TechBizWebTechBizWeb

    Subscribe to Updates

    Get the latest news about Technology and Business from all around the web..

    What's Hot

    Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

    November 7, 2022

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022
    Facebook Twitter Instagram
    • About Us
    • Privacy Policy
    • Guest Post
    • Terms
    • Contact
    Facebook Twitter Instagram
    TechBizWebTechBizWeb
    Subscribe
    • Home
    • Technology

      Amazon says it has ‘hundreds’ of Rivian electric vans making deliveries in the US

      November 7, 2022

      Devialet brings its sci-fi design aesthetics to a $790 portable speaker

      November 7, 2022

      Elon Musk’s response to fake verified Elon Twitter accounts: a new permanent ban policy for impersonation

      November 7, 2022

      The iPhone 14 Pro and Pro Max will come with ‘longer wait times’ due to factory lockdown

      November 6, 2022

      Meta’s reportedly planning to lay off ‘thousands’ of workers this week

      November 6, 2022
    • Business
    • Cyber Security
      National Security News

      List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

      September 24, 2022

      Cybersecurity ranked most serious enterprise risk in 2022

      August 31, 2022

      Registration open for CISA virtual summit on K-12 school safety

      August 31, 2022

      What do the Trickbot leaks reveal about Russian cybercrime?

      August 31, 2022

      What cybersecurity measures do CISOs outsource?

      August 30, 2022
    • Blockchain
    • Vulnerabilities
    • Social Engineering
    • Malware
    • Cyber Security Alerts
    TechBizWebTechBizWeb
    Home»Cyber Security»Are We Beyond Peak Buzzword?
    Cyber Security

    Are We Beyond Peak Buzzword?

    March 26, 2019Updated:March 26, 2019No Comments6 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp
    Share
    Facebook Twitter LinkedIn Pinterest Email


    It’s Fefreshing to See the Industry Hyping Security Concepts That Actually Work

    Every year at the RSA Conference, industry practitioners are treated to a never-ending set of marketing buzzwords. Peppered throughout the talks, and plastered on booths and billboards, with invocations of FUD and FOMO to energize spend in a new area. Of course, the use of buzzwords isn’t exclusive to RSA, but this time of year seems to be when new campaigns are rolled out and the big new products are announced. 

    Everyone’s experience is difference, but at this year’s RSA Conference, I got the feeling that peak buzzword might be behind us. Previous years’ buzzwords included everything from “APT” and “Machine Learning” to “Artificial Intelligence” and “Threat Intelligence.” While there’s a place for all of these, they’re the essence of buzziness. They were amorphous and hard to put into action. How is a CISO really supposed to make Artificial Intelligence useful? How can a SOC actually make Threat Intelligence work for them? 

    This year’s buzzwords – if you can call them that – seemed more cogent, and represented actionable, proven concepts. Here were the trending themes that I picked up on:

    DevSecOps: DevSecOps is all about incorporating security into the Software Development Lifecycle and building software that is secure by design. Pure play vendors such as ThreatModeler Software, Aqua Security, Puppet, and Synopsys help developers think about risks, gain visibility into application activity, automate security checks, and build security throughout the SDLC. Larger vendors, such as IBM, AWS and Microsoft are promoting their tools for integrating security at every phase of design, build, and test. I like the DevSecOps buzzword because it calls for building secure software from the start, and in that sense is really nothing new. Companies have been incorporating static code checking into developer IDEs for a long time, and I remember Shannon Lietz (@devsecops) proclaiming the fundamentals of DevSecOps five years ago, before the term was popular. I’m all for drawing attention to good fundamentals, even if it means making the old new again!

    Zero Trust: It’s great to see the fundamental ideas behind Zero Trust gaining so much traction, and unlike nebulous concepts such as “Artificial Intelligence,” this is a proven concept that can help organizations start securing their environment. Least privileged access, stronger identity-based access to applications, inspection of traffic, and network segmentation are old ideas, and get to the heart of security. I also like the emphasis on Zero Trust because it doesn’t need to be (nor can it be) purchased from any one vendor – in fact, the very idea of that is funny, and should make organizations question any vendor who says they can sell it. Anyone can make incremental and cost-effective steps by applying its underlying principles. 

    MITRE ATT&CK™: MITRE describes ATT&CK as, “…a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations.” Much has been written about how to use it to help secure an environment – I like Devon Kerr’s (@_devonkerr_) recent SecurityWeek article on the topic. ATT&CK is great because it’s based on the real world, has so many practical applications, and doesn’t belong to any vendor. I see it shaping the way we think about attacker activity in the same way that @mikecloppert and @rohanamin’s Kill Chain or @Mandiant ‘s Attack Lifecycle helped us think about attacks 8+ years ago (hard to believe it’s been that long!). 

