /><a href="http://www.informationweek.com/news/security/vulnerabilities/showArticle%0D.jhtml?articleID=212000971" target="blank">Read More</a> ]]>
        
    </content>
</entry>

<entry>
    <title>Keys To Success Of Vulnerability Management</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/11/keys-to-success-of-vulnerabili.html" />
    <id>tag:news.qualys.com,2008://3.62</id>

    <published>2008-11-12T17:47:49Z</published>
    <updated>2008-11-12T21:31:54Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Industry News" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="InformationWeek-VAP.gif" src="http://news.qualys.com/images/InformationWeek-VAP.gif" class="mt-image-right" style="margin: 0pt 0pt 20px 20px; float: right;" height="197" width="254" /></span>InformationWeek outlines four principles to achieve ongoing vulnerability management success:<br /><b><br />Principle 1: Focus on Output, Not Input</b><br />Tools are only a means to an end. Data collection is a fundamental requirement for vulnerability management, but providing timely, accurate, contextual reports to appropriate individuals is critical. Many organizations develop programs that generate vast amounts of data, but struggle to make it actionable and measurable.<br /><br /><b>Principle 2: Align with Business Processes</b><br />Vulnerability management process integration with and awareness of business processes is critical to understanding enterprise risk and focusing on the areas that matter most.<br /><br /><b>Principle 3: Continue to Integrate Technologies</b><br />Incorporating change and configuration technologies will increase the reliability of data, build accurate reporting, and increase overall effectiveness in lowering enterprise risk and achieving compliance objectives.<br /><br /><b>Principle 4: Leverage Measurement and Promote Visibility</b><br />Defining key performance indicators, such as an acceptable host-to-vulnerability ratio, and using measurement tools will help focus the program on activities that will have the most impact.<br /><br /><a href="http://www.informationweek.com/news/security/vulnerabilities/showArticle.jhtml?articleID=212000972" target="blank">Read More</a><br /> ]]>
        
    </content>
</entry>

<entry>
    <title>Deloitte&apos;s Technology Fast 50 Recognized Qualys for Strong Five-Year Growth Rate</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/11/deloittes-technology-fast-50-r.html" />
    <id>tag:news.qualys.com,2008://3.55</id>

    <published>2008-11-05T19:44:46Z</published>
    <updated>2008-11-08T00:10:13Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Company News" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="Don-McCauley-DFF-Award.gif" src="http://news.qualys.com/images/Don-McCauley-DFF-Award.gif" class="mt-image-right" style="margin: 0pt 0pt 20px 20px; float: right;" height="509" width="332" /></span>The Silicon Valley Technology Fast 50 Program honors the fastest growing software and information technology companies in the San Francisco Bay Area. Don McCauley, Qualys CFO Qualys accepted this honor at The Computer History Museum on October 30th.<br /><br /><i>"We are pleased to be regarded by Deloitte as one of the fastest growing software and information technology companies in Silicon Valley," said Philippe Courtot, Qualys CEO.&nbsp; </i><i>"We share this recognition with our customers who understand the value of Software as a Service.&nbsp; It is through the customer adoption of this innovative platform that we continue to experience growth and we extend a thank you to our customers for making this achievement possible."</i><br /><br /><a href="http://www.qualys.com/company/newsroom/newsreleases/usa/?view=20081031" target="blank">Read More</a><br />]]>
        
    </content>
</entry>

<entry>
    <title>Nils Puhlmann of Electronic Arts Joins Qualys as CSO &amp; VP of Risk Management</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/11/nils-puhlmann-of-electronic-ar.html" />
    <id>tag:news.qualys.com,2008://3.61</id>

