<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1761136646117768061</id><updated>2011-04-21T20:24:15.427-07:00</updated><category term='Introduction Gartner'/><title type='text'>Gartner Security Summit</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>20</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-6378604005146688917</id><published>2008-10-02T03:48:00.003-07:00</published><updated>2008-10-02T03:48:37.125-07:00</updated><title type='text'>Magic Quadrant and the Colour of Security</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;This post combines feedback from the last two sessions of the conference.  The first session was an explanation of the famous Gartner "Magic Quadrant", and during this session they exploded a few myths.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Magic Quadrants&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Every vendor in the diagram is a worthy alternative—it depends on what you need from the product.  If you have a niche need, then a niche product may be perfectly appropriate; but don't expect that you can make a purchase decision by just looking at the diagram; furthermore, don't expect to make a decision based on looking at the diagram and reading the analysis.  Instead, look at the diagram, read the analysis and then speak to an analyst—through that last process, the analyst will sometimes suggest vendors that didn't meet the criteria for inclusion in the report but are more appropriate to us than the vendors listed.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Magic quadrant diagrams are only produced for markets that have reached a certain maturity, so the inclusion of a vendor on the diagram should give us an indication not only of their place in the market, but the maturity of the market altogether.  Sometimes, magic quadrant reports get combined over time as markets become less siloed and products more integrated.  We need to keep an eye on acquisitions ourselves, as diagrams are not updated especially to reflect events—only yearly on a schedule.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The Colour of Security&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;This session took the form of a panel discussion which asked two questions:&lt;br /&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Will business systems be more or less secure in ten years time?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Will there be a separate IT security function in ten years or will it have become wholly integrated into IT operations?&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;table border='0' style='border-collapse:collapse'&gt;&lt;colgroup&gt;&lt;col style='width:213px'/&gt;&lt;col style='width:213px'/&gt;&lt;col style='width:213px'/&gt;&lt;/colgroup&gt;&lt;tbody valign='top'&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;&lt;p&gt;Separate IT Security Function&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;&lt;p&gt;Perpetual Arms Race&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;&lt;p&gt;Security Nirvana&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;&lt;p&gt;No Security Function&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;&lt;p&gt;Chaos&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;&lt;p&gt;Software Engineering&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;&lt;p&gt;Less Secure&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;&lt;p&gt;More Secure&lt;br /&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;&lt;p&gt;The above grid was revealed to us after the final vote.  Clearly, the descriptions are for the extremes, whereas reality is likely to be less clear cut (when is reality ever clear cut?)&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Perpetual Arms Race:&lt;/strong&gt; if there remains a separate IT security organisation, more and more will move to IT operations (as they are seeing anti-virus and anti-malware moving now) but there will always be new threats to be mitigated in the future and IT security experts to mitigate them.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Chaos:&lt;/strong&gt; if IT security organisations are operationalized and yet we are less secure, the world will descend into chaos (or at least &lt;em&gt;towards&lt;/em&gt; chaos.  &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Security Nirvana:&lt;/strong&gt; if IT security professionals maintain a separate function, but the world is more secure, then their world (and ours) will be a better place.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Software Engineering:&lt;/strong&gt; If we end up more secure, yet there is no separate IT function, it is because we have solved the problems of IT security through software engineering.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;When an American audience was asked to vote before the debates, they predicted a security nirvana; after the debate, they predicted an arms race.  We, the European audience were able immediately to predict the arms race, and stuck with that prediction after the debate.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The arguments are these:&lt;br /&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;IT security products are almost wholly reactive, so we will always be on the back foot—preparing for the most recently discovered hack, but never predicting the next one (and adequately defending against it).&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Ross Anderson (&lt;a href='http://www.ross-anderson.com'&gt;www.ross-anderson.com&lt;/a&gt; ) who spoke the previous day, indicated that security vulnerability in emerging technologies was virtually an economic certainty—only when markets mature, can vendors afford to get security right (look at Windows, look at the internet).&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Hackers are becoming professional, and are in it for the money, not the fame—that means that their priorities are different.  TJ Maxxs (TK Maxxs to us) was breached months before they realised and it was even longer before their customers were told.  This particular point kept me thinking—how many other institutions have been breached already and simply haven't found out yet…&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Separate from my blog, I am developing a slide deck that I will post when it's ready highlighting my feedback from the conference.&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-6378604005146688917?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/6378604005146688917/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=6378604005146688917' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/6378604005146688917'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/6378604005146688917'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/10/magic-quadrant-and-colour-of-security.html' title='Magic Quadrant and the Colour of Security'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-8492574529235579945</id><published>2008-10-02T03:48:00.001-07:00</published><updated>2008-10-02T03:48:21.857-07:00</updated><title type='text'>Information Security Audits as an Accepted Business Support Tool at Novartis</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;Potemkin's villages are what you get when you announce information security audits, because people can't afford to be at the receiving end of "critical audit findings".  "Audits are of little use for the management to steer a company and manage risks."  No sustainability of audit preparation.  People are threatened by audits, and don't see audits as risk management techniques.&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Make the assessment selection process transparent&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Make the conclusions transparent&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Make it a shared decision and assessment process&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Don't blame anybody for risks found in an assessment&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-8492574529235579945?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/8492574529235579945/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=8492574529235579945' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/8492574529235579945'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/8492574529235579945'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/10/information-security-audits-as-accepted.html' title='Information Security Audits as an Accepted Business Support Tool at Novartis'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-6105770808573824149</id><published>2008-10-01T06:26:00.001-07:00</published><updated>2008-10-01T06:26:33.847-07:00</updated><title type='text'>Communities of Trust Case Studies</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;What we do is dependent on us being able to share data with people outside the organisation—how can we do that safely in a "community of trust"?  What risks are introduced through the extended enterprise?&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The greater the degree of separation, the greater the difficulty of evaluating risk.  How willing is your organisation to accept risk from unmanaged PCs and non-employees?&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Trust reduction factors:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Greater distance&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Different organisations&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Cultural diversity&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Multiple jurisdictions&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Incompatible technologies&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The less you know about something, the riskier you must assume that it is.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;A Community of Trust offers:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Assurance that you know with whom you are dealing&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Confidence that information has not been manipulated&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Expectation that sensitive information will not leak&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Line of business decides how to use the technology that is provided by IT.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Call to action:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Re-evaluate your current outsourcing and partnering risks.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Move controls up the stack to application and data layers.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Put controls on endpoints where the data is used.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Use discretionary controls and logging and move towards mandatory controls—ultimately, automated controls.&lt;/li&gt;&lt;/ul&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-6105770808573824149?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/6105770808573824149/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=6105770808573824149' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/6105770808573824149'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/6105770808573824149'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/10/communities-of-trust-case-studies.html' title='Communities of Trust Case Studies'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-7380575716255696787</id><published>2008-10-01T05:35:00.001-07:00</published><updated>2008-10-01T05:35:31.096-07:00</updated><title type='text'>SANS Institute Workshop: Frontline Solutions for Security Professionals</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;This is a longer session that all the others, and I hope will take us to a greater depth of understanding of some of the issues.  The speaker is a trainer by profession, so the flavour of this posting might be different than the others.  Again, SQL injection and Cross-site scripting are the two most common attacks.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The talk was longer than it needed to be (ah well) and covered much of the same ground as the other talk by the same presenter.  However, he did give a demonstration of a SQL injection attack used to get passed a bank's credential logon screen, as well as a hacker's toolkit product that he recommended we use to determine what vulnerabilities our own systems might have against the black-hat use of the same techniques.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-7380575716255696787?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/7380575716255696787/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=7380575716255696787' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/7380575716255696787'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/7380575716255696787'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/10/sans-institute-workshop-frontline.html' title='SANS Institute Workshop: Frontline Solutions for Security Professionals'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-389023471702485238</id><published>2008-10-01T02:20:00.001-07:00</published><updated>2008-10-01T02:20:09.577-07:00</updated><title type='text'>Security in the Age of Web 2.0</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;You will be exposed to Web 2.0 insecurities, no matter what.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Web 2.0: User-Centric (user as developer); distributed; open (and open source); lightweight (user friendly)&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;What makes Web 2.0 applications insecure?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;What technologies and practices will secure Web 2.0?&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Ajax, LAMP, SOAP: Lightweight.  It is not the webmaster that selects content, no project manager, no network administrator, no DBA, no business analyst defining the taxonomy.  Results are risky for us, and for banks, businesses…&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Availability of resources&lt;/strong&gt;—those resources that we can use to analyse our applications (SAST and DAST) can be used by attackers as well (which means it is even more important that we use them).  &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Openness and collaborations as a threat&lt;/strong&gt;—deep linking, Mashups, RSS, iFrames—these things are a threat to advertising revenues (as it is main web pages that contain the advertising.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;SOA as a threat&lt;/strong&gt;—reusable services==reusable security vulnerabilities.  WSDL and UDDI disclose information to hackers.  Legacies in SOA are exposed to new (web) types of attacks.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;SWOT for Web 2.0 Application Security&lt;br /&gt;&lt;/p&gt;&lt;div&gt;&lt;table border='0' style='border-collapse:collapse'&gt;&lt;colgroup&gt;&lt;col style='width:319px'/&gt;&lt;col style='width:319px'/&gt;&lt;/colgroup&gt;&lt;tbody valign='top'&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;&lt;strong&gt;Strengths&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Good-enough technology&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Increasing awareness&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Pressure from Government and regulators&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;&lt;strong&gt;Weaknesses&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Users less mature than tools&lt;br /&gt;&lt;/li&gt;&lt;li&gt;No developers responsibility&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;div&gt;Misconceptions about:&lt;br /&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Inward facing apps&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Role of QA separate from security assurance&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Network security is no replacement for defence in depth&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;&lt;strong&gt;Threats&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Dual purpose technologies&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Changing nature of attacks (from massive to targeted) &lt;br /&gt;&lt;/li&gt;&lt;li&gt;Hackers industry&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Extreme openness, collaboration&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;&lt;strong&gt;Opportunities&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Security solutions span over application lifecycle&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Security built into applications&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Evolution towards Security 3.0 (application security, separate from network security)&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;p&gt;&lt;br/&gt;Recommends tactical acquisition of DAST and SAST—these technologies are not likely to disappear.  Check out the slide deck for the hype curve and list of vendors for DAST and SAST.  Need to look into monitors and scanners for DBMS, network and application.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Do Software Composition Analysis—validate the IP of components; validate the security/functionality of patches; validate releases.  Black Duck and Palamida are the vendors.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Mashups: Validate all input; examine license compliance; filter content presented to customers; formalize SLAs with third parties; expect abuse in unpredictable ways; prepare for HTML/XML screen scraping and iFrames.&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-389023471702485238?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/389023471702485238/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=389023471702485238' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/389023471702485238'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/389023471702485238'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/10/security-in-age-of-web-20.html' title='Security in the Age of Web 2.0'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-9152908229604280409</id><published>2008-09-30T08:39:00.001-07:00</published><updated>2008-09-30T08:39:34.390-07:00</updated><title type='text'>Creating an Effective Security and Risk Management Culture</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;Superheroes are not here to prevent things from happening—we can't afford to be drawn to a superhero model with respect to security and risk management.  The alternative is to have a mandate from the top and to earn the trust of the organisation as a whole.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The head of security must be:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Never considered an obstacle&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Consulted by business&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Someone who listens &lt;br /&gt;&lt;/li&gt;&lt;li&gt;Knows how the company makes money&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Even better:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Considered an added value&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Advice is sought out&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Board/CEO reads report&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Integral to IT planning&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Must understand constraints on activity:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Regulations: External/Internal [effectiveness of rules is a function of organizational culture]&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Cultural Proclivity [effectiveness of rules is a function of organizational culture]&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Market Forces [if it affects the bottom line, it will automatically become a priority]&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Technical Possibilities [functions in spite of control subject]&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;How many security officers does it take to make an enterprise secure?  Just one… …but the enterprise must &lt;em&gt;want&lt;/em&gt; to be secure.  Awareness, Willingness, Ability. This is the natural logical progression as we bring up security awareness.  &lt;br /&gt;&lt;/p&gt;&lt;p&gt;Can we come up with a form with the service catalog and get numbers for the level of confidentiality, integrity and availability they need for each of those systems?  Need to make sure that data owners assess their own data criticality.  Data owners explicitly accept associated risks.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Key message is that business owners own the risk, not us.  They might delegate to us the actions to reduce risk, but we don't own the risk for them.  Work with business owners to determine risks, and make sure they understand the residual risk that remains after we have performed agreed actions.&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-9152908229604280409?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/9152908229604280409/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=9152908229604280409' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/9152908229604280409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/9152908229604280409'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/creating-effective-security-and-risk.html' title='Creating an Effective Security and Risk Management Culture'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-6206202892490502058</id><published>2008-09-30T07:31:00.001-07:00</published><updated>2008-09-30T07:36:40.620-07:00</updated><title type='text'>Sales Pitches</title><content type='html'>I have blogged something about some of the cendors at the conference, ut put it on my Sharepoint blog for the sake of security...