Securosis

Research

The Future Of Information-Centric Security: From Data Loss Prevention to Content Monitoring and Prot

Over the past couple of weeks Mike Rothman has been posting his Security Incites, a series of predictions for 2008. Prediction number 9 was titled, “Get the Jumper Cables for DLP”, and I, of course, have to disagree with at least some of it. There are three reasons I spend a lot of time talking about DLP so much here on the blog. First, I think it’s one of the least understood security technologies on the market, yet one with high value when used properly. There’s a lot of confusion out there, and I think I provide more value by clearing that up than by talking about more established technologies. Second, DLP was one of the first technologies I covered as an analyst, long before there was an established market. I have something like 6 years invested in it, which is longer than most of the people working at most of the vendors. Can’t let that go to waste. Finally, it’s because I do believe that what we now call DLP with form the core of a significant chunk of our information-centric (data) security moving forward. Rather than pick through Mike’s prediction I’m going to take this opportunity to start laying out the evolution of DLP so you can make your own decisions as to where we’re headed. Since I’m still recovering from my shoulder surgery and only running at about 60-70%, this series will consists of a bunch of shorter posts rather than my usual long-winded Hoffesque diatribes. Sidebar: Why DLP is a bad name: When I first started covering this market we had a hard time deciding what to call it. I even once had a conference call with the two leading competitors to try and hash out a term. I picked Content Monitoring and Filtering, which I now use to describe the second phase of the technology, While it wasn’t sexy, I felt that the tools offered a lot more than just “data leak prevention”, and that such a generic term could be easily co-opted by other data protection technologies, like encryption. For once I was right- everything from USB port blockers to digital rights management calls itself DLP these days, confusing customers, while the “DLP” solutions have added discovery, classification, and other capabilities well beyond mere leak prevention. A Three Phase Evolution I believe we’ll see three phases in the evolution of this technology over the next 5-7 years. While the technology itself will evolve more quickly than that, the realities of the market, new technology adoption, and deployment practicalities mean we won’t see complete, mainstream deployments until the latter part of that timeframe. Don’t read that the wrong way- most, probably all of you will deploy much of DLP/CMP over the next 5 years, but only the early mainstream will achieve the full vision I’m describing by then. At that point your organization will be more of a limiting factor than the technology. If you want it. it will be there. The three phases we’re seeing are: Data Loss Prevention: Although most people call today’s solutions DLP, the leading solutions have all moved well beyond this phase of the market. I still have to use the term so people know what I’m talking about, but the top solutions are already in the next phase. DLP solutions are characterized by protecting predominantly data in motion (including USB transfers). These are true “leak/loss prevention” only solutions. Content analysis techniques tend to be more basic, sometimes limited to just regular expressions/rules combined with a little context. Content Monitoring and Filtering: In this phase we see more robust solutions; with protection for data in motion, at rest, and in use. The tools are more widespread, covering all major channels from network, to endpoints and storage. Content analysis techniques are more advanced, with (at a minimum) regular expressions/rules, partial document matching, and database fingerprinting (exact data matching). Content Monitoring and Protection: In this final phase (okay, it’s just as far out as I’m comfortable predicting) the technology becomes ubiquitous is user productivity applications and communications. Enterprise DRM is integrated and content is classified at the point of creation. Advanced content analysis techniques become more effective, better allowing us to classify more complex data, taking into account business context. Data is protected through its lifecycle. Here’s an easier way to think about it: DLP is about preventing basic leaks of easy to identify sensitive content. With CMF, we start protecting a wider range of content, and putting controls in place before it’s already trying to fly out the door. With CMP, we have cradle to grave content classification and protection. This is just a top level overview. Over the next several posts I’ll detail more of the specifics of each phase. I consider this complementary to my series and paper on Understanding and Selecting a DLP Solution. That series focused on helping you pick and deploy a tool today, while this series will help you navigate the waters as the tools and market evolve and you make upgrade and deployment decisions. Hmm… I smell another paper coming… < p style=”text-align:right;font-size:10px;”>Technorati Tags: CMP, Data Loss Prevention, Database Security, DLP, Content Monitoring and Protection Share:

