Showing posts with label Strategy. Show all posts
Showing posts with label Strategy. Show all posts

Thursday, August 8, 2013

CIO can be Chief Digital Officer?

It's difficult — if not impossible — to build great digital capabilities without linking to your existing IT capabilities and people

CIOs who do great things in leading IT soon gain extra responsibilities. By helping business leaders to improve their businesses, the CIO becomes an obvious candidate to fill any open role that involves technology, process, or strong governance. Some CIOs become CIO-Plus-COO or CIO-Plus-Head of Shared Services. Others gain new responsibilities in strategy, integration, or innovation.

But there is another leadership role that has arisen in many organizations in recent years: the Chief Digital Officer (CDO). In many companies, "digital" is a cacophony of disconnected, inconsistent, and sometimes incompatible activities.

It's commonly seen that company have three simultaneous mobile marketing initiatives, conducted by different groups, using different tools and vendors. Other companies have multiple employee collaboration platforms with different rules and technologies. The problem is exacerbated as business units do their own things digitally, or as companies hire vendors who can only do things their own way.

The CDO's job is to turn the digital cacophony into a symphony. It's OK to experiment with new businesses and tools, but experimentation must be coupled with building scalable, efficient capabilities.

The CDO creates a unifying digital vision, energizes the company around digital possibilities, coordinates digital activities, helps to rethink products and processes for the digital age, and sometimes provides critical tools or resources. That's why Starbucks — an early leader in all things digital — hired a CDO last year. And it's why many other companies are naming CDOs before they get too far along the digital road.

The title CDO may or may not become permanent in the company. But the responsibilities of the CDO will be required. You may appoint a temporary CDO to get your house in order, or you may develop other ways to get the job done.

Whatever approach you choose, you need to create appropriate levels of digital technology synergy, brand integration, investment coordination, skill development, vendor management, and innovation over the long term.

In an increasingly digitizing business world, most companies need better digital leadership and coordination. You need to create a compelling digital vision, coordinate digital investments, drive appropriate synergies, build a clean technology platform, and foster innovation. You need to energize a busy workforce and generate shared understanding in your senior executive team. 

Sunday, July 14, 2013

Five Ways To Plump Your Security Program Without Going Broke

Some are quick, cheap and often free! Others require a little more time and critical thinking

Addressing cyber-attacks is not just a technology issue. It requires a holistic view from the entire organization. Today's security threats span a broad spectrum of social engineering schemes, international hackers, and insider threats like the recent NSA breach.

It's easy to get overwhelmed by all of the potential threats and where money should be spent to keep up, let alone stay ahead of the curve. Security functions are getting only 70 percent of the resources that they need to do an adequate job" of securing the business, including hardware, software, services and staff. 

The hard stuff is in the next 30 percent." Meanwhile, worldwide spending on security infrastructure, including software, services and network security appliances used to secure enterprise, rose to $60 billion in 2012, up 8.4 percent from $55 billion in 2011, according to Gartner Inc. That number is expected to hit $86 billion by 2016.

Security experts offer five tips for enhancing security that don't cost a lot of cash — and sometimes no money at all — so companies can spend their security dollars on the hard stuff.

1. Patch security holes and identify vulnerabilities

Three of the top 10 botnets reported in February 2013 were more than 8 years old, according to Fortiguard Labs, the threat-researching arm of network security firm Fortinet Inc. in Sunnyvale, Calif. In the most successful attacks, the majority of those threats had been identified and fixed by vendors years earlier, said Derek Manky, global security strategist.

Companies need to keep patches up to date.

2. Install your free firewall and antivirus upgrades

A lot of people don't realize their basic support contracts with most vendors for support, firewalls and antivirus include free upgrades. If you don't have a strategy to revisit what the available technology is that you've already paid for, then you're missing out on a lot of new features and enhancements" that could prevent a security breach. 

Call your vendor and revisit our firewall and antivirus solution contracts.

3. Keep up with BYOD

Personal devices in the business environment are here to stay. Yet 79 percent of businesses had a mobile security incident in the past year, ranging from malicious apps downloaded to a mobile device to unsecure Wi-Fi connections to lack of security patches from services providers, according to a June mobile security report by Check Point Software Technologies.

These mobile security incidents cost companies between $100,000 and $500,000 in staff time, legal fees and resolution processes.

Organizations can improve mobile device security through BYOD agreements with users to ensure they take security precautions. The checklist should include installing available upgrades and patches; ensuring that each mobile device infrastructure component has its clock synced to a common time source; reconfiguring access control features as needed, according to the Computer Security Division of the National Institute of Standards and Technology.

4. Define a enterprise-wide security strategy

Nine out of 10 big companies lacked defined security strategy and security plans, or they re not tied with business goals and business objectives. There's no way to know if you're supporting business objectives unless you take the time to develop the security strategy and make they're sure they're doing the most important things for overall risk reduction. 

