<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>The Security Catalyst&#187; trustmark</title>
	<atom:link href="http://www.securitycatalyst.com/tag/trustmark/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitycatalyst.com</link>
	<description>harnessing the human side of security</description>
	<lastBuildDate>Wed, 25 Jan 2012 15:57:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.4" -->
	<itunes:summary>harnessing the human side of security</itunes:summary>
	<itunes:author>The Security Catalyst</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.securitycatalyst.com/wp-content/plugins/powerpress/itunes_default.jpg" />
	<itunes:subtitle>harnessing the human side of security</itunes:subtitle>
	<image>
		<title>The Security Catalyst&#187; trustmark</title>
		<url>http://www.securitycatalyst.com/wp-content/plugins/powerpress/rss_default.jpg</url>
		<link>http://www.securitycatalyst.com</link>
	</image>
		<item>
		<title>I prepare to depart Michigan with gifts for you</title>
		<link>http://www.securitycatalyst.com/2008/11/i-prepare-to-depart-michigan-with-gifts-for-you/</link>
		<comments>http://www.securitycatalyst.com/2008/11/i-prepare-to-depart-michigan-with-gifts-for-you/#comments</comments>
		<pubDate>Thu, 13 Nov 2008 00:39:48 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[CSI]]></category>
		<category><![CDATA[into the breach]]></category>
		<category><![CDATA[Maryland]]></category>
		<category><![CDATA[Michigan]]></category>
		<category><![CDATA[ohio]]></category>
		<category><![CDATA[trustmark]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=587</guid>
		<description><![CDATA[After a great week in Michigan, tonight we pack up and prepare to head to Ohio tomorrow. Friday promises to be busy and exciting â€“ and then on Saturday, we head to Maryland (Metro DC) for a week. Which brings me to the gifts I promised: Join a conversation, get a free copy (hardcover) of [...]]]></description>
			<content:encoded><![CDATA[<p><!--StartFragment--></p>
<p class="MsoNormal">After a great week in Michigan, tonight we pack up and prepare to head to Ohio tomorrow. Friday promises to be busy and exciting â€“ and then on Saturday, we head to Maryland (Metro DC) for a week. Which brings me to the gifts I promised:</p>
<h2>Join a conversation, get a free copy (hardcover) of <em>Into the Breach</em></h2>
<p class="MsoNormal">First â€“ while in Maryland, I am attending CSI next week in support of the CompTIA Security Trustmark. It turns out that a chapter of <em>Into the Breach</em> examines how to evaluate, build and improve â€œthird party trustâ€ â€“ what we need for success with our service providers and other vendors.</p>
<p class="MsoNormal">CompTIA Security Trustmark is hosting a handful of â€œcatalyst conversationsâ€ to discuss my findings and examine how the industry handles this today, and what we can do in the future. This is not a sales pitch; rather, this is an opportunity to come together and work toward a common solution.</p>
<p class="MsoNormal">For those invited to attend, CompTIA will present you will your own copy of <em>Into the Breach</em> â€“ which I will promptly autograph for you. Drop me an email â€“ securitycatalyst (gmail) if you want to join us.</p>
<p class="MsoNormal">This leads me to my second offeringâ€¦</p>
<h2>Not going to CSI? Do you want to?</h2>
<p class="MsoNormal">CSI was generous enough to share with me two ways for you to get involved:</p>
<p class="MsoNormal">* I can offer (I think) a free conference pass with full access â€“ based on response. Hereâ€™s the deal â€“ share with me the biggest challenge you face in changing how people protect information. The best answer gets a signed copy of the book and a pass to the show (Iâ€™ll hand you the book at the show).</p>
<p class="MsoNormal">* If you are already planning to attend, you can get 25% off your registration with code: <strong><span>BLOG25</span></strong></p>
<p class="MsoNormal">I will do my best to both tweet (twitter id: catalyst) from CSI and report on interesting talks/findings from the floor. I will also be taking a limited number of vendor meetings to learn more about the products and solutions that make it easier for people to protect information. Shoot me a note if there is a product you want me to check out and report back on.Â </p>
<p><!--EndFragment--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/11/i-prepare-to-depart-michigan-with-gifts-for-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Three Ways to Avoid â€œWheel Reinventionâ€ &#8211; and Build a Better, Trusted Solution</title>
		<link>http://www.securitycatalyst.com/2008/07/three-ways-to-avoid-%e2%80%9cwheel-reinvention%e2%80%9d-and-build-a-better-trusted-solution/</link>
