<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-8867134452295701909</atom:id><lastBuildDate>Mon, 28 Nov 2011 00:40:53 +0000</lastBuildDate><category>ethics</category><category>Firewalls</category><category>PCI</category><category>bpo</category><category>GRC</category><category>phones</category><category>authentication</category><category>Cloud Computing</category><category>risk management</category><category>MPLS</category><category>XML</category><category>wsvvdkn</category><category>vulnerability_management</category><category>data center</category><category>outsourcing</category><category>IT-GRC</category><category>products</category><category>VPN</category><category>SaaS</category><category>MSSP BPO</category><category>Web Application Security</category><category>configuration</category><category>metrics</category><category>Security Awareness</category><category>remote access</category><category>compliance</category><category>patching</category><category>windows</category><category>operations</category><category>endpoint</category><category>RSA Conference</category><category>career</category><category>DLP SaaS</category><category>architecture</category><category>IDS IPS Open Source</category><category>WAF</category><category>Mergers and Acquisitions</category><title>Information Security  Q&amp;A</title><description>Everyday questions and answers on Information Security..</description><link>http://security.24kasim.org/</link><managingEditor>noreply@blogger.com (Yinal Ozkan)</managingEditor><generator>Blogger</generator><openSearch:totalResults>112</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/InformationSecurityQa" /><feedburner:info uri="informationsecurityqa" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><creativeCommons:license>http://creativecommons.org/licenses/by/2.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by/2.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><feedburner:emailServiceId>InformationSecurityQa</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-4435750695171488614</guid><pubDate>Wed, 26 Oct 2011 02:59:00 +0000</pubDate><atom:updated>2011-10-31T22:52:53.550-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">IT-GRC</category><category domain="http://www.blogger.com/atom/ns#">GRC</category><title>ITGRC Software Vendors 2011</title><description>Here is the most "far-reaching" list of IT-GRC vendors that you can find on the Internet.&lt;br /&gt;
&lt;br /&gt;
I stand by my statement that IT-GRC &lt;a href="http://security.24kasim.org/2008/12/why-grc-does-not-stick.html"&gt;does not stick due to several reasons.&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
My previous posts with risk management frameworks and tools are &lt;a href="http://security.24kasim.org/2009/08/it-governance-risk-and-compliance-itgrc.html"&gt;at this link&lt;/a&gt; (I will update risk management tools sometime this year)&lt;br /&gt;
&lt;br /&gt;
Currently there are 4 types of companies at IT GRC market:&lt;br /&gt;
&lt;br /&gt;
1- IT-GRC vendors: IT Risk Management solutions with integrated workflow and compliance features.&lt;br /&gt;
2- Enterprise GRC vendors: ERM (Enterprise Risk Management) tools expanding into IT GRC space -sometimes called eGRC&lt;br /&gt;
3- Glorified Access Control Tools: This is the world of SAP, Oracle and the related vendors ( note to the vendors - GRC is not SoD - Segregation of Duties)&lt;br /&gt;
4- Compliance Management Tools (just targeting without risk focus)&lt;br /&gt;
&lt;br /&gt;
Market is not as dynamic as 2010.IT-GRC and Enterprise Risk Management (ERM) solutions have not unified (yet). There are apps for contract management, vendor management, trading risk management, ethics management, asset management, policy management, workflow management, financial risk management, quality management, hazard management, incident management etc..All we need on the other hand is comprehensive authoritative templates, and a solid / easy to use unified GRC framework.. IT-GRC is a good starting point for merging risk management of all these activities. The effort required for this usually delays the actual quick wins IT-GRC.&lt;br /&gt;
&lt;br /&gt;
2010 -11 Changes:&lt;br /&gt;
1- IBM acquired OpenPages and the Algorithmics Inc&lt;br /&gt;
2- Software AG acquired IDS Sheer&lt;br /&gt;
3- RSA Archer started bundle enVision (SIEM) and RSA DLP&lt;br /&gt;
4- Paisley's latest name is Accelus at Thomson Reuters&lt;br /&gt;
5- Strategic Thought is now ActiveRisk (name change)&lt;br /&gt;
6-&amp;nbsp;&lt;a href="http://http//www.checkpoint.com" target="_blank"&gt;Check Point&lt;/a&gt;&amp;nbsp;(a security veteran in conventional security software - firewalls, ips, endpoint security, dlp, drm etc) acquired&amp;nbsp;&lt;a href="http://www.easy2comply.com/" target="_blank"&gt;Easy2Comply&lt;/a&gt;&amp;nbsp;provider Dynasec as of 10/31/201&lt;br /&gt;
&lt;br /&gt;
Before moving forward, please remember that &lt;a href="http://office.microsoft.com/en-us/excel"&gt;Excel&lt;/a&gt; is 'by far' the most common application in IT-GRC market : )&lt;br /&gt;
&lt;br /&gt;
There is no order or filter on the list... I simply added all visible vendors (keep me posted)&lt;br /&gt;
&lt;br /&gt;
IT-GRC vendors&lt;br /&gt;
&lt;br /&gt;
Agiliance&lt;br /&gt;
&lt;a href="http://www.agiliance.com/"&gt;http://www.agiliance.com/&lt;/a&gt;&lt;br /&gt;
RSA eGRC - Archer&lt;br /&gt;
&lt;a href="http://www.rsa.com/node.aspx?id=3732"&gt;http://www.rsa.com/node.aspx?id=3732&lt;/a&gt;&lt;br /&gt;
BWise&lt;br /&gt;
&lt;a href="http://www.bwise.com/"&gt;http://www.bwise.com/&lt;/a&gt;&lt;br /&gt;
Trustwave GRC (Control Path)&lt;br /&gt;
&lt;a href="https://www.trustwave.com/GRC.php"&gt;https://www.trustwave.com/GRC.php&lt;/a&gt;&lt;br /&gt;
Symantec (Control Compliance Suite)&lt;br /&gt;
&lt;a href="http://www.symantec.com/business/control-compliance-suite"&gt;http://www.symantec.com/business/control-compliance-suite&lt;/a&gt;&lt;br /&gt;
Modulo&lt;br /&gt;
&lt;a href="http://www.modulo.com/"&gt;http://www.modulo.com/&lt;/a&gt;&lt;br /&gt;
Relational Security - RSAM&lt;br /&gt;
&lt;a href="http://www.relsec.com/rsam_overview.htm"&gt;http://www.relsec.com/rsam_overview.htm&lt;/a&gt;&lt;br /&gt;
Metric Stream&lt;br /&gt;
&lt;a href="http://www.metricstream.com/"&gt;http://www.metricstream.com/&lt;/a&gt;&lt;br /&gt;
nCircle’s IT GRC Solution – Suite360 (acquired ClearPoint Metrics)&lt;br /&gt;
&lt;a href="http://www.ncircle.com/index.php?s=solution_IT-Governance-Risk-Compliance"&gt;http://www.ncircle.com/index.php?s=solution_IT-Governance-Risk-Compliance&lt;/a&gt;&lt;br /&gt;
Lumension&lt;br /&gt;
&lt;a href="http://www.lumension.com/Solutions/IT-Risk-Management.aspx"&gt;http://www.lumension.com/Solutions/IT-Risk-Management.aspx&lt;/a&gt;&lt;br /&gt;
BPS&lt;br /&gt;
&lt;a href="http://www.bpsresolver.com/"&gt;http://www.bpsresolver.com/&lt;/a&gt;&lt;br /&gt;
Avedos&lt;br /&gt;
&lt;a href="http://www.avedos.com/en/home/home.html"&gt;http://www.avedos.com/en/home/home.html&lt;/a&gt;&lt;br /&gt;
Neupart&lt;br /&gt;
&lt;a href="http://www.neupart.com/"&gt;http://www.neupart.com/&lt;/a&gt;&lt;br /&gt;
Thomson Reuters (old Paisley)&lt;br /&gt;
&lt;a href="http://accelus.thomsonreuters.com/solutions/risk-management/"&gt;http://accelus.thomsonreuters.com/solutions/risk-management/&lt;/a&gt;&lt;br /&gt;
IBM OpenPages (yes IBM acquired Openpages)&lt;br /&gt;
&lt;a href="http://www.openpages.com/"&gt;http://www.openpages.com/&lt;/a&gt;&lt;br /&gt;
Software AG GRC (IDS Scheer was acquired by Software AG)&lt;br /&gt;
&lt;a href="http://www.softwareag.com/us/solutions/grc/overview/default.asp"&gt;http://www.softwareag.com/us/solutions/grc/overview/default.asp&lt;/a&gt;&lt;br /&gt;
ARC Logics  - Axentis&lt;br /&gt;
Wolters Kluwers, the parent of Axentis; also acquired CI-3 , MediRegs ComplyTrack, CCH, TeamMate audit, FRS&lt;br /&gt;
&lt;a href="http://www.axentis.com/Products/Axentis/ProductOverview.html"&gt;http://www.axentis.com/Products/Axentis/ProductOverview.html&lt;/a&gt;&lt;br /&gt;
Methodware&lt;br /&gt;
&lt;a href="http://www.methodware.com/grc/"&gt;http://www.methodware.com/grc/&lt;/a&gt;&lt;br /&gt;
Protiviti&lt;br /&gt;
&lt;a href="http://www.protiviti.com/grc-software/Pages/default.aspx"&gt;http://www.protiviti.com/grc-software/Pages/default.aspx&lt;/a&gt;&lt;br /&gt;
Cura Software&lt;br /&gt;
&lt;a href="http://www.curasoftware.com/pages/content.asp?SectionId=7&amp;amp;SubSectionID=48"&gt;http://www.curasoftware.com/pages/content.asp?SectionId=7&amp;amp;SubSectionID=48&lt;/a&gt;&lt;br /&gt;
Mega&lt;br /&gt;
&lt;a href="http://www.mega.com/index.asp/l/en/c/grc"&gt;http://www.mega.com/index.asp/l/en/c/grc&lt;/a&gt;&lt;br /&gt;
ControlCase&lt;br /&gt;
&lt;a href="http://controlcase.com/it-grc.htm"&gt;http://controlcase.com/it-grc.htm&lt;/a&gt;&lt;br /&gt;
Compliance 360 ( eGRC )&lt;br /&gt;
&lt;a href="http://www.compliance360.com/"&gt;http://www.compliance360.com/&lt;/a&gt;&lt;br /&gt;
Nemea&lt;br /&gt;
&lt;a href="http://www.nemea.us/"&gt;http://www.nemea.us/&lt;/a&gt;&lt;br /&gt;
eGestalt SecureGRC - &amp;nbsp;SaaS hosted GRC offering&lt;br /&gt;
&lt;a href="http://www.egestalt.com/"&gt;http://www.egestalt.com/&lt;/a&gt;&lt;br /&gt;
Aline GRC&lt;br /&gt;
&lt;a href="http://www.alinegrc.com/GRC-Platform/20/"&gt;http://www.alinegrc.com/GRC-Platform/20/&lt;/a&gt;&lt;br /&gt;
Easy2Comply (Powered by Dynasec which is Check Point now...)&lt;br /&gt;
&lt;a href="http://www.easy2comply.com/"&gt;http://www.easy2comply.com/&lt;/a&gt;&lt;br /&gt;
SAI Global&lt;br /&gt;
&lt;a href="http://www.saiglobal.com/compliance/grc-software/"&gt;http://www.saiglobal.com/compliance/grc-software/&lt;/a&gt;&lt;br /&gt;
SwordAchiever Governance, Risk and Compliance (GRC) Software&lt;br /&gt;
&lt;a href="http://www.sword-achiever.com/Pages/Home.aspx"&gt;http://www.sword-achiever.com/Pages/Home.aspx&lt;/a&gt;&lt;br /&gt;
Xybion eGRC Enterprise 2011 (formerly Amadeus International)&lt;br /&gt;
&lt;a href="http://www.xybion.com/Products/eGRCEnterprise/eGRCProductOverview.aspx"&gt;http://www.xybion.com/Products/eGRCEnterprise/eGRCProductOverview.aspx&lt;/a&gt;&lt;br /&gt;
Ethics.Point  Adaptive GRC Framework (acquired HeatShield, Audit 2)&lt;br /&gt;
&lt;a href="http://www.ethicspoint.com/products/"&gt;http://www.ethicspoint.com/products/&lt;/a&gt;&lt;br /&gt;
MitraTech TeamConnect GRC&lt;br /&gt;
&lt;a href="http://www.mitratech.com/teamconnect-grc"&gt;http://www.mitratech.com/teamconnect-grc&lt;/a&gt;&lt;br /&gt;
Optial GRC&lt;br /&gt;
&lt;a href="http://www.optial.com/Products/GovernanceRiskandComplianceGRC.aspx"&gt;http://www.optial.com/Products/GovernanceRiskandComplianceGRC.aspx&lt;/a&gt;&lt;br /&gt;
Highpoint&lt;br /&gt;
&lt;a href="http://www.highpointgrc.com/"&gt;http://www.highpointgrc.com/&lt;/a&gt;&lt;br /&gt;
RVR GRC&lt;br /&gt;
&lt;a href="http://www.rvrsystems.com/IG.php"&gt;http://www.rvrsystems.com/IG.php&lt;/a&gt;&lt;br /&gt;
NeoGRC Compliance Manager (Neohapsis also acquired Securac Certus)&lt;br /&gt;
&lt;a href="http://www.neohapsis.com/products/neogrc-compliance-manager.php"&gt;http://www.neohapsis.com/products/neogrc-compliance-manager.php&lt;/a&gt;&lt;br /&gt;
TraceSecurity Compliance Manager (TSCM)&lt;br /&gt;
&lt;a href="http://www.tracesecurity.com/products/ts_compliance_manager.php"&gt;http://www.tracesecurity.com/products/ts_compliance_manager.php&lt;/a&gt;&lt;br /&gt;
Avior BenchMark risk and compliance management platform&lt;br /&gt;
&lt;a href="http://www.aviorcomputing.com/solutions/benchmark"&gt;http://www.aviorcomputing.com/solutions/benchmark&lt;/a&gt;&lt;br /&gt;
AssurX CATSWeb Quality Risk and Compliance Management&lt;br /&gt;
&lt;a href="http://www.assurx.com/solutions.html"&gt;http://www.assurx.com/solutions.html&lt;/a&gt;&lt;br /&gt;
ANX GRC (TrueARX)&lt;br /&gt;
&lt;a href="http://www.anx.com/content/solutions/compliance-and-risk-management/trucomply"&gt;http://www.anx.com/content/solutions/compliance-and-risk-management/trucomply&lt;/a&gt;&lt;br /&gt;
Telos Xacta IA Manager: Governance, risk, and compliance management&lt;br /&gt;
&lt;a href="http://www.telos.com/cybersecurity/grc/index.cfm"&gt;http://www.telos.com/cybersecurity/grc/index.cfm&lt;/a&gt;&lt;br /&gt;
ServiceNow IT Governance, Risk and Compliance (ITGRC) Management&lt;br /&gt;
&lt;a href="http://www.service-now.com/itgrc.do"&gt;http://www.service-now.com/itgrc.do&lt;/a&gt;&lt;br /&gt;
White Cyber Knight -WCK  / Lancelot&lt;br /&gt;
&lt;a href="http://www.wck-grc.com/Products_Lancelot_IT-GRC.htm"&gt;http://www.wck-grc.com/Products_Lancelot_IT-GRC.htm&lt;/a&gt;&lt;br /&gt;
Simeio Solutions GRCAXS (IT GRC module)&lt;br /&gt;
&lt;a href="http://www.simeiosolutions.com/"&gt;http://www.simeiosolutions.com/&lt;/a&gt;&lt;br /&gt;
Evantix Vendor IT Risk and Compliance Management&lt;br /&gt;
&lt;a href="http://www.evantix.com/what-is-evantix/"&gt;http://www.evantix.com/what-is-evantix/&lt;/a&gt;&lt;br /&gt;
Align Alytics Risk, IT, Compliance Management&lt;br /&gt;
&lt;a href="http://www.align-alytics.com/clientsolutions/"&gt;http://www.align-alytics.com/clientsolutions/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
There are many other tools with ERM (Enterprise Risk Management) Compliance Management, Audit and Access Control Governance feature sets.&lt;br /&gt;
&lt;br /&gt;
Here is a long list of indirect GRC software providers:&lt;br /&gt;
Oracle Enterprise Governance, Risk, and Compliance Manager&lt;br /&gt;
Oracle also acquired Reveleus, Mantas, Logical Apps, Ruleburst, Oracle GRC Manager&lt;br /&gt;
&lt;a href="http://www.oracle.com/us/solutions/corporate-governance/grc-manager/index.html"&gt;http://www.oracle.com/us/solutions/corporate-governance/grc-manager/index.html&lt;/a&gt;&lt;br /&gt;
SAP (no clear IT-GRC besides Access Control - SoD)&lt;br /&gt;
&lt;a href="http://www.sap.com/solutions/sapbusinessobjects/large/governance-risk-compliance/index.epx"&gt;http://www.sap.com/solutions/sapbusinessobjects/large/governance-risk-compliance/index.epx&lt;/a&gt;&lt;br /&gt;
Greenlight&lt;br /&gt;
&lt;a href="http://www.greenlightcorp.net/index.aspx"&gt;http://www.greenlightcorp.net/index.aspx&lt;/a&gt;&lt;br /&gt;
Qumas(Regulatory Compliance)&lt;br /&gt;
&lt;a href="http://www.qumas.com/"&gt;http://www.qumas.com/&lt;/a&gt;&lt;br /&gt;
Aveksa (Enterprise Access Governance)&lt;br /&gt;
&lt;a href="http://www.aveksa.com/"&gt;http://www.aveksa.com/&lt;/a&gt;&lt;br /&gt;
Trintech (Financial controls- no IT)&lt;br /&gt;
&lt;a href="http://www.trintech.com/"&gt;http://www.trintech.com/&lt;/a&gt;&lt;br /&gt;
Doublecheck ERM&lt;br /&gt;
&lt;a href="http://www.doublechecksoftware.com/solutions.htm"&gt;http://www.doublechecksoftware.com/solutions.htm&lt;/a&gt;&lt;br /&gt;
ACL - Transactional controls testing&lt;br /&gt;
&lt;a href="http://www.acl.com/products/ccm.aspx"&gt;http://www.acl.com/products/ccm.aspx&lt;/a&gt;&lt;br /&gt;
Approva (ERP Audit / SoD on steroids)&lt;br /&gt;
&lt;a href="http://www.approva.net/solutions/itsecurity/"&gt;http://www.approva.net/solutions/itsecurity/&lt;/a&gt;&lt;br /&gt;
Open Text Governance, Risk Management &amp;amp; Compliance&lt;br /&gt;
&lt;a href="http://www.opentext.com/2/global/sol-products/sol-pro-compliance-governance/pro-open-text-governance-risk-compliance.htm"&gt;http://www.opentext.com/2/global/sol-products/sol-pro-compliance-governance/pro-open-text-governance-risk-compliance.htm&lt;/a&gt;&lt;br /&gt;
Grant Thornton - ExpeditionGRC - GT acquired &amp;nbsp;Avalion Consulting ComplianceSet solution&lt;br /&gt;
&lt;a href="http://bit.ly/9bvCFB"&gt;http://bit.ly/9bvCFB&lt;/a&gt; (Long URL shortened)&lt;br /&gt;
Incom Enterprise Risk Mgr ISO 31000&lt;br /&gt;
&lt;a href="http://www.incom.com.au/"&gt;http://www.incom.com.au&lt;/a&gt;&lt;br /&gt;
EIQNetworks SecureVue&lt;br /&gt;
&lt;a href="http://www.eiqnetworks.com/securevue/securevue.php"&gt;http://www.eiqnetworks.com/securevue/securevue.php&lt;/a&gt;&lt;br /&gt;
Brinqa brings privacy, identity and vendor management&lt;br /&gt;
&lt;a href="http://www.brinqa.com/products/brinqa-grc-platform/"&gt;http://www.brinqa.com/products/brinqa-grc-platform/&lt;/a&gt;&lt;br /&gt;
SecurityWeaver (SoD tool)&lt;br /&gt;
&lt;a href="http://www.securityweaver.com/Products_Separations_Enforcer.asp"&gt;http://www.securityweaver.com/Products_Separations_Enforcer.asp&lt;/a&gt;&lt;br /&gt;
ControlpanelGRC - SOX compliance for SAP users&lt;br /&gt;
&lt;a href="http://www.controlpanelgrc.com/"&gt;http://www.controlpanelgrc.com/&lt;/a&gt;&lt;br /&gt;
Xpandion SAP Security -&lt;br /&gt;
&lt;a href="http://www.xpandion.com/"&gt;http://www.xpandion.com/&lt;/a&gt;&lt;br /&gt;
EtQ Reliance (Quality Management, Environmental Health &amp;amp; Safety (EHS) Management)&lt;br /&gt;
&lt;a href="http://www.etq.com/reliance/"&gt;http://www.etq.com/reliance/&lt;/a&gt;&lt;br /&gt;
Active Risk Management - ARM (Strategic Thought Group became Active Risk)&lt;br /&gt;
&lt;a href="http://www.activerisk.com/risk-management/"&gt;http://www.activerisk.com/risk-management/&lt;/a&gt;&lt;br /&gt;
Symb ERM and Aptius Risk Management&lt;br /&gt;
&lt;a href="http://www.symb.com/content/c_symbhome.asp"&gt;http://www.symb.com/content/c_symbhome.asp&lt;/a&gt;&lt;br /&gt;
Actimize (Fraud Prevention and ERM - acquired Syfact)&lt;br /&gt;
&lt;a href="http://www.actimize.com/index.aspx?page=actimizeplatform"&gt;http://www.actimize.com/index.aspx?page=actimizeplatform&lt;/a&gt;&lt;br /&gt;
Guideline Risk Universe Business Intelligence (RUBI)&lt;br /&gt;
&lt;a href="http://www.guidelinerisk.com/RUBI_system_intro.html"&gt;http://www.guidelinerisk.com/RUBI_system_intro.html&lt;/a&gt;&lt;br /&gt;
Hitec Labs Policy Hub and Ten Risk Management&lt;br /&gt;
&lt;a href="http://www.hiteclabs.com/uk/solutions/policy-management-policyhub/"&gt;http://www.hiteclabs.com/uk/solutions/policy-management-policyhub/&lt;/a&gt;&lt;br /&gt;
Horwath Software Services Magique Galileo&lt;br /&gt;
&lt;a href="http://www.horwathsoftware.com/hsl/hslwebsite.nsf"&gt;http://www.horwathsoftware.com/hsl/hslwebsite.nsf&lt;/a&gt;&lt;br /&gt;
IBS Compliance Pro Compliance Management&lt;br /&gt;
&lt;a href="http://www.ibs-us.com/en/products/compliantpro/index.html"&gt;http://www.ibs-us.com/en/products/compliantpro/index.html&lt;/a&gt;&lt;br /&gt;
LRN Ethics Compliance&lt;br /&gt;
&lt;a href="http://lrn.com/"&gt;http://lrn.com/&lt;/a&gt;&lt;br /&gt;
Pentena PAWS Audit &amp;amp; Risk Management Software&lt;br /&gt;
&lt;a href="http://www.pentana.com/products.asp"&gt;http://www.pentana.com/products.asp&lt;/a&gt;&lt;br /&gt;
Prodiance ERM Spreadsheet Compliance (now Microsoft)&lt;br /&gt;
&lt;a href="http://www.microsoft.com/pathways/prodiance/"&gt;http://www.microsoft.com/pathways/prodiance/&lt;/a&gt;&lt;br /&gt;
policyIQ Risk &amp;amp; Compliance&lt;br /&gt;
&lt;a href="http://www.policyiq.com/solutions_risk_compliance.asp"&gt;http://www.policyiq.com/solutions_risk_compliance.asp&lt;/a&gt;&lt;br /&gt;
SAS Operational Risk Management&lt;br /&gt;
&lt;a href="http://www.sas.com/industry/fsi/oprisk/index.html"&gt;http://www.sas.com/industry/fsi/oprisk/index.html&lt;/a&gt;&lt;br /&gt;
FairWarning Healthcare Compliance Audit /Monitoring&lt;br /&gt;
&lt;a href="http://www.fairwarningaudit.com/subpages/auditing.asp"&gt;http://www.fairwarningaudit.com/subpages/auditing.asp&lt;/a&gt;&lt;br /&gt;
Assuria Audit &amp;amp; Compliance Management&lt;br /&gt;
&lt;a href="http://www.assuria.com/products-new.html"&gt;http://www.assuria.com/products-new.html&lt;/a&gt;&lt;br /&gt;
Flexeye Operational Intelligence&lt;br /&gt;
&lt;a href="http://www.flexeyetech.com/operational-intelligence.html"&gt;http://www.flexeyetech.com/operational-intelligence.html&lt;/a&gt;&lt;br /&gt;
Consult2Comply Compliance Infrastructure Management&lt;br /&gt;
&lt;a href="http://www.consult2comply.com/main/"&gt;http://www.consult2comply.com/main/&lt;/a&gt;&lt;br /&gt;
CMO Audit Compliance Risk Management&lt;br /&gt;
&lt;a href="http://www.cmo-compliance.com/"&gt;http://www.cmo-compliance.com/&lt;/a&gt;&lt;br /&gt;
ComplianceBridge Compliance Policy and Procedure Management&lt;br /&gt;
&lt;a href="http://www.compliancebridge.com/"&gt;http://www.compliancebridge.com/&lt;/a&gt;&lt;br /&gt;
The Gartland RiskKey Continous Compliance&lt;br /&gt;
&lt;a href="http://www.thegarlandgroup.net/services/continuous-compliance-service/"&gt;http://www.thegarlandgroup.net/services/continuous-compliance-service/&lt;/a&gt;&lt;br /&gt;
NextLabs Policy and Compliance Management&lt;br /&gt;
&lt;a href="http://www.nextlabs.com/html/?q=control-center"&gt;http://www.nextlabs.com/html/?q=control-center&lt;/a&gt;&lt;br /&gt;
McAfee Risk &amp;amp; Compliance Products&lt;br /&gt;
&lt;a href="http://www.mcafee.com/us/products/risk-and-compliance/index.aspx"&gt;http://www.mcafee.com/us/products/risk-and-compliance/index.aspx&lt;/a&gt;&lt;br /&gt;
Collaborative Software Initiative -  Standardized Information Gathering (SIG)&lt;br /&gt;
&lt;a href="http://csinitiative.com/products/sig/overview/"&gt;http://csinitiative.com/products/sig/overview/&lt;/a&gt;&lt;br /&gt;
LogicManager ERM&lt;br /&gt;
&lt;a href="http://www.logicmanager.com/contents/why_logicmanager/model.php"&gt;http://www.logicmanager.com/contents/why_logicmanager/model.php&lt;/a&gt;&lt;br /&gt;
Enablon ERM&lt;br /&gt;
&lt;a href="http://enablon.com/products/risk-management.aspx"&gt;http://enablon.com/products/risk-management.aspx&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
IT-GRC software make our lives more organized but we should not skip the motto of the &lt;a href="http://www.csi4global.com/website/index/index.php?pagid=131"&gt;CSI audit people&lt;/a&gt;: " ‘A fool with a tool is still a fool’"&lt;br /&gt;
&lt;br /&gt;
Other Links:&lt;br /&gt;
&lt;a href="http://www.gartner.com/it/content/925200/925212/ks_sd_may09.pdf"&gt;http://www.gartner.com/it/content/925200/925212/ks_sd_may09.pdf&lt;/a&gt;&lt;br /&gt;
Gartner eGRC 2011 report: &lt;a href="http://www.openpages.com/Information-Center-Registration/Campaign_88.asp"&gt;http://www.openpages.com/Information-Center-Registration/Campaign_88.asp&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.isaca.org/Knowledge-Center/Documents/COBIT-Focus-ISO-38500-Why-Another-Standard.pdf"&gt;http://www.isaca.org/Knowledge-Center/Documents/COBIT-Focus-ISO-38500-Why-Another-Standard.pdf&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-4435750695171488614?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/aBHsAplc1Zal8cnb4Jm87I9hVlY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/aBHsAplc1Zal8cnb4Jm87I9hVlY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/aBHsAplc1Zal8cnb4Jm87I9hVlY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/aBHsAplc1Zal8cnb4Jm87I9hVlY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=n8pq7DqyfuQ:rEpPh2li2xs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=n8pq7DqyfuQ:rEpPh2li2xs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=n8pq7DqyfuQ:rEpPh2li2xs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=n8pq7DqyfuQ:rEpPh2li2xs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=n8pq7DqyfuQ:rEpPh2li2xs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/n8pq7DqyfuQ" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/n8pq7DqyfuQ/itgrc-software-vendors-2011.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2011/10/itgrc-software-vendors-2011.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-5432311458884560589</guid><pubDate>Thu, 29 Sep 2011 03:52:00 +0000</pubDate><atom:updated>2011-09-28T23:52:57.192-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">IT-GRC</category><title>Which Logs are Security Logs?</title><description>&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: x-small;"&gt;This was originally posted on my RSA Conference &lt;a href="https://365.rsaconference.com/blogs/yinal-ozkan/2011/07/09/which-logs-are-security-logs"&gt;Blog&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px;"&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div class="MsoNormal" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;Many of the security logging discussions center about the following topics:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;1-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Log Collection&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;2-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Log Transport&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;3-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Log Storage&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;4-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Log Taxonomy&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;5-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Log Analysis / Correlation&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;6-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Log Protection / Security&lt;/div&gt;&lt;div class="MsoNormal" style="height: 8pt; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;These are all good topics but a very important topic is rarely discussed, and it is usually the most important one:&lt;/div&gt;&lt;div class="MsoNormal" style="height: 8pt; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;h3 style="color: #333333; font-size: 1.5556em; font-weight: bold; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 4px; padding-left: 0px; padding-right: 0px; padding-top: 10px;"&gt;What are the security logs?&lt;/h3&gt;&lt;div class="MsoNormal" style="height: 8pt; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;It is easy to work with security devices (Firewall, IDP, DLP, AV etc), their logs/alerts are classified as security logs, but what about regular applications or infrastructure components that are not build as&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;a&amp;nbsp;&lt;/span&gt;“security device” or security in mind? Do we need to process all logs from these devices? Which logs are more important?&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;Which logs go to “security” queue?&lt;/div&gt;&lt;div class="MsoNormal" style="height: 8pt; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;Let’s go with example, if you are the security architect, what would you recommend to a system owner who came up with a new application that writes the logs to a flat file or a database? Even if the logs are shipped to a syslog collector or an OS log queue; does it change the question?&lt;/div&gt;&lt;div class="MsoNormal" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;The question is same “Which” logs? What do you want?&lt;/div&gt;&lt;div class="MsoNormal" style="height: 8pt; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;h3 style="color: #333333; font-size: 1.5556em; font-weight: bold; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 4px; padding-left: 0px; padding-right: 0px; padding-top: 10px;"&gt;Here is a quick check list of activities to ask for the logs:&lt;/h3&gt;&lt;div class="MsoListParagraphCxSpFirst" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;1-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Logs for all access (User, Admin, Service, Application etc)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;2-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Logs for all changes (changes in monitored files, configurations, hardware,software – MACD logs)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;3-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Logs for critical transactions in the applications&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;4-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Logs from user repository (e.g if AD, LDAP, RADIUS is used) access, change and transaction logs from user repository&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;5-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Logs for anomalies (changes in baseline activity, failed attempts, unexpected connections etc)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="height: 8pt; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;Since a security architect cannot know all applications, this is a good start to communicate with 3&lt;sup style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;rd&lt;/sup&gt;&amp;nbsp;party developers and application/system owners for security log generation.