<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/securitysoftware/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Following the White Rabbit Blog : Computer Security Institute</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/tags/Computer+Security+Institute/default.aspx</link><description>Tags: Computer Security Institute</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>CSI Annual Conference - Highlights on Web App Security</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2008/11/19/csi-annual-conference-take-aways-on-web-app-security.aspx</link><pubDate>Wed, 19 Nov 2008 04:00:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:86678</guid><dc:creator>RafalLos</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/securitysoftware/blogs/rafal/rsscomments.aspx?PostID=86678</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2008/11/19/csi-annual-conference-take-aways-on-web-app-security.aspx#comments</comments><description>&lt;p&gt;Listening to the speakers (yes, this time around I was a spectator only... sort of) and the audience from these past 2 days, and specifically at the Web 2.0 Security Summit here at &lt;a class="" title="CSI Annual Homepage" href="http://www.csiannual.com/" target="_blank"&gt;CSI Annual 2008&lt;/a&gt;... I&amp;#39;ve come up with a few things that I think you (the readers who may or may not have attended) should come away with.&amp;nbsp; These are important points, highlights from a very well organized conference geared towards &lt;strong&gt;actual solutions&lt;/strong&gt; rather than the &lt;em&gt;typical smoke, mirrors, and hand-waving&lt;/em&gt; [&lt;a class="" title="Security Spin Control" href="http://treyford.wordpress.com/" target="_blank"&gt;Trey Ford&lt;/a&gt;] you may expect from a security conferences.&amp;nbsp; A nod to Robert Richardson for the guest pass, and an excellent conference.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;From the experts&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div&gt;Threats &lt;em&gt;continue to escalate&lt;/em&gt; and get more clever in their attack&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Browsers cannot be trusted, applications can be compromised - this is not a rosy picture&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;End-user (and business) &amp;quot;push&amp;quot; is needed to help move browser&amp;nbsp;developers to produce more secure browsers&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;HTML-spec and standards are &lt;em&gt;actually working against&amp;nbsp;security&lt;/em&gt; in some cases (see: ClickJacking)&amp;nbsp;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Web applications are, and will continue to be, the prime target for attackers&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Few businesses are prepared to drive standardized security throughout their organization&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;&lt;em&gt;Metrics&lt;/em&gt; - good metrics collection and delivery is one of the secrets to making a security program work for you&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Process, services, secure coding tools, code analyzers/scanners and Web App Firewalls&amp;nbsp;&lt;em&gt;are not mutually exclusive&lt;/em&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Your business must have a short-term &lt;em&gt;tactical fix&lt;/em&gt; and long term &lt;em&gt;strategic plan&lt;/em&gt; to succeed&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Services and tools are maturing at a great rate - and businesses should understand the purpose of each&lt;/div&gt;&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div&gt;Tools&amp;nbsp;are a support mechanism for automation, standardization, and repeatability - they do not replace people&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Services allow for independent 3rd party verification (satisfying some regulatory and compliance requirements)&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Neither of the above will magically &amp;quot;make your applications secure&amp;quot;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;li&gt;
&lt;div&gt;SaaS (Software as a Service) for web app security provides immediate ROI, implementation, and won&amp;#39;t use up your CapEx (instead uses OpEx) spending&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;You can&amp;#39;t use the Ostrich approach (head in the sand, ignoring what&amp;#39;s around you)&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Right now, someone is hacking either your applications, your users or both&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;The bottom line from the experts?&amp;nbsp; &lt;strong&gt;The web is more dangerous than the wild-west; and things are going south fast.&amp;nbsp; There is hope.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;From the audience&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div&gt;Managers and practitioners alike are confused and disheartened when it comes to security ... specifically web application security&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Despite &lt;em&gt;wanting&lt;/em&gt; to do the right thing, managers facing insecure (or worse, unknown) web applications are finding it &lt;em&gt;difficult to implement&lt;/em&gt; a program&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Between integrations, acquisitions, and poor oversight security teams are struggling to keep up with the avalanche of published web apps&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Overwhelming numbers of vulnerabilities presents itself in a feeling of &amp;quot;we&amp;#39;re powerless, why not just give up&amp;quot; as one person put it...&amp;nbsp;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Managers are confused on where, when, and how to apply tools to web application security programs&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Some managers have their hands tied by long-term contracts with outsource developers which &lt;em&gt;do not&lt;/em&gt; properly include information security components&lt;/div&gt;&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div&gt;When code is finally turned over to them, are faced with checking the security of that code on their own&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;... that code, if found defective, will then require re-work &lt;em&gt;at their cost!&lt;/em&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Ineffective contractual obligations are making it impossible to have an effective security program&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;li&gt;
&lt;div&gt;Security metrics are typically a problem...&lt;/div&gt;&lt;/li&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div&gt;Some companies don&amp;#39;t know what metrics to collect&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;... others collect them and manually try to make sense of them&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;... still others have intelligent metrics but haven&amp;#39;t been able to translate them into actionable items yet&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;... still haven&amp;#39;t figured out how to take raw metrics and model them for upper-management consumption&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;li&gt;
&lt;div&gt;Security outsourced services are still too confusing&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Compliance is causing more headaches than it is solving&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Companies are striving to be compliant... but are &lt;em&gt;still terribly insecure&lt;/em&gt; - and managers are getting that but feel powerless to change&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;The bottom line from the audience?&amp;nbsp; &lt;strong&gt;Make security simple, actionable, and consumable for my organization... and do more than just sell me tools or services - help me build a program.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;font color="#ff0000"&gt;There is good news, and bad news.&lt;br /&gt;&amp;nbsp; The good news is that I feel very strongly that we (HP Application Security Center) can help you accomplish your goals.&lt;br /&gt;&amp;nbsp; &amp;nbsp; The bad news is ... it&amp;#39;s still going to be your job to sell it to your upper management and execute...&lt;/font&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=86678" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/tags/Computer+Security+Institute/default.aspx">Computer Security Institute</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/tags/CSI+Conference/default.aspx">CSI Conference</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/tags/web+application+security/default.aspx">web application security</category></item></channel></rss>