Don’t Put Off Till Tomorrow What You Should Start Today (Part 2)

In the first blog of this series we reviewed perceptions and current states of preparation for the EU legislative changes and how they impact your cyber security strategies, drawing on information that was collected during the registration process for a webinar run for practitioners with ISACA.

News Flash: On May 4, 2016, the European Union (EU)’s General Data Protection Regulation (GDPR) was published in the Official Journal of the EU.  The regulation will enter into force 20 days after its publication, on May 25, 2016.  Its provisions will be directly applicable in all member states two years after this date, so companies will need to comply with the GDPR as of May 25, 2018.

The GDPR will replace the 1996 Data Protection Directive.  The GDPR is a complex piece of legislation, with many different requirements, and coming into compliance with them all by the May 25, 2018 deadline will take extensive work for companies around the world that handle the personal data of EU residents. 

In this second blog, we will examine three further questions that we asked live. You should note that many listen to such sessions in the post-recording, so the sample set in the live polls was 300+, but I would suggest this still gives us a very valuable sample of perceptions.

Obviously any new legislation being implemented is done with noble intent. In these instances, the way in which we use and depend on the Internet has evolved: there is a desire to drive confidence in society as our digital world grows. It was therefore good to see that 74 percent of respondents saw the General Data Protection Regulation (GDPR) and the Network and Information Security Directive (NIS Directive) as raising the bar for cybersecurity, compared to their current capabilities. Nine percent felt that existing security regulations in their industry were already higher, which I would suggest is most likely organizations in the financial services space. But what we should consider is that the bigger the gap between where organizations are today and the needed requirements, the more time and budget will be required to achieve compliance. As such, one of the first tasks for any organization should be to complete the gap analysis to validate the scope of work ahead and, importantly, to get the right executive sponsorship behind the project.

The second poll looked at just what the gap analysis was. Nearly half (44 percent) suggested they have significant work ahead. There are both positives and negatives here. There is an indication that analysis has been done, but only 14 percent suggested they had a managed project already underway. A concerning 36 percent suggested they had no idea of the effort required or were not planning to start focusing on becoming compliant until the legislation goes live.

This highlights some very differing perceptions on legislation across the EU and different industry groups. But with harmonization being a key driver for the EU, I would anticipate that, in years to come, the diversity of answers would reduce.

As a security leader, it is critical to ensure that the decision to achieve compliance should be made collaboratively, which means engaging the legal team, business leaders and the cybersecurity team to make an informed decision on what the right next steps are for the business to take. It’s easy to simply state that this is a “must”, but for each business there must be a review in terms of gap analysis, costs of compliance, ownership and investment strategy. For some, the timescales and investment required may already be too constrictive.

The final poll validated as much, with only 35 percent of respondents confident in their company’s ability to adhere to the 2018 deadline. Thirty-six percent already considered the timescales to be tight, and 14 percent suggested they didn’t expect to make the go-live date. Of note was the 15 percent that are still waiting on timelines to be finalized, to which I would suggest that these are now sufficiently well-defined. We should not be waiting to act, but for many legislation can be a complex quagmire. That is why organizations must engage with their legal teams and ensure they either get educated or remain informed about these legislations and how they impact cyber strategies.

Hopefully the insight from your peers gives you confidence that you are in line with others on your journey in adhering to the upcoming requirements. If you are not, may that insight help you gain the business support you need to validate the importance of catching up with your peers.

So what next? I would suggest you consider the following key steps in your action plan:

1. If you haven’t already, start preparing now!

2. Stay informed. Palo Alto Networks will continue to provide you with updates on what this means for you and your cyber strategies on our microsite:http://go.paloaltonetworks.com/regulation.

3. Assign executive ownership.

4. Complete a gap assessment: Can you qualify your risk today and do you have the relevant regard for ”State of the Art”?
– Work with your auditor/advisors to have a clearly defined risk assessment.

5. Ensure you have legal and privacy guidance (internal/eternal) to validate that you have the right understanding of the legislation for your business.

