How much should the U.S. government be involved in securing midmarket enterprises? It was one of several hot topics during this week’s “Accelerating America’s Middle Market” conference in Washington DC, hosted by The Wall Street Journal.
Scott Stevens, Palo Alto Networks VP, Technology and Worldwide Systems Engineering, was part of a panel titled “Can Cybersecurity Be Fixed?” alongside Michael Daniel, Special Assistant to the President and Cybersecurity Coordinator at the White House. Among discussions over private-public sector collaboration in cybersecurity and how midmarket companies should prioritize cyber investments, Scott was pressed on how those organizations should re-architect security to meet the challenge of today’s sophisticated cyber threats.
“We all got comfortable, but what we we have been doing is no longer working,” said Scott, describing how a poorly automated, point product approach to securing networks and endpoints has stymied our collective efforts to thwart cyber attackers. “Attackers are automated. Why are we fighting them with all these manual processes?”
Scott also highlighted the need for better information sharing and collaboration among peers in security. Attackers are organized, he explained.
“They don’t do it because they like each other,” he said. “They share techniques.”
Check out some photos from The Wall Street Journal event below, and learn more about Palo Alto Networks next-generation security platform here.
Left to right: John Bussey, Associate Editor from the WSJ; Michael Daniel, Special Assistant to the President and Cybersecurity Coordinator at the White House; and Scott Stevens, Palo Alto Networks VP, Technology and Worldwide Systems Engineering
Internet of Things (IOT) Working Group Provides Easily Understandable Recommendations for Securely Implementing and Deploying IoT Solutions
Las Vegas, NV – CSA Congress 2016 — Sept 30, 2015 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, today announced that its Internet of Things (IoT) Working Grouphas released a new summary guidance report titled Identity and Access Management for the Internet of Things. The Internet of Things (IoT) has been experiencing massive growth in both consumer and business environments. In response to this emerging market and the particular security requirements of these connected devices, The CSA established the IoT Working Group to focus on providing relevant guidance to its stakeholders who are implementing IoT solutions. To download a free copy of the guidance report, click here: https://cloudsecurityalliance.org/download/identity-and-access-management-for-the-iot/.
The IoT introduces the need to manage exponentially more identities than existing IAM systems are required to support. The security industry is seeing a paradigm shift whereby IAM is no longer solely concerned with managing people but also managing the hundreds of thousands of “things” that may be connected to a network. In many instances these things are connected intermittently and may be required to communicate with other things, mobile devices and the backend infrastructure.
“This document is the first in a series of summary guidance aimed at providing easily understandable recommendations to information technology staff charged with securely implementing and deploying IoT solutions,” said Brian Russell, co-chair of the Internet of Things Working Group for the Cloud Security Alliance. “With this guidance, the CSA’s IoT Working Group is seeking to provide prescriptive guidance to stakeholders detailing an easy-to-follow set of recommendations for establishing an IAM for IoT program within their organization.”
To help security practitioners ensure the integrity of their IoT deployments, the report details 23 recommendations for implementing IAM for IoT which are drawn from real-world best practices culled by CSA’s IoT Working Group along with guidance from a number of other organizations including the Kantara Initiative, FIDO, and the IETF.
Some of these recommendations include:
Integrate your IoT implementation into existing IAM and GRC governance frameworks in your organization.
Do not deploy IoT resources without changing default passwords for administrative access.
Evaluate a move to Identity Relationship Management (IRM) in place of traditional IAM.
Design your authentication and authorization schemes based on your system-level threat models.
About the Cloud Security Alliance
The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, follow us on Twitter @cloudsa.
Contributions from Six Dedicated Individual CSA Volunteers Recognized in Honor of the Late CSA Member and Volunteer Contributor Ron Knode
LAS VEGAS, NV – CSA CONGRESS 2015 – September 30, 2015 – The Cloud Security Alliance (CSA) today announced the recipients of its fourth annual Ron Knode Service Award, recognizing six members from the Americas, Asia-Pacific and EMEA regions for their excellence in volunteerism. The honorees were selected by the CSA executive team and chosen based on their valuable contributions towards fulfilling CSA’s mission of promoting best practices to help ensure security in cloud computing and next-generation IT. This year’s recipients will be honored this week at the CSA Congress 2015 & IAPP Privacy Academy 2015.
