<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DMS Consulting LLC</title>
	<atom:link href="http://dmsconsultingllc.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://dmsconsultingllc.com</link>
	<description>Improving Your Business, One Detail at a Time</description>
	<lastBuildDate>Tue, 02 Feb 2010 20:52:36 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>The risks of SHARING!</title>
		<link>http://dmsconsultingllc.com/blog/2010/02/02/the-risks-of-sharing/</link>
		<comments>http://dmsconsultingllc.com/blog/2010/02/02/the-risks-of-sharing/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 20:27:54 +0000</pubDate>
		<dc:creator>Mark Davidson</dc:creator>
				<category><![CDATA[Information Security]]></category>

		<guid isPermaLink="false">http://dmsconsultingllc.com/?p=247</guid>
		<description><![CDATA[As you&#8217;ve probably heard or read in the news, there was a recent leak of some extremely sensitive Congressional documents through a file sharing service.  This leak highlights some of the inherent risks in the use of such services for moving data between users.  In the past, email has been the primary form of [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><img src="http://dmsconsultingllc.com/files/2010/02/020210_2028_TherisksofS1.jpg" alt="" align="left" />As you&#8217;ve probably heard or read in the news, there was a recent leak of some <a target="_blank" href="http://abcnews.go.com/Business/wireStory?id=8955108">extremely sensitive Congressional documents</a> through a file sharing service.  This leak highlights some of the inherent risks in the use of such services for moving data between users.  In the past, email has been the primary form of communication between users, however, email has it&#8217;s limits.  The explosion of data and email traffic has forced many corporate email administrators to significantly reduce the size of email boxes and attachments that can be sent through the corporate email system.  This has forced employees to find alternative ways of moving data.</p>
<p>File sharing services, such as <a target="_blank" href="http://www.kazaa.com">Kazaa</a> and <a target="_blank" href="http://www.limewire.com">Gnutella</a>, have been used for nearly a decade to share music and other non-essential files between computers.  These have been well documented as a potential security risk.</p>
<p>More recently, services such as <a target="_blank" href="http://docs.google.com">Google Docs</a>, Apple&#8217;s<a target="_blank" href="http://www.apple.com/mobileme/features/idisk.html"> iDisk</a>, and dozens more have started file sharing services.   The value of these services lies in users&#8217; ability to easily share data from anywhere in the world to anywhere in the world.  That same ability makes these services as dangerous as some of the p2p file sharing services.    If security is not set properly or mistakes are made in sharing the right files/directories, users can expose sensitive data to virtually anyone.  Additional data exposures can also occur to those sharing computing resources such as hotel kiosks, family computers, and multi-user business machines.</p>
<p><em>How do we prevent these types of exposures?  Let&#8217;s look at some of the options available:</em></p>
<p><strong><em>Thou shalt not share data!</em></strong><br />
One of the first options considered is to not allow the sharing of sensitive data.  To determine if this is the best option for your company, there are some questions you should ask:</p>
<ul>
<li>Has your company defined a classification for sensitive or confidential data?</li>
<li>Has your company defined what data can and cannot be shared outside your organization?</li>
<li>Has your company provided tools for you to share that data with others?</li>
</ul>
<p>If the answer to any of those questions is <em>NO,</em> you should evaluate your policy and/or toolsets.   It is important in today&#8217;s virtual &#8220;corporation&#8221; to share data with others, whether they are employees, contractors, or clients.    Policies and tools should to be reviewed to ensure that you can meet the goals of your company so that you can support those needs without forcing your employees to seek a solution outside your company.</p>
<p><strong><em>Stupid Users</em></strong></p>
<p>Ask any Information Technology Security professional where their biggest risk is and you will find one universal answer: <a target="_blank" href="http://news.cnet.com/8301-13846_3-10167843-62.html" />USERS</a>!  In most corporate cultures today, high productivity is valued and information security is viewed as a hindrance to that productivity.  As a result, the highest producing users will almost always take the path of least resistance to problem solving, thereby presenting an increased security risk.<br />
<img src="http://dmsconsultingllc.com/files/2010/02/020210_2028_TherisksofS3.png" alt="" align="left" />File sharing services are a perfect example of one of those paths.  Technically savvy users are far less likely to turn to the IT Department to provide a service, but will simply use the same tools they use for sharing their personal files on the web to perform business functions in order to quickly and inexpensively share files with consultants, contractors, or other users. </p>
<p>While being solutions oriented and thinking outside the box is a prized trait in our most productive users, without an effective set of tools and services readily available from your IT Department, users will present an increased data security risk. Always keep in mind that the end user will not adhere to policies that are slow, inefficient, and detrimental to their productivity levels.  The goal of any Information Security policy should be to keep the company&#8217;s data as secure as possible, while providing the tools necessary for your users to get their work done effectively and efficiently. </p>
<p><strong><em>Digital Rights Management</em></strong></p>
<p><img src="http://dmsconsultingllc.com/files/2010/02/020210_2028_TherisksofS4.png" alt="" align="left" />DRM has been around for several years. Many felt that DRM was <a target="_blank" href="http://www.infotoday.com/it/nov02/dykstra2.htm" />the panacea for all data security risks</a>.  The use of DRM in securing data does eliminate the problem with having confidential or private data from being &#8220;leaked.&#8221;   DRM is quickly becoming the next security management nightmare, right behind PKI.</p>
<p>The complexity of managing DRM and the severe limitations that DRM has placed on media companies and data owners have forced all parties to <a target="_blank" href="http://www.dbskeptic.com/2009/01/18/drm-is-failure-in-action" />re-evaluate the technology as practical</a>.   As a technology, DRM can help to control the availability of sensitive data, but the cost of managing that data is extremely high and just isn&#8217;t cost effective for most organizations.</p>
<p><img src="http://dmsconsultingllc.com/files/2010/02/020210_2028_TherisksofS5.jpg" alt="" align="right" /><strong><em>DRM Lite aka Identity Based Encryption?</em></strong></p>
<p>A new form of DRM is emerging.  This form allows sensitive data to be transferred securely, and authenticated by the user receiving that data.  That data is encrypted unless you have the authentication credentials.  Think of storing a password with the data.  This type of encryption is sometimes referred to as Identity Based Encryption (IBE).   IBE allows any user to send data encrypted via an email.   In the email are instructions for the recipient to retrieve or decode the message using a variety of different methods.    In more automated environments, passwords can be generated based upon well known facts based upon information the sender already has such as address or zip code.  While this isn&#8217;t PERFECT security, it does eliminate many of the risks for data being accidentally shared and viewed by those who shouldn&#8217;t have access.</p>
<p>Take a look in your environment?  Review your policies; conduct a web audit on whether or not your employees are using file sharing services.    Is your company supporting tools that allow users to send data securely?  If not, they will find a way to do it increasing your corporate risk.</p>



Share and Enjoy:


	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2010%2F02%2F02%2Fthe-risks-of-sharing%2F&amp;title=The%20risks%20of%20SHARING%21%20&amp;bodytext=As%20you%27ve%20probably%20heard%20or%20read%20in%20the%20news%2C%20there%20was%20a%20recent%20leak%20of%20some%20extremely%20sensitive%20Congressional%20documents%20through%20a%20file%20sharing%20service.%C2%A0%20This%20leak%20highlights%20some%20of%20the%20inherent%20risks%20in%20the%20use%20of%20such%20services%20for%20moving%20data%20be" title="Digg"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2010%2F02%2F02%2Fthe-risks-of-sharing%2F&amp;title=The%20risks%20of%20SHARING%21%20&amp;notes=As%20you%27ve%20probably%20heard%20or%20read%20in%20the%20news%2C%20there%20was%20a%20recent%20leak%20of%20some%20extremely%20sensitive%20Congressional%20documents%20through%20a%20file%20sharing%20service.%C2%A0%20This%20leak%20highlights%20some%20of%20the%20inherent%20risks%20in%20the%20use%20of%20such%20services%20for%20moving%20data%20be" title="del.icio.us"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2010%2F02%2F02%2Fthe-risks-of-sharing%2F&amp;t=The%20risks%20of%20SHARING%21%20" title="Facebook"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2010%2F02%2F02%2Fthe-risks-of-sharing%2F&amp;title=The%20risks%20of%20SHARING%21%20" title="Mixx"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2010%2F02%2F02%2Fthe-risks-of-sharing%2F&amp;title=The%20risks%20of%20SHARING%21%20&amp;annotation=As%20you%27ve%20probably%20heard%20or%20read%20in%20the%20news%2C%20there%20was%20a%20recent%20leak%20of%20some%20extremely%20sensitive%20Congressional%20documents%20through%20a%20file%20sharing%20service.%C2%A0%20This%20leak%20highlights%20some%20of%20the%20inherent%20risks%20in%20the%20use%20of%20such%20services%20for%20moving%20data%20be" title="Google Bookmarks"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2010%2F02%2F02%2Fthe-risks-of-sharing%2F&amp;title=The%20risks%20of%20SHARING%21%20" title="Live"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2010%2F02%2F02%2Fthe-risks-of-sharing%2F&amp;t=The%20risks%20of%20SHARING%21%20" title="MySpace"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://ping.fm/ref/?link=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2010%2F02%2F02%2Fthe-risks-of-sharing%2F&amp;title=The%20risks%20of%20SHARING%21%20&amp;body=As%20you%27ve%20probably%20heard%20or%20read%20in%20the%20news%2C%20there%20was%20a%20recent%20leak%20of%20some%20extremely%20sensitive%20Congressional%20documents%20through%20a%20file%20sharing%20service.%C2%A0%20This%20leak%20highlights%20some%20of%20the%20inherent%20risks%20in%20the%20use%20of%20such%20services%20for%20moving%20data%20be" title="Ping.fm"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2010%2F02%2F02%2Fthe-risks-of-sharing%2F&amp;title=The%20risks%20of%20SHARING%21%20" title="StumbleUpon"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="mailto:?subject=The%20risks%20of%20SHARING%21%20&amp;body=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2010%2F02%2F02%2Fthe-risks-of-sharing%2F" title="email"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2010%2F02%2F02%2Fthe-risks-of-sharing%2F" title="Technorati"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2010%2F02%2F02%2Fthe-risks-of-sharing%2F&amp;t=The%20risks%20of%20SHARING%21%20&amp;s=As%20you%27ve%20probably%20heard%20or%20read%20in%20the%20news%2C%20there%20was%20a%20recent%20leak%20of%20some%20extremely%20sensitive%20Congressional%20documents%20through%20a%20file%20sharing%20service.%C2%A0%20This%20leak%20highlights%20some%20of%20the%20inherent%20risks%20in%20the%20use%20of%20such%20services%20for%20moving%20data%20be" title="Tumblr"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://cgi.fark.com/cgi/fark/farkit.pl?h=The%20risks%20of%20SHARING%21%20&amp;u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2010%2F02%2F02%2Fthe-risks-of-sharing%2F" title="Fark"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/fark.png" title="Fark" alt="Fark" class="sociable-hovers" /></a>


