Posts

Showing posts with the label Privacy

Internet security guidance

Image
The second edition of ISO/IEC 27032 "Cybersecurity - Guidelines for Internet security" has just been published. The introduction to the new edition commences: "The focus of this document is to address Internet security issues and provide guidance for addressing  common Internet security threats, such as: — social engineering attacks; — zero-day attacks; — privacy attacks; — hacking; and — the proliferation of malicious software (malware), spyware and other potentially unwanted  software." Notice the standard is focused on " Internet security issues " which, in practice, means it covers active attacks perpetrated via the Internet. However:

'Breach cost per record' metric - BUSTED

Image
  Finally! Data in a  report by Cyentia confirms my bias!

The discomfort zone

Image
Compliance is a concern that pops up repeatedly on the ISO27k Forum , just this  morning for instance. Intrigued by ISO 27001 Annex A control A.18.1.1 "Identification of applicable legislation and contractual requirements", members generally ask what laws are relevant to the ISMS.  That's a tough one to answer for two reasons.   Firstly, I'm not a lawyer so I am unqualified and unable to offer legal advice. To be honest, I'm barely familiar with the laws and regs in the UK/EU and NZ, having lived and worked here for long enough to absorb a little knowledge. The best I can offer is a layman's perspective. I feel more confident about the underlying generic principles of risk, compliance, conformity, obligations, accountabilities, assurance and controls though, and have the breadth of work and life experience to appreciate the next point ... Secondly, there is a huge range of laws and regs that have some relevance to information risk, security, management and t...

ISO/IEC 27400 IoT security and privacy standard published

Image
To celebrate the publication of ISO/IEC 27400:2022 today, we have slashed the price for our IoT security policy templates to just $10 each through SecAware.com. IoT policy is the first of the basic security controls shown on the 'risk-control spectrum' diagram above, and is Control-01 in the new standard ... Do you have a security policy on IoT? If not, does that mean IoT is out of control in your organisation? Even if you do, what does it say? Is it valid, appropriate, worthwhile, sufficient?   The spectrum diagram shows quite a variety of risks and controls, but it is merely a summary, selected highlights. Attempting to cover them all in a policy document would be counterproductive - in fact, general employees can barely cope with a much-simplified one-page 'acceptable use policy'.   The new ISO/IEC 27400 standard takes a broad perspective with copious advice on information security and privacy for the designers, manufacturers, purchasers, users and administrators o...

AA privacy breach -- policy update?

Image
According to a Radio New Zealand news report today: "Hackers have taken names, addresses, contact details and expired credit card numbers from the AA Traveller website used between 2003 and 2018. AA travel and tourism general manager Greg Leighton said the data was taken in August last year and AA Traveller found out in March. He said a lot of the data was not needed anymore, so it should have been deleted, and the breach "could have been prevented"." The disclosure prompted the acting NZ Privacy Commissioner to opine that companies 'need a review policy': "Acting Privacy Commisioner Liz Macpherson told Midday Report that if data was not needed it should be deleted ... Companies needed a review policy in place to determine if the data stored was neccessary, or could be deleted, Macpherson said." So I've looked through our SecAware information security policies to see whether we have it covered already, and sure enough we do - well, sor...

Professional services - concluding phase

Image
Having introduced this blog series and covered information risks applicable to the preliminary and operational phases of a professional services engagement, it's time to cover the third and final phase when the engagement and business relationship comes to an end. Eventually, all relationships draw to a close. Professional services clients and providers go their separate ways, hopefully parting on good terms unless there were unresolved disagreements, issues or incidents (hinting at some information risks). It is worth considering what will/might happen at the end of a professional services engagement as early as the preliminary pre-contract phase. Some of the controls need to be predetermined and pre-agreed in order to avoid or mitigate potentially serious risks later-on. Straightforward in principle ... and yet easily neglected in the heady rush of getting the engagement going. This is not unlike a couple drawing up their "pre-nup" before a wedding, or a sensible organi...

Domotics - a can-o-worms

Image
This morning, I’ve been browsing and thinking about ISO/IEC 27403 , a draft ISO27k standard on the infosec and privacy aspects of “domotics” i.e. IoT things at home.   Compared to a [reasonably well controlled] corporate situation, there are numerous ‘challenges’ (risks) in the home setting e.g.: Limited information security awareness and competence by most people. IoT things are generally just black-boxes. Ad hoc assemblages of networked IT systems - including things worn/carried about the person (residents and visitors) and work things, not just things physically installed about the home (e.g. smart heating controls, door locks and cat feeders). Things are not [always] designed for adequate security or privacy since other requirements (such as low price and ease of use) generally take precedence. Finite processing and storage capacities, plus limited user interfaces, hamper/constrain their security capabilities. Lack of processes for mana...