<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: elements]]></title>
    <link>http://securityratty.com/tag/elements</link>
    <description></description>
    <pubDate>Thu, 11 Sep 2008 18:32:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Not Your Father's Data Breach]]></title>
      <link>http://securityratty.com/article/6e6dd929bba96e08b0dee7eee16ea946</link>
      <guid>http://securityratty.com/article/6e6dd929bba96e08b0dee7eee16ea946</guid>
      <description><![CDATA[I am surprised this doesn't happen more often, or become public when it does happen, and I suspect it will


Corporate custodians of confidential medical data should be closely monitoring events...]]></description>
      <content:encoded><![CDATA[<p>I am surprised <a href="http://www.stltoday.com/blogzone/the-platform/published-editorials/2008/11/express-scripts-data-breach-is-bitter-medicine/"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">this</span></a><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> doesn&#39;t happen more often, or become public when it does happen, and I suspect it will:</span></p><div><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Corporate custodians</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;of confidential medical data should be closely monitoring events connected to a nightmarish computer security breach in the St. Louis region.</span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Express Scripts is one of the nation’s largest pharmacy benefits managers. The company, with headquarters in St. Louis County, handles approximately 500 million prescriptions per year for 50 million workers at 1,600 American companies. Early in October, it received an extortion letter, the details of which it released on Nov. 6.</span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The letter included personal information on about 75 Express Scripts clients — Social Security numbers, dates of birth and, in some cases, information about prescription medications. Whoever sent the letter demanded money from the company — the amount has not been disclosed — and threatened to use the Internet to reveal personal and medical information about millions of people if the demands were not met.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">...</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Beyond&#0160;</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">the scale of the problem for Express Scripts — and the potential impact on the company is enormous — the issue extends well beyond the mounting concerns about identity theft, a phenomenon with which most people have become at least somewhat familiar.</span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The greater problem is the unique nature of personal medical records, the importance of moving to computerization of such records to improve health safety and reduce costs and the irreversibility of the damage people can suffer if confidential medical information becomes public. The stakes are so high that a federal law establishes strict standards for maintaining the privacy of medical information and stiff fines for failing to do so.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Medical records of all kinds — paper and, especially, electronic — must be protected with the most sophisticated kinds of security systems available, including backup protections and automatic alerts of security violations. Yet Express Scripts learned of this breach in the “worst way,” as InformationWeek.com security correspondent George Hulme put it in an online report: “via an extortion letter.”</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The Express Scripts</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;breach raises many questions for all elements of the health industry: hospitals, clinics and doctors’ practices, benefits management firms, insurance companies, pharmacies, employers and government agencies:</span></span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Are they using the most advanced information security technology possible? Do they minimize the amount of data they collect and keep it only as long as necessary? Do they have strict protocols governing access to personal and medical data — and systems to enforce those protocols? If criminals were to hack into their systems, how would the companies know? How soon? And are the systems capable of instantly cutting off illegal access as soon as a breach is discovered?</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Confronted</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;with a grave breach of electronic security, Express Scripts has responded by contacting law enforcement, establishing an informational website, offering a substantial reward and hiring a private consulting firm to help clients who have privacy concerns and investigate situations that “appear to be tied to identity theft” and provide “identity restoration services.” There is no question that the company is taking the situation extremely seriously.</span></span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Given the ongoing criminal situation, information about how Express Scripts’ data systems were compromised — and whether it could have been avoided — has yet to be disclosed. But the American people have the right to expect that their sensitive personal and medical information is zealously protected and kept secure — not only by Express Scripts but also by every person or company entrusted with it.</span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><div><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The reason I am surprised this doesn&#39;t happen more often is that many Fortune 500 companies have oceans and oceans of personal data. Almost the only companies that have even tried to get to a medium level assurance are financial companies, yet many of the other companies have as much or even more data, with lower assurance. All that was lacking in the mix was an incentive and a bit of creativity and risk taking by the bad guys.</span></span></p><div><span style="color: #333333; line-height: 17px;"><br /></span></div><div><span style="color: #333333; line-height: 17px;">I posted this to the security metrics list and Andy Jaquith quoted it in his great book S<a href="http://1raindrop.typepad.com/1_raindrop/2007/08/chicken-soup-fo.html">ecurity Metrics</a>:</span></div><div><span style="color: #333333; line-height: 17px;"><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; ">&quot;Customers and customer relationships...have tangible measurable value to businesses, and their value is much easier to communicate to those who fund projects. So in an enterprise risk management scenartio, their vlaue informs the risk management process...