<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: suddenly]]></title>
    <link>http://securityratty.com/tag/suddenly</link>
    <description></description>
    <pubDate>Tue, 02 Sep 2008 02:05:53 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links for 2008-11-25 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/5f45c605eed2ff767afb830215eb7e3a</link>
      <guid>http://securityratty.com/article/5f45c605eed2ff767afb830215eb7e3a</guid>
      <description><![CDATA[The Myth of Software Support Chris Swans Weblog
More On Why I Think Free Microsoft AV Will Be Good For Consumers | securosis.com My belief is that we essentially have both conditions today (low...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://thestateofme.wordpress.com/2008/11/20/the-myth-of-software-support/">The Myth of Software Support &laquo; Chris Swan&rsquo;s Weblog</a></li>
<li><a href="http://securosis.com/2008/11/25/more-on-why-i-think-free-microsoft-av-will-be-good-for-consumers/">More On Why I Think Free Microsoft AV Will Be Good For Consumers | securosis.com</a><br/>
My belief is that we essentially have both conditions today (low innovation, easy evasion), and the nature of attacks will continue to change rapidly enough to exceed the current capabilities of AV.</li>
<li><a href="http://securosis.com/2008/11/21/idiocy/">Idiocy | securosis.com</a></li>
<li><a href="http://securosis.com/2008/11/19/the-impact-of-free-antivirus-from-microsoft/">The Impact Of Free Antivirus From Microsoft | securosis.com</a><br/>
This gives them enough time to avoid suddenly losing 40% (don’t quote me on that, I’m on an airplane and just guessing) of profits over 12 months. The real losers will be the consumer-only AV companies without diversified portfolios or a larger enterprise base.</li>
<li><a href="http://www.csoonline.com/article/463067/Rich_Mogull_Infosec_Trends_for_">Rich Mogull: 7 Infosec Trends for 2009 - CSO Online - Security and Risk</a></li>
<li><a href="http://news.cnet.com/8301-1001_3-10096254-92.html">Safe bets for IT spending in '09 | Business Tech - CNET News</a><br/>
Second, security management will merge with log management. That works for ArcSight, RSA, LogLogic, and LogRhythm.</li>
<li><a href="http://darkmatterlabs.blogspot.com/2008/11/land-of-confusion.html">Dark Matters: Land of Confusion</a></li>
<li><a href="http://www.internetnews.com/software/article.php/3786036/Enterprise+SaaS+Buyers+Want+More+Than+Uptime.htm">InternetNews Realtime IT News - Enterprise SaaS Buyers Want More Than Uptime</a></li>
<li><a href="http://www.socaltech.com/high_tower_software_shuts_down/s-0018681.html">High Tower Software Shuts Down | socalTECH.com</a><br/>
Aliso Viejo-based High Tower Software, a venture-backed developer of security, compliance, and log management software, has shut down.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/465834955" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tower software shuts">tower software shuts</category>
      <category domain="http://securityratty.com/tag/log management software">log management software</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/tower software">tower software</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security management">security management</category>
      <category domain="http://securityratty.com/tag/larger enterprise base">larger enterprise base</category>
      <category domain="http://securityratty.com/tag/enterprise saas buyers">enterprise saas buyers</category>
      <category domain="http://securityratty.com/tag/cnet news">cnet news</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/465834955/anton18">Links for 2008-11-25 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[McColo takedown: Vigilantism or Neighborhood Watch?]]></title>
      <link>http://securityratty.com/article/2319b33f696f803e7cd1dd3252e9af8a</link>
      <guid>http://securityratty.com/article/2319b33f696f803e7cd1dd3252e9af8a</guid>
      <description><![CDATA[Few tears were shed when McColo Corp., a San Jose-based ISP that allegedly hosted companies known to be prolific purveyors of spam and other malware, was suddenly taken offline last Tuesday by its...]]></description>
      <content:encoded><![CDATA[Few tears were shed when McColo Corp., a San Jose-based ISP that allegedly hosted companies known to be prolific purveyors of spam and other malware, was suddenly taken offline last Tuesday by its upstream service providers.]]></content:encoded>
      <pubDate>Sun, 16 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/upstream service providers">upstream service providers</category>
      <category domain="http://securityratty.com/tag/mccolo corp">mccolo corp</category>
      <category domain="http://securityratty.com/tag/prolific purveyors">prolific purveyors</category>
      <category domain="http://securityratty.com/tag/san">san</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/tuesday">tuesday</category>
      <category domain="http://securityratty.com/tag/tears">tears</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <source url="http://www.networkworld.com/news/2008/111708-mccolo-takedown-vigilantism-or-neighborhood.html?fsrc=rss-security">McColo takedown: Vigilantism or Neighborhood Watch?</source>
    </item>
    <item>
      <title><![CDATA[Days numbered for standalone NAC, anti-data leakage firms? ]]></title>
      <link>http://securityratty.com/article/5aabe77fead5f69ba856f5065096d694</link>
