<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Situational Room by eIQnetworks</title>
	<atom:link href="http://situationalroom.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://situationalroom.wordpress.com</link>
	<description></description>
	<lastBuildDate>Thu, 26 Jan 2012 14:02:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='situationalroom.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>The Situational Room by eIQnetworks</title>
		<link>http://situationalroom.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://situationalroom.wordpress.com/osd.xml" title="The Situational Room by eIQnetworks" />
	<atom:link rel='hub' href='http://situationalroom.wordpress.com/?pushpress=hub'/>
		<item>
		<title>The first casualties of cyber war.</title>
		<link>http://situationalroom.wordpress.com/2012/01/26/the-first-casualties-of-cyber-war/</link>
		<comments>http://situationalroom.wordpress.com/2012/01/26/the-first-casualties-of-cyber-war/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 14:02:08 +0000</pubDate>
		<dc:creator>The Secure View</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[AOL Government]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Cyberwar]]></category>
		<category><![CDATA[Networked Society]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=1192</guid>
		<description><![CDATA[In his latest post for AOL Government eIQnetworks&#8217;s John Linkous explores how, in our increasingly networked society, it is only a matter of time before we see the first casualties from advanced persistent cyber attacks.  He also asks what can be done to mitigate the risk of virtual attacks affecting the physical world. You can [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1192&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In his latest post for <a title="AOL Government" href="http://gov.aol.com/" target="_blank">AOL Government</a> eIQnetworks&#8217;s John Linkous explores how, in our increasingly networked society, it is only a matter of time before we see the first casualties from advanced persistent cyber attacks.  He also asks what can be done to mitigate the risk of virtual attacks affecting the physical world.</p>
<p>You can read John&#8217;s post in full at <a title="When the Virtual Becomes Physical" href="http://ow.ly/8H5uB" target="_blank">http://ow.ly/8H5uB</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1192/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1192&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2012/01/26/the-first-casualties-of-cyber-war/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/17aea691e1223f0a73257f630c551ca0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">broadpr</media:title>
		</media:content>
	</item>
		<item>
		<title>Everything you ever wanted to know about Situational Awareness&#8230; [but were afraid to ask!]</title>
		<link>http://situationalroom.wordpress.com/2012/01/24/everything-you-ever-wanted-to-know-about-situational-awareness-but-were-afraid-to-ask/</link>
		<comments>http://situationalroom.wordpress.com/2012/01/24/everything-you-ever-wanted-to-know-about-situational-awareness-but-were-afraid-to-ask/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 22:20:47 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Comment]]></category>
		<category><![CDATA[Company News]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Gartner]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[John Pescatore]]></category>
		<category><![CDATA[SIEM is Dead]]></category>
		<category><![CDATA[SIEM Plus]]></category>
		<category><![CDATA[situational awareness]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=1185</guid>
		<description><![CDATA[Most security professionals will, by now, be aware of the term Situational Awareness &#8211; but how many understand what it actually is?  How many understand how to deliver it within their organization?  Situational Awareness has become one of the big buzzwords of the security industry in the last 12 months and, as the company that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1185&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Most security professionals will, by now, be aware of the term Situational Awareness &#8211; but how many understand what it actually is?  How many understand how to deliver it within their organization?  Situational Awareness has become one of the big buzzwords of the security industry in the last 12 months and, as the company that coined the term within our industry AND the first to offer a working platform, we thought it was time to clarify much of the confusion that exists around the term.</p>
<p>“Proactive Threat Discovery and Risk Mitigation Demands Situational Awareness,” is an eIQnetworks webinar, featuring Gartner analyst John Pescatore, which aims to answer many of the questions we&#8217;ve been asked by security professionals in recent months.  The webinar also explains how situational awareness delivers key competencies that cannot be achieved using existing SIEM and SIEM Plus tools and how it provides security analysts with the ability to effectively protect large distributed networks effectively and efficiently in a way they cannot do with traditional point tools.</p>
<p>You can view the video <a href="http://www.eiqnetworks.com/resources/gartnerandeiqnetworks_webinar.php">here</a></p>
<p>If you have a question that is not included in our webinar then please let us know and we&#8217;ll be happy to answer it for you.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1185/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1185&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2012/01/24/everything-you-ever-wanted-to-know-about-situational-awareness-but-were-afraid-to-ask/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
