Showing posts with label Audits. Show all posts
Showing posts with label Audits. Show all posts

Tuesday, October 13, 2015

Experian Hack

It has been almost a month that Experian reported a breach in which 15 million T-mobile customer accounts were said to be compromised. The information included names, addresses, email ids, social security numbers and few more details of the T-mobile customers in USA. Though Experian was quick to react before the information could have been misused to that effect, yet it was a scary news for those 15 million individuals and others who are T-mbile customers or those who have accounts with any of the service providers who use Experian as the Credit verification agency.  

For those who think they are not impacted, they need to rethink about not getting worried because Experian is one Credit Reporting Agency and if its systems can be compromised, then the other Credit Agencies  too can be. What does that mean to common man? Well, take control of your information that is stored, processed and transmitted by the Credit Reporting Agencies (TransUnion & Equifax included). 

As a reaction to the hack, Experian announced two year free Identity Theft protection service "ProtectMYID" for affected T-mobile customers.  Now, the big question that arises here is - "Why is it a reactive announcement and why is it that they otherwise are charging to monitor misuse of our information that they store/process/transmit?" Isn't it just logical to ensure that they or the service providers from whom we obtain the service should actually be providing this service as a complimentary service? Also, why should Experian provide us this service free only for 2 years? Is there a logical conclusion by them that the hackers will not misuse the data after two years?  Well, I guess they are just trying to shrug off their responsibility to protect our information available on their systems.  First of all they had their systems configured in a manner that got compromised and then they are offering something to show off to the world that they care.  Not something that I would buy with any sort of logic, though I would be the first person to avail immediate patch work offer from them to ensure data regarding myself and my family is not misused impacting my Credit Ratings.

So what does that mean for the Federal Regulators like FDIC should first look at amending the Fair Credit Reporting Act (FCRA) or State Regulations like Consumer Credit Reporting Agencies Act (as referred in California) need to be amended to ensure that the Credit Reporting Agencies are legally bound to secure Consumer Information.  At the same time, the Credit Rating Agencies must consider reviewing their current Security Architectures for access provisions and data flows to identify the possible loopholes that may leave enough space for data compromise like Experian. A composite review is the mandate of time and certainly the Audit reports by independent Auditors must be submitted to the regulators.  This needs to be a time bound activity to ensure that the Credit Reporting Agencies take required remedial measures to ensure that they step up the security provisions and ensure that such future breaches are thwarted right at the attempt level itself rather than letting it to be a news post breach.  It certainly is an important step to be proactive in securing the data and information rather than taking reactive measures that sometimes may result in an organization getting booted from business.

The Experian Breach should not be looked at just limited to T-mobile or Experian for that matter, the industry should take it as an alarm for the future attacks that hackers may be planning to gain more information and if they could get through the doors of Experian, they may get through the doors of other such agencies.  It is important that proactive measures and steps are taken to secure Consumer Data / Information for which these organizations are custodians, not the owners.  
____________________________________
Disclaimer: The views expressed above are solely of the Author and are not endorsed by any organization, individual or industry body for that matter.

Saturday, October 13, 2012

Misconceptions around SSAE 16 / ISAE3402 / CSAE 3416

Post my previous post, I received a mail from one of my Friend around SSAE 16 / ISAE 3402 and I provided the reply to the friend and then thought, why not share the explanation with the wider Audiences for the good.  May be if somewhere I made a mistake, I would also get to learn -


Hi MT,
 
You are doing a good job...:-)
 
"The discussion was more centered around the need of Assurance Standards like SSAE 16 and ISAE 3402 and the interesting twist that was brought in was "If my organization is ISO 27001 Certified, do I still need to undergo SSAE 16 or ISAE 3402 Audits?"

It took me good enough time initially to make the person understand that the ISO 27001 standard and the controls framework revolves around the Information Security and not just IT Security."
 
Well, I've the same confusion... rather argument. Though ISO27001 is focused on Information Security, it doesn't stop you from adding additional controls, if required. As it is a standard, everything is in black and white..nothing more nothing less...just follow/comply to whatever is mentioned. If you need to add additional controls that you considered as very important, then add the controls and comply.
 
