The days of doing business with a handshake and a smile are long gone. However, one thing continues to remain constant—how few vendor contracts are updated, even if the scope of service changes. This can be detrimental to an organization, particularly if the vendor is handling sensitive data such as personally identifiable information (PII), protected health information (PHI), cardholder data (CHD), or confidential, intellectual property and strategic data (also known as CIPS).
Periodically reviewing—and appropriately updating—master services agreements ensures both parties are aware of the processes, data elements and where the data processing is being performed. In other words; contracts must be continuously reviewed and revised as scopes of work change. The best way (or at least, the cleanest way) to update the master services agreement is via addendums that are signed and dated by both parties.
Effective vendor risk management is in managing the details. A key consideration in developing a durable vendor contract also means identifying the success criteria for the vendor and includes:
The business unit’s requirements for the vendor
The technical requirements involved (e.g., data elements, IT components, connectivity)
The vendor’s requirements for the customer
To ensure that all expectations (performance, compliance, regulatory, etc.) are met—and no one is blindsided—it is important for the organization to identify early and manage the following key vendor risk operational points:
Coordination between sourcing and vendor management
Vendor risk classification
The monitoring of vendor performance
Effective use of assessment results
Responding to and managing vendor performance issues
But what do you do if the vendor is not living up to the agreed-upon expectations documented in the contract?
An exit strategy is a must when a vendor does not meet its contractual expectations. It is a prudent step for the organization to ensure that a backup plan exists to either redirect the work to an already existing vendor used by the organization or to find a new vendor (one that most likely went through the previous request for proposal [RFP] process).
In my upcoming session (#145—“Contracting for the Full Vendor Lifecycle”) at ISACA’s 2015 North America CACS taking place 16-18 March 2015 in Orlando, FL, I will discuss these and other challenges during the contract phase of the third-party relationship. Hope to see you there!
Tom Garrubba, CISA, CRISC, CIPT, CTPRP
Senior Director, The Santa Fe Group
Program Director for the Shared Assessments Program
With our data-driven culture, data must be and is everywhere. But public sector networks that secure this government information are being targeted by cyber criminals, terrorists and nation states. Cyber threats are growing against government IT and control systems running critical infrastructure and sensors, and the sense of urgency is real. It’s vital to our way of life and livelihoods that governments are able to keeps these systems secured.
At Palo Alto Networks, we continue to contribute to these efforts by creating the Palo Alto Networks Public Sector Advisory Council (formed in 2014), which is a consulting body made up of retired military and civilian officers that advise Palo Alto Networks on the cyber security challenges and technology needs of the world’s governments.
This year, we’ve continued our momentum in the public sector by adding Ryan Gillis to the Palo Alto Networks team. Ryan, formerly Director of Legislative Affairs and Cybersecurity Policy at the White House National Security Council, joins as Vice President of Government Affairs and Policy. His expertise in cybersecurity, and public policy are a valued addition to the team. Welcome, Ryan!
In other public sector news, Palo Alto Networks President and CEO Mark McLaughlin was recently selected by President Obama to serve as Chairman of the National Security Telecommunications Advisory Committee (NSTAC). The Committee’s mission is to provide the U.S. Government with advice from industry leaders on matters related to national security and emergency preparedness.
Ever since COBIT 5 was released, I have had the honor of both leading the ISACA Istanbul Chapter’s COBIT 5 translation team as well as supporting hundreds of COBIT practitioners with training and implementation professional support services. My clients serve the financial services, telecommunications, software, automotive production and retail industries. During the course of these engagements, I have found that most of my clients quickly and easily adapt some aspects of the framework while other aspects are perceived as more challenging and are generally omitted from the implementation process. My goal is to describe both these “quick wins” (slow fat rabbits) as well as the hard sells.