<br/><br/> <a href="http://www.blogtrafficexchange.com/related-posts"><strong>Related Posts</strong></a> <ul>  <li> <a onClick="window.location='http://bte.tc/csR'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/11/flight1549-security-incident/">Flight 1549: A Blueprint for handling Security Incidents</a> <small>I was watching the 60 Minutes interview with Captain Sullenberger and his flight crew on...</small> </li> <li> <a onClick="window.location='http://bte.tc/6pJ'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/09/security-posture-assessment/">Security Posture Assessment - Key to a successful security program</a> <small>What is a Security Posture Assessment anyway? To put it simply, a Security Posture Assessment...</small> </li> <li> <a onClick="window.location='http://bte.tc/CAe'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/10/cheapest-easiest-effective-security-2/">Cheapest, Easiest and Most Effective Security - Security Awareness Training</a> <small>In my career I have been asked hundreds of times what single item is the...</small> </li> </ul> <a STYLE="border:none;text-decoration:none;outline:none;" href="http://www.blogtrafficexchange.com"><img border="0" alt="Blog Traffic Exchange" src="http://dmsconsultingllc.com/wp-content/plugins/related-sites/24x24.png"></a> <a href="http://www.blogtrafficexchange.com/related-websites"><strong>Related Websites</strong></a> <ul>  <li> <a onClick="window.location='http://bte.tc/SXZ'; return false;" href="http://alliantdatatel.com/2009/12/10/the-upcoming-of-internet-telephony.html">The Upcoming of Internet Telephony</a> </li> <li> <a onClick="window.location='http://bte.tc/ahK9'; return false;" href="http://www.worldphoto360.com/home-network-security/">Home Network Security</a> </li> <li> <a onClick="window.location='http://bte.tc/Wcu'; return false;" href="http://alliantdatatel.com/2009/12/17/hosted-virtual-pbx-phone-system-perfect-for-companies-with-5-50-employees.html">Hosted Virtual PBX Phone System - Perfect For Companies With 5 - 50 Employees</a> </li> </ul>]]></content:encoded>
			<wfw:commentRss>http://dmsconsultingllc.com/blog/2010/02/02/the-risks-of-sharing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ensuring your SaaS Vendor is Secure</title>
		<link>http://dmsconsultingllc.com/blog/2009/03/24/ensuring-saas-security/</link>
		<comments>http://dmsconsultingllc.com/blog/2009/03/24/ensuring-saas-security/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 20:13:45 +0000</pubDate>
		<dc:creator>Mark Davidson</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[SDLC]]></category>

		<guid isPermaLink="false">http://dmsconsultingllc.com/?p=208</guid>
		<description><![CDATA[How to ensure your SaaS or Cloud vendor has the right security to entrust your business.]]></description>
			<content:encoded><![CDATA[<p></p><div class="wp-caption aligncenter" style="width: 350px">
	<img class=" " src="http://tbn3.google.com/images?q=tbn:W14PdKYZErThhM:http://www.dftdigest.com/images/clouds.jpg" alt="Cloud Computing" width="350" height="113" />
	<p class="wp-caption-text">Cloud Computing</p>
</div>
<p>Cloud computing and Software as a Service (Saas) are quickly replacing software vendors in today&#8217;s marketplace.    Industry veterans such as Gartner are saying that over 25% of new software purchases will be using SaaS and not the traditional model.  The power of communications, support, cost and deployment ensure this into the future.</p>
<p>How does this affect the information security professional?  Substantially, but not necessarily in a bad way.   What does all of this mean to the security expert?   It means that we had better be prepared EARLY in the process of choosing of the SaaS vendor and not as an afterthought.   To accomplish this task, let&#8217;s take a look at the Top 8 items to ensure that your SaaS vendor has appropriate security:</p>
<ul class="unIndentedList">
<li>
<div class="mceTemp">
<dl> <strong>Security is a process not technology or checklists</strong>.
<dt><strong><span style="font-weight: normal"><br />
</span></strong></dt>
</dl>
</div>
</li>
</ul>
<p><img class="size-thumbnail wp-image-225" src="http://dmsconsultingllc.com/files/2009/03/security-posture-assessment-150x150.gif" alt="Security Process" width="105" height="105" />John Sawyer had it right in his article in <a target="_blank" href="http://www.darkreading.com/blog/archives/2009/02/pci_dss_is_a_pr.html">DarkReading,</a> security IS a process and not a checklist.    Make sure that the SaaS vendor&#8217;spolicies clearly articulate<br />
this.  It is not simply a check box stating that they PCI DSS compliant, or Verisign Compliant.  It is a process and a procedure for all to follow.</p>
<ul class="unIndentedList">
<li> <strong>Does Service Level Agreement (SLA) include Security</strong></li>
</ul>
<p>SaaS SLA&#8217;s offer you, the client, a financial recourse if there are any availability issues surrounding their service.  Do those include security breaches?  If your SaaS vendor loses a tape containing your client data, do you have recourse against them?  Make sure that security is included in the SLA that you sign with them.</p>
<ul class="unIndentedList">
<li> <strong>Disaster Recovery TESTING</strong></li>
</ul>
<p>Many companies, especially SaaS companies have a clearly d<img class="alignright" src="http://tbn3.google.com/images?q=tbn:FdMHkMEM03IBPM:http://www.jofil.com/assets/images/disaster_recovery_1_1_0202.jpg" alt="" width="116" height="95" />esigned and documented Disaster Recovery policy and procedure.  If they do not, then I wouldn&#8217;t even CONSIDER doing business with that company.  However, the real issue in any disaster is not whether or not they backed data up, but how fast can they put YOUR data and software back online.  You are now tied to their success.  Make sure that they provide clear evidence that they TEST their procedure and know that it will work and more importantly, how fast can they recover.</p>
<ul class="unIndentedList">
<li> <strong>Encryption and Compartmentalization of Customer Data</strong></li>
</ul>
<p><img class="alignleft" src="http://tbn2.google.com/images?q=tbn:74r-mgdGO2osPM:http://zieglers.files.wordpress.com/2008/10/encryption.jpg" alt="" width="123" height="95" />Ensure that your SaaS vendor has clear policies and technologies to ensure that data that should be encrypted is and effectively encrypted.  Simple hash algorithms for a record or row in a data table are not sufficient.</p>
<ul class="unIndentedList">
<li> <strong>Auditing vs Technical Controls </strong></li>
</ul>
<p>According to <a target="_blank" href="http://www.burtongroup.com/AboutUs/Bios/AnalystBios.aspx">Eric Maiwald</a> of the <a target="_blank" href="http://www.burtongroup.com/">Burton Group</a>, technical controls, such as for content or rights management, typically don&#8217;t work as well in an outsourced environment. When you entrust your data to SaaS, &#8220;audit replaces your day-to-day management controls and technical controls,&#8221; he asserts.  Ensure that your vendor has appropriate auditing from application to network vulnerability.  Audit is your key to ensuring security with your vendor.</p>
<ul class="unIndentedList">
<li> <strong>Secure Software Development Life Cycle (SDLC) </strong></li>
</ul>
<p>Does your SaaS vendor follow a standard practice for developing secure code?  Your data is only as safe as the code itself.  If your SaaS vendor does not subscribe to secure coding practices and standards, it is only a matter of time before data is compromised.  Take a look at the following two standards from Microsoft and the Department of Defense as examples of Secure Software Development Life Cycle:</p>
<p>o       <a target="_blank" href="https://www.thedacs.com/techs/enhanced_life_cycles/">Department of Defense Information Analysis Center&#8217;s  Secure Software Development Life Cycle</a></p>
<p>o       <a target="_blank" href="http://msdn.microsoft.com/en-us/library/ms995349.aspx">Microsoft Trustworthy Computing Security Development Lifecycle</a></p>
<ul class="unIndentedList">
<li> <strong>Can I get it Back?</strong></li>
</ul>
<p>So you have taken the plunge, and started using SaaS to handle yo<img class="alignright" src="http://tbn1.google.com/images?q=tbn:C5dR84yPAJTXfM:http://1.bp.blogspot.com/_Ym-1KNuDqF0/R-gMNHuqCRI/AAAAAAAABhQ/V_850nRccMo/s320/recoverHD.jpg" alt="" width="112" height="112" />ur aspects of your business?  What happens if they go away?   What happens if you chose the wrong vendor and they constantly miss their SLA&#8217;s?  Does your contract stipulate the ability to extract your data back from the SaaS vendor so that you can use it elsewhere?  Work with your legal department to ensure that your contracts include appropriate language to retrieve your data given these and other scenarios.</p>
<ul class="unIndentedList">
<li> <strong>Transparency </strong></li>
</ul>
<p>Does your SaaS vendor provide transparency in security, availability and performance?  The SaaS vendors that do well and succeed do already.  Look at SalesForce.com and their rollout of the <a target="_blank" href="http://trust.salesforce.com/">Trust Platform</a>.  Salesforce.com realizes that transparency in security, performance and availability is an essential component to a SaaS vendor.  Pressure your vendors to ensure that you have access to this data, since their business is servicing YOUR data, afterall.</p>
<p><img class="alignleft" src="http://tbn1.google.com/images?q=tbn:JbcVRtRLFh_zpM:http://www.the20life.com/wp-content/uploads/2008/09/money-saving-tips.jpg" alt="" width="116" height="116" />As you can see, it is important for the Information Security team to be involved early in the process when reviewing potential SaaS partners.  A great relationship with your legal team is also helpful.    The proper balance of security and the financial savings of the SaaS vendor can really be a great asset to many companies during these turbulent times.  Don&#8217;t get caught left behind when reviewing your SaaS vendors, ensure that you are leading from the front.</p>
<p><span style="color: #ff0000">Do you have an opinion?   Did I miss any of YOUR top SaaS security issues? I&#8217;d love to hear it!</span></p>



Share and Enjoy:


