Connected Cars—Is the Risk Worth the Reward?

There is a revolution taking place in the automotive industry that will affect nearly every car owner, driver and passenger. It is the introduction of connected cars and the promise of enhanced safety and convenience.

With that promise comes massive security and privacy risk. After all, cars will be operated by highly intelligent computing devices that can be accessed remotely. Driver override will be built-in, but malicious tampering is possible. And in this case, there is absolutely no margin for error.

Having connected cars is fantastic and is the way the industry and society have been progressing, but not without questioning the concept and not without the assurance that the system cannot be compromised. It is critical that we ensure customers that a hacker cannot take over operation of the vehicle. And so far, it has been proven that this is possible today.

The benefits can go from having metrics about your driving style to preventing an accident. For example, a connected car can know the best route and where gas stations or restaurants are located. Although you could have these tools on other devices, the real value comes from optimizing fuel consumption and providing the best advice on how to drive safely and even taking control (with the right parameters in place), if necessary. A connected car is, or can be, intelligent, autonomous and smart.

The safety benefits of connected cars are very clear. A driver can be located in a dangerous situation, the car can be traced if stolen and the vehicle could potentially be locked if the driver is not the approved one. On the other hand, we need to understand that we are talking about identity management, authenticity and accountability. We need to understand that data can potentially be used against us if we do something wrong while driving.

As a potential user of a connected car, I would first ask what is really at stake. I would think about all the “what if” scenarios so I could fully understand the different roles the car will play in terms of advice, taking control, providing information and collecting information. Let me emphasize the importance of not only being a driving aid (which is at the core of a connected car), but that it also collects and potentially shares information about driving behaviors. I would try to clearly understand all aspects of privacy when purchasing a car that will “learn” a great amount of information about me.

Protecting user information is critical, both technical and legal. In terms of technical protection, vendors need to ensure that the system is robust and solid, that it has been hardened and that it is impossible to access it from places other than the “guaranteed” ones. If we consider a system that cannot be accessed remotely and does not allow a third party to take control of the car, that would make the vehicle less connected—which is something that we do not want. Thus, we have to ensure that the proper communication channels have been established. For this, vendors must be certain that the technology they deploy is safe and bug-free. On the legal side, a driver will have to agree with the collection and sharing of personal information. That is something that can fundamentally change and challenge our approach to driving.

It has been proven that hackers can take control of some models of electric cars. Remember, there’s a computer inside the car, standard protocols to connect to the Internet and operating systems that might have some flaws. Millions of cars provide a good customer base for the bad guys to try. And, while that may not make the bad guys money, it will certainly be something governments must monitor since a terrorist attack on thousands of vehicles would have a massive impact on society.

As with previous advances in technology, our prediction is that the market for connected cars will expand and change very rapidly. As a society, we will have to look at the legal ramifications and accept the sharing of data. If we accept that, we accept things such as the car taking control in heavy traffic. Sometimes we are pushed by technology that we do not really understand, but that is nice for us to use. We believe that focusing only on the benefits is short-sighted and we always appreciate the risk assessment approach—understanding what is at stake and if the benefits outweigh the risks or not.

Integrity is key in every security program, and even more so with connected cars. Making sure that the information is correct, and that it has not been altered by a third party is critical to success. A connected car, and the way it collects and correlates information, will be transparent for the user, much like a black box on a plane. Integrity is fundamental so that we know that data is the original and reliable. This is one of the key aspects of the validity of the information of a connected car.

Ramses Gallego
Security strategist and evangelist, Dell Software
ISACA International Vice President

[ISACA]

New US Congressional Bills Are an Important Milestone for Cybersecurity Professionals

News over the past year has focused the world’s attention on issues surrounding cybersecurity—notably that cyber attacks emerged as a top technology risk in the World Economic Forum’s Global Risks 2015 report. In April, US President Barack Obama declared cybercrime a national emergency and signed an executive order authorizing new sanctions against individuals and groups deemed responsible for cyberattacks.

The attention resonated with consumers, business leaders and legislators alike.

Mixed together with news of the Sony Corporation breach and other retail hacking occurrences, awareness of the need for increased cybersecurity focus has been at a high level. Now there is even more—but this time the news is about the US House of Representatives passage of two cybersecurity information sharing bills: Protecting Cyber Networks Act (PCNA) and National Cybersecurity Protection Advancement (NCPA) Act.

