Security's Everyman

Security's Everyman
Showing posts with label Polls. Show all posts
Showing posts with label Polls. Show all posts

Friday, August 01, 2008

Result from DNS Poll

This has been one of the most popular polls that I've had. My post about this garnered a good deal of comments and emails. Most of which disagree with me. Not surprising since usually people who do agree don't comment nearly as much as those who disagree. I'm not through with this either. LonerVamp has come good comments that I want to respond to when I have more time.

There were 106 votes on the poll almost 70% of you said that HD should have released the exploit for one of the 3 yes reasons. The totals were 70 yes and 26 no. For a while I thought I would be the only one to vote "No, It was irresponsible of him". I still stand by that statement and when I respond to Loners comment I'll explain why in more detail. But for now I will say that I'm not against him releasing an exploit at a later date, just not at the time he did.

Here is the breakdown by answer.

Yes, we deserve to have it
18 (16%)
Yes, if he didn't someone else would
24 (22%)
Yes, the bad guys already have their own
28 (26%)
No, it was irresponsible of him to do so
9 (8%)
No, it's too early and several people haven't patched their servers yet.
23 (21%)
No, we don't need WhiteHat exploits.
4 (3%)

I was a little surprised that 4 of you voted "No, we don't need WhiteHat exploits." I'd love to hear from you with your reasoning why you feel that way.

Hopefully by now everyone has patched their servers, including AT&T (that is another irresponsible matter in my opinion) and that this is behind us.

Saturday, July 12, 2008

Information Security Poll on the DNS Patch

I haven't done a poll in a while and decided that the DNS issue was a good time to bring back the poll. I have a simple question "Have You Patched Your DNS Server?"

The reason that I'm asking is because I want to know just how quickly everyone has reacted and whether or not some of you think that it's not a big deal. Also, if you have internal DNS servers that don't get updates from the internet I'm curious as to whether you still patched due to potential insider threat issues.

Thursday, December 13, 2007

Patch Management Poll Results

Judging from the voter turnout for this weeks poll you would think that it was a local government election. Voter turnout is usually in the 10% arena and this week it was closer to about 3%.

Here are the results:
How does your company handle Patch Management?
A)Research, Test, Deploy w/i 30 days 27%
B)Research, Test, Deploy with no set time frame 18%
C)Deploy all soon after release 0%
D)Deploy all after a month or so if no bad effects made known 27%
E)Use MS Update w/ automatic installation 18%
F)We don't need no stinkin' patches 9%

The good news is that most of you are patching your systems and I imagine the one who
voted for (E) is either lying or works in a one may shop running Linux and needs to
patch it.:) The better news is that most of you actually have a plan beyond using MS
Update with no over site. The really good news is that no one said that they were blindly deploying the patches soon after release. Wait, except for those who chose E. :( The bad news is that since so few of you actually voted that makes me wonder if you aren't patching and just don't want to admit it.

There won't be anymore polls this year. It's getting close to the end of the year and
lots of people are going on vacation and when it comes to reading blogs and such I
imagine that lots of people will just give them a quick glance and only actually
read them if they look really interesting or exciting. Actually taking action and
making a choice on a poll is probably asking too much.

Sunday, November 18, 2007

New Poll on Incident Response Plan

I've just posted a new poll about company Incident Response Plans. This is an area that is often over looked and under planned. Many companies don't even realize that there is a need for an IR plan and have no real idea what they would do if an incident occurred. In this day of legal and compliance issues having a plan is no longer just a good idea. The lack of one could cost your company lots more than the cost of clean up. You need to have a plan of attack for a variety of different incidents. The way you would handle a virus outbreak is different than how you would have a server compromise that exposed financial or customer data.

If you don't know where your company stands in regards to an IR Plan don't just take it for granted that they have one. Ask your boss and if there isn't one inform them of the necessity and importance of one. Be prepared to either volunteer to help or be volunteered. :) Do your homework and you may come out smelling like a rose.

Here is the question and the possible answers to choose from. You can find the poll itself here.

When it comes to Incident Response does Your Company


A. Have a formal and tested plan
B. Have a plan that hasn't been tested
C. Has a general idea what they will do
D. Not have a plan

Friday, November 16, 2007

Ethics Poll Results

The polls have closed on the Are You Ethical Poll. Pretty good turn out for the first poll in a few weeks. Here's how it breaks down.

