Tuesday, July 12, 2011
Reminder: PCI DSS 2.0 is asking for Vulnerability Risk Rating
Posted by yinal at 0 comments
Labels: compliance, PCI, vulnerability_management
Monday, July 4, 2011
Video Notes From the RSA 2011 Conference
RSA Conference 2011
Video Blog #1
RSA Conference Video Blogger Yinal Ozkan talks about his first day at the 2011 RSA Conference in San Francisco, California.
http://www.youtube.com/rsaconference#p/u/99/88pVqQgjkH0
Video Blog #2
http://www.youtube.com/rsaconference#p/u/96/Ss33IH0laAw
Video Blog #3
http://www.youtube.com/rsaconference#p/u/94/vUtFR_DeHOc
Posted by yinal at 0 comments
Labels: RSA Conference
Sunday, June 26, 2011
Talent Filtering for Information Security
- Technical Skills (This is standard – I will dig into this item more down below)
- Conceptual Thinking (Seeing the big picture)
- Communication Skills (This is not talking too much as perceived by many engineers. Effective communication is a very valuable skill in all team deliverables
- Ask them questions starting with who?, when?, where?, what?? If you can get good answers that means your candidate has “information”. Your candidate is probably familiar with the topic.
- Ask them questions starting with “how?”. If you can get good answers that means your candidate has knowledge.This is a clear signal of experience.
- Ask them questions starting with “why?” If you can get good answers to “why” questions that means your candidate has the wisdom and the conceptual thinking skills that you are looking for.
- How much do they do they own their domain of specialization?
- How much do they understand about how other domains work?
- New Grads with no experience
- Project Managers, Auditors, and Managers (usually go well with the certificates like CISSP, CISM etc)
- If you are interviewing a candidate with over 3 years of Information Security experience with no particular specialty that is a big red flag.
- Network Security Specialists: This is the most abundant resource. Most of the resources have strong networking background and they do have operational and engineering know-how about common tools like firewalls, IDP, content security, OS hardening. Ask for the enterprise know how instead of small shops, that is completely different skill-set. It usually makes sense to get “Security Operations” resources from this background since their operational background fits well with the SOC (Security Operation Centers)
- Vulnerability Testers: This is another domain where you can find a lot of resources. (not necessarily the best ones) From network testing, to penetration testing, this area requires a lot of technical skills. Ask for methodologies, frameworks, references and sample deliverables in addition to basic checks. Network Vulnerabilities, Application Vulnerabilities, operational Vulnerabilities, and the Physical Vulnerabilities are different so make sure that you have the right skill sets.
- Single Domain Specialists: If your project is big enough you can acquire a domain specialist (e.g. SIEM) or a technology (e.g. RSA envision) specialist. Be sure to question other skills as discussed above. DLP, DRM, Virtualization Security, Social Media, and Mobile Security-type of next generation projects usually require specialists so it makes sense to start with a consultant specialists to acquire the skills sets.
- Application Security Specialists: Securing SAP, Siebel, Oracle is a life time goal. It does require life time experience. Again the same rules with hiring specialists.
- Desktop Security: Understanding desktop security is different than all other security areas where the end users are non-IT users. Lately desktop security domain is crisscrossing a lot of other domains like NAC, 802.1x, VDI so be very careful to filter.
- Code Security: This is a hot domain, possible candidates interact with application security, vulnerability testing. It is not possible to understand code security in every development framework so an eclipse environment expert cannot be very useful in the .NET environment
- Security Architects: Even if you see a lot of titles with Security Architect, the real ones are tough to come by, look for understanding of EA frameworks like TOGAF, Zachman etc. Also look for special frameworks like ISO 27001, CoBIT, and NIST. Generic frameworks like ITIL, 6 Sigma, and other compliance frameworks are important. In addition, look for perfect understanding of operations and the technology.
- Compliance Specialists: Audit background helps. Top 4 experience helps. Compliance has 2 important parts, meeting compliance and an accreditation. Make sure that you acquire the right internal resources to meet your compliance goals. Instead of going with multiple security compliance specialists, it will make more sense to build an information security management program that can answer the common 80% requirements of all frameworks.
