Tuesday, July 12, 2011

Reminder: PCI DSS 2.0 is asking for Vulnerability Risk Rating

You know the story; if your systems/applications store transmit or process credit card data, you must meet PCI data security standards.
Since Q4 2010 all PCI shops are aware that their Cardholder Data Environments need a risk ranking procedure.

But, What is it and how does it change current practices?

PCI DSS Requirement 6.2 says "Establish a process to identify and assign a risk ranking to newly discovered security vulnerabilities"
And a new recommendation may certainly effect how you manage risk…

This recommendation (which will be a requirement by June 30, 2012) can be classified as Risk Management 101, and yet it may change several cornerstones of your processes.

Here is what 6.2.a is asking for:
1- Check your processes for identifying new security vulnerabilities (make sure you have one)
2- Assign risk ranking to identified vulnerabilities
6.2.b Continues with the  recommendation that you use and outside source for this risk ranking process.

This translates into a solid scoring system for risk. Enterprise options to collect data for a scoring system are:
1- Vendor Security Alerts
2- Vulnerability Management Advisories (Usually security scanner, and IDS/IPS shops)
3- Vulnerability Intelligence Advisories (e.g. Secunia, iDefense, Deepsight)
4- Internal risk scoring systems (yes we all love academic endeavors - that is why PCI SSC asks for "outside" source : )

Either way (using one of the options, using some/all of them) PCI recommendation 6.2 will push risk management practices in the right direction and make risk prioritization a priority...Eventually PCI shops will (6/30/2012) integrate risk management with vulnerability scanning devices, security alerts, advisories and patch management solutions to audit and validate PCI 6.2 with risk rankings.

Here are a few good links:
Common Vulnerability Scoring System (CVSS-SIG) - http://www.first.org/cvss/
Common Vulnerabilities and Exposures -CVE - http://cve.mitre.org/
National Vulnerability Database - NVD - http://nvd.nist.gov/
TippingPoint Zero Day Initiative ZDI - http://www.zerodayinitiative.com/advisories/upcoming/
Symanted DeepSight Alert Services - https://tms.symantec.com/
Cisco Security IntelliShield Alert Manager Service -http://www.cisco.com/en/US/products/ps6834/serv_group_home.html

p.s. I have written this article for RSA Conference 


Monday, July 4, 2011

Video Notes From the RSA 2011 Conference

RSA Conference 2011

Video Blog #1
RSA Conference Video Blogger Yinal Ozkan talks about his first day at the 2011 RSA Conference in San Francisco, California.

http://www.youtube.com/rsaconference#p/u/99/88pVqQgjkH0 

Video Blog #2
http://www.youtube.com/rsaconference#p/u/96/Ss33IH0laAw

Video Blog #3
http://www.youtube.com/rsaconference#p/u/94/vUtFR_DeHOc

Sunday, June 26, 2011

Talent Filtering for Information Security

I have written this article for RSA Conference blog originally (https://365.rsaconference.com/blogs/yinal-ozkan)


Great results are not achieved by mediocre teams… Building the right Information Security team does matter, and usually it becomes a full time task for the owners of Information Security initiatives at today’s enterprise.

Information Security domain might be hot, and we may have a positive influx of talent to the sector, however finding the right people with right skills sets at the right time and the right cost is close to impossible.

This post has no intention of questioning/changing years of HR practices – the goal is to give feedback from the enterprise Information Security field and to create useful short order cook content that can quickly be consumed within the next 15 minutes for the upcoming interview you are conducting…

Here are my experiences with finding/hiring talent in Information Security:
1-      Do not reinvent basics. As Buffet/Gates duo has stated the great talent should have the 3 basic skills:
    • Technical Skills (This is standard – I will dig into this item more down below)
    • Conceptual Thinking (Seeing the big picture)
    • Communication Skills (This is not talking too much as perceived by many engineers. Effective communication is a very valuable skill in all team deliverables
It is usually simple to find any one of these skills in an individual, but when you find 3 of them together never miss the opportunity, these people will carry the workload of many!


2-      Have the right pyramid mix of talent in your team: Complex projects require good leaders who can set the target, coach others, lead by example and more important than all great leaders can take the team from A to B. Then you need good managers, who can plan, organize and delegate. It is usually a good practice to have managers who cut their teeth in project management and financial management offices. Last, but not least, the engineers (or consultants). Based on the size of the project, you must determine whether to go with specialists or generalists. This is a big decision point. The more specialists you have, the more integration glue (architects, project managers, program managers ) you need.

