WIRED Editor David Rowan Predicts Future of Audit, Governance, Risk Management

ISACA Now recently interviewed David Rowan, editor of WIRED magazine and keynote speaker atEuroCACS 2016. He discussed the future of audit, governance and risk management, as well as what can be done to stop cybercriminals once and for all.

ISACA Now: What are some of the changes/innovations audit, governance and risk management professionals should expect in the next 5-10 years?
Rowan: 
We are in a networked world of ever increasing transparency, as well as increasing vulnerability to data breaches. Starting with transparency, the recent breaches of client confidentiality over Panamanian accounts, and the Snowden disclosures before that, are a stark reminder that every professional’s decisions could tomorrow be scrutinized on the front page of the New York Times. If you’re an auditor or a risk management professional, are you comfortable with your advice, your private emails, your entire work life being exposed to the twittersphere? I hope so. At the same time, we’ll find foreign states and criminal gangs investing ever greater efforts in breaching supposedly secure corporate networks to transfer funds or steal proprietary data. How well defended are you against these real and growing risks? Is your CEO taking personal responsibility?

ISACA Now:  Will the technology of cybersecurity ever catch up to or surpass the technology used by cybercriminals?
Rowan: 
The single biggest worry I have today is our growing reliance on networked connections to keep our economy moving—the satellites empowering communications, the servers running our utilities, the corporate decisions being made on supposedly safe internal networks. The bad guys are terrific innovators; they understand psychology as well as technology, so whether they’re spoofing the GPS signal of a satellite to put it out of orbit or hijacking your home computer with ransomware, they’re delivering nicely rising profits at our expense. I’m not sure we’ve seen the political will or the corporate education to confront these criminals with well-resourced defense systems that can scale and can keep up with the bad guys’ rate of innovation. They, after all, have a great incentive:  you used to rob a bank because that was where the money was; today the money is all over the network.

ISACA Now:  You’ve interviewed many global influencers over the years. What key characteristics have allowed them to be so influential? Any examples?
Rowan:  When it comes to entrepreneurs who really build something huge—the Facebooks, the WhatsApps, the Kickstarters—there tend to be a few common characteristics in many cases. Often they are motivated to solve a big problem, something that really makes a difference and not simply make money. That motivation keeps them going through the tough bits. They’re often very resilient personalities who don’t take it personally when things go wrong, so they can get up and push past the problem. They’re often outsiders in some way who don’t see the rules other people rely on:  maybe they had dyslexia at school, or were immigrants who didn’t easily fit in, or were misfits in some other way. They have tremendous self-belief, which lets them motivate their teams as well as attract investors and the media. And often I’ve found they had difficult relationships with their father—I can’t prove this scientifically, but perhaps it’s something that leads them to be driven beyond reason to prove themselves…

ISACA Now:  You will be speaking at the EuroCACS conference 30 May-1 June 2016 in Dublin. Give us a brief preview of what you’ll discuss and what attendees will take away.
Rowan: 
My life is spent travelling to meet the start-ups transforming industries and the investors betting big on them, as well as the research labs designing the way we will interact in the future with technology. So I’ll translate what I’m seeing in real fast-growth businesses to how it will impact successful existing businesses in the next five years—and how consumer behavior is being transformed by everything from mobile screens to virtual-reality headsets. The bottom line is the world will never move this slowly again, as exponential technologies create massive new opportunities to build businesses that could never have existed a couple of years ago. So there’s a risk that delegates will go back to the office with a rather big to-do list of urgent things they need to do to become as innovative as the start-ups…

David Rowan, Editor, WIRED

[ISACA Now Blog]

Five Endpoint Backup Features That Help Drive Adoption

If you’re among the 28 percent of enterprises that still haven’t implemented a planned endpoint backup system, here are 5 key attributes to look for in a system, to help drive adoption and success. These recommendations are courtesy of Laura DuBois, program vice president at IDC, a global market intelligence provider with 1,500 highly mobile, knowledge-driven employees:

1. Supports Productivity
Look for a lightweight system that doesn’t put a drag on memory, so employees can access data and collaborate quickly. If the system slows people down, they won’t use it.

