Showing posts with label Architecture. Show all posts
Showing posts with label Architecture. Show all posts

Thursday, September 5, 2013

Successful Digital Strategy: Bridge the gap between CIO and CMO

CIO & CMO doesn't trust each other, IT doesn't provide fast turn-around!

Business is largely about competition and, even within organizations, a healthy dose of rivalry between colleagues can be a good thing. However, a survey just conducted by Accenture Interactive (see The CMO-CIO Disconnect) points to a downright unhealthy relationship in many C-Suites which can do nothing but damage to firms. 

At a time when many executives say that improving digital reach will be a significant differentiator for their companies, research shows that two of the most important digital leaders — the Chief Marketing Officer (CMO) and the Chief Information Officer (CIO) — do not trust each other, understand each other, or collaborate with each other.

That is very bad news for their businesses and, not incidentally, for their own careers. When IT and marketing departments work at cross-purposes, the results are inefficiencies and mishaps and it is customers who suffer. Potential buyers simply don't have the time or energy to do business with a company that makes things harder for them.

To begin to mend the CMO-CIO relationship, it's important to understand the source of each side's frustrations. CMOs' answers to survey questions make it clear that they view IT as an "execution and delivery" provider, instead of as a strategic partner. CMOs do not believe they are getting fast enough turnaround on projects and adequate quality from the IT departments. Because many CMOs do not believe they are getting the service they want from their IT departments, many bypass the IT department and work with outside vendors. Forty-five percent of marketing executives say they would prefer to enable marketing employees to operate data and content without IT intervention.


For their part, IT executives believe marketers make promises they can't keep and do not provide them with adequate information on business requirements. The CIOs believe the marketing teams often do not understand — or appreciate — data integration or IT standards. Nearly half (49 percent) of CIOs say marketing pulls in technologies without consideration for IT standards. Forty-seven percent say the marketing team lacks understanding of data integration.


CEOs and others in the C-suite should not turn a blind eye to this tension, hoping for it to resolve itself. It is crucial for companies to instill more collaboration and understanding across the functions.

Here are five suggestions for supporting a CMO-CIO relationship that will ultimately benefit customer experience and drive sales:

Identify the CMO as the "Chief Experience Officer."
This is more than simply a change in nomenclature It is a constant reminder to the CMO that the job doesn't end with branding and advertising. The CMO must design and drive a customer experience that is consistently first-rate, at every touch point within the company — a goal that lays more emphasis on the role of IT and the need to reach a deeper understanding.

Signal that IT is the strategic partner to marketing
The CIO cannot be viewed as only the chief technology platform provider; the role must be elevated to a strategic member of the C-suite.

Get the two leaders working from the same playbook
Already, CIOs and CMOs spend more than 30 percent of their respective budgets on technology. It is time for them to agree on key business levers for marketing and IT integration, such as access to customer data and speed to market along with security, privacy, and standardization.

Change the skill mixes
Make sure the marketing department becomes more tech savvy and the IT department better understands marketing. Again, coming together around the consumer and customers will help to breakdown internal silos and align agendas. Upgrading their skills will help both departments make better decisions about technology and understand its impact on business outcomes.

Develop trust by trusting
It is time for leaders in organizations to extend their trust to — and accept it from — business units beyond their own.

Monday, June 24, 2013

NIST Publishes Draft Cloud Computing Security Document for Comment

NIST Cloud Computing Security Reference Architecture provides a security overlay to the NIST Cloud Computing Reference Architecture published in 2011

The National Institute of Standards and Technology (NIST) has published a draft document on security for cloud computing as used in the federal government. The public comment period runs through July 12, 2013.

The 2011 NIST Cloud Computing Reference Architecture provided a template and vocabulary for federal cloud adopters to follow for a consistent implementation of cloud-based applications across the government.

This new addition, the NIST Cloud Computing Security Reference Architecture, contributes a comprehensive security model that supplements the NIST Cloud Computing Reference Architecture.

Using this model and an associated set of security components derived from the capabilities identified by the Cloud Security Alliance in its Trusted Cloud Initiative Reference Architecture, the NIST Cloud Computing Security Reference Architecture introduces a cloud-adapted Risk Management Framework for applications and/or services migrated to the cloud.

The NIST Cloud Computing Security Reference Architecture provides a case study that walks readers through steps an agency follows using the cloud-adapted Risk Management Framework while deploying a typical application to the cloud—migrating existing email, calendar and document-sharing systems as a unified, cloud-based messaging system.

Deadline for comments is July 12, 2013. Please use the template for comments and mail to Michaela Iorga at Michaela.iorga@nist.gov with the subject line "Comments SP 500-299."

Wednesday, February 13, 2013

In-House App Stores is MUST for Enterprise?

