<?xml version="1.0" encoding="utf-8"?>
			
<rss version="2.0" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:cc="http://web.resource.org/cc/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">

<channel>
	<title>Clerkendweller : Web Security, Usability and Design</title>
	<link>http://www.clerkendweller.com</link>
	<description>A blog about security issues for web site designers, developers and owners.</description>
	<atom:link href="http://www.clerkendweller.com/atom.php" type="application/rss+xml" />
	<language>en-gb</language>
	<pubDate>Wed, 19 Jun 2013 20:14:52 +0100</pubDate>
	<lastBuildDate>Tue, 18 Jun 2013 18:17:00 +0100</lastBuildDate>
	<item>
		<title>Website Security Statistics Report 2013</title>
		<link>http://www.clerkendweller.com/2013/6/18/Website-Security-Statistics-Report-2013</link>
		<description>
		
		&lt;p&gt;WhiteHat Security in the United States has &lt;a href=&quot;https://www.whitehatsec.com/news/13pressarchives/PR_050213_statsreport.html&quot;&gt;published&lt;/a&gt; another edition of its Website Security Statistics Report. This would seem to be the 13th edition, although the numbering label appears to have been dropped.&lt;/p&gt;

&lt;img style=&quot;border:1px solid #999;padding:0;margin-top:1em;margin-bottom:1.2em;&quot; src=&quot;http://www.clerkendweller.com/posts/2013/appsec-scorecard-1.jpg&quot; width=&quot;500&quot; height=&quot;350&quot; alt=&quot;Partial image of one of the industry scorecards from the WhiteHat Website Security Statistics Report 2013&quot; /&gt;

&lt;p&gt;Like previous editions, &lt;a href=&quot;https://www.whitehatsec.com/resource/stats.html&quot;&gt;the 2013 report&lt;/a&gt; contains a wealth of valuable information about the prevalence of web site security vulnerabilities, the time required to resolve them, the drivers for application security, accountabilities for system/data breaches, and what type of security activities are being undertaken in the software development processes to prevent vulnerabilities occurring in production releases.&lt;/p&gt;

&lt;p&gt;Information leakage and cross-site scripting continue to be the most prevalent issues found. SQL injection is still notable, although its prevalence has reduced slightly over the last eight years, but it is certainly not yet extinct. The most common drivers for security are reported to be compliance and risk reduction.&lt;/p&gt;

&lt;p&gt;But I am most excited about the industry-sector scorecards included for banking, financial services, healthcare, retail and technology industry. These summarise the report&apos;s data for each sector in an easily comprehensible manner. They are ideal templates for an organisation&apos;s own high-level web site security metrics dashboards.&lt;/p&gt;

&lt;p&gt;As &lt;a href=&quot;https://www.clerkendweller.com/2012/7/17/Website-Vulnerability-Statistics-Summer-2012&quot;&gt;mentioned before&lt;/a&gt;, the definition of &quot;serious vulnerabilities&quot; in previous versions of this report included only those with a High, Critical or Urgent severity as defined by PCI DSS naming conventions, exploitation of which &quot;could lead to server breach, user account take-over, data loss or compliance failure&quot;. The current edition seems to have changed this to &quot;those in which an attacker could take control over all, or some part, of the website, compromise user accounts on the system, access sensitive data, violate compliance requirements, and possibly make headline news&quot;. So somewhat wider, but it would be good to know more about this definition.&lt;/p&gt;

&lt;p&gt;Registration is required to download the report at the link provided above.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/6/18/Website-Security-Statistics-Report-2013&apos; style=&apos;display:none;&apos;&gt;Website Security Statistics Report 2013&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>metrics</category>
		<category>SQL</category>
		<category>maturity</category>
		<category>vulnerabilities</category>
		<category>leakage</category>
		<category>technical</category>
		<category>SDLC</category>
		<category>information assurance</category>
		<category>testing</category>
		<category>XSS</category>
		<pubDate>Tue, 18 Jun 2013 18:17:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/6/18/Website-Security-Statistics-Report-2013</guid>
		
	</item>

	<item>
		<title>Enterprise Application Usage</title>
		<link>http://www.clerkendweller.com/2013/6/15/Enterprise-Application-Usage</link>
		<description>
		
		&lt;p&gt;Have you ever wondered what applications are typically being used in enterprise-scale organisations and what the risks are? A report by Palo Alto Networks has analysed over 3,000 worldwide traffic assessments to produce an aggregated summary report.&lt;/p&gt;

&lt;img style=&quot;border:1px solid #999;padding:0;margin-top:1em;margin-bottom:1.2em;&quot; src=&quot;http://www.clerkendweller.com/posts/2013/applications-threats-1.jpg&quot; width=&quot;500&quot; height=&quot;350&quot; alt=&quot;Partial screen capture showing the interactive tool published to allow the data to be examined dynamically&quot; /&gt;

&lt;p&gt;This is the first of three posts relating to publications that came out some time ago &amp;mdash; I am just catching up, but hopefully they are worth mentioning. This first post relates to the oldest, a &lt;a href=&quot;http://www.paloaltonetworks.com/news/press/2013/application-usage-and-threat-report-0213.html&quot;&gt;report published in February&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.paloaltonetworks.com/literature/whitepapers/aur-report.html&quot;&gt;The Application Usage and Threat Report, 10th Edition&lt;/a&gt; provides regional data on the use of personal, business and custom/other applications on enterprise networks. The last category relates to 8-10% traffic that does not match any known application such as a custom internal application or a commercial application not yet identified in the assessment, and could include malware. The report provides data on:&lt;/p&gt;

&lt;ul&gt;
    &lt;li&gt;Usage of applications by category (e.g. social networking, file sharing, photo, video)&lt;/li&gt;
    &lt;li&gt;Application functionality overlap&lt;/li&gt;
    &lt;li&gt;Bandwidth usage by category&lt;/li&gt;
    &lt;li&gt;Malware and exploit prevalence&lt;/li&gt;
    &lt;li&gt;Use of transport layer security.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The conclusions include that social networking, file sharing and video applications are not the most common threat vectors; attackers are masking their activities through custom or encrypted applications. The report&apos;s data can be analysed dynamically using a well-designed &lt;a href=&quot;http://researchcenter.paloaltonetworks.com/app-usage-risk-report-visualization/#&quot;&gt;online tool&lt;/a&gt; where the data point information is viewable for each chart element.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/6/15/Enterprise-Application-Usage&apos; style=&apos;display:none;&apos;&gt;Enterprise Application Usage&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>detective</category>
		<category>policies</category>
		<category>threats</category>
		<category>operation</category>
		<category>technical</category>
		<category>risks</category>
		<pubDate>Sat, 15 Jun 2013 10:30:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/6/15/Enterprise-Application-Usage</guid>
		
	</item>

	<item>
		<title>Wish List for Security of Outsourced Payment Card Forms/Pages</title>
		<link>http://www.clerkendweller.com/2013/6/11/Wish-List-for-Security-of-Outsourced-Payment-Card-Forms-Pages</link>
		<description>
		
		&lt;p&gt;The &lt;a href=&quot;http://www.clerkendweller.com/2013/2/6/PCI-DSS-ECommerce-Guidelines&quot;&gt;PCI DSS E-commerce Guidelines v2&lt;/a&gt; were a welcome update to the previous version of the document.&lt;/p&gt;

