Wednesday, March 13, 2019

We are all Samurai


We never used to call it "Cybersecurity" - we all called it "Information Security" - this was when the Internet didn't exist - we were tasked with protecting the Information or Data derived from business operations.  It didn't become "cybersecurity" until that data was connected to the Internet.

At some point, businesses understood that they couldn't share this data over this new medium called the "Internet" without ensuring others couldn't see or access this data.  So Information Security turned into Cybersecurity.

Today all articles reporting on hacks of sensitive data call it a "cybersecurity" hack - therefore we must all embrace the pop culture of "cybersecurity" as our calling.  That is so that we can relate to those decision-maker's understanding and terminology.

For us - nothing has changed.  We continue to implement the required security controls.  Those today include - enhanced endpoint protection (with threat intelligence) - network-based intrusion and intelligence - and perimeter-based default controls along with intelligence-based controls.

A Samurai would understand what the Shogun wanted to accomplish, and then translate that down to his team of battle-ready Samurai.  Our current security operations team has the same goals - what does your application need to do?  Once that is ascertained, we know how to secure it

Cybersecurity warriors act from a place of honor - of integrity.  We are here to protect the Shogonate, or the organization.  We understand the threats and our defenses - we recommend and manage those improvements to ensure the security of the Shoganate or organization.

Understand where the security pro is coming from.  Trust them to carry out that mission.  There is no greater of a protector thank one who has based Integrity as their prime directive.

Friday, April 7, 2017

Don Rickles (and my childhood)

I am saddened to hear of the passing of Don Rickles.  Don was a frequent comedian in my younger years, appearing many times on the Johnny Carson show as well as roasts of others.  I used to cry if my parents wouldn't allow me to stay up to watch Johnny Carson.

Anyways....  Don Rickles was a dominant force in those years.  He was ruthless in his honest comedy.  I particulary enjoyed his portraying of deference (comedic but also truthful) to Frank Sinatra.  I'd attended a local concert where Mr. Sinatra sang.  He actually seemed to be intrigued at this young boy so entranced by this songs he gave me a little cheek squeeze.

Mr. Rickles used truth to skewer his targets - but he was successful because his targets knew he loved them.  It was the truth surrounded by love and admiration of his targets that made Don Rickles so funny and successful.  He made us all understand that even the most successful, rich, and powerful had their faults.  

I laugh every time I recall one of his real (but actually planned) skits.  He taught us all a valuable lesson - don't take yourself so seriously.  Someone as brilliant as Mr. Rickles can come along and skewer you.  We all have our faults - focus on your strengths but learn from your faults.  There will always be someone close to you that sees through your facade and can point out your deficiencies.  

Just remember that this is always done with love - Mr. Rickles proved that.

Rest in peace Don.

Saturday, December 12, 2015

What is Phishing?


We have probably heard of Phishing.  Phishing is a very big risk in today's world.  It is imperative that we understand what it is, and how to NOT fall for it.  

Phishing is basically when someone tries to get you to think that they are legitimate, and then tries to get you to do something detrimental to your own or your company's security.  An example of phishing is when you get an email that says it's from FedEx - it says there is a problem with your account and you must log in immediately to fix it.  There is a link in the email - when you click that link it may look like you're going to the FedEx site, but you're not.  You're going to a fake site, and then you put in your username and password.  You're giving your username and password to the hacker.

Another example is when you get a phone call - they say they are from technical support and are calling to help you fix your computer problem.  We've all had computer problems, so this call might be welcome.  The caller often has an Indian accent.  They want you to perform some actions.  When you connect to their website, you are compromised.  Or they convince you to type in your username and password, and then they have your login information.  

I recently connected a landline through my cable provider.  Within 2 days, I received a phishing phone call.  The caller was a female Indian (think Chennai, not teepees...)  she advised that I was having computer issues and said she was calling to help.  Of course I told her I appreciated the call and would cooperate.  She wanted me to open the Run line - she told me to type in iexplore followed by a website address (the address was 121usahelp - dot - com) - IF I had done so, the instant my browser hit their web server I would have been compromised by some sort of malware or rootkit.  OR, once I connected, I would have had to approve their remote access into my computer, and then I would have been compromised.

