Showing posts with label ISSA. Show all posts
Showing posts with label ISSA. Show all posts

Sunday, May 17, 2020

Program Maturity - Cyber-security and Operational Risk Maturity

The Balancing Act

In reviewing my LinkedIn notifications I was wonderfully surprised to find  an article written by Gideon T. Rasmussen, VCISO topic: Cyber-Security and Operational Risk Maturity.  As soon as I saw it I was thinking this is center to our consulting business I better pay attention. So here we go.


As Gideon T. Rasmussen comments on leveraging risk I immediately get hooked.  How can you even begin to understand your operational and situational awareness with out at first understanding your risk.  At Integris Security we advise our clients if not done within the past twelve months get a solid risk assessment done ASAP!  This risk assessment can then help you set priorities, establish tactical and strategic budgeting, technology goals and priorities and help you weigh your operational risk.  We at Integris believe this will improve the overall maturity of your cyber and operational approach.  But let's go on and see what else Rasmussen's nicely laid out article reveals.

Rasmussen's talks about U.S. Department of Commerce's,  N.I.S.T. (National Institute for Science and Technology).  For a great many of us in the IT security practice N.I.S.T. for years has been the go to "tool shed" for in-depth building blocks.  Their publications can take you from the very beginning of ....   What should I do? Where do I start? To a polished well informed presentation.   N.I.S.T. has a great many publications and they are 100% free.

The F.F.I.E.C., also provides great free guidance.  The men and women of the Northeast Chapter of the F.F.I.E.C., are your local financial services regulators.  You should get to know them, work with them and understand how they are approaching many of the same issues we all are trying to tackle every day.  Integris Security highly recommends you  review the regulators guidance and find answers to your company's compliance problems. These tools are also 100% free and incredibly useful information.

I do take issue with Rasmussen regarding this statement:
"There are no requirements for disaster recovery or business continuity. The card brands do not care if your business goes under, as long as their payment card data is secure." 
This is a nit, and can also be style but the point has to be made.  Their are literally hundreds of best practices for disaster recovery and business continuity and they should be put to use, despite the lack of attention by card brands to advise this.  Promotion of best practices is something we owe to the industry as a whole in our writings and presentations.  Taking on the Card Brands for lack of attention to Rasmussen's legitimate concerns would do better as a separate article, another a day and time in my eyes. We're talking Cyber-Security and Operational Risk Maturity.  At Integris Security we push all to stay focused.  Good practice is too important to relegate to tomorrow's news.  Let's keep it up front and worthy of continual presence and persuasion in our discussions in how to improve cyber-security and operational risk maturity.

In maturity level II, I love this discussion of controls and it reminds me of C.O.B.I.T., as well as the many information security joint forums held with ISACA in years past and their auditor/members.  You gotta love the structure that these individual professionals have developed and the principles that they follow.  This is a serious group of security professionals and we could all learn allot from them.  Rasmussen then lays out the common controls read: GAP analysis, and Risk based deployment of controls, while not much new here he provides a great review.  All solid material for a CEO and others within the organization to read and understand when weighing decisions on investment in the security program or cutting the fat off an already lean program.  These decisions will not be easy ones for sure.

My own note here:

The Cyber-Security and Operational Risk Maturity discussions can not be left alone to the operational business units, departments or divisions of your company.  These discussions need to expand and involve audit committee's at the board level and become a fluid ongoing discussions lead by the chair of the audit, technology and other important committees as the board and operational personnel try to achieve a balance of risk Vs reward and continue to build market value for the company's shareholders and investors.
 Joseph R. Concannon             

