Cyber Security Lessons from “The Martian”

First things first, if you have not seen the movie or read the book “The Martian,” stop right now and do not continue because there will be spoilers. You have been warned.

On more than one occasion in my life as a security professional, I have felt like I was stranded on Mars – all alone with only my wits and spirit to survive. As I read The Martian, I kept thinking about what skills and practices would help a security practitioner in their day-to-day life. What would Mark Watney do?

During an ongoing attack, there is no time to deploy new tools and there is no one else who is more familiar with your network environment than you. Instead, you must use the tools and knowledge immediately available to survive, and time is not on your side. Maybe that is why this book resonated so well with me.

This post is the first in a two-part series. Watney’s approaches can be divided between methodologies and psychological skills, both of which are equally important in a stressful situation such as a cyber-attack. In this post, I’ll explore how Watney approached problem-solving and what logic he used to give himself the best chance of survival.

Science is helpful for what can be explained by science
Sciences like physics, chemistry and botany teach us that a small percentage of the future can be predicted if we play within the laws that are deterministic. It is within these formulas that we can predict the future outcome of an action, but what “The Martian” illustrates is even with all that science provides, the majority of the future cannot be determined and we just need to deal with it. Science only explains a very small percentage of what we as humans experience, so if you happen to be on the high horse of science, get off before you fall.

Science only takes you so far; for the rest you are on your own.

Adapt or die
During the entire time on Mars, Watney needed to adapt to an unfriendly and deadly environment. He needed to assume the role of farmer, trucker and construction worker to survive. As a farmer, he used his limited resources to create an environment suitable for growing potatoes to sustain a diet until rescue. As a trucker, he had to get his entire living space mobile for the trek across plans and mountains to a rescue craft. As a construction worker, he needed to modify the craft and reduce weight and other properties so that he could get to orbit with the fuel that was on hand.

All of these roles are crafts, which means they encompass not just processes and skills but resources and tools as well. Watney needed all of it to survive. It is likely that an individual in your organization fulfills multiple roles such as incident responder, business leader, IT operations, etc. as they go about their daily job. Adaptation is a survival skill on any planet.

Utilize lateral thinking
While Watney had advanced machinery and materials designed specifically for Mars, none of it was meant for use beyond 31 days. Watney had to stretch it for a year and a half and use it in ways it wasn’t intended. To do that, he had to get creative. He modified machines, adapted materials and jury-rigged a potato farm in his living quarters.

In cyber-security, organizations cannot afford to buy a new tool for every specific need. In fact, attempting to do so is ineffective and can lower the overall security. Instead, we must adapt our tools. Oftentimes, we can use them for purposes the designer did not envision and make them work with our other tools in creative ways. Again, this is also applicable to processes. What doesn’t work at another organization may work in yours. Maybe your team is versatile and benefits from regular role reassignments. Maybe your tools are also beneficial to network operations, which can help garner more funding for future cooperative investments. Don’t be afraid to try new and crazy things. It just might save you.

Plan for Failure
A plan is good until it makes first contact with the enemy. Unfortunately, systems sometimes fail and processes may prove ineffective. You cannot rely on success. For every plan that Watney thought of, he tested and prepared for failure. Whenever he made modifications to the rover, Watney would drive it around his living area for days to see how it held up to use. When he reestablished communication with Houston using the remains of the Mars Pathfinder probe, he created a plan on how to provide updates via Morse code should communications fail. Of course, Watney couldn’t imagine every failure scenario, but he planned for enough to keep himself alive.

In cyber security, we must plan for failures. Having strong network perimeter defenses are important, but they cannot be relied on as the sole source of security. Monitoring internal network traffic, utilizing proper segmentation and detecting anomalous and malicious behaviors are important measures to ensure attackers can be stopped after other measures fail.

Also, don’t forget to save a nice meal for the day you survive something that should have killed you.

