Security's Everyman

Security's Everyman

Friday, June 27, 2008

Lying for the truth

The SANS Newsbites email today has a link to this article on Forbes.com. It talks about the apparent disconnect between what Security and Privacy departments think is going on and what seems to really be going on. Now I'm not accusing anyone of lying to the Security/Privacy departments or to management, but it sure looks like someone may not be telling the whole truth. More than likely what has happened is a disconnect between these departments. Security/Privacy creates a policy that states that sharing personal data or sensitive data with third parties is not allowed. Marketing either is unaware of the policy or decides that the policy is stupid and ignores it. This is where my comments in the last post about being able to monitor, verify and enforce policy is crucial to it's success.

I know in my personal experience that I've been lied to about certain things. I'm sure I'm not the only one. I've asked questions and received answers that were incorrect and the person who gave me the answers knew that they were incorrect. When later confronted I was told that I was given the answer that I wanted. Obviously since then I've learned not to be so trusting (remember: "I like you. I just don't trust you.). Now I require proof and if proof can't be given then the answer is left blank and steps are taken to fix the issue.

The real problem in this is that by lying the company as a whole is put at risk. Proper security can't be put in place because the truth isn't known. If a incident occurred as a result of this lie then it could be detrimental to the company. Again I stress that if we are to do our jobs effectively then we need to know the truth and be able to verify that truth.

Why process trumps technology

My morning routine usually involves having Headline News on the TV as I'm getting dressed and packing my lunch. A couple of mornings ago I heard a snippet of a story about a child abduction from a daycare center in Arkansas that caught my attention. Obviously, as a parent and caring individual I was sad to hear that it happened but what raised the red flag in my mind was a comment that they were going to install security cameras to combat this.

When I got a chance I used a little "google foo" (OK, it really wasn't google foo but I like that word) and found an article to verify that was really what I heard. Here is an article that confirms that and adds a little more that either wasn't mentioned on HLN or I ignored didn't hear. This is a quote from the article.

Those picking up children are required to show ID, she said. She added the center is installing security cameras and is exploring a keyless lock pad that would require a different number for each family. A person could not enter the building unless they knew the code, she said.

My first thought was that putting in security cameras was a knee jerk reaction that really would do nothing to stop this from happening again. I would be helpful in identifying the person but will not stop this. I do think that cameras are a good idea but before cameras there needs to be policy, process and procedures. After reading the article it is obvious that they have the 3 P's in place but they were not effective in this case because someone failed to follow at least one of the P's.

Similar scenarios are played out in businesses and IT shops all over the world almost daily. Something happens and immediately knee jerk reactions occur. When the 3 P's and common sense prevail the reactions stop in their tracks. Unfortunately common sense often fails instead of prevails. Products are purchased just to "show" that we are on top of the situation. Decisions are made to ease tensions and worries that really do nothing to solve the real problem.

When Policy, Process and Procedures are in place, followed, monitored and verified then there is less need for knee jerk reactions because things work better. In order for these to be effective your employees have to know about them, what they say, how they work and that they are not suggestions. In some cases there needs to be specific training to ensure proper compliance with them. Having them sitting on your company intranet is not enough. If your employees don't know about them then they are useless.  Often these things are created just to keep audit happy and then they are forgotten about or blatantly ignored. This works for a while but one day it will catch up to you. When something bad happens or audit decides to verify whether or not you are following them then you will have problems.

The purpose of Policy, Process and Procedures is to ensure that you are doing things in a way that allows you to operate your business effectively, efficiently, securely. They also serve as a way to ensure that what you are doing can be repeated and verified. They are not just a bunch of documents that are boring to read they are vital to the long term success of your program. They are the things that makes your technology work effectively and that allow you to continue operations if the technology fails.

Wednesday, June 18, 2008

The nick of NAC gave me a paddy whack

Sorry for the title, but I just couldn't resist.

We're deploying a NAC solution at work. It's been a long process that is finally starting to see the light of day. We set up a small test environment and after successfully completing that phase we decided to roll it out to a larger test environment. Our engineer who is leading the project realized that there were a couple of potential snags with our current environment and that we may have to alter our test a bit. After much thought and discussion we decided that we didn't want to make that change. It would have been different than our "go live" deployment scenario so we felt that it wasn't a valid test. So the engineer continued to research and we decided that using a different switch for the test environment would not compromise our test plan too much. So it was set up and deployed to a larger test group.

While the testing was going on the engineer continued to work on what would be the  "live" environment. He was successful in getting one of the switches to work with the NAC setup but the other two switches that we were use wouldn't work. Everything was the same on the switches. Firmware, software version, code versions, everything but for some reason the switches wouldn't communicate with the NAC device. So the engineer decided to go ahead and move those of us on the old test switch to the new switch. In doing so he failed to complete part of the change and so those of us in the test environment were not prisoners of NAC. We could do absolutely nothing. Then to top it off the engineer went on vacation.