6. Define a plan to get adopt and maintain relevant regard for “State of the Art”.

7. Make a clear plan on how you will deal with incidents, as they will happen.

8. Ensure you have a made conscious decisions on how you balance your investments, between prevention and detection (“State of the Art”) and responsive capabilities.

[Palo Alto Networks Research Center]

Certified Cloud Security Professional (CCSP) – Vietnamese Walk of Fame

 

6

Last Updated: 10-JAN-2022

All statistics are based upon personal verification. Please use it at your own risk for reference only. Total number may be different from public list of (ISC)² since it includes active, inactive, and suspended & also certification holders who are both local & overseas Vietnamese. If you are a Vietnamese (local & overseas) CCSP and your name is not in this list, or you claim for wrong information, pls help to contact me. Thank you so much.

• For (ISC)² Certification Verification, pls take reference from here: https://webportal.isc2.org/custom/CertificationVerification.aspx
• For (ISC)² Member Counts, pls take reference from here: https://www.isc2.org/member-counts.aspx

 

IDName & ContactDate of Certificate
PHILIP HUNG CAO – PHILIP HÙNG CAO
Cyber & Zero Trust Evangelist
contact info
MAY-2016
366342NGUYEN TRUNG LUAN – NGUYỄN TRUNG LUẬN
Current: Business Director at Mi2 (Hanoi, Vietnam)
contact info
593068LEO DANG XUAN TRUONG – ĐẶNG XUÂN TRƯỜNG
Current: Cloud Security Architect – Prudential Group Information Security (Singapore)
contact info
MAR-2018
PETER NGO
Current: Product Line Manager, Certifications at Palo Alto Networks (Irvine, California, USA)
contact info
09-DEC-2020
DANG HUY THUAN – ĐẶNG HUY THUẬN
Current: IT Risk & Compliance Officer at MBBank (Hanoi, Vietnam)
contact info
08-JAN-2021
654994TRI NGUYEN – NGUYỄN TRÍ
Current: Senior Security Engineer at Carousell Group (Saigon, Vietnam)
contact info
05-JAN-2022
©2016-2022 Philip Hung Cao. All rights reserved. Please specify source when you copy or quote information from this website (Xin vui lòng trích dẫn nguồn khi bạn sao chép hay sử dụng lại thông tin từ website)

Navigating the Cybersecurity Threat Landscape

With every day that passes it seems that cybersecurity becomes a bigger and bigger issue for businesses and citizens. General and specialized media are flooded with stories on threats and attacks. On top of that, countless niche cybersecurity vendors out there are fighting to communicate how their products can solve most cybersecurity problems. It all contributes to a collective fragmentation of views on what cybersecurity actually is, creating a fog of information.

In the meantime, executives, security managers and specialists are looking to cut through this fog to find proper and holistic navigation tools. A disciplined information security approach suggests adopting the established views for guiding maps, such as ISO 27001, the Federal Information Security Management Act (FISMA), PCI Data Security Standard (PCI DSS), and new ones, such as the US Cybersecurity Framework. Unfortunately, they are not sufficient to provide enough relevant knowledge for establishing cyberresilient organizations, data centers and information systems.

What is missing in all of this are the connections between actual attack techniques, vulnerabilities, threat actors and further detailed analysis of the domain.

So how to fill this gap properly?
I wish I could say that my beloved Center for Internet Security’s (CIS) Critical Security Controls (CSC) is the right answer. Unfortunately, while it is a useful instrument, it does not provide sufficient guidance.

Recently the European Union Agency for Network and Information Security (ENISA) published its Threat Landscape 2015 (ETL 2015), and I was pleased with what I found in it for cybersecurity strategists and practitioners. For the last two years I have referred people to ETL, also Verizon’s Data Breach Investigation Report (DBIR) and CIS CSC, because they all offer relevant, independent sources for strategic, operational and tactical guidance for cybersecurity.

What is so special about these reports? Here are my thoughts on the recently published ETL; hopefully they will inspire you to read the reports if you have not already.

