A Tool to Help You Develop Your Cybersecurity Career

We’ve all heard that cybersecurity is a booming field. But sometimes it can be challenging to know career-wise where to begin, or how to take the next step.

The new CSX Career Road Map is a valuable educational tool for young professionals looking to jump-start or launch a career in the cybersecurity/ information security field. The Road Map is comprised of three sections:  your background, your current skills, and future goals and aspirations in the cybersecurity field.

The first stage takes you through basic information such as building your profile by providing your name, current job title, current role (technical or nontechnical), education level, years of relevant security experience, and any certification(s) you have earned. After completing this, there is a little circle below which tells you which level on the CSX certification path you are currently at and what the actual path is.

The second stage consists of your current skills. It asks you what managerial and soft skills you have. After entering the information, the tool tells you how many job titles you qualify for. This is an awesome feature.

The job titles also include nice descriptions so that you will know exactly what each entails and can compare that against where you want to go in cybersecurity. At this stage, you should have a good idea of what job you can be looking for in the market if you are not yet employed. However, if you are already employed, this stage gives you a good idea of what you should be responsible for in your current cybersecurity role, as well as some alternate areas to consider pursuing.

The third stage helps you determine where you want to be in the future in the cybersecurity field based on the path that appeals to you most (managerial/technical). It gives you a list of future job considerations and development goals that you can choose from to reach your goals.

Since I currently work as an information security analyst—the equivalent of a cybersecurity practitioner in the CSX Career Road Map tool—I was able to determine where I am now and where I am supposed to be next in my cybersecurity/information security career.

Another great feature of the CSX Career Road Map is that it gives you a great level of detail on suggested potential roles, which may help you discover new roles you might be interested in pursuing. Importantly, it also tells you possible certifications to earn in order to strengthen your path to a successful cybersecurity/information security career. Certifications are really important in the cybersecurity field in order to validate your skills. With that, I was able to see what certification I need to earn in order to get to an information security manager (ISM) role. It also gives hints on what to do to achieve your development goals.

Overall, this is an awesome tool that provides very valuable information. It will not only help many young professionals starting their careers in cybersecurity find out what to do and where to start, but it will also help practitioners like me who are already in the field figure out how to advance to the next level to better identify, protect, detect, respond and recover.

Yaro Sadek Tahirou, Information Security Analyst, Affinity Plus Federal Credit Union

[ISACA Now Blog]

A Nontraditional Approach to Prioritizing and Justifying Cybersecurity Investments

Investments in cybersecurity tend to be fairly significant, so organizations continually seek ways to determine whether the investments are appropriate based on return. However, companies are challenged to apply and fit the traditional discounted cash flow methods to calculate a return on investment (ROI) and justify cybersecurity initiatives. Return on (cyber)security investment (ROSI) with a method to quantify the intangible returns on cybersecurity initiatives are even harder to calculate than traditional IT initiatives using traditional accounting methods.

The perceptions and views of non-IT management toward cybersecurity are among the contributing factors posing the challenge to justify the expense of such initiatives. A communication gap has resulted and is apparent in some of the following views and questions:

  • Security is not an investment.
  • Is cybersecurity an IT discipline?

The investment justification methodology proposed in my recent Journal article applies to situations in which company competitiveness is examined, critical success factors are defined, and risk and challenges are identified. The objective of the company’s cybersecurity decision model (CSDM) is to frame cybersecurity initiatives with justifications in alignment with company business objectives and governance.

One critical component of my proposed cybersecurity investment decision model formation is based on the company’s collective efforts managed in a workshop environment. The tool used in the workshop based on analytic hierarchy process (AHP) is the technique used to facilitate and determine the degree of impacts and priorities of the proposed initiatives

Figure 1—Example of Cybersecurity Decision Model 

View Large Graphic.

Source:  Robert Putrus. Reprinted with permission.

In my recent Journal article, I stated several benefits and byproducts to expect through the use and performance of the ROSI nontraditional justification methodology, including:

  1. Establishing a clear and dynamic link among company goals, objectives, risk and cybersecurity initiatives
  2. Elevating cybersecurity planning and implementation to the corporate governance level with easier interpretation for nontechnical and technical personnel
  3. Providing a communication platform for management team alignment and support
  4. Developing a company business model that is well understood by the management team and other company entities
  5. Identifying and prioritizing the interrelated elements where management is able to establish better planning, rationalization and deployment of initiatives
  6. Quantifying the impact the proposed initiative might have on each of the company objectives and on the bottom line
  7. Seeking the support of the management team for future departmental initiatives and operational decisions

Read Robert Putrus’s recent Journal article:
A Nontraditional Approach to Prioritizing and Justifying Cybersecurity Investments,” ISACA Journal, vol. 2, 2016.

