<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CTOvision.com &#187; CTO</title>
	<atom:link href="http://ctovision.com/tag/cto/feed/" rel="self" type="application/rss+xml" />
	<link>http://ctovision.com</link>
	<description>News, analysis and context on enterprise technology for the CTO</description>
	<lastBuildDate>Thu, 09 Feb 2012 21:03:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Are Security Pros Becoming Too Paranoid?</title>
		<link>http://ctovision.com/2011/12/are-security-pros-becoming-too-paranoid/</link>
		<comments>http://ctovision.com/2011/12/are-security-pros-becoming-too-paranoid/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 20:30:19 +0000</pubDate>
		<dc:creator>BryanHalfpap</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Technology Leadership]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=14859</guid>
		<description><![CDATA[Tweet Paranoia is good when it comes to cyber-security&#8230;or is it? Are we making ourselves paranoid? Like many computer security professionals, I tend to closely follow technology and security news, even though its often discouraging and depressing.  It is routine to see articles disclosing general information about recent attacks and criminal successes (and sometimes criminal [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F12%2Fare-security-pros-becoming-too-paranoid%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/12/are-security-pros-becoming-too-paranoid/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/12/are-security-pros-becoming-too-paranoid/"  data-text="Are Security Pros Becoming Too Paranoid?" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/12/are-security-pros-becoming-too-paranoid/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/12/are-security-pros-becoming-too-paranoid/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><div>
<div style="text-align: center;">
<dl>
<dt><a href="http://ctovision.com/wp-content/uploads/2011/12/paranoia-demotivational-poster-12417266221.jpg"><img class="aligncenter" title="paranoia-demotivational-poster-1241726622" src="http://ctovision.com/wp-content/uploads/2011/12/paranoia-demotivational-poster-12417266221-300x225.jpg" alt="" width="300" height="225" /></a></dt>
<dd>Paranoia is good when it comes to cyber-security&#8230;or is it?</dd>
</dl>
</div>
<p>Are we making ourselves paranoid? Like many computer security professionals, I tend to closely follow technology and security news, even though its often discouraging and depressing.  It is routine to see articles disclosing general information about recent attacks and criminal successes (and sometimes criminal captures).  I suppose that at this point it is fairly common to find &#8220;shocking&#8221; breaches of trust and security in major corporations or large, widely-used or well-trusted systems.  Even reports of malware infections in drone control centers was met with a certain &#8220;well it was only a matter of time&#8221; feeling. This cynicism is common amongst those who work in the computer security field, both as reporters and as professionals in some capacity from tier 1 support to penetration testing and CSO&#8217;s.  When you&#8217;re a cynic, you stop being surprised.</p>
<p>What has started to happen as a blowback from all this security bad press and cynisism is a general feeling of paranoia.  This paranoia, advocated by security pros to general users in order to cut down the rate of infection of users and lessen security risks, is starting to creep into the minds and actions of security personnel.</p>
<p>This is a major problem because overly-paranoid security team members can cause major headaches with overreactions to abnormal conditions.  Like in Illinois with the water pump scare, or with the recent rumours of Iranian spy drone hacking.  While computer security problems have plagued us for years, they aren&#8217;t always to blame when something unexpected happens.  It&#8217;s important not to alienate users, customers, and the world at large by overreacting or acting before all the information is gathered.</p>
<p>It&#8217;s like the boy who cried wolf.  If your security team jumps at nothing all the time, they will not be taken seriously when they need to.</p>
<p>Implement policy to fix announcements of false positives.  A simple series of steps and confirmations should be enough to let you detect, learn about, and defeat intrusions.</p>
<ol>
<li>Verify with users or other policy that system behaviour is unexpected or unwanted.</li>
</ol>
<ol start="2">
<li>Gather information about activities on system.  Running programs, users, log information, communications to other systems, and outbound communications are important to know in order to profile the attack and determine the extent of the damage and action.</li>
</ol>
<ol start="3">
<li>Disable/disarm attacker.  Use knowledge gained from step 2 to block attackers when starting remediation/triage.</li>
</ol>
<ol start="4">
<li>Perform triage and remediation procedures on affected systems.</li>
</ol>
<p>You will need to determine for yourself when along that process a security disclosure needs to occur in order to remain compliant with standards and honest with users/customers.</p>
</div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_1" class="nrelate nrelate_related nrelate_default nr_100"><!-- no data found 200 --></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.domain = "ctovision.com";nRelate.fixHeight("nrelate_related_1");nRelate.adAnimation("nrelate_related_1");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/12/are-security-pros-becoming-too-paranoid/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Risk Management with Fixmo Sentinel</title>
		<link>http://ctovision.com/2011/12/risk-management-with-fixmo-sentinel/</link>
		<comments>http://ctovision.com/2011/12/risk-management-with-fixmo-sentinel/#comments</comments>
		<pubDate>Tue, 20 Dec 2011 15:26:45 +0000</pubDate>
		<dc:creator>BryanHalfpap</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[BlackBerry]]></category>
		<category><![CDATA[Cell Phone]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Fixmo]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[IPhone]]></category>
		<category><![CDATA[MDM]]></category>
		<category><![CDATA[Mobile device]]></category>
		<category><![CDATA[Mobile Device Management]]></category>
		<category><![CDATA[National Security Agency]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Sentinel]]></category>
		<category><![CDATA[Tech/Internet]]></category>
		<category><![CDATA[The Future of Technology]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=14740</guid>
		<description><![CDATA[Tweet These days we hear a lot of terms thrown about like the “Consumerization of IT” and “Bring your own device” (BYOD), and “Network health”.  This is because corporations are starting to warm up to the idea that maybe if they let you bring in your personal computing devices such as smartphones and tablets, they [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F12%2Frisk-management-with-fixmo-sentinel%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/12/risk-management-with-fixmo-sentinel/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/12/risk-management-with-fixmo-sentinel/"  data-text="Risk Management with Fixmo Sentinel" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/12/risk-management-with-fixmo-sentinel/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/12/risk-management-with-fixmo-sentinel/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><div>
<p><a href="ctovision.com"><img class="zemanta-img-inserted zemanta-img-configured alignleft" style="margin: 4px;" title="mobile devices" src="http://farm4.static.flickr.com/3477/3859140905_58f9062d56.jpg" alt="mobile devices" width="350" height="218" /></a></p>
</div>
<p>These days we hear a lot of terms thrown about like the “Consumerization of IT” and “Bring your own device” (BYOD), and “Network health”.  This is because corporations are starting to warm up to the idea that maybe if they let you bring in your personal computing devices such as smartphones and tablets, they won’t have to pay to give you one.</p>
<div>
<p dir="ltr">The flip-side of letting employees bring their consumer devices into the corporate fold is that there are much fewer mechanisms on these devices to allow them to be administered by a corporate IT policy, which can cause more than a few security and compatibility headaches, not to mention auditing and compliance nightmares. The idea of complete and total control over the corporate IT landscape is dying, and here to replace it is a feeling of unease in corporate IT departments even as executives push for more BYOD models.</p>
<p>Why the unease in IT?  When email isn’t working on your new Android or <a class="zem_slink" title="iPhone" href="http://www.apple.com/iphone" rel="homepage">iPhone</a>, you or your employees will call the IT department. The department, which typically supported a population of devices that were all very similar and very manageable from one point, now moves to support hundreds of different devices across multiple platforms which require different services to be managed. They are not only expected to support the new phones and tablets &#8212; they are also expected to ensure the continued security integrity of corporate networks and data while doing so. In an environment with such a rapidly-growing malicious software base and uneducated users, the task quickly becomes daunting.</p>
<p>Enter <a href="http://fixmo.com">Fixmo</a>, the creators of the commercial versions of the AutoBerry and AutoBES software. These software packages were designed to automate the secure setup of corporate BlackBerry phones and to ensure their security. This is what Fixmo cut their teeth on before moving into Mobile Device Management software (MDM) and solutions for mobile security.</p>
<p><strong>Mobile Device Management/Mobile Risk Management</strong></p>
<p>Mobile device management and mobile risk management are oriented around reducing and managing risk associated with connecting highly mobile devices which “roam” networks to enterprise technology structures. While the act of connecting them to a network may be simple, ensuring that enterprise policy is translated to these devices appropriately is a challenge. Many consumer devices require software and servers which may not be in use, or which can’t be implemented. Furthermore, policies are difficult to set and more difficult to manage. It is for this reason that many corporations choose to issue devices which they have complete control over (<a class="zem_slink" title="BlackBerry" href="http://www.blackberry.com" rel="homepage">BlackBerries</a>).</p>
<p>Fixmo’s MDM solution, <a href="fixmo.com/products/sentinel" target="_blank">Sentinel</a>, changes this with an approach that provides management and auditing to both phones and framework servers. This approach differs slightly between phones due to differences in the architectures of the phone operating systems it supports, but they all share a few features. The main component of the phone MDM is the agent. The agent monitors changes made to the phone and analyzes activities and installed applications. It relays this information to the Sentinel Server via automatic push or timed updates, and the server stores this information.<br />
The agent can be made to monitor for any type of system event, and is responsible for enforcing policies on the phone and communicating with the server. The Sentinel server can be used to view things such as current phone status (on, off, out of service, last reported in date) and information about the phone such as recent policy violations, installed programs, set policies, group membership, and more. The interface is easy to use (it’s a web application interface) and provides plenty of information with a presentation which doesn&#8217;t confuse users.</p>
<p>Perhaps one of the greatest features of the Sentinel agent is in its Android incarnation. One of the great roadblocks to major corporate adoption of Android has been its reliance on Google apps and the Google “cloud”. By using the Sentinel agent on Android, Android phones can be taught to use corporate networks through the Sentinel server. This allows corporate information technology departments to provide their own app store of supported applications or company-specific <a class="zem_slink" title="Android" href="http://code.google.com/android/" rel="homepage">Android apps</a>. Fixmo will provide app-store services through their App47 product, which is still in development.</p>
<p><strong>Making it Easy All The Way Up</strong></p>
<p>Autoberry and AutoBES are two mature Blackberry management software packages from Fixmo that manage both the phone and the server. Fixmo has taken what they learned with those platforms and taken it to the next level with Sentinel. Good, Blackberry Enterprise Server, and Microsoft exchange are all integrated into the Sentinel management platform, allowing for the management of both devices and their servers. This means compliance with regulations and audits are much easier when using Sentinel, which can generate reports on these servers and their policies.</p>
<p>Users of the management and auditing application can be integrated from active directory or other LDAP software and from BES groups. These users can be given granular privileges over phones, servers, and management and reporting applications depending on their needs.</p>
<p><strong>SafeZone</strong></p>
<p>Fixmo is rolling out encrypted containers on the <a class="zem_slink" title="IOS (Apple)" href="http://www.apple.com/ios" rel="homepage">iOS</a> and Android platforms which will allow users to work inside of FIPS-compliant environments on mobile devices which may not otherwise meet security requirements. The container, called Safezone, is an encrypted sandbox which has an API with which developers can create proprietary applications which can communicate and operate securely on mobile platforms. The container also has several applications from Fixmo which ship with the product, such as document editing services. This will allow mobile users to work on sensitive data without losing security, and without moving the data beyond the corporate network, since the application communicates via virtual network with devices placed inside of a corporate network.</p>
