Showing posts with label IT Security. Show all posts
Showing posts with label IT Security. Show all posts

Thursday, June 14, 2007

IT Security Outsourcing Decisions - Considerations

As already raised the bar of suspicion in the previous two articles, now the
thing to think is - what needs to be done to clear the air of suspicion?
What is the possible way out to clear the ambiguity in the Process of
Outsourcing? Well though there are various ways to deal with the situation,
and one can do what may seem to be appropriate, but the steps that need to
be considered are -

* Think as a Hacker

* Decide on Accessibility?

* Control Data Usage and Handling

* Protect the Information

* Maintain Confidentiality

* Apply the Sixth Sense / Instinct

* Deploy Vigilance for Incidence Reporting


Think as a Hacker


There are few things to be considered and understood before finally handing
over the reigns to a stranger. One needs to view the IT issues from a
hacker's perspective. One needs to clearly take a good note of the situation
looking for the answer to the questions -

* What if my confidential information gets into the wrong hands?

* Do I have IT assets worth an abuse?

* What negative consequences would occur if they were abused?

* Is my job going to be on the line if my organization makes the
headlines?


Decide on Accessibility?


Most outsourced IT services require one or other person to have full access
to whole or a part of the organization's IT assets. For instance, IT
Helpdesk support professionals will most likely need administrative rights
to the client machines and probably the respective servers also. This
meaningfully translates into full access to corporate data stored on the
local drives and, potentially, network shares. Consider what an IT auditor
or security consultant may gather during the days, weeks or months while
working onsite at an organization's IT facility. It at times might translate
into more than what even the best guys of the organization know. Certainly
limitless and it only takes one miscreant to cause the damage.


Control Data Usage and Handling


Outsourced IT service provider might have access to the data as highlighted
in the previous point. But that's just one of the points identifying the
risks associated with Outsourcing. What is more important to establish is
what are the various outsourced personnel doing with the data. Data
handling by the outsourced agency is another aspect to be understood. If we
look into the matter we might find that the outsourced agency personnel
could be storing the data on their servers, laptops, CDs or USB drives or
might even be printing hard copies? Clients should expect to turn at least
some of their information over and need to be informed of why it's needed
and how it's going to be used.


Protect the Information


IT Systems deal, process and store vital data and information that is
sensitive, crucial and confidential for the business. When outsourcing the
security of the IT establishment and the organization wide information
security process, one has to consider how the data and information is being
protected? -- if at all. What are they doing with data and/or information?
Are they sharing it with colleagues or competitors? Keeping it to sell on
eBay in a few years? Even if the people you're outsourcing your IT services
to are bound by contract to protect your information, they may not have your
best interests in mind, or they may be just plain sloppy. Consider what a
person has to lose if he ends up leaving the company or getting out of the
IT business altogether. The probability of sales data, source code or
patient information being used for ill-gotten gains is pretty low, but it
can happen.


Maintain Confidentiality


Call me a pessimist, but I've seen too many digital goods mishandled by
careless IT experts with a general disregard for other people's property.
The root of a lot of this -- which continues to amaze me -- is when
organizations outsource IT support, but never consider the basics such as
running background checks and examining references on the people they're
placing trust in. Confidentiality agreements are being used more and more,
but arguably not enough.


Apply the Sixth Sense / Instinct


Strong contracts and clean criminal records are not a perfect indicator of
safe and sound IT services, so don't rely solely on them. It's also
unrealistic to attempt to completely control where your sensitive data is
housed and what a third-party does with it. Whether you're for or against
outsourcing IT services, you'll have to do it eventually. Do your best to
find good people to do business with - preferably through referrals - and
trust your instincts.


Deploy Vigilance for Incidence Reporting


Don't stop there though. It's not a matter of just having the proper
security controls and paperwork in place to take the risk out of outsourcing
IT services. It's just as important to have watchful employees who can tell
when something's not right and management that's willing to listen, support
their employees and create an overall sense of security vigilance in the
organization.

Saturday, June 9, 2007

IT Outsourcing Decisions - Concerns

Outsourcing of IT Services is the trend of today, and why not it helps an organization in focusing towards its core business where the strength lies. Why should an organization spend the time, effort and other resources where it does not specialize and which is not its core area of operations.

The first and foremost thing that is considered while taking the step of outsourcing is the selection of the right company. Yes, it is very important to select the right company to execute the outsourced job and in the manner and with the effect as the outsourcing organization would prefer it to be conducted. But is it the only requirement in outsourcing scenario? May be most out there would say ‘Yes’, but there is a difference somewhere, somewhere we are lagging. Why shall we just focus on the efficiency of the outsourced Company’s delivery mechanism and why not address the some other issues? Other than the effective and efficient delivery mechanism followed by the Outsourced Company, there are other areas that are more important and rather critical to the success of the Outsourcing Model being followed. These issues are rather related to the mechanism followed by the Outsourced Company to address the security risks involved in the overall outsourcing model.

For instance lets’ have a look at the US market that is one of the biggest market for the Outsourced Business Process concept. The organizations there are increasingly outsourcing their IT divisions including their IT Security set-up. Certainly to manage the growing cost of managing the IT establishment and at the same time to focus on the more profitable Business Divisions/Processes.

But then there is a flip side of the decision and that might have more of impact than the benefits. The flip side is for the obvious risks associated in outsourcing the IT function; the function that deals with processing and storage of the information that even includes critical and business sensitive information.

Now, coming from an Outsourcee background and being and being one of the Lead Consultants on the Outsourced jobs for my company, I would be one of those in the bandwagon to support the Outsourcing trend. Why should not I and why should I ever oppose it? After all I get my bread and butter from the outsourced jobs.

But just because I am an Outsourcee I should defy the fact that there is no risk in the Outsourcing models and approach as being followed? Should I just try to conceal the fact that when an Organization outsource a process to a third-party, be it for desktop support, security testing or network monitoring, the more accessible the electronic assets are and the greater is the risk of something bad happening. There is always a potential for loss increases given the seemingly endless amount of data stored processed and transmitted through so many different devices.

Though it might seem to be but it would not be a wild statement to say, “While most IT consultants are trustworthy and responsible, some might not. Seemingly not so bad people are doing bad things on computers all the time – and often the company who hired them doesn't even realize it.”

Let us examine the various risks that are associated with the outsourcing decision and then we can look into the aspects or steps that would help us in making the appropriate decision on outsourcing and what to outsource.

Concerns of Outsourcing

As every aspect of business has inherent concerns and the related risks, so is with the decision to outsource. Making a decision with the knowledge of these inherent risks makes life easier as we would be ready to take steps to avoid any materialization of these risks and avoid any adverse impact of the business profitability.

So what are the risks? and where they exist? are the main questions to be known. Let’s have a closure look at the risks that exist with the decision to outsource –

n Loss of Control

n Availability v/s Quality

n Mutual Trust

n Costs – Real and Uncertain

n Knowledge Transfer

n Shared v/s Dedicated Operations

n Legal and regulatory Compliance

Sunday, May 27, 2007

Principles of Information Security

Information Security has three basic principles commonly referred to as the CIA Triad of Information Security (i.e. Confidentiality, Integrity and Availability). These principles include standards, conventions and mechanisms that form the basis for defining and implementing security controls and practices.

In addition to the base principles (i.e. confidentiality, availability and integrity), there are the few additional principles which are more related to the technological and process controls that could be deployed to achieve the desired level of Information Security. Following paragraphs detail the base as well as additional principles which assist in effective management of Information Security:

Confidentiality

Providing the framework to restrict data/information access, Confidentiality refers to protection of information from disclosure to or interception by unauthorized individuals. The concept of Data / Information Privacy stems out from the Confidentiality Principle.

Simple question to be answered for Confidentiality Part is - "Is the Person Accessing Data/Information the right person to do so?"

Integrity

Providing the framework for Data / Information accuracy and completeness, Integrity refers to the Quality of Data / Information. Integrity ensures that information once recorded and approved cannot be modified in an unauthorized manner through improper channels.

The focus is more so on the accuracy and completeness a the consequences of using inaccurate information could result in inaccurate / inadequate inputs for decision making purpose.

Availability

Providing the framework to the timeliness and extent of Data /Information availability to the users, Availability refers to the continuity of services and controls for the reachability of the users to the required Data / Information.

Availability also encompasses the technical deployment i.e. - networked machines and other aspects of the technology infrastructure.

Authentication

Authentication refers to the mechanism deployed to ensure that the person trying to access the Data / Information is the right person to do so. It involves the Identification step and can be called as the Gate Keeper Stage for Data / Information Access.

Authorization

Authorization refers to the mechanism deployed to control the kind of access a user gets on the Data / Information and the systems as deployed to store, process and transmit the Data / Information.Its a usual practice to define the Authorization levels as per the roles and responsibilities of the authenticated user.

Accountability

Accountability refers to the mechanism deployed to ensure that the ownership of actions carried out by a user while dealing with Data / Information could be ascertained and that the users are made responsible for the overall Security of the Data / Information.

Auditability

Auditability refers to the system controls that would ensure that the System has a mechanism to record the user actions and assist in establishing the accountability of the user. The Auditability feature is vital during troubleshooting exercises.

Assurance

Assurance highlights the need of ensuring that the interest of the various parties involved in the are safeguarded. Assurance of Data / Information Security is required from the perspective of the various stack holds including Governmental / Law enforcement Agencies, Investors, Management, Employees etc.

Awareness

Last but not the least, Awareness is still not a much stressed principle. Awareness about the Policies/Procedures/Process/Guidelines/Organizational Operating Procedures etc, provides for the mechanism of trained and efficient users, to support the Effective Processes and Procedures.

IT Security V/S Information Security

IT Security and Information Security are the two different domains often misunderstood as one. Though both of them have some common areas that are to be dealt, but by large, IT Security is a subset of Information Security.

IT Security deals with the technical set of controls and revolves more around the technological deployments across the Business to store, process, generate or transmit the Information. On the contrary Information Security also covers up the additional functionalities as those of Business Operations, legal, Human Resource, Facility Management etc. i.e. the Information Security also encompasses the various departments that deal with the data/information in other than electronic format.

If we talk of the controls that make part of the IT Security, then we would have controls revolving around following heads -
  1. IT Risk Assessment
  2. IT Asset Classification and Management
  3. Logical Access Control
    1. User Management
    2. Password Guidelines
    3. Access Rights and Permissions
    4. Login Restrictions
  4. Physical Access Control
    1. To the Data Center / Server Room
    2. To End User Terminal
  5. Emanation Security - dealing with Cabling security etc
  6. Communication Security - dealing with security during electronic transmission
  7. Systems Development, Acquisition and Management
    1. In-house Development
    2. Out-Sourced Development
    3. Off the Shelf Purchase
    4. System Change Management
  8. End User Computing
    1. Access to End User Development - Usage of Scripts and Macros in documents and spreadsheets
    2. Access to Install Custom Programs and Free-wares
    3. File Sharing through Local Shares
    4. Email and Internet Usage
    5. Acceptable usage of IT Resources
  9. Disaster Recovery Planning
    1. Back and Archiving
    2. DR Site Planning
    3. Fault Tolerance and Site Redundancy Planning
  10. Network and Operations Management
    1. Network Documentation
    2. Network Controls
    3. IP Addressing and Network Zoning
    4. Network Performance Monitoring and Capacity Management
    5. Remote Connectivity and Remote Access Management
    6. Usage of Cryptographic Techniques
    7. Operations Management
    8. Malicious Content Management
    9. Incident Monitoring and Management
    10. Media Handling and Storage
    11. Audit Logging and Log Retention
    12. Segregation of Development, Test and Production Environment
The Additional Control Areas that would make part of the Information Security can be listed as -
  1. Physical and Environmental Security - Encompasses Emanation and Cabling Security along with deployment of Human Personnel, CCTV Monitoring mechanism etc.
  2. Third Party Operations
  3. Business Continuity Management
  4. Compliance Audit and Management
  5. Human Resource Security - Identifying Human resource involved in operations as a source of threat
  6. Business Threat and Risk Assessment including Business Impact Analysis
References -

ISO/IEC 17799, ISO/IEC 27001, CObIT