Thursday, September 19, 2019

Data Security and Facebook

An online report published by CNET on September 4, 2019 identified that at least 419 million records  of phone numbers tied with Facebook accounts appeared in databases online. The report was based on the revelation by TechCrunch. 

The exposure identified 133 million users from US alone and another 18 million and 50 million records from UK and Vietnam respectively.  The flaw as highlighted is Lack of Password protection on the server by Facebook. Records were identified with Demographic details also.

Now the big question, does this impact my privacy and security of my data online (read facebook data too)? Answer to this is pretty simple - if your demographic data and phone number is available example - sex, country and phone number (along with Facebook's Unique User ID) it is pretty much a compromise of your personal information leaving you vulnerable to certain cyber attacks. The data can also be misused to forge your identity with the modern mechanics of hacking.

This certainly is a big mess here by the team at Facebook to have left a critical server without password, the first baseline defense mechanism to check against unauthorized access. Though the very next day or so Facebook reverted with a statement that the data has been scrapped and is no more exposed to the open web. But from the time that server would have been put in place to the time the data was reported to be exposed and the steps by Facebook to scrap the data, do you think that the data would not have been compromised?  In all probabilities it would have been.

Though this is not the first time that such exposure or compromise has been reported. We keep on hearing such cases almost every other day.  The corporates accumulate our data for their business benefits and then miss out on the aspects of security to be deployed.  As per Facebook, this server probably served the purpose of searching a person on Facebook using the Phone Number of that person. My question here is why should the Phone Number search for Facebook user be activated in the first place? That itself is a breach of privacy and compromise of data that has been provided to a service provider as a security feature for secondary authentication.  

Facebook may state that they have this feature of find by phone to be controlled by the user and if user doesn't want to have this feature on, they can restrict it. Based on this aspect, I had a few discussions with a few facebook users and majority of them (close to 65%) didn't have an idea that they can control this feature of Search by Phone.  

So, the question still looms - "Should Corporates be allowed to Introduce Features that may pose Security and Privacy threats to the users?"

Saturday, September 9, 2017

Equifax Data Breach

Almost 2 years from the time we all witnessed the Experian Data Breach, we are at the stage where we all are informed about the Equifax Data Breach. Now, with almost half of the US Consumers are probably hit by this breach, Equifax made a statement that not all information was compromised. Well, if Name, SSN, Driving License details (though not in all cases) are compromised and the hackers have those details, what is Equifax trying to convey? More so, with where Equifax stands, does it have any way to explain the attack that was carried out over 2 months (May - June 2017) and Equifax could only uncover it somewhere in July? Doesn't this highlight the level of security measures or the loopholes that exist in the overall system configurations and more so in monitoring the traffic as well as transactions? Didn't Equifax CISO review the Experian Hack and the ways he could have directed the team to act swiftly to ensure that they don't fall in the similar trap? Sad, but true, they indeed fell in that sinkhole that was waiting for them and no one else can be blamed but for their Not So Productive approach.
So, where do we go from here? Should we accept the registration with Equifax's "Trusted ID Premier" service for Next Year "Free"? Would that be enough for them to prove their commitment to protect consumer from any sort of fraud? or wait, isn't this in itself a cony capitalism step by Equifax to exploit the situation from there to charge us $19.95 a months there after until we cancel the service? It is important to note that the hackers wouldn't use that information on immediate basis for they would also know that just like "Experian's Protect My ID" service for free, Equifax may also float that service free (which they indeed did). In most probability, the hackers may sell the database at a premium to the fraudsters and the, the fraudsters at a convenient time exploit the vulnerable. Probably the Theft Protection cover being offered free for one year would be blown away by then. More so, I would not recommend you to sign for Equifax's free service as if you do that you would surrender your right to join a Class Action Suite should that happen. 
Consider the specific situation where the frauds that would happen few months down the line during the tax filing period when the information hacked could actually be used for impersonation and tax filing "AS". That is the type of fraud that an ID Protection service would not be able to prevent and the consumer would be just left in a situation running from pillar to post to get the situation corrected. 

The impact of this breach on consumers can only be estimated at this time. There is no confirmed way to identify the long term impact on any of the consumer with compromised identity; until the compromise makes a landfall on that consumer's account.

This however is not the first breach at Equifax or a group company, thanks to the horses blinds that they have put up assuming that the Data Security is prime for them. If we are horrified with the news that this data breach lasted two months and they uncovered this only after 2 months and waited another 4 to 6 weeks to make the disclosure, please search about the TALX breach that was reported to have started back in April 2016 and continued for almost a year. Quite a number of W2 data was compromised then too. Equifax didn't learn a lesson from that either.

Now, that's a sad story from the Organization that is tasked to store our data, but is not sincere enough to really secure that data. Certainly, the business of the Organization is to compile and store the data to be used for marketing and cross selling purpose. The accessibility of data needs to be maintained by them to be able to make more money than ever. But, shouldn't the federal and state legislators ensure that the organizations or kind are regulated and made responsible for such breach? Shouldn't there be a commitment by the US legislatures to have a regulations in the lines of GDPR and ensure that the requirement to disclose have a stringent deadline (72 hrs in case of GDPR). What most of the US states have is "reasonable time period" or at the max 30 to 90 days. Gracious God that's a lot of time for the hackers to misuse the data leaving hardly any space for the consumer to step up and protect their interest.

From a consumer point of view what can be done? Most of the consumers would think the same and am sure most of them would sign in to the Trusted ID Premier for one year thinking that is the best step forward. But, as mentioned above that would just prove to be another marketing stunt for Equifax rather than a permanent fix. After 1 year (or the time period they offer for...may be 2 years), even if half of who sign in for the service sign out, Equifax would make millions per month charging them the fee. 

Am sure once the news spreads further, most of the consumers would start wondering or what should be done now? I would suggest to visit https://www.consumer.ftc.gov/blog/2017/09/equifax-data-breach-what-do#comment-256824 and consider the following steps that are detailed there - 
  1. Place a Credit Freeze with your Bankers. This will make it hard for the hackers to act as you, but they can still misuse your credit cards
  2. Limit and Monitor your Credit Card statement
  3. Monitor your Credit Scores and reports on a regular basis. There are a few that may provide free service and updates; Evaluate them and make a decision. Alternatively, obtain your 3 bureau credit report from annualcreditreport.com (limited once a year though)
  4. Consider placing a Fraud Alert on your files if you chose not to go for Credit Freeze. This would indicate to the institutions to verify that it indeed is you who is requesting for account opening or for credit services
  5. Ensure that you file your taxes promptly as soon as you get your W2 in hand. You shouldn't delay filing your returns as that may be a costly delay should a fraudster file them as you. And ensure that this step is repeated every year as you never know when your information may be misused.
-----------------------
P.S. - Would Transunion pick a cue from the Experian and Equifax Hacks to ensure that they are up-to the mark with the measures to Secure our Data? 

