<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CTOvision.com &#187; HP</title>
	<atom:link href="http://ctovision.com/tag/hp/feed/" rel="self" type="application/rss+xml" />
	<link>http://ctovision.com</link>
	<description>News, analysis and context on enterprise technology for the CTO</description>
	<lastBuildDate>Thu, 09 Feb 2012 21:03:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Special Summary: Enterprise security stories</title>
		<link>http://ctovision.com/2011/11/special-summary-enterprise-security-stories/</link>
		<comments>http://ctovision.com/2011/11/special-summary-enterprise-security-stories/#comments</comments>
		<pubDate>Tue, 22 Nov 2011 11:12:22 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Andrzej Kawalec]]></category>
		<category><![CDATA[Big Data]]></category>
		<category><![CDATA[Blog Talk Radio]]></category>
		<category><![CDATA[BobGourley]]></category>
		<category><![CDATA[Chief Information Officer]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[CTOvision]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=14397</guid>
		<description><![CDATA[Tweet The state of computer security is in continual change. The only constant in this game is the very dynamic nature of defense and offense. If you are a defender you will always have a hard job. You will always need to be on the lookout for ways to succeed in the face of a dynamic, never ending [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F11%2Fspecial-summary-enterprise-security-stories%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/11/special-summary-enterprise-security-stories/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/11/special-summary-enterprise-security-stories/"  data-text="Special Summary: Enterprise security stories" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/11/special-summary-enterprise-security-stories/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/11/special-summary-enterprise-security-stories/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><a href="http://ctovision.com/wp-content/uploads/2011/09/digitalglobe.jpg"><img class="alignleft size-medium wp-image-13858" style="margin: 4px;" title="Digital Globe" src="http://ctovision.com/wp-content/uploads/2011/09/digitalglobe-300x193.jpg" alt="" width="300" height="193" /></a>The state of computer security is in continual change. The only constant in this game is the very dynamic nature of defense and offense. If you are a defender you will always have a hard job. You<br />
will always need to be on the lookout for ways to succeed in the face of a dynamic, never ending threat.</p>
<p>This special report is a summary of the <a href="http://ctovision.com/cyber-initiative" target="_blank">Cyber Security</a> category of the<a href="http://ctovision.com" target="_blank"> CTOvision.com</a> blog. This means it is a summary of pieces we know and care about, and we hope these stories generate thoughts and comments and suggestions from you on future content. Please let us know your<br />
thoughts:</p>
<p>Summary:</p>
<p>On 15 July we published two items related to cybersecurity. The first was a pointer to the Department of Defense&#8217;s new cybersecurity strategy titled <a href="http://ctovision.com/2011/07/deputy-secretary-of-defense-lynn-cyber-strategy%e2%80%99s-thrust-is-defensive/" target="_blank">Deputy Secretary of Defense Lynn: Cyber Strategy’s Thrust is Defensive</a></p>
<p>This piece provided an overview of DoD&#8217;s new cyber strategy, a strategy that we think many enterprises can learn from. We also printed a review of a piece of cybersecurity writing that succinctly describes a key failing of overly simplistic security measures titled &#8221;<a href="http://ctovision.com/2011/07/the-maginot-line-of-information-systems-security/" target="_blank">The Maginot Line of Information Systems Security</a>&#8220; It reviews the 1999 advice of cyber security strategist Rick Forno who underscores that &#8220;Good firewalls and other purely technical solutions do their work effectively, but to a clever and determined attacker they are just obstacles to be either broken or side-slipped, whichever is more effective.&#8221;</p>
<p>We also reported on a Brookings institution piece tilted &#8220;<a href="http://ctovision.com/2011/07/pirates-of-the-isps-tactics-for-turning-online-crooks-into-international-pariahs/" target="_blank">Pirates of the ISPs: Tactics for Turning Online Crooks Into International Pariah</a>s&#8221; This review provided a framework that our nation could use to help reduce cyber crime. The bad news is that this type of action will only occur with lots of coordination and leadership and to date we have not seen the broad action required to move this concept forward. Enterprises must continue to mount a vigorous defense without this<br />
type of top cover.</p>
<p>We did note with pleasure the success Microsoft had in battling major criminal organizations, including collecting information leading to the arrest and shutdown of major botnets like Waledac and Rustock. For more see &#8220;<a href="http://ctovision.com/2011/08/microsoft-works-to-tame-the-wild-wild-web/" target="_blank">Microsoft Works To Tame The Wild Wild Web</a>&#8220; Please thank Microsoft at every turn for this great action.</p>
<p>Do you need to learn more about the language of cyber defense? Many in leadership positions find themselves overwhelmed when they are assigned to play roles in cyber defense. The fastest way to learn the new language is to start with a primer on cyber defense taxonomies. We review the greatest of those at &#8220;<a href="http://ctovision.com/2011/08/enhancing-collective-defense-with-taxonomies-for-operational-cyber-defense/" target="_blank">Enhancing Collective Defense with Taxonomies for Operational Cyber Defense.</a>&#8221;</p>
<p>Some of the greatest enterprise defenders gathered in the DC area on September 12, 2011 at the <a href="http://www.arcsight.com/protect2011/" target="_blank">HP Protect conference</a>. Attending this event enabled us to better assess the state of enterprise IT and also provided us with content relevant to our future reporting. For example, Dillon Behr provided a recap on &#8220;<a href="http://ctovision.com/2011/09/bob-gourley-discusses-big-data-security-with-idg/" target="_blank">Big Data Security</a>&#8220; Enterprises everywhere are using increasing amounts of data to make better/faster decisions. Doing so has security ramifications.</p>
<p>Alex Olesker captured content on the &#8220;<a href="http://ctovision.com/2011/09/the-evolving-enterprise-threat-environment/" target="_blank">Evolving Enterprise Threat Environment</a>.&#8221; This included information from an online interview with HP&#8217;s CTO of Enterprise Security, Andrzej Kawalec, as well as the CTOvision.com editor Bob Gourley. This discussion highlighted threads like Spear<br />
Phishing, Malicious Code and Insiders. The discussion also reviewed the threat of insiders and the important trend of cloud computing.</p>
<p>Adam Elkus wrote about the traditional approach to cybersecurity in &#8221;<a href="http://ctovision.com/2011/09/thinking-about-the-traditional-approach/" target="_blank">Thinking About The Traditional Approach</a>&#8221;  And Alex Olesker captured more information on &#8220;<a href="http://ctovision.com/2011/10/big-data-and-the-enterprise-cio-2/" target="_blank">Big Data and the<br />
Enterprise CIO</a>&#8220;, including a video of a discussion with Bob Gourley at HP Protect. Alex would later underscore that &#8220;<a href="http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/" target="_blank">Yesterday&#8217;s Security Doesn&#8217;t Work For Today&#8217;s Threats</a>&#8220; where he reviewed the video of Andrzej Kawalec and Bob Gourley in more detail. Kawalec and Gourley continued their discussions on security in another piece titled &#8220;<a href="http://ctovision.com/2011/10/evolving-approaches-to-cyber-threats-2/" target="_blank">Evolving Approaches to Cyber Threats</a>.&#8221;</p>
<p>Social media is playing multiple roles in cyber security. It is a vector for threats, it is a means for adversaries to learn more about you, and it is also a means for defenders to exchange information on what is happening. As an example of its strength in helping defenders and other IT professionals learn, <a href="http://www.enterprisecioforum.com/en/users/jdodge" target="_blank">John Dodge of the Enterprise CIO Forum</a> and Bob Gourley of CTOvision conducted a series of radio broadcasts and blog posts which were fueled by summaries of hot<br />
security topics noticed in Twitter. The first of these was summarized at <a href="http://ctovision.com/2011/10/blog-talk-radio-with-thedodgeretort-and-bobgourley/" target="_blank">Blog Talk Radio</a><br />
and &#8220;<a href="http://ctovision.com/2011/10/new-enterprise-cio-forum-blog-talk-radio/" target="_blank">New Enterprise CIO Forum Blog Talk Radio</a>&#8221;</p>
<p>Another cyber security opinion piece was captured in a piece that asked the question &#8220;<a href="http://ctovision.com/2011/10/if-you-could-pick-one-thing-for-congress-to-do-regarding-cybersecurity-what-would-it-be/" target="_blank">If You Could Pick One Thing For Congress To Do Regarding Cybersecurity, What Would It Be?</a>&#8220; This piece quotes Abraham Lincoln who stated &#8220;If we could first know where we are, and whither we are tending, we could better judge what to do, and how to do it.&#8221; We reference that as a way of asking for better metrics on cyber security. We believe Congress can help in that regard by requiring more detailed breach reporting from firms.</p>
<p>Bob Gourley and Tom Reilly, Vice President and General Manager of Enterprise Security for HP, provided context on two cybersecurity studies which provided valuable statistics for enterprise professionals. Their video and more on the statistics is at &#8220;<a href="http://ctovision.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/" target="_blank">Survey Says: Security Risks Never Higher, Or Most Costly</a>.&#8221;</p>
<p>Bob and Tom also dove deep into the &#8220;<a href="http://ctovision.com/2011/11/myths-and-realities-of-cloud-security/" target="_blank">Myths and Realities of Cloud Security</a>&#8221;  In this recorded discussion the two discuss the approach of Security Intelligence and Risk Management. Risk management is a construct of increasing importance since all recognize that 100% security is<br />
impossible and therefore tradeoffs and decisions must be made focused on the risk to mission. Security intelligence is a key enabler of smart risk management since it informs on the status of your own mission, your resources, your enterprise and the state of the threat.</p>
<p>Another key event this quarter was the FedCyber.com Government-Industry Cybersecurity Summit. This was a closed event which was attended by a hand selected group of cyber practitioners from government and industry which focused on discussion of new models<br />
for security. To register for the next event stay tuned to <a href="http://fedcyber.com " target="_blank">FedCyber.com</a>. For a short recap of the event see: &#8220;<a href="http://ctovision.com/2011/10/quicklook-report-the-fedcyber-com-government-industry-cybersecurity-summit-of-28-sep-2011/" target="_blank">Quicklook Report: The FedCyber.com Summit of 28 Sep 2011</a>&#8221;</p>
<p>The conclusion of this review of security reporting: Our advice is that security professionals continue to do what you have been doing and continue to work on your agility while at it. You already know that there is no such thing as a perfect defense. And you already know you must establish defense in depth. And you already know you must avail yourself of very smart concepts of operation and must ensure your strategy and your work force are informed. We hope one of your ways of staying informed is by tracking the <a href="http://ctovision.com" target="_blank">CTOvision.com blog</a>. But we write about strategy. You need tactical intelligence feeds continuously updated on the threat. And you need a team of enterprise security architects and designers acting in your interests to continually assess the state of your enterprise.</p>
<p>Let us know please your thoughts on the above. We are especially interested in your ideas for what we should be covering next.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=e74cb92e-2f16-41fa-94bf-d622d5905f82" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_1" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/bob-gourley%e2%80%99s-2012-outlook-%e2%80%9cexpect-disruptions%e2%80%9d/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/c018c1e93edc52116f81a37dfb106aa8_thumb_WashingtonExec.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Bob Gourley’s 2012 Outlook: “Expect Disruptions”</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/thinking-about-the-traditional-approach/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/5c1597bbb9d4aa4103e2166210768a84_thumb_Cavalrycharge.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Thinking About the Traditional Approach</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/note-to-cios-your-organization-will-never-be-100-secure/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/61274150f8f1420a3f5aeb7c253f1892_thumb_keyboard_lock_small.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Note to CIOs: Your organization will never be 100% secure</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/12/tech-review-for-november-2011/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/7a6abed9828705e4a6740dbb2595a8b9_thumb_MP900405500.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Tech Review for November 2011</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/myths-and-realities-of-cloud-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/1566bfe294df4cdcb855d28ec73cb69a_thumb_protect-e1319104550402.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Myths and realities of cloud security</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/the-evolving-enterprise-threat-environment/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/ice-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The Evolving Enterprise Threat Environment</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/new-enterprise-cio-forum-blog-talk-radio/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunset-free-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">New Enterprise CIO Forum Blog Talk Radio</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/wave-open-sea.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Survey says: Security risks never higher, or more costly</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/10/evolving-approaches-to-cyber-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/great-red-wood-circle-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Evolving Approaches to Cyber Threats</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/big-data-and-the-enterprise-cio/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/weather-station-robe-south-australia.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Big Data and the Enterprise CIO</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Special+Summary%3A+Enterprise+security+stories&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F11%2Fspecial-summary-enterprise-security-stories%2F&nr_ad_number=0&nr_div_number=1");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.domain = "ctovision.com";nRelate.fixHeight("nrelate_related_1");nRelate.adAnimation("nrelate_related_1");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/11/special-summary-enterprise-security-stories/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The PC is Changing Before Our Eyes</title>
		<link>http://ctovision.com/2011/11/the-pc-is-changing-before-our-eyes/</link>
		<comments>http://ctovision.com/2011/11/the-pc-is-changing-before-our-eyes/#comments</comments>
		<pubDate>Wed, 16 Nov 2011 10:10:49 +0000</pubDate>
		<dc:creator>AlexOlesker</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Bob Gourley]]></category>
		<category><![CDATA[Chief Information Officer]]></category>
		<category><![CDATA[Consumerization]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[HP Enterprise Security]]></category>
		<category><![CDATA[IDG]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[Personal computer]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=14390</guid>
		<description><![CDATA[Tweet While PCs will likely remain with us for a long time, the PC era has come to a close. Bob Gourley discussed this transition and the rise of mobile in an interview with IDG’s Bill Laberis at the HP Protect 2011 conference on Monday, September 12, 2011. Though there are currently 1.2 billion PCs in the [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F11%2Fthe-pc-is-changing-before-our-eyes%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/11/the-pc-is-changing-before-our-eyes/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/11/the-pc-is-changing-before-our-eyes/"  data-text="The PC is Changing Before Our Eyes" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/11/the-pc-is-changing-before-our-eyes/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/11/the-pc-is-changing-before-our-eyes/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><object width="500" height="281"><param name="movie" value="http://www.youtube.com/v/x1RzIXRj3Z0?version=3&#038;feature=oembed"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/x1RzIXRj3Z0?version=3&#038;feature=oembed" type="application/x-shockwave-flash" width="500" height="281" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>While PCs will likely remain with us for a long time, the PC era has come to a close. Bob Gourley discussed this transition and the rise of mobile in an interview with IDG’s Bill Laberis at the <a href="http://h20331.www2.hp.com/hpsub/cache/281822-0-0-225-121.html?jumpid=ex_2845_vanitysecur/productssecurity/ka011106" target="_blank">HP Protect 2011 conference</a> on Monday, September 12, 2011.</p>
<p>Though there are currently 1.2 billion PCs in the world, there are 4 billion active cell phone accounts, a growing proportion of which are smartphones. This, along with the explosive rise of tablets, has brought about the mobile era, impacting enterprise architecture, operations, and security. With data being pushed out to mobile devices, including possibly devices not issued by the company, protecting that data outside of the enterprise becomes a challenge. To do so, you must use multiple layers of protection, encrypt the data en route to the device, manage the device&#8217;s configuration, and ensure that the device has no malicious code. Currently, there is a need for solutions that can deliver those capabilities in an end-to-end manner.</p>
<p>Compliance with regulations such as HIPAA for medicine pose additional challenges when data moves outside the enterprise and on to a mobile device. While you can encrypt the data from the enterprise to the device, configure devices to be in compliance with the policy, and implement software to fight malicious code on some of the devices out there, some of the solutions we need do not yet exist. As a result, we&#8217;re in a very high risk environment with regards to mobile devices and CIOs and CISOs need to issue their policies accordingly.</p>
<p>The consumerization of IT, which brings millions of new devices into the business environment, further complicated this problem, especially given tightening IT budgets in government and industry. To secure this data without swelling strained budgets, Bob suggests coupling securityand functionality. Enterprises have no choice but to send their information out to their people in order to accomplish their mission, but they also need to keep it safe. Security and functionality can not be an either/or trade off, so IT budgets must be executed smartly for both crucial needs to be met.</p>
<p><strong>Related Articles:</strong></p>
<ul>
<li><a href="http://ctovision.com/2011/11/note-to-cios-your-organization-will-never-be-100-secure/" target="_blank">Note to CIOs: Your Organization Will Never Be 100% Secure</a> (ctovision.com)</li>
<li><a href="http://ctovision.com/2011/11/myths-and-realities-of-cloud-security/" target="_blank">Myths and Realities of Cloud Cybersecurity</a> (ctovision.com)</li>
<li><a href="http://ctovision.com/wp-admin/post.php?post=14216&amp;action=edit" target="_blank">Survey says: Security risks never higher, or more costly</a> (ctovision.com)</li>
<li><a href="http://ctovision.com/2011/10/evolving-approaches-to-cyber-threats-2/">Evolving Approaches to Cyber Threats</a> (ctovision.com)</li>
<li><a href="http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/">Yesterday’s Security Doesn’t Work for Today’s Threats</a> (ctovision.com)</li>
<li><a href="http://ctolabs.com/2011/10/big-data-and-the-enterprise-cio/">Big Data and the Enterprise CIO</a> (ctolabs.com)</li>
</ul>
<p>&nbsp;</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=760ce626-7022-4fba-9e05-36c3de35f417" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_2" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/bob-gourley%e2%80%99s-2012-outlook-%e2%80%9cexpect-disruptions%e2%80%9d/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/c018c1e93edc52116f81a37dfb106aa8_thumb_WashingtonExec.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Bob Gourley’s 2012 Outlook: “Expect Disruptions”</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2012/01/join-cloudera-and-carahsoft-for-big-data-success-in-government/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/1a20c00c6e77b8c2362d7050dbc3eec5_thumb_cloudera-and-carahsoft.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Join Cloudera and Carahsoft for Big Data Success in Government</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/thinking-about-the-traditional-approach/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/5c1597bbb9d4aa4103e2166210768a84_thumb_Cavalrycharge.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Thinking About the Traditional Approach</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/12/tech-review-for-november-2011/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/7a6abed9828705e4a6740dbb2595a8b9_thumb_MP900405500.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Tech Review for November 2011</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/fedcyber-com-cybersecurity-summit-on-wednesday-september-28/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/22f67ff1bc473d1363ba44d476bf8aab_thumb_FedCyber-Logo41.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">FedCyber.com Cybersecurity Summit on Wednesday, September 28</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/02/fdcci-preparation-with-virtual-instruments-and-carahsoft/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/weather-station-robe-south-australia.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">FDCCI Preparation with Virtual Instruments and Carahsoft</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/splunk-is-going-public-2/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-blue-ad-white-strips.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Splunk is Going Public</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/new-enterprise-cio-forum-blog-talk-radio/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-blue-ad-white-strips.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">New Enterprise CIO Forum Blog Talk Radio</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/google-tv-you-should-buy-it-just-not-yet/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-blue-ad-white-strips.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Google TV – You should buy it, just not yet…</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2012/01/ctovision-newsletters-and-tech-reports/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/weather-station-robe-south-australia.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">CTOvision Newsletters and Tech Reports</span><span class="nr_source">Bob Gourley</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=The+PC+is+Changing+Before+Our+Eyes&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F11%2Fthe-pc-is-changing-before-our-eyes%2F&nr_ad_number=0&nr_div_number=2");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_2");nRelate.adAnimation("nrelate_related_2");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/11/the-pc-is-changing-before-our-eyes/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Note to CIOs: Your organization will never be 100% secure</title>
		<link>http://ctovision.com/2011/11/note-to-cios-your-organization-will-never-be-100-secure/</link>
		<comments>http://ctovision.com/2011/11/note-to-cios-your-organization-will-never-be-100-secure/#comments</comments>
		<pubDate>Sat, 12 Nov 2011 02:41:18 +0000</pubDate>
		<dc:creator>AlexOlesker</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[ArcSight]]></category>
		<category><![CDATA[Bill Laberis]]></category>
		<category><![CDATA[Bob Gourley]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[Fortify]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[HP Enterprise Security]]></category>
		<category><![CDATA[IDG]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[SPI Dynamics]]></category>
		<category><![CDATA[Tipping Point]]></category>
		<category><![CDATA[Tom Reilly]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=14269</guid>
		<description><![CDATA[Tweet We&#8217;ve already established that perfect security is impossibly in cyberspace, especially with the move to the cloud, the consumerization of IT, and the rise of mobile. Still, even with current transformations, IT can still get more secure as it evolves. Recently, HP announced an enterprise security strategy to address these new challenges, which was [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F11%2Fnote-to-cios-your-organization-will-never-be-100-secure%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/11/note-to-cios-your-organization-will-never-be-100-secure/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/11/note-to-cios-your-organization-will-never-be-100-secure/"  data-text="Note to CIOs: Your organization will never be 100% secure" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/11/note-to-cios-your-organization-will-never-be-100-secure/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/11/note-to-cios-your-organization-will-never-be-100-secure/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><object width="500" height="281"><param name="movie" value="http://www.youtube.com/v/fhttnIOmDp8?version=3&#038;feature=oembed"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/fhttnIOmDp8?version=3&#038;feature=oembed" type="application/x-shockwave-flash" width="500" height="281" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>We&#8217;ve already established that perfect security is impossibly in cyberspace, especially with the move to the cloud, the consumerization of IT, and the rise of mobile. Still, even with current transformations, IT can still get more secure as it evolves. Recently, HP announced an enterprise security strategy to address these new challenges, which was described in an interview by IDG&#8217;s Bill Laberis at the <a href="http://h20331.www2.hp.com/hpsub/cache/281822-0-0-225-121.html?jumpid=ex_2845_vanitysecur/productssecurity/ka011106" target="_blank">HP Protect 2011 conference</a> on Monday, September 12, 2011, with CTOvision&#8217;s Bob Gourley and Tom Reilly, Vice President and General Manger of Enterprise Security at HP.</p>
<p>HP&#8217;s strategy is called Security Intelligence and Risk Management. Risk Management is the understanding that 100% security is impossible, so decisions and tradeoffs must be made, while at the same time organizations have to be proactive about defense, determining what the greatest vulnerabilities and worst attacks would be on their enterprise to preempt them and perform remediation efficiently and swiftly when necessary. In order to manage risk, you need Security Intelligence, the knowledge of who and what is on your network, as well as whether, where, and how you&#8217;ve been breached. To do so, HP uses best-of-breed technologies such as Tipping Point for network security, <a href="https://www.fortify.com/" target="_blank">Fortify </a>and SPI Dynamics for application security, and <a href="http://www.arcsight.com/" target="_blank">ArcSight </a>for universal log management and intelligence. HP brings those offerings together, integrating them so that the whole is better than the sum of its parts.</p>
<p>Bob Gourley, former CTO of the Defense Intelligence Agency, offered a CTO view of HP&#8217;s approach. CTOs, CISOs, and CIOs are eager to find a provider that can bring intelligence, risk management, application security and network security together to lower costs, speed up return on investment, and lower risk to the enterprise.  Enterprise security almost always pairs these increases in security with increases in functionality, the other role of the CIO.</p>
<p>But what if a CIO likes what HP has to offer, but has already invested in alternative security infrastructure? Implementing HP&#8217;s Enterprise Security solutions doesn&#8217;t have to be a &#8220;rip and replace&#8221; upgrade.  Rather, the goal is integration, tying together software like Tipping Point, Fortify, SPI Dynamics, and ArcSight with your security investments and making them all work better together. Bringing great, stand alone solutions together into a powerful Enterprise Security ecosystem is the real innovation that HP is now offering CIOs.</p>
<p><strong>Related Articles:</strong></p>
<ul>
<li><a href="http://ctovision.com/2011/11/myths-and-realities-of-cloud-security/" target="_blank">Myths and Realities of Cloud Cybersecurity</a> (ctovision.com)</li>
<li><a href="http://ctovision.com/wp-admin/post.php?post=14216&amp;action=edit" target="_blank">Survey says: Security risks never higher, or more costly</a> (ctovision.com)</li>
<li><a href="http://ctovision.com/2011/10/evolving-approaches-to-cyber-threats-2/">Evolving Approaches to Cyber Threats</a> (ctovision.com)</li>
<li><a href="http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/">Yesterday’s Security Doesn’t Work for Today’s Threats</a> (ctovision.com)</li>
<li><a href="http://ctolabs.com/2011/10/big-data-and-the-enterprise-cio/">Big Data and the Enterprise CIO</a> (ctolabs.com)</li>
</ul>
<p>&nbsp;</p>
<p>&nbsp;</p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_3" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/1566bfe294df4cdcb855d28ec73cb69a_thumb_protect-e1319104550402.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Survey says: Security risks never higher, or more costly</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/myths-and-realities-of-cloud-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/1566bfe294df4cdcb855d28ec73cb69a_thumb_protect-e1319104550402.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Myths and realities of cloud security</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/variety-of-short-grass-on-field.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Yesterday's Security Doesn't Work for Today's Threats</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2012/01/alexs-2012-tech-predictions/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/c2ca6b33dbce7e4646c5f3874a9380e3_thumb_2012.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Alex's 2012 Tech Predictions</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/the-pc-is-changing-before-our-eyes/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/307ff201bc9bc88b93dc55dbe0ea8ee0_thumb_160px-WindowsPhone7Series.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The PC is Changing Before Our Eyes</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/12/register-for-16-dec-webinar-on-what-the-cio-and-cto-need-to-know-about-developing-secure-code/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-blue-stripes.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Register for 16 Dec webinar on what the CIO and CTO need to know about develo ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/yesterday%e2%80%99s-security-doesn%e2%80%99t-work-for-today%e2%80%99s-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-red.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Yesterday’s Security Doesn’t Work for Today’s Threats</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/the-evolving-enterprise-threat-environment/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/ice-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The Evolving Enterprise Threat Environment</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/alexs-2012-tech-predictions/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-macro-plant.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Alex’s 2012 Tech Predictions</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/the-%e2%80%9cbig-five%e2%80%9d-it-trends-of-the-next-half-decade-mobile-social-cloud-consumerization-and-big-data/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/cloud-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The “Big Five” IT trends of the next half decade: Mobile, social, cloud, cons ...</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Note+to+CIOs%3A+Your+organization+will+never+be+100%25+secure&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F11%2Fnote-to-cios-your-organization-will-never-be-100-secure%2F&nr_ad_number=0&nr_div_number=3");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_3");nRelate.adAnimation("nrelate_related_3");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/11/note-to-cios-your-organization-will-never-be-100-secure/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Myths and realities of cloud security</title>
		<link>http://ctovision.com/2011/11/myths-and-realities-of-cloud-security/</link>
		<comments>http://ctovision.com/2011/11/myths-and-realities-of-cloud-security/#comments</comments>
		<pubDate>Thu, 03 Nov 2011 08:28:36 +0000</pubDate>
		<dc:creator>AlexOlesker</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Bob Gourley]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[HP Enterprise Security]]></category>
		<category><![CDATA[IDG]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[Tom Reilly]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=14248</guid>
		<description><![CDATA[Tweet Whenever the topic of cloud computing comes up, cloud security isn&#8217;t far behind. Survey after survey has shown it to be a top CIO concern, but how much of that concern is legitimate?   CTOvision&#8217;s Bob Gourley and Tom Reilly, Vice President and General Manger of Enterprise Security at HP separated myth from reality on [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F11%2Fmyths-and-realities-of-cloud-security%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/11/myths-and-realities-of-cloud-security/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/11/myths-and-realities-of-cloud-security/"  data-text="Myths and realities of cloud security" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/11/myths-and-realities-of-cloud-security/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/11/myths-and-realities-of-cloud-security/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><object width="500" height="281"><param name="movie" value="http://www.youtube.com/v/YiPWhaEhOUo?version=3&#038;feature=oembed"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/YiPWhaEhOUo?version=3&#038;feature=oembed" type="application/x-shockwave-flash" width="500" height="281" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>Whenever the topic of cloud computing comes up, cloud security isn&#8217;t far behind. Survey after survey has shown it to be a top CIO concern, but how much of that concern is legitimate?   CTOvision&#8217;s Bob Gourley and Tom Reilly, Vice President and General Manger of Enterprise Security at HP separated myth from reality on cloud security in an interview with IDG&#8217;s Bill Laberis at the <a href="http://h20331.www2.hp.com/hpsub/cache/281822-0-0-225-121.html?jumpid=ex_2845_vanitysecur/productssecurity/ka011106" target="_blank">HP Protect 2011 conference</a> on Monday, September 12, 2011.</p>
<p>While concerns over cybersecurity are well founded especially if an organization makes a hasty transition to cloud computing, it&#8217;s a myth that the cloud must be less secure than conventional computing. If you architect and design for the cloud, your enterprise can be more secure than ever, even when your data is going out to mobile devices.</p>
<p>Tom noted that current trends like cloud and mobile are major IT transformations and such transformations always bring new risks, just like the transitions from mainframe to client servers, then from client servers to IP addresses, and finally web applications.  Each shift has come with increasing risk, but due to the tremendous business benefits the IT industry has adapted and faced the new challenges. With cloud computing, we&#8217;re doing even better by designing security into the new platforms rather than waiting for threats and reactively adding in security measures. This helps the IT industry overcome its concerns by designing cloud to be inherently safer than current platforms.</p>
<p>To achieve this, CIOs and CISOs must change the way they think. Bob Gourley advocated treating security as a discipline so that designers can think it through fully when switching platforms and creating cloud and mobile solutions. Tom Reilly reiterated designing security into the cloud, so that organizations adopt the cloud because of, not despite, security.  Some examples of this are making the cloud transparent so that you have visibility into a multi-tenant environment to see how your operation is being conducted.  Applications for the cloud should have their vulnerabilities designed out before they even reach production, and there needs to be research into possible attacks on a cloud environment. The key, Reilly notes, is that, as a multi-tenant environment shared by several divisions or corporations, the cloud can have more invested into security than any single division or corporation has in its current platform.</p>
<p><strong>Related Articles:</strong></p>
<ul>
<li><a href="http://ctovision.com/wp-admin/post.php?post=14216&amp;action=edit" target="_blank">Survey says: Security risks never higher, or more costly</a> (ctovision.com)</li>
<li><a href="http://ctovision.com/2011/10/evolving-approaches-to-cyber-threats-2/">Evolving Approaches to Cyber Threats</a> (ctovision.com)</li>
<li><a href="http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/">Yesterday’s Security Doesn’t Work for Today’s Threats</a> (ctovision.com)</li>
<li><a href="http://ctolabs.com/2011/10/big-data-and-the-enterprise-cio/">Big Data and the Enterprise CIO</a> (ctolabs.com)</li>
</ul>

<div class="nr_clear"></div>	
	<div id="nrelate_related_4" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/12/a-look-at-vmwares-vfabric-cloud-application-platform/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/0717589ce7df6c98de9d81caca8a3571_thumb_vmware.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">A look at VMware's vFabric Cloud Application Platform</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/is-the-healthcare-industry-on-life-support-without-the-cloud/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/92ac26033bc839c52530d90d0d2c4c63_thumb_cloud_111-1024x950.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Is the Healthcare Industry on Life Support Without the Cloud?</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/12/when-chuck-norris-gets-cloud-mobile/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/aa1af3be09acb5fea3524d54ad475060_thumb_CTOvisionSOFCLOUD.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">When Chuck Norris Gets Cloud-Mobile</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/05/live-from-the-gov-2-0-expo-security-in-the-cloud/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/011fd5a2dff7f4ca7be764ab0883d99a_thumb_NIST-Logo.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Live from the Gov 2.0 Expo - Security in the Cloud</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/bob-gourley%e2%80%99s-2012-outlook-%e2%80%9cexpect-disruptions%e2%80%9d/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/c018c1e93edc52116f81a37dfb106aa8_thumb_WashingtonExec.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Bob Gourley’s 2012 Outlook: “Expect Disruptions”</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://blogs.oracle.com/drcloud/entry/cloud_security_books"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/art-rhododendron-flower.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cloud Security Books</span><span class="nr_source">Dr Cloud's Flying Software Circus</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/12/a-look-at-vmware%e2%80%99s-vfabric-cloud-application-platform/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunrise-desktop.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">A look at VMware’s vFabric Cloud Application Platform</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/nist-identifies-cloud-computing-standards-gaps/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/mosaic-detail.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">NIST identifies cloud computing standards gaps</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/02/cloud-security-costs-concern-federal-it-pros/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-macro-plant.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Cloud Security, Costs Concern Federal IT Pros</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/02/nsf-releases-cloud-computing-report/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/art-rhododendron-flower.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">NSF releases Cloud Computing Report</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Myths+and+realities+of+cloud+security&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F11%2Fmyths-and-realities-of-cloud-security%2F&nr_ad_number=0&nr_div_number=4");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_4");nRelate.adAnimation("nrelate_related_4");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/11/myths-and-realities-of-cloud-security/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>New Enterprise CIO Forum Blog Talk Radio</title>
		<link>http://ctovision.com/2011/10/new-enterprise-cio-forum-blog-talk-radio/</link>
		<comments>http://ctovision.com/2011/10/new-enterprise-cio-forum-blog-talk-radio/#comments</comments>
		<pubDate>Fri, 28 Oct 2011 18:29:34 +0000</pubDate>
		<dc:creator>RyanKamauff</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Arts]]></category>
		<category><![CDATA[Blog Talk Radio]]></category>
		<category><![CDATA[BobGourley]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Dodge]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[Government Accountability Office]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[John Dodge]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=14231</guid>
		<description><![CDATA[Tweet In this week&#8217;s Blog Talk Radio, Bob Gourley and John Dodge talk about the new avenues of attack in the cyber world. In addition, they hit on the #cloudsecurity tweets of the week on Twitter. Highlights of the re-tweets are an interview with CIA CTO Gus Hunt and some thoughts on moving from a [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F10%2Fnew-enterprise-cio-forum-blog-talk-radio%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/10/new-enterprise-cio-forum-blog-talk-radio/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/10/new-enterprise-cio-forum-blog-talk-radio/"  data-text="New Enterprise CIO Forum Blog Talk Radio" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/10/new-enterprise-cio-forum-blog-talk-radio/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/10/new-enterprise-cio-forum-blog-talk-radio/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>In this week&#8217;s Blog Talk Radio, Bob Gourley and John Dodge talk about the new avenues of attack in the cyber world. In addition, they hit on the #cloudsecurity tweets of the week on Twitter. Highlights of the re-tweets are an interview with CIA CTO Gus Hunt and some thoughts on moving from a private cloud to a public cloud. The two also hit on topics like HP&#8217;s integrated suite of security tools and <a href="http://www8.hp.com/us/en/software/software-solution.html?compURI=tcm:245-936139">the importance of testing applications</a>, especially web applications. The mobile risk management company <a href="http://fixmo.com">Fixmo</a> was also an important topic, as well as <a href="http://vmware.com">VMware</a>.</p>
<p>Find Bob Gourley (<a href="http://twitter.com/#!/bobgourley">@BobGourley</a>) and John Dodge (<a href="http://twitter.com/#!/thedodgeretort">@thedodgeretort</a>) on twitter.</p>
<p>&nbsp;</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=c7613fb3-3b0d-459a-81d2-0efdcd8416a6" alt="" /></div>
<p><object id="244257" width="210" height="270" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="quality" value="high" /><param name="wmode" value="transparent" /><param name="menu" value="false" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://www.blogtalkradio.com/btrplayer.swf" /><param name="flashvars" value="file=http://www.blogtalkradio.com%2fecioforum%2fplay_list.xml%3Fitemcount%3D5&amp;autostart=false&amp;shuffle=false&amp;callback=http://www.blogtalkradio.com/FlashPlayerCallback.aspx&amp;width=210&amp;height=270&amp;volume=80&amp;corner=rounded" /><param name="pluginspage" value="http://www.macromedia.com/go/getflashplayer" /><param name="allowscriptaccess" value="always" /><embed id="244257" width="210" height="270" type="application/x-shockwave-flash" src="http://www.blogtalkradio.com/btrplayer.swf" quality="high" wmode="transparent" menu="false" allowScriptAccess="always" flashvars="file=http://www.blogtalkradio.com%2fecioforum%2fplay_list.xml%3Fitemcount%3D5&amp;autostart=false&amp;shuffle=false&amp;callback=http://www.blogtalkradio.com/FlashPlayerCallback.aspx&amp;width=210&amp;height=270&amp;volume=80&amp;corner=rounded" pluginspage="http://www.macromedia.com/go/getflashplayer" allowscriptaccess="always" /></object></p>
<div style="font-size: 10px; text-align: center; width: 220px;">Listen to <a href="http://www.blogtalkradio.com">internet radio</a> with <a href="http://www.blogtalkradio.com/ecioforum">ECIOForum</a> on Blog Talk Radio</div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_5" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/latest-dodgeretort-gao-federal-cios-need-to-focus-more-on-information-management-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/3bf47f1c25400dc5323702d359eb65c2_thumb_cio.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Latest DodgeRetort - GAO: Federal CIO's need to focus more on information man ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/special-summary-enterprise-security-stories/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/a9eb3edce3d5c67a7bf299ecbc588db5_thumb_digitalglobe.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Special Summary: Enterprise security stories</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/blog-talk-radio-with-thedodgeretort-and-bobgourley/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/fdc8a98315e5414a02932aaf9834c1c6_thumb_Capture6.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Blog Talk Radio with @thedodgeretort and @bobgourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/12/tech-review-for-november-2011/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/7a6abed9828705e4a6740dbb2595a8b9_thumb_MP900405500.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Tech Review for November 2011</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/fedcyber-com-cybersecurity-summit-on-wednesday-september-28/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/22f67ff1bc473d1363ba44d476bf8aab_thumb_FedCyber-Logo41.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">FedCyber.com Cybersecurity Summit on Wednesday, September 28</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/learn-lessons-on-the-fdcci-with-bob-gourley-and-carahsoft-webinar/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/water-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Learn Lessons On The FDCCI with Bob Gourley and Carahsoft (Webinar)</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/latest-dodgeretort-%e2%80%93-gao-federal-cio%e2%80%99s-need-to-focus-more-on-information-management-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-blue-ad-white-strips.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Latest DodgeRetort – GAO: Federal CIO’s need to focus more on information man ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/learn-how-to-get-ready-for-the-fdcci-with-bob-gourley-and-carahsoft-webinar/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/evening-in-marlborough-sounds.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Learn how to get ready for the FDCCI with Bob Gourley and Carahsoft (Webinar)</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2012/01/join-cloudera-and-carahsoft-for-big-data-success-in-government/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunset-free-wallpaper.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Join Cloudera and Carahsoft for Big Data Success in Government</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-red.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Survey says: Security risks never higher, or more costly</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=New+Enterprise+CIO+Forum+Blog+Talk+Radio&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F10%2Fnew-enterprise-cio-forum-blog-talk-radio%2F&nr_ad_number=0&nr_div_number=5");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_5");nRelate.adAnimation("nrelate_related_5");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/10/new-enterprise-cio-forum-blog-talk-radio/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Survey says: Security risks never higher, or more costly</title>
		<link>http://ctovision.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/</link>
		<comments>http://ctovision.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/#comments</comments>
		<pubDate>Thu, 27 Oct 2011 12:30:49 +0000</pubDate>
		<dc:creator>AlexOlesker</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Bob Gourley]]></category>
		<category><![CDATA[Chief Information Officer]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[HP Enterprise Security]]></category>
		<category><![CDATA[HP Protect 2011 conference]]></category>
		<category><![CDATA[Ponemon Institute]]></category>
		<category><![CDATA[Tom Reilly]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=14216</guid>
		<description><![CDATA[Tweet In an interview at the HP Protect 2011 conference on Monday, September 12, 2011. Bob Gourley and Tom Reilly, Vice President and General Manger of Enterprise Security at HP, discussed two studies on cyber crime from the Ponemon Institute and Coleman Parks. The median cost to an organization due to cyber attack was $5.9 million a year, [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F10%2Fsurvey-says-security-risks-never-higher-or-more-costly%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/"  data-text="Survey says: Security risks never higher, or more costly" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><object width="500" height="281"><param name="movie" value="http://www.youtube.com/v/2rF3Q2ewa4E?version=3&#038;feature=oembed"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/2rF3Q2ewa4E?version=3&#038;feature=oembed" type="application/x-shockwave-flash" width="500" height="281" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>In an interview at the <a href="http://h20331.www2.hp.com/hpsub/cache/281822-0-0-225-121.html?jumpid=ex_2845_vanitysecur/productssecurity/ka011106" target="_blank">HP Protect 2011 conference</a> on Monday, September 12, 2011. Bob Gourley and Tom Reilly, Vice President and General Manger of Enterprise Security at HP, discussed two studies on cyber crime from the Ponemon Institute and Coleman Parks. The median cost to an organization due to cyber attack was $5.9 million a year, 56% more than last year, and  the time it takes to resolve the attack was 18 days with an average price tag of $416,000, a 70% increase. Studies reveal that sentiment towards security has been changing. Only 29% of executives said that they had confidence in their organization&#8217;s cybersecurity. What do these startling statistics mean for CTOs, CIOs, and CISOs?</p>
<p>While the numbers are interesting, Tom Reilly believes that its the year to year trends that really stand out.  A 56% jump in the cost of cyber attacks and a 70% increase in the price of remediation indicate that cyber attacks are more common and more sophisticated. This rise also correlates with the introduction of more cloud and mobile computing in the workplace, which causes an increase in possible attack vectors and vulnerabilities, at least until security catches up to these new developments.</p>
<p>Bob Gourley saw reports on the growing cost of cyber crime as an opportunity to improve. In IT, security professionals are always fighting to justify their budget. Since cyber crime prevention is cheaper than remediation, data like this helps make the case for investing in security to save money. Tom added that, with all of the high-profile cyber attacks in the news this year, not only is security seen as an important corporate issue, but robust security measures can be justified by the impact on brand image of a serious breach.</p>
<p>Bob was less optimistic about the figures on confidence, stating that the 29% who believed in their cyber defenses just don&#8217;t know that they&#8217;ve already been breached. Those that have experienced large cyber attacks are less confident and understand that they must always be vigilant and constantly improve their security. Tom&#8217;s take away was that nobody really knows how secure they are because most corporations can&#8217;t measure the effectiveness of their security programs. No company is 100% secure so you have no choice but to assume that you&#8217;re already breached.</p>
<p>Since perfect security is impossible especially if an organization wants to take advantage of the cloud and mobility, HP adopted a risk-management approach. They suggest that CTOs, CIOs, and CISOs identify their most valuable data and protect it as best as possible, knowing that other information may be vulnerable. They must also identify their greatest vulnerabilities. Once an organization assumes it has been breached, it needs to gather the security intelligence to understand where and how, then respond correctly to isolate and quarantine the environment for effective remediation.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://ctovision.com/2011/10/evolving-approaches-to-cyber-threats-2/">Evolving Approaches to Cyber Threats</a> (ctovision.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/">Yesterday’s Security Doesn’t Work for Today’s Threats</a> (ctovision.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ctolabs.com/2011/10/big-data-and-the-enterprise-cio/">Big Data and the Enterprise CIO</a> (ctolabs.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=b8f0a994-7e37-42fb-ba24-8287e39b6999" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_6" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/myths-and-realities-of-cloud-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/1566bfe294df4cdcb855d28ec73cb69a_thumb_protect-e1319104550402.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Myths and realities of cloud security</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/special-summary-enterprise-security-stories/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/a9eb3edce3d5c67a7bf299ecbc588db5_thumb_digitalglobe.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Special Summary: Enterprise security stories</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/note-to-cios-your-organization-will-never-be-100-secure/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/61274150f8f1420a3f5aeb7c253f1892_thumb_keyboard_lock_small.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Note to CIOs: Your organization will never be 100% secure</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/bob-gourley-discusses-big-data-security-with-idg/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/9de79b6d91f8cf09244a41240fab1e70_thumb_big-data.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Bob Gourley Discusses Big Data Security With IDG</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/big-data-and-the-enterprise-cio-2/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/ff6b7e09da05c3bcfe13d0f2a9fb8376_thumb_hprotect.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Big Data and the Enterprise CIO</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/gourley-discusses-big-data-security-with-idg/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/wave-open-sea.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Gourley Discusses Big Data Security With IDG</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2011/10/evolving-approaches-to-cyber-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/art-rhododendron-flower.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Evolving Approaches to Cyber Threats</span><span class="nr_source">Bob Gourley</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/the-evolving-enterprise-threat-environment/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/evening-in-marlborough-sounds.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The Evolving Enterprise Threat Environment</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/new-enterprise-cio-forum-blog-talk-radio/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/mountains-dust.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">New Enterprise CIO Forum Blog Talk Radio</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/yesterday%e2%80%99s-security-doesn%e2%80%99t-work-for-today%e2%80%99s-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/cut-log.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Yesterday’s Security Doesn’t Work for Today’s Threats</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Survey+says%3A+Security+risks+never+higher%2C+or+more+costly&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F10%2Fsurvey-says-security-risks-never-higher-or-more-costly%2F&nr_ad_number=0&nr_div_number=6");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_6");nRelate.adAnimation("nrelate_related_6");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Latest DodgeRetort &#8211; GAO: Federal CIO&#8217;s need to focus more on information management, security</title>
		<link>http://ctovision.com/2011/10/latest-dodgeretort-gao-federal-cios-need-to-focus-more-on-information-management-security/</link>
		<comments>http://ctovision.com/2011/10/latest-dodgeretort-gao-federal-cios-need-to-focus-more-on-information-management-security/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 22:37:07 +0000</pubDate>
		<dc:creator>RyanKamauff</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Gov2.0]]></category>
		<category><![CDATA[Chief Information Officer]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[Federal government of the United States]]></category>
		<category><![CDATA[GAO]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Government Accountability Office]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[List of United States federal agencies]]></category>
		<category><![CDATA[Office of Management and Budget]]></category>
		<category><![CDATA[United States]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=14189</guid>
		<description><![CDATA[Tweet A just-released GAO report says Federal CIOs do not have the authority they need to do their jobs &#8211; and serve the public. Should federal CIOs be given more power? What stands in their way? Enterprise CIO Forum community manager John Dodge and Bob Gourley, CTOvision.com editor-in-chief who used to work for the federal government, explore [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F10%2Flatest-dodgeretort-gao-federal-cios-need-to-focus-more-on-information-management-security%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/10/latest-dodgeretort-gao-federal-cios-need-to-focus-more-on-information-management-security/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/10/latest-dodgeretort-gao-federal-cios-need-to-focus-more-on-information-management-security/"  data-text="Latest DodgeRetort &#8211; GAO: Federal CIO&#8217;s need to focus more on information management, security" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/10/latest-dodgeretort-gao-federal-cios-need-to-focus-more-on-information-management-security/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/10/latest-dodgeretort-gao-federal-cios-need-to-focus-more-on-information-management-security/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p>A <a href="http://www.gao.gov/products/GAO-11-634">just-released GAO report</a> says Federal CIOs do not have the authority they need to do their jobs &#8211; and serve the public. Should federal CIOs be given more power? What stands in their way? Enterprise CIO Forum community manager John Dodge and Bob Gourley, CTOvision.com editor-in-chief who used to work for the federal government, explore the problem of un-empowered CIOs in Federal IT.</p>
<p><object id="244257" width="210" height="105" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="quality" value="high" /><param name="wmode" value="transparent" /><param name="menu" value="false" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://www.blogtalkradio.com/btrplayer.swf" /><param name="flashvars" value="file=http%3A%2F%2Fwww.blogtalkradio.com%2Fecioforum%2F2011%2F10%2F21%2Fare-federal-cios-under-powered%2fplaylist.xml&amp;autostart=false&amp;shuffle=false&amp;callback=http://www.blogtalkradio.com/FlashPlayerCallback.aspx&amp;width=210&amp;height=105&amp;volume=80&amp;corner=rounded" /><param name="pluginspage" value="http://www.macromedia.com/go/getflashplayer" /><param name="allowscriptaccess" value="always" /><embed id="244257" width="210" height="105" type="application/x-shockwave-flash" src="http://www.blogtalkradio.com/btrplayer.swf" quality="high" wmode="transparent" menu="false" allowScriptAccess="always" flashvars="file=http%3A%2F%2Fwww.blogtalkradio.com%2Fecioforum%2F2011%2F10%2F21%2Fare-federal-cios-under-powered%2fplaylist.xml&amp;autostart=false&amp;shuffle=false&amp;callback=http://www.blogtalkradio.com/FlashPlayerCallback.aspx&amp;width=210&amp;height=105&amp;volume=80&amp;corner=rounded" pluginspage="http://www.macromedia.com/go/getflashplayer" allowscriptaccess="always" /></object></p>
<div style="font-size: 10px; text-align: center; width: 220px;">Listen to <a href="http://www.blogtalkradio.com">internet radio</a> with <a href="http://www.blogtalkradio.com/ecioforum">ECIOForum</a> on Blog Talk Radio</div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_7" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/12/announcing-fedcyber-com-a-resource-for-firms-with-cybersecurity-solutions-for-the-federal-space/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/a2397bbc0c03466363c0ffa7afdb94d3_thumb_cyber-spend-300x100.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Announcing FedCyber.com: A resource for firms with cybersecurity solutions fo ...</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/12/debrief-from-the-white-house-forum-on-it-management-reform/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/988d7cadc13187103157eb840f725633_thumb_techstat-300x239.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Debrief from The White House Forum on IT Management Reform</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/06/cto-perspectives-on-cyber-security-bill-of-the-us-senate-homeland-security-and-governmental-affairs-comittee/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/c91e4caea6e3b96614f0ae61090ec4b3_thumb_hsgac-liberman-collins.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">CTO Perspectives on Cyber Security Bill</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/big-data-and-the-enterprise-cio-2/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/ff6b7e09da05c3bcfe13d0f2a9fb8376_thumb_hprotect.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Big Data and the Enterprise CIO</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/new-enterprise-cio-forum-blog-talk-radio/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-city-windows.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">New Enterprise CIO Forum Blog Talk Radio</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/latest-dodgeretort-%e2%80%93-gao-federal-cio%e2%80%99s-need-to-focus-more-on-information-management-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/evening-in-marlborough-sounds.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Latest DodgeRetort – GAO: Federal CIO’s need to focus more on information man ...</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2012/01/learn-lessons-on-the-fdcci-with-bob-gourley-and-carahsoft-webinar/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunrise-desktop.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Learn Lessons On The FDCCI with Bob Gourley and Carahsoft (Webinar)</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/12/federal-agencies-struggle-to-define-their-cybersecurity-workforce-finds-gao/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/sunrise-desktop.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Federal agencies struggle to define their cybersecurity workforce, finds GAO</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/gao-federal-data-at-cyber-risk-2/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/spiral-seashells-painted-gold.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">GAO: Federal data at cyber risk</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Latest+DodgeRetort+%26%238211%3B+GAO%3A+Federal+CIO%26%238217%3Bs+need+to+focus+more+on+information+management%2C+security&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F10%2Flatest-dodgeretort-gao-federal-cios-need-to-focus-more-on-information-management-security%2F&nr_ad_number=0&nr_div_number=7");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_7");nRelate.adAnimation("nrelate_related_7");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/10/latest-dodgeretort-gao-federal-cios-need-to-focus-more-on-information-management-security/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Evolving Approaches to Cyber Threats</title>
		<link>http://ctovision.com/2011/10/evolving-approaches-to-cyber-threats-2/</link>
		<comments>http://ctovision.com/2011/10/evolving-approaches-to-cyber-threats-2/#comments</comments>
		<pubDate>Thu, 20 Oct 2011 12:44:31 +0000</pubDate>
		<dc:creator>BobGourley</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Andrzej Kawalec]]></category>
		<category><![CDATA[Big Data]]></category>
		<category><![CDATA[Bob Gourley]]></category>
		<category><![CDATA[Chief Information Officer]]></category>
		<category><![CDATA[Chief technology officer]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[HP]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=14136</guid>
		<description><![CDATA[Tweet Bob Gourley and HP&#8217;s Andrzej Kawalec, CTO of Enterprise Security continued to discuss emerging security issues at the HP Protect 2011 conference on Monday, September 12, 2011, exploring problems with traditional approaches to enterprise security. Andrzej began by defining the customary enterprise security approach. We&#8217;ve been taking a very reactive stance to cybersecurity, focusing on responding to [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F10%2Fevolving-approaches-to-cyber-threats-2%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/10/evolving-approaches-to-cyber-threats-2/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/10/evolving-approaches-to-cyber-threats-2/"  data-text="Evolving Approaches to Cyber Threats" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/10/evolving-approaches-to-cyber-threats-2/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/10/evolving-approaches-to-cyber-threats-2/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><object width="500" height="281"><param name="movie" value="http://www.youtube.com/v/Of3CfNJ84oQ?version=3&#038;feature=oembed"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/Of3CfNJ84oQ?version=3&#038;feature=oembed" type="application/x-shockwave-flash" width="500" height="281" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>Bob Gourley and HP&#8217;s Andrzej Kawalec, CTO of Enterprise Security continued to discuss emerging security issues at the <a href="http://h20331.www2.hp.com/hpsub/cache/281822-0-0-225-121.html?jumpid=ex_2845_vanitysecur/productssecurity/ka011106" target="_blank">HP Protect 2011 conference</a> on Monday, September 12, 2011, exploring problems with traditional approaches to enterprise security.</p>
<p>Andrzej began by defining the customary enterprise security approach. We&#8217;ve been taking a very reactive stance to cybersecurity, focusing on responding to incidents, and cybersecurity has been more of an art than a science. Our understanding of how different systems, defenses, and attack vectors interact is far less developed than our knowledge of networks or data centers. He also noted that traditionally, security was below the level of the board and even the CIO, posing a significant challenge to CISOs and CIOs today.</p>
<p>I elaborated on where those traditional approaches and attitudes fail. fundamentally, these approaches do not deliver defense in depth, which has become the goal of modern cybersecurity. When defense is reactive, it focuses on the last battle rather than the future threats and, as a result, misses the major transformations currently underway in the enterprise, such as cloud computing and users shifting from PCs to mobile devices for work or as the endpoints for software-as-a-service. With current approaches, enterprises are not prepared for a &#8220;post-PC era.&#8221;</p>
<p>Noting all of those problems, Andrzej and I both laid out lists of priorities for CIOs. They must take a transformational posture, focusing on moving from a reactive security policy to more effective and forward-looking defense in depth. To do so, they need a more analytical,  broad, Big Data approach to their information, for example correlating various security events to find trends and performing forensics after a breach. Another element of this is getting all of the security professionals in the enterprise together to form a team with a deeper grasp of threats. To do so, enterprises must also begin to view security  its own distinct discipline.</p>
<p>Ultimately, an analytics approach of providing a fast, accurate, and aggregated view of data within the enterprise is crucial for current CIOs. It allows them to coordinate their operational staff and to better communicate with their board so that they can transform the enterprise and shed dated, reactive responses to threats for active and deep defense.</p>
<p>Many enterprises are finding that the best way to transition from reactive to proactive postures is by measuring what exists, monitoring ongoing activity, and planning for continuing enhancement using those insights.  This type of continuous improvement is aided by integrated technology, including IT testing, security testing, SIEM and forensics capabilities.  For more on enterprise capabilities like these and HP Enterprise Security we recommend diving into the great context at: <a href="http://www.arcsight.com/protect2011/" target="_blank">http://www.arcsight.com/protect2011/</a></p>
<p>Related articles</p>
<ul>
<li><a href="http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/">Yesterday&#8217;s Security Doesn&#8217;t Work for Today&#8217;s Threats</a> (ctovision.com)</li>
<li><a href="http://ctolabs.com/2011/10/big-data-and-the-enterprise-cio/">Big Data and the Enterprise CIO</a> (ctolabs.com)</li>
</ul>
<div></div>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=64ebcc52-2663-4506-960c-f8f39ba1223b" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_8" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-old-wood.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Yesterday's Security Doesn't Work for Today's Threats</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/special-summary-enterprise-security-stories/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/a9eb3edce3d5c67a7bf299ecbc588db5_thumb_digitalglobe.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Special Summary: Enterprise security stories</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/1566bfe294df4cdcb855d28ec73cb69a_thumb_protect-e1319104550402.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Survey says: Security risks never higher, or more costly</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/the-evolving-enterprise-threat-environment/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/26bba1be39a5b1601cf7dfaa47327590_thumb_LockedComputer.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The Evolving Enterprise Threat Environment</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/thinking-about-the-traditional-approach/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/5c1597bbb9d4aa4103e2166210768a84_thumb_Cavalrycharge.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Thinking About the Traditional Approach</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/yesterday%e2%80%99s-security-doesn%e2%80%99t-work-for-today%e2%80%99s-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/cut-log.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Yesterday’s Security Doesn’t Work for Today’s Threats</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/09/fedcyber-com-cybersecurity-summit-on-wednesday-september-28/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/22f67ff1bc473d1363ba44d476bf8aab_thumb_FedCyber-Logo41.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">FedCyber.com Cybersecurity Summit on Wednesday, September 28</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/01/federal-cyber-security-missions-initiatives-opportunities-and-risks/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/7211aac7adbb945cc945ba4e55d660ad_thumb_cybersecurityconference-300x195.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Federal Cyber Security: Missions, Initiatives, Opportunities and Risks</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/note-to-cios-your-organization-will-never-be-100-secure/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-macro-plant.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Note to CIOs: Your organization will never be 100% secure</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2010/10/sinet-showcase-27-october-2010/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/7085c1943117fd89432608020683ecf2_thumb_general-hayden-robert-rodriquez-sinet-300x225.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">SINET Showcase 27 October 2010</span><span class="nr_source">CTOvision.com</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Evolving+Approaches+to+Cyber+Threats&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F10%2Fevolving-approaches-to-cyber-threats-2%2F&nr_ad_number=0&nr_div_number=8");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_8");nRelate.adAnimation("nrelate_related_8");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/10/evolving-approaches-to-cyber-threats-2/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Yesterday&#8217;s Security Doesn&#8217;t Work for Today&#8217;s Threats</title>
		<link>http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/</link>
		<comments>http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/#comments</comments>
		<pubDate>Thu, 13 Oct 2011 16:46:02 +0000</pubDate>
		<dc:creator>AlexOlesker</dc:creator>
				<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[ArcSight]]></category>
		<category><![CDATA[Big Data]]></category>
		<category><![CDATA[Bob Gourley]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[HP Enterprise Security]]></category>
		<category><![CDATA[IDG]]></category>
		<category><![CDATA[Wikileaks]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=14018</guid>
		<description><![CDATA[Tweet Another discussion from the HP Protect 2011 conference on Monday, September 12, 2011 featured Bob Gourley and HP&#8217;s Andrzej Kawalec, CTO of Enterprise Security, discussing the evolving enterprise threat environment and how it can be mitigated. Bob and Andrzej agreed on three major emerging challenges in enterprise cybersecurity. The first is simply the nature of the threat, which is growing [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F10%2Fyesterdays-security-doesnt-work-for-todays-threats%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/"  data-text="Yesterday&#8217;s Security Doesn&#8217;t Work for Today&#8217;s Threats" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><object width="500" height="281"><param name="movie" value="http://www.youtube.com/v/eEzmXrs0mdA?version=3&#038;feature=oembed"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/eEzmXrs0mdA?version=3&#038;feature=oembed" type="application/x-shockwave-flash" width="500" height="281" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>Another discussion from the <a href="http://h20331.www2.hp.com/hpsub/cache/281822-0-0-225-121.html?jumpid=ex_2845_vanitysecur/productssecurity/ka011106" target="_blank">HP Protect 2011 conference</a> on Monday, September 12, 2011 featured Bob Gourley and HP&#8217;s Andrzej Kawalec, CTO of Enterprise Security, discussing the evolving enterprise threat environment and how it can be mitigated.</p>
<p>Bob and Andrzej agreed on three major emerging challenges in enterprise cybersecurity. The first is simply the nature of the threat, which is growing in sophistication, speed, and targeting over time. Phishing, for example, gives way to <a title="Phishing" href="http://en.wikipedia.org/wiki/Phishing" rel="wikipedia">Spear phishing</a> where the impostor emails are designed to look like they came from colleagues, offer a malicious link tailored to the target, and may have company letterheads and logos. Threats to enterprise are growing more serious because, as Bob noted, the money is with the enterprises and the threats follow.</p>
<p>The second emerging challenge is the consumerization of IT. Employees no longer do all their work on a (hopefully) secured company workstation. Instead, they are flipping through presentations on their personal tablets and checking emails on their smartphones. While on one hand this is great as it allows users to stick with the devices they prefer and are comfortable with, and encourages them to work wherever and whenever is convenient, it also means that hardening single data endpoints is no longer enough, as an enterprise can&#8217;t know what device its employees will be working on. Already, <a href="http://www.net-security.org/secworld.php?id=11620" target="_blank">a recent survey of IT managers </a>reveals that employees use personal devices for work in almost 90% of companies, and that most do not have the tools to manage them.</p>
<p>Lastly, the cloud is changing how IT is delivered. <a title="Software as a service" href="http://en.wikipedia.org/wiki/Software_as_a_service" rel="wikipedia">Software-as-a-Service</a>, Platform-as-a-Service, and <a title="Cloud computing" href="http://en.wikipedia.org/wiki/Cloud_computing" rel="wikipedia">Infrastructure-as-a-Service</a> are reinventing how we consume and interact with IT. Again, cloud computing has brought many benefits, but also its share of challenges as CTOs, CIO, and CISOs adjust and make their security work for a new paradigm.</p>
<p>Adapting to this threat environment requires a risk management approach. We must assume we will eventually be breached and be ready to respond with in-depth forensics and remediation immediately. As Kawalec noted, enterprises must plan to fail and expect to be under attack not just from malware or malicious code in general, but also internal threats, the quintessential example being Bradley Manning and all the anonymous contributors to <a title="WikiLeaks" href="http://en.wikipedia.org/wiki/WikiLeaks" rel="wikipedia">WikiLeaks</a>. This complicates security not only because social engineering and trusted users can get around any current technical solution, but also because their motivations tend to be different from traditional criminal hackers.</p>
<p>If enterprises assume that their networks are already compromised, they need to protect them with a remediation approach. An example would be <a title="Triumfant" href="http://www.triumfant.com/default.asp" rel="homepage">Triumfant</a>’s Configuration and Change Management Tool, which effectively scans networks for anomalies before users even notice that something is wrong, and then reduces infection turnaround time from days to minutes as it implements solutions at the click of a button then fills on gaps from healthy computers if important file systems have been deleted.</p>
<p>Still, even with products emerging to help enterprises &#8220;plan to fail&#8221; at perfect internet security, dealing with a shifting IT paradigm and threat environment takes a different kind of CIO. Since perfect security is impossible, CIOs need to decide what level of risk they are willing to accept. Today&#8217;s CIOs and CISOs also need to understand architecture, vision, and design, to see the system on both macro and micro levels to reduce security silos and provide robust solutions for a changing world.</p>
<p>Staying ahead of the threat has always been hard but there are new integrated capabilities that aid defense, like <a href="http://www.arcsight.com/">ArcSight&#8217;s</a> suite of integrated capabilities (ArcSight is in the leader&#8217;s quadrant of <a href="http://www.arcsight.com/library/download/GartnerMQ2011">Gartner&#8217;s SIEM Magic Quadrant Report</a>). Ensuring SIEM capabilities like this are integrated into your enterprise is a key component in ensuring your enterprise is able to meet the threat.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://ctovision.com/2011/10/big-data-and-the-enterprise-cio-2/">Big Data and the Enterprise CIO</a> (ctovision.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.bobgourley.com/2011/07/using-triumfant-for-secure-configuration-and-change-management/">Using Triumfant for Secure Configuration and Change Management</a> (bobgourley.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.fedcyber.com/2011/08/27/in-search-of-a-russian-winter-of-information-systems-security/">In Search of a Russian Winter of Information Systems Security</a> (fedcyber.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=aee7d5c9-65e2-4179-ab2e-35a58b719f00" alt="" /></div>

<div class="nr_clear"></div>	
	<div id="nrelate_related_9" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/evolving-approaches-to-cyber-threats-2/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/1566bfe294df4cdcb855d28ec73cb69a_thumb_protect-e1319104550402.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Evolving Approaches to Cyber Threats</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/the-evolving-enterprise-threat-environment/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/26bba1be39a5b1601cf7dfaa47327590_thumb_LockedComputer.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">The Evolving Enterprise Threat Environment</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/special-summary-enterprise-security-stories/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/a9eb3edce3d5c67a7bf299ecbc588db5_thumb_digitalglobe.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Special Summary: Enterprise security stories</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/1566bfe294df4cdcb855d28ec73cb69a_thumb_protect-e1319104550402.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Survey says: Security risks never higher, or more costly</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/11/note-to-cios-your-organization-will-never-be-100-secure/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/61274150f8f1420a3f5aeb7c253f1892_thumb_keyboard_lock_small.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Note to CIOs: Your organization will never be 100% secure</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/yesterday%e2%80%99s-security-doesn%e2%80%99t-work-for-today%e2%80%99s-threats/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/wave-open-sea.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Yesterday’s Security Doesn’t Work for Today’s Threats</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/big-data-and-the-enterprise-cio/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-old-wood.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Big Data and the Enterprise CIO</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/myths-and-realities-of-cloud-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/cut-log.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Myths and realities of cloud security</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://ctovision.com/2011/09/thinking-about-the-traditional-approach/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/5c1597bbb9d4aa4103e2166210768a84_thumb_Cavalrycharge.png" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Thinking About the Traditional Approach</span><span class="nr_source">CTOvision.com</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/gourley-discusses-big-data-security-with-idg/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/mosaic-detail.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Gourley Discusses Big Data Security With IDG</span><span class="nr_source">CrucialPointLLC</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Yesterday%26%238217%3Bs+Security+Doesn%26%238217%3Bt+Work+for+Today%26%238217%3Bs+Threats&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F10%2Fyesterdays-security-doesnt-work-for-todays-threats%2F&nr_ad_number=0&nr_div_number=9");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_9");nRelate.adAnimation("nrelate_related_9");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/10/yesterdays-security-doesnt-work-for-todays-threats/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Big Data and the Enterprise CIO</title>