Robert Putrus, CISM, CFE, CMC, PE, PMP

[ISACA Journal Author Blog]

Top 3 Malware Bogeymen Keeping CISOs Up at Night

What keeps CISOs up at night? Of all the cyberthreats, malware sends chills down a CISO’s spine, according to The CyberEdge Group’s recently released 2016 Cyberthreat Defense Report. Malware bogeymen come in many shapes and sizes. Here are three of the most nefarious in their respective categories:

Ransomware: CryptoWall
Ransomware has come a long way since 1989, when the AIDS Trojan first encrypted a user’s hard drive files and demanded money to unlock them. The latest version of CryptoWall, the most significant ransomware threat in the States, not only encrypts the file, it also encrypts the file name—making it a challenge to even find “kidnapped” files.

CryptoWall cost victims more than $18 million in losses in a single year, according to the FBI. While individual ransom fees are typically only $200 to $10,000, additional costs can include loss of productivity, mitigating the network, incorporating security countermeasures, and purchasing credit monitoring services for employees and/or customers.

Banking Trojan: Dyreza
Banking Trojans use a man-in-the-browser attack. They infect web browsers, lying in wait for the user to visit his or her online banking site. The Trojan steals the victim’s authentication credentials and sends them to the cyberthief, who transfers money from the victim’s account to another account, usually registered to a money mule.

For nearly a decade, the ZeuS Trojan conducted a reign of terror in the banking world. Even after Europol took down the Ukrainian syndicate suspected of operating ZeuS in 2015, new strains kept appearing. But it seems ZeuS has met its match in Dyreza (aka Dyre, aka Dyzap). More than 40% of banking Trojan attacks in 2015 were by Dyreza, according to Kaspersky Lab’s 2015 Security Bulletin. Dyreza’s one-two punch? It can now attack Windows 10 machines and hook into the Edge browser.

Mutant two-deaded worm: Duqu 2.0
There isn’t an official category yet for the most sophisticated malware seen to date. At a London press conference announcing an attack by the new version of the Duqu worm on its corporate network, Kaspersky Lab founder Eugene Kaspersky described the malware as a “mix of Alien, Terminator and Predator, in terms of Hollywood.

The original Duqu worm was mysterious enough, being written in an unknown, high-level programming code. Now Duqu 2.0 is further flabbergasting the security experts. Some describe it as a compound sequel of the Duqu worm that assimilates the features of a Trojan horse and a computer worm. Others call it a collection of malware or a malware platform.

I’m dubbing it the Mutant Two-Headed Worm because it has two variants. The first is a basic back door that gives attackers an initial foothold on a victim network. The second variant contains multiple modules that give it multiple superpowers: it can gather system information, steal data, do network discovery, infect other computers and communicate with command-and-control servers. And did I mention Duqu 2.0 has an invisibility Cloak? The malware resides solely in a computer’s memory, with no files written to disk, making it almost impossible to detect.

If Duqu 2.0 attacks increase in 2016, expect malware to be a CISO’s worst nightmare next year too.

Download the 2016 Cyberthreat Defense Report to learn how IT security professionals perceive cyberthreats and their plan to defend against them.

Susan Richardson, Manager/Content Strategy, Code42

[Cloud Security Alliance Blog]

PCI DSS: Centuries in the Making?

The modern day Payment Card Industry Data Security Standard (PCI DSS) v3.1, applies a robust layered approach for the security of cardholder data, applying the concept of defence in depth (DiD). This concept is nothing new and can be seen to have been applied by the Roman Empire in the 4th century AD1 and developed over 700 years, during the enhancements of the city of Troy2 , between 1700 BC and 1190 BC.

DiD was successfully developed as the result of numerous ‘lessons identified’, following numerous conflicts and incidents over many years.

However, given this strong legacy and long history of successful application of the DiD methodology, why is it that successful business leaders are still struggling to recognise the importance of creating a robust PCI DSS citadel, for the safety and security of their customers’ cardholder data operations?

The major difference between the Romans and the Trojans and now is that the types of assets have changed.

Historically, the assets were visible, tangible assets (Helen of Troy, precious jewellery, etc.) that were clearly identifiable and easier to see. Today, technological advancements have changed the assets into a mix of tangible assets (physical credit cards, receipts, chargeback letters, etc.) and virtual, intangible assets (eCommerce, Mail Order/Telephone Order computer processed, etc.) that are more difficult to identify and locate where they might reside (databases, spreadsheets, flat files, etc.).

Added to this is the fact that most acquiring banks grant approval for merchants to process cardholder data before they have created their secure citadel, in support of their card payment operations, or they are not made aware of the associated costs and complexities of building and maintaining secure card payment processes.

How can the lessons of the Romans and Trojans be applied to modern day business card payment operations?

