Friday, July 9, 2010

The Role Network Devices Play in Defense in Depth

Over the past many years the security industry has coined the phrase “Defense In Depth”. While many Pundants have stated that defense in depth is dead, what I believe the point the Pundants are really trying to get across is administrators are not practicing defense in depth. A spoken or written language, when people no longer use it, is in-fact a dead language. However, with defense in depth, there are still some security professionals that believe defense in depth has not seen it’s true implementation. This is mainly because IT professionals in general are not identifying the roles each network device will play in a defense in depth program.

Because of the this, NWN STAR will help provide a foundation to which IT professionals can better understand some of the roles network devices can play in a defense in depth program. As part of the foundation NWN STAR will identify some of the possible roles an IT professional may encounter or identify in their own network. Then each month NWN STAR will publish an article about the various roles, helping to extend the knowledge and practical deployment of an effective defense in depth program.

The Roles of Network Devices

Due to the nature of network devices requiring an always up status and complexity sometimes surrounding networking equipment, IT professionals usually take a “If it is not broke, don’t fix it” approach. Meaning network devices forgo software upgrades and configuration hardening. However, if the IT professional were able to identify the various roles each device in the network portrayed, then possibly a better plan or approach could be taken to patching and hardening of network systems.

As I see it, there are 2 fundamental types of network equipment, a layer 3 packet switch (a.k.a. a ROUTER), and a layer 2 packet switch (a.k.a switch). Now I know most of you are saying, what about firewalls, IDS/IPS, wireless controllers and so on. If you were to step back, what is a firewall, but a very smart router. What is a wireless controller, but a 802.11a/b/g/n switch. Even an IPS/IDS, depending on the deployment, can be a layer 2 bridging device, i.e a switch, or a layer 3 forwarding device, i.e. a router. So with diving into to all the possibilities up front, if we focus on the core functions of a router and switch, we can identify the roles portrayed by networking devices.

As I was in the Marines for many years in the 1990’s, the analogies I will make will be similar to Marine Infantry. The switch is the initial point of access, so it could be referred to as the front line in our defense perimeter, a.k.a. a Marine Rifle Company. Some of the roles on the front line are the infantry, medics, fire and support, and finally the artillery.

The Switch

In the role of the infantry, the switch will engage with the endpoint and make the first decision on if the node allowed. The switch will monitor the switch traffic and decide if the correct system is connected and if so is the traffic from that system the correct kind.

Then as the medic, the switch must be able to detect injuries to the network and respond accordingly. The medic must also be able to anticipate where problems are going to arise and attempt to divert the injury. An example of this is Navy Corpsman would always make sure the Marines drank lots of water and wore sunscreen. These are two fairly low-tech tasks, yet if Marines don’t have water or are sun burned very badly, they can’t fight. The medic functions of the switch would be similar to a BPDU filter or broadcast storm monitor, and both functions are low-tech and easily configured, they can reduce the threat of tools which can flood the cam table in switch turning it into a HUB.

The fire and support aspect will be the Weapons platoon in a rifle company. The Weapons platoon has heavy machine guns, like the M-60 (Yes I was in when Marines still carried M-60’s) and the 40mm mortars. These systems would be able to attack a larger number of enemy combatants, but remain extremely portable. The switches must be able to act in the same manner, using 802.1x or port-security, a switch can be extremely effective against blocking unauthorized users from gaining access to the network. Additionally using STP port security or private VLAN’s the switch can also provide a greater level of segmentation.

The Router

If the switch is the Marine rifle company, the router and firewalls could be seen as the Marine Expeditionary Unit (MEU). The MEU has an Infantry Battalion, Armored Assault Company, Tank Company, Artillery Company, and an Air Support Wing. All the big fire support needed to support a highly mobile and deadly Infantry Marine. That said, what is the role the router is going to play again, you ask? The answer is quite simple, A BIG role.

