Showing posts with label information security management. Show all posts
Showing posts with label information security management. Show all posts

Tuesday, September 26, 2017

Why CISOs Fail: The Missing Link in Security Management--and How to Fix It

Why CISOs Fail: The Missing Link in Security Management--and How to Fix It provides insight as to why and how current security management practices fail at their basic foundation, resulting in overall dissatisfaction by practitioners and lack of success in the corporate environment. Barak Engel examines the reasons and how to fix them. The resulting improvement is highly beneficial to any corporation that chooses to pursue this strategy and from a bottom-line and business operations perspective, not just in technical operations. This book transforms the understanding of the role of the CISO, the selection process for a CISO, and the financial impact that security plays in any organization.

Monday, September 11, 2017

Information Security: The Dismal Discipline?

Read this chapter from Why CISOs Fail: The Missing Link in Security Management--and How to Fix It and understand why the author likes to call information security the "dismal discipline," and why this perception needs to change.

Wednesday, December 3, 2014

Top 3 Enterprise Software and Security Trends for 2015


It's the time for prognostications for 2015. Cirius is first out of the gate. Here's what it foresees as significant trends developing in enterprise software and security. 

1. Data jurisdiction and data sovereignty will impact the growth of Office 365 and Azure. 
Satisfy local, grow global: Enhanced national privacy legislation introduced in Australia, Singapore, Germany, Malaysia, as well as the EU Data Protection Directive, is the sign of what is to come. In many cases opinion trumps facts and products like Office 365 and Azure need to demonstrate aggressively that they understand the privacy and security  concerns of partners and resellers. Addressing domestic privacy and data jurisdiction concerns will help facilitate global growth

2."Cloud" will no longer be perceived as a security threat compared to on premise solutions.
The future of security is in the cloud: Cloud solution providers have had to deal with the perception the cloud was "unsecure" from day one. As a result cloud solution providers historically had to over deliver to be a viable alternative to on premise solutions. The reality is that security and compliance are not the core competency of most I.T. departments  and they lack the internal resources to meet compliance requirements and evolving security threats. 
3. Data Loss Prevention will become a hot issue for business leaders.
Who saw what when: Businesses need to know where their business critical information is at all times. Flagging content and communication before it leaves the office is a good start but it is not enough. Machine learning, pattern recognition, and "post-send" message controls are the next wave of DLP functionality that will protect employees, clients and increasingly the brand.

Wednesday, May 14, 2014

Is Infosec Getting More Stressful?


Is Infosec Getting More Stressful? 

Frankly, I think everything is getting more stressful, and not just at work.

But specifically regarding InfoSec, external threats and pressure are increasing, helped by wide media coverage of intrusions. And, internal pressure must be building, too. Just think about the Target CIO falling on his sword because of the data theft. Now there are real costs to personnel as well as the enterprise.

What do think?

Thursday, August 22, 2013

Just Published! Information Security Management Handbook, Sixth Edition, Volume 7


This is the first annual edition of the Information Security Management Handbook since 1994 without the guidance and the insight of Hal Tipton. Hal passed away in March 2012. He will be missed by a lot of people for a lot of reasons.

It seems that every year is an interesting one for information security, and 2012 was no different. It is interesting, too, how perceptive Kaspersky Labs, for example, was with its forecast. It also foreshadows the end of online trust and privacy. If you cannot trust digital certificates, what is left to trust?

Cyberwarfare has jumped to the front pages of every newspaper, both print and virtual. Stuxnet spawned Flame, Duqu, and Gauss. While we were all focused on attacks and espionage by China, France, and Israel, Iran mounted a DDoS (Distributed Denial of Service) attack against US banks in retaliation for sanctions that appear to be working. At the same time, Iran’s central bank was attacked. Added to the online attacks is the growing threat of supply chain security, and products shipped with back doors or embedded systems that let them phone home. Witness the difficulty Chinese telecom equipment suppliers like Huawei are having with gaining toeholds in the United States by purchasing the US suppliers.

While Russians and Eastern Europeans are not singled out for cyberwarfare, crime syndicates based there continue to threaten commerce and privacy.

Theft of passwords from LinkedIn and Dropbox, and what seems like daily reports of attacks on or by Facebook show (not to mention Zuckerberg's Facebook page being hacked) the lure of social media to hackers, and the dangers to the rest of us. And while Facebook and others do not install rootkits as Sony did, their data collection efforts, combined with the apparent insecurity of the site emphasizes the growing dangers of Big Data and the Cloud.

