<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Neil MacDonald</title>
	<atom:link href="http://blogs.gartner.com/neil_macdonald/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.gartner.com/neil_macdonald</link>
	<description>A Member of the Gartner Blog Network</description>
	<lastBuildDate>Fri, 03 Feb 2012 13:55:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>Intrusion Prevention Systems? We Need Intrusion Resilient Systems</title>
		<link>http://blogs.gartner.com/neil_macdonald/2012/02/03/intrusion-prevention-systems-we-need-intrusion-resilient-systems/</link>
		<comments>http://blogs.gartner.com/neil_macdonald/2012/02/03/intrusion-prevention-systems-we-need-intrusion-resilient-systems/#comments</comments>
		<pubDate>Fri, 03 Feb 2012 13:53:58 +0000</pubDate>
		<dc:creator>Neil MacDonald</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Beyond Anti-Virus]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Next-generation Security Infrastructure]]></category>
		<category><![CDATA[Security Intelligence]]></category>
		<category><![CDATA[Adaptive Security Infrastucture]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Context-aware Security]]></category>
		<category><![CDATA[DC-Summit-NA]]></category>
		<category><![CDATA[Defense-in-Depth]]></category>
		<category><![CDATA[DevOpsSec]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2012/02/03/intrusion-prevention-systems-we-need-intrusion-resilient-systems/</guid>
		<description><![CDATA[I’ve blogged before about advanced threats that easily bypass our traditional protection mechanisms and reside undetected for extended periods of time on our systems. On one of the panels I moderated on APTs, Dave Merkel from Mandiant put it best. “You are compromised, get over it”. Others in the US Government have come to the [...]]]></description>
			<content:encoded><![CDATA[<p>I’ve blogged before about <a href="http://blogs.gartner.com/neil_macdonald/2011/04/14/advanced-persistent-threats-finding-the-needle-in-a-haystack/">advanced threats that easily bypass our traditional protection mechanisms</a> and reside undetected for extended periods of time on our systems.</p>
<p>On one of the panels I moderated on APTs, Dave Merkel from Mandiant put it best. <a href="http://blogs.gartner.com/neil_macdonald/2011/03/01/one-big-take-away-from-rsa-intelligence/">“You are compromised, get over it”.</a> Others in the <a href="http://blogs.gartner.com/neil_macdonald/2011/04/05/theres-no-such-thing-as-secure-anymore/">US Government have come to the same conclusion.</a></p>
<p>We spend far too much of our information security budget on increasingly ineffective mechanisms designed to prevent intrusions including network and host-based solutions, firewalls, IPS and antimalware systems. Does that mean we give up on these Not at all. What we need are new capabilities in other areas.</p>
<p>Assume you’ve been compromised. How would you know? We don’t spend nearly enough on systems that help us to better detect a compromise after it has occurred. <a href="http://blogs.gartner.com/neil_macdonald/2011/07/11/sand-castles-and-advanced-persistent-threats/">We can’t keep pretending that we can keep the bad guys out.</a></p>
<p>Where are net new investments needed? Here’s just a few of the specific areas I discuss in my research.</p>
<ul>
<li>More monitoring. <a href="http://blogs.gartner.com/neil_macdonald/2011/04/27/if-detection-is-security-101-why-do-we-keep-getting-nailed-with-apts/">Lots more.</a> At all layers of the stack – packet, flows, sessions, transactions, applications, user activities – all of it.</li>
<li><a href="http://blogs.gartner.com/neil_macdonald/2010/05/15/the-future-of-information-security-is-context-aware-and-adaptive/">More context-awareness.</a> To separate meaningful anomalies out from a sea of monitored events will require more context – identity, application, content, location, time of day, reputation and so on.</li>
<li>Big data and analytics brought to information security. <a href="http://blogs.gartner.com/neil_macdonald/2011/04/12/information-security-is-becoming-big-data-problem/">Information security is becoming a big data problem</a> and we need the systems, algorithms and new sets of security skills to derive insight from this.</li>
<li><a href="http://blogs.gartner.com/neil_macdonald/2010/12/01/securing-private-clouds-requires-changes-to-information-security-infrastructure/">Higher levels of automation</a>. To free up time to focus on the really important stuff, security professionals have got to get out of the day to day programming of security policy enforcement points. <a href="http://blogs.gartner.com/neil_macdonald/2010/09/21/security-thought-for-tuesday-program-policies-not-infrastructure/">Program policies? Yes. Program quintuples?</a> No.</li>
<li>Cloud-based security policy enforcement. If we don’t own the device or the network (think 3G, 4G etc) then we can’t always rely on traditional network and host-based security controls for protection.</li>
<li>Applications that are designed to be securely operated and used from inception. <a href="http://blogs.gartner.com/neil_macdonald/2012/01/17/devops-needs-to-become-devopssec/">DevOpsSec</a> must and will become a reality.</li>
<li>A shift in thinking from Security Information and Event Management to delivering <a href="http://blogs.gartner.com/neil_macdonald/2011/03/01/one-big-take-away-from-rsa-intelligence/">Security Intelligence</a></li>
</ul>
<p>I believe information security infrastructure is at a critical inflection point. The status quo isn’t cutting it. Changes are needed.</p>
<p>Are the vendors up to it if it means we spend less for increasingly ineffective legacy solutions they are selling us? (The good news is that we’ll spend more in the other areas highlighted above if they’d make these types of advancements)</p>
<p>Are we up to it? Are we prepared to admit that we are currently on the losing side of this battle and make the types of process, technology and mindset changes above?</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/neil_macdonald/2012/02/03/intrusion-prevention-systems-we-need-intrusion-resilient-systems/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Interactive Application Security Testing</title>
		<link>http://blogs.gartner.com/neil_macdonald/2012/01/30/interactive-application-security-testing/</link>
