<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risk Management and Compliance&#187; breach data</title>
	<atom:link href="http://blog.kraasecurity.com/tag/breach-data/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.kraasecurity.com</link>
	<description>Risk Assessment, Vulnerabilities, Website Security</description>
	<lastBuildDate>Wed, 26 May 2010 02:45:39 +0000</lastBuildDate>
	<generator>http://wordpress.org/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Web Security Testing has come of age</title>
		<link>http://blog.kraasecurity.com/2009/07/20/web-security-testing-has-come-of-age/</link>
		<comments>http://blog.kraasecurity.com/2009/07/20/web-security-testing-has-come-of-age/#comments</comments>
		<pubDate>Tue, 21 Jul 2009 04:30:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Corporate Stupidity]]></category>
		<category><![CDATA[breach data]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hipaa security]]></category>
		<category><![CDATA[web security]]></category>
		<category><![CDATA[Website security]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/?p=86</guid>
		<description><![CDATA[Website security is the one of the most dangerous places for a company. If you look at a layered security approach, we start out with the internal network. There we have host security, patch management, host IDS and other server based technologies. Next we have the network security layers, network intrusion detection, network monitoring and [...]]]></description>
			<content:encoded><![CDATA[<p>Website security is the one of the most dangerous places for a company. If you look at a layered security approach, we start out with the internal network. There we have <strong>host security, patch management, host IDS </strong>and other server based technologies. Next we have the network security layers,<strong> network intrusion detection, network monitoring and firewall</strong> protection. So if we have the internal servers secured, the network protection place, what is left is that an attacker can possibly get into a secure environment?</p>
<p>The website is the open frontdoor to many companies. <strong>Security education</strong> for both the developers of website applications and the users of web sites is sadly lacking. If we look at most of the compliance regulations such as <strong>HIPAA </strong>or <strong>PCI</strong>, there is a component of education required, but most companies do not spend the time to provide more than a written manual that no one reads. In those same regulations, there are requirements for a <strong>Secure Development Lifecycle</strong> strategy, but how many web application developers actually follow a strict methodology?</p>
<p>So on Linkedin, I asked the quesion &#8220;what are the Web security tools&#8221; that are favored by the security community (<a href="http://www.linkedin.com/gbaha">www.linkedin.com/gbaha</a>). These can provide some help and insight for those looking to conduct some security testing. Some are paid and some are free. Here is the list in no particular order.</p>
<p>1) Foundstone             http://<a href="http://www.foundstone.com">www.foundstone.com</a><br />
2) Acunetix WVS        http://<a href="http://www.acunetix.com">www.acunetix.com</a><br />
3) Scrawlr                      <a href="https://h30406.www3.hp.com/">https://h30406.www3.hp.com/</a><br />
4) N-Stalker                  http://<a href="http://www.nstalker.com/">www.nstalker.com/</a><br />
5) Nikto                          <a href="http://cirt.net/nikto2">http://cirt.net/nikto2</a><br />
6) Scarab                       <a href="http://www.owasp.org">http://www.owasp.org</a><br />
7) WebInspect            http://<a href="http://www.hp.com">www.hp.com</a><br />
 <img src='http://blog.kraasecurity.com/wp-includes/images/smilies/icon_cool.gif' alt='8)' class='wp-smiley' /> Fiddler -                   http://<a href="http://www.fiddlertool.com">www.fiddlertool.com</a><br />
9) Samurai Web Testing Framework &#8211; <a href="http://samurai.inguardians.com/">http://samurai.inguardians.com/</a><br />
10) FireCAT -               http://<a href="http://www.security-database.com">www.security-database.com</a><br />
11) W3af                         <a href="http://w3af.sourceforge.net/">http://w3af.sourceforge.net/</a><br />
12) CORE Impact        <a href="http://www.coresecurity.com/content/web-app-pro">http://www.coresecurity.com/content/web-app-pro</a><br />
13) Appscan                 <a href="http://www-01.ibm.com/software/awdtools/appscan/">http://www-01.ibm.com/software/awdtools/appscan/</a></p>
<p>Having listed these and of course there a re a number of other tools, we can begin to secure the environment. (Please send me any comments on other tools you like). Running a tools is a first and easy step you can take to close that open web door (Webdoor, I am going to try and coin that phrase). If you can target tactical prablems, get them fixed quickly, you can then tackle the strategic problems that led to your web vulnerabilities.</p>
<p>The basic steps you want to take in website security are:<br />
1) Vulnerability testing<br />
2) Secure Code Review<br />
3) Architecture review<br />
4) Monitoring and Logging<br />
5) Consistent Testing (monthly) and Validation of Controls</p>
<p>Do not get lax when it comes to Web security. Its a bit black magic and a lot of hard work but as its the &#8220;webdoor&#8221; try and keep it closed.</p>
<p>Gary Bahadur</p>
<p><a href="mailto:baha@kraasecurity.com">baha@kraasecurity.com</a></p>
<p><a href="http://www.kraasecurity.com">http://www.kraasecurity.com</a></p>
<p><a href="http://blog.kraasecurity.com">http://blog.kraasecurity.com</a></p>
<p><a href="http://twitter.com/kraasecurity">http://twitter.com/kraasecurity</a></p>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" src="http://img.zemanta.com/pixy.gif?x-id=050a75a1-022d-8f14-a07a-0b5aef9c2026" alt="" /></div>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 101px; width: 1px; height: 1px;"><!-- 		@page { margin: 0.79in } 		P { margin-bottom: 0.08in } 		A:link { so-language: zxx } --><span style="background: #ffff00 none repeat scroll 0% 0%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;">S</span><span style="text-decoration: none;"><span style="font-family: Arial,sans-serif;"><span style="font-size: x-small;"><span style="font-style: normal;"><strong><span style="background: #ffff00 none repeat scroll 0% 0%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;">ecurity penetration test</span></strong></span></span></span></span><span style="text-decoration: none;"><span style="font-family: Arial,sans-serif;"><span style="font-size: x-small;"><span style="font-style: normal;"><strong> (</strong></span></span></span></span><span style="color: #000080;"><span lang="zxx"><span style="text-decoration: underline;"><a href="http://www.kraasecurity.com/freewebsitetest"><span style="text-decoration: none;"><span style="font-family: Arial,sans-serif;"><span style="font-size: x-small;"><span style="font-style: normal;"><strong>http://www.kraasecurity.com/freewebsitetest</strong></span></span></span></span></a></span></span></span><span style="text-decoration: none;"><span style="font-family: Arial,sans-serif;"><span style="font-size: x-small;"><span style="font-style: normal;"><strong>)</strong></span></span></span></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/07/20/web-security-testing-has-come-of-age/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Breaches are still misunderstood</title>
