Cybersecurity Digital Transformation

Security: A Moving Target!

Most innovations including virtualization, SOA, and Web 2.0 are still not fully cooked and have security vulnerabilities. Furthermore, there are more new innovations in the pipeline. How does an enterprise secure anything when everything is in flux?

Contributor

    • John Pescatore, Vice president and Research Fellow, Gartner Research

Download Podcast
Apple PodcastGoogle PodcastSpotifyPandoraiHeartRadioSoundCloudTuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.

Explore More

Transcript

Sanjog Aul
Good morning and welcome to CIO Talk Radio. To learn more about the show, please visit www.ciotalkradio.com. Today’s topic, Security: A Moving Target! Our guest for today is John Pescatore.

Sanjog Aul
We were to have Dave Cullen in, but he, I guess, had some last-minute issue which prevented him from joining us, but definitely brings a wealth of knowledge on the subject. So we will be going through the questions. How is it going?

John Pescatore
How’s business? Security business is good from both the vendor side and certainly from the bad guy side. They’ve seemed to have pretty good business going on as well.

Sanjog Aul
But do you think then when you have a good business, that means there’s not much security out there?

John Pescatore
Well, I mean, this has historically been the issue. How much security is enough? And obviously the answer to will we ever get to the point where security is perfect is no. What I’ve always looked at I’ve worked in security, computer and network and information security for 30 years now. One thing I’ve always looked at is the retail industry has numbers for hundreds of years really on what percent of revenue in the research industry is, or in the retail industry, is lost to they call it shrinkage, employee theft, pilfering and shoplifting, that kind of thing, and over all those years of data, typically in the retail industry, no matter what happens, they still lose 1.5% of revenue to shrinkage, and they spend about 1.5% of revenue to keep shrinkage down to 1.5% of revenue. So in the retail world, obviously, we human beings have been selling things to each other for thousands of years. So the most mature commerce market. In that world, they average over the past 30 years, 3% of revenue we’ve lost due to keeping shrinkage at 1.5% and experiencing the 1.5%

John Pescatore
and that’s an acceptable cost of doing business. So security is not perfect in retail, nor is it perfect in fighting counterfeiting of the US currency. I worked for the Secret Service and the Treasury Department, and obviously we do the government does lots of things to fight counterfeiting, but we still have some counterfeiting. So the issue in security is how do we keep the security incidents down to an acceptable level? And how do we keep the dollars we spend on security down to an acceptable level as well? Obviously, in shrinkage, if I could get shrinkage down to 1% of retail revenue, but it would cause me to spend another 4% of revenue, we’d be losing more money. So it’s the issue of how much security is enough is both how effective is it stopping the real-world threats, but also how efficient is it and how much of the company’s resources does it consume?

Sanjog Aul
So when you talk about security, this seems like, of course, it is a very big domain, and within that you have physical security, logical, and then IT. When it was introduced, of course, it brought its own risk, but also was an enabler of security technologies which would allow you to prevent other types of security issues. So It is introducing risk and is also enabling you to do a better job as a security professional. So when you look at the two sides of the coin, which one is causing more? You can say, what’s the net effect? Are we getting net positive or net negative here?

John Pescatore
One way I like to look at that is if you were to point at probably the two most successful In US anyway, in the US businesses today, you probably point at Google and Microsoft, say those are two companies that sell technology. Those are two companies that are really highly targeted by attackers and hackers, and they would say technology has been a net plus to our business, and I think eBay and Amazon would say the same thing. Now, if you were to point at Citicorp or UBS or Let’s even say the TJX Corporation that had a very large, highly publicized security incident that cost them hundreds of millions of dollars. If you were to point to them as technology overall, been a net plus to you or a net minus, they would certainly say a net plus. In the security world, it’s sort of like an irresistible force, and the technology invading things is happening.

John Pescatore
It started happening many years ago. Every wave of technology back to when the PDP first came around, every wave of technology provides business advantage well before it is secure enough to be used. So that the PC had no thoughts about security. I mean, really until Windows 2000, basically. So PCs are in use by businesses for 10 years before they had any Microsoft had any thoughts with security in Windows, and similarly, wireless LANs. Had no security or minimal security thoughts, improved business value. The internet, Web 2.0, all these things, businesses use them for business benefit quickly.

