Building the Business Case for Enterprise Governance of IT

The adoption of practices and approaches for governance and management of enterprise IT (GEIT) is rising, and enterprises do experience its practical relevance in delivering value to their stakeholders. But implementing and improving GEIT takes a reasonable amount of effort, as it requires a company to assess and rethink the governance and management enablers (including their policies, processes, structures and skill sets) and how they support enterprise business goals.

As a result, investments in improving governance and management of IT are often perceived as costly and complex, while return in stakeholder value is difficult to measure in tangible—often financial—outcomes.

To address this challenge, ISACA commissioned a research project to the University of Antwerp— Antwerp Management School. This practice-oriented research was executed in the second quarter of 2015 and attempts to demonstrate the business value achieved by applying governance and management enabler categories as proposed in COBIT 5. By offering the empirical evidence that governing and managing those enablers has a positive impact on enterprise value creation, management will find it easier to support investment propositions related to GEIT.

Additionally, the results of this research contribute to the relatively new domain of knowledge and theory being built. It will assist practitioners by providing an international benchmark and more guidance on how governance and management frameworks such as COBIT 5 can lead to higher enterprise value creation from their information and technology (IT) assets and resources.

A glimpse of some findings
The findings suggest that professionals perceive and experience governance and management enablers such as structures, processes, skills, etc. as valuable for adopting and implementing GEIT. Each of the COBIT 5 enablers is seen as highly important. Better implementation rates of the COBIT enablers clearly show positive correlations with the achievement of IT-related goals, which in turn strongly associates to the achievement of enterprise goals.

The research also revealed that, in general, many governance and management processes that required more business management involvement achieved lower implementation scores (e.g. managing organizational changes, business process controls). This is a call for action as the importance of business involvement in IT-enabled value creation has been stressed by many researchers (e.g., Weill and Ross, 2009; De Haes and Van Grembergen, 2015; Turel and Bart, 2014). Or in the words of Weill and Ross, “If senior managers do not accept accountability for IT, the company will inevitably throw its IT money to multiple tactical initiatives with no clear impact on the organizational capabilities. IT becomes a liability instead of a strategic asset.”

By extension, the research also showed limited board-level commitment in management and governance of IT. These results confirm other international studies that report on the “surprising state of practice” (Andriole, 2009) after having observed low involvement rates of boards in enterprise governance of IT. However, other studies underline the importance of board involvement, demonstrating a clear association between board-level involvement in GEIT and organizational performance (Turel and Bart, 2014). As such, these results are also a call for action for board members in the area of GEIT as Wim Van Grembergen and I noted in our text onEnterprise Governance of IT.

The results of this study are available in Benchmarking and Business Value Assessment of COBIT 5, which is available for free download at www.isaca.org/benchmarking-cobit. Many results will also be discussed in the next ISACA Journal edition. We invite you to explore the results and look forward to your comments.

Steven De Haes
University of Antwerp – Antwerp Management School

[ISACA]

Palo Alto Networks Researcher Discovers Two Critical Internet Explorer Vulnerabilities

Palo Alto Networks researcher Bo Qu discovered two new critical Internet Explorer (IE) vulnerabilities affecting IE versions 6, 7, 8, 9, 10, and 11. Both are included in Microsoft’s July 2015 Security Bulletin, and documented in Microsoft Security Bulletins MS15-065 and MS15-066.

In our continuing commitment to the security research community, these vulnerabilities were disclosed to Microsoft through our participation in the Microsoft Active Protections Program (MAPP) program, which ensures the timely, responsible disclosure of new vulnerabilities and creation of protections from security vendors.

Palo Alto Networks is a regular contributor to vulnerability research. Previous critical IE vulnerability discoveries from the past year included three in Junethree in Mayone in Marchfive in February (revised from three), three in November 2014one in October 201415 in September 2014,  three in August 201410 in July 2014, and 22 in June 2014 (revised from 21).

By proactively identifying these vulnerabilities, developing protections for our customers, and sharing them with Microsoft for patching, we are removing one weapon used by attackers to compromise enterprise and government networks.

