<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: interoperable]]></title>
    <link>http://securityratty.com/tag/interoperable</link>
    <description></description>
    <pubDate>Tue, 15 Jan 2008 20:31:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Taming of the Information Security]]></title>
      <link>http://securityratty.com/article/d22f10755f4bc01c24a23a86362200d0</link>
      <guid>http://securityratty.com/article/d22f10755f4bc01c24a23a86362200d0</guid>
      <description><![CDATA[In many mid-size to large organizations, information security grows up to become an unmanageable complex beast. In some cases, this happens consciously where information security goes out of control,...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face="Times New Roman,Times,serif"><FONT size=3><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">In many mid-size to large organizations, information security grows up to become an unmanageable complex beast.&nbsp; </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">In some cases, this happens consciously where information security goes out of control, but in other cases this&nbsp;</SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">happens unconsciously where there is a slow but incremental increase in the complexity of information security </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">which leads to chaos. </SPAN></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond"><?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p><FONT face="Times New Roman,Times,serif" size=3>&nbsp;</FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face="Times New Roman,Times,serif"><FONT size=3><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">The information security field is not yet fully mature; there is a lack of cohesive interoperable framework.<SPAN style="mso-spacerun: yes">&nbsp;&nbsp; </SPAN></SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">The rapidly evolving landscape adds to the existing problem. There are several examples: Intrusion Detection System </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">(IDS) was quickly overtaken by Intrusion Prevention System (IPS).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>On the Firewall arena: the focus has moved </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">from perimeter security to end point security.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>There are some security visionaries who are preaching inside-out </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">security approach i.e. building products with information security in mind from the beginning. </SPAN></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt">&nbsp;</P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face="Times New Roman,Times,serif"><FONT size=3><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">Threats are </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">moving higher up in the OSI stack making it harder to detect. Hackers are becoming more sophisticated – there </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">are powerful free open source hacking tools available at their disposal. </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">Security managers driving security initiatives without co-ordination can result in pieces of puzzle that don't </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">fit well. Agency problem i.e. security managers thinking more about their personal advancement rather than security </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">of the company is bad for the company’s security initiative. Security leaders who do not have a clear vision of </SPAN></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face="Times New Roman,Times,serif"><FONT size=3><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">security at the component level, the administration level and the strategy level can only make information </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">security even more convoluted. The CISO and acting CIO of US Dept of Veteran affairs resigned after the breach</SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond"><SPAN style="mso-spacerun: yes">&nbsp;</SPAN>in May, 2006 where personal data of 26 million veterans and more than 2 million service members was stolen. </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">This clearly demonstrates the accountability and visibility of security leadership.</SPAN></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond"><o:p><FONT face="Times New Roman,Times,serif" size=3>&nbsp;</FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face="Times New Roman,Times,serif"><FONT size=3><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">The attitude of IT security leaders and security team members has a significant impact on security.<SPAN style="mso-spacerun: yes">&nbsp;&nbsp;Reckless buying of information security technology can result in wasteful expenditure&nbsp;and very little gain in efficiency</SPAN></SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">. Not understanding </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">the business perspective of security issues or security perspective of business issues can lead to poor security </SPAN></FONT></FONT><FONT face="Times New Roman,Times,serif"><FONT size=3><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">decisions. Using security as a mechanism to gain control rather than using it as a tool to reduce risk can only&nbsp;</SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">diminish the perceived value of security initiative. Implementing security as an afterthought rather than building </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">it into the framework not only result in poor architectural decision. Security investment is more like buying insurance.&nbsp;</SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">Thinking security as a vehicle providing an ROI can result in wrong expectation and lead poor decision. The business i</SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">n which a company operates contributes largely to the perceived importance to security. Financial institutions </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">usually have a higher bar on security because of the very nature of their business and their exposure legal liability. </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">It is a good idea for many technology companies to emulate&nbsp;financial institutions to raise their information security bar</SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">.</SPAN></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond"><o:p><FONT face="Times New Roman,Times,serif" size=3>&nbsp;</FONT></o:p></SPAN></P>
<P class=MsoNormal style="MARGIN: 0in 0in 0pt"><FONT face="Times New Roman,Times,serif"><FONT size=3><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">It could be a pipedream to accomplish complete<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>information security but accomplishing a well managed information </SPAN><SPAN style="FONT-SIZE: 14pt; FONT-FAMILY: Garamond">security program is an attainable possibility.</SPAN></FONT></FONT></P><PRE>&nbsp;</PRE>]]></content:encoded>
      <pubDate>Wed, 09 Jul 2008 02:33:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/information security field">information security field</category>
      <category domain="http://securityratty.com/tag/information security bar">information security bar</category>
      <category domain="http://securityratty.com/tag/information security program">information security program</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/information security technology">information security technology</category>
      <category domain="http://securityratty.com/tag/poor security decisions">poor security decisions</category>
      <category domain="http://securityratty.com/tag/information security grows">information security grows</category>
      <category domain="http://securityratty.com/tag/companys security initiative">companys security initiative</category>
      <source url="http://ravichar.blogharbor.com/blog/_archives/2008/7/9/3785025.html">Taming of the Information Security</source>
    </item>
    <item>
      <title><![CDATA[VMSafe = A Safer More Secure VMWare Environment]]></title>
      <link>http://securityratty.com/article/41bdf340ae6d0403d75aacbb37dde870</link>
      <guid>http://securityratty.com/article/41bdf340ae6d0403d75aacbb37dde870</guid>
      <description><![CDATA[New VMware VMsafe Technology Allows the Virtual Datacenter to Be More Secure Than Physical Environments Twenty Industry-Leading Security Vendors, Including CheckPoint, McAfee and Symantec, Endorse...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><h1>New VMware VMsafe™ Technology Allows the Virtual Datacenter to Be More Secure Than Physical Environments</h1>
			
