Posts

Showing posts with the label Accountability

Philosophical phriday: why have policies?

Image
An interesting topic cropped up on the ISO27k Forum this week. In essence, the issue is whether a small, immature company without an I nformation S ecurity M anagement S ystem could or should have an information security policy. ​ Speaking as an infosec pro, the knee-jerk response is "Yes, of course!". Why do I say that? If SmallCo's CEO or owner asked me to explain, how would I justify my recommendation to have a policy? Hmmm. Tag along or watch from the precipice as I dive into another rabbit warren.

Philosophical phriday: looking forward to 2025

Image
I'm not a fan of new year's resolutions that tend (in my experience) to have limited impact and are often soon forgotten. My cynical self says the same thing applies to pledges, vows and other stated commitments, even agreements and contracts to some extent. They are more symbolic than actual control mechanisms (although I'm sure the lawyers would argue otherwise - on the clock, naturally). The focus is often on avoiding, preventing or stopping bad things, a negative emphasis although the actual language may be positive as in "I will lose weight" and "I will get fit". They can be a last resort, a sharp retrospective reminder of where we thought we were going when we are already heading off-course.

Information risk management - a worked example [LONG]

Image
In the past few days, I have been triggered yet again by someone fearing that ISO/IEC 27001 certification auditors may insist that various Annex A controls are applicable and must therefore be implemented for conformity. Apocryphal nightmares about auditors doing exactly that tend to stoke the fear and prolong the myth. Myth, yes, myth. I've said it before and no doubt I'll say it again: the Annex A information security controls are not formally required for conformity with the standard - none of them, not even one. If you or your auditors believe otherwise, kindly tell us which clause of the standard applies. What are the exact words leading to that conclusion? Spoiler alert: there are none. There is no such requirement. IT DOES NOT EXIST. There is , however, a conformity requirement to check through Annex A for any controls that might reduce otherwise untreated information risks, but even then there is no (repeat, no ) obligation to implement the controls as stated in A...

Directors as kaumātua

Image
The Institute of Directors has just released their Code of Conduct for Directors , promoting six principles: Leading by example. Integrity. Transparency. Accountability. Fairness. Responsible business. So far, so good ... although somehow I feel there's something missing. But what?

Accreditation vs certification

Image
First, two definitions: " Certification " is the process of checking something against defined criteria, and if it passes (meets the criteria), issuing a certificate of compliance or conformity or assurance or whatever. Certification gives some assurance that the certified organisation or individual meets the criteria ... provided the certification body or person is competent and trustworthy, the checks were done properly, and the certificate itself is authentic. Hmmm, quite a few caveats there ... " Accreditation " is the process of confirming that whoever is checking and issuing certificates is properly qualified, competent and trusted to issue meaningful certificates by following prescribed processes. It adds credibility, meaning and value to the certification and issued certificates ... provided the accreditation body or person is competent and trustworthy, the checks were done properly, and the a...

mmmmmm, More Meaningful Management Metrics

Image
For about a week, I've enjoyed following and participating in an expansive discussion thread on LinkeDin about the value of measurement and metrics for management , debating various issues that can occur both in theory and in practice. One straw-man argument is that 'managing by the numbers' can imply a myopic focus on commonplace business metrics such as stock price or annual profit, both of which can be manipulated to some extent by managers even at the expense of long term resilience and commercial success, let alone other business objectives. Despite Taylor's outmoded 'scientific management' experiments having been debunked a century ago, some LinkeDinners in the thread evidently still believe that science (in the form of numeric data) and management are poles apart.  I beg to differ. That's so last century! Management is complex, dynamic and nuanced, hence I accept that simplistic or crude metrics can't possibly address the entire practice. For exam...

Information risks a-gurgling

Image
There are clearly substantial information risks associated with the redaction of sensitive elements from disclosed reports and other formats, risks that the controls don't necessarily fully mitigate. Yes, controls are fallible and constrained, leaving residual risks. This is hardly Earth-shattering news to any competent professional or enlightened infidel, and yet others are frequently shocked.  A new report* from a research team at the University of Illinois specifically concerns failures in the redaction processes and tools applied to  PDF documents . The physical size of redacted text denoted (covered or replaced) with a variable-length black rectangle may give clues as to the original content, while historically a disappointing number of redaction attempts have failed to prevent the original information being recovered simply by removing the cover images or selecting then pasting the underlying text. Doh!

