Showing posts with label reading. Show all posts
Showing posts with label reading. Show all posts

Tuesday, July 17, 2012

Book Review: “UP and to the RIGHT: Strategy and Tactics of Analyst Influence: A complete guide to analyst influence” by Richard Stiennon

This is not a book for everybody (and your grandmother probably does not need to read it; neither does an average IT professional). However, I think that this book is pure gold for those tasked with interacting with analyst firms.

I am an analyst, and I wish every vendor client read this book and followed some of the advice given there. It would reduce pain on both sides of the conversation, as well as make the interactions more valuable for – again! - both sides.

Obviously, this is not a book to guarantee your IT product a favorable placement in analyst research. It is also not a book on how to bamboozle the analysts, despite its focus on analyst influence. However, it is definitely a book to make sure that well deserving products, developed and marketed by good teams of people, don't get sidelined.

Some of the specifics that I liked include the influence pyramid concept, social media techniques, a careful approach to managing corporate Wikipedia entries, specific approaches to various analyst activities (such as calls, reports, advisory days and conferences), etc. My favorite sections (both fun to read as well as insightful!) are the one on “guerrilla tactics” and the obligatory “what not to do” chapter (the latter has a few sad case studies of IT vendors who screwed themselves up). Another great chapter covers the role of a vendor sales team in both helping the interaction with the analyst firm and avoiding some embarrassing mistakes.

In fact, this book makes me proud to be an analyst. Then again, maybe it is my ego talking as the book seems to project an impression that “an analyst is the most important person in the world“, at least as far as IT vendors are concerned.

Finally, if you are a IT vendor marketer, remember: when you say “holistic," some analysts think “imaginary.” Richard suggests to scrub your presentations of silly meaningless words like “synergy” and “holistic.”

Monday, March 28, 2011

My “Recent” Security Writing and Speaking

Now that I flooded with work (with more on the way), I am eternally procrastinating  on my “Fun Security Reading” blog posts. So, let me at least try to blog about what I was WRITING if I don’t have time to blog about what I was reading (Google Reader shared item feed). The list is loosely sorted by time:

My writing:

  1. HIPAA Logging HOWTO, Part 1
  2. “HIPAA Logging HOWTO, Part 2”
  3. PCI Security: Q&A with Anton Chuvakin, PCI Compliance Expert
  4. PCI Security: Q&A with Anton Chuvakin, PCI Compliance Expert, PART 2
  5. “ASSESSMENT SUCCESS: PCI DSS STANDARDS AND SECURE DATA STORAGE
  6. "How to Do Application Logging Right" (with Gunnar Petersen)
  7. FISMA Logging HowTo, Part 1
  8. Logging for FISMA part 2 : Detailed FISMA logging guidance
  9. Log management software can aid data security, boost IT accountability
  10. Log review for incident response, Part 1
  11. A Pragmatic Approach to SIEM: Buy for Compliance, Use for Security
  12. Log review for incident response, Part 2
  13. PCI DSS 2.0 Fun Facts
  14. Logs vs Bots and Malware Today
  15. PCI DSS Today and Tomorrow: Logging is the Key
  16. Logs for Insider Abuse Investigations

Presentations:

  1. Log Standards and Future Trends” (BrightTalk)
  2. What PCI DSS Taught Us About Security” (BrightTalk)
  3. You Got That SIEM. Now What Do You Do?"(BayThreat 2010)
  4. Achieve PCI Compliance and Ensure Security in a Data Deluge” (Focus.com webcast)
  5. Address Network Security & Dramatically Reduce PCI DSS Scope with Gateway Tokenization” (Intel – NRF (!) webcast)
  6. Proactive Compliance for new PCI-DSS 2.0” (SANS webcast)
  7. Using Logs for Breach Investigations and Incident Response” (Brightalk webcast) and presentation
  8. PCI Compliance: Tips, Tricks & Emerging Technologies” (BankInfoSec webcast)
  9. You can always see more on my Slideshare page.

Audio/podcasts/etc:

  1. Cloudchasers podcast “Cloud security and compliance: its all about the logs – May 20, 2010” (mp3)
  2. Cloudchasers podcast “IT Security industry consolidation and the cloud – Sept 16, 2010” (mp3)
  3. Logs, Clouds and Open Source, Oh My!
  4. ETM podcast “Insight into SIEM” (mp3)
  5. McAfee podcast about retail security (mp3)
  6. …and, obviously, our own log podcast LogChat

Miscelaneous:

  1. Scaling the Security Chasm” is not by me, but it is written based on my HITB keynote last year
  2. How to handle PCI DSS requirements for log management in the cloud” is also not by my, but has significant input from me

BTW, if you’d like to see what I’ve been reading, subscribe up for my Google Reader shared item feed and Like feed/Buzz. Or use the widget below:

And, no, Twitter didn’t kill blogging, but it sure looks like Twitter is intent on killing Twitter Smile

P.S. Posted by a scheduler – please don’t laugh, but I am in Siberia now Smile Responses to comments will happen when I am back.