&lt;img style=&quot;border:1px solid #999;padding:0;margin-top:1em;margin-bottom:1.2em;&quot; src=&quot;http://www.clerkendweller.com/posts/2013/grid-box-1.jpg&quot; width=&quot;500&quot; height=&quot;213&quot; alt=&quot;Photograph taken during Muse&apos;s performance at Arsenal&apos;s Emirates Stadium in June 2013 showing the projected backdrop&quot; /&gt;

&lt;p&gt;One of the new aspects included in the revised guidance was a discussion of the most common e-commerce implementation models (section 3.4) and what responsibilities the merchant and other parties have (section 3.5) under &lt;a href=&quot;https://www.pcisecuritystandards.org/security_standards/documents.php?document=pci_dss_v2-0#pci_dss_v2-0&quot;&gt;PCI DSS&lt;/a&gt;. The models discussed are:&lt;/p&gt;

&lt;ul&gt;
   &lt;li&gt;Merchant-managed e-commerce implementations
	&lt;ul style=&quot;margin: 0.3em 0 1em 0;&quot;&gt;
		&lt;li&gt;Proprietary/custom (bespoke) developed shopping cart/payment application&lt;/li&gt;
		&lt;li&gt;Commercial shopping cart/payment application (typically PA-DSS
validated)&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
   	&lt;li&gt;Shared-management e-commerce implementations
	&lt;ul style=&quot;margin: 0.3em 0 1em 0;&quot;&gt;
		&lt;li&gt;Third-party embedded application programming interfaces (APIs) with direct post&lt;/li&gt;
		&lt;li&gt;An inline frame (or &quot;iFrame&quot;) that allows a payment form hosted by a third party to be visually embedded within the merchant&apos;s page(s), sometimes also including other intermediaries&lt;/li&gt;
		&lt;li&gt;Customer redirection to a third-party hosted page for payment entry&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
	&lt;li&gt;Wholly outsourced e-commerce implementations.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;While some merchants believe they are &quot;wholly outsourced&quot; already, the definitions should be read. The guidance reminds merchants they still have primary responsibility for particular PCI DSS requirements. In the case of inline frame and hosted payment page approaches, this includes for example securing the web page(s) containing the iFrame code and redirection code and/or function(s) respectively.&lt;/p&gt;

&lt;p&gt;During a recent exercise I was involved with, to identify security requirements using the &lt;a href=&quot;https://www.owasp.org/index.php/OWASP_Cornucopia&quot;&gt;OWASP Cornucopia Ecommerce Website Edition&lt;/a&gt; card game, a merchant&apos;s payment page hosted by a payment services provider was assessed. The process highlighted additional information security risks than those already mentioned in the PCI DSS information supplement. These related to aspects the merchant still has control over despite the outsourcing &amp;mdash; in the exercise it was identified the merchant could customise the template of the payment service provider&apos;s page and include self-hosted (by the merchant) content referenced by the template (logo, card brand images, style sheet, and a JavaScript file). I am not sure the existing guidance is explicit enough on this aspect, and some merchants may therefore have a false sense of security, and their own risks, regarding the protection of payment cardholder data in these &quot;semi-outsourced&quot; (i.e. shared responsibility) situations.&lt;/p&gt;

&lt;p&gt;If a website security assessment identified any third-party hosted content on authentication, account management or payment web pages &amp;mdash; even JavaScript library files and web analytics code &amp;mdash; this would normally be worthy of mention. Therefore, I think we should also take note of this merchant-controlled content appearing on payment pages/forms elsewhere, especially if the level of security assurance is different between the two (as is often the case). Merchants can outsource in an attempt to de-scope for PCI DSS and reduce the number of applicable requirements (e.g. to use &lt;a href=&quot;https://www.pcisecuritystandards.org/security_standards/documents.php?category=saqs#leadgendiv&quot;&gt;SAQ A&lt;/a&gt; for such an online-only merchant). This may not be adequate if the merchant (its employees, contractors, systems, partners, suppliers etc) still has some control over the partially/wholly outsourced (e.g. payment service provider) hosted page/form.&lt;/p&gt;

&lt;p&gt;Merchants should include security review and verification activities during template change processes. But regardless of PCI DSS compliance, what other technical security controls could be considered when selecting an outsourced online payment page or form? If I was a merchant, I would prefer to choose one that enables and enforces the following web application security wish list, in addition to the outsourcer&apos;s own existing PCI DSS compliance requirements:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Page template administration
	&lt;ul style=&quot;margin: 0.3em 0 1em 0;&quot;&gt;
		&lt;li&gt;Each user (e.g. each designated merchant employee) with the ability to upload or edit templates to have a unique identity, and no use of shared accounts&lt;/li&gt;
		&lt;li&gt;Two factor authentication for all access to the outsourcer&apos;s systems (e.g. file transfers, web administrative interfaces, web services)&lt;/li&gt;
		&lt;li&gt;User account access limited to a small set of merchant IP addresses&lt;/li&gt;
		&lt;li&gt;Encrypted connections for authentication and template upload/edit&lt;/li&gt;
		&lt;li&gt;Event alert to nominated address/system on template change&lt;/li&gt;
		&lt;li&gt;Automatic stripping of any other party hosted (i.e. non outsourcer and non merchant) content from the template with related event alerting&lt;/li&gt;
		&lt;li&gt;Accessible audit trail of changes&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
	&lt;li&gt;Payment form/page hosting
	&lt;ul style=&quot;margin: 0.3em 0 1em 0;&quot;&gt;
   		&lt;li&gt;Only available using Transport Layer Security&lt;/li&gt;
    		&lt;li&gt;No other party (i.e. non outsourcer and non merchant) content&lt;/li&gt;
		&lt;li&gt;No use or reliance on any merchant, outsourcer or other party HTTP cookies&lt;/li&gt;
		&lt;li&gt;X-Frame-Options HTTP header, with the value &quot;DENY&quot; for a page that is not framed, else with a value &quot;ALLOW-FROM ...&quot; that (supporting web browsers) only permits the particular form to be framed by the specific individual merchant&apos;s whitelist hostnames&lt;/li&gt;
		&lt;li&gt;HTTP Strict Transport Security Header&lt;/li&gt;
		&lt;li&gt;X-Content-Security-Policy/X-WebKit-CSP/Content-Security-Policy header with a strict policy that does not allow any content from other parties (or perhaps just some types of content from the merchant&apos;s selected hostnames&lt;/li&gt;
		&lt;li&gt;MIME type and character set HTTP headers correctly defined&lt;/li&gt;
                &lt;li&gt;Strong anti-caching HTTP headers&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
	&lt;li&gt;Payment form submission
	&lt;ul style=&quot;margin: 0.3em 0 1em 0;&quot;&gt;
		&lt;li&gt;HTTP method POST enforced, and no other method permitted&lt;/li&gt;
   		&lt;li&gt;Only possible using Transport Layer Security.&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This is a somewhat long list, but it would be interesting to know which commonly used payment outsourcers can provide this level of assistance to ecommerce merchants.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/6/11/Wish-List-for-Security-of-Outsourced-Payment-Card-Forms-Pages&apos; style=&apos;display:none;&apos;&gt;Wish List for Security of Outsourced Payment Card Forms/Pages&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>operation</category>
		<category>administrative</category>
		<category>preventative</category>
		<category>technical</category>
		<category>SDLC</category>
		<category>PCIDSS</category>
		<category>physical</category>
		<category>specification</category>
		<category>maturity</category>
		<category>detective</category>
		<category>information assurance</category>
		<pubDate>Tue, 11 Jun 2013 17:34:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/6/11/Wish-List-for-Security-of-Outsourced-Payment-Card-Forms-Pages</guid>
		
