Posts

Rejected ISO/IEC 27002 control for SDLC

Image
Suggested text for a new ISO/IEC 27002 control on integrating security into the systems lifecycle Back in February 2011, I proposed to incorporate a new information security control statement concerning integrating security into the systems lifecycle into  ISO/IEC 27002  which was being revised by the committee at the time. To set the scene, recall that section 12 of ISO/IEC 27002:2005 covered Information systems acquisition, development and maintenance  without mentioning development projects or system lifecycles as such. See what you make of the donor text I provided in Standards New Zealand's submission to  ISO/IEC JTC1/SC27  ... ---------------------------------- Control objective To take due account of information security throughout the entire IT systems lifecycle. Implementation guidance While the exact naming, nature and sequence of activities may vary according to different development methods and lifecycle models, appropriate information security activ...

ISO27k Toolkit

Image
On the toolkit theme, I have just updated the FREE ISO27k Toolkit over at ISO27001security.com with an Excel workbook used to track progress on implementing the ISO/IEC 27001 and 27002 standards . Thanks mostly to Ed Hodgson, the gap analysis/SoA workbook in the ISO27k Toolkit has been updated for the 2013 releases of the standards. The new version has two main spreadsheets: The first sheet is used to check and track progress towards implementing an ISMS complying with all the mandatory front parts of ISO/IEC 27001:2013 - mandatory, that is, if you intend to get your ISMS certified.  I made a few little wording changes and editorial decisions in this section, so if you use this for certification purposes, please double-check against the requirements formally specified in the standard and don't rely entirely on the spreadsheet!  The spreadsheet is not definitive.  The standard rules. The second sheet covers the discretionary parts, namely the controls listed briefly in A...

PRAGMATIC security metrics toolkit

Krag and I have been thinking about what might be of value in a 'toolkit' for security metrics.  The kinds of things we have in mind are: Resources such as books and standards on information security, risk management, governance, metrics, statistics and business management - the toolkit would contain references, reviews and links , not the actual content! Techniques, methods and approaches - naturally I'm thinking of the PRAGMATIC method but there are alternative approaches (such as GQM) that complement it: again, the toolkit would contain just a summary with pointers to further advice, since there is a lot to be said; Bootstrap metrics - perhaps a few suggested information security metrics to get you started?  I'm not so sure about this because it's hard to think of information security measurement requirements that are widely applicable, but I guess we could come up with a few illustrative metrics ideas.  Oh wait, we did that already - the 150 metrics in the bo...

Rejected ISO/IEC 27002 control for SCADA

Image
The ISO27k standards are written and maintained by a sizable committee of international experts, working through their national standards bodies and following formal processes, with most of the business conducted at just two face-to-face meetings per year.  As such, the committee sometimes struggles to accept changes and reflect emerging information security issues, particularly in the case of ISO/IEC 27002 . Back in 2011, I suggested the text below as a new control for SCADA/ICS in 27002 but was unable to persuade the project team of its merits, perhaps because they were hoping that ISO/IEC TR 27019:2013 would cover it. --------------------------------- Security requirements for specialist IT systems Control objective  To identify and satisfy the particular information security control requirements of specialist IT systems such as industrial control systems. Implementation guidance The particular information security risks associated with specialist IT systems such as I ndu...

Malawareness, InfoSec 101 and security culture

Image
We've spent an unusually busy February updating two key awareness modules. The awareness module for March covers malware, including bank Trojans, ransomware, APTs, worms and more. We update the malware module annually, and it needs it: malware is a constantly evolving beast, so standing still implies falling back. In the same vein, the module looks forward at how the malware risks are likely to change in the years ahead, prompting a serious discussion with management about strategic options. In our considered opinion having researched the topic in some depth for the module, malware risks that are already serious are getting even worse. The trajectory is clear, with significant implications on the way organizations treat the risks. The  Information Security 101  module has been thoroughly refreshed and updated for use in new employee security orientation sessions, and in launching security awareness programs. Along with many other changes, we've introduced a checklist format ...

Contextually relevant information security metrics

Image
In " Business Analytics - An Introduction ", Evan Stubbs describes "value architecture" in these terms: "Results need to be measurable, they need to be contextually relevant, they need to link into a strategic vision, and their successful completion needs to be demonstrable". Breaking that down, I find that there are really only two key factors. If results are measurable, that implies to me that they can be demonstrated. Also, it's hard to see how results that are 'contextually relevant' might not 'link into a strategic vision' since that is the context, or at least a major part of it. So, in short, results need to be both relevant and measurable. Of those two aspects, measurability is the easier. Read " How to Measure Anything " by Douglas Hubbard! Evan also talks about objectivity, and he is writing in the context of big data analytics, meaning the difficult problem of extracting useful meaning from huge and dynamic volumes ...

Holistic security metrics

Image
Yet again today I find my blood pressure reading as I read yet another incredibly biased pronouncement on security metrics from security vendors: "Do you know what security metrics are right for your organization? For a holistic view, both network and host metrics are required, including firewalls, routers, load balancers, and hosts." To claim that having network and host security metrics qualifies as holistic almost beggars belief, for any thinking person's definition of the term but I'm afraid it's typical of the incredibly myopic purely technical perspective on security metrics, continually reiterated for blatantly obvious marketing reasons by the purveyors of ... IT security products. Being sick and tired of explaining that IT security is a dead end off the main information security highway, I'll merely suggest a few non-technical security metrics that might get us a tiny bit closer towards a truly holistic view: Information security ascendancy  - a measu...