We saw a huge increase in hacktivism as Anonymous and LulzSec launched various attacks on both government and private sites around the world.

It was only a matter of time until Mac OS X became a profitable target. Once critical mass was reached, hackers could not resist investing the time to own it. As with Mac OS X, mobile devices are becoming even more alluring targets. We have seen the same types of attacks and malware used against PCs adapted to mobile, plus new threats like SMS (short message service) spoofing. Not surprisingly, Android, Google’s open platform, has suffered the most. Plus, the growing number of apps for all platforms introduces a level of threat that is hard to estimate, but definitely growing.

M2M and the Internet of Things are creating more opportunities for hackers. From NFC (near field communication) payments to utility sensors sending unencrypted data, this is a potentially lucrative area for fraud and identity theft. Sensor networks are now in the DIY (do-it-yourself) arena, which creates yet a new class of threats.

BYOD (Bring Your Own Device), IT consumerization, whatever you call it, is making life so much more fun for black hats. It has given new meaning to “insider threats.” With portable digital devices being introduced into the enterprise, both with and without permission, we are seeing a manifold increase in threats. Clearly, policies alone are not sufficient to deal with this, and it is unclear how draconian management wants to be with forcing compliance. The products exist, but does the will to use them?

Looking at 2013, the promise of more surveillance, both from governments and online data collectors, means less privacy, even for the most careful users. Short of totally disconnecting from the grid, if such a thing is possible now, it is apparent we do not and would not have privacy.

This edition of the Information Security Management Handbook addresses many of these trends and threats, plus new areas such as security SDLC (software development life cycle), as well as forensics, cloud security, and security management. Chris Hare takes an in-depth look at hacktivism, identifying the motivations and the players, and providing advice on how to protect against it. Becky Herold analyzes the security and privacy challenges of social media. Sandy Bacik looks at the security implication of BYOD, and the challenges of managing user expectations. The Smart Grid offers its own security and privacy challenges as Terry Komperda explains. Noureddine Boudriga explains attacks in mobile environments.

There is new guidance on PCI and HIPAA/HITECH compliance. In addition to forensics and e-discovery, a chapter looks at cell phone protocols and operating systems from the perspective of a forensic investigator.

I have heard it said, “You can’t patch stupid.” So many of these attacks are successful because of clueless or irresponsible users. In what I hope is not a vain effort, Ken Shaurette and Tom Schleppenbach look at human firewall testing, social engineering, and security awareness. We also look at security and resilience in the software development life cycle, managing the security testing process, and SOA (service-oriented architecture) security.

Here is a shout out to my friend Jim Tiller, head of Security Consulting, Americas for HP Enterprise Security Services, for his help in preparing this edition. Jim’s done a lot for the Handbook over the years, and I am hoping he will continue.

All-in-all, this is a good volume of the Information Security Management Handbook. We are working on the next edition now. If you would like to contribute, please contact me at rich.ohanley@taylorandfrancis.com.

You can order a copy here.

Tuesday, April 24, 2012

Tech groups push for cyberthreat information-sharing bill. Great idea. It's worked real well with Federal agencies.

So, now industry wants Congress to legislate what it won't do volunarily. So far, there's as much trust between companies as there is between government agencies. They're all willing for a one-way exchange. This isn't going to change in government, and it won't in industry. Which reminds me. Didn't Congress legislate sharing between agencies? That's working real well, isn't it.

Friday, April 20, 2012

"You can't patch stupid." House committees approve 2 cybersecurity bills

One of the best phrases I've heard lately is, "You can't patch stupid." This speaks to the ongoing threats to security posed by users. Now it appears that Congress again is trying to legislate what can't be fixed by legislation. I think "You can't patch stupid" is more easily applied to Congress.

Thursday, April 19, 2012

PWC Survey: "... majority of executives ... are confident in the effectiveness of their organization’s information security practices."

According to the results of the 2012 Global State of Information Security Survey®, the majority of executives across industries and markets worldwide are confident in the effectiveness of their organization’s information security practices.

Doesn't this fly in the face of fact? With reported breaches on the rise, and fears of fraud, APTs, and supply chain security, among other threats, increasing, why are these executives so confident?