Posts

Showing posts with the label IPR

Right to repair vs IPR

Image
This week I've been contemplating the right to repair movement, promoting the idea that c onsumers and third parties (such as repair shops) should not be legally denied the right to meddle with the stuff they have bought - to diagnose, repair and update it - without being forced to go back to the original manufacturer (a monopolistic constraint) or throw it away and buy a replacement (eco-unfriendly). Along similar lines, I am leaning towards the idea that products generally ought to be repairable and modifiable rather than disposable. That is, they should be designed with ‘repairability’ as a requirement, as well as safety, functionality, standards compliance, value, reliability and what have you. I appreciate that miniaturization, surface mounting, multi-layer PCBs, flow soldering and robotic parts placement make modern day electronic gizmos small and cheap as well as tough to repair, but obsolescence shouldn’t be built-in, deliberately, by default. Gizmos can still have test po...

End of an era

Image
Friends, Romans, customers, lend me your screens.  I come to bury NoticeBored, not to praise it. Sadly, the time has come to draw a lengthy chapter in our lives to a close. Our monthly  security awareness and training subscription service will cease to be early next year. As of April 2020,  it will be no more.  It will be pushing up the daisies.  We'll be nailing it to the perch and sending it off to the choir invisibule. Beautiful plumage though. The final straw and inspiration for the title of this piece was yet another exasperating phisher: ... and the realisation that suckers will inevitably fall for scams as ridiculous as that, no matter what we do. There will always be victims in this world. Some people are simply beyond help ... and so too, it seems, are organizations that evidently don't understand how much they need security awareness and training. "It's OK, we have technology" they say, or "Our IT people run a seminar once a year!" and sure en...

About information assets ... and liabilities

Image
Information security revolves around reducing unacceptable risks to information, in particular significant or serious risks which generally involve especially valuable, sensitive, critical, vital or irreplaceable information.   Those are the ‘information assets’ most worth identifying, risk-assessing and securing.   That seems straightforward but it is more complicated than it sounds for many reasons e.g. : Information exists in many forms, often simultaneously e.g. computer data and metadata (information about information), knowledge, paperwork, hardware designs, molds, recipes, concepts and ideas, strategies, policies, understandings and agreements, experience and expertise, working practices, contacts, software, data structures, intellectual property (whether legally registered and protected or not) … any of which may need to be secured; Information is generally dynamic, hence there is a timeliness aspect to its value ( e.g. breaking vs old ...

Awareness devices

Image
Today in a sudden flash of inspiration I invented a "device", a mechanism to raise awareness.  It's a graphical image, a metric, a simple visual device, an analytical or rhetorical tool to set people thinking about and discussing the topic - privacy in this case.  It explores their perceptions of the state of readiness of the organization to meet the May 25th GDPR deadline.  The specific thinkers and discussers I have in mind at this point are senior managers, executives or board members, with a significant interest in the organization's readiness for GDPR. They ought to know where things stand, and ought to have a reasonable grasp of the situation, but do they? The device is a way to find out. Generalizing from there, with minor changes the same device could be used to stimulate analysis and discussion on almost any deadline or situation where there are several non-exclusive options or possibilities on the table, and inherent uncertainties. That's most business d...

The business case for security awareness

Image
A day or so ago I wrote about organizations being pressured into security awareness for compliance reasons.  With some exceptions, compliance is externally imposed and doesn't directly benefit the organization through increased profits - rather it avoids or reduces the losses and costs (including penalties) associated with non compliance.  That is still a financial benefit but with negative, oppressive connotations.  Today I'm moving on to more positive, profitable matters, the business benefits arising from security awareness and training, of which there are several: Better recognition and identification of information risks More appreciation and understanding of information risks Fewer, less costly incidents Better governance Greater organizational and personal resilience Organizational learning and sustained improvement (maturity) A genuine, deep-rooted and all-encompassing corporate security culture Deterrence Getting the most out of other information security control...

Nothing small about business

Image
As a small business, we have to do and manage much the same stuff that any business has to do, such as: Marketing, promoting and selling our products e.g. maintaining and updating our websites, preparing advertising copy etc. Procurement and sales administration - licensing, invoicing etc. Customer and supplier relations Financial administration: budgeting, accounting, tax, expenses, pay & rations HR & personal development IT - hardware, software, firmware, wetware and - yes - IoT Information risk and security, including awareness (golly!) Strategy, governance, compliance  Planning, resource allocation, priorization Market and competitor analysis Research and development Operations/production - working hard to make the products we sell Quality assurance and quality control Packaging, delivery and logistics Elf'n-safety Blogging and other social marketing/social media stuff In our case these are on a smaller, simpler scale compared to, say, a multinational megacorporati...

Security innovators wanted

Image
Today while completing the final drafting, we further refined the scope and clarified the purpose of the awareness module. It has evolved in the course of production and ended up looking like this: Innovation has two distinct phases - theory and practice: First comes creativity and inventiveness, the spark of original thought that that might, at least theoretically, turn out to be practical and valuable enough to be worth exploiting; Next comes the effort required to develop and evaluate an idea, putting it into practice and so gaining the benefit. Having just called them distinct phases, they can overlap in the sense that the innovation process is iterative: when first imagined, ideas tend to be indistinct and incomplete. The documentation and evaluation activities lead to the idea being gradually clarified and refined, while the practicalities of implementation often involve revisiting the design, and further brainstorming.  In fact, both phases of innovation are creative. As I g...

Coats off

Image
A blog mentioning patent trolls reminded me that inventions may be patented, opening up several innovation-related information risks and opportunities. Hmmm, that's something else to bring up in the management stream this month - intellectual property rights protecting creative expression and innovation. Meanwhile, there are sheep to shear and fences to mend. So long as the rain holds off, it's a good weekend for 'outside jobs' ...

