Posts

Management awareness paper on insider threat metrics

Image
How do you measure 'insider threats' in your organization?   If your answer is "We don't!", then I have to wonder how you are managing insider threats.  Without suitable metrics, how do you figure out how much of a problem you might have from employees, contractors, consultants, temps and interns?  How do you determine where best to spend your security budget? How do you persuade management to loosen the purse strings sufficiently to address the risks?  I guess you guess! The discussion paper breaks down 'insider threat' into chunks that can be measured sensibly.  The main divide falls between deliberate attacks (such as frauds by insiders) and accidents (such as mistakenly overwriting the entire production database - don't laugh, it happened to me 25 years ago and the nightmare still haunts me today!).  The paper picks up on one of the most productive sources of information security metrics: the IT Help/Service Desk's problem and incident manage...

Management awareness paper on network security metrics

Image
Measuring network security involves, first and foremost, determining what 'network security' encompasses, and how it relates to the business. Writing way back in 2007 , we said that network security "comprises a range of technical and procedural controls designed to prevent, detect and/or recover from security incidents affecting the corporate data networks – incidents such as unauthorized access (hacking), worms and other malware infections, and unplanned network downtime". The context for the paper was a security awareness module exploring security arrangements protecting data networks against both deliberate and accidental threats. The paper described ways to measure network security incidents, controls, risks, compliance and governance.  It ended with an upbeat conclusion and call-to-action: "Do not neglect the value of having the experts present and discuss reports with management.  The dialogue that ensues adds value to the written reports.  Why not present...

PCI embraces security awareness

Image
The PCI Security Standards Council's  Security Awareness Program Special Interest Group  has released an 'information supplement' to PCI-DSS, suggesting an awareness approach that is remarkably similar to ours. Best Practices for Implementing a Security Awareness Program is a well-written guide elaborating on four key ideas: 1) Security awareness is a vital tool supporting the business.  "It is therefore vital that organizations have a security awareness program in place to ensure employees are aware of the importance of protecting sensitive information, what they should do to handle information securely, and the risks of mishandling information." [We go further in emphasizing the business value of information security, for example giving management confidence that information assets will be sufficiently well protected when exploring new business opportunities.] 2) Security awareness is best delivered on a continual basis, all-year-round. "Security awareness...

Management awareness paper on malware metrics

Image
Malware - mal icious soft ware - encompasses a variety of computer viruses, Trojans, network worms, bots and other nasties.   Malware has been the scourge of IT users ever since the Morris worm  infected the early Internet way back in 1988.  Despite the enormous global   investment over the intervening years in information security controls against malware (including security awareness!), it remains a significant security concern today.  Although antivirus software companies sometimes admit that they are fighting a losing battle, malware is generating so much income both for the VXers (malware authors) and their criminal masterminds, plus the antivirus software companies, that the arms race looks set to continue for the forseeable future.  Both sides are constantly investing in new tricks and techniques, fuelling a thriving black market in zero-day exploits and novel malware. Meanwhile, the rest of us are lumbered with paying for it in one way or another...

Management awareness paper on database security metrics

Image
The next  security awareness paper suggests to management a whole bunch of metrics that might be used to measure the security of the organization's database systems. Most information-packed application systems are built around databases, making database security a significant concern for the corporation.  We're talking about the crown jewels, the bet-the-farm databases containing customer, product and process information, emails, contracts, trade secrets, personal data and so much more.   Despite the importance of database security, we don't know of any organization systematically measuring it ... although we do know of many that struggle to keep on top of database security design, development, testing, patching, administration and maintenance! So how exactly are management supposed to manage database security without database security measures? Extra sensory perception, perhaps, or gut-feel? Either way, it's hardly what one might call scientific management!

New hi-tech risks awareness module

Image
In the 11 years that we’ve been providing the awareness service, it has grown substantially in both breadth and depth. We’ve covered risk management as a discrete topic a few times before, while information risk is the foundation for information security and hence virtually all the security awareness modules.  This month, however, the latest addition to our bulging portfolio of security awareness topics concerns the central yellow area of the scope diagram shown  here. A large proportion of information these days is communicated, processed and stored using IT systems and networks.  There are numerous risks associated with IT which are central to this awareness module.  However, it makes little sense to discuss IT or tech risks in isolation since it is the possible adverse consequences on the business that determine whether or not they are a genuine concern.  If there were no impacts, the risks to the organization would be negligible. “Hi-tech risks”, t...

Management awareness paper on IPR metrics

Image
When we get a spare moment over forthcoming months, we plan to release a series of awareness papers describing metrics for a wide variety of information security topics through the SecurityMetametrics website . The first paper , dating back to 2007, proposes a suite of information security management metrics relating specifically to the measurement of Intellectual Property Rights (IPR). Managing and ideally optimizing IPR-related controls (namely the activities needed to reduce the chances of being prosecuted by third parties for failing to comply with their copyright, patents, trademarks etc . plus those necessary to protect the organization's own IPR from abuse by others), requires management to monitor and measure them and so get a sense of the gap between present and required levels of control, apply corrective actions where necessary and improve performance going forward. These metrics papers were written for managers.  Their primary purpose is to raise awareness of the...