CISO Platform's Posts (73)

Sort by

Advanced Threat Protection (ATP) is used to protect against sophisticated, highly skilled, well funded and motivated threat actor . The solution uncovers advance threats across Endpoints, Network, Email and Cloud. These solutions are used to detect advanced persistent threats that existing controls are not able to detect or are simply not capable of doing it.
Advance threat protection is not about a single security solution, It is about a combination of security controls, best practices/procedures, security awareness and continuous monitoring. It is more of a program based approach than a single solution. Although we understand Advance threat protection has a broad scope, here in this category we have focused on tools/solutions those employs both signature based and signature-less methods (Advance Sandboxes, Behavioral analytics, Advance correlation/machine learning, Deception technique etc. ) to detect advance threats by analyzing Web, and Network traffics. Here we call them Network Advance Threat Protection solution.

Key Use cases:

  • To detect advance Targeted attacks which may go undetected by your SIEM, IPS/IDS, FW, Endpoint Security tools: Detect Custom built malware/ zero-day attacks against your organization fast by using advance detection and mitigation tools
  • Reduce Man hours required to detect, respond and gain insights into a security breach: Mitigate incidents in minutes by quick detection and automatic remediation. Future proof yor organization defenses by applying endpoint and network forensics to gain insights into attacker tactics, techniques and procedures.
  • Looking to deploy Sand-boxing solution: Sand-boxing tools are one of the critical tools for advance malware analysis and detection. Today it is imperative to deploy sandbox inside your network if you want to gain visibility into your network traffic, email attachment and web objects.
  • Wants to quickly find answers to who, what, how, where, when, after a security breach (Contextual security): Most of the Advance threat protection tool are context aware, i.e, they maintain stateful analysis of happening inside your network and store it for correlation of events across devices, applications, users, ports and protocols. Contextual security also helps in historical analysis and incidents forensics to understand more about the adversary. This helps you better prepare for any future eventuality.
  • Requires capability to have full forensics details to reconstruct the attacks and avoid future risks: This is about capturing data points to help you aid in investigation post breach. capturing raw network data, keeping meta-data, Malware anatomy, analytics engine and all the right tools and processes that you must have should you want to find out what actually has happened, whats went wrong and how to prevent it in future.
  • You want to detect APT’s in SSL traffics and encrypted archive files: SSL is great for keeping our privacy on the internet, but the same tool is used by hackers nowdays to evade all of our security controls in pace to prevent us from getting attacked. Some ATP tool gives you the ability to look into the outbound & inbound encrypted traffic of your organizations, thereby, preventing anything wanted from getting downloaded into your organization network
  • You want to notify  your security controls regarding advance threats uncovered by your sandboxing tools: Integrating your advance threat protection tools with other security tools such as SIEM, Endpoint security, IAM, NGFW, IPS/IDS can really enhance overall security posture of any organization. ATP tools can reduce noise in SIEM results, can help contain the breach by updating the Endpoint security solution with latest signatures etc.

Do let me know if you want us to add or modify any of the listed key use cases.

Check out the Network Advanced Threat Protection market within  Product comparison platform to get more information on these markets.

Read more…

Identity and Access Management is the practice of managing digital identities through-out their life-cycle, managing access rights to enterprise resources and auditing of user access rights, use/misuse of digital identities. The entire process is mostly automated and require little to no human involvement.
Digital identities are often distributed across the heterogeneous mix of systems, devices and applications and poses significant risk to organizations in terms of security breaches and frauds. IAM consolidates and brings all identities under centralized management system where users are provisioned/de-provisioned role-based access rights to all enterprise resources centrally.

Key Use Cases 

–> Single Sign on:
 It is one of the greatest motivations for implementing IAM technologies. The benefits are quick and reduces the pain for maintaining several difficult passwords. Single-sign on is one credential to access of of the enterprise resources which you are authorized for both on-premise and cloud.

