Analytics // Security Monitoring
5/3/2013
11:06 AM
Wendy Nather
Wendy Nather
Commentary
Connect Directly
RSS
E-Mail
50%
50%
Repost This

La Vie En ROSI

Return on security investment may be slightly less mythical than you think

With very few exceptions, there is really nothing in security that gives you a return on investment. Unless you're selling them, security technologies almost never make you any money -- what they're there for is loss avoidance. Now, you may be able to achieve that loss avoidance by spending a lot of money, or by spending a little money; if you manage the latter, then yes, you have parlayed a cost savings into another cost savings. But that's not the same as investing some money and watching it grow in value.

If that were the end of the story, though, this blog post would be pretty short. So let's look at what material advantages there might be in security monitoring, besides just (hopefully) catching attackers before they do too much (more) damage.

As I've written before, good security monitoring can tell you more about your organization than just how many nmap probes your firewall has blocked. (By the way, I don't consider that number to be at all interesting. Basing your metrics on how many packets your firewall has automatically blocked and calling them "security events" is like counting how many "water events" your roof has handled during the last rainstorm.)

Two areas in which security monitoring can help the business are in performance measurement and data flows. Performance measurement doesn't just mean the load on the server or the network bandwidth saturation. It can also mean the latency on database queries, which will almost certainly affect your application performance. It can refer to how quickly you can make configuration changes, how consistently they're done, and how long they stay configured that way. A lot of operational efficiency metrics are hidden in those logs, along with troubleshooting data. (Oh, the SSL certificate expired! That explains all the failed connections from one server to another...)

Data flows are the lifeblood of your business, and if you don't believe that, then try tripping over a network or power cable sometime. But it doesn't stop with availability of data: Many organizations don't really know who is accessing what data and why. Anyone who has tried a server migration will find this out very quickly, when other departments show up at the planning meetings to slow down the project. Knowing your highest-use data will help you understand its value; it may also tell you which business operations cross disciplines, which ones need optimization (because they're processing redundant data, for example), and where you might have opportunities that you hadn't thought about.

Business intelligence is a thing these days, and CEOs do like to hear about that. Operational efficiency is something that everyone can get behind. If you can demonstrate that security monitoring contributes uniquely to either or both of these, then you may just get permission to pay more for that fancy, new SIEM. Helping the business make more money is the next best thing to making it yourself. The outlook still isn't ROSI, but it does have a nice shine to it.

Wendy Nather is Research Director of the Enterprise Security Practice at the independent analyst firm 451 Research. You can find her on Twitter as @451wendy. Wendy Nather is Research Director of the Enterprise Security Practice at independent analyst firm 451 Research. With over 30 years of IT experience, she has worked both in financial services and in the public sector, both in the US and in Europe. Wendy's coverage areas ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Latest Comment: LOL.
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-3154
Published: 2014-04-17
DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files, which allows local users to obtain the XAUTHORITY file conte...

CVE-2013-2143
Published: 2014-04-17
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

CVE-2014-0036
Published: 2014-04-17
The rbovirt gem before 0.0.24 for Ruby uses the rest-client gem with SSL verification disabled, which allows remote attackers to conduct man-in-the-middle attacks via unspecified vectors.

CVE-2014-0054
Published: 2014-04-17
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External ...

CVE-2014-0071
Published: 2014-04-17
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.

Best of the Web