		<comments>http://blogs.gartner.com/neil_macdonald/2012/01/30/interactive-application-security-testing/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 14:24:52 +0000</pubDate>
		<dc:creator>Neil MacDonald</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Security Intelligence]]></category>
		<category><![CDATA[Adaptive Security Infrastucture]]></category>
		<category><![CDATA[application security testing tools]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2012/01/30/interactive-application-security-testing/</guid>
		<description><![CDATA[Dynamic Application Security Testing (DAST) solutions test applications from the “outside in” to detect security vulnerabilities. In contrast, Static Application Security Testing (SAST) solutions test applications from the “inside out” by looking a source code, byte code or binaries. Both approaches have their pros and cons and, until recently, the market for these tools has [...]]]></description>
			<content:encoded><![CDATA[<p>Dynamic Application Security Testing (DAST) solutions test applications from the “outside in” to detect security vulnerabilities. In contrast, Static Application Security Testing (SAST) solutions test applications from the “inside out” by looking a source code, byte code or binaries.</p>
<p>Both approaches have their pros and cons and, until recently, the market for these tools has evolved separately with different vendors and solutions. Even when a single vendor offers both DAST and SAST solutions, they have not historically been integrated.</p>
<p>In the latest research for clients &#8211; <a href="http://www.gartner.com/resId=1883624">Gartner Magic Quadrant for Dynamic Application Security Testing</a> – one of the criteria we looked at was whether or not the vendor’s solution provided Interactive Application Security Testing (IAST). Specifically, we are looking for ways that application security testing solutions combine dynamic and static techniques to improve the overall quality of the testing results. The information gathered by this instrumentation agent gives the hybrid solution an inside-out view that complements the outside-in view of a purely DAST solution — for example, identifying the specific line of code where a security vulnerability occurred, or providing detailed visibility into code coverage. There are a couple of ways that Dynamic and Static testing techniques can be integrated and made to be interactive:</p>
<p>1) The web application platform (IIS, Apache, or other) can be instrumented to observe the application as it is being tested dynamically.</p>
<p>2) The web application can be instrumented via injected code (.NET, Java, or other) so that it can be observed during dynamic testing</p>
<p>3) The output of a static code/binary analysis could be used to create and “tune” the dynamic test that is subsequently performed.</p>
<p>4) The results of observing an application under dynamic test or in use could be used to modify the dynamic test that is being performed in real time. In this way, the dynamic test can be made much more “intelligent” in how it tests an application. This is exactly the approach used by Quotium – a vendor we wrote up in 2011 as a Gartner Cool Vendor.</p>
<p>Multiple DAST solutions now provide IAST capabilities.  Some of the vendors evolving their offerings in this direction and offering IAST include Acunetix, HP, IBM, NTO, Parasoft and Quotium. However, most IAST solutions also requires that an agent be deployed on the application platform, which relegates the technique largely to QA and also requires that the vendor explicitly support the platform or language being instrumented (such as PHP, Java or .NET/ASP).</p>
<p>Look for IAST capabilities <a href="http://blogs.gartner.com/neil_macdonald/2012/01/04/the-market-for-dynamic-application-security-testing-is-anything-but-static-2/">in your next evaluation of Dynamic Application Security Testing solutions.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/neil_macdonald/2012/01/30/interactive-application-security-testing/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>DevOps Needs to Become DevOpsSec</title>
		<link>http://blogs.gartner.com/neil_macdonald/2012/01/17/devops-needs-to-become-devopssec/</link>
		<comments>http://blogs.gartner.com/neil_macdonald/2012/01/17/devops-needs-to-become-devopssec/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 15:13:09 +0000</pubDate>
		<dc:creator>Neil MacDonald</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Next-generation Security Infrastructure]]></category>
		<category><![CDATA[Adaptive Security Infrastucture]]></category>
		<category><![CDATA[application security testing tools]]></category>
		<category><![CDATA[Defense-in-Depth]]></category>
		<category><![CDATA[DevOpsSec]]></category>
		<category><![CDATA[Next-generation Data Center]]></category>
		<category><![CDATA[Security-Summit-NA]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2012/01/17/devops-needs-to-become-devopssec/</guid>
		<description><![CDATA[DevOps seeks to bridge the development and operations divide through the establishment of a culture of trust and shared interest among individuals in these previously siloed organizations. However, this vision is incomplete without the incorporation of information security, which represents yet another silo in IT. Breakdowns in communications and processes across development, operations and security [...]]]></description>
			<content:encoded><![CDATA[<p>DevOps seeks to bridge the development and operations divide through the establishment of a culture of trust and shared interest among individuals in these previously siloed organizations. However, this vision is incomplete without the incorporation of information security, which represents yet another silo in IT. Breakdowns in communications and processes across development, operations and security are the root cause of the vast majority of critical system downtime, including downtime caused by breaches in security. For example, Gartner research shows that 75% of successful attacks occur against previously known vulnerabilities for which a patch or secure configuration standard was already available (actually, this used to be about 90%, but <a href="http://blogs.gartner.com/neil_macdonald/2011/04/27/if-detection-is-security-101-why-do-we-keep-getting-nailed-with-apts/">advanced and targeted attacks</a> have changed the equation).</p>