Possibly related posts:

Monday, October 18, 2010

Verizon PCI Report is Out

Taking notes as I am reading Verizon’s awesome “Verizon 2010 Payment Card Industry Compliance Report” [PDF]

“Organizations struggled most with requirements 10 (track and monitor access), 11 (regularly test systems and processes), and 3 (protect stored cardholder data). ” - not surprising, given DAILY log review in 10.6.image

“Overall, organizations that suffered a data breach were 50% less likely to be compliant than a normal population of PCI clients.” – one of THE KEY  findings and a good measure of PCI DSS efficiency. “PCI works” side of an argument gets a powerful weapon!

“All of the top 10 threat actions leading to the compromise of payment card data are well within scope of the PCI DSS.” – not at all surprising to me, but might surprise some of the “attacks are soooooo dynamic” people :-)

“An organization may be able to pass validation in order to “achieve compliance” but then—once the QSA leaves—become lax about maintaining the degree of security the standard is designed to provide over time. As such, the goal of any organization should be to maintain its state of security in adherence with the minimum baseline compliance requirements set by the standard.” – a very useful reminder to more than a few folks who forget that “QSA do not manufacture compliance”

“22% were validated compliant with the PCI DSS at the time of their IROC.” – indeed a point worthy of discussion. 22% found compliant from the 1st shot is pretty darn good, IMHO.

“these organizations had at least some expectation going into the validation process that they would be found compliant and yet over three quarters of them were not” – indeed, compliance is MUCH easier if exists only in your mind :-)

“Most organizations appear overconfident when assessing the state of their security practices.” – Cap’n Obvious calling..calling..calling :-)

“Regular testing (R11) and monitoring (R10) may be the most crucial but underrated and least appreciated aspects of security.” – if a merchant has to work at it throughout the year, as opposed to simply buy – or check! – the box, compliance rates lag.

image 

image

“we have shown that the majority of organizations do not meet their goal of 100% compliance upon initial assessment” – BTW, do we realize that these guys were likely not compliant for most of the time since their last compliant FRoC?

“Organizations tend to struggle in all of these areas, most notably with generating (10.1 and 10.2), protecting (10.5), reviewing (10.6), and, to a lesser extent, archiving (10.7) logs” – well, it is not only the hard stuff that is hard. The easy stuff is hard too…mmmm.

“breach victims are less compliant than a normal population of organizations [..]  these results do suggest that an organization wishing to avoid breaches is better off pursuing PCI DSS than shunning it altogether” – this is [a part of] proof that PCI DSS works to improve security. Nice!

“it cannot be said that the PCI DSS fails to address the most prevalent threats to cardholder data. None of the top threat actions listed above falls outside the scope of its 12 requirements. For most of them, in fact, multiple layers of relevant controls exist across the standard.” – as obvious as it was to me, I suspect some people will be surprised. Threats today’s don’t seem as “dynamic” as some people think…

“the requirements exhibiting the worst assessment scores (10, 11) are also those most broadly applicable to the threat actions shown in Table 4. It should not be terribly surprising, then, that organizations suffering known data breaches were not highly  compliant with the PCI DSS” – oops! Fail to do the right things –> suffer a breach – with or without PCI DSS.

achieving and maintaining PCI Compliance should not be considered an annual project but a daily process – please keep this in mind, darn it. What is so special about this line that we have to repeat it every freaking day … and still have some people act as if it is news to them!!!?

.. next I started quoting from report conclusions and realized I’d be quoting most of their content. So, just read it!

Finally, a good way to think about PCI DSS below (from page 11 of the report):

image

Overall, a SUPERB piece of work (did I mention that I think it is awesome? :-)) and a must-read for any PCI DSS proponent OR skeptic!

Enhanced by Zemanta

Tuesday, June 01, 2010

Monthly Blog Round-Up – May 2010

Blogs are "stateless" and people often only pay attention to what they see today. Thus a lot of useful security reading material gets lost.  These monthly round-ups is my way of reminding people about interesting content. If you are “too busy to read the blogs,” at least read these.

So, here is my next monthly "Security Warrior" blog round-up of top 5 popular posts/topics.

  1. By a HUGE margin again, the #1 post this month is “Simple Log Review Checklist Released!” Grab our log review checklist here, if you have not done so already. It is perfect to hand out to junior sysadmins who are just starting up with logs. Another similar resource is in the works…
  2. Next up are my notes from University PCI DSS workshop where I delivered a keynote: “My Best PCI DSS Presentation EVER!” (the infamous “compliance kitten” quotes comes from here)
  3. Everybody loved my whitepaper on SIEM+ log management, released via the post called “Two New Logging Resources Published.” Check out the paper here (registration with Novell required). Just as a  preview, another big research whitepaper on SIEM is in the works….
  4. A recent post “On Choosing SIEM“ went to the top like lighting last month and stayed there this month. If you are thinking of getting a SIEM or a log management tool, check it out – please also look at related resources there at the end.
  5. Proving that all SIEM/LM vendor product managers read this blog, the post “Log Management / SIEM Users: “Minimalist” vs “Analyst”” is in the Top5 too. It is about two vastly different types of people who buy and [try to] use SIEM and log management tools.
  6. Just for a good measure, the item #6 of my Top 5 :-) is “Compliance Mega-Epiphany!