  • PCNA aims to defend against cyberattacks through the creation of a framework for the voluntary sharing of cyber threat information between private entities and the federal government. Importantly, it includes liability protection for those companies who choose to participate.
  • NCPA is similar to PCNA, with the distinction being that it encourages voluntary information sharing about cyber threats between the private sector and the Department of Homeland Security.

To help cybersecurity professionals understand the importance of these two new acts, ISACA has added a new CSX Special Reportto its Cybersecurity Legislation Watch center as part of its Cybersecurity Nexus (CSX). I encourage you to take a look at the report to better understand the two acts and what this new legislation could mean for you in your role and for your enterprise.

For professionals in the cybersecurity profession the implication is crystal clear. The general business community is more aware of the challenges, and those charged with protecting their organizations from attack must be highly aware and trained, including being knowledgeable of evolving legislation, such as this.

Keeping current and positioning your organization to best take advantage of the evolving regulatory landscape is of utmost importance in today’s fast-moving cybersecurity environment. This is not a time to be caught flat-footed.

Douglas Rausch, CISSP
President, Aurora CyberSecurity Consultants, Inc.

[ISACA]

How to Create a GEIT System that Delivers Value

Governance is vital to accomplishing the goals of an enterprise. By its very definition, governance of enterprise IT (GEIT) places a structure around how an organization aligns IT strategy with business strategy, ensuring that companies stay on track to achieve goals and implement methods to measure performance.

To be successful, an enterprise needs to manage expectations and satisfy stakeholder requirements— the drivers behind development of enterprise goals and subsequent IT-related goals. These goals must be in alignment and are best created with the full cooperation and involvement of IT and the stakeholders.

While governance is critical to any enterprise, form does not always follow function, resulting in many different pathways to successful implementation. In short, there seems to be no agreed-upon approach.

How to you get there—how do you start?

One valuable new resource is ISACA’s white paper, “Getting Started with GEIT.” The white paper outlines how an enterprise can begin the process of understanding needs and how to take that knowledge and put it into action.

It summarizes how using a well-established framework, such as COBIT 5, assists in creating a common language and understanding of governance concepts throughout the enterprise.

For example, the early benefits of using a framework include:

  • Deliver value to stakeholders.
  • Accomplish established stakeholder goals.
  • Make future change easier to accomplish.
  • Establish a framework that is part of the enterprise culture.
  • Strengthen internal control.
  • Rely less on external parties.
  • Enhance credibility of internal resources.

One item to note is that no matter what new framework is introduced, the timing of its introduction should be sensitive to the general business environment or commitment to its adoption could prove difficult.

The beauty of a successful framework is that its strength resides in its flexibility. It offers guidance, not prescriptive steps in what to do. The end result? Risks to the enterprise are significantly reduced and overall value quickly recognized.

Joanne De Palma, CISM, BCMM Assessor, MBA
Director, Global Information Technology Risk Management – ORM
PFI

[ISACA]

Closing the Cybersecurity Skills Gap

Organizations are realizing that it is not a matter of if a cyberattack will occur against their enterprises; it is a matter of when. This realization is causing executives and board members to take a growing interest in what is being done to protect and defend their top non-human asset: information. Support for growth in cybersecurity staffing is here; the problem is that the pool of skilled cybersecurity talent is facing a drought.

To address the global cybersecurity skills shortage, ISACA has launched a portfolio of innovative skills-based cybersecurity training courses and performance-based exams and certifications, through its Cybersecurity Nexus (CSX). These new CSX certifications are providing a benchmark that will help shape the future of cybersecurity hiring and the career progression of cybersecurity professionals. CSX will help assure cybersecurity pros that they can keep their skills sharp in the face of evolving threats, changing technology, and highly motivated adversaries who seem to get cleverer every minute. Organizations will have assurance that candidates have the right skills to address cybersecurity incidents from day one on the job, and that their security teams have the most important and current skills, knowledge and advanced capabilities.

This ISACA effort is critical, as 82 percent of organizations expect to experience a cyberattack in 2015. But, they feel they are relying on a workforce that is not qualified to handle complex threats, according to the State of Cybersecurity: Implications for 2015 survey from ISACA and RSA Conference. The results also revealed that 35 percent are unable to fill open cybersecurity positions.