		<item>
		<title>Cybersecurity: what&#8217;s the point?</title>
		<link>http://situationalroom.wordpress.com/2012/01/17/cybersecurity-whats-the-point/</link>
		<comments>http://situationalroom.wordpress.com/2012/01/17/cybersecurity-whats-the-point/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 17:13:29 +0000</pubDate>
		<dc:creator>The Secure View</dc:creator>
				<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[camus]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[existentialism]]></category>
		<category><![CDATA[futility]]></category>
		<category><![CDATA[sartre]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=1179</guid>
		<description><![CDATA[Last week the FBI claimed that cybersecurity posed an &#8220;existential&#8221; threat to American corporations, &#8220;meaning it could eliminate whole companies&#8221;. Despite this, it said, many consumers and commercial organizations are &#8220;still not taking the threat serious, claiming, &#8220;either they don&#8217;t recognize it, they don&#8217;t understand it or they don&#8217;t care&#8221;.  I wonder what Sartre or [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1179&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Last week the FBI claimed that cybersecurity <a href="http://www.huffingtonpost.com/2012/01/12/cyber-threats_n_1202026.html">posed an &#8220;existential&#8221; threat to American corporations</a>, &#8220;meaning it could eliminate whole companies&#8221;. Despite this, it said, many consumers and commercial organizations are &#8220;still not taking the threat serious, claiming, &#8220;either they don&#8217;t recognize it, they don&#8217;t understand it or they don&#8217;t care&#8221;.  I wonder what Sartre or Camus would have to say on the matter?</p>
<p>I&#8217;m have no doubt they would have <span id="more-1179"></span>thought long and hard on the philosophical questions facing CISOs in many commercial organizations and Government departments. Questions like: Do advanced persistent threats really exist? How can we minimize our risk of attack? And, &#8216;If we are attacked, how do we detect and deal with it?&#8217;.  Hopefully you won&#8217;t conclude that that the struggle is futile or absurd!</p>
<p>The battle against cyberattacks can often feel a little like Sisyphus, pushing a rock up a mountain only to have it roll to the bottom again. We can only hope that the majority of security professionals, regardless of how absurd or futile the struggle can appear, take steps to protect themselves and their organizations from the threats that undoubtedly threaten their existence.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1179/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1179&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2012/01/17/cybersecurity-whats-the-point/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/17aea691e1223f0a73257f630c551ca0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">broadpr</media:title>
		</media:content>
	</item>
		<item>
		<title>Less Turtle, More Awareness</title>
		<link>http://situationalroom.wordpress.com/2012/01/11/less-turtle-more-awareness/</link>
		<comments>http://situationalroom.wordpress.com/2012/01/11/less-turtle-more-awareness/#comments</comments>
		<pubDate>Wed, 11 Jan 2012 20:27:21 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[Unified Situational Awareness]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[Security Week]]></category>
		<category><![CDATA[situational awareness]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=1170</guid>
		<description><![CDATA[Catching up on some reading this week, I came across this piece  in Security Week, written by Chris Poulin, Chief Security Officer at Q1 Labs, talking about how a childhood experience can help the modern information security professional.  Chris makes some good points, such as the need for continuous monitoring, and using all available tools [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1170&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Catching up on some reading this week, I came across this <a title="Why you should put a GPS tracker on your turtle" href="http://www.securityweek.com/why-you-should-put-gps-tracker-your-turtle" target="_blank"><span style="text-decoration:underline;">piece</span></a>  in Security Week, written by Chris Poulin, Chief Security Officer at Q1 Labs, talking about how a childhood experience can help the modern information security professional.  Chris makes some good points, such as the need for continuous monitoring, and using all available tools to capture multiple data points in order to enable you to pinpoint the vector of advanced persistent threats (and slow moving box turtles).</p>
<p>This is certainly all good advice &#8211; although we contend that the average cyber or insider attack moves slightly quicker than the average box turtle.  There are, however, some major problems with Chris&#8217; piece.<span id="more-1170"></span></p>
<ul>
<li>First, the assumption is made that SIEM tools – of which Q1 Labs makes a very good one – can capture all of the information required to find our good friend, the turtle.  Unfortunately, that simply isn’t the case.  SIEM tools are highly focused on events.  Even in cases where a SIEM can look outside of the world of events at one or two other pieces of data (say, at network traffic, which is something that Q1 Labs’ SIEM does), that’s still woefully inadequate: if we’re going to find an errant turtle, we certainly need events and network traffic data, but we also need system asset and configuration state (from <strong><em>both</em></strong> hosts <strong><em>and</em></strong> devices, not just one or the other), system performance metrics, visibility into file integrity, and much, much more.  A SIEM is great if our Turtle friend has left behind a trail of breadcrumbs (or whatever it is that turtles leave behind them when they travel), but otherwise, the SIEM is going to likely lead us to a cold trail due to lack of data.</li>