So instead of actually typing this in, I started asking about the company - WHO was I allowing to connect by typing this in.  She immediately suspected that I was on to her, and she began cussing me!  She called me a "bloody F#$KER" and told me to "F$@K OFF" and then hung up.  Once I stopped laughing, I told my wife that the call was a fake tech support scam, and my wife, the wife of a computer security guy, said "how did you know?"  So I knew right then that I had to publish something to raise the level of awareness.

These people are looking for non-savvy people - people who may really need the help, people who may in fact be having a lot of computer problems.  The first thing to do is:

1. Think - did I request assistance?  
2. Can I verify that this caller is in fact from a company I trust?
3. Will my company ever call me and ask for my password?

When in doubt, don't give them any information, and DON'T connect to them with your computer.  There are several ways they can get you to connect:

1. Browser - if they ask you to open your browser and connect to a website - DON'T!  The instant you hit enter, you may be compromised.
2. Open/Run - if they ask you to go to the Windows button and then type in iexplore followed by a website, DON'T do it.  This is the same thing as opening up your browser and typing in a URL.  It calls the Internet Explorer program with their website address.
3. Giving them your username and password - this is the most obvious phishing attack.  Your employer, Microsoft or any other vendor will NOT ask you to divulge your username and password.  Anyone who does is likely trying to steal your credentials.  No legitimate technical support or service provider needs this.  

Remember, you are likely using the same username and password for multiple accounts, including your bank, credit cards, etc.  Although this is a bad habit, if you at least don't divulge your username and password in these scenarios, you're ok.  If you DO divulge it, you are divulging the login to multiple accounts.

The only reason Phishing is such a lucrative criminal business is that the victims do not suspect that they are being phished.  If everyone would ask the 3 questions above and be very suspicious of any caller or email asking for information, Phishing would be almost impossible to do.  

For those companies wondering how to address the risk of Phishing, there are a few things you can do:

1. Ensure your security awareness program covers the risks of phishing, how to spot it and how to prevent it.
2.  Use a tool which checks any links in email and quarantines potential phishing attempts.
3.  Use a phishing program - there are vendors out there who can perform phishing attempts on your users - if they actually click the links in an email they are re-directed to a security awareness training link and you can gather metrics on what percentage of users actually fell for the phishing.

Technical controls combined with user security awareness training can greatly limit the effectiveness of phishing.  There will always be ways to compromise our computer systems.  Phishing can be prevented through awareness - if you just realize there are people out there looking to take advantage of your lack of awareness, and always be suspicious of any caller or email asking you to do something like divulge your username and password, we can put the Phishers out of business.


Sunday, September 13, 2015

Personal Threat Preparedness

If you're reading this blog, it's likely that you're involved or interested in security.  Security comes in many forms - Information Security, physical security, personal protection, etc.  This article will deal with what we need to do to be safe as we move through our daily lives.  With all the recent violence, it is important that we both understand the risks and have a threat preparedness mindset.

I know our special agents and law enforcement personnel are given some training on assessing threats, but where does that leave the average citizen?  I've searched "the Google" extensively but guidance for the private citizen on assessing and dealing with threats is very limited.  As a former law enforcement officer, hopefully I can share some important tips as we go through our daily lives.

If I go to the grocery store, I expect to go through each aisle, finding the items I need to complete my grocery list.  But how many of us keep an eye out for potential threats?  Do you really believe no active shooters, homicides or assaults happen at the grocery store, mall, theater or other public gathering?

If you are a law enforcement officer, a federal agent or a military operator, you're trained in threat assessment.  But what does that mean?  This article will deal with assessing and dealing with threats for the average citizen.

We are most likely not deployed to a foreign country - kicking down doors and looking for terrorists.  However, we do frequently enter rooms, situations where the unknown and surprise situation may happen.  If we are walking through life unaware of possible dangers, we will certainly miss the advance clues and most probably will be just another statistic.  If we are aware of both the possibilities of danger and the best ways to prepare, we may be able to spot things out of place.  We can develop a habit of identifying possible escape routes, improvised weapons, as well as spotting potential dangers.

So let's say I'm at the grocery store or gas station at 10 PM.  I can, 99.999999% of the time, just get my groceries or gas, oblivious to danger.  But that .00000001% of the time, danger will strike.  That danger will manifest in a robbery in progress, a deranged, suicidal maniac, even a drive-by shooting.  What habits should I develop to ensure that I am as prepared as I can be, without being paranoid?

