Africa CACS Keynote Herman Konings to Introduce “Cathedral Thinking”

Trend analyst and consumer psychologist Herman Konings will present the Africa CACS 2016 closing keynote address, titled Cathedral Challenges: What Happens After What Comes Next? Konings is a genuine storyteller who inspires the spectator on an engaging course about the amazing world of passions and interests, trends and future expectations, and about what is and what will be.

Africa CACS will take place at the InterContinental Nairobi, Kenya, from Monday, 8 August to Tuesday, 9 August. For more information click here.

The following is a question-and-answer session with Konings.

ISACA NOW:  What major societal trends do you see in the near and long terms?
KONINGS:  To understand trend watching, it is vitally important to know what a trend is. It is not, as many think, a term exclusively associated with the world of marketing, fashion or design. At its most essential, a trend can be defined as the direction in which something/anything tends to move and which has a consequential impact on the society, culture or business sector through which it moves.

Trends are, therefore—as London-based trend forecaster Martin Raymond describes—a fundamental part of our emotional, physical and psychological landscape; and by detecting, mapping and using them to anticipate what is new and next in the world or business, we are contributing to better understanding the underlying ideas and principles that drive and motivate us as consumers, citizens, users, creators, and decision makers.

From a global point of view, interesting (societal) trends are, among other things, the growth of life expectancy (and the related overpopulation), the digitization of jobs, the sustainability (including mobility) challenge and the collaborative mindset of Generation Y. I have the strong conviction that these global trends are “true” global trends, not only relevant for Northern America, Europe or the Far East, but in the “long-near” (= within 5 to 10 years) also self-evident for Africa.

ISACA NOW:   As a trend watcher, what have you learned about the portability of trends? Does a trend in Europe, for example, generally translate into a trend elsewhere? Can you predict portability? Also, can you predict which trends will move from fad to mainstay?
KONINGS:  A legitimate question is whether trends are portable from one region or even continent to another. Can a trend detected in Europe take root in, for example, Sub-Saharan Africa? The answer is quite complex. One has to take into consideration different demographic, economic, socio-cultural, technological, ecological, political and—maybe the most tricky of all—psychological circumstances. On the other hand—and this is promising—the profound globalization of the 21st century means that younger generations (the so-called “Millennials”—GEN Y—and “Digital Aboriginals” —GEN Z) are behaving more and more in the same way as their peers on other continents. The similarities within a global age group have never been more pronounced as within the group of teenagers and twenty-somethings of today. This will obviously enhance the portability of trends associated with young adults.

ISACA NOW:  What will attendees of Africa CACS take away from your presentation?
KONINGS:  On 9 August, I will introduce the idea of “Cathedral Thinking.” Short-term, instant-gratification thinking seems to fail. Both consumers and business leaders are reconsidering the idea of long-term thinking. Like builders of cathedrals in medieval times (in Europe), when fathers passed the task on to sons, who in turn passed the task on to their sons. Once initiated to the job, cathedral builders knew exactly that neither they, nor their children, grandchildren or even grand-grandchildren would be joining in the housewarming party of that cathedral.

The attendees of my presentation at Africa CACS will learn, among other things, about sensors leading to an Internet that is more adapted to the individual, turning the Internet of Things into an Internet of Me. I will also be discussing the humanization of the digital and “augmented intelligence,” the joint forces of hyper-cognitive intelligence (supercomputers) and both social and emotional intelligence of (bio only) humans.

For more information on Africa CACS, click here.

[ISACA Now Blog]

COBIT 5, Creating an Audit Program and Enabling Compliance

Last year I wrote an article that discussed using COBIT 5 to audit cyber controls, in this instance the Australian Signals Directorate (ASD) Top 4. At the time of writing this article I had the privilege of being an expert reviewer on a draft ISACA white paper on creating an audit program. This white paper has now been released.

In the Australian government, as with all governments around the world, compliance against legislative and regulatory requirements is an important factor for the various government entities responsible for the delivery of functions for the Australian government. As a result, the internal audit programs for these government entities generally have a strong focus on compliance factors. Within the Australian government, entities are required to comply with a myriad of legislation, regulations and rules, including (but not limited to):

  • The Protective Security Policy Framework
  • The Information Security Manual
  • The Public Governance Performance and Accountability Act (and associated legislation)
  • The Commonwealth Procurement Rules
  • The Commonwealth Risk Management Policy
  • Whole-of-government ICT Policy
  • The Commonwealth Fraud Control Policy

Each government entity is also required to comply with their individual enabling legislation and regulations, as well as laws and regulations that any business and organization must comply with. In recent times, the following have been a focus of internal audit programs:

  • Workplace health and safety requirements
  • The Privacy Act

As discussed in my article about the ASD Top 4, internal audit has traditionally taken a yes/no approach to auditing compliance in government. For instance, if an audit on procurement was scheduled on the audit program, an auditor would take a sample of recent procurements, assess them against the regulatory requirements and internal policy and procedures, and produce a report that outlined instances of noncompliance.

