Information security teams work hard to secure the data that they are responsible for. They put in perimeter protections, network protections, host protections and all sorts of devices to monitor and manage all of these devices and protections. Configurations are checked before they go into production and all changes are tested and approved. All of this hard work pays off when you look at firewall logs, IDS/IPS logs, and the reports that your SIEMs generate to show just how many attacks are blocked, dropped and stopped before they get to the goal of stealing or damaging your data.
Of course we all know that this can easily be bypassed by one unpatched system, zero day exploit, reckless admin or user or a really good hacker or social engineer. There is always something that isn't exactly as it should be and that one thing leaves you vulnerable. There is one other area that information security needs to have regular contact with and influence with. Physical Security. Physical Security are the ones who are tasked with keeping the bad guys physically away from the data. Unfortunately, many times these two disciplines don't communicate with each other and this lack of communication can ruin the well laid plans and protections that have been put into place.
CISO's and their management teams need to be proactive and take the lead in reaching out to the physical security teams at their company. They need to collaborate with each other and they need to work together to ensure that the data is protected. Often physical security teams don't realize the dangers that a person can present when they allow them to roam the halls unescorted or when they don't do their job and ensure that a person is really supposed to be there. They don't understand that a good hacker may not be able to gain physical access to the data center due to other access controls in place but if he gets a hold of a hot network jack or a unmanned system. They aren't aware of the fact that a seemingly innocent flower, stuffed animal or other item can hide wireless AP's, mini laptops, wireless cameras, etc...
This is another reason that when you are rolling out a security awareness program you need to ensure that it's not a generic one size fits all program. Different departments need to be taught different things so that they are aware of the things that are most likely to affect them. A effective security program will reach out to all lines of business and work with them to be proactive in securing the data.
Security's Everyman
Wednesday, November 26, 2008
Infophysical Security
Posted by
Andy, ITGuy
at
5:36 PM
Labels: Andy ITGuy, information security, physical security
Friday, September 05, 2008
How NOT to work securely from a coffee shop
Many of you are aware that my favorite independent coffee shop closed about a month ago. Since then I'm having a hard time finding a good place to work from when I don't go into the office. I've tried another local coffee shop that is just too small and uncomfortable to work from. I've tried 2 different Starbucks that have very poor reception for my AT&T air card so VPN is out of the question. Today I decided to drive a little farther to another Starbucks to try it out. Air card reception is good, coffee is good, atmosphere (music, tables, light, etc) is good. So I'm pretty happy.
When I got here there there several people sitting around so I found a table next to a wall with an outlet and set up shop. The table is one of three along a long booth seat. The middle table was empty and the other end table was occupied by a lady who also was set up to work. Papers were out, cell phone on the table, laptop up and running. Shortly after I got here a friend of her's walked in and spoke to her. After getting his coffee he came back and asked her if she had a minute to talk. She said sure and he said lock your laptop and come with me. She looked at him like he was a little off in the head and said "What do you mean?" He told her to password protect her laptop so that this guy (looking at me) won't steal all of your personal info. I looked at him and said "Good advice, I am a hacker". Then, of course, I told him that I was one of the good guys. So she locks her laptop and they go to the parking lot.
While she is in the parking lot with this guy all of her stuff is right here. Laptop, purse, cell phone, papers (insurance settlement related I gathered from her phone conversations), purse (which I'm sure had here wallet with license, credit cards, etc). They were gone for several minutes, plenty of time for someone with less morals and ethics to do lots of damage. After a while she come back and unlocks her laptop and goes back to work. After a few minutes she places a call and starts talking about work stuff. I heard her mention a claim settlement and then she seemed to realize that she was in public so she gets up and walks to the back of the store. Again, everything is left right there but this time her Laptop is not locked. She can't see the table she was at and I can't see her. Another perfect opportunity to take something, read something, load keystroke logger, get CC #'s etc.... It's a good thing I'm a good guy.
After about 15 minutes she comes back and goes back to work. Again after just a short time she's talking on the phone and tells the person that she can go to her car and print something out. I guess she has a 12v converter in her car. So she unplugs her laptop, picks up her purse and leaves the building. She's getting better but she left her phone and papers sitting there. In a few minutes her phone rings and it's all I can do not to answer it. I resist and a few minutes later she returns with her purse and laptop. Plugs back up and gets to work. She stayed with her stuff for the rest of the time she is in the store, that is right up to the time she is ready to leave. She shuts down, unplugs and stacks everything up in a nice and neat stack. Then she goes to the bathroom with her stuff nicely stacked up and ready to be walked out the door. The shop was empty by now except for myself, the lady and a couple of employees who were not in sight.
