<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Blog Posts From Open Port IT Community Tagged With intel</title>
    <link>http://communities.intel.com/community/openportit/blog</link>
    <description>General Community Blog</description>
    <pubDate>Wed, 15 May 2013 19:49:16 GMT</pubDate>
    <generator>Jive SBS 5.0.2.0  (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2013-05-15T19:49:16Z</dc:date>
    <item>
      <title>Our New PC Delivery Process Cuts Employee Downtime</title>
      <link>http://communities.intel.com/community/openportit/blog/2013/05/15/our-new-pc-delivery-process-cuts-employee-downtime</link>
      <description>&lt;!-- [DocumentBodyStart:cab28d11-3eb0-4153-aa4d-634f663899b6] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;table align="left" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&lt;span style="color: #000000; font-size: 12pt;"&gt;Getting a new PC used to take valuable time out of the workday.&amp;nbsp;&amp;nbsp; But as part of our focus on a user-centered model of delivering IT services, Intel IT recently optimized our PC delivery process, resulting in improved employee productivity, a better employee experience, and reduced operational costs.&amp;nbsp; These process improvements allow our employees to return to work more quickly, reducing their downtime from an average of 4.5 hours to 1 hour, a 77-percent reduction. Read the paper &lt;span style="font-family: arial,helvetica,sans-serif;"&gt;"&lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/it-management/intel-it-best-practices/new-pc-delivery-process-cuts-employee-downtime-white-paper.html" target="_blank"&gt;New PC Delivery Process Cuts Employee Downtime&lt;/a&gt;" to learn about the changes we made.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:cab28d11-3eb0-4153-aa4d-634f663899b6] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it@intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it_business_value</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel_it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">pc_refresh</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it_best_practices</category>
      <pubDate>Wed, 15 May 2013 19:49:16 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2013/05/15/our-new-pc-delivery-process-cuts-employee-downtime</guid>
      <dc:date>2013-05-15T19:49:16Z</dc:date>
      <clearspace:dateToText>1 week, 1 hour ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/our-new-pc-delivery-process-cuts-employee-downtime</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15846</wfw:commentRss>
    </item>
    <item>
      <title>Enterprises Security Choices and Tradeoffs for BYOD</title>
      <link>http://communities.intel.com/community/openportit/blog/2013/05/13/enterprises-security-choices-and-tradeoffs-for-byod</link>
      <description>&lt;!-- [DocumentBodyStart:69711d27-2434-4fd7-b0cf-3fc8d8acfa47] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Bring Your Own Devices (BYOD) continues to gain momentum as users bring devices into work environments by the droves.&amp;nbsp; Enterprises must make tricky security decisions to balance the tradeoffs of costs, user productivity, and security.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;BYOD is effecting organizations both large and small.&amp;nbsp; In our highly connected world, workers bring in familiar and favored smartphones, tablets, and other compute devices into work and expect to leverage them for convenience and to improve productivity.&amp;nbsp; It can have a great positive effect on the business but also raises security concerns.&amp;nbsp; Management can&amp;#8217;t hide from taking a position, establishing boundaries, and understanding the tradeoffs.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15843-232295/Enterprise+Factors.jpg"&gt;&lt;img alt="Enterprise Factors.jpg" class="jive-image" height="169" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15843-232295/214-169/Enterprise+Factors.jpg" style="float: right;" width="214"/&gt;&lt;/a&gt;In today&amp;#8217;s responsible corporate environment, enterprises realize the danger of uncontrolled devices on their network and accessing business data.&amp;nbsp; It introduces chaos to security and IT manageability, driving up risks and expenses.&amp;nbsp; Organizations want to enable productivity of employees but must maintain a level of acceptable risks and keep costs flat, or at the very least justifiable.&amp;nbsp; It is a tough balancing act between risks, costs, and user productivity.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Management has a number of high level choices, each with pro/cons and other tradeoffs.&amp;nbsp; Before committing to a particular path, leaders must understand these options in order to select the best direction to set for their organization:&lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;&lt;strong&gt;1. No personal devices allowed&lt;/strong&gt;.&amp;nbsp; Forbid personal smartphones, tablets, and non-managed computers from accessing work systems, networks, and data.&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;&lt;strong style="color: #0000ff;"&gt;Pro:&lt;/strong&gt; This stratagem manages security risks and keeps costs relatively flat.&amp;nbsp; It has been the traditional solution.&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;&lt;strong style="color: #ff0000;"&gt;Con:&lt;/strong&gt; Not practical for 99.9% of the world.&amp;nbsp; It&amp;#8217;s like trying to hold back a tidal wave with a paper cup.&amp;nbsp; Workers, starting with the tech savvy, will bring in devices and connect them, soon to be followed by the rest of the staff.&amp;nbsp; Most likely they and the less technical community has already been doing this for some time.&amp;nbsp; It starts with email forwarding, access to work calendars, meeting logistics, file sharing, instant messaging, etc.&amp;nbsp; Implementing such a policy ignores the opportunity for significant worker productivity gains and stifles flexibility which is so desired by everyone.&amp;nbsp; When employees have convenient access to such data, they are more effective, efficient, and happy.&lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;&lt;strong&gt;2. Company provides mobile devices&lt;/strong&gt;.&amp;nbsp; Providing corporate managed devices in lieu of employees&amp;#8217; personal devices, allows vetting of systems before they access work networks and data.&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;&lt;span style="color: #0000ff;"&gt;&lt;strong&gt;Pro:&lt;/strong&gt;&lt;/span&gt; Security standards, selective deployment, and the ability to enforce controls, allows the organization to manage risks and costs.&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;&lt;strong style="color: #ff0000;"&gt;Con:&lt;/strong&gt; Upfront expenses are high, user happiness tends to be low, and manageability costs slowly creeps up over time.&amp;nbsp; The out-of-pocket equipment and service costs can be very expensive.&amp;nbsp; To control costs, most organizations will not provide everyone a company device.&amp;nbsp; So there emerges a &amp;#8220;have&amp;rdquo; and &amp;#8220;have-not&amp;#8217;s&amp;rdquo; class system which spawns resentment.&amp;nbsp; Those who are provided devices must manage their personal devices in addition to the company provided ones.&amp;nbsp; If you have ever been forced to carry two phones, you know how much of a pain this becomes.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;span style="color: #000000;"&gt;Even in a perfect environment with happy users, a different problem emerges.&amp;nbsp; The comingling of personal and private data on employer managed devices.&amp;nbsp; This can be a nightmare, fraught with legal and ethical pitfalls.&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;span style="color: #000000;"&gt;Each class, brand, and even model must be configured and secured.&amp;nbsp; IT departments must support users trying to access services and data.&amp;nbsp; The more types of devices, the more complex and expensive the support becomes.&amp;nbsp; One of the keys to managing support costs is scalability.&amp;nbsp; So, it is normal for an organization to settle on one or two to start.&amp;nbsp; Which will not make everyone happy as people have their own preferences.&amp;nbsp; Demand can grow to expand the list of supported configurations, especially as new options become available in the marketplace.&amp;nbsp; Expanded support is great for users, but a nightmare for IT as it increases the legacy support of older configurations which are still in use.&amp;nbsp; Over time the cost to support will steadily increase and the cost of refreshing old and damaged devices will be ever present.&lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;span style="color: #000000;"&gt;From a productivity perspective, users get an initial boost from the latest equipment and software, but will soon see a degradation as the organization cannot keep up with the latest features coming to market.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;br/&gt; &lt;br/&gt;&lt;span style="color: #000000;"&gt;&lt;strong&gt;3. BYOD of Any Device. &lt;/strong&gt; All devices welcome with open arms!&amp;nbsp; Users are able to bring in, connect, and use their favorite devices.&amp;nbsp; Security controls are usually network based or via containerization technology on the device itself.&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;&lt;strong style="color: #0000ff;"&gt;Pro:&lt;/strong&gt; Initial hardware costs are very low for the organization, as the user absorbs initial out-of-pocket costs for the device.&amp;nbsp; Productivity remains high, as users will continually install latest applications and refresh to current hardware as they see fit.&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;&lt;strong style="color: #ff0000;"&gt;Con:&lt;/strong&gt; Expensive to manage and secure.&amp;nbsp; Costs skyrocket to provide and maintain security controls and connectivity support over a wide swath of different devices and applications.&amp;nbsp; Security solutions, many with a high per-seat cost, is required. Not all devices are created or configured equally, adding to the cost and frustration of IT and security departments.&amp;nbsp; The expenses continue to increase and never plateau as users follow the non-stop march of evolving technology, applications, and shiny devices&lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;span style="color: #000000;"&gt;Challenges with co-mingling of users private data with enterprise oversight can still persist depending upon controls and access configurations&lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;span style="color: #000000;"&gt;&lt;strong&gt;4. BYOD of Certain Devices. &lt;/strong&gt; The middle ground, allowing users to front the initial costs and enterprises can focus on security and management of a much smaller subset of devices.&amp;nbsp; Network, cloud, and device containerization technology provide security.&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;&lt;strong style="color: #0000ff;"&gt;Pro:&lt;/strong&gt; Low initial costs as users purchase the devices.&amp;nbsp; It is a flexible model where the optimal balance of cost, productivity, and security can be adjusted as needed.&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;&lt;strong style="color: #ff0000;"&gt;Con:&lt;/strong&gt; Still costly, as the enterprise must invest in security solutions for allowed devices, but policy will limit the number of configurations and therefore help keep costs and risks more manageable.&amp;nbsp; As new devices are supported costs will rise due to legacy support and other complexities.&amp;nbsp; Security is managed based upon the vetting and controls mandated for approved configurations. &lt;/span&gt;&lt;br/&gt;&amp;nbsp;&amp;nbsp; &lt;br/&gt;&lt;span style="color: #000000;"&gt;Productivity varies based upon the breadth and timeliness of support for new technologies.&amp;nbsp; Satisfaction and productivity also follow this curve.&amp;nbsp; The more devices and applications supported in a timely manner, the happier and more productive the users, but the costs skyrocket accordingly.&lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;span style="color: #000000;"&gt;Sadly, the pesky problem of data comingling is still present.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;There is no universal winning choice.&amp;nbsp; It really depends on the organization, risk appetite, budget, worker productivity needs, and the sway of the most vocal users.&amp;nbsp; A very small number of organizations can disallow all personal devices, mostly government types.&amp;nbsp; Only companies willing to spend a tremendous amount of money on hardware or those which already have a strong caste systems to support a limited distribution will be interested in providing workers with such devices in addition to primary work PC&amp;#8217;s.&amp;nbsp; Organizations which have little need for confidentiality, integrity, and availability aspects of security might be able to live with openly connecting any BYOD their users may bring into the office.&amp;nbsp; Although a significant number of organizations may try to dabble in this area before realizing the rapidly growing support costs and security issues before changing to a different strategy.&amp;nbsp; In the end, I believe the majority of organizations will choose to embrace the last option of supporting only certain BYOD devices.&amp;nbsp; They will select a mix of devices, software, and controls which satisfy a broad community while keeping costs and risks predictable.&amp;nbsp; This is no small feat as these solutions are not yet mature.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Every organization must find their own path.&amp;nbsp; They must consider the options and tradeoffs of costs, productivity, and risk.&amp;nbsp; No perfect solution exists, but with forethought, collaboration with users, and solid execution, a manageable solution might be within grasp.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:69711d27-2434-4fd7-b0cf-3fc8d8acfa47] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it@intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">roi</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">value</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">rosi</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">model</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">risk</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">optimal_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew_rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">threat</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">strategy</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">enterprise_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">loss</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">consumerization</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">byod</category>
