Showing posts with label Information Security veterans. Show all posts
Showing posts with label Information Security veterans. Show all posts

Saturday, May 2, 2020

Big Data: Security, Trust and Integrity

In information security the jewel of all certifications is the CISSP (certified information systems security professional).  The certification is your entry key into the top tier cyber security jobs and earned respect of your peers in the industry. 

The group that hosts the coveted CISSP certification is (ISC)2: the world's leading cyber security professional organization.  They actively promote their members and insist you want one our people at the switch if threats of an attack are at your doorstep. 

A great many information security professionals have earned this certification and live up to its standards and for that they are proud card carrying members.  I salute them for their achievement. 

One of the most important aspects of the certification in my eyes is the code of ethics.  The code of ethics tells you something about the individual and the organizations they belong to.  (ISC)2 spares no dime on its code.  The code of ethics is huge and prominent.  Honor and duty are fundamental in any cyber security career.  The group lays it out like this:

  • Our code
  • Code of ethics preamble
  • Code of ethics canons
We again salute (ISC)2 for their outstanding work.  Note well that prominence of the code, its preamble and canons can not replace the responsibility of the issuing organization to aggressively maintain the standards so that they ensure its integrity.  The organization owes it to its members to police itself and has a complaint procedure, ethics committee and international working group.

As data becomes accessed from hundreds and in some cases thousands of sources we reflect on the role of the information security professional has in the work place and what a pivotal role it is.  Untimely and inaccurate intelligence/data can cause food supply shortages, it could run up the price of a barrel of oil and shift geopolitical affairs world wide.  The use of big data and concerns around integrity have never been more critical and important.  

The role of the CISSP member becomes exponentially more important and his/her integrity should not come in question, hence the focus on "Big Data" in this article.  Data can shift global markets, take down thriving economies and strip citizens of their bill of rights so the importance and focus on this topic is both timely with a need to be accurate.  As governments and citizens react to COVID-19 the initial focus was on data driven models which reported that millions were in peril if the US Government did not act quickly.  Today we see state governments restricting the movement of its citizens, baring them from accessing their properties (Michigan), removing business and liquor  licenses from businesses who refused to comply (Maine) and here in NYC the issuance of one thousand dollar fines if you are found in non compliance - wear your mask, don't get closer than six feet or else!  

As time passes we are learning that models are just that models.  Accuracy depends on the information you put into models we have learned and if the data is awful so is the model and its outcome. Thus data its custodians and security personnel take heed. I think I made the case, data its timeliness and accuracy is very, very important.  The integrity of data custodians, security personnel has never been more acute.

 

Monday, April 27, 2020

Pandemic: Human Resource Help

A Resource no one should ignore


As some of you will no doubt know I do a lot of networking on LinkedIn.  I'm always interested in what's growing, what's moving and how to advance the story of our lives here in America.  Many of my professional connections are on LinkedIn and I am thrilled that I can reach into the resource from time to time seek the advice and opinions that they willingly provide.


This post is about exposing a resource whose time has come.  The need is here and people should pay attention to the depth and breathe of posts.  Its about helping others who may really be in a bind due to the downturn (self imposed) of our economy during this pandemic.  As we press forward and reopen our economy the endless opportunities will slowly give rise to America's unlimited potential which should be great news for everyone involved.

In the meantime, Andrew Seaman does a segment on LinkedIn called #Gethired and provides some tremendous resources that I have found to be just terrific and incredibly helpful.  Andrew is a great writer and inserts into his posts another resource of LinkedIn called LinkedIn Learning.  I have viewed many of the videos and taken a number of these courses and found the quality to be top notch.  He quotes experts from the field and links them in his posts for additional value.  I call that bonus points.

A take away from the resume course is in the table I'm inserting below.  Within a few minutes you can brighten your day and freshen up that resume with color and relevance.