<li>Second, even if your SIEM can collect different types of data in search of our elusive turtle friend, it probably uses multiple, separate products to do so.  Q1 Labs has a great SIEM product – Qradar – but requires separate appliances to collect flow data and Q1’s proprietary pseudo-DPI information, as well as another, completely separate appliance to collect system asset data and configuration state (and even then, this data is limited to a small subset of network devices, and completely excludes hosts… which means we’re stuck in the world of limited data again).  Of course, Q1 Labs is not the only SIEM vendor who runs into this issue: Tripwire, Nitro Security, NetIQ, Arcsight, and others all rely on multiple tools to try and collect more than just event-based data.  Unfortunately, all this approach does is result in taking a bunch of smaller silos (from individual systems and point security tools), and turn them into a smaller number of bigger silos – certainly not useful as the clock ticks on finding our buddy, the turtle!</li>
<li>Finally, even if you can collect a multitude of data points from various point security tools, and your security analysts have fed them into a traditional SIEM, you still have a problem: the SIEM views everything as an event: a piece of system state data becomes an “event” (which it isn’t), performance metrics become “events” (which they aren’t), and so on.  Much of the richness of the data is lost, and the only thing that most organizations are left with is a general idea that “’something’ has certainly happened…”, but they lose the critical context of exactly what that ‘something’ is.  A manual hunt for the turtle then begins in earnest.</li>
</ul>
<p>So yes, what Chris describes is absolutely valid &#8212; we call it <a href="http://www.eiqnetworks.com/securevue/securevue.php"><span style="text-decoration:underline;">Unified Situational Awareness</span></a> – but the fact is, traditional SIEM and “SIEM-plus” tools simply can&#8217;t deliver it.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1170/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1170&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2012/01/11/less-turtle-more-awareness/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
		<item>
		<title>Situational Awareness: It&#8217;s not a Technology; it&#8217;s a Way of Life</title>
		<link>http://situationalroom.wordpress.com/2012/01/09/situational-awareness-its-not-a-technology-its-a-way-of-life/</link>
		<comments>http://situationalroom.wordpress.com/2012/01/09/situational-awareness-its-not-a-technology-its-a-way-of-life/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 15:38:40 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Homeland Security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[CSO Magazine]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Freedom Tower]]></category>
		<category><![CDATA[situational awareness]]></category>
		<category><![CDATA[WTC]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/2012/01/09/situational-awareness-its-not-a-technology-its-a-way-of-life/</guid>
		<description><![CDATA[Recently, CSO Magazine published a story on the efforts to secure the new Freedom Tower and other buildings that are being built at the site of the new World Trade Center in New York.  Throughout the article, Louis Barani &#8211; the former U.S. Naval Officer who is developing the security technologies for the new facility [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1166&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Recently, CSO Magazine published a <a title="CSO Magazine - WTC Situational Awareness" href="http://www.csoonline.com/article/689109/situational-awareness-inside-the-new-world-trade-center" target="_blank">story</a> on the efforts to secure the new Freedom Tower and other buildings that are being built at the site of the new World Trade Center in New York.  Throughout the article, Louis Barani &#8211; the former U.S. Naval Officer who is developing the security technologies for the new facility &#8211; frequently uses the term &#8220;situational awareness&#8221; to describe his team&#8217;s efforts to ensure the security of the Freedom Tower and other buildings.</p>
<p>What&#8217;s most interesting is how Mr. Barani talks about situational awareness not as a <em>product</em>, but as a <em>capability</em>.  While much of his interest is in physical security &#8212; as opposed to information security, which is where eIQnetworks and SecureVue reside &#8212; he identifies all the different types of security-related information that are required to achieve situational awareness: physical access control and logs; CCTV feeds and data; HVAC systems; elevator controls; and many, many more.  His team will be using a platform designed to bring together the physical security data from all these different sources into a single platform that facilitates situational awareness.</p>
