The Future of Security with Joe Gottlieb

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Notes on slide 1

    Vision OneEnable compliance for risk reductionIsolate security architecture changes and governance for servicesIntegrate more easily with detection engines for the open platformCo-locate security frameworks across multiple server instances on single hostsEnable more configurable and dynamic disaster recovery leading to easier business continuity planningVision TwoMaster prohibitive physical scale (~20,000 systems)Vision ThreeUsing cloud overlays for cloud environments will enable low-cost malware detection for cloud (enabled by virtualization) applicationsCloud services (e.g., McAfee Artemis) can protect virtualized application deploymentsCloud infrastructure can be lean and very fluid, using another cloud’s services for securityIncident response readiness is enabled with cloud security services to allow real-time monitoring of virtual-based application and infrastructure traffic

    Favorites, Groups & Events

    The Future of Security with Joe Gottlieb - Presentation Transcript

    1. Trends & Futures in Information Security
      Joe Gottlieb
      VP, Marketing & Business Development, SenSage
    2. The future of security is already being reshaped by…
      Metrics, but for what?
      Virtualization, but how?
      Cloud, but why?
      Integration & Automation, but when?
      Negotiations, but with whom?
    3. theVILLAINS…
      Digital Theft
      Heterogeneity
      Organizational Behavior
      Web 2.0
      Growth : )
      3
    4. so evolves theft
      4
      As value evolves…
      Age ofDigital Theft
      Age of Physical Theft
    5. Physical Reality (as we love it)
      5
      Server 1
      Server 2
      Physical Network
      Source: Securing Virtual Data Centers, Lynch et al, 10/9/09
    6. Virtual Reality 1.0
      6
      Physical Network
      Source: Securing Virtual Data Centers, Lynch et al, 10/9/09
    7. eBay & Virtualization
      Vision One – Reduce Risk
      Vision Two – Master Prohibitive Scale
      Vision Three – Leverage Cloud Computing
      7
      Source: Securing Virtual Data Centers, Lynch et al, 10/9/09
    8. New Age Currency
      8
      Source: The McAfee Vision for Total Data Protection, Watzinger et al, 10/9/09
    9. McAfee’s Prescription for Data Protection
      9
      Source: The McAfee Vision for Total Data Protection, Watzinger et al, 10/9/09
    10. McAfee Data Loss Prevention:Learning through Capture
      10
      Source: Eliminating Data Amnesia, Ahuja et al, 10/9/09
    11. “Compliance” is a loaded term…
      11
      Source: Reducing the Total Cost of Compliance, Cougias et al, 10/9/09
    12. McAfee alone must comply with…
      12
      Source: Reducing the Total Cost of Compliance, Cougias et al, 10/9/09
    13. Unified Compliance Framework
      13
      Source: Reducing the Total Cost of Compliance, Cougias et al, 10/9/09
    14. Tyco International Compliance Requirements
      14
      Source: Compliance Approaches in a Down Economy, Fredriksen et al, 10/9/09
    15. The Tyco (CISO’s Office) Response
      15
      Source: Compliance Approaches in a Down Economy, Fredriksen et al, 10/9/09
    16. GM’s Lynn Trent: The value of control…
      16
      Source: The Value of Control, Trent, 10/09
    17. Citrix Systems: Exciting New Challenges
      17
      Source: The True Cost of Free, La Bella et al, 10/09
    18. Citrix Systems: Protecting the Inner Perimeter
      18
      Source: The True Cost of Free, La Bella et al, 10/09
    19. Web 2.0: Conflict of Interest
      19
      Source: Web 2.0: Allow, Deny or Ignore?, Roddy et al, 10/09
    20. Koobface uses Twitter to attack…
      20
      Source: Web 2.0: Allow, Deny or Ignore?, Roddy et al, 10/09
    21. Social Networking Stats…
      21
      If access to social networking sites, such as MySpace and Facebook, is blocked, how would this impact your organization?
      Percentage of Company’s Bandwidth Consumed by Web 2.0 Applications
      Source: Web 2.0: Allow, Deny or Ignore?, Roddy et al, 10/09
    22. “Hi Mr. Credit Applicant…What is your reputation?”
      22
      Source: Intelligence to Predict, Protect, and Enable, Murphy et al, 10/09
