UK’s “National Cyber Security Strategy”: Contributing to Increasing Cybersecurity and Prosperity in the UK and Worldwide

The UK government recently released its new National Cyber Security Strategy 2016-2021. Recognizing that cyberattacks on the UK are a top threat to the UK’s economic and national security, the strategy outlines a vision and goals to create a UK that is secure and resilient to cyberthreats, as well as prosperous and confident in the digital world. The UK has always been at the forefront of cybersecurity activities, and its new strategy is an important contribution to and model for global efforts.

The strategy lays out a substantive set of goals, actions and metrics mapped to three important pillars:

  • Defend: The government will strengthen its own IT defenses and work with industry to ensure UK networks, data and systems are protected against evolving cyberthreats.
  • Deter: The UK will strengthen law enforcement’s capabilities to increase the cost of cybercrime.
  • Develop: The government will help to develop the UK’s critical capabilities, including cyber skills, as well as the country’s growing cybersecurity industry, to keep pace with cyberthreats.

The strategy includes an impressive set of plans, based extensively on working with the private sector.  While all parts of the strategy are laudable, highlighted below are a number of its forward-looking approaches that will surely contribute to greater cybersecurity in the UK.

First, the strategy immediately puts into action its stated goal of partnering with industry. For example, as part of his strategy, the UK has created a new National Cyber Security Center (NCSC), which is a single, central government body bringing together many of the government’s cybersecurity functions, including CERT-UK. The NCSC will be the UK’s authoritative voice on cybersecurity and aims to build effective cybersecurity partnerships between government, industry and the public. The NCSC’s commitment to direct industry engagement will help to deliver many elements of the strategy. The NCSC will manage national cyber incidents, provide expertise and deliver tailored support and advice to government and industry.

Second, the strategy aims to prevent and reduce the impact of cyberattacks on the UK, reflected in a new “Active Cyber Defence” program. Described in a blog by Ian Levy, technical director of the NCSC, this effort aims to make a significant proportion of UK networks more robust through automated prevention, ensuring UK citizens are protected by default from the majority of large-scale commodity cyberattacks. For example, the government plans to provide automated protections to citizens accessing online government services and states that, where possible, “similar technologies should be offered to the private sector and the citizen.” Using automation to prevent successful cyberattacks is wise, given that attackers themselves deploy sophisticated, automated attacks. Responding with manual defenses just won’t scale: we won’t keep up and, in fact, will continue to fall behind. The UK’s prevention-focused calculus will change the dynamic that currently favors attackers, tilting the balance to help the UK government, businesses and individuals better protect their networks. The strategy envisions the development and deployment of automated cyber defense in partnership with industry.

Third, the strategy strongly endorses cyberthreat information sharing. In fact, one of the NCSC’s initial emphases will be on facilitating such sharing, including ensuring UK government organizations have easy access to cyberthreat information and improving government-industry sharing. The goal is to “ensure that citizens, businesses, public and private sector organizations and institutions have access to the right information to defend themselves.” Sharing threat intelligence on advanced cyberattacks, cybercriminal motivations, and the tactics of malicious actors is essential to defend networks and prevent successful attacks. The UK also plans to move toward automated cyberthreat information sharing to allow organizations to act swiftly on relevant information, an important measure that will support the aforementioned automated prevention goal.

Fourth, the strategy focuses heavily on helping industry to raise its cyber resilience. The government plans to work with critical national infrastructure (CNI) but also will expand outreach to many more firms: the “UK’s most successful” companies, companies that hold a large amount of data, high threat targets, digital service providers, insurers, and others. While the exact risks to these companies may differ, they all require cybersecurity for competitiveness and efficiency. Although the government plans to continue its practice of helping via investing in innovation and encouraging industry’s voluntary action, the strategy acknowledges a role for regulation, noting that the UK plans to use the forthcoming General Data Protection Regulation (GDPR) to drive standards of cybersecurity across the economy.