&lt;/div&gt;&lt;div class="MsoNormal" style="height: 8pt; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="height: 8pt; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;h5 style="color: #333333; font-size: 1.2222em; font-weight: bold; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 4px; padding-left: 0px; padding-right: 0px; padding-top: 10px;"&gt;For a structured approach here are a few good reads to start with:&lt;/h5&gt;&lt;div class="MsoNormal" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;NIST 800-92, Guide to Computer Security Log Management&lt;/div&gt;&lt;div class="MsoNormal" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;a class="jive-link-external-small" href="http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf" style="color: #507dbf; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="height: 8pt; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;Common Event Expression White Paper (also has a history on other initiatives)&lt;/div&gt;&lt;div class="MsoNormal" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;a class="jive-link-external-small" href="http://cee.mitre.org/docs/Common_Event_Expression_White_Paper_June_2008.pdf" style="color: #507dbf; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://cee.mitre.org/docs/Common_Event_Expression_White_Paper_June_2008.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="height: 8pt; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;Watch Your Logs! Quick intro&lt;/div&gt;&lt;div class="MsoNormal" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;a class="jive-link-external-small" href="http://www.issa.org/Library/Journals/2007/July/Malatesti%20-%20Watch%20Your%20Logs.pdf" style="color: #507dbf; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://www.issa.org/Library/Journals/2007/July/Malatesti%20-%20Watch%20Your%20Logs.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="height: 8pt; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;Microsoft's The Security Monitoring and Attack Detection Planning Guide&lt;a class="jive-link-external-small" href="http://www.dabcc.com/documentlibrary/file/MicrosoftreleasesanewSecurity,MonitoringandAttackDetectionWhitepaper.pdf" style="color: #507dbf; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://www.dabcc.com/documentlibrary/file/MicrosoftreleasesanewSecurity,MonitoringandAttackDetectionWhitepaper.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-5432311458884560589?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/tOcnjq7moU9shnW9SvPgIU0U1TM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tOcnjq7moU9shnW9SvPgIU0U1TM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/tOcnjq7moU9shnW9SvPgIU0U1TM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tOcnjq7moU9shnW9SvPgIU0U1TM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=gfbmKf752q8:0-VHDlroeSw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=gfbmKf752q8:0-VHDlroeSw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=gfbmKf752q8:0-VHDlroeSw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=gfbmKf752q8:0-VHDlroeSw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=gfbmKf752q8:0-VHDlroeSw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/gfbmKf752q8" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/gfbmKf752q8/which-logs-are-security-logs.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2011/09/which-logs-are-security-logs.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-8175049335856891815</guid><pubDate>Tue, 12 Jul 2011 21:27:00 +0000</pubDate><atom:updated>2011-07-12T17:27:30.291-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">compliance</category><category domain="http://www.blogger.com/atom/ns#">vulnerability_management</category><category domain="http://www.blogger.com/atom/ns#">PCI</category><title>Reminder: PCI DSS 2.0 is asking for Vulnerability Risk Rating</title><description>&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;You know the story; if your systems/applications store transmit or process credit card data, you must meet PCI data security standards.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Since Q4 2010 all PCI shops are aware that their Cardholder Data Environments need a risk ranking procedure.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;But, What is it and how does it change current practices?&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;PCI DSS Requirement 6.2 says "Establish a process to identify and assign a risk ranking to newly discovered security vulnerabilities"&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;And a new recommendation may certainly effect how you manage risk…&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;This recommendation (which will be a requirement by June 30, 2012) can be classified as Risk Management 101, and yet it may change several cornerstones of your processes.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Here is what 6.2.a is asking for:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;1- Check your processes for identifying new security vulnerabilities (make sure you have one)&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;2- Assign risk ranking to identified vulnerabilities&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;6.2.b Continues with the&amp;nbsp; recommendation that you use and outside source for this risk ranking process.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;This translates into a solid scoring system for risk. Enterprise options to collect data for a scoring system are:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;1- Vendor Security Alerts&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;2- Vulnerability Management Advisories (Usually security scanner, and IDS/IPS shops)&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;3- Vulnerability Intelligence Advisories (e.g. Secunia, iDefense, Deepsight)&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;4- Internal risk scoring systems (yes we all love academic endeavors - that is why PCI SSC asks for "outside" source : )&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Either way (using one of the options, using some/all of them) PCI recommendation 6.2 will push risk management practices in the right direction and make risk prioritization a priority...Eventually PCI shops will (6/30/2012) integrate risk management with vulnerability scanning devices, security alerts, advisories and patch management solutions to audit and validate PCI 6.2 with risk rankings.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;h5 style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 1.2222em; font-weight: bold; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 4px; padding-left: 0px; padding-right: 0px; padding-top: 10px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Here are a few good links:&lt;/span&gt;&lt;/h5&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Common Vulnerability Scoring System (CVSS-SIG) -&amp;nbsp;&lt;a class="jive-link-external-small" href="http://www.first.org/cvss/" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://www.first.org/cvss/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Common Vulnerabilities and Exposures -CVE -&amp;nbsp;&lt;a class="jive-link-external-small" href="http://cve.mitre.org/" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://cve.mitre.org/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;National Vulnerability Database - NVD -&amp;nbsp;&lt;a class="jive-link-external-small" href="http://nvd.nist.gov/" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://nvd.nist.gov/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Secunia -&amp;nbsp;&lt;a class="jive-link-external-small" href="http://secunia.com/advisories/" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://secunia.com/advisories/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Verisign iDefense -&amp;nbsp;&lt;a class="jive-link-external-small" href="http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/index.xhtml" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/index.xhtml&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;TippingPoint Zero Day Initiative ZDI -&amp;nbsp;&lt;a class="jive-link-external-small" href="http://www.zerodayinitiative.com/advisories/upcoming/" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://www.zerodayinitiative.com/advisories/upcoming/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Symanted DeepSight Alert Services -&amp;nbsp;&lt;a class="jive-link-external-small" href="https://tms.symantec.com/" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;https://tms.symantec.com/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Cisco Security IntelliShield Alert Manager Service -&lt;a class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6834/serv_group_home.html" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6834/serv_group_home.html&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;IBM ISS XForce -&amp;nbsp;&lt;a class="jive-link-external-small" href="http://www-935.ibm.com/services/us/iss/xforce/" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://www-935.ibm.com/services/us/iss/xforce/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;VUPEN -&amp;nbsp;&lt;a class="jive-link-external-small" href="http://www.vupen.com/english/research.php" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://www.vupen.com/english/research.php&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;McAfee Threat Intelligence Services (MTIS) -&amp;nbsp;&lt;a class="jive-link-external-small" href="http://www.mcafee.com/us/mcafee-labs/technology/threat-intelligence-services.aspx" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://www.mcafee.com/us/mcafee-labs/technology/threat-intelligence-services.aspx&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Bugtraq -&lt;a class="jive-link-external-small" href="http://seclists.org/bugtraq/" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://seclists.org/bugtraq/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Full Disclosure -&amp;nbsp;&lt;a class="jive-link-external-small" href="http://seclists.org/fulldisclosure/" style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;" target="_blank"&gt;http://seclists.org/fulldisclosure/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;p.s. I have written this &lt;a href="https://365.rsaconference.com/blogs/yinal-ozkan/2011/06/28/reminder-pci-dss-20-is-asking-for-vulnerability-risk-ranking"&gt;article&lt;/a&gt; for RSA Conference&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="color: #333333; font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="color: #333333; font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-8175049335856891815?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/S_sxsPYixISSmxFtCVfvARfJ0Wg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/S_sxsPYixISSmxFtCVfvARfJ0Wg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/S_sxsPYixISSmxFtCVfvARfJ0Wg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/S_sxsPYixISSmxFtCVfvARfJ0Wg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=6Mpub3vjzmE:X2SIILMzMXk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=6Mpub3vjzmE:X2SIILMzMXk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=6Mpub3vjzmE:X2SIILMzMXk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=6Mpub3vjzmE:X2SIILMzMXk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=6Mpub3vjzmE:X2SIILMzMXk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/6Mpub3vjzmE" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/6Mpub3vjzmE/reminder-pci-dss-20-is-asking-for.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2011/07/reminder-pci-dss-20-is-asking-for.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-7493644874437224211</guid><pubDate>Mon, 04 Jul 2011 19:20:00 +0000</pubDate><atom:updated>2011-07-04T15:28:45.176-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">RSA Conference</category><title>Video Notes From the RSA 2011 Conference</title><description>RSA Conference 2011&lt;br /&gt;
&lt;br /&gt;
Video Blog #1&lt;br /&gt;
RSA Conference Video Blogger Yinal Ozkan talks about his first day at the 2011 RSA Conference in San Francisco, California.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.youtube.com/rsaconference#p/u/99/88pVqQgjkH0 "&gt;http://www.youtube.com/rsaconference#p/u/99/88pVqQgjkH0&amp;nbsp;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Video Blog #2&lt;br /&gt;
&lt;a href="http://www.youtube.com/rsaconference#p/u/96/Ss33IH0laAw"&gt;http://www.youtube.com/rsaconference#p/u/96/Ss33IH0laAw&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Video Blog #3&lt;br /&gt;
&lt;a href="http://www.youtube.com/rsaconference#p/u/94/vUtFR_DeHOc"&gt;http://www.youtube.com/rsaconference#p/u/94/vUtFR_DeHOc&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-7493644874437224211?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/_vrmfTMTaU0Hfbes0x5zn1hoZow/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_vrmfTMTaU0Hfbes0x5zn1hoZow/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/_vrmfTMTaU0Hfbes0x5zn1hoZow/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_vrmfTMTaU0Hfbes0x5zn1hoZow/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=aS5lafaG28s:eDACwHVKUm8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=aS5lafaG28s:eDACwHVKUm8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=aS5lafaG28s:eDACwHVKUm8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=aS5lafaG28s:eDACwHVKUm8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=aS5lafaG28s:eDACwHVKUm8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/aS5lafaG28s" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/aS5lafaG28s/video-notes-from-rsa-2011-conference.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2011/07/video-notes-from-rsa-2011-conference.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-897600363157219552</guid><pubDate>Sun, 26 Jun 2011 04:05:00 +0000</pubDate><atom:updated>2011-06-26T00:05:27.045-04:00</atom:updated><title>Talent Filtering for Information Security</title><description>&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;I have written this article for RSA Conference blog originally (&lt;span class="Apple-style-span" style="font-family: 'Times New Roman'; font-size: small;"&gt;&lt;a href="https://365.rsaconference.com/blogs/yinal-ozkan"&gt;https://365.rsaconference.com/blogs/yinal-ozkan&lt;/a&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Great results are not achieved by mediocre teams… Building the right Information Security team does matter, and usually it becomes a full time task for the owners of Information Security initiatives at today’s enterprise.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Information Security domain might be hot, and we may have a positive influx of talent to the sector, however finding the right people with right skills sets at the right time and the right cost is close to impossible.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;This post has no intention of questioning/changing years of HR practices – the goal is to give feedback from the enterprise Information Security field and to create useful short order cook content that can quickly be consumed within the next 15 minutes for the upcoming interview you are conducting…&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Here are my experiences with finding/hiring talent in Information Security:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;1-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Do not reinvent basics. As Buffet/Gates duo has stated the great talent should have the 3 basic skills:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/div&gt;&lt;ol style="clear: both; display: block; font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 30px; padding-right: 0px; padding-top: 0px;"&gt;&lt;ul style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Technical Skills (This is standard – I will dig into this item more down below)&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Conceptual Thinking (Seeing the big picture)&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Communication Skills (This is not talking too much as perceived by many engineers. Effective communication is a very valuable skill in all team deliverables&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/ol&gt;&lt;div style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;It is usually simple to find any one of these skills in an individual, but when you find 3 of them together never miss the opportunity, these people will carry the workload of many!&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;2-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Have the right pyramid mix of talent in your team: Complex projects require good leaders who can set the target, coach others, lead by example and more important than all great leaders can take the team from A to B. Then you need good managers, who can plan, organize and delegate. It is usually a good practice to have managers who cut their teeth in project management and financial management offices. Last, but not least, the engineers (or consultants).&amp;nbsp;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/span&gt;Based on the size of the project, you must determine whether to go with specialists or generalists. This is a big decision point.&amp;nbsp;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: underline;"&gt;The more specialists you have,&amp;nbsp;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/span&gt;the more integration glue (architects, project managers, program managers ) you need.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;3-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Since generic HR topics are not my intention here, I will skip managerial skills and focus on finding the right technical resources. Project based deliverables do not require that much real-time information. Therefore, it does not make sense to filter candidates based on closed book random interview questions. My recommendation is to measure their knowledge so you may level them based on knowledge. This is management basics -&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;data to wisdom:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/div&gt;&lt;ul style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;ul style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Ask them questions starting with&amp;nbsp;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;who?, when?, where?, what??&lt;/span&gt;&amp;nbsp;If you can get good answers that means your candidate has&amp;nbsp;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;“information”&lt;/span&gt;.&amp;nbsp;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/span&gt;Your candidate is probably familiar with the topic.&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Ask them questions starting with&amp;nbsp;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;“how?&lt;/span&gt;”. If you can get good answers that means your candidate has&amp;nbsp;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;knowledge.&lt;/span&gt;This is a clear signal of experience.&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Ask them questions starting with “&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;why?”&lt;/span&gt;&amp;nbsp;If you can get good answers to “why” questions that means your candidate has the&amp;nbsp;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;wisdom&lt;/span&gt;&amp;nbsp;and the conceptual thinking skills that you are looking for.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/ul&gt;&lt;div style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;4-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Specialists: Being a specialist does not create a rain check to omit basics of information security. I have met several consultants who were very familiar with compliance but did not understand the technical tools, or I have seen great application security people with zero understanding of network basics. The trend is to have good understanding of all domains where you excel in 1 or 2 of the domains as a specialist. Interviewing specialists should have 2 different class of questions to gauge:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/div&gt;&lt;ul style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;ul style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;How much do they do they own their domain of specialization?&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;How much do they understand about how other domains work?&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/ul&gt;&lt;div style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;5-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/span&gt;Generalists: I believe there are 2 types of generalists you can trust in Information Security:&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;ul style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;New Grads with no experience&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Project Managers, Auditors, and Managers (usually go well with the certificates like CISSP, CISM etc)&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;If you are interviewing a candidate with over 3 years of Information Security experience with no particular specialty that is a big red flag.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/ul&gt;&lt;div style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;6-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Send consultants the questions that you will ask in advance. This will eliminate the&amp;nbsp;&lt;em style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;“it is not at the top of my head /it has been a while”&lt;/em&gt;&amp;nbsp;excuse. Since you send the technical interview questions in advance you can ask any particular sub question. This asynchronous Q&amp;amp;A style is more close to real life. This way you can also ask really tough questions as well.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;7-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Ask for a sanitized copy of deliverables from the past assignments. Good samples are good indicators of pitched skills. Obtaining samples are problematic especially in Information Security due to security and Intellectual Property concerns but checking is better than not checking.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;8-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Classify Information Security resource types (this is subjective)&amp;nbsp;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: underline;"&gt;Classification will help you to identify your candidates specialty, customize your questions and assess them more evenly&lt;/span&gt;. In today’s IS world,&amp;nbsp;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/span&gt;I see the following backgrounds We can dig into each area in separate articles. Here is the bird’s eye view for the 15m intro:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/div&gt;&lt;ul style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;ul style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Network Security Specialists: This is the most abundant resource.&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;Most of the resources have strong networking background and they do have operational and engineering know-how about common tools like firewalls, IDP, content security, OS hardening.&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;Ask for the enterprise know how instead of small shops, that is completely different skill-set. It usually makes sense to get “Security Operations” resources from this background since their operational background fits well with the SOC (Security Operation Centers)&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Vulnerability Testers:&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;This is another domain where you can find a lot of resources. (not necessarily the best ones) From network testing, to penetration testing, this area requires a lot of technical skills. Ask for methodologies, frameworks, references and sample deliverables in addition to basic checks.&amp;nbsp;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/span&gt;Network Vulnerabilities, Application Vulnerabilities, operational Vulnerabilities, and the Physical Vulnerabilities are different so make sure that you have the right skill sets.&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Single Domain Specialists: If your project is big enough you can acquire a domain specialist (e.g. SIEM) or a technology (e.g. RSA envision) specialist. Be sure to question other skills as discussed above. DLP, DRM, Virtualization Security,&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;Social Media, and Mobile Security-type of next generation projects usually require specialists so it makes sense to start with a consultant specialists to acquire the skills sets.&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Application Security Specialists: Securing SAP, Siebel, Oracle is a life time goal. It does require life time experience. Again the same rules with hiring specialists.&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Desktop Security: Understanding desktop security is different than all other security areas where the end users are non-IT users. Lately desktop security domain is crisscrossing a lot of other domains like NAC, 802.1x, VDI so be very careful to filter.&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Code Security: This is a hot domain, possible candidates interact with application security, vulnerability testing. It is not possible to understand code security in every development framework so an eclipse environment&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;expert cannot be very useful in the .NET environment&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Security Architects: Even if you see a lot of titles with Security Architect, the real ones are tough to come by, look for understanding of EA frameworks like TOGAF, Zachman etc. Also look for special frameworks like ISO 27001, CoBIT, and NIST.&amp;nbsp;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/span&gt;Generic frameworks like ITIL, 6 Sigma, and other compliance frameworks are important. In addition, look for perfect understanding of operations and the technology.&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Compliance Specialists:&amp;nbsp;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/span&gt;Audit background helps. Top 4 experience helps. Compliance has 2 important parts, meeting compliance and an accreditation. Make sure that you acquire the right internal resources to meet your compliance goals.&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;Instead of going with multiple security compliance specialists, it will make more sense to build an information security management program that can answer the common 80% requirements of all frameworks.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/ul&gt;&lt;div style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;9-&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Classify candidate backgrounds based on the verticals; it makes sense to find Information Security resources with vertical specialization. I find it amusing to mark “government” background as we start discussing topics with “cyber” word… So far I have seen the following backgrounds in the field. Based on your project’s requirements, different backgrounds provide different outcome.. You can find Information Security professionals with the following backgrounds&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;ul style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/ul&gt;&lt;ul style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Enterprise&lt;/span&gt;&lt;ul style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;ul style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Financials&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Healthcare&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Manufacturing&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Utility&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;High Tech&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Media&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Other&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/ul&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Government&lt;/span&gt;&lt;ul style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;ul style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Federal&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;State&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/ul&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Military&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;SMB&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Consultancy&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Higher-Ed&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Service Provider&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;New Grad&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Vendor&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Reseller&lt;/span&gt;&lt;/li&gt;
