info security considerations for it decision makers - redspin information security

Upload: redspin-inc

Post on 10-Apr-2018

215 views

Category:

Documents


0 download

TRANSCRIPT

  • 8/8/2019 Info Security Considerations for IT Decision Makers - Redspin Information Security

    1/13

    2>9; R`m Uimf& Zy`~i:

    Jmu{`a~iu`m& JM 0:;=:

    8;;,75=,0=77

    8;9,28>,2898

    WH@^I [M[IU

    @aboulm~`oa Zijyu`~pJoaz`nium~`oaz Man

    Uijollianm~`oaz Bou @^ ManEyz`aizz Nij`z`oa Lmdiuz

    Bou ma `aboulm~`oa

    zijyu`~p zpz~il ~o zy{{ou~

    ~hi eyz`aizz wi lyz~ ~uim~

    `~ f`di m zpz~il!

  • 8/8/2019 Info Security Considerations for IT Decision Makers - Redspin Information Security

    2/13

    ^MEFI OB JOA^IA^ZZyllmup=

    ^hi @aboulm~`oa Zijyu`~p Zpz~il5

    @zzyiz& ^huim~z man Zpz~il Bfmwz:

    Z~uyj~yu`ag m Uiz{oazi>

    Lmd`ag Nij`z`oaz9

    Eyz`aizz @l{mj~2

    mgi = v www!uinz{`a!jol 5;;0 v Wh`~i

  • 8/8/2019 Info Security Considerations for IT Decision Makers - Redspin Information Security

    3/13

    Oyu gomf `z ~o

    {uizia~ aboulm~`oa~hm~ w`ff ei hif{byf

    ao~ oafp ~o @^ man

    `aboulm~`oa zijyu`~p

    {uobizz`oamfz ey~

    eyz`aizz ya`~ giaiumf

    lmamgiuz mz wiff!

    ^h`z wh`~i {m{iu oy~f`aiz joaz`nium~`oazman uijollianm~`oaz ou uinyj`ageyz`aizz u`zd ~huoygh ~hi yzi o maiij~`ri ia~iu{u`zi `aoulm~`oa zijyu`~p{uoguml!

    Oyu gomf `z ~o {uizia~ `aoulm~`oa

    ~hm~ w`ff ei hif{yf ao~ oafp ~o @^ man

    `aoulm~`oa zijyu`~p {uoizz`oamfz

    ey~ eyz`aizz ya`~ giaiumf lmamgiuz

    mz wiff!

    ^huoyghoy~& wi ~mdi ~hi {iuz{ij~`rio {uizia~`ag man joaz`niu`ag jho`jizemzin oa o{~`l`s`ag m zijyu`~p {uogumlou iij~`riaizz& ij`iajp man eyz`aizz`l{mj~!

    @a m uijia~ Hmurmun Eyz`aizz Uir`iwmu~`jfi ~`~fin ^hi E`g Zh`~ (HEU4 Cyfp,Mygyz~ 5;;04 Coha Ziifp,Euowa& FmagNmr`nzoa ~hi my~houz {uizia~in ~hi`nim ~hm~ `a ~`liz o ijoaol`j ju`z`zzyjh mz ~hozi wi mji aow& ~umn`~`oamfli~u`jz ou lmamg`ag eyz`aizz lmp ei`azyj`ia~ ~o {o`a~ ~hi wmp ouwmun!^hi HEU mu~`jfi {uizia~z m umliwoud ouyaniuz~man`ag eyz`aizz ~umazoulm~`oa`a ~iulz o ~huii mj~ouz3 oyanm~`oaz oulmcou jhmagi (zyjh mz jol{y~i {owiuman @a~iuai~ yzmgi& bowz o uizoyujiz(zyjh mz `aoulm~`oa man daowfingiman ~hi `l{mj~ o ~hi jole`am~`oa o~hi {uir`oyz ~wo mj~ouz oa jol{ma`izman ~hi ijoaolp! Mz `z o~ia ~hi jmzi

    `a eyz`aizz& ~h`z umliwoud `z limzyuinmz ma `anix (~hi zh`~ `anix jol{u`zino ~huii jol{oaia~z3 oyanm~`oa& bowman `l{mj~! ^hi oyanm~`oa `anix `zz~uoagfp `abyiajin ep jol{y~`ag manjollya`jm~`oaz (@a~iuai~ `aumz~uyj~yui!

    ^hi bow `anix `z `abyiajin ep`aoulm~`oa zhmu`ag man @a~iuai~ mj~`r`~p!^hi `l{mj~ `anix `z `abyiajin epeuman fopmf~p man jol{i~`~`ri `a~iaz`~p!^hi mu~`jfi joajfyniz ep jhmffiag`agixijy~`riz oa how ~hip jma eiz~ juim~iman jm{~yui rmfyi ep lmamg`ag ~hizimj~ouz!

    ^hi {yu{ozi o ~h`z {m{iu `z ~o ixml`ai`aoulm~`oa zijyu`~p `a ~iulz o iamef`ageyz`aizz! W`zifp yzin& wi eif`iri ~hm~zijyu`~p {fmpz m lmcou uofi a juim~`ag manjm{~yu`ag eyz`aizz rmfyi! G`ria ~h`z uofi&wi umli ~hi n`zjyzz`oa o `aoulm~`oazijyu`~p mz m zpz~il whozi ijmjp jmaei irmfym~in `a ~hi ~iulz zyggiz~ epZiifp,Euowa man Nmr`nzoa! Wi joaz`niu`aoulm~`oa zijyu`~p uol ~hi {iuz{ij~`rio iamef`ag ma ij`ia~ jol{y~i manjollya`jm~`oaz `aumz~uyj~yui ({oz`~`rifp`l{mj~`ag ~hi oyanm~`oa `anix! Wiixml`ai whm~ `z ui}y`uin ~o zy{{ou~~hi bow o `aoulm~`oa man daowfingiuizoyujiz `a m zijyui mzh`oa ({oz`~`rifp`l{mj~`ag ~hi bow `anix! Fmz~fp& wiix{foui li~honz ~o ni{fop `aoulm~`oa

    zijyu`~p ~ijhaofogp man {uojizziz`a ouniu ~o {uo~ij~ jou{oum~i eumanzman {uolo~i jol{i~`~`ri mnrma~mgi({oz`~`rifp `l{mj~`ag ~hi `l{mj~ `anix!