Friday, January 27, 2017

Cyber Security Program - Need for All Inclusive Approach



Cyber Security Program the way I have often observed in various organization over the years, is lead with piecemeal approach. There is no holistic view or review of the same and the Cyber Security team, often to be counted on fingers, is left to fend the entire organization's Information and Information Technology establishments. The other teams from IT as well as Business just shun off their responsibilities to be participative in the overall Cyber Security Program.

The main culprit for the piecemeal approach as I have see is the Business alignment to the overall Information Security aspects. The biggest misconception that Managers at various levels in a Business carry is - "Business to Run as Usual, doesn't need to be secure and if anything needs to be secured, then the Information Security Team has been hired for the purpose." In one of my interactions with one of the Client IT Manager, when I highlighted that there is acute need for them to focus on the Information Security aspects, I was told to submit my detailed Information Security Assessment Report and they will see what they would have to do. The IT Manager also had additional responsibility of handling Information Security Domains and was a influence in the Office of CIO. 

There are many such instances that I have waded through in the industry where organizations take piecemeal approach rather than holistic view for implementing Information Security measures. For instance, in one of the case a Senior Information Security Architect was forcing us to include two layers of Security even to reach DMZ. I was not able to understand that logic of having two layers of firewall from same make and model and same set of rule-base. May be I was ignorant as I always believe Firewalls are the Dumbest Security Device because they can't differentiate between legitimate and illegitimate traffic on the ports they are supposed to let the traffic flow. It certainly is good to have layered Perimeter Security, but only when we look at the holistic view of the overall Perimeter layer security and not just a small dumb appliance called Firewall. It is important that we also consider the other layers of IPS/IDS, Anti-malware, Anti-virus, Deep Inspectors, Threat Monitors etc at that layer rather than just relying on the Firewall. Even if we are looking at two layers of Firewall, please consider two different make and models and technologies rather than what I explained in my example above.

Another aspect of Information Security that take piecemeal approach is to address & report compliance requirements as may be applicable from Industry to Industry. For instance it is indeed a very good practice to have Risk Based Internal Audit (RBIA) practice, but then the practice must cover an inclusive scope of audit rather than exclusive. What I mean here is rather than focusing on a particular standard and then covering the Risk Assessment to the requirements of the particular standard to define Audit Program for next year would limit overall Audit Scope. It would be a better aspect to cover the Risk Assessment with an holistic approach and based on the Control Domains applicable to the Business as well as IT functions. This Risk Assessment would provide with a wider aspects that must be audited on a regular basis as this would provide with whole lot of more situations to audit and assess from the Risk Management perspective. These audit activities then can feed into the residual Risk assessment and helping with a better RBIA result than the micro-results achieved with previous approach of what I call Need Based Audit and not a true RBIA.

Even though today the Compliance Assertion and Risk Management has been branched out from the earlier Information Security initiative to now Governance, Risk and Compliance function; the base still remains the same. Information Security initiatives drive the overall Risk and Compliance posture of an organization. It is in fact imperative that Information Security should be driven with a Bottom up approach with Information sitting at the bottom of the pyramid and the overall Governance at the top. Certainly this would help drive the Holistic view and review with the Information at the bottom getting shielded with the Controls deployed at the technology and process levels; and the Controls providing inputs to the compliance assertion requirements flowing into Risk Management and Governance piece. The overall system needs to be deployed in a fashion that would say "All Inclusive" rather than "Exclusive PCI" or "Exclusive HIPAA" or "Exclusive FIPS". Though the industry has been talking about Unified Compliance Framework from ages now, but that term has still not been adopted by most of the organizations and I do not see a major breakthrough there, unless organizations first see at Macro level for All Inclusive Approach rather than the current Piecemeal Approach by technology or by security or by compliance need.



Friday, October 23, 2015

The Startup World

Fifteen (15) years after the .com bubble burst, the market is once again booming with the startups with some niche some traditional business ideas.  Its' not that the Startup market had dried up in between, but the intensity with which the Startups were being worked on has picked up good time once again. There were many mistakes that were made back in the days by the .com startups that compelled the entrepreneurs to shut down the shutters and be back to the regular / routine jobs.  However, with the ever increasing internet penetration and with more and more industry segments resorting to e-commerce ideas, startups in IT sector are walking all smiling to the banks.
However, there are some key aspects that would be extremely helpful for the entrepreneurs to be successful and not get bogged down by the various pressure points.  From what I learnt from the .com bubble burst and then researching the success stories of various startups can be called as “Wisdom to Drive a Startup to Success” .
 The points that need to be considered to Drive a Startup to Success can be listed as below -  
  1. Market Research – Don’t rely on your idea, back it up with tangible research
  2. Welcome Inputs / Feedback – Be open to remodel your business, being closed to criticism would not yield fruitful
  3. Focus – Use Horse-blinds to keep your focus on your core, after you achieve success once, there are many opportunities to expand and diversify
  4. Consumer Preference – Always remember the old marketing joke of what consumer actually wanted and what was envisaged by marketing team for product team to supply a dud. Ensure you understand the market need better and have a feel of Consumer needs
  5. Market Review – Don’t take positive feedback as revenue inflow. Praising the product is way different than actually buying it. 
  6. Planning – Define a roadmap and stick to plans, don’t overwhelm yourself with over-planning to out-plan from the market
  7. Hiring – Look for talent with experience. It is also important that a #startup ensures to hire mix & match of experience & fresh talent. Experience = Stability & Fresher = Enthusiasm
  8. Venture / Angel Capital – Ensure that the decision is based on a clear RACI of what you want and what Investor’s expectation is
  9. Scaling the Operations – Ensure to stay on top to regulate expansion at a gradual pace
  10. Be Flexible – Try to achieve perfection but not at the cost of impacting delivery
  11. Listen & Evaluate – Not every advice coming your way may be a good advice for your business, listen, evaluate, filter and implement the advice with thorough decision making process
  12. Partner v/s Solo – Define the motive and team up with like-minded individuals else you may choose to go solo
  13. Timing – Ensure that you are well prepared to hit the market with the product at the right time
  14. Money Management – Raise capital based on the projected revenue model to manage finances well. Always keep a buffer to ensure that the initial deficit from revenues could be addressed
  15. Know your money's worth. Spend judiciously not rigorously when you wish to own a #startup. Hold your horses before shelling out money
  16. Follow the #hypercare path for your #startup with passion and not obsession.  Obsession may lead to over enthusiasm leading to downfall
  17. Critical #startup point: Wear your Head above your Shoulders and let heart handle the blood flow. Use your brain to think and evaluate
  18. #startup shouldn't be used as a weapon to display ideation skills. It needs more than Ideation and acute Business Acumen needs to prevail
  19. #startups who target to get funded by the time they market their product are bound to fail faster than their peers who plan for contingency
  20. #startups with targets set for next two years have more chances to thrive and survive than those with less than 1 yr of expense forecast
I hope those who are planning for a startup or are already working on a startup would be benefitted by this compilation. 
I would welcome ideas that are different and that are derived from Experience of running a startup.  Please don't hesitate to write back a comment of sending me a message if you have inputs for me on this topic

Tuesday, October 13, 2015

Experian Hack

It has been almost a month that Experian reported a breach in which 15 million T-mobile customer accounts were said to be compromised. The information included names, addresses, email ids, social security numbers and few more details of the T-mobile customers in USA. Though Experian was quick to react before the information could have been misused to that effect, yet it was a scary news for those 15 million individuals and others who are T-mbile customers or those who have accounts with any of the service providers who use Experian as the Credit verification agency.  

