The Cybersecurity Canon: Measuring and Managing Information Risk: A FAIR Approach

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

Book Review by Canon Committee Member, Ben RothkeMeasuring and Managing Information Risk: A FAIR Approach (2014) by Jack Freund and Jack Jones

Executive Summary

One is hard pressed to go a day without encountering some sort of data about information security and risk. Research from firms like Gartner are accepted without question, even though they can get their results from untrusted and unvetted sources.

Panic around Ebola and other rare events shows how people are ill-informed about risk. While distressing over Ebola, the media is oblivious to true public health threats like obesity, heart disease, drunk driving, diabetes, and the like.

When it comes to information security, the situation is not much better. With myriad statistics, surveys, data breach reports and costs, global analyses and the like, there is an overabundance of data but an under abundance of meaningful data.

In Measuring and Managing Information Risk: A FAIR Approach, authors Jack Freund and Jack Jones have written a magnificent book that will change (for the better) the way you think about and deal with IT risk.

Review

The book details the factor analysis of information risk (FAIR) methodology, which is a proven and credible framework for understanding, measuring, and analyzing information risk of any size or complexity.

An Open Group standard, FAIR is a methodology and a highly effective, quantitative analysis tool. The power of FAIR is immense: it enables the risk practitioner to make well-informed decisions based on meaningful measurements. While that seems obvious, in practicality, it is a challenging endeavor.

FAIR is invaluable in that it helps the risk professional understand the language that the corporate board and senior executives speak. Understanding that, and communicating in their language, can make it much easier for information security to be perceived as a valued asset, as opposed to using Chicken Little statistics. FAIR takes the risk professional out of the realm of dealing with risk via the checklist; which only serves to produce meaningless measurements, into the world of quantitative, defendable results.

For those who are looking for a tool to create pretty executive summary charts with lots of colors, FAIR will sorely disappoint them. For those who are looking for a method to understand how to calculate qualitative risk to support a formal enterprise risk management program, they won’t find a better guide than this book.

Measuring and Managing Information Risk is an incredibly good reference that will force you to look again at how you view risk management. As Jones writes in the preface, the book is not about checklists and formulas, but about critical thinking.

The authors note that information security and operational risk have operated for far too long as art, without enough science. This is the gap that FAIR attempts to fill. The authors also write that risk decision-making quality boils down to the quality of information decision-makers are operating from, and the decision-makers themselves. The book does a remarkable job of showing how a person can become a much better decision-maker.

A subtle but important point the book makes early on is that many risk professionals confuse risk possibilities with risk probabilities. The FAIR method forces you to focus on probabilities and not to obsess on Ebola-like possibilities. Such a quantitative analysis approach is what makes FAIR so beneficial.

The book spends a few chapters going through FAIR risk ontology and terminology. Inconsistent and poorly defined terminology is one of the most significant challenges the information security and operational risk profession faces. Having a consistent set of logical terms and definitions that make up the FAIR framework significantly improves the quality of risk relations communications within an organization.

The value of having a consistent set of logical terms and definitions is significant. For example, the book notes that many people use the term threat. In the context of risk analysis, it might not be a real threat if there is no resulting loss. In that case, it would be considered a vulnerability event.

The challenge of FAIR is acclimating to its dialect. But once done, it creates an extremely powerful methodology for risk communication and management. And therein lies its power. Setting up a common framework for risk management becomes an invaluable tool to present risk ideas. In addition, it makes the findings much more objective and defendable.

In Chapter 5, the authors address the biggest objection to quantitative risk management: it can’t be measured or is simply unknowable. They agree that risk can’t be measured at the micro level, but it can be effectively measured to the degree to reduce management’s uncertainly about risk.

They also, importantly, note that risk is a forward-looking statement about what may come to pass in the future. With that, perfect accuracy is impossible; but, effective quantitative risk management is very possible.

The power of FAIR is that is helps add clarity to ambiguous risk situations by giving you the tools to add data points to a situation that is purported to be unknowable.