<p>Solutions currently on the market to perform MDM services are not currently as robust or full-scope as the Fixmo product, largely because they either highly focused or do not address some of the many limitations that the consumerization trend has brought upon corporate IT (namely, the lack of corporate policy enforcement mechanisms). Thus, Fixmo is a good investment for any IT firm looking to control their network and their security.</p>
</div>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://ctolabs.com/2011/12/mobile-apps-can-have-strategic-impact-if-mobile-risk-can-be-managed/">Mobile Apps Can Have Strategic Impact: If Mobile Risk Can Be Managed</a> (ctolabs.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.bobgourley.com/2011/09/fixmo-sentinel-manage-your-mobile-risk/">Fixmo Sentinel: Manage Your Mobile Risk</a> (bobgourley.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.bobgourley.com/2011/11/fixmo-and-mobile-risk-management-for-enterprise-and-government-agencies/">Fixmo And Mobile Risk Management For Enterprise and Government Agencies</a> (bobgourley.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=b1a3706c-bf62-492d-b7a2-871b9b0cdbcc" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_2" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/fixmo-and-mobile-risk-management-for-enterprise-and-government-agencies/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/deeaf259f29b608057f78c8d4a056615_thumb_fixmo.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Fixmo And Mobile Risk Management For Enterprise and Government Agencies</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/fixmo-sentinel-manage-your-mobile-risk/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/51a89e8c073c2a1b83aecdb413c1b6a4_thumb_Sentinel-Overview1.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Fixmo Sentinel:  Manage Your Mobile Risk</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2012/01/fixmo-announces-advisory-board-adds-to-board-of-directors/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/80c43d49b7c1841b45e094b0988759c4_thumb_Sentinel-Overview1.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Fixmo Announces Advisory Board, Adds to Board of Directors</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/12/mobile-apps-can-have-strategic-impact-if-mobile-risk-can-be-managed/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/0f6dc483ae417e653abc13edcfbed18e_thumb_imQ8zCUBakyM.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Mobile Apps Can Have Strategic Impact: If Mobile Risk Can Be Managed</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/ttps-cradas-mrm-and-fixmo/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/54765ae33264d2cb1428e0a3752ff43e_thumb_fixmonsa.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">TTPs, CRADAs, MRM, and Fixmo</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/fixmo-extends-no-charge-mobile-risk-management-solutions-for-government-agencies-through-agreements-with-national-security-agency/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunrise-desktop.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Fixmo Extends No-Charge Mobile Risk Management Solutions for Government Agenc ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/02/fixmo-the-mobile-risk-management-company/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/variety-of-short-grass-on-field.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Fixmo: The Mobile Risk Management Company</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/fixmo-unveils-safezone-a-risk-management-solution-for-personal-mobile-devices-in-the-workplace/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/blue-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Fixmo Unveils SafeZone, a Risk Management Solution for Personal Mobile Device ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/fixmo-partners-with-correlog-to-create-holistic-mobile-infrastructure-compliance-solutions/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-macro-plant.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Fixmo Partners With CorreLog to Create Holistic Mobile Infrastructure Complia ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/fixmo-appoints-tyler-lessard-as-chief-marketing-officer/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/cut-log.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Fixmo Appoints Tyler Lessard as Chief Marketing Officer</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Risk+Management+with+Fixmo+Sentinel&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F12%2Frisk-management-with-fixmo-sentinel%2F&nr_ad_number=0&nr_div_number=2");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_2");nRelate.adAnimation("nrelate_related_2");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/12/risk-management-with-fixmo-sentinel/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Social Searching Everything, For Everyone</title>
		<link>http://ctovision.com/2011/12/social-searching-everything-for-everyone/</link>
		<comments>http://ctovision.com/2011/12/social-searching-everything-for-everyone/#comments</comments>
		<pubDate>Sun, 11 Dec 2011 15:12:43 +0000</pubDate>
		<dc:creator>BryanHalfpap</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Web2.0]]></category>
		<category><![CDATA[CTO]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[Natural language processing]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Tech/Internet]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Weblogs]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=14726</guid>
		<description><![CDATA[Tweet What could you do if you had access to all of twitter all at once? What if you combined that with 75 million other data feeds? And combined it with an easy-to-use-tool and impressive visuals? What if it were a service software? That’s exactly what the Social Media Command Center from InTTENSITY is. It’s [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F12%2Fsocial-searching-everything-for-everyone%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/12/social-searching-everything-for-everyone/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/12/social-searching-everything-for-everyone/"  data-text="Social Searching Everything, For Everyone" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/12/social-searching-everything-for-everyone/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/12/social-searching-everything-for-everyone/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://ctovision.com/wp-content/uploads/2011/12/logo.png"><img class="alignleft size-full wp-image-14729" title="inTTensity" src="http://ctovision.com/wp-content/uploads/2011/12/logo.png" alt="inTTensity" width="302" height="104" /></a>What could you do if you had access to all of twitter all at once? What if you combined that with 75 million other data feeds? And combined it with an easy-to-use-tool and impressive visuals? What if it were a service software?</p>
<p>That’s exactly what the Social Media Command Center from InTTENSITY is. It’s your social media and Internet war room &#8212; replete with maps, calenders, lists of events and people. Its primary purpose: to allow users to quickly view their search/filter information and utilize it to make intelligent decisions based on social media information from the Internet.</p>
<p><strong>How it works:</strong></p>
<p>InTTENSITY servers constantly crawl over 75 million social media sources. As the data is imported into the system, a set of processing rules defined by the user is run over the imported data and marked up. This markup data can be stored on request by users for up to 6 months from the implementation of the rules.</p>
<p>Processing rules are created by using a workbench, a thick client which allows users to create processing rules using the natural language processing engine. Creating a rule with this method requires some training, but allows for very powerful rules and high levels of specificity. Without using the engine, users of the social media workbench can create simple searches based off of keywords or simple metadata such as location. All rules are processed by the engine and assigned critical information such as positivity and negativity ratings (how did the user feel about what they were talking about) and location.</p>
<p>Once data has been marked with the processing rules, it is sent to processing clusters and then displayed to the user on the Social Media Command Center which provides a very intuitive interface for people to view their topics, location, and more. The interface provides easy methods to drill down topics and get into the details.</p>
<p><strong>Easy as Pie</strong></p>
<p>This technology is possible because of the 75 different patents that InTTENSITY holds in processing this type of information. It’s also because the InTTENSITY product is a conglomeration of two strong natural language processing engines put together. This, put together with the access to the 75 million data feeds and the entirety of twitters traffic (excepting private tweets), combines into a technology which any marketing or intelligence official would give their left arm for.</p>
<p><strong>Everyone Gets a Slice</strong></p>
<p>The Social Media Command Center and the workbench allow information technology personnel to create and define searches and terms for users to monitor in real-time. This in turn allows people in marketing to determine how the new ad campaign is working, the employees in PR to determine how people are viewing the company, and engineers to discover any bugs or product issues, all in real-time. This tool can provide you total social media knowledge while keeping both time and money low.</p>
<p>Go check out InTTENSITY’s Social Media Command Center now at <a href="http://www.inttensity.com/socialmedia.aspx">inttensity.com</a>.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=e2e87c46-f231-4985-8e64-89be2d069d06" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_3" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/07/what-google-means-for-you/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/df75465993f96b42ab6e985575759162_thumb_Google-Plus-+.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">What Google+ Means for You</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/were-already-cyborgs/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/e2909ad3b1b47e510a879f96fb8cd3ae_thumb_extended_mind.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">We're Already Cyborgs</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2012/01/dear-google-i-am-not-buying-plus/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/1b40c22b34b4604e6052dbd42152f756_thumb_google-plus.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Dear Google, I am not buying Plus</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/jive-and-social-business/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/d86c7704a25bbe81826c42293f45bbdc_thumb_jive.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Jive and Social Business</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/08/pollbob-iphone-app-review/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/d6b4cb521a32d5f510c9f52003899652_thumb_logo.gif" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Pollbob iPhone App Review</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/we%e2%80%99re-already-cyborgs/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-old-wood.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">We’re Already Cyborgs</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://1x57.com/2011/10/13/be-prepared-for-facebook-timeline-updated/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/70d30d7799f2f8d3bac3e0b9429372ce_thumb_aaron-roe-fulkerson-facebook-timeline-profile-page-screenshot-new.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Be Prepared for Facebook Timeline (UPDATED)</span><span class="nr_source">1X57</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.jdkathuria.com/2011/05/stuart-shea-of-saic-advice-from-a-college-professor-expanding-your-network-and-the-social-media-community/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/0631970d7cb1323ce3c64c280aa5047b_thumb_shea_5-125x150.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Stu Shea: Advice From A College Professor, How To Expand Your Network, And Th ...</span><span class="nr_source">JD Kathuria | It's not about who you know, but who wants to know you</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/02/encrypting-your-life-tools-and-tips/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/77f73aed4b6c019b7b47eb99a04cc88a_thumb_300px-Cell_phone_ctu-away_mg_372124.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Encrypting Your Life: Tools and Tips</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/08/weighing-in-on-wayin/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/aa4806717bed935ff4439b1e3d2cd12e_thumb_wayin_logo-e1312820733455-300x144.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Weighing in on WayIn</span><span class="nr_source">CTOvision.com</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Social+Searching+Everything%2C+For+Everyone&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F12%2Fsocial-searching-everything-for-everyone%2F&nr_ad_number=0&nr_div_number=3");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_3");nRelate.adAnimation("nrelate_related_3");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/12/social-searching-everything-for-everyone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Government Android Should Concern You</title>
		<link>http://ctovision.com/2011/12/government-android-should-scare-you/</link>
		<comments>http://ctovision.com/2011/12/government-android-should-scare-you/#comments</comments>
		<pubDate>Tue, 06 Dec 2011 21:49:47 +0000</pubDate>
		<dc:creator>BryanHalfpap</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Gadgets]]></category>
		<category><![CDATA[Gov2.0]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Fixmo]]></category>
		<category><![CDATA[Fixmo Sentinel]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[gov2]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Handhelds]]></category>