Also, below I am thanking my top 5 referrers this month (those who are people, not organizations). So, thanks a lot to the following people whose blogs sent the most visitors to my blog:

  1. Walt Conway
  2. Michał Wiczyński
  3. Dancho Danchev
  4. Cédric Blancher
  5. Kevin  Riggins

See you in May ; also see my annual “Top Posts” - 2007, 20082009!

Possibly related posts / past monthly popular blog round-ups:

Monday, May 24, 2010

Fun Reading on Security and Compliance #25

Here is an issue #25 of my “Fun Reading on Security and Compliance,” dated May 24, 2010 (read past ones here). You can judge by its size that my “2blog” folder has been way too full, since I was too busy working on a few fun consulting projects.

Main section: 

  1. Fun piece from my co-author (“PCI Compliance”) Branden: “Compliance, Easier Than Security!
  2. CloudAudit (former A6WG) goes ahead full-steam: “Q&A: CloudAudit targets automated risk assessment, management” (I suspect this is where we’d go for practical guidance in a few years … not to CSA [PDF]) BTW, CSA did release its cloud compliance control matrix  a while ago and it is used by CloudAudit.
  3. I dunno why, but I forgot to highlight Alex’s awesome BSides presentation on…risk management: “Risk Management - Time to blow it up and start over?” (now you know that my 2blog folder has been rotting since March 2010 :-))
  4. Worthwhile posts from Securosis: “Mogull’s Law”, “LHF: Quick Wins with DLP—the Conclusion”, “Announcing NetSec Ops Quant: Network Security Metrics Suck. Let’s Fix Them” , “Help Build the Mother of All Data Security Surveys”  and their discoveries regarding PCI Level 4 merchants "Level 4 Apathy"
  5. In addition, Securosis folks started a series on SIEM (a must):  "Understanding and Selecting SIEM/Log Management: Introduction"  "Understanding and Selecting SIEM/LM: Use Cases, Part 1", "Understanding and Selecting SIEM/LM: Use Cases, Part 2", "Understanding and Selecting SIEM/LM: Business Justification"
  6. Notable pieces from FUDSec: ”The Broken Windows Economics of IT Security” , “SCSOVLF (aka, the Shpantzer Coma Scale Of Vendor Lameness and FUD)” (quote: “If, when asked, "How do you approach the APT issue, exactly?" they respond "That's on our roadmap"”)
  7. Fun posts from Richard: “Time and Cost to Defend the Town”, “Forget ROI and Risk. Consider Competitive Advantage” (a fresh batch of ROI jokes inside)
  8. Famous Forrester “too much compliance” study (notes, full PDF) , a must read!
  9. Gunnar’s “10 Quick, Dirty and Cheap Things to Improve Enterprise Security” that I should have highlighted earlier (and of course: “8. Improve your Audit Logging”…)
  10. Completely awesome presentation on REAL cloud security from Alex Stamos @ SourceBoston (was one of my favorite at Source)
  11. Interesting report on web ownage from Dasient (disclosure: I am an advisor). Quote: “We found that 97% of Fortune 500 web sites are at a high risk of getting infected with malware due to external partners. In fact, Fortune 500 web sites have such a high risk because 69% of them use external Javascript to render portions of their sites and 64% of them are running outdated web applications.” Niiice.
  12. InfoSecMentors (site, blog) launched off the ideas from the SourceBoston mentorship panel.
  13. The Security FAIL Chronicles launched (site); “the purpose of this site is to document security failures in various technologies.” Note to self: I need to get my KilledBySoftware site finally up… :-)
  14. SANS produces a mid-year list of security predictions for 2011-2012. Why now? I don’t know, but the predictions are always fun.
  15. How to Kick Ass in Information Security — Hoff’s Spritually-Enlightened Top Ten Guide to Health, Wealth and Happiness”...awesomely hoffistic piece.
  16. Please don’t laugh but do check the calendar (the year part): people…still…ask…questions…what…ports…to block…on…a firewall! On a list where Marcus Ranum lurks. If this is not the best way to have you balls flattened, I don’t know what is.
  17. Upon leaving security (!), Mark Curphey reposted all his Security Bullshit cartoons here.
  18. A great, though-provoking piece from Michal Zalewski "Security engineering: broken promises"
Logging, log management section and SIEM section:
  1. Using OSSEC for the forensic analysis of log files” – OSSEC is mostly for real-time log analysis, but now you can also analyze stored logs
  2. Useful list of windows event IDS that record application install/updates, such as “1005 Install operation initiated a reboot” and all others.
  3. Gorka Sadowski has a useful bit on various logs here (especially read the part about anti-virus logs)
  4. Rocky has a series of fun posts on SIEM that you need to read: "SIEM Evolution: Chapter 1" , "2010 Gartner MQ for SIEM" (with a lot of fun MQ analysis), "Tetragon of Prestidigitation".
  5. Centralized vs. Distributed Syslog System Architectures” about exactly what it says :-)
  6. This fits under both PCI DSS and logging so, “log data revisited” is worth a read (it mentions 70TB of log data which is always juicy): “The second thing we hear most often is, “We only look at log data when we have a problem.” Typically what this means is that the problem has now grown to the size of a whale and has become noticeable by end users who are complaining.”
  7. Building a logging VM – syslog-ng and Splunk
  8. A really old log trick that people need to be reminded of: “How to Protect Your Logs from Tampering
  9. SANS ISC on application logs explains deep suckage of [most] application logs: “dear developer, please spare us the debug log that got swiftly re-branded into "audit log" five minutes before project completion.”
  10. My “PCI Logging HOWTO, Part 2” (part 1). While we are on this subject, here is a fairly useful list on what to log for PCI DSS on Windows.
  11. Another “you have no logs – when you REALLY need them” horror story: “ERP billing systems that did zero audits (total breach of SarOx) due to performance constraints and lack of vendor know how on what to implement let alone how.
  12. I've long whined about firewall "connection allowed" logs (example), LogLogic folks  reminder everybody about their value again: "Do your "Traffic Allowed" logs sing?"
  13. Another bit on SIEM "SIEM: The good and the bad - Part I" with SIEM basics. Key quote "I believe SIEM's will be as common as firewalls within 5 years. " (let’s see whether it will happen this way!)
  14. Well-spelled out example of what one organization are looking for in a SIEM/log management tool: "Open Source centralized log management/SIEM solutions"
  15. Bloor folks also unleashed a salvo in a direction of SIEM - their angle is SIEM as information management solution: "The problem with SIEM 1" and "The problem with SIEM 2" Quote: "…  analytic warehouses are currently capable of ingesting data much faster than any of the SIEM products. In our survey the highest load rates we found were at around 4TB per day: analytic warehouses can often load that much per hour!"
  16. SIEM implementation lessons video.

