<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: retain]]></title>
    <link>http://securityratty.com/tag/retain</link>
    <description></description>
    <pubDate>Thu, 05 Jun 2008 10:14:42 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Gartner Data Center Conference 2008]]></title>
      <link>http://securityratty.com/article/9a247228428224b9e36fa0f0db8d1d84</link>
      <guid>http://securityratty.com/article/9a247228428224b9e36fa0f0db8d1d84</guid>
      <description><![CDATA[The Gartner Data Center Conference kicked off this morning in Las Vegas. Despite the completely packed plane coming out here, Vegas seems quieter and not so crowded. The bartender at Wolfgang Pucks...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="96" alt="clip_image002" src="http://blog.sciencelogic.com/wp-content/uploads/2008/12/clip-image002.jpg" width="439" border="0" /></p>
<p>The <a href="http://www.gartner.com/it/page.jsp?id=627607" target="_blank">Gartner Data Center Conference</a> kicked off this morning in Las Vegas. Despite the completely packed plane coming out here, Vegas seems quieter and not so crowded. The bartender at Wolfgang Puck&#8217;s Bistro told me they were looking <a href="http://www.datacenterknowledge.com/archives/2008/12/02/at-the-gartner-data-center-conference/" target="_blank">forward to the 1800 people coming</a> to this show to fill the hotel up. As we&#8217;ve noted, the economic crisis is impacting business travel all around.</p>
<p>22% of the attendees at Data Center come from the public sector and government, with 44% coming from very large enterprises of 20K+ employees.</p>
<p>During the <a href="http://www.gartner.com/it/page.jsp?id=603107" target="_blank">Gartner IOM conference</a> in June, some of the most interesting info coming out of it was the quick polls of the audience on a variety of infrastructure and operations management topics. What are enterprises doing? Where are they headed? What&#8217;s important to them? Here are some quick takes from the opening session:</p>
<p>1) What is the largest data center challenge that you currently face?</p>
<ul>
<li><b>Smaller Budgets: 21%</b></li>
<li><b>Power &amp; Cooling: 20%</b></li>
<li>Dealing with the Rate of Technology Change: 15%</li>
<li>Aligning Activities with the Business: 15%</li>
<li>Modernizing Legacy Applications: 10%</li>
<li>Lack of Data Center Space because of Equipment Spread: 9%</li>
<li>How to Source IT Services: 5%</li>
<li>How to Find and Retain Talent: 5%</li>
</ul>
<p>Well, it&#8217;s taken almost a year to be &#8220;official&#8221;, but the National Bureau of Economic Research just announced that <a href="http://www.msnbc.msn.com/id/27999557/" target="_blank">the US has been in a recession since December of 2007</a>. It should come as a surprise to no one that dealing with smaller budgets is top of mind, even for the predominantly larger enterprises attending here. </p>
<p>2) What projects will receive the most funding in 2009?</p>
<ul>
<li><b>Virtualization/Consolidation: 31%</b></li>
<li>Data Center Facilities &#8211; new builds: 17%</li>
<li>IT Operations Process Improvement: 12%</li>
<li>IT Modernization: 7%</li>
<li><b>Green IT: 5%</b></li>
</ul>
<p>Virtualization and (server) consolidation projects are clearly a priority for larger enterprises in 2009. What&#8217;s interesting here is the relatively very low priority of <a href="http://www.devx.com/IT_Innovation/Article/40073?trk=DXRSS_LATEST" target="_blank">Green IT projects</a> &#8211; in spite of the importance to attendees of getting power and cooling costs under control. Perhaps there&#8217;s a gap here between what&#8217;s often the hype of Green IT and practical considerations for data center managers when it comes to power and cooling management.</p>
<p>3) Where are you with server consolidation projects?</p>
<ul>
<li>No Plans: 3%</li>
<li>Looking at it now and will start in next 2 years: 13%</li>
<li><b>In process now: 58%</b></li>
<li><b>Have already completed server consolidation project: 26%</b></li>
</ul>
<p>Larger enterprises are consolidating servers with a quarter of attendees already having gone through the process at least once. And according to poll #2, this trend will definitely continue.</p>
]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 15:55:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data center">data center</category>
      <category domain="http://securityratty.com/tag/enterprises">enterprises</category>
      <category domain="http://securityratty.com/tag/predominantly larger enterprises">predominantly larger enterprises</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/server consolidation projects">server consolidation projects</category>
      <category domain="http://securityratty.com/tag/data center managers">data center managers</category>
      <category domain="http://securityratty.com/tag/consolidation projects">consolidation projects</category>
      <category domain="http://securityratty.com/tag/data center facilities">data center facilities</category>
      <category domain="http://securityratty.com/tag/larger enterprises">larger enterprises</category>
      <source url="http://blog.sciencelogic.com/gartner-data-center-conference-2008/12/2008">Gartner Data Center Conference 2008</source>
    </item>
    <item>
      <title><![CDATA[Developing and Retaining a Security Testing Mindset]]></title>
      <link>http://securityratty.com/article/c9fe8331afdf4b02d5abd01f6850b9ba</link>
      <guid>http://securityratty.com/article/c9fe8331afdf4b02d5abd01f6850b9ba</guid>
      <description><![CDATA[Developing a security testing mindset is a hard task. Moreover, as hard as it is to develop it, it's just as hard to retain it and effectively apply it during testing. The authors discuss what it...]]></description>