		<category><![CDATA[IOS (Apple)]]></category>
		<category><![CDATA[Mobile computing]]></category>
		<category><![CDATA[Mobile Risk Management]]></category>
		<category><![CDATA[Tech/Internet]]></category>
		<category><![CDATA[The Future of Technology]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=14862</guid>
		<description><![CDATA[Tweet Android is a great mobile computing platform. It’s extensible, fairly easy-to-use (considering its plethora of features), has a great application store with hundreds of thousands of applications, and connects back with everything in Google so that all of Google’s information and services are at the users fingertip. For developers, it’s a very extendable platform [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F12%2Fgovernment-android-should-scare-you%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/12/government-android-should-scare-you/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/12/government-android-should-scare-you/"  data-text="Government Android Should Concern You" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/12/government-android-should-scare-you/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/12/government-android-should-scare-you/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><div>
<div class="mceTemp mceIEcenter">
<div class="wp-caption alignleft" style="width: 276px"><img class="  " title="Android Root Software" src="http://software2tech.com/wp-content/uploads/2011/03/werwerwee44_thumb.jpg" alt="" width="266" height="252" /><p class="wp-caption-text">Android exploits present a problem for enterprise and Gov&#39;t adoption of Android</p></div>
</div>
<p>Android is a great mobile computing platform. It’s extensible, fairly easy-to-use (considering its plethora of features), has a great application store with hundreds of thousands of applications, and connects back with everything in Google so that all of Google’s information and services are at the users fingertip. For developers, it’s a very extendable platform which is able to integrate code from a variety of languages, run C programs, and deploy applications easily to users.</p>
<p>This combination of versatility, extendability, usability, and many features are a few reasons why Android has a significant market share in the mobile computing industry. These great features are also the things attracting enterprise users, including the government.</p>
<p>But something is becoming increasingly clear to security researchers. There are some very serious security issues with this platform. They are so serious the government should think twice before rushing to Android as a most favored mobile platform. In fact, a case can be built that it should be excluded from government use unless guidelines are followed in order to mitigate the issues.</p>
<p>Bottom line up front: If you are going to use Android, use it with a well thought out Mobile Risk Management solution.</p>
<p><strong>Here is more to ponder:</strong></p>
<p>Android is supposedly secure from the ground up, running a Linux kernel (with many adaptations), a walled-garden application model, system architecture to increase security (DEP, ASLR), application permissions, and more. Unfortunately, holes or bypasses have been found in nearly all of these security features. Some, like the application permissions model, may require significant overhauls in order to maintain security.  For more on Android security, please use the Crucialpoint contact form in &#8220;Contact Us&#8221; to request access to the &#8220;Current State of Android Security&#8221; whitepaper.</p>
<p>The security of the platform in question is not just notable for what has been broken or evaded,  it&#8217;s notable for what it doesn&#8217;t include: fine-grain enterprise management and mature management tools. Android from its inception has been primarily a consumer device and its somewhat meager corporate tools reflect this path. As the operating system grows, it has been adding new management/control features in order to allow its use in corporate infrastructure, but these features are still growing. Enterprise adoption of the platform has thus been low and slow. It doesn&#8217;t yet provide the myriad of options that blackberry does, and it doesn’t have the level of integration with existing corporate services either. These features need to be built into the core of the operating system and its management tools.</p>
<p>Android devices have also had a notoriously difficult update process, with devices waiting months or years to receive critical patches or version upgrades from service providers and/or manufacturers. Government devices need to be kept to a higher security standard and as such should receive patches at-pace. Android devices are computers, and they should be treated as such.</p>
<p>Government adoption of Android should meet these requirements in order to securely implement Android:</p>
<ul>
<li>Hardware that will be able to run next-generation Android versions</li>
<li>Ability to push patches and upgrades</li>
<li>Require vendors to have a quick patch turnaround (a few weeks instead of months, like Google Nexus devices)</li>
<li>Management and Policy deployment platforms (such as <a href="http://fixmo.com/products/sentinel">Fixmo Sentinel</a>)</li>
<li>Support contracts from vendors or in-house Android support</li>
<li>Release of patches back into Android Open Source Project</li>
<li>Disablement of the Android Debug Bridge</li>
<li>Encryption or Encryption Services (such as <a href="http://fixmo.com/products/safezone">SafeZone</a>)</li>
</ul>
<p>Admittedly, most of the infection vectors for android require the ability to install malicious applications, a feature which can be easily disabled with simple policy, but some common application exploits are available for Android as well. Physical access to a device can also give other attack vectors to motivated criminals or state actors, and given the ease with which phones are lost, it isn’t beyond the realm of possibility that phone would get misplaced or stolen, hacked, and then returned to the user.</p>
<p>Android may be the most common, most easily extendable platform, but with its security concerns, very careful planning is recommended so that mistakes aren’t made in its deployment.</p>
<p>A concluding caution: There are issues in closed approaches to mobile as well. And some of those might even be harder to fix. With this article we wanted to focus a bit more on Android because the Government seems to be rushing there. The key point is that any mobile system will require the right planning and systems to be put in place. When it comes to Android, the versatility and ability to modify Android will prove to be an asset to the Government &#8212; so long as it is properly managed and as long as security is part of your architecture.</p>
</div>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=23b4769e-2c39-460f-b31a-d15bec7ab327" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_4" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/fixmo-sentinel-manage-your-mobile-risk/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/51a89e8c073c2a1b83aecdb413c1b6a4_thumb_Sentinel-Overview1.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Fixmo Sentinel:  Manage Your Mobile Risk</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/12/how-the-federal-government-is-slowly-embracing-mobile/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/229ce286aebfda8ccb3dcbaa1ef60c8d_thumb_ipad.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">How the Federal Government is Slowly Embracing Mobile</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/?p=14740"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/303dce04d89d918d8c1778df62b33f21_thumb_Phones.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Risk Management with Fixmo Sentinel</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/12/mobile-apps-can-have-strategic-impact-if-mobile-risk-can-be-managed/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/0f6dc483ae417e653abc13edcfbed18e_thumb_imQ8zCUBakyM.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Mobile Apps Can Have Strategic Impact: If Mobile Risk Can Be Managed</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/12/a-look-at-vmwares-vfabric-cloud-application-platform/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/0717589ce7df6c98de9d81caca8a3571_thumb_vmware.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">A look at VMware's vFabric Cloud Application Platform</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/fixmo-extends-no-charge-mobile-risk-management-solutions-for-government-agencies-through-agreements-with-national-security-agency/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/blue-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Fixmo Extends No-Charge Mobile Risk Management Solutions for Government Agenc ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/mobile-continues-to-trickle-in-to-the-military/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/variety-of-short-grass-on-field.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Mobile Continues to Trickle in to the Military</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/12/a-look-at-vmware%e2%80%99s-vfabric-cloud-application-platform/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/water-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">A look at VMware’s vFabric Cloud Application Platform</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/12/google%e2%80%99s-currents-is-what-reader-should-have-been/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/art-rhododendron-flower.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Google’s Currents is what Reader should have been</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/top-10-intuitive-updates-for-ios5/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/great-red-wood-circle-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Top 10 Intuitive Updates for iOS5</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Government+Android+Should+Concern+You&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F12%2Fgovernment-android-should-scare-you%2F&nr_ad_number=0&nr_div_number=4");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_4");nRelate.adAnimation("nrelate_related_4");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/12/government-android-should-scare-you/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Cloudera and SGI Partner: With new benchmarks and better mission support the result</title>
		<link>http://ctovision.com/2011/10/cloudera-and-sgi-partner-with-new-benchmarks-and-better-mission-support-the-result/</link>
		<comments>http://ctovision.com/2011/10/cloudera-and-sgi-partner-with-new-benchmarks-and-better-mission-support-the-result/#comments</comments>
		<pubDate>Fri, 28 Oct 2011 12:02:43 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Big Data]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[CTO]]></category>
		<category><![CDATA[Apache Hadoop]]></category>
		<category><![CDATA[bigdata]]></category>
		<category><![CDATA[Cloudera]]></category>
		<category><![CDATA[Distribution Including Apache Hadoop]]></category>
		<category><![CDATA[Hadoop]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[SGI]]></category>
		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=14224</guid>
		<description><![CDATA[Tweet During the recent GEOINT conference I spoke with SGI and Cloudera about the meaning of their recent announcement. They just announced a strategic agreement where SGI will ship Cloudera&#8217;s Distribution Including Apache Hadoop (CDH) and Cloudera Enterprise Management Suite factory installed on SGI Hadoop Clusters. Although this is good news for both companies there is [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F10%2Fcloudera-and-sgi-partner-with-new-benchmarks-and-better-mission-support-the-result%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/10/cloudera-and-sgi-partner-with-new-benchmarks-and-better-mission-support-the-result/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/10/cloudera-and-sgi-partner-with-new-benchmarks-and-better-mission-support-the-result/"  data-text="Cloudera and SGI Partner: With new benchmarks and better mission support the result" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/10/cloudera-and-sgi-partner-with-new-benchmarks-and-better-mission-support-the-result/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/10/cloudera-and-sgi-partner-with-new-benchmarks-and-better-mission-support-the-result/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><img class="alignleft size-full wp-image-13431" title="hadoop" src="http://ctovision.com/wp-content/uploads/2011/08/hadoop.png" alt="" width="313" height="252" /></p>
<p>During the recent <a href="http://ctovision.com/?s=geoint">GEOINT</a> conference I spoke with <a href="http://www.sgi.com/">SGI</a> and <a href="http://cloudera.com">Cloudera</a> about the meaning of their recent announcement. They just announced a strategic agreement where SGI will ship Cloudera&#8217;s Distribution Including Apache Hadoop (CDH) and Cloudera Enterprise Management Suite factory installed on SGI Hadoop Clusters.</p>
<p>Although this is good news for both companies there is better news for users of Apache Hadoop. Benchmarking of this Cloudera CDH/SGI platform has proven to provide incredible performance over massive datasets. They clocked in at 81% faster than the competition.</p>
<p>Another thing I really like about this is the power of <a href="http://www.cloudera.com/products-services/tools/">Cloudera&#8217;s Enterprise Management Suite</a>. This suite of tools provides activity monitor, service and configuration manager, resource manager, and an authorization manager.</p>
<p>And of course it includes the<a href="http://cloudera.com"> Cloudera Distribution including Apache Hadoop (CDH)</a>, the platform of open source software that is already the most widely used open source suite of tools.</p>
<p>Their announcement provides more info.  It is pasted below for reference. But here is the overall significance as I see it:</p>
<p>- If you are a program manager looking into Hadoop, start your journey with CDH.  It is the smart, fast, free way to get up and running with Hadoop-centric solutions.</p>
