ISACA Now Chats with NACACS Keynote Speaker Tim Sanders

ISACA Now recently talked to Tim Sanders, a keynote speaker at the North America CACS 2016 2-4 May in New Orleans. Sanders is the New York Times best-selling author of Love Is The Killer App: How to Win Business & Influence Friends and an Internet pioneer. He advises Fortune 500 executives on leadership, marketing and new media strategies to grow business.

ISACA Now:  Your new book Dealstorming: The Secret Weapon That Can Solve Your Toughest Sales Challenges suggests a team approach to sales. What are the keys to developing a best-in-class team, no matter its function?

Sanders:  Effective problem solving teams are diverse in thinking and united in shared vision. So ask yourself:  Who has a stake in the outcome? Who has expertise about our problem? These are your blockers, tacklers and skill position players for your team. Every team has an overarching goal or purpose, so make sure yours cuts across the lines. In sales, you can’t lead with just the revenue opportunity; you need to elevate the discussion to winning a rivalry, pursuing excellence or building your brand. Same goes for any other problem area at work. A bigger why creates a stronger team, especially when finding a solution takes a lot of meetings and time.

ISACA Now:  You recently tweeted that nurturing team building and team players is more important than hiring rock stars. Why is that?

Sanders:  From business to technology, complexity is rising fast. This puts pressure on organizations to quickly innovate, keeping up with the times. In my research, I’ve found that genius is a team sport…not the work of a lone creative type. There are bodies of research (such as The Myths of Creativity by David Burkus) that debunk the stories of lone-invention. It’s a romantic notion, really. We want to think that the rock star programmer, sales person or marketer will save the day. But really, the effective team builder and player will harness group genius to move things forward more quickly. Additionally, many “rock stars” on paper are the product of their previous working environment. That’s why so often as they move to new opportunities, they can’t replicate their success. And making matters worse, because they were a rock star at their previous job, they’ve likely developed the lone-wolf mentality.

ISACA Now:  Many IT professionals are introverted or work remotely. How can they become lovecats?

Sanders:  A lovecat is a person who is strong and intelligent but at the same time, generous and empathetic to their colleagues. One way we can be generous is knowledge sharing or mentoring. This can be done now online, in a series of very helpful emails. For networking, another way to be generous at work, email introductions or LinkedIn endorsements offer a way to connect others that “should meet.” Finally, introverts are naturally great listeners. Helping others be heard is a valuable offering in organizations where there is constant change.

ISACA Now:  You will be speaking at the NACACS conference 2-4 May 2016 in New Orleans. Give us a brief preview of what you’ll discuss and what attendees will take away.

Sanders:  I’ll be talking about the power of great relationships, team work, collaboration and leading from the heart. Main takeaways will include insights on how to be an effective mentor, a power networker and a great listener. Also, I’ll reveal the collaboration process I’ve developed over my career, and how when fueled by relationships, it can triple your chances at solving your toughest challenges.

[ISACA Now Blog]

Palo Alto Networks and PwC: Enabling Prevention-focused Cybersecurity

Earlier today at Ignite 2016, our annual user conference, we announced that we are joining forces with PwC’s Cybersecurity Practice to help customers establish security architectures, organizational structures and computing processes optimized to prevent cyber breaches.

Together, we are designing a next-generation security framework to guide customers through establishing a breach prevention-oriented security architecture. This framework incorporates the latest advances in security technology and addresses the modern threat landscape.

To learn more about our partnership, visit Palo Alto Networks & PwC page to read the press release, download an executive overview, and register for a webinar featuring the security framework.

[Palo Alto Networks Research Center]

‘Creating Audit Programs’ White Paper Introduces Template Redesign

With the release of its white paper Information Systems Auditing Tools and Techniques:  Creating Audit Programs, ISACA describes the basic steps to create an audit program. This white paper is part of a series created to deliver practical guidance on how to perform an audit engagement—from planning to reporting and closing—that is consistent with ISACA Auditing Standards (ITAF) as well as those issued by the Public Company Accounting Oversight Board (PCAOB), the Institute of Internal Auditors (IIA), and the American Institute of Certified Public Accountants (AICPA).