		<link>http://blog.kraasecurity.com/2009/07/19/data-breaches-are-still-misunderstood/</link>
		<comments>http://blog.kraasecurity.com/2009/07/19/data-breaches-are-still-misunderstood/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 04:27:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Corporate Stupidity]]></category>
		<category><![CDATA[Security Assesment]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[breach data]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[security metrics]]></category>

		<guid isPermaLink="false">http://blog.kraasecurity.com/2009/07/19/data-breaches-are-still-misunderstood/</guid>
		<description><![CDATA[The Ponemon Institute and Ounce Labs (www.ouncelabs.com) released a study on the view CEOs have regarding data protection in their environment. In the study of 213 CEOs and other senior executives, CEOs did not share the same view on how secure their organization is with their executives. 92 percent of respondents said they were attacks. [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">The <strong>Ponemon Institute</strong> and Ounce Labs (<strong>www.ouncelabs.com</strong>) released a study on the view CEOs have regarding data protection in their environment. In the study of 213 CEOs and other senior executives, CEOs did not share the same view on how secure their organization is with their executives. 92 percent of respondents said they were attacks. Who has the more realistic view of data security? Could it also be the fault of the executives who usually do not share all the bad information with the CEO? That is probably part of the security education challenge the CEO faces.<span>  </span></span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">The study also found that 33 percent of C-level executives replied that attacks happened &#8220;hourly or more often,&#8221; while only 17 percent of CEOs said the same thing. That’s a pretty big difference of opinion. Whose responsibility is it to manage, monitor and report on hacker activity? Obviously tactically speaking it fall under IT, the CIO or maybe even the Chief Compliance Officer. But ultimate responsibility in any company falls to the CEO. If a data breach happens such as in the case of TJ Max, it&#8217;s the CEO who has to appear on television to explain what happened and answer to their customers.</span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">How do you apply <strong>security metrics</strong> to report appropriately to the CEO? That magic &#8220;Dashboard&#8221; is what everyone is after and no one gets right. A good Compliance dashboard that you may want to check out comes with the reports from RiskWatch software (www.riskwatch.com). Its worth a look.</span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">The category of technology CEO&#8217;s need to focus on these days is Data Loss Prevention (DLP). Every major company in security has a DLP product and the reason is probably because the education is finally in the market around the necessity of looking at all inputs and output of data in the organization. A data breach can be caused by lack of proper <strong>firewalls</strong>, no <strong>antivirus</strong>, no <strong>browser protection,</strong> not malware protection, lack of <strong>patch management</strong> or no <strong>vulnerability management</strong>. Or it could be a hundred other things. A CEO needs to know these terms, how data flows and what the data life cycle really means if they are to truly grasp the threat to their environment. </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;">Prevention is really worth more than detection. If the CEO doesn’t bridge the gap to thinking they might be secure to understanding that they are under attack ever day and perhaps every minute, data breached will continue to occur.<br />
</span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"> </p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><!--  /* Font Definitions */ @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-alt:HigherStandards-Light; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} span.EmailStyle15 	{mso-style-type:personal; 	mso-style-noshow:yes; 	mso-style-unhide:no; 	mso-ansi-font-size:11.0pt; 	mso-bidi-font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi; 	color:windowtext;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --></p>
<p class="MsoNormal"><span>Gary Bahadur</span></p>
<p class="MsoNormal"><span>CEO KRAA Security,  <span style="color: #c0504d;"><a href="mailto:baha@kraasecurity.com"><span style="color: blue;">baha@kraasecurity.com</span></a></span></span></p>
<p class="MsoNormal"><strong><span><a href="http://www.kraasecurity.com/"><span style="color: blue;">http://www.kraasecurity.com</span></a></span></strong></p>
<p class="MsoNormal"><strong><span>http://blog.kraasecurity.com</span></strong></p>
<p class="MsoNormal">http://twitter.com/kraasecurity<br />
<strong><span> </span></strong></p>
<p class="MsoNormal"><span style="color: #c00000;">*Managed Security Services</span></p>
<p class="MsoNormal"><span style="color: #c00000;">*Vulnerability Management</span></p>
<p class="MsoNormal"><span style="color: #c00000;">*Compliance &amp; Policy Development</span></p>
<p class="MsoNormal"><span style="color: #c00000;">*PGP Security</span></p>
<p class="MsoNormal"><span style="color: #c00000;">*FREE Website Security Test</span></p>
<p><span style="font-size: 10pt; font-family: &quot;Arial&quot;,&quot;sans-serif&quot;;"> </span></p>
<p>Technorati Tags: <a class="performancingtags" rel="tag" href="http://technorati.com/tag/data%20breach">data breach</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/data%20loss">data loss</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.kraasecurity.com/2009/07/19/data-breaches-are-still-misunderstood/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
