<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: NotObvious On Heartland</title>
	<atom:link href="http://newschoolsecurity.com/2009/12/notobvious-on-heartland/feed/" rel="self" type="application/rss+xml" />
	<link>http://newschoolsecurity.com/2009/12/notobvious-on-heartland/</link>
	<description>The Blog Inspired By The Book</description>
	<lastBuildDate>Wed, 16 May 2012 16:05:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Andre Gironda</title>
		<link>http://newschoolsecurity.com/2009/12/notobvious-on-heartland/#comment-703</link>
		<dc:creator>Andre Gironda</dc:creator>
		<pubDate>Mon, 21 Dec 2009 17:18:03 +0000</pubDate>
		<guid isPermaLink="false">http://newschoolsecurity.com/?p=1207#comment-703</guid>
		<description>According to their 10-Ks, &quot;We have developed a number of systems that are designed to improve the effectiveness of our sales force, customer service and the management of our business. In 2008, 2007 and 2006 we spent $5.9 million, $4.2 million and $2.5 million, respectively, on capitalized software development costs. Many of the following systems are accessible over the Internet through www.e-hps.com. Each of these systems is regularly updated, with new releases of software scheduled every six weeks&quot;.

So, $12.6M is more than twice what they spend on their on-going software development costs.

My guess is even without an information security management program, companies like Heartland can at least afford to spend $15k/release (assuming every six weeks) on third-party application assessments that would include findings such as SQL injection. This might be a good starting point, at the very least. &lt;a href=&quot;http://securitybuddha.com/2007/10/02/software-security-budgets/&quot; rel=&quot;nofollow&quot;&gt;2% of software development budget&lt;/a&gt; has been tossed around as an indicator for software security budget in the past.

Better -- they would partner with an application security consulting firm, which would involve spending millions of dollars over several years. The impact of such efforts would probably pay off in several different areas of quality and security improvement.

My guess is that companies such as Heartland spend almost all, or at least 60-80%, of their security budget on end-user systems and issues. InfoSec is likely not tied to capital planning or enterprise architecture.

With over a half-billion dollars in assets, and as a payment processor, I would think Heartland would be heavily invested in risk management. It&#039;s extremely unlikely that they are willing to eat $13M annually for these types of costs. Let&#039;s say, for example, that a company such as this spends $1M annually on their information security management program (note that this is less than one-fifth of a percent of their total assets). Verizon Business suggests spending these dollars on &lt;a href=&quot;http://securityblog.verizonbusiness.com/2009/04/14/2009-dbir-compromised-assets/&quot; rel=&quot;nofollow&quot;&gt;online data&lt;/a&gt; versus spending it on end-user systems, based on asset classes by percent of breaches and records.

You don&#039;t have to be Gunnar Peterson to make a top-level decision to heavily invest in the areas prescribed here.</description>
		<content:encoded><![CDATA[<p>According to their 10-Ks, &#8220;We have developed a number of systems that are designed to improve the effectiveness of our sales force, customer service and the management of our business. In 2008, 2007 and 2006 we spent $5.9 million, $4.2 million and $2.5 million, respectively, on capitalized software development costs. Many of the following systems are accessible over the Internet through <a href="http://www.e-hps.com" rel="nofollow">http://www.e-hps.com</a>. Each of these systems is regularly updated, with new releases of software scheduled every six weeks&#8221;.</p>
<p>So, $12.6M is more than twice what they spend on their on-going software development costs.</p>
<p>My guess is even without an information security management program, companies like Heartland can at least afford to spend $15k/release (assuming every six weeks) on third-party application assessments that would include findings such as SQL injection. This might be a good starting point, at the very least. <a href="http://securitybuddha.com/2007/10/02/software-security-budgets/" rel="nofollow">2% of software development budget</a> has been tossed around as an indicator for software security budget in the past.</p>
<p>Better &#8212; they would partner with an application security consulting firm, which would involve spending millions of dollars over several years. The impact of such efforts would probably pay off in several different areas of quality and security improvement.</p>
<p>My guess is that companies such as Heartland spend almost all, or at least 60-80%, of their security budget on end-user systems and issues. InfoSec is likely not tied to capital planning or enterprise architecture.</p>
<p>With over a half-billion dollars in assets, and as a payment processor, I would think Heartland would be heavily invested in risk management. It&#8217;s extremely unlikely that they are willing to eat $13M annually for these types of costs. Let&#8217;s say, for example, that a company such as this spends $1M annually on their information security management program (note that this is less than one-fifth of a percent of their total assets). Verizon Business suggests spending these dollars on <a href="http://securityblog.verizonbusiness.com/2009/04/14/2009-dbir-compromised-assets/" rel="nofollow">online data</a> versus spending it on end-user systems, based on asset classes by percent of breaches and records.</p>
<p>You don&#8217;t have to be Gunnar Peterson to make a top-level decision to heavily invest in the areas prescribed here.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

