Showing posts with label Technology. Show all posts
Showing posts with label Technology. Show all posts

Federal Meeting on Cyber Insurance




Federal Cyber Insurance Meeting
November 21, 2014

The new "Cyber Insurance" industry is getting a federal once over from the US Federal Treasury. These new insurance standards for information systems will reinforce and implement and test information security best practices among all US companies. Below are some perspectives on this meeting's objectives and success.

http://www.politico.com/morningcybersecurity/1114/morningcybersecurity16198.html

TREASURY, INDUSTRY MEET ON CYBER INSURANCE - The Treasury Department held a roundtable discussion on cyber insurance. Included were representatives from insurers, reinsurers, brokers, insurance consumers and senior federal agency leaders.  Topics included markets for cyber insurance and how insurance can spread and incentivize cybersecurity best practices - a process that the Obama administration has heavily encouraged and touted. Treasury Deputy Secretary Sarah Bloom Raskin reiterated the agency's "interest in the cyber insurance market and desire to encourage the development of market forces that could embrace our nation's cybersecurity" 

http://www.bna.com/treasury-plans-meeting-n17179907061/

The Treasury Department announced plans for a public meeting that will include an examination of developments in the cyberinsurance market and a cybersecurity "framework" developed by the Obama administration. 

Meeting notice: https://www.federalregister.gov/articles/2014/10/21/2014-24990/open-meeting-of-the-federal-advisory-committee-on-insurance


.wdnii.

© 2014 Norris Proprietaries Inc.

Information Class Warfare part V

Information Security Process: Repeat
August 30, 2013


Information Security like all relationships requires time and effort. I use a security management system which works well for the companies I have secured and maintained. Classify, Secure, Audit, Educate, Repeat. Not a memorable acronym, but a very valuable path to cycle through. Each iteration has made my companies better prepared for the inevitable attacks and recovery easier and faster.


Repeat, yes, more than just to keep you as a security professional relevant to your employer, but also, repeat at sporadic intervals.

Perhaps this is the most important step, but all of the previous steps should be repeated.

Classification: Revisit your information classification document at least annually to verify that types of information can be added or removed. I have found that the levels of security and access rarely change, more likely that some services have been added or removed in the past year, so the information associated with those products needs to be added to the scope of your security planning or removed.

Securing Devices: These documents should be revisited more often, a scheduled review should be done at least every six months, but they should also be revisited every time a new vulnerability is released for the various systems or networks to verify that adequate controls are in place to mitigate a loss and that security is still at the same levels before the vulnerability was known.

Auditing procedures are generally an ongoing activity, but the guidelines and tools should be reviewed at least annually to see if there are better ways to make the job of auditing easier.

Education for each employee should be part of the on-boarding process, with static links pointing them to useful information specific to their job and a time should e set aside to visit each team at least once a year to see if they have any new issues they wish to address. Short fifteen minute meetings do not impact productivity and longer detailed questions can be answered outside of the meeting scope.

I hope this short series of articles was of use to you, these are some general principles that I use every day as an information security professional.


.wdnii.
© 2013 Norris Proprietaries Inc.

Information Class Warfare part IV

Information Security Process: Security Education
August 29, 2013

Information Security like all relationships requires time and effort. I use a security management system which works well for the companies I have secured and maintained. Classify, Secure, Audit, Educate, Repeat. Not a memorable acronym, but a very valuable path to cycle through. Each iteration has made my companies better prepared for the inevitable attacks and recovery easier and faster.


Security Education is always an interesting topic for me to espouse. This can be done in large meetings with power points, white boards and boring speeches, just to show that you have exposed every employee to the magic of security. Another alternative are the various online materials which employees can use on their own, the more interesting piece is that your employees can refer back to these materials when they are actually useful.

Another way to avoid the large auditoriums and conference rooms full of employees who would rather be working and helping the company keep and create new revenue is to hold small short meetings with the various teams and if there needs to be longer discussions break those into several small 15 minute meetings. Getting directly to the specific points, flaws and how they can best keep your company information accessible, correct and private. This of course requires you as a security professional to spend many more hours preparing different presentations and holding many more meetings, spending much more time talking than the standard several hour big speech which usually causes more confusion and glazed expressions than a better security posture for your company. This method also lets your coworkers know that you are available if they have any issues, or questions.

The educational points on which I like to focus are that security is each persons responsibility, and as they say in New York "If you see something, say something". These general speaking points can be tailored into relevance for almost every group. I also try to let them describe what they feel are the relevant security issues in their departments, doing this twice once at the beginning of the presentation and then at the end after they have had a chance to hear why you think the various pieces of their job are important.

A few don'ts about your presentation, don't try to prove you are an expert in their field, don't try to be their friend, and don't over simplify your requirements.

I hope this is helpful, just a few tricks that I use every day when I do my various roles as a security professional.


.wdnii.
© 2013 Norris Proprietaries Inc.

Information Class Warfare part III

Information Security Process: Internal Auditing
August 28, 2013


Information Security like all relationships requires time and effort. I use a security management system which works well for the companies I have secured and maintained. Classify, Secure, Audit, Educate, Repeat. Not a memorable acronym, but a very valuable path to cycle through. Each iteration has made my companies better prepared for the inevitable attacks and business recovery easier and faster.