Luckily it didn't take long to figure out what had happened and we put the original switch back in the mix and got us all back up and running. Hmmmm, another potential disaster in the making for those who aren't adequately prepared for ALL potential issues.

Danger, Will Robinson, Danger

Disaster recovery is a key process in running a successful business. Failure to have an adequate disaster recovery plan in place can do impact a business in many ways. Disasters can cost you money, information, customers and in the worst cases it can cost you your business. How you prepare your DR plan depends on several things and every company implements differing levels of disaster recovery planning. Hopefully your DR plan takes into consideration several different disaster scenarios and each has different tasks associated with getting things back up and running in a timely manner.

One thing that we need to take into consideration is that disasters don't always come in "disastrous" ways. Disasters can strike in ways that you don't expect. Some of the ways that a disaster can sneak up on you are things such as not paying attention to when contracts expire is one thing that can bite you if your not careful. If you have a service contract and it expires the consequences can be disastrous. Also lack of planning can be a disaster for you. If for example you are planning on moving your web server hosting in house and you don't adequately plan you may have a disaster on your hands. You may find yourself down to the last hour and not be able to make the transition in a timely and secure manner.

We tend to think of disasters being events beyond our control but sometimes events within our control can have the same effect as a real disaster. Having plans in place for ALL scenarios is a good idea.

Monday, June 16, 2008

Hello, My name is Andy and I attend meetings

Hi, My name is Andy and I attend meetings. It started out to be just causal meetings with the guys on my IT team. We'd talk about things that we were working on and give tips to help solve problems. Then the meetings became organized. We meet weekly and had agendas and formal discussions. After that I started attending project meetings. These were more hardcore with people from different business units and the formality became more important.

I tried to stop. I didn't like attending meetings but I kept getting pulled back in. Of course the longer I attended the meetings became more hard core. Now I was expected to not only attend but to add value and actually be a leader. Before I knew it I even started leading my own meetings and encouraging others to attend. I didn't like what I had become but I couldn't kick the habit. What started out as once or twice a week has now become a 8 to 15 time a week habit. It's affecting my life and productivity at work. Now not only do I attend and am looked to for leadership and guidance but I've taken the next step. Document review.

That's right, I also review documents to ensure that they, and the projects they support, comply with our security policy and to make design recommendations. Now I spend my days writing policy, planning programs and working to ensure compliance. No longer do I configure equipment and troubleshoot network  and security issues. No longer do I spend my days working with technology.

No longer am I a technology geek. No longer am I a hands on engineer. My name is Andy and I'm a Professional Meeting Attender. Someone please help me find my way out.

Friday, June 13, 2008

GRC - Love it or hate it

Last week I received an email from a marketing firm wanting to know if I'd like to talk to Symantec about IT GRC and an upcoming announcement that they were going to be making. Usually I ignore these emails because my blog is NOT an advertisement for vendors. It's my place to voice my thoughts, good or bad, on technology and security. I try to stay as focused as possible and not get off on tangents regarding politics, religion, personal life, food, or anything else. That includes free advertising for vendors. Plus, I usually am not that interested in talking to marketing people about their product. If I want information on a product I want to talk to the engineers that designed it and support it. Not the marketers and sales guys.

Anyway, since I do have an interest in GRC and like the concept of it I decided to take the bait and have a conversation with them. So we scheduled a time and spent about an hour talking about what Symantec is doing in the GRC space. Of course they have a product that helps manage and maintain your program and that was they jest behind the conversation. They let me in on the announcement that they were making on Wednesday of this week and we had a good conversation. Then they invited me to sit in on a conference call of Wednesday this week where they were having a round table discussion about their offering and getting ready to make their big announcement as part of their Vision Conference. I wasn't sure if I'd get to because of the audit that we were having but I did find time to join in on the call. In preparation for the call they sent me an advance copy of the announcement and a report on IT GRC.

I tried to be a good blogger and read the report before the call but just didn't get the time to do more than skim it quickly. It looked interesting and like it had some good information in it, but I just didn't get the time to really read it. Then the time for the call came and I dialed in, pen in hand (my new Cross fountain pen that I LOVE to write with) ready to take notes and hear some good stuff regarding GRC. Of course you know that didn't happen. I was tired from lack of sleep and 2 1/2 days of audit and my mind wandered. I kept trying to bring it back and just as I'd get focused someone would talk who wasn't close enough to the mic and I couldn't hear them very well and I'd fade again. After about 45 minutes I gave in and hung up.