–> Centralized Provisioning/De-provisioning of users/identities:
Whether it is provisioning  identities to new employees or de-provisioning ex-employees accounts or managing third party/contractors  user accounts , It can all be done with one centralized console. This reduces the time and management overhead and also reduces the risk of any ghost accounts.

–> Auditing:
Track the end-to-end activities of users and use of access rights management. This includes both ongoing activity monitoring and periodic policy review, for concerns such as separation of duties.

–> Provisioning of Cloud applications or services to users:
Manage end to end Account of users to these services right from account registration, Account management, account revocation to auditing with ease.
–> Role-based access to enterprise resources:
–> Attribute exchange:
–> Enabling automated online reporting to customers
–> Enabling extensive self-service functions in customer portals
–> Verifying customer identities during registration via direct link to the company’s CRM

Do let me know if you want us to add or modify any of the listed key use cases.

Check out the Identity and Access Management market within Product comparison platform to get more information on these markets.

Read more…

Things To Know About Print Security

These days, Printer is not the box in the corner of the office, which is harmless and doesn’t need more attention than normal wear and tear repair. In this 21st century, Printers and Multifunction printers (MFPs) are most vulnerable to the cyberattack and can be the cause of the breach of a very sensitive information. Most companies are cognizant of the fact that they need to secure themselves from the cyberattacks and hacks, but they generally forget to include their printers and multifunction printers in this purview and for some the concept of print security is vague.

According to PwC 90% of large and 74% of small UK organisations reported suffering a data breach in 2015, while a 2016 study from the Ponemon Institute reveals the average total cost of a breach to be $3 million, with the average cost per stolen record $158. According to QuoCirca’s survery, about 61% of the large enterprises admitted suffering from data breaches because of the insecure printing.

As Gartner reports, “Print devices were some of the first IoT devices on the enterprise network, yet customer awareness of print security risks is lagging.” We will try to collate all the important points which an organization should be aware of for better print security.

  1. Printers should not be forgotten and should also be included in companies’ security policies.
  2. Invest in authentic and good printer security, plus integrate your whole printer fleet under this security option including all brands.
  3. MultiFunction Printers (MFPs) need secure access to the network as they can be the entry points to the IoT networks. As Gartner reports, “Print devices were some of the first IoT devices on the enterprise network, yet customer awareness of print security risks is lagging.”
  4. Monitor the Printer users and usage to ensure compliance and to trace unauthorised access by using MFP audit log data or third-party tools, which provides full audit trail
  5. Instead of waiting for the breach to happen to know the status of your print security, conduct vulnerability assessment on regular interval and seek expert guidance.
  6. Follow a good security model for your print security, The Gartner report suggests your security model include:
    1. “Features that harden devices
    2. Encrypting data in motion and at rest
    3. Securing and controlling access
    4. Securing paper trays and paper output
    5. Providing detailed, auditable logs for forensic activity analysis”
  7. Follow the new trends in print security market and keep looking for vendors with innovative solutions in the print security market e.g. HP printers incorporate interruption recognition frameworks to alarm security groups when somebody is messing with gadget settings, and the gadgets can check the framework to guarantee just approved firmware is running when it boots up.

To know more about the printer security market, visit our Print Security market page within  Product comparison platform to get more information on these markets.

Read more…

Learn More About Key Program Metrics Of CASB

Cloud Access Security Brokers (CASB) are placed between cloud service consumers and cloud service providers to support continuous visibility, compliance, threat protection, and security for cloud services. They act as a security policy enforcement point for Cloud-based Services (primarily SaaS).

Common Use Cases:
-> Govern Shadow IT – Discovery, Risk Profiling and Policy Enforcement of Unauthorised Cloud Apps   Usage

-> Single Point of Policy Enforcement for SaaS Apps – DLP, IAM, Encryption etc.