      <guid>http://securityratty.com/article/5aabe77fead5f69ba856f5065096d694</guid>
      <description><![CDATA[Bargain hunting was all the talk of the 451 Group event this week in Boston, where one security pro quipped that vendors should be paying customers to install their software and where anyone remotely...]]></description>
      <content:encoded><![CDATA[Bargain hunting was all the talk of the 451 Group event this week in Boston, where one security pro quipped that vendors should be paying customers to install their software and where anyone remotely smelling of money became suddenly quite popular with other attendees looking to sell things.]]></content:encoded>
      <pubDate>Tue, 11 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security pro">security pro</category>
      <category domain="http://securityratty.com/tag/boston">boston</category>
      <category domain="http://securityratty.com/tag/bargain">bargain</category>
      <category domain="http://securityratty.com/tag/attendees">attendees</category>
      <category domain="http://securityratty.com/tag/popular">popular</category>
      <category domain="http://securityratty.com/tag/install">install</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <category domain="http://securityratty.com/tag/vendors">vendors</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <source url="http://www.networkworld.com/news/2008/111208-security-wireless-green-451-group.html?fsrc=rss-security">Days numbered for standalone NAC, anti-data leakage firms? </source>
    </item>
    <item>
      <title><![CDATA[Making Security Vendor Review a Continuous Process]]></title>
      <link>http://securityratty.com/article/6de26c721a867fd9ada1e45cdcc9fc8f</link>
      <guid>http://securityratty.com/article/6de26c721a867fd9ada1e45cdcc9fc8f</guid>
      <description><![CDATA[The IT security market is moving faster than almost any area of technology. The churn of new companies popping up and existing companies getting acquired or disappearing can be seen by comparing a...]]></description>
      <content:encoded><![CDATA[The IT security market is moving faster than almost any area of technology. The churn of new companies popping up and existing companies getting acquired or disappearing can be seen by comparing a Magic Quadrant with the previous year's version. The ever-changing threat is the major driver for this hyperactivity.<br />
<br />
Every security professional needs a list of the vendors used, including open-source projects. Don't just do due diligence with new vendors. Do a vendor check when you are renewing support or upgrading a product, and ensure that you check the status of all your vendors at a regular frequency. Have any vendors been acquired? Are they suddenly cool? Having problems with product vulnerabilities? Talking to their other customers about end of life for a product before there's a formal announcement?<br />
<br />
We can help you with this - don't hesitate to call or e-mail us on the status of any IT security vendor before making a purchase or renewing a big-ticket support agreement. At a minimum, you may want to do this before your annual internal budget setting.]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 11:23:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security vendor">security vendor</category>
      <category domain="http://securityratty.com/tag/vendors">vendors</category>
      <category domain="http://securityratty.com/tag/big-ticket support agreement">big-ticket support agreement</category>
      <category domain="http://securityratty.com/tag/support">support</category>
      <category domain="http://securityratty.com/tag/product vulnerabilities">product vulnerabilities</category>
      <category domain="http://securityratty.com/tag/product">product</category>
      <category domain="http://securityratty.com/tag/annual internal budget">annual internal budget</category>
      <category domain="http://securityratty.com/tag/vendor check">vendor check</category>
      <category domain="http://securityratty.com/tag/check">check</category>
      <source url="http://blog.gartner.com/blog/security.php?x=0&amp;itemid=3965">Making Security Vendor Review a Continuous Process</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Wi-Fi Robot Attack; Silicon Valley Plan Proceeds]]></title>
      <link>http://securityratty.com/article/a73229a533aa9f53897566105f7e6501</link>
      <guid>http://securityratty.com/article/a73229a533aa9f53897566105f7e6501</guid>
      <description><![CDATA[The Spykee is a $300 Wi-Fi Skype robot: Lots of strange coolness here. I don't know how I missed hearing about this before, but apparently an actual customer got his hands on the thing and recorded a...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><strong><a href="http://www.robotsrule.com/html/spykee.php">The Spykee is a $300 Wi-Fi Skype robot:</a></strong> Lots of strange coolness here. I don't know how I missed hearing about this before, but apparently an actual customer got his hands on the thing and recorded a video. It's cute. You can access its video through control software or a remote Skype video connection. It's got a speaker and microphone, and can be used for VoIP calls. The control software allows it to move around, play sound effects, and produce music. Like the computer in Superman III (or a Roomba), it craves power, and knows to return to its charger.</p>