A Do-it-Yourself Approach to Ensuring Mobile Security

As personal mobile devices become ubiquitous in corporate networks - even in organizations without official bring-your-own-device policies - IT and security personnel are implementing new approaches to prevent malware and ensure data integrity. 

One approach beginning to take root is the creation of in-house corporate app stores, where organizations offer users access to custom-built, secure applications designed specifically for that organization, along with access to approved public apps for smart phones, tablets and other personal devices.

Tackling Application Insecurity

With malware infesting the authorized commercial app stores, including the two largest - Google Play for Android and to a lesser extent, the Apple iOS App Store - corporate security and IT executives are exploring new strategies to limit the use of unauthorized applications on devices connected to corporate networks.

Because of the rapid growth in the use of personal devices for work-related tasks, IT departments generally do not permit users to install any application on corporate computers but many companies still have not yet established similar policies for personal devices. 

Companies that opt for a private app store can minimize much of that risk by requiring users to select only from applications that are certified by their employer as safe.

Any suggestions or ideas?

Saturday, January 26, 2013

Documentary: A Gift for the Hackers

Privacy is becoming antiquated

Increasingly devices like printers and scanners are being connected directly to the Internet. It’s all very convenient, bit is it safe?

Your mobile, your printer, your hard drive, everything is connected… but it’s like a Swiss cheese. Medical files, financial information, and trade secrets, they’re all there for the taking. It’s shocking, it should not be allowed. It’s a design flaw.

Is this vulnerability in tens of thousands of devices compromising your security and your privacy? Computer security has become a big concern for companies and individuals.

As a result it has also become a big business. The world’s number one producer of computers and printers, Hewlett – Packard (HP), has an annual turn over of 127 billion dollars.

Thursday, July 26, 2012

The Department of Defense Cloud Computing Strategy

Goals presented “consolidate and share commodity IT functions resulting in a more efficient use of resources.”


The Department of Defense needs to accomplish its critical global missions despite a decreasing budget and rising cybersecurity threat. To that end, the Chief Information Officer of the DoD, Teri Takai, released its Cloud Computing Strategy, which outlines its goals to accelerate the adoption of cloud computing throughout the department.


In the strategy, the Office of the CIO explains why it wants to move to the cloud, its goals, the challenges that stand in its way and methods to mitigate them, and the coming steps the Defense Department plans to take to get there. The strategy uses the National Institute of Standards and Technology’s definition of cloud computing for their strategy.


NIST defines cloud computing as: “A model for enabling ubiquitous, convenient, on‐demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.”


DoD likes this definition because it includes Software as a Service, Platform as a Service, and Infrastructure as a Service. According to the CIO, the DoD currently has a “duplicative, cumbersome, and costly set of application silos” that can benefit from more cloud computing. The goals presented in the Cloud Computing Strategy is to “consolidate and share commodity IT functions resulting in a more efficient use of resources.”


The DoD hopes to provide device and location independent on-demand secure global access to mission data and enterprise services. They also hope to enable rapid application development and reuse of applications by other organizations. This means both sharing and adopting the most secure commercially available cloud services.


The Cloud Computing Strategy also lays out four steps for implementing the Department of Defense Cloud Environment. The first will be to “Foster Adoption of Cloud Computing” by establishing a joint governance structure to drive the transition and an Enterprise First approach while reforming DoD IT finance, acquisition, and contracting and increasing cloud outreach and awareness.


The next step is to “Optimize Data Center Consolidation” by consolidating and virtualizing legacy applications and data. The third step is to “Establish the DoD Enterprise Cloud Infrastructure” so that it’s agile, consolidated, and secure.


The last step will be to “Deliver Cloud Services” using existing DoD cloud services and external providers. The CIO will provide oversight for component implementation of these steps.


Please refer here to download the strategy.

Sunday, June 10, 2012

Apple has released IOS Security

Apple IOS Security


Apple normally stays very quiet when it comes to discussing the security mechanisms of its products. Apple has released a document that will make life a little easier for anyone responsible for securing iOS devices.


The document, titled iOS Security, provides details on the system architecture, encryption and data protection, network security features and device access for iOS devices. If you develop policies and/or mechanisms for BYOD security, this is recommended reading. 


From the Apple iOS Security document:


“This document provides details about how security technology and features are implemented within the iOS platform. It also outlines key elements that organizations should understand when evaluating or deploying iOS devices on their networks.”


System architecture: The secure platform and hardware foundations of iPhone, iPad, and iPod touch.


Encryption and Data Protection: The architecture and design that protects the user’s data when the device is lost or stolen, or when an unauthorized person attempts to use or modify it.


Network security: Industry-standard networking protocols that provide secure authentication and encryption of data in transmission.


Device access: Methods that prevent unauthorized use of the device and enable it to be remotely wiped if lost or stolen.”