Share:
Read Post

Understanding and Selecting a Database Activity Monitoring Solution: Part 4, Alerts, Workflow, and R

It seems that every time I write the next part of this multipart series I find myself apologizing for taking too long between posts. I swear I have a good excuse this time- with the whole doctor sticking cameras into my shoulder, shaving out bits, cutting tendons and tying them to new places, putting in plastic anchors, and sewing torn parts of muscles together thing. I’m 11 days into my recovery and while the days are fine, despite learning not to use my arm for the next three months, the nights… let’s just say I fear the nights. I think I’m getting closer to figuring out the right combination of drugs, body position, and pillows that will let me get a little closer to some functional sleep. But business is good, I’m gaining a little more productivity every day, and… enough about me. In today’s post we’re going to delve deeper into Database Activity Monitoring. We’re going to talk about alerting, workflow, and reporting. In my previous post we discussed central management, including policy creation. One of the key advantages of DAM over passive auditing and logging solutions is the ability to define policies for active alerts and manage remediation. While policies are mostly deployed in a passive mode (alerting only) some products also support active blocking, which we will cover in a future post. I’m really not a fan of relying on passive auditing for security; it’s often important, but with the tools we have today we can generate immediate alerts allowing us to contain security incidents before they spread, or even stop a multi-stage attack before completion. This is one key characteristic separating proactive security tools from simple monitoring/logging tools. Alerts Your DAM tools should support both active alerting and an incident handling queue, similar to DLP. These alerts take a few different forms, from email integration, to self-contained events, to communications with outside security tools (like SIEM) using anything from SNMP to syslog to proprietary integration. Policies should support granular alerting based on conditions, such as thresholds. For example, detection of a single errant query might trigger a low level incident within the included incident handling system, while an incident involving an administrator or high count of credit cards is emailed to a security admin and dropped into the SIEM tool as a high alert. Not to say you should rely on a SIEM or other external tool to manage your incidents; those tools will never contain the full context and investigative abilities of the dedicated DAM workflow. External alerts play a valuable role in escalating incidents and correlating with external factors, but the primary handling will tend to be managed within the DAM tool itself. Databases are complex beasts, and full understanding of what’s going on internally requires a dedicated tool. Policy based alerts tend to fall into two or three interrelated categories which often overlap: User activity: Incidents when a user takes an action that violates policy. It could be a user running a query on sensitive data, updating an existing financial transaction outside of an application, or an application running a query never seen before. Attack activity/signatures: Some DLP solutions include pre-built detection for certain attack activity. This may be linked to vulnerability analysis, signature based, or heuristic (I’m sure some vendors will chime in with even more options). System and administrative activity: Incidents involving administrative or internal system activity. E.g. new account creation, privilege escalation, DML/DDL changes, system updates. stored procedures, or other configuration changes. Think of these alerts as being focused on SQL (and non-SQL) outside of simple SELECT, INSERT, UPDATE, DELETE queries. Workflow Once an incident is created and any external alerts sent out, it should appear in an incident handling queue for management. This is similar to what we see in DLP and many other security tools, but optimized for database activity. The queue should be visually well-designed to make critical information easier to find, and allow customization for different work styles and interests. Unlike DLP, it’s less important that the queue appeal to non-technical handlers since it’s far less likely that anyone without database and security knowledge will work directly within the system. For DAM, we tend to rely more on reports for the auditors, risk managers, and other non-security types. Incidents should be easy to sort and include color coding for sensitivity and criticality. When you click on an incident, it should let you drill down into more details to assist the investigative process. Handlers should be able to assign, share, and route incidents to different users within the system. I’m a big fan of having a drop down field to change incident status right on the incident row. The system should also support role based administration, allowing you to assign specific handlers/administrators based on the policy violated, database affected, or other factors. The basic workflow must allow for quick sorting, analysis, and investigation of incidents. Once an incident is detected, the handler can close it, add supporting investigative material, change the priority, assign it to someone else, or escalate it. To support investigations you should be able to correlate the current incident with other activity in that database by that user, violations of that policy across different systems, and other factors to help determine what’s going on. Since incident handlers may come from either a database or a security background, look for a tool that appeals to both audiences and supplies each with the information they need to understand the incidents and investigate appropriately. My description has so far focused on database-only incidents, but some systems are now expanding into platform activity on the database host, or application activity. Reports As with nearly any security tool you’ll want flexible reporting options, but pay particular attention to compliance and auditing reports to support compliance needs. Aside from all the security advantages we’ve been talking about, many organizations initially deploy DAM to meet their database audit and compliance requirements. Pre-built report templates can save valuable time, and some vendors