[Palo Alto Networks Blog]

The Cybersecurity Canon: Cybercrime and Espionage: An Analysis of Subversive Multi-Vector Threats

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

Book Review by Canon Committee Founder & Palo Alto Networks CSO, Rick HowardCybercrime and Espionage: An Analysis of Subversive Multi-Vector Threats (2011) by Will Gragido and John Pirce

Executive Summary

Cybercrime and Espionage, published in 2011, is a book that was ahead of its time. The authors were pushing the envelope in terms of how the security community should think about advanced threats. However, almost five years later, there is not enough in here to make the book Cybersecurity Canon material. Gragido and Pirc present some stimulating ideas, but in the end, the security community has not adopted many of them.

My recommendation is to read this book if you are interested in how our community has evolved in terms of thinking about adversary campaigns. However, if you are looking for a state-of-the-art book about cybercrime and cyber espionage, this is not it.

Introduction

Will Gragido and John Pirc published this book in February 2011 — the year after the commercial industry experienced its wake-up call in terms of cyber espionage: Operation Aurora. [1] Aurora refers to the adversary campaign launched at Google and other commercial organizations that was designed to steal intellectual property, collect information on human rights activists, and gather intelligence regarding on-going FBI wiretap operations. [2]

What made Aurora notable was Google’s reaction to it. They went public and accused the Chinese government of being responsible for the attacks. Before Aurora, most commercial organizations would not admit that they had been breached, even though nation states had been targeting commercial organizations for at least a decade. Business leaders worried that admitting a breach would significantly affect the bottom line. After Aurora and Google’s public mea culpa, it became easier for other commercial entities to admit that they had been breached. Fast-forward to today, and public breach notifications are so common that it is difficult to keep up with them all.

But this was the beginning. Before Aurora, the only significant cyberthreat to the commercial world at the time was crime. After, cyber espionage became something that we all had to worry about. This is the context for the book: defining cybercrime and cyber espionage as motivations — what makes them different and what makes them the same.

Impressions

The two authors, Will Gragido and John Pirc, are experienced cybersecurity professionals, and it is clear that they know what they are talking about; but the book is a bit disorganized in terms of who the target audience is. The content is a mix of introductory and advanced material. However, I did not see that the book had a through line. The authors’ analysis of the cybercrime world is at the introductory level. If you want a more in-depth book on the same topic that was published around the same time, consider Kingpin, written by Kevin Poulsen. [3] If you are looking for something a little more recent, consider Spam Nation by Brian Krebs, which was inducted into the Canon earlier this year. [4] The espionage material is more advanced, but if you want to go deeper, consider Kim Zetter’s Countdown to Zero Day [5], another Canon inductee, or Richard Bejtlich’s The Practice of Network Security Monitoring. [6]

I do give the Gragido and Pirc credit though for covering some advanced ideas ahead of their time that have not really become popular until just recently. One idea that I really like is that commercial organizations should build their own intelligence teams to track adversary campaigns. They published the book almost five years ago, and this was not universally accepted at the time. It is not universally accepted today either, but more and more organizations are starting to understand the value of such teams. As an aside, this is one of the reasons I got hired at Palo Alto Networks: to build an intelligence team that we eventually called Unit 42.

Gragido and Pirc push their own intelligence model called MOSAIC: Motive, Awareness, Open Source Intelligence Collection, Study, Asymmetrical Intelligence Correlation, Intelligence Review and Interrogation and Confluence. It is a good framework for an intelligence analyst; unfortunately, the model has not really caught on. Most intelligence organizations — the CIA, the FBI, and the NSA, as well as Unit 42 — use a model called The Intelligence Cycle. [7][8] They are basically the same thing, but the MOSAIC model has more detail.

The authors introduce a new phrase called Subversive Multivector Threats (SMTs), a sort of superset to what the cybersecurity community used to call the Advanced Persistent Threat (APT). They even explain the origin of the APT phrase, a phrase the military had been using for almost a decade in an UNCLASSIFIED setting to mean anything that involved Chinese government-sanctioned cyber espionage. Gragido and Pirc were ahead of their time, understanding that the community needed another name to label similar attacks that did not originate from China. Thus, they came up with SMTs, but the community has not embraced that term. We have evolved the APT phrase to include everything instead.

