Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, December 14, 2009

IRAN: Iran and Afghanistan, threaten Gulf security

The Afghan war and the Iran nuclear crisis are among the threats to security in the Gulf region, Kuwaiti foreign minister and deputy prime minister Sheikh Muhammed Sabah al-Salem al-Sabah said Friday.
Sheikh Muhammed was addressing delegations from more than 25 countries in the Gulf Cooperation Council at the opening of the sixth Manama Dialogue security conference in Bahrain.
Threats to GCC security ran from "Afghanistan and neighbouring Pakistan, go through Iran's confrontation with the international community, to the reality of Palestine and the suffering of the Palestinian people, down the Horn of Africa, to the crisis in Yemen," he said.
In additional and implicit swipe at Iran, he spoke of "when people call for rebellion against the regime, challenging the government and calling for the overthrow of the government in place."

Gulf officials "should recognise the risks of abusing ideologies in the relations between states," he added. Iran has been accused by the West and various Gulf states of interfering in the affairs of its neighbors and attempting to foment instability.
Sheikh Muhammed also discussed what he described as mid-term problems: the threat posed to Gulf countries by international economic downturns, and the risk of relying primarily on oil for revenue. And he added: "We must look closely at the demographic situation of our six GCC countries, and we will note that there are real demographic challenges in the mid- and long-term."
These challenges included the projected 30 percent rise in the population of the GCC countries by 2020; the large percentage of young people; and the large number of foreign workers in the Gulf.

The consequently large remittances being sent out of the Gulf and the growing number of children of foreign workers in GCC countries also posed a problem, he added. "This generation has no other home than the GCC countries -- they were born, have lived and worked here, and they represent a great challenge in terms of absorption into society from a cultural and a social viewpoint," he said.
The Manama Dialogue conference is sponsored by the International Institute for Strategic Studies. This year's conference, which lasts through Sunday, will focus on Afghanistan, Pakistan, Yemen and Iran.

Saturday, November 28, 2009

EU Security Agency Highlights Cloud Computing Risks

Cloud computing users face problems including loss of control over data, difficulties proving compliance, and additional legal risks as data moves from one legal jurisdiction to another, according to a assessement of cloud computing risks from the European Network and Information Security Agency (ENISA).
Comments By Mikael Ricknäs

Fri, November 20, 2009 — IDG News Service — Cloud computing users face problems including loss of control over data, difficulties proving compliance, and additional legal risks as data moves from one legal jurisdiction to another, according to a assessement of cloud computing risks from the European Network and Information Security Agency (ENISA).

The agency highlighted those problems as having the most serious consequences and being among the most likely for companies using cloud computing services, according to ENISA.

ENISA examined the assets that companies put at risk when they turn to cloud computing, including customer data and their own reputation; the vulnerabilities that exist in cloud computing systems; the risks to which those vulnerabilities expose businesses, and the probabilities that those risks will occur.

When moving to cloud-based computing services, companies have to hand over control to the cloud provider on a number of issues, which may affect security negatively. For example, the provider's terms of use may not allow port scans, vulnerability assessment and penetration testing. At the same time, service level agreements (SLAs) may not include those services. The result is a gap in defenses, ENISA said in the report.

Compliance could also prove to be a big problem if the provider can't offer the right levels of certification or the certification scheme hasn't been adapted for cloud services, the report said.

One of the advantages of cloud services is that data can be stored in multiple locations, which could save the day in the event of an incident in one of the data centers. However, it could also be a big risk if the data centers are located in countries with a shaky legal system, according to the report.

Other areas of concern are vendor lock-in, failure of mechanisms separating different companies, management interfaces that get accessed by hackers, data not deleted properly and malicious insiders.

To minimize these risks the report proposes a list of questions that a company needs to ask potential cloud providers. For example, what guarantees does the provider offer that customer resources are fully isolated, what security education program does it run for staff, what measures are taken to ensure third-party service levels are met, and so on.

In the end a good contract can lessen the risks, according to the report. Companies should especially pay attention to their rights and obligations related to data transfers, access to data by law enforcement and notifications of breaches in security, it said.

ENISA's report isn't all doom and gloom, though. Using cloud computing services can result in more robust, scalable and cost-effective defenses against certain kinds of attack, according to the report. For example, the ability to dynamically allocate resources could provide better protection against DDoS (distributed denial-of-service) attacks, ENISA said.

Thursday, October 22, 2009

Caution! Rise in Scareware Tactics - Rough Security software

Rogue security software, also dubbed scareware, is an "ongoing threat" that is impacting largely users from English-speaking markets, according to findings from a year-long study by Symantec.

Released Tuesday, Symantec's report on rogue security software noted that 250 rogue security programs launched some 43 million attempts to prompt user installation between July 2008 and June 2009.

Read also: Fake 'Conflicker.B Infection Alert' spam campaign drops scareware

Further analysis on the top 50 most reported scareware was carried out between July and August this year, during which Symantec found that 38 of the programs had been detected prior to Jul. 1, 2008.

"The continued prevalence of these programs emphasizes the ongoing threat they pose to potential victims, despite efforts to shut them down and raise public awareness," the security vendor said in the report.

The five most commonly reported rogue security applications during the study were SpywareGuard 2008, AntiVirus 2008, AntiVirus 2009, Spyware Secure and XP AntiVirus.

For more info read ZDNet Asia Security Blog.........

Fake Conficker.B Infection Alerts Impersonate Microsoft

An ongoing spam campaign is once again attempting to impersonate Microsoft’s security team — the same campaign was first seen in April — by mass mailing Conficker.B Infection Alerts (install.zip), which upon execution drop a sample of the Antivirus Pro 2010 scareware.

Whereas the theme remains the same, the botnet masters have slightly modified the message:

“Dear Microsoft Customer,

Starting 18/10/2009 the ‘Conficker’ worm began infecting Microsoft customers unusually rapidly. Microsoft has been advised by your Internet provider that your network is infected. To counteract further spread we advise removing the infection using an antispyware program. We are supplying all effected Windows Users with a free system scan in order to clean any files infected by the virus.

Please install attached file to start the scan. The process takes under a minute and will prevent your files from being compromised. We appreciate your prompt cooperation.

Regards,
Microsoft Windows Agent #2 (Hollis)
Microsoft Windows Computer Safety Division”
The use of email as propagation vector for scareware campaigns (The ultimate guide to scareware protection), and in particular the use of email attachments is an uncommon practice, compared to the single most effective way of hijacking traffic through blackhat search engine optimization where the cybercriminals rely on real-time news events.

The campaign is an example of a — thankfully - badly executed one in the sense that with Microsoft’s Security Essentials recently gained momentum, even the average Internet user would notice the suspicious timing of the offered “antispyware program”.

Wednesday, October 21, 2009

China: 43 Uighur men have 'disappeared'

Months after security forces seized them in the wake of ethnic riots in July, at least 43 ethnic Uighur men from far western China have disappeared, an advocacy group said in a report released on Wednesday.