      <pubDate>Mon, 13 May 2013 19:34:26 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2013/05/13/enterprises-security-choices-and-tradeoffs-for-byod</guid>
      <dc:date>2013-05-13T19:34:26Z</dc:date>
      <clearspace:dateToText>1 week, 2 days ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/enterprises-security-choices-and-tradeoffs-for-byod</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15843</wfw:commentRss>
    </item>
    <item>
      <title>Information Security – it’s not only about the technical controls!</title>
      <link>http://communities.intel.com/community/openportit/blog/2013/04/11/information-security-it-s-not-only-about-the-technical-controls</link>
      <description>&lt;!-- [DocumentBodyStart:76f4a2d1-8c87-4099-8ee1-6c2cb6c67b19] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="font-size: 10pt;"&gt;Security means many different things in different contexts. With Information Security, it should be about protection of an asset from a known threat. But many times there are biases to security solutions based on controls that are predetermined. The most important questions that should be asked before the how part is defined for a security solution are; &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="font-size: 10pt;"&gt;Why is there a need to establish security? It&amp;#8217;s an important premise that you determine the value of information to your organization and to your adversaries.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: 10pt;"&gt;Secondly, who are you protecting this information from? If one is to protect something, one has to identify what the threats are, so as to take appropriate steps to mitigate them.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: 10pt;"&gt;Thirdly, protection or prevention is one aspect of security controls. Considere detective and corrective mitigating controls addition to preventative mechanisms that could fail. &lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt;"&gt;Because of biases in specialty areas, there could be a tendency to emphasize specific technical controls in defining a security solution. This leaves a great deal of ambiguity and more fuel for fear, uncertainty, and doubt that plagues the field of protecting computer information systems. And as Matthew Rosenquist described in one of his blog posts last year when asked for one word to describe the biggest challenge in information security these days, he used the word &lt;a class="jive-link-blog-small" data-containerId="1002" data-containerType="37" data-objectId="15117" data-objectType="38" href="http://communities.intel.com/community/openportit/blog/2012/03/26/one-word-to-describe-the-biggest-challenge-of-information-security"&gt;ambiguity&lt;/a&gt;. While many security researchers are trying to find the latest security flaw, other security professionals are trying to determine how the next security tools provide better technical protection capabilities. But it&amp;#8217;s important to realize that information security is not only about the technical solution, it should be a business decision first.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt;"&gt;Information Security is not only about technical threats and so technical security controls should not be the first consideration for protection. Technology is often among several other countermeasures used to implement a security solution after defining what it is that needs protecting and from whom it needs protection. This is where administrative controls should be considered first so that the definition of what needs to protect can be defined through procedural controls. Some industries have policies, standards and guidelines that must be followed based on the type (classification) of information, but risk should be evaluated based on threats in context of the environment for which the information made available through processes, transferred, stored, or destroyed. A defense-in-depth strategy should be considered during the earliest stages of the development lifecycle&amp;nbsp; but oftentimes there are changes to the environment that are made well after the deployment of a system or software solution that can introduce risk from new threats or greater exposure to existing ones. Before administrative controls are defined, a risk assessment should be completed to analyze the threats for which any system is vulnerable to. &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 10pt;"&gt;The real value of a risk assessment is that some systems may process information that is not under industry regulations for protection but still have value to an organization. In many cases an organization will focus on risk from audit failures and apply most of the security dollars to mitigate risks defined by audit report because information classification levels require regulatory protection such as Sarbanes-Oxley Act (SOX),&amp;nbsp; PCI Data Security Standard (DSS), or Health Insurance Portability and Accounting Act (HIPAA) just to name a few. But information of value does not only fall under classifications that have industry standards for protection levels. The risk assessment is a way to have dialog amongst the team and is helpful to communicate with management across the board for all information protection requirements becuase ultimately it is a business decision to implement security controls. Additionally,&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt; security controls can be protective but detective and corrective security controls should always be a consideration for a &lt;a class="jive-link-external-small" href="http://en.wikipedia.org/wiki/Defense_in_depth_(computing)" target="_blank"&gt;Defense-In-Depth&lt;/a&gt; security strategy. &lt;/span&gt;&lt;span style="font-size: 10pt;"&gt;One strategy that is taking a more reasonable approach to increasing the level of information assurance is the focus on the threat rather than the vulnerability through the use of a &lt;a class="jive-link-blog-small" data-containerId="1002" data-containerType="37" data-objectId="12982" data-objectType="38" href="http://communities.intel.com/community/openportit/blog/2010/01/05/whitepaper-prioritizing-information-security-risks-with-threat-agent-risk-assessment"&gt;Threat Agent Risk Assessment&lt;/a&gt; methodology developed by Intel. This approach places emphasis on what is reasonably possible from a threat perspective in order to address the most likely events. &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:76f4a2d1-8c87-4099-8ee1-6c2cb6c67b19] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it@intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">value</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it_business_value</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">model</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">risk</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">optimal_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">threat</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">plan</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel_it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attack</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">strategy</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">andy_good</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it_best_practices</category>
      <pubDate>Thu, 11 Apr 2013 20:49:41 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2013/04/11/information-security-it-s-not-only-about-the-technical-controls</guid>
      <dc:date>2013-04-11T20:49:41Z</dc:date>
      <clearspace:dateToText>1 month, 5 days ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/information-security-it-s-not-only-about-the-technical-controls</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15786</wfw:commentRss>
    </item>
    <item>
      <title>Security Does Not Need to be Complex to be Effective</title>
      <link>http://communities.intel.com/community/openportit/blog/2013/04/08/security-does-not-need-to-be-complex-to-be-effective</link>
      <description>&lt;!-- [DocumentBodyStart:f5eba56f-426b-4ecd-9bac-21712bae69ec] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Even a 10 year old little girl can &lt;a class="jive-link-external-small" href="http://toronto.ctvnews.ca/attempted-child-abduction-thwarted-when-girl-asks-stranger-for-code-word-1.1204634#ixzz2PtQoJlBy" target="_blank"&gt;prove this fact&lt;/a&gt;:&amp;nbsp; &lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15775-231898/Caution.jpg"&gt;&lt;img alt="Caution.jpg" class="jive-image" height="114" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15775-231898/143-114/Caution.jpg" style="float: right;" width="143"/&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;A 10-year-old girl thwarted an abduction attempt after asking a stranger for a code word that he did not know.&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;A man approached a 10 year old girl outside a public school and attempted to lure the girl into his vehicle.&amp;nbsp; The man told the girl her parents had sent him to pick her up.&amp;nbsp; But the girl and her parents had setup a shared secret code-word for anyone authorized to pick her up from school.&amp;nbsp; &lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;The girl asked for the code word but the suspect got it wrong.&amp;nbsp; She told him it was incorrect and he drove away.&amp;nbsp; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;I applaud the parents for a job well done in implementing a simple and effective security solution and to the little girl who deftly executed to it, likely without the need of understanding the grim impacts of failure.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;In the security and technology industry, we can learn volumes from this encounter.&amp;nbsp; First, a security savvy person is far more effective than a stack of technical security controls.&amp;nbsp; Second, complexity does not guarantee effectiveness.&amp;nbsp; In fact, simplicity can be more cost efficient and easier to implement. An elegant solution, is one which is accepted, applied, and delivers the preferred result.&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;As security professionals, we have an opportunity to meet these requirements to deliver an optimal solution through a marriage of inherent human and technical considerations.&amp;nbsp; We must not forget, computer security is a combination of both.&amp;nbsp; The very best solutions enhance the user&amp;#8217;s ability to be secure without being cumbersome.&amp;nbsp; Pure elegance.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:f5eba56f-426b-4ecd-9bac-21712bae69ec] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it@intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">value</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">model</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">risk</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">optimal_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew_rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">threat</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attack</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">strategy</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attacker</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">loss</category>
      <pubDate>Mon, 08 Apr 2013 18:12:39 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2013/04/08/security-does-not-need-to-be-complex-to-be-effective</guid>
      <dc:date>2013-04-08T18:12:39Z</dc:date>
      <clearspace:dateToText>1 month, 2 weeks ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/security-does-not-need-to-be-complex-to-be-effective</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15775</wfw:commentRss>
    </item>
    <item>
      <title>Poor Security Policies Lead to Disastrous Customer Service</title>
      <link>http://communities.intel.com/community/openportit/blog/2013/01/25/poor-security-policies-lead-to-disastrous-customer-service</link>