    <published>2008-11-05T19:10:05Z</published>
    <updated>2008-11-05T19:23:18Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Company News" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="Niles_Puhlmann.gif" src="http://news.qualys.com/images/Niles_Puhlmann.gif" class="mt-image-left" style="margin: 0pt 20px 20px 0pt; float: left;" height="230" width="143" /></span>Nils is responsible for security, risk management and business
continuity planning, including the security of the QualysGuard
platform. Additionally, with his working industry knowledge, Nils will
oversee Qualys' <a href="http://www.qualys.com/company/csoboard/" target="blank">CSO Advisory board</a> which main charter is to collaborate
with other CSOs and industry leaders to offer real-world expertise in
forging and implementing security and compliance best practices. <br /><br />He stated: <i>"Qualys has differentiated itself within the industry with its SaaS
delivery platform and by keeping attention focused on the needs of the
customer. I am looking forward to work with the Qualys
team and with other CSOs in the industry to collaborate on real-life
security and compliance issues and come up with best practices to
address them."</i><br /><br /><a href="http://www.qualys.com/company/newsroom/newsreleases/usa/?view=20081105" target="blank">Read More</a>]]>
        
    </content>
</entry>

<entry>
    <title>Tata Communications Launches New Vulnerability Management Service with Qualys</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/11/tata-communications-launches-n.html" />
    <id>tag:news.qualys.com,2008://3.57</id>

    <published>2008-11-05T16:00:00Z</published>
    <updated>2008-11-05T19:03:47Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Company News" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="Tata.gif" src="http://news.qualys.com/images/Tata.gif" class="mt-image-right" style="margin: 0pt 0pt 20px 20px; float: right;" height="158" width="187" /></span>"Our partnership with Tata Communications allows them to offer their global customer base a proven, scalable and cost effective solution to help these organizations improve their security and streamline compliance initiatives. We are pleased to partner with such a world class organization and look forward to working with them" said Philippe Courtot, Qualys CEO. <br /><br />John Landau, Senior Vice President of Global Managed Services for Tata Communications spoke about the company's latest launch saying&nbsp; - "Effectively managing vulnerabilities to best-practice levels, in-house, is an expensive and difficult undertaking for businesses of any size. Mistakes can lead to crippling service downtime, potential data corruption, and the risk of being non-compliant. Tata's vulnerability management service helps organizations wrap their arms around which critical systems need patching at a drastically reduced total cost of ownership. There is no investment in capital or special skills required. The service allows customers both large and small to offload the grinding technical and operational aspects of vulnerability management while retaining control over decision-making and the actual remediation process."<br /><br /><a href="http://www.qualys.com/company/newsroom/newsreleases/usa/?view=20081105b" target="blank">Read More</a> ]]>
        
    </content>
</entry>

<entry>
    <title>MarketScope for Vulnerability Assessment</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/10/marketscope-for-vulnerability.html" />
    <id>tag:news.qualys.com,2008://3.60</id>

    <published>2008-10-31T19:01:54Z</published>
    <updated>2008-10-31T19:04:53Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Industry News" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"></span><span class="mt-enclosure mt-enclosure-image" style="display: inline;"></span><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="gartner.png" src="http://news.qualys.com/images/gartner.png" class="mt-image-none" style="" height="40" width="117" /></span><br /><br />In this MarketScope report, Gartner details the challenges and tools to consider when evaluating and deploying Vulnerability Assessment technologies. MarketScope includes Gartner's vendor rating where Qualys received the highest possible rating ('Strong Positive').<br /><br /><a href="http://mediaproducts.gartner.com/reprints/qualys/156038.html" target="blank">Read Report</a>]]>
        
    </content>
</entry>

<entry>
    <title>Free Webcast: Web 2.0 Security ThreatsWednesday, November 12th, 11:00am PST</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/10/free-webcast-web-20-security-t.html" />
    <id>tag:news.qualys.com,2008://3.59</id>