&lt;li style="list-style-image: initial; list-style-position: initial; list-style-type: none; margin-bottom: 0.2em; margin-left: 0px; margin-right: 0px; margin-top: 0.2em; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Out of Sector&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;/ul&gt;&lt;div style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; height: 8pt; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; min-height: 8pt; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Arial, Helvetica, Tahoma, sans-serif; font-size: 12px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;"&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;Wrap Up: Look for talent with specific skill-sets – To help you better identify the right skill sets, customize your questions based on experience background, vertical background and universal skills such as conceptual thinking.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-897600363157219552?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/WUv-84Wk2GJLgu91SeRIJI-a7gg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/WUv-84Wk2GJLgu91SeRIJI-a7gg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/WUv-84Wk2GJLgu91SeRIJI-a7gg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/WUv-84Wk2GJLgu91SeRIJI-a7gg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=8P_4-g_dk7g:Dsap96Y72Ls:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=8P_4-g_dk7g:Dsap96Y72Ls:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=8P_4-g_dk7g:Dsap96Y72Ls:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=8P_4-g_dk7g:Dsap96Y72Ls:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=8P_4-g_dk7g:Dsap96Y72Ls:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/8P_4-g_dk7g" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/8P_4-g_dk7g/talent-filtering-for-information.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>1</thr:total><feedburner:origLink>http://security.24kasim.org/2011/06/talent-filtering-for-information.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-5855492132337037222</guid><pubDate>Sun, 20 Mar 2011 06:06:00 +0000</pubDate><atom:updated>2011-03-20T02:30:29.824-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">authentication</category><title>RSA SecurID Breach Questions</title><description>&lt;span class="Apple-style-span" style="color: yellow;"&gt;&lt;b&gt;Q:&lt;/b&gt; What was stolen from RSA? (based on Art Coviello's&amp;nbsp;&lt;a href="http://www.rsa.com/node.aspx?id=3872"&gt;blog&lt;/a&gt;) and What is the current risk for SecurID users?&lt;/span&gt;&lt;br /&gt;
&lt;div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh3.googleusercontent.com/-C-tR4PVXfQc/TYWdasTDEHI/AAAAAAAAAHk/h87pycpqu7s/s1600/token.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="147" src="https://lh3.googleusercontent.com/-C-tR4PVXfQc/TYWdasTDEHI/AAAAAAAAAHk/h87pycpqu7s/s320/token.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;&lt;b&gt;A&lt;/b&gt;: RSA says &lt;i&gt;"..extracted&amp;nbsp;information could potentially be used to reduce the effectiveness of a current two-factor authentication implementation..."&lt;/i&gt; This is boiling water and everybody is trying to reverse engineer this statement.. What does RSA mean by reduced effectiveness? Without the full disclosure, all interpretations will be semi fictional.. Information sources are limited when RSA is silent. A very important sign of &amp;nbsp;RSA's response is "RSA SecurID Authentication Engine Security Best Practices Guide" document which was published in March 17.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;Here are the 2 interesting statements from the March 17 Guide:&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;1 - "RSA recommends a defense-in-depth approach for protecting token data stored in your environment. RSA strongly recommends that your storage systems encrypt the token data with a separate key in addition to the encryption provided by RSA SecurID Authentication Engine. Using two separate keys maximizes the protection of stored token data."&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;&lt;u&gt;My&amp;nbsp;interpretation: &lt;/u&gt;Do not trust RSA authentication server's built-in encryption, use yours.This means 3rd party who "extracted information from RSA" &amp;nbsp;has a good understanding of how RSA obscures token data on the authentication server...It is usually possible to access stored encryption keys since they have to be accessed for operation anyway. So if source code is lost, this may happen faster..&lt;b&gt;Risk&lt;/b&gt;: You had to secure auth server anyway, now the risks are higher but this specific risk does not require you to replace every single token in the field until your own auth server is hacked.. And believe me when your authentication server is hacked you have other serious problems as well (BTW I'am not sure how auth server will work if I encrypt token data with my keys at file level)&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;2- "Never give the token serial number, PIN, tokencode, token, passcode or passwords to anyone."&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;My&amp;nbsp;interpretation:&amp;nbsp;Let's analyze this one in-depth.. When you use SecurID, you enter passcode as your &amp;nbsp;password. A passcode is made up 2 pieces on RSA, a pseudo-number (that is dynamically generated on the token a.k.a. tokencode) and your PIN..&amp;nbsp;&lt;/div&gt;&lt;div&gt;The beauty of multi-factor dynamic password tokens is that if I know your PIN I still need the tokencode (so the token).. If I steal your token, I still need the PIN... No attacks are effective until you get token for that specific 60 seconds+PIN combo.(in theory ; ).... &amp;nbsp;The scary part of the warning above is the "token serial number", a number on the back of the token usually used as a subfactor for &amp;nbsp;enrollment and password resets... Directly losing ""token serial number" shouldn't have mattered . if it did, it was not supposed to be imprinted on the back of the token..So the&amp;nbsp;hypothetical&amp;nbsp;risk is that the guys who extracted data from RSA can generate a tokencode from the serial number.. I do not think this is the possibility since that eliminates the whole idea for the need for the token seeds..Hopefully RSA token's private algos are not that simple (serial number generates the seed). &amp;nbsp;Same argument is valid for tokencodes.. If I have to hide my tokencode where is the advantage of using a dynamic code generator?&lt;br /&gt;
&lt;br /&gt;
&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://lh3.googleusercontent.com/-hUIoGC1e8fE/TYWdl_SaalI/AAAAAAAAAHo/dUAxiid028M/s1600/tokenserial.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="140" src="https://lh3.googleusercontent.com/-hUIoGC1e8fE/TYWdl_SaalI/AAAAAAAAAHo/dUAxiid028M/s320/tokenserial.jpg" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Back Image with Token Serial Number&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;I will keep covering this topic until &amp;nbsp;we have a conclusive answer.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-5855492132337037222?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/6qfobtHIkc5-bwuKRa4E1SrjXuw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6qfobtHIkc5-bwuKRa4E1SrjXuw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/6qfobtHIkc5-bwuKRa4E1SrjXuw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6qfobtHIkc5-bwuKRa4E1SrjXuw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=c_fiV_-N04Y:_tH9rRJ2epk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=c_fiV_-N04Y:_tH9rRJ2epk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=c_fiV_-N04Y:_tH9rRJ2epk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=c_fiV_-N04Y:_tH9rRJ2epk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=c_fiV_-N04Y:_tH9rRJ2epk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/c_fiV_-N04Y" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/c_fiV_-N04Y/rsa-securid-breach-questions.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://lh3.googleusercontent.com/-C-tR4PVXfQc/TYWdasTDEHI/AAAAAAAAAHk/h87pycpqu7s/s72-c/token.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://security.24kasim.org/2011/03/rsa-securid-breach-questions.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-1667429652884594516</guid><pubDate>Wed, 12 Jan 2011 06:17:00 +0000</pubDate><atom:updated>2011-01-17T23:11:06.941-05:00</atom:updated><title>MSSPs - Another one bites the dust - Dell acquires SecureWorks</title><description>So I had&amp;nbsp;to update my chart for &lt;a href="http://istanbul.tc/blog/MSSPhistory.pdf"&gt;MSSP history&lt;/a&gt; ..Again..&lt;br /&gt;
&lt;br /&gt;
SecureWorks no more (independent). As you all know, last Tuesday (Jan 4th) Dell made this announcement from Round Rock, Texas "Dell today announced it has signed a definitive agreement to acquire SecureWorks Inc" &lt;br /&gt;
&lt;br /&gt;
Financial Analysts were puzzled with the "all-cash" move from Dell. How come a technology giant with $53 Billion in annual revenues, is making a scene with a small services company with $120M revenue?..&lt;br /&gt;
&lt;br /&gt;
Before moving to possible reasoning, let's dig the deeper question: "How Much ?"... Terms were not disclosed but here are the facts:&lt;br /&gt;
&lt;br /&gt;
• As of 2010 SecureWorks was completing all the necessary prep work for an IPO after the &lt;a href="http://www.greathillpartners.com/index.php/news/view/100"&gt;2008&lt;/a&gt; fiasco.&lt;br /&gt;
&lt;br /&gt;
• So it is not very difficult to guess the game changer on SecureWorks side: Bags of cash….&lt;br /&gt;
&lt;br /&gt;
• Dell paid 10x reveunue ($1.4B) for a mediocre virtualized storage company (EqualLogic), so why not paying 10x to a successful company with over 3000 qualified "services" buyer accounts? (for those who pull the calc, it makes $1.2 billion in cash, but of course this is a guess – it looks like the number is around 600M) &lt;br /&gt;
&lt;br /&gt;
• Bean counters will need to factor in the cost of acquiring an acqusition mode startup company with plenty of debt when calculating SecureWorks' price tag.(SecureWorks acquired Lurqh, DNS, and Verisign -$45M- MSS lately - from 2004–2008. SecureWorks grew 492 percent)&lt;br /&gt;
&lt;br /&gt;
• At the end of the day IBM paid $1.3B to ISS in 2006.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Why Dell Acquired SecureWorks?&lt;br /&gt;
&lt;br /&gt;
CATALYST:&lt;br /&gt;
&lt;br /&gt;
Security is the catalyst component in many large scale complex deals even if does not present a larger financial percentage of the whole deal. Lately information security is getting more and more byzantine and unmanageable,so selling security hardware/software/consulting does not quench today’s enterprise level security needs. So instead of acquiring half baked hardware/software solutions (like HP's TippingPoint, Arcsight or IBM’s Guardium, Ounce Labs, BigFix acquisitions) Dell made a shortcut to get the whole security package. SecureWorks can offer full security services with or without “best of breed hardware/software” , they do all they need is a “Dell” box loaded with a homemade software such as iSensor, iScanner etc/. &lt;br /&gt;
&lt;br /&gt;
MSP + MSSP &lt;br /&gt;
&lt;br /&gt;
Merging MSPs with MSSPs enable companies like Dell to offer complex services remotely. Outsourcing performed in the form of “body shop” is so 1990s. Taking over the operations of a large company and their IT staff is not outsourcing / neither sending the same operation to overseas. The leverage is where shared services are utilized .That is why Telecoms like Verizon, BT, AT&amp;amp;T and NTT are behind all “managed service” offerings. When compared with HP and IBM, Dell is much better positioned with their strategy. Please evaluate Everdream, Silverback, MessageOne, and KACE acquisitions of Dell. Dell has been making acquisitions to become the “Shared Services” central of the world. Dell is perfectly positioned to offer services remotely from Data Centers without the outsourcing shops like HP-EDS or IBM Global Services. Remote device management, or in Dell’s words “Distributed Device Management” is the next generation of outsourcing. With SecureWorks, Dell will add another critical piece to remote device management and in-the-cloud offerings : Security. (Dell also acquires Perot Systems to fill in the “services” gap) . With SecureWorks, Dell will acquire Verisign’s remote management platform and SecureWorks’ SIM-On-Demand hosted security solutions… Dell already owns in the cloud Message-One security systems..HP and IBM will need to build services around the security tools they have acquired.&lt;br /&gt;
&lt;br /&gt;
POWER OF MARKETING&lt;br /&gt;
&lt;br /&gt;
SecureWorks reached the first 1000 customers with a very small dedicated team from Atlanta, GA. Targeting small credit unions and healthcare organizations, SecureWorks now has around 3000 managed security services customers. Even if the revenue numbers are limited, Dell will be happy to leverage the SecureWorks’ know-how in acquiring “Monthly Recurring Revenue”. &lt;br /&gt;
&lt;br /&gt;
COMPETITION&lt;br /&gt;
&lt;br /&gt;
HP, Dell, Cisco and IBM are in a tight race to own enterprise data centers…Any leverage is welcome for Dell. Many of HP Enterprise Services (HPES - formerly known as EDS) customer shops are SecureWorks customers. Dell’s SecureWorks acquisition puts HP on a very uncomfortable seat. HP does not have an MSSP like IBM (EDS came with UK based Vistorm but try finding "managed security" on hp web sites today) , and they do not have the know-how for build and run an MSSP (where Verizon has Cybertrust, BT has Counterpane , NTT has Integralis, IBM has ISS etc).. it will be an interesting year to watch remaining managed/in-the-cloud security service providers: Perimeter, Fishnet, Trustwave, Solutionary and zScaler. &lt;br /&gt;
&lt;br /&gt;
Outsourcing shops, and System Integrators (SI)s are puzzled with this as well. Other major players like Fujitsu, AT&amp;amp;T, Raytheon, Savvis, Unisys, T-Systems, Tata, CSC, Wipro, Logica and any other large scale Telecoms offer managed security (MSS) as a part of other offerings. Security heavy weights McAfee (now Intel) and Symantec have conflict of interest when offering vendor agnostic services.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
What Does SecureWorks Offer Today?&lt;br /&gt;
&lt;br /&gt;
Managed SERVICES&lt;br /&gt;
&lt;br /&gt;
• SIM On-Demand – SaaS without 3rd party vendors&lt;br /&gt;
&lt;br /&gt;
• Log Monitoring&lt;br /&gt;
&lt;br /&gt;
• Log Retention&lt;br /&gt;
&lt;br /&gt;
• IPS / IDS – via 3rd party CPE and internal appliances&lt;br /&gt;
&lt;br /&gt;
• Firewall via 3rd party CPE and internal appliances&lt;br /&gt;
&lt;br /&gt;
• Web App Firewall&lt;br /&gt;
&lt;br /&gt;
• Host IPS&lt;br /&gt;
&lt;br /&gt;
• Vulnerability Scanning via 3rd party CPE and internal appliances&lt;br /&gt;
&lt;br /&gt;
• Web App Scanning via 3rd party CPE and internal appliances&lt;br /&gt;
&lt;br /&gt;
• Encrypted Email&lt;br /&gt;
&lt;br /&gt;
• Security and Risk Consulting&lt;br /&gt;
&lt;br /&gt;
• Deployment Services&lt;br /&gt;
&lt;br /&gt;
Compliance Solutions&lt;br /&gt;
&lt;br /&gt;
• GLBA/FFIEC – financial services&lt;br /&gt;
&lt;br /&gt;
• HIPAA - healthcare&lt;br /&gt;
&lt;br /&gt;
• NERC CIP - utilities&lt;br /&gt;
&lt;br /&gt;
• PCI – payment services&lt;br /&gt;
&lt;br /&gt;
• FISMA –US government&lt;br /&gt;
&lt;br /&gt;
Vertical Solutions&lt;br /&gt;
&lt;br /&gt;
• Banking Compliance Solutions&lt;br /&gt;
&lt;br /&gt;
• Credit Unions Compliance Solutions&lt;br /&gt;
&lt;br /&gt;
• Utilities Compliance Solutions&lt;br /&gt;
&lt;br /&gt;
• Healthcare Compliance Solutions&lt;br /&gt;
&lt;br /&gt;
• Insurance Compliance Solutions&lt;br /&gt;
&lt;br /&gt;
• Retail Compliance Solutions&lt;br /&gt;
&lt;br /&gt;
• Government Compliance Solutions&lt;br /&gt;
&lt;br /&gt;
Security Research&lt;br /&gt;
&lt;br /&gt;
• Advisories&lt;br /&gt;
&lt;br /&gt;
• Articles&lt;br /&gt;
&lt;br /&gt;
• Counter Threat UnitSM&lt;br /&gt;
&lt;br /&gt;
• Newsletter&lt;br /&gt;
&lt;br /&gt;
• Research Blog&lt;br /&gt;
&lt;br /&gt;
• Security Tools&lt;br /&gt;
&lt;br /&gt;
• Security Threat Analyses&lt;br /&gt;
&lt;br /&gt;
• Webcasts&lt;br /&gt;
&lt;br /&gt;
• White Papers&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
SecureWorks VC investors&lt;br /&gt;
&lt;br /&gt;
Mellon Ventures Inc., GE Capital, SBK Capital, Alliance Technology Ventures L.P., ITC Holding Co. Frontier Capital (via Lurhq) , Great Hill Partners, and Noro-Moseley Partners.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Recent Relevant Dell acquisitions &lt;br /&gt;
&lt;br /&gt;
• Everdream Software 2007 - MSP - Remote Service Management&lt;br /&gt;
&lt;br /&gt;
• ACS (not Xerox' ACS Inc) 2006 - Application Management&lt;br /&gt;
&lt;br /&gt;
• SilverBack Technologies 2007, MSP - Platform Provider&lt;br /&gt;
&lt;br /&gt;
• MessageOne 2008 - Security As a Service (Content Filtering)&lt;br /&gt;
&lt;br /&gt;
• Perot Systems 2009 - SI&lt;br /&gt;
&lt;br /&gt;
• KACE Networks 2010 - MSP Appliance&lt;br /&gt;
&lt;br /&gt;
Recent Relevant IBM acquisitions&lt;br /&gt;
&lt;br /&gt;
• Internet Security Systems (ISS), 2006 - MSSP&lt;br /&gt;
&lt;br /&gt;
• Consul Risk Management, Inc., 2007 - Risk Management&lt;br /&gt;
&lt;br /&gt;
• Watchfire Corporation, 2007 - Security Testing&lt;br /&gt;
&lt;br /&gt;
• Ounce Labs 2009 - Code/Application Security&lt;br /&gt;
&lt;br /&gt;
• Guardium 2010 - Database Security&lt;br /&gt;
&lt;br /&gt;
• BigFix, Inc 2010 - Patch Management&lt;br /&gt;
&lt;br /&gt;
• OpenPages 2010 - GRC&lt;br /&gt;
&lt;br /&gt;
Recent Relevant HP acquisitions&lt;br /&gt;
&lt;br /&gt;
• SPI Dynamics Inc., 2007 - Application Security Testing&lt;br /&gt;
&lt;br /&gt;
• Opsware - 2007 Network management&lt;br /&gt;
&lt;br /&gt;
• Atos Origin Middle East Group - SI&lt;br /&gt;
&lt;br /&gt;
• Electronic Data Systems, 2008 - SI &amp;nbsp;(EDS acquired Vistorm)&lt;br /&gt;
&lt;br /&gt;
• 3Com (includes TippingPoint), 2009 - Network and Security Infrastructure&lt;br /&gt;
&lt;br /&gt;
• ArcSight, 2010 - Security Event and Information Management&lt;br /&gt;
&lt;br /&gt;
• Fortify Software, 2010 - Code/Application Security&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-1667429652884594516?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/B4ehgWlaOQKJyp8eiN31uTksNW4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/B4ehgWlaOQKJyp8eiN31uTksNW4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/B4ehgWlaOQKJyp8eiN31uTksNW4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/B4ehgWlaOQKJyp8eiN31uTksNW4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=NZCM632T_q0:vtbNpHXxGgk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=NZCM632T_q0:vtbNpHXxGgk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=NZCM632T_q0:vtbNpHXxGgk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=NZCM632T_q0:vtbNpHXxGgk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=NZCM632T_q0:vtbNpHXxGgk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/NZCM632T_q0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/NZCM632T_q0/mssps-another-one-bites-dust-dell.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2011/01/mssps-another-one-bites-dust-dell.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-7551447563218108146</guid><pubDate>Sat, 16 Oct 2010 04:57:00 +0000</pubDate><atom:updated>2010-10-23T08:29:47.689-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">phones</category><title>Why Did Nokia Fail in Enterprise Smartphone Business ?</title><description>&lt;span class="Apple-style-span" style="font-family: Arial; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px;"&gt;Q:&amp;nbsp;&lt;/span&gt;&lt;/span&gt;Why Did Nokia Fail in Enterprise Smartphone Business?&lt;br /&gt;
&lt;br /&gt;
&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;A&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;I do write about security, but seeing Nokia fail hurts everyone. (When Dilbert Came to Nokia - &lt;a href="http://www.theregister.co.uk/2010/10/14/nokia_dilbert/"&gt;http://www.theregister.co.uk/2010/10/14/nokia_dilbert/&lt;/a&gt; ) &amp;nbsp;So here is my part of the story. &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;Being a part of one of the largest Nokia Enterprise Security Partners, we felt the Dilbert story of Nokia organization at first hand. Since Nokia Enterprise Security is no more, I can write about what happened. It was around 2004 when Nokia Reps, SEs started to visit us regarding “Mobile Business Solutions” even back then Blackberry was so popular, so we developed an interest in “free” Nokia phones handed to us by Nokia. &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;Nokia Access Mobilizer ( NAM which became N1BS&amp;nbsp; -Nokia One Business Solution) was our first hit. Our idea was that Nokia will deliver an excellent mail server, and then Blackberry would be the history &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;Here is an email I have written to a colleague in 2004 regarding &amp;nbsp;NAM / N1BS&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Here are my notes:&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;N1BS is the new name that Nokia marketing geniuses found for Nokia Access Mobilizer. N1BS stands for Nokia One Business Server.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;N1BS does not run on classic Nokia hardware and the IPSO operating system. Instead, this product runs on a specific blend of Linux called IPSO-SX and the proprietary "Intel" server called EM6000. If you need to dig more here is the Nokia's acquisition path for these products:&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;a- N1BS was acquired from EIZEL in 2003. Its original name was Amplifi : &lt;/span&gt;&lt;/i&gt;&lt;a href="http://web.archive.org/web/20030422051926/http:/www.eizel.com/"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;http://web.archive.org/web/20030422051926/http://www.eizel.com/&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;b-The Linux kernel for IPSO-SX is from Montevista. Isn't it a coincidence that Montevista is a Linux distributor for mobile phones :) &lt;/span&gt;&lt;/i&gt;&lt;a href="http://www.mvista.com/"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;http://www.mvista.com/&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;c- The em6000 hardware is from ablecom which sells the system in the name of superserver: &lt;/span&gt;&lt;/i&gt;&lt;a href="http://www.ablecom.com/system/6013p-8.htm"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;http://www.ablecom.com/system/6013p-8.htm&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;N1BS is good for the following: &lt;br /&gt;
1- Any mobile device with wap browser can access to any web page through its proxy. Device independent internet service. N1BS morphs the web pages to your tiny mobile device screen.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;2- Email and PIM (Calendar-contacts) integration. Supports exchange and Lotus Notes in native mode &lt;br /&gt;
3- Offline sync for PIM and e-mail (through IMAP client) &lt;br /&gt;
4- Content processing; N1BS aggregates/abbreviates the data for you. Image processing: Images are re-rendered. &lt;br /&gt;
5- Viewers for most of the attachments. E.g. powerpoints. pdfs on your phone &lt;br /&gt;
6- Secure, reliable, flexible etc, enterprise marketing stuff.. &lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Here are the highlights that drew my attention &lt;br /&gt;
a- Licensing is important. This device uses FlexLM licenses. This means you get a LAC (License Authorization Code) and generate the real license on Nokia web site. 2 per LAC.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;b- Sensitive information on the device is encrypted with Blowfish &lt;br /&gt;
c- Regular RPM packages are installable by newpkg command. Nokia recommends some packages so this means it does not break the support agreement&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;d- There is an integrated postgreSQL on the box &lt;br /&gt;
e- X libraries are there too. The reason is attachment processing &lt;br /&gt;
f- No "Voyager" or "Clish" on this new IPSO-SX. You are on your own. &lt;br /&gt;
g- No HA or load balancing solutions are in place &lt;br /&gt;
h- No central authentication system integration (LDAP, Radius, AD etc). Even with Radius you need to define users one by one&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;i- No central "config" file like IPSO &lt;br /&gt;
j- No CD bay on the EM6000 hardware &lt;br /&gt;
k- No Cron :) &lt;br /&gt;
l- No SSL accelerator &lt;br /&gt;
m- Nokia gives NAM support from India &lt;br /&gt;
n- There is integrated openoffice for attachment viewing &lt;br /&gt;
o- You may see NAM, MCA, Documa, names in the documentation . They all mean N1BS &lt;br /&gt;
p- No SNMP integration &lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;There is a rumor that Nokia will use this IPSO-SX on the firewalls too but I think it is still too early(See items above that start with No). I have heard that Nokia quit message protector which was also runnning on IPSO-SX&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
