Putting the METI Cyberthreat Information Sharing Recommendation Into Action in Japan

n our May 2016 blog post, we described Japan’s new Cybersecurity Guidelines for Business Leadership Version 1.0, issued by the Japanese Ministry of Economy, Trade, and Industry (METI) and its Information-Technology Promotion Agency (IPA), and the positive progress seen in Japanese industry since the Guidelines’ release in December 2015. This follow-up blog post analyzes one of METI’s specific recommendations: that companies undertake more cyberthreat information sharing. We provide our thoughts on what more can be done to improve and enhance the cybersecurity of Japanese industry to benefit both Japan and the world.

METI puts information sharing as the Cybersecurity Guidelines’ Action Item 8, which states that leadership should “actively participate in and contribute to cyberthreat information-sharing activities” to the extent possible to minimize incidents or damage to companies’ networks. This is an essential recommendation. To dramatically shift the balance of power, close the competitive gap between the attacker and victim, and realize exponential leverage against cyber adversaries to restore trust in the digital age, we must operationalize cyberthreat information sharing. What is the current status in Japan, what are the obstacles to greater cyberthreat information sharing by companies, and how might things be improved?

Despite varied levels of success, all countries are struggling to establish effective cyberthreat information sharing frameworks in which members can exchange information about threats and incidents—such as botnet command and control servers, malware samples, malware analysis results, and indicators of compromise—in a timely manner. There are myriad reasons that might slow adoption of this practice: technical (many systems cannot adequately share at volume, and there are still a number of different sharing standards), regulatory and legal concerns, and trust issues.

Although all countries need to improve cyberthreat information sharing, Japan seems to lag behind its global peers in adopting the practice. PricewaterhouseCoopers (PwC) reported in its Global State of Information Security Survey 2016 that Japanese companies are less willing to share information about cybersecurity threats than other companies across the globe. While 30.4 percent of Japanese companies share such information, PwC reports that 64.7 percent of companies in the world do. (PwC interviewed more than 10,000 C-level executives and board members in charge of IT in 127 countries between May and June 2015 for this survey report.)

The top reason Japanese companies reported for not wanting to share threat information is that they do not have adequate information sharing frameworks (39%). Until cyberthreat information sharing programs are set up to leverage automation – which requires both technical work and strong privacy protections – such frameworks are dependent upon skilled people to actually do the work. At present, Japan lacks adequate human resources to participate more in information sharing. According to a 2015 METI study, Japanese companies lack IT and cybersecurity professionals who can judge which threat intelligence should be shared, when, and with whom, largely because Japanese companies tend to outsource cybersecurity-related work to system integrators. METI compared Japan to the United States, where large companies, such as banks, sometimes have a cybersecurity team and even an in-house cyberthreat intelligence team. According to METI’s statistics, 24.8 percent of IT professionals in Japan work in-house, whereas 75.2 percent work at IT services companies (e.g., system integrators and others providing cybersecurity to other companies). By comparison, in the United States, 71.5 percent of IT professionals work in-house, with 28.5 percent at IT services companies. Other top reasons cited in the PwC study for low participation of Japanese companies in information sharing are the lack of trust in competitors and in third parties’ information.

We believe cultural attitudes also may contribute to reluctance to participate in cyberthreat information sharing in Japan. As described by anthropologist Ruth Benedict in 1946, Japanese culture has a shame factor, where the desire to avoid “loss of face” is extremely powerful. Although many companies around the world may not wish to admit they have been the victim of a cyber incident, or reveal the fact that they were targeted, admitting so—even within a “trust”-based environment, as cyberthreat information sharing groups are meant to be—may be inordinately difficult for Japanese companies.

Additionally, volunteerism—in the sense of contributing to a community—is likely a factor in the success of information sharing among participants. A Japanese government-affiliated foundation has noted that the United States has had a long history of volunteer-based activities to complement public administration and social welfare, dating from as far back as the 17th century. Japan, on the other hand, started to develop American-style volunteerism only after the end of World War II, and Japanese volunteer activities have tended to focus on social welfare activities for their own residential communities. This history could make it challenging for the Japanese to contribute to a larger, much more distributed volunteer community for information sharing.

To help Japanese companies rapidly embark on more information sharing, it would be useful for other countries to discuss their information sharing best practices with Japan. In fact, some Japanese organizations already are modeled on U.S. approaches. For example, the United States has numerous industry-specific Information Sharing and Analysis Centers (ISACs) which are now being complemented by a broader category of Information Sharing and Analysis Organizations (ISAOs). In fact, Japan launched its first ISAC, the Telecom-ISAC, in 2002, followed by the Financials ISAC in 2014. This ISAC is modeled after the U.S. Financial Services ISAC, or FS-ISAC, arguably one of the most successful ISACs, and it is trying to learn lessons from this body. The Japanese Financial Services Agency’s guidelines for the financial sectorencourage financial institutions to share threat intelligence via relevant information sharing frameworks, including the Financials ISAC.

