Standardizing Cloud Security with CSA STAR Certification

In early 2014 Dropbox joined the Cloud Security Alliance (CSA). Working with the CSA is an important part of Dropbox’s commitment to security and transparency.

In June of 2014 Dropbox achieved Level 1 Certification through STAR, the CSA’s publicly available registry, which documents how Dropbox’s security practices measure up to industry-accepted standards and the CSA’s best practices. Building on its Level 1 Self-Assessment, Dropbox recently announced CSA STAR Level 2 Certification which attests to its security controls and processes.

“Dropbox continuously proves to be at the forefront of compliance standards,” said Jim Reavis, co-founder and CEO of the Cloud Security Alliance (CSA). “With rigorous independent auditing and certification for both well-accepted and up-and-coming standards, they’re demonstrating an impressive dedication to their customers’ security. We’re excited to have Dropbox on the short list of companies that have achieved our Security, Trust & Assurance Registry (STAR) Level 2 Certification.”

Dropbox is dedicated to building trust with its customers across the globe, and helping them fit Dropbox into their compliance strategies. Dropbox is proud to work closely with the CSA to establish open and transparent cloud security best practices within the industry. Dropbox strives to stay ahead of the curve as new standards and certifications are introduced and will continue to partner with the CSA to support research and education in key cloud security areas.

Standards such as CSA STAR certification underscore Dropbox’s commitment to keeping customer data safe, operating at the highest levels of availability, and maintaining transparency in data storage and processing. And they demonstrate Dropbox’s leadership in the SaaS industry, as Dropbox is one of the first major providers to achieve CSA STAR certification. Dropbox is excited to make continued strides with these compliance milestones.

Tolga Erbay, Senior Manager, Security Risk and Compliance, Dropbox

[Cloud Security Alliance Blog]

Blockchain: The Glue That Binds the Internet of Things

One of the hottest emerging technology topics surrounds the Internet of Things (IoT), or as some have characterized it, the Internet of Everything. A McKinsey Global Institute report estimates that by 2025, the global financial impact of the IoT could reach between $3.9 trillion to $11.1 trillion a year.

Every industry will potentially benefit from this technology that relies on small sensors communicating among themselves and providing data that will drive exceptionally huge big data.

Smart sensors integrated into buildings could monitor and collectively control environmental conditions. Miniature medical sensors could keep healthcare workers informed and alerted about patients in hospitals or as they go about their normal activities. Manufacturing processes could self-control production providing instantaneous correction as sensors collaborate throughout the production of a product. Our self-driving cars will communicate with other vehicles and the roadway, navigating safe and quick transit to a desired location while providing city-wide information about traffic patterns to city planners.

IoT has the potential to dramatically change how things are done while significantly enhancing the quality of life for everyone. Our small experiments with home automation and building control are nothing compared to the automation we will see integrated into daily life and work.

The concept behind the IoT seems relatively simple. Multitudes of miniscule sensors will collect specific information, share information with neighboring devices, and communicate data to a repository where control can be coordinated or information massaged, giving never-before-seen insights. While this description is the basis for the IoT, it is not clear how devices will communicate and coordinate. It is not clear how innovative thinking could evolve new uses and business models around IoT that will result in significant levels of market disruption.

The most promising intra-device communication and data record among devices could well be blockchain. Blockchain is essentially a secure, distributed, peer-to-peer implementation of a ledger system that is most often associated with bitcoin monetary transactions.

The truth is that the blockchain ledger can contain any information, including heath records, identity, and non-financial transactions. A really interesting use is developing smart contracts using blockchain as the organizing infrastructure. Smart contracts could bind individuals, or for IoT, sensors that share information, and when a certain condition is met that is a metric included in the e-contract, a pre-programmed response is initiated. This could be a payment in the case of business-to-business relationships.

Between devices, smart e-contracts could be associated with carbon credits, power creation and consumption, or any number of other device-to-device activities. At an even higher level of organization, IoT sensors could be implemented within a Distributed Autonomous Organization (DAO) to achieve some end result but governed completely within the smart contract that established the DAO.