Share:
Read Post

Ask Securosis: Is Safari Less Secure?

This week, our question is courtesy of Allen: … As a long time Mac user and an inspiring security professional (i am in the process of completing my CISSP certification), I found this article on Macworld’s web site to be very fascinating. If you could please comment on this on your web site and/or on your podcast would be very grateful. The article in question, located here, is a very odd interview with Michael Barrett, PayPal’s chief information security officer. Michael argues that the main reason Safari is less secure is its lack of anti-phishing features or support for Extended Validation SSL certificates. For you non-geeks, those are extra, higher cost, digital certificates that highly trusted websites can buy to prove they are who they say they are. A few snippets: “Apple, unfortunately, is lagging behind what they need to do, to protect their customers,” Barrett said in an interview. “Our recommendation at this point, to our customers, is use Internet Explorer 7 or 8 when it comes out, or Firefox 2 or Firefox 3, or indeed Opera.” … Unlike its competitors, Safari has no built-in phishing filter to warn users when they are visiting suspicious Web sites, Barrett said. Another problem is Safari’s lack of support for another anti-phishing technology, called Extended Validation (EV) certificates. This is a secure Web browsing technology that turns the address bar green when the browser is visiting a legitimate Web site. When it comes to fighting phishing, “Safari has got nothing in terms of security support, only SSL (Secure Sockets Layer encryption), that’s it,” he said. … Still, Barrett says data compiled on PayPal’s Web site show that the EV certificates are having an effect. He says IE 7 users are more likely to sign on to PayPal’s Web site than users who don’t have EV certificate technology, presumably because they’re confident that they’re visiting a legitimate site. Over the past few months, IE 7 users have been less likely to drop out and abandon the process of signing on to PayPal, he said. “It’s a several percentage-point drop in abandonment rates,” he said. “That number is… measurably lower for IE 7 users.” This is complete and utter bunk. I’d like to reference an article at Dark Reading, on anti-phishing, and this one about a Harvard/MIT study: APRIL 13, 2007 | The lock-and-key icon was broken. The site-authentication image was not there. A security message popped up, warning that the site was not properly certified. And still, more than half of them entered a password and tried to log in. That’s the bottom-line finding of a new study from researchers at Harvard University and MIT, who conducted a live test of banking users to measure the effectiveness of browser-based authentication and anti-phishing features earlier this year. The research is scheduled to be presented at the IEEE Symposium on Security and Privacy next month. PayPal is completely off base- I highly doubt the lack of anti-phishing features correlates in any material way to Safari users dropping out of the sign in process. The level of assumptions in those statements is ridiculous. Now, let’s look at Safari. The truth is, based on talking with security researchers. that IE7 on Vista is more fundamentally secure than Safari. I’m not sure about Firefox, but suspect it is also probably more fundamentally secure. But that almost doesn’t matter- the real world risk, today, of using Safari is extremely low. That could change instantly, at any given time, and probably will, but until then I feel comfortable using it for most of my browsing needs. A bigger hole with Mac (or PC) browsing is QuickTime, which is in the midst of some rough times from a security perspective. But QuickTime runs in any browser, not just Safari. My overall take? Most users don’t understand or care about anti-phishing notifications built into their browsers. Safari does lack security features available in competitors, and has had a few vulnerabilities this year, but real-world risk is low for now. Support for extended validation certificates is a nice to have feature, but probably won’t improve Safari security for the average user in any material way. Not that we shouldn’t keep the pressure on Apple to keep strengthening the OS and browser, but I’d prefer they put more effort into sandboxing and other anti-exploitation defenses than little green borders when I visit someone willing to cough up an insane amount of cash to Verisign. < p style=”text-align:right;font-size:10px;”>Technorati Tags: Apple, Mac, PayPal, Phishing, Security Share:

Share:
Read Post

Curphey on BPM

Today, Mark Curphey posted about Tenets of Effective BPM. He lays out five high level principles for doing business process management. This is really great stuff. It’s so good, in fact, that I’m going to quote a huge chunk of his post here: 1. Understand and Documenting the Process Effect: Implement a Structured and Effective Information Security Program 2. Understand Metrics and Objectives Effect: Understand Success Criteria and Track Effectiveness 3. Model and Automate Process Effect: Improve Efficiency and Reduce Cost 4. Understand Operations and Implement Controls Effect: Improve Efficiency and Reduce Cost Effect: Fast and Accurate Compliance and Audit Data (Visibility) 5. Optimise and Improvement Effect: Do More With Less Effect: Reduce Cost Notice that none of the above is specific to security, but if you apply them you do get security and compliance benefits. Also, you recover cash for use with other projects without having to ask for more cash, which always makes you more popular with the CIO and CFO. Perhaps most importantly, this type of behavior enables you to demonstrate that IT Security is taking on a business oriented focus, which is good for your career and for raising the exposure of InfoSec at the executive level. It’s like the old maxim, dress for the job you want to have; you have to act like the executive you want to be treated as. Share:

Share:
Read Post

Network Security Podcast, Episode 95 Up

Boy- never get shoulder surgery if you can avoid it. Although I can type, the pain, lack of sleep, and other restrictions probably have me down to 50% productivity. No fun when you work for yourself. Trying to not use my right arm for any lifting, pulling, pushing, or reaching for the next 3 month swill be an interesting prospect. This week on the podcast Martin and I get caught up and cover a wide range of news items- from the encryption news last week, to the CLEAR airport security scam. As always, the episode is available at netsecpodcast.com. < p style=”text-align:right;font-size:10px;”>Technorati Tags: Network Security Podcast Share:

Share:
Read Post

Want To Win Free Debix Identity Theft Protection For A Year?

Securosis is very pleased to announce that Debix is providing a year of free credit protection to three lucky readers. Those of you who read this site and listen to the Network Security Podcast know that I’m a big fan of preventative credit protection instead of just passive monitoring. I’ve been using Debix for a few months now and am extremely pleased with the service. Normally I never pick one vendor over the other, but there are only two providers in this market, and LifeLock has a sordid history. Debix works by placing a fraud alert on your credit report with all three agencies. They automatically renew these every three months, and instead of listing your personal information all calls to open new credit on your account are routed to the Debix call center, which then tracks you down on different contact numbers. Any time someone contacts a credit agency to try to open an account in your name, you get a phone call to authorize it. It’s anti-exploitation for your credit history. To back this up, you get $25,000 of identity theft coverage and recovery services. They also add you to the national Do Not Call list and opt you out of pre-screened credit offers. Here’s how the contest will work- In the comments, tell us a story of how you’ve been a victim of fraud. Real stories only, and you have to use an email address you check, even if it’s just an anonymous Gmail account. It can be any type of fraud, humorous or serious, from card skimming to identity theft. The Securosis staff (Dave, myself, and Chris, even though he doesn’t know it yet) will pick the three winners, announce them on the site, and privately connect you with our contact at Debix to get your account started. Our families are excluded, as are those of my friends who are essentially family (sorry, have to be fair). Tom is excluded since he made fun of the blog today and called me a slacker (okay, you can submit under a random email as long as I can’t figure out it’s you). This is limited to the US, since that’s the only place it works. I’m really excited about this opportunity and we’ve been working on it for a couple of months. Debix is a great service and cheaper than most of the credit monitoring out there. So get running in the comments. We’re looking for real examples of how fraud has hurt you in your past. (Full disclosure- Debix is providing the award but is not otherwise sponsoring this contest. I currently have a free Debix trial that was provided before we came up with the contest, but have no business relationship with them). < p style=”text-align:right;font-size:10px;”>Technorati Tags: Debix, Fraud, Identity Theft, Contest Share:

Share:
Read Post

DLP Article In Information Security Magazine Now Online

I really don’t see the appeal of the whole drug thing. I’ve never been into recreational drugs other than alcohol, and even that I prefer in moderation. By “never been into” I mean never tried. Nope- didn’t hold it, didn’t inhale. Last week after my shoulder surgery I was on reasonably heavy pain meds. I couldn’t think, couldn’t focus, couldn’t even read or watch a full length movie. I still had plenty of pain, barely slept, and definitely didn’t notice much happy in the little pills. Friday, after a client mentioned her husband bailed on the meds the first week, I went cold turkey during the days and almost immediately felt better. I still need a little at night to sleep, but boy am I glad to be off that stuff. I’d like to say I’m tanned, rested, and ready for action, but I’m really pale (as always), tired, and gimpy. That said, it’s great to be back at work; one of the advantages of having a job you love. Another advantage, for some of us at least, is that articles we write weeks or months earlier still get published even if we’re out of action. This month I wrote the DLP feature for Information Security Magazine. It’s all new content, although some of it will look familiar to any of you who read my DLP manifesto. On Wednesday I’ll be giving a companion webcast over at SearchSecurity. Hopefully it looks good in print, I still don’t have a copy myself. Anyone have a copy to send to my mom? Thanks again to everyone who supported (and continues to support) me through this surgery. Share:

Share:
Read Post

Evaluating And Protecting Yourself From The Cold-Boot Encryption Attack

Even in my drug-addled state last week it was hard to miss the cold boot encryption attack released by Ed Felten and the Princeton Center for Information Technology Policy. This is some seriously impressive work with major implications, but despite all the articles I’ve seen there has been little information on how to evaluate and mitigate your personal or organizational risk. That’s where I come in. I’m not going to assume you know a lot about file and media encryption, so we’ll start with en explanation of how, and why, the attack works. Then we’ll evaluate the risk and discuss mitigation strategies. I’ll close with some suggestions for vendors to close out this vulnerability. And yes, this works on a Mac with FileVault. What is the cold boot attack and how does it work? All encryption systems need access to a key to encrypt and decrypt data. It doesn’t matter what you’re encrypting- a hard drive, file, database, or whatever, you need a key. When encrypting and decrypting data, because of how computer systems are designed, the key always passes through memory at some point. For smaller content this is a transient process and the key is only in memory for a short time (assuming the software is designed properly), but when you need constant access to data the key is kept in memory. This is nearly ubiquitous for full-disk encryption or file encryption systems that leave files open for read/write operations. It’s not something we worried about, because when you turn a computer off the RAM (memory for the non geeks) loses power and anything stored is lost. Thus we would password protect our encrypted systems so that even if they wake up from sleep mode, an attacker would have to reboot the system unless they had the key, confident this process would erase the key from memory and keep the data secure. What the Princeton researchers demonstrated is that modern RAM doesn’t degrade immediately after power is removed. The contents of memory can persist from seconds to minutes, and that time extends when cold is applied to the memory. An easy way to do this is to just use a can of dust off spray. That’s the first part of the attack- keeping the contents in memory after the system is shut down. For the second part of the attack they use a special tool, which they haven’t made public, to recover memory contents from RAM. In the demo this tool is on a bootable USB drive, so merely rebooting the computer from this USB stick, ignoring the host operating system of the computer, allows them to scan memory and recover the encryption key. Additional work allowed them to recover a full key even if a few bits were lost as the memory degraded. To execute the attack, the attacker opens the computer, sprays the memory with an upside-down can of dust off to cool it, then reboots off the USB device with their software for key recovery on it, thus recovering the keys and gaining access to the data. If you use a boot password or something similar they perform the same attack, but remove the memory and place it into a different system for key recovery. Thanks to the cold spray you have more than enough time to pull this off. Evaluating the Risk There are no public tools for this attack but it’s only a matter of time. Your immediate risk is low, but don’t be surprised if tools appear reasonably soon. This is a serious vulnerability, with a probability of attack that only increases over time. In other words, don’t panic, but keep your eyes open. Once a public tool appears it’s time to be more concerned. The researchers outline how most current protection techniques only partially, if at all, mitigate this flaw. Since memory can be removed, BIOS locks and other restrictions are ineffective. You are only at risk when your computer is powered on or in sleep mode and you lose physical control of it. Powering off your system begins the memory degradation process and you are safe within a few minutes. Reducing Your Risk The most effective method is to power off your system completely (not sleep or hibernate mode) when it’s at risk of physical loss. This is inconvenient, but I’m going to start powering off when I’m in higher risk areas (like airport security) and can’t maintain physical control of the system. Which brings recommendation number 2- don’t let someone steal your computer. I personally maintain physical control over my system nearly all the time when it’s out of my home (and I have a pretty good security system there). At hotels is the greatest risk, and I do tend to power off when I’m out of the room. You sales guys should start getting into the habit of not using sleep mode when you leave your computer locked in a rental car. At least until the encryption and laptop vendors come up with alternative protections. For those of you with very sensitive information, combine file and folder encryption for sensitive files with your whole disk encryption. A few vendors offer this (feel free to brag in the comments guys). Just close those sensitive files or images before entering sleep mode, and make sure they are password protected and not linked to your normal login credentials. Also consider an encryption system that supports storing the keys on a smart card (not in memory). I don’t believe there are many practical options today, but expect to see them crop up thanks to this paper. Finally, ask your vendor their plans to manage this risk. Today it’s not a big deal, but we don’t know if it will be 2 weeks, 2 months, or two years before public tools appear (and it’s safe to assume some governments have this by now – or more accurately, it would be unsafe and foolish to assume any government does note have this capability by

