In Cybersecurity, Professional Practice Transcends Politics

As Europe absorbs the news that the United Kingdom (UK) has voted to leave the European Union (EU), questions inevitably rise around the impact this decision will have on our profession. During the campaign running up to the vote, I fielded several queries from journalists on the relevance of pending European regulation, and whether the UK would undermine its ability to face cyber threat if voters chose to leave.

In or out, I believed, our professional challenges would be unaffected by the result. Earlier this month, as the referendum debates headed into the final weeks, these thoughts were reinforced as London played host to Infosecurity Europe, our region’s largest information security event. This year, the show attracted nearly 14,000 delegates from 80 different countries.

On the (ISC)2 stand, we heard from (ISC)2 members and other delegates alike that it seemed particularly vibrant this year, with many of the largest stands on the exhibition floor having been the start-ups featured in the innovators section not so long ago. The sessions reflected very current concerns that were being debated around the world. The many sessions that were focussed on European issues were very well attended, including one on the last day presented by the president of our (ISC)2 Germany Chapter Rainer Rehm.

Now that the referendum results are in, I believe the Brexit vote will serve to highlight our profession’s value as that vibrant international community. Our challenges and (therefore) inherent instincts have motivated levels of co-operation that already transcend national boundaries and politics. There is no reason to believe that this will come to an end, or even be significantly interrupted by the UK’s political decision to leave the European Union.

Practicing professionals in the UK and across Europe have at least two years ahead of them to understand the practicalities that will affect their day-to-day job. Also, there’s a good chance that quite a lot of what was anticipated over this time will not change. The need in the UK to comply with the EU’s General Data Protection Regulation (GDPR), for example, will remain the same, as we can expect UK businesses to continue handling EU citizen data. The march of technical innovation will continue to shape the challenges we face on the front lines. Indeed, we all understand that threats and attacks are international. We as a community have evolved to become incredibly influential in raising the profile of key developments and risks, the shaping of standards, and organizing events and forums that bring this community together at national, regional and international levels.

Looking again to Infosecurity Europe, we have observed that this show has become an important forum for our members to meet. We know of nearly 1,000 who made themselves known at registration and anticipate there were many, many more.

Day two referred to as ‘Member Day’ by the (ISC)2 EMEA team played host to a meeting of chapter leaders and our EMEA Advisory Council members, who had travelled from Switzerland, Algeria, Kuwait, France, Croatia, Germany and various corners of the UK. The discussions covered our members’ readiness to manage GDPR, gaps in the existing security discussion around IoT and proposals to enhance our ability to share experience across our region’s network of 32 chapters. Our member reception later that day featured an interactive Town Hall discussion with about 200 attendees where our CEO David Shearer discussed new tools, programmes and benefits to help our global membership develop their skills, elevate the discussions we have with business, and serve as ambassadors to society.

Information security is appreciated as an international concern. The way we behave and the work we do as a profession already ensures that the standards and practices required to face these concerns account for differences in markets and regulatory expectations. I’m confident that, as a community, information security professionals right across Europe will continue to work together.

–Dr. Adrian Davis, CISSP, managing director, EMEA, (ISC)²

[(ISC)² Blog]

Do ISACA Certifications Benefit Employers, Professionals?

ISACA’s website states that “membership sets you apart from other IT professionals by signifying that you are:

  1. Dedicated to best practices and successful results
  2. Committed to professional growth and advancement
  3. Helping to advance your profession
  4. A seeker of professional knowledge and a problem solver
  5. Serious about continuing education
  6. Connected with a highly regarded organization
  7. Part of a global network of peers”I wanted to see if this was true in the UK.

My reason is that CISA and CISM are widely known—more so than ISACA itself. Many organizations know COBIT and many additional firms use the framework but may not know it comes from ISACA. CGEIT and CRISC are not quite as well known, in comparison, but as a professional organization we have an opportunity to promote these as a substantial solution to better manage cyber-security threats, which have finally hit the board agenda.

ISACA certifications provide a virtuous circle. By getting the governance framework right, it is easier to identify the risks to implement solutions, many based on security controls, and provide value-added assurance from executives and auditors.

The ISACA London Chapter works with Hays, a recruiting firm, to connect professionals and employers. Their UK IT job websiteshows CISA, CISM and ITIL are ‘must haves.’

This means ISACA reason #3 is true, but do employers recognize the rest?