This is a perfect example of what not to do. She made so many mistakes that I started to wonder if maybe this was some sort of a sting operation. I envision agents in the parking lot waiting with hands on guns for someone to do something illegal. Maybe someone with a high power lens across the street snapping pictures. If so then they failed to make a bust today. Maybe next time they will have more luck. :)
Posted by
Andy, ITGuy
at
3:54 PM
Labels: Andy ITGuy, information security, physical security, security awareness training
Friday, May 23, 2008
Did I do that?
That's the question that often needs to be asked.
I'm not responsible for physical security at my company. It is spread out over various departments depending on what it is that you are securing. One of those areas is building access. We have gates that you must go through to enter our headquarters building, a security guard at the front desk and a key card is required for entry.
When I started this position a year and 2 days ago I was issued a card with an expiration date of one year even though my contract was just 6 months. The 6 months came and went and shortly there after I became a permanent contract employee. At that time I was to be issued a new ID card given an employee number and sent on my merry way.
I did get a employee number but nothing was ever said about getting my new ID (with the employee number) and having my key card access updated. I mentioned this to my boss a few days ago and she said to wait and see what happens when it expires. We've heard "rumors" of some cards continuing to work well after the expiration date. So yesterday at 10:37 am my ID and Key Card expired. I went to leave the building and it wouldn't let me out. Good. This also meant that I should not be able to get back in this morning without being cleared by security.
This is where the problem comes in. Security is rotated regularly but it is always one of about 5 or 6 people. So after a while they recognize you. When I got here this morning my card didn't work (yeah!) so security just pushed a button and let me in. WHAT? He didn't ask to see my ID. He didn't check the terminal screen to see WHY my card wasn't working. He didn't call up to see if I was still employed here. He just let me in. Not good.
This is a perfect example of how a good system and process can be foiled by people not following procedures. All the technology in the world is useless if people mess it up.
Posted by
Andy, ITGuy
at
9:24 AM
Labels: Andy ITGuy, information security, physical security
Thursday, November 30, 2006
Refreshing Vendor Story
I met with a Security Vendor today. I told him what I wanted and he told me that his company could do it but that they usually did not work with financial institutions because that was not their specialty. He said that they felt better giving a referral to a competitor than giving us below par security. I kept waiting for him to start laughing but he was serious. He said that they are great at what they do, but for our industry they just chose to stay out. How often does that happen?
Posted by
Andy, ITGuy
at
4:42 PM
Labels: information security, physical security, vendors
More Physical Security
As I've mentioned in past posts I work for a small company and my role is multifaceted. I was hired for IT Security but that quickly morphed into managing all IT functions (if it plugs in, turns on, or looks technical it's mine), project management for new branch openings, managing facilities, and physical security. A lot of this has been trivial due to partnerships that we have had with other companies. I did little day to day, hands on with a lot of these areas. I just managed the vendors, partners and people who did the day to day. All of that is changing. The company that we partnered with that did a lot of this is parting ways with us. Come the first of February we will have brought all these things in house. Some of it will still be outsourced, but the direct responsibility of it will be on my team.
Because of the nature of our business and the location of many of our offices, physical security is a BIG deal. Prior to this job I had very little experience with physical security beyond typical IT physical security. Server Room access and monitoring and such. I got this responsibility because I have a security mindset like The Mogull talks about here. Now that I'm responsible for ALL aspects I'm learning lots of new things that are being done in the realm of physical security. There is some pretty cool stuff and what is really great is the convergence of physical security and the rest of IT. Were in the middle of talks with various vendors to get all of the pieces in place prior to February and choosing the right vendor for each piece will be critical to the safety of our employees and the success of our business. Luckily my inexperience in this area is offset by my security mindset and others in the company who have been in this and similar industries for many years. They are not security experts, but they have seen and experienced lots of things that add value to my information gathering. I'm getting hints, tips and ideas from executives, hourly employees and everyone in between. It's good to know that even if most of my users don't get IT security that at least they are thinking about physical security and have something to add.
Posted by
Andy, ITGuy
at
5:27 AM
Labels: information security, physical security