<p><img src="http://wifinetnews.com//images/2008/spykee_1.jpg" alt="spykee_1.jpg" border="0" width="200" height="200" /></p>

<p>The name reveals some of its creepy appeal: Spykee = Spy Camera. I suppose the nanny you're trying to make sure isn't shaking your baby might be freaked out when it suddenly starts emitting Star Wars music, or such like. Made by Meccano under the Erector brand, its control software is Mac and Windows compatible. </p>

<p>I, for one, welcome our new Spykee overlords--on 15-Oct-2008 when it starts to ship generally.</p>

<p><strong><a href="http://news.yahoo.com/s/ibd/20080924/bs_ibd_ibd/20080924tech01">Silicon Valley project finally gets underway:</a></strong> It's a still a pilot, small, with no promised outcome. And after all this time, a switch of partners, and new parameters, they've still mounted just 20 of 28 access points.</p>]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 17:13:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/control software">control software</category>
      <category domain="http://securityratty.com/tag/spykee">spykee</category>
      <category domain="http://securityratty.com/tag/spykee overlords">spykee overlords</category>
      <category domain="http://securityratty.com/tag/suddenly starts">suddenly starts</category>
      <category domain="http://securityratty.com/tag/wi-fi skype robot">wi-fi skype robot</category>
      <category domain="http://securityratty.com/tag/silicon valley project">silicon valley project</category>
      <category domain="http://securityratty.com/tag/star wars music">star wars music</category>
      <category domain="http://securityratty.com/tag/play sound effects">play sound effects</category>
      <category domain="http://securityratty.com/tag/starts">starts</category>
      <source url="http://wifinetnews.com/archives/008460.html">Wee-Fi: Wi-Fi Robot Attack; Silicon Valley Plan Proceeds</source>
    </item>
    <item>
      <title><![CDATA[One Mans Frustrations With Risk Management]]></title>
      <link>http://securityratty.com/article/35f7d9bc833b43ad15689be67c2bbe31</link>
      <guid>http://securityratty.com/article/35f7d9bc833b43ad15689be67c2bbe31</guid>
      <description><![CDATA[Chris, who is a male in Government C&amp;A has a blog with a wonderful title: How is that Assurance Evidence
Id love to have another blog even more specific - Ok, that Assurance is Evidence Of What,...]]></description>
      <content:encoded><![CDATA[<p>Chris, who is a male in Government C&amp;A has a blog with a wonderful title:<a href="http://howisthatassuranceevidence.blogspot.com/"> How is that Assurance Evidence? </a></p>
<p>I&#8217;d love to have another blog even more specific - &#8220;Ok, that Assurance is Evidence <em><strong>Of What, Exactly</strong></em>?</p>
<p>Today he has a great article called:</p>
<p><a name="2599135121032652210"></a></p>
<h2 class="title"><a href="http://howisthatassuranceevidence.blogspot.com/2008/09/whats-matter-with-risk-management.html">What&#8217;s the matter with Risk Management?</a></h2>
<p><em>And &#8220;in short, it&#8217;s everything.&#8221;</em> It pretty much sums up why I had to grow to re-evaluate how our industry does risk, risk management, approaches controls &amp; vulnerability and find a new way.   A couple of things jump out at me in reading Chris&#8217; article:</p>
<p><strong>1.)  Just because that Deming cycle sucks and is full of unknowns doesn&#8217;t mean &#8220;risk&#8221; doesn&#8217;t exist, nor that it isn&#8217;t of primary importance.</strong> Nor does it mean that in the absence of model &amp; methodology, we won&#8217;t be &#8220;doing&#8221; risk analysis anyway - just in an ad hoc method and completely from &#8220;the gut&#8221;.</p>
<p>Our industry calls these unstructured risk analysis &#8220;Best Practices&#8221;, as it&#8217;s an easy and convenient way of sweeping the unknowns under the rug of bureaucracy and enforcing it via peer pressure.</p>
<p><strong>2.)  What this &#8220;suckiness&#8221; does mean is that your model and methodology aren&#8217;t helping you.</strong> As Chris intimates, there is too much uncertainty in the inputs for his model (they are, in the language of Bayesians - too subjective to be useful priors).</p>
<p>Take for example how we might be approaching the &#8220;controls&#8221; part of our analysis.  Chris writes:</p>
<blockquote><p><em>&#8220;2.  What are the controls that we have to employ?<br />
800-53, ISO 27001, PCI, etc.</em></p>
<p><em>Still kinda good, but we basically know that ISO is relatively voluntary and NIST supplies a control catalog and not policies. So here we have to take the control catalog, and mash our policies into it.&#8221;</em></p></blockquote>
<p>I wouldn&#8217;t call this &#8220;kinda good&#8221; at all :)  These control catalogs only provide a hierarchy within which to look for evidence of  our ability to resist an attacker.  They are incapable of making any claim about the effectiveness of the controls when they are operated at 100% efficiency, or more importantly, what % efficiency our specific organization operates at.</p>
<p>Let&#8217;s use <a href="http://risktical.com/initech-inc/">Chris Hayes&#8217; Initech as our fictional example</a>.</p>
<p>Initech has a control (a back door on a loading dock).  Now the locks on the door are 100% capable of locking the door.  This is different than saying that they are capable of frustrating all but the top 5% of lockpicking burgalars.  It is also diffferent than saying that in a sample of several &#8220;walk around audits&#8221; the doors are left open 20% of the time (they are not in compliance with policy 100% of the time).  Even worse, that 80% of the time the door is not propped open?  Yeah, tailgating is a known issue.</p>
<p>So we have several different variables here that we need to account for (and it&#8217;s just a door).  But the analogy stands that most &#8220;risk management&#8221; methodologies are &#8220;We have a door, yes/no?&#8221; And most GRC platforms, when asked for their &#8220;opinion&#8221; will simply say &#8220;door is needed&#8221; or, even worse, &#8220;a door policy is needed&#8221;.</p>
<p><strong>3.)  Criticality and the Source of Value is all messed up in these Risk Management models.<br />
</strong></p>
<p>Chris writes:</p>
<blockquote><p><em>Someone wants me to tell them which boxes are more critical than others. This is mainly because of budgetary or operational reasons. To which I usually say &#8220;All of them, it is a system after all&#8221;.</em></p></blockquote>