2. Increases Security
While some people think of endpoint backup primarily for disaster recovery, you should think of it as a data loss prevention tool, too. A good endpoint backup system offers a multi-layered security model that includes transmission security, account security, password security, encryption security (both in transit and at rest) and secure messaging.

3. Offers Intuitive Self-Service
Employees don’t want to wait for IT to recapture lost data. Having an easy-to-use, self-service interface allows employees to locate and retrieve their own data. Not only does this help increase adoption, it also cuts down on calls to the IT Help Desk to save administrative time and money. A survey of Code42 customers found that 36 percent had fewer restore support tickets after installing the CrashPlan endpoint backup system, and 49 percent reduced IT hours spent on data restores.

In fact, for CISOs looking to make the case for an endpoint backup system, DuBois suggests compiling Help Desk volume data and the productivity associated with it.

4. Supports Heterogeneity
DuBois’ research showed that the average corporate employee uses 2.5 devices for work, some company issued and some not. Your endpoint backup system has to accommodate today’s diversity in devices, platforms and network connectivity.

5. Handles the Added Traffic
Some endpoint backup systems can get bogged down with lots of users and not enough network bandwidth. Look for a system that backups up almost continuously, so the processing is spread out vs. taxing the system all at once and slowing it down.

To learn more, see DuBois’ webinar, “5 Expert Tips to Drive User Adoption in Endpoint Backup Deployments.”

Susan Richardson, Manager/Content Strategy, Code42

[Cloud Security Alliance Research News]

Next-Gen Drive: Rob Megennis Roars Back at the Grand Prix of Alabama!

Robert Megennis is a 16-year-old racing prodigy. Palo Alto Networks is proud to be an ongoing sponsor of Rob’s races for the 2016 Mazda Road to Indy racing season. We’ll be checking in to chronicle his adventures as a true next-generation competitor!

Rob’s road to the Indy 500 continues, including his recent stop at the Grand Prix of Alabama. Check out video and photos below:

Rob came from 10th on the grid to the podium, and his pass for third place was called the “overtake of the weekend.” Rob is the highest placed rookie in the championship standings and the only American in the top ten. More photos from Alabama are below:

If you’re in the Indianapolis area, be sure to plan for the Grand Prix of Indianapolis, held May 12-14, 2016!

Learn more about Rob:

Keep up with Rob’s journey on social media:

And if you’re interested in taking a Palo Alto Networks Ultimate Test Drive, check out our upcoming events:

[Palo Alto Networks Research Center]

The Benefits of Effective SIEM Policy Development

There is an imbalance between technical issues and process aspects related to security information and event management (SIEM). This gap is the root cause of some skepticism with and disappointment in SIEM.

Be aware that before implementing SIEM, it is necessary to establish the basis of the information security management system (ISMS), which includes considering the global management commitment, asset inventory and categorization, and risk assessment.

The SIEM process consists of following 5-step cycle:

  • SIEM policy establishment
  • SIEM infrastructure provision
  • Event treatment
  • Checking
  • Correction

This SIEM approach is based on the plan-do-check-act (PDCA) cycle. Consider the first step, “SIEM Policy Establishment.” Upper management should demonstrate a commitment to the ISMS, including SIEM, by ensuring the SIEM policy is established and is compatible with the business direction, context and risk approach. Usually, the chief information security officer (CISO) prepares this internal policy and obtains the approval of all stakeholders. This policy should be mapped with existing internal policies, such as defining detailed event lists into standard and baselines for servers and network tools.

The SIEM policy should contain these basic components:

  • Purpose of the policy
  • Scope of the SIEM infrastructure
  • Responsibilities of involved individuals
  • Compliance

The SIEM has become the core of an ISMS and security operation centers (SOC), but it is unwise to rely on just the technical aspects of SIEM. The SIEM policy is essential for ensuring effective SIEM within an ISMS. The time used for SIEM policy development is worthwhile; it will save effort in future steps.

