Behavox on course for Level 2 STAR Attestation from the Cloud Security Alliance

Rigorous Third Party Independent Assessment To Validate Company’s Security Posture

SEATTLE, WA – December 28, 2016 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, today announced that Behavox, the specialist AI enterprise software company offering compliance solutions for capital markets, has begun its audit towards achieving the Cloud Security Alliance’s (CSA) Level 2 Security, Trust & Assurance Registry (STAR) Attestation, a rigorous third party independent assessment of the security of a cloud service provider.

Schellman & Company, LLC (Schellman), a leading provider of compliance and audit services, is conducting the examination of the entirety of Behavox’s compliance platform.

“This is an important certification for Behavox and we are pleased to be working with the CSA which has set the worldwide industry standard for cloud transparency and security,” said Erkin Adylov, CEO of Behavox.  “With its rigorous approach to audit, the additional requirements beyond other standards such as SOC2, and the ability to gain this attestation through a credible third party audit arbiter like Schellman, our customers can be assured that we have the most stringent security controls and policies for cloud environments. With membership comes the need for continuous update and annual testing – there is no better evidence of our commitment to the highest standards of data security.”

The Behavox system provides multiple layers of defence for any regulated financial institution. At its core is the comfort that an institution’s entire data set (structured and unstructured): is held in a real-time accessible archive; is searchable; can be easily controlled (escalated; used for reporting; data retention); is presented holistically (for surveillance and other purposes); provides a full audit trail and a complete picture of every recorded interaction between an employee and another individual to facilitate discovery, trade reconstruction, full historic analysis of a contested situation.

“We look forward to helping Behavox and their team on their journey towards full compliance” said Jim Reavis, CEO of the CSA. “In adhering to the industry’s most stringent security controls, Behavox is set to join an elite class of cloud providers capable of effectively and securely meeting enterprise-level security needs.”

The CSA STAR program is the industry’s most powerful program for security assurance in the cloud and encompasses the key principles of transparency, rigorous auditing, harmonization of standards, with continuous monitoring.

Behavox has published its CSA STAR Self-Assessment documenting the extent to which its security controls and procedures are already compliant with the CSA’s required standards – the path to full compliance and third party audit confirmation is the next logical step for the business in 2017.

About Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, certification, events and products. CSA’s activities, knowledge and extensive network benefit the entire community impacted by cloud — from providers and customers, to governments, entrepreneurs and the assurance industry — and provide a forum through which diverse parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at www.cloudsecurityalliance.org, and follow us on Twitter @cloudsa.

About Behavox

Behavox is an enterprise compliance software company providing holistic employee surveillance solutions. Our solutions allow Senior Management, Risk & Compliance Officers to detect cases of market abuse, insider threat, collusion and reckless behavior in real time. Through the combination of cutting-edge technology, thought leadership and industry collaboration, we have created a Risk and Compliance ecosystem which transforms the way that firms conduct surveillance and supervise risk within their business. We provide an effective and scalable solution that delivers compliance with finance regulations such as Dodd Frank, MAR, FCPA, SMR & MIFID II. By linking structured internal communication (voice, email, chat etc) data with other internal unstructured data (GPS, browser history etc), users can discover, visualize and quantify relationships between people, organizations and content. In addition to this, the Behavox machine learning algorithms compare this data to a series of proprietary scenarios developed by our regulatory experts, which can also be configured to meet existing and future institutional policies.

Contacts

Kari Walker for the CSA
ZAG Communications
703.928.9996
kari@zagcommunications.com

[Cloud Security Alliance Research News]

Why Conquering Complexity Is a Critical Component of an Effective Security Program

Security professionals tend to have a penchant for making things more complicated than they need to be. But life and our work are complicated enough without us adding extra layers of needless complexity. When it comes to operating an effective enterprise security program, the old adage of “complexity being the enemy of security” really does ring true.

Many CIOs and CISOs are guilty of chasing the cool blinking lights of newer technologies and keep adding additional technologies to an already overburdened and poorly integrated security stack. Many enterprise security programs look like a scattered city of isolated Jenga towers. From a risk management perspective, the more complex the infrastructure, the harder it is to defend.

