Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Friday, October 19, 2007

Counter to Intelligence

A top US counterintelligence executive says (http://www.cnn.com/2007/US/10/19/cyber.threats/index.html) that US networks are far too easy to hack into, and that nearly 140 intelligence agencies are trying to get in illegally.



First of all, how do they KNOW it's exactly 140? Maybe it's just the top 5 trying 28 different ways; possible isn't it?



Top 5 in my opinion? China, Iran, Pakistan, Saudi Arabia, Venezuela.

My wild guesses, needless to say. Most probably I'm wrong, or most probably I'm right. NSA is not talking.



Humor aside, the threat is very real - and not just to the US, of course. UK has also been reeling under similar threats. I blogged about this earlier on how China was using its extramilitary agency to do its dirty work. Conveniently you can then deny any responsibility for a 'renegade' organization's crazy plans. Too convenient.



What are the chances and what would be the impact/result of such an action taking an evil course, where the motive is not just to break in and snoop around a little but actually DO something?



Before we get into that, let's see what the current setup is.



a. Security awareness is pathetically low. People can be 'social-engineered' - if you have to Google the term to know what it means you're vulnerable already.



b. Security implementation is even worse; people pay very little attention (and respect) to physical security. If you have a sensitive server you want to lock it down OS-wise and physically as well so nobody can just push a button or disconnect cables.



c. Knowledge of key security concepts is woefully lacking. Most people wouldn't be able to tell you what encryption means (technical answers only).



d. Attitudes are also a problem -- people don't seem to appreciate what it means to be secure and what could happen in a non-secure environment in case of a threat. Further, they tend to treat security as an inconvenience than a safety measure (think seat belts in the 60s).



I'd like to stop here with the first part, and proceed to what connectivity means.



Connectivity means you place a call from your cell and turn on your microwave. It means watching a program recorded on a SlingBox-like machine, from across the world. It means paying your local Texas utility bills from Nigeria. It means logging in to work from an airplane. It also means the ability to get into someone else's computer without their permission. And do it anonymously, leaving no traces or leaving confusing, contradictory traffic patterns.



Therefore, when hackers penetrate a network and get into a sensitive machine they have the ability to shut down the entire water supply to/of, say, LA. They have the ability to shut down entire grids and freeze a country to death in the winter or boil a country alive in the summer. In essence, connectivity is a fantastic enabler of technology-based synergy, and it's also a huge liability when it comes to destructive ideas.

Like a row of dominoes, it's possible to take over all the computers of a company by logging on to the weakest one and going from there. As they say, a chain is only as strong...



What is the current threat level? Answer: VERY high.



Being ultra-secretive by nature, unnamed govt organizations that don't have an abbreviation or an address, and whose budgets are unlimited and oversight equally limited or nonexistent, but whose responsibility it is to protect the nation's security interests - may not always come clean.



A simple conjecture on my part with no facts: If they bet on security via obfuscation, everyone is in deep trouble. Security gets stronger by spreading knowledge of its existence and not by hiding it.



Consider an example: There are 2 houses, one with an electrified fence that says so boldly outside, and one with an ordinary fence that says "Beware of dog."

Honestly, which one would you pick if you were up to no good? I'd pick the one that says "Beware" because while I don't know what kind of a dog it is, it's a living thing, and all living things are mortal and also vulnerable to temptations of many kinds.



I'd avoid the electrified fence because while it's a known entity, it's also obviously dangerous. There are people that might say - you can cut off the power to the fence but you never know what the dog can do. However, which is easier: hunting for an electrical connection to mess with, or throwing a bone in the direction of the threat?



Anyway, I don't want to extend the example too much, but you get the idea.



In encryption technology, the key is the key and not the algorithm. The algorithm is public but the key is private, much like every home has a lock that is visible to the world but only the owner has the key to it. Therefore, security by obfuscation is a patently insane way to think about protection and safety.