	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F03%2F24%2Fensuring-saas-security%2F&amp;title=Ensuring%20your%20SaaS%20Vendor%20is%20Secure&amp;bodytext=How%20to%20ensure%20your%20SaaS%20or%20Cloud%20vendor%20has%20the%20right%20security%20to%20entrust%20your%20business." title="Digg"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F03%2F24%2Fensuring-saas-security%2F&amp;title=Ensuring%20your%20SaaS%20Vendor%20is%20Secure&amp;notes=How%20to%20ensure%20your%20SaaS%20or%20Cloud%20vendor%20has%20the%20right%20security%20to%20entrust%20your%20business." title="del.icio.us"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F03%2F24%2Fensuring-saas-security%2F&amp;t=Ensuring%20your%20SaaS%20Vendor%20is%20Secure" title="Facebook"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F03%2F24%2Fensuring-saas-security%2F&amp;title=Ensuring%20your%20SaaS%20Vendor%20is%20Secure" title="Mixx"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F03%2F24%2Fensuring-saas-security%2F&amp;title=Ensuring%20your%20SaaS%20Vendor%20is%20Secure&amp;annotation=How%20to%20ensure%20your%20SaaS%20or%20Cloud%20vendor%20has%20the%20right%20security%20to%20entrust%20your%20business." title="Google Bookmarks"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F03%2F24%2Fensuring-saas-security%2F&amp;title=Ensuring%20your%20SaaS%20Vendor%20is%20Secure" title="Live"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F03%2F24%2Fensuring-saas-security%2F&amp;t=Ensuring%20your%20SaaS%20Vendor%20is%20Secure" title="MySpace"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://ping.fm/ref/?link=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F03%2F24%2Fensuring-saas-security%2F&amp;title=Ensuring%20your%20SaaS%20Vendor%20is%20Secure&amp;body=How%20to%20ensure%20your%20SaaS%20or%20Cloud%20vendor%20has%20the%20right%20security%20to%20entrust%20your%20business." title="Ping.fm"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F03%2F24%2Fensuring-saas-security%2F&amp;title=Ensuring%20your%20SaaS%20Vendor%20is%20Secure" title="StumbleUpon"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="mailto:?subject=Ensuring%20your%20SaaS%20Vendor%20is%20Secure&amp;body=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F03%2F24%2Fensuring-saas-security%2F" title="email"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F03%2F24%2Fensuring-saas-security%2F" title="Technorati"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F03%2F24%2Fensuring-saas-security%2F&amp;t=Ensuring%20your%20SaaS%20Vendor%20is%20Secure&amp;s=How%20to%20ensure%20your%20SaaS%20or%20Cloud%20vendor%20has%20the%20right%20security%20to%20entrust%20your%20business." title="Tumblr"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://cgi.fark.com/cgi/fark/farkit.pl?h=Ensuring%20your%20SaaS%20Vendor%20is%20Secure&amp;u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F03%2F24%2Fensuring-saas-security%2F" title="Fark"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/fark.png" title="Fark" alt="Fark" class="sociable-hovers" /></a>


<br/><br/> <a href="http://www.blogtrafficexchange.com/related-posts"><strong>Related Posts</strong></a> <ul>  <li> <a onClick="window.location='http://bte.tc/CAe'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/10/cheapest-easiest-effective-security-2/">Cheapest, Easiest and Most Effective Security - Security Awareness Training</a> <small>In my career I have been asked hundreds of times what single item is the...</small> </li> <li> <a onClick="window.location='http://bte.tc/avjZ'; return false;" href="http://dmsconsultingllc.com/blog/2010/02/02/the-risks-of-sharing/">The risks of SHARING! </a> <small>As you've probably heard or read in the news, there was a recent leak of...</small> </li> <li> <a onClick="window.location='http://bte.tc/6pJ'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/09/security-posture-assessment/">Security Posture Assessment - Key to a successful security program</a> <small>What is a Security Posture Assessment anyway? To put it simply, a Security Posture Assessment...</small> </li> </ul> <a STYLE="border:none;text-decoration:none;outline:none;" href="http://www.blogtrafficexchange.com"><img border="0" alt="Blog Traffic Exchange" src="http://dmsconsultingllc.com/wp-content/plugins/related-sites/24x24.png"></a> <a href="http://www.blogtrafficexchange.com/related-websites"><strong>Related Websites</strong></a> <ul>  <li> <a onClick="window.location='http://bte.tc/avsv'; return false;" href="http://alliantdatatel.com/2010/01/25/what-is-a-service-level-agreement-an-example.html">What is a Service Level Agreement (An Example)</a> </li> <li> <a onClick="window.location='http://bte.tc/gPR'; return false;" href="http://alliantdatatel.com/2009/09/12/software-as-a-service-saas-software-on-demand-using-saas-the-smart-way.html">Software As a Service (SaaS) Software on Demand - Using SaaS the Smart Way</a> </li> <li> <a onClick="window.location='http://bte.tc/a2h3'; return false;" href="http://alliantdatatel.com/2010/02/12/rapid-growth-in-telecom-voip-employment-opportunities-48.html">Rapid Growth in Telecom &amp; VoIP Employment Opportunities</a> </li> </ul>]]></content:encoded>
			<wfw:commentRss>http://dmsconsultingllc.com/blog/2009/03/24/ensuring-saas-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using Analytics to Measure InfoSec Success</title>
		<link>http://dmsconsultingllc.com/blog/2009/02/16/security-analytics/</link>
		<comments>http://dmsconsultingllc.com/blog/2009/02/16/security-analytics/#comments</comments>
		<pubDate>Mon, 16 Feb 2009 19:43:01 +0000</pubDate>
		<dc:creator>Mark Davidson</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Security Posture Assessment]]></category>
		<category><![CDATA[CISO]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Information Management]]></category>
		<category><![CDATA[SIM]]></category>
		<category><![CDATA[Vulnerability Management]]></category>

		<guid isPermaLink="false">http://www.dmsconsultingllc.com/?p=168</guid>
		<description><![CDATA[Introduction
As today&#8217;s companies become leaner and meaner, I see the use of performance metrics being used by many corporations to ensure that their productivity remains high and that the company&#8217;s employees are properly compensated.  One of the biggest challenges that I have faced as a security executive was to prove my organizations value to the [...]]]></description>
			<content:encoded><![CDATA[<p></p><h2>Introduction</h2>
<p>As today&#8217;s companies become leaner and meaner, I see the use of performance metrics being used by many corporations to ensure that their productivity <img src="http://www.strategydriven.com/wp-content/themes/strategydriven/img/OPMDrivers.jpg" alt="performance metric" hspace="12" width="192" height="163" align="right" />remains high and that the company&#8217;s employees are properly compensated.  One of the biggest challenges that I have faced as a security executive was to prove my organizations value to the business.  I was asked to objectively measure my success as a security organization.   Honestly, I was stumped for quite a while.  How do you measure success for a CISO?    Information Security can be difficult to explain to executive management.   How can we do a better job as a profession to demonstrate our business value to our companies?</p>
<h2>Concept 1:  Vulnerability Management</h2>
<p>The first concept was to measure the number of vulnerabilities in my environment and to demonstrate that the reduction in the number of vulnerabilities means that security has been improved.  This can be a very successful way to measure the <img src="http://blog.securitymonks.com/images/hackers.jpg" alt="Vulnerability" hspace="12" width="214" height="138" align="left" />success of your organization.  Better tracking, remediation and management of your vulnerabilities demonstrates to management that security as a process is being followed, that policies are being adhered and that the IT and Security organizations are working together to reduce risk.  What is the downside to measuring your success only by vulnerability management?  Well, legacy applications, new applications, new servers and M&amp;A activities create an environment that is difficult to measure and trend to the positive side.  The measurement of vulnerabilities will always increase and decrease based upon these and other factors.  These swings are difficult to explain to management since they tend to want to see nice steady improvements, not violent shifts.   Make sure you can identify the spikes when using this tool.  What has your success been using vulnerability management to measure your organizations security value?</p>
<h2>Concept 2:  Security Information Management</h2>
<p><img src="http://innovationininformation.com/images/main_image.jpg" alt="Security Information management" hspace="12" width="182" height="179" align="right" />A few years ago, the security industry spent a lot of money and resources working with a set of products called security information management tools (SIM).  These tools promised the ability to correlate complex environments and reduce the amount of information for security related data.  SIM tools delivered for the most part.  They correlated vast amounts of data and provided useful information for the security organization.  Reports from these tools provided management with actionable information and clearly demonstrated the success of security organizations from many standpoints:</p>
<ul class="unIndentedList">
<li> User and Role based controls</li>
<li> Virus Integration</li>
<li> Firewalls and IPS Logging</li>
<li> VPN/User Reporting</li>
<li> System and DB availability</li>
</ul>
<p>The challenge with these tools for many companies was the complexity of integrating the tool inside the company while creating usable reports.   The truly successful companies that implement SIM tools also implement a team of people that understand the business needs and can provide reports that are useful for the organization, not just security or IT. Deployment of a SIM tool does not guarantee success.  How successful have you been using SIM reports as the sole measurement of organizations performance?</p>
<h2>Concept 3:  Risk Management</h2>
<p><img src="http://www.vgic.com/Portals/0/Risk2.jpg" alt="Risk Measurement" hspace="12" width="169" height="117" align="left" /></p>
<p>After working on several tools including SIM and Vulnerability reports, I developed a tool that measured broad risk across many fronts including vulnerability and SIM.  The nice thing about the broad view is that I could strategically look at spheres of influence outside of pure security and measure those as well.  Development is an example.  By developing a risk model, I could now begin to look at security processes across the entire enterprise and include them in the process.  This allowed me to work more closely with some of the other business units within the company building value.  Most executives DO want to do the right thing; they just need to understand what those issues are.  The risk tool helps many business line managers to understand how security can impact them and how they impact a corporation&#8217;s risk.   The risk model turned into the Security Posture Assessment, a nearly 900 question tool for measure broad risk in an organization.  The tool allowed one to plan where resources, whether people or money for tools, needed to be invested across the organization.  The tool provided a very easy to understand metric for executives to understand where we stood and what are game plan was to improve.    Have you used a risk tool at your company to measure the value of security?  If so, how did it work?</p>
<h2>Conclusion</h2>
<p>What is the right way to measure the value of security?  There is no right answer.  The best method to use is the one that works for you and your organization.  Remember, the security wheel&#8230;security is a process, not a destination.   I would love to hear back from you!   What ways did you use at your organization to measure that success?</p>
<p><span style="color: #ff0000"><br />
</span></p>
<p><span style="color: #ff0000">Do you have an opinion?  I&#8217;d love to hear it! </span></p>



Share and Enjoy:


	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F16%2Fsecurity-analytics%2F&amp;title=Using%20Analytics%20to%20Measure%20InfoSec%20Success&amp;bodytext=Introduction%0D%0AAs%20today%27s%20companies%20become%20leaner%20and%20meaner%2C%20I%20see%20the%20use%20of%20performance%20metrics%20being%20used%20by%20many%20corporations%20to%20ensure%20that%20their%20productivity%20remains%20high%20and%20that%20the%20company%27s%20employees%20are%20properly%20compensated.%20%C2%A0One%20of%20the%20b" title="Digg"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F16%2Fsecurity-analytics%2F&amp;title=Using%20Analytics%20to%20Measure%20InfoSec%20Success&amp;notes=Introduction%0D%0AAs%20today%27s%20companies%20become%20leaner%20and%20meaner%2C%20I%20see%20the%20use%20of%20performance%20metrics%20being%20used%20by%20many%20corporations%20to%20ensure%20that%20their%20productivity%20remains%20high%20and%20that%20the%20company%27s%20employees%20are%20properly%20compensated.%20%C2%A0One%20of%20the%20b" title="del.icio.us"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F16%2Fsecurity-analytics%2F&amp;t=Using%20Analytics%20to%20Measure%20InfoSec%20Success" title="Facebook"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F16%2Fsecurity-analytics%2F&amp;title=Using%20Analytics%20to%20Measure%20InfoSec%20Success" title="Mixx"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F16%2Fsecurity-analytics%2F&amp;title=Using%20Analytics%20to%20Measure%20InfoSec%20Success&amp;annotation=Introduction%0D%0AAs%20today%27s%20companies%20become%20leaner%20and%20meaner%2C%20I%20see%20the%20use%20of%20performance%20metrics%20being%20used%20by%20many%20corporations%20to%20ensure%20that%20their%20productivity%20remains%20high%20and%20that%20the%20company%27s%20employees%20are%20properly%20compensated.%20%C2%A0One%20of%20the%20b" title="Google Bookmarks"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F16%2Fsecurity-analytics%2F&amp;title=Using%20Analytics%20to%20Measure%20InfoSec%20Success" title="Live"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F16%2Fsecurity-analytics%2F&amp;t=Using%20Analytics%20to%20Measure%20InfoSec%20Success" title="MySpace"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://ping.fm/ref/?link=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F16%2Fsecurity-analytics%2F&amp;title=Using%20Analytics%20to%20Measure%20InfoSec%20Success&amp;body=Introduction%0D%0AAs%20today%27s%20companies%20become%20leaner%20and%20meaner%2C%20I%20see%20the%20use%20of%20performance%20metrics%20being%20used%20by%20many%20corporations%20to%20ensure%20that%20their%20productivity%20remains%20high%20and%20that%20the%20company%27s%20employees%20are%20properly%20compensated.%20%C2%A0One%20of%20the%20b" title="Ping.fm"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F16%2Fsecurity-analytics%2F&amp;title=Using%20Analytics%20to%20Measure%20InfoSec%20Success" title="StumbleUpon"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="mailto:?subject=Using%20Analytics%20to%20Measure%20InfoSec%20Success&amp;body=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F16%2Fsecurity-analytics%2F" title="email"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F16%2Fsecurity-analytics%2F" title="Technorati"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F16%2Fsecurity-analytics%2F&amp;t=Using%20Analytics%20to%20Measure%20InfoSec%20Success&amp;s=Introduction%0D%0AAs%20today%27s%20companies%20become%20leaner%20and%20meaner%2C%20I%20see%20the%20use%20of%20performance%20metrics%20being%20used%20by%20many%20corporations%20to%20ensure%20that%20their%20productivity%20remains%20high%20and%20that%20the%20company%27s%20employees%20are%20properly%20compensated.%20%C2%A0One%20of%20the%20b" title="Tumblr"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://cgi.fark.com/cgi/fark/farkit.pl?h=Using%20Analytics%20to%20Measure%20InfoSec%20Success&amp;u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F16%2Fsecurity-analytics%2F" title="Fark"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/fark.png" title="Fark" alt="Fark" class="sociable-hovers" /></a>


<br/><br/> <a href="http://www.blogtrafficexchange.com/related-posts"><strong>Related Posts</strong></a> <ul>  <li> <a onClick="window.location='http://bte.tc/6pJ'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/09/security-posture-assessment/">Security Posture Assessment - Key to a successful security program</a> <small>What is a Security Posture Assessment anyway? To put it simply, a Security Posture Assessment...</small> </li> <li> <a onClick="window.location='http://bte.tc/CAe'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/10/cheapest-easiest-effective-security-2/">Cheapest, Easiest and Most Effective Security - Security Awareness Training</a> <small>In my career I have been asked hundreds of times what single item is the...</small> </li> <li> <a onClick="window.location='http://bte.tc/avjZ'; return false;" href="http://dmsconsultingllc.com/blog/2010/02/02/the-risks-of-sharing/">The risks of SHARING! </a> <small>As you've probably heard or read in the news, there was a recent leak of...</small> </li> </ul> <a STYLE="border:none;text-decoration:none;outline:none;" href="http://www.blogtrafficexchange.com"><img border="0" alt="Blog Traffic Exchange" src="http://dmsconsultingllc.com/wp-content/plugins/related-sites/24x24.png"></a> <a href="http://www.blogtrafficexchange.com/related-websites"><strong>Related Websites</strong></a> <ul>  <li> <a onClick="window.location='http://bte.tc/ahK9'; return false;" href="http://www.worldphoto360.com/home-network-security/">Home Network Security</a> </li> <li> <a onClick="window.location='http://bte.tc/et7'; return false;" href="http://www.handymanfixhomerepair.com/guide-to-measuring-and-marking-tools-pt-5/">Guide to Measuring and Marking Tools pt 5</a> </li> <li> <a onClick="window.location='http://bte.tc/4Xk'; return false;" href="http://alliantdatatel.com/2009/11/26/twelve-key-questions-you-need-to-ask-about-your-computer-security-for-your-home-or-business.html">Twelve Key Questions You Need to Ask About Your Computer Security for Your Home or Business</a> </li> </ul>]]></content:encoded>
			<wfw:commentRss>http://dmsconsultingllc.com/blog/2009/02/16/security-analytics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Flight 1549: A Blueprint for handling Security Incidents</title>
		<link>http://dmsconsultingllc.com/blog/2009/02/11/flight1549-security-incident/</link>
		<comments>http://dmsconsultingllc.com/blog/2009/02/11/flight1549-security-incident/#comments</comments>
		<pubDate>Wed, 11 Feb 2009 19:42:03 +0000</pubDate>
		<dc:creator>Mark Davidson</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Captain Sullenberger]]></category>
		<category><![CDATA[CISO]]></category>
		<category><![CDATA[Flight 1549]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[security awareness]]></category>

		<guid isPermaLink="false">http://www.dmsconsultingllc.com/?p=159</guid>
		<description><![CDATA[I was watching the 60 Minutes interview with Captain Sullenberger and his flight crew on Sunday.  If you haven&#8217;t seen it, please take a few minutes to watch the interview below:
CBS 60 Min Interview with Capt. Sullenberger
Introduction

I was struck by the professionalism and the calmness of the flight crew and especially Capt. Sullenberger.  During [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><span style="font-size: 12pt;font-family: &quot;Times New Roman&amp;quot">I was watching the 60 Minutes interview with Captain Sullenberger and his flight crew on Sunday.  If you haven&#8217;t seen it, please take a few minutes to watch the interview below:</span></p>
<p><a target="_blank" href="http://www.cbs.com"></a><a target="_blank" href="http://www.cbsnews.com/video/watch/?id=4784194n"></a><a target="_blank" href="http://www.cbsnews.com/video/watch/?id=4784194n">CBS 60 Min Interview with Capt. Sullenberger</a></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small"><span style="font-family: Times New Roman"><strong>Introduction</strong></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt">
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small"><span style="font-family: Times New Roman">I was struck by the professionalism and the calmness of the flight crew and especially Capt. Sullenberger.<span> </span><span> </span>During the interview, I kept thinking about how this could be applied to the information security industry, and especially to my CISO counterparts.<span> </span>What are some lessons for handling our emergencies, security incidents, that we should learn from this near tragedy?<span> </span><span> </span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman">No matter how well designed the Airbus A320 that was used by US Air Flight 1549, problems can arise that are outside of the control of the plane designers and their flight crew.<span> </span>In Flight 1549’s case, these problems were not design flaws but a flock of birds.<span> </span>Equate that to our world of information security.<span> </span>We have designed networks.<span> </span>We have purchased firewalls, intrusion prevention systems, and various other types of technologies to secure the companies that employ us.<span> </span>Yet there are times that we still have security breaches.<span> </span>How can we take the lessons of Capt. Sullenberger and his crew and apply them to our industry?</span><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><strong><span style="font-size: small"><span style="font-family: Times New Roman">Training</span></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small"><span style="font-family: Times New Roman">The first thing that I noticed from the interview was how Capt. Sullenberger immediately took over the plane’s climb out from <span lang="EN">Jeffrey B. Skiles, </span>his First Officer.<span> </span>There was an obvious protocol for transition.<span> </span>The flight team’s training was obvious.<span> </span>They immediately began checking down through various protocols, attempting to restart the engines, calling an emergency all the while attempting to glide the disabled plane to safety.<span> </span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman">Is there a clear and defined process for handling your security incidents at your company?<span> </span>Have ALL of your IT and information security employees been trained on those procedures and know their responsibilities?<span> </span>If your organization does not have a documented Incident Response policy and procedures, you should immediately develop one.<span> </span>I would say that many companies do have an Incident Response Policy and Procedures. <span> </span>However, most companies do not provide adequate training for those procedures.<span> </span>Make sure that your IT and Security staff are not only aware of the Incident Response policy and procedures but have yearly training so that they are familiar with them.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><strong><span style="font-size: small"><span style="font-family: Times New Roman">Testing</span></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small"><span style="font-family: Times New Roman">When listening to Capt. Sullenberger describe his background, his experience in handling emergency procedures was clear.<span> </span>Capt. Sullenberger obviously had used simulators and role playing in his safety consulting practice and accident investigations.<span> </span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman">Training and clearly written procedures are absolutely critical in the handling of security incidents.<span> </span>One of the most obvious omissions is the TESTING of those procedures.<span> </span>Running a periodic test of the incident handling procedures not only provides a training vehicle, but also helps refine the process for when the real emergency occurs.<span> </span>Test your Incident Procedures at least yearly to ensure this process works smoothly when you need it.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><strong><span style="font-size: small"><span style="font-family: Times New Roman">Teamwork</span></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman">During the interview you heard Capt. Sullenberger say several times that he trusted in his flight crew as professionals.<span> </span>He mentioned that he heard the flight attendants in the main cabin quickly understand and prepare the cabin with his very terse phrase, “Brace for impact,” while he and First Officer Skiles were gliding the plane and quickly assessing a landing area.<span> </span>Capt. Sullenberger had faith that his crew knew what to do and didn’t second guess them.<span> </span>His crew had faith in Capt. Sullenberger and that he would keep them safe.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman">Ensuring that we have the right members of the Incident Response team is critical.<span> </span>Do we have a PR person identified?<span> </span>Can we retrieve emergency backups if necessary?<span> </span>All these team members are critical to a successful incident response procedure.<span> </span>Ensure that your team is in place and is prepared.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><strong><span style="font-size: small"><span style="font-family: Times New Roman">Calmness</span></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman">Finally, I noticed that during the entire 3.5 minutes that Capt. Sullenberger had to land that airplane, his demeanor was always professional and calm.<span> </span>The entire crew and even the passengers noticed that trait.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small"><span style="font-family: Times New Roman">I have seen many IT and security organizations panic when an incident is identified.<span> </span>It interrupts daily operations, business and can take away focus from other important items in a company.<span> </span>Keeping calm in an emergency can help focus your team.<span> </span>It keeps your co-executives from being uneasy and helps to ensure your success.<span> </span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman">Remember these lessons from the Captain Sullenberger and his crew.<span> </span>His lessons are very useful for us all. <span> </span>From my heart and the families of the passengers of Flight 1549:</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: 18pt"><span style="font-family: Times New Roman"> </span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;text-align: center" align="center"><strong><span style="font-size: 18pt"><span style="font-family: Times New Roman">Thank You!</span></span></strong></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="font-size: small;font-family: Times New Roman"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt"><span style="color: red"><span style="font-size: small"><span style="font-family: Times New Roman"><span style="color: #ff0000">Do you have an opinion?  I&#8217;d love to hear it!</span><span><span style="color: #ff0000"> </span> </span></span></span></span></p>