	</item>

	<item>
		<title>User Profiling and &quot;Significant Impact&quot;</title>
		<link>http://www.clerkendweller.com/2013/6/7/User-Profiling-and-Significant-Impact</link>
		<description>
		
		&lt;p&gt;Do you profile your customers, clients and citizens with data from your applications?&lt;/p&gt;

&lt;div class=&quot;quotation&quot;&gt;&lt;p&gt;&quot;Profiling&quot; means any form of automated processing of personal data, intended to analyse or predict the personality or certain personal aspects relating to a natural person, in particular the analysis and prediction of the person&apos;s health, economic situation, performance at work, personal preferences or interests, reliability or behaviour, location or movements.&lt;/p&gt;&lt;/div&gt;

&lt;p&gt;The European Commission&apos;s &lt;a href=&quot;http://ec.europa.eu/justice/data-protection/article-29/&quot;&gt;Article 29 Working Party&lt;/a&gt; has &lt;a href=&quot;http://ec.europa.eu/justice/data-protection/article-29/press-material/press-release/art29_press_material/20130528_pr_profiling_en.pdf&quot;&gt;published&lt;/a&gt; an opinion, in  the form of an &lt;a href=&quot;http://ec.europa.eu/justice/data-protection/article-29/documentation/other-document/files/2013/20130513_advice-paper-on-profiling_en.pdf&quot;&gt;advice leaflet&lt;/a&gt;, to provide input into the current discussions on European data protection reform.&lt;/p&gt;

&lt;p&gt;The paper supports that the scope of Article 20 covering processing of personal data for the purpose of profiling or measures based on profiling, and that there should be greater transparency and control for data subjects of profiling and subsequent measures based upon the profile generated, and thus acknowledges the this creates more responsibility and accountability for data controllers.&lt;/p&gt;

&lt;p&gt;However, the paper suggests profiling and measures should only be subject to additional control if they significantly affect the interests, rights or freedoms of the data subject.&lt;/p&gt;

&lt;p&gt;See further discussion &lt;a href=&quot;http://www.privacy-europe.com/blog/profiling-what-is-the-european-data-protection-authorities-direction/&quot;&gt;here&lt;/a&gt; and &lt;a href=&quot;http://www.out-law.com/en/articles/2013/may/profiling-rules-should-not-apply-unless-individuals-rights-are-significantly-affected-says-privacy-body/&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/6/7/User-Profiling-and-Significant-Impact&apos; style=&apos;display:none;&apos;&gt;User Profiling and &quot;Significant Impact&quot;&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>business logic</category>
		<category>privacy</category>
		<category>operation</category>
		<category>data protection</category>
		<category>technical</category>
		<category>legislation</category>
		<pubDate>Fri, 07 Jun 2013 19:03:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/6/7/User-Profiling-and-Significant-Impact</guid>
		
	</item>

	<item>
		<title>Request to Participate in the OWASP CISO Survey 2013</title>
		<link>http://www.clerkendweller.com/2013/6/5/Request-to-Participate-in-the-OWASP-CISO-Survey-2013</link>
		<description>
		
		&lt;p&gt;OWASP is conducting a survey among senior information security leaders and managers and needs your help.  The results will be published in the OWASP CISO Report 2013, which shall be released in Autumn.&lt;/p&gt;

&lt;p&gt;The project team (Tobias Gondrom, Marco Morana, Eoin Keary and Ivy Zhang) have asked if we can share  this invitation with security contacts in companies and other organisations. This would be a great help to achieve a broad outreach and derive valuable data and insights for OWASP and the industry as a whole.&lt;/p&gt;

&lt;div style=&quot;margin-left:5%;margin-right:5%;font-style:italic;&quot;&gt;

&lt;p&gt;Dear colleague,&lt;/p&gt;

&lt;p&gt;As a respected information security executive in the industry, OWASP (Open Web Application Security Project, &lt;a href=&quot;https://www.owasp.org/index.php/&quot;&gt;www.owasp.org&lt;/a&gt;) would like to hear your opinion!&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://www.surveymonkey.com/s/CISO2013Survey&quot;&gt;Link to take the CISO Survey 2013 now&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;OWASP is preparing the Global CISO report 2013 and conducting a survey among CISOs and information security managers in relation to application security with the aim of providing you with new insights about the state of application security across various industry sectors and about new security trends and aligning our efforts to better help solving the problems of the future that you face.&lt;/p&gt;

&lt;p&gt;The survey shall take only a few minutes of your precious time and by completing it you are helping shape the future of OWASP, the Internet and software security.
 At the conclusion of the survey, the aggregated results will be publicly available in the form of a report on the owasp.org website, keeping your information completely anonymous.&lt;/p&gt;

&lt;p&gt;As you may know OWASP is a volunteer open-source organization dedicated to fighting the causes of software insecurity. We are also a registered charity &amp;amp; non-profit in the USA and the EU. See more at &lt;a href=&quot;https://www.owasp.org/index.php/About_OWASP&quot;&gt;https://www.owasp.org/index.php/About_OWASP&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The survey can be found here: &lt;a href=&quot;https://www.surveymonkey.com/s/CISO2013Survey&quot;&gt;https://www.surveymonkey.com/s/CISO2013Survey&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;And to spice things up, during the first 14 days of June (until June-16 23:59 GMT), if you provide your contact details at the end of the survey, you will also be entered into a drawing for one of the following donated prizes:&lt;/p&gt;
&lt;ul&gt; 
   &lt;li&gt;1 free OWASP CISO training day pass at the &lt;a href=&quot;https://appsec.eu/&quot;&gt;AppSecEU in Hamburg&lt;/a&gt;&lt;/li&gt;
   &lt;li&gt;1 free OWASP CISO training day pass at the &lt;a href=&quot;http://appsecusa.org/2013/&quot;&gt;AppSecUS in New York&lt;/a&gt;&lt;/li&gt;
   &lt;li&gt;and 1 free CISO training day or half-day pass at one of the upcoming events in Asia.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Thank you very much in advance for your time.&lt;/p&gt;

&lt;p&gt;Best regards,&lt;/p&gt;


&lt;p&gt;OWASP CISO Survey Project team&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;If you are a CISO, please complete the survey; otherwise please forward details to relevant contacts.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/6/5/Request-to-Participate-in-the-OWASP-CISO-Survey-2013&apos; style=&apos;display:none;&apos;&gt;Request to Participate in the OWASP CISO Survey 2013&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>corrective</category>
		<category>administrative</category>
		<category>maturity</category>
		<category>technical</category>
		<category>SDLC</category>
		<category>information assurance</category>
		<category>preventative</category>
		<category>detective</category>
		<category>physical</category>
		<pubDate>Wed, 05 Jun 2013 08:27:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/6/5/Request-to-Participate-in-the-OWASP-CISO-Survey-2013</guid>
		
	</item>

	<item>
		<title>Presentation from OWASP London, 3rd June 2013</title>
		<link>http://www.clerkendweller.com/2013/6/3/Presentation-from-OWASP-London-3rd-June-2013</link>
		<description>
		
		&lt;p&gt;&lt;a href=&quot;https://www.clerkendweller.com/2013/5/21/OWASP-EU-Tour-2013-in-London-June-3rd&quot;&gt;Today&apos;s OWASP London&lt;/a&gt; event was very successful.&lt;/p&gt;

