Application security continues to be a growing concern according to respondents of the latest (ISC)2 2015 Global Information Security Workforce Study. Consistent with the past two (ISC)² studies in 2011 and 2013, application vulnerabilities and malware are at the top of the list. These concerns are trending upward as 72 percent of survey respondents in the 2015 study selected this vulnerability and threat as either a top or high concern. As mobile platforms increasingly become the choice for delivering services, applications on the mobile devices are also a top concern for information security professionals.
As more sensitive data and transaction data is transmitted on mobile communication channels, the security risks associated with unreliable communications, such as public Wi-Fi, have to be addressed. Secure Sockets Layer/Transport Layer Security (SSL/TLS) has been widely used for authentication and encryption. However, fraudsters can set up fake Wi-Fi access points and fake Secure Sockets Layer (SSL) certificates to conduct man-in-the-middle (MITM) attacks to capture sensitive data.
Fig.1 Testing Environment – Simulate MITM attack; Source: “Best Practice Guide (SSL Implementation) for Mobile App Development” jointly published by PISA & HKCERT
In view of the growing concerns, Hong Kong Professional Information Security Association (PISA), the (ISC)2 Hong Kong Chapter, the Special Interest Group of PISA and Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) conducted a study on transaction security of mobile applications in Hong Kong. Based on our target scope of the study and search criteria, we tested a total of 130 mobile apps. One-third of mobile apps that involved payment transactions and personal information collection were found to be insecure. Thirty-four percent were vulnerable (i.e. vulnerable and serious); and 62.5 percent of financial securities apps did not validate the SSL certificates. With a vision to raise the awareness of public and mobile developers on the security of SSL implementation of mobile apps, we also released a report on “Best Practice Guide (SSL Implementation) for Mobile App Development” for mobile app owners and developers to use as a reference.
The collaboration between PISA & HKCERT was a perfect match, as PISA was responsible for providing technical advice on the Guide while HKCERT utilized its proven incident response mechanism for the study. While conducting the study, we were in contact with regulatory agencies and organizations in public and private sectors to follow up on rectifying the vulnerabilities found in the mobile apps.
Fig.2 Level Distribution of 130 Apps
The release of the report is only the beginning of our efforts to raise the awareness of mobile apps security. If we, as information security professionals, can conduct this study in various economies and compare the results, we can help raise attention and foster collaboration between government, regulatory and industry stakeholders in regards to application security. — Frankie Wong, CISSP, and Eric Fan
For more information about the study, the full report and Best Practice Guide are available at:
SFIA, the Skills Framework for the Information Age, has become the globally accepted common language for skills in the digital world. It provides descriptions of skills and responsibilities for professionals in and around information and communications technology.
SFIA is used in nearly 200 countries and is growing fast. It enables individuals to easily assess current skills and levels, identify skill goals and plan professional development, and match skills to roles and jobs.
SFIA Version 6, released in 2015, contains 97 skills, each described at one or more of 7 levels of responsibility. To aid navigation, SFIA structures the skills into 6 categories, each with a number of sub-categories. It also describes 7 generic levels of responsibility, in terms of Autonomy, Influence, Complexity, and Business Skills.
One of the areas that has grown since the publication of V5, and is therefore reflected in V6, is the area of cybersecurity. SFIA V5 contained three core skills for security professionals: Information assurance, Information security and security administration. All of these were updated in V6, including adding a level 7 description for Information security and level 1 and 2 descriptions for Security administration.
SFIA V5 also contained 10 skills which specifically included the word ‘security.’ Investigation identified another 22 SFIA skills which were regularly used to describe the roles of security professionals and were needed for security capabilities, but didn’t include the word ‘security’ anywhere. Apart from demonstrating the limitations of using word search to identify relevant skills—which sadly many users resort to—it highlighted how much coverage SFIA already had for this area.
Security references were specifically added to Solution architecture, Systems development management, Programming/software development, and Testing.
Digital forensics (DGFS), and Penetration testing (PENT) were also added to the skills list in V6.
SFIA works well with the various cybersecurity frameworks and information security standards. However, it covers a much wider scope, defining skills needed across the complete digital information and communications technology landscape.