<p>This literally made me laugh out loud.  And <strong><a href="http://riskmanagementinsight.com/riskanalysis/?p=383">this sort of &#8220;rate the firewall as Risk = 500 but rate the actual business application as Risk = 157&#8243; thing is</a></strong> also endemic.  Now Chris is very smart here.  He correctly identifies that the value is tied to the business process the systems support, and not to a specific box.  Oh, we scan at the specific box level - but because of the nature of systemic failures - all the boxes in the process are inexorably interrelated.</p>
<p>One of the reasons I really like FAIR is that the losses are quantified (or qualified) based not on some amorphous value of the box or the process itself, but<strong> losses are linked to the actions that the threat will take. </strong> Take systems in a highly regulated industries as an example.  Usually the most probable losses aren&#8217;t due to system compromise per se, but in the disclosure the compromise causes (regulators are a threat source, after all).  But many &#8220;risk management&#8221; methodologies will say &#8220;online banking is worth $2 billion, the value of the systems is therefore $2 billion&#8221;.  And suddenly we&#8217;re telling executive management that there&#8217;s a 60% probability that they&#8217;ll lose $2 billion.</p>
<p><strong>4.)  If the primary source of prior information for your &#8220;risk management&#8221; methodology is a vulnerability scanner</strong> - <em><strong>you&#8217;re doing it wrong</strong></em>.  Chris writes:</p>
<blockquote><p><em>So we ran a scan and now we have a report. A snapshot in time to make all decisions. Where did these vulnerability ratings come from? Do I even know if my system is at risk? What if I spend my time on vulnerabilities that have no threat?</em></p></blockquote>
<p>So first, my thoughts are that actual &#8220;vulnerability&#8221; must be a comparison of the force a threat can apply, and our ability to resist that force (this is a probability statement, btw).</p>
<p>Changing your thinking about vulnerability now helps us understand the problem in several new ways.  First, you can start to divorce yourself from the scanner.  After all, the scanner is simply providing you with current state information that is usually just relevant variance from policy. It doesn&#8217;t really tell you about real &#8220;weakness in a system&#8221; because the system is an interrelated mess of people, processes and IT assets.</p>
<p><strong>5.)  Finally, most &#8220;risk management&#8221; approaches just *don&#8217;t* do a good job of helping us understand the how&#8217;s and why&#8217;s of <em>managing</em> <em>risk</em>.</strong> In the past, I&#8217;ve referred to these standards as really being &#8220;issue management&#8221; because they are at their heart, an act of discovery - a formal process around gathering prior information.  They are not, in and of themselves, capable of linking the issues discovered to the root cause.  And these root causes?  Yeah, they&#8217;re the things that create &#8220;risk&#8221;.  Not a threat, not a vulnerability, not the existence of an asset - the amount of risk that we have stems from our capability to manage it.</p>
<p>So Chris, I completely agree - but I wouldn&#8217;t give up yet.  There actually are a few of us who are focused on what you suggest:</p>
<blockquote><p>Where to go from here: A fundamental revamp of how to deal with Risk. Where risk professionals focus on the treating the sickness and not the symptoms, and come up with some new success/actionable metrics.</p></blockquote>
<p>Chris, there&#8217;s nothing I want to do more than that.</p>
]]></content:encoded>
      <pubDate>Tue, 23 Sep 2008 14:05:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management methodologies">risk management methodologies</category>
      <category domain="http://securityratty.com/tag/risk management approaches">risk management approaches</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management methodology">risk management methodology</category>
      <category domain="http://securityratty.com/tag/risk management models">risk management models</category>
      <category domain="http://securityratty.com/tag/risk professionals focus">risk professionals focus</category>
      <category domain="http://securityratty.com/tag/risk analysis">risk analysis</category>
      <category domain="http://securityratty.com/tag/specific">specific</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=447">One Mans Frustrations With Risk Management</source>
    </item>
    <item>
      <title><![CDATA[Interop NY: IT Roundtable]]></title>
      <link>http://securityratty.com/article/4137ad5ff76308605c9861b27c7d0404</link>
      <guid>http://securityratty.com/article/4137ad5ff76308605c9861b27c7d0404</guid>
      <description><![CDATA[This session is a bit different than the usual sessions at Interop. It provides insights from three CIOs in three different industries
Moderator: Jim Metzler, Vice President, Ashton, Metzler &amp;...]]></description>
      <content:encoded><![CDATA[<p>This session is a bit different than the usual sessions at Interop. It provides insights from three CIOs in three different industries.</p>
<ul>
<li>Moderator: Jim Metzler, Vice President, Ashton, Metzler &amp; Associates</li>
<li>Rowan Snyder, CIO, KPMG</li>
<li>David Michael, CIO, United Business Media Group</li>
<li>Joanna Young, Chief Information Officer, Corporate Information Systems &amp; Enterprise Services, Liberty Mutual</li>
</ul>
<p><strong>Jim: Is the CIO a technical job anymore? For example, inside Liberty there are business projects with an IT component.</strong></p>
<p><strong>Joanna:</strong> We are organized to partner with internal business clients or vendors who provide objectives and business requirements. We strive to figure out the smallest amount of an IT investment we can make to get this to work.</p>
<p><strong>Rowan:</strong> We have both. Part of the dilemma is that the thing that sells the best is fear. I don&#8217;t want to use that to get business.</p>
<p><strong>Joanna:</strong> One good example is security from an application perspective. It&#8217;s hard to talk about security investments in business terms. We put it into terms like &#8220;this is what it will cost us if we DON&#8217;T do this.&#8221; For example, a solution for spam required us to do research into what it was costing us overall. Once we put it together, the business was all for it. You have to put your business hat on and think &#8220;how can I make this important for a businessperson?&#8221; If you can&#8217;t, you may need to ask yourself why you&#8217;re pushing services on them that they may not need.</p>