3-      Since generic HR topics are not my intention here, I will skip managerial skills and focus on finding the right technical resources. Project based deliverables do not require that much real-time information. Therefore, it does not make sense to filter candidates based on closed book random interview questions. My recommendation is to measure their knowledge so you may level them based on knowledge. This is management basics -  data to wisdom:

    • Ask them questions starting with who?, when?, where?, what?? If you can get good answers that means your candidate has “information”Your candidate is probably familiar with the topic.
    • Ask them questions starting with “how?”. If you can get good answers that means your candidate has knowledge.This is a clear signal of experience.
    • Ask them questions starting with “why?” If you can get good answers to “why” questions that means your candidate has the wisdom and the conceptual thinking skills that you are looking for.

4-      Specialists: Being a specialist does not create a rain check to omit basics of information security. I have met several consultants who were very familiar with compliance but did not understand the technical tools, or I have seen great application security people with zero understanding of network basics. The trend is to have good understanding of all domains where you excel in 1 or 2 of the domains as a specialist. Interviewing specialists should have 2 different class of questions to gauge:
    • How much do they do they own their domain of specialization?
    • How much do they understand about how other domains work?

5-      Generalists: I believe there are 2 types of generalists you can trust in Information Security:
    • New Grads with no experience
    • Project Managers, Auditors, and Managers (usually go well with the certificates like CISSP, CISM etc)
    • If you are interviewing a candidate with over 3 years of Information Security experience with no particular specialty that is a big red flag.

6-      Send consultants the questions that you will ask in advance. This will eliminate the “it is not at the top of my head /it has been a while” excuse. Since you send the technical interview questions in advance you can ask any particular sub question. This asynchronous Q&A style is more close to real life. This way you can also ask really tough questions as well.

7-      Ask for a sanitized copy of deliverables from the past assignments. Good samples are good indicators of pitched skills. Obtaining samples are problematic especially in Information Security due to security and Intellectual Property concerns but checking is better than not checking.

8-      Classify Information Security resource types (this is subjective) Classification will help you to identify your candidates specialty, customize your questions and assess them more evenly. In today’s IS world, I see the following backgrounds We can dig into each area in separate articles. Here is the bird’s eye view for the 15m intro:
    • Network Security Specialists: This is the most abundant resource.  Most of the resources have strong networking background and they do have operational and engineering know-how about common tools like firewalls, IDP, content security, OS hardening.  Ask for the enterprise know how instead of small shops, that is completely different skill-set. It usually makes sense to get “Security Operations” resources from this background since their operational background fits well with the SOC (Security Operation Centers)
    • Vulnerability Testers:  This is another domain where you can find a lot of resources. (not necessarily the best ones) From network testing, to penetration testing, this area requires a lot of technical skills. Ask for methodologies, frameworks, references and sample deliverables in addition to basic checks. Network Vulnerabilities, Application Vulnerabilities, operational Vulnerabilities, and the Physical Vulnerabilities are different so make sure that you have the right skill sets.
    • Single Domain Specialists: If your project is big enough you can acquire a domain specialist (e.g. SIEM) or a technology (e.g. RSA envision) specialist. Be sure to question other skills as discussed above. DLP, DRM, Virtualization Security,  Social Media, and Mobile Security-type of next generation projects usually require specialists so it makes sense to start with a consultant specialists to acquire the skills sets.
    • Application Security Specialists: Securing SAP, Siebel, Oracle is a life time goal. It does require life time experience. Again the same rules with hiring specialists.
    • Desktop Security: Understanding desktop security is different than all other security areas where the end users are non-IT users. Lately desktop security domain is crisscrossing a lot of other domains like NAC, 802.1x, VDI so be very careful to filter.
    • Code Security: This is a hot domain, possible candidates interact with application security, vulnerability testing. It is not possible to understand code security in every development framework so an eclipse environment  expert cannot be very useful in the .NET environment
    • Security Architects: Even if you see a lot of titles with Security Architect, the real ones are tough to come by, look for understanding of EA frameworks like TOGAF, Zachman etc. Also look for special frameworks like ISO 27001, CoBIT, and NIST. Generic frameworks like ITIL, 6 Sigma, and other compliance frameworks are important. In addition, look for perfect understanding of operations and the technology.
    • Compliance Specialists: Audit background helps. Top 4 experience helps. Compliance has 2 important parts, meeting compliance and an accreditation. Make sure that you acquire the right internal resources to meet your compliance goals.  Instead of going with multiple security compliance specialists, it will make more sense to build an information security management program that can answer the common 80% requirements of all frameworks.


9-      Classify candidate backgrounds based on the verticals; it makes sense to find Information Security resources with vertical specialization. I find it amusing to mark “government” background as we start discussing topics with “cyber” word… So far I have seen the following backgrounds in the field. Based on your project’s requirements, different backgrounds provide different outcome.. You can find Information Security professionals with the following backgrounds
      •   Enterprise
          • Financials
          • Healthcare
          • Manufacturing
          • Utility
          • High Tech
          • Media
          • Other
      • Government
          • Federal
          • State
      • Military
      • SMB
      • Consultancy
      • Higher-Ed
      • Service Provider
      • New Grad
      • Vendor
      • Reseller
      • Out of Sector


    Wrap Up: Look for talent with specific skill-sets – To help you better identify the right skill sets, customize your questions based on experience background, vertical background and universal skills such as conceptual thinking.

