Posts

Showing posts with the label Outsider

Information risk management - a worked example [LONG]

Image
In the past few days, I have been triggered yet again by someone fearing that ISO/IEC 27001 certification auditors may insist that various Annex A controls are applicable and must therefore be implemented for conformity. Apocryphal nightmares about auditors doing exactly that tend to stoke the fear and prolong the myth. Myth, yes, myth. I've said it before and no doubt I'll say it again: the Annex A information security controls are not formally required for conformity with the standard - none of them, not even one. If you or your auditors believe otherwise, kindly tell us which clause of the standard applies. What are the exact words leading to that conclusion? Spoiler alert: there are none. There is no such requirement. IT DOES NOT EXIST. There is , however, a conformity requirement to check through Annex A for any controls that might reduce otherwise untreated information risks, but even then there is no (repeat, no ) obligation to implement the controls as stated in A...

Passionate dispassion

Image
Someone who is actively involved in, or is managing, an activity is patently not independent of it. They may well make a conscious, rational and determined effort to be objective, dispassionately reviewing evidence etc ., but their subconscious/emotional biases/prejudices and beliefs/value-systems will inevitably influence what they do. With the best will in the world, they will struggle to challenge and assess their past decisions and activities, especially if they were "certain" or "determined" or genuinely believed they were "doing the right thing". Furthermore, it is very hard for anyone to review the things they did not do, decisions they did not make or options they did not even consider. Mostly, they remain out of sight or out of the question.

Internet security guidance

Image
The second edition of ISO/IEC 27032 "Cybersecurity - Guidelines for Internet security" has just been published. The introduction to the new edition commences: "The focus of this document is to address Internet security issues and provide guidance for addressing  common Internet security threats, such as: — social engineering attacks; — zero-day attacks; — privacy attacks; — hacking; and — the proliferation of malicious software (malware), spyware and other potentially unwanted  software." Notice the standard is focused on " Internet security issues " which, in practice, means it covers active attacks perpetrated via the Internet. However:

Ailien beacons warn of rocks ahead

Image
Lately, I've been contemplating how the widespread availability and use of AI might affect humankind - big picture stuff. We are currently awash in a tidal wave of commentary about AI innovation, the information risks of AI and its naive users, the tech, the ethics and compliance aspects, the inevitable grab by greedy big tech firms, misinformation, disinformation, jailbreaking and so on. Skimming promptly past well-meaning advisories about prompt engineering from people excited to share their discoveries, I've been reading pieces about how AI can support or will supplant all manner of expert advisors on any topic sufficiently well represented in the models and datasets. The likelihood (near certainty!) of AI-generated content feeding back into AI-data sets and hence the potential consequences of runaway hallucinations, coupled with deliberate manipulation by those with private agendas, is quite scary - but equally the possibility of AI generating new knowledge (valid and usefu...

The business context for information risk and security

Image
Although the organisational/business context is clearly relevant and important to information risk and security management, it is tricky to describe.  In my opinion, clause 4 of ISO/IEC 27001 is so succinct that it leaves readers perplexed as to what 'context' even means.  It stops short of explaining how to determine and make use of various 'internal and external issues' in an I nformation S ecurity M anagement S ystem.  So, to help clients, I wrote and released a pragmatic 5-page management guideline on this for the SecAware ISMS toolkit , expanding on this neat little summary diagram: With about a thousand words of explanation and pragmatic advice, the guideline has roughly ten times as many words as clauses 4.1 and 4.2 ... or twenty times if you accept that the picture is worth a thousand words. It was written independently of, and complements, ISO/IEC 27003 's advice in this area. Although I am happy with the SecAware ISMS toolkit materials as they are, I...

Responsible disclosure - another new policy

Image
We have just completed and released another topic-specific information security policy template, covering responsible disclosure (of vulnerabilities, mostly). The policy encourages people to report any vulnerabilities or other information security issues they discover with the organisation's IT systems, networks, processes and people. Management undertakes to investigate and address reports using a risk-based approach, reducing the time and effort required for spurious or trivial issues, while ensuring that more significant matters are prioritised. The policy distinguishes authorised from unauthorised security testing, and touches on ethical aspects such as hacking and premature disclosure. It allows for reports to be made or escalated to Internal Audit, acting as a trustworthy, independent function, competent to undertake investigations dispassionately. This is a relief-valve for potentially sensitive or troublesome reports where the reporter is dubious of receiving fair, prompt t...

