Transcript
Page 1: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Why We Don't Know.

What We Can Do About It.

Page 2: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Director of Security Intelligence for Akamai Technologies Former Research Director, Enterprise Security [The 451 Group] Former Principal Security Strategist [IBM ISS]

Industry: Co-Founder of “Rugged Software” www.ruggedsoftware.org Faculty: The Institute for Applied Network Security (IANS) 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: www.cognitivedissidents.com

Things I’ve been researching: DevOps Security Intelligence Chaotic Actors Espionage Security Metrics

Page 3: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 4: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Passionate Purposeful Principled Protector Provider

Page 5: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Honest Courageous

Consequential

Page 6: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Unreasonable A Fool

Page 7: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 8: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

No

Page 9: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Is it getting better?

Or do you feel the same?

Page 10: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Will it make it easier on you now?

You got someone to blame…

Page 11: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

How would you know?

By which criteria?

Page 12: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Evolving Threat

Evolving Compliance

Evolving Technology

Evolving Economics

Evolving Business

Cost Complexity

Risk

12

Page 13: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 14: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

WHAT

WHY

http://www.ted.com/talks/simon_sinek_how_great_leaders_inspire_action.html

HOW

WHAT

Page 16: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Performance

Fungible Assets

IntellectualProperty & TradeSecrets

Rights & Civility

Safety & Human Life

Page 17: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Dependence

Page 18: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 19: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 20: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 21: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

s/Software/Vulnerability/

Page 22: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

s/Connected/Exposed/

Page 23: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Our challenges are not technical… but cultural

Page 24: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Activity Effect

Page 25: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Symptoms Root Causes

Page 26: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Easy Important

Page 27: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 28: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Best Practices

aren’t

Page 29: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Good Enough

isn’t

Page 30: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Faith-based Security

Evidence-Based

Security

Available Data

Drunks & Lamp Posts

Numerology

Page 31: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Incentives

Page 32: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 33: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

GET A MAP

Page 34: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

0) “Vendors don’t need to be Ahead of the Threat…

…just Ahead of the Buyer”

1) AV Certification Omissions

2) There is no Perimeter… [nor Santa Claus]

3) Risk Management Threatens Vendors

4) Psst… There is more to Risk than Weak Software

5) Compliance Threatens Security…

6) Vendor Blind Spots Allowed for Storm++

7) Security has grown well past “Do it yourself”

Page 35: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

RUGGED SOFTWARE

Page 36: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 37: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Amazon EC2 - IaaS

Salesforce - SaaS

Google AppEngine - PaaS

with Chris Hoff and solo talks models by Chris Hoff

Page 38: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 39: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 40: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 41: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 43: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 44: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 45: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Control and Chaos ”World War 3.0” by Michael Joseph Gross

Vanity Fair - May 2012

Page 46: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Josh Corman & Jericho

BruCON 2012

Page 47: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 48: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Pick one: Make Excuses Make Progress

Page 49: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It
Page 50: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Countermeasures Situational Awareness Operational Excellence Defensible Infrastructure

Page 51: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Countermeasures Situational Awareness

Operational Excellence

Defensible Infrastructure

Page 52: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Countermeasures

Situational Awareness

Operational Excellence

Defensible Infrastructure

Page 53: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Countermeasures

Situational Awareness

Operational Excellence

Defensible Infrastructure

Page 54: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Knowledge Seeker Zombie Killer

Page 55: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Experimentation An untested hypothesis is a wish

Page 56: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Seeker

Page 57: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Unreasonable Fool

Page 58: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

THANK YOU My Collaborators My Teammates

Page 59: Why We Don't Know. What We Can Do About It. · Why We Don't Know. What We Can Do About It

Joshua Corman [Knowledge Seeker | Zombie Killer]

Twitter: @joshcorman

BLOG: http://blog.cognitivedissidents.com