      <content:encoded><![CDATA[Developing a security testing mindset is a hard task. Moreover, as hard as it is to develop it, it's just as hard to retain it and effectively apply it during testing. The authors discuss what it takes to conduct successful software security testing, primarily by describing how to develop a security testing mindset, retain it, and effectively apply it. In particular, they explore the different roles and processes an organization needs to maintain a high level of security assurance.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=f4c2de69626f7d492905a8a8564599e6" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=f4c2de69626f7d492905a8a8564599e6" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:42:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/mindset">mindset</category>
      <category domain="http://securityratty.com/tag/security assurance">security assurance</category>
      <category domain="http://securityratty.com/tag/effectively apply">effectively apply</category>
      <category domain="http://securityratty.com/tag/hard task">hard task</category>
      <category domain="http://securityratty.com/tag/hard">hard</category>
      <category domain="http://securityratty.com/tag/develop">develop</category>
      <category domain="http://securityratty.com/tag/authors discuss">authors discuss</category>
      <category domain="http://securityratty.com/tag/retain">retain</category>
      <source url="http://www.pheedo.com/click.phdo?i=f4c2de69626f7d492905a8a8564599e6">Developing and Retaining a Security Testing Mindset</source>
    </item>
    <item>
      <title><![CDATA[Ideal Tool to Solve Real Problems ... of the Near Future? - II]]></title>
      <link>http://securityratty.com/article/4d45e2880b790245f00c577a7d0b0226</link>
      <guid>http://securityratty.com/article/4d45e2880b790245f00c577a7d0b0226</guid>
      <description><![CDATA[I would like to continue the discussion I started in my previous post called &quot; Ideal Tool to Solve Real Problems ... of the Near Future? &quot; Specifically, upon outlining some problems with logging, I...]]></description>
      <content:encoded><![CDATA[<p>I would like to continue the discussion I started in my previous post called &quot;<a href="http://chuvakin.blogspot.com/2008/06/ideal-tool-to-solve-real-problems-of.html">Ideal Tool to Solve Real Problems ... of the Near Future?</a>&quot; Specifically, upon outlining some problems with logging, I will now forecast what will happen with them in 18-24 months. </p>  <ul>   <li>Which problems will be solved and forgotten? </li>    <li>Which ones will simply go away? </li>    <li>Which ones will persist and in fact increase? </li>    <li>Finally, which new ones might emerge? </li> </ul>  <p>First, let me bet my ass that &quot;<strong>Not knowing what to log</strong>&quot;<strong> </strong>problem <strong>will be licked in 18-24 months</strong>; at least as far as major regulations go, people will have a pretty good idea a) what&#160; the auditors want them to log (and review!) b) what they need to log for solving their problems. Now, for esoteric log sources (and custom applications) might still present a challenge from that point of view, but for basic &quot;staples&quot; (firewall, network gear, major OS) the mystery will be over (again, see &quot;<a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">Tell me EXACTLY what to log for PCI?</a>&quot;&#160; for reference)</p>  <p>Next, the problem of &quot;<strong>Log volume&quot; will&#160; definitely get worse, much worse</strong>.&#160; One might think that <em>100,000 each second</em> is a lot of log - but there WILL BE more at many companies! <em>Big application log explosion is coming</em>, fueled by the need to address logging in areas where such motivation was lacking before (basically, custom and vertical applications) as well as harness the power of &quot;uncommon&quot; logs for such tasks as fraud analysis or SOA monitoring. Keep in mind that even though in some areas logging is NOT a preferred way of monitoring and auditing activities (see <a href="http://chuvakin.blogspot.com/2007/12/how-to-do-database-loggingmonitoring.html">this discussion</a> on database logs <u><a href="http://chuvakin.blogspot.com/2007/12/how-to-do-database-loggingmonitoring.html">here</a></u>), application logging will still explode on us...</p>  <p>The problem of &quot;<strong>Log diversity&quot; </strong>(the fact that most logs all look different in format and meaning) <strong>will get worse before it will get better</strong> - and better it WILL (!!!) get since <a href="http://cee.mitre.org">standards are being developed</a>. We will see people struggling with all sorts bizarro log data in the coming years. Virtualization, web services and SOA, various ERP applications and even cloud services will increase the diversity of logging in the coming years.</p>  <p>Similar to the above, a problem of &quot;<strong>Bad logs&quot; </strong>(ones that are subjective, miss key information, require groping for a crystal ball to understand, turn log <em>analysis</em> into dark voodooistic experience or are <a href="http://www.loganalysis.org/pipermail/loganalysis/2008-January/000534.html">useless in some other way</a>) will also follow the pattern of the above log diversity problems - it <strong>will get worse before it gets better</strong> (via the <a href="http://cee.mitre.org">CEE standard effort</a> that now covers the <u><a href="http://openxdas.sourceforge.net/">OpenXDAS effort as well</a>!</u>) I noticed that people started asked me questions about &quot;how to do application logging right?&quot; and &quot;what to tell application developers about logging?&quot; which almost never happened in the past. BTW, watch <a href="http://www.securitywarrior.org">my blog</a> for some uber-fun info on that!