What should the government do?



a. Hire the best security experts - with the highest clearances - and let them run amok. Get them to hack into whatever system they want (read-only activities, please) and document all moves. Identify with their help the best way to stop such threats



b. Hire white-hat hackers to do the same job in the most unorthodox ways possible - including social engineering - and again identify weak spots and fix them ASAP



c. Institute STRONG security measures throughout: No USBs, no portable drives, no cameras, no cell phones, no pagers, no electronic equipment at all in sensitive zones



d. Implement signal jamming - so that cell phones do not work inside and also no signal (such as keyboard/console) leaves the perimeter



e. Strong physical controls - use of biometric authentication methods for all systems



f. Auditing at every level for every phase of the working of the organization



g. Strong firewalls and private VPNs with absolutely no access to the Internet at any time



h. Logging of all incoming and outgoing packets for disassembly and analysis later on



i. Forbid the idea of remote office (no 'working from home' business)



j. No laptops - and if any issued, with self-destructing and beaconing software, with AES 256 or higher (it's the govt - they're bound to have the best already, unreleased) encryption



k. All desktops completely encrypted; all internal network communication also encrypted



l. Use of client certificates to be enforced

m. Multifactor authentication at remote sites also - syncing with the mothership for every change within a few seconds for maximum protection

n. Logging of all login/logout/download activities and cross-check immediately with employee if they are indeed performing this operation

o. Quadruple existing security budget, hire the best and pay them very well

p. Bonus based not just on performance but security proficiency and level of the department

q. Continual training on the latest threats, hacking methods, and countermeasures

r. Punish any lapse immediately, with severity going up exponentially with each recurring lapse (first probation, second suspension, third termination)

s. Reward good security practices by recognizing the person, and publicize as much as possible

t. Random deep-dive audits

u. Keep all software patched (incl and esp OS), and ban all external, uncertified software (glue up the CDROM, USB, and floppy drives if they exist)

v. Keep a record of all software deployments and have a plan B and a plan C in case deployment fails or a problem is found and so on.

I really doubt that foreign agencies will stop trying, and I really doubt the US is keeping quiet, either. I'm sure it's checking out the checkers as soon as it detects any penetration attempt and maybe does so even proactively.

Ultimately, security is not just about installing the latest patches or using the latest encryption techniques (like Quantum encryption methods used in Sweden for voting integrity), but it's about a mindset; it's an attitude that asks fearlessly, "What's the risk in doing this and how can it be done in a more secure way"?

Be safe!

Friday, September 21, 2007

More on eVoting (DRE Machines)

I just finished reading a document written by one Daniel Castro at ITIF (http://www.innovationpolicy.org/), a think-tank. When you hear the phrase "think-tank" two question should spring in your mind before you can trust whatever the organization has put out:
a. Who's behind it?
b. What's their agenda?

In this case, ITIF seems to be very industry-friendly sometimes (http://www.itif.org/index.php?id=76) and somewhat neutral or even unfavorable at other times (http://www.itif.org/index.php?id=56)

Read through the website to get a flavor of what they do and what they're about. It does appear they are non-partisan to some extent, but it's going to be hard to guess without knowing who funds them.

This particular post deals with a 'paper' written by Daniel Castro about the use of paper audits during voting (on DRE machines, or Direct Recording Electronic machines). Curiously, he seems very much against it.

A good section of the document deals with the problems of paper ballot (when he should be discussing problems with paper audits). The document lists a couple of DRE concepts that could be applied for audit purposes, but somehow seems dead set against a paper printout.

One argument is that it'd be less secure. In my opinion, NOT having a receipt would be totally insecure. Would you like to do without your bank statement? Would you like to blindly deposit and spend money not knowing what's going on? I thought so.

Much the same way, a voter MUST know if his vote was recorded (he may not know if it was tallied, but the document has a section that deals with it quite well) and he must be able to store that receipt for reference.

The author also seems against disclosure of source code, arguing (disingenuously) that not only the system's code but also any third-party software code as well as OS code would have to be distributed. I've read many issues relating to Diebold's source code for one of their systems (http://avirubin.com/vote/analysis/index.html) so the author's argument is dangerous in that sense.

Some redeeming features of the article:
a. It does seek some sort of auditing
b. It proposes interesting new concepts to deal with eVoting issues (mainly tallying and verification)
c. It advocates a favorable outlook to companies that disclose their source code

However, the way the paper tackles (condescendingly) those that are FOR a paper audit is childish, amateurish, and completely runs against what the tone of such a paper should be (at least a little scholarly, IMHO).