A function of the Air Wing and Armored Assault is transportation, hopefully a secure mode of transportation. The role of the router is to secure the transport from one end point to another end point. In doing this, the router can deploy different forms of IPSec, routing table segmentation, and varying levels of packet inspection and filtering.

By packet inspection, a router can now do a deep inspection of packet headers, using Network Based Application Recognition (NBAR), Zone Based Firewall (ZBF), and Quality of Service (QoS). These services can detect flaws in a packet and allow or deny the packet as needed. While the IT professional will not configure all of these features, they might combine the varying features at different levels. For example, when configuring ZBF, the class-maps used to identify traffic could identify traffic using DSCP, IP Pref, or CoS, just to name a few. While the TOS bits, used in the DSCP and IP Pref, can be set using NBAR. Then once the traffic is identified, the traffic can be permitted, denied, and modified in some way to reduce the overall threat. These features can be used to reduce the impact of a DDoS attack, deny packets over a certain size, or throttle traffic down to a limiting factor.

Similar to artillery, the Router can use NULL routes to totally block certain threats based on black lists. A great set of firewall rules and snort rules can be found at http://www.emergingthreats.net. The firewall rules can be changed into NULL route statements, and then advertised via an Interior Gateway Protocol (IGP), to a central router, and then forwarded to a NULL interface, a.k.a. the BIT BUCKET. This is just one way the router can act like artillery and block large blanketing attacks across a wide area.

For a more precise targeted attack against hard targets, the infantry will call in Tanks or Cobra Attack Helicopters. These are great, fast, and super effective. In a similar way, a router can make smaller, more targeted routing rules called Policy Based Routing (PBR). PBR can target traffic entering an interface and forcing traffic to move in a special direction based on a wide number of layer 3 and layer 4 headers.

The Defense in Depth Plan

As with any Marine operation, the Commander gets a set of orders, then formats a plan. So the IT Professional will get a set of business requirements and will format a strategy for supporting these requirements. When the commander first begins his planning, he/she goes to an overlay map and evaluates the current state of the battlefield. So should the IT professional map out the network, even if the map is a high level functional map. Identify critical systems or potential targets, then do a threat assessment. Who is going to attack the system, why would they want to attack the system, and what methods will they use. Then format a plan to defend against those attacks.

For defense in depth to work, the IT Professional must do defense in depth. Look at each layer of access in the network. Some examples are the end-point, switch, wireless, routers, servers, firewalls, VPN termination, and intrusion identification systems (IDS, IPS, SEIM, etc). Once all of these layers can be identified, create your plan. But don’t forget about overwhelming power of network devices, much like the human brain, IT Professionals only use 10% of the features found in networking devices.

Configuration Examples

I also have a blog (www.melcara.com), where I post configuration builders. These are spreadsheet tools used to complete a hardened configuration and create a template easily followed by users with differing skill sets. So feel free to check out the config builders.

Thursday, July 1, 2010

SMB Security - The Forgotten Target

I've performed security assessments for organizations that have thousands or employees and for organizations that could fit every member of the company on a city bus. Some of these assessments were done for very "high-tech" organizations while others barely use computers. Logic would dictate that high-tech large, enterprise-class organizations make the biggest targets and that is probably true but it is not the entire picture. Big organizations make big targets but they also can bring to bear big resources. Even having a single person with the correct skill set focused on security can make a huge difference in the effectiveness of an organization's security program. Small or mid-sized businesses (SMB), on the other hand, are often under-staffed with respect to IT in general and have no security expertise whatsoever. This creates a big problem because while they may know how to deploy a firewall, they don't fully understand the threats and thus have minimal or even non-existent security programs.

Now, you could say that small organizations aren't really big targets because they don't have anything that the bad guys would want. After all, they are small and/or not particularly technical. Well, that's not always the case.

I recently did work for a couple of collections companies. Both were small (with less than 50 employees) but each maintained a database with millions of records containing personal information (can you say identity theft) and even credit card and bank account information. Another customer with less than 50 employees stored significant amounts of sensitive information about pharmaceuticals. Still another sub-50 person company manages over $3 billion in assets. If you were a bad guy hacker, would these targets be interesting to you?

