Navigating the Cybersecurity Threat Landscape

With every day that passes it seems that cybersecurity becomes a bigger and bigger issue for businesses and citizens. General and specialized media are flooded with stories on threats and attacks. On top of that, countless niche cybersecurity vendors out there are fighting to communicate how their products can solve most cybersecurity problems. It all contributes to a collective fragmentation of views on what cybersecurity actually is, creating a fog of information.

In the meantime, executives, security managers and specialists are looking to cut through this fog to find proper and holistic navigation tools. A disciplined information security approach suggests adopting the established views for guiding maps, such as ISO 27001, the Federal Information Security Management Act (FISMA), PCI Data Security Standard (PCI DSS), and new ones, such as the US Cybersecurity Framework. Unfortunately, they are not sufficient to provide enough relevant knowledge for establishing cyberresilient organizations, data centers and information systems.

What is missing in all of this are the connections between actual attack techniques, vulnerabilities, threat actors and further detailed analysis of the domain.

So how to fill this gap properly?
I wish I could say that my beloved Center for Internet Security’s (CIS) Critical Security Controls (CSC) is the right answer. Unfortunately, while it is a useful instrument, it does not provide sufficient guidance.

Recently the European Union Agency for Network and Information Security (ENISA) published its Threat Landscape 2015 (ETL 2015), and I was pleased with what I found in it for cybersecurity strategists and practitioners. For the last two years I have referred people to ETL, also Verizon’s Data Breach Investigation Report (DBIR) and CIS CSC, because they all offer relevant, independent sources for strategic, operational and tactical guidance for cybersecurity.

What is so special about these reports? Here are my thoughts on the recently published ETL; hopefully they will inspire you to read the reports if you have not already.

  1. ETL 2015 (and 2014) provide measurement of the landscape of cybersecurity, connecting strategic and tactical views;
  2. ETL 2015 offers mitigation vectors (controls) for the Top 15 threats. For example, CIS CSC provides aggregated mitigation vectors for all threats in prioritized and increased sophistication levels. Such CSC aggregation is good for overall enterprise vision, however it dilutes details of a particular threat, which are relevant to motivate and prove that a threat can be handled adequately;
  3. Cybersecurity vendors publish quarterly and annual reports on threat analysis; however they have internal conflicts—covering only information that is relevant to vendor product portfolio. ETL 2015 mitigates this conflict nicely by providing links to relevant deeper vendor analysis for particular top threats. I find it so elegant and a valuable resolution!
  4. ETL 2015 provides a separate visual Top 15 threats poster – allowing it to be used as an instrument for discussion on how this information is relevant for a particular environment;
  5. I have been involved previously in a few threat classification efforts. I am happy to see that ETL 2015 has issued their Threat Taxonomy in a mindmap, and also in an elaborated Excel format (after opening Excel, for it to be readable, hide the document comments). It can be a great tool to validate your views and see if any gaps remain in your cybersecurity defense architecture. It also allows you to link to an IT infrastructure resilience theme.

DBIR gathers cybercrime facts, even while it is not clear to what extent European law enforcement agencies can legally analyze cases and share anonymized data. DBIR provides great analysis on what should be changed to improve resilience to cybercrime, and it maps practical guidance to CIS CSC. I hope that future ETLs will connect to CIS CSC as well, and to COBIT and ISACA’spublications.

At the end of the day, most organizations have to work through the fog of hysteria on cybersecurity to choose their own strategy for cyberresilience. I hope that these resources will be valuable anchors for you and your organization to evaluate and choose your own way.

Benetis will present Cybersecurity Skills Audit at EuroCACS 2016 30 May – 1 June in Dublin.

Dr. Vilius Benetis, CISA, CRISC, CEO, NRD

[ISACA Now Blog]

How to Reduce Costs and Security Threats Using Two Amazon Tools

Have you ever gone to see a movie that would have been amazing if not for one person? The plot was engaging, the dialogue was well-written, and there were strong performances from most of the cast. But there was just that one actor who simply didn’t live up to the rest of the film, and it made every scene he was in that much worse? Simply put, that actor was bad, and brought down the whole operation.

That idea of the “bad actor” can be applied to Internet clients, as well. Fortunately, you’re not hurting any feelings by sussing them out: the bad actors are usually automated processes that can harm your systems. The two most common forms are content scrapers, which dig into your content for their own profit, and bad bots, who will misrepresent who they are to get around any restrictions stopping them.

We’d all like to believe that everyone accessing content will use it appropriately. Unfortunately, we can’t always assume the best, and being proactive in dealing with these bad actors will reduce security threats to your infrastructure and apps.

Even better, blocking bad actors will also lower your operating costs. When these bots access your content, you’re serving the traffic to them, whether you want to or not. That adds more to your overall costs. By blocking them, you’re restricting traffic from a number of undesired sources. Luckily, AWS has a pair of tools you can combine to say goodbye to these bad actors: Amazon CloudFront with an AWS web application firewall (WAF).