In my opinion, this approach is useless. It does not help management understand why there was noncompliance and how they can prevent noncompliance. This white paper goes through a 5-step process to develop an audit plan:

  1. Develop an audit plan.
  2. Define audit objective.
  3. Set audit scope.
  4. Perform audit planning.
  5. Determine steps for data gathering

These five steps provide details on how to put together an effective audit plan that can ensure that you help management. It very deliberately guides you on what to consider and prepare in the planning process so you are better prepared to undertake the audit. This will help ensure that when undertaking an audit of legislative compliance in government, you move away from the traditional yes/no approach and consider the factors or, to use a COBIT 5 term, the enablers that actually help management achieve compliance.

David Berkelmans, CISA, Executive Director IT Audit, Synergy Group

[ISACA Now Blog]

What You Need to Know: Navigating EU Data Protection Changes – EU-US Privacy Shield and EU General Data Protection Regulation

If you’re an organization with trans-Atlantic presence that transmits and stores European citizen data (e.g. employee payroll & HR data, client & prospect data) in the U.S. you will want to pay attention. What we will discuss was administered under the European Union’s Data Protection Directive and a previous EU-U.S. agreement called Safe Harbor.  We will cover what happened, what’s next, new rules (and penalties) that are set to go into effect and our recommendations.

What Happened?
Safe Harbor, invalidated by a European Court of Justice (ECJ) ruling (PDF) in October 2015, allowed companies to transmit and store EU citizen data in the US so long as the U.S. companies agreed to meet requirements as described in Decision 2000/520/EC otherwise known as ‘Safe Harbor Privacy Principles’. The European Court of Justice ruled to invalidate the Safe Harbor agreement as it determined that US companies were not able to meet Safe Harbor Privacy Principles as they conflicted with National Security Agency or other government agency subpoenas request for information and other government data collection programs.  Data on EU citizens was found as a result of US government surveillance program information being made public. In other words, if U.S. companies were complying with Safe Harbor Privacy Principles, that information would not have been found or made public as a result of those programs.

What’s Next…
In early February 2016, the US Department of Commerce and the European Commission announced a new framework called the Privacy Shield. Since then, a group known as the Article 29 Working Party, Europe’s data protection body, issued its own statement (PDF) about the Privacy Shield framework and expressed their reservations regarding the adequacy of the “Privacy Shield.” On July 8, 2016 the European Union Member States Representatives approved the final version of the Privacy Shield. The new Privacy Shield framework allows for transatlantic data transmission and outlines obligations on companies handling the data, in addition to written assurances from the U.S. that among other items rules out indiscriminate mass surveillance of European citizens’ data.

Additionally, in early 2016 the European Union enacted a new data protection framework that has been in the works since 2012, known as the General Data Protection Regulation. This new Regulation repeals and replaces the pre-existing European Union’s Data Protection Directive. While not much has changed in the new ‘Regulation’ U.S. companies should note that policies and procedures as it relates to employee data transmission from the EU to U.S. be updated as well as be aware of new penalties. The new rules of the Regulation (and penalties) “will become applicable two years thereafter.” So, in 2018, the rules and penalties around the General Data Protection Regulation will go into effect.

New Rules that will go into effect (enforceable, starting in January 2018):

  • Strong obligations on companies handling Europeans’ personal data and robust enforcement:U.S. companies wishing to import personal data from Europe will need to commit to robust obligations on how personal data is processed and individual rights are guaranteed. The Department of Commerce will monitor that companies publish their commitments, which makes them enforceable under U.S. law by the US. Federal Trade Commission. In addition, any company handling human resources data from Europe has to commit to comply with decisions by European DPAs.
  • Clear safeguards and transparency obligations on U.S. government access: For the first time, the US has given the EU written assurances that the access of public authorities for law enforcement and national security will be subject to clear limitations, safeguards and oversight mechanisms. These exceptions must be used only to the extent necessary and proportionate. The U.S. has ruled out indiscriminate mass surveillance on the personal data transferred to the US under the new arrangement. To regularly monitor the functioning of the arrangement there will be an annual joint review, which will also include the issue of national security access. The European Commission and the U.S. Department of Commerce will conduct the review and invite national intelligence experts from the U.S. and European Data Protection Authorities to it.
  • Effective protection of EU citizens’ rights with several redress possibilities: Any citizen who considers that their data has been misused under the new arrangement will have several redress possibilities. Companies have deadlines to reply to complaints. European DPAs can refer complaints to the Department of Commerce and the Federal Trade Commission. In addition, Alternative Dispute resolution will be free of charge. For complaints on possible access by national intelligence authorities, a new Ombudsperson will be created.