<p>Conventional wisdom believes the agile nature of the DevOps vision is fundamentally at odds with the historically static and cumbersome nature of information security. I disagree. I believe that security can support a unified vision of DevOpsSec, but to do this, information security must change in multiple ways including security infrastructure becoming more <a href="http://blogs.gartner.com/neil_macdonald/2010/05/15/the-future-of-information-security-is-context-aware-and-adaptive/">adaptive</a> and <a href="http://blogs.gartner.com/neil_macdonald/2010/12/01/securing-private-clouds-requires-changes-to-information-security-infrastructure/">programmable</a> and making information security representation an integral part of DevOpsSec teams from the genesis of new applications and services.</p>
<p>I’ve just published a research note for clients <a href="http://www.gartner.com/resId=1896617">DevOpsSec: Creating the Agile Triangle</a> that makes the argument for DevOpsSec and outlines the major areas of change for information security to support a unified DevOpsSec vision. My colleague, <a href="http://blogs.gartner.com/cameron_haight">Cameron Haight</a>, from the IT Operations side of Gartner research joined me on the research note. He has pioneered much of the research on DevOps for Gartner and increasingly he is being asked how DevOps can be adopted without sacrificing security. Increasingly, I am being asked how to rationalize the agile nature of DevOps with the need for <a href="http://blogs.gartner.com/neil_macdonald/2012/01/04/the-market-for-dynamic-application-security-testing-is-anything-but-static-2/">security testing</a>. Together, we teamed up to deliver the first in a series of research notes on how to deliver DevOpsSec.</p>
<p>Development, operations and security are fundamentally intertwined. A well-designed, developed and managed system is the foundation of a secure system. DevOps must evolve to a new vision of DevOpsSec that balances the need for speed and agility of enterprise IT capabilities with the enterprise need to protect critical assets, applications and services.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/neil_macdonald/2012/01/17/devops-needs-to-become-devopssec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Link Web Application Firewalls to Dynamic Application SecurityTesting Tools</title>
		<link>http://blogs.gartner.com/neil_macdonald/2012/01/09/link-web-application-firewalls-to-dynamic-application-securitytesting-tools/</link>
		<comments>http://blogs.gartner.com/neil_macdonald/2012/01/09/link-web-application-firewalls-to-dynamic-application-securitytesting-tools/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 13:06:41 +0000</pubDate>
		<dc:creator>Neil MacDonald</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Security Intelligence]]></category>
		<category><![CDATA[application security testing tools]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Security No-Brainer]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2012/01/09/link-web-application-firewalls-to-dynamic-application-securitytesting-tools/</guid>
		<description><![CDATA[I called this a “security no brainer” years ago and the advice is absolutely still relevant today. In Gartner’s latest Magic Quadrant for Dynamic Application Security Testing (DAST) solutions for clients, one of the evaluation criteria we looked at was whether or not the vulnerability knowledge of the DAST solution could be exported and used [...]]]></description>
			<content:encoded><![CDATA[<p>I called this a <a href="http://blogs.gartner.com/neil_macdonald/2009/08/19/security-no-brainer-9-application-vulnerability-scanners-should-communicate-with-application-firewalls/">“security no brainer”</a> years ago and the advice is absolutely still relevant today.</p>
<p>In Gartner’s latest <a href="http://www.gartner.com/resId=1883624">Magic Quadrant for Dynamic Application Security Testing (DAST) solutions</a> for clients, one of the evaluation criteria we looked at was whether or not the vulnerability knowledge of the DAST solution could be exported and used by a web application firewall (WAF – for example Imperva, F5, Citrix, Barracuda, DenyAll, ModSecurity, Bee Ware, etc ) to protect the vulnerability application from attacks (note that this is conceptually identical to using network or host-based IPSs to shield from attacks on endpoints until patches can be applied)</p>
<p>Before I start a firestorm of comments, let me be clear: we believe the vulnerable application should be fixed if possible (just like vulnerable endpoints should ultimately be patched). WAFs should be viewed as a way to shield vulnerable web applications until they can be fixed/patched. However, this isn’t always possible in a timely manner. Sometimes the backlog of applications in development prevents a timely fix. Sometimes the organization doesn’t have the expertise to fix the application because the person that wrote it has left (or the development was outsourced/contracted). In other cases, there may be limited access to the source code. Regardless, what if we’ve got a vulnerable web application that we can’t fix in a timely manner?</p>
<p>That’s where DAST/WAF integration comes in. Most DAST solution providers will link directly to WAF providers to provide specific protection from a vulnerability. The DAST tool discovers the vulnerability and the WAF helps to shield from attacks on that vulnerability. Makes sense doesn’t it?</p>
<p>Here’s a couple of things to keep in mind:</p>
<ul>
<li>Look for explicit WAF support. Some DAST solution providers will talk about exporting vulnerability knowledge in XML and how this could be consumed by a WAF… leaving out the part where you have to perform the translation from a generic XML-based representation of the vulnerability into the native WAF rule syntax. Make sure both your WAF provider and DAST solution provider state explicit out of the box support for this integration.</li>
<li>Even with explicit integration, don’t expect DAST vulnerability information to flow to a WAF without requiring human intervention and testing.</li>