-> Security Monitoring, Configuration Monitoring and Management
->Access Control – Who had access to what (Internal & External stakeholders)
->SaaS Application ownership, control – Who are the admins, business owner(s)
-> Demonstrate Compliance – PCI DSS, ISO, HIPAA etc.
-> Threat Protection
-> Cloud Spend Optimization
->Eliminate redundant applications (E.g.: Dropbox and Box)
->Dormant accounts / Ex-Employee accounts

 

Key Program Metrics:

High Risk Cloud Apps Discovered :

Number of High Risk Cloud Apps Detected based on Risk classification parameters

Of Redundant Cloud Apps Eliminated :
Number of duplicate / redundant cloud apps eliminated based on app discovery and use case. E.g.: File Storage consolidated to 1 from 4 (Google Drive, SkyDrive, Box and Dropbox)

Incidents Detected :
How many incidents were detected related to cloud apps usage

Cloud Apps Authorized / Unauthorized :
Ratio of Authorized vs Unauthorized Cloud-Apps in use

 

Do let me know if you want us to add or modify any of the listed key use cases.

Check out the Cloud Access Security Brokers (CASB) market within Product comparison platform to get more information on these markets.

Read more…
Application Security Testing ( AST ) are tools and services that helps you discover security vulnerabilities in all kinds of applications. Current application security practices/tools available broadly falls into following categories:
  • Static Application Security Testing (SAST): Static application security testing tools analyzes the application source code to determine if vulnerabilities exist. IT is also referred to as White-box testing. SAST tools looks at the code before its compiled, so nothing is executed while testing applications code. This method helps in early identification of vulnerabilities thereby reducing the mean-time to production. S-AST tools can also be easily integrated with organizations Secure Development Life Cycle (SDLC) to further improve its effectiveness.
  • Dynamic Application security Testing (DAST): DAST tools are also referred to as Black box testing tools. They find potential vulnerabilities inside an application by trying to penetrate them in variety of ways, while the applications are running. They also do not require access to source code and binaries and can find business logic vulnerabilities and vulnerabilities in third-part software interfaces. They often complement the capabilities of S-AST tools, that’s why are often time used by organizations in addition to S-AST tools.
  • Interactive Application Security Testing (IAST): IAST is the mix of DAST and RASP, Run-time Application Security Protection, techniques. This approach analyzes application in the testing phase, using the RASP runtime agent and D-AST as an attack inducer. The agent, which is instrumented into the application runtime engine (e.g., into JVM), has insight into the application’s logic flow, data flow and configuration, monitors the test attacks initiated by the D-AST attack inducer, and then reports on the attacks that resulted (or might result) in an application’s exploit. I-AST reports help developers prioritize the vulnerability findings from dynamic scans, so that they can more effectively reduce risk while keeping up with production schedules.
  • Mobile Application Security Testing (Mobile AST): Mobile AST uses a combination of traditional SAST and D-AST and behavioral analysis using static and dynamic techniques to discover malicious or potentially risky actions the app may be taking unknown to the user (for example, activating the user’s address book or GPS)

Key Program Metrics:

# vulnerabilites in code over a period of time :
This includes bugs found through threat modeling and code reviews; by static analysis security testing (SAST), dynamic analysis security testing (DAST) and interactive application security testing (IAST) tools; and through pen testing and other testing.

Vulnerability density in a particular application :
The number of vulnerabilities divided by lines of code or some other proxy will give you vulnerability density, which makes it easier to compare risk in different systems, by technology platform or language and over time.

# vulnerabilities with high severity :
Evaluate how serious the vulnerabilities are by determining risk by likelihood (discoverability, exploitability, reproducibility) and impact. Standardize risk scores across tools and applications, using a scheme such as the Common Vulnerability Scoring System (CVSS), which ranks vulnerabilities from critical to low based on how easily a vulnerability can be exploited and its potential impact on data confidentiality, integrity and system availability.

Percentage of vulnerabilities fixed :
The percentage of total vulnerabilities, discovered through any means, fixed

Mean-time to repair :
How long did it take to fix the vulnerabilities? Or, to look at this data another way, how long, on average, did vulnerabilities stay open, especially serious vulnerabilities? What is your window of exposure?

 

Do let me know if you want us to add or modify any of the listed key use cases.

