Showing posts with label Information Security. Show all posts
Showing posts with label Information Security. Show all posts

Monday, December 12, 2011

New Reader Poll - CISSP Exam

CISSP Logo
Image via Wikipedia
I just posted a reader poll that's now viewable on the right-hand column of this blog. I want to get opinions from those of you that have your CISSP certification. There are two questions in the poll:

  1. If you are a CISSP, did your employer at the time encourage you to take the CISSP exam? (Yes/No)
  2. If you are a CISSP, did your employer pay for you to take the CISSP exam, or did you? (Employer paid/you paid)

The poll can also be accessed directly from here.

As for the value of a CISSP vs. other certifications ... that's for yet another posting.

Friday, December 9, 2011

Free Security Awareness Training - Part 5 of 5

Class 1: Explosives
Image via Wikipedia
Today's post concludes the series of five posts whereby I wanted to give you links to 25 security awareness courses and videos that are publicly available.

I strongly believe that security awareness training is an essential component to good security. Throwing money and technology at the security problem might be worthwhile in the early stages of maturity of an originzatzion's information security program. However, the problem with this approach is that there are diminishing returns; more technology becomes less and less effective at improving security. Something needs to improve beyond installing and patching technology on a daily basis, forever running around attempting to deal with security incidents and emerging threats and doing work simply for work's sake. The human dimension is a critical part of this, and security awareness training helps sharpen this human component; the HumanOS.
  1. Analytical Investigative Tools (Multijurisdictional Counterdrug Task Force Training)
    1. What Every Law Enforcement Officer Should Know About DNA Evidence – Investigators and Evidence Technicians (DNA Initiative)
    2. Food Security Training (US Food and Drug Administration)
    3. Explosives, Booby Traps and Bomb Threat Management (Multijurisdictional Counterdrug Task Force Training)
    4. HAZMAT Transportation Security Awareness Training (Dangerous Goods International)

    Thursday, December 8, 2011

    Free Security Awareness Training - Part 4 of 5

    A U.S. Coast Guardsman searches for survivors ...
    Image via Wikipedia
    This week I'm sharing with you links to 25 security awareness training sites. The training links are being broken up into groups of five, published within five separate postings. Today we reach the forth set of training links for an accumulative total of 20.

    The 2008 information security survey by Pricewaterhouse Coopers revealed that investment in security technologies had increased but “the acute focus on technology over the last year has not been matched by an equally robust commitment to other critical drivers of security’s value, such as: (1) many of the critical business and security processes that support technology, and (2) the people who administer them.” Security awareness training helps address the second item.
    "The security discipline has so far been skewed toward technology - firewalls, ID management, intrusion detection - instead of a risk analysis and proactive intelligence gathering. Security investment must shift from the technology-heavy, tactical operation it has been to date to an intelligence-centric, risk analysis and mitigation philosophy. We have to start addressing the human element of information security, not just the technological one; it i only then that companies will stop being punching bags." - PricewaterhouseCoopers
    Below is the next set of security awareness training links.
    1. The History of Bio-Terrorism (Center for Disease Control and Prevention)
    2. Detecting Bio-Terror (Center for Public Health Preparedness)
    3. Radiological Terrorism: Just in Time Training for Hospital Clinicians (Center for Disease Control and Prevention)
    4. Nuclear Terrorism: Pathways & Prevention (Center for Public Health Preparedness)
    5. Preparedness & Community Response to Pandemics (Center for Public Health Preparedness)

    Monday, December 5, 2011

    Free Security Awareness Training - Part 1 of 5

    Poster produced in the US warning the public a...
    Image via Wikipedia

    As a security profesional I believe it's essential that we maintain security awareness and an understanding of the threats we face. Education often isn't cheap and the reality is that for many employers funding for training and education is very limited.

    Fortunately, we're entering into the holiday season, which is a time of giving, and what I'm giving you are 25 security awareness courses and videos that are publicly available. Okay - maybe not the most exciting gift, but it fits the budget.

    I will publish a series of five posts and each post will have links to five training resources. The security awareness courses may be completed online (or on CD-ROM) and are provided without cost to you. This study program is designed to provide you with a broad security awareness. There will be overlap in training that will help you to build depth of knowledge and to emphasize important areas. I emphasize "broad". The material covers many of the domains within security, some of it IT Security, and some of the material may seem a bit Rambo'esque or even doom-and-gloom.