The best plan is to avoid danger altogether.  The first thing I do is to look through the windows.  Is anything out of place?  Are people acting normally, or are they afraid, stressed, focused on one area?  Think about a scenario with a robbery in progress.  Everyone inside would be afraid and focused on one point - the robber.  Make sure you look first before entering, and if you spot the likelihood of a robbery in progress, don't go in.  DON'T be a hero...  call 911.. Give a description, location and direction of travel.  Those are the most critical things law enforcement needs.  Move away from the danger and ensure law enforcement has the most correct and up-to-date information.

Assuming no obvious threat exists, you enter the establishment.  Just because no obvious clue of threat was present doesn't mean a threat isn't there.  As you enter the establishment, do three things:
  1. Identify the location and description of all persons
  2. Identify all escape routes
  3. Identify all potential improvised weapons
When you enter the location, look around.  Note any persons present - note their demeanor.  Are they behaving normally or do they appear to be stressed?  Note the persons gender, approximate age, race, height, weight, hair color...  These things are difficult or impossible to change.  Additional factors to notice will be the clothes they are wearing - the color - any distinguishing marks like hairstyle, tattoos, scars...  Also if they leave the scene in a car, note the car's color, approximate age, make, model and license plate number and State, if you can.

If you walk in a room, take note of any persons present.  Certainly a person with a gun would stand out, but someone overly stressed should catch your attention.  Is the person wearing a heavy coat in the summer?  Do they appear to be under the influence of some substance?  Do they seem to be acting weird?  Mentally gauge each person's state - mental/physical.  Most times, you will assess the threat of each individual and determine that they are not a threat.  It's a quick mental exercise but worth the effort.

Occasionally you will encounter someone who appears out of place - who seems suspicious to you.  Note that person and if there are no further threats, proceed with your business while keeping an eye on that person, as well as #2 and #3 above.  Listen to your instinct - if you have a bad feeling, don't ignore it.  Head for the door and get the bread, milk and eggs tomorrow.  Get to a safe place and call the Police if needed.  Better to be safe and mistake the situation, than to be a victim.

As you enter any room, make sure you are aware of all possible escape routes.  Do they have fire escapes?  Are there exit signs posted?  If danger in any form manifests, can you get yourself and others out?  Or will you simply panic and freeze?

If that suspicious person pulls a gun or starts causing an issue, what will you do?  The purpose of the exercise is to think through all likely scenarios.  The truth is that, in a crisis, you will do whatever you've trained to do - even if that's just thinking through possibilities and at least having a game plan (however unlikely it is that you'll use it.)  If you haven't trained yourself in this way, you will again do exactly what you've trained to do - nothing.  You will panic and freeze.

If a danger arises, you will have already already identified escape routes and improvised weapons - move to exit the scene and call 911 with description and direction of travel, identifying marks, etc.  If you find yourself unable to leave or are directly engaged with the danger, you must act quickly and with certainty.

We have heard of several active shooter incidents over the last few years.  The police have targeted training for civilians, especially teachers - the core of this training is "run, hide, fight."  If you realize you're in such a situation, the best thing to do is run.  If you're responsible for your family or students, gather them together and run.  If you find that you cannot run without increasing the danger, or find yourself in a locked room or otherwise unable to get away from the danger, hide.  Hide everyone behind a locked door.  Get on the phone with 911 immediately.  And if the danger comes to you and you are unable to escape, you must fight.

If you cannot run and must hide, you must be prepared to fight should the shooter find you.  If that active shooter comes in the room, obviously intent to mow down everyone, you have little choice.  Get in a position where you can surprise the shooter - when he comes through the door, ambush him.  If you don't act, you're likely going to be shot anyway.  Grab the gun and point it away from everyone, then shove your fingers in the attacker's eye sockets as hard as you can.  Have a letter opener or scissors - shove that into the attacker with every ounce of strength and bravery you have.  You must mentally prepare yourself and decide that you'd be willing to do this, faced with such a situation.  It isn't a nice thing to think about but if you don't mentally prepare yourself, you will just be a victim.

If we have this mindset and diligence, we will be prepared should an attack occur.  Unless we're deployed to a wartime situation, the likelihood of occurrence is low.  However, the impact of this occurrence is so high that we must prepare ourselves both mentally and physically.

Be safe out there - keep your eyes open.  The most important thing we can do is to always be situationally-aware - be aware of our surroundings and don't walk into a dangerous situation.  Quickly identify and assess each person - note all possible escape routes.  If you find yourself in the midst of danger, run.  If you cannot run, hide.  And if you cannot run or hide, be prepared to identify anything that can help you fight and win.

