CISO Platform's Posts (73)

Sort by

RSA conference is one of the leading security conference worldwide.  It creates tremendous opportunity for vendors, users and practitioners to innovate, educate and discuss around the current security landscape.

 

The EDR market has emerged to satisfy the need for faster detection and response to Advance malwares attacks that bypass perimeter and other traditional security controls. An EDR tool has the capability to detect security incidents, either via monitoring endpoint activity or by leveraging IOC’s from externally fed sources, Investigate security incidents, via historical analysis of endpoint states to determine the damage caused for business, and remediate security incidents, by removing the malware, isolating the system to prevent malware spread , and restoring the system to previous known good state etc.

 

Here are top 6 emerging vendors to watch out for in Endpoint detection and response technology

 

Cybereason

Cybereason an Israeli cyber security company uses behavioral correlation to detect anomalous action and provide realtme threat detection. Cybereason deploys endpoint sensors which collects data to be fed to centralized server which can either be deployed on-premise or can be cloud based. Centralized management console provides investigation and forensics capabilities for any security incidents.

 

To Know More: Visit Cybereason Deep Detect & Respond Product Page

 

CarbonBlack

Carbon Black is a dedicated EDR tool vendor leading the new era of endpoint security to protect against advance attacks. Carbon Black continuously records all endpoints activities  such as  all execution events, memory events, file and registry  modifications, network connections and store them centrally for their analysis. It uses methods such as matching against IOC’s and behavioral monitoring to protect against threats. carbon Black server can be deployed either on-premise or on cloud.

 

To Know More: Visit Carbon Black Defense Product Page

 

(Read More: What Is Next-Generation Endpoint Security and Why Do You Need It? (RSA Conference 2016) )

CrowdStrike

Crowdstrike Falcon host is software as a Service (SaaS) based platform for Endpoint detection and response. Endpoints sensors are available for Windows, Linux and Mac OS’s which collect all the endpoint activities and relays the data to cloud for its analysis.

 

To Know More: Visit Crowdstrike Falcon Host Product Page

Bromium

Bromium utilizes micro-virtualization technology to protect against the exploits. Bromium runs content (HTML, Flash, Java, office doc, pdf’s etc) in a microvisor isolated from the core OS kernal. This enables users to click on anything without risk of compromise.

 

To Know More: Visit Bromium Advanced Endpoint Security Product Page

 

Endgame

Endgame Detect and respond Platform protects enterprises from attacks such as , APT’s, Privileged escalation, in-memory fileless attacks etc. Endgame’s Hardware Assisted Control Flow Integrity (HA-CFI) stops adversaries before any code is executed, Endgame MalwareScore™) instantly indentifies known and unknown malicious files using machine learning and In-Memory attack detection stops attackers from hiding in memory to evade detection, preventing fileless attacks.

 

To Know More: Visit Endgame Vendor Page

 

SentinelOne

SentinelOne’s next-generation endpoint and server protection uses several layers of attack prevention, including behavior detection and machine learning, to stop attacks that other vendors simply can’t. It also provides unparalleled threat visibility at a minimum system impact.

 

To Know More: Visit SentinelOne Endpoint Protection Platform Page

Read more…

RSA conference is one of the leading security conference worldwide.  It creates tremendous opportunity for vendors, users and practitioners to innovate, educate and discuss around the current security landscape.

 

Application security testing are tools and services that helps you discover security vulnerabilities in all kinds of applications. Current application security practices/tools available broadly falls into following categories:

 

  • SAST: Static application security testing tools analyzes the application source code to determine if vulnerabilities exist. IT is also referred to as White-box testing.
  • DAST: DAST tools are also referred to as Black box testing tools. They find potential vulnerabilities inside an application by trying to penetrate them in variety of ways, while the applications are running.
  • IAST: AST is the mix of DAST and RASP, Run-time Application Security Protection, techniques. This approach analyzes application in the testing phase, using the RASP runtime agent and DAST as an attack inducer.

 

(Read More: How to choose your Security/Penetration Testing Vendor?)

 

Here are the top 7 vendors to watch out for in AST market:

 

HPE

HPE Fortify is an application security testing that enables customers to create, supplement and expand a Software Security Assurance program. The Fortify suite uses open APIs to embed application security testing into all stages of the development tool chain; development, deployment, and production.

 

To Know More: Visit HPE Fortify Product Page

 

Veracode

Veracode is one of the top vendors in Application security testing domain. Product family includes Binary Static Analysis (SAST), Web Application Perimeter Monitoring, Dynamic Analysis (DAST), Mobile Application Security, Vendor Application Security testing and RASP.

 

To Know More: Visit Veracode Application Security Product Page

 

IBM

IBM Security AppScan Standard helps organizations decrease the likelihood of web application attacks and data breaches by automating application security vulnerability testing. IBM Security AppScan Standard can be used to reduce risk by permitting you to test applications prior to deployment and for ongoing risk assessment in production environments.

 

To Know More: Visit IBM Security AppScan Standard Product Page

 

Whitehat Security

WhiteHat Sentinel is a Software-as-a-Service (SaaS) platform that enables you to quickly deploy a scalable application security program across the entire software development lifecycle (SDLC).

 

To Know More: Visit WhiteHat Sentinel Product Page

 

Checkmarx

Powerful Static Source Code Analysis solution designed for identifying, tracking and fixing technical and logical security flaws from the root: the source code. CxSAST can be integrated seamlessly into the Software Development Life Cycle (SDLC), enabling the early detection and mitigation of crucial security flaws in all major programming languages. Checkmarx also has DAST capabilities.

 

To Know More: Visit Checkmarx CxSAST Product Page

 

Qualys

Qualys Web Application Scanning (WAS) is a cloud-based service that provides automated crawling and testing of custom web applications to identify vulnerabilities including cross-site scripting (XSS) and SQL injection. The automated service enables regular testing that produces consistent results, reduces false positives, and easily scales to secure a large number of websites.

 

To Know More: Visit Qualys Web Application Scanning (WAS) Product Page

 

Synopsys

Seeker is an automated Interactive Application Security Testing (IAST) solution that works with developers to efficiently produce secure software. It analyzes code and data flows at runtime to better understand a security vulnerability’s business impact and exploitability. Synopsys has also acquired Cigital, another leading application security vendor, to add to it capabilities.