    Sunday, March 20, 2011

    RSA SecurID Breach Questions

    Q: What was stolen from RSA? (based on Art Coviello's blog) and What is the current risk for SecurID users?



    A: RSA says "..extracted information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation..." This is boiling water and everybody is trying to reverse engineer this statement.. What does RSA mean by reduced effectiveness? Without the full disclosure, all interpretations will be semi fictional.. Information sources are limited when RSA is silent. A very important sign of  RSA's response is "RSA SecurID Authentication Engine Security Best Practices Guide" document which was published in March 17.

    Here are the 2 interesting statements from the March 17 Guide:

    1 - "RSA recommends a defense-in-depth approach for protecting token data stored in your environment. RSA strongly recommends that your storage systems encrypt the token data with a separate key in addition to the encryption provided by RSA SecurID Authentication Engine. Using two separate keys maximizes the protection of stored token data."

    My interpretation: Do not trust RSA authentication server's built-in encryption, use yours.This means 3rd party who "extracted information from RSA"  has a good understanding of how RSA obscures token data on the authentication server...It is usually possible to access stored encryption keys since they have to be accessed for operation anyway. So if source code is lost, this may happen faster..Risk: You had to secure auth server anyway, now the risks are higher but this specific risk does not require you to replace every single token in the field until your own auth server is hacked.. And believe me when your authentication server is hacked you have other serious problems as well (BTW I'am not sure how auth server will work if I encrypt token data with my keys at file level)

    2- "Never give the token serial number, PIN, tokencode, token, passcode or passwords to anyone."

    My interpretation: Let's analyze this one in-depth.. When you use SecurID, you enter passcode as your  password. A passcode is made up 2 pieces on RSA, a pseudo-number (that is dynamically generated on the token a.k.a. tokencode) and your PIN.. 
    The beauty of multi-factor dynamic password tokens is that if I know your PIN I still need the tokencode (so the token).. If I steal your token, I still need the PIN... No attacks are effective until you get token for that specific 60 seconds+PIN combo.(in theory ; )....  The scary part of the warning above is the "token serial number", a number on the back of the token usually used as a subfactor for  enrollment and password resets... Directly losing ""token serial number" shouldn't have mattered . if it did, it was not supposed to be imprinted on the back of the token..So the hypothetical risk is that the guys who extracted data from RSA can generate a tokencode from the serial number.. I do not think this is the possibility since that eliminates the whole idea for the need for the token seeds..Hopefully RSA token's private algos are not that simple (serial number generates the seed).  Same argument is valid for tokencodes.. If I have to hide my tokencode where is the advantage of using a dynamic code generator?

    Back Image with Token Serial Number



    I will keep covering this topic until  we have a conclusive answer.

    Wednesday, January 12, 2011

    MSSPs - Another one bites the dust - Dell acquires SecureWorks

    So I had to update my chart for MSSP history ..Again..

    SecureWorks no more (independent). As you all know, last Tuesday (Jan 4th) Dell made this announcement from Round Rock, Texas "Dell today announced it has signed a definitive agreement to acquire SecureWorks Inc"

    Financial Analysts were puzzled with the "all-cash" move from Dell. How come a technology giant with $53 Billion in annual revenues, is making a scene with a small services company with $120M revenue?..

    Before moving to possible reasoning, let's dig the deeper question: "How Much ?"... Terms were not disclosed but here are the facts:

    • As of 2010 SecureWorks was completing all the necessary prep work for an IPO after the 2008 fiasco.

    • So it is not very difficult to guess the game changer on SecureWorks side: Bags of cash….

    • Dell paid 10x reveunue ($1.4B) for a mediocre virtualized storage company (EqualLogic), so why not paying 10x to a successful company with over 3000 qualified "services" buyer accounts? (for those who pull the calc, it makes $1.2 billion in cash, but of course this is a guess – it looks like the number is around 600M)

    • Bean counters will need to factor in the cost of acquiring an acqusition mode startup company with plenty of debt when calculating SecureWorks' price tag.(SecureWorks acquired Lurqh, DNS, and Verisign -$45M- MSS lately - from 2004–2008. SecureWorks grew 492 percent)

    • At the end of the day IBM paid $1.3B to ISS in 2006.



    Why Dell Acquired SecureWorks?