&lt;img style=&quot;border:1px solid #999;padding:0;margin-top:1em;margin-bottom:1.2em;&quot; src=&quot;http://www.clerkendweller.com/posts/2013/cornucopia-ecommerce-2.jpg&quot; width=&quot;500&quot; height=&quot;305&quot; alt=&quot;Colin Watson demonstrating the use of OWASP Cornucopia Ecommerce Website Edition to assess the application security requirements for an externally hosted payment page&quot; /&gt;

&lt;p&gt;The majority of attendees had never been to an OWASP event previously, and three-quarters were developers. My own presentation has been uploaded to:&lt;/p&gt;

&lt;ul&gt;
   &lt;li&gt;&lt;a href=&quot;https://www.owasp.org/index.php/File:Owasplondon-colinwatson-cornucopia.odp&quot;&gt;Open Office presentation&lt;/a&gt; including the animated game&lt;/li&gt;
   &lt;li&gt;&lt;a href=&quot;https://www.owasp.org/index.php/File:Owasplondon-colinwatson-cornucopia.pdf&quot;&gt;Static PDF&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I have also uploaded an updated version of OWASP Cornucopia - Ecommerce Website Edition (&lt;a href=&quot;https://www.owasp.org/index.php/File:OWASP-Cornucopia-Ecommerce_Website.docx&quot;&gt;v1.01&lt;/a&gt;) with some minor changes and additions:&lt;/p&gt;

&lt;ul&gt;
   &lt;li&gt;Framework-specific card deck discussion added&lt;/li&gt;
   &lt;li&gt;Additional FAQs created&lt;/li&gt;
   &lt;li&gt;Descriptive text updated&lt;/li&gt;
   &lt;li&gt;New cover image, and previous cover image moved to back&lt;/li&gt;
   &lt;li&gt;Cut lines added&lt;/li&gt;
   &lt;li&gt;Alternative rules and deck subset descriptions added&lt;/li&gt;
   &lt;li&gt;Project website and mailing list added&lt;/li&gt;
   &lt;li&gt;Cornucopia King cross-reference to AppSensor updated.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Play to win!&lt;/p&gt;

&lt;p&gt;&lt;i&gt;Update 10th June 2013:&lt;/i&gt; The video recordings from are now available. The videos can be accessed via the links on the &lt;a href=&quot;https://www.owasp.org/index.php/EUTour2013#London&quot;&gt;EU Tour 2013 London page&lt;/a&gt;. The recording of my own &lt;a href=&quot;https://www.owasp.org/index.php/OWASP_Cornucopia&quot;&gt;OWASP Cornucopia Ecommerce Website Edition&lt;/a&gt; presentation is &lt;a href=&quot;http://youtu.be/Q_LE-8xNXVk&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/6/3/Presentation-from-OWASP-London-3rd-June-2013&apos; style=&apos;display:none;&apos;&gt;Presentation from OWASP London, 3rd June 2013&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>vulnerabilities</category>
		<category>preventative</category>
		<category>technical</category>
		<category>threats</category>
		<category>development</category>
		<category>testing</category>
		<category>requirements</category>
		<category>specification</category>
		<category>design</category>
		<category>risks</category>
		<pubDate>Mon, 03 Jun 2013 18:33:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/6/3/Presentation-from-OWASP-London-3rd-June-2013</guid>
		
	</item>

	<item>
		<title>Consultation on Incident Reporting Notification Thresholds</title>
		<link>http://www.clerkendweller.com/2013/5/28/Consultation-on-Incident-Reporting-Notification-Thresholds</link>
		<description>
		
		&lt;p&gt;The UK&apos;s &lt;a href=&quot;https://www.gov.uk/government/organisations/department-for-business-innovation-skills&quot;&gt;Department for Business, Innovation and Skills&lt;/a&gt; (BIS) is consulting on one aspect of the &lt;a href=&quot;/2013/2/8/EU-Cybersecurity-Strategy-and-Proposed-Directive&quot;&gt;proposed EU directive on network and information security&lt;/a&gt; (NIS), announced in February.&lt;/p&gt;

&lt;img style=&quot;border:1px solid #999;padding:0;margin-top:1em;margin-bottom:1.2em;&quot; src=&quot;http://www.clerkendweller.com/posts/2013/incident-reporting-1.jpg&quot; width=&quot;500&quot; height=&quot;300&quot; alt=&quot;A table from the consultation document &apos;EU Directive on Network and Information Security SWD(2013) 31 &amp;amp; SWD(2013) 32 &apos; showing an indication of possible reporting trigger thresholds&quot; /&gt;

&lt;p&gt;This mandates certain sectors to compulsory reporting of security breaches that have a significant impact on the provision of core services to a national competent authority that would enforce the directive. These sectors include public administration, the finance, energy, transport and health sectors, as well as to &quot;enablers of internet society 
services&quot; which includes app stores, cloud service providers, social networks and e-payment providers. These requirements are unlikely to apply to individual ecommerce web sites, unless they enable the provision of other information society services.&lt;/p&gt;

&lt;p&gt;However the BIS&apos; &lt;a href=&quot;https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/200708/bis-13-880-eu-directive-on-network-and-information-security-call.pdf&quot;&gt;call for reviews and evidence&lt;/a&gt;, with the title &quot;EU Directive on Network and Information Security SWD(2013) 31 &amp;amp; SWD(2013) 32&quot;, seeks input on just what a significant impact might be, and thus when notification would be necessary. Some example reporting thresholds are presented that incorporate the number of customers, citizens, clients, etc affected and the duration of the disruption or lack of availability. I note there is no mention of breaches of integrity or confidentiality, nor misuse of these systems whilst maintaining availability.&lt;/p&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.gov.uk/government/consultations/eu-directive-on-network-and-information-security-call-for-evidence&quot;&gt;consultation&lt;/a&gt; closes on 21st June. A response template is included within the document, and views can be returned using a web form, by email or by post.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/5/28/Consultation-on-Incident-Reporting-Notification-Thresholds&apos; style=&apos;display:none;&apos;&gt;Consultation on Incident Reporting Notification Thresholds&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>detective</category>
		<category>incidents</category>
		<category>operation</category>
		<pubDate>Tue, 28 May 2013 14:37:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/5/28/Consultation-on-Incident-Reporting-Notification-Thresholds</guid>
		
	</item>

	<item>
		<title>OWASP EU Tour 2013 in London on June 3rd</title>
		<link>http://www.clerkendweller.com/2013/5/21/OWASP-EU-Tour-2013-in-London-June-3rd</link>
		<description>
		
		&lt;p&gt;As part of the &lt;a href=&quot;https://www.owasp.org/index.php/EUTour2013&quot;&gt;OWASP EU Tour 2013&lt;/a&gt;, there will be a special event in London next month, along the lines of the recent ones in &lt;a href=&quot;/2013/5/4/OWASP-European-Tour-KickOff-in-Cambridge&quot;&gt;Cambridge&lt;/a&gt; and Leicester.&lt;/p&gt;

&lt;img style=&quot;border:1px solid #999;padding:0;margin-top:1em;margin-bottom:1.2em;&quot; src=&quot;http://www.clerkendweller.com/posts/2013/london-shard-3.jpg&quot; width=&quot;500&quot; height=&quot;348&quot; alt=&quot;Photograph of London at dusk with the river Thames in the foreground and St Paul&apos;s cathedral lit up&quot; /&gt;