I asked Hays staff what they thought. They see the expectation for IT audit and security employees at all levels to possess relevant certification. The weighting of certifications depends on several factors:

  • Internal audit divisions expect CISA or CISM of their IT auditors to ensure teams have sufficient IT-related knowledge to hold useful conversations with auditees.
  • More stress is placed on certifications if the team is lean, but…
  • … less if the role is senior management, where others skills and experiences come into play.
  • The certifications requested often reflect those held by the hiring manager.
  • CRISC is becoming important for second line of defense roles, but…
  • …CSX is not as well known yet since it is early days

It also seems that, in the UK, salaries are related to the role, not the certification. Certifications provide opportunities to obtain roles rather than salary increases. A variation on this is that a strong candidate for a junior role, without certification, may be encouraged to study for one through company sponsorship in lieu of a lower salary. A lapsed certification counts for nothing and is seen as not being committed to the industry. It is worse than not having had it.

An interesting UK trend is an increasing demand for focused, technical knowledge mixed with interpersonal and business knowledge. A range of certifications help here, as IT auditors grapple with complex security controls, for example, or go beyond efficiency in ‘value-for-money’ reviews, such as safety, quality and relevance. In banking, this trend happens at a junior level because the regulatory environment demands assurance and compliance. Outside that industry, a mix of management, professional and business skills happens at a more senior level.

COBIT is well-loved but sometimes treated as a teddy bear—there when you need it and tragic if lost. Thus, the explicit need to show COBIT qualifications is rarely part of the job spec. But it turns out that COBIT is the de facto standard, so deeply entrenched in corporate assurance that there is no need to shout about it. That means experienced IT auditors are expected to be well-versed in COBIT.

Globally, recognition and employer demand for globally recognized certifications seems greater than in the UK. This may be cultural or due to regulatory requirements. In some cases, if opportunities to gain relevant experience are limited, certification is proof of knowledge not obtainable elsewhere.
All well and good, but this is a recruiter’s view. I wanted the employer’s view, which I found at a CISO meeting in London. They said that having no certifications would not automatically exclude a candidate. The choice of certification, and how many, came down to the individual, their aspirations and complementary skillsets.

Slightly contradictory was the expectation that staff with four years’ experience have certifications. They expected less experienced staff not to have them – no time or experience to obtain them – but expected junior staff to study for certifications. More senior roles required broader and/or deeper skillsets. For management, MBAs and professional management programs can help broaden skillsets. The issue was those remaining in technical roles – what professional qualifications were there outside a master’s or doctorate? There seemed to be a gap in the ‘professional training’ market for experienced staff.

The CISOs said the increasing integration between IT and non-IT activity has narrowed so most IT professionals need to understand business and develop interpersonal and communication skills. Knowing how the business runs—being able to have conversations between IT and non-IT—help get IT right.

It comes down to keeping up to date with trends. Employers look for knowledgeable, experienced professionals who keep abreast of daily organizational IT changes and challenges. Continuing professional education, which is demanded of certification holders, provides comfort to employers. Their staff not only stays up to date, but also have many resources to apply within the organization. ISACA membership benefits support this. We should take full advantage of them.

Editor’s note:  As part of ISACA’s celebration of Women in Technology Month this June ISACA is seeking women in tech to guest blog on the subject of their choice. If you are interested in learning more, please contact news@isaca.org.

Sue Milton, Managing Director, SSM Governance Associates, and Past President, ISACA London Chapter

[ISACA Now Blog]

Tracking Elirks Variants in Japan: Similarities to Previous Attacks

A recent, well-publicized attack on a Japanese business involved two malware families, PlugX and Elirks, that were found during the investigation. PlugX has been used in a number of attacks since first being discovered in 2012, and we have published several articles related to its use, including an analysis of an attack campaign targeting Japanese companies.

Elirks, less widely known than PlugX, is a basic backdoor Trojan, first discovered in 2010, that is primarily used to steal information from compromised systems. We mostly observe attacks using Elirks occurring in East Asia. One of the unique features of the malware is that it retrieves its C2 address by accessing a pre-determined microblog service or SNS. Attackers create accounts on those services and post encoded IP addresses or the domain names of real C2 servers in advance of distributing the backdoor. We have seen multiple Elirks variants using Japanese blog services for the last couple of years. Figure 1 shows embedded URL in an Elirks sample found in early 2016.

Figure 1 Embedded URLs in Elirks variant

In another sample found in 2014, an attacker used a Japanese blog service. The relevant account still exists at the time of writing this article (Figure 2).

Figure 2 Blog account created by the attacker in 2014

Link to previous attack campaign

Unit 42 previously identified an Elirks variant during our analysis of the attack campaign calledScarlet Mimic. It is years-long campaign targeting minority rights activists and governments. The malware primarily used in this series of attacks was FakeM. Our researchers described the threat sharing infrastructure with Elirks in the report.

As of this writing, we can note similarities between previously seen Elirks attacks and this recent case in Japan.

Spear Phishing Email with PDF attachment

Figure 3 shows an email which was sent to a ministry of Taiwan in May 2012.