In maturity level III, Risk Management, Rasmussen covers it nicely and I smiled as he stated:
"It is necessary to tailor controls to the organization and to adapt to changes in the threat landscape."
Nicely done Gideon T. Rasmussen, these words couldn't be truer.  It also reminds me to tell our readers to remember that each organization has its own culture.  Some are very risk sensitive and others not so much so.  I often use Johnson and Johnson and Martha Steward Living as examples.  Two great companies but their approach to security was night and day.  Johnson and Johnson a security controls organization (almost war like) and Martha Steward Living a creative design firm.  The cultures were completely different at the time of my interview with security personnel.  Management of your and the company expectations are very important.  Don't get ahead of your skates or you  may get caught off balance.  Knowing the culture of your organization is key and very important.  Now that you have new security and risk management information in hand how do you operationalize it?  The best advice is work with your team and leader and try to introduce incremental improvements to improve your organizations overall security/risk posture.  This will work to your benefit for the short term tactical business operations as well as long term strategic planning for important improvements.

Your threat and vulnerability map will be constantly evolving, as targets and priorities come and go.  The risk assessment report provides you with items for your to-do list.  The report will show best practices and offer a target rich list for you to prioritize.  Rasmussen I believe understands this and covers it nicely and provides some bonus points by laying out some bullets for a prospective slide deck to communicate your findings and setting some future objectives.

The Risk Register is a platform to inform and Rasmussen points this out clearly.  Want to know more about your risk?  The Risk Register is a place you want to go to identify, define, understand impact, respond, prioritize, and take notes.  Its an invaluable tool given to us by the folks from project management.

Maturity level IV, Strong Risk Management, Rasmussen lays out a ten step program.


Rasmussen says:


1. There is appropriate separation of duties in the CISO’s reporting structure, such as reporting to the CEO, Chief Risk Officer or Board of Directors. When the CISO reports to the CIO, it is a conflict of interest  2. Cyber-security metrics, KPIs and KRIs feed into an Enterprise Risk Management program.  3.The CISO provides updates to the Board of Directors or similar executive group.  4.The cyber-security program maintains controls specific to line of business products, services and assets. 5. A process management program is in place, to include policy, an inventory and process risk analysis.  6. A fraud prevention program is in place, to include fraud risk assessments conducted by an independent third party. 7. An operational risk management function maintains a risk scenarios inventory and conducts quantitative risk analysis. 8.The organization leverages the Three Lines of Defense Model, with active support from operational management, risk management and compliance functions and internal audit. 9.  Operational functions and lines of business are required to declare self-identified audit issues, with metrics in place to demonstrate the control environment is improving continuously 10. Incident response and business continuity exercises are conducted annually to include senior executives, lines of business leaders, information technology, legal, public relations and critical suppliers
This information is a like having a great cyber-security road map.  However, just like any road map their are going to be detours, accidents, potholes and your going to need the awareness, patience and skills to work around it all.  If you follow the program laid out by Rasmussen you'll be in a better position to mitigate those great unknowns and navigate your way freely from obstructions.

At Integris Security we say: you make it, we make it secure!  We look forward to having these and many other important discussions with you and really enjoyed our read of Gideon T. Rasmussen's LinkedIn article concerning Program Maturity - Cyber-Security and Operational Risk Maturity and hope that you will too!  Their is much to learn and many experiences to endure before we can truly say we're secure.


#Cyber-Security  #HomelandSecurity  #InfraGard #ISSA #ISACA #FFIEC #NIST










Saturday, May 2, 2020

Big Data: Security, Trust and Integrity

In information security the jewel of all certifications is the CISSP (certified information systems security professional).  The certification is your entry key into the top tier cyber security jobs and earned respect of your peers in the industry. 

The group that hosts the coveted CISSP certification is (ISC)2: the world's leading cyber security professional organization.  They actively promote their members and insist you want one our people at the switch if threats of an attack are at your doorstep. 

A great many information security professionals have earned this certification and live up to its standards and for that they are proud card carrying members.  I salute them for their achievement. 