&lt;p&gt;The one day conference is being held in central London on Monday 3rd of June 2013 at the &lt;a href=&quot;http://www.lion-court.com/&quot;&gt;Lion Court Conference Centre&lt;/a&gt;, 25 Procter Street, Holborn, London, WC1V 6NY. The nearest tube station is Holborn. It is free to attend and is open to all, but &lt;a href=&quot;http://owasp-london.eventbrite.co.uk/&quot;&gt;registration&lt;/a&gt; is required as numbers are limited to 100.&lt;/p&gt;

&lt;p&gt;The agenda is still being finalised, but &lt;a href=&quot;https://www.owasp.org/index.php/Ireland&quot;&gt;OWASP Ireland&lt;/a&gt; chapter leader &lt;a href=&quot;http://ie.linkedin.com/in/fcerullo&quot;&gt;Fabio Cerullo&lt;/a&gt; is presenting PCIDSS for developers,  &lt;a href=&quot;https://www.owasp.org/index.php/Cambridge&quot;&gt;OWASP Cambridge&lt;/a&gt; chapter leader &lt;a href=&quot;http://uk.linkedin.com/in/vdbaan&quot;&gt;Steven van der Baan&lt;/a&gt; will be talking about simple steps for secure coding, and &lt;a href=&quot;https://www.owasp.org/index.php/London&quot;&gt;OWASP London&lt;/a&gt; chapter leader &lt;a href=&quot;http://uk.linkedin.com/in/connectjunkie&quot;&gt;Justin Clarke&lt;/a&gt; will be speaking about securing development with PMD,  the popular Java code scanning tool. I will be introducing and demonstrating &lt;a href=&quot;https://www.clerkendweller.com/2013/5/18/Cornucopia-Ecommerce-Website-Edition-v100&quot;&gt;OWASP Cornucopia&lt;/a&gt;. A very developer-orientated agenda so far.&lt;/p&gt;

&lt;p&gt;The EU Tour continues to OWASP chapters in Barcelona, Bucharest, Belgium, Denmark, Dublin, Lisbon, Netherlands and Rome. Other locations will be added in due course.&lt;/p&gt;

&lt;p&gt;&lt;i&gt;Update 29th May 2013:&lt;/i&gt; Dinis Cruz, Rory McCune and Tobias Gondrom are now also speaking.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/5/21/OWASP-EU-Tour-2013-in-London-June-3rd&apos; style=&apos;display:none;&apos;&gt;OWASP EU Tour 2013 in London on June 3rd&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>mobile</category>
		<category>vulnerabilities</category>
		<category>data protection</category>
		<category>threats</category>
		<category>SDLC</category>
		<category>PCIDSS</category>
		<category>trust</category>
		<category>risks</category>
		<category>code</category>
		<category>maturity</category>
		<pubDate>Tue, 21 May 2013 19:59:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/5/21/OWASP-EU-Tour-2013-in-London-June-3rd</guid>
		
	</item>

	<item>
		<title>Cornucopia Ecommerce Website Edition v1.00</title>
		<link>http://www.clerkendweller.com/2013/5/18/Cornucopia-Ecommerce-Website-Edition-v100</link>
		<description>
		
		&lt;p&gt;Cornucopia Ecommerce Website Edition v1.00 was &lt;a href=&quot;https://www.owasp.org/index.php/File:OWASP-Cornucopia-Ecommerce_Website.docx&quot;&gt;uploaded&lt;/a&gt; to the &lt;a href=&quot;https://www.owasp.org/&quot;&gt;OWASP website&lt;/a&gt; in February and has now been upgraded to a full OWASP &lt;a href=&quot;https://www.owasp.org/index.php/Category:OWASP_Project&quot;&gt;project&lt;/a&gt;.&lt;/p&gt;

&lt;img style=&quot;border:1px solid #999;padding:0;margin-top:1em;margin-bottom:1.2em;&quot; src=&quot;http://www.clerkendweller.com/posts/2013/cornucopia-ecommerce-1.jpg&quot; width=&quot;500&quot; height=&quot;375&quot; alt=&quot;Photograph of some playing cards from OWASP Ecommerce Web Site Edition v1.00&quot; /&gt;

&lt;p&gt;Today, I have completed the new &lt;a href=&quot;https://www.owasp.org/index.php/OWASP_Cornucopia&quot;&gt;OWASP Cornucopia Project&lt;/a&gt; pages which include:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Description and objectives&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;https://www.owasp.org/images/2/29/Owaspnl-colinwatson-cornucopia.odp&quot;&gt;Presentation&lt;/a&gt; given at &lt;a href=&quot;/2013/3/15/Presentations-at-OWASP-Netherlands&quot;&gt;OWASP Netherlands&lt;/a&gt; in March&lt;/li&gt;
        &lt;li&gt;Links to all the references files, including a new &lt;a href=&quot;https://www.owasp.org/index.php/File:Owasp-requirements-numbering.zip&quot;&gt;security coding practice requirement identities&lt;/a&gt;, created last week&lt;/li&gt;
	&lt;li&gt;Instructions on how to play&lt;/li&gt;
	&lt;li&gt;Frequently asked questions&lt;/li&gt;
	&lt;li&gt;Acknowledgements&lt;/li&gt;
	&lt;li&gt;Road map and how to get involved&lt;/li&gt;
        &lt;li&gt;Link to the &lt;abbr title=&quot;Payment Card Industry Security Standards Council&quot;&gt;PCISSC&lt;/abbr&gt; information supplement for &lt;abbr title=&quot;Payment Card Industry Data Security Standard&quot;&gt;PCIDSS&lt;/abbr&gt; &lt;a href=&quot;/2013/2/6/PCI-DSS-ECommerce-Guidelines&quot;&gt;referencing Cornucopia&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Please let me know if you think I can add anything of use to the project pages.&lt;/p&gt;

&lt;p&gt;I am also working on some minor updates to the ecommerce website edition&apos;s documentation and deck. I will be presenting the project at an event in London shortly.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/5/18/Cornucopia-Ecommerce-Website-Edition-v100&apos; style=&apos;display:none;&apos;&gt;Cornucopia Ecommerce Website Edition v1.00&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>PCIDSS</category>
		<category>preventative</category>
		<category>technical</category>
		<category>threats</category>
		<category>SDLC</category>
		<category>development</category>
		<category>specification</category>
		<category>requirements</category>
		<category>risks</category>
		<category>design</category>
		<category>testing</category>
		<pubDate>Sat, 18 May 2013 19:30:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/5/18/Cornucopia-Ecommerce-Website-Edition-v100</guid>
		
	</item>

	<item>
		<title>Internet and Mobile Literacy, Usage &amp; Opinions</title>
		<link>http://www.clerkendweller.com/2013/5/17/Internet-and-Mobile-Literacy-Usage-Opinions</link>
		<description>
		
		&lt;p&gt;&lt;a href=&quot;http://www.ofcom.org.uk/about/&quot;&gt;OFCOM&lt;/a&gt;, the UK communications sector&apos;s regulator and competition authority, has &lt;a href=&quot;http://media.ofcom.org.uk/2013/04/23/uk-adults-taking-online-password-security-risks/&quot;&gt;announced&lt;/a&gt; a report on adults&apos; use of media and attitudes.&lt;/p&gt;

&lt;div class=&quot;quotation&quot;&gt;&lt;p&gt;More than half of internet users say they use the same passwords for most websites&lt;/p&gt;&lt;/div&gt;