Keywords
Tell a story
Contrast/Compare
Never give up

I was also interested in what LinkedIn was saying on its blog.  Yes, if you didn't know it LinkedIn has a blog and this is another terrific resource for all involved.  LinkedIn has managed to pull together a great team of individuals on its platform who do one terrific job of communicating.  That can not be understated.

That's what this post is all about.  Take a look at your LinkedIn account and drive some attention to the posts and resources that LinkedIn personnel and contactors have so handsomely put together in one place for your use.

@andrewseaman #Gethired

Thursday, April 16, 2020

Zooming not so fast....slow down

Video Conferencing Software/Weak Security?


Never Share Passwords
Keep Meeting ID’s Private
Make Use of Waiting Rooms

Zoom, the video conferencing software maker learned a lot of lessons this past month as a result of legions of new visitors who stopped by and signed up as new customers.  The software company Zoom updates from the past weekliterally exploded with new customers during Mid March 2020 as a result of the COVID -19.  However a number of security incidents started happening and with that a fire hose of commentary poured into their email boxes, security blogs, conference calls and forums.  Security professionals came on strong.  One security practitioner commented that the right out of the box the default settings needed serious review and the general public was at the point of the spear - buyer beware.  Waiting rooms, passwords, and many other enhancements all focused on security and reducing risk were heard from all quarters.  

To the credit of Zoom, now known as that easy, cheap video conferencing software have made the changes to improve security (change to many of the default settings, like requiring password as a default for all meetings, establishing a waiting room so you can verify participants and sprinkling of the message not to share passwords, etc) and reduce the risks to many of its users. Zoom has taken it on the chin for many in this functional area: "Video Conferencing Brands" while the rest of the pack gets the opportunity to take another look at security.  Zoom brought on a security professional and kinder days seem to be in the future. Zoom also has a HIPAA compliant application separate from what general users get to use.  See the photo above for the last known update from Zoom.  Zoom is growing and has been sending out improvements as they become available.

Video Conference Software:

Never Share Passwords
Keep Meeting ID’s Private
Make Use of Waiting Rooms



Here are some additional products for consideration:
  • GoToMeeting
  • Webex Teams
  • Skype for business
  • Google Hangouts
  • Join.Me LogMeIn
  • Amazon Chime
  • Microsoft Teams
  • Cisco Webex Meetings
  • Updox
  • Vsee
  • Zoom for healthcare
  • Spruce health care messenger
  • Apple Face Time
  • Doxy.me
  • Face Book Messenger Chat
  • Blue Jeans - recently purchased by Verizon
Check out each of these products and note well during a declared national emergency many if not all maybe used without compliance penalty.  However, after the emergency is over please do use HIPPA compliant software.  See shorturl.at/fijHL for future updates at U.S. H.H.S. dot gov.


NIST - Navigating the Conference Call Security Highway



Today 4/25/20 I reviewed an article from Dr Eric Cole, Secure Anchor Consulting. These are some of his thoughts:

Zooming now household word
Due to pandemic March/April 2020 video conferencing increases 1000 fold.  "Zooming" takes on a life of its own for all brands of video conference calling software.
ZOOM BOMBING:  DEFINED
Is where a person joins into Zoom video conferencing calls uninvited and either 1.) listens in, 2.) gathers important info to use at a later time or 3.) become disruptive to your meeting or event.
How do you protect a Zoom call?
    1. Remember you are a target, 2. Cyber security is your business, 3. Make sure your software is up to date. 

    • Make sure your computer operating system is up to date
    • Make sure your Zoom app is up to date and other apps as well
    • Make sure you are using anti-virus software and its up to date
    • Do not post Zoom links in the public eye
    • Don't click on links you don't know
    • Setting up meetings:
      • Use strong passwords
      • Do not share the meeting ID
      • Use a non obvious meeting ID
      • Use the waiting room function
      • Lock the meeting once everyone is in

New Post: 5/5/20


Jeff Furman my "go to guy" for Project management hosts a blog and has some Zoom fun and other suggestions check it out here:  https://www.linkedin.com/pulse/so-your-internet-crashes-middle-zoom-session-what-you-jeff-furman/

Take a peek at the: Project Management Answer book click the link.

