CISA, Audit Thyself

It is 9:30 p.m. on Sunday—Mother’s Day. I am in my home office reformatting my laptop as a result of a mysterious Windows 10 EVENT_TRACING_FATAL_ERROR. As I sit at my desk playing Mahjong on my cell phone and cursing Bill Gates, I wait for Windows 10 to reload and check for updates. Thank goodness I keep all of my data on a separate hard disk. As I sigh with exasperation, my husband’s voice sounds from the other room as he suggests “Just restore it to the last point that worked.” Silence. “You do create restore points before you load updates, don’t you?” he asks, snickering. I growl under my breath and respond “No” in a tone that grudgingly implies that I did not and never have.

Oh, did I mention that I am a home-based worker? If I have technology issues, I am 1,900 miles away from my office, so I can’t just hop in the car and get somebody else to fix my problems.

By now you might be wondering why, as an IS auditor, do I not practice what I preach?

I know that my problem, if not caused by my own ignorance, was at least exacerbated by not following the best practice of creating a restoration point. If creating backups of data is a prerequisite for recovery,1 then the corresponding code and system configuration should also be required for successful recovery. However, lest you think I am a complete Luddite, please know that I do back up my confidential data to a separate hard disk not connected to the Internet and use a personal cloud as back up for non-confidential data. I also have a UPS, several extra modems and routers, and a backup laptop. In case my Internet goes down, I even have a nifty business resumption plan (e.g., go to Starbucks, enjoy a latte, and use their free Wi-Fi). Yet why, despite my education, certification and years of experience in IS auditing, do I place my systems at risk by employing some best practices while blatantly ignoring others?

Cost was obviously not a factor as creating a restore point is a built-in Windows OS function. Nor is lack of understanding the ramifications of failing to employ restoration points. As far as I can tell, my only excuse for failing to create a restoration point was my perception of the risk of OS failure being low compared to other types of risk, such as loss of connectivity or data loss.

An individual’s willingness to adopt or to reject an IT control is reliant not only upon the real security risk, but also the perceived risk.2Perception plays a far more important role in decision making than we realize. This means that some people (and organizations) will accept the possibility that something might happen rather than use precious resources to implement controls to prevent it. This false optimism is simply human nature,3 and sometimes it is only after experiencing the pain of one’s actions (or lack thereof) that individuals and organizations change.

How can we, as CISAs, ensure our clients perceive the real risk? As IS auditors, it is important that we understand why our clients might be resistant to change and reluctant to employ controls. If we can relate to them, then perhaps we can more effectively communicate our recommendations. After all, isn’t auditing another method of education?

At the very least…I might start taking my own advice.

Editor’s note: The ISACA Now Blog section is celebrating Women in Technology Month throughout June by featuring female bloggers. If you are a female blogger and would like to contribute a blog, please contact us at news@isaca.org.

1  ISACA, CISA Review Manual, USA, 2009
2  Huang, Ding Long, Pei-Luen Patrick Rau, Gavriel Salvendy, “Perception of information security,” Behaviour & Information Technology 29 (3): 221-232, May 2010
3  University of Kansas, “People By Nature Are Universally Optimistic, Study Shows,” Science Daily, 5 May 2009,www.sciencedaily.com/releases/2009/05/090524122539.htm

Stephanie Mahlig, CISA, MIS, Information Risk Management Technician, Allstate Insurance Company, Northbrook, IL

[ISACA Now Blog]

How Big Data Demoted Pluto

Let me say in advance that you will not learn a new audit or data analytics technique from this article. It is purely to demonstrate the power of data analytics on a massive scale. My goal is to inspire you.

A few months ago I attended a conference that featured Dr. Neil deGrasse Tyson as the keynote speaker. And yes, he is that guy from the Cosmos: A Spacetime Odyssey TV show.

He was hilarious and engaged the audience, receiving a standing ovation from the data geeks. He inspired me to make even more use of data analytics.

His first comment was about Pluto:  “It is not a planet. Get over it.” And then he said:  “We demoted Pluto because we had more data.” Whaaat? That sentence resonated with me so much that I started researching about the data that demoted Pluto.

