Posts

Website attack exposure metric

Image
Page Rank versus  Internet attack rate - a worked example of the metrics selection/design process In theory, organizations that establish a substantial web presence for marketing reasons are also, potentially, setting themselves up as high-profile targets for Internet-based attacks.   But is the premise true?   Are organizations that maintain high-profile websites attacked more often from the Internet than those that maintain a low profile?   Let's try to address the question by developing a metric using the  PRAGMATIC  approach. Most websites are routinely scored or ranked by Internet search engines and social networking sites.   Some popularity measures are distinctly dubious, however, but  Google Page Rank   is a simple, widely-used and well-respected measure of the visibility or popularity of a website, so that part of the equation is easy enough.  To measure Internet-based attacks, w e might count up the number of web-related inform...

SMotW #47: inactive user accounts disabled

Image
Security Metric of the Week #47:  proportion of inactive computer user accounts disabled in accordance with policy To calculate this metric, someone first checks how many inactive user accounts there were on the systems in total, and then how many of them were disabled as they should have been according to ACME's policy during the reporting period ( e.g. this calendar quarter). Counting inactive accounts is tedious if it involves manually checking activity records maintained by the individual IT systems, but easier if the checks can be performed by running scripts on a limited number of shared/centralized network user authentication systems (such as domain servers for Windows domains), in which case this becomes a fairly straightforward and useful compliance measure. ACME's management determined the following  PRAGMATIC  numbers for this metric: P R A G M A T I C Score 68 56 74 76 73 64 64 52 75 67% The PRAGMATIC ra...

The bloggings will continue until morale improves

Image
I've just noticed that, according to Blogger, this is my 1,000th piece on this blog since 2005, an average of about 10 a month.   In fact, I published  a few hundred more on the previous blog platform but I've long since forgotten how many, and it doesn't matter much anyway. Just in case you are the least bit interested, here are the top ten most popular posts according to the mimimalist statistics that Blogger gives me: A distinctly cynical piece about the launch of the Information Security Awareness Forum - a laudable British initiative unfortunately overshadowed by a lack of focus and the competing interests of its commercial sponsors.  I guess the ISAF website is still running but updates are few and far between, while the associated blog's domain has expired.  Such a shame, yet another missed awareness opportunity.  A short note about a NIST paper Directions in Security Metrics Research (NISTIR 7564).  The paper outlined a bunch of possi...

How-to security awareness guide from ENISA

Image
Re-reading ENISA's excellent how-to guide on security awareness  has spurred me into getting ready to update our  Information Security 101  module    The guide is strong on the purpose and objectives for security awareness: "An information security awareness programme will: Provide a focal point and a driving force for a range of awareness, training and educational activities related to information security, some of which might already be in place, but perhaps need to be better coordinated and more effective. Communicate important recommended guidelines or practices required to secure information resources. Provide general and specific information about information security risks and controls to people who need to know. Make individuals aware of their responsibilities in relation to information security. Motivate individuals to adopt recommended guidelines or practices. Create a stronger culture of security, one with a broad understanding and commitment to infor...

Malware & APT awareness

Image
Malware is a core information security topic, something that virtually every security awareness program covers. As such, we update the malware module once a year to remind our audiences about the ever-present malware risks ... which means we have covered it several times already and, to be frank, we're getting ever so slightly bored by it! We try to find different angles every time to keep interest levels up: t his year, thanks to a customer suggestion, we have focused on APTs - Advanced Persistent Threats - which combine sophisticated malware with other methods of penetrating targeted organizations, hence there are a few mentions of social engineering, hacking and physical intrusion as well as classic malware in the module. A recent upsurge in reports, mostly from the US, about the Chinese state-sponsored spies and hackers is timely since APTs are undoubtedly part of their arsenal. However, Stuxnet (at least) was an APT attack allegedly sponsored or conducted by the US plus Israel...

Security awareness: it's easy, right?

Anyone can 'do' security awareness.  It's easy, right?  Tell staff to choose strong passwords, avoid dodgy websites, and comply with policies and procedures, and the job's a good 'un.  Bish bash bosh, is it time to go home already? OK, smarty-pants: try writing something meaningful and worthwhile about information security for a non-technical audience, people who 'have things to do' or 'have a life', don't particularly care about information security, have limited attention spans and negligible vocabularies. For a genuine challenge, limit yourself to the "ten hundred" most common English words . If you can say what has to be said without it coming across as a condescending finger-wagging lecture to a six-year-old, congratulations, that's one hurdle cleared.   For bonus marks, make it engaging, action-oriented or motivational in style, sufficient to persuade your audience not just to nod sagely as if they actually give a toss, but to...

SMotW #46: IT capacity and performance metric

Image
Security Metric of the Week #46: measuring IT capacity and performance The capacity and performance of IT services, functions, systems, networks, applications, processes, people etc . are generally measured using a raft of distinct metrics addressing separate pieces of the puzzle.  Collectively, these indicate how 'close to the red line' IT is running.   Conceivably the individual metrics could be combined  mechanistically to generate a single summary metric or indicator giving an overall big-picture view of IT capacity and performance ... but more likely in practice is a dashboard-type display with multiple gauges showing important metrics in one view, allowing the viewer to identify which aspects of IT performance and capacity are or are not causing concern, and perhaps dig down for still more details on specific gauges.  Glossing over the question of precisely what is shown on IT's capacity and performance dashboard, let's see how ACME Enterprises scored the metri...