SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

5 mantras for the security solution shopper

5 mantras for the security solution shopper

By:  Winn Schwartau  On: 20 Oct 2008 For: CSO (US)(NA) 

Many security vendors make a "fast u-turn" when customers ask for a guarantee or warranty on the performance of their products, says Winn Scwartau. Here's what you should look for the next time you shop for a security product

Security vendors have long been criticized for making grandiose claims about the efficacy of their wares. They have taken to presenting return on investment (ROI) arguments to justify the sales of their gear.

In his article , Bruce Schneier makes this point and further argues, quite effectively, that calculating a specific product or solution's potential ROI "is mostly bunk in practice."

I thoroughly agree. Further, I have seen vendors make a fast U-turn when a customer asks for a "guarantee" or "warranty" on the performance of the specific product in question. In my mind, any sort of ROI should be associated with a performance assurance. Or, one could equally ask the vendor, "OK, I see your ROI assumptions.

Now, since you won't give me a written warranty, how much should I discount the value of your ROI proposition?" The two cannot be separated.

Bruce also makes well-reasoned cases for the use of ALE , or Annualized Loss Expectancy, a risk view of security budgeting.

My only fear is that readers might, as I did at first, come to the conclusion that security is not measurable. Far from it -- there are many additional specific data points that can contribute to the evaluation of risk and security. Some of them are indeed even derivable directly from a wide range of security products and integrated solutions.

First, I don't believe security professionals should get dragged into the endless and futile debate over the value of information. That is not our job. The value of information should be determined at the highest levels of the organization. As Bruce says, in the event of a security incident, many of those values are intangible -- customer reactions, market perception, cost to re-brand along with the more traditional event mitigation and direct consequential costs.

But we can help. A few basic concepts should help understand that some aspects of security are measurable--and meaningful--if we find a common metric. Without getting into all of the math and formulas, that metric is time. From a risk and security standpoint, time is a common theme where we can bridge other information. A few mantras:

-- A security event should be detected rapidly.

-- A detected security event should trigger an alert as quickly as possible.

-- The cyber-first-responder should react to the alarm in as close to zero-time as required by policy and the detected and evaluated severity of the threat.

-- Threats should be thoroughly matrixed according to class, vector, severity, and time to infect, propagate and so on.

-- The greater the time it takes to detect and react to the event, the greater the risk.

Since we cannot measure, or be assured of the efficacy of primary security protection devices, we have to look at the problem backwards.


Sign up for our Newsletters












Print |  Views: 962   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Winn Schwartau Winn Schwartau is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Detection and cleanup, Symantec Norton Internet Security 2009's strengths
Detection and cleanup, Symantec Norton Internet Security 2009's strengthsSmoking-out and cleaning-up malware are strong suits of Symantec Norton's new Web security suite
Anti-virus no defence against botnets, says vendor
Anti-virus no defence against botnets, says vendorMany anti-virus programs are near to useless in blocking the binaries used to spread botnets, says FireEye's chief scientist
Staff running virtual desks behind IT admin's back
Staff running virtual desks behind IT admin's back Virtualization is a 'black hole' in IT security and firms are leaving themselves exposed to cyber attacks, says Sophos
IBM releases Workforce Analytics
the first software and services package to come out of ibm's cognos acquisition is its new workforce analytics offering.the human capital management service and software package is geared toward users looking for improved workforce trends and metrics, along with demographics,
Dan Swanson's Security Resources: #4
my fourth column provides another diverse collection of leading resources. this week’s question: “how prepared is your organization?” if you have any concerns on the robustness of your disaster recovery, business continuity, and/or your emergency management capabilities, i’d strongly recommend you check out the canadian centre for emergency preparedness. studying for your ciss
The Olympics as a showcase for IT security
public safety minister peter van loan announced yesterday that security costs for vancouver’s 2010 winter olympics could reach up to $1-billion. but how much of that money is allocated to the it security threats that might arise during the games? 
blog comments powered by Disqus