Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
How to Gain Visibility and Control: Compliance Mandates, Security Threats and Data Leaks by Dr. Anton Chuvakin
1. How to Gain Visibility and Control:Compliance Mandates, Security Threats and Data Leaks Dr. Anton Chuvakin Security Warrior Consulting www.securitywarriorconsulting.com Nov 2009
2. Outline Threats: From Hackers to Auditors What’s in Common? Accountability! Log Management for Accountability, Visibility and Control “Compliance“+”: Many Uses for Logs When Incident Strikes Conclusions
36. Congressional Hearing: Subcommittee on Emerging Threats, Cybersecurity and Science and Technology April 2008 http://geer.tinho.net/geer.housetestimony.070423.txt “In a free country, you don't have to ask permission for much of anything, but that freedom is buttressed by the certain knowledge that if you sufficiently screw things then up you will have to pay.” Daniel Geer, Sc.D.
37. Why Logs for Accountability Everybody leaves traces in logs! Potentially, every action could be logged! Control doesn’t scale, accountability (=logs!) does! More controls -> more complexity -> less control! The only technology that makes IT users (legitimate and otherwise) accountable:logging!
38. Control vs Visibility Myth: Stringent access controls will stop all attacks! What about those that have legitimate access? What about those who “break the rules”? The only control you can get is based on visibility and accountability!
39. Corporate Accountability Accountability Accountability is answerability, enforcement, responsibility, blameworthiness, liability Log Management Log management is collecting, retaining and analyzing audit trails across the organization There is a strong link between accountability and logging Big Picture: Logs as Enabler of Corporate Accountability
55. 11% 82% 8% 14% 77% 9% 17% 74% 9% 15% 73% 12% 15% 69% 16% 19% 66% 15% 17% 66% 17% 24% 54% 22% 22% 51% 28% Security detection and remediation Security analysis and forensics Monitoring IT controls for regulatory compliance Troubleshooting IT problems Monitoring end-user behavior Service level/performance management Configuration/change management Monitoring IT administrator behavior Capacity planning Business analysis 7% 90% 2% 0% 10% 20% 30% 40% 50% 60% 70% 80% 90% 100% (Percentage of respondants, N = 123) Yes, we use SIM technologies for this today No, we don’t use SIM technologies for this today, but plan or would like to do so in the future No, we don’t use SIM technologies for this today and have no plans to do so Source: Enterprise Strategy Group, 2007 Use Cases for Log Data Continue to Expand Does your organization use log management for any of the following?
56. “Compliance+” Model At Work You bought it for PCI DSS You installed it Your boss is happy Your auditor is … gone What are you going to do next?
57. Get More Info! “PCI Compliance” by Anton Chuvakin and Branden Williams www.pcicompliancebook.info Useful reference for merchants, vendors – and everybody else Out in December 2009!
58. “Compliance+” Model At Work You bought it for PCI DSS You installed it Your boss is happy Your auditor is … gone What are you going to do next?
59. Frequent First Use of Logs Logs for Incident Response Priorities: Have response process! Have logging enabled Have logs centralized Have logs searchable Have logs “baselined”
60. Conclusions In today’s complex IT, the only control comes from visibility and accountability Logs and log management is what enables it across all systems Start logging – then start collecting logs – then start reviewing and analyzing logs Prepare for incidents by deploying log management system!
61. Questions Dr. Anton Chuvakin Email:anton@chuvakin.org Google Voice: 510-771-7106 Site:http://www.chuvakin.org Blog:http://www.securitywarrior.org LinkedIn:http://www.linkedin.com/in/chuvakin Twitter:@anton_chuvakin Consulting: www.securitywarriorconsulting.com
62. More on Anton Book author: “Security Warrior”, “PCI Compliance”, “Information Security Management Handbook”, “Know Your Enemy II”, “Hacker’s Challenge 3”, etc Conference speaker: SANS, FIRST, GFIRST, ISSA, CSI, Interop, many, many others worldwide Standard developer: CEE, CVSS, OVAL, etc Community role: SANS, Honeynet Project, WASC, CSI, ISSA, OSSTMM, InfraGard, ISSA, others Past roles: Researcher, Security Analyst, Strategist, Evangelist, Product Manager, Consultant
63. Security Warrior Consulting Services Logging and log management policy Develop logging policies and processes, log review procedures, workflows and periodic tasks as well as help architect those to solve organization problems Plan and implement log management architecture to support your business cases; develop specific components such as log data collection, filtering, aggregation, retention, log source configuration as well as reporting, review and validation Customize industry “best practices” related to logging and log review to fit your environment, help link these practices to business services and regulations Help integrate logging tools and processes into IT and business operations Content development Develop of correlation rules, reports and other content to make your SIEM and log management product more useful to you and more applicable to your risk profile and compliance needs Create and refine policies, procedures and operational practices for logging and log management to satisfy requirements of PCI DSS, HIPAA, NERC, FISMA and other regulations More at www.SecurityWarriorConsulting.com
Notas del editor
Title: How to Gain Visibility and Control over Compliance Mandates, Security Threats and Data LeaksData integrity and confidentiality is critical. 62% of fraud is committed by insiders. Downtime is measured in millions of dollars per minute. Constant security threats and intense scrutiny by regulators and auditors require complete visibility and accountability, both in real-time and historically. Organizations face significant risks and exciting rewards during this period of economic and regulatory change.To meet the growing demands, you need to make a shift from worrying about the unknown to gaining a visibility and control over your operational threats. Top organizations are effectively managing their security threats and compliance requirements by building a foundation for internal investigations, forensics, and compliance that allows them to correlate information and detect real-time threats and fraud. By building pre-defined response plans they are able to significantly reduce the costs of managing network security and firewall policies. During this session we will cover how you can leverage the logs that you are already collecting to achieve regulatory compliance, protect valuable customer information and improve the efficiency of your IT operations team. This webcast will also feature a real world case study.(*) How to easily and cost-effectively automate your log management(*) How Log Management can be used to achieve compliance(*) How to protect valuable customer data(*) Best practices and tips for simplifying your life----I would like you to focus on the problem:(*) Data integrity and confidentiality is critical.(*) Constant security threats and intense scrutiny by regulators and auditors require complete visibility and accountability, both in real-time and historically.What organizations need to do:(*) To meet the growing demands, you need to make a shift from worrying about the unknown to gaining a visibility and control over your operational threats.(*) effectively managing the security threats and compliance requirements by building a foundation for internal investigations, forensics, and compliance that allows them to correlate information and detect real-time threats and fraud.(*) By building pre-defined response plans they are able to significantly reduce the costs of managing network security and firewall policies.=====We are trying to highlight all we do.This is infosec us audience====I'll be looking for a PPT presentation of between 12 and 20 slides, plus a spoken word preso of about 20 minutes from you - for submission one week ahead of the event itself - so can I suggest close of business on 01 December please?