&lt;p&gt;The &lt;a href=&quot;http://stakeholders.ofcom.org.uk/market-data-research/media-literacy/media-lit-research/adults-2013/&quot;&gt;Adults&apos; Media Use and Attitudes Report 2013&lt;/a&gt; (&lt;a href=&quot;http://stakeholders.ofcom.org.uk/binaries/research/media-literacy/adult-media-lit-13/2013_Adult_ML_Tracker.pdf&quot;&gt;complete 181 page print version&lt;/a&gt;) discusses media literacy, take-up, preference and media use, understanding, attitudes and concerns, use of the internet and mobile phones, and users in three class &amp;mdash; new, &quot;narrow&quot; and non-users.&lt;/p&gt;

&lt;div class=&quot;quotation&quot;&gt;&lt;p&gt;Over half of all internet users think that online purchasing puts their privacy at risk&lt;/p&gt;&lt;/div&gt;

&lt;p&gt;There is a wealth of valuable data for strategic planning and marketing purposes, but also useful information on security and safety habits and attitudes to regulation of the internet. If you need information to help support decisions around security and usability, this report will have something of use to you.&lt;/p&gt;

&lt;div class=&quot;quotation&quot;&gt;&lt;p&gt;A quarter of internet users say they have experienced a virus on their home PC or laptop in the past year&lt;/p&gt;&lt;/div&gt;

&lt;p&gt;It is this weekend&apos;s best read.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/5/17/Internet-and-Mobile-Literacy-Usage-Opinions&apos; style=&apos;display:none;&apos;&gt;Internet and Mobile Literacy, Usage &amp; Opinions&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>metrics</category>
		<category>data protection</category>
		<category>threats</category>
		<category>operation</category>
		<category>legislation</category>
		<category>risks</category>
		<pubDate>Fri, 17 May 2013 08:34:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/5/17/Internet-and-Mobile-Literacy-Usage-Opinions</guid>
		
	</item>

	<item>
		<title>IP Address Sharing and Individual Identification</title>
		<link>http://www.clerkendweller.com/2013/5/10/IP-Address-Sharing-and-Individual-Identification</link>
		<description>
		
		&lt;p&gt;BT has announced a trial of its Carrier-Grade Network Address Translation (CGNAT) where Internet Protocol (IP) addresses will be shared between subscribers.&lt;/p&gt;

&lt;div class=&quot;quotation&quot;&gt;&lt;p&gt;organisations [will] generally have to treat IP addresses as personal data&lt;/p&gt;&lt;/div&gt;

&lt;p&gt;&lt;a href=&quot;http://www.ispreview.co.uk/index.php/2013/01/uk-isps-react-to-the-pros-and-cons-of-ipv4-internet-address-sharing.html&quot;&gt;Concerns&lt;/a&gt; have been expressed about the ability for some application to work if they rely on the assumption that IP addresses are unique, and also how this affects the identification of individual people.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.out-law.com/&quot;&gt;Out-law.com&lt;/a&gt; provides a &lt;a href=&quot;http://www.out-law.com/en/articles/2013/may/individuals-can-be-identified-despite-ip-address-sharing-bt-says/&quot;&gt;good review of the issues and information from BT&lt;/a&gt;, but links to the sources are not provided. BT has apparently stated they will still be able to identify individuals despite using CGNAT.&lt;/p&gt;

&lt;p&gt;But the issue of identification does not only relate to newsworthy &quot;illegal online activity&quot; but also for wider privacy protection of completely legal activity where it is clear that IP addresses really must be considered as personal identifiers, especially when they can be combined with other data sets. Something to be considered in privacy impact assessments.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/5/10/IP-Address-Sharing-and-Individual-Identification&apos; style=&apos;display:none;&apos;&gt;IP Address Sharing and Individual Identification&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>detective</category>
		<category>data protection</category>
		<category>identity</category>
		<category>IP addresses</category>
		<category>legislation</category>
		<pubDate>Fri, 10 May 2013 09:48:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/5/10/IP-Address-Sharing-and-Individual-Identification</guid>
		
	</item>

	<item>
		<title>Consultation on Cyber Security Standard</title>
		<link>http://www.clerkendweller.com/2013/5/7/Consultation-on-Cyber-Security-Standard</link>
		<description>
		
		&lt;p&gt;The UK Cabinet Office has announced a &lt;a href=&quot;https://www.gov.uk/government/consultations/cyber-security-organisational-standards-call-for-evidence&quot;&gt;consultation&lt;/a&gt; into the proposed cyber risk management standard for organisations as part of its &lt;a href=&quot;http://www.clerkendweller.com/2011/12/2/UK-Cyber-Security-Hub&quot;&gt;cyber security strategy&lt;/a&gt; announced in November 2011.&lt;/p&gt;

&lt;img style=&quot;border:1px solid #999;padding:0;margin-top:1em;margin-bottom:1.2em;&quot; src=&quot;http://www.clerkendweller.com/posts/2013/security-experience-1.jpg&quot; width=&quot;500&quot; height=&quot;325&quot; alt=&quot;Photograph of the feedback entry device for travellers at a Gatwick Airport who have just passed through the outbound security checks labelled &apos;How was your security experience&apos; with four smiley-style buttons below&quot; /&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/193316/bis-13-853-cyber-security-organisational-standards-guidance.pdf&quot;&gt;proposed guidance&lt;/a&gt; and accompanying &lt;a href=&quot;https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/132466/bis-13-659-cyber-security-organisational-standards-call-for-views-and-evidence.pdf&quot;&gt;call for views and evidence&lt;/a&gt; define Cyber security as &quot;preservation of confidentiality, integrity, and availability of information in cyberspace&quot; and cyberspace quite broadly as &quot;complex environment resulting from the interaction of people, software, and services on the Internet by means of technology devices and networks connected to it, which does not exist in any physical form&quot;.&lt;/p&gt;

&lt;p&gt;The UK Government intends to select and endorse an organisational standard that best meets the requirements for effective cyber risk management. The current proposal outlines requirements for a standard, its objectives, outcomes, auditable requirements and controls in &quot;at least&quot; the following areas:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;Network security&lt;/li&gt;
	&lt;li&gt;Malware prevention 
	&lt;li&gt;Secure configuration of information systems &lt;/li&gt;
	&lt;li&gt;Monitoring &lt;/li&gt;
	&lt;li&gt;Removable media &lt;/li&gt;
	&lt;li&gt;Home and mobile working &lt;/li&gt;
	&lt;li&gt;Managing user privileges &lt;/li&gt;
	&lt;li&gt;User education and awareness &lt;/li&gt;
	&lt;li&gt;Incident management.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;So, somewhat disappointing that application security isn&apos;t mentioned, but those requirements pre-date this consultation - about the choice of an existing standard to follow.&lt;/p&gt;

&lt;p&gt;Responses can be sent by email to &lt;a href=&quot;cybersecurity@bis.gsi.gov.uk&quot;&gt;cybersecurity@bis.gsi.gov.uk&lt;/a&gt; or by post to Cyber Security Team, BIS, 1 Victoria Street, London SW1H 0ET. The closing date to submit evidence is 14 October 2013.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/5/7/Consultation-on-Cyber-Security-Standard&apos; style=&apos;display:none;&apos;&gt;Consultation on Cyber Security Standard&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>legislation</category>
		<pubDate>Tue, 07 May 2013 19:39:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/5/7/Consultation-on-Cyber-Security-Standard</guid>
		
	</item>

	<item>
		<title>OWASP European Tour Kick-Off in Cambridge</title>
		<link>http://www.clerkendweller.com/2013/5/4/OWASP-European-Tour-KickOff-in-Cambridge</link>
		<description>
		