&lt;br /&gt;&lt;a href="http://cis-netsps03.lancs.ac.uk:28921/personal/meikle/Blog/default.aspx"&gt;http://cis-netsps03.lancs.ac.uk:28921/personal/meikle/Blog/default.aspx&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-6206202892490502058?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/6206202892490502058/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=6206202892490502058' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/6206202892490502058'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/6206202892490502058'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/sales-pitches.html' title='Sales Pitches'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-2914872448201750956</id><published>2008-09-30T05:53:00.001-07:00</published><updated>2008-09-30T05:53:57.539-07:00</updated><title type='text'>The Future of Database Security</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;Hmmm… Too much that is relevant here, so my comments going into e-mail.  Drop me a line if you want to know what my thoughts were.&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-2914872448201750956?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/2914872448201750956/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=2914872448201750956' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/2914872448201750956'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/2914872448201750956'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/future-of-database-security.html' title='The Future of Database Security'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-2012964968570109701</id><published>2008-09-30T03:51:00.001-07:00</published><updated>2008-09-30T03:51:45.451-07:00</updated><title type='text'>The Identity and Access Management Scenario</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;Note: there is a separate Identity and Access Management Summit.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;A set of processes and technologies to manage:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Users' digital identities&lt;br /&gt;&lt;/li&gt;&lt;li&gt;The relationship to civil identity&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Users' access to systems and the information they contain&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Identity: user lifecycle management.  Access model: role life cycle management.  Identity lifecycle consumes roles from access model.  Workflow that passes roles to user lifecycle has a lifecycle itself.  All this is done to reduce risk (how does the security framework affect the workflows).  &lt;br /&gt;&lt;/p&gt;&lt;p&gt;Security efficiency; security effectiveness; business enablement.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Interesting that, when talking about the value of IAM, the first thing the speaker mentioned was attracting and retaining customers—that is exactly what we're doing when we use UIM to help with PGA.  &lt;br /&gt;&lt;/p&gt;&lt;p&gt;Value:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Attract and retain customers&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Improve critical business processes and workflows&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Maximise performance and profitability&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;IAM Program Maturity&lt;br /&gt;&lt;/p&gt;&lt;div&gt;&lt;table border='0' style='border-collapse:collapse'&gt;&lt;colgroup&gt;&lt;col style='width:106px'/&gt;&lt;col style='width:106px'/&gt;&lt;col style='width:106px'/&gt;&lt;col style='width:106px'/&gt;&lt;col style='width:106px'/&gt;&lt;col style='width:106px'/&gt;&lt;/colgroup&gt;&lt;tbody valign='top'&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: center'&gt;Non-existent&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: center'&gt;Initial&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: center'&gt;Developing&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: center'&gt;Defined&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: center'&gt;Managed&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: center'&gt;Optimizing&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: center'&gt;4%&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: center'&gt;10%&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: center'&gt;40%&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: center'&gt;28%&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: center'&gt;15%&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: center'&gt;4%&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;&lt;p&gt;Does indicate the importance of process definition before applying IAM to that process.  We need to work out what process definition we need to do for students during the registration process (and during the application process) to give them the access they need.&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-2012964968570109701?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/2012964968570109701/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=2012964968570109701' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/2012964968570109701'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/2012964968570109701'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/identity-and-access-management-scenario.html' title='The Identity and Access Management Scenario'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-8976937316309310056</id><published>2008-09-30T02:50:00.001-07:00</published><updated>2008-09-30T02:50:16.565-07:00</updated><title type='text'>Controlling Unauthorized Network Access in a Large Organization</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;Deploying NAC at Nottingham City Council, with Sophos.  Chose Sophos because they already had their AV.  Interesting that yesterday, we were encouraged to push back on the cost of AV, and threaten to pull out our existing AV if we don't get a cut in price.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Very little detail in this presentation.  Does remind me that NAC is not an enforcement technology.  The questions from the audience reflect the issues of NAC for: a variety of roles (visitors, parent companies etc); multiple platforms (LINUX and Mac not supported by Sophos).&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-8976937316309310056?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/8976937316309310056/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=8976937316309310056' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/8976937316309310056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/8976937316309310056'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/controlling-unauthorized-network-access.html' title='Controlling Unauthorized Network Access in a Large Organization'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-4694500313183297706</id><published>2008-09-30T02:35:00.001-07:00</published><updated>2008-09-30T02:35:11.000-07:00</updated><title type='text'>Protecting Business in a Web 2.0 World</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;Signature approach to malware is running out of steam, so what should replace that paradigm?  