<li>Favor DAST solutions that allow you to quickly and easily retest/replay a specific vulnerability with the WAF in place to confirm that the protection is working as expected.</li>
<li>To check for false positives, use testing scripts or recorded sessions to exercise the web application with the WAF rule in place. Favor WAF solutions that can place new rules in a “monitor only” mode for a period of time before being placed into blocking mode.</li>
</ul>
<p>If you haven’t evaluated DAST solutions recently, it is time to take another look. <a href="http://blogs.gartner.com/neil_macdonald/2012/01/04/the-market-for-dynamic-application-security-testing-is-anything-but-static-2/">The market continues to evolve rapidly</a>. If a vulnerable web application can’t be fixed in a timely manner, don’t leave yourself exposed. Look for explicit, out of the box support for WAF rule generation in your next DAST or WAF solution evaluation.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/neil_macdonald/2012/01/09/link-web-application-firewalls-to-dynamic-application-securitytesting-tools/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>The Market for Dynamic Application Security Testing is Anything but Static</title>
		<link>http://blogs.gartner.com/neil_macdonald/2012/01/04/the-market-for-dynamic-application-security-testing-is-anything-but-static-2/</link>
		<comments>http://blogs.gartner.com/neil_macdonald/2012/01/04/the-market-for-dynamic-application-security-testing-is-anything-but-static-2/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 14:26:49 +0000</pubDate>
		<dc:creator>Neil MacDonald</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Applications]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[application security testing tools]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2012/01/04/the-market-for-dynamic-application-security-testing-is-anything-but-static-2/</guid>
		<description><![CDATA[We’ve just published a new Magic Quadrant for Dynamic Application Security Testing (DAST) for Gartner clients. In Gartner research, we use the term DAST to refer to testing solutions and techniques that are designed to test an application from the “outside in” to detect conditions indicative of a security vulnerability in an application in its [...]]]></description>
			<content:encoded><![CDATA[<p>We’ve just published a new <a href="http://www.gartner.com/resId=1883624">Magic Quadrant for Dynamic Application Security Testing (DAST)</a> for Gartner clients. In Gartner research, we use the term DAST to refer to testing solutions and techniques that are designed to test an application from the “outside in” to detect conditions indicative of a security vulnerability in an application in its running state.</p>
<p>DAST solutions have been around for years, so you’d might think the market is fairly static. Not at all. DAST solutions must and have evolved well beyond the security testing of back-end web applications. In order to dynamically test the next-generation of applications, new DAST capabilities are required and not all vendors support them equally.</p>
<p>Here are several areas where DAST solutions are evolving:</p>
<p><strong>(1) Dynamic application security testing as a service.</strong> The market for dynamic testing as a service is growing and some of the DAST solutions we evaluated – Qualys, Veracode and WhiteHat – only offer their solution as a service. However, many organizations tell us they prefer to use a product <span style="text-decoration: underline">and</span> a service from the DAST vendor — for example, testing their more-sensitive applications on-premises using a DAST product, and testing their less-sensitive applications via DAST as a service, or testing deployed applications as a service, with testing of applications in the QA phase of the development process using on-premises DAST products.</p>
<p><strong>(2) The ability to crawl and test Rich Internet Applications (RIA).</strong> A hallmark of Web 2.0 applications is the use of RIA, mostly in the form of JavaScript (The &#8220;J&#8221; in Ajax) and Ajax frameworks. In addition, many applications include large amounts of client-side logic in the form of Adobe Flash, Flex, and Microsoft&#8217;s Silverlight. The use of client-side RIA logic complicates how applications are crawled and how traditional DAST testing is performed, since the JavaScript and other types of code are rendered at the client, not at the server.</p>
<p><strong>(3) HTML5</strong>  More recently, interest has shifted to the use of HTML5 for RIA. HTML5 isn’t a single standard and the multiple standards that collectively represent HTML5 are at different levels of maturity and adoption. Testing HTML5 and keeping up with the fluid standards is an emerging requirement for all DAST solutions.</p>
<p><strong>(4) The ability to crawl and test applications that use other types of interfaces carried over web protocols.</strong> For example, many DAST solutions test Web services using protocols and formats, such as Simple Object Access Protocol (SOAP), representational state transfer (REST), Extensible Markup Language (XML) and JavaScript Object Notation (JSON).</p>
<p><strong>(5) Static application testing capabilities (SAST).</strong> For comprehensive application security testing, applications should be able to be tested from the <a href="http://blogs.gartner.com/neil_macdonald/2011/01/19/static-or-dynamic-application-security-testing-both/">“inside out” using static analysis and from the “outside in” using dynamic analysis</a>. Several vendors now offer organizations both DAST and SAST solutions.</p>
<p><strong>(6) Interactive Security Testing.</strong> Building on #5, some of the testing providers enable interaction between their static and dynamic security testing techniques. One of the most common ways is to instrument the application while it is being tested dynamically. This provides more detailed information (such as identifying the line of code where a vulnerability occurs and assessing the code coverage of testing). While this may not be suitable for production applications, this approach is quite useful in QA testing in order to provide more meaningful results to developers.</p>
