<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Replacing the Traditional IPS in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Replacing-the-Traditional-IPS/m-p/4634#M493</link>
    <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/212535869"&gt;@greppy73&lt;/a&gt;&amp;nbsp;I hear you on the perimeter disappearing. That's funny. I remember hearing my first presentation on "deperimeterization" about 8 years ago.&amp;nbsp;The interesting thing is that deperimeterization happened a long time ago for some organizations and is still just now happening for others. Also, it doesn't always feel like "de"-perimeterization - more like "poly-perimeterization." Places still have things that resemble the old fashioned castle and moat network but now they've added 15 jillion more perimeters as they move business to the cloud, mobile, etc. I could go on but no.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, you make extremely good points: performance/uptime and control of the rules in multi-tenant arrangement. I guess I already knew these things passively but you are helping me to get focused. BTW this particular business runs all 80/443 through a cloud-based secure web gateway and it's terrific. But this SWG is one robust, global cloud service provider with serious redundancy and performance management. It has been very successful. Things get a little more complicated when all ports and protocols come into play. Thanks again for the reply. BTW I believe I detected a tongue in cheek on that Yahoo! news comment. Nicely done.&lt;/P&gt;</description>
    <pubDate>Fri, 29 Dec 2017 18:15:55 GMT</pubDate>
    <dc:creator>DepartmentZ</dc:creator>
    <dc:date>2017-12-29T18:15:55Z</dc:date>
    <item>
      <title>Replacing the Traditional IPS</title>
      <link>https://community.isc2.org/t5/Industry-News/Replacing-the-Traditional-IPS/m-p/4632#M491</link>
      <description>&lt;P&gt;Has anyone replaced their traditional intrusion prevention system (IPS) (physical boxes&amp;nbsp;on-premises, at the perimeter) with a different solution? Like perhaps one of the cloud-based IPS services? I'm interested to know the latest options available in accomplishing IPS goals. What are the pros/cons/things to look out for with the option you selected? Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2017 13:57:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Replacing-the-Traditional-IPS/m-p/4632#M491</guid>
      <dc:creator>DepartmentZ</dc:creator>
      <dc:date>2017-12-29T13:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing the Traditional IPS</title>
      <link>https://community.isc2.org/t5/Industry-News/Replacing-the-Traditional-IPS/m-p/4633#M492</link>
      <description>&lt;P&gt;So I've dabbled in this a bit.&amp;nbsp; I deplore "marketing speech" but the perimeter is disappearing, so my&amp;nbsp;effort has veered more towards HIPS agents and EDR controls (which may not be your question).&amp;nbsp; In my pipe dream world, there is a perfect stack of agents that can defend an endpoint as well as if it was in my network.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've never done this with incoming IDS.&amp;nbsp; I think, over every port, at a cloud provider - internet is a point of failure, so you'll need redundancy.&amp;nbsp; Throughput is going to be a concern, too - ensuring a minimum speed test.&amp;nbsp; You'll also need to lock down those hops very tightly between internal and external. If it's a vendor providing this, I'd want to know specifically what the SLA's are and if I'm on a shared IPS .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have done this on outgoing connections.&amp;nbsp; This was a large enterprise with millions to spend, so we just figured what the heck...they're offering it as a service (really a Palo Alto) and are guaranteeing throughput, so let's just try it.&amp;nbsp; This probably sounds a bit weird, but there are good reasons for it.&amp;nbsp; It worked, I suppose, but there were issues -&amp;nbsp;sometimes due to the complexity of the setup,&amp;nbsp;sometimes due to the service itself.&amp;nbsp; You're likely to face a load issue on your IPS so whoever you're doing this with, better guarantee some level of service.&amp;nbsp; Makes me nervous to think that the CEO's daily visits to Yahoo! news are being slowed down or stopped by something that's not in my direct control.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The biggie, control, is likely where I'm going to lose the most sleep.&amp;nbsp; The other issues can probably be overcome.&amp;nbsp; Historically, IPS rules were specific to the business.&amp;nbsp; What was "bad" for someone might not be bad for others.&amp;nbsp; So what defines that?&amp;nbsp; If I move to the cloud, how much granular control do I have?&amp;nbsp; If you are in a shared cloud (to my earlier remark), that could mess up your ability to create specific rules for your business.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Several other thoughts, but I'll just stop there b/c they delve into other areas beyond IPS.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2017 15:11:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Replacing-the-Traditional-IPS/m-p/4633#M492</guid>
