<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Situational Room by eIQnetworks</title>
	<atom:link href="http://situationalroom.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://situationalroom.wordpress.com</link>
	<description></description>
	<lastBuildDate>Fri, 24 Feb 2012 20:58:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='situationalroom.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>The Situational Room by eIQnetworks</title>
		<link>http://situationalroom.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://situationalroom.wordpress.com/osd.xml" title="The Situational Room by eIQnetworks" />
	<atom:link rel='hub' href='http://situationalroom.wordpress.com/?pushpress=hub'/>
		<item>
		<title>It’s not about adding another data source&#8230;</title>
		<link>http://situationalroom.wordpress.com/2012/02/24/its-not-about-adding-another-data-source/</link>
		<comments>http://situationalroom.wordpress.com/2012/02/24/its-not-about-adding-another-data-source/#comments</comments>
		<pubDate>Fri, 24 Feb 2012 20:58:52 +0000</pubDate>
		<dc:creator>The Secure View</dc:creator>
				<category><![CDATA[actionable intelligence]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[SIEM is Dead]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[New York Times]]></category>
		<category><![CDATA[NYT]]></category>
		<category><![CDATA[QRadar]]></category>
		<category><![CDATA[situational awareness]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=1209</guid>
		<description><![CDATA[&#8230;it’s what you do with it that counts! The New York Times Bits blog devoted 700 words to IBM&#8217;s announcement earlier this week that it has now managed to connect its newly acquired QRadar SIEM platform to its X-Force database. While this is news for IBM and QRadar customers it is, perhaps, less relevant for [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1209&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>&#8230;it’s what you do with it that counts!</p>
<p>The New York Times Bits blog devoted 700 words to IBM&#8217;s announcement earlier this week that it has now managed to <a href="http://bits.blogs.nytimes.com/2012/02/22/ibm-turns-to-big-data-algorithms-for-computer-security/">connect its newly acquired QRadar SIEM platform to its X-Force database</a>. While this is news for IBM and QRadar customers it is, perhaps, less relevant for organizations that aren&#8217;t exclusively &#8216;Big Blue&#8217;.</p>
<p>The same piece states, &#8220;Businesses spend billions of dollars each year on firewalls, applications and antivirus software in a desperate attempt to ward off hackers and yet, even the companies, like Symantec and RSA, that sell “security solutions” <a href="http://bits.blogs.nytimes.com/2012/02/07/symantec-says-hackers-tried-extortion/">can’t keep themselves hacker-free</a>&#8220;.  This is, I believe, far more newsworthy &#8211; and an issue that I hope the industry will explore as it convenes in San Francisco next week for the annual RSA conference.</p>
<p>The article&#8217;s author claims that, &#8216;the crux of the problem is that businesses have taken a piecemeal approach to security&#8217;.  I disagree. There is no denying that you need these purpose built products as part of overall security strategy. The crux is that organizations do not have the capability to collect, monitor, analyze and correlate ALL relevant security data from each of the different devices/products, to make sense of what is actually happening in their network.  The majority products, including SIEM tools like IBM’s QRadar, collect just log and event data.  This may enables security analysts to understand that something has happened, but not answer the most important question: How, Where and What, exactly, has happened?  Because they can&#8217;t answer this question they can&#8217;t figure out what needs to be done to repel an attack, identify the likely target, and take timely action to stop it. .  You need to collect, analyze and correlate not only log data with Threat Intelligence data like X-Force, but need other critical data like asset configuration state, vulnerability state, asset criticality, connectivity state, etc. for effective threat detection and mitigation.</p>
<p>For the majority of organizations information security is more post mortem than critical care… and regardless of how many billions of dollars you spend on security tools until you fix this inherent problem in traditional SIEM tools large organizations will continue to be breached at will.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1209/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1209/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1209/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1209/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1209/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1209/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1209/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1209/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1209/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1209/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1209/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1209/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1209/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1209/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1209&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2012/02/24/its-not-about-adding-another-data-source/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/17aea691e1223f0a73257f630c551ca0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">broadpr</media:title>