With regard to digital forensics, cybersecurity and information security, SFIA is being used to help quantify and close the skill/capability gaps, providing a consistent model for all (ICT) professions.
It’s not just about determining the headcount gap regarding the number of cybersecurity professionals, but it assists in understandinghow organisations can build their own cybersecurity capability.
By understanding the unique skills required, organisations can determine if the gaps are in knowledge, role design and/or professional skills. It helps determine who needs upskilling, which roles may require a redesign, and identifying relevant training, mentoring, knowledge transfer and other development activities.
Of course, security is just one of the many ICT elements covered in SFIA. Organisations and governments around the world use SFIA in a multitude of different ways, from defining role profiles and job descriptions to recruitment and procurement. SFIA is also utilized in talent and skills management to quickly identify an individual’s skills, the skills they may be lacking, and recommendations for further education and training.
Note: Matthew Burrows is speaking on this topic at ISACA’s EuroCACS conference in Cophenhagen this month. Learn more about the conference.
Organizations around the world are quickly moving IT services to cloud computing platforms in an attempt to meet a wide range of business needs. From business organizations implementing a user-friendly and cost-effective SaaS platform for e-mail and calendaring to firms chasing wholesale adoption of infrastructure-as-a-service (IaaS), enterprise IT is clearly undergoing a radical transformation.
As services migrate to the cloud, there is high demand for security professionals experienced in adapting existing security controls to cloud environments. How can organizations gauge whether their existing security staff and potential hires have the knowledge required to operate effectively in a cloud-based environment?
(ISC)² and Cloud Security Alliance (CSA) recently joined forces in a unique partnership designed to address this problem for the entire industry. As the producer of the Certified Information Systems Security Professional (CISSP), the industry’s gold standard security certification, (ISC)² brings substantial certification expertise to the table. CSA, on the other hand, has a long background in developing and promoting cloud security standards. The product of their collaboration is the new Certified Cloud Security Professional (CCSP) credential.
Inside the CCSP Exam
The CCSP exam is computer-based and uses the standard multiple-choice format found on many IT certification exams. Candidates will face 125 multiple-choice questions containing four possible answer choices each. There are 100 actual exam questions, while the remaining 25 are research questions used to prepare future examination question pools. Passing the exam requires a scaled score of 700 out of 1,000 possible points from the scored exam questions.
CCSP candidates will not face simulation-based questions where they are asked to manipulate IT systems or perform configurations. The exam does, however, include scenario-based questions where the candidate is asked to read a detailed scenario and then answer several multiple-choice questions pertaining to that scenario. The questions in these sections follow the same four-option multiple choice style used on the remainder of the exam.
Candidates who successfully pass the examination must also demonstrate hands-on expertise in cloud security issues. Earning the CCSP requires at least five years of experience in information technology, three years of experience in information security, and a year of experience in one of the six CCSP domains.
Candidates who already hold CISSP certification automatically meet all three of the CCSP experience requirements. Candidates holding the CSA’s Certificate of Cloud Security Knowledge (CCSK) automatically meet the one year of CCSP domain-specific experience requirement, but must still demonstrate that they meet the remaining two requirements.
Exploring the Six Domains of Cloud Security
Cloud security is a specialization within the broader field of information security. IT professionals seeking a career in this area may wish to start with a general information security certification, such as CompTIA’s Security+, or (ISC)²’s own SSCP, before tackling a cloud security specialization. The six CCSP domains of knowledge focus on security issues specific to cloud computing and presume that the candidate is already familiar with the basics of information security. Let’s take a look at each of the six CCSP domains and the cloud-specific security issues they cover.
Domain 1: Architectural Concepts and Design Requirements focuses on the fundamental concepts of cloud computing. Candidates must have a working knowledge of cloud computing concepts and models, as well as the high-level security issues associated with the cloud, such as encryption, access control, hypervisor security and network security. This domain includes a focus on securing different cloud computing environments, including software, platform, and infrastructure services. Candidates must also demonstrate the ability to understand the principles of sound cloud security design and cloud service certification programs.
Domain 2: Cloud Data Security begins the certification’s deep dive into cloud-specific technical security issues. Candidates must be able to describe cloud-based data storage architectures and the controls commonly used to secure those environments, such as encryption, tokenization, data masking and data lifecycle management. This domain also includes coverage of data rights management (DRM) technology, retention, deletion and archiving policies and ensuring the auditability of cloud data events.