Figure 3 Spear Phishing Email sent to a ministry of Taiwan

The email characteristics were bit similar to the recent case (Table 1).

2012 2016
Email Sender Masquerades as an existing bank in Taiwan Masquerade as an existing aviation company in Japan
Email Recipient Representative email address of a ministry of Taiwan, which is publicly available. Representative email address of a subsidiary company, which is publicly available.
Subject “Bank credit card statement” in Chinese “Airline E-Ticket” in Japanese
Attachment PDF file named “Electronic Billing1015” in Chinese File named “E-TKT” in Japanese with PDF icon

Table 1 Email characteristics

When a user opened the attached PDF file, the following message is displayed. It exploits a vulnerability in Adobe Flash, CVE-2012-0611 embedded in the PDF and installs Elirks malware on the system.

Figure 4 opening malicious PDF attachment

Airline E-Ticket

Attackers choose a suitable file name to lure targeted individual or organization. In the recent case, the malicious attachment name in the email was reported as “E-TKT”. We found similar file name in the previous attack in Taiwan in August 2012 (Figure 5).

Figure 5 Elirks executable file masquerade as folder of E-Ticket

When opening the file, Elirks executes itself on the computer and creates ticket.doc to deceive users (Figure 6).

Figure 6 doc file created by Elirks

We’ve also seen another file name related to aviation at Taiwan in March 2012. Figure 7 shows PDF file named “Airline Reservation Numbers (updated version).pdf”. When opening the PDF file, it displays the exactly same message with the Figure4, exploits CVE-2011-0611 and installs Elirks.

Figure 7 PDF named “Airline Reservation Number”

Conclusion

Currently, we have found no reliable evidence to indicate the same adversary attacked a company in Japan in 2016 and multiple organizations in Taiwan in 2012. However, we can see some resemblances between the two attacks. In both cases, attackers used the same malware family, crafted spear phishing emails in a similar manner, and seem to be interested in some areas related to aviation. We have been seeing multiple Elirks variants targeting Japan in the last few years, potentially indicating an ongoing cyber espionage campaign. We will keep an eye on the threat actors.

Palo Alto Networks customers are protected from Elirks variant and can gather additional information using the following tools:

  • WildFire detects all known Elirks samples as malicious
  • All known C2s are classified as malicious in PAN-DB
  • AutoFocus tags have been created: Elirks

Indicators:

Executable File:

8587e3a0312a6c4374989cbcca48dc54ddcd3fbd54b48833afda991a6a2dfdea

0e317e0fee4eb6c6e81b2a41029a9573d34cebeabab6d661709115c64526bf95

f18ddcacfe4a98fb3dd9eaffd0feee5385ffc7f81deac100fdbbabf64233dc68

Delivery PDF:

755138308bbaa9fcb9c60f0b089032ed4fa1cece830a954ad574bd0c2fe1f104

200a4708afe812989451f5947aed2f30b8e9b8e609a91533984ffa55d02e60a2

[Palo Alto Networks Research Center]

Be Part of the World’s Largest Information Security Workforce Survey

By Patrick Craven, director, Center for Cyber Safety and Education

As the new director for the Center for Cyber Safety and Education, I’m proud to announce that we’re launching the latest edition of the (ISC)² global information workforce survey. The biennial survey provides an in-depth look at the current state of the cybersecurity workforce – examining trends in pay, training, hiring, budgets and more. The latest edition is now open for responses until September 30, 2016. I’m asking for about 20 minutes of your time to offer your personal insights for the survey, which dives into various issues facing the workforce.

Conducted since 2004, the survey is known for providing the most comprehensive snapshot of the unique position of the information security workforce worldwide. Your responses to the survey will be compiled and released early next year as the 2017 Global Information Security Workforce Study (GISWS). The GISWS is conducted by Frost & Sullivan, a global analyst firm, and is distributed to members of (ISC)², as well as other cybersecurity professionals. Referenced by governments, employers, professionals, and industry stakeholders, the GISWS has been a respected global benchmark for 12 years. In 2015, the United Kingdom’s Cabinet Office referenced the results in their review of the national cybersecurity spending commitments and in a speech delivered by the country’s Chancellor of the Exchequer.

I also want to share that we listened to the respondents from the last survey and reduced the time commitment to participate in this important research. Two years ago, nearly 14,000 (ISC)² members and nonmembers around the world participated in the nearly hour-long survey. The time commitment has been reduced to only 20 minutes for this year’s survey. We ask for your help to sustain the historically high response rate that distinguishes this vital research.