[For example, consider] a farmer deciding which crop to grow. A farmer interested in short term profits may grow the same high yield crop every year, but over time this would burn the fields out. The long term focused farmer would rotate the crops and invest in things that build the value of the farm and soil over time. Investing in security on behalf of your customers is like this. The investment made in securing your customer&#39;s data build current and future value for them. Measuring the value of the customer and relationships helps to target where to allocate security resources.&quot;</span></p></blockquote><div><span style="color: #333333; line-height: 17px;"><br /></span></div><div><span style="color: #333333; line-height: 17px;">Of course this is the opposite of how most organizations do risk management and security architecture, and now, the fields have turned brown.<br /></span><div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">(Thanks to Chris for pointing me to this story)</span></div></div></div>]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 06:37:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/medical information">medical information</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/personal">personal</category>
      <category domain="http://securityratty.com/tag/personal medical records">personal medical records</category>
      <category domain="http://securityratty.com/tag/medical records">medical records</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/security systems">security systems</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/not-your-fathers-data-breach.html">Not Your Father's Data Breach</source>
    </item>
    <item>
      <title><![CDATA[Podcast: Cloud Computing, Software Development, Testing and Security]]></title>
      <link>http://securityratty.com/article/17d0b9aafe426c2e469aa3ccc41622d5</link>
      <guid>http://securityratty.com/article/17d0b9aafe426c2e469aa3ccc41622d5</guid>
      <description><![CDATA[Last month I was interviewed for a podcast with SearchSoftwareQuality.com
We talked about some of the advantages Cloud Computing could bring to software development and testing. Notice I say could - I...]]></description>
      <content:encoded><![CDATA[<p><img class="alignleft" src="http://media.techtarget.com/searchSoftwareQuality/images/header_logo2.gif" alt="SearchSoftwareQuality Logo" /></p>
<p>Last month I was interviewed for a podcast with <a href="http://SearchSoftwareQuality.com">SearchSoftwareQuality.com</a>.</p>
<p>We talked about some of the advantages Cloud Computing could bring to software development and testing.  Notice I say &#8216;could&#8217; - I continue to see <a href="http://cloudsecurity.org/2008/07/21/assessing-the-security-benefits-of-cloud-computing/">great potential benefits</a> but some of these require us to rethink how we do things as &#8216;end-users&#8217; and depend on the Cloud Computing ecosystem maturing enough to deliver them (e.g. security monitoring of Cloud API calls).</p>
<p>This was recorded prior to the Microsoft Azure announcement hence the &#8220;software + services&#8221; model wasn&#8217;t covered.</p>
<p>Anyway, the podcast is broken into 3 x 8 minute segments (I think I broke the spoken word count ;-):</p>
<ul>
<li><span class="a3"> General benefits of cloud computing for software development</span></li>
<li><span class="a3"> Cloud computing&#8217;s impact on agile development practices, software testing, and e-commerce</span></li>
<li><span class="a3">Security elements surrounding cloud computing, such as software monitoring, implementing security patches, and the reduction of data leakage.</span></li>
</ul>
<p>You can access the podcast segments <a href="http://searchsoftwarequality.techtarget.com/generic/0,295582,sid92_gci1338164,00.html">here</a>.</p>
<p>My thanks to Michelle and Erick over at TechTarget for the opportunity.</p>
<h4>What About You?</h4>
<p>Apart from general feedback on whether the podcast was helpful or not, I&#8217;m interested to hear if you&#8217;ve started any Cloud based development projects - please share in the comments.</p>
<img src="http://feeds.feedburner.com/~r/CloudSecurity/~4/447347585" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 09 Nov 2008 08:57:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/software development">software development</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/cloud computings impact">cloud computings impact</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <category domain="http://securityratty.com/tag/cloud api calls">cloud api calls</category>
      <category domain="http://securityratty.com/tag/advantages cloud">advantages cloud</category>
      <category domain="http://securityratty.com/tag/podcast segments">podcast segments</category>
      <source url="http://feeds.feedburner.com/~r/CloudSecurity/~3/447347585/">Podcast: Cloud Computing, Software Development, Testing and Security</source>
    </item>
    <item>
      <title><![CDATA[Sleep more and live longer]]></title>
      <link>http://securityratty.com/article/9f762fb9b67dbcb8db8c308caea29d19</link>
      <guid>http://securityratty.com/article/9f762fb9b67dbcb8db8c308caea29d19</guid>
      <description><![CDATA[An interesting study was discussed on WTOP radio today

It seems that two Swedish doctors conducted a sleep study between 1987 and 2006. Their findings have been published in the New England School of...]]></description>