    CATALYST:

    Security is the catalyst component in many large scale complex deals even if does not present a larger financial percentage of the whole deal. Lately information security is getting more and more byzantine and unmanageable,so selling security hardware/software/consulting does not quench today’s enterprise level security needs. So instead of acquiring half baked hardware/software solutions (like HP's TippingPoint, Arcsight or IBM’s Guardium, Ounce Labs, BigFix acquisitions) Dell made a shortcut to get the whole security package. SecureWorks can offer full security services with or without “best of breed hardware/software” , they do all they need is a “Dell” box loaded with a homemade software such as iSensor, iScanner etc/.

    MSP + MSSP

    Merging MSPs with MSSPs enable companies like Dell to offer complex services remotely. Outsourcing performed in the form of “body shop” is so 1990s. Taking over the operations of a large company and their IT staff is not outsourcing / neither sending the same operation to overseas. The leverage is where shared services are utilized .That is why Telecoms like Verizon, BT, AT&T and NTT are behind all “managed service” offerings. When compared with HP and IBM, Dell is much better positioned with their strategy. Please evaluate Everdream, Silverback, MessageOne, and KACE acquisitions of Dell. Dell has been making acquisitions to become the “Shared Services” central of the world. Dell is perfectly positioned to offer services remotely from Data Centers without the outsourcing shops like HP-EDS or IBM Global Services. Remote device management, or in Dell’s words “Distributed Device Management” is the next generation of outsourcing. With SecureWorks, Dell will add another critical piece to remote device management and in-the-cloud offerings : Security. (Dell also acquires Perot Systems to fill in the “services” gap) . With SecureWorks, Dell will acquire Verisign’s remote management platform and SecureWorks’ SIM-On-Demand hosted security solutions… Dell already owns in the cloud Message-One security systems..HP and IBM will need to build services around the security tools they have acquired.

    POWER OF MARKETING

    SecureWorks reached the first 1000 customers with a very small dedicated team from Atlanta, GA. Targeting small credit unions and healthcare organizations, SecureWorks now has around 3000 managed security services customers. Even if the revenue numbers are limited, Dell will be happy to leverage the SecureWorks’ know-how in acquiring “Monthly Recurring Revenue”.

    COMPETITION

    HP, Dell, Cisco and IBM are in a tight race to own enterprise data centers…Any leverage is welcome for Dell. Many of HP Enterprise Services (HPES - formerly known as EDS) customer shops are SecureWorks customers. Dell’s SecureWorks acquisition puts HP on a very uncomfortable seat. HP does not have an MSSP like IBM (EDS came with UK based Vistorm but try finding "managed security" on hp web sites today) , and they do not have the know-how for build and run an MSSP (where Verizon has Cybertrust, BT has Counterpane , NTT has Integralis, IBM has ISS etc).. it will be an interesting year to watch remaining managed/in-the-cloud security service providers: Perimeter, Fishnet, Trustwave, Solutionary and zScaler.

    Outsourcing shops, and System Integrators (SI)s are puzzled with this as well. Other major players like Fujitsu, AT&T, Raytheon, Savvis, Unisys, T-Systems, Tata, CSC, Wipro, Logica and any other large scale Telecoms offer managed security (MSS) as a part of other offerings. Security heavy weights McAfee (now Intel) and Symantec have conflict of interest when offering vendor agnostic services.



    What Does SecureWorks Offer Today?

    Managed SERVICES

    • SIM On-Demand – SaaS without 3rd party vendors

    • Log Monitoring

    • Log Retention

    • IPS / IDS – via 3rd party CPE and internal appliances

    • Firewall via 3rd party CPE and internal appliances

    • Web App Firewall

    • Host IPS

    • Vulnerability Scanning via 3rd party CPE and internal appliances

    • Web App Scanning via 3rd party CPE and internal appliances

    • Encrypted Email

    • Security and Risk Consulting

    • Deployment Services

    Compliance Solutions

    • GLBA/FFIEC – financial services

    • HIPAA - healthcare

    • NERC CIP - utilities

    • PCI – payment services

    • FISMA –US government

    Vertical Solutions

    • Banking Compliance Solutions

    • Credit Unions Compliance Solutions

    • Utilities Compliance Solutions

    • Healthcare Compliance Solutions

    • Insurance Compliance Solutions

    • Retail Compliance Solutions

    • Government Compliance Solutions

    Security Research

    • Advisories

    • Articles

    • Counter Threat UnitSM

    • Newsletter

    • Research Blog

    • Security Tools

    • Security Threat Analyses

    • Webcasts

    • White Papers



    SecureWorks VC investors

    Mellon Ventures Inc., GE Capital, SBK Capital, Alliance Technology Ventures L.P., ITC Holding Co. Frontier Capital (via Lurhq) , Great Hill Partners, and Noro-Moseley Partners.







