Thursday, May 31, 2012

The 7 Qualities of Highly Secure Software

We just published The 7 Qualities of Highly Secure Software by Mano Paul. Providing a framework for designing, developing, and deploying hack-resilient software, this book uses engaging anecdotes and analogies—from Aesop’s fables and athletics to architecture and video games—to illustrate the qualities needed for the development of highly secure software. Each chapter details one of the seven qualities that make software less susceptible to hacker threats. Filled with real-world examples, the book explains complex security concepts in language that’s easy to understand to supply readers with the understanding needed to building secure software.

This excerpt discusses the need for building security into software. Building security in is about proactively designing and developing appropriate security controls into the software. The quality of building security in that will result in highly secure software can be achieved by addressing the people, the process, and the technology components in the software engineering process.

Wednesday, May 23, 2012

86% Say No to ‘Dial High Club’: Travellers against Phones on Planes

Well, travellers are apparently on the side of sanity and good sense. I know it's too much to expect the same from carriers. Just because you're able to do something, doesn't mean you should. We can only hope that they somehow require access charges as they do with WiFi, and that the charges are exorbitant. At least there's a "quiet car" on my commuter train, although it should be just one "loud" car, leaving the rest of us in peace and contemplation. "Make the pain go away!"

Friday, May 18, 2012

"Loaphobia." I wonder what the Diagnostic and Statistical Manual of Mental Disorders says about this?

Loaphobia (Lack-of-Application-Phobia), I learned today, is fear in the workforce of not being able to hit deadlines, missing promotions, or losing their jobs due to inabilty to access an applicatoin. This fear is apparently well founded because recent research found that 19% have missed a critical deadline as a result of being denied full access to an application, 14% lost a job and 6% missed a promotion. Just when you thought it was safe to close your eyes and sleep at night.

Thursday, May 10, 2012

Just Say No?

It wasn't easy to do when Nancy Reagan wanted kids to reject peer-pressure to try drugs, and it's apparently even harder to say no to users intent on BYOD.

The same people who want to create more security threats now want more security. I wonder what they'll think about more security when it'll require installation management software on their digital toys, and maybe have to submit to intense awareness training?

Monday, April 30, 2012

Patch Management the Easy Way

by Casper Manes on behalf of GFI Software Ltd.

Patching is one of the most critical system admin activities, but it is also one of the most frequently neglected. The stated reasons may vary, but usually come down to a simple lack of patch management strategy, and an application to make patching easy. To get from bad/non-existent patching strategy to sound and successful patch management strategy, like so many others, starts with a single step.

Decide patch management is important
IT needs to patch, but they also have to want to patch. It’s far too easy to push patching off, especially when most patches require reboots, and no one wants to stay up until 3AM on a Saturday. Security needs to patch, since many exploits take advantage of flaws that have been patched. Management needs to patch since patched systems are more stable and reliable, and have better performance against SLAs. Everybody knows patching is important, so you all need is to agree to it, and senior management needs to support that. With senior management support’s go ahead, the rest of the steps are easy.

Implement a patch management solution
That senior management support must include funding for a patch management solution. One of the biggest reasons why patching is so painful to many is because they try to do it manually, or with a combination of Windows Server Update Services (WSUS) and scripts, or other home-grown solutions. A good patch management solution can automate all the work, letting you approve and schedule patching, and then just check on status when it’s done.

Include third-party applications
Patching operating systems, but not third-party applications, is like locking all the windows and leaving the front door open. It’s the applications that are what the users interact with, and that process data submitted from the web, and these must be patched just as diligently as your operating systems. Good patch management solutions can patch third party apps just as easily as operating systems.

Commit to testing
The vendors do a lot to test their patches, but ultimately it is your responsibility to test patches before deploying them. Testing requires users to run patches on their workstations, and on test versions of your application servers, and to run things through their paces to ensure there are no issues. Senior management needs to allocate resources to perform this testing each month. Your patch management app should be able to deploy patches to a set of test machines to make it easier to evaluate patches before pushing them to all of production.

Have a way to rollback
Even with testing it’s possible to encounter an issue with a patch, so make sure your patch management solution can automate the rollback of a patch.

Assess, log, report and audit
The biggest risk with manually patching is that something will be missed. Patch management applications should be able to assess all systems, log all patching, generate scheduled and on-demand reports, and you need to audit these to ensure all machines are patched and compliant.

Respect the window
Establish a patching window and make sure everyone knows what that is. Make that window one that takes priority over other actions, and set the expectation that the business will have to work around patching, and not vice-versa. Again, you will need senior management support to get this through, but you don’t want to delay critical security patches just because the marketing team wants to update the content of the website.

Patch with confidence
With a good patch management application, the support of senior management, a sound testing plan, and windows where you are able to patch, proceed with confidence. Patching is a good thing and shouldn’t be a cause of pain or suffering. Leave that for when patches are missed, because it’s a safe bet that if you miss a critical patch, the pain and suffering will come.

If your IT organization and senior management see that patching is important, advocate patching within the organization, allocate a modest amount of resources to patching, and then set the expectation that patching will be done, you will soon find that patching is a normal and easy part of systems administration activities. Take that first step with your patch management process and you will be well on your way.

For more on patch management, see Security Patch Management.

Tuesday, April 24, 2012

Tech groups push for cyberthreat information-sharing bill. Great idea. It's worked real well with Federal agencies.

So, now industry wants Congress to legislate what it won't do volunarily. So far, there's as much trust between companies as there is between government agencies. They're all willing for a one-way exchange. This isn't going to change in government, and it won't in industry. Which reminds me. Didn't Congress legislate sharing between agencies? That's working real well, isn't it.

Monday, April 23, 2012

Mac trojan fallout: Apple security glory days gone?

There are cults in IT. UNIX is one; Macs is another. These cultists fervently believe their OS is superior to others, and, by extension, they're superior to everyone else.

When it comes to vulnerability to attacks, though, UNIX was always an easy target. Macs are so safe and secure. Of course, until recently there weren't many of them, and they weren't in the enterprise, and so they were not as attractive a target as, say, Windows. Now that there are more Macs, making them an attactive target, the myth is staring to explode. Still, zealots being zealots, all's right in their world. Koolaid anyone?