Posts

Showing posts with the label Surveillance

Mandatory vs discretionary ISMS documentation

Image
Whereas ISO/IEC 27001 indicates that only fourteen (14) types of ISMS documentation are strictly required  (mandatory), they are barely a start, even for a barebones ISMS.  In practice,  both mandatory and  discretionary documents are valuable . ISO/IEC 27001 c lause 4.4   states: “The organization shall establish, implement, maintain and continually improve an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document.” Documentation (termed 'documented information' in the standard - see clause 7.5) is generally the best way for management to inform workers about their information security responsibilities  e.g. through written policies, procedures/work instructions and job/role descriptions, accompanied by awareness and training materials such as guidelines and briefings. In addition, many security-related processes generate 'records' such as completed forms, ...

Book review: Permanent Record by Ed Snowden

Image
Title: Permanent Record Author: Edward Snowden ISBN: 978-1-250-23723-1 Price: US$18 from Amazon GH rating: 90% Summary Until I read this book, I considered my personal integrity a fundamental strength, core to my very being. It pales in comparison to Ed's extreme courage and intense determination to expose the shocking truth about the NSA's mass surveillance programme and the way it was concealed from Congress.

To what extent do you trust the robots?

Image
This Sunday morning, fueled by two strong coffees, I'm cogitating on the issue of workers thoughtlessly disclosing all manner of sensitive personal or proprietary information in their queries to AI/ML/LLM systems and services run by third parties, such as ChatGPT. This is clearly topical given : (1) the deluge of publicity and chatter around ChatGPT right now, coupled with  (2) our natural human curiosity to explore new tech toys, plus  (3) limited appreciation of the associated information risks, and  (4) the rarity of controls such as policies and Data Leakage Protection technologies.  Furthermore, even if we do persuade our colleagues (and, let's be honest, ourselves!) to be more careful and circumspect about whatever we are typing or pasting into various online systems, the possibility remains that the general nature of our interests and queries is often sensitive.

March 20 - COVID-19 infosec awareness special

Image
Today I trawled through our back catalog of information security awareness content for anything pertinent to COVID-19. The "Off-site working" security awareness module published less than a year ago is right on the button.  "Off-site working" complements the "on-site working" awareness module, about the information risk and security aspects of working on corporate premises in conventional offices and similar workplaces. Off-site concerns the information risk and security aspects of working from home or on-the-road ( e.g. from hotels or customer premises), often using portable IT equipment and working independently ... which is exactly the situation many of us are in right now. Off-site working changes the information risks compared to working in purpose-built corporate offices. Mostly, the risks increase in line with the complexities of remote access, portability and physical dispersion … but offsetting that, off-site working can be convenient, productive...

Reflecting on privacy

Image
Anyone who read Orwell's masterpiece or saw the film "1984" appreciates the threat of mass surveillance by the state a.k.a. Big Brother. Anyone who has followed Ed Snowden's revelations knows that mass surveillance is no longer fanciful fiction. There are clearly privacy impacts from surveillance with implications for personal freedoms, assurance and compliance. At the same time, surveillance offers significant social benefits too, in other words, pros and cons which vary with one's perspective. Big Brother sees overwhelming benefits from mass surveillance and has the power, capability and (these days) the technology to conduct both overt and covert mass or targeted surveillance more or less at will.  The same thing applies to other forms of surveillance and other contexts: many of us gleefully carry surveillance devices with us wherever we go, continuously transmitting information about our activities, conversations, locations, contacts and more. We may call them...

Privacy awareness update

Image
Privacy is a  deeper, broader and more complex than it might appear, blending  personal, organizational and societal issues.  Privacy means different things to different people. Privacy and information security have a lot in common but each goes further.   Personal information is both sensitive and valuable, hence the associated information risks deserve to be identified, evaluated and treated in the same manner as other information risks.  Compliance with privacy laws and regulations such as GDPR should be a non-issue if the organization takes privacy seriously. However, there are specific obligations that need to be identified and satisfied. From an individual’s perspective, privacy is mostly about people retaining control over their own personal information ( e.g. being able to restrict its use and onward disclosure). From the organizational perspective, personal information is acquired, processed and exploited for various business purposes - hopefully with...

Conspicuous consumption

Image
A short article set me thinking this morning about the interplay between rights, compliance, personal freedoms, ethics and culture.  The article is about tax authorities picking up on conspicuous consumption by citizens, suggesting that they are 'living beyond their means' - a classic fraud indicator. Although the article specifically concerns disclosures through social media, that's just one of many ways of voluntarily disclosing information. Furthermore, some disclosures are involuntary: the authorities can demand information from and about us, for example, and we  inadvertently or incidentally   disclose information about ourselves in the course of living our lives. The tax authorities have to address tax fraud, of course, using relevant information legitimately obtained from anywhere ... but in this situation the information was not disclosed for that specific purpose. Tax fraudsters would happily prohibit the authorities from accessing and using the information if t...