			<h4>Twenty
Industry-Leading Security Vendors, Including CheckPoint, McAfee and
Symantec, Endorse VMsafe Technology and Announce Plans to Build
Interoperable Security Solutions</h4>
			
			<p><strong>Cannes, FRANCE, February 27, 2008</strong>
– VMware, Inc. (NYSE: VMW), the global leader in virtualization
solutions from the desktop to the datacenter, today announced new
security technology called VMware VMsafe™, <a href="http://www.vmware.com/go/vmsafe">http://www.vmware.com/go/vmsafe</a>,&nbsp; that protects applications running in virtual machines in ways previously not possible in physical environments.</p>

<p>To read more click here:&nbsp; <a href="http://www.vmware.com/company/news/releases/vmsafe_vmworld.html">http://www.vmware.com/company/news/releases/vmsafe_vmworld.html</a></p>

<p>---------</p>

<p>Wow, what an announcement today for security vendors looking to sell their wares to a growing base of customers taking advantage of virtualization and a great way for VMWare to help its customers secure networks created by VMWare!</p>

<p>This announcement from&nbsp; VMWare&nbsp; does highlight that VMWare is serious about helping their customers address security challenges.&nbsp; What is still to be determined however, is what this really means to customers.&nbsp; There were 20 security companies announced in the partnership and little information about what security problem each company is solving.&nbsp; I guess&nbsp; we should expect to see 20 press releases from these individual security companies in the near future.</p>

<p>My educated guess though, is that most security vendors will just be offering their existing security products that are in many cases physical firewalls, anti-virus, UTM, etc. The real value will be from solutions that bring unique value to the virtual environment vs. network designs that dictate routing traffic out of the Virtual Environment to a physical security appliance and back in.&nbsp; The other question is ; will the software vendors just be installing their software on the operating systems of Virtual Machines vs. Physical Machines?</p>

<p>Are there any real hooks being offered today that connect to VMWare and take advantage of these API's or are these things yet to come?&nbsp; My educated guess is that these are still things yet to come from the majority of the vendors in the program.</p>

<p>I've had the privileged of reading the API documents as the CTO of Montego Networks which is also part of the VMSafe program that was just announced and am very excited about the future possibilities of the program.&nbsp; </p>