Share and Enjoy:


	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F11%2Fflight1549-security-incident%2F&amp;title=Flight%201549%3A%20A%20Blueprint%20for%20handling%20Security%20Incidents&amp;bodytext=I%20was%20watching%20the%2060%20Minutes%20interview%20with%20Captain%20Sullenberger%20and%20his%20flight%20crew%20on%20Sunday.%C2%A0%20If%20you%20haven%27t%20seen%20it%2C%20please%20take%20a%20few%20minutes%20to%20watch%20the%20interview%20below%3A%0D%0A%0D%0ACBS%2060%20Min%20Interview%20with%20Capt.%20Sullenberger%0D%0AIntroduction%0D%0A%0D%0AI%20was%20" title="Digg"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F11%2Fflight1549-security-incident%2F&amp;title=Flight%201549%3A%20A%20Blueprint%20for%20handling%20Security%20Incidents&amp;notes=I%20was%20watching%20the%2060%20Minutes%20interview%20with%20Captain%20Sullenberger%20and%20his%20flight%20crew%20on%20Sunday.%C2%A0%20If%20you%20haven%27t%20seen%20it%2C%20please%20take%20a%20few%20minutes%20to%20watch%20the%20interview%20below%3A%0D%0A%0D%0ACBS%2060%20Min%20Interview%20with%20Capt.%20Sullenberger%0D%0AIntroduction%0D%0A%0D%0AI%20was%20" title="del.icio.us"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F11%2Fflight1549-security-incident%2F&amp;t=Flight%201549%3A%20A%20Blueprint%20for%20handling%20Security%20Incidents" title="Facebook"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F11%2Fflight1549-security-incident%2F&amp;title=Flight%201549%3A%20A%20Blueprint%20for%20handling%20Security%20Incidents" title="Mixx"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F11%2Fflight1549-security-incident%2F&amp;title=Flight%201549%3A%20A%20Blueprint%20for%20handling%20Security%20Incidents&amp;annotation=I%20was%20watching%20the%2060%20Minutes%20interview%20with%20Captain%20Sullenberger%20and%20his%20flight%20crew%20on%20Sunday.%C2%A0%20If%20you%20haven%27t%20seen%20it%2C%20please%20take%20a%20few%20minutes%20to%20watch%20the%20interview%20below%3A%0D%0A%0D%0ACBS%2060%20Min%20Interview%20with%20Capt.%20Sullenberger%0D%0AIntroduction%0D%0A%0D%0AI%20was%20" title="Google Bookmarks"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F11%2Fflight1549-security-incident%2F&amp;title=Flight%201549%3A%20A%20Blueprint%20for%20handling%20Security%20Incidents" title="Live"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F11%2Fflight1549-security-incident%2F&amp;t=Flight%201549%3A%20A%20Blueprint%20for%20handling%20Security%20Incidents" title="MySpace"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://ping.fm/ref/?link=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F11%2Fflight1549-security-incident%2F&amp;title=Flight%201549%3A%20A%20Blueprint%20for%20handling%20Security%20Incidents&amp;body=I%20was%20watching%20the%2060%20Minutes%20interview%20with%20Captain%20Sullenberger%20and%20his%20flight%20crew%20on%20Sunday.%C2%A0%20If%20you%20haven%27t%20seen%20it%2C%20please%20take%20a%20few%20minutes%20to%20watch%20the%20interview%20below%3A%0D%0A%0D%0ACBS%2060%20Min%20Interview%20with%20Capt.%20Sullenberger%0D%0AIntroduction%0D%0A%0D%0AI%20was%20" title="Ping.fm"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F11%2Fflight1549-security-incident%2F&amp;title=Flight%201549%3A%20A%20Blueprint%20for%20handling%20Security%20Incidents" title="StumbleUpon"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="mailto:?subject=Flight%201549%3A%20A%20Blueprint%20for%20handling%20Security%20Incidents&amp;body=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F11%2Fflight1549-security-incident%2F" title="email"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F11%2Fflight1549-security-incident%2F" title="Technorati"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F11%2Fflight1549-security-incident%2F&amp;t=Flight%201549%3A%20A%20Blueprint%20for%20handling%20Security%20Incidents&amp;s=I%20was%20watching%20the%2060%20Minutes%20interview%20with%20Captain%20Sullenberger%20and%20his%20flight%20crew%20on%20Sunday.%C2%A0%20If%20you%20haven%27t%20seen%20it%2C%20please%20take%20a%20few%20minutes%20to%20watch%20the%20interview%20below%3A%0D%0A%0D%0ACBS%2060%20Min%20Interview%20with%20Capt.%20Sullenberger%0D%0AIntroduction%0D%0A%0D%0AI%20was%20" title="Tumblr"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://cgi.fark.com/cgi/fark/farkit.pl?h=Flight%201549%3A%20A%20Blueprint%20for%20handling%20Security%20Incidents&amp;u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F11%2Fflight1549-security-incident%2F" title="Fark"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/fark.png" title="Fark" alt="Fark" class="sociable-hovers" /></a>


<br/><br/> <a href="http://www.blogtrafficexchange.com/related-posts"><strong>Related Posts</strong></a> <ul>  <li> <a onClick="window.location='http://bte.tc/6pJ'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/09/security-posture-assessment/">Security Posture Assessment - Key to a successful security program</a> <small>What is a Security Posture Assessment anyway? To put it simply, a Security Posture Assessment...</small> </li> <li> <a onClick="window.location='http://bte.tc/avjZ'; return false;" href="http://dmsconsultingllc.com/blog/2010/02/02/the-risks-of-sharing/">The risks of SHARING! </a> <small>As you've probably heard or read in the news, there was a recent leak of...</small> </li> <li> <a onClick="window.location='http://bte.tc/9FJ'; return false;" href="http://dmsconsultingllc.com/blog/2009/03/24/ensuring-saas-security/">Ensuring your SaaS Vendor is Secure</a> <small>/caption] Cloud computing and Software as a Service (Saas) are quickly replacing software vendors in...</small> </li> </ul> <a STYLE="border:none;text-decoration:none;outline:none;" href="http://www.blogtrafficexchange.com"><img border="0" alt="Blog Traffic Exchange" src="http://dmsconsultingllc.com/wp-content/plugins/related-sites/24x24.png"></a> <a href="http://www.blogtrafficexchange.com/related-websites"><strong>Related Websites</strong></a> <ul>  <li> <a onClick="window.location='http://bte.tc/Fk5'; return false;" href="http://www.rateladder.com/2008/05/02/blogger-obtains-loan-using-social-capital/">Blogger Obtains Loan Using Social Capital</a> </li> <li> <a onClick="window.location='http://bte.tc/-rv'; return false;" href="http://www.worldphoto360.com/2009/12/27/more-details-surrounding-suspected-airplane-terroristumar-farouk-abdulmutallab/">More details surrounding suspected Airplane Terrorist: Umar Farouk Abdulmutallab</a> </li> <li> <a onClick="window.location='http://bte.tc/abpA'; return false;" href="http://www.worldphoto360.com/2009/12/30/dutch-to-use-full-body-scans-for-u-s-flights/">Dutch to use full body scans for U.S. flights</a> </li> </ul>]]></content:encoded>
			<wfw:commentRss>http://dmsconsultingllc.com/blog/2009/02/11/flight1549-security-incident/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cheapest, Easiest and Most Effective Security &#8211; Security Awareness Training</title>
		<link>http://dmsconsultingllc.com/blog/2009/02/10/cheapest-easiest-effective-security-2/</link>
		<comments>http://dmsconsultingllc.com/blog/2009/02/10/cheapest-easiest-effective-security-2/#comments</comments>
		<pubDate>Tue, 10 Feb 2009 13:30:45 +0000</pubDate>
		<dc:creator>Mark Davidson</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Security Awareness Training]]></category>