Managing professional services engagements

Image
In relation to professional services, management responsibilities are shared between client and provider, except where their interests and concerns diverge. Identifying and exploiting common interests goes beyond the commercial/financial arrangements , involving different levels and types of management: Strategic management: whereas some professional services may be seen as short-term point solutions to specific issues ("temping"), many have longer-term implications such as the prospect of repeat/future business if things work out so well that the engagement is clearly productive and beneficial to both parties. Establishing semi-permanent insourcing and outsourcing arrangements can involve substantial investments and risks with strategic implications, hence senior management should be involved in considering and deciding between various options, designing and instituting the appropriate governance and management arrangements, clarifying responsibilities and accountabilities...

Professional services infosec policy template

Image
  We have just completed and released a brand new information security policy template on professional services. The policy is generic, pragmatic and yet succinct at just over 2 pages. Professional services engagements, and hence the associated information risks, are so diverse that it made no sense to specify particular infosec controls, except a few examples. Instead, the policy requires management to nominate Information Owners for each professional services engagement, and they, in turn, are required to identify, evaluate and treat the information risks. This is another shining example of the value of the 'information ownership' concept. Although they are encouraged to delegate responsibilities to, or at least take advice from, relevant, competent experts (e.g. in Information Risk and Security, Legal/Compliance, HR, IT, Procurement), Information Owners are held personally accountable for the protection and legitimate exploitation of 'their' information. If Informati...

Data masking and redaction policy

Image
  Last evening I completed and published another SecAware infosec policy template addressing ISO/IEC 27002:2022 clause 8.11 "Data masking": "Data masking should be used in accordance with the organization’s topic-specific policy on access control and other related topic-specific, and business requirements, taking applicable legislation into consideration." The techniques for masking or redacting highly sensitive information from electronic and physical documents may appear quite straightforward. However, experience tells us the controls are error-prone and fragile: they generally fail-insecure, meaning that sensitive information is liable to be disclosed inappropriately. That. in turn, often leads to embarrassing and costly incidents with the possibility of prosecution and penalties for the organisation at fault, along with reputational damage and brand devaluation. The policy therefore takes a risk-based approach, outlining a range of masking and redaction controls...

Weaving strategies with policies

Image
I mentioned recently here on the blog that there can be strategic elements to policies, just as there are operational aspects to the supporting procedures and guidelines. With the new year fast approaching, I'd like to explore that further today. Warning : your blinkers are coming off. Prepare for the glare. Take for instance the corporate responses to COVID-19. Out of necessity, organisations in lockdown shifted rapidly from on-site office work and in-person meetings to home-working, using video conferencing, email and collaborative approaches. Although that may have been a purely reactive, un-pre-planned response to the global crisis that erupted (despite prior pandemics and warnings arising from increasing international travel) , it was facilitated by longer-term planned, strategic changes and investments in a resilient workforce with flexible working practices and positive attitudes, strong relationships within and without the organisation, plus appropriate tools and technolog...

Infosec policy development

Image
We're currently preparing some new information risk and security policies for SecAware.com .  It's hard to find gaps in the suite of ~80 policy templates already on sale  (!) but we're working on these four additions: Capacity and performance management : usually, an organization's capacity for information processing is managed by specialists in IT and HR.  They help general management optimise and stay on top of information processing performance too.  If capacity is insufficient and/or performance drops, that obviously affects the availability of information ... but it can harm the quality/ integrity and may lead to changes that compromise confidentiality , making this an information security issue.  The controls in this policy will include engineering, performance monitoring, analysis/projection and flexibility, with the aim of increasing the organisation's resilience. It's not quite as simple as 'moving to the cloud', although that may be part of the...

Is Facebook an asset?

Image
Yet another good question came up on the ISO27k Forum today*. Someone asked whether to add the company's Facebook page to their information asset register (implying that it would need to be risk-assessed and secured using the Information Security Management System processes), or whether the asset should be the Facebook account (ID and password, I guess)**. From the marketing/corporate perspective, good customer relations are perhaps the most valuable information assets of all, along with other external relations ( e.g. your suppliers, partners, prospective and former customers, regulators/authorities and owners) and internal relations (the workforce, including staff, management, contractors, consultants and temps, plus former and prospective workers). It’s tempting to think of these as just categories or faceless corporations, but in reality the interactions are between individual human beings, so social relations  in general are extremely important in business.  ...

Reflecting on privacy

Image
Anyone who read Orwell's masterpiece or saw the film "1984" appreciates the threat of mass surveillance by the state a.k.a. Big Brother. Anyone who has followed Ed Snowden's revelations knows that mass surveillance is no longer fanciful fiction. There are clearly privacy impacts from surveillance with implications for personal freedoms, assurance and compliance. At the same time, surveillance offers significant social benefits too, in other words, pros and cons which vary with one's perspective. Big Brother sees overwhelming benefits from mass surveillance and has the power, capability and (these days) the technology to conduct both overt and covert mass or targeted surveillance more or less at will.  The same thing applies to other forms of surveillance and other contexts: many of us gleefully carry surveillance devices with us wherever we go, continuously transmitting information about our activities, conversations, locations, contacts and more. We may call them...

