An In-House Security Approach for Cloud Services That Won’t Drive Your IT Department Insane

“If your security sucks now, you’ll be pleasantly surprised by the lack of change when you move to cloud.” — Chris Hoff, Former CTO of Security, Jupiter Networks

The chances are, almost everyone in your organization loves the convenience of the cloud for data storage and for collaborative workflow needs. And why wouldn’t they when documents and files are now easily accessible to all team members, whether down the hall, in another state or even on another continent? From a cost and operations perspective, cloud storage is certainly pretty compelling. However “almost everyone” might not include CIOs, CISOs and their teams, who often harbor concerns about the security of data in the cloud, and particularly where sensitive data is involved. I have similar misgivings. I’m not saying that we should not use the cloud, but I do believe that we can improve how we secure sensitive data stored on it.

Blue Skies or Dark Clouds Ahead?
In a recent report titled “Blue Skies Ahead? The State of Cloud Adoption,” Intel Security said that IT decision makers are warming to the cloud along with the rest of us with 77 percent saying they trusted the cloud more than they did a year ago. This hides a darker reality that only 13 percent of respondents actually voiced full trust in the public cloud, with 37 percent trusting their private cloud. Surprisingly, a full 40 percent of respondents claim to process sensitive data in the cloud, indicating that there is both room and a real need for cloud security improvement.

Adding Peace of Mind to Cloud Storage
When I hand over data to a third party, I want to be sure that they are not only contractually obliged to look after it properly but are actually equipped to do it. This means protecting it from accidental loss, malicious attacks and from silent subpoenas, among other threats. Logging and multi-factor authentication are part of the tool kit that can be implemented, as is encryption. There is an existing (and growing) awareness of the importance of encryption which is why most cloud service providers offer encryption options of one kind or another. But too frequently the third-party vendor is doing the encrypting, and holding the keys, which isn’t very reassuring to say the least.

Fundamentally, the best way to ensure data is safe and managed well is to pre-encrypt it before it’s sent to the cloud. Coupled with a policy of keeping key management in house, these precautions should allow for several hours of blissful sleep each night for members of the IT security team whether the cloud is public, private, or a hybrid of the two! Other approaches include using 2 or more different vendors to handle the different parts of the storage solution: one vendor can manage the keys while the other manages storage itself. Key wrapping is another way to reduce risk: the end customer can manage master keys that in turn wrap the document keys, giving you some assurance of isolation between your data and that of other customers stored on the same cloud, as well as control for document access. Through these approaches, you can provide a significantly higher level of protection for data stored in the cloud.

Encryption is the best tool we have for protecting sensitive information so we need to use it to support and enable our expansion to the cloud. As seen above, the devil is in the details of how we do it, but keeping control of keys is fundamental. Of course, there is also the issue of how strong the keys are that you are using, but that is a topic for another day….

Jane Melia, VP/Strategic Business Development, QuintessenceLabs

[Cloud Security Alliance Blog]

Training, Awareness Keys to Battling Social Engineering

The weakest link in every security posture is always the human element, which is a problem because the core asset of every business is its people. It is that human factor that makes social engineering such a significant, difficult to manage problem.

The term “social engineering” incorporates any and all human-intelligent interactions that are designed to elicit an involuntary or unconscious response that serves the social engineer’s need. In many cases, this means that social engineering is conducted to elicit sensitive/private information or induce end users or enterprises to adopt a certain set of behaviors.

Typically, social engineering is a precursor to, or simultaneous to, technology-based attacks. The overall attack, therefore, has a technical and a social component, allowing attackers to fine-tune their methods and reactions to end-user or corporate behavior. The more background research and intelligence the social engineer possesses, the more difficult it will be to recognize the social engineering attempt.

Social engineering is especially dangerous for employees who may have special access to valuable assets that other employees may not, such as the ability to wire funds. A good example of this occurred last year when Ubiquiti Networks Inc., a US-based manufacturer of high-performance networking technology for service providers and enterprises, was taken for US $39 million. An employee of a Ubiquiti subsidiary was the victim of a CEO scam, which hijacks or impersonates the email of a senior executive within an organization. In this case the victim, who had authority to initiate wire transfers, transferred large amounts of money from company accounts to the criminal’s accounts.

Adversaries are cognizant of the basic human tendency to trust people on face value, and accordingly, they abuse that trust to perform social engineering attacks. Unfortunately, the best way to combat these conditions is to change behavior. Specifically, it is best to change behavior in a way that makes people less trusting and more skeptical. Changing behavior is already difficult and especially more so when the change requires a person to acquire a bleaker outlook on the world around them. For these reasons, organizations need to recognize that results may require investments of time and resources to drive a long term change.

