I know, I know... it has been a long time since I posted to this blog. It is truly unfortunate that there is not 25 or 26 hours in a day. Truth be told, things are heating up substantially at work. With this, coupled with my doctoral coursework, being a dad and a husband, time is pretty valuable for me to decompress. However, no excuses. I will get back into the swing of things and find some time to post to this blog.
With that, I may as well check in with how I am seeing the information security profession and the things I am coming into contact with (or avoiding intentionally).
1) Data Loss Prevention is a much bigger problem than most companies realize. While this may not come as a newsflash to some, peers and organizations that I have come into contact with are starving for justifications; yet, are probably grossly underestimating the time, budget, and strategy needed to effectively manage data before it leaves the cloud.
2) Is anyone else waiting for the next big virus to stem from the shortening of URLs ala Twitter and Facebook?
3) It should be interesting to see the adoption of Windows 7 in the corporate world. A colleague of mine recently made the statement that Microsoft may be in financial trouble if Windows 7 does not succeed. To a certain extent, I think he is correct. We are 3-5 years removed from anything truly innovative, and from the sidelines, it does appear that Microsoft is too busy regaining footing in the web browser and desktop operating systems space. Maybe they should think about...
4) Varonis. In working with the Data Loss Prevention suite directly, what Varonis is bringing to the market is truly innovative. In my humble opinion, I am not convinced that they scale to the enterprise level, but they are getting there.
5) Finally (for tonight at least), I think the security industry is still lacking a fundamental strategy for its customers. With the economy being in such a tumultuous state, every move should be calculated, justified, and brought into the wider context for our business partners. I still, to this day, believe that metrics are such a fundamental construct for justification of efforts and setting the vision. Yet I am completely surprised that organizations are still overcommitting and under-delivering on metrics that would allow the executives with the money to make a common sense call to arms.
Monday, September 7, 2009
Saturday, December 20, 2008
Security Metrics as a Process
Recently, I was presented with an interesting challenge within my organization. Quite honestly, the challenge is not anything new or specific to this organization; it is a systematic problem within the Information Security function. The concept of Information Security metrics is, in my opinion, largely based on snake oil sales. Unfortunately, it perpetuates as a nebulous science, complicated further by inconsistency and contention on resources that fail to see the value of the art.
If you had to read that last sentence multiple times to catch the meaning, well then you are at the same wavelength that our decision makers are at when it comes to the metrics that we define as a horizontal function. The statement is based on opinion, contains fancy words, and yet somehow dos not address the challenge in quantitative terms.
This is the crux of my challenge, and one that I hope can translate into my dissertation in organizational management. Metrics can be defined by nearly everyone; effective metrics cannot. The practice of arriving at effective security metrics will take many resources: human, financial, temporal, and technological.
Like the Information Security function itself, the effective metrics process is a process, not a product. Borrowing from Andrew Jaquith's book Security Metrics: Replacing Fear, Uncertainty, and Doubt, I believe he is correct when he defines the criteria for an effective metric:
Surprisingly to me at this point, is the noticable lack of material on the subject of Information Security Metrics. Outside of Andrew Jaquith's book and the works of ISO 27004, which is yet to be published, I have yet to find good material on the topic.
What I would be interested to see, is what practioners in the field use to measure their effectiveness in Information Security as a process.
If you had to read that last sentence multiple times to catch the meaning, well then you are at the same wavelength that our decision makers are at when it comes to the metrics that we define as a horizontal function. The statement is based on opinion, contains fancy words, and yet somehow dos not address the challenge in quantitative terms.
This is the crux of my challenge, and one that I hope can translate into my dissertation in organizational management. Metrics can be defined by nearly everyone; effective metrics cannot. The practice of arriving at effective security metrics will take many resources: human, financial, temporal, and technological.
Like the Information Security function itself, the effective metrics process is a process, not a product. Borrowing from Andrew Jaquith's book Security Metrics: Replacing Fear, Uncertainty, and Doubt, I believe he is correct when he defines the criteria for an effective metric:
- Consistently Measured
- Cheap to Gather
- Expressed as a Cardinal Number or Percentage
- Expressed using at least One Unit of Measure
- Contexually specific
Surprisingly to me at this point, is the noticable lack of material on the subject of Information Security Metrics. Outside of Andrew Jaquith's book and the works of ISO 27004, which is yet to be published, I have yet to find good material on the topic.
What I would be interested to see, is what practioners in the field use to measure their effectiveness in Information Security as a process.
Labels:
CISSP,
Information Security,
Metrics,
research,
security
Sunday, December 14, 2008
First Stripe
Thursday marked an important day in my brazilian jiu-jitsu training. Along with a handful of other students, I received my first promotion in the gentle art. As many of you have heard or read, I felt I had plateaued in my training, and was struggling for answers. In the ceremony, Luis "Sucuri" Togno explained how this was natural for students, and further went on to explain how proud he was of all of his students.
The interesting thing about Team Alliance from my vantage point is that, unlike many schools, Luis is very interested in the student's advancing through strict adherence to the details of each technique. He does not promote in order to run a profitable business and maintain student tuition. This is extremely important for the real world defense of the art and the skills of the practitioner. Too often we read about students at other schools being promoted to blue after 6 months or so. However, in many cases, these students do not understand the roots of the art, the accomplished fighters, or the reasons why details are so important.
I am proud to have received my bar and stripe this week, and sincerely look forward to the day I can look back on this and provide that new student, struggling in his or her own training and provide the motivation to continue on, regardless of how difficult it may seem.
Check out Alliance of Charlotte and reach out to Luis "Sucuri" Togno for more information about the academy.
Good night!
The interesting thing about Team Alliance from my vantage point is that, unlike many schools, Luis is very interested in the student's advancing through strict adherence to the details of each technique. He does not promote in order to run a profitable business and maintain student tuition. This is extremely important for the real world defense of the art and the skills of the practitioner. Too often we read about students at other schools being promoted to blue after 6 months or so. However, in many cases, these students do not understand the roots of the art, the accomplished fighters, or the reasons why details are so important.
I am proud to have received my bar and stripe this week, and sincerely look forward to the day I can look back on this and provide that new student, struggling in his or her own training and provide the motivation to continue on, regardless of how difficult it may seem.
Check out Alliance of Charlotte and reach out to Luis "Sucuri" Togno for more information about the academy.
Good night!
Labels:
BJJ,
Luis Sucuri Togno,
promotion,
Team Alliance
New Alliance BJJ YouTube Channel
Well, my professor and friend Luis "Sucuri" Togno has done it again. With very little discretionary time on his hands, he has somehow managed to find time to help Brazilian Jiu-Jitsu practioners around the world by creating a YouTube channel which demonstrates world-class techniques. The Alliance of Charlotte channel can be found here.
For those in the Charlotte, NC area looking for a rewarding and challenging experience in martial arts, highly encourage you to consider Alliance. Alliance of Charlotte's website is located in the SouthPark area, over by Angry Ale's and The Press Box.
Even if you are unsure of whether the academy is right for you, Sucuri offers a 30-day free trial.
For those in the Charlotte, NC area looking for a rewarding and challenging experience in martial arts, highly encourage you to consider Alliance. Alliance of Charlotte's website is located in the SouthPark area, over by Angry Ale's and The Press Box.
Even if you are unsure of whether the academy is right for you, Sucuri offers a 30-day free trial.
Sunday, December 7, 2008
Tuscan Whole Milk
Quite possibly the best milk ever created. If you don't believe me, check out the Amazon.com reviews...
http://www.amazon.com/Tuscan-Whole-Milk-Gallon-128/dp/B00032G1S0
http://www.amazon.com/Tuscan-Whole-Milk-Gallon-128/dp/B00032G1S0
Monday, November 17, 2008
North Carolina BJJ State Championships
Over the weekend, Team Alliance participated in the North Carolina Brazilian Jiu-Jitsu State Championships. Overall, I think the team did pretty well, taking yet another State team title. One of the highlights of the tournament for me was when a Team Alliance member was down 6-0 in points with a minute left, when he pulled this gem of a move to submit his opponent:
It was the first time I had ever seen a flying triangle in real competition, and the circumstances by which it was executed was truly amazing. Congratulations to all of my teammates on an impressive display of skill and dedication.
