Posts

Showing posts with the label Law

Philosophical phriday: looking forward to 2025

Image
I'm not a fan of new year's resolutions that tend (in my experience) to have limited impact and are often soon forgotten. My cynical self says the same thing applies to pledges, vows and other stated commitments, even agreements and contracts to some extent. They are more symbolic than actual control mechanisms (although I'm sure the lawyers would argue otherwise - on the clock, naturally). The focus is often on avoiding, preventing or stopping bad things, a negative emphasis although the actual language may be positive as in "I will lose weight" and "I will get fit". They can be a last resort, a sharp retrospective reminder of where we thought we were going when we are already heading off-course.

Philosophical phriday - compliance risk

Image
According to a vendor's promotional video interview I saw recently, the 'cybersecurity compliance burden' has allegedly become so significant that [customer] organisations are eagerly buying [their] software tools and services to help them manage and fulfil their obligations. The vendor's argument goes that, instead of accumulating a ragtag bunch of policies and other controls relating to user Identification and Authentication (I&A), for instance, it makes sense to:  Identify all the cybersecurity-related laws, regulations and standards that apply to the organisation; Examine them for any security control requirements relating to, say, I&A; Rationalise the I&A controls down to the smallest set that satisfies all the requirements - the lowest common denominator; Design, implement, use, manage and maintain those I&A controls; Have the I&A controls checked or audited to gain assurance that the compliance requirements are met.  OK so far? Sounds reasonab...

Book review: Permanent Record by Ed Snowden

Image
Title: Permanent Record Author: Edward Snowden ISBN: 978-1-250-23723-1 Price: US$18 from Amazon GH rating: 90% Summary Until I read this book, I considered my personal integrity a fundamental strength, core to my very being. It pales in comparison to Ed's extreme courage and intense determination to expose the shocking truth about the NSA's mass surveillance programme and the way it was concealed from Congress.

A round dozen risk treatment options

Image
I've been thinking about the 'treatment' phase of risk management lately. These are the four conventional and generally-accepted ways of treating (addressing) identified risks: Acceptance : living with the risk, hoping that it doesn't materialise; Avoidance : steering well clear of, or stopping, risky activities; Mitigation : reducing the probability and/or impact of incidents using various types of control;   Sharing : with others, such as business partners, insurers and communities. However, it occurs to me that a further eight risk treatment approaches are possible, whether you consider them alternatives, variants or complementary: Procrastination : delaying decisions and actions ostensibly in order to understand risks and possible treatment options (which, meanwhile, implies risk acceptance). Speedy decision-making is an important part of effective

Ten tips on tackling a thorny infosec issue

Image
A member approached the  ISO27k Forum   this morning for advice: " What would you recommend to do if our warnings as ISMS department specialists/auditors are not taken into account?" What can realistically be done if  management isn't paying sufficient attention to information risks that we believe are significant ?  This is a thorny issue and not an uncommon challenge, particularly among relatively inexperienced or naïve but eager information risk and security professionals, fresh out of college and still studying hard for their credentials. It can also afflict the greybeards among us: our passion for knocking down information risks can overtake our abilities to convince managers and clients. Here are ten possible responses to consider: 

The discomfort zone

Image
Compliance is a concern that pops up repeatedly on the ISO27k Forum , just this  morning for instance. Intrigued by ISO 27001 Annex A control A.18.1.1 "Identification of applicable legislation and contractual requirements", members generally ask what laws are relevant to the ISMS.  That's a tough one to answer for two reasons.   Firstly, I'm not a lawyer so I am unqualified and unable to offer legal advice. To be honest, I'm barely familiar with the laws and regs in the UK/EU and NZ, having lived and worked here for long enough to absorb a little knowledge. The best I can offer is a layman's perspective. I feel more confident about the underlying generic principles of risk, compliance, conformity, obligations, accountabilities, assurance and controls though, and have the breadth of work and life experience to appreciate the next point ... Secondly, there is a huge range of laws and regs that have some relevance to information risk, security, management and t...

Managing professional services engagements

Image
In relation to professional services, management responsibilities are shared between client and provider, except where their interests and concerns diverge. Identifying and exploiting common interests goes beyond the commercial/financial arrangements , involving different levels and types of management: Strategic management: whereas some professional services may be seen as short-term point solutions to specific issues ("temping"), many have longer-term implications such as the prospect of repeat/future business if things work out so well that the engagement is clearly productive and beneficial to both parties. Establishing semi-permanent insourcing and outsourcing arrangements can involve substantial investments and risks with strategic implications, hence senior management should be involved in considering and deciding between various options, designing and instituting the appropriate governance and management arrangements, clarifying responsibilities and accountabilities...

AA privacy breach -- policy update?

Image
According to a Radio New Zealand news report today: "Hackers have taken names, addresses, contact details and expired credit card numbers from the AA Traveller website used between 2003 and 2018. AA travel and tourism general manager Greg Leighton said the data was taken in August last year and AA Traveller found out in March. He said a lot of the data was not needed anymore, so it should have been deleted, and the breach "could have been prevented"." The disclosure prompted the acting NZ Privacy Commissioner to opine that companies 'need a review policy': "Acting Privacy Commisioner Liz Macpherson told Midday Report that if data was not needed it should be deleted ... Companies needed a review policy in place to determine if the data stored was neccessary, or could be deleted, Macpherson said." So I've looked through our SecAware information security policies to see whether we have it covered already, and sure enough we do - well, sor...