Today I see that Neil Roiter over at Search Security has a write up on the report and the Symantec Round table. You can check it out if you have any interest in what the report or Symantec has to say regarding this. There are a couple of things that I want to point out myself. It seems that the report seems to validate many of my thoughts regarding IT GRC. Mainly that it isn't about technology but about process. The longer I work in IT and especially dealing with security and compliance the more I appreciate how effective good processes can be in your program.

Here are the things in the Search Security write up that I really like. My comments are in blue.

  • The panel identified bridging that gap between senior management's business goals and IT operations as one of the keys to a successful IT GRC program, especially in complex global business environments with disparate regulatory requirements and a wide range of costs in different parts of the world.  No program is going to work if there is not an understanding between the business and IT as to what needs to be accomplished.
  • "A framework is a framework is a framework," said KPMG's Lesser. "It's taking the key portions and figuring out what are most important to your organization; what are the outside threats, risks and vulnerabilities that you need to consider, and what is going to provide the most value to your organization; defining a framework based on these industry standards that really fits your specific needs." This is so true. There are several good methods that work equally well. It all depends on what works for you and your organization. As long as the business agrees across the board what they are going to use they can all be equally effective.
  • Implementing automation tools, the panel agreed, was the last step in building IT GRC in an organization. See my post here for my thoughts on this.

  • "The poor approach is to say we're going to do IT GRC, and there are some automated tools available," said ISACA's Hale, "and let's implement these without really understanding what GRC is, what their objectives are, who's going to use the information, and how does it support their decision making." Unfortunately this mind set isn't limited to GRC programs. Tools can't fix everything and without good process and policy to back it up they can't really fix anything.

  • "There's no finish line with IT GRC; it's cyclical because the risks, and the threats and the landscape outside is constantly going to be changing." There is no finish line with much in technology especially security and compliance. If you ever get to the point where you think you are finished then you are likely to quit paying attention to it and you will end up in worse shape than before you started.

Tuesday, June 10, 2008

Audit driven programs

There are many different ways that a company can develop a security program and plan. Not all of them will work for all companies and a couple of them won't work anywhere. One of the best ways is to get IT and the business units together with Security and look at where you are, where you want to go and what you are doing to get there. You look at the threats to your environment and how your users interact with technology and the rest of the world. That includes Internet access, partner access, vendors, and a whole host of other variables. Once you have done this and have a general idea of what your risk profile is you determine your needs and how to address them. They you put together a plan to address the needs. (This is generic in principle, not every organization will follow this). Once you have your plan you start executing it.

What happens in reality is usually one of two things. You either buy what seems cool to you, what will allow you to check off the compliance check box, what you deem necessary just as "basic" security, or what audit dictates. Maybe I should restate that, What usually happens is a combination of any of the above and occasionally a "real" plan is in the mix.

I'm currently in the process of getting a "real" plan in place at my company. It's been a long and slow process but it is coming together. I have several projects that we are investigating and determining need for and priority of. There is a long list of things that need to be done and I have my idea of how things should be prioritized based on what my understanding of the business is. This is based off of conversations with business units and IT management. Again, nothing is set in stone yet.

Well, now audit has come into the picture. They are recommending several things that are being looked into already but honestly most of them are not towards the top of my list. So now I'm faced with the dilemma of either trying to convince management that what audit thinks isn't what should be our top priority or do I just quietly go with the flow and re-prioritize projects to reflect what audit recommends. I think I know what I will do. I'll take audits recommendations and compare them with my plan. I'll fight for a couple of the things and give in on a couple. I hate to admit this, but it is the reality of business. I'm not pretending that I know what is best and no questions should be asked, but I do know that audit does not know the full scope of our business and they are focused on a fairly narrow part that affects financial's directly.

I know the question that is going through everyone's mind is "Well, do you have management approval and buy-in on your plan. The honest answer.......... No, not yet. It's not quiet ready for that. They are aware of what I'm doing and what is on my radar and they agree with the general direction that things appear to be going at the moment. What I do know is that once audit submits their recommendations they are going to push to get them met before anything else unless I can convince them otherwise. No matter what happens it will be a busy year and full of excitement. Hopefully plenty of "blog worthy" things that I can actually write about.

Friday, June 06, 2008

In praise of documentation

One of the most important things that a company can do is to document their environment. This holds true for all areas of business. You need to know what you have, how it works, what it's worth (not just in dollars but to the operations of the business), how do you operate without it, what dependencies does it have and what depends on it. When you get into talking about technology you have a few more things to take into consideration. What does it take to keep it up and running, how is it configured and secured, what are the specs required to run it, and on and on.

