Connected Vehicles are in the news for introducing new features and capabilities to the modern automobile. Headlines also highlight security hacks that compromise vehicle operations and usability. While sources note that the vulnerabilities identified so far have been addressed, a greater understanding is needed on how tomorrow’s Connected Vehicle will operate in an environment composed of both legacy and modernized traffic infrastructure. The Connected Vehicle will be designed to communicate with countless other devices and interfaces. Security systems, tools, and guidance are needed to aid in protecting vehicles and the supporting infrastructure.Through research and development within the CSA Internet of Things Working Group and the United States Department of Transportation Federal Highway Administration, CSA is introducing “Observations and Recommendations on Connected Vehicle Security” to keep consumers and manufacturers up to date on the evolution of vehicle connectivity, areas of concern, and recommendations for securing the connected vehicle environment. The paper will provide a “big picture” view of the various aspects of vehicles and infrastructure components to better understand their interrelationships, dependencies and threats to the traffic ecosystem.
Learn about:
Connected Vehicle reference architectures and messaging protocols
V2V, V2I, V2X interactions
Potential System-of-System attacks and outcomes
Cross collaboration of IoT devices and systems
Vehicle design, platform, and infrastructure security best practices
The CSA Internet of Things Working Group continually evaluates and conducts research on new technologies involving cloud and the Internet of Things. CSA collaborates with other industry organizations to bring the latest guidance and security best practices to IT and enterprise.
John Yeoh, Research Director/Americas, Cloud Security Alliance
Editor’s note:ISACA Belgium Chapter President Marc Vael, CISA, CISM, CGEIT, CRISC, recently took a creative approach to spread awareness about General Data Protection Regulation (GDPR), spearheading a game about the coming regulations that will affect enterprises worldwide. Competitors can win the game by answering GDPR questions correctly and with a little luck with the dice. ISACA Now recently visited with Vael about the game, which will be available on a limited basis at the ISACA chapter leadership event, this weekend in Munich, Germany, prior to EuroCACS. The following is an edited transcript.
ISACA Now: How did this GDPR game come about, and who was primarily involved with its development?
Basically, at my IT company, Smals, we were looking to bring the content of the EU GDPR to this group of IT developers, IT analysts, IT project managers and even management differently, avoiding PowerPoint or brochures or self-assessment questionnaires.
Initially, my colleague Nathalie Dewancker and myself started building “the journey to become EU GDPR compliant,” but that journey was too simple, and we started adding gaming effects, and before we knew it ourselves, we had a full-blown EU GDPR game. We loved the reactions so much that we didn’t want to keep it within our company or for ourselves, and thus we decided to ask ISACA Belgium for support, which the board of ISACA Belgium did by funding the professional look and feel of the EU GDPR game.
ISACA Now: ‘Game’ is probably not the first word that comes to mind when people think about GDPR. Why did you think this format would be a good fit?
True. Most of the messaging happens via PowerPoints, brochures and information on websites. Here and there we discover some apps with the searchable EU GPDR text in different languages or some EU GDPR self-assessment questionnaires. We found out that up to today, we are the only ones with a proper EU GDPR game box. Gamification is a well-known concept, but it is not used enough, in our humble opinion. Moreover, we notice huge discussions between the players, and that is just what we want to achieve: not just “acquiring” knowledge, but critically looking at this knowledge.
ISACA Now: Did it really only take a few weeks to put the game together? How were you able to execute the idea so swiftly?
Yes, we build from initial journey to full game in three weeks, with some tryouts. Then, molding it into a professional looking game box took another three weeks, thanks to the help of our external PR agency that we use here in Belgium. So, six weeks in all. And we were just in time to bring our game boxes for the main Belgian INFOSECURITY exhibition in Brussels, where over 3,000 attendees came in the end of March this year. Thus, it was plain teamwork.
ISACA Now: What has been the preliminary response to the game’s release?
Initially, skepticism that participants would learn about “such a complex matter as EU GDPR” via a game. But then, when playing, a lot of discussions happen between the participants and between participants and observers (since there can only be a maximum four participants, more people can join as observers of the game). It is great fun to see how some people really want to win.
We only made 300 EU GDPR game boxes and almost all are sold now. We initially wanted to give them away for free as marketing, but since we only had 300 game boxes, we did not want to have people take them and throw them away, so we ask only 5 Euro per game box as a token of appreciation and eagerness to have the box.