		<guid isPermaLink="false">http://www.dmsconsultingllc.com/?p=136</guid>
		<description><![CDATA[In my career I have been asked hundreds of times what single item is the holy grail of security.  Is it a firewall?  Is it an Intrusion Prevention System (IPS)?  Perhaps it is a Single Sign-On Tool (SSO)?  No, contrary to what most vendors say, the cheapest, easiest and most effective security component of any [...]]]></description>
			<content:encoded><![CDATA[<p></p><p style="text-align: center"><img class="aligncenter" src="http://blogs.southtownstar.com/money/Juggle_cheap_cs_20080625172105.jpg" alt="Cheap Frugal" width="127" height="130" />In my career I have been asked hundreds of times what single item is the holy grail of security.  Is it a firewall?  Is it an Intrusion Prevention System (IPS)?  Perhaps it is a Single Sign-On Tool (SSO)?  No, contrary to what most vendors say, the cheapest, easiest and most effective security component of any corporation is NOT a firewall, an IPS nor is it ANY technology.    So what is it?</p>
<p style="text-align: center"><img class="aligncenter" src="http://halfwaytoconcord.com/wp-content/uploads/2008/07/customer-service.jpg" alt="Weakest Link" width="180" height="135" />The old axiom is true&#8230;security is only as good as its weakest link.  What is your company&#8217;s weakest link?  In the vast majority of companies, that link is it&#8217;s&#8230;. PEOPLE!   All the technology in the world can&#8217;t stop an employee circumventing that technology to make his or her job easier.</p>
<p style="text-align: center"><img class="aligncenter" src="http://webtoolsandtips.com/wp-content/uploads/2008/12/top-10-internet-security-free-services.gif" alt="Security Tools" width="164" height="149" /></p>
<p>While technologies such as firewalls, IPS and the myriad of other tools are needed and useful, they alone do not address the issues of people. How do we address this issue? What is that low cost way for ensuring that your company&#8217;s security posture improves? It is quite simple…one of the most overlooked tools in a security providers kit, Security Awareness Training.</p>
<p><img class="alignleft" src="http://www.pophtc.pitt.edu/images/KS85341.jpg" alt="Security Training" width="130" height="194" />Training is a simple and inexpensive way to increase your company&#8217;s security posture. The effort put into training your employees can greatly increase your security coverage. Think of it as the security geometric curve of effectiveness. Training allows all your employees to cover more areas with vigilance.</p>
<p>What are the steps to creating better security awareness at your company?</p>
<ul>
<li>Security Awareness is a campaign and not a class.</li>
</ul>
<p style="margin-left: 18pt">While a power point presentation on security can have effect it is not an effective campaign, just a component of one. Periodic security reminders are very useful in keeping vigilant in this day and age.</p>
<p style="margin-left: 18pt"> </p>
<ul>
<li>Compliance</li>
</ul>
<p style="margin-left: 18pt">Compliance is a dirty word of today&#8217;s corporate environment. But in reality, many compliance initiatives require some sort of awareness training (HIPAA/PCI). Leverage those corporate initiatives to help educate your employees. This may be a way to find some budget for your awareness program.</p>
<p style="margin-left: 18pt"> </p>
<ul>
<li>Help your employees at home and they will help you at work<img class="aligncenter" src="http://www.loanprocessor.org/images/work-at-home-job-opportunity.jpg" alt="Work From Home" width="290" height="212" /></li>
</ul>
<p style="margin-left: 18pt">One of the best ways to educate your employees is to teach them how to secure their own privacy data and home computers. This teaches them the importance of security as it relates to their own resources, not just the companies. Most employees take this to heart and will begin to see how they can utilize those same practices with the corporate assets and your customer data.</p>
<p style="text-align: center"><img class="aligncenter" src="http://www.tsgraves.com/images/posters/wellsfargo_500Reward.jpg" alt="Reward" width="330" height="239" /></p>
<ul>
<li>Reward</li>
</ul>
<p style="margin-left: 18pt">If one of your associates sees a security issue and notifies you, play it up! A great tool for helping create awareness is to give awards when people do the right thing. Take them to lunch; write them up in your company newsletter. These little things reinforce great behavior.</p>
<p style="margin-left: 18pt"> </p>
<ul>
<li>Don&#8217;t be Chicken Little</li>
</ul>
<p style="margin-left: 18pt"><img src="http://2.bp.blogspot.com/_DEPuKIoxvxE/SLQ4QgwNipI/AAAAAAAACLI/KtuwvtxJVXk/s400/disney-chicken-little-sky-falling.jpg" alt="Chicken Little" width="117" height="144" />Think about the last time you paid attention to the Homeland security threat level? What is it today? Do you know? We, in the security industry have done a great disservice to many of our users. We have said the &#8220;sky is falling&#8221; so many times that people have stopped listening. Be positive in your security training. Talk about effective techniques for creating passwords, not just telling users to not use their names for passwords.</p>
<p style="margin-left: 18pt"> </p>
<ul>
<li>Utilize your corporate training tools</li>
</ul>
<p style="margin-left: 18pt">There are many tools you can utilize to help keep this campaign going:</p>
<ul style="margin-left: 72pt">
<li>Intranet/Internet – Leverage your collaboration or internal sites. Put up a weekly/daily security highlight. Link to various internet resources. Set up Security FAQ. These are all great tools to help keep that awareness high.</li>
</ul>
<ul style="margin-left: 72pt">
<li>Newsletters – Does your company have a newsletter? Leverage a column in that newsletter? If not, create your own quarterly security newsletter. What are the best topics…use topics that will help educate your employees on how to secure themselves AT HOME? At Home? Yes, at home. The more aware they are on security and privacy issues with their home computers, the more aware they are of the risks to your company and your customer&#8217;s private data.</li>
</ul>
<p style="text-align: center"><img class="aligncenter" src="http://eslpod.com/eslpod_blog/wp-content/uploads/2008/02/emergency-1.jpg" alt="Emergency" width="305" height="203" /></p>
<ul style="margin-left: 72pt">
<li>Emails – Leverage periodic emails for emergencies patches/releases. This not only affects your corporate environment, but again, it helps to educate home users. An ever increasing amount of home computers are being used to connect to corporate environments using VPN&#8217;s. Keeping your employees home computers secure is also important.</li>
</ul>
<ul style="margin-left: 72pt">
<li>Learning Management Systems &#8211; Does your company utilize learning management tools and training tools. Great security content works very well with many corporate LMS systems. Many larger corporations have a training department that will help you develop content.</li>
</ul>
<p>A good training program can really increase a company&#8217;s security posture at a fraction of the cost of technology. Leverage these tools in YOUR Company to make a lasting effect.</p>



Share and Enjoy:


	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F10%2Fcheapest-easiest-effective-security-2%2F&amp;title=Cheapest%2C%20Easiest%20and%20Most%20Effective%20Security%20-%20Security%20Awareness%20Training&amp;bodytext=In%20my%20career%20I%20have%20been%20asked%20hundreds%20of%20times%20what%20single%20item%20is%20the%20holy%20grail%20of%20security.%C2%A0%20Is%20it%20a%20firewall%3F%C2%A0%20Is%20it%20an%20Intrusion%20Prevention%20System%20%28IPS%29%3F%C2%A0%20Perhaps%20it%20is%20a%20Single%20Sign-On%20Tool%20%28SSO%29%3F%C2%A0%20No%2C%20contrary%20to%20what%20most%20vendors%20say%2C%20t" title="Digg"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F10%2Fcheapest-easiest-effective-security-2%2F&amp;title=Cheapest%2C%20Easiest%20and%20Most%20Effective%20Security%20-%20Security%20Awareness%20Training&amp;notes=In%20my%20career%20I%20have%20been%20asked%20hundreds%20of%20times%20what%20single%20item%20is%20the%20holy%20grail%20of%20security.%C2%A0%20Is%20it%20a%20firewall%3F%C2%A0%20Is%20it%20an%20Intrusion%20Prevention%20System%20%28IPS%29%3F%C2%A0%20Perhaps%20it%20is%20a%20Single%20Sign-On%20Tool%20%28SSO%29%3F%C2%A0%20No%2C%20contrary%20to%20what%20most%20vendors%20say%2C%20t" title="del.icio.us"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F10%2Fcheapest-easiest-effective-security-2%2F&amp;t=Cheapest%2C%20Easiest%20and%20Most%20Effective%20Security%20-%20Security%20Awareness%20Training" title="Facebook"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F10%2Fcheapest-easiest-effective-security-2%2F&amp;title=Cheapest%2C%20Easiest%20and%20Most%20Effective%20Security%20-%20Security%20Awareness%20Training" title="Mixx"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F10%2Fcheapest-easiest-effective-security-2%2F&amp;title=Cheapest%2C%20Easiest%20and%20Most%20Effective%20Security%20-%20Security%20Awareness%20Training&amp;annotation=In%20my%20career%20I%20have%20been%20asked%20hundreds%20of%20times%20what%20single%20item%20is%20the%20holy%20grail%20of%20security.%C2%A0%20Is%20it%20a%20firewall%3F%C2%A0%20Is%20it%20an%20Intrusion%20Prevention%20System%20%28IPS%29%3F%C2%A0%20Perhaps%20it%20is%20a%20Single%20Sign-On%20Tool%20%28SSO%29%3F%C2%A0%20No%2C%20contrary%20to%20what%20most%20vendors%20say%2C%20t" title="Google Bookmarks"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F10%2Fcheapest-easiest-effective-security-2%2F&amp;title=Cheapest%2C%20Easiest%20and%20Most%20Effective%20Security%20-%20Security%20Awareness%20Training" title="Live"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F10%2Fcheapest-easiest-effective-security-2%2F&amp;t=Cheapest%2C%20Easiest%20and%20Most%20Effective%20Security%20-%20Security%20Awareness%20Training" title="MySpace"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://ping.fm/ref/?link=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F10%2Fcheapest-easiest-effective-security-2%2F&amp;title=Cheapest%2C%20Easiest%20and%20Most%20Effective%20Security%20-%20Security%20Awareness%20Training&amp;body=In%20my%20career%20I%20have%20been%20asked%20hundreds%20of%20times%20what%20single%20item%20is%20the%20holy%20grail%20of%20security.%C2%A0%20Is%20it%20a%20firewall%3F%C2%A0%20Is%20it%20an%20Intrusion%20Prevention%20System%20%28IPS%29%3F%C2%A0%20Perhaps%20it%20is%20a%20Single%20Sign-On%20Tool%20%28SSO%29%3F%C2%A0%20No%2C%20contrary%20to%20what%20most%20vendors%20say%2C%20t" title="Ping.fm"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F10%2Fcheapest-easiest-effective-security-2%2F&amp;title=Cheapest%2C%20Easiest%20and%20Most%20Effective%20Security%20-%20Security%20Awareness%20Training" title="StumbleUpon"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="mailto:?subject=Cheapest%2C%20Easiest%20and%20Most%20Effective%20Security%20-%20Security%20Awareness%20Training&amp;body=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F10%2Fcheapest-easiest-effective-security-2%2F" title="email"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F10%2Fcheapest-easiest-effective-security-2%2F" title="Technorati"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F10%2Fcheapest-easiest-effective-security-2%2F&amp;t=Cheapest%2C%20Easiest%20and%20Most%20Effective%20Security%20-%20Security%20Awareness%20Training&amp;s=In%20my%20career%20I%20have%20been%20asked%20hundreds%20of%20times%20what%20single%20item%20is%20the%20holy%20grail%20of%20security.%C2%A0%20Is%20it%20a%20firewall%3F%C2%A0%20Is%20it%20an%20Intrusion%20Prevention%20System%20%28IPS%29%3F%C2%A0%20Perhaps%20it%20is%20a%20Single%20Sign-On%20Tool%20%28SSO%29%3F%C2%A0%20No%2C%20contrary%20to%20what%20most%20vendors%20say%2C%20t" title="Tumblr"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://cgi.fark.com/cgi/fark/farkit.pl?h=Cheapest%2C%20Easiest%20and%20Most%20Effective%20Security%20-%20Security%20Awareness%20Training&amp;u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F10%2Fcheapest-easiest-effective-security-2%2F" title="Fark"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/fark.png" title="Fark" alt="Fark" class="sociable-hovers" /></a>


