OPM Breach: Training and Skills Are Key to Safeguarding Information

In a recently filed class-action lawsuit filed against OPM, the plaintiffs cited a November 2014 Office of the Inspector General (OIG) report stating that the “drastic increase in the number of [software] systems operating without valid authorization is alarming and represents a systemic issue of inadequate planning by the OPM offices to authorize the [software] systems they own.” The OIG report also cited the cybersecurity deficiencies that “could potentially have national security implications.” These included:

  • The OPM’s decentralized governance structure
  • A lack of acceptable risk management policies and procedures
  • Failure to maintain a mature vulnerability scanning program to find and track the status of security weaknesses in software systems
  • A high rate of false security alerts that could delay the identification of and response to actual security breaches
  • Failure to use tools to monitor the progress of corrective efforts for cyber security weaknesses
  • Remote access sessions which did not terminate or lock out after the period of inactivity required by federal law
  • Failure to continuously monitor the security controls of all software systems
  • Failure to maintain and test contingency plans for every information system as required under the OPM’s policies
  • Failure to use Personal Identification Verification (PIV) cards for multi-factor authentication in all major software systems

According to the OIG report, evidence points to credentials stolen from a private contractor as the source of the breach. It notes that the third-party contractor had suffered a breach in August 2014, employee credentials were compromised, and OPM failed to take proactive measures to address the possible access privileges provided to employees of that contractor. This breach provides a case study for senior executives in large organizations and cybersecurity professionals of the need to improve understanding and implementation of prudent cybersecurity risk management and governance best practices and to ensure a strong and skilled cyber workforce.

While implementing technical solutions may have played a significant role in potentially preventing or lowering the risk associated with this kind of incident, it likely would not have saved the day against a well-funded and determined nation-state adversary. Technology is only effective if risk management and governance policies are developed and implemented and cybersecurity professionals at all levels of the organization are trained and have the requisite skills to perform the tasks related to their functional roles in cybersecurity.

In today’s world of advanced threats, it is critical that staff at all levels obtain training and certifications that build the most up-to-date cyber defense capabilities. It is a clear indication that training and education, through programs such as ISACA’s Cybersecurity Nexus (CSX), need to be at the forefront. Enterprises need hands-on skills to manage a mature vulnerability scanning program, more quickly recognize false-positive security alerts, properly monitor progress related to corrective actions related to cybersecurity weaknesses, implement effective remote access policies, employ effective continuous monitoring of security controls, develop, maintain, and test information systems contingency plans, and finally, ensure multi-factor authentication is implemented on critical information systems.

Robin “Montana” Williams
Sr. Manager, Cybersecurity Practices
ISACA/Cybersecurity Nexus (CSX)

[ISACA]

Why Hiring CCSPs Will Help the C-Suite Sleep at Night

A few short years ago, cloud computing was considered a relatively new concept inherent with risks that many IT professionals weren’t comfortable taking. I’ll avoid the debate about who coined the term cloud computing, but I’m old enough to remember how we formerly referenced the cloud in telecommunications as a way to simplify and abstract the details of the external network that’s connected to internal devices. Today, the concept of cloud computing is intended to simplify communication by eliminating the need to know all of the specifics of the cloud provider’s underlying software and infrastructure. The cloud provides benefits to businesses and consumers alike by offering consolidated services, quicker delivery time and decreased costs.

As we look toward the future of IT, cloud computing hovers over us at the forefront. Adoption rates are soaring, and cloud computing must integrate with in-house IT infrastructure and data assets. According to nearly 14,000 respondents from the 2015 (ISC)² Global Information Security Workforce Study (GISWS) by Frost & Sullivan, 43 percent state that cloud is a priority for their organizations and 57 percent of total respondents state it will become even more of a priority over the next two years.

Though it may be obvious to some, the growing adoption of cloud services will increase the demand for security professionals who can apply the proper controls to public, private, community and hybrid cloud models. Cloud computing was identified as the top area of information security with growing demand for education and training within the next three years, according to the (ISC)² GISWS. IT professionals who understand how cloud services can be securely implemented and managed within their organization’s IT strategy and governance requirements are essential. In fact, 73 percent of GISWS respondents believe leveraging cloud-based solution and services will require information security professionals to develop new skills.