Increasing Vigilance, Awareness
It takes considerable training and awareness for organizations to develop the skills and collective mindfulness required to consistently fend off social engineering attacks. Though commonly seen as synonyms, it is important to note that training and awareness are distinct topics.

Training seeks to educate individuals about what they should or should not do. Through training, personnel become more educated about the ways they may unwittingly become victimized, so they can become more vigilant. For example, a good training program would teach attendees about why they should be suspicious of a phone call asking for information, and it would provide them with techniques to politely ascertain the validity of the request.

Awareness seeks to galvanize the group to address security problems together. Through awareness, members of a team become more cognizant of what each member is doing. For example, an effective awareness program leads members to raise a red flag if they see a delivery person walking through the office area unescorted. Seemingly innocuous circumstances (such as package deliveries) are the arenas in which social engineers operate most effectively.

Editor’s note:  ISACA Now is running a series of blogs on the 10 threats covered in ISACA’s Cybersecurity Nexus (CSX)Threats & Controls tool.  To learn more about the controls for cybercrime, as well as recent examples and references, typical patterns of cybercrime and more, visit the tool here. Ted Harrington drives thought leadership initiatives for Independent Security Evaluators, and is a sought-after speaker, presenting at high-profile conferences in a range of industries, including media and entertainment, hospitality, finance and others.

Ted Harrington, Executive Partner, Independent Security Evaluators

[ISACA Now Blog]

Mobile Application Security Testing releases its white paper

The Mobile Application Security Testing (MAST) Initiative is a research which aims to help organizations and individuals reduce the possible risk exposures and security threat in using mobile applications. MAST aims define a framework for secure mobile application development, achieving privacy and security by design. Implementation of MAST will result in clearly articulated recommendations and best practices in the use of mobile applications.

Mobile application security testing and vetting processes utilized through MAST involve both static and dynamic analyses to evaluate security vulnerabilities of mobile applications for platforms such as Android, iOS and Windows. These processes cover permissions, exposed communications, potentially dangerous functionality, application collusion, obfuscation, excessive power consumption and traditional software vulnerabilities. It also covers internal communications such as debug flag and activities and external communications such as GPS, NFC access as well as checking the links that are written in the source code. In addition to security testing and vetting, the initiative has also proposed processes and procedures for security incidence response.

The use of mobile applications has become unavoidable, almost a necessity, in today’s world. More people are starting to question the security of mobile applications and it’s about time that you take a look at what the Cloud Security Alliance has to say about mobile application security!

To access the full report visit the download page at: https://cloudsecurityalliance.org/download/mobile-application-security-testing/

[Cloud Security Alliance Research News]

Former Pittsburgh Steel Worker and Former New Orleans Saxophonist Partner to Cover Cybersecurity Blind Spots

As a young man growing up in the Pittsburgh, Pennsylvania area working in steel mills, (ISC)2 CEO David Shearer learned early on that a strong work ethic and collaborative spirit were important factors to being successful in business. David met fellow Safety Harbor, Florida-based CEO of PivotPoint Risk Analytics Julian Waits, who was originally a budding saxophone player performing in his hometown of New Orleans, Louisiana at the first annual conference for the International Consortium of Minority Cybersecurity Professionals (ICMCP). After realizing that they both resided in the same town in Florida and worked for organizations that could be mutually beneficial, the two leaders began a business partnership to help advance the automation of cyber insurance decisions in an effort to protect businesses from financial risk in the event of a breach.

By (ISC)² CEO David Shearer

(ISC)² and PivotPoint Risk Analytics have signed a business agreement with the goal of empowering chief information security officers (CISOs) to make more effective security business operations and cyber insurance decisions. The solution, called ‘cyber value-at-risk analytics’ (CyVaR™), aims to support CISOs and information security professionals with the information they need to make more strategic business decisions and mitigate risks.

Some may wonder why we’re venturing into this type of relationship as a longstanding vendor-neutral certification body. Our education and certification programs are based on a Common Body of Knowledge (CBK) and will remain vendor-neutral; however, I’m open to fostering relationships with organizations and companies that can provide benefits to our international membership. We’re doubling up our thought leadership efforts in areas where we see potential blind spots within our membership and the industry.

Simply stated, we know we must do more for our members. When it comes to our certified members, we realize that they use tools and programs for their organizations as part of their jobs. As CEO, I believe that I have an obligation to our members to negotiate discounts—where possible—for existing and/or new offerings that we believe can be helpful in advancing their organizations’ cyber, information, software and infrastructure security. This certainly includes tools and services that can better position their organizations’ ongoing cyber insurance requirements. We are open to discussing opportunities for our membership with any organization or company that wants to present how their offerings can add value to our members, their career development and their respective jobs.