  1. ETL 2015 (and 2014) provide measurement of the landscape of cybersecurity, connecting strategic and tactical views;
  2. ETL 2015 offers mitigation vectors (controls) for the Top 15 threats. For example, CIS CSC provides aggregated mitigation vectors for all threats in prioritized and increased sophistication levels. Such CSC aggregation is good for overall enterprise vision, however it dilutes details of a particular threat, which are relevant to motivate and prove that a threat can be handled adequately;
  3. Cybersecurity vendors publish quarterly and annual reports on threat analysis; however they have internal conflicts—covering only information that is relevant to vendor product portfolio. ETL 2015 mitigates this conflict nicely by providing links to relevant deeper vendor analysis for particular top threats. I find it so elegant and a valuable resolution!
  4. ETL 2015 provides a separate visual Top 15 threats poster – allowing it to be used as an instrument for discussion on how this information is relevant for a particular environment;
  5. I have been involved previously in a few threat classification efforts. I am happy to see that ETL 2015 has issued their Threat Taxonomy in a mindmap, and also in an elaborated Excel format (after opening Excel, for it to be readable, hide the document comments). It can be a great tool to validate your views and see if any gaps remain in your cybersecurity defense architecture. It also allows you to link to an IT infrastructure resilience theme.

DBIR gathers cybercrime facts, even while it is not clear to what extent European law enforcement agencies can legally analyze cases and share anonymized data. DBIR provides great analysis on what should be changed to improve resilience to cybercrime, and it maps practical guidance to CIS CSC. I hope that future ETLs will connect to CIS CSC as well, and to COBIT and ISACA’spublications.

At the end of the day, most organizations have to work through the fog of hysteria on cybersecurity to choose their own strategy for cyberresilience. I hope that these resources will be valuable anchors for you and your organization to evaluate and choose your own way.

Benetis will present Cybersecurity Skills Audit at EuroCACS 2016 30 May – 1 June in Dublin.

Dr. Vilius Benetis, CISA, CRISC, CEO, NRD

[ISACA Now Blog]

How to Reduce Costs and Security Threats Using Two Amazon Tools

Have you ever gone to see a movie that would have been amazing if not for one person? The plot was engaging, the dialogue was well-written, and there were strong performances from most of the cast. But there was just that one actor who simply didn’t live up to the rest of the film, and it made every scene he was in that much worse? Simply put, that actor was bad, and brought down the whole operation.

That idea of the “bad actor” can be applied to Internet clients, as well. Fortunately, you’re not hurting any feelings by sussing them out: the bad actors are usually automated processes that can harm your systems. The two most common forms are content scrapers, which dig into your content for their own profit, and bad bots, who will misrepresent who they are to get around any restrictions stopping them.

We’d all like to believe that everyone accessing content will use it appropriately. Unfortunately, we can’t always assume the best, and being proactive in dealing with these bad actors will reduce security threats to your infrastructure and apps.

Even better, blocking bad actors will also lower your operating costs. When these bots access your content, you’re serving the traffic to them, whether you want to or not. That adds more to your overall costs. By blocking them, you’re restricting traffic from a number of undesired sources. Luckily, AWS has a pair of tools you can combine to say goodbye to these bad actors: Amazon CloudFront with an AWS web application firewall (WAF).

With AWS WAF, you can define a set of rules known as a web access control list (web ACL). Every single rule contains a set of conditions, plus an action. Any request that’s received by CloudFront gets handed over to AWS WAF for further inspection; if the request matches, the user can access the content as attempted. If the request doesn’t match the conditions in a specified rule, the default action of the web ACL is taken. These conditions will remove quite a bit of unwanted traffic, as you can set filters by source IP address, strings of text, and a whole lot more. As for the web ACL actions, you can count the request for later analysis, allow it, or block it.

Perhaps the best attribute of the WAF is that you can smoothly integrate it within your existing DevOps, and automate workflows to react. Since bad actors are always switching their methods to mask their actions, your proactive detection methods must constantly change, as well. Having those automations in place is immensely helpful in finding bad actors and restricting their access.