New Post: 5/7/20 am

On a conference call today.  Discussion of fat client verses thin client again for VT software (for the young at heart this seems to reoccur every 5-10 years), functionality services were discussed (I think more of what you are used to using drives the most favorite product discussion) and end to end encryption took place.   Zoom came up and given that it is slowly improving its security posture some note it is moving into the "pack" of other VT implementations given that it will become less of a pick up and use utility because of security concerns.  Those with more security concerns and less functionality can look here: https://www.infosecnews.org/national-security-agency-releases-guide-to-secure-video-conferencing

New Post: 5/7/20 pm

Take a look at this very comprehensive post from Citizen Lab:
https://citizenlab.ca/2020/04/faq-on-zoom-security-issues/

Then this video by none other than: Dr Eric Cole

A few weeks ago there was a lot in the news about ZOOM Bombing. So ZOOM took action and set up some default security to 'appease the masses'. But here's the thing... they did too little, too late AND ZOOM meetings are still being targeted.
It's not over! The adversary is still on the prowl and creating havoc.
I recorded a quick video for you to share with your organization to help keep the awareness around how to protect against ZOOM Bombing.

Dr Coles Tips:


#security  #cybersecurity @Zoom @NIST #VideoConferenceCalling #VT #DrEricCole  #zoombombing


Last edit: Monday, 5/5/20 0930 hours











Friday, October 21, 2016

Cyber Security Month: Looking for Answers Part II?


NEW YORK METRO JOINT CYBER SECURITY CONFERENCE
NY Metro Joint Cyber Security Conference
I recently attended the Third Annual New York Metro Joint Cyber Security Conference (http://nymjcsc.org/), held in mid-town Manhattan.  Security conferences are now a dime-a-dozen, but this event is unique in that it is a collaborative effort developed by a consortium of eight leading security, audit, and risk focused, NY metropolitan area, not-for-profit professional associations. Each organization brings its best to the table, creating a rare combination of expertise and diversity of talent.  

There were many informative sessions – some standing room only – but some of the greatest value was in the interaction with the other professionals.  For example, in sessions, we learned that security professionals must adopt the language of Directors to be understood by a Board.  The Internet Security Alliance is even working on metrics for Boards to use in evaluating security risks and controls.  But, after all the talk of security maturity models, cyber risk management frameworks, and “cyber balance sheets,” CISOs (Chief Information Security Officers) will tell you that Boards still “just don’t get it” and don’t seem to be that interested.  Perhaps CISOs as a group aren’t very good at explaining how greater focus on preventing and mitigating cyber threats is in the self-interests of very diverse sets of Directors.  Maybe, despite approaching the problem with the best of business concepts and lingo, CISOs just don’t have influence with Directors.  (As one CISO put it, “formulas don’t work.  Relationships do.”) Or, perhaps it’s because, as one speaker put it, there is not a single instance of a cyber breach that has been demonstrated to have a material impact on a company.  In the end, the surprising takeaway may not be that CISOs are becoming more adept at speaking the language of the Board, but that some Boards are beginning to listen at all.
This sold-out event offered excellent, high-quality presentations with plenty of actionable content.  If you weren't able to attend, you can still benefit from the recordings of many of the sessions.  They are available at http://livestream.com/internetsociety/nymjcsc/.  Presentation slides may be found at http://tinyurl.com/z3fz44d. I would highly recommend reviewing them.
And, don't forget to sign up early for next year's conference.  It's one of the best values in information security education that you'll find anywhere.  Follow www.nymjcsc.org and @NYMJCSC for details.

Phil Froehlich is Chief Operating Officer of Integris Security and a member (who listens) of the Executive Board of New York Metro InfraGard.

Cyber Security Month: Looking for Answers: Part I?


