Press

El País (July 2011): An Spanish investigator detects a serious vulnerability in Facebook

Article published in El País about a security vulnerability discovered on Facebook by Internet Security Auditors Audit Manager, Vicente Aguilera.


SIC 95 (June 2011): Return of Security Investment of PCI DSS

This paper was published in SIC magazine journal #95 (June 2011).

We analyze in detail how the reduction of risk (in economic terms) provided by the implementation of the PCI DSS regulations far exceeds the costs of a potential security incident related to payment cards. Therefore, the investment required to adapt the processes of a company to the PCI DSS has a positive return.

SIC 94 (April 2011): Security technical controls for application web protection

This article was published in SIC magazine journal #94 (April 2011).

The paper shows, through several OWASP projects, different techniques for protecting web applications focusing on areas such as architecture, authentication, session management, access control, input validation, output encoding, encryption, errors management and logging, data protection, security comunications, HTTP security, security settings, malicious code and internal security.

Red Seguridad 49 (November 2010): Tokenization and its application in PCI DSS

This article was published in Red Seguridad journal #49 (November 2010).

Article details one of the techniques of hiding information on the rise lately: "tokenization" or use of tokens. Article refers to the description of this security mechanism to use in the adjustement of processes and entities to PCI DSS requirements.

SIC 92 (November 2010): PCI DSS v2.0, the maduration of a standard

This article, published in SIC journal #92 (November 2010), explains the novelties about new version PCI DSS (2.0).

Miguel Ángel Domínguez, director of consulting department at Internet Security Auditors, presents the major changes that have been introduced in the standard and factors to be considered by all involved to adapt its processes of transmission, storage and processing of payment card data.

Security Acts #3 (May 2010): Cloud or storm clouds? Cloud Computing Security

Article published in issue 3 (May 2010) of Security Acts electronic magazine. Security Acts is an electronic magazine exclusively for IT security professionals.

The article describes the main features of Cloud Computing, a fully fenonemos booming in the field of information technology. Threshed the main models Cloud Computing service and their main threats and benefits as far as information security is concerned.

Red Seguridad #41 (July 2009): Trends of Information Security Certifications

Article written by the Consulting Director of Internet Security Auditors and published in issue 41 (July 2009) of Red Seguridad magazine.

The article features shelled the most important certifications in IT security. It highlights the benefits that these certifications awarded to businesses and professionals of the Information Security. It includes a summary table with the description of the latest certifications.

ACIS Magazine #110 (April - June 2009): Article about PCI DSS in the ACIS magazine in Colombia

The Colombian Association of Systems Engineers (ACIS) published in the issue 110 of his magazine, the article written by a member of the consulting team at Internet Security Auditors.

The article develops the twelve requirements of PCI DSS standards, then deepen the importance that the management and monitoring of logs and events, takes this security standard data associated with credit and debit cards.

SIC 85 (June 2009): Development of a Secure Software Development Methodology in Rural Servicios Informáticos (RSI)

In the article published in the journal SIC threshed the design and implementation of a Secure Programming Methodology (METPROGSEC) within what is called S-SDLC (Secure Spftware Deveplpment Lifecycle), associated with SDLC.

This methodology was implemented in Rural Servicios Informáticos (RSI) who selected Internet Security Auditors as a provider with expertise in this field.

SIC #84 (June 2009): Implementation PCI DSS in LocalBilling

In the Projects section of the SIC magazine of June, included article that tells the implementation and certification in the state PCI-DSS, which took place in LocalBilling by Internet Security Auditors advice.

LocalBilling provides brokerage services in the online payment processing for which it needs to collect, store and transmit data from credit / debit cards. Because of this, LocalBilling, decided to implement PCI-DSS standards, with the support of our consulting department.

SIC #83 (February 2009): AntiMalware Security Service in SIC

This article describes what the operation of AntiMalware Security Service, detailing HoneyClient philosophy that is based on this pioneering service.

The high knowledge of Information Security responsible for the service within Internet Security Auditors, and their experience in deploying such solutions have allowed in this article reflect the characteristics of the service clearly and concisely.

Red Seguridad #38 (January 2009): OWASP Spain chapter

Interview magazine "Red Seguridad", OWASP Spain Chapter Leader and partner co-founder of Internet Security Auditors.