This documentation gives you the needed information to continue operations, or get back up and running quickly if problems, disasters or failures occur. When done properly it can be the difference between continued operations and closing the door and hanging a "Gone Fishing" sign. It can be the difference between having a system back up and running in a matter of hours or days. Good documentation can cut troubleshooting time down to little or nothing.

Documentation also plays other roles. Auditors ask for lots of documentation of what you are doing and how you can prove it. They want proof of what you say and often good documentation is the proof that keeps them happy.

The problem is that documentation is no fun. Not many people enjoy documenting a server configuration or how the network is connected. Most of us in IT would rather build, fix and configure than document how we did it. This presents a problem when it comes time to rebuild a system and you can't remember how an application was configured or how you had an ACL constructed to help protect the financial department from engineering.

It can also become a nightmare when you get notice that an audit is coming up in the next few weeks or months. It's important to not only have your documentation in order but to know what it is that is expected and what you told them last year you would do this year. Spending a few weeks trying to figure out if you have met the requirements from last years audit and trying to gather all the information needed for this years in not much fun. Not to mention it takes valuable time away from other things that needs to be done.

Managing your documentation is an important part of any program. It is as important as any other piece and often more important. It's kind of like an insurance policy that sits in a file cabinet and you wonder why you spent money on it until you need it. Then you realize that it's worth every dime it cost you. Having someone who is good at documenting and can help you manage it will be a valuable asset to an organization. It will save time and money. It will help keep your stress level low and may well be the difference between a minor blip in operations and a complete shut down in operations.

Monday, June 02, 2008

The best laid plans.......

Growth can hit you square in the mouth if you are not careful. Growth can even kill you if you aren't prepared for it. Growth is good but like most things it needs to happen in a controlled manner. Not an easy thing to do when you are talking about your business and the success of a plan or product that takes you by surprise, even beyond your wildest dreams. Yet without a plan to address growth, even unexpected growth it can damage your business beyond repair.

In the last few months I've seen several incidences of growth that happened unexpectedly and quicker than expected. In many of these instances the companies have been sent reeling as their technology has not been able to keep up with the demand that is being put on it. Twitter is a perfect example. It's been around for a couple of years but as of late it has seen significant growth. Growth that it isn't prepared for. Growth that has all but taken it off line for much of the last week. Growth that may send users running to other similar services. Already within the security community there is a push to use FriendFeed as well as Twitter. Maybe even to replace Twitter.

I have a friend who works for a company that worked for years to build a business and they did build it. It was small but growing. A few months back growth hit them suddenly and their databases had a hard time handling the new load put on them. They have had a couple of outages but more importantly they have had several features of their application quit working properly. They had not planned (nor tested a plan) to handle growth to this degree. In the past as they experienced growing pains they just dealt with/ them as they arose. Now they are faced with/ potential crisis because they can't continue to operate this way. They have to fix the problems and put into place a practical plan that will address them and prepare so that they don't happen in the future.

With gas prices pushing $4 a gallon here in the US transit agencies are seeing big increases in riders. Many of them are experiencing growth related problems in regards to database usage, storage space, and scheduling routes for buses and trains. Increased routes means that there are more trains and buses on the road and rails that have to be tracked to ensure that they are where they need to be WHEN they need to be. Especially when dealing with trains being too early can cause real problems. Also you have to know when to stop, slow down, go and speed up. Technology is what allows the train operators know when these things need to happen. Last week Boston and Chicago (I think) both experienced passenger rail accidents. Were they due to growth issues? I don't know for sure but it's highly likely that growth did play a part in them.

How does this relate to Information Security? It has the potential to fall under the A in the CIA triad. These issues affect the availability of services and systems and although this type of availability issues are not usually security issues they can lead to security issues. If you database is under undue stress and heavy load then it makes it more likely that someone with malicious intent can sneak in and do something that they are not usually allowed to do. While under heavy load trying to process data it may allow a window where an attacker can bypass a security measure. If your service is off line or only sporadically available it could allow for someone to impersonate you and lure your users to their site where all sorts of bad things could happen. Not to mention that when you are focused on a issue that affects your users then security often gets overlooked or ignored. You are concerned with getting back up and running even if it means that you do something insecure.

I'm one of these who believes that information security touches EVERY part of the enterprise and needs to be included in all aspects of planning. This is just another example of how not only good business planning but also good security planning can save you lots of headaches.

Friday, May 30, 2008

Are they never going to learn?

Another day and another company loses unencrypted personal information on their customers. When are companies going to learn? When are they going to finally get serious about protecting their customers information?

ComputerWorld reports that the Bank of New York Mellon Corp lost back up tapes with PII on 4.5 million customers. The PII includes names, social security numbers, birth dates and other information on their customers. All the good things that a hacker needs to steal an identity or commit financial crimes in the name of innocent people.