- Enterprise
- Financials
- Healthcare
- Manufacturing
- Utility
- High Tech
- Media
- Other
- Government
- Federal
- State
- Military
- SMB
- Consultancy
- Higher-Ed
- Service Provider
- New Grad
- Vendor
- Reseller
- Out of Sector
Sunday, March 20, 2011
RSA SecurID Breach Questions
Q: What was stolen from RSA? (based on Art Coviello's blog) and What is the current risk for SecurID users?
![]() |
| Back Image with Token Serial Number |
Posted by yinal at 1 comments
Labels: authentication
Wednesday, January 12, 2011
MSSPs - Another one bites the dust - Dell acquires SecureWorks
So I had to update my chart for MSSP history ..Again..
SecureWorks no more (independent). As you all know, last Tuesday (Jan 4th) Dell made this announcement from Round Rock, Texas "Dell today announced it has signed a definitive agreement to acquire SecureWorks Inc"
Financial Analysts were puzzled with the "all-cash" move from Dell. How come a technology giant with $53 Billion in annual revenues, is making a scene with a small services company with $120M revenue?..
Before moving to possible reasoning, let's dig the deeper question: "How Much ?"... Terms were not disclosed but here are the facts:
• As of 2010 SecureWorks was completing all the necessary prep work for an IPO after the 2008 fiasco.
• So it is not very difficult to guess the game changer on SecureWorks side: Bags of cash….
• Dell paid 10x reveunue ($1.4B) for a mediocre virtualized storage company (EqualLogic), so why not paying 10x to a successful company with over 3000 qualified "services" buyer accounts? (for those who pull the calc, it makes $1.2 billion in cash, but of course this is a guess – it looks like the number is around 600M)
• Bean counters will need to factor in the cost of acquiring an acqusition mode startup company with plenty of debt when calculating SecureWorks' price tag.(SecureWorks acquired Lurqh, DNS, and Verisign -$45M- MSS lately - from 2004–2008. SecureWorks grew 492 percent)
• At the end of the day IBM paid $1.3B to ISS in 2006.
Why Dell Acquired SecureWorks?
CATALYST:
Security is the catalyst component in many large scale complex deals even if does not present a larger financial percentage of the whole deal. Lately information security is getting more and more byzantine and unmanageable,so selling security hardware/software/consulting does not quench today’s enterprise level security needs. So instead of acquiring half baked hardware/software solutions (like HP's TippingPoint, Arcsight or IBM’s Guardium, Ounce Labs, BigFix acquisitions) Dell made a shortcut to get the whole security package. SecureWorks can offer full security services with or without “best of breed hardware/software” , they do all they need is a “Dell” box loaded with a homemade software such as iSensor, iScanner etc/.
MSP + MSSP
Merging MSPs with MSSPs enable companies like Dell to offer complex services remotely. Outsourcing performed in the form of “body shop” is so 1990s. Taking over the operations of a large company and their IT staff is not outsourcing / neither sending the same operation to overseas. The leverage is where shared services are utilized .That is why Telecoms like Verizon, BT, AT&T and NTT are behind all “managed service” offerings. When compared with HP and IBM, Dell is much better positioned with their strategy. Please evaluate Everdream, Silverback, MessageOne, and KACE acquisitions of Dell. Dell has been making acquisitions to become the “Shared Services” central of the world. Dell is perfectly positioned to offer services remotely from Data Centers without the outsourcing shops like HP-EDS or IBM Global Services. Remote device management, or in Dell’s words “Distributed Device Management” is the next generation of outsourcing. With SecureWorks, Dell will add another critical piece to remote device management and in-the-cloud offerings : Security. (Dell also acquires Perot Systems to fill in the “services” gap) . With SecureWorks, Dell will acquire Verisign’s remote management platform and SecureWorks’ SIM-On-Demand hosted security solutions… Dell already owns in the cloud Message-One security systems..HP and IBM will need to build services around the security tools they have acquired.
POWER OF MARKETING
SecureWorks reached the first 1000 customers with a very small dedicated team from Atlanta, GA. Targeting small credit unions and healthcare organizations, SecureWorks now has around 3000 managed security services customers. Even if the revenue numbers are limited, Dell will be happy to leverage the SecureWorks’ know-how in acquiring “Monthly Recurring Revenue”.
