Most security products are by tradition point products targeted to solve one or (if you are lucky) two problems at the time. I have a history in networking and every time we did anything we talked about the implications from an architecture perspective. The main purpose was to make sure that that the traffic in the network was running as efficient as possible (with as much up-time as possible).
In the security space we often seem to lack this knowledge. We gladly add new products into the network without thinking about if they co-exist with other parts of the infrastructure. We add new mobile solutions that does not work with the authentication system, we add access systems that does not work with the LDAP system, we install BIG firewalls and leave the network open, we build a DMZ and then we let PC:s connect behind the DMZ the same time (split tunnelling...) etc etc.
So learn from the networking people and think from an architecture point of view, I bet there is money to be saved from this approach.
Friday, 17 April 2009
Thursday, 16 April 2009
Will better applications save the world?
First of all, I hope that you enjoyed your Easter...I did and therefore I been away from my blog...
I have been involved in an discussion about how much better the world would be if all programmers could make applications more secure from start. Apparently this would save an awful amount of money and would make all security products unnecessary. In a way I think that the notion is fairly insulting to all programmers in the world, of course that are rotten eggs among the community, but I think that most wants to do a good job.
I claim that even if all applications where perfect (from a security point of view..) we still would need security applications as the biggest problem in security is the access problem. Who, when, how etc etc should get access to information. In general it is too easy to access information.
I do not believe that it is possible for all applications to have granular access control, encrypted transmission etc. I agree that applications (and especially operating systems) could more secure but believing that this is the “silver bullet” to make the world more secure is fairly naïve.
I have been involved in an discussion about how much better the world would be if all programmers could make applications more secure from start. Apparently this would save an awful amount of money and would make all security products unnecessary. In a way I think that the notion is fairly insulting to all programmers in the world, of course that are rotten eggs among the community, but I think that most wants to do a good job.
I claim that even if all applications where perfect (from a security point of view..) we still would need security applications as the biggest problem in security is the access problem. Who, when, how etc etc should get access to information. In general it is too easy to access information.
I do not believe that it is possible for all applications to have granular access control, encrypted transmission etc. I agree that applications (and especially operating systems) could more secure but believing that this is the “silver bullet” to make the world more secure is fairly naïve.
Thursday, 2 April 2009
Another day...another rumour
I was really expecting something interesting to happen the first of April related to the virus that was expected to explode. I have searched for info but I have not seen any...so I have a question: are we now so good to handle viruses that we dealt with the problem...or did vendors use this threat to save their first quarter numbers?
Tuesday, 31 March 2009
More about clouds...it is an interesting topic
There is one thing about cloud computing that has to be said: you have to compare your existing security level with the cloud alternative. I have seen many examples of companies that have been over-confident about their security. For companies that does not have enough competence or resources cloud computing can actually increase the security level. Be realistic even if it hurts.
lA big problem that many organizations are facing is that of compliance with various regulations. Being compliant can imply a load new IT projects and forming your house in-house system into compliance can be costly.
Instead, Compliance as a Service may be offered where the service provider takes care of every requirement around the application. And the fundamental security functions such as separation, access control, authorization, end point security etc, may now be seen as selling factors
lA big problem that many organizations are facing is that of compliance with various regulations. Being compliant can imply a load new IT projects and forming your house in-house system into compliance can be costly.
Instead, Compliance as a Service may be offered where the service provider takes care of every requirement around the application. And the fundamental security functions such as separation, access control, authorization, end point security etc, may now be seen as selling factors
Monday, 30 March 2009
GhostNet In The Machine
Sometimes interesting articles about security disappears due to other more important news stories so therefore I want to highlight this one:
http://www.forbes.com/2009/03/29/ghostnet-computer-security-internet-technology-ghostnet.html
The first time I read the story I thought it was a good plot for a Hollywood movie but it turned out to be a real-life example of the insecurities in our world. When I grow up there was a saying in Sweden that came out of the 2:nd World War: A spy lays a puzzle. In meant that a spy would collect little pieces of information from different sources, the same way that this computer network worked. Viewed separately the information was not very valuable but accumulated it was indeed very valuable. The government has a responsibility in this to help private companies and organisations to defend "their piece of the puzzle". I think that governments around the world at least has to make sure that information security is a part of the public debate and to provide best practices and help with information. The problem is now too big and “evil forces” to powerful. Government has a great tradition to help the consumers through international co-operation and regulations. Now is the time to do the same in information security.
