Showing posts with label Controls. Show all posts
Showing posts with label Controls. Show all posts

Wednesday, September 3, 2014

Guarding the Castle

Our network is our castle - we can never become complacent when trusted to protect our corporate assets, customer data or sensitive information.  All too often, we find ourselves asleep at the wheel, relying on all the security controls and processes we have implemented.  We must have a strong monitoring and auditing function built into our Information Security program.  Heathens are in the woods, watching our every move, waiting for the chance to storm the castle, slipping through a crack or blowing down the main gate, to invade, loot and pillage.

You have passed out administrative credentials to many employees.  How do you know those employees are not deviating from the expected and approved tasks?  This deviation could be malicious, or it could simply be a mistake.  Either way we face many risks when we allow employees to operate as an administrator on any system - we must have some oversight in place to detect and report on anomalous activity.  

How do you know your webserver is not under attack, right this very instant?  Webservers are notorious for being a primary target of attack while also being one area we find with the weakest security controls.  What if someone dropped some malicious code on your Linux webserver?  How would you know?

I suggest that, along with requirements definition around that latest firewall or antivirus platform, the coolest new email security product or the best-rated web filter, we include security monitoring, some form of configuration change detection, and the ability to capture, consolidate and filter logs from all our devices.  Many ways exist to do this properly, instead of just plugging in that shiny new firewall and then going back to sleep, we must remain diligent and on-guard - part of that is proper monitoring and mechanisms in place to quickly detect potential attacks.

If we utilize a Security Information and Event Monitoring solution, we can employ resources to review these logs, respond to alerts, and have some chance of catching an attack in progress, before it becomes a major emergency.  Those teams should be trained to know exactly what is suspicious and what is just noise.  The secops teams should be good enough to quickly scan the logs and anything out of place will catch their eye.  

In addition to active monitoring and review of logs, we must capture our configurations, whether that's a web server or a router, and then detect when that configuration has changed.  I've been in companies where they haven't made any updates or checked the configuration for years.  There are mechanisms or scripts you can write that will take a hash of the configuration of the router or the web server /var/www once a day.  The script does a compare of the hash from one day to the next.  If the hash value changes, something has changed in your config, or something has been modified in your web server.  

Once we've detected a change, we can inquire as to whether there was an approved change within the last 24 hours.  If there was, then the alert is simply a confirmation.  If there was no approved change, we must find out if an unapproved change was made, or if we've been compromised.  If the admin just forgot to send in a change control and added a line to the .conf file, then we just remind him of the policy and move on.  If no one knows of any internal change, we must suspect that we've been compromised in some way.  We must now go into Incident Response mode and try to find out what was changed and what that means.  From there, if we were compromised, we can quickly find it and kick them out of our server or our router.

Maintaining a secure network isn't rocket science but it does require expertise and diligence.  We must ensure we have the right tools, the right processes, and the right expertise to utilize those tools to the greatest effect.  The Information Security professional needs to understand how a router works, what a config looks like, what goes in the /var/www folder, how a Perl script works.  We must be able to quickly review logs and know what is normal and what is not.  It takes a while to get up to speed on all this, however your employer trusts that, in giving you the keys to the kingdom, that you have all the ports and moats covered properly.

Monday, December 17, 2012

All Aboard

Years ago, I worked for a large Fortune 500 healthcare company.  Obviously this company was concerned about it's requirements under HIPAA - at the time cell phones were being used but they were not the same as today.  Some had cameras, but many phones were simple flip phones without cameras.  Because a camera is a way in which you can gather, capture and move data, the company was rightly concerned about the new "camera-phones" and instituted a policy restricting their use and/or possession on company grounds.

Can you imagine what the compliance rate would be on that policy today?  I'm not certain you can purchase a new phone today without a camera.  We may have to revert to the vintage electronics section of eBay to find such a dinosaur of technology.  In today's healthcare environment, you have every single employee, from the doctor to the janitor, carrying not only one smart device, complete with camera, WIFI and the capability to instantly post the latest thought or photograph to Facebook, but it's likely some of these people have an iPad, some other tablet or small form factor laptop in their shirt pocket.  

We can no longer dictate that no one have these devices.  We have no effective administrative control that we can use to limit or restrict the presence of these devices - policies prohibiting something which has become woven into the very fabric of our culture would only be ignored.  It's like prohibiting them from bringing in their shoes or wallet.  The key point here -  a large risk has become assimilated into the culture, so much so that we've crossed the point of prohibition.  We only stand in front of this fast-moving train at our peril.  If we are to be effective, we must learn how to jump on board this thing as it's moving and at least find some room in the driver's car to figure out a way of putting some controls in place.

As with anything else, our usual template of Information Security will suffice - we need a well-conceived set of administrative and technical controls - our policy, while still acknowledging that every living creature on the planet is organically attached to a smart device, must dictate that the user will follow the policy at risk of termination and permanent smart-phone-ectomy.  This policy sets the table firmly for other controls - but why is this piece so important?

I have a tool that I am permanently attached to, that I take home with me, I use in the car, in the bathroom, it's my alarm clock, the way I check the news and the weather, the way I talk to my 14-year old, the thing that tells me when my favorite cigar goes on sale and lets me take notes or dictate.  This list really can go on forever - just look through the app store and you'll find just about anything to meet your needs and help you make your day more efficient.

Because of the fact that this device is our constant companion, we tend to be more lax with it - we don't treat it like a work device.  So we must force users to understand the importance of turning on their brains with respect to using the device.  We must educate users on the risk of using the device and their responsibility to use it wisely.  And we must put in some common sense controls which, while not prohibiting the usage of these devices, controls exactly what we want to control.

Today's solution to this problem is mobile security- some tool or agent which is installed on the device and phones home - the console can force a passcode (which means forcing encryption of the device), it can alert on devices which are out of compliance, let me know when the devices moves from place to place.  It's a happy compromise - I can't prohibit it but I can restrict certain things and wipe the device if it's lost or stolen.  I can force the thing to encrypt the data.  And I can "sort-of" disable the device's camera.

As a security guy in charge of infosec for a hospital, that's really what I care most about.  We cannot stop the train of mobile devices - we have to learn to get on-board and help steer away from our most critical asset - patient data.