Cloud Data Security Services Just Got Easier to Build and Assess

It is well documented that security is the leading concern hindering cloud adoption. However, it is not so clear cut how to build secure cloud services, or how to assess whether cloud services adhere to relevant security requirements. The Cloud Security Alliance (CSA) Cloud Control Matrix (CCM) framework was specifically designed to offer insights on these topics. The CCM framework provides fundamental security principles to guide cloud service providers (CSPs) and to assist prospective cloud customers in assessing the overall security risk of a cloud offering.

Using the latest CCM framework, version 3.0.1, Vormetric has created two white papers that shed further light on these critical topics. One paper helps cloud providers understand how to meet industry security guidelines with Vormetric data security solutions. The second paper explains how customers looking to adopt cloud services can assess whether their cloud vendors adhere to cloud security best practices. This paper also describes which Vormetric solutions to look for in complying with these standards.

The CCM is aligned with many industry standards and control frameworks, including International Organization for Standardization (ISO) 27001 and 27002, ISACA COBIT, National Institute of Standards and Technology (NIST), Jericho Forum, North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP), the Payment Card Industry Data Security Standard, version 3, and several others. As a result, CSPs can meet a number of industry security guidelines simply by adopting CCM requirements. In addition, the CCM framework features the Consensus Assessments Initiative Questionnaire (CAIQ), a detailed questionnaire that customers can use to assess the security capabilities of CSPs.

To develop our white papers, Vormetric staff worked with CSA CCM experts to identify which requirements pertained to data security. These white papers explain how the Vormetric Data Security Platform meets critical data security requirements.

By leveraging these white papers, security teams at CSPs can establish a clear path forward for securing data in their cloud environments. Further, executives at enterprises can use a concrete list of questions to assess and qualify prospective CSP offerings and ensure their data security needs are met. Below is a brief description of each white paper and the link to download the paper directly.

Industry Guidelines for Building Secure Cloud Services: This white paper explains how CSPs can use the Vormetric Data Security Platform to address CCM requirements for data segregation, persistent protection of customer data, data access monitoring and auditability, availability, and data destruction.

Best Practices for Assessing Your Cloud Data Security Services: This white paper offers a detailed look at how Vormetric solutions address the requirements specified in the CAIQ. In addition, the paper details what enterprise decision makers should look for in their cloud data security services.

Both white papers are also available on the Vormetric resources page.

By Alan Eng, Senior Manager/Product Marketing, Vormetric

[Cloud Security Alliance Blog]

Cloud Security Alliance Appoints Daniele Catteddu to CTO Post

As Its First Ever CTO, Catteddu to Spearhead Organization’s Global Technology Strategy and Roadmap Throughout Key Lines of Business

Seattle, WA – February 23, 2016 – The Cloud Security Alliance (CSA) today announced the appointment of Daniele Catteddu as its first ever Chief Technology Officer. In this role, he will be responsible for driving the development of CSA’s global technology strategy and roadmap throughout its lines of business including research, membership services, standards, education and products. Additionally, Catteddu will be charged with identifying technology trends, products, global policies and evolving social behavior and the impact of each in relation to CSA’s activities.

“Daniele is one of the industry’s foremost cloud security experts,” said Jim Reavis, CEO of the CSA.  “I look forward to working with him in the CTO role as we grow CSA’s influence and continue our expansion into defining assurance for important next generation information technologies.”

Prior to this appointment, Catteddu served as Managing Director of CSA EMEA, where he is credited for establishing and elevating CSA’s presence in the region, making it a center of excellence as viewed by both corporations and policy makers. Catteddu also was instrumental in the development of CSA’s Open Certification Framework, an industry initiative to allow global, accredited and trusted certification of cloud providers.

“I am very much looking forward to taking on the role of CTO for the CSA, where I will have the opportunity to combine my passion for technology with critical and creative thinking to help ensure that any technological advancement is in harmony with and in support of society,” said Catteddu. “I see a tremendous need to educate the market on the fundamental role that information security will play in our future and to provide each market stakeholder with the tools to approach the complexity of the information security issue. With ‘data as the new currency,’ providing high level of info security and protecting people’s right to privacy has become equal to protecting their future investments.”  In the year ahead, Catteddu plans to focus on advancing CSA’s Security, Trust and Assurance Registry (STAR)certification program, including the launch of the STAR Continuous, the identification of new trends especially those related to IoT security, and the creation of the Futures Advisory Committee.

About Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, certification, events and products. CSA’s activities, knowledge and extensive network benefit the entire community impacted by cloud — from providers and customers, to governments, entrepreneurs and the assurance industry — and provide a forum through which diverse parties can work together to create and maintain a trusted cloud ecosystem.

Contact

Kari Walker for the CSA
ZAG Communications
703.928.9996
kari@zagcommunictions.com

Newbies/Mid-Careerists: Jumpstart Your IT Audit Careers

In the two decades that I have been an IT Audit recruiter, the field has come a long way, and there is now much more recognition for the IT Audit profession. Going back to 1995, whenever I speak at an ISACA gathering I’ve always asked how many knew in college that they wanted to be an IT auditor. Just 10 years ago, no one ever raised their hand. About five years ago, hands started to go up. That IT Audit is now considered a viable career choice has been helped considerably by the steady increase in college curriculum focused on IT risks and controls.

As an IT Audit recruiter I am often asked by individuals at various stages of their IT Audit journey—from college to mid-career—what they can do to jump-start their IT audit careers and stand out from the pack. Here are some suggestions.

IT Audit Internships for Newbies
Let us start with those still in college. I strongly recommend you get into a good internship program to gain experience and “try before you buy” to help you decide if IT audit is something you are truly interested in. A good place to look for these programs is with the Big 4 accounting firms, but also with Fortune 500 companies, more and more which are developing audit internship opportunities.

ISACA Membership/CISA Highly Recommended
For those starting out or at mid-career looking to get into the IT audit field, my first suggestion: You need to become a member of ISACA. To get a foothold in the IT Audit world, ISACA can be invaluable particularly for the networking opportunities an ISACA membership affords. Robust ISACA chapters can be found in most major cities.

You should approach every chapter meeting as a networking opportunity. Yes, those events are great for learning more about the profession through training and presentations, but networking is key for those looking to break into the IT audit field. Sit with people you do not know. Move around the room. Introduce yourself to the chapter president or vice president. Ask for 30 seconds to a minute to introduce yourself to the entire group and present your stump speech/elevator pitch to make everyone aware of who you are and that you are looking to get into the IT audit field. How many times will you need to introduce yourself and network your way to an opportunity? Maybe once, maybe one hundred times…but if you put in that level of effort to go beyond the comfort zone and market yourself, you will eventually win somebody over.

Next: It is critical that you sit for the CISA certification. It sends a clear message to prospective employers that have mastered the IT Audit body of knowledge, but even more important, it shows you have taken initiative in your professional development. It demonstrates that you have bought into IT audit, which is something potential employers need to know, especially if they are going to take the risk of hiring someone who needs additional time and training to get up to speed. The CISA has gone from a “nice to have,” to a “Why in the world do you not have your CISA?” CISA is a door opener if you have it and a door shutter if you do not….so dig into your wallet and pay for the exam. If you are serious about the IT Audit field, this is an investment that will definitely pay off.

As for other ISACA certifications, both the CISM and CRISC are continuing to gain recognition. Non-ISACA certifications I recommend include the CISSP from the International Information Systems Security Certification Consortium and the CIA from the Institute of Internal Auditors (IIA).

To sum up, with IT audit candidate scarcity as significant as it has been since the initial years of Sarbanes-Oxley compliance, demand for qualified IT audit professionals will likely continue to exceed supply for the foreseeable future. This creates opportunities for those looking to break into the field, and an ISACA membership and certification are the keys to doing just that.

Derek Duval is the owner of Duval Search Associations, which is devoted exclusively to enhancing careers of IT audit, risk management, compliance, and advisory professionals.

Derek Duval, CPC
Duval Search Associates, LLC

[ISACA Now Blog]

Has David Chaum Saved The Internet?

As the Internet of Things continues its promising evolution, the world is becoming more engaged in the discussion of privacy issues versus issues of national security. At the center of this exchange is the burning question of whether we, as nations and communities, should sacrifice privacy for security.