Is Apple now recognizing the growing threats their products face? Prior to this, security researchers have traditionally had to rely on reverse engineering Apple’s products to better understand their security mechanisms.


Refer here to download the document from Apple website.

Sunday, May 13, 2012

Basic checklist for Remove Access Security

The Remote Access Security Checklist


The checklist of must-haves for any remote access policy.


Remote Access Policy Security Checklist


Antivirus software with real-time protection enabled - Make sure company-approved antivirus software is included on all remote access devices and set to update regularly.


Required personal firewall - In addition to antivirus software, a personal firewall should be configured and enabled on all remote devices. If a threat is detected all communications should be blocked.


Defined operating systems - Only allowed operating systems should be able to connect to the corporate network. If your company only uses and supports Windows computers, you should disallow *nix, Macs, etc.


Time out periods – Should be defined and set to when there is no activity on the computer. If there is no activity for 30 minutes for example, enforce a policy so the connection terminates. Be careful to test and make sure a download or upload triggers activity.


Targeted access to systems while on VPN - Only allow access to necessary internal resources. If a department only accesses one application on your internal network only provide them with access to that application.


Non-Disclosure Agreement - Vendors, third party companies, and even employees should sign an NDA in order to gain remote access. This will help protect any confidential information.

Friday, May 11, 2012

Whitepaper: HMI/SCADA System Security Gaps

Understanding and Minimizing Your HMI/SCADA System Security Gaps


Being at the heart of an operation’s data visualization, control and reporting for operational improvements, HMI/SCADA systems have received a great deal of attention, especially due to various cyber threats and other media-fueled vulnerabilities.


The focus on HMI/SCADA security has grown exponentially in the last decade, and as a result, users of HMI/SCADA systems across the globe are increasingly taking steps to protect this key element of their operations. The HMI/SCADA market has been evolving over the last 20 years with functionality, scalability and interoperability at the forefront.


For example, HMI/SCADA software has evolved from being a programming package that enables quick development of an application to visualize data within a programmable logic controller (PLC) to being a development suite of products that delivers powerful 3-D visualizations, intelligent control capabilities, data recording functions, and networkability. With HMI/SCADA systems advancing technologically and implementations becoming increasingly complex, some industry standards have emerged with the goal of improving security. However, part of the challenge is knowing where to start in securing the entire system.


The purpose of this paper is to explain where vulnerabilities within a HMI/SCADA system may lie, describe how the inherent security of system designs minimize some risks, outline some proactive steps businesses can take, and highlight several software capabilities that companies can leverage to further enhance their security.


Refer here to download this website. (Registration Required)

Friday, March 9, 2012

NIST Releases Final Smart Grid 'Framework 2.0' Document

Framework will provide an expanded view of the architecture of the Smart Grid

An updated roadmap for the Smart Grid is now available from the National Institute of Standards and Technology (NIST), which recently finished reviewing and incorporating public comments into the NIST Framework and Roadmap for Smart Grid Interoperability Standards, Release 2.0.

The 2.0 Framework lays out a plan for transforming the nation's aging electric power system into an interoperable Smart Grid—a network that will integrate information and communication technologies with the power-delivery infrastructure, enabling two-way flows of energy and communications.

The final version reflects input from a wide range of stakeholder groups, including representatives from trade associations, standards organizations, utilities and industries associated with the power grid.

Refer here to read further details or here to download the document.

Wednesday, November 2, 2011

WebCast: Hacking Web Servers and Countermeasures

Learn how to secure webserver!

In this on-demand IT security webcast, EC-Council Master Certified Instructor Eric Reed will address the subject of Hacking Webservers. The webcast will cover topics such as webserver architecture, webserver attack methodologies, footprinting tools, and many more critical concepts. The webcast also includes demonstrations on performing a directory traversal attack, fingerprinting a webserver with HTTPRecon, and web-based password cracking with Brutus.

This webcast is available on-demand at http://www.careeracademy.com/ceh-m12-infosec.aspx

Please feel free to forward to others in your organization who may be interested this type of training.

Details:

This free module is a part of CareerAcademy.com’s EC-Council Endorsed CEH Certification course, which gives each student in-depth knowledge and practical experience with current essential security systems.

When a student completes the course they will have hands on understanding and experience in Ethical Hacking and be fully prepared to pass EC-Council Certified Ethical Hacker Exam 312-50.

You can attend this complimentary webcast right now at:

http://www.careeracademy.com/ceh-m12-infosec.aspx

Sunday, September 11, 2011

ZigBee Architecture Basics

Zigbee Networking Architecture

This training video is intended to explain the ZigBee mesh networking architecture at a high level. It discusses basic topics such as:

What is mesh networking?