		</media:content>
	</item>
		<item>
		<title>Situational Awareness in one sentence</title>
		<link>http://situationalroom.wordpress.com/2012/02/22/situational-awareness-in-one-sentence/</link>
		<comments>http://situationalroom.wordpress.com/2012/02/22/situational-awareness-in-one-sentence/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 15:28:35 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[CISO]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[Aviation]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Definition]]></category>
		<category><![CDATA[situational awareness]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=1201</guid>
		<description><![CDATA[In the technology industry we&#8217;re often guilty of using 100 words, where three would suffice… or over complicating things to the point that only a handful of people are able to figure out what we&#8217;re saying.  So, when I heard a summary of the value of situational awareness that even your grandmother would understand, I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1201&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In the technology industry we&#8217;re often guilty of using 100 words, where three would suffice… or over complicating things to the point that only a handful of people are able to figure out what we&#8217;re saying.  So, when I heard a summary of the value of situational awareness that even your grandmother would understand, I wanted to share it.</p>
<p>The explanation, provided by a pilot, explains the role situational awareness plays in doing what they do safely, and why it enables them to deal with unforeseen events quickly and effectively.</p>
<p>&#8220;  …We [pilots] need situational awareness… you have to realize how you got into a situation to figure your way out of it…&#8221;</p>
<p>It occurred to me that this one sentence explains why situational awareness is set to play such a huge role in the future of information security.  Unless you have data, from which you can deduce how an attack took place [and in many cases will still be taking place] you will have no way of figuring out how to repel it, mitigate it, and protect the intended target of the attack.  Without situational awareness you’re faced with the proverbial needle in a haystack!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1201/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1201&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2012/02/22/situational-awareness-in-one-sentence/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
		<item>
		<title>Quis custodiet ipsos custodes? [Answers on a postcard, please!]</title>
		<link>http://situationalroom.wordpress.com/2012/02/05/quis-custodiet-ipsos-custodes-answers-on-a-postcard-please/</link>
		<comments>http://situationalroom.wordpress.com/2012/02/05/quis-custodiet-ipsos-custodes-answers-on-a-postcard-please/#comments</comments>
		<pubDate>Sun, 05 Feb 2012 19:54:07 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[SIEM is Dead]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[info sec]]></category>
		<category><![CDATA[Quis custodiet ipsos custodes?]]></category>
		<category><![CDATA[SEC]]></category>
		<category><![CDATA[transparency]]></category>
		<category><![CDATA[Verisign]]></category>
		<category><![CDATA[Who will watch the watchers?]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=1195</guid>
		<description><![CDATA[Reading the news that Verisign, the company responsible for delivering people safely to more than half the world&#8217;s websites, suffered a series of breaches back in 2010 comes as no surprise.  Why?  Because I think that we have entered a new era of cybersecurity; one where the objective is not to protect against a breach [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1195&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Reading the news that Verisign, the company responsible for delivering people safely to more than half the world&#8217;s websites, <a href="http://blogs.csoonline.com/data-protection/2013/verisign-hit-hackers">suffered a series of breaches back in 2010</a> comes as no surprise.  Why?  Because I think that we have entered a new era of cybersecurity; one where<span id="more-1195"></span> the objective is not to protect against a breach &#8211; it&#8217;s not that I think organizations shouldn&#8217;t try, just that I think the majority of large organizations are no longer able to &#8211; but instead to detect them and mitigate the damage done by them.</p>
