Two Steps to a Robust Security Culture

By Kwinton Scarbrough, CISSP

In the midst of the business and technology merge, organizations of all industries have started their journey into the cognitive era of cybersecurity. In this era, it is essential for a business to have an IT security strategy to govern how the organization will protect itself from internal and external cyber threats. However, what commonly fails to align to IT security strategy is the organization’s overall security culture. IT security strategy can only be effective if there is a strong security culture embedded into the very fabric of the company’s operations. Today, I will cover the two core components for building a robust security culture, to maximize the effectiveness of the IT security strategy.

An organization’s security culture is comprised of the mindset and habits of employees, as it relates to IT security. Habits that are intended to prevent and protect against internal and external threats are, unfortunately, not always unified for the greater good of the organization. Many times, different siloed habits are formed within individual business units based on the easiest route to achieve the task at hand (e.g.: using shared accounts, instead of unique individual accounts or using privileged accounts to perform simplistic tasks). Within an organization that lacks a mature IT security strategy, employees are more likely to naturally learn and follow what is perceived to be the path of least resistance to accomplish a task. They then continue to pass these learned, non-compliant, methods on to other employees within that business unit. Eventually, it becomes the mindset of that business unit as the only way to accomplish that task because – as I’m sure you’ve heard before – “ that’s the way we’ve always done it.” Building a strong security culture will encourage employees to question the norm if something doesn’t seem quite right.

Every organization is unique and will have its own security culture. Throughout my consulting experience I’ve come to find the state of the security culture depends on two factors: (1) well defined security policies, processes and procedures; and (2) exceptional communication about the adoption of those security policies, processes and procedures. To have a strong security culture, these two factors must be coordinated and implemented together as one has little to no lasting effect without the other.

Define a Security Policy

A security culture begins with a well-defined and properly enforced security policy. The development and enforcement of a security policy starts at the very top of the leadership pyramid and reflects down to the junior level employee. In defining a security policy, the first step is to understand the business environment and its threat landscape. An organization’s security policy should

  • Define the baseline security requirements
  • Define the requirements that meet or exceed the industry and regulations requirements
  • Align to the risk appetite of the organization

While a well-defined security policy should be clear and strictly enforced, it should not, however, dictate how each business unit must operate to comply with the requirements. Meaning the policy should be separate from the procedures. While the security requirements should be clearly defined, a strong security culture will allow for each individual business unit to determine an optimal method for incorporating these requirements into their own business operations. The ideal security policy should be seamlessly integrated into employee day-to-day thinking and decision making to ensure a secure mode of operations for all business units. The security culture should unify the organization by allowing all business units to work together, while operating in loosely-coupled coordination to provide an optimal level of protection against internal and external threats. For an organization as a whole, the goal is to create centralized policies that can be incorporated into the daily process and procedures for all business units within an organization. An organization with a strong security culture has employees that understand cybersecurity and the importance of making the necessary operation adjustments to comply with defined security requirements.

Communicate and Train Secure Habits

The communication of security requirements and security awareness go hand and hand in building a strong security culture. More communication brings more awareness and with more security awareness, individual employees are more likely to incorporate security into their day-to-day thinking and decision making. As a result, security becomes thoroughly embedded into the mindset and work habits of each employee therefore creating a strong security culture.

However, communicating the security requirement is not as straightforward as defining the security policy. To effectively communicate security policies, the communication tactics should be tailored to the target audience based on analyzed behavior, their current security understanding and preferred communication style. The goal is to effectively communicate, to each business unit, why it is necessary to follow the organization’s security policies. Better communication of the purpose and reasoning for security policies, will help to build a strong security culture through the elimination of decentralized execution of centralized policies. To take security maturity one step further, organization should also provide security awareness training. This training should serve the purpose of eliminating nonconformist habits, by bringing awareness and competence to better, more secure habits.

Conclusion

Clearly defined and communicated centralized security policies will allow an organization to enforce organization-wide security requirements. Each business unit will understand the importance of security, while having the freedom to create and establish optimal operations within well-defined boundaries.

[(ISC)² Blog]

Data Breach Preparation and Response in Accordance With GDPR

Many may be familiar with guidelines on personal data breach notification from Article 29 Working Party (WP29) prepared in October 2017 under Regulation 2016/679. In addition, the General Data Protection Regulation (GDPR) introduces the requirement for a personal data breach (henceforth “breach”) to be notified to the competent national supervisory authority.

The basic concept of personal data breaches was not introduced first by the GDPR, and there are also some EU Member States that already have their own national breach notification obligation. This may include the obligation to provide notification of breaches involving categories of controllers in addition to providers of publicly available electronic communication services (for example in Germany and Italy), or an obligation to report all breaches involving personal data (such as in the Netherlands).

GDPR contains several provisions relating to personal data breaches that data controllers (and processors) must also be aware of. Additional information can be found in ISACA’s Implementing the General Data Protection Regulation publication; however, I’ve outlined some key highlights on breaches below.