    Recent Relevant Dell acquisitions

    • Everdream Software 2007 - MSP - Remote Service Management

    • ACS (not Xerox' ACS Inc) 2006 - Application Management

    • SilverBack Technologies 2007, MSP - Platform Provider

    • MessageOne 2008 - Security As a Service (Content Filtering)

    • Perot Systems 2009 - SI

    • KACE Networks 2010 - MSP Appliance

    Recent Relevant IBM acquisitions

    • Internet Security Systems (ISS), 2006 - MSSP

    • Consul Risk Management, Inc., 2007 - Risk Management

    • Watchfire Corporation, 2007 - Security Testing

    • Ounce Labs 2009 - Code/Application Security

    • Guardium 2010 - Database Security

    • BigFix, Inc 2010 - Patch Management

    • OpenPages 2010 - GRC

    Recent Relevant HP acquisitions

    • SPI Dynamics Inc., 2007 - Application Security Testing

    • Opsware - 2007 Network management

    • Atos Origin Middle East Group - SI

    • Electronic Data Systems, 2008 - SI  (EDS acquired Vistorm)

    • 3Com (includes TippingPoint), 2009 - Network and Security Infrastructure

    • ArcSight, 2010 - Security Event and Information Management

    • Fortify Software, 2010 - Code/Application Security

    Saturday, October 16, 2010

    Why Did Nokia Fail in Enterprise Smartphone Business ?

    Q: Why Did Nokia Fail in Enterprise Smartphone Business?


    I do write about security, but seeing Nokia fail hurts everyone. (When Dilbert Came to Nokia - http://www.theregister.co.uk/2010/10/14/nokia_dilbert/ )  So here is my part of the story.

    Being a part of one of the largest Nokia Enterprise Security Partners, we felt the Dilbert story of Nokia organization at first hand. Since Nokia Enterprise Security is no more, I can write about what happened. It was around 2004 when Nokia Reps, SEs started to visit us regarding “Mobile Business Solutions” even back then Blackberry was so popular, so we developed an interest in “free” Nokia phones handed to us by Nokia.

    Nokia Access Mobilizer ( NAM which became N1BS  -Nokia One Business Solution) was our first hit. Our idea was that Nokia will deliver an excellent mail server, and then Blackberry would be the history

    Here is an email I have written to a colleague in 2004 regarding  NAM / N1BS

    Here are my notes:
    N1BS is the new name that Nokia marketing geniuses found for Nokia Access Mobilizer. N1BS stands for Nokia One Business Server.
    N1BS does not run on classic Nokia hardware and the IPSO operating system. Instead, this product runs on a specific blend of Linux called IPSO-SX and the proprietary "Intel" server called EM6000. If you need to dig more here is the Nokia's acquisition path for these products:
    a- N1BS was acquired from EIZEL in 2003. Its original name was Amplifi : http://web.archive.org/web/20030422051926/http://www.eizel.com/
    b-The Linux kernel for IPSO-SX is from Montevista. Isn't it a coincidence that Montevista is a Linux distributor for mobile phones :) http://www.mvista.com/
    c- The em6000 hardware is from ablecom which sells the system in the name of superserver: http://www.ablecom.com/system/6013p-8.htm

    N1BS is good for the following:
    1- Any mobile device with wap browser can access to any web page through its proxy. Device independent internet service. N1BS morphs the web pages to your tiny mobile device screen.
    2- Email and PIM (Calendar-contacts) integration. Supports exchange and Lotus Notes in native mode
    3- Offline sync for PIM and e-mail (through IMAP client)
    4- Content processing; N1BS aggregates/abbreviates the data for you. Image processing: Images are re-rendered.
    5- Viewers for most of the attachments. E.g. powerpoints. pdfs on your phone
    6- Secure, reliable, flexible etc, enterprise marketing stuff..

    Here are the highlights that drew my attention
    a- Licensing is important. This device uses FlexLM licenses. This means you get a LAC (License Authorization Code) and generate the real license on Nokia web site. 2 per LAC.
    b- Sensitive information on the device is encrypted with Blowfish
    c- Regular RPM packages are installable by newpkg command. Nokia recommends some packages so this means it does not break the support agreement
    d- There is an integrated postgreSQL on the box
    e- X libraries are there too. The reason is attachment processing
    f- No "Voyager" or "Clish" on this new IPSO-SX. You are on your own.
    g- No HA or load balancing solutions are in place
    h- No central authentication system integration (LDAP, Radius, AD etc). Even with Radius you need to define users one by one
    i- No central "config" file like IPSO
    j- No CD bay on the EM6000 hardware
    k- No Cron :)
    l- No SSL accelerator
    m- Nokia gives NAM support from India
    n- There is integrated openoffice for attachment viewing
    o- You may see NAM, MCA, Documa, names in the documentation . They all mean N1BS
    p- No SNMP integration
    There is a rumor that Nokia will use this IPSO-SX on the firewalls too but I think it is still too early(See items above that start with No). I have heard that Nokia quit message protector which was also runnning on IPSO-SX