<p><strong>(7) Comprehensive fuzz testing.</strong> Some DAST solutions are designed specifically to expand well beyond Web protocols to include non-Web protocols (for example, remote procedure calls, Server Message Block, Session Initiation Protocol [SIP] and so on) as well as data input malformation. This is especially critical for the dynamic security testing of applications used within embedded devices, such as storage appliances, telecommunications and networking equipment, directories, automated teller machines, medical devices and so on.</p>
<p><strong>(8) Testing mobile and Cloud-based applications.</strong> Ideally mobile applications would be tested with SAST and DAST; however, pure DAST testing can add value. Beyond the use of RIA and HTML5 discussed previously, most Android and iOS applications (even when written as native applications) are Web-like in nature and communicate over Web or RESTful HTTP-based protocols. At a minimum, the exposed interfaces of the applications should be testable using DAST. Many of the mobile applications communicate with cloud-based applications on the back end, which must also be tested. In addition, many applications have specific code paths for supporting mobile devices. In order to test these properly, DAST solutions must emulate a number of mobile browsers.</p>
<p>These are just a few examples of how the market for DAST solutions is anything but static. The market is evolving rapidly and requires that successful solutions here continue to adapt as well. If you haven’t evaluated DAST solutions in a while, it’s time to take another look.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/neil_macdonald/2012/01/04/the-market-for-dynamic-application-security-testing-is-anything-but-static-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security Observations from Gartner&#8217;s Data Center Summit</title>
		<link>http://blogs.gartner.com/neil_macdonald/2011/12/09/security-observations-from-gartners-data-center-summit/</link>
		<comments>http://blogs.gartner.com/neil_macdonald/2011/12/09/security-observations-from-gartners-data-center-summit/#comments</comments>
		<pubDate>Fri, 09 Dec 2011 17:37:38 +0000</pubDate>
		<dc:creator>Neil MacDonald</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Next-generation Data Center]]></category>
		<category><![CDATA[Next-generation Security Infrastructure]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[Virtualization Security]]></category>
		<category><![CDATA[GartnerDC]]></category>
		<category><![CDATA[Hypervisor Security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[vShield]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2011/12/09/security-observations-from-gartners-data-center-summit/</guid>
		<description><![CDATA[I’m just back from Gartner’s US 2011 Data Center Summit held this week in Las Vegas. In my previous post, I talked about information security vendor’s concerns on the potential impact of the Eurozone crisis on information security spending. Here, I want to outline the top security-related  issues and concerns that I discussed with attendees [...]]]></description>
			<content:encoded><![CDATA[<p>I’m just back from Gartner’s US 2011 Data Center Summit held this week in Las Vegas. In my previous post, I talked about information security vendor’s concerns on the potential <a href="http://blogs.gartner.com/neil_macdonald/2011/12/09/will-the-euro-crisis-affect-information-security-spending-2/">impact of the Eurozone crisis on information security spending.</a></p>
<p>Here, I want to outline the top security-related  issues and concerns that I discussed with attendees at the conference:</p>
<ul>
<li>Interest in securing the next-generation virtualized data center remains high with most of the questions focused on the separation of workloads of different trust levels (e.g. PCI, DMZ, dev/test) in virtualized environments. In most cases, this will involve the use of <a href="http://blogs.gartner.com/neil_macdonald/2011/08/24/its-time-for-security-to-ascend/">software-based virtualized security controls</a>. Specific to PCI, one attendee indicated their QSA had accepted PCI and non-PCI related workloads on the same physical host without all workloads being considered in scope (in this case, they used externalized physical firewall-based separation).</li>
<li>Several attendees asked if I was aware of any publicized incidents of hypervisor breaches. I’m not, but that doesn’t mean that they won’t (or haven’t) happened. <a href="http://blogs.gartner.com/neil_macdonald/2011/01/26/yes-hypervisors-are-vulnerable/">The vulnerabilities are there</a>. It will happen, it’s just a matter of time – hackers are quite aware that a successful attack at this layer represents an opportunity to penetrate the entire machine regardless of the security controls within each host.</li>
<li>I had several questions on optimizing antimalware scanning in a virtualized environment. Trend Micro has been an early innovator here with its integration <a href="http://blogs.gartner.com/neil_macdonald/2011/06/06/is-single-instance-security-the-future/">with VMware’s vShield Endpoint APIs</a>, but there are other options and approaches, each with pros and cons.</li>
<li>In terms of cloud security, most questions revolved around extending enterprise virtualized data centers to public cloud IaaS providers in hybrid scenarios and how to protect this.</li>
<li>The second most common cloud security issue discussed was the use of encryption and other approaches to securing data in the cloud. <a href="http://blogs.gartner.com/neil_macdonald/2011/07/15/seven-cloud-computing-pet-peeves/">Since cloud isn’t one thing</a>, our approaches to securing data in the cloud will be different at different layers.</li>
</ul>
<p>It was a great conference with record-setting attendance. It’s clear to me that <a href="http://blogs.gartner.com/neil_macdonald/2010/01/04/six-trends-that-will-further-reshape-information-security-in-2010/">virtualization, mobilization and cloud computing are transforming the enterprise data center</a> and that information security needs to evolve to support this. Based on the interests from attendees of the conference in information security, I’d say they feel exactly the same way.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/neil_macdonald/2011/12/09/security-observations-from-gartners-data-center-summit/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Will the Euro Crisis Affect Information Security Spending?</title>
