Entries Categorized as 'Security Intelligence'
by Neil MacDonald | February 3, 2012 | 1 Comment
I’ve blogged before about advanced threats that easily bypass our traditional protection mechanisms and reside undetected for extended periods of time on our systems. On one of the panels I moderated on APTs, Dave Merkel from Mandiant put it best. “You are compromised, get over it”. Others in the US Government have come to the [...]
Category: Application Security Beyond Anti-Virus Cloud Cloud Security Next-generation Security Infrastructure Security Intelligence Tags: Adaptive Security Infrastucture, Application Security, Best Practices, Beyond Anti-Virus, Cloud Security, Context-aware Security, DC-Summit-NA, Defense-in-Depth, DevOpsSec, Next-generation Security Infrastructure
by Neil MacDonald | January 30, 2012 | 8 Comments
Dynamic Application Security Testing (DAST) solutions test applications from the “outside in” to detect security vulnerabilities. In contrast, Static Application Security Testing (SAST) solutions test applications from the “inside out” by looking a source code, byte code or binaries. Both approaches have their pros and cons and, until recently, the market for these tools has [...]
Category: Application Security Security Intelligence Tags: Adaptive Security Infrastucture, Application Security, application security testing tools
by Neil MacDonald | January 9, 2012 | 6 Comments
I called this a “security no brainer” years ago and the advice is absolutely still relevant today. In Gartner’s latest Magic Quadrant for Dynamic Application Security Testing (DAST) solutions for clients, one of the evaluation criteria we looked at was whether or not the vulnerability knowledge of the DAST solution could be exported and used [...]
Category: Application Security Security Intelligence Tags: Application Security, application security testing tools, Best Practices, Security No-Brainer
by Neil MacDonald | October 13, 2011 | Comments Off
Context-aware security is the use of supplemental information to improve security decisions at the time the decision is made. The goal? More-accurate security decisions capable of supporting more-dynamic business and IT environments as well as providing better protection against advanced threats. In this 2010 research note that provided a definition and framework for understanding context-aware [...]
Category: Next-generation Security Infrastructure Security Intelligence Tags: Adaptive Security Infrastucture, Context-aware Security, Endpoint Protection Platform, Next-generation Security Infrastructure, symposium
by Neil MacDonald | October 11, 2011 | 1 Comment
Traditional data loss prevention has been focused on looking for signatures and patterns of sensitive data at rest within the organization and as it moves throughout the organization, including to destinations outside of the enterprise (the latter is where most organizations have started). <digress> You noticed I didn’t use the term “DLP”. That’s because I [...]
Category: Information Security Next-generation Security Infrastructure Security Intelligence Tags: Defense-in-Depth, Information Security, Next-generation Security Infrastructure, Security No-Brainer
by Neil MacDonald | July 14, 2011 | Comments Off
We can’t secure everything equally, nor does everything need to be equally secured. What we need is a context-aware, risk-based view of where to focus our efforts where part of the context is the business value and sensitivity of the asset we are protecting.
Category: Information Security Security Intelligence Tags: Information Security, Reducing Cost
by Neil MacDonald | April 12, 2011 | Comments Off
We talk about the need for analytics and business intelligence to help the business make better business decisions, It is time to bring this same technology to the information security department. What we need is actionable, prioritized and risk-based insight from this sea of information. I’ll take it a bit further. There are some emerging [...]
Category: Cloud Security Next-generation Security Infrastructure Security Intelligence Tags: Adaptive Security Infrastucture, Beyond Anti-Virus, Cloud Security, Defense-in-Depth, Next-generation Data Center, Next-generation Security Infrastructure
by Neil MacDonald | March 9, 2011 | Comments Off
Sitting here in the airport getting ready to fly back home, it occurred to me that all of these hyped technologies have had a critical shift in mindset over the past several years. Each of these technologies was originally touted with their ability to block and control “bad things” from happening. With NAC, this entailed [...]
Category: Beyond Anti-Virus Endpoint Protection Platform Security Intelligence Tags: Beyond Anti-Virus, Endpoint Protection Platform, Information Security, Next-generation Security Infrastructure, Whitelisting
by Neil MacDonald | March 1, 2011 | 1 Comment
As I walked the exhibit hall floor at RSA, I couldn’t help but notice the large numbers of vendors talking about the need for improved detection capabilities and security intelligence that provides actionable insight as to what is going on in our IT infrastructure. Complete protection requires both prevention and detection capabilities. I’ve blogged about [...]
Category: Beyond Anti-Virus Endpoint Protection Platform Security Intelligence Tags: Adaptive Security Infrastucture, Defense-in-Depth, Endpoint Protection Platform, Next-generation Security Infrastructure, Reducing Cost
by Neil MacDonald | December 7, 2010 | 1 Comment
I attended a breakfast presentation this morning given by Schneider Electric on the topic of facilities and energy intelligence. Essentially, they are tearing down the monitoring silos of energy, fire, lighting, data center power, HVAC and physical security monitoring to deliver a unified dashboard for facilities and energy management. As I listened to the presentation, [...]
Category: Information Security Next-generation Data Center Security Intelligence Tags: GartnerDC, Information Security, Next-generation Data Center, Next-generation Security Infrastructure