Things such as encryption of backup tapes should not be an issue in today's world. Especially when you are dealing with peoples personal information. There is no excuse for this continuing to happen time and again. What is it going to take for companies to take this kind of thing seriously? Obviously the pain that they experience isn't enough to make them take note. The "myth" that a breach cost companies close to $200 per record can't be true or companies would stand up and do something proactive to prevent this. 4.5 million time $200 is  900 million dollars. If this is really what it would cost the bank do you think that they would still be shipping unencrypted tapes? No they wouldn't.

They made a decision to not adequately secure their customers information based on a risk assessment that they had done (formally or informally). They decided that the cost of the technology wasn't worth it to them because they knew that if something happened it wouldn't cost them enough to hurt. In my opinion this is irresponsible and negligent. If I were the law I'd even say criminally negligent. They aren't too concerned about the fact that their carelessness may cost a family lots of money, time and pain in trying to put the pieces of their stolen lives back together. And this bit about giving them a free year of credit monitoring is STUPID!

What makes this even worse is the fact that they waited 3 months to notify the customers. What good is a years worth of credit monitoring if your name and information has been used in the last 3 months to buy who knows what. By this time it could be too late! This is by far the most negligent part of this whole fiasco. UNBELIEVABLE!

I don't care how you've always done it

Martin Mckeay makes a great point on a PCI mail list. A question was asked about the need to keep full credit card numbers for the purpose of refunds. The questionnaires account group says that they must have the full number. The questionnaire has heard differently and wants clarification. What Martin said is that it's up to the acquiring bank to make the determination as to what is required for a refund. Now the company can make a business risk decision to still maintain the full credit card number for it's own reasons but they don't make the rules as to what is required for the bank to issue a refund.

What Martin said next is the really good part.

The accountants can say whatever they want about the process, but I'm willing to hazard a guess that they haven't talked to your acquiring bank about refunds in a long time, if ever.

This probably holds true for a lot on network and security groups. How long has it been since they've taken a long, hard look at what they are doing, how they are doing it and why they are doing it? Are they continuing to throw good money at a technology that no longer meets their needs? Are they using the technology in the way that best fits for them?

We need to step back from time to time and evaluate what we are doing to determine if it still makes sense. We need to stay up to date with not only new technologies but also with what the bad guys are doing. This way we can better assess if what we are doing is going to continue to be effective for us. It may be time to remove or replace a layer of security with something else that will work better for us. It may be time to change how we do something that will give us better information on what is going on on our network. It may be that we discover that a particular event is happening that is exposing our network to dangers that we were unaware of.

We also need to be constantly evaluating how we monitor things. Logs are great (OK, they suck, but they do provide useful information) but if we aren't collecting the right logs or correlating them with other logs, or looking at them (shame on you) then they don't do us any good. But what about other ways to see what is going on. Internal network scans and vulnerability assessments are a great way to learn more about your environment.

It used to be that we configured our firewalls to only allow specific traffic in and anything out. We've since learned that doing that isn't the best thing. It's the easiest because the users can do what they need but it also allows the bad guys to do what they need. Reconfiguring your firewall to only allow specific traffic out can stop lots of potential issues. You have to be VERY careful with this one because no matter how careful you are you will break something so be prepared to react quickly when that user yells with a legitimate issue.

I think I'm starting to sound like a broken record but I just see this too often. We have to be willing to change to keep our information protected. We can't rely on the fact that we've never had a breach (or just don't know about it), we can't rely on the fact that what we're doing has worked for us so far. We have to think ahead and think proactively.

Monday, May 26, 2008

Until They All Come Home

I just wanted to take a minute and say THANKS to all those who have served or are serving in the US Military. Today is Memorial Day here in the US. A time when we stop to remember those who died while serving our Country. It's also a day when we should be reminded of the sacrifice that is made every day by those who server in the military and their families.

It's a job that often goes without the thanks that is deserved. The work is often hard and dirty and the pay is no where near what is should be. Often they put their lives on the line to ensure that they are ready at a moments notice to answer the call. If they are in a combat zone then they are constantly on alert while in miserable conditions. Family members spend their days wondering if they will see them again. Yet life has to go on. Children are born while dad is away. Birthdays are missed, holidays are celebrated without them. Husbands, wifes, kids, parents all go through the day with a heavy heart waiting on the return of their loved ones.

I know because I have a close relative who is in a combat zone. He's there because he believes in freedom for all no matter the cost. He doesn't like being there but he is and he's doing what he has to do. Growing up I often thought that he was selfish but all of that is erased now. He proved his unselfishness by making the decision to put his life on the line for the freedom of those he doesn't even know.

I've always gotten a little choked up when I hear a patriotic song or think about the sacrifice that is made by those in the military but this year it's a little different. This time it's close to home and personal.