Another advanced idea presented that I really liked was the concept that there are humans behind these attacks. Tools do not attack our systems. Humans — often organized into groups — attack our systems, and they use tools to accomplish some goal. These adversary groups can be rated in skill level from novice to expert and have motivations like cybercrime and cyber espionage; and it helps defenders do a better job by understanding that context, according to the authors. I wholeheartedly agree. But today, I think we can expand that motivation list to include hacktivism, cyberterrorism and cyberwarfare, and I thought their definitions of hackers’ maturity levels were not definitive enough to be useful.

Also, Gragido and Pirc introduce a two-tiered categorization scheme for adversary campaigns, where Tier – 1 campaigns target:

“… air-gapped networks or networks that would be considered highly secured, such as those of power companies (supervisory control and data acquisition or SCADA networks), governments, and defense organizations.” [9]

Tier-2 adversary campaign plans are all other APT campaigns. This two-tiered system seems ill-conceived today. The security community considers SCADA networks in general, and power companies in particular, as being at least 10 years behind the rest of the community [10].  And government networks have proven to be even less secure than most commercial organizations, except for maybe the intelligence community’s networks and some select defense networks. [11] I do not see a need for this two-tiered system in today’s threat environment.

One last advanced idea that I really liked was that threat prevention is possible. There has been a trend in the industry these past five years where security leaders have thrown their hands in the air saying they cannot possibly stop the APT, and that it is better to concentrate their precious resources solely on detection and mitigation. This is just plain wrong, and Gragido and Pirc do well to point that out. If I can prevent 90 percent of all attack campaigns because most adversaries use known techniques, why not do it? That lets me concentrate my resources on finding the unknown techniques. Detection and mitigation is important, but these activities hould be balanced with a robust threat prevention program. Even in 2011, Gragido and Pirc asserted this philosophy.

Conclusion

Cybercrime and Espionage is a book that was ahead of its time. I give the authors credit for pushing the envelope as to how the security community’s thinking around advanced threats should evolve. If you read it when it was published, it would have stimulated your thought process around your own security program. But almost five years later, there is not enough in here to make the book Canon material. Gragido and Pirc present some stimulating ideas, but in the end, the security community has not adopted many of them. My recommendation is to read this book if you are interested in how our community has evolved in terms thinking about adversary campaigns. However, if you are looking for a state-of-the-art book about cybercrime and cyber espionage that will stand the test of time, this is not it.

Sources

[1] “Google Hack Attack Was Ultra Sophisticated, New Details Show,” by KIM ZETTER, Wired Magazine, 14 January 2010, Last Visited 5 July 2015, http://www.wired.com/2010/01/operation-aurora/

[2] “Google Aurora Hack Was Chinese Counterespionage Operation,” by Mathew J. Schwartz, Information Week: Dark reading, 21 May 2013, Last Visited 5 July 2015, http://www.darkreading.com/attacks-and-breaches/google-aurora-hack-was-chinese-counterespionage-operation/d/d-id/1110060?

[3] “The Cybersecurity Canon: Kingpin,” by Rick Howard, Palo Alto Networks, 11 February 2014, Last Visited 9 July 2015, http://researchcenter.paloaltonetworks.com/2014/02/cybersecurity-canon-kingpin/

[4] “The Cybersecurity Canon: Read Rick Howard’s First-Look Review of SPAM Nation by Brian Krebs,” by Rick Howard, Palo Alto Networks, 17 November 2014, Last Visited 9 July 2015, http://researchcenter.paloaltonetworks.com/2014/11/cybersecurity-canon-rick-howard-reviews-brian-krebs-spam-nation/

[5] “The Cybersecurity Canon: Countdown to Zero Day: Stuxnet and the Launch of the World’s First Digital Weapon,” by Rick Howard, Palo Alto Networks, 28 January 2015, Last Visited 9 July 2015, http://researchcenter.paloaltonetworks.com/2015/01/cybersecurity-canon-countdown-zero-day-stuxnet-launch-worlds-first-digital-weapon/

[6] “The Cybersecurity Canon: The Practice of Network Security Monitoring,” by Rick Howard, Palo Alto Networks, 10 November 2014, Last Visited 9 July 2015, http://researchcenter.paloaltonetworks.com/2014/11/cybersecurity-canon-practice-network-security-monitoring/