The report, by Human Rights Watch, asserted that the number of vanished Uighurs was likely higher, although the group could conclusively document only 43 cases during weeks of secret investigations in the Xinjiang region of China.

At least 197 people died and another 1,600 were injured during three days of protests and rioting by thousands of Uighurs in early July in Urumqi, the capital of Xinjiang. The riots, the worst ethnic violence in recent Chinese history, led police and security forces to round up hundreds of Uighurs, mostly men, in subsequent weeks.

State-run newspapers have reported that more than 200 persons were charged with crimes in connection with the protests, and 19 Uighur men were sentenced this month — 11 to death, 3 to life in prison — for their roles in the violence. In a separate trial, one man with an ethnic Han surname received a death sentence and another was given a prison term of 10 years.

The government has insisted that those accused of violence have been treated in accordance with Chinese law, which requires authorities to give detained suspects access to lawyers and to tell suspects’ families where they have been detained and why.

The Human Rights Watch report disputes that, stating that in most cases, “the men and boys detained in the course of these sweeps and raids have been missing since the security forces took them away.”

“Their families’ attempts to inquire about the relatives at local police stations or with other law-enforcement agencies proved futile,” the report stated. “The authorities either said they had no knowledge of the arrests, or claimed the inquiry was still ongoing without admitting the fact of detention, or simply chased the families away.”

The report called the 43 cases “enforced disappearances,” saying they “are serious violations of international human-rights law” as well as Chinese law.

A request for Chinese government comment on the report, sent by fax at the government’s request, was not immediately answered.

The 48-page report involved random interviews with “many dozens” of Uighur residents of Urumqi and at least two dozen Urumqi residents who were Han, the ethnic group that makes up 90 percent of China’s population. Most of the violence in the July riots was directed at the Han who have become the more prosperous majority in what was once a Uighur-dominated city.

The report states that while almost every Uighur interviewee claimed to know a friend, relative or acquaintance who had gone missing after being detained by security forces, only a few were willing to give detailed accounts of the disappearances for fear of punishment by authorities.

The unaccounted-for detainees, all males, were as young as 14, but most were in their twenties, the report stated. Many were said to have disappeared during large-scale roundups of Uighur men conducted by security forces in Urumqi neighborhoods in the days after the riots. But others were seized in what the report called “targeted raids” in ethnic Uighur parts of the capital.

Witnesses were sometimes uncertain who had detained the suspects, but other people interviewed for the report mentioned the Chinese military, the local police and the People’s Armed Police, a national paramilitary force that often responds to natural disasters and public disturbances.

The report cited witnesses’ accounts of the detentions of 11 Uighur men, none of whom has been seen since. In one case, witnesses were quoted as saying that some 150 police officers and soldiers sealed off a street in Saimachang, a predominantly Uighur neighborhood, on July 6, the day after the protests began.

“Women and elderly were told to stand aside, and all men, 12 to 45 years old, were all lined up against the wall,” one witness was quoted as saying. “Police and the military were examining the men to see if they had any bruises or wounds. They also asked where they had been on July 5 and 6. They beat the men randomly, even the older ones — our 70 year-old neighbor was punched and kicked several times.”

The witnesses said that 17 men were taken away, including the 25-year-old husband of one of the witnesses. “She has not heard anything about her husband’s fate since then,” the report stated.

A woman in a second Uighur neighborhood, Erdaoqiao, said that three men in civilian clothes came to her home July 28. Identifying themselves as police officers, they took away her 18-year-old son for questioning, saying he would be freed in a couple of days.

“It’s been more than three weeks and I have no idea where he is and whether he is still alive,” she said. “I went to the local police station twice — they did not say whether he was there or not, but said the inquiry was still ongoing.”

Another witness said the soldiers seized her 14-year-old brother, apparently injuring his leg, after he left his Erdaoqiao home to go to his father’s shop on the morning of August 7. Family members said they tracked the boy to a local hospital, where he was treated, but he was then placed in a truck and driven away.

The boy has not been seen since, the report said. Police officers in the neighborhood told the family that he is not on their list of detained people.

Human Rights Watch said the Chinese government has not responded to an August 24 request to give an account of the deaths, arrests and detentions stemming from the Urumqi riots. The group urged Navanethem Pillay, the United Nations high commissioner for human rights, to investigate the events in Xinjiang.

The group has posted its report on its Web site, which the Chinese government blocks its citizens from accessing.

Friday, October 16, 2009

Recession hit Cyber-crime just doesn't pay like it used to.

Recession hits Cybercrime! With botnets everywhere, DDoS attacks get cheaper $30 will buy a one-day DDoS attack now!

Security researchers say the cost of criminal services such as distributed denial of service, or DDoS, attacks has dropped in recent months. The reason? Market economics. "The barriers to entry in that marketplace are so low you have people basically flooding the market," said Jose Nazario, a security researcher with Arbor Networks. "The way you differentiate yourself is on price."

Criminals have gotten better at hacking into unsuspecting computers and linking them together into so-called botnet networks, which can then be centrally controlled. Botnets are used to send spam, steal passwords, and sometimes to launch DDoS attacks, which flood victims' servers with unwanted information. Often these networks are rented out as a kind of criminal software-as-a-service to third parties, who are typically recruited in online discussion boards.

DDoS attacks have been used to censor critics, take down rivals, wipe out online competitors and even extort money from legitimate businesses. Earlier this year a highly publicised DDoS attack targeted U.S. and South Korean servers, knocking a number of Web sites offline.

Are botnet operators having to cut costs like other businesses in these troubled economic times? Security researchers don't know if that's been a factor, but they do say that the supply of infected machines has been growing. In 2008, Symantec's Internet sensors counted an average of 75,158 active bot-infected computers per day, a 31 percent jump from the previous year.

DDoS attacks may have cost hundreds or even thousands of dollars per day a few years ago, but in recent months researchers have seen them going for bargain-basement prices.

Nazario has seen DDoS attacks offered in the US$100-per-day range, but according to SecureWorks Security Researcher Kevin Stevens, prices have dropped to $30 to $50 on some Russian forums.

And DDoS attacks aren't the only thing getting cheaper. Stevens says the cost of stolen credit card numbers and other kinds of identity information has dropped too. "Prices are dropping on almost everything," he said.

While $100 per day might cover a garden-variety 100MB/second to 400MB/second attack, it might also procure something much weaker, depending on the seller. "There's a lot of crap out there where you don't really know what you're getting," said Zulfikar Ramzan, a technical director with Symantec Security Response. "Even though we are seeing some lower prices, it doesn't mean that you're going to get the same quality of goods."

In general, prices for access to botnet computers have dropped dramatically since 2007, he said. But with the influx of generic and often untrustworthy services, players at the high end can now charge more, Ramzan said.

Thursday, September 24, 2009

It Takes the 'Right Stuff' to be a Good Leader. Do you have it?

You see here the Fantasy character Buzz Lightyear, recently returned from a tour of duty in the ISS. Carried there and back by one of the NASA astronauts, in the Shuttle Discovery. Science Fiction Fantasy meets Science Reality. The one a parody of the other.