I cover auditing of the various security policies in this short article. Perhaps one of the driest piece of this repetitive puzzle, unless you decide to make this a game.

Continuous scanning, is one of the best methods to secure internal and external networks. These will detect poorly configured servers before external auditors, or hackers, and alert you to each device someone attempts to slip onto your network. Using a log consolidation system, helps identify threats and attacks, but can also be used for auditing. Attack each server with one of the various vulnerability frameworks and rotate through those only during maintenance windows or when agreed by the product owner. The logs will help indicate if there are any additional vulnerabilities that can be exploited, along with the framework reporting.

The game I generally see security professionals play is to attack servers and try to determine vulnerabilities before the System or Network Engineers are able to patch those servers, this always encourages poor cooperation between these teams, which succeed or fail only with each others help. A more interesting way is to hire outside auditors to test your site security or internal corporate security, and then run your own internal tests to see if you can find more vulnerabilities than they did. This is always more rewarding and rarely incurs the wrath of those on your own team.

Internal Auditing is a crucial piece of the the security puzzle, and must be regularly executed to maintain a working and thorough knowledge of your networks, perimeters and the success of your policies.

.wdnii.
© 2013 Norris Proprietaries Inc.

Taught by Dad

Confidentiality
June 16, 2013


Growing up I lived in small towns all my life, and my father was one of the respected ministers in the community. These places were so small that everyone knew everyone else’s business and even my elementary school teachers were eager to discuss town gossip in front of the class.


One day Mrs. C walked into class after our recess and had a solemn expression on her face. We had all taken our places at our desks, and I was ready to engage her in our nap time game of chess as we usually dueled while the rest of the class slept.


Instead she came to my desk, and took me outside. She explained that another student in the class, I’ll just call him N, his parents were getting a divorce and she wanted me to talk with him about how things weren’t that bad. At this time I had no idea what a divorce even was, but she picked me because of my father’s position. So a few minutes later N came out, and we talked.


Late that night, when my father came home I talked with him about what happened, and he told me that I had been entrusted with a very important piece of someone’s life, and I shouldn’t relate that information to anyone, and so I never discussed what was said even to my teacher.


Later in High School, our house was egged, eggs thrown at the doors, windows and cars. The clean up was messy. I was furious, wanting to know who did this, and of course to find justice. My father sensing my anger took me aside and told me not to mention this incident, but always remember and one day someone would lapse and mention something that they shouldn’t know, and then I could find out who. But if I let them know that they had any effect, then they wouldn’t need to pry to see my reaction, and i would probably not discover who was behind the prank.


My father never speaks bad of anybody, but is opinionated about policies. He never rakes mud over someone discussing their infidelities or faults. He has never broken confidence about anything discussed with him. He is a role model for information security.


These incidents helped to teach me how to control and take care of confidential information. How to keep private incidents private and how bringing someone else down does not make you a better person, and to be wary of people who do.


Each of these life lessons can be applied to information security, determine which pieces of the company to keep private, even from other employees. Keeping failed attacks undisclosed can bring out who actually caused the attack, because they may not be able to determine if their attack succeeded. And pointing fingers without evidence only burns bridges.


Happy Father’s Day


wdnii

© 2013 Norris Proprietaries Incorporated

Information Aggregation

Information Visualization and Aggregation
June 10, 2013


The way I think of Information aggregation are processes which organize the incoming flow into various streams or channels, yes, channels like  television. These channels could be, for example, like sections of a newspaper, “Sports”, “Current”, “Politics”, and can be grouped further by how well you trust the source such as: qualified information, unqualified information and advertising Information, or by the information being pushed up or down by other site users, such as on reddit.


There are way too many applications to individually name, but I am particularly interested in mobile apps, and the best appear to be: Flipboard, Google Now, Google Currents and Taptu.


Taptu has a nice interface, but ignores social media sites and only has access to news.


Google Currents does not aggregate between information providers, so you cannot see just a general category of ‘Sports’. But you can view the articles in the LA Times, for example. The information display feels to be displayed more by a program than by human design.


Google Now places applications on the google search page to customize information selection and the display dynamic, such as providing current conditions effecting the daily commute.


Flipboard is one of the more interesting applications. They provide access to social networking posts from your friends, magazines, newspapers and current trending social networking and news feeds. Some of the magazine articles are the initial teaser and then you are prompted to subscribe if you want to read the entire article. Flipboard uses a pictorial interface, like an advanced Tumblr., and Flipboard does display Tumblr. blogs better than Tumblr. The interface feels designed, less robotic.


Finally Android OS and the various widgets can fit into this category allowing aggregation updates, but each widget has a slightly different look and feel, not providing a uniform experience.


Next I expect we will see News TV aggregation would pull out snippets of the news programs for you to view only on the topics you were interested. You could build your own 30 minute news TV show from the various programs. Probably a few copyright issues to clear first.


Another along the same thought would aggregate articles on a single topic eliminating redundancy creating one article with all of the information. Be kind of interesting to run editorials from opposing points of view.


And an aggregation stream that will include radio and social tv channels, along with social picture, blogs, and the pay for media sites.


Finally, the big changes will come when some company can provide a subscription service which includes most all of the various premium content for one monthly fee. This will encourage a pay stream for internet content which is currently underperforming compared to other content/information delivery systems.

wdnii

© 2013 Norris Proprietaries Incorporated