Share:
Read Post

Off Topic: Quick Update

Just a quick update to say all is well, if a bit painful. On Monday I had shoulder surgery to repair a moderate tear to my cartilage in the shoulder (the superior labrum, to be specific). Turns out the tear was a series of tears and I also managed to injure my rotator cuff. The 20 minute procedure took about an hour (still minor in the scheme of things) and my recovery will take a little longer than expected. The worst part is this week as I get past the initial pain, after that everything should be on track. I want to thank Chris Pepper (who starts a new job in a couple of days) and Dave Mortman for keeping an eye on the blog and contributing new content. Hopefully I’ll be able to convince Dave to keep contributing after I’m back full time. Dave is one of those rare individuals who can combine the practical and the theoretical in security, and has held the management positions to actually execute his theories. I’ll be taking it easy for another couple of days, but I’m past the hump and have a full schedule next week. Thanks for all the support, and we’ll be back to encryption, DAM, and all your favorite acronyms before you can say “Vicodin”. Share:

Share:
Read Post

Interview With Mike Rothman, Part 2

It’s Wednesday, and if my doctor’s predictions are correct I might be in front of the keyboard for an hour at a time today. Odds are I’m now in a recliner, watching bad TV, staring wistfully at my Guitar Hero Les Paul leaning against the entertainment center. You may think you’ve won Slash, but once my recovery is complete I’ll be more powerful than you can possibly imagine. And I’m not even on the meds yet. Yesterday Mike and I talked about his 2008 predictions around network security. Today we’ll talk about my favorite area, information-centric security, and educating consumers. This brings us to another step-child of the security world, Data Loss Prevention (DLP). You’re predicting a stall, although I’d argue it’s been stalled for years with only about $70M in revenue in 2007. What’s your unva ished opinion of DLP- do you think it provides value other than preventing those accidental emails? What if we include content discovery? You could probably make a case that the DLP business never even got started. The fact is it had the law of small numbers working in its favor. The entire market could grow at 80-100% when it was small. Now it’s a bit bigger and it’ll be a lot harder to show accelerating growth. Also combine that with the number of deals we saw last year and the fact that it does take time for small nimble start-ups to find their sea legs in the morass of a big security or storage player, and things look pretty dark for DLP in 2008. Your second question is a bit more interesting. I do believe that there is value in the promise of DLP. We need to start thinking about the data and how it’s used and where it goes. I just don’t think the current deployment models really reflect the answer to the customer problem. Sure, if you are worried about an account number or a SS# being sent out, the existing products work fine. But they don’t give you persistent control of your data assets, and I think that’s really the problem that customers need to address. Unfortunately this may be the biggest problem in all of IT. There are no simple answers to solve that one. DLP is one of the few tools that focus on data security, or “information-centric” security, depending on who you talk to. You do predict greater focus on database security in 2008, but what’s your opinion for the long haul? Will we migrate away from networks and hosts as the focus of security? Or is there too much momentum with too many big companies tied to our current model to expect changes anytime within the next 3-5 years? Database security is a feature. If the databases weren’t so security tone-deaf, there wouldn’t be a need for this technology at all. But they are, so there is. Over time, a portion of the functions get subsumed into the DBMS, a portion into the security management platform (log analysis and monitoring) and some into the network (intelligently blocking direct database attacks). Though that is truly a long term vision. 