One of the most important aspects of the certification in my eyes is the code of ethics.  The code of ethics tells you something about the individual and the organizations they belong to.  (ISC)2 spares no dime on its code.  The code of ethics is huge and prominent.  Honor and duty are fundamental in any cyber security career.  The group lays it out like this:

  • Our code
  • Code of ethics preamble
  • Code of ethics canons
We again salute (ISC)2 for their outstanding work.  Note well that prominence of the code, its preamble and canons can not replace the responsibility of the issuing organization to aggressively maintain the standards so that they ensure its integrity.  The organization owes it to its members to police itself and has a complaint procedure, ethics committee and international working group.

As data becomes accessed from hundreds and in some cases thousands of sources we reflect on the role of the information security professional has in the work place and what a pivotal role it is.  Untimely and inaccurate intelligence/data can cause food supply shortages, it could run up the price of a barrel of oil and shift geopolitical affairs world wide.  The use of big data and concerns around integrity have never been more critical and important.  

The role of the CISSP member becomes exponentially more important and his/her integrity should not come in question, hence the focus on "Big Data" in this article.  Data can shift global markets, take down thriving economies and strip citizens of their bill of rights so the importance and focus on this topic is both timely with a need to be accurate.  As governments and citizens react to COVID-19 the initial focus was on data driven models which reported that millions were in peril if the US Government did not act quickly.  Today we see state governments restricting the movement of its citizens, baring them from accessing their properties (Michigan), removing business and liquor  licenses from businesses who refused to comply (Maine) and here in NYC the issuance of one thousand dollar fines if you are found in non compliance - wear your mask, don't get closer than six feet or else!  

As time passes we are learning that models are just that models.  Accuracy depends on the information you put into models we have learned and if the data is awful so is the model and its outcome. Thus data its custodians and security personnel take heed. I think I made the case, data its timeliness and accuracy is very, very important.  The integrity of data custodians, security personnel has never been more acute.

 

Friday, October 21, 2016

Cyber Security Month: Looking for Answers Part II?


NEW YORK METRO JOINT CYBER SECURITY CONFERENCE
NY Metro Joint Cyber Security Conference
I recently attended the Third Annual New York Metro Joint Cyber Security Conference (http://nymjcsc.org/), held in mid-town Manhattan.  Security conferences are now a dime-a-dozen, but this event is unique in that it is a collaborative effort developed by a consortium of eight leading security, audit, and risk focused, NY metropolitan area, not-for-profit professional associations. Each organization brings its best to the table, creating a rare combination of expertise and diversity of talent.  

There were many informative sessions – some standing room only – but some of the greatest value was in the interaction with the other professionals.  For example, in sessions, we learned that security professionals must adopt the language of Directors to be understood by a Board.  The Internet Security Alliance is even working on metrics for Boards to use in evaluating security risks and controls.  But, after all the talk of security maturity models, cyber risk management frameworks, and “cyber balance sheets,” CISOs (Chief Information Security Officers) will tell you that Boards still “just don’t get it” and don’t seem to be that interested.  Perhaps CISOs as a group aren’t very good at explaining how greater focus on preventing and mitigating cyber threats is in the self-interests of very diverse sets of Directors.  Maybe, despite approaching the problem with the best of business concepts and lingo, CISOs just don’t have influence with Directors.  (As one CISO put it, “formulas don’t work.  Relationships do.”) Or, perhaps it’s because, as one speaker put it, there is not a single instance of a cyber breach that has been demonstrated to have a material impact on a company.  In the end, the surprising takeaway may not be that CISOs are becoming more adept at speaking the language of the Board, but that some Boards are beginning to listen at all.
This sold-out event offered excellent, high-quality presentations with plenty of actionable content.  If you weren't able to attend, you can still benefit from the recordings of many of the sessions.  They are available at http://livestream.com/internetsociety/nymjcsc/.  Presentation slides may be found at http://tinyurl.com/z3fz44d. I would highly recommend reviewing them.
And, don't forget to sign up early for next year's conference.  It's one of the best values in information security education that you'll find anywhere.  Follow www.nymjcsc.org and @NYMJCSC for details.

