Cloud Security Alliance Announces Speakers and Presentations for Upcoming SecureCloud 2016 Conference

Leaders from Intel, Microsoft, Forrester Research and NIST Among Presenters at Upcoming Premiere European Cloud Security Event

DUBLIN, IRELAND – April 25, 2016 – The Cloud Security Alliance (CSA), in collaboration withFraunhofer FOKUS and ENISA, today announced the presentations and speaker line up for the upcoming SecureCloud conference. The SecureCloud 2016 conference is scheduled for May 24 – 25 at Aviva Stadium in Dublin, Ireland. SecureCloud is the only European conference focused exclusively on cloud security and aims to provide an opportunity for government experts, industry experts, and corporate decision makers to discuss and exchange ideas about how to shape the future of cloud computing security.

“Even with all the awareness of the benefits of cloud technology, an overwhelming number of companies still have concerns about security, privacy and data management in the cloud and conferences such as this one are an important forum to address, discuss and resolve these concerns,” said Daniele Catteddu, Chief Technology Officer of the CSA. “SecureCloud will bring together some of the cloud industry’s top experts and thought leaders and we expect that it will draw substantial interest from the industry. We anticipate that this year’s event will further grow this body of knowledge and help us achieve a more trusted and secure cloud environment.”

An initial line up of featured speakers include:

  • “Securing the Cloud of Tomorrow” by Raj Samani, VP and CTO for Intel Security
  • “Privacy & Security in the Cloud: Customer Rights and Governments’ Lawful Access to Data” by John Frank, Vice President, EU Government Affairs at Microsoft
  • “Understanding the Crux – Abuse of Cloud Storage Services for Targeted Cyber Attacks” by Aditya K. Sood, Director of Security and Cloud Threat Labs at Elastica.
  • “Flying Through a Cloudy Sky” by Michaela Iorga, Senior Security Technical Lead for Cloud Computing at NIST.

Additional featured presentations will also be given by Laura Koetzle, Vice President and General Manager‬, Forrester Research; Vinay Patel, Global Head of Information Security Risk Management at Citi Technology Infrastructure; Dr. Kuan Hon, Senior Researcher at QML, Nathaly Rey, EMEA Trust Manager, Google for Work, EMC and Jim Reavis, Co-founder and CEO of the CSA.

This year’s event will also include a number of key panel presentations focused on some of the most emerging trends and issues in cloud computing including:

  • “Cloud Computing Compliance Controls Catalog (C5)” by Information Security Expert Patrick Grete, Clemens Doubrava of Bristish Standards Institute (BSI) and Charles Schulz of Agence nationale de sécurité des systèmes d’information (ANSSI)
  • “Financial Services in the Cloud” by Craig Balding of Barclays, Mario Maawad of Caixa Bank and Douglas Taylor of Citi

For more information on SecureCloud 2016, including registration details and schedule, please visithttps://csacongress.org/event/securecloud-2016/

Media Contact

Kari Walker for the CSA
kari@zagcommunications.com
703.928.9996

[Cloud Security Alliance Research News]

Board Involvement With IT Governance

Interest in IT governance is increasing due to the changing role and relevance of IT within organizations for supporting, sustaining and expanding business. According to the IT Governance Institute, IT governance is the form of leadership, organizational structures and processes that ensure an organization’s IT sustains and extends the organization’s strategies and objectives. While management’s role in IT governance is imperative, practitioners and academics have also long advocated board involvement in IT governance. However, the literature shows that boards may not be very involved in IT governance. This could be because board members may not have the needed IT expertise to provide direction on important operational and strategic IT-related issues. Boards may also not be very involved because IT does not get put on the board’s agenda or board members simply do not understand their roles regarding IT governance.

Our recent Journal article addresses this issue of the board’s role in IT governance by examining the charters of board-level IT committees. We reviewed the committee charters to analyze the prescribed roles and responsibilities of these committees. If the charters are not clear or complete, board members may misunderstand their roles. We found that only 23 Fortune 500 companies had board-level IT committees at the time of our study. We used content analysis to categorize the documented roles and responsibilities according to the 5 IT governance domains:  strategic alignment, value delivery, resource management, risk management and performance measurement. Our Journal article contains our findings and discusses the opportunities for these committees to improve their governance roles.

A topic that we are interested in beyond the scope of our article is the IT auditor’s role in ensuring the effectiveness of these committees or the board at large in terms of IT governance. During an IT governance audit, the auditor should examine the committee charters to ensure committees are set up to fulfill best practices and COBIT-related IT governance roles. Examining meeting minutes and matching them to the prescribed roles could further ensure these committees are effective in their oversight role. In fact, IT-related issues may be discussed and documented in board meeting minutes regardless of whether the company has a specifically designated board-level IT committee. We hope to explore some of these issues in the future.

Read Nancy Lankton and Jean Price’s recent Journal article:
Board-level Information Technology Committees,” ISACA Journal, volume 2, 2016.

