{"version":1,"type":"rich","provider_name":"Libsyn","provider_url":"https:\/\/www.libsyn.com","height":90,"width":600,"title":"Episode 194 - Evaluating Security Product Vendors","description":"Evaluating Security Product Vendors &amp;nbsp; In light of recent news about \u201cVendors Behaving Badly\u201d we want to talk about how a security professional should evaluate vendors and their products. &amp;nbsp; Recent News: Tanium exposed hospital\u2019s IT while using its network in sales demos:  https:\/\/arstechnica.com\/security\/2017\/04\/security-vendor-uses-hospitals-network-for-unauthorized-sales-demos\/ Lawyers, malware, and money: The antivirus market\u2019s nasty fight over Cylance:  https:\/\/arstechnica.com\/information-technology\/2017\/04\/the-mystery-of-the-malware-that-wasnt\/ &amp;nbsp;  There are so many different sources of information about vendors and their products. &amp;nbsp;You owe it to yourself to evaluate not just the vendor but also each source of information.  Analyst Firms: &amp;nbsp;Gartner\/Forrester\/etc   Always remember they take a very generic view using a notional enterprise as the standard. Current customer interviews are important but, remember, those customer contacts likely came from the vendor. The perception of \u201cPay for Play\u201d is there no matter how much the firms want to squelch that.   These tests presume a lot so make sure you understand what the conditions of the test were. The \u201cPay for Play\u201d perception exists here too\u2026. The results of the testing aren\u2019t specific but can help show outliers in a group   3rd Party Testing: &amp;nbsp;NSS Labs, etc.  Obviously your best and most relevant source of information. &amp;nbsp;:-)   Podcasts  If you have developed a reliable network of peers you can reach out and ask folks. &amp;nbsp;But, remember, buy them a beer for their troubles\u2026 Always remember perspective is everything. &amp;nbsp;Some people just don\u2019t like Company_Z and will always hate their products.   Networking   Information Sources  Start with 3rd party data and demos. &amp;nbsp;This will determine if your requirements (you did write out your requirements, right?) are met by the product  Do not allow the vendor to drive the definition of \u201csuccess\u201d in a PoC Try to break it. &amp;nbsp;I mean REALLY try to break it. Remember during the PoC is going to be the best support and interaction you will ever get. &amp;nbsp;If that sucks you might want to move along. Test *all* of your use cases. (you do have documented use cases, right?)   Do a PoC (Proof of Concept).   Product Evaluation Rules  Service providers such as penetration testers and MSSPs   Edge Cases  ","author_name":"The Southern Fried Security Podcast","author_url":"http:\/\/www.southernfriedsecurity.com","html":"<iframe title=\"Libsyn Player\" style=\"border: none\" src=\"\/\/html5-player.libsyn.com\/embed\/episode\/id\/5303251\/height\/90\/theme\/custom\/thumbnail\/yes\/direction\/forward\/render-playlist\/no\/custom-color\/88AA3C\/\" height=\"90\" width=\"600\" scrolling=\"no\"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen><\/iframe>","thumbnail_url":"https:\/\/assets.libsyn.com\/secure\/item\/5303251"}