    Zyllmup

    mgi 5 v www!uinz{`a!jol 5;;0 v Wh`~i

  • 8/8/2019 Info Security Considerations for IT Decision Makers - Redspin Information Security

    4/13

    ^hi @aboulm~`oa Zijyu`~p Zpz~ilBou ma `aoulm~`oa zijyu`~p zpz~il ~o zy{{ou~ ~hi eyz`aizz wi lyz~ ~uim~ `~ f`di m zpz~il!@~ lyz~ hmri z~uyj~yui man ei limzyumefi! @a lmap ia~iu{u`ziz ~h`z limaz jm{~yu`agfog fiz& joya~`ag `a~uyz`oaz man ~umjd`ag foz~ nm~m `aj`nia~z! Wi zyggiz~ m n`iuia~m{{uomjh ~hm~ z~mu~z w`~h m ~o{ nowa {iuz{ij~`ri! Wi mfzo eif`iri ~hm~ m zpz~il lyz~ei u`jh w`~h ~hi aijizzmup `aoulm~`oa ey~ z`l{fi iaoygh ~o zy{{ou~ eyz`aizz nij`z`oalmd`ag!

    Oyu `aoulm~`oa zijyu`~p zpz~il yziz ~hi ~iulz {uizia~in `a ~hi HEU mu~`jfi! Yf~`lm~ifpwi hmri ~huii ifilia~z ~o lmamgi w`~h ~huii mzzoj`m~in `an`jiz ~o ~umjd! ^hi zpz~il `z`ffyz~um~in `a ~mefi =!

    mefi =! H`gh firif ifilia~z man li~u`jz mzzoj`m~in w`~h ~hi @aboulm~`oa Zijyu`~p Zpz~il

    Boyanm~`oa Bfow @l{mj~

    Dip Ifilia~z

    Dip Li~u`j

    Z~oumgi& Jol{y~i&M{{f`jm~`oaz&

    Jollya`jm~`oaz@abumz~uyj~yui

    Nm~m& @aboulm~`oa&Daowfingi& [io{fi

    Mrm`fme`f`~p Joab`nia~`mf`~p @a~igu`~p

    Eyz`aizz[uojizziz&

    Eyz`aizz Rmfyi

    B`gyui =! H`gh firif jol{oaia~z ob ~hi @aboulm~`oa Zijyu`~p Zpz~il

    Aix~& wi lyz~ ~h`ad meoy~ ~hi ifilia~z ~hm~ joaaij~ ~hi `aboulm~`oa zijyu`~p zpz~ilw`~h ~hi eyz`aizz! Ma `nimf nizju`{~`oa ob ~hi jyz~oliu zijyu`~p zpz~il `z zhowa `a ~hiboffow`ag n`mguml3

    H`gh Firif Jol{oaia~z

    ob ~hi @aboulm~`oa

    Zijyu`~p Zpz~il

    mgi : v www!uinz{`a!jol 5;;0 v Wh`~i

  • 8/8/2019 Info Security Considerations for IT Decision Makers - Redspin Information Security

    5/13

    G`ria ~h`z z~uyj~yui ~hi jyz~oliu zijyu`~p {uoguml loriz ouwmun emzin oa eyz`aizzui}y`uilia~z man `z mjjifium~in emzin oa z{ij`j eyz`aizz nu`riuz! ^hi {u`lmupjol{oaia~z o ~hi {uoguml mui {of`jp& z~um~igp& man joa~uof! ^hi niz`uin z`~ym~`oa `zou m jyz~oliu ~o niai ~hi u`zdz mj`ag ~hi eyz`aizz& ~hi ui}y`uilia~z ou ~hi zijyu`~p{uoguml man mu~`jyfm~i ~hi gomfz man limzyuiz ou ~hi {uoguml ~o mjh`iri! hi z~um~igp`z nirifo{in ~huoygh m lonif o ~hi u`zd z`~ym~`oa& nm~m ~o ei {uo~ij~in man joa~uofz~o jmuup oy~ ~hi {uo~ij~`oa oecij~`ri! Fmz~fp ~hi joa~uof zij~`oa `l{filia~z& myn`~z manlmamgiz ~hi {fma! ^hi ai~ uizyf~ `z eyz`aizz iamefilia~!

    @a ma nimf z`~ym~`oa ~hi jyz~oliu zijyu`~p zpz~il offowz ~hi {fma ~hm~ z `ffyz~um~in meori!@a lmap ia~iu{u`ziz ~onmp& ~h`z `z ao~ ~hi jmzi& ey~ m {uoguml joaz~uyj~in ~huoygheiz~ {umj~`jiz zhoyfn ei nu`ria ep eyz`aizz ui}y`uilia~z& ojyz oa u`zd uinyj~`oa mangy`nin ~huoygh {of`jp! Zpz~ilm~ j li~u`jz lyz~ ei yzin ~o gmygi ~hi iij~`riaizz manij`iajp o ~hi {uoguml w`~h joyuzi jouuij~`oaz whiui aijizzmup!

    Lmap jol{ma`iz mff zhou~ o ~h`z `nimf! M jolloa ~ianiajp `z ~o ojyz oa ~ijhaofogpum~hiu ~hma {uojizz! O~ia ~hi ~huim~z {uizia~in ep ~hi ijozpz~il uizyf~ a nij`z`oaz nu`ria~huoygh imu! Z`l`fmufp& ~hi aiin ~o uiz{oan ~o {mu~`jyfmu iria~z zyjh mz m uigyfm~oupmyn`~ n`j~m~iz eihmr`ou man nij`z`oaz `a m zyeo{~`lmf mzh`oa! ^mdia mnn`~`rifp& ~hizijoan`~`oaz fimn ~o mn hoj z~mag& `ff niain uiz{oaz`e`f`~`iz man yaz~uyj~yuin zijyu`~p{of`j`iz! ^hi ai~ uizyf~ uiz~u`j~z eyz`aizz mg`f`~p& guow~h man `ajoli!