		<link>http://blogs.gartner.com/neil_macdonald/2011/12/09/will-the-euro-crisis-affect-information-security-spending-2/</link>
		<comments>http://blogs.gartner.com/neil_macdonald/2011/12/09/will-the-euro-crisis-affect-information-security-spending-2/#comments</comments>
		<pubDate>Fri, 09 Dec 2011 16:26:17 +0000</pubDate>
		<dc:creator>Neil MacDonald</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Next-generation Data Center]]></category>
		<category><![CDATA[GartnerDC]]></category>
		<category><![CDATA[symposium]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2011/12/09/will-the-euro-crisis-affect-information-security-spending-2/</guid>
		<description><![CDATA[I’ve just gotten back from Gartner’s Data Center Conference in Las Vegas. Like Gartner’s recent US Symposium and European Symposium, the conference had record attendance and interest in information security was high. I’ll place the top security-related issues from non-vendor attendees in a separate post. On the vendor side, I had several information security providers [...]]]></description>
			<content:encoded><![CDATA[<p>I’ve just gotten back from Gartner’s Data Center Conference in Las Vegas. Like Gartner’s recent <a href="http://blogs.gartner.com/neil_macdonald/2011/10/24/us-symposium-summary-from-a-security-perspective/">US Symposium</a> and <a href="http://blogs.gartner.com/neil_macdonald/2011/11/14/security-observations-from-european-symposium/">European Symposium</a>, the conference had record attendance and interest in information security was high.</p>
<p>I’ll place the top security-related issues from non-vendor attendees in a separate post.</p>
<p>On the vendor side, I had several information security providers ask me about the potential impact of the Euro crisis on information security spending. Many of the vendors are right in the middle of their 2012 revenue forecasting and budget planning process so the question is top of mind. My recommendation to them was to bound their forecast and budgets with a worst case and best case envelope around their most likely forecast.</p>
<p>Gartner is following the developments closely and we have several resources available to clients and vendors to navigate this turbulent period. First, <a href="http://my.gartner.com/webinardetail/resId=1870520">there is a webcast planned to discuss the impact of the Eurozone crisis</a> that is open to all. Second, there is a special report being developed for Gartner clients that addresses the issue from multiple angles across all of Gartner research. The first research note for this set has already published for clients <a href="http://www.gartner.com/resId=1867317">“CIOs Should Address the Impacts of the Euro Crisis on Their Enterprises Now”.</a> Third, my European colleague has a just posted <a href="http://www.surveymonkey.com/s/2KHWYHG">a survey</a> to gather data for use in his research and his blog posts on the topic.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/neil_macdonald/2011/12/09/will-the-euro-crisis-affect-information-security-spending-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Observations from European Symposium</title>
		<link>http://blogs.gartner.com/neil_macdonald/2011/11/14/security-observations-from-european-symposium/</link>
		<comments>http://blogs.gartner.com/neil_macdonald/2011/11/14/security-observations-from-european-symposium/#comments</comments>
		<pubDate>Mon, 14 Nov 2011 12:02:14 +0000</pubDate>
		<dc:creator>Neil MacDonald</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Virtualization Security]]></category>
		<category><![CDATA[application security testing tools]]></category>
		<category><![CDATA[GartnerDC]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[symposium]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2011/11/14/security-observations-from-european-symposium/</guid>
		<description><![CDATA[I spent the last week in Barcelona with 4,000+ attendees at the 2011 Gartner European Symposium. It was a new venue for Gartner (we were displaced from Cannes by the G20), and I’m happy to say it was a fantastic with record attendance. Security was front and center of attendee interests. We had a total [...]]]></description>
			<content:encoded><![CDATA[<p>I spent the last week in Barcelona with 4,000+ attendees at the 2011 Gartner European Symposium. It was a new venue for Gartner (we were displaced from Cannes by the G20), and I’m happy to say it was a fantastic with record attendance.</p>
<p>Security was front and center of attendee interests. We had a total of 23 security sessions throughout the 4 days. Like US Fall Symposium, I was fully booked with 1-1 sessions where attendees are able to meet and discuss their issues and questions with analysts.</p>
<p>The top issues of our European attendees <a href="http://blogs.gartner.com/neil_macdonald/2011/10/24/us-symposium-summary-from-a-security-perspective/">differed from those at Gartner’s US Fall Symposim</a>. Here’s what was top of mind in Europe:</p>
<p><strong>1) Protecting information.</strong> I had a large number of discussions on how to move information security beyond just a “bottoms up” approach to information security. These organization felt they had a good handle on traditional firewalling, IPS and endpoint protection but hadn’t done much for information protection beyond encrypting laptops. In addition to encouraging them to think about <a href="http://blogs.gartner.com/neil_macdonald/2010/02/24/its-time-to-redefine-dlp-as-data-lifecycle-protection/">information security protection as a process</a>, we also discussed specific technical controls such as database activity monitoring, file activity monitoring and web application firewall/monitoring solutions.</p>
<p><strong>2) Cloud security.</strong> <a href="http://blogs.gartner.com/neil_macdonald/2011/07/15/seven-cloud-computing-pet-peeves/">Cloud isn’t one thing, security isn’t either</a>, so these discussions varied. Most were focused on how to better secure access to cloud-based services at the Software-as-a -service level. There were some questions on IaaS, but only one on securing PaaS. In that case it was a leading -edge client moving their entire business as a service provider to Microsoft’s Azure platform and we discussed encryption options within Microsoft’s Azure.</p>