John Pescatore
Bad guys figure out how to exploit them for criminal purposes quickly, and then security people have often then just reacted. So I think part of the key to changing that balance is, Gordon, we’ve called it Security 3.0, for example, ’cause say get ahead of Web 2.0 and start realizing these technology waves will hit, will get used by businesses, and it’s real key to say, how do we make sure we get security built in, but as the business starts using these technologies, not looking at how do we sprinkle security on after the business starts using these new technologies.

Sanjog Aul
If you talk to an entrepreneur or you talk to an innovator, if you start challenging them upfront, or not exactly challenging, but you just put in these ifs and buts, in front of them, that kind of stifled the very entrepreneurial nature and/or the innovation process, or at least that will be, that is how it will be perceived. So would you say that while you want to be ahead, but you just have to put your ear to the ground versus going and challenging those people up front?

John Pescatore
Well, I mean, I think it’s more a matter for any entrepreneur, any innovator these days is realizing that security, and I’ll even say more broadly safety, has become a key requirement from customers. So if you’re an innovator and you’ve thought up a great way to get 90 miles per gallon out of an automobile these days, that’s a pretty attractive proposition, but if the car blows up once a week, probably not something venture capitalists are going to invest in. So similarly in technology, There’s you can look at the Microsoft world, or Google’s another great example. As Google has tried to expand beyond a search engine to get into enterprise business, one of the first things they ran out and did was acquire some security companies, Postini, for example, GreenBorder, and start building some security capabilities into Google’s offerings. So I think anybody would point at Google as an innovative company, and building security into their Google Apps offerings and some of their other offerings has turned out to be a key requirement for that innovation. So I really look at security viewed these days more and more by the end user as a feature. I really don’t wanna have to buy a new PC because they got riddled with spyware.

John Pescatore
Somebody can innovate and block that for me, that’s a cool thing. Similarly, if I’m a consumer and I have all my, photos now stored on my PC along with my electronic tax file. I’m considering keeping that safe, a feature of some of the software I’ll buy or the services. So we’re actually seeing a lot of innovation around ways to do security more transparently, ways to keep people safe without having to disrupt the way they want to do business.

Sanjog Aul
Would you say ignorance by discretion, that’s the phrase that I would use, is the way the world is working today? Because they would like to start trying something new while they may know that the security flaws may exist, but still they would want to go ahead and see, is it worth to go ahead and play with this and see if this really starts working? And then we try to grab the vendor by the neck and say, hey, why is it not secure?

John Pescatore
There’s a lot of that that still goes on. Almost invariably, at Barton, we’ve seen it falls into two categories. One is strictly some technology is going to save the business money and we can’t stop it from being used. A great example of that is something like Skype. Skype is something companies look at and say, well gee, if we bet our employees use Skype on their PCs, they could make long-distance phone calls, international especially, international long-distance phone calls, and instead of doing that on their cell phones, if they did it on Skype, we could save thousands of dollars per user per year. So in the old days, security would try to say, no, Skype’s not ready, and Gartner, we put out research 3 or 4 years ago, Skype is dangerous, shouldn’t be used for enterprises, but then you meet the irresistible force.

John Pescatore
Wait a minute, it’s a business benefit because it’ll reduce cost. We are going to use it. Don’t say no, tell us how to use it securely. So Skype, who got acquired by eBay, started building in a few security features. Gartner, we started coming out with guidance how to use it securely. So, one example is where something is going to reduce the business’s cost, and putting up a website instead of having people call an 800 number is another cost saver, they sure, they’re going to rush out to do it, but again, security groups can get involved early and say, here’s a secure way to use Skype, here’s a secure way to set up the website. The second way, which is much tougher to deal with, is happening these days in a big way.

John Pescatore
Gartner, we call this the consumerization of IT, and it’s really an old trend. Hey, people are using the internet at home. I want to use it at work, but today, if I want to work from my home PC, I’m going to read email. You expect me to read email at 10 o’clock at night? Why can’t I use my home PC and my own version of Outlook? And I’m running Vista instead of XP we have at work. Creativity is and you, if you get let users use the tools they’re familiar with. Not only do they work at odd times of the day or at night, why should we stop our employees from working 100 hours a week if that’s what they want to do?, but often they might be more creative and more productive

John Pescatore
and so that’s a little harder to sort of wrap your arms around with from a security perspective and say, wait a minute, your home PC, it’s not ready for business use. It’s got all these problems, but even there, we’re seeing many businesses’ approaches like network access control or even virtualization, desktop virtualization, be ways you can allow work to be done almost on the user’s terms and still be done securely.