Our agents of national security are trained to assess and deal with potential threats.  We can utilize this basic set of principles to ensure that we are prepared to spot a threat and, if needed, to properly deal with the threat.  A proper mindset and preparedness may avoid our being just another statistic.  If you have questions or comments, please let me know.

Friday, March 27, 2015

The Umbrella of IT Risk Management

We are getting ready to go out.  We've showered, dressed, and are getting ready to leave.
 The forecast indicated a chance of rain.  Should we take that umbrella or not?  What is the likelihood it will rain, and what would the impact be, if we get caught without an umbrella in a downpour.  This eventuality may dampen our evening.  This decision is not unlike the decisions we make in Information Technology.
If we work in Information Technology, our job is to design, implement, test, support, upgrade or replace technology in some way.  This technology exists to support the business mission.  But we can get so involved with the execution of our job that we forget a critical fact - the infrastructure we work with is part of the foundation of our business.  Without that foundation, our business could not continue to operate as efficiently - it would not operate as profitably - it would not operate as securely.  Technology brings business some amazing capabilities, but if that foundation is not stable and secure, our business cannot continue to grow and strive toward its mission.  The business must have confidence in its technology foundation.  It does not want to get caught out in the rain.  We are confident in going out, knowing that umbrella is with us in the car.  Businesses must have that same confidence in the IT infrastructure.
IT Risk Management helps to provide the business with that confidence so critical for organizations today.  They must know that the money, time and resources they are investing is being properly managed.  A big part of that management is the management of IT risk.  IT risk management is all about ensuring that we have properly identified all the assets and data within our IT infrastructure.  Once identified, we classify that data in terms of sensitivity and importance to the business - how critical is that asset or data to keep the business going.  Then we assess those assets in order of criticality, against potential threats to the confidentiality, integrity and availability of the assets.  
Once we have identified the risks and the severity of those risks, we can document those risks in terms of the likelihood the risks will become a reality, and the impact to the business should those risks be manifested.  This methodology is detailed in the NIST Risk Management special publication 800-30.  Those two measurements allow the organization to rate the risk in terms of severity - from that rating the organization can derive a cost-benefit from efforts to remediate risks, as well as prioritize risk remediation efforts.  We can get as deep as needed into this process of defining risks - but we don't need to calculate the Annual Loss Expectancy of everything.  We start simply by seeing that many IT processes or functions fall under the umbrella of IT Risk Management.
IT Risk Management is like an umbrella for other IT security activities.  Vulnerability management is under this umbrella.  Vulnerability management allows the organization to identify and manage vulnerabilities - vulnerabilities are weaknesses or potential openings in the defenses protecting the infrastructure.  Those vulnerabilities are risks - the remediation of those vulnerabilities is a risk management activity.  And often the remediation of a vulnerability involves applying an operating system patch to a system.  Therefore patch management is a subset of vulnerability management.
This hierarchical relationship extends into other IT areas.  Configuration management is an important component of risk management.  In configuration management, we are identifying the configurations as they currently are on our devices, then having a process in place to review, approve and monitor those configurations going forward.  If a configuration changes and we aren't aware of that change, this issue directly impacts the integrity of our infrastructure - the configuration is different than it was before.  The business must be able to know what the configurations are, and that they can trust that this state won't change unless it is approved.  That change could potentially open up a weakness on that device.  Configuration management allows us to control and monitor those changes, thereby limiting the additional risk due to unapproved changes.
Since the changes to configurations can add risk, we can derive that any IT change can add additional risk to our enterprise.  A modified switch or router configuration can be a security issue.  A website change can bring in vulnerabilities.  The installation of an application on the network can open us up for malware.  If you've been working in IT for any length of time, it is likely you know of situations where a change caused an outage or another security issue.  Change Management is the process of documenting, reviewing and approving all changes to the infrastructure.  Proper change management allows us to vet the requested change to determine if it will add additional risk.  It allows us to make sure the change doesn't increase the possibility that the confidentiality of data can be violated.  It allows us to ensure that the change is documented, so that we maintain the integrity of the network.  And it also allows us to ensure that the change won't cause an unintended downtime (lack of availability) or outage in our infrastructure.  
As we can see, configuration management, change management, patch management, and vulnerability management are all under the umbrella of IT risk management.  Other areas under this umbrella are account management, vendor management, incident management, and many other IT general and IT security processes.  When desktop support installs antivirus on a PC, that's managing the risk of malware.  When helpdesk requires user validation for a password reset, that is a risk management activity.  When a developer tests code, he's not only validating functionality and error-free operation, he's also managing risk due to bugs or vulnerabilities.  
From this insight, we can start to see that just about everything we do is either a direct risk management activity, or could affect the IT risk within the organization.  As stewards of our business technical infrastructure, we must be able to see this hierarchical relationship and our part in contributing to the overall risk posture of the organization.  We are entrusted with a particular responsibility within the IT function - we must be sure we always keep the effort to minimize risks as a core part of our job, no matter what IT function we do.  This effort, if taken to heart as a critical component of our activity, allows the business to have confidence in the technology platform upon which they can grow the business and continue to strive toward fulfilling the mission of the organization.
Whether you know it or not, you help to hold up that IT risk management umbrella.  Make sure you always have a good grip in understanding your part - your business counts on it to protect itself against the rain.