We all know that there are many paths to follow that lead from Fantasy to Reality. The story of science fiction evolving into science fact can only happen when dedicated visionaries lead the way.

What do we look for in our leaders and how often do we find the 'right stuff'.


In depth knowledge, self confident and self-awareness has always been necessary to build good leaders but it was never enough. You also had to have the 'right stuff'. You need the ability and character to inspire, support and motivate before you can ultimately lead.

It may not be fashionable and it may not be 'the new, new thing' but the adage that the Leadership Model follows a hierarchy similar to that of Maslow's hierarchy of needs, is still relevant and very pertinent today.

Maslow's Hierarchy of Needs starts at the lowest level, with meeting basic neeeds before moving on to addressing issues with Safety and Security. Once that has been achieved, you can take into consideration the higher goal of finding and sharing Love, Affection and the sense of Belonging. The next step is to achieve Status and Esteem before finally climbing up to and sitting on the top of the world, brim full of Self Awareness, sometimes known as Actualisation.

Organisations still need Self-Aware leaders but there are no shortcuts. We need leaders who are able to progress through all the stages and completely fulfill the lower level needs. It's not acceptable to be a self confessed leader if you do not fully understand and accept the 3 dimensional nature of leadership and the voyage to the top that took you there.

Let's look back at the precipitous journey you are on or possibly, you have already completed.

1) Basic Wants/ Physiological Needs
At the base root of all organisation some core wants have to be addressed. They include the tools needed to survive and thrive. This is the core technical skills, in the leadership model. Clearly, if you want to be a Finance Manager, you need to know how to perform accounting tasks and understand the associated practices. Many skills are needed to sel but the main one will be the ability to be erudite.

All one needs to demonstrate, to future employers is that you have the core skills to do the job. Most leaders get promoted to successive levels of leadership through technical mastery but by being technically competent alone does not give them the skills or ability to be exceptional and charismatic leaders.

2) Safety & Security
Leaders need to provide their organisational units with structure and a competent framework to operate in. They need to develop the hierarchy, roles and responsibilities and, most importantly they need to provide the organisational employees with the criteria and opportunity to be successful.

To clamber up to the second level of leadership, a good leader must provide his team with the precise operational model that will make them not only feel secure but also instil a philosophy of positive attitude and how to approach success.

Poor leaders rely heavily on their ego to direct them. They believe that they can be the all powerful king in the midst of disarray and chaos. They think they are controlling and directing the masses but in reality they are burning valuable resources, whilst lurching from crisis to crisis.

A good leader creates the framework where every employee not only feels secure operating in and focusing on his job but also has a repeatable chance of being creative and successful. They have the chance to stretch themselves and not fear the consequences of loss or failure because their leader is there to guide and support them, throughout. They do their job well and the organisation benefits.

3) Love, Affection and Belonging
This builds on from the creation of a safe and secure environment and leads us into the need and ability to foster cohesive teamwork. The basic requirements here is that the leader needs to ensure that his team players are working well together but he also has to ensure that his team plays well within the whole organisation and can work well with 'others'.

You are not provided with the chance to model a team from a single piece of clay. you have to build this team from the wide assortment of characters and personalities that this world provides. Even after the skilled HR department has carefully filtered,selected and processed the candidates.

You have a team of disparate (or desperate) people from different backgrounds, brought together for a common purpose and it is your challenge to make them interact in a positive, productive and interactive way by building good, strong relationships.

Poor or weak leadership can easily create divisions, within and without your locality. It is so easy to create a self-protective silo mentality that spends too much energy and time defending itself from outside 'influences' and gets caught up in 'power' struggles. What you don't want is to be a stressed out head of a dysfunctional family unit that is feuding with it's neighbours. You need to actively create a common sense of purpose that transcends boundaries and divisions.

4) Esteem
As we mature in our organisational interactions with others, professional respect and appropriate response, may be all that really matters. For a leader to be considered a good leader, this respect has to be born of an independent outlook and a strong vision. Discard fear and intrepidation, actively and sincerely appreciate what every person is bringing to the table.

A good leader will not give respect lightly. You will need to prove your worth through your commitment and your actions. Talk alone does not do it. A good leader looks at the role you play in the organisation and will treat you with the respect the role commands, unless or until, you prove unworthy of it.

5) Self-Awareness
Do you consider yourself to be a 'good well balanced, human being'. Self Awareness is 'presence', 'authority', 'charisma', 'qudos', etc. The ability a leader possess, by the sheer power of his positive presence. One in which he is able to hold a clear vision, taking a higher road that puts the interests of his organisation to the fore.

The self-aware leader never takes credit for the actions of their team, there is no 'gray area of interpretation' on morals or ethics. A self-aware leader is in the spotlight 24x7, laid bare before the organisation, always on call for their people.

A good leader is inspiring and consistent in their judgement. They are fair, balanced and trustworthy. People are driven and motivated by a good leader. They respect them but are not diminished or intimidated by them.

If you know a good organisations that is looking for good leaders. Tell them to clearly and honestly, examine their true requirements and goals. The 3 dimensional levels of needs that they want to meet and satisfy.

Remember that truly successful organisations must be led by thoroughly 'good human beings', people of good character. These are the only people who will lead us from deception and fantasy into the harsh reality of the future, and they will deal with it appropriately, when we get there.

Saturday, August 29, 2009

Beware Trojan Horse Laptops bearing Gifts: Security Risk

The FBI has launched an investigation to find out who is sending unsolicited laptops to state governors across the country.

The Service is reporting that governors and state officials in at least 10 US states have received mysterious computers in the mail.

The mystery began in West Virginia earlier this month when Gov. Joe Manchin’s office received five Compaq computers on Aug. 5. A week later, Manchin’s office received a sixth notebook, a Hewlett-Packard model.

The Charleston Gazette, which first reported the story, said Manchin’s office didn’t turn on the machines for security reasons. Very wise! West Virginia state police said HP confirmed the notebooks were ordered online for delivery to the governor’s office, but didn’t reveal who made the purchase.

Wyoming and Vermont have also reported similar incidents, which has led to the FBI investigation.

The incidents are raising concerns that hackers are taking advantage of low-cost laptops to circumvent digital security and anti-virus controls to infiltrate high-value targets. It’s an intriguing and ingeniously simple idea, provided that they actually take possession of a machine in the supply chain.

The entire idea of having an inside, physical component to a hack is nothing new. Security history is replete with stories of hackers using social engineering techniques to enter buildings to gain access to unsecured workstations, plant bugs and monitoring devices and steal information necessary for remote access.

If you have seen the movies “Hackers,” “Sneakers,” “Mission: Impossible,” “Eraser” and others, with similar plot lines, then you know how this works. While it's possible for people to don janitor and Fedex uniforms to gain access to offices, the most common, cost-effective and likely way of making such an attack is 'Dumpster diving'. Simply, sifting through other people's trash to find discarded clues that may lead to establishing remote access.