    Breach & Attack Simulation: This last bit of buzz might be the most commercial one on the list, and that’s because it represents a new class of products seeking to establish a category. Again, the concept isn’t new. For years, smart security teams have taken what we know about an attacker – their tactics, techniques, and procedures (TTPs) – perhaps as represented in the MITRE ATT&CK framework. They then use those TTPs to test the controls in their environment. Over the last few years, this has been expressed through internal or external Red Team engagements. I love the idea of Red Teaming, but it is very point-in-time, and can get expensive. Breach & Attack Simulation (BAS) vendors claim to do this constantly, and can provide real-time reports on how an organization would fare against a specific attacker (APT35, FIN7, etc.) or type of attack (e.g., a cryptocurrency miner delivered via a specific vulnerability). The BAS vendors talk a lot about “automated red teaming at a fraction of the cost” because they’re looking for existing budget to sell into. This is reasonable, but I don’t see BAS products just as replacements for Red Teaming. They lack the creativity and determination of a good Red Team. Instead, I see them as supplements (or eventually, replacements) for traditional vulnerability scanning. Security practitioners always struggle to get senior leadership to prioritize vulnerability management and eyes tend to glaze over when vulnerability managers share CVE status. Reframing the conversation around real-world vulnerability is different. Explaining to a risk committee that your organization is vulnerable to the OceanLotus/APT32 group, which they read about in SecurityWeek, and which has been targeting companies in your industry, could create a completely different sense of urgency.

    Unlike buzzwords from prior years, this year’s buzzwords are all throwbacks of sorts. They represent a return to fundamentals of information security. DevSecOps is about building security in. ZeroTrust is about verifying everything and trusting nothing. MITRE ATT&CK is about understanding attacker TTPs and how they relate to an environment. Breach & Attack Simulation is about applying those TTPs to the organization and operationalizing the concepts behind a Red Team. 

    Although it wasn’t due to any coordinated effort, it’s refreshing to see the industry hyping concepts that work, instead of pushing products that are likely unneeded. Let’s hope this year’s themes represents a longer-term turning away from buzzwords and toward effective fundamentals.

    Related: MITRE ATT&CK Matrix Used to Evaluate EDR Products

    Related: Observations From RSA Conference 2019

     

    Related: MITRE Uses ATT&CK Framework to Evaluate Enterprise Security Products

    Grady Summers is Executive VP and Chief Technology Officer at FireEye, where he oversees the global CTO team that supports R&D and product engineering and works with customers to address today’s evolving threat landscape. Grady has over 15 years of experience in information security both as a CISO and consultant to many Fortune 500 companies. He joined FireEye through its acquisition of Mandiant in 2014. Prior to Mandiant, he was a partner at Ernst & Young, responsible the firm’s information security program management practice. Before E&Y, Grady was the CISO at General Electric, overseeing a global information security organization. His previous roles at GE include divisional CTO and a variety of positions in application security, web development, and infrastructure management. He holds an MBA from Columbia University and a bachelor of science in computer systems from Grove City College.

    Previous Columns by Grady Summers:
    Tags:





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    National Security News

    List of 620 Russian spies, featuring one alleged agent at the centre of one of the biggest personal scandals in Wall Street history.

    September 24, 2022 Cyber Security

    Cybersecurity ranked most serious enterprise risk in 2022

    August 31, 2022 Cyber Security

    Registration open for CISA virtual summit on K-12 school safety

    August 31, 2022 Cyber Security

    What do the Trickbot leaks reveal about Russian cybercrime?

    August 31, 2022 Cyber Security

    What cybersecurity measures do CISOs outsource?