Wednesday, January 14, 2015

What Condition Are You In?

The military and police are trained to be ready - their jobs inherently put them in circumstances which are dangerous.  But as we constantly see in the news, just going to the gas station can be dangerous today.  I see people all the time with their head in the clouds, their eyes on their smartphone - oblivious to their surroundings.  

A few years back, I knew someone who lived in a very upscale area of town.  His wife went to the gas station to fill up.  She was just filling up her tank - some guy in the next row of pumps came up behind her and shot her in the head.  He then went back in his car and shot himself.  She didn't do anything to him - he was just crazy and woke up that morning determined to die and take someone with him.  

We never know what the dangers are - all we can do is be prepared.  Preparedness isn't paranoia - it is just common sense.  We must know what is going on around us.  If we are at the gas station, we look around and see what everyone else is doing - do they have anything in their hands - are they getting something out of the trunk?  When we go inside the station to buy a soda, before we walk in we look through the windows.  Are the people inside acting normally?  Are the clerks acting normally?  Do they have their hands in the air?  Are people running?  Shouldn't you look before you go walking in, just in case?  Has there ever been a hold-up before?  How do you know there isn't one happening now?

As you're driving down the street, are you aware of the other vehicles around you?  Are the occupants of the vehicles acting normally?  Is there anything up ahead or coming up quickly behind of concern?  At the workplace, are you keeping an ear open for anything out of place?  Would you spot someone acting strange?  Workplace shootings are happening more frequently - have you thought about what you would do if that scenario manifested in your place of work?

As you can see, it is very important to be in a condition of relaxed preparedness and alertness, even as we're going about our mundane activities.  Depending on what neighborhood you're in or line of work, the risk of an attack or other danger is relatively low - however the impact is very high.  In risk management, we quantify risk in terms of likelihood and impact.  A tornado hitting your datacenter is a very low likelihood, however the impact of that event would be catastrophic.  Therefore companies plan for that contingency by building alternate sites, standing up standby servers and syncing their data to that disaster recovery facility.  The business understands that, even though it is highly unlikely that the event will occur, the impact to the business would so disastrous that they had better spend the money just in case.

We must think of ours and our family's safety in the same way.  The likelihood that you will walk into a hold-up in progress is very low.  The possibility that someone will invade your home is also pretty unlikely.  However if that should occur and you are not prepared, the risk to you and your family is dire.  It is vital that we understand the risk, and understand what we can do to be better prepared.

http://armeddefense.org/the-color-code-of-awareness
The military and police have a set of codes or conditions based on the mindset and level of preparedness.  They are color codes - Condition White is basically when your head is in the clouds - you are oblivious to your surroundings.  This is the condition most people are in all the time - if someone had a gun and began walking in your direction, you would never see them coming.  This is a very dangerous state to be in, however it's the most common mental condition.

Condition Yellow is a state of relaxed preparedness.  In Condition Yellow you are aware of your surroundings - you recognize that danger can arise at any time in any place - although it is highly unlikely you understand the impact such an event would be.  You watch everyone around you - you know what they are doing, you know what they have in their hands.  You are, almost subconsciously, looking for anything out of place or any activity that is abnormal for the place and time.  If you spot something that looks out of the ordinary, you are already one step ahead.  If that situation appears to be dangerous, you go into Condition Red.