    There are several separate agencies and organizations that are offering the courses. Certificates of training can be printed following completion of the courses. You can enroll in any individual course, or if you're more highly motivated, aim for completing all of them. Personally, I believe that anyone who completes all of the courses will become a much more valuable security asset to their employer as well as their community.

    Bring out the leftover turkey, stuffing and cranberry sauce ... it's time to cram in some free security awareness classes!

    1. Phishing Awareness (Defense Information Systems Agency - US DoD)
    2. Personally Identifiable Information (PII) (Defense Information Systems Agency - US DoD)
    3. Security & Privacy Awareness Training (National Institute of Health Information)
    4. Information Assurance Awareness (Defense Information Systems Agency - US DoD)
    5. Information Assurance Awareness shorts (Defense Information Systems Agency - US DoD)

    Sunday, May 31, 2009

    Cyberspace Security Review

    On Friday (May 29, 2009) President Obama announced the nation’s plan to defend against attacks on the nation's computer networks; a “strategic national asset.” This plan includes appointing a Cyber-Security Chief, whom he has not yet chosen, in the White House. Obama will sign a classified order within the coming weeks that will create the military cybercommand.

    He stated that cyber-criminals have cost US citizens over $8 billion worth of stolen data and that the figure worldwide was up to $1 trillion.

    The announcement came with the release of the Cyberspace Security Review, a 76 page document that had 60-days to be completed from the date of the initial request. The Cyberspace Security Review explains how the US intends to secure its critical network infrastructure. It was stated that the review was necessary because, “America's failure to protect cyberspace is one of the most urgent national security problems facing the new administration”, and that, “our digital infrastructure has already suffered intrusions that have allowed criminals to steal hundreds of millions of dollars and nation-states and other entities to steal intellectual property and sensitive military information.”

    The Cyberspace Security Review made the following 10 recommendations for near-term action:

    1. Appoint a cybersecurity policy official responsible for coordinating the Nation’s cybersecurity policies and activities; establish a strong NSC directorate, under the direction of the cybersecurity policy official dual-hatted to the NSC and the NEC, to coordinate interagency development of cybersecurity-related strategy and policy.
    2. Prepare for the President’s approval an updated national strategy to secure the information and communications infrastructure. This strategy should include continued evaluation of CNCI activities and, where appropriate, build on its successes.
    3. Designate cybersecurity as one of the President’s key management priorities and establish performance metrics.
    4. Designate a privacy and civil liberties official to the NSC cybersecurity directorate.
    5. Convene appropriate interagency mechanisms to conduct interagency-cleared legal analyses of priority cybersecurity-related issues identified during the policy-development process and formulate coherent unified policy guidance that clarifies roles, responsibilities, and the application of agency authorities for cybersecurity-related activities across the Federal government.
    6. Initiate a national public awareness and education campaign to promote cybersecurity.
    7. Develop U.S. Government positions for an international cybersecurity policy framework and strengthen our international partnerships to create initiatives that address the full range of activities, policies, and opportunities associated with cybersecurity.
    8. Prepare a cybersecurity incident response plan; initiate a dialog to enhance public-private partnerships with an eye toward streamlining, aligning, and providing resources to optimize their contribution and engagement.
    9. In collaboration with other EOP entities, develop a framework for research and development strategies that focus on game-changing technologies that have the potential to enhance the security, reliability, resilience, and trustworthiness of digital infrastructure; provide the research community access to event data to facilitate developing tools, testing theories, and identifying workable solutions.
    10. Build a cybersecurity-based identity management vision and strategy that addresses privacy and civil liberties interests, leveraging privacy-enhancing technologies for the Nation.

    What is promising about the Review is that there's repeated focus on outcomes as opposed to the inputs. Too often forward progress is hindered by the inefficient efforts of trying to define process before goals and objectives are clearly defined and understood. Rather, the Review consistently attempts to make it clear what the strategic outcomes are, and from those objectives, the development of process will be guided.