    August 30, 2022 Cyber Security

    SIA announces Women in Security Forum scholarship recipients

    August 30, 2022 Cyber Security
    Editors Picks

    Ryanair swings to first-half profit and raises passenger forecast

    November 7, 2022

    Devialet brings its sci-fi design aesthetics to a $790 portable speaker

    November 7, 2022

    Google Cloud Says Running Validator on Solana Blockchain

    November 7, 2022

    European stocks rise as investors boosted by China speculation

    November 7, 2022
    Trending Now

    Evergrande creditors sell ‘Versailles mansion’ plot in Hong Kong

    By techbizweb

    OpenSea Creates Tool for NFT Creators to Enforce Royalties On-Chain

    By techbizweb

    FTSE chairs warn of declining relations with institutional investors

    By techbizweb

    https://www.nationalsportsacademy.com

    slot gacor hari ini

    http://www.inadesfo.org/

    http://www.eueomgbissau.org/

    http://www.congo-mai-mai.net/

    http://www.angelesdelafrontera.org/

    http://fifaworldcup2018schedule.com/

    http://tony4gtrmcr.co.uk/

    http://www.standrewsagreement.org/

    http://www.bob-russell.co.uk/

    http://davidmulholland.co.uk/

    http://railwayhotelenniskillen.com/

    http://www.fantasysportstrades.com/

    http://www.rainleaf-flooring.com

    http://mothersagainstguns.org/

    http://ma-coc.org/

    slot online

    http://www.paradoxmag.com/situs-judi-slot-online-gampang-menang-2021/

    http://www.paradoxmag.com/situs-judi-slot-online-terbaru-2021/

    http://slot-terbaru.net/

    Slot Gacor

    Slot Online

    Situs Slot Gacor

    http://www.appdexterity.com/

    https://cars4kids-deutschland.de/

    https://www.stretchingculture.com/

    https://www.b-123-hp.com/slot-gacor/

    https://denzstaffing.nl/

    https://ezbbqcooking.com/slot-gacor/

    https://www.mbahelp24.com/slot-gacor

    https://minhtanstore.com/slot-jackpot-terbesar/

    https://njbpusupplierdiversity.com/slot-gacor-gampang-menang/

    https://www.floridaspecialtycropfoundation.org/slot-gampang-menang/

    https://childrenscornerpreschool.org/slot-gacor-gampang-menang/

    https://cryptoquoter.com/slot-online-terbaik/

    https://alorkantho24.com/slot-gacor/

    https://ellas.xyz/slot-gacor/

    https://it.dougamatome.xyz/slot-online/

    https://www.daltercume.com/slot-gacor/

    https://josi-ana.dougamatome.xyz/slot88/

    https://josi-ana.dougamatome.xyz/slot-gacor/

    https://fastobserver.com/slot-jackpot-terbesar/

    https://www.planetexperts.com/slot-gacor/

    https://bfsolution.group/slot-bet-kecil/

    https://rustleva.co/slot/

    https://bfsolution.group/slot-bet-kecil/

    https://www.hotelcalimareal.com/togel-online/

    https://anime-game.dougamatome.xyz/slot-gacor-gampang-menang/

    https://anime-game.dougamatome.xyz/togel-online/

    https://bourbonbarrelfoods.com/slot/

    http://suneo39.wp.xdomain.jp/slot/

    https://techbizweb.com/slot-gacor/

    https://www.generalcatalyst.com/18-daftar-slot-gacor-terbaik-gampang-menang-jackpot-hari-ini/

    https://www.hotelcalimareal.com/slot-online/

    https://www.blockgates.io/slot-gacor/

    https://l12.com.br/slot-gacor/

    slot paling gacor

    https://www.donalds-hobby.com/slot-online/

    https://thecryptodirt.com/slot-gacor-hari-ini/

    http://iseta.edu.ar/aulavirtual/app/upload/users/1/1205/my_files/sbobet.html

    http://escuelavirtual.mincit.gov.co/app/upload/users/1/194/my_files/slot.html

    https://www.dev.medecinesfax.org/courses/JUDICASINO/document/slot.html

    http://www.e-archivos.org/cursos/courses/JUDICASINO/document/slot-gacor.html

    http://iesma.com.br/ead/main/upload/users/4/447/my_files/slot.html

    https://www.fundacoop.org/chamilo/app/upload/users/1/1185/my_files/slot.html

    https://fata-aatf.org/eskola/main/upload/users/3/31/my_files/slot.html

    https://uancv.edu.pe/ofinvestigacion/app/upload/users/3/328/my_files/slot-terlengkap.html

    https://micost.edu.my/EL/app/upload/users/2/209/my_files/slot-gacor.html

    https://www.academiacoderdojo.ro/elearningdev/app/upload/users/2/2442/my_files/slot-online.html

    http://campus-cidci.ulg.ac.be/courses/JUDICASINO/document/slot-termurah.html

    https://www.escueladerobotica.misiones.gob.ar/aula-ste/courses/LIVECASINO/document/slot-tergacor.html

    http://ccdipeepccqqfar.usac.edu.gt/chamilo/app/upload/users/3/358/my_files/slot-online.html

    https://cunori.edu.gt/campus/app/upload/users/7/7334/my_files/slot-online.html

    http://u-rus.com.ar/aula/app/upload/users/1/1322/my_files/slot.html

    http://icrodarisoveria.edu.it/chamilo/app/upload/users/1/1855/my_files/slot.html

    https://iestpliliagutierrez.edu.pe/clarolgm/courses/CASINO/document/slot.html

    http://pva.cobach.edu.mx/app/upload/users/7/7379/my_files/slot.html

    http://www.imb-pc-online.edu.gt/PL/app/upload/users/3/373/my_files/slot.html

    http://avcs.upeu.edu.pe/main/upload/users/3333/my_files/slot.html

    https://chamilo.fca.uas.edu.mx/app/upload/users/1/11186/my_files/slot-online/

    TechBizWeb
    Facebook Twitter Instagram Pinterest Vimeo YouTube
    • Home
    • Guest Post
    • About Us
    • Privacy Policy
    • Our Authors
    • Terms and Conditions
    • Contact
    © 2023 Tech Biz Web. Developed by Sawah Dev.

    Type above and press Enter to search. Press Esc to cancel.