<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>Speaking of Security - The RSA Blog and Podcast &#187; Art Coviello</title>
	<atom:link href="http://blogs.rsa.com/author/art-coviello/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.rsa.com</link>
	<description>The Security Blog for Security Professionals</description>
	<lastBuildDate>Fri, 17 May 2013 12:30:58 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5</generator>
<!-- podcast_generator="Blubrry PowerPress/4.0.7" -->
	<itunes:summary>The Speaking of Security podcast features lively discussion with industry experts on the latest issues and trends in the security industry.</itunes:summary>
	<itunes:author>RSA, The Security Division of EMC</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://blogs.rsa.com/wp-content/uploads/userphoto/sos.png" />
	<itunes:owner>
		<itunes:name>RSA, The Security Division of EMC</itunes:name>
		<itunes:email>podcast@rsa.com</itunes:email>
	</itunes:owner>
	<managingEditor>podcast@rsa.com (RSA, The Security Division of EMC)</managingEditor>
	<itunes:subtitle>The Security Blog for Security Professionals</itunes:subtitle>
	<itunes:keywords>Security, Cyber Crime, APTs, Sam Curry, RSA, EMC, Advanced Persistant Threats, Fraud</itunes:keywords>
	<image>
		<title>Speaking of Security - The RSA Blog and Podcast &#187; Art Coviello</title>
		<url>http://blogs.rsa.com/wp-content/uploads/userphoto/sos.png</url>
		<link>http://blogs.rsa.com</link>
	</image>
	<itunes:category text="Technology">
		<itunes:category text="Tech News" />
		<itunes:category text="Podcasting" />
	</itunes:category>
		<item>
		<title>The move to an intelligence-driven security model</title>
		<link>http://blogs.rsa.com/the-move-to-an-intelligence-driven-security-model/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-move-to-an-intelligence-driven-security-model</link>
		<comments>http://blogs.rsa.com/the-move-to-an-intelligence-driven-security-model/#comments</comments>
		<pubDate>Tue, 08 Jan 2013 14:00:11 +0000</pubDate>
		<dc:creator>Art Coviello</dc:creator>
				<category><![CDATA[Big data]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Big Data]]></category>
		<category><![CDATA[Information Sharing]]></category>
		<category><![CDATA[Intelligence-driven security]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security intelligence]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=7699</guid>
		<description><![CDATA[Albert Einstein defined insanity as doing the same thing over and over again and expecting different results. Reflect on that for a moment. For the past 10 years, the Internet has become a ubiquitous form of communication. Growth of digital content and use of mobile devices have soared, organizations have opened their infrastructures to enhance [...]]]></description>
				<content:encoded><![CDATA[<div id="attachment_7700" class="wp-caption aligncenter" style="width: 310px"><a href="http://blogs.rsa.com/?attachment_id=7700" rel="attachment wp-att-7700"><img class="size-medium wp-image-7700" alt="Image: Internet cables are seen at a server room REUTERS/Kacper Pempel" src="http://blogs.rsa.com/wp-content/uploads/intel-driven-model-300x168.jpg" width="300" height="168" /></a><p class="wp-caption-text">Image: Internet cables are seen at a server room REUTERS/Kacper Pempel</p></div>
<p>Albert Einstein defined insanity as doing the same thing over and over again and expecting different results. Reflect on that for a moment.</p>
<p>For the past 10 years, the Internet has become a ubiquitous form of communication. Growth of digital content and use of mobile devices have soared, organizations have opened their infrastructures to enhance productivity and, for our reflection on Einstein’s quote, as nation states, criminals and hacktivists have taken obscene advantage of all of us. Meanwhile, IT organizations have continued to construct security infrastructures around a disintegrating perimeter of increasingly ineffective controls.</p>
<p>If you have heard my opinions before about the need for change, maybe you think I am the insane one. Perhaps that is the case, but in the past year I have talked with many security executives and get agreement that a new model of cybersecurity makes sense. What is it? An intelligence-driven security system consisting of multiple components:</p>
<ol>
<li>A thorough understanding of risk</li>
<li>The use of agile controls based on pattern recognition and predictive analytics</li>
<li>The use of big data analytics to give context to vast streams of data to produce timely, actionable information</li>
<li>Personnel with the right skill set to operate the systems</li>
<li>Information sharing at scale</li>
</ol>
<p>How do we move from traditional security to intelligence-driven security?</p>
<p>First, we need to address security budgets. The vast majority of the spend is still preventive and perimeter-based, static and inflexible, making it increasingly difficult to timely detect a breach and have the capability to respond fast enough to avoid loss.</p>
<p>Second, the capability to respond to threats is not just about technology. We face a severe skills shortage. We need to work on ways to find new talent or train new talent. The number of security professionals worldwide needs to increase from 2.25 million today to 4.25 million by 2015. Where are they all going to come from?</p>
<p>Third, there is a need for more understanding and information sharing. We need context, not a list of the latest breaches – a broader and more collaborative understanding of the problems we face and the enemies we are fighting.</p>
<p>The implication of these forces holding back security is that security models are not moving fast enough to make the transition from perimeter-based to intelligence-based security, while adversaries become more sophisticated.</p>
