Posts

Showing posts with the label Awareness

Philosophical phriday: why have policies?

Image
An interesting topic cropped up on the ISO27k Forum this week. In essence, the issue is whether a small, immature company without an I nformation S ecurity M anagement S ystem could or should have an information security policy. ​ Speaking as an infosec pro, the knee-jerk response is "Yes, of course!". Why do I say that? If SmallCo's CEO or owner asked me to explain, how would I justify my recommendation to have a policy? Hmmm. Tag along or watch from the precipice as I dive into another rabbit warren.

Insider risks

Image
There are information risks associated with people joining any corporate function – information risks that deserve to be identified, assessed, evaluated and treated appropriately like any other. If your organisation currently pays little if any attention to these risks, how about developing and trialling a suitable strategy and approach for, say, the information risk and security management function, as a pilot or demonstrator for other corporate functions and rôles that place a high reliance on the personal integrity of their people?

Mandatory vs discretionary ISMS documentation

Image
Whereas ISO/IEC 27001 indicates that only fourteen (14) types of ISMS documentation are strictly required  (mandatory), they are barely a start, even for a barebones ISMS.  In practice,  both mandatory and  discretionary documents are valuable . ISO/IEC 27001 c lause 4.4   states: “The organization shall establish, implement, maintain and continually improve an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document.” Documentation (termed 'documented information' in the standard - see clause 7.5) is generally the best way for management to inform workers about their information security responsibilities  e.g. through written policies, procedures/work instructions and job/role descriptions, accompanied by awareness and training materials such as guidelines and briefings. In addition, many security-related processes generate 'records' such as completed forms, ...

Philosophical phriday - AI-enhanced ISO27k creativity

Image
Denis Yakimov ​shared this on LinkeDin: " Imagine your ISMS as a battlefield: Context : The battlefield terrain—topography, weather, and conditions. Issues : Your main enemies. ​Controls and SoA : Troops, tools, and fortifications. Each control is a soldier with a specific purpose. ​Leadership : The chain of command, setting the battle’s tone and ensuring everyone understands their role. ​ Planning : The war strategy how to deploy soldiers (controls) to address issues under current conditions. ​Operation : Execution of the battle plan where soldiers confront issues directly. ​ Internal Audit : A field hospital that identifies wounded soldiers and offers opportunities to remediate them. Improvement : Lessons learned applied to strengthen future engagements.” ​Google Gemini made a reasonable if naive attempt to draw a military analogy for me too: ​ " Imagine a military base: ​ The Base : Represents the organization and its information assets. ​ The General : Top management, se...

Philosophical phriday - why take the risk? [LONG]

Image
If, as many security professionals evidently believe, risk concerns the possibility of harm, then surely we ought to do everything possible to reduce the possibility and/or the harm caused, by strengthening and extending security or ideally avoiding it completely by simply not doing risky things - right? OK, so then why do we take risks at all ? Why do we need security to mitigate bad stuff? Security is costly and fallible, so can't we save money by totally avoiding or eliminating risk? Errrrrmmm  ... since it's philosophical phriday, this is an opportunity to explore the issue further, taking a deep dive. But, before I blabber on, dear reader, please take a moment to ponder this for yourself.  No, take several. Take as long as you can. Take the rest of the day off: it's phriday after all. Why do we take risks?  Seriously, why ?   What does it mean to 'take risk'? Grab a pencil or mouse. Jot something down. Think again.  Ponder on. Keep listing, scribbling,...

Philosophical phriday - cybersecurity awareness month

Image
We should congratulate and support colleagues around the world who have conceived, organised and promoted creative events for October's cybersecurity awareness month. Seriously, well done all of you. Thank you for your energy and efforts. Thank you for caring. Thank you for doing your bits. Thank you for taking time out of whatever else you were doing, perhaps even allocating some of your budget towards this. I am being 100% genuine here: this is not a sarcastic piece. I am truly grateful.

Philosophical phriday - a little hype for the weekend

Image
Advertising copy, marketing reports, social media pieces and news articles in general warn us that things are getting worse. Pretty much everything is getting worse, and of course that's bad. See if you recognise any of these choice phrases: In today's [*] world : a classic throwaway AI/MML introductory phrase, presumably emphasising that the present is different to the past, the future dramatically so. With just a short browse through my LinkeDin feed, I've seen the following fill-ins for that asterisk: 'unpredictable', 'complex and uncertain', 'complex business', 'hectic', 'fast-evolving' (paradoxically), 'fast-paced', 'digital', 'fast-paced digital', 'fast-paced hyper-connected', 'fast-paced tech', 'fast-paced data-driven', 'tech-driven', 'mobile-first', 'B2B', 'globalized' (yes, really) blah blah blah. Despite there being 87 synonyms , the robots are c...