    ^o mjh`iri ~hi niz`uin z`~ym~`oa o ~hi `aoulm~`oa zijyu`~p zpz~il iamef`ag eyz`aizz&

    ma `l{ou~ma~ {o`a~ o firiumgi f`iz w`~h {of`jp! mefi 5 `ffyz~um~iz zoli dip `aoulm~`oazijyu`~p {of`jp muimz man ~hi`u uifm~`oa ~o oyu oyanm~`oa& bow& `l{mj~ lonif o ~hi`aoulm~`oa zijyu`~p zpz~il!

    ^hi {u`lmup

    jol{oaia~z ob ~hi

    {uoguml mui {of`jp&

    z~um~igp man joa~uof!

    Boyanm~`oa Bfow @l{mj~

    Dip Ifilia~z

    Dip Li~u`j

    Z~oumgi& Jol{y~i&M{{f`jm~`oaz&

    Jollya`jm~`oaz@abumz~uyj~yui

    Nm~m& @aboulm~`oa&Daowfingi& [io{fi

    Mrm`fme`f`~p Joab`nia~`mf`~p @a~igu`~p

    Eyz`aizz[uojizziz&

    Eyz`aizz Rmfyi

    [of`jp Muimz Eyz`aizz Joa~`ay`~p Nm~m Jfmzz`b`jm~`oa U`zd M~~`~yni

    U`zd Mzzizzlia~ Uigyfm~oup Jol{f`maji

    Zijyu`~p Iaboujilia~ [u`rmjp Myn`~ [uojizz

    N`zmz~iu Uijoriup @a~iffij~ymf[uo{iu~p [uo~ij~`oa

    @aj`nia~ Uiz{oazi

    Loa`~ou`ag Zijyu`~pMwmuiaizz ^um`a`ag

    [uoguml man[uojizz Rmfym~`oa

    M{{f`jm~`oa Zijyu`~p @nia~`~p manMjjizz Lmamgilia~

    U`zd Lmamgilia~

    @abumz~uyj~yui@l{mj~ Uir`iw

    @aboulm~`oa@l{mj~ Uir`iw

    Eyz`aizz@l{mj~ Uir`iw

    @aboulm~`oa [u`r`figi

    mefi 5! [of`jp muimz mzzoj`m~in w`~h ~hi @aboulm~`oa Zijyu`~p Zpz~il

    mgi > v www!uinz{`a!jol 5;;0 v Wh`~i

  • 8/8/2019 Info Security Considerations for IT Decision Makers - Redspin Information Security

    6/13

    Bou ma `aoulm~`oa zijyu`~p zpz~il ~o ei uyaa`ag o{~`lmffp lmamgiuz lyz~ lmdi {of`jpnij`z`oaz meoy~ imjh o ~hizi muimz man {y~ `a {fmji {uojizziz ~o jmuup oy~ ~hi`unij`z`oaz! @ lmamgiuz `gaoui ~hi`u uiz{oaz`e`f`~p ou ~mdi zhou~jy~z oa {uojizz& mn,hojnij`z`oaz w`ff ff ~hi ro`n! O~ia w`~h n`zmz~uoyz uizyf~z!

    Fi~z n`zjyzz m iw {of`jp muimz `a imjh jm~igoup ~o ix{foui ~hi uifm~`oazh`{ o {of`jp ~o~hi `aoulm~`oa zijyu`~p zpz~il!

    BOYANM^@OA

    U`zd Mzzizzlia~Ma ia~iu{u`zi lyz~ z{ij`p ~hi zjo{i& ui}yiajp man m{{uomjh ~o u`zd mzzizzlia~z!^p{`jmffp ~h`z mj~`r`~p ui}y`uiz z{ij`mf zd`ffz `a ixijy~`ag ~hi mzzizzlia~ mz wiff mzjollya`jm~`ag ~hi uizyf~z! hi eiai~ z m u`zd emzin mamfpz`z o whiui ~o ojyz zijyu`~puizoyujiz man ~ijhaofogp!

    M{{f`jm~`oa Zijyu`~p^hi {of`jp ~iml lyz~ oy~f`ai ui}y`uilia~z ou zijyui zo~wmui nirifo{lia~ {uojizziz&~iz~`ag {uojinyuiz& jhmagi lmamgilia~ {uojinyuiz mz wiff mz lmap o~hiu muimz ~hm~`l{mj~ m{{f`jm~`oa zijyu`~p! Ixijy~in wiff& ~hi jol{map w`ff hmri m firif o mzzyumaji~hm~ ~h`z loz~ {uirmfia~ ~huim~ rij~ou `z yaniu joa~uof!

    @aumz~uyj~yui @l{mj~ Uir`iw[of`jp lmdiuz lyz~ nij`ni ~hi ui}yiajp& {uojizz& {mu~`j`{ma~z& li~u`jz man `aoulm~`oazoyujiz ~hm~ jol{u`zi ~hi uir`iw o {iuoulmaji mgm`az~ {of`jp! ^hi jol{map jma yzi~h`z ouyl ~o lmdi joyuzi jouuij~`oaz `a ~hi`u nij`z`oaz man mj~`oaz!

    BFOW

    Nm~m Jfmzz`bjm~`oa^hi ia~iu{u`zi {of`jp `a ~h`z muim z{ij`iz m~~u`ey~iz meoy~ jfmzziz o nm~m man ~hiuizyf~`ag `l{f`jm~`oaz `a z~ou`ag& ~umazl`~~`ag man zijyu`ag ~hi nm~m! M w`zi {of`jp `a ~h`zmuim hmz z`ga`jma~ eyz`aizz {mpemjd eijmyzi `~ mffowz ~ijhaofogp man uizoyujiz ~oojyz nm~m zijyu`~p iou~z whiui `l{mj~ w`ff ei loz~ eiaij`mf!

    [u`rmjp@a uijia~ pimuz {u`rmjp hmz eijoli ma l{ou~ma~ jol{oaia~ o goriualia~ man anyz~upuigyfm~`oaz! Ep l{filia~`ag m jou{oum~i {of`jp ~hm~ lii~z ~hi aiinz o ~hi jou{oum~`oamz wiff mz ~hi uigyfm~ouz m guim~ nimf o firiumgi jma ei mjh`irin!

