Showing posts with label resilience. Show all posts
Showing posts with label resilience. Show all posts

Tuesday, April 7, 2009

Re-thinking IT Security in tough times

The current economic downturn is forcing a corporate change and metamorphosis that, when combined with ever broadening security threats, presents information security groups with an opportunity to radically change their identity and add more value to the business.

To capitalise on the moment, security groups need to reassess their approach, add visibility and transform the very role of security.

It is good timing because maintaining security during tough economic times is critical. Besides external threats that evolve even more rapidly in economic downturns, business slumps increase the probability of disgruntled employees striking out using intimate knowledge of corporate systems.

Risk is further exacerbated by the fact that, since the last economic crisis of this magnitude, companies have become far more reliant on information technology systems, which are now highly complex and essential to sound operations.

Your current security path represents existing programs, capabilities, processes, etc. The goal is to create a parallel path that influences existing practices and allows you to refine a new strategy without disrupting current expectations. In time, the new path will become a dominating force and take you in a new direction.

Step 1: Tuning the Approach
During the last decade security has been virtually defined by compliance. For many companies, it has been less about security than it has been about ensuring that certain regulatory demands are being met. Unfortunately, compliance does not necessarily enable the business, align with core initiatives, and alone may not thwart debilitating attacks.

Understanding this, some security groups have strived to use compliance efforts to improve their security posture.

Unfortunately, not all companies see the value of such activities and instead simply see compliance as a cost of doing business.

You have to convert the security practices that fall under the banner of "mandated for compliance" into specific activities that resonate with the business. For example, a predominant force in business is time to market and the rapid conversion of investments to revenue generation. This can materialize as a new service, application, communication platform, network or alliance. The key to tuning your approach is to optimize security features to help the business move more quickly, reduce barriers or accommodate a requirement quickly.

Key to being able to accomplish this is institutional knowledge within the security group and leveraging and combining resources in ways that benefit the business as much as it does security, for example: supporting secure coding practices through collaboration with the development team, optimizing standard builds to stand up servers more quickly, security testing as part of performance testing, or utilization of directory services to support streamlining of access controls for a new partner.

Fundamentally, it is about operating in a risk/reward model. Prioritize activities based on risk as well as where the greatest opportunities are for the business. By becoming intimate with business goals and mapping against elements of risk, what begins to surface is a common thread that demonstrates a point where the business and security goals become more closely aligned.

A good place to start is within the project management arena, where risks to the initiative or life cycle will become apparent, in addition to helping identify critical paths and what is most important or critical to the business unit. By using information of this nature, combined with institutional knowledge that the security group possess, you can begin to interpret demands and risks in business initiatives and quickly find areas of common ground.

Step 2: Adding Visibility
Security groups typically make security efforts visible to executive management by presenting security metrics, risk dashboards, and the like. However, along the way, many encounter some key challenges.

The first challenge is that the measurements are only focused on security and typically do not provide insights to other aspects of security operations that demonstrate effectiveness. For example, a dashboard may present compliance risk, operational risk, technical risk and current threats. It is assumed that keeping the values in an optimal or desired range means that security is doing its job.

However, company executives are increasingly focused on efficiency, effectiveness and overall alignment to business initiatives. They want to know how well these objectives are being met, what influence they have had on other key business performance indicators (such as time to market, customer retention), and how resources and other valuable assets are being utilized.

Executives are concerned about inefficient or wasteful activities and want to ensure all activities focus on the bottom line. Presenting to the board a risk dashboard can be helpful to demonstrate your alignment to security concerns, but that's only one part of the equation in the eyes of executives. The more effectively security can reduce the need to translate security results into something meaningful for the business, the better.

The second challenge relates to the "gap" factor. The gap refers to the difference in what security is providing to executives as visibility and the ability for the security group to influence the system to enact change.

For example, a report may demonstrate that the number of vulnerabilities in Internet-facing applications is increasing significantly quarter over quarter. However, the security group may not have the capacity or capability to reduce that number to a reasonable value. As a result, some senior security managers find themselves tasked to correct an issue they simply do not have the ability to accomplish.

In short, information from the security program is misaligned with its ability. Some use this to justify investments that would address the gap. But unfortunately this pattern is growing increasingly ineffective as business owners demand more accountability. The solution is to create a security program that not only presents good and bad trends, but more importantly, has the ability to have a meaningful impact in changing them.