http://www.forbes.com/2009/03/29/ghostnet-computer-security-internet-technology-ghostnet.html
The first time I read the story I thought it was a good plot for a Hollywood movie but it turned out to be a real-life example of the insecurities in our world. When I grow up there was a saying in Sweden that came out of the 2:nd World War: A spy lays a puzzle. In meant that a spy would collect little pieces of information from different sources, the same way that this computer network worked. Viewed separately the information was not very valuable but accumulated it was indeed very valuable. The government has a responsibility in this to help private companies and organisations to defend "their piece of the puzzle". I think that governments around the world at least has to make sure that information security is a part of the public debate and to provide best practices and help with information. The problem is now too big and “evil forces” to powerful. Government has a great tradition to help the consumers through international co-operation and regulations. Now is the time to do the same in information security.
Friday, 27 March 2009
It is in the cloud
Andrew Yeomans from the Jericho Forum is a very smart person. I have had the opportunity to meet him a couple of times and he has impressed me every time. He is also the reason why AppGate (the company I co-founded) is a proud member of the Jericho Forum. I read an article today where he asked some very good questions about cloud computing.
Here is a short summary:
When you repatriate data from a cloud provider, taking it back into your own internal systems, how can you be sure that no trace of that data resides on their own systems? What leaks might exist between the cloud service back into our own infrastructure? Does the provider adhere to the same physical, logical and personnel controls that are applied to our own internal systems? What will happen if the provider goes bust?
These are all important things to consider before you jump into the cloud! If you do not have the answer….you should not take the dive.
Here is a short summary:
When you repatriate data from a cloud provider, taking it back into your own internal systems, how can you be sure that no trace of that data resides on their own systems? What leaks might exist between the cloud service back into our own infrastructure? Does the provider adhere to the same physical, logical and personnel controls that are applied to our own internal systems? What will happen if the provider goes bust?
These are all important things to consider before you jump into the cloud! If you do not have the answer….you should not take the dive.
Wednesday, 25 March 2009
You pay to much for your insecurity
I am the first to admit that it is hard to calculate ROI on security investments but that should not prevent us from making sure that we get as much security out of every invested dollar.
The first thing to realise is that every investment consists of two parts, the initial investment and the running cost...and that the running cost is usually much higher then expected. Why? Because in most calculations the small factor "time spent" is left out.
Think about it for a second, if you have many different specialised products installed they all have to be maintained, patched, connected etc etc but I guess that most of the products probably did not cost that much so the investment cost was low.
Why do I talk about this subject now? Because now is the perfect time to look over the real cost of running our security infrastructure...because we all need to save costs now.
I thought about this today when I got a new customers (take this as a tip rather then pure marketing) and he pressured me to pay over an extended time period as the cost saving became visible. (I have some explanation to do to my sales person now....). In the end I thought it was a good deal for both of us…he did not have to pay that much money up front..and I got a new customer.
The customer replaced his old mobile email system, his ssl VPN and re-build his DMZ.
The first thing to realise is that every investment consists of two parts, the initial investment and the running cost...and that the running cost is usually much higher then expected. Why? Because in most calculations the small factor "time spent" is left out.
Think about it for a second, if you have many different specialised products installed they all have to be maintained, patched, connected etc etc but I guess that most of the products probably did not cost that much so the investment cost was low.
Why do I talk about this subject now? Because now is the perfect time to look over the real cost of running our security infrastructure...because we all need to save costs now.
I thought about this today when I got a new customers (take this as a tip rather then pure marketing) and he pressured me to pay over an extended time period as the cost saving became visible. (I have some explanation to do to my sales person now....). In the end I thought it was a good deal for both of us…he did not have to pay that much money up front..and I got a new customer.
The customer replaced his old mobile email system, his ssl VPN and re-build his DMZ.
Subscribe to:
Posts (Atom)