Sanjog Aul
So when we go ahead and ask our life insurance person to give us a policy and we say, give me $1 million or $2 million or $500,000, and that is all dependent on what the probability of us being run over by a truck. Similarly, when we are going out there, how are we creating this? How are we estimating the probability of a security issue happening? I mean, there’s so much going on there, and we know that we could have that fear in us, but what is the actual level of security issues that may crop up? I mean, how does an organization make that determination and then kind of buy that policy? But let’s talk more when we come back from the break. Please stay tuned.

Sanjog Aul
Welcome back. We were talking about the actual issues that may come up and what’s the probability of a security threat coming, becoming a reality, and how, like in the life insurance policy when we buy, We don’t know when and what is the probability of us getting run over by a truck, but we buy the policy based on what we perceive as the probability. So what is the corresponding angle that we take in organizations or should take in organizations when they’re trying to write a check for how much should be budgeted for security?

John Pescatore
The way I usually address that is, I mean, there’s some things we look at things at a due diligence level, and if there’s some things where we say the probability that this incident will happen is 100%, what I don’t know is when it’ll happen. So for example, when I buy a house, I don’t know when it’s going to rain, but I know sooner or later it will rain. So I buy a house with a roof and I buy a house with a roof with shingles, and if I live in a place where it’s probably gonna snow, I might have different decisions to make, but I don’t say, well, maybe it, Maybe it won’t rain this year, so I won’t buy a roof. So similarly in information security, there’s some things that are just due diligence levels of things, things we know, and things like there will be network attacks. They happen every day.

John Pescatore
100% chance that if you’re connected to the internet, somebody will attack you. 100% probability. 100% probability if you have a website, somebody will try to attack it. 100% probability that if you have email, somebody will send you a virus or phishing email me like, so we know 100% probability bad things will happen, just as we know if I live in my house long enough, 100% chance there’ll be a thunderstorm, rain, et cetera. So the real issue is how do I prioritize areas that may not be sort of at that due diligence level? How do I determine how much I should spend on security? Again, thinking about retail, it’s had numbers over all these years, and then how do I prioritize what I should do? And that’s where a couple things come into play. Typically, risk assessment methodologies are used to say, what are my critical business systems? What incidents could happen that would disrupt my business? Whether it disrupt revenue, cause me high levels of cost to restore services or deal with an incident, and that’s relatively straightforward.

John Pescatore
Now, the issue is, by the way, Typically IT people, business people who are great at thinking up, here’s a new line of business we could get into, and IT people, hey, here’s a new technology that we could use to implement that new line of business. Those people who are good at that are usually very bad at thinking about the bad things that could happen. So it does take a separate discipline to do threat analysis and sort of look at, like we did the bad things, how would the bad guys exploit it and the like, but part of risk assessment is that first level of what’s critical to the business and then what are the potential threats against it, and then the gap analysis that says, where am I today in protecting against that threat? Then you get to the part of risk assessment where typically much of this starts to fall down, where you do start defining the probabilities to say, well, how do I prioritize these? So typically when we look at the most successful risk assessment methodologies, they’re not trying to do the old probability is 2% that they’ll happen and the cost of impact is $9 billion because what you’d normally what you typically find in that approach is you come up with a very small imaginary number. What’s the probability a meteorite will hit my house? And you multiply it by a very large imaginary number. I’d have to buy a new house for $1 million

John Pescatore
and you come up with a medium-sized imaginary number. So really what we typically see the successful approaches are looking at what are those critical business areas, what are the costs of interruption to those, and then what would be the cost of preventing those interruptions, and then that’s a decision that’s passed on to the bid list manager. Here’s the exposure, here’s what we could do to prevent the exposure. You own the profit and loss, you make the decision which way you want to go. Now that other areas where compliance comes into play, where things are dictated to us, we have to do it because we’ll fail an audit. Again, those, the risk assessment methodology fall down because we have regulatory reasons we have to do certain things. Bottom line is we see the typical enterprise these days spending on the order of about 6% of its IT budget on security

John Pescatore
and in some industries less, in some industries more, but that’s been a pretty typical number where businesses have been able to be secure enough to meet the business needs and the regulatory needs, and efficient enough that they’re not using up so much of the IT budget that the company can’t devote IT resources towards new business efforts.