 

To Know More: Visit Synopsys Seeker Product Page

Read more…

RSA conference is one of the leading security conference worldwide. It creates a tremendous opportunity for vendors, users and practitioners to innovate, educate and discuss around the current security landscape.

Deception Technology market is rapidly evolving with more & more vendors coming up with their unique offerings. Deception technology basically plants number of decoys which are indistinguishable with the actual servers, endpoints, devices and data. These decoys serves the purpose of low hanging fruit which an attacker targets and hence gives himself away. It is no doubt that deception technology is going to be the next generation of Intrusion detection and response systems and hence it is wise to pay attention to it today.

 


Here are top 5 vendors to consider when looking for cyber deception solution:

 

Illusive Networks

Illusive Networks is a cyber security firm headquartered in Tel Aviv, Israel. It was founded in  Illusive Network’s “Deceptions everywhere” lays out a deceptive layer over your entire network. The decoys can be data, servers, applications, devices and hosts. The moment the attacker steps onto one of the decoys, he/she is seamlessly transferred to a virtual network separate from enterprise network and investigations and forensics follows.

 

To Know More:  Visit Illusive Networks’ Deceptions Everywhere Product Page

 

Attivo Networks

Attivo networks, founded in 2011 and headquartered in Fremont, CA, US, is a deception based threat detection platform. Attivo network “Threat Matrix Platform” checks all the right boxes and is packed of features that a modern day deception technology should have

 

To Know More:  Visit Threat Matrix Deception Platform Product Page

 

(Read More: Deception Technology: Use Cases & Implementation Approaches)

 

Smokescreen

Smokescreen’s IllusionBLACK deception platform detects cyber attacks like reconnaissance, spear phishing, lateral movement, stolen credentials and data theft.  IllusionBLACK features rapid out-of-band deployment, no performance impact, enterprise scalability, and minimal false positives, leading to faster breach detection and improved security and incident response team productivity.

To Know More:  Visit Smokescreen’s IllusionBlack Product Page

 

TrapX

TrapX is a cyber security company founded in 2010 and headquartered in California, US. TrapX “Deception grid” platform provides deception based advance threat defense solution. TrapX has number of out-of-box use cases for detecting zero-day malware, Ransomware and attcks through compromised accounts.

 

To Know More:  Visit TrapX’s Deception grid Product Page

 

Cymmetria

Cymmetria, Founded in 2014 and headquartered in California, US, has Deception platform called as “Mazerunner”. Mazerunner intercepts the attacker during the reconnaissance phase and carefully lead them to a monitored deception network where they are analyzed for their tactics, techniques and procedures employed for attacking the enterprise. Mazerunner can be deployed as a virtual appliance and required minimal effort in deployement

 

To Know More:  Visit Cymmetria’s Mazerunner Product Page

 

Acalvio

Acalvio provides Advanced Threat Defense (ATD) solutions to detect, engage and respond to malicious activity inside the enterprise networks. Acalvio holds patents in deception and data science and have developed have developed their product “Deception2.0” around that. Acalvio is founded in 2015 and headquartered in California, USA.

 

To Know More:  Visit Acalvio Deception2.0 Product Page

Read more…

RSA conference is one of the leading security conference worldwide.  It creates tremendous opportunity for vendors, users and practitioners to innovate, educate and discuss around the current security landscape.

 

User behavior analytics technology is in a way similar to SIEM technology but with certain subtle differences:

  • Most standalone UBA tools utilize both basic and advance analytics approach ranging from rules-based models to Deep machine learning. A SIEM tool may or may not utilize advanced analytics approaches such as unsupervised machine learning
  • Most standalone UBA tools utilize narrow but highly relevant set of data for ex. Active directory logs, end point security solutions, DLP solutions etc, for analysis. This results in higher quality of alerts with less false-negatives and false-positives. compare this to SIEM  tools which ingest overwhelming amount of data only to generate more noise in their alerts
  • Standalone UBA tools builds profiles/models for Users and Entities (Hosts, applications, devices etc.) behavior over a period of time and uses that as a baseline to detect any malicious actions by noting any abrupt or sudden change in their behavior. This functionality is only available as a feature in some SIEM tools.
  • UBA excels in certain use cases such as insider threat detection, detecting compromised accounts etc.


Here are top 5 emerging UBA vendors to watch out for:

 

Exabeam

Exabeam user behavior intelligence solution helps organizations tackles challenges like external/internal threats and data theft by applying the advancements in data science to cyber-security. The product is built on a big data platform and performs behavioral analytics and risk scoring to determine any malicious activity.

To Know More: Visit Exabeam User Behavior Intelligence Solution Page

Gurucul

Gurucul’s user behavior analytics and identity access intelligence technology uses machine learning and predictive anomaly detection algorithms to reduce the attack surface for accounts, unnecessary access rights and privileges, and identify, predict and prevent breaches.

 

To Know More: Visit Gurucul Risk Analytics Platform Product Page

(Read More: Technology Stack For Ransomware Protection )

 

Fortscale

Fortscale UEBA uses unsupervised machine learning algorithms to provide user and entity profiling and anomaly detection. Fortscale can ingest myriad sources of data and has inbuilt forensics and investigation capabilities.

 

To Know More: Visit Fortscale UEBA Product Page

 

Redowl

RedOwl uses a mix and match advance and basic analytics, such as, statistical pattern matching, machine learning and content analytics to profile user behavior, and identify anomalous user activity. RedOwl UBA solution can ingest both structured and unstructured data formats and has multiuse cases out-of-the box.

 

To Know More: Visit RedOwl UBA Solution Page

 

Niara

Niara security analytics platform utilizes both supervised and unsupervised machine learning for behavioral profiling of user and entities. It ingests data sources such as network packets, log data from hosts, application and other security products such as SIEM, DLP and WAF. Niara security analytics platform can be deployed on-premise or can be cloud based.

 

To Know More: Visit Niara Security Analytics Platfrom Page

Read more…

About Project

The scope of the project encompassing Business Units, Support Functions, 200+ Processes and 8500+ employees. The project was an outcome of the data pilferage risk envisaged in terms of sensitive customer information and financial data. The risk assessment took inputs from various avenues such as internal audits, external audits, risk event, control committees conducted with the Top Management, business requirement were driven by the customer expectations.