For those who think they are not impacted, they need to rethink about not getting worried because Experian is one Credit Reporting Agency and if its systems can be compromised, then the other Credit Agencies  too can be. What does that mean to common man? Well, take control of your information that is stored, processed and transmitted by the Credit Reporting Agencies (TransUnion & Equifax included). 

As a reaction to the hack, Experian announced two year free Identity Theft protection service "ProtectMYID" for affected T-mobile customers.  Now, the big question that arises here is - "Why is it a reactive announcement and why is it that they otherwise are charging to monitor misuse of our information that they store/process/transmit?" Isn't it just logical to ensure that they or the service providers from whom we obtain the service should actually be providing this service as a complimentary service? Also, why should Experian provide us this service free only for 2 years? Is there a logical conclusion by them that the hackers will not misuse the data after two years?  Well, I guess they are just trying to shrug off their responsibility to protect our information available on their systems.  First of all they had their systems configured in a manner that got compromised and then they are offering something to show off to the world that they care.  Not something that I would buy with any sort of logic, though I would be the first person to avail immediate patch work offer from them to ensure data regarding myself and my family is not misused impacting my Credit Ratings.

So what does that mean for the Federal Regulators like FDIC should first look at amending the Fair Credit Reporting Act (FCRA) or State Regulations like Consumer Credit Reporting Agencies Act (as referred in California) need to be amended to ensure that the Credit Reporting Agencies are legally bound to secure Consumer Information.  At the same time, the Credit Rating Agencies must consider reviewing their current Security Architectures for access provisions and data flows to identify the possible loopholes that may leave enough space for data compromise like Experian. A composite review is the mandate of time and certainly the Audit reports by independent Auditors must be submitted to the regulators.  This needs to be a time bound activity to ensure that the Credit Reporting Agencies take required remedial measures to ensure that they step up the security provisions and ensure that such future breaches are thwarted right at the attempt level itself rather than letting it to be a news post breach.  It certainly is an important step to be proactive in securing the data and information rather than taking reactive measures that sometimes may result in an organization getting booted from business.

The Experian Breach should not be looked at just limited to T-mobile or Experian for that matter, the industry should take it as an alarm for the future attacks that hackers may be planning to gain more information and if they could get through the doors of Experian, they may get through the doors of other such agencies.  It is important that proactive measures and steps are taken to secure Consumer Data / Information for which these organizations are custodians, not the owners.  
____________________________________
Disclaimer: The views expressed above are solely of the Author and are not endorsed by any organization, individual or industry body for that matter.

Friday, October 9, 2015

Compliance Management - Considerations

Many a times we encounter situations where we find that certain Information Security Policy requirements and considerations are not in line with the Global Security Best Practices and they actually are not in-line with the Global Standards to that effect. But, the major mistake that we make at such a point is to take into considerations the Business Requirements for that organization or for those who actually are the recipient of the overall results on those Business Requirements.

The issues are overwhelming for the Risk and Compliance Manager across the world as they try to bridge the gap between the Auditor's Expectation with the Real World Scenarios with all the practicalities.  This doesn't mean that Auditor's Expectations are not practical or not something that need not be entertained per say.  What is more important for the Risk and Compliance Managers as well as the Business Managers is to ensure that these expectations are well understood so that it would be easier to meet them by remediating the open issues.

More often than not Auditors as well as Risk & Compliance Managers are often misunderstood and seen as a "Red Flag Bearers" by the Business & Technology Managers. Though this perception can't be justified, but then they have their own reasons as they have to run the show.  There are many a times when Business as well as Technology Managers have to take quick decisions and at times they circumvent / bypass some critical security / compliance considerations to ensure that the "Show has to Go on."

However, though they say everything needs to be done to ensure that the Business as Usual must prevail, there are some checks and balances that must be applied and Compliance Considerations must be brought to the every day work life.  Though I had maintained for long that "what is compliant" is not always secure (for if it were secure we would not have as many breaches as we hear), I still maintain that Compliance provides for the baseline controls we must have in place.  How we convert them from Compliance Controls to Security Controls depends on how Security Focused we are.

The Compliance Considerations that I prefer Organizations should keep up to are -

  1. Following defined processes and procedures
  2. Documenting what is being done - meetings, notifications, trainings, approvals etc.
  3. Documenting the changes being introduced
  4. Resolving issues with Long Term strategies than short term remediations
  5. Following Risk Based Approach
  6. Adopting Return on Investment from Technology (ROIT) adoption rather than resorting to Cost  & Benefit Analysis (CBA) - This would always prove to be profitable approach in longer term
  7. Unified Compliance Approach rather than Project base Compliance Approach working in Silos - This would always help reduce duplication / redundancy in controls being managed and technology being deployed. There always is an overlap of requirements across various Industry standards and regulations impacting compliance posture of any organization
  8. Drive Enterprise-wide Compliance efforts rather than Business Segment Silos
There are few others that may be considered, but the basics of Compliance Management would seek solace in the ones mentioned above.

Thursday, October 8, 2015

EU-US Safe Harbor Treaty

Finally the fact has been said. 

Safe Harbor is an instrument for US companies to use at comfort and will to state compliance to EU DPD. I said instrument because it was tilted for the benefit of US companies with "Self signing to assert compliance" with absolutely no country level Privacy Law. Interesting point to note there, US does not have an Umbrella Privacy Act that would be equivalent to EU DPD (EC/95/46). Though state privacy laws prevail, but they are more of "Privacy & Disclosure acts" different for 48 (out of 50) states. With Massachusets Privacy Act being the most stringent.

Summation of situation, US would have to act swiftly and pass that pending Congress Bill that would provide for the US Data Privavy Act rather than banking on State Privacy Acts. 
Full on Impact - US companies would need to either follow Standard / Model Contractual Clauses route OR gear up to follow Binding Corporate Rules like the organizations from Third World Countries. 

Now it would be interesting to note HOW Federal Trade Commission would deal with this situation as the CJEU ruling actually puts it into a spot. Would they Negotiate for time OR would this lead to Penalties OR would we see different sort of Negotiations!!! The time for some big showdown!!!

For some other articles on this topic, please refer -
  1. Data Transfer Pact Between U.S. and Europe Is Ruled Invalid - NY Times
  2. How Will the Safe Harbor Ruling Affect Tech Giants? - Wall Street Journal
  3. What The EU's Safe Harbor Ruling Could Mean For Tech Startups - Forbes

Tuesday, September 22, 2015

Indian National Encryption Policy

It is interesting to note that the Government of India's Department of Engineering and Information Technology has issued National Encryption Policy for public comment.  And today the first addendum for the same has been issued for the people to refer to.  However, when it comes to the overall policy, it has been left out pretty lopsided. When I say Lopsided, I mean from the subjectiveness & perspective dependence that has been maintained throughout the Policy.

I would not get into those micro level details where the industry's who's who is making some or other comment on the types of services that would be covered and the type of data user as well as business would need to be retained for 90 days.  That's a very low level speculative inference that would differ from person to person and from perspective to perspective. My initial view was same and I also took to twitter for that :)

What my assessment of the Policy is the lacuna that is maintained by not aligning it to the industry standards and not basing it on the prevailing trends.  For that matter, one of the key aspect that I find missing is the way the Committee should have taken cognizance of the "Heart Bleed" as well as "Poodle" vulnerabilities that led to the demise of SSL as an Encryption Standard. It should have been noted that the PCI-Council has declared that SSL is no more a supported standard for encryption and that TLS 1.2 is the deficto standard until next such notification. Indian National Encryption Policy has this void in it to align itself with the latest, thought he vision and mission state so.  The policy goes anywhere else than stay around the vision and mission.

I am surprised to actually read the reference of SSL in the Policy at the time the world is moving to TLS 1.2 and the bigwigs of industry have already moved to the other side of adopting TLS 1.2.  Moreover, TLS 1.3 is already being eyed as it is slated for release by next year. We have already seen the advent of SHA3 earlier this year and the Policy still sticks around to 3DES and RC4. It needs to be noted that RC4 already has been vulnerable to attacks and can be actually be used to get some hand on the information encrypted using the encryption standard (Read - Article on Security Week - Dated March 2015). Moving on to the 3DES, it is not at all considered strong enough to protect the data and when the Target Breach happened, it was identified that 3DES was deployed and there was a lot of scrutiny on that move as to when AES was available why 3DES was used?

So, when the industry is basing their opinion on the micro issues of what to store how to store, where to store and talking about the data security & integrity from a different angle, my real concern is the coverage of obsolete standards and technologies as part of the overall Policy and basing the policy on those obsolete standards and technologies.  I am not sure why the Trade Pundit's or the bloggers in social media have not raised this issue till now.

Certainly, in its current format the Policy itself would be obsolete in not more than 6 months and that would call for next round.  But would DeitY listen to the Gen Next or are we still going to hear from the "Experienced" folks who missed to evaluate the latest and greatest developments??

Would you hear the voice of Young India or would this also go the TRAI way???

Friday, May 15, 2015

Seamless & Transparent Compliance & Security operations

Information Security and IT operations generally do not go hand in hand or I rather make a not so controversial statement that IT Operations Folks generally don't like Information Security Folks for they see the Information security folks to be the Show Stoppers.  The way I have witnessed it in my career, I have had the Label of "Bad Man of IT" then they used to call me "Risky Guy of IT" and all other sorts. I have had worked with various organization on consulting assignments and every time there used to be the same story - Chief Security Officer / Chief Information Security Officer would have to literally wrestle with the IT Operations for getting the Budget and then getting the technologies implemented. 

As quoted by one Vice President of IT at one of the client - "Don't bother much about them, they are just running various Projects that go no where and just wastes the money." When I interacted with the CISO on job and a direct report of CIO, he stated - "We have been able to procure some best of the techniques for Security, Risk and Compliance Management, But we have not been able to integrate them with the rest of the IT Systems, for they would not give us time to test the APIs and Connectors."

In another case where my team was conducting an IT Audit to help them identify the improvement areas to align with ISO 27001, I have had another weird experience.  The IT Manager who was the contact point for my team was my audience for the observations presentation.  And to my surprise or should I say dismay, he told me - "You do your work and submit the report, I will see where do I take this?" I was shocked as my team was engaged in a full length consulting assignment to finally ensure that the client organization gets to the level of being awarded ISO 27001 certification for IT practices.  What happened next over the course of time was altogether a different story.

Sounds strange, but its pretty much true as this is not a heard story and I myself have been the witness to have them say what they said and that has lead to me thinking on the ways Information Security and Compliance Management can actually be integrated into Daily IT Ops.  I have been an advocate of Information Security Culture rather than Enforcing the Information Security to avoid any such negative traction as to create stiff work environment.

To this effect, I have always thought about Security with Transparency or say Transparent Security.  The way it works for me that if there is a problem then certainly there is something NOT working right and there is a Problem.  This very problem is the issue creator for the IT Security Function to be able to work the way they are required to. These problems can then be used as the base cases by the IT Ops to push every issue towards IT Security.  So, I opine to establish the control regime in such a fashion that the overall IT Security Function becomes transparent to the level it can.  

For an IT Security Operation to be transparent, the first few steps would certainly involve automation of certain controls and functions. A very good way to proceed on automation journey would be to start from Log Aggregation and Correlation using the SIEM tool and then integrating the same with a GRC tool to create Dashboards and Reports. The next steps then would be to integrate an enterprise level IAM tool and Two factor Authentication (Preferably Soft tokens to be used) with the LDAP and other Applications to enable seamless connectivity with lesser passwords to manage (we all hate passwords, but remember that the hackers love them and if we would have lesser passwords to manage, we would feel better. and the two factor authentication would as is cover up for the weak passwords...), the IAM tool can also be extended for the purpose of Federated Identity Management as well as Single Sign On (SSO) and User Self Help to reset the Passwords.

Once the initial steps are successfully taken, the next step that I would suggest would be to integrate the GRC tool with the various tools and technologies deployed across the IT Landscape to obtain direct feed using APIs and Connectors. This though may be cumbersome and initially the IT Ops may oppose, but in a long run even they would start loving the results.  The live feeds configured can be used to identify any anomalies or say unauthorized changes or similar other compliance issues that may jeopardize the security of the system and leave it vulnerable for compromise.  

The whole benefit that can be derived out from the Integration of GRC tool with SIEM tool as well as the other IT tools and technologies is to be able to create the Dashboards and Reports for various Management Levels to provide them runtime snapshot of the Enterprise Security and Compliance Posture.  Also, this would mean that the IT Ops is not being bugged or harassed (as IT Ops actually feels) by the IT Security, Compliance an Audit functions for various data and evidence requests, because the required data and evidence feed would already be available on the GRC tool or the connected EDMS (Electronic Data Management System) library.

Also, it needs to be noted that the misconception of the Security, Compliance, Risk and Audit being the Pain areas for IT Ops would not end so soon unless they understand the importance of what we all do in our space.  We can start with the various steps as summarized above, but the mindset would take time to arrive at a cordial relations between IT Ops and the Security, Compliance, Risk and Audit guys....

Tuesday, April 21, 2015

Cyber Security & Kids

With the advent of Mobile Platforms, the biggest challenge that parents face is to restrict the kids from accessing vulnerable sites or say malware that may be hosted on the "Malicious Sites." Though more or less the Kids face same kind of threats as the adults where they can be susceptible to malware, viruses, trojans etc. But these malicious sites that could be created as the "Fan Pages" or "Free Stuff" giving aways can be more enticing for the kids where they may end up sharing information more than what a legitimate site may require or ask for.  

