Let’s Not Ignore Security in the Internet of Things

The more we talk about the Internet of Things (IoT) the more we have to talk about securing it. Gartner forecasts that by 2020, the IoT will comprise 26 billion devices and will generate incremental revenues of $300 billion, along with some $1.9 trillion in what the researcher describes as “global economic value-add through sales into diverse markets.”

But before we start seeing wireless diapers and connected beer kegs everywhere, there are significant concerns about IoT and security that need to be addressed. Every IoT security headline, whether it’s about hacked baby monitors or compromised insulin pumps, is a reminder that as a community, we’re still weighing the benefits of a hyper-connected lifestyle against potential security risks.

At Palo Alto Networks we’re in constant discussion about how the IoT concept will affect different enterprises and markets, from healthcare to retail, as well as how a next-generation enterprise security platform is crucial to securing so much connectivity. Here are a few recent examples of our global colleagues sharing IoT insights:

  • Sharat Sinha talked with MIS Asia about the challenges of securing so many IP-enabled devices
  • Arthur Capella offered IoT security perspective for Brazil’s CanalTech (Portuguese)
  • Gavin Coulthard addressed securing SCADA infrastructure with CommsCritical in Australia
  • Armando Decal shared four best practices for securing IoT devices with TechDay and ZDNet

How is your organization approaching good security for the Internet of Things? Leave a comment below and let us know.

[Source: Palo Alto Networks]

Internet of Things: Challenges of securing IP-enabled devices


Photo: Sharat Sinha

A few years ago, the idea of having home and office appliances connected to a network may have seemed like something straight out of science fiction. Today, however, as technology continues to develop and evolve, this is fast becoming a reality that is increasing in complexity and sophistication.

Commonly referred to as the ‘Internet of Things’ (IoT), this connectedness is seeing a surge in growth, as everyday appliances are being IP-enabled and connected to the network. Clearly, it is a trend which seems set to continue.

Last month’s Internet of Things (IoT) Asia Exhibition and Conference, held in Singapore, reflected the direction local enterprises are moving towards to enhance their competitive advantage, with devices in the IoT used to better address their consumer and/or enterprise needs. But the benefits of IoT, while often cited as significant, have been countered with talks of increased security risks, which could be substantial, particularly in areas such as critical infrastructure, where they become targets for nation states and criminal organisations intent on accessing confidential data and information.

What are the vulnerabilities posed by IoT?
Analyst group Gartner projected that by 2020, the number of IP-enabled devices, not including PCs, tablets and smartphones, will hit 26 billion units globally, while IDC’s assessment pegged that number at 212 billion units. These numbers are significant, as each device represents another potential entry-point for hackers to launch targeted attacks on enterprises. With more devices communicating and sharing potentially confidential and sensitive data, coupled with the emergence of unprotected networks, the conclusion is obvious: there will be far more vulnerability points for security breaches.

Secondly, vendors with little or no security expertise are likely to overlook the security aspect of their low-cost IP-enabled devices that can be hooked up to the IoT. Thus, it may not be surprising to find basic security features absent in these devices. Moreover, there are no security standards to conform to in the majority of these devices—each differing in purpose and construction, utilising different operating systems and plugging into different parts of a network or system. As a result, protecting these devices and the communication between them has become a big challenge.

The third major risk is the devices’ connection to cloud-based applications and services. New data is constantly being uploaded, processed and deposited in the cloud, bringing the issue on data sovereignty into question. Moreover, data collection is often vague, with little clarity on access control and management, resulting in further complexities to segment and secure these massive volumes of data.

How to secure the Internet of Things
Fortunately, securing the multitude of potential attack points exists. This involves leveraging the same strategy as other IP-based communications.

Firstly, it is important to identify and understand which devices are part of the IoT network. Crucial knowledge about the nature of IoT devices is one of the stronger approaches in making decisions to protect the device and manage its data, similar to the security functions currently in existence for mobile endpoints. If a device is infected with malware, for example, it can be blocked from accessing the IoT network.

As IP-enabled devices differ in functionality, the most logical solution is to secure these devices at a network level rather than the endpoint level, thereby overcoming the limitations present in endpoint security functions. Depending on the support of inspection of IoT communications protocol, IoT can also leverage on existing network security solutions like firewall and IPS. In addition, by using the Zero Trust principles of least privilege access with granular segmentation, enterprises can secure IoT data and application access.

While the IoT may offer potential for improving the way that enterprises and government currently operate, it is fundamental to overcome the biggest challenge faced: the regulation surrounding IoT data collection system and the way these records will be used, shared and secured. To achieve this, it is imperative for enterprises, governments and standard organisations to collaborate and leverage expertise to overcome IoT’s complex, multi-faceted security vulnerabilities.

Sharat Sinha is Vice President, Asia Pacific, Palo Alto Networks

[Source: MIS Asia]

ISACA Names Matthew S. Loeb as CEO

Rolling Meadows, IL, USA (5 June 2014)—ISACA, a global professional association serving 115,000 information systems assurance, security, governance and risk professionals, has selected Matthew S. Loeb, CAE, as its new chief executive officer. With a strong background in enterprise strategy, corporate development, global business operations and governance, Loeb brings his extensive experience in leading innovation and strategic growth to ISACA.