<p><strong>Jim: Can you give us insight into business-IT alignment? What about governance?</strong></p>
<p><strong>Rowan:</strong> Governance is the hardest part of IT. It&#8217;s not like the technology is easy. If it&#8217;s a business project with an IT component, I don&#8217;t usually get involved. It comes down to overall budget. The infrastructure we own and let people know exactly what it will cost to do it. We are a distributed IT firm, there are multiple groups. This is the most distributed and risk-prone organization I&#8217;ve worked in. It can be difficult for the business to exert control. It demonstrates risk, in security, compliance, methodologies, etc.</p>
<p><strong>Joanna:</strong> Governance has become a word that nobody wants to use. It suddenly implies that IT is the holder of all the money and they are the ones that get to decide. We stopped using that word and position IT as a strategic business partner.</p>
<p><strong>David:</strong> We have a highly decentralized IT set-up. We have about 600 globally and around 40 in the headquarters. We have 10 CIOs for each division, and within each division it is decentralized. We try to run each unit as autonomous. This is a close alignment with IT and business. However, then the problem of how do you have commonality between divisions and collaboration?</p>
<p><strong>Jim: How can you minimize risk in distributed environment using standards and procedures?</strong></p>
<p><strong>David:</strong> The reality is it can be impractical for an organization. You end up with a patchwork of platforms and technologies. We have to accept that we&#8217;ll have multiple solutions. We can attempt to push a standard, but overall have a much more relaxed approach to manage everything. There is a lot of equality between divisions in what they can choose to purchase.</p>
<p><strong>Joanna:</strong> Standards are easier to apply the further down the staff you are. The most important thing with any of this is to understand why you are making the decisions. If there is a process and pros and cons are identified, there is a clear record of why decisions were made.</p>
<p><strong>Audience Poll: Everyone raised their hand that MORE standards were needed</strong>.</p>
<p><strong>Audience Question: Are there inefficiencies in the data center in terms of energy and green IT? What are you doing about it?</strong></p>
<p><strong>Joanna:</strong> Everyone focuses on cars for carbon footprints. But, it&#8217;s really buildings&#8230;and then data centers. The data center has the same importance as any other efficiency. They need to be running as cheaply as possible. Corporations have a responsibility to make sure they are energy efficient.</p>
<p><strong>Rowan:</strong> We recently did a carbon footprint analysis, and found that half of carbon comes from electricity, with half of that from the data center.</p>
<p><strong>David:</strong> Every company does have a responsibility to look at its carbon emission globally. Consider international travel, flying, etc. As much as possible, we are not building data centers. We are using other people&#8217;s data centers in an effort to get out of the data center business.</p>
<p><strong>Audience Question: How do you balance the good from standards with agile development and possible roadblocks?</strong></p>
<p><strong>Joanna:</strong> Luckily agile development is under the CIO&#8217;s control. You can see the lifecycle and savings that occur. When I look, I check what the standards are that I&#8217;m measuring by.</p>
<p><strong>Jim: Does web 2.0 have any business meaning in your environment? If so, what are you doing about it?</strong></p>
<p><strong>Joanna:</strong> I&#8217;ve been in IT for 20 years. It&#8217;s another component to business IT investment, and has to be presented as such. As IT professionals we have a responsibility to identify what Web 2.0 is, and then translate to see if there is anything the company should be doing with it. Monitor it based on your current portfolio, and consider its impact.</p>
<p><strong>David:</strong> It&#8217;s pretty important to our business as a media company. I don&#8217;t think it means one thing, it&#8217;s a term people use to talk about the web and what&#8217;s going on online. From mobile, to ajax, cloud computing or mashups - you can draw multiple conclusions. More and more business is being done online. We have a lot of growth opportunities online.</p>
<p><strong>Rowan:</strong> Compliance, security, and privacy issues just explode with Web 2.0.</p>
]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 15:45:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/terms">terms</category>
      <category domain="http://securityratty.com/tag/data center business">data center business</category>
      <category domain="http://securityratty.com/tag/data center">data center</category>
      <category domain="http://securityratty.com/tag/business terms">business terms</category>
      <category domain="http://securityratty.com/tag/business projects">business projects</category>
      <category domain="http://securityratty.com/tag/business-it alignment">business-it alignment</category>
      <category domain="http://securityratty.com/tag/internal business clients">internal business clients</category>
      <category domain="http://securityratty.com/tag/business hat">business hat</category>
      <source url="http://blog.sciencelogic.com/interop-ny-it-roundtable/09/2008">Interop NY: IT Roundtable</source>
    </item>
    <item>
      <title><![CDATA[Zune Owners Get Free Wi-Fi at McDonald's]]></title>
      <link>http://securityratty.com/article/2afb17aca42cecdef0eb17c5e5e72ced</link>
      <guid>http://securityratty.com/article/2afb17aca42cecdef0eb17c5e5e72ced</guid>
      <description><![CDATA[Microsoft signs three-year deal with Wayport for old and new Zune owners alike: This is a nice win for Zune users, Wayport, and McDonald's, each in their own way, and it's something Microsoft can...]]></description>
      <content:encoded><![CDATA[<p><strong>Microsoft signs three-year deal with Wayport for old and new Zune owners alike:</strong> This is a nice win for Zune users, Wayport, and McDonald's, each in their own way, and it's something Microsoft can simply write off as useful marketing--and a way to get people to try the latest models of their music player, which are being released on 16-September.</p>