Like its counterpart in the United States, the Financials ISAC has multiple levels of membership for financial institutions and vendors to disseminate and access threat intelligence. Core and associate members—banks and insurance companies—can receive more sensitive threat intelligence, and they can participate in working groups on such issues as best practices, cyber exercises, global information sharing with the FS-ISAC, and incident response. This type of arrangement generates a comfortable environment in which to exchange sensitive information among trusted members belonging to the same industry.

Japan realizes it needs more ISACs. The Japanese Ministry of Internal Affairs and Communications (MIC) plans to expand and rename the Telecom-ISAC to the “ICT-ISAC” to include not only telecom companies and Internet Service Providers (ISPs), to which membership has traditionally been restricted, but also ICT companies—including security vendors—and system integrators. In addition, a new Electric Power-ISAC will also be established in Japan and work closely with both the U.S. Electricity ISAC and European Energy-ISAC.

These cross-border efforts are commendable. For one thing, they can help to raise the global bar by allowing Japanese companies to share intelligence uniquely seen in Japan to help multinational companies with a presence in the market better protect themselves from threats.

ISACs have traditionally developed in industry verticals (e.g., financial services, healthcare, energy) in which each participating company uses the information it receives to protect its own network and share threats to their specific sector. However, ISACs are not the only form of information sharing organizations in the U.S.

For example, the Cyber Threat Alliance (CTA), established in September 2014 is a group of cybersecurity companies who have chosen to work together in good faith to share threat information for the purpose of improving defenses against advanced cyber adversaries across member organizations and their customers. Palo Alto Networks is proud to be one of the four founding members of the CTA. The CTA reflects a departure from the traditional philosophy of cybersecurity companies, which are known for competing against each other based on the threat information each company has. The CTA enables security companies to act upon a common knowledge of shared cyberthreats. Unlike ISACs, the CTA is tailored to the unique capabilities of the security industry, and a requirement for every member to share previously unknown – or zero-day – threats. Consequently, the shared information is then used by the participating companies to protect their clients across all verticals (financial, health, energy, etc.).

Trust and cultural factors that might impact information sharing are important for any country to address. In fact, trust is a key ingredient to cyberthreat information sharing. It takes time to build mutual confidence and share cyberthreat intelligence among members of any information sharing framework. Personal relationships often make a big difference and can lead to institutionalizing those ties. Japanese companies are beginning to talk more frankly with each other about cybersecurity and share ideas and best practices, as we noted in our May blog, which we believe will lead to greater trust.

Thought leadership engagements are indispensable in helping reduce feelings of shame. Business executives in any country need to understand that all companies are being targeted by cyberattacks and that threat intelligence sharing is an essential ingredient to prevent the expansion of similar attacks. Being targeted is not a shame. It is simply another risk to business operations.

As with many of Japan’s cybersecurity activities, the actions toward greater cyberthreat information sharing reflect the fact that Japan’s government and industry aim to enhance cybersecurity to make the Tokyo Olympic Games 2020 successful, setting the stage for a positive legacy and national cybersecurity capability toward 2020 and beyond. But there also is the larger goal of building cyber resilience throughout the economy. We agree with the Japanese government that cyberthreat information sharing is a crucial part of that equation, as highlighted in METI’s Cybersecurity Guidelines.

This is the third in a series of blogs co-authored by Mihoko Matsubara and Danielle Kriz aimed at introducing Japan’s cybersecurity efforts and their significance to a global audience, including governments, global industry, and other thought leaders. Subsequent blogs are expected to cover Japan’s role in global cybersecurity capacity-building, the cybersecurity ramifications of planning for the Tokyo Olympic Games 2020, and other topics.

and

[Palo Alto Networks Research Center]

Cybersecurity Education—Starting Young and Making It Fun


Above are the developers of the CynjaSpace mobile app, which was created in partnership with ISACA.

To advance cyber education for children and families, CynjaTech and ISACA are partnering to create a new fully guided educational experience that teaches kids and their families about computer science, security and safety.

The collaboration combines ISACA’s industry-leading Cybersecurity Nexus (CSX)curriculum with the successful Cynja comic series inside the CynjaSpace mobile app to offer exciting interactive games and lessons that teach digital survival skills to children.