Overall, I'd simply ignore this document (See this: http://home.businesswire.com/portal/site/google/index.jsp?ndmViewId=news_view&newsId=20070920005900&newsLang=en) -- especially because of this (extract from the above link):

About the Election Technology Council (www.electiontech.org)
The Election Technology Council (ETC) consists of companies that offer voting system technology hardware products, software and services to support the electoral process. The ETC represents manufacturers of the voting equipment used by over 90% of the population in the United States. These companies have organized as an industry trade association to work together to address common issues facing the industry. Membership in the ETC is open to any company in the election systems marketplace. Current members of the Election Technology Council include Election Systems & Software, Hart InterCivic, Premier Election Solutions and Sequoia Voting Systems.

Also, see my post here:
http://threeheadeddog.blogspot.com/2007/07/review-of-electronic-voting-systems.html

My view is this: People DESERVE to
  • have a record of whom they voted for (verification/validation of vote)
  • know their vote counted (verification/validation of local tally)
  • feel satisfied that the total vote count reflects their decision/will with 100% accuracy (verification/validation of overall tally)

You can ensure the first by giving a paper copy of their vote (can be/should be anonymized -should have no tracking or identifiable information).

You can ensure the second by having a release of the total count from each machine for each county (along with audit verification by a third party - not the govt, not the officers of the electoral system, not a private company. How about the UN? :-)

You can ensure the third by repeating the above for the entire system (here the author introduces the use(fulness) of homomorphic cyrptography - a good idea, I think, with the use of, ironically enough, paper)

In conclusion, I wouldn't listen to any such so-called "think-tanks" or "policy centers" -- especially those that start with "Americans for" or have the words "Insititute" or "Center" in them.
I'd listen to the people.

Start by asking sane questions, and you will get surprisingly clear, smart, and highly implementable suggestions.
  • What are you comfortable with using?
  • Do you trust this voting system? What if we can show independent proof of how this works?
  • Do you have any better ideas?
  • How would YOU do it?
  • What problems do you face with DRE machines or mechanical systems?
  • What can we do to make sure we earn your trust in accepting the outcome of an election?
Grassroots organizations can help, too.
  • Initiate focus groups to determine how to make the system simple, easy, and trustworthy
  • Get communities involved (especially in depressed localities) in advocating the need for participation in the effort -- and to enhance turnout for the big event
  • Initiate training and education throughout the nation (will help in removing doubts, suspicions and misconceptions; with the added bonus that you may get some excellent user-centered design ideas)
And a non-partisan election commission should:

  • Make sure all machines pass a complete software (source code) test by a third-party validation agency (staffed by non-partisan scientists and researchers)
  • Perform all manner of intrusion and hacking (physical, electronic, electrical, remote) to gauge the security of the product
  • Assess all existing vulnerabilities and assign strict deadlines to fix the issues, then perform 100% regression testing
  • MAKE ALL RESULTS PUBLIC - the process should be totally transparent and auditable/verifiable by any interested parties

Be safe!

Thursday, September 6, 2007

The Monster Inside Monster.com

I'm sure many of you are aware by now of the data breach at monster.com, which not only affects monster.com users, but also the subsidiary that serves the military, called Military Advantage. Also affected was usajobs.gov (I think I got that right).

As of yesterday Monster could not figure out the extent of the breach and the depth of the data theft (meaning, what kind of data - how granular). But it does appear that names, email addresses, and other such common information were uploaded to a rogue server, which M.com shut down once they figured out where the siphoned-off info was actually going.

They are not able to trace the hackers yet, but I'm sure they're working on it. I'd say they better get the NSA and other such people involved - that's the only way to use the government's brute power to get to the bottom of this mess.

How does this affect most people? One of the main, potentially dangerous, ramifications is that users may be subject to blackmail. Not only that, but knowing most details about a user, including possibly home address, the hackers could initiate the infamous 'Hit Man' scam, where random people got mail that they're on a hit list and if they didn't send a certain amount they'd be killed. Very few people fell for it (from those who actually came forward to report the embarrassing incident) but I'm quite sure a significant majority kept quiet.