28 days of awareness: day 22

Image
While working on next month's module, we're also thinking forward to those that will follow. As soon as the ransomware module is delivered, we'll need to come up with poster ideas for a brand new module on 'innovation and creativity' - an unusual topic for a security awareness program for sure. We've been quietly researching the topic for months, in parallel with the ongoing work. Over the next week or two we need to review the information already gathered and firm-up the scope and purpose of the new module, clarifying the learning objectives and key messages that we'll be putting across. The fundamental premise we originally had in mind was to encourage the legitimate exploitation of the organization's intellectual property and other information assets, while at the same time protecting them from various risks including (in part) theft and exploitation by others. Instead, or perhaps as well, we might delve into the controls and tools supporting informat...

Internet security awareness

Image
We've just delivered our first awareness module for 2017 with a few brief hours left until the new year.   Updating the awareness module on Internet security turned out to be a mammoth task: we've basically rewritten it from scratch, such is the pace of change in this area. We could probably have continued writing for another month, in which time I'm quite sure further issues would have emerged ... so we had to call a halt to the writing in order to hit our self-imposed delivery deadline. We can always come back later for another bite at the cherry and, to be fair, most security awareness topics touch on the Internet in some fashion. "Fake news" is a recurring theme in the materials, picking up on media reports following the US presidential election. Today, we completed the final piece for the module, the awareness newsletter, drawing on a US CERT - DHS - FBI alert about GRIZZLY STEPPE  published yesterday. Two Russian hacking groups used Remote Access Trojans to ...

A little something for the weekend, sir?

Image
The following bullet-points were inspired by another stimulating thread on the ISO27k Forum , this one stemming from a discussion about whether or not people qualify as "information assets", hence ought to be included in the information asset inventory and information risk management activities of an ISO27k ISMS. It's a crude list of people-related information risks: Phishing, spear-phishing and whaling, and other social engineering attacks targeting trusted and privileged insiders; ‘Insider threats’ of all sorts – bad apples on the payroll or at least on the premises, people who exploit information gained at work, and other opportunities, for personal or other reasons to the detriment of the organization; ‘Victims’ – workers who are weak, withdrawn and easily (mis)lead or coerced and exploited by other workers or outsiders; Reliance on and loss of key people (especially “knowledge workers”, creatives and lynch-pins such as founders and execs) through various causes (resi...

CIS Critical Security Controls [LONG]

Image
Today I've been nosing through the latest 6.1 version of the CIS Critical Security Controls for Effective Cyber Defense , described as  "a concise, prioritized set of cyber practices created to stop today’s most pervasive and dangerous cyber attacks". In reality, far from being concise, it is a long shopping list of mostly IT/technical security controls, about 100 pages of them, loosely arranged under 20 headings. There are literally  hundreds of controls, way more than the '20 critical controls' mentioned although obviously 'Implement the 20 critical controls' sounds a lot more feasible than 'Implement  hundreds of tech controls, some of which we believe are critical for cyber defense (whatever that is)'! The selection of controls is evidently driven by a desire to focus on what someone believes to be the key issues: The CIS Controls embrace the Pareto 80/20 Principle, the idea that taking just a small portion of all the security actions you could...

Sony still paying for the hack

Image
The Sony hack two years ago is still costing Sony money. An article in the Hollywood Reporter notes that Sony has paid $millions already: "After the hack, Sony has faced several lawsuits over failure to safeguard private data and most notably settled a class action from former employees in a deal worth somewhere between $5.5 million to $8 million." That is on top of the substantial costs directly incurred in or caused by the incident, including the loss of business, inability for Sony Pictures Entertainment to operate for several weeks, penalties from the authorities due to its problems filing financial results on time, and of course the incident investigation and actions arising, clearing-up the mess. Possibility Pictures is now  claiming compensation for the loss of revenue on one of its films that Sony was supposed to be distributing. "To write love on her arms" was one of five films stolen in the hack and released onto the Internet as part of the incident. Pos...

IP Intellectual Poverty

Image
A thought-provoking piece in Forbes about the commercial value of intellectual property contains a stack (a set? A pile? A jumble? An assortment?) of remarkable statistics ... and I feel inspired to comment on one graph in particular: Neither the Forbes piece nor the Ocean Tomo source explain how the numbers on that graph were calculated. Intangible assets are not normally reported/disclosed, and in fact are notoriously difficult to value . Various approaches could have been used to estimate the asset values but we don't know how it was done. The valuation appears to have been based, in part, on the 'market value' or capitalization - essentially the product of the number of issued shares and the share price - of some or all of the Standard & Poor's Top 500 companies. The difference between capitalization and reported tangible asset values would estimate the value of intangibles ... but both values are somewhat uncertain. Share prices, for instance, tend to be far ...

Permissions - another novel security awareness topic

Image
When a customer suggested that we ought to cover privileges, we thought "Great idea!" ... but when we got stuck into the research for the new module, we soon realized that we couldn't really discuss privileges without also dipping into access rights ... which takes us into rights ... and compliance ... and a whole stack of other stuff. From being a narrow and specific topic, it mushroomed into an enormous beast, a far more complicated, wide-ranging awareness subject than we originally anticipated, taking in more than thirty aspects: access controls; access rights; accountability; authorization; awareness, education and training (!); compliance; controls; disclaimers; enforcement; entitlement; escalation; ethics; exceptions; exemptions; forensics; governance; granting, denying and revoking permissions; groups and rôles; identification and authentication; incident response and management; obligations and responsibilities; passes and ID cards; penetration and security testin...