PCI DSS section:

  1. “PCI And Cloud Computing: It’s All About Scope” …PCI DSS + clouds = what else do you need? :-)
  2. Fun interview with me on PCI DSS. Quote: “Q: Where do you see the PCI compliance industry in five years? A: To be honest, I don’t want to see “PCI compliance industry” at all: not now, not in a year, not to five years. […]
  3. Undergoing a PCI Assessment – How to Prepare” and “PCI Onsite Assessment - Part 1” (also “Part Two - Preparation for an onsite assessment and what to do first!” and all the way to “Part Five - Selecting a QSA!”)
  4. Please take a good swig from the bottle of no less than 60 proof alcohol before reading this. EXTREME RAGE ALERT! :-)
  5. A really good Forbes piece on PCI: “The easiest way for small businesses to address the information security requirements imposed by credit card companies is the wrong way. I'm talking about lying and praying.” and a quote from me:  “Businesses that endanger their customers really do deserve to die.” 

Enjoy!

Possibly related posts:

Reblog this post [with Zemanta]

Monday, May 03, 2010

Monthly Blog Round-Up – April 2010

Blogs are a "stateless" media and people often only pay attention to what they see today. Thus a lot of useful security reading material gets lost.  These monthly round-ups is my way of reminding people about interesting content. If you are “too busy to read the blogs,” at least read these.

So, here is my next monthly "Security Warrior" blog round-up of top 5 popular posts/topics.

  1. By a HUGE margin, the #1 post this month is again “Simple Log Review Checklist Released!” Grab our log review checklist here, if you have not done so already. It is perfect to hand out to junior sysadmins who are just starting up with logs.
  2. Next is the post announcing the release of SANS Log Management Survey 2010 (“SANS Log Management Survey Is Out”), some highlights – and some surprises! - from the survey are in the post.
  3. The post announcing the release of my detailed whitepaper on SIEM and Log Management is also in Top5 (“Two New Logging Resources Published”); also see other relates content such as “One More Time on SIEM vs Log Management.” To get the paper, you’d need to fill the form at Novell site, but I assure you – it is totally worth it :-)
  4. A recent post “On Choosing SIEM“, only published a few days ago, went to the top like lighting. If you are thinking of getting a SIEM or a log management tool, check it out.
  5. The Myth of SIEM as “An Analyst-in-the-box” or How NOT to Pick a SIEM-II?“ and its predecessor ““I Want to Buy Correlation” or How NOT to Pick a SIEM?” hold the next position this month. They present some sadly popular misconceptions about acquiring and implementing SIEM and log management tools.
  6. My log management maturity curve post (“Logging, Log Management and Log Review Maturity”) continues to sit in Top 5 (as #6 :-)). Is it awesome or what? :-)

BTW, notice something funny about the Top 5 this month? Look, Ma, no PCI DSS! :-)

Also, below I am thanking my top 5 referrers this month (those who are people, not organizations). So, thanks a lot to the following people whose blogs sent the most visitors to my blog:

  1. Cédric Blancher
  2. Kevin  Riggins
  3. Michał Wiczyński
  4. Walt Conway
  5. Guerilla CISO

See you in May ; also see my annual “Top Posts” - 2007, 20082009!

Possibly related posts / past monthly popular blog round-ups:

Thursday, April 01, 2010

Monthly Blog Round-Up – March 2010

As we all know, blogs are a bit "stateless" and a lot of useful security reading material gets lost since people often only pay attention to what they see today. These monthly round-ups is my way to remind people of useful content from the past month! If you are “too busy to read the blogs,” at least read these.

So, here is my next monthly "Security Warrior" blog round-up of top 5 popular posts/topics.