COMPETITION
HP, Dell, Cisco and IBM are in a tight race to own enterprise data centers…Any leverage is welcome for Dell. Many of HP Enterprise Services (HPES - formerly known as EDS) customer shops are SecureWorks customers. Dell’s SecureWorks acquisition puts HP on a very uncomfortable seat. HP does not have an MSSP like IBM (EDS came with UK based Vistorm but try finding "managed security" on hp web sites today) , and they do not have the know-how for build and run an MSSP (where Verizon has Cybertrust, BT has Counterpane , NTT has Integralis, IBM has ISS etc).. it will be an interesting year to watch remaining managed/in-the-cloud security service providers: Perimeter, Fishnet, Trustwave, Solutionary and zScaler.
Outsourcing shops, and System Integrators (SI)s are puzzled with this as well. Other major players like Fujitsu, AT&T, Raytheon, Savvis, Unisys, T-Systems, Tata, CSC, Wipro, Logica and any other large scale Telecoms offer managed security (MSS) as a part of other offerings. Security heavy weights McAfee (now Intel) and Symantec have conflict of interest when offering vendor agnostic services.
What Does SecureWorks Offer Today?
Managed SERVICES
• SIM On-Demand – SaaS without 3rd party vendors
• Log Monitoring
• Log Retention
• IPS / IDS – via 3rd party CPE and internal appliances
• Firewall via 3rd party CPE and internal appliances
• Web App Firewall
• Host IPS
• Vulnerability Scanning via 3rd party CPE and internal appliances
• Web App Scanning via 3rd party CPE and internal appliances
• Encrypted Email
• Security and Risk Consulting
• Deployment Services
Compliance Solutions
• GLBA/FFIEC – financial services
• HIPAA - healthcare
• NERC CIP - utilities
• PCI – payment services
• FISMA –US government
Vertical Solutions
• Banking Compliance Solutions
• Credit Unions Compliance Solutions
• Utilities Compliance Solutions
• Healthcare Compliance Solutions
• Insurance Compliance Solutions
• Retail Compliance Solutions
• Government Compliance Solutions
Security Research
• Advisories
• Articles
• Counter Threat UnitSM
• Newsletter
• Research Blog
• Security Tools
• Security Threat Analyses
• Webcasts
• White Papers
SecureWorks VC investors
Mellon Ventures Inc., GE Capital, SBK Capital, Alliance Technology Ventures L.P., ITC Holding Co. Frontier Capital (via Lurhq) , Great Hill Partners, and Noro-Moseley Partners.
Recent Relevant Dell acquisitions
• Everdream Software 2007 - MSP - Remote Service Management
• ACS (not Xerox' ACS Inc) 2006 - Application Management
• SilverBack Technologies 2007, MSP - Platform Provider
• MessageOne 2008 - Security As a Service (Content Filtering)
• Perot Systems 2009 - SI
• KACE Networks 2010 - MSP Appliance
Recent Relevant IBM acquisitions
• Internet Security Systems (ISS), 2006 - MSSP
• Consul Risk Management, Inc., 2007 - Risk Management
• Watchfire Corporation, 2007 - Security Testing
• Ounce Labs 2009 - Code/Application Security
• Guardium 2010 - Database Security
• BigFix, Inc 2010 - Patch Management
• OpenPages 2010 - GRC
Recent Relevant HP acquisitions
• SPI Dynamics Inc., 2007 - Application Security Testing
• Opsware - 2007 Network management
• Atos Origin Middle East Group - SI
• Electronic Data Systems, 2008 - SI (EDS acquired Vistorm)
• 3Com (includes TippingPoint), 2009 - Network and Security Infrastructure
• ArcSight, 2010 - Security Event and Information Management
• Fortify Software, 2010 - Code/Application Security
Saturday, October 16, 2010
Why Did Nokia Fail in Enterprise Smartphone Business ?
Q: Why Did Nokia Fail in Enterprise Smartphone Business?
1- Any mobile device with wap browser can access to any web page through its proxy. Device independent internet service. N1BS morphs the web pages to your tiny mobile device screen.
3- Offline sync for PIM and e-mail (through IMAP client)
4- Content processing; N1BS aggregates/abbreviates the data for you. Image processing: Images are re-rendered.