Key findings from the 2015 survey included the continuation of the security workforce shortage, as 62 percent of respondents indicated that their organizations have too few security professionals. This number was up from 56 percent in 2013, and the reasons appear to be less about money (as more organizations are making the room in their budget to hire), but rather an insufficient pool of suitable candidates.

As the field of cybersecurity grows due to the ever-expanding nature of the Internet of Things (IoT), cloud-based services and mobile devices, the demands on the information security workforce will continue to build. Training and educating existing staff is a priority for organizations worldwide, but the talent pipeline also needs to be addressed as the workforce ages.

Don’t miss your chance to be a part of the largest information security workforce survey worldwide. If you’re an (ISC)² member, you will receive an email from Frost and Sullivan with a unique link, created just for you, that will look something like this: {thepowerofhybrid.frost.com/……}. Alternatively, you may go directly to http://www.isc2cares.org to access the general survey link.

I know that your time is valuable, and I appreciate your attention to this relevant industry research. I look forward to sharing the global results of the study in February. Thank you in advance for your participation!

[(ISC)² Blog]

Using Risk Scenarios for COBIT 5 to Help Achieve Business Success

If I had a £1 for every time a client said “it won’t happen to us,” I would be a very rich man and probably would not be writing this blog!

Risk management is about minimizing the chance that it will happen to us, by anticipating what might occur to affect the successful delivery of an enterprises’ business goals or objectives and to implement an appropriate risk response to minimize the risk of an adverse business impact materializing.

This is how risk management is usually seen. However, a good risk management process can also be used to help achieve the successful delivery of a business goal or objective.

In life, we all make mistakes, but the important thing is to learn from the experience. Even better is to learn from the mistakes of others. The use of risk scenarios in an enterprise’s risk management process helps us do just that.

Building a library of risk scenarios will help an enterprise foresee potential risk and select suitable risk responses to reduce the impact to within its risk appetite and risk tolerance. The ISACA publications COBIT 5, COBIT 5 for Risk, and Risk Scenarios for COBIT 5 for Risk provide some very helpful tools to the risk practitioner.

COBIT 5 defines two risk-related process enablers:  EDM03, a governance process, and APO12, a management process.

COBIT 5 for Risk Expands on Process Enablers
A key tool in the risk management process is the use of risk scenarios. COBIT 5 for Risk, which expands upon EDM03 and APO12 process enablers, also has a small section providing some generic risk scenarios. However, the risk professional should arm themselves with Risk Scenarios Using COBIT 5 for a comprehensive library of risk scenarios.

Risk Scenarios Using COBIT 5
But what is a risk scenario? A risk scenario is a description of a possible event that, if it occurs, will have an uncertain impact on the enterprise. The core of a risk management process requires risk to be identified and assessed and a suitable risk response to be implemented. Well-developed risk scenarios support these activities and make them realistic and relevant to the enterprise.


Source: ISACA, COBIT 5 for Risk, USA, 2013

Scenarios Inform on Suitable Risk Response
The risk scenario then provides some guidance on a suitable risk response. When a risk assessment identifies that risk is not within the risk appetite and tolerance of the enterprise, then one of four risk responses is required:

  • Avoid:  Stop doing that activity.
  • Mitigate:  Implement mitigation actions to reduce the inherent risk.
  • Share/Transfer:  Transfer the risk, such as the use of insurance.
  • Accept:  Do nothing and live with the risk.

If the selected risk response is mitigate, then the risk scenario gives some pointers to the COBIT 5 process enablers that could be implemented to appropriately manage the risk.

Risk Mitigation in an Elevator
One final thought:  even risk professionals get it wrong. Risk Scenarios for COBIT 5 for Risk was developed by a group of nine risk professionals from around the world. Just imagine that these nine arrive at ISACA headquarters 08.00 one Sunday morning and all step into the same elevator to go up the 10th floor. There is no one else expected in the building until 07.00 the following morning.

These nine highly experienced risk professionals failed to effectively assess the risk of all getting into the same elevator, and, yes, you’ve guessed it—the elevator jammed just past the 2nd floor. Fortunately, after only few minutes (which seemed a lot longer) of panic, they were able to pry open the doors and the lift so everyone was able to easily step out. But like all good risk professionals, they then learned from their experience and broke into two groups and took two separate lifts to continue their journey to the 10th floor.

How do I know? I was one of the nine! If only we had had a book of risk scenarios we could have consulted.

As part of your member benefits, Risk Scenarios Using COBIT 5 for Risk is available as a no cost pdf download.

Editor’s Note:  Risk Scenarios Using COBIT 5 for Risk is the ISACA Bookstore’s June Book of the Month. Click here to download.

Mike Hughes, CISA, CGEIT, CRISC, ISACA Central UK Immediate Past President, Principal Director, HWgrc

[ISACA Now Blog]

English
Exit mobile version