Thursday, January 29, 2009

Security Perspectives

I think I have come upon a realization that has probably hit everyone else but me before this. I have come to understand why security is so difficult for most organizations to do right. It has to do with perspective.

I had the opportunity to be involved with a couple of security assessments recently. My role, for a number of reasons, was limited. Two other consultants did most of the heavy lifting; one who spends most of his time in the network world and the other focuses mostly in systems (Microsoft, etc.). The work they did was excellent but...

The network portion focused included detailed information about the environment starting at the the physical design and proceeding up through the OSI model covering spanning tree, HSRP, route propagation, network segmentation, ACLs, monitoring and more - all of which were a mess. The systems portion covered the AD schema, users and groups, forests, domains and OUs, Exchange, group policy objects, DNS, DHCP and server hardening - most of which were a mess. The document then provided a bunch of fantastic recommendations for remediation. This is all good but I think it misses the point.

I look at some of my colleagues in the security industry - people who I look up to and admire greatly. They are awesome at penetration testing, intrusion detection, web application hacking, vulnerability discovery, malware analysis and exploit development. I find myself wanting to be as good, as skilled, as 31337 as them. That said, does some of that focus miss the point as well?

Security is hard. Each individual component is hard and there are a lot of them - patch management, change control, hardening, monitoring, incident resposne, education, policy development, penetration testing, vulnerability research, tool development, malware analysis and the list goes on and on. Security is also only as strong as its weakest link (excuse the cliche). An organization can have the best technical security on the planet to include fantastic patch management, excellent hardening, outstanding monitoring, etc. If users, because of the lack of education, give the bad guys the keys it all can be rendered useless. An organization may have everything covered - outstanding security in every respect but all of that expertise resides in the heads of employees - no documented policies, standards, etc. This means that the level of excellence is only as good as the focus applied. If the organization changes priorities, will security remain consistent. If key people leave, will their effectiveness leave with them.

This now brings me to my point (finally). Truly effective security is a process (yes another cliche). That process has to involve everyone working together and should be focused on identifying risk and mitigating it to an acceptable level. It is easy to find a book or class on individual aspects of security. I'm sitting at my desk right now and can see books on web application penetration testing, Google hacking, wireless security and security assessment. I can jump online and find courses that cover Windows security, firewalls, IDS, penetration testing and literally hundreds of other similar topics. This wealth of resources points out to me what's missing.

Where are the books on developing a complete program to manage risk?

Where is the class on determining if risk is acceptable for my organization?

Where can I learn to balance security and functionality in five easy steps?

How do I accomplish the levels of protection, detection, responsiveness and ability to recover I need to have with a limited staff?

Technology is easy when compared to the issues that can truly make or break security. Am I right about this or am I missing something? If I am right, what can we do to fix it? What are the skills needed to do security correctly?

No comments:

Post a Comment