Testing and rehearsals are critical
According to Watney, “in space no one can hear you scream like a little girl.” We can plan for failure, but that doesn’t make it any less terrifying. To avoid that terror Watney tested and tested and rehearsed and tested some more before he did anything. His modified rover had days’ worth of travel time on the odometer before he drove further than walking distance from the Hab. He put his makeshift tent through the ringer, breaking it in the process, before he ever spent a night in it.

Some failures are so complete that there are no possible backup plans, so we must push our tools and responses until they break in order to make them as strong as possible. This is the mentality behind penetration testing. Security teams need to know exactly what to do in the event of an attack. If they don’t know something, the need to be able to find it out – in minutes. Security tools must function properly under pressure, and responses need to be effective.

Start with these questions: Do you have an incident response plan? (You should) Have you tested that plan? (You should) Do you know what to do in the event of an outside attack? What about an inside attack? What are the limits of your tools? Are there any critical blind spots or vulnerabilities in your network? How do you know? Rehearse attack scenarios to find out the answer to these questions. Then rehearse some more, and do it regularly. If you don’t identify your own weaknesses first, someone else will.

Next week, I’ll cover what Watney did to stay sane in the face of isolation and death. I’ll also touch on what interpersonal factors were present in the entire Ares 3 crew, which ultimately allowed them to rescue Watney without losing a single person.

TK Keanini, Chief Technology Officer, Lancope

[Cloud Security Alliance Blog]

Big Data: Beware Comfortable Inaction

Former US President John F. Kennedy once said, “There are risks and costs to action, but they are far less than the long-range risks and costs of comfortable inaction.” He was speaking about ways to decrease antagonism among nuclear powers, but I think there’s a lesson in what he said for those of us in the business world as well. Specifically, sometimes things arise that seem risky in the short term; we’re nervous about doing them because of potential short-term risks or disruption to the organization. But when these potential downsides are weighed against the status quo (i.e., the “comfortable inaction” Kennedy was talking about), taking the short-term risk might very well be the more optimal path when viewed over a longer horizon.

This can be seen very acutely when it comes to adoption of new technologies. New technologies have the potential to be transformative to the organization—in both positive and negative ways. Positive benefits vary depending on the technology, but possible negative impacts could be disruption to business operations, potential erosion of the value of existing technology investments (for example, adopting a new technology would decrease the value of what we have in place now), and potential new technical risks as “kinks” are ironed out of the technology and organizations figure out how to safeguard usage of it.

Despite all this, pulling the trigger and adopting a new technology is often still the optimal path. Consider two hypothetical organizations competing in the same niche market. One organization implements a change that enables it to produce goods faster at lower cost; the other decides that it cannot or will not implement that same change because the short-term risks are too high. What are the logical consequences should the first organization adopt successfully?

Clearly, the organization that realized potential benefits becomes more competitive: it can satisfy more of the market, has the option to reduce price given the lower overhead, and can potentially focus attention and resources on other areas. In short, it has an edge. Even if the change carries with it some degree of potential risk initially, the potential upside trivializes the short-term downside risks by comparison.

The point I’m making here is that looking solely at the technical risks associated with a particular change misses a huge part of the equation. In evaluating the holistic risk to our organizations and making recommendations, we absolutely need to consider risks that may be introduced through adoption of new technologies, but we need to consider the risks of inaction as well. Nowhere is this more true than when it comes to Big Data analytics.

Big Data analytics is the use of advanced analytics techniques to operate on large sets of business data. This could be data derived from existing business processes and tools, data that exist independently of the organization such as social media, or new sources of data entirely. For many in the ISACA community, we know this can present risks. We know, for example, that there are privacy and security risks that can occur as a result of the adoption of big data analytics; in fact, ISACA has published quite a bit of guidance on exactly these issues. However, to evaluate risk holistically, we need to weigh these risks against the risks to the business should we choose not to adopt and adapt. Do the business gains outweigh the technical and other risks? Do the risks to competitiveness eclipse in the long term the short-term additional risk we take on? Good questions.