N1BS had a brilliant idea, back then smartphones were very expensive and there was a clear need for a mid market mail solution. With Sync-ML and integrated mail/calendar/contact synchronization this was the right solution for midmarket. It also had auto abbreviation which is made sense where data was costing arms and legs.. So we made the decision and I spearheaded the investment on developing a managed services solution for N1BS.. Then came the Nokia announcement, “We do not think that N1BS works like Blackberrry so we are changing the platform”&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;When Nokia canceled N1BS you could tell there was an internal friction at Nokia organization. In September 2005 (&lt;a href="http://www.theregister.co.uk/2005/09/13/nokia_unveils_mobile_email_drive/"&gt;http://www.theregister.co.uk/2005/09/13/nokia_unveils_mobile_email_drive/&lt;/a&gt;) Nokia told us that we were supposed to use Nokia Business Center – NBC,&amp;nbsp; NBC would support push mail that N1BS suffered. So we formatted the N1BS server started from the scratch with NBC, we were still ok because I was a big fan for &amp;nbsp;my S80 9500. We believed in Nokia and continued to market the Nokia mail solution.We built NBC server, tried to build the services around it. But there were problems here is an email I have written in Oct 2005. You can tell that NBC was buggy..Now looking back, I can tell what the problem was; Symbian Group did not work with NBC group at Nokia, they were simply different business lines (retail vs enterprise), so NBC could not use any of the OS level features, even cut&amp;amp;paste was not available to NBC mail client, without phone OS integration NBC's doom was fixed.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;The email client interface is not good. It lacks the basic editing functionality of Nokia Symbian interface. I even could not select-cut&amp;amp;paste the e-mail content. Mouse over dial/e-mail things do not work, I have to go over the menu. Body of the messages format is clumsy.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;If this is a unified messaging tool, then it should. I like the built-in messaging interface more. Built-in mail client has the ability to forward mails to cell phones, and fax (fax, SMS, MMS profiles). Built-in client works perfect..on the other hand NBC client is worse than built-in mail client.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;External e-mail does not work with the following message:&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Sending of e-mail failed . Please try again&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;mail.send.failed:Invalid Addresses&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&amp;nbsp;nested exception.js&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;class.javax.mail.SendFailedException: 451 Can't connect to gmail.com – psmtp.&amp;nbsp;This problem has been fixed&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;PIM sync has its own problems&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;This problem has been fixed. I get PIM sync failed errors sporadically. It works after 2-3 trials&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;When I forward reply and e-mail with NBC, I do not see forward, reply information in Exchange. It only marks read/unread data. If an e-mail is forwarded or replied via business center client, exchange not update the&amp;nbsp; forward/reply history&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Embedded URL links are stripped. No URL links in incoming mail&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;URL links are stripped by NBC server or the client. An example is the following mailAttached below is the outlook version where URL and the links are working.. On NBC both the format is gone and there are no links..&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;I did a couple of tests, this mail goes to gmail&amp;nbsp;as a&amp;nbsp;multi-part message in MIME format with base64 encoding. That may be the problem.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;NBC does not work well with these mails.&lt;br /&gt;
Attachments open a separate interface when 'add' is chosen. This interface requires shut down after adding the attachment.This problem has been fixed&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;I could not manage to delete/edit original mail content when replying&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Connectivity is a big problem… It never survives the night. Executives will not like that.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Clients still hang due to GRPS errors. If they are left on all night (sometimes) or phone is shutdown during communication, the client hangs up in "connecting" state.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Here is the fix that works for me:&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;ol&gt;&lt;li&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;From tools conn.manager menu highlight GPRS connection and disconnect&lt;/span&gt;&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Go to NBC client and switch to offline&lt;/span&gt;&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Reconnect from NBC choose GPRS connection.&lt;/span&gt;&lt;/i&gt;&lt;/li&gt;
&lt;/ol&gt;&lt;br /&gt;
&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Wouldn't be easier if the NBC client disconnects GPRS and reconnects instead off trying "connecting" for hours..?&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;But if the G sign is still there and the connection is not there (G sign not in the box) the conn manager displays receive/sent 0/0kB duration 00:00:00, this means remove the battery - hard reset solution.. I cannot kill/disconnect a an already disconnected GPRS connection..&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;This will be annoying for novice executives..&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Sometimes after rebooting I get the "install business extras?" installation prompt even if it is installed.. Ususally phone crashes afterward, 2,nd remve battery insert batttery solved the problem.. Can we request for a reboot, or ctrl+alt+del button?&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Signature sends a garbage character with rich text. There is no option to choose text/html only signature&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Directory search does not search local contacts database. Sending e-mail to local contacts is difficult.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;When the phone is off (or no coverage), NBC does not work over wi-fi for 9500 hundred. There is no switch connection option either.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;You would think Nokia was settled no, right after we deployed NBC Nokia announced that they have acquired intellisync (Nov 2005) for $430M.( &lt;a href="http://www.infoworld.com/d/networking/update-nokia-acquires-intellisync-430-million-221"&gt;http://www.infoworld.com/d/networking/update-nokia-acquires-intellisync-430-million-221&lt;/a&gt;) I was furious I have developed a solution 2 times for nothing. Intellisync was simply a replication platform on steroids. It was replicating files, emails whatever it could find. Nokia liked it because Verizon, and Vodaphone used it.. (Service Providers used Intellisync because it was cheap) ..Right after the acquisition, I was told we should wait because Intellisync did not match the development quality of Nokia….It was so bad even internal Nokai employees couldn’t switch, they were still on NBC.. So within that turmoil I was invited to a partner conference. Partner conference was for&amp;nbsp; Nokia Business as it is described in the recent register article&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;So this time we did not move.. In 2006 I received an invite from Nokia&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Hello Nokia Partner, &lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Just a note to remind you to register for the Nokia Enterprise Solutions Partner Conference in Boston next month on October 25-27 2006&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Your participation and feedback as one of our most valued partners is vital to our continued growth and success together.&amp;nbsp; This will be one of the most substantial and important Partner Conferences we have had in a number of years.&amp;nbsp; This event will be an opportunity to meet and listen to Nokia Enterprise Solutions Senior Management as they share their vision and strategies for the enterprise market.&amp;nbsp; Mary McDowell, Executive Vice President and General Manager, Nokia Enterprise Solutions, David Petts, Senior VP Global Sales, Marketing &amp;amp; Services, Nokia Enterprise Solutions, and other members of the Nokia management team will be there to present their ideas and to meet you personally.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;You do not want to miss the kick off of our newly designed Partner Program or the roll out of new products that will offer your business new strategic directions.&amp;nbsp; I guarantee you will leave the conference excited, energized, and ready to get to work.&amp;nbsp; We also have a little fun planned.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;During the conference I did speak. I told hundreds of Nokia Executives that as a partner I lost my confidence that nokia could deliver a solution that could last more than 1 year.. nobody listened they were all lost in the glory of the "Intellisync", they even didn’t know about competition, I remember 1 comment, “We are bigger than Microsoft in Operating Systems”…That was nothing more than self soothing propaganda - as we all expected the truth was not so far in the future (&lt;a href="http://www.theregister.co.uk/2010/10/22/symbian_wound_down/"&gt;http://www.theregister.co.uk/2010/10/22/symbian_wound_down/&lt;/a&gt;)&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;So Nokia Enterprise Business gave their promise on 2 major tickets at the Boston conference&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Intellisync is the last stop, trust us, and invest in Intellisync&lt;/li&gt;
&lt;li&gt;Nokia IPSO platform is here to stay, trust us, do not invest in any other appliance&lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;I was like Cassandra, So as expected nothing happened with intellisync, Nokia was so lost, you could tell is when they announced that they are killing Intellisync (&lt;a href="http://www.open-horizons.net/blog/erno/replacement-strategies-did-nokia-kill-intellisync-or-protect-your-investment"&gt;http://www.open-horizons.net/blog/erno/replacement-strategies-did-nokia-kill-intellisync-or-protect-your-investment&lt;/a&gt;) in Sep 2008 Nokia made the expected announcement&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;i&gt;“&lt;br /&gt;
"The Nokia-Microsoft collaboration to bring corporate mobile email to businesses and mobile professionals is truly unbeatable. No other device manufacturer provides the wide range of devices that we have which immediately mobilize the hundreds of millions of email accounts from Microsoft Exchange," said Anssi Vanjoki, Executive Vice President, Markets, Nokia. "The costs of mobility are contained as companies are able to utilize existing Microsoft Exchange infrastructure, and there is also the strong possibility that a large number of employees already have one or more of the 43 Nokia devices that enable Exchange ActiveSync - &lt;/i&gt;&lt;/span&gt;&lt;a href="http://www.designtaxi.com/news/20941/Nokia-brings-Microsoft-Exchange-ActiveSync-Corporate-Mobile-Email-Solutions/"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;i&gt;http://www.designtaxi.com/news/20941/Nokia-brings-Microsoft-Exchange-ActiveSync-Corporate-Mobile-Email-Solutions/&lt;/i&gt;&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;i&gt;"&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;But this time we were prepared we already had Blackberries everywhere..&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-7551447563218108146?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/8E7ZDGG69GATuKnUd6C9GM0fhzc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/8E7ZDGG69GATuKnUd6C9GM0fhzc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/8E7ZDGG69GATuKnUd6C9GM0fhzc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/8E7ZDGG69GATuKnUd6C9GM0fhzc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=bFh16lvCXpw:8d5pB8gbAtw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=bFh16lvCXpw:8d5pB8gbAtw:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=bFh16lvCXpw:8d5pB8gbAtw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=bFh16lvCXpw:8d5pB8gbAtw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=bFh16lvCXpw:8d5pB8gbAtw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/bFh16lvCXpw" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/bFh16lvCXpw/why-nokia-failed-in-enterprise.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2010/10/why-nokia-failed-in-enterprise.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-3682472955506862434</guid><pubDate>Mon, 23 Aug 2010 03:47:00 +0000</pubDate><atom:updated>2011-10-27T19:54:21.254-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">IT-GRC</category><category domain="http://www.blogger.com/atom/ns#">GRC</category><title>IT-GRC ( Governance Risk and Compliance) Tools  - 2010</title><description>I have updated this list (October 2011), you can find the recent copy @ this URL:&lt;br /&gt;
&lt;a href="http://security.24kasim.org/2011/10/itgrc-software-vendors-2011.html"&gt;http://security.24kasim.org/2011/10/itgrc-software-vendors-2011.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Here is the 2010 version:&lt;br /&gt;
-----------------------------------------------------------------------&lt;br /&gt;
&lt;br /&gt;
I stand by my statement that IT-GRC &lt;a href="http://security.24kasim.org/2008/12/why-grc-does-not-stick.html"&gt;does not stick due to several reasons.&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
My previous posts with risk management frameworks and tools are &lt;a href="http://security.24kasim.org/2009/08/it-governance-risk-and-compliance-itgrc.html"&gt;at this link&lt;/a&gt; (I will update risk management tools next month)&lt;br /&gt;
&lt;br /&gt;
Currently there are 4 types of companies at IT GRC market:&lt;br /&gt;
1- IT-GRC vendors: IT Risk Management solutions with integrated workflow and compliance features.&lt;br /&gt;
2- Enterprise GRC vendors: Audit driven ERM tools expanding into IT GRC space&lt;br /&gt;
3- Glorified Access Control Tools: This is the world of SAP, Oracle and the related vendors ( note to the vendors - GRC is not SoD)&lt;br /&gt;
4- Compliance Management Tools (without risk focus)&lt;br /&gt;
&lt;br /&gt;
There are a lot of changes in the market. Market is not as colorful as 2009. I think the main reasons are:&lt;br /&gt;
1- Global market for pure IT-GRC vendors are still around $120M /year.&lt;br /&gt;
2- Entry to market is not very difficult&lt;br /&gt;
&lt;br /&gt;
Big News are:&lt;br /&gt;
CA killed the whole GRC Manager line.&lt;br /&gt;
Archer was acquired by RSA (of EMC) - 04-Jan 2010&lt;br /&gt;
Compliance Spectrum is now history.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Before moving forward, please remember that &lt;a href="http://office.microsoft.com/en-us/excel"&gt;Excel&lt;/a&gt; is 'by far' the most common application in IT-GRC market : )&lt;br /&gt;
&lt;br /&gt;
IT-GRC vendors&lt;br /&gt;
&lt;br /&gt;
Agiliance&lt;br /&gt;
&lt;a href="http://www.agiliance.com/"&gt;http://www.agiliance.com/&lt;/a&gt;&lt;br /&gt;
RSA eGRC - Archer&lt;br /&gt;
&lt;a href="http://www.rsa.com/node.aspx?id=2428"&gt;http://www.rsa.com/node.aspx?id=2428&lt;/a&gt;&lt;br /&gt;
Trustwave GRC (Control Path)&lt;br /&gt;
&lt;a href="https://www.trustwave.com/GRC.php"&gt;https://www.trustwave.com/GRC.php&lt;/a&gt;&lt;br /&gt;
Symantec (Control Compliance Suite)&lt;br /&gt;
&lt;a href="http://www.symantec.com/business/control-compliance-suite"&gt;http://www.symantec.com/business/control-compliance-suite&lt;/a&gt;&lt;br /&gt;
Modulo&lt;br /&gt;
&lt;a href="http://www.modulo.com/"&gt;http://www.modulo.com/&lt;/a&gt;&lt;br /&gt;
Relational Security - RSAM&lt;br /&gt;
&lt;a href="http://www.relsec.com/rsam_overview.htm"&gt;http://www.relsec.com/rsam_overview.htm&lt;/a&gt;&lt;br /&gt;
Lumension&lt;br /&gt;
&lt;a href="http://www.lumension.com/Solutions/IT-Risk-Management.aspx"&gt;http://www.lumension.com/Solutions/IT-Risk-Management.aspx&lt;/a&gt;&lt;br /&gt;
BPS&lt;br /&gt;
&lt;a href="http://www.bpsresolver.com/"&gt;http://www.bpsresolver.com/&lt;/a&gt;&lt;br /&gt;
Avedos&lt;br /&gt;
&lt;a href="http://www.avedos.com/en/home/home.html"&gt;http://www.avedos.com/en/home/home.html&lt;/a&gt;&lt;br /&gt;
BWise&lt;br /&gt;
&lt;a href="http://www.bwise.com/"&gt;http://www.bwise.com/&lt;/a&gt;&lt;br /&gt;
Neupart&lt;br /&gt;
&lt;a href="http://www.neupart.com/"&gt;http://www.neupart.com/&lt;/a&gt;&lt;br /&gt;
Metric Stream&lt;br /&gt;
&lt;a href="http://www.metricstream.com/"&gt;http://www.metricstream.com/&lt;/a&gt;&lt;br /&gt;
Nemea&lt;br /&gt;
&lt;a href="http://www.nemea.us/"&gt;http://www.nemea.us/&lt;/a&gt;&lt;br /&gt;
Highpoint&lt;br /&gt;
&lt;a href="http://www.highpointgrc.com/"&gt;http://www.highpointgrc.com/&lt;/a&gt;&lt;br /&gt;
Paisley Enterprise GRC® for IT (Requires registration to display product information :)&lt;br /&gt;
&lt;a href="http://paisley.thomsonreuters.com/website/pcweb.nsf/pages/ARAE-6XLQSR"&gt;http://paisley.thomsonreuters.com/website/pcweb.nsf/pages/ARAE-6XLQSR&lt;/a&gt;&lt;br /&gt;
OpenPages&lt;br /&gt;
&lt;a href="http://www.openpages.com/solutions/governance_risk_compliance_management_solutions.asp"&gt;http://www.openpages.com/solutions/governance_risk_compliance_management_solutions.asp&lt;/a&gt;&lt;br /&gt;
IDS Scheer (GRC is a part of BPM offering)&lt;br /&gt;
&lt;a href="http://www.ids-scheer.com/us/en/ARIS/ARIS_Solutions/Governance_Risk__Compliance_Management/139893.html"&gt;http://www.ids-scheer.com/us/en/ARIS/ARIS_Solutions/Governance_Risk__Compliance_Management/139893.html&amp;nbsp;&lt;/a&gt;&lt;br /&gt;
ARC Logics &amp;nbsp;- Axentis (same company for CCH TeamMate audit)&lt;br /&gt;
&lt;a href="http://www.axentis.com/Products/Axentis/ProductOverview.html"&gt;http://www.axentis.com/Products/Axentis/ProductOverview.html&lt;/a&gt;&lt;br /&gt;
Methodware&lt;br /&gt;
&lt;a href="http://www.methodware.com/grc/"&gt;http://www.methodware.com/grc/&lt;/a&gt;&lt;br /&gt;
Protiviti&lt;br /&gt;
&lt;a href="http://www.protiviti.com/grc-software/Pages/default.aspx"&gt;http://www.protiviti.com/grc-software/Pages/default.aspx&lt;/a&gt;&lt;br /&gt;
Cura Software&lt;br /&gt;
&lt;a href="http://www.curasoftware.com/pages/content.asp?SectionId=7&amp;amp;SubSectionID=48"&gt;http://www.curasoftware.com/pages/content.asp?SectionId=7&amp;amp;SubSectionID=48&lt;/a&gt;&lt;br /&gt;
Mega&lt;br /&gt;
&lt;a href="http://www.mega.com/index.asp/l/en/c/grc"&gt;http://www.mega.com/index.asp/l/en/c/grc&lt;/a&gt;&lt;br /&gt;
ControlCase&lt;br /&gt;
&lt;a href="http://controlcase.com/it-grc.htm"&gt;http://controlcase.com/it-grc.htm&lt;/a&gt;&lt;br /&gt;
Simeio Solutions GRCAXS (IT GRC module)&lt;br /&gt;
&lt;a href="http://www.simeiosolutions.com/"&gt;http://www.simeiosolutions.com/&lt;/a&gt;&lt;br /&gt;
Compliance 360 ( eGRC )&lt;br /&gt;
&lt;a href="http://www.compliance360.com/"&gt;http://www.compliance360.com/&lt;/a&gt;&lt;br /&gt;
eGestalt SecureGRC - &amp;nbsp;SaaS hosted GRC offering&lt;br /&gt;
&lt;a href="http://www.egestalt.com/"&gt;http://www.egestalt.com/&lt;/a&gt;&lt;br /&gt;
Aline GRC&lt;br /&gt;
&lt;a href="http://www.alinegrc.com/GRC-Platform/20/"&gt;http://www.alinegrc.com/GRC-Platform/20/&lt;/a&gt;&lt;br /&gt;
TrueArx&lt;br /&gt;
&lt;a href="http://www.truarx.com/"&gt;http://www.truarx.com/&lt;/a&gt;&lt;br /&gt;
Easy2Comply&lt;br /&gt;
&lt;a href="http://www.easy2comply.com/"&gt;http://www.easy2comply.com/&lt;/a&gt;&lt;br /&gt;
SAI Global&lt;br /&gt;
&lt;a href="http://www.saiglobal.com/compliance/grc-software/"&gt;http://www.saiglobal.com/compliance/grc-software/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
There are many other tools with ERM (Enterprise Risk Management) Compliance Management, Audit and Access Control Governance feature sets.&lt;br /&gt;
&lt;br /&gt;
Here is a long list of indirect GRC software providers that make auditors happy:&lt;br /&gt;
Oracle (formerly Logical Apps and Oracle GRC Manager)&lt;br /&gt;
&lt;a href="http://www.oracle.com/solutions/corporate_governance/it-grc-management.html"&gt;http://www.oracle.com/solutions/corporate_governance/it-grc-management.html&lt;/a&gt;&lt;br /&gt;
SAP (no clear IT-GRC besides Access Control - SoD)&lt;br /&gt;
&lt;a href="http://www.sap.com/solutions/sapbusinessobjects/large/governance-risk-compliance/index.epx"&gt;http://www.sap.com/solutions/sapbusinessobjects/large/governance-risk-compliance/index.epx&lt;/a&gt;&lt;br /&gt;
Greenlight&lt;br /&gt;
&lt;a href="http://www.greenlightcorp.net/index.aspx"&gt;http://www.greenlightcorp.net/index.aspx&lt;/a&gt;&lt;br /&gt;
Qumas avoids GRC term (Regulatory Compliance)&lt;br /&gt;
&lt;a href="http://www.qumas.com/"&gt;http://www.qumas.com/&lt;/a&gt;&lt;br /&gt;
Aveksa (Enterprise Access Governance)&lt;br /&gt;
&lt;a href="http://www.aveksa.com/"&gt;http://www.aveksa.com/&lt;/a&gt;&lt;br /&gt;
Trintech (Financial controls- no IT)&lt;br /&gt;
&lt;a href="http://www.trintech.com/"&gt;http://www.trintech.com/&lt;/a&gt;&lt;br /&gt;
Doublecheck ERM&lt;br /&gt;
&lt;a href="http://www.doublechecksoftware.com/solutions.htm"&gt;http://www.doublechecksoftware.com/solutions.htm&lt;/a&gt;&lt;br /&gt;
ACL - Transactional controls testing&lt;br /&gt;
&lt;a href="http://www.acl.com/products/ccm.aspx"&gt;http://www.acl.com/products/ccm.aspx&lt;/a&gt;&lt;br /&gt;
Approva (ERP Audit / SoD on steroids)&lt;br /&gt;
&lt;a href="http://www.approva.net/solutions/itsecurity/"&gt;http://www.approva.net/solutions/itsecurity/&lt;/a&gt;&lt;br /&gt;
Strategic Thought (Full Service ERM)&lt;br /&gt;
&lt;a href="http://www.strategicthought.com/"&gt;http://www.strategicthought.com/&lt;/a&gt;&lt;br /&gt;
Open Text Governance, Risk Management &amp;amp; Compliance&lt;br /&gt;
&lt;a href="http://www.opentext.com/2/global/sol-products/sol-pro-compliance-governance/pro-open-text-governance-risk-compliance.htm"&gt;http://www.opentext.com/2/global/sol-products/sol-pro-compliance-governance/pro-open-text-governance-risk-compliance.htm&lt;/a&gt;&lt;br /&gt;
Enablon - ERM&lt;br /&gt;
&lt;a href="http://enablon.com/products/risk-management.aspx"&gt;http://enablon.com/products/risk-management.aspx&lt;/a&gt;&lt;br /&gt;
Pentana Audit Work System (risk Audit)&lt;br /&gt;
&lt;a href="http://www.pentana.com/products.asp#PAWS"&gt;http://www.pentana.com/products.asp#PAWS&lt;/a&gt;&lt;br /&gt;
Grant Thornton - Compliance Management - GT acquired &amp;nbsp;Avalion Consulting ComplianceSet solution&lt;br /&gt;
&lt;a href="http://bit.ly/9bvCFB"&gt;http://bit.ly/9bvCFB&lt;/a&gt; (Long URL shortened)&lt;br /&gt;
Incom Enterprise Risk Mgr ISO 31000&lt;br /&gt;
&lt;a href="http://www.incom.com.au/products.asp?ID=407"&gt;http://www.incom.com.au/products.asp?ID=407&lt;/a&gt;&lt;br /&gt;
EIQNetworks SecureVue also avoids the GRC acronym &lt;br /&gt;
&lt;a href="http://www.eiqnetworks.com/products/SecureVue.shtm"&gt;http://www.eiqnetworks.com/products/SecureVue.shtm&lt;/a&gt;&lt;br /&gt;
Brinqa brings privacy, identity and vendor management &lt;a href="http://www.brinqa.com/solutions"&gt;http://www.brinqa.com/solutions&lt;/a&gt;&lt;br /&gt;
SecurityWeaver (SoD tool) &lt;a href="http://www.securityweaver.com/Products_Separations_Enforcer.asp"&gt;http://www.securityweaver.com/Products_Separations_Enforcer.asp&lt;/a&gt;&lt;br /&gt;
ControlpanelGRC - SOX compliance for SAP users &lt;a href="http://www.controlpanelgrc.com/"&gt;http://www.controlpanelgrc.com/&lt;/a&gt;&lt;br /&gt;
Xpandion SAP Security - &lt;a href="http://www.xpandion.com/"&gt;http://www.xpandion.com/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
IT-GRC software make our lives more organized but we should not skip the motto of the &lt;a href="http://www.csi4global.com/website/index/index.php?pagid=131"&gt;CSI audit peopl&lt;/a&gt;e : " ‘A fool with a tool is still a fool’"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-3682472955506862434?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/3G-smGoelQ4NM0JH48S0Vff4sKI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/3G-smGoelQ4NM0JH48S0Vff4sKI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/3G-smGoelQ4NM0JH48S0Vff4sKI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/3G-smGoelQ4NM0JH48S0Vff4sKI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=B5le1_zPcjk:kBHmZhJbNIM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=B5le1_zPcjk:kBHmZhJbNIM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=B5le1_zPcjk:kBHmZhJbNIM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=B5le1_zPcjk:kBHmZhJbNIM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=B5le1_zPcjk:kBHmZhJbNIM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/B5le1_zPcjk" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/B5le1_zPcjk/it-grc-governance-risk-and-compliance.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2010/08/it-grc-governance-risk-and-compliance.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-5497897693434473917</guid><pubDate>Thu, 17 Jun 2010 13:56:00 +0000</pubDate><atom:updated>2010-06-17T09:56:23.857-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Firewalls</category><title>Free and Commercial Firewall Analysis Tools</title><description>&lt;div style="color: #b45f06;"&gt;&lt;b&gt;Q&lt;/b&gt;:Hello,&lt;/div&gt;&lt;div style="color: #b45f06;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="color: #b45f06;"&gt;Do we have a tool for analyzing Cisco ASA/PIX and router config files?  The client has a 2500 line config, and I would like to be able run some reports on the configuration.&lt;/div&gt;&lt;div style="color: #b45f06;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="color: #b45f06;"&gt;Thanks,&lt;/div&gt;&lt;br /&gt;
&lt;div style="color: #b45f06;"&gt;&lt;b&gt;A:, &lt;/b&gt;&lt;/div&gt;There are several audit tools with different features. The most common features in these tools are: &lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Rule Analysis to detect security holes in the configuration (e.g. allow any) &lt;/li&gt;
&lt;li&gt;Configuration Analysis to find duplicate/overlapping unnecessary setting/rules/object &lt;/li&gt;
&lt;li&gt;Logfile analysis to find most used rules objects &lt;/li&gt;
&lt;li&gt;Rulebase analysis to find unused/unconsolidated objects rules &lt;/li&gt;
&lt;li&gt;Simulation of changes. &lt;/li&gt;
&lt;li&gt;Risk Analysis &lt;/li&gt;
&lt;li&gt;Access Analysis using multiple firewall rules (Can Point A reach at Point B using service C) &lt;/li&gt;
&lt;li&gt;Workflow automation &lt;/li&gt;
&lt;li&gt;Backup management &lt;/li&gt;
&lt;li&gt;Normalization of different firewall rules (e.g. Cisco Juniper Check Point on the same format) &lt;/li&gt;
&lt;li&gt;Change Management &lt;/li&gt;
&lt;li&gt;Regular Log Analysis &lt;/li&gt;
&lt;/ul&gt;&lt;br /&gt;
Of course, it is not possible to find all features on all solutions. Firewall vendors do also provide several tools to make audits easy. &lt;br /&gt;
&lt;br /&gt;
That being said, I have seen 2 freeware config audit tools for Cisco (RAT and Nipper) &lt;br /&gt;
&lt;a href="http://www.titania.co.uk/"&gt;http://www.titania.co.uk/&lt;/a&gt; Nipper &lt;br /&gt;
&lt;a href="http://ncat.sourceforge.net/"&gt;http://ncat.sourceforge.net/&lt;/a&gt; RAT &lt;br /&gt;
&lt;br /&gt;
Commercial Area is more active and they usually cover the known suspects (Check Point, Juniper, Cisco, Fortinet): &lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.tufin.com/"&gt;http://www.tufin.com&lt;/a&gt; SecureTrack, SecureChange Workflow &lt;br /&gt;
&lt;a href="http://www.algosec.com/"&gt;http://www.algosec.com&lt;/a&gt; Firewall Analyzer, FireFlow &lt;br /&gt;
&lt;a href="http://www.securepassage.com/"&gt;http://www.securepassage.com&lt;/a&gt; Firemon &lt;br /&gt;
&lt;a href="http://www.manageengine.com/"&gt;http://www.manageengine.com&lt;/a&gt; Firewall Log Analyzer &lt;br /&gt;
&lt;a href="http://www.skyboxsecurity.com/"&gt;http://www.skyboxsecurity.com/&lt;/a&gt; CertiFire, Firewall Analysis &lt;br /&gt;
&lt;a href="http://www.redseal.net/"&gt;http://www.redseal.net/&lt;/a&gt; Redseal Vulnerability Advisor &lt;br /&gt;
&lt;a href="http://www.athenasecurity.net/"&gt;http://www.athenasecurity.net&lt;/a&gt; FirePac, Verify &lt;br /&gt;
&lt;br /&gt;
Let me know if you have a specific question. &lt;br /&gt;
cheers, &lt;br /&gt;
- yinal&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-5497897693434473917?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/36Zp2Po61iZFjEv8gDEObbl6OXE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/36Zp2Po61iZFjEv8gDEObbl6OXE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/36Zp2Po61iZFjEv8gDEObbl6OXE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/36Zp2Po61iZFjEv8gDEObbl6OXE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=ID5YZLqAV2I:LSanaLnzeGY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=ID5YZLqAV2I:LSanaLnzeGY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=ID5YZLqAV2I:LSanaLnzeGY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=ID5YZLqAV2I:LSanaLnzeGY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=ID5YZLqAV2I:LSanaLnzeGY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/ID5YZLqAV2I" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/ID5YZLqAV2I/free-and-commercial-firewall-analysis.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2010/06/free-and-commercial-firewall-analysis.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-7175381877465261986</guid><pubDate>Thu, 17 Jun 2010 13:48:00 +0000</pubDate><atom:updated>2010-06-17T09:48:50.111-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">VPN</category><category domain="http://www.blogger.com/atom/ns#">IDS IPS Open Source</category><title>HIPS and VPN Concentrator Network Deployment</title><description>&lt;div class="MsoNormal" style="margin-bottom: 3.75pt; vertical-align: baseline;"&gt;&lt;span style="color: #cc6600; font-family: &amp;quot;inherit&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 13.5pt;"&gt;Q: How decide the placement of Host Based Intrusion prevention System &amp;amp; VPN Concentrator&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt; vertical-align: baseline;"&gt;&lt;span style="color: black; font-family: &amp;quot;inherit&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 10pt;"&gt;What is criteria to decide the placement of HIPS and VPN Concentrator.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b style="color: #b45f06;"&gt;A:&lt;/b&gt; Hi XXXXX,&lt;/div&gt;&lt;div class="MsoNormal"&gt;Your question generated more questions than answers : )&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;u&gt;Here is how I think on where host based IPS should be:&lt;/u&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;HIPS should be installed on hosts which need IPS (based on risk assessment). &lt;/li&gt;