<p>- If you are an enterprise looking to enhance your ability to manage and support and provide better authorization and permissions, use Cloudera&#8217;s Enterprise Management Suite. This is also smart and fast and will lower your administration costs.</p>
<p>- If you are dealing with Big Data, you will want the best integrated hardware/software solution and it is best to get that delivered in a well thought out way. A GREAT option is the SGI factory-installed delivery of CDH and Cloudera Enterprise Management Suite. This will give you the power proven in benchmarks.</p>
<p>More is below:</p>
<blockquote><p>Cloudera and SGI Partner to Take High Performance Computing onApache Hadoop to the Next Level</p>
<p>Under Strategic Distribution Agreement, SGI Will Ship Cloudera&#8217;s Distribution Including Apache Hadoop and<br />
Cloudera Enterprise Management Suite Factory-installed On SGI Hadoop Clusters</p>
<p>Palo Alto, CA and Fremont, CA, October 17, 2011 — Cloudera Inc., the leading provider of Apache Hadoop-based data management software and services, and SGI (NASDAQ: SGI), the trusted leader in technical computing, today jointly announced that their companies have signed an agreement for SGI to distribute Cloudera software pre-installed on SGI® Hadoop Clusters. SGI, which recently set a world record performance benchmark for Terasort data processing and analysis leveraging Cloudera&#8217;s Distribution Including Apache Hadoop (CDH) and is a member of the Cloudera Connect Partner Program, will resell and offer level one support for Cloudera software and services &#8211; including Cloudera University training courses &#8211; to its customers. The relationship will also enable the two companies to jointly build, sell and deploy integrated, high performance Apache Hadoop-based commercial solutions.</p>
<p>Apache Hadoop is a powerful and disruptive open source technology that addresses the economic, flexibility and scalability issues surrounding massive amounts of enterprise data and enables actionable insights to be derived from structured and unstructured data sets. Hadoop, which forms the infrastructure foundation of many of the world&#8217;s leading social media companies, including Facebook, LinkedIn and Twitter, has rapidly become a leading solution to the new challenges generated by Big Data.</p>
<p>Together, SGI Hadoop clusters and Cloudera&#8217;s software, services and support form a complete, end-to-end solution for enterprises deploying Apache Hadoop in performance-intensive environments. As the global leader in technical computing, SGI was among the first technology vendors to embrace and proliferate the use of Apache Hadoop in the Federal and enterprise sectors, and is currently running the largest Hadoop clusters servers in the world. Cloudera has pioneered the use of Apache Hadoop in business applications and was first to make Hadoop enterprise-ready, delivering best of breed management software, support and training services. CDH is the most widely deployed Hadoop distribution in both commercial and non-commercial environments, bundling 100% pure open source Apache Hadoop with other leading open source components in the Hadoop stack.</p>
<p>&#8220;We understand the power of Hadoop. Since the technology&#8217;s inception, we have successfully deployed tens of thousands of Hadoop servers to our customers,&#8221; said Bill Mannel, vice president of product marketing at SGI. &#8220;Leveraging Cloudera&#8217;s Distribution Including Apache Hadoop together with our SGI Hadoop Cluster, we achieved a world record Hadoop benchmark for data processing and analysis &#8211; 81% faster than the competition. CDH, combined with Cloudera&#8217;s management suite, puts the promise and potential of Hadoop &#8211; and the complete Hadoop stack &#8211; within reach. We are pleased to work with Cloudera, and together, we are enabling our mutual customers to streamline the path to putting Hadoop to work for their businesses.&#8221;</p>
<p>&#8220;The combination of Cloudera&#8217;s market-leading software with SGI&#8217;s first-class products and reputation in the HPC market enables global access and delivery capacity for Apache Hadoop in stalwart HPC verticals, including defense, intelligence, research and telecommunications,&#8221; said Ed Albanese, Head of Business Development for Cloudera. &#8220;This partnership enables Cloudera to better serve a segment of customers accustomed to factory-installed products and solution-oriented delivery. We&#8217;re pleased that SGI has selected Cloudera products and will offer these products as a bundled component of their proven server line.&#8221;</p>
<p><strong>About SGI</strong><br />
SGI, the trusted leader in technical computing, is focused on helping customers solve their most demanding business and technology challenges. Visit sgi.com for more information.</p>
<p>Connect with SGI on <a href="http://www.twitter.com/sgi_corp" target="_blank">Twitter</a> (@sgi_corp), <a href="http://www.youtube.com/sgicorp" target="_blank">YouTube</a> (youtube.com/sgicorp), and <a href="http://www.linkedin.com/company/sgi">LinkedIn</a>.</p>
<p><strong>About Cloudera</strong><br />
Cloudera, the leader in Apache Hadoop-based software and services, enables data driven enterprises to easily derive business value from all their structured and unstructured data. Cloudera&#8217;s Distribution Including Apache Hadoop (CDH), available to download for free at <a title="This link will open in a new browser window." href="http://www.cloudera.com/downloads" target="_blank">www.cloudera.com/downloads</a>, is the most comprehensive, tested, stable and widely deployed distribution of Hadoop in commercial and non-commercial environments. For the fastest path to reliably using this completely open source technology in production for Big Data analytics and answering previously un-addressable big questions, organizations can subscribe to Cloudera Enterprise, comprised of Cloudera Support and a portfolio of software including Cloudera Management Suite. Cloudera also offers consulting services, training and certification on Apache technologies. As the top contributor to the Apache open source community and with tens of thousands of nodes under management across customers in financial services, government, telecommunications, media, web, advertising, retail, energy, bioinformatics, pharma/healthcare, university research, oil and gas and gaming, Cloudera&#8217;s depth of experience and commitment to sharing expertise are unrivaled. <a title="This link will open in a new browser window." href="http://www.cloudera.com/" target="_blank">www.cloudera.com</a></p>
<p>&nbsp;</p>
<p><strong>Connect with Cloudera</strong><br />
Read the blog: <a title="This link will open in a new browser window." href="http://www.cloudera.com/blog/" target="_blank">http://www.cloudera.com/blog/</a><br />
Follow on Twitter: <a title="This link will open in a new browser window." href="http://twitter.com/cloudera" target="_blank">http://twitter.com/cloudera</a><br />
Visit on Facebook: <a title="This link will open in a new browser window." href="http://www.facebook.com/cloudera" target="_blank">http://www.facebook.com/cloudera</a></p>
<p>© 2011 Silicon Graphics International Corp. All rights reserved. SGI is a registered trademark of Silicon Graphics International Corp. or its subsidiaries in the United States and/or other countries. All other trademarks are property of their respective holders.</p>
<p><strong>Media Contacts</strong></p>
<p>Ogilvy Public Relations<br />
Analisa Schelle<br />
415-677-2721<br />
<a href="https://mail.google.com/a/crucialpointllc.com/mail/?view=cm&amp;fs=1&amp;tf=1&amp;to=SGImedia@ogilvyr.com" target="_blank">SGImedia@ogilvyr.com</a></p>
<p>Cloudera<br />
Hope Nicora<br />
Bhava Communications<br />
<a href="https://mail.google.com/a/crucialpointllc.com/mail/?view=cm&amp;fs=1&amp;tf=1&amp;to=cloudera@bhavacom.com" target="_blank">cloudera@bhavacom.com</a><br />
510-984-1527</p></blockquote>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=8c29ed84-45c0-4216-b556-c8c251c74a61" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_5" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/06/data-wizards-know-hadoop-is-powerful-but-they-want-more-automation/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/3feabd9723f0994091e1088fd98c78e3_thumb_trade-data.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Data Wizards Know Hadoop is Powerful: But they want more automation</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/12/if-you-use-hadoop-you-have-been-waiting-for-this-cloudera-enterprise-3-7/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/2d3acf199ffe4e20885ed9dcb126dffd_thumb_lifecycle.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">If You Use Hadoop You Have Been Waiting For This: Cloudera Enterprise 3.7</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/04/enterprise-ctos-learn-hadoop-and-clouderas-cdh3-on-21-april/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/19895bb8a71ff4f7b49e5159e08d7345_thumb_Hadoop-logo.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Enterprise CTOs: Learn Hadoop and Cloudera's CDH3 on 21 April</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/08/the-quickest-way-to-deploy-a-well-engineered-apache-hadoop-solution-to-a-production-environment/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/20ba6b5ed99831d229407c650ecd57ab_thumb_delpoweredge.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The Quickest Way To Deploy A Well Engineered Apache Hadoop Solution To A Prod ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/hadoop-world-breakout-sessions-8-and-9-nov-recommendations-for-the-enterprise-cto/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/5795a505ac3bd51a6489c9c8337befb8_thumb_decide.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Hadoop World Breakout Sessions 8 and 9 Nov: Recommendations for the enterpris ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2012/01/join-cloudera-and-carahsoft-for-big-data-success-in-government/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/weather-station-robe-south-australia.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Join Cloudera and Carahsoft for Big Data Success in Government</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/cloudera-and-carahsoft-webinar-big-data-success-in-government-19-jan-2012/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-abstract-glass.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cloudera and Carahsoft Webinar: Big Data Success in Government 19 Jan 2012</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/cloudera-day-in-dc/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/blue-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cloudera Day in DC</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/cloudera-and-sgi-partner-with-new-benchmarks-and-better-mission-support-the-result/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/spiral-seashells-painted-gold.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cloudera and SGI Partner: With new benchmarks and better mission support the  ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/cloudera-and-sgi-partner-to-take-high-performance-computing-on-apache-hadoop-to-the-next-level/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/stone-wall-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cloudera and SGI Partner to Take High Performance Computing on Apache Hadoop  ...</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Cloudera+and+SGI+Partner%3A+With+new+benchmarks+and+better+mission+support+the+result&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F10%2Fcloudera-and-sgi-partner-with-new-benchmarks-and-better-mission-support-the-result%2F&nr_ad_number=0&nr_div_number=5");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_5");nRelate.adAnimation("nrelate_related_5");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/10/cloudera-and-sgi-partner-with-new-benchmarks-and-better-mission-support-the-result/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Thinking About the Traditional Approach</title>
		<link>http://ctovision.com/2011/09/thinking-about-the-traditional-approach/</link>
		<comments>http://ctovision.com/2011/09/thinking-about-the-traditional-approach/#comments</comments>
		<pubDate>Fri, 23 Sep 2011 20:12:45 +0000</pubDate>
		<dc:creator>AdamElkus</dc:creator>
				<category><![CDATA[Big Data]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[The Future]]></category>
		<category><![CDATA[Bob Gourley]]></category>
		<category><![CDATA[cio]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[Hewlett-Packard]]></category>
		<category><![CDATA[Maginot Line]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Private Security]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=13692</guid>
		<description><![CDATA[Tweet A recent IDG interview of Bob Gourley of Crucial Point and Andrzej Kawalec of HP delved into the problem of the &#8220;traditional&#8221; method of enterprise security, a paradigm  under severe challenge. We can sum up the traditional approach as less a certain tactic, technique, technology, or policy than a way of viewing the world. [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F09%2Fthinking-about-the-traditional-approach%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/09/thinking-about-the-traditional-approach/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/09/thinking-about-the-traditional-approach/"  data-text="Thinking About the Traditional Approach" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/09/thinking-about-the-traditional-approach/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/09/thinking-about-the-traditional-approach/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://ctovision.com/wp-content/uploads/2011/09/Cavalrycharge.png"><img class="alignleft size-thumbnail wp-image-13694" style="margin: 4px;" title="Cavalrycharge" src="http://ctovision.com/wp-content/uploads/2011/09/Cavalrycharge-150x150.png" alt="" width="150" height="150" /></a>A recent IDG interview of Bob Gourley of Crucial Point and Andrzej Kawalec of HP delved into the problem of the &#8220;traditional&#8221; method of enterprise security, a paradigm  under severe challenge. We can sum up the traditional approach as less a certain tactic, technique, technology, or policy than a way of viewing the world.</p>