Chapter 8 is an extremely enlightening one, in that it provides 11 risk analysis examples. The examples do a great job of reinforcing the key FAIR concepts and methods.

In Chapter 10, the authors write that the hardest part of learning FAIR is having to overcome bad habits. For most people, FAIR represents a recalibration of your mental model about what risk is and how it works. The chapter deals with common mistakes and stumbling blocks when performing a FAIR analysis. The five, high-level categories of mistakes the chapter notes are: checking results, scoping, data, variable confusion and vulnerability analysis.

FAIR is a powerful methodology that can revolutionize risk management. The challenge is that it takes a village to make such a change. Management may be reticent to invest in what is perceived as yet another risk management framework.

But once you start using the language of FAIR and validate your findings, astute management will likely catch on. Over time, FAIR can indeed become a risk management game changer.

Conclusion

There are plenty of security books that will give you a basic overview of risk management.  It is sort of like giving a person a fish. For those who are looking to master the art of risk management, and learn how to fish, Measuring and Managing Information Risk: A FAIR Approach is one of the best books you can add to your library.

The book is flawless in its execution and description of the subject. The only critique is that the authors should have been a bit more transparent in the text when (especially in Chapter 8) mentioning the FAIR software, in that it is their firm that makes the software.

For those who are willing to put in the time to understanding FAIR, this book will make their jobs much easier. It will help them earn the trust of senior management and make them much better risk management professionals in the process.

This is a book that will stand the test of time and be valuable to risk management professionals for years to come, which makes it a worthy entrant into the Cybersecurity Canon.

[Palo Alto Networks Blog]

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

Book Review by Canon Committee Member, Ben RothkeThe Code Book: The Science of Secrecy from Ancient Egypt to Quantum Cryptography (2009) by Simon Singh

Executive Summary

It’s not clear who first uttered the quip: Of course I can keep a secret. It’s the people I tell it to that can’t. But what’s clear is that there are plenty of times when it’s a matter of life and death to ensure that secrets remain undisclosed.

In The Code Book: The Science of Secrecy from Ancient Egypt to Quantum Cryptography, author Simon Singh reveals the often hush-hush world of the science of secrecy.

How powerful are these cryptography tools? Until about only a decade ago, the U.S. Department of Commerce categorized strong cryptographic tools the same way it did F-15s and M-16s (more about that in Chapter 7).

Singh is a particle physicist who understands the science well and, more importantly in the case of this book, knows how to explain those details quite well.

Sit back and be enthralled by the fascinating world of cloak-and-dagger spies, and how without strong cryptography, we wouldn’t have online banking, Amazon Prime, and other things that make life meaningful.

Review

For anyone who ever had to study for the CISSP certification examination, the cryptography domain was almost always the hardest and most intimidating of the ten exam domains. While the ISC2 recently retired the cryptography domain and put it under Security Engineering, any topic with obscure terms such as hash function, public key cryptosystem, side-channel attacks and the like will certainly be intimidating.

In The Code Book: The Science of Secrecy from Ancient Egypt to Quantum Cryptography, while not a comprehensive overview of cryptography, this masterful book by Simon Singh is a history of encryption, with a focus on the 16th century to the end of the 20th century. As a history book, Singh strikes a good balance between writing about the history, and providing a good technical and mathematical overview of the topic of cryptography

With a Ph.D. in physics, Singh follows in the footsteps of fellow physicist, Richard Feynman, who was a great explainer. Feynman noted that if a specific topic couldn’t be explained in a freshman lecture, it was not yet fully understood. In the book, Singh spends about 400 pages on this freshman lecture. It’s worth noting that a number of freshman university courses use this book as a reference; it’s that good.

I first became acquainted with Singh when he gave a most entertaining keynote at an information security conference about a decade ago, where he dispelled the claim that Stairway to Heaven contained subliminal satanic messages.

Classic cryptography goes back thousands of years. While the book provides details into cryptography from the times of the Bible, Caesar and more; its focus is predominantly on the modern era, starting with the cryptography used by Mary, Queen of Scots in the mid-1500s, up to the topic of quantum cryptography.

