Showing posts with label Risk Management. Show all posts
Showing posts with label Risk Management. Show all posts

Friday, October 9, 2015

Compliance Management - Considerations

Many a times we encounter situations where we find that certain Information Security Policy requirements and considerations are not in line with the Global Security Best Practices and they actually are not in-line with the Global Standards to that effect. But, the major mistake that we make at such a point is to take into considerations the Business Requirements for that organization or for those who actually are the recipient of the overall results on those Business Requirements.

The issues are overwhelming for the Risk and Compliance Manager across the world as they try to bridge the gap between the Auditor's Expectation with the Real World Scenarios with all the practicalities.  This doesn't mean that Auditor's Expectations are not practical or not something that need not be entertained per say.  What is more important for the Risk and Compliance Managers as well as the Business Managers is to ensure that these expectations are well understood so that it would be easier to meet them by remediating the open issues.

More often than not Auditors as well as Risk & Compliance Managers are often misunderstood and seen as a "Red Flag Bearers" by the Business & Technology Managers. Though this perception can't be justified, but then they have their own reasons as they have to run the show.  There are many a times when Business as well as Technology Managers have to take quick decisions and at times they circumvent / bypass some critical security / compliance considerations to ensure that the "Show has to Go on."

However, though they say everything needs to be done to ensure that the Business as Usual must prevail, there are some checks and balances that must be applied and Compliance Considerations must be brought to the every day work life.  Though I had maintained for long that "what is compliant" is not always secure (for if it were secure we would not have as many breaches as we hear), I still maintain that Compliance provides for the baseline controls we must have in place.  How we convert them from Compliance Controls to Security Controls depends on how Security Focused we are.

The Compliance Considerations that I prefer Organizations should keep up to are -

  1. Following defined processes and procedures
  2. Documenting what is being done - meetings, notifications, trainings, approvals etc.
  3. Documenting the changes being introduced
  4. Resolving issues with Long Term strategies than short term remediations
  5. Following Risk Based Approach
  6. Adopting Return on Investment from Technology (ROIT) adoption rather than resorting to Cost  & Benefit Analysis (CBA) - This would always prove to be profitable approach in longer term
  7. Unified Compliance Approach rather than Project base Compliance Approach working in Silos - This would always help reduce duplication / redundancy in controls being managed and technology being deployed. There always is an overlap of requirements across various Industry standards and regulations impacting compliance posture of any organization
  8. Drive Enterprise-wide Compliance efforts rather than Business Segment Silos
There are few others that may be considered, but the basics of Compliance Management would seek solace in the ones mentioned above.

Sunday, May 12, 2013

$45 Million Heist with Prepaid Card Duplication: Lessons Learned

In my previous post "$45 Million Heist with Prepaid Card Duplication", I had highlighted the questions that creep up in our mind as general readers or followers of the news.  Those questions are basically something that need to be dealt with or answered for a meaningful conclusion of the investigation.

However, from the Risk Management perspective and the ongoing compliance enforcement, there are few critical lessons learned if the GRC world is watching this incident from that perspective.  