Nancy Lankton, CISA, CPA, and Jean Price

[ISACA Journal Author Blog]

NEW! Mitigating Risk for Cloud Apps Survey

Time: 15 minutes
Prizes: 10 CCSK Tokens
Closing Date: May 23rd

Participate Now

Abstract:

Current state of SaaS security – with several years of cloud adoption in many organizations, approaches to security have been evolving rapidly. The purpose of this survey is to look at the specific concerns, policies, and controls that enterprises are using. The goal will be to answer the question, what are today’s enterprises doing to mitigate risk across both sanctioned and unsanctioned cloud applications?

[Cloud Security Alliance Research News]

The Panama Papers, Mossack Fonseca and Security Fundamentals

The release of details contained in the Panama Papers will be one of the biggest news stories of the year. The number of high-profile individuals implicated will continue to grow as teams comb through the 11.5 million documents leaked from Mossack Fonseca, a Panamanian law firm. While the news headlines will focus on mainly world leaders, athletes and well-to-dos, the overview from The International Consortium of Investigative Journalists (ICIJ) gets into additional details. This overview is worth reading to understand what services the firm provided, who uses the services, how they can be used legally and how they can be abused.

The overview seems like something out of a John Grisham book. In fact some of the information being released is similar to a plot from a book he wrote over 25 years ago. In 1991, John Grisham published “The Firm”, a book which revolves around several lawyers working for the fictional law firm Bendini, Lambert and Locke. Some of the similarities between the book and today include a law firm that primarily exists to assist money laundering and tax evasion, part of the plot involves the details of many transactions from retrieving thousands of documents and there is a whistleblower. The fictional firm also provided services to legitimate clients, although in the book that number is about 25 percent. It is unknown what percentage of Mossack Foneseca clients were legitimate and how many would be described as Ponzi schemers, drug kingpins and tax evaders, as the ICIJ overview mentions. While the novel is fiction, the book sets the stage as something that has been seen before.

Whether the leak started from an external breach of systems or an intentional leak from an insider, it is always intriguing to know how it occurred and what could have been done. Did it start with a phishing email, a rogue employee, a web application flaw, etc.? Forbes reported that the client portal server was running Drupal 7.23, which was found to be susceptible to a SQL injection vulnerability that was announced in October 2014. There were many reports of exploitation of this vulnerability days after it was announced, so it is likely someone took advantage of the exploit. The team responsible for WordFence, a popular WordPress security plugin, provided another possible exploitation scenariorelated to upload functionality that existed in the Revolution Slide plugin. These are just some of the potential means that could have caused a breach at Mossack Fonseca. Other possibilities include scenarios related to weaknesses in the email server and a lack of encryption in transit. Mossack Fonseca’s does have a Data Security page on their site, although it primarily touts SSL and the fact they house all of our servers in-house as their primary security measures. In 2011, I wrote a post on how the legal profession was an easy target for breaches. Looking back I realize that technology has changed, but in many ways the weaknesses are likely to stay the same. One of the biggest changes to note from 2011 is the number of online applications law firms have now. This isn’t just the top 100 law firms; this includes smaller regional firms as well. In addition to the main corporate web site and an area to share documents (or client portal), which are now offerings that appear much more prevalent across firms of all sizes, firms have blog sites, premium service offerings, extranets and even applications that provide a gateway into all the other online applications. More applications means a larger attack surface. Unlike Mossack Fonseca, which claims it hosted everything internally, many law firms we see do use third-party SaaS offerings to handle some of these functions. Outsourcing to a third party which specializes in providing a particular service can often provide better security than a firm can provide in house.

Given the Mossack Fonseca’s focus on company formation, minimizing tax burdens, Private Interest Foundations and the like, the firm could have easily been a target given the recent groundswell of activism against tax avoidance and income inequality. While the lapse in security at Mossack Fonseca may not be representative of security at all law firms, the details surrounding their environment point to likely weaknesses in people, processes and technology which could exist in any organization.

  • People – Given what we know about potential vulnerabilities in their environment and the exfiltration of data, we can surmise that someone was not paying attention for an extended period of time. There are many security roles in an organization including, but not limited to policy development, administration and monitoring. In some environments one person may be responsible for many roles and in some cases not all responsibilities can be met. This may because no one was given the role or the person that was given the responsibility left the organization. A recent search of LinkedIn did not turn up too many IT-related profiles with Mossack Fonseca as a current or previous employer, although this doesn’t necessarily mean these individuals do not exist. Contractors may have also performed the role. That said, a third party could have been hired for a given job, say deploying the client portal, but maybe was not responsible for post implementation support.
  • Process – Being notified of vulnerabilities in the software supporting the organization is paramount to understanding where risks exist. Knowing what data is leaving the environment is also critical. The likelihood that either of these was occurring is low and if either were occurring there wasn’t necessarily anyone to act on it in a timely fashion.
  • Technology – A breakdown in people and processes can occasionally be mitigated by technology. The WordPress and Drupal sites are now protected by a third party security provider, but other sites likely are not. An up-to-date intrusion detection system (IDS) may have detected some of the threats the organization faced, or activities that occurred, although there were several potential options to exploit so one avenue or another would have likely been open. For an organization that appears to have missed some fundamental security concerns, they may have used technology to secure some data as there is a site named crypt.mossfon.com, which is still up.