Putting policies under pressure

Image
A note on LinkeDin led me to an intriguing scientific research study that tested the following five hypotheses: People who receive instructions via a written policy about rules will have better knowledge of these rules than those that do not.  People who receive a shorter form version of policy about the rules with less text will have better knowledge of the rules than those who receive a longer training form.  People who receive a written policy outlining the rules in a more vernacular and less legal technical language will have better knowledge of the rules than those presented with a more formal-legal-styled training text.  People with better knowledge of rules will also comply more with such rules. The more legal rules align with people’s personal and social norms, the higher people score in their knowledge of these legal rules.  

Guiding the helmsman

Image
Every so often, I find myself working with clients that "get it" - not just the individual people I'm collaborating with, nor even their functions/departments: I'm talking about entire organisations with a cadre of supportive and enthusiastic managers who understand and appreciate the genuine business value of sound information risk management. It's a real pleasure for me, a welcome relief from the usual slog.

Accountability is ...

Image
  ... "i n contrast to responsibility , a sticky property that cannot be unilaterally delegated or passed by the accountable person or organisation to another, in other words the buck stops here " [source:  SecAware glossary ]   ... l ess ambiguous and yet, strangely, more confusing than other terms in this blog series ... being able to give a satisfactory reason or justification ... distinct from, but often conflated with,  responsibility ... an inherent part of various jobs, roles or positions ... knowing that things must be done properly ... easily forgotten until an incident occurs ... both a threat and an opportunity ... the latitude to decide and act ... a token of respect and trust ... a governance arrangement ... a degree of independence ... beyond mere expectation ... having to explain oneself ... imposed by an authority ... a powerful disincentive ... invariably bad news ... the sting in the tail ... a niggling concern ... power, moderated ... having guard...

Ten tips on tackling a thorny infosec issue

Image
A member approached the  ISO27k Forum   this morning for advice: " What would you recommend to do if our warnings as ISMS department specialists/auditors are not taken into account?" What can realistically be done if  management isn't paying sufficient attention to information risks that we believe are significant ?  This is a thorny issue and not an uncommon challenge, particularly among relatively inexperienced or naïve but eager information risk and security professionals, fresh out of college and still studying hard for their credentials. It can also afflict the greybeards among us: our passion for knocking down information risks can overtake our abilities to convince managers and clients. Here are ten possible responses to consider: 

The discomfort zone

Image
Compliance is a concern that pops up repeatedly on the ISO27k Forum , just this  morning for instance. Intrigued by ISO 27001 Annex A control A.18.1.1 "Identification of applicable legislation and contractual requirements", members generally ask what laws are relevant to the ISMS.  That's a tough one to answer for two reasons.   Firstly, I'm not a lawyer so I am unqualified and unable to offer legal advice. To be honest, I'm barely familiar with the laws and regs in the UK/EU and NZ, having lived and worked here for long enough to absorb a little knowledge. The best I can offer is a layman's perspective. I feel more confident about the underlying generic principles of risk, compliance, conformity, obligations, accountabilities, assurance and controls though, and have the breadth of work and life experience to appreciate the next point ... Secondly, there is a huge range of laws and regs that have some relevance to information risk, security, management and t...

Professional services infosec policy template

Image
  We have just completed and released a brand new information security policy template on professional services. The policy is generic, pragmatic and yet succinct at just over 2 pages. Professional services engagements, and hence the associated information risks, are so diverse that it made no sense to specify particular infosec controls, except a few examples. Instead, the policy requires management to nominate Information Owners for each professional services engagement, and they, in turn, are required to identify, evaluate and treat the information risks. This is another shining example of the value of the 'information ownership' concept. Although they are encouraged to delegate responsibilities to, or at least take advice from, relevant, competent experts (e.g. in Information Risk and Security, Legal/Compliance, HR, IT, Procurement), Information Owners are held personally accountable for the protection and legitimate exploitation of 'their' information. If Informati...

