Five Ways Firewalls Keep Getting Better

Firewalls have been a mainstay for cybersecurity for many years, but they aren’t perfect tools. Despite advances in internet and device technology, basic firewalls haven’t changed much since their inception. But researchers and IT experts are working tirelessly to improve the foundational model and provide a better layer of protection for firewall users.

The firewall basics
Firewalls aren’t especially complicated, but they can work in a few different ways. All firewalls can be customized with specific criteria, allowing certain types of data to pass through while stopping others from passing into the network. Packet-based firewalls allow or deny specific packets entry to the network based on those protocols. Other types of firewalls retrieve the packets themselves as a kind of poison tester, before passing them onto the network. Most firewalls exist as an appliance or application, used in conjunction with your network.

How firewalls are evolving
So, how is this basic model starting to evolve?

  1. FWaaS. One major development in the firewall space has been the popularization of firewall as a service (FWaaS). FWaaS is cloud-based.Working much like a cloud storage system or similar cloud platform, FWaaS provides a layer of firewall protection to your network, no matter how remotely located it is or how many new links you add to the network. According to Cato Networks, this is advantageous because it means the firewall is more reliable, and covers a wider distance. In most cases, it’s more cost-effective as well. Plus, cloud-based firewalls are often updated automatically by providers, allowing for a mode of constant improvement.
  2. Lower costs. Firewalls are also getting less expensive. The tools necessary to create and maintain firewalls are becoming open-source and more available, and firewall management is becoming more intuitive thanks to better user interfaces. Overall, this means companies have to spend less time managing firewalls and less money getting the physical accessories necessary to maintain it.
  3. Higher throughput speeds. Throughput speeds are getting faster, which is good, because internet speeds are getting faster, and users won’t tolerate a slowdown just because the firewall needs extra time to kick in. Because the firewall takes action on data packets before passing them along (no matter what type of firewall is in effect), the time between requesting and receiving data is increased significantly under normal circumstances. Modern firewalls are becoming more advanced, enabling them to complete this process faster, and reduce lag in retrieving information.
  4. Awareness of users and applications. Traditional firewalls operate almost exclusively in layers 2 and 3 of the OSI model, in the network and data link, dealing with packets and frames. But modern firewalls are taking things a step further, according to findings by NSS Labs, improving awareness of applications and users. This gives firewalls more options in terms of blocking and allowing access to data, and gives organizations a wider berth of coverage to protect their systems. For organizations with hundreds of users and dozens of core applications, this functionality is indispensable.
  5. Third-party and multi-factor authentication systems. Authentication is a pivotal step for most firewalls, verifying that data has come from a trusted source and that the users attempting to access that data have the authorization to do so. Newer firewalls have more advanced means of authenticating; for example, they might partner with third-party authentication systems to define and/or allow certain groups of users access to specific information, while denying others. Multi-factor authentication can also use multiple protocols to ensure the validity of a given user (or packet of information).

Your cybersecurity should be one of your biggest priorities, so your firewall demands your attention and investment. Despite advances in other areas of cybersecurity, your firewall is still the first line of defense you have against the cybercriminals who would compromise your data, and the malware that could otherwise infiltrate your systems. Pay attention to these keystone developments, and make sure your firewall is upgraded enough to provide the best protection.

Anna Johannson, Writer

[ISACA Now Blog]

CSA Summit Returns to Infosecurity Europe 2018

Seattle, WA – May 9, 2018 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, today announced the agenda for the second annual CSA Summit at Infosecurity Europe 2018. The full-day event will be held Tuesday, June 5, as part of Infosecurity Europe 2018 (London, June 5-7).

The event will bring together leading security experts and cloud providers from around the world to discuss global governance, the latest trends in technology, the threat landscape, security innovations, and best practices, in order to help organizations fully understand the capabilities of cloud and how to properly protect themselves from its potential risks. Attendees will also have the opportunity to take advantage of Certificate of Cloud Security Knowledge (CCSK) exam training and a workshop – Achieving General Data Protection Regulations (GDPR) Compliance with the CSA Code of Conduct.

“Today, cloud adoption encompasses a wide range of mission-critical business functions. Some organizations, such as those in the financial and government sectors, have made significant steps thanks to regulatory mandates, requiring a change in technology security as well as the mindset of security professionals,” said Jim Reavis, CEO of the Cloud Security Alliance. “This year’s Summit will examine these advancements and others as we look to provide companies with actionable advice on how they can best apply these technologies to their unique business needs.”