When we launched the game box at INFOSECURITY BELGIUM, our stand was very popular and people bought all 100 game boxes we brought over there in two days. We were surprised.
ISACA Now: What was the most remarkable reaction you got on the game?
Actually, some players asked why we did not include more information about the EU GDPR in the game box (like a manual on EU GDPR or some form of brochure or leaflet). We did not do that on purpose, and we responded by saying to them “If you play Monopoly, do you first have to follow a real estate course? No. If you play Stratego or Risk, do you first have to follow a military course? No.” So, if you play the EU GPDR game, we believe you do not have to follow some privacy course before playing either since the objective is to learn about EU GDPR during the game. People truly liked our reaction very much.
ISACA Now: What are some of the biggest implications GDPR could have on organizations that are affected by it?
The need to review and update the inventory of processes and suppliers, execute the privacy risk assessments on the core processes and suppliers, execute privacy awareness amongst employees and external personnel, and test the incident escalation process (to check if they can make it within 72 hours).
ISACA Now: What are a few misconceptions that technology professionals have about GDPR?
Very good question; here are some of the misconceptions I hear frequently by IT experts:
Some organisations believe they are too small for EU GDPR so they pretend not to fall under the regulation
Believing EU GDPR is merely an information security issue which can be solved by encrypting all data
Stating that May 2018 is still far away to handle such compliance topic
Believing EU GDPR is a legal topic so legal counsel will handle it
IT is mainly a data processor so the responsibility for EU GDPR is for the data controller (which is not IT)
ISACA Now: What is the best way for someone to purchase a copy of the game?
When living in Belgium (since the game is in Dutch/French combined), people can come and collect game boxes in our office (if they warn us upfront). When living outside of Belgium, we try to arrange for the cheapest way to get a game box shipped (I can be reached by email at president@isaca.be). We will also bring some game boxes to the ISACA European chapter leadership meeting this weekend since some ISACA chapter leaders have asked to bring a box over there.
One thing is certain: The need for cyber security professionals isn’t going away any time in the near future. As our digital footprint and the Internet of Things (IoT) continue to expand, we become increasingly vulnerable to having our private information poached with a single click, swipe or utterance. As a result, this is a field where 95 percent of people are certified, and within that group, 87 percent are specifically certified in security or privacy.
As major data breaches have demonstrated time and time again, cyber security and compliance is the responsibility of all employees—not just those who formally specialize in cyber security efforts. Of course, if you’re reading this blog, you’re probably already well aware of the importance of everyday cyber security measures and know it’s not a matter of “if” so much as “when” your organization or company will experience a breach.
We can’t move fast enough
There’s one statistic circulating that lends itself to a real sense of urgency in the field.
According to the consulting firm Frost & Sullivan, there is expected to be a 1.8 million person worldwide workforce shortage in cyber security by 2022. Let that sink in for a minute. Nearly 2 million people are needed to cultivate cyber security know-how to protect their organizations from breaches in the next five years. That’s a huge vacancy in skills and, more importantly, leadership.
And who is helping create cyber security and business technology leaders of today and tomorrow? Meet ISACA. As an organization driven to promote cyber security awareness and skills, ISACA provides a deeper validation of skills for those working in governance, IT audit and assurance, risk, as well as information and cyber security.
ISACA enables professionals to take a leadership role by increasing their depth of knowledge. Greater skills validation translates to being better able to leverage that background into leadership positions.
As a result of those advanced, validated skills, ISACA-certified professionals typically have average salaries 44 percent higher than those of their non-certified peers worldwide, according to the Global Knowledge 2017 IT Skills and Salary Report. In fact, ISACA certifications (CRISC and CISM) earned the top two spots in top-paying certifications this year, and overall, six of the top 20 highest-paying certifications are in the field of cyber security.
“It’s clear from the growth in certifications from organizations like ISACA that companies and employees put increasing value on investment in skills and abilities. We see that investment across the board as the IT industry realizes that the return on investment for people exceeds the ROI for technology,” said Dave Buster, Global Senior Portfolio Director for Cybersecurity at Global Knowledge.
Never content and always learning
What’s more, the report revealed ISACA-certified professionals weren’t content to rest on their laurels once certified. Globally, 89 percent of industry professionals holding ISACA credentials trained in the last year, and on top of that, 75 percent of respondents said they did so in order to cultivate new skills. Compared to their peers that are not ISACA-certified, professionals holding at least one ISACA certification were more likely to attend a webinar or conference and download white papers or articles to stay informed with industry trends and best practices.