So first, what is a personal data breach?
The GDPR defines a “personal data breach” in Article 4(12) as: “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.”

What type of personal data breaches exist?

  • Confidentiality breach
  • Availability breach
  • Integrity breach

It is also apparent from above that the concept of personal data breaches is closely linked to the principle of the integrity and confidentiality of personal data (Article 5 (1) (f) of the GDPR). Therefore, a wide variety of personal data breaches may occur, such as losing a laptop or USB drive that contains personal data, attacking an IT system, or even sending a letter or an email to wrong recipient.

Four years earlier, WP29, in its Opinion issued in 2014 (Opinion No. 03/2014), presented a number of practical examples of what is considered to be a personal data breach and the consequences it may have.

Why is it so important that the personal data breach is handled as soon as possible?
The Preamble to the GDPR (Point 85) states that “a personal data breach may, if not addressed in an appropriate and timely manner, result in physical, material or non-material damage to natural persons,” such as:

  • Loss of control over their personal data or limitation of their rights
  • Discrimination
  • Identity theft or fraud
  • Financial loss

What should you do if a personal data breach occurs?
The data controller has several tasks when a personal data breach is noticed:

  1. The controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the competent supervisory authority.
  2. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.
  3. The controller shall document any personal data breaches.
  4. The processor shall notify the controller without undue delay after becoming aware of a personal data breach.

When does the personal data breach not need to be reported to the authority and when do the persons concerned not have to be notified directly?
If the data controller can demonstrate, in accordance with the principle of accountability, that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons, the notification may be omitted. (For example, if mail sent by a controller to a wrong address is returned without being opened, meaning that no personal data has been accessed by an unauthorized person.

How can controllers prepare for handling personal data breaches?
Given that personal data breaches can occur at any data controller, and in such cases data controllers need to react quickly, it is important for controllers to be prepared in this respect as well.

First, every actor must prepare a data breach response plan, for which there may be internal rules as well. A data breach response plan enables an entity to respond quickly to a data breach. By responding quickly, an entity can substantially decrease the impact of a breach on affected individuals, reduce the costs associated with dealing with a breach, and reduce the potential reputational damage that can result.

Below is a data breach response plan quick checklist to help with this preparation:

Information to be included Yes/No Comments
What a data breach is and how staff can identify one    
Clear escalation procedures and reporting lines for suspected data breaches    
Members of the data breach response team, including roles, reporting lines and responsibilities    
Details of any external expertise that should be engaged in particular circumstances    
How the plan will apply to various types of data breaches and varying risk profiles with consideration of possible remedial actions    
An approach for conducting assessments    
Processes that outline when and how individuals are notified    
Circumstances in which law enforcement, regulators (such as the OAIC), or other entities may need to be contacted    
Processes for responding to incidents that involve another entity    
A record-keeping policy to ensure that breaches are documented    
Requirements under agreements with third parties such as insurance policies or service agreements    
A strategy identifying and addressing any weaknesses in data handling that contributed to the breach    
Regular reviewing and testing of the plan    
A system for a post-breach review and assessment of the data breach response and the effectiveness of the data breach response plan    


Recommendations on next steps:

An effective data breach response generally follows a four-step process — contain, assess, notify and review:

  1. Contain the data breach to prevent any further compromise of personal information.
  2. Assess the data breach by gathering the facts and evaluating the risks, including potential harm to affected individuals and, where possible, take action to remediate any risk of harm.
  3. Notify individuals and the Commissioner if required. If the breach is an “eligible data breach” under the NDB scheme, it may be mandatory for the entity to notify.
  4. Review the incident and consider what actions can be taken to prevent future breaches.

How does the Hungarian DPA prepare to perform its duties in relation to personal data breaches?
Based on available information from the Hungarian DPA, there is a separate department within the Hungarian DPA’s organization that addresses receiving and managing the personal data breach notifications. It is also expected that data breach notification must be made on the authority’s website, or there will be an online interface which the notifications can be sent to the authority.

Editor’s noteISACA’s Implementing the General Data Protection Regulation publication is an educational resource for privacy and other interested professionals; it is not legal or professional advice. Consult a qualified attorney on any specific legal question, problem or other matter. ISACA assumes no responsibility for the information contained in this publication and disclaims all liability with respect to the publication. 2018 © ISACA. All rights reserved. For additional ISACA resources on GDPR, visit www.isaca.org/GDPR.

Laszlo Dellei, MBA,CISA, CGEIT, CRISC, C|CISO

[ISACA Now Blog]

Cloud Security: Embracing Change Requires a Mindset Shift

When meeting with organizations across EMEA, I often hear them cite concerns about putting security in the cloud. However, in the following discussions, they typically admit that doing just that is inevitable. There’s a mindset change here that needs to be embraced on all sides of the cybersecurity equation.

I’ve worked previously with companies operating on the mantra that change is the only constant, yet cybersecurity experts often perceive change as a loss of control that they have to regain. This is perhaps why 70 percent of cybersecurity professionals across Europe and the Middle East say a rush to the cloud is not taking full account of the security risks, according to a recent survey conducted by Palo Alto Networks[1].

