Digital Forensics Professionals Encountering New Challenges

When I began performing digital forensics more than 10 years ago, things were relatively simple. At that time, the complexity of digital forensics revolved around ensuring each artifact of relevance was identified, and the proper tools to analyze them were available to leverage against computers used by the suspect.

The computer(s) of the suspect were typically the only focus. In some instances, we were also having to deal with mailbox exports of corporate users. When mobile devices came onto the scene in 2008 timeframe, our single device analysis approach to investigations was disrupted significantly. What are these things? Why don’t my hard drive forensics tools work on phones? We “forensicators” had no idea what challenges we would face in the next decade.

The significant challenges facing digital forensics experts today are the vast amounts of devices and locations that may house the valuable information. It is no longer always the case that all data sought to derive a conclusion is on a single device or in a single location. While it is now common to analyze both the computer(s) and phones used by the suspect, there now must be consideration given to other mobile devices (tablets), cloud-based email, cloud-based storage, social media activity, game consoles, IoT devices and even wearables.

Forensics tools for mobile devices were historically valued based on how many phones were supported. We are now arguably down to four phone types that you will likely encounter. Even now as the forensics tools have advanced considerably, the collection of mobile devices requires different approaches than computers. In many instances, the trusted full forensic image of the evidence is not always available – only the data the phone manufacturer will allow you to have. With the drastic reduction in the types of phones you will now encounter, the value is now in the parsers for the applications. With the millions of mobile applications available, and the frequent updates, it continues to be a challenge for the mobile phone forensic platforms to keep up with the rapid pace.

Over the past decade, users have traded in their locally stored email from their Internet service provider (ISP) for the convenience of webmail platforms such as Gmail, Yahoo Mail, or Outlook.com. When users are using webmail services, it is very unlikely that their email will be stored locally and, compared to years past, only fragments of the email are available in Internet cache files. Depending on the nature of the investigation, forensicators may be given the needed access to collect this information from the provider for analysis. When involved in internal investigations involving employees, it is very unlikely that forensicators will be given this access. In addition, even if you can obtain the webmail credentials from the device analyzed, you are not permitted to log into their personal email account. Therefore, the Internet histories and limited file fragments are all that will be available.

This same scenario now applies to personal files as users have migrated this information to cloud-based storage such as Box, Google docs and Dropbox. The same difficulties as webmail email exist.

There are few investigations that do not have a social media component, either directly or indirectly. While Internet histories may demonstrate the usage of these sites, the available information related to all activity and communications can be difficult to extract from the device alone. While the social media providers likely have extensive activity available for each user, this information would require subpoena power that you may or may not have.

Lastly, the IoT phenomenon is also significantly impacting the digital forensics field to provide types of information we have not had in the past. From Internet cameras to fitness wearables, anything electronic may now be a potential target for collection and analysis. However, IoT devices pose similar challenges to that of mobile devices in 2010. There are thousands of different types of devices and little to no standardization. With that diversity and chaos, there are challenges for the collection, parsing, and analyzing of this information. As the mobile device forensic platforms exploded and faced challenges a decade ago, I predict the same for IoT devices going forward.

The overall goal of forensic analysts is to have confidence that every artifact has been properly identified, parsed and analyzed for an accurate conclusion. We have digital artifacts that we never dreamed of years ago. With the diversity of information and numerous locations where pertinent data may now be stored, it is a challenge to be certain you have everything you need.

I suggest that forensicators be patient, yet diligent, with the data sources available. As an artifact points to a data source that is not currently available, regroup and seek that information for additional analysis.

Editor’s note: For more insights on digital forensics, visit www.isaca.org/digitalforensics, and watch a related video at https://youtu.be/ZUqzcQc_syE.

Bill Dean, Senior Manager, LBMC Security

[ISACA Now Blog]

In Era of Digital Disruption, ISACA is Ready to Rise to the Occasion

Much of what I learned about being a professional – and being part of a professional community – came through my association with ISACA.

As the first person in my family to graduate from college, I entered the workforce hungry for the educational resources, networking and professional growth opportunities to make an impact. ISACA provided that and much more, allowing me to envision and embark upon a career trajectory that otherwise would not have been possible.