[7] “The Intelligence Cycle,” Central Intelligence Agency: Kids Zone, Last Visited 9 July 2015, https://www.cia.gov/kids-page/6-12th-grade/who-we-are-what-we-do/the-intelligence-cycle.html

[8] “The Intelligence Cycle,” Federation of American Scientists, Last Visited 9 July 2015, http://fas.org/irp/cia/product/facttell/intcycle.htm

[9] “Cyber Crime and Espionage: An Analysis of Subversive Multi-Vector Threats,” by Will Gragido & John Pirc, Syngres Publishing, 7 January 2011, Last Visited 10 July 2015, https://www.goodreads.com/book/show/10651366-cyber-crime-and-espionage?ac=1

[10] “SCADA systems: Riddled with vulnerabilities?” by Doug Drinkwater, SC Magazine, 26 August 2014, Last Visited 10 July 2015, http://www.scmagazineuk.com/scada-systems-riddled-with-vulnerabilities/article/368094/

[11] “4 Worst Government Data Breaches Of 2014,” by Jai Vijayan, InformationWeek: Government, 12 November 2014, Last Visited 10 July 2015,http://www.informationweek.com/government/cybersecurity/4-worst-government-data-breaches-of-2014/d/d-id/1318061

References

“APT1 Three Months Later – Significantly Impacted, Though Active & Rebuilding,” by Dan Mcwhorter 21 May 21 2013, Last Visited 9 July 2015, https://www.mandiant.com/blog/apt1-months-significantly-impacted-active-rebuilding/

“EU Data Protection Directive (Directive 95/46/EC),” by TechTarget, Last Visited 10 July 2015, http://searchsecurity.techtarget.co.uk/definition/EU-Data-Protection-Directive

“Internet Crime Complaint Center (IC3),” The Federal Bureau of Investigation (FBI) and the National White Collar Crime Center (NW3C), Last Visited 5 July 2015, http://www.ic3.gov/media/annualreports.aspx

“SAFE HARBOR PRIVACY PRINCIPLES,” by export.gov, Last Visited 10 July 2015, http://www.export.gov/safeharbor/eu/eg_main_018475.asp

[Palo Alto Networks Blog]

Spotlight on Advanced Persistent Threats in Industrial Control Systems

The challenge of APTs targeting Industrial Control Systems continues to evolve and escalate.  It is true that a number of the ICS-specific attacks in the years immediately following Stuxnet (e.g. Duqu, Flame, Shamoon) are not so interesting as derivatives of Stuxnet or in how they utilize more general, IT-centric exploits.  However, 2014 was a milestone year in that we saw two APTs that uniquely expanded on the initial methods used by Stuxnet:  Energetic Bear/Dragonfly (Havex) and Sandworm (Black Energy campaign). 

The most recent campaigns from these APTs have upped the bar in terms of “craftiness” with techniques combining more sophisticated social engineering, ICS protocol exploits, and exploits to automation-specific HMI software.  In the case of the APT attack to the German steel mill, also disclosed in 2014, we are reminded of potentially destructive cyberphysical effects that could occur when ICS systems are breached. (In this case, the destruction of a blast furnace.)

The “people, process, technology” discussion around security is very relevant here.  As always, the human element involved in social engineering is a particularly difficult challenge.  Most advanced attacks will employ some form of social engineering.  Education goes a long way in terms of mitigating the issue but motivated attackers will always find a way to trick a targeted individual into opening the malicious email attachment, loading and infected file on the free USB thumb drive, or visiting a seemingly innocent website housing drive-by malware, unknowingly initiating the APT attack.

To add, on the technology front, these attacks by well resourced actors like nation states and cybercriminal organizations typically use both known attacks and zero-day exploits and/or malware which conventional methods cannot detect nor prevent.  Combine social engineering and zero days, and you have a very effective methodology for establishing a beachhead for an ICS attack whether it is first into the IT side of the house or directly in the OT side.

Is APT Prevention a Holy Grail?