Likened to history, today there is a clear and present threat from hostiles attempting to penetrate your defences, in order to gain from stealing customers’ cardholder data. These attackers can range from the opportunist, amateur hacker, who is driven by 3 incentives:

  • Inquisitiveness
  • Challenge
  • Reward (mostly not financial reward, but more personal reward—like winning a game of strategy)

Or:

The attacker could be a determined, organised criminal gang, who is informed of the value of the assets within an organisation. The criminal fraternity have changed their modus operandi to reflect the gains of the modern day. No longer do they need to go through the complexities of planning to rob a bank, much like they might have done in the 1950s or 1960s, when they can gain the same benefit from dropping in a simple piece of malware (such as a RAM scraper) into a large retail business.

These examples present the ‘kinetic’ (external) threat vectors. However, the successful application and management of PCI DSS also helps protect against the non-kinetic (insider) threat—that authorised insider who carries out an activity (either maliciously or accidentally) that causes a breach.

Would your staff help to wheel a Trojan Horse through your suite of defensive countermeasures?

What steps are required?

The city of Troy took 700 years to construct; PCI DSS is only 12 years old and still in development. However, there are a great deal of lessons we can take from history, as shown in figure 1 and listed here:

Figure 1: Nettitude PIE FARM methodology

  • Plan & Prepare3
    Set up a team, within the business, to design architectural and project plans, presented within a business case, which clearly articulates what the predicted set-up and maintenance costs might be, along with defined milestones.
  • Identify & Isolate
    • What are the methods of taking card payments (payment channels)?
    • What are your businesses card data flows?
    • What assets (technologies, people, processes, locations, etc.) support the card payment operations?
    • Are there any inter-connecting assets?
    • Is it possible to reduce the scope, through the creation of a Secure Bunker/Citadel (RED Channel) where the card payment systems reside, that is isolated from the non-card payment systems?
    • Which of the PCI DSS controls apply to the business?
  • Evaluate
    Having established the baseline, carry out a gap analysis to provide the rapid identification of areas requiring improvement.
  • Fix
    Work through a suite of remediation activities.
  • Assess
    Carry out an investigation into the maturity and effectiveness of the application of the baseline controls.
  • Report
    Complete a Self-Assessment Questionnaire (SAQ), against each of your payment channels (low-volume merchants) or have an independent onsite assessment, by a Qualified Security Assessor (QSA), to validate that your card payment operations are safe and secure.
  • Maintain
    Do not become complacent, once having completed the process to ‘get across the line’ and achieve the compliance status. PCI DSS requires a number of mandated, scheduled activities:
    • 6-month firewall reviews
    • Quarterly card data discovery
    • Annual web application testing
    • Vulnerability and patch management
    • Daily audit trails reviews
    • Weekly change detection reviews
    • Quarterly wireless checks
    • Quarterly internal and external
    • Annual penetration testing (or after any significant change)

In complex environments, how can you hope to effectively govern your PCI DSS footprint, ensuring that assigned responsibilities are being carried out effectively and in a timely manner?

  • Scheduling?
  • On The Job (OJT)?
  • Security Awareness?
  • Well-written and -communicated, effective policies and procedures?
  • Effective security incident response?
  • Employment of a governance, risk and compliance tool? (shown in figure 2)4

Figure 2: Acuity STREAM GRC Platform

View Large Graphic

The associated PCI DSS worlds are ever-changing, dynamic environments, with the attackers become ever more creative. Therefore, as attackers create new and innovative approaches, we need to ensure that our defensive responses are just as innovative and responsive.

The benefit of this approach is that it will help to reduce the chance of suffering a breach, whilst reducing the cost and improve the overall security culture within an organisation.

“Cyber Security is everyone’s responsibility”
Federal Bureau of Investigations5

1 Royal Military Academy, ‘Defence in Depth’, www.honga.net/totalwar/attila/technology.php?l=en&v=attila&f=att_fact_western_roman_empire&t=att_roman_military_defence_in_depth
2 Sharlun, Glen, ‘Defense in Depth: The lessons from Troy and the Maginot line applied’, SANS Institute, 2000-2005,www.giac.org/paper/gsec/282/defense-in-depth-lessons-troy-maginot-line-applied/100331
3 Nettitude, ‘What Is PIE FARM?’, www.nettitude.co.uk/pie-farm-methodology
4 Acuity Risk Management, www.acuityrm.com
5 The Federal Bureau of Investigations (FBI), ‘Cyber Security Is Everyone’s Responsibility’, October 2012,www.fbi.gov/washingtondc/news-and-outreach/stories/cyber-security-is-everyones-responsibility

Jim Seaman, Security Consultants Team Lead for Nettitude Group

[ISACA Now Blog]

Insecure of Things

During this exciting time of technological advancements, when there is an app for every facet of our lives, from letting you know the right time to take a bathroom break during a movie to how to build a space shuttle, why am I continually disappointed?  We have become a generation addicted to our apps and having the latest and greatest technologies, but that comes with a steep price. We have to continually ask ourselves with every purchase and click, what is my data and privacy worth if and when it is leaked, breached or stolen?

