Slow progress of late
We are still here (thanks to those of you who've written to check)....however the core team have been busy on other projects (and their day jobs)....which all in all has meant slow progress.
Updates, insights, and commentary from the OSA community. Tracking the evolution of security architecture since 2008.
We are still here (thanks to those of you who've written to check)....however the core team have been busy on other projects (and their day jobs)....which all in all has meant slow progress.
We've added a new icon to the 13_02 set for an upcoming PCI pattern. We now have a White Hat to represent an ethical 'hacker' (I place it in quotes as the term originally meant computer user who hacked together code quickly to achieve a given objective, and has somewhat changed meaning in recent years), a.k.a Pen Tester.
When we founded OSA a few years back it seemed likely that we would soon inhabit a world where IT Security and the management of IT Risks would be a crucial part of the equation to ensure that our society and it's industrial, commercial and economic systems functioned effectively. There was already a strong case for ensuring that computing architectures were secure for financial services but it was less clear on the importance of security for Industrial Control Systems, or the need to ensure that social networking and information providers maintained high levels of integrity.
There have been a remarkable number of news items lately on hacking operations uncovered at large organisations that have exfiltrated significant volumes of data and gone undetected for 6 months plus. The QinetiQ example that Wired mention is typical of the breed.
We've been very quiet at OSA for the last 18 months, as the Core Team members have been busy on other projects. However it's not long until Spring (we hope), and in line with the awakening of life in the Northern Hemisphere we are planning a spring clean and freshen up for the site.
Some more vulnerabilities come to light in SCADA systems:
More Siemens vulnerabilities have come to light. See the article at Ars for more info http://arstechnica.com/security/news/2011/08/serious-security-holes-found-in-siemens-control-systems-targeted-by-stuxnet.ars (http://arstechnica.com/security/news/2011/08/serious-security-holes-found-in-siemens-control-systems-targeted-by-stuxnet.ars)
We've added a few new icons to the 11_02 set for an upcoming pattern. We now have a Black Hat to represent a 'hacker' (I place it in quotes as the term originally meant computer user who hacked together code quickly to achieve a given objective, and has somewhat changed meaning in recent years).
2 high impact outages for large service providers recently. Amazon cloud services which had knock on effects for a number of large companies relying on their cloud services. Sony which suffered a major security breach and which at the time of writing is still being cleaned up with unknown total impact on customers.
## February 2011 Open Security Architecture Newsletter