NIST RMF vs Adaptive SME Security

Image
NIST has just released SP 1314 Risk Management Framework (RMF) Small Enterprise Quick Start Guide  as a lightweight form/introduction to the full RMF. ... and, despite having said the steps are not necessarily sequential ... It's interesting to compare and contrast the NIST RMF against the  Adaptive SME Security  approach we released just last week: 

Adaptive SME security Crowdstrike special

Image
As if on cue, along comes a golden opportunity to consider what the Adaptive SME security  approach has to say regarding the Crowdstrike incident: That's not 20/20 hindsight but foresight: I've picked out the most relevant rows from the security controls table published in the guide 24 hours before the incident.  Although Crowdstrike primarily supplies much larger enterprises than SMEs, the incident could equally have afflicted other security software, or indeed operating systems such as Windows and assorted cloud apps commonly used by SMEs. Regardless of the details, it is a wake-up call, an opportunity to consider and respond to the information risks ... and to adapt , accordingly.

An evolutionary revolution?

Image
"Mitigation and adaptation are required together to reduce the risks and impacts of climate change, including extreme weather events. Mitigation refers to actions taken to limit the amount of greenhouse gas emissions, reducing the amount of future climate change. Adaptation refers to actions taken to limit the impacts of a changing climate. Mitigation and adaptation together provide co-benefits for other environmental and social goals." That paragraph by Lizzie Fuller, Climate Science Communicator for the UK's Met Office, plucked from another excellent digest of lessons learned from various UK resilience exercises and initiatives , obviously con cerns climate change ... but it occurs to me that 'mitigate and adapt' might be a novel approach to information risks and impacts as well.

A nightmare on DR street

Image
A provocative piece on LinkeDin by Brian Matsinger caught my beady eye and sparked my fertile imagination today. I'm presently busy amplifying the disaster recovery advice in NIS 2 for a client. When I say 'amplifying', I mean generating an entire awareness and training piece on the back of a single mention of 'disaster recovery' in all of NIS 2. Just the one. Blink and you'll miss it. Oh boy. Anyway, Brian points out that recovering from disasters caused by 'cyber attacks' requires a different DR approach than is usual for physical disasters such as storms, fires and floods. Traditional basic DR plans are pretty straightforward: essentially, the plans tell us to grab recent backups and pristine systems, restore the backups onto said systems, do a cursory check then release services to users. Job's a good 'un, off to the pub lads.

Mil-spec management lessons

Image
  "A calamity can often strike without warning. Whether it be generated by humans or a natural disaster, leaders need to be ready to direct their teams in the aftermath. In order to be ready for crisis, leadership skills, like any others, must be practised over and over beforehand. So the way you lead in the quiet times helps to build the skills you need when you have to dig deep." That paragraph plucked from this month's impressive  NZ Airforce newsletter  about the military response to the devastating flooding caused by cyclone Gabrielle here in Hawkes Bay caught my beady eye this morning.  The idea of practicing incident management as well as incident handling or operations  on relatively small incidents makes perfect sense.

Checklust security

Image
" Seventy Questions to Assess Cybersecurity Risk on a Rapidly Changing Threat Landscape "  is an ISACA 'industry news' article by Patrick Barnett.  Whereas normally I give 'industry news' and checklists a wide berth, Patrick is (according to the article) highly qualified and experienced in the field, so I took  a closer look at this one. The prospect of condensing such a broad topic to a series of questions intrigued me. I'm not totally immune to the gleaming allure of well-conceived checklists. Patrick says: "There are 70 questions that can be asked to determine whether an enterprise has most defensive principles covered and has taken steps to reduce risk (and entropy) associated with cybersecurity. If you can answer “Yes” to the following 70 questions, then you have significantly reduced your cybersecurity risk. Even so, risk still exists, and entropy must be continuously monitored and mitigated. There is no specific number of layers that can remove...

Hyperglossary published!

Image
Having declared it officially 'done', the SecAware information security hyperglossary is finally self-published as an eBook in PDF format. More than three thousand terms-of-art are defined in the areas of: Information risk  Information security  Cybersecurity (IT/Internet security) ICS/SCADA/OT security Artificial Intelligence Privacy, data protection, personal information Governance Conformity and compliance Incidents  Business continuity and more.  It has taken me three decades so far to compile the glossary, initially just as a reference for my personal use, then for our security awareness clients, and now for anyone with a little cash to spare and an interest in the field.

