10
Future Security ZACon Conference A Olivier [email protected] Twitter: anthonyolivier www.discussIT.co.za

A future security landscape

Embed Size (px)

DESCRIPTION

Anthony OlivierZaCon 2009http://www.zacon.org.za/Archives/2009/slides/

Citation preview

Page 1: A future security landscape

Future Security ZACon Conference

A Olivier

[email protected]

Twitter: anthonyolivier

www.discussIT.co.za

Page 2: A future security landscape

Opinions “We have had the same Information Security problems for 25 years. We

still haven’t solved them”

“For $200.000 dollars you can hire the hacking team that will crack anything. That’s less than the average American bank’s Anti Virus budget”

“We are being overwhelmed by governance”

“The complexity of new IT systems exceeds our capacities to secure them”

Page 3: A future security landscape

The security cost curve?

Operations New Opportunity cost

Systems

Perimeter

Data

Applications

Process

Systems

Perimeter

Data

Applications

Process

Systems

Perimeter

Data

Applications

Process

This is the security frontier

Page 4: A future security landscape

`The Frontier: Semantic Web

The Semantic Web is an evolving development of the World Wide Web in which the meaning (semantics) of information and services on the web is defined, making it possible for the web to understand and satisfy the requests of people and machines to use the web content

(wikipedia)

Page 5: A future security landscape

The Frontier: Social Networking

!   Gartner predictions: !   By 2012 more than half the people we communicate with in

our personal lives we will never have met face to face !   By 2012 Social Networking tools will have superseded eMail

for personal communications

!   New developments: Google Wave, Twitter Lists, search from Google and Bing

!   Legal implications unclear – what Wave document is legal?

!   Targeted SN attacks – while the individual gives away information. Privacy – yesterday Google modified their dashboard to provide users with privacy controls

Page 6: A future security landscape

The Frontier: Man Machine Interface

!   Shift towards more natural interface, with implications for an “engaged network” !   Microsoft Surface

!   Microsoft Natal

!   Emotiv

!   Nike Run

!   Information collection capabilities exceed our ability to manage the data about us (notwithstanding Google’s efforts)

Page 7: A future security landscape

The Frontier: Virtual Worlds

!   Virtual worlds most likely to evolve into business focused tools: Toyota, Wells Fargo, IBM, Cisco et al

!   Money laundering

!   Revenue streams: the hairdressers of the virtual world

!   Virtual worlds hint at a new reality: the intersection of technologies in which multiple personalities in multiple contexts become the norm.

Page 8: A future security landscape

The Frontier: Already Here

!   Service Oriented Architectures: !   Existing standards (WSS) address only part of the problem

!   Consider the privacy issues surfaced by Google Street Level View

!   Where does mashup liability reside

!   Cloud computing: !   Economics will drive IT into the cloud

!   Publicized security failures already: companies will be driven to lower their guards in order to remain competitive.

Page 9: A future security landscape

A Risk-Based Progression

Restrictions

Page 10: A future security landscape

Debate