Massive increase in the number of unique samples of malware.  There are programs now that generate malware (so there are many variants).&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Mmmm.  This has turned into a brief history of SaaS and a sales pitch for security SaaS…&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-4694500313183297706?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/4694500313183297706/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=4694500313183297706' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/4694500313183297706'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/4694500313183297706'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/protecting-business-in-web-20-world.html' title='Protecting Business in a Web 2.0 World'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-1495153359903414624</id><published>2008-09-30T01:20:00.001-07:00</published><updated>2008-09-30T01:20:58.855-07:00</updated><title type='text'>Managing Legacy Content to Decrease IT Costs and Reduce Business Risks</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;If our default, as we look at our e-mail is "I'll keep it &lt;em&gt;just in case&lt;/em&gt;." Keeping everything is expensive and most of what we keep we don't need to.  Data storage needs are going up about 50% per year (without taking into account pictures, audio and video).  No one has responsibility for information retention management.  How do we manage the costs of undisciplined data retention.  Retention schedules cannot be implemented (because no one has the responsibility).&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Suggestions:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Give legal training to IT people so that they can argue with the lawyers over what can be thrown away&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Hire data archivists (directly, not as consultants)—who can make decisions about what to save and what to keep&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Information value degrades over time—rarely does it maintain value.  After the first month of e-mail archiving, archives are rarely hit.  There are certain things that you should keep—but it is the exception, not the rule.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Five Myths about Rising Storage Demand:&lt;br /&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;It can be offset by better technology &lt;br /&gt;&lt;/li&gt;&lt;li&gt;It can be offset by paying less&lt;br /&gt;&lt;/li&gt;&lt;li&gt;It can be offset with more storage tiers&lt;br /&gt;&lt;/li&gt;&lt;li&gt;It can be satisfied with more tape&lt;br /&gt;&lt;/li&gt;&lt;li&gt;It can be accommodated with archiving software&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Determine TCO for storage and react.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Use automated methods to determine what files can be thrown away.  Determine a set of rules that can help build a list of what could be thrown away.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;How does this stuff affect us?  For students, I assume that people's home directories aren't kept in perpetuity.  For their submissions, how long do they need to be kept—do we want to keep them forever?  For e-mail, for staff H: drives, we need to work out what can be stored forever and what can't.  What's worse: not giving people lots of central storage so that things get lost on C: drives, or giving them lots of central storage and having capacity requirements go up and up…?&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-1495153359903414624?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/1495153359903414624/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=1495153359903414624' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/1495153359903414624'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/1495153359903414624'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/managing-legacy-content-to-decrease-it.html' title='Managing Legacy Content to Decrease IT Costs and Reduce Business Risks'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-7483673632632707656</id><published>2008-09-29T08:16:00.001-07:00</published><updated>2008-09-29T08:16:59.462-07:00</updated><title type='text'>Latest Trends in Computer Hacking</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;This presentation is given by Jess Garcia, of SANS.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Hacking activities have changed over the last three years or so.  &lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Dec-07—Sophiticated Trojan loots business bank accounts.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Jan-08—Bank Trojan charges for sex, breaks two factor authentication.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Botnets are being used differently now—they are the basis for more than just Denial of service attacks.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Hackers now attacking the security software itself and then obfuscate what has happened.  &lt;br /&gt;&lt;/p&gt;&lt;p&gt;Another reason why we should patch immediately—85% of the time now, there are exploits released the same day as patches for vulnerabilities.  That's up from 18% in 2004.  No longer are the attackers teenager computer experts, now they are professional cyber-criminals (hired by criminal gangs—or, if they are teenagers, they have been kidnapped by the gangs and threatened).  Rather than being motivated by prestige and curiosity, they are motivated by money.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Top Threats 2008:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Client side: Browser Plugin Attacks&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Web Apps (51% of all vulnerabilities): &lt;a href='http://en.wikipedia.org/wiki/Sql_injection'&gt;SQL Injection&lt;/a&gt; and &lt;a href='http://en.wikipedia.org/wiki/Cross_site_scripting'&gt;cross-site scripting&lt;/a&gt;&lt;br /&gt;				&lt;/li&gt;&lt;li&gt;Virtualization—this seems to be a growing area&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;div&gt;Malware&lt;br /&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Trojan Bankers&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Botnets&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Haydan is a tool that can be used to create payload with the desired MD5 hash… so much harder to trust hashes.&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-7483673632632707656?