 

The overall Project approach:

  • Risk Assessment
  • Management By-in
  • Business Alignment
  • Budgeting
  • Product Selection / Proof of Concept
  • Solution Deployment and Operations

 

Checklist to consider in Evaluating and implementing DLP solution

Identify Critical Business Information

  • Right scoping to cover all the critical business processes
  • Defined roles and responsibility matrix
  • Identification of the sensitive information
  • Laying down the notification and reporting requirements

 

Policy Definition and Finalization

  • Defining and documenting the policy statements.
  • Configuring the tool with the policy statements.
  • Establish the protocol for the policy violations and related logging.
  • Mapped the internet access and external email access with the role profiles to ensure that the access is strictly
  • as per business need.

DLP Incident Management Process and Consequence Management

  • The incidents review by the appropriate Incident Managers.
  • Incident analysis to determine Legitimate use of business information
  • Identify wrong business processes
  • Add new processes to address data loss risks
  • Policy fine-tuning recommendations to be identified

Policy Fine Tuning

  • Based on the findings from earlier exercise, policies needs to be fine-tuned
  • Policy fine-tuning reduces unwanted incidents
  • Helps organizations to transform the DLP tool for monitoring to block mode
  • Actionable Auditing and Policy fine-tuning would be a continuous process

Continuous monitoring and Management Reporting Framework

  • Establish a mechanism to feed in the learning to ensure mature program in place 

Read more…

RSA conference is one of the leading security conference worldwide.  It creates tremendous opportunity for vendors, users and practitioners to innovate, educate and discuss around the current security landscape.

 

A SIEM tool enables an organization to aggregate structured (logs from hosts, devices, applications, network etc.)  and unstructured (News feed, Threat intelligence, articles etc)  data and apply advance analytics onto it to detect security incidents in near real time. With SIEM solution you have greater amount of visibility into your IT infrastructure, you can correlate between different security events, identify and fix broken security processes and perform forensics for any security events.

 

Here are top 5 SIEM vendors to watch out for :

IBM

IBM® Security QRadar® SIEM consolidates log source event data from thousands of devices endpoints and applications distributed throughout a network. It performs immediate normalization and correlation activities on raw data to distinguish real threats from false positives. IBM Security QRadar SIEM can also correlate system vulnerabilities with event and network data, helping to prioritize security incidents.

To Know More: Visit IBM QRadar Product Page

 

Splunk

Splunk’s Security Intelligence Platform, consisting of Splunk Enterprise and the Splunk App for Enterprise Security, offers a sonar view of the sea of threats to your data. Splunk provides insight into machine data generated from security technologies such as network, endpoint, access, malware, vulnerability and identity information.

Splunk’s Security Intelligence Platform, consisting of Splunk Enterprise and the Splunk App for Enterprise Security, offers a sonar view of the sea of threats to your data. Splunk provides insight into machine data generated from security technologies such as network, endpoint, access, malware, vulnerability and identity information.

To Know More: Visit Splunk’s Security Intelligence Platform Page

(Read More: Top Metrics To Manage Your Siem Program )

 

Hewlett Packard Enterprise (HPE)

A comprehensive Security Information & Event Management (SIEM) solution that enables cost-effective compliance and provides advanced security analytics to identify threats and manage risk.

To Know More: Visit HP ArcSight SIEM solution Page

 

LogRhythm

LogRhythm’s security intelligence and analytics platform enables organizations to detect, prioritize and neutralize cyber threats that penetrate the perimeter or originate from within.

LogRhythm’s security intelligence and analytics platform enables organizations to detect, prioritize and neutralize cyber threats that penetrate the perimeter or originate from within.

 

To Know More: Visit Logrhythm SIEM Product Page

 

Intel security (McAfee)

McAfee SIEM products high-performance, powerful security information and event management (SIEM) solution brings event, threat, and risk data together to provide strong security intelligence, incident response, log management, and compliance reporting.

To Know More: Visit McAfee Enterprise Security Manager Product Page

Read more…

RSA conference is one of the leading security conference worldwide.  It creates tremendous opportunity for vendors, users and practitioners to innovate, educate and discuss around the current security landscape. The following blog enlists the top DLP vendors at RSAC 2017.

 

DLP is a set of security controls that helps organization protect their sensitive data, throughout its life cycle, across all platforms, from getting disclosed to unauthorized users(insiders or outsiders) either accidentally or intentionally.

 

Here are top 5 vendors to watch out for in DLP market :

 

Symantec

Symantec Data Loss Prevention is the most comprehensive and a fully integrated DLP which protects your information wherever it lives—in the cloud, on mobile devices and in your data centers. Security experts at Symantec are leading the innovation in Data leakage prevention (DLP)Technology for the start.

 

To Know More: Visit Symantec DLP Product Page

 

Digital Guardian

Digital Guardian Data Loss Prevention (DLP) gives you the deepest visibility, the fine-grained control and the industry’s broadest data loss protection coverage – to stop sensitive data from getting out of your organization.

 

To Know More: Visit Digital Guardian DLP Product Page

 

Forcepoint

The Forcepoint™ DLP Module enables you to discover and protect sensitive data in the Cloud or on-premise. you can secure personal data, intellectual property and meet compliance requirements quickly, with custom or out-of-the-box

 

To Know More: Visit Forcepoint™ DLP Product Page

 

Intel Security

McAfee Total Protection for Data Loss Prevention (DLP) safeguards intellectual property and ensures compliance by protecting sensitive data wherever it lives—on premises, in the cloud, or at the endpoints. McAfee Total Protection for DLP is delivered through physical or virtual low-maintenance appliances and the McAfee ePolicy Orchestrator platform for streamlined deployment, management, updates, and reports.

 

To Know More: Visit McAfee DLP Product Page

 

Please suggest the 5th DLP vendors to your liking, which you feel has worked for your organization, in the comments below.

 

(Read More :- Top 6 Reasons Why Data Loss Prevention(DLP) Implementation Fails)

 

Read more…

RSA conference is one of the leading security conference worldwide.  It creates a tremendous opportunity for vendors, users, and practitioners to innovate, educate and discuss around the current security landscape. Cloud Access Security Brokers (CASB) market has seen tremendous growth over past couple of years.  Significant number of CASB vendors are already acquired by large security organizations and the trend will likely continue in future.