I can wonder and suppose all day long but this is all theory, right? WRONG! A recent article on the Dark Reading site (http://www.darkreading.com/smb-security/security/management/showArticle.jhtml?articleID=225701975&cid=RSSfeed) told the story of a Demolition firm in California that suffered a computer breach that resulted in hackers transferring almost a half a million dollars from the firm's accounts to various accounts worldwide. This happened because an employee clicked on a link in an email that directed them to a malicious web site. The site leverages a vulnerability in Internet Explorer to load a Trojan horse on the employees system. From there the attackers collected information about the company and its finances. This allowed the hackers to conduct 27 transactions involving $447,000.

This example is news for the simple fact that it involved actual theft. The only reason the crime was detected was that funds were transferred. If the attackers were after credit card numbers, personal information or even a place to store contraband child pornography, they might never have been discovered. This should make us wonder.....how many SMBs have already been hacked and just don't know about it? Of equal importance, what can small to medium-sized businesses do to promote security if they have a limited staff, limited resources and limited expertise. Oddly enough, I think for most businesses, the answer is simple. Following a few basic steps, organizations of virtually any size can create an environment that is resistant to attack.

  • Step 1: Patch your technology. This means patching not only Microsoft Operating systems but non-Microsoft operating systems, Microsoft applications, non-Microsoft applications (e.g. Adobe, etc.) and network devices.
  • Step 2: Baseline your environment. Understanding what your environment looks like when it is running normally is critical if you are going to identify abnormal or malicious activity.
  • Step 3: Run anti-virus software and keep it updated. AV is not a silver bullet but it can help. Running AV won't stop all threats but stopping 60% of the malware is better than falling victim to all of it.
  • Step 4: Regularly test your environment using a network vulnerability scanner such as Nessus. This allows you to identify problems before the bad guys can. Vulnerability scanning should be run, at a minimum, weekly and scans should be "credentialled" if possible. Any vulnerabilities that are discovered should be addressed in a timely manner.
  • Step 5: Use mail and web filtering technologies. As shown in the story about the demolitions company, hackers today target end users via their mail clients and web browsers. Leveraging a product or service that scans incoming and outgoing email and web traffic for harmful content reduces the size of these attack vectors and should be considered a mandatory part of any security program.
These steps won't make organizations 100% secure. These steps shouldn't be considered a total security solution. They should be considered to be a good start. They will make any environment more resistant to attack and will allow organizations to more easily identify problems and thus are a decent starting point. The best part - taking these steps can generally be done with a very limited IT staff, minimal security expertise and in a way where the costs can scale to fit virtually any environment.

Remember, from a hackers perspective size does not matter. Smaller organizations represent juicy targets because the rewards can be great and the risk of discovery is small. Change the game and take steps to make your environment more secure. Take control.


Tuesday, December 8, 2009

Security Fundimentals

It's been a while. I haven't posted anything in over a month which is actually a good thing. Things have been very busy and seem to be getting more so. I've just come off doing a series of security assessments for a variety of organizations and have come to a realization - the information security industry is broken.

Now before you get all upset and start bombarding me with hate mail, let me explain. Security professionals often talk about being proactive. It is better to put security in place before something bad happens than after. I agree entirely. While we say this however, we spend a huge portion of our time encouraging reactive thinking. Even when we are being proactive, we are being reactive. That might not seem to make sense but think about this.

