ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY...

34
ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013

Transcript of ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY...

Page 1: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

ISE Confidential - not for distribution

T H E E V O LV I N G T H R E A T L A N D S C A P E :

A D V A N C I N G E N T E R P R I S E S E C U R I T Y

11 December 2013

Page 2: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

Agenda

ISE Confidential - not for distribution

• Objectives• About ISE• I. Security Separated from Functionality• II. Black Box vs. White Box• III. Secure Assets, Not Perimeters• IV. “Build It In,” Not “Bolt It On”• V. Security as Ongoing Process• Q&A

Page 3: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

Objectives

ISE Confidential - not for distribution

• Analyze trending best practices• Keep pace with the rapidly evolving adversaries• Streamline resource and financial investment

Page 4: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

About ISE

ISE Confidential - not for distribution

Page 5: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

About ISE

ISE Confidential - not for distribution

Analysts

• Fortune 500 Enterprises• Media & Entertainment, Security Software, Healthcare, etc

Customers

• White box

Perspective

• Computer Scientists• Ethical Hackers

Research• Recent: Browsers; Routers• Upcoming: Digital Cinema; Hospital Pilot

Page 6: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

I. Security Separated From Functionality

ISE Confidential - not for distribution

Page 7: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

I. Security Separated From Functionality

ISE Confidential - not for distribution

CONFLICT IS GOOD!There, I said it.

Page 8: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

I. Security Separated From Functionality

ISE Confidential - not for distribution

Page 9: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

I. Security Separated From Functionality

ISE Confidential - not for distribution

I.T.

Page 10: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

I. Security Separated From Functionality

ISE Confidential - not for distribution

Page 11: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

I. Security Separated From Functionality

ISE Confidential - not for distribution

Page 12: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

I. Security Separated From Functionality

ISE Confidential - not for distribution

Page 13: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

I. Security Separated From Functionality

ISE Confidential - not for distribution

Objective of Conflict• Facilitate dialogue amongst teams to arrive at a

usable system, on deadline, that entails an acceptable level of security protocols.

Page 14: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

II. Black Box vs. White Box

ISE Confidential - not for distribution

Page 15: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

II. Black Box vs. White Box

ISE Confidential - not for distribution

• Evaluation Types• Penetration Test• Vulnerability Assessment

• Methodologies• Black Box• White Box

Page 16: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

II. Black Box vs. White Box

ISE Confidential - not for distribution

Black Box Perspective

Page 17: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

II. Black Box vs. White Box

ISE Confidential - not for distribution

White Box Perspective

Page 18: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

II. Black Box vs. White Box

ISE Confidential - not for distribution

Page 19: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

III. Secure Assets, Not Perimeters

ISE Confidential - not for distribution

Page 20: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

III. Secure Assets, Not Perimeters

Traditional Attacks Traditional Defenses

20

Page 21: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

III. Secure Assets, Not Perimeters

21

Modern Attacks

Page 22: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

III. Secure Assets, Not Perimeters

22

Page 23: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

IV. “Build It In,” Not “Bolt It On”

ISE Confidential - not for distribution

Page 24: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

IV. “Build It In,” Not “Bolt It On”

ISE Confidential - not for distribution

Page 25: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

IV. “Build It In,” Not “Bolt It On”

ISE Confidential - not for distribution

Page 26: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

IV. “Build It In,” Not “Bolt It On”

ISE Confidential - not for distribution

Page 27: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

IV. “Build It In,” Not “Bolt It On”

ISE Confidential - not for distribution

Page 28: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

V. Security as Ongoing Process

ISE Confidential - not for distribution

Page 29: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

V. Security as Ongoing Process

ISE Confidential - not for distribution

Page 30: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

V. Security as Ongoing Process

ISE Confidential - not for distribution

Page 31: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

V. Security as Ongoing Process

ISE Confidential - not for distribution

Page 32: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

V. Security as Ongoing Process

ISE Confidential - not for distribution

Page 33: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

Recap

ISE Confidential - not for distribution

I. Security Separated from FunctionalityII. Black Box vs. White BoxIII. Secure Assets, Not PerimetersIV. “Build It In”, Not “Bolt It On”V. Security as Ongoing Process

Whitepaper forthcoming

Page 34: ISE Confidential - not for distribution THE EVOLVING THREAT LANDSCAPE: ADVANCING ENTERPRISE SECURITY 11 December 2013.

Questions?

ISE Confidential - not for distribution

Ted HarringtonExecutive Partner

[email protected]