5. Educate Employees

Successful attacks are usually ones that exploit the human mind. Humans are always the weakest link in the chain.

Education can help stop employees from falling victim to phishing attacks or pretexting schemes or careless use of login credentials, which accounted for 3 of the top 10 threat actions performed against large companies, according to Verizon's 2012 data breach investigations report.

Friday, May 24, 2013

BYOD is here to stay, Why?


Should enterprise adapting to an increasingly mobile world?

Statistics from major BYOD surveys and analysts over the last year shows that the BYOD trend is strong and will only get stronger. There are already 1 billion smartphone users around the world, with 1.3 billion smartphone and tablet sales expected in 2013.

Employees are using their personal smartphones for work all over the globe. However, the trend is strongest in high growth countries, such as Brazil, Russia and India, and among the youngest workers. Employees bring their own devices because they believe they let them do their jobs better, they like the flexibility to work when they want, and they prefer to carry a single device for work and personal use. Even knowing the security risks and that their companies might be watching their online activities, isn’t stopping this trend. 

IT departments are paying attention. They are aware of the growth of BYOD and are mostly positive about it. High growth countries and the US are more positive and providing the most support. While most IT departments have been supporting BlackBerry and Apple devices, many are realizing the need to support Android and Windows Mobile as well. Not surprisingly, the most popular business applications being used on mobile are email, web browsing, contacts and calendars, however more than half of IT departments report mobile apps being used for office applications, task and project management, social media, sales force automation or CRM as well. 

By embracing the rise of BYOD and enterprise mobility, 2013 presents the opportunity for IT to change their role from service providers and technology partners to leaders and business strategists. By taking the initiative and working closely with all areas of the business, IT can lead the company into the New Age of enterprise mobility – enabling increased productivity and operational efficiencies, securely, and cost-effectively. 

See below A Visual Display of the Current State of BYOD 2013:

Monday, February 25, 2013

AusCERT - Cyber Crime and Security Survey Report 2012

Over half of respondents have increased their expenditure on IT security in the previous 12 months

The recently released Cyber Crime and Security Survey Report 2012 conducted by CERT Australia, in partnership with the Centre for Internet Safety at the University of Canberra, is readily available from CERT Australia’s public website – see www.cert.gov.au.

It is highly recommended reading for IT & Information Security professionals within Australia.

Some 450 businesses were approached to participate in the CERT Australia Cyber Crime and Security Survey, from which the report was developed. It is suggested that you share the report with your IT colleagues (and vice versa).

The report highlights cyber security issues and may be suitable for referencing as external source - providing justification for funding of IT/control system security initiatives.

The inaugural Survey was designed to obtain a better understanding of how cyber incidents are affecting the businesses that form part of Australia’s systems of national interest – the businesses that partner with CERT Australia.


The survey consisted of 24 questions, both closed and open ended, to ascertain:

  • business description
  • types of IT security used
  • types of cyber security incidents experienced, and
  • industry reporting of incidents.


The findings from the survey provide a picture of the current cyber security measures these businesses have in place; the recent cyber incidents they have experienced; and their reporting of them.

Refer here to download the report.

Saturday, August 25, 2012

Effectively Assessing Information Risks within the Enterprise

3 Lines of Cyberdefence

By combining responsible management, risk management and compliance functions and internal audits, organizations will go far in securing their data and systems. 

To succeed, internal auditors and business systems owners, including chief information security officers, must collaborate more closely to assure the security of their organizations' data systems. 

A new report from PwC, Fortifying Your Defenses: The Role of Internal Audit in Assuring Data Security and Privacy, which identifies three lines of cyberdefense:  

Management: Companies that are good at managing information security risks typically assign responsibility for their security regimes at the highest levels of the organization. Management has ownership, responsibility and accountability for assessing, controlling and mitigating risks. Risk management and 

Compliance Functions: Risk management functions facilitate and monitor the implementation of effective risk management practices by management, and help risk owners in reporting adequate risk-related information up and down the enterprise.

Internal Audit: The internal audit function provides objective assurance to the board and executive management on how effectively the organization assesses and manages its risks, including the manner in which the first and second lines of defense operate.

It's vital that internal audits be at least as strong as the management and risk management and compliance functions for critical risk areas. Without internal audits that provide proficient and objective assurance, organisations risk having their information privacy practices becoming inadequate or outmoded. 

This is a role that internal audit is uniquely positioned to fill, but, it must have the support and the resources to match to do so.

Refer here to download the report.

Thursday, July 26, 2012

The Department of Defense Cloud Computing Strategy

Goals presented “consolidate and share commodity IT functions resulting in a more efficient use of resources.”


The Department of Defense needs to accomplish its critical global missions despite a decreasing budget and rising cybersecurity threat. To that end, the Chief Information Officer of the DoD, Teri Takai, released its Cloud Computing Strategy, which outlines its goals to accelerate the adoption of cloud computing throughout the department.