The CSA Summit at Infosecurity Europe 2018 will feature keynote presentations from some of the industry’s most notable thought leaders in cloud, who will speak on such topics as:

  • Security as a Service: Work Where Your Engineers Live. Julia Knecht, Adobe Experience Cloud’s manager of Security & Privacy Architecture, will explain how Adobe leveraged existing software development processes to enable their engineers to get security work done when and where it needs to get done —without the overhead of constantly trying to reinforce security-specific processes.
  • Confessions of a Cloud Security Convert. In this talk, Michael Farnum, solutions architect manager/South Texas for Set Solutions, Inc., will share what he has learned as he transitioned from a career in network and application security to one in cloud security and take attendees through his journey of converting to the cloud.
  • Quantum-Safe Cloud Security. ID Quantique’s Quantum Safe Product Manager Bruno Huttner will discuss quantum-safe security and the recent work of the CSA Quantum-Safe Security Working Group.
  • Threat Modeling: The Ultimate DevSecOps. Learn how to take DevSecOps to the next level using threat modeling in this session from Fraser Scott, senior cloud security & DevSecOps engineer, with Capital One. He will walk the audience through a threat model of a cloud-based service using the Open Web Application Security Project (OWASP) Cloud Security project, looking at it from the perspective of development, operations and security. Attendees will walk away with an understanding of how threat modeling can dramatically improve the security of services by identifying and addressing threats, and will have the basic tools and techniques they need to get started threat modeling their own cloud services.
  • Secure by Design IoT. In this session, Matthew Theobald, a Cloud Security Architect with Schneider Electric, will show how to significantly reduce an Internet of Things (IoT) device’s attack surface using an alternative approach for bi-directional data flows to arrive at an IoT solution that is secure by design. The session will include a demonstration of an IoT device which sends telemetry to the cloud and responds to commands from a web application to perform actions on the board. The demonstration will include a network scan to show the device does not have an addressable server endpoint.

Also on the agenda is the EMEA Chapters Panel, during which time attendees will have the chance to provide feedback on cloud issues that are specific to Europe, as well as:

  • Discover what is going on in their country;
  • Understand what research is being undertaken within Europe; and
  • Learn of various projects’ progress and how they can contribute to areas of their own areas of interest.

Additional Training

CCSK v4 at Infosecurity Europe 2018. Attendees who are thinking of taking the CCSK exam or who simply want to deepen their knowledge of cloud security controls and implementation will want to register for this 1-day training workshop on June 7. Taught by Peter HJ van Eijk, an authorized CSA training partner and noted cloud computing expert, the provides students a comprehensive 1- day review of cloud security fundamentals and prepares them to take the CSA CCSK certificate exam.

Starting with a detailed description of cloud computing, the course covers all major domains in the Guidance document from the Cloud Security Alliance, the CSA Cloud Control Matrix (CCM), and the recommendations from the European Network and Information Security Agency (ENISA). Participants are encouraged to take advantage of some of the online training that is provided in advance of the course in ordered to maximize the training’s benefit. Students receive an exam token as part of the course fee.

Achieving GDPR Compliance with the CSA Code of Conduct. This workshop on June 7 (10 a.m. – 1 p.m.) provides a brief overview of the European General Data Protection Regulations (GDPR) requirements. It explains the key role of the principles of accountability and transparency within the scope of the law and finally introduces the CSA Code of Conduct for GDPR compliance. During the workshop, representatives from CSA, the auditing community (ICT Legal and EY Certify Point) and a cloud service provider will walk-through a real-world scenario of how they can adopt the Code of Conduct for their organizations. Attendees of this workshop will walk away understanding:
which are the GDPR requirements for data controller and processors in the cloud.
what the CSA Code of Conduct for GDPR compliance is and how to integrate the CSA Code within their existing security program.

the importance of transparency and accountability from both the cloud service providers and customer perspective.
Presenters include Daniele Catteddu, CTO, Cloud Security Alliance; Paolo Balboni, founder of ICT Legal Consulting and chair of the CSA Privacy Level Agreement Working Group; Mayank Joshi, Manager, Ernst & Young Certify Point; and a representative from a cloud service provider.

To register or learn more, visit csacongress.org.

About Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security- specific research, education, certification, events and products. CSA’s activities, knowledge and extensive network benefit the entire community impacted by cloud — from providers and customers, to governments, entrepreneurs and the assurance industry — and provide a forum through which diverse parties can work together to create and maintain a trusted cloud ecosystem.