My professional development was accelerated by pursuing ISACA volunteer opportunities such as helping to coordinate local conferences, which allowed me to make valuable industry contacts and build my project management skills. Eventually I became president of ISACA’s Greater Washington DC Chapter, providing another important opportunity to expand my skill set and learn more about the audit and assurance, governance, risk, and information and cyber security professions. Serving on several ISACA committees and on the board of directors provided further enrichment, both professionally and personally, as I am fortunate to have built treasured relationships with many of ISACA’s 130,000-plus members worldwide.

Now, as the newly installed chair of ISACA’s board of directors, I am grateful for the opportunity to help lead the organization that has provided me so much fulfillment. I’m privileged to work with and on behalf of our global professional community to advance the positive potential of technology in the professions that we serve and society as a whole.

ISACA is nearing its 50-year mark, and with technology-driven challenges and opportunities all around us, there is no doubt we are more relevant than ever. In addition to ongoing activities building toward our 50th anniversary in 2019, there is so much to accomplish in the year ahead. Cultivating a deeper pipeline of leaders in our professions through the Leadership Development Advisory Council, building toward greater societal impact through a revitalized foundation and ensuring ISACA’s Connecting Women Leaders in Technology program becomes even more robust and influential are among many projects for which there is promising momentum.

As we anticipate the progress ahead, I want to express my appreciation for the many contributions of our outgoing board members, as well as our outgoing board chair, Chris Dimitriadis. Chris has led with a calm and good-natured approach, steering ISACA through a period of growth and change while making sure that local chapters and all members of our community are heard and included.

I am delighted that Chris will be part of the smart, dedicated and diverse group of board members for 2017-2018 that will help shape ISACA’s vibrant future:

  • Theresa Grafenstine, CISA, CGEIT, CRISC, CPA, CISSP, CIA, CGMA, CGAP, chair
  • Rob Clyde, CISM, vice-chair
  • Brennan Baybeck, CISM, CISSP, CISA, CRISC, director
  • Zubin Chagpar, CISA, CISM, PMP, director
  • Peter Christiaans, CISA, CISM, CRISC, PMP, director
  • Hironori Goto, CISA, CISM, CGEIT, CRISC, ABCP, director
  • Mike Hughes, CISA, CRISC, CGEIT, director
  • Leonard Ong, CISA, CISM, CGEIT, CRISC, CFE, CIS, CISSP, CPP, CSSCP, ISSAP, ISSMP, PMP, director
  • R.V. Raghu, CISA, CRISC, director
  • Jo Stewart-Rattray, CISA, CISM, CGEIT, CRISC, director
  • Ted Wolff, CISA, director
  • Tichaona Zororo, CISA, CISM, CRISC, CGEIT, CIA, CRMA, director
  • Chris Dimitriadis, CISA, CISM, CRISC, ISO 20000 LA, director and past board chair
  • Robert E Stroud, CGEIT, CRISC, director and past board chair
  • Tony Hayes, CGEIT, AFCHSE, CHE, FACS, FCPA, FIIA, director and past board chair
  • Matt Loeb, CGEIT, director and CEO

While the board will work diligently on ISACA’s behalf, it will take a team effort – all of us collaborating as ONE – to achieve all that we can. We live in a world that is grappling with widespread digital disruption. ISACA can and must be a leading voice in providing a sense of assurance and security as professionals and enterprises navigate a challenging technology landscape.

I know how influential ISACA can be, as evidenced by my own journey. I am proud of what ISACA has meant for myself and so many others, but more than anything, I am energized about the future that we can build together.

Theresa Grafenstine, CISA, CGEIT, CRISC, CPA, CISSP, CIA, CGMA, CGAP, chair of ISACA’s Board of Directors and inspector general of the U.S. House of Representatives

[ISACA Now Blog]

Building Skills and Capacity in the Banking System: A Case Study From India

Indian banks have deployed IT-based solutions to cater to increasing demands in the banking industry required for a growing economy. Adoption of technology has necessitated improving IT-related skills of experienced bankers. Considering the unavailability of internal IT skills, most banks resort to outsourcing IT activities. This has resulted in over-relying on third-party vendors and slackened the pace of acquisition of skills by bank employees.