In the strategy, the Office of the CIO explains why it wants to move to the cloud, its goals, the challenges that stand in its way and methods to mitigate them, and the coming steps the Defense Department plans to take to get there. The strategy uses the National Institute of Standards and Technology’s definition of cloud computing for their strategy.


NIST defines cloud computing as: “A model for enabling ubiquitous, convenient, on‐demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.”


DoD likes this definition because it includes Software as a Service, Platform as a Service, and Infrastructure as a Service. According to the CIO, the DoD currently has a “duplicative, cumbersome, and costly set of application silos” that can benefit from more cloud computing. The goals presented in the Cloud Computing Strategy is to “consolidate and share commodity IT functions resulting in a more efficient use of resources.”


The DoD hopes to provide device and location independent on-demand secure global access to mission data and enterprise services. They also hope to enable rapid application development and reuse of applications by other organizations. This means both sharing and adopting the most secure commercially available cloud services.


The Cloud Computing Strategy also lays out four steps for implementing the Department of Defense Cloud Environment. The first will be to “Foster Adoption of Cloud Computing” by establishing a joint governance structure to drive the transition and an Enterprise First approach while reforming DoD IT finance, acquisition, and contracting and increasing cloud outreach and awareness.


The next step is to “Optimize Data Center Consolidation” by consolidating and virtualizing legacy applications and data. The third step is to “Establish the DoD Enterprise Cloud Infrastructure” so that it’s agile, consolidated, and secure.


The last step will be to “Deliver Cloud Services” using existing DoD cloud services and external providers. The CIO will provide oversight for component implementation of these steps.


Please refer here to download the strategy.

Friday, July 6, 2012

Why Business Continuity is Critical For Your Business?

4 Tips to Gain Upper Management Attention


Companies often make many strategic decisions such as outsourcing, off-shoring and long supply chains without full consideration of the consequence of business interruption.


They primarily focus in adding short-term value to the bottom-line, but when these strategies fail to deliver, reputation and brand image are compromised. Short-term financial losses might be containable, but long-term loss of market share is often much more damaging.


By implementing effective business continuity plans, businesses can increase their recovery capabilities dramatically. And that means they can make the right decisions quickly, cut downtime and minimize financial losses. So, getting buy-in at the top is crucial. It requires professionals to have better understanding of the concerns of top management and an ability to communicate risk issues in a common language.


Here are a few ways business continuity practitioners can seek upper management attention.


Emphasize business consequences: Many leaders were shaken by the corporate impact that the Gulf of Mexico oil spill incident had on the finances, share-price and reputation of British Petroleum.


Business continuity managers need to bring these real-life cases in their presentation to management and further use their skills to identify their own organization's potential high consequence events. 


Implement innovative tests and exercises: A traditional difficulty is that BCM practitioners do not report at a high enough level to affect decisions. Although often true, they are not without influence, and one way to use it is in developing an innovative testing and exercising program.


In the past, too many exercises have concentrated on evacuation, safety and emergency response. Although these are required, top management employs specific specialists to handle safety and security on their behalf. 


What BC practitioners need to do is choose scenarios and techniques in their exercises that really interest the leadership team. Using scenarios that highlight fundamental business threats and challenging top management to respond can be scary, but it also can raise the profile of BCM rapidly.


Techniques such as war games, stress testing, scenario planning and horizon scanning are becoming important to business continuity tests. These are areas in which the BCM professional could and (in the future) really should take a leading role.


Be more assertive: BCM professionals can get top level attention by taking a more assertive position to organizational change. Clearly, there are limits to which individuals can become involved in strategic decisions, but by producing a well considered analysis of the consequences of change, they can often get senior management interest.


Decisions can be reviewed or modified if consequential risks are better articulated. BCM professionals can do this through a risk management organizational framework and can make their voice heard.


Communicate BCM benefits: Practitioners must concentrate on finding value and benefits for BCM and promoting them.


For example, if having proper BCM in place helps the organization get on the approved supplier list for a major customer, it's the BC professional's job to ensure that everyone knows about it. If it were a key deciding factor that actually won a big contract, make sure that sales, marketing and finance recognize and publicize that fact.


If BCM helps procurement eliminate high-risk suppliers, again getting that message out through whatever communication vehicles is key.

Saturday, May 19, 2012

The evolving role of the CISO

New study by IBM
A study by IBM’s Center for Applied Insights concludes that there are now three ‘types’ of CISO: influencers, protectors and responders. Evolution towards the ‘influencer’ role is necessary, and happening.
Security is now seen as a vital aspect of business, and the role and influence of the chief information security officer is correspondingly rising, concludes Finding a strategic voice, a new study from IBM.