Sanjog Aul
Now, lately you would’ve seen a lot more, or we have all seen for that matter, a lot more infusion of new disruptive technologies, new way of doing things, new paradigms. Would you say that perception of things likely to happen, and because we are kind of shooting in the dark with, from a security standpoint, when we are kind of playing with it, Should it not automatically, instead of 6%, it should turn into 8 or 9%, at least for that time being till the time this wave of innovation is happening? Because this is, this is different from some of the mature organizations using IT to get by doing their things, but now this is totally disruptive. So the, the question should change.

John Pescatore
I don’t think it should change. It often does. I don’t think it has to, and we certainly have examples of best practices why that percent of the budget spent on security does not just keep going up and up and up, and here’s why. In IT, we have a well-known thing called Murphy’s Law. Not Murphy’s Law, Moore’s Law. In security, we have a thing called Murphy’s Law that whatever can go wrong will.

John Pescatore
Whatever can’t go wrong, that’ll go wrong too. Moore’s Law says in information technology, essentially, This is the simplified version, but essentially next year when I buy the same product, it should cost less. Cost less. Or next year when I pay the same amount for technology, it should do more. That’s the rule of Moore’s Law simplified. Well, in security, the security vendors and the security marketplace for many years has been trying to ignore Moore’s Law in that people were paying $40 a desktop for antiviral software year after year after year. Even though each year all it did was the same thing it did the year before. Then along came a new threat, spyware, and the vendors tried to get another $40 for desktop.

John Pescatore
You need another thing that’ll stop spyware, and then the percent of you spending on security would grow up and up and up. Well, Moore’s Law has started to apply to the security market, and if you notice on the desktop, the major vendors all now have what are called endpoint protection platforms where you get anti-spyware, antiviral, personal firewall. For that $40. You want to keep Symantec or McAfee on your desktop, they know next year they have to add more or they’ll get replaced. Similarly on the network, what Gartner calls next-generation firewalls, instead of having to buy a separate intrusion prevention box for these type of threats and a firewall box for these type of threats, next-generation firewalls that use combined engines to do the two. So what we see the best practices are is reducing your cost of dealing with the old threats, applying Moore’s Law on cost reduction to how you deal with the old threats, so you can free up budget to deal with the new threats.

John Pescatore
The second thing that’s really huge that we’ve seen successful companies do, and for example, we saw the Office of the CIO of the Department of Agriculture recently come out with a memo to this effect to all Department of Agriculture agencies. The other thing you can do is spend $0 and greatly improve your security. So for example, the best way to not spend a dime and to greatly increase your security posture is by not having so many vulnerabilities in the software that you are using, that you’re buying. So for example, think about Windows, how much it costs to patch Windows. If Windows had fewer patches, we’d spend a lot, lots of our money on having to block attempts to exploit those patches and so on, but even beyond that, when you’re developing an internal piece of software, web code, for example, is the biggest example today. Security groups saying, oh, I need to spend thousands of dollars on web application security scanners to detect vulnerabilities on our website before the bad guys do. Well, what about if the application development group, as part of its standard code development, software development lifecycle, checked for vulnerabilities as they were developing the code? And what about if your standard process certification accreditation or final QA for allowing software to go on the operational website, what if it checked for vulnerabilities first? The security budget would not need all these extra capabilities.

John Pescatore
That approach to security would be baked into how you develop software, and by the way, it would not cost you more to develop software because you’d have fewer trouble tickets coming back that cost you a lot more to fix operational software and change the documentation. So again, just like however many years it was, boy, what, 25 years ago when we had sort of a quality revolution that said it’s much better for General Motors to have fewer defects in cars than for General Motors to have more mechanics at the dealership to fix cars that have problems. We’re finally getting to that point in software where you can take that approach to try to push removal of software deep vulnerabilities further up the food chain, another way to say we can get to a high level of security. Web 2.0 new disruptive technology, uh, we got to increase security spending. Well, wait a minute, can we push things up the chain to make sure that Web 2.0 Ajax type stuff that comes down, or that we deploy fewer vulnerabilities in it and then we don’t need to increase security spending?