LONG ISLAND BUSINESS NEWS
LI Business New Cyber Conference
Hilton, was once again informative, invigorating and enrolling. With a number of panelists participating, including both the Integris Security CTO, Blake Cornell, and United States Congressman US District 1, Lee Zeldin, nearly 100 individuals attended the breakfast event.
Topics of interest had included Cyber Terrorism, Business Continuity, Government Legislation, Small Business Best Practices and other wide ranging topics. Some of the information shared, information that attendees can use in their day to day business operations.
A goal of Integris Security CTO, Blake Cornell, was to provide “simple and sound information that is short and sweet” further stating that “if your employees are untrained then no amount of technical information will help them understand. You can’t make them understand but you can help them understand”.

Blake Cornell is the CTO of Integris Security LLC.

Sunday, October 16, 2016

Ransomware: Osterman Research Survey for Malwarebytes

https://www.integrissecurity.com/index.php?aboutus=JosephConcannon
Joseph Concannon
Today I receive a note from a friend who said he had fallen victim to a Ransomware attack.  So I figured its a good time to review some up to date expert research.  This review is a product of Integris Security LLC and we gladly share this with the community.

First, Ransomware is a global issue effecting enormous sized companies as well as my local friend.  Ransomware is a global threat/problem.  We must recognize the size and depth of this issue.  A survey was conducted during June of 2016 that included CIO's, CTO's, CISO's and other executives.  The survey included 165 corporations in the United States as well as companies from around the world.  39% percent of the companies that were contacted were impacted by a ransomware attack in the U.S. alone.  This is truly a global problem and issue but let's keep the focus here at home.  The report shows the various priorities by country.

The FBI talks about Ransomware as a, "an insidious type of malware that encrypts, or locks, valuable digital files and demands a ransom to release them". Integris Security LLC evangelizes through its President, Joseph Concannon the value of Risk Management and the ongoing development of a solid business continuity program.  Concannon states: "this isn't a once a year review, this is a daily, weekly, monthly, quarterly and semi-annual program.  Risk Management opens the eyes of the Executive Team and Boards of Directors".

Second, it comes as no surprise that the survey results identified healthcare and financial services industry as the prime target.  Each are highly dependent upon business critical information according to Osterman Research, Inc.Cyber criminals lay and weight until they find the prime target for an attack; one which they can not recover from due to the lack of ransomware fighting software.  In Osterman's survey U.S. companies were most likely to fall victim to a ransomware attack (79% fell victim according to the survey).

Third, Ransomware ranks the fourth highest security concern for senior executives in the United States as surveyed by Osterman Research, Inc., and more:

 U.S. organizations are also more likely to place a high or very high priority on investing in education and training about ransomware for their end users; and for investing in resources, technology, and funding to address the ransomware problem.

Note well: What the Osterman Research reveals is the power play between tenured industry executives and newly appointed CIO's, CISO's, CTO's learning the mine field of budgeting.  Where do these technology executives make the push to gain budget for their projects and can they convince business unit managers to join their team?  Who pays for training and education and how does that weigh in the balance of getting things done?  Here's how its playing out so far:
Somewhat ironically, however, U.S. organizations are also the least likely to have implemented any sort of ransomware training for their end users, and are among the most likely to offer only minimal training when they actually do so.  U.S. companies rate Ransomware as a high or extremely high priority, unlike their European counterparts in Germany and the UK or Canada which consider it less of a threat. 
Yet the training dollars in the U.S. continue to lag behind.   