<p>The fact that the breaches have only been made public because a Reuters journalist, Joseph Menn, found the company&#8217;s disclosure in a quarterly US Securities and Exchange Commission [SEC] filing should worry anybody that has a .com, .net or .gov domain.  It proves that the new guidance from the SEC works &#8211; but the fact that the breach was not immediately disclosed means that critical data MAY have been compromised, without its owners realizing that the risk had increased significantly.  To their credit, it appears Verisign acted quickly once it became aware &#8211; but reports indicate that staff waited a year before alerting senior management.</p>
<p>Perhaps the most worrying aspect of the story is that senior executives still don&#8217;t know exactly what happened, and what data was stolen.  While it is likely that Verisign has all of the right tools in place – end-point security tools, a traditional SIEM, a netflow analyzer, etc. – it appears unable to make sense of the data.  As a CISO, I once had to face my board to explain why my organization had been hit by the SQL slammer worm back in 2003 (long before situational awareness tools were available); I can only presume that attempts to do get answers were the reason for the 12 month delay.</p>
<p>Verisign aside, the story raises a much more important question.  It is one that I wrote about more than three years ago in a piece authored for Risk magazine entitled, ‘Quis custodiet ipsos custodes?’ [Who will watch the watchers?].  If we can’t trust the guardians of the data at the heart of our new network-dependent economy, who can we trust?</p>
<p>Answers on a postcard please… [alternatively, you can add yours in the comments section below]</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1195/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1195/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1195/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1195/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1195/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1195/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1195/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1195/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1195/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1195/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1195/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1195/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1195/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1195/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1195&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2012/02/05/quis-custodiet-ipsos-custodes-answers-on-a-postcard-please/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
		<item>
		<title>The first casualties of cyber war.</title>
		<link>http://situationalroom.wordpress.com/2012/01/26/the-first-casualties-of-cyber-war/</link>
		<comments>http://situationalroom.wordpress.com/2012/01/26/the-first-casualties-of-cyber-war/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 14:02:08 +0000</pubDate>
		<dc:creator>The Secure View</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[AOL Government]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Cyberwar]]></category>
		<category><![CDATA[Networked Society]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=1192</guid>
		<description><![CDATA[In his latest post for AOL Government eIQnetworks&#8217;s John Linkous explores how, in our increasingly networked society, it is only a matter of time before we see the first casualties from advanced persistent cyber attacks.  He also asks what can be done to mitigate the risk of virtual attacks affecting the physical world. You can [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1192&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In his latest post for <a title="AOL Government" href="http://gov.aol.com/" target="_blank">AOL Government</a> eIQnetworks&#8217;s John Linkous explores how, in our increasingly networked society, it is only a matter of time before we see the first casualties from advanced persistent cyber attacks.  He also asks what can be done to mitigate the risk of virtual attacks affecting the physical world.</p>
<p>You can read John&#8217;s post in full at <a title="When the Virtual Becomes Physical" href="http://ow.ly/8H5uB" target="_blank">http://ow.ly/8H5uB</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1192/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1192&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2012/01/26/the-first-casualties-of-cyber-war/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/17aea691e1223f0a73257f630c551ca0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">broadpr</media:title>
		</media:content>
	</item>
		<item>
		<title>Everything you ever wanted to know about Situational Awareness&#8230; [but were afraid to ask!]</title>
		<link>http://situationalroom.wordpress.com/2012/01/24/everything-you-ever-wanted-to-know-about-situational-awareness-but-were-afraid-to-ask/</link>
		<comments>http://situationalroom.wordpress.com/2012/01/24/everything-you-ever-wanted-to-know-about-situational-awareness-but-were-afraid-to-ask/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 22:20:47 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Comment]]></category>