5- Viewers for most of the attachments. E.g. powerpoints. pdfs on your phone
6- Secure, reliable, flexible etc, enterprise marketing stuff..
a- Licensing is important. This device uses FlexLM licenses. This means you get a LAC (License Authorization Code) and generate the real license on Nokia web site. 2 per LAC.
c- Regular RPM packages are installable by newpkg command. Nokia recommends some packages so this means it does not break the support agreement
e- X libraries are there too. The reason is attachment processing
f- No "Voyager" or "Clish" on this new IPSO-SX. You are on your own.
g- No HA or load balancing solutions are in place
h- No central authentication system integration (LDAP, Radius, AD etc). Even with Radius you need to define users one by one
j- No CD bay on the EM6000 hardware
k- No Cron :)
l- No SSL accelerator
m- Nokia gives NAM support from India
n- There is integrated openoffice for attachment viewing
o- You may see NAM, MCA, Documa, names in the documentation . They all mean N1BS
p- No SNMP integration
N1BS had a brilliant idea, back then smartphones were very expensive and there was a clear need for a mid market mail solution. With Sync-ML and integrated mail/calendar/contact synchronization this was the right solution for midmarket. It also had auto abbreviation which is made sense where data was costing arms and legs.. So we made the decision and I spearheaded the investment on developing a managed services solution for N1BS.. Then came the Nokia announcement, “We do not think that N1BS works like Blackberrry so we are changing the platform”
Attachments open a separate interface when 'add' is chosen. This interface requires shut down after adding the attachment.This problem has been fixed
- From tools conn.manager menu highlight GPRS connection and disconnect
- Go to NBC client and switch to offline
- Reconnect from NBC choose GPRS connection.
- Intellisync is the last stop, trust us, and invest in Intellisync
- Nokia IPSO platform is here to stay, trust us, do not invest in any other appliance
"The Nokia-Microsoft collaboration to bring corporate mobile email to businesses and mobile professionals is truly unbeatable. No other device manufacturer provides the wide range of devices that we have which immediately mobilize the hundreds of millions of email accounts from Microsoft Exchange," said Anssi Vanjoki, Executive Vice President, Markets, Nokia. "The costs of mobility are contained as companies are able to utilize existing Microsoft Exchange infrastructure, and there is also the strong possibility that a large number of employees already have one or more of the 43 Nokia devices that enable Exchange ActiveSync - http://www.designtaxi.com/news/20941/Nokia-brings-Microsoft-Exchange-ActiveSync-Corporate-Mobile-Email-Solutions/"
Posted by yinal at 0 comments
Labels: phones
Sunday, August 22, 2010
IT-GRC ( Governance Risk and Compliance) Tools - 2010
I have updated this list (October 2011), you can find the recent copy @ this URL:
http://security.24kasim.org/2011/10/itgrc-software-vendors-2011.html
Here is the 2010 version:
-----------------------------------------------------------------------
I stand by my statement that IT-GRC does not stick due to several reasons.
My previous posts with risk management frameworks and tools are at this link (I will update risk management tools next month)
Currently there are 4 types of companies at IT GRC market:
1- IT-GRC vendors: IT Risk Management solutions with integrated workflow and compliance features.
2- Enterprise GRC vendors: Audit driven ERM tools expanding into IT GRC space
3- Glorified Access Control Tools: This is the world of SAP, Oracle and the related vendors ( note to the vendors - GRC is not SoD)
4- Compliance Management Tools (without risk focus)
There are a lot of changes in the market. Market is not as colorful as 2009. I think the main reasons are:
1- Global market for pure IT-GRC vendors are still around $120M /year.
2- Entry to market is not very difficult
Big News are:
CA killed the whole GRC Manager line.
Archer was acquired by RSA (of EMC) - 04-Jan 2010
Compliance Spectrum is now history.