There’s a great walkthrough of how to set up this solution on the AWS Security Blog, step-by-step. Feel free to check it out for more information, or get in touch with us if you have any additional questions. And for AWS customers that need even more than what the AWS WAF has to offer, there are services that are complimentary to the AWS WAF that provide enhanced protection for business critical applications on AWS. You won’t even need to thank the Academy when all of those bad actors are removed.

David Lucky, Director of Product Management, Datapipe

[Cloud Security Alliance Blog]

Palo Alto Networks Joins Forces with the White House and Industry Partners to Support Veterans and their Families

Last Thursday I had the distinct honor to attend a special White House event celebrating the 5th anniversary of Joining Forces, an initiative that First Lady Michelle Obama and Dr. Jill Biden launched in 2011 in order to support service members, veterans, and their families through wellness, education, and employment opportunities.  Joining Forces works closely with both the public and private sectors to ensure that service members, veterans and their families have the tools they need to succeed throughout their lives.

The primary objectives of Joining Forces include:

  • Bringing attention to the unique experiences and strengths of America’s service members, veterans and their families.
  • Inspiring, educating, and sparking action from all sectors of society —citizens, communities, businesses, nonprofits faith-based institutions, philanthropic organizations, and government — to ensure service members, veterans and their families have the opportunities, resources and support they have earned.
  • Showcasing the skills, experience and dedication of America’s service members, veterans and their families to strengthen our nation’s communities.
  • Creating greater connections between the American public and the military.

You can find more information about this important and effective initiative here:https://www.whitehouse.gov/joiningforces.

I attended the event as a representative of Palo Alto Networks along with Chuck Konrad, who is our Director of Recruiting, Sales and Engineering at Palo Alto Networks and leads our veteran-focused initiatives.

This event was indeed special for one very important reason. During the ceremony in the White House State Dining Room, First Lady Michelle Obama and Dr. Jill Biden announced a new private sector hiring and training initiative where more than 40 companies have committed to hiring 110,000 veterans and military spouses. In addition, 15 companies and organizations have also committed to lead training programs, sponsor scholarships and support certification courses for nearly 60,000 veterans and military spouses over the next five years, primarily in the fields of aerospace, telecommunications and technology.  You can read the First Lady’s remarks from the event here:  https://www.whitehouse.gov/the-press-office/2016/05/05/remarks-first-lady-joining-forces-fifth-anniversary-employment-event.

As a retired Major General in the U.S. Army with more than 35 years of service, let me tell you that you’re going to want to read the First Lady’s remarks at the website above.  I was deeply moved during Michelle Obama’s remarks, and I can tell you that she spoke from her heart and showed her deep commitment to this effort. Dr. Biden, a proud Blue Star mom, emphasized the importance of supporting our veterans when they return home and how hiring veterans and military spouses is good for both companies and the morale of our military.  It does this old Soldier’s heart good to see such deep respect and support for the welfare, educational and employment opportunities of our current and former military and their families coming from the top, and the First Lady and Dr. Biden set the example magnificently!  I was truly humbled by their leadership.

As a strong supporter of this program, we’re doing our part. Along with our Education Services Team and our Veterans Programs team, we conducted a pilot training program for veterans in February 2016, where we trained 16 veterans in a one-week course for our ACE Accreditation. We’re proud to report that each veteran that took the final accreditation exam passed it, which helped prove to us that the program was successful and scalable.

As a result, we’ve committed to Joining Forces to train 400 veterans and transitioning service members over the next five years through the Palo Alto Networks Academy program. After completion of the coursework and successfully passing the accreditation exam, candidates will receive their Palo Alto Networks ACE (Accredited Configuration Engineer) Accreditation and career guidance on entering the cybersecurity workforce.  More information can be found at: www.paloaltonetworks.com/veterans.

[Palo Alto Networks Research Center]

English
Exit mobile version