So, the same thing could happen here; think about the millions of records that were probably taken, and if you assume that only 1% responded to the blackmail, that's still a very large amount of money for the taking.

Where does the responsibility lie in this case? No question at all -- it's with the CISO if there is one; if not, the COO and CTO.

It's really remarkable that a company such as M.com, which has the trust of millions of job seekers, could not figure out the problem early enough, which would have saved a whole bunch of people a whole bunch of problems.

You also have fake employers posting ads wanting people and then scamming money out of the gullible, or even the street-smart ones. I don't want to sound as if M.com is not a good place to further one's career interests, but I'm still a firm believer in networking - PHYSICAL, human networking.

You know why bin Laden has still not been caught? Lack of humint (human intelligence), that's why. I was reading a very nice article on Newsweek that talked about the hunt for this insanely elusive mass-murderer, and they cited how he uses money as well as punishement (the old carrot-and-stick approach) to get his way and evade the technological might of the most powerful nation in the world.

What does this have to do with data breach? Well, who commits these acts? Not a self-learning, self-aware machine like HAL in 2000: A Space Odyssey (although that's not difficult to do), but HUMANS. It's people like you, like me, like us, who indulge in such nasty acts of damage and destruction.

It's impossible to prevent it (just read about the most current hacking controversy, that China's military is behind the hacking of Pentagon - and UK military's - computers). In this age, data is king; but information is the emperor. Getting random bits and bytes won't accomplish much, but it's the intelligence that puts those bits and bytes together that causes the real damage to the data ecosystem.

Certainly, precautions MUST be taken. All kinds of anti-hacking software should be installed, and users (usually the weakest link) MUST be educated in depth. I've repeatedly stressed the power of education on this blog, but I'm sure nobody at such data-sensitive companies including the government - neither management nor employees - take it seriously. You cannot change such a mindset overnight, but you can certainly take a stab at it.

How?

a. Hire white-hat hackers (Especially a Certified Ethical Hacker) so they can form tiger teams to hunt down vulnerabilities (remember Kevin Mitnick?)

b. Perform vulnerability scans as often as possible

c. Keep AV/Anti Spam/Anti Malware etc software updated to the latest version

d. Educate, educate, educate your employees and raise their awareness to the imminent threat that is the WWW

e. Isolate weak machines (those with vulnerabilities and either fix them or take them down)

f. Have an internal email system and an external system, so even if the external is compromised (which at some point it will) it won't shut the company communciations down. There should be a clear demarcation between the two, and they should NEVER mix

I could go on forever, but I need to stop before this becomes more than a blog and ends up a novella!

Be safe!

Friday, August 31, 2007

SONY's Latest Screwup

Which one, you ask.
This one has to do with another (yes, another!) rootkit problem. And it has to do with, ironically enough, their secure USB stick. How in the world, after learning a very bitter lesson with their idiotic DRM rootkit 'protection', SONY can create another fine mess is beyond me.

I really think they need a rethink on how they approach security, be it authentication via fingerprint analysis or simply protection of IP. Security by obfuscation is not security - it's a pathetic camouflage that will come unraveled before you know it. Companies such as F-Secure, McAfee are not twiddling their thumbs waiting for the next threat - they can already foresee what hackers are going to be up to.

And in such cases, rootkit exploits are passe' and so can be easily detected, as F-Secure did with SONY's misguided implementation of fingerprint data protection using that horrid method.

The problem here is not that SONY chose to protect the data, but the way they set about doing it. I think I can smell another class action suit rising up from within the dark war-rooms of plaintiff firms.

So, another lesson learned - a final one, we hope.

Be safe!

Friday, August 10, 2007

EMC's Purchase of Tablus

http://www.thestreet.com/s/emc-expands-data-security-reach/newsanalysis/techsoftware/10373440.html?puc=googlefi

This is a really good buy - EMC is fast expanding its Security offerings. Coupled with its content management system, it's not that hard to see where EMC is headed. And you already know that EMC bought RSA - and the wealth of knowledge that comes from RSA is unparalleled. The main competitor to EMC, NetApp, has DeCru, but I have not read up much about it, although it seems like a very capable product.