The challenges can be summarized as providing visibility into more than security in security terms, but also in a manner that is more readily digested by executives and easier to align to business goals. Secondly, build a security program that not only produces meaningful information relative to security and business metrics, but also has the inherent capability to institute change and thereby meet expectations.

Providing additional visibility to existing risk-based perspectives can be enormously valuable. To accomplish this, you need to become more intimate with what resonates with the executives -- the measurements they focus on day in and day out, the performance indicators they study beyond the financial ones. Each company is different and each business unit may have a different spin. Moreover, many may seem like the furthest thing from security, such as shipping metrics, warehousing, capacity indicators, system use or even collaboration indicators. You have to look behind these to begin to see where security can begin to mimic the same philosophies.

From a security perspective, look to report on areas within your domain of influence and help reflect how well you're running as a business. It can be as simple as resource utilization, project involvement or performance quality scores from your peers.

From there you can start tying to other reported information and trends, such as the planned decline in effort to perform regular vulnerability testing, but an incline in report quality and effectiveness, essentially demonstrating that you are meeting security and business objectives. Or show how, through collaboration activities (which have been measured) and modifications to technologies, you've helped reduce the number of security related helpdesk tickets. These are, of course very basic. Nevertheless, the point is to find related information between what you are doing for security and how well you are doing related to business expectations.

This approach helps form your new path for security, drawing from your original strategies and enhancing them. Start small, test the waters and seek mentorship within the organization. As more confidence grows in providing additional perspectives on activities, you can move into closing the gap.

Step 3: Service orientation
By this point you've learned how to orchestrate your core competencies to help the business reach its goals using a risk/reward method. And you've started experimenting with adding visibility to the executives on alignment. As a result, the identity of security is beginning to shift. It may not be obvious, but it's happening. However, this is a critical stage and the time to innovate. Once executives see something they like, they want more, expectations increase, and that "good job" turns into "what have you done for me lately?"

One of the common pitfalls is not following through to ensure a foundation exists to keep up with new expectations. As a result, massive ground is lost and you're back to square one.

Adopting a service orientation can help you continue to move forward. Service orientation has three primary objectives:

1) Convert tactical best practices that were once hidden within compliance efforts into business services that can be consistently utilized.

2) Close the gap between what you can control/influence and what you're reporting on.

3) Create a foundation for building a highly agile security approach.

The key is to learn from experimental practices in tuning activities and report on additional metrics and indicators relative to business goals. For the development of security services, it's the tuning of the approach that provides the information you need to get started.

In the most simple of definitions, a security service is a well-formed package of related processes, technologies and capabilities that has a predictable outcome that is needed or in demand by the business. What makes security services differ from traditional security activities is input.

Just about everything requires input to feed a process to produce an output. For security, the input is usually "self-assigned," meaning the business must meet a specific policy or some other documented requirement to have security perform an action. For example, a policy may read, "Any material change to an Internet-facing application requires a penetration test." That's a sound approach, but it's reactive and misses the opportunity to gain valuable insights to underlying business needs and goals.

While looking for risk/reward scenarios, you will see a pattern emerge and the tuning efforts outlined above should help you identify opportunities to incorporate specific business attributes into what you're performing.

The basis for security services is taking advantage of this pattern. In fact, you're doing this today to some degree. For example, an application is due for a test, but you've learned that the changes relate to one of several roles defined in the system. As a result, you may limit testing to that one area because of your knowledge and comfort with the application from previous tests. Now, extrapolate this to all things in security. It's less about simply doing what you do and more about giving the business additional opportunity to feed the process in order to refine the activity -- or service in this case -- to the business need.

The next important characteristic of security services is how people, processes, tools, methods and technology are architected to perform the service relative to input and output. This is a lot easier to say than to do. Organizations tend to approach these elements as independent or loosely coupled. Moreover, some security architectures and frameworks facilitate segmentation, making alignment of them seem alien and uncomfortable.

One challenge is internally developed standards that are either overly comprehensive or too granular. Successful implementation of security services typically starts with reviewing the standards and looking at them as a common foundation to services as opposed to specific elements for a given security function.