The book covers a wide range of topics, from both a historical and technology perspective. Singh takes a broad approach to the topic and doesn’t focus entirely on ciphers and algorithms, rather he brings historical stories like the Rosetta stone, Man in the Iron Mask, Manhattan Project, Navajo Code Talkers and much more.

While encryption and cryptography have their roots in the world of mathematics and number theory, the book often places a focus on the human elements. While many cryptosystems work perfectly in the pristine environs of a lab, they will fail miserably when incorrectly implemented. Singh gives numerous examples, from Mary, Queen of Scotts to the German Enigma cipher machine, where the human element leads to extreme failures.

A number of the eight chapters start with a story, which Singh then uses as a lead to provide the underlying details of a specific aspect of security and cryptography.

For the story of Mary, Queen of Scots in Chapter 1, the message is that the underlying cipher needs to be reasonably impenetrable. In Chapter 4 on cracking the Enigma machine, the message is that even the strongest of cryptography devices finds its kryptonite if its users don’t follow the directions.

Chapter 5 on Language Barrier is perhaps the most fascinating chapter in the book. Singh details the story of how the U.S. used Navajo Indians and their obscure language as a means of ensuring the Japanese would have a much harder time deciphering the messages. By the time the war ended, the Japanese were never able to read a single message when Navajo was used.

The chapter also details the story of the Rosetta stone. While not a cryptographic issue in the common sense, hieroglyphics had been indecipherable for thousands of years. Singh writes how common wisdom at the time was that the Ancient Egyptian language of hieroglyphs should be treated as symbols and not letters. Singh highlights the story of how Jean-François Champollion was able to decipher the stones by using new research that the hieroglyphs were indeed letters, not symbols.

Anyone involved with cryptography knows terms such as Diffie–Hellman and RSA on a first-name basis. Those cryptosystems are the very backbone of today’s Internet security infrastructure. Singh does a good job of explaining how they work and what makes them secure. For RSA, it’s built on a very simple premise, that factoring the product of two huge prime numbers is difficult.  While most people may be oblivious to it, much of the underlying security for online banking and the Internet is built on top of RSA.

The book closes with the next generation of secrecy, which is quantum cryptography.  As a particle physicist, quantum mechanics is Singh’s bread and butter. When Singh wrote the book, quantum cryptography was not a practical technology, and that is still the case.

As a side note, if and when quantum cryptography becomes practical, it would be so powerful as to be able to break every RSA key in existence.

Conclusion

The Code Book was first published in 1999, around the time Windows 2000 came out. While the latter became obsolete in 2005, The Code Book is still quite germane given the value of the information in the book, which is still relevant and of interest.

For those looking for an encyclopedic reference, David Kahn’s The Codebreakers: The Comprehensive History of Secret Communication from Ancient Times to the Internet is the definitive tome on the topic.

For those looking for a more informal and selected overview of some of the core topics from the last 600 years of cryptography, this book is readable and interesting, and a perfect read for those looking for an introduction to the topic.

Those looking for a captivating and very readable book on the history of modern cryptography will find The Code Book: The Science of Secrecy from Ancient Egypt to Quantum Cryptographya valuable read, and one that is certainly worthy of being in the Cybersecurity Canon.

[Palo Alto Networks Blog]

The Cybersecurity Canon: @War: The Rise of the Military-Internet Complex

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

Book Review by Canon Committee Member, Christina Ayiotis@War: The Rise of the Military-Internet Complex (2014) by Shane Harris

EXECUTIVE SUMMARY

Shane Harris takes us on a journey from the Iraq War “surge” (arguably the first cyber war) to the almost weekly hacks of 2014 to demonstrate the rise of a military-Internet complex and the prescience of Eisenhower’s admonition regarding the power of a military-industrial complex. Harris ends @War by reminding us that only “an alert and knowledgeable citizenry” ensures “security and liberty may prosper together.” (EMPHASIS ADDED)

Harris is a first-rate storyteller providing just enough context (and detail) to enable readers to easily follow the evolution of cybersecurity and cyberwarfare, and to make them feel like they personally know the important players. As a member of this Inside the Beltway Cyber Community (who knows at least one third of the people cited or referenced in the book), I think he’s done a terrific job of accurately representing them and their viewpoints. While not very technical, this book should still appeal to the technical community interested in understanding the bigger picture in which they operate. I’d actually make @War required reading in high school and college—the next generation needs to better understand all things cyber, and the implications of future technological capabilities, as well as their own role and the risks inherent in an increasingly interconnected, wired world.