When it comes to company policy do you:


A. Follow all the rules
5 (11%)
B. Have work arounds that are necessary and approved
26 (61%)
C. Break the rules how ever I can
2 (4%)
D. We have Security Policies?
9 (21%)

It turned out about like I thought it would. What surprised me the most (although I'm not sure why) was the number of you who answered D. We have Security Policies? This shows that lots of companies do a poor job of communicating the policies that they do have. Maybe it's because they were created and haven't been seen since. I don't think giving a new hire a book full of documents or a link to an intranet site is a good way to inform them of security policies. But I guess it allows companies to say that they have done their part.

To those of you who answered A. Follow all the rules, I say LIAR!!!! Just kidding. I know that there are those who do and I wish that there were more. It's not an easy thing to do. There are too many things that are easy to get around and really don't cause any harm. They just happen to be against policy. For those who do get around things w/o approval, or even those who do get approval, be careful. Not so much because it can allow bad things to happen (you're a security professional you know better) but because if end users know about it then it can harbor bad attitudes towards IT and we don't need any more of those.

Friday, November 09, 2007

The Polls are Open!!!

I've decided to start my information security polls again. This one relates back to my last post on ethics and the information security professional.

When it comes to company security policies do you:
A. Follow all the rules
B. Have work arounds that are necessary and approved
C. Break the rules how ever I can
D. We have Security Policies?

I have no way of tracking who you are so you can answer honestly and truthfully (of course if you don't then are you really ethical?) :) Something to think about.

Monday, September 17, 2007

Security Purchases Poll Results

Voting was way down this week. Either it was a lousy question or not enough people voted early on and forgot about it. It could also be due to my lack of posting last week. I know traffic to the site was down.

Here is the question and answer choices:

In your Organization are most security purchases based on

1) Reaction to an event or scare 30%
2) Cool Toy "C" level wants to implement 13%
3) Careful Research 30%
4) Good sales pitch by vendor 17%
5) Other (Please leave comment w/ details) 8%

I was glad to see that careful research was up at the top. It wasn't as high as we would like to see it but at least it tied for first. The fact that many purchases are based on a "reaction" isn't surprising but a little disturbing. It's sad that many companies won't take reasonable steps until something bad happens then they often end up buying the wrong solution or buying something that isn't the best fit for their environment.

I also wanted to thank Alex and Dr. Anton for pointing out a couple of options that I left out. I had them in my mind when I wrote the first option (Reaction to an event or scare) but failed to put them in their own category. They are Risk reduction and compliance. Two of the biggest factors in our decisions (or should be) and I forgot them. That's what happens when you try to do something quickly.

I'll have a new poll out shortly. I know you can't wait. :) Please vote this time!!!!!





Monday, September 10, 2007

New Poll is Up

I just put up my new poll for this week. Here is the questions and answers to choose from.

In your Organization are most security purchases based on

Reaction to an event or scare
Cool Toy "C" level wants to implement
Careful Research
Good salses pitch by vendor
Other

If you select Other please leave me a comment and let me know how your company decides on what to buy.

Information Security Poll Results (SPAM)

The poll regarding SPAM and who has done what has ended. Just as a recap here is the question and the answer choices.

Have You or anyone you know actually bought something sold via spam or gotten a virus due to clicking on a malicious email link?

Yes, I bought something. (0%)
Yes, I know someone who bought something. (7%)
No, I have not bought anything nor no anyone who has. (45%)
Yes, I have gotten a virus via a malicious email link. (11%)
Yes, I know someone who has gotten a virus via a malicious link. (54%)
No, I have not nor do I know anyone who has gotten a virus via a malicious email link. (27%)

Obviously the totals add up to more than 100% because you could choose more than one answer.

I like the honesty of those who admitted to getting a virus because the clicked on a malicious link. That's something hard to admit especially when you are in IT or Information Security.
What is really interesting is that only 7% of you even know anyone who has bought something via SPAM. It still boggles my mind that anyone would actually buy something via a complete stranger because they received an email. Just think of the possible dangers. 1) You have now given them your address. 2) You have given them your Credit Card or Bank Account information. 3) Even if they don't do anything malicious w/ the first two you are taking the chance that they will bill you and never ship the product. Unless you are using a 3rd party that guarantees you some sort of protection you are out that money. I guess though that if 7% of all SPAM that is trying to sell you something is acted on that is a whole lot of sales. I don't know what the average actually is but I'd venture to guess is quiet a bit less than 7%.

