Thanks to all the people that contacted me with interest on how HP Labs has applied HP Security Analytics techniques for Risk Analysis in the context of Incident Management Processes. I would like to remind that this HP Labs capability (along with related technologies and know-how) have now been transferred to HP Enterprise Security Services (HP ESS). Please feel free to contact HP ESS representatives if you would like to use the service.
An example of the benefits and risk assessment capabilities that can be achieved with Security Analytics (specifically in the space of Security Operation Centers and their Incident Management Processes) has been docuemented in a recent HP Labs Technical Report has been recently called “Security Analytics – Risk Analysis for an Organisation’s Incident Management Processes”:
“This document is an example of the type of report an organisation would receive at the end of a HP Security Analytics engagement. The focus is on the analysis of the security risks and performance of the organisation’s Security Incident & Events Management (SIEM) Processes and related Security Operation Centre (SOC)’s activities. HP Labs carried out the underlying R&D work in collaboration with HP Enterprise Security Services and involved analysis of processes, probabilistic modeling, simulation and “what-if” analysis for some of HP’s key customers. The outcome of this was a set of case studies from which we have been able to create this more general anonymised report illustrating the richness of the risk assessment and “what-if” analysis that has been carried out.
The lifecycle management of security is critical for organisations to protect their key assets, ensure a correct security posture and deal with emerging risks and threats. It involves various steps, usually carried out on an ongoing, regular basis, including: risk assessment; policy definition; deployment of controls within the IT infrastructure; monitoring and governance. In this context, Security Incident & Events Management play a key role. Even the best information security practices and investments in security controls cannot guarantee that intrusions – accidental and criminal activities – and/or other malicious acts will not happen. Controls can fail, be bypassed or become inadequate over time; new threats emerge. Managing such incidents requires detective and corrective controls to minimise adverse impacts, gather evidence, and learn from previous situations in order to improve over time. These incident management processes are usually run in the context of a SOC and/or as part of specialised Computer Security Incident Response Teams (CSIRTS), built on top of SOCs.
Even with SIEM in place, a potential major risk for the organisation arises due to delays introduced in assessing and handling known incidents: this may postpone the successful resolution of critical security incidents (e.g. devices exposed on the Internet, exploitation of privileged accounts, deployed malware, etc.) and allow for further exploitation. Another related risk can be introduced by sudden and/or progressive changes of the threat landscape, due to changing economic and social scenarios, new business activities or process failings within the existing IT services. This might create unexpected volumes of new events and alerts to be processed by the security team and as such, introduce additional delays. Hence, it is important for an organisation to understand the risk exposure due to their Incident Management processes, explore potential future scenarios (e.g. changes in available resources or threats landscapes or adoption of Cloud solutions) and identify suitable ways to address related issues, e.g. by introducing process changes and/or making investments in security controls.
HP Security Analytics is uniquely positioned to provide the analysis of the involved risks, explore what-if scenarios and provide decision support for decision makers. This type of Security Analytics assessments is now available as a service, provided by HP ESS.”.
--- Posted by Marco Casassa Mont (here and here) ---
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
--- NOTE: my original HP blog can be found here ---
The focus of this blog is on trends, new technologies/solutions and innovative aspects of Security and the Cloud, in a variety of contexts. What is the next big thing in this space?
Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163
Showing posts with label Incident Management. Show all posts
Showing posts with label Incident Management. Show all posts
Friday, November 30, 2012
Friday, December 2, 2011
On Incident Management, Security Analytics and the Cloud
In previous posts of mine I discussed the fact that HP Labs have developed an approach and capabilities to assess the risks associated to organisations’ Incident Management and Remediation processes. These capabilities, centred on HP Security Analytics, enable decision makers not only to assess the performance and security risks associated to current processes but also to explore potential what-if scenarios (e.g. changes of SLAs, changes of processes/resources, changes of threat environments) and identify suitable investments.
These capabilities are now offered as a service by HP Security Business (HP ESS).
I am interested in exploring the implications of doing this in emerging scenarios involving organisations that increasingly rely on outsourcing, supply-chains and the Cloud. What are the implications in terms of Incident Management and Response? How to effectively enable Information Sharing? How to enable accountability among the involved parties?
There is an opportunity in designing and building the next generation of Security Analytics and Risk Management services that can scale and cope with these emerging scenarios. More to come.
In the meanwhile, I am looking for additional requirements and use cases in the above space. Please contact me if you are interested in engaging in this area.
--- Posted by Marco Casassa Mont (here and here) ---
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
--- NOTE: my original HP blog can be found here ---
These capabilities are now offered as a service by HP Security Business (HP ESS).
I am interested in exploring the implications of doing this in emerging scenarios involving organisations that increasingly rely on outsourcing, supply-chains and the Cloud. What are the implications in terms of Incident Management and Response? How to effectively enable Information Sharing? How to enable accountability among the involved parties?
There is an opportunity in designing and building the next generation of Security Analytics and Risk Management services that can scale and cope with these emerging scenarios. More to come.
In the meanwhile, I am looking for additional requirements and use cases in the above space. Please contact me if you are interested in engaging in this area.
--- Posted by Marco Casassa Mont (here and here) ---
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
--- NOTE: my original HP blog can be found here ---
Friday, July 1, 2011
Towards A “Social Network” of Monitoring and Incident Management in the Cloud?
I recently read a very interesting article called “Log files – are you reviewing yours?”. Organisations often fail to fully leverage and analyse the audit log information that is collected within their IT and business environment …
Things might get worse when more and more organisational services and IT infrastructure is outsources in the Cloud …
This triggered a few thoughts about how assurance could be provided in the Cloud and how this could be done effectively to handle various degrees of risks.