REVIEW

It is particularly difficult to review a book that has already been reviewed by professionals at major news outlets and Think Tanks (not to mention Amazon or goodreads). I will not regurgitate what they’ve already said—I encourage all to read those very good reviews. My bent is looking at the book’s value as part of the Cybersecurity Canon. Since I take a broad view of the definition of cybersecurity professional, I consider @War to be foundational, enabling those who comprise the cybersecurity community to better understand the larger geopolitical and economic context in which they live and work. The headlines of the past few years provide the outline of a story and @War fills in many of the details. This is a book that any cyber professional can have family members and friends read; once read, they can all have lively, informed discussions on the hot topics of surveillance, espionage, power grabs, etc.—it is that readable and engaging.[1]

By starting the book with the story of a war hero’s success using signals intelligence (SIGINT), Harris predisposes the reader to want to use such techniques to succeed in other contexts. (Most do not know this backstory regarding reduced IED deaths in Iraq, though they probably should—it solidified the “new” way wars are fought.) He doesn’t shy away from highlighting the dubious legal validity of certain data-gathering processes and provides much historical context (sometimes from the 2013 “unauthorized disclosures”). He pinpoints exactly when “[t]he military-Internet complex was born.”[2]

Harris chronicles in detail how the Cyber Army was built, including the role of the private sector. He persuades us that the Internet has become militarized and is now a legitimate battlefield. His detailed account of the creation and evolution of U.S. Cyber Command, including its complicated relationship with the NSA, is important in understanding how the military-Internet complex came about and is evolving. The internecine feuding between the various branches of government responsible for cybersecurity is worthy of its own soap opera.

The book gives great context to understand today’s major controversies around encryption, bug bounties, and surveillance programs/capabilities negatively impacting U.S.-based technology multinationals. Harris covers the established players, as well as the disruptive upstarts. He drills down into various scandals from Hunton & Williams’ proposed cyber propaganda operation that “killed” HBGary[3] to LabMD’s FTC woes because of Tiversa.[4]

Finally, Harris provides unprecedented detail on the role private sector entities play in the “business of defense”—whether it’s the commoditization of cyber services for both government and private sector customers (Lockheed’s “Cyber Kill Chain”[5]) or how threat intelligence services and marketing strategies can influence U.S. policy (Mandiant’s APT1 Report—“The government would never have been so bold as to come out with such a report.”[6]).

My only criticism is on the editing front—there should have been no typos (and, in acronym-obsessed D.C., there should not have been a “HIPPA”-like mistake regarding the important classified Presidential Policy Directive).

CONCLUSION

This book tells a compelling story about where cybersecurity is headed, given the “rise of the military-Internet complex,” and enables cybersecurity professionals to understand their place in the ecosystem. It should be part of the Cybersecurity Canon, as well as required reading for students and CEOs alike. Technological capability is evolving exponentially, and we all need to be prepared to meet the challenges and opportunities presented—@War will help on that front.

POSTSCRIPT ON “ACKNOWLEDGEMENTS”

As someone who believes in the importance of expressing gratitude (early and often), I was struck by how thoughtful and heartfelt Harris’ three-and-a-half pages of acknowledgements are.Cyber as a discipline and a profession is ever-evolving; understanding it requires having many diverse, trusted relationships. Properly and creatively recognizing and appreciating them is an art form.

 

[1] As a cyber-professional/corporate attorney/former GWU Adjunct Professor of Information Policy, I can attest to the importance of books that read like best-selling thrillers.
[2] Shane Harris, @War: The Rise of the Military-Internet Complex (Houghton Mifflin Harcourt 2014), p. 31.
[3] Ibid., p. 116.
[4] Ibid., p. 117.
[5] Ibid., p. 199.
[6] Ibid., p. 207.