<p>So what&#8217;s the point?  First, that situational awareness isn&#8217;t just a tool or a technology &#8212; it&#8217;s a way of life that requires continuous, real-time evaluation of the environment (whether the goal is system operations, physical security, information security, or otherwise), correlation of different types of events and other data together, and the ability to act on abnormalities right away.  Second, to make all of these things happen, you need the right tools to <em>facilitate</em> &#8212; not <em>automate</em> &#8211; situational awareness. In the information security world, that means collecting all security-related data, whether that data is encapsulated in events, asset state, network traffic, system performance, or any other piece of information.  Once you have the data, the other critical capability is correlation: are unusual network traffic, an abnormal performance metric, and an unauthorized change on a server related?  If so, how?</p>
<p>Just like in physical security systems, in the world of information security there are plenty of assets generating security data: events from host OS&#8217;s, devices, applications and databases; point security tools like IDS/IPS and anti-malware; performance data; network traffic; the current operating state of systems; and so much more.</p>
<p>Like the architects of physical security at Freedom Tower, delivering situational awareness for information security requires the ability to bring all of this data together into a single location, and correlate this data to find abnormalities &#8212; the hallmark of situational awareness.  Unfortunately, there aren&#8217;t many solutions available today that really do this for information security: SIEMs have limited data collection capabilities, and treat everything like an event (which is decidedly <em><span style="text-decoration:underline;">not</span></em> situational awareness); configuration management tools have no visibility into events or what&#8217;s happening at the network layer; and NBA and network monitoring tools lack visibility into system state.  So, like a CCTV system, or an HVAC controller, or an elevator system, each of these information security tools provides visibility into a limited &#8212; but critical &#8211; wedge of data.  You still need something to bring all the data together, and facilitate true situational awareness.  Fortunately, we know <a title="SecureVue - The Unified Situational Awareness Platform" href="http://www.eiqnetworks.com/securevue/securevue.php" target="_blank">exactly where you can find</a> a product that does this.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1166/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1166&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2012/01/09/situational-awareness-its-not-a-technology-its-a-way-of-life/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
		<item>
		<title>Forget End-of-Year Predictions&#8230; We Have End-of-the-World Predictions!</title>
		<link>http://situationalroom.wordpress.com/2011/12/31/forget-end-of-year-predictions-we-have-end-of-the-world-predictions/</link>
		<comments>http://situationalroom.wordpress.com/2011/12/31/forget-end-of-year-predictions-we-have-end-of-the-world-predictions/#comments</comments>
		<pubDate>Sat, 31 Dec 2011 15:33:06 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[end of the world]]></category>
		<category><![CDATA[info security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mayan]]></category>
		<category><![CDATA[Predictions]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=1009</guid>
		<description><![CDATA[As we officially kickoff “prediction week” – where virtually every security vendor, journalist and pundit gazes into their crystal ball and prognosticates about the next twelve months – we at eIQ have decided to up the proverbial ante.  Our predictions aren’t just about the next year… they’re about the end of the world. How’s that, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1009&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As we officially kickoff “prediction week” – where virtually every security vendor, journalist and pundit gazes into their crystal ball and prognosticates about the next twelve months – we at eIQ have decided to up the proverbial ante.  Our predictions aren’t just about the next year… they’re about the end of the world.</p>
<p>How’s that, you might ask?  Well, it all starts – or rather, ends – with our favorite pre-Columbian civilization, the Mayans.  Ah, the Maya… ask anyone on the street today about them, and the first thing you’re likely to hear about is the <a title="Wikipedia - Mayan Calendar" href="http://en.wikipedia.org/wiki/Mayan_calendar" target="_blank">Mayan calendar</a>.  Like other Mesoamerican civilizations such as the Aztecs and Inca, the Maya very much believed that time operated in cycles.  The Maya “long count” calendar – the longest individual cycle – is currently scheduled to complete on December 21, 2012.</p>
<p>The Mayans themselves would simply start a new cycle (called b’ak’tun) on December 22; but in our clever world, that’s not good enough for many.  Unfortunately, the end of the “long count” cycle this year has been misinterpreted by some as “the end of the world” – often by people who are looking to make a quick buck.  Rest assured that just as Y2K, the IRS tax deadline of April 15th, and other critical dates have been the focus of phishing and other scam activity in the past, so too will December 21, 2012.</p>
<p>It’s only a matter of time before we start seeing it: <strong>“Click here to download the PDF <em>[which is infected]</em> / program <em>[which is trojaned]</em> / website link <em>[which is XSS’d to malware]</em> that shows you why the Mayans were right about the end of the world!”</strong>  Like any other scam, these emails and web ads will play to people’s worst fears, and doubtless some of them will succeed in facilitating identity theft, illegal transfer of funds, or even worse.  People are fascinated by doom, and the idea that someone might have “secret knowledge” will cause many unsuspecting people to be drawn into these scams.  We saw this happen endlessly during Y2K, over ten years ago when the term phishing hadn’t even been coined yet.  With the advent of new methods to reach people – no longer just e-mail, but text messages, social media sites, embedded links in documents, and so many more – the amount of fraud that will be perpetrated from end-of-the-world scare tactics will be extreme.</p>
