Showing posts with label Security Framework. Show all posts
Showing posts with label Security Framework. Show all posts

Wednesday, October 23, 2013

Aligning Security with GRC

How to Leverage GRC for Security?

Governance, Risk & Compliance (GRC) has long been viewed as a framework for tracking compliance requirements and developing business processes aligned with best practices and standards. It plays a strong role in helping security teams understand the business and to protect the organization from threats

But now, more security professionals are turning to data collected by GRC tools for insights into the organization's processes and technologies. The insights gained can help them to develop better controls to protect the organization from cyber-attacks and insider threats.

As part of GRC programs, organizations document processes, specify who owns which assets and define how various business operations align with technology. Security professionals can use this information to gain visibility into the organization's risks, such as determining what servers are running outdated software.

GRC programs collect a wealth of information and insights that can be valuable to security professionals as they manage risk and evaluate the organization's overall security posture. It provides the business context necessary to improve areas such as asset and patch management, incident response and assessing the impact of changes in technical controls on business processes.

Asset Inventory

Many compliance programs, including those for PCI-DSS [Payment Card Industry-Data Security Standard], require organizations to extensively document each asset and identify who uses it for what purpose. The documentation includes information about which business processes rely on which hardware and software. Mapping a piece of technology to a particular business function makes it possible to better identify the risks and the impact on operations if that technology is compromised.

The inventory process may identify equipment that the IT department was previously unaware of. By understanding the business processes that rely on that equipment, security teams can decide what kind of firewall rules to apply, better manage user accounts and learn what software needs to be updated. Understanding who the end-users are and how the asset is being used helps security teams assess how to prioritize the risks and plan how to reduce them.

Security professionals can use GRC programs to understand how technology maps to certain business processes and functions, says Mike Lloyd, CTO of Red Seal Networks, a network security management company. This information can help them figure out what the key threats are and identify ways to mitigate that risk, he says.

Incident Response, Controls

Security professionals can also use GRC to improve information sharing across the organization and streamline incident response. For example, because GRC makes it clear what kind of business processes depend on which assets, security teams have a clear path of who should be notified when there is a security event. Incident response teams can also look at all related processes and be able to identify other assets they should investigate to assess the magnitude of a breach.

Summary

Security professionals must understand the need to move away from a technical view of risk to a more strategic one when evaluating and deploying controls. They should evaluate how certain technical controls, while improving security, can impact business functions, and make necessary adjustments.

GRC enables security professionals to "draw a line between what security tasks are necessary and what business is concerned about.

Wednesday, June 26, 2013

6 Steps to Secure Mobile Devices

NIST Guidelines for Managing the Security of Mobile Devices in the Enterprise

When NIST issued in 2008 its initial guidance on managing mobile device security, the Apple iPhone was just a year old and the introduction of the iPad was 15 months off. Even the guidance name, Special Publication 800-124: Guidelines on Cell Phone and PDA Security, sounds ancient to today's ears.

The National Institute of Standards and Technology on June 24 published its first revision of the SP 800-124, renaming it Guidelines for Managing the Security of Mobile Devices in the Enterprise.

NIST says the revised guidance provides recommendations for selecting, implementing and using centralized management technologies, explains the security concerns inherent in mobile device use and provides recommendations for securing mobile devices throughout their life cycles.

The guidance covers enterprise-issued devices as well as the bring-your-own device trend.

Step-by-Step Approach

The revised publication offers six major steps enterprises need to take to manage mobile devices in a secure environment. According to the guidance, organizations should:

  1. Have a mobile device security policy that defines which types of the organization's resources may be accessed via mobile devices, which types of mobile devices - for example, organization-issued devices vs. BYOD - are permitted to access the organization's resources, the degree of access that various classes of mobile devices may have and how provisioning should be handled.
  2. Develop system threat models for mobile devices and the resources that are accessed through the devices. These devices often need additional protection because of their higher exposure to threats than other client devices, such as desktops and laptops.
  3. Consider the merits of each provided security service, determine which services are needed for their environment and then design and acquire one or more solutions that collectively provide the necessary services. Categories of services to be considered include general policy, data communication and storage, and user and device authentication and applications.
  4. Implement and test a mobile device solution before putting it into production. Aspects of the solution that should be evaluated for each type of mobile device include connectivity, protection, authentication, application functionality, solution management, logging and performance.
  5. Secure fully each organization-issued mobile device before allowing a user to access it. This ensures a basic level of trust in the device before it is exposed to threats.
  6. Regularly maintain mobile device security, including checking for upgrades and patches and acquiring, testing and deploying them; ensuring that each mobile device infrastructure component has its clock synced to a common time source; reconfiguring access control features as needed; and detecting and documenting anomalies within the mobile device infrastructure, including unauthorized configuration changes to mobile devices.

The revised guidance also recommends that organizations periodically perform assessments to confirm that their mobile device policies, processes and procedures are being properly followed. Assessment activities may be passive, such as reviewing logs, or active, such as performing vulnerability scans and penetration testing.

Tuesday, May 21, 2013

Cybersecurity is about more than technology

Securing Supply Chains Beyond Vendors and Service Providers

Securing supply chains is becoming a more crucial aspect of information risk management. But the definition of the supply chain is evolving.

The supply chain, from an IT security perspective, often is perceived as the hardware and software an organization acquires from vendors as well as online offerings furnished by service providers.

According to control SA-12: Supply Chain Protection, organizations use acquisition and procurement processes to require supply chain entities to implement necessary security safeguards to reduce the likelihood of unauthorized modifications at each stage in the supply chain and protect information systems and their components, before taking delivery of such systems and components.

But that's not quite how it works with shadow suppliers. Those running IT and IT security at government agencies and businesses don't always know that a system or component has been acquired. That's because the technology was not acquired through the normal procurement process.

We see organizations acquiring a service such as Dropbox, which allows individuals to easily share documents through a public-cloud service: 
Colleagues sitting around a conference table want to share a document, but the document owner, after five attempts, can't access Microsoft SharePoint, a document management system that operates on the internal corporate network. 
Frustrated, the document owner uploads the document to Dropbox, where his colleagues can easily access it. Suddenly, Dropbox is a supplier, and the business or government agency doesn't even know it. This is a huge area of the supply chain that now exists that is completely shadowed.

Of course, NIST offers other controls to deal with cloud services, such as requiring that information stored on the cloud be encrypted for added security. And many organizations have implemented controls to limit or ban the use of employee-owned devices and cloud services, such as Dropbox.

But as long as employees can find better technology than their employers offer, they will concoct ways to use them. Even if there is a policy against doing it, people are naturally doing it anyway, not to be rebellious but just to be more productive.

Organizations must be more agile in developing policies and adopting controls because there are too many choices in the marketplace. Years ago, organizations provided their employees with the best technology; not so today.

Saturday, May 18, 2013

Cyber Infrastructure Protection Guidelines by Strategic Studies Institute

It provides the foundation for long-term policy development and a roadmap for cyber security

Increased reliance on the Internet and other networked systems raise the risks of cyber attacks that could harm our nation’s cyber infrastructure.

The cyber infrastructure encompasses a number of sectors including: the nation’s mass transit and other transportation systems; banking and financial systems; factories; energy systems and the electric power grid; and telecommunications, which increasingly rely on a complex array of computer networks, including the public Internet.

However, many of these systems and networks were not built and designed with security in mind. Therefore, our cyber infrastructure contains many holes, risks, and vulnerabilities that may enable an attacker to cause damage or disrupt cyber infrastructure operations.

Threats to cyber infrastructure safety and security come from hackers, terrorists, criminal groups, and sophisticated organized crime groups; even nation-states and foreign intelligence services conduct cyber warfare.

Cyber attackers can introduce new viruses, worms, and bots capable of defeating many of our efforts. Costs to the economy from these threats are huge and increasing. Government, business, and academia must therefore work together to understand the threat and develop various modes of fighting cyber attacks, and to establish and enhance a framework to assess the vulnerability of our cyber infrastructure and provide strategic policy directions for the protection of such an infrastructure.