Professional services - preliminaries

Image
Yesterday I proposed a guideline on the information risk, security and privacy aspects of professional services . I introduced a simplistic 3-phase model for the business relationship through which one or more professional services assignments are delivered and consumed.  Today, I'm exploring the preliminary phase. Before professional services are delivered, client and provider form a business relationship. They determine the professional services required and offered, and of course negotiate the commercial arrangements. They also have the opportunity to decide how the services are to be provided, and how both the assignment/s and the business relationship are to be managed. Contracting is an important control in its own right with significant information and commercial risks associated. The contract may for instance: Be inappropriate for either organisation, the relationship and/or the professional service/s;  Be informal, undocumented, invalid and hence unenforceable; Bypass...

Stepping on the cracks

Image
Anyone seeking  information security standards or guidance is spoilt for choice e.g. : ISO27k - produced by a large international committee of subject matter experts and national representatives   NIST SP 800 series – well researched, well written, actively maintained ... and FREE! IT Grundschutz - a typically thorough Germanic approach, to the point of absurdity (4,800 pages!  It's encyclopaedic!)    CSA - cloud security guidance is their home turf COBIT - takes a deliberately different perspective on 'risk' and 'control'   Secure application development standards such as those from  OWASP   IT standards and methods as a whole : relevant because IT or cyber security is clearly a big part of information security   HR, physical security, privacy and business continuity standards and methods as a whole : filling-in the substantial gaps in IT or cyber security  Risk management standards , the best of which at least mention the im...

Risky business

Image
Physical penetration testing is a worthwhile extension to classical IT network pentests, since most technological controls can be negated by physical access to the IT equipment and storage media. In Iowa, a pentest incident that led to two professional pentesters being jailed and taken to court  illustrates the importance of the legalities for such work.  A badly-drafted pentest contract and 'get out of jail free' authorization letter led to genuine differences of opinion about whether the pentesters were or were not acting with due authority when they broke into a court building and were arrested.  With the court case now pending against the pentesters, little errors and omissions, conflicts and doubts in the contract have taken on greater significance than either the pentest firm or its client appreciated, despite both parties appreciating the need for the contract. They thought they were doing the right thing by completing the formalities. Turns out maybe they had...

Super management systems

Image
ISO 22301, already an excellent standard on business continuity, has just been revised and republished.  Advisera has a useful page of info about ISO 22301 here . There’s quite a bit of common ground between business continuity and information risk and security, especially as most organizations are highly dependent on their information, IT systems and processes.  T he most significant risks are often the same, hence it makes sense to manage both aspects competently and consistently.   The ISO ‘management system’ structured approach is effective from the governance and management perspective.   Aligning/coordinating the infosec and business continuity management systems has several valuable benefits since they are complementary.  Extending that thought, it occurs to me that most if not all other areas of management also have information risk and security implications: Physical site security and facilities management ( e.g.  reliable power and cooling for the...

Digital (cyber) forensics module released

Image
IT systems, devices and networks can be the targets of crime as in hacking, ransomware and computer fraud. They are also tools that criminal use to research, plan and coordinate their crimes. Furthermore, criminals use technology routinely to manage and conduct their business, financial and personal affairs, just like the rest of us. Hence digital devices can contain a  wealth  of evidence concerning crimes committed and the criminals behind them. Since most IT systems and devices store security-related information digitally, digital forensics techniques are also used to investigate other kinds of incidents, figuring out exactly what happened, in what sequence, and what went wrong ... giving clues about what ought to be fixed in order to prevent them occurring again.   It’s not as simple as you might think for investigators to gain access to digital data, then analyze it for information relevant to an incident. For a start, there can be a lot of it, distributed amon...

Cyber-insurance standard published

Image
We are delighted to announce the birth of another ISO27k standard :  ISO/IEC 27102:2019 — Information security management — Guidelines for cyber-insurance The newest, shiniest member of the ISO27k family nearly didn't make it into this world. Some in the insurance industry are concerned about this standard muscling-in on their territory. Apparently, no other ISO/IEC standards seek to define categories of insurance, especially one as volatile as this. Despite some pressure not to publish, this standard flew through the drafting process in record time thanks mostly to starting with an excellent ‘donor’ document and a project team tightly focused on producing a standard to support and guide this emerging business market. Well done I say! Blaze that trail! This is what standards are all about. ‘Cyber’ is not yet a clearly-, formally- and explicitly-defined prefix, despite being bandied about willy-nilly, a solid-gold buzzword. It is scattered like confetti throughout but unfortunately...

The formalities of certification

Image
ISO/IEC JTC 1/SC 27 is currently getting itself all hot-under-the-collar about cloud security certificates, certifying compliance with standards that were neither intended nor written for certification purposes.  The ISO27k cloud security standards ISO/IEC 27017 and ISO/IEC 27018 are not written as formally as certifiable standards such as ISO/IEC 27001 ... and yet I gather at least one accredited certification body has been issuing compliance certificates anyway, implying that the auditors must have used their discretion in interpreting the standards and deciding whether the organizations fulfilled the requirements sufficiently well to 'deserve' certificates. The trustworthiness of those certificates, then, depend in part on the competence and judgement of the certification auditors, not just on the precise wording of the standards. In other words, there's an element of subjectivity about it. The key issue is that, in this context, compliance certification is a formal ...

Forensic mythbusters

Image
We're currently researching for a future awareness module on forensics - a topic that has absolutely fascinated me since I was a kid through to my 20s as a geneticist (a "DNA scientist"). Naturally, for security awareness purposes, we'll be focusing on the use of forensics within the context of information risk and security ... but forensic science is all about information, including its availability and integrity, so our brief might yet widen. Today I stumbled across  The Innocence Network , a growing global movement to re-investigate dubious convictions, exonerate wrongly convicted people and press for improvements to criminal justice systems as appropriate.  Wrongful convictions are a treble tragedy: An innocent person is punished for something they didn't do. This is unjust and harmful to the individual, plus their families and social networks. A guilty person often goes free. This typically flows from point 1. I say 'often' and 'typically' be...