    23. “Hi Mr. IP Address or URL…What is your reputation?”
      23
      Source: Intelligence to Predict, Protect, and Enable, Murphy et al, 10/09
    24. McAfee Firewall Enterprise (not your SMB UTM…)
      24
      IP & Web Reputation
      SmartFilter
      Includes File Reputation (Artemis)
      Source: The Future of Network Security, Brown et al, 10/9/09
    25. McAfee Global Threat Intelligence
      25
    26. Heartland …………
      26
      Source: Data Privacy and Security: Legal Trends and Developments, Organ, 10/09
    27. Heartland…
      Over 100 million consumers’ credit and debit cards were stolen.
      More than 650 institutions have been impacted by the Heartland data breach.
      The information was stolen by using malware uploaded onto Heartland’s systems
      Over 30 class actions have been filed against Heartland as a result of the breach
      According to Heartland CEO Bob Carr: “In the first half of 2009, we laid out $32 million and we don’t know what will happen going forward. We are aggressively defending against litigation. That’s all I can say.”-- August 12, 2009 interview with CSO Security and Risk
      27
      Source: Data Privacy and Security: Legal Trends and Developments, Organ, 10/09
    28. TJ Maxx…
      28
      Source: Data Privacy and Security: Legal Trends and Developments, Organ, 10/09
    29. Is law enforcement catching up yet?
      29
      Source: Data Privacy and Security: Legal Trends and Developments, Organ, 10/09
    30. How “optimized” is your security architecture?
      30
      Source: Fact or Fiction: Security Metrics Can Boost Compliance Efforts, Ross et al, 10/09
    31. Cost/Benefit of the Enterprise Security Maturity Model
      31
      Source: Fact or Fiction: Security Metrics Can Boost Compliance Efforts, Ross et al, 10/09
    32. Gartner Security Program Maturity, 2009
      32
      Source: Gartner Information Security Summit, London, 9/09
    33. The evolution of security…
      33
      Proactive
      More Talent,No Metrics
      Tomorrow’s GRC is Proactive Science
      Compliance as Excuse, Motivationor InspirationforMETRICS
      Science
      Art
      ComplianceRules
      Proud Legacy:SmartSecurityFolks
      Reactive
    34. What makes a good metric?
      34
      Source: Fact or Fiction: Security Metrics Can Boost Compliance Efforts, Ross et al, 10/09
    35. Ryder Truck…“Moved” by IT GRC
      35
      Source: Managing Risk While Enabling Compliance with Regulatory Mandates, Holt et al, 10/09
    36. Got heterogeneity?
      36
      Source: How Optimized Security Can Improve Your Business, Dover et al, 10/09
    37. McAfee Security Innovation Alliance
      Integration
      …Automation
      …Closed-loop Risk Management…
      DoD
      Citigroup
      Etc.
    38. Best-of-breed vs. One-stop-shop Biorhythm
      38
      Security Yield
      One-stop-shopDemi-trend
      Time
      Best-of-breedDemi-trend
    39. How much is enough Information Security?
      39
      Source: Fact or Fiction: Security Metrics Can Boost Compliance Efforts, Ross et al, 10/09
    40. SenSage is creating a new category
      40
      Deep Security Context
      Security Intelligence
      Traditional SIEM & Log Management Products
      Low Event Data Management Scalability
      High Event Data Management Scalability
      General Purpose Columnar Databases
      Traditional Data Warehouse Products
      No Security Context
    41. Do security companies exaggerate the threat?
      Yes
      But…
      Does your company hold digital value?
      Will your company’s brand suffer if you have a breach?
      What part of the addressable market do you represent?
      41
    42. Thank Youjoe.gottlieb@sensage.com
    SlideShare Zeitgeist 2009

    + TechColumbus OhioTechColumbus Ohio Nominate

    custom

    125 views, 0 favs, 1 embeds more stats

    Thought leader in enterprise security, Joe Gottlieb more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 125
      • 117 on SlideShare
      • 8 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 7
    Most viewed embeds
    • 8 views on http://www.techcolumbus.org

    more

    All embeds
    • 8 views on http://www.techcolumbus.org

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories