Posts

Showing posts with the label insurance

Will "Guaranteed Security" Save the Digital World?

Image
Thanks to a comment by Jeremiah Grossman on LinkedIn, I learned of his RSA talk  No More Snake Oil: Why InfoSec Needs Security Guarantees . I thought his slide deck looked interesting and I wish I had seen the talk. One of his arguments is that security products and services lack guarantees, "unlike every day 'real world' products," as shown on slide 3 at left. The difference between the products at left and those protected by security products and services, however, is that security products and services are trying to counter intelligent, adaptive adversaries. Jeremiah does include a slide showing multiple "online security guarantees" for financial services. Those assets do indeed face challenges from the sorts of adversaries I have in mind. I need to hear more about what Jeremiah said at this point, and also I need to learn more about this individual guarantees. It may be useful to look at what physical security companies offer by way of guarante...

Cyberinsurance in IT Security Management

Image
One more thought before I retire this evening. I really enjoyed reading Cyberinsurance in IT Security Management by Walter S. Baer and Andrew Parkinson. Here are my favorite excerpts. IT security has traditionally referred to technical protective measures such as firewalls, authentication systems, and antivirus software to counter such attacks, and mitigation measures such as backup hardware and software systems to reduce losses should a security breach occur. In a networked IT environment, however, the economic incentives to invest in protective security measures can be perverse. My investments in IT security might do me little good if other systems connected to me remain insecure because an adversary can use any unprotected system to launch an attack on others. In economic terms, the private benefits of investment are less than the social benefits, making networked IT security a public good — and susceptible to the free-rider problem. As a consequence, private individuals and org...

Security Staff as Ultimate Insurance

Image
I'm continuing to cite the Fifth Annual Global State of Information Security : Speaking of striking back, the 2007 security survey shows a remarkable (some might say troubling) trend. The IT department wants to control security again. In the first year of collaboration on this survey, CIO, CSO and PWC noted that the more confident a company was in its security, the less likely that company's security group reported to IT. Those companies also spent more on security. The reason CIO and CSO have always advocated for the separation of IT and security is the classic fox-in-the-henhouse problem. To wit, if the CIO controls both a major project dedicated to the innovative use of IT and the security of that project — which might slow down the project and add to its cost — he's got a serious conflict of interest. In the 2003 survey, one CISO said that conflict "is just too much to overcome. Having the CISO report to IT, it's a death blow." Ouch. CIO continues: What...