		<comments>http://www.securitycatalyst.com/2008/07/three-ways-to-avoid-%e2%80%9cwheel-reinvention%e2%80%9d-and-build-a-better-trusted-solution/#comments</comments>
		<pubDate>Mon, 07 Jul 2008 13:15:05 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[teamwork]]></category>
		<category><![CDATA[trustmark]]></category>
		<category><![CDATA[truthiness]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=469</guid>
		<description><![CDATA[The last article in this series explored the top three reasons why group have a tendency to reinvent the wheel (read it here, or the entire series started here). And now, some solutions: Beyond the frustration caused by an approach that simply recreates the wheel, the result is often a solution that is not trusted [...]]]></description>
			<content:encoded><![CDATA[<p><!--StartFragment--></p>
<p class="MsoNormal"><em>The last article in this series explored the top three reasons why group have a tendency to reinvent the wheel (<a href="http://www.securitycatalyst.com/2008/07/why-teams-reinvent-the-wheel/" target="_blank">read it here</a></em><em>, or the entire series started here</em><em>). And now, some solutions:</em></p>
<p class="MsoNormal"><em><span style="font-style: normal;">Beyond the frustration caused by an approach that simply recreates the wheel, the result is often a solution that is not trusted and therefore readily cast aside in favor of the next offering. To put a stop to this cycle requires taking a different approach. Success has to be based to fundamentals and sound principles.</span></em></p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal"><strong>How to do it? </strong></p>
<p class="MsoNormal">A key part of the solution is to enter into deliberate discourse (note: this is a central theme of <em>I</em><em><a href="http://www.securitycatalyst.com/into-the-breach/" target="_blank">nto The Breach</a></em> and a topic I am passionate about). More voices with an opportunity to review, consider and contribute have the potential to lead to a better product. For this to lead to a better product requires a strong leadership team with enough expertise to guide and the skills to help facilitate and negotiate the final result.</p>
<p class="MsoNormal">Instead of starting with a blank slate, it is a good practice to build on the success of others. When it comes to strategies that protect information, we have plenty of choices â€“ frameworks like ISO 2700x, PCI, FISMA, etc. However, limiting the solution to a narrow set of industry standards may not yield the best results. Sometimes, real progress comes at the intersection of industries (to gain more insight on this approach, consider reading: The Medici Effect) â€“ leveraging how the medical, engineering or other industries have dealt with and handled challenges may bring valuable insight to the effort at hand.</p>
<p class="MsoNormal">The advantage to building on the validated and transparent work of others is the ability to avoid conjecture and â€œgut feeling.â€ <strong>This is the challenge: there are few shortcuts to spending the time to outline, think, plan, distill, check, cross-reference.</strong> This is an area where transparency really provides a benefit.</p>
<p class="MsoNormal">When the group of professionals is assembled, here are three steps to harnessing the collective power, building on the wheel (instead of building a new wheel) and reaching a point of success:</p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal"><strong>1. Capture and distill frameworks (or solutions)</strong></p>
<p class="MsoNormal">Start by presenting a model to work from, based on an existing solution. In general, individuals and groups struggle to create but excel at editing and revising. With this in mind, selecting an initial framework or set of solutions to present to the group acts as a strawman [<a href="http://en.wikipedia.org/wiki/Strawman"><span>http://en.wikipedia.org/wiki/Strawman</span></a>]. This has the added benefit of allowing people to beat on the framework(s) instead of each other.</p>
<p class="MsoNormal">The frameworks or solutions can either be selected in advance or decided by the team. Allowing the team to decide may provide for more diverse results but requires more time and a stronger facilitator (who possesses deep subject matter expertise). Stronger frameworks and solutions are those that have already been publicly validated and are more transparent. This suggests the â€œheavy liftingâ€ has already been done and the team can focus on refining and tailoring what already exists from multiple sources into the solution required.</p>
