Posts

The start is nigh

Image
With near-perfect timing, we're into the final stages of polishing off January's awareness module on IoT and BYOD security.   I say near- perfect because this is the last weekend of 2017 with just over a day remaining until 2018. After a week of chilly and miserable weather, an unseasonal polar blast, I'd rather be out enjoying the fine weather and getting ready for the traditional new year's eve celebrations!  The last section of writing took a bit longer than planned, but I'm confident we'll hit the delivery deadline.  Updates to the website are in hand and we'll be packaging and sending the materials to subscribers tomorrow, electronically that is. Looking forward, we've selected awareness topics for first few months of 2018 and written them up on our distinctly low-tech office whiteboard. We deliberately don't plan too far ahead (who knows what will crop up?) but it takes time to research and draft the materials. Having working titles and outline...

Slowly slowly catchee monkey

Image
As the end of month deadline looms, we're close to finishing January's awareness module on IoT and BYOD security.  Today I'm working on the awareness seminar slide deck and accompanying briefing paper for the audience group we call 'professionals', blue-collar workers essentially, specialists in IT, risk, security, audit, facilities, control, compliance etc. We dig a bit deeper into topic for that audience, but not too deep. The overriding awareness objective is to inform, intrigue, motivate and set them talking to their colleagues (other professionals plus the general and management audiences) about and around the topic. Awareness is not training, although there is a grey area and the terms are often confused.  Ultimately, we hope the pros will pass on some of their knowledge and enthusiasm for the topic to others, preferably with more than just a casual nod towards the information risk and security aspects.  IoT and BYOD are obviously IT-related, so the pro materi...

Inspirational security awareness

Image
Normally in security circles, the word 'exploitation' has the distinctly negative and foreboding connotation of some evil miscreant wantonly attacking and taking advantage of us ... but we'll be using the word in a much more positive sense in the IoT and BYOD security awareness materials for January. The topic presents a golden opportunity to point out that information security mitigates the substantial information risks associated with IoT and BYOD, risks that would otherwise reduce, negate or even reverse the business advantages. It's not entirely plain sailing, though, since the risks are context-dependent. Someone needs to identify and evaluate the risks and the corresponding security controls, in order to determine firstly whether the risks are truly of concern to the organization (they can't be avoided or accepted), and secondly whether the security controls are necessary and justified since there are costs as well as benefits. We've pump-primed the proces...

Government security manual

Image
An updated version of the N ew Z ealand I nformation S ecurity M anual (NZISM) - in effect the government's information security policy manual, or at least the public non-secret element - was released this month: NZISM is painstakingly maintained and published by the G overnment C ommunications S ecurity B ureau (GCSB) - our spooks in other words. It is a substantial tome, well over six hundred A4 pages split across two volumes. Part 1 (365 pages) covers: A brief introduction to the topic and the manual, in the NZ government context; Governance arrangements including overall controls such as accountability and responsibility, and compliance through system certification and accreditation, audits and reviews; Policies, plans,  S tandard O perating P rocedures plus emergency and incident response procedures; Change management; Business continuity and D isaster R ecovery management;  Physical security; Personnel security (including security awareness; Infrastructure securit...

Auditor independence [LONG]

Image
Over on the ISO27k Forum , we've been discussing one of my favourite topics: auditing, or more precisely the question of auditor independence.  How independent should an auditor be? What does that even mean, in this context?  SPOILER ALERT : there's rather more to it than reporting lines. My experienced IT auditor friend Anton posted some relevant definitions from ISACA, including this little gem: "Independence of mind: the state of mind that permits the expression of a conclusion without being affected by influences that compromise professional judgement, thereby allowing an individual to act with integrity and exercise objectivity and professional scepticism." While I agree this is an extremely important factor, I have a slightly different interpretation. 'Independence of mind', to me, is the auditor's mental capacity to examine a situation free of the prejudice or bias that naturally afflicts people who have been in or dealing with or managing or indee...

Sticky ends

Image
Surveys typically show that:  Most organizations have some form of BYOD scheme encouraging or permitting workers to use their own laptops, smartphones and tablets for work; and IoT is spreading fast but still has a long way to go before it peaks. We infosec geeks may throw up our hands in horror ... but the facts remain: BYOD and IoT are popular, now. They are here to stay  and almost certain to expand . It's too late now for us to bleat on about the information risks and security concerns*. The train has long since left the station. So how should we handle this situation? An obvious approach is to retrospectively identify, assess and treat the information risks as best we can, emphasizing threats such as hackers, malware, theft or loss of information, and inappropriate disclosure, and promoting security controls such as - well, that's where it gets tricky because we have limited options for technical controls, and (despite our best efforts!) security awareness is never going ...

The complexities of simplification

Image
From a worker's perspective, BYOD is 'simply' about being allowed to work on his/her own ICT devices, rather than having to use those owned and provided by the organization.  What difference would that make? It's straightforward, isn't it? Good questions! There are numerous differences in fact, some of which have substantial implications for information risk, security and privacy. For example, ownership and control of the device is distinct from ownership and control of the data: so what happens when a worker leaves the organization (resigns or is 'let go'), taking their devices with them? Aside from any corporate data on the devices, they had been permitted access to the corporate network, systems, apps and data.  The corporate IT support professionals had been managing the devices, and probably had access to any personal data on them.  Lines are blurred. In a similar vein, IoT is more than just allowing assorted things to be accessed through the Internet a...