Sanjog Aul
So you’re saying that we can leave everything in a status quo mode and the new flavors of technologies, which also are also introducing complexity. So if we don’t dig into these, you can say, new technology environments, we will not know enough about how much more complex have they made it, and in turn, how much more, you can say, security flaws that may have got introduced. So if we don’t know all that, how are we going to ever be able to make the decision? With respect to what is the risk versus what’s the opportunity cost, when and based on which we will make the decisions.

John Pescatore
Again, I sort of look at it, how do we make, how does the business side make the decisions on what technologies to use for some new line of business, some new financing application or e-commerce application? There’s not a hard model, a calculator or spreadsheet that they do that. You look at the data you have, you look at the things you do know and make some quick decisions and move on, but we can drill down into how that applies to security in a little bit, I guess.

Sanjog Aul
Let’s take a quick break, listeners. We’ll be back and just discuss about the risk versus opportunity cost equation in this new environment where we’ve introduced software as a service, so Web 2.0, virtualization, mobility, and they’re all working together. So all of that must be creating some change in the way other, the previous organizational standard in terms of security and where, what IT looked like and with the increased complexity, with the increased number of moving parts, has that increased the threat? And if yes, how do we measure? Please stay tuned.

Sanjog Aul
Welcome back. Since we have introduced new paradigms and new computing paradigms and new disruptive technologies, and we keep doing that because we are in an innovation age, it seems like. The increased security risk or the perception of increased security risk is there, and then we have to see how much and how do we measure and what is the risk versus opportunity cost? And if we do not have a ready answer for this, how does a CISO, which is the Chief Information Security Officer, and his or her crew justifying their salary in an organization?

John Pescatore
I think that’s a great question because that’s sort of the heart of this issue of CIO has a new business project here that wants to do X, Y, and Z, and it has a CISO over there. If we do X, Y, Z, the world will end, the sky will fall, and how do you move beyond that point? So we’ve seen both some more sort of heavyweight methodologies that are in use by companies we consider, Gartner considers best practice, and then I’ll talk about some sort of lighter weight ways we’ve seen smaller companies or the ones that can’t quite do everything the best practices way. So what we found is a lot of organizations that have real forward-looking chief security officers have put together standard security architecture elements, standard security services, and anytime there’s a new business project that wants to use IT technology resources, they assign a business security analyst to that project who participates in the early definition of of the project and the requirements and says, here’s the standard security services. You want to have a website where people can buy things, then we need authentication, we need auditing, we need to turn SSL on. You want to accept credit card payments? Well, they require the credit card data to be stored. We need encryption services. So they’ve defined the security architecture and security services that answer the standard business needs.

John Pescatore
Now, Part of that project then is the security recommendations for the solution and some threat analysis, why these security services are needed. Now, obviously those security services come with some cost, and the recommendation is that these services are needed to maintain the due diligence level of security and protect against these threats, and then the business side gets to accept that, that’s part of the project, or we can’t fund it at that level, we wouldn’t be profitable, we want to accept the risk., and that’s really no different than when a business makes a decision to enter a new line of business or start operations in a new country where there’s new risks and they can’t— all the physical risks can’t be predicted. So having on the security side, both the risk assessment methodology and the security architecture and standard security services that are what is built into any application that needs to touch customer-sensitive data or surveying dock fleet data or HISTA data or intellectual property or whatever. That enables the solution to be part of the overall project and the costs of the solution to be part of the cost of achieving the revenue objectives of that, or the business objectives of that project. Now, there’s some lighter weight approaches. Gartner, we put out a number of research notes, sort of toolkits here recently, because a lot of these things in today’s way of doing business aren’t quite so formal. It’s not, hey, here’s the new $100 million line of business.

John Pescatore
We want to get into, and there’s a project, and a business security analyst, lots of times it’s, hey, we want to use Google Apps instead of paying Microsoft $450 a user per year. If we pay Google $50 per user per year, we’ll save $400 per user per year. Or we want to connect our network with this other guy, and it’ll cut down the time it takes us to recognize revenue, and that’s not quite a formal project. So, You look at things in a sort of a simple, relatively simple manner. You should look at what’s the benefit to the business, high, low, let’s quantify it in some dollar threshold level if the business can quantify the business benefit, and then what’s the security pressure or security exposure? So a simple example might be something that’s going to expose a credit card number. We could be fined $5,000 a day.