With AWS WAF, you can define a set of rules known as a web access control list (web ACL). Every single rule contains a set of conditions, plus an action. Any request that’s received by CloudFront gets handed over to AWS WAF for further inspection; if the request matches, the user can access the content as attempted. If the request doesn’t match the conditions in a specified rule, the default action of the web ACL is taken. These conditions will remove quite a bit of unwanted traffic, as you can set filters by source IP address, strings of text, and a whole lot more. As for the web ACL actions, you can count the request for later analysis, allow it, or block it.

Perhaps the best attribute of the WAF is that you can smoothly integrate it within your existing DevOps, and automate workflows to react. Since bad actors are always switching their methods to mask their actions, your proactive detection methods must constantly change, as well. Having those automations in place is immensely helpful in finding bad actors and restricting their access.

There’s a great walkthrough of how to set up this solution on the AWS Security Blog, step-by-step. Feel free to check it out for more information, or get in touch with us if you have any additional questions. And for AWS customers that need even more than what the AWS WAF has to offer, there are services that are complimentary to the AWS WAF that provide enhanced protection for business critical applications on AWS. You won’t even need to thank the Academy when all of those bad actors are removed.

David Lucky, Director of Product Management, Datapipe

[Cloud Security Alliance Blog]

Palo Alto Networks Joins Forces with the White House and Industry Partners to Support Veterans and their Families

Last Thursday I had the distinct honor to attend a special White House event celebrating the 5th anniversary of Joining Forces, an initiative that First Lady Michelle Obama and Dr. Jill Biden launched in 2011 in order to support service members, veterans, and their families through wellness, education, and employment opportunities.  Joining Forces works closely with both the public and private sectors to ensure that service members, veterans and their families have the tools they need to succeed throughout their lives.

The primary objectives of Joining Forces include:

  • Bringing attention to the unique experiences and strengths of America’s service members, veterans and their families.
  • Inspiring, educating, and sparking action from all sectors of society —citizens, communities, businesses, nonprofits faith-based institutions, philanthropic organizations, and government — to ensure service members, veterans and their families have the opportunities, resources and support they have earned.
  • Showcasing the skills, experience and dedication of America’s service members, veterans and their families to strengthen our nation’s communities.
  • Creating greater connections between the American public and the military.

You can find more information about this important and effective initiative here:https://www.whitehouse.gov/joiningforces.

I attended the event as a representative of Palo Alto Networks along with Chuck Konrad, who is our Director of Recruiting, Sales and Engineering at Palo Alto Networks and leads our veteran-focused initiatives.

This event was indeed special for one very important reason. During the ceremony in the White House State Dining Room, First Lady Michelle Obama and Dr. Jill Biden announced a new private sector hiring and training initiative where more than 40 companies have committed to hiring 110,000 veterans and military spouses. In addition, 15 companies and organizations have also committed to lead training programs, sponsor scholarships and support certification courses for nearly 60,000 veterans and military spouses over the next five years, primarily in the fields of aerospace, telecommunications and technology.  You can read the First Lady’s remarks from the event here:  https://www.whitehouse.gov/the-press-office/2016/05/05/remarks-first-lady-joining-forces-fifth-anniversary-employment-event.

As a retired Major General in the U.S. Army with more than 35 years of service, let me tell you that you’re going to want to read the First Lady’s remarks at the website above.  I was deeply moved during Michelle Obama’s remarks, and I can tell you that she spoke from her heart and showed her deep commitment to this effort. Dr. Biden, a proud Blue Star mom, emphasized the importance of supporting our veterans when they return home and how hiring veterans and military spouses is good for both companies and the morale of our military.  It does this old Soldier’s heart good to see such deep respect and support for the welfare, educational and employment opportunities of our current and former military and their families coming from the top, and the First Lady and Dr. Biden set the example magnificently!  I was truly humbled by their leadership.

As a strong supporter of this program, we’re doing our part. Along with our Education Services Team and our Veterans Programs team, we conducted a pilot training program for veterans in February 2016, where we trained 16 veterans in a one-week course for our ACE Accreditation. We’re proud to report that each veteran that took the final accreditation exam passed it, which helped prove to us that the program was successful and scalable.

As a result, we’ve committed to Joining Forces to train 400 veterans and transitioning service members over the next five years through the Palo Alto Networks Academy program. After completion of the coursework and successfully passing the accreditation exam, candidates will receive their Palo Alto Networks ACE (Accredited Configuration Engineer) Accreditation and career guidance on entering the cybersecurity workforce.  More information can be found at: www.paloaltonetworks.com/veterans.

[Palo Alto Networks Research Center]

English
Exit mobile version