I learned how powerful new ground and space-based observatories have completely changed our understanding of the outer solar system. As these tools have evolved over the past generation, so too has our picture of the universe. New capabilities have provided new understandings about our place in the cosmos, but they have also unleashed a baffling torrent of data. Amazing discoveries might be right in front of us, yet hidden within all that information.

Since 2000, the Sloan Digital Sky Survey at Apache Point Observatory in New Mexico has imaged more than one-third of the night sky, capturing more than 930,000 galaxies and 120,000 quasars. Computational analysis of Sloan’s prodigious data set has uncovered evidence of some of the earliest known astronomical objects and has determined that most large galaxies harbor super massive black holes. It has even mapped out the three-dimensional structure of the local universe.

So it was just a question of time until someone started searching for large objects everywhere, including the Kuiper Belt. It was astronomer Mike Brown who was convinced by the data on the Belt that there must be many more nearby objects and that some of them were potentially larger than Pluto.

Bingo! In 2003 Brown thought he had found a new planet that was larger than Pluto. He named it Eris (EER-is). Instead of being the only planet in its region, like the rest of the solar system, Pluto and its moons are now known as just a large example of a collection of objects in the Kuiper Belt.

“You didn’t lose a Planet; you gained a new place in the universe.” Dr. Neil deGrasse Tyson

The Kuiper Belt data that led to Pluto’s demotion came from routine observations at Mount Palomar Observatory in California. These data are stored at many repositories, including the National Optical Astronomy Observatory (NOAO) in the United States. The NOAO collects a large quantity and variety of scientific data products, including images, spectra, catalogs, etc., from many instruments deployed on two continents. Wow!

The NOAO has archived all data from their telescopes, accumulating about 10 terabytes of data annually. These data are now available to the public, which is actually an exciting discovery for a data geek like me.

The key to maximizing knowledge extracted from this massive amount of data is the successful application of data mining and knowledge discovery techniques. The data can help classify stars, galaxies and planetary nebulae based on images and spectral parameters, forecasting of sunspots and geomagnetic storms from solar winds, antimatter search in cosmic rays, etc.

Astronomy professor Robert Brunner said:  “Before Sloan, individual researchers or small groups dominated astronomy. You’d go to a telescope, get your data and analyze it. Then Sloan came along and suddenly there was this huge data set designed for one thing, but people were using it for all kinds of other interesting things.” Brilliant!

There you go—factual big data demoted Pluto and not some technicality pushed by a small group of scientists.

I hope you search for interesting ways to use the data available to you. Perhaps to revise long-standing decisions and notions formed when data and easy-to-use analytics tools were less reliable. What truth is hidden on your data just waiting to be set free? You may want to reflect on how much of this all applies to corporate environments.

Editor’s note: The ISACA Now Blog section is celebrating Women in Technology Month throughout June by featuring female bloggers. If you are a female blogger and would like to contribute a blog, please contact us at news@isaca.org.

Karina Korpela, CISA, CISM, CISSP, PMP, IT Audit Manager, AltaLink

[ISACA Now Blog]

Five Telltale Signs You Don’t Have the Latest Backup System

It’s Backup Awareness Month—time to take stock of how well your backup system is serving your organization. To help you get started, here are five telltale signs you don’t have the most modern endpoint backup system:

1. You still get Help Desk calls to retrieve lost data.
The latest backup systems feature intuitive, self-service backup so employees can restore their own data. Not surprisingly, enterprises with a modern endpoint backup system cited fewer backup/restore-related support tickets as a top benefit in a recent survey. More importantly, they were able to use the reduced support time to cost justify their more-advanced system.

2. Your backup system doesn’t support multiple platforms.
Today, 96 percent of companies support Macs. That’s because the enterprise has gone heterogeneous and your backup system should, too. A modern endpoint backup system doesn’t care whether a file is on Windows, Linux or OS X, or whether a device operates on iOS, Android or Kindle Fire. It backs up every file, every time, from anywhere—without requiring a cumbersome VPN connection.