</p>  <p><strong>&quot;Getting the logs&quot;</strong>&#160; has gotten much easier in recent years; agentless collectors like <u><a href="http://sourceforge.net/projects/lassolog">Project Lasso</a></u> (which, BTW, just <u><a href="http://www.loglogic.com/news/news-releases/2008/07/loglogic-launches-centralized-windows-event-log-collection-appliance-for-enterprise/">got updated</a></u>) and grabbing&#160; files remotely via secure protocols made application log collection easier (syslog-NG with TCP transfer and buffering also helped). Next, Windows 2008 will make it MUCH easier for the whole Windows kingdom due to their <a href="http://www.realtime-windowsserver.com/tips_tricks/2007/08/event_log_subscriptions_in_win.htm">use of web serv</a>ices (<u><a href="http://blogs.msdn.com/ericfitz/">thanks Eric!</a></u>). However, in the future it <strong>might resurface</strong> as we try to collect logs from &quot;weird&quot; places, again, <u><a href="http://chuvakin.blogspot.com/2008/05/cloud-this-cloud-that.html">clouds come to mind</a></u> as well as <u><a href="https://www.sans.org/webcasts/show.php?webcastid=91979">virtual environments</a></u> (e.g. how do you get logs off a dormant VM?). What's the next frontier in this area? Log discovery - automatic finding and identifying log files on systems in order to analyze and retain them (Yo, <u><a href="http://chuvakin.blogspot.com/2008/06/thanks-for-wonderful-t-shirt.html">my t-shirt-making colleagues...</a> </u>:-))</p>  <p>All this, however, pales in comparison with my favorite &quot;uber-challenge&quot;, &quot;<strong>Making sense of logs in&#160; an automated fashion&quot;</strong> - this baby is definitely not going away in 2-3 years. Much more research is needed to make that &quot;<strong>log-&gt;conclusion&quot;</strong> jump automatically without head-scratching, invoking ancient deities and cursing under ones's breath. Only then we can attempt to reliable handle &quot;proactive logging&quot; (i.e. analyzing various failure or compromise precursors in logs and then predicting the future based on them), another Holy Grail of logging domain.</p>  <p>Anything new will emerge? Yes, I think awareness of the <strong>&quot;Logging Gap&quot; problem will grow</strong>. &quot;Logging gap&quot; happens when you combine &quot;a need to log&quot; with utter &quot;inability to do so.&quot;&#160; For example, this will happen when people will know that they HAVE TO log, say, for compliance, but will have no way of doing it due to application or platform limitations. This will become one of the challenges and special &quot;logging add-ons&quot; will appear to close the logging gap and create additional logs where activity audit is desperately needed, but native logging is not helping to achieve it.</p>  <p>Also, I think people will <strong>finally</strong> <strong>wake up to</strong> &quot;<strong>Log security</strong>&quot; challenges - i.e. producing for use as evidence, compliance attestations, etc. <u><a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Log security</a></u> is not getting the attention <u><a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">it deserves</a></u>, but I think this challenge will finally emerge in full force in the next 2-3 years. My next poll will address that :-)</p>  <p>Anything else I missed? Share away!</p>  <p><strong>Related posts:</strong></p>  <ul>   <li>     <h5><a href="http://chuvakin.blogspot.com/2008/06/ideal-tool-to-solve-real-problems-of.html">Ideal Tool to Solve Real Problems ... of the Near Future?</a></h5>   </li>    <li>     <h5><a href="http://chuvakin.blogspot.com/2007/11/ideal-log-management-tool.html">Ideal Log Management Tool?</a></h5>   </li> </ul>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=OiE77K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=OiE77K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=mHZh5K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=mHZh5K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=MlgSPK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=MlgSPK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/356001661" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 17:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/log discovery">log discovery</category>
      <category domain="http://securityratty.com/tag/log">log</category>
      <category domain="http://securityratty.com/tag/log diversity">log diversity</category>
      <category domain="http://securityratty.com/tag/esoteric log sources">esoteric log sources</category>
      <category domain="http://securityratty.com/tag/log security">log security</category>
      <category domain="http://securityratty.com/tag/application log explosion">application log explosion</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/log analysis">log analysis</category>
      <category domain="http://securityratty.com/tag/log volume">log volume</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/356001661/ideal-tool-to-solve-real-problems-of.html">Ideal Tool to Solve Real Problems ... of the Near Future? - II</source>
    </item>
    <item>
      <title><![CDATA[US Government Won't Cede Control Over DNS Root Zone]]></title>
      <link>http://securityratty.com/article/921395ec15b9d9c6bc5244b23e58a028</link>
      <guid>http://securityratty.com/article/921395ec15b9d9c6bc5244b23e58a028</guid>
      <description><![CDATA[In a letter to ICANN Board chairman Peter Dengate-Thrush Meredith A. Baker, Acting Assistant Secretary for Communications and Information in the Commerce Department's NTIA (National Telecommunications...]]></description>
      <content:encoded><![CDATA[In <a href="http://www.ntia.doc.gov/comments/2008/ICANN_080730.html">a letter to ICANN Board chairman Peter Dengate-Thrush</a> Meredith A. Baker, Acting Assistant Secretary for Communications and Information in the Commerce Department's <A href="http://www.ntia.doc.gov/">NTIA (National Telecommunications and Information Administration)</A> has declared that the US government has no plans to yield the control it now has over changes to the Internet's DNS root zone file. ICANN manages the DNS root zone, but according to terms of an agreement between it and the NTIA. The distribution of changes in the zone file to the various root servers across the world is performed by VeriSign.