    N1BS had a brilliant idea, back then smartphones were very expensive and there was a clear need for a mid market mail solution. With Sync-ML and integrated mail/calendar/contact synchronization this was the right solution for midmarket. It also had auto abbreviation which is made sense where data was costing arms and legs.. So we made the decision and I spearheaded the investment on developing a managed services solution for N1BS.. Then came the Nokia announcement, “We do not think that N1BS works like Blackberrry so we are changing the platform”

    When Nokia canceled N1BS you could tell there was an internal friction at Nokia organization. In September 2005 (http://www.theregister.co.uk/2005/09/13/nokia_unveils_mobile_email_drive/) Nokia told us that we were supposed to use Nokia Business Center – NBC,  NBC would support push mail that N1BS suffered. So we formatted the N1BS server started from the scratch with NBC, we were still ok because I was a big fan for  my S80 9500. We believed in Nokia and continued to market the Nokia mail solution.We built NBC server, tried to build the services around it. But there were problems here is an email I have written in Oct 2005. You can tell that NBC was buggy..Now looking back, I can tell what the problem was; Symbian Group did not work with NBC group at Nokia, they were simply different business lines (retail vs enterprise), so NBC could not use any of the OS level features, even cut&paste was not available to NBC mail client, without phone OS integration NBC's doom was fixed.

    The email client interface is not good. It lacks the basic editing functionality of Nokia Symbian interface. I even could not select-cut&paste the e-mail content. Mouse over dial/e-mail things do not work, I have to go over the menu. Body of the messages format is clumsy.
    If this is a unified messaging tool, then it should. I like the built-in messaging interface more. Built-in mail client has the ability to forward mails to cell phones, and fax (fax, SMS, MMS profiles). Built-in client works perfect..on the other hand NBC client is worse than built-in mail client.
    External e-mail does not work with the following message:
    Sending of e-mail failed . Please try again
    mail.send.failed:Invalid Addresses
     nested exception.js
    class.javax.mail.SendFailedException: 451 Can't connect to gmail.com – psmtp. This problem has been fixed
    PIM sync has its own problems
    This problem has been fixed. I get PIM sync failed errors sporadically. It works after 2-3 trials
    When I forward reply and e-mail with NBC, I do not see forward, reply information in Exchange. It only marks read/unread data. If an e-mail is forwarded or replied via business center client, exchange not update the  forward/reply history
    Embedded URL links are stripped. No URL links in incoming mail
    URL links are stripped by NBC server or the client. An example is the following mailAttached below is the outlook version where URL and the links are working.. On NBC both the format is gone and there are no links..
    I did a couple of tests, this mail goes to gmail as a multi-part message in MIME format with base64 encoding. That may be the problem.
    NBC does not work well with these mails.
    Attachments open a separate interface when 'add' is chosen. This interface requires shut down after adding the attachment.This problem has been fixed
    I could not manage to delete/edit original mail content when replying
    Connectivity is a big problem… It never survives the night. Executives will not like that.
    Clients still hang due to GRPS errors. If they are left on all night (sometimes) or phone is shutdown during communication, the client hangs up in "connecting" state.
    Here is the fix that works for me:
    1. From tools conn.manager menu highlight GPRS connection and disconnect
    2. Go to NBC client and switch to offline
    3. Reconnect from NBC choose GPRS connection.

    Wouldn't be easier if the NBC client disconnects GPRS and reconnects instead off trying "connecting" for hours..?
    But if the G sign is still there and the connection is not there (G sign not in the box) the conn manager displays receive/sent 0/0kB duration 00:00:00, this means remove the battery - hard reset solution.. I cannot kill/disconnect a an already disconnected GPRS connection..
    This will be annoying for novice executives..
    Sometimes after rebooting I get the "install business extras?" installation prompt even if it is installed.. Ususally phone crashes afterward, 2,nd remve battery insert batttery solved the problem.. Can we request for a reboot, or ctrl+alt+del button?
    Signature sends a garbage character with rich text. There is no option to choose text/html only signature
    Directory search does not search local contacts database. Sending e-mail to local contacts is difficult.
    When the phone is off (or no coverage), NBC does not work over wi-fi for 9500 hundred. There is no switch connection option either.