Read Aleksandr Kuznetcov’s recent Journal article:
“Security Information and Event Management Policy,” ISACA Journal, volume 3, 2016.

Aleksandr Kuznetcov, CISM

[ISACA Journal Author Blog]

AutoFocus Lenz: Taking the Blue (Team) Pill

The Palo Alto Networks AutoFocus threat intelligence services accelerates analysis and response workflows for unique, targeted attacks. The services further make an immense set of threat intelligence available via the AutoFocus API, which can enrich existing security systems or workflows. Today, security teams can easily build scripts on top of this data using theAutoFocus Python Client Library (af_lenz.py) script, providing an even simpler way to extract and automate actionable information from AutoFocus, which can be used to respond or proactively take action, against security threats.

The AutoFocus Lenz script builds on top of the Python client library by providing a set of outputs that enable rapid extraction of relevant information that can be used for operational intelligence, or further research, by performing various analytical tasks for you.

To demonstrate some of the scenarios where this tool may be helpful, we’ve put together a short video showing it in action.

The video covers:

  • Enumerating potential targets of a malicious email campaign, within an organization, by dynamic behaviors
  • Pro-actively identifying C2 domains for blocking, pattern improvement, or further research
  • Converting dynamic analysis information into YARA signatures for in-memory hunting

For its initial release, there are 8 “functions” that pull back data from AutoFocus, based on your query, and display it in various ways to expedite analytical tasks.

  • hash_scrape – The most straightforward function, it simply provides output for each section of the analysis reports (e.g. Network, DNS, HTTP, File, Registry, Process), which allows for chaining to other utilities through the command line. This can be run for multiple samples to pull back large amounts of behavioral information.
  • common_artifacts – This function takes an AutoFocus query, iterates across all samples identified, and outputs the dynamic artifacts which exist in each sample across the set. The commonality percentage can be adjusted with the “-c” flag, such that you can find things that exist in 75% of the samples. This is useful while trying to build detective or preventive signatures across your security tool stack by identifying truly unique artifacts across malware families or campaigns.
  • common_pieces – Similar to common_artifacts function, but takes it one step further and breaks down the artifact entries into smaller parts. Where common_artifacts might match on “sample.exe, DeleteFile, C:\importantfile”, common_pieces will match on “sample.exe”, “DeleteFile”, and “C:\importantfile”. This is particularly useful when dealing with malware that randomly generates files, or injects into random processes, but also increases the likelihood of noise since there will be more matches.
  • uniq_sessions – Displays unique values across some of the more relevant session fields, such as filename, e-mail subject, and the application used for delivery. This can allow a blue team to quickly identify targeted users of e-mail campaigns, files to search for on endpoints, and get the jump on responding to threats.
  • http_scrape, dns_scrape, and mutex_scrape – These functions will iterate across all of the identified samples, scrape out the unique values for their respective section of behavioral artifacts, and then try to format and print them in a concise way. These can be particularly helpful when trying to identify all of the callbacks seen for a type of malware as they relate to HTTP and DNS traffic, which might be used to proactively put blocks into tool stack.
  • meta_scrape – This last function is more of a high-level overview of the items which matched your AutoFocus query, similar to if you were using the AutoFocus UI but from the CLI. Specifically, it provides the SHA256, file type, first seen date, malicious verdict, file size, and accompanying AutoFocus tags.

To further aid in pulling back only the most relevant data, output returned from the functions can be filtered based on how prevalent the artifacts are throughout the AutoFocus corpus of files. For example, if an artifact is seen in 1 million samples, it may not be unique to that sample and can be removed from the output.

For more details and usage examples, please check out the Lenz repo on our Palo Alto Networks GitHub.

Hopefully this will prove to be a useful tool for users of AutoFocus in ascertaining information quickly for verdict determinations, operational intelligence, defending their networks and preventing threats.

[Palo Alto Networks Research Center]

English
Exit mobile version