So to all of you who have served, who are serving or who have a family member serving I say THANKS!!! Thanks for the sacrifice that you are making. If you see a member of the military don't just walk by them stop and say Thanks. If you know someone who has a family member who is serving in the military let them know that you appreciate their special sacrifice. You'd be surprised at how appreciative they are at knowing that we notice what they are doing. Even if you don't support the war, SUPPORT OUR TROOPS AND THEIR FAMILIES!

Friday, May 23, 2008

It's Twitteriffic!

I'm on Twitter. I don't use it much. It's mostly a novelty. I use it to converse a little and to see what others are talking about that may be of interest. Sometimes I find good things to talk about in regards to Information Security. This is the main reason that I joined Twitter. A few of my friends from the Security Catalyst Community had accounts and so I thought I'd see what all the buzz was about. Soon after that Jennifer Leggio (MediaPhyter) created a "Twit List" of Security Professionals. It's lovingly called "Security Twits".

I've noticed that the level of participation varies from person to person. Some twit almost constantly. Some twit rarely. Some twit from work, home, school, conferences, birthing rooms, cars, airports, just about any where you can imagine. Some use the web interface while others use IM clients, Twitter clients, or their mobile phone/PDA. The twittering varies also in content. It might be a "I'm currently doing <fill in the blank>. Sometimes it's asking questions, posting links, making comments. Talking about sports, work, anything and everything.

What I've noticed though is that some people tell a little too much information. They seem to forget a couple of things.

  1. There could be lots and lots of people following them who do nothing but "lurk". They don't twit back. They just sit and listen. Who are they? What are the listening for? I know that I've had people "follow" me who are following thousands of people. There is NO way that they can be keeping up with all the conversations. So what are they doing? Are they harvesting all you say for some other reason? Research, information gathering about your company, looking for a way to discredit you, blackmail?
  2. Some people who are at work twit a lot about what they are doing and it's not work. Sure it may be a slow day and maybe the company doesn't mind you doing non-work related things from time to time, but then again, maybe they do.
  3. It's still the Internet which means that once you put it out there it's out there to stay. Remember there is NO privacy on the Internet.

So, my fellow "Tweeples" (as Kevin Riggins likes to say) be careful out there.

You can use any vendor you want as long as it's Cisco

Henry Ford's famous quote "The customer can have any color he wants so long as it's black." is echoed by many a network and security manager across the world. "Sure, get me a quote from Vendor X, Vendor Y and Cisco. Then they choose Cisco. Don't get me wrong. I like Cisco but they aren't the best for everything.

This article from Leadership Wired "The Challenge of Change" by John Maxwell. http://www.injoy.com/newsletters/leadership/content/issues/11_8/default.htm#1  spurred my thought process. How many times have you seen a similar situation played out in IT and Security?

In Ford's mind, producing multiple colors was foolhardy since black paint dried the fastest and could be used most efficiently. Amazingly, Ford did not comprehend the human preference for variety. Customers flocked en masse to other producers who catered to their color preferences, and Ford Motor Company never regained its grip on the market.

For so long, Henry Ford had focused on moving from inefficiency to efficiency that he refused to move in the opposite direction - from efficiency to inefficiency - even when doing so would have been wise and profitable. Ford's genius in sparking change had catapulted him to the pinnacle of American commerce, but later, his inability to change cost him dearly.

Often we get so caught up in the mind set that because it's Cisco (I don't mean to pick on them but they are the one that I've experienced this with the most) then it's the answer.

So how do we stay out of this trap and ensure that we are making the best choices for our business. First, we have to (this is getting redundant) know our environment, know our business, know our risk acceptance level, know our technical knowledge level, know what we are trying to protect and from who, know our budgetary limits. Once we have answered those questions then we can start to look at solutions. Evaluate them and make a choice based on what works best for you. If you don't answer these questions and just pick a solution based on who the vendor is, what it cost, it's the "industry standard", or how easy it is to deploy and maintain then you are not solving a problem, you're just wasting money.

It's our job and responsibility to make decisions based on what is best for the company. It's kind of like raising kids. Just because it's on the Disney Channel or Cartoon Network doesn't mean that it's what our kids need to watch. What is appropriate for a 12 year old isn't appropriate for a 5 year old and just because it's animated doesn't mean that it's good for any child to watch. The same goes for what we choose to secure our networks. Just because it's considered 'industry standard' or it's made by a big company doesn't mean it's good for us.

So if you've fallen into this trap step back and take a long, hard look at your selection process and refine it to best meet your needs. If it turns out that you still choose Cisco or whoever you would have chosen by "default" then that's great. However, if you discover that there are other vendors who can meet you needs better then you have a feather to put in your hat.

Did I do that?