    <published>2008-10-28T21:58:41Z</published>
    <updated>2008-10-28T22:45:50Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Training &amp; Events" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://events.qualys.com/content/Forrester_Webcast_Nov8" target="blank"><img alt="Forrester-Webcast-110208.gif" src="http://news.qualys.com/images/Forrester-Webcast-110208.gif" class="mt-image-right" style="margin: 0pt 0pt 20px 20px; float: right;" height="299" width="346" /></a></span>This talk will examine how the adoption of Web 2.0 and consumer
technologies impact application security and how you should respond to
the new requirements. Topics covered:<br /> 
<ul><li>Global trends and the enterprise security impact of Web 2.0
adoption, de-perimeterization, and the consumerization of corporate IT.
</li><li>Steps information security professionals can follow to
strengthen application security, especially in an open and
collaborative environment. </li><li>An overall application security maturity model, and steps to create best-practices for application security.</li></ul><a href="http://events.qualys.com/content/Forrester_Webcast_Nov8" target="blank">Register</a>]]>
        
    </content>
</entry>

<entry>
    <title>Stanford Hospital&apos;s, CISO Michael Mucha Writes Feature Essay for Information Security Magazine</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/10/stanford-hospitals-ciso-michae.html" />
    <id>tag:news.qualys.com,2008://3.58</id>

    <published>2008-10-28T19:14:02Z</published>
    <updated>2008-10-28T22:50:06Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Customers in the News" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="info-security-10-08.gif" src="http://news.qualys.com/images/info-security-10-08.gif" class="mt-image-right" style="margin: 0pt 0pt 20px 20px; float: right;" height="225" width="181" /></span>As an honoree of Information Security's Security 7 award, Michael Mucha addresses Security for the Masses highlighting his team's attention to secure collaboration and proactive investments in SaaS and other outsourcing ventures enabling focus on risks specific to the Stanford Hospital environment.<br /><br /><span class="mt-enclosure mt-enclosure-file" style="display: inline;"><a href="http://news.qualys.com/files/October_08_Michael_Mucha.pdf">Read Essay</a></span> <div><br /></div><div><br /></div>]]>
        
    </content>
</entry>

<entry>
    <title>Customers Speak Out</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/10/customers-speak-out.html" />
    <id>tag:news.qualys.com,2008://3.56</id>

    <published>2008-10-20T16:39:25Z</published>
    <updated>2008-11-17T20:14:41Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Customers in the News" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[Hear what Qualys customers have to say about their experience with QualysGuard®. <br /><br />To view the full-length interviews, visit:<br /><a href="http://www.qualys.com/customers/testimonials/" target="blank">http://www.qualys.com/customers/testimonials/</a><br /><br />

<!-- saved from url=(0013)about:internet -->
<object classid='clsid:d27cdb6e-ae6d-11cf-96b8-444553540000' codebase='http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0' width='600' height='368' id='videoSkin' align='middle'>
<param name='allowScriptAccess' value='always' />
<param name='flashVars' value='configXML=http%3A//icvdm.vo.llnwd.net/o10/Qualys/media_assets/xml/pullout_video_qualys.xml&emailAddress=your-friends-email-here&emailSubject=Customers%20Using%20QualysGuard&emailBody=Check%20out%20this%20video%20%5BURL%20Here%5D&enableMenu=false' />
<param name='movie' value='http://icvdm.vo.llnwd.net/o10/Qualys/media_assets/swf/qualys_video_non_autostart.swf' /><param name='quality' value='high' />
<param name='bgcolor' value='#ffffff' />
<embed src='http://icvdm.vo.llnwd.net/o10/Qualys/media_assets/swf/qualys_video_non_autostart.swf' quality='high' bgcolor='#ffffff' width='600' height='368' name='videoSkin'
 align='middle' allowScriptAccess='always' type='application/x-shockwave-flash'
 pluginspage='http://www.macromedia.com/go/getflashplayer' flashVars='configXML=http%3A//icvdm.vo.llnwd.net/o10/Qualys/media_assets/xml/pullout_video_qualys.xml&emailAddress=your-friends-email-here&emailSubject=Customers%20Using%20QualysGuard&emailBody=Check%20out%20this%20video%20%5BURL%20Here%5D&enableMenu=false'/>
</object>]]>
        