<p><strong>3) Hosted Virtual Desktop</strong>  (or if you prefer, Virtual Desktop Infrastructure). In these conversations, the interest was driven primarily as a way to provide access to legacy Windows applications while maintaining control of the information. Several conversations were on the pros/cons of VDI as compared to traditional terminal services.There are strengths and weaknesses to each approach. In a separate roundtable on virtualization and security that I moderated, the preference of the attendees of the session was to use full VMs (VDI/HDV) rather than terminal services..</p>
<p><strong>4) Application security </strong>This is really a form of #1 above, but focusing on securing the applications that handle the sensitive information. Most had adopted <a href="http://blogs.gartner.com/neil_macdonald/2011/01/19/static-or-dynamic-application-security-testing-both/">some amount of security testing</a>, but were interested pushing testing further back into software development. There was a significant amount of interest in testing as a service offerings, many of which are quite inexpensive as compared to testing in house. In most of these cases, testing as a service wasn’t replacing what they were doing, just augmenting it.</p>
<p>Overall, the biggest difference I saw in the interests of European attendees from US attendees was the intense interest on specific ways and mechanisms to augment traditional “bottoms up” security mechanisms with a “tops downs” approach to protecting information. Both are needed.</p>
<p>That’s a good sign that information security organizations are understanding that in a world where IT increasingly doesn&#8217;t own or control much of the IT stack (end user device, network, server, OS, etc), our focus absolutely <a href="http://blogs.gartner.com/neil_macdonald/2009/03/12/does-securing-information-require-a-different-mindset/">must shift up to various ways to protect the information.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/neil_macdonald/2011/11/14/security-observations-from-european-symposium/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>US Symposium Summary from a Security Perspective</title>
		<link>http://blogs.gartner.com/neil_macdonald/2011/10/24/us-symposium-summary-from-a-security-perspective/</link>
		<comments>http://blogs.gartner.com/neil_macdonald/2011/10/24/us-symposium-summary-from-a-security-perspective/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 13:22:51 +0000</pubDate>
		<dc:creator>Neil MacDonald</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Beyond Anti-Virus]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Microsoft Security]]></category>
		<category><![CDATA[Next-generation Security Infrastructure]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[Virtualization Security]]></category>
		<category><![CDATA[Adaptive Security Infrastucture]]></category>
		<category><![CDATA[Context-aware Security]]></category>
		<category><![CDATA[DC-Summit-NA]]></category>
		<category><![CDATA[Endpoint Protection Platform]]></category>
		<category><![CDATA[symposium]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2011/10/24/us-symposium-summary-from-a-security-perspective/</guid>
		<description><![CDATA[Last week I attended Gartner’s US Symposium conference in Orlando. With 8,000+ attendees (25% of which were CIOs) and at least 1,000 more analysts, vendors and support staff, you can imagine it was quite a scene. In addition to three presentations, I had more than 30 fantastic one on ones with attendees over the four [...]]]></description>
			<content:encoded><![CDATA[<p>Last week I attended Gartner’s US Symposium conference in Orlando. With 8,000+ attendees (25% of which were CIOs) and at least 1,000 more analysts, vendors and support staff, you can imagine it was quite a scene.</p>
<p>In addition to three presentations, I had more than 30 fantastic one on ones with attendees over the four days.</p>
<p>What was hot? Many of the same issues I blog about. In order of priority, most attendee discussions were on:</p>
<p>1) Endpoint security, <a href="http://blogs.gartner.com/neil_macdonald/2011/07/19/the-key-to-successful-application-control-is-not-to-control-applications/">application control and whitelisting.</a> Microsoft is causing significant disruption in this market with its <a href="http://blogs.gartner.com/neil_macdonald/2011/08/04/microsofts-forefront-endpoint-protection-is-it-good-enough/">new version of Forefront Endpoint Protection</a> and its change in licensing policies.</p>
<p>2) Strategies for <a href="http://blogs.gartner.com/neil_macdonald/2011/07/11/sand-castles-and-advanced-persistent-threats/">protection against Advanced threats</a> (note that this overlaps with #1 a bit)</p>
<p>3) Security trends – what are the major trends we are seeing in information security and are they missing anything? What investments should we be thinking about for 2012?</p>
<p>4) Virtualization and security – trust/assurance of the hypervisor for separation of workloads of different trust levels as well as protecting VMs as they move offsite into Cloud-based providers.</p>
<p>Surprisingly, I only had one or two conversations on application security – specifically looking for best practices to push security testing further back in the SDLC.</p>
<p>In terms of “Cloud”, I think most organizations are moving beyond the ill-defined hype of “cloud security” and looking for specific advice and best practices for addressing specific cloud-related computing concerns. That’s a welcome step forward. <a href="http://blogs.gartner.com/neil_macdonald/2011/07/15/seven-cloud-computing-pet-peeves/">Cloud is a computing style, not a location.</a> It’s great to see people embrace this computing style and look to proactively build security in. Thursday afternoon’s presentation on securing private clouds had a good crowd for the final day. The biggest reaction was on the evolution of security <a href="http://blogs.gartner.com/neil_macdonald/2010/12/01/securing-private-clouds-requires-changes-to-information-security-infrastructure/">to a set of software-based services delivered by programmable infrastructure.</a> I think most IT security professionals have become so accustomed to their firewalls as a physical box, they have a difficult time <a href="http://blogs.gartner.com/neil_macdonald/2011/08/24/its-time-for-security-to-ascend/">imagining firewall services decoupled from the physical hardware underneath</a> and shifting to security policies based on logical, not physical, attributes. Indeed, I believe the biggest challenges to the security of private clouds will be related to cultural and mindset change issues, not technical.</p>