(ISC)² and the Cloud Security Alliance (CSA) teamed up in an effort to address the need to establish a common global understanding of professional knowledge and best practices in design, implementation, management and service orchestration of cloud computing systems. CSA’s Certificate of Cloud Security Knowledge (CCSK) provides a very solid baseline of cloud security. Working together, (ISC)² and CSA developed a cloud security credential for those requiring a deeper understanding and demonstrated experience. The Certified Cloud Security Professional (CCSPSM) validates that professionals have met the highest standard for cloud security expertise. The combined initiative addresses the expanded information security complexities as organizations begin to leverage cloud-based infrastructure, software and services more frequently.

So why should organizations take note? With breaches rife and the C-suite increasingly aware of the implications of inadequate security, hiring CCSPs will help the C-suite sleep at night. Companies will benefit from employing CCSPs because they possess the knowledge, skills and abilities needed to address the security and business issues associated with the complexities of cloud computing. CCSP is vendor-neutral and requires practical knowledge and skills covering a broad set of cloud security capabilities necessary for cloud professionals to effectively carry-out their responsibilities and contributes to the overall security of their cloud environment.

Those in the C-suite at organizations who have decided to take advantage of recurring savings related to leveraging cloud solutions and services should consider what a modest investment in staff training and certification could mean for near-term and long-term success in relation to recurring operating cost savings, while ensuring cloud security best practices. Cloud security should be more of a science than an art. Leveraging the cloud should be predictable and repeatable, versus becoming an area of self-expression across an organization’s business units.

Had I been able to employ CCSPs during my early cloud implementation days, I know I certainly would’ve slept easier at night. For more information about CCSP, please visit https://www.isc2.org/ccsp/default.aspx.
-David Shearer, CISSP, PMP, CEO, (ISC)²

Using COBIT 5 to Audit Knowledge Management

As an African proverb reminds us, “Knowledge is the only treasure you can give entirely without running short of it.” Knowledge is recognized as the most important strategic asset for every organization. According to the Journal of Knowledge and Process Management, knowledge management is a holistic process that optimizes intellectual capital to achieve organizational objectives by leveraging information and expertise. The main purpose of knowledge management practice is to mitigate the possible loss of extensive tacit and explicit knowledge due to loss of employees.

Knowledge management practices enhance the capability of an organisation to identify, capture or acquire, share, reuse and internalization of knowledge. Audits of knowledge management practices are rarely undertaken by audit functions, and this gap has been identified as one of the contributing factors in knowledge management initiatives.

COBIT 5 introduced a new defined process—BAI08:Manage Knowledge process. This process fits well in one of COBIT 5’s information technology goals: “ knowledge, expertise and initiatives for business innovation.” The process provides guidelines on how to facilitate information system knowledge management within an IT organisation. For a detailed look at it, download ISACA’s BAI08 Manage Knowledge Audit Assurance Program.

What is knowledge management audit?
In an article from The Hong Kong Polytechnic University, “Re-Thinking knowledge audit: its values and limitations in the evaluation of organizational and cultural asset ,” knowledge management audit is defined as the systematic investigation, examination, verification, measurement and evaluation of explicit and tacit knowledge resources and assets, in order to determine how efficiently and effectively they are used and leveraged by the organisation . A knowledge management audit provides an opportunity to understand the current state of the knowledge management capability of an organization and a direction of where and how to improve the capability to provide the knowledge for quality decision making and enhanced productivity.

Planning for knowledge management audits for IT function
Before planning to undertake knowledge management audits, professionals should understand the knowledge management landscape within the entire organisation, and not just the IT function. It goes without saying that understanding the bigger picture of the organisation is critical in planning IT knowledge management audits. Noted in the Journal of Knowledge and Process Management, the knowledge management landscape of any organisation will involve people culture, processes, structures and technology that support its initiatives. The following knowledge management elements should be reviewed at the audit planning stage.

