10 Key Questions to Answer Before Upgrading Enterprise Software

The evolution of software has made possible things we never dreamed. With software upgrades come new competencies and capabilities, better security, speed, power and often disruption. Whenever something new enters an existing ecosystem, it can upset the works.

The cadence of software upgrades in large organizations is typically guided by upgrade policies; the risk of disruption is greater in large organizations—which is the chief reason large companies lag up to two versions behind current software releases. They take a wait-and-see approach, observe how the early adopters fare with software upgrades and adopt as a late majority.

A proper upgrade process involves research, planning and execution. Use these top 10 principles to establish when and why to upgrade:

1. What’s driving the upgrade? Software upgrades addressing known security vulnerabilities are a priority in the enterprise. Usability issues that impact productivity should also be addressed quickly.

2. Who depends on the legacy software? Identifying departments that depend on legacy software allows IT to schedule an upgrade when it has the least impact on productivity.

3. Can the upgrade be scheduled according to our policy? Scheduling upgrades within the standard upgrade cycle minimizes distraction and duplication of effort. Change control policies formalize how products are introduced into the environment and minimize disruption to the enterprise and IT.

4. Is the organization ready for another upgrade? Just because an organization needs a software upgrade doesn’t mean it can sustain that upgrade. Upgrade and patch fatigue are very real. Consider the number of upgrades you’ve deployed in recent months when deciding whether to undertake another one.

5. What is the upgrade going to cost? Licensing costs are only one part of the total cost associated with software upgrades. Services, staff time, impact to other projects, tech support for associated systems and upgrades for systems that no longer work with the new platform must also be included in the total cost.

6. What is the ROI of the upgrade? Software updates that defeat security vulnerabilities are non-negotiable—security itself is the ROI. Non-security related upgrades, however, must demonstrate their value through increased productivity or improved efficiency and reduced costs.

7. How will the customer be impacted? Consider all the ways an upgrade could impact customers and make adjustments before the upgrade begins. Doing so ensures you mitigate any potential issues before they happen.

8. What could go wrong? Since your goal is to increase performance, not diminish it, draft contingency plans for each identified scenario to readily address performance and stability issues, should they arise.

9. What level of support does the vendor provide? Once you understand what could go wrong during the upgrade, look into the level of support the vendor provides. Identify gaps in coverage and source outside resources to fill in as needed.

10. What’s your recourse? No one wants to think about it, but sometimes upgrades do more harm than good. In the event something goes wrong and you need to revert to a previous software version, can you?

Download The Guide to Modern Endpoint Backup and Data Visibility to learn more about how a modern endpoint backup solution can simplify software upgrades.

Rachel Holdgrafer, Business Content Strategist, Code42

[Cloud Security Alliance Blog]

Study on Grade 4-8 Internet Usage Indicates 40 percent Chat with Strangers

Recently, the Center for Cyber Safety and EducationTM released the results of the Children’s Internet Usage Study. The study contrasted the self-reported online behaviors of U.S. kids in grades 4-8 with their parents’ perceptions of their behavior. The findings were surprising and could be a cause for concern for many parents, as it shows that children are spending more time online, including late into the evenings, than their parents were aware. The children indicated they visit sites they know they are not supposed to, and engage with strangers despite warnings from parents. A few of the survey results are below:

  • 40 percent said they connected with or chatted online with a stranger.
  • 30 percent texted a stranger from their phone.
  • 21 percent spoke to a stranger by phone.
  • 15 percent tried to meet with a stranger they first encountered online.
  • 11 percent met a stranger.
  • 6 percent revealed their home address.
  • 53 percent access the Internet for reasons other than homework seven days a week.
  • 49 percent have been online at 11 p.m. or later on a school night.
  • 33 percent have been online at midnight or later.

David Shearer, CEO of (ISC)² and the Center for Cyber Safety and Education said, “We are grateful to Booz Allen Hamilton, a valued partner over the years, for supporting this important initiative to raise parents’ awareness about the types of risky activities their children are engaging in online.  Concerning findings such as these only reinforce the need for educational programs like Safe and Secure Online to help parents play an active role in preventing risks.”

In response to the survey results, the Center updated their Safe and Secure Online program, a leading free education program that teaches families and educators how to be safer online. Certified security expert members of (ISC)² contribute to the development of the program and all members are encouraged to share this information with their families and community. The free education program can be accessed in English at http://www.SafeAndSecureOnline.org. The program materials will be translated into other languages (Spanish, French, German, Portuguese and more) throughout the next few months.

In the U.S., April 28 is ‘Take Your Child to Work Day’ when children accompany their parents to the workplace. The (ISC)² headquarters office will be educating young visitors on how to stay safe online in hopes that children will become more cautious in the future and treat online strangers like they would real-world strangers.

(ISC)² Management

[(ISC)² Blog]

Avoid Monetizing Safety Risk

Last year I attended an international risk management conference and was quite shocked by one of the sessions I attended. One of the presenters said, “ERM’s job is to protect the balance sheet.” Enterprise risk management (ERM) is a function that must address all types of risk, not just financial risk.
Monetizing risk and normalizing risk are two of the biggest problems risk practitioners face. Monetizing and normalizing risk makes it very easy to report risk exposure and risk treatment cost but obscures the true risk impact. When risk impact is obscured or under valued, it causes decision makers to make very poor decisions. This is especially true for safety risk where poorly managed risk events can lead to loss of life.