Fifth, augmenting the cyber resilience goals above, the strategy stresses that whether in industry or government, cybersecurity now needs to be viewed as a C-level or board-level concern, not simply an IT issue. The strategy notes responsibility for cybersecurity in the private sector lies with boards, owners and operators, while security of UK public sector organizations lies with Ministers, Permanent Secretaries and Management Boards. Palo Alto Networks agrees on the need for senior leadership involvement, and we are helping educate corporate directors and board members worldwide on these responsibilities through our recent book, Navigating the Digital Age. The UK version, including chapters by almost a dozen UK thought leaders, is slated for launch in early 2017. It is critical for modern corporations to have the capacity not just to understand the opportunities but also to understand and mitigate the risks inherent in our digital age, and we are pleased to contribute to that discussion in the UK.

Finally, the strategy stresses that the UK will work internationally. We wholeheartedly support this approach by all governments. Neither the global digital infrastructure nor the threats attacking it know national boundaries. We are only as strong as the weakest link. We appreciate that the UK will continue to play a strong role in global cybersecurity capacity building and use its influence in multilateral organizations, such as the European Union (EU), NATO and the G20.

These are only some of the many important activities in the UK’s new strategy, which also details plans to tackle cybercrime, develop cybersecurity skills across the population, and support a thriving UK cybersecurity sector. The UK’s National Cyber Security Strategy 2016-2021 sets out how the UK will become one of the most secure places in the world to do business in cyberspace. This framing is important. Cybersecurity must be viewed as an enabler, and the UK’s strategy, while acknowledging the growing threats, focuses on the benefits to the UK of better cyber resilience. As the sixth largest economy in the world, strong cybersecurity in the UK has multiplier effects around the globe. Palo Alto Networks looks forward to working with the UK government and private sector to realize the goals of its 2016-2021 Cyber Security Strategy and improve the UK’s – and hence the world’s – cybersecurity.

[Palo Alto Networks Research Center]

Cloud Security: Who’s Responsible for What?

The typical journey to the cloud is based on a partnership between the cloud vendor and an enterprise or business, so the next logical question becomes: who is responsible for what, when it comes to securing cloud applications and the very important data within?

Solely relying on the cloud provider for security is not a viable approach. Rather, cloud security is a shared responsibility between the provider and the tenant that should be meticulously defined and understood by both parties. Only then can they work together to prevent successful cyberbreaches.

Responsibility Breakdown

There are two ways to think about this responsibility divide. The cloud provider is typically responsible for security “of” the cloud, meaning the cloud infrastructure, typically including security at the storage, compute and network service layers. The enterprise assumes responsibility for security “in” the cloud. This includes applications, data, and services that operate within their managed cloud environment.  However, depending on the cloud infrastructure – private, public or SaaS – responsibility varies between the cloud vendor and organization:

Private – In private clouds, enterprises are responsible for all aspects of security for the cloud because it is hosted within their own data centers. This includes the physical network, infrastructure, hypervisor, virtual network, operating systems, firewalls, service configuration, identity and access management, etc. The enterprise also owns the data and the security of the data.

Public – In public clouds, like AWS or Microsoft Azure, the cloud vendor owns the infrastructure, physical network and hypervisor. The enterprise owns the workloads, apps, virtual network, access to their tenant environment/account, and the data.

SaaS – SaaS vendors are primarily responsible for the security of their platform, which includes physical security, infrastructure and application security. These vendors do not own the customer data nor assume responsibility for how customers use the applications. As such, the enterprise is responsible for security that would prevent and minimize the risk of malicious data exfiltration, accidental exposure or malware insertion.

While responsibility for securing data, apps and infrastructure falls more into the hands of the cloud vendor as businesses transition from private cloud to public cloud or SaaS, it’s important to note that ensuring the security of its own data is always the responsibility of the enterprise.

Security Measures – Vendor & Enterprise

Because of security and privacy concerns with moving data to the cloud, many cloud and SaaS vendors have focused on ensuring the security of the organization’s infrastructure and data. SaaS vendors invest significantly in building a strong defense for their own infrastructure, and they sometimes extend this security to the customer data with basic policy controls. However, these are typically not sufficient and organizations are forced to look for a more complete SaaS security solution.

The security gaps not addressed by SaaS vendors include: preventing data exposure through improper sharing and preventing threat insertion and distribution. It is here that the SaaS vendors’ responsibility ends and the IT team’s responsibility begins: to employ effective security measures to fill these security gaps and protect the organization’s data.