John Pescatore
By the payment card industry, if we expose card data, and the typical partner says the typical cost per account exposed is $250, and 100,000 accounts means we have a $25 million exposure, and so when you start looking at business benefit versus security exposure, you can sort of lay out 4 different strategies. So if it’s low security exposure and low business risk, a low business benefit, who cares? Nobody really cares about that one. It’s a high business benefit and it’s low security exposure, then we just say, go ahead. If it’s low business benefit and high security exposure, then we might want to block and say, we’re not going to allow this. We have to keep people, keep people away from going to malicious websites because there’s no business benefit to going to those websites and there’s high security exposure. It’s the case where there’s high security exposure and high business benefit. Where we have to come up with embrace strategies, which are how do we do that securely? And that’s the mapping of how do we do Skype securely? How do we allow people to do work from home security? How do we allow two networks to be connected security? That’s where the bulk of the security work ends up.

Sanjog Aul
So given that in today’s day and age, we are recognizing that the innovation does happen at the end user level, and that’s why they should be allowed to use their own gadgets to an extent. I mean, gonna put some security perimeter around it. The same time, we also should somehow be able to inculcate that sense of responsibility in these end users that, guys, while we are giving you the option to play with your own toys and to get the thing done, whatever, but then we also want you to be aware that you are putting us at risk. So is that education being imparted in the fashion and is that working?

John Pescatore
Well, the typical guideline I’ve always used is if you had a dollar to spend on in your budget, for every $1 you have to spend on security awareness and education training, you should spend 99 cents on it on educating IT and the developers of IT and only 1% on the end user using IT. Great example I always use is these days we’re all used to it, but 20 years ago there was a major change in automobile design. I’ll never forget renting a car out of the Boston Logan Airport and I could not get it to go into drive, and the guy came out and said, what’s the problem? I said, it won’t go into drive. He said, well, you have to have your foot on the brake. All new cars, in order to shift from park to drive, you have to have your foot on the brake, and that’s because so many people who drove cars were not doing that. They were driving thinking they were going to go backwards, they were going forward and smashing into the 7-Eleven window or killing people in the phone booth or whatever.

John Pescatore
And we could have just had a bunch of commercials trying to convince people, hey, remember, you should shift, put your foot on the brake before you shift, but instead, the automobile industry built in, and this was not government regulation, this was the automobile industry built in this interlock that said you have to put your foot on the brake. Similarly, We have interlocks so you hopefully can’t electrocute yourself if you open up your TV. We don’t try to convince people, don’t, don’t do this. We put in ground fault interrupt circuit to prevent them from killing themselves if they do bring their blow dryer in the tub for some reason. So it’s, it’s people, a hopeful species. Do you ever notice how hopeful people look at casinos when they reach forward at the slot machine and pull that arm back? They’re very hopeful that good things are going to happen. It’s very much like users when they click on a link in email, they’re very hopeful something good is going to happen.

John Pescatore
When we look at the security incidents, most of them are not because users are stupid. Most of them are because users are creative and hopeful and not enough security interlocks are built into the things they use. If you notice today in most modern email systems, they make it harder to click on links and ask you, are you sure? You sure you want to do— do you want to enable links in this message? Are you sure? Hey, the browser bar now says you’re going to a phishing site. Are you sure you want to do that? So awareness and education is good to a level. You have to make people aware of the risk and aware of their responsibilities, but you cannot expect them to really change human behavior very quickly. Security has to be baked into the things they use, not attempt to make them use insecure things securely, and Arvie, You think about it, look how much more suspicious everybody is of email links these days. People have gotten aware of phishing.

John Pescatore
Now, of course, what the bad guys do then is say, you’re not going to click on my link and I can’t do it that way. I’ll go out and I’ll infect the major sites you go to anyway. So, for example, USA Today and MSNBC and the Miami Dolphins website all had their websites infected and people went to legitimate links and in fact The bad guys even did smart things like Google hacking to steer people towards the infected links on these legitimate sites, and then people went and got infected without even clicking on a link. So when we get there, the bad guys are pretty smart and the bad guys keep changing. So I sort of look at it like, you think by now this— I live in Washington, D.C. area now. We’re busy fighting Japanese beetles infesting our lawns.

John Pescatore
You’d think by now we’d have solved this problem, but Every time we come up with one solution, the pests come up with a way around that solution, and the game doesn’t change. The issue is, again, back to retail and ways of shoplifting or ways of counterfeiting changed. The game was never really over with. The issue is making sure the cost of keeping things secure enough doesn’t consume ever-increasing parts of the budget.