The primary driver, suggests IBM, is that security is now recognised as a business rather than just a technology imperative. “In today’s hyper-connected world,” states the report, “information security is expanding beyond its technical silo into a strategic, enterprise-wide priority,” driven by the increasing number of high profile attacks.


The result is that while “many organizations remain in crisis response mode, some have moved beyond a reactive stance and are taking steps to reduce future risk.” Key to this is that business is beginning to understand what security experts have been saying for years: security is not a thing or a product that can be bought and installed – it is a continuous process at the heart of the business itself.
“The Influencers have the attention of business leaders and their boards. Security is not an ad hoc topic, but rather a regular part of business discussions and, increasingly, the culture. These leaders understand the need for more pervasive risk awareness.” Influencers have a strategic role on business security. “Responders,” says the report, “are more tactically oriented.
They are concentrating on foundational building blocks: incorporating new security technology to close security gaps, redesigning business processes and hiring new staff. While technology and business processes are still important to Influencers, they are in the mode of continuously innovating and improving rather than establishing basic capabilities.”


In reality, the clear implication here is that business either needs both an influencer and a responder, or that the influencer needs also to be a responder: strategy needs implementation tactics. But what of the protectors? This is the traditional view of security. Almost half of the report’s respondents take this role, a role that is likely to be the most prevalent in smaller companies.
“These security leaders,” says IBM, “recognize the importance of information security as a strategic priority. However, they lack important measurement insight and the necessary budget authority to fully transform their enterprises’ security approach.” “This data painted a profile of a new class of CISO leaders who are developing a strategic voice, and paving the way to a more proactive and integrated stance on information security,” said David Jarvis, IBM’s author of the report.
“We see the path of the CISO is now maturing in a similar pattern to the CFO from the 1970s, the CIO from the 1980s – from a technical one to a strategic business enabler. This demonstrates how integral IT security has become to organizations.”
In short, this IBM study demonstrates that security and the role of the CISO is evolving from a reactive stance to a proactive stance, both within security itself and the wider business – but there is still a long way to go from protector to influencer.


To read further please refer here.

Monday, March 26, 2012

How to develop effective Information Security Awareness Program?

Security Awareness Training Topics

Security Awareness is a key challenge in Implementing information security. Many organizations find it difficult to provide the right information security awareness to its staff and thus have less support from its staff in implementing the information security measures.

It is important to tailor the security awareness program to cover the potential threats and risks of the organization.

The first item in the security awareness should be about the password security. The password security awareness should cover topics such as:
  • What is the password policy of the organization

  • How to build secure but easy to passwords in compliance with the password policy

  • Possible tools for password storage and how to use them securely

  • Now writing down of passwords in excel or paper or sickies

  • How the Password sharing is dangerous to the staff in specific and the organization in general
Keeping the work place clean or Clean Desk Policy. This should include topics like:
  • Importance of having a clean workplace from a security perspective

  • Potential confidentiality issues when the critical documents are in the eyes of those who are not supposed to have access

  • Importance of shredding of documents when they are no more required

  • Keeping the printer and fax trays empty all the time
Information Handling and Classification

Classification guidelines and information on how to handle the information should be part of this discussion. this should cover topics such as:
  • Classification labels and when and how to use them

  • Precautions to take when sending or receiving such information
Physical Security

Visitor Control is another area, which can be part of information security awareness. Checkout this cartoon on Physical & Information Security Awareness, it can be part of the security awareness materials.

Key things include (1) questioning the visitors without a badge or who looks suspicious (2) accompanying the visitors to confidential areas such as datacentre (3) about piggybacking etc…

Another Physical Security control is about the protection of laptops and other mobile computing devices. It is often the laptops, smart phones, or removable devices which are getting lost. Protection of these devices are critical in information security. Many times we have heard about data leakage through lost or stolen devices

Another key area to include is Incident Reporting and Management. This should cover the types of incidents to be reported, whom to be reported, means of reporting etc…

Phishing & Social Engineering is another key topic which can be included. This will help the staff not to become a victim of such attacks by malicious internal or external entities. Cover the possibility of email and phone channels for social engineering.

Social Networking and its threats are another set of topic which can be covered within the security awareness session. Topics like what to post in the social media and what not, who represents the company in social media and things like that.
Bring Your Own Device or BYOD and use of the personal device usage within the organization. What are the restriction related to BYOD including the removable media

Acceptable use of the IT environment such as Internet and Email, Desktop systems etc…

Desktop security including the use of antivirus, locking or logging of the system when not in use.

Importance of data backups. Corporate process on backups. Is it allowed to backup only to the file servers? Or can the user backup to a USB or CD.

Critical Success Factors of an Information Security Awareness session
  • Engaging with the staff interactively

  • Quoting real life examples. It would be helpful to include News items on related contents

  • Having good humour included in the topics

  • References to the corporate security policies is a key item to be included in the related topics

  • Choose the right topics for the right group of audience. Social engineering, desktop security etc might be a topic for all groups.

