Intelligence-led security assurance

Simon Saunders · Computer Fraud & Security · 2014

Have we lost sight of risk as the primary motivation for information security assurance projects? Early in the new millennium, security assurance projects such as penetration testing were still an emerging approach and a big part of the sales process was to explain it and justify the reasons for doing it. It was far from a de facto approach or commoditised and was vying for budget alongside other security projects – such as a new firewall, anti-virus upgrade or completely different exercises such as performance testing. However, once a decision was made to do some testing many clients then asked, ‘what should I test?’. It is rarely the known risks that cause security problems. So we have to work harder to uncover the gap in our knowledge that hackers exploit. One approach for achieving this is intelligence-led assurance. This means proactively seeking out weaknesses and managing these appropriately to ensure that major breaches do not happen, explains Simon Saunders of Portcullis Computer Security.

Read the paper · More papers on PaperTik