The survey that I am reviewing is called, "Understanding The Depth of The Global Ransomware Problem" a report promoted by a company called Malwarebytes
The perceived importance of regular, on-premises backups as a ransomware-recovery tool is quite high among U.S. and German organizations, but somewhat lower among the organizations we surveyed in Canada and the United Kingdom. However, Canadian and UK-based organizations were more likely to use regular, cloud-based backups to recover from ransomware. Other capabilities in place to address ransomware included on-premises ransomware-detection solutions (highest penetration in the U.S.), network segmentation (highest in Germany), and air gaps between data stores and the Internet (highest in Canada).
At Integris Security LLC we point out that segmentation and air gaps are important as well as on-premises backups NOT connected to the network you are backing up.  Strong passwords that are changed every 90 days.  Here are the top 15 Cyber Security Precautions to follow.  Here are some very good tips for enterprise environment security teams to review (FBI):

Here are some tips for dealing with ransomware (primarily aimed at organizations and their employees, but some are also applicable to individual users):
  • Make sure employees are aware of ransomware and of their critical roles in protecting the organization’s data.
  • Patch operating system, software, and firmware on digital devices (which may be made easier through a centralized patch management system).
  • Ensure antivirus and anti-malware solutions are set to automatically update and conduct regular scans.
  • Manage the use of privileged accounts—no users should be assigned administrative access unless absolutely needed, and only use administrator accounts when necessary.
  • Configure access controls, including file, directory, and network share permissions appropriately. If users only need read specific information, they don’t need write-access to those files or directories.
  • Disable macro scripts from office files transmitted over e-mail.
  • Implement software restriction policies or other controls to prevent programs from executing from common ransomware locations (e.g., temporary folders supporting popular Internet browsers, compression/decompression programs).
  • Back up data regularly and verify the integrity of those backups regularly.
  • Secure your backups. Make sure they aren’t connected to the computers and networks they are backing up.

For those at home we strongly recommend backup on USB stick, or other storage drive with proper security "on board" to assess the devices health each time the device is accessed.  Saving important documents to a computer is a thing of the past.  Time to think 2016 and the threats that come with the technological age we live in.  Store important documents in a safe deposit box (whether in paper or USB or storage drive or other form).  If its important, then take the extra security steps.

https://www.stopthinkconnect.org/STOP THINK CONNECT is the U.S. Department of Homeland Security Campaign promoted during Cyber Security Awareness Month (October each year).  However, the evil email attachment continues to lure an seemly endless waterfall of users into the brink.  Nothing beats education and awareness in preventing the lost of your computer to a cyber attack.  While on the computer remember you are not in your living room.  You are in the "Wild West" and everyone's your friend.  You wouldn't leave your front door open at night, so don't leave your computer open either.  
Integris Security LLC grew from our passion for protecting our nation’s critical infrastructures and years of providing industry professionals with best of breed solutions, proven best practices and top notch security education. We work tirelessly to nurture our clients’ TRUST. We will work equally diligently to EARN your trust.


Thursday, October 6, 2016

LIBN Cyber Security Conference - October 6th, 2016

Today's cyber security conference held by the Long Island Business News at the Huntington Hilton was a huge success.  The conference was packed and the panel with headliner U.S. Congressman Lee Zeldin was both informative and far reaching.

A wide range of cyber security topics included  a discussion of the potential federal funding of security awareness strategies like, "If you see something, Say Something".  Attendee's suggested a new cyber security awareness strategy like see something be started. Blake Cornell, CTO Integris Security suggest we use, "Think twice before you click twice".  The simple message was something that everyone agreed was needed.

The panel touched upon some key areas and agreed that security awareness training when implemented correctly brings everyone into the company's security strategy and not just the security team.  Twenty - thirty employees watching the security posture of a company is better than 3-5 employees from the security team.  Chief Security Officers have their hands full and gaining the trust and confidence of all employees to be on the look out makes the CSO's job 100% easier. 

Is it IT or is it Business?  A lively discussion broke out concerning the politics, budgeting and organizational culture in which professional security people work in.  This environment is not always 100% on board with a strong security posture.  General agreement was reached on the theory of security starting from the top down works best.  If the boss is concerned about security so is everyone else.  The next discussion was about whether it was the business or IT department.  Well, this was put to rest quickly.  The IT staff and security personnel need to team with business unit managers and ask them to take ownership for what belongs to them and what is enabling their success. The better the integration with business leaders on function and feature of the computer tools used to bring profits to the business,  the smoother the discussions will be for improvements to strengthen the security budgets so that the profit center environment is safe and secure.  The better everyone will sleep.

