Posts

Showing posts with the label Development

Innovative approaches to ISO/IEC 27001 implementation

Image
This week I've read an interesting, inspiring piece by Robin Long exploring the costs, benefits, approaches and strategic options for implementing ISO27k.   I like Robin's idea of trying things out and banking some 'security wins' before committing to a full implementation. A full-scope ISMS is a major commitment requiring strong understanding and support from management, requiring a high degree of trust in the team and CISO/ISM/project leader as well as the [planned] ISMS. Demonstrating and celebrating security wins is a good way to build trust and sustain it, once the ISMS is running. I'm also intrigued by the possibilities of unconventional, creative, less boring approaches to implementation project planning - for example, instead of plodding sequentially through ISO/IEC 27001, clause-by-clause, think about:

Security control categories and attributes

Image
On LinkeDin this morning, Morten Ingvard asked: "As part of updating and reshaping some parts of our information security management system (ISMS), I'm not convinced that the new categorization of controls in ISO/IEC 27002:2022 (Organizational, people, physical and technical), is the best suit for our organization to rationally identify relevant controls for their work. I understand there is an increased focus on the use of attribution - so controls can be selected based on different perspectives, but I want to have a "default view" that the organization can read and understand, and currently, I'm strongly considering sticking with a categorization structure looking more like the older 2013-version in ISO/IEC 27001." Here's my response to Morten: "The categories are primarily a convenient way to sequence the controls in the standard. It was the 'default view' selected by ISO/IEC JTC1/SC27.

2 more topic-specific information security policies

Image
We have just completed and released another two information security policy templates through SecAware.com . The latest additions are security policy templates on: APIs ( A pplication P rogramming I nterfaces) and microservices , used as building blocks to construct compound applications; DNS ( D omain N ame S ervice) , used to associate domain names with Internet server IP addresses. The full SecAware policy suite now has 83 templates: They were all researched and written to a consistently high quality, by me. They are designed to mesh together, complementing each other. I maintain them, updating individual policies as and when required and reviewing the entire suite every year or so.  We provide them as MS Word documents that you can easily customise.  Get in touch for additional policies, procedures or guidelines, or if you need assistance to adapt them to your corporate style.  Buy them individually for $20 or take the whole lot for $399, saving over $1200.

Security awareness month

Image
Since October is cybersecurity awareness month in the USA, we've seized the opportunity to update SecAware.com with additional information on our security awareness material.  SecAware's information security awareness modules explore a deliberately wide variety of individual topics in some depth:

Security in software development

Image
Prompted by some valuable customer feedback earlier this week, I've been thinking about how best to update the SecAware policy template on software/systems development. The customer is apparently seeking guidance on integrating infosec into the development process, which begs the question "Which development process?". These days, we're spoilt for choice with quite a variety of methods and approaches.  Reducing the problem to its fundamentals, there is a desire to end up with software/systems that are 'adequately secure', meaning no unacceptable information risks remain. That implies having systematically identified and evaluated the information risks at some earlier point, and treated them appropriately - but how? The traditional waterfall development method works sequentially from business analysis and requirements definition, through design and development, to testing and release - often many months later. Systems security ought to be an integral part of th...

Standards development - a tough, risky business

Image
News emerged during June of likely further delays to the publication of the third edition of ISO/IEC 27001 , this time due to the need to re-align the main body clauses with ISO's revised management systems template (specfically, the 2022 edition of the ISO/IEC Directives, Part 1 "Consolidated ISO Supplement —  Procedure for the technical work — Procedures specific to ISO",  Annex SL "Harmonized approach for management system standards").    Although we already have considerable discretion over which information security controls are being managed within our ISO/IEC 27001 I nformation S ecurity M anagement S ystems today, an unfortunate side-effect of standardisation, harmonisation, adoption, accreditation and certification is substantial inertia in the system as a whole. It’s a significant issue for our field where the threats, vulnerabilities, impacts and controls are constantly shifting and often moving rapidly ahead of us … but to be honest it’s equally pro...