So, where should we start? how much parental control and parental guidance is needed and how should we speak to our kids about the security?

Though it may not be simple with the kids, but then it is required.  We would need to educate them and talk to them on the requirement for practicing Security in their routine usage of internet specifically on the Mobile platforms.  What needs to be understood by the parents and teachers is that the kids for themselves wouldn't like to get tricked, cheated or exploited. They need to be made to understand why some apps are being locked on the Mobile Device or some sites are blocked for them on the Computers they use for Study purpose.

Parents need to actually sit across with the kids and tell them about the harmful sites and the impact that these sites can have by the way of stealing information about them.  Teachers on the contrary need to help understand the Students on the adequate use of Internet and the way those can be used for meaningful purpose say study research etc.

Both the Mobile Devices and the Computers can be configured with Security Features and some additional Security Software. Though there could be some expenses involved in the additional security software including Antivirus et al, it is worth it to put in rather than facing that breach and compromise of your personal information.

On the other side, it is high-time that the Mobile Platforms integrate parental controls and additional security measures as part of the Mobile O/S and ensure that those features are well communicated to the parents.  Workshops can be organized with help of the Educational Institutes for the Parents as part of the Parent -Teacher meet to educate parents on the additional features.

There is more to what we can actually do to this effect but the steps above can actually serve as the basic steps to secure kids from the Big Bad World of Cyber Crooks.

Tuesday, March 17, 2015

PCI-DSS and Risk Management

PCI-DSS and requirement of Risk Assessment have a very close relationship. In effect PCI-DSS has specified the requirement for an annual risk assessment as per the control 12.2 and has mentioned the requirement under guidance for requirement 10.6.2 and Testing Procedures for requirement 11.5.

PCI-DSS requirement 12.2 establishes the requirement for implementing a risk assessment process that:
  • Is performed at least annually and upon significant changes to the environment (for example, acquisition, merger, relocation, etc.),
  • Identifies critical assets, threats and vulnerabilities, and 
  • Results in formal risk assessment

Guidance to PCI-DSS requirement 10.6.2 - Logs for all other system components should also be periodically reviewed to identify indications of potential issues or attempts to gain access to sensitive systems via less-sensitive systems. The frequency of the reviews should be determined by an entity’s annual risk assessment.

Testing Procedures for 11.5 - Additional critical files determined by entity (for example, through risk assessment or other means).

When we analyze the requirement 12.2, it has though established the need to conduct annual risk assessment per set standards including NIST 800-53 and others, but it has not covered the overall efficiency led requirement for a risk assessment. The requirement as cited above states setting up a process that results in a formal risk assessment by the way of identifying the critical assets, threats and vulnerabilities, but shies out to specify the continuous monitoring of Threats as well as Risk Spectrum.  

In the current scenario, if an organization has to pass a PCI audit, it would be easy to lay down the risk assessment process, conduct the risk assessment and then publish the risk assessment report. But in the real world, is that all that an organization would need to fend off the hackers? Certainly not!!
So what is needed for the organizations to step up to and for the PCI-DSS as a standard to emphasize? The answer is to extend the requirement 12.2 from a being a risk assessment requirement to a risk management program requirement. This would put emphasis on the requirement to cover the full circle from the time Threat and Risks are identified to the point that those are remediated / accepted.
PCI standards council should also look at introducing Risk based approach to select the Compensating Controls by the organizations. The completed ROC should be modified to include the outcome of Risk Management snapshot covering the reasons to not implement given control and selection of the Compensating control instead. 

In the prioritized approach also, PCI Standards Council should assert highest priority to Risk Management.  

On part of the organization impacted with the change in the requirements around Risk Assessment and Management, the focus should be on the composite Risk Management activities that they conduct at the organizational / enterprise level. The organizations need to understand that the silo approach to compliance never benefits their functioning, rather just increases the cost of managing compliances. If they would integrate the Risk Assessment as required by various standard and compliances, they would be able to harbor a better compliance assertion against each one of them with minimal set of controls and maximum cover.

Sunday, November 2, 2014

Data Privacy Acts - Where the World needs to Converge

Data Privacy in today's world has crossed over from a requirement dependent on one agency or organization to be the global phenomenon.  Today the data traverses across the countries as well as continents at the speed unimaginable in past. In a flash of second, the data originating from EU may be transferred to China and may be who knows to another country from where a Hacker might be sitting and listening to the data traffic.

Let's take an example of some other countries say India and Brazil, both being third countries and both engaged in Off-shoring of services.  In this context we will talk about the  scenario where an Indian IT company providing services to a multinational client located in US, Australia and EU would have its service locations in India, US, Brazil and Germany.

In the scenario highlighted above, all the geographies / countries involved do have one or other kind of Data Privacy Law, let's examine them -

  1. European Union - EU Data Privacy Directive - EC/95/46
  2. United States - State Data Privacy Laws (enacted in 48 States), Country level Data Privacy Law pending with Senate
  3. Australia - Privacy Act 1988 (National Security Legislation Amendment Act (No. 1) 2014)
  4. Brazil - No definitive law covering Data Privacy, though Privacy requirements have been dealt with under various different legislation
  5. India - Telegraph Act 1885 amended in 2004, Indian IT Act 2000 (Amendment Act 2008) and few others cover a part of Privacy, but no comprehensive law exists
  6. Germany -  Bundesdatenschutzgesetz (BDSG), The German Federal Data Protection Act in line with EU Data Privacy Directive (Germany for that matter is part of EU and hence the European Data Privacy Directive is the base)
Now if we look at the above list, we will find that there is no commonality among the Privacy Laws across the countries / geographies except for the German Privacy Laws and the EU Data Privacy Directive.  

Coming back to our scenario, there would be no issues of data transfer between any EU nation and Germany, But with the data traversing across multiple borders, the Data Security Officer would have a nightmare to meet the compliance requirements that would include - 
  1. Safe Harbor - to ensure compliance between US State Data Privacy Laws as well as EU Data Privacy Directive
  2. Standard Contractual Clauses (SCCs)- to ensure compliance requirements are addressed when transferring data from EU Nations to India, Brazil and Australia.  It must be noted that SCCs would need to be executed for each EU nation and that would mean multiple SCCs to be executed.
Such scenarios are very much prevalent today and these just add to the complexities.  The organizations though have the options to file for Binding Corporate Rules or BCRs providing them the overall cover to transfer data, but it serves to be an expensive step from Business Perspective and its easier to sign multiple SCCs. All this ends up in complexities to be handled by the Data Security Officers or the Privacy Officers. So, what is the way to handle such complex situation and to avoid complexities to be handled by the Data Security Officers or the Privacy Officers?

If we take a closer look at the current prevailing situation, we will find that it is the disparity in the Privacy and Data Security Laws across the countries / geographies.  Though the Safe Harbor sort of options are available, but then that is also a self certification / attestation case.  

I personally would prefer a better option like the one between EU nations and Switzerland, Guernsey, Isle of Man, Israel etc. In such cases, we see that the EU Commission has identified the adequacy of Data Privacy Laws and adequate Protection of Personal Information / Data. In this scenario, the sole reason of the mutual trust is for the similarity of the Privacy and Data Protection Directives.

Now, if a small group of nations can have the required similarity in the Data Privacy and Protection requirements, why can't the rest of the world follow the suite. With the world converging for the global trade there is a higher degree of requirement for the bilateral trust for the Privacy and Protection of Data and for that common agenda needs to be driven. Organizations like WTO, OECD and other similar organizations may lead this effort to bring the governments together and develop Common Criteria for Data Privacy and Protection.  With the need of the time, the World needs to converge at these Common Criteria and the respective Governments must issue directives to regulate Protection of Personal Data / Information as per these Common Criteria.

Tuesday, April 22, 2014

Need to Security Private Information - Requirement in India

Unique Identification Authority of India (UIDAI) data center in Bangalore is reported to have got a cover of 65 star guards from multi-skilled security agency, the Central Industrial Security Force (CISF) - Your identity is guarded by 65 armed men (article on times of India).

It indeed is a commendable step by the authorities, but my question here is - Is this measure enough to secure the Identity and avert the threat from identity theft? Actually Speaking NO and the reasons that attribute to the answer NO are -
  1. The personal information of an average Indian is scattered across the Government Offices, Public and Private Banks and other Financial Institutions to a large extent.  More scary portion is the availability of this information on papers across the offices
  2. There is no defined mechanism to destroy the paper work by the various organizations and agencies.  Many a times some or other people from various organizations sell of these as waste papers to the scrap dealers.  There have been various incidents in past where papers with critical and sensitive information have been located with the road side vendors (bhel puri and other chat senders)
  3. There is no defined guideline by the Government of India on how to use / dispose / destroy the information whether in paper or on computers
  4. There are no set standards in India with respect to destruction or recycling of magnetic / optical media that may contain sensitive / private / identity information.  Such media may be Hard-Drives, Pen-Drives, Backup Tapes, CDs, DVDs, SD Cards etc among others
  5. Nasscom has also not worked to this effect to advice with any standard guidelines to be utilized to this effect
Saying all this, we should not actually be cheering the news as published as it is the least of the measures that is required at deployment.  Another aspect to look at is - Has Government also provisioned a DR site for the UIDAI Data Center? Is that location also guarded with similar set of Security Personnel?  Unless we get that information, I guess this news is just a hogwash,

If you feel I am trying to belittle Government's efforts, then well I am not.  But my effort is to sensitize that there are additional steps required by the Government to ensure that the information related to the Identity of Indians as well as tourists / visitors to India is treated as sensitive and private.  Adequate measures as detailed below need to be put in place to ensure that such information is treated in fair and just manner - 
  1. Enact a Data Privacy Law - Government needs to take immediate measures to ensure that the Data Privacy Law is enacted and enforced to set the expectations on dealing with Private and Sensitive Data.  The Information that needs to be treated as private and sensitive should include - Aadhar Number (as part of the UIDAI effort), PAN Card numbers (from Income Tax Authorities), Voter ID (from election commission), Ration Card, Passports and any other similar set of documents and information that can help establish the identity of any individual
  2. Define Data Handling Guidelines - As part of the Data Privacy Law, Government must define the treatment of information classified as Private and Personal in a manner cognizant to safeguard the Identity of person holding it
  3. Define Data Destruction Guidelines - As part of the Data Privacy Law, Government must also define how the data no more needed is to be destroyed.  For the data on paper and optical media for that matter must be destroyed by using shredders. The data on magnetic media for that matter must be destroyed by using programs that would over-write the data multiple times using different algorithms and thus rendering data as unreadable
  4. Define Consent Requirement - Often this is one of the most overlooked case where the private and personal information of any individual is circulated / shared for commercial benefits.  There are cases where the Customer Relationship Officers or the Marketing Staff carries over the contact and similar other information to the next organization without consent of the Data Owners.  It needs to be noted that the receiving Organizations / Agencies are Data Custodians and not Data Owners, meaning they can use data for their internal processing purpose only.  For sharing or using data for any other reason than intended reason should not be permitted without consent from the Data Owners (Data Owner is the person about whom the information is)
  5. Define Agreement Forms - Government must ensure that the Agreement forms used for the purpose of providing services are defined only for those services for which the Information is obtained.  Such Agreements must not any Clause or Fine Prints like "Organization / Agency may use this information for any of the required processing as may be deemed required by the organization / agency.
These are the basic steps to be taken to ensure Data Privacy & Protection.  These needs to be enforced along with the Indian IT Security Act 2008 Amendment Act to ensure that adequate Information Security Risks are addressed including the identity theft and information compromise.....



Saturday, July 13, 2013

Simplifying ISO 27001 Clause A.10.10

Clause A.10.10 revolves around monitoring with the objective of detecting unauthorized information processing activities.  Though there can be many ways to do the same,   automation is the most preferred way to do so owing to the size and amount of logged data.  It becomes humanly insane task to review logs manually.

But when I look at the various sub clauses of the Standard, I tend to infer the following points - 
  1. It is not mandatory to have an SIEM or any automated solution for real time log collection and Analysis.  Clause A.10.10.1 states - "Audit Logs recording User Activities, exceptions, and information security events shall be produced and kept for an agreed period to assist in future investigations and access control monitoring."  That means logging is important whether or not you do it real time is not compulsory.  A review is indeed required.
  2. Added to the above is Clause A.10.10.2 stating - "Procedures for monitoring use of information processing facilities shall be established and the results of the monitoring activities reviewed regularly". Going by this the standard is not asserting on Automated or manual process, the organization may choose to do it manually or automate it depending on the business requirements.  If in your procedures you mention out that the activity would be done on a manual basis, it would be fine as long as you can evidence that the logs are being reviewed and monitoring is being conducted with regular reports rolling.
  3. Nothing in ISO 27001 is mandatory.  Not even the clause A.10.10, You may choose or not choose a control to adopt it and develop the "Statement of Applicability" limiting the Scope and extent of adopting ISO 27001 standard.  The scope may be limited to geographic locations, systems, facilities, departments, personnel involved, operations etc.  However, due caution needs to be taken while developing the Statement of Applicability to provide a valid business driven reason to exclude any of the controls and related scope.  Be cautious that Auditors may call out the inter-dependencies of the systems and or operations citing the touch points and may therefore press that their is a non-conformity.
Overall, specifically with regards to the clause A.10.10, I see no problem with the manual approach as long as it is duly documented and followed. Auditors generally would tend to call out a "Need For Improvement" in their observations and there would be time given till re-certification Audit.  It hence would be appropriate to define a plan and lay-out a way forward to achieve automation over a period of time.  Auditors would be fine if they see that their is an intent to achieve and they would then Audit accordingly.

As I conclude, please note that ISO 27001 doesn't tell you How to do it. The standards lays out What is to be done and that too from the Best Practice standpoint.

Friday, July 5, 2013

Use of Technology for Payment Transactions

The days when we used to make payments with hard cash are long gone.  With the advent of new age technology, Bank cards (Debit/Credit) and the Internet Banking, we all do go for convenience payment sitting in the comfort of our home and / or office.  The payments made in this way are something that can be tracked without dealing with the trouble of paper receipts.  

That's said, it is critically important to review the options before making payments with the use of technology as along with the convenience of making payment, technological advancements have provided the newer ways for attacks and scams.  Initially there were Phishing Attacks where the attacker would host a Dummy Site for the target bank and get the required information and enjoy the proceedings.  As the users started getting smarter and the Banks started implementing tighter security norms and getting the fake sites down, there came the Vishing Attack or where the attacker posing as the genuine Phone Banker or Customer Service Associate tries to extract relevant information including Sensitive Personal Information and PIN/CVV/CVC of the Card being discussed about. In many instances the Customers Do fall pray to such calls and they end up loosing their hard earned money.  Typical Case to be read here - Paying bill online costs man Rs 50,000

Now the main points to be noted while making online payments or while getting on for online transactions  are - 
  1. For making online payments, ensure that you register the organization, to whom you want to make payment, at your Bank's Internet Banking site
  2. If you find it cumbersome to register the Biller at your Bank's site, please ensure that you make the payment from the Official Site of the Biller and also by creating your own Account on that site
  3. Ensure that you DO NOT use any third party website for any online Bill Pay, as they may claim  to facilitate the transaction, but this is NOT always safe
Another aspect that needs to be taken care of is the payment through IVR System of the Biller or the Bank.  It is pretty important to note the following points - 
  1. Never reveal Sensitive Information like CVC/CVV/PIN during an Automated Call or while talking to the Phone Banker or Customer Service Representative
  2. It is critical to note that you never get a Call from either the Bank or the Biller stating to share your sensitive information to enable the payment through Phone Banking or IVR.  A Payment through IVR or Phone can only be initiated when you would call the Bank or the Biller to make such Payments
  3. Please ensure that if anyone claiming to be from the Bank or from the Biller seeks to gain your PIN/CVV/CVC and other information that is generally not sought by Banks / Biller, disengage yourself from the call and raise a written complain with your Bank / Biller through netbanking/biller website. This will trigger a automated response to your mail box.  Do not reply to that address and just wait for an official mail from your bank (delivered in netbanking inbox) and or Biller (delivered at your Registered email address).  
  4. You have a choice to refer the case to the Consumer Forum / RBI / Appellate Tribunal depending on your choice and party involved. When you refer the case to concerned authority you wold need to provide details around the transaction that is being referred, the person's name (if you remember), time you made the call, duration of the call and summary of the call proceedings.  Remember that IVR calls are always recorded and in such a case your claims can be verified at the Bank / Biller's side.
So, to be safe is in your hands and to ensure that you don't fall pray to such cases is totally in your hands.  You need to be really careful for not disclosing the sensitive information to anyone or on any weblink that you may get claiming to be of a bank.

Please ensure to verify the Website address as it would always have some altered information if it would be from the imposter. And the most important thing - if you suspect that your information has been compromised - raise a Red Flag Complain immediately with the Bank.  Bank's Do provide you with all the required help to protect against any fraudulent activity in your account.  In case you know that someone gained your personal information and has misused it, please lodge a written complain with the bank before you head to the Law Enforcing Agency.  A Copy of the Complain raised with Bank always helps you in your case and the Banks then have to ensure that they do cooperate in your case to get you the rightful justice.

However, in the current technological era, the old saying "Better to be Safe than Sorry" as well as "Precaution is Cure" still stand true.  So take due precautions to not let someone defraud you...its your information and you have the right to refusal for imparting the same...

Sunday, May 12, 2013

$45 Million Heist with Prepaid Card Duplication: Lessons Learned

In my previous post "$45 Million Heist with Prepaid Card Duplication", I had highlighted the questions that creep up in our mind as general readers or followers of the news.  Those questions are basically something that need to be dealt with or answered for a meaningful conclusion of the investigation.

However, from the Risk Management perspective and the ongoing compliance enforcement, there are few critical lessons learned if the GRC world is watching this incident from that perspective.  

It was really amazing to learn the way these scammers came along together and indulged in such a widespread scam to cover 27 countries as reported.  Here is the first lesson learned - 
  • Organize your move and collateral to ensure that Risks are covered at all times. This can be achieved only when you have a sound Risk Management Framework to document All the possible Risks and monitor them on an ongoing basis
Banking organizations across the 27 countries failed to identify the large chunk of withdrawals from their ATMs. Here is the second lesson learned - 
  • Banks need to put a governing policy to monitor the cash withdrawals from their ATMs. They need to closely review the Cash withdrawal pattern from various ATMs they own. This would help raise the red flag faster
Payment Processors failed to maintain their security measures in-line with those required for Banking Organizations. Here is the third lesson learned - 
  • Payment Processors must ensure that they deploy layered security to ensure that the Databases are always hosted in the most secure zone and preferably be protected by host based IPS systems that would raise alarms on detecting any anomalous behavior
Card Networks failed to raise the alarm too and rather delisted a given payment processor that was breached.  This is certainly an act of washing out once own hands of the responsibility. Fourth lesson learned here - 
  • Card Networks need to ensure that they control the limits once defined. Meaning, once a Payment Processor or Bank has defined transaction limit on a given Pre-Paid Card, it needs to be populated to the Card Network. This should be a One Time one way update.  Generally a Pre-Paid Card user is not worried with the limits set on the card as they use cards for limited set of transactions only.  So if there is a change in the Transaction limit from the Payment Processor or Bank, the Card Network should over-write it....(this may seem to be insensible to many, but would help avoid such heists in future)
The entire Banking System across the reported 27 Countries failed to detect the heist and report it. here is the Fifth Lesson learned - 
  • The Banking system across world would need to develop a Governance mechanism to share daily charge back reports and highlight the cases that they seem are alarming. This would help the target banks to react faster than not and help avoid such mass scale heists
Few other lessons learned - 
  1. Payment processors and Banks to ensure that they have transaction monitoring systems deployed specifically for the Pre-Paid Cards as with the change in the Guard on Debit and Credit Cards, Scammers would focus on less secure cards
  2. Payment processors and Banks to develop systems to ensure that Risk Management Function is made responsible to review the anomalous behavior as noted in the transaction monitoring systems and as received in the charge back reports
  3. Information Security Mechanisms are beefed up across all the Payment Processors and Across the Payment Networks to help thwart such attempts in future
  4. Though Pre-Paid Cards are not related to any person in particular and hence they are not treated at par with the other Bank Cards, it it critical that Data Protection Regulations do cover these Cards. PCI Council too must ensure that they have comprehensive steps taken to this effect and bring the Pre-Paid Cards under the Scanner of PCI-DSS. They should also ensure that the Applications used for the Purpose are brought under the Scanner of PA-DSS.
------------------------------------------------------------------------------------------------------------

Thursday, March 28, 2013

Government unveils roadmap for use of new internet addresses

Quoted Article:






This is one of the most awaited change that the government is now rolling out.  Though late in the race, still better as this would kick off the next level of development and would result in far reaching results.  With this change, the reach of Internet would be possible even at the remote villages and towns and will help establish a better Governance Framework. 

A few out there might try to relate this to the various Schemes and Yojanas that are run by government and how this change would impact in far reaching results of those schemes? Now these are the things that we need to understand that rolling out IPV6 would help roll out more internet kiosks across the villages and would enable reach of information to the remote areas. 

There is also a great deal of benefit that can be derived by automating more Post offices and as I read the term the other day if Postal Department modernizes and applies for Banking license, then well you got a lot of things moving towards betterment of rural areas :).  These post offices can also be used as Cyber Cafe's with minimal charge on surfing to learn and surfing to have information sort of model.

Interestingly, if this change is coupled with few other changes like setting up Cyber Kiosks for Children Education, it would be less costlier to take education to villages. The interactive classes can be setup for educating not just the children, but also the illiterates.  The classes would increase participation of children who would though would be fascinated by the advancement of the technology, but would love to attend the school as they would see themselves as part of a bigger class that they would see.

Another scheme that can make more impact would be the Information Sharing with the farmers through the Cyber Kiosks that would help them learn about the weather forecasts, farming techniques, usage of manure, knowing the policies and procedures of lone facilities as well as the Govt supported rates. more advanced information would lead to more advanced farming and better productivity to boost the Agricultural Sector

These are just a few benefits that I see, there can be many more for that matter and for that the strategists in the Government need to run their brains and think out of the box :)

Tuesday, December 18, 2012

New Viruses as reported

The recent developments that hackers are adopting to target the systems are pretty interesting.  The Batchwiper as detected by the Iranian CERT and the Trojan as reported with evade technology are the two recent developments.  The Batch Wiper though can be contained with certain precautionary measures, but the Trojan with evade technology would certainly be something that would create a widespread Havoc.  

With the evade technology the Anti-Virus Firms would need time and research to ensure that the right set of detection & quarantine techniques are used so as not to jeopardize the O/S routines that the Trojans use to evade the AV.

Specifically with the Trojan that is reported and that waits for the left Mouse Click routine to execute the commands is one tricky case.  Certainly, we can't stop using mouse with the fear of the Trojan getting executed.....

Time to look out and dig deeper around these aspects to ensure that the corporate as well as home users are impacted the least.....

Saturday, October 13, 2012

Misconceptions around SSAE 16 / ISAE3402 / CSAE 3416

Post my previous post, I received a mail from one of my Friend around SSAE 16 / ISAE 3402 and I provided the reply to the friend and then thought, why not share the explanation with the wider Audiences for the good.  May be if somewhere I made a mistake, I would also get to learn -


Hi MT,
 
You are doing a good job...:-)
 
"The discussion was more centered around the need of Assurance Standards like SSAE 16 and ISAE 3402 and the interesting twist that was brought in was "If my organization is ISO 27001 Certified, do I still need to undergo SSAE 16 or ISAE 3402 Audits?"

It took me good enough time initially to make the person understand that the ISO 27001 standard and the controls framework revolves around the Information Security and not just IT Security."
 
Well, I've the same confusion... rather argument. Though ISO27001 is focused on Information Security, it doesn't stop you from adding additional controls, if required. As it is a standard, everything is in black and white..nothing more nothing less...just follow/comply to whatever is mentioned. If you need to add additional controls that you considered as very important, then add the controls and comply.
 
Wherein SSAE16 leads to confusion as they allow you to define your own controls based on GCC (general computer controls). If I select 10 controls, which I feel as important, for example, it is not necessary that you will agree to that, as you may have a different opinion and probably select few different controls that you feel as important. In other words, if 2 people are asked to define the controls for the same environment, the list of controls will definitely not match.
 
Whether it is ISO27001 or SSAE 16, the auditor will test the stated/defined controls and provide an opinion...of course in a different way i.e. either qualification or non-conformity, but the end result is the same.
 
So, the question is still the same, "If my organization is ISO 27001 Certified, why do I still need to undergo SSAE 16 or ISAE 3402 Audits?"
 
Can you help me understand please?
----------------------------------------------------------
My Reply - 

The point is the way the Audit is approached.  ISO 27001 is quite Generic Control Set that revolves around the set of Industry Standard Controls that may or may not be applicable to the set of given Industry Scenario.  The ISO 27001 is Organization wide control environment where you may select or omit the control from within the 133 controls that are defined in the Standard.  You may add a new control, but that needs to be covered under one of the predefined 11 control clauses (domains).  once done, you define the SOA to identify the controls as applicable/omitted from your Organizational environment.  Under such case the Audit is focused around the SOA and the reasoning for omitting a given control.

However, when you look at the specific set of operations for the given Client, the environment may differ from the overall organizational control set.  Certain controls may be applicable from the current set of ISO 27001 controls and certain controls that have been omitted from the Organizational perspective may be applicable in that scenario.  This certainly requires the organizations to go for SSAE 16 / ISAE 3402 (CSAE 3416 in Canadian Context) by defining specific set of controls.  

Let me give you an interesting perspective on the difference of Scope of ISO 27001 and SSAE 16 / ISAE 3402 / CSAE 3416 - 
  1. ISO 27001 specifically focuses on the Controls around Information Security, it does not cover the other scope like Contract Management, Delivery Organization & SLAs, these controls may be defined in the SSAE 16 / ISAE 3402 / CSAE 3416.  ISO 27001 doesn't have the provision on these sets
  2. ISO 27001 Certification revolves around the Set of 11 Control Clauses, where as in case of the SSAE 16 / ISAE 3402 /CSAE 3416, you would find that the Control Clauses can be customized to suit the environment, operations and services to be covered.
  3. Interesting point is around the set of Controls and Operations that are covered in both the cases.  As I mentioned above ISO 27001 focuses on Information Security and the Controls and Operations around that. However if we look at the SSAE 16 / ISAE 3402 / CSAE 3416 they can cover other set of operations and controls like Accounting Principles, Financial Controls etc.
  4. SSAE 16 / ISAE 3402 / CSAE 3416 SOC 1 controls and Audit Reports revolve around the Service Organization Controls that impact the Internal Controls on Financial Reporting (ICFRs) of the client. ISO 27001 does not focus on ICFRs.
  5. SOC 2 Reporting focuses more around 5 Trust Principles and how each control is implemented, monitored, executed etc.  Even SOC 3 Controls focus on the same 5 trust principles, but the objective of reports is different
  6. SOC 1 & SOC 2 Audit Reports are restrictive reports and the Intended Audience are limited set of people within the Service Provider and Client Organization. SOC 3 reports are not so confidential and can be shared publicly as desired.
I hope this clarifies you with the difference between the two Standards and Reporting Requirements