Posts

Critiquing NIST's Cyber Security Framework

Image
Today in the final stages of preparing the awareness module on "Security frameworks", I'm thinking and writing about the NIST C yber S ecurity F ramework  (CSF). For awareness purposes, there's no point describing and elaborating on the CSF in great detail, but I need to read and evaluate it in order to sum it up and comment meaningfully for our subscribers.  I'm investing m y time and effort partly on their behalf, partly for my own education: I'm interested in infosec standards, keen to discover NIST's take on 'cyber security', and on the look out for good security practices. So, indulge me for a moment as I talk you through the evaluation of just one small part of the CSF, specifically the core framework's advice on a wareness and training (denoted "PR.AT", making it the prat section :-). "The organization’s personnel and partners are provided cybersecurity awareness education and are trained to perform their cybersecurity rel...

ISO27k updates

Image
Slogging away tediously for 3 full days, I've caught up with a 3-month backlog of emails from the ISO/IEC JTC 1/SC 27 committee, picking out and checking through all the ISO27k-related items and updating our website . It's a laborious process but worth it, I think, to keep up with developments, especially as the ISO27k standards will feature heavily in July's awareness module on security frameworks. Here's a potted selection of news highlights on the ISO/IEC 27000-series standards : 27001 (ISMS) is likely to see some changes in the wording around risks and opportunities, and the Statement of Applicability. Hopefully the end result will be an improvement! The 27002 (controls) revision is starting to get to grips with reorganizing and tagging the information security controls. This is going to be a slog ... but at the end of it, there will be more flexibility for users of the standard, for example if you are auditing, reviewing or (re)designing the IT suite, it should ...

Critical of the critical infrastructure

Image
A comment at the end of a piece in The Register about the safety aspects making it tricky to patch medical equipment caught my beady eye: "Hospitals are now considered part of the critical national infrastructure in Israel and ought to be given the same status elsewhere". Personally, I'm not entirely sure what being 'considered part of the critical national infrastructure' really means, in practice. It may well have specific implications in Israel or elsewhere, but I suspect that's just stuff and nonsense. Those of you who don't work in hospitals, or in Israel, nor in critical national infrastructure industries and organizations, please don't dismiss this out of hand.  Ultimately, we are all part of the global infrastructure known as human society , or wider still life on Earth but it is becoming increasingly obvious that we are materially harming the environment  (= the Earth, our home) and if Space Force is real (not Space Farce ) then even the sk...

Happy solstice!

Image
10 o'clock this evening on June 21st is the Winter solstice for us down here in the Southern hemisphere. According to Wikipedia, we should be celebrating with "Festivals, spending time with loved ones, feasting, singing, dancing, fires". I lit the wood fire to warm the IsecT office before 8 this morning as usual. Having just fed the animals, I'm singing along to the radio as usual while I work. As to feasting, maybe we'll splash out on a special meal this weekend. Up there on the Far Side, it's Midsommerfest which means festivals, spending time with loved ones, feasting, singing, dancing ... but no fires, hopefully. Most people are looking forward to summer holidays, I guess. We're looking forward to longer, warmer days and spring lambs, talking of which our Prime Minister is in hospital having a baby. It's OK though because we have a caretaker PM keeping an eye on things. The next few weeks will be interesting in NZ politics.

Parting messages

Image
Advertisers know the value of a parting message at the end of an advertisement. It's something catchy to stick in the memory, reminding people about the advertisement or rather the messages the ad was meant to convey, generally concerning the brand rather than the specific product. Making ads memorable is one thing: making them influential or effective is another. Some ads are memorable for the wrong reasons, annoying and intrusive rather than enticing and beneficial. However, one man's hot button is another's cancel/exit. Ads are usually targeted at audience segments or categories, as opposed to everyone, though, so don't be surprised that you hate some ads and love others. Translating that approach to security awareness, the end of an awareness event is just as important as the start and the main body of the session. It’s your final chance to press home the key awareness messages and s et people thinking about the session as they wander off.  In the closing remarks a...

Metrics maturity metric, mmm

Image
Given that measurement can both establish the facts and drive systematic improvement, I wonder whether I might develop a metric to measure organizations' approach to security metrics?  Specifically, I have in mind a security metrics maturity metric (!).  Immature organizations are likely to have few if any security metrics in place, with little appreciation of what they might be missing out on and little impetus to do anything about it. In short, they are absolutely rubbish at it. Highly mature organizations, in contrast, will have a comprehensive, well-designed system of metrics that they are both actively using to manage their information risk and security, and actively refining to squeeze every last ounce of value from them. They are brilliant. Those two outlines roughly describe the end points of a maturity scale, but what about those in the middle? What other aspects or features have I seen in my travels, what other characteristics are indicative of the maturity status? E...

Infosec priorities

Image
I'm rapidly bringing myself back up to speed on information security frameworks for July's security awareness materials. Today, I've been updating my knowledge on the wide range of frameworks in this area, thinking about the variety of concepts, approaches and recommendations out there. There are several space-frame models. For some reason presumably relating to our visual perception, they are almost always symmetrical, often triangular or pyramidal in shape such as the ICIIP ( I nstitute for C ritical I nformation I nfrastructure P rotection) one above, developed at the USC Marshall School of Business in Los Angeles. The ICIIP model caught my eye back in 2008 shortly before ISACA adopted it as BMIS ( B usiness M odel for I nformation S ecurity ). Alternatively the shape might represent the magic number 3, or perhaps 9 (3 squared) counting the nodes and links of a triangular 'pyramid' (glossing over the fact that the ancient Egyptian pyramids have square bases and h...