<p class="MsoNormal">More important that just compiling a list of viable frameworks and solutions is how they are captured and processed. As the elements are suggested, reviewed and documented, look not only for the similarities, but also the distinctions between them. Working to understand why specific elements were either included or excluded may also reveal key insights that aid the development of a stronger solution. Note the intended audience and users of the solution and how it is received. It may be useful to note the level of maturity, too (since that provides some insights).</p>
<p class="MsoNormal">This process generates a lot of discussion â€“ this is good, and leads to the second point.</p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal"><strong>2. Capture and distill the running dialogue</strong></p>
<p class="MsoNormal">More important, perhaps, than the solutions selected in the last step is the running dialogue that occurs as part of the process. Yet few organizations take the time or make the effort to capture that solid gold value.</p>
<p class="MsoNormal">Ultimately, the discussion â€“ the true process of negotiation and coming to a common understanding â€“ is precisely what allows a group to build the final product. While the discussion is natural, here are three important questions to ask, answer and record during this process:</p>
<p class="MsoNormal">a. What works &#8212; and why?</p>
<p class="MsoNormal">b. What does not work &#8212; and why?</p>
<p class="MsoNormal">c. How is this applied &#8212; and why?</p>
<p class="MsoNormal">Look for specifics. This is an area where people tend to rely on &#8220;truthiness&#8221; â€“ which, to a certain extent, may be okay. In the overall discussion, however, guide people back to more concrete grounding by asking more questions to ensure everyone shares a common understanding (which is not necessarily the same as a common opinion!). The next segment will explore the benefit of capturing this conversation and making it available in the future.</p>
<p class="MsoNormal">As the conversation continues, there is one more step to increase the overall value.</p>
<p class="MsoNormal"><strong>3. Capture and distill references</strong></p>
<p class="MsoNormal">The value of having experts together in a room is their collective knowledge â€“ informed by experience, training and a vast array of resources. Therefore, it is incredibly valuable to regularly ask this group to cite the references they find of value.</p>
<p class="MsoNormal">As the discussion rages on (if you have been part of a working group, rage is definitely the right word), asking people to take the time to cite the references that support their assertions returns focus to the fundamentals.</p>
<p class="MsoNormal">Not only does this improve the overall framework, but this also improves how it is applied and verified (as we will explore in the next sections).</p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal"><strong>Bottom Line</strong></p>
<p class="MsoNormal">Bring together a small, tight team that works well together. Welcome as many voices into the process as reasonable. Take the time to distill and overlay what already works.</p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal"><strong>How this Applies to Trustmark</strong></p>
<p class="MsoNormal">When <a href="http://www.comptia.org/businesscred/securitytrustmark.aspx" target="_blank">Trustmark</a> gets this right, it will essentially be an overlay on the entire industry â€“ explaining where, how and why the different control families and control objectives can be met. This is important, since it allows for additional regulations or efforts to be acceptable without prescribing a set way of working. But whether working on Trustmark or a new process to protect information, following these steps leads to a stronger &#8211; and more trustworthy &#8211; result.</p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal"><em>Up Next: the second challenge facing Trustmark and similar efforts is in how the solution is applied. We examine this challenge with potential solutions before moving on to the final challenge of how the solution is measured and verified. </em></p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal">If you enjoyed reading this article, please take a moment to either subscribe to the RSS feed (<a href="http://www.securitycatalyst.com/feed/">www.securitycatalyst.com/feed/</a>) or sign up for <a href="http://www.feedblitz.com/f/f.fbz?AddNewUserDirect" target="_blank">free updates by email</a>. Use the buttons below to print this article or share this with friends and colleagues that will benefit from this.</p>