The new Process Reference Model with particular focus on the “Applying a Single Integrated Framework” principle has been a pleasure to implement as clients often asked me whether they should implement previous COBIT versions or some other framework like ITIL, ISO 20000 or 27001. I can answer with complete confidence that COBIT is integrated with all of them and that if they implement COBIT, they will have implemented the bulk of every other relevant framework and standard. For example, the Project Management Body of Knowledge (PMBOK) has some very detailed financial metrics, reporting and modeling approaches that are not present in COBIT 5. While they may be relevant to very large projects (billions of dollars), they are a bit too detailed to add significant value to projects at the size that most of my clients run (10s to 100s of thousands). That they are not a part of COBIT 5 is thus not relevant. The new “APO05 Manage Portfolio” process is a wonderful addition to COBIT in that it brings the framework into alignment with PMBOK in an area that I often found myself having to go outside of previous COBIT versions (often to Val IT).
APO03 Manage Enterprise Architecture is another new process that takes its inspiration from TOGAF. IT architecture and its critical strategic focus on selecting and supporting the “right” technologies for the business were very challenging to address with previous versions of COBIT. Describing the best way to select the enterprise’s IT building blocks required concurrently referring to TOGAF so that we could adequately address their control and management. Now, COBIT 5 includes this big-money area.
The new capability model has generally been a hard sell. My clients find the present capability attributes challenging to understand and miss the previous maturity model’s clarity, prescriptive approach and best practice content. The one aspect of the new capability model that is universally loved is that partially achieved process attributes can satisfy process capability. This new approach saves me from having to answer, “The framework says ‘no,’ but I will make an exception for you,” each time a client asked me, “Since we satisfy most of the next level maturity requirements, why can’t we be rated a 2.5?” I believe that most COBIT users would welcome a fleshed out version of the present capability model, provided that it included more detail about how to implement the attributes for each process. Even something as simple as mapping each processes practices and activities to specific attributes would help COBIT users understand how to easily implement the capability model.
Kaya Kazmirci, CISA, CISM, CISSP
Managing Director, Kazmirci Associates
As noted in the survey from MeriTalk this week (read the full report here), Federal IT pros cite numerous challenges with their current security solutions, including integration challenges, long provisioning cycles, performance shortcomings, fragmented solutions, and lack of security for their virtual machines.
Security for the data center and cloud computing has to ensure not only the protection of north-south communications (those to and from the data center) but also east-west communications (those between virtual machines). It must be able to quickly learn which IP addresses are changing, then automatically apply those changes contextually to update security policies. Otherwise administrators are left constantly chasing their data center changes – a cumbersome process that can leave the network vulnerable. You’ve heard us say it before, and you’ll likely hear us say it again: IT must also have visibility to what applications are being used within the data center or their cloud instance(s) and be able to contextually control who has access. But the reality is that the MeriTalk report’s findings signify either a lack of awareness of, or ability to invest in, the right security options for today’s consolidating, virtualizing data centers and cloud implementations. You can read more about what we do today to address all of the main technology challenges identified in the survey here.
What isn’t mentioned in the survey but which we do see in our own data is that 10 business critical applications – those typically found running in data centers – generate 94 percent of our customers’ exploit logs. This means there is tremendous risk within today’s data centers. What’s more, the widespread encryption used in today’s applications can actually be hiding attacker communications. Often, organizations feel that as long as they are monitoring their (cleartext) web and email traffic, they are secure. But that’s far from the case. You’ve likely heard us refer to the attackers today as “hiding in plain sight,” using applications and exploit techniques in innovative ways to mask dangerous threat activity.
Budgetary issues
Ironically, the consolidation of Government data centers and the adoption of virtualization and the public cloud, including AWS GovCloud, should conceivably save money. The Federal Data Center Consolidation Initiative (FDDCI) aims to reduce the costs of data center operations as well as the necessary hardware and software to run all of the data centers. The hope is that the reduction of the real estate footprint will also reduce costs and energy consumption.
Yet by all accounts, the U.S. government still lags behind in adoption. You can review another report MeriTalk issued earlier last year which is one indicator of how far behind the U.S. government may be on a number of these initiatives. According to MeriTalk, only 14 percent of agencies had completed their virtualization projects last spring, meaning overall, the government is estimated to miss $2.7B in possible savings. Apparently only 9 percent of agencies had adopted cloud computing, which again estimated to leave $3.2B in unrealized savings. These federal agencies point to network reliability and capacity issues as impediments. The good news is that when government agencies *do* choose to adopt consolidation, virtualization and cloud computing, they turn to Palo Alto Networks to provide good, sound options to secure data and applications every step of the way.