Information systems (IS) audits help enterprises ensure effective, efficient, secure and reliable operation of information technology. Audits can also help confirm compliance with numerous legal and administrative regulations, and help management determine if the business is functioning well and meeting challenges. Most importantly, audits assure stakeholders of the organization’s financial, operational and ethical well-being. All of these outcomes are supported by IS audits, especially the information and related technology and systems that most businesses and public institutions rely upon for a competitive advantage.

An important component of the audit plan is the audit program. Audit programs are commonly used to document the specific procedures and steps of testing and verifying control effectiveness. The audit program’s quality has significant impact on the consistency and quality of the audit results, so it is imperative that IS auditors understand how to develop comprehensive audit programs.

The many benefits of an effective audit depend on proper and thorough planning of the audit engagement. To make this happen, the auditor and the area being audited must understand and accept the scope and objective of the audit. Once the purpose is defined, the next step is to create an audit plan that captures the agreed scope, objectives and procedures required to get the relevant, reliable and sufficient evidence to draw and support audit conclusions and opinions.

To demonstrate the process described in the white paper, ISACA has released a sample audit and assurance program developed using a five-step process to gather the necessary information to define the audit subject, objective, scope and audit methodology. The sample audit program for a virtual private network can be customized to create a specific audit and assurance program tailored to your unique needs.

The documents are intended for IT audit professionals who are either new to the profession preparing to the Certified Information Systems Auditor (CISA) or simply want to brush up on their skills.

To learn more see the white paper here.

Eva Sweet, Technical Research Manager, ISACA

[ISACA Now Blog]

Cloud Security Alliance Releases Results of Software-Defined Perimeter Hackathon

CSA, The World’s Leading Cloud Organization Collaborated with Verizon and Vidder To Validate Security and Feasibility of High Availability Public Cloud Architecture at Fourth Annual CSA Hackathon at the RSA Conference 2016

SEATTLE, WA – March 31, 2016 – The Cloud Security Alliance (CSA), today released The Software Defined Perimeter (SDP) Hackathon #4 Report: High Availability Public Cloud Research. The report is based on the findings and key learnings from the fourth annual Hackathon held by CSA’s SDP Working Group during the RSA Conference 2016 held last month in San Francisco. Conducted over a four-day period, the goal of this year’s Hackathon was to validate the concept of creating a high availability application environment by combining the compute resources of multiple public clouds. With the support of Verizon and Vidder, the contest was designed to challenge the pre-conceived notions of public cloud security and reliability.

Jim Reavis, CEO of the CSA commented, “We would like to thank Verizon and Vidder for their leadership, resources and support in this year’s Hackathon. We are encouraged and pleased that it worked to validates the SDP’s working group theory that a high availability application infrastructure can be created for mission critical applications by combining multiple public clouds.”

In this fourth iteration of the Hackathon, Verizon helped define the architecture to ensure it reflected real world that included use of Vidder’s PrecisionAccess SDP Gateways deployed in two different public clouds while providing access to a redundant application that was located in a third cloud. To monitor contest activity, Vidder deployed its Insight real-time monitoring system to identity attackers. While this Hackathon saw a significant increase in the number of highly sophisticated attacks, the result was that no attacker was able to breach the SDP gateway even though they were provided a full packet capture of a valid connection.

Get the report

About Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, certification, events and products. CSA’s activities, knowledge and extensive network benefit the entire community impacted by cloud — from providers and customers, to governments, entrepreneurs and the assurance industry — and provide a forum through which diverse parties can work together to create and maintain a trusted cloud ecosystem.

Contact

Kari Walker for the CSA
ZAG Communications
703.928.9996
kari@zagcommunictions.com

About Vidder

Vidder PrecisionAccessTM isolates the protected applications from all networked users and devices, connecting only authorized users and trusted devices to applications they are authorized to access. The resultant new paradigm enables enterprises to achieve agility with security, augmenting cloud migration and business ecosystem collaboration, while reducing risk for traditional IT. PrecisionAccess is the industry’s first and most widely deployed solution based on the Software-Defined Perimeter (SDP) framework for advanced access control promoted by the Cloud Security Alliance (CSA). In 2015, Gartner named Vidder a Cool Vendor in Cloud Security Services. The company’s headquarters are in Campbell, Calif. For more information, visit http://www.vidder.com.