    The Review also states, “Other structures will be needed to help ensure that civil liberties and privacy rights are protected.” The inclusion to help protect our privacy and civil liberties is an indication of the balanced intention of the plan.

    Money will also be set aside for research and development of security technologies, from which there will be significant opportunity.

    What I'm not certain about is the overall effectiveness the Cyber-Security Chief will have. Specifically, the position will not have direct access to the president. As a result, this position may not be high-level enough to prevent the almost certain bureaucratic nonsense, internal bickering and games that could waste millions/billions of dollars.

    Though the Review solely focusses on defensive measures, I'm also curious what efforts are underway, if any, towards the development and potential use of cyberweapons.

    Overall, the document doesn't suggest that there will be any major changes that will affect the private sector within the near term. The Review recommends specific changes to the direction of future US policies. Within the mid-term I imagine that lawmakers will develop regulations that will require the sharing of security incident data from the private sector with the government, presumably tempered with the commitment to ensure civil liberties. I anticipate that we will also see more emphasis put towards penetration testing and incident response.

    Steve

    ###

    Wednesday, May 27, 2009

    How ITIL Can Improve Information Security

    By: Steven Weil

    Introduction

    ITIL - the Information Technology Infrastructure Library - is a set of best practices and guidelines that define an integrated, process-based approach for managing information technology services. ITIL can be applied across almost every type of IT environment.

    Interest in and adoption of ITIL has been steadily increasing throughout the world; the numerous public and private organizations that have adopted it include Proctor & Gamble, Washington Mutual, Southwest Airlines, Hershey Foods, and the Internal Revenue Service. In addition to the often touted benefits of ITIL - aligning IT with the needs of the business, improving service quality, decreasing the costs of IT service delivery and support - the framework can aid the information security professional both directly (there is a specific Security Management process) and indirectly.

    This article will provide a general overview of ITIL and discuss how ITIL can improve how organizations implement and manage information security.

    ITIL overview

    ITIL began in the 1980s as an attempt by the British government to develop an approach for efficient and cost-effective use of its many IT resources. Using the experiences and expertise of successful IT professionals, a British government agency developed and released a series of best-practice books, each focusing on a different IT process. Since then, ITIL has become an entire industry of organizations, tools, consulting services, related frameworks, and publications. Currently in the public domain and still evolving, the 44-volume set of ITIL guidelines has been consolidated into 8 core books.

    When most people discuss ITIL, they refer to the ITIL Service Support and Service Delivery books. These contain a set of structured best practices and standard methodologies for core IT operational processes such as Change, Release, and Configuration Management, as well as Incident, Problem, Capacity, and Availability Management.

    ITIL stresses service quality and focuses on how IT services can be efficiently and cost-effectively provided and supported. In the ITIL framework, the business units within an organization who commission and pay for IT services (e.g. Human Resources, Accounting), are considered to be "customers" of IT services. The IT organization is considered to be a service provider for the customers.

    ITIL defines the objectives, activities, inputs, and outputs of many of the processes found in an IT organization. It primarily focuses on what processes are needed to ensure high quality IT services; however, ITIL does not provide specific, detailed descriptions about how the processes should be implemented, as they will be different in each organization. In other words, ITIL tells an organization what to do, not how to do it.

    The ITIL framework is typically implemented in stages, with additional processes added in a continuous service improvement program.

    Organizations can benefit in several important ways from ITIL:

    • IT services become more customer-focused
    • The quality and cost of IT services are better managed
    • The IT organization develops a clearer structure and becomes more efficient
    • IT changes are easier to manage
    • There is a uniform frame of reference for internal communication about IT
    • IT procedures are standardized and integrated
    • Demonstrable and auditable performance measurements are defined

    ITIL details

    ITIL takes a process-based approach to managing and providing IT services; IT activities are divided into processes, each of which has three levels:

    • Strategic: An organization's objectives are determined, along with an outline of methods to achieve the objectives.
    • Tactical: The strategy is translated into an appropriate organizational structure and specific plans that describe which processes have to be executed, what assets have to be deployed, and what the outcome(s) of the processes should be.
    • Operational: The tactical plans are executed. Strategic objectives are achieved within a specified time.