    You would think Nokia was settled no, right after we deployed NBC Nokia announced that they have acquired intellisync (Nov 2005) for $430M.( http://www.infoworld.com/d/networking/update-nokia-acquires-intellisync-430-million-221) I was furious I have developed a solution 2 times for nothing. Intellisync was simply a replication platform on steroids. It was replicating files, emails whatever it could find. Nokia liked it because Verizon, and Vodaphone used it.. (Service Providers used Intellisync because it was cheap) ..Right after the acquisition, I was told we should wait because Intellisync did not match the development quality of Nokia….It was so bad even internal Nokai employees couldn’t switch, they were still on NBC.. So within that turmoil I was invited to a partner conference. Partner conference was for  Nokia Business as it is described in the recent register article

    So this time we did not move.. In 2006 I received an invite from Nokia


    Hello Nokia Partner,
    Just a note to remind you to register for the Nokia Enterprise Solutions Partner Conference in Boston next month on October 25-27 2006
    Your participation and feedback as one of our most valued partners is vital to our continued growth and success together.  This will be one of the most substantial and important Partner Conferences we have had in a number of years.  This event will be an opportunity to meet and listen to Nokia Enterprise Solutions Senior Management as they share their vision and strategies for the enterprise market.  Mary McDowell, Executive Vice President and General Manager, Nokia Enterprise Solutions, David Petts, Senior VP Global Sales, Marketing & Services, Nokia Enterprise Solutions, and other members of the Nokia management team will be there to present their ideas and to meet you personally.
    You do not want to miss the kick off of our newly designed Partner Program or the roll out of new products that will offer your business new strategic directions.  I guarantee you will leave the conference excited, energized, and ready to get to work.  We also have a little fun planned.


    During the conference I did speak. I told hundreds of Nokia Executives that as a partner I lost my confidence that nokia could deliver a solution that could last more than 1 year.. nobody listened they were all lost in the glory of the "Intellisync", they even didn’t know about competition, I remember 1 comment, “We are bigger than Microsoft in Operating Systems”…That was nothing more than self soothing propaganda - as we all expected the truth was not so far in the future (http://www.theregister.co.uk/2010/10/22/symbian_wound_down/

    So Nokia Enterprise Business gave their promise on 2 major tickets at the Boston conference
    • Intellisync is the last stop, trust us, and invest in Intellisync
    • Nokia IPSO platform is here to stay, trust us, do not invest in any other appliance


    I was like Cassandra, So as expected nothing happened with intellisync, Nokia was so lost, you could tell is when they announced that they are killing Intellisync (http://www.open-horizons.net/blog/erno/replacement-strategies-did-nokia-kill-intellisync-or-protect-your-investment) in Sep 2008 Nokia made the expected announcement


    "The Nokia-Microsoft collaboration to bring corporate mobile email to businesses and mobile professionals is truly unbeatable. No other device manufacturer provides the wide range of devices that we have which immediately mobilize the hundreds of millions of email accounts from Microsoft Exchange," said Anssi Vanjoki, Executive Vice President, Markets, Nokia. "The costs of mobility are contained as companies are able to utilize existing Microsoft Exchange infrastructure, and there is also the strong possibility that a large number of employees already have one or more of the 43 Nokia devices that enable Exchange ActiveSync -
    http://www.designtaxi.com/news/20941/Nokia-brings-Microsoft-Exchange-ActiveSync-Corporate-Mobile-Email-Solutions/"


    But this time we were prepared we already had Blackberries everywhere..


    Sunday, August 22, 2010

    IT-GRC ( Governance Risk and Compliance) Tools - 2010

    I have updated this list (October 2011), you can find the recent copy @ this URL:
    http://security.24kasim.org/2011/10/itgrc-software-vendors-2011.html

    Here is the 2010 version:
    -----------------------------------------------------------------------

    I stand by my statement that IT-GRC does not stick due to several reasons.

    My previous posts with risk management frameworks and tools are at this link (I will update risk management tools next month)

    Currently there are 4 types of companies at IT GRC market:
    1- IT-GRC vendors: IT Risk Management solutions with integrated workflow and compliance features.
    2- Enterprise GRC vendors: Audit driven ERM tools expanding into IT GRC space
    3- Glorified Access Control Tools: This is the world of SAP, Oracle and the related vendors ( note to the vendors - GRC is not SoD)
    4- Compliance Management Tools (without risk focus)

    There are a lot of changes in the market. Market is not as colorful as 2009. I think the main reasons are:
    1- Global market for pure IT-GRC vendors are still around $120M /year.
    2- Entry to market is not very difficult

    Big News are:
    CA killed the whole GRC Manager line.
    Archer was acquired by RSA (of EMC) - 04-Jan 2010
    Compliance Spectrum is now history.