Putting malware on a free machine that just shows up in the office, is different and arguably ingenious. Notebook, desktop and hardware costs have shrunk to the point where everyday hackers can afford the investment of buying a dozen for planting in high-value targets and the pay-off would be well worth th eeffort.

Saturday, August 22, 2009

Symantec and Norton Produce list of 100 Dirtiest Websites

Symantec and Norton have produced a definitive listing of 100 of the dirtiest websites i.e. the websites to avoid.

These websites are most likely to damage your PC or laptop system and /or to install viruses, Malware and Mal-bots, intended to cause major disruptions to all web users.

Click here to see the Report.....

Sunday, August 9, 2009

US Marines Ban Facebook and Twitter: Use of Social Network Sites

The U.S. Marine Corps made it official this week: Social networking sites such as Facebook and Twitter are banned from military networks.

This new administrative directive doesn't change very much but clarifies the use of social networks from a security perspective.

Marines have never been allowed to access non-official sites like Facebook, MySpace or Twitter from military networks because it is classed as improper use of government property.

In this new or revised directive, the Marines have simply put an official stamp on the ban. At the same time, they are also laying out the process to be followed by any Marine who wants to officially access such a site, as part of his or her job.


A Haven and Conduit for Adversaries
"These Internet sites in general are a proven haven for malicious actors and content and are particularly high risk due to information exposure, user generated content and targeting by adversaries," the directive noted.

Increased Threat
"The very nature of social networking sites, creates a larger threat, attack and exploitation window, exposes unnecessary information to adversaries and provides an easy conduit for information leakage."

Improper use of US equipment
The ban, however, is only for people using Marines' equipment and networks while they are working. Marines may still Twitter or post to Facebook on their own time and on their own computers but they should do so with a raised level of awareness.

The military isn't against using sites like Facebook and Twitter, said 1st Lt. Craig Thomas, a Pentagon-based spokesman for the Marine Corps.

Facebook, YouTube and Twitter
The U.S. Central Command has a Facebook page, a channel on YouTube and a Twitter account to get out information regarding operations news. The Army is using MySpace to recruit new soldiers and the U.S. Forces Afghanistan page on Facebook has more than 24,000 fans.
A Balanced Approach
"The Marine Corps has got to find a balance between security and letting Marines capitalise on the technology," Thomas said in a recent interview. "We don't want information leaks. We want to keep Marines focused on their mission at work and we also wanted to save critical bandwidth. We're trying to find the fine line."
Measured Progress
Thomas noted that 30 years ago, soldiers were warned about revealing too much information in letters home. Then 10 years ago, they were warned about how they used e-mail. Today, the focus is on social networks.

Tight Lips
"You can't have someone posting, 'Hey, we're leaving on this date and at this time,'" he added. "Believe me, the enemy is checking out what you guys are reporting and what service men and women are saying online.

The Marine Corps instills tight operational security. They need to be cognizant of what they're saying, whether verbally or what they're saying on social networking sites."

Wednesday, August 5, 2009

Rejoice! Latvian ISP linked to online criminal activity booted out of Internet

IDG News Service — A Latvian ISP linked to online criminal activity has been cut off from the Internet, following complaints from Internet security researchers.

Real Host, based in Riga, Latvia was thought to control command-and-control servers for infected botnet PCs, and had been linked to phishing sites, Web sites that launched attack code at visitors and were also home to malicious "rogue" antivirus products, according to a researcher using the pseudonym Jart Armin, who works on the Hostexploit.com Web site.

"This is maybe one of the top European centers of crap," he said in an e-mail interview.

"It was a cesspool of criminal activity," said Paul Ferguson a researcher with Trend Micro.

The ISP was disconnected from the Internet by its upstream provider, Junik, on Monday, after its provider, TeliaSonera told it to stop servicing Real Host or face sanctions Armin said.

Real Host was considered a "bullet proof" hosting provider, that would allow customers to remain online even after they had been linked to malicious activity. It had been linked to the Zeus botnet-making software.

This isn't the first time this type of hosting provider has been knocked offline. In the past year, at least three U.S. ISPs: Atrivo, McColo and 3FN have been unplugged after security researchers built cases against them. Atrivo and McColo were also taken offline by their upstream providers. 3FN was shut down by the U.S. Federal Trade Commission.

But according to Armin, this may be the "first time an international group has achieved this across borders and in Eastern Europe."

In the past, these takedowns have had a serious affect on spam. And while some observers reported a noticeable drop in spam over the weekend, security experts say that this was probably not attributable to the Real Host takedown.

Observers expect to see the criminal activity linked to Real Host resume soon, but they say that the takedown puts some pressure on the bad guys and the networks that provide service to them. "The precedent that's being set right now is that you need to take some responsibility for your network," said Lawrence Baldwin, owner of security research firm Mynetwatchman.

"There actually are some consequences now for allowing an obviously heavy concentration of criminal activity on your networks. It's just not going to be accepted anymore."

Thursday, July 30, 2009

Social Engineering - The biggest Threat to Security is still You and your People

Social Engineering - Are you Tempted?
Whether they are going through the eTrash, dumpster diving, pod slurping, or impersonating other people, our constant companions, the hackers know that social engineering is still the best way to by-pass security.

People Skills
Social engineering finds and hits directly at our weak spot, you're a nice gal /guy, a people person and people are still the weakest link in security. Yes, it is difficult to change this because it means changing people's attitude and behaviour. Plus you have just spent 10's of thousands of Dollars, Pounds and Euros, to give them better customer facing skills.

Why? It Works!
Why are hackers still using social engineering to gain access to organisations? Because it still works better than anything else and it provides quicker results. It's easier to infiltrate an organisation via the people because the security is focused elsewhere, on the building and on Technology. Plus your guard is down, your complacent because you 'think' you are secure.

Who? People!
Front-of-House contact people are the most succeptible to intrusions. Partly because they form the first barrier but also because they are often bored, busy, isolated. Almost certainly, the least aware, uninformed or not adequately trained, concerning social engineering techniques and their risk to security. After all, who doesn't like to help a nicely dressed, sexy gal /guy and be rewarded by a smile, a compliment or just some friendly attention? What 'bait' would work on you?

What are the most likely vulnerabilities versus bad behaviours:

1. People want to be, and are trained to be helpful and co-operative. Sometimes this help can go too far and they give away too much information. - Make it clear to them what they can and cannot reveal, in writing.

2. People want to avoid confrontation and are trained towards compromise. It's difficult for some people to ask others to prove who they are. They don't like or want confrontation, especially with a possible 'authority' figure. Support your staff's doubts and back them up, review and clarify their decisions.

3. People like convenience and easy options. No one wants to take the complex additional security check route because they are busy or distracted, even if it may protect or benefit the organisation. Make the secure route the easy option for your staff.

4. People are messy, unorganised and easily distracted. They leave paper around, leave screens open to view, copy multiple people on e-mails, gossip and leak data. Provide them with pleasant incentives to change their behaviour and give them other, more positive things to talk about.