Media Contact


Kari Walker for the CSA 
ZAG Communications
703.928.9996
kari@zagcommunications.com

[Cloud Security Alliance Research News]

The EU’s Network and Information Security (NIS) Directive Goes Live Amidst Range of Expanding Cybersecurity Efforts

Yesterday was the “go live” date for the EU’s Network and Information Security (NIS) Directive. The NIS Directive was adopted in 2016, and as a directive, it sets out objectives and policies to be attained through legislation at an EU member state level within a certain timeframe (a process called transposition). Member states were required to transpose the NIS Directive into national law by May 9, 2018.

As the first EU law specifically focused on cybersecurity, the NIS Directive has three parts, affecting both industry and member state governments.

  • Requirements on organisations: The directive establishes security and incident notification requirements for “operators of essential services” (OES) (e.g., providers of energy, transportation, healthcare, drinking water, some financial services) and, to a less stringent extent, “digital service providers” (DSP) (online marketplaces, online search engines, and cloud service providers). The NIS Directive requires these companies “to have regard to the state of the art technologies” to manage risks posed to the security of the networks and information systems used to provide the covered services, and take appropriate measures to prevent and minimise the impact of incidents. Security incidents of certain magnitudes must be reported to national competent authorities. The above obligations apply whether the OES or DSP manages its own network and information systems or outsources them.
  • National activities: The directive requires member states to adopt national cybersecurity strategies; to designate national competent authorities; and to have one or more computer security incident response teams (CSIRTs), corresponding at least to the sectors covered by the directive, to detect, prevent, and respond to cyber incidents and risks.
  • EU-wide collaboration: The directive emphasises coordination among member states, setting up a CSIRT network (also to include CERT-EU) to promote swift and effective operational cooperation regarding threats and incidents, and a strategic NIS “cooperation group” to support and facilitate cooperation and information exchange among member states.

Officials in Brussels and other EU capitals have worked hard to make NIS successful. Many countries have updated or issued, for the first time, their national cybersecurity strategies. CSIRTs have been established, and legislation has been readied to transpose NIS. The European Commission has issued guidance to countries on effective implementation of NIS.  ENISA – the EU Agency for Network and Information Security – has also issued a range of guidance, including recommendations on the use and management of CSIRTs and recommendations regarding the security and incident notification measures for DSPs. .  The NIS cooperation group –  composed of representatives of member states, the Commission, and ENISA– reportedly meets regularly to coordinate efforts among EU countries, including sharing information about how to implement NIS as consistently as possible. To that end, the cooperation group has issued  non-binding guidelines on security measures and incident notification for OESs. The EU member states that have held the EU Presidency since NIS was adopted- Slovakia, Malta, Estonia, and now Bulgaria—have all made NIS implementation a priority, driving NIS-related activity including in the Cooperation Group.

Of course, steps remain. Some countries need to finish transposing NIS (not all countries made the deadline). Per the directive, they also have another six months to identify the operators of essential services established in their territories (this information might not be made public for security reasons).  And equally importantly, organisations covered by NIS will be determining if they must change their security practices to meet its requirements, and if so, how. The European Commission understands that more needs to be done, and announced May 4 that, to help member states rapidly transpose the NIS Directive and build their capabilities, the Connecting Europe Facility programme is providing €38 million in funding until 2020 to support national CSIRTs as well as other NIS Directive stakeholders, such as the operators of essential services and digital service providers.

As part of the May 4 announcement above, European Commission Vice-President Andrus Ansip, responsible for the Digital Single Market, Commissioner for Migration, Home Affairs and Citizenship Dimitris Avramopoulos, Commissioner for the Security Union Julian King and Commissioner Mariya Gabriel, in charge of Digital Economy and Society, issued a statement, noting that “The adoption of the NIS Directive two years ago was a turning point for the EU’s efforts to step up its cybersecurity capacities.” This is true.  However, NIS is just one of an expanding list of activities driven out of Brussels to improve cybersecurity. Many people close to the action in Brussels reported that attention to cybersecurity rose quickly among senior policymakers in the wake of the May 2017 WannaCry ransomware attack. In September 2017, EU President Jean-Paul Juncker made cybersecurity a major theme – for the first time ever — of the “State of the EU” address, highlighting the need for the EU to better protect Europeans in the digital age. That same month, the European Commission issued a package of cybersecurity legislative and other proposals. This included a new EU cybersecurity strategy, “Resilience, Deterrence and Defence: Building Strong Cybersecurity for the EU,” with a focus on protection and prevention of cyberattacks. Further, the Commission announced the intention to set up a “cybersecurity competence network” and a “European Cybersecurity Research and Competence Centre,” and a recommendation to establish an EU-wide “Coordinated Response to Large Scale Cybersecurity Incidents and Crises.” It also proposed a new law – the Cybersecurity Act — to increase and make permanent ENISA’s mandate, as well as develop an EU-wide certification scheme. This Act is currently being debated in Parliament and the European Council.