      <description>&lt;!-- [DocumentBodyStart:d495ae15-5a63-4dbf-bcef-68fffe3513e6] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Security is about preventing loss.&amp;nbsp; But be careful, as instituting poor security policies can drive away customers and impact your business.&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;This is a story of how a financial institution is doing security wrong.&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15626-231237/Policy+Failure+Letter.jpg"&gt;&lt;img alt="Policy Failure Letter.jpg" class="jive-image" height="175" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15626-231237/357-175/Policy+Failure+Letter.jpg" style="float: right;" width="357"/&gt;&lt;/a&gt;I have been a customer of a local credit union for nearly 40 years.&amp;nbsp; It has a few branches, online services, and prides itself on customer service.&amp;nbsp; My account was open at a very young age and had since moved away but always kept my account active and enjoyed a number of the financial service offerings over the years.&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;The problem began in a benign manner.&amp;nbsp; I recently moved and was changing my mailing address with my various financial, health, and business accounts.&amp;nbsp; In today's web-centric world, it is pretty easy to accomplish.&amp;nbsp; In every case except one, I would login to the organization's website with my credentials and provide my new address.&amp;nbsp; In some cases I would have to provide additional information for verification, but the process was smooth.&amp;nbsp; They quickly followed up with an email notification or a card in the mail at the previous address as a measure to detect fraudulent submissions.&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Then came my credit union.&amp;nbsp; Their website requires a User ID, password, and additional validation of challenge-response questions if connecting from an unrecognized or public PC.&amp;nbsp; It even sports an anti-spoofing feature where an image previously selected by the customer is provided as part of the login.&amp;nbsp; All wonderful security measures which I applaud.&amp;nbsp; However, it lacks a friendly user interface to edit profile details.&amp;nbsp; With no obvious way to change my mailing address online, I called the support number and was informed I needed to write a letter requesting a change of address, provide my account number, and signature, and send it via US mail to their offices for processing.&amp;nbsp; Although inconvenient, I followed the instructions.&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;A few days later I received a voicemail at my home number, which was on record with the credit union, and was informed they received my written request but didn't believe my signature was authentic and therefore declined my change of address.&amp;nbsp; &lt;em&gt;&lt;strong&gt;What?&lt;/strong&gt;&lt;/em&gt;&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;I called again and at their request provided my account number, date of birth, and last four of my social security number, home phone, email address, and mobile phone number to validate my identity.&amp;nbsp; After providing all that was requested in addition to details about my account history which would not be on any recent statements, I explained my issue to the supervisor in charge.&amp;nbsp; I was informed they could not readily locate my written request but reassured me it should be around somewhere and instructed me to either come into a branch, which is nearly 2 hours away, or photocopy my driver&amp;#8217;s license and fax it in.&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;&lt;strong&gt;No.&lt;/strong&gt;&lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;I refused to be a part of such "security theater" (as &lt;a class="jive-link-external-small" href="http://www.schneier.com/" target="_blank"&gt;Bruce Schneier would say&lt;/a&gt;).&amp;nbsp; I asked why all this is necessary to change my mailing address?&amp;nbsp; With the information I provided on the phone or necessary to login online, I can electronically transfer funds to external accounts, receive a personal loan, reset passwords, request checks, and change all other contact data in my profile.&amp;nbsp; Why the elevated security for a mailing address change?&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Here is my favorite part.&amp;nbsp; The supervisor, in his best authoritarian voice told me it is for my protection, that I probably wouldn't fully understand the security risks, and that is was 'required by law'.&amp;nbsp; When I told him I am a security professional of 20 years, have consulted banks, and work as a computer security strategist for one of the most prominent companies in technology, his voice went soft.&amp;nbsp; I explained how the additional controls provided no appreciable value and how the rest of the industry follows more rational practices.&amp;nbsp; I challenged the representative to identify the regulatory requirement, because none exists which specifies a written and signed request or photocopy of a state identity as necessary to fulfill a change of address request on a basic consumer financial account.&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;In the end, we came to the obvious conclusion he was simply following the company's security policy, one created with the best of intents, but lacking both insight and effectiveness to reducing the risk of loss.&amp;nbsp; It is in fact counter-productive, causing frustration on behalf of the customer and consuming employee resources for no appreciable risk benefit.&amp;nbsp;&amp;nbsp; Regardless of the absurdity, as good employees, they are bound to adhere to it.&amp;nbsp; I don't fault them, rather the management who instituted the ill-advised policy.&amp;nbsp; We were at an impasse, my stubbornness against their policy.&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;As I am a fan of economic models and democracy, I have chosen to vote with my wallet.&amp;nbsp; I abandoned my goal of an address change and instead asked for two things.&amp;nbsp; First, to close my account.&amp;nbsp; Second, to provide me with the email address of the CEO. &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;I deal daily with the security industry and ecosystem.&amp;nbsp; I have found in many cases the CEO's and CISO's are insulated from some of the choices they make and unaware of potential side effects of their security policy.&amp;nbsp; The best management hunger to know of issues and is always looking to optimize their security practices.&amp;nbsp; With this in mind, I wrote a friendly note which I emailed and also hand delivered (when I visited in person to close my accounts) to the CEO of the credit union to help in his awareness.&amp;nbsp; Although he has not responded, I still have hope good security practices will prevail for the benefit of the remainder of his customers. &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;The lesson here is security controls must be consummate with the value of what is being protected.&amp;nbsp; A proper, efficient, and effective security policy is a powerful tool in the hands of capable employees.&amp;nbsp; But at the same time, poor security policies can have a detrimental effect on customer service, resources, and the business's bottom line.&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="color: #000000;"&gt;Beware of policies which provide no additional level of security.&amp;nbsp; It does not make sense to require extra hurdles to protect less critical assets.&amp;nbsp; In this case, current phone and online verifications, sufficient for more sensitive transactions, should have sufficed for a change of address.&amp;nbsp; As an extra measure, consider a post transaction notification via mail, phone, or email, which is the accepted standard.&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #000000;"&gt;Superfluous policies create inefficiencies and more unnecessary work for the employees and customers.&amp;nbsp; There is always a cost to security.&amp;nbsp; Squandering resources due to poor security policies is not good use of time, customer's patience, and employee effort. &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #000000;"&gt;Any policy which unduly hassles customers, delays services, and potentially exposes private information to unintended parties should be revised.&amp;nbsp; In this case, with the wrong address on file, upcoming tax documents would be sent to an address not that of the customer.&amp;nbsp; Such policies must consider that 'failing-safe' may require a change in status-quo.&amp;nbsp; Additionally, in this case, the policy called for the creation of more unneeded documentation with account information and potentially a photocopy of government issued identification (which likely would also contain unneeded personal information), and the apparent inability to manage the storage and destruction of aforementioned paperwork.&amp;nbsp; Policies should not exacerbate or complicate identity and data situations.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Instituting the perfect security policy is difficult in every industry.&amp;nbsp; We must however keep our eyes open and understand the unintended consequences in order to learn and adapt.&amp;nbsp; An optimal security policy must align to the risk-appetite of the organization, meet legal requirements, and fit within cost considerations without jeopardizing the critical services to customers.&amp;nbsp; When it fails, either too overbearing or too weak, it can fail big.&amp;nbsp; I hope other organizations can learn from the viewpoint of their customers and the lessons of their peers.&amp;nbsp; This is a learning opportunity for all.&lt;/span&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;span style="color: #000000; font-size: 8pt;"&gt;&lt;em&gt;I have intentionally omitted the name of the institution and parties involved, as they are not important.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/em&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000; font-size: 8pt;"&gt;&lt;em&gt;..if the CEO does respond, I will update this blog and even post his response if he grants permission.&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:d495ae15-5a63-4dbf-bcef-68fffe3513e6] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it@intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">value</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">model</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">risk</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">optimal_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew_rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">threat</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">service</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attack</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">policy</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">strategy</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attacker</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">financial</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">loss</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">bank</category>
      <pubDate>Fri, 25 Jan 2013 18:13:03 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2013/01/25/poor-security-policies-lead-to-disastrous-customer-service</guid>
      <dc:date>2013-01-25T18:13:03Z</dc:date>
      <clearspace:dateToText>3 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/poor-security-policies-lead-to-disastrous-customer-service</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15626</wfw:commentRss>
    </item>
    <item>
      <title>Deploying Microsoft Windows* 8 in the Enterprise</title>
      <link>http://communities.intel.com/community/openportit/blog/2013/01/21/deploying-microsoft-windows-8-in-the-enterprise</link>
      <description>&lt;!-- [DocumentBodyStart:9919eea1-099d-4e18-b6f8-1ae31cfb9a65] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; font-size: 9pt;"&gt;Intel IT is standardizing on Windows* 8 as the primary operating system for business Ultrabook&amp;#8482; devices and Intel&amp;reg; architecture-based tablets. We are accelerating the deployment readiness for business Ultrabook devices and tablets, and intend to make the new OS available for laptop and desktop PCs. Our plan is based on six months of extensive analysis and testing of Windows 8, including a pilot of over 300 users.&amp;nbsp; Read the &lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/it-management/intel-it-best-practices/deploying-microsoft-windows-8-in-the-enterprise.html" target="_blank"&gt;paper&lt;/a&gt; and tell us what you think.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:9919eea1-099d-4e18-b6f8-1ae31cfb9a65] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it@intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it_best_practices</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">windows_8</category>
      <pubDate>Mon, 21 Jan 2013 23:46:02 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2013/01/21/deploying-microsoft-windows-8-in-the-enterprise</guid>
      <dc:date>2013-01-21T23:46:02Z</dc:date>
      <clearspace:dateToText>4 months, 21 hours ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/deploying-microsoft-windows-8-in-the-enterprise</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15619</wfw:commentRss>
    </item>
    <item>
      <title>Top 10 Security Predictions for 2013 and Beyond</title>
      <link>http://communities.intel.com/community/openportit/blog/2013/01/03/top-10-security-predictions-for-2013-and-beyond</link>