It was really amazing to learn the way these scammers came along together and indulged in such a widespread scam to cover 27 countries as reported.  Here is the first lesson learned - 
  • Organize your move and collateral to ensure that Risks are covered at all times. This can be achieved only when you have a sound Risk Management Framework to document All the possible Risks and monitor them on an ongoing basis
Banking organizations across the 27 countries failed to identify the large chunk of withdrawals from their ATMs. Here is the second lesson learned - 
  • Banks need to put a governing policy to monitor the cash withdrawals from their ATMs. They need to closely review the Cash withdrawal pattern from various ATMs they own. This would help raise the red flag faster
Payment Processors failed to maintain their security measures in-line with those required for Banking Organizations. Here is the third lesson learned - 
  • Payment Processors must ensure that they deploy layered security to ensure that the Databases are always hosted in the most secure zone and preferably be protected by host based IPS systems that would raise alarms on detecting any anomalous behavior
Card Networks failed to raise the alarm too and rather delisted a given payment processor that was breached.  This is certainly an act of washing out once own hands of the responsibility. Fourth lesson learned here - 
  • Card Networks need to ensure that they control the limits once defined. Meaning, once a Payment Processor or Bank has defined transaction limit on a given Pre-Paid Card, it needs to be populated to the Card Network. This should be a One Time one way update.  Generally a Pre-Paid Card user is not worried with the limits set on the card as they use cards for limited set of transactions only.  So if there is a change in the Transaction limit from the Payment Processor or Bank, the Card Network should over-write it....(this may seem to be insensible to many, but would help avoid such heists in future)
The entire Banking System across the reported 27 Countries failed to detect the heist and report it. here is the Fifth Lesson learned - 
  • The Banking system across world would need to develop a Governance mechanism to share daily charge back reports and highlight the cases that they seem are alarming. This would help the target banks to react faster than not and help avoid such mass scale heists
Few other lessons learned - 
  1. Payment processors and Banks to ensure that they have transaction monitoring systems deployed specifically for the Pre-Paid Cards as with the change in the Guard on Debit and Credit Cards, Scammers would focus on less secure cards
  2. Payment processors and Banks to develop systems to ensure that Risk Management Function is made responsible to review the anomalous behavior as noted in the transaction monitoring systems and as received in the charge back reports
  3. Information Security Mechanisms are beefed up across all the Payment Processors and Across the Payment Networks to help thwart such attempts in future
  4. Though Pre-Paid Cards are not related to any person in particular and hence they are not treated at par with the other Bank Cards, it it critical that Data Protection Regulations do cover these Cards. PCI Council too must ensure that they have comprehensive steps taken to this effect and bring the Pre-Paid Cards under the Scanner of PCI-DSS. They should also ensure that the Applications used for the Purpose are brought under the Scanner of PA-DSS.
------------------------------------------------------------------------------------------------------------

Friday, March 25, 2011

Cloud Computing - The Risk Management Aspect

Cloud Computing is the Buzz Word that has caught the lime light in recent years and it is indeed interesting to see where does it go from here?  Will it be Hype or will it be a successful Marketing Gimmick by the Infrastructure Services Providers and the OEMs.  There has been a lot written and lot deliberated over the cloud security and cloud compliance, but the main case here is the case of Risk Management in Cloud Computing.  It is pretty important for the CIOs and the CFOs to understand the Risks as associated with the Cloud Computing Infrastructure.  Specifically in the Light of the Data Security and the Data Privacy requirements.  I am sure none of the CIOs and for that matter CXOs would ever want to fall in the trap where the data movement in cloud scenario would impact the Regulatory Compliance scenario with Cross Border Data movement on Cloud Infrastructure spanning across geographical locations.

I remember during one of my discussion with my colleagues, where I was skeptical about the data privacy issues.  It was one of the situation where I was pitted against the team of Architects who were pretty confident about building a solution providing the business benefit to the client.  But on my question - "What is the Geographical Span of the Cloud that you are looking at?" oops that was like a jolt from Blue for the Architects and they were looking for a definite answer, but to no avail.

In another offline discussion with one of the CSO friend of mine, the same question stumped him too.  His company was looking at Cloud Based Email Solution from a leading Service Provider.  My question to him was followed by another on the type of Data that flows on email.  It is interesting to note that Corporate emails carry attachments right from Employee details to Corporate Financial Performance and Business Strategies.  That means from Company HR, Marketing, Legal and Financial Data flows on Corporate Emails.  Interestingly, the organization didn't go for the Cloud Email Solution, as they could not find an answer to the question of Risk Management while going for Cloud based Email Solution.

I am still trying to look for an Answer from the Experts around on the questions a pitted above.  I would love to get an answer on the question of Managing Risks in a Cloud Based Computing Solution!!!