<p>So remember, you heard it here first… and if we’re all still around on December 22, 2012, we’ll see if we at eIQ were right.   <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1009/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1009&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2011/12/31/forget-end-of-year-predictions-we-have-end-of-the-world-predictions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
		<item>
		<title>If Containment is the New Prevention&#8230;</title>
		<link>http://situationalroom.wordpress.com/2011/12/14/if-containment-is-the-new-prevention/</link>
		<comments>http://situationalroom.wordpress.com/2011/12/14/if-containment-is-the-new-prevention/#comments</comments>
		<pubDate>Wed, 14 Dec 2011 17:16:42 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[SIEM is Dead]]></category>
		<category><![CDATA[Cybersecurity predictions 2012]]></category>
		<category><![CDATA[info security]]></category>
		<category><![CDATA[Ponemon Institute]]></category>
		<category><![CDATA[SecureVue]]></category>
		<category><![CDATA[situational awareness]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=999</guid>
		<description><![CDATA[A couple of weeks ago, Websense published its cybersecurity predictions for 2012.  One in particular prediction caught our eye: that containment will become the new prevention.  We&#8217;re assuming that Websense&#8217; prediction is that the focus for many organizations will shift from preventing external and insider attacks, data breaches, and other incidents, to containment (rather than [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=999&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A couple of weeks ago, Websense published its <a title="Websense Cyber Security Predictions - 2012" href="http://community.websense.com/blogs/websense-news-releases/archive/2011/11/17/2012-cyber-security-predictions-from-the-websense-security-labs.aspx">cybersecurity predictions for 2012</a>.  One in particular prediction caught our eye: that <strong>containment will become the new prevention</strong>.  We&#8217;re assuming that Websense&#8217; prediction is that the focus for many organizations will shift from preventing external and insider attacks, data breaches, and other incidents, to containment (rather than being something that many aspire to, but very few have yet to attain, by the way&#8230;)</p>
<p>We&#8217;ve been saying the same thing for a number of years.  2011 has demonstrated that, <span id="more-999"></span>even when an organization knows that an attack is imminent, many remain unable to do anything to prevent it.  On this basis, it&#8217;s inconceivable that using the point SIEM tools that exist in many large organizations most will be able to contain it.  This is supported by <a title="Second Annual Cost of Cybercrime report" href="http://www.infosecurity-magazine.com/view/19838/ponemon-institute-report-highlights-soaring-cost-of-cybercrime/" target="_blank">Ponemon Institute research</a> that suggests that <strong>the current average response time to a security incident is 18 days</strong>.</p>
<p>If Websense&#8217; prediction is going to become reality then there needs to be a fundamental shift towards tools that can correlate large amounts of security data, in all of its native formats to provide analysts with a real-time, contextual view of their security posture.  And, in order for this to happen, <strong><a title="SIEM is Dead" href="http://www.eiqnetworks.com/resources/SIEM_is_DEAD.php" target="_blank">SIEM must be dead</a></strong>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/999/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=999&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2011/12/14/if-containment-is-the-new-prevention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;&#8230;there will be a catastrophic attack on the United States within the next 12 months&#8221;. Are you ready?!</title>
		<link>http://situationalroom.wordpress.com/2011/12/06/there-will-be-a-catastrophic-attack-on-the-united-states-within-the-next-12-months-are-you-ready/</link>
		<comments>http://situationalroom.wordpress.com/2011/12/06/there-will-be-a-catastrophic-attack-on-the-united-states-within-the-next-12-months-are-you-ready/#comments</comments>
		<pubDate>Tue, 06 Dec 2011 13:09:56 +0000</pubDate>
		<dc:creator>The Secure View</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Comment]]></category>
		<category><![CDATA[critical infrastructure]]></category>
		<category><![CDATA[Cybersecurity; Legislation]]></category>
		<category><![CDATA[Homeland Security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cyberspace]]></category>
		<category><![CDATA[House Intelligence Committee]]></category>
		<category><![CDATA[NCTA]]></category>
		<category><![CDATA[Ruppersberger]]></category>
		<category><![CDATA[situationalawareness]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=974</guid>
		<description><![CDATA[Vendors, particularly those working in the security space, are often criticized for what many see as spreading fear, uncertainty and doubt [otherwise known as FUD] as a marketing tactic &#8211; using the prospect of a terrible event as a lever to persuade organizations they need a product or service.  But, when somebody like Rep &#8220;Dutch&#8221; Ruppersberger, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=974&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Vendors, particularly those working in the security space, are often criticized for what many see as spreading fear, uncertainty and doubt [otherwise known as FUD] as a marketing tactic &#8211; using the prospect of a terrible event as a lever to persuade organizations they need a product or service.  But, when somebody like Rep &#8220;Dutch&#8221; Ruppersberger, a member of the House Intelligence Committee says it, surely everybody should take notice?</p>