That's the question that often needs to be asked.

I'm not responsible for physical security at my company. It is spread out over various departments depending on what it is that you are securing. One of those areas is building access. We have gates that you must go through to enter our headquarters building, a security guard at the front desk and a key card is required for entry.

When I started this position a year and 2 days ago I was issued a card with an expiration date of one year even though my contract was just 6 months. The 6 months came and went and shortly there after I became a permanent contract employee. At that time I was to be issued a new ID card given an employee number and sent on my merry way.

I did get a employee number but nothing was ever said about getting my new ID (with the employee number) and having my key card access updated. I mentioned this to my boss a few days ago and she said to wait and see what happens when it expires. We've heard "rumors" of some cards continuing to work well after the expiration date. So yesterday at 10:37 am my ID and Key Card expired. I went to leave the building and it wouldn't let me out. Good. This also meant that I should not be able to get back in this morning without being cleared by security.


This is where the problem comes in. Security is rotated regularly but it is always one of about 5 or 6 people. So after a while they recognize you. When I got here this morning my card didn't work (yeah!) so security just pushed a button and let me in. WHAT? He didn't ask to see my ID. He didn't check the terminal screen to see WHY my card wasn't working. He didn't call up to see if I was still employed here. He just let me in. Not good.

This is a perfect example of how a good system and process can be foiled by people not following procedures. All the technology in the world is useless if people mess it up.

Thursday, May 22, 2008

My standards aren't your standards

Something that I hear all the time that gets my goat is "What is the industry standard for that?". What I want to say is "What does it matter?". Very few of the companies in my industry have a network or environment anywhere close to what we have. Most of them run much smaller companies, networks and less complex environments. So what is standard for them is not standard for us. I understand what the intent of the question is but intent doesn't help us in this. What will help us is for us to quit trying to look like any other company out there and do what is best for us.

If we choose to go with a completely different architecture, technology or philosophy than anyone else that is fine as long as it is what works for us and what makes the most sense for our business model and processes. Industry standards, best practices and such are a great place to start but don't use them as the apex of your program. Just as PCI is a good baseline for securing your network that doesn't mean that it will ensure a secure network. You have to know your environment and what will work for you. That is YOUR industry standard. Your company and your environment are your industry. Not what another insurance office, manufacturing plant or real estate office is doing. It's not what SANS, NIST or any other organization says. It's what secures your company according to your level of risk acceptance, network environment, and company culture.

I Like You. I Just Don't Trust You

Here's a real world example of how trust can be misused from the most unlikely sources.

I received a phone call yesterday from a close friend who was VERY upset with her mother. It seems that she had trusted her mother with her MySpace username and Password for some reason. The mother was on it a few days back and was looking at some other profiles. There was one in particular of a girl who the mother isn't overly fond of and she left her a message under my friends name. Needless to say the message wasn't something that my friend would have said. Her mom did qualify by saying "(not friends name)" at the end but that hardly makes it any better.

You expect this from a kid but not from an adult.

Tuesday, May 20, 2008

GRC is NOT dead and it also NOT a Tool.

There is a debate going on involving the validity of GRC and whether it's living, dead or was every around. You can find some of the discussions here, here, here, here and here. I'm here to tell you that GRC isn't dead. It's alive and well and living in a business near you. At the same time it also was never a viable option for a business to buy. If we look at GRC as a tool then we are missing the point of GRC.

One of the biggest problems in Information Security is that we try to throw a tool at everything. Being technology geek's we seems to think that the answer to everything is technology oriented. There is no technology that can do any of these things for you. Technology can assist you in maintaining a secure and compliant environment but they can't do it for you.

Let's look at each of the three pieces of GRC individually and talk about how we can make them work within the business. This is not intended to be an exhaustive look at GRC or any one part of it. It's a common sense look at how each piece can work for you.

Governance basically means that IT is not driving the business but is working in conjunction with the business to meet the needs. How does process help out here? It starts with an understanding throughout the business that IT has to be involved in the process of finding a solution to a problem or need. That means that IT doesn't tell the business what the solution will be but it also means that the business doesn't drop something in IT's lap and then say "Make it work and keep it running". The process involves an understanding between all parties that they have to work together to reach a solution that meets the needs of the business while fitting into the infrastructure and design of the IT program. That is the easy part. The hard part is convincing the business that this is the best way to work. I can't help you with that much. That's a fight you have to fight on your own. I've got my own battles to win. :)

Risk is looking at your environment, the threats to it and how likely you are to have some of the threats realized. This involves knowing what you have, where it's at, what's wrong with it (vulnerabilities), who has access to it, who may be able to gain access to it, do they want it and what you can do to keep your risk at bay. Now there are all kinds of technologies that will help you with this but the key to it is having the right policies in place and the ability to enforce them. Knowing your environment is vital to maintaining a successful risk program. I can't tell you the number of companies that I've worked at, seen or talked to that don't have a clue as to what they really have nor where it's at. I'm not only referring to data but even technology and systems. Servers that were deployed without being added to the server management matrix, new switches that were put in but never noted. Changes to the flow of information that doesn't get documented. Get the point? You can't manage your risk if you don't know what the risks are. The technology required to manage this is expensive to buy and can be complex to maintain so that puts it out of range for lots of companies. So having policy and process in place is necessary to try and keep control over this.