That is bad enough but to me the real danger here is the potential of getting your machine infected or owned by clicking on a malicious link in and email. Getting a traditional virus or worm is bad but today the real likelihood is that you will get botware that turns your PC into a SPAM bot or allows it to be used for other nefarious purposes. Worse than that is getting a rootkit or keystroke logger that is used to steal your identity and all of your user ID's and passwords for online banking, trading, etc... This can really cause nightmares in real life.

Thanks again for taking my poll and I'll have another one posted soon.

Friday, August 31, 2007

Information Security Poll

My latest information security poll was a hit with y'all. It received more votes than the other 3 combined. I was very pleased to see the response. I have to admit that I did solicit a couple of votes towards the end of the poll. I was in a chat room with some of the other members of the Security Catalyst Community and since I was just a couple of votes shy of 100 I asked any of them who hadn't already voted (and shame on my friends for not being the first) :) to go ahead and vote to push me over the 100 vote mark.

I have to admit that I am quiet surprised at the results. I honestly expected about 95 to 98 percent of the votes to go to the last 2 options (Slightly or None). While they did receive the majority of the votes it was only about 73% of the total vote. The second option (Mostly) received about 26% of the vote and the first option (Completely) received 1% of the votes. My first glance says that some of you were not being completely honest (yes I'm talking to you who voted for option 1). But then Cutaway pointed out to me that there were a couple of different ways to interpret the question and the response could vary depending on your interpretation. As I looked back at the question I see how that could be so I take back what I said of you who voted for option 1. :) Then there is the possibility that those of you who voted for option 1 were talking about yourself. Maybe you are your user.

If the results of this poll really do show that a full 26% of you trust your users to act securely and there was no misunderstanding of the question then that is quiet encouraging. It tells me that y'all are doing a good job in getting the message of security out to your users and that they are listening. I would love to talk with some of you about what it is you are doing that is working so well for you. Please drop me a note either in the comments or via email.

As usual I don't have a question for the next poll yet, but I'll have something in a day or two. Monday is a holiday here in the US so it may be Tuesday before I have something up. I'm hoping to spend most of the weekend enjoying spending time with my Wife and daughters and not blogging or coming up with another poll. Yet, you never know. I am up earlier than them most of the time and that's when I try to catch up on reading and blogging.

Friday, August 24, 2007

New Security Poll

I meant to tell you about this in my last post but I got so irritated and on a rant roll that I completely forgot.

My Information Security Poll for this week will deal with How much do we trust our users to act securely. Here is the question and the answer choices. Go to my home page to take the poll.

How much can you trust your users to act securely?
A. Completely
B. Mostly
C. Slightly
D. Not at All

Friday, August 17, 2007

New Information Security Poll

Yesterday I asked a few guys on the TCC SILC channel for ideas for a new poll. The first suggestion had to do with keeping SSN's. I thought it was ironic because there was a thread on a PCI mail list asking that very question. They guy on the TCC channel that suggested the SSN question was completely unaware of the PCI mail thread. Then when I got home I had a letter in the mail telling me that a company that has access to my PII had had it compromised. It was sold by an employee to a marketing broker. Who knows what happened to it after that. Part of the information that they had was my SSN. How lovely. Then on top of that I remembered a friend who works in a university environment that has had a couple of SSN incidents lately. So all of that combined made me think that a Poll on the validity of companies keeping SSN's was in order. So here is the question and you can rush to my web site to take the poll.

Is there a valid reason for companies (other than employeers) to ask for and keep SSN's?

This is a hot topic in the world of Information Security. Many think that there is no valid reason for any company to ask for them and definitely not to keep them. Then there are those who think that there is a valid business reason. Others argue that it depends on the industry. In my opinion SSN's and ANY PII (personally identifiable information) should only be used when absolutely necessary and storage of them should be kept to an absolute minimum and guarded like it was financial information. Customers are the life blood of any business and need to be treated as such.

Creative Commons License
This work is licensed under a Creative Commons Attribution-NC-SA 3.0.