    Your board members or senior management may not want to undergo one hour awareness sessions and thus, the topics should be carefully opted when designing the materials for them

  • Have a test or a quiz at the end of the session. It will give an opportunity to understand the effectiveness of the awareness sessions
The above list gives a number of topics useful for a typical information security awareness session.

Tuesday, August 23, 2011

Smart grid cybersecurity strategy – industry proposals

Smart grid security challenge highlighted in report

Government plans to create a smart grid for energy networks will require a coordinated focus on cybersecurity as communication networks play a key role, according to a report from The Energy Networks Association (ENA).

The ENA published the report for the Department of Energy and Climate Change (DECC), which is responsible for the energy smart grid. The findings of the research, which was carried out by consultancy KEMA, revealed that the government and network providers need a more "coherent and joined-up approach" to secure the smart grid.

Security a top priority in smart grid development

The report outlines how the smart grid will affect networks and describes how cybersecurity should be an important consideration when developing the smart grid's architecture, technology and management systems.

For example, the report says: "ICT security, along with computing system reliability, safety and maintainability, are critical attributes for smart grid implementation and operation, and need to be considered as part of overall risk management for this critical national infrastructure."

Coordinating the smart grid project

Last week, the IT sector, under the wing of Intellect, got involved in the smart grid debate with the launch of cross-industry organisation SmartGrid GB. This group brings together IT companies, environmental organisations, government, regulators and consumer groups. It will coordinate the multiple stakeholders and advise the government.

Robert McNamara, energy and environment programme manager at Intellect, is SmartGrid GB's manager. He welcomed the report: "A lot of data will be transported on the smart grid and through smart metering. It is absolutely imperative that security is the number one priority."

IT suppliers invited to bid for smart grid contracts

The DECC has already put a notice out to IT suppliers informing them to be ready to bid for work. A new company will be set up to manage the data that smart meters send and receive. The central data and communications company (DCC), as it is known, will require services from IT and communication service providers.

The smart grid project involves using smart meters in the home to help consumers control their energy usage. But a survey, which was commissioned by smart meter technology provider T-Systems and carried out by the Economist Intelligence unit, revealed antipathy towards the government's plans to roll out smart meters to 30 million homes by 2020. Consumers are more concerned about the financial costs of using smart meters than the environmental costs of inefficient energy use.

Friday, July 29, 2011

Obama to Battle International Cybercrime

Administration Strategy Sees IT as Fostering Cybercrime

President Obama Monday declared a national emergency to battle what he characterizes as the extraordinary threat transnational criminal organizations pose to the nation's security, foreign policy and economy.

As part of the national emergency declaration, the White House issued a strategy to combat transnational organized crime in which cyber plays a crucial component in fostering and combating transnational cybercrime.

"During the past 15 years, technological innovation and globalization have proven to be an overwhelming force for good," Obama said in the introduction to the strategy. "However, transnational criminal organizations have taken advantage of our increasingly interconnected world to expand their illicit enterprises."
The strategy's 56 priorities include enhancing intelligence and information sharing and protecting the nation's financial system and strategic market against transnational organized crime.
Transnational organized crime has traditionally been largely regional in scope, hierarchically structured and had only occasional links to terrorism, the strategy says, adding that's no longer the case. "Today's criminal networks are fluid, striking new alliances with other networks around the world and engaging in a wide range of illicit activities, including cybercrime and providing support for terrorism," the strategy states. "Virtually every transnational criminal organization and its enterprises are connected and enabled by information systems technologies, making cybercrime a substantially more important concern."
The strategy says criminal networks employ cyber technologies to perpetrate sophisticated frauds; create the potential for the transfer of weapons of mass destruction to terrorists; and expand narco-trafficking and human and weapons smuggling networks.
Among the actions the strategy says the administration will take is to enhance domestic and foreign capabilities to combat the increasing involvement of transnational-organized-crime networks in cybercrime and build international capacity to forensically exploit and judicially process digital evidence.

According to the strategy, transnational-organized-crime networks cost consumers billions of dollars annually, threaten sensitive corporate and government computer networks and undermine worldwide confidence in the international financial system. Through cybercrime, transnational criminal organizations pose a significant threat to financial and trust systems - banking, stock markets, e-currency and value and credit card services - on which the world economy depends.

$1 Billion in Fraud Against U.S

How bad is the situation? The strategy contends online frauds perpetrated by Central European cybercrime networks have defrauded American citizens and businesses of $1 billion in a single year. And, the Secret Service says financial crimes facilitated by anonymous online criminal fora result in billions of dollars in losses to the nation's financial infrastructure.

Pervasive criminal activity in cyberspace imperils citizens' and businesses' faith in digital systems, which are critical to our society and economy, the strategy says.