SIM swap fraud

Image
I've heard rumours about the possibility of SIM-swap "identity theft" (fraud) but wasn't aware of the details ... until reading a couple of recent articles pointing to an academic paper from a team at Princeton University . The fraud involves socially-engineering the cellphone companies into migrating a victim's cellphone number onto a new SIM card, one in the fraudster's possession. That gives the fraudster control of a factor used in several multifactor authentication schemes ... and in some cases, that's enough to take full control ( e.g. resetting the victim's password - another factor). Otherwise, it might take them a bit more effort to guess, steal or brute-force the victim's password or PIN code first.  Authentication is usually a key control, yet authentication schemes often turn out to have vulnerabilities due to: Fundamental design flaws ( e.g. saving passwords unencrypted or weakly encrypted)  Bugs in the software and firmware ( e.g.  ...

Woe betide ...

Image
.... any organization unfortunate enough to suffer a privacy breach today, of all days, being "Data Privacy Day".  In the unlikely event that there are no new ones today, recent newsworthy breaches are liable to be trawled up and paraded across the media , again.  I've been writing about preparing to deal with malware incidents all this month. Managing or controlling the publicity aspects is trickier than it may appear. Sony pulled a master stroke in getting its legal team to threaten action against journalists who continued to exploit the tittle-tattle disclosed in the Sony Pictures Entertainment breach five years ago - but that's not a universally applicable approach. Travelex did well to get basic, static web pages published quickly, plus a talking-heads video explanation/apology by the CEO ... but ask their retail customers whether they feel 'informed', while the promised restoration of services is patently taking longer than anyone (except perhaps the cy...

Business discontinuity

Image
As if following a cunning plan (by sheer coincidence, in fact) and leading directly on from my last two bloggings about business continuity exercises,  Belgian manufacturing company Picanol suffered a ransomware infection this week, disabling its IT and halting production of high-tech weaving machines at its facilities in Ypres, Romania and China. Fortunately, Picanol's corporate website is still up and running thanks to Webhosting.be, hence management was able to publish this  matter-of-fact press release about the incident : Unsurprisingly, just  a few short days after it struck,  technical details about the "massive ransomware attack" are sparse at this point. The commercial effects, though, are deemed serious enough for trading in its shares to have been suspended on the Brussels bourse.  There's already plenty of information here for a case study in February's awareness module. Through a brief scenario and a few rhetorical questions, we'll prompt workers...

Post-malware-incident notification & other stuff

Image
A couple of days ago I wrote:  " One screamingly-obvious lesson from the rash of ransomware incidents is that we need to anticipate malware infections when the preventive controls fail, which means strengthening the security protecting our business-critical systems and being ready to recover IT services and data efficiently following incidents."  That's not all. Anticipating that, despite all we do to prevent them, malware infections are still likely to occur implies the need for several post-event controls.   These are the kinds of controls I have in mind: Reliable, efficient, effective, top-quality incident response and management processes - in particular, speed is almost always of the essence in malware incidents, and the responses need to be well-practiced - not just the run-of-the-mill routine infections but the more extreme/serious "outbreaks"; Decisive action is required, with strong leadership , clear roles and responsibilities , and of course strong aw...

Risky business

Image
Physical penetration testing is a worthwhile extension to classical IT network pentests, since most technological controls can be negated by physical access to the IT equipment and storage media. In Iowa, a pentest incident that led to two professional pentesters being jailed and taken to court  illustrates the importance of the legalities for such work.  A badly-drafted pentest contract and 'get out of jail free' authorization letter led to genuine differences of opinion about whether the pentesters were or were not acting with due authority when they broke into a court building and were arrested.  With the court case now pending against the pentesters, little errors and omissions, conflicts and doubts in the contract have taken on greater significance than either the pentest firm or its client appreciated, despite both parties appreciating the need for the contract. They thought they were doing the right thing by completing the formalities. Turns out maybe they had...

Transparency and oversight

Image
Along with increasing legal and regulatory compliance pressures on organizations to implement appropriate privacy controls, popular awareness of the issues appears to be on the up with commercial implications for organizations. Global IT megacorps such as Facebook, Microsoft, Apple and Google are particularly exposed to public criticism simply because they are household names ... but that's not to say they are powerless, far from it.  Contrast Apple's handling of the FBI iPhone security incident against Facebook's handling of the Cambridge Analytica scandal , plus other privacy incidents. All the megacorps have to take their own cybersecurity seriously simply because they are such massive targets facing business-critical information risks: it's literally an existential issue. They are also forced to comply with various laws and regulations, for the same reasons as any other organization - to avoid potentially huge punitive fines and other substantial costs arising from...