Following the Wh1t3 Rabbit - Practical Enterprise Security

Enterprise Security organizations often find themselves caught between the ever-changing needs of the agile business, and the ever-present, ever-evolving threats to that business. At the same time – all too often we security professionals get caught up in “shiny object syndrome” which leads us to spend poorly, allocate resources unwisely, and generally de-couple from the organization we’re chartered to defend. Knowing how to defend begins with knowing what you’ll be defending, why it is worth defending, and who you’ll be defending from… and therein lies the trick. This blog takes the issue of enterprise security head-on, challenging outdated thinking and bringing a pragmatic, business-aligned, beyond the tools perspective … so follow the Wh1t3 Rabbit and remember that tools alone don’t solve problems, strategic thinkers are the key.

Rafal (Principal, Strategic Security Services)

SecOps - Security's a Need-to-Know Event Problem

Security OPS teams are often limited by their own rules. When an event is suspected, the only people allowed to have knowledge and information about the suspected event are security people, which limits not only the effectiveness of that investigative body, but also the effectiveness of detection, early-warning, and response ultimately. This need-to-know problem is the reason why many organizations have separate IT OPS and Security OPS event managers, ticketing systems, and investigative processes... 

SecOps - A step closer to bridging the Security Operations and IT Operations organizations

Today's post is a guest-blog by Scott Edwards, from the HP BSM (Business Service Management) group - oddly enough not a 'security' function - but as I promised in a previous post to provide more information on the SOC + NOC integrations.  This is some very cool, very useful stuff that crosses domains from security to network and applications - beyond the boundaries of traditional security.  I think you'll enjoy the read, and more importantly find the opportunity to enrich your IT Operations <> Security Operations relationship and efficiency.

Search
About the Author(s)


HP Blog

HP Software Solutions Blog

Community Announcements
Follow Us
Labels