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/7483673632632707656/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=7483673632632707656' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/7483673632632707656'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/7483673632632707656'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/latest-trends-in-computer-hacking.html' title='Latest Trends in Computer Hacking'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-1681936306554239565</id><published>2008-09-29T07:28:00.001-07:00</published><updated>2008-09-29T07:28:55.538-07:00</updated><title type='text'>Malice, Misuse or Mistake: Getting to the "root" of the problem</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;This presentation seemed to suffer the same issue that I saw in vendor presentations in Barcelona—everything seemed to revolve around selling rather than imparting information—the speaker's motivation was different.  Little to say really other than we should try to follow the principle of least privilege—but nothing about how much harder that might be as we try to breakdown data silos and provide new views on data across multiple databases—no strategies for managing those new problems… ah well.&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-1681936306554239565?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/1681936306554239565/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=1681936306554239565' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/1681936306554239565'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/1681936306554239565'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/malice-misuse-or-mistake-getting-to-of.html' title='Malice, Misuse or Mistake: Getting to the &amp;quot;root&amp;quot; of the problem'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-2135070244120957292</id><published>2008-09-29T06:37:00.001-07:00</published><updated>2008-09-29T06:37:56.928-07:00</updated><title type='text'>Security of Big Applications, Legacies, Databases and Vendors</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;There is a key need for: Dynamic Analysis Security Testing and Static Analysis Security Testing.  They will help us to ensure that the applications we buy or develop are secure.  I had my 1-on-1 with the speaker at lunchtime.  He suggests that we should be asking vendors what kinds of analysis they have performed on their code. We should expect that the applications we use in conjunction with code development are deeply integrated with Visual Studio.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;There is a growing body of threats to database applications, via their web interfaces.  We should look at data obfuscation technologies to help us with testing and if we have vendors asking us to send them databases for debugging (something we won't do now).  Vendors: Applimation, DCR, Compuware, Camouflage, IBM, Oracle.  &lt;br /&gt;&lt;/p&gt;&lt;p style='text-align: justify'&gt;"Legacy application is any application that really works."  i.e., as soon as an application goes live, it is legacy.  As soon as we take our eye off the ball, we're not working on an application, it becomes legacy.  Legacy understanding is key to legacy security.  Use dynamic and static analysis to collect information on legacy, and determine what needs to be done to secure our legacy systems.&lt;br /&gt;&lt;/p&gt;&lt;p style='text-align: justify'&gt;Consider a quadrant picture with two axes: application business value against application technical quality.&lt;br /&gt;&lt;/p&gt;&lt;div&gt;&lt;table border='0' style='border-collapse:collapse'&gt;&lt;colgroup&gt;&lt;col style='width:213px'/&gt;&lt;col style='width:213px'/&gt;&lt;col style='width:213px'/&gt;&lt;/colgroup&gt;&lt;tbody valign='top'&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: justify'&gt;Increasing&lt;br /&gt;&lt;/p&gt;&lt;p style='text-align: justify'&gt;Application technical quality&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: justify'&gt;Tolerate&lt;br /&gt;&lt;/p&gt;&lt;p style='text-align: justify'&gt;(Re-evaluate/reposition)&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: justify'&gt;Integrate&lt;br /&gt;&lt;/p&gt;&lt;p style='text-align: justify'&gt;(maintain/evolve)&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: justify'&gt;Eliminate&lt;br /&gt;&lt;/p&gt;&lt;p style='text-align: justify'&gt;(Retire/Consolidate)&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: justify'&gt;Migrate&lt;br /&gt;&lt;/p&gt;&lt;p style='text-align: justify'&gt;(Modernize/re-engineer)&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: justify'&gt;Application business value -&amp;gt;&lt;br /&gt;&lt;/p&gt;&lt;p style='text-align: justify'&gt;(successful attack, is low harm)&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p style='text-align: justify'&gt;Increasing&lt;br /&gt;&lt;/p&gt;&lt;p style='text-align: justify'&gt;(successful attack is high harm&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;p style='text-align: justify'&gt;&lt;br /&gt; &lt;/p&gt;&lt;p style='text-align: justify'&gt;&lt;br /&gt;			&lt;/p&gt;&lt;p style='text-align: justify'&gt;Open Source SAST and DAST technologies are being used by hackers to determine vulnerabilities in applications.  They can then use the vulnerabilities that they find to hack those applications.  We need to ensure we understand what the hackers understand about our applications.  &lt;br /&gt;&lt;/p&gt;&lt;p style='text-align: justify'&gt;We should be using tools through all phases of application development to ensure we develop secure applications.  Need to look at the speaker's Gartner publications for more direction.&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-2135070244120957292?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/2135070244120957292/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=2135070244120957292' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/2135070244120957292'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/2135070244120957292'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/security-of-big-applications-legacies.html' title='Security of Big Applications, Legacies, Databases and Vendors'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-6734176600025218608</id><published>2008-09-29T06:06:00.001-07:00</published><updated>2008-09-29T06:06:31.781-07:00</updated><title type='text'>DNS</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;Spent some time over lunch talking to DNS.  We discussed Self-Service Password Reset (SSPR).  They indicated the following:&lt;br /&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;If you get password convergence, the use of SSPR reduces, as people have only one password to remember&lt;br /&gt;&lt;/li&gt;&lt;li&gt;People feel a stronger ownership of their password when they have only one (it is &lt;strong&gt;&lt;em&gt;their password&lt;/em&gt;&lt;/strong&gt;, not the &lt;strong&gt;&lt;em&gt;Windows password&lt;/em&gt;&lt;/strong&gt; or the &lt;strong&gt;&lt;em&gt;e-mail password&lt;/em&gt;&lt;/strong&gt; or &lt;strong&gt;&lt;em&gt;VLE password)&lt;/em&gt;&lt;/strong&gt;.  That stronger ownership leads to them keeping &lt;strong&gt;&lt;em&gt;their password&lt;/em&gt;&lt;/strong&gt; more secure.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;When there is password convergence, people are less likely to share their password, as that password gives access to their e-mail.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;They have implemented SSPR but use up to twelve questions to identify someone, and let the end-user determine the questions that they would be asked.  