		<link>http://ctovision.com/2011/10/big-data-and-the-enterprise-cio-2/</link>
		<comments>http://ctovision.com/2011/10/big-data-and-the-enterprise-cio-2/#comments</comments>
		<pubDate>Thu, 06 Oct 2011 06:15:50 +0000</pubDate>
		<dc:creator>AlexOlesker</dc:creator>
				<category><![CDATA[Big Data]]></category>
		<category><![CDATA[CTO]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Bob Gourley]]></category>
		<category><![CDATA[Cloudera]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Crucialpoint]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[HP]]></category>
		<category><![CDATA[IDG]]></category>
		<category><![CDATA[social media]]></category>

		<guid isPermaLink="false">http://ctovision.com/?p=13913</guid>
		<description><![CDATA[Tweet On Monday, September 12, 2011, Crucial Point&#8217;s Bob Gourley met with cyber security industry leaders at the National Harbor Gaylord Convention Center near Washington D.C. during the HP Protect 2011 conference. This event brings together the most significant enterprise cybersecurity capabilities, including highly regarded capabilities like ArcSight and Netwitness and HP Fortify. The event is also an [...]]]></description>
			<content:encoded><![CDATA[<div class="bottomcontainerBox" style="border:1px solid #808080;background-color:#F0F4F9;">
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fctovision.com%2F2011%2F10%2Fbig-data-and-the-enterprise-cio-2%2F&amp;layout=button_count&amp;show_faces=false&amp;width=85&amp;action=like&amp;font=verdana&amp;colorscheme=light&amp;height=21" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width=85px; height:21px;" allowTransparency="true"></iframe></div>
			<div style="float:left; width:80px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<g:plusone size="medium" href="http://ctovision.com/2011/10/big-data-and-the-enterprise-cio-2/"></g:plusone>
			</div>
			<div style="float:left; width:95px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;">
			<a href="http://twitter.com/share" class="twitter-share-button" data-url="http://ctovision.com/2011/10/big-data-and-the-enterprise-cio-2/"  data-text="Big Data and the Enterprise CIO" data-count="horizontal" data-via="ctovision">Tweet</a>
			</div><div style="float:left; width:105px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script type="in/share" data-url="http://ctovision.com/2011/10/big-data-and-the-enterprise-cio-2/" data-counter="right"></script></div>			
			<div style="float:left; width:85px;padding-right:10px; margin:4px 4px 4px 4px;height:30px;"><script src="http://www.stumbleupon.com/hostedbadge.php?s=1&amp;r=http://ctovision.com/2011/10/big-data-and-the-enterprise-cio-2/"></script></div>			
			</div><div style="clear:both"></div><div style="padding-bottom:4px;"></div><p><object width="500" height="281"><param name="movie" value="http://www.youtube.com/v/BBO38WdztXc?version=3"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/BBO38WdztXc?version=3" type="application/x-shockwave-flash" width="500" height="281" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>On Monday, September 12, 2011, <a href="crucialpointllc.com" target="_blank">Crucial Point&#8217;s</a> <a title="Bob Gourley" href="http://twitter.com/bobgourley" rel="twitter">Bob Gourley</a> met with cyber security industry leaders at the National Harbor Gaylord Convention Center near Washington D.C. during the <a href="http://h20331.www2.hp.com/hpsub/cache/281822-0-0-225-121.html?jumpid=ex_2845_vanitysecur/productssecurity/ka011106" target="_blank">HP Protect 2011 conference</a>. This event brings together the most significant enterprise cybersecurity capabilities, including highly regarded capabilities like ArcSight and Netwitness and HP Fortify. The event is also an opportunity to hear from cyber security experts with proven past performance in providing security services.</p>
<p>Enterprise security is a discipline requiring deep familiarity with advanced data management constructs, including &#8220;<a href="http://ctovision.com/bigdata">Big Data</a>&#8221; approaches. Bill Laberis, Senior Editorial Director of <a href="http://www.idgenterprise.com/">IDG Custom Solutions Group</a> interviewed Bob on this topic.</p>
<p>Bill began the interview with a question that has been on a lot of people&#8217;s minds lately. What is <a href="http://ctovision.com/big-data/" target="_blank">Big Data</a>? Bob&#8217;s response started with simple context: Big Data is the data you cannot adequately analyze with your current information architecture. There are more technical approaches to this discussion, but simply put we are all looking for ways to more rapidly analyze larger and larger quantities of information. This is especially true in security. Security professionals need the tools to run on top of their architecture to help them analyze the massive increase in security related data.</p>
<p>Bob noted that security professionals need to worry not only about protecting data from loss by physical means such a floods or hurricanes or fires by physically protecting and backing up the servers, but also by protecting from intrusions and manipulations of data. CTOs and CISOs need to work together in government and enterprise to help each other get the job done better.</p>
<p>When asked what tools can CIOs leverage against the problem Bob responded. CIOs need to be educated about the problem and ho to deal with it.  There are several great resources including <a href="www.apache.org" target="_blank">Apache.org</a> and <a href="www.cloudera.com" target="_blank">Cloudera</a>. Users and architects need to arm themselves with a body of knowledge and then run the analytical tools on top that can help them out. The greatest security solutions, capabilities like <a href="http://www.arcsight.com/">ArchSight</a>, are built with Big Data capabilities as a foundation, which is one of the reasons they scale to serve security needs of all enterprises.</p>
<p>Bill then asked Bob what the vendor community was doing to help with this situation. Bob pointed out that many companies are looking to the examples of some of the large social media platforms that have figured out how to deal with very large amounts of real-time data. Facebook is one such example, with over 700 million users and growing, <a href="www.facebook.com/pages/Crucial-Point-LLC/153858477963727" target="_blank">Facebook</a> deals with a massive amount of instantaneously rendered information and does it well.  Hadoop is a part of their solution.  <a href="twitter.com/crucialpointllc" target="_blank">Twitter</a> and <a href="www.linkedin.com/company/crucial-point-llc" target="_blank">LinkedIn</a> are also great examples of dynamically rendered information being managed effectively. What enterprises need to do is look at how these companies have done it and ask them selves &#8216;How can these solutions help me?&#8217;</p>
<p>For more on topics of enterprise security and end-to-end enterprise IT solutions visit the Enterprise CIO Forum at: <a href="http://www.enterprisecioforum.com/" target="_blank">www.enterprisecioforum.com</a></p>

<div class="nr_clear"></div>	
	<div id="nrelate_related_10" class="nrelate nrelate_related nrelate_default nr_100"><h3 class="nr_title">You may also like -</h3><div class="nr_inner"><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/09/bob-gourley-discusses-big-data-security-with-idg/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/9de79b6d91f8cf09244a41240fab1e70_thumb_big-data.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Bob Gourley Discusses Big Data Security With IDG</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/survey-says-security-risks-never-higher-or-more-costly/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/1566bfe294df4cdcb855d28ec73cb69a_thumb_protect-e1319104550402.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Survey says: Security risks never higher, or more costly</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2010/10/sinet-showcase-27-october-2010/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/7085c1943117fd89432608020683ecf2_thumb_general-hayden-robert-rodriquez-sinet-300x225.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">SINET Showcase 27 October 2010</span></span></a><a class="nr_panel nr_rc_link nr_link nr_internal" href="http://ctovision.com/2011/10/evolving-approaches-to-cyber-threats-2/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/image_cache/ctovision.com/1566bfe294df4cdcb855d28ec73cb69a_thumb_protect-e1319104550402.jpeg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Evolving Approaches to Cyber Threats</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/09/gourley-discusses-big-data-security-with-idg/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/stone-wall-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Gourley Discusses Big Data Security With IDG</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/10/new-enterprise-cio-forum-blog-talk-radio/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-abstract-glass.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">New Enterprise CIO Forum Blog Talk Radio</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/myths-and-realities-of-cloud-security/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/stone-wall-background.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Myths and realities of cloud security</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://crucialpointllc.com/2011/11/note-to-cios-your-organization-will-never-be-100-secure/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-red.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">Note to CIOs: Your organization will never be 100% secure</span><span class="nr_source">CrucialPointLLC</span></span></a><a class="nr_panel nr_rc_link nr_link nr_external" href="http://www.bobgourley.com/2012/01/ctovision-newsletters-and-tech-reports/"><span class="nr_img_div"><img class="nr_img" src="http://imgcdn.nrelate.com/common_wp/default_images/100_100/background-red.jpg" style="height:100px; width:100px;"/></span><span class="nr_text"><span class="nr_post_title">CTOvision Newsletters and Tech Reports</span><span class="nr_source">Bob Gourley</span></span></a><div style="clear:both;"></div></div> <script type="text/javascript"> nRelate.getNrelatePosts("http://api.nrelate.com/rcw_wp/0.50.3/nr_load.php?tag=nrelate_related&keywords=Big+Data+and+the+Enterprise+CIO&domain=ctovision.com&url=http%3A%2F%2Fctovision.com%2F2011%2F10%2Fbig-data-and-the-enterprise-cio-2%2F&nr_ad_number=0&nr_div_number=10");</script></div>
	<!--[if IE 6]>
		<script type="text/javascript">jQuery('.nrelate_default').removeClass('nrelate_default');</script>
	<![endif]-->
	<script type="text/javascript">nRelate.fixHeight("nrelate_related_10");nRelate.adAnimation("nrelate_related_10");nRelate.tracking("rc");</script>
	
<div class="nr_clear"></div>]]></content:encoded>
			<wfw:commentRss>http://ctovision.com/2011/10/big-data-and-the-enterprise-cio-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

