Home > Intel Communities > Open Port IT Community > IT@Intel > Blog > Tags > corporate_security
1 2 Previous Next

IT@Intel Blog

19 Posts tagged with the corporate_security tag
1

Measures generate data and metrics organize data to generate information.  The difference between ‘data’ and ‘information’, the former is something you know, the latter is something you use.

 

Everyone wants information security to be easy.  Wouldn’t it be nice if it were simple enough to fit snugly inside a fortune cookie?  Well, although I don’t try to promote such foolish nonsense, I do on occasion pass on readily digestible nuggets to reinforce security principles and get people thinking how security applies to their environment.

 

The key to fortune cookie advice is ‘common sense’ in the context of security.  It must be simple, succinct, and make sense to everyone, while conveying important security aspects.

 

Fortune Cookie advice for September, 2009:

 

Data and Metrics.jpg

 

Measures generate data and metrics organize data to generate information. 

The difference between ‘data’ and ‘information’, the former is something you know,

the latter is something you use.

 

In security, it is easy to confuse the terms ‘measures’ and ‘metrics’.  They are two distinct but related concepts.  Measurement theory incorporates the scale of nominal, ordinal, interval, ratio, and absolute.  These scales are used to measure something, with the output being data.  Metrics however are about analysis and intelligent decision making.  Metrics translate data into meaningful information which will support decision making.  Data is something you know.  Information is something you use to make decisions.

 

Fortune Cookie Security Advice - No Royal Road to Security - July 2008

Fortune Cookie Security Advice - Strategic Compettive Secure - June 2009

Fortune Cookie Security Advice - May 2008

Fortune Cookie Security Advice - June 2008

Fortune Cookie Security Advice - August 2008

Fortune Cookie Security Advice - September 2008

Fortune Cookie Security Advice - November 2008

Fortune Cookie Security Advice - December 2008

Fortune Cookie Security Advice - January 2009

Fortune Cookie Security Advice - February 2009

Fortune Cookie Security Advice - March 2009

Fortune Cookie Security Advice - April 2009

Fortune Cookie Security Advice - May 2009

1 Comments Permalink
0

There is no Royal Road to understanding and achieving information security

 

Everyone wants information security to be easy.  Wouldn’t it be nice if it were simple enough to fit snugly inside a fortune cookie?  Well, although I don’t try to promote such foolish nonsense, I do on occasion pass on readily digestible nuggets to reinforce security principles and get people thinking how security applies to their environment.

 

The key to fortune cookie advice is ‘common sense’ in the context of security.  It must be simple, succinct, and make sense to everyone, while conveying important security aspects.


Fortune Cookie advice for July, 2009:

 

Road1.jpg

There is no Royal Road to understanding and achieving information security

 

Taking a line of thought from Euclid, there is no easy route to understand the ever changing complexities of information security.

We exist in an era where information security is both exciting and complex. 

 

The rapid evolution of information technology, increasing number of targets, and the explosive development of creative tools attackers employ all contribute to a dynamic environment where a continual struggle between aggressors and defenders shifts the balance on a daily basis.  Only through hard work can security professionals effectively pursue achieving an optimal level of security which manages the tradeoffs of cost against controlling impacts and effectiveness of attacks.  Achieving information security is an exercise in hard work, diligence, consistency, and flexibility to adapt technology and behaviors in meeting the challenge.

       

 

Fortune Cookie Security Advice - Strategic Compettive Secure - June 2009

Fortune Cookie Security Advice - May 2008

 

Fortune Cookie Security Advice - May 2008

Fortune Cookie Security Advice - June 2008

Fortune Cookie Security Advice - August 2008

Fortune Cookie Security Advice - September 2008

Fortune Cookie Security Advice - November 2008

Fortune Cookie Security Advice - December 2008

Fortune Cookie Security Advice - January 2009

Fortune Cookie Security Advice - February 2009

Fortune Cookie Security Advice - March 2009

Fortune Cookie Security Advice - April 2009

Fortune Cookie Security Advice - May 2009

0 Comments Permalink
0

Think strategic.  Act competitive.  Be secure.

 

Everyone wants information security to be easy.  Wouldn’t it be nice if it were simple enough to fit snugly inside a fortune cookie?  Well, although I don’t try to promote such foolish nonsense, I do on occasion pass on readily digestible nuggets to reinforce security principles and get people thinking how security applies to their environment.

 

The key to fortune cookie advice is ‘common sense’ in the context of security.  It must be simple, succinct, and make sense to everyone, while conveying important security aspects.

 


Fortune Cookie advice for June, 2009:

 

 

Strategy.gif

Think strategic.  Act competitive.  Be secure.

 

Security is a sustaining commitment where long term planning provides a distinct advantage.  Threats are derived from intelligent adversaries.  Success requires maneuvering in a competitive manner to remain secure.

 

 

 

 

Fortune Cookie Security Advice - May 2008

Fortune Cookie Security Advice - June 2008

Fortune Cookie Security Advice - August 2008

Fortune Cookie Security Advice - September 2008

Fortune Cookie Security Advice - November 2008

Fortune Cookie Security Advice - December 2008

Fortune Cookie Security Advice - January 2009

Fortune Cookie Security Advice - February 2009

Fortune Cookie Security Advice - March 2009

Fortune Cookie Security Advice - April 2009

Fortune Cookie Security Advice - May 2009

0 Comments Permalink
0

Optimal security must not only be attained, but also sustained over time.  A good security strategy must be forward thinking to understand how intervention and continual maintenance will be needed, then implement those capabilities as part of a complete service deployment.

 

Balance.gif

'Optimal Security' is the right balance of security spending and losses prevented where business acceptable losses are achieved.  It changes often and likely maintains different targets for the dissimilar parts of the entity.

 

Organizations are likely to mandate security expectations which typically manifests in a set of configurations, specifications, and operating standards.  The risk is these security controls may be relatively static and entrenched.

 

Establishing a baseline security is a good practice, but in order to remain effective it must adapt to changes in the environment by remaining dynamic to keep in lock-step with rapidly changing threats, vulnerabilities, and resulting exposures.  It must be a fluid posture, able to rapidly change based upon different internal priorities and external changes.  Sustaining business structure must be designed to continually predict areas needing modification and support design and deployment of those changes.  Rigid security postures lack the ability to remain effective over time and are likely derived by an equally rigid infrastructure which will struggle to adapt to new threats and changes within the organization.  Design security to be flexible and you enable the service to keep up with the continual changes in the information branch of security.

 

I recently spoke with an organization who had established a security posture which relied heavily on a hardened OS and application build for their systems.  At the time, they deployed a platform which took into consideration all the best configurations for hardening.  They were so confident they had satisfied security requirements they considered the problem solved.  They integrated the security design into their normal platform refresh cycle of system replacement every few years.  They never comprehended the fact they would need to continually update the build to compensate for changes in threats, new vulnerabilities and malware, and evolving business usage models.

 

The platform’s security, which initially was strong, began to quickly erode.  With no internal mechanism to identify when changes needed to be made, nor the testing and distribution capability, they soon found themselves in a situation where they were responding to individual incidents and changing systems one at a time based upon particular end-user needs.  This created inconsistencies in the builds which was more difficult to support.  Without proper forethought, the security team turned themselves into a firefighting organization, losing the initiative in the war of security.

 

This is one simple technical example.  The same holds true for the expanse of automated solutions and behavioral security controls as well.  Highly effective and efficient security strategies are forward thinking and understand how intervention and continual maintenance will be needed, then implement those capabilities as part of a complete service deployment.  Overall, the concept of ‘optimal security’ is one of fluid adaptations of controls to meet an ever changing target for risk acceptance.

0 Comments Permalink
0

Everyone wants information security to be easy.  Wouldn’t it be nice if it were simple enough to fit snugly inside a fortune cookie?  Well, although I don’t try to promote such foolish nonsense, I do on occasion pass on readily digestible nuggets to reinforce security principles and get people thinking how security applies to their environment.

 

Common Sense
I think the key to fortune cookie advice is ‘common sense’ in the context of security.  It must be simple, succinct, and make sense to everyone, while conveying important security aspects.

 

Fortune Cookie advice for May:

 

Fear and anxiety will lead to poor risk analysis conclusions

 

Stay focused on the available facts, use a dose of reality to fill in the gaps, and trust reliable risk models to generate analytical conclusions.