Domain 3: Cloud Platform and Infrastructure Security covers the physical and virtual security risks around cloud infrastructure. This includes the protection of virtualization platforms, communication between cloud services and implementation of audit mechanisms. CCSP candidates must be able to conduct cloud risk assessments and design appropriate security controls in response to identified risks. Finally, this domain also includes the development of appropriate business continuity and disaster recovery plans around the use of cloud services.
Domain 4: Cloud Application Security explores the application security issues found in cloud computing environments. Security professionals taking the exam will face questions relating to cloud software assurance, the software development lifecycle (SDLC) and the appropriate integration of identity and access management solutions with cloud-based computing services.
Domain 5: Operations dives into the new operational issues that arise from the use of cloud computing services. Many of the topics covered in this domain focus on the management of cloud infrastructure and are geared toward security professionals working for cloud service providers, rather than the customers of cloud services. Questions from this domain can be quite technical and explore the design, implementation and management of both physical and logical cloud infrastructure.
Domain 6: Legal and Compliance ensures that candidates grasp the complex legal and regulatory issues that emerge when organizations create and adopt cloud computing services. These include legal and privacy issues related to cloud computing, the impact of cloud computing on enterprise risk management programs and the auditing of cloud security controls. This domain also includes coverage of cloud contract design, security issues related to outsourcing arrangements and the management of cloud computing vendors.
The six CCSP domains cover a wide variety of topics but also dive deeply into technical security issues related to cloud computing. Candidates shouldn’t be surprised if they answer a high-level question about cloud security policies right before diving down into a detailed question on VLAN configurations that enable isolation between different IaaS customers. This exam is not for the faint of heart and should be attempted only by experienced security professionals who are quite familiar with cloud computing issues.
Will the CCSP Catch On?
The CCSP credential holds great promise, but faces some challenges to adoption. The unique partnership between (ISC)² and CSA provides good marketing clout, and (ISC)²’s deep experience in developing and marketing security certification programs strongly suggests that the CCSP credential will do well. That said, (ISC)² has tried to roll out specialized security certifications in the past with mixed success.
We’ll see some early indications of the CCSP’s viability based upon the number of candidates sitting for the exam over the next few months. (ISC)² aggressively marketed the credential to their strong existing base of CISSP credential holders and the waiver of the experience requirement is an alluring inducement for those individuals to sit for the exam if they are so inclined.
Basically, existing CISSPs only need to pay the $549 exam fee and pass the exam to earn the certification. If they adopt the certification in large numbers, that will help provide the critical mass necessary for the CCSP’s success. If CISSPs don’t get on board, then the challenge of building a strong contingent of CCSP holders becomes more problematic. In either case, (ISC)² will need to successfully identify and engage cloud professionals seeking security training if CCSP is to be more than a niche certification. Time will tell!
Mike Chapple is Senior Director for IT Service Delivery at the University of Notre Dame. Mike is CISSP certified and holds bachelor’s and doctoral degrees in computer science and engineering from Notre Dame, with a master’s degree in computer science from the University of Idaho and an MBA from Auburn University.
We are at a pivotal moment in time. Cyberattacks continue to escalate, and they have now emerged as a top technology risk in the World Economic Forum’s Global Risks 2015 report. Exacerbating this issue is the widening gap between demand and supply of properly trained cybersecurity professionals. We are in the midst of what is now described as a “perfect storm,” and as we wrap up another Cybersecurity Awareness Month, it’s the right time for ISACA to provide a forum for keeping the conversation moving forward.
Your roles—many as cyber first responders—have become more complex and more critically important to your organizations than ever before. Cybersecurity is more than a business issue and more than a concern over financial security. It’s a matter of public safety, and therefore needs to be monitored and addressed at all times. Cybersecurity doesn’t take holidays. Cyber threats don’t have borders and are fueled by smart and motivated people. The numbers tell the story:
83 percent of organizations believe that cyberattacks are one of the top three threats facing organizations today.1
86 percent of cybersecurity professionals say there is a global shortage of skilled cybersecurity professionals, and only 38 percent feel their organizations are prepared for a sophisticated attack.1
Nearly two million cyber security professionals will be needed globally by 2017.2
Attempted cyberattacks on corporate IT networks jumped 458% last year.3
And, recognizing these issues, companies will invest more than US $170 billion on cybersecurity by 2020.4
While these statistics are daunting, I challenge you to look at them as opportunities. Digital technologies are the backbone of the world economy, of our society, and are a key enabler of innovation, freedom and prosperity. Times like these enable us to look ahead and work together in addressing the evolving technology challenges that we face. Over the next few years, we can shape future technology decisions, traditionally based on benefits, cost and ease-of-use, to include a more strategic focus on security.