The Panama Papers incident may once again raise awareness around data security with legal firms. Organizations performing support services to legal firms, such as eDiscovery and Case Management providers, may also want to take note. Mossack Fonseca has a link on their page for ISO Certifications. However, the only one listed is ISO 9001:2008. An ISO 27001 assessment, or certification, may not have prevented the leak, but it would have demonstrated greater consideration of security on the part of Mossack Fonseca. A penetration test would also have been beneficial, although given the vulnerabilities that existed even a vulnerability scan would have detected some of the issues.

With most data breaches, the actual data on the people and companies is less interesting (albeit potentially more valuable) than the way in which the breach occurred or the attacker persisted in the attack. As it relates to the Panama Papers, it is the opposite. The forthcoming details related to various individuals, their transactions, and the potential future tax and privacy implications are far more interesting to the public than the means whereby the exfiltration actually occurred. That said, taking a few minutes to understand how it happened and what we can learn can be a worthwhile step in preventing future breaches.

Matt Wilgus, Practice Director, Schellman

[Cloud Security Alliance Blog]

Automate Security or Face the Wrath of the Millennials

Like it or not, Millennials will dominate the workforce of the future. Right now, Millennials comprise about 38% of the workforce, and by 2025, that will rise to 50%. For the past year, Anitian has been researching the impact this trend will have on workforce development and information security. In short, most companies are not equipped for this change. Among the many issues we have uncovered,automation is one of the most disruptive to information security.

The Millennial generation has grown up surrounded with ubiquitous Internet access. Moreover, they have also grown up in a world where significant aspects of their lives are automated.

Consider an obvious example:  Google. Prior to the 1990s, if you did not know something, you had to go to a library or search through a book. This was time consuming, which meant you were motivated to remember whatever you looked up. Google changed all that. It put nearly unlimited information a few keystrokes away and automated the process of searching. The mere fact that Google is a verb proves this. Don’t believe me? Well, Google it.

Consequently, we have a generation of workers who are extremely accustomed to this kind of automation. There are countless other examples:  iPhones, Netflix, Facebook, Instagram, Amazon.com, and so forth…all of these are highly automated platforms with ubiquitous access to data that can do a lot of the tedious work of storing, searching and cataloging. They also provide automated ways to alert or remind us of events.

Millennials expect this kind of access and automation. Nothing is more frustrating to a Millennial than being forced to use manual, time-consuming processes. They seem archaic and stupid. This results in disengagement, and eventually, they quit and go elsewhere. Millennials trust the cloud more than they trust a piece of paper.

Information security is not immune from this issue. Sitting at consoles chasing down every virus alert is stupid to a Millennial (I think it is stupid as well, and I am a GenXer). They expect this kind of work to be automated. However, for older executives and directors, this kind of automation is frightening. We hear it all the time in our assessments:  “We cannot allow security to impede the business.”

Except, that is exactly what is happening. The lack of automation is creating an environment where attack, compromise and theft are more likely. It is naive to think that humans (or any internal incident response process) can work at the speed of the attackers. The “bad guys” leverage automation in every conceivable way possible. The notion that hackers are all hoodie-wearing kids with tattoos tapping away on keyboards is the stuff of TV shows, not reality. The bad guys are global, sophisticated and highly automated. The sophistication of today’s attackers can outclass some of the largest software vendors in the world. And while a living person may monitor all the attacks, it is the compromised servers and content distribution networks that do all the work.

Millennials know this, implicitly. Their whole life has been about automating anything they could. And for them, it seems positively archaic to reject automation, when your enemies have completely embraced it. This means if your information security program is going to be effective with the workforce of the future, it must automate.

The good news is automation is getting easier. The growth of security analytics platforms is allowing organizations to unify and automate large portions of their security monitoring. Leading security analytics market are companies like Cisco, IBM, Blue Coat, Forcepoint (formerly Raytheon|Websense), Palo Alto Networks and Fortinet. Emergent companies like Phantom are exciting, as they can provide cross-platform automation.

Your workforce is changing and your information security must change along with it. If you want to build the next generation security program, then you need to listen to what the next generation is saying. And they have made a very clear statement:  automate or we are out of here.

Andrew Plato will speak on Insider Threats at the North America CACS 2016 2-4 May in New Orleans, Louisiana. He is a veteran author, speaker and industry analyst on matters of IT security, risk management and compliance.

Andrew Plato, CISSP, CISM, QSA, President/CEO, Anitian

[ISACA Now Blog]

English
Exit mobile version