      <content:encoded><![CDATA[An interesting study was discussed on WTOP radio today.<br /><span id="fullpost"><br />It seems that two Swedish doctors conducted a sleep study between 1987 and 2006.  Their findings have been published in the New England School of Medicine's records.<br /></span><br />They discovered that 5% more heart attacks were recorded the Monday after clocks go forward.  At the same time, there were less heart attacks documented on the Monday following the weekend period when clocks go backward.<br /><br />The findings indicate the importance of getting a good night's rest.  When the clocks are set forward an hour, people lose an hour of sleep.  That was the time when more heart attacks were found to have occurred.<br /><br />In the field of security, it is not always possible to get enough rest.  Many times it is necessary to work a 12 hour shift and then drive home afterwards.  If this is the case, the officer/agent should make sure that he/she gets adequate rest when they are off duty.<br /><br />Unfortunately, there are other elements that add to a less than healthy lifestyle such as; drinking a lot of coffee, not eating balanced meals, lack of exercise, etc.  Armed with the knowledge that sleep is so vital to our health, it is more important now than ever to ensure that we are taking proper care of ourselves.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Fri, 31 Oct 2008 00:16:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/heart attacks">heart attacks</category>
      <category domain="http://securityratty.com/tag/hour">hour</category>
      <category domain="http://securityratty.com/tag/hour shift">hour shift</category>
      <category domain="http://securityratty.com/tag/forward">forward</category>
      <category domain="http://securityratty.com/tag/rest">rest</category>
      <category domain="http://securityratty.com/tag/set forward">set forward</category>
      <category domain="http://securityratty.com/tag/clocks">clocks</category>
      <category domain="http://securityratty.com/tag/drive home">drive home</category>
      <category domain="http://securityratty.com/tag/monday">monday</category>
      <source url="http://www.thebulletproofblog.com/2008/10/sleep-more-and-live-longer.html">Sleep more and live longer</source>
    </item>
    <item>
      <title><![CDATA[On Being Informative, or Seeing Through The Fog]]></title>
      <link>http://securityratty.com/article/525775c15c5a11217da6325a35c96ec8</link>
      <guid>http://securityratty.com/article/525775c15c5a11217da6325a35c96ec8</guid>
      <description><![CDATA[UPDATE: @MYRCURIAL from the great site Liquidmatrix says that I need to post the following warning
YOU MAY NOT WANT TO PROCESS THIS PRIOR TO YOUR 11TH CUP OF COFFEE

Carrying on from yesterdays post a...]]></description>
      <content:encoded><![CDATA[<p>==================================</p>
<p>UPDATE:  @MYRCURIAL from the great site <strong><a href="http://www.liquidmatrix.org/blog/">Liquidmatrix</a></strong> says that<strong> <a href="http://twitter.com/myrcurial/status/980493800">I need to post the following warning</a></strong>:</p>
<p><span class="entry-content"> YOU MAY NOT WANT TO PROCESS THIS PRIOR TO YOUR 11TH CUP OF COFFEE</span></p>
<p>==================================</p>
<p>Carrying on from yesterday&#8217;s post a bit, I&#8217;m happy to admit that Chris&#8217; poem is right: we don&#8217;t have nearly the information we need now when we&#8217;re supposed to have &#8220;control&#8221; over our assets, putting things in a hosted/asp/cloud/buzzword model ain&#8217;t going to help our quest for visibility. My intention was/is to show that you need visibility (in part one) and then today explain that unfortunately, that&#8217;s only half the picture.</p>
<p>Today&#8217;s follow-on is about the fact that whatever visibility we can contractually enforce (be it in the &#8220;cloud&#8221; or in our own perimeter) has to be informative (Amrit, this is why I was plugging you with those variance questions on Twitter yesterday).  That is, we can ask whatever IT department (ours, theirs, whomever) for all sorts of information, and maybe they&#8217;ll even give it to us.  But we&#8217;re not really ready to:</p>
<ul>
<li>Know what to ask for</li>
<li>Use it to create wisdom</li>
</ul>
<p>A really salient example of this from outside IT hit my browser this morning.  Now it&#8217;s not at all my intention to be political or endorse one candidate over another.  Those who know me know I&#8217;m fiercely independent.  But this morning there&#8217;s a headline on a well-read news website about how one candidate is now &#8220;+2&#8243; over another in a Gallup poll of &#8220;likely voters&#8221;. The source is <a href="http://www.gallup.com/poll/111124/Gallup-Daily-Likely-Voters-Traditional.aspx"><strong>here</strong></a>.</p>
<p><a href="http://www.gallup.com/poll/111124/Gallup-Daily-Likely-Voters-Traditional.aspx"><img class="alignnone" title="Gallup +2" src="http://www.riskmanagementinsight.com/media/images/weblog/gallup.jpg" alt="" width="597" height="452" /></a></p>
<p>That is a screen grab from Gallup&#8217;s website that shows the &#8220;+2&#8243;.   I have to ask - how informative is this information?  Part of the problem is that Gallup&#8217;s methods are hidden as some sort of &#8220;secret sauce&#8221; (their <strong><a href="http://www.gallup.com/poll/111268/How-Gallups-likely-voter-models-work.aspx">FAQ section</a></strong> doesn&#8217;t help much, either).  But regardless of the quality of the measurement, this &#8220;+2&#8243; has no context - we don&#8217;t really know what this information means with regards to an actual election.  Nor is there any predictive element (I hate the using the word predictive, but it&#8217;s common nomenclature - so there you go).  We don&#8217;t have what we need from this Gallup poll to create wisdom about the ability of either candidate to be elected.</p>
<p>Allow me show you what I mean by way of contrast.  Take a look at Nate Silver&#8217;s work at <strong><a href="http://www.fivethirtyeight.com/">http://www.fivethirtyeight.com/</a></strong>.  Now I&#8217;ve been long familiar with Nate due to his work in baseball.  He&#8217;s been at these sorts of &#8216;predictive&#8217; analytics around our shared passion: creating wisdom from baseball statistics.</p>
<p>What Nate is doing at 538 is applying that acumen from his baseball work to the political process.  He&#8217;s breaking down the vote not just on popularity among likely voters, but in the context of the electoral college, accounting for variance and uncertainty, running Monte Carlo simulations and taking into account all sorts of polling information.  The result is really quite amazing. Here&#8217;s just one graph he presents - it&#8217;s the most similar to the Gallup one above, but you should really visit the site to understand the difference in quality of information and to check out the predictive elements he creates.</p>
<p><a href="http://www.fivethirtyeight.com/"><img class="alignnone" src="http://www.riskmanagementinsight.com/media/images/weblog/538.jpg" alt="" width="376" height="377" /></a></p>