Knowledge Management (KM) Elements Why review this document at planning stage
Knowledge management strategy The document provides the long-term vision and objectives of the organisation as far as knowledge management is concerned. KM elements like KM structure, resources, projects, roles and responsibilities and roadmaps will be highlighted in this document.
Knowledge management policy To understand the high-level management commitment and support for knowledge management within the organisation
Interview those responsible for knowledge management (Knowledge Management Officers) To understand current knowledge management initiatives, structures and challenges within the organisation
Walk through existing collaborative tools (intranet, online community of practice, knowledge- sharing platforms, document management systems, etc.) To understand the available collaborative tools used across the organisation for knowledge management
Preliminary social network analysis to map the major information flows within an organisation To understand knowledge flow within the organisation. This aids the auditor to identify the key nodes of knowledge creation, sharing, reuse and storage.

Audit Reporting
Knowledge management audit reports should provide the following outputs: an assessment of current levels of knowledge management practice and knowledge sharing; identification and analysis of knowledge management opportunities that have not been explored; isolation of potential problems and existing gaps; and an evaluation of the perceived value of knowledge management within the IT organisation. The report should highlight the existing knowledge management gaps and offer recommendations on four key perspectives: people culture, processes, structures and technology.

By auditing knowledge management processes, you will be able to identify gaps in an organization’s knowledge management practices and activities, build from what is working, and identify areas that require improvement. The outcome should be a blueprint for moving forward in developing organizational knowledge management best practices.

John Masika
IS Audit Manager at Kenya Airways Ltd

[ISACA]

Top Digital Trends Affecting Organizations Today—And What You Should Do About Them

When it comes to the use of technology decision making, the stakes for the business have never been higher. Investing in the right technology at the right time can very often mean direct competitive advantage to the business. Investing poorly, at the wrong time, or not at all (especially when competitors do so) can instead mean the business operates at a disadvantage relative to peers and competitors.

At the same time, the time window that organizations have to consider the options available to them is decreasing. It seems like digital trends and new technologies arise quickly and appear from seemingly out of nowhere, leaving organizations relatively little time to evaluate trends, understand the risk and rewards, and make an informed decision about investment. And, as we know, making an informed decision about value and risk tradeoffs for any technology or digital trend can be complicated. We need to consider business value added, new risks introduced (and old risks potentially mitigated), cost of the investment, possible disruption to business teams and numerous other factors.

To help with these challenges, ISACA is making a new resource available: ISACA Insights. The purpose of Insights is to identify the most impactful digital trends that organizations should consider in their strategic decision making:

  1. Big data analytics
  2. Mobile technologies
  3. Cloud computing
  4. Machine learning
  5. Internet of Things
  6. Massive open online courses
  7. Social networking
  8. Digital business models
  9. Cybersecurity
  10. Digital currency

Insights consists of a top 10 report describing the high level trends in business-accessible language and supplemental individual trend reports highlighting specific trends with an eye to overall organizational risk and value. Because the reports are short and business-accessible rather than technical, they are easily understood by those on either the technology or business side of the organization. They can be used as a discussion aid between business and technical teams—for example, to help business teams understand the risk impact of a particular trend or to help technical teams understand the business value drivers that might be driving interest in a particular trend or technology area.

Over the next few weeks, ISACA will be looking in depth at some of the information outlined in these reports and some of the risk, value and security implications of each of the top trends. Making a holistic decision about the risk vs. reward associated with investing in any particular trend means understanding both sides of the risk equation—the value to the business in adopting, the potential business risks associated with failing to adopt, as well as the technical risks that can be introduced when adopting these trends.

I encourage you to view the report on the top 10 trends, as well as the more in-depth reports on each of the top four trends. All are free at www.isaca.org/isaca-insights.

Ed Moyle
Director of Emerging Business and Technology, ISACA

[ISACA]

Cybersecurity Akin to Being in a War Zone—You Have to Be “Left of Boom” to Survive

Being a chief information security officer (CISO) is not unlike being in a war zone. Professionally and politically, your survival is dependent upon being “left of boom”—to coin a term from the US Pentagon when dealing with Improvised Explosive Devices (IEDs). In other words, constructing your defensive measures to be in place to prevent “boom” from occurring is the most prudent course of action. About 10 to 12 years ago, as a CISO in the US federal government, the job was to protect and defend because at that time we were most concerned with the basic security hygiene of the enterprise and viruses in the wild, so we tried to do basic preventive maintenance. We were not yet facing sophisticated, targeted attacks. We were trying to keep our configurations up to date, and then we thought we would be okay. CISOs’ perspectives have evolved because of the advanced persistent threat (APT) becoming a larger problem in the past few years. We have gone from protect and defend, to early detection and rapid incident response with immediate recovery so that businesses can continue to operate in a compromised environment. Essentially, we have gone from risk management to risk tolerance.

Threat Intelligence and Analytics
The enterprise now must have an active capability to gather and analyze threat intelligence to learn which of the threats and threat actors are looking at and targeting the enterprise. This requires a thorough understanding of your business lines and the types of business processes your enterprise is involved in so as to better understand who is targeting your business and how they are conducting their operations. If you know what type of threats there are, you can determine what type of technology to put in place, such as behavior-based rather than signature-based technology.

Today, more than ever, CISOs and their staff have to be agile enough to get ahead of the problem as opposed to letting the problem—or the “boom”—happen and cleaning up afterwards. The “right of boom” approach is quite costly and ends up consuming most of a security program’s resources. “Right of boom” enterprises include all of those who have made headlines because of their publicized breaches over the past couple of years.

Looking forward, there are encouraging developments in big data analytics, where helpful proactive information can be derived from the terabytes of information from companies’ deployed security devices. In the past, security staffs did not have the tools to analyze this data in a cost-effective fashion, so often, the data was lost due to storage limitations. Today, with advanced analytics, a company can take that information and develop pattern and behavior analysis to see if something is actually getting into the enterprise, or worse, data is being exfiltrated. Additionally, there are cloud and mobile security operating realities that may have the effect of weakening security over the next 5-10 years because adversaries’ targeted capabilities are getting stronger. Keeping up with these developments is a constant challenge for CISOs.

Legislation Shortcomings
Legislatively, the US Congress has not approached the cyber security problem from a holistic, enterprise-wide perspective. Rather, US legislation has been focused on compliance with requirements of questionable security relevance. Most legislative efforts have not emphasized the rapid and continuous changes of the IT environment that are necessary in meeting the challenges of securing today’s enterprises. Legislation is generally about putting controls in place and making sure they are implemented effectively and doing risk management—which did not work well in the past and is even more misguided in the present. In today’s environment, an organization needs to be more proactive, rapidly changing to meet the attacks with rapid responses that are difficult to legislate. The US bill, Federal Information Security Modernization Act of 2014, which is more attuned to continuous monitoring of technical controls, may be a step in the right direction, but legislative solutions generally tend to stifle the ability of enterprises to meet the security challenges with swiftness and agility.

Mentoring Needed
The critical skills gap in cyber security staff requirements is growing, but enterprises are having a difficult time meeting the demand. Companies seem to want a cybersecurity staff with the wisdom of experienced executives, but at the pay scale of college graduates. The problem that the Fortune 1000 has yet to solve is that the experienced substantive expert understands how to apply security across an enterprise, while the recent college graduate may only know how to put controls in place.

Professional certifications are also important, but are becoming more and more targeted at specific roles. For example, incident responders, forensics staff or governance and compliance professionals should have the relevant certification that attests to their knowledge of that particular skill set. But the big concern is—as businesses cut costs and move the experienced staff into retirement—who will mentor the next generation on how to effectively manage risk across large heterogeneous enterprises?

Bruce A. Brody
Chief Information Security Officer, Cubic Global Defense
Chief Cyber Security Strategist, Cubic

[ISACA]

English
Exit mobile version