Condition Red is a high suspicion of danger.  You see people in the gas station running - you spot someone pulling what looks like a rifle out of their trunk - you hear what sounded like a gunshot in your workplace or hear people screaming.  You go into a state of high alert - the hair on the back of your neck probably stands up - adrenaline begins pumping.  If unprepared, you will likely freeze and panic.  If prepared, you will do what you've trained yourself to do - picking up the phone to call 911, moving quickly to a safe location, exiting the building, stopping from going into the gas station, etc.  

Condition Black is confirmation of a threat - you see the active shooter in your workplace - you see the driver next to you pointing a gun.  All your training kicks in, or you are left unprepared and act from instinct and fear.  You will either die or you won't.  That depends both on luck and your state of alertness, preparedness and training.  The soldier and the police officer understand this - they have prepared for the worst and have a better chance of surviving.  There are many things we can do as well to be better prepared.

Think about the potential for danger as you go about your day - think about these mental states and conditions.  In future posts, I will go deeper into the things we can do to prepare - things we can do to train for possible threats in terms of your physical security and safety.  We don't have to walk around in a state of paranoia - we can operate in a way that allows us to be aware of our surroundings and potential dangers, and understand the things we can do if we find ourselves in Condition Red or Black.  Stay tuned!


Tuesday, October 21, 2014

Masters Progress

As I (may have) stated, I finished my BSIT at WGU last year.  The program was really awesome - at WGU you are able to "accelerate" - this basically means you don't have to sit through an entire semester and wait to take a final exam.  At WGU your entire course of study is available - you have the syllabus and read at your own pace.  You can take the assessments as soon as you feel you're able.  If you've developed the competence required by the course, you pass the assessments and once complete, the course is done.  If that takes you 6 months, fine.  If it takes you 6 days that's also fine.  With this program I was able to complete 83 credit units in 3 6-month terms.  I was also selected to speak at the commencement ceremony.
Yeah that's me...

Don't get me wrong - the courses were tough.  I was just very motivated and pushed most things aside to dedicate at least 25 hours a week to school work.  

So either I'm a glutton for punishment or just an overachiever - I recently enrolled in the WGU Masters of Science in Information Security and Assurance (MSISA).  This is a 2-year program with the option to "accelerate" if you're able.  Since I had flew through the BSIT program, I figured this would be a cake-walk - it's in my area of expertise and I'm highly motivated.

Unfortunately I have come to the realization that the Masters program is MUCH more difficult than the BSIT.  There are 11 courses to complete - each class has at least 3 papers to write.  I'm presently enrolled in 3 courses - Emerging Technology, Cyberlaw and Hacking-something-or-other.  The first course on Emerging Technology required me to write an RFP to a company to develop an information sharing portal across regional offices, do an evaluation of rural Internet connectivity methods, and writing up a proposal on virtualizing a small city's IT infrastructure.  Each paper has been 10-15 pages and each submitted paper has been returned for re-writing due to something missing or not fully covering the topic.  

"UMM is not an answer!"
My second course is on Cyberlaw - I just finished two papers - one was on developing policy statements for a healthcare organization - one on new users and one on passwords.  The other paper was an analysis of a healthcare breach - determining what policy statements could have prevented the breach.  The final two papers are rewriting an SLA to protect the organization and doing an analysis of fraud at a fake bank.   Writing the papers is not too bad - reading all the legal stuff - court opinions - case studies - this is really dry stuff!  Glad I'm not studying to be a lawyer (I love you Judge Judy!)

I will attempt to write more as I progress through the program, for those who just don't have anything better to do, or for those who are considering attending WGU.  I think WGU is revolutionary in higher education - they offer a challenging program - they are an accredited school - all online - with the ability to accelerate through the program, which saves the student time and tuition costs.  I am so thankful for WGU - if you're as old as I am, you may have dreamed of such a school at some point.  Well I can tell you from experience that WGU is that school.  The student and course mentors are all great - the admissions process is not too bad.  They will turn you away if you don't match the criteria for the program.  If you want more information don't hesitate to reach out to me via the blog or LinkedIN.