Given their more senior-level roles within their organizations, generally, ISACA-certified professionals are more apt than their counterparts to report training in areas of business process improvement and leadership.
Driven to succeed
The takeaway: ISACA-certified professionals are driven to succeed and consistently re-evaluate the definition of success through continued engagement and learning. While ISACA can’t single-handedly solve the worldwide personnel shortage for those working in cyber security and related fields, according to the IT Skills and Salary Report, those who turn to ISACA for skills development and certification are committed to the cause and tend to be rewarded with higher salaries.
Editor’s note: For more information, visit Global Knowledge’s cybersecurity certification page and scroll to ISACA. To learn more about ISACA certifications, visit ISACA’s certification page.
Casey Wasserman, Ph.D, Content Marketing Manager for Global Knowledge
Not surprisingly, WannaCry remained top of mind last week. We’re sure you’re doing everything you can to patch your environment and prevent similar ransomware attacks in the future. Here are some WannaCry headlines (and other security news) that caught our eye last week.
WannaCry Rolls On
According to the Dark Reading article WannaCry’s ‘Kill Switch’ May Have Been a Sandbox-Evasion Tool, researchers early last week were looking into the “kill switch” and consensus seemed to be building that it was a poorly constructed VM analysis/sandbox evasion technique.
An attack of this magnitude involving so many missteps raises plenty of questions while delivering a sobering reminder: If actual cybercriminal professionals improved on the group’s methods, the results could be even graver.
Want to learn how fast WannaCry can spread? BleepingComputer’s reporting shows has aggressive and fast this ransomware can propagate to vulnerable machines:
During one of those infections, WannaCry infected the honeypot in a mere three minutes after it was reset, showing the aggressive nature of the ransomware’s scanning module, which helps it spread to new victims…Furthermore, three minutes is about the same amount of time IoT malware will infect a vulnerable home router left connected to the Internet without patches.
Security vendor Check Point created an infection map for anyone curious about the latest global distribution of WannaCry here.
House of Mouse Hacked?
Disney has reportedly been targeted by cyber-extortionists who have pirated a copy of the Pirates of the Caribbean: Dead Men Tell No Tales, threatening to release the movie online if a ransom is not paid. Netflix was similarly targeted when a third-party production company was reportedly compromised and leading to episodes of the Orange is the New Black being were leaked online. Infosecurity Magazine reported on it here.
Thus far, Disney has refused to cooperate, raising the possibility that “Pirates” could hit the Internet before its planned release date.
No Jailbroken Phones on Your Network. Are You Sure?
Dark Reading recently covered findings from mobile security vendor Lookout. According to the article:
A jailbroken iPhone or a rooted Android phone that connects to the corporate network is one of the greatest fears of CISOs and other security team members, according to a new study. Their fears are not unfounded. Mobile security firm Lookout Security found five in every 1,000 Android devices in enterprises were rooted, while one in every 1,000 iPhones device was jailbroken.
DocuSign Phishing Campaign
According to Krebs on Security:
DocuSign, a major provider of electronic signature technology, acknowledged today that a series of recent malware phishing attacks targeting its customers and users was the result of a data breach at one of its computer systems.
Check out Krebs’ write-up to learn more and see a screen shot of a very convincing phishing sample.
560 Million Passwords Now Easier to Get
Reports emerged last week of a giant trove of new stolen passwords has surfaced online. According to CNet:
…while this database is composed largely of passwords from a variety of sources, many of them years old, its newfound accessibility — and conglomeration into a single collection — is cause for concern.
Cloud computing technologies have revolutionized the way organizations manage and store their information. Where companies used to house and maintain their own data, a host of organizations have now made the switch to a cloud-based model due to the ease of use and cost-saving benefits promised by the cloud.
But what is a cloud without a little rain? The benefits of cloud technologies have not come without their costs.
Within the world of cloud computing, there have been three persistent concerns:
Security
Security
Security
A quick search for the pitfalls and concerns organizations face with cloud computing yields a recurring motif. Every company looking to incorporate a cloud-based service has to weigh the benefits that a cloud environment affords against the risks associated with entrusting an organization with its sensitive data. This data tends to include personally identifiable information (henceforth referred to as PII), which is generally the most scrutinized category of data and is subject to some of the strictest legal and regulatory requirements.