As with all things of this nature, a slow and methodical approach wins the race. Don't try to create a services model over night. Take what you've learned in tuning, couple it with something you're already doing today (such as vulnerability testing, patch management, identity management, data protection, monitoring), and then pilot a services approach with a friendly business unit.

As this approach begins to solidify, several interesting things start to happen. The identity of security and perceived value continues to shift in a positive direction. Nevertheless, you will quickly realize that you have far more capabilities to measure operational details of your organization, and more importantly -- you inherently have more influence over them as a result.

This essentially slams the door on the gap. Services facilitate the risk/reward model, they make it possible to organize activities specific to demand, provide the means to measure those activities more effectively, and allow for the controlled management of each element to ensure that what is being reported can be influenced. This can be a perfect storm, but you're not done. To truly transform, you have to close the loop with governance.

Step 4: Governance Loop
The "governance loop" is the final step and provides the opportunity to realize real transformation. To this point, you've tuned, experimented, tested and created the early stages of services and are beginning to rely on the new path and less on the old one.

This has helped increase visibility, initial alignment to the business and promotes effectiveness. Nevertheless, at this point, time becomes your enemy -- without governance, the services will eventually break down. Governance, interestingly, provides the mechanism to ensure expectations are being met, but also the means to promote adaptability, closing the loop with the business.

Governance acts as the bonding agent between ebbs and flows in the business, compliance, risk and security activities. More importantly, this is where risk/reward is measured and fed back into the system to instigate change. It is also important to realize that risk (management, assessments, reporting) has played a pivotal role throughout the journey, and governance is the means to realize full potential. Risk remains at the top of the pyramid, but now with services underlying it, supported by governance, it can move far closer to the business.

In short, governance is analogous to "inspect what you expect" and influence change. That means creating a set of responsibilities and practices with the goal of providing direction as well as ensuring objectives are achieved and resources are used responsibly. In so doing, measurements from the oversight of security not only ensure efficient and effective execution, but also facilitate change in the program through intimate connections with risk management and the business offering feedback into the system.

In some companies governance is associated with enforcement. Although partly true, a security group empowered by services and close interlinks with overall enterprise governance through risk management activities will be able to put governance to work for them. This is similar to how, over the last several years, many security organizations have changed their perspective of the audit group.

Historically seen as a regular and painful exposure of operational weakness in security, audit processes are now being seen as a way to strengthen security. It's turning what is usually thought of as a negative into a positive force. The same is true with governance processes that are outside of the control of the security group or where security is part of a governance committee.

Nevertheless, an important aspect is to understand that the security group is ultimately responsible for its activities -- good and bad. Therefore, it is recommended that governance be reflected in the security services and program owned and operated by management resources within the group. This is not a replacement for enterprise governance -- rather, it's an extension focused on the betterment of security.

Organizations need security more now than ever, and as a result, are more receptive to security as a community. What you do with that attention today could have enormous influences on the future of security within your company. Although times are tough, don't assume this means opportunities don't exist. The economy will correct itself and businesses will emerge stronger and with a new sense of determination and demands for operational maturity. Taking advantage of what appears to be short-term focus on security for long-term gains is the crux of the opportunity, and opportunity favors the prepared.

This article is by James Tiller, author of The Ethical Hack and Technical Guide to IPSec VPNs, and contributing author on several other books, including the Official (ISC)2 Guide to the CBK, is vice president of security services for BT in North America. He consults with organizations globally on how security can enable business. You can reach him at james.tiller@bt.com.

Sunday, March 8, 2009

Calculating the odds of being paid off - First step

"Will I still have a job tomorrow? and in the tomorrows after that"

With the world economy claiming to be in a far-reaching recession and companies announcing layoffs seemingly every day, the question of continuing employment looms large in every thinking person's mind.

Clearly, some employees feel that they are at greater risk of losing their jobs than others. What's not so clear is how to calculate that risk. So how do you become your own Risk Manager and carry out a risk assessment on yourself. Consider how you can devise a good method that would help, not only yourself but also other IT professionals, get a relatively objective handle on the odds of getting laid off.

You may be wondering why anyone would want to determine the likelihood of their losing a job. You may also believe that a 'layoff' risk assessment method could be a very helpful tool. Depending on your circumstances, outlook and character, many people worry unnecessarily about getting laid off and others who do get laid off, are often taken completely by surprise.