 

CASB is now a must have security controls for organizations who have adopted multiple cloud services for their business regardless of their industries /verticals. Cloud Access Security Brokers (CASB) are placed between cloud service consumers and cloud service providers to support continuous visibility, compliance, threat protection, and security for cloud services. They act as a security policy enforcement point for Cloud-based Services (primarily SaaS).

 

Here are top 5 emerging CASB vendors to watch out for :

 

Skyhigh Networks

Skyhigh networks was one of the first CASB vendors to shed light on Shadow IT problem by discover of cloud apps running on enterprise endpoints. They were also the first to have a product which can assess the security posture of SaaS applications. Skyhigh also offers on-premise virtual appliance option for deployment if you are wary of data privacy and security, so that none of your data leaves your organizations network for analysis.

 

To Know More: Visit Skyhigh Cloud Security Manager Product Page
 

Ciphercloud

Ciphercloud is also one of the early CASB vendors, initially focused on providing data security by encrypting data in some enterprise cloud applications. Ciphercloud now provides, complete data security for both structured and unstructured data, shadow IT discovery, risk assessment for SaaS apps and provides rich set of integration with other on-premise security tools. Ciphercloud can be deployed as an on-premise physical or virtual appliance.

READ MORE >>  Top 6 Vendors in Enterprise Mobility Management (EMM) Market at RSAC 2017

To Know More: Visit CipherCloud Cloud Security Broker (CSB) Product Page

 

 (Read More: CASB: A CISO’s Guide To Top Considerations Before Buying)

 

Netskope

The Netskope active platform shows you all the details about all the cloud apps, both sanctioned and un-sanctioned, are being used in your organization. It can do user behavior anlytics to give you visibility into users actions and provides strong DLP capability to protect your data. Netskope solution can also integrate with your on-premise DLP solution.

 

To Know More: Visit The Netskope Active Platform Page

 

Bitglass

Bitglass Cloud Access Security Broker (CASB) solution provides enterprises with end-to-end data protection from the cloud to the device.  Enterprises can secure cloud apps like Office 365 and Salesforce, and internal apps like Exchange and Sharepoint. Bitglass also allows to enforce corporate data security policies across multiple cloud services by integrating with enterprise’s DLP and IAM solution.

 

To Know More: Visit Bitglass Standard Edition Product Page

 

Vaultive

The Vaultive Cloud Data Protection Platform helps encrypts data before it leaves the trusted on-premises infrastructure, gives the data owner or a trusted third party sole custody of the encryption keys.

 

To Know More: Visit Vaultive Cloud Data Protection Platform Page

Read more…

RSA conference is one of the leading security conference worldwide.  It creates tremendous opportunity for firewall vendors, users and practitioners to innovate, educate and discuss around the current security landscape.


A Next-Generation Firewall (NGFW) is an integrated network platform that combines a traditional firewall with application specific granular controls to help them detect application specific attacks. They help detect attacks through application specific protocols such as HTTP, HTTPS, SMTP and so on. It also incorporates various network device filtering functionalities such as an intrusion prevention system (IPS), Web filtering and Email security.

Here are top 6 vendors to watch out for in NGFW market : 

Palo Alto

Palo Alto Networks next-generation firewalls are all based on a consistent Single-Pass Architecture. Palo Alto integration with GlobalProtect mobile security service extends policy-based security to mobile devices (whether on-premises or remote). Integration with threat intelligence services keeps information up to date for the firewall (e.g., URL categories, threat signatures).

 

To Know More: Visit Palo Alto Networks NGFW Product Page

 

Fortinet

The FortiGate next gen firewall is a high-performance network security appliance that adds intrusion prevention, application control, and anti-malware to the traditional firewall-VPN combination. This NGFW provides one platform for end-to-end security across your entire network.

 

To Know More: Visit Fortinet NGFW Product Page

 

Checkpoint

Check Point’s enterprise firewall product line includes 17 appliances and two chassis for hardware blades, scaling up to 400 Gbps. It can also be delivered as a virtual appliance, deployed on VMware, Amazon Web Services (AWS), OpenStack and Microsoft Azure, or delivered as software.

 

To Know More: Visit Check Point NGFW Product Page

 

(Read More: 9 Top Features To Look For In Next Generation Firewall (NGFW))

 

CISCO

Cisco Firepower NGFW appliances combine network firewall with next-gen IPS and advanced malware protection for better security and visibilty.

To Know More: Visit Cisco ASA Firewall Product Page

Juniper technologies

Juniper next-generation firewalls use information from Juniper’s Sky Advanced Threat Protection cloud-based service and third-party GeoIP feeds to block malicious activities as they enter or traverse the network. It also provide application visibility and control, IPS and user-based application policies, plus unified threat management (UTM) to protect and control your business assets.

 

To Know More: Visit Juniper Networks NGFW Product Page

 

Forcepoint

Forcepoint Stonesoft NGFW provides centralizing monitoring, management and reporting across diverse virtual, physical and Cloud environments, as well as third-party devices. Optimized workflows streamline daily administrative tasks and security management for high efficiency and low total cost of ownership (TCO)

 

To Know More: Visit Forcepoint Stonesoft NGFW Product Page

Read more…

RSA Conference is one of the leading security conference worldwide.  It creates tremendous opportunity for Enterprise mobility management vendors, users, and practitioners to innovate, educate and discuss around the current security landscape.


Enterprise mobility management (EMM) is a suite of products which allows you to safely enable the use of mobile devices in your organization. Employees today want to use their personal devices for checking corporate mails and access sensitive documents as and when they need it, be it inside or outside the corporate network.

Here are top 6 vendors to watch out for in EMM market:

 

Airwatch by VMware

VMware AirWatch Enterprise Mobility Management (EMM) delivers unified endpoint management, end-to-end security from devices to the data center, and seamless integration across enterprise systems. It has one of the most comprehensive set of capabilities and has been the consistent leader in the Gartner EMM magic quadrant:

 

To Know More: Visit VMware AirWatch EMM Product Page

 

MobileIron

The MobileIron mobile security platform was built to secure and manage modern operating systems in a world of mixed-use devices. It incorporates identity, context, and privacy enforcement to set the appropriate level of access to enterprise data and services.

 

To Know More: Visit MobileIron EMM Product Page

 

Citrix

Citrix XenMobile delivers complete enterprise mobility management (EMM)—mobile device management, mobile application management and enterprise-grade productivity apps—in one comprehensive solution. XenMobile enhances the user experience on BYO or corporate devices without compromising security.