This new partnership provides (ISC)² members with a 35 percent discount for the first year of a CyVaR subscription. The benefit provides our members with another way to demonstrate value to their organization, while also making the job of the CISO more efficient.

Information security professionals can sometimes speak a different language than the leadership they answer to, be it a board of directors, CEO or other executives. The business impact of decisions made by the cybersecurity team needs to be quantified, which is the problem that cyber value-at-risk solutions solves. By changing the conversation from a technical discussion about cybersecurity threats to a business discussion about the potential financial impact of cyber risk, members of the C-suite and board can better position their organizations for increasingly sophisticated cyber threats.

“By quantifying the risk to the most critical corporate information assets and associated software and infrastructure, cyber value-at-risk helps CISOs secure the value of their business and bolster their respect in the boardroom,” said Julian Waits, CEO, PivotPoint RA. “We are excited about this collaboration with (ISC)², a recognized organization that is committed to enhancing the security posture of global organizations.”

CyVaR can help determine, for example, how much money an organization could lose to a cyberattack, how investing in security can reduce their risk and what types of cyber insurance would be advisable to transfer financial risks. The CyVaR approach is endorsed by The World Economic Forum’s “Partnering for Cyber Resilience” initiative and is the common risk quantification for its members.

A webinar will be available on July 12 for (ISC)² members and cybersecurity professionals alike to learn more about the partnership, program and what it can mean for them and their organizations. For more information about the CyVaR solution, please visit http://pivotpointra.com/.

[(ISC)² Blog]

Shock Treatment: Combatting Infosec Negligence

Boring training videos, box-ticking to meet regulations, blacklisting software at the expense of productivity: large enterprise has been reliant on these methods of “cyber security control” for too long. They are outdated and don’t work. Cyber criminals don’t follow the steps outlined in a training video from 2006—they innovate, manipulate, penetrate and steal information in many different ways and by many different means.

Internally, employees can also represent a real and significant danger to corporate information—whether by accident or design—they are the insider threat. Think about it this way. Dropbox might be an easy way to transfer a file to a client—but has it been sanctioned by IT? Ask every knowledge worker in a company that question, and you can guarantee you won’t get a single, clear cut answer. In fact, according to Code42’s 2016 Datastrophe Study, 22% of knowledge workers surveyed said their IT department doesn’t know they use third-party cloud sharing solutions.

So in 2016, what are the right ways to educate your employees about data security from both an internal and external perspective?

Shock therapy
We briefly covered that training videos and generic presentations don’t work that well. Within 10 minutes, staff will have switched off and words will be going in one ear and out of the other—unless you’ve invited Snowden himself to present the training.

To encourage employees to take responsibility and ownership of sensitive corporate data, a more direct approach is needed. Fortunately, cybersecurity consultancy and threat-based penetration testing is something we’re well versed in at First Base Technologies, and we’d recommend the following to drive employee awareness:

  • Faking data loss—by targeting specific departments (or even the entire company) with a well-designed program of phishing attacks, you can easily demonstrate the real risk to the business and start the process of education. No information is actually compromised, and the affected employees are told it’s been a simple training exercise. I can guarantee that over time, with the right messages it’ll hammer home the importance of double-checking whether to click that link, install that file, or respond to that unknown request in the future. Think of it as the cyber security equivalent of regular fire drills.
  • Physical penetration testing—this involves hiring third-party security consultants to visit an office disguised as “help-desk” computer engineers, visitors or even cleaners. In actuality, they are penetration testers evaluating both the physical security of an organization and its network infrastructure, with the goal of demonstrating unauthorized access to sensitive information. The resulting report, often accompanied by video footage of the exercise, provides valuable guidance on security weaknesses and remediation. Staff is briefed on what happened and the potential gravitas of the situation—providing another important lesson as a result.
  • Company-wide warnings—as information security professionals, we are well versed in the latest threats and the results of high-profile breaches. And thanks to the recent media agenda, it does seem to be filtering down to non-IT folk too. According to Datastrophe, 74% of knowledge workers say that IT staff’s ability to protect corporate and customer data is very important to their company’s brand and reputation. To communicate these facts to the remaining 26% of employees, breach and security risk information should be regularly delivered to staff at all levels.

Education. It really is the most important weapon in IT and security professionals’ arsenals. It’s a fact that in 2016 and beyond, organizations are under attack pretty much constantly, and if employees aren’t wise to this, the insider threat they present is realized with devastating results. With Datastrophe highlighting that 36% of knowledge workers think the business they work for may be at risk of a public data breach in the next year, it seems people are fortunately starting to understand the threat. And by IT and senior management enacting some of the training methodology above, knowledge workers will start getting well versed in information security practices too.

Peter Wood, Cyber Security Consultant, Code42

[Cloud Security Alliance Blog]

English
Exit mobile version