Phil Froehlich is Chief Operating Officer of Integris Security and a member (who listens) of the Executive Board of New York Metro InfraGard.

Cyber Security Month: Looking for Answers: Part I?


LONG ISLAND BUSINESS NEWS
LI Business New Cyber Conference
Hilton, was once again informative, invigorating and enrolling. With a number of panelists participating, including both the Integris Security CTO, Blake Cornell, and United States Congressman US District 1, Lee Zeldin, nearly 100 individuals attended the breakfast event.
Topics of interest had included Cyber Terrorism, Business Continuity, Government Legislation, Small Business Best Practices and other wide ranging topics. Some of the information shared, information that attendees can use in their day to day business operations.
A goal of Integris Security CTO, Blake Cornell, was to provide “simple and sound information that is short and sweet” further stating that “if your employees are untrained then no amount of technical information will help them understand. You can’t make them understand but you can help them understand”.

Blake Cornell is the CTO of Integris Security LLC.

Thursday, December 18, 2014

Banks: Federal/State Rules

No holiday would be complete with out a stern warning to the banking industry from both state and federal regulators, right?  Ho, ho, ho Merry Christmas - can you please assure us that your security controls are in order!

I was going to review Governor Andrew Cuomo's Department of Financial Services as it pertained to "new" security regulations for chartered banks in New York State.  The Superintendent of the Department of Financial Services initiated a press release and letter to chartered New York financial institutions.  After reviewing the memo I concluded that if all companies implemented the items in the Superintendent's letter, the public and private industries would be in a much better place. 

Then late yesterday the FFIEC (federal financial institutions examination council)  OCC (Office of the Comptroller of Currency) spokesman Joel Anderson spoke up.  Mr Anderson responding in a interview in American Banking Magazine stated, "we already do this" and what's going on in New York is nothing new. 

This is what New York DFS said they would look for:

New Rules: NYS
  • Corporate governance, including organization and reporting structure for cyber security related issues;
  • Management of cyber security issues, including the interaction between information security and core business functions, written information security policies and procedures, and the periodic reevaluation of such policies and procedures in light of changing risks;
  • Resources devoted to information security and overall risk management;
  • The risks posed by shared infrastructure;
  • Protections against intrusion including multi-factor or adaptive authentication and server and database configurations;
  • Information security testing and monitoring, including penetration testing;
  • Incident detection and response process, including monitoring;
  • Training of information security professionals as well as all other personnel;
  • Management of third-party service providers;
  • Integration of information security into business continuity and disaster recovery policies;
  • Cyber security insurance coverage and other third party protections
These are all things we at Integris Security does.

New York State then went on to list more topics which chartered banks in NYS would be expected to furnish.  We list them here for your review:


1.  Provide the CV and job description of the current Chief lnformation Security Officer or the individual otherwise responsible for information security, describe that individual's information security training and experience, and identify all reporting lines for that individual, including all committees and managers. In addition, provide an organization chart for your institution's IT and information security functions.
2.  Describe the extent to which your institution maintains information security policies and procedures designed to address the information security goals of confidentiality, integrity, and availability. Provide copies of all such information security policies.
3.  Describe how data classification is integrated into information risk management policies and procedures.
4.  Describe your institution's vulnerability management program as applicable to servers, endpoints, mobile devices, network devices, systems, and applications.
5.  Describe the organization's patch management program including how updates, patches, and fixes are obtained and disseminated, whether processes are manual or automated, and how often they occur.
6.  Describe identity and access management systems employed by the organization for both internal and external users, including all administrative, logical, and physical controls and whether such controls are preventive, detective, or corrective in nature.
7.  Identify and describe the current use of multi-factor authentication for any systems or applications.
8.  Describe your institution's due diligence process regarding information security practices that is used in vetting, selecting, and monitoring third-party service providers.
9.  Describe all application development standards utilized by the organization, including the use of a secure software development life cycle, and the extent to which security and privacy requirements are assessed and incorporated into the initial phases of the application development process.
10. Provide a copy of, to the extent it exists in writing, or otherwise describe, the organization's incident response program, including how incidents are reported, escalated, and remediated.
11. Describe the extent to which information security is incorporated into the organization's BCP/DR plan, how and how often the BCP/DR is tested, and the results of the most recent test.
12. Describe any significant changes to the institution's IT portfolio over the last 24 months resulting from mergers, acquisitions, or the addition of new business lines.

