Archive for June, 2008

Verizon report of data breaches

June 24th, 2008

Some interesting stuff in here.

Posted in Just Thumbed In | No Comments »

Of Clouds and Security…

June 23rd, 2008

The topic of security in the cloud has been around for a few years and practiced in bits and pieces, but has been heating up lately. Pundits are pontificating, cloud blogs are online, cloud security startups are hiring, established companies are launching new products - I mean services, so the cloudbuzz seems real enough. It is probably not a bad idea to look into security in the cloud and see if we are all talking about the same thing.

An evolutionary aspect to security in the cloud is the business of putting traditional security functions into a hosted platform, with the low hanging fruit being perimeter-facing functions like gateway antivirus and spam filtering. ScanSafe is an oft-cited example of a first mover in this space. It is evolutionary in that it is essentially taking MSS one step further. MSS has grown by creating efficiencies by outsourcing some of your security people and management systems, but leaving your security hardware in place. Security in the cloud is eliminating the hardware from your point of presence as well. This seems like a logical progression - having just enough experts in managing gateways and blocking malware using just enough hardware and bandwidth (ok, sometimes “not enough” - that’s what SLAs are for).

It gets more challenging as we seek to provision cloud services that solve security problems in locations other than the perimeter. A cloud service can manage policy-based encryption from Internet point to point. It becomes much more difficult to manage the internal slice of the corporate encryption policy - not impossible, but an organization will likely try to solve this problem with a cloud service and a traditional product suite at the same time, risking policy violations and data breaches from a disjointed approach. In this new world of hybrid security via cloud and traditional products, security architects will need to work overtime to develop solutions with integrity.

So, aside from evolving security we know today to hosted services, what else do we mean by security in the cloud? To me, it means securing the cloud itself. As organizations move towards more line of business applications running as Software as a Service (SaaS), they are bypassing carefully architected controls that no longer apply. A wide variety of new security solutions need to be built to address the new complexities of information residing anywhere, hosts that are really a VMWare instance and data centers that you will never see.

So the question before us is, “Is security in the cloud good security?” Cloud security can only succeed within limited boundaries if as businesses we conservatively adopt SaaS. Cloud security is strategic if it evolves to manage enterprise SaaS applications. So the real question becomes, “Is SaaS good enough to run my entire business?” Another formulation is to understand the cost savings that SaaS is delivering and determine if we are faced with an increased risk offset. In the long run, I feel that investing in SaaS and securing it natively will certainly be more cost effective and secure. I say this with all due respect to enterprise security practitioners, but in my experience they generally are not as well versed in the technology as the practitioners within the MSSPs or vendors that are living with it 7×24 in many different environments. Outsourcing the technology and not the business acumen is logical on the face of it. What I can’t predict is when we will reach the point of SaaS being provably more secure than the alternative and how many CISOs need to get thrown under the bus until we get to that point. What did Keynes say about the long run?

Posted in Articles, Future Forecast | No Comments »

Send in your ROI & Metrics stories, get a book

June 12th, 2008

I would like to hear some readers’ experiences, stories and tips about how they have been able to use security metrics, develop a credible ROI, create a business case or otherwise quantify information security projects and investments. I have heard some rational anecdotes about reducing annualized loss exposure related to data breaches, creating operational efficiencies with IdM and a few others, but I would definitely like a bigger war chest.

I have three copies of Dan Geer’s “Economics & Strategies of Data Security” that I will hand out to the lucky winners! You can email me at jim@reavis.org.

P.S. This book, How to Measure Anything has been recommended by multiple people as useful resource for risk professionals trying to think through this problem.

Posted in Articles | No Comments »

How the malware market works

June 10th, 2008

Fast changing email addresses, questionable online payment/money laundering services characterize the well organized blackmarket for malware, or in this case, extortionware.

Posted in Just Thumbed In | No Comments »

Webinar: New Directions in Firewalls for Emerging Web 2.0 threats

June 5th, 2008

Sophisticated Web 2.0 technology is powering new classes of malware and popular rogue applications that are regularly bypassing corporate firewall defenses.

Join industry experts Nir Zuk, CTO of Palo Alto Networks and Joel Scambray, author of the Hacking Exposed book series, as they discuss the latest threats, analyze how Web 2.0 technology traverses secure perimeters and explain how firewalls must evolve to address these issues. This interactive webcast is moderated by Jim Reavis, former Executive Director of the Information Systems Security Association.

For more information and to register, go here.

The live date is June 11 at 1pm EDT, it will be archived for on-demand broadcast.

Posted in Articles, Firewall 2.0, Future Forecast | No Comments »

Office worker goes insane

June 4th, 2008

I believe this employee was protesting the new “free Red Bull” corporate policy.

Posted in Articles | 1 Comment »

Sidebar