 

To Know More: Visit Citrix XenMobile Product Page

 

IBM Maas360

IBM® MaaS360® Enterprise Mobility Management (EMM) combines device, app and content management with strong security to simplify how you go mobile. You can monitor for threats and automate compliance to maximize security without compromising the user experience.

 

To Know More: Visit IBM Maas360 Product Page

 

Blackberry

BES®12 is a part of the Good Secure EMM Suites, offering a trusted end-to-end approach to security, and allowing organizations to support a wide range of devices, including iOS®, Android™, Samsung KNOX™, Android™ for Work, Windows®, Mac OS® X, and BlackBerry.

 

To Know More: Visit Blackberry EMM Suite Product Page

 

Please suggest the 6th Enterprise mobility solution of your liking, which you feel has worked for your organization, in the comments below.

 

 

Read more…

Threat Intelligence Program is a set of people, process and technology which enables you to proactively Identify, collect, enrich and analyze threat information, strategic and tactical, so that your organization is ever ready to defend and respond to any kind of cyber attacks. Threat intelligence as applied in conventional security is  any information that helps you tune your security defenses, build an effective response program for any contingency and also if required take preemptive measures to neutralize any looming threats. Key characteristics of any threat intelligence is that they should be timely, actionable and relevant to your organization. Threat intelligence gives out information about the attackers, their motivations, their tactics, techniques and procedure. This information and other contextual information when correlated gives out a better picture of the threats, vulnerabilities, and their impact. Threat intelligence helps you prioritize risk against your organizations and also helps in preparing a security road-map for future security investments.

Key Use Cases

Threat Research:

Deeper Insight into artifacts related to IOCs found on their network. A threat intelligence service eliminates the need to manually research, gather and analyze volumes of threat information from multiple sources, mainly across the Internet.

Proactive protection:

Current defensive protocols may be adjusted prior to an attack

Strategic planning:

Future planning is relevant to the emerging threat based on risk & its potential impacts relevant to your organization

Streamline patch management program:

Prioritize vulnerability management activities based on risk criteria & its impact

Security Education:

Develop case studies for use during internal incident response training exercises and business continuity management efforts

Threat Assessment:

Explore new zero-day exploits/new malware variants and vulnerabilities, monitor direct attacks against an organization

Data Leaks:

Real time alerts enable timely action, Monitor unauthorized information disclosure including credentials etc.

Security architecture planning: 

Provide security related inputs into architectural and procurement decisions

Incident response: 

Better understand the business impact by relating incident artifacts to threat actor profiles

Do let me know if you want us to add or modify any of the listed key use cases.

Check out the Threat Intelligence market within Product comparison platform to get more information on these markets.

Read more…

The term Security Information and Event Management (SIEM) finds its origin from the combination of Security Information Management (SIM) and Security Event Management (SEM). Where SIM focuses on the collection and long-term storage of log files, SEM focuses on real-time monitoring of (suspicious) behaviour. SEM does this by aggregating and identifying interesting log entries (events), often collected by a SIM implementation. A SIEM collects log files and security information from internal- (i.e. server-, network- and application logs) and external sources (i.e. threat intelligence sharing). Event correlation is used to detect and alert on, by the organisation defined, unwanted activities within the network. Lets have a look at the Key Use Cases for the SIEM Market:

Key Use cases:

  • Manage and store Security Logs across devices and applications: one of the important capability of SIEM solution is that it can aggregate log sources across the IT infrastructureof an organization and stores them for their analysis. It performs log normalization, log parsing and log timestamping for better stogate and correlation.
  • Detect Indicators of compromise (IOC’s) by analyzing the aggregated Log sources for possible security breach: SIEM correlation engine performs analysis on the log data to identify any sucpecious activity inside the organizations network. Correlation rules can be written to detect for any indicators of compromise by correlation logs from different devices, applications and systems.
  • Maintain and monitor compliance with various regulatory bodies on a continuous basis: One of the major drivers of SIEM tools in the market is due to the compliance and regulatory requirements. Compliance, regulations and industry standards requires organizations to collect and store log data from various systems, devices and applications, have visibility into and continuous monitoring of enterprise networks for better security. SIEM is a great tool to accomplice that.
  • Detect and mitigate Advance persistent threats: APT’s  are hard to detect if already inside any organization as they keep a low profile. No single point product can help you protect from APT attacks. SIEM tool provides a birds eye view  for the entire enterprise IT, SIEM analytics engine and continuous monitoring can help protect against APT’s.
  • Continuous monitoring of organizational IT Infrastructure: As mentioned previously, SIEM tools provides a holistic picture of the state of security in any organizations. The SIEM tool is fed with logs, vulnerability data, configuration data, and threat intelligence feeds which helps it monitor for any breaches and abnormal behavior inside the organization.
  • Integrate with and streamline organization cyber incident response program: SIEM generates alerts and notifications for critical security incidents/ suspicious activity inside your network. SIEM tools have built-in incident workflow defined to appropriately respond to such scenarios and track the Incident until its remediation. SIEM can also be integrated with Incident response and Forensics tools.

Do let me know if you want us to add or modify any of the listed key use cases.

Check out the Security Information and Event Management (SIEM) market within Product comparison platform to get more information on these markets.

Read more…

WAF is specialized firewall designed to protect  web applications (HTTP applications) from attacks such as cross-site scripting (XSS), SQL injection and other vulnerabilities that may exist. A WAF is able to detect and prevent unknown attacks by inspecting every HTML, HTTP/HTTPS, SOAP and XML-RPC data packet. Using WAF you can monitor the Input/Output traffic to your web applications. A WAF can also monitor access to web applications and can send access log data to other security tools such as SIEM for its analysis.Lets have a look at the Key Use Cases of Web Application Firewall (WAF) market:

Key Use Cases :

1.Secure vulnerable Web applications : 

Web application whose source codes are not reviewed properly or are un-patched can reasonable protection by deploying WAF as reverse proxy.

2.Basic protection for all web Application: 

Using Web Application firewall you can provide basic protection to all of your web applications against attacks such as SQL injection, XSS, CSRF etc.

3.Apply quick hot-fixes for newly discovered vulnerabilities in web applications: 

Using WAF whitelisting feature the vulnerability can be fixed quickly, so that it cannot be exploited before next scheduled maintenance (Particularly useful in security productive applications, which cannot be quickly taken down for maintenance)

4. Detect any malicious. abusive use of your web applications: 

All the access logs, usage logs & error messages can be collected from WAF and be fed to analytics tools for analyzing any malicious behavior.