<p>If you follow my thoughts from the conference on <a href="http://twitter.com/#!/@nmacdona/">twitter (@nmacdona),</a> you’ll see some of the feedback on my context-aware security presentation.Despite losing AC during the presentation (not good in Florida, even in October!), the crowd stuck it out with some hanging out in the doorways to watch the presentation and catch a breeze at the same time.</p>
<p>As I have discussed previously many times, all of <a href="http://my.gartner.com/portal/server.pt?open=512&amp;objID=260&amp;mode=2&amp;PageID=3460702&amp;id=1369721&amp;ref=clientFriendlyUrl">information security is becoming context-aware and adaptive</a> and this attribute will be a key characteristic of all next generation security offerings (<a href="http://blogs.gartner.com/neil_macdonald/2011/10/13/next-gen-context-aware-intrusion-prevention/">IPS</a>, FW, endpoint protection, IAM, DLP, and so on).</p>
<p>Overall, it was another great Symposium conference (my 15th with Gartner!). They just keep getting better. For those of you that didn’t make it, I’m attending <a href="http://www.gartner.com/technology/summits/na/data-center/">Gartner’s upcoming US Data Center summit in December in Las Vegas</a> and we can catch up there.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/neil_macdonald/2011/10/24/us-symposium-summary-from-a-security-perspective/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Next-gen Context Aware Intrusion Prevention</title>
		<link>http://blogs.gartner.com/neil_macdonald/2011/10/13/next-gen-context-aware-intrusion-prevention/</link>
		<comments>http://blogs.gartner.com/neil_macdonald/2011/10/13/next-gen-context-aware-intrusion-prevention/#comments</comments>
		<pubDate>Thu, 13 Oct 2011 13:40:58 +0000</pubDate>
		<dc:creator>Neil MacDonald</dc:creator>
				<category><![CDATA[Next-generation Security Infrastructure]]></category>
		<category><![CDATA[Security Intelligence]]></category>
		<category><![CDATA[Adaptive Security Infrastucture]]></category>
		<category><![CDATA[Context-aware Security]]></category>
		<category><![CDATA[Endpoint Protection Platform]]></category>
		<category><![CDATA[symposium]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/neil_macdonald/2011/10/13/next-gen-context-aware-intrusion-prevention/</guid>
		<description><![CDATA[Context-aware security is the use of supplemental information to improve security decisions at the time the decision is made. The goal? More-accurate security decisions capable of supporting more-dynamic business and IT environments as well as providing better protection against advanced threats. In this 2010 research note that provided a definition and framework for understanding context-aware [...]]]></description>
			<content:encoded><![CDATA[<p>Context-aware security is the use of supplemental information to improve security decisions at the time the decision is made. The goal? More-accurate security decisions capable of supporting more-dynamic business and IT environments as well as providing better protection against advanced threats.</p>
<p>In this 2010 research note that provided a definition and framework for understanding context-aware security <a href="http://www.gartner.com/resId=1369721">The Future of Information Security is Context Aware and Adaptive</a>, I used the term “next-generation IPS” to describe how advanced intrusion prevention systems were becoming context aware in order to make improved security decisions (faster, more accurate and better suited to detect advanced threats).</p>
<blockquote><p>Network security solutions are evolving to incorporate &#8220;application awareness&#8221; and &#8220;identity awareness&#8221; into their offerings. Information protection solutions are evolving to deliver &#8220;content awareness.&#8221; Application, identity and content awareness are all part of the same underlying shift to incorporate more context at the point when a security policy enforcement decision is made.</p></blockquote>
<p>In the research note, I provided several examples of how information security infrastructure was evolving to become context-aware, including next-generation IPSs:</p>
<blockquote><p>Intrusion prevention systems (IPSs) — Rather than apply all IPS rules to all traffic flows, next-generation IPS systems are able to use real-time contextual knowledge of what version of an OS or application a workload is running and what vulnerabilities are present in the systems they are protecting (for example, Real-time Network Awareness (RNA)/Real-time User Awareness (RUA) integration with Sourcefire). This context improves the speed and accuracy of IPS decisions, allowing more-efficient use of processing resources, as well as reducing the chance of false positives.</p></blockquote>
<p>We’ve just published <a href="http://www.gartner.com/resId=1818521">this research note for clients</a> that outlines the key attributes of a next-generation IPS. Context-awareness in the form of application, identity, content and environmental awareness is the foundation for a next-generation IPS.</p>
<p><a href="http://blogs.gartner.com/neil_macdonald/tag/context-aware-security/">As I have observed several times</a>, <strong>all information security infrastructure must become context-aware </strong>– endpoint protection platforms, access control systems, network firewalls, IPS systems, security information and event management systems, secure web gateways, secure email gateways, data loss prevention systems … all of it.</p>
<p>The shift to incorporate “application awareness”, “identity awareness”, “virtualization awareness”, “location awareness”, “content awareness” and so on are all facets of the same underlying shift in information security infrastructure to become context-aware.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/neil_macdonald/2011/10/13/next-gen-context-aware-intrusion-prevention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

