Posts

Spinning the security awareness yarn

Image
The number and variety of information risks relating to email and inter-person messaging is both a challenge and an opportunity for the awareness program. On the one hand, there's a lot to cover hence no shortage of things to say. On the other hand, the coverage tends to be 'bitty' and quite superficial because we don't have time to go into everything in detail.   We tackle this in several ways: We mention a wide variety of issues illustrating the risk landscape. Diagrams such as the ARA graphic and mind maps are helpful, presenting lots of information in structured, visually-appealing and thought-provoking ways.  We use recent/current incidents, risks, controls and news concerning the topic to illustrate and draw out the key points as they stand today . As well as being topical, they turn the spotlight towards present and future issues rather than dwelling on stale news. We're running on Internet time here: yesterday is so last week. At the same time, we are where ...

P2P messaging

Image
The awareness module on email and person-to-person messaging is gradually taking shape. Today we've brainstormed the information risks associated with email and P2P messaging and arranged them on an Analog Risk Assessment graphic: So far, the risks are scattered across the green and amber zones with none in the red high-risk region. However, there are more than 20 risks already identified hence, taking them all into account, the cumulative risk is significant. Furthermore, many directly concern employees' insecure use of email/P2P systems - falling for scams, making typoos and inappropriately trusting the veracity of messages for examples. This is clearly an important topic for security awareness purposes. We'll reconsider, adjust and refine the risks as the module develops, using the ARA graphic to illustrate some of the briefing papers and presentations. By the way, phishing is but one of the 20+ information risks in this domain. Even if we group it with spear-phishing, w...

Security metrics pissing contest

Image
A lengthy white paper ably if inadvertently demonstrates the value of the PRAGMATIC approach . " Using Security Metrics to Drive Action " includes a page or three of advice from a bunch of mostly big-company CISOs concerning the security metrics they use to communicate security program effectiveness to business executives and the board. According to the report, Tenable asked 33 'IT security experts' the following question: "Your CEO calls and asks, “Just how secure are we?” What strategies and metrics do you use to answer that question?" Unfortunately, there is little consensus among the 33 contributors, with stark discrepancies between them in some cases. They don't even discuss metrics and measurement strategies in the same terms. Most wax lyrical on their favorite (pet) metrics, although some seem confused about the term, referring vaguely to areas of concern rather than actual metrics. Some say more about how to present metrics than what metrics to p...

Tree removal

Image
A productive weekend ... Before: During: After: Metrics for tangible things such as trees are more straightforward than for intangible things such as risks. We can easily see the progress being made as the tree is cleared, estimate how much work remains, calculate the value earned and so on. We could measure the height, spread and volume of the foliage section with a tape measure (or use a ruler on the photographs above), and weigh the firewood using scales. You could potentially verify our measurements, using your own measures and scales. We might need to convert the units, but the units of measure and the conversion factors are scientifically determined and generally agreed. There would inevitably be discrepancies in the measured values (we may need to repeat them or adopt other measurement methods) and estimates (such as the value of firewood). We might need to clarify certain parameters such as exactly what constitutes 'the foliage section'. With care it ought to be possibl...

NZISM

Image
I spent the whole day slogging through the N ew Z ealand I nformation S ecurity M anual ,  a typical government/large, mature organisation's infosec policy: detailed, lengthy (over 600 pages!), explicit and frankly rather tedious and boring.  We prefer a reader-friendly suite of individual policies covering a range of information risk, security, privacy and related topics . Each of our policies includes a short background section explaining why it is needed, the idea being to inform and convince the reader that it is in their interest as well as the organization's for everyone to comply. Topic-based policies are easier to manage, too, since nobody is expected to slog their way through hundreds of pages: most are less than 5 pages, of which the actual policy statements ("axioms") are just a couple of sentences with a page or so of supporting statements explaining, in straightforward language, how the policy is to be interpreted and applied in practice. Most of the day ...

Infosec innovation

Image
By sheer coincidence, the latest issue of the ISSA Journal , released today, covers cybersecurity innovation. Innovative approaches mentioned by various authors include: Machine learning, behavioral analytics and artificial intelligence; Deception technologies - the author describes honey tokens designed to detect malware accesses, and later hints vaguely at other emerging antimalware techniques; Browser isolation using virtual machines - which looks to me like an elaboration of the classic sandbox approach but perhaps I should check into that too; Cloud Access Security Brokers (CASBs) - hmmm, I shall be Googling that one shortly!; DevOps - with rapid/agile development techniques plus Continuous Integration, Continuous Delivery and microservices leading to sub-second cycle times for software updates, security testing and hardening becomes an enormous challenge. Security tools such as Docker Notary are forging new paths in the area of DevOpsSec and DevSecOps (are those the same or do th...

Announcing Uncommon Criteria

Image
While there is a desperate need for creative ideas or inventions in the general area of information risk and security controls, specifically for defensive purposes, the implementation phase of innovation is also in need of creativity and care. Information security products (both goods and services) that are inherently in secure are not uncommon, unfortunately. Aside from simple bugs, implementation issues, incompetence and ineptitude, we occasionally see evidence of fundamental security flaws in the designs, while rumours of backdoors being deliberately inserted by the authorities persist (partly a reflection of justifiable distrust in Big Brother).  Given the trusted nature of their products, social engineering, insider threats and subterfuge are likely to occur in organizations that produce security products .... so we also need innovation in the area of security assessment and certification of security products, as well as various internal security controls. In government a...