5. People are curious, inquisitive creatures. A great example is an employee who finds a USB drive in the parking lot. The first thing they do when they get to their desk is plug it in to see what's on it. You have to tell them why this is a threat to security and also a violation of someone else's privacy.

Is there light?
Social engineering attacks are some of the most difficult to defend against, but not all is darkness. Your greatest weapon is training and education. Maintaining awareness of current threat profiles and passing those on as a simple and easy to implement 'cheat sheet' or guidelines. Address all of peoples' senses, sight, sound and listenning. Use the technology Podcasts, MP3s, YouTube Videos, Twit and Facebook them. Whatever it takes.

Technical Barriers
There are very few technical solutions to people problems but here are some technical controls that are sensible to put in place:

* Lock down or limit capability of all peripheral devices, especially USB ports. There are now many commercial products that allow security administrators to completely lock down USB ports. This might be difficult but not impossible, because many devices are connected via USB ports.
* Use Data Loss Prevention techniques and products. Know who has access to your data, when they access it, and what they are accessing. Not very effective if someone's profile has been duplicated, stolen or access has been incorrectly allowed.
* Use encryption on every device and wherever systems talk to systems.

Remember 'If your employees don't know what social engineering is and how it operates, why should they change their behaviour?" You are the Agent of Change! Make it so!

Friday, July 17, 2009

Surf the Internet Freely and Safely: Care of Symantec

Everything you wanted to know about safety and security on the Internet but were afraid to ask!
Symantec have created a really friendly easy to use web page that provides basic information and advice on Internet and Credit card security, etc.

Wednesday, April 22, 2009

Risk Management - 5 steps to success

What does it take to get Stakeholder attention and for IT initiatives to be acknowledged and accepted in today's lean mean enterprise?

In most cases it means making a compellingly attractive business case, getting the pertinent information to the right decision makers and being sure that its written in a language they can understand.

Executive suite
IT risk management initiatives are most definitely aimed at executive attention and for good reasons. The economy has become increasingly dependent on the Internet and IT systems (the Cloud). this makes the inherent risks in these systems far more visible and potentially more significant than ever.

Risk management is a discipline with a myriad mix of interests groups and stakeholders: CIOs, CFOs, enterprise risk management teams, compliance and regulation staff, and both internal and external auditors.

Choose your words wisely
You need to aim your plan at CIO level and there are generally two types of CIOs; the executive infrastructure managers and the strategic business thinkers. The latter will succeed with their IT risk management agenda because they speak in terms of business advantages, not technology outages (Business Impact Analysis). Par example;

  • Instead of talking about a "zero day threat," consider the impact of a potential incident, in terms of potential business losses. (Quantify in general terms)
  • Instead of talking about RTOs and RPOs, speak in terms of lost revenue and customers during an outage. (Sales, turnover, throughput, etc)
  • Instead of highlighting unimplemented ISO controls, speak about the lost communication and effectiveness of employees who need to collaborate and share information both inside and outside the firewall.
  • It also doesn't hurt to point out the impact on productivity when the critical path and workflow is disrupted.

Use a High-Medium-Low spectrum of potential business loss

Part of using the right language is to help you move away from absolutes. Inevitably, a single prediction of loss will start a battle of statistics and probability debate, with the risk that your request will get lost or bound up in the process. Instead, provide stakeholders with a variety of realistic scenarios and have some good data to back it up.

Start by considering whether you are a low risk company, moderately tolerant, or highly tolerant and then you can go to work with some calculations. Be prepared to back up your recommendations with numbers. Understand that you probably won't get exactly what you are asking for, but by presenting accurate potential scenarios, you might get your mid-range goal.

Use headlines to your benefit

All of today's business leaders have been shocked by the recent headlines regarding corporate scandals and the sudden loss of freedom or career prospects that this may bring. They dread the thought of the "orange jumpsuit retirement program." and there is still a steady stream of privacy and data leakage issues that will continue to feed into the headlines.

Those held responsible, willingly or otherwise, have ranged from; unsuspecting backup administrators and employees who unwittingly left laptops in car trunks; to mid-level managers involved in publishing quarterly financial reports and executives operating with full and certain knowledge of potential breaches.

You can make good use of these "publicly displayed sacrificial offerings" to illustrate and re-enforce the real risks at stake. This will help you move away from the discussion regarding the siza, shape and probability of an incident or event and break the statistical deadlock.

Move your message up and around the chain

Identify and consider the strong players and potential champions involved. Work hard to win them over to yor way of thinking. Rememeber, IT risk management isn't an exclusively IT-driven discipline. Work with the compliance team, the IT group, the legal group, the auditors, the enterprise risk management group, and the business leaders. Create cross-company initiatives to align each of these groups. This will require as much time communicating outside of IT as inside.

Identify your milestones

Before going into an executive meeting with your precious ember of a request, identify up to three milestones you expect to meet and explain in business terms how these milestones will provide real benefits and payback to both the business and IT.

If you can, start with a proof of concept e.g. for a content filtering project. This will have much more value if users from audit, legal and a line of business are involved in choosing terms to flag, track and quarantine events. A security 'incident reporting' process may get more enthusiastic response, if users understand that increasing their awareness will help to save the company money and protect the corporate image.

Conclusion:
IT risk management will become increasingly important as key organisational stakeholders begin to see the importance and effectiveness of an ongoing program. For now, IT risk professionals and their associated colleagues can continue to work to establish a baseline program by using the right language and the right information to ensure continued support internally.

Friday, April 17, 2009

Four Tele-commuting Security Mistakes


  1. Careless use of Wi-Fi and accessing unsecured open networks
  2. Letting family and friends use work-issued devices and attaching unauthorised peripherals
  3. Altering or deleting security settings to view Web sites that have been blocked by the company
  4. Leaving a work-issued device in an unsecured place or public location
Security is a good mind-set to adopt

For more information and assistance, speak to your IT Helpdesk and Security personnel . They have a range of proven and tested (approved) tools, which are closely aligned with simple operating procedures and guidelines to help you reduce the potential impact of threats and vulnerabilities. The effective use and implementation of these, is up to you.

Remember to check with the security guys regularly. There is always something new going on in their world that will directly affect your business world.

If in doubt give the Security doctor a shout!

As with most things, it is always easier to find security issues and threats before they escalate into a crisis. A mild infection can be treated quickly and effectively if brought to their attention early but, if left untreated, there is always the risk of cross-infection to other members of staff, with the potential loss of a limb or vital organ.

In your business world, it is your server, applications and your data that keeps you alive! You don't want to lose any of these or even break the arterial chain that holds them together.

3 Security Flaws in Google Docs?

Security Analysts find 3 Flaws in Google Docs!

1) One of the flaws allows images to be accessible even if a document has been deleted
2) The second problem allows users to see all versions of an image that's been modified
3) A third problem is perhaps the most serious of all; It appears to allow people who once had access to someone's Google Docs to still get access even if access rights have been changed. Details of this one have not been released yet.