The need to improve cybersecurity is more urgent than ever as enterprises around the world struggle with finding knowledgeable and experienced cybersecurity staff. Hiring and retaining skilled workers is a significant global issue. However, there is an upside. The global skills gap creates a variety of career opportunities for students, recent graduates and professionals seeking a career change. Those who can demonstrate their skills in this area can earn higher incomes and choose the jobs that provide them with the most rewarding experiences.
Deploying technology and retaining the right staff to enable innovation and build the business is best accomplished when done in a focused and strategic manner. Cyber and technology advances, while fraught with risks, are bringing great opportunity. It is up to us to take the action necessary to capitalize on these opportunities for the benefit not just of our enterprises, but for the society as well.
As noted in our latest Global Information Security Workforce Study, the majority of security professionals (78 percent) anticipate the greatest need for new hires at the entry-level in their organizations. With a predicted shortage of 1.5 million global cybersecurity professionals by 2020, we must put efforts behind bringing more entrants into the industry. It’s one of my goals to bring more awareness to the Associate of (ISC)² program, which is ideal for students, recent graduates just beginning their career journey, or those new to cyber, information, software and infrastructure security.
Many college graduates today have a difficult time finding employment post-graduation. The information security industry has long experienced a shortage of qualified professionals, making unemployment virtually nonexistent. Bringing graduates into careers at the entry-level and setting them up on a pathway to success is essential to garner the growth we so desperately need. I believe that this program has enormous potential to have a real impact on not only bringing entrants into careers, but helping to develop the qualified security professionals needed to combat growing cyber threats.
By becoming an Associate, you, as an aspiring cybersecurity professional, join an internationally respected organization of nearly 110,000 professionals to network and learn. You also have the added benefit of earning a reputation for industry knowledge and expertise by passing one of our rigorous credential exams before you’ve obtained the requisite years of experience. Additional benefits of becoming a member include the option of joining a local (ISC)² chapter, and having access to monthly webinars, regional multi-day and one-day conferences, members-only InfoSecurity Professional magazine and more, all at free or deeply discounted prices for members.
Earning one of our certifications is a recognized accomplishment, career differentiator, and in-demand for industry jobs. A 2015 Burning Glass Cybersecurity Jobs report found that nearly 50,000 job postings requested candidates holding the CISSP in 2014. Those newer to the field may see our solid experience requirements as an obstacle and look elsewhere to start their career paths. But they shouldn’t! The Associate of (ISC)² program offers you the opportunity to earn the status that comes with becoming a member of our organization while you gain more experience, continuing on your career path to earn one of our credentials; thus advancing your career.
Associates of (ISC)² will also soon be able to broadcast achievements via digital badging. Digital badging is a major trend in the credentialing space, and is designed to translate learning outcomes, including certifications, into digital, web-based representations. These badges can then be broadcast to social media sites, shared via email, or added to a website. Sharing accomplishments in a verifiable way is also key for candidates to achieve their ‘dream job.’ When the program goes live in December, Associates of (ISC)² and members who have our certifications will receive an invitation to claim their digital badge(s) and begin sharing their accomplishments with the world.
As CEO for (ISC)², it’s my job to advocate for programs that I believe help to drive our vision to inspire a safe and secure cyber world. The Associate program, currently at more than 3,000 strong globally, has enormous potential to cultivate aspiring cyber, information, software and infrastructure security professionals to become part of a qualified workforce, filling the current and future needs of the industry. Let’s spread the word about providing a pathway for professionals looking for that first step on their pathway to a cybersecurity career. For more information about the Associate of (ISC)² program, please visit https://www.isc2.org/associate/default.aspx.