In my home office I have a collection of computer security books. Some are focused on various certifications so I'll ignore those for the purpose of this discussion. Of the remaining, I count 25 books. (No, that's not all my books but most are in my office at work). Of these 25 books, 23 are focused, in one way or another, on securing things by understanding how they can be compromised with a few focused exclusively on discussing how to compromise. Only two of the 25 (that's 8%) look at security from an exploit or attack independent perspective. One of these focuses on establishing metrics for security and the other on designing security around detection rather than protection. Let's take this further. Almost all of the news groups and email lists I am a part of focus on the newest vulnerabilities, attacks or victims. Most of the podcasts I look at take about penetration testing, computer forensics or social engineering. As I see it, we spend the vast majority of our time learning how bad stuff could happen then reacting to that knowledge. Hopefully, we are proactively reacting but we are reacting none the less. This creates a situation where "good" security can only be achieved by security experts who fully understand the threat landscape. Unfortunately, not all organizations have access to such people.

The other side of the security industry are the vendors of security technology. They often represent the ultimate in proactive action. They want to sell their products and rightly so. However, in doing so, they are often forced into a situation where they have the solution to a problem that may not exist (at least for any given customer) thus they often try to show the customer why they have a problem and then how "technology A" solves it. This creates a situation where security product implementation may not really match up with actual risk. This means security spend is not in line with risk reduction and potentially leaves areas of significant risk unmitigated.

If the security industry has three sides, the third would be regulation. In my opinion, most security regulations have combined the worst aspects of reactive security with a misalignment of controls vs. risk. Some regulatory writes a document that states, to varying degrees of detail, the controls that organizations need to put in place. Affected organizations then react to the regulation by implementing the mandated controls and completing their compliance checklist. They effectively replace security with compliance assuming they are one and the same. Unfortunately, they are not. The result, excessive spend that may not be in line with actual risk and that doesn't actually accomplish the security goals of the regulation.

So what are we missing? In my opinion, what we are missing is a set of basic, fundamental security measures that are easily understood, that can be implemented in virtually every environment and that don't require reading hundreds or thousands of pages of highly technical documentation to understand. Furthermore, these measures cannot be tied to specific technologies. Basically, I'm thinking of some basic uses of common technology and some operational processes that "everyone" can use. Some things that come to mind are:

- Segmenting the network based on business requirements
- Applying access controls to network segments
- Ingress AND egress filtering on firewalls
- Logging ALLOWED inbound & BLOCKED outbound firewall traffic
- Basic data classification measures
- Security incorporated into change control procedures
- Implementation of basic hardening standards for core technologies

The list can get longer but hopefully you get the idea. By putting together some basic guidance, the average IT person who also must deal with security has a good place to start. They can create a technical and operational environment that supports security by design rather than having to try to layer security on top of in inherently insecure environment using the vendor or regulation-recommended technology of the day.

Thoughts?

Friday, October 2, 2009

Where Compliance Went Wrong

Earlier this week I had the opportunity to give a presentation on the new Massachusetts Privacy law or 201 CMR 17. The goal of the presentation was to give attendees a detailed understanding of what the law required, penalties for non-compliance and a roadmap for cost-effective compliance. The presentation itself however, is not the focus of this discussion. Rather, a question asked by an attendee is. During the course of the presentation, one participant asked "if I'm 100% compliment with 201 CRM 17, will I still be fined if there's a breach?" My short answer at the time was "Yes" (although it is still a little unclear how that fine will be determined. The question however, got me thinking.

With regulations like Sarbanes-Oxley, GLBA and the HIPAA Security Standards the focus is on input. What do I mean by that? Well, many of the various laws define that you must implement controls to make sure something bad doesn't happen. In some cases, organizations are left to determine the specifics of the controls while in other, the control requirements are relatively detailed. They key is that these regulations tell organizations what they must do to stop bad things from occurring. I'm referring to this as "input" focus because the regulations focus on what needs to go into a security program.

The converse to this is an "output" focused law. California Senate Bill 1386, the first well known state privacy law, is an example of this. The law is very light on requiring organizations to do anything as far as implementing controls. It is very short and to the point. If you suffer a security breach that results in the disclosure of personal information, bad things will happen to you. The only "control" really mentioned is encryption and even that is not required. This approach allows organizations to perform their own risk assessment and implement the controls they feel are necessary to reduce risk to an acceptable level.

While there is probably no perfect solution, the question asked during my recent presentation highlighted the major flaw in "input" focused regulations. With this type of regulation, compliance does not equal security. Recent security breaches where the organization was previously identified as "compliant" highlight this problem. Unfortunately, the response to these events was to blame the auditor. I watched numerous discussions where people made the case that auditors should be held responsible should a "compliant" organization suffer a breach. I'm sorry but that is just plain stupid. That removes the decision making responsibility from the organization and put it in the hands of a third party who will do what is in their best interests. That means, to a large degree, massive risk avoidance rather than reasonable risk management. Risk avoidance then results in significant increases in cost that are way out of line. Ask yourself this, if you were told that you had to audit another company for security and if they suffered a breach, you would be held responsible, what would you do?

Another problem with "input" focused regulation is that it forces organizations to focus on the specific regulation requirements rather than on good overall security. In response, many organizations create checklists for compliance. They will do the minimum to check off each item in the checklist and nothing more. Suffice to say that this is not the best approach to security either. In effect, it gives the attacker a list of exactly what you are doing and what you are not doing to secure sensitive data. It's no wonder "compliant" organizations often suffer security breaches.

Back to the questions I was asked. If I'm 100% compliment with 201 CRM 17, I will still be fined if there's a breach? To me, that sounds like a significant amount of input focus. I'll restate the question. If I complete everything on the 201 CMR 17 checklist, do I really need to worry about actually protecting personal information? The same question can be asked about other regulations.

Now, let's look at output focused laws like many of the state privacy rules. They simply say that organizations are requited to protect personal information and if they don't, bad things happen. Generally speaking, there are no requirements for periodic audit and there are no checklists for compliance. If you protect personal information, you win. If you fail to protect personal information, you suffer the consequences.

It seems obvious to me that the current method of checkbox security doesn't work well. All it has done is increase IT spend and increase costs of external audit without any real gains in security. Perhaps more focus on achieving security goals and objectives and less focus on a bunch of predefined controls might be a good idea.

Wednesday, September 2, 2009

Snow Leopard Install Knightmare

Well, it happened. On Friday of last week I ran out to the Apple store and purchased Snow Leopard. More specifically, I purchased the Snow Leopard Box Set with iLife '09 and iWork '09. That was one lucky purchase but more on that later.

After a bite to eat I introduced my MacBook Pro to the Snow Leopard disk. They seemed to get along well for the first minute or two. Then the Snow Leopard installation routine asked me where it should install Snow Leopard. There is only one problem. NONE of my disks including the default "Macintosh HD" were identified as "bootable" and thus Snow Leopard woudn't install. No options, no nothin'. I then went to my favorite troubleshooting tool - Google. I discovered that others were having the same problem but there was no definitive solution. Some people said it had to do with PGP Desktop so I removed PGP Desktop. That didn't work. Some said there was a backup file in the root directory of the hard drive that would cause the problem but that file didn't exist. I tried booting from the install disk. Fail! So what's next? Call Apple.

I got tech support on the line and told them what was going on and what I did. They politely asked me if they could put me on hold and then did so. They came back and had me boot from the install disk and attempt to repair the disk volume. No problems were detected (I had already checked but humored them nonetheless). They put me on hold again and came back with the secret, fine-print, little known fact. The upgrade from Leopard to Snow Leopard works for computers that had Leopard originally installed but not for computers that originally had Tiger. I was told that I needed to buy the full version and not the upgrade. I asked how much that would cost. I then mentioned that I was a little upset as I had already dropped $170 on the "box set". At this time I was somewhat relieved as we had found the solution. At the same time I was a little ticked off because I was going to have to drop even more money on this upgrade. The tech support guy heard me mention the box set and put me on hold again. It turns out that the box set is the full version and thus I had the right product and it still wouldn't install. The brought in another tech support guy to help. This one was a product specialist.

We did another troubleshooting dance, going round and round. We tried to install Leopard on top of Leopard with no success. OK, so it's not a Snow Leopard problem but something wrong with my laptop. We checked the partition information and found all was as it should be. We checked a few other settings associated with the disk and still found no problems. What was the final option? We had to re-partition the hard drive. Yep, that's right. We blew out the whole thing and installed from scratch. I guess it's a good thing that I purchased the "box set".

After a clean install I was able to use my Time Machine backups (completed earlier in the day) to restore my profile, applications, etc. After using the Mac for a couple of days now, everything seems to be working well. I'm still figuring out all the in's and out's of the new Exchange integration but otherwise, everything is working.

Total time to install Snow Leopard including restoring from Time Machine and installing iWork and iLife upgrades - about 6 hours.

Thursday, July 9, 2009

Massachusetts Privacy Law - Why EVERYONE should care

The Massachusetts Privacy Law (AKA 201 CMR 17.00) is on the horizon with the deadline for compliance is 6 months away. While many states have instituted privacy laws, this one is a game changer and affects companies beyond those geographically located in Massachusetts. Why is that? I'm glad you asked. Here are some things you need to know:

Q: Who does the law apply to?

The law applies to any person or business who owns, licenses, stores or maintains personal information about a resident of the Commonwealth of Massachusetts. Keep in mind, this is not limited to Massachusetts-based companies. Technically, a company based on California that has personal information about a Massachusetts resident must comply.

Q: What is the purpose of the law?

The law establishes minimum standards for safeguarding personal information in both paper and electronic form.

Q: When does the law go into effect?
Organizations must be in full compliance with the law on or before January 1, 2010.

Q: What is “personal information”?
The law defines personal information as a first and last name or a first initial and last name in combination with any of the following:
- Social security number
- Driver’s license number
- State-issued identification card number
- Financial account number
- Credit or debit card number (with our without access code or PIN)

Q: What does this law require?
The law places a number of requirements on every person or organization “covered entities” that owns, licenses, stores or maintains personal information about a resident of the Commonwealth of Massachusetts. To comply with this law, covered entities must:

- Develop, implement, maintain and monitor a comprehensive, written information security program. Such a program must contain administrative, technical and physical safeguards to ensure the confidentiality of personal information.

- Designate one or more employees to maintain the comprehensive information security program.

- Identify and assess foreseeable internal and external risks

- Evaluate and seek to improve the effectiveness of existing safeguards on an ongoing basis including; (1) Performing ongoing employee (including temporary and contract employee) training, (2) Verifying employee compliance and (3) Implementing a means for detecting and preventing security system failures

- Develop security policies

- Impose disciplinary measures for violations of security program rules

- Prevent terminated employees from accessing records containing personal information.

- Take all reasonable steps to verify that any third-party service provider with access to personal information will protect it

- Limit the amount of personal information collection to the greatest extent possible, limiting the time such information is retained and limiting access to that information as possible.

- Identify paper, electronic and other records, computing systems, storage media (incl. laptops and portable devices) used to store personal information.

- Implement restrictions to physical access to personal information records including a written procedure that defines the manner in which physical access is restricted.

- Perform regular monitoring to ensure that the security program is operating in the manner designed.

- Review the scope of security measures at least annually or whenever there is a significant change in business practices.

- Develop an incident response plan.

- Implement reasonably strong user authentication

- Implement access controls to restrict access to personal information

- Encrypt all transmitted records or files containing personal information that will travel across public or wireless networks

- Perform monitoring of systems for unauthorized use of or access to personal information

- Encryption of all personal information stored on laptops or other portable devices

- Provide firewall protection, up-to-date patching and up-to-date anti-malware signatures of all systems containing personal information that are connected to the Internet

- Conduct regular education and training of employees

Q: Wow, that's a long list. Can you summarize all of that?
Sure. Basically organizations need to:
- Perform an assessment to identify internal and external risks.
- Develop a formal, documented information security program based on the results of the risk assessment.
- Document the program via a suite of information security policies.
- Utilized strong authentication methods and strict access controls
- Ensure effective patch and configuration management
- Implement physical access controls
- Incorporate risk assessment into daily operations
- Perform regular internal audits to verify compliance
- Use secure, encrypted communications protocols
- Perform security monitoring and maintain an incident response program

Q: What can be done to comply with this law? What are the next steps?
First, and most importantly, it is critical to perform of an initial compliance/risk assessment. During such a project you would ideally accomplish two simultaneous goals; assess your current security posture to identify any compliance gaps and perform the initial risk assessment dictated by 201 CMR 17.00.

