Building a Security Transformation Program in Our New Information Security World

From an information security perspective, companies often have perceived their own organization as a castle with well-defined walls, with few entry points sufficiently staffed with guards monitoring what information is coming in or leaving the organization. If further protection is needed, it is obvious what to do: build higher or thicker walls or add additional security guards. What is inside the castle can be considered safe.

However, there have been several significant changes in the past few years, namely:

  • New business models and supply chain dependencies transcending traditional company and information boundaries
  • Advances in technology and digitization increase ICT reliance
  • Increasing reliance on external parties and their security approach
  • Scarcity of resources, be it financial or human resources
  • Increased regulatory requirements supporting the shift from a protection focus to a detection/response focus (e.g., GDPR)
  • Changes in the cyber threat landscape (e.g., crime-as-a-service, espionage)

This means that reliance on traditional perimeter security is no longer sufficient, a mindset that information security professionals have been advocating for several years. The National Institute of Standards and Technology (NIST) in the US, for instance, has developed a model by mandating an ‘Identify – Protect – Detect – Response – Recover’ approach.

The next generation CISO
So why are so many companies still struggling to adopt this approach? A CISO of a reputable company once said: “I was hired for my technical security skills; however, I do not know how to build an organizational change program.” The next-generation CISO not only needs an understanding of security challenges, but also needs to deliver this change in a programmatic approach.

The need for a step-change in information security
What is needed is a way to package the NIST thinking into an information security transformation framework considering the organizational model of companies.

The goal of the different components:

  • Governance, risk and compliance: Align the approach to the company’s governance model and build alliances with related functions, such as risk management, corporate security, compliance and audit.
  • Secure architecture: Ensure a ‘security by design’ approach.
  • Secure baseline: Do the fundamental things right (e.g., patching, monitoring, adopting good IT operations practice).
  • Cyber threat management: Understand the threat environment and provide appropriate incident response.
  • Training and awareness: Address the human factor in information security.

Define KPIs
By first comparing the current organizational capabilities against future need, we can determine how fast and in which areas a company needs to act. Derived from this assessment, the projects can be planned and budgeted covering several years, including sourcing requirements (in-house or managed security provider). Each year, the required capabilities are re-assessed considering the threat landscape, business strategy and technological advances.

One key element is the definition of KPIs to measure the progress for each framework component. These KPIs help to communicate the benefits of a multi-year program to senior management. The assignment of skilled project/program management resources also helps to maintain the focus rather than daily operational tasks superseding project/program goals.

Experience so far
Taking this approach, we have experienced the following changes:

  • Shift toward a holistic view: from a tool discussion to a capability-based discussion covering people, process and technology.
  • Regular re-assessment of capability profile, threat landscape and business strategy define the security projects for the coming year.
  • Capability needs drive security strategy and implementation priorities.
  • A failure to meet incident resolution target KPIs resulted in a root cause analysis and renegotiation of service level agreements (SLAs) with vendors.

New threats demand a new mindset – and approach – for information security professionals.

Editor’s note: Monika Josi will present on “Building a Sustainable Security Program” at ISACA’s EuroCACS 2017 conference, which will take place 29-31 May in Munich, Germany.

Monika Josi, Head of Group Security Consulting, AXAS AG

[ISACA Now Blog]

What To See in Austin – Security Congress Sessions Announced

With less than 150 days until Security Congress, the full agenda has been released. Keynote speakers include Ben Makuch, national security reporter for VICE News, Donald W. Freese, deputy assistant director at the FBI, and Juliette Kayyem, founder of Kayyem Solutions.

The seventh annual conference will be hosted at the JW Marriott Austin, September 25-27, 2017. There will be 11 tracks at this year’s event, including:

  • Cloud Security
  • Cyber Crime
  • Critical Infrastructure
  • Incident Response & Forensics
  • Governance, Regulation & Compliance
  • Identity Access Management
  • People & Security
  • Professional Development
  • Software Assurance/Application Security
  • Swiss Army Knife
  • Threats

We listened to the feedback from past year’s events and this year, cloud security is the largest track with three FULL days of sessions on the topic. The Swiss Army Knife track also returns this year. This track is a potpourri of cybersecurity topics that impact practitioners and sessions will include tips, tools and tricks to help attendees in their day-to-day work.

New this year are workshops, with topics including “Can IT and OT Ever Come to the Same Table?” and “CISO Skill Set: The Tools and Techniques You Need to Succeed.”

The Center for Cyber Safety and Education will also be presenting a session for Safe and Secure Online Volunteers, “I’ve Completed Orientation, Now What?” to help members put their knowledge to use and help their community – children, parents and seniors – stay safe online.

If you’re not a member of your local (ISC)² Chapter, be sure to attend the information session hosted by Jayda Shriver, Chapter Program Manager. The session, (ISC)² Chapters: Membership Has Its Benefits, will discuss ways to learn how to join, or start, a chapter in your local community.

View the full Security Congress agenda online now and register before July 31 for early bird savings.