<p>The Zune doesn't include a Web browser or any Internet focused features; it's not an iPod touch. But you can use Wi-Fi to browse the Zune Marketplace for music and games, and download new songs in programmed channels, music selections created by a variety of artists and stations. Zune offers both music purchases and a subscription for unlimited music listening. The new models range from $149 for an 8 GB flash model to $249 for a 120 GB hard drive-based player.</p>

<p>The feature I'm most interested in is Buy from FM, which leverages the built-in FM tuner and very low-bandwidth data that's already pushed over analog AM/FM. (See <strong><a href="http://wifinetnews.com/archives/008432.html">my write-up of this feature</a></strong> from last week.) With Buy from FM, when you're listening to radio stations that participate, you'll be able to click a button and buy the song you're listening to if you're connected to a Wi-Fi network. Zune Pass subscribers can download the song at no additional charge. If there's no Wi-Fi network, the song download or purchase is queued.</p>

<p><img src="http://wifinetnews.com//images/2008/new_zune.jpg" alt="new_zune.jpg" border="0" width="137" height="256" align="right" />Wayport's marketing head Dan Lowden said, "Obviously, it's cool because folks who already own a Zune device and just need to do an upgrade will be able to use this just as with any of the new Zune devices that they start selling as soon as possible." (Microsoft may have a little accounting work to do: Sarbanes-Oxley doesn't let you enhance a product in the market without a fee if you realize the revenue all at once.)</p>

<p>The benefit for Wayport is to have yet another hefty but undisclosed fixed sum underlying its fixed infrastructure costs. In the past, Wayport has done deals with Nintendo, ZipIt, and Eye-Fi to allow all devices in a category unlimited access at McDonald's locations. McDonald's obviously gets more customers, or existing customers who spend more time or visit more frequently.</p>

<p>A partnership with a hotspot operator means that Microsoft doesn't have to provide tools and their users endure frustration in joining a network. "We're experts enabling one click to get this network connected," Lowden said. He noted that Wayport has opened test labs to work with manufacturers in Japan, San Francisco, San Diego, and Seattle. "We're working with these guys from day 1 to make sure it's one click to get connected," he said. I'd also note that San Diego happens to be where Qualcomm's headquarters are located, not that Lowden gave me any tip-off there. </p>

<p>And I have to just say: burn, burn, burn on Apple. Despite Apple partnership with AT&T, which relies on Wayport to operate the AT&T-branded hotspot network and resells access to Wayport's own network, iPhone and iPod touch users have no inclusive Wi-Fi service. AT&T slipped a few times and ostensibly opened up their network or released details that iPhone users would gain free hotspot access--like all AT&T's fiber and all its standard and premium DSL customers. </p>