    @aoulm~`oa @l{mj~ Uir`iw^h`z {of`jp uir`iw giaiumffp ~mdiz ~hi zmli zhm{i mz ~hi `aumz~uyj~yui uir`iw ey~ ~ianz~o ei loui n`jyf~ ~o lmamgi eijmyzi o ~hi n`riuz`~p o r`iw{o`a~z man `a~iuiz~z! Oyuuijollianm~`oaz mui ~o jmuiyffp joaz`niu ~hi myn`iaji man ~hi gomfz ~o ei mjh`irin~huoygh ~hi uir`iw {uojizz!

    mgi 9 v www!uinz{`a!jol 5;;0 v Wh`~i

  • 8/8/2019 Info Security Considerations for IT Decision Makers - Redspin Information Security

    7/13

    Loz~ a~iuam~`oamf

    ia~iu{u`ziz mui

    zyecij~ ~o hyanuinz

    ob uigyfm~`oaz! Ob~ia

    `~ `z z`l{fp ~oo

    ix{iaz`ri ~o juim~i

    ma yeiu,{of`jp

    ~hm~ mnnuizziz mff

    `zzyiz!

    [uo~ij~`oa O^umazmj~`oa Rmfyi

    M jolloa{fmji mj~`r`~p mloageyz`aizziz z ~o jfimu ~umazmj~`oaz ~huoyghifij~uoa`j yanz ~umaziu! hizi {uojizziz{uizia~ m z`ga`jma~ muim o ix{ozyui oueuimjhiz o zijyu`~p!

    [uo~ij~`oa O Zy{{fp/nilman Jhm`a @a~igu`~p

    Mz ma `ajuimz`ag mloya~ o eyz`aizzmzzoj`m~in w`~h jol{ma`iz zy{{fp mannilman jhm`a `z joanyj~in oriu ~hi`a~iuai~& ~hi ix{ozyui ~o nmlmgi guowz![mu~`jyfmufp& ~h`z z`~ym~`oa `z jol{oyaninw`~h m~~mjdz n`uij~in m~ loai~mup gm`az!

    [uo~ij~`oa O [u`rmjp^hizi aiinz {iurmni mff mz{ij~z o ~hijou{oum~`oaz eyz`aizz ~umazmj~`oaz& ey~

    mui {mu~`jyfmufp r`z`efi `a ~hi jyz~oliuuifm~`oazh`{ lmamgilia~ {uojizziz!Bfmwz a ~h`z muim jma uizyf~ a uigyfm~oup{iamf~`iz ou wouzi!

    Uigmunfizz o whi~hiu m jyz~oliu z ixijy~`ag ma o{~`lmf ou zye,o{~`lmf zijyu`~p {uoguml~hip lyz~ zy{{ou~ ~hi eyz`aizz! ^h`z `z ~uyi `a map `anyz~up ziglia~! Ziriumf o ~hi `zzyiz{uizia~in ~o eyz`aizziz w`~h uiz{ij~ ~o `aoulm~`oa zijyu`~p `ajfyni3

    [uo~ij~`oa O@a~iffij~ymf [uo{iu~p

    ^h`z ui}y`uilia~ rmu`iz mjuozz `anyz~upziglia~z ey~ ui}y`uiz {uo~ij~`oa oju`~`jmf eyz`aizz `aoulm~`oa! O~ia ~h`zui}y`uilia~ `z ixmjiuem~in ~huoygh ~hiaiin ~o zhmui ju`~`jmf niz`ga nm~m w`~hzy{{f`iuz man {mu~aiuz!

    [uo~ij~`oa O EumanMan Ui{y~m~`oa

    W`~h ~hi mnria~ o ~hi `a~iuai~~hi o{{ou~ya`~`iz ou jol{ma`iz ~omnrmaji ~hi`u euman uijoga`~`oa manui{y~m~`oa hmri `ajuimzin numlm~`jmffp!Jouuiz{oan`agfp& ~hi ~huim~z hmri`ajuimzin mz wiff! W`~hoy~ m z~uoagzijyu`~p {uoguml jol{ma`iz mji mlmcou u`zd!

    [uo~ij~`oa O^umazmj~`oa @a~igu`~pMz loui jol{ma`iz joanyj~ eyz`aizzemzin oa `a~iuai~ {uo~ojofz ~hio{{ou~ya`~p ~o mjjifium~i eyz`aizz `zguim~fp `ajuimzin! Howiriu& lmapj`ujylz~majiz ix`z~ `a wh`jh ~hi zijyu`~po ju`~`jmf ~umazmj~`oaz jma ei zyeriu~in&uizyf~`ag `a lmcou nmlmgi ~o ~hijou{oum~`oa!

    @L[MJ^

    Uigyfm~oup Jol{f`majiLoz~ `a~iuam~`oamf ia~iu{u`ziz mui zyecij~ ~o hyanuinz o uigyfm~`oaz! O~ia `~ `z z`l{fp~oo ix{iaz`ri ~o juim~i ma yeiu,{of`jp ~hm~ mnnuizziz mf f `zzyiz! Howiriu& ~h`z {of`jpmuim lyz~ ei ix{f`j`~ meoy~ whiui iou~ w`ff ei joazof`nm~in& ~hi zjo{i o jol{f`majiiou~z man ~hi {uojizziz ou `a~iumj~`ag w`~h myn`~ouz man ui{ou~`ag uizyf~z!

    U`zd Lmamgilia~

    Wh`fi u`zd lyz~ ei m joaz`nium~`oa `a mff muimz o ~hi zijyu`~p zpz~il& {of`jp lyz~ gy`ni~hi limaz ep wh`jh u`zd `z lmamgin! @aoulm~`oa zijyu`~p `z ma o{ium~`oamf u`zd ~hm~ ~zw`~h`a m fmugiu zpz~il o ia~iu{u`zi amaj`mf u`zd! ^hi {of`jp lyz~ z{ij`p ~hi gomfz manzjo{i o ~h`z muim ~hm~ hmz m h`gh {o~ia~`mf ~o eu`ag z`ga`jma~ eyz`aizz eiai~ ~huoygh`l{uor`ag iij~`riaizz man ij`iajp!

    [uoguml Man [uojizz Rmfym~`oa^hi {of`jp zhoyfn zi~ ou~h ~hi gy`nif`aiz ou irmfym~`ag man limzyu`ag eyz`aizz rmfyi ozijyu`~p {uogumlz man {uojizziz! Joaz`z~iajp `a ~h`z muim `z dip ~o juim~`ag m jyf~yui ozijyu`~p {uogumlz mz eyz`aizz rmfyi juim~ouz! @a {umj~`ji wi hmri oyan ~ loui yziyf ~oirmfym~i ai~ {uizia~ rmfyi o m {uoguml um~hiu ~hma ma UO@ uol joz~ zmr`agz!