This book addresses such questions as:

  • How serious is the cyber threat?
  • What technical and policy-based approaches are best suited to securing telecommunications networks and information systems infrastructure security?
  • What role will government and the private sector play in homeland defense against cyber attacks on critical civilian infrastructure, financial, and logistical systems?
  • What legal impediments exist concerning efforts to defend the nation against cyber attacks, especially in preventive, preemptive, and retaliatory actions?
Refer here to download the book.

Saturday, March 23, 2013

7 Key Duties Of CISOs

CISO's Responsibilities 

The CISO's responsibilities would include: 

  1. Overseeing the establishment and maintenance of a security operation that through automated and continuous monitoring can detect, contain and mitigate incidents that impair information security and enterprise information systems;
  2. Developing, maintaining and overseeing an enterprise-wide information security program;
  3. Developing, maintaining and overseeing information security policies, procedures and control techniques to address all applicable requirements;
  4. Training and overseeing personnel with significant responsibilities for information security;
  5. Assisting senior agency officials on cybersecurity matters;
  6. Ensuring the enterprise has a sufficient number of trained and security-cleared personnel to assist in complying with cybersecurity law and procedures;
  7. Reporting at least annually to enterprise executives the effectiveness of the agency information security program; information derived from automated and continuous monitoring, including threat assessments; and progress on actions to remediate threats.
The CISOs should posses the necessary qualifications, including education, training, experience and the security clearance needed to do the job.

Friday, November 16, 2012

Securing Mobile Devices Using COBIT 5 for Information Security

ISACA published (Members Only) guidelines for Securing Mobile Devices 

Securing Mobile Devices Using COBIT 5 for Information Security should be read in the context of the existing publications COBIT 5 for Information Security, Business Model for Information Security (BMIS) and COBIT 5 itself. This publication is intended for several audiences who use mobile devices directly or indirectly.

These include end users, IT administrators, information security managers, service providers for mobile devices and IT auditors. The main purpose of applying COBIT 5 to mobile device security is to establish a uniform management framework and to give guidance on planning, implementing and maintaining comprehensive security for mobile devices in the context of enterprises.

The secondary purpose is to provide guidance on how to embed security for mobile devices in a corporate governance, risk management and compliance (GRC) strategy, using COBIT 5 as the overarching framework for GRC.

Refer here to download. (Members Only)

Monday, June 4, 2012

Free Framework for Vulnerability Reporting

Breach Info Sharing Tool Enhanced


The Industry Consortium for Advancement of Security on the Internet has introduced an enhanced version of its free security vulnerability reporting framework designed to ease the sharing of breach information.


The framework enables stakeholders across different organizations to share vulnerability information in an open and common machine-readable format. ICASI, a non-profit association of eight major information technology companies, says Version 1.1 of the Common Vulnerability Reporting Framework offers users a more comprehensive and flexible format, while reducing duplication and the possibility of errors.


"CVRF replaces the many nonstandard reporting formats previously in use, thus speeding up information exchange and processing," the association says. Russell Smoak, ICASI's president, in an earlier interview with Information Security Media Group, explained that the framework allows for consistency among vendors, researchers and customers in exchanging vulnerability information. "It speeds the response in the event of a breach," he said.


For example, by using the framework, an organization that's a customer of three companies that have all been affected by a data breach could receive consistent reports and then more promptly take appropriate action, Smoak explained. The framework is available for free at the consortium's website, which also includes information about a May 30 webcast on the framework.

Monday, February 20, 2012

Learn the process of documentation writing to implement ISO 27001

ISO 27001 Video Tutorials

One of the biggest obstacles for companies starting to implement ISO 27001 is writing various documents required by this information security standard.

Information Security & Business Continuity Academy has launched ISO 27001 Video Tutorials, a new product that facilitates the process of documentation writing.