<p><strong>NOT ALL INFORMATION IS CREATED EQUAL</strong>, <em>AND NOT ALL  JUDGMENTS ARE CREATED EQUALLY</em></p>
<p>And take a look at the contrast, here:</p>
<p>On one hand you have Gallup giving us a &#8220;+2&#8243; advantage to a particular candidate.  Now Gallup themselves draws no conclusion but, as digested, how many readers do you think take this as evidence that the election is *really* close?</p>
<p>On the other hand, 538&#8217;s predictions show a 348/189 electoral college split, and one candidate winning 96% of the time in simulated elections.  That doesn&#8217;t seem close at all!</p>
<p><strong>RISK MANAGEMENT</strong></p>
<p>It is these predictive elements that we need in order to make better strategy and decisions.  I&#8217;ve been talking in the past about risk management&#8217;s inability to link current state to systemic causes, and this &#8220;context&#8221; is what predictive analytics provide.  We might have all sorts of visibility into our environment, and measurement of various amounts of variability that visibility gives us. But unless we have context to create wisdom, it&#8217;s all just, as Chris says, &#8220;machinations&#8221;.  <em><strong>We have to move beyond &#8220;+2&#8243;.<br />
</strong></em></p>
<p>So Cloud/Grid/Utility/ASP/TimeShare/Whatever you want to call it - security will have to clean up our own mess first before we can do a good job with or without a perimeter.  Once we can start moving beyond &#8220;+2&#8243; statements, then we can know what sort of visibility we require into an ability to Prevent, Detect, and Respond.</p>
]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 10:18:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gallup">gallup</category>
      <category domain="http://securityratty.com/tag/gallup poll">gallup poll</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/electoral college split">electoral college split</category>
      <category domain="http://securityratty.com/tag/predictive analytics provide">predictive analytics provide</category>
      <category domain="http://securityratty.com/tag/predictive analytics">predictive analytics</category>
      <category domain="http://securityratty.com/tag/electoral college">electoral college</category>
      <category domain="http://securityratty.com/tag/wisdom">wisdom</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=503">On Being Informative, or Seeing Through The Fog</source>
    </item>
    <item>
      <title><![CDATA[A horse's ass approach to virtualization security - Part 3 - Data is the "constant"]]></title>
      <link>http://securityratty.com/article/af1e0093472ebbd2f739b12a4817fa7e</link>
      <guid>http://securityratty.com/article/af1e0093472ebbd2f739b12a4817fa7e</guid>
      <description><![CDATA[The third in the series where I am trying to think through the current approaches to securing virtual environments

See part one and two here

Virtualization enables organizations to optimally manage...]]></description>
      <content:encoded><![CDATA[The third in the series where I am trying to think through the current approaches to securing virtual environments...<br /><br />See <a href="http://bitarmor.blogspot.com/2008/10/horses-ass-approach-to-virtualization.html">part one</a> and <a href="http://bitarmor.blogspot.com/2008/10/horses-ass-approach-to-virtualization_22.html">two here</a>...<br /><br />Virtualization enables organizations to optimally manage their infrastructure resources. It can provide significant cost benefits (by sharing resources), flexibility (by just-in-time allocation of resources where they are needed), and agility (speed of provisioning resources).  Therefore, organizations have been able to virtualize:<br /><ul><li><span style="font-weight: bold;">Devices/OS</span>: Companies such as VMWare, Citrix, Microsoft, and Sun are providing hypervisor, virtual machine, and virtual device solutions where several virtual “devices,” “servers,” or “desktops” can mimic separate physical devices.</li><li><span style="font-weight: bold;">Networks</span>: Virtualized networks enable dynamic collaboration by slicing bandwidth into virtual, isolated channels that can be assigned to a particular set of devices, real or virtual.  Setting up new connections and collaborative environments becomes extremely easy.</li><li><span style="font-weight: bold;">Applications</span>: Virtual applications can either be streamed down to execute on local desktops (Microsoft App-V or Altiris SVS) or executed remotely from server farms such as Citrix XenApp.  This allows applications to be portable and accessible from anywhere while reducing inter-application conflicts.</li></ul>However, organizations will never be able to virtualize the fourth element, I talked about in teh <a href="http://bitarmor.blogspot.com/2008/10/horses-ass-approach-to-virtualization_22.html">second blog</a> post — the data itself. The focus of device, network, and application virtualization is about flexibility, resource sharing, and agility. This involves short life spans, since these elements are brought up to fulfill a specific short term task, and upon completion, they are brought down or even deleted. Data, however, has a lifetime <span style="font-weight: bold; font-style: italic;">beyond </span>the short term and will therefore live on for further use or analysis in a non-virtual or subsequent virtual world.<br /><br />This makes data the “constant” in a dynamically changing environment — even if the location of data itself is virtualized. Data will also have the longest lifetime of the four elements in the infrastructure and thus will have to live “outside” of the virtual environment. Therefore, from a security standpoint, it is imperative that data becomes the focus of protection - and we dont just continue protecting the infrastructure.  Data is the critical asset, and since it travels across boundaries and lives longer than virtual elements, it can be easily compromised.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=nM7eM"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=nM7eM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=xKbIm"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=xKbIm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=JcSvM"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=JcSvM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/430031380" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 23 Oct 2008 16:51:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/virtual devices">virtual devices</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <category domain="http://securityratty.com/tag/virtual applications">virtual applications</category>