    @zzyiz& ^huim~z man Zpz~il Bfmwz

    mgi 2 v www!uinz{`a!jol 5;;0 v Wh`~i

  • 8/8/2019 Info Security Considerations for IT Decision Makers - Redspin Information Security

    8/13

    ^hi offow`ag muimz ui{uizia~ z`~ym~`oaz`a wh`jh jyz~oliuz o~ia go wuoag `almamg`ag ~hi`u zijyu`~p {uogumlz!

    M jolloa {uoefil `z ~hi m`fyui~o yaniuz~man ~hi iar`uoalia~mfjoan`~`oaz zyuuoyan`ag zijyu`~p

    {uogumlz!Ma ixml{fi o ~h`z {uoefil `z eyp`agmnn`~`oamf zijyu`~p {uonyj~z `a ~hi ho{i~hm~ oriumff zijyu`~p w`ff `ajuimzi! Zyjhj`ujylz~majiz {uizia~ m ayleiu o{uoefilz! B`uz~ ~hi jol{fix`~p `a~uonyjinep mnn`~`oamf zijyu`~p {uonyj~z o~iauizyf~z `a nijuimzin zijyu`~p! Aix~& ~him~~mjdiuz hmri ~hi mnrma~mgi o~iam~~u`ey~in ~o ~hi joan`~`oaz o mzplli~u`jwmumui& a ~hm~ ~hip lyz~ z`l{fp an oaimriayi ~o ix{fo`~ m ryfaiume`f`~p whiuimz~hi jou{oum~`oa lyz~ niian mff {ozz`efi

    {o`a~z o ix{ozyui!

    Mao~hiu `l{ou~ma~ {o`a~ `z ~hm~ lmapjol{ma`iz nimf w`~h zijyu`~p mz m ~uyz~`zzyi& ziid`ag li~honz ~o iazyui ~hm~`aoulm~`oa `z ~uim~in `a ~hi loz~ zijyuilmaaiu {ozz`efi uigmunfizz o ~hiz`~ym~`oa! @a zyjh m zjiamu`o ~hijou{oum~`oa anz `~zif `a ma mulzumji w`~h ~hi m~~mjdiuz! ^hi jol{map`z niz{ium~ifp ~up`ag ~o iazyui ~hm~`aoulm~`oa `z {uo~ij~in wh`fi ~him~~mjdiuz hmri ~hi mnrma~mgi o nia`ag

    ~hi em~~fiifn man jhooz`ag ~hi {o`a~z om~~mjd!

    @ABOULM^@OA ZIJYU@^P ZPZ^IL BFMWZ

    Byu~hiu& jyz~oliuz o~ia l`zyaniuz~manzijyu`~p zpz~il ui}y`uilia~z! @~ `zm{{imf`ag ~o uimj~ ~o aiw {uonyj~z ~hm~nimf w`~h ll`aia~ ~huim~z wh`fi ougo`agemz`j `aoulm~`oa zijyu`~p {u`aj`{fizuigmun`ag {uojizz! ^o `l{filia~ mzijyu`~p {uoguml {uo{iufp ~hi {u`lmup

    ojyz zhoyfn ei oa {uojizz& w`~hui}y`uilia~z jia~iuin oa ~hi zijyu`~p&zjmfme`f`~p man `a~igum~`oa jm{me`f`~`izmzzoj`m~in w`~h ~hi zpz~il mz m whofi!

    @a f`gh~ o ~h`z z`~ym~`oa& zijyu`~p {fm~oulrianouz man {uor`niuz o `a~iuai~`aumz~uyj~yui hmri m lmcou mnrma~mgi`a zy{{fp`ag jou{oum~`oaz w`~h zijyu`~pzofy~`oaz! Eijmyzi ~hi ~huim~ iar`uoalia~`z mz~ lor`ag& ~hi aiin ou {o`a~zofy~`oaz w`ff mfwmpz ix`z~& ey~ `a ~`li~hizi {uonyj~z w`ff ei `a~igum~in w`~h`ama oriumff zijyu`~p umliwoud {uor`ninep ~hi lmcou zy{{f`iuz `a ~hi `anyz~up![iuhm{z ~hi loz~ `l{ou~ma~ jol{oaia~o ~h`z mugylia~ `z ~hm~ zijyu`~p aiinz ~om{{imu mz zimlfizz ~o ~hi ian yziuz manmz zyjh lyz~ ei nif`riuin mz {mu~ o ~hioriumff @^ `aumz~uyj~yui!

    B`amffp `~ `z `l{ou~ma~ ~o uijoga`si ~hm~zijyu`~p `z ao~ m uizyf~ ou jou{oum~`oaz~o mjh`iri& ey~ liuifp m limaz omj`f`~m~`ag eyz`aizz! Noai wiff ~hi{uojizz w`ff ao~ `a~iuiui man o~iaw`ff mj`f`~m~i {uo~mefi guow~h o ~hi

    eyz`aizz!

    Jyz~oliu @aboulm~`oa

    Zijyu`~p Zpz~ilJoajiuaz

    B`gyui 5! Jyz~oliu aboulm~`oa zijyu`~p joajiuaz

    mgi 7 v www!uinz{`a!jol 5;;0 v Wh`~i

  • 8/8/2019 Info Security Considerations for IT Decision Makers - Redspin Information Security

    9/13

    ^HUIM^ IAR@UOALIA^

    Jyz~oliuz mji m npaml`j ~huim~ iar`uoalia~! ^hi irofy~`oa o ~h`z iar`uoalia~ `z{uizia~in `a ~hi gyui eifow!

    Ma `l{ou~ma~ `~il ~o ao~i `z ~hm~ m~~mjdiuz mui joaz~ma~fp mnm{~`ag lijhma`zlz ougm`a`ag mnrma~mgi! Lo~`rm~`oaz hmri mfzo jhmagin oriu ~`li! @a`~`mffp& m~~mjdiuz wiuizm~`zin w`~h ~hi ao~ou`i~p mzzoj`m~in w`~h ei`ag mefi ~o {iai~um~i m jou{oum~`oa![uizia~fp lo~`rm~`oaz mui nu`ria ep loai~mup gm`a! @~ `z mfzo ao~iwou~hp ~hm~ m~~mjdz muin`uij~in mgm`az~ ju`~`jmf `aumz~uyj~yui man mui joaz`niuin ma `l{ou~ma~ jol{oaia~ `aam~`oa,z~m~i wmumui!