&lt;li&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&lt;/span&gt;HIPS should not be installed on hosts where installing a 3&lt;sup&gt;rd&lt;/sup&gt; party agent may decrease the reliability of the services on the host system&lt;/li&gt;
&lt;li&gt;HIPS should not be installed on hosts where installing a 3&lt;sup&gt;rd&lt;/sup&gt; party agent may slow down the speed of the host system due to extra resource utilization, added latency etc.&lt;/li&gt;
&lt;li&gt;HIPS should be installed when it is possible to manage HIPS. In large scale deployments remote installation, central management etc are usually more important than security.&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -0.25in;"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;u&gt;Here are the important points of VPN Concentrator placement:&lt;/u&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;It is recommended that your VPN concentrator has trusted and untrusted segments (It is also possible to deploy one-arm single interface deployments – but for management and audit I do recommend 2 segments – where untrusted segment is Internet facing&lt;/li&gt;
&lt;li&gt;Untrusted segment should be protected by a firewall &amp;nbsp;(usually in a dedicated DMZ) even if all VPN vendors claim to be very secure. Make sure that the firewall protecting your VPN supports IPSEC pass through (if you are using IPSEC). &lt;/li&gt;
&lt;li&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&lt;/span&gt;Instead of hooking the trusted (Internal) segment into your (internal) networks, connect your trusted segment back to the firewall so that decrypted traffic is firewalled. If you have an IPS make sure that IDS/IPS is inspecting decrypted traffic.&lt;/li&gt;
&lt;li&gt;Make sure that you have a dedicated management network to manage the VPN concentrator. If you do not have an extra management interface, use trusted interface for management. Do not allow management over untrusted interface.&lt;/li&gt;
&lt;li&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&lt;/span&gt;Do not deploy NAT before the VPN traffic hits your concentrator, &amp;nbsp;try to use real public IP address (es) &amp;nbsp;on the untrusted /public&amp;nbsp; side of your concentrator&amp;nbsp; &amp;nbsp;since using private addresses may create configuration nightmares&lt;/li&gt;
&lt;li&gt;Check destination networks for VPN clients / or remote VPN sites on your network. Analyze the protocols. Sometimes based on the nature of the traffic (e.g. complex VOIP) &amp;nbsp;you may need to hook your concentrator directly into your network. &amp;nbsp;Always check reverse routing for VPN networks.&lt;/li&gt;
&lt;li&gt;Verify IP addressing assignments for VPN clients, choose a subnet that will not create internal routing problems (e.g. overlapping IP address space. Dynamic routing etc). If you are dealing with site to site VPNs make sure that you address overlapping IP address spaces.&lt;/li&gt;
&lt;li&gt;Check the location of authentication servers. The placement of the concentrator must be is close/redundant proximity to authentication servers (AD, RADIUS, TACACS, LDAP etc). Make sure that the communication with auth servers is not a n issue&lt;/li&gt;
&lt;li&gt;Verify multiple entry points, if you are deploying concentrators in HA, make sure that failover works properly, and NAT issues, IP address assignments for different concentrators&amp;nbsp; are configured properly. Also make sure that your access logs can be unified.&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;Let me know if you have a specific question,&lt;/div&gt;&lt;div class="MsoNormal"&gt;Cheers,&lt;br /&gt;
-&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt; y&lt;/span&gt;inal&lt;/div&gt;&lt;span id="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-7175381877465261986?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/YlN5ZT2JsE05yQZPQbUAmoFJRU0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/YlN5ZT2JsE05yQZPQbUAmoFJRU0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/YlN5ZT2JsE05yQZPQbUAmoFJRU0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/YlN5ZT2JsE05yQZPQbUAmoFJRU0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=J5Hfb4TN7I8:XvYCjjkoPE4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=J5Hfb4TN7I8:XvYCjjkoPE4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=J5Hfb4TN7I8:XvYCjjkoPE4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=J5Hfb4TN7I8:XvYCjjkoPE4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=J5Hfb4TN7I8:XvYCjjkoPE4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/J5Hfb4TN7I8" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/J5Hfb4TN7I8/hips-and-vpn-concentrator-network.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2010/06/hips-and-vpn-concentrator-network.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-7821689812411475335</guid><pubDate>Sat, 05 Jun 2010 22:56:00 +0000</pubDate><atom:updated>2010-08-22T23:59:37.291-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Mergers and Acquisitions</category><title>Why did Symantec buy Verisign's security business ?</title><description>&lt;b style="color: #b45f06;"&gt;Q: Why did Symantec buy Verisign's security business ?&lt;/b&gt;&lt;br /&gt;
A 3.5 revenue multiple for a revenue stream comprising largely of a commoditized business (SSL) begs for a strong rationale that goes beyond pure top line growth for this acquistion. Would love to hear of use cases that this will enable that will result in new products/offers from this combined entity.&lt;br /&gt;
&lt;br /&gt;
&lt;b style="color: #b45f06;"&gt;A: Here are quick comments: &lt;/b&gt;&lt;br /&gt;
1- Symantec will have direct access to almost all major enterprise accounts using Verisign's SSL certificate relationship. there are a lot of cross-sell opportunities for Symantec such as securing server 2 server communication. On the retail side Symantec can cross sell Norton line at Verisign's high-volume SSL online store &lt;br /&gt;
&lt;br /&gt;
2- Last year Verisign asold MSS (to Secureworks) and security consulting (to AT&amp;amp;T) units, these were the overlapping units for Symantec. The security products that Symantec acquired from Verisign do not have an overlap with Symantec's existing portfolio. &lt;br /&gt;
&lt;br /&gt;
3- Related with the note above, Symantec could not provide full identity management solutions. With Verisign acqusition (SSL certificates, Trust Seal, PKI, VIP ) they will fill-in a big gap. This creates a nice go-to-market plan. e.g. Hosted PKI, Norton Identity Safe etc.. &lt;br /&gt;
&lt;br /&gt;
4- All cloud based / remote management solutions (e.g. HEP from Symantec) rely on certificates, Verisign acquisition will play a strong role for Symantec's cloud strategy. Identity security is a key block in delivering cloud based solutions for data security and compliance. &lt;br /&gt;
&lt;br /&gt;
5- Check-out PGP and GuardianEdge acquisitions. They will all integrate well with Vontu line when Verisign's solutions are added to the mix..Verisign complements encryption really well. Re-evaluate data at rest, data in transit and data in use terms : ) &lt;br /&gt;
&lt;br /&gt;
6- Verisign has a good brand name, Symantec can definitely leverage the Verisign name&lt;br /&gt;
&lt;br /&gt;
7- The value of the deal can be multiplied if Symantec manages to integrate security solutions (inlcuding this Verisign Portfolio) with its Veritas, Altiris, MSS, and Hosted Security (MessageLabs) lines. &lt;br /&gt;
&lt;br /&gt;
Let me know if you have a specific question, &lt;br /&gt;
&lt;br /&gt;
regards,&lt;br /&gt;
- yinal ozkan &lt;br /&gt;
&amp;nbsp;(on personal behalf)&lt;br /&gt;
&lt;span id="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-7821689812411475335?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/DydSRc7rtclT512hdHcpsWOf0EY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DydSRc7rtclT512hdHcpsWOf0EY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/DydSRc7rtclT512hdHcpsWOf0EY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DydSRc7rtclT512hdHcpsWOf0EY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=O36vDgRlZRs:wm1GZEAZGYY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=O36vDgRlZRs:wm1GZEAZGYY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=O36vDgRlZRs:wm1GZEAZGYY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=O36vDgRlZRs:wm1GZEAZGYY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=O36vDgRlZRs:wm1GZEAZGYY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/O36vDgRlZRs" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/O36vDgRlZRs/why-did-symantec-buy-versigns-security.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2010/06/why-did-symantec-buy-versigns-security.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-6336899340754884052</guid><pubDate>Sat, 05 Jun 2010 22:51:00 +0000</pubDate><atom:updated>2010-06-05T18:51:21.161-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">DLP SaaS</category><title>DLP as a Service: What's the business case for this?</title><description>&lt;div style="color: #b45f06;"&gt;&lt;b&gt;&lt;u&gt;Question:&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="color: #b45f06;"&gt;DLP as a Service: What's the business case for this?&lt;/div&gt;&lt;br /&gt;
&lt;b&gt;&lt;u&gt;Answer:&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Xxxxxx,&lt;br /&gt;
DLP can leverage all the advantages of service-alization on legacy information systems.&lt;br /&gt;
If we define service a standard offering delivered by a service provider, business case (of DLP as a service versus technology solution) can be summarized as:&lt;br /&gt;
1- Leveraging economies of scale with utilizing shared resources at service provider&lt;br /&gt;
2- Leveraging deep-dive technical specialization at service provider since service provider can effort dedicated specialists (not because they are more intelligent). Levering know-how gained from managing multiple customers.&lt;br /&gt;
3- Measurements and metrics program guaranteed by service level agreements&lt;br /&gt;
4- Ability to scale up/down easily, more reliability and redundancy on the provider side.&lt;br /&gt;
5- The old capex vs opex discussion&lt;br /&gt;
6- No operational worries (e.g. who will patch my appliance) / focus on core business goals, competitiveness&lt;br /&gt;
7- Pay as you go elastic service.&lt;br /&gt;
&lt;br /&gt;
But if you look at DLP specific cases, the answers could be categorized in many different buckets. (this might be different for different organizations). We believe that a DLP program must include &lt;br /&gt;
• DLP program management (GRC, Policies , Procedures)&lt;br /&gt;
• Endpoint enforcement components, &lt;br /&gt;
• Secure remote access components,  &lt;br /&gt;
• Data classification &amp;amp; governance components, &lt;br /&gt;
• Encryption components &lt;br /&gt;
• Rights management components. &lt;br /&gt;
• Training and user awareness component&lt;br /&gt;
• Incident management component&lt;br /&gt;
• Central monitoring , Access Control, RBCA the usual InfoSec components&lt;br /&gt;
&lt;br /&gt;
This can all be offered as a hybrid service of people, process, technology and managed services. Usually an important component of DLP program is the network based DLP gateway solutions. A managed offering for network level DLP gateway may offer&lt;br /&gt;
1- Ability to get a clean pipe from service provider (e..g prevention in the cloud)&lt;br /&gt;
2- Ability to leverage a wide set of solutions for the recognition of different data types / file formats since service provider is developing the service for other customers&lt;br /&gt;
3- Ability get experts for custom scripting (yes you will need this)&lt;br /&gt;
4- Transparent deployment&lt;br /&gt;
5- Correlation of events with other network activities (e.g. IPS, Anomaly Detection, Content security solutions, Firewalls, AV etc)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span id="fullpost"&gt; Type rest of the post here &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-6336899340754884052?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/vHAMwxskGO8ntKWzGT3cs25wz9I/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vHAMwxskGO8ntKWzGT3cs25wz9I/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/vHAMwxskGO8ntKWzGT3cs25wz9I/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/vHAMwxskGO8ntKWzGT3cs25wz9I/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=X5EMYxvWjuk:Knm2iE_4_tI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=X5EMYxvWjuk:Knm2iE_4_tI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=X5EMYxvWjuk:Knm2iE_4_tI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=X5EMYxvWjuk:Knm2iE_4_tI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=X5EMYxvWjuk:Knm2iE_4_tI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/X5EMYxvWjuk" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/X5EMYxvWjuk/dlp-as-service-whats-business-case-for.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2010/06/dlp-as-service-whats-business-case-for.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-6485477982906196115</guid><pubDate>Sat, 05 Jun 2010 22:47:00 +0000</pubDate><atom:updated>2010-06-05T18:47:59.285-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">IDS IPS Open Source</category><title>Open Source IDS/IPS</title><description>&lt;span style="color: orange;"&gt;&lt;b&gt;&lt;u&gt;Question &lt;/u&gt;&lt;/b&gt;: Are there an &lt;b&gt;open source&lt;/b&gt; IDS or Firewall which alert the command center or system administrator by pager, e-mail or cell phone when an event listed on the company’s security event list is triggered?&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;Answer:&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Xxxxxxxxxx,&lt;br /&gt;
The answer will be based on the company’s security event list. The first prerequisite is that you need to find an opensource IDS or Firewall that can detect security events in the list. Detection success rate will be based on the complexity of the security events in your list. &lt;br /&gt;
&lt;br /&gt;
Firewalls are usually not very good in malicious activity detection so IDS/IPS is a better idea. Snort is a good start (http://www.snort.org/) . It is opensource and it allows you to configure your custom detection signature and rules. &lt;br /&gt;
&lt;br /&gt;
Alerting is simple, you can configure Snort to alert via e-mail E-mail messages can be converted to SMS and pager messages easily. (you may need to pay for SMS messages depending on the destination and or geographic location) &lt;br /&gt;
&lt;br /&gt;
For IDS/IPS deployment you have to be careful. You might be receiving millions of alerts so forwarding them as a message might not be the best good idea. You need to tune your IDS to report real incidents only (e.g. you may have detected 1 million identical events but all you need is to know what the incident is when it started and what is the frequency). Also remember that Snort will only inspect cleartext traffic in day1 unless you are decrypting the encrypted traffic. &lt;br /&gt;
&lt;br /&gt;
Another approach is to use a Security Information Event Management Solution in addition to the IDS. Forward all Snort alerts and other alerts (e.g. Windows logs, Syslog) to your SIEM tool and make sure that the SIEM consolidates normalizes and correlates the alerts for you, so that you receive the ultimate information from SIEM instead of IDS tools. There are opensource SIEM tools like OSSIM (http://sourceforge.net/projects/os-sim/) and Cyberoam iView (http://sourceforge.net/projects/cyberoam-iview/files/) &lt;br /&gt;
&lt;br /&gt;
Let me know if you have a specific question, &lt;br /&gt;
&lt;br /&gt;
Cheers, &lt;br /&gt;
- yinal&lt;br /&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;span id="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-6485477982906196115?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/EkrJcmdcrzuJrHzSNo9MGmdHbuQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/EkrJcmdcrzuJrHzSNo9MGmdHbuQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/EkrJcmdcrzuJrHzSNo9MGmdHbuQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/EkrJcmdcrzuJrHzSNo9MGmdHbuQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=qE1rmvzEm8w:Se2q_v8xewU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=qE1rmvzEm8w:Se2q_v8xewU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=qE1rmvzEm8w:Se2q_v8xewU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=qE1rmvzEm8w:Se2q_v8xewU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=qE1rmvzEm8w:Se2q_v8xewU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/qE1rmvzEm8w" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/qE1rmvzEm8w/open-source-idsips.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2010/06/open-source-idsips.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-5947869062600718046</guid><pubDate>Tue, 23 Mar 2010 17:27:00 +0000</pubDate><atom:updated>2010-03-23T13:27:20.650-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">outsourcing</category><category domain="http://www.blogger.com/atom/ns#">remote access</category><title>Securing Offshore Remote Access</title><description>&lt;b&gt;Question:&lt;/b&gt;&lt;br /&gt;
How to secure data and protect intellectual property while allowing remote access to remote consultants / outsourcing partners / offshore captive operations? &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Answer:&lt;/b&gt;&lt;br /&gt;
This is a long procedural and legal discussion. Restriction of access for remote administrators / consultants / offshore centers is not an actual “productivity” solution, so there is a clear need for sharing data in an intelligent and secure way. &lt;br /&gt;
Recently I have seen several discussions on policy based governance and operational controls but I was disappointed with the available technical options. Most of the articles I have seen so far were limited with phrases like “We do use firewalls”, ”We have SAS 70” , “We have strong authentication” or “We do have encryption” type of over the counter canned answers. The most joyful one was (this was on an overseas web site describing how secure the outsourcing operations were) : “We do use SecureFTP”&lt;br /&gt;
Well, basic technical controls are nice, like using scrubbed test data, segmenting servers,&amp;nbsp; using strong auth, physical data center security, or using full VPNs..But, what if the requirement is to have real controls?&lt;br /&gt;
&lt;br /&gt;
The technical controls can be deployed at 2 layers:&lt;br /&gt;
1-&amp;nbsp;&amp;nbsp;&amp;nbsp; Controls at the Offshore Center: Regardless of the desktop security controls, endusers at remote data centers can access and steal critical data, at the end of the day, who will stop them if they can take a 5 megapixel shot of their screens with their cell phones. So it is a good idea to have a CCTV / camera based monitoring where access stations are (All remote access should be limited to secured facilities where it is possible – try to avoid roaming laptop based remote workers). I use the term access station because it makes no sense to have regular desktops at offshore operational centers.&amp;nbsp; Using terminal server type of solutions are great but citrix/terminal server type of emulations do not work great for developers. I like virtual desktop infrastructure (VDI) for developers since it gives them full independence in a controlled environment.&amp;nbsp; Base station should be thin clients or must be managed (e.g. group policies with limited user rights) even if they are using the base station only for terminal session.&lt;br /&gt;
If you do not have a captive center, and you do not have the full control on remote desktops or you cannot enforce thin client stations or managed workstations, securing the other endpoint (where terminal connection/citrix/VDI term is run) is very difficult. On these cases, make sure that you require VPN connection from individual endpoints so that you can control split tunneling, and you can apply /enforce pre-auth/during-auth posture checks very much like a NAC. The idea is to enforce endusers to install a security applet before they login to your network and run cleaning prior to auth. Create onetime secure virtual workspace that expire at the end of the session. You may also create remediation and quarantine options for non-managed remote access.&lt;br /&gt;
When you are securing the remote offshore centers never skip the “air” piece. Roque AP detection is a key feature. Your remote switch must detect any attached device to network esp if it is working as a switch. Also your policies must limit usage of cell phones and other wireless gadgets.&lt;br /&gt;
Of course endpoint security is still a key, like using full group policies, firewall/IPS, antimalware, antivirus, encryption, rights management etc, but it is much better to have it on a VDI system. It is also easier to control peripherals on a VDI. &lt;br /&gt;
Non-repudiation is another important point. Like the physical camera, a secure remote tamper proof logging facility is highly recommended.&lt;br /&gt;
2-&amp;nbsp;&amp;nbsp;&amp;nbsp; Controls at the server level: Consultants / remote system administrators/ offshore developers do need to access servers in development, test and sometimes production environment. It is a mandate to enforce individual user identities, with full access audit. Actually you can steal the PCI requirements.&amp;nbsp; There are systems that record every single move (literally on a video file&amp;nbsp; - ObserveIT) of a remote administrator. Or you can basically deploy privilege escalation management systems integrated with jump servers (e.g. SSH proxies, Power Broker) Need to know access is essential, but even after policy decisions, make sure that every activity is logged at different layers (network layer, OS layer, DB layer and Application layer) Remote admins should never access to log settings or the log repository (tamper proof logging is the key). This is the time to put SIEM solutions in use. Write correlation rules to alert you when suspicious activity is detected.&lt;br /&gt;
Segmentation is another key, but today’s high speed computing makes network level firewalling very difficult. (If you have 100 servers with only 1 Gbps NICs, you will a 100Gbps full duplex firewall ,&amp;nbsp; and as of today there is no IPS). I do expect switch vendors to offer port based filrewalling / IPS in the very near future but not today unless you have 7 figures to spend. Either way segment your servers at network level as much as possible, Even if you are using VMware, categorize servers physically according to their risk levels. There are also creative solutions like Apani Networks, Rohati Networks (now Cisco), or the NAC vendors for network based segmentation using user identities. Basically segmenting users with their user IDs instead of their source and destination addresses is better. You can even utilize secure de&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Again, none of the technical controls eliminate the need for governance, policy based controls and the risk management frameworks. &lt;br /&gt;
Full data life-cycle management, data privacy, data security, audit program, security management program (like ISO 27001)&amp;nbsp; are all essential. But technical controls do really help you to reach your security objectives.&lt;br /&gt;
&lt;br /&gt;
Let me know if you have a detailed question&lt;br /&gt;
&lt;br /&gt;
Regards,&lt;br /&gt;
-&amp;nbsp;&amp;nbsp;&amp;nbsp; Yinal Ozkan&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-5947869062600718046?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/FtQ8UG47n8UDZPoGzuCW8JxQ_Kw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/FtQ8UG47n8UDZPoGzuCW8JxQ_Kw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/FtQ8UG47n8UDZPoGzuCW8JxQ_Kw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/FtQ8UG47n8UDZPoGzuCW8JxQ_Kw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=Ztp3nFJb4Lw:bTf4lkY6-VE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=Ztp3nFJb4Lw:bTf4lkY6-VE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=Ztp3nFJb4Lw:bTf4lkY6-VE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=Ztp3nFJb4Lw:bTf4lkY6-VE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=Ztp3nFJb4Lw:bTf4lkY6-VE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/Ztp3nFJb4Lw" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/Ztp3nFJb4Lw/securing-offshore-remote-access.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2010/03/securing-offshore-remote-access.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-8966812585714375328</guid><pubDate>Mon, 08 Feb 2010 13:42:00 +0000</pubDate><atom:updated>2010-02-08T08:42:15.370-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Security Awareness</category><title>Security awareness - what worked for you</title><description>&lt;div class="MsoNormal" style="margin-bottom: 3.75pt; mso-line-height-alt: 9.0pt; mso-outline-level: 1; vertical-align: baseline;"&gt;&lt;span style="color: #cc6600; font-family: &amp;quot;inherit&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 13.5pt; mso-bidi-font-family: Arial; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-font-kerning: 18.0pt;"&gt;Question:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin-bottom: .0001pt; margin-bottom: 0in; mso-line-height-alt: 9.0pt; vertical-align: baseline;"&gt;I am interested to know from you guys what methods you have used to prick the consciousness of your end users - from the standard policy delivery &amp;amp; enforcement tools (e.g. neupart, policy matter, netconsent, et al), through posters &amp;amp; startup screens, right through to "guerilla tactics" rather like Chris Nickerson &amp;amp; hisd guys who did the job on the car dealer.&lt;br /&gt;
&lt;br /&gt;
I had thought of gearing ideas around end user pain points - e.g. post-it notes with a PIN on a dummy credit card, etc. Interested in what low-cost ways others have used.&lt;br /&gt;
&lt;br /&gt;