New Penalties that will go into effect (enforceable, starting in January 2018):
Under Article 79 of the Regulation, penalties and enforcements are described for Organizations less than 250 personnel and Enterprises. Violations of certain provisions for Enterprise organizations (> 250 employees) will carry a penalty of “up to 2% of total worldwide annual [revenue] of the preceding financial year.” Violations of other provisions will carry a penalty of “up to 4% of total worldwide annual [revenue] of the preceding financial year.”  The 4% penalty applies to “basic principles for processing, including conditionals for consent,” as well as “data subjects’ rights” and “transfers of personal data to a recipient in a third country or an international organization.”

What should U.S. companies consider?
There are a few options we’ll highlight here such as conducting Privacy Assessments with Privacy Shield and GDPR regulations in mind, ISO 27001 / 27018 certification, cyber risk program development to include vendor risk management, incident response planning and cyber risk assessments.

What to do – Privacy Shield
As it relates to the new EU-U.S. Privacy Shield, companies should review and be aware of the legal requirements outlined in the Privacy Shield (PDF). For certified Safe Harbor organizations, continue to abide by those elements within Safe Harbor, as you still have an obligation to protect EU data transfers, and begin to incorporate the Privacy Shield requirements as you will have to obtain certification (in-house or third-party) to gain listing on the Privacy Shield website maintained by the Department of Commerce.

Specifically, “It requires participating U.S. organization to develop a conforming privacy policy, publicly commit to comply with the Privacy Shield Principles so that the commitment becomes enforceable under U.S. law, annually re-certify their compliance to the Department (of Commerce), provide free independent dispute resolution, to EU individuals, and be subject to the authority of the U.S. Federal Trade Commission (“FTC”), Department of Transportation (“DOT”), or another enforcement agency.”

New requirements for Privacy Shield participating companies as outlined on the Commerce.gov site include:

  • Informing individuals about data processing
  • Maintaining Data Integrity and purpose limitation
  • Ensuring accountability for data transferred to third parties
  • Cooperating with the Department of Commerce
  • Transparency related to enforcement actions
  • Ensuring commitments are kept as long as data is held

What to do – EU GDPR
Under the new EU General Data Protection Regulation (Chapter 4, Section 2), not only is there also a requirement for an annual assessment, but the Regulation requires for data breach notification, incident response planning and security awareness training for staff involved in the data transmission process.

As it pertains to incident response plan and handling, the regulation stipulates notification to a supervisory authority within the European Union within 24 hours and notification to data owners without undue delay. Having an incident response plan in place will be critical to an organizations ability to respond to a data compromise incident.

On vendor risk management, Article 26 stipulates that subcontractors cannot process or transmit data on behalf of the organization (e.g Data controller). Since most organizations have programs for vendors to access systems or assist in data management, you’ll want to evaluate your vendors’ security and risk posture, since you could be affected by their negligence and entangled into one of those 2% or 4% of total revenue fine situations.

There are many other certifications and services that organizations should consider if they are not being done already including ISO 27001/27018 certification and attestation, privacy assessments and vendor risk management services to ensure data processors participate with Privacy Shield requirements and GDPR regulations.

ISO 27001 AND 27018 Certifications are an international security framework for securing information systems. ISO 27001 establishes an Information Security Management System and is an independent verification that your organization meets the ISO 27001 security standard.

ISO 27018 is a compliment to ISO 27001 and specifically focuses on protecting Personally Identifiable Information (PII) transmission and storage in the cloud. For Data Controllers and Data processors, meeting ISO 27018 will provide your organization with a method to establish control objectives, controls and guidelines for implementing measures to protect PII in the cloud in accordance with privacy principles in ISO/IEC 29100.

In Conclusion
The finalized Privacy Shield and the updated EU General Data Protection Regulation will require U.S. Companies to make EU citizen privacy a paramount priority to avoid any ramifications from EU regulations. Contact Coalfire to discuss any of the above information. Where needed we can also pull in our partner law firm to further educate and provide guidance on the updated EU privacy and data changes.

Marshall England, Industry Marketing Director, Technology & Cloud, Coalfire

[Cloud Security Alliance Blog]

2016 (ISC)2 Security Congress General Session to Focus on CISO Impact

Chief information security officers and their teams must lead their organizations into adopting safe business practices. In our increasingly connected world, this goal is more important than ever. Speaking the language of the C-suite and the board, and translating information security into business terms is key for CISO success.