      <dc:creator>greppy73</dc:creator>
      <dc:date>2017-12-29T15:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing the Traditional IPS</title>
      <link>https://community.isc2.org/t5/Industry-News/Replacing-the-Traditional-IPS/m-p/4634#M493</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/212535869"&gt;@greppy73&lt;/a&gt;&amp;nbsp;I hear you on the perimeter disappearing. That's funny. I remember hearing my first presentation on "deperimeterization" about 8 years ago.&amp;nbsp;The interesting thing is that deperimeterization happened a long time ago for some organizations and is still just now happening for others. Also, it doesn't always feel like "de"-perimeterization - more like "poly-perimeterization." Places still have things that resemble the old fashioned castle and moat network but now they've added 15 jillion more perimeters as they move business to the cloud, mobile, etc. I could go on but no.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, you make extremely good points: performance/uptime and control of the rules in multi-tenant arrangement. I guess I already knew these things passively but you are helping me to get focused. BTW this particular business runs all 80/443 through a cloud-based secure web gateway and it's terrific. But this SWG is one robust, global cloud service provider with serious redundancy and performance management. It has been very successful. Things get a little more complicated when all ports and protocols come into play. Thanks again for the reply. BTW I believe I detected a tongue in cheek on that Yahoo! news comment. Nicely done.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2017 18:15:55 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Replacing-the-Traditional-IPS/m-p/4634#M493</guid>
      <dc:creator>DepartmentZ</dc:creator>
      <dc:date>2017-12-29T18:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing the Traditional IPS</title>
      <link>https://community.isc2.org/t5/Industry-News/Replacing-the-Traditional-IPS/m-p/4635#M494</link>
      <description>Oh and I do support your strategy to get closer to the endpoint/action/data via HIPS/EDR - it's solid if you can do it.</description>
      <pubDate>Fri, 29 Dec 2017 18:19:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Replacing-the-Traditional-IPS/m-p/4635#M494</guid>
      <dc:creator>DepartmentZ</dc:creator>
      <dc:date>2017-12-29T18:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing the Traditional IPS</title>
      <link>https://community.isc2.org/t5/Industry-News/Replacing-the-Traditional-IPS/m-p/4637#M495</link>
      <description>&lt;P&gt;&lt;SPAN&gt;As an aside, if anyone was wondering where the whole 'De-Perimiterization' thing&amp;nbsp;first surfaced then you can marvel at the&amp;nbsp;Technicolor Nightmare(in a good way, no really wear shades) that is&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;David Lacey's&amp;nbsp;presentation material on de-perimeterisation to&amp;nbsp;the first&amp;nbsp;meeting of the Jerichio Forum, January 16th 2004:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="boldText"&gt;&lt;A href="https://collaboration.opengroup.org/jericho/presentations/dl_040116.ppt" target="_blank"&gt;Introduction to De-perimeterisation&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I've heard the concept originated with a chap called&amp;nbsp;&lt;SPAN&gt;Jon Measham who was at the Royal Mail in the UK) but my&amp;nbsp;first intro was from David.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The concept of 're-perimiterization' really fits nicely with your idea of poly-perimiterization, which I take to mean that DID is still a thing and will continue to be a thing.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Dec 2017 14:16:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Replacing-the-Traditional-IPS/m-p/4637#M495</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2017-12-30T14:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing the Traditional IPS</title>
      <link>https://community.isc2.org/t5/Industry-News/Replacing-the-Traditional-IPS/m-p/4681#M497</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;Wow. You weren't kidding. I'm pretty sure that was sent back in time to 1984 for final edits. Somehow it works for me though.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, thank you for sharing that peek into the history of "de-perimeterisation." I did not know the origins. I followed it up with some self-guided rabbit hole exploration on Wikipedia starting with&amp;nbsp;&lt;A href="https://en.wikipedia.org/wiki/Jericho_Forum" target="_blank"&gt;https://en.wikipedia.org/wiki/Jericho_Forum&lt;/A&gt; - great stuff.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interesting, much of this material could have been written yesterday&amp;nbsp;and&amp;nbsp;would be timely. One more thought about perimeter: There is a perimeter around every bit of data that you would mind losing, wherever it is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2018 18:10:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Replacing-the-Traditional-IPS/m-p/4681#M497</guid>
      <dc:creator>DepartmentZ</dc:creator>
      <dc:date>2018-01-02T18:10:06Z</dc:date>
    </item>
  </channel>
</rss>