      <description>&lt;!-- [DocumentBodyStart:1ecea7e9-bbcb-4b82-ae75-59af5ba22ecc] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15592-231013/2012+Stack+of+Papers.jpg"&gt;&lt;img alt="2012 Stack of Papers.jpg" class="jive-image" height="215" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15592-231013/400-215/2012+Stack+of+Papers.jpg" style="float: right;" width="400"/&gt;&lt;/a&gt;It has been an exciting and eventful year in the world of computer and information security.&amp;nbsp; As I look back through the stack of articles, conference notes, political and regulatory wrangling, technology winners and losers, and most captivatingly, the behaviors of the attackers, I find myself giggling like a schoolboy.&amp;nbsp; It is truly a wonderful time to be in this industry.&amp;nbsp; We certainly live in interesting times.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt; &amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;As the chapter of 2012 has come to a close and the blank pages of 2013 open before us to be written, it is time once again to look into the future and predict what the next 12 months hold for the cyber and information security domain.&amp;nbsp; Based upon nailing &lt;a class="jive-link-blog-small" data-containerId="1002" data-containerType="37" data-objectId="14984" data-objectType="38" href="http://communities.intel.com/community/openportit/blog/2011/12/29/security-predictions-for-2012-and-beyond"&gt;last year&amp;#8217;s predictions&lt;/a&gt;, I believe I have earned consideration to wear the turban of Carnac the Magnificent.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt; &amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;&lt;em&gt;&amp;hellip;which as I think about it, may be a reference which most readers may not get: Johnny Carson, The Tonight Show.&amp;nbsp; Oh, never mind.&amp;nbsp; I am old, go Google it.&lt;/em&gt;&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt; &amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Many aspects of security will continue to hold true.&amp;nbsp; Malware will increase, vulnerabilities will be discovered, systems will be hacked, patches will be issues, fraud and loss will be rampant, stories will be sensationalized, victims will cry, attackers and defenders will get better, legislatures will demand action, and the citizens will be aggressive in expressing their opinions and asserting their rights.&amp;nbsp; Certain characteristics of security are persistent.&amp;nbsp; These are pedestrian predictions.&amp;nbsp; They go without saying.&amp;nbsp; Above and beyond those are my security predictions for 2013 and beyond:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt; &amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong style="color: #000000;"&gt;Top 10 Security Predictions for 2013 and Beyond:&lt;/strong&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="color: #0000ff;"&gt;&lt;strong&gt;The devastating Internet-infrastructure Cyber-DOS attack, will NOT happen!&lt;/strong&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Fear mongers relax.&amp;nbsp; The debilitating Denial-of-Service of our precious Internet-of-Things will not happen, at least in 2013 and likely not for some time, if ever.&amp;nbsp; The only real chance of this is if an all-out war broke out between major technology-vested countries.&amp;nbsp; When troops and tanks roll, all bets are off on the potential for collateral damage in the cyber world.&amp;nbsp; Short of that, an elaborate attack to do irreparable harm to the Internet is just not likely.&amp;nbsp; Those who can, rely upon it themselves.&amp;nbsp; Those who want to destroy the evils of the Internet, likely do not have the ability to succeed.&amp;nbsp; It is a stalemate.&amp;nbsp; Targeted attacks may occur, but the great &amp;#8220;Cyber Pearl-Harbor&amp;rdquo; is just not realistic.&lt;br/&gt;&lt;br/&gt;&lt;/span&gt;&lt;span style="color: #000000;"&gt;But what about the rapid advances of nation state cyber warriors and technologists?&amp;nbsp; Heavily financed, well resourced, and highly motivated to fight and win in the cyber battlefield?&amp;nbsp; Well, here is the real story.&amp;nbsp; Any professional investigator, military strategist, or intelligence operative worth their merit, will tell you the goal is to compromise a command, communications, and control network.&amp;nbsp; Not to destroy it or take it offline, but rather to conduct surveillance, gather intelligence, and then use it in ways to undermine and target the enemy.&amp;nbsp; The last thing you want to do is take it offline!&amp;nbsp; The professionals know this.&amp;nbsp; It is the amateurs who launch DOS attacks, as the pro&amp;#8217;s play a smarter game. &lt;br/&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #0000ff;"&gt;&lt;strong&gt;The real target for 2013 and beyond, are BANKS!&lt;/strong&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Forget DOS attacks against social sites, vulnerabilities in toasters, lost health records at the local clinic, and data compromises at NASA.&amp;nbsp; The real targets are banks.&amp;nbsp; Professional criminals and syndicates are getting smarter and realizing the Internet is a much better means to achieve financial gains, than the local streets and traditional businesses they play in.&amp;nbsp; With unimaginable wealth sitting just beyond the keyboard, they have the resources to invest in order to seize major scores.&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Where are all these riches you ask?&amp;nbsp; Mr. Willie Sutton, an infamous bank robber of the 20&amp;#8217;s, would likely tell his compatriots to &amp;lsquo;go where the money is&amp;#8217;.&amp;nbsp; Banks.&amp;nbsp; This is how &lt;a class="jive-link-blog-small" data-containerId="1002" data-containerType="37" data-objectId="10761" data-objectType="38" href="http://communities.intel.com/community/openportit/blog/2007/11/19/deconstructing-cyber-security-attacks-threat-model"&gt;it has always been&lt;/a&gt;, as thieves gravitate to where the loot is.&lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;With banks rushing to connect with customers online and via phones, they have underestimated the lurking dragons waiting to pounce.&amp;nbsp; These attackers range from the rudimentary to the highly organized.&amp;nbsp; But the truly dangerous villains are experienced in being selective, stealthy, and planning for multi-million dollar heists and scams.&amp;nbsp; It is happening already and we have seen but the tip of the iceberg.&amp;nbsp; The banking industry needs to wake up.&amp;nbsp; Security must be taken seriously as they expand to reach and service their customers.&amp;nbsp; In 2013, we will see many failures of this.&amp;nbsp; Only those organizations who invest in both superior security leadership and technology will stand confident.&lt;br/&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #0000ff;"&gt;&lt;strong&gt;Arrests, prosecutions, and pressure against threat agents will continue go up!&lt;/strong&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Last year we witnessed an aggressive &lt;a class="jive-link-blog-small" data-containerId="1002" data-containerType="37" data-objectId="15586" data-objectType="38" href="http://communities.intel.com/community/openportit/blog/2012/12/27/2012-crackdown-on-hackers-and-cyber-criminals"&gt;crackdown on hackers and cyber criminals&lt;/a&gt;.&amp;nbsp; Security and law enforcement capabilities, techniques, and cooperation continue to grow and improve.&amp;nbsp; Tangible success in security reinforces investment.&amp;nbsp; This momentum will accelerate in 2013 and we will see many of the less savvy players brought to justice.&amp;nbsp; Expect this trend to thankfully continue forward.&amp;nbsp; &lt;br/&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #0000ff;"&gt;&lt;strong&gt;Cyber regulations remain inconsistent across borders, vague, and ineffective.&amp;nbsp; But will continue to slowly coalesce.&lt;/strong&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Politics, economics, social expectations, and regional differences in what is considered an individual&amp;#8217;s right will continue to hamper globally adopted regulations. But this is an important and valuable effort, which is the one thing everyone agrees in common.&amp;nbsp; They will continue to slowly align, find tradeoffs, and coalesce for everyone&amp;#8217;s benefit.&amp;nbsp; Patience.&amp;nbsp; It will be a bumpy ride with false starts and turmoil, but it will get a little better in 2013, then 2014, etc.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br/&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #0000ff;"&gt;&lt;strong&gt;Governments invest heavily in Cyber &lt;/strong&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Tech savvy governments have no choice.&amp;nbsp; They must now invest in cyber technology to defend their systems, people, privacy, and national infrastructure.&amp;nbsp; Larger governments are investing heavily in offense, defense, detection, infrastructure testing, survivability, intelligence, resilience, SOC/CERT's, &lt;a class="jive-link-blog-small" data-containerId="1002" data-containerType="37" data-objectId="15548" data-objectType="38" href="http://communities.intel.com/community/openportit/blog/2012/11/28/cyber-security-hunter-teams-are-the-next-advancement-in-network-defense"&gt;Hunter Teams&lt;/a&gt;, etc.&amp;nbsp; They will evolve to both establish and defend their online territory and systems.&amp;nbsp; As we saw in 2012, many governments are openly recruiting and establishing centers of excellence for the particular skills necessary to reach out and influence or affect others.&amp;nbsp; In 2013, many such entities will have created and begun training in earnest with viable offensive cyber weapons.&amp;nbsp; Welcome to the &lt;a class="jive-link-blog-small" data-containerId="1002" data-containerType="37" data-objectId="14865" data-objectType="38" href="http://communities.intel.com/community/openportit/blog/2011/10/27/cyber-security-the-fifth-domain-of-warfare"&gt;fifth domain of warfare&lt;/a&gt;.&amp;nbsp; There is no going back.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br/&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #0000ff;"&gt;&lt;strong&gt;Regulations increase in depth, breadth, and specificity for high technology &lt;/strong&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Technology hardware, software, cloud services, mobile devices, and the data collected from all those sensors will come under regulatory scrutiny.&amp;nbsp; It won&amp;#8217;t all come at once, but it will come.&amp;nbsp; Privacy, critical infrastructure protection, government systems standards and minimum controls, data aggregation, and remote surveillance will be the first targets for more specific and comprehensive requirements.&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Many of the current or first generation government regulations were broad in nature.&amp;nbsp; They are getting more explicit and lengthy.&amp;nbsp; Ever read the &lt;a class="jive-link-external-small" href="http://csrc.nist.gov/publications/PubsSPs.html" target="_blank"&gt;NIST 800 series&lt;/a&gt;?&amp;nbsp; This is not necessarily a bad thing, but bureaucracy can sometimes be slow to respond to rapidly changing environments.&amp;nbsp; Satisfying regulations is always a start, but never a guarantee of security.&amp;nbsp; In 2013, we will see more required oversight, business practice investigations, clarity in technical and behavioral requirements, and those out of compliance will be penalized.&amp;nbsp; &lt;br/&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #0000ff;"&gt;&lt;strong&gt;Mobile malware and attacks increase&lt;/strong&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;No surprises here.&amp;nbsp; Although it falls into the category of blazingly obvious, it still deserves a call-out.&amp;nbsp; The rapid adoption of smartphones worldwide has spawned an insatiable vortex of desire for applications and services.&amp;nbsp; Each an opportunity for attackers.&amp;nbsp; The rush and competition for product releases has left security as a distant bystander.&amp;nbsp; This environment is ripe for rampant malware and attacks.&amp;nbsp; We all will start to see and feel the pain in 2013. &lt;br/&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #0000ff;"&gt;&lt;strong&gt;Covert attacks get better, more sophisticated, and tougher to decipher &lt;/strong&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Amateur night is over.&amp;nbsp; Although the vast majority of malware out on the Internet is basic and well understood, this will begin to change.&amp;nbsp; Sophisticated covert attackers have learned that discovery is the death knell of their malware.&amp;nbsp; They will take innovative steps to stay hidden, be more resilient, survive counter-attacks, and make it much more challenging for security researchers to understand the inner working of future malware.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br/&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #0000ff;"&gt;&lt;strong&gt;Innovation rules.&amp;nbsp; Attackers and defenders get better, at a much faster rate than before.&lt;/strong&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Investment spurs innovation.&amp;nbsp; The world is becoming more connected between people and valuable services.&amp;nbsp; With governments, businesses, and consumers investing in security, the stakes and investment are raised.&amp;nbsp; Both attackers and defenders will improve to counter their respective adversaries with innovations backed by these investments and opportunities.&amp;nbsp; The race will simply get faster.&amp;nbsp;&amp;nbsp; &lt;br/&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #0000ff;"&gt;&lt;strong&gt;Patent lawsuits to infiltrate the security services industry?&lt;/strong&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;Patent lawsuits are rampant in the technology sector.&amp;nbsp; Will security become the latest target in 2013?&amp;nbsp; Perhaps.&amp;nbsp; This prediction will come down to economics.&amp;nbsp; I will confidently predict more patents will be filed for security in 2013.&amp;nbsp; Only if a significant paycheck is plausible, will the patent lawsuit community begin to circle.&amp;nbsp; I give this a 50% chance of seeing a security technology patent lawsuit by the end of the year.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt; &amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;There you have it.&amp;nbsp; My top 10 predictions for 2013.&amp;nbsp; Come back in December and we can celebrate together or you can berate me mercilessly.&amp;nbsp; Either way, it should be a fun and interesting 12 months.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:1ecea7e9-bbcb-4b82-ae75-59af5ba22ecc] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it@intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">value</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">model</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">risk</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">optimal_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew_rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">threat</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attack</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">strategy</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">prediction</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attacker</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">loss</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">2013</category>