The strategy sees computers and the Internet playing a role in most transnational crimes, either as the target or the weapon used in the crime. "The use of the Internet, personal computers and mobile devices all create a trail of digital evidence," the strategy states. "Often the proper investigation of this evidence trail requires highly trained personnel. Crimes can occur more quickly, but investigations proceed more slowly due to the critical shortage of investigators with the knowledge and expertise to analyze ever increasing amounts of potential digital evidence."

Wednesday, July 20, 2011

International Strategy for Cyber Space

Preparing for 21st Century Security Challenges

Cyberspace, and the technologies that enable it, allow people of every nationality, race, faith, and point of view to communicate, cooperate, and prosper like never before.

Today, as nations and peoples harness the networks that are all around us, we have a choice. We can either work together to realise their potential for greater prosperity nd security, or we can succumb to narrow interests and undue fears that limit progress.

Cyber security is not an end unto itself; it is instead an obligation that our governments and societies must take on willingly, to ensure that innovation continues to flourish, drive markets, and improve lives. While offline challenges of crime and aggression have made their way to the digital world, we will confront them consistent with the principles we hold dear: free speech and association, privacy, and the free flow of information.

Envision a future in which reliable access to the Internet is available from nearly any point on the globe, at a price that businesses and families can afford. Computers can communicate with one another across a seamless landscape of global networks permitting trusted, instantaneous communication with friends and colleagues down the block or around the world.

Content is offered in local languages and flows freely beyond national borders, as improvements in digital translation open to millions a wealth of knowledge, new ideas, and rich debates. New technologies improving agriculture or promoting public health are shared with those in greatest need, and difficult problems benefit from global collaboration among experts and innovators.

This, in part, is the future of cyberspace that the United States seeks—and the future we will work to realize.

You can download this paper from here: http://www.logicalsecurity.com/resources/whitepapers/Cyberspace_Strategy_INTL%20051611.pdf

Monday, July 18, 2011

Department of Defense Strategy for Operating in Cyberspace

"Cybersecurity threats represent one of the most serious national security, public safety, and economic challenges we face as a nation"

The Department of Defense released today the DoD Strategy for Operating in Cyberspace (DSOC). It is the first DoD unified strategy for cyberspace and officially encapsulates a new way forward for DoD’s military, intelligence and business operations.

The five primary pillars of the strategy are:
  1. DoD is treating cyberspace as an operational domain, like land, air, sea, and space.
  2. DoD introducing new active cyber defenses. Active defenses use sensors, software and signatures to detect and stop malicious code;
  3. Working with Department of Homeland Security and the private sector to protect critical infrastructure;
  4. DoD building collective cyber defenses with our allies and international partners;
  5. Enhance network security. A more secure and resilient internet is in everyone´s interest.
Dowload the document here: http://www.defense.gov/news/d20110714cyber.pdf

Saturday, July 16, 2011

Attorneys General seek to co-operate in terms of Cybercrime

Cyber security and crime represents a significant and growing threat to everyone around the world

The Attorneys General from the US, the UK, Canada, Australia and New Zealand plan to co-ordinate their efforts to combat internet crime more closely. The prosecutor quintet's third meeting since 2009 will be held on Thursday in Sydney, Australia.

According to a media release by the hosting Australian Attorney General, Robert McClelland, the meeting will focus on joint and cooperative actions that can be taken to address the growth of international cyber-threats. McClelland's spokesperson denied reports of potential plans for a cybercrime agreement between the quintet countries, pointing out Australia's ongoing preparations to sign and ratify the 2001 Council of Europe Convention on Cybercrime.

In late June, McClelland and the Australian home secretary, Brendan O'Connor, introduced a bill that is designed to prepare Australia for adopting the Convention on Cybercrime. In addition to the ability to "quick freeze" telecommunications data, the bill aims to regulate confidentiality obligations in terms of data access, and contains minor amendments to the criminal laws against intrusions into computers and data manipulations. The bill is currently being discussed by the Joint Select Committee on Cyber Security.

With Australia intending to adopt the Convention on Cybercrime, the only remaining quintet member that will have not done so is New Zealand. However, the Convention still needs to be put into practice, not only in Australia, but also in the UK and in Canada. The Convention on Cybercrime is currently
only in force in the US. The UK will follow in September 2011.

At their meeting in Sydney, the five Attorneys General will also lead discussions on a range of key national security and legal policy issues. For example, the UK Attorney General, Dominic Grieve, will report on the disclosure of digitally stored material, while Robert McClelland will present Australia's strategy for countering violent extremism on the internet.

The Australian authorities say that they will spend up to a million dollars (about £660,000) on supporting citizens' rights groups that raise public awareness on violent extremism and build community resilience to radicalisation and extremist views.