Interestingly, when outsourcing in the Cloud, part of the organisational control on IT and processes is lost. This might include the ability of logging information at the desired level of granularity and timely acting on it, e.g. in case on incidents …
Which mechanisms should be put in place to enable organisations to get timely information, including logs and incidents, from their Cloud Service Providers?
This has an impact not only on SLAs and contractual agreements but also on technical solutions that needs to be deployed to:
- enable Cloud service providers to flexibly collect log information, at different level of abstractions in the IT stack – for specific customers - and provide it to organisations
- enable organisations to deal with mixed sources of log files, with potentially different level of accuracy and trust, to drive their audit & compliance management activities as well as incident management processes
It is going to be a “recursive” issue, as Cloud Service providers might rely on other providers in the Cloud …
I envisage a situation where enterprises’ business and governance requirements will dictate a wider collaboration between various Service Providers in order to collect, process, sanitise and share “logs information” and incidents.
Are we moving towards Federated Monitoring in the Cloud i.e. a sort of “Social Network” of Monitoring and Incident Management in the Cloud? …
--- Posted by Marco Casassa Mont (here and here) ---
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
--- NOTE: my original HP blog can be found here ---
Things might get worse when more and more organisational services and IT infrastructure is outsources in the Cloud …
This triggered a few thoughts about how assurance could be provided in the Cloud and how this could be done effectively to handle various degrees of risks.
Interestingly, when outsourcing in the Cloud, part of the organisational control on IT and processes is lost. This might include the ability of logging information at the desired level of granularity and timely acting on it, e.g. in case on incidents …
Which mechanisms should be put in place to enable organisations to get timely information, including logs and incidents, from their Cloud Service Providers?
This has an impact not only on SLAs and contractual agreements but also on technical solutions that needs to be deployed to:
- enable Cloud service providers to flexibly collect log information, at different level of abstractions in the IT stack – for specific customers - and provide it to organisations
- enable organisations to deal with mixed sources of log files, with potentially different level of accuracy and trust, to drive their audit & compliance management activities as well as incident management processes
It is going to be a “recursive” issue, as Cloud Service providers might rely on other providers in the Cloud …
I envisage a situation where enterprises’ business and governance requirements will dictate a wider collaboration between various Service Providers in order to collect, process, sanitise and share “logs information” and incidents.
Are we moving towards Federated Monitoring in the Cloud i.e. a sort of “Social Network” of Monitoring and Incident Management in the Cloud? …
--- Posted by Marco Casassa Mont (here and here) ---
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
--- NOTE: my original HP blog can be found here ---
Labels:
Assurance,
cloud,
governance,
Incident Management,
Logging,
risk management
Friday, April 29, 2011
Applying Security Analytics in the Space of SOC and Incident Management
Here is another exciting area in the space of Security Analytics.
I and colleagues of mine have been carrying out a few case studies, jointly with HP Customers and HP businesses, in the space of situational awareness by using Security Analytics.
This is an exciting area, very suitable for the HP Labs and HP IS Security Analytics methodology and tools, as it involves modelling critical processes, people behaviours and dealing with risk assessment issues.
The aim is to provide decision support to strategic decision makers (CISOs, CIOs, risk managers, etc.) and support the definition of related security policies.
Of particular interest and relevance is the application of our modelling & simulation methodology (along with related tools) to the processes involved in Security Operations Centres (SOCs) and related Incident Management & Remediation.
Specifically, we aim at assessing the risk exposure of organisations due to their SOC/incident management processes and the involved performance (e.g. time wasted in handling false positives). A series of metrics have been identified to measure the involved risks, e.g. time to fully manage incidents (the higher the wider the risk exposure window).
We used our analytics models to explore “what-if” scenarios e.g. the impact of changing SOC/incident management process steps, introducing automation and/or changing the number of involved personnel.
Interesting trade-offs are currently explored based on the priorities of decision makers, e.g. costs vs productivity vs security risks.
--- Posted by Marco Casassa Mont (here and here) ---
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
--- NOTE: my original HP blog can be found here ---
I and colleagues of mine have been carrying out a few case studies, jointly with HP Customers and HP businesses, in the space of situational awareness by using Security Analytics.
This is an exciting area, very suitable for the HP Labs and HP IS Security Analytics methodology and tools, as it involves modelling critical processes, people behaviours and dealing with risk assessment issues.
The aim is to provide decision support to strategic decision makers (CISOs, CIOs, risk managers, etc.) and support the definition of related security policies.
Of particular interest and relevance is the application of our modelling & simulation methodology (along with related tools) to the processes involved in Security Operations Centres (SOCs) and related Incident Management & Remediation.
Specifically, we aim at assessing the risk exposure of organisations due to their SOC/incident management processes and the involved performance (e.g. time wasted in handling false positives). A series of metrics have been identified to measure the involved risks, e.g. time to fully manage incidents (the higher the wider the risk exposure window).
We used our analytics models to explore “what-if” scenarios e.g. the impact of changing SOC/incident management process steps, introducing automation and/or changing the number of involved personnel.
Interesting trade-offs are currently explored based on the priorities of decision makers, e.g. costs vs productivity vs security risks.
--- Posted by Marco Casassa Mont (here and here) ---
--- NOTE: use this mirror blog if you prefer posting on an external blog site ---
--- NOTE: my original HP blog can be found here ---
Subscribe to:
Posts (Atom)