		<category><![CDATA[Company News]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Gartner]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[John Pescatore]]></category>
		<category><![CDATA[SIEM is Dead]]></category>
		<category><![CDATA[SIEM Plus]]></category>
		<category><![CDATA[situational awareness]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=1185</guid>
		<description><![CDATA[Most security professionals will, by now, be aware of the term Situational Awareness &#8211; but how many understand what it actually is?  How many understand how to deliver it within their organization?  Situational Awareness has become one of the big buzzwords of the security industry in the last 12 months and, as the company that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1185&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Most security professionals will, by now, be aware of the term Situational Awareness &#8211; but how many understand what it actually is?  How many understand how to deliver it within their organization?  Situational Awareness has become one of the big buzzwords of the security industry in the last 12 months and, as the company that coined the term within our industry AND the first to offer a working platform, we thought it was time to clarify much of the confusion that exists around the term.</p>
<p>“Proactive Threat Discovery and Risk Mitigation Demands Situational Awareness,” is an eIQnetworks webinar, featuring Gartner analyst John Pescatore, which aims to answer many of the questions we&#8217;ve been asked by security professionals in recent months.  The webinar also explains how situational awareness delivers key competencies that cannot be achieved using existing SIEM and SIEM Plus tools and how it provides security analysts with the ability to effectively protect large distributed networks effectively and efficiently in a way they cannot do with traditional point tools.</p>
<p>You can view the video <a href="http://www.eiqnetworks.com/resources/gartnerandeiqnetworks_webinar.php">here</a></p>
<p>If you have a question that is not included in our webinar then please let us know and we&#8217;ll be happy to answer it for you.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1185/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1185/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1185/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1185&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2012/01/24/everything-you-ever-wanted-to-know-about-situational-awareness-but-were-afraid-to-ask/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
		<item>
		<title>Cybersecurity: what&#8217;s the point?</title>
		<link>http://situationalroom.wordpress.com/2012/01/17/cybersecurity-whats-the-point/</link>
		<comments>http://situationalroom.wordpress.com/2012/01/17/cybersecurity-whats-the-point/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 17:13:29 +0000</pubDate>
		<dc:creator>The Secure View</dc:creator>
				<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[camus]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[existentialism]]></category>
		<category><![CDATA[futility]]></category>
		<category><![CDATA[sartre]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=1179</guid>
		<description><![CDATA[Last week the FBI claimed that cybersecurity posed an &#8220;existential&#8221; threat to American corporations, &#8220;meaning it could eliminate whole companies&#8221;. Despite this, it said, many consumers and commercial organizations are &#8220;still not taking the threat serious, claiming, &#8220;either they don&#8217;t recognize it, they don&#8217;t understand it or they don&#8217;t care&#8221;.  I wonder what Sartre or [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1179&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Last week the FBI claimed that cybersecurity <a href="http://www.huffingtonpost.com/2012/01/12/cyber-threats_n_1202026.html">posed an &#8220;existential&#8221; threat to American corporations</a>, &#8220;meaning it could eliminate whole companies&#8221;. Despite this, it said, many consumers and commercial organizations are &#8220;still not taking the threat serious, claiming, &#8220;either they don&#8217;t recognize it, they don&#8217;t understand it or they don&#8217;t care&#8221;.  I wonder what Sartre or Camus would have to say on the matter?</p>
<p>I&#8217;m have no doubt they would have <span id="more-1179"></span>thought long and hard on the philosophical questions facing CISOs in many commercial organizations and Government departments. Questions like: Do advanced persistent threats really exist? How can we minimize our risk of attack? And, &#8216;If we are attacked, how do we detect and deal with it?&#8217;.  Hopefully you won&#8217;t conclude that that the struggle is futile or absurd!</p>
<p>The battle against cyberattacks can often feel a little like Sisyphus, pushing a rock up a mountain only to have it roll to the bottom again. We can only hope that the majority of security professionals, regardless of how absurd or futile the struggle can appear, take steps to protect themselves and their organizations from the threats that undoubtedly threaten their existence.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1179/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1179/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1179/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1179&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2012/01/17/cybersecurity-whats-the-point/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/17aea691e1223f0a73257f630c551ca0?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">broadpr</media:title>
		</media:content>
	</item>
		<item>
		<title>Less Turtle, More Awareness</title>
		<link>http://situationalroom.wordpress.com/2012/01/11/less-turtle-more-awareness/</link>
		<comments>http://situationalroom.wordpress.com/2012/01/11/less-turtle-more-awareness/#comments</comments>
		<pubDate>Wed, 11 Jan 2012 20:27:21 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[SIEM]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[Unified Situational Awareness]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[Security Week]]></category>
		<category><![CDATA[situational awareness]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=1170</guid>
		<description><![CDATA[Catching up on some reading this week, I came across this piece  in Security Week, written by Chris Poulin, Chief Security Officer at Q1 Labs, talking about how a childhood experience can help the modern information security professional.  Chris makes some good points, such as the need for continuous monitoring, and using all available tools [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1170&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Catching up on some reading this week, I came across this <a title="Why you should put a GPS tracker on your turtle" href="http://www.securityweek.com/why-you-should-put-gps-tracker-your-turtle" target="_blank"><span style="text-decoration:underline;">piece</span></a>  in Security Week, written by Chris Poulin, Chief Security Officer at Q1 Labs, talking about how a childhood experience can help the modern information security professional.  Chris makes some good points, such as the need for continuous monitoring, and using all available tools to capture multiple data points in order to enable you to pinpoint the vector of advanced persistent threats (and slow moving box turtles).</p>
<p>This is certainly all good advice &#8211; although we contend that the average cyber or insider attack moves slightly quicker than the average box turtle.  There are, however, some major problems with Chris&#8217; piece.<span id="more-1170"></span></p>
<ul>
<li>First, the assumption is made that SIEM tools – of which Q1 Labs makes a very good one – can capture all of the information required to find our good friend, the turtle.  Unfortunately, that simply isn’t the case.  SIEM tools are highly focused on events.  Even in cases where a SIEM can look outside of the world of events at one or two other pieces of data (say, at network traffic, which is something that Q1 Labs’ SIEM does), that’s still woefully inadequate: if we’re going to find an errant turtle, we certainly need events and network traffic data, but we also need system asset and configuration state (from <strong><em>both</em></strong> hosts <strong><em>and</em></strong> devices, not just one or the other), system performance metrics, visibility into file integrity, and much, much more.  A SIEM is great if our Turtle friend has left behind a trail of breadcrumbs (or whatever it is that turtles leave behind them when they travel), but otherwise, the SIEM is going to likely lead us to a cold trail due to lack of data.</li>
<li>Second, even if your SIEM can collect different types of data in search of our elusive turtle friend, it probably uses multiple, separate products to do so.  Q1 Labs has a great SIEM product – Qradar – but requires separate appliances to collect flow data and Q1’s proprietary pseudo-DPI information, as well as another, completely separate appliance to collect system asset data and configuration state (and even then, this data is limited to a small subset of network devices, and completely excludes hosts… which means we’re stuck in the world of limited data again).  Of course, Q1 Labs is not the only SIEM vendor who runs into this issue: Tripwire, Nitro Security, NetIQ, Arcsight, and others all rely on multiple tools to try and collect more than just event-based data.  Unfortunately, all this approach does is result in taking a bunch of smaller silos (from individual systems and point security tools), and turn them into a smaller number of bigger silos – certainly not useful as the clock ticks on finding our buddy, the turtle!</li>
<li>Finally, even if you can collect a multitude of data points from various point security tools, and your security analysts have fed them into a traditional SIEM, you still have a problem: the SIEM views everything as an event: a piece of system state data becomes an “event” (which it isn’t), performance metrics become “events” (which they aren’t), and so on.  Much of the richness of the data is lost, and the only thing that most organizations are left with is a general idea that “’something’ has certainly happened…”, but they lose the critical context of exactly what that ‘something’ is.  A manual hunt for the turtle then begins in earnest.</li>
</ul>
<p>So yes, what Chris describes is absolutely valid &#8212; we call it <a href="http://www.eiqnetworks.com/securevue/securevue.php"><span style="text-decoration:underline;">Unified Situational Awareness</span></a> – but the fact is, traditional SIEM and “SIEM-plus” tools simply can&#8217;t deliver it.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1170/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1170/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1170/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1170&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2012/01/11/less-turtle-more-awareness/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
		<item>
		<title>Situational Awareness: It&#8217;s not a Technology; it&#8217;s a Way of Life</title>
		<link>http://situationalroom.wordpress.com/2012/01/09/situational-awareness-its-not-a-technology-its-a-way-of-life/</link>
		<comments>http://situationalroom.wordpress.com/2012/01/09/situational-awareness-its-not-a-technology-its-a-way-of-life/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 15:38:40 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Homeland Security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[CSO Magazine]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Freedom Tower]]></category>
		<category><![CDATA[situational awareness]]></category>
		<category><![CDATA[WTC]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/2012/01/09/situational-awareness-its-not-a-technology-its-a-way-of-life/</guid>
		<description><![CDATA[Recently, CSO Magazine published a story on the efforts to secure the new Freedom Tower and other buildings that are being built at the site of the new World Trade Center in New York.  Throughout the article, Louis Barani &#8211; the former U.S. Naval Officer who is developing the security technologies for the new facility [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1166&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Recently, CSO Magazine published a <a title="CSO Magazine - WTC Situational Awareness" href="http://www.csoonline.com/article/689109/situational-awareness-inside-the-new-world-trade-center" target="_blank">story</a> on the efforts to secure the new Freedom Tower and other buildings that are being built at the site of the new World Trade Center in New York.  Throughout the article, Louis Barani &#8211; the former U.S. Naval Officer who is developing the security technologies for the new facility &#8211; frequently uses the term &#8220;situational awareness&#8221; to describe his team&#8217;s efforts to ensure the security of the Freedom Tower and other buildings.</p>
<p>What&#8217;s most interesting is how Mr. Barani talks about situational awareness not as a <em>product</em>, but as a <em>capability</em>.  While much of his interest is in physical security &#8212; as opposed to information security, which is where eIQnetworks and SecureVue reside &#8212; he identifies all the different types of security-related information that are required to achieve situational awareness: physical access control and logs; CCTV feeds and data; HVAC systems; elevator controls; and many, many more.  His team will be using a platform designed to bring together the physical security data from all these different sources into a single platform that facilitates situational awareness.</p>
<p>So what&#8217;s the point?  First, that situational awareness isn&#8217;t just a tool or a technology &#8212; it&#8217;s a way of life that requires continuous, real-time evaluation of the environment (whether the goal is system operations, physical security, information security, or otherwise), correlation of different types of events and other data together, and the ability to act on abnormalities right away.  Second, to make all of these things happen, you need the right tools to <em>facilitate</em> &#8212; not <em>automate</em> &#8211; situational awareness. In the information security world, that means collecting all security-related data, whether that data is encapsulated in events, asset state, network traffic, system performance, or any other piece of information.  Once you have the data, the other critical capability is correlation: are unusual network traffic, an abnormal performance metric, and an unauthorized change on a server related?  If so, how?</p>
<p>Just like in physical security systems, in the world of information security there are plenty of assets generating security data: events from host OS&#8217;s, devices, applications and databases; point security tools like IDS/IPS and anti-malware; performance data; network traffic; the current operating state of systems; and so much more.</p>
