Analytics // Security Monitoring
5/3/2013
11:06 AM
Wendy Nather
Wendy Nather
Commentary
50%
50%

La Vie En ROSI

Return on security investment may be slightly less mythical than you think

With very few exceptions, there is really nothing in security that gives you a return on investment. Unless you're selling them, security technologies almost never make you any money -- what they're there for is loss avoidance. Now, you may be able to achieve that loss avoidance by spending a lot of money, or by spending a little money; if you manage the latter, then yes, you have parlayed a cost savings into another cost savings. But that's not the same as investing some money and watching it grow in value.

If that were the end of the story, though, this blog post would be pretty short. So let's look at what material advantages there might be in security monitoring, besides just (hopefully) catching attackers before they do too much (more) damage.

As I've written before, good security monitoring can tell you more about your organization than just how many nmap probes your firewall has blocked. (By the way, I don't consider that number to be at all interesting. Basing your metrics on how many packets your firewall has automatically blocked and calling them "security events" is like counting how many "water events" your roof has handled during the last rainstorm.)

Two areas in which security monitoring can help the business are in performance measurement and data flows. Performance measurement doesn't just mean the load on the server or the network bandwidth saturation. It can also mean the latency on database queries, which will almost certainly affect your application performance. It can refer to how quickly you can make configuration changes, how consistently they're done, and how long they stay configured that way. A lot of operational efficiency metrics are hidden in those logs, along with troubleshooting data. (Oh, the SSL certificate expired! That explains all the failed connections from one server to another...)

Data flows are the lifeblood of your business, and if you don't believe that, then try tripping over a network or power cable sometime. But it doesn't stop with availability of data: Many organizations don't really know who is accessing what data and why. Anyone who has tried a server migration will find this out very quickly, when other departments show up at the planning meetings to slow down the project. Knowing your highest-use data will help you understand its value; it may also tell you which business operations cross disciplines, which ones need optimization (because they're processing redundant data, for example), and where you might have opportunities that you hadn't thought about.

Business intelligence is a thing these days, and CEOs do like to hear about that. Operational efficiency is something that everyone can get behind. If you can demonstrate that security monitoring contributes uniquely to either or both of these, then you may just get permission to pay more for that fancy, new SIEM. Helping the business make more money is the next best thing to making it yourself. The outlook still isn't ROSI, but it does have a nice shine to it.

Wendy Nather is Research Director of the Enterprise Security Practice at the independent analyst firm 451 Research. You can find her on Twitter as @451wendy. Wendy Nather is Research Director of the Enterprise Security Practice at independent analyst firm 451 Research. With over 30 years of IT experience, she has worked both in financial services and in the public sector, both in the US and in Europe. Wendy's coverage areas ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-6477
Published: 2014-11-23
Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4290, CVE-2014-4291, CVE-2014-4292, CVE-2014-4...

CVE-2014-4807
Published: 2014-11-22
Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a '\0' character.

CVE-2014-6183
Published: 2014-11-22
IBM Security Network Protection 5.1 before 5.1.0.0 FP13, 5.1.1 before 5.1.1.0 FP8, 5.1.2 before 5.1.2.0 FP9, 5.1.2.1 before FP5, 5.2 before 5.2.0.0 FP5, and 5.3 before 5.3.0.0 FP1 on XGS devices allows remote authenticated users to execute arbitrary commands via unspecified vectors.

CVE-2014-8626
Published: 2014-11-22
Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding...

CVE-2014-8710
Published: 2014-11-22
The decompress_sigcomp_message function in epan/sigcomp-udvm.c in the SigComp UDVM dissector in Wireshark 1.10.x before 1.10.11 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?