[Palo Alto Networks Blog]

Stay Up-to-Date with the Cybersecurity Canon

Want to keep up with the latest details of the Cybersecurity Canon? Follow @CyberSecCanon on Twitter and “like” the Canon Facebook page to read book reviews, find out what books are nominated, see what our committee members are up to, and more!

Also, don’t forget, we want to hear from you. Click here for more information on how you can be involved with the Canon and nominate your favorite cybersecurity book for inclusion in the candidate list.

Questions about the Canon? Read the full set of blog posts to learn more, and check out the committee members for 2016.

[Palo Alto Networks Blog]

The Cybersecurity Canon: The Florentine Deception

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

Book Review by Canon Committee Member, Jon Oltsik: The Florentine Deception (2015) by Carey Nachenberg

Executive Summary

The Florentine Deception by Carey Nachenberg is a recently published novel grounded in cybersecurity.  The book begins when cybersecurity expert, Alex Fife, is asked to clean up an old PC his father purchased at an estate sale, only to discover a piece of rather sophisticated malware that captures the user’s keystrokes and sends them to an email server in Russia.  To Fife, this situation doesn’t compute; and after a bit of forensic analysis and some sleuthing about the PC’s previous owner, he determines that this system compromise is no accident.  In his investigation, Fife also discovers a mysterious detail he can’t quite figure out – something about an item known as Florentine.

The Florentine Deception is a picaresque novel in that it follows Fife’s investigation from beginning to end.  Through this journey, Alex gets increasingly engaged as his investigation evolves from the obsessive hobby of a rich, out-of-work technology executive to an international incident with potentially devastating national security implications.

While The Florentine Deception is most certainly a fun read, it also has educational value for cybersecurity professionals.  The author is an experience cybersecurity professional and Symantec Fellow who certainly has in-depth experience with cyberattacks, and this knowledge is clearly evident in his descriptions of social engineering techniques, threat actors, and malware.  Yet he is able to weave cybersecurity themes throughout the book without overwhelming less erudite readers with technical gobbledygook.  The story also includes a credible, albeit frightening cyberwar-like conclusion.  In this way, the book is enlightening and entertaining.

Cybersecurity professionals who enjoy reading books by authors like Dan Brown (Digital Fortress) and Mark Russinovitch (Trojan Horse, Zero Day) will find this book particularly worthwhile.

Review

As I walked across the halls of Moscone North during this year’s RSA Security Conference, I saw a friend from Symantec coming toward me, accompanied by another person.  I stopped the pair in order to exchange pleasantries and discuss RSA happenings.  That’s when I was introduced to my friend’s colleague, Carey Nachenberg, who holds the distinguished position of Symantec Fellow.

I can’t remember the exact flow of the conversation, but somehow, Carey mentioned that he had just published his first novel, The Florentine Deception and told me that, if I liked reading cybersecurity-centric fiction, I would thoroughly enjoy his book.  Being an avid reader of all things InfoSec, I enthusiastically accepted this offer and responded that I would welcome the opportunity to peruse his first work.  Nachenberg then took my card and vowed to send me a copy soon after RSA.  About a week later, I received a FedEx package from Symantec, as promised, containing a paperback edition.  I proceeded to motor through the entire book a few weeks hence.

The Florentine Deception is a first-person narrative about a cybersecurity professional named Alex Fife, and the entire story takes place in the Greater Los Angeles area of Southern California.  While in college, Fife starts a cybersecurity company based upon a crowdsourcing model for anti-malware.  Eventually the company gains market success and is then sold to the 800-pound antivirus gorilla, ViruTrax, for nearly $300 million.

After remaining with ViruTrax for a year subsequent to the acquisition, Fife leaves the company a rich man, but quickly finds that he is bored by his new freedom.  He spends his free time partying with his techie friends and getting into serious rock climbing with another group, but something is missing in his life, and he longs for some type of new adventure.