Considering these limitations, the Reserve Bank of India (RBI) – India’s central bank – appointed a ‘Committee on Capacity Building’ that has made recommendations relating to particular areas/components of function, such as recruitment, performance assessment, promotion, placement, job rotation, and skills and capacity building. The committee also has made a number of recommendations for certification of staff in specialized areas, emphasizing that banks should make certification mandatory for the following areas:

  • Treasury operations – dealers, mid-office operations
  • Risk management – credit risk, market risk, operational risk, enterprise-wide risk, information security, liquidity risk
  • Accounting – preparation of financial results, audit function
  • Credit management – credit appraisal, rating, monitoring, credit administration
  • Information and cyber security
  • Governance of enterprise IT (GEIT)

The Indian Banks’ Association (IBA), in consultation with RBI, identified 10 institutes, such as the Indian Institute of Banking and Finance (IIBF), the National Institute of Bank Management (NIBM), ISACA, and others, as certifying organizations. ISACA is identified for its certifications in audit, risk management, security and GEIT.

RBI’s directives for banks
RBI had made a compliance requirement for banks in 1999 to perform annual IS audit of IT-based systems deployed and used by banks, with the report of the audit to be submitted to RBI. The notification recognized CISA as a qualifying certification for conducting IS audits.

Another committee provided guidelines for IT governance, information security, IS audit, outsourcing management, business continuity and compliance in 2011. These guidelines recommended banks to use COBIT 5 or similar frameworks for GEIT. Recommendations for other areas include adopting global best practices, including ISO 27001.

In June 2016, RBI issued a notification for banks specifying compliance requirements for cyber security.

Considering these compliance requirements and skills and competency development requirements, banks have already taken steps to recognize ISACA certifications. Some banks provides examination and membership fees reimbursement on passing the examination.

Role of ISACA certifications in skills development of bank staff
ISACA offers certifications in governance of enterprise IT (CGEIT), risk and control (CRISC), information systems audit (CISA), information security management (CISM) and performance-based cyber security (CSXP).

Certified Information Systems Auditor (CISA)
Most banks have made this certification mandatory for IS auditors, both internal and external.

Certified in Risk and Information Systems Control (CRISC)
Most banks have a defined chief risk officer (CRO) to implement enterprise risk management (ERM); however, there is a gap in aligning them with IT risk. CRISC helps bankers in aligning IT risk with ERM.

Certified Information Security Manager (CISM)
CISM is designed for information security and cyber security professionals including CISOs, information security managers and enterprise leadership.

Certified in Governance of Enterprise IT (CGEIT)
CGEIT is designed for senior management personnel who are responsible for overall governance of IT to ensure that investments in IT realize the expected benefits. This certification is ideal for the CIO, CEO, and members of the board of directors. Considering the RBI’s expectations from banks to implement GEIT, this certification is valuable for bankers in understanding the steps to implement an IT governance framework.

CSX Practitioner (CSXP)
This performance-based cyber security certification provides technical skills for much-needed and critically important cyber security responders working in the area of threat intelligence, incident response, SOC, etc.

Current challenges and next steps
Banking professionals with these skills are needed all over India and in many other countries throughout the world. Therefore, IBA has decided to develop and launch e-learning certification courses, and certifications in other areas are being developed by different institutes.

ISACA’s CISA, CISM, CRISC and CGEIT certifications are experience-based; however, there is some level of preparation required. There are 10 ISACA chapters in India, some of which offer review courses. Many banks officers, therefore, may not have access to the review courses conducted by chapters. However, ISACA is launching online review courses for some of its certifications and has moved to global computer-based testing, which should expand accessibility for bankers interested in pursuing these important certifications.