Hyper-glossary nearing completion (?)

Image
My next book will be a 'hyper-glossary' of terms relating to information security, including closely related aspects such as information risk management, governance, compliance ... and more ... and there's the rub: I'm struggling to catch up/keep up with developments in the field, not least because of the rate at which novel concepts are introduced and new terms are coined. Here's an example of a definition originally added a couple of years ago and most recently amended today: There I've defined "Deep fake", one of several terms washed up in the AI tsunami. The underlined terms are hyperlinked to their definitions ... and so on forming an extensive web within the document.

Pro services under attack

Image
Among all the other bad news in the excellent Cy-Xplorer 2023 report from Orange Cyberdefense , this nugget of threat intelligence poked me in the eye: I've become increasingly concerned about the information risks relating to professional services in recent years. They seem obvious targets for malicious cyber attacks, given:

A pragmatic alternative to the SuperCISO [L O N G]

Image
Yet again this morning, something on the ISO27k Forum caught my imagination, firing-up my sleepy caffeine-deprived neurons.  We have been chatting lately about what is expected of the C hief I nformation S ecurity O fficer role - namely an exceptional mixture of knowledge, skills and competences possessed by  the 'SuperCISO'.  Today, Nigel Landman referred us to an interesting article by JC Gaillard at Medium.com .    JC's repeated assertions that 'cybersecurity is not purely technical' caught my beady eye: the 'cyber' bit clearly suggests that it  is  100% purely tech ... but those of us who have swallowed the ISO27k pill recognise that  information  security requires more than just securing the bits-n-bytes. This is yet another example of the confusing use of language - specifically 'cyber'. Many professionals immersed in the field take 'cyber ' implicitly to include technology  plus  other aspects but the general perceptio...

eWaste safety hazards and information risks

Image
A warning in the New Zealand Information Security Manual  caught my beady eye yesterday: “Electrical and electronic equipment contains a complex mix of materials, components and substances, many which can be poisonous, carcinogenic or toxic in particulate or dust form. Destruction and disposal of WEEE [Waste from Electrical and Electronic Equipment] needs to be managed carefully to avoid the potential of serious health risk or environmental hazard.” Disposing of eWaste presents environmental and safety hazards arising from noxious/toxic/carcinogenic chemicals such as gallium arsenide (GaAs) and polychlorinated biphenyls (PCBs), plus the obvious dangers when handling sharp-edged metal or plastic chassis fragments, wires, printed circuit boards and CD/DVD discs plus  leaky electrolytic capacitors and old batteries . While there may be money to be made by extracting and recycling valuable metals  and reusable components ,  subsystems and modules , that's really a jo...

Hinson tip on ChatGPT

Image
When using ChatGPT and its ilk, d on't forget that the AI robot's contribution  is generic and not necessarily smart, accurate, sufficient or appropriate, despite the beguiling use of language that makes it  appear  logical, credible and reasonable at face value ... but is it, really? Or is it short on integrity? When, for instance, a real-world client reads a human expert advisor's report or consultant's recommendation, they are generally: Thinking critically about it, c onsidering what is and what is not stated and how it is expressed; Posing additional questions for clarity ( e.g. "On what basis do you believe we can achieve all that in 8 months, given that there's only one of me and I'm stretched thin as steam-rollered chewing gum?") or credibility ("How long did your last client take for this?") and perhaps a rguing the toss ("8 months? You're kidding, right? We only have 4!"); Taking advantage of knowledge and experience w...

To what extent do you trust the robots?

Image
This Sunday morning, fueled by two strong coffees, I'm cogitating on the issue of workers thoughtlessly disclosing all manner of sensitive personal or proprietary information in their queries to AI/ML/LLM systems and services run by third parties, such as ChatGPT. This is clearly topical given : (1) the deluge of publicity and chatter around ChatGPT right now, coupled with  (2) our natural human curiosity to explore new tech toys, plus  (3) limited appreciation of the associated information risks, and  (4) the rarity of controls such as policies and Data Leakage Protection technologies.  Furthermore, even if we do persuade our colleagues (and, let's be honest, ourselves!) to be more careful and circumspect about whatever we are typing or pasting into various online systems, the possibility remains that the general nature of our interests and queries is often sensitive.