		&lt;p&gt;Following the success of similar events in Latin America, a rolling tour of events with &lt;a href=&quot;https://www.owasp.org/&quot;&gt;OWASP&lt;/a&gt; speakers will be occurring in European Countries, beginning with Cambridge this month.&lt;/p&gt;

&lt;img style=&quot;border:1px solid #999;padding:0;margin-top:1em;margin-bottom:1.2em;&quot; src=&quot;http://www.clerkendweller.com/posts/2013/european-tour-1.jpg&quot; width=&quot;500&quot; height=&quot;375&quot; alt=&quot;Banner image from the OWASP European Tour flyer for the application security event in Cambridge, UK on 13th May 2013&quot; /&gt;

&lt;p&gt;This first event of the tour has been organised in conjunction with Anglia Ruskin University&apos;s &lt;a href=&quot;http://www.anglia.ac.uk/ruskin/en/home/faculties/fst/departments/comptech.html&quot;&gt;Department of Computing&lt;/a&gt; and Technology for &lt;a href=&quot;http://www.anglia.ac.uk/ruskin/en/home/faculties/fst/news0/owasp_tour_2013.html&quot;&gt;Monday 13 May 2013&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The &lt;a href=&quot;http://www.anglia.ac.uk/ruskin/en/home/faculties/fst/news0/owasp_tour_2013.Maincontent.0005.file.tmp/OWASP%20EU%20Tour%202013%20-%20Cambridge%20Chapter%20and%20Anglia%20Ruskin%20University%20-%20Monday%20May%2013th%202013.pdf&quot;&gt;agenda&lt;/a&gt; lists all the speakers:&lt;/p&gt;

&lt;ul&gt;
	&lt;li&gt;&lt;a href=&quot;http://uk.linkedin.com/pub/adrian-winckles/3/2ab/258&quot;&gt;Adrian Winckles&lt;/a&gt;, &lt;a href=&quot;https://www.owasp.org/index.php/Cambridge&quot;&gt;OWASP Cambridge&lt;/a&gt; Chapter Leader &amp;amp; Senior Lecturer&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;http://www.cl.cam.ac.uk/~rja14/&quot;&gt;Ross Anderson&lt;/a&gt;, &lt;a href=&quot;http://www.cam.ac.uk/&quot;&gt;Cambridge University&lt;/a&gt; &lt;a href=&quot;http://www.cl.cam.ac.uk/&quot;&gt;Computer Laboratory&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;DI Stewart Garrick, &lt;a href=&quot;http://content.met.police.uk/Home&quot;&gt;Metropolitan Police&lt;/a&gt; &lt;a href=&quot;http://content.met.police.uk/Site/pceu&quot;&gt;ECrime Unit&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;http://uk.linkedin.com/in/connectjunkie/&quot;&gt;Justin Clarke&lt;/a&gt;, &lt;a href=&quot;https://www.owasp.org/index.php/London&quot;&gt;OWASP London&lt;/a&gt; Chapter Leader&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;http://ie.linkedin.com/in/eoinkeary/&quot;&gt;Eoin Keary&lt;/a&gt;, &lt;a href=&quot;https://www.owasp.org/&quot;&gt;OWASP&lt;/a&gt; &lt;a href=&quot;https://www.owasp.org/index.php/About_OWASP#2013_Global_Board_Members&quot;&gt;Board Member&lt;/a&gt;&lt;/li&gt;
	&lt;li&gt;&lt;a href=&quot;http://uk.linkedin.com/in/vdbaan/&quot;&gt;Steven van der Baan&lt;/a&gt;, &lt;a href=&quot;https://www.owasp.org/index.php/Cambridge&quot;&gt;OWASP Cambridge&lt;/a&gt; Chapter Leader&lt;/li&gt;
	&lt;li&gt;... and &lt;a href=&quot;http://uk.linkedin.com/in/clerkendweller/&quot;&gt;myself&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;I will be speaking about application security vulnerability severity ranking and prioritisation. This will be of use if you have to create or consume vulnerability assessments and penetration test reports, or are involved in patch management or PCIDSS compliance.&lt;/p&gt;

&lt;p&gt;Thank you to &lt;a href=&quot;http://ie.linkedin.com/in/fcerullo&quot;&gt;Fabio Cerullo&lt;/a&gt; and the OWASP team who made this tour happen.&lt;/p&gt;

&lt;p&gt;The event runs from 11:00 to 17:15 hrs and is located in LAB 002, Lord Ashcroft Building, &lt;a href=&quot;http://www.anglia.ac.uk/ruskin/en/home.html&quot;&gt;Anglia Ruskin University&lt;/a&gt;, Cambridge. It is free to attend, but &lt;a href=&quot;https://www.surveymonkey.com/s/OWASP-Tour-May2013&quot;&gt;advance registration&lt;/a&gt; is required.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/5/4/OWASP-European-Tour-KickOff-in-Cambridge&apos; style=&apos;display:none;&apos;&gt;OWASP European Tour Kick-Off in Cambridge&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>operation</category>
		<category>maturity</category>
		<category>specification</category>
		<category>technical</category>
		<category>SDLC</category>
		<category>PCIDSS</category>
		<category>information assurance</category>
		<category>risks</category>
		<category>disposal</category>
		<category>design</category>
		<category>testing</category>
		<category>development</category>
		<pubDate>Sat, 04 May 2013 07:36:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/5/4/OWASP-European-Tour-KickOff-in-Cambridge</guid>
		
	</item>

	<item>
		<title>2013 Information Security Breaches</title>
		<link>http://www.clerkendweller.com/2013/4/30/2013-Information-Security-Breaches</link>
		<description>
		
		&lt;p&gt;Last week the UK&apos;s &lt;a href=&quot;https://www.gov.uk/government/organisations/department-for-business-innovation-skills&quot;&gt;Department for Business Innovation &amp;amp; Skills&lt;/a&gt; &lt;a href=&quot;https://www.gov.uk/government/news/more-small-businesses-hit-by-cyber-attacks&quot;&gt;published&lt;/a&gt; the 2013 Information Security Breaches Survey, created in conjunction with PwC.&lt;/p&gt;

&lt;img style=&quot;border:1px solid #999;padding:0;margin-top:1em;margin-bottom:1.2em;&quot; src=&quot;http://www.clerkendweller.com/posts/2013/breach-incidents-1.jpg&quot; width=&quot;500&quot; height=&quot;350&quot; alt=&quot;One of the bar charts in the DBIS &apos;2013 Information Security Breaches Survey&apos;&quot; /&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.gov.uk/government/publications/information-security-breaches-survey-2013-technical-report&quot;&gt;report&lt;/a&gt; presents the results of the survey and breaks the findings down for larger (&amp;gt;250 staff), medium and smaller (&amp;lt;50 staff) organisations. The term &quot;cyber&quot; appears 15 times and &quot;APT&quot; only once, so is generally hyperbole-free.&lt;/p&gt;

&lt;p&gt;The most interesting data points for me are:&lt;/p&gt;