Their are a great many things that people can do to keep the internet secure.  Unfortunately their are a great many things which LURE us away from this common sense approach to internet safety.  Changing (long with symbols, CAPS, lowercase letters and numbers) passwords every 90 days is driving a positive change for your safety and security on the internet.  Writing those passwords down and storing them in a secure place is also a good idea. See more ideas on our web site.

For a two hour conference this one was packed with information and many new contacts as well.  Good job to LIBN and we look forward to next years conference and some of the articles to appear in LIBN which should keep everyone on their toes.

For additional information on security tips, visit www.integrissecurity.com.  we have a full page of tips on our web site.

Wednesday, September 28, 2016

Information Security in Corporate Valuation

What do you look at when considering the corporate valuation of a company?  Chief financial officers pour over spreadsheets, public filings and much more to get a temperature so they can inform investors, boards and others in the decision making process.  Where is Information security in this discussion?  Who is the chairman of the board's audit committee and how comprehensive are the details and reports?  How accurate and truthful are these reports and details?  Who is the chairman of the technology committee and are his/her reports accurate, timely and reflective of the needs of the company to support the basic operations of the company.
Whether your a big box company like Target, credit card processor like Hartland Payment Systems or just one of the largest email giants like YAHOO!  these and many other questions have to be answered, accurately, timely and honestly and yes, sometimes even painfully.

We have all read in the news that VERIZON is on the path to make an offer to Yahoo! with finalization next year and this latest exposure is certainly going to figure large into pricing.  Verizon
will pay a competitive price, but will not buy based on a hunch.  They will skillfully look at every single part of the Yahoo! digital empire and figure out just how much work will be needed to mend the broken system.  Information security practice will loom large as the price for Yahoo! could potentially shrink.  Information security is going to have to push its way into the board room and profit center discussions.  If not the corporate valuation is just not honest and leaves a lot to be desired when looking at the totality of the circumstances concerning corporate valuation.  Assessing a computer environment can be a very straight forward business.  But what we're seeing are limitations put on security professionals or very narrow scoping of projects which is shaving away a more wholesome look into the entire computer enterprise.  This is just a delaying tactic which is putting off the unavoidable.  Auditing should be ongoing quarter to quarter, year to year and used in helping to set budgets for the out years.  Audit chairs should be apart of the internal profit center discussions and everyone should be mindful of function over feature creep without warranted information security checks prior to implementation.  The sales guys are going to have to get involved in security the environment which they play a critical role in.

Integris Security is your trusted IT Security team that can help you as we provide tailored, high quality security solutions based on industry best practices and our principals combined experience of more than eighty years.  Call us for an appointment and free consultation.

Wednesday, December 3, 2014

The Rear View Mirror

Typical in the information technology sector everyone is always focused on what’s next, the latest, hottest new application, the coolest mobile telephone and of course the work around that just makes life a little easier.  Not to be ignored are all those newly fashioned functions and features. Technology at the speed of life forever changing our lives for the better, right?  Forward looking for ever.

2014 hopefully has hopefully taught us some very important lessons that should not be ignored even if we were not directly impacted.  A look in the rear view mirror can sometimes be very revealing.  We are so focused on what’s coming directly ahead of us that we refuse to see what’s going on right behind us.  So for 2014 let me list a couple of things which could have made this a better year in the security space.

Network segmentation: You can’t get there from here should be the mantra, no? Did we learn anything this past year? Network segmentation is the act or profession of splitting a computer network into subnetworks, each being a network segment or network layer. Advantages of such splitting are primarily for boosting performance and improving security.   Please review a great eWeek article clicking here.