      <pubDate>Thu, 03 Jan 2013 17:04:49 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2013/01/03/top-10-security-predictions-for-2013-and-beyond</guid>
      <dc:date>2013-01-03T17:04:49Z</dc:date>
      <clearspace:dateToText>4 months, 2 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/top-10-security-predictions-for-2013-and-beyond</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15592</wfw:commentRss>
    </item>
    <item>
      <title>2012 Crackdown on Hackers and Cyber Criminals</title>
      <link>http://communities.intel.com/community/openportit/blog/2012/12/27/2012-crackdown-on-hackers-and-cyber-criminals</link>
      <description>&lt;!-- [DocumentBodyStart:c9d245d8-a36f-4a4e-a3ee-ba36ae3c74d9] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15586-230963/Handcuffs.jpg"&gt;&lt;img alt="Handcuffs.jpg" class="jive-image" height="162" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15586-230963/284-162/Handcuffs.jpg" style="float: right;" width="284"/&gt;&lt;/a&gt;A number of high profile takedowns, arrests, and prosecutions have occurred throughout the year.&amp;nbsp; As &lt;a class="jive-link-blog-small" data-containerId="1002" data-containerType="37" data-objectId="14984" data-objectType="38" href="http://communities.intel.com/community/openportit/blog/2011/12/29/security-predictions-for-2012-and-beyond"&gt;I predicted for 2012&lt;/a&gt;, we have witnessed a tremendous amount of pressure towards the people behind computer attacks.&amp;nbsp; More focus is being placed on interdicting and removing the &lt;a class="jive-link-wiki-small" data-containerId="2006" data-containerType="14" data-objectId="1151" data-objectType="102" href="http://communities.intel.com/docs/DOC-1151"&gt;threat-agents&lt;/a&gt;, the term for archetypes of attackers, instead of just addressing the vulnerabilities exploited by their attacks.&amp;nbsp; Targeting the culprits behind computer attacks effectively cures the root cause instead of just treating symptoms.&amp;nbsp;&amp;nbsp; Individuals and groups were pursued by law enforcement agencies, security firms, and internal response teams worldwide.&amp;nbsp; It is emerging as an effective and necessary practice which continues to gain momentum.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Recently, US Justice Department officials announced they will &lt;a class="jive-link-external-small" href="http://arstechnica.com/security/2012/12/feds-reportedly-plan-to-prosecute-hackers-sponsored-by-other-nations/" target="_blank"&gt;pursue criminal charges against threat agents sponsored by other nations&lt;/a&gt;.&amp;nbsp; This is huge.&amp;nbsp; It will expand the scope and depth of worthwhile investigations in areas holding the greatest potential for loss.&amp;nbsp; Although laws have been in place since 1996 to protect from economic espionage, it has largely been ignored, partly due to the difficulty of proving foreign government collusion, political ramifications, and also due to the complexities of presenting a solid legal case.&amp;nbsp; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;With sufficient numbers of properly trained prosecutors, it may be possible to bring enough cases to into public view to have a sufficient impact and drive change.&amp;nbsp; Optimally, public awareness and support is critical to address political hurdles and approve necessary funding for future prosecutions.&amp;nbsp; Knowledge by current or prospective threat-agents promotes deterrence and a stigma of wrongdoing for those who are impressionable and may see such activities as attractive.&amp;nbsp; Lastly, successes in prosecution will show other regional and international law enforcement agencies that this is a problem which can and should be tackled.&amp;nbsp; With a growing list of successful cases, it promotes the necessary legal infrastructure and expertise to make the process more efficient.&amp;nbsp; All this adds to a stronger capability to remove the elite and upcoming talent who choose to leverage technology in malicious ways at the detriment of others.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Here are some of my favorite cases for 2012:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Arrests against the international Butterfly Botnet crime ring, responsible for over 11 million compromised computers and $850 million in losses &lt;a class="jive-link-external-small" href="http://www.fiercegovernmentit.com/story/fbi-announces-arrests-case-international-cyber-crime-rings-linked-butterfly/2012-12-13" target="_blank"&gt;http://www.fiercegovernmentit.com/story/fbi-announces-arrests-case-international-cyber-crime-rings-linked-butterfly/2012-12-13&lt;/a&gt;&lt;/li&gt;&lt;li&gt;FBI "Carder Profit" sting busts people in 12 countries, dealing in stolen credit card numbers.&amp;nbsp;&amp;nbsp; &lt;a class="jive-link-external-small" href="http://tpmmuckraker.talkingpointsmemo.com/2012/06/fbi_sting_carderprofit_cc.php" target="_blank"&gt;http://tpmmuckraker.talkingpointsmemo.com/2012/06/fbi_sting_carderprofit_cc.php&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Microsoft&amp;#8217;s Digital Crime Unit (DCU) continues to lead the charge against botnets, with impressive work against Nitol, Kelihos, and Zeus.&amp;nbsp; These guys and gals are my heroes, really.&amp;nbsp;&amp;nbsp; &lt;a class="jive-link-external-small" href="http://www.microsoft.com/en-us/news/presskits/dcu/" target="_blank"&gt;http://www.microsoft.com/en-us/news/presskits/dcu/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;An international cyber scam ring was prosecuted, which had used scareware tactics to defraud $71 million by selling bogus security software after infecting systems.&amp;nbsp; &lt;a class="jive-link-external-small" href="http://www.justice.gov/opa/pr/2012/December/12-crm-1503.html" target="_blank"&gt;http://www.justice.gov/opa/pr/2012/December/12-crm-1503.html&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Sentencing of the team behind a shockingly coordinated worldwide banking attack, involving participants in over 280 cities worldwide, who siphoned over $9 million from 2100 ATM's.&amp;nbsp; This involved compromised bank accounts and synchronized ATM withdrawals&amp;nbsp; &lt;a class="jive-link-external-small" href="http://www.fbi.gov/atlanta/press-releases/2012/sentencing-in-major-international-cyber-crime-prosecution" target="_blank"&gt;http://www.fbi.gov/atlanta/press-releases/2012/sentencing-in-major-international-cyber-crime-prosecution&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;This is just the start.&amp;nbsp; Expect this list to grow significantly in 2013.&amp;nbsp; I am confident as more pressure is exerted on cyber criminals, the threat landscape will thin thus allowing for resources to target those who adapt and attempt to cause the greatest harm.&amp;nbsp; It is the normal cycle of criminals, technology, and justice.&amp;nbsp; I can&amp;#8217;t wait to see what interesting prosecution holds for 2013. &lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:c9d245d8-a36f-4a4e-a3ee-ba36ae3c74d9] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it@intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">value</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">model</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">risk</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">optimal_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew_rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">threat</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attack</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">strategy</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">threat_agent</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attacker</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">loss</category>
      <pubDate>Thu, 27 Dec 2012 17:36:09 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2012/12/27/2012-crackdown-on-hackers-and-cyber-criminals</guid>
      <dc:date>2012-12-27T17:36:09Z</dc:date>
      <clearspace:dateToText>4 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/2012-crackdown-on-hackers-and-cyber-criminals</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15586</wfw:commentRss>
    </item>
    <item>
      <title>The confounding world of information security terms, from Access to Zone of Control</title>
      <link>http://communities.intel.com/community/openportit/blog/2012/12/17/the-confounding-world-of-information-security-terms-from-access-to-zone-of-control</link>
      <description>&lt;!-- [DocumentBodyStart:88df79a9-0d15-4645-8c62-a862dd230099] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #000000;"&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15578-230887/Book.jpg"&gt;&lt;img alt="Book.jpg" class="jive-image" height="198" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15578-230887/258-198/Book.jpg" style="float: right;" width="258"/&gt;&lt;/a&gt;Communication is incredibly important in the security industry.&amp;nbsp; We must work together, be it small teams, across organizations, or beyond boarders throughout the industry, government, supporting ecosystem and academia.&amp;nbsp; But we have a problem.&amp;nbsp; It has become commonplace to talk past each other with terms a speaker perceives as precise, but audiences interpret in vastly differing ways.&amp;nbsp; In many cases terms can have a multitude of definitions with a high dependency on context.&amp;nbsp; But when the description of the context also contains words with varying or unclear meanings, the problem is proliferated.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #000000;"&gt;It causes enough separation to inhibit conveyance of clear ideas, concerns, and expectations.&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #000000;"&gt;To make matters worse, the sheer size of the security vocabulary has grown immense and continues to expand.&amp;nbsp; Listening to some conversations, it sounds like a new language of acronym soup: "The ROSI of the SEIM is highly dependent on the SOC's ability to filter False Positives to track APT's and protect SPOF's from Integrity and DOS Availability attacks. "&amp;nbsp; &lt;em&gt;I am truly sorry for anyone who actually understood that...&lt;/em&gt; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #000000;"&gt;Even the hard core professionals get tripped up over terms which may be clear in their mind but not so with listeners.&amp;nbsp; Terms like hacker, Advanced-Persistent-Threat (APT), identity, loss, threat, and even what constitutes an 'Attack' can differ greatly.&amp;nbsp; One of the most overused and inconsistently defined term is 'virus'.&amp;nbsp; It has become a catchphrase and conglomeration of negative events, computer code, and a moniker for vulnerability.&amp;nbsp; If you asked twenty people to define 'virus', you would likely get twenty-one different answers.&amp;nbsp;&amp;nbsp; It did at one time, have a very specific definition.&amp;nbsp; It was a type of code which injected itself into other code or processes and replicated.&amp;nbsp; But today it tends to be used as a term which covers all manner of malware, including Trojans, bots, droppers, worms, spyware, sniffers, loggers, backdoors, spyware, ad-ware, Potentially-Unwanted-Programs (PUP), etc.&amp;nbsp; Some of which are actual categories of code, while others are simply descriptions of how or what that code does.&amp;nbsp; A blurry line of delineation to be sure and all of which actually have their own definitions.&amp;nbsp; It can be all so confusing and we in the industry are not helping the situation.&amp;nbsp; Does anti-virus software only target viruses?&amp;nbsp; No, of course not.&amp;nbsp; But we cannot be more articulate, at the risk of confusing everyone even more!&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #000000;"&gt;The industry is hobbled by an inability to consistently and effectively communicate.&amp;nbsp;&amp;nbsp; So, with a big round of applause and gratitude, I want to thank those hard working folks at NIST.&amp;nbsp; NIST has been busy, very busy.&amp;nbsp; They have released the second draft of their &lt;span style="color: #000000;"&gt;&lt;a class="jive-link-external-small" href="http://csrc.nist.gov/publications/drafts/ir-7298-rev2/nistir7298_r2_draft.pdf" target="_blank"&gt;Glossary of Key Information Security Terms&lt;/a&gt;&lt;/span&gt;.&amp;nbsp; An impressive listing of technical and general industry terms, covered in over 200 pages.&amp;nbsp; It is a sizeable document, defining terms from Access to Zone-of-Control.&amp;nbsp; But sadly, it is not even close to a complete reference for computer security vocabulary.&amp;nbsp; &lt;span style="font-size: 10pt;"&gt;The NIST glossary focuses on aggregating the terms and definitions of their library of documents.&amp;nbsp; It is not intended to define terms for the whole of security.&amp;nbsp; Acronyms and expressions like ROSI (Return on Security Investment), Crossover Rate (the point where False-Positives equals False Negatives, also referred as the Crossover Error Rate), SOC (Security Operations Center), and CERT (Computer Emergency Response Team) won&amp;#8217;t be found in those pages.&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: 'Calibri','sans-serif'; color: #000000; font-size: 10pt;"&gt;So how big is the computer security vocabulary?&amp;nbsp; It is a bit scary to ponder and doubtful anyone knows for certain.&amp;nbsp; But until someone comes out with something better, I am adding this to my reference library.&amp;nbsp; In the end, we must all struggle to communicate effectively.&amp;nbsp; Defining common terms goes a long way to make our security industry stronger.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:88df79a9-0d15-4645-8c62-a862dd230099] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it@intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">model</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">risk</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">optimal_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew_rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">threat</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attack</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">strategy</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attacker</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it_best_practices</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">tim_casey_intelsme</category>