  1. By a HUGE margin (20x?), the #1 post this month is “Simple Log Review Checklist Released!” Grab our log review checklist here, if you have not done so already.
  2. My RSA 2010 interview with Bob Russo and Troy Leach from PCI SSC holds the #2 spot: “RSA 2010 EXCLUSIVE PCI Security Standards Council Interview.” BTW, my other RSA coverage shows up on the top list as well: “RSA 2010 – Day 1 Metricon” and other RSA 2010 posts.
  3. The Myth of SIEM as “An Analyst-in-the-box” or How NOT to Pick a SIEM-II?“ and its predecessor ““I Want to Buy Correlation” or How NOT to Pick a SIEM?” hold the next position this month. They present some sadly popular misconceptions about acquiring and implementing SIEM and log management tools.
  4. Log Management / SIEM Users: “Minimalist” vs “Analyst”” being next on the hotlist made me think that maybe my blog is back to being the best blog on SIEM and log management :-) Also, my post on progressing from logging to log management to log monitoring discussion in “Logging, Log Management and Log Review Maturity”  is still popular as well. It presents a maturity scale for organization selecting log management or SIEM.
  5. Open source SIEM – and now also open source log management - theme continues to drive a lot of traffic (starting from “Short Observation on Open Source SIEM”) – it looks like folks are still desperately googling for it. “Why No Open Source SIEM, EVER?” post takes the spot in Top5 this month again – and so does “Open Source CLOUD SIEM, Anybody?” The older inspiration for these posts is “On Open Source in SIEM and Log Management.”

This month I am continuing a new tradition: I am going to thank my top 5 referrers this month (those that are actual humans, that is). So, thanks a lot to the following people whose blogs sent the most visitors to my blog:

  1. Walt Conway
  2. Sandro Süffert
  3. Dancho Danchev
  4. Lenny Zeltser
  5. Stefano Zanero

Thank you for all the link-love!

See you in April; also see my annual “Top Posts” - 2007, 20082009!

Possibly related posts / past monthly popular blog round-ups:

Obligatory “added everywhere” posts :-)

  • I am available for consulting projects related to logging, log management, SIEM, PCI DSS etc. Please see the services list at my consulting site.

Wednesday, March 31, 2010

Fun Reading on Security and Compliance #24

Here is an issue #24 of my “Fun Reading on Security and Compliance,” dated March 31, 2010 (read past ones here). You can judge that my “2blog” folder has been kinda full, since I was too busy working on a few fun consulting projects.
This edition is dedicated to RSA conference – an unending source of awesomeness!
Main section:
image
  1. First, a great read from Dave Shackleford “A Glimpse Into the Security Mindset” which reminds: “Security people have a challenge that is 100% unique to their discipline [within IT – A.C.]: we have adversaries.” While there, also read his “5 Reasons Your Security Program is a Failure.” (quote: “if you don’t have daily SOPs around your monitoring tools and capabilities, you will end up with shelfware, and that just sucks”). But if you really into sucking, check Lenny’s “How to Suck at Information Security
  2. Gartner blog has hilarious “Worst and Best Security Sales Practices” (first). Example: '”saying your product is in market X, since X is currently cool”
  3. Josh Corman, Jeff Williams (of OWASP fame) and David Rice (of “Geekonomics” fame) launch “RUGGED software” manifesto: “Software that endures against the environmental forces arrayed against it in cyberspace.” The manifesto is here at its brand new site. 
  4. Sad hilarity reigns supreme here in comments at  “Thor vs Clown”  from TaoSecurity. Example: “P(Compromise) = P(C.SMS) x P(C.PIN)
Logging, log management section and SIEM section:
  1. Using Logs To Reduce Response Gap”: “Unfortunately, auditing and never really using logs for anything except for records retention can cause organizations to treat them as merely objects to move around and not necessarily utilize for any action.”
  2. Prism Microsystems continues its epic mega-saga of “100 Log Management Useshere at “#27 Printer logs.”   While there, also please read “Sustainable vs. situational values” by Ananth that has this great quote: “I am often asked that if Log Management is so important to the modern IT department, then how come more than 80% of the market that “should” have adopted it has not done so?”
  3. Something made the Team Securosis think about correlation – and even argue between themselves: “Network Security Fundamentals: Correlation” (quote: “Most security professionals have tried and failed to get sufficient value from correlation relative to the cost, complexity, and effort involved in deploying the technology.”) and “Counterpoint: Correlation Is Useful, but Threat Assessment Is Fundamental” – then Rocky comments on the whole thing [BTW, I have no idea why they think correlation is about NETWORK security…]
  4. BTW, fun correlation discussion is also ongoing at one of the SANS blogs: “IT Audit: Correlating Logs and Event Logs.” It looks like David Hoelzer might bring his DAD correlation project back to life…
  5. A fairly intelligent piece on logging (“Best Practices For Windows Log Monitoring”) has this great quote: “Not monitoring your Windows logs is like setting up a security camera and putting an exit sign in front of it.”
  6. Lenny has “Establishing a Practical Routine for Reviewing Security Logs:” “A practical routine for reviewing security logs is regularly scheduled, partially automated, alternated among team members, and linked to problem resolution.” Our joint project, "Critical Log Review Checklist for Security Incidents" definitely helps with that.
  7. I mean, come on, even McAfee suddenly started talking about logs (something they’ve been ignoring forever). Eric Cole talks about logs in the context of SANS CAG/CSC in “Critical Control 6: Maintenance, Monitoring, and Analysis of Audit Logs.” He says: “Unmanaged Logs Hurt” and reminds that “Sometimes logging records are the only evidence of a successful attack.” Sadly, at the end he hints that you should be using ePO as a SIEM… gasp.
Vendor section [now that I am not employed by the vendor I can call vendors names, etc :-)]:
  1. Finally, one SIEM vendor realized that  analyzing firewall rules together with vulnerability data should not be left to the dedicated vendors [I always thought that fw rules + vuln scans analysis is waaay too narrow to launch a company on; SIEM should have ‘owned’ that a long time ago] and launched a new product that looks at events, flows, rules and vulnerability scans. Good idea!
  2. And one log management vendor realized that “Reviewing logs everyday is a pain, we just made it easier
  3. AlienVault, OSSIM commercial home, has released OSSIM 2.2. This deck has the highlights. As I am using the system now, it looks more impressive than ever. Seriously!
Enjoy!
Possibly related posts:

Wednesday, March 03, 2010

Monthly Blog Round-Up – February 2010

As we all know, blogs are a bit "stateless" and a lot of useful security reading material gets lost since many people, sadly, only pay attention to what they see today. These monthly round-ups is my attempt to remind people of useful content from the past month! If you are “too busy to read the blogs,” at least read these.

So, here is my next monthly "Security Warrior" blog round-up of top 5 popular posts/topics.

  1. Our  PCI DSS panel at ShmooCon (“ShmooCon 2010 – Our PCI DSS Panel”) was very interesting and justifiably took the #1 spot this month. That controversial video has been released [[FLV]. Other ShmooCon notes are in the post called “ShmooCon 2010 – Show Notes
  2. Progressing from logging to log management to log monitoring discussion in “Logging, Log Management and Log Review Maturity” took the next spot. It presents a maturity scale for organization selecting log management or SIEM.
  3. Open source SIEM theme continues to drive a lot of traffic (namely “Short Observation on Open Source SIEM”) – it looks like folks are still desperately googling for it. “Why No Open Source SIEM, EVER?” post takes the spot in Top5 this month again. The older inspiration for this post is “On Open Source in SIEM and Log Management.”  While you are reading up on SIEM , check out the post called “SIEM Bloggables” with key SIEM use cases.
  4. The announcement about the release of Security Scoreboard was next – ““Security Scoreboard” Out!”. Think of Security Scoreboard as of Zagat or, better,Yelp for security products.
  5. A completely humorous post about Advanced Persistent Threat (APT) called “Top Nine Reasons How PCI Is Like APT” (humor! humor! humor! – don’t respond to it seriously!) took the final spot in February Top5.

This month I am continuing a new tradition: I am going to thank my top 5 referrers this month (those that are actual humans, that is). So, thanks a lot to the following people whose blogs sent the most visitors to my blog:

  1. Walt Conway
  2. Dancho Danchev
  3. Chris Hoff
  4. Alexey Babenko (in Russian)
  5. Richard Bejtlich
  6. Paul Melson.

Thank you for all the link-love!

See you in March; also see my annual “Top Posts” - 2007, 20082009!

P.S. Why am I not blogging about RSA while I am at RSA 2010? Well, I am – these posts will come next week after I recover :-)

Possibly related posts / past monthly popular blog round-ups:

Obligatory “added everywhere” posts :-)

  • I might be available for consulting projects related to logging, log management, SIEM, PCI DSS etc. Please see the services list at my consulting site.