<p>As Gourley has noted, traditional enterprise security can be characterized with one of these bullets:</p>
<ul>
<li>Primarily exists below the CIO level and is primarily thought of as a technical&#8211;rather than policy&#8211;matter</li>
</ul>
<ul>
<li>Is based on <a href="http://ctovision.com/2011/07/the-maginot-line-of-information-systems-security/">point defense</a> of all access points (The Maginot line approach)</li>
</ul>
<ul>
<li>Doesn&#8217;t provide <a href="http://ctovision.com/2011/07/the-maginot-line-of-information-systems-security/">defense-in-depth</a></li>
</ul>
<ul>
<li>Is not about the enterprise as a whole</li>
</ul>
<ul>
<li>Does not take into account enterprise use of computing technologies besides PCs</li>
</ul>
<p>Enterprise security, in the traditional approach, is thought of as an technical issue rather than a policy problem. This limits the ability to think strategically and keeps the conversation (and policy) focused on tactics and technical measures and counter-measures&#8211;losing sight of overall problems and solutions that are typically decided at the CIO level. Point defense is seen as a viable solution to dealing with security problems, a solution with a poor historical track record in both military and private security contexts. It does not focus on the enterprise itself but looks narrowly at a discrete set of technical issues, and similarly is blind and deaf to the growing enterprise use of &#8220;post-PC&#8221; mobile technologies.</p>
<p>As noted before, this is an aggregate set of practices formed by an underlying worldview rather than a deliberate policy that a <a href="http://en.wikipedia.org/wiki/Bill_Lumbergh">Bill Lumbergh</a> sat down and decided to inflict on his subordinates. It was formed less by deliberate design than a confluence of factors, including the dominance of the PC as a singular computing practice within the enterprise, the relatively primitive (compared to today) nature of security problems, the marginalization of computer security as a technical rather than policy issue, and an desire to minimize loss by attempting to protect everything within the enterprise.</p>
<p>Although military examples are often useful in looking at attack/defense dynamics in the cyber world, a more mundane example from private security also illustrates the point. Dignitary protection, a fairly standard mission for both private security in the corporate, political, and entertainment world, is not just about neutralizing a discrete set of technical threats (the stereotype of a bodyguard checking for bombs or people with guns). It&#8217;s also about understanding and calculating plausible threat scenarios informed by a knowledge of the principal&#8217;s everyday lifestyle, security weaknesses, likely adversaries, and many other factors. Point defense is a worst-case scenario, and is arguably seen as a denial of tradeoffs <a href="http://www.schneier.com/book-beyondfear.html">inherent in the profession</a>.</p>
<p>Obviously, the creation of the CIO itself (and the similar rise in CTO positions) is a symptom of greater change in both government and private organizations. The idea that technology policy within an organization can be centralized and strategically directed in a long-term frame has enormous implications for the way we think about enterprise security. We&#8217;ll be discussing these issues in more depth at the <a href="http://events.fedcyber.com/">FedCyber Government-Industry Cyber Security Summit</a> and hope you&#8217;ll be able to attend.</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_6" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/special-summary-enterprise-security-stories/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/a9eb3edce3d5c67a7bf299ecbc588db5_thumb_digitalglobe.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Special Summary: Enterprise security stories</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/the-evolving-enterprise-threat-environment/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/26bba1be39a5b1601cf7dfaa47327590_thumb_LockedComputer.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The Evolving Enterprise Threat Environment</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/latest-dodgeretort-gao-federal-cios-need-to-focus-more-on-information-management-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/3bf47f1c25400dc5323702d359eb65c2_thumb_cio.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Latest DodgeRetort - GAO: Federal CIO's need to focus more on information man ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/art-rhododendron-flower.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Yesterday's Security Doesn't Work for Today's Threats</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/new-enterprise-cio-forum-blog-talk-radio/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/271b072ca6c9cd085c27d605e635dda3_thumb_cio1.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">New Enterprise CIO Forum Blog Talk Radio</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/02/fdcci-preparation-with-virtual-instruments-and-carahsoft/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/stone-wall-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">FDCCI Preparation with Virtual Instruments and Carahsoft</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2012/01/big-data-success-in-government/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/blue-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Big Data Success in Government</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/note-to-cios-your-organization-will-never-be-100-secure/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-red.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Note to CIOs: Your organization will never be 100% secure</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/10/evolving-approaches-to-cyber-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/wave-open-sea.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Evolving Approaches to Cyber Threats</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/latest-dodgeretort-%e2%80%93-gao-federal-cio%e2%80%99s-need-to-focus-more-on-information-management-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/weather-station-robe-south-australia.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Latest DodgeRetort – GAO: Federal CIO’s need to focus more on information man ...</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Thinking+About+the+Traditional+Approach&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F09%2Fthinking-about-the-traditional-approach%2F&nr_ad_number=0&nr_div_number=6");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_6");nRelate.adAnimation("nrelate_related_6");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/09/thinking-about-the-traditional-approach/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Running the Gauntlet &#8212; Hacker Convention Prep Guide</title>
		<link>http://ctovision.com/2011/08/running-the-gauntlet-hacker-convention-prep-guide/</link>
		<comments>http://ctovision.com/2011/08/running-the-gauntlet-hacker-convention-prep-guide/#comments</comments>
		<pubDate>Mon, 01 Aug 2011 15:15:25 +0000</pubDate>
		<dc:creator>BryanHalfpap</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Cell Phone]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech/Internet]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=13263</guid>
		<description><![CDATA[Tweet As the various intelligence agencies, computer security companies, and hackers prepare for the week of convention carnage that is Blackhat (Going on now), Defcon, and BSidesLV, it&#8217;s important to remember how easy it is for security professionals to end up on the dreaded &#8220;wall of sheep&#8221; (a very public listing of usernames and partially-redacted [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F08%2Frunning-the-gauntlet-hacker-convention-prep-guide%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/08/running-the-gauntlet-hacker-convention-prep-guide/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/08/running-the-gauntlet-hacker-convention-prep-guide/"  data-text="Running the Gauntlet &#8212; Hacker Convention Prep Guide" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/08/running-the-gauntlet-hacker-convention-prep-guide/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/08/running-the-gauntlet-hacker-convention-prep-guide/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://ctovision.com/wp-content/uploads/2011/08/dc19-logo_smsq.png"><img class="alignleft size-full wp-image-13264" style="margin-right: 4px; margin-left: 4px; margin-top: 6px; margin-bottom: 6px;" title="dc19-logo_smsq" src="http://ctovision.com/wp-content/uploads/2011/08/dc19-logo_smsq.png" alt="" width="144" height="144" /></a></p>
<div>
<p id="internal-source-marker_0.8763067091349512" dir="ltr">As the various intelligence agencies, computer security companies, and hackers prepare for the week of convention carnage that is Blackhat (Going on now), Defcon, and BSidesLV, it&#8217;s important to remember how easy it is for security professionals to end up on the dreaded &#8220;wall of sheep&#8221; (a very public listing of usernames and partially-redacted passwords pilfered from the network and displayed to all). It&#8217;s not considered a surprise to get hacked and infected while there &#8212; it&#8217;s almost expected.  You have to be aware of your surroundings while schmoozing with hackers of every nationality, background, and moral code.  You have to be prepared: mentally, physically, and digitally.</p>
<h2>Mental Security:</h2>
<p>Before wading into an event as socially oriented as Defcon, you should know what you can and can&#8217;t talk about.  People will understand if you can&#8217;t talk about something because of an NDA, but if you make it seem really juicy, you&#8217;re just making yourself a target and you probably shouldn&#8217;t have brought it up.  If you can&#8217;t say to yourself: &#8220;My boss/security officer would be OK with this.&#8221; then you probably shouldn’t talk about it. While one question does not constitute a security threat, you should always be wary of disclosing information on corporate IT infrastructure if someone seems less than on the level.</p>
<h2>Physical Security:</h2>
<p>In a community that rewards physical security intrusion prowess as much as it does digital intrusions (and any mix thereof) it pays to pay attention to physical security.  Make sure anything sensitive to you or your company’s Operational Security is under lock and key(pad).  If that means putting your laptop in a safe because it&#8217;s an unwiped work laptop, then that&#8217;s what you should do.  It&#8217;s not hard to trick hotel staff.</p>
<p>Items such as RFID cards, bluetooth devices without encryption, magstripe cards, and access tokens should be accounted for at all times, especially RFID cards, since they are easy to clone, even from a distance.  All of these things can significantly impact your security and the security of your employer if lost or stolen.  Unless absolutely nessecary, never bring RFID cards, Access or ID badges, or RSA tokens to a security conference &#8212; you might even be made an example of in a presentation if you do (it&#8217;s happened before).</p>
<h2>Digital Security:</h2>
<p><strong>Updates:</strong></p>
<p>This should be the most obvious to people, yet it never fails to be left undone.  Update everything and check the week before you go, just in case there is a last-minute update from a vendor affected by something at the conference.  You won&#8217;t want to be walking around with a vulnerable computer when everyone is looking for a target to test out the new exploit.</p>
<p><strong>Encryption:</strong></p>
<p>An oft-overlooked protection against theft is full disk encryption, but only when it&#8217;s used correctly.  If you set up encryption on your laptop, make sure that hibernation and suspend states are being protected by something as well.  Failing to do this could mean that all your preparation and encryption goes to waste if the computer is on while stolen.  Be sure to also encrypt any sensitive files on your phone and your USB drives.</p>
<p><strong>Set Passwords:</strong></p>
<p>Double-check that your operating system&#8217;s auto-login feature is disabled, that you don&#8217;t have passwords stashed away inside the battery bay of your laptop or phone, and that your phone is set to require a password.  Be sure to clean your touchscreen devices after entering your password so that a thief can&#8217;t use your fingerprints to determine the password.</p>
<p><strong>Prevent Data Leakage:</strong></p>
<p>Should you be crazy (or desperate) enough to use the wifi, be sure to use HTTPS connections with NO certificate errors.  Even with this precaution, don’t be too sure.  There have been several issues found in SSL implementations in programs in the past few years, and it’s best to be safe.  If you have to use the internet, use your mobile phone as a tether or use SSH encryption.</p>
<p>SSH Tunneling is a great way to stay secure on the road by using it as a tunnel to another server (assuming you have one that you wish to use).  Create a tunnel to shove your internet traffic through by creating a local proxy with the -D command-line option.  The syntax is ssh -D [PORT] [username]@[IP ADDRESS].  Then set the proxy settings on your browser of choice to “localhost” for the hostname of the proxy, and [PORT] for the port.  It’s a socks proxy, so be sure to select that option.  This method works on Windows using Cygwin or Putty as well as Linux.</p>
<p>SSH Tunnels encrypt your traffic to and from your server, ensuring the security of your local connection, so long as you heed any warnings about changed keys (this could mean someone is attempting to intercept your traffic).</p>
<p><strong>Phones:</strong></p>
<p>Install tracking software with remote wipe and backup capabilities.  Lookout is a great application for android that combines all the features together.  You&#8217;ll sleep easier knowing that if your phone is lost or stolen, you can still wipe it and have all your data offsite.</p>
<h2>Security Checklist</h2>
<p><strong>Disable the following:</strong></p>
<ul>
<ul>
<li>Any Ad-Hoc wireless network holdovers from XP (free public wifi, hpsetup, ect&#8230;) these can be used to connect to and take advantage of your computer in many nefarious ways.</li>
<li>Any phone wifi hotspots, unless you have WPA2 encryption with a strong password/passphrase.</li>
<li>Boot from CD (unless you are using a liveCD system)</li>
<li>Autorun (if not already disabled)</li>
<li>Any Unnecessary Services (Filesharing in particular)</li>
</ul>
</ul>
<p><strong>Enable the Following:</strong></p>
<ul>
<ul>
<li>Screensaver lock</li>
<li>BIOS passwords</li>
<li>Hard drive passwords</li>
</ul>
</ul>
<p><strong>Mental:</strong></p>
<ul>
<ul>
<li>Check NDA&#8217;s</li>
<li>Check materials being brought to conference.  Do I really need this USB drive to come with me?</li>
</ul>
</ul>
<p><strong>Physical:</strong></p>
<ul>
<ul>
<li>Are my RFID badges out of my wallet?</li>
<li>Are my ID badges out of my wallet?</li>
<li>Do I have to bring my authentication tokens?</li>
<ul>
<li>Do I have a safe place to put my tokens in the hotel?</li>
</ul>
</ul>
</ul>
<p><strong>Digital:</strong></p>
<ul>
<ul>
<li>Am I using an encrypted tunnel to the internet?</li>
<li>Are my thumbdrives encrypted?</li>
<li>Are my devices encrypted?</li>
<li>Did I do updates the same week I leave?</li>
<li>Are all the applications up-to-date, including my Antivirus?</li>
<li>Do I have login passwords set and required for all my devices?</li>
</ul>
</ul>
<p><strong>Potential Rookie Mistakes:</strong></p>
<p>If you want to go a notch above secure and just below paranoid, some people recommend that you use non-persistent liveCD operating systems booted from USB.  I do NOT recommend this as they are usually at least somewhat out-of-date and can&#8217;t be updated (because they are non-persistent, even on USB).</p>
<p>Stay safe out there!</p>
<p>&nbsp;</p>
</div>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=d90e4b9b-772e-4d3f-bebe-64d56f00f1ce" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_7" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/08/social-engineering-hacking-by-asking/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/fb309384cad5c2ed1bf0ffaa493f4910_thumb_socialengineering-300x195.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Social Engineering -- Hacking by Asking</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/02/feds-fight-cyberattacks-on-public-image/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/evening-in-marlborough-sounds.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Feds fight cyberattacks on public image</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/feds-concerned-about-hackers-opening-prison-doors/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/art-rhododendron-flower.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Feds concerned about hackers opening prison doors</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/pentagon-weighing-how-to-respond-to-cyberattacks/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/variety-of-short-grass-on-field.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Pentagon Weighing How to Respond to Cyberattacks</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/globalsign-stops-issuing-security-certificates-pending-probe/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunset-free-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">GlobalSign Stops Issuing Security Certificates Pending Probe</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Running+the+Gauntlet+%26%238212%3B+Hacker+Convention+Prep+Guide&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F08%2Frunning-the-gauntlet-hacker-convention-prep-guide%2F&nr_ad_number=0&nr_div_number=7");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_7");nRelate.adAnimation("nrelate_related_7");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/08/running-the-gauntlet-hacker-convention-prep-guide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using Triumfant for Secure Configuration and Change Management</title>
		<link>http://ctovision.com/2011/07/triumfant-administration-shakeup/</link>
		<comments>http://ctovision.com/2011/07/triumfant-administration-shakeup/#comments</comments>
		<pubDate>Tue, 19 Jul 2011 22:56:57 +0000</pubDate>
		<dc:creator>BryanHalfpap</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[The Future]]></category>
		<category><![CDATA[Web2.0]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[The Future of Technology]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=13155</guid>
		<description><![CDATA[Tweet It’s late Monday morning when your computer security department notices that a suspicious message has been emailed to most of the email addresses at your company. It contains a malicious PDF that exploits a new vulnerability that came out over the weekend. The patch hasn’t been applied to the company workstations yet, and it’s [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F07%2Ftriumfant-administration-shakeup%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/07/triumfant-administration-shakeup/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/07/triumfant-administration-shakeup/"  data-text="Using Triumfant for Secure Configuration and Change Management" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/07/triumfant-administration-shakeup/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/07/triumfant-administration-shakeup/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><img class="alignleft" title="Triumfant" src="http://www.triumfant.com/Images/logo_117x100.jpg" alt="Triumfant Logo" width="217" height="200" />It’s late Monday morning when your computer security department notices that a suspicious message has been emailed to most of the email addresses at your company. It contains a malicious PDF that exploits a new vulnerability that came out over the weekend. The patch hasn’t been applied to the company workstations yet, and it’s too little, too late by the time the email goes out telling everyone not to click on the links.</p>
<p>By the time inboxes are scrubbed and most of the infections have been catalogued it’s clear that this is going to be a security nightmare, since a few dozen machines have been compromised. The attack will take a week or more to fix as desktops are reloaded, servers are checked for more intrusions, and any data losses are reported to the proper authorities.</p>
<p>This is how computer security has been operating at most corporations for a decade. Now enter the world of Secure Configuration and Change Management, or SCCM. SCCM can take the infection turnaround time from days and weeks to minutes or hours, and one of the products leading the charge is Triumfant.</p>
<p>Triumfant’s Configuration and Change Management Tool is an almost completely self-sufficent heuristic scanning software algorithm that manages to neatly sidestep some of the problems with traditional heuristic detection using a combination of patented intellectual property and a gradually changing baseline scanner that is able to move with an IT environment instead of against it.</p>
<p>In a Triumfant environment, baseline behaviors are scanned in groups weekly. These weekly scans are then compared against nightly aggregations of endpoint scans. The nightly aggregations are in turn made up of changes tracked by the user-agent on the endpoint. By comparing gradual baselines within user-defined groups, Triumfant is better able to understand what is and isn’t anomalous, thereby eliminating false positives and negatives.</p>
<p><strong><br />
</strong></p>
<h2>How are anomalies detected?</h2>
<p>The agent on the endpoint hashes all of the files on the hard disk with a cryptographic algorithm, generating a fingerprint for each file. If a file is changed, then the hash will change, signaling a need to compare the old and new versions. The endpoint agent then performs change detection sweeps, comparing hashes of older scans against the MD5 hashes of the current scan. When something changes, a flag is raised and an entry is made in a local change database. The agent also scans a list of over 3000 metrics (such as registry settings) that determine the behavior of the computer.</p>
<p>Every minute, the client makes a connection request to the Triumfant server. If the server responds with a request for the list of recent changes (which it does by default every night) the list is uploaded. All databases and lists are encrypted and signed.</p>
<p>When a rouge application, malware, or an unauthorized user make changes in the system registry, adds files to the hard drive, or modifies critical files in system directories, the endpoint client detects these changes and adds them to a behavior profile. If the behavior is deemed to be malicious, Triumfant flags it as a rouge application and gathers the related system events and changes up into a single, coherent event and prepares them for reversal in remediation. No white- or black-listing is used in this technique, meaning that the server does not need to be constantly updated with new profiles or lists, other than Microsoft windows update signatures, which are used to help determine the patch status of a machine.</p>
<p><strong><br />
</strong></p>
<h2>Remediation:</h2>
<p>Once an undesirable change or application has been discovered, and cataloged, it is presented to an administrator via the Triumfant web interface. The web interface is a highly customisable AJAX application that allows for the creation of new views, reports with charts and graphics, users with different groups and permissions, and the ability to remediate issues with only a few simple clicks.</p>
<p>Simply click on the problem, then click on the remediation button in the left-hand corner. The remediation will be performed automatically by the tool, then put into the list of remediated issues automatically. If for some reason the remediation cant be performed, then it is placed in the “unsuccessful remediation” category.  Unsuccessful remediations are not commonplace.  Even if important system files are deleted or corrupted, computers in the same group are able to copy files for other group members to use, provided that the hash values matched before corruption or deletion.</p>
<p><strong><br />
</strong></p>
<h2>Taking it further:</h2>
<p>Triumfant has extrapolated on their heuristic detection and automatic remedition because the scanning technology behind it can do so much more. Triumfant scans over 3000 parameters for use in their tool, and it collects this data inside of a large, highly-opimised database, allowing it to be easily used for other applications, such as compliance testing.</p>
<p>Inside of the Triumfant server tool, administrators can import SCAP files to use as templates in compliance testing. Once Triumfant has scanned it’s member computers and determined that they are outside of compliance, the template will be used to build remediations against whatever parameters are out of alignment with the SCAP specifications.</p>
<p>Triumfant can also take the data from its database and insert it into a variety of third-party applications with which it has integration, including ePO and the Remedy ticketing system for high cohesion with existing software. Triumfant has custom-built integration for custom ticketing and tracking systems as well.</p>
<p><strong><br />
</strong></p>
<h2>Past and Present:</h2>
<p>Due to the problems associated with heuristic detection, most CCM software has not seen deep market penetration. Triumfant’s tool has been around for some time, having been fire tested at the pentagon for almost 4 years now, while the company has been around since 2002.</p>
<p>In the next few months, Triumfant will be debuting an updated version of their tool that is able to perform all of it’s functions on Macs as well as Windows computers. By the end of the year a Unix or Unix-variant (Linux, BSD, Solaris) should be out, followed by smartphone variations.</p>
<p>Tools such as Triumfant may very well become the future of computer security configuration management over the next few years. Tools like those provided by Triumfant offer ease of use without sacrificing security, bringing thousand-system compliance requirements into the reach of even small IT security departments. It&#8217;s ability to remediate nasty infections (like rootkits) give it a leg up on many anti-virus vendors which must release signatures, patches, and fixes and which will forever lag behind heuristic detection technology.</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_8" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/art-rhododendron-flower.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Yesterday's Security Doesn't Work for Today's Threats</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/the-evolving-enterprise-threat-environment/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/26bba1be39a5b1601cf7dfaa47327590_thumb_LockedComputer.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The Evolving Enterprise Threat Environment</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/07/invincea-and-triumfant-two-firms-filling-important-roles-in-enterprise-it/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/ca35e4df6edcea1badd7031f4320fca1_thumb_computer_security.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Invincea and Triumfant: two firms filling important roles in enterprise IT</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/01/some-context-on-malware-in-the-enterprise/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/e6ff3b6c0fa2bb1378b75f072aa77c94_thumb_invincea.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Some Context on Malware in the Enterprise</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/12/mobile-apps-can-have-strategic-impact-if-mobile-risk-can-be-managed/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/0f6dc483ae417e653abc13edcfbed18e_thumb_imQ8zCUBakyM.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Mobile Apps Can Have Strategic Impact: If Mobile Risk Can Be Managed</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/yesterday%e2%80%99s-security-doesn%e2%80%99t-work-for-today%e2%80%99s-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunset-free-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Yesterday’s Security Doesn’t Work for Today’s Threats</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/02/triumfant-a-new-approach-to-it-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-city-windows.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Triumfant: A New Approach to IT Security</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/12/granola-disruptive-technology-without-the-disruption/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-old-wood.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Granola: Disruptive Technology without the Disruption</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/12/register-for-16-dec-webinar-on-what-the-cio-and-cto-need-to-know-about-developing-secure-code/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/evening-in-marlborough-sounds.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Register for 16 Dec webinar on what the CIO and CTO need to know about develo ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/11/special-summary-enterprise-security-stories/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/ice-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Special Summary: Enterprise security stories</span><span class="nr_source">Bob Gourley</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Using+Triumfant+for+Secure+Configuration+and+Change+Management&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F07%2Ftriumfant-administration-shakeup%2F&nr_ad_number=0&nr_div_number=8");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_8");nRelate.adAnimation("nrelate_related_8");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/07/triumfant-administration-shakeup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CTOVision.com Monthly Tech Review</title>
		<link>http://ctovision.com/2011/05/ctovision-com-monthly-tech-review/</link>
		<comments>http://ctovision.com/2011/05/ctovision-com-monthly-tech-review/#comments</comments>
		<pubDate>Sun, 01 May 2011 11:39:39 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Big Data]]></category>
		<category><![CDATA[CTO]]></category>
		<category><![CDATA[cio]]></category>
		<category><![CDATA[CISO]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Mailing list]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=12617</guid>
		<description><![CDATA[Tweet The CTOVision.com Monthly Tech Review provides a recap of the hottest technology trends in industry and government. You can sign up using the form below. We appreciate our subscribers and will never sell your e-mail. Our newsletter production system gives you easy ways to put your subscription on hold or unsubscribe if you desire. [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F05%2Fctovision-com-monthly-tech-review%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/05/ctovision-com-monthly-tech-review/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/05/ctovision-com-monthly-tech-review/"  data-text="CTOVision.com Monthly Tech Review" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/05/ctovision-com-monthly-tech-review/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/05/ctovision-com-monthly-tech-review/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>The CTOVision.com Monthly Tech Review provides a recap of the hottest technology trends in industry and government. You can sign up using the form below.</p>
<p>We appreciate our subscribers and will never sell your e-mail. Our newsletter production system gives you easy ways to put your subscription on hold or unsubscribe if you desire.</p>
<p>Please sign up and let us know what you think about our reporting and analysis.</p>
<p>(We also produce the <a href="http://ctolabs.com/government-big-data-newsletter-sign-up/" target="_blank">Government Big Data Newsletter</a> and would appreciate you signing up there as well).</p>
<h2 style="text-align: center;">Subscribe to the CTOvision.com Monthly Tech Review<br />
<!--[endif] --><br />
<!--[if IE 7]><br />
<mce:style type="text/css" media="screen"><! .mc-field-group {overflow:visible;} --><br />
<!--[endif] --></h2>
<div id="mc_embed_signup">
<form id="mc-embedded-subscribe-form" class="validate" style="font: normal 100% Arial, sans-serif; font-size: 10px;" action="http://ctovision.us1.list-manage.com/subscribe/post?u=4cb4c08d876d7481bbc4bc70f&amp;id=df49dcb58c" method="post">
<fieldset style="border-radius: 4px; border: 1px solid #ccc; padding-top: 1.5em; margin: .5em 0; background-color: #fff; color: #000; text-align: left;">
<legend style="white-space: normal; text-transform: capitalize; font-weight: bold; color: #000; background: #fff; padding: .5em 1em; border: 1px solid #ccc; border-radius: 4px; font-size: 1.2em;"><span>join our mailing list</span></legend>
<div class="indicate-required" style="text-align: right; font-style: italic; overflow: hidden; color: #000; margin: 0 9% 0 0;">* indicates required</div>
<div class="mc-field-group" style="margin: 1.3em 5%; clear: both; overflow: hidden;"><label style="display: block; margin: .3em 0; line-height: 1em; font-weight: bold;" for="mce-EMAIL">Email Address <strong class="note-required">*</strong><br />
</label>&nbsp;</p>
<input id="mce-EMAIL" class="required email" style="margin-right: 1.5em; padding: .2em .3em; width: 90%; float: left; z-index: 999;" name="EMAIL" type="text" />
</div>
<div class="mc-field-group" style="margin: 1.3em 5%; clear: both; overflow: hidden;">
<p><label class="input-group-label" style="display: block; margin: .3em 0; line-height: 1em; font-weight: bold;">Email Format </label></p>
<div class="input-group" style="padding: .7em .7em .7em 0; font-size: .9em; margin: 0 0 1em 0;">
<ul style="margin: 0; padding: 0;">
<li style="list-style: none; overflow: hidden; padding: .2em 0; clear: left; display: block; margin: 0;">
<input id="mce-EMAILTYPE-0" style="margin-right: 2%; padding: .2em .3em; width: auto; float: left; z-index: 999;" name="EMAILTYPE" type="radio" value="html" /><label style="display: block; margin: .4em 0 0 0; line-height: 1em; font-weight: bold; width: auto; float: left; text-align: left !important;" for="mce-EMAILTYPE-0">html</label></li>
<li style="list-style: none; overflow: hidden; padding: .2em 0; clear: left; display: block; margin: 0;">
<input id="mce-EMAILTYPE-1" style="margin-right: 2%; padding: .2em .3em; width: auto; float: left; z-index: 999;" name="EMAILTYPE" type="radio" value="text" /><label style="display: block; margin: .4em 0 0 0; line-height: 1em; font-weight: bold; width: auto; float: left; text-align: left !important;" for="mce-EMAILTYPE-1">text</label></li>
<li style="list-style: none; overflow: hidden; padding: .2em 0; clear: left; display: block; margin: 0;">
<input id="mce-EMAILTYPE-2" style="margin-right: 2%; padding: .2em .3em; width: auto; float: left; z-index: 999;" name="EMAILTYPE" type="radio" value="mobile" /><label style="display: block; margin: .4em 0 0 0; line-height: 1em; font-weight: bold; width: auto; float: left; text-align: left !important;" for="mce-EMAILTYPE-2">mobile</label></li>
</ul>
</div>
</div>
<div>
<input id="mc-embedded-subscribe" class="btn" style="clear: both; width: auto; display: block; margin: 1em 0 1em 5%;" name="subscribe" type="submit" value="Subscribe" /></div>
</fieldset>
<p><a id="mc_embed_close" class="mc_embed_close" style="display: none;" href="#">Close</a></p>
</form>
</div>
<p><script type="text/javascript">// <![CDATA[
 var fnames = new Array();var ftypes = new Array();fnames[0]='EMAIL';ftypes[0]='email';fnames[1]='FNAME';ftypes[1]='text';fnames[2]='LNAME';ftypes[2]='text'; try {     var jqueryLoaded=jQuery;     jqueryLoaded=true; } catch(err) {     var jqueryLoaded=false; } var head= document.getElementsByTagName('head')[0]; if (!jqueryLoaded) {     var script = document.createElement('script');     script.type = 'text/javascript';     script.src = 'http://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js';     head.appendChild(script);     if (script.readyState &#038;&#038; script.onload!==null){         script.onreadystatechange= function () {               if (this.readyState == 'complete') mce_preload_check();         }         } } var script = document.createElement('script'); script.type = 'text/javascript'; script.src = 'http://downloads.mailchimp.com/js/jquery.form-n-validate.js'; head.appendChild(script); var err_style = ''; try{     err_style = mc_custom_error_style; } catch(e){     err_style = 'margin: 1em 0 0 0; padding: 1em 0.5em 0.5em 0.5em; background: FFEEEE none repeat scroll 0% 0%; font-weight: bold; float: left; z-index: 1; width: 80%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; color: FF0000;'; } var head= document.getElementsByTagName('head')[0]; var style= document.createElement('style'); style.type= 'text/css'; if (style.styleSheet) {   style.styleSheet.cssText = '.mce_inline_error {' + err_style + '}'; } else {   style.appendChild(document.createTextNode('.mce_inline_error {' + err_style + '}')); } head.appendChild(style); setTimeout('mce_preload_check();', 250); var mce_preload_checks = 0; function mce_preload_check(){     if (mce_preload_checks>40) return;
    mce_preload_checks++;
    try {
        var jqueryLoaded=jQuery;
    } catch(err) {
        setTimeout('mce_preload_check();', 250);
        return;
    }
    try {
        var validatorLoaded=jQuery("#fake-form").validate({});
    } catch(err) {
        setTimeout('mce_preload_check();', 250);
        return;
    }
    mce_init_form();
}
function mce_init_form(){
    jQuery(document).ready( function($) {
      var options = { errorClass: 'mce_inline_error', errorElement: 'div', onkeyup: function(){}, onfocusout:function(){}, onblur:function(){}  };
      var mce_validator = $("#mc-embedded-subscribe-form").validate(options);
      options = { url: 'http://ctovision.us1.list-manage1.com/subscribe/post-json?u=4cb4c08d876d7481bbc4bc70f&#038;id=df49dcb58c&#038;c=?', type: 'GET', dataType: 'json', contentType: "application/json; charset=utf-8",
                    beforeSubmit: function(){
                        $('#mce_tmp_error_msg').remove();
                        $('.datefield','#mc_embed_signup').each(
                            function(){
                                var txt = 'filled';
                                var fields = new Array();
                                var i = 0;
                                $(':text', this).each(
                                    function(){
                                        fields[i] = this;
                                        i++;
                                    });
                                $(':hidden', this).each(
                                    function(){
                                    	if ( fields[0].value=='MM' &#038;&#038; fields[1].value=='DD' &#038;&#038; fields[2].value=='YYYY' ){
                                    		this.value = '';
									    } else if ( fields[0].value=='' &#038;&#038; fields[1].value=='' &#038;&#038; fields[2].value=='' ){
                                    		this.value = '';
									    } else {
	                                        this.value = fields[0].value+'/'+fields[1].value+'/'+fields[2].value;
	                                    }
                                    });
                            });
                        return mce_validator.form();
                    }, 
                    success: mce_success_cb
                };
      $('#mc-embedded-subscribe-form').ajaxForm(options);      </p>
<p>    });
}
function mce_success_cb(resp){
    $('#mce-success-response').hide();
    $('#mce-error-response').hide();
    if (resp.result=="success"){
        $('#mce-'+resp.result+'-response').show();
        $('#mce-'+resp.result+'-response').html(resp.msg);
        $('#mc-embedded-subscribe-form').each(function(){
            this.reset();
    	});
    } else {
        var index = -1;
        var msg;
        try {
            var parts = resp.msg.split(' - ',2);
            if (parts[1]==undefined){
                msg = resp.msg;
            } else {
                i = parseInt(parts[0]);
                if (i.toString() == parts[0]){
                    index = parts[0];
                    msg = parts[1];
                } else {
                    index = -1;
                    msg = resp.msg;
                }
            }
        } catch(e){
            index = -1;
            msg = resp.msg;
        }
        try{
            if (index== -1){
                $('#mce-'+resp.result+'-response').show();
                $('#mce-'+resp.result+'-response').html(msg);            
            } else {
                err_id = 'mce_tmp_error_msg';
                html = '</p>
<div id="'+err_id+'" style="'+err_style+'"> '+msg+'</div>
<p>';</p>
<p>                var input_id = '#mc_embed_signup';
                var f = $(input_id);
                if (ftypes[index]=='address'){
                    input_id = '#mce-'+fnames[index]+'-addr1';
                    f = $(input_id).parent().parent().get(0);
                } else if (ftypes[index]=='date'){
                    input_id = '#mce-'+fnames[index]+'-month';
                    f = $(input_id).parent().parent().get(0);
                } else {
                    input_id = '#mce-'+fnames[index];
                    f = $().parent(input_id).get(0);
                }
                if (f){
                    $(f).append(html);
                    $(input_id).focus();
                } else {
                    $('#mce-'+resp.result+'-response').show();
                    $('#mce-'+resp.result+'-response').html(msg);
                }
            }
        } catch(e){
            $('#mce-'+resp.result+'-response').show();
            $('#mce-'+resp.result+'-response').html(msg);
        }
    }
}
// ]]&gt;</script><br />
<!--End mc_embed_signup--><br />