Many organizations assume they will breached, and think preventing advanced attacks is not feasible.  Hence, they try their best to isolate the SCADA/ICS network and stop known threats.  Capabilities to stop more advanced threats are typically non-existent or just starting to be deployed by some more forward-thinking organizations. Considering the high costs to organizations that are breached and the people and safety concerns associated with cyberphysical processes going awry in critical infrastructure, an inability to stop advanced threats should be something asset owners take seriously and address.

At Palo Alto Networks we believe that preventing attacks from APTs is possible.  No security solution is ever 100% effective, but we have a strong platform that makes it extremely hard for the bad guys, even the very sophisticated ones behind APTs, to successfully implement their attacks.  It is based on a platform approach that combines the power of the next-generation firewall, our threat intelligence cloud and advanced endpoint protection to prevent attacks and provide increased automation of security functions while providing correlated threat intelligence and logs.

Get up to Speed on APTs in ICS

We take a closer look at APTs in ICS and methods for protecting your organization against them using a platform approach in an upcoming webinar co-hosted by Mike Assante, Director of ICS at the SANS Institute, and myself.  Join us on Wednesday, July 22, to learn more about:

  • The evolution of APTs in ICS from the original Stuxnet to the recent Black Energy
  • The model of the APT attack lifecycle with a focus on the different phases and associated “kill points” which are critical to understand from a defensive standpoint
  • Best practices and technologies that help organizations better protect themselves from such attacks, particularly those using zero-day techniques

Register for the webinar at this link.  Thanks, and we hope to see you there!

[Palo Alto Networks Blog]

8 Practical Steps to Starting Risk Identification

Optimizing business risks associated with the use, ownership, operation, involvement, influence and adoption of IT within an enterprise is a key component in an enterprise’s ability to create value. This will allow the enterprise to reach the main objectives and it will most likely result in expansion.

Optimizing IT risks not only requires key practices of the company governance, such as the definition of risk appetite and policies, but also a continuous management process to identify, analyze, evaluate and treat IT risks covering the whole enterprise end-to-end.

However, a frequent issue is that organizations are limited in essential resources for IT risk management—for example, staff-related gaps (quantity and skills), lack of automated tools, restricted budget, incomplete inventories of IT assets and absence of historical data of loss events related with IT risks.

Although all these limitations are solvable, the solution may not come up immediately. As a result, an organization would still be exposed to unidentified IT risk scenarios that could overcome the established appetite or even the capacity to resist losses, compromising the sustainability of the company.

Therefore, the priority is to start as soon as possible by defining valid criteria to identify the IT risk scenarios and determine an optimized scope for the IT risk management process depending on the resources and capabilities available. To start the primary identification of the risk scenarios, the following eight steps are suggested:

  1. Consider internationally recognized standards and guidance, such as:
    1. COBIT 5 for Risk—provides 111 examples of IT risk scenarios
    2. MAGERIT—includes numerous threats for each type of assets/resources with their corresponding safeguards
    3. Additional documents from ISACA on topics such as big data, cloud computing, vendor management and social media
  2. Analyze business objectives of the organization to identify IT-related risks that could jeopardize its success.
  3. Collect the know-how of the experts within the organization scope (e.g., CISO, DBA and CTO) to engage them in the process of IT risk management.
  4. Assess news of vulnerabilities of the IT assets/resources adopted by the company.
  5. Apply “reverse engineering” over controls required by the ongoing regulations to infer/detect possible threats from those controls.
  6. Analyze the events of operational risk loss database to detect materialized IT risk scenarios.
  7. Once you have collected a considerable universe of scenarios, the organization´s possible scope of analysis should be formally defined. This will require a formal approval from the relevant bodies (e.g., risk committee).
  8. Approved register of IT risk scenarios should be enriched periodically, depending on: what actually happened about threats, updates of standards, new technological developments and improvement of the capacity level of the facilitators required for risk management.

Once the registry of risk scenarios is formally approved, the universe of assets/IT resources to analyze could be defined assigning priority to the most critical ones in terms of their support for the business processes. After this, the phase of IT risk analysis within the company could already be started with the most appropriate scope.

Franco Rigante, CISA, CRISC, PMP
IT – GRC Specialist
ISACA Communities Committee

[ISACA]

English
Exit mobile version