      <pubDate>Mon, 17 Dec 2012 21:46:43 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2012/12/17/the-confounding-world-of-information-security-terms-from-access-to-zone-of-control</guid>
      <dc:date>2012-12-17T21:46:43Z</dc:date>
      <clearspace:dateToText>5 months, 5 days ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/the-confounding-world-of-information-security-terms-from-access-to-zone-of-control</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15578</wfw:commentRss>
    </item>
    <item>
      <title>Intel Goes with Windows 8</title>
      <link>http://communities.intel.com/community/openportit/blog/2012/12/14/intel-goes-with-windows-8</link>
      <description>&lt;!-- [DocumentBodyStart:90cd1ec0-2a55-4c2e-937e-4aa588e4b38b] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;After evaluating Microsoft Windows 8, we have chosen Windows8 on Intel Architecture as the standard operating system&amp;nbsp; for Ultrabooks and tablets in our enterprise environment.&amp;nbsp; We are excited to use this totally new operating system on a variety of devices, especially those that include touch.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Windows 8 will enable IT to deliver a flexible, positive user experience. It provides greater mobile productivity and the user experience our employees crave.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The response of the early users of Windows 8 in our environment has been very positive. We are moving ahead. By mid-2013 thousands of Intel employees will be using Windows 8.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Follow me on Twitter @kimsstevenson. &lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:90cd1ec0-2a55-4c2e-937e-4aa588e4b38b] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it_business_value</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel_it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">windows</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it_best_practices</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">kim_stevenson</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel_cio</category>
      <pubDate>Fri, 14 Dec 2012 17:30:05 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2012/12/14/intel-goes-with-windows-8</guid>
      <dc:date>2012-12-14T17:30:05Z</dc:date>
      <clearspace:dateToText>5 months, 1 week ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/intel-goes-with-windows-8</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15573</wfw:commentRss>
    </item>
    <item>
      <title>AV is Not Dead</title>
      <link>http://communities.intel.com/community/openportit/blog/2012/12/06/av-is-not-dead</link>
      <description>&lt;!-- [DocumentBodyStart:f777ced4-d414-4a5a-aed7-09abe45d70b8] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15560-230845/AV+Protection.jpg"&gt;&lt;img alt="AV Protection.jpg" class="jive-image" height="135" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15560-230845/181-135/AV+Protection.jpg" style="float: right;" width="181"/&gt;&lt;/a&gt;Recent stories in the news imply Anti-Virus (AV) is dead.&amp;nbsp; A longtime staple of security managers and consumers, AV and more broadly, anti-malware products are a pillar of the security industry.&amp;nbsp; Could all our investments, preconceptions, and efforts be worthless?&amp;nbsp; Rest assured, the sky is not falling.&amp;nbsp; The &amp;#8220;Anti-Virus is worthless/dead&amp;rdquo; mantra has been around for years.&amp;nbsp; Yet the anti-virus/malware industry is alive and thriving, with good reason.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;The world of computing is a dangerous place.&amp;nbsp; Client systems, such as PC&amp;#8217;s and more recently smartphones, are under constant pressure from new malicious software.&amp;nbsp; To date, about a hundred million different specimens of nefarious code are in the wild and ready to pounce on their next victim.&amp;nbsp; Those numbers continue to increase by tens-of-thousands of new malware emerging daily.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Most of the security industry embraces anti-virus/malware protections resident on their devices, to resist the persistent onslaught of malware developers.&amp;nbsp; Even consumers, typically not savvy in security matters, recognize the value of AV in protecting their devices and data.&amp;nbsp; In most managed environments, anti-malware controls are leveraged across the networks and back-end servers, in addition to client systems. &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Over the years, a very small community has voiced opinions that AV is dead or worthless.&amp;nbsp; They hold the position client based anti-virus and anti-malware are ineffective at protecting systems.&amp;nbsp; They run tests against small samples of new malicious code or show how some systems still get compromised even when benefiting from AV products.&amp;nbsp; Year over year they speculate how traditional AV methods can&amp;#8217;t keep pace with the increasing malware being introduced and it is on the verge of collapse.&amp;nbsp; Like doomsday predictions, they keep coming.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;I believe this is an extremist position and in many cases, putting forward a misleading straw-man argument.&amp;nbsp; The false-logic goes something like this:&lt;/span&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;span style="color: #000000;"&gt;&lt;span style="text-decoration: underline;"&gt;Longstanding position of the security industry&lt;/span&gt;: &lt;em&gt;Anti-Virus/Malware provides important protection of systems against malicious code&lt;/em&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: #000000;"&gt;&lt;span style="text-decoration: underline;"&gt;False-logic counter argument&lt;/span&gt;:&amp;nbsp; &lt;em&gt;Anti-Virus/Malware does not provide total protection and a system could be infected with malicious code, therefore AV is not worthwhile and dead (or soon will be)!&lt;/em&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Don&amp;#8217;t fall for the hype.&amp;nbsp; Here is the real scoop.&amp;nbsp; Anti-virus/malware solutions are one of many different security controls.&amp;nbsp; It is not an impervious shield, just like all other potential protections are not perfect solutions.&amp;nbsp; These tools do provide a great deal of protection but should be used in combination with other controls.&amp;nbsp; In security parlance, it is called Defense-in-Depth.&amp;nbsp; No one tactic or tool will suffice.&amp;nbsp; The attackers are just too many and too smart for a single control to work across the board for any meaningful period of time.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;More reasonable people in the past have also weighed in on the value of AV and in some cased they have chosen to rely on other compensating controls.&amp;nbsp; But their message is different than &amp;#8220;AV is worthless&amp;rdquo;.&amp;nbsp; They see AV as one of many different options which can manage security risks.&amp;nbsp; They are savvy enough to choose the right set of interlaced solutions which achieve the desired level of security for their specific computing environment.&amp;nbsp; This can be misconstrued when it is not understood.&amp;nbsp; In the end, they are still applying a defense-in-depth methodology.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Why would a security professional choose not to deploy Anti-virus/malware on clients?&amp;nbsp; Well, in some delicate, isolated, or sensitive environments AV may not be a viable option.&amp;nbsp; Products may not support the hardware, software or operating systems, be cost prohibitive, invalidate system or maintenance warranties, or be unacceptable from a performance perspective.&amp;nbsp; Instead, other security controls may be employed which compensate for this deficiency.&amp;nbsp; As far as I have seen, these tend to be limited to small parts of corporate environments.&amp;nbsp; For most systems which connect to large networks and the Internet, anti-virus/malware makes practical and economic sense.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Evaluating controls and implementing the right combination has been at the very heart of computer security from inception.&amp;nbsp; Time and again, anti-virus/malware has been chosen as a valuable contributor to the mix.&amp;nbsp; This will likely not change in my lifetime.&amp;nbsp;&amp;nbsp;&amp;nbsp; Rest assured, akin to what Mark Twain said, I say the death of AV has been greatly exaggerated.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;span style="color: #000000;"&gt;Time machine sampling for the &amp;#8220;AV is dead&amp;rdquo; concept:&amp;nbsp; &lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;2012 report: &lt;a class="jive-link-external-small" href="http://www.cio.com/article/722389/Antivirus_Software_a_Waste_of_Money_for_Businesses_Report_Suggests" target="_blank"&gt;Antivirus Software a Waste of Money for Businesses, Report Suggests &lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;span style="color: #000000;"&gt;2012 article: &lt;a class="jive-link-external-small" href="http://computer-forensics.sans.org/blog/2012/04/09/is-anti-virus-really-dead-a-real-world-simulation-created-for-forensic-data-yields-surprising-results" target="_blank"&gt;Is Anti-Virus Really Dead? A Real-World Simulation Created for Forensic Data Yields Surprising Results&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;2010 article: &lt;a class="jive-link-external-small" href="http://hakin9.org/is-anti-virus-dead-the-answer-is-yes-here%E2%80%99s-why%E2%80%A6/" target="_blank"&gt;Is Anti-virus Dead &amp;#8211; The answer is YES. Here&amp;#8217;s why&amp;hellip;&lt;/a&gt; &lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;span style="color: #000000;"&gt;2009 article: &lt;a class="jive-link-external-small" href="http://www.csoonline.com/article/495827/experts-only-time-to-ditch-the-antivirus-" target="_blank"&gt;Experts only: Time to ditch the antivirus?&lt;/a&gt;&lt;/span&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;2009 venerable Bruce Schneier&amp;#8217;s blog: &lt;a class="jive-link-external-small" href="http://www.schneier.com/blog/archives/2009/11/is_antivirus_de.html" target="_blank"&gt;Is Antivirus Dead?&lt;/a&gt; &lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;span style="color: #000000;"&gt;2008 article: &lt;a class="jive-link-external-small" href="http://www.zdnet.com/signature-based-antivirus-is-dead-get-over-it-1339288527/" target="_blank"&gt;Signature based antivirus is dead: Get over it &lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;span style="color: #000000;"&gt;2007 article: &lt;a class="jive-link-external-small" href="http://www.pcworld.com/article/130455/article.html" target="_blank"&gt;Is desktop antivirus dead?&lt;/a&gt; &lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;span style="color: #000000;"&gt;2006 white paper: &lt;a class="jive-link-external-small" href="https://www.bit9.com/files/wp-2006-Bit9-Anti-Virus-is-Dead.pdf" target="_blank"&gt;Anti-virus is Dead&lt;/a&gt; &lt;/span&gt;&lt;/p&gt;&lt;p style="padding-left: 30px;"&gt;&lt;br/&gt;&lt;span style="color: #000000;"&gt;And finally, here is my own blog post from 2010 showing hard numbers of effectiveness for AV: &lt;a class="jive-link-blog-small" data-containerId="1002" data-containerType="37" data-objectId="13278" data-objectType="38" href="http://communities.intel.com/community/openportit/blog/2010/04/19/the-hard-truth-of-anti-virus"&gt;The Hard Truth of Anti-Virus. &lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:f777ced4-d414-4a5a-aed7-09abe45d70b8] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it@intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">value</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">model</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">malware</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">risk</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">corporate_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">virus</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">internet</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">optimal_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew_rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">defense_in_depth</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">threat</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attack</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">strategy</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">protect</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">trojan</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">loss</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">bot</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">av</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">anti-virus</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it_best_practices</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">anti-malware</category>