Service Level Agreements: Service agreements are important and a quick web search can be helpful to identify some key questions for developing such important tools for your company. The Outsourcing Center has developed ten key questions for developing effective service level agreements. It’s a solid read and you’ll find plenty of similar research on the web. A service-level agreement (SLA) is a part of a service contract[disambiguation needed] where a service is formally defined. Particular aspects of the service - scope, quality, responsibilities - are agreed between the service provider and the service user. A common feature of an SLA is a contracted delivery time (of the service or performance). As an example, Internet service providers and telcos will commonly include service level agreements within the terms of their contracts with customers to define the level(s) of service being sold in plain language terms. In this case the SLA will typically have a technical definition in terms of mean time between failures (MTBF), mean time to repair or mean time to recovery (MTTR); identifying which party is responsible for reporting faults or paying fees; responsibility for various data rates; throughput; jitter; or similar measurable details. {Attribution: Wikipedia}

Too big to fail: While not at all a technical term your company would do well to heed this warning. No company is too big to fail. No one. In our recent newsletter we talked about the breach of the week. The roadway is littered with companies failing over and over again until everyone in the industry is just tired of hearing of another breach. The breaches become “white noise” a distraction from the good work being performed by many security professionals in the field. Fight complacency, challenge everything and everyone with respect and “ASK Questions”. It won’t make you popular but it will certainly make you a very, very valuable employee.  Please read the ARS Technica article   HERE because it puts good perspective of what can happen after a breach. 

Alarms: Alarms are invitations that are yelling out, “come investigate me” I’m making noise and need your direct undivided attention. Please don’t ignore alarms. The story goes like this: Hey did you hear that alarm go off? Yeah, I’m getting a cup of coffee – you want anything? Hey, maybe I’ll come with you. Great! How many times do we ignore the obvious? Alarms are put in place for a reason to warn us, right? If the alarms are not configured appropriately and are creating noise, then someone has to go in and make a determination to turn them down and accept the consequences or turn them up and act each time they alert. 

Egress Filtering: Is that a freight train of information running out of our company? Egress filtering is protecting what’s going out as well as protecting others from malware coming from inside your own company. In computer networking, egress filtering is the practice of monitoring and potentially restricting the flow of information outbound from one network to another. Typically it is information from a private TCP/IP computer network to the Internet that is controlled. Egress filtering helps ensure that unauthorized or malicious traffic never leaves the internal network. In a corporate network, typical recommendations [2][3][4][5] are that all traffic except that emerging from a select set of servers would be denied egress. Restrictions can further be made such that only select protocols such as HTTP, email, and DNS are allowed. User workstations would then need to be configured either manually or via proxy auto-config to use one of the allowed servers as a proxy. Corporate networks also typically have a limited number of internal address blocks in use. An edge device at the boundary between the internal corporate network and external networks (such as the Internet) is used to perform egress checks against packets leaving the internal network, verifying that the source IP address in all outbound packets is within the range of allocated internal address blocks. The purpose is to prevent computers on the internal network from IP address spoofing. Such "spoofing" is a common technique used in "Denial of Service" attacks. {Attribution: Wikipedia}

Enumeration: Thanks to Wikipedia we know that Network enumeration is a computing activity in which usernames and info on groups, shares, and services of networked computers are retrieved. It should not be confused with network mapping, which only retrieves information about which servers are connected to a specific network and what operating system run on them. Network Enumeration is the discovery of hosts/devices on a network, they tend to use overt discovery protocols such as ICMP and SNMP to gather information, they may also scan various ports on remote hosts for looking for well-known services in an attempt to further identify the function of a remote host. The next stage of enumeration is to fingerprint the Operating System of the remote host.

We hope that this short laundry list helps each of you.  We understand the complications of local, national and global enterprises.  None of this is easy, but neither is dealing with the stockholders and the media if your company falls victim to a breach or other such incident.

Tuesday, December 2, 2014

Ten Mistakes that Boards Make


Too often we are learning of executive level errors or omissions which cause massive breaches to the data or PI of millions of citizens.  Here's the "Ten Mistakes That Board Make".