    A description of each of the numerous IT processes covered by ITIL is beyond the scope of this article. What follows are brief, general descriptions of the ITIL processes that, along with the Security Management process, have a significant relationship with information security. Each of these areas is a set of best practices:

    • Configuration Management: Best practices for controlling production configurations (for example, standardization, status monitoring, asset identification). By identifying, controlling, maintaining and verifying the items that make up an organization's IT infrastructure, these practices ensure that there is a logical model of the infrastructure.
    • Incident Management: Best practices for resolving incidents (any event that causes an interruption to, or a reduction in, the quality of an IT service) and quickly restoring IT services. These practices ensure that normal service is restored as quickly as possible after an incident occurs.
    • Problem Management: Best practices for identifying the underlying cause(s) of IT incidents in order to prevent future recurrences. These practices seek to proactively prevent incidents and problems.
    • Change Management: Best practices for standardizing and authorizing the controlled implementation of IT changes. These practices ensure that changes are implemented with minimum adverse impact on IT services, and that they are traceable.
    • Release Management: Best practices for the release of hardware and software. These practices ensure that only tested and correct versions of authorized software and hardware are provided to IT customers.
    • Availability Management: Best practices for maintaining the availability of IT services guaranteed to a customer (for example, optimizing maintenance and design measures to minimize the number of incidents). These practices ensure that an IT infrastructure is reliable, resilient, and recoverable.
    • Financial Management: Best practices for understanding and managing the cost of providing IT services (for example, budgeting, IT accounting, charging). These practices ensure that IT services are provided efficiently, economically, and cost-effectively.
    • Service Level Management: Best practices for ensuring that agreements between IT and IT customers are specified and fulfilled. These practices ensure that IT services are maintained and improved through a cycle of agreeing, monitoring, reporting, and reviewing IT services.

    There is also a Service Desk function that describes best practices for establishing and managing a central point of contact for users of IT services. Two of the Service Desk's most important responsibilities are monitoring incidents and communicating with users.

    Figure 1 depicts the above processes, showing how the Service Desk function serves as the single point of contact for the various service management processes.


    Figure 1
    Figure 1. ITIL Service Management Processes

    More detailed information about the above processes and Service Desk function can be found in the references listed at the end of this article.

    ITIL and information security

    ITIL seeks to ensure that effective information security measures are taken at strategic, tactical, and operational levels. Information security is considered an iterative process that must be controlled, planned, implemented, evaluated, and maintained.

    ITIL breaks information security down into:

    • Policies - overall objectives an organization is attempting to achieve
    • Processes - what has to happen to achieve the objectives
    • Procedures - who does what and when to achieve the objectives
    • Work instructions - instructions for taking specific actions

    It defines information security as a complete cyclical process with continuous review and improvement, as illustrated in Figure 2:


    Figure 2
    Figure 2. Information Security Process

    As some organizations look at Implementation and Monitoring as a single step, ITIL's Information Security Process can be described as a seven step process:

    1. Using risk analysis, IT customers identify their security requirements.
    2. The IT department determines the feasibility of the requirements and compares them to the organization's minimum information security baseline.
    3. The customer and IT organization negotiate and define a service level agreement (SLA) that includes definition of the information security requirements in measurable terms and specifies how they will be verifiably achieved.
    4. Operational level agreements (OLAs), which provide detailed descriptions of how information security services will be provided, are negotiated and defined within the IT organization.
    5. The SLA and OLAs are implemented and monitored.
    6. Customers receive regular reports about the effectiveness and status of provided information security services.
    7. The SLA and OLAs are modified as necessary.

    Service level agreements

    The SLA is a key part of the ITIL information security process. It is a formal, written agreement that documents the levels of service, including information security, that IT is responsible for providing. The SLA should include key performance indicators and performance criteria. Typical SLA information security statements should include:

    • Permitted methods of access
    • Agreements about auditing and logging
    • Physical security measures
    • Information security training and awareness for users
    • Authorization procedure for user access rights
    • Agreements on reporting and investigating security incidents
    • Expected reports and audits

    In addition to SLAs and OLAs, ITIL defines three other types of information security documentation:

    • Information security policies: ITIL states that security policies should come from senior management and contain:
      1. Objectives and scope of information security for an organization
      2. Goals and management principles for how information security is to be managed
      3. Definition of roles and responsibilities for information security
    • Information security plans: describes how a policy is implemented for a specific information system and/or business unit.
    • Information security handbooks: operational documents for day-to-day usage; they provide specific, detailed working instructions.