<p>I'm excited to see the space finally get its due attention and am confident that the program will give birth to many new ideas and products that help solve the many security challenges introduced by virtualization.<br /><a onclick="window.open(this.href, '_blank', 'width=640,height=451,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/02/27/vmsafepartners.jpg"><img width="400" height="281" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/02/27/vmsafepartners.jpg" title="Vmsafepartners" alt="Vmsafepartners" style="margin: 0px 5px 5px 0px; float: left;" /></a>
</p>

<p>There are so many vendors in this newly announced program.&nbsp; I hope to see quality from the program vs. marketing quantity!</p>

<p><a onclick="window.open(this.href, '_blank', 'width=180,height=95,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/02/27/montegologoremix.jpg"><img width="200" height="105" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/02/27/montegologoremix.jpg" title="Montegologoremix" alt="Montegologoremix" style="margin: 0px 5px 5px 0px; float: left;" /></a>
</p><br /><br /></div>
]]></content:encoded>
      <pubDate>Thu, 28 Feb 2008 00:35:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/security companies">security companies</category>
      <category domain="http://securityratty.com/tag/individual security companies">individual security companies</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security products">security products</category>
      <category domain="http://securityratty.com/tag/solutions">solutions</category>
      <category domain="http://securityratty.com/tag/interoperable security solutions">interoperable security solutions</category>
      <category domain="http://securityratty.com/tag/physical security appliance">physical security appliance</category>
      <category domain="http://securityratty.com/tag/vmware vmsafe">vmware vmsafe</category>
      <source url="http://feeds.feedburner.com/~r/SecurityInTheVirtualWorld/~3/242525800/vmsafe-security.html">VMSafe = A Safer More Secure VMWare Environment</source>
    </item>
    <item>
      <title><![CDATA[VMSafe = A Safer More Secure VMWare Environment]]></title>
      <link>http://securityratty.com/article/cebe8a775d70b4df9a43f4ed031113b2</link>
      <guid>http://securityratty.com/article/cebe8a775d70b4df9a43f4ed031113b2</guid>
      <description><![CDATA[New VMware VMsafe??? Technology Allows the Virtual Datacenter to Be More Secure Than Physical Environments Twenty Industry-Leading Security Vendors, Including CheckPoint, McAfee and Symantec, Endorse...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><h1>New VMware VMsafe??? Technology Allows the Virtual Datacenter to Be More Secure Than Physical Environments</h1>
			
			<h4>Twenty
Industry-Leading Security Vendors, Including CheckPoint, McAfee and
Symantec, Endorse VMsafe Technology and Announce Plans to Build
Interoperable Security Solutions</h4>
			
			<p><strong>Cannes, FRANCE, February 27, 2008</strong>
??? VMware, Inc. (NYSE: VMW), the global leader in virtualization
solutions from the desktop to the datacenter, today announced new
security technology called VMware VMsafe???, <a href="http://www.vmware.com/go/vmsafe">http://www.vmware.com/go/vmsafe</a>,&nbsp; that protects applications running in virtual machines in ways previously not possible in physical environments.</p>

<p>To read more click here:&nbsp; <a href="http://www.vmware.com/company/news/releases/vmsafe_vmworld.html">http://www.vmware.com/company/news/releases/vmsafe_vmworld.html</a></p>

<p>---------</p>

<p>Wow, what an announcement today for security vendors looking to sell their wares to a growing base of customers taking advantage of virtualization and a great way for VMWare to help its customers secure networks created by VMWare!</p>

<p>This announcement from&nbsp; VMWare&nbsp; does highlight that VMWare is serious about helping their customers address security challenges.&nbsp; What is still to be determined however, is what this really means to customers.&nbsp; There were 20 security companies announced in the partnership and little information about what security problem each company is solving.&nbsp; I guess&nbsp; we should expect to see 20 press releases from these individual security companies in the near future.</p>

<p>My educated guess though, is that most security vendors will just be offering their existing security products that are in many cases physical firewalls, anti-virus, UTM, etc. The real value will be from solutions that bring unique value to the virtual environment vs. network designs that dictate routing traffic out of the Virtual Environment to a physical security appliance and back in.&nbsp; The other question is ; will the software vendors just be installing their software on the operating systems of Virtual Machines vs. Physical Machines?</p>