3. You have no visibility into what’s on employee devices.
The latest backup systems give IT a comprehensive, single point of visibility and control across every employee device in the enterprise—including desktops, tablets and smartphones. You gain the insight to pinpoint leaks and prevent insider threat, because you know:

  • Which employees are uploading which files to third-party clouds
  • Which employees have transferred which files to removable media
  • Which employees have uploaded which files via web browsers, including web-based email attachments
  • Unusual file restores that may signal compromised credentials
  • The content of files and folders
  • The location of sensitive, classified and “protected” data

4. You can’t pinpoint where a breach occurred.
With legacy backup, you have to conduct lots of inquiries that take lots of time. With a modern endpoint system, you have visibility into every endpoint (see #3 above), so you can quickly identify where a breach occurred and reduce your Mean Time to Contain (MTTC). You also eliminate unnecessary reporting, because with 100 percent data attribution, you know for certain whether or not there was a breach.

5. You have to confiscate a device to enact a legal hold.
Really? Are you still putting up with that significant productivity drain? With a modern endpoint backup system, your legal team can conduct in-place legal holds and file collection without confiscating user devices—and without having to rely on IT staff.

If two or more of these statements apply to your organization, it’s time to go shopping for modern endpoint backup. See #1 above on how to cost justify it.

Download The Guide to Modern Endpoint Backup and Data Visibility to learn more about selecting a modern endpoint backup solution that protects data without sacrificing productivity for today’s mobile workforce.

Susan Richardson, Manager/Content Strategy, Code42

[Cloud Security Alliance Blog]

Open Surveys: Mitigating Risk for Cloud Apps and IT Security in the Age of Cloud

We have two surveys open. If you have a few minutes and would like to win
some cool prizes, consider taking our surveys.

Mitigating Risk for Cloud Apps

Time: 10-15 minutes
Prizes: 10 CCSK tokens and a fun new prize will be added shortly
Abstract:

Current state of SaaS security – with several years of cloud adoption in many organizations, approaches to security have been evolving rapidly. The purpose of this survey is to look at the specific concerns, policies, and controls that enterprises are using. The goal will be to answer the question, what are today’s enterprises doing to mitigate risk across both sanctioned and unsanctioned cloud applications?

Participate Now

IT Security in the Age of Cloud

Time: 25 minutes
Prizes: Oculus Rift virtual reality set and 5 CCSK Tokens
Abstract:

The shift of IT resources to the cloud is changing the day-to-day operations of IT security teams. This survey investigates shifts in IT security in 2016 including changing budgets and the importance of new skills. The survey will also investigate IaaS adoption and barriers to securing corporate data stored in applications on IaaS platforms. Finally, the survey will gauge your organization’s perspective and experience with security alerts and endpoint agents.

Participate Now

[Cloud Security Alliance Research News]

Open Peer Review – Big Data Security and Privacy Handbook: 100 Best Practices in Big Data Security and Privacy

The Cloud Security Alliance would like to invite you to review and comment on the Big Data working group’s latest document, Big Data Security and Privacy Handbook: 100 Best Practices in Big Data Security and Privacy. This document lists out in detail the best practices that should be followed by big data service providers to fortify their infrastructures. The document presents ten best practices for each of the top ten challenges in big data security and privacy providing us a roster of one hundred best practices.

This is your opportunity to provide feedback and identify any critical areas that we might be missing in the document’s focus. The open review and comments period starts today and ends on Friday, July 1, 2016. Follow the below link to the peer review site to begin the process to submit feedback:

https://cloudsecurityalliance.org/document/best-practices-in-big-data-security-and-privacy/

Additionally, the working group will have a call on Thursday 6/2 at 9am PDT to go over the paper and provide a status update for next steps. Please contact us at research@cloudsecurityalliance.org to be added to the event invite, or visit this link that morning.

Thank you in advance for your time and contribution and we appreciate your involvement. If you are interested in getting involved with this working group, please register on the Big Data micrositeregistration page.

[Cloud Security Alliance Research News]

English
Exit mobile version