    Ma `ffyz~um~`oa o ~hi jyuuia~ z~m~i o ~hi ~huim~ ijoaolp `z {uizia~in `a ~hi n`mgumleifow!

    Jyuuia~ Z~m~i ob ~hi

    ^huim~ Ijoaolp

    B`gyui >! huim~ Ijoaolp

    B`gyui :! huim~ Irofy~`oa

    mgi 8 v www!uinz{`a!jol 5;;0 v Wh`~i

  • 8/8/2019 Info Security Considerations for IT Decision Makers - Redspin Information Security

    10/13

    Wh`fi jo{`ag

    w`~h ~hizi ~huim~z

    eyz`aizziz lyz~ mfzo

    bmji ~hi jhmffiagi

    ob jol{fp`ag

    w`~h `anyz~up man

    goriualia~mf

    uigyfm~`oaz!

    Wh`fi nimf`ag w`~h ~hizi uigyfm~oup {uizzyuiz jyz~oliuz lyz~ jo{i w`~h m guow`ag~huim~ fmanzjm{i `ajfyn`ag jpeiuju`li& `a~iuamf ~huim~z man lmf`j`oyz mj~`r`~p oa ~hi{mu~ o eyz`aizz {mu~aiuz! Imjh o ~hizi muimz {uizia~z ya`}yi ~huim~z man zijyu`~pjhmffiagiz!

    Eijmyzi o ~h`z nmagiuoyz jf`lm~i jyz~oliuz mui u`gh~fp joajiuain meoy~ m ayleiu oz`ga`jma~ zzyiz ajfyn`ag3

    Euman [uo~ij~`oa

    U`zd Uinyj~`oa

    Ziur`ji Mrm`fme`f`~p

    Il{fopii [uonyj~`r`~p

    Uigyfm~oup B`aiz

    Ui{y~m~`oamf Nmlmgi

    @~ `z `l{ou~ma~ ~o ao~i ~hi jou{oum~`oa mz m whofi `z m z~mdihofniu w`~h uiz{ij~ ~o ~hi`zzyiz& ey~ imjh ougma`sm~`oa rmfyiz ~hil n`iuia~fp! Eyz`aizz ya`~z ~ian ~o {u`ou`~`sieuman {uo~ij~`oa man ziur`ji mrm`fme`f`~p eijmyzi ~hip mui yanmlia~mf ~o lm`a~m`a`agman `l{uor`ag eyz`aizz rmfyi! @^ ougma`sm~`oaz lyz~ uiz{ij~ ~hi aiin ~o mnnuizz iriup`zzyi& ey~ o~ia {u`ou`~`si jol{f`maji mz m limaz o zijyu`ag mnn`~`oamf yan`ag!Zijyu`~p guoy{z ~ian ~o ei nu`ria ep ~hi fm~iz~ ~huim~z ~o ~hi jol{mapz ui{y~m~`oa mz mwmp o {uor`ag ~hi`u rmfyi ~o ~hi ougma`sm~`oa! Bouwmun ~h`ad`ag jol{ma`iz uimf`si ~hm~`aoulm~`oa zijyu`~p z m lm~~iu o u`zd uinyj~`oa man z~u`ri ~o ya`p zijyu`~p {uogumlz zyjh

    ~hm~ ~hip lii~ ~hi joajiuaz o ~hi eyz`aizz `a ~hi loz~ ijoaol`jmf mzh`oa!

    JOL[F@MAJI UI]Y@UILIA^Z

    Wh`fi jo{`ag w`~h ~hizi ~huim~z eyz`aizz lyz~ mfzo mji ~hi jhmffiagi o jol{fp`agw`~h `anyz~up man goriualia~mf uigyfm~`oaz! Bou ~hi loz~& {mu~ ~hizi uigyfm~`oaz wiui`a~uonyjin eijmyzi eyz`aizziz fmjdin n`uij~ lo~`rm~`oa ~o `l{uori goriuamaji manzijyu`~p! ^hi `ffyz~um~`oa eifow ni{`j~z m umliwoud ou uifirma~ uigyfm~oup z~manmunzman gy`nmaji {uor`nin ep rmu`oyz `anyz~up man goriualia~mf ougma`sm~`oaz ~o mzz`z~ `ahif{`ag jou{oum~`oaz w`~h jol{f`maji!

    Lmap m~~il{~z hmri eiia lmni ~owmun {uor`n`ag m umliwoud ou lmamg`agma `aoulm~`oa zijyu`~p {uoguml! ^hizi umagi uol @ZO z~manmunz zyjh mz @ZO=7700 mz wiff mz giaiumf @^ lmamgilia~ umliwoudz zyjh mz Joe`^ man @^@F! Zhowa`a ~hi n`mguml eifow `z m umliwoud emzin oa A@Z^ gy`nif`aiz ~hm~ fmugifp uibij~zeiz~ {umj~`jiz!

    Z~uyj~yu`ag M Uiz{oazi

    B`gyui 9! Uigyfm~oup jol{f`maji z~uyj~yui

    mgi 0 v www!uinz{`a!jol 5;;0 v Wh`~i

  • 8/8/2019 Info Security Considerations for IT Decision Makers - Redspin Information Security

    11/13

    Um~hiu ~hma wmni a~o imjh muim o ~hi A@Z^ Gy`nif`aiz wi w`ff ui~yua ~o ~hi oyanm~`oa&bow& l{mj~ lonif o ~hi aoulm~`oa zijyu`~p zpz~il ~o z~uyj~yui m uiz{oazi! Oyu {uil`zi`z ~hm~ eyz`aizz u`zd uinyj~`oa {uor`niz ~hi uimzoa ou ~hi ix`z~iaji o ~hi `aoulm~`oazijyu`~p zpz~il! Wi w`ff irmfym~i zoli `l{ou~ma~ muimz o eyz`aizz u`zd `a ~hi ~iulz ooyu lonif!