As I said in my commencement speech, at WGU not only are you learning the subject matter, you are demonstrating and developing your skills in setting goals, getting things done,  multitasking, critical thinking, and self-motivation..  these are all crucial to success at WGU but even more so in the business world.  Any employer wants someone who can demonstrate that, without guidance, you can pick up a large task, organize it and work through to completion.  These are the characteristics of the leaders and executive managers, the positions we are all shooting for as we pursue a Master's Degree.  Of course having a Master's level foundation in all the subjects is also very helpful.

Along the way, I may try to relate my studies to some real world topics, just for entertainment or educational purposes.  It is a good way to take a break from all the reading and writing - or I could just play Angry Birds.... 

Wednesday, September 3, 2014

Guarding the Castle

Our network is our castle - we can never become complacent when trusted to protect our corporate assets, customer data or sensitive information.  All too often, we find ourselves asleep at the wheel, relying on all the security controls and processes we have implemented.  We must have a strong monitoring and auditing function built into our Information Security program.  Heathens are in the woods, watching our every move, waiting for the chance to storm the castle, slipping through a crack or blowing down the main gate, to invade, loot and pillage.

You have passed out administrative credentials to many employees.  How do you know those employees are not deviating from the expected and approved tasks?  This deviation could be malicious, or it could simply be a mistake.  Either way we face many risks when we allow employees to operate as an administrator on any system - we must have some oversight in place to detect and report on anomalous activity.  

How do you know your webserver is not under attack, right this very instant?  Webservers are notorious for being a primary target of attack while also being one area we find with the weakest security controls.  What if someone dropped some malicious code on your Linux webserver?  How would you know?

I suggest that, along with requirements definition around that latest firewall or antivirus platform, the coolest new email security product or the best-rated web filter, we include security monitoring, some form of configuration change detection, and the ability to capture, consolidate and filter logs from all our devices.  Many ways exist to do this properly, instead of just plugging in that shiny new firewall and then going back to sleep, we must remain diligent and on-guard - part of that is proper monitoring and mechanisms in place to quickly detect potential attacks.

If we utilize a Security Information and Event Monitoring solution, we can employ resources to review these logs, respond to alerts, and have some chance of catching an attack in progress, before it becomes a major emergency.  Those teams should be trained to know exactly what is suspicious and what is just noise.  The secops teams should be good enough to quickly scan the logs and anything out of place will catch their eye.  

In addition to active monitoring and review of logs, we must capture our configurations, whether that's a web server or a router, and then detect when that configuration has changed.  I've been in companies where they haven't made any updates or checked the configuration for years.  There are mechanisms or scripts you can write that will take a hash of the configuration of the router or the web server /var/www once a day.  The script does a compare of the hash from one day to the next.  If the hash value changes, something has changed in your config, or something has been modified in your web server.  

Once we've detected a change, we can inquire as to whether there was an approved change within the last 24 hours.  If there was, then the alert is simply a confirmation.  If there was no approved change, we must find out if an unapproved change was made, or if we've been compromised.  If the admin just forgot to send in a change control and added a line to the .conf file, then we just remind him of the policy and move on.  If no one knows of any internal change, we must suspect that we've been compromised in some way.  We must now go into Incident Response mode and try to find out what was changed and what that means.  From there, if we were compromised, we can quickly find it and kick them out of our server or our router.

Maintaining a secure network isn't rocket science but it does require expertise and diligence.  We must ensure we have the right tools, the right processes, and the right expertise to utilize those tools to the greatest effect.  The Information Security professional needs to understand how a router works, what a config looks like, what goes in the /var/www folder, how a Perl script works.  We must be able to quickly review logs and know what is normal and what is not.  It takes a while to get up to speed on all this, however your employer trusts that, in giving you the keys to the kingdom, that you have all the ports and moats covered properly.

Friday, April 18, 2014

Speaking of Mobile Security

I've been doing a fair amount of speaking about Mobile Security lately.  The audience has been financial operations - accounts payable and accounts receivable.  These folks are concerned with the evolution of mobile technology and how it is being progressively integrated into their operations.  They have found that the risks are pretty large, and no one seems to be paying attention to this.

We are racing headfirst into the mobile revolution, interweaving it into our everyday life.  I can check my bank account balance, transfer funds, make investment trades, take payments, even manage my company's finances all from a tablet device.  In healthcare, we have mobile apps which allow clinicians to check your chart, monitor your blood pressure, view x-rays, write prescriptions...  this increased mobility is a great thing - it adds productivity and mobility - but we have to balance the benefits with the risks.  In other words, we need to understand and control the risks as we continue to weave mobile technology into our world.