To help organizations answer them, ISACA evaluated Big Data Analytics—along with a number of other business trends—using anew methodology that attempts to objectively score risk and value impacts of business trends. The goal: find a reproducible and systematic way to find out what “megatrends” have the highest value potential in light of possible technical and other risks. Much like measurements such as “signal-to-noise ratio” or “earnings-per-share” provide an objective unit of measurement that organizations can use to inform data-driven decision-making, the goal here was to find a way that organizations can systematically assess and analyze these tough questions.

Of all the trends we investigated, Big Data analytics scored the highest in terms of business value created relative to potential negative risk impact.

Now, obviously every organization is different, so your particular organization may have unique factors that impact either the risk or the value side of that equation. You’ll certainly want to examine that data point through the lens of your particular organization’s needs, circumstances and business context. That said, given that it could be so impactful, it’s almost certainly a good idea to—at a minimum—ensure that strategic discussions are taking place about the role that Big Data analytics has in your organization.

There are some key questions you should be asking about how you might use this to forward your business goals and how your competitors might be using it to gain a competitive edge. We’ve tried to distill down the most critical questions that you might want to ask in our report covering the findings from our analysis, with the hope being to provide one potential framework around which those conversations can be built and those questions can be asked.

Ed Moyle
Director, Emerging Business and Technology, ISACA

[ISACA Now Blog]

Acting as a Liaison to Help Develop Secure Web Applications

A challenge that has developed in our work with US federal clients is taking a system that we develop here at RTI through the certification and accreditation (C&A) process and receiving an Authority to Operate (ATO). To date, we have at least 1t systems that have undergone C&A. One of my early learning experiences was working with the US Department of Homeland Security on a moderate impact web application that was developed and hosted at RTI. In this experience, I learned to act as an effective liaison between our development group and the DHS directorate’s security office.

As a member of our software quality assurance group, I was drafted into the development effort to help research and respond to DHS information requests. Gradually, I learned more about the system and the process and was allowed to take on more responsibility liaising with the client, eventually becoming the information system security officer (ISSO). Also, as our clients increased their security awareness and the demand for security experience increased, I became the “security guru” for multiple projects across multiple clients that include SAMHSA and CDC.

In graduate school, I taught literature and writing, and conducted my own research. I translated this experience to help development teams document their systems and to learn and apply the C&A fundamentals quickly. As an ISSO, I implemented processes to develop and maintain documentation and helped develop and maintain excellent communications between our development team and our client. One aspect of these communications was becoming the point of contact through which most communications were funneled. This allowed me to respond if I had the necessary information, or contact the appropriate person and gather information as needed.

We were able to meet our overall goals of hosting a successful, operating website in a secure environment, maintaining all applicable security standards, and meeting the client’s expectations and requirements.

Part of meeting these goals meant responding quickly to our client’s requests. We provided all information as requested, operated transparently (i.e., open and above-board communication), asked questions in a clear and respectful manner, and maintained civility in all our interactions.

It also meant operating in as proactively as possible. In addition to addressing client requests, we maintained a shared drive in which we placed all new documents and maintained archives that required regular updates and maintenance. Documents included the system security plan, the contingency plan, the incident response plan, and change control requests and documentation, among others.

Updated documentation was crucial for our first recertification effort. The client examined artifacts carefully. Due to the diligence of the project team, we were able to assemble a package that gave us recertification with only five minimal Plan of Action and Milestones (POAM) items to correct.

Other process examples include working with our IT system administrators to develop a plan to implement the required DHS Windows Hardening Guidelines. With nearly 220 items on the checklist, we devised logical groups, and then implemented and tested items.

I also serve as a filter for feedback from clients to our project team members and for communicating back to the client to help clarify issues. For example, our project developer might have a question about how the client wants a NIST control implemented. I contact the client ISSO and gather information.

