+ All Categories
Home > Documents > Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Date post: 29-Apr-2018
Category:
Upload: lekhanh
View: 224 times
Download: 8 times
Share this document with a friend
59
Why We Don't Know. What We Can Do About It.
Transcript
Page 1: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Why We Don't Know.

What We Can Do About It.

Page 2: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Director of Security Intelligence for Akamai Technologies Former Research Director, Enterprise Security [The 451 Group] Former Principal Security Strategist [IBM ISS]

Industry: Co-Founder of “Rugged Software” www.ruggedsoftware.org Faculty: The Institute for Applied Network Security (IANS) 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: www.cognitivedissidents.com

Things I’ve been researching: DevOps Security Intelligence Chaotic Actors Espionage Security Metrics

Page 3: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 4: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Passionate Purposeful Principled Protector Provider

Page 5: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Honest Courageous

Consequential

Page 6: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Unreasonable A Fool

Page 7: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 8: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

No

Page 9: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Is it getting better?

Or do you feel the same?

Page 10: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Will it make it easier on you now?

You got someone to blame…

Page 11: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

How would you know?

By which criteria?

Page 12: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Evolving Threat

Evolving Compliance

Evolving Technology

Evolving Economics

Evolving Business

Cost Complexity

Risk

12

Page 13: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 14: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

WHAT

WHY

http://www.ted.com/talks/simon_sinek_how_great_leaders_inspire_action.html

HOW

WHAT

Page 16: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Performance

Fungible Assets

IntellectualProperty & TradeSecrets

Rights & Civility

Safety & Human Life

Page 17: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Dependence

Page 18: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 19: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 20: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 21: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

s/Software/Vulnerability/

Page 22: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

s/Connected/Exposed/

Page 23: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Our challenges are not technical… but cultural

Page 24: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Activity Effect

Page 25: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Symptoms Root Causes

Page 26: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Easy Important

Page 27: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 28: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Best Practices

aren’t

Page 29: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Good Enough

isn’t

Page 30: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Faith-based Security

Evidence-Based

Security

Available Data

Drunks & Lamp Posts

Numerology

Page 31: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Incentives

Page 32: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 33: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

GET A MAP

Page 34: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

0) “Vendors don’t need to be Ahead of the Threat…

…just Ahead of the Buyer”

1) AV Certification Omissions

2) There is no Perimeter… [nor Santa Claus]

3) Risk Management Threatens Vendors

4) Psst… There is more to Risk than Weak Software

5) Compliance Threatens Security…

6) Vendor Blind Spots Allowed for Storm++

7) Security has grown well past “Do it yourself”

Page 35: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

RUGGED SOFTWARE

Page 36: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 37: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Amazon EC2 - IaaS

Salesforce - SaaS

Google AppEngine - PaaS

with Chris Hoff and solo talks models by Chris Hoff

Page 38: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 39: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 40: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 41: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 43: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 44: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 45: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Control and Chaos ”World War 3.0” by Michael Joseph Gross

Vanity Fair - May 2012

Page 46: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Josh Corman & Jericho

BruCON 2012

Page 47: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 48: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Pick one: Make Excuses Make Progress

Page 49: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.
Page 50: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Countermeasures Situational Awareness Operational Excellence Defensible Infrastructure

Page 51: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Countermeasures Situational Awareness

Operational Excellence

Defensible Infrastructure

Page 52: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Countermeasures

Situational Awareness

Operational Excellence

Defensible Infrastructure

Page 53: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Countermeasures

Situational Awareness

Operational Excellence

Defensible Infrastructure

Page 54: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Knowledge Seeker Zombie Killer

Page 55: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Experimentation An untested hypothesis is a wish

Page 56: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Seeker

Page 57: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Unreasonable Fool

Page 58: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

THANK YOU My Collaborators My Teammates

Page 59: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It.

Joshua Corman [Knowledge Seeker | Zombie Killer]

Twitter: @joshcorman

BLOG: http://blog.cognitivedissidents.com


Recommended