| |

Microsoft discusses Security Challenges at RSA2013

February 26, 2013, RSA Conference, San Francisco—Scott Chaney from Microsoft proposed some interesting concepts from a software company. The challenges of securing computers from attacks and the costs of a security breach are common headline material these days.

One concept is to ensure end-to-end trust. This idea requires a hardware-based security structure to address the increasing complexity of certifications and compliance. Even with all the new software, systems still need a root of trust. The imposition of more hardware, however, raises the question of operations and security versus user privacy.

Recent advances like UEFI set up a trusted and measured boot sequnce that identifies the machine. Computers are being built better to increase security. In addition, companies are adopting a security development lifecycle and getting machines that can scale up the built-in security. The emerging standards are helping IT to secure the compute environment.

The security landscape is driving companies to work at meeting the market challenges, while the tense atmosphere is pushing users to adopt more security measures and becoming an inflection point. Networks need to identify users and devices, and the overall system must get credential alignment.

Outside the enterprise, consumers are slow to adopt any security measures that are inconvenient to them. For example, ID cards are being replaced with electronic ID cards. The government works to reduce the number of layers in government, as people, services, and standards move towards more interoperability. Now the organizations like the DMV are the access points for many government identity functions. however the consumers only acquiesce through government edicts. 

The range of access ports makes for a plethora of delivery models, apps stores, cloud, etc, and all need to establish minimum security standards. The remediation models like killbit lets users manage updates easily in the cloud. Operational security requires policies that mandate patching apps and operating systems regularly.

On top of the individual devices, the systems need to have the technologies for prevention, detection, containment, and response to any attempts for intrusion. Best practices can account for about 85 percent of operational security. Effective policies and procedures include authorization management. The key to better security is credential management authorization.

International cooperation and cyber security strategies can address the four main areas of cyber threats: crime, state-sponsored attacks, military espionage, and cyber warfare.  The enterprises need to focus on each area and find ways to harmonize the efforts and develop cyber norms. Current systems and networks have too much noise. Increasing authentication will reduce the pool of suspects for attacks. The enterprises are making slow progress with the norms, leading to better Internet health. The movement towards acceptance of code of conduct and more public-private cooperation is helping improve security.
 

Similar Posts