      <category domain="http://securityratty.com/tag/subsequent virtual world">subsequent virtual world</category>
      <category domain="http://securityratty.com/tag/virtual environments">virtual environments</category>
      <category domain="http://securityratty.com/tag/non-virtual">non-virtual</category>
      <category domain="http://securityratty.com/tag/virtual machine">virtual machine</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/430031380/horses-ass-approach-to-virtualization_23.html">A horse's ass approach to virtualization security - Part 3 - Data is the "constant"</source>
    </item>
    <item>
      <title><![CDATA[A horse's ass approach to virtualization security - The four horsemen]]></title>
      <link>http://securityratty.com/article/8fa3354e9fe6c665bdd3e918f53590e1</link>
      <guid>http://securityratty.com/article/8fa3354e9fe6c665bdd3e918f53590e1</guid>
      <description><![CDATA[I opinioned a bit about the current approaches to virtualization security and how they might be failing to address current and future threats - let me explain further what I mean

In this blog I want...]]></description>
      <content:encoded><![CDATA[I opinioned a bit about the <a href="http://bitarmor.blogspot.com/2008/10/horses-ass-approach-to-virtualization.html">current approaches to virtualization security</a> and how they might be failing to address current and future threats - let me explain further what I mean.<br /><br />In this blog I want to talk about the four elements that make up every computing environment<br />(i.e. the four horsemen :)):<br /><ul><li><span style="font-weight: bold;">Devices</span>: These are the hardware and operating system combinations that host or store the execution environment.</li><li><span style="font-weight: bold;">Applications</span>: Applications execute on host environments (devices + OS) and transform data into information useful for the business.</li><li><span style="font-weight: bold;">Data</span>: Digital representation of information that is acted upon by applications.</li><li><span style="font-weight: bold;">Networks</span>: Enable collaboration and the sharing of information across multiple devices and/or applications.</li></ul><img src="file:///C:/Users/manun/AppData/Local/Temp/moz-screenshot-1.jpg" alt="" /><img src="file:///C:/Users/manun/AppData/Local/Temp/moz-screenshot-2.jpg" alt="" />All four are abso<img src="file:///C:/Users/manun/AppData/Local/Temp/moz-screenshot-3.jpg" alt="" />lutely essential to complete any transaction in the modern business world. However, to gain competitive advantage, organizations are looking to optimize the usage of these four elements. Technology, flexibility, and agility are becoming increasingly important in a fast-changing business world and have therefore led to the rise of virtualization.<br /><br />In my next post I will discuss how these elements are being changed in a virtual environment and what impact it has on security.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=LbtfM"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=LbtfM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=h9Dmm"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=h9Dmm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=lnMVM"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=lnMVM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/428570711" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 22 Oct 2008 09:31:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/business world">business world</category>
      <category domain="http://securityratty.com/tag/modern business world">modern business world</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/virtualization security">virtualization security</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/environment">environment</category>
      <category domain="http://securityratty.com/tag/execution environment">execution environment</category>
      <category domain="http://securityratty.com/tag/applications">applications</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/428570711/horses-ass-approach-to-virtualization_22.html">A horse's ass approach to virtualization security - The four horsemen</source>
    </item>
    <item>
      <title><![CDATA[Comments, administrivia, and the future of the infosec professional]]></title>
      <link>http://securityratty.com/article/aa143c7f981843ba4a20d86448ecfd43</link>
      <guid>http://securityratty.com/article/aa143c7f981843ba4a20d86448ecfd43</guid>
      <description><![CDATA[Back when the spam was spiraling out of control, I configured my blog to close comments after 90 days. Ive removed the limitation now, for two reasons: the spam is under control, and I wanted to reply...]]></description>
      <content:encoded><![CDATA[<p>Back when the spam was spiraling out of control, I configured my blog to close comments after 90 days. I’ve removed the limitation now, for two reasons: the spam is under control, and I wanted to reply to a comment made to my post on IPsec/IPv6 direct connect.</p>  <p>On <a target="_blank" href="http://blogs.technet.com/steriley/archive/2008/06/25/directly-connect-to-your-corpnet-with-ipsec-and-ipv6.aspx#3104911">13 August, jcorey</a> asked about how to deal with those who firmly believe that the only answer to any security problem is to inspect everything at the edge. This is an important question, and I wanted to give Joe an answer. (You might have to scroll down when you click the previous link, it seems that linking to individual comments is broken.)