Balancing usability, security and complexity seems like a daunting task at times. Trying to do so on a daily basis costs many of us our sanity (think of Homer Simpson when he was forced to give up beer and TV!).

During one of my more salient moments, I came across a useful and applicable metaphor that security pros should heed when it comes to balancing that aforementioned unholy trinity: the purpose of a door is to control the flow of people to and from a house, room or building. If you were to put 50 locks on the door, it would most definitely be secure, but it would no longer function well as a door. The complexity would destroy the functionality. This is a sin that many security professionals are guilty of when it comes to securing business systems.

Many security teams have the tendency to secure business processes in such a way that they become cumbersome and difficult for employees to use. It should stand to reason that if the secure way of doing things is more complex and not intuitive for employees to use, then they will not use it. If the “secure” way of doing business is a complex, clunky, overly manual solution, do you really think employees are going to embrace it? Not a chance!

In fact, they will take shortcuts (which pose an even greater security risk) to avoid using the “secure” method. As a quick example, think of a clunky corporate file sharing service versus an intuitive and easy-to-use cloud storage service like Dropbox. When deploying “secure solutions” that are employee-facing, we need to remember that the solution should not only be as simple as possible (think path of least resistance), but security should enhance the overall user experience.

One of the best ways to rein in complexity is to not rush and provide technology solutions first. To best conquer complexity, teams should clearly define the business problem they are trying to solve and gather business requirements first (do not follow the new shiny objects). Defining the problem and requirements first greatly reduces the complexity.

I had a professor who would always say “It is better to have an approximate solution to an exact problem than an exact solution to an approximate problem.” After understanding and analyzing the business problem and requirements, only then should you begin steps for procuring a solution that matches your business requirements. Buying a technology solution and mashing your business requirements to match the technology is a sure bet to create a complex calamity.

Dominic Vogel, Chief Security Strategist, Cyber.SC

[ISACA Now Blog]

Why Cars Are Increasingly Vulnerable to Cyber Attack

Adrian Davis, Managing Director, EMEA at (ISC)² explains how we can stop the ongoing proliferation of vulnerabilities in connected cars

It’s clear that we are rapidly moving towards turning cars into rolling internet browsers, connecting to everything from traffic lights to household appliances. Future vehicles will get remote updates on traffic jams or weather, automatically alert emergency services to accidents as they happen, allow drivers to get over-the-air ‘upgrades’ without visiting a dealership and even warm up their kettles from their cars. Software updates can now give cars self-driving features, turn them into rolling Wi-Fi hotspots or even allow them to interact with traffic lights.

All of these features mean that cars are becoming mobile data hotspots, receiving and sending information that can be exploited by automotive firms to sell or create more people-centric products or services. This data can also be sold to other companies to target location-based advertising at drivers, or help insurance companies set their rates. It is predicted that connected cars will soon send up to 25 gigabytes of data to the cloud every hour.

Yet all the indications are that cybersecurity has failed to keep pace with increasing automotive connectivity. This was starkly illustrated earlier this year when a team of hackers remotely took control of a Tesla from 12 miles away. Many basic software vulnerabilities have been found in cars, including a failure to apply basic encryption to remote car-locking.

The problem is that manufacturers are treating cybersecurity as an afterthought to the design process, with flaws only being found and fixed after the car is already on the road. This ‘fire brigade approach’ to cybersecurity was exemplified by Fiat Chrysler’s recall of 1.4 million vehicles after security researchers exposed a software flaw which should have been found at the design stage. It is as if car manufacturers were to build cars and forget to put door locks on them until someone managed to break into the vehicle.

This problem extends far beyond the automotive industry; (ISC)² has found that software applications are often not scanned for vulnerabilities during software development. This means that application vulnerabilities still top the list of security concerns among information security professionals worldwide.

The current automotive design model sees software developers and security researchers as two separate silos of expertise that rarely meet. This produces a disjointed approach to security, leading to panicked vehicle recalls and emergency software updates.