Sanjog Aul
With respect to the type of user that’s out there, especially in organizations, the corporate user, The Gen X, Gen Y, baby boomer people have had issues with the way they take an instruction and the way they carry out their work. Is security impacted with the Gen Y introduction?

John Pescatore
The current culture is the consumerization of IT. A lot of our clients call it the Gen X, Gen Y problem, and there’s a couple aspects to it. It’s one that this newer employees and even newer managers these days. They’ve grown up with computers in their house. They’ve grown up with being their own CIO, and they feel they know how to use technology. It’s not some mysterious thing that only the IT organization knows. A couple other things where they’re, they’re more used to using consumer-grade services to get their job done, and they want to use Facebook and other things, and the question is, how do we enable them to use them securely versus How do we just try to keep Gen Y people from doing things the way Gen X people did them?

Sanjog Aul
Let’s take a quick break. Let’s do it. We’ll be back and let’s discuss about this a little more, because we definitely would like to tell them what to do, but if they don’t agree, what then? Please stay tuned.

Sanjog Aul
Welcome back. So we are referring to Gen Y, this younger workforce which wants to test the limits to what is assigned to them and how do they execute on that, and are the security policies that we are putting out there, are they being embraced? Are they being followed? And is that resulting in that end-user computing, which we want them to adopt as well? And do things at their own leisure time, even at home working 24 hours. So, so how is that all coming together? Are we there?

John Pescatore
Well, there’s a number of different approaches. I mean, the basics of the problem is we have a very creative workforce that grew up using technology. Often at home, they have more powerful technology than we give them at work, and out on the internet, they see resources like Facebook or YouTube or lots of things that they could use to get their job done better than the alternatives, customer relationship management, Salesforce automation things we built a couple years ago for them. So the issue is, again, how do we deal with this problem? We can do our best to block things, keep them from using those types of things. That’s certainly been the way most companies have tried it, but increasingly we’re finding our own feet. I most productive salesperson or most productive engineer or best business managers are often the ones who want to break these rules. Just the way, by the way, 15 years ago, the ones that snuck PCs into work and used spreadsheets before we supported them and used wireless and used the internet before IT supported them, we had the same thing 15 years ago.

John Pescatore
It just didn’t work. So, there’s a couple different strategies, and again, it depends on the business tolerance and the really the business mode of operation. To some people, the purchase problem, wherever you are, I’ll give you an image, your corporate image, your standard desktop from the company and your applications on this VMware image. You could run it wherever you want. You’ll be happy. Well, no, on my home machine, I have Vista and Office 2007, and I like that a lot better than XP and Office 2003 that you guys support, and I still can’t use my photo booth tool on the Mac because you guys only support Windows and Photoshop or whatever. So that approach, when you think about it, is really just the dumb terminal approach.

John Pescatore
You’re saying, we still know about what applications you should use, we’ll just let you run them on any PC you want. Well, that only is a baby step in this direction of dealing with Gen X, Gen Y, and the real issue is how do we allow these things to be used and still keep them secure enough, these applications, these services. There’s some long-term answers. Someday we’ll have things like digital management where I can encapsulate my sensitive business data and business applications with a security policy and they could run anywhere and the data could not be transferred or left out on a machine that gets sold on eBay or posted on YouTube or something. We’re not there yet. We won’t be there for a long time. So the intermediate steps we’ve always seen people take is to use technologies like Data Leak prevention to know when sensitive business data is flowing out to unmanaged PCs, to use technologies like network access control to know when employee-owned PCs are connecting to our business systems and give limited access based on is that PC safe or not, safe enough or not.

John Pescatore
By the way, colleges have been dealing with this problem for 5 years now as kids bring totally unmanaged computers to the dorm rooms and connect to the network. That type of technology is spilled from university environments into corporate environments here. A little bit, not quite what you can do today and not quite what you’ll be able to do 10 years from now, but over the next couple of years, Gartner thinks we’re going to see the rise of what we’re calling security as a service, which is the idea that says, I’ve got my Janet, my most productive sales guy, this 30-year-old kid out there. He wants to use his own PC. We give him salesforce.com. It’s out on the web. He wants to use Google Apps and Facebook. He’s never even coming into work.