All these EU efforts are essential. They include important plans and activities: increasing cybersecurity-related education and training, stepping up law enforcement activities, and accelerating cyberthreat information sharing, to name a few. They also, of course, complement an array of actions being taken by the member states individually.

Palo Alto Networks commends European policymakers for putting cybersecurity front and center.  The NIS Directive hits a key milestone today, but today is simply a stage on a journey. The EU understands that cybersecurity is essential to economic activity and growth as well as to the user confidence in online activities that underpins it.  Companies in Europe, across all sectors, must ensure their business are resilient to cyberattacks as they embrace the digital world, EU governments need secure online operations, and consumers need trust in their online experiences. Ultimately, the more all EU member states can raise the collective bar the more the global digital infrastructure will benefit.  Palo Alto Networks looks forward to continuing to contribute to Europe’s efforts.

[Palo Alto Networks Research Center]

The Importance of Securing Your Cloud

One of the biggest misconceptions regarding the cloud is that you can rely on the cloud provider service to protect your business, your data and everything else your firm holds dear.

Take a minute to think about your own home security system. Do you just lock the doors with the key and head off to work, fully secure that your valuables will still be there when you get back? Not likely. Many of us have at least a simple alarm system in place on doors and windows. More and more people are heading toward the latest trends in home security: motion sensors, 24-hour video cameras, remote door answering, etc.

Why does securing your cloud matter? Three enormous reasons:

  • Your cloud provider is only managing part of your security.
  • Cloud security lowers the risk of data breaches.
  • The minimum level of security compliance should never be enough.

Your security vs. cloud security
Let’s talk about your security against the cloud service provider’s security. The provider has specific language in any contract it signs with you concerning what it is and isn’t responsible for if there is a security breach. In its 2016 “Cloud Adoption & Risk Report,” SkyHigh Networks reported that the average user in an organization employed 36 different cloud services at work. That’s 36 potential security breach points into your cloud and 36 ways for information to leak out. By introducing all of the apps you need to make your business run to your cloud environment, you must take on the responsibility of ensuring that they are only serving their necessary capacity when analyzing and manipulating the data stored in your cloud.

It is integral that you manage all of your cloud-based applications and treat them all as security risks until the day you can scratch them off that list. The old days of hiring a third-party app to plug-and-play into your network are long gone. Your best way forward should be with a Security-as-a-Service (SECaaS) solution. Just like your infrastructure, software and your share of the cloud itself, SECaaS is the scalable solution that can handle your growth but also downgrade in the event your business shrinks. Even an in-person, onsite IT expert is not available 24 hours a day, 7 days a week, but a SECaaS is. The service can deploy solutions instantaneously when problems or suspicious activities arise, unlike in a traditional setting where everyone is waiting around for the IT professional to respond to a call for help.

The high price of data breaches
As for breaches, a 2016 study showed that the estimated cost of a data breach for a company is US $4 million. If your company has an extra $4 million lying around, by all means don’t fret about your cloud security. That figure might seem high at first glance, but there’s far more at work here than merely a loss of data or intellectual property. When you take a public data breach, word travels fast. Your best employees will be more receptive to offers from competitors. Your recruitment will suffer as those entering the workforce and those seeking to switch employers will take a lot harder look at what sort of company gets breached and what kind of company they’re looking to work for. And last but not least is the impact your data breach will have on your company’s public perception. The public has an incredibly long memory when it comes to embarrassing incidents for public companies. Don’t believe it? Fast-food giant Jack in the Box had a scare with mislabeled meat in 1981, and 37 years later, it’s still one of the top Google results for the restaurant chain.

Nobody wants the minimum
You didn’t get into business to do the bare minimum when it comes to protecting your assets and your customers’ information. No salesman has ever told a customer that he’d do the absolute least amount of work he could to get the customer’s business. The same excellence you strive for in taking command of your market and maximizing your profits should be applied to keeping your cloud secure.

To ensure the security of your cloud, consider adding dimensions such as multifactor security, where even if an employee’s login name and password are stolen or compromised, the party that took it still cannot access your cloud without an additional layer of security. Simple steps like this can be the difference between a secure cloud system and one just waiting to be picked apart by hackers.