Sunil Bakshi, CISA, CISM, CRISC, CGEIT, Consultant

[ISACA Now Blog]

Palo Alto Networks Joins the European Commission’s Digital Skills and Jobs Coalition

This month Palo Alto Networks proudly joined the European Commission’s Digital Skills and Jobs Coalition. This coalition brings together European Union (EU) member states, companies, social partners, non-profit organisations and education providers, all of whom are taking action to boost digital skills in Europe. Members of the coalition have endorsed its objectives and principles: to build strong partnerships and work together to reduce digital skills gaps in Europe, including training young people, supporting “upskilling” and retraining of the workforce in technical areas, and modernizing education. Members also can pledge to carry out initiatives to tackle the digital skills gap, an area in which Palo Alto Networks has already been active.

Within the Digital Skills and Jobs Coalition, we will address two important aspects of cybersecurity: providing students with training in technical skills and raising awareness about the importance of cybersecurity at the organizational board and C-suite levels. Both activities are essential for improving cybersecurity, preventing successful cyberattacks and maintaining trust in the digital age. With today’s threats growing in volume and sophistication, it is more critical than ever to arm colleges and universities with the latest cybersecurity curriculum to ensure our future generations have the necessary skills to prevent successful cyberattacks. At the same time, companies and other organisations need to prioritize strengthening their own cybersecurity. This is where boards of directors and the C-suite have a role. Senior executives need to understand and manage cybersecurity risks and guide their organizations – whether in the private or public sectors – to make the appropriate investments in cybersecurity.

Palo Alto Networks commitments within the Digital Skills and Jobs Coalition are encapsulated in two of our signature efforts:

1. Palo Alto Networks Academy Program: Training students with hands-on cybersecurity knowledge

The International Information System Security Certification Consortium, or (ISC)2forecasts an overall cybersecurity skills shortage of 350,000 workers in Europe by 2022. Security professionals across the public and private sectors alike agree that cybersecurity training must be considered a high priority as the sophistication and volume of successful cyberattacks increase, threatening our digital way of life. Palo Alto Networks is committed to equipping this next generation of students with the hands-on cybersecurity knowledge they will need to keep pace with the ever-changing global cyberthreat landscape and learn best practices for preventing cyberattacks. The Palo Alto Networks Academy will provide cybersecurity courseware, certifications, faculty training, instructional resources and next-generation security platform lab technology at no cost to qualified European academic institutions. We will also be actively involved in sponsoring and supporting collegiate and secondary cybersecurity competitions in Europe. The start of this project is scheduled for the third quarter of 2017.

As of June 2017, nearly 40 educational institutions in the EU were members of the Palo Alto Networks Cyber Academy Program. In the 2016–2017 school year, we are training more than 400 students in the EU. Under the Digital Skills and Jobs Coalition, we’ve pledged to train 2,000 students by the end of 2018 and add 80 new qualified European academic institutions to our Authorized Academy Program by the end of 2018.

2. Navigating the Digital Age books: Educating CEOs and boards of directors across Europe on cybersecurity as a business issue

Palo Alto Networks believes cybersecurity is a business issue, not simply an IT issue. Today’s businesses must have the knowledge base, skills and tools needed to mitigate the cyber risks inherent in our digital age. Palo Alto Networks pledges to bring cybersecurity awareness to the European C-suite, in government agencies and in the private sector, by leveraging the European editions of our book series, “Navigating the Digital Age: The Definitive Cybersecurity Guide for Directors and Officers.” These books share best practices with chapters authored by European CEOs, CISOs, lawyers and consultants, as well as current and former government officials. Additionally, the books address current cybersecurity issues that businesses must consider, including how to manage strategic cybersecurity initiatives at the boardroom level, as well as how to navigate relevant EU and country-level legislation.

We have launched three European versions to date – FranceUnited Kingdom and Benelux – all of which are available for free online. Under the Digital Skills and Jobs Coalition, we’ve pledged to distribute thousands of additional free copies of the books and hold roundtables and other events on the topics they cover. We would be pleased to join forces with governments throughout Europe to bring these messages to the C-suite in government agencies and the private sector.

Palo Alto Networks welcomes the European Commission’s emphasis on digital skills and education in the EU. As a member of the cybersecurity community, we have a deep interest in promoting and contributing to cybersecurity awareness and education throughout Europe. We are excited to join and contribute to the Digital Skills and Jobs Coalition, and look forward to working with its other stakeholders involved in digital skills development.