ICANN's authority to administer various aspects of the Internet DNS derives from agreements with the Commerce Department. The current agreement for that authority, <a href="http://www.icann.org/general/JPA-29sep06.pdf">the JPA or Joint Project Agreement</a>, is set to expire in September 2009. <a href="http://www.icann.org/en/jpa/iic/index.htm">ICANN has been gearing up for what comes next</a> with preparations for taking more complete control. The Baker letter pulls the rug out from under some of those plans.

I'm not surprised at the letter and it wouldn't surprise me if even an Obama administration were to retain such control, but observers in Europe and Asia will probably be disappointed.<br style="clear: both;"/>
      <a href="http://www.pheedo.com/click.phdo?s=2ab9e9989e648261565bc1d66a94e510"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=2ab9e9989e648261565bc1d66a94e510"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=2ab9e9989e648261565bc1d66a94e510" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/352691125" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 06:54:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/control">control</category>
      <category domain="http://securityratty.com/tag/dns root zone">dns root zone</category>
      <category domain="http://securityratty.com/tag/baker">baker</category>
      <category domain="http://securityratty.com/tag/joint project agreement">joint project agreement</category>
      <category domain="http://securityratty.com/tag/agreement">agreement</category>
      <category domain="http://securityratty.com/tag/baker letter pulls">baker letter pulls</category>
      <category domain="http://securityratty.com/tag/letter">letter</category>
      <category domain="http://securityratty.com/tag/internet dns derives">internet dns derives</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/352691125/us_government_wont_cede_control_over_dns_root_zone.html">US Government Won't Cede Control Over DNS Root Zone</source>
    </item>
    <item>
      <title><![CDATA[U.S. Government Won't Cede Control Over DNS Root Zone]]></title>
      <link>http://securityratty.com/article/acdeee9347364bcb941d4fd5080bf4ed</link>
      <guid>http://securityratty.com/article/acdeee9347364bcb941d4fd5080bf4ed</guid>
      <description><![CDATA[In a letter to ICANN Board Chairman Peter Dengate Thrush, Meredith A. Baker, acting assistant secretary for communications and information in the Commerce Department's National Telecommunications and...]]></description>
      <content:encoded><![CDATA[In <a href="http://www.ntia.doc.gov/comments/2008/ICANN_080730.html">a letter to ICANN Board Chairman Peter Dengate Thrush,</a> Meredith A. Baker, acting assistant secretary for communications and information in the Commerce Department's <A href="http://www.ntia.doc.gov/">National Telecommunications and Information Administration,</A> has declared that the U.S. government has no plans to yield the control it now has over changes to the Internet's DNS root zone file. ICANN manages the DNS root zone, but according to terms of an agreement between it and the NTIA. The distribution of changes in the zone file to the various root servers around the world is performed by VeriSign.