[(ISC)² Blog]

The Darknet and Deep Web: What Are They, and Why Should I Care?

In this age of growing technology, we trust the Internet. We trust it with making secure payments, storing our medical history and sharing personal photos with family and friends. We trust a website when it claims our information is safe from intruders and that when our information is posted privately, it is only ours to see.

However, once information is posted, sent, or clicked, it is public. Hackers can crawl into these supposedly private portals and extract information.

The vast Internet consists of three layers. The first layer is public, consisting of sites we use frequently such as Facebook, Twitter, Amazon and LinkedIn. This layer makes up only 4 percent of the entire Internet.

What is the other 96 percent? The deep web and the darknet. The deep web, the second layer, is a network where data is stored in inaccessible databases. The darknet is the third, deeper layer of the Internet where hackers congregate and facilitate illegal meetings. Customers whose data is breached do not have access to the darknet.

Tor (originally short for The Onion Router) began life as a U.S. Navy project for anonymous online activity but is now used by a wide range of groups, including the military, journalists, bloggers, activists and, yes, criminals. Tor makes communications harder to trace through traffic analysis by routing Internet activity through a series of network nodes, each ignorant of the whole route from beginning to end. The trade-off for increased security is slower speed.

To surf the darknet, we use a browser that allows us to access .onion sites with call browsers like:

  • Tor Browser
  • TAILS
  • Onion Browser

Or, websites like “Tor2Web” and “Onion2web” can be used, which allow users to easily access .onion sites on browsers like Google Chrome. As easy as this may be, it guarantees that your IP address is exposed – and when this happens, you’re open to all sorts of attacks from hackers.

Here are some steps to protect your computer:

  • When users surf the darknet, it opens up their computer to possible malware and scans that can compromise their network. Do not surf the darknet from a work computer on your work network. Use a computer that you are willing to rebuild, and use a VPN to protect your network connection. I would also advise using software that can protect your computer from any unauthorized changes such as:
    • Deep Freeze
    • Sandboxie
    • SmartShield
    • SysFreezer
  • Be safe and do not enable any Macros or scripts on a .onion site
  • Do not download files off untrusted or unknown sites.
  • Do not buy anything on the darknet because there are lots of scams. Buyers may never even hear from the seller, and what you are buying may be illegal.
  • Be careful of what you may find on the darknet because it could be related to something illegal – drugs, weapons, hackers, pornography and classified data. You may have to report to the authorities what you find and explain what you were doing. Furthermore, nearly all darkweb transactions use cryptocurrencies like Bitcoins, so it’s completely untraceable, and a refund is usually out of the question.
  • Do not make friends or enemies on the darknet; messing with a hacker can potentially ruin your life.
  • You can use services that will search for you, or allow you to search in a secure manner, like Harris corporation’s TORNADO.TM

What are some reasons to search the darknet? There could be company data that may be on the darknet now, such as user name and passwords, network maps, and other confidential data that could be problematic. Once users become good at searching the darknet, they can create a seed file. A seed file is kept internally by companies. Finding them on the darknet is an indication that the company has been compromised.

Editor’s note: To learn more about this topic, an archived webinar, “The Dark Web – A Threat To Your Business?,” is available at www.isaca.org/Education/Online-Learning/Pages/Webinar-The-Dark-Web-a-Threat-to-Your-Business.aspx.

Jay Ferron, C|EH, CISSP, CHFI, CISM, CRISC, CVEi, MCTIP, MCSE, MVP, NSA-IAM, past president Greater Hartford ISACA Chapter, Interactive Security Training, and Tim Singletary, CISSP, CISM, CRISC, CTT+, C|EH, Security +,A +,Net+ ,Linux+, Harris – Information & Cyber Solutions

[ISACA Now Blog]

Are Women the Answer to the Cybersecurity Skills Gap?

Information security is one of the most important and fastest growing professions in the world, possessing a near-zero unemployment rate, but also a worker shortfall that grows larger every year. Most organisations admit that bridging the industry’s skills gap, while attracting women into cybersecurity is crucial; yet female participation has remained static since I began working with our Global Information Security Workforce Study programme in 2004.

When we first began benchmarking the development of the cybersecurity workforce, analysts projected a double-digit growth that has since been realised. Today we forecast a skills gap projected to reach a shortage of 1.8 million by 2022. The obvious implication being here that the trend can’t be explained by a lack of available jobs: hiring managers participating in the study admit that they struggle for as long as six months to fill positions.

Additionally, new research from (ISC)²’s charitable arm, the Center for Cyber Safety and Education™, found that women comprised only 8% of the UK’s information security workforce – a number that has been stagnant since 2013. The study also suggested that initiatives to attract women aren’t proactive enough or that the profession isn’t as committed to building the balanced and sustainable workforce as it claims to be.

But if the level of women in information security were to double, it would fill the anticipated workforce gap. The clear need for talent makes the apparent lack of progress on this front baffling.

