Posts

Showing posts with the label Mobile

New ISO27k domotics security standard

Image
ISO/IEC 27403 " Cybersecurity – IoT security and privacy – Guidelines for IoT-domotics " was published at the very end of last month. “Domotics” is a neologism for smart homes. This  new   standard  covers the cybersecurity and privacy aspects of thing -to- thing interactions ( e.g. home hubs and entertainment subsystems) as well as human-to- thing  plus  thing -to-sensors/actuators that physically interact with the home ( e.g . smart door locks and thermostats) and networking both within the home ( e.g . WiFi, Bluetooth) and beyond ( e.g . fibre or wireless broadband). The  standard  is aimed squarely at guiding the designers, manufacturers and security or privacy assessors of IoT domotics, as oppoed to retail customers and users. It provides examples of information risks that should (in theory at least) have been identified, evaluated and addressed by IoT suppliers baking-in suitable security controls to protect their valued customers' interests. I...

BCM for WFH

Image
Since home and mobile workers rely on IT to access critical business systems and corporate data, and to communicate with others, organisations need a robust IT network infrastructure that extends to workers' homes or wherever they hang out. If, in reality, the infrastructure turns out to be fragile and unreliable, business activities are likely to be equally fragile and unreliable, leading to frustration and grief all round. In other words, the extended IT infrastructure is quite likely business-critical. W orking F rom H ome or on the road can increase various information risks relative to conventional office-based work, due to factors such as: Use of cloud computing services*; Workers using their own or shared devices and internet connections for work purposes, raising questions about their suitability and security, ownership of and access to any intellectual property or personal information on them;

ISO/IEC 27400 IoT security and privacy standard published

Image
To celebrate the publication of ISO/IEC 27400:2022 today, we have slashed the price for our IoT security policy templates to just $10 each through SecAware.com. IoT policy is the first of the basic security controls shown on the 'risk-control spectrum' diagram above, and is Control-01 in the new standard ... Do you have a security policy on IoT? If not, does that mean IoT is out of control in your organisation? Even if you do, what does it say? Is it valid, appropriate, worthwhile, sufficient?   The spectrum diagram shows quite a variety of risks and controls, but it is merely a summary, selected highlights. Attempting to cover them all in a policy document would be counterproductive - in fact, general employees can barely cope with a much-simplified one-page 'acceptable use policy'.   The new ISO/IEC 27400 standard takes a broad perspective with copious advice on information security and privacy for the designers, manufacturers, purchasers, users and administrators o...

Stepping on the cracks

Image
Anyone seeking  information security standards or guidance is spoilt for choice e.g. : ISO27k - produced by a large international committee of subject matter experts and national representatives   NIST SP 800 series – well researched, well written, actively maintained ... and FREE! IT Grundschutz - a typically thorough Germanic approach, to the point of absurdity (4,800 pages!  It's encyclopaedic!)    CSA - cloud security guidance is their home turf COBIT - takes a deliberately different perspective on 'risk' and 'control'   Secure application development standards such as those from  OWASP   IT standards and methods as a whole : relevant because IT or cyber security is clearly a big part of information security   HR, physical security, privacy and business continuity standards and methods as a whole : filling-in the substantial gaps in IT or cyber security  Risk management standards , the best of which at least mention the im...

Policy development process: phase 2

Image
Today we completed and published a new "topic-specific" information security policy template on clear desk and screen . Having previously considered information risks within the policy scope, writing the policy involved determining how to treat the risks and hence what information security or other controls are most appropriate.   Here we drew on guidance from the ISO27k standards, plus other standards, advisories and good practices that we've picked up in the course of ~30 years in the field, working with a variety of industries and organizations - and that's an interesting part of the challenge of developing generic policy templates. Different organizations - even different business units, departments, offices or teams within a given organization - can take markedly different attitudes towards clear desk and screen. The most paranoid are obsessive about it, mandating controls that would be excessive and inappropriate for most others. Conversely, some are decidedly l...

March 14 - COVID-19 information risk update

Further to yesterday's assessment of the information risks associated with the coronavirus pandemic and the discussion arising, here are a few more aspects. An increased number of knowledge workers are now working from home, some of them for the first time. What equipment and services are they using? What are the information risks and security arrangements? Who knows? Larger organizations tend to have in place suitable policies plus structured, systematic approaches towards home and other off-site working, with controls such as management authorization, remote security management of end user devices (corporate or BYOD), VPNs, network security monitoring, network backups, automated patching, antivirus etc.  Hopefully they have all scaled easily to cope with the changing proportions of off-siters. Medium and especially small organizations, however, may be less well prepared ... and all of them are likely to be feeling the strain of changed working practices and social interaction. T...