Some governments think so, and have gone to great lengths to gather information from sources both inside and outside their borders, quite often acquiring the information of millions of persons in a quest to identify the specific actions of only a few individuals.

On the other side of the argument are those who believe that an individual’s right to privacy is sacrosanct; nothing can, nor should, supersede it, including a government’s desire to act in what it deems the interests of national security.

The actions of Edward Snowden put a spotlight on these conflicting perspectives, pointing out the various ‘back door’ entry points that enabled a government to examine the information of private citizens at any moment it deemed such an examination necessary.  Today, we find governments and citizens across the world having conversations about the appropriate balance of privacy and security.  Those discussion, as yet, have yielded little agreement, and few signs of potential resolution.

And now, the voice of someone new has joined that conversation: David Chaum.

David Chaum was the creator of the mix networks of the late 1970s.  He has spent much of his career in encryption, ensuring that information stays the property of the individual, and no one else’s.  In January at the Real World Crypto conference at Stanford University, he proposed a new way to ensure an individual’s online privacy, a model he calls PrivaTegrity.

His solution is somewhat counterintuitive.  He proposes more ‘back doors’—nine of them, in fact.  Simply put, Chaum’s PrivaTegrity model places nine servers in nine different nations.  No single server can provide access to the information being transmitted, nor can any combination of the nine servers access the information —save all of them acting in unison.  His rationale is simple: if nine governments or other entities can agree that something is undesirable—terrorist plots, human or drug trafficking, or similar endeavors—then that information should be accessed and acted upon.

A critic of Chaum’s pointed out the central flaw in this, though.  Why would criminals and terrorists use a construct that you have already publicly stated has the ability to be accessed through a back door, albeit a door with nine locks?

While Tor encrypts and bounces communications through a network of relay servers, preventing traffic analysis, Tor cannot—and does not—protect against traffic confirmation. Because of imperfections such as this, Tor and similar constructs are vulnerable to decryption efforts—but are they vulnerable enough, in the mind of a bad actor, to merit switching from that to Chaum’s PrivaTegrity model?  PrivaTegrity may make privacy more difficult to pierce—but it can still be pierced.

To be blunt, the only reason for criminal or terrorist elements to use PrivaTegrity would be if they controlled all nine servers.  It is difficult to imagine a scenario in which any one of nine criminal or terroristic enterprises would act against their own self-interests, so it would be extremely difficult to get all nine actors’ approvals, and lift the veil of privacy.  This could prove appealing to such groups—and be a nightmare beyond imagination for law enforcement, cybersecurity and national security professionals.

So, I believe it is safe to say—no, David Chaum has not saved the Internet.

But perhaps he has pointed to a way forward.  Plurilateral agreements require the approval of all entities involved before an action can be undertaken, and may be the nontechnological solution to the privacy versus security debate.  This is not a new approach to issues that are borderless, global in scope, and with implications for nations and individuals the world over; a plurilateral agreement regarding the future development and usage of Antarctica was entered into force by a dozen nations in 1961.  In the half-century since, the member nations have worked together to increase the number of nations in the Antarctica Treaty, as well as to set parameters for the scientific and research on that continent.

In this age of the Internet, privacy is disappearing—or perhaps we might soothe our souls by acknowledging that privacy is being redefined. Individuals are continuing to reveal more about themselves online.  Governments are actively pursuing what they believe to be the best security interests of their respective nations.  While many security-focused agencies around the world would be loath to have another similar agency in an outside nation sign off on their actions, the fact remains that it just might be the best way to ensure the privacy of the individual while still engaging in the pursuit and apprehension of criminals, terrorists and similar bad actors.

The Internet does not belong to an individual or a nation; it is among the few constructs in our world that can make that claim.  Instead, it is a construct that deserves the responsible stewardship of both state actors and individuals.  It is time that privacy be given the same status that other issues of global import have been given. It is time we work together to ensure that innocent, ordinary individuals the world over can communicate with one another—and only one another.

Matt Loeb, CGEIT, CAE
CEO, ISACA

[ISACA Now Blog]

How to Overcome Common Pitfalls in Data Analytics

The proliferation of data analytics in the world of internal audit has been a boon to some companies and a disappointment to others. Companies using analytics effectively are auditing with fewer resources and getting better coverage; reducing fraud, waste and abuse by the millions; and providing executives the ability to make smarter, data-driven business decisions.