Marty Puranik, CEO, Atlantic.Net

[ISACA Now Blog]

Inclusion and Diversity: How Do We Lead?

At Palo Alto Networks, we’re committed to creating an environment where all the members of the team feel inspired to do their best work and contribute to the mission of protecting our way of life in the digital age. To do this, our team must better reflect the world we live in and secure with our products and services. For us, this means Palo Alto Networks should lead our industry on inclusion and diversity (I&D). It’s ambitious, but achievable, as we focus on fostering a workplace that welcomes every culture, gender, age, sexual orientation, disability, background and experience.

A key feature of our corporate culture is self-awareness, so let me start by sharing my perspective on how we’re currently doing. The short answer: we must do better as a company.

On our website, you will find numbers and percentages associated with the composition of our team across race and gender, which, as you can see, does not represent the world in which we live. While the data is humbling, sharing it is an important step in the work and commitment required to achieve true inclusion and diversity across our organization.

As a company, we’re experienced at bringing technology leadership to the market: launching, iterating, improving, and repeating those steps until we are the best. We will do that here as well. Research shows conclusively that diverse teams are more creative, innovative, and perform better than teams that are not diverse. Having people from different backgrounds – particularly those who have been historically underrepresented in the tech industry – at the decision-making table will lead us to better business outcomes and result in better products to meet the needs of the broad spectrum of people we serve worldwide. It’s common sense backed by empirical research. More importantly, it’s the right thing to do.

These numbers have prompted me to think a lot about the corporate culture we have cultivated at Palo Alto Networks. While I am proud of our core values of putting our customers first, transparency, and a “no egos” approach, at the end of the day, inclusion and diversity must be part of our company DNA if we are to make meaningful change. We need the entire company to embrace this effort.

Ultimately it all comes down to action. We’ve launched a number of initiatives to build a culture of inclusion at the company, through our own internal programs and by signing on to the CEO Action for Inclusion and Diversity pledge. Here’s a snapshot of where we’ve been focusing:

  • Launched our “Power of Inclusion” training program to help employees understand the research on inclusion and diversity, reflect on their experiences, personalize what inclusion and diversity means to them, and identify actions they can take to create a more inclusive workplace. All people managers worldwide will be expected to complete the training by July 31.
  • Recognizing that training is not enough, we are also in the process of planning ongoing, systemic efforts to put this training into action with toolkits and resources for employees and managers to help build more inclusive teams and a more inclusive culture.
  • Enhanced our hiring practices to better focus on attracting candidates with diverse backgrounds and expertise. For example, we’ve partnered with organizations like Direct Employers and InHerSight to post our jobs on over 150 channels focused on diverse communities. We are ensuring diversity in our interview teams and rolling out a “License to Hire” training program for interviewers to eliminate unconscious bias in our hiring processes.
  • Expanded our Employee Networks to foster a greater sense of community across our organization. So far, we have network groups for women, veterans, Black and Latino employees, and early-in-career professionals. Muslim, Asian and LGBTQIA+ networks are in the early stages of forming, and I encourage more to come.
  • Established the Mosaic advisory board, a diverse group of women and men from across the organization responsible for providing guidance on companywide I&D investments and championing I&D efforts within their own organizations.
  • Deepened our relationships with the National Center for Women & Information Technology (NCWIT), AnitaB.org, Women of the Channel, VetsinTech and National Society for Black Engineers (NSBE). With NCWIT, for example, we are creating training and resource kits for thousands of community college career counselors to encourage female and minority students to consider cybersecurity, and we will launch a new Collegiate Cybersecurity Award to recognize the cybersecurity achievements of college women.
  • Through our collaboration with Girl Scouts of the USA (GSUSA), we are introducing cybersecurity education to millions of girls across the United States through compelling programming designed to increase their interest and instill in them a valuable 21st century skillset. This national effort is a huge step toward eliminating traditional barriers to industry access, and will target girls as young as five years old, helping to ensure that even the youngest girls have a foundation primed for future life and career success. The first in a series of 18 Cybersecurity badges will be available to Girl Scouts throughout the United States in September 2018. We’re also partnering with Black Girls Code to develop a cyber camp that will be delivered this August.

There is so much more to do and, in addition to the internal discussions we’ll have as a company, we continue to seek input and advice from outside experts. We are committed to providing you with updates on our progress and look forward to suggestions and feedback.

Mark

[Palo Alto Networks Research Center]

English
Exit mobile version