</p>  <p>Today, <a target="_blank" href="http://blogs.technet.com/steriley/archive/2008/06/25/directly-connect-to-your-corpnet-with-ipsec-and-ipv6.aspx#3136984">15 October, I</a> wrote a little thesis as an answer to his question. I’m calling it out in a separate post because I want to make sure those of you with aggregators that don’t update when posts receive new comments still have a chance to reply with your thoughts. I’ll also repost it here:</p>  <blockquote>   <p>jcorey-- You've nailed the biggest obstacle to deploying something like direct connect. Many security professionals have been taught that there simply is, and never will be, a process or technology that allows you to trust anything that originates from outside your corpnet. These professionals cling to this belief, and have been the cause that allowed the whole “detection” market to bloom. </p>    <p>Let me be clear: this total lack of trustworthiness is no longer absolutely true. Of course there will be times when unknown machines will be used by known and unknown people to access your information. But what about one particular subset -- known humans, with known portable computers -- can't we do something better than treat them as toxic invaders? </p>    <p>Indeed we can. And that's what I'm proposing with direct connect. The technology -- managed, of course, with the right processes -- exists so that you can extend the trust to known computers even though you don't trust the network they're connected to. This is because you have mechanisms that: </p>    <p>1. Allow you to configure the machine according to your requirements (domain join, group policy) </p>    <p>2. Dictate computer and user authentication requirements (IPsec policies, smart cards) </p>    <p>3. Limit what the users of these machines can do (UAC, non-admin, Forefront Client Security, Windows Firewall, even software restriction policies) </p>    <p>4. Validate the health of machines initiating incoming connections and remediate if necessary (NAP, System Center Configuration Manager) </p>    <p>5. Limit the threat of attacks against stolen computers (domain logon, smart cards, BitLocker with TPM) </p>    <p>With the robust authentication, validation, configuration, and control mechanisms available to you, I simply don't see that there's any need to fall back to “detection” now. Detection technologies were -- and remain -- necessary for the times when we have no clue about the health of client computers and when we had no way to gauge the intent of the users. But it is truly reflective of a head-in-the-sand mentality to assume that this is a complete description of what's capable today. </p>    <p>You know, someone once asked me what it takes to be a security professional. I answered that there are two primary elements: <strong>become a networking/packet wonk</strong>, and <strong>be willing to change your opinions</strong> when the right evidence comes along. Indeed, I suspect that many security folk have forgotten the need to keep their wonikness updated, which in turn makes them resist new ideas regardless of the strength of the evidence. I'm not very proud of what I just wrote, because I loathe generalities, but I'm not sure what else to think here. Sigh.</p> </blockquote>  <p>Joe’s question is important and strikes at the foundation of what it means to be a security professional today. I’m eager to continue this conversation, because it’s reflective of what I sense to be a radical shift in our jobs—we are, or should be, no longer the wolf-crying propeller-head who sits in the basement and twiddles with the firewall. Instead, our job should be defined as one who’s charged with protecting the organization’s information from attack, while maximizing its utility to authorized users, according to the principles of least privilege. Your thoughts?</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3136996" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 15 Oct 2008 18:29:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/forefront client security">forefront client security</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/security professionals">security professionals</category>
      <category domain="http://securityratty.com/tag/professionals">professionals</category>
      <category domain="http://securityratty.com/tag/security professional">security professional</category>
      <category domain="http://securityratty.com/tag/direct connect">direct connect</category>
      <category domain="http://securityratty.com/tag/ipsecipv6 direct connect">ipsecipv6 direct connect</category>
      <category domain="http://securityratty.com/tag/computers">computers</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/10/15/comments-administrivia-and-the-future-of-the-infosec-professional.aspx">Comments, administrivia, and the future of the infosec professional</source>
    </item>
    <item>
      <title><![CDATA[A horse's ass approach to virtualization security]]></title>
      <link>http://securityratty.com/article/6d6310950dd47b0806138e4729f21f01</link>
      <guid>http://securityratty.com/article/6d6310950dd47b0806138e4729f21f01</guid>
      <description><![CDATA[The interest and excitement around virtualization is palpable. However, it seems like the security approaches in this area are similar to the constrains that a horse's ass put on the space shuttle...]]></description>
      <content:encoded><![CDATA[The interest and excitement around virtualization is palpable. However, it seems like the security approaches in this area are similar to the constrains that a <a href="http://www.astrodigital.org/space/stshorse.html">horse's ass put on the space shuttle design</a>.<br /><br />Virtualization security solutions today primarily focus on protecting the virtual OS, the virtual networks, or the hypervisor software itself. More specifically, most current virtualization security technologies are focused on preventing hypervisor root kits, providing intrusion detection, anti-malware, anti-virus, network security, etc. In the physical world, this is similar to individually protecting hardware, operating systems, and the networks that connect them. That is, the focus is mainly on protecting infrastructure and perimeter, not data. Protecting that data, however, should be the single most important aspect of virtualization security.<br /><br />Here is why: Any execution environment requires four elements: devices/hardware/OS, networks, applications, and data. With the advent of virtualization, physical devices/OS are being replaced by flexible, on-demand virtual “devices,” networks are being virtualized and applications are being streamed down from virtual environments. Therefore, the only remaining “constant” element is the data itself - which also has a longer lifetime than the ephemeral virtual environment. While protecting the virtual infrastructure is important, I believe the primary focus for protection should be the data – the true IT asset.<br /><br />Virtualization is a game-changer for computing and has forced the IT world to rethink its infrastructure; now virtualization security has to be rethought as well. An information-centric approach to persistently protecting the data itself is the only way to really benefit from virtualization and keep the data truly secure.