But far too often, audit functions are launching data analytics that sputter, flame out and waste precious resources, and most immature data analytics programs are stumbling over the same few hurdles. Here are the five main hurdles and how to clear them.

Get Executive Buy-In From the Start
Data analytics is a disruptive technology, particularly for internal audit functions, and switching to data-driven decision making can be jarring for executives accustomed to basing decisions on intuition and business acumen alone. Preventing new data analytics initiatives from being stymied early on requires investment, agreement and evangelists at the top of the organization.

To win the hearts and minds of your executives, cherry pick a few analytics projects that promise a high return on investment through cost recovery or an increase in internal audit efficiencies. Audits of financial processes like T&E reporting or accounts payable often yield big returns from easy-to-access data. Demonstrate the value of a modest investment in analytics, and get your executives on board.

Plan for the Data Overload
With the quantities of data collected in most corporate environments today, sifting through all of them can be a headache. But byfront-loading your time—spending more time planning, identifying requirements and cleansing data—you can drastically improve the likelihood of a successful project and reduce the time spent on downstream analysis and review.

A key objective during the planning phase should be to identify all possible data streams that could impact the result of your planned analytic. Document those data streams, where they are stored, who the owners are, what related data might be relevant and what permissions will be needed to access them. By investing in an accurate inventory of the relevant data upfront, you can launch the project with confidence and avoid unexpected roadblocks or delays during the project.

Build a Data Analytics Team that Works
A recent Sunera survey of Fortune 50 to Fortune 2000 companies highlighted two key success factors for companies building internal analytics teams. First, companies with mature internal audit data analytics programs typically have resources dedicated specifically to data analytics. Second, program maturity correlates with the size of the data analytics team in relation to the overall internal audit function. A mature program often requires an investment of 10-15 percent of the overall internal audit budget. But with salaries skyrocketing and a high demand, it can be hard to snag the right professionals for your data analytics teams.

Using a strategic approach, you can build a skills-based team that fits the needs of your organization. Start by targeting individuals who have skills across a few key areas like business analysis, project management and data analysis. From there, look to add roles like IT specialist and data hygienist. These resources ensure you have the infrastructure support to scale your analytics programs. And finally, when you are ready for your data analytics program to really take off, consider adding individuals with graphic design skills for visual analytics and predictive analytics capabilities.

Fight Back Against Dirty Data
More than 25 percent of critical data in Fortune 1000 companies are “dirty,” meaning they are inaccurate, incomplete or duplicated. Dirty data can plague your data analytics initiative at any stage, derailing your budget, generating misleading results and potentially causing project failure.

The best (and only) way to fix the dirty data problem is through better institutional data governance. Proper data governance means clearly communicated objectives, processes and metrics; data quality controls and issue resolution processes; clear and documented data conventions; well-understood roles and responsibilities for analytics resources; and data governance training. Developing a robust system of data governance is worth the investment to ensure that quality data are available to your team.

Make Data Accessible With Visual Analytics
What good is data analytics if executives do not understand the results? That is the central question driving the spread of visual analytics platforms through audit functions nationwide. Visual analytics allows for meaningful exploration through analytic results, giving executives the ability to discover cost-saving or efficiency-improving trends, opportunities and relationships in the data.

Visual analytics gives executives and auditors a powerful tool to ensure that data deliver strategic and significant value to the organization. As you undertake each data analytics project, consider how the output can be visualized to communicate data in the language of your executives, speaking directly to the business challenge at the heart of the analytics initiative. With proper planning and a modest investment in tools and expertise, your organization can provide a far greater level of insight to executives making critical business decisions.

Cliff Stephens is a director in Sunera’s Data Analytics practice where he develops analytics to improve clients’ internal audit functions and provide value to executives. Before joining Sunera, Cliff created and led the Internal Audit Data Analytics team at Home Depot. To read Cliff’s full white paper on this topic, please visit https://sunera.com/data-analytics-pitfalls/.

Cliff Stephens
Director
Sunera Data Analytics

[ISACA Now Blog]

English
Exit mobile version