Customers of cloud service providers want to rest assured that the PII they have entrusted a cloud service provider with is maintained and held to at least the same level of security standards that they would have placed if the data had remained within their control. For some organizations, the stakes are even higher as this is mandated by certain legal and regulatory requirements such as the Health Insurance Portability and Accountability Act (HIPAA) for electronic personal health information and the Graham-Leach-Bliley Act (GLBA) for sensitive financial information.
Many cloud service providers maintain that they are ignorant to the data ingested on behalf of their customers. However, in the event of a security breach involving either personal health information or sensitive financial data, significant fines and reputational damage can be incurred by the cloud service provider if appropriate security and privacy measures are not in place. This is where an effective information security management system, with specific control considerations tailored to cloud security and privacy surrounding PII, can prove invaluable to a cloud service provider.
You may have questions regarding what an information security management system is. To define an information security management system, it may be easier to first understand what it is not. An information security management system is not referring to an actual “system”, “application”, or “tool” that performs information security functions.
A broader definition is as follows: an information security management system represents the organization’s holistic approach to addressing information security concerns. This includes top management’s buy-in to addressing these risks which can be demonstrated in its actions by performing the following:
Fostering a top-down approach to information security that encourages personnel throughout the organization to be aware of information security best practices
Performing risk assessments that are tailored to its organization’s unique threats and vulnerabilities
Proactively searching for issues and concerns through the use and selection of internal auditors
Monitoring and measuring the performance and effectiveness of the information security management system
Establishing a commitment to continually improving the information security management system
Ensuring that security controls are implemented and applicable to its organization’s goals and purpose
The standard most commonly used to demonstrate an organization’s effective implementation of an information security management system is the ISO 27001 standard. The ISO 27001 standard serves as a baseline framework which virtually all service providers, cloud-based or otherwise, can work toward implementing. It is worth noting that ISO 27001 provides a multitude of benefits to organizations that implement an effective information security management system, but two are perhaps the most pertinent and deserve to be mentioned:
An effective information security management system demonstrates to prospective and current customers that the service organization means business about protecting the data that it is entrusted with and responsible for.
An effective information security management system assists organizations with establishing a forward-thinking, proactive approach to addressing information security concerns as opposed to enabling a backward-looking mindset which is generally fostered by audit culture, which typically focuses on historical information.
The above-mentioned points may be enough for any service organization to consider implementing an information security management system. The reputational benefit that an organization can enjoy by demonstrating to its customers that it takes its handling of information seriously is difficult to measure. The cost-savings that an organization can enjoy by implementing effective response procedures in the event of a security incident are also incalculable – just ask United Airlines. Sure, maybe that was a different kind of incident, but the age-old adage remains: failing to prepare is preparing to fail – this is the essence of ISO.
However, the buck does not stop at ISO 27001, especially for cloud service providers who by virtue of their trade must take information security more seriously. This is where organizations can implement, in addition to the requirements held forth by the ISO 27001 standard, a slew of measures to increase the security and privacy measures in place when handling sensitive data, such as PII. This standard is referred to as ISO 27018, which can be achieved in tandem with an effective information security management system in accordance with the ISO 27001 standard.
ISO 27018, otherwise referred to as ISO/IEC 27018:2014, builds upon an organization’s information security management system by establishing a group of privacy-based controls that are dedicated to protecting PII in public clouds that act as PII processors, with an emphasis on protecting PII in the cloud. ISO 27018 provides a new subset of controls dedicated to the protection of sensitive personal data.
A high-level overview of some of the ISO 27018 requirements are included below:
Providing cloud customers with the ability to access, correct, and erase their own PII
Ensuring that data is processed according to its intended purpose and not taken out of context
Procedures for the deletion of temporary files
Implementing defined disclosure procedures
Providing open, transparent notice in the event that sub-contractors are utilized
Encouraging accountability on behalf of the cloud service provider through the implementation of breach notification procedures
More stringent information security requirements on the part of the cloud service provider
Hopefully after considering the above, it is more clear that implementing an information security system aligned with ISO 27001 is tremendous for a service organization, but for cloud service providers hoping to assuage any security and privacy concerns for their customers, aligning these controls with ISO 27018 may be the organization’s best option.
As the technologies around us evolve, so do their underlying threats and vulnerabilities. An effective information security management system affords an organization a proactive, forward-thinking approach to information security. This is all the more important given that cloud computing technologies have been plagued with security and privacy concerns since their inception; the risks will only continue to increase.
If you represent a cloud service provider, it may be time to consider how your organization can benefit from the implementation of an information security management system that aligns its 27001 controls with the ISO 27018 objectives.