Check out the Application Security Testing (AST) market within Product comparison platform to get more information on these markets.

Read more…

Key Program Metrics of Data Loss Prevention

Data Loss Prevention is a set of security controls that helps organization protect their sensitive data, throughout its life cycle, across all platforms, from getting disclosed to unauthorized users (insiders or outsiders) either accidentally or intentionally.
Different types of DLP:
  1. Endpoint DLP: Protects data leak from endpoints devices such as, data leak from removable storage devices (USB’s), Local file shares, print services etc. Endpoint DLP controls data usage on laptops, workstations, servers and provides additional layer of protection for Mobile users.
  2. Network DLP: Provides broad security coverage across networks.  Network DLP is able to perform deep packet inspection across applications, Protocols and are able to monitor SSL/ and other forms of encrypted traffic. They are content aware and uses myriad set of rules and policies to monitor data in Motion.
  3. Storage DLP: Protects data stored on Storage towers and network storage. Helps in data discovery, data classification and data de-duplication.  Enforces sensitive data storage policy across all devices and networks.
  4. Cloud DLP: DLP functionality extended to the cloud. This is for the protection of your cloud apps or if you have sensitive data residing on the cloud. Cloud based DLP also has an additional advantage of being deployed in the more speedy and cost effective way. Cloud Access Security Brokers (CASB) provides Cloud DP features in addition to other security features.

Let’s have look at some of the key program metric of Data Loss Prevention (DLP) Technology:

Key Program Metrics:

#Exceptions granted during defined time period :
This is the number of exceptions granted over a defined time period. Exceptions are temporary permissions granted on a case-to-case basis. If the Exceptions are not tracked or documented these could result in potential vulnerabilities for exploitation. Ideally, the number of exceptions for a defined time period should remain as minimum as possible

# False positives during defined time period :
One of the major challenges in Data Loss Prevention program is dealing with false positives. Any mature DLP program within an organisation will try to reduce the false positives to near zero value. This metric is a very good indicator of your Data classification effectiveness, DLP rule-set effectiveness etc.

Mean time to respond to any attempted data breach :
This is the mean time to respond and initiate action to DLP alerts regarding possible data exfiltration attempt. This metric is important as most DLP implementations are for alerts only and aren’t put into Blocking mode due to high False-positives. DLP alerts are among the most significant security events those Data if not prioritized can result in a major data breach. DLP alerts can uncover malicious insider attacks, advance persistent threats and accidental data breach.

# Mis-managed devices in your network handling sensitive data :
This is the number of mis-managed devices which processes and stores sensitive data. This could be file shares, endpoints, servers etc. Each of these devices is potential egress points for sensitive data. A good DLP program will have all of the devices, that handles sensitive data, managed using DLP tool.

# Databases not yet fingerprinted :
Database fingerprinting is one of the key methods which any modern DLP tool use to protect your sensitive data against possible leakages. Ideally, all the databases holding sensitive data must be fingerprinted and available to the DLP tool. This metric gives an indication of the risks associated with databases which are yet to be fingerprinted.

# Databases and data residents not yet classified :
The first step in any Data Loss Prevention program is data classification. Data classification is done to identify sensitive data wherever it resides. It is imperative to classify databases and other data resident devices so that effective controls can be applied to them. If you are blind about your sensitive data sources your DLP is already a failure. This metric indicates you the number of databases, devices, endpoints, file shares which are still at your blind spots.

Do let me know if you want us to add or modify any of the listed key use cases.

Check out the Data Loss Prevention (DLP) market within Product comparison platform to get more information on these markets.

Read more…

Unified Threat Management (UTM) is an all in one security solution that integrates firewalls, anti-viruses, content filtering, spam filtering, VPN protection, anti-spyware and other security system you need to protect your network. It can perform many security functions simultaneously to provide layered protection to all sizes of organization.