<p>Like the architects of physical security at Freedom Tower, delivering situational awareness for information security requires the ability to bring all of this data together into a single location, and correlate this data to find abnormalities &#8212; the hallmark of situational awareness.  Unfortunately, there aren&#8217;t many solutions available today that really do this for information security: SIEMs have limited data collection capabilities, and treat everything like an event (which is decidedly <em><span style="text-decoration:underline;">not</span></em> situational awareness); configuration management tools have no visibility into events or what&#8217;s happening at the network layer; and NBA and network monitoring tools lack visibility into system state.  So, like a CCTV system, or an HVAC controller, or an elevator system, each of these information security tools provides visibility into a limited &#8212; but critical &#8211; wedge of data.  You still need something to bring all the data together, and facilitate true situational awareness.  Fortunately, we know <a title="SecureVue - The Unified Situational Awareness Platform" href="http://www.eiqnetworks.com/securevue/securevue.php" target="_blank">exactly where you can find</a> a product that does this.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1166/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1166&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2012/01/09/situational-awareness-its-not-a-technology-its-a-way-of-life/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
		<item>
		<title>Forget End-of-Year Predictions&#8230; We Have End-of-the-World Predictions!</title>
		<link>http://situationalroom.wordpress.com/2011/12/31/forget-end-of-year-predictions-we-have-end-of-the-world-predictions/</link>
		<comments>http://situationalroom.wordpress.com/2011/12/31/forget-end-of-year-predictions-we-have-end-of-the-world-predictions/#comments</comments>
		<pubDate>Sat, 31 Dec 2011 15:33:06 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[Situational Awareness]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[end of the world]]></category>
		<category><![CDATA[info security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mayan]]></category>
		<category><![CDATA[Predictions]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=1009</guid>
		<description><![CDATA[As we officially kickoff “prediction week” – where virtually every security vendor, journalist and pundit gazes into their crystal ball and prognosticates about the next twelve months – we at eIQ have decided to up the proverbial ante.  Our predictions aren’t just about the next year… they’re about the end of the world. How’s that, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1009&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As we officially kickoff “prediction week” – where virtually every security vendor, journalist and pundit gazes into their crystal ball and prognosticates about the next twelve months – we at eIQ have decided to up the proverbial ante.  Our predictions aren’t just about the next year… they’re about the end of the world.</p>
<p>How’s that, you might ask?  Well, it all starts – or rather, ends – with our favorite pre-Columbian civilization, the Mayans.  Ah, the Maya… ask anyone on the street today about them, and the first thing you’re likely to hear about is the <a title="Wikipedia - Mayan Calendar" href="http://en.wikipedia.org/wiki/Mayan_calendar" target="_blank">Mayan calendar</a>.  Like other Mesoamerican civilizations such as the Aztecs and Inca, the Maya very much believed that time operated in cycles.  The Maya “long count” calendar – the longest individual cycle – is currently scheduled to complete on December 21, 2012.</p>
<p>The Mayans themselves would simply start a new cycle (called b’ak’tun) on December 22; but in our clever world, that’s not good enough for many.  Unfortunately, the end of the “long count” cycle this year has been misinterpreted by some as “the end of the world” – often by people who are looking to make a quick buck.  Rest assured that just as Y2K, the IRS tax deadline of April 15th, and other critical dates have been the focus of phishing and other scam activity in the past, so too will December 21, 2012.</p>
<p>It’s only a matter of time before we start seeing it: <strong>“Click here to download the PDF <em>[which is infected]</em> / program <em>[which is trojaned]</em> / website link <em>[which is XSS’d to malware]</em> that shows you why the Mayans were right about the end of the world!”</strong>  Like any other scam, these emails and web ads will play to people’s worst fears, and doubtless some of them will succeed in facilitating identity theft, illegal transfer of funds, or even worse.  People are fascinated by doom, and the idea that someone might have “secret knowledge” will cause many unsuspecting people to be drawn into these scams.  We saw this happen endlessly during Y2K, over ten years ago when the term phishing hadn’t even been coined yet.  With the advent of new methods to reach people – no longer just e-mail, but text messages, social media sites, embedded links in documents, and so many more – the amount of fraud that will be perpetrated from end-of-the-world scare tactics will be extreme.</p>
