Showing posts with label Information Security Controls. Show all posts
Showing posts with label Information Security Controls. Show all posts

Friday, May 15, 2015

Seamless & Transparent Compliance & Security operations

Information Security and IT operations generally do not go hand in hand or I rather make a not so controversial statement that IT Operations Folks generally don't like Information Security Folks for they see the Information security folks to be the Show Stoppers.  The way I have witnessed it in my career, I have had the Label of "Bad Man of IT" then they used to call me "Risky Guy of IT" and all other sorts. I have had worked with various organization on consulting assignments and every time there used to be the same story - Chief Security Officer / Chief Information Security Officer would have to literally wrestle with the IT Operations for getting the Budget and then getting the technologies implemented. 

As quoted by one Vice President of IT at one of the client - "Don't bother much about them, they are just running various Projects that go no where and just wastes the money." When I interacted with the CISO on job and a direct report of CIO, he stated - "We have been able to procure some best of the techniques for Security, Risk and Compliance Management, But we have not been able to integrate them with the rest of the IT Systems, for they would not give us time to test the APIs and Connectors."

In another case where my team was conducting an IT Audit to help them identify the improvement areas to align with ISO 27001, I have had another weird experience.  The IT Manager who was the contact point for my team was my audience for the observations presentation.  And to my surprise or should I say dismay, he told me - "You do your work and submit the report, I will see where do I take this?" I was shocked as my team was engaged in a full length consulting assignment to finally ensure that the client organization gets to the level of being awarded ISO 27001 certification for IT practices.  What happened next over the course of time was altogether a different story.

Sounds strange, but its pretty much true as this is not a heard story and I myself have been the witness to have them say what they said and that has lead to me thinking on the ways Information Security and Compliance Management can actually be integrated into Daily IT Ops.  I have been an advocate of Information Security Culture rather than Enforcing the Information Security to avoid any such negative traction as to create stiff work environment.

To this effect, I have always thought about Security with Transparency or say Transparent Security.  The way it works for me that if there is a problem then certainly there is something NOT working right and there is a Problem.  This very problem is the issue creator for the IT Security Function to be able to work the way they are required to. These problems can then be used as the base cases by the IT Ops to push every issue towards IT Security.  So, I opine to establish the control regime in such a fashion that the overall IT Security Function becomes transparent to the level it can.  

For an IT Security Operation to be transparent, the first few steps would certainly involve automation of certain controls and functions. A very good way to proceed on automation journey would be to start from Log Aggregation and Correlation using the SIEM tool and then integrating the same with a GRC tool to create Dashboards and Reports. The next steps then would be to integrate an enterprise level IAM tool and Two factor Authentication (Preferably Soft tokens to be used) with the LDAP and other Applications to enable seamless connectivity with lesser passwords to manage (we all hate passwords, but remember that the hackers love them and if we would have lesser passwords to manage, we would feel better. and the two factor authentication would as is cover up for the weak passwords...), the IAM tool can also be extended for the purpose of Federated Identity Management as well as Single Sign On (SSO) and User Self Help to reset the Passwords.

Once the initial steps are successfully taken, the next step that I would suggest would be to integrate the GRC tool with the various tools and technologies deployed across the IT Landscape to obtain direct feed using APIs and Connectors. This though may be cumbersome and initially the IT Ops may oppose, but in a long run even they would start loving the results.  The live feeds configured can be used to identify any anomalies or say unauthorized changes or similar other compliance issues that may jeopardize the security of the system and leave it vulnerable for compromise.  

The whole benefit that can be derived out from the Integration of GRC tool with SIEM tool as well as the other IT tools and technologies is to be able to create the Dashboards and Reports for various Management Levels to provide them runtime snapshot of the Enterprise Security and Compliance Posture.  Also, this would mean that the IT Ops is not being bugged or harassed (as IT Ops actually feels) by the IT Security, Compliance an Audit functions for various data and evidence requests, because the required data and evidence feed would already be available on the GRC tool or the connected EDMS (Electronic Data Management System) library.

Also, it needs to be noted that the misconception of the Security, Compliance, Risk and Audit being the Pain areas for IT Ops would not end so soon unless they understand the importance of what we all do in our space.  We can start with the various steps as summarized above, but the mindset would take time to arrive at a cordial relations between IT Ops and the Security, Compliance, Risk and Audit guys....

Tuesday, April 22, 2014

Need to Security Private Information - Requirement in India

Unique Identification Authority of India (UIDAI) data center in Bangalore is reported to have got a cover of 65 star guards from multi-skilled security agency, the Central Industrial Security Force (CISF) - Your identity is guarded by 65 armed men (article on times of India).

It indeed is a commendable step by the authorities, but my question here is - Is this measure enough to secure the Identity and avert the threat from identity theft? Actually Speaking NO and the reasons that attribute to the answer NO are -
  1. The personal information of an average Indian is scattered across the Government Offices, Public and Private Banks and other Financial Institutions to a large extent.  More scary portion is the availability of this information on papers across the offices
  2. There is no defined mechanism to destroy the paper work by the various organizations and agencies.  Many a times some or other people from various organizations sell of these as waste papers to the scrap dealers.  There have been various incidents in past where papers with critical and sensitive information have been located with the road side vendors (bhel puri and other chat senders)
  3. There is no defined guideline by the Government of India on how to use / dispose / destroy the information whether in paper or on computers
  4. There are no set standards in India with respect to destruction or recycling of magnetic / optical media that may contain sensitive / private / identity information.  Such media may be Hard-Drives, Pen-Drives, Backup Tapes, CDs, DVDs, SD Cards etc among others
  5. Nasscom has also not worked to this effect to advice with any standard guidelines to be utilized to this effect
Saying all this, we should not actually be cheering the news as published as it is the least of the measures that is required at deployment.  Another aspect to look at is - Has Government also provisioned a DR site for the UIDAI Data Center? Is that location also guarded with similar set of Security Personnel?  Unless we get that information, I guess this news is just a hogwash,

If you feel I am trying to belittle Government's efforts, then well I am not.  But my effort is to sensitize that there are additional steps required by the Government to ensure that the information related to the Identity of Indians as well as tourists / visitors to India is treated as sensitive and private.  Adequate measures as detailed below need to be put in place to ensure that such information is treated in fair and just manner - 
  1. Enact a Data Privacy Law - Government needs to take immediate measures to ensure that the Data Privacy Law is enacted and enforced to set the expectations on dealing with Private and Sensitive Data.  The Information that needs to be treated as private and sensitive should include - Aadhar Number (as part of the UIDAI effort), PAN Card numbers (from Income Tax Authorities), Voter ID (from election commission), Ration Card, Passports and any other similar set of documents and information that can help establish the identity of any individual
  2. Define Data Handling Guidelines - As part of the Data Privacy Law, Government must define the treatment of information classified as Private and Personal in a manner cognizant to safeguard the Identity of person holding it
  3. Define Data Destruction Guidelines - As part of the Data Privacy Law, Government must also define how the data no more needed is to be destroyed.  For the data on paper and optical media for that matter must be destroyed by using shredders. The data on magnetic media for that matter must be destroyed by using programs that would over-write the data multiple times using different algorithms and thus rendering data as unreadable
  4. Define Consent Requirement - Often this is one of the most overlooked case where the private and personal information of any individual is circulated / shared for commercial benefits.  There are cases where the Customer Relationship Officers or the Marketing Staff carries over the contact and similar other information to the next organization without consent of the Data Owners.  It needs to be noted that the receiving Organizations / Agencies are Data Custodians and not Data Owners, meaning they can use data for their internal processing purpose only.  For sharing or using data for any other reason than intended reason should not be permitted without consent from the Data Owners (Data Owner is the person about whom the information is)
  5. Define Agreement Forms - Government must ensure that the Agreement forms used for the purpose of providing services are defined only for those services for which the Information is obtained.  Such Agreements must not any Clause or Fine Prints like "Organization / Agency may use this information for any of the required processing as may be deemed required by the organization / agency.
These are the basic steps to be taken to ensure Data Privacy & Protection.  These needs to be enforced along with the Indian IT Security Act 2008 Amendment Act to ensure that adequate Information Security Risks are addressed including the identity theft and information compromise.....



Friday, September 7, 2012

BYOD Program & Controls Requirement - II

As I wrote the previous Post - BYOD Program & Controls Requirement I received the comment on WFH, but I am certainly not covering that in this article, as that is a separate topic of discussion. What is more interesting that broke out as a discussion point with a colleague over a cup of coffee.  The discussion actually presented a counter argument to the Jump Server configuration.  

While in the discussion, I was very much inclined to and well still am that an organization as the first step to BYOD program should define the set of machines that they would allow.  It is pretty much important for the organization to define whether they are going to allow.  The Deep Dive on the topic reveals that the selection of devices would prompt additional thought process or should I say depending on the Support Strategy for the BYOD program the organization needs to define what devices would be allowed.

The various strategies would revolve around user experience v/s technological deployments. If an organization would like to restrict user experience and go with technological deployments that would ensure Data Security and related controls, the organization would then need to restrict the BYOD to Laptops and Desktops (may be or when its WFH). In this case the controls would be around the set of controls that have already been discussed in the previous post as mentioned above.

In case the organization would select User Experience then the organization would need to ensure that they provide support to any device and enhance the Mobility aspect of the user.  This decision however needs to be based on the following decisions - 
  1. What applications would be supported for BYOD and what level of modifications / application changes would need to be carried out?
  2. What level of Security would be needed to extend the support to the devices?
  3. What would be the application support, would it be Browser based only or Client based with a part of the program sits on the client side
  4. Would VPN security be extended to these Devices that would be supported?
There are many more questions that need to be answered for a Successful BYOD program. The Organization would additionally need to check if One Device One Number sort of Program be adopted or not. If the organization would decide to implement this program for increased mobility they need to ensure the Soft Phone Support. 

The BYOD Program as it seems is not actually an easy decision to take as the organization would require to answer many other questions and Specifically that would help them ensure mitigating Risks and meeting Compliance Requirements in Operationally Effective and Efficient Manner




BYOD Program & Controls Requirement


BYOD or Bring Your Own Device is the way organizations are planning to take.  The talk is going abuzz in the corporate world as it would help organizations reduce their IT budget and increase operational efficiency.  In my view it is not that bad an idea, but would require looking a bit deeper at the Compliance perspective and the risks that would emanate when an organization would run BYOD.  The Organizations would require investing and managing various technological solutions to ensure that the Data Privacy and Protection Laws of the world are addresses and that the common framework of controls is enforced across all the devices that come in being due to BYOD. 

The BYOD program from the aspect of controlling data access and ensuring data protection would need to evaluate and consider deploying following technologies:
  •   Jump Server – to log in to the organizations corporate network and provide viral desktop environment to the users.  The virtual desktop would have all the desired user settings including file & print configuration, Proxy settings, mailbox configuration and the application shortcuts for the desired applications for the user concerned
  • Network Admission Control – to control the risks emanating from the unpatched and unprotected personal devices that can introduce Trojans, viruses, worms, BOTS etc in the corporate network.  The Organizations would need to critically look at investing on a strict Anti-Virus & Patch Management Regime Supported by the Network Admission Control devices.
  • Two Factor Authentications – to ensure that the password compromises do not impact / provide access to the corporate network. Additionally this would also help organizations to be able to support the Work from Home (WFH) program thus further reducing their operational cost associated with Facility Management for the ever growing number of seats with workforce increase.

These are just the indicative controls that should be considered or rather implemented by the organizations seriously going the BYOD path.  Certainly the CXOs of the world would be better placed to take the final decision on the set of controls from the likes of IDM, DLP, SSO to add to.  This would certainly require an indepth assessment on the requirements and the risks emanating to an organization.

Saturday, March 7, 2009

Information Security Breach - Minimize Points of Entry to the Network

Information Security Breach can be referred to as the compromise with Confidentiality of Data / Information with an Unauthorized and Unwarranted access. However a breach might not always result in Data Theft, but as the Information Guardian, the Information Security Team of an organization must vigilantly secure access to the Information Assets hosting/processing critical information including Personally Identifiable Information (PII) of customers, vendors, employees and other associated entities, Card Holder Data (ChD, that includes, PAN, Expiry Data, Name as on Card and other such information as identified under PCI-DSS v 1.2).

The Information Security Team and the IT operations team must be aware of the Security Scams and the methods that may be used to attempt and effect the Breach.  General methods deployed for the purpose are - 
  • Theft of Physical Equipment/s
  • Social Engineering
  • Phishing
  • Hacking
  • DoS, DDoS, Ping of Death, Syn Flood Attack
  • Defacement of Website
  • URL / IP redirects (also referred as Pharming, normally is man-in-middle attack)
  • Malware implants (trojans, worms, viruses to capture keyboard inputs, sniff network activity etc)
To reduce the chance and to reduce the impact of any breach, it is always a good practice to identify the entry points to the corporate network and reduce them to the minimum.  With minimized entry points the steps that must be taken to reduce the impact of any attempt or breach therein are - 
  • Firewall / IDS / IPS and System logs must be reviewed on a regular basis to identify any sign of security Breach or attempt therein
  • Consider deployment of an effective event-correlation mechanism to help you in root cause analysis and establishing the entry point and the probable target system.
  • Ensure that the Mobile Equipments are configured with Data Security and Protection measures like File / Hard Disk encryption
  • Employee awareness must be maintained with regards to the procedures for reporting suspicious activities, system issues, mails etc
  • Engage Interaction with external parties (Law Enforcement, Security Consultants, Industry Associations etc) to be informed about the porabable or possible Security Breach
The steps discussed above are just the preliminary steps and organizations need to do more than just guarding the gates / entry points. 

I would discuss the road ahead in next post.

Regards
Mayank Trivedi
E-mail - mayank.a.trivedi@gmail.com
Being Proactive Saves Time and Money

Sunday, May 27, 2007

IT Security V/S Information Security

IT Security and Information Security are the two different domains often misunderstood as one. Though both of them have some common areas that are to be dealt, but by large, IT Security is a subset of Information Security.

IT Security deals with the technical set of controls and revolves more around the technological deployments across the Business to store, process, generate or transmit the Information. On the contrary Information Security also covers up the additional functionalities as those of Business Operations, legal, Human Resource, Facility Management etc. i.e. the Information Security also encompasses the various departments that deal with the data/information in other than electronic format.

If we talk of the controls that make part of the IT Security, then we would have controls revolving around following heads -
  1. IT Risk Assessment
  2. IT Asset Classification and Management
  3. Logical Access Control
    1. User Management
    2. Password Guidelines
    3. Access Rights and Permissions
    4. Login Restrictions
  4. Physical Access Control
    1. To the Data Center / Server Room
    2. To End User Terminal
  5. Emanation Security - dealing with Cabling security etc
  6. Communication Security - dealing with security during electronic transmission
  7. Systems Development, Acquisition and Management
    1. In-house Development
    2. Out-Sourced Development
    3. Off the Shelf Purchase
    4. System Change Management
  8. End User Computing
    1. Access to End User Development - Usage of Scripts and Macros in documents and spreadsheets
    2. Access to Install Custom Programs and Free-wares
    3. File Sharing through Local Shares
    4. Email and Internet Usage
    5. Acceptable usage of IT Resources
  9. Disaster Recovery Planning
    1. Back and Archiving
    2. DR Site Planning
    3. Fault Tolerance and Site Redundancy Planning
  10. Network and Operations Management
    1. Network Documentation
    2. Network Controls
    3. IP Addressing and Network Zoning
    4. Network Performance Monitoring and Capacity Management
    5. Remote Connectivity and Remote Access Management
    6. Usage of Cryptographic Techniques
    7. Operations Management
    8. Malicious Content Management
    9. Incident Monitoring and Management
    10. Media Handling and Storage
    11. Audit Logging and Log Retention
    12. Segregation of Development, Test and Production Environment
The Additional Control Areas that would make part of the Information Security can be listed as -
  1. Physical and Environmental Security - Encompasses Emanation and Cabling Security along with deployment of Human Personnel, CCTV Monitoring mechanism etc.
  2. Third Party Operations
  3. Business Continuity Management
  4. Compliance Audit and Management
  5. Human Resource Security - Identifying Human resource involved in operations as a source of threat
  6. Business Threat and Risk Assessment including Business Impact Analysis
References -

ISO/IEC 17799, ISO/IEC 27001, CObIT