    Ten ways ITIL can improve information security

    There are a number of important ways that ITIL can improve how organizations implement and manage information security.

    1. ITIL keeps information security business and service focused. Too often, information security is perceived as a "cost center" or "hindrance" to business functions. With ITIL, business process owners and IT negotiate information security services; this ensures that the services are aligned with the business' needs.
    2. ITIL can enable organizations to develop and implement information security in a structured, clear way based on best practices. Information security staff can move from "fire fighting" mode to a more structured and planned approach.
    3. With its requirement for continuous review, ITIL can help ensure that information security measures maintain their effectiveness as requirements, environments, and threats change.
    4. ITIL establishes documented processes and standards (such as SLAs and OLAs) that can be audited and monitored. This can help an organization understand the effectiveness of its information security program and comply with regulatory requirements (for example, HIPAA or Sarbanes Oxley).
    5. ITIL provides a foundation upon which information security can build. It requires a number of best practices - such as Change Management, Configuration Management, and Incident Management - that can significantly improve information security. For example, a considerable number of information security issues are caused by inadequate change management, such as misconfigured servers.
    6. ITIL enables information security staff to discuss information security in terms other groups can understand and appreciate. Many managers can't "relate" to low-level details about encryption or firewall rules, but they are likely to understand and appreciate ITIL concepts such as incorporating information security into defined processes for handling problems, improving service, and maintaining SLAs. ITIL can help managers understand that information security is a key part of having a successful, well-run organization.
    7. The organized ITIL framework prevents the rushed, disorganized implementation of information security measures. ITIL requires designing and building consistent, measurable information security measures into IT services rather than after-the-fact or after an incident. This ultimately saves time, money, and effort.
    8. The reporting required by ITIL keeps an organization's management well informed about the effectiveness of their organization's information security measures. The reporting also allows management to make informed decisions about the risks their organization has.
    9. ITIL defines roles and responsibilities for information security. During an incident, it's clear who will respond and how they will do so.
    10. ITIL establishes a common language for discussing information security. This can allow information security staff to communicate more effectively with internal and external business partners, such as an organization's outsourced security services.

    Implementing ITIL

    ITIL does not typically start with IT - it is usually initiated by senior management such as the CEO or CIO. As an information security professional, however, you can add value by bringing ITIL to the attention of senior management. With the framework's rapidly increasing adoption, your organization might already be talking about ITIL; letting your management know specifically about ITIL's information security benefits can help spur its adoption.

    Implementing ITIL does take time and effort. Depending on the size and complexity of an organization, implementing it can take significant up front time and effort. For many organizations, successful implementation of ITIL will require changes in their organizational culture and the involvement and commitment of employees throughout the organization.

    Critical factors for successful ITIL implementation include:

    • Full management commitment and involvement with the ITIL implementation
    • A phased approach
    • Consistent and thorough training of staff and management
    • Making ITIL improvements in service provision and cost reduction sufficiently visible
    • Sufficient investment in ITIL support tools

    Conclusion

    Information security measures are steadily increasing in scope, complexity, and importance. It is risky, expensive, and inefficient for organizations to have their information security depend on cobbled-together, homegrown processes. ITIL can enable these processes to be replaced with standardized, integrated processes based on best practices. Though some time and effort are required, ITIL can improve how organizations implement and manage information security.


    Author Resource: Steven Weil, CISSP, CISA, CBCP is senior security consultant with Seitel Leeds & Associates, a full service consulting firm based in Seattle, WA. Mr. Weil specializes in the areas of security policy development, HIPAA compliance, disaster recovery planning, security assessments, and information security management. He can be reached at sweil@sla.com.

    Article From: SecurityFocus

    Saturday, February 7, 2009

    Thoughts on IT Security Organizational Structure

    I've recently been asking myself how to most effectively structure Information Security (InfoSec) within an organization. Here are some thoughts I've had while trying to answer this.