CynjaTech’s founders, Heather C. Dahl and Dr Chase Cunningham, started bringing cyberspace to life by publishing their first book, The Cynja® Volume 1, based on their professional experience in tech and cybersecurity. In the following question and answer session Dahl and Cunningham talk about their mission to educate kids on cyber safety.

ISACA Now:  Your book series The Cynja tells an action-packed story about malicious cyberattacks, which is an important topic for ISACA members. Why was it important to tell this story?
Dahl: The cyber world is filled with battles between good and evil—it’s as thrilling as any comic book—and yet it didn’t have its own superhero. So we started thinking, what would you call someone with super powers in cyberspace? What would they look like? They’d need to be smart and stealthy, wouldn’t they? And have awesome weapons? And before you could say “DDoS attack!” we had “the Cynja”—a cyber ninja!

The other thing was that the kids in our lives were reading stories about old-school bad guys like dragon slayers even as there were digital monsters invading their computers. It was time for an upgrade, one that could teach kids a really valuable life lesson as they grew into technology: There’s a whole new world of digital crime out there!

ISACA Now:  How did the writing of your book series lead to the creation of the CynjaSpace app?
Cunningham: Think of CynjaSpace as cyberspace with training wheels. The app combines the safety, controls and activity reports parents need, while allowing kids the fun and freedom of using the web and chatting with friends.

This isn’t a web search filter, a ho-hum tutorial, or even just a social network; CynjaSpace inspires kids to learn to be Internet savvy while interacting with our original comic characters and storylines. Ultimately, our Cynja characters are the role models for kids in cyberspace.

We’re very excited to partner with ISACA to bring cyberpower education for kids into CynjaSpace. By adapting the CSX content for kids and including it in our app, we can start children on a path to a smart, safe digital life.

Our mission is personal—together with ISACA, we will develop the educational lessons that we as technology and security professionals want to teach kids, parents and our own families.

ISACA Now:  As information security professionals, what can we tell other non-tech parents about the online dangers that many of us see every day?
Dahl: Parents need to help their children understand cyberspace isn’t the Magic Kingdom, it’s the Wild West—only worse. Online you rarely see the bad guys before they attack, and it’s hard to see the white hats who serve as role models. No one gets to observe others as they make choices and experience the consequences.

Being a cyber hero for children is far more than being a successful Internet entrepreneur. It’s living a smart, ethical life online. It’s treating people and data with respect.

It sounds straightforward, but here’s the problem: It’s hard for many kids to see their parents as digital role models because parents don’t open up their online lives to their kids. Our kids aren’t riding tandem as we email, shop online, surf the web, and use social media, but that’s the view of the cyber world that kids need to experience. Just like daily life, digital life is not a fairytale; it’s a place where there are real consequences.

I’m here to tell you, all adults—techies or not—are role models for children. If we are concerned about our children’s digital welfare then we must fill this void.

ISACA Now:  ISACA members know firsthand that understanding the background behind a cyber-attack is quite technical. There are multiple layers and plenty of technical terms; however, the layout of your Cynja books and the way the stories takes shape, the process is broken down into a more simplified and easy-to-understand progression. How did you translate that process to your comic series and CynjaSpace app?
Cunningham: I provided insight into what it was like to fight real battles in cyberspace—in all their glorious, geeky detail. But we then had to turn this into something a kid would relate to—and so Heather spent a lot of time with her nephew trying to see the world through a six-year old’s imagination—and what it’s like to be the hero of your own magical battles against bad guys.

We wanted to illustrate The Cynja so that readers could understand the gravity of being stuck in an infected network or encountering malicious malware. Shirow Di Rosso, our illustrator, who we call the Artmaster, was an IT engineer, so he knew exactly what this world looked like and how to visualize it in an imaginative yet accurate way.

With CynjaSpace and our ISACA partnership, we move the story and technology lessons from the book, into a fully interactive digital learning experience for kids. With ISACA’s expertise and support, we are creating the next generation of cyber education for kids and their families.

It’s important for kids to know that it’s up to people like ISACA members to protect vital computer systems. We need to encourage kids to be safe online and to learn about the technology. Incredibly, we’re facing a shortage of cybersecurity professionals that is expected to last for years. My hope is that the CynjaSpace will inspire kids to in fighting bad guys online.

[ISACA Now Blog]

Modern Endpoint Backup Sees Data Leak Before It Hurts

Picture this: You’re enjoying a beautiful summer Saturday, watching your kid on the soccer field, when your phone rings. It’s work. Bummer. “Hi, this is Ben from the InfoSec team. It appears that John Doe, whose last day is next Friday, just downloaded the entire contents of his work hard drive to an external drive. Given his role, there’s a high probability that it includes confidential and sensitive employee data.”