Real-world physical impacts

Image
At the moment, as currently scoped, June's awareness module primarily concerns physical security measures protecting information, data and IT systems, including health and safety protection for workers ... but there's another aspect that potentially falls in scope: IT incidents with physical real-world impacts . Thus far, fortunately, such incidents have been very rare, mostly proof-of-concept demonstrations that hacking, say, the IT systems controlling an electricity generator could indeed cause it to liberate the smoke . The potential is very real and scary however once you appreciate just how much of modern life is controlled by vulnerable computers, often Internetworked, with design flaws and bugs mostly tucked out of sight, lurking in the extreme technical complexities under the hood. There be dragons, as the Iranians discovered . The proliferation and interconnectedness of IT systems has reached epic proportions lately with Internet-connected lightbulbs, air conditioners,...

Security awareness for off-site workers

Image
Hot off the production line comes May's security awareness and training module about working off-site . The 69th topic in our portfolio was inspired by a subscriber asking for something on home working. It ended up covering not just working at home but  the information risk and security implications of working on the road (digital nomads), in hotels, on supplier or customer sites and so forth , touching on online collaboration and other related areas along the way. Module #193 is 95% brand new, prepared from scratch during April and blended-in with a little updated content recycled from previous modules on workplace security and portable ICT security, plugging the gap, as it were. I'm proud of the guideline (item #04), part of the staff awareness stream .  At 16 pages, i t is lengthier than normal due to the sheer variety.  With the odd touch of humor and stacks of pragmatic security tips for home and mobile workers, it would make a neat little awareness booklet or eDoc...

Another NSA contractor accused of schlurping

Image
Catching up with recent infosec news, I stumbled across a piece about NSA contractor Harold T Martin III , accused of schlurping (pinching and hoarding) some 50 terabytes of secret data.  50 Tb!   Along with Julian Assange, Ed Snowden and Chelsea Manning, the US government appears to be hemorrhaging secrets by the shed-load, despite all the extraordinary security controls designed to prevent and detect it. I say 'shed-load' advisedly: a typical page of a typical document has about 500 typical words per side i.e. 1,000 words per double-sided sheet needing about 200 kb of rich text data ( e.g. a Word document). That's 5 sheets per Mb*. 50 Tb is 50 million Mb or about 250 million sheets. A typical box of printer paper contains 10 reams of 500 sheets i.e. 5,000 sheets per box, enough to print out about 1 Gb of data*. So, printing 50 Tb would take about 50,000 boxes of paper, a stack of about 37x37x37 boxes. That's a shed-load ... a big shed, a small warehouse or ...

Working off-site

Image
We're rapidly spiralling-in on a scope, purpose and hence title for the next security awareness and training module, currently extruding its way through the awareness module sausage machine at IsecT HQ. Inspired by a customer request to cover the security aspects of 'home working', we set out to complement the BYOD and business continuity topics ... but in exploring the associated information risks and controls, we've realized that there are other ways and means of working with similar issues.  Mobile or portable working, for example, is almost the rule for managers and professionals these days, at least to the extent of being constantly in touch by cellphone, keeping up with emails and TXT messages, and using work apps on smartphones, laptops and tablet PCs. Commuters on public transport often seem totally absorbed by their screens and ear-buds, whether that's personal or work emails, podcasts, news from the city desk, Harry Potter, Game of Thrones, Bach or BoyZone...

Off-site security

Image
Do your mobile sales reps look after the information relating to products, pricing, contracts, supplies, specifications, strategies and all that – not just the sales apps, spreadsheets and slide decks on their laptops, tablets and smartphones, but all the other sensitive and valuable corporate and personal data they carry or access? What about your roaming product/tech support and maintenance people? Your company doctor? The Board of Directors? Managers and business travelers generally? Workers catching up with email on their way home, or putting the final touches on a progress report while stretched out on the couch watching an episode of CSI? Are they vigilant and alert? Do they have the faintest clue about the information risks around them, or what's expected of them in the way of information security and privacy? Do they  care ? Portable ICT has revolutionized our lives to the point that we take it for granted these days. We've become b lasé  about it. No longer are we tie...

Passwords are dead

Image
I've blogged about passwords several times. It's a zombie topic, one that refuses to go away or just lie down and die quietly. On CISSPforum, we've been idly chatting about user authentication for a week or so. The consensus is that passwords are a lousy way to authenticate, for several reasons. First the obvious.  Passwords are: Hard to remember, at least good ones are, especially if we are forced to think up new ones periodically for no particular reason; Generally weak and easily guessed, due to the previous point; Sometimes generated and issued not chosen or changeable by the user; Readily shared or disclosed ( e.g. by watching us type), or written down; Readily obtained by force, coercion, deception and other forms of social engineering such as phishing or password reset tricks, or interception, or hacking, or brute force attacks, or spyware or .. well clearly there are lots of attacks; Often re-used (for different sites/apps etc ., and over time). Next comes some les...

Workplace information security awareness

Image
With a final dash for the finishing line, July's awareness module on workplace information security was successfully completed on time.  If you've been tracking this blog, you'll have a pretty good idea what it's all about.   The listing below shows the variety of awareness materials in three parallel streams for three target audience groups: That's another 85 Mb of awareness content in the bag, including two brand new and two updated model policies, rounding out our policy suite:  With 70 model policies in the set, and over 60 awareness topics in the portfolio, it's getting progressively harder to think of new angles on information security to cover - difficult but not impossible.   August's topic will be a brand new one for us: cyberinsurance . Although we've been quietly exploring it in the background, I'm looking forward to diving right in and immersing full in in the new topic. Truth is, I've had enough of workplace infosec. It was an intere...

