from the pillory to the joneses using peer pressure to improve your security kpis :: metricon 6.5

62
From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs Bob Rudis & Albert Yin Mini-Metricon 6.5 February 27, 2012 1 Thursday, January 24, 13

Upload: bob-rudis

Post on 01-Nov-2014

1.525 views

Category:

Documents


0 download

DESCRIPTION

There is a natural human desire to both not be punished as well as to covet that which thy neighbor has (hence the existence of the well known "thou shalt not…" Commandment). Humans also strongly desire to be rewarded for the accomplishments they make but at the same time would like to be as anonymous as possible. With such diverse characteristics, how could one possibly use something like security metrics to change/channel the right behaviours? Since the most effective metrics programs have a measurable, reportable resulting action component, the way in which this is carried out must be designed in up-front. Given the limited resources in business units and IT areas, this design should focus on the most critical areas first and shift focus as progress is made in individual KPIs. To that end, we present an approach that has an element of the medieval gallows (i.e. shame) as well as an element of "keeping up with the Joneses" (i.e. competition) to improve the effectiveness of concrete risk, security & compliance program goals/controls. We will demonstrate real-world improvements made in the area of policy/standard exceptions as well as anti-virus infections and propose other concrete areas organizations of all sizes can work on in 2012 & beyond to drive critical improvements in their programs.

TRANSCRIPT

Page 1: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

From The Pillory To The JonesesUsing Peer Pressure To Improve Your Security KPIsBob Rudis & Albert Yin

Mini-Metricon 6.5February 27, 2012

1Thursday, January 24, 13

Page 2: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

2Thursday, January 24, 13

Page 3: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

http://www.historicalstockphotos.com/images/xsmall/1971_people_locked_in_a_pillory_while_awaiting_witch_trials.jpgUsed With Permission

2Thursday, January 24, 13

Page 4: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

3Thursday, January 24, 13

Page 5: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

http://gentlemanredux.com/blog/2011/11/24/keeping-up-with-the-joneses/Used With Permission

3Thursday, January 24, 13

Page 6: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

4Thursday, January 24, 13

Page 7: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

I know you all know this…

4Thursday, January 24, 13

Page 8: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

5Thursday, January 24, 13

Page 9: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

But, it’s worth repeating…

5Thursday, January 24, 13

Page 10: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

6Thursday, January 24, 13

Page 11: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

Metrics are supposed to be…

6Thursday, January 24, 13

Page 12: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

7Thursday, January 24, 13

Page 13: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

Getty Images :: “Comping” & Preview Use License

7Thursday, January 24, 13

Page 14: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

8Thursday, January 24, 13

Page 15: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

NBC News Footage :: Fair Use

8Thursday, January 24, 13

Page 16: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

How To Pick An Area Of Focus

9Thursday, January 24, 13

Page 17: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

How To Pick An Area Of Focus

Do you even have data for it?

9Thursday, January 24, 13

Page 18: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

How To Pick An Area Of Focus

Do you even have data for it?

Is that data easy to get on a regular basis?

9Thursday, January 24, 13

Page 19: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

How To Pick An Area Of Focus

Do you even have data for it?

Is that data easy to get on a regular basis?

Can you trust the data?

9Thursday, January 24, 13

Page 20: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

How To Pick An Area Of Focus

Do you even have data for it?

Is that data easy to get on a regular basis?

Can you trust the data?

Is it an area you can measure consistently over time?

9Thursday, January 24, 13

Page 21: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

How To Pick An Area Of Focus

Do you even have data for it?

Is that data easy to get on a regular basis?

Can you trust the data?

Is it an area you can measure consistently over time?

Is it actually going to help reduce risk in your environment?