    </content>
</entry>

<entry>
    <title>Qualys Ranked the 36th Fastest Growing Company in Silicon Valley by The Silicon Valley/San Jose Business Journal&apos;s 2008 &apos;Fast 50&apos;</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/10/qualys-ranked-the-36th-fastest.html" />
    <id>tag:news.qualys.com,2008://3.54</id>

    <published>2008-10-10T22:57:08Z</published>
    <updated>2008-10-16T22:56:38Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Company News" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="Rima-Bruno-Fast50-Award.png" src="http://news.qualys.com/images/Rima-Bruno-Fast50-Award.png" class="mt-image-right" style="margin: 0pt 0pt 20px 20px; float: right;" height="398" width="300" /></span>In a private dinner ceremony held on October 7, 2008 at the San Jose Fairmont's Club Regency, Qualys Vice President of HR, Rima Touma-Bruno was in attendance to receive the Fast 50 award.<br /><br />"Being named the 36th fastest growing company in Silicon Valley is a tribute to the global adoption of our Security-as-a-Service platform and applications," said Philippe Courtot, CEO and chairman of Qualys. "We are honored that the San Jose/Silicon Valley Business Journal has recognized Qualys' growth, and in turn, highlighted the ease if use, quality, scalability and cost effectiveness that the Security-as-a-Service model uniquely provides."<br /><br /><a href="http://www.qualys.com/company/newsroom/newsreleases/usa/?view=20081010" target="blank">Read More</a><br /><br /> ]]>
        
    </content>
</entry>

<entry>
    <title>QualysGuard PCI 3.0 Helps Merchants Meet Now Mandatory PCI Requirement</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/09/qualysguard-pci-30-helps-merch.html" />
    <id>tag:news.qualys.com,2008://3.53</id>

    <published>2008-09-30T21:07:42Z</published>
    <updated>2008-10-02T17:30:43Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Product News" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="QG-PCI.gif" src="http://news.qualys.com/images/QG-PCI.gif" class="mt-image-none" style="" height="67" width="533" /></span><br /><br />QualysGuard PCI 3.0 now with a Web Application Scanning (WAS) module, combines the application's traditional compliance scanning, remediation and e-filing capabilities with automated web application scanning.&nbsp; This advancement helps merchants in their efforts to effectively meet requirement 6.6 for maintaining secure web applications. Specifically, the WAS module evaluates web applications before and after deployment. This ensures that the applications are built and maintained in a secure way. Delivered via Software-as-a-Service (SaaS), the WAS module fully automates the scanning of vulnerability types within customized code and allows customers to crawl web applications, identify cross-site scripting vulnerabilities, isolate SQL injection attacks and conduct authenticated and unauthenticated scanning. <br /><br /><a href="http://www.qualys.com/company/newsroom/newsreleases/usa/?view=20081001" target="blank">Read Press Release</a><br /><a href="http://www.qualys.com/docs/QG_PCI_3-0_Tech_Brief.pdf" target="blank">Read Technical Brief</a><br />]]>
        
    </content>
</entry>

<entry>
    <title>PCI DSS 1.2 Spec Released</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/09/pci-dss-12-spec-released.html" />
    <id>tag:news.qualys.com,2008://3.52</id>