George Santayana wrote: “Those who cannot remember the past are condemned to repeat it.”  (The Life of Reason, 1905)

With all the massive security breaches that happen daily around the globe, why are we not learning from them and from each other? Why are we not taking the necessary precautionary steps as consumers and manufacturers? Maybe a better term for “Internet of Things” should be “Anyone Can Control my Things?”

Just because it is convenient to connect all your devices doesn’t mean you should.  The price for convenience can cost our privacy, our reputation, our livelihood, and even our lives. To the average user, a connected smart thermostat is just a thermostat. We would never imagine that it could be a fully equipped, connected and functioning computer that is able to influence the physical world. Through these in-home devices, an entry point is established to enter your home, access all of your connected devices, and ultimately your entire digital DNA. Over 70% of these devices are vulnerable to cyber-attacks, due to loopholes and backdoors that were left in the hardware and software and being exploited daily by anyone.

We, the consumers, need to band together to push these security threats back onto the responsibility of the companies that create them.  The best way to do that is by voting with our feet, our wallets and through legislation. We need to demand that companies build in security.  Not just in the beginning with the initial discovery phase when they are researching new products and services, but also carry it out all through the software/hardware development life cycle (SDLC) to include support and maintenance.

What can I do as a consumer?

  1. Research before you buy, and vote with your wallets. Read the EULA, security features and the privacy policies. Install patches, software updates and product upgrades when available.
  2. Don’t buy the first or beta version of the product. Let someone else test it out and wait for the manufacturer to rev the product.
  3. Become active with legislation to help create or change privacy laws for public and private companies to become more accountable for their products and services they bring to the market.
  4. Stop connecting everything. Don’t give up security for convenience.
  5. Use strong passwords and two factor authentication.

What can I do as an employee/manufacturer?

  1. Adopt a security focused approach, build and design security in, create use cases and test cases, write security related requirements through out every iteration. Develop threat models, pen testing and offensive security plans to test potential attacks. Ensure your Business Analysts, Project Managers, QA Engineers, Developers, Architects and Managers are measured on quality and security. Don’t be afraid to speak up if the product does not use proper encryption or privacy controls to secure user data and network services properly.
  2. Stop collecting so much user data, provide consumers with more choices to opt-out of data collection.
  3. Build in a line item into your budget just for security, and that does not mean buy more hardware and software. Invest in your employees, get them trained, cross trained or certified.
  4. Purchase and partner with key manufacturers for the memory, chips, sensors and processors who you trust, don’t pass the buck onto the consumers to pay for your laziness or cheapness.
  5. Don’t create backdoors or leave them open. Harden and secure endpoints.
  6. Listen to your customers, put quality first. Take the lead on creating a secure product line.
  7. Invest in systems that automate the detection of malicious activity so that it can be contained and remediated before data is lost or damage is done. Your network has to be configured to automatically prevent or detect these nefarious behaviors.
  8. Secure the data. Most data is unprotected in the cloud; personally identifiable information (PII) is open to anyone who wants it. The protection needs to start from the sensors and go all the way up to where the data is stored to cover data at rest and data in transit. Companies need to have and enforce a strict data retention policy and make sure they maintain a high level of security compliance.

I often get asked by friends and family, whose responsibility is security, isn’t it the companies that make it? The answer is a resounding, “no,” it is ours. It is our data, we own it and we should protect it. We need to become educated and aware of all the risks that come with surrounding ourselves with IoT connected devices. Companies are not good at securing their products or even their own infrastructures. They are starting to see and feel the effects of these poor decisions and security breaches by firing C-level executives or paying out millions in fines for lost consumer data. Security is every human’s responsibility to ensure that they are taking the necessary precautions to protect their own data. Do not rely on companies to do this on your behalf. As long as being first to market (quickly and cheaply) is their main driver, then security will most likely continue to be an afterthought and a reactionary gesture.

There is good news through all these breaches; the knowledge, experience and awareness is already here, we just need to learn from it. Listen and adapt to fit the constraints of IoT devices into our lives properly. Technology will continue to advance at a rapid pace and get better over time, but so will the bad actors.

Change your passwords frequently, install anti-malware, set up firewalls for your home networks, and most of all, never stop learning and educating yourself on security. Take control of your data and your lives, it is your responsibility. – – Wesley Simpson, COO, (ISC)²

[(ISC)² Blog]

English
Exit mobile version