<p>Are there any real hooks being offered today that connect to VMWare and take advantage of these API's or are these things yet to come?&nbsp; My educated guess is that these are still things yet to come from the majority of the vendors in the program.</p>

<p>I've had the privileged of reading the API documents as the CTO of Montego Networks which is also part of the VMSafe program that was just announced and am very excited about the future possibilities of the program.&nbsp; </p>

<p>I'm excited to see the space finally get its due attention and am confident that the program will give birth to many new ideas and products that help solve the many security challenges introduced by virtualization.<br /><a onclick="window.open(this.href, '_blank', 'width=640,height=451,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/02/27/vmsafepartners.jpg"><img width="400" height="281" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/02/27/vmsafepartners.jpg" title="Vmsafepartners" alt="Vmsafepartners" style="margin: 0px 5px 5px 0px; float: left;" /></a>
</p>

<p>There are so many vendors in this newly announced program.&nbsp; I hope to see quality from the program vs. marketing quantity!</p>

<p><a onclick="window.open(this.href, '_blank', 'width=180,height=95,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/02/27/montegologoremix.jpg"><img width="200" height="105" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/02/27/montegologoremix.jpg" title="Montegologoremix" alt="Montegologoremix" style="margin: 0px 5px 5px 0px; float: left;" /></a>
</p><br /><br /></div>
]]></content:encoded>
      <pubDate>Thu, 28 Feb 2008 00:35:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security companies">security companies</category>
      <category domain="http://securityratty.com/tag/individual security companies">individual security companies</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security products">security products</category>
      <category domain="http://securityratty.com/tag/solutions">solutions</category>
      <category domain="http://securityratty.com/tag/interoperable security solutions">interoperable security solutions</category>
      <category domain="http://securityratty.com/tag/vmware">vmware</category>
      <category domain="http://securityratty.com/tag/physical security appliance">physical security appliance</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <source url="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/2008/02/vmsafe-security.html">VMSafe = A Safer More Secure VMWare Environment</source>
    </item>
    <item>
      <title><![CDATA[OMG, This is Funny: BullshIT Awards :-)]]></title>
      <link>http://securityratty.com/article/21d233499052e0d7e9f8bc78c9f1abc7</link>
      <guid>http://securityratty.com/article/21d233499052e0d7e9f8bc78c9f1abc7</guid>
      <description><![CDATA[Nick Selby delivers: &quot; The 2007 BullsIT Awards: The Top Ten Tech-Flack Quotes of the Year! Annotated

Examples: &quot;Our offering is very unique in the origination space.&quot; (#10) or &quot;Its a single,...]]></description>
      <content:encoded><![CDATA[<a href="http://nickselby.com">Nick Selby</a> delivers: "<a href="http://nickselby.com/yak/2007/11/15/top-ten-tech-flack-quotes-of-the-year-annotated/">The 2007 BullsIT Awards: The Top Ten Tech-Flack Quotes of the Year! Annotated!</a>"<br /><br />Examples: <strong>"Our offering is very unique in the origination space." (#10) </strong>or<strong> "It’s a single, interoperable, scalable, extensive security framework that protects the data today and tomorrow as the infrastructure changes." (#3) </strong> and of course his old fave <strong>"They’re not related. There’s no relationship to our funding and our research and development cycle." (#1)</strong><strong></strong><strong></strong><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=ReUaALD"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=ReUaALD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=XeEPM0D"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=XeEPM0D" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/217499996" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 15 Jan 2008 20:31:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nick selby delivers">nick selby delivers</category>
      <category domain="http://securityratty.com/tag/extensive security framework">extensive security framework</category>
      <category domain="http://securityratty.com/tag/development cycle">development cycle</category>
      <category domain="http://securityratty.com/tag/bullsit awards">bullsit awards</category>
      <category domain="http://securityratty.com/tag/tech-flack quotes">tech-flack quotes</category>
      <category domain="http://securityratty.com/tag/origination space">origination space</category>
      <category domain="http://securityratty.com/tag/relationship">relationship</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/protects">protects</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/217499996/omg-this-is-funny-bullshit-awards.html">OMG, This is Funny: BullshIT Awards :-)</source>
    </item>
  </channel>
</rss>