Compliance is meeting the requirements set forth by various rules, regulations and laws. People will try to sell you all sorts of tools and technologies to make you compliant. The problem there is that none of them will make you compliant. I won't spend much time on this because it's been blogged to death. The key to compliance is just good security. When you have a good security program in place then you will only have to make minor changes to ensure that you are compliant with most of the regulations that affect you. There are few regulations that get so involved that they will require you to make major changes to a good security program.

So GRC isn't dead we just have to look at it from the right perspective. If we focus on it being a technology solution then if it's not dead we need to kill it. If we look at it from a policy, process and common sense perspective then it is alive and well and will thrive for years to come.

Wednesday, May 14, 2008

Life through the eyes of a security geek

I had dinner tonight with a vendor. They wanted to meet to talk about some of the challenges that I'm facing at work. We've had meetings before about what they can do for me and for my company to ease the pain of developing a security program and getting some of my initiatives off the ground and into production. As we talked about some the pains and the pain points (aka management and others who don't always understand security) one of the guys made a comment that struck home. He said that we look at the world through different eyes than network guys, server guys, application guys, etc.... How true.

That's why we can sit in a meeting and listen to someone from another IT discipline talk about a project and pick security vulnerabilities and issues out of thin air. These guys have been working on this for weeks or months and trying to avoid the very things that we see but still miss them. We have conditioned ourselves to not only look for potential security issues but also to look for ways to make it work in spite of the problems. We look for ways to enable business not hinder it. We look for ways to make things happen in a manner that secures the environment while allowing the user to do his/her job with minimal disruption.

I've said it before and I'm sure I'll say it again. IT is one of the first departments that needs to get a real clue as to how security works. IT needs to go beyond knowing how to secure their devices and environment but they need to understand security and how it affects the business as a whole. They need to understand how security fits into the business and not just how to secure. When you have one without the other you chance causing unnecessary disruptions, spending more money than necessary to secure the environment and deploying technologies that don't fit into the "big" picture.

So if you are in IT (or even if you aren't) take the time to learn what you can about how security works and why it works. It will give you a better understanding of why the Security department does some of what it does and it will allow you to deploy devices, applications and networks that are secure. They will be secure and they will be more likely to be secure in a way that fits into the big picture and in a way that fits into the business need.

Wednesday, April 30, 2008

I hack Johnny Long

 P4300561 As I said in my SecureWorld Atlanta Day 2 post I met Johnny Long today. He gave the Keynote talk today and was by far the best part of the event. He gave his "No Tech Hacking" talk and also talked a little about his new venture "Hackers for Charity" and explained what they do. After his talk I went to talk to him about a few things. I wanted to talk to him about his faith which is very much a part of who he is. I wanted to talk to him about "Hackers for Charity" and about "No Tech Hacking". We talked about the first two and had to cut it short before getting to the third topic. Of course the first two are the most important and made my few minutes with him well worth it.

I was a little familiar with "Hackers for Charity" but had never really checked into it. After hearing Johnny talk about it and seeing a few slides that he had I decided that I wanted to do something to support it. Right now I can't go to Africa but I can do a couple of other things. I'm going to buy a copy of Johnny's new book "No Tech Hacking". This will help because when you go to his site and click on the book link it takes you to Amazon and you can buy it there. Also when you do it this way all of the proceeds of the sale go to "Hackers for Charity" . The proceeds of the sale of just one book will feed a child for a month. Johnny isn't keeping any money from the sale of these books. So in addition to getting a good book I'll also be doing something to help the charity.

The next thing that I'm going to do is ask each of you to do a couple of things. Buy the book from Johnny's site and take a look at "Hackers for Charity" and see if there is anything else that you can do. Then tell all your friends about it and encourage them to do something.

Why am I making such a big deal about this? Not that I think that this is the greatest charity ever but because it is a charity that was started by a hacker and security professional. It's something that we as Security Pros can get involved with and make a real difference in the lives of kids and others. We all talk about wanting to make a difference in the world of security but that has limited impact. Changing lives is something that has lasting impact.

Creative Commons License
This work is licensed under a Creative Commons Attribution-NC-SA 3.0.