Encouraging sound security practices with employee education
Employee education is important but it’s not foolproof. The right security technology should always ensure the utmost protection regardless of human missteps. Processes such as red teaming to test user behavior and technology controls are also important. Regardless of how much you train, attackers will always evolve their techniques to fool even the most diligent employees.
Look at the evolution from blatantly obvious phishing emails to today’s watering hole attacks in which attackers target legitimate and well-used websites to plant malicious code. How would a government employee or partner know not to visit the same website he/she has always visited for a conference, for research, or to seek other information? The security controls we provide in our Enterprise Security Platform can block the URL or IP address – so you don’t have to rely on the employee’s knowledge or decisions. Threat Prevention can prevent malicious malware and Traps Advanced Endpoint Protection can prevent exploit techniques against vulnerabilities on the host or client machine – regardless of whether the IT team has gotten around to updating the software with the given vulnerability or even before they know about an as-yet-undisclosed vulnerability.
But that doesn’t mean we can ignore the employee education component. Train and retrain. Governments and all organizations can create mandatory employee training, but to be meaningful, the materials must be refreshed so that the knowledge sharing is timely and keeps up with the latest attacker techniques. You can also institute red team exercises against the people part of the people/process/technology triad to test employee knowledge of good security practices or “hygiene”. These are informative for everyone and can demonstrate real-world use cases (without necessarily naming the employee involved) which are always more informative than describing theoretical situations. For an employee, security training is as engaging as you make it — especially if you walk them through real-world scenarios and ask what they would do. Their responses can inform where you need to emphasize future training.
Looking ahead
The threats to federal systems will of course continue to grow. The payoff for a disclosure of sensitive government activities or disruption of critical systems is enormous for attackers as we all know. I don’t like to give the attackers any more attention than necessary to get across the point. The U.S. move to Continuous Diagnostics and Mitigation (CDM) is an important step to provide government agencies with ongoing visibility to what is happening on their networks all the time – not just a once-in-a –predetermined-period review of security controls.
I know that all of our government customers work hard to maintain the best security practices using the NIST Cyber Security Framework, the ISO 27000 series of standards. And don’t forget to include SCADA security in your overall security planning. The threats of today and the future will not be limited to the IT infrastructure alone.
As we begin the New Year, it is critical for companies to understand the impact of cybersecurity breaches and attacks—and young professionals can play a key role in this.
As a young professional, I believe our objective should be to help our senior leaders define security levels and protect their key assets this year. How can we plan to do that? Here are some of my ideas for the New Year’s resolutions for young professionals (though professionals of any age will benefit from these tips):
Knowledge-sharing: It is very important to share our knowledge with others because the world is too big to know everything. ISACA provides good support for knowledge sharing through publications, blog posts, guidelines and the community around it, including at conferences and local chapter events. Furthermore, using social media is a good way to exchange with people.
Also, I recommend planning meetings, security breakfasts and trainings with your colleagues to help them understand the objective.
Personal training plan: Each day, new security features appear and we need to continuously update our cybersecurity skills. This is why a personal training plan is useful. The Cybersecurity Fundamentals Certificatefrom ISACA’s Cybersecurity Nexus (CSX) or the Certified Information Security Manager (CISM) Certified in the Governance of Enterprise IT (CGEIT) certification can be a good way to upgrade your skills and get recognized. Also, the virtualization age allows us to create labs for making tests with few resources. Personally, I focus on enhancing my capabilities in risk and governance management, such as penetration testing.
Educating users, management and the board: Many times, a user clicks on a link and downloads malware or something of that nature. Educating people takes time and patience, but allows you to create a strong security culture that lasts through time. Do not hesitate to explain the importance of security with a pragmatic view that relates to their own interests. Some people are more careful about finance and others about personal responsibilities. Create some user-friendly guidelines such as a guide on how to protect your privacy on Facebook to help convey your message.
Discovering new cultures: All countries are different and we need to respect them and be aware about local cultures we work with. Personally, I want to leave my country this year to discover a new working method, a new way of thinking and to increase my comprehension about the world. One benefit about being a young professional at ISACA is that the global association connects you with fellow professionals from around the world.
And you, what do you plan for 2015?