Ron Knode was an information security expert and member of the CSA family who passed away in May 2012. He is remembered as an innovative thinker with endless energy and humor to guide his volunteer contributions. He also was the creator of the CSA Cloud Trust Protocol, which today remains an important asset for the continuous monitoring and auditing for cloud assurance and transparency certification.
Established in 2012, the Ron Knode Service Award is awarded to CSA members on an annual basis whose contributions reflect Ron’s passion for volunteerism and embody the spirit for which this award was established.
This year’s six recipients are:
Brian Russell, CSA Americas: Brian Russell is a Chief Engineer focused on Cyber Security Solutions for Leidos. He oversees the design and development of security solutions and the implementation of privacy and trust controls for customers. Brian leads efforts that include security engineering for Unmanned Aerial Systems (UAS) and Connected Cars, the design of secure next-generation energy systems (microgrids) and the development of high assurance cryptographic key management systems. He supports the Center for Internet Security as a member of the 20 Critical Security Controls Editorial Panel and serves as Co-Chair of the Cloud Security Alliance (CSA) Internet of Things (IoT) Working Group. Brian also represents CSA in many IoT industry collaborations, including the FCC Technical Advisory Council.
Dr. Said Tabet, CSA Americas: Dr. Said Tabet is a Senior Technologist and Industry Standards Strategist in the Corporate Office of the CTO at EMC. He is a member of the Object Management Group Board of Directors and the principal EMC representative to the Industrial Internet Consortium. Said is the Chair of the INCITS CS1 Secure Cloud Computing Ad-Hoc Group, and a member of the US delegation to ISO SC27. He is also a member of the Cloud Security Alliance International Standardization Council, Co-Chair of the SME Council and the Cloud Security SLA working group. Said spent over two decades driving and contributing to various international standardization activities including ISO, RuleML, OMG standards, W3C Semantic Web and Rules, Risk and Compliance, GRC-XML, Regulatory Reporting and Supervision, Security and Data protection and Privacy. Said continues to work on challenges around Cloud Computing adoption, IoT, Cloud SLA and security SLA automation, Big Data Analytics and security, cyber security and best practices, Industrial Internet of Things, and Semantic Data Collaboration. He is a regular speaker and panelist at industry conferences and international standards meetings, authors and editor of book series and articles.
David Siah, CSA APAC: David Siah is actively involved in cyber security activities in Singapore. He is a member of Infocomm Development Authority of Singapore’s (IDA) Cyber Security Alliance as well as IDA’s working group on Cloud Outage Incidence Response. David is also a committee member on the Singapore Information Technology Federation’s Security and Governance Chapter and is the Country Manager of Trend Micro. In his capacity, he runs Trend Micro’s business operations in Singapore and is in charge of Trend Labs Singapore—responsible for malware analysis and response.
Benildus Nadar, CSA APAC: Benildus Nadar provides senior advisory services in area of Information Technology with a concentration on Information Security and Risk. Currently with Ericsson, he has worked with IBM, Fidelity Investment, and Comodo in a career spanning 14 Years. Benildus is the founder and chairperson of the CSA Bangalore Chapter, one of the biggest chapters for CSA worldwide.
Mariano Benito, CSA EMEA: Mariano J. Benito is CISO at GMV, a leading Spanish company in the cybersecurity field, and CSA Spanish Chapter task force (CSA-ES CTO). Along his twenty-year long career, he has contributed to the development and implementation of international standards, including ISO 27001 & 22031 at GMV. Mariano J. Benito has also developed a specific focus also on Cloud Computing, Compliance & Governance, being the author of the first security analysis in Spain regarding cloud security (2009) and currently contributing to the deployment in Spain of CSA Guide, CCM, PLA and other local CSA initiatives.
Kai Roer, CSA EMEA: Kai Roer provides Fortune 1000 companies worldwide with expertise on how to build and maintain security culture based on his free and open Security Culture Framework. Roer is a bestselling author, speaker and security culture facilitator who believes in the power of volunteerism.
“We will always remember Ron’s humor, energy and incredible generosity. CSA is grateful for his hard work and dedication, and we continue to benefit from his commitment and passion,” said Jim Reavis, CEO of the CSA. “The six individuals we are recognizing today embody the spirit of Ron’s tireless efforts and commitment to volunteerism. In his honor, we congratulate and thank them for their deep commitment to promoting secure cloud computing globally.”