The authority of the Internet Corporation for Assigned Names and Numbers to administer various aspects of the Internet Domain Name System derives from agreements with the Commerce Department. The current agreement for that authority, <a href="http://www.icann.org/general/JPA-29sep06.pdf">the Joint Project Agreement</a>, is set to expire in September 2009. <a href="http://www.icann.org/en/jpa/iic/index.htm">ICANN has been gearing up for what comes next</a> with preparations for taking more complete control. The Baker letter pulls the rug out from under some of those plans.

I'm not surprised at the letter, and it wouldn't surprise me if even an Obama administration were to retain such control, but observers in Europe and Asia will probably be disappointed.<img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/x3qgSRHLfMQ" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 01 Aug 2008 06:54:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/control">control</category>
      <category domain="http://securityratty.com/tag/dns root zone">dns root zone</category>
      <category domain="http://securityratty.com/tag/baker">baker</category>
      <category domain="http://securityratty.com/tag/joint project agreement">joint project agreement</category>
      <category domain="http://securityratty.com/tag/agreement">agreement</category>
      <category domain="http://securityratty.com/tag/baker letter pulls">baker letter pulls</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/letter">letter</category>
      <category domain="http://securityratty.com/tag/internet domain">internet domain</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/x3qgSRHLfMQ/us_government_wont_cede_control_over_dns_root_zone.html">U.S. Government Won't Cede Control Over DNS Root Zone</source>
    </item>
    <item>
      <title><![CDATA[Seven steps to managing IT Risk]]></title>
      <link>http://securityratty.com/article/3cc491d771b5e862de257f98f7667692</link>
      <guid>http://securityratty.com/article/3cc491d771b5e862de257f98f7667692</guid>
      <description><![CDATA[Came across this overview read from a Gartner research note recently. It lays out seven recommended steps managing risk


Implement a framework for risk assessment and mapping
Establish the...]]></description>
      <content:encoded><![CDATA[Came across this <a href="http://www.pmportal.co.uk/content.asp?id=1812">overview read from a Gartner</a> research note recently.  It lays out seven recommended steps managing risk. <br /><br /><ul><li>Implement a framework for risk assessment and mapping.</li><li>Establish the responsibilities of risk managers with their areas of responsibility.</li><li>Identify and define the risks to which the business is exposed and what constitutes a risk event or "near miss" so that incidents can be mapped to specific risks.</li><li>Determine the threat level, and focus on those risks with the highest impact on performance.</li><li>Establish levels of controls for processes commensurate with the perceived threat.</li><li>Record and retain risk incident and near-miss information.</li><li>Conduct periodic risk assessments to determine changes in the operations risk profile and assess control performance.</li></ul>Great advice.  These seven steps are precisely what IT-GRC solutions should help an Enterprise accomplish.  They provide the construct (aka think configuration wizard) for establishing and maintaining a quality risk management program.   If you have on your company priority list advancing the the risk mitigation/management capabilities or if you've recently been burned, take the time and check out some of our new product demonstration videos.  We strive to be transparent around what we offer with our software.  That's why our marketing isn't really "marketing" it's live product in action.  <a href="http://security-works.com/metrics.html">Come check it out</a>.<img src="http://feeds.feedburner.com/~r/PracticalRiskManagement/~4/341936763" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 17:34:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk event">risk event</category>
      <category domain="http://securityratty.com/tag/risk assessment">risk assessment</category>
      <category domain="http://securityratty.com/tag/risk managers">risk managers</category>
      <category domain="http://securityratty.com/tag/operations risk profile">operations risk profile</category>
      <category domain="http://securityratty.com/tag/retain risk incident">retain risk incident</category>
      <category domain="http://securityratty.com/tag/specific risks">specific risks</category>
      <category domain="http://securityratty.com/tag/steps">steps</category>
      <category domain="http://securityratty.com/tag/risks">risks</category>
      <source url="http://feeds.feedburner.com/~r/PracticalRiskManagement/~3/341936763/seven-steps-to-managing-it-risk.html">Seven steps to managing IT Risk</source>
    </item>
    <item>
      <title><![CDATA[Have you googled, HR security breaches lately?]]></title>
      <link>http://securityratty.com/article/891bb72b417d85643a8bd1df738baf4f</link>
      <guid>http://securityratty.com/article/891bb72b417d85643a8bd1df738baf4f</guid>
      <description><![CDATA[Blogger: Randall Gamby
As briefly mentioned in a Burton Group IdPS blog and a ZDNet Australia published article on July 3, 2008, HR data from Google was stolen from one of their previous HR outsource...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby</p>

<p>As briefly mentioned in a Burton Group <a href="http://bgidps.typepad.com/bgidps/2008/07/physician-heal.html">IdPS blog</a> and a ZDNet Australia published <a href="http://www.zdnet.com.au/news/security/soa/Stolen-Google-s-employee-records-/0,130061744,339290305,00.htm">article</a> on July 3, 2008, HR data from Google was stolen from one of their previous HR outsource partners.&nbsp; It seems that the partner, Colt Express Outsource Partners, had equipment stolen that contained HR data from some of its clients, including Google.&nbsp; The data was unencrypted and stored on systems that were apparently portable.</p>

<p>So what does this mean for all of us?&nbsp; </p>

<p>First, it shows that even large SaaS companies like Google can be bitten by a lack of security at their partners, just like many of us can.&nbsp; Burton Group has been warning clients for a long time about the dangers of sending confidential information to outsource partners without proper security and audit processes in place. Of course this should also be backed by strong contractual language.&nbsp; </p>

<p>Second, be prepared to pay.&nbsp; Even if Google had breach mitigation terms in their contract, Colt Express announced that it was in financial difficulty. So Google has had to pay for financial reporting and other compensation to its own employees, even though Google did nothing wrong.&nbsp; </p>

<p>Third, a Google representative stated &quot;We take the security of our employees very seriously and require outside vendors to meet appropriate security standards. We review and update these standards on an on-going basis.”&nbsp; Does this mean that Google doesn’t require encryption of its confidential information since encryption of the data was not deployed at Colt Express?&nbsp; When working with third parties, whether it’s financial data or confidential personal data, this information needs to be protected from unauthorized access. One of the simplest ways is encrypting the data while at rest, regardless of where it’s located.&nbsp; </p>

<p>Final, the Colt Express breach brings to mind a question Burton Group is always asking: “What is your exit strategy if the contract is terminated with your outsourcing partner?”&nbsp; A lot of effort is expended in creating an outsourcing agreement around use and protection of data, but what happens when the contract is ended?&nbsp; Do you obtain and retain the information the outsource partner maintained?&nbsp; Do you have the outsource partner destroy the information and any archives of it (and verify this was done)?&nbsp; Do you create a custodial contract with the outsourcing partner for them to maintain the information and archives on your behalf (ensuring the data is properly protected)?&nbsp; As was found in this incident, after their contract with Google was terminated the outsourcing partner apparently retained the employee data unencrypted on their servers. This was the fatal mistake that allowed the breach to occur.</p>

<p>So as you work with your outsourcing and SaaS vendors, you should not only consider how day-to-day operations should be secured to maintain the confidentiality of your data. You should also think about how that data is being maintained over time, and what are your procedures should the unthinkable happen if your partner allows your data to be compromised.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/329819020" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 08 Jul 2008 05:38:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/employee data">employee data</category>
      <category domain="http://securityratty.com/tag/outsource partner destroy">outsource partner destroy</category>
      <category domain="http://securityratty.com/tag/outsource partner">outsource partner</category>
      <category domain="http://securityratty.com/tag/confidential personal data">confidential personal data</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/financial data">financial data</category>
      <category domain="http://securityratty.com/tag/partner">partner</category>
      <category domain="http://securityratty.com/tag/partner apparently">partner apparently</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/329819020/have-you-google.html">Have you googled, HR security breaches lately?</source>
    </item>
    <item>
      <title><![CDATA[Have you googled, ???HR security breaches??? lately?]]></title>
      <link>http://securityratty.com/article/bf3d37721214cbdc7177cde027bf8732</link>
      <guid>http://securityratty.com/article/bf3d37721214cbdc7177cde027bf8732</guid>
      <description><![CDATA[Blogger: Randall Gamby
As briefly mentioned in a Burton Group IdPS blog and a ZDNet Australia published article on July 3, 2008, HR data from Google was stolen from one of their previous HR outsource...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Randall Gamby</p>