9Thursday, January 24, 13

Page 22: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

Candidate #1 : Policy Exceptions

10Thursday, January 24, 13

Page 23: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

Candidate #1 : Policy Exceptions

We (Enterprise Security) controlled the process & data

10Thursday, January 24, 13

Page 24: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

Candidate #1 : Policy Exceptions

We (Enterprise Security) controlled the process & data

Policy exceptions inherently introduce risk into the environment, hence a great target to focus on

10Thursday, January 24, 13

Page 25: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

Original

11Thursday, January 24, 13

Page 26: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

Original

WORTHLESS

(Mostly)

11Thursday, January 24, 13

Page 27: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

12Thursday, January 24, 13

Page 28: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

“So what?”

12Thursday, January 24, 13

Page 29: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

13Thursday, January 24, 13

Page 30: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

No consequences…

13Thursday, January 24, 13

Page 31: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

14Thursday, January 24, 13

Page 32: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

14Thursday, January 24, 13

Page 33: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

New & Improved

15Thursday, January 24, 13

Page 34: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

New & Improved

15Thursday, January 24, 13

Page 35: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

New & Improved

ComparisonOver Time

15Thursday, January 24, 13

Page 36: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

New & Improved

ComparisonOver Time Aligned To

Risk

15Thursday, January 24, 13

Page 37: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

New & Improved

16Thursday, January 24, 13

Page 38: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

New & Improved

16Thursday, January 24, 13

Page 39: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

New & Improved

Show The Trend!

16Thursday, January 24, 13

Page 40: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

New & Improved

Show The Trend!

Focus On Risk!

16Thursday, January 24, 13

Page 41: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

New & Improved

Show The Trend!

Focus On Risk!

16Thursday, January 24, 13

Page 42: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

New & Improved

Show The Trend!

Focus On Risk!

16Thursday, January 24, 13

Page 43: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

17Thursday, January 24, 13

Page 44: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

18Thursday, January 24, 13

Page 45: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

http://www.geograph.org.uk/photo/630105Attribution-NonCommercial-ShareAlike 2.0 Generic (CC BY-NC-SA 2.0)

18Thursday, January 24, 13

Page 46: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

19Thursday, January 24, 13

Page 47: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

http://hyperboleandahalf.blogspot.com/Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 United States License

19Thursday, January 24, 13

Page 48: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

What Did It Take?

20Thursday, January 24, 13

Page 49: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

What Did It Take?

~6 months

20Thursday, January 24, 13

Page 50: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

What Did It Take?

~6 months

Constant contact with SBUs

20Thursday, January 24, 13

Page 51: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

What Did It Take?

~6 months

Constant contact with SBUs

Tons of documentation

20Thursday, January 24, 13

Page 52: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

What Did It Take?

~6 months

Constant contact with SBUs

Tons of documentation

Senior management visibility & support

20Thursday, January 24, 13

Page 53: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

What are next candidates?

21Thursday, January 24, 13

Page 54: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

What are next candidates?

Repeat virus offenders per-SBU, per-month

21Thursday, January 24, 13

Page 55: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

What are next candidates?

Repeat virus offenders per-SBU, per-month

“So what?” => What are these folks doing to keep getting infected? Do the infected users handle/have access to sensitive data? (Loss of Integrity/Confidentiality)

21Thursday, January 24, 13

Page 56: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

What are next candidates?

22Thursday, January 24, 13

Page 57: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

What are next candidates?

# Windows 7 Systems Deployed &% With Encryption Enabled (per SBU)

22Thursday, January 24, 13

Page 58: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

What are next candidates?

# Windows 7 Systems Deployed &% With Encryption Enabled (per SBU)

“So what?” => Primary Concern Of Corporate Legal & OCC (safe harbor loss); Doing a migration to Win 7 and off of competing technology at same time

22Thursday, January 24, 13

Page 59: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

What are next candidates?

23Thursday, January 24, 13

Page 60: From The Pillory To The Joneses Using Peer Pressure To Improve Your Security KPIs :: Metricon 6.5

What are next candidates?

Internet-facing Vulnerability/Pen-test Metrics(per SBU)

23Thursday, January 24, 13