&lt;ul&gt;
   &lt;li&gt;18% of &quot;worst breaches&quot; related to websites and internet gateways, and 4% to breach of laws/regulations&lt;/li&gt;
   &lt;li&gt;For all breaches, operation disruption typically lasts a week, with 2-4weeks FTE effort responding to the incident, and a quarter of incidents leading to lost business&lt;/li&gt;
   &lt;li&gt;Reputation losses were estimated to be between &amp;pound;10,000 and &amp;pound;100,000.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The report is available to download &lt;a href=&quot;https://www.gov.uk/government/publications/information-security-breaches-survey-2013-technical-report&quot;&gt;in full&lt;/a&gt; free of charge without registration.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/4/30/2013-Information-Security-Breaches&apos; style=&apos;display:none;&apos;&gt;2013 Information Security Breaches&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>maturity</category>
		<category>incidents</category>
		<category>threats</category>
		<category>operation</category>
		<category>technical</category>
		<category>corrective</category>
		<category>legislation</category>
		<pubDate>Tue, 30 Apr 2013 20:53:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/4/30/2013-Information-Security-Breaches</guid>
		
	</item>

	<item>
		<title>Reflections on Security B-Sides London 2013</title>
		<link>http://www.clerkendweller.com/2013/4/28/Reflections-on-Security-BSides-London-2013</link>
		<description>
		
		&lt;p&gt;I have just had time to catch up on my attendance and &lt;a href=&quot;https://www.clerkendweller.com/2013/4/19/AppSensor-at-Security-BSides-London&quot;&gt;participation&lt;/a&gt; at &lt;a href=&quot;http://www.securitybsides.org.uk/&quot;&gt;Security B-Sides London 2013&lt;/a&gt;.&lt;/p&gt;

&lt;img style=&quot;border:1px solid #999;padding:0;margin-top:1em;margin-bottom:1.2em;&quot; src=&quot;http://www.clerkendweller.com/posts/2013/bsides-london-1.jpg&quot; width=&quot;500&quot; height=&quot;300&quot; alt=&quot;One of the cartoon-like illustrated pages from the presentation &apos;The Realex Payments Application Security story&apos; by David Rook (Security Ninja) at Security B-Sides London 2013&quot; /&gt;

&lt;p&gt;This community-led event was held at the town hall of the &lt;a href=&quot;http://www.rbkc.gov.uk/&quot;&gt;Royal Borough of Kensington and Chelsea&lt;/a&gt; on Wednesday 24th April, and was supported by a large number of speakers, educators, volunteers and sponsors. It was an extremely well organised, and useful, day.&lt;/p&gt;

&lt;p&gt;Following the very well attended welcome and introduction from the B-Sides London crew, I went to an immensely valuable and engaging presentation by &lt;a href=&quot;ie.linkedin.com/pub/david-rook/3/41a/b1b&quot;&gt;David Rook&lt;/a&gt; (aka &lt;a href=&quot;http://twitter.com/securityninja&quot;&gt;Security Ninja&lt;/a&gt;) on how he introduced and developed an application security programme at his employer Realex Payments. He has got to the point where customers are approaching his company to act as a payment services provider due only to their knowledge of Security Ninja, and so the marketing department kindly designed cartoon-style presentation slides (like the one illustrated above). They also had these printed as booklets to hand-out to those attending the talk at B-Sides London. David described what was done, how it was achieved, and things he would approach differently in hindsight. I won&apos;t spoil the plot for you as you will be able to read the booklet yourselves (keep an eye open for a &lt;a href=&quot;http://www.securityninja.co.uk/blog/&quot;&gt;blog post&lt;/a&gt; (now &lt;a href=&quot;http://www.slideshare.net/securityninja/b-sides-2013presentation&quot;&gt;available&lt;/a&gt;).&lt;/p&gt;

&lt;p&gt;After this, I went down to the new Rookie Track where new presenters had been given support through mentoring to give 15-minute presentations. Firstly I listened to &lt;a href=&quot;http://uk.linkedin.com/in/artjom&quot;&gt;Artjom Vassiljev&lt;/a&gt; describe how he has built software security testing checks into a continuous integration process with Jenkins.&lt;/p&gt;

&lt;p&gt;Following a quick coffee break and catch up with some friends &amp;amp; acquaintances, I returned to the Rookie Track and listened to &lt;a href=&quot;https://www.linkedin.com/in/diarmaidmcmanus&quot;&gt;Diarmaid McManus&lt;/a&gt; describe a new Eclipse plugin called &lt;a href=&quot;https://github.com/diarmaid-mcmanus/ESPSecurityPlugin&quot;&gt;ESP&lt;/a&gt; he has been working on to help integrate code review checks into developer&apos;s coding tools.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://ru.linkedin.com/in/kseniadmitrieva&quot;&gt;Ksenia Dmitrieva&lt;/a&gt; provided an introduction to HTML5 risks and gave explanations and examples of common attacks. She also explained the preventative measures which should be used to protect against these issues.&lt;/p&gt;

&lt;p&gt;Post lunch, I tracked down &lt;a href=&quot;http://uk.linkedin.com/in/diniscruz&quot;&gt;Dinis Cruz&lt;/a&gt; and we set up our workshop on using &lt;a href=&quot;https://www.owasp.org/index.php/OWASP_O2_Platform&quot;&gt;OWASP O2&lt;/a&gt; to visualise &lt;a href=&quot;https://www.owasp.org/index.php/OWASP_AppSensor_Project&quot;&gt;OWASP AppSensor&lt;/a&gt; behaviour. I introduced the concept of application-specific attack detection and response, and described how the ideas might be retrofitted relatively simply to an existing web application such as the bulletin board software &lt;a href=&quot;https://www.phpbb.com/&quot;&gt;phpBB&lt;/a&gt;. A review of phpBB&apos;s inherent capabilities and logging provide a useful hook for detection points, and responses can include adding users to phpBB&apos;s list of &quot;banned IPs&quot; and blocking IPs at the operating system level. Dinis continued with a live demo of the AppSensor demo application, created by Michael Coates, and then he went on to show how AppSensor&apos;s new web services Java code can be called directly from within a .Net application TeamMentor.It was good to bounce ideas off the workshop participants and get their thoughts and suggestions on the practicalities of implementing AppSensor-like capabilities.&lt;/p&gt;

&lt;p&gt;Finally I saw &lt;a href=&quot;http://uk.linkedin.com/in/gavinholt&quot;&gt;Gavin Holt&lt;/a&gt;  talking about &quot;NoSQL &amp;amp; Big Data - A Way to Lose Even More Stuff&quot; in which he described the common weaknesses in using NoSQL and attacks that attempt to access such systems and their data. I really liked the 15minute format on the Rookie Track and all three speakers I heard were really good.&lt;/p&gt;

&lt;p&gt;Overall, an excellent day. Many thanks to the very professional B-Sides London team in particular for making sure it all happened.&lt;/p&gt;

&lt;p&gt;&lt;i&gt;Update 30th April 2013:&lt;/i&gt; Link to Security Ninja&apos;s slides added. Ksenia Dmitrieva&apos;s talk added.&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com/2013/4/28/Reflections-on-Security-BSides-London-2013&apos; style=&apos;display:none;&apos;&gt;Reflections on Security B-Sides London 2013&lt;/a&gt;&lt;/p&gt;
		

&lt;p&gt;&lt;a href=&apos;http://www.clerkendweller.com&apos; style=&apos;display:none;&apos;&gt;Clerkendweller&lt;/a&gt;&lt;/p&gt;
		
		</description>
				
		
		<category>detective</category>
		<category>design</category>
		<category>SDLC</category>
		<category>threats</category>
		<category>operation</category>
		<category>development</category>
		<category>testing</category>
		<category>preventative</category>
		<pubDate>Sun, 28 Apr 2013 23:39:00 +0100</pubDate>
		<guid>http://www.clerkendweller.com/2013/4/28/Reflections-on-Security-BSides-London-2013</guid>
		
	</item>

</channel></rss>