      <pubDate>Thu, 06 Dec 2012 17:45:15 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2012/12/06/av-is-not-dead</guid>
      <dc:date>2012-12-06T17:45:15Z</dc:date>
      <clearspace:dateToText>5 months, 2 weeks ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/av-is-not-dead</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15560</wfw:commentRss>
    </item>
    <item>
      <title>Cyber security Hunter teams are the next advancement in network defense</title>
      <link>http://communities.intel.com/community/openportit/blog/2012/11/28/cyber-security-hunter-teams-are-the-next-advancement-in-network-defense</link>
      <description>&lt;!-- [DocumentBodyStart:93d77d58-1056-485b-9a1b-be5e676e28ff] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15548-230701/Hunter+Team+2.jpg"&gt;&lt;img alt="Hunter Team 2.jpg" class="jive-image" height="122" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15548-230701/150-122/Hunter+Team+2.jpg" style="float: right;" width="150"/&gt;&lt;/a&gt;&lt;strong&gt;Hunter teams are emerging as a new tool in the world of cyber defense.&lt;/strong&gt;&amp;nbsp;&amp;nbsp; Computer security continues to improve and evolve of overtime. One of the latest practices gaining momentum is the use of cyber security &amp;#8220;Hunter teams&amp;rdquo;.&amp;nbsp; Differing from how standard security operations function, hunter teams fill an important gap and push us one step further on the evolutionary ladder of cyber security.&amp;nbsp; They are cyber-investigators which enhance an organization&amp;#8217;s capabilities by supplementing the overall defense from persistent attackers.&amp;nbsp; They are typically a group of bright, experienced, talented, and motivated professionals which work together to detect, identify, and understand an advanced and determined threat agent. &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Hunter teams approach threats in a personal way.&amp;nbsp; They seek the human origins of attacks and focus their attention on disruption or removal of those threat agents, instead of the attacks themselves.&amp;nbsp; In simple terms, they target the attackers.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;These hunter teams are sprouting and taking root in many different places.&amp;nbsp; Anti-malware companies, research organizations, and internal security departments have begun to embrace looking for the attackers.&amp;nbsp; Investigation teams, including cyber guns-for-hire which are brought in after the fact when serious breaches are detected, are also looking for the people behind the attacks.&amp;nbsp; However, it has been the military and sensitive government organizations which have been most vocal in recruiting for hunter team talent.&amp;nbsp; They have the long history of knowing the value of identifying the enemy and have been quick to embrace this practice and are serious in making it successful. &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Hundreds of years ago Sun Tsu penned the authoritative tome on warfare strategy.&amp;nbsp; One of its pillars is to know your enemy.&amp;nbsp; A key to conflict is to understand that attacks are simply a method for the threat agent to achieve their objectives.&amp;nbsp; An active defense not only shields against attacks, but also targets the attackers.&amp;nbsp; Those people who would do you or your mission harm.&amp;nbsp; Take the attackers out of the equation and the attacks also go away.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;&lt;strong&gt;Hunter teams play an important role, different than standard security operations staff.&lt;/strong&gt;&amp;nbsp;&amp;nbsp; In the past decade, we have seen the rise of security operations centers (SOC).&amp;nbsp; Security operations departments are typically configured, resourced, and driven to contain attacks and remediate to a state of normal operations.&amp;nbsp;&amp;nbsp; They are in a continuous cycle of fixing the symptoms and tweaking the defenses so the organization continues to operate in a stable and expected manner.&amp;nbsp; It is a never ending struggle which works best against the flood of broadly sweeping attacks on the internet, which look for any target of opportunity.&amp;nbsp; In most cases, SOC&amp;#8217;s are only interested in attacks which undermine the operational performance and value of the environment under their protection.&amp;nbsp; They are well suited to tackle ordinary malware infections or plug understood exploit activities by using industry best-known-practices, but can easily falter when faced with something unique and specifically targeting only them.&amp;nbsp; They are by design inwardly focused, limited to a technology sandbox of security control configuration or fixing assets within their internal environment.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Hunter teams take a different approach and seek the root cause, namely the threat agent themselves, who are initiating one or more attacks.&amp;nbsp; This may be internal or external to the organization.&amp;nbsp; Not satisfied with simply undermining the latest infraction, they want to quell the problem at the source and eliminate future attacks from the same threat agent, whom may possess the ability to coordinate completely unique and unpredictable maneuvers.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;History shows why this is important.&amp;nbsp; Attackers maintain the combat initiative and determine where, when, and by what method an attack will occur.&amp;nbsp; Defenders typically respond to attacker&amp;#8217;s moves and evolve the defenses to protect against those newly understood methods.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Attackers therefore have an advantage.&amp;nbsp; It takes time, effort, and resources for defenders to recognize they are being attacked, decipher how it is being done, then develop a means to isolate the ongoing breach and block future attacks, and then remediate the affected systems.&amp;nbsp; A threat agent who is determined to attack a specific target can try a number of methods until they succeed.&amp;nbsp; Without threat of themselves being in jeopardy, they can continue varying the assault until they find an approach which works.&amp;nbsp; The only effective way to stop such a persistent threat agent is to dissuade or remove them from the equation.&amp;nbsp; This is where the hunter teams come into play.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Criminal investigators are a good example of the hunter team methodology at work.&amp;nbsp; If someone breaks down a door to rob a bank, the security operations team looks to install stronger doors and maybe a better alarm system.&amp;nbsp; They are inclined to identify and close the vulnerability.&amp;nbsp; A criminal investigator will look to see who is trying to rob banks and target those threat agents.&amp;nbsp; The investigator knows such a robber will continue to evolve their tactics until they succeed.&amp;nbsp; Operations efforts to improve door standards, alarms, etc. are still fine measures which reduce the risk of loss, but the investigator&amp;#8217;s role is just as important.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;When I managed Intel&amp;#8217;s Security Operations Center, I was also the Incident Commander for the company&amp;#8217;s IT Emergency Response Process.&amp;nbsp; This is the team that takes charge whenever the company&amp;#8217;s computer environment is being attacked.&amp;nbsp; I remember during a virus outbreak instructing the security operations team to track, isolate, and clean infected systems, and then turning to my intelligence section leader and asking him to go forth and determine whether the incident was simply a wild virus finding its way through the cracks or was it a directed attack specifically against our company.&amp;nbsp; The challenge I assigned the intelligence lead was so I could understand if the threat agent was specifically targeting Intel Corp with their malicious attacks or if we were simply caught in a broader net cast with a generic attack.&amp;nbsp; This would help me understand whether it was a fluke oversight in the configuration of our defenses or just the beginning of something far worse, potentially a directed campaign against our security infrastructure.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;&lt;strong&gt;Cost and scalability limits will constrain their use, but hunter teams are an important step forward for the industry.&lt;/strong&gt;&amp;nbsp; Cyber security hunter teams have been in limited use for some time and are gaining momentum.&amp;nbsp; The results can be seen in the news.&amp;nbsp; Botnet takedowns, the breaking-up carding rings, shutting down of illegal fraud sites, malware author arrests, and the prosecution of insider theft and sabotage cases are possible because the attackers were targeted.&amp;nbsp; What are not publicized are the equally impressive results which occur quietly in defense of highly protected networks.&amp;nbsp; These teams can be valuable in identifying the root cause of problems, putting the puzzle pieces of seemingly disparate incidents together, identifying the offending attackers, reconnaissance for early alerting, and providing intelligence necessary to interdict and prosecute them.&amp;nbsp; Hunter teams can be a very powerful tool and effective in stopping some of the most grievous threats.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;These specialized capabilities come at a cost.&amp;nbsp; In order to succeed, a combination of brilliant talent, tools, support from legal, and in some cases partnership with law enforcement and industry partners/suppliers/customers, is required.&amp;nbsp; It is a significant investment to establish and maintain a team at a sufficient level to see worthwhile results.&amp;nbsp; Additionally, something intangible is needed; patience.&amp;nbsp; Even the most proficient team needs time to hunt and results can vary greatly.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Beyond costs, hunter teams also have a significant downside.&amp;nbsp; They are not very scalable.&amp;nbsp; Most teams work a single case or issue to closure.&amp;nbsp; Some teams can multi-task, but at a great loss of effectiveness.&amp;nbsp; I have been fortunate to be a part of a world class loss prevention team, specializing in detecting, tracking and prosecuting threat agents.&amp;nbsp; When on the hunt, teams are narrowly focused.&amp;nbsp; Timing is critical.&amp;nbsp; Proficiency matters.&amp;nbsp; Splitting attention to a multitude of separate cases is a recipe for disaster.&amp;nbsp; Compared to security operations teams, which can much more easily multitask and close issues with great speed, hunter teams seem to move in slow motion.&amp;nbsp; But what they lack in the quantity of case closures, they can make up for in results.&amp;nbsp; Overall, the high costs and the lack of scalability are tall barriers which prevent widespread adoption.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Certain organizations, where the cost and scalability headaches are worth the additional security capabilities, should consider the use of hunter team&amp;#8217;s.&amp;nbsp; Environments where assets are targeted by persistent, creative, and resourceful threat agents, seeking explicit objectives, from a specific target will benefit the most.&amp;nbsp; Identifying and understanding these dangerous and capable adversaries, who seek to undermine your security controls and compromise your environment, is an important step in countering massive potential damage.&amp;nbsp; This is not important to most, but for those organizations which are under the pressure of being targeted directly by skillful and motivated threat agents, hunter teams are a viable and attractive option.&amp;nbsp; I strongly suggest financial, defense, sensitive government, and high profile critical infrastructure organizations look into using them.&amp;nbsp; Additionally, I urge security providers and consulting firms to evaluate offering professional hunter team services.&amp;nbsp; The demand over time will continue to grow.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;&lt;strong&gt;Hunter teams are a necessity in the evolution of cyber security.&lt;/strong&gt; They are a pivotal step forward, applying desired pressure to attackers.&amp;nbsp; Yet, they are not the final state. We will continue to evolve the practices and technology of targeting threat agents into something more scalable, affordable, and effective.&amp;nbsp; But for the time being, I welcome hunter teams to the playing field.&amp;nbsp; It is about time you showed up.&amp;nbsp; We really need you.&amp;nbsp; Happy hunting!&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:93d77d58-1056-485b-9a1b-be5e676e28ff] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it@intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">value</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">model</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">risk</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">corporate_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">optimal_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew_rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">threat</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">defense</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attack</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">strategy</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attacker</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">loss</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">security_operations</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">hunter</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">hunter_teams</category>
      <pubDate>Wed, 28 Nov 2012 15:52:17 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2012/11/28/cyber-security-hunter-teams-are-the-next-advancement-in-network-defense</guid>