Standardising ISMS data/application program interfaces

Image
We've been chatting on the ISO27k Forum  lately about using various IT systems to support ISO27k ISMSs. This morning, in response to someone saying that a particular tool which had been recommended did not work for them, Simon Day made the point that " Each organisation trying to implement an ISMS will find it’s own way based on their requirements. " Having surveyed the market for ISMS products recently, I followed-up with my usual blurb about organisations having different information risks and business situations, hence their requirements in this area are bound to differ, and in fact vary dynamically (in part because organisations mature as they gain experience with their ISMS: their needs change). The need for flexibility is why the ISO27k standards are so vague (essentially: figure out your own requirements by identifying and evaluating your information risks using the defined governance structure - the ISMS itself), rather than explicitly demanding particular securit...

Adjusting to the new normal

Image
According to alert AA20-133A from US-CERT : "The U.S. Government has reported that the following vulnerabilities are being routinely exploited by sophisticated foreign cyber actors in 2020: Malicious cyber actors are increasingly targeting unpatched Virtual Private Network vulnerabilities. An arbitrary code execution vulnerability in Citrix VPN appliances, known as CVE-2019-19781, has been detected in exploits in the wild. An arbitrary file reading vulnerability in Pulse Secure VPN servers, known as CVE-2019-11510, continues to be an attractive target for malicious actors. March 2020 brought an abrupt shift to work-from-home that necessitated, for many organizations, rapid deployment of cloud collaboration services, such as Microsoft Office 365 (O365). Malicious cyber actors are targeting organizations whose hasty deployment of Microsoft O365 may have led to oversights in security configurations and vulnerable to attack. ...

Break-in news

Image
Kaspersky has released information on Operation ShadowHammer , a malware/APT infection targeting ASUS systems with particular MAC addresses on their network adapters. According to a Motherboard report : "The issue highlights the growing threat from so-called supply-chain attacks, where malicious software or components get installed on systems as they’re manufactured or assembled, or afterward via trusted vendor channels. Last year the US launched a supply chain task force to examine the issue after a number of supply-chain attacks were uncovered in recent years. Although most attention on supply-chain attacks focuses on the potential for malicious implants to be added to hardware or software during manufacturing, vendor software updates are an ideal way for attackers to deliver malware to systems after they’re sold, because customers trust vendor updates, especially if they’re signed with a vendor’s legitimate digital certificate." And that, in a nutshell, is a concern with, ...

Computer errors

Image
Whereas "computer error" implies that the computer has made a mistake, that is hardly ever true. In reality, almost always it is us - the humans - who are mistaken: Flaws are fundamental mistakes in the specification and design of systems such as 'the Internet' (a massive, distributed information system with seemingly no end of security and other flaws!). The specifiers and  architects are in the frame, plus the people who hired them, directed them and accepted their work. Systems that are not sufficiently resilient for their intended purposes are an example of this: the issue is not that the computers fail to perform, but that they were designed to fail due to mistakes in the requirements specification; Bugs are coding mistakes  e.g. the  Pentium FDIV bug  affecting firmware deep within the chip. Fingers point towards the software developers but again various others are implicated;  Config and management errors are mistakes in the configuration and management ...

What is the best development method for security?

Image
In answer to someone on CISSPforum asking for advice about the impact of various software development lifecycles, methods or (as if we need another ology) methodologies, I asserted that the SDLC method affects the way or the manner in which infosec is achieved (spec'd, built, confirmed, delivered, used, managed, monitored, maintained ...) more than how effective it ends up being. There are pros and cons to all the methods - different strengths and weaknesses, different purposes, opportunities, risks and constraints. Software or systems development involves a load of trade-off and compromises. For example, if information risks absolutely must be minimized, formal methods are a good way to achieve that ... at huge cost in terms of both the investment of money and time for the development, and the functionality and rigidity of the developed system. However, an even better way to minimize the risk is to avoid using software, sidestepping the whole issue! In most circumstances, I would ...

Taking a poke at ADDIE

Image
ADDIE is an acronym from the I nstructional S ystems D esign field, standing for: A nalysis - examine the situation, determine the learning objectives; D esign - design an approach to satisfy the learning objectives; D evelopment - prepare the course materials etc. ; I mplementation - deliver the course or whatever (some form of training or awareness or learning opportunity); E valuation - figure out how well it's going in terms of meeting the objectives. ADDIE was published back in the 1970's.  At first glance, it looks like a useful framework ... but look again. Isn't that just the core of the classic waterfall structured project management method? If so, consider this: what's missing?  As commonly represented, it's an open-ended linear process, whereas in fact it should be iterative. In particular, the E valuation activity generates metrics, information that can and should be used to guide the next round of awareness and training. It feeds into future A nalysis ...