To compensate for what cloud vendors do not secure, an organization must have the right tools in place to effectively manage and secure risks to keep data secure. These tools must provide visibility into activity within the SaaS application, detailed analytics on usage to prevent data risk and compliance violations, context-aware policy controls to drive enforcement and quarantine if a violation occurs, real-time threat intelligence on known threats, and the ability to detect unknown threats to prevent new malware insertion points. For additional information, learn more about Aperture or check out the “Safely Enable Your SaaS Applications” tech brief.

[Palo Alto Networks Research Center]

Tech Docs: Traps 3.4.2 Documentation Now Available

Technical Documentation for the recent Traps 3.4.2 release is now available!

  • Read about the latest in Traps advanced endpoint protection on the Technical Documentation site. Highlight: You can now install Traps on Windows Server 2016 Standard (Server with Desktop Experience) with this release.

  • Download the software from the Support portal by selecting Software Updates and then filtering by one of the Endpoint categories.

Happy reading!

Your friendly Technical Documentation team

Have a question? Email us at: documentation@paloaltonetworks.com

[Palo Alto Networks Research Center]

Three Ways to Make Information Security a Habit During Project Management

With eyeballs rolling, they mumble, “Why do security people insist on stopping our projects?”

As information security (IS) professionals, we have seen this response from project managers (PM), developers, and fill-in-your-favorite-role here, when we have derailed a project due to an unplanned InfoSec issue.

What is an InfoSec Professional to Do?
Police chiefs don’t lock our car doors, nor do CISOs read application teams’ code. Because InfoSec is a lifestyle, not an event, we need a security culture. It takes a village. After reading this post you will have three tips for infusing security habits into a village of project managers.

1. Make it easy. According to BJ Fogg, Ph.D., founder of Persuasive Tech Lab at Stanford University, we are basically lazy. Want to make IS easy (or at least easier) for non-InfoSec professionals? Think like Jeopardy!’s Alex Trebek and get the participants to “ask the question.”

Start with your written InfoSec policies and standards. Summarize one or two into a question and work with your Project Management Office (PMO) to include the questions in a new project checklist to provide guidance.

Examples:

  • Building a mobile app? Refer to “Vulnerability Scan Standard.”;
  • Outsourcing or working with third parties? Refer to “Outsourcing and Third Party Policy.”

2. Make it simple. Did you know that InfoSec training and experiences may yield Continuing Education Units (CEU) for certified project managers? For example, certified Project Management Professionals (PMP®s) may be eligible to earn CEUs if the InfoSec training meets the Project Management Institute’s criteria. Risk management is a knowledge and skills area for the institute, and PMPs need to recertify every three years. If you help PMP®s make that connection, it may mean reduced training costs and time, enhanced careers, and stronger InfoSec advocates; all factors in creating habits and a culture of village security.

3. Make it rewarding. Have a “Village Citizen of the Year” recognize her. Does a PM role model a good InfoSec practice? Take five minutes to recognize the specific behavior (example – uses PMO “New Project” checklist to identify new mobile apps that require vulnerability scans). Fogg identifies “pleasure” (think: positive recognition email to boss) as a core motivator for changing behaviors.

What Next? Start Small. It is as Easy as 1…2…3

  1. Ask your PMO or individual PMs if a Jeopardy! approach would reduce project derailments and make InfoSec adoption easier. Then start with one question for the most frequently overlooked InfoSec standard or policy.
  2. Have an upcoming InfoSec event or activity where InfoSec learning may occur? Include in your invite:  “Did you know that some InfoSec training may serve as CEU for certified or wannabe-certified project managers? Click PMI certifications to learn more.”
  3. Add a five-minute invite to your calendar to “Recognize PM once a month.” Example: To: Boss, cc: PM; “Just wanted to recognize PM for role modeling fill-in-the-blank InfoSec practice or attitude! Our organization, teams, and customers are better because of it. Great job, PM!”

Sources: BJ Fogg, Ph.D.; PMI

Luanne Spiros, CISM, PMP

[ISACA Now Blog]

English
Exit mobile version