Click on the dragon for more details

Sunday, April 12, 2009

Risk Management; A mind set

To those who have not yet discovered it, security and risk management is a mind-set. When you go into a shop or restaurant, you may automatically check out the security and note where the exits are. If so, you will also check as to how secure the financial transactions are. How does the waitress handle the credit cards? How far the credit card machine is to staff and other customers. You will have noted the location of the security cameras, the lack of a security station or the location and the number of bouncers.

As a security and risk specialist, you will always be thinking about and assessing the security scenarios but not to exploit or take advantage of it but to be aware. You cannot switch it off, its the way you are. It is the same for members of the emergency services, never really off duty.

Security Compliance

If you have to consider a risk management approach to security compliance, as part of your many regulatory obligations, the best way to approach compliance is through risk. It is ineffective to focus on the bare minimum, just ensuring you are simply compliant. Threats and vulnerabilities are forever mutating, growing and changing. The bare minimum is not enough. This is the first principle of IT security and of risk-based IT management.

When looking at new applications, components, systems or architectures, check out the risks to your business and the risk to your core information. Those are the important things to note. You are concerned if it meets a line item associated with HIPAA and SOX.

Pattern recognition

The 'always on' risk management mind-set is always looking for patterns, checking out ways of doing rather than items on a regulatory checklist. You will look closely for items that pose a threat to your core assets, those that you are responsible for and have dedicated your reputation to protecting.

When somebody comes to you with a potential security problem, even if you know nothing about the particular system or application, you can assess it by the application of the risk framework and therefore formulate a validate set of pertinent and probing questions.

Secure games

Most security and risk managers live and breathe in a security mind-set, whether they are hardcore techies or recruits from the business side. The methodology they follow day by day at work is the methodology they live by, outside of work. Even at conferences, when they unwind afterwards with a soft drink, they invariably play a Where’s Waldo? version of security gaffes, competing to see who can spot the most security lapses. It can appear very weird and a little black, if you are outside the circle.

Nailed by the business

The mind-set can have its limitations and can be self-perpetuating. There is an old adage that says 'If you are a hammer, the whole world looks like a nail.' Indeed, when taken by surprise, the average security and risk manager is typically out manouvered by something that happens on the business side.

Good grief! Have they learned nothing? You can’t believe that the business would make such a decision. Just because you have a structured, risk averse and secure mind-set, you forget that 'normal' people don’t always think that way.

Damage control

What happens next is up to you. If the security has been jeopordised or the risks are too high then it is your task to get it back into line and put the geni back in the bottle. The fact is clear, you are dealing with consequences. The business has taken a chosen path and you have to control the damage, mitigate against it or make it right. After all, isn't that your job as security and risk 'support' person? In reality, you are seen by the business (suits) as being in the same category as the IT help desk and that is all you are.

Although it is accepted that the security and risk manager serves and protects the
organisation and its profits, until it can be unequivacally determined how you can directly make money and grow the profits for the organisation, you will always be considered as merely a supporting act. So, let's make up and get on with it! The show must go on!

Thursday, April 9, 2009

Microsoft Security Intelligence Report - Extracts

Here’s a look at the five most important aspects from the full Microsoft Security Intelligence Report.

1. Vulnerabilities (the response and reaction to them) vary, depending on whether the target is at work or home.

Based on data provided by its enterprise Forefront Client Security and consumer Windows Live OneCare, Microsoft found that vulnerabilities are very different. Why? A corporate user may have email and Internet limitations that reduce the attack surface. A home user has more software tools to be infected but less critical data at risk.

Simply put, a home user is more likely to get hit with a Trojan attack to extract bank and credit card details, etc. In the enterprise, the weapon of choice is the Worm attack, which is primarily destructive and disruptive.

The greatest difference between enterprise and home vulnerabilities is social engineering. Microsoft explains:

  • The Windows Live OneCare list also includes several families associated with rogue security software, such as Win32/Renos, Win32/FakeXPA, and Win32/Antivirus2008.
  • The social engineering messages used in connection with rogue security software may be less effective in an enterprise environment, where malware protection is typically the responsibility of the IT department…
  • By contrast, the Forefront Client Security list is dominated by worms, like Win32/Autorun, Win32/Hamweq, and Win32/Taterf.
  • Worms rely less on social engineering to spread than categories like trojans and downloaders do, does and more on access to unsecured file shares and removable storage volumes, both of which are often plentiful in enterprise environments.

2. Users don’t always remove unwanted software: There’s great appeal to the procrastinator in the “ignore” button.

  • Microsoft explains one nuance of the malware issue:Software cannot always be classified in binary terms as “good” or “bad.”
  • Some software inhabits a gray area wherein the combination of behaviors and value propositions presented by the software is neither universally desired nor universally reviled.
  • This gray area includes a number of programs that do things like display advertisements to the user that may appear outside the context of the Web browser or other application and which may be difficult or impossible to control.

Microsoft’s scans allow users to ignore a security alert, allow software to remain, issue a prompt, quarantine or remove it.

If software is really malicious it is removed without user input. The gray areas appear when users have a choice.

Microsoft adds:
  • These decisions are influenced by a number of factors, such as the user’s level of expertise, how certain they feel about their judgment regarding the software in question, the context in which the software was obtained, societal considerations, and the benefit (if any) being delivered by the software or by other software that is bundled with it.
  • Users make choices about what to do about a piece of potentially unwanted software for different reasons, so it’s important not to draw unwarranted conclusions about their intent.

Moderate or Low threats are often ignored by users, who think that there’s value in the software. These threats are keepers based on user behaviour:

3. Rogue security software (Scareware) gains momentum.

The concept of rogue security software is pure genius. Malicious hackers prey on the fears of users, cook up bogus security software and extract payments to keep your PC running. Microsoft notes that rogue security software is becoming a hot category.

Microsoft reports:

  • Rogue security software authors have long attempted to exploit this trust by giving their programs generic, anodyne names, like “Antivirus 2009,” and making them resemble genuine security software in many ways.
  • Recently, many threats have taken this approach a step further, posing as components of the operating system itself or as a familiar search engine.
  • One of the first families observed to exhibit this behavior was Win32/FakeSecSen, which was added to the MSRT in November 2008 and was the eighth most prevalent family in 2H08 overall.
  • Win32/FakeSecSen adds an icon to the Control Panel named Vista AV or MS AV and fraudulently uses the same four-colour shield icon as the Windows Security Center. Double-clicking the icon launches the rogue software, which claims to detect a large number of nonexistent threats and urges the user to “activate” the software by paying for it.

Win32/Renos is a longtime threat that delivers rogue security software. It was the most prevalent threat in the second half of 2008. Two new trojans–Win32/FakeXPA and Win32/FakeSecSen were the seventh and eight most prevalent family class.

4. Social networking phishing attacks represented less than 1 percent of attacks, but yielded a big chunk of phishing impressions.

Translation: Social networking sites will remain a big phishing target.