<br /><br />Or thinking about it another way - why was Google's approach to navigate the web using search better than the initial Yahoo approach of hierarchical mapping? Coz Yahoo was mapping an old yellow-book approach to managing data, while Google took advantage of the new medium.<br /><br />I shall try and elaborate on my thoughts in upcoming posts...<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=I3ERM"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=I3ERM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=Y0Zmm"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=Y0Zmm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=uQozM"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=uQozM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/420080548" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 13 Oct 2008 21:52:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtualization security">virtualization security</category>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/virtualization security solutions">virtualization security solutions</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <category domain="http://securityratty.com/tag/virtual infrastructure">virtual infrastructure</category>
      <category domain="http://securityratty.com/tag/approach">approach</category>
      <category domain="http://securityratty.com/tag/on-demand virtual devices">on-demand virtual devices</category>
      <category domain="http://securityratty.com/tag/ephemeral virtual environment">ephemeral virtual environment</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/420080548/horses-ass-approach-to-virtualization.html">A horse's ass approach to virtualization security</source>
    </item>
    <item>
      <title><![CDATA[Interop NY Keynotes: Cisco]]></title>
      <link>http://securityratty.com/article/c55a3293fe594f4363a5830f6da4d48c</link>
      <guid>http://securityratty.com/article/c55a3293fe594f4363a5830f6da4d48c</guid>
      <description><![CDATA[After some rousing introduction music, Marie Hatter , Vice President, Network Systems and Security Solutions Marketing / CMO of Cisco began her presentation on virtualization
Introduction...]]></description>
      <content:encoded><![CDATA[<p>After some rousing introduction music, <a href="http://blogs.cisco.com/authors/bio/83" target="_blank">Marie Hatter</a>, Vice President, Network Systems and Security Solutions Marketing / CMO of Cisco began her presentation on virtualization.</p>
<p><strong>Introduction</strong></p>
<p>Virtualization is a word used by consumers and also by IT. But, do we all mean the same thing?</p>
<p>A very cool video from Cisco provided answers to &#8220;what is virtualization&#8221; from an  engineering perspective, data center perspective, IT perspective and the user perspective (virtual world).</p>
<p>Virtualization is about breaking the bonds between applications and server hardware, nodes and networks, applications and operating systems.</p>
<p>Why is this interesting? Virtualization holds the promise to transform the way we work, live, learn and play.</p>
<p><strong>Why virtualize?</strong></p>
<p>The real estate boom over the last 30 years has driven people to the suburbs. People didn&#8217;t mind commuting for an hour with lower gas prices. Today, we have a weak economy and gas prices are high. Something has to change.</p>
<p>Many are opting to stay at home. Businesses are trying out telecommuting, some (like Cisco) are even offering telepresence. This helps by reducing carbon footprint. Corporations are breaking free from physical requirements. The global workforce is also having an impact on the network. These changes are having a huge impact on the network.</p>
<p>We are on the cusp of transitioning from virtualization to VIRTUALIZATION.</p>
<p><strong>&#8220;One to many&#8230;.many to one.&#8221;</strong></p>
<p>This is Cisco&#8217;s idea of virtualization.</p>
<p>Consider the different roles we play in life - one to many. Spouse, executive, friend, parent, gym rat. This would be &#8220;one to many&#8221;. This is exactly what virtualization does. It allows you to partition resources off that you can use on the fly.</p>
<p><strong>Where do I start?</strong></p>
<p>Virtualization starts with server and storage. But, it&#8217;s the network that touches everything - it spans the physical, the virtual, and the cloud. This provides the connectivity to all these resources. The network brings transparency to the picture. It allows you to better monitor performance and better implement security - great benefits!</p>
<p><strong>Why do I need this?</strong></p>
<p>At Cisco, we saw that we were only using 20% of our storage utilization. We wanted to virtualize our datacenters. When we did that, we were able to get 68% storage utilization. For each year that we were able to defer buildup, we saved $40 million.</p>
<p>From a business standpoint, virtualization helps you differentiate and work faster. Provisioning in minutes, improved productivity and competitive differentiation, using less power (environmental impact), and up the ante of business continuity. If VMWare fails? It&#8217;s OK. You can reprovision it on the fly.</p>
<p><strong>Is it for everyone?</strong></p>
<p>IT organizations tend to be siloed. You have the IT side and the Operations side. Each has responsibility. For virtualization to work, these walls have to come down. The concept of virtualization depends on shared resources.</p>
<p><strong><a href="http://en.wikipedia.org/wiki/Metcalfe%27s_law" target="_blank">Metcalfe&#8217;s Law of the Network</a> Effect</strong></p>
<p>Everytime you add a node to the network, you increase the value. This is what happens with virtualization. Every device you virtualize increases the power of each device. More control of environment and more efficiency.</p>
<p>This leads to&#8230;</p>
<p><strong>Cloud computing.</strong></p>
<p>Wow, show of hands from the audience when Marie asked &#8220;how many are using cloud computing?&#8221; and &#8220;how many are using your own clouds?&#8221; - not a lot of hands were raised. Interesting considering the coverage cloud computing has and the focus of it.</p>
<p>Cloud computing has three possibilities at Cisco:</p>
<ul>
<li>Flexible infrastructure (hosting)</li>
<li>Abstract services (APIs)</li>
<li>Application services (SaaS)</li>
</ul>
