Last week San Francisco became the information security capital of the world for the 2015 RSA Conference. Around 30,000 attendees, mostly security professionals and vendors, descended on the Moscone Center for a week of discussion about the industry and new technologies. With literally too many talks for one person to attend, it’s hard to build a session schedule. Yet, as with any industry conference, there are key themes that arise in sessions, conversations, and the show floor. As a first time attendee who tried to make the most of my first RSA Conference, here are my three key observations on the industry:
A Need for Standardization
As information security and risk management practices mature, many are asking whether the industry needs more concrete standards for a variety of functions. For example, many inquired about the need for a national breach standard notification law during the panel discussion Cybersecurity Legislation: Congressional and Administrative Actions. While some panelists noted that differing state level breach notification laws were merely bureaucratic red tape for businesses, many audience members seemed to express discontent with the current status quo.
In a panel on a very different topic, the need for standardization was also brought up as essential to manage third party software security. During The Coming Revolution: Industry Groups Defining Vendor Assessment Standards the panelists called for a standard around vetting third party software vulnerabilities. Working with SAFECode, the panelists along with other industry experts presented a basic framework for businesses to better standardize their approach to software security. They noted that a standard model would take away the power struggles that define the current system: small software vendors jump through hoops for large companies and large software vendors ignore software security requests from smaller customers. It seems that on a wide range of topics, the community is ready to begin embracing common standards to streamline security and risk management practices.