Before moving forward, please remember that Excel is 'by far' the most common application in IT-GRC market : )
IT-GRC vendors
Agiliance
http://www.agiliance.com/
RSA eGRC - Archer
http://www.rsa.com/node.aspx?id=2428
Trustwave GRC (Control Path)
https://www.trustwave.com/GRC.php
Symantec (Control Compliance Suite)
http://www.symantec.com/business/control-compliance-suite
Modulo
http://www.modulo.com/
Relational Security - RSAM
http://www.relsec.com/rsam_overview.htm
Lumension
http://www.lumension.com/Solutions/IT-Risk-Management.aspx
BPS
http://www.bpsresolver.com/
Avedos
http://www.avedos.com/en/home/home.html
BWise
http://www.bwise.com/
Neupart
http://www.neupart.com/
Metric Stream
http://www.metricstream.com/
Nemea
http://www.nemea.us/
Highpoint
http://www.highpointgrc.com/
Paisley Enterprise GRC® for IT (Requires registration to display product information :)
http://paisley.thomsonreuters.com/website/pcweb.nsf/pages/ARAE-6XLQSR
OpenPages
http://www.openpages.com/solutions/governance_risk_compliance_management_solutions.asp
IDS Scheer (GRC is a part of BPM offering)
http://www.ids-scheer.com/us/en/ARIS/ARIS_Solutions/Governance_Risk__Compliance_Management/139893.html
ARC Logics - Axentis (same company for CCH TeamMate audit)
http://www.axentis.com/Products/Axentis/ProductOverview.html
Methodware
http://www.methodware.com/grc/
Protiviti
http://www.protiviti.com/grc-software/Pages/default.aspx
Cura Software
http://www.curasoftware.com/pages/content.asp?SectionId=7&SubSectionID=48
Mega
http://www.mega.com/index.asp/l/en/c/grc
ControlCase
http://controlcase.com/it-grc.htm
Simeio Solutions GRCAXS (IT GRC module)
http://www.simeiosolutions.com/
Compliance 360 ( eGRC )
http://www.compliance360.com/
eGestalt SecureGRC - SaaS hosted GRC offering
http://www.egestalt.com/
Aline GRC
http://www.alinegrc.com/GRC-Platform/20/
TrueArx
http://www.truarx.com/
Easy2Comply
http://www.easy2comply.com/
SAI Global
http://www.saiglobal.com/compliance/grc-software/
There are many other tools with ERM (Enterprise Risk Management) Compliance Management, Audit and Access Control Governance feature sets.
Here is a long list of indirect GRC software providers that make auditors happy:
Oracle (formerly Logical Apps and Oracle GRC Manager)
http://www.oracle.com/solutions/corporate_governance/it-grc-management.html
SAP (no clear IT-GRC besides Access Control - SoD)
http://www.sap.com/solutions/sapbusinessobjects/large/governance-risk-compliance/index.epx
Greenlight
http://www.greenlightcorp.net/index.aspx
Qumas avoids GRC term (Regulatory Compliance)
http://www.qumas.com/
Aveksa (Enterprise Access Governance)
http://www.aveksa.com/
Trintech (Financial controls- no IT)
http://www.trintech.com/
Doublecheck ERM
http://www.doublechecksoftware.com/solutions.htm
ACL - Transactional controls testing
http://www.acl.com/products/ccm.aspx
Approva (ERP Audit / SoD on steroids)
http://www.approva.net/solutions/itsecurity/
Strategic Thought (Full Service ERM)
http://www.strategicthought.com/
Open Text Governance, Risk Management & Compliance
http://www.opentext.com/2/global/sol-products/sol-pro-compliance-governance/pro-open-text-governance-risk-compliance.htm
Enablon - ERM
http://enablon.com/products/risk-management.aspx
Pentana Audit Work System (risk Audit)
http://www.pentana.com/products.asp#PAWS
Grant Thornton - Compliance Management - GT acquired Avalion Consulting ComplianceSet solution
http://bit.ly/9bvCFB (Long URL shortened)
Incom Enterprise Risk Mgr ISO 31000
http://www.incom.com.au/products.asp?ID=407
EIQNetworks SecureVue also avoids the GRC acronym
http://www.eiqnetworks.com/products/SecureVue.shtm
Brinqa brings privacy, identity and vendor management http://www.brinqa.com/solutions
SecurityWeaver (SoD tool) http://www.securityweaver.com/Products_Separations_Enforcer.asp
ControlpanelGRC - SOX compliance for SAP users http://www.controlpanelgrc.com/
Xpandion SAP Security - http://www.xpandion.com/
IT-GRC software make our lives more organized but we should not skip the motto of the CSI audit people : " ‘A fool with a tool is still a fool’"

