Vulnerabilities / Threats
5/3/2012
05:40 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

2012 Strategic Security Survey: Pick The Right Battles

Whether it's cloud computing, mobile devices, or insecure software, some threats are more prevalent than others. Our latest survey delves into where security pros are putting their resources.

InformationWeek Green - Mar. 7, 2011 InformationWeek Green
Download the entire May 7, 2012 issue of InformationWeek, distributed in an all-digital format as part of our Green Initiative
(Registration required.)
We will plant a tree for each of the first 5,000 downloads.

Pick Your  Battles

What's the biggest challenge facing security teams? It's not preventing breaches, meeting compliance demands, or even vying for executive attention. It's managing complexity, our InformationWeek 2012 Strategic Security Survey finds. Now, we've been running this study for 15 years, and security has never, ever been simple. But over the past decade the threats have piled up; we have too many fancy technologies to deploy and long-winded policies to enforce--with no guarantee that any of them will reduce risk.

So let's break it down. Prioritize the threats most likely to affect your company. If you try to block every conceivable attack, you'll stretch your people and resources so thin that something is bound to break. Stop worrying about what you can't control or predict and focus like a laser on where you can make an impact. That includes tried-and-true basics like strong access control. It includes taking a hard look at potential cloud providers' security claims, and writing Web apps and business software with an eye toward reducing vulnerabilities. It means being prepared for when a salesperson leaves an iPad in a taxi or has her phone snatched out of her hand.

We'll provide guidance on these areas in this article and go into more depth in our full 2012 Strategic Security Survey report. We'll also delve into what 946 business technology and IT security professionals from companies with 100 or more employees told us in our latest in-depth look at the security landscape.

What's In That Cloud, Anyway?

Our 2012 State of Cloud Computing Survey shows adoption of public cloud on a consistent upward pace; just 27% of 511 respondents from companies with 50 or more employees aren't in the market for these services. Unfortunately, in 2011, only 18% of our Strategic Security respondents actually assessed the security of cloud providers. This year, that number jumped to 29%. However, another 14% rely on the self-audit reports vendors provide. An example is the SSAE 16, a widely used set of auditing standards that providers say attest to controls they have in place.

We don't recommend blindly accepting these reports. One reason is that SSAE 16 attestations contain different sets of scope and system descriptions, so one provider's SSAE 16 may be dramatically different from another's. A better bet? The Cloud Security Alliance explicitly lays out a set of security best practices for cloud providers across a variety of domains, including encryption, data center management, cloud architecture, and application security. The CSA's guidelines are much more prescriptive, and the group offers the Security Trust and Assurance Registry, a free, publicly accessible registry that documents the security controls inherent in various cloud offerings. All providers can submit self-assessment reports that document compliance with CSA-published best practices.

When it comes to cloud computing risks, the most prominent concern among our survey respondents is unauthorized access to or leak of customer information. That's unchanged from 2011. Other top concerns include worries about security defects in cloud technology and the loss of proprietary data.

Pick The Right Battles

Our full 2012 Strategic Security report is available free with registration.

This report includes 44 pages of action-oriented analysis, packed with 38 charts. What you'll find:
  • Security guidance on cloud, mobile and more
  • How to get value from collecting security metrics
Get This And All Our Reports


To read the rest of the article,
Download the May 7, 2012 issue of InformationWeek

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Doug Barbin
50%
50%
Doug Barbin,
User Rank: Apprentice
5/8/2012 | 4:12:45 AM
re: 2012 Strategic Security Survey: Pick The Right Battles
Based on the comments in the narrative regarding SSAE 16 and CSA STAR, I was hoping that the survey itself would provide more depth on the types of assurance tools that security professionals use and/or rely on it. If there is such data not included in the findings report, I believe the readers would find it relevant. SSAE 16 (or SOC 1) has specific use cases. STAR, as shown via Microsoft's submissions has a nice tie-in to ISO 27001 certification but could also be attached to an attestation report. What about PCI and FedRAMP? https://www.BrightLine.com contains additional information for SSAE 16, SOC 2, PCI DSS, ISO 27001 certification, and more.
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7407
Published: 2014-10-22
Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2014-3675
Published: 2014-10-22
Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.

CVE-2014-3676
Published: 2014-10-22
Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."

CVE-2014-3677
Published: 2014-10-22
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.

CVE-2014-4448
Published: 2014-10-22
House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information from a Documents directory by obtaining this UID.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.