At the same time, there is increasing pressure from regulation, such as GDPR, to be mindful of what data (specifically PII) is put into the cloud. Unlike databases or other IT systems, the concern is typically around how PII data can be accidentally captured by security tools being used.

With all this in mind, it’s not surprising that the initial idea of moving cybersecurity to the cloud makes many security leaders anxious, just as IT leaders felt when it came to moving their applications.

 

The Benefits of Agility

Perhaps the biggest cybersecurity challenge today relates to our ability to normalise and process the increasing volume of artefacts we gather through security tools and turn them into intelligence we can act on in a timely manner to prevent business impact. With many businesses now processing millions of artefacts per month, the key challenge is the time required to achieve this. How much is your business processing today, and what are the growth predictions for the next three years? The cloud effectively gives unlimited compute power with no big Capex investments, so the same rationale for moving applications and data to the cloud surely applies to cybersecurity. Indeed, our research highlighted that 75 percent of cybersecurity professionals agree embracing the cloud could be a method of enhancing cybersecurity capabilities in their organizations.

 

Inevitability

As more applications and data move to the cloud, the cybersecurity tools that gather all these artefacts are themselves having to move to the cloud. This must be natively integrated to detect the artefacts and understand the environment in order to effectivity secure it. However, the natural tendency of cybersecurity professionals is to haul this data back into their own organizations for analysis.

 

Human Emotions

It is a typical human emotional response to want to keep precious things close at hand, and information that pertains to potential breaches is precious. However, if you look at traditional endpoint security, most security point products today share information about attacks against you with the security provider via the cloud, with the aim being to better detect and understand attack trends. Other organizations have already gone much further and send their security logs to managed security service providers to analyse and act upon.

Taking this into account, why are some cybersecurity teams more open to sharing than others? And what’s different between sharing in this way and storing artefacts or indicators in a private cloud?

In certain circles, data classification means that “no information leaves the building; where data is confidential or top secret”, yet for most, that’s not the limiting factor. All too often, regulation may be the justification, but it may not actually be the case. Security vendors and partners don’t want your PII, so they work hard to filter it out and give you control over what is shared. Likewise, regulations such as GDPR recognise the value of cybersecurity tools when it comes to helping protect PII, and this should allow for a little more leniency should personal data mistakenly get caught up in the process.[2]

 

Trust

Not so long ago, people would bury treasures or hide their money under the bed, yet today, such prized items would typically be kept in a bank. This is because we recognize and trust that banks can better protect valuables, and there is incremental value – in terms of interest – in putting them there.  Did you known Monzo bank was launched in April 2017 in the UK as one of the first cloud based banks utilised through an app.  Banks are shifting to the cloud!

Now, consider cybersecurity. Security professionals apply it themselves as they trust in their own capabilities. This is absolutely valid, yet cloud services typically have more budget and resource to protect security data, and – most importantly – have the incremental value of agility, in terms of elastic compute power, to process it. The matter at hand therefore becomes how each business builds trust in storing its security data in the cloud. I would suggest that this starts with transparency and control: where and what is gathered, how it is stored and used, who has access to it and why. More and more cloud security services are sharing this information to ensure you can have trust in their capabilities.  Likewise, there is also a growth in 3rd party tools that provide governance of your cloud services based on this growing need.  Palo Alto Networks has recently acquired Evident.IO[3]

 

You Can’t Stop It, Even If You Want To

Not so long ago, many held the same concerns for any use of the cloud, yet cloud-first strategies are commonplace today. I believe the same applies for cybersecurity, as most companies are now leveraging the cloud to enable or apply some level of their cybersecurity capabilities. However, at some point, each security professional will go through his or her own mindset shift, where concerns about the risk of putting security information in the cloud will be overtaken by the value of leveraging the elastic compute power to apply the latest smart AI algorithms against security artefacts, or by the growing need for security to be natively applied in the cloud to protect the business processes that have moved there.

The important things, at this point, are knowing when that mindset shift will occur in your business, and being clear and confident on what you and your business require to embrace it. Typically, business leaders are pushing IT teams to transform faster, which can potentially lead to bigger lag with cybersecurity teams. What’s clear is that business isn’t going to wait, so the longer it takes to make that mindset shift, the more catching up there will be to do.

 

[1] https://www.paloaltonetworks.com/company/press/2018/cloud-research

[2] The processing of personal data by public authorities, computer emergency response teams, computer security incident response teams, providers of electronic communications networks and services, and providers of security technologies and services – to the extent strictly necessary and proportionate to ensure network and information security – constitutes a legitimate interest of the data controller concerned. This could include, for example, preventing unauthorised access to electronic communications networks and malicious code distribution as well as stopping “denial of service” attacks and damage to computer and electronic communication systems.

[3] https://evident.io

[Palo Alto Networks Research Center]

English
Exit mobile version