“The ISACA Board of Directors welcomes Matt, and we look forward to working closely with him and building on our 45-year history helping our members and their enterprises drive value through information and information systems,” said Tony Hayes, 2013-2014 international president of ISACA and chair of the CEO search panel. “Matt is the right person to lead ISACA and is an ideal match for the execution of ISACA’s Strategy 2022, a long-term plan to expand the association’s reach into critical areas impacting business and technology, including cybersecurity and privacy. His experience in digital publishing, certification, global expansion and new programs in emerging technologies is key as we continue to enhance our resources for enterprises and members.”

He will assume his role as ISACA CEO on 1 September 2014. Loeb will come to ISACA after having completed a 20-year career as staff executive for the Institute of Electrical and Electronics Engineers (IEEE) and as the executive director of the IEEE Foundation.

“As enterprises continue to invest in information systems to build personal relationships with their customers and gain business efficiencies, challenges of compliance, risk, big data, privacy and cybersecurity are increasing complexity for ISACA members in their work to ensure trust and value from these systems.” said Loeb. “While ISACA already delivers resources to help, we have the opportunity to do even more, including increasing appreciation for the role our professionals play in advancing economic prosperity and keeping the digital world safe. I am privileged to have the opportunity to partner with ISACA’s board and employees to grow the organization’s influence and impact globally.”

Established in 1969, ISACA serves members in more than 180 countries and offers four globally recognized certifications: Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in the Governance of Enterprise IT (CGEIT) and Certified in Risk and Information Systems Control (CRISC). ISACA developed the COBIT framework, which helps companies govern and manage their information and technology, and recently launched the Cybersecurity Nexus program to help enterprises develop their cybersecurity work force and address the global skills shortage.

Loeb takes over the position from Acting CEO Ron Hale, Ph.D., CISM, who has filled the role since Susan M. Caldwell retired in September 2013 after 21 years as CEO of ISACA.

Additional information about ISACA is available at www.isaca.org.

 

About ISACA

With more than 115,000 constituents in 180 countries, ISACA (www.isaca.org) helps business and IT leaders build trust in, and value from, information and information systems. Established in 1969, ISACA is the trusted source of knowledge, standards, networking, and career development for information systems audit, assurance, security, risk, privacy and governance professionals. ISACA offers the Cybersecurity Nexus, a comprehensive set of resources for cybersecurity professionals, and COBIT, a business framework that helps enterprises govern and manage their information and technology. ISACA also advances and validates business-critical skills and knowledge through the globally respected Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in the Governance of Enterprise IT (CGEIT) and Certified in Risk and Information Systems Control (CRISC) credentials. The association has more than 200 chapters worldwide.

Participate in the ISACA Knowledge Center: www.isaca.org/knowledge-center

Follow ISACA on Twitter:  https://twitter.com/ISACANews

Join ISACA on LinkedIn: ISACA (Official), http://linkd.in/ISACAOfficial

Like ISACA on Facebook: www.facebook.com/ISACAHQ

 

Contact:

Kristen Kessinger, +1.847.660.5512, news@isaca.org

Joanne Duffer, +1.847.660.5564, news@isaca.org

[Source: ISACA]

Four Things You Didn’t Know About Cloud Security

As more organizations move their data to cloud-based platforms, best practices for protecting sensitive assets continuously evolve. One of the biggest stumbling blocks IT professionals face with cloud security is purely conceptual—fail to understand the cloud and you will fail to understand the threats your assets face.

Let’s explore four ideas about the cloud that have clear security implications, both good and bad…

Emulate the biggest cloud user
The single biggest user of cloud storage—and thus the biggest stakeholder in keeping it secure—is the US federal government. More than 50% of government organizations now store their data and applications on a cloud-based platform and almost US $2 billion is spent each year keeping these cloud services functional and secure.

So what does this mean for you? It means that, of all places, the US government may be one of the most worthwhile organizations to emulate when it comes to best practices for data security in the cloud. In fact, the White House’s cloud-computing strategyprovides an excellent template for safely migrating sensitive data.

20% of data center devices are obsolete
Growing demand for cloud services has led to a virtual epidemic of providers upgrading their infrastructure in a haphazard, inefficient manner. In fact, data from the Uptime Institute indicates that one-fifth of all cloud servers are “obsolete, outdated or unused.”This widespread inefficiency represents a serious hidden security risk—many cloud users have had their sensitive data unknowingly exposed through systems that are improperly monitored, security resources that are stretched too thin, or improper offloading of old drives, servers and other hardware.

In this case, being vigilant about whom you work with is the best way to stay safe. Compliance with SSAE 16 or ISO 27001 usually indicates that a data center is prepared to meet the challenges associated with growth.

Data encryption does not equal privacy
Data encryption is a major selling point of many cloud services, and most of us have been brought up to believe that encrypted data is inherently safe. That changes in the cloud, however. If your encryption keys are being held by your provider, are your assets really secure? Whether it is a malicious insider or a government operative working under the auspices of the US PATRIOT Act, encryption keys are surprisingly accessible by third parties.

Instead, practice two-factor encryption of sensitive data—encrypt it before sending it to the cloud to make sure it cannot be accessed by an outsider.

The biggest threats may be from within
According to research conducted in February 2012 by IBM and the Ponemon Institute, the single biggest threat to sensitive data is user error. More than viruses, data breaches or insecure application programming interfaces, your own employees pose the biggest threat to the security of your cloud-stored data. Simple mistakes like improper password storage or forgetting to log off a shared workstation jeopardize countless assets every day.

For many organizations, the best investment that can be made in cloud-data security is training. Team members who have to access important data need to know proper safety techniques and these techniques should be implemented and enforced on a day-to-day basis.

Rich Murphy
Director of Technical Account Management—BlackStratus

[Source: ISACA]

English
Exit mobile version