Friday, July 15, 2011

Virtual Event: Mitigation Strategies for Today's Global Enterprise

ISACA: Enterprise Risk Management

As companies become more global, risks increase, as does the need for effective enterprise risk management (ERM). Join ISACA and SearchCompliance.com on 10 August, 6:45AM-4:30PM EDT (UTC -4), for a free virtual seminar and tradeshow, Enterprise Risk Management, Mitigation Strategies for Today's Global Enterprise, that will provide practical ERM advice from leading experts.

By attending, you will learn how to spot opportunities and develop an action plan, understand why risk management should be part of your business culture, and gain insight about who should be contributing to the risk process. You will also have the opportunity to network with peers from around the world and earn up to 5 continuing professional education (CPE) hours.

Register now, for 10 August and make a difference in your enterprise by learning how to implement effective ERM.

Educational Sessions:

Session 1: Enterprise Risk Management in the European Landscape
Session 2: Enterprise Risk Management: Your Role in Reducing Risk to Business
Session 3: Sustainability and Enterprise Risk Management
Session 4: Supply Chain Risk Management
Session 5: Managing Network Security Threats with an ERM Strategy

Thursday, July 14, 2011

Mobile Security Summit

Free Online Event

Consumer-oriented devices are used to access the enterprise network, email and applications on the move. While the productivity gains and strategic opportunities of accessing data remotely are real, enterprise decision makers are increasingly challenged by cost and security.

Join industry experts, analysts and end users as they identify the key vulnerabilities you should be aware of and the solutions that will allow you to keep your business running securely.

Sign up to attend the live interactive webcasts on Wednesday, July 13, 2011, or view them afterward on demand here: http://www.brighttalk.com/r/Grz .

Presentations include:

‘Thriving in the Era of the Mobile Workforce’
Christian Kane, Forrester Research; Gaston Brown, Hobart Brothers Co.; Matthew Dieckman, SonicWALL

‘Strategic Mobile Security: A Practitioner Panel’
Chenxi Wang, Forrester; Anil Karmel, Los Alamos Nat'l Lab; Terrell Herzig, UA Medical Center

‘The Composition of Mobile Security – Risks and Results’
Daniel Miessler; Principal Security Consultant, HP Application Security

‘Top 10 Mobile Risks’
Vladimir Jirasek, Senior Enterprise Security Architect, Nokia

‘Leveraging Mobile Devices for Strong Authentication’
David Mahdi, Product Manager, Entrust

You can view the full lineup and sign up to attend any or all presentations at http://www.brighttalk.com/r/Grz . This summit is part of the ongoing series of thought leadership events presented on BrightTALK(TM). I hope you are able to attend.

Tuesday, June 21, 2011

Webinar: Effective Information Security Risk Assessments

Align Practices with Business Strategy

From payment card fraud to skimming attacks and corporate account takeover, we've seen a wide variety of threats to banking institutions and their customers.
And with the advent of the ID Theft Red Flags Rule, and in the aftermath of the economic upheaval, we know banking regulators are paying closer attention to institutions' information security practices.

So, in light of increased threats and greater regulatory scrutiny, how should a banking institution approach one of its most critical undertakings - the information security risk assessment?

Learn how in this exclusive new webinar on 30th June 2011 and 18th July 2011. Guided by an experienced banking/security leader, you will receive timely, hands-on advice and new risk assessment tools regarding:
  • How to build process and strategies to identify and manage risks;
  • Risk assessment techniques that work - and those that don't;
  • How to satisfy your regulators' and customers' security and privacy needs and requirements.
Refer here for further details and to register for the event.

Sunday, June 5, 2011

Security concern as cyber threat grows

Australian Government will soon release a white paper focusing on Cyber Security!

The Gillard government has become so concerned about attacks on the computer systems of industry and the public sector it will produce a white paper focusing largely on cyber security.

In a speech in Adelaide today, Attorney-General Robert McClelland will warn that foreign intelligence agencies, criminal gangs and commercial competitors are targeting intellectual property in Australia worth $30 billion.

Mr McClelland will say malicious activity is increasing to a point where computer systems in both the government and the private sector are under continuous threat.

"Cyber espionage is not just the purview of foreign intelligence agencies, but something undertaken by criminal organisations and commercial competitors alike," Mr McClelland says.

And Defence Minister Stephen Smith says attacks on Australia's computer systems are becoming increasingly sophisticated and targeted.

Development of the paper will be led by the Department of Prime Minister and Cabinet and extensive public consultations will begin next month with the release of a discussion paper.

It is expected the white paper will be ready in the first half of next year.



Mr McClelland says the cyber threat to Australia is real, evolving and continuing to test the nation's defences. "It comes from a wide range of sources, and from adversaries possessing a broad range of skills."

The cyber white paper will help Australians to connect to the internet with confidence. The document will provide a comprehensive review of how governments, businesses and individuals can work together to realise the full benefits of cyberspace while ensuring risks can be managed.