They do not recommend we try that in the university as they would probably go with "Q1", "Q2" for the questions and "yes" for all the answers.&lt;/li&gt;&lt;/ol&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-6734176600025218608?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/6734176600025218608/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=6734176600025218608' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/6734176600025218608'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/6734176600025218608'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/dns.html' title='DNS'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-8297165356937960531</id><published>2008-09-29T03:35:00.001-07:00</published><updated>2008-09-29T03:35:19.771-07:00</updated><title type='text'>The Mark One Human Being</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;Recent security breaches:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Nationwide fined £980,000 for stolen laptop.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;HMRC lost two CDs of child support data&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Bank customer data sold on eBay&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Secret terror file left on train&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Royal Navy laptop stolen with 600,000 people's details…&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;66% of companies increased IT security spending in 2007, but still these events continue.  &lt;br /&gt;&lt;/p&gt;&lt;p&gt;40% provide ongoing security awareness training to staff—i.e. 60% do not.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;If we don't teach people what they need to know about security, we will not be able to make the university's data more secure. We need to make security education and awareness a key part of our information security strategy.  It is not enough to tell people that security is their responsibility.  Consider how we &lt;em&gt;market&lt;/em&gt; information security awareness to ensure that the message gets across.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Once the communication is out, measure whether there is a change in behaviour.  Policy compliance, and survey results are used to inform the following year's approach.  &lt;br /&gt;&lt;/p&gt;&lt;p&gt;If we put the technology in place, but do not market and communicate the programme, so that individuals understand and fulfil their responsibilities, the investments wwe make will be worthless and security breaches will happen—meanwhile our support for investment in security will wane.&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-8297165356937960531?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/8297165356937960531/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=8297165356937960531' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/8297165356937960531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/8297165356937960531'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/mark-one-human-being.html' title='The Mark One Human Being'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-5184163631778742942</id><published>2008-09-29T02:14:00.001-07:00</published><updated>2008-09-29T02:14:50.989-07:00</updated><title type='text'>Conference Opening and Building a Real-Time Adaptive Security Infrastructure</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;Speakers: Jay Heiser; Tom Scholtz; Neil MacDonald.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Coming up later this week:&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Ross Anderson—professor of Security Engineering, University of Cambridge Computer Laboratory--speaks tomorrow and has written a book called "Security Engineering".&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Peter Hustinx, European Data Protection Supervisor—strategic issues for data protection in Europe.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Best practice workshops: SANS; ISACA.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Adaptive Security Infrastructure; Neil MacDonald discussing how information security must become adaptive.  Adaptive to changing threats and to changing business needs.  At the moment, information security is not keeping up; too many point products, with too much complexity; products are too expensive and vendors are not investing enough.  Network, endpoint, application and content security all separate and don't talk to each other.  We need to switch from "zero risk" to "managed risk".  &lt;br /&gt;&lt;/p&gt;&lt;p&gt;Implications for security as we virtualize hardware, operating system and applications; data from applications is abstracted through web services.  Then there are portable personalities, EC2 (Amazon) etc etc...&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The current model is flawed: there is no "us" and "them".  Every device, every packet, all content, every user is a risk.  Implication is that the notion of the "perimeter" is less important; security and trust are no longer binary; we need to think about the "relative trustability".  Rather than just one "perimeter" there will be multiple.  Look to survival of the system:  protect workloads and information, not endpoints.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;			&lt;/p&gt;&lt;p&gt;At the bottom, firewalls, application control.  In the middle, anti-virus, anti spam, URL filtering.  At the top, looking at behaviour.  The layers communicate with each other.  &lt;br /&gt;&lt;/p&gt;&lt;p&gt;Service Mark-up Language is going to be used to build security models (amongst other things) at the point that applications are written (will be announced by Microsoft at TechEd as project "Oslo").  Seems like the next generation of Dynamic Systems Initiative.  The model describes the role(s) that should be able to perform particular functions within the application.&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-5184163631778742942?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/5184163631778742942/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=5184163631778742942' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/5184163631778742942'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/5184163631778742942'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/conference-opening-and-building-real.html' title='Conference Opening and Building a Real-Time Adaptive Security Infrastructure'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-5402165806305027663</id><published>2008-09-29T00:51:00.001-07:00</published><updated>2008-09-29T00:51:45.960-07:00</updated><title type='text'>Mobility and Security Management Cycle</title><content type='html'>&lt;span xmlns=''&gt;&lt;p&gt;Security requires management, management requires security.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Cycle: Manage-Secure-Defend-Budget-Specify-Configure&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;How does mobility affect the challenge of management and security?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;What are the key implementation decisions to security and management?