 

Do let me know if you want us to add or modify any of the listed use cases.

Check out the Web Application Firewall (WAF) market within Product comparison platform to get more information on these markets

Read more…

An Approach for DLP Implementation

 

  

Myth: – DLP is for IT and it is an IT Project  | Truth: – DLP is for Business and it is a Business Project

DLP Solution is implemented by IT for the business with the close association of various business departments; DLP implementation requires strong upper management commitment and support, in-depth involvement of middle management, IT operation and business/data owners of various departments.


DLP implementation project is destined to be failed if it is considered merely as IT project.


Let’s understand the objective of the DLP

  • Discover the sensitive, confidential or restricted information across the enterprise network, Servers, Machines, Databases etc
  • Monitor and control the flow of such information across the network
  • Monitor and control such information on the end user systems

In short, the prime objective of DLP is to monitor and control the sensitive/confidential/restricted information whether it is at rest, in use or in transit

 

DLP benefits to Business

  • Protection of sensitive business information and IP
  • Improve compliance
  • Reduce data leakage breach risk
  • User Awareness for information security and handling sensitive information

 

There are 3 states of information that any DLP should handle:  Data in Rest, Data in Motion and Data in Use.

Data in Rest: – 

DLP must have the capability to discover various file types like spreadsheet, word and pdf documents etc whether they are present on end user machines, file server, databases, SAN or NAS storage etc. Once found such file types, DLP must be able to open the files and scan the contents to determine the specific type of information as per decided policy like credit card numbers, PAN card no or bank accounts, customer details or specific information. To accomplish this, DLP uses crawler application which crawls through various data stores in the network, machines, databases etc to discover the set of information and develop fingerprints

Discovering the locations and collecting the specific set of information is very critical and important to determine whether its location is permitted to store that specific information set as per business guidelines and policies

 

Data in Move: – 

To monitor information movement in the network, DLP use network analyzer and sensors that capture and analysis network traffic. DLP must have Deep Packet Inspection capability (DPI). It allows DLP to inspect the data in transit and determine contents, source and destination. If sensitive information is detected flowing to an unauthorized destination, DLP has the capability to alert the user and manager and IT and block the data flow

 

Data in Use (end point): 

Data in Use refer monitoring data movement on the end user that they perform on their machines whether data is being copied on thumb drive, sending information to the printer, or cut and paste activities in between applications.

 

Approach

Implementing DLP solution is complex task and requires significant preparatory activities like policies development, directory service integration, work flow management, incident handling, business process analysis, assessment of various type of information that org uses, detailed inventories of the assets carries sensitive information, data flow analysis, data classification and these activities require the deep involvement of the various business dept, data owners, stakeholders and IT dept.

(Read more:  How to write a great article in less than 30 mins)

 

DLP strategy

  1. Get the Management support for the Solution: –

     Justify the requirement of the DLP solution in the organization with the facts, trends, and POC results

  2. Proper planning and strategy are vital for successful DLP implementation

  • Involvement of business owners & stakeholders: – correct business people from various departments who understand what information should be restricted and why should be involved in the DLP project.
  • Data Flow Analysis: – understanding the flow of information between various business processes and department inside and outside are very imperative. Output of DFA will be played very important role while designing policies for the DLP
  • Data Classification: – Here the involvement of business users is very critical. Business owner, business stakeholders are the key people who know the criticality and sensitivity of the organization information and can provide key information that what information is critical for them and organization and where located and who should access that information. Based on the severity level, data is classified and controls are selected.
  • Data Discovery: – once data is classified and segregated based on sensitivity and criticality, DLP discovery engine that uses crawls agents gets deeper into various data stores across the enterprise network to identify and log the sensitive information and their locations and develop fingerprints for further usages in policy

Note: – Quite often enterprises are unaware about all type of information they posse and have limited clue about the locations of sensitive and critical information. So it is very imperative to identify all type of sensitive information and their locations and classify them based on their sensitivity.

 

  • Defining DLP Policies with Business workflow: – once the sensitive information has been identified, next step is to develop policies to protect the identified sensitive information. Each policy consists of few rules that dictate the flow of the information and determine that how the information will be handled by DLP mechanism. Mind it policies will only be developed at this stage not enforced
  • Understanding information flow is critical component of policy formation.
  • What should be source and destination of the identified data?
  • What are the egress points in the network through which information flows out the org
  • What processes are there to govern of the information flow?

DLP rules operates on Content and Context awareness hence Understanding What, Who, Where & How are very important for DLP Security Policies

WhatWhoWhereHowAction
Financial statementFinance DeptPersonal EmailMail ServiceBlock, Notify, Audit
Financial statementFinance DeptTax consultantMail ServiceAllow, Notify, Audit
Salary StatementsHR DeptUSBMemory StickBlock, Notify, Audit

READ MORE >>  Top 10 must-read blogs for CISOs on Data Loss Prevention solution

 

  • Incident Management: – DLP is useless if it does not report the incident, it must report violation whenever occurs. IT dept, compliance dept or any other authorized individual must receive the incident notification. Once the manager review and assess the report, further course of action may be taken. If an incident is false positive then the policies should be fine tuned to bring the false positive scale minimally. If an incident is truly positive, appropriate action must be taken .i.e. DLP policy should be redefined. DLP policy management must be agile and flexible enough and they must accommodate rapidly changing security needs.
  • DLP must be tuned for low false positive (DLP detect non-sensitive information in an incident)
  • DLP must be tuned for high true positive (DLP detect sensitive information in an incident)
  • DLP must be tuned for low false negative (DLP not detecting sensitive information in an incident)
  • Go Slow: – start monitoring two or three departments and get the incident management and workflow in place. Starting with all department will overwhelm the DLP incident management will tons of false positive.
  • Monitoring & Period review of DLP policies: – A Period review of policies, rule, and logs is quite critical to identify the false positive/negative.

Read More:- 7 Tips For DLP Implementation

Associated Operation risk of DLP Implementation

High Volume of False Positive may cause productivity loss, hence plan and systematic approach is very much needed. Black Box and using readymade templates approach should be avoided.