    mefi :! [of`jp muimz mzzoj`m~in w`~h ~hi @aboulm~`oa Zijyu`~p Zpz~il

    Boyanm~`oa Bfow @l{mj~

    Dip Ifilia~z

    Dip Li~u`j

    Z~oumgi& Jol{y~i&M{{f`jm~`oaz&

    Jollya`jm~`oaz@abumz~uyj~yui

    Nm~m& @aboulm~`oa&Daowfingi& [io{fi

    Mrm`fme`f`~p Joab`nia~`mf`~p @a~igu`~p

    Eyz`aizz[uojizziz&

    Eyz`aizz Rmfyi

    U`zd Muimz Eyz`aizz Joa~ ay ~p Nm~m Zijyu ~p Uigyfm~oupJol{f`maji

    Zijyu`~pIaboujilia~

    @aboulm~`oaLmamgilia~

    @aj`nia~ Uiz{oazi

    N zmz~iu Uijoriup Joffmeoum~ oa Zpz~ilz Myn ~ [uojizz

    ^ijhaofogp@l{filia~m~`oa

    Ro`ji Jollya`jm~`oaz Zy{{fp Jhm`aLmamgilia~

    @abumz~uyj~yuiMujh`~ij~yui

    [u`rmjp Lmamgilia~ Nilman Jhm`aLmamgilia~

    @abumz~uyj~yuiLoa`~ou`ag

    @nia~`~p manMjjizz Lmamgilia~

    B`amaj`mf Ui{ou~`ag

    M{{f`jm~`oa Zijyu ~p Bumyn [uiria~`oa Mj}y`z ~ oa [uojizz

    B`gyui 2! A@Z^ Gy`nif`aiz

    mgi =; v www!uinz{ a!jol 5;;0 v Wh`~i

  • 8/8/2019 Info Security Considerations for IT Decision Makers - Redspin Information Security

    12/13

    Uigmunfizz ob ~hi

    joan`~`oa ob ~hi

    zpz~il& eyz`aizz

    lyz~ gi~ noai man`aboulm~`oa zijyu`~p

    nij`z`oaz w`ff ei

    lmni!

    Wh`fi ~hi u`zd muimz nizju`ein mui ep ao limaz ixhmyz~`ri& imjh muim jma eiirmfym~in `a ~iulz o u`zdz {uizia~in ~o ~hi eyz`aizz! @a~iuni{ianiaj`iz jma mfzo ei~mdia a~o mjjoya~! Bou ixml{fi u`zdz w`~h`a ~hi nia~`~p man mjjizz lmamgilia~ zpz~ilmui ni{iania~ y{oa u`zdz mzzoj`m~in w`~h `aumz~uyj~yui ~ijhaofogp `l{filia~m~`oa!

    ^hi ~umn`~`oamf lonif ou irmfym~`ag u`zd joaz`z~z o ryfaiume`f`~p x {uoeme`f`~p o ojjyuuiajix `l{mj~! Mzzizz`ag ryfaiume`f`~`iz hmz eiia ~hi ojyz o ~hi zijyu`~p jollya`~p ounijmniz! M rmu`i~p o lijhma`zlz ix`z~ ~o }yma~`p ~h`z mj~ou! @l{mj~ `z mfzo giaiumffpuimzoamefp wiff yaniuz~oon ~huoygh n`zjyzz`oaz w`~h ~hi eyz`aizz owaiuz who yzi ~hi

    zpz~ilz! Loui jhmffiag`ag `z ~hi {uoeme`f`~p o ojjyuuiaji! M z`l{f`z~`j m{{uomjh `z ~oum~i ~hi f`dif`hoon w`~h m h`gh& lin`yl& fow zjhili! ^hi aix~ z~i{ `z ~o aoulmf`si ~o mjolloa zjmfi man ni~iul`ai ~hi u`zd o imjh muim a ~iulz o noffmuz! @a oyu ix{iu`iaji&ou ju`~`jmf muimz `~ `z wou~h ~hi ~`li ~o nirifo{ m }yma~`~m~`ri lonif o {uoeme`f`~p oojjyuuiaji yz`ag Loa~i Jmufo z`lyfm~`oa ~o ni~iul`ai ~hi lima noffmuz m~ u`zd man ~hin`z~u`ey~`oa!

    Lmd`ag Nij`z`oaz@nimffp& ~hi ia~iu{u`zi zijyu`~p zpz~il hmz eiia joaz~uyj~in w`~h m ~o{,nowa lonif&nu`ria ep {of`jp man gy`nin ep uinyj`ag u`zdz! Uigmunfizz o ~hi joan`~`oa o ~hi zpz~il&

    eyz`aizz lyz~ gi~ noai man `aoulm~`oa zijyu`~p nij`z`oaz w`ff ei lmni! ^hi offow`agzij~`oa nizju`eiz zoli {umj~`jiz ~hm~ wi hmri oyan yziyf uol ix{iu`iaji!

    Yzi m z`l{fi z~i{ ep z~i{ nij`z`oa lmd`ag {uojizz! Bou ixml{fi3

    Yaniuz~man ^hi Eyz`aizz Joan`~`oaz=!iml jm{me`f`~p& o{ium~`ag iar`uoalia~& ~huim~ lonif& eyz`aizz nu`riuz& i~j!

    Ni~iul`ai ^hi Ui}y`uilia~z Bou Zyjjizz5!Eyz`aizz gomfz& zijyu`~p ui}y`uilia~z& o{ium~`oamf li~u`jz

    @nia~`bp [o~ia~`mf Zofy~`oaz:!Yzymffp ~huii ou boyu uimzoamefi jho`jiz

    ]yma~`~m~`rifp Lonif ^hi Eyz`aizz @l{mj~ Ob Imjh Zofy~`oa>!

    Mjjoya~ bou yajiu~m`a~p mzzoj`m~in w`~h imjh jho`ji

    Jhoozi ^hi O{~`lmf Zofy~`oa9!

