Posts

Showing posts with the label Metrics

Phisosophical phriday - objectives of desire

Image
Objectives are king. If strategy is the organisational or personal journey ahead, we must truly understand our objectives to move ahead confidently in the right direction, systematically measuring progress towards those objectives.  If the objectives are uncertain, well, any path will do, and our measures are largely pointless: we may know how far we've come and how much fuel we've consumed so far but we're not sure how much further we need to go, nor in what direction and at what speed. That's sub-optimal. So far so good. But what if the objectives are hidden, in conflict, or not what they seem? There are clearly potential problems with objective-led approaches - a little seething cluster of problems in fact.  So, then, it seems objectives have objectives. 

Systematically improving professional services

Image
My beady eye has been caught by another excellent thought-provoking Protiviti article by Jim DeLoach with Randy Armknecht concerning board-level blind spots. I highly recommend reading and contemplating Are There Blind Spots in Your Boardroom ? Jim and Randy offered ten practical suggestions for boards to address the issue. Here they are with my thoughts and ideas on how to apply them in other contexts, besides the boardroom, such as within the information risk and security management team for example: Assess whether current board culture, composition and agendas are fit for purpose in the current disruptive business environment. Assess the current team culture, composition, priorities, skills & competences, expertise, relationships, interests etc. with a view towards the future. How should the team evolve or adapt to changing circumstances, building on past successes and learning from failures?

Measuring and managing ethics

Image
KPMG's Soft Controls model caught my beady eye this week: KPMG are evidently using these 8 factors to analyse, measure and help clients manage their corporate cultures, claiming that "Our model gives organisations a valid tool for getting a clear picture of the current organisational situation, confront it, and break through the silence and passivity." Hmmm, 'silence and passivity', really KPMG? Well OK, whatever. It appears to be a viable approach.

Knit your own security metrics

Image
This morning on the ISO27k forum, Vurendar told us:  "I saw your pragmatic book but I was confused on the way criteria and no’s were assigned. If you could guide will really help.  I’m doing a RBI Based compliance assessment where regulator has asked for such metrics. Help would be really appreciated."   Here's my reply.   For guidance on choosing which metrics to take a look at and maybe score, I recommend Lance Hayden's book " IT Security Metrics " which describes the  G oal- Q uestion- M etric approach. 

ISMS implementation project guidance checklist

Image
This checklist is appended to a SecAware guideline on implementing an ISMS , elaborating clause-by-clause on ISO/IEC 27001 - essentially, our version of ISO/IEC 27003 .   It offers  pragmatic guidance for information security managers and CISOs - nothing too obscure or complex. ---oooOOOooo--- Project definition, justification, scoping and planning ⬚   Study the standards, in depth: complete lead implementer training if possible. ⬚   Study the business, in depth, to understand its objectives, strategies, culture, governance arrangements, existing information risk and security management etc . ⬚   If the organisation has a defined, structured approach for this phase, use it! ⬚   Build a business case that identifies and promotes the business benefits of the ISMS. ⬚   Look beyond ‘security’ and ‘compliance’ e.g . helping management to manage business risks, supporting/enabling other business initiatives and strategies.

Assessing upstream supply chain information risks

Image
Yesterday, someone sought guidance from the ISO27k Forum on categorising vendors by risk. Here's my coffee-fueled early-morning response, lightly edited for this blog. Risk assessment criteria In the context of an ISO 27001   I nformation S ecurity M anagement S ystem, information risk in the upstream supply chain/network, viewed from the customer organisation's business perspective, is the primary concern in relation to vendors.  Breaking that down, the kinds of factors that may affect the information risk levels include:

Using security enquiries by customers as a security metric

Image
On CISSPforum, Walt Williams suggested a novel security metric: "If your organization has customers that ask you to complete questionnaires before engagement, track those against logos added or better revenue brought in. You’re now tracking your return on investment and a key risk of if your security is not good enough, those are the businesses you loose.Do the same with each customer that asks for your ISO certification or SOC 2 report. You have an excellent metric that allows you to track that return on investment and shows security as a revenue generating part of the organization. My organization’s last quarter internal company meeting had the Senior Revenue officer publicly acknowledge and thank InfoSec for our role in landing their biggest customer. It doesn’t get much better than that." So, inspired by Walt's intriguing idea, I prepared a conventional metric specification using a combination of the G oal- Q uestion- M etric approach (as ably described by Lance Hayd...

mmmmmm, More Meaningful Management Metrics

Image
For about a week, I've enjoyed following and participating in an expansive discussion thread on LinkeDin about the value of measurement and metrics for management , debating various issues that can occur both in theory and in practice. One straw-man argument is that 'managing by the numbers' can imply a myopic focus on commonplace business metrics such as stock price or annual profit, both of which can be manipulated to some extent by managers even at the expense of long term resilience and commercial success, let alone other business objectives. Despite Taylor's outmoded 'scientific management' experiments having been debunked a century ago, some LinkeDinners in the thread evidently still believe that science (in the form of numeric data) and management are poles apart.  I beg to differ. That's so last century! Management is complex, dynamic and nuanced, hence I accept that simplistic or crude metrics can't possibly address the entire practice. For exam...

Preparing managers to be ISO27001 certified

Image
This morning,  a new member of the ISO27k Forum asked us some questions about his organisation's upcoming ISO/IEC 27001 certification audit (paraphrased below).  Since these are commonplace issues, I address them here on SecAware blog for the benefit of others in the same situation now ... or at earlier stages.  Management being ready for the certification audit has implications for the way an ISO/IEC 27001 I nformation S ecurity M anagement S ystem was originally initiated/conceived, scoped, planned and approved, as well as how it is managed once it comes into operation. 1. Does the auditor need to talk to the CEO or would another member of Top Management such as the COO or a VP be sufficient? That is for the auditor to decide. CEOs are invariably busy people ... but the CEO's non-involvement (even before being asked!) hints  at a lack of support or engagement from senior management*. If other senior managers are more willing and able to be interviewed, that ...

The power of power measurement

Image
Electrical power consumption by a computer cupboard, IT room, tech suite, data centre or facility  is one of my favourite [pet!] metrics   for several reasons: It is readily measured using a wattmeter, watt-hour meter or ammeter on the main supply line/s; Compared to more technical metrics, power is simple to plot, report, explain and understand; As the installed IT equipment and usage gradually changes, so does the power consumption. It is straightforward to track and predict the overall trends without necessarily measuring and controlling every single item and change;  Step changes in power consumption indicate substantial changes in the IT equipment or usage. Marked decreases are welcome but quite rare ( e.g . as older equipment is retired from service or replaced by more modern, energy-efficient stuff), whereas marked increases in consumption - especially if unexpected - may be cause for concern; The first law of thermodynamics tells us that all the input energy has t...

Two dozen data centre fire controls

Image
Fire is clearly a significant risk to any data centre given that  a major incident (disaster!) is reported globally roughly every quarter year on average  plus an unknown number of smaller/unreported ones. Limited public disclosure of data centre fire investigation reports makes it tough, even for experienced professionals , to assess and quantify the risk.  However, s ince the likely impacts and costs of such major incidents are obviously non-trivial and the number of incidents is definitely not zero, it would be negligent to ignore the risks. Controls to avoid, mitigate or share data centre/IT facility fire risks include: Governance and management arrangements taking due account of information risks including physical security aspects when designing and procuring information services such as commercial cloud services and data centre/co-location facilities - which, by the way, don't automatically reduce

ISO27k ISMS metrics

Image
Information is clearly a valuable yet fragile corporate asset that must be protected against a wide range of threats. Protecting information is complicated by its ubiquity, plus its intangible and ephemeral, dynamic nature, on top of which the information risks are also constantly changing. Furthermore, information risks have to be managed alongside all other risks facing the business, of which there are many. Information risk management is a tough challenge, made still harder if management lacks sufficient, relevant and reliable information concerning the status of information risk management activities, processes, information security etc .   "What  should  we be measuring?" is a common refrain, along with "What are the most common security metrics?". At face value, these are perfectly reasonable and sensible questions. However the first is impossible to answer without knowing more about the organization's situation, while the second is trickier still: scie...

Riding the waves

Image
  Yesterday, I wrote about preparing and promoting your budget proposal, strategy, programme of projects or an individual initiative, gaining management support and negotiating for approval. Today I'd like to emphasis a fleeting, easily overlooked step in your journey, an opportunity to do even better. At the very moment when the negotiations are completed and management finally agrees your infosec budget, their interest, motivation and support for it is high ... so, before the dust settles, why not seize the moment: a window of opportunity has opened. Before long, the wave of enthusiasm will subside and management's focus will turn to other matters. 

COVID information risk analysis - retrospective

Image
Two and a half years ago in March 2020 as we were fast approaching our first lockdown, I published the following P robability I mpact G raph depicting my analysis of the information risks relating to COVID: The PIG reports the information risks I identified at the time, thinking about COVID from the general societal perspective as opposed to a personal or organisational perspective.

'Breach cost per record' metric - BUSTED

Image
  Finally! Data in a  report by Cyentia confirms my bias!

Learning points from a 27001 certification announcement

Image
This morning I bumped into a marketing/promotional piece announcing PageProof’s certified "compliance" (conformity!) with "ISO 27001" (ISO/IEC 27001!). Naturally, they take the opportunity to mention that information security is an integral part of their products. The promo contrasts SOC2 against '27001 certification, explaining why they chose ‘27001 to gain some specific advantages such as GDPR compliance - and fair enough. In the US, compliance is A Big Thing. I get that. It occurs to me, though, that there are other, broader advantages to ‘27001 which the promo could also have mentioned, further valuable benefits of their newly-certified ISMS.

Iterative scientific infosec

Image
      Here's a simple, generic way to manage virtually anything, particularly complex and dynamic things: Think of something to do Try it Watch what happens Discover and learn Identify potential improvements GOTO 1 It's a naive programmer's version of Deming's P lan- D o- C heck- A ct cycle - an iterative approach to continuous improvement that has proven very successful in various fields over several decades. Notice that it is rational, systematic and repeatable. Here's a similar grossly-simplified outline of the classical experimental method that has proven equally successful over several centuries of scientific endeavour:

What actually drives information security?

Image
  The 'obvious' driver for information security is information risk: valuable yet vulnerable information must be secured/protected against anything that might compromise its confidentiality, integrity or availability, right? Given an infinite array of possible risks and finite resources to address them, information risk analysis and management techniques help us scan the risk landscape for things that stand out - the peaks - and so we play whack-a-mole, attempting to level the field through mitigating controls, remainingly constantly on the lookout for erupting peaks and those hidden behind the ones we can see or were otherwise transparent. That's 'obvious' from my perspective as an experienced information risk and security professional, anyway. Your perspective probably differs. You may look at things from a slightly or dramatically different angle - and that's fine. I see these as interesting and stimulating complementary approaches, not alternatives. Complian...

How many metrics?

Image
While perusing yet another promotional, commercially-sponsored survey today, something caught my beady eye. According to the report, "On average, organizations track four to five metrics".   Four to five [cybersecurity] metrics?!!  Really?   Oh boy. Given the importance, complexities and breadth of cybersecurity, how on Earth can anyone sensibly manage it with just four to five metrics? It beggars belief, particularly as the report indicates that three quarters of the 1,200 surveyed companies had at least a $billion in revenue, and more than half of them have at least 10,000 employees. With a total cybersecurity expenditure of $125billion (around 80% of the total global estimate), these were large corporations, not tiddlers. The report indicates the corresponding survey question was "Q30. Which of the following cybersecurity metrics does your organization track, and which metrics are the most important?". Well OK, that's two questions in one, and the report does...

Threat intelligence policy

Image
  I finally found the time today to complete and publish an information security policy template on threat intelligence.  The policy supports the new control in ISO/IEC 27002:2022 clause 5.7:  "Information relating to information security threats should be collected and analysed to produce threat intelligence." The SecAware policy template goes a little further: rather than merely collecting and analysing threat intelligence, the organisation should ideally respond to threats - for example, avoiding or mitigating them. That, in turn, emphasises the value of 'actionable intelligence', in the same way that 'actionable security metrics' are worth more than 'coffee table'/'nice to know' metrics that are of no practical use. The point is that information quality is more important that its volume . This is an information integrity issue, as much as information availability. The policy also mentions 'current and emerging threats'. This is a ve...