Tablus makes content PROTECTION systems; you can call it 'leak management' systems. The idea is that an administrator will prepare a policy of what's sensitive and assign a grade of some kind. The system then parses through the various files and figures out if they match the criteria set in the policy. Based on settings it can block/inform/audit the actions that took place on the protected object.
You know the rest.

Be safe!

Friday, June 22, 2007

What Else is Surprising? DHS in Trouble!

http://www.informationweek.com/news/showArticle.jhtml?articleID=199905838&pgno=2&queryText=


As I've mentioned many times before, computer security is taken too lightly by too many people. I hope the CIO of DHS doesn't think that way.
First off, we need a CISO *and* a CIO for an organization as complex and as bureaucratic as the DHS. The CIO and CISO should get together to formulate a strategy that will feed the needs of the IT dept (CIO) and balance it or temper it with the security ramifications that come with the needs (CIOSO).

My worry is that while Congress battles the powerful bureaucrats and while the bureaucrats expend energy in defending themselves, the door is left wide open for everyone to do what they want to do. In other words, the utter indifference to real security is what results in trojans, viruses, inappropriate and objectionable content invading the computers.

Another concern is that the computers are allowed to access the Internet! First off, you want to very severely restrict access to the 'Net, and if you must, make sure you have powerful tools to control both access as well as downloads.

Here's what a basic, 20-point policy would look like (for user-terminals/computers at least):
1. Disable floppy drives (or buy computers without them)
2. Disable CD drive (need special code to unlock and use - content to be disclosed first)
3. Disable USB drives
4. Disable any and all controls on the OS that will permit configuration changes (such as IE security level etc)
5. Disable all downloads from the 'Net (incl HTTP/FTP)
6. Disable all uploads to ANY location
7. Internal data transfer should happen through pre-mapped, controlled, and constantly-monitored, network drives - probabaly a departmentalized storage subsystem such as NetApp Filers or EMC CLARiiON etc
8. Use encryption as much as possible, both on disk as well as on the network
9. Use forced authentication at every entry point (no trusted hosts nonsense)
10. Disable installation of any kind of unauthorized programs
11. Use at least 2-factor authentication (password + random key as an example)
12. Go for biometric authentication whenever and wherever possible
13. Use AV software extensively, ensuring prompt and forced updates and reboots as needed
14. Use IDS (pref IPS also) software at every sensitive node
15. Control, monitor, and record ALL communication - IM, email, phone etc
16. Email clients should be tuned to only send mail to internal personnel - no external addresses should be allowed - EVER
17. Scan ALL incoming packets - and outgoing packets at sensitive nodes
18. NO ATTACHMENTS ALLOWED ANYTIME - email/IM - whatever mode of communication
19. Use hardware encryption devices and encrypt all data, everywhere. Use PKI devices to manage the keys
20. Finally, EDUCATE THE EMPLOYEES. Nothing works better than education

Watch this space for more ideas that DHS will probably never implement! Next I'll be focusing on actual employee monitoring details.

Be safe!

Tuesday, June 19, 2007

Security Companies Getting Bought Out...

http://creativemac.digitalmedianet.com/articles/viewarticle.jsp?id=153590

I think the recent buying binge demands at least some investigation into:
a. Exactly what these companies market
b. What does the software actually do
c. Is it ready to deal with, or can it be extended to deal with, latest threats
d. How easy is it to integrate with current solutions
e. Are these FIPS-compliant

In any case, it does look like the Security market is golden, and doing fantastically well. If you want to make a few million dollars, start with an idea, write up rudimentary software, say it patches up this threat and that vulnerability while scanning the network and making your morning coffee, and BOOM! your company's set for sale!

Seriously though, the real value of these acquisitions will come from how easily and painlessly the products integrate into current product offerings. HP just bought SPID, and if that could be merged into any of HP's products (logically so) then customers have one less thing to deploy, manage, patch, and keep inventory.

Overall, definitely a solid consolidation in the SS market is going on, and is long overdue, too, but quite importantly we should note WHO'S buying - that will indicate a stronger trend toward tighter bonding between existing enterprise management/monitoring tools and actual Security tools.

Now you could predict that IBM will have a significant share of Security-based revenues from its purchase of ISS, that EMC will carve out a bigger and bigger share of the market using RSA, that BT will reap the fruits of its bagging of CounterPane.