Based on the outcome of the assessment, there are a number of initiatives that will commonly be required:
- Development of information security policies
- Development of an internal audit program
- Performance of periodic security reviews
- Penetration testing & web application security testing
- Development of an incident response plan
- Configuration of technologies to provide encrypted communications protocols

One final thought. Keep in mind that the law specifically states that compliance will factor the size of the business, the resources available, the amount of stored data and the need for confidentiality of both customer and employee information. Because of this, our recommendations to any customer will only be based on the outcome of a risk assessment.

All of that said, if you are a company that "does business" in the Commonwealth of Massachusetts, you should take a hard look at your security posture and your level of compliance with the requirements of this law. Failure to do so could mean failure to comply with the law and that could open you up to legal liability risks, public relations problems and a host of other nastiness that nobody wants.

Tuesday, July 7, 2009

10 Most Dangerous Infosec Mistakes

I have had the opportunity over the past couple of months to perform security assessments for a bunch of different organizations including hospitals, universities, manufacturing companies and real estate companies. While the results of these assessments are as unique as the companies for which they were performed, I have noticed some common trends. I thought it would be interesting to try to condence them down into a "top 10" list.

1. Ignoring web application security
2. Poor patch management (expecially internal systems and workstations)
3. Lack of a risk basis to security decisions (or making decisions based on fear uncertainty and doubt)
4. Relying solely on the perimeter for protection
5. Ignoring the operational aspects of security (e.g. IDS tuning, maintenance, incident response, etc.)
6. Poor password management (Is 8 characters with an upper, lower, numeric and special char. changed every 90 days really strong?)
7. Ignoring detection - focusing solely on attempts at protection
8. Failing to account for users (who will always find a way to break security)
9. Failing to implement a DMZ, allowing external access directly to the internal network
10. Focusing exclusively on completing regulatory "checkboxes" - compliance does not equal security

As you read this list, ask yourself, is this you? Have you adequately tested the security of your web applications? Have you conducted a web application penetration test that is complete and comprehensive? If not, how do you now your web applications are secure?

What about patch management? Cross site scripting, email-based links and malicious Javascript make your end users direct targets. If an end user workstation gets compromised the attacker can continue their attacks from within your network perimeter. What will they be able to do? Are you expecting your firewall and other perimeter devices to provide protection in this scenario? Is your network resistant to attack from within? Have you implemented proper network segmentation and implemented strong access controls between internal segments?

If an attacker were to get in, are you ready? Do you have sufficient detective capabilities to identify the attack in its early stages or will you wait until a partner, customer or other third party notifies you of the breach? If you notice the attack, do you have a formal, approved incident response plan in place? What are your incident response goals? Do you want to conduct a forensics investigation or simply get the system back up and running? What about notifying law enforcement?

What about regulatory compliance and risk? Does your security plan focus exclusively on meeting regulatory compliance requirements or are you making security decisions based on assessed risk? One way will cost a lot and achieve little with respect to actual risk reduction. The other reduces costs, achieves compliance in the face of a dynamic regulatory landscape and reduces business risk to an acceptable level. Which are you doing.

I have put together a podcast that covers each of the items on this top 10 list so if you are interested, give it a listen. If you want to discuss this in more detail, please reach out to me. Also, don't forget to follow me on twitter - http://www.twitter.com/nwnsecurity - and on facebook (kevinfiscus).

Take care!

Kevin