Join the conversation as industry leaders discuss why we struggle to attract more women into information security

Next month, a global panel of industry thought leaders from the USA, Australia and UK will each bring their unique perspectives to the table while exploring and debating the recent findings from our Global Information Security Workforce Study; as well as discussing concrete steps in closing that imminent cybersecurity workforce gap.

The Frost & Sullivan webinar Women in Cyber: Why Can’t We Attract Them? will feature leading information security experts, including Jarad Carleton (Principal Consultant – Digital Transformation Practice, Frost & Sullivan), Richard Horne (Partner – Cyber Security, PwC UK), Professor Jill Slay (Director – ACCS, UNSW Canberra), Lynn Terwoerds (Executive Director, Executive Women’s Forum) and Vicki Gavin (Head of Business Continuity Information Security and Data Privacy, The Economist Group), who will be examining many of the issues faced by the sector and females, including equality challenges for women in the profession. They will also put forward proposed recommendations that will endeavor to offer equal opportunities for all professionals, such as compulsory quantitative key performance indicators to bring about a gender-balanced workforce.

Only by developing the profile of our workforce should we be able to attain a truer reflection of talent and fulfill the needs of our digital society. It will be interesting to see whether companies answer the call for progress within the industry, as well as the experts’ take on how this can be achieved.

Lyndsay Turley
Head of Comms & Public Affairs, (ISC)² EMEA

 

Webinar details: Women in Cyber: Why Can’t We Attract Them?

A Global Information Security Workforce Study debate

Wednesday, 3rd May 2017 – 1:00 PM BST / 8:00 AM EDT

To submit a question that will be answered live during the briefing, please email: Gil_Briefings@frost.com.

Register for this event  and follow us on Facebook and Twitter.

[(ISC)² Blog]

Help ISACA Mark its 50th Year, Look Toward the Next 50

Planning is well underway to lead into ISACA’s 50th year in 2019, mark the anniversary, and carry momentum forward into the next decade and beyond. From outreach nearly a year ago to ISACA’s past presidents —an early tap of their ideas and insights — to anniversary footings now in place, importance, inclusivity, curiosity and enthusiasm characterize efforts to date.

And today is an important date, as ISACA debuts one of those footings — and a digital one at that. The first phase of our anniversary microsite, www.ISACA50.org, is up and running. The site will serve as a hub for stories, to gather and share history, for celebrating toolkits, to post anniversary news and updates from around the global, and to predict our future. It will lead the way to bring our anniversary theme to life:

Honor Our Past. Innovate Our Future.

As you read this, the site is having its first show-and tell during the ISACA Regional Leadership Conference, beginning today in Las Vegas. The site, the celebration underway and to come, is theirs, yours, ours. It has taken a collective effort to reach such a proud milestone, so it is only natural that the global ISACA community enjoys the celebration together: ISACA50.org is just the start. We encourage you to share your story of what ISACA means to you, as well as any images, videos or other materials — whether related to ISACA or the professions we serve — that will help enhance anniversary programming.

The anniversary logo is featured prominently on ISACA50.org. There is meaning to its design, and we hope you sense its energy. Concentric circles in the “50” represents the perpetual motion and innovation that have been hallmarks of ISACA’s past and present, and will be even more prominent going forward. Fittingly for a future-minded tech organization such as ISACA, envisioning and embracing the possibilities of the next 50 years will be a rallying point of our celebration.

Beyond the web portal, there are many other in-progress plans to commemorate this demarcation of the past and future. Another foundational element is an immersive, innovatively designed event exhibit. Preliminary concepts feature interactive, responsive technologies to illustrate history, ISACA contributions and milestones, people and impact, and a central “Future Visions” booth to capture and enhance visitor experiences and aspirations — for themselves, for ISACA, for our industry and for the world.

A third and just as essential early anniversary element are plans, creative programs and packaged toolkits to prompt celebrations of all shapes, sizes and durations by and for ISACA chapters, volunteers, leaders, members and engaged professionals the world over. The anniversary provides a clarion call, as ONE global community, to deliver ISACA’s Purpose and Promise:

  • Help you realize the positive potential of technology
  • Inspire confidence that enables innovation through technology

Indeed, you will see, hear and feel the impact of Purpose and Promise as we honor, and as we innovate over the course of our anniversary years.

ISACA has an incredible story to tell. Consider the seismic shifts in technology that have unfolded since 1969, when a small group of individuals in the Los Angeles area formed the EDP Auditors Association, which eventually became ISACA. For the past five decades, ISACA has been at the forefront of helping professionals and their enterprises navigate the fast-moving technology landscape. Our ability to do so for the next 50 years is even more imperative given the scale of global digital disruption we’re experiencing.

This is a special time for ISACA. Our global professional community — growing each year in number and impact — will honor our past and innovate our future together. It will be a fun, enlightening and rewarding celebration.

Stay tuned – there will be much more to share, know and do in the coming months and years. It is time to Honor Our Past. Innovate Our Future. A first visit to www.ISACA50.org is a great place to start!

[ISACA Now Blog]

English
Exit mobile version