 Analysis:

It is a positive step forward for New York State Department of Financial Services to require its chartered financial institutions to meet minimum guidelines for the security of its information technology processes.  These security baselines are critically important not just to financial services institutions but to all public and private entities.  Since NYS has published these official rules it should now become the benchmark or de facto standard by which all other organizations are measured against.  These rules are appropriate and an outstanding starting point for any one who is not sure where to start.

The federal government provides an seemingly endless amount of guidance for the protection of information technology assets.  The fed's use the NIST framework and numerous NIST publications to assist everyone involved in the security of IT assets.  The federal regulators have been the go to professionals in the banking space for establishing standards so its not unusual to hear from Mr. Anderson of OCC or any of the regulators who are apart of the FFIEC. 

What is the news with this New York letter?  The federal regulators often calibrate their examinations according asset size.  Thus larger institutions receive more intense evaluation then smaller organizations.  However, New York has a very specific set of rules in which every institution must be prepared to comply with.  This is not a little matter and could have significant cost ramifications. 

Lastly, I have for years heard from administrators, mangers and CISO's who have tried to get budget authority to make the purchases necessary to secure their environments.  I am suggesting that security personnel use the NYS standards to present to CFO's as justification for future purchases.

http://dfs.ny.gov/about/press2014/pr1412101.htm

http://dfs.ny.gov/banking/bil-2014-10-10_cyber_security.pdf

www.americanbanker.com/news/bank-technology/occ-our-cybersecurity-exams-are-plenty-detailed-too-1071708-1.html

http://www.americanbanker.com/

Wednesday, December 3, 2014

The Rear View Mirror

Typical in the information technology sector everyone is always focused on what’s next, the latest, hottest new application, the coolest mobile telephone and of course the work around that just makes life a little easier.  Not to be ignored are all those newly fashioned functions and features. Technology at the speed of life forever changing our lives for the better, right?  Forward looking for ever.

2014 hopefully has hopefully taught us some very important lessons that should not be ignored even if we were not directly impacted.  A look in the rear view mirror can sometimes be very revealing.  We are so focused on what’s coming directly ahead of us that we refuse to see what’s going on right behind us.  So for 2014 let me list a couple of things which could have made this a better year in the security space.

Network segmentation: You can’t get there from here should be the mantra, no? Did we learn anything this past year? Network segmentation is the act or profession of splitting a computer network into subnetworks, each being a network segment or network layer. Advantages of such splitting are primarily for boosting performance and improving security.   Please review a great eWeek article clicking here.

Service Level Agreements: Service agreements are important and a quick web search can be helpful to identify some key questions for developing such important tools for your company. The Outsourcing Center has developed ten key questions for developing effective service level agreements. It’s a solid read and you’ll find plenty of similar research on the web. A service-level agreement (SLA) is a part of a service contract[disambiguation needed] where a service is formally defined. Particular aspects of the service - scope, quality, responsibilities - are agreed between the service provider and the service user. A common feature of an SLA is a contracted delivery time (of the service or performance). As an example, Internet service providers and telcos will commonly include service level agreements within the terms of their contracts with customers to define the level(s) of service being sold in plain language terms. In this case the SLA will typically have a technical definition in terms of mean time between failures (MTBF), mean time to repair or mean time to recovery (MTTR); identifying which party is responsible for reporting faults or paying fees; responsibility for various data rates; throughput; jitter; or similar measurable details. {Attribution: Wikipedia}