Involve valid business users from all department from the initial stage itself. Business users are the right person to take a quick decision on false positive and IT can tune the rules and policies accordingly.

Proper placement of DLP components is very critical, else you will certainly miss coverage for the important data stream. An updated Network diagram must be available to DLP team to understand the flow of information in the network.

Tight integration between DLP and directory service (AD or LDAP) is essential, else it will be difficult to trace user in case of violation.

 

This is a re-post of the blog originally published on CISO Platform

Link to original blog: http://www.cisoplatform.com/profiles/blogs/dlp-an-approach

Read more…

IT-GRC solutions allows organizations to effectively manage IT and Security risks while reducing the cost and complexity of compliance. IT and Security GRC management solution are focused on leveraging near-real time information on IT and Security assets – application, data and infrastructure – that are increasingly virtual, mobile and in the cloud – and correlating that information in the context of business processes, policies, controls, as well as partners, supply chain and customers to understand the size, scope, and scale of risks. IT GRC solutions typically are deployed in phased manner supporting one or more use cases. Let’s have a look at the Key Use Cases of IT- GRC market:

Key Use cases:

Integrated GRC: 
  • Integrated and comprehensive risk and compliance posture across all organizational units.
  • Role-based reporting and risk and compliance  analytics based on single version of the truth, in a central repository
  • Dramatic efficiencies gained through automation of workflow and notifications
IT Policy:  
  • Automated Policy lifecycle management to create, edit, review, approve, publish, distribute policies; support attestation and exception management
  • Mapping of policy elements to international regulations and standards, controls and risks
  • Ability to measure impact of new and changing regulatory and business requirements to policy framework
IT Compliance and Controls Monitoring:
  • Automated and accurate mapping between compliance requirements, policy, controls and risk
  • Visibility into compliance posture through integration of policy, control testing and regulatory requirements
  • Ability to measure impact of new and changing requirements to compliance framework
  • Embedded content based on standard frameworks and regulations and harmonized controls across authority sources such as COBIT, ISO 27001/2, SOX, FFIEC, PCI, GLBA, HIPAA, CMS, and NERC through the Unified Compliance Framework (UCF) database.
  • Technology connectors to support the automated measurement and reporting of IT controls via integration with third-party products
IT Audit
  • Automated audit planning and scoping process
  • Automation of audit workflow, work paper management and evidence collection and storage in a central repository
  • Automated testing through checklists and continuous controls monitoring
Others:
  • IT risk Management
  • Vendor Risk Management
  • Threat and vulnerability management
  • Issue and incident management

Do let me know if you want us to add or modify any of the listed key use cases.

Check out the IT Governance, Risk and Compliance (IT GRC) market within Product comparison platform to get more information on these markets.

Read more…

Here are some Tips To Evaluate Your Readiness Before Implementing Data Loss Prevention (DLP) Solution:

 

  • Your organization have developed appropriate policy to govern the use of Data Loss Prevention (DLP) solution

    To draw true value from any DLP deployment an organization must first come up with a Data Loss Prevention specific policy to start with. The policy should clearly talk about the goals and objectives of Data Loss Prevention (DLP) deployment, identify and allocate resources for it and talk about the roles and responsibilities of stakeholders for effective governance of the same

 

  • You can define the data to be protected in your Data Loss Prevention (DLP) Solution

    It is very important to know what is to be protected. You have to be very meticulous in defining what constitute sensitive data. You can look at the regulatory requirement that your organization must comply with or/and refer to the various Industry standards to find out.

 

  • You have conducted risk assessment to identify the applications, people, processes, systems and protocols that deals with the sensitive data

    Once you have defined what is to be protected, next step is to find out who to protect it from? And how to protect it? Risk assessment can help you answer these questions.  Identify all the key applications that processes that data, the system on which it resides, the network devices through it passes, the protocols that is uses, the people who uses it etc. Unless this is in place, your Data Loss Prevention (DLP) Solution cannot function properly.

     

    Read More:- 7 Tips For DLP Implementation

 

  • You have designe5 Tips To Evaluate Your Readiness Before Implementing Data Loss Prevention (DLP) Solutiond workflow to handle policy violations and data breaches

    Incidence response workflow must be designed to tackle any data breaches. Flow-chart can be developed identifying steps to take to isolate the incident, people to notify immediately, and methods for the preservation of evidence for forensics. The entire process must be tested by conducting drills at regular intervals. A Data Loss Prevention (DLP) solution can only function with proper policy definition and violation test cases.

 

  • Your organization has clearly defined roles and responsibilities for each employee, including privileged users

    Clearly, define the roles and responsibility for each employee. Identifying who is the owner of data? Who is the custodian of data? Who is the user of data? The answer to these questions will help you in assigning privileges to users on data. If your Data Loss Prevention (DLP) Solution doesn’t have proper privileges, the wrong access will never raise flags.

Read more…

A Next-Generation Firewall (NGFW) is an integrated network platform that combines a traditional firewall with application specific granular controls to help them detect application specific attacks. They help detect attacks through application specific protocols such as HTTP, HTTPS, SMTP and so on. It also incorporates various network device filtering functionalities such as an intrusion prevention system (IPS), Web filtering and Email security. They also features functionalities such as centralized management, SSL interception, VPN’s, Virtualized deployment, QoS/bandwidth management, Gateway antivirus and Third-party integration (i.e. Active Directory).

Key Use cases:

  1.  Safely enable all required applications on Enterprise Networks: Help detect attacks against through enterprise applications. Enforce application functionality specific controls, monitor application data & content, monitor HTTP, HTTPS, SMTP and other application protocols for better protection
  2.  Need protection against known and unknown threats, irrespective of the applications used to transport the threats: It allows very granular controls for network applications. With its deep packet inspection capabilities and state-full inspection of applications in real-time, NGFW provides robust defence against known and unknown threats against your web applications.
  3.  Need to have comprehensive visibility into users, Hosts, applications and content on enterprise networks: Audit applications running on your enterprise networks, monitor their content and data, identify Hosts on which applications are running, identify users of the applications.
  4.  You need a single Network filtering appliance which can do it all. For example, Firewall, IPS, Web filtering, Gateway Antivirus, Email filtering (Limited) etc. : A NGFW has all firewall, IPS/IDS, NAC, Gateway antivirus, Email filtering and so on. A single solution for multiple use cases.
  5.  Need a Network security platform which can deliver high performance and offer integration with other security controls in your network such as, Cloud sandboxing, Threat Intel feeds, SIEM etc. : Highly scalable and integrated solution. It has the capability to ingest threat intel feeds for real-time blocking and can be tightly integrated with Sandboxing or any advance malware protection solution, CASB solution and so on.