<p>Automation is going to be key, and will need to integrate virtualization-aware elements.</p>
<p>Can you imagine if you wanted interoperability in the cloud? People haven&#8217;t even begun thinking about it.</p>
<p><strong>Conclusion</strong></p>
<p>As you virtualize, your role will change. You will think more about strategy. But keep in mind these &#8220;minefields&#8221; of virtualization:</p>
<ul>
<li>Insufficient planning</li>
<li>Lack of standards</li>
<li>Weak security</li>
</ul>
<p>Security cannot be an afterthought. It has to be planned. We&#8217;ve seen new forms of malware, hypervisor attacks, and root kit infections.</p>
<p>As higher expectations from end users evolve, we&#8217;re becoming not server oriented, but SERVICE oriented.</p>
<p><strong>Tips:</strong></p>
<ul>
<li>Think holistically</li>
<li>Consider IT culture - equipment and people</li>
</ul>
]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 10:11:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtualization">virtualization</category>
      <category domain="http://securityratty.com/tag/virtualization starts">virtualization starts</category>
      <category domain="http://securityratty.com/tag/virtualization helps">virtualization helps</category>
      <category domain="http://securityratty.com/tag/helps">helps</category>
      <category domain="http://securityratty.com/tag/virtualization depends">virtualization depends</category>
      <category domain="http://securityratty.com/tag/virtualization holds">virtualization holds</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network brings transparency">network brings transparency</category>
      <category domain="http://securityratty.com/tag/cisco">cisco</category>
      <source url="http://blog.sciencelogic.com/interop-ny-keynotes-cisco/09/2008">Interop NY Keynotes: Cisco</source>
    </item>
    <item>
      <title><![CDATA[New addition to the starting line-up...]]></title>
      <link>http://securityratty.com/article/bba1eed8238898849e065890447b0038</link>
      <guid>http://securityratty.com/article/bba1eed8238898849e065890447b0038</guid>
      <description><![CDATA[Hey all Dave here
Wanted to drop a quick note to introduce the latest member of the SDL team - Katie Moussouris
Many of you may already know Katie from her past work on the MSRC Ecosystem Strategy...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><?xml:namespace prefix = o /><o:p>Hey all – Dave here…</o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><o:p>Wanted to drop a quick note to introduce the latest member of the SDL team - Katie Moussouris!</o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><o:p>Many of you may already know Katie from her past work on the <A class="" title="MSRC Ecosystem Strategy Team" href="http://blogs.technet.com/ecostrat/default.aspx" target=_blank mce_href="http://blogs.technet.com/ecostrat/default.aspx">MSRC Ecosystem Strategy Team</A> or her tenure at Symantec and @Stake. </o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><o:p>Katie has joined the SDL team to help drive crucial elements of our SDL outreach effort; her primary responsibility will be managing our relationships with security consulting and training partners. She’ll additionally be tasked with ongoing analysis of the SDL – with a goal of assisting industry verticals that are looking to apply the SDL in critical computing scenarios.&nbsp; </o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><o:p>It goes without saying that she will be a regular contributor on the SDL Blog – but given her expertise, it’s likely she’ll continue to blog on an occasional basis over on Ecostrat...</o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><o:p>Anyway – here’s Katie in her own words!</o:p></FONT></FONT></P>
<BLOCKQUOTE>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><o:p><EM>Katie Moussouris is a Senior Security Program Manager in the Security Development Lifecycle (SDL) Outreach Team, working to bring Microsoft’s SDL to partners, vendors and customers in order to improve the security of the Internet as a whole. Katie began her nerdy life programming her C64 in grade school, writing her own Zork-like text-based adventure – which was of limited use, since she had no friends and she knew all the puzzles in her own game.&nbsp; Good thing she eventually left her room and found some like-minded people at a local 2600 meeting.</EM></o:p></FONT></FONT></P></BLOCKQUOTE>
<BLOCKQUOTE>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri><o:p><EM>Katie’s professional background is application security, having come from Symantec by way of the @stake acquisition. Katie founded the Microsoft Vulnerability Research Program (MSVR), extending the focus of Microsoft’s security vulnerability research to third party software.&nbsp; Katie also founded and ran the Symantec Vulnerability Research Program, the first program of its kind in Symantec's history to allow the publication through Responsible Disclosure of original vulnerability advisories discovered by Symantec researchers. In addition to performing security research, Katie has been an application penetration tester for Fortune 500 companies across numerous industries. She has uncovered serious vulnerabilities during the course of her work before they could be widely exploited by hooligans and criminals for either fun or profit, respectively.<BR></P></BLOCKQUOTE></EM></o:p></FONT></FONT><img src="http://blogs.msdn.com/aggbug.aspx?PostID=8945661" width="1" height="1">]]></content:encoded>
      <pubDate>Thu, 11 Sep 2008 18:32:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sdl">sdl</category>
      <category domain="http://securityratty.com/tag/sdl outreach effort">sdl outreach effort</category>
      <category domain="http://securityratty.com/tag/katie">katie</category>
      <category domain="http://securityratty.com/tag/katie moussouris">katie moussouris</category>
      <category domain="http://securityratty.com/tag/microsofts sdl">microsofts sdl</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security research">security research</category>
      <category domain="http://securityratty.com/tag/sdl team">sdl team</category>
      <category domain="http://securityratty.com/tag/security development lifecycle">security development lifecycle</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/09/11/new-addition-to-the-starting-line-up.aspx">New addition to the starting line-up...</source>
    </item>
  </channel>
</rss>