    Before moving forward, please remember that Excel is 'by far' the most common application in IT-GRC market : )

    IT-GRC vendors

    Agiliance
    http://www.agiliance.com/
    RSA eGRC - Archer
    http://www.rsa.com/node.aspx?id=2428
    Trustwave GRC (Control Path)
    https://www.trustwave.com/GRC.php
    Symantec (Control Compliance Suite)
    http://www.symantec.com/business/control-compliance-suite
    Modulo
    http://www.modulo.com/
    Relational Security - RSAM
    http://www.relsec.com/rsam_overview.htm
    Lumension
    http://www.lumension.com/Solutions/IT-Risk-Management.aspx
    BPS
    http://www.bpsresolver.com/
    Avedos
    http://www.avedos.com/en/home/home.html
    BWise
    http://www.bwise.com/
    Neupart
    http://www.neupart.com/
    Metric Stream
    http://www.metricstream.com/
    Nemea
    http://www.nemea.us/
    Highpoint
    http://www.highpointgrc.com/
    Paisley Enterprise GRC® for IT (Requires registration to display product information :)
    http://paisley.thomsonreuters.com/website/pcweb.nsf/pages/ARAE-6XLQSR
    OpenPages
    http://www.openpages.com/solutions/governance_risk_compliance_management_solutions.asp
    IDS Scheer (GRC is a part of BPM offering)
    http://www.ids-scheer.com/us/en/ARIS/ARIS_Solutions/Governance_Risk__Compliance_Management/139893.html 
    ARC Logics  - Axentis (same company for CCH TeamMate audit)
    http://www.axentis.com/Products/Axentis/ProductOverview.html
    Methodware
    http://www.methodware.com/grc/
    Protiviti
    http://www.protiviti.com/grc-software/Pages/default.aspx
    Cura Software
    http://www.curasoftware.com/pages/content.asp?SectionId=7&SubSectionID=48
    Mega
    http://www.mega.com/index.asp/l/en/c/grc
    ControlCase
    http://controlcase.com/it-grc.htm
    Simeio Solutions GRCAXS (IT GRC module)
    http://www.simeiosolutions.com/
    Compliance 360 ( eGRC )
    http://www.compliance360.com/
    eGestalt SecureGRC -  SaaS hosted GRC offering
    http://www.egestalt.com/
    Aline GRC
    http://www.alinegrc.com/GRC-Platform/20/
    TrueArx
    http://www.truarx.com/
    Easy2Comply
    http://www.easy2comply.com/
    SAI Global
    http://www.saiglobal.com/compliance/grc-software/


    There are many other tools with ERM (Enterprise Risk Management) Compliance Management, Audit and Access Control Governance feature sets.

    Here is a long list of indirect GRC software providers that make auditors happy:
    Oracle (formerly Logical Apps and Oracle GRC Manager)
    http://www.oracle.com/solutions/corporate_governance/it-grc-management.html
    SAP (no clear IT-GRC besides Access Control - SoD)
    http://www.sap.com/solutions/sapbusinessobjects/large/governance-risk-compliance/index.epx
    Greenlight
    http://www.greenlightcorp.net/index.aspx
    Qumas avoids GRC term (Regulatory Compliance)
    http://www.qumas.com/
    Aveksa (Enterprise Access Governance)
    http://www.aveksa.com/
    Trintech (Financial controls- no IT)
    http://www.trintech.com/
    Doublecheck ERM
    http://www.doublechecksoftware.com/solutions.htm
    ACL - Transactional controls testing
    http://www.acl.com/products/ccm.aspx
    Approva (ERP Audit / SoD on steroids)
    http://www.approva.net/solutions/itsecurity/
    Strategic Thought (Full Service ERM)
    http://www.strategicthought.com/
    Open Text Governance, Risk Management & Compliance
    http://www.opentext.com/2/global/sol-products/sol-pro-compliance-governance/pro-open-text-governance-risk-compliance.htm
    Enablon - ERM
    http://enablon.com/products/risk-management.aspx
    Pentana Audit Work System (risk Audit)
    http://www.pentana.com/products.asp#PAWS
    Grant Thornton - Compliance Management - GT acquired  Avalion Consulting ComplianceSet solution
    http://bit.ly/9bvCFB (Long URL shortened)
    Incom Enterprise Risk Mgr ISO 31000
    http://www.incom.com.au/products.asp?ID=407
    EIQNetworks SecureVue also avoids the GRC acronym
    http://www.eiqnetworks.com/products/SecureVue.shtm
    Brinqa brings privacy, identity and vendor management http://www.brinqa.com/solutions
    SecurityWeaver (SoD tool) http://www.securityweaver.com/Products_Separations_Enforcer.asp
    ControlpanelGRC - SOX compliance for SAP users http://www.controlpanelgrc.com/
    Xpandion SAP Security - http://www.xpandion.com/


    IT-GRC software make our lives more organized but we should not skip the motto of the CSI audit people : " ‘A fool with a tool is still a fool’"