How much is human life worth?1

When asked this question, many people’s response will be “Human life is priceless.” Unfortunately, the desire to monetize risk impact has given rise for the need to quantify the value of human life. The international standard for the value of human life is $50,000. The Stanford Graduate School of Business conducted research awhile back that indicates the actual value of human life is $129,000. Anyone who has lost a loved one would likely argue that these values are woefully inadequate.

Monetizing risk impact causes these values to be used by decision makers to make decisions about what safety guards are worthwhile and cost effective. Consider a safety risk event that has a risk impact of $2.5 million and the risk treatment cost is $4.4 million. Many decision makers would simply accept this risk because the treatment cost is nearly twice the potential impact, and it doesn’t make economic sense to spend $4.4 million to save $2.5 million.

There would likely be a very different outcome if this risk event was presented to decision makers as a safety risk event that could cause 50 people to lose their lives and the risk treatment cost is $4.4 million. I would like to think that decision makers would choose to spend the $4.4 million to save 50 lives. Please note, 50 lives multiplied by the international standard value of human life of $50,000 is $2.5 million. As you can see, monetizing risk impact can dramatically change the equation.

ERM’s job should be much broader than simply protecting the balance sheet. ERM’s job is to manage all types of risk including budget risk, schedule risk, quality risk, safety risk, reputation risk and mission risk.

Mayo will present How Culture Affects ERM at EuroCACS 2016 30 May – 1 June in Dublin.

Footnote
1 Kingsbury, K. (2008, May). The Value of a Human Life: $129,000. Time.

Joseph W. Mayo, President, J.W. Mayo Consulting Services

[ISACA Now Blog]

2016 Verizon Data Breach Investigations Report (DBIR): Insights from Unit 42

The ninth annual edition of Verizon’s Data Breach Investigations Report (DBIR) has just been released, and Palo Alto Networks is proud to have contributed data and analysis to help make the report as comprehensive as possible. Palo Alto Networks is committed to sharing threat intelligence across the security industry, exposing the evolving nature of threats, in order for organizations to better protect themselves.

This year we extracted a massive dataset from the AutoFocus threat intelligence service on over 38 million sessions carrying over 2.7 million unique malware samples. We worked with the Verizon team to add context to these samples with AutoFocus tag data, illuminating what campaign or family they were associated with.

Rapidly evolving malware

The DBIR team combined our data with intelligence collected from other contributors, coming to the conclusion that the life span of malicious samples is typically very low (i.e. samples are very rarely used more than a few times). The report found that “99% of malware hashes are only seen for 58 seconds or less,” lending credence to the critical need for constantly updated protections deployed back to the network, lest organizations risk being infected by rapidly changing malware.

Shifts in Crimeware

In many ways, this report suggests that the threat landscape has not shifted significantly from the 2015 report. However, it does present one compelling insight into the rise of a threat that is top of many people’s minds, ransomware. The graph below is the average price per payment card record in USD over the last 5 years (Source: Intel Security).

If you were a cyber criminal and had previously focused on stealing credit cards data with malware, the supply of new card numbers into the market in the last few years has made your life very hard. A 76% drop in the price of your offering over 5 years is devastating, and that might make you look for alternative ways to monetize the computers you infect with malware. This graph is a near inverse of the ramp we’ve seen in ransomware attacks between 2013 and today, adding more evidence to suggest cyber criminals may be abandoning certain forms of fraud to focus on their ransomware business model.

Overall, the 2016 DBIR underscores how time-tested techniques for infecting organizations continue to be responsible for the vast majority of breaches. While there may be shifts in monetizing attack, such as moving from stolen credit cards to holding machines for ransom, attackers continue to rely on their old tricks. Primarily motived by profit, we expect cyber attacks to continue going back to highly effective tactics like spearphishing or comprise by infected websites.

[Palo Alto Networks Research Center]

How to Achieve PCI Compliance in AWS

Achieving PCI compliance in Amazon Web Services (AWS) involves determining where AWS compliance efforts intersect with your own compliance efforts. Who is responsible for documentation? And do the same concepts of network segmentation and separation apply within AWS, and if so how? These and many other questions arise when you combine PCI compliance with AWS.

To hear the answers to these and many other questions regarding PCI compliance on AWS with the VM-Series virtualized next generation firewall , please join Palo Alto Networks and Warren Rogers for a webinar on Tuesday May 3 at 10 a.m. PDT.

This is an interesting customer case study. First off, Warren Rogers chose to pursue PCI compliance not because it was a requirement, but because they wanted to improve their security posture and enhance their customer value proposition. Second, if you remove the notion of cloud and virtualization, all of the same questions, considerations and processes Warren Rogers addressed are applicable to PCI compliance on a physical network.

About Warren Rogers: Warren Rogers is a 37-year-old, privately held company that provides the leading fuel system monitoring solution in the industry. Its entire IT infrastructure is housed in AWS, and the Warren Rogers All-Point Monitoring System provides the most accurate and complete information of the fueling operation including every tank and every line. Their customers include companies like QuikTrip, Wilco/Hess, CircleK and many more.

A Customer Case Study: Achieving PCI Compliance in AWS
When: Tuesday, May 3, 2016
Time: 10am PDT, 12pm CDT, 1pm EDT
Speakers: Matthew R. McLimans, Computer Engineer at Warren Rogers
Register Now.

[Palo Alto Networks Research Center]

English
Exit mobile version