Wherein SSAE16 leads to confusion as they allow you to define your own controls based on GCC (general computer controls). If I select 10 controls, which I feel as important, for example, it is not necessary that you will agree to that, as you may have a different opinion and probably select few different controls that you feel as important. In other words, if 2 people are asked to define the controls for the same environment, the list of controls will definitely not match.
 
Whether it is ISO27001 or SSAE 16, the auditor will test the stated/defined controls and provide an opinion...of course in a different way i.e. either qualification or non-conformity, but the end result is the same.
 
So, the question is still the same, "If my organization is ISO 27001 Certified, why do I still need to undergo SSAE 16 or ISAE 3402 Audits?"
 
Can you help me understand please?
----------------------------------------------------------
My Reply - 

The point is the way the Audit is approached.  ISO 27001 is quite Generic Control Set that revolves around the set of Industry Standard Controls that may or may not be applicable to the set of given Industry Scenario.  The ISO 27001 is Organization wide control environment where you may select or omit the control from within the 133 controls that are defined in the Standard.  You may add a new control, but that needs to be covered under one of the predefined 11 control clauses (domains).  once done, you define the SOA to identify the controls as applicable/omitted from your Organizational environment.  Under such case the Audit is focused around the SOA and the reasoning for omitting a given control.

However, when you look at the specific set of operations for the given Client, the environment may differ from the overall organizational control set.  Certain controls may be applicable from the current set of ISO 27001 controls and certain controls that have been omitted from the Organizational perspective may be applicable in that scenario.  This certainly requires the organizations to go for SSAE 16 / ISAE 3402 (CSAE 3416 in Canadian Context) by defining specific set of controls.  

Let me give you an interesting perspective on the difference of Scope of ISO 27001 and SSAE 16 / ISAE 3402 / CSAE 3416 - 
  1. ISO 27001 specifically focuses on the Controls around Information Security, it does not cover the other scope like Contract Management, Delivery Organization & SLAs, these controls may be defined in the SSAE 16 / ISAE 3402 / CSAE 3416.  ISO 27001 doesn't have the provision on these sets
  2. ISO 27001 Certification revolves around the Set of 11 Control Clauses, where as in case of the SSAE 16 / ISAE 3402 /CSAE 3416, you would find that the Control Clauses can be customized to suit the environment, operations and services to be covered.
  3. Interesting point is around the set of Controls and Operations that are covered in both the cases.  As I mentioned above ISO 27001 focuses on Information Security and the Controls and Operations around that. However if we look at the SSAE 16 / ISAE 3402 / CSAE 3416 they can cover other set of operations and controls like Accounting Principles, Financial Controls etc.
  4. SSAE 16 / ISAE 3402 / CSAE 3416 SOC 1 controls and Audit Reports revolve around the Service Organization Controls that impact the Internal Controls on Financial Reporting (ICFRs) of the client. ISO 27001 does not focus on ICFRs.
  5. SOC 2 Reporting focuses more around 5 Trust Principles and how each control is implemented, monitored, executed etc.  Even SOC 3 Controls focus on the same 5 trust principles, but the objective of reports is different
  6. SOC 1 & SOC 2 Audit Reports are restrictive reports and the Intended Audience are limited set of people within the Service Provider and Client Organization. SOC 3 reports are not so confidential and can be shared publicly as desired.
I hope this clarifies you with the difference between the two Standards and Reporting Requirements

Saturday, October 6, 2012

Misconceptions around SSAE 16 / ISAE3402

Pretty recently was indulged in a discussion around the need of Certification to the Need of Assurance.  It was a pretty interesting discussion that led me to evaluate the conceptions and misconceptions that prevail in the industry. I thought why not share it with the rest of the folks who would like to participate in the discussion here (though the discussion is over in the real life)

The discussion was more centered around the need of Assurance Standards like SSAE 16 and ISAE 3402 and the interesting twist that was brought in was "If my organization is ISO 27001 Certified, do I still need to undergo SSAE 16 or ISAE 3402 Audits?"

It took me good enough time initially to make the person understand that the ISO 27001 standard and the controls framework revolves around the Information Security and not just IT Security.  The certification process and the audit methodology involved has a different perspective from the perspective that SSAE 16 or ISAE 3402 Audits take.    

Another argument that was thrown in during the discussion was SSAE 16 and ISAE 3402 are aligned to the Financial Industry and the other industries do not have much benefit of adopting these standards. I had a tough time addressing this point as the set of people were not ready to understand the point for the misconception had a deep rooted belief behind it.  To explain them I had to then break the entire Audit and Reporting perspective of SSAE 16 and ISAE 3402 by the Audit Reports and the manner in which Audit is Approached.  The discussion went from points to tangents with the counter arguments, and there I had to actually dissect the SSAE 16 and ISAE 3402 Reporting requirements as based on the Impact to ICFRs and the Trust Principles. The explanation around Corporate Governance and impact to ICFRs and the relationship between SSAE 16 SOC 1 Type II and ISAE 3402 Type II report helped the audience to clarify the misconceptions they were carrying.

Another aspect that came in to my notice is the misconception around the Reporting requirements in ISAE 3402.  I was a bit startled that one of the person from a Senior Audit Position came with the SOC 2 Reporting requirements for ISAE 3402.  I clarified to them that there is no SOC 1, SOC 2 or SOC 3 reporting requirement in ISAE 3402, however ISAE 3000 provides with a provision to customize the ISAE 3402 reports to suit the Reporting Requirements and that the ISAE 3402 Report may be based on SOC 1, SOC 2 or SOC 3 as may be deemed reasonable.

The next point was to distinguish between the Certification and the Audit Report to provide "Reasonable Assurance".  Most of the participants in the discussion carried a misconception around SSAE 16 and ISAE 3402 about the "Certification". They thought that the Auditors issue or release a Certificate of Compliance.  However, they well noted when explained that the SSAE 16 as well as ISAE 3402 Audits do not result in any certification, rather they result in issuance of an Audit Report that "may be" called a Report on Compliance Status and where the Auditors provide with "Qualified" or "Unqualified" opinion on Service Organization's Controls as defined and implemented for the given "client" operations. 

This however is not the first time that I had been in such a situation, where I had to explain the requirement to undergo an Audit that is more of Attestation Audit than a Certification Audit. But I hope that as these two standards come more into practice, the situation would not look so grim to me.

Thursday, October 7, 2010

CardSystems Solutions Hack 2005 - Legal Suit Targetting Auditor

The topic sounds to be shocking, but if you read the article "In Legal First, Data-Breach Suit Targets Auditor" you would be surprised to know the proceedings that led to the Legal Suit. 

It will be really interesting to note the developments from here on as the Auditor may contest that the report was good for "As on Date" of Report and they are not liable for any subsequent breach as they are not keeping an eye on how the organization dealt with the information post the Audit Completion.


But does the role of Auditor end with the submission of report, specifically when the identified organization fails a previous Audit for storing sensitive data in an unprotected manner or in a manner that is not as per the specifications?  

Should not the Auditor go back at the records of previous Audit and identify the reasons that might have led to the failure in complying to the requirement?


Isn't the Auditor supposed to maintain the integrity of Audit Process and NOT overlook serious issue that were being reported for a period of 5 years preceding the Audit?


There are lot of questions that create a eye of suspicion on the role of Auditors.  Many a times the Auditors tend to turn a blind eye towards certain issues that are present due to organizational work culture.  They don't tend to highlight the issues for the reason that they feel they are not responsible for that.


We had earlier seen a law emanating out from the hi-profile case of Enron and Arthur Anderson, where both the companies disappeared from the Market.  As if that was not enough a lesson to be learnt by the Auditors that we often get to know of similar cases, though not of that profile.


Would that mean we will soon see another law stemming out, something that would Regulate and Govern the Audit Scenario?  Should not the Auditors tighten their belts to ensure that the Audits and the Audit Reports are fair and square, resulting in what they are actually supposed to result in, rather than twisting the results one way or other?

It is quite interesting that the Noble Profession of Auditors is fast becoming Commercialized, and at this pace, i would not be surprised to see a License Regime enforced for the Auditors on same line as the Lawyers and Formation of a Regulatory Body Like Auditor's Council to Govern Auditors'.