The risks of mobile technology are pretty scary.  I would bet that you have apps on your phone or iPad that have more permissions than you are aware of.  Most of the time, we install an app without checking the permissions.  It usually asks your permission to install and gives you a list of permissions you're giving the app.  But we don't really check those - we are in a hurry to get the benefits of the app!  But the rights you're giving this app may be excessive.  Do you want Angry Birds to be able to delete data off your iPad?  Do you want your fitness app to be able to read your contact list?  Do you want your travel app to be able to send emails in your name?  Can they do that now?  You had better check!

I will try to write more frequently - I'm going to do a series on Mobile Security, since that seems to be a really hot issue at the moment.  I just added a Speaking tab to the blog - you can check out where I've been speaking and also let me know if you'd like to have me out to speak at an event.  


Wednesday, December 26, 2012

Maintain the Combat Stance

Miyamoto Musashi was a great Samurai - born in 1584, he lived in the prime age of the Samurai warrior class.  Musashi was a ronin, a master-less warrior, who wandered the country, trained, fought other warriors and was undefeated in over 60 duels.  

In his old age, Musashi retired to the hills as some Samurai were known to do, and composed poetry and other works of literature and art.  Musashi had mastered the art of combat - he composed a book called "The Book of Five Rings" - it is a treatise on combat.  The book is widely admired today in both martial arts circles and in business, as a way to know your enemy and improve your own tactics and strategy in war.

In this book, Musashi writes "The Way is in training. Become acquainted with every art." - This wise advice applies directly to our mission in Information Security.  We are faced with the constant threat of attack, just as Musashi was while walking the Japanese countryside.  Musashi advises us to know our enemy - know his skill.  Understand the threats.  

When I was studying for my CISSP, I had to either learn or become reacquainted with ten domains of information security.  Even though I may not use it on a daily basis, the CISSP exam would test me on my knowledge and understanding of all areas - I didn't need to be an expert but I needed to be acquainted with every art.  

Musashi lived a life of constant training - working to improve his physical skill and mental preparedness.  He learned to assess the opponent's skill and capabilities - in security we also must learn about the risks.  We scan for any vulnerabilities, we strive to understand the threats which might exploit those vulnerabilities, and we look for ways to plug those holes, remediate those risks - like Musashi we constantly try to improve, training and educating ourselves to the potential dangers to our data and learning to battle the attackers.

We must seek to constantly improve our skills and our defenses - tighten up our security while also increasing our ability to be alerted for anything which might be out of the ordinary. We never know how small of a clue we will get, if any at all, that an attack is coming.  We must learn the tools and tricks of our opponents so that we may understand what we need to defend against.  And we must use strategy to drive our stance - as Musashi also writes - "In all forms of strategy, it is necessary to maintain the combat stance in everyday life and to make your everyday stance your combat stance. You must research this well."

Musashi's words are very appropriate for us - how do we maintain the combat stance in our networks?  And what does he mean by - make your everyday stance your combat stance?  If we understand the threats and prepare our defenses well, we maintain a combat stance, ready to repel any attackers or be notified of a battle underway.  We must have our plan in place and ready to go - our security operations should be buzzing and our incident response program will be standing by.

Just don't go running out of your office with a headband, a samurai sword, yelling "BANZAI"!!!  HR would probably frown on that.

Monday, December 17, 2012

All Aboard

Years ago, I worked for a large Fortune 500 healthcare company.  Obviously this company was concerned about it's requirements under HIPAA - at the time cell phones were being used but they were not the same as today.  Some had cameras, but many phones were simple flip phones without cameras.  Because a camera is a way in which you can gather, capture and move data, the company was rightly concerned about the new "camera-phones" and instituted a policy restricting their use and/or possession on company grounds.

Can you imagine what the compliance rate would be on that policy today?  I'm not certain you can purchase a new phone today without a camera.  We may have to revert to the vintage electronics section of eBay to find such a dinosaur of technology.  In today's healthcare environment, you have every single employee, from the doctor to the janitor, carrying not only one smart device, complete with camera, WIFI and the capability to instantly post the latest thought or photograph to Facebook, but it's likely some of these people have an iPad, some other tablet or small form factor laptop in their shirt pocket.  

We can no longer dictate that no one have these devices.  We have no effective administrative control that we can use to limit or restrict the presence of these devices - policies prohibiