3 ms·
#2 is the most disturbing to me, simply because it's SO SIMPLE. Know your environment, patch it. My guess would be the reason their security scanners didn't ale
by sputknick 9y ago
#2 is the most disturbing to me, simply because it's SO SIMPLE. Know your environment, patch it. My guess would be the reason their security scanners didn't alert to the missing patch was that they scanner had not been updated. Again, SO SIMPLE, get updated definitions anytime you scan.
#4 I'm fine with, the CEO meeting on IT security quarterly sounds adequate to me. His involvement in IT security should not extend beyond ensuring policy is in place and being acted on. Quarterly is more than adequate to ensure this is being done.
- TallGuyShort 9y agoAgreed on #2. Quarterly meetings with CEO about security don't seem so bad in the general case (although in Equifax's case, security is a way bigger deal), but that shouldn't be all. Only 1 person knew about the patch? Even a medium-size enterprise where security is even a moderate concern should have more people than that focused on security 100% of the time.
- wglb 9y agoQuarterly is possibly fine, but when sparks are flying in the back end, and fluid is pouring out of the transmission on the running engine, CSO needs to be able to access CEO promptly.
- cookiecaper 9y agoFirst, no one gives a crap about security until something like this happens to them. The incentives are not in place to require it. Time and resources spent on security are time and resources not spent on beating the competitor. The best outcome you can hope for if you _do_ spend on security is that your competitor will have some apocalyptic breach similar to this one, and that doesn't happen most of the time, at least not in a way that results in any accountability or visibility. It's important to understand that because it's the reason why your bosses will never care unless/until they have an experience like this, or until they expect someone important to be looking for an opening (audits, due diligence, etc). Second, there are indeed some clowns and cronies hired at these sort of places, but a lot of the people are decently skilled. I'm speaking generally about the workforce at these larger enterprisey companies, as I don't know anyone at Equifax afaik. Technical competence is less of an issue than intra-managerial political games like "shift the blame" and "silo defense", at least some of the time. Part of "intra-managerial games" is having the least-skilled people in the most authoritative positions, leaving decision authority with those least equipped to evaluate a situation and determine a responsible response. I am sure that there is someone at Equifax who saw the news on this vulnerability and registered it as being something they needed to patch. I wouldn't be surprised at all to learn that this person didn't say anything because they learned long ago that there's nothing to be gained by actually trying to get the patch done in any non-routine manner. I also wouldn't be surprised to learn they did try to raise the alarm and were mocked and/or shut down, both by other technical groups trying to avoid the appearance of an issue with "their" section of the system, and/or by management, who are likely to interpret such attempts as alarmism, if not plain political malfeasance. Hate to say it but we're on the brink of a formalized licensing program for security, servers, etc. I am honestly surprised that the mainstream outlets and politicians have not been touting this yet, with all the high-profile and extremely costly data security breaches that have been occurring over the last few years, but I really expect it to come soon. I wouldn't be surprised at all to see Equifax become the Enron-like scapegoat for such legislation.
- uuoc 9y ago> First, no one gives a crap about security until something like this happens to them. The incentives are not in place to require it. Time and resources spent on security are time and resources not spent on beating the competitor. Exactly. I'm reminded about the tale about the two hikers and the bear. Two hikers are out hiking one day, when off in the distance they see a bear running their way to attack them. One starts to run, but the other stops to change his hiking boots to running shoes. The other says: "What are you doing? You can't outrun a bear!". To which the running shoe changer replies: "I don't have to outrun the bear, I just have to outrun you". Same goes here. Don't have to really spend on security, just enough to not actually be the one of the two (or three or four) who suffer a breach.
- konceptz 9y ago#2 is more than just production scanning. Open source vulnerability management is a technology process that has levels of maturity. That being said, a freeware tool could have spotted this right away.
- lloydde 9y agoAlthough open source likely makes up a large part of software inventory, particularly if developing or customizing software, most usually open source isn’t singled out from “software vulnerability management”