Sunday, June 12, 2011

Join the Cloud Security Summit

Free Online Event on June 16

The adoption of cloud computing is no luxury, and compliance and privacy concerns are now more pertinent than ever. Attend this summit to hear from key thought leaders and end users as they provide an in-depth look into the new world for cloud security and privacy.

Presenters will discuss ways to fully classify, analyze and mitigate both the legal and compliance risks associated.

Sign up to attend the live interactive webcasts on June 16, 2011, or view them afterward on demand here: http://www.brighttalk.com/r/mxX .

Presentations include:

‘Getting PCI to the Cloud: Amazon Web Services and SafeNet’
Mr. Dean Ocampo, CISSP, Dir. of Product Marketing, SafeNet, & Mr. Tom Stickle, Sr. Solution Architect, Amazon Web Services

‘Audit Considerations in a Cloud Computing Environment’
Jason Wood, Assistant Professor, Jack Welch Management Institute & Chancellor University and President of WoodCPA Plus P.C.

‘Trusting Cloud Services with Intel® Trusted Execution Technology’
Iddo Kadim, Director of Data Center Virtualization Technologies, Intel

‘Storm Clouds on the Horizon: Can I Trust My Data in the Cloud?’
Michael Sutton, Zscaler; Randy Barr, ServiceSource; Eran Feigenbaum, Google Apps; Matt Broda, Microsoft

‘The Evolution of IAM to Enable Security in The Cloud’
Tim Dunn, Vice President of Strategy, CA Technologies Security Europe

‘Cloud Computing & the Law: How to Protect Your Data’
Jonathan Armstrong, Technology Lawyer Partner, Duane Morris LLP

‘Vetting a Cloud Service Provider’
Emma Webb-Hobson, Information Assurance Consultant, QinetiQ

‘Cloudonomics or Risky Business? How to Architect your Services’
Gregor Petri ; Advisor on Lean IT and Cloud Computing, CA Technologies

‘Cloud Storage Security Introduction’
Glyn Bowden, SNIA & Storage Infrastructure Architect

‘Update: Cloud Computing and Data Protection’
Ibrahim Hasan, Director and Solicitor, Act Now Training LTD

You can view the full lineup and sign up to attend any or all presentations at http://www.brighttalk.com/r/mxX .

This summit is part of the ongoing series of thought leadership events presented on BrightTALKTM. I hope you are able to attend.

Thursday, June 2, 2011

Security and Prosperity in the Information Age

America's Cyber Future!

America’s growing dependence on cyberspace has created new vulnerabilities that are being exploited as fast as or faster than the nation can respond. Cyber attacks can cause economic damage, physical destruction, and even the loss of human life. They constitute a serious challenge to U.S. national security and demand greater attention from American leaders.

Despite productive efforts by the U.S. government and the private sector to strengthen cyber security, the increasing sophistication of cyber threats continues to outpace progress. To help U.S. policymakers address the growing danger of cyber insecurity, this two-volume report features accessible and insightful chapters on cyber security strategy, policy, and technology by some of the world’s leading experts on international relations, national security, and information technology.

Volume I

America’s Cyber Future: Security and Prosperity in the Information Age
By Kristin Lord and Travis Sharp

Volume II

Note: Chapters are bookmarked within the Table of Contents.

Chapter I: Power and National Security in Cyberspace
By Joseph S. Nye, Jr.

Chapter II: Cyber Insecurities: The 21st Century Threatscape
By Mike McConnell

Chapter III: Separating Threat from the Hype: What Washington Needs to Know about Cyber Security
By Gary McGraw and Nathaniel Fick

Chapter IV: Cyberwar and Cyber Warfare
By Thomas G. Mahnken

Chapter V: Non-State Actors and Cyber Conflict
By Gregory J. Rattray and Jason Healey

Chapter VI: Cultivating International Cyber Norms
By Martha Finnemore

Chapter VII: Cyber Security Governance: Existing Structures, International Approaches and the Private Sector
By David A. Gross, Nova J. Daly, M. Ethan Lucarelli and Roger H. Miksad

Chapter VIII: Why Privacy and Cyber Security Clash
By James A. Lewis

Chapter IX: Internet Freedom and Its Discontents: Navigating the Tensions with Cyber Security
By Richard Fontaine and Will Rogers

Chapter X: The Unprecedented Economic Risks of Network Insecurity
By Christopher M. Schroeder

Chapter XI: How Government Can Access Innovative Technology
By Daniel E. Geer, Jr.

Chapter XII: The Role of Architecture in Internet Defense
By Robert E. Kahn

Chapter XIII: Scenarios for the Future of Cyber Security
By Peter Schwartz

This study was co-chaired by Robert E. Kahn, Mike McConnell, Joseph S. Nye, Jr. and Peter Schwartz, and edited by Kristin M. Lord and Travis Sharp.

Download Volume I (PDF)
Download Volume II (PDF)