 

Excerpt from the Traps of Measuring Security Blog: In our world of information security, we must take a step back from the limitations and biases we possess and stay true to proper forms of analysis in order to see the truth.  It is far too easy for us to slip backwards and inaccurately measure risk of situations we don’t understand.  Let’s continue to remind each other of this fact and challenge risk assessments, especially in situations where concern is more prevalent than fact.

 

So am I contributing to the problem of over simplifying security? Or am I reaching out to those who might not take an inordinate amount of time necessary to understand the complexities and nuances of our industry? You decide and feel free to share your knowledge-nuggets.

 

Fortune Cookie Security Advice - April 2009

Fortune Cookie Security Advice - May 2008

Fortune Cookie Security Advice - June 2008

Fortune Cookie Security Advice - September 2008

Fortune Cookie Security Advice - November 2008

Fortune Cookie Security Advice - August 2008

0 Comments Permalink
0

Everyone wants information security to be easy.  Wouldn’t it be nice if it were simple enough to fit snugly inside a fortune cookie?  Well, although I don’t try to promote such foolish nonsense, I do on occasion pass on readily digestible nuggets to reinforce security principles and get people thinking how security applies to their environment.

 

Common Sense
I think the key to fortune cookie advice is ‘common sense’ in the context of security.  It must be simple, succinct, and make sense to everyone, while conveying important security aspects.

 

Fortune Cookie advice for April:

 

Capability, intent, and focus are the defining aspects to quickly prioritize threats.


The world of information security threats is vast.  We can easily be overwhelmed with different components, processes, impacts, and concerns.  Quickly identifying the benign from the urgent is a competitive advantage.  In order to organize and prioritize, we must have a consistent method to judge criteria.

 

I submit the three most compelling aspects are related to the attacker who is committing the violation.  Their capability to do harm, defines the likelihood of a successful attack.  The intent of the attacker has significant implications for the likelihood to detect activity and the persistence of continuing attempts.  Lastly, the focus of the attack, whether it is targeting you specifically or just looking for opportunistic victims, completes the overlapping picture to understand the precision of activities.

 

Given these three aspects, a quick evaluation can be made to determine the severity of the threat and attacks.  Of course this is just the first step necessary for triage, while a full evaluation should be conducted for the areas which rise to the top of the severity list.

 

Fortune Cookie Security Advice - May 2008

Fortune Cookie Security Advice - June 2008

Fortune Cookie Security Advice - August 2008

Fortune Cookie Security Advice - September 2008

Fortune Cookie Security Advice - November 2008

Fortune Cookie Security Advice - December 2008

Fortune Cookie Security Advice - January 2009

Fortune Cookie Security Advice - February 2009

Fortune Cookie Security Advice - March 2009

0 Comments Permalink
0

Everyone wants information security to be easy.  Wouldn’t it be nice if it were simple enough to fit snugly inside a fortune cookie?  Well, although I don’t try to promote such foolish nonsense, I do on occasion pass on readily digestible nuggets to reinforce security principles and get people thinking how security applies to their environment.

 

Common Sense
I think the key to fortune cookie advice is ‘common sense’ in the context of security.  It must be simple, succinct, and make sense to everyone, while conveying important security aspects.

 

Fortune Cookie advice for March:

 

The most successful civilizations rose to power, not by ignoring security, rather they ensured greatness through strategy and achievement.

 

Rosenquist Sig pic2.gif

 

For this month’s advice, you are a victim of eye-candy.  I created this slide for a recent presentation, to capture the audience’s attention and rouse some brain juices flowing.

 

The general message does hold true.  Security strategy is the long term endeavor to protect an organization’s future.  If the war is fought thinking exclusively about one battle at a time, you will lose the tide of initiative and ultimately spend most of resources responding to your opponent’s attacks.  If however, we keep in mind the end goals and manage to a state of optimal security, we can progress towards an advantageous and sustainable level of security.

 

We don’t have to win every fight, lock every door, and close every exposure.  Instead, we are in a position to selectively choose our victories to maximize our capabilities.  Our victory is finding the right balance of risk and costs.  Thinking strategically, in concert with tactical actions, will drive clarity for the desired end-state of security.