<p><!--EndFragment--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/07/three-ways-to-avoid-%e2%80%9cwheel-reinvention%e2%80%9d-and-build-a-better-trusted-solution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Can you be trusted? Can you prove it?</title>
		<link>http://www.securitycatalyst.com/2008/06/can-you-be-trusted-can-you-prove-it/</link>
		<comments>http://www.securitycatalyst.com/2008/06/can-you-be-trusted-can-you-prove-it/#comments</comments>
		<pubDate>Thu, 19 Jun 2008 21:39:25 +0000</pubDate>
		<dc:creator>Michael Santarcangelo</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[assurance]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[certification]]></category>
		<category><![CDATA[comptia]]></category>
		<category><![CDATA[trustmark]]></category>
		<category><![CDATA[vendors]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=455</guid>
		<description><![CDATA[â€œWhat questions do I need to ask to make sure my vendor is protecting my information?â€ I got asked that question last week from a new client working through the Protecting Information Program (PIP). Following the PIP process, he realized vendors were supporting key systems &#8212; raising questions he could not answer. He needed more [...]]]></description>
			<content:encoded><![CDATA[<p><!--StartFragment--></p>
<p class="MsoNormal"><em>â€œWhat questions do I need to ask to make sure my vendor is protecting my information?â€</em></p>
<p class="MsoNormal">I got asked that question last week from a new client working through the Protecting Information Program (PIP). Following the PIP process, he realized vendors were supporting key systems &#8212; raising questions he could not answer. He needed more assurance that he wasnâ€™t taking on unnecessary risk â€“ and was looking for guidance. It is a good question. The challenge, however, is to provide an equally good answer.</p>
<p class="MsoNormal">Traditionally, the answer to that question is focused on the vendor employees in terms of how many hold a security certification (my status as a CISSP Instructor has been valuable in the past). This is better than nothing, but all-too-common is the situation where the cobblerâ€™s children wear no shoes (or the modern adaptation where the contractorâ€™s spouse never has anything fixed around the house).<span>Â  </span></p>
<p class="MsoNormal">Instead of relying on individuals holding certifications, some turn to checklists. Checklists are both good and dangerous (<em>I feel another post coming on about my experiences with developing checklists</em>). Checklists that are simple easy-to-understand and as easy to apply/answer are more effective. But what happens if the business asking the questions lacks the experience to gauge the answers?</p>
<p class="MsoNormal">We need a better solution.</p>
<p class="MsoNormal">I recently got an insiderâ€™s look at a better solution: The Security Trustmark, a new organizational-level certification being developed by CompTIA. Some limited information is available here: http://www.comptia.org/sections/trustmark/<span></span></p>
<p class="MsoNormal">From their website:</p>
<blockquote>
<p class="MsoNormal"><em>The CompTIA Security Trustmark is a vendor neutral accreditation around security business capabilities and processes that have been agreed upon by the IT industry to promote generally accepted security practices that will invoke the trust of end-users.</em></p>
<p class="MsoNormal"><em>The objective of the CompTIA Security Trustmark accreditation is to develop a baseline standard of security practices around service and support business competencies for Solution Providers and Managed Services Providers (MSPs).</em></p>
</blockquote>
<p class="MsoNormal">After participating in the workshop and spending a few weeks pondering this approach, I want to briefly introduce what I consider to be the benefits of this offering, share what I liked and explain where I see the challenges (tomorrow).</p>
<p class="MsoNormal"><strong>And then I want to learn â€“ join me in the conversation about this whether by email (securitycatalyst &#8211; gmail), by twitter (<a href="http://twitter.com/catalyst">http://twitter.com/catalyst</a>), in the Security Catalyst Community Discussion Forums or by telephone. I want to learn about other models, efforts, and attempts. I want to understand if there are additional challenges for us to consider. I want to understand how this effort is (or becomes) useful to more people.</strong></p>
<p class="MsoNormal"><span>Â </span></p>
<p class="MsoNormal"><strong>The Starting Point</strong></p>
<p class="MsoNormal">Initially, this approach is geared toward small and mid-size vendors and VARS: companies that work within â€œthe channel.â€ This approach:</p>