<p>We&#8217;ll let you judge for your selves&#8230; <span id="more-974"></span>here&#8217;s video from an event organized by the National Cable &amp; Telecommunications Association [NCTA] last week, entitled Protecting American Innovation in Cyberspace, at which Rep Ruppersberger states that he, and many of the countries most senior officials, believe there will be a catastrophic attack on a US target.</p>
<p>You can watch the video here; it gets interesting at about 30 minutes in&#8230;</p>
<p><a href="http://www.ncta.com/MediaCenter/MediaCenter/Protecting-American-Innovation-in-Cyberspace.aspx#videoStart">Protecting American Innovation in Cyberspace</a></p>
<p>*Copyright NCTA 2011</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/974/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/974/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/974/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/974/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/974/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/974/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/974/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/974/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/974/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/974/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/974/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/974/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/974/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/974/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=974&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2011/12/06/there-will-be-a-catastrophic-attack-on-the-united-states-within-the-next-12-months-are-you-ready/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/17aea691e1223f0a73257f630c551ca0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">broadpr</media:title>
		</media:content>
	</item>
		<item>
		<title>Get Situational Awareness Today… No Strings Attached!</title>
		<link>http://situationalroom.wordpress.com/2011/11/29/get-situational-awareness-today-no-strings-attached/</link>
		<comments>http://situationalroom.wordpress.com/2011/11/29/get-situational-awareness-today-no-strings-attached/#comments</comments>
		<pubDate>Tue, 29 Nov 2011 13:00:12 +0000</pubDate>
		<dc:creator>The Secure View</dc:creator>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[SIEM is Dead]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[free download]]></category>
		<category><![CDATA[SecureVue]]></category>
		<category><![CDATA[SecureVue Express]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=964</guid>
		<description><![CDATA[Today we are pleased to make available SecureVue Express, a no-cost version of our award-winning SecureVue, the industry’s first unified situational awareness platform.  SecureVue Express is available as a free download from our website.  SecureVue Express provides basic situational awareness capabilities through collection, correlation and analysis of a broad range of security data including events, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=964&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Today we are pleased to make available SecureVue Express, a no-cost version of our award-winning SecureVue, the industry’s first unified situational awareness platform.  SecureVue Express is available as a<span id="more-964"></span> <a href="http://www.eiqnetworks.com/securevueexpress">free download</a> from our website.  SecureVue Express provides basic situational awareness capabilities through collection, correlation and analysis of a broad range of security data including events, asset and configuration information, network flows and performance metrics.  SecureVue Express includes much of the key functionality that comprises SecureVue, and demonstrates why we&#8217;ve long claimed that the future of information security requires a more holistic approach than the traditional point products once adopted by many large organizations.</p>
<p>Currently in Beta, SecureVue Express offers a glimpse of the future for security analysts, and has a brand-new user interface that simplifies enterprise security management.</p>
<p>To download your copy of SecureVue Express, click <span style="text-decoration:underline;"><a title="SecureVue Express" href="http://www.eiqnetworks.com/securevue/SecureVueExpress/SecureVueExpress-download.php" target="_blank">here</a>.</span>  We&#8217;d also welcome feedback via <span style="text-decoration:underline;"><a title="eIQnetworks" href="mailto:info@eiqnetworks.com" target="_blank">email</a></span>, via <span style="text-decoration:underline;"><a title="@eIQnetworks" href="http://www.twitter.com/eiqnetworks" target="_blank">Twitter</a> </span>or by commenting below.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/964/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/964/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/964/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/964/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/964/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/964/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/964/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/964/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/964/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/964/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/964/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/964/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/964/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/964/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=964&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2011/11/29/get-situational-awareness-today-no-strings-attached/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/17aea691e1223f0a73257f630c551ca0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">broadpr</media:title>