Microsoft explains:
  • A typical social network phish is likely to trick an order of magnitude more users than a typical financial phish. There are a number of explanations for this discrepancy.
  • While financial institutions targeted by phishers can number in the hundreds, just a handful of popular sites account for the bulk of the social network usage on the Internet, so phishers can effectively target many more people per site.
  • In addition, phishers often use the messaging features of the sites themselves to distribute their attacks, typically by gaining control of a user’s account and using it to send phishing messages to the victim’s friends.
  • These attacks can be much more effective than e-mail–based attacks, because they exploit the considerable level of trust users place in their friends.

Take a look at:

And.

5. Malware is dominant in the U.S. and accounted for 67 percent of all infected computers.

Trojans—the miscellaneous variety–were detected on 29.4 percent of infected computers. Among other items:

  • Five of the top 20 families detected in the United States in Q3 and Q4 of 2008 (Win32/Renos, Win32/FakeXPA, Win32/FakeSecSen, Win32/Antivirus2008, and Win32/Winfixer) download rogue security software or display misleading warning messages to convince users to purchase a program that supposedly removes spyware.

Here are the top five individual threats:

Trojan downloaders and droppers were detected on 24.4 percent of all infected computers.

I trust this was of interest to you and you will see the sense of protecting your computer(s) with known and trusted anti Virus software as well as setting up a good Firewall and Intrusion detection. The rise and rise of Malware across the globe means that you will also need to protect your system(s) from this menace.

Do your research, read the reviews and never be the first to try any new protection software.

Tuesday, April 7, 2009

Re-thinking IT Security in tough times

The current economic downturn is forcing a corporate change and metamorphosis that, when combined with ever broadening security threats, presents information security groups with an opportunity to radically change their identity and add more value to the business.

To capitalise on the moment, security groups need to reassess their approach, add visibility and transform the very role of security.

It is good timing because maintaining security during tough economic times is critical. Besides external threats that evolve even more rapidly in economic downturns, business slumps increase the probability of disgruntled employees striking out using intimate knowledge of corporate systems.

Risk is further exacerbated by the fact that, since the last economic crisis of this magnitude, companies have become far more reliant on information technology systems, which are now highly complex and essential to sound operations.

Your current security path represents existing programs, capabilities, processes, etc. The goal is to create a parallel path that influences existing practices and allows you to refine a new strategy without disrupting current expectations. In time, the new path will become a dominating force and take you in a new direction.

Step 1: Tuning the Approach
During the last decade security has been virtually defined by compliance. For many companies, it has been less about security than it has been about ensuring that certain regulatory demands are being met. Unfortunately, compliance does not necessarily enable the business, align with core initiatives, and alone may not thwart debilitating attacks.

Understanding this, some security groups have strived to use compliance efforts to improve their security posture.

Unfortunately, not all companies see the value of such activities and instead simply see compliance as a cost of doing business.

You have to convert the security practices that fall under the banner of "mandated for compliance" into specific activities that resonate with the business. For example, a predominant force in business is time to market and the rapid conversion of investments to revenue generation. This can materialize as a new service, application, communication platform, network or alliance. The key to tuning your approach is to optimize security features to help the business move more quickly, reduce barriers or accommodate a requirement quickly.

Key to being able to accomplish this is institutional knowledge within the security group and leveraging and combining resources in ways that benefit the business as much as it does security, for example: supporting secure coding practices through collaboration with the development team, optimizing standard builds to stand up servers more quickly, security testing as part of performance testing, or utilization of directory services to support streamlining of access controls for a new partner.

Fundamentally, it is about operating in a risk/reward model. Prioritize activities based on risk as well as where the greatest opportunities are for the business. By becoming intimate with business goals and mapping against elements of risk, what begins to surface is a common thread that demonstrates a point where the business and security goals become more closely aligned.

A good place to start is within the project management arena, where risks to the initiative or life cycle will become apparent, in addition to helping identify critical paths and what is most important or critical to the business unit. By using information of this nature, combined with institutional knowledge that the security group possess, you can begin to interpret demands and risks in business initiatives and quickly find areas of common ground.

Step 2: Adding Visibility
Security groups typically make security efforts visible to executive management by presenting security metrics, risk dashboards, and the like. However, along the way, many encounter some key challenges.

The first challenge is that the measurements are only focused on security and typically do not provide insights to other aspects of security operations that demonstrate effectiveness. For example, a dashboard may present compliance risk, operational risk, technical risk and current threats. It is assumed that keeping the values in an optimal or desired range means that security is doing its job.

However, company executives are increasingly focused on efficiency, effectiveness and overall alignment to business initiatives. They want to know how well these objectives are being met, what influence they have had on other key business performance indicators (such as time to market, customer retention), and how resources and other valuable assets are being utilized.

Executives are concerned about inefficient or wasteful activities and want to ensure all activities focus on the bottom line. Presenting to the board a risk dashboard can be helpful to demonstrate your alignment to security concerns, but that's only one part of the equation in the eyes of executives. The more effectively security can reduce the need to translate security results into something meaningful for the business, the better.

The second challenge relates to the "gap" factor. The gap refers to the difference in what security is providing to executives as visibility and the ability for the security group to influence the system to enact change.

For example, a report may demonstrate that the number of vulnerabilities in Internet-facing applications is increasing significantly quarter over quarter. However, the security group may not have the capacity or capability to reduce that number to a reasonable value. As a result, some senior security managers find themselves tasked to correct an issue they simply do not have the ability to accomplish.

In short, information from the security program is misaligned with its ability. Some use this to justify investments that would address the gap. But unfortunately this pattern is growing increasingly ineffective as business owners demand more accountability. The solution is to create a security program that not only presents good and bad trends, but more importantly, has the ability to have a meaningful impact in changing them.

The challenges can be summarized as providing visibility into more than security in security terms, but also in a manner that is more readily digested by executives and easier to align to business goals. Secondly, build a security program that not only produces meaningful information relative to security and business metrics, but also has the inherent capability to institute change and thereby meet expectations.

Providing additional visibility to existing risk-based perspectives can be enormously valuable. To accomplish this, you need to become more intimate with what resonates with the executives -- the measurements they focus on day in and day out, the performance indicators they study beyond the financial ones. Each company is different and each business unit may have a different spin. Moreover, many may seem like the furthest thing from security, such as shipping metrics, warehousing, capacity indicators, system use or even collaboration indicators. You have to look behind these to begin to see where security can begin to mimic the same philosophies.

From a security perspective, look to report on areas within your domain of influence and help reflect how well you're running as a business. It can be as simple as resource utilization, project involvement or performance quality scores from your peers.

From there you can start tying to other reported information and trends, such as the planned decline in effort to perform regular vulnerability testing, but an incline in report quality and effectiveness, essentially demonstrating that you are meeting security and business objectives. Or show how, through collaboration activities (which have been measured) and modifications to technologies, you've helped reduce the number of security related helpdesk tickets. These are, of course very basic. Nevertheless, the point is to find related information between what you are doing for security and how well you are doing related to business expectations.

This approach helps form your new path for security, drawing from your original strategies and enhancing them. Start small, test the waters and seek mentorship within the organization. As more confidence grows in providing additional perspectives on activities, you can move into closing the gap.