Safe & secure

Image
The Coming Software Apocalypse is a long, well-written article about the growing difficulties of coding extremely complex modern software systems. With something in the order of 30 to 100 million lines of program code controlling fly-by-wire planes and cars, these are way too large and complicated for even gifted programmers to master single-handedly, while inadequate specifications, resource constraints, tight/unrealistic delivery deadlines, laziness/corner-cutting, bloat, cloud, teamwork, compliance assessments plus airtight change controls, and integrated development environments can make matters worse.  Author James Somers spins the article around a central point. The coding part of software development is a tough intellectual challenge: programmers write programs telling computers to do stuff, leaving them divorced from the stuff - the business end of their efforts - by several intervening, dynamic and interactive layers of complexity.  Since there's only so much they ca...

Workplace infosec policies

Image
Protecting information in the workplace is such a broad brief that we're working on 4 policy templates for the July awareness module: Workplace information security policy - concerns the need to identify and address information risks wherever work is performed, and wherever valuable information exists (not just at the office!).   This is an update to our 'office security policy'. Information retention policy - the timescales for retention and/or the criteria for disposal, of information should be specified when it is classified, along with the security requirements for safe storage, communications and access. Information disposal policy - when information is no longer required, it may need to be disposed of securely using forensically sound techniques. Information classification policy - updated to reflect the need to specify retention and destruction requirements where applicable ( e.g. if mandated in laws, regulations or contracts). Several other information security pol...

The periodic table of atomic controls [updated]

Image
Many information security controls are multi-purpose, hence they could be specified in several places, several policies plus procedures and standards and guidelines etc . That multiplicity creates a nightmare for the ISO/IEC JTC 1/SC 27 project team trying to generate a succinct version of ISO/IEC 27002 without duplications, gaps or discrepancies in the control catalog. It’s also a potential nightmare for anyone writing corporate policies, or an opportunity depending on how you deal with it.  My current pragmatic approach is to mention [hopefully] all the important controls in each topic-specific policy template, with a reference section that mentions other related policies, creating a kind of policy matrix. I’m still wary of gaps and discrepancies though: with 60+ policies in our matrix so far, it’s fast approaching the limit of my intellectual abilities and memory to keep them all aligned! It’s an ongoing task to review and revise/update the policy templates, without breaking li...

Nothing small about business

Image
As a small business, we have to do and manage much the same stuff that any business has to do, such as: Marketing, promoting and selling our products e.g. maintaining and updating our websites, preparing advertising copy etc. Procurement and sales administration - licensing, invoicing etc. Customer and supplier relations Financial administration: budgeting, accounting, tax, expenses, pay & rations HR & personal development IT - hardware, software, firmware, wetware and - yes - IoT Information risk and security, including awareness (golly!) Strategy, governance, compliance  Planning, resource allocation, priorization Market and competitor analysis Research and development Operations/production - working hard to make the products we sell Quality assurance and quality control Packaging, delivery and logistics Elf'n-safety Blogging and other social marketing/social media stuff In our case these are on a smaller, simpler scale compared to, say, a multinational megacorporati...

Weaving the Web

Image
One of the pleasures of my job is continual learning, doing my best to keep up with the field. I read loads, mostly on the Web but I also maintain a physical bookshelf well-stocked with books ... including: Sir Tim Berners-Lee recounts the original design and development of the World Wide Web in the 1980s and 90s . This is more than merely an authoritative historical account, however valuable that may be. Tim elaborates on his big dreams and deep personal philosophy that drove him to conceive and gift to humanity the most powerful information technology invented - so far.  62 years ago when Tim was born (happy birthday!), ENIAC was in the final few months of its life and the 5,000-tube UNIVAC was just 2 years into commercial production. Computers were monstrous beasts with (by today's standards) minimal processing, storage and communications capabilities, yet ironically they were known as 'electronic brains'. Networking was virtually nonexistent, and email wasn't even i...