The genius of the IoT is not that there are multitudes of small sensors creating terabytes of data, but that there is a system of devices sharing information in an intelligent and controlled manner that achieve a result within a self-governing structure. The thing that binds these sensors, providing both governing and the ability to act intelligently, will come from the blockchain.

Ron Hale, Ph.D., CISM, Chief Knowledge Officer, ISACA

[ISACA Now Blog]

Fishing vs. Hunting for an IT Assurance Job

The Internet is awesome, isn’t it? At any moment, you have the ability to see hundreds of job postings and post your resume for all to see. However, if the only thing you are doing to find a job is fishing by dropping your resume “lure” in the water hoping for a hiring manager to bite, you will be waiting a while.

You need to get out and hunt for your next job. Know the terrain, have spotters in the field, pick the right tree to sit under. Truth be told, I know nothing about actual hunting but, after nearly 10 years of helping IT assurance professionals find new opportunities, I know a few things about hunting for a job.

Here are my top three tips:

Don’t Post Your Resume Online
Monster, CareerBuilder, Indeed, Dice; I have nothing against these services, but you are not their target audience. If the service is free, you are the product, right? The main problem with posting online using these types of sites is that you immediately lose control over where your resume ends up.

One of the pitfalls of the typical recruiting firm is what I call the shotgun approach. They fire your resume in every direction to every client they have, hoping that someone will want to interview you. Now you are faced with a potential situation where your resume is in front of a hiring manager (if it makes it there, more following) from multiple sources, and you start to look desperate.

There are ways you can safely post your resume online anonymously. But, it is hard to do, and even the most “scrubbed” resume can still be figured out. (Word document author metadata, anyone?) Yes, I even see professionals in the information security space get it wrong. It is safer just not to mess with it.

Instead:

Use Your Relationships
The common belief is that only a small percentage of jobs are actually posted online. Not sure if that is completely true anymore, but I can tell you that most hiring managers have an idea of who they want to hire long before the posting goes up. You want to be the person they think of.

Make sure your personal brand in the marketplace is a positive one. I am always surprised at just how small our IT assurance world is. Make sure people know you for being honest, self-motivated, dependable and collaborative, and word will start to spread about the positive impacts you have had on your organization. Be intentional about networking. Seek out people at ISACA events who work at companies you are interested in. Don’t just add people on LinkedIn, take them to coffee. Make relationships and use them.

Applying Directly Online
It should be your very last option. I’m not telling you to never apply online. What I am saying is use what I’m about to tell you first, and if you still come up empty, that is the only time I would suggest applying directly online. The companies that pay to advertise their job openings will not even be upset at this. Their goal is to make sure they see qualified candidates, and if you became aware of their opening through their online listing, then their money was spent wisely.

I hear it all the time: “I applied to this job online but never heard anything back.” I know for a fact that job-seekers who could have gotten the job they applied for do not get contacted at all because the resume never makes it to the right person. Most companies have talent acquisition teams with increasingly complex systems that are heavily dependent on keyword filtering. I don’t blame HR or talent acquisition teams for wanting to use these filters. Their job is tough. They have to work on potentially hundreds of jobs at the same time. They can’t possibly dig into the level of detail it would take to understand what it takes to be successful in an ISACA-related position.

Applying to a job without an external or internal advocate will more than likely result in silence. You need someone who knows your values, personality and skill set who can help you get visibility with the hiring manager, the real decision-maker in the hiring process. It all comes back to reputation and relationships.

This is just the very tip of the iceberg on how to successfully navigate an IT assurance job hunt, and the first in a series of ISACA Now blog posts I am planning on IT assurance interviewing and hiring. If you have additional questions or a topic you would like to see discussed in the future, feel free to post them in the comments section.

Author’s note: What tips for successful job hunting have I missed? What is the best or worst piece of job search advice you have ever been given?

Brad Owens, Recruiting Director, Duval Search

[ISACA Now Blog]

Support Design Should Begin at the Start

Everyone can think of a moment when they have experienced a problem with goods or services. Everyone can also think of a moment after the problem that…wait for it (drumroll)…there was poor customer support or no support at all.

So where does the disconnect between an enterprise’s strategic objectives and its failure in the eyes of the customer begin? Could this failure have been avoided from the start?