Or see: <a href="http://eepurl.com/cQT_2" target="_blank">http://eepurl.com/cQT_2</a></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=f8f2eea3-93b4-4b12-8a82-ba2120b3ecda" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_9" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/signing-up-for-our-newsletters-and-tech-reports/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/e4708c72a67232bdf7aab53b8f0a99c9_thumb_ctovisionsquare.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Signing up for our Newsletters and Tech Reports</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2012/01/ctovision-newsletters-and-tech-reports/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/76f2094ad9eecb172cb2b705153e67f6_thumb_ctovisionsquare.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">CTOvision Newsletters and Tech Reports</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/08/please-sign-up-for-our-newsletters-and-tech-reports/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/0cabc4e7c4ec0bc0ed87b72d41d5ebc9_thumb_computer-technology-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Please Sign Up For Our Newsletters and Tech Reports</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/07/technology-context-delivered-the-way-you-want-it/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/170efd135ae8848ca38d2bdb18b2d576_thumb_internet_world_copy.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Technology Context Delivered The Way You Want It</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/nominating-technologies-for-review-at-ctolabs-com/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/a9eb3edce3d5c67a7bf299ecbc588db5_thumb_digitalglobe.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Nominating Technologies For Review At CTOlabs.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/stay-informed-sign-up-for-our-tailored-tech-newsletters-and-tech-reports/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/weather-station-robe-south-australia.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Stay Informed: Sign up for our Tailored Tech Newsletters and Tech Reports</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/02/a-swarm-of-nano-quadrotors-the-flying-robot-video-you-absolutely-must-watch/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/mosaic-detail.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">A Swarm of Nano Quadrotors: The flying robot video you absolutely must watch</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/crucial-point-provides-premium-content-via-newsletters-and-tech-reports/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/wave-open-sea.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Crucial Point Provides Premium Content Via Newsletters and Tech Reports</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/12/tech-of-occupywallstreet/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/evening-in-marlborough-sounds.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Tech of #OccupyWallStreet</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/07/announcing-the-new-ctovision-com/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/0cabc4e7c4ec0bc0ed87b72d41d5ebc9_thumb_computer-technology-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Announcing The New CTOvision.com</span><span class="nr_source">CTOvision.com</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=CTOVision.com+Monthly+Tech+Review&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F05%2Fctovision-com-monthly-tech-review%2F&nr_ad_number=0&nr_div_number=9");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_9");nRelate.adAnimation("nrelate_related_9");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/05/ctovision-com-monthly-tech-review/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Making vPro Work For You</title>
		<link>http://ctovision.com/2011/04/making-vpro-work-for-you/</link>
		<comments>http://ctovision.com/2011/04/making-vpro-work-for-you/#comments</comments>
		<pubDate>Sat, 30 Apr 2011 10:13:59 +0000</pubDate>
		<dc:creator>BryanHalfpap</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Disruptive IT]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[Intel]]></category>
		<category><![CDATA[Intel Active Management Technology]]></category>
		<category><![CDATA[Intel Core 2]]></category>
		<category><![CDATA[Intel Corporation]]></category>
		<category><![CDATA[Intel vPro]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Personal computer]]></category>
		<category><![CDATA[The Future of Technology]]></category>
		<category><![CDATA[Trusted Execution Technology]]></category>
		<category><![CDATA[Wi-Fi]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=12458</guid>
		<description><![CDATA[Tweet vPro is a suite of high-impact technology that has just begun to make its presence known in mainstream IT organizations.  vPro can help you bring your organization&#8217;s security structure into shape with features that make a dramatic positive difference. vPro technologies are implemented in the hardware and firmware of the Intel chipset in Intel [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F04%2Fmaking-vpro-work-for-you%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/04/making-vpro-work-for-you/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/04/making-vpro-work-for-you/"  data-text="Making vPro Work For You" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/04/making-vpro-work-for-you/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/04/making-vpro-work-for-you/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><div>
<p><a href="http://ctovision.com"><img class="alignleft size-medium wp-image-12624" style="margin: 4px;" title="intel-logo" src="http://ctovision.com/wp-content/uploads/2011/04/intel-logo-300x198.jpg" alt="" width="300" height="198" /></a>vPro is a suite of high-impact technology that has just begun to make its presence known in mainstream IT organizations.  vPro can help you bring your organization&#8217;s security structure into shape with features that make a dramatic positive difference.</p>
<p>vPro technologies are implemented in the hardware and firmware of the Intel chipset in Intel Core 2 Duo computers and above (at the bottom of this post is a link to a list of vPro-enabled processors) which can provide everything from secure remote management to hardware-assisted virtualization.  This suite of technologies holds many computer security advantages for the corporations willing and able to take advantage of them.</p>
<p>When you hear vPro think of Active Management Technology (AMT) and Trusted Execution Technology (TXT).  There are other capabilities in vPro but these are the first two we recommend implementing to dramatically enhance your enterprise security.</p>
<h3>Active Management Technology</h3>
<p>AMT is the Intel implementation of the open DASH standard (DASH stands for Desktop and Mobile Architecture for System Hardware) of the Distributed Management Task Force (DMTF). Consider an enterprise where computers may need to have a significant amount of reliable up-time through business hours. Most of the machines when they are left for the night are shut off, which means that at 1:00am, the only time that IT has to push security updates, most of the computers are off and only receive updates when turned on the next day by students, causing up-time issues.</p>
<p>By utilizing AMT with vPro-enabled chipsets, the enterprise IT shop could turn on all the computers on the network, allow them to receive the update, and then turn them back off when it is finished. This saves the organization time, money, and vulnerability exposure from the thousands of users browsing the internet from the machines each day.</p>
<p>Other AMT technologies that have security uses/implementations are remote KVM at BIOS and the ability to remotely isolate PC’s from the network at a hardware level</p>
<h3>Trusted Execution Technology (TXT):</h3>
<p>The Intel Trusted Execution Technology is instrumental in detecting and preventing malware from running on a vPro-enabled computer. At boot-time, the computer checks the validity of the configurations against stored configurations in protected memory in the processor. If the two don’t match, then it can be safely assumed that some tampering has occurred.</p>
<p>The same sort of approach is also taken with encryption key management. The keys are encrypted within hardware, but will only be decrypted when the environment is the same as when the keys were first encrypted. Thus preventing key theft in the event of exploitation.</p>
<p>The TXT system also allows for increased protection with the both the display and the input of data to a system with TXT-developed software. USB keyboards can be configured to have encrypted communications with the system, and software applications can be developed using more secure system calls to the computer display, preventing applications that sniff internal communications from stealing sensitive information.</p>
<h3>Theft Protection:</h3>
<p>Theft protection is one of the biggest and most-developed areas of the vPro technology suite.  By utilizing the out-of-band communication capabilities built-in the to vPro system, some proprietary Intel technologies, and a 3G wireless connection built into the laptop, fears about stolen laptops and desktops can be alleviated quickly and efficiently using a “poison pill”.</p>
<p>The poison pill is a code that can be sent remotely by system administrators from an asset management console to the device to render it inaccessible and useless by deleting encryption keys and disabling key boot processes. This code can be sent via wireless 3G, wired, WiFi, or SMS to the target device. When the poison pill is sent, the target computer. Different conditions can be set for the computer to activate its theft mode locally as well, such as a specified number of login failures, or failure to check in with the remote server after a designated time interval.</p>
<h3>Beyond the Boundaries:</h3>
<h3><span style="font-size: 13px; font-weight: normal;">Today’s businesses are more and more often placing people outside of the relative safety of the internal corporate network and into unknown and sometimes even dangerous locales. By setting up a secure method of communications with the corporate network, companies can be more assured of the integrity, confidentiality, and accessibility of their data. But how does a company go about implementing this?</span></h3>
<p>By building a network from the ground-up with compliant hardware, and utilizing a vPro gateway, properly configured clients will be able to establish highly secured and encrypted communications throughout their travels. By combining the security and management features with the roaming security tunnels, a fairly secure system with high accessibility could be achieved by a determined organization.</p>
<h3>Comparisons to “Current” Tech:</h3>
<p>Most of the issues with current tech is the lack of high-level integration with the hardware, firmware, and software of a computer in the sense that usually a software breach can compromise firmware and sometimes hardware. What the vPro system has done is reduced the available information to be gained from exploiting the operating system, automatically disabled infected and stolen computers, and created a remote viewing and on/off switch that has a high degree of manageability.</p>
<p>Current solutions generally don’t stand up to the same kinds of tasks because the solutions require complex hardware solutions that Intel is offering here in the form of AMT and their Third Party Protected Storage system. Sure, a company could continue to use full disk encryption, VPN’s, and Active Directory, but these solutions lack Out-of-Band communications with hardware, and are all software solutions with their own separate flaws and vulnerabilities that could each be exploited to affect the others (even the full disk encryption has methods for being defeated.  vPro technologies could mitigate or negate many current attacks).</p>
<h3>More Resources for vPro technology application:</h3>
<p>List of processors supporting vPro: <a href="http://www.intel.com/support/vpro/sb/CS-030703.htm#core17m">http://www.intel.com/support/vpro/sb/CS-030703.htm#core17m</a></p>
<p>Intel vPro Whitepaper: <a href="http://www.intel.com/technology/vpro/pdf/intelcorevprowhitepaper.pdf">http://www.intel.com/technology/vpro/pdf/intelcorevprowhitepaper.pdf</a></p>
<p>More about AMT and its features: <a href="http://cache-www.intel.com/cd/00/00/32/09/320960_320960.pdf">http://cache-www.intel.com/cd/00/00/32/09/320960_320960.pdf</a></p>
</div>
<p>&nbsp;</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://ctovision.com/2011/04/configuring-your-enterprise-hardware-to-nist-standards/">Configuring Your Enterprise Hardware to NIST Standards</a> (ctovision.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=b10d19af-8c44-424c-93f1-ecfdcb739d8c" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_10" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/04/nist-security-configuration-checklist-for-intel-vpro-technology/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/02a0accb4d5e0fa95329531fd61d0feb_thumb_nist-300x133.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">NIST Security Configuration Checklist for Intel vPro Technology</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/03/hardware-really-matters-for-computer-functionality-and-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/b0bde52f1b8fbef2b25cb6a97445f21d_thumb_blue_lock-main-300x300.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Hardware Really Matters for Computer Functionality and Security</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/yesterday%e2%80%99s-security-doesn%e2%80%99t-work-for-today%e2%80%99s-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/wave-open-sea.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Yesterday’s Security Doesn’t Work for Today’s Threats</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/special-summary-enterprise-security-stories/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-city-windows.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Special Summary: Enterprise security stories</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Making+vPro+Work+For+You&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F04%2Fmaking-vpro-work-for-you%2F&nr_ad_number=0&nr_div_number=10");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_10");nRelate.adAnimation("nrelate_related_10");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/04/making-vpro-work-for-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