<p>As briefly mentioned in a Burton Group <a href="http://bgidps.typepad.com/bgidps/2008/07/physician-heal.html">IdPS blog</a> and a ZDNet Australia published <a href="http://www.zdnet.com.au/news/security/soa/Stolen-Google-s-employee-records-/0,130061744,339290305,00.htm">article</a> on July 3, 2008, HR data from Google was stolen from one of their previous HR outsource partners.&nbsp; It seems that the partner, Colt Express Outsource Partners, had equipment stolen that contained HR data from some of its clients, including Google.&nbsp; The data was unencrypted and stored on systems that were apparently portable.</p>

<p>So what does this mean for all of us?&nbsp; </p>

<p>First, it shows that even large SaaS companies like Google can be bitten by a lack of security at their partners, just like many of us can.&nbsp; Burton Group has been warning clients for a long time about the dangers of sending confidential information to outsource partners without proper security and audit processes in place. Of course this should also be backed by strong contractual language.&nbsp; </p>

<p>Second, be prepared to pay.&nbsp; Even if Google had breach mitigation terms in their contract, Colt Express announced that it was in financial difficulty. So Google has had to pay for financial reporting and other compensation to its own employees, even though Google did nothing wrong.&nbsp; </p>

<p>Third, a Google representative stated &quot;We take the security of our employees very seriously and require outside vendors to meet appropriate security standards. We review and update these standards on an on-going basis.???&nbsp; Does this mean that Google doesn???t require encryption of its confidential information since encryption of the data was not deployed at Colt Express?&nbsp; When working with third parties, whether it???s financial data or confidential personal data, this information needs to be protected from unauthorized access. One of the simplest ways is encrypting the data while at rest, regardless of where it???s located.&nbsp; </p>

<p>Final, the Colt Express breach brings to mind a question Burton Group is always asking: ???What is your exit strategy if the contract is terminated with your outsourcing partner????&nbsp; A lot of effort is expended in creating an outsourcing agreement around use and protection of data, but what happens when the contract is ended?&nbsp; Do you obtain and retain the information the outsource partner maintained?&nbsp; Do you have the outsource partner destroy the information and any archives of it (and verify this was done)?&nbsp; Do you create a custodial contract with the outsourcing partner for them to maintain the information and archives on your behalf (ensuring the data is properly protected)?&nbsp; As was found in this incident, after their contract with Google was terminated the outsourcing partner apparently retained the employee data unencrypted on their servers. This was the fatal mistake that allowed the breach to occur.</p>

<p>So as you work with your outsourcing and SaaS vendors, you should not only consider how day-to-day operations should be secured to maintain the confidentiality of your data. You should also think about how that data is being maintained over time, and what are your procedures should the unthinkable happen if your partner allows your data to be compromised.</p></div>
]]></content:encoded>
      <pubDate>Tue, 08 Jul 2008 05:38:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/employee data">employee data</category>
      <category domain="http://securityratty.com/tag/outsource partner destroy">outsource partner destroy</category>
      <category domain="http://securityratty.com/tag/outsource partner">outsource partner</category>
      <category domain="http://securityratty.com/tag/confidential personal data">confidential personal data</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/financial data">financial data</category>
      <category domain="http://securityratty.com/tag/partner">partner</category>
      <category domain="http://securityratty.com/tag/partner apparently">partner apparently</category>
      <source url="http://srmsblog.burtongroup.com/2008/07/have-you-google.html">Have you googled, ???HR security breaches??? lately?</source>
    </item>
    <item>
      <title><![CDATA[Will Idiocy Ever End?]]></title>
      <link>http://securityratty.com/article/7a7383b72d02885cfc7f7edc37372687</link>
      <guid>http://securityratty.com/article/7a7383b72d02885cfc7f7edc37372687</guid>
      <description><![CDATA[So, I just came back from FIRST2008 and a typical conference discussion over beer has turned - again! - to academic security research