According to ISO Survey of Certifications published by the International Organization for Standardization (ISO), ISO 27001 is within the 5 most popular management standards, and is also one of the standards with the highest growth in the number of certified companies – about 20% annually.

However, the fact that a large percentage of companies that have started to implement this standard never finish the job is less known. The reason for failure is very often insufficient time or lack of knowledge for writing the documentation – ISO 27001 has very specific requirements about how the documentation should look like.

At the moment 13 video tutorials are available, and each month 2 new tutorials will be published. A total of 50 video tutorials are planned, which will cover all the steps in ISO 27001 implementation – from setting up the project all through successful certification.

Dejan Kosutic, the author of the video tutorials said:
"I've worked with quite many companies as a consultant, and most of those companies struggle with the same thing – how to fill in the documentation. I believe these video tutorials will increase the success rate of ISO 27001 projects by at least 25%, and increase the speed of implementation by 50%".

Wednesday, November 9, 2011

Guidance to Safeguard Digital Assets in Fiscally Challenged Times

12 Core Information Security Services

To help states keep their IT security robust in these tough economic times, the National Association of State Chief Information Officers has published a taxonomy of a dozen critical IT security service.

The 12 core services identified in the report, The Heart of the Matter: A Core Services Taxonomy for State IT Security Programs, could prove useful for other government and non-government organizations working to secure their information assets under financially challenging conditions.

1. Information Security Program Management: Plans, provides oversight and coordinates all information security activities.
  • Align security program activities and staff with a generally accepted best practice framework.
  • Oversee the creation and maintenance of information security policies, standards, procedures and guidelines.
  • Create and maintain strategic and tactical plans.
  • Coordinate the movement of plans, policies, standards and other authoritative documents through a governance process.
  • Track information security risk key performance indicators.
  • Disseminate security metrics and risk information to executives and other managers for decision making.
  • Coordinate security efforts.
2. Secure System Engineering: Designs appropriate security controls in new systems or systems that are undergoing substantial redesign, including in-house and outsourced solutions.
  • Integrate information security design requirements in the system development life cycle.
  • Participate as a security consultant on significant technology projects.
  • Assist with the creation of system security plans, outlining key controls to address risks.
  • Assist with the creation of residual risk documentation for management acceptance.
  • Integrate security requirements into contracts for outsourced services.
  • Assist with the creation of information security policies, standards, procedures and guidelines.
  • Assist with the creation of secure configuration standards for hardware, software and network devices.
  • Integrate security requirements into contracts for outsourced services.
3. Information Security Awareness and Training: Provides employees at all levels with relevant security information and training to lessen the number of security incidents.
  • Coordinate general security awareness training for all employees and contractors.
  • Coordinate security training for groups with specialized needs, such as application developers.
  • Provide persistent and regular messaging relating to cybersecurity threats and vulnerabilities.
4. Business Continuity: Ensures that critical business functions will be available in a time of crisis.
  • Coordinate business impact analysis.
  • Development of appropriate recovery strategies for services.
  • Develop disaster recovery plans for identified key technologies.
  • Coordinate testing to ensure that services can be recovered in the event of an actual disaster.
5. Information Security Compliance: Validates that information security controls are functioning as intended.
  • Coordination of continuing assessments of key security controls in in-house and outsourced systems.