5-7 years, best case. The existing database security market has a lot of running room as these other things fall into place. I don’t think we’ll ever be able to neglect network and host security. A layered security model is really the only way to protect yourself from attacks we can’t even envision. That being said, we need to do a lot better job securing the data. The fundamental element of data, in terms of how it’s used and where it goes. As I mentioned before, that is a really big problem. Looking at the database traffic is a start. It’s not the long term answer, but it adds another layer of protection. Last year you published the Pragmatic CSO. I think one thing that’s always made you stand out as an analyst is this focus on practicalities. I find myself recommending the book to someone almost weekly since there are so few just-get-it-done approaches to security. Why do you think we make our lives so much more complicated than they need to be, and what inspired you to finally write the P-CSO? I wrote the P-CSO because I was frustrated. Security folks just don’t understand basic business realities and practices and it is hurting them. They can’t relay the value of what security does and they don’t understand how to play the game to get things done. If anything, I’ve screwed up a lot of things in business and I thought I could provide some perspective that someone who spent their entire career managing firewall rules could appreciate. Especially as they are about to get in front of the Board of Directors and tell them why they aren’t going to be the next TJX. That’s the thing about the P-CSO. It’s not a technology book. It’s a philosophy book. How security professionals need to think about the business of security moving forward. I really believe it’s the difference between success and failure. You’re trying to do something similar for consumers with Security Mike; how’s that project going? Security Mike is going well, but I haven’t put the cycles behind it that it deserves. I’ll be spending a lot more time with that project throughout this year. Security Mike is a big idea. If we can train the consumers out there to protect themselves more effectively, we cut off the oxygen that the hackers breathe. Yes, that’s a long term goal, but you have to start somewhere. The first hundred, then the next thousand, then ten thousand. If we can remove the low hanging fruit, the economic model of Internet fraud changes. The bad guys need to work a lot harder to make the same income. That’s the vision. Thanks a lot for your time today. One last question, is it true someone sent you a holiday card addressed to “Mike Rothman and The Boss”? How did THAT

Share:
Read Post

Totally Transparent Research is the embodiment of how we work at Securosis. It’s our core operating philosophy, our research policy, and a specific process. We initially developed it to help maintain objectivity while producing licensed research, but its benefits extend to all aspects of our business.

Going beyond Open Source Research, and a far cry from the traditional syndicated research model, we think it’s the best way to produce independent, objective, quality research.