    [iuhm{z ~hi imz`iz~ wmp ~o zii nij`z`oa lmd`ag uifm~in ~o ~hi `aoulm~`oa zijyu`~pzpz~il `z w`~h ma ixml{fi! @a ~h`z jmzi& ~hi jol{map wi woudin w`~h wmz m lmcouz~oumgi i}y`{lia~ zy{{f`iu! ^hi `aoulm~`oa ~ijhaofogp man zijyu`~p o{ium~`oaz ~imlzwiui `arofrin w`~h m {uocij~ ~o zmri 59) `a maaymf o{ium~`ag joz~z wh`fi mjh`ir`aguigyfm~oup jol{f`maji (m w`ni rmu`i~p o uigyfm~`oaz! ^hi {uoefil {uizia~in ~o ~hi~iml ep ixijy~`ri lmamgilia~ wmz ~o mjh`iri ~hi 59) gomf man limzyui ~hi eyz`aizzrmfyi o ~hi {uocij~!

    @a ixml`a`ag ~hi eyz`aizz joan`~`oaz loui jfozifp& ~hi @^ man zijyu`~p o{ium~`oazougma`sm~`oaz hmn m giaiumf ui{y~m~`oa ou ~ijha`jmf ixjiffiaji! Joz~ uinyj~`oa ~huoygh

    ~h`z {mu~`jyfmu jol{f`maji `a`~`m~`ri wmz m dip ~o oriumff ougma`sm~`oamf zmr`agz! M{uocij~ {fma wmz mfuimnp `a {fmji w`~h ~o~mf joz~ o owaiuzh`{ (^JO man ui~yua oa`ariz~lia~ (UO@ mz dip li~u`jz!

    Byanmlia~mf `zzyiz ~hm~ hmn pi~ ~o ei joaz`niuin wiui3

    Wmz ~hi {uo{ozin {uocij~ {fma ~hi loz~ iij~`ri?

    Wiui ~hiui loui iij~`ri man ibj`ia~ mf~iuam~`riz?

    Whm~ wmz ~hi rmfyi joa~u`ey~in ~o ~hi eyz`aizz ep no`ag ~hi {uocij~?

    mgi == v www!uinz{ a!jol 5;;0 v Wh`~i

  • 8/8/2019 Info Security Considerations for IT Decision Makers - Redspin Information Security

    13/13

    ^hi jyuuia~ joan`~`oaz zyggiz~in ~hm~ m z~m~yz }yo m{{uomjh woyfn ei ~mdia ~o ~hi{uoefil! Himnjoya~ uinyj~`oaz woyfn ei ixijy~in& man joz~ gomfz mz limzyuin epUO@ man JO woyfn ei li~! Ziriumf zzyiz wiui nia~`in w`~h ~h`z m{{uomjh! B`uz~& aozpz~ilm~`j limzyui o eyz`aizz rmfyi ix`z~in! Aix~& ~hiui wmz ao joaniaji ~hm~ joz~uinyj~`oa ~mugi~z joyfn ei }yma~`~m~`rifp {uin`j~in!

    ^hi uijollianin nij`z`oa lmd`ag m{{uomjh wmz mz offowz3

    Yaniuz~man jyuuia~ zpz~il jhmumj~iu`z~`jz

    Mj}y`ui }ymf`~m~`ri man }yma~`~m~`ri nm~m

    Nirifo{ m lonif o o{ium~`oamf joz~ oriu m ~huii pimu ~`li {iu`on joaz`niu`agr`mefi o{~`oaz

    Nirifo{ m lonif o eyz`aizz rmfyi man nu`riuz oriu ~huii pimuz joaz`niu`agr`mefi o{~`oaz

    Irmfym~i A[R& UO@& man ^JO o r`mefi {fmaz

    Lori ouwmun w`~h ~hi mj~`oaz ui}y`uin ~o lii~ ~hi gomfz man m{{fp eiz~{umj~`jiz whiui imz`efi

    ^hi oy~joli o ~hi {uocij~ mamfpz`z zyggiz~in ma mf~iuam~`ri m{{uomjh& zyumjin ~huoyghA[R mamfpz`z o ~hi eyz`aizz `l{mj~! Jol{f`maji gomfz wiui li~ wh`fi himnjoya~uinyj~`oaz wiui l`a`l`sin!

    Eyz`aizz @l{mj~Yf~`lm~ifp& ~hi ai~ uizyf~ z ~hi `a~igum~`oao ~hi eyz`aizz `l{mj~ o ~hi `aoulm~`oazijyu`~p zpz~il w`~h ~hi {uojizziz ~hm~mfuimnp lmamgi ~hi ia~iu{u`zi! M~ ~hiian o ~hi nmp& aoulm~`oa zijyu`~p joz~zloaip! Pi~& m wiff uya aoulm~`oa zijyu`~p{uoguml jma {oz`~`rifp `l{mj~ eyz`aizz

    uizyf~z! ^hi aijizzmup ui}y`uilia~

    `z m wiff mguiin y{oa umliwoud ~o`a~igum~i ~hi `aoulm~`oa zijyu`~p zpz~ilw`~h eyz`aizz o{ium~`oaz! ^h`z {m{iuhmz {uor`nin gy`nmaji ou yz`ag ~hi~oofz o {of`jp lmamgilia~ man u`zdlmamgilia~ ~o giaium~i {oz`~`ri uizyf~zou ~hi eyz`aizz!

    Uinz{`a nif`riuz ~hi h`ghiz~ }ymf`~p `aoulm~`oa zijyu`~p mzzizzlia~z ~huoygh ~ijha`jmfix{iu~`zi& eyz`aizz mjylia man oecij~`r`~p! Uinz{`a jyz~oliuz ajfyni fimn`ag jol{ma`iz`a muimz zyjh mz himf~h jmui& amaj`mf ziur`jiz man ho~ifz& jmz`aoz man uizou~z mz wiffmz ui~m`fiuz man ~ijhaofogp {uor`niuz! Zoli o ~hi fmugiz~ jollya`jm~`oaz {uor`niuzman jolliuj`mf emadz uifp y{oa Uinz{`a ~o {uor`ni ma iij~`ri ~ijha`jmf zofy~`oa~m`fouin ~o ~hi`u eyz`aizz joa~ix~& mffow`ag ~hil ~o uinyji u`zd& lm`a~m`a jol{f`maji man`ajuimzi ~hi rmfyi o ~hi`u eyz`aizz ya`~ man @^ {ou~of`oz![iai~um~`oa ^iz~`ag

    Meoy~ Uinz{`a www!uinz{`a!jol

    http://www.redspin.com/http://www.redspin.com/http://www.redspin.com/