Throughout the interview, Vicente Aguilera gives an overview of the history of OWASP both internationally and in terms of the Spanish chapter, describing the main areas of activity of the organization and its influence on the state of Security Information in today's society.

SIC #81 (September 2008): WiFi-Ciutat Project, wireless access of citizens in Sant Feliu.

This article describes what has been the technological solution to provide wireless access based on authentication with digital certificates to citizens of the City of Sant Feliu de Llobregat.

The project described in the article had been able to develop thanks to the collaboration of the team's own staff Information Technology council, CATCert (Catalan Certification Agency) and the consortium Localret.

SIC #78 (February 2008): PA-DSS, the security standard of payment application

This article presents the new standard managed by the PCI SSC and it intends to cover, along with the PCI DSS and PCI PED space referred to the security requirements of the developments related to electronic payment applications.

Hakin9 (January 2008): CTF DefCon 2007

In this article, written by members of the technical team at Internet Security Auditors participating in the team that qualified for the finals of the competition CTF (Capture the Flag) held under the DefCon 2007 in Las Vegas, are detailed the tests had to overcome to the previous classification and the development of competition itself, which only 8 of over 400 teams qualified.

SIC #76 (September 2007): PCI DSS, how reach compliance?

This article presents a practical approach to implementation of PCI DSS that can address a compliance plan as we are developing in the different companies in different sectors and institutions both acquirers, service providers and businesses.

In addition, we show some details of how to harness the introduction of PCI DSS to develop an ISMS or if any previous one, the integration of compliance with the rule within the existing management system.

SIC #74 (April 2007): Study of Personnel Management Solutions Passwords

Today, the number of passwords that must drive any day of the IT professional is enormous and growing. One of the biggest problems that arises is that of maintaining security in all places where authentication is required to avoid recycling of passwords or simplified. In addition, there are situations where SSO systems, for example, are not viable.

This article presents an analysis of a type of tools is finding increasingly greater number of adherents as are the solutions of personal password management, in addition, all open source.

e.Security #12 (February 2007): More Security in electronic card transactions

In this article, conducted as an interview in which he participated Daniel Fernandez, was a review of the standard PCI-DSS, its history and implications and requirements for businesses affected by compliance.

SIC (Security in Computer Science and Communications) #66

Article published in the 66th issue of "SIC: Security in Computer Science and Communications" where the evolution that have suffered the mobile telephone devices is shown and the deficiences of the used technologies are presented. Finally, some security recommendations to mitigate the dangers of the smartphones are explained.

Article published in the CiberP@ís

Article published in the CiberP@ís the 1st September 2005 and wrote by Mercè Molist. The journalist went to the security event What The Hack! cellebrated in Liempde (The Netherlands) during 28th and 31st of July 2005.

In the conferences of the program, one done by two of the members of our technical team, that presented their job in an Application Open Source firewall based in the Apache module "mod_security", is remarked.

SIC (Security in Computer Science and Communications) #65

Article published in the number 65 of " SIC: Security in Computer science and Communications " where are presented the security problems relating to Web Applications and how these problems affects business continuity.

Red Seguridad #7

Article published in the number 7 of "Red Seguridad". Writing together with Pete Herzog, Managing Director of the ISECOM. This article shows a need for an " Hacker Ethics " in the Security IT Companies and proposes the first step towards a deontological code " Rules of Engagement " of the OSSTMM methodology maintained by the ISECOM organization. Internet Security Auditors has been contributing to the OSSTMM since year 2001.

SIC (Security in Computer Science and Communications) #55

Article published in the number 55 of "SIC: Security in Computer science and Communications" where are presented the security problems relating to Domain Names in the Internet and Domain Name registration companies, and how to avoid these problems

Más que Bytes, El Mundo

Article published in the Sunday Magazine "Más que bytes" that it was accompanying the newspaper "El Mundo" on Sunday, the 23rd of March, 2003.

Mundo Linux #51

Chronicle published in Mundo Linux #51 about the 19th Chaos Computer Club in which we had the pleasure of taking part together with Pablo Garaizar (Sindominio, Euskadi), Jorge Gómez and Marcos Serrano (Sindominio.net-CPSR-ES, Madrid).

Red Seguridad #1

Article about Internet Security Auditors in the first number of " Red SEguridad " after our assistance to ExpoInternet 2002.