Security awareness on oversight

Image
We bring the year to a close with an awareness and training module on  a  universal control  that is applicable and valuable in virtually all situations in some form or other.    Oversight  blends monitoring and watching-over with directing, supervising and guiding, a uniquely powerful combination. The diversity and flexibility of the risk and control principles behind oversight are applied naturally by default, and can be substantially strengthened where appropriate. Understanding the fundamentals is the first step towards making oversight more effective, hence this is a cracker of an awareness topic with broad relevance to information risk and security, compliance, governance, safety and all that jazz. It’s hard to conceive of a security awareness and training program that would not cover oversight, but for most it is implicit, lurking quietly in the background.  We have drawn it out, putting it front and center.   In the most general sense...

Dynamic authentication

Image
It is hard to authenticate someone's claimed identity: Quickly; Consistently and reliably to the same criteria at all times; Strongly, or rather to a required level of confidence; Cheaply, considering the entire lifecycle of the controls including their development, use and management; Practically, pragmatically, feasibly, in reality; On all appropriate platforms/systems/devices (current, legacy and future) and networks with differing levels of trustworthiness and processing capabilities; Under all circumstances, including crises or emergencies; For all relevant people (insiders, outsiders and inbetweenies), regardless of their mental and physical abilities/capacities, other priorities, concerns, state of health etc., while also failing to authenticate former employees, twins (evil or benign), fraudsters, haXXors, kids, competitors, crims, spooks, spies, pentesters and auditors on assignment; Using currently viable technologies, methods, approaches and processes; and Without relyin...

Smart assurance

Image
With just days to go to the delivery deadline, April's security awareness module on assurance is rounding the final corner and fast approaching the finishing line. I've just completed updating our 300+ page hyperlinked glossary defining 2,000+ terms of art in the general area of information risk management, security, privacy, compliance and governance. Plus assurance, naturally. As I compiled a new entry for Dieselgate, it occurred to me that since things are getting smarter all the time, our security controls and assurance measures need to smarten-up at the same rate or risk being left for particulates. Emissions and other type-testing and compliance verification for vehicles needs to go up a level, while the associated safety and technical standards, requirements, laws and regulations should also be updated to reflect the new smart threats. In-service monitoring and testing becomes more important if we can no longer rely on lab tests, but that creates further issues and risks...

More biometric woes

Image
In the course of a routine eye checkup yesterday, the optician took and showed me high-definition digital images of both my retinas. Fascinating!  This morning while in the dual-purpose creative thinking + showering cubicle, I idly wondered about the information risks. Could I trust the optician to have properly secured their systems and networks, and to have encrypted my retinal images to prevent unauthorized disclosure? If not, what impact might such disclosure cause, and what are the threats?  I don't personally use retina-scanning biometric authentication, and I seriously doubt anyone would be desperate enough to steal and use my retinal images to clone my identity (given other much easier ways to commit identity fraud) so I'm not that fussed about it - it's a risk I'm willing to accept, not being entirely paranoid.  I'm curious about the risk on a wider level though: are opticians and other health professionals adequately securing their systems, networks, apps ...

Peripheral vision

Image
Part of security awareness is situational or contextual awareness - being alert to potential concerns in any given situation or context. At its core, it is a biological capability, an inherent and natural part of being an animal.  Think of meercats, for instance, constantly scanning the area for predators and other potential threats. We humans are adept at it too, particularly in relation to physical safety issues. The weird creepy feeling that makes the hairs stand up on the back of your neck as you wander down a dark alley is the result of your heightened awareness of danger triggering hormonal changes. A rush of adrenaline primes you for the possible fight or flight response. I'm talking here about reflexes acting a level below conscious thought, where speed trumps analysis in decision-making. When 'something catches your eye', it's often something towards the edge of your visual field: peripheral light receptors coupled with the sophisticated pattern-recognition cap...

Email security

Image
As part of the background research for next month's awareness module on 'email and messaging security', I figured it is about time I got to grips with secure email. You'd have thought I'd be on top of it already, given that my career started nearly 30 years ago with email system administration and then information security! Truth is, I've managed OK without it until now. The few times I have really needed to send secure email, I have either used a secure webmail facility provided by the client or achieved the same ends using AES-encrypted WinZip archives, sharing the secret password off-line. Now, I find myself needing to communicate securely with a company that doesn't offer secure webmail but does (allegedly) use PGP for secure email. Hmmm. Today I re-discovered a key reason for not bothering with secure email - the very same reason that has caused me to try, fail and give up previously. The process of configuring MS Outlook - a commonplace, mainstream ema...

Raising awareness of surveillance risks

Image
We have just uploaded the latest awareness module on surveillance for our subscribers.  As you’ll appreciate from the word cloud, this is fascinating topic, something we hope will really catch workers' imaginations and so get them thinking and chatting (an awareness win!). Our two main areas of focus in the new module are:  (1) Surveillance of various kinds conducted by the organization ( e.g. CCTV coverage of public and controlled areas, network traffic monitoring, system security and audit logs, spam and malware scanning); and  (2) Surveillance conducted on the organization and its workers by various third parties ( e.g. compliance monitoring by various authorities, and industrial espionage or spying by competitors). With some exceptions, the former is authorized by management for legitimate business purposes, while the latter can be sinister ( e.g. Big Brother and industrial espionage). The tools and techniques to mitigate the risks include counter-surveillance...