Do let me know if you want us to add or modify any of the listed key use cases.

Check out the Next Generation Firewall (NGFW) market within FireCompass to get more information on these markets.

Read more…

Key Use Cases of User Behavior Analytics (UBA)

User Behavior Analytics (UBA) solutions are the applications of advancements in Data science and Machine learning to tackle the current challenges in cyber security. UBA solutions captures data from myriad of sources both in structured and un-structured format such as Network flow/Packet data, Logs from Host and other security solutions, logs from Active directory, Email metadata, News sources/Articles and data from HR systems and apply Machine learning to detect any anomalous or suspicious behavior inside your enterprise network.
UBA solutions learns from the data being fed to it and builds normal operating profiles for users and entities (groups, hosts, applications) over a period of time. It then compare users actions on a continuous basis with these profiles to detect any abnormal actions and behaviour. These baseline profiles or normal operating profiles are dynamic in nature and changes itself automatically to better suit the user and entities normal behavior or to take into account any roles-changes inside the organization.
UBA solutions uses both basic (Rules based and statistical models) and more advance (supervised and unsupervised machine learning) analytics to build these profiles. Lets look at the Key Use Cases of User Behavior Analytics program:

Uncovering compromised credentials:
UBA can detect compromised accounts/credentials by correlating log data from active directory, IAM systems, Network flow  and other sources.
Detecting Malware Infected hosts, endpoints:
This is another area where it can detect malwares in hosts, systems and devices by detecting abnormalities in systems and host behavior. UBA tool can detect out-bound traffics to remote  malicious C&C by looking into the netflow data after enrichment with logs data from endpoints and other security solutions.
Detecting insider threats:
UBA can also help you detect insider threats especially from privileged users by means of risk scoring and outlier detection based on behavioral profiling
Detect data exfiltration:
UBA can also detect data exfiltration attempts by insiders/outsiders by integrating itself with DLP and leveraging logs from SIEM, IAM and active directory.

Do let me know if you want us to add or modify any of the listed key use cases.

Check out the User Behavior Analytics  market within Product comparison platform to get more information on these markets.

Read more…

Things To Know About Print Security

These days, Printer is not the box in the corner of the office, which is harmless and doesn’t need more attention than normal wear and tear repair. In this 21st century, Printers and Multifunction printers (MFPs) are most vulnerable to the cyberattack and can be the cause of the breach of a very sensitive information. Most companies are cognizant of the fact that they need to secure themselves from the cyberattacks and hacks, but they generally forget to include their printers and multifunction printers in this purview and for some the concept of print security is vague.

According to PwC 90% of large and 74% of small UK organisations reported suffering a data breach in 2015, while a 2016 study from the Ponemon Institute reveals the average total cost of a breach to be $3 million, with the average cost per stolen record $158. According to QuoCirca’s survery, about 61% of the large enterprises admitted suffering from data breaches because of the insecure printing.

As Gartner reports, “Print devices were some of the first IoT devices on the enterprise network, yet customer awareness of print security risks is lagging.” We will try to collate all the important points which an organization should be aware of for better print security.

  1. Printers should not be forgotten and should also be included in companies’ security policies.
  2. Invest in authentic and good printer security, plus integrate your whole printer fleet under this security option including all brands.
  3. MultiFunction Printers (MFPs) need secure access to the network as they can be the entry points to the IoT networks. As Gartner reports, “Print devices were some of the first IoT devices on the enterprise network, yet customer awareness of print security risks is lagging.”
  4. Monitor the Printer users and usage to ensure compliance and to trace unauthorised access by using MFP audit log data or third-party tools, which provides full audit trail
  5. Instead of waiting for the breach to happen to know the status of your print security, conduct vulnerability assessment on regular interval and seek expert guidance.
  6. Follow a good security model for your print security, The Gartner report suggests your security model include:
    1. “Features that harden devices
    2. Encrypting data in motion and at rest
    3. Securing and controlling access
    4. Securing paper trays and paper output
    5. Providing detailed, auditable logs for forensic activity analysis”
  7. Follow the new trends in print security market and keep looking for vendors with innovative solutions in the print security market e.g. HP printers incorporate interruption recognition frameworks to alarm security groups when somebody is messing with gadget settings, and the gadgets can check the framework to guarantee just approved firmware is running when it boots up.

To know more about the printer security market, visit our Print Security market page within  Product comparison platform to get more information on these markets.

Read more…

Identity and Access Management is the practice of managing digital identities through-out their life-cycle, managing access rights to enterprise resources and auditing of user access rights, use/misuse of digital identities. The entire process is mostly automated and require little to no human involvement.
Digital identities are often distributed across the heterogeneous mix of systems, devices and applications and poses significant risk to organizations in terms of security breaches and frauds. IAM consolidates and brings all identities under centralized management system where users are provisioned/de-provisioned role-based access rights to all enterprise resources centrally.

Key Use Cases 

–> Single Sign on:
 It is one of the greatest motivations for implementing IAM technologies. The benefits are quick and reduces the pain for maintaining several difficult passwords. Single-sign on is one credential to access of of the enterprise resources which you are authorized for both on-premise and cloud.

–> Centralized Provisioning/De-provisioning of users/identities:
Whether it is provisioning  identities to new employees or de-provisioning ex-employees accounts or managing third party/contractors  user accounts , It can all be done with one centralized console. This reduces the time and management overhead and also reduces the risk of any ghost accounts.

–> Auditing:
Track the end-to-end activities of users and use of access rights management. This includes both ongoing activity monitoring and periodic policy review, for concerns such as separation of duties.

–> Provisioning of Cloud applications or services to users:
Manage end to end Account of users to these services right from account registration, Account management, account revocation to auditing with ease.
–> Role-based access to enterprise resources:
–> Attribute exchange:
–> Enabling automated online reporting to customers
–> Enabling extensive self-service functions in customer portals
–> Verifying customer identities during registration via direct link to the company’s CRM

Do let me know if you want us to add or modify any of the listed key use cases.

Check out the Identity and Access Management market within Product comparison platform to get more information on these markets.

Read more…