<p>Why should any of this matter to you? It’s a cliché, but we are only as strong as our weakest link and we are interdependent as never before. Attacks on one of us have the potential to be attacks on all. My position is that we are truly crazy if we don’t act and change. You don’t have to be Einstein to figure this out.</p>
<p><em>Author: Art Coviello is Executive Chairman of <a href="http://blogs.rsa.com/" target="_blank">RSA</a>, The Security Division of EMC</em></p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&amp;t=The%20move%20to%20an%20intelligence-driven%20security%20model"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=The%20move%20to%20an%20intelligence-driven%20security%20model%20-%20http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&amp;title=The%20move%20to%20an%20intelligence-driven%20security%20model&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=%0D%0A%0D%0AAlbert%20Einstein%20defined%20insanity%20as%20doing%20the%20same%20thing%20over%20and%20over%20again%20and%20expecting%20different%20results.%20Reflect%20on%20that%20for%20a%20moment.%0D%0A%0D%0AFor%20the%20past%2010%20years%2C%20the%20Internet%20has%20become%20a%20ubiquitous%20form%20of%20communication.%20Growth%20of%20digital%20co"></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=The%20move%20to%20an%20intelligence-driven%20security%20model&body=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-7699')" id="sociable-post-7699" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&amp;t=The%20move%20to%20an%20intelligence-driven%20security%20model"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&amp;title=The%20move%20to%20an%20intelligence-driven%20security%20model&amp;notes=%0D%0A%0D%0AAlbert%20Einstein%20defined%20insanity%20as%20doing%20the%20same%20thing%20over%20and%20over%20again%20and%20expecting%20different%20results.%20Reflect%20on%20that%20for%20a%20moment.%0D%0A%0D%0AFor%20the%20past%2010%20years%2C%20the%20Internet%20has%20become%20a%20ubiquitous%20form%20of%20communication.%20Growth%20of%20digital%20co"></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&amp;title=The%20move%20to%20an%20intelligence-driven%20security%20model&amp;bodytext=%0D%0A%0D%0AAlbert%20Einstein%20defined%20insanity%20as%20doing%20the%20same%20thing%20over%20and%20over%20again%20and%20expecting%20different%20results.%20Reflect%20on%20that%20for%20a%20moment.%0D%0A%0D%0AFor%20the%20past%2010%20years%2C%20the%20Internet%20has%20become%20a%20ubiquitous%20form%20of%20communication.%20Growth%20of%20digital%20co"></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&amp;title=The%20move%20to%20an%20intelligence-driven%20security%20model"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&title=The%20move%20to%20an%20intelligence-driven%20security%20model"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&amp;title=The%20move%20to%20an%20intelligence-driven%20security%20model&amp;annotation=%0D%0A%0D%0AAlbert%20Einstein%20defined%20insanity%20as%20doing%20the%20same%20thing%20over%20and%20over%20again%20and%20expecting%20different%20results.%20Reflect%20on%20that%20for%20a%20moment.%0D%0A%0D%0AFor%20the%20past%2010%20years%2C%20the%20Internet%20has%20become%20a%20ubiquitous%20form%20of%20communication.%20Growth%20of%20digital%20co"></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&amp;t=The%20move%20to%20an%20intelligence-driven%20security%20model"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=The%20move%20to%20an%20intelligence-driven%20security%20model&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=%0D%0A%0D%0AAlbert%20Einstein%20defined%20insanity%20as%20doing%20the%20same%20thing%20over%20and%20over%20again%20and%20expecting%20different%20results.%20Reflect%20on%20that%20for%20a%20moment.%0D%0A%0D%0AFor%20the%20past%2010%20years%2C%20the%20Internet%20has%20become%20a%20ubiquitous%20form%20of%20communication.%20Growth%20of%20digital%20co"></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&amp;Title=The%20move%20to%20an%20intelligence-driven%20security%20model"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&amp;title=The%20move%20to%20an%20intelligence-driven%20security%20model&amp;selection=%0D%0A%0D%0AAlbert%20Einstein%20defined%20insanity%20as%20doing%20the%20same%20thing%20over%20and%20over%20again%20and%20expecting%20different%20results.%20Reflect%20on%20that%20for%20a%20moment.%0D%0A%0D%0AFor%20the%20past%2010%20years%2C%20the%20Internet%20has%20become%20a%20ubiquitous%20form%20of%20communication.%20Growth%20of%20digital%20co"></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&amp;t=The%20move%20to%20an%20intelligence-driven%20security%20model&amp;s=%0D%0A%0D%0AAlbert%20Einstein%20defined%20insanity%20as%20doing%20the%20same%20thing%20over%20and%20over%20again%20and%20expecting%20different%20results.%20Reflect%20on%20that%20for%20a%20moment.%0D%0A%0D%0AFor%20the%20past%2010%20years%2C%20the%20Internet%20has%20become%20a%20ubiquitous%20form%20of%20communication.%20Growth%20of%20digital%20co"></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&amp;title=The%20move%20to%20an%20intelligence-driven%20security%20model&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fthe-move-to-an-intelligence-driven-security-model%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-7699')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-7699',true)" class="close">

		  <img onclick="hide_sociable('post-7699',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/the-move-to-an-intelligence-driven-security-model/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/the-move-to-an-intelligence-driven-security-model/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