         1. Not Asking Questions

2. Failing to Understand the Company and the Risks it Faces
3. Failing to Lead on Ethics and Compliance
4. Not Insisting on a Crisis-Management Plan
5. Speaking out in a Crisis Before the Facts are in
6. Relying on the Wrong Outside Counsel
7. Failing to Understand Attorney-Client Privilege
8. Underestimating Regulators
9. Giving too Much Leeway to Rainmakers
10. Getting Caught Up in the dilemma of False Options
Taken from the magazine Corporate Board Members, an article written by Randy Meyers.
Make Integris Security your Chief Risk Officer (CRO) as the independent keeper of oversight in your corporate enterprise.  It is the job/function of the CRO to keep regulator awareness at a high level and to let the business be in charge of risk management.
Integris Security LLC grew from our passion for protecting our nation’s critical infrastructures and years of providing industry professionals with best of breed solutions, proven best practices and top notch security education. We work tirelessly to nurture our clients’ TRUST. We will work equally diligently to EARN your trust.


Reference: http://operationalrisk.blogspot.com/2014/11/top-ten-mistakes-board-of-directors-risk.html
 

Saturday, May 31, 2014

Lessons from the U.S. Veterans Administration

Government run healthcare is suffering from the stiff stench of reality this week as the Veterans Administration emplodes in a wide scale corruption probe in over 46 different facilities - defining systematic corruption which has infected the entire bureaucracy.  What can we learn?

Audits tell part of the story and so does strong management which not only holds those accountable but is in fact in trenches leadership.  Take a hard look at, "Undercover Boss" and ask yourself if the leadership of the VA had been in the trenches could things have been any different.  Clearly the Administrator of the VA was fighting an uphill battle of liars, cheats, and more.  But "Undercover Boss" makes the point: get out of the office and get into the trenches for a reality check.  Now let's see if our USDOJ follows the Veterans Administration IG's report and starts the most necessary criminal investigations to clean the VA once and for all so that our war heros finally get what they deserve - the best health care known to man.

We talk much in this blog about management and boards of directors.  As we should.  Organizations depend on these fine men and women to do the impossible, to be supermen and women.  But the days of hands off management are long gone.  Whether you are in government or the private sector if you haven't gotten that message its high time you did.  Get out of the office and learn the reality of what is going on in the workplace.

We heard much this week about out dated technology and "scheduling".   We worry, is this a sign of times to come in government run healthcare?  Well, those of us in technology know all too well that technology does a backflip and ten steps forward about every 60-90 days.  So if you're thinking of saving money and leveraging your entire corporation and/or government run agency on shoestring that has a one time techology budget - in the immortal words from Brooklyn, NY - forget about it.

Technology is in the worst case an infant, with an appetite that rivals most young U.S. Marines in boot camp.  Belly up to the table because this infant is going to need your undying attention, your understanding and your coddling every single day of the week.  Budgeting and planning for the unexpected are just another great aspect which many who are so quick to adopt technology and outsourcing with an expectation of saving millions may want to slow down and take a deep breath.  Technology implementations are expensive and those seeking to cut to shortcuts are only doing a royal disservice to their companies and agencies and fooling themselves.  While the passing of timely and accurate information is exciting and used correctly can help you turn on a dime....it comes with a fairly large investment and huge reality check on expectations - but not on the information delivered, but on the intense care and ongoing maintainence to systems, controls and people.

Take a hard look at the Veterans Administration of today and ask yourself Mr/Mrs CEO or Agency head...could this be me?  Do I even have a clue?  We hope this as in any number of cases we bring to your attention help you focus not just on security but the fundermentals of leadership and management.

If you need a trusted source and friendly but well grounded reality check give us a call.  We would like your business, but we're not willing to suffer our reputation just to make a buck.

Trust is at the core of Integris Security. We can be counted upon to provide you with the services and intelligence to keep your information, systems and institution secure. Call us and let's get to work on improving your security/risk posture.