Here’s how it works:

  • Content is developed ‘live’ on the blog. Primary research is generally released in pieces, as a series of posts, so we can digest and integrate feedback, making the end results much stronger than traditional “ivory tower” research.
  • Comments are enabled for posts. All comments are kept except for spam, personal insults of a clearly inflammatory nature, and completely off-topic content that distracts from the discussion. We welcome comments critical of the work, even if somewhat insulting to the authors. Really.
  • Anyone can comment, and no registration is required. Vendors or consultants with a relevant product or offering must properly identify themselves. While their comments won’t be deleted, the writer/moderator will “call out”, identify, and possibly ridicule vendors who fail to do so.
  • Vendors considering licensing the content are welcome to provide feedback, but it must be posted in the comments - just like everyone else. There is no back channel influence on the research findings or posts.
    Analysts must reply to comments and defend the research position, or agree to modify the content.
  • At the end of the post series, the analyst compiles the posts into a paper, presentation, or other delivery vehicle. Public comments/input factors into the research, where appropriate.
  • If the research is distributed as a paper, significant commenters/contributors are acknowledged in the opening of the report. If they did not post their real names, handles used for comments are listed. Commenters do not retain any rights to the report, but their contributions will be recognized.
  • All primary research will be released under a Creative Commons license. The current license is Non-Commercial, Attribution. The analyst, at their discretion, may add a Derivative Works or Share Alike condition.
  • Securosis primary research does not discuss specific vendors or specific products/offerings, unless used to provide context, contrast or to make a point (which is very very rare).
    Although quotes from published primary research (and published primary research only) may be used in press releases, said quotes may never mention a specific vendor, even if the vendor is mentioned in the source report. Securosis must approve any quote to appear in any vendor marketing collateral.
  • Final primary research will be posted on the blog with open comments.
  • Research will be updated periodically to reflect market realities, based on the discretion of the primary analyst. Updated research will be dated and given a version number.
    For research that cannot be developed using this model, such as complex principles or models that are unsuited for a series of blog posts, the content will be chunked up and posted at or before release of the paper to solicit public feedback, and provide an open venue for comments and criticisms.
  • In rare cases Securosis may write papers outside of the primary research agenda, but only if the end result can be non-biased and valuable to the user community to supplement industry-wide efforts or advances. A “Radically Transparent Research” process will be followed in developing these papers, where absolutely all materials are public at all stages of development, including communications (email, call notes).
    Only the free primary research released on our site can be licensed. We will not accept licensing fees on research we charge users to access.
  • All licensed research will be clearly labeled with the licensees. No licensed research will be released without indicating the sources of licensing fees. Again, there will be no back channel influence. We’re open and transparent about our revenue sources.

In essence, we develop all of our research out in the open, and not only seek public comments, but keep those comments indefinitely as a record of the research creation process. If you believe we are biased or not doing our homework, you can call us out on it and it will be there in the record. Our philosophy involves cracking open the research process, and using our readers to eliminate bias and enhance the quality of the work.

On the back end, here’s how we handle this approach with licensees:

  • Licensees may propose paper topics. The topic may be accepted if it is consistent with the Securosis research agenda and goals, but only if it can be covered without bias and will be valuable to the end user community.
  • Analysts produce research according to their own research agendas, and may offer licensing under the same objectivity requirements.
  • The potential licensee will be provided an outline of our research positions and the potential research product so they can determine if it is likely to meet their objectives.
  • Once the licensee agrees, development of the primary research content begins, following the Totally Transparent Research process as outlined above. At this point, there is no money exchanged.
  • Upon completion of the paper, the licensee will receive a release candidate to determine whether the final result still meets their needs.
  • If the content does not meet their needs, the licensee is not required to pay, and the research will be released without licensing or with alternate licensees.
  • Licensees may host and reuse the content for the length of the license (typically one year). This includes placing the content behind a registration process, posting on white paper networks, or translation into other languages. The research will always be hosted at Securosis for free without registration.

Here is the language we currently place in our research project agreements:

Content will be created independently of LICENSEE with no obligations for payment. Once content is complete, LICENSEE will have a 3 day review period to determine if the content meets corporate objectives. If the content is unsuitable, LICENSEE will not be obligated for any payment and Securosis is free to distribute the whitepaper without branding or with alternate licensees, and will not complete any associated webcasts for the declining LICENSEE. Content licensing, webcasts and payment are contingent on the content being acceptable to LICENSEE. This maintains objectivity while limiting the risk to LICENSEE. Securosis maintains all rights to the content and to include Securosis branding in addition to any licensee branding.

Even this process itself is open to criticism. If you have questions or comments, you can email us or comment on the blog.