how to bring security transparency into your organization issa educational session

24
Enterprise security How to bring security transparency into your organization ISSA EDUCATIONAL SESSION Nicklaus Schleicher, VP Support & Customer Service

Upload: jaimie

Post on 16-Mar-2016

25 views

Category:

Documents


0 download

DESCRIPTION

How to bring security transparency into your organization ISSA EDUCATIONAL SESSION. Nicklaus Schleicher, VP Support & Customer Service. Consul. 17 years of security event management experience Winner of ISSA Organization of the Year in 2003 Founded in 1986 Worldwide presence: US, - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

How to bring security transparency into your organization

ISSA EDUCATIONAL SESSION

Nicklaus Schleicher,VP Support & Customer Service

Page 2: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Consul

17 years of security event management experience

Winner of ISSA Organization of the Year in 2003

Founded in 1986 Worldwide presence:

– US, – Europe, – Asia-Pacific, – Latin America

Page 3: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Security landscape is changing

Disappearing perimeter More complex security devices Heterogeneous networks Information overload Not enough resources Increasing threats Regulatory requirements Cost pressure

Page 4: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

What are customers saying

Make their security operations more efficient Gain a holistic understanding of their overall security

Comply with regulations

Make sense out of the chaos that is a large network

Respond more quickly and intelligently to problems

Monitor and enforce business-critical policies Conduct more effective post-event forensics and

analysis

Move from auditing to monitoring

Page 5: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

It’s all about Value

Suppose you could protect your most valuable business assets at the lowest cost?

Wouldn’t you want to know how?

Page 6: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

It’s all about Your Critical Data

Most security devices monitor the network perimeter.Yet key assets are on the less-protected inside.

Is your core network adequately protected?

Page 7: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Lots of Products - Few Solutions

Companies have invested heavily in firewalls, IDS, and AV systems, yet remain vulnerable to devastating attacks.

What are you doing to continuously monitor security on your perimeter AND core networks?

Page 8: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Regulations are a worry

Proliferating industry and regulatory standards raise the bar on implementing and demonstrating effective security.HIPAA, GLB, BS 7799, Basel II

What is the value of effective compliance to regulations in your company?

Page 9: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

The security infrastructure is in place

Security Infrastructure

Authorization AuthenticationFirewall / VPN

Anti-Virus

PKI

OS Security

Application SecurityIntrusion Detection

Systems (IDS)

Biometrics

Page 10: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

But security remains a tradeoff

More Openness

Incr

ease

d Se

curit

y

Page 11: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Too many reports and alarms

From firewalls

From intrusion detection systems

From anti-virus systems

Many log files

Page 12: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Too few reports where it matters

Internal systems are not monitored enough:– Logging turned off or not understood– Reports have no real-world meaning

Comparison across systems impossible

Auditing versus company policy impossible

Are you secure? “I don’t know”

Page 13: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Insiders remain a threat

Inside is as hostile as outside, but in a different way

64% of companies admit they suffer from security breaches

76% of all security breaches are due to insider work

70% of all corporate data still on mainframes

Page 14: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Security management process

Page 15: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Step one: define

What’s the status?

Assess current enterprise security

Review policies

Benchmarking and gap analysis

Compliance to standards and regulations

Understand source of today’s vulnerabilities

Define metrics for success

Page 16: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Step two: protect

Implementation of solution:

Implement policies

Define security procedures

Create awareness and communication

Establish administration and support roles

Page 17: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Step three: check

How secure are we?:

Measure Compliance

Check for existing vulnerabilities

Modify policies and settings

Learn from intrusions and issues

Measure against metrics

Security event management

Page 18: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Comprehensive approach

Page 19: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

People

system administrators

managers

finance

human resource

secretary

on line customers / suppliers / partners

hackers

etc.

Page 20: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Technology

operating system

intrusion detection system

firewalls

business applications

anti-virus software

etc.

Page 21: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Security policy

Who is allowed to

do what kind of actions

on what kind of documents

in which period of time

from which place and

on which server?

Page 22: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Consul/eAudit Simplifying a complex environment…

Page 23: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Monitors output from over 50 platformsEvaluates security events, policy violations

Real-time, intuitive view of network Prioritized, actionable alerts, drill-down reports

Best practices baselines, HIPAA, GLBExtensive auditing, reporting and forensics

Visualization, reporting and alerting

Normalization and correlation

Policy

Consul/eAudit

Page 24: How to bring security transparency  into your organization   ISSA  EDUCATIONAL SESSION

Enterprise security

Helping you lower the costs of security