<p>As Wi-Fi becomes an expected part of any handheld gadget, the venues in which Wi-Fi is used multiply beyond cafes and hotels. Lifestyle locations--which could be clothing stores, nightclubs, ski resorts, and the tops of mountains suddenly become places where people want the same kind of access they have at home. Ultima thule is already unwired.</p>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 23:01:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/zune">zune</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/zune pass subscribers">zune pass subscribers</category>
      <category domain="http://securityratty.com/tag/inclusive wi-fi service">inclusive wi-fi service</category>
      <category domain="http://securityratty.com/tag/zune offers">zune offers</category>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/zune devices">zune devices</category>
      <category domain="http://securityratty.com/tag/wi-fi network">wi-fi network</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <source url="http://wifinetnews.com/archives/008440.html">Zune Owners Get Free Wi-Fi at McDonald's</source>
    </item>
    <item>
      <title><![CDATA[A New Security Breach in Google Docs Revealed]]></title>
      <link>http://securityratty.com/article/caf2790afa2996d6a38ac70d10ec784a</link>
      <guid>http://securityratty.com/article/caf2790afa2996d6a38ac70d10ec784a</guid>
      <description><![CDATA[I am a big fan of Google and, over time, I have started to enjoy the freedom from my desktop with Google Docs . For example, when I keep track of business expenses I have found it easier to update a...]]></description>
      <content:encoded><![CDATA[<p>I am a big fan of Google and, over time, I have started to enjoy the freedom from my desktop with <a href="http://docs.google.com/">Google Docs</a>.  For example, when I keep track of business expenses I have found it easier to update a Google Spreadsheet versus depending on Microsoft Excel on my laptop because I can update from anywhere in the world and share with my bookkeeper too.     So, I&#8217;ve been using Google Docs more lately.</p>
<p>Today, however, I discovered a huge security breach in Google Docs.  While I was in my account working on a spreadsheet I suddenly found my Google Doc account listing many documents that did not belong to me.  I clicked on one of the documents and the results are in the image below, where my Google Doc session appears to have &#8220;crossed over&#8221; with another users.</p>
<p><img style="width: 474px; height: 443px;" src="http://www.thecepblog.com/imgs/google.docs.security.breach.jpg" alt="" /></p>
<p>I decided to do a bit more exploring and take a few more screenshots, because I don&#8217;t yet know how to reproduct this security breach.  The image below show a Google document (fifth from the top) which is not owned by me, &#8220;owned by me&#8221;. However, when I click on this mysterious &#8220;owned by me&#8221; document, it is owned by another user.  Here is another screenshot below; you can click on the image for the full-screen version.</p>
<p><a href="http://www.thecepblog.com/imgs/google.docs.security.breach2.jpg"><img style="width: 474px; height: 443px;" src="http://www.thecepblog.com/imgs/google.docs.security.breach2.jpg" alt="" /></a></p>
<p>Again, here is another example of the same security violation with two documents. As above, you can click on the image for a full-screen version.</p>
<p><a href="http://www.thecepblog.com/imgs/google.docs.security.breach4.jpg"><img style="width: 473px; height: 442px;" src="http://www.thecepblog.com/imgs/google.docs.security.breach4.jpg" alt="" /></a></p>
<p>I contacted the owner of the Google Docs account which I had suddenly and mysteriously &#8220;crossed sessions&#8221; with today.   I asked him if he was in Thailand (since a few of the documents were in Thai) and he said yes, however he say he did not have any Thai language documents in his account.    However, as you can see from the screenshot, the Google Docs menu shows this person as &#8220;the owner&#8221; of a Thai language document.  He also mentioned that, today, he saw &#8220;wierd documents&#8221; in his account that did not belong to him (or &#8220;normally&#8221; shared with him).</p>
<p>Unfortunately, I was having problems with the Internet connection in my hotel room so I could not continue to investigate the breach.  When I logged back in a few hours later, everything was back to normal.  So far, all is &#8220;normal&#8221; and I have not been able to repeat this breach.</p>
<p>I suspect the Google Docs flaw comes from a JavaScript error in how Google manages user sessions.  The bottom line is that the security breach is real and dangerous.  Your Google Docs, and I suspect other Google applications that use the same session management code, are vulnerable.  There may be an underlying XSS vulnerability as well.</p>
<p>Note: Reposted from my original post on the <a href="http://blog.isc2.org/isc2_blog/2008/09/serious-securit.html" target="_blank">ISC2 blog</a>.</p>
]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 07:59:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google docs">google docs</category>
      <category domain="http://securityratty.com/tag/google docs menu">google docs menu</category>
      <category domain="http://securityratty.com/tag/google docs flaw">google docs flaw</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/google docs account">google docs account</category>
      <category domain="http://securityratty.com/tag/security breach">security breach</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/thai language documents">thai language documents</category>
      <source url="http://www.thecepblog.com/2008/09/15/a-new-security-breach-in-google-docs-revealed/">A New Security Breach in Google Docs Revealed</source>
    </item>
    <item>
      <title><![CDATA[Security ROI]]></title>
      <link>http://securityratty.com/article/22a56a0fbf977e9d5e4cffb543ff0d74</link>
      <guid>http://securityratty.com/article/22a56a0fbf977e9d5e4cffb543ff0d74</guid>
      <description><![CDATA[Return on investment, or ROI, is a big deal in business. Any business venture needs to demonstrate a positive return on investment, and a good one at that, in order to be viable
It's become a big deal...]]></description>
      <content:encoded><![CDATA[<p>Return on investment, or ROI, is a big deal in business. Any business venture needs to demonstrate a positive return on investment, and a good one at that, in order to be viable.</p>

<p>It's become a <a href="http://www.csoonline.com/article/print/217727">big</a> <a href="http://www.computerworld.com/securitytopics/security/story/0,10801,83207,00.html?nas=ROI-83207">deal</a> in IT security, too. Many corporate customers are demanding ROI models to demonstrate that a particular security investment pays off. And in response, vendors are providing ROI models that demonstrate how their particular security solution provides the best return on investment.</p>

<p>It's a <a href="http://communities.intel.com/openport/blogs/it/2008/08/25/are-security-roi-figures-meaningless">good</a> <a href="http://communities.intel.com/openport/blogs/it/2007/08/14/the-problem-of-measuring-information-security">idea</a> in <a href="https://buildsecurityin.us-cert.gov/daisy/bsi/articles/knowledge/business/677-BSI.html">theory</a>, <a href="http://taosecurity.blogspot.com/2007/07/are-questions-sound.html">but</a> <a href="http://www.bloginfosec.com/2007/07/13/bejtlich-and-business-will-it-blend/">it's</a> <a href="http://blog.vorant.com/2007/07/my-input-to-roi-spat.html">mostly</a> <a href="http://taosecurity.blogspot.com/2007/07/no-roi-no-problem.html">bunk</a> <a href="http://chuvakin.blogspot.com/2007/07/security-roi-pile-up.html">in</a> <a href="http://taosecurity.blogspot.com/2007/07/security-roi-revisited.html">practice</a>.</p>

<p>Before I get into the details, there's one point I have to make. "ROI" as used in a security context is inaccurate. Security is not an investment that provides a return, like a new factory or a financial instrument. It's an expense that, hopefully, pays for itself in cost savings. Security is about loss prevention, not about earnings. The term just doesn't make sense in this context.</p>

<p>But as anyone who has lived through a company's vicious end-of-year budget-slashing exercises knows, when you're trying to make your numbers, cutting costs is the same as increasing revenues. So while security can't produce ROI, loss prevention most certainly affects a company's bottom line.</p>

<p>And a company should implement only security countermeasures that affect its bottom line positively. It shouldn't spend more on a security problem than the problem is worth. Conversely, it shouldn't ignore problems that are costing it money when there are cheaper mitigation alternatives. A smart company needs to approach security as it would any other business decision: costs versus benefits.</p>