<br/><br/> <a href="http://www.blogtrafficexchange.com/related-posts"><strong>Related Posts</strong></a> <ul>  <li> <a onClick="window.location='http://bte.tc/fjQ'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/16/security-analytics/">Using Analytics to Measure InfoSec Success</a> <small>Introduction As today's companies become leaner and meaner, I see the use of performance metrics...</small> </li> <li> <a onClick="window.location='http://bte.tc/6pJ'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/09/security-posture-assessment/">Security Posture Assessment - Key to a successful security program</a> <small>What is a Security Posture Assessment anyway? To put it simply, a Security Posture Assessment...</small> </li> <li> <a onClick="window.location='http://bte.tc/csR'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/11/flight1549-security-incident/">Flight 1549: A Blueprint for handling Security Incidents</a> <small>I was watching the 60 Minutes interview with Captain Sullenberger and his flight crew on...</small> </li> </ul> <a STYLE="border:none;text-decoration:none;outline:none;" href="http://www.blogtrafficexchange.com"><img border="0" alt="Blog Traffic Exchange" src="http://dmsconsultingllc.com/wp-content/plugins/related-sites/24x24.png"></a> <a href="http://www.blogtrafficexchange.com/related-websites"><strong>Related Websites</strong></a> <ul>  <li> <a onClick="window.location='http://bte.tc/akZN'; return false;" href="http://sosrooflinesystems.co.uk/blog/2161/microsoft-mcsa-mcse-training-providers-insights/">Microsoft MCSA-MCSE Computer Training Examined</a> </li> <li> <a onClick="window.location='http://bte.tc/dXW'; return false;" href="http://www.thegoodhuman.com/2006/08/04/giving-incentives-to-employeesits-not/">Giving incentives to employees..it's not just the salary!</a> </li> <li> <a onClick="window.location='http://bte.tc/ajNK'; return false;" href="http://alliantdatatel.com/2010/01/14/home-telephone-technology.html">Home Telephone Technology</a> </li> </ul>]]></content:encoded>
			<wfw:commentRss>http://dmsconsultingllc.com/blog/2009/02/10/cheapest-easiest-effective-security-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Internet Evolution &#8211; Internet Evolution&#8217;s Virtualization Security Tutorial</title>
		<link>http://dmsconsultingllc.com/blog/2009/02/09/internet-evolution-internet-evolutions-virtualization-security-tutorial/</link>
		<comments>http://dmsconsultingllc.com/blog/2009/02/09/internet-evolution-internet-evolutions-virtualization-security-tutorial/#comments</comments>
		<pubDate>Tue, 10 Feb 2009 01:44:26 +0000</pubDate>
		<dc:creator>Mark Davidson</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Virtualization security]]></category>

		<guid isPermaLink="false">http://www.dmsconsultingllc.com/?p=150</guid>
		<description><![CDATA[I will do a post in more detail on Virtualization Security later.  In the mean time, please take a look at my good friend Josh Corman at IBM/ISS  and his take on Virtualization Security.

Internet Evolution &#8211; Internet Evolution&#8217;s Virtualization Security Tutorial.



Share and Enjoy:


	
	
	
	
	
	
	
	
	
	
	
	
	


 Related Posts    Using Analytics to Measure InfoSec Success Introduction [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>I will do a post in more detail on Virtualization Security later.  In the mean time, please take a look at my good friend <a target="_blank" title="Josh Corman Linked In" href="http://www.linkedin.com/pub/2/840/5b0" target="_blank">Josh Corman</a> at IBM/ISS  and his take on Virtualization Security.</p>
<p><img src="http://media1.podtech.net/media/2008/06/PID_013624/Podtech_intro_virtualization_vmware.jpg" alt="VMWare Virtualization" width="106" height="59" /></p>
<p><a target="_blank" href="http://www.internetevolution.com/tutorial_virtualizationsecurity.asp">Internet Evolution &#8211; Internet Evolution&#8217;s Virtualization Security Tutorial</a>.</p>



Share and Enjoy:


	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Finternet-evolution-internet-evolutions-virtualization-security-tutorial%2F&amp;title=Internet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualization%20Security%20Tutorial&amp;bodytext=I%20will%20do%20a%20post%20in%20more%20detail%20on%20Virtualization%20Security%20later.%C2%A0%20In%20the%20mean%20time%2C%20please%20take%20a%20look%20at%20my%20good%20friend%20Josh%20Corman%20at%20IBM%2FISS%C2%A0%20and%20his%20take%20on%20Virtualization%20Security.%0D%0A%0D%0A%0D%0A%0D%0AInternet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualizati" title="Digg"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Finternet-evolution-internet-evolutions-virtualization-security-tutorial%2F&amp;title=Internet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualization%20Security%20Tutorial&amp;notes=I%20will%20do%20a%20post%20in%20more%20detail%20on%20Virtualization%20Security%20later.%C2%A0%20In%20the%20mean%20time%2C%20please%20take%20a%20look%20at%20my%20good%20friend%20Josh%20Corman%20at%20IBM%2FISS%C2%A0%20and%20his%20take%20on%20Virtualization%20Security.%0D%0A%0D%0A%0D%0A%0D%0AInternet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualizati" title="del.icio.us"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Finternet-evolution-internet-evolutions-virtualization-security-tutorial%2F&amp;t=Internet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualization%20Security%20Tutorial" title="Facebook"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Finternet-evolution-internet-evolutions-virtualization-security-tutorial%2F&amp;title=Internet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualization%20Security%20Tutorial" title="Mixx"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Finternet-evolution-internet-evolutions-virtualization-security-tutorial%2F&amp;title=Internet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualization%20Security%20Tutorial&amp;annotation=I%20will%20do%20a%20post%20in%20more%20detail%20on%20Virtualization%20Security%20later.%C2%A0%20In%20the%20mean%20time%2C%20please%20take%20a%20look%20at%20my%20good%20friend%20Josh%20Corman%20at%20IBM%2FISS%C2%A0%20and%20his%20take%20on%20Virtualization%20Security.%0D%0A%0D%0A%0D%0A%0D%0AInternet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualizati" title="Google Bookmarks"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Finternet-evolution-internet-evolutions-virtualization-security-tutorial%2F&amp;title=Internet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualization%20Security%20Tutorial" title="Live"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Finternet-evolution-internet-evolutions-virtualization-security-tutorial%2F&amp;t=Internet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualization%20Security%20Tutorial" title="MySpace"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://ping.fm/ref/?link=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Finternet-evolution-internet-evolutions-virtualization-security-tutorial%2F&amp;title=Internet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualization%20Security%20Tutorial&amp;body=I%20will%20do%20a%20post%20in%20more%20detail%20on%20Virtualization%20Security%20later.%C2%A0%20In%20the%20mean%20time%2C%20please%20take%20a%20look%20at%20my%20good%20friend%20Josh%20Corman%20at%20IBM%2FISS%C2%A0%20and%20his%20take%20on%20Virtualization%20Security.%0D%0A%0D%0A%0D%0A%0D%0AInternet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualizati" title="Ping.fm"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Finternet-evolution-internet-evolutions-virtualization-security-tutorial%2F&amp;title=Internet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualization%20Security%20Tutorial" title="StumbleUpon"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="mailto:?subject=Internet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualization%20Security%20Tutorial&amp;body=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Finternet-evolution-internet-evolutions-virtualization-security-tutorial%2F" title="email"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Finternet-evolution-internet-evolutions-virtualization-security-tutorial%2F" title="Technorati"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Finternet-evolution-internet-evolutions-virtualization-security-tutorial%2F&amp;t=Internet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualization%20Security%20Tutorial&amp;s=I%20will%20do%20a%20post%20in%20more%20detail%20on%20Virtualization%20Security%20later.%C2%A0%20In%20the%20mean%20time%2C%20please%20take%20a%20look%20at%20my%20good%20friend%20Josh%20Corman%20at%20IBM%2FISS%C2%A0%20and%20his%20take%20on%20Virtualization%20Security.%0D%0A%0D%0A%0D%0A%0D%0AInternet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualizati" title="Tumblr"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://cgi.fark.com/cgi/fark/farkit.pl?h=Internet%20Evolution%20-%20Internet%20Evolution%27s%20Virtualization%20Security%20Tutorial&amp;u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Finternet-evolution-internet-evolutions-virtualization-security-tutorial%2F" title="Fark"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/fark.png" title="Fark" alt="Fark" class="sociable-hovers" /></a>


<br/><br/> <a href="http://www.blogtrafficexchange.com/related-posts"><strong>Related Posts</strong></a> <ul>  <li> <a onClick="window.location='http://bte.tc/csR'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/11/flight1549-security-incident/">Flight 1549: A Blueprint for handling Security Incidents</a> <small>I was watching the 60 Minutes interview with Captain Sullenberger and his flight crew on...</small> </li> <li> <a onClick="window.location='http://bte.tc/fjQ'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/16/security-analytics/">Using Analytics to Measure InfoSec Success</a> <small>Introduction As today's companies become leaner and meaner, I see the use of performance metrics...</small> </li> <li> <a onClick="window.location='http://bte.tc/CAe'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/10/cheapest-easiest-effective-security-2/">Cheapest, Easiest and Most Effective Security - Security Awareness Training</a> <small>In my career I have been asked hundreds of times what single item is the...</small> </li> </ul> <a STYLE="border:none;text-decoration:none;outline:none;" href="http://www.blogtrafficexchange.com"><img border="0" alt="Blog Traffic Exchange" src="http://dmsconsultingllc.com/wp-content/plugins/related-sites/24x24.png"></a> <a href="http://www.blogtrafficexchange.com/related-websites"><strong>Related Websites</strong></a> <ul>  <li> <a onClick="window.location='http://bte.tc/4Xk'; return false;" href="http://alliantdatatel.com/2009/11/26/twelve-key-questions-you-need-to-ask-about-your-computer-security-for-your-home-or-business.html">Twelve Key Questions You Need to Ask About Your Computer Security for Your Home or Business</a> </li> <li> <a onClick="window.location='http://bte.tc/eaa'; return false;" href="http://www.blogtrafficexchange.com/why-blog-ill-tell-you-why/">Why Blog? I'll Tell You Why!</a> </li> <li> <a onClick="window.location='http://bte.tc/Fhc'; return false;" href="http://www.onlinesecurityauthority.com/home-pc-security/cybercrime-how-online-crooks-put-us-all-at-risk/">Cybercrime: How online crooks put us all at risk</a> </li> </ul>]]></content:encoded>
			<wfw:commentRss>http://dmsconsultingllc.com/blog/2009/02/09/internet-evolution-internet-evolutions-virtualization-security-tutorial/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Posture Assessment &#8211; Key to a successful security program</title>
		<link>http://dmsconsultingllc.com/blog/2009/02/09/security-posture-assessment/</link>
		<comments>http://dmsconsultingllc.com/blog/2009/02/09/security-posture-assessment/#comments</comments>
		<pubDate>Mon, 09 Feb 2009 20:05:19 +0000</pubDate>
		<dc:creator>Mark Davidson</dc:creator>
				<category><![CDATA[Security Posture Assessment]]></category>
		<category><![CDATA[Access Controls]]></category>
		<category><![CDATA[Audit and Monitoring Controls]]></category>
		<category><![CDATA[Cryptography Controls]]></category>
		<category><![CDATA[GLBA and PCI Compliance]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[SOX]]></category>
		<category><![CDATA[System Integrity Controls]]></category>
		<category><![CDATA[Vulnerability Assessment]]></category>