      <dc:date>2012-11-28T15:52:17Z</dc:date>
      <clearspace:dateToText>5 months, 3 weeks ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/cyber-security-hunter-teams-are-the-next-advancement-in-network-defense</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15548</wfw:commentRss>
    </item>
    <item>
      <title>Inside IT: The Evolving Role of IT</title>
      <link>http://communities.intel.com/community/openportit/blog/2012/11/06/inside-it-the-evolving-role-of-it</link>
      <description>&lt;!-- [DocumentBodyStart:7c5b2860-615b-4dd7-95d5-4e4b8aeebabf] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;It&amp;#8217;s the essence of this podcast series &amp;#8211; the change of IT&amp;#8217;s place in the organization, and the role IT plays in relation to all the business units in the company. In this episode we wanted to turn to someone with a long-term view of the evolution of the IT organization, Kumud Srinivasan. She was recently named the next president of Intel India, one of Intel&amp;#8217;s largest non-manufacturing sites outside the U.S. At the moment, Srinivasan leads IT&amp;#8217;s 1,000-person Silicon, Software and Services organization. In all, she&amp;#8217;s been with Intel for a quarter of a century. I was fortunate enough to get some time with her before she transitioned into her new role. It was a fascinating conversation to be a part of. To hear from someone who really has first hand knowledge of so many changes IT has undergone. For me, she brought a renewed excitement for the next phase of evolution Intel IT will be entering into. In this podcast, we focus on how Information Technology became such an essential part of the enterprise, and how IT&amp;#8217;s role continues to change. You can listen &lt;a class="jive-link-external-small" href="http://connectedsocialmedia.com/intel/6280/inside-it-the-evolving-role-of-it/" target="_blank"&gt;here.&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:7c5b2860-615b-4dd7-95d5-4e4b8aeebabf] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it@intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it_business_value</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel_it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">strategy</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it_best_practices</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">kumud_srinivasan</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">evolving_it</category>
      <pubDate>Tue, 06 Nov 2012 18:53:43 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2012/11/06/inside-it-the-evolving-role-of-it</guid>
      <dc:date>2012-11-06T18:53:43Z</dc:date>
      <clearspace:dateToText>6 months, 2 weeks ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/inside-it-the-evolving-role-of-it</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15453</wfw:commentRss>
    </item>
    <item>
      <title>McAfee 2012 FOCUS security conference is a success</title>
      <link>http://communities.intel.com/community/openportit/blog/2012/10/26/mcafee-2012-focus-security-conference-is-a-success</link>
      <description>&lt;!-- [DocumentBodyStart:b397b844-b494-4cbe-80a6-11d938dc1891] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15439-230308/McAfee+FOCUS+Conference+2012.jpg"&gt;&lt;img alt="McAfee FOCUS Conference 2012.jpg" class="jive-image jiveImage" height="463" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15439-230308/300-463/McAfee+FOCUS+Conference+2012.jpg" style="float: right;" width="300"/&gt;&lt;/a&gt;&lt;span style="color: #000000;"&gt;Every year, McAfee hosts the FOCUS security conference to pull together its customers, partners, and industry leaders.&amp;nbsp; The conference informs and educates attendees on the latest threats, trends, best-known-methods, and showcases McAfee's new technologies and services.&amp;nbsp; This year's conference was another grand event and success, with a 20% attendee increase over last year, two keynote speeches, and over 70 targeted, highly technical sessions organized into 14 tracks.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;The first day focused heavily on technologies and how the threat landscape is manifesting new types of attacks.&amp;nbsp; Mike DeCesare, co-president of McAfee, and Michael Fey, McAfee CTO, did a wonderful job of outlining McAfee's strategy and how it aligns to legacy and emerging attack methodologies.&amp;nbsp; DeCesare clearly showed how McAfee&amp;#8217;s acquisition by Intel is paying dividends with the integration of Intel/McAfee technology, resulting in DeepSAFE/Defender and an ePO-vPro AMT extensibility.&amp;nbsp; Fey and his team did a real-time demonstration of how new malicious malware continues to evolve and is a real threat, by showing the audience a new critical level Denial-of-Service takedown of a PC, MacOS, and Android system.&amp;nbsp; They explained how the DeepSAFE/Defender product could prevent such attacks and how ePO with Intel vPro AMT technology can recover PC's remotely without the need of a physical touch by a technician.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;On day-2, Mike Fey announced a new strategy to advance both the capabilities and economic automation of security controls through a more comprehensive and open ecosystem.&amp;nbsp; It will leverage the vast McAfee GTI sensor cloud to identify tactical opportunities and advise customer environments, which can benefit at their discretion, by instituting local rules and even share their data to 3rd party services for advanced analysis and management.&amp;nbsp; This will finally allow customers finer control of risk decisions for their environment, based upon near real-time intelligence gathered worldwide, to rapidly institute and easily maintain technical rules which may be inappropriate at larger scales or for broader communities, but fit perfectly for their local environment and risk appetite.&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;On the technology side, what was talked to last year with great anticipation, was shown in practice in this year's conference.&amp;nbsp; In one of the most attended technical sessions, a team of Intel and McAfee speakers showed the architecture and spoke to the benefits of Deep Defender.&amp;nbsp; In the past year, Deep Defender has become available and activations have been aggressive.&amp;nbsp; Audiences were impressed with the capabilities and game-changing potential of this exclusive offering.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Deep Defender and other DeepSAFE technologies represent a disruptive change in the balance between how attackers and defenders interact.&amp;nbsp; It has the capability of shifting the initiative to defenders, forcing the attackers into an undesirable position of responding to innovative detection and response technology.&amp;nbsp; This is very good news for McAfee customers benefiting from the Deep Defender.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;For those who explored the trade show floor, they were able to catch a glimpse of future Intel/McAfee technologies which may come to market.&amp;nbsp; Demonstrations of secure boot technology, secure storage, virtualized IPS, secure video/audio, and others were available with lab folks to discuss the potential.&lt;/span&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span style="color: #000000;"&gt;Overall, this year&amp;#8217;s McAfee FOCUS conference was great investment of time for customers, partners, technologists, and security veterans.&amp;nbsp; I can&amp;#8217;t wait to see what next year&amp;#8217;s conference has in store.&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:b397b844-b494-4cbe-80a6-11d938dc1891] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it@intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">value</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">model</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">conference</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">risk</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">optimal_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew_rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">rosenquist</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">threat</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">attack</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">strategy</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">matthew</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">mcafee</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">loss</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">focus</category>
      <pubDate>Fri, 26 Oct 2012 16:41:47 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2012/10/26/mcafee-2012-focus-security-conference-is-a-success</guid>
      <dc:date>2012-10-26T16:41:47Z</dc:date>
      <clearspace:dateToText>6 months, 4 weeks ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/mcafee-2012-focus-security-conference-is-a-success</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15439</wfw:commentRss>
    </item>
    <item>
      <title>What a difference a few months make - Intel IT Mid-Year Report</title>
      <link>http://communities.intel.com/community/openportit/blog/2012/09/14/what-a-difference-a-few-months-make--intel-it-mid-year-report</link>
      <description>&lt;!-- [DocumentBodyStart:8168427b-423e-4aaa-8a6d-4bc2a4500bd9] --&gt;&lt;div class="jive-rendered-content"&gt;&lt;p&gt;What a difference a few months make.&amp;nbsp; I&amp;#8217;ve been Intel&amp;#8217;s CIO for the past 8 months&amp;#8212;a long time given the speed at which the business and IT are changing.&amp;nbsp; This became obvious in preparing our 1st mid-year report.&amp;nbsp; Annual reports no longer seem sufficient.&amp;nbsp; In our report, you&amp;#8217;ll find insights, lessons learned and the results we are striving for as we collaborate with Intel&amp;#8217;s business units to drive business growth, employee productivity, and efficiencies across Intel.&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Here&amp;#8217;s a glimpse into some of the content included in the mid-year report:&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;How the development of advanced business intelligence solutions across Intel is yielding significant business results in the areas of manufacturing, security, sales and marketing and product design.&lt;/li&gt;&lt;li&gt;How the deployment of Intel&amp;#8217;s first open source private cloud is enabling us to advance our cloud beyond compute IaaS and deliver services faster and cheaper.&lt;/li&gt;&lt;li&gt;How our BYOD program has helped Intel gain 2.75M hours of employee productivity in the past 6 months.&lt;/li&gt;&lt;li&gt;How social media techniques like crowdsourcing and gamification are providing insights into improving Intel, advancing our business and developing new products&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a href="http://communities.intel.com/servlet/JiveServlet/showImage/38-15369-230036/MID-YEAR+infographic.JPG"&gt;&lt;img alt="MID-YEAR infographic.JPG" class="jive-image" height="900" src="http://communities.intel.com/servlet/JiveServlet/downloadImage/38-15369-230036/420-900/MID-YEAR+infographic.JPG" style="margin-right: auto; margin-left: auto; display: block;" width="420"/&gt;&lt;/a&gt;&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Culture change is another big focus for the leaders in IT. With the landscape changing all around us, we are focused upon building a culture of &amp;#8220;possibility thinking&amp;rdquo; across IT, one where our employees challenge the status quo, take informed risks and use disciplined collaboration to drive changes into the environment and innovate (see the story about &amp;lsquo;IT on the Go&amp;#8217; vending machines that dispense PC peripherals).&lt;/p&gt;&lt;p style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I invite you to check out Intel &lt;span lang="EN" style="font-family: 'Tahoma','sans-serif'; color: #1f497d; font-size: 10pt;"&gt;&lt;a class="jive-link-external-small" href="http://www.intel.com/content/www/us/en/it-management/intel-it-best-practices/intel-it-midyear-performance-report-2012.html" target="_blank"&gt;IT&amp;#8217;s mid-year report &lt;/a&gt;&lt;/span&gt;&lt;span style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;online &lt;/span&gt;and please don&amp;#8217;t forget to share your thoughts and insights with me here or connect with me on Twitter, @kimsstevenson.&lt;/p&gt;&lt;/div&gt;&lt;!-- [DocumentBodyEnd:8168427b-423e-4aaa-8a6d-4bc2a4500bd9] --&gt;</description>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it@intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">roi</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">data_center</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">corporate_security</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">information</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">cost_savings</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">intel_it</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">strategy</category>
      <category domain="http://communities.intel.com/community/openportit/blog/tags">it_best_practices</category>
      <pubDate>Fri, 14 Sep 2012 18:33:44 GMT</pubDate>
      <author>webadmin@intel.com</author>
      <guid>http://communities.intel.com/community/openportit/blog/2012/09/14/what-a-difference-a-few-months-make--intel-it-mid-year-report</guid>
      <dc:date>2012-09-14T18:33:44Z</dc:date>
      <clearspace:dateToText>8 months, 1 week ago</clearspace:dateToText>
      <clearspace:objectType>0</clearspace:objectType>
      <wfw:comment>http://communities.intel.com/community/openportit/blog/comment/what-a-difference-a-few-months-make--intel-it-mid-year-report</wfw:comment>
      <wfw:commentRss>http://communities.intel.com/community/openportit/blog/feeds/comments?blogPost=15369</wfw:commentRss>
    </item>
  </channel>
</rss>