Here’s how it happens:  Oftentimes an enterprise reviews its strategic plan, which is a process that often generates new ideas and a new focus on how to achieve its objectives. A critical factor in achieving these objectives is IT. As part of this effort business cases are created and reviewed with due diligence and care, focusing on risk analysis, costing and other key planning issues. Approvals are given at various levels, and once the green light is reached, we then develop the product/service/upgrade, with implementation to follow.

Imagine that all of the above stages are completed and the enterprise has just successfully launched a new service to customers through its digital channel. The product is marketed well and it is disruptive, so this results in huge demand from customers. At this point it may seem that all is well and good; however, as with all things, problems are going to occur and customers (internal/external) will be affected.

This is where the true test begins and where many enterprises fail because proper support systems were not put in place at the start. There are several reasons why this can occur, including a lack of foresight at the beginning, a focus on being first to market over competition, improper resource analysis, a lack of training, a poorly developed service level agreement (SLA) or no SLA review.

Just as security and risk are key considerations, proper support mechanisms should be considered when implementing your enterprise IT governance structure since this is a form of risk mitigation in itself. You can implement the most state of the art IT infrastructure that strategically aligns with your enterprise’s objectives and delivers super-fast service; however, if there is no support for the 100 percent certainty that something will go wrong, then all becomes useless. Design your framework so that failures are welcomed and not left to chance.

Ammett Williams CCIE, CGEIT, Telecommunication Team Leader – First Citizens, TT

[ISACA Now Blog]

Insurance Carrot Beats Government Stick in Quest for Stronger Cybersecurity

When it comes to cybersecurity, the U.S. federal government recognizes the carrot is more effective than the stick. Instead of using regulations to increase data security and protect personal information within private organizations, the White House is enlisting the insurance industry to offer incentives for adopting security best practices.

In March 2016, the U.S. House Homeland Security Cybersecurity Subcommittee held a hearing to explore possible market-driven cyber insurance incentives. The idea, said Rep. John Ratcliffe, chairman of the subcommittee, is to enable “all boats to rise, thereby advancing the security of the nation.”

The issue isn’t a lack of cyber insurance. Today, 80% of companies with more than 1,000 employees have a standalone cybersecurity policy, according to a Risk and Insurance Management Society survey. The real issue is getting companies to maintain more than a minimum set of security standards.

Borrowing from the fire insurance playbook
The insurance industry has been a catalyst for change in the past. Attendees of the Homeland Security Cybersecurity Subcommittee hearing pointed to the fire insurance market as a good example of using a carrot to drive positive behavior. Insurers offer lower rates to policyholders who adhere to certain fire safety standards, such as installing sprinklers and having extinguishers nearby.

Identifying best practices
So, what are the cybersecurity equivalents of sprinklers and fire alarms? Hearing attendees highlighted four components of an effective cyber risk culture:

  • Executive leadership: what boards of directors should do to build corporate cultures that manage cyber risk well.
  • Education and awareness: training and other mechanisms that are necessary to foster a culture of cybersecurity.
  • Technology: specific technologies that can improve cybersecurity protections.
  • Information sharing: ensuring the right people within the company have the information they need to enhance cybersecurity risk investments.

Spurring much-needed actuarial data
The hearing also touched on a major missing element in the current cyber insurance industry: reliable actuarial data regarding data breaches and other cyber incidents. Auto insurers know the likelihood of car accidents, so they know how to price the liability and measure the risk. But the likelihood and ramifications of various data breaches are a wildcard today, leading to problems in pricing cybersecurity policies.

Hearing attendees discussed creating an actuarial data repository with data from leading actuarial firms, forensic technology firms and individual insurer cyber claims. The proposed database would be housed at a nongovernmental location such as the Insurance Services Office Inc. (ISO), which has managed insurer actuarial databases for more than four decades. The hope is the database would encourage voluntary sharing of information about data breaches, business interruption events and cybersecurity controls to aid in risk mitigation.

While the cyber insurance carrot is a long way from becoming reality, at least the seed has been planted.

Laurie Kumerow, Consultant, Code42

[Cloud Security Alliance Blog]

English
Exit mobile version