Process and learning pay off. When our system was selected for an Independent Verification and Validation (IV&V), we were well-equipped with documentation and processes.

Craig R. Hollingsworth, CISA
ISSO, RTI

[ISACA Now Blog]

Managing Changes in Risk Management

Working with risk assessments and risk management is a challenging job. Everyone has an opinion, and there is no single outcome. Things change over time, and changing threat landscapes will influence the assessment and make it necessary to revisit the assessment again.

The area of risk assessments is covered by multiple theories and frameworks, which are no doubt scientifically well-founded but, at the same time, are difficult to make operational in a changing environment. We cannot gather all relevant stakeholders to update assessments quarterly.

What we can do is focus efforts on the critical assets top-down and keep these in mind when vulnerabilities and threats are identified. We can also make ad hoc assessments using the bottom-up methods when involved in projects and when asked to comment on new initiatives.

Of course, the methods should be formalized to make this repeatable and minimize reliance on single individuals. But the final delivery (risk assessment) is a snapshot in time and will, to some degree, always be the interpretation of multiple factors. Adherence to a cumbersome methodology will slow down the response time and, in the end, make the assessment inflexible. The risk landscape is diverse and so the response possibilities should be too.

Mette Brottmann, Klaus Agnoletti, Morten Als Pedersen, Ronnie Lykke Madsen, Michael Rosendal Krumbak and Thor Ahrends, CISA, CISM, CRISC

Read Mette Brottmann, Klaus Agnoletti, Morten Als Pedersen, Ronnie Lykke Madsen, Michael Rosendal Krumbak and Thor Ahrends’s recent Journal article:
Real-life Risk Theory,” ISACA Journal, volume 6, 2015.

[ISACA Journal Author Blog]

Global Privacy Study: How Does Your Organization Compare?

Major privacy breaches of customer data records are becoming common news headlines, shattering the trust of customers who expected the affected enterprises to protect their personal information. Almost 75 percent of the respondents to ISACA’s 2015 Privacy Survey indicate that their enterprises’ use of privacy policies, procedures, standards and other management approaches is mandatory, while 19 percent indicate that their use is “recommended.” This finding is a reflection of good practice because written policies and procedures should be at the heart of every enterprise, regardless of size.

However, less than one-third of the surveyed privacy professionals are very confident in their enterprise’s ability to ensure the privacy of its sensitive data. This is confirmed by the fact that more than half of surveyed privacy professionals believe that consumers should not be confident that enterprises are protecting their personal information.

Slightly more than 90 percent of the respondents to the survey report that the privacy function has a significant or moderate level of interaction with information security. This may explain why the CISO/CSO is a consistent selection as the role with primary accountability for privacy across all enterprise sizes. Unfortunately, nearly 8 percent report that no one is assigned to privacy accountability.

More than half of the respondents identify a lack of training or poor training as the most common type of privacy-related failure. This put an emphasis on the fact that privacy governance/management depends on regular, consistent monitoring of the program effectiveness, coupled with a commitment to making changes when weaknesses are spotted.

Any enterprise program as complex as privacy—requiring the coordinated efforts of many departments and individuals—requires a formal system of governance and management. Having the appropriate leadership and staff structures is an integral part of privacy governance and management. Increased (and increasingly diverse) regulation adds to the complexity, making an effective system of governance and management that involves frameworks, standards, policies and metrics a requirement. Operating in multiple jurisdictions adds a layer of complexity to privacy programs because it requires knowledge of and compliance with a wide variety of differing global regulations.

All of this is why ISACA is developing privacy principles for enterprises to use to develop a privacy program that is adaptable, flexible and applicable to the global population, with plans to publish the principles in the near future. These principles will use the COBITframework to provide structure and an implementation road map to guide practitioners through privacy management activities.

Yves Le Roux, CISM, CISSP
Chair, ISACA’s Privacy Task Force
CA Technologies

[ISACA Now Blog]

English
Exit mobile version