The General Session at this year’s (ISC)² Security Congress will help CISOs chart their paths to successful leadership and cybersecurity practices. “CISO Impact: Driving Security Into the Business” will be presented by Phil Gardner and Stan Dolberg. Both speakers are executives at IANS, an information security advisory and consulting firm: Gardner is founder and chief executive officer, and Dolberg is chief research officer.

The session is based on IANS’s data-driven leadership framework, CISO ImpactTM, based on research with more than 1,000 information security teams, including many (ISC)2 members. The session will take place on Thursday, September 15 from 8:00-9:00 a.m.

Gardner founded IANS in 2001 and currently oversees strategic and operational decisions. He has seven years of service in security with the U.S. Navy as a strike fighter pilot and ordnance requirements officer. He received his B.A. from Harvard University, as well as his MBA from Harvard Business School.

Dolberg has been the chief research officer at IANS since 2015. Before joining the organization, he ran his own consulting firm working with CEOs and boards of technology companies, addressing key questions about markets that affect sales velocity. He received his B.A. from Harvard University and his MBA from the Carroll Graduate School of Management at Boston College.

Along with the General Session, full-conference attendees will have access to more than 90 educational sessions, as well as the exhibit floor, Career Pavilion, and Solutions Theater. This year’s Security Congress event has 11 tracks:

  • Application Security/Software Assurance
  • Cloud Security
  • Forensics
  • Governance, Regulation and Compliance
  • Incident Response
  • Malware
  • Mobile
  • People Centric Security
  • Professional Development
  • Swiss Army Knife
  • Threats: Inside & Out
  • Threat Intelligence

While the first session takes place Monday morning, September 12, (ISC)2 members are invited to attend the annual Town Hall meeting the day before, Sunday, September 11. (ISC)2 leadership, including CEO David Shearer and board members, will be available to answer questions about membership, certifications and more. Questions may be submitted to the panel via email at congress@isc2.org or tweet them to us on Twitter @ISC2Congress (Use #Congress16TownHall).

This year’s (ISC)2 Security Congress will take place in Orlando, Florida at the Orange County Convention Center from September 12-15, 2016. The event will be co-located with the ASIS International 62nd Annual Seminar and Exhibits, once again bringing together operational security and cybersecurity professionals. As the best-value and largest industry event of the year, more than 20,000 professionals from around the world are expected to attend. For more information, or to register to attend, please visit http://congress.isc2.org/.

[(ISC)² Blog]

SDN Concerns and Benefits

Software-defined networking (SDN) is the next big focus in network intelligence. When the network is virtualized into the software-driven layer, the operations become more automated with less administrative overhead, allowing administrators to deeply penetrate the network fabric, giving better control through the programming ability in addition to reducing cost. However, as enterprises look to adopt  SDN, the top issue is the concern for security. As with any software and interconnected system, whenever we shift the responsibility of day-to-day activities and operations to a programmable software, we also invariably introduce an element of risk. Whenever resources are available over a network, there is always a chance of them being compromised.

Whether the use of SDN takes the role of being a straightforward standards-based SDN solution or proprietary technology from a single vendor, the fact is that all SDN technologies create the same problem for organizations:  Organizations are forced to trust and depend on software that is new, relatively complicated and not fully understood. Although the positives of SDN are well known and widely discussed, the negative impact of it being exploited is still a black box. For example, what are the SDN vulnerabilities of which the organization must be aware? Do these vulnerabilities take different forms in the control layer as compared to the data layer? What do an SDN rootkit or man-in-the-middle attack look like? Does an SDN worm have a different DNA  structure, making it harder to be identified than a traditional worm? The problem with SDN is that each control point on the network becomes a potential target of attack. If weak, it can be converted into an entry point for attackers who can further conceal these golden gates and cover them up from detection from monitoring and management watchdogs.

It should also be noted that with new generation technologies overhauling the traditional network setup, the organization’s operational support systems (OSS) becomes more dependent on automation and software. Humans could face challenges in identifying network security issues with the use of the SDN fabric on the network.

The future of SDN is promising with its obvious business benefits. In the early days of application programming, however, security was not given enough attention to ensure that it was embedded in each line of code and reflected in the architecture and design of applications. The impact of this misstep is still seen by the industry today. Organizations can only try to anticipate what the attackers may target with SDN. The implementation of SDN, its protocols and the controller programming software are all new, and our knowledge on SDN attacks is limited. Before an organization embarks on an SDN deployment effort, the key will be how it will strategize in securing the system during the early design stage and continue to implement strategies and processes around it based on the growing knowledge of the vulnerabilities around the use of SDN.

Read Nikesh Dubey’s recent Journal article:
From Static Networks to Software-driven Networks—An Evolution in Process,” ISACA Journal, volume 4, 2016.

Nikesh Dubey, CISA, CISM, CRISC, CCISO, CISSP

[ISACA Journal Author Blog]

English
Exit mobile version