<p>The classic methodology is called annualized loss expectancy (ALE), and it's straightforward. Calculate the cost of a security incident in both tangibles like time and money, and intangibles like reputation and competitive advantage. Multiply that by the chance the incident will occur in a year. That tells you how much you should spend to mitigate the risk. So, for example, if your store has a 10 percent chance of getting robbed and the cost of being robbed is $10,000, then you should spend $1,000 a year on security. Spend more than that, and you're wasting money. Spend less than that, and you're also wasting money.</p>

<p>Of course, that $1,000 has to reduce the chance of being robbed to zero in order to be cost-effective. If a security measure cuts the chance of robbery by 40 percent -- to 6 percent a year -- then you should spend no more than $400 on it. If another security measure reduces it by 80 percent, it's worth $800. And if two security measures both reduce the chance of being robbed by 50 percent and one costs $300 and the other $700, the first one is worth it and the second isn't.</p>

<p>The Data Imperative</p>

<p>The key to making this work is good data; the term of art is "actuarial tail." If you're doing an ALE analysis of a security camera at a convenience store, you need to know the crime rate in the store's neighborhood and maybe have some idea of how much cameras improve the odds of convincing criminals to rob another store instead. You need to know how much a robbery costs: in merchandise, in time and annoyance, in lost sales due to spooked patrons, in employee morale. You need to know how much not having the cameras costs in terms of employee morale; maybe you're having trouble hiring salespeople to work the night shift. With all that data, you can figure out if the cost of the camera is cheaper than the loss of revenue if you close the store at night -- assuming that the closed store won't get robbed as well. And then you can decide whether to install one.</p>

<p>Cybersecurity is considerably harder, because there just isn't enough good data. There aren't good crime rates for cyberspace, and we have a lot less data about how individual security countermeasures -- or specific configurations of countermeasures -- mitigate those risks. We don't even have data on incident costs.</p>

<p>One problem is that the threat moves too quickly. The characteristics of the things we're trying to prevent change so quickly that we can't accumulate data fast enough. By the time we get some data, there's a new threat model for which we don't have enough data. So we can't create ALE models.</p>

<p>But there's another problem, and it's that the math quickly falls apart when it comes to rare and expensive events. Imagine you calculate the cost -- reputational costs, loss of customers, etc. -- of having your company's name in the newspaper after an embarrassing cybersecurity event to be $20 million. Also assume that the odds are 1 in 10,000 of that happening in any one year. ALE says you should spend no more than $2,000 mitigating that risk.</p>

<p>So far, so good. But maybe your CFO thinks an incident would cost only $10 million. You can't argue, since we're just estimating. But he just cut your security budget in half. A vendor trying to sell you a product finds a Web analysis claiming that the odds of this happening are actually 1 in 1,000. Accept this new number, and suddenly a product costing 10 times as much is still a good investment.</p>

<p>It gets worse when you deal with even more rare and expensive events. Imagine you're in charge of terrorism mitigation at a chlorine plant. What's the cost to your company, in money and reputation, of a large and very deadly explosion? $100 million? $1 billion? $10 billion? And the odds: 1 in a hundred thousand, 1 in a million, 1 in 10 million? Depending on how you answer those two questions -- and any answer is really just a guess -- you can justify spending anywhere from $10 to $100,000 annually to mitigate that risk.</p>

<p>Or take another example: airport security. Assume that all the new airport security measures increase the waiting time at airports by -- and I'm making this up -- 30 minutes per passenger. There were 760 million passenger boardings in the United States in 2007. This means that the extra waiting time at airports has cost us a collective 43,000 years of extra waiting time. Assume a 70-year life expectancy, and the increased waiting time has "killed" 620 people per year -- 930 if you calculate the numbers based on 16 hours of awake time per day. So the question is: If we did away with increased airport security, would the result be more people dead from terrorism or fewer?</p>

<p>Caveat Emptor</p>

<p>This kind of thing is why most ROI models you get from security vendors are <a href="http://www.postini.com/services/roi_calculator.html">nonsense</a>. Of course their model demonstrates that their product or service makes financial sense: They've jiggered the numbers so that they do.</p>

<p>This doesn't mean that ALE is useless, but it does mean you should 1) mistrust any analyses that come from people with an agenda and 2) use any results as a general guideline only. So when you get an ROI model from your vendor, take its framework and plug in your own numbers. Don't even show the vendor your improvements; it won't consider any changes that make its product or service less cost-effective to be an "improvement." And use those results as a general guide, along with risk management and compliance analyses, when you're deciding what security products and services to buy.</p>

<p>This essay <a href="http://www.csoonline.com/article/446866/Security_ROI_Fact_or_Fiction_">previously appeared</a> in <i>CSO Magazine</i>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Ql60WL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Ql60WL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=npHViL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=npHViL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 02:05:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security countermeasures">security countermeasures</category>
      <category domain="http://securityratty.com/tag/countermeasures">countermeasures</category>
      <category domain="http://securityratty.com/tag/incident">incident</category>
      <category domain="http://securityratty.com/tag/security incident">security incident</category>
      <category domain="http://securityratty.com/tag/individual security countermeasures">individual security countermeasures</category>
      <category domain="http://securityratty.com/tag/security measure cuts">security measure cuts</category>
      <category domain="http://securityratty.com/tag/security measure reduces">security measure reduces</category>
      <category domain="http://securityratty.com/tag/security vendors">security vendors</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/security_roi_1.html">Security ROI</source>
    </item>
  </channel>
</rss>