<p class="MsoNormal">
<ul>
<li>sets a standard for smaller companies to achieve, allowing them to demonstrate to their channel partners they pose less risk to work with</li>
<li>allows vendors higher confidence across their entire channel</li>
<li>creates distinction for VARs and Channel Vendors alike that results in competitive advantage</li>
</ul>
<p class="MsoNormal">With the growing attention on breaches, privacy and compliance â€“ rather than working to explain all of your measures, think of the power of explaining that you have attained the Trustmark â€“ publicly verifiable and audited.</p>
<p class="MsoNormal">Â </p>
<p class="MsoNormal"><strong>The Big Picture (as I see it today)</strong></p>
<p class="MsoNormal">My passion for this, of course, is bigger. In the last few years, a growing challenge for those I work with is defining and explaining the minimum set of acceptable controls to protect information. Equally challenging for larger organizations is designing and employing third-party (vendor) review processes.</p>
<p class="MsoNormal">This results in a lot of re-creating the wheel. And it increases the cost of business for everyone involved. I have no argument with the need for due-diligence on vendors â€“ but lament every year the lack of a â€œ<a href="https://www.commonapp.org/CommonApp/default.aspx">common application</a>â€ approach that seems to work for university applicants.</p>
<p class="MsoNormal">Imagine being able to pre-validate vendors by virtue of having a Trustmark?</p>
<p class="MsoNormal">Provided the core elements of Trustmark are publicly available (transparent) and regularly maintained to represent the distilled good practices for managing people, information and risk, we collectively take a step forward.</p>
<p class="MsoNormal">
<ul>
<li>Businesses know what is expected of them â€“ and will have the opportunity for the guidance and support to take the appropriate actions for their business. They can then earn the Trustmark designation and use that to differentiate themselves for contracts.</li>
<li>Companies seeking to review vendors can greatly cut down on costs and timelines for vendors with a valid and audited Trustmark. It may not replace the current programs â€“ but it certainly establishes a stronger base to start from and increases assurance while decreasing risk.</li>
</ul>
<p class="MsoNormal">Done right, Trustmark is not another reinvention of the wheel. Rather, it provides a clear direction for businesses that distills the best of industry guidance. I envision this operating almost as an â€œoverlayâ€ â€“ where several valid methods to meet the controls are deemed acceptable. This reduces complexity and more naturally meets the needs of those who seek the certification. For example, companies already compliant with HIPAA and PCI should be able to easily earn the Trustmark. At the same time, a company that need not meet any of those requirements is equally able to address and satisfy the controls necessary to get certified.</p>
<p class="MsoNormal">Over time, I envision this meeting the needs of car dealers, medical offices, bank branches â€“ the very places we visit on a regular basis. I see this as the smartest way to distill the best of our industry and present guidance in simple terms to businesses that want to protect information, but focus on other areas (for example, making money).</p>
<p class="MsoNormal"><strong>Answering the Question</strong></p>
<p class="MsoNormal">No question, I am excited about the potential Trustmark holds (both short-term and long-term). I see this as a real answer to valid and necessary questions about how vendors protect information &#8212; in a way that builds trust and allows everyone to focus on whatever they do best while meeting fiduciary duties.</p>
<p class="MsoNormal">As I was working on this article, I took an unexpected meeting with a company facing the same challenge: how to assess their vendors from an information-protection perspective. The marketplace is ready for standard guidance and a program that builds confidence; we have an opportunity to make a difference!</p>
<p class="MsoNormal">Tomorrow, Iâ€™ll continue this article by explaining the key challenges I see facing Trustmark, as well as some insights on how to avoid it. In the meantime â€“ how do you answer the question when asked about assessing vendors? How do we avoid creating the wheel? How would this benefit your business?</p>
<p><!--EndFragment--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2008/06/can-you-be-trusted-can-you-prove-it/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