  • Completion of independent pre-production assessments of security controls in new systems or systems that are undergoing substantial redesign.
  • Coordination of all IT audit and assessment work done by third-party auditors.
  • Monitoring of third parties' compliance to state security requirements.
6. Information Security Monitoring: Gain situational awareness through continuous monitoring of networks and other IT assets for signs of attack, anomalies and inappropriate activities.
  • Create and implement an event logging strategy.
  • Place sensors, agents and security monitoring software at strategic locations throughout the network.
  • Monitor situational awareness information from security monitoring and event correlation tools to determine events that require investigation and response.
  • Disseminate potential security events to the information security incident response team.
7. Information Security Incident Response and Forensics: Determines the cause, scope and impact of incidents to stop unwanted activity, limit damage and prevent recurrence.
  • Manage security incident case assignments and the security investigation process.
  • Mobilize emergency and third-party investigation and response processes, when necessary.
  • Consult with system owners to help quarantine incidents and limit damage.
  • Consult with human resources on violations of appropriate use policy.
  • Communicate with law enforcement, when necessary.
8. Vulnerability and Threat Management: Continuously identify and remediate vulnerabilities before they can be exploited.
  • Strategic placement of scanning tools to continuously assess all information technology assets.
  • Implement appropriate scan schedules, based on asset criticality.
  • Communicate vulnerability information to system owners or other individuals responsible for remediation.
  • Disseminate timely threat advisories to system owners or other individuals responsible for remediation.
  • Consult with system owners on mitigation strategies.
9. Boundary Defense: Separates and controls access to different networks with different threat levels and sets of users to reduce the number of successful attacks.
  • Assist with the development of a network security architecture that includes distinct zones to separate internal, external and demilitarized-zone traffic and segments internal networks to limit damage, should a security incident occur.
  • Participate in the change management process to ensure that firewall, router and other perimeter security tools enforce network security architecture decisions.
  • Periodically re-certify perimeter security access control rules to identify those that are no longer needed or provide overly broad clearance.
10. Endpoint Defense: Protects information on computers that routinely interact with untrusted devices on the internet or may be prone to loss or theft.
  • Manage processes and tools to detect malicious software.
  • Manage processes and tools that only permits trusted software to run on a device, commonly referred to as white listing.
  • Manage processes and tools to prevent certain software from running on a device, commonly referred to as blacklisting.
  • Manage processes and tools to identity unauthorized changes to secure configurations.
  • Manage processes and tools to encrypt sensitive data.
11. Identity and Access Management: Manages the identities of users and devices and controls access to resources and data based on a need to know.
  • Maintenance of identities, including provisioning and de-provisioning.
  • Enforce password policies or more advanced multifactor mechanisms to authenticate users and devices.
  • Manage access control rules, limiting security access to the minimum necessary to complete defined responsibilities.
  • Periodically recertify access control rules to identify those that are no longer needed or provide overly broad clearance.
  • Restrict and audit the use of privileged accounts that can bypass security.
  • Define and install systems to administer access based on roles.
  • Generate, exchange, store and safeguard encryption keys and system security certificates.
12. Physical Security: Protects information systems and data from physical threats.
  • Maintain facility entry controls and badging systems.
  • Manage equipment and media destruction processes.
  • Maintain building emergency procedures.
  • Perform screening/background checks on job applicants.
  • Implement controls to mitigate facility vulnerabilities.