A risk assessment for layoffs could help IT professionals determine whether they are in the red zone (high) or the green zone (low) risk category, when job losses come around. Low-risk professionals will then be able to rest easy and carry on with their work and the high-risk employees can be proactively defend and entrench their positions, whilst actively preparing themselves emotionally, professionally and financially, for the moment when their jobs get cut.

As a first step, let us propose a list of possible variables that could indicate someone is likely to get laid off. Let us also propose another list of variables that could indicate someone is unlikely to get laid off.

Our goal is to develop an accurate and plausible assessment, one that will really help people get a grip on their futures. Coming up with such an assessment, can be difficult, for a whole variety of reasons. One of these reasons would be an incomplete or inappropriate list of variables.

If you examine the lists below and identify which of the variables are appropriate to your circumstances and discard those that are not. You can also weigh a certain number of the retained variables more heavily than others, because of their importance or criticality.

Examine also how the assessment is structured. Structuring it as a questionnaire would allow people to assign points for each negative variable (e.g. each strike against them) and subtract points for each positive variable. The conclusion would be easily calculated and greatly simplified. People with high scores are more likely to be laid off than people will lower scores.

Remember that the goal of this assessment is to help and support people, not to frighten them.

Variables that Could Indicate Someone Is Likely to Get Laid Off

1. Your employer is not meeting its financial plan. (he's broke!)
2. Your salary is at the high-end of the pay scale for your profession or function. (so much for ambition!)
3. A position or function you help support has been eliminated or restructured. (the horse died!)
4. You work on a project that has been cut or that you sense is going to be cut. (Zepellin restoration)
5. You gossip or complain a lot. (no wonder. Look at the previous options on this list)
6. The work you do is mundane or repetitive in nature (e.g. re-setting passwords or setting up routers) and could be outsourced to a third party. (or monkey with learning difficulties)
7. Your work is not customer-focused. (but I work in Security)
8. The function you work in is well/over-staffed (full of "fat" cats that need a trim)
9. You don't "fit in" with the 'culture' of your department. (You are sober)
10. Your company could find someone to replace you at a lower cost with relative ease (e.g. going to the bus stop line, rather than hiring a head hunter)

Variables That Could Indicate Someone Is Unlikely to Get Laid Off

1. You've demonstrated your ability to adapt to new strategies. (Flexible as Yoga)
2. You have good relationships with different people throughout your company. (married to the boss?)
3. Your position is cross-matrixed to different leaders. (you are a bigomist)
4. You have a good rapport with your boss, and your boss is regarded highly by senior management. (you still own the negatives from the office party)
5. You work on multiple projects that are critical to dealing with existing business conditions. (your wife sleeps around)
6. Your skills are up to date, in demand and align with the IT organization's current and future needs. (you have killed all the competition in the office)
7. Your company would have difficulty finding someone to fill your shoes. (you are overweight)

Sunday, January 18, 2009

Project failure starts at the begining

We are all familiar with countries, towns and destinations that are difficult to reach, either by road, rail or public transport and yet people exist there and thrive. It is not in another dimension or another planet, where predictable 'difficulties' are numerous e.g. expensive ad hoc rocket ship service, an atmosphere of sulphuric acid, temperature variations in the region of 'scorchingly off-the-scale', etc. No, our difficulties in reaching our earthly destinations are because we do not start from the correct location.

This is a lesson I learned when lost in Dublin and forced to ask for directions. It was made clear to me that to get to point B I should have started at point A and not the point that I was currently at, which was currently unknown and would henceforth be referred to as X. Thus, making the logic more mathematically predictive.

The start point and the end point, part of the defining structure of a project and thus lifting it away from the realms of a simple action or activity, are critical in the initiation and definition of the project and the associated project plan. You will never reach the end destination if the start is left to serendipitous happenstances.

  • Plan the beginning of your project meticulously
  • Involve as many of the stakeholders as possible
  • Hold a workshop with all the allocated resources
  • Seek out Subject Matter Experts (SMEs)
  • Do your research, technical, business, historical, etc
  • Assess the Risks (qualitative and quantitative) and
  • Look where you are going

The dark matter of Projects failing

IT projects suffer from a similar force to that of the astronomically evasive 'dark matter'. A force that is not so much negative in its manifestation as it is in its effect, especially on other matter. It has an ability to occupy space without contributing anything, interacting with 'light matter' only to drain its energy and restrict its ability to move freely.