Laptop ban [UPDATED]

Image
One of the workplace information risk and security issues worth discussing with management is the possibility of a total ban on portable ICT devices such as laptops, tablets and smartphones by airlines, and perhaps other forms of mass public transport. At present, some ICT devices are banned from the cabin by some airlines on some routes, but it is not inconceivable that the ban might be extended given escalating terrorism and safety threats. I presume the only reason we are still allowed to take our explosive battery packs on board at all is the inconvenience and customer dissatisfaction that would follow if portable and wearable devices were completely banned - a typical risk-reward trade-off. As far as the security awareness program goes, whether and how a ban is extended is inconsequential: the point is to prompt the audience to think about how they would deal with that situation. It's a theoretical exercise at this stage, based on a credible scenario. What effects would it hav...

Weaving news into awareness

Image
Today I'v e been searching for news items to illustrate the awareness materials on workplace security, particularly incidents involving corporate information.  At first I thought maybe we have over-estimated the risks: Googling for, say, "office security" brings up stacks of news about MS Office but not so much on traditional office break-ins, fires and the like. "Commercial burglary" was a more productive search term but still not exactly overwhelming. Likewise searching for "theft from vehicle" leads to a plethora of brief police incident logs and the occasional news piece about laptops and other IT gizmos stolen from parked cars - seemingly just opportunistic thefts by druggies. Digging a little deeper, though, I realized that those police incident logs indicate a level of crime so widespread and commonplace that it is barely newsworthy any more. Tot up all those little incidents involving theft of computers, laptops, iPads, smartphones and the like...

Nose to the grindstone

Image
Having completed and submitted our bids yesterday, it's back to the day-job today, picking up where we left off the workplace information security awareness module. Well it would be noses-to-the-grindstone ... except MS Office is playing up for no obvious reason, so I sit here watching the clock tick while it reinstalls, again, idly wondering why an organization the size of Micro$oft can't be bothered to put enough resources and effort into sorting out its numerous information security and quality problems properly, for once ... and so here I am an hour and much frustration later. It seems to be running, for now, sort-of: Outlook still tells me it isn't activated while the Office365 online site says "We’re still setting a few things up, but feel free to get started" (thanks a bunch: it was working until you screwed it up, M$). No cl ue what was wrong with it - lack of oomph  in the dilithium crystals or something. Given how keen M$ is to charge us, perhaps we shou...

Staff awareness on security innovation

Image
The staff briefing paper on security innovation is 'done'.  Writing it reminded me of the flaming Samsung Galaxy Note 7 debacle from 2016, a neat example of risks associated with 'bleeding edge' high technology that I'm sure most workers will recall.   Samsung is back in the news now, apologizing to shareholders for the incident and a separate bribery scandal. Given the direct costs, reputational damage and brand devaluation, it's a neat way to illustrate the commercial risks of innovation for management too. Introducing relevant news from the general media into the security awareness content, especially while it is fresh, is a deliberate part of our strategy. We're not only highlighting the topical information risk, security and other angles in the particular news pieces but also more subtly encouraging people to consider those same perspectives whenever they catch the news. At some future point, there is bound be another headline-grabbing news story concer...

Surveillance: awareness challenge or opportunity?

Image
We're busy preparing February's security awareness module on the topic of surveillance . As often happens, what we anticipated would be a fairly narrow and specific issue has mushroomed before our very eyes as we've delved into the writing. We're now looking at surveillance on the population by the authorities, by the organization on workers and third parties, by third party organizations on workers, and by individuals on each other ... The awareness module covers a fascinatingly diverse patchwork of information risks e.g. industrial espionage and intelligence, health and safety, network and physical security monitoring, oversight and supervision, privacy and confidentiality, office security, things , portable devices, artificial intelligence, hacking, malware and more. We've covered all of them separately but this is our chance to bring them together - an awareness story with with a novel perspective. The news story about a TV presenter's verbal comment alleg...

Infosec awareness lessons from NZ quakes

Image
A big earthquake at midnight last night on the Northern end of South Island New Zealand was a major incident with various implications for incident/disaster management. I'd like to pick up on a few security awareness aspects while the incident is fresh in my mind and still playing out on the NZ media as I write this. There is a lot of effort put into preparedness for such events, across the whole country. For instance, the central safety message " Drop, cover, hold " is simple, widely repeated and used consistently in a variety of media and situations. Even the iconic images and colours (lots of black-and-yellow, warning colours with a strong biological basis) are consistent. Schools run classroom teaching on it. Websites and public safety demonstrations repeat it, frequently. There are flyers and leaflets, plus local, regional and national exercises to practice the actions, with extensive media coverage. "Get ready, get thru" is a strong theme. Full marks!  [I ...