Step 3: Service orientation
By this point you've learned how to orchestrate your core competencies to help the business reach its goals using a risk/reward method. And you've started experimenting with adding visibility to the executives on alignment. As a result, the identity of security is beginning to shift. It may not be obvious, but it's happening. However, this is a critical stage and the time to innovate. Once executives see something they like, they want more, expectations increase, and that "good job" turns into "what have you done for me lately?"

One of the common pitfalls is not following through to ensure a foundation exists to keep up with new expectations. As a result, massive ground is lost and you're back to square one.

Adopting a service orientation can help you continue to move forward. Service orientation has three primary objectives:

1) Convert tactical best practices that were once hidden within compliance efforts into business services that can be consistently utilized.

2) Close the gap between what you can control/influence and what you're reporting on.

3) Create a foundation for building a highly agile security approach.

The key is to learn from experimental practices in tuning activities and report on additional metrics and indicators relative to business goals. For the development of security services, it's the tuning of the approach that provides the information you need to get started.

In the most simple of definitions, a security service is a well-formed package of related processes, technologies and capabilities that has a predictable outcome that is needed or in demand by the business. What makes security services differ from traditional security activities is input.

Just about everything requires input to feed a process to produce an output. For security, the input is usually "self-assigned," meaning the business must meet a specific policy or some other documented requirement to have security perform an action. For example, a policy may read, "Any material change to an Internet-facing application requires a penetration test." That's a sound approach, but it's reactive and misses the opportunity to gain valuable insights to underlying business needs and goals.

While looking for risk/reward scenarios, you will see a pattern emerge and the tuning efforts outlined above should help you identify opportunities to incorporate specific business attributes into what you're performing.

The basis for security services is taking advantage of this pattern. In fact, you're doing this today to some degree. For example, an application is due for a test, but you've learned that the changes relate to one of several roles defined in the system. As a result, you may limit testing to that one area because of your knowledge and comfort with the application from previous tests. Now, extrapolate this to all things in security. It's less about simply doing what you do and more about giving the business additional opportunity to feed the process in order to refine the activity -- or service in this case -- to the business need.

The next important characteristic of security services is how people, processes, tools, methods and technology are architected to perform the service relative to input and output. This is a lot easier to say than to do. Organizations tend to approach these elements as independent or loosely coupled. Moreover, some security architectures and frameworks facilitate segmentation, making alignment of them seem alien and uncomfortable.

One challenge is internally developed standards that are either overly comprehensive or too granular. Successful implementation of security services typically starts with reviewing the standards and looking at them as a common foundation to services as opposed to specific elements for a given security function.

As with all things of this nature, a slow and methodical approach wins the race. Don't try to create a services model over night. Take what you've learned in tuning, couple it with something you're already doing today (such as vulnerability testing, patch management, identity management, data protection, monitoring), and then pilot a services approach with a friendly business unit.

As this approach begins to solidify, several interesting things start to happen. The identity of security and perceived value continues to shift in a positive direction. Nevertheless, you will quickly realize that you have far more capabilities to measure operational details of your organization, and more importantly -- you inherently have more influence over them as a result.

This essentially slams the door on the gap. Services facilitate the risk/reward model, they make it possible to organize activities specific to demand, provide the means to measure those activities more effectively, and allow for the controlled management of each element to ensure that what is being reported can be influenced. This can be a perfect storm, but you're not done. To truly transform, you have to close the loop with governance.

Step 4: Governance Loop
The "governance loop" is the final step and provides the opportunity to realize real transformation. To this point, you've tuned, experimented, tested and created the early stages of services and are beginning to rely on the new path and less on the old one.

This has helped increase visibility, initial alignment to the business and promotes effectiveness. Nevertheless, at this point, time becomes your enemy -- without governance, the services will eventually break down. Governance, interestingly, provides the mechanism to ensure expectations are being met, but also the means to promote adaptability, closing the loop with the business.

Governance acts as the bonding agent between ebbs and flows in the business, compliance, risk and security activities. More importantly, this is where risk/reward is measured and fed back into the system to instigate change. It is also important to realize that risk (management, assessments, reporting) has played a pivotal role throughout the journey, and governance is the means to realize full potential. Risk remains at the top of the pyramid, but now with services underlying it, supported by governance, it can move far closer to the business.

In short, governance is analogous to "inspect what you expect" and influence change. That means creating a set of responsibilities and practices with the goal of providing direction as well as ensuring objectives are achieved and resources are used responsibly. In so doing, measurements from the oversight of security not only ensure efficient and effective execution, but also facilitate change in the program through intimate connections with risk management and the business offering feedback into the system.

In some companies governance is associated with enforcement. Although partly true, a security group empowered by services and close interlinks with overall enterprise governance through risk management activities will be able to put governance to work for them. This is similar to how, over the last several years, many security organizations have changed their perspective of the audit group.

Historically seen as a regular and painful exposure of operational weakness in security, audit processes are now being seen as a way to strengthen security. It's turning what is usually thought of as a negative into a positive force. The same is true with governance processes that are outside of the control of the security group or where security is part of a governance committee.

Nevertheless, an important aspect is to understand that the security group is ultimately responsible for its activities -- good and bad. Therefore, it is recommended that governance be reflected in the security services and program owned and operated by management resources within the group. This is not a replacement for enterprise governance -- rather, it's an extension focused on the betterment of security.

Organizations need security more now than ever, and as a result, are more receptive to security as a community. What you do with that attention today could have enormous influences on the future of security within your company. Although times are tough, don't assume this means opportunities don't exist. The economy will correct itself and businesses will emerge stronger and with a new sense of determination and demands for operational maturity. Taking advantage of what appears to be short-term focus on security for long-term gains is the crux of the opportunity, and opportunity favors the prepared.

This article is by James Tiller, author of The Ethical Hack and Technical Guide to IPSec VPNs, and contributing author on several other books, including the Official (ISC)2 Guide to the CBK, is vice president of security services for BT in North America. He consults with organizations globally on how security can enable business. You can reach him at james.tiller@bt.com.

Thursday, March 5, 2009

Lock-up your dockers

A laptop is stolen every 53 seconds, and 97 percent are never recovered!

Worse, one out of every 10 laptops will be stolen within the first 12 months of purchase!

Will you be next?

All of your family photos, tax return files, bank statements, etc. at risk. Not to mention all those usernames and passwords that you auto-saved somewhere. You say something must be done.

If you manage a business or work in a corporate environment, the cost will be even steeper than just replacing hardware: think of the public relations nightmare from the theft and legal requirement to alert employees and clients about the information breach.

According to some expert sources, the cost to a company can total €197 per missing record when factoring in the loss of customers, legal fees and the PR crisis management quelling efforts.

Clearly, a few thousand records can quickly add up.

“The loss of a laptop computer may well be quite expensive if it contains unencrypted confidential data,” according to the 2008 CSI Computer Crime and Security Survey. In 2008, 42 percent of all corporate security incidents were because of a stolen laptop, second only to viruses and insider abuse.