<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: sims]]></title>
    <link>http://securityratty.com/tag/sims</link>
    <description></description>
    <pubDate>Tue, 11 Mar 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Is IF-MAP the spark that will ignite theTCG/TNC and the security industry?]]></title>
      <link>http://securityratty.com/article/9bb14b4ce6033e3aaabea0ddf8020db1</link>
      <guid>http://securityratty.com/article/9bb14b4ce6033e3aaabea0ddf8020db1</guid>
      <description><![CDATA[The big news at Interop yesterday was the new IF-MAP specification and standard announced by the Trusted Computing Group/ TNC group. Some may call it TCG NAC 2.0 but it actually goes way beyond just...]]></description>
      <content:encoded><![CDATA[<p><a onclick="window.open(this.href, '_blank', 'width=800,height=394,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://www.stillsecureafteralltheseyears.com/.shared/image.html?/photos/uncategorized/2008/04/30/if_map.jpg"><img title="If_map" height="147" alt="If_map" src="http://www.stillsecureafteralltheseyears.com/ashimmy/images/2008/04/30/if_map.jpg" width="300" border="0" style="FLOAT: left; MARGIN: 0px 5px 5px 0px"></img></a> The big <a href="https://www.trustedcomputinggroup.org/news/events/interop_2008/">news at Interop</a> yesterday was the new IF-MAP specification and standard announced by the Trusted Computing Group/ TNC group. Some may call it TCG NAC 2.0 but it actually goes way beyond just NAC. IF-MAP represents a method that allows disparate security technologies to talk to each other and leverage the information gathered from multiple sources to make better and more secure decisions about network devices, users and traffic. It has huge implications for not only NAC, but IDS/IPS, vulnerability management, SIMs, etc. Also, it represents a real opportunity for the TCG/TNC to move out beyond the shadow of NAP and really become a dominant standard for the network and security industry to rally around.<br><br>The idea behind IF-MAP is that data is stored in a central container called a MAP or meta-data access point. This data can be called upon or supplemented with more data from a wide variety of sources. You can publish, search or subscribe to the data. The format is XML. The diagram (which you can click on for a bigger version) on the left shows a sample multi-vendor configuration, but the combinations are endless. To get a better flavor for what you can do you can click <a href="https://www.trustedcomputinggroup.org/news/events/interop_2008/TCG_TNC_update_04282008_final.pdf">here</a> to see a PDF presentation by the TCG of IF-MAP.<br><br>I had a chance to speak about IF-MAP with Steve Hanna and Mike Fratto. If it does indeed become widely adopted this can have a profound impact on our industry. Also, Steve and the TNC is very much looking to diversify and distribute the administration of the MAP among many vendors so that it does not become a single vendor steered standard. I applaud Steve and the rest of the group for working so hard on MAP. I challenge the rest of the industry to take a look at it and work towards adopting it. It truly can help be a win for all security vendors, but most of all a win for security administrators who would finally be able to use best-of-breed products from different vendors and have them talk to and work with each other.</p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=xDXXfo"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=xDXXfo" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=la83LG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=la83LG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=EoriIG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=EoriIG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=tyUWcG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=tyUWcG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ZUZkEG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ZUZkEG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=xGxxZg"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=xGxxZg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=IqTtrg"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=IqTtrg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/280801482" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 30 Apr 2008 05:25:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/if-map">if-map</category>
      <category domain="http://securityratty.com/tag/if-map specification">if-map specification</category>
      <category domain="http://securityratty.com/tag/map">map</category>
      <category domain="http://securityratty.com/tag/if-map represents">if-map represents</category>
      <category domain="http://securityratty.com/tag/represents">represents</category>
      <category domain="http://securityratty.com/tag/security industry">security industry</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/meta-data access">meta-data access</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/280801482/is-if-map-the-s.html">Is IF-MAP the spark that will ignite theTCG/TNC and the security industry?</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-03-11 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/cdcba6c8662cb7e405cb7df9772262b9</link>
      <guid>http://securityratty.com/article/cdcba6c8662cb7e405cb7df9772262b9</guid>
      <description><![CDATA[ROSI: Security Returns? | BlogInfoSec.com
Devil's Advocate Security - About Logging TLR
Challenges behind operational integration of security and network management To integrate a SIMs into a useful...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.bloginfosec.com/2008/03/10/rosi-security-returns/">ROSI: Security Returns? | BlogInfoSec.com</a></li>
<li><a href="http://devilsadvocatesecurity.blogspot.com/2008/03/log-management-observations-from-log.html">Devil's Advocate Security - About Logging TLR</a></li>
<li><a href="http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1297881_tax309847,00.html">Challenges behind operational integration of security and network management</a><br/>
To integrate a SIMs into a useful tool that both SOC and NOC team members can utilize, the process of successfully &quot;filtering&quot; alerts takes utmost priority.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/249923652" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 11 Mar 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security returns">security returns</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/operational integration">operational integration</category>
      <category domain="http://securityratty.com/tag/noc team">noc team</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/devil">devil</category>
      <category domain="http://securityratty.com/tag/challenges">challenges</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/sims">sims</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/249923652/anton18">Links for 2008-03-11 [del.icio.us]</source>
    </item>
  </channel>
</rss>