About the Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, certification, events and products. CSA’s activities, knowledge and extensive network benefit the entire community impacted by cloud — from providers and customers, to governments, entrepreneurs and the assurance industry — and provide a forum through which diverse parties can work together to create and maintain a trusted cloud ecosystem. CSA has developed the definitive best practices for the industry, such as the “Security Guidance for Critical Areas of Focus in Cloud Computing”, the “Cloud Controls Matrix”, “Top Threats to Cloud Computing” and 50 other cloud security research artifacts.
If you’ve got your AWS re:Invent 2015 pass (Oct. 6–9, Las Vegas) and you’re building your schedule, be sure to set time aside to visit us at booth #331, where you can learn more about using our next-generation firewall and threat prevention features to protect your applications and data.
Common VM-Series for AWS deployment scenarios include using it as a firewall gateway and IPSec VPN termination point, allowing you to effectively extend your on-premises data center into AWS in a secure manner. A more involved scenario is to use it for VPC-to-VPC protection, controlling which applications can communicate with each other and blocking lateral threat movement. For employee remote access, we are seeing customers deploy GlobalProtect on the VM-Series for AWS – taking full advantage of the scalability and ubiquitous access that AWS brings to bear.
Can’t make it to AWS re:Invent? Then, check out these VM-Series for AWS resource to learn more:
While users and enterprises are becoming aware of the risk of mobile-based malware to the sensitive data stored on mobile devices, an often overlooked attack vector is attackers using a compromised mobile device to attack other devices on the network. Mobile devices, as their name implies, are upwardly mobile, often connecting to a plethora of different Wi-Fi networks as they accompany their owner to work, school, home, the coffee shop, the airport, etc. Each new platform is a gateway to a direct network connection to vulnerable systems.
Some penetration testers drop malicious devices that call home on a network as part of a physical access attack, simulating compromised devices on a network. This provides a pivot point to attack internal assets from the Internet. While this is a valid attack vector, what is being overlooked is that any of the mobile devices that are joining the network have this functionality by design, if they are compromised. Attached to the corporate network as well as the carrier mobile network, these devices are a natural pivot point.
Devices can become compromised while not on an enterprise’s watch. Users can download malicious applications or open malicious web pages. Mobile devices can be attacked on hostile networks they encounter as they travel outside the office with the user. Or, they could fall victim to remote code execution attacks, such as the recent Stagefright vulnerability that only required sending a malicious MMS (text message with media attachment) to a vulnerable phone.
When a compromised device attaches to an enterprise network, it can begin hunting for vulnerabilities in the internal network. As any penetration tester or security engineer will tell you, most networks are hard on the outside, but soft on the inside. Many corporations focus on their external, Internet-facing vulnerabilities, as naturally these are easier for attackers to exploit. To attack internal assets, an attacker will need to already be on the internal network by cracking a Wi-Fi password, phishing an employee at their workstation, etc. Penetration testers usually consider it trivial to find exploitable vulnerabilities on internal networks. The compromised mobile device has direct access to exploit those vulnerabilities.
Compromised mobile devices also provide a method of bypassing any data loss prevention mechanisms at the network perimeter. In the figure above, after the compromised mobile device has exploited a vulnerable local system, that system calls back to an attacker system on the Internet, just like in traditional compromise scenarios. Thus, security conscious enterprises are deploying technologies to notice malicious connections and sensitive data leaving the network and block these connections. Once again, it is the compromised mobile device to the rescue. That same pivot point that gave attackers access to the network in the first place through the carrier network connection can be used to infiltrate malicious connections as shown below. This will bypass any perimeter data loss prevention controls.
With mobile devices entering the enterprise en masse, it is important to recognize the unique threats these devices bring with them. Mobile devices default to being as connected as possible, often to multiple networks at a time (e.g., carrier mobile network and corporate Wi-Fi). This opens up a unique scenario for malicious attackers to use compromised devices as a pivot point to attack the internal network and bypass perimeter controls.
Georgia Weidman
Founder and CEO of Bulb Security, LLC
Georgia will be presenting Going from Practitioner to Entrepreneur at ISACA’s Inaugural CSX North America Conference, 19-21 October in Washington DC.