[Cloud Security Alliance News]

Four Security Solutions Not Stopping Third-Party Data Breaches

A new breed of cyberattack is on the rise. Although it was practically unheard of a few years ago, the third-party data breach is rapidly becoming one of the most infamous IT security trends of modern times: Target, Home Depot, Goodwill, Dairy Queen, Jimmy John’s and Lowes are just a few of the US companies to have lost massive amounts of customer records as a result of their contractors’ usernames and passwords falling into the wrong hands.

What went wrong? Hackers have started to see contractors as the easy way into their targets’ networks. Why? Because too many organizations are still using yesterday’s security solutions, which weren’t designed for today’s complex ecosystems and distributed (read cloud-based) applications and data.

Here are four examples of solutions that, in their traditional forms, simply aren’t capable of stopping third-party data breaches. Could your company be at risk?

1. Firewalls and Access Control Lists
Many organizations still control traffic flow between network segments in the same way they’ve done for decades: with firewalls and access control lists (ACLs). Unfortunately, security in the modern age isn’t as simple as just defining which IP addresses and ranges can access which resources.

Let’s say you have a single VPN for all of a department’s workers and contractors, with every authenticated user getting a DHCP-allocated IP address. Your firewall rules are going to have to be wide open to suit the access needs of each user on the IP range, and yet you’re not going to be able to trace suspicious activity back to a particular account and machine.

It’s also a lot of work for your IT department to set up and maintain complex firewall rules across the entire organization, so it’s not unlikely that they’ll make mistakes, respond slowly to employee departures, and leave access wider open than it should be.

2. Authentication and Authorization
Leading on from this, another problem with ACLs is that they generally rely on static rules, which in no way account for the security risks of today’s distributed workforces. A username and password pair will unlock the same resources whether used from a secure workstation at a contractor’s premises or from an unknown device on the other side of the world.

Authentication and authorization rules should be dynamic rather than static, and adjusted on the fly according to the risk profile of the connection. One of your contractors needs remote access to a management network segment? Fine – but only if they use a hardened machine during office hours. If the context of their connection is more suspicious, you might consider two-factor authentication and more limited access.

3. IPsec and SSL VPNs
More than nine in ten organizations (91 percent) still use VPNs – a 20-year-old technology – to provision remote access to their networks. It’s potentially their single greatest risk factor for third-party data breaches, because both IPsec and SSL VPNs are readily exploitable by hackers.

In an IPsec session, remote users are treated as full members of the network. Nothing is invisible – they have direct access to the underlying infrastructure. So, if they’re malicious, they can start digging around and looking for vulnerabilities in seconds.

SSL VPNs, meanwhile, deliver resources via the user’s browser. And what web application has ever been secure? Tricks like SQL injection and remote code execution attacks make it trivial for hackers to start widening their foothold on the network.

4. IDS, IPS and SIEM
Finally, a word on the technologies organizations use to detect data breaches. IDS, IPS and SIEM are generally mature and effective solutions that do the job they’re intended to do: identify suspicious activity on the network.

However, the combination of the antiquated technologies described above means that most networks are rife with false positives: legitimate users and harmless applications causing suspicious traffic in the network layer. Change this model, and IDS, IPS and SIEM systems might start to deliver more value. As it stands, though, they’re often resource-intensive and reactive rather than proactive, so they’re not really equipped to stop hackers in their tracks.

The Alternative to Prevent Third-Party Data Breaches
In the new world of pervasive internal and external threats, distributed organizations and global ecosystems, the perimeter is more porous and less relevant than ever. The old models simply aren’t working. We need to move from perimeter-centric, VLAN and IP-focused security to a model that focuses on securing the entire path from user to application, device to service – on a one-to-one basis.

That’s where solutions like AppGate that enables organizations to adopt a software-defined perimeter approach for granular security control become increasingly a must have security solution. AppGate makes the application/server infrastructure effectively “invisible.” It then delivers access to authorized resources only, creating a ‘segment of one’ and verifying a number of user variables and entitlements each session—including device posture and identity—before granting access to an application. Once the user logs out, the secure tunnel disappears.

Philip Marshall, Director of Product Marketing, Cryptzone

[Cloud Security Alliance Blog]

English
Exit mobile version