Friday, June 17, 2011

How to define and secure Mobile Devices?

Mobile Computing: 10 key security tips

If you do not have a portable device management plan in place, now is the time to act. Don't wait until an incident occurs to develop a plan of action.

But keep in mind that reducing the risks of exposure from portable devices and media requires much more work and planning than a simple laptop encryption program.

Here are some suggested steps:
  • Inventory the use of portable devices and media across ALL areas of the organization. This is a difficult, but critical task. If you do not know the size and scope of the problem, how can you expect to manage it?
  • Examine ALL avenues of product acquisition, use and disposal. Does your organization have purchasing contracts in place for certain types of devices? Will your suppliers help you enforce your encryption policies? How about medical product vendors?
  • Understand the data flow on and off each device type. What is the data content being stored on the drives? Determine the sensitivity of the data and the amount being transported. How are the devices being used relative to employee workflow? Don't leave CD/DVDs out of the equation. Often, radiology departments will use CD and DVD devices to record patient diagnostics for use in referrals.
  • Develop an audit plan and gather statistics on the amount and type of data and devices being used within your organization. Conduct a thorough risk assessment for the use of portable computing and storage devices. Present your findings to senior management. Demonstrate ROI based on the costs associated with a breach. Solicit their buy-in for a holistic, problem-based approach. Once senior management support is obtained, educate the organization on the related issues. Provide real-life examples of recent breaches.
  • If your organization doesn't have a portable media/device policy, develop one. Don't forget to address device ownership; data ownership; rules of behavior; contractors and temporary employees; media destruction or sanitization; appropriate identification of what constitutes sensitive information; and when it is appropriate to use a portable device. The policy should specify who may use portable devices under what conditions as well as the process to gain appropriate management approval.
  • Educate ALL users on the content of the portable media/device policy and the organization's expectations of appropriate device handling and use. This is a great opportunity to remind your staff of the risks involved. Education should include training on how to properly transport the device, use it and safely remove sensitive information when it is no longer needed. A policy alone does not constitute an adequate control, nor is it effective in reducing risk. And you should be able to provide documentation validating the training of all staff members.
  • Develop sound layered security controls to reduce risk. Consider the different types of devices and the encryption technologies available for each platform. For example, with laptops, are you encrypting the entire hard disk? If not, can you demonstrate that the individual properly placed a sensitive file within the encrypted container? Are you using hardware-based encryption or software-based tools? Software-based USB drives often require the user to have administrative rights on the computer they are using to mount the drive. Even if the individual has these rights on their office computer (not a good idea), would they expect to have them at a shared computer in a hotel or coffee shop?
  • Investigate end-point security controls. While examining the different devices you need to legitimately service, examine methods and products that will enforce the use of appropriate devices. This will involve controls that can restrict computer USB ports to appropriate white-listed devices. Without such an end-point tool, policy cannot be enforced.
  • Educate the workforce on how to acquire appropriate secure devices and how compliance will be enforced.
  • If your end-point controls support operating in an audit mode, deploy it to monitor USB device activity. This will help fill in areas of device usage you may have missed, such as biomedical devices and dictation equipment.
Finally, deploy your endpoint controls SLOWLY. Allow areas to become comfortable with the controls and adequate time to purchase the appropriate tools. After sufficient roll out, routinely audit compliance and continue to educate the workforce. The success of your program will depend on your educational efforts and the availability of support staff to address issues promptly as they occur.

Tuesday, September 21, 2010

Characteristics of Good IT Governance

Implementing effective IT governance continues to be a challenge

IT governance is about ensuring that the organisation's resources are used the right way to create value while managing IT risks. The Val-T framework from the IT Governance Institute helps address these challenges. The four "Ares" are the core of Val-IT framework. This is a sound framework which helps organisations ensure IT efforts are aligned and IT continues to deliver value.

1) Are we doing the right things?

To quote Peter Drucker: "There is nothing so useless as doing efficiently that which should not be done at all". This is the question about should we be doing something at all. It ensures strategic alignment between business and IT. Is what we are trying to do fit with the organisations vision and strategy? Is it consistent with the business principles?

2) Are we doing them the right way?

This is the question about architecture and standards. Is what we are doing conform to the architecture and process?

3) Are we getting it done well?

This is the question about the execution. Do we have the disciplined delivery and change management processes? Do we have the right skilled resources and are we managing them well? How does our performance measure up to others? Are we effectively managing risks?

4) Are we getting the benefits?

This is a question about realising value from investments in IT/projects. Are we clear about the benefits? Do we have metrics? Is the accountability for the benefits clearly defines?

Characteristics of Good IT Governance
  • IT investments and decisions are assessed in a manner similar to business investments and IT is managed as a strategic asset. This means there is top management participation in key IT decisions. There is board oversight of IT investments and executives are held accountable for realising benefits.

  • IT is essential part of corporate planning and strategic planning. IT understands the business dynamics and contributes to the development of business strategy, which is interlinked to IT strategy. IT and business work together to identify opportunities.

  • Top IT risks are considered within the enterprise risk management framework. Risks such as data protection, IT security and business continuity receive periodic board oversight.

  • IT performance is regularly measured and compared with peers and best practice.

  • How decisions are made and why, is well understood and outcomes are clearly and formally communicated to the stakeholders. Formal exception processes are established and promote transparency as well as allowing organisational learning.