Vulnerabilities / Threats
5/3/2012
05:40 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

2012 Strategic Security Survey: Pick The Right Battles

Whether it's cloud computing, mobile devices, or insecure software, some threats are more prevalent than others. Our latest survey delves into where security pros are putting their resources.

InformationWeek Green - Mar. 7, 2011 InformationWeek Green
Download the entire May 7, 2012 issue of InformationWeek, distributed in an all-digital format as part of our Green Initiative
(Registration required.)
We will plant a tree for each of the first 5,000 downloads.

Pick Your  Battles

What's the biggest challenge facing security teams? It's not preventing breaches, meeting compliance demands, or even vying for executive attention. It's managing complexity, our InformationWeek 2012 Strategic Security Survey finds. Now, we've been running this study for 15 years, and security has never, ever been simple. But over the past decade the threats have piled up; we have too many fancy technologies to deploy and long-winded policies to enforce--with no guarantee that any of them will reduce risk.

So let's break it down. Prioritize the threats most likely to affect your company. If you try to block every conceivable attack, you'll stretch your people and resources so thin that something is bound to break. Stop worrying about what you can't control or predict and focus like a laser on where you can make an impact. That includes tried-and-true basics like strong access control. It includes taking a hard look at potential cloud providers' security claims, and writing Web apps and business software with an eye toward reducing vulnerabilities. It means being prepared for when a salesperson leaves an iPad in a taxi or has her phone snatched out of her hand.

We'll provide guidance on these areas in this article and go into more depth in our full 2012 Strategic Security Survey report. We'll also delve into what 946 business technology and IT security professionals from companies with 100 or more employees told us in our latest in-depth look at the security landscape.

What's In That Cloud, Anyway?

Our 2012 State of Cloud Computing Survey shows adoption of public cloud on a consistent upward pace; just 27% of 511 respondents from companies with 50 or more employees aren't in the market for these services. Unfortunately, in 2011, only 18% of our Strategic Security respondents actually assessed the security of cloud providers. This year, that number jumped to 29%. However, another 14% rely on the self-audit reports vendors provide. An example is the SSAE 16, a widely used set of auditing standards that providers say attest to controls they have in place.

We don't recommend blindly accepting these reports. One reason is that SSAE 16 attestations contain different sets of scope and system descriptions, so one provider's SSAE 16 may be dramatically different from another's. A better bet? The Cloud Security Alliance explicitly lays out a set of security best practices for cloud providers across a variety of domains, including encryption, data center management, cloud architecture, and application security. The CSA's guidelines are much more prescriptive, and the group offers the Security Trust and Assurance Registry, a free, publicly accessible registry that documents the security controls inherent in various cloud offerings. All providers can submit self-assessment reports that document compliance with CSA-published best practices.

When it comes to cloud computing risks, the most prominent concern among our survey respondents is unauthorized access to or leak of customer information. That's unchanged from 2011. Other top concerns include worries about security defects in cloud technology and the loss of proprietary data.

Pick The Right Battles

Our full 2012 Strategic Security report is available free with registration.

This report includes 44 pages of action-oriented analysis, packed with 38 charts. What you'll find:
  • Security guidance on cloud, mobile and more
  • How to get value from collecting security metrics
Get This And All Our Reports


To read the rest of the article,
Download the May 7, 2012 issue of InformationWeek

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Doug Barbin
50%
50%
Doug Barbin,
User Rank: Apprentice
5/8/2012 | 4:12:45 AM
re: 2012 Strategic Security Survey: Pick The Right Battles
Based on the comments in the narrative regarding SSAE 16 and CSA STAR, I was hoping that the survey itself would provide more depth on the types of assurance tools that security professionals use and/or rely on it. If there is such data not included in the findings report, I believe the readers would find it relevant. SSAE 16 (or SOC 1) has specific use cases. STAR, as shown via Microsoft's submissions has a nice tie-in to ISO 27001 certification but could also be attached to an attestation report. What about PCI and FedRAMP? https://www.BrightLine.com contains additional information for SSAE 16, SOC 2, PCI DSS, ISO 27001 certification, and more.
121 Pieces of Malware Flagged on NSA Employee's Home Computer
Kelly Jackson Higgins, Executive Editor at Dark Reading,  11/16/2017
Mobile Malware Incidents Hit 100% of Businesses
Dawn Kawamoto, Associate Editor, Dark Reading,  11/17/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Managing Cyber-Risk
An online breach could have a huge impact on your organization. Here are some strategies for measuring and managing that risk.
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.