Too big to fail: While not at all a technical term your company would do well to heed this warning. No company is too big to fail. No one. In our recent newsletter we talked about the breach of the week. The roadway is littered with companies failing over and over again until everyone in the industry is just tired of hearing of another breach. The breaches become “white noise” a distraction from the good work being performed by many security professionals in the field. Fight complacency, challenge everything and everyone with respect and “ASK Questions”. It won’t make you popular but it will certainly make you a very, very valuable employee.  Please read the ARS Technica article   HERE because it puts good perspective of what can happen after a breach. 

Alarms: Alarms are invitations that are yelling out, “come investigate me” I’m making noise and need your direct undivided attention. Please don’t ignore alarms. The story goes like this: Hey did you hear that alarm go off? Yeah, I’m getting a cup of coffee – you want anything? Hey, maybe I’ll come with you. Great! How many times do we ignore the obvious? Alarms are put in place for a reason to warn us, right? If the alarms are not configured appropriately and are creating noise, then someone has to go in and make a determination to turn them down and accept the consequences or turn them up and act each time they alert. 

Egress Filtering: Is that a freight train of information running out of our company? Egress filtering is protecting what’s going out as well as protecting others from malware coming from inside your own company. In computer networking, egress filtering is the practice of monitoring and potentially restricting the flow of information outbound from one network to another. Typically it is information from a private TCP/IP computer network to the Internet that is controlled. Egress filtering helps ensure that unauthorized or malicious traffic never leaves the internal network. In a corporate network, typical recommendations [2][3][4][5] are that all traffic except that emerging from a select set of servers would be denied egress. Restrictions can further be made such that only select protocols such as HTTP, email, and DNS are allowed. User workstations would then need to be configured either manually or via proxy auto-config to use one of the allowed servers as a proxy. Corporate networks also typically have a limited number of internal address blocks in use. An edge device at the boundary between the internal corporate network and external networks (such as the Internet) is used to perform egress checks against packets leaving the internal network, verifying that the source IP address in all outbound packets is within the range of allocated internal address blocks. The purpose is to prevent computers on the internal network from IP address spoofing. Such "spoofing" is a common technique used in "Denial of Service" attacks. {Attribution: Wikipedia}

Enumeration: Thanks to Wikipedia we know that Network enumeration is a computing activity in which usernames and info on groups, shares, and services of networked computers are retrieved. It should not be confused with network mapping, which only retrieves information about which servers are connected to a specific network and what operating system run on them. Network Enumeration is the discovery of hosts/devices on a network, they tend to use overt discovery protocols such as ICMP and SNMP to gather information, they may also scan various ports on remote hosts for looking for well-known services in an attempt to further identify the function of a remote host. The next stage of enumeration is to fingerprint the Operating System of the remote host.

We hope that this short laundry list helps each of you.  We understand the complications of local, national and global enterprises.  None of this is easy, but neither is dealing with the stockholders and the media if your company falls victim to a breach or other such incident.

Thursday, October 9, 2014

Cyber Security Awareness Month

Now not half way into DHS Cyber Security Awareness Month and the industries leading computer organizations in NYC have hit the ground running with their first joint conference, a success,  ushered in without nearly breaking a sweat.

NY Metro InfraGard, ISSA, ISACA, OWASP, Cloud Security and others joined together with over 300 security professionals in Brooklyn, NY at St Francis College.  The lectures showcased outstanding sessions on Active Directory and a number of security and related discussions.
The all day event produced a Women in Security panel as the
afternoon plenary event.

Most attendee's remarked that this was the opening for the 2015 joint Cyber Security Conference which all believe will now be an annual event.  Congratulations to the organizing committee who persisted and stayed on course to make this important event happen.  A big thank you to St Francis College in Brooklyn for moving heaven and earth to make this happen and for being flexible during the days events.

We look forward to seeing more of this next year.