 

In practical terms:

  • Have a plan and communicate it
  • Understand the business need for security
  • Prioritize security initiatives based upon their value
  • Develop an overall defense-in-depth capability, with interlocking services
  • Characterize the most severe threats and identify the most likely and impactful exposures
  • Know what you are protecting
  • Be cognizant of when you need more, have enough, or too much security

 

My moment of enlightenment is over.  It is time to get back to the grind of the security firefights.  But my strategy is never far from my mind.  It defines the boundaries and guides my tactical decisions.

0 Comments Permalink
0

Everyone wants information security to be easy.  Wouldn’t it be nice if it were simple enough to fit snugly inside a fortune cookie?  Well, although I don’t try to promote such foolish nonsense, I do on occasion pass on readily digestible nuggets to reinforce security principles and get people thinking how security applies to their environment.

 

Common Sense

I think the key to fortune cookie advice is ‘common sense’ in the context of security.  It must be simple, succinct, and make sense to everyone, while conveying important security aspects.

 

Fortune Cookie advice for February:

 

A worthless metric is one which fails to drive decisions, even when the metric result radically changes.

 

The world of information security is full of metrics.  Sadly, many are worthless.  A valuable metric is one which drives decisions.  Unfortunately, our industry also persists in publishing metrics which may nicely fill graphs and catch attention with flash, but in the end are meaningless.  The true test: can it facilitate change.

 

One of my favorite metrics to pick on is a graphic which shows the percentage of internet attacks by country.  Provided every year, this metric presentation is visually stunning, usually consisting of a background of the globe with offending countries in vibrant colors.  It is clear, attention grabbing, and even interesting in a sublime way.  Media outlets love the eye candy.  But at the end of the day, the data is meaningless.  It does not really matter where attacks initiate from.  Organizations will not change their course of security if the numbers shifted drastically over time.  The proximity and country of origin simply does not matter.  The number and types of attacks are far more relevant, but not the division of origin based upon international borders.

 

Whenever we are presented with metrics, we must think critically to understand their value.  Don’t get caught up in beautiful graphics or catchy titles.  Challenge everything.  Would you do something differently in your approach to securing your environment if the data changed radically?  If not, then move along, nothing here to see.

 

Fortune Cookie Security Advice - January 2009

Fortune Cookie Security Advice - December 2008

Fortune Cookie Security Advice - November 2008

Fortune Cookie Security Advice - September 2008

Fortune Cookie Security Advice - August 2008

Fortune Cookie Security Advice - June 2008

Fortune Cookie Security Advice - May 2008

0 Comments Permalink
1

Everyone wants information security to be easy.  Wouldn’t it be nice if it were simple enough to fit snugly inside a fortune cookie?  Well, although I don’t try to promote such foolish nonsense, I do on occasion pass on readily digestible nuggets to reinforce security principles and get people thinking how security applies to their environment.

 

Common Sense

I think the key to fortune cookie advice is ‘common sense’ in the context of security.  It must be simple, succinct, and make sense to everyone, while conveying important security aspects.

 

Fortune Cookie advice for January:

 

Insider threats will always outpace external threats.

 

Insiders, those people you trust at some level, represent a significantly greater risk than outsiders.  External threats may have a numerical advantage, but insiders have the access to cause staggering losses.  They possess the permissions, system and process knowledge, authority, visibility to critical systems and valuable resources, and can more easily circumvent existing behavioral controls.  Overall, insiders are tougher to detect, investigate, interdict, and prosecute.  Security organizations may inadvertently reinforce this disproportional risk by focusing on thwarting external threats, leaving insiders more latitude to conduct undesired activities.

 

It is a frustrating problem for security to address.  There are complex political, business, technical, legal, and behavioral aspects which plague efforts.  Due to their nature, insiders have an advantage, can be stealthier, and easily overlooked.  Security organizations may discount this slippery threat or lose sight of this aspect and exclusively focus on more noisy external threats.  I believe insiders represent the greatest challenge in the security industry.

 

Every security organization should purposely put in mechanisms to keep the ‘insider threat’ in the equation.  Regularly talk about it.  Do an annual risk assessment for senior staff.  If it makes sense, launch projects to manage the risk.  Anything!  Just don’t let it slip from memory.  Don’t overlook the risks.  The challenge is tough and may appear insurmountable, but that is not just cause to ignore the problem.  This is a battle worthy of fighting.