		<guid isPermaLink="false">http://www.dmsconsultingllc.com/?p=114</guid>
		<description><![CDATA[What is a Security Posture Assessment anyway?

To put it simply, a Security Posture Assessment (SPA) is a tool that contains over 850 measurable independent data points, used to objectively measure the current state of your company&#8217;s security risks.
Why use DMS Consulting to handle your SPA?

We&#8217;ve developed a unique Security Posture Assessment that measures where your [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><strong>What is a Security Posture Assessment anyway?<br />
</strong></p>
<p>To put it simply, a Security Posture Assessment (SPA) is a tool that contains over 850 measurable independent data points, used to objectively measure the current state of your company&#8217;s security risks.</p>
<p><strong>Why use DMS Consulting to handle your SPA?<br />
</strong></p>
<p>We&#8217;ve developed a unique Security Posture Assessment that measures where your company&#8217;s security risks are, what you need to do to address those risks, and the costs associated with achieving the necessary results and presents your data in an easy to read scorecard format.  Use this tool to plan and measure for your company&#8217;s compliance needs such as HIPAA, SOX, GLBA or PCI Compliance.</p>
<p><strong>The SPA measures the following areas of risk:<br />
</strong></p>
<ul>
<li>Access Controls</li>
<li>System Integrity Controls</li>
<li>Cryptography Controls</li>
<li>Audit and Monitoring Controls</li>
<li>Configuration Management and Assurance</li>
<li>Security Processes and Policies</li>
<li>Application Security Standards and Policies</li>
<li>Privacy Policy and Controls</li>
<li>Emerging Risks</li>
</ul>
<p>For more information, feel free to review the Slideshow below.</p>
<p><span style="font-size: x-small">Uploaded on authorSTREAM by <a target="_blank" title="More presentations by mdavidson58 on authorSTREAM" href="http://www.authorstream.com/User-Presentations/mdavidson58/" target="_blank">mdavidson58</a></span></p>



Share and Enjoy:


	<a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Fsecurity-posture-assessment%2F&amp;title=Security%20Posture%20Assessment%20-%20Key%20to%20a%20successful%20security%20program&amp;bodytext=What%20is%20a%20Security%20Posture%20Assessment%20anyway%3F%0D%0A%0D%0A%0D%0ATo%20put%20it%20simply%2C%20a%20Security%20Posture%20Assessment%20%28SPA%29%20is%20a%20tool%20that%20contains%20over%20850%20measurable%20independent%20data%20points%2C%20used%20to%20objectively%20measure%20the%20current%20state%20of%20your%20company%27s%20security%20ris" title="Digg"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Fsecurity-posture-assessment%2F&amp;title=Security%20Posture%20Assessment%20-%20Key%20to%20a%20successful%20security%20program&amp;notes=What%20is%20a%20Security%20Posture%20Assessment%20anyway%3F%0D%0A%0D%0A%0D%0ATo%20put%20it%20simply%2C%20a%20Security%20Posture%20Assessment%20%28SPA%29%20is%20a%20tool%20that%20contains%20over%20850%20measurable%20independent%20data%20points%2C%20used%20to%20objectively%20measure%20the%20current%20state%20of%20your%20company%27s%20security%20ris" title="del.icio.us"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Fsecurity-posture-assessment%2F&amp;t=Security%20Posture%20Assessment%20-%20Key%20to%20a%20successful%20security%20program" title="Facebook"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Fsecurity-posture-assessment%2F&amp;title=Security%20Posture%20Assessment%20-%20Key%20to%20a%20successful%20security%20program" title="Mixx"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Fsecurity-posture-assessment%2F&amp;title=Security%20Posture%20Assessment%20-%20Key%20to%20a%20successful%20security%20program&amp;annotation=What%20is%20a%20Security%20Posture%20Assessment%20anyway%3F%0D%0A%0D%0A%0D%0ATo%20put%20it%20simply%2C%20a%20Security%20Posture%20Assessment%20%28SPA%29%20is%20a%20tool%20that%20contains%20over%20850%20measurable%20independent%20data%20points%2C%20used%20to%20objectively%20measure%20the%20current%20state%20of%20your%20company%27s%20security%20ris" title="Google Bookmarks"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Fsecurity-posture-assessment%2F&amp;title=Security%20Posture%20Assessment%20-%20Key%20to%20a%20successful%20security%20program" title="Live"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Fsecurity-posture-assessment%2F&amp;t=Security%20Posture%20Assessment%20-%20Key%20to%20a%20successful%20security%20program" title="MySpace"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/myspace.png" title="MySpace" alt="MySpace" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://ping.fm/ref/?link=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Fsecurity-posture-assessment%2F&amp;title=Security%20Posture%20Assessment%20-%20Key%20to%20a%20successful%20security%20program&amp;body=What%20is%20a%20Security%20Posture%20Assessment%20anyway%3F%0D%0A%0D%0A%0D%0ATo%20put%20it%20simply%2C%20a%20Security%20Posture%20Assessment%20%28SPA%29%20is%20a%20tool%20that%20contains%20over%20850%20measurable%20independent%20data%20points%2C%20used%20to%20objectively%20measure%20the%20current%20state%20of%20your%20company%27s%20security%20ris" title="Ping.fm"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/ping.png" title="Ping.fm" alt="Ping.fm" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Fsecurity-posture-assessment%2F&amp;title=Security%20Posture%20Assessment%20-%20Key%20to%20a%20successful%20security%20program" title="StumbleUpon"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="mailto:?subject=Security%20Posture%20Assessment%20-%20Key%20to%20a%20successful%20security%20program&amp;body=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Fsecurity-posture-assessment%2F" title="email"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Fsecurity-posture-assessment%2F" title="Technorati"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Fsecurity-posture-assessment%2F&amp;t=Security%20Posture%20Assessment%20-%20Key%20to%20a%20successful%20security%20program&amp;s=What%20is%20a%20Security%20Posture%20Assessment%20anyway%3F%0D%0A%0D%0A%0D%0ATo%20put%20it%20simply%2C%20a%20Security%20Posture%20Assessment%20%28SPA%29%20is%20a%20tool%20that%20contains%20over%20850%20measurable%20independent%20data%20points%2C%20used%20to%20objectively%20measure%20the%20current%20state%20of%20your%20company%27s%20security%20ris" title="Tumblr"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a>
	<a rel="nofollow"  target="_blank" href="http://cgi.fark.com/cgi/fark/farkit.pl?h=Security%20Posture%20Assessment%20-%20Key%20to%20a%20successful%20security%20program&amp;u=http%3A%2F%2Fdmsconsultingllc.com%2Fblog%2F2009%2F02%2F09%2Fsecurity-posture-assessment%2F" title="Fark"><img src="http://dmsconsultingllc.com/wp-content/plugins/sociable/images/fark.png" title="Fark" alt="Fark" class="sociable-hovers" /></a>


<br/><br/> <a href="http://www.blogtrafficexchange.com/related-posts"><strong>Related Posts</strong></a> <ul>  <li> <a onClick="window.location='http://bte.tc/avjZ'; return false;" href="http://dmsconsultingllc.com/blog/2010/02/02/the-risks-of-sharing/">The risks of SHARING! </a> <small>As you've probably heard or read in the news, there was a recent leak of...</small> </li> <li> <a onClick="window.location='http://bte.tc/fjQ'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/16/security-analytics/">Using Analytics to Measure InfoSec Success</a> <small>Introduction As today's companies become leaner and meaner, I see the use of performance metrics...</small> </li> <li> <a onClick="window.location='http://bte.tc/csR'; return false;" href="http://dmsconsultingllc.com/blog/2009/02/11/flight1549-security-incident/">Flight 1549: A Blueprint for handling Security Incidents</a> <small>I was watching the 60 Minutes interview with Captain Sullenberger and his flight crew on...</small> </li> </ul> <a STYLE="border:none;text-decoration:none;outline:none;" href="http://www.blogtrafficexchange.com"><img border="0" alt="Blog Traffic Exchange" src="http://dmsconsultingllc.com/wp-content/plugins/related-sites/24x24.png"></a> <a href="http://www.blogtrafficexchange.com/related-websites"><strong>Related Websites</strong></a> <ul>  <li> <a onClick="window.location='http://bte.tc/TVQ'; return false;" href="http://alliantdatatel.com/2009/12/12/how-to-encrypt-your-voip-network-for-a-secure-connection.html">How to Encrypt Your VoIP Network For a Secure Connection</a> </li> <li> <a onClick="window.location='http://bte.tc/-2E'; return false;" href="http://alliantdatatel.com/2009/12/27/the-3-ws-wares-in-security-management.html">The 3 W's (Wares) in Security Management</a> </li> <li> <a onClick="window.location='http://bte.tc/Z9x'; return false;" href="http://blog.7touchgroup.com/2009/12/apple%e2%80%99s-new-tablet-to-be-baptized-islate-let%e2%80%99s-dig-a-little-deeper/">Apple’s New Tablet To Be Baptized iSlate? Let’s Dig A Little Deeper</a> </li> </ul>]]></content:encoded>
			<wfw:commentRss>http://dmsconsultingllc.com/blog/2009/02/09/security-posture-assessment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