<p>So remember, you heard it here first… and if we’re all still around on December 22, 2012, we’ll see if we at eIQ were right.   <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/1009/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=1009&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2011/12/31/forget-end-of-year-predictions-we-have-end-of-the-world-predictions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
		<item>
		<title>If Containment is the New Prevention&#8230;</title>
		<link>http://situationalroom.wordpress.com/2011/12/14/if-containment-is-the-new-prevention/</link>
		<comments>http://situationalroom.wordpress.com/2011/12/14/if-containment-is-the-new-prevention/#comments</comments>
		<pubDate>Wed, 14 Dec 2011 17:16:42 +0000</pubDate>
		<dc:creator>John Linkous</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[Comment]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[SIEM is Dead]]></category>
		<category><![CDATA[Cybersecurity predictions 2012]]></category>
		<category><![CDATA[info security]]></category>
		<category><![CDATA[Ponemon Institute]]></category>
		<category><![CDATA[SecureVue]]></category>
		<category><![CDATA[situational awareness]]></category>

		<guid isPermaLink="false">http://situationalroom.wordpress.com/?p=999</guid>
		<description><![CDATA[A couple of weeks ago, Websense published its cybersecurity predictions for 2012.  One in particular prediction caught our eye: that containment will become the new prevention.  We&#8217;re assuming that Websense&#8217; prediction is that the focus for many organizations will shift from preventing external and insider attacks, data breaches, and other incidents, to containment (rather than [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=999&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A couple of weeks ago, Websense published its <a title="Websense Cyber Security Predictions - 2012" href="http://community.websense.com/blogs/websense-news-releases/archive/2011/11/17/2012-cyber-security-predictions-from-the-websense-security-labs.aspx">cybersecurity predictions for 2012</a>.  One in particular prediction caught our eye: that <strong>containment will become the new prevention</strong>.  We&#8217;re assuming that Websense&#8217; prediction is that the focus for many organizations will shift from preventing external and insider attacks, data breaches, and other incidents, to containment (rather than being something that many aspire to, but very few have yet to attain, by the way&#8230;)</p>
<p>We&#8217;ve been saying the same thing for a number of years.  2011 has demonstrated that, <span id="more-999"></span>even when an organization knows that an attack is imminent, many remain unable to do anything to prevent it.  On this basis, it&#8217;s inconceivable that using the point SIEM tools that exist in many large organizations most will be able to contain it.  This is supported by <a title="Second Annual Cost of Cybercrime report" href="http://www.infosecurity-magazine.com/view/19838/ponemon-institute-report-highlights-soaring-cost-of-cybercrime/" target="_blank">Ponemon Institute research</a> that suggests that <strong>the current average response time to a security incident is 18 days</strong>.</p>
<p>If Websense&#8217; prediction is going to become reality then there needs to be a fundamental shift towards tools that can correlate large amounts of security data, in all of its native formats to provide analysts with a real-time, contextual view of their security posture.  And, in order for this to happen, <strong><a title="SIEM is Dead" href="http://www.eiqnetworks.com/resources/SIEM_is_DEAD.php" target="_blank">SIEM must be dead</a></strong>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/situationalroom.wordpress.com/999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/situationalroom.wordpress.com/999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/situationalroom.wordpress.com/999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/situationalroom.wordpress.com/999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/situationalroom.wordpress.com/999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/situationalroom.wordpress.com/999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/situationalroom.wordpress.com/999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/situationalroom.wordpress.com/999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/situationalroom.wordpress.com/999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/situationalroom.wordpress.com/999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/situationalroom.wordpress.com/999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/situationalroom.wordpress.com/999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/situationalroom.wordpress.com/999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/situationalroom.wordpress.com/999/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=situationalroom.wordpress.com&amp;blog=17107788&amp;post=999&amp;subd=situationalroom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://situationalroom.wordpress.com/2011/12/14/if-containment-is-the-new-prevention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/26b8228ee1d43d6035459b3a2feefa69?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">phylum</media:title>
		</media:content>
	</item>
	</channel>
</rss>