Key Program Metrics:

  • Redundant rules :  These are the rules that are masked, completely or partially, by other rules that are either placed    higher up in the rule base. they add to the inefficiency and must be detected and removed subsequently
  • Of exception in rules :
    These are the exceptional cases where a rule is created temporarily to cater to the particular business need. care should be taken that all such rules are removed as soon as they are expired.
  • Rules with permissive services :
    Permissive services give more access then is needed to the destination by allowing additional services. The most common examples of this are rules with “ANY ” in the service field. These kind of rules should be minimized
  • Rules with risky services :
    Services such as telnet, ftp, snmp, pop etc. are risky because they usually credentials to be passed in plain text. Any service that exposes sensitive data or allows for shell access should be tightly monitored and controlled.
  • Rules with no documentation :
    UTM rules should be documented. Rules should be explained in detail, business case is described. Any rule change shall be according to proper change ticket.
  • Rules with no logging :
    UTM logs are useful for troubleshooting and forensics. It is very imperative that firewall logging hould be enabled and logs are leveraged for proper firewall management

 

Do let me know if you want us to add or modify any of the listed key use cases.

Check out the Unified Threat Management (UTM) market within Product comparison platform to get more information on these markets

Read more…

Key Program Metrics of Vulnerability Assessment

Vulnerability assessment is a process that defines, identifies, and classifies the security holes in a computer, network, or communications infrastructure. In addition, vulnerability analysis can forecast the effectiveness of proposed countermeasures and evaluate their actual effectiveness after they are put into use.
Vulnerability management program addresses the inherent problem associated with vulnerable software programs. These vulnerability if not checked and fixed may be exploited anytime thus giving unauthorised access to your organizations systems and networks, theft of your organizations confidential data, Regulatory/compliance violations and so on.

Key Program Metrics 

Mean time to resolve any reported vulnerability :

The time interval taken to remediate any vulnerabilities as reported by the VA tool

Remediation time for critical vulnerabilities :
This is the remediation time for vulnerability whose active exploits exist in the market and can have severe impact on the organization if exploited

# systems & applications not scanned for vulnerabilities :
This metrics will tell you the number of systems and applications which could become the entry point for hackers and they are never scanned for any vulnerabilities inside them. This is important because scanning only critical systems is not always safe, you have to scan systems & apps which are less critical and could be exploited.

# of vulnerabilities for which no patch is available :
This allows you to identify systems and applications for which you have to take extra care of or isolate since no patch is available to fix their vulnerabilities

# exceptions granted (Vulnerabilities) :
This metrics allows you to track the vulnerabilities which you may consider to be not critical and defer its remediation for the time being. You may set rules in your scanner to overlook such vulnerabilities but you have to track them for auditing and/or future actions

Do let me know if you want us to add or modify above information.

Check out the Vulnerability Assessment (VA) market within Product comparison platform to get more information on these markets

Read more…

Enterprise mobility management ( EMM ) is a suite of products which allows you to safely enable the use of mobile devices in your organization. Employees today want to use their personal devices for checking corporate mails and access sensitive documents as and when they need it, be it inside or outside the corporate network. This trend is not only adding to the productivity but also helps organizations cut down spending on IT infrastructure requirements.

EMM suites will help you safely provision/ de-provision mobile devices , Manage & secure access rights to your organization resources , Protects organization sensitive data on mobile devices and much more. You can remotely manage devices and perform actions such as remote lock, remote wipe, remove access rights etc. you can also manage and secure enterprise apps on the mobile devices of users and encrypt sensitive data/mails etc.
Several modules under Enterprise mobility suite are:

  • MDM: Mobile device Management (Device level management using agents)
  • MAM: Mobile application management (App level management through enterprise app store)
  • MCM: Mobile Content Management (Data protection)

 

# unmanaged devices in the enterprise network :
This is the total number of un-managed devices being used in the enterprise. Un-managed devices poses security risk to any organization, hence, this number should be as minimum as possible

# Shadow IT apps used by employees on mobile devices :
This metric identifies the number of unauthorized apps used on employees enterprise mobile devices

# Policy violations per month :
This is the total number of policy violations per month. This metric indicates the possible false positives/false negatives and help in policy fine-tuning.