Unbeknownst to Fife at the time, his life would take an unexpected turn, based upon a rather innocuous incident.  Fife’s father purchases an old PC at an estate sale, hoping to donate it to a church charity.  Alex receives a call from his dad, asking him if he will clean up the PC and bring it back to a state of usability – a mundane task for someone with his technical skills.  Fife proceeds with this PC-recovery routine only to discover a piece of unknown malware on the system – a keylogger linked to a Russian email address.

Now most PC technicians would simply re-image the system at this point, but as a cybersecurity nerd, Fife can’t help but follow up with additional malware research, and a forensic investigation, to get a better understanding as to why this malware had found its way to an ancient PC acquired at an estate sale.  He then proceeds with his forensic investigations and discovers the identity of the PC’s previous owner, a recently deceased antiquities dealer from nearby Malibu named Richard Lister, Fife’s combs the Internet to gather any intelligence he can about this person.  When he stumbles upon a Los Angeles Times article with the headline, “Malibu Man Acquitted of Antiquities Smuggling,” Fife’s instincts tell him that this malware is no coincidence and he quickly suspects something bigger involving cybercrime or some type of Russian state-sponsored espionage.  Through his investigation, he also learns of an item that seems to be at the center of the mystery, something with the name Florentine.

Alex is intrigued and becomes engrossed in discovering the identity, location, and personalities involved in this elusive Florentine, and thus, his exploration proceeds through a series of twists and turns that develop throughout the remainder of the book.

Fair warning to more impatient types: you may be unimpressed by the first few dozen pages of this book (as I admit I was) and wonder where all the cybersecurity intrigue is, but I assure you that it is worthwhile to keep reading.  Through the course of Fife’s picaresque journey, his role evolves from that of a bored and wealthy technologist acting as amateur detective to a cybersecurity expert, deeply involved a potential national security incident.  This evolutionary transition is what makes The Florentine Deception so entertaining.  Just when you think you understand what’s happening and where things are going, Nachenberg takes you in a completely different direction, ending with a truly credible (and frightening) cyberterrorism/cyberwarfare scenario that will have any InfoSec devotee reading as fast as they possibly can.

It’s also worthwhile to note that, in addition to its entertainment factor, The Florentine Deceptionhas value as a vehicle for cybersecurity education, which is why I chose to review and expose it as part of the Cybersecurity Canon.  First, the story takes the reader through the intricacies of things like social engineering, phishing, cyber-attacker tactics, techniques, and procedures (TTPs), computer forensics and advanced malware.  Nachenberg does a great job of highlighting these cybersecurity topics without too much of a geeky description, helping to guide less technically savvy readers and keep them engaged.  In spite of this writing style, however, cybersecurity professionals will appreciate the tasks, details, and workflow undertaken by the protagonist.  This book is also built upon a foundation of international intrigue, realistic geopolitical relationships, and actual good guys and bad guys with distinct agendas from different countries, cultures, and belief systems.  This makes the notion of cyberterrorism and cyberwarfare a convincing, yet engaging component of the novel.

Conclusion

I absolutely recommend The Florentine Deception by Carey Nachenberg to those who enjoy reading books by authors like Dan Brown (Digital Fortress) and Mark Russinovitch (Trojan Horse, Zero Day).  In fact, Russinovitch’s books are good analogues to The Florentine Deception, so if you found them educational and entertaining (as I did), than this one is worth picking up.  It is also worth noting that the Foreword section of The Florentine Deception was written by Eugene H. Spafford (“Spaf”), a leading InfoSec expert and longtime faculty member at Purdue University.  If you know Spaf, you know that his contribution provides enormous cybersecurity “street cred,” making The Florentine Deception that much more enticing.

In closing, I mentioned previously that this book may be a bit slow at first, but readers will be rewarded for their patience and perseverance.  I truly believe that curious InfoSec professionals will find The Florentine Deception fun and informative, making it a logical addition to the Cybersecurity Canon.

[Palo Alto Networks Blog]

English
Exit mobile version