Professional services - preliminaries

Image
Yesterday I proposed a guideline on the information risk, security and privacy aspects of professional services . I introduced a simplistic 3-phase model for the business relationship through which one or more professional services assignments are delivered and consumed.  Today, I'm exploring the preliminary phase. Before professional services are delivered, client and provider form a business relationship. They determine the professional services required and offered, and of course negotiate the commercial arrangements. They also have the opportunity to decide how the services are to be provided, and how both the assignment/s and the business relationship are to be managed. Contracting is an important control in its own right with significant information and commercial risks associated. The contract may for instance: Be inappropriate for either organisation, the relationship and/or the professional service/s;  Be informal, undocumented, invalid and hence unenforceable; Bypass...

KISS or optimise your ISO27k ISMS?

Image
From time to time as we chat about scoping and designing I nformation S ecurity M anagement S ystem s on the ISO27k Forum , someone naively suggests that we should K eep I t S imple S tupid . After all, an ISO27k ISMS is, essentially, simply a way of managing information security, isn't it? At face value, then, KISS makes sense. In practice, however, factors that complicate matters for organizations designing, implementing and using their ISMSs include different: Business contexts – different organization sizes, structures, maturities, resources, experiences, resilience, adaptability, industries etc. ; Types and significances of risks – different threats, vulnerabilities and impacts, different potential incidents of concern; Understandings of ‘information’, ‘risk’ and ‘management’ etc . – different goals/objectives, constraints and opportunities, even within a given organization/management team (and sometimes even within someone’s head!); P...

IAAC Directors' Guides

Image
Some time back I bumped into a handy management guide on information risk - a double-sided leaflet from the I nformation A ssurance A dvisory C ouncil. In 2015, it inspired a security awareness briefing explaining that colourful process diagram, which has now morphed into a further 5-page briefing on  I nformation R isk M anagement, soon to join the  SecAware ISMS templates . Googling for the IAAC guide led me to a cluster of FREE Directors' Guides from the IAAC offering useful, relevant guidance for senior management: Why Information Risk is a Board Level Issue - is a backgrounder including this apt and succinct explanation: "Information Risk encompasses all the challenges that result from an organisation’s need to control and protect its information." Governance and Structures - describes directors' governance responsibilities relating to information risk: "Directors need to put in place the arrangements and processes by which responsibilities are distribute...

Google customers phishing

Image
We're seeing a steady stream of 'update your email'-type crude phishers along these lines: I have lightly redacted the URL, but those action buttons are clearly not  pointing to an IsecT domain.   Firebase Storage is a Google cloud storage/app service: Google promotes Firebase security in terms of high availability and authentication for their customers i.e. web developers using Firebase to host content on the web. No mention of security for their customers' victims though and although Google can't be held entirely responsible for its customers' nefarious activities, I presume (hope!) they have the processes in place to identify and respond efficiently to incidents of this nature. I've reported this incident through a Firebase customer support channel as there is no obvious way for us to report misuse of their services by phishers etc. I'll let you know how they respond. PS  They didn't.  Harrumph.

Musing on ISO/IEC 27014 and infosec governance

Image
This morning I've been studying the final draft of the forthcoming second edition of ISO/IEC 27014 "Governance of information security" , partly to update ISO27001security.com but mostly out of my fascination with the topic. Section 8.2.5 of the standard specifies the governance objective to "Foster a security-positive culture": "Governance of information security should be built upon entity culture, including the evolving needs of all the interested parties, since human behaviour is one of the fundamental elements to support the appropriate level of information security. If not adequately coordinated, the objectives, roles, responsibilities and resources can conflict with each other, resulting in the failure to meet any objectives. Therefore, harmonisation and concerted orientation between the various interested parties is very important.  To establish a positive information security culture, top management should require, promote and support coordination...

What is "operational resilience"?

Image
Seeing the term 'operational resilience' being bandied about right now, I thought I'd take a closer look, starting with the definitions. So what is 'operational resilience'?   It is: " a set of techniques that allow people, processes and informational systems to adapt to changing patterns. It is the ability to alter operations in the face of changing business conditions. Operationally resilient enterprises have the organizational competencies to ramp up or slow down operations in a way that provides a competitive edge and enables quick and local process modification." says Gartner . " both a process and a characteristic of an organization to adapt rapidly to changing environments and needs. It is an organizational trait that allows it to carry out its mission or business despite the presence of operational stress and disruption. In other words, it is the organization's ability to handle and control external factors that may hinder it from function...