Posts

Blowing the whistle

Image
No, Panera Bread Doesn’t Take Security Seriously is a heartfelt piece by Dylan Houlihan regarding a company that was notified responsibly of a privacy breach but apparently failed to act until, some 8 months later, it was informed by Brian Krebs. Then, all of a sudden, it reacted. This is far from the first time a genuine, well-meaning whistleblower has been callously rebuffed or studiously ignored. Organizations clearly need strategies, policies and procedures for receiving and dealing with incident notifications and warnings of all sorts.  Doing so makes sense for several good reasons: Business reasons e.g . hacking, fraud, privacy breaches and other inappropriate disclosures; Compliance reasons e.g . PCI-DSS and [soon] GDPR; Ethical/social reasons e.g . offensive/inappropriate behavior or bribery & corruption by workers, failure to uphold corporate social responsibilities; Bringing those responsible for various issues to account.  So why don't they? Lame excuses inclu...

No foolin

Image
We have  published the security awareness module on assurance, I assure you. Rest assured, the module is on its way . For sure. This is not a test.  We're no April fools, har har. Assurance is a broad topic, stretching well beyond the obvious assurance-related functions such as Audit and Quality Assurance ... which makes it a surprisingly strong subject for security awareness purposes - our 64th topic in fact.  Although we haven't produced an assurance module as such before, we've certainly touched on it in subjects such as integrity, trust, audit and oversight. We have seized the opportunity to focus-in on and explore assurance in more depth … while at the same time reinforcing core awareness messages on the integrity, trust and control value of assurance, for business, compliance, management (including risk management) and governance reasons. In uncertain situations or circumstances, assurance can be extremely valuable, particularly where uncertainties concern inform...

Quality assurance

Image
Our own assurance measures kick into top gear about now with the impending completion of the next awareness module - specifically proofreading and final corrections on the awareness materials before they are packaged up for delivery. Like any craftsmen, we take pride in our work. It's what we do , our specialism. We strive to make our output as good as we possibly can, a perfectionist streak that probably goes beyond what's strictly necessary. It flows from our deep-set belief in the value of integrity, both as individuals and as a business.  It matters. Quality assurance is integral to our production process. Checking our finished work (quality control) is the final stage and an opportunity for me to take stock. Having had my head inside the topic all month, it's good to step back for a look at the whole package of awareness goodies as it comes together. Provided the proofreading reveals few issues, I'm reassured that we did a good job, bringing the month's activit...

Smart assurance

Image
With just days to go to the delivery deadline, April's security awareness module on assurance is rounding the final corner and fast approaching the finishing line. I've just completed updating our 300+ page hyperlinked glossary defining 2,000+ terms of art in the general area of information risk management, security, privacy, compliance and governance. Plus assurance, naturally. As I compiled a new entry for Dieselgate, it occurred to me that since things are getting smarter all the time, our security controls and assurance measures need to smarten-up at the same rate or risk being left for particulates. Emissions and other type-testing and compliance verification for vehicles needs to go up a level, while the associated safety and technical standards, requirements, laws and regulations should also be updated to reflect the new smart threats. In-service monitoring and testing becomes more important if we can no longer rely on lab tests, but that creates further issues and risks...

Assurance and business continuity

Image
Business continuity management involves three distinct but complementary approaches: Resilience arrangements aim to maintain essential/critical information services despite incidents if at all possible, at a reduced, fallback or emergency service level at least; Disaster recovery arrangements to recover and restore services that have failed for whatever reason (including failed or overwhelmed resilience); Contingency arrangements to help the organization cope with whatever situations turn up unexpectedly (including failures in the other approaches, plus other novel incidents and crises, unfortunate coincidences and extreme/outlier risks involving  Little Green Men From Mars ). Resilience is often neglected or misunderstood, yet it’s a valuable approach with benefits under normal operational conditions as well as during and following major incidents. Plenty of capacity generally means good performance, for instance. Assurance is another advantag...

Repetitititition

Image
It is often said (repeatedly in fact) that repetition is the key to learning. Well is that true? Is that a fact? It must be true if it is said often enough, surely?   This blog piece is about using and misusing repetition as an awareness technique, repeatedly. You may have come across the classic 3-step tell-em technique for classes, lectures and seminars: Tell them what you're about to tell them about. Tell them it. Tell them about what you told them about. It's a simple, or rather simplistic approach, a crude technique based on simple repetition. You have probably sat through repetitive classes, lectures and seminars by teachers or speakers that follow the advice slavishly, every time, some of them even pointing out what they are doing as if that helps. It's obvious, without being pointed out. You don't need to tell us that you're using the tell-em technique!  In my experience, the tell-em technique is most often used by teachers and presenters who are not comfort...

Assurance metrics

Image
Today I'm writing about 'security assurance metrics' for April's awareness module.   One aspect that interests me is measuring and confirming (being assured of) the correct operation of security controls.  Such metrics are seldom discussed and, I suspect, fairly uncommon in practice. Generally speaking, we infosec pros just  love measuring and reporting on incidents and stuff that doesn't work because that helps us focus our efforts and justify investment in the controls we believe are necessary.  It also fits our natural risk-aversion. We can't help but focus on the downside of risk. Most of us blithely assume that, once operational, the security controls are doing their thing: that may be a dangerous assumption, especially in the case of safety-, business- or mission-critical controls plus the foundational controls on which they depend ( e.g. reliable authentication is a prerequisite for access control, and physical security underpins almost all other forms o...