    As with any "structure" there needs to be some form of integral support, whether it's a frame for a house or honeycomb for a beehive. This is also true with organizational structures - there needs to be support. In order for InfoSec to be successful it must have the full support of senior or executive management. This support would be actualized as a sincere commitment by senior management to achieve the following:

    • Develop high standards of corporate governance
    • Treat InfoSec as a critical function that enables an organization to do business
    • Create an environment that understands the importance of, and embraces, InfoSec
    • Consistently show 3rd parties that InfoSec is vital and will always be handled in a professional manner
    • Ensure that controls being implemented by InfoSec are appropriate and proportionate to risk being addressed
    • Stay informed and accept ultimate responsibility and accountability

    The first bulleted point in the above list, "Develop high standards of corporate governance", is where the necessary framework is built from which InfoSec can flourish. At a minimum, an effective governance framework includes:

    • An all-inclusive security strategy that links to clearly defined and documented business objectives
    • Security policies that address the multiple facets of security strategy, regulatory compliance and controls
    • Standards for each of the policies to make sure that procedures and guidelines comply with policy
    • An organizational structure void of conflicts of interest with sufficient resources and authority
    • Metrics and monitoring processes to ensure compliance and provide feedback

    Again, I want to emphasize that It is imperative that an organization's top management sees InfoSec as a critical business function and is fully committed to stand behind InfoSec. Without the complete assurance from top management we will continue to see security functions getting moved around the organization while adequate resources are never obtained and conflicts of interest are progressively created.

    To limit conflicts of interest and actualize the benefits from investing within InfoSec, the Chief Information Security Officer (CISO/ISO) or Information Security Manager (ISM) must report directly to the top of the organizational structure, or an independent branch such as Audit. The trend in the past was to embed central InfoSec within Information Technology (IT), that is, until organizations began realizing that this structure kept InfoSec's hands tied behind their back, significantly reducing InfoSec's overall effectiveness. In other words, organizations were self-limiting their return on investment (ROI) from InfoSec. To resolve this issue and improve the ROI from InfoSec, CISO's/ISO's/ISM's began reporting to the CEO's, CFO's, CTO's and CIO's.

    Slide11.png

    Ok, great, so the ISO should report to the CFO ... then what?

    What we want to avoid is a structure with the fragmentation that is commonly seen today. Rather, create a tighter integration of the duties and activities performed by IT Security, Operations, Policy & Compliance, Risk Management and Audit. To anticipate the trends of the future, it’s very likely that individuals and departments taking on central InfoSec duties will also have various risk management responsibilities that extend beyond IT. This can include anything from physical security, business continuity and disaster recovery.

    Slide1.png

    Fact is, too often in industry the security discipline is (mis)directed by technology instead of using a risk analysis and proactive ‘intelligence’ approach. To add to the vicious cycle, when majority of the investment is being put into technology then most of the return comes from there too. This reinforcement perpetuates the destructive spiral.

    So, how does a business avoid this technodazed shortsightedness? It comes down to strategy, making the conscious shift to be more strategic. This means moving away from the predictable technology-centric and tactical security operation seen in the industry since the golden days of the dot-gone era. At a high level, for InfoSec to more closely align with and help business achieve its objectives, InfoSec will need to become more focussed on 'intelligence'; gathering information, ability to comprehend, ability to develop policy and plans at a high level, using a methodology of risk analysis and risk mitigation, having the knowledge about an organization's business environment that has implications for its long-term viability and success, thinking long-term, and being both pragmatic and visionary.

    Thinking strategically while taking into account anticipation of future trends and using proactive 'intelligence', I believe the wise CISO, or equivalent, who's in a healthy organizational environment needs to start planning for incorporating some of the non-IT specific risk management responsibilities before it's thrust upon them within the next three to five years. There will need to be coordination between IT Security, Operations, Policy & Compliance, Risk Management, Audit and Physical Security.

    What this boils down to is that a very effective way to structure InfoSec within an organization involves having the CISO, or equivalent, reporting directly to the senior/executive level of the organization while having their full support, commitment and involvement. This top level commitment includes the development of high standards of corporate governance and actively limiting conflicts of interest so that InfoSec will be effective and provide a high ROI by enabling the organization to do business.

    Slide2.png
    Steve
    ###