Thanks in advance guys&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="margin-bottom: 3.75pt; margin-left: 0px; margin-right: 0px; margin-top: 0px; vertical-align: baseline;"&gt;&lt;span style="color: #cc6600; font-family: inherit, serif; font-size: 13.5pt;"&gt;Answer:&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="MsoNormal"&gt;........,&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-bookmark: OLE_LINK1;"&gt;I have gone through several iterations of awareness initiatives. Web based, class based, print media based, campaign based you name it… &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-bookmark: OLE_LINK1;"&gt;Information Security Practitioners usually skip a very important part of awareness programs, these programs are not security projects where you deliver a technical solution; awareness programs depend on the training component…&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-bookmark: OLE_LINK1;"&gt;Here is the most important thing I learned: Adult psychology is different, you cannot train adults as you train kids.. When you put kids a in a class they simply listen and they learn. Adults never do, they keep questioning: “ Why I am here? Is this good for me? What will I lose if I do not listen? What is in it for me? etc”&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;The questions above must be answered within security awareness initiative since they will keep occupying the short focus of the of the adult minds during training.. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-bookmark: OLE_LINK1;"&gt;So the important structural shift of awareness program initiative is that this is not a project, this not about a portal with multiple choice questions with diagrams, this is not about an application that pops-up, &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;this is about training, and the adult training rules apply. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-bookmark: OLE_LINK1;"&gt;Years ago, I was in charge of security awareness training &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;of a large trading house.. Participation of all employees was mandatory. Everybody in the class (pre WebEx days) thought this was yet another training, and the eyes were focused on the clock.. I started the conversation with, “I am reading all your e-mail” Well, I got the attention. The whole class got mad . But we had established the training rationale, everybody wanted to how and why I was able to read their e-mail , they were questioning on who else can read their e-mail. Until that moment most of them thought the problems were someone else’s.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-bookmark: OLE_LINK1;"&gt;In order to share create the &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;personal interest, the best way is to demonstrate vulnerability in day to day applications with live demonstrations (not the checklists, and the pop-quizzes) that employees can associate themselves individually.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;The demo should not be about the millions that a distant company lost (yes we all heard about TJ Max) or powerpointing defaced web sites to death to bore sales team away. There must be personal interest in security awareness program. Unfortunately not too many people care about the greater good of their employers or the security teams…A salesperson will be more interested so see his CRM database being stolen using his own small blackberry.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Or displaying chain of evidence for intellectual property for design engineers, more examples can be given but I think everybody who has managed to read until this paragraph gets the idea; unless there is personal interest there won’t be success. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-bookmark: OLE_LINK1;"&gt;That being said classical program components like continuous improvement, cyclic approach, audit, measurement/metrics etc will help. ISO programs or the programs like neupart can be used as a good base program management.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="mso-bookmark: OLE_LINK1;"&gt;-Regards,&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoListParagraph" style="mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;&lt;span style="mso-bookmark: OLE_LINK1;"&gt;&lt;span style="mso-ascii-font-family: Calibri; mso-bidi-font-family: Calibri; mso-fareast-font-family: Calibri; mso-hansi-font-family: Calibri;"&gt;&lt;span style="mso-list: Ignore;"&gt;-&lt;span style="font: 7.0pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Yinal Ozkan&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-8966812585714375328?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/fN-7ukR9DWW7i-YfZx3H1LTlxK4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fN-7ukR9DWW7i-YfZx3H1LTlxK4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/fN-7ukR9DWW7i-YfZx3H1LTlxK4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fN-7ukR9DWW7i-YfZx3H1LTlxK4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=ySqVU82AA2c:zPH4pz8Bw10:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=ySqVU82AA2c:zPH4pz8Bw10:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=ySqVU82AA2c:zPH4pz8Bw10:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=ySqVU82AA2c:zPH4pz8Bw10:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=ySqVU82AA2c:zPH4pz8Bw10:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/ySqVU82AA2c" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/ySqVU82AA2c/security-awareness-what-worked-for-you.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2010/02/security-awareness-what-worked-for-you.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-6380801199943142061</guid><pubDate>Sun, 06 Dec 2009 18:57:00 +0000</pubDate><atom:updated>2009-12-06T13:58:34.534-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">architecture</category><category domain="http://www.blogger.com/atom/ns#">authentication</category><title>Using Certificates for Authentication ? Where to store them ?</title><description>&lt;div class="MsoNormal" style="margin-bottom: 3.75pt; mso-line-height-alt: 11.25pt; mso-outline-level: 1;"&gt;&lt;span style="color: #cc6600; font-family: Arial, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Question:&amp;nbsp;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="margin-bottom: 3.75pt; mso-line-height-alt: 11.25pt; mso-outline-level: 1;"&gt;&lt;span style="color: #cc6600; font-family: Arial, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;Has anyone deployed a VPN solution that leverages user certificates for authentication?&lt;/b&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: 11.25pt; margin-bottom: .0001pt; margin-bottom: 0in;"&gt;&lt;span style="color: black;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;We are considering the possibility of leveraging digital certificates as an authentication factor for VPN. Has anyone implemented this or looked&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: black;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt; at solutions that do this? We are not comfortable with solely relying on a certificate and the security/integrity of the PC as an authentication mechanism. If you are currently using certificates, I would be interested in hearing how you are deployin&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: black;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;g this.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;o:p&gt;&lt;span style="font-family: Arial, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;b&gt;&lt;span style="color: #b45f06;"&gt;Answer:&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;.....,&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The sho&lt;/span&gt;&lt;span style="color: #b45f06;"&gt;&lt;span style="font-size: small;"&gt;r&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: small;"&gt;t answer is yes.&amp;nbsp; We did deploy several off-the-shelf certificate based authentication solutions for remote access VPN systems such as Cisco, Check Point, Juniper, Citrix, Nortel.. It is again very possible to deploy similar solutions over SSL VPN solutions (This time easier since browser is the client).&amp;nbsp; &amp;nbsp;I worked with Entrust as the PKI integration provider. &amp;nbsp;When using certs, most of the questions/problems are generic PKI related questions (CRLs, &amp;nbsp;OCSP, identity management etc)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;9 out of 10, enterprise shops store the certs on PC or mobile devices since they want to avoid using tokens/smart cards. Using a 3&lt;/span&gt;&lt;/span&gt;&lt;sup&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;rd&lt;/span&gt;&lt;/span&gt;&lt;/sup&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt; party storage is ideal but to be honest smart cards share the fate of PKI for complexity so many solution sets avoid tokens/smart cards, unless the policies mandate certificates.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;When smart cards are more expensive/complex (readers, personalization etc) enterprises use USB tokens to store certificates. (Several companies &amp;nbsp;provide tokens with certificate support, ActivIdentity, Aladdin, Authenex, Entrust, SafeNet (merged with Aladdin) , RSA (RSA has a hybrid token for OTP + certs)). &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;If you would like to use smart cards as the certificate container, or use the same certs for physical security simultaneously, you can simple take one of the ready to use HSPD-12 Personal Identity Verification (PIV) Card solutions (&lt;/span&gt;&lt;/span&gt;&lt;a href="http://fips201ep.cio.gov/apl.php"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;http://fips201ep.cio.gov/apl.php&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;) so that you can avoid designing all components architecture yourself.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Of course do it yourself path is more fun, technically it is straightforward to integrate certs with any 802.1x based authentication server but as you know it usually gets more complex. We have deployed a complete system for enrollment, biometrics, cards, CMS etc, (took 3+ years)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;cheers,&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="mso-list: l0 level1 lfo1; text-indent: -.25in;"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;-&lt;/span&gt;&lt;/span&gt;&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; - y&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: Arial, Helvetica, sans-serif;"&gt;&lt;span style="font-size: small;"&gt;inal ozkan&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-6380801199943142061?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/CHOr9BZ9o8akM0LOJnnhmUvrces/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/CHOr9BZ9o8akM0LOJnnhmUvrces/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/CHOr9BZ9o8akM0LOJnnhmUvrces/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/CHOr9BZ9o8akM0LOJnnhmUvrces/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=fUBFmhKDQyc:qOqTzyJXGt8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=fUBFmhKDQyc:qOqTzyJXGt8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=fUBFmhKDQyc:qOqTzyJXGt8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=fUBFmhKDQyc:qOqTzyJXGt8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=fUBFmhKDQyc:qOqTzyJXGt8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/fUBFmhKDQyc" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/fUBFmhKDQyc/using-certificates-for-authentication.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>1</thr:total><feedburner:origLink>http://security.24kasim.org/2009/12/using-certificates-for-authentication.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-1070097458770488809</guid><pubDate>Mon, 16 Nov 2009 12:14:00 +0000</pubDate><atom:updated>2009-11-16T07:14:21.406-05:00</atom:updated><title>Best way to stop malware from spreading in a large secure network</title><description>&lt;strong&gt;Question :&lt;/strong&gt;What's the best way to stop malware from spreading in a large secure network with no internet connectivity and a multi-platform environment?&lt;br /&gt;
&lt;br /&gt;
Even though the secure environment has no internet access and is on a controlled environment, external USB devices have been added to the network and viruses have been introduced. I'm trying to think of the best ways to stop such external threats being added to a secure closed network. I've got a few ideas bouncing around my head as I believe Antivirus software should be deployed on the workstations in case additional methods of malware introduction are given other that USB. The USB ports could be disabled on all workstations and then the external devices could be scanned before adding to the network. But I'm sure there could be other ideas so can someone offer some suggestions?&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Answer:&lt;/strong&gt;There are multiple approaches, but “the” best way will depend on the mix of your devices in your multi-platform environment (if you still have NT4s and ancient slackware linux copies the solutions you are looking at will be different) and your network status. If there is no internet connectivity naturally you should focus more on entry points (intranets, USB, CD, Floppy, Bluetooth, IR, Wi-Fi)&lt;br /&gt;
&lt;br /&gt;
If you want to classify approaches, your solutions can be at 3 levels, host based, network based and hybrid.&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;1- Host Based:&lt;/em&gt;&lt;br /&gt;
&lt;br /&gt;
a. Use a comprehensive “endpoint security” solution that will have &lt;br /&gt;
&lt;br /&gt;
i. Port Control (USB, CD, Floppy, Bluetooth, IR, Wi-Fi, Ethernet etc)&lt;br /&gt;
&lt;br /&gt;
ii. Encryption (file, disk, mail), key/cert management&lt;br /&gt;
&lt;br /&gt;
iii. Firewall&lt;br /&gt;
&lt;br /&gt;
iv. IPS&lt;br /&gt;
&lt;br /&gt;
v. Antivirus (http and SMTP)&lt;br /&gt;
&lt;br /&gt;
vi. Antispam, Phishing, Malware control (http, SMTP, SMS)&lt;br /&gt;
&lt;br /&gt;
vii. URL filtering&lt;br /&gt;
&lt;br /&gt;
viii. Application control&lt;br /&gt;
&lt;br /&gt;
ix. File integrity Monitoring&lt;br /&gt;
&lt;br /&gt;
x. Remote device management (in a secure manner :)&lt;br /&gt;
&lt;br /&gt;
xi. Biometrics/TPM/SSO/802.1x support&lt;br /&gt;
&lt;br /&gt;
b. Lock down the environment. Do not allow end users to modify any system settings. (e.g. use group policies on windows environment, security blanket on Linux etc)&lt;br /&gt;
&lt;br /&gt;
c. Use point solutions start with port control, anti malware, AV, IPS, firewall . Monitor system resource utilization you may kill endpoints by multiple clients&lt;br /&gt;
&lt;br /&gt;
d. Get physical; super glue all USB ports, remove the CD Drives, break IR sensors, turn off the radios.&lt;br /&gt;
&lt;br /&gt;
e. For old unsupported platforms, deploy file integrity monitoring on critical areas (e.g. tripwire)&lt;br /&gt;
&lt;br /&gt;
f. Use a big brother monitoring tool like Raytheon Oakley’s SureView (check with legal first : )&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;2- Network Based:&lt;/em&gt;&lt;br /&gt;
&lt;br /&gt;
a. Use IPS on the network. IPS will alert you on suspicious traffic you that you can take action faster. If the network traffic is encrypted, IPS will not be very helpful. You may consider decrypting traffic but the solution is a topic for another post&lt;br /&gt;
&lt;br /&gt;
b. Use anomaly detection tools. I really like using these tools; they are my most favorite malware detection solutions. They can either sniff traffic over taps or get flow data. Good solutions are Q1 Labs, Mazu (now Riverbed Cascade).. But any netflow tool will help&lt;br /&gt;
&lt;br /&gt;
c. Segment your network with firewalls&lt;br /&gt;
&lt;br /&gt;
d. Do not allow all protocols (who needs IPX, NetBeui, AppleTalk, SNA anyway : )&lt;br /&gt;
&lt;br /&gt;
e. Use ACLs on network devices. Only allow known ports, lock down network for SRC/DST APP based access rules&lt;br /&gt;
&lt;br /&gt;
f. Monitor Airspace… Make sure that nothing flies out /comes in via wi-fi/Bluetooth et al. I can recommend several tools.&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;3- Hybrid&lt;/em&gt;&lt;br /&gt;
&lt;br /&gt;
a. Use Network access control (NAC). You can have all the security in the world until the cable guy plugs-in his laptop to the Ethernet port in the cafeteria.&lt;br /&gt;
&lt;br /&gt;
b. Use an agent-less scanning tool. Compare all hosts, applications vs your approved gold copies. Monitor all malware constantly from remote. My favorite is Promisec. But you can even use Microsoft SMS &lt;br /&gt;
&lt;br /&gt;
c. Never forget the phones, the smartphones, VOIP phones are the new hosts for the virulent outbreaks/pandemic&lt;br /&gt;
&lt;br /&gt;
If you have a specific question please let me know.&lt;br /&gt;
&lt;br /&gt;
Regards,&lt;br /&gt;
&lt;br /&gt;
- Yinal Ozkan&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-1070097458770488809?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ZSQpYNnszJ6HMAO3AjvrD8nwuWY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZSQpYNnszJ6HMAO3AjvrD8nwuWY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ZSQpYNnszJ6HMAO3AjvrD8nwuWY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZSQpYNnszJ6HMAO3AjvrD8nwuWY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=7i7CRtAp0mM:_2Uabv7kZak:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=7i7CRtAp0mM:_2Uabv7kZak:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=7i7CRtAp0mM:_2Uabv7kZak:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=7i7CRtAp0mM:_2Uabv7kZak:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=7i7CRtAp0mM:_2Uabv7kZak:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/7i7CRtAp0mM" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/7i7CRtAp0mM/best-way-to-stop-malware-from-spreading.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>1</thr:total><feedburner:origLink>http://security.24kasim.org/2009/11/best-way-to-stop-malware-from-spreading.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-3695670882006534939</guid><pubDate>Sat, 17 Oct 2009 00:11:00 +0000</pubDate><atom:updated>2009-10-16T20:13:06.596-04:00</atom:updated><title>The "Cyber" Word</title><description>I got the following e-mail from one of my peers.&lt;br /&gt;
==================&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;&lt;strong&gt;From:&lt;/strong&gt; Chris Camejo &lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;&lt;strong&gt;Sent:&lt;/strong&gt; Sunday, October 04, 2009 2:19 PM&lt;br /&gt;
&lt;strong&gt;To:&lt;/strong&gt; ---------------------&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;&lt;strong&gt;Subject:&lt;/strong&gt; Cyberwords&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;I&amp;nbsp;saw this “Cybersecurity” article on CNN and the ridiculous overuse of cyberwords is good for a chuckle:&lt;/span&gt;&lt;br /&gt;
&lt;a href="http://www.cnn.com/2009/POLITICS/10/02/dhs.cybersecurity.jobs/index.html"&gt;&lt;span style="font-size: x-small;"&gt;http://www.cnn.com/2009/POLITICS/10/02/dhs.cybersecurity.jobs/index.html&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;Apparently the government wants a “cyberczar” and more “cyberexperts” to work as “cyberanalysts” to protect “cybernetworks” from “cyberthreats” and engage in “cyberwarfare” so they can be a an effective “cyberorganization”. Yes, all of those words were really used in the article.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;It scares me that there are people making decisions in government who write stuff like that.&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;-Chris&lt;/span&gt; &lt;br /&gt;
=====================&lt;br /&gt;
I could not agree more.&lt;br /&gt;
&lt;br /&gt;
Every time I see an acronym or a government program that starts with “cyber” prefix I get irritated. I quickly associate the misapplication of the “cyber” prefix with ill-thought, wrong- footed, erroneous information security initiatives – cybersecurity, cyberczar, cybercop, cyberspace and the list goes on…Even my MS Word spell check doesn’t like them. This (using cyber prefix) simply takes the meaning of many serious topics that we are working on by diluting the significance, to the point of serious confusion to everyone except the small number of cyber experts : )&lt;br /&gt;
&lt;br /&gt;
It is also very interesting that only state and federal agencies use “cyber”&lt;br /&gt;
&lt;br /&gt;
The word cyber entered English language in 1991 as “of, relating to, or involving computers or computer networks” according to Merriam-Webster.&lt;br /&gt;
&lt;br /&gt;
The reason I cannot associate cyber is that etymologically it is wrong. Cyber prefix is derived from cybernetics. Cybernetics as a concept in society has been around at least since Plato used it to refer to government. Maybe that is why the government today likes to use it. In modern times, the term became widespread because Norbert Wiener wrote a book called "Cybernetics" in 1948. The study is described as the science of communication and control theory that is concerned especially with the comparative study of automatic control systems (as the nervous system and brain and mechanical-electrical communication systems) Cybernetics is an established interdisciplinary science not a sci-fi flick or an internet buzz word (http://en.wikipedia.org/wiki/Cybernetics) ) The word comes from Greek “kybernetes” pilot, governor (from kybernan to steer, govern) + English –ics.&lt;br /&gt;
&lt;br /&gt;
So what is the relationship between Internet and Cyber? I do not see a real one ..Maybe it is the cyborgs which is a combination of cybernetic + organism.&lt;br /&gt;
&lt;br /&gt;
-yinal&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-3695670882006534939?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/e-rGpfSMPJQyr3hHX-5EA8SQSwY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/e-rGpfSMPJQyr3hHX-5EA8SQSwY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/e-rGpfSMPJQyr3hHX-5EA8SQSwY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/e-rGpfSMPJQyr3hHX-5EA8SQSwY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=Oc8aNbYSOEw:qdfMTaWCyOs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=Oc8aNbYSOEw:qdfMTaWCyOs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=Oc8aNbYSOEw:qdfMTaWCyOs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=Oc8aNbYSOEw:qdfMTaWCyOs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=Oc8aNbYSOEw:qdfMTaWCyOs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/Oc8aNbYSOEw" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/Oc8aNbYSOEw/cyber-word.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2009/10/cyber-word.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-4396830283812654510</guid><pubDate>Tue, 15 Sep 2009 15:49:00 +0000</pubDate><atom:updated>2009-09-15T11:49:28.111-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">WAF</category><category domain="http://www.blogger.com/atom/ns#">Web Application Security</category><category domain="http://www.blogger.com/atom/ns#">XML</category><title>Web Application Security Tools</title><description>I have been checking tools for a while for web application security engagements. Here is my list for web application scanners, test tools, proxies, source code analyzers, web application firewalls, XML SOA gateways (I will crosscheck methodologies in another post)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Remote Web App Test Tools and test proxies&lt;br /&gt;
1- SPI Dynamics WebInspect &amp;nbsp;- Now HP Webinspect - &lt;a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200^9570_4000_100__"&gt;https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200^9570_4000_100__&lt;/a&gt;&lt;br /&gt;
2- Sanctum then Watchfire AppScan - Now IBM Rational AppScan - &amp;nbsp;&lt;a href="http://www-01.ibm.com/software/awdtools/appscan/"&gt;http://www-01.ibm.com/software/awdtools/appscan/&lt;/a&gt;&lt;br /&gt;
3- Kavado Scando - Now Protegrity - &lt;a href="http://www.protegrity.com/DefianceSecuritySuite"&gt;http://www.protegrity.com/DefianceSecuritySuite&lt;/a&gt;&lt;br /&gt;
4- AppSecInc AppDetective Pro - &lt;a href="http://www.appsecinc.com/products/appdetective/index.shtml"&gt;http://www.appsecinc.com/products/appdetective/index.shtml&lt;/a&gt;&lt;br /&gt;
5- Cenzic Hailstorm - &lt;a href="http://www.cenzic.com/products/software/overview/"&gt;http://www.cenzic.com/products/software/overview/&lt;/a&gt;&lt;br /&gt;
6- NT Objectives NTOSpider &lt;a href="http://www.ntobjectives.com/products/ntospider.php"&gt;http://www.ntobjectives.com/products/ntospider.php&lt;/a&gt;&lt;br /&gt;
7- Acunetix Web Vulnerability Scanner http://www.acunetix.com/vulnerability-scanner/&lt;br /&gt;
8- Burp Suite -proxy- &amp;nbsp;&lt;a href="http://www.portswigger.net/"&gt;http://www.portswigger.net/&lt;/a&gt;&lt;br /&gt;
9- Sandsprite Web Sleuth - &lt;a href="http://sandsprite.com/Sleuth/about.html"&gt;http://sandsprite.com/Sleuth/about.html&lt;/a&gt;&lt;br /&gt;
10- Positive Technologies MaxPatrol 7 - &lt;a href="http://www.ptsecurity.com/mp_eval.asp"&gt;http://www.ptsecurity.com/mp_eval.asp&lt;/a&gt;&lt;br /&gt;
11- NGS Typhon III - &lt;a href="http://www.ngssoftware.com/products/internet-security/ngs-typhon.php"&gt;http://www.ngssoftware.com/products/internet-security/ngs-typhon.php&lt;/a&gt;&lt;br /&gt;
12- Parasoft &lt;a href="http://www.parasoft.com/jsp/solutions/soa_solution.jsp?itemId=319#web_iface_penetration"&gt;http://www.parasoft.com/jsp/solutions/soa_solution.jsp?itemId=319#web_iface_penetration&lt;/a&gt;&lt;br /&gt;
13- Hyperscan -Art of Defense&amp;nbsp;- &lt;a href="http://www.artofdefence.com/en/hyperscan/hyperscan.html"&gt;http://www.artofdefence.com/en/hyperscan/hyperscan.html&lt;/a&gt;&lt;br /&gt;
14- HP Assessment Management Platform software - &lt;a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200^9580_4000_100__"&gt;https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200^9580_4000_100__&lt;/a&gt;&lt;br /&gt;
15- nCircle - &lt;a href="http://www.ncircle.com/index.php?s=products_webapp360"&gt;http://www.ncircle.com/index.php?s=products_webapp360&lt;/a&gt;&lt;br /&gt;
16- Qualys - Web Application Scanning - &lt;a href="http://www.qualys.com/solutions/web_application_scanning/"&gt;http://www.qualys.com/solutions/web_application_scanning/&lt;/a&gt;&lt;br /&gt;
17- Foundstone - Now McAfee Vulnerability Manager - &lt;a href="http://www.mcafee.com/us/enterprise/products/risk_and_vulnerablity_management/vulnerability_manager.html"&gt;http://www.mcafee.com/us/enterprise/products/risk_and_vulnerablity_management/vulnerability_manager.html&lt;/a&gt;&lt;br /&gt;
18- Nessus - Tenable Security - &lt;a href="http://www.tenablesecurity.com/nessus/"&gt;http://www.tenablesecurity.com/nessus/&lt;/a&gt;&lt;br /&gt;
19- Syhunt SandCat &lt;a href="http://www.syhunt.com/"&gt;http://www.syhunt.com/&lt;/a&gt;&lt;br /&gt;
20- Saint - No Web App Customization - &lt;a href="http://www.saintcorporation.com/products/vulnerability_scan/saint/saint_scanner.html"&gt;http://www.saintcorporation.com/products/vulnerability_scan/saint/saint_scanner.html&lt;/a&gt;&lt;br /&gt;
21- MileSCAN Web Security Auditor (WSA) - Paros Proxy - &lt;a href="http://www.milescan.com/hk/"&gt;http://www.milescan.com/hk/&lt;/a&gt; , &lt;a href="http://www.parosproxy.org/index.shtml"&gt;http://www.parosproxy.org/index.shtml&lt;/a&gt;&lt;br /&gt;
22- N-Stalker Web Application Security Scanner &lt;a href="http://www.nstalker.com/products"&gt;http://www.nstalker.com/products&lt;/a&gt;&lt;br /&gt;
23- Nikto - Open Source (GPL) web server scanner &amp;nbsp;&lt;a href="http://www.cirt.net/nikto2"&gt;http://www.cirt.net/nikto2&lt;/a&gt;&lt;br /&gt;
24- Canvas (formerly SpikeSecurity) - &lt;a href="http://www.immunitysec.com/products-canvas.shtml"&gt;http://www.immunitysec.com/products-canvas.shtml&lt;/a&gt;&lt;br /&gt;
25- WebScarab -proxy- &amp;nbsp;&lt;a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project"&gt;http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project&lt;/a&gt;&lt;br /&gt;
26- Odysseus - proxy- &lt;a href="http://www.bindshell.net/tools/odysseus"&gt;http://www.bindshell.net/tools/odysseus&lt;/a&gt;&lt;br /&gt;
27- CoreImpact - &lt;a href="http://www.coresecurity.com/content/core-impact-overview"&gt;http://www.coresecurity.com/content/core-impact-overview&lt;/a&gt;&lt;br /&gt;
28- Metasploit - &lt;a href="http://www.metasploit.com/"&gt;http://www.metasploit.com/&lt;/a&gt;&lt;br /&gt;
29- Wikto - &lt;a href="http://www.sensepost.com/research/wikto/"&gt;http://www.sensepost.com/research/wikto/&lt;/a&gt;&lt;br /&gt;
30- Proventia Scanner (formerly ISS) -&lt;a href="http://www-935.ibm.com/services/us/index.wss/offering/iss/a1027216"&gt;http://www-935.ibm.com/services/us&lt;/a&gt; , &lt;a href="http://www-935.ibm.com/services/us/index.wss/offering/iss/a1027208"&gt;http://www-935.ibm.com/services2&lt;/a&gt;&lt;br /&gt;
31- e-Eye Retina Web Scanner &lt;a href="http://www.eeye.com/html/products/RetinaWebScanner/index.html"&gt;http://www.eeye.com/html/products/RetinaWebScanner/index.html&lt;/a&gt;&lt;br /&gt;