    <published>2008-09-30T21:03:41Z</published>
    <updated>2008-10-10T22:56:37Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Industry News" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="PCI-DSS_1-2.gif" src="http://news.qualys.com/images/PCI-DSS_1-2.gif" class="mt-image-none" style="" height="57" width="255" /></span><br /><br />PCI DSS 1.2 represents an update to the original 12 requirements found in PCI DSS version 1.1.&nbsp; The intent of the latest specification is to clarify existing requirements and provide clarification and flexibility in terms of interpretation of the standard. <br /><br /><ul><li>Guidance around scope of PCI DSS and elaborate on segmentation of Cardholder data environment&nbsp;</li><li>Clarification of wireless technology requirements and provide sunset date for use of WEP - All WEP implementations must be discontinued as of June 30, 2010&nbsp;</li><li>Clarification around requirement 6.6 for web application security to remove references to source code review and add use of automated assessment tools&nbsp;</li><li>Require employees that interact with cardholder data to review and accept security policy annually</li><li>Compensating controls should now be reviewed and validated annually by a qualified assessor&nbsp;</li><li>Flexibility for incorporation of evolving technologies and threats&nbsp;</li><li>Announcement of Quality Assurance program for assessors <br /></li></ul><br /><a href="http://www.qualys.com/mp3s/Qualys093008_PCI_DSS.mp3" target="blank">Listen to Podcast</a><br /><a href="http://www.qualys.com/docs/PCI_DSS_1-2_Summary.pdf" target="blank">Read Summary</a><br /><br /><b>Related Coverage:</b><br /><a href="http://www.networkworld.com/news/2008/100108-pci-credit-card.html" target="blank">Credit-Card Security Standard Issued After Much Debate</a>, by Ellen Messmer, Network World<br /><a href="http://redmondmag.com/news/article.asp?EditorialsID=10260" target="blank">Payment Card Security Toughens With DSS 1.2 Release</a>, by <span class="aa11gray">Jabulani  Leffall, Redmond<br /></span>]]>
        
    </content>
</entry>

<entry>
    <title>Hot or Not: What You Need to Know to Keep Mac OS X Secure</title>
    <link rel="alternate" type="text/html" href="http://news.qualys.com/2008/09/hot-or-not-what-you-need-to-kn.html" />
    <id>tag:news.qualys.com,2008://3.51</id>

    <published>2008-09-25T23:51:20Z</published>
    <updated>2008-09-25T23:57:04Z</updated>

    <summary></summary>
    <author>
        <name>Qualys</name>
        <uri>http://www.qualys.com</uri>
    </author>
    
        <category term="Industry News" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://news.qualys.com/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://www.scmagazineus.com/Hot-or-not-What-you-need-to-know-to-keep-Mac-OS-X-secure/article/118073/" target="blank"><img alt="SC-Mag-Hot-or-Not.gif" src="http://news.qualys.com/images/SC-Mag-Hot-or-Not.gif" class="mt-image-right" style="margin: 0pt 0pt 20px 20px; float: right;" height="230" width="156" /></a></span>When it comes to security, Apple isn't sitting still. Amol Sarwate, guest columnist for SC Magazine's Hot or Not column looks at some of the new features inherent in OS X 10.5 that help keep the system secure. According to Apple, these security enhancements were added to 10.5, released last fall:<br /><br /><ul><li><b>Tagging and first-run warning:</b> Mac OS X 10.5 marks files that are downloaded to help prevent users from inadvertently running malicious downloaded applications.&nbsp;</li><li><b>Runtime protection:</b> New technologies such as execute disable, library randomization, and sandboxing help prevent attacks that try to hijack or modify system software.&nbsp;</li><li><b>Improved firewall:</b> After the new application firewall is activated, the firewall configures itself so that users get the benefits of firewall protection without having to understand the details of network ports and protocols.</li><li><b>Mandatory access control: </b>These enforce restrictions on access to system resources. Not even a compromised "root" user can change some settings.</li><li><b>Application signing: </b>This enables users to verify the integrity and identity of applications on the Mac.&nbsp;</li><li><b>Improved secure connectivity:</b> Virtual private network (VPN) support has been enhanced to connect to more of the most popular VPN servers-without additional software.<br /></li></ul><a href="http://www.scmagazineus.com/Hot-or-not-What-you-need-to-know-to-keep-Mac-OS-X-secure/article/118073/" target="blank">Read More</a> ]]>
        
    </content>
</entry>

</feed>