		</media:content>
	</item>
		<item>
		<title>From Russia with Malice</title>
		<link>http://situationalroom.wordpress.com/2011/11/28/from-russia-with-malice/</link>
		<comments>http://situationalroom.wordpress.com/2011/11/28/from-russia-with-malice/#comments</comments>
		<pubDate>Mon, 28 Nov 2011 21:00:05 +0000</pubDate>
		<dc:creator>The Secure View</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Comment]]></category>
		<category><![CDATA[critical infrastructure]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Homeland Security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[SIEM is Dead]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Illinois]]></category>
		<category><![CDATA[infosecurity]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[Stuxnet]]></category>
		<category><![CDATA[water treatment]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=961</guid>
		<description><![CDATA[Three weeks ago a pump at a water treatment facility in Illinois was damaged by a malicious attack launched by an attacker using a computer based in Russia.  Or maybe it wasn&#8217;t.  Perhaps the pump was destroyed, but the attacker wasn&#8217;t based in Russia.  Maybe nothing happened at all… in fact, the DHS is now [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=961&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Three weeks ago a pump at a water treatment facility in Illinois was damaged by a malicious attack launched by an attacker using a computer based in Russia.  Or maybe it wasn&#8217;t.  Perhaps the pump was destroyed, but the attacker wasn&#8217;t based in Russia.  Maybe nothing happened at all… in fact, the DHS is now denying that a hack even occurred; yet the FBI has, according to reports, launched an investigation.</p>
<p>If we&#8217;re honest, there is no consensus on what did, or did not, happen in Illinois &#8211; not whether the attack (if indeed an attack took place) was based in Russia, or any other country.  The purpose of this post is not to speculate one way or another.  The confusion is, however, <span id="more-961"></span>something that we in the security industry should be very, VERY, concerned about.  It&#8217;s an all too familiar story; something doesn&#8217;t feel right, but confirming whether indeed something has happened, if it is something you should be concerned about, what the vector of the potential attack might be, and what you can do to mitigate the damage it could do is very difficult to pinpoint.  It’s not that, the majority of, organizations don&#8217;t have the tools they need to answer these questions, it&#8217;s simply that they don&#8217;t have the means to make sense of the multitude reports in order to differentiate the positives from the false positives and the double negatives &#8211; and do it quickly.</p>
<p>This problem is only going to get more complex as the role that information networks play in everyday business life.  Protecting sensitive corporate and customer data from those that wish to do harm, or use it for their own competitive advantage is increasingly going to be a key battle ground.  If it takes you three weeks to determine whether or not you&#8217;ve been breached you&#8217;ll have lost the battle without ever knowing you were under attack.</p>
<p>This is why we firmly believe that a new approach to information security is required.  We proclaimed the death of SIEM as an effective way to protect large corporate information networks a few months ago, and everything we see strengthens our position.  SIEM is still a valuable tool for collecting log and event based data, but situational awareness gives you the ability to collect ALL network data in it&#8217;s native format, correlate it in real time (20 seconds, rather than 20 days) and provides a clear picture of what has happened via a single pane of glass.</p>
<p>Situational Awareness means you can take immediate action to repel or take action to minimize the impact of an attack.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/961/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/961/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/961/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/961/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/961/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/961/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/961/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/961/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/961/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/961/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/961/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/961/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/961/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/961/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=961&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2011/11/28/from-russia-with-malice/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/17aea691e1223f0a73257f630c551ca0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">broadpr</media:title>
		</media:content>
	</item>
	</channel>
</rss>