32- SQL Power Injector &lt;a href="http://www.sqlpowerinjector.com/"&gt;http://www.sqlpowerinjector.com/&lt;/a&gt;&lt;br /&gt;
33- Sensepost BiDiBLAH - Security Assessment Power Tools (not sure for Web App features) &amp;nbsp; &lt;a href="http://www.sensepost.com/research/bidiblah/"&gt;http://www.sensepost.com/research/bidiblah/&lt;/a&gt;&lt;br /&gt;
34- The Security Auditor's Research Assistant (SARA) - &lt;a href="http://www-arc.com/sara/"&gt;http://www-arc.com/sara/&lt;/a&gt;&lt;br /&gt;
35- Founstone Tools - &lt;a href="http://www.foundstone.com/us/resources/freetools.asp"&gt;http://www.foundstone.com/us/resources/freetools.asp&lt;/a&gt;&lt;br /&gt;
36- Wapiti Web application vulnerability scanner / security auditor - &lt;a href="http://wapiti.sourceforge.net/"&gt;http://wapiti.sourceforge.net/&lt;/a&gt;&lt;br /&gt;
37- Curl - httptools, not a scanner - &lt;a href="http://curl.haxx.se/"&gt;http://curl.haxx.se/&lt;/a&gt;&lt;br /&gt;
38- Stanford SecuriBench - &lt;a href="http://suif.stanford.edu/~livshits/securibench/"&gt;http://suif.stanford.edu/~livshits/securibench/&lt;/a&gt;&lt;br /&gt;
39- Fiddler Proxy - &lt;a href="http://www.fiddler2.com/fiddler2/"&gt;http://www.fiddler2.com/fiddler2/&lt;/a&gt;&lt;br /&gt;
40- Pantera - another spikeproxy- &lt;a href="http://www.owasp.org/index.php/Category:OWASP_Pantera_Web_Assessment_Studio_Project"&gt;http://www.owasp.org/index.php/Pantera&lt;/a&gt;&lt;br /&gt;
41- Suru - proxy from sensepost - &lt;a href="http://www.sensepost.com/research/suru/"&gt;http://www.sensepost.com/research/suru/&lt;/a&gt;&lt;br /&gt;
42- Charles Proxy - &lt;a href="http://www.charlesproxy.com/"&gt;http://www.charlesproxy.com/&lt;/a&gt;&lt;br /&gt;
43- Burp, Paros, and WebScarab for Mac OS X - &lt;a href="http://www.corsaire.com/downloads/"&gt;http://www.corsaire.com/downloads/&lt;/a&gt;&lt;br /&gt;
44- RatPrxoy from Google &lt;a href="http://code.google.com/p/ratproxy/"&gt;http://code.google.com/p/ratproxy/&lt;/a&gt;&lt;br /&gt;
45- JS Proxy - for javascript - &lt;a href="http://jscmd.rubyforge.org/"&gt;http://jscmd.rubyforge.org/&lt;/a&gt;&lt;br /&gt;
46- OWASP Phoenix Chapter - Another List of Tools : &lt;a href="http://www.owasp.org/index.php/Phoenix/Tools"&gt;http://www.owasp.org/index.php/Phoenix/Tools&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Source Code Analysis&lt;br /&gt;
1.Coverity Integrity Server / Prevent -&lt;a href="http://www.coverity.com/products/coverity-prevent.html"&gt;http://www.coverity.com/products/coverity-prevent.html&lt;/a&gt;&lt;br /&gt;
2.Escher Technologies Eschertech &amp;nbsp;- &lt;a href="http://eschertech.com/"&gt;http://eschertech.com/&lt;/a&gt;&lt;br /&gt;
3.Fortify Software Suite (analysis, workbench, metrics &amp;amp; trending console, customization module) &lt;a href="http://www.fortify.com/products/fortify-360/vulnerability-detection.jsp"&gt;http://www.fortify.com/products/fortify-360/vulnerability-detection.jsp&lt;/a&gt;&lt;br /&gt;
4.Gimple PC and Flexe-Lint C/C++ &amp;nbsp;-&lt;a href="http://www.gimpel.com/html/products.htm"&gt;http://www.gimpel.com/html/products.htm&lt;/a&gt;&lt;br /&gt;
5.Grammatech CodeSurfer C/C++ - &lt;a href="http://www.grammatech.com/products/codesurfer/overview.html"&gt;http://www.grammatech.com/products/codesurfer/overview.html&lt;/a&gt;&lt;br /&gt;
6.Ounce Labs - Now IBM - http://www.ouncelabs.com/application_security/&lt;br /&gt;
7.Parasoft JTest &amp;nbsp;Parasoft Application Security- Java Static Code Analysis - &lt;a href="http://www.parasoft.com/jsp/products/home.jsp?product=Jtest"&gt;http://www.parasoft.com/jsp/products/home.jsp?product=Jtest&lt;/a&gt;&lt;br /&gt;
8.Secure Software CodeAssure Workbench C/C++, Java (Now Fortify)&lt;br /&gt;
9.Veracode - &lt;a href="http://www.veracode.com/solutions"&gt;http://www.veracode.com/solutions&lt;/a&gt;&lt;br /&gt;
10.Armorize Codesecure - &lt;a href="http://www.armorize.com/?link_id=codesecure"&gt;http://www.armorize.com/?link_id=codesecure&lt;/a&gt;&lt;br /&gt;
11.Klocwork Insight/Solo &lt;a href="http://www.klocwork.com/products/product-comparison-matrix/"&gt;http://www.klocwork.com/products/product-comparison-matrix/&lt;/a&gt;&lt;br /&gt;
12.Hypersource - Art of Defense - &lt;a href="http://www.artofdefence.com/en/hypersource/hypersource.html"&gt;http://www.artofdefence.com/en/hypersource/hypersource.html&lt;/a&gt;&lt;br /&gt;
13. PHP Pixy - &lt;a href="http://pixybox.seclab.tuwien.ac.at/pixy/"&gt;http://pixybox.seclab.tuwien.ac.at/pixy/&lt;/a&gt;&lt;br /&gt;
14. BFBTester: Brute Force Binary Tester - &lt;a href="http://bfbtester.sourceforge.net/"&gt;http://bfbtester.sourceforge.net/&lt;/a&gt;&lt;br /&gt;
15. CROSS (Codenomicon Robust Open Source Software) &amp;nbsp;-&lt;a href="http://www.codenomicon.com/solutions/cross.shtml"&gt;http://www.codenomicon.com/solutions/cross.shtml&lt;/a&gt;&lt;br /&gt;
16. Flawfinder - C/C++ source code - &lt;a href="http://www.dwheeler.com/flawfinder/"&gt;http://www.dwheeler.com/flawfinder/&lt;/a&gt;&lt;br /&gt;
17. Gendarme -.NET applications and libraries - &lt;a href="http://www.mono-project.com/Gendarme"&gt;http://www.mono-project.com/Gendarme&lt;/a&gt;&lt;br /&gt;
18. Stanford SecuriBench -open source - &lt;a href="http://suif.stanford.edu/~livshits/securibench/"&gt;http://suif.stanford.edu/~livshits/securibench/&lt;/a&gt;&lt;br /&gt;
19. OWASP Phoenix Chapter - Another List of Tools : &lt;a href="http://www.owasp.org/index.php/Phoenix/Tools"&gt;http://www.owasp.org/index.php/Phoenix/Tools&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Web Application Firewalls:&lt;br /&gt;
I am excluding network firewalls with deep inspection features such as Cisco, Juniper, Check Point, Fortinet&lt;br /&gt;
&lt;br /&gt;
F5- ASM -Application Security Manager - &lt;a href="http://www.f5.com/products/big-ip/product-modules/application-security-manager.html"&gt;http://www.f5.com/products/big-ip/product-modules/application-security-manager.html&lt;/a&gt;&lt;br /&gt;
Breach Security - &lt;a href="http://www.breach.com/products/"&gt;http://www.breach.com/products/&lt;/a&gt;&lt;br /&gt;
Imperva - SecureSphere -&lt;a href="http://www.imperva.com/solutions/web-application-security.html"&gt;http://www.imperva.com/solutions/web-application-security.html&lt;/a&gt;&lt;br /&gt;
Cisco ACE Web Application Firewall &lt;a href="http://www.cisco.com/en/US/products/ps9586/index.html"&gt;http://www.cisco.com/en/US/products/ps9586/index.html&lt;/a&gt;&lt;br /&gt;
White Hat Sentinel (add-on for F5, Imperva, Breach) - &lt;a href="http://www.whitehatsec.com/home/services/waf.html"&gt;http://www.whitehatsec.com/home/services/waf.html&lt;/a&gt;&lt;br /&gt;
Citrix NetScaler &lt;a href="http://www.citrix.com/English/ps2/products/product.asp?contentID=25636"&gt;http://www.citrix.com/English/ps2/products/product.asp?contentID=25636&lt;/a&gt;&lt;br /&gt;
Protegrity WAF - &lt;a href="http://www.protegrity.com/WebApplicationFirewall"&gt;http://www.protegrity.com/WebApplicationFirewall&lt;/a&gt;&lt;br /&gt;
Fortify Real Time Analyzer RTA - &lt;a href="http://www.fortify.com/products/detect/"&gt;http://www.fortify.com/products/detect/&lt;/a&gt;&lt;br /&gt;
AQtronix for IIS &amp;nbsp;- &lt;a href="http://www.aqtronix.com/?PageID=99"&gt;http://www.aqtronix.com/?PageID=99&lt;/a&gt;&lt;br /&gt;
DenyAll rWeb - &lt;a href="http://www.denyall.com/products/rweb_en.html"&gt;http://www.denyall.com/products/rweb_en.html&lt;/a&gt;&lt;br /&gt;
Applicure DotDefender - &lt;a href="http://www.applicure.com/About_dotDefender"&gt;http://www.applicure.com/About_dotDefender&lt;/a&gt;&lt;br /&gt;
Armorlogic Profense - &lt;a href="http://www.armorlogic.com/"&gt;http://www.armorlogic.com/&lt;/a&gt;&lt;br /&gt;
Bee Ware i-Sentry &lt;a href="http://www.bee-ware.net/en/product/i-sentry/"&gt;http://www.bee-ware.net/en/product/i-sentry/&lt;/a&gt;&lt;br /&gt;
BinarySec (French) &lt;a href="http://www.binarysec.com/cms/docs/products/products.html"&gt;http://www.binarysec.com/cms/docs/products/products.html&lt;/a&gt;&lt;br /&gt;
BugSec WebSniper &lt;a href="http://www.bugsec.com/index.php?q=WebSniper"&gt;http://www.bugsec.com/index.php?q=WebSniper&lt;/a&gt;&lt;br /&gt;
e-Eye SecureIIS &lt;a href="http://www.eeye.com/html/products/secureiis/index.html"&gt;http://www.eeye.com/html/products/secureiis/index.html&lt;/a&gt;&lt;br /&gt;
webscurity web.AppSecure &lt;a href="http://www.webscurity.com/products.htm"&gt;http://www.webscurity.com/products.htm&lt;/a&gt;&lt;br /&gt;
Phion Airlock &lt;a href="http://www.phion.com/INT/products/websecurity/Pages/default.aspx"&gt;http://www.phion.com/INT/products/websecurity/Pages/default.aspx&lt;/a&gt;&lt;br /&gt;
Radware AppWall &lt;a href="http://www.radware.com/Products/ApplicationDelivery/AppWall/default.aspx"&gt;http://www.radware.com/Products/ApplicationDelivery/AppWall/default.aspx&lt;/a&gt;&lt;br /&gt;
Hyperguard - Art of Defense : &lt;a href="http://www.artofdefence.com/en/hyperguard/hyperguard.html"&gt;http://www.artofdefence.com/en/hyperguard/hyperguard.html&lt;/a&gt;&lt;br /&gt;
Barracuda Web Application Firewall - &lt;a href="http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php"&gt;http://www.barracudanetworks.com/ns/products/web-site-firewall-overview.php&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
XML Firewalls&lt;br /&gt;
Radware AppXML &lt;a href="http://www.radware.com/Products/ApplicationDelivery/AppXML/default.aspx"&gt;http://www.radware.com/Products/ApplicationDelivery/AppXML/default.aspx&lt;/a&gt;&lt;br /&gt;
DataPower (now owned by IBM) - WebSphere DataPower SOA Appliances -&lt;a href="http://www-01.ibm.com/software/integration/datapower/"&gt;http://www-01.ibm.com/software/integration/datapower/&lt;/a&gt;&lt;br /&gt;
Reactivity, Inc. (acquired by CISCO), The Cisco ACE XML Gateway - &lt;a href="http://www.cisco.com/en/US/products/ps7314/index.html"&gt;http://www.cisco.com/en/US/products/ps7314/index.html&lt;/a&gt;&lt;br /&gt;
Forum Sentry XML Gateway &amp;nbsp;- &lt;a href="http://www.forumsys.com/products/index.php"&gt;http://www.forumsys.com/products/index.php&lt;/a&gt;&lt;br /&gt;
Layer 7 Technologies' SecureSpan XML Firewall - &lt;a href="http://www.layer7tech.com/main/solutions/firewalling.html"&gt;http://www.layer7tech.com/main/solutions/firewalling.html&lt;/a&gt;&lt;br /&gt;
Vordel XML Gateway - &lt;a href="http://www.vordel.com/products/vx_gateway/"&gt;http://www.vordel.com/products/vx_gateway/&lt;/a&gt;&lt;br /&gt;
Dajeil - &lt;a href="http://www.dajeil.com/Products.asp"&gt;http://www.dajeil.com/Products.asp&lt;/a&gt;&lt;br /&gt;
Sarvega (now owned by Intel) Intel SOA Expressway - &lt;a href="http://www.intel.com/cd/software/products/asmo-na/eng/373233.htm"&gt;http://www.intel.com/cd/software/products/asmo-na/eng/373233.htm&lt;/a&gt;&lt;br /&gt;
Bloombase Spitfire Security Server - &lt;a href="http://www.bloombase.com/products/spitfire/index.html"&gt;http://www.bloombase.com/products/spitfire/index.html&lt;/a&gt;&lt;br /&gt;
Sonoa &lt;a href="http://www.sonoasystems.com/product-matrix#anc-security"&gt;http://www.sonoasystems.com/product-matrix#anc-security&lt;/a&gt;&lt;br /&gt;
inferno - opensource - &lt;a href="http://ixmlfirewall.sourceforge.net/"&gt;http://ixmlfirewall.sourceforge.net/&lt;/a&gt;&lt;br /&gt;
DAXFi - Dynamic XML Firewal - Opensource - &lt;a href="http://sourceforge.net/projects/daxfi/"&gt;http://sourceforge.net/projects/daxfi/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
open for feedback,&lt;br /&gt;
- yinal ozkan&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-4396830283812654510?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/LSVyCu5Ew-YgxdJNp7Q-zB9FjzM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LSVyCu5Ew-YgxdJNp7Q-zB9FjzM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/LSVyCu5Ew-YgxdJNp7Q-zB9FjzM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LSVyCu5Ew-YgxdJNp7Q-zB9FjzM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=6N665lyVQPg:vV4ER47WgNQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=6N665lyVQPg:vV4ER47WgNQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=6N665lyVQPg:vV4ER47WgNQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=6N665lyVQPg:vV4ER47WgNQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=6N665lyVQPg:vV4ER47WgNQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/6N665lyVQPg" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/6N665lyVQPg/web-application-security-tools.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>3</thr:total><feedburner:origLink>http://security.24kasim.org/2009/09/web-application-security-tools.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-2288361208879073854</guid><pubDate>Sun, 13 Sep 2009 02:28:00 +0000</pubDate><atom:updated>2009-09-12T22:32:43.290-04:00</atom:updated><title>RSA Conference Notes (US 2009)</title><description>&lt;span style="font-family: Arial; font-size: small;"&gt;&lt;span style="font-size: 13px;"&gt;&lt;span style="font-family: arial; font-weight: bold;"&gt;Better late than never...&lt;/span&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
During the RSA conference (April 2009) organizers had flip cameras for us (where they announced over twitter)&lt;br /&gt;
Instead of &amp;nbsp;typing/blogging my notes, I experienced the "vlogging" which was easy. Here are RSA edited notes from RSA Conference web site:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://365.rsaconference.com/community/connect/rsa-conference-usa-2009/blog/2009/04/23/yinal-ozkan-on-day-2-keynotes-class-tracks-and-peer-to-peer-sessions-part-one"&gt;Part I&lt;/a&gt;&lt;br /&gt;
&lt;a href="https://365.rsaconference.com/community/connect/rsa-conference-usa-2009/blog/2009/04/23/yinal-ozkan-on-day-2-keynotes-class-tracks-and-peer-to-peer-sessions-part-two"&gt;Part II&lt;/a&gt;&lt;br /&gt;
&lt;a href="https://365.rsaconference.com/community/connect/rsa-conference-usa-2009/blog/2009/04/28/yinal-ozkan-on-the-second-to-last-day-of-the-conference" style="text-decoration: none;"&gt;&lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;Part III&lt;/a&gt;&lt;br /&gt;
&lt;span id="fullpost"&gt;&lt;br /&gt;
Sometimes it is positive to see and hear the author, sometimes it is not. But as far as I see we should better not hide behind anonymous posts. I think that we can communicate better with the new gadgets offered us literally at no cost.&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
cheers,&lt;br /&gt;
- yinal&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-2288361208879073854?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/RK6bvopm4_aRmJy6_LoYrGJTzk0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/RK6bvopm4_aRmJy6_LoYrGJTzk0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/RK6bvopm4_aRmJy6_LoYrGJTzk0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/RK6bvopm4_aRmJy6_LoYrGJTzk0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=5vqiJdaOboQ:Vw5gRfJMC80:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=5vqiJdaOboQ:Vw5gRfJMC80:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=5vqiJdaOboQ:Vw5gRfJMC80:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=5vqiJdaOboQ:Vw5gRfJMC80:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=5vqiJdaOboQ:Vw5gRfJMC80:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/5vqiJdaOboQ" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/5vqiJdaOboQ/rsa-conference-notes-us-2009.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2009/09/rsa-conference-notes-us-2009.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-2319749815699427345</guid><pubDate>Sun, 16 Aug 2009 19:26:00 +0000</pubDate><atom:updated>2011-10-31T22:56:21.514-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">compliance</category><category domain="http://www.blogger.com/atom/ns#">GRC</category><title>IT Governance, Risk and Compliance (ITGRC) Tools August 2009</title><description>For 2011 list follow this &lt;a href="http://security.24kasim.org/2011/10/itgrc-software-vendors-2011.html" target="_blank"&gt;link&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Here are the updated links for the IT-GRC vendors, IT-GRC wanna be GRC vendors, and some IT based risk management tool/software providers.&lt;br /&gt;
&lt;br /&gt;
There is still a thin line between IT, Financial and ERP GRC solution providers.&lt;br /&gt;
&lt;br /&gt;
I have noticed that SAP has created its own GRC context where GRC means a lot of other things... SoD- Segregation of Duties, entitlements management, users access/authorization for applications/transactions, audit managment, role management etc.Basically a dull extention of IT audit controls. SAP's Virsa  and SUN's Vaau acqusitions are good examples of this trend. That is not GRC -- that is mediocre IT controls audit. The term GRC is used without any consideration. This statement is also valid for the other usual suspects l(Oracle, PeopleSoft, Hyperion, JD Edwards,)&lt;br /&gt;
&lt;br /&gt;
Here is a quick M&amp;amp;A update from last post:&lt;br /&gt;
Brabeion is acquired by Archer (Big News)&lt;br /&gt;
Controlpath is acquired by Trustwave.&lt;br /&gt;
Paisley is acquired by ThomsonReuters&lt;br /&gt;
Iconium is acquired by Logicalis&lt;br /&gt;
IBM dropped their own suite and working with Modulo&lt;br /&gt;
Favored GRC has a new name Highpoint GRC&lt;br /&gt;
Achiever is gone&lt;br /&gt;
I looked at ACL, Approva,Aveksa,Opentext,SecurityWeaver, Xpandion, Spatiq solutions,, I will be checking these vendors in the future, these solutins tend to manage ERP security only)..&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
IT-GRC solution Providers:&lt;br /&gt;
&lt;br /&gt;
Agiliance&lt;br /&gt;
&lt;a href="http://www.agiliance.com/"&gt;http://www.agiliance.com/&lt;/a&gt;&lt;br /&gt;
Archer  ( acquired Brabeion)&lt;br /&gt;
&lt;a href="http://www.archer-tech.com/solutions/index.html"&gt;http://www.archer-tech.com/solutions/index.html&lt;/a&gt;&lt;br /&gt;
Trustwave GRC&lt;br /&gt;
&lt;a href="https://www.trustwave.com/GRC.php"&gt;https://www.trustwave.com/GRC.php&lt;/a&gt;&lt;br /&gt;
Symantec (Control Compliance Suite)&lt;br /&gt;
&lt;a href="http://eval.symantec.com/mktginfo/enterprise/fact_sheets/b-datasheet_control_compliance_suite_9.0-11_2008_14121573.en-us.pdf"&gt;http://eval.symantec.com/mktginfo/enterprise/fact_sheets/b-datasheet_control_compliance_suite_9.0-11_2008_14121573.en-us.pdf&lt;/a&gt;&lt;br /&gt;
Compliance Spectrum&lt;br /&gt;
&lt;a href="http://www.compliancespectrum.com/"&gt;http://www.compliancespectrum.com/&lt;/a&gt;&lt;br /&gt;
Modulo&lt;br /&gt;
&lt;a href="http://www.modulo.com/home.jsp"&gt;http://www.modulo.com/home.jsp&lt;/a&gt;&lt;br /&gt;
NeIQ&lt;br /&gt;
&lt;a href="http://www.netiq.com/solutions/scm/default.asp"&gt;http://www.netiq.com/solutions/scm/default.asp&lt;/a&gt;&lt;br /&gt;
eIQ Networks SecureVue&lt;br /&gt;
&lt;a href="http://www.eiqnetworks.com/products/SecureVue/SecureVue_Technology.shtml"&gt;http://www.eiqnetworks.com/products/SecureVue/SecureVue_Technology.shtml&lt;/a&gt;&lt;br /&gt;
CA GRC&lt;br /&gt;
&lt;a href="http://www.ca-grc.com/"&gt;http://www.ca-grc.com/&lt;/a&gt;&lt;br /&gt;
Relational Security - RSAM&lt;br /&gt;
&lt;a href="http://www.relsec.com/rsam_overview.htm"&gt;http://www.relsec.com/rsam_overview.htm&lt;/a&gt;&lt;br /&gt;
Logicalis grace (acquired Iconium Assets)&lt;br /&gt;
&lt;a href="http://www.uk.logicalis.com/business_issues/governance_grace.asp"&gt;http://www.uk.logicalis.com/business_issues/governance_grace.asp&lt;/a&gt;&lt;br /&gt;
Lumension (acquired Security-Works)&lt;br /&gt;
&lt;a href="http://www.lumension.com/landing.spring?contentId=154643"&gt;http://www.lumension.com/landing.spring?contentId=154643&lt;/a&gt;&lt;br /&gt;
Oracle (formerly Logical Apps and Oracle GRC Manager)&lt;br /&gt;
&lt;a href="http://www.oracle.com/solutions/corporate_governance/it-grc-management.html"&gt;http://www.oracle.com/solutions/corporate_governance/it-grc-management.html&lt;/a&gt;&lt;br /&gt;
Proteus&lt;br /&gt;
&lt;a href="http://www.infogov.co.uk/proteus_enterprise/index.php"&gt;http://www.infogov.co.uk/proteus_enterprise/index.php&lt;/a&gt;&lt;br /&gt;
BPS&lt;br /&gt;
&lt;a href="http://www.bpsinc.com/"&gt;http://www.bpsinc.com/&lt;/a&gt;&lt;br /&gt;
Avedos&lt;br /&gt;
&lt;a href="http://www.avedos.com/257-Home-EN.html"&gt;http://www.avedos.com/257-Home-EN.html&lt;/a&gt;&lt;br /&gt;
BWise&lt;br /&gt;
&lt;a href="http://www.bwise.com/"&gt;http://www.bwise.com/&lt;/a&gt;&lt;br /&gt;
Neupart&lt;br /&gt;
&lt;a href="http://www.neupart.com/"&gt;http://www.neupart.com/&lt;/a&gt;&lt;br /&gt;
Metric Stream&lt;br /&gt;
&lt;a href="http://www.metricstream.com/"&gt;http://www.metricstream.com/&lt;/a&gt;&lt;br /&gt;
Nemea&lt;br /&gt;
&lt;a href="http://www.nemea.us/"&gt;http://www.nemea.us/&lt;/a&gt;&lt;br /&gt;
Highpoint&lt;br /&gt;
&lt;a href="http://www.highpointgrc.com/"&gt;http://www.highpointgrc.com/&lt;/a&gt;&lt;br /&gt;
Paisley (now Thomson Reuters)&lt;br /&gt;
&lt;a href="http://www.paisley.com/"&gt;http://www.paisley.com/&lt;/a&gt;&lt;br /&gt;
OpenPages&lt;br /&gt;
&lt;a href="http://www.openpages.com/Solutions/Technology_17.asp"&gt;http://www.openpages.com/Solutions/Technology_17.asp&lt;/a&gt;&lt;br /&gt;
Qumas&lt;br /&gt;
&lt;a href="http://www.qumas.com/products/index.asp"&gt;http://www.qumas.com/products/index.asp&lt;/a&gt;&lt;br /&gt;
IDS Scheer&lt;br /&gt;
&lt;a href="http://www.ids-scheer.com/us/en/ARIS/ARIS_Solutions/Governance_Risk__Compliance_Management/139893.html"&gt;http://www.ids-scheer.com/us/en/ARIS/ARIS_Solutions/Governance_Risk__Compliance_Management/139893.html&lt;/a&gt; Axentis&lt;br /&gt;
&lt;a href="http://www.axentis.com/offerings/solutions/itgovernance"&gt;http://www.axentis.com/offerings/solutions/itgovernance&lt;/a&gt;&lt;br /&gt;
Methodware&lt;br /&gt;
&lt;a href="http://www.methodware.com/it-security/"&gt;http://www.methodware.com/it-security/&lt;/a&gt;&lt;br /&gt;
Protiviti&lt;br /&gt;
&lt;a href="http://www.protiviti.com/grc-software/Pages/default.aspx"&gt;http://www.protiviti.com/grc-software/Pages/default.aspx&lt;/a&gt;&lt;br /&gt;
Cura Software&lt;br /&gt;
&lt;a href="http://www.curasoftware.com/pages/content.asp?SectionId=7&amp;amp;SubSectionID=48"&gt;http://www.curasoftware.com/pages/content.asp?SectionId=7&amp;amp;SubSectionID=48&lt;/a&gt;&lt;br /&gt;
Mega&lt;br /&gt;
&lt;a href="http://www.mega.com/index.asp/l/en/c/grc"&gt;http://www.mega.com/index.asp/l/en/c/grc&lt;/a&gt;&lt;br /&gt;
ControlCase&lt;br /&gt;
&lt;a href="http://controlcase.com/it-grc.htm"&gt;http://controlcase.com/it-grc.htm&lt;/a&gt;&lt;br /&gt;
McAfee Risk and Compliance Manager (formerly McAfee Preventsys),&lt;br /&gt;
&lt;a href="http://www.mcafee.com/us/local_content/white_papers/dashboard_reporting_it_grc.pdf"&gt;http://www.mcafee.com/us/local_content/white_papers/dashboard_reporting_it_grc.pdf&lt;/a&gt;&lt;br /&gt;
Greenlightcorp (SAP GRC)&lt;br /&gt;
&lt;a href="http://www.greenlightcorp.net/sap_grc_cross_platform.html"&gt;http://www.greenlightcorp.net/sap_grc_cross_platform.html&lt;/a&gt;&lt;br /&gt;
Trintech -Financial GRC only&lt;br /&gt;
&lt;a href="http://www.trintech.com/"&gt;http://www.trintech.com/&lt;/a&gt;&lt;br /&gt;
SAI global&lt;br /&gt;
&lt;a href="http://www.saiglobal.com/compliance/grc-software/"&gt;http://www.saiglobal.com/compliance/grc-software/&lt;/a&gt;&lt;br /&gt;
SAP&lt;br /&gt;
&lt;a href="http://www.sap.com/solutions/sapbusinessobjects/large/governance-risk-compliance/index.epx"&gt;http://www.sap.com/solutions/sapbusinessobjects/large/governance-risk-compliance/index.epx&lt;/a&gt;&lt;br /&gt;
eFortresses&lt;br /&gt;
&lt;a href="http://www.efortresses.com/Compliantz.htm"&gt;http://www.efortresses.com/Compliantz.htm&lt;/a&gt;&lt;br /&gt;
Simeio Solutions GRCAXS (IT GRC module)&lt;br /&gt;
&lt;a href="http://www.simeiosolutions.com/"&gt;http://www.simeiosolutions.com/&lt;/a&gt;&lt;br /&gt;
Compliance 360 ( eGRC )&lt;br /&gt;
&lt;a href="http://www.compliance360.com/news.asp"&gt;http://www.compliance360.com/news.asp&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
There are also dedicated Risk Management Tools which will soon identify themselves (maybe they already do) for IT GRC marketspace&lt;br /&gt;
Callio&lt;br /&gt;
&lt;a href="http://www.callio.com/"&gt;http://www.callio.com/&lt;/a&gt;&lt;br /&gt;
Casis&lt;br /&gt;
&lt;a href="http://www.clearpriority.com/"&gt;http://www.clearpriority.com/&lt;/a&gt; (clearpriority)&lt;br /&gt;
Strategic Thought Active Risk Manager&lt;br /&gt;
&lt;a href="http://www.strategicthought.com/riskmanagement.html"&gt;http://www.strategicthought.com/riskmanagement.html&lt;/a&gt;&lt;br /&gt;
Cobra&lt;br /&gt;
&lt;a href="http://www.riskworld.net/"&gt;http://www.riskworld.net/&lt;/a&gt;&lt;br /&gt;
Citicus&lt;br /&gt;
&lt;a href="http://www.citicus.com/oursoftware.asp"&gt;http://www.citicus.com/oursoftware.asp&lt;/a&gt;&lt;br /&gt;
Alion – Countermeasures (makers of Buddy System)&lt;br /&gt;
&lt;a href="http://www.countermeasures.com/"&gt;http://www.countermeasures.com/&lt;/a&gt;&lt;br /&gt;
Siemens – CRAMM&lt;br /&gt;
&lt;a href="http://www.cramm.com/"&gt;http://www.cramm.com/&lt;/a&gt;&lt;br /&gt;
Acuity Stream&lt;br /&gt;
&lt;a href="http://www.acuityrm.com/"&gt;http://www.acuityrm.com/&lt;/a&gt;&lt;br /&gt;
EAR/Pilar&lt;br /&gt;
&lt;a href="http://www.ar-tools.com/en/index.html"&gt;http://www.ar-tools.com/en/index.html&lt;/a&gt;&lt;br /&gt;
GStool (mainly German)&lt;br /&gt;
&lt;a href="https://www.bsi.bund.de/cln_136/EN/topics/ITGrundschutz/ITGrundschutzGSTOOL/itgrundschutzgstool_node.html"&gt;https://www.bsi.bund.de/cln_136/EN/topics/ITGrundschutz/ITGrundschutzGSTOOL/itgrundschutzgstool_node.html&lt;/a&gt; Sigea GxSGSI (this site is in Spanish only)&lt;br /&gt;
&lt;a href="http://www.gxsgsi.es/"&gt;http://www.gxsgsi.es/&lt;/a&gt;&lt;br /&gt;
RA2&lt;br /&gt;
&lt;a href="http://www.aexis.de/index.php?site=static&amp;amp;staticID=4"&gt;http://www.aexis.de/index.php?site=static&amp;amp;staticID=4&lt;/a&gt;&lt;br /&gt;
RiskPAC&lt;br /&gt;
&lt;a href="http://www.cpacsweb.com/riskpac.html"&gt;http://www.cpacsweb.com/riskpac.html&lt;/a&gt;&lt;br /&gt;
Risicare (French)&lt;br /&gt;
&lt;a href="http://www.risicare.fr/"&gt;http://www.risicare.fr/&lt;/a&gt;&lt;br /&gt;
Riskwatch&lt;br /&gt;
&lt;a href="http://www.riskwatch.com/"&gt;http://www.riskwatch.com/&lt;/a&gt;&lt;br /&gt;
ISmart&lt;br /&gt;
&lt;a href="http://www.biznet.com.tr/english/ismart_info.htm"&gt;http://www.biznet.com.tr/english/ismart_info.htm&lt;/a&gt;&lt;br /&gt;
Resolver&lt;br /&gt;
&lt;a href="http://www.resolver.ca/"&gt;http://www.resolver.ca/&lt;/a&gt;&lt;br /&gt;
RMStudio&lt;br /&gt;
&lt;a href="http://www.riskmanagementstudio.com/"&gt;http://www.riskmanagementstudio.com/&lt;/a&gt;&lt;br /&gt;
RiskConnect&lt;br /&gt;
&lt;a href="http://www.riskonnect.com/riskonnect_products.html"&gt;http://www.riskonnect.com/riskonnect_products.html&lt;/a&gt;&lt;br /&gt;
PTA Risk Assessment Tools and Technology&lt;br /&gt;
&lt;a href="http://www.ptatechnologies.com/"&gt;http://www.ptatechnologies.com/&lt;/a&gt;&lt;br /&gt;
Avedos Risk2Value&lt;br /&gt;
&lt;a href="http://www.avedos.com/111-Short-Facts.html"&gt;http://www.avedos.com/111-Short-Facts.html&lt;/a&gt;&lt;br /&gt;
Non-IT Risk Software&lt;br /&gt;
&lt;a href="http://www.riskworld.com/SOFTWARE/sw5sw001.htm"&gt;http://www.riskworld.com/SOFTWARE/sw5sw001.htm&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
I still need time to add URL links for the well known risk assessment methodologies. A little bit googling will take you to the right resources if you want to build your won system using a methodology or a framework.&lt;br /&gt;
Methodologies for Risk Assessment and Management listed below can be used at IT operations... Endless discussion for quantifying the risks... I like ISO 27000 series to lead, but each case is different.&lt;br /&gt;
&lt;br /&gt;
ISO 14971 – Risk Management for Medical Technologies&lt;br /&gt;
NIST 800-30 Risk Management Guide for IT Systems - National Institute of Standards and Technology&lt;br /&gt;
OCTAVE (Carnegie Mellon)&lt;br /&gt;
The Institute of Risk management (IRM) The Risk Management Standard&lt;br /&gt;
ISO 13335-2 Information Security Risk Management, To be replaced by ISO/IEC IS 27005&lt;br /&gt;
BS 7799-3:2006 Information security management systems. Guidelines for information security risk management&lt;br /&gt;
BSI Grundschutz Handbuch&lt;br /&gt;
ENISA Regulation (2004)&lt;br /&gt;