This is just the beginning of the trend - quite possibly we'll see the same and new software vendors buying more and more of such companies. Ultimately, one'd be hard-pressed to find a single Security ISV.

Hot areas will include:
a. Identity management
b. Patch management
c. Vulnerability assessment and management
d. Threat assessment (from internal and external sources based on patterns and trends)
e. Code and system-hardening
f. Security services and consulting operations
g. Compliance and regulatory assessment, management, consulting and validation
h. Outsourcing of Security tasks
and so on

Be safe!

Tuesday, June 12, 2007

Privacy Concerns and Google

Quite interesting, the recent concerns over how Google mines data and how it might use it when combined with its recent acquisition, DoubleClick. Plus, now you have street-level, 360-degree, detailed snapshot views of actual happenings on streets that Google has covered.

Somewhat creepy, a little scary, but mostly harmless. For now.
How Google addresses privacy concerns raised by both small privacy groups and organizations like ACLU, EPIC etc is to be seen, but it's quite likely that G, whose main edict is 'Don't be evil' may be forced more and more to live up to its grand statements. Only, you don't want it going the way of 'We don't do finance'...

What is the Security concern here? Plenty, plenty, plenty. Imagine this fantastic goldmine of data that tells you all you want to know about someone's secrets and the makeup of their psyche - right from search terms to visited sites to how long they surfed those sites to your most private communication (email). Imagine this fantastic data in the hands of a hacker. There. You know what I'm saying.

So, G, which employs the most brilliant minds it can afford to buy on the strength of its balance sheet as well as brand name, needs to REALLY tighten up its environment. You do NOT want embarrassments like when someone stole G's own blog and it had to do some red-faced explaining. We don't have to teach G about security and how to protect its data, but we do have a RIGHT to expect that what G knows, only G knows and nobody else. Plus, you also hope (wish, pray, beseech, request, beg, fight) that G also has a bad memory (think data retention policies).

Anyway, the coming few months are going to be very intense as the search, advertising, and portal markets heat up with existing giants waking up and new, disruptive technologies start chipping away at the heels of the Big Ones.

Be safe!

Monday, May 28, 2007

FBI Security

...or the lack of it, really, at least according to a GAO report that was on the news a couple of days ago.
Problems included lack of encryption (for sensitive data), improper or missing authentication and authorization of users before they accessed sensitive information, and improper or default configuration of network devices.

Usually, network devices come with a default password that's a pain to change because each piece of hardware has a different management interface. Let's say you have five network devices - two switches (from different vendors), a router, a bridge, and a gateway.

Each device will have a unique website, a different way to set passwords, and a different way they can be accessed. The point is that a lack of common management interface leads to some very lazy administrators.

Here's my recommendation:
All you network hardware vendors -- can't you work together to create A SINGLE interface that could be used to work with the multitude of devices!?
It'd make life a million times easier for everyone, and make the environment a lot safer. I'm not about to go into the details of what such an interface should have, and would entail, but maybe later.

For now, this is what the FBI should do:
a. Follow a proper process that would track every piece of hardware from cradle to grave
b. Make people responsible and accountable for changing passwords every 2 months (or as often as needed per the security policy)
c. Make sure the results of the password change are updated in a document that lists those devices that could not be modified (maybe they're getting serviced, or were down for some reason), and get to them ASAP
d. Provide a checklist to any manager that has people reporting to him, on whether his employees (and he himself) actually needs access to any sensitive data. Be harsh and do not be afraid of treading on egos - do what is important and necessary to keep the country safe. People who mind on the basis of ego are eminently dispensable, and could prove dangerous in their efforts to satisfy their power-hungry needs
e. Every vendor that supplies to the FBI MUST supply a password that is tough to crack (the default password should satisfy existing requirements) - maybe not ALL criteria should be revealed to the vendor, but a few, such as the length, inclusion of special characters, etc should be mandatory
f. Use a password management software to make sure these devices are in compliance at all times (as opposed to 'b') if resistance from people is high
g. All changes should go through Change Management control and sign-off must be received from the proper authorities before changes are implemented
h. Audit the entire organization every 6 months - this may seem too frequent, but it's completely worth the time and effort. After the first 3-4 audits, the time and effort required for each subsequent audit should reduce as long as compliance rules are being properly followed
i. DO NOT make exceptions at any stage - as the cliche goes: a chain is only as strong as its weakest link
j. The default access for any device in its original, default configuration should be DENY_ALL, and then it can be configured to selectively permit traffic and users
k. Use RBACs and ACLs to control, limit, and deny access
l. Use strong and detailed logging at all levels. Storage is cheap - lives are not

Be safe!