There goes your Saturday.

It happened to us—it’s probably happened to you
This happened to us at Code42 a few months ago. A longtime employee was coming up on his last day, and innocently wanted to take years of work with him. We’ve all probably done this—grabbed some templates and examples of our work to use in our next chapter—and instead of sorting through years worth of work, it’s just easier to copy the whole drive. Unfortunately, this is against company policy and puts the company at risk. And in this case, there were confidential and sensitive files related to company personnel.

Not all data theft is malicious, but it’s still dangerous
Of the fifty percent of departing employees that take sensitive or confidential data—most are not malicious. Some don’t know the rules; some don’t follow the rules; and most see no harm in their small actions. At Code42, we’re fortunate to have great people, and they have good intentions. But even the best intentions can have terrible consequences, especially when it comes to enterprise data security.

Too often, “innocent” data taken by employees inadvertently includes sensitive corporate data such as financial information, employee data, trade secrets or even customer information. There are risks and costs associated with leaked data; but knowing what was leaked and where it is greatly reduces the risk and damages.

Code42 CrashPlan avenges data theft—saves the weekend
Back to the sunny soccer field, where I might have spent horrible moments dreading the fallout from this particular data pilfer, I make a single phone call and spend no time worrying about the cost of tracking down or trying to recreate lost files or deal with a potential breach.

With Code42 CrashPlan, I have complete certainty that all of this employee’s endpoint data is backed up, down to the minute. And I know our InfoSec team can tell me what the data is, what was copied and where it was copied to—down to the serial number of the external drive.

Modern endpoint backup: Sees what data you have, and it knows where it goes
From there, the resolution is quick and—while it sounds dramatic—painless. A company representative contacts the departing employee, explains that we observed the content of the hard drive has been copied to a drive and requests return of the drive to Code42 on Monday morning. The employee promptly returns the drive.

And the best part of the story, I enjoyed the rest of the weekend, without the threat of data theft clouding the summer sky.

This is the power of modern endpoint backup. No matter where insider threat comes from—malicious lone wolves, employees conspiring with external actors, or well-intentioned, accidental rule-breakers—modern endpoint backup sees it all, in real time.

Download The Guide to Modern Endpoint Backup and Data Visibility to learn more about selecting a modern endpoint backup solution in a dangerous world.

Ann Fellman, Vice President/Marketing and Enterprise Product Marketing Director, Code42

[Cloud Security Alliance Blog]

Effective Third-Party Risk Assessment – A Balancing Process

The vendor risk assessment is the lynchpin of every effective third-party risk management program. In theory, the essential components of an assessment are easily determined. However, in practice, the ability to effectively understand and assess third-party controls usually conflicts with the resources available to perform the assessments, and is further handicapped by the need to rapidly conclude assessments so contracts can be finalized and projects begun.

All too often this results in assessments that are performed based on resource availability and time rather than an appropriate review of required security controls.

Adding additional complexity is the growing pressure to expand third-party assessments. Regulatory agencies have significantly increased third-party assessment requirements. The U.S. Office of the Comptroller of the Currency (OCC) now requires companies to look at the entire vendor lifecycle when managing third-party risk (OCC 2013-29). The U.S. Federal Financial Institutions Examination Council (FFIEC) recently added the requirement that companies include an assessment of their vendors’ business continuity programs as part of the assessment process (FFIEC Examination Handbook, Exhibit J). Healthcare regulators have also joined in requiring a thorough security risk analysis as part of the HITECH Act/Omnibus rules.

Industry standards are also increasing the focus on third-party security. PCI DSS 3.0 (12.8.2) and the latest versions of ISO 27001/2 require a comprehensive assessment of third-party security controls. NIST also requires that third-party information security risk be evaluated for NIST compliance (SP 800-39).
The very practical need for thorough third-party assessments is the fact that third-parties are increasingly targeted by criminals, and continue to be the primary source of breach incidents. Rather than attempt to breach the systems of large and usually well protected company networks, criminals look for the weakest link in the chain, which is all too often a third-party.

The growing demand for more comprehensive third-party assessments necessarily requires expanded resources, budgets and timelines for completion. These needs run contrary to very real budget and staff constraints, and the pace at which business units need to bring new (often web/cloud based) products and services to market. So, how do you satisfy the growing demand for more comprehensive assessments of third-party risk controls without substantially increasing the cost and time for conducting assessments?

The first step is to fully understand your assessment workflow, and identify all of your information requirements, both internal and external. Then identify those activities that are extremely manual in nature. The simple truth is that it is difficult, if not impossible, to effectively manage assessments in a manual environment. From initiating and collecting assessment information, to managing your workflow and providing a centralized repository for all assessment-related activities, there are a number of industry applications that can automate the assessment process and provide significant relief for overburdened processes and resources.

