Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 28 guests and 2 members online
You are here:
Home
Features
Opinions
[Article]-The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net
May 24, 2013, 06:27:38 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Features
>
Opinions
(Moderator:
don
) >
[Article]-The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: [Article]-The Broken: Assessing Corporate Security in 2012 to Make a Better 2013 (Read 4203 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4168
Editor-In-Chief
[Article]-The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
«
on:
December 19, 2012, 09:07:24 PM »
Agree, disagree, don't care... that's the great thing about opinions. Here's an opinion piece by an industry veteran pondering what 2012 meant and what can be done in 2013. Read and join in the conversation.
Permalink:
[Article]-The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
Quote
by Paul Jaramillo, CISSP, EnCE
So as we are about to close out 2012, many of us in the IT Security community look around and try to assess where we were, what we have accomplished this year, and what is next. I’ve been working in IT since the late 90s with a focus on security for much of that time. Most of my work has been in large private-sector companies with a brief but very rewarding stint working for the government. To me while much has changed, many of the core issues remain today as they were back then. Our security condition has actually worsened in many cases. While that is up for debate, no one can argue the pace, sophistication, and impact of major cyber events related to nation-sponsored, organized crime. Hacktivism threats have increased exponentially in the last 4-5 years as well. This new normal has been applicable to the government and defense industrial base for a long time but really surfaced in the private sector around 2007. You would assume that with all that increased attention, dollars and executive support at the highest levels, it would be making things happen. To a certain extent they are, but we as an industry are still losing in the never-ending cat and mouse game with our adversaries. Why?
Over the years, I have sat through countless “you’re doing it wrong” or “we’re screwed’ type of presentations. Some of them were very informative, and I absolutely respect anyone that publicly voices their opinions and ideas, knowing they will be criticized and nitpicked for things taken out of context. However, I often leaving conferences with a desire for a way to fix what we all know has been broken. So what is stopping us? That is where I would like to focus some energy. What are the key road blocks and stumbling points that are keeping the security industry from truly raising the bar as opposed to being stuck in a continual state of catch up?
The ideas that follow are not all my own, and I’m sure I have subconsciously absorbed them or unknowingly added them to my mantra. I have a set of wise men that I learn from constantly, however I won’t list them out or directly associate them to this article out of respect. These ideas shouldn’t be taken as a statement of fact either, as they are only my humble opinions. My goal is to start a real discussion and starting point for documenting and overcoming our greatest challenges to our broken system.
Let the debate begin,
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
3xban
Hero Member
Offline
Posts: 608
Re: [Article]-The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
«
Reply #1 on:
December 25, 2012, 11:46:25 AM »
Excellent Article Paul...
Obstacle 1: agree and will add this can also benefit the person if they may have done the opposite before leaving a company. Force resignation and all. But certainly tracking the bad apples would be beneficial and hold them accountable for their decisions. I believe a bonus should be earned if you not only help make the company money but also help prevent the loss of said money.
Obstacle 2: I am finding this to be a reality. I find it more trying to defend against advanced attacks when you can't even implement security 101. Thankfully though where I am the audits are taken pretty seriously and are usually addressed within the first few months after. But that may be only because the current auditors are not as well trained. I am finding auditors are becoming much more technically savvy and are looking for things they never did in the past. I've seen a few IT folks move over to audit mainly because you no longer need to fix the problems but you can just report them. Maybe they are sick of trying to fix them only to be told it costs too much blah blah blah. It certainly is easier to click a check box, specially if you know where to look.
Obstacle 3: Agree as well, but how do we do this? Do we sacrifice skills training for business classes? Do we take one of the SANS MGT courses over a SEC or FOR course? Do we go for an MBA or a MIA? Or do we look at day long workshops to help gain a better focus? I personally don't want to leave the trenches anytime soon, but I find I am being asked to do so although I am not a manager nor care to be. Then again, do I have the aptitude to stay in the trenches? I think so, I just started in InfoSec (well in concentrating on it), and I have no desire to put down the keyboard just yet.
Obstacle 3: so long as the staff is up to par and keeps improving their skill sets. I think heavy reliance on outsourcing your support causes this competitive advantage to decline. I am currently seeing the situation where ALL of your IT knowledge is in the hands of the outsourced company and almost known exists with your FT IT staff. I think it is important to keep the skills up on both sides so you essentially have FTEs with the knowledge to do the job, but they send the work to the out-sourced staff to carry out. They then can focus their time on developing new and better solutions for the company, they may even develop a new product or service from this.
Obstacle 4: Partially agree on this one. This forum clearly shows there is a large number of new people wanting to be "hackers" or pen testers, but seem to lack the base skills and understanding about the systems they want to hack. I partially agree because I think both the technical and business skills are needed equally. The DoD description of what they need does not reflect their target. They want highly trained people fresh out of college? We all know that typical MIS/CS majors graduate with information that is probably 5 yrs out-of-date. Unless of course they were gaining some real world experience during school, but even those entry level security jobs require experience. Essentially you want to groom people for these jobs. Moving those with a strong base knowledge about technology into a security focused job then giving them incentives to build the business skills for that key person we need in that board room. Again how do you do that with someone who wants to stay in the trenches or has no desire to be in that board room mainly because they think nothing will get done either way?
Obstacle 5: Agree with this, my drive is not being bored. I think anyone with a legitimate love for what they do, do it for that simple fact. I think having a love for all things InfoSec related is no different. We enjoy a challenge, that is a real challenge. I think in most enterprises the challenge isn't developing the solution, it is dealing with the red tape around getting it approved. We also love seeing something we created get implemented successfully. But if we are tasked to come up with a solution to something and then not see it implemented or implemented poorly, we are left with a bitter taste in our mouth.
As you had mentioned before there have been a lot of great talks at the security cons about what is wrong with the industry. In most cases those speakers are preaching to the choir. There are probably many of us that do know how to speak the business to the C-Levels, but are they truly listening? Do they even care? Have they ever seen something like the anatomy of a virus? Seeing something so small destroy a company because a single simple patch was not installed or proper network ACLs were not in place to prevent the spread of a worm? I like the point about the Security managers need to be able to tell someone above them - "No we cannot do that and here's why..." If they are worth their salt, they shouldn't need to worry about finding another job if they are fired for disagreeing. Which brings us back to the first obstacle, sure I was asked to resign but here is why and hand over the sign documents.
Logged
Certs: GCWN
(@)Dewser
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.