Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

SAP CSO: Security Requires Context

Security depends on the apps and networks it protects. SAP CSO Justin Somaini discusses three scenarios.

When Justin Somaini talks about security, "context" comes up as often as any technology or process.

"How do we think about security? How do you bring the context of security to the application context?" he asked when Dark Reading interviewed him at the recent Sapphire NOW conference in Orlando, Fla.

Pivoting to an answer, he admitted that the answers are easier for some applications than others. He went on to discuss a trio of context types.

1. Critical Contexts
In an application such as Concur, SAP's travel expense management suite, "there's a lot of travel security in there. There's also fraud protection," Somaini explained. The challenge, he said, is identifying the same sort of contextual framework for other applications, such as those supporting HR or the supply chain.

But doing so is critical. "For us, being able to take security into the line-of-business context is critical," Somiani said. "It's where security really meets the business."

An increased use of analytics is one of the ways Somaini is working to find context. The questions he works through are similar to those many have in data-heavy security: "How much [data] do you need? What are the signals going in that return useful information?" he asked.

The answer is a work in progress. "I believe there's more we can do, but we haven't really figured it out," he admitted.

2. The IoT Context
Talk turned to the Internet of things (IoT). In that context, Somaini said, a particular security difficulty comes with the long reach of the devices at the edge.

"In the IoT, you're including a dependency on the supply chain," he explained. In other words because so many IoT devices are difficult or impossible to upgrade or modify,  to a big extent customers are reliant on the security decisions made by device manufacturers.

In some cases, however, IoT can be easier to secure because the machine-to-machine communications that make up so much of the IoT aren't dependent on the vagaries of user interaction, Somiani said. Yet at the same time, he added, the sheer breadth of the IoT brings its own set of challenges.

"You have to trap the big network that might include cellphones or robots on the factory floor or rail transport," he said. That huge span provides a great deal of room in which criminal activity can hide. For example, a malicious actor from outside of the organization might try to masquerade as someone on the factory floor or as a device on rolling stock.

That possibility means the context has shifted. "Everything we've done previously has been digital, but IoT takes it into the real world," Somaini said.

3. The Employee Context
As the interview neared its end, an SAP employee spotted Somaini and took the opportunity to ask a question about the FBI's recommendation of action on VPNFilter. Somaini answered, and then turned to larger questions about the responsibility of enterprise IT security in the face of such threats.

First, he admitted that it might well be time for CSOs to look at programs to either remediate problems on employees' home routers or show the employees how to remediate issues on their own devices. The issue, he said, is complexity.

"We made the configuration and management of systems incredibly painful. It's impossible for a nonsecurity professional or an end user to set things up," Somaini said.

Somaini also pointed out the similarities between the security challenges of the IoT and those of employees at home. Ultimately, he said, the answer will come in building more security into the systems that machines, enterprise employees, and consumers use to do their work.

Related Content:

 

 

Top industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Click for more information

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
US Mayors Commit to Just Saying No to Ransomware
Robert Lemos, Contributing Writer,  7/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17210
PUBLISHED: 2019-07-20
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level permissions can bypass t...
CVE-2019-12934
PUBLISHED: 2019-07-20
An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.
CVE-2019-9229
PUBLISHED: 2019-07-20
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can...
CVE-2019-12815
PUBLISHED: 2019-07-19
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.
CVE-2019-13569
PUBLISHED: 2019-07-19
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.