We need to see security as a core aspect of the automotive software development profession, just as vehicle safety is a central aspect of the automotive engineering profession. Car companies should be building cybersecurity into every piece of software from the beginning, just as they incorporate car locks, airbags and seatbelts into the car at the design stage.

Instead of the software developers outsourcing the task of cybersecurity to security researchers, security should become a core part of coding, integral to every part of the software development lifecycle.

This will require a change in the way that coding is taught, with cybersecurity turned into a core component of all school, college and degree courses in computing and software development. The UK is pioneering this approach.

BCS – The Chartered Institute for IT, which accredits most University computing courses in Britain, recently incorporated cybersecurity guidelines and learning outcomes in its official accreditation criteria for its computing degrees for the first time. This means that cybersecurity will no longer be taught as a stand-alone subject, but will soon be part of every computing degree. Everyone from software engineers to game developers will have a common base of cybersecurity knowledge. The first General Certificate of Secondary Education (GCSE) questions on cybersecurity were recently launched, and schools have also been receiving cybersecurity lesson packs as part of school computing classes. Meanwhile, the UK Engineering Council now includes cybersecurity in its UK-SPEC competence requirements for engineering professionals.

But there cannot simply be a supply-side solution to this. The automotive industry needs to further incentivise the new approach by including cybersecurity as one of the key criteria in their hiring checklists for coders. Cybersecurity knowledge needs to be considered a requirement for entry-level software developers, just as we would expect all automotive engineers to understand safety features and requirements. The only way to ensure the safety and security of all road-users in the age of connected cars is to is ensure all future software is designed with an electronic version of locks and seatbelts.

[(ISC)² Blog]

CSA’s Big Data Working Group seeking new Co-chairs to develop and maintain Research Portfolio

The Cloud Security Alliance’s Big Data Working Group is seeking new co-chairs to develop and maintain a research portfolio providing capabilities to lead the crystallization of best practices for security and privacy in big data, help industry and government on adoption of best practices, establish liaisons with other organizations in order to coordinate the development of big data security and privacy standards, and accelerate the adoption of novel research aimed to address security and privacy issues. These volunteer positions will have a one-year term commitment at minimum. The co-chair works in collaboration with the CSA Research Team and work group volunteers. The work group co-chair positions include the following duties which are shared and typically alternated between co-chairs:

  • Lead the research team that defines the vision and concept of the Big Data Working Group
  • Plan out the roadmap for deliverables related to the Working Group
  • Represent CSA as the SME in the areas of data-centric security and related privacy issues
  • Assist with work group administrative duties (i.e. Running Working Group Calls, Promoting Involvement of WG Members, etc)
  • Assist with organizing events, deliverables, and initiatives related to the Big Data working group
  • Other duties should be defined by the reconstituted working group.

The co-chair positions for this work group will be a rotating position. Being a co-chair of the work group presents great opportunities such as networking and interacting closely with volunteers representing some of the top minds in information security and cloud computing. If you have questions or are interested in becoming the co-chair for the Big Data Working Group, or if you would like to nominate someone for the position, please please email Frank Guanco.

For your convenience, here is the Big Data Working Group Charter to be updated with new leadership and the other documents the working group has produced.

[Cloud Security Alliance Research News]

Call for Participation: Contribute to CSA Security Guidance V.4 Peer Review

Closing Date: Jan 13th, 2017

The Cloud Security Alliance would like to invite you to review and comment on 12 Domains of the CSA’s Security Guidance for Critical Areas of Focus in Cloud Computing. This document acts as a practical, actionable roadmap to individuals looking to safely and securely adopt the cloud paradigm. This is your opportunity to provide feedback and identify any critical areas that we might be missing in the document’s focus.

The Domains that are going for peer review are:

To participate, please identify specific Domains which you have expertise in and follow the link to the Google Docs. You should be able to provide your comments in the document. Please do not provide editorial comments (i.e. grammar, formatting, etc), rather focus instead on the content of the document.

The peer review for the 12 Domains start today and ends one month from now, on the 13th of January. We appreciate your assistance. Thank you in advance for your time and contribution.

CSA Research Team

research@cloudsecurityalliance.org

[Cloud Security Alliance Research News]

English
Exit mobile version