Monday, February 15, 2010

Fun Reading on Security and Compliance #23

Here is an issue #23 of my “Fun Reading on Security and Compliance,” dated February 16, 2010 (read past ones here). You can judge that my “2blog” folder has been kinda full, since I was too busy working on a few consulting projects.
This edition of dedicated to all bloggers who only care about the opinions of other bloggers. Please grow up! :-)
  1. First, I’d like to highlight a surprisingly intelligent whitepaper "SIEM: Five Best Practices for Success" from some outfit called Pivot Point Security (which I personally never heard of before).  You have to register to get it, but it is worth it for those who are planning to deploy a SIEM.
  2. "Ranum's Rants: Cloud Forum Roundtable": Marcus Ranum + Cloud + Security. What can possibly go wrong? Boom! Quotes: "Cloud Computing is going to happen. In fact, if you think it hasn't happened, it just means you're out of the loop"  and "loud Computing can be seen as the business units' final revenge on IT (and security) for saying "no" one time too many, taking too long, or costing too much"  as well as other fun insights. Read it!
  3. Finally, read this("Don’t ask me, ask that guy over there") and think really hard: "How many organizations out there consider data breach notification laws to be completely irrelevant to them?  Not because they aren’t applicable, but because the organization’s security state is so abysmal that they wouldn’t know a data breach if it sent them a strippergram with their own money? " or even "You’re ignoring the vast majority of people who are responsible in some way for the security of their networks, but (a) don’t know it, (b) don’t care, and/or (c) don’t have the knowledge or management backing to do anything about it."  SO, next time you whine about PCI DSS, keep that in mind!  BTW, while you are there, read this too on political risk.
  4. FUDSec continues to impress; for examples read these two pieces: "FUD and Other Sales Errors" and "FUD Just Feels Right" ("FUD is something we all use, abuse and understand and it is a Good Thing[™] as long as it motivates action and does not lead to submission.").Oh, and this one too: "Guerilla Security Leadership."  And this one: “he argues that FUD is less about security, and more about shills selling security to suckers” and “Why, without a firewall, you're screwed like a slow ape by a fast gorilla!”
  5. Somehow I forgot to mention Ben's "How NOT To Build a Security Program" is a fun read. While on this subject, read “Top 10 Reasons Your Security Program Sucks and Why You Can’t Do Anything About It”: “The bad guys are more interested in attacking you then you are in defending yourself, at least they work longer hours.”
  6. Cloud: Security Doesn’t Matter (Or, In Cloud, Nobody Can Hear You Scream)” is a good piece from Chris Hoff: “Manage compliance, don’t let it manage you because a Cloud is a terrible thing to waste.” :-)
  7. If you read only one piece from all the APT/Google/China crapfest, that’s this one from Richard: “4. The victim named the perpetrator. This amazes me. We need more of this to happen. By doing so a private company influenced a powerful policy maker to issue a statement of a diplomatic nature.”
  8. Finally, a quick – but often useful - reminder from Securosis: “Getting Your Mindset Straight for 2010.” Quote: “Repeat after me: A widget will not make me secure. Neither will two widgets or a partridge in a pear tree.”
  9. Dave always has a very fun prospective on security, here is an example: “Everyone says an attack is "sophisticated" whenever any 0day is involved. But that should be the baseline. Or rather, it IS the baseline and everyone seems to just be finding out.”
  10. AlertLogic folks has quietly launched SecureCloudReview.com  and it has some fun posts, like “Cloud-Bashing and The Innovator's Dilemma”: “The most relevant points of debate are about current examples of the fits and starts of cloud evolution.  Will cloud solutions succeed in "trickling" up-market or will they become extinct after a short life?” (they will trickle, for sure - example)
  11. Read these two and weep: “Is Quantified Security a Weak Hypothesis?” (which refers to this [PDF])  and “THE MOST MAGICAL QUESTION OF ALL -- WHY ARE SO MANY BRIGHT PEOPLE FOOLING THEMSELVES ABOUT THE SCIENCE IN NFORMATION SECURITY”: "Read that if you think there is a place for science in information security. On the other hand, if you think information security is something else, better off to go read something on creative journalism, public relations, politics, marketing, etc.”
PCI DSS section:
  1. Fun follow up from our “The Great PCI Security Debate of 2010” is here: “LOAD UP ON STEEL, AND SHOOT IT OUT! PCI AND THE MARKET FOR SILVER BULLETS”: “By way of hypotheses in the market for silver bullets, we then find ourselves seeking to reduce the exposure to those external costs; this causes the evolution of some form of best practices which is an agreed set that simply ensures you are not isolated by difference.”
  2. Heartland Breach: State of Payments Security 1 Year Later” is a fun read as well.
  3. If you have a Forrester subscription, read “PCI Unleashed” by John Kindervag. If not, read Branden’s blog about it: “Just try asking a rep from a payment brand if this is why PCI DSS was started, and you might learn a new way to answer a question without actually answering it.” :-)
  4. Time to Revisit Intent of PCI DSS”  has some curious arguments, like: “When you add up all the money being spent on that compliance effort, you can’t help but wonder if it would be simpler and less expensive for all if the payment card issuers were to stop doing business with a minority of merchants that become embroiled in a fraudulent act until they can prove that they have put the appropriate level of security in place.”
  5. PCI Security Policies and You - Part 3” from Walt shares some wisdom on PCI DSS security policies: ”A good security policy template provides you with a structure while preserving flexibility. It also should lead you to additional resources where this can be useful.”
Enjoy!
BTW, I can use a bit more work in March – let me know if you need anything done around the area where I focus: logs, SIEM, etc.
Possibly related posts:

Wednesday, February 03, 2010

Monthly Blog Round-Up – January 2010

As we all know, blogs are a bit "stateless" and a lot of useful security reading material gets lost since many people, sadly, only pay attention to what they see today. These monthly round-ups is my attempt to remind people of useful content from the past month! If you are “too busy to read the blogs,” at least read these.
So, here is my next monthly "Security Warrior" blog round-up of top 5 popular posts/topics.
  1. As predicted, my security predictions ( “Security Predictions 2010” and “Security Predictions 2020 (!)” - yes, 2020!) took the #1 spot this month. They are fun – but I will also check how well they panned out early next year. Then we will know who is laughing :-)
  2. How to Stay Compliant? or Ongoing Tasks in PCI DSS,”  a repost of my paper published at EthicalHacker.net was next. Indeed, “getting compliant” is only half the fun (actually, getting validated is only 1/3 of it :-))
  3. SIEM is on a lot of people’s minds. That is why ““I Want to Buy Correlation” or How NOT to Pick a SIEM?” is on the hot list. BTW, I am planning more of “how not to buy a SIEM?” posts…
  4. Top Log FAIL!” is still hot! The post summarizes the most egregious, reckless, painful, negligent, sad, idiotic examples of “Log FAIL.”
  5. MUST-DO Logging for PCI?” took the next spot. BTW, there is a newer post on the subject of PCI DSS logging requirements: “More on PCI DSS and Logging.” This, BTW, has been the main goal of some of my recent consulting projects. Should I maybe talk about “PCI logging in the cloud” next? :-)
  6. Open source SIEM theme continues to drive a lot of traffic – it looks like folks are still desperately googling for it. “Why No Open Source SIEM, EVER?” post takes the spot in Top5 this month again. The older inspiration for this post is “On Open Source in SIEM and Log Management.”  While you are reading up on SIEM , check out the post called “SIEM Bloggables” with key SIEM use cases. BTW, the funny (and new!) part is that I see more queries for “open source log management” as well.
This month I am continuing a new tradition: I am going to thank my top 5 referrers this month (those that are actual humans, that is). So, thanks a lot to the following people whose blogs sent the most visitors to my blog:
  1. Dancho Danchev
  2. Walt Conway
  3. Alexey Babenko (in Russian)
  4. Richard Bejtlich
  5. Gunnar Peterson
Thank you for all the link-love!
See you in February; also see my annual “Top Posts” - 2007, 20082009!
Possibly related posts / past monthly popular blog round-ups:
Obligatory “added everywhere” posts :-)
  • I might be available for fun consulting projects related to logging, log management, SIEM, PCI DSS etc. Please see the services list at my consulting site.

Tuesday, January 19, 2010

Some Fun Reading and Listening

As I am preparing to attend to a family emergency and thus go “offline” for a while, here is something fun stuff for my dear readers:
  • “PCI War” rages one in this “CSO Online” podcast “The Great PCI Security Debate of 2010: Part 1[MP3] with such fun people as Joshua Corman, Mike Dahn, Jack Daniel, Ben Rothke, Martin McKeay, etc.  It is a bit chaotic at times, but fun and enlightening. It was also fun to participate in, despite the fact that it was recorded at 7AM. This piece provides some background for the debate.
  • The second part of the PCI debate was just posted here.
  • Those with interest in SIEM must read Rocky’s “The 2010 SIEM Winter Olympics Preview
Enjoy! More fun posts coming when I am back. For now, buy The PCI Book :-)
BTW, see you all at ShmooCon and then at RSA 2010.

Thursday, January 07, 2010

Annual Blog Round-Up – 2009

If monthly, why not annual blog round-up? These are my top popular "Security Warrior" blog posts for 2009. This list covers the posts most popular in 2009, not necessarily only those written in 2009.  Enjoy!
  1. The quest for open source SIEM continues! In fact, the TWO top posts on my blog in 2009 resulted from search queries for “open source SIEM.” They are: “Why No Open Source SIEM, EVER?” and “On Open Source in SIEM and Log Management.” BTW, all SIEM posts are tagged here.
  2. Next, we got scientific (eh..statistical :-)) proof that Heartland Payment Systems mega-breach was The Security Event of 2009. My coverage of the Heartland saga is next on the top list: “On Heartland”, “On Heartland II”, “On Heartland III”, “On Heartland IV”, “On Heartland V”, “On Heartland VI.”  BTW, what is the overall security lesson of the “HPS-gate”? Sorry, but it is “it’s OK to have a massive card data breach!”
  3. I suspect a lot of security folks do a lot of career soul searching nowadays. That is why “A Myth of An Expert Generalist” is so HOT. I suspect you already read it, but if not – go do it!
  4. It is interesting that Windows log collection is still very much an issue with many folks. That is why “Windows Log Collection Poll Analysis” is in the top for the year.
  5. Thoughts and Notes from PCI DSS Hearing in US House of Representatives”  needs no introduction or explanation why it is on the top list for 2009 :-)
  6. Top Log FAIL!” summarizes the most egregious, reckless, painful, negligent, sad, idiotic examples of “Log FAIL.” Log management at its worst!
  7. I am not really “a rant-master”, but some of the more philosophical posts (“Smart vs Stupid: But Not Why You Think So!”) end up being very popular – this one definitely struck a cord with many people.
  8. “Compliant” + 0wned = ?” … this posts seeks to answer this “eternal” question.
  9. A champion of multiple months – AND last year!-  “MUST-DO Logging for PCI?  is also on the list the second time; the world does need more specific PCI DSS guidance. PCI DSS guidance is not “too prescriptive,” it is more often not prescriptive enough!  BTW, you can hire me to help you with your logging, log architecture, log management/SIEM product selection or related product development.
  10. Five Reasons to Dislike PCI DSS – And Why They Are WRONG!” is a fun little piece which fights the war in defense of PCI DSS.
See you in December 2010 when I will post the next annual blog round-up (see my previous annual “Top Posts” - 2007, 2008)
Possibly related posts / past monthly popular blog round-ups:
Obligatory “added everywhere” posts :-)
  • I might be available for fun consulting projects related to loggging, log management, SIEM, PCI DSS, security writing, events, etc. Please see the services list at my consulting site.

Dr Anton Chuvakin