'Dark matter', and its ability to absorb and retain energy without contribution, is a universal anomaly for physicists. A puzzle yet to be solved. A question unanswered but not for project managers and team leaders. We know this effect and understand the consequences very well. It is a similar force to the one that will cause your project to fail. It is your greatest adversary. Its invisible. It can be detected but not controlled, without the right tools and level of experience.

Corporate Defense Domain

The Corporate Defense Domain is a convenient way of describing the sum total of numerous secure approaches, tools, processes, etc. that incorporates the entire environment security of an organisation, from end to end or perimeter to perimeter.

The concept of Corporate Defensive Domain is an aid to perception evolving from a vision of Physical Risk through IT Risk, Operational Risk to Governance, Compliance, Legal and Reputation Risks.

Corporate defense
Corporate security is purely defensive. There is no moral imperative that allows positive attacking action against threats and those that attempt to, or unequivocally, inflict damage on your organisation. Some but not all, of these attacks can be very determined and sophisticated because they are goverment funded and are either commercially or politically motivated. Most are just motivated individuals that can be classed as intellectual vandals.

As with all the good guys, you must work within the framework of the law and this only allows vigilance, defensive action, and possibly post-event retribution and compensation. The subsequent capture and imprisonment of a perpetrator may become a public spectacle. An apparent show of the success of your strategy and hopefully it will act as an example to others but in reality it is of limited effect and brings little solace to the organisation.

Showing your hand
There is also a view that public trials act as a learning curve for other attackers. The attacker creates an action on your perimeter and you display a measured reaction. Thus revealing some of your defensive strategy, processes and tools.

Security realms
There are many realms that exist in the land of security e.g. physical, electronic, virtual, etc. and there are many ways to look at and examine security. It can be viewed as a) a physical obstacle b) a process inflicted on reluctant personnel without explanation or c) an acceptable mindset that is instilled in the environment with the full involvement of the personnel. This latter approach should produce the best results, giving staff a sense of involvement, empathy and a real feeling for the potential consequences.

Secure personnel
It is critically important that your staff buy into securing the corporate domain because they are typically, the weakest link in the security of organisations.

Staff issues
  • They are not so easily or reliably programmed,
  • They don't always retain or apply knowledge appropriately,
  • They are swayed and diverted by social engineering techniques,
  • They have good and bad days,
  • Their attention is inconsistent, etc.
  • Their human!
Threats & Vulnerabilities
There are many ways to examine Threats and Vulnerabilities in an organisation e.g. by geographical location, business type, resources used, historical or political instability, etc. Do you know and understand what criteria and imperatives are being used to drive changes in your defenses? Are they appropriate, operationally maintainable or cost effective.

Analyse the Risk

Organisations are are driven to respond to threats and are compelled to adopt more and more complex defense strategies to address and defend their security needs. Security policies and strategies dictate that a full gambit of approaches should be adopted, from standard process implementation to strict and intricate application frameworks but this has an operational and business cost implication.

The questions that are not always being asked are;
  • What is the real cost of defending your business?
  • How much are you likely to lose?
  • Where will the danger come from and in what form?
  • How will it impact us?
  • What is our response capability?
  • What is the overall Risk profile?
Feal the fear and hold your ground
With the constant threat of intrusion and compromise, regular and detailed testing and re-examination of all your defenses are necessary but before you can realistically and effectively apply what you have learned, you need to conduct a detailed analysis and assessment of the Risks, the potential business impact and your response options .

7 Points to build stronger, more secure Corporate Defenses
  • Create executive level authority and responsibility for Corporate Defense, policy and implementation
  • Assess your strengths and weaknesses using mature Risk management methodology
  • Examine the interdependencies between your tools, processes and defensive positions. Strengthen the perimeters and communications
  • Map and review your Corporate Defense Domain strategy, continuously, in a structured and determined manner.
  • Determine, test and examine areas of Convergence, for overlap and gaps. Establish strong boundary defenses and stringent hand-over criteria
  • Develop a single hardened core entity, an authoritative cross functional discipline, incorporating Governance, Compliance and Risk
  • Lock the perimeter gatesways, give the spare keys to your organisation to the central hardened core and prepare yourself for the next attack