Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
It's been said that security is hard to measure. Producing measurable results around a lack of problems or incidents is challenging. But the field of security metrics has evolved considerably in recent years, giving security managers more resources to make the case for investing in security programs and technologies. . Now the SANS Institute, through their Securing the Human Program, is offering a set of free metric tools designed to give security leaders the ability to track and measure the impact of their own security awareness programs. The link for this article located at Network World is no longer available. . The SANS Institute offers free resources to evaluate security awareness initiatives, helping organizations measure training effectiveness and enhance their security posture. Security Metrics, SANS Tools, Cyber Awareness, Risk Measurement. . LinuxSecurity.com Team
Security is very old in most respects, yet very young in others. As a corporate discipline, security unfortunately languished for years in the basement. Today, as organizations come to grips with a wide swath of risks, the 2010 State of the CSO survey shows those organizations are rapidly adopting more sophisticated view of security. Of course, there's more work to be done--most prominently in the areas of security metrics and awareness programs. . Let's look at the numbers. 1. How well does each statement describe your organization? (Percent who agree or strongly agree with each statement.) Take a moment to reflect on the enormous progress reflected in the chart above. Six years ago, respondents reported a generally low regard for security risk management within their companies. Policies were not defined. Security leaders were sidelined. Training was minimal. The link for this article located at Network World is no longer available. . The 2010 CSO survey results highlight the evolving nature of security as a complex issue in organizations, emphasizing a shift to a holistic, integrated approach to protect data. CSO Survey Insights, Risk Management Trends, Security Challenges, Security Metrics Analysis. . LinuxSecurity.com Team
Securosis, Microsoft team up to solicit input for building a metrics model that measures efficiency and costs of security patching. Security consulting firm Securosis is spearheading a new effort to create metrics to quantify the cost and efficiency of an organization's security patching process. . Rich Mogull, founder of Securosis, says to date there's no real way to accurately measure the cost and productivity of an organization's security patch management process. "Those fully quantified [IT] risk models don't apply and the numbers aren't accurate," he says. "It's also bothered me to see those uber-metrics approaches that get an overview of everything in the security program. So why not start with one thing we can accurately measure and use it as a core for building security metrics?" Securosis, with the financial backing of Microsoft for the initial phase of the project, will gather input in an open submission process for the so-called Project Quant metrics model. Version 1 is planned for release by the end of June. The link at DarkReading is no longer available. . Uncover an innovative project aimed at evaluating expense and effectiveness in security update handling through a collaboration between Securosis and Microsoft.. Patch Management, Security Metrics, Cost Efficiency, Securosis Initiative. . LinuxSecurity.com Team
Mozilla is moving forward on a number of initiatives to ensure that Internet security improves. Among the efforts is a new approach for determining and measuring security metrics. The security metrics effort, announced earlier this year, is designed to figure out what matters in security and then measure and track those metrics. Snyder explained that the first step of the process, now wrapping up, is about determining what the company needs to look at in terms of security metrics. The next step is figuring how to get that information out of bugzilla and capture it on an ongoing basis. After that the challenge is to get information out and generating raw numbers. At the end the company will do analysis on that information to identify trends, correlate factors and draw conclusions. Mozilla is working on steps to improve the security of it's software by creating a security metrics. What do you think about this security metrics that they are developing? Will it help the security for Firefox? . The link for this article located at InternetNews is no longer available. . Google's commitment to privacy standards seeks to elevate data integrity, bolstering user confidence in Chrome.. Mozilla Security, Software Development, Internet Protection. . Bill Locke