Mean time it takes to provision and deprovision mobile devices in an enterprise network :
This metric refers to the mean time it takes to provision/deprovision any mobile devices in the network. EMM solution with centralized management and control this time should be usually in minutes.

Do let me know if you want us to add or modify above information.

Check out the Enterprise Mobility Management (EMM) market within Product comparison platform to get more information on these markets

Read more…

An emerging technology, Endpoint Detection and Response (EDR) constitutes a set of tools and solutions that enterprises use to detect, investigate and mitigate suspicious activities on hosts and endpoints. The term was originally called as Endpoint Threat Detection and Response (ETDR) but it is more popular as EDR.

Key Program Metrics:

Level of visibility the solution provides :
It defines the level of visibility the solutions provides for hosts and endpoints

Types of threat detected :
Threat types may be malware- crimeware, ransomware, trojans, exploit kits, etc

OS supporting ability :
Ability to support Operating Systems and platforms used by the organisation

File detection :
Ability to detect and hinder File based attacks (Microsoft Office, Adobe PDF, etc)

Security controls :
Security controls the solution uses to protect itself and response capabilties the solution offers

Do let me know if you want us to add or modify above information.

Check out the Endpoint Detection and Response (EDR) market within Product comparison platform to get more information on these markets.

Read more…

Distributed denial-of-service (DDoS) attack is one in which a multiple sources attack a single target causing denial of service for legitimate users of the targeted system. The flood of incoming traffic totally overwhelms the system, hence denying service to legitimate users.

Key Program Metrics:

Loss percentage :
number of packets or bytes lost due to the interaction of the legitimate traffic with the attack

Transaction Duration :
time between the start and end of the data transfer between a source and destination

Attack Traffic Filtering percentage :
overall percentage of attack traffic filtered after the detection of the attack

Detection percentage :
percentage of exactly defined attack sources

Traceback :
identification of the sources of the offending packets during and after the attack

READ MORE >>  5 Best DDoS Tools (Distributed Denial of Service) for Q1 2017

Do let me know if you want us to add or modify above information.

Check out the Distributed Denial Of Service (DDOS)  market within FireCompass to get more information on these markets.

Read more…

Distributed denial-of-service (DDoS) attack is one in which a multiple sources attack a single target causing denial of service for legitimate users of the targeted system. The flood of incoming traffic totally overwhelms the system, hence denying service to legitimate users.

Key Program Metrics:

Loss percentage :
number of packets or bytes lost due to the interaction of the legitimate traffic with the attack

Transaction Duration :
time between the start and end of the data transfer between a source and destination

Attack Traffic Filtering percentage :
overall percentage of attack traffic filtered after the detection of the attack

Detection percentage :
percentage of exactly defined attack sources

Traceback :
identification of the sources of the offending packets during and after the attack

READ MORE >>  5 Best DDoS Tools (Distributed Denial of Service) for Q1 2017

Do let me know if you want us to add or modify above information.

Check out the Distributed Denial Of Service (DDOS)  market within FireCompass to get more information on these markets.

Read more…

Distributed denial-of-service (DDoS) attack is one in which a multiple sources attack a single target causing denial of service for legitimate users of the targeted system. The flood of incoming traffic totally overwhelms the system, hence denying service to legitimate users.

Key Program Metrics:

Loss percentage :
number of packets or bytes lost due to the interaction of the legitimate traffic with the attack

Transaction Duration :
time between the start and end of the data transfer between a source and destination

Attack Traffic Filtering percentage :
overall percentage of attack traffic filtered after the detection of the attack

Detection percentage :
percentage of exactly defined attack sources

Traceback :
identification of the sources of the offending packets during and after the attack

READ MORE >>  5 Best DDoS Tools (Distributed Denial of Service) for Q1 2017

Do let me know if you want us to add or modify above information.

Check out the Distributed Denial Of Service (DDOS)  market within FireCompass to get more information on these markets.

Read more…