PARA - Practical application of risk analysis&lt;br /&gt;
PTA - Practical Threat Analysis for Securing Computerized Systems&lt;br /&gt;
Austrian IT Security Handbook&lt;br /&gt;
Federal Financial Institutions Examination Council’s (FFIEC) IT handbook covers information security risk assessment&lt;br /&gt;
Threat and Risk Assessment Working Guide from The Government of Canada Security Policy&lt;br /&gt;
CRAMM - British Office of Government Commerce or The CCTA's (Central Computer and Telecommunications Agency) Risk Analysis and Management Method&lt;br /&gt;
Afhankelijkheids- en Kwetsbaarheidsanalyse (Dutch A&amp;amp;K)&lt;br /&gt;
EBIOS (French Government)&lt;br /&gt;
FRAP: Facilitated Risk Assessment Process&lt;br /&gt;
ISF –IRAM : Information Security Forum Ltd. Information Risk Analysis Methodologies . Also check FIRM (Fundamental Information Risk Management), SARA (Simple to Apply Risk Analysis) , SPRINT (Simplified Process for Risk Identification)&lt;br /&gt;
CLUSIF MEHARI - Club de la Sécurité de l'Information Français&lt;br /&gt;
Calpana CRISAM&lt;br /&gt;
Securitree from Ameneza&lt;br /&gt;
OSSTMM RAV (RAV stands for Risk Assessment Values)&lt;br /&gt;
SOMAP - Security Officers Management and Analysis Project&lt;br /&gt;
FAIR Factor Analysis of Information Risk&lt;br /&gt;
DRAM Delphic Risk Assessment Method&lt;br /&gt;
Buddy System&lt;br /&gt;
AS/NZS 4360 (2004) Risk Management. Australia/New Zealand standard for risk management&lt;br /&gt;
&lt;br /&gt;
There are also Compliance Management/SIM/SIEM solutions which partially present GRC.&lt;br /&gt;
Here are a few links:&lt;br /&gt;
&lt;br /&gt;
Tivoli Security Compliance Manager&lt;br /&gt;
&lt;a href="http://www-01.ibm.com/software/tivoli/products/security-compliance-mgr/"&gt;http://www-01.ibm.com/software/tivoli/products/security-compliance-mgr/&lt;/a&gt;&lt;br /&gt;
Novell Compliance Management Platform&lt;br /&gt;
&lt;a href="http://www.novell.com/products/compliancemanagementplatform/"&gt;http://www.novell.com/products/compliancemanagementplatform/&lt;/a&gt;&lt;br /&gt;
Easy2comply (formerly Dynasec)&lt;br /&gt;
&lt;a href="http://www.easy2comply.com/"&gt;http://www.easy2comply.com/&lt;/a&gt;&lt;br /&gt;
AlertLogic&lt;br /&gt;
&lt;a href="http://www.alertlogic.com/"&gt;http://www.alertlogic.com/&lt;/a&gt;&lt;br /&gt;
NetForensics&lt;br /&gt;
&lt;a href="http://www.netforensics.com/compliance/"&gt;http://www.netforensics.com/compliance/&lt;/a&gt;&lt;br /&gt;
Arcsight&lt;br /&gt;
&lt;a href="http://www.arcsight.com/solutions/solutions-compliance/"&gt;http://www.arcsight.com/solutions/solutions-compliance/&lt;/a&gt;&lt;br /&gt;
RSA enVision&lt;br /&gt;
&lt;a href="http://www.rsa.com/solutions/compliance/datasheets/9373_ISOENV_DS_0408-lowres.pdf"&gt;http://www.rsa.com/solutions/compliance/datasheets/9373_ISOENV_DS_0408-lowres.pdf&lt;/a&gt;&lt;br /&gt;
Intellitactics&lt;br /&gt;
&lt;a href="http://www.intellitactics.com/int/solutions/compliance.asp"&gt;http://www.intellitactics.com/int/solutions/compliance.asp&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Actually all SIM SIEM vendors have a compliance management solution. For their list you can check the following post:&lt;br /&gt;
&lt;a href="http://security.24kasim.org/2008/12/differentiation-of-log-management.html"&gt;http://security.24kasim.org/2008/12/differentiation-of-log-management.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-2319749815699427345?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Zgwha-A4kdmpvkQN_s6nj65hids/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Zgwha-A4kdmpvkQN_s6nj65hids/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Zgwha-A4kdmpvkQN_s6nj65hids/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Zgwha-A4kdmpvkQN_s6nj65hids/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=iXwQI_BEx3Y:uvmR-svhtEM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=iXwQI_BEx3Y:uvmR-svhtEM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=iXwQI_BEx3Y:uvmR-svhtEM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=iXwQI_BEx3Y:uvmR-svhtEM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=iXwQI_BEx3Y:uvmR-svhtEM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/iXwQI_BEx3Y" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/iXwQI_BEx3Y/it-governance-risk-and-compliance-itgrc.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>2</thr:total><feedburner:origLink>http://security.24kasim.org/2009/08/it-governance-risk-and-compliance-itgrc.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-8448995321037695298</guid><pubDate>Fri, 31 Jul 2009 16:00:00 +0000</pubDate><atom:updated>2009-07-31T12:04:53.426-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">compliance</category><category domain="http://www.blogger.com/atom/ns#">PCI</category><title>PCI Reporting Requirements for Merchants</title><description>&lt;em&gt;Facts:&lt;/em&gt;&lt;br /&gt;- Check  your PCI Merchant levels and validation requirements from the following post: &lt;a href="http://security.24kasim.org/2009/06/pci-levels-for-merchants-2009.html"&gt;http://security.24kasim.org/2009/06/pci-levels-for-merchants-2009.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Amex&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Level 1-&lt;br /&gt;If compliant, Attestation of Compliance –AOC- (recommended) or exec summary of onsite security assessment report (QSA/internal) annually and quarterly network scan&lt;br /&gt;If not compliant, AOC (recommended) or exec summary of onsite security assessment report and Remediation Plan annually and quarterly network scan and Remediation Plan&lt;br /&gt;&lt;br /&gt;Level 2-&lt;br /&gt;Quarterly Network Scans (and Remediation Plan if not compliant)&lt;br /&gt;AOC (Recommended)  or Executive Summary&lt;br /&gt;In EU: PCI SAQ&lt;br /&gt;&lt;br /&gt;Level 3- Level 4 -&lt;br /&gt;No reporting Required for Amex at L3 and L4&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Discover&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Level 1 –&lt;br /&gt;Network Merchants:&lt;br /&gt;If compliant Appendix D of PCI DSS requirements and Security Assessment Procedures v1.2 - Attestation of Compliance –AOC-&lt;br /&gt;If not fully compliant must also complete the Action Plan for Nono-Compliant Section of the AOC&lt;br /&gt;Acquired Merchants:&lt;br /&gt;Consult acquirer – Acquirer must submit the Discover Acquirer Network Portfolio Compliance Status Submission Form to Discover twice a year&lt;br /&gt;&lt;br /&gt;Level 2:&lt;br /&gt;Network Merchants:&lt;br /&gt;If compliant Attestation of Compliance –AOC- from applicable SAQ&lt;br /&gt;If not fully compliant must also complete the Action Plan for Non-Compliant Section of the AOC&lt;br /&gt;Acquired Merchants:&lt;br /&gt;Consult acquirer – Acquirer must submit the Discover Acquirer Network Portfolio Compliance Status Submission Form to Discover twice a year&lt;br /&gt;&lt;br /&gt;Level 3:&lt;br /&gt;Network Merchants:&lt;br /&gt;If compliant Attestation of Compliance –AOC- from applicable SAQ&lt;br /&gt;If not fully compliant must also complete the Action Plan for Non-Compliant Section of the AOC&lt;br /&gt;Acquired Merchants:&lt;br /&gt;Consult acquirer – Acquirer must submit the Discover Acquirer Network Portfolio Compliance Status Submission Form to Discover twice a year&lt;br /&gt;&lt;br /&gt;Level 4:&lt;br /&gt;Network Merchants&lt;br /&gt;If compliant Attestation of Compliance –AOC- from applicable SAQ maybe required&lt;br /&gt;If not fully compliant must also complete the Action Plan for Non-Compliant Section of the AOC&lt;br /&gt;Acquired Merchants:&lt;br /&gt;Consult acquirer – Acquirer must submit the Discover Acquirer Network Portfolio Compliance Status Submission Form or Level 4 Merchant Action Plan to Discover twice a year&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;JCB&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;JCB has no reporting requirements at this time&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;MasterCard&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Level 1-&lt;br /&gt;Acquirers register compliant merchants in the MasterCard Registration Program (MRP)&lt;br /&gt;Acquirers report status of all merchants quarterly&lt;br /&gt;&lt;br /&gt;Level 2-&lt;br /&gt;Acquirers annually register compliant merchants in the MasterCard Registration Program (MRP)&lt;br /&gt;Acquirers report status of all merchants quarterly&lt;br /&gt;&lt;br /&gt;Level 3 –&lt;br /&gt;Acquirers register compliant merchants in the MasterCard Registration Program (MRP)&lt;br /&gt;Acquirers report status of all merchants quarterly&lt;br /&gt;&lt;br /&gt;Level 4-&lt;br /&gt;No requirements&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Visa Inc&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Level 1-&lt;br /&gt;At least a twice a year , a statement of merchant compliance / non-compliance&lt;br /&gt;Annual AOC form&lt;br /&gt;Upon request a copy of Report on Compliance (ROC)&lt;br /&gt;&lt;br /&gt;Level 2-&lt;br /&gt;At least a twice a year , a statement of merchant compliance / non-compliance&lt;br /&gt;Annual AOC form&lt;br /&gt;Upon request a copy of Report on Compliance (ROC)&lt;br /&gt;&lt;br /&gt;Level 3-&lt;br /&gt;At least a twice a year , a statement of merchant compliance / non-compliance&lt;br /&gt;&lt;br /&gt;Level 4-&lt;br /&gt;Set by the acquirer&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Visa Europe&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;Level 1-&lt;br /&gt;Annual statement of merchant compliance&lt;br /&gt;For merchants in progress, quarterly update until compliance confirmed&lt;br /&gt;Upon request a copy of Report on Compliance (ROC) including indication of scan completion&lt;br /&gt;&lt;br /&gt;Level 2-&lt;br /&gt;Annual Statement of compliance / non-compliance&lt;br /&gt;For merchants in progress, quarterly update until compliance confirmed&lt;br /&gt;&lt;br /&gt;Level 3-&lt;br /&gt;Quarterly statement of compliance / non-compliance for merchants above 20000 transactions/year. Annual statement for merchant below 20000 transactions/year&lt;br /&gt;&lt;br /&gt;Level 4:&lt;br /&gt;Annual statement of compliance / non-compliance for merchants processing &lt; 1 million Visa transactions/year.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Service Providers are not merchants so if you are providing card processing for 3rd parties  (Payment Service Provider) PSP or if you are a TPP (Third Party Processor) PCI levels, validation and reporting requirements are different. The charts above are for merchants only.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-8448995321037695298?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/6gCtRW_2RWLIhL6GH96WwrjfmEg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6gCtRW_2RWLIhL6GH96WwrjfmEg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/6gCtRW_2RWLIhL6GH96WwrjfmEg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/6gCtRW_2RWLIhL6GH96WwrjfmEg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=I_OEqR6y5_w:mejpkqEF1Po:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=I_OEqR6y5_w:mejpkqEF1Po:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=I_OEqR6y5_w:mejpkqEF1Po:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=I_OEqR6y5_w:mejpkqEF1Po:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=I_OEqR6y5_w:mejpkqEF1Po:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/I_OEqR6y5_w" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/I_OEqR6y5_w/pci-reporting-requirements-for.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2009/07/pci-reporting-requirements-for.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-3483378438070305800</guid><pubDate>Sun, 28 Jun 2009 21:04:00 +0000</pubDate><atom:updated>2009-06-28T17:12:57.290-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">MPLS</category><category domain="http://www.blogger.com/atom/ns#">Cloud Computing</category><title>Clouds and the VPN</title><description>&lt;strong&gt;Question:&lt;/strong&gt;&lt;br /&gt;Do I need VPNs in the cloud?&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Answer:&lt;/strong&gt;&lt;br /&gt;There are several questions regarding the necessity of VPNs in the cloud.&lt;br /&gt;&lt;br /&gt;I think the first step is to clear the concept of cloud. Currently the word “cloud” is used interchangeably for TelCo service provider transport clouds (Network Clouds) (e.g.MPLS) and Cloud computing web services that provide resizable compute capacity as a cloud (like Amazon EC2).. We can also define private service providers like SaaS providers, managed service providers MSPs) as cloud/utility providers (like force.com from salesforce.com, webroot SaaS). Here are some articles defining cloud and transport options.&lt;br /&gt;&lt;a href="http://www.eecs.berkeley.edu/Pubs/TechRpts/2009/EECS-2009-28.pdf"&gt;http://www.eecs.berkeley.edu/Pubs/TechRpts/2009/EECS-2009-28.pdf&lt;/a&gt;&lt;br /&gt;&lt;a href="http://mediaproducts.gartner.com/reprints/f5networks/vol3/article4/article4.html"&gt;http://mediaproducts.gartner.com/reprints/f5networks/vol3/article4/article4.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;When the necessity of VPNs in the clouds are analyzed, it is obvious that encryption is indeed one of the key pillars of modern information security. And VPNs do provide confidentiality and integrity for data at transit. When cloud networks do transport the data they should provide integrity and confidentiality of data. That being said this does not have to be at layer 3 (IPSEC) or layer 6 (SSL). So focusing on an IPSEC client does not help to address the issue. Confidentiality and integrity services can also be provided via applications themselves. When data is critical you may certainly encrypt data at application layer. (e.g. rights management solutions)&lt;br /&gt;&lt;br /&gt;Here is the high level satus for VPNs in the cloud&lt;br /&gt;&lt;br /&gt;1-      TelCo Network Clouds (Service Provider) – This is the most interesting part. TelCos claim that their shared infrastructure and MPLS VPNs are secure. This is questionable (see article below) but the answer depends on the security needed.&lt;br /&gt;If service provider cloud is not trusted enough you always encrypt at another layer (usually with the application).I personally believe that cloud service provider (TelCos) must be subject to heavier inspection when they are transporting almost all of the intersite traffic. Here are some articles discussing the issue&lt;br /&gt;&lt;a href="http://www.blackhat.com/presentations/bh-europe-06/bh-eu-06-Rey-up.pdf"&gt;http://www.blackhat.com/presentations/bh-europe-06/bh-eu-06-Rey-up.pdf&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.techworld.com/networking/features/index.cfm?featureid=3360"&gt;http://www.techworld.com/networking/features/index.cfm?featureid=3360&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I also do not understand why TelCos are exempt from security regulations. (PCI is a good example)  TelCos (and their admins, applications, helpdesk people,  servers, cable guys…) do have access to almost all interoffice data traffic when MPLS type of TelCo backbone is used. And when the MPLS cloud is compromised, all clear text (yes even the tunneled ones) will be compromised.  Real encryption is rarely used. TelCos have been promoting themselves as secure service providers while promoting layered tunnels as segmentation, but I believe they must seal these claims with 3rd party certifications and allowing encryption friendly (where keys are held by the data custodians) clouds.&lt;br /&gt;&lt;br /&gt;2-     Cloud Computing providers: These providers addressed encryption at their inception thanks to their security aware generation. Before encryption there are several other questions. Here is my post on generic cloud computing security issues: &lt;a href="http://security.24kasim.org/2009/02/cloud-computing-security.html"&gt;http://security.24kasim.org/2009/02/cloud-computing-security.html&lt;/a&gt;  &lt;br /&gt;&lt;br /&gt;3-     SaaS providers. SSL looks like the king at these providers. Segregation of customer data, and customer driven/controlled encrpytion for data at rest and data at transit is required. For data at transit, SSL is secure enough when proper authentication/cert management is provided.&lt;br /&gt;&lt;br /&gt;I am still following the following basic principles when I evaluate a platform. Regardless of the nature of technology, all platforms (clouds and others) should answer properly to following areas of information security:&lt;br /&gt;1-     Authentication&lt;br /&gt;2-     Authorization&lt;br /&gt;3-     Confidentiality&lt;br /&gt;4-     Integrity&lt;br /&gt;5-     Non-Repudiation&lt;br /&gt;&lt;br /&gt;cheers,&lt;br /&gt;-       yinal&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-3483378438070305800?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/mju0sCSN9t83IdYsZbBnFIdvsdY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/mju0sCSN9t83IdYsZbBnFIdvsdY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/mju0sCSN9t83IdYsZbBnFIdvsdY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/mju0sCSN9t83IdYsZbBnFIdvsdY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=6ZJHFH7IW_o:NRrlMNxakBE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=6ZJHFH7IW_o:NRrlMNxakBE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=6ZJHFH7IW_o:NRrlMNxakBE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=6ZJHFH7IW_o:NRrlMNxakBE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=6ZJHFH7IW_o:NRrlMNxakBE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/6ZJHFH7IW_o" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/6ZJHFH7IW_o/clouds-and-vpn.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>0</thr:total><feedburner:origLink>http://security.24kasim.org/2009/06/clouds-and-vpn.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-8867134452295701909.post-7211961967348963391</guid><pubDate>Mon, 01 Jun 2009 04:04:00 +0000</pubDate><atom:updated>2009-07-31T12:06:06.861-04:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">compliance</category><category domain="http://www.blogger.com/atom/ns#">PCI</category><title>PCI Levels and Validation Requirements for Merchants 2009</title><description>&lt;p class="MsoNormal"&gt;This topic is always in the air so here are the official numbers for 2009 from PCI Security Standards Council the official governing body on the PCI&lt;span style="mso-spacerun: yes"&gt; &lt;/span&gt;requirements for merchants: &lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;i style="mso-bidi-font-style: normal"&gt;Facts&lt;/i&gt;:&lt;/p&gt;&lt;p style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 0.5in; mso-list: l0 level1 lfo1; tab-stops: list .5in" class="MsoNormal"&gt;&lt;span style="mso-list: Ignore"&gt;-&lt;span style="FONT: 7pt 'Times New Roman'"&gt; &lt;/span&gt;&lt;/span&gt;Payment Brands determine Merchant PCI levels. Payment Brands are Visa, Mastercard, Discover , Amex etc. They do have the last word on this topic&lt;/p&gt;&lt;p style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 0.5in; mso-list: l0 level1 lfo1; tab-stops: list .5in" class="MsoNormal"&gt;&lt;span style="mso-list: Ignore"&gt;-&lt;span style="FONT: 7pt 'Times New Roman'"&gt; &lt;/span&gt;&lt;/span&gt;Transaction volume is determined by Acquirer&lt;/p&gt;&lt;p style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 0.5in; mso-list: l0 level1 lfo1; tab-stops: list .5in" class="MsoNormal"&gt;&lt;span style="mso-list: Ignore"&gt;-&lt;span style="FONT: 7pt 'Times New Roman'"&gt; &lt;/span&gt;&lt;/span&gt;Transaction volume is aggregate number of transactions (chain stores do count if cards are processed centrally)&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;?xml:namespace prefix = o /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;u&gt;Amex&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 1- Over 2.5 Million Amex card transactions/year, or any merchant who is Level 1 according to another Payment Brand&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Annual Onsite QSA or Internal Audit signed by Merchant Co, Quarterly ASV scans&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 2- 50000-2.5Million Amex transactions/year, or any merchant who is Level 2 according to another Payment Brand&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: EU only annual SAQ, Quarterly ASV scans&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 3- Less than 50000 AMEX transactions/year&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action Quarterly ASV scans (recommended) , EU only SQA (recommended)&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 4- N/A&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: None&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;u&gt;Discover&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 1 - Over 6 Million Discover card transactions/year, anybody who Discover thinks&lt;span style="mso-spacerun: yes"&gt; &lt;/span&gt;that they level 1 (discretionary) or any merchant who is validated/reported as Level-1 to another Payment Brand&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Annual Onsite QSA or Internal Audit signed by Merchant Co, Quarterly ASV scans&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 2- 1-6 Million Discover transactions/year, or any merchant who is validated/reported as Level-2 to another Payment Brand&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Annual SAQ, Quarterly ASV scans&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 3- 20000-1 Million Discover transactions/year, or any merchant who is validated/reported as Level-3 to another Payment Brand&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Annual SAQ, Quarterly ASV&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 4- Everybody else with Discover card processing&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Determined by Acquirer, &lt;span style="mso-spacerun: yes"&gt;&lt;/span&gt;Annual SAQ, Quarterly ASV recommended&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;u&gt;JCB&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 1 - Over 1 Million JCB card transactions/year or anybody who is compromised&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Annual Onsite QSA audit, Quarterly ASV scans&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 2- Less than 1 Million JCB transactions/year&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Annual SAQ, Quarterly ASV scans&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 3- N/A&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: none&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 4- N/A&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: None&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;u&gt;MasterCard&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 1- Over 6 Million Mastercard card transactions/year, or any merchant who is Level 1 according to another Payment Brand or anybody who is compromised&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Annual Onsite QSA or Internal Audit signed by Merchant Co, Quarterly ASV scans&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 2- 1-6 Million Mastercard transactions/year, or any merchant who is validated/reported as Level-2 to another Payment Brand&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Annual SAQ, Quarterly ASV scans&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 3- 20000-1 Million Mastercard “e-commerce” transactions/year, or any merchant who is validated/reported as Level-3 to another Payment Brand&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Annual SAQ, Quarterly ASV&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 4- All other Mastercard merchants&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Compliance validation is at discretion of&lt;span style="mso-spacerun: yes"&gt; &lt;/span&gt;acquirer: Annual SAQ, Quarterly ASV recommended&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;u&gt;Visa Inc&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 1- Over 6 Million Visa card transactions/year (all transactions not just e-commerce), or any global merchant who is identified as Level 1 by Visa by any Visa Region&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Annual Onsite QSA or Internal Audit signed by Merchant Co, Quarterly ASV scans and attestation of compliance form&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 2- 1 Million to 6 Million Visa card transactions/year (all transactions not just e-commerce),&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Annual SAQ, Quarterly ASV scans and attestation of compliance form&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 3-&lt;span style="mso-spacerun: yes"&gt; &lt;/span&gt;20000-1 Million Visa “e-commerce” transactions/year&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Action: Annual SAQ (In Canada SAQs require QSA reviews), Quarterly ASV&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 4- Merchants processing less than 20000 e-commerce transactions/year or merchants processing up to 1M any channel Visa transactions/year&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Compliance validation is at discretion of&lt;span style="mso-spacerun: yes"&gt; &lt;/span&gt;acquirer: Annual SAQ, Quarterly ASV recommended&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;u&gt;Visa &lt;?xml:namespace prefix = st1 /&gt;&lt;st1:place st="on"&gt;Europe&lt;/st1:place&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 1- Over 6 Million Visa card transactions/year (all transactions not just e-commerce), or compromised merchants&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Annual Onsite QSA or Internal Audit signed by Merchant Co, Quarterly ASV scans and attestation of compliance form&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 2- 1 Million to 6 Million Visa card transactions/year (all transactions not just e-commerce),&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Annual SAQ, Quarterly ASV scans and attestation of compliance form&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 3-&lt;span style="mso-spacerun: yes"&gt; &lt;/span&gt;1 (one) to 1 Million Visa “e-commerce” transactions/year&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Annual SAQ, Quarterly ASV or use PCI DSS certified processor for all transactions&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Level 4- &lt;span style="mso-spacerun: yes"&gt;&lt;/span&gt;Merchants processing up to 1 Million any channel Visa transactions/year&lt;/p&gt;&lt;p class="MsoNormal"&gt;Action: Compliance validation is at discretion of&lt;span style="mso-spacerun: yes"&gt; &lt;/span&gt;acquirer: Annual SAQ, Quarterly ASV recommended&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Of course all parties who process store or transmit credit cards must follow PCI requirements (PCI-DSS) regardless of their levels.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;I will cover reporting requirements for merchants in another post.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8867134452295701909-7211961967348963391?l=security.24kasim.org' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/7BhsZmoS5nTB-070sTAkQIdX0eY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/7BhsZmoS5nTB-070sTAkQIdX0eY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/7BhsZmoS5nTB-070sTAkQIdX0eY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/7BhsZmoS5nTB-070sTAkQIdX0eY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=BClrxmFvXmE:E4bP7y0xvmo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=BClrxmFvXmE:E4bP7y0xvmo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=BClrxmFvXmE:E4bP7y0xvmo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityQa?a=BClrxmFvXmE:E4bP7y0xvmo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityQa?i=BClrxmFvXmE:E4bP7y0xvmo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityQa/~4/BClrxmFvXmE" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/InformationSecurityQa/~3/BClrxmFvXmE/pci-levels-for-merchants-2009.html</link><author>noreply@blogger.com (Yinal Ozkan)</author><thr:total>1</thr:total><feedburner:origLink>http://security.24kasim.org/2009/06/pci-levels-for-merchants-2009.html</feedburner:origLink></item></channel></rss>