"The digital world is evolving rapidly. It's transforming the way governments and businesses operate and the way Australians connect to each other and the world," Mr McClelland says.

Minister for Broadband, Communications and the Digital Economy Stephen Conroy says the white paper recognises the increasingly significant role the online environment plays in the lives of Australians.

"With increased availability and use of technology, it's important that all Australians are able to go online safely and securely," he says.

Source: AustralianIT

Thursday, June 2, 2011

Security and Prosperity in the Information Age

America's Cyber Future!

America’s growing dependence on cyberspace has created new vulnerabilities that are being exploited as fast as or faster than the nation can respond. Cyber attacks can cause economic damage, physical destruction, and even the loss of human life. They constitute a serious challenge to U.S. national security and demand greater attention from American leaders.

Despite productive efforts by the U.S. government and the private sector to strengthen cyber security, the increasing sophistication of cyber threats continues to outpace progress. To help U.S. policymakers address the growing danger of cyber insecurity, this two-volume report features accessible and insightful chapters on cyber security strategy, policy, and technology by some of the world’s leading experts on international relations, national security, and information technology.

Volume I

America’s Cyber Future: Security and Prosperity in the Information Age
By Kristin Lord and Travis Sharp

Volume II

Note: Chapters are bookmarked within the Table of Contents.

Chapter I: Power and National Security in Cyberspace
By Joseph S. Nye, Jr.

Chapter II: Cyber Insecurities: The 21st Century Threatscape
By Mike McConnell

Chapter III: Separating Threat from the Hype: What Washington Needs to Know about Cyber Security
By Gary McGraw and Nathaniel Fick

Chapter IV: Cyberwar and Cyber Warfare
By Thomas G. Mahnken

Chapter V: Non-State Actors and Cyber Conflict
By Gregory J. Rattray and Jason Healey

Chapter VI: Cultivating International Cyber Norms
By Martha Finnemore

Chapter VII: Cyber Security Governance: Existing Structures, International Approaches and the Private Sector
By David A. Gross, Nova J. Daly, M. Ethan Lucarelli and Roger H. Miksad

Chapter VIII: Why Privacy and Cyber Security Clash
By James A. Lewis

Chapter IX: Internet Freedom and Its Discontents: Navigating the Tensions with Cyber Security
By Richard Fontaine and Will Rogers

Chapter X: The Unprecedented Economic Risks of Network Insecurity
By Christopher M. Schroeder

Chapter XI: How Government Can Access Innovative Technology
By Daniel E. Geer, Jr.

Chapter XII: The Role of Architecture in Internet Defense
By Robert E. Kahn

Chapter XIII: Scenarios for the Future of Cyber Security
By Peter Schwartz

This study was co-chaired by Robert E. Kahn, Mike McConnell, Joseph S. Nye, Jr. and Peter Schwartz, and edited by Kristin M. Lord and Travis Sharp.

Download Volume I (PDF)
Download Volume II (PDF)

Saturday, May 21, 2011

International Cyber Security Strategy from White House

Protecting Nation’s Critical Infrastructure

The Obama administration, in a White House event Monday that featured four cabinet secretaries, issued its international cybersecurity strategy with the goal to work with other nations to promote an open, interoperable, secure and reliable information and communications infrastructure that supports global trade and commerce, strengthens international security and fosters free expression and innovation.

To achieve that goal, the strategy says, cooperation among nations is needed to build and sustain an environment in which norms of responsible behavior guide states' actions, sustain partnerships and support the rule of law in cyberspace.

Clinton outlined the seven principles in the international cybersecurity framework:

Economic engagement Promoting international standards, innovation and open markets to ensure that cyberspace serves the needs of the global economies and innovators.
Protecting networks: Enhancing security, reliability and resiliency because strong cybersecurity is critical to national and economic security in the broadest sense.

Law enforcement: Extending collaboration and the rule of law to strengthen confidence in cyberspace and pursue those who would exploit online systems.

Military cooperation: Preparing for 21st century security challenges because the nation's commitment to defend its citizens, allies and interests extends to wherever they might be threatened,

Multi-stakeholder Internet governance: Fostering governance structures that effectively serve the needs of all Internet users.

International development: Building capacity, security and prosperity to promote the benefits of networked technology globally, enhance the reliability of shared networks and build a community of responsible stakeholders in cyberspace.

Internet freedom: Supporting fundamental freedoms and privacy to help secure fundamental freedoms as well as privacy in cyberspace.

The release of the international cybersecurity policy is the second major Obama administration IT security initiative in as many weeks. On Thursday, the White House introduced a cybersecurity legislative package that would codify the Department of Homeland Security as the lead agency in protecting federal civilian agencies and the national critical IT infrastructure as well as nationalize data breach notification and the toughening of penalties for cybercrimes (see
White House Unveils Cybersecurity Legislative Agenda).