The average unpatched Linux system survives for months on the Internet before being hacked, a report recently issued by the Honeypot Project claims. . The life expectancy of Linux has lengthened dramatically since 2001 and 2002, the project said, from a mere 72 hours two and three years ago to an average of three months today. Honeypot Project is a non-profit that, as its name suggests, connects vulnerable systems to the Internet in the hope of drawing attacks so that they can be studied. To figure out the lifespan of a Linux system, the group set up a dozen "honeynets" -- the project's term for a system that hosts numerous virtual honeypot machines -- in eight countries, then tracked the time it took for those machines to be compromised. The link for this article located at Gregg Keizer is no longer available. . The life expectancy of Linux has lengthened dramatically since 2001 and 2002, the project said, from. average, unpatched, linux, system, survives, months, internet, being, hacked, report. . LinuxSecurity.com Team
Many believe that demonstrating a ROSI in the enterprise is nigh impossible because there are no metrics that measure the ROSI unless a company is attacked or security is outsourced to a managed security provider. However, I've always been astounded by this attitude, as to me it appears that the most obvious point has been completely missed; organisations must begin with information risk assessments in order to evaluate the true effectiveness of their ROSI. . . .. Many believe that demonstrating a ROSI in the enterprise is nigh impossible because there are no metrics that measure the ROSI unless a company is attacked or security is outsourced to a managed security provider. However, I've always been astounded by this attitude, as to me it appears that the most obvious point has been completely missed; organisations must begin with information risk assessments in order to evaluate the true effectiveness of their ROSI. Most of us read with interest the publication of the Information Security Breaches Survey 2002 (ISBS 2002) from the DTI and learnt that last year 44% of UK organisations suffered at least one severe security incident that cost on average £30,000. Although the DTI recognised that the appropriate level of information security expenditure clearly depended on an organisations business circumstances, they went on to make the broad recommendation that information security officers (ISO's) allocate between 3-5% (rising to 10% for high risk sectors) of their IT budgets to information security. Furthermore that they thoroughly evaluate the ROI of IT security expenditure as only 30% of UK businesses were doing so, and of this only 16% incorporated this into their normal business processes. Today information risk is generally viewed in terms of threat, vulnerability and cost. If organisations are performing information risk assessments they are already aware of their risk profile; their threats, ease of exploitation, impact, and exposure levels; and have assigned them values and attributed overall costs.Organisations understand that there are levels of "acceptable" risk associated with trading and are therefore conscious of what risks their organisations are willing to bear. Strategic planning allows them to review the countermeasures and consider the costs ideally ensuring that these fall either around or beneath the original cost of the risk itself. By monitoring the effectiveness of the solutions deployed they have ensured that the ROI in IT security expenditure at best has been met; at worse is evolving. The link for this article located at ebcvg.com is no longer available. . Investigating the challenges associated with demonstrating Return on Security Investment (ROSI) in businesses through risk evaluations and quantitative measures.. Risk Assessment, ROIs, Security Metrics, IT Security Expenditures. . Anthony Pell
The government today received an overall failing grade for systems security the second consecutive year as Rep. Steve Horn issued his latest annual report card. There were few improvements in this year's card. The government's overall score was 55, up . . . . The government today received an overall failing grade for systems security the second consecutive year as Rep. Steve Horn issued his latest annual report card. There were few improvements in this year's card. The government's overall score was 55, up from 53 a year ago, and only 14 of 24 executive branch agencies received an F, compared with 16 agencies last year. But last year's standout agency, the National Science Foundation, dropped from a B+ to a D-. This year's top performer was the Social Security Administration, which climbed from a C+ to a B-. In the cellar this year is the Transportation Department, which scored what Horn called "an appalling 28 points out of a possible 100." The California Republican issued the grades during a hearing of his House Subcommittee on Government Efficiency, Financial Management and Intergovernmental Relations. The scores are based on weighted evaluations of each agency's performance in five major areas. The information is drawn from studies by the General Accounting Office, the Office of Management and Budget, and agencies' CIOs and inspectors general. The link for this article located at GCN is no longer available. . The government today received an overall failing grade for systems security the second consecutive y. government, today, received, overall, failing, grade, systems, security, second, consecutive. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.