Rich Mogull: 7 Infosec Trends for 2009
Shrinking budgets, the collapse of the database security market, DLP going mainstream - the former Gartner pundit places his bets for the coming year. (Part of the What Happens Next security predictions series.)
» View Article
Rich Mogull: 7 Infosec Trends for 2009
Shrinking budgets, the collapse of the database security market, DLP going mainstream - the former Gartner pundit places his bets for the coming year. (Part of the What Happens Next security predictions series.)
» View Article
I disagree with these:
DLP is not going mainstream. The idea that companies can deploy control technology to stop data leaks at the gateway is ridiculously expensive and convoluted. There are more benefits to be gained by education of users than purchasing and deploying expensive gear to try and stop electrons from leaving. Especially when said solutions cost an arm, leg and torso.
Cloud aka Smoke. Growth will track hype. I don't think there are manifold benefits especially if company has properly aligned IT operations with objectives. In such cases, proper policies, controls and management can keep things humming along nicely.
PCI...means complexity. Not that good practices are bad, but the credit card industry has set a very high, expensive bar. If you play in their sandbox they require you to submit to their PCI DSS examination. It's thorough and complex...and you know you've gone thru it. But does it apply to every other non-credit processing entity? Nope. PCI, to me, is just an excuse/justification to try and sell more expensive, complex technology...
I agree on many of Rich Mogull's points but share the opinion of the previous comment related to money being better spent educating users rather than using another security technology (DLP or otherwise).
As to the value of cloud computing, I see many parallels with how the markets embraced outsourcing, over indulged, and eventually found a balance. In the case of cloud computing, one has to balance the loss of control with the gains on flexibility and scalability. Security in the cloud is as of yet uncharted territory.
Dirty Tricks: Social Engineers' Favorite Pickup Lines
Tabletop Exercises: 3 Sample Scenarios
19 Ways to Build Physical Security Into Your Data Center
Get instant notifications when whitepapers, webcasts and case studies are added to our library. Sign up for a Resource Alert now!
CSO Corporate Partners
» More blogs
CSO Perspectives
Santa Clara, California
(ISC)2 members can earn up to 24 CPE Credits!
Trend Micro ranked #1 against real-world malware. Read more.
64-page prescriptive guide to security, compliance, and IT operations.
Removing Barriers To Better Server Virtualization Efficiency
Mining for Gold: Cybercrime Prevention and the Role of Log Management
The Executive Guide to Data Loss Prevention
Organizations can spend up to 50% more on compliance efforts than necessary.
White Paper: A Security Blueprint Delivered From within the Network
Read the RSA report: Security for Business Innovation
Upgrading to VMware vSphere with vWire
Explore the increasing importance of log management as cybercrime threats grow.
The Tripwire HIPAA Solution: Meeting the Security Standards Set Forth in Section 164
Implementing Best Practices for Web 2.0 Security
Five Ways to Reduce Your IT Audit Burden
THE IDG NETWORK