&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Management becomes more difficult when personal devices must be managed and secured (makes me think of devices bought by departments and faculties.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Platforms each require infrastructure for security and management: Blackberry, Windows Mobile, PC, personal PC, Nokia… But if we restrict platform support, people forward mail from managed device to personal account—then what happens to the security?&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Recommendations: apply security policy at the point that a device is provisioned.  Change management should check whether the device is within compliance.  As issues are solved, move them out of the responsibilities of the security group—those problems are solved, and the security group needs to look constantly to the future.  Network access control; VPN; patch management; local data encryption; port/peripheral usage control; firewall; anti-spyware; anti-virus.  For us, many of these things are rightly handled by "operations"—but maybe we need to look to the others.&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;What are the inherent weaknesses of the device?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;What default measures will strengthen device security?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;What exposures are caused by the way the device is used?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;What security measures and user practices will reduce exposure?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Can the device configuration be monitored or controlled?&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Will good management reduce operations and support costs as well as improve security?&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Consider that all the above questions need to be asked for each type of device that we use…&lt;br /&gt;&lt;/p&gt;&lt;p&gt;We may be at odds with users' requirements to ensure security.  It is interesting that the speaker says that we don't have time to evaluate windows updates before we apply them—we should just accept the risk of deploying straight away.  Not worth using EFS unless you follow best practices—otherwise it is too easy to break.  Encryption and strong authentication much better than remote lockdown/erase for mobile devices.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Securing wifi is to be a big problem moving forward—too many different kinds of devices.&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Trusted devices: corporate-issued, fully controlled (ISS managed PCs)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Tolerated device: limited to safe interactions &lt;br /&gt;&lt;/li&gt;&lt;li&gt;Unwanted devices: uncontrolled, unmanaged &lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Speaker used this grid to show that there is a landscape of issues, and that we must look to converge on solutions that cover multiple areas of the grid—though there are different strategies for doing that.  I think that we would benefit from looking to build a list of devices appropriate to the institution and determine how we &lt;em&gt;are&lt;/em&gt; approaching the different areas of concern versus how we &lt;em&gt;ought&lt;/em&gt; to approach them.&lt;br /&gt;&lt;table border='0' style='border-collapse:collapse'&gt;&lt;colgroup&gt;&lt;col style='width:82px'/&gt;&lt;col style='width:79px'/&gt;&lt;col style='width:47px'/&gt;&lt;col style='width:67px'/&gt;&lt;col style='width:72px'/&gt;&lt;col style='width:57px'/&gt;&lt;col style='width:84px'/&gt;&lt;col style='width:67px'/&gt;&lt;col style='width:40px'/&gt;&lt;col style='width:43px'/&gt;&lt;/colgroup&gt;&lt;tbody valign='top'&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;Encryption&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;lock/ wipe&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;backup/ restore&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;Inventory &amp;amp; audit&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;patch update&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;software distribution&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;anti-malware&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;VPN&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  solid black 0.5pt; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;user Auth&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;Company Desktop&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;Company notebook&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;Windows Mobile&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;Contractor PC&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;Employee notebook&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;Portable personality&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;iPhone&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  solid black 0.5pt; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt;&lt;p&gt;Blackberry&lt;/p&gt;&lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;td style='padding-left: 7px; padding-right: 7px; border-top:  none; border-left:  none; border-bottom:  solid black 0.5pt; border-right:  solid black 0.5pt'&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-5402165806305027663?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/5402165806305027663/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=5402165806305027663' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/5402165806305027663'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/5402165806305027663'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/mobility-and-security-management-cycle.html' title='Mobility and Security Management Cycle'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1761136646117768061.post-5589189831090777791</id><published>2008-09-28T23:57:00.000-07:00</published><updated>2008-09-28T23:59:39.790-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Introduction Gartner'/><title type='text'>Introduction</title><content type='html'>I am attending Gartner's Security Summit in London at the Royal Lancaster Hotel.  This blog will contain my notes from the various sessions I will attend.&lt;br /&gt;&lt;br /&gt;The first session is early on Monday morning--the music is the same as at the last Gartner event I attended--May in Barcelona...  Look forward to my session notes.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1761136646117768061-5589189831090777791?l=gartnersecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://gartnersecurity.blogspot.com/feeds/5589189831090777791/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1761136646117768061&amp;postID=5589189831090777791' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/5589189831090777791'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1761136646117768061/posts/default/5589189831090777791'/><link rel='alternate' type='text/html' href='http://gartnersecurity.blogspot.com/2008/09/introduction.html' title='Introduction'/><author><name>andrewmeikle</name><uri>http://www.blogger.com/profile/18028392641195567365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