Also, make sure that you don’t reinvent the wheel. There are a number of existing assessment frameworks you can use to refine or jumpstart your program. NIST, Health Information Trust Alliance (HITRUST), and PCI all have framework controls and questionnaires.

To learn more, join us on 26 July for an ISACA webinar, titled Effective Third-Party Risk Assessment – A Balancing Process, on how to manage all of these competing requirements and develop an effective program for third-party assessments. We will discuss how to find the best methods to balance these competing demands, and key ways to enhance your assessment process so you can do more comprehensive assessments without increasing the time and cost of assessment due diligence.

Brad Keller, Senior Director of Third-Party Practice Lead, Prevalent

[ISACA Now Blog]

Mobile Payments: Risks Versus Opportunities

Have you heard the story about the foolish farmer’s new horse? The story goes that one day in early spring, a farmer’s horse dies. The farmer needs a horse to pull his plow, so he goes to market to buy a new horse. There he meets a neighbor who says, “I have a promising yearling [adolescent horse] that will be up for sale in a month or two. Why not wait? The yearling will be much stronger and healthier than some old nag you’d buy here.” The farmer agrees.

A few months go by, and on the way to bring the yearling to market, the neighbor tells the (still horseless) farmer, “I have a foal—born just this season—that will be the strongest and healthiest of all my animals. Much stronger than this yearling if you wait a few more months.”

The farmer once again agrees, and as the harvest time is coming to a close, the neighbor comes again, this time saying, “I’ve found a stallion that will surely sire the strongest line of horses this town has ever seen…” The farmer stops him and says not to bother because, “Without a horse, I could not till. Without tilling, I could not reap. Without reaping, I could not lay stores. And without laying stores, I won’t survive the winter.”

The point of this parable isn’t hard to understand. Specifically, while future opportunities are great, it does not matter if you are not handling the critical needs of today. It’s a balance between the advantages of what you might get in the future against the “opportunity cost” of taking action right now.

This is a useful principle for practitioners making risk decisions for their firms. For example, consider a new technology, new application or new business process. There’s often a temptation to focus almost exclusively on the new risks such changes might introduce. But what about the risks offset by that change? What about the business risks in failing to adopt (i.e., if we don’t adopt and our competitor does)? The holistic risk equation is more complicated than it might seem on the surface, and saying that something new is “risky” is really only accounting for one half of the equation.

Mobile Payment Opportunity Costs?
One noteworthy example of this phenomenon right now involves mobile payments. Specifically, we know that many technology professionals are extremely leery of mobile payments. ISACA’s 2015 Mobile Payment Security Study found only 23 percent of IT and security professionals believe mobile payments will keep information safe—which, let’s face it, is not exactly a vote of confidence.

It bears asking, though, how that compares to the alternative. Meaning, are there risks to mobile payment scenarios? Sure. Show me a technology without some risk and I’ll show you a technology that’s completely valueless. But even if there is risk, what is the opportunity cost? What do we miss out on by waiting for some future scenario that is even more locked down? And how does the risk of mobile payments compare, for example, to the physical and e-commerce transactions that you perform already using your physical card?

Is a mobile payment scenario riskier than, for example, handing your credit card to a waiter at a restaurant? Is it more likely to bring about fraud than using a “knuckle-buster” in a taxicab? Is it more or less likely for the card number to be stolen when making a mobile payment versus entering the card number into the web form at a merchant? In most situations—and for most frequently encountered types of fraud—the traditional payment scenario is arguably significantly less risky than the mobile one.

For example, the mechanisms used to protect a point-of-sale mobile payment (e.g., tokenization and encryption) might have some advantages; likewise, a lost/stolen mobile phone probably provides better protection of the cardholder data (where usually enhanced authentication such as a fingerprint or facial recognition is required to make a payment) compared to a scenario like a lost/stolen wallet.

Holistic Analysis
In short, accounting for mobile payments from a holistic standpoint means understanding how the mobile payments themselves work, understanding what the risks associated with that usage are, and understanding how that usage might be applicable to the enterprise.

ISACA’s new white paper, Is Mobile the Winner in Payment Security?, tries to help practitioners do this. The paper outlines mobile payments from a practitioner point of view:  going into potential risk areas, ways mobile payments can offset risks, and exploring business-enhancing value opportunities. Likewise, the document explores some possible controls that might bring about a value-add in light of mobile payments.

Ed Moyle, Director of Emerging Business and Technology, ISACA

[ISACA Now Blog]

English
Exit mobile version