 

Fortune Cookie Security Advice - December 2008

Fortune Cookie Security Advice - November 2008

Fortune Cookie Security Advice - September 2008

Fortune Cookie Security Advice - August 2008

Fortune Cookie Security Advice - June 2008

Fortune Cookie Security Advice - May 2008

1 Comments Permalink
0

Everyone wants information security to be easy. Wouldn’t it be nice if it were simple enough to fit snugly inside a fortune cookie? Well, although I don’t try to promote such foolish nonsense, I do on occasion pass on readily digestible nuggets to reinforce security principles and get people thinking how security applies to their environment.

Common Sense

I think the key to fortune cookie advice is ‘common sense’ in the context of security. It must be simple, succinct, and make sense to everyone, while conveying important security aspects.

Fortune Cookie advice for December:

Be mindful of the security message you deliver to your customers and how it is interpreted

Rallying your populace to be security savvy is a worthwhile investment and must be approached with the appropriate diligence. It is not enough to haphazardly deliver security information and walk away. If it is perceived as ‘junk-mail’, it will be treated as such. Information security must be understood and applied in order to make a difference. This embrace will only occur if the audience understands not only the message, but also why it is important and the overall context. Every good communication program draws in the audience by letting them know how it applies and benefits them.

If we want to be successful, we have an obligation to understand what is being absorbed and how it is being interpreted.

Andy, ITGuy has a great post (check out the picture for a good laugh).

“How we communicate our security plans has to be in a way that the user will understand and that will make them want to work with us”.  This is key, as ultimately it is a partnership between dedicated security folks and the organization they protect.

Additionally, Mike Rothman has some great follow-up comments which I think nails the right perspective:

“effective communication is based upon the perception of the person on the other end”. Sounds basic, but how often do we ignore this fundamental principle in our rush to deliver our message?

If you are interested in good security insights, consider subscribing to Andy,ITGuy and Mike Rothman’s blogs. They mix perspective, humor, to timely issues.

So am I contributing to the problem of over simplifying security? Or am I reaching out to those who might not take an inordinate amount of time necessary to understand the complexities and nuances of our industry? You decide and feel free to share your knowledge-nuggets.

Fortune Cookie Security Advice - November 2008

Fortune Cookie Security Advice - September 2008

Fortune Cookie Security Advice - August 2008

Fortune Cookie Security Advice - June 2008

Fortune Cookie Security Advice - May 2008

0 Comments Permalink
0

Measuring the value of information security programs is difficult and a problem for the entire industry. Come join us for a 3 part series discussing the challenges, how Intel is taking a practical approach, and where the future may take information security metrics.

 

Last week, Matthew Rosenquist & I discussed an actual Intel case study with Enrique Herrera. In this last of the three part series, we will discuss some practical approaches to determine the value of information security initiatives, including some future-looking ideas, and how security metrics might be implemented on a national scale.

 

The show is 30 minutes, starting tomorrow (June 4) at 10:30 PDT. To listen in, go to the OpenPort home page, and a little ways down on the left side you'll find the BlogTalk Radio link. Take that link and follow the instructions. You don't need an account to listen or participate in the discussion. If you can't make it live, you can also find the recorded sessions there too, after the show.

 

See you there!

 

Return On Security Investment - BlogTalk Radio

Wednesday, June 4, 2008

10:30 AM PDT / 1:30 EDT

http://communities.intel.com/index.jspa

0 Comments Permalink
1

Measuring the value of information security programs is difficult and a problem for the entire industry. Come join us for a 3 part series discussing the challenges, how Intel is taking a practical approach, and where the future may take information security metrics.

 

Last week, Matthew Rosenquist & I discussed why measuring ROSI is important, and the very difficult challenges in doing so. In this second of the three part series, we will discuss a practical approach to determine value of information security initiatives. Joining Matt & myself this week from Costa Rica is Enrique Herrera, who will discuss an actual Intel case study.

 

The show is 30 minutes, starting tomorrow (May 29) at 10:30 PDT. To listen in, go to the OpenPort home page, and a little ways down on the left side you'll find the BlogTalk Radio link. Take that link and follow the instructions. You don't need an account to listen or participate in the discussion. If you can't make it live, you can also find the recorded sessions there too, after the show.

