| Dell SecureWorks - On the Radar Newsletter - 0211 | |
|---|---|
![]() | |
Dell SecureWorks has been recognized as the Best Managed Security Service within the Reader Trust category of the 2011 SC Awards. Dell SecureWorks won the award for the fifth time in six years.
Click here to read the full story
Much as a carpenter uses a hammer and saw, security research teams utilize a variety of tools to protect valuable information assets and thwart attacks. The knowledge, skill and experience of a security research team add value to an organization's security efforts, and complimenting those attributes with a variety of tools enables more effective, timely protection.
Staying one step ahead of the ever-evolving threat landscape is a challenge. New threats constantly appear, all with one goal: to get to a customers valuable assets. The risks for organizations targeted by an attack are numerous, including (but not limited to) damage to reputation, erosion of market share, direct loss of confidential data, and ultimately a negative impact on revenue and future growth.
A research team defines four valuable parameters in the battle to keep critical information safe:
This information-gathering phase is critical for research teams, which then apply this knowledge to discover, assess, develop, refine and deploy countermeasures to address the greatest security risks as quickly as possible. And technology is a strong ally in the research team's fight. Applying the right tools to mitigate risk is a critical component in stopping threats before they infiltrate a security environment.
Ranging from statistical packages that analyze trends across very large datasets to code disassemblers and compilers, having access to the right tools is essential. Network monitoring tools, operating system tools and debugging tools are all required to help the researcher assess and reverse-engineer vulnerabilities, exploits and patches to deliver countermeasures. Additionally, forensic tools allow a research team to determine the integrity of externally sourced information being analyzed.
Research teams also require access to substantial computing and network resources so they can set up honeypots, honeynets and sandnets, and install malware on different systems to monitor behavior. Researchers rely on these technologies to observe threats and identify new attack patterns, methods and tools. Other technologies enable a team to safeguard their sensitive research and securely collaborate on issues requiring high confidentiality. Encryption technology protects information, allowing communication with other response teams and vendors. Fuzzers and application assessment tools enable researchers to perform black box and white box testing.
Without these and other tools, a research team will not be able to completely understand the risks to the security environment, and their effectiveness in protecting critical assets will be limited. This understanding leads to better defenses moving forward, helping to further secure information assets and provide peace of mind that a research team is accomplishing its mission of keeping your organization ahead of the latest threats.
Thinking of turning to an MSSP for your information security needs? This white paper outlines how to analyze infomation security options in a context understood by everyone - Total Cost of Ownership (TCO) - including how to recognize the true costs of internal security staff, infrastructure, compliance requirements and responding to a significant security incident.
Only 43 percent of small businesses have a plan in place to respond to loss of customer data.
Source: 2010 National Cyber Security Alliance / Visa Small Business StudySM