[Palo Alto Networks Research Center] 

Faces of ISACA: Gerard A. Joseph, CISA, CISSP, CSAM, Ph.D., Independent Consultant

Editor’s note: The ISACA Now series titled “Faces of ISACA” highlights the contributions of ISACA members to our global professional community, as well as providing a sense of their lives outside of work. Today, we spotlight Australia-based consultant Gerard A. Joseph.

Australia resident and ISACA member Gerard Joseph has traveled extensively throughout the United States, as his visits to all 50 US states would attest.

One of Joseph’s can’t-miss US destinations is wherever ISACA’s North America CACS conference is taking place.

Joseph has amassed some serious frequent flyer miles – and drawn his share of quizzical banter from fellow conference attendees – for what has become an annual tradition of trekking to North America CACS all the way from his home just outside Canberra, Australia.

“It does kick off the conversation quite nicely, and you can go from there,” Joseph said. “At the conferences, you’re not just talking commercially, but you can mix it with the personal side of things. I guess coming from Australia, it does attract attention to some extent because of the distance. It just helps to cement a nice, easygoing relationship, even if it’s just for a couple of minutes, to talk about where you’ve been and how much of the country you’ve seen.”


Australia resident Gerard Joseph, pictured attending the Alchemy & Ale social event at North America CACS last month in Las Vegas, is a regular North America CACS attendee.

Joseph became an ISACA member in 2006 when he pursued the CISA certification, and, as he learned more about the depth of offerings at North America CACS, he decided it was well worth the time and financial investment to attend. Joseph has attended North America CACS each of the past four years, including the most recent gathering last month in Las Vegas.

Joseph has many friends, business associates and even a daughter in the United States, so he tends to combine his CACS trips with other visits and sightseeing. Besides, journeying thousands of miles is a fact of life for Australians with a taste for travel.

“For Australians and for New Zealanders, really to travel anywhere you’ve got to travel a long way,” said Joseph, who has visited around 35 countries in total. “If we travel, we’re used to traveling a long distance.”

Joseph, a consultant, is a registered security assessor under a program managed by an agency of the Australian Department of Defence. As his career unfolds, he has become intrigued to learn more about trends and best practices in audit and security. That, along with what he called “absolutely enthralling” speakers, quality networking opportunities and an array of exhibitors that “just help you to keep tabs on where the industry is going” has made him a North America CACS loyalist.

Despite Joseph residing in Australia, the conference’s US location might be more of a bonus than deterrent. He has been fond of the United States since he was young – an affinity he and his wife seemingly passed on to their children, one of whom attended Massachusetts Institute of Technology and another who currently resides in Honolulu, Hawaii. Those family visits helped Joseph expand the list of US states he’d visited, and, by 2012, he realized he’d been to 41 states.

“I thought, well, this is ridiculous, I really have to see the other nine,” said Joseph, who did just that, completing his 50-state milestone with a trip to Juneau, Alaska that capped a two-week, eight-state odyssey.

Despite having seen much more of the country than most US residents ever will – for the record, he counts New York as his favorite locale due to its cultural gravitas – Joseph’s wanderlust remains intact. Visiting the remaining 10 state capitals he has yet to see remains a goal.

“Regardless of how much of any country I’ve seen, I always feel I’ve merely scratched the surface and that there is a vast amount left that I’d like to explore, and that is certainly true of the U.S.,” Joseph said.

Along with work and travel, Joseph is passionate about history, classical movies and music, ballet and genealogy. His interests and travel experience supply him plenty of potential ice-breakers with fellow conference attendees, though he might have slightly less time on his hands at North America CACS 2018, set for 30 April-2 May in Chicago, Illinois.

As if making another overseas expedition to attend North America CACS doesn’t convey enough dedication, Joseph has an eye on potentially making his debut as a conference presenter.

“Chicago will be my fifth NA CACS conference so I thought it was time to elevate my participation – and my overall profile in audit and security – by being part of the program,” Joseph said. “Of course, it depends on whether my proposal is accepted, but even if it isn’t, I’ll still enjoy the conference and the networking opportunities it presents.”

[ISACA Now Blog]

English
Exit mobile version