It was the first time I had ever seen a flying triangle in real competition, and the circumstances by which it was executed was truly amazing. Congratulations to all of my teammates on an impressive display of skill and dedication.
Sunday, November 2, 2008
Good to Great?
It is truly going to be a sad day for many Circuit City employees around the United States, as Circuit City has apparently decided to close 155 stores and withdraw from 12 markets.
Recently, I completed reading the book Good to Great by Jim Collins. Between the time I began reading it, and tonight, I have seen several of the companies profiled in this book do a complete 180. Companies, such as Fannie Mae, Circuit City, Kroger, etc. were highlighted in Jim's books. Now, I am not questioning the power of the analysis of Jim's team, and the facts do not lie about their performance. The point I am trying to make is that something happened to these companies that made them stop being great.
Are we in an age whereby large, monolithic organizations can simply steamroll the competition? The images of Walmart, Best Buy, and Bank of America spreading their business model across the landscape like a swarm of locusts. Landing where they wish, devouring all of the vegetation, and leaving permanent scarring across rural America.
I am not naive, and I understand that at this point, cost is a very important consideration for consumers. However, it makes me wonder how much these monolithic organizations are capturing, compiling, and ultimately leaving vulnerable for hackers and other mal-intended organizations.
To put it in perspective, consider the role that Microsoft plays in the world of personal computing. From my perspective -- and for the sake of this argument -- Microsoft is playing the same role that a Walmart or Best Buy is playing. However, ironically as it sounds, we do not hear the same pleas for choice as we do when we think of retail organizations. There is an entire community of people that choose the open source community for their computing needs. While the attractiveness of low cost is one factor, this is not the true motivation for many of the open source projects out there.
I could go on and on about this topic, the social impacts of the "locust swarm"; however, what I am truly searching for is a follow up book from Jim Collins that takes the same approach as his book Good to Great to perform a post mortem on the original 11 companies to see how the leadership and management has changed.
Recently, I completed reading the book Good to Great by Jim Collins. Between the time I began reading it, and tonight, I have seen several of the companies profiled in this book do a complete 180. Companies, such as Fannie Mae, Circuit City, Kroger, etc. were highlighted in Jim's books. Now, I am not questioning the power of the analysis of Jim's team, and the facts do not lie about their performance. The point I am trying to make is that something happened to these companies that made them stop being great.
Are we in an age whereby large, monolithic organizations can simply steamroll the competition? The images of Walmart, Best Buy, and Bank of America spreading their business model across the landscape like a swarm of locusts. Landing where they wish, devouring all of the vegetation, and leaving permanent scarring across rural America.
I am not naive, and I understand that at this point, cost is a very important consideration for consumers. However, it makes me wonder how much these monolithic organizations are capturing, compiling, and ultimately leaving vulnerable for hackers and other mal-intended organizations.
To put it in perspective, consider the role that Microsoft plays in the world of personal computing. From my perspective -- and for the sake of this argument -- Microsoft is playing the same role that a Walmart or Best Buy is playing. However, ironically as it sounds, we do not hear the same pleas for choice as we do when we think of retail organizations. There is an entire community of people that choose the open source community for their computing needs. While the attractiveness of low cost is one factor, this is not the true motivation for many of the open source projects out there.
I could go on and on about this topic, the social impacts of the "locust swarm"; however, what I am truly searching for is a follow up book from Jim Collins that takes the same approach as his book Good to Great to perform a post mortem on the original 11 companies to see how the leadership and management has changed.
Subscribe to:
Posts (Atom)