 

See you there!

 

Return On Security Investment - BlogTalk Radio

Thursday, May 29, 2008

10:30 AM PDT / 1:30 EDT

http://communities.intel.com/index.jspa

1 Comments Permalink
1

Come join us!

 

The success of a security program is measured by an event that doesn't happen, so how do you know if you were successful? Matt Rosenquist, Intel’s Information Security Strategist will do a three-part series on Blog Talk Radio discussing the difficulties of measuring a security program.

 

Segment 1: May 20th at 10:30 AM (Pacific): The Problem of Measuring Security Part 1 of 3


Segment 2: May 29th at 10:30 AM (Pacific): Return on Security Investment - Intel Cast Study Part 2 of 3


Segment 3: June 4th at 10:30 AM (Pacific): Future State of Security Measurement Part 3 of 3


 

Our Blog Talk Radio segments are interactive and we will be taking live calls from listeners (Call-in Number: (347) 326-9831) and live chat over the Web.

 


What are your questions for Matt around security metrics?

1 Comments Permalink
1

In the summer of 2002 I received a phone call from one of Intel’s senior information security experts, Brian Willis. Brian had just returned from an event in Washington D.C. that he was very excited about. Gartner and the U.S. Naval War College had hosted a three-day seminar-style war game called “Digital Pearl Harbor.” The purpose of the war game was to involve industry for the first time in investigating the possibilities for catastrophic attack of and through the U.S. internet system. They had invited a number of private corporations to participate in this new methodology, and Brian attended as Intel’s representative.

 

At the time I was working on some risk modeling techniques, so Brian figured I’d be interested in what he had learned. He called and started with, “We have to do this!” He described the event and the possibilities he saw for Intel. The event was very successful and provided much valuable information to the sponsors as defenders, but Brian saw a different aspect. As an “attacker” in the game, he saw how easily and dynamically the attackers in cyberspace were able to build their own systems, business as well as technological, and emphasize their own priorities. The visibility that the game gave into this process came as a bit of a surprise to him and other participants, and Brian recognized how valuable this perspective was to understanding risks facing any defender.

 

So we decided to stage something similar at Intel, but focusing on the attacker viewpoint rather than the defenders. Although this is somewhat different than a classical war game, we kept the basic process (and the name “war game”) to keep it different from other risk assessment methods. It wasn’t easy to come up with our own game. At the time, there was very little about war gaming that wasn’t based on military objectives, and it was almost all from the defender’s point of view. I even called the U.S. Naval War College; they were very interested and supportive but had little they could share. But through the collective effort of many people, by the summer of 2003 we had put together our own Intel Digital Wargame. The game event itself lasted for two days, and involved nearly every Intel business unit organized in six cells spread across three U.S. cities. It was wildly successful, beyond our expectations, and all the participants said it was exhausting but also both the most instructive and the most fun event they had attended in a long time.

 

Since then, we have conducted a number of smaller games and continue to have good success with the process. Along the way we have refined it, although we consider it still very much a work in progress. The paper published here is a detailed description of our current process. If war gaming sounds interesting to you, or you are already doing something similar, I hope this will be of use to you. In any case, I would like to hear of your thoughts or experiences or best practices in this area, as we are always looking to learn and improve.

 

Wargames: Serious Play that Tests Enterprise Security Assumptions

1 Comments Permalink
0

In this videocast, I talk about some of the key tools used at Intel to understand current and future risks and threats (including secret agents!)

 

Some links to additional information are below...


 


 

What are the tools you use in managing risks? Are they off-the-shelf or developed internally? And do you ever get to wear a tux while at work?


 

Here are some links for more information:

 

My presentation on corporate infosec Wargaming for the upcoming Intel Premier IT Professional (IPIP) events:

Security Wargarming Best Practices

 

Our Threat Agent Library is available for anyone to use. A whitepaper describing it is here:

Threat Agent Library Helps Identify Information Security Risks

 

Matthew Rosenquist's latest blog on security is a great discussion about Security in Depth:

Defense in Depth Information Security Strategy

0 Comments Permalink
1 2 Previous Next