Thursday, May 24, 2007

Database Security

http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1255955,00.html

Quite an interesting article, and it talks about concepts that are very logical, obvious, and yet something that's hard to implement and track.
How so?

Let's say you're the CISO of a company/govt organization that has access to highly sensitive data such as taxes, divorce records, alimony and so on. What would be your first instinct relating to protecting the data? Encryption, RBAC, ACL...?
There are many choices and each comes with its own tradeoffs. 'Mindboggling' is a mild word for the conundrum you just got yourself into.

Believe it or not, people actually abuse power! Hmmm didn't know that one, did you?

Now that you do, start with the basics. Make a list of talented people who can handle the responsibilities that will be given to them. They should be held strictly accountable at all times when it comes to the ownership and privacy of the information entrusted in their hands.

Then define roles and responsibilities that will match those tasks. With the help of commercially available software, you can do that very quickly.
For especially sensitive data, institute authentication codes. Meaning, access to certain types of data should only be possible with the help of a code that's generated by a security officer who oversees the overall security aspects of the data.

Thus, you now have division of roles and a division of how the responsibilities are executed. How does this help? Two words - collusion avoidance (and detection).

Next, logging and audit control.

Make sure the software that you use can log certain types of searches and classify them as inappropriate when applicable. It should alert the manager or supervisor within a time defined by an SLA. This kind of alert is preferred to be real-time so any violation can be stopped immediately.
Audits should be performed on a regular basis, and at least 3 times a year on a surprise! basis. That will keep any potentially devious employees somewhat honest and probably catch those that have crossed the line before they could do more damage.

Rewards - any quarter/6 months/year when there have been no violations, every employee in the security team should be congratulated and rewarded for saving the CISO's reputation and bonus.

Continuous improvement -- this phrase is used so much it's almost near meaningless, but because it's almost meaningless, if I use it just once or twice it won't hurt.

But let me define it slightly differently -- CI means new ways of figuring out how to keep secure data secure (think new hacking methods, new forms of spyware/malware/adware/badware, spam, viruses, trojans - boy you have your hands full). How to keep employees from stealing data or misusing their newfound power. How to maintain the integrity of the system and its value.
How to have business running 24/7 with no bottlenecks from the DB department. How to maintain the system's authority as the final arbiter of the correctness of data that resides within.

Needless to say most of these have strong security angles, but the top rank goes to getting employees to keep the data secure and keeping themselves honest. Very honest.
Remember: Encrypted databases and password-protected sites are powerless to stop an employee with the proper key and password, but relevant training dealing in ethics and company policies pertaining to correct use and access of records, coupled with rewards for excellent and spotless conduct, should go a long way. Combined necessarily and mandatorily with the latest technology to keep data visible to only those that need to see it, this approach should be quite foolproof.

It's quite difficult, if not downright impossible, to expect 100% adherence to policy (otherwise we wouldn't have any scandals). So, the next best step to remedy and fix a potentially devastating violation in the future is to ENCOURAGE and REWARD good habits than simply discourage and penalize bad ones. This is not to say that the bad eggs should not be disciplined/terminated/penalized, but that good behavior should be recognized and made worthwhile.

Be safe!

Wednesday, May 16, 2007

Not Again! Yes, Again

http://www.networkworld.com/news/2007/051507-ibm-contractor-loses-employee.html

The link tells the story. Again. Someone. Lost. Critical. Data.
This time the information was unencrypted on some tapes - which makes retrieval a snap for those with the right tools. I think the govt should really step in immediately and pass legislation that would make encryption of all employee-related data mandatory, especially if such data were being physically transported.

I'm going to stop here.

Be safe!