I lamented and ranted and rambled about it ( here , here , here...]]></description>
      <content:encoded><![CDATA[So, I just came back from <a href="http://www.first.org/conference/2008/program/#p864">FIRST2008</a> and a typical conference discussion over beer has turned - again! - to  academic security research.<br /><br />I lamented and ranted and rambled about it (<a href="http://chuvakin.blogspot.com/2007/12/spaf-on-academic-security-research.html">here</a>, <a href="http://chuvakin.blogspot.com/2007/09/once-more-on-failure-of-academic.html">here</a>, <a href="http://chuvakin.blogspot.com/2008/05/fun-security-reading-3.html">here</a>), but I am still shocked. I come from academic background myself and it is unthinkable to me that a research physicist today will write a thesis on 2nd Law of Newton or will set to prove that objects tend to fall down while dropped. Or that they, in fact, "fall up."<br /><br />However, that is the type of stuff I see in academic security papers that I occasionally get to review. Based on our FIRST conversation, other people who happen to retain ties to academia are reporting the same: research work that confuses "phishing" with "fast flux networks" (thanks Jose), inventing a new intrusion detection "paradigm, "  and all sorts of other bizarre crap continues to be cooked and  submitted to publications.<br /><br />When will this end? Why can't you people tackle REAL problems? Or at least useful and hard classic problems? Or, at the very least, learn  WTF is going on the real world of operational security before you do ANYTHING? The maybe you stop saying things like "in general, IDS is considered to be a security tool" as if it was some kind of Zen wisdom (a quote from a pathetic excuse for a paper that I reviewed recently...)<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=RlxgsI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=RlxgsI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=GLg27I"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=GLg27I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=0keoFI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=0keoFI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/319714659" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 02:15:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/academic security research">academic security research</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/people tackle real">people tackle real</category>
      <category domain="http://securityratty.com/tag/bizarre crap continues">bizarre crap continues</category>
      <category domain="http://securityratty.com/tag/typical conference discussion">typical conference discussion</category>
      <category domain="http://securityratty.com/tag/research physicist">research physicist</category>
      <category domain="http://securityratty.com/tag/academic security papers">academic security papers</category>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/319714659/will-idiocy-ever-end.html">Will Idiocy Ever End?</source>
    </item>
    <item>
      <title><![CDATA[CISSP's - Be Prepared for Audit]]></title>
      <link>http://securityratty.com/article/410312330d8927e04bc44cadca6affee</link>
      <guid>http://securityratty.com/article/410312330d8927e04bc44cadca6affee</guid>
      <description><![CDATA[Just a quick note to all CISSPs, or other certification-holders from (ISC)2
ISC)2 is taking a hard stand on CPE submissions and coming down heavy-handed on audits. If you attend an event, even if the...]]></description>
      <content:encoded><![CDATA[<p>Just a quick note to all CISSPs, or other certification-holders from <a class="offsite-link-inline" href="http://www.isc2.org/" target="_blank">(ISC)2</a></p><p>(ISC)2 is taking a hard stand on CPE submissions and coming down heavy-handed on audits. If you attend an event, even if the event host is an (ISC)2 CPE-Submitter, you need to retain your &#8216;proof of attendance&#8217; and keep those documents on file. Generally an event host will provide a CPE audit retention sheet at the time of the event, or post-event. </p><p>I recently received an audit for my attendance at the<a class="offsite-link-inline" href="http://rsaconference.com/" target="_blank"> RSA Conference </a>in February. While they don&#8217;t specify a specific date or time frame you have to respond, I would recommend responding to an audit within 30 days. </p><p>Here are some quick tips&#8230;</p><ul><li><div>Provide your CISSP number to event hosts that are CPE-Submitters</div></li><li><div>Keep and file any documentation, programs&nbsp;and&nbsp;badges from the event</div></li><li><div>If provided, keep the &#8216;Proof of Attendance&#8217; sheet&nbsp;from the event host</div></li><li><div>Keep supporting docs for 12 months past the 3-year certification cycle you claimed the CPEs in</div></li></ul><p>For more information, visit the official <a class="offsite-link-inline" href="http://www.isc2.org/" target="_blank">(ISC)2 site</a>. </p><p># # #</p>
]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 10:14:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/event hosts">event hosts</category>
      <category domain="http://securityratty.com/tag/event host">event host</category>
      <category domain="http://securityratty.com/tag/post-event">post-event</category>
      <category domain="http://securityratty.com/tag/audit">audit</category>
      <category domain="http://securityratty.com/tag/attendance">attendance</category>
      <category domain="http://securityratty.com/tag/isc">isc</category>
      <category domain="http://securityratty.com/tag/attendance sheet">attendance sheet</category>
      <category domain="http://securityratty.com/tag/time frame">time frame</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/6/5/cissps-be-prepared-for-audit.html">CISSP's - Be Prepared for Audit</source>
    </item>
  </channel>
</rss>