John Pescatore
How do we apply security policy? Well, if we said, as long as everything you do flows through security.com in the sky, and we can do some filtering, we can make sure sensitive data is not flowing outwards, we can check to see that whatever PC you’re using doesn’t have nasty stuff installed. That’s sort of the future. We’ve seen the start of that, companies like WebSense with web services offerings and in then cloud type offerings. AT&T, for example, doing this with denial of service filtering in the cloud to prevent attacks against that company. So I think we’re going to see a rise over the next couple years, a lot more security as a service offerings to deal with the whole consumerization problem and the fact that increasingly in the future, work is not getting done on the headquarters network. It’s getting done by people working out there wherever they happen to be on whatever device they happen to be using.

Sanjog Aul
Would you think that working in a secure environment in an organization is also a cultural thing? And if at all that is the case, when you do M&A, different organizations may have a different perception and a different understanding of security and the way they may have implemented. How do you bring the two together and what do you do during the transition period?

John Pescatore
Yes, that’s very much the case. M&A is a great example. Mergers and acquisition is a great example. Even within one large company, global operations, different operations in different countries have very different cultures and sensitivities and, and ways of getting things done. So if you use the most abrupt example of where there is a merger and acquisition and you’re trying, trying to combine two systems, the danger is ending up at the lowest common denominator. That one, the new company acquired had a very loose security policy, it wasn’t really very visible or targeted or have much exposure. Now it’s connected to the other company’s higher security network and the, the whole level is dragged down to the lowest common denominator. So typically here is gap analysis is done between the postures of the two companies and on each of these common areas around authentication, access control, confidentiality, integrity, availability, decisions are made about what the acceptable level is.

John Pescatore
Does it have to be the highest level and it dropped to the level of the lower company? Does it need to be somewhere in between? But the, again, the important side of things is the actual implementation of security processes, security controls, and security architectures, not just security policy. So if you bought a very creative, innovative technology company that was operating out of the Wild Wild West, and had horrible security, trying to just issue them policy to act like bankers in the way they handle security is A, not gonna work, and two, doesn’t match their creativity. So it has to be looking at the processes and architectures and security controls implemented, not simply making the policy match.

Sanjog Aul
So one last very quick question. Would you think that the vendors, customers, and the academia are working very much closely together now to make, to kind of secure the fort?

John Pescatore
Well, we certainly see efforts in all those areas. I think what we’ve seen lacking the most has been the larger infrastructure vendors, say the Citgoes and Microsofts and IBMs and Suns and Oracles. We have not seen them take this as seriously as they should be in making sure that the software I have on my desktop and the network equipment I have and the applications I run on my operating systems, that they make it easy for security to interoperate across all these levels versus have network security here and application security there. I think that’s probably the biggest area where we’d like to see more cooperation. There was a thing called the ISAC, Information Technology Security, or Information Analysis Capability, that the IT community was all members of, didn’t work very well. Here more recently, they formed a new consortium to say how to address this problem. I hope we see real progress from that.

Sanjog Aul
Thanks again for sharing your thoughts about how we can make security from being just a moving target, which where we keep playing catch up, to something where we can be a little more proactive. Very good. Thanks for having me. Thank you so much again, and now we know that we are in exciting times with organizations going through the rapid change and are also adopting new revolutionary technologies, and trying to make things happen when the change is constant, security seems to be an inevitably undermined entity, or you can say an area. So we definitely need to put some more attention in it, and then IT security leadership needs to be proactive and they need to work with their business leaders and CIOs to understand changes that are to be brought about when, wherever IT is involved and where potentially the security gaps may emerge.

Sanjog Aul
So how would security and security leadership view today in your organization? And if you’re a security leader, what would you like your CIO business leaders to do in order for you to do a better job? Please let us know your thoughts. Views@ciotalkradio.com. That is views@ciotalkradio.com. Thank you again for listening to CIO Talk Radio. This is Sanjog Aul, your talk show host. Till next week, take care and bye.

Contributors

John Pescatore

John Pescatore, Vice president and Research Fellow, Gartner Research

John Pescatore is a Vice President and Research Fellow in Gartner Research, with 24 years experience in computer network and information security. He is frequestly quoted in such publications as BusinessWeek Online, InformationWeek, and oth... More   View all posts
Add Comment
Click here to post a comment

Advertisement

Cigniti-Kobiton-Webinar-364776190-mobile-centric3-MPU
John Pescatore