Historically, cybersecurity training has been more general and did not evolve with the changing threat landscape. There has never been a defined career progression for cybersecurity. ISACA examined the lifecycle of a cybersecurity career and the skills that are needed at every level to develop a holistic approach to cybersecurity from beginning to end.

ISACA’s new cybersecurity certifications are:

  • CSX Practitioner—For this certification, a professional must demonstrate the ability to serve as a first responder to a cybersecurity incident following established procedures and defined processes. There is one certification at this level, and three training courses are available. This certification is a prerequisite for any of the five CSX Specialist certifications.
  • CSX Specialist—A professional must demonstrate effective skills and deep knowledge in one or more of five areas based closely on the NIST Cybersecurity Framework: Identify, Detect, Protect, Respond and Recover. There is one certification and one training course for each of these five areas. Professionals can choose to attain one or more of the five. CSX Practitioner is a prerequisite for a CSX Specialist designation.
  • CSX Expert—Only those who possess a master level of cybersecurity skills will be able to attain CSX Expert. Professionals must demonstrate skills that show they can identify, analyze, respond to and mitigate complex cybersecurity incidents. There is one training course and one certification at this level. No prerequisites are required.

ISACA is the first organization to use PerformanScore, a unique learning and development tool that measures a professional’s skill in performing cybersecurity job activities in a virtual setting using real-world cybersecurity scenarios.

Skills verification for cybersecurity pros should recognize that there are multiple ways to respond to threats, and PerformanScore can do just that—measure skills across the entire solution set of possibilities. Since the tool compares actions to grading criteria that are referenced against an adaptive scoring rubric in real-time, instructors can provide more precise feedback and professionals can learn more efficient cybersecurity techniques.

ISACA is the right organization to answer the urgent call for skilled cybersecurity professionals. ISACA blends the membership strength, vision, global reach, reputation, integrity and ties to global governmental entities like no other organization. We have the commitment, tools, resources and foundation to offer the complete holistic program that is provided through CSX. As a member of ISACA for over 15 years, it is exciting to see the strong strides ISACA is making to help strengthen enterprise security today.

For more information, visit www.isaca.org/csxnews .

Eddie Schwartz, CISA, CISM
President of White Ops, Inc.
Chair of ISACA’s Cybersecurity Task Force

[ISACA]

ISACA International President: Addressing The Current State of Cybersecurity

It is no secret that more and more organizations are experiencing cyberattacks, and many go undetected for lengths of time. ISACA and RSA recently joined forces on the State of Cybersecurity: Implications for 2015 survey, which uncovers issues surrounding hacks, cyberattacks, security positions, budgets and policies. As threats grow in number and complexity, it is important that organizations are equipped with the right information, team and resources to address the issues.

According to the State of Cybersecurity survey, we have seen an increase in cyberattacks from 2013 to 2015, and 82 percent of organizations are expecting to be attacked this year. This high-risk environment is made worse by the lack of skilled talent prepared for the job. Only 16 percent feel at least half of their applicants are qualified for cybersecurity roles. Fifty-three percent say it can take as long as three to six months to find a qualified candidate, and more than a third are left with unfilled job openings. So, who is watching the shop?

On a positive note, cybersecurity is now receiving more respect from leadership. A majority (56%) said that they plan on spending more on cybersecurity this year. Though most are confident in their security teams’ ability to detect and respond to incidents, less than half feel that their security teams are able to detect and respond to complex incidents. With increasingly sophisticated threats and a lack of qualified professionals, this is concerning.

But filling these positions creates an opportunity for college graduates and professionals seeking a career change. One path is to pursue certification—92 percent of respondents find certification valuable, including a majority (69%) that require certification to fill cybersecurity job openings. Practical hands-on experience and certifications can pave the way for a very rewarding career.

There is a growing need for valuable guidance, credentials, tools, networking and training for professionals in this fast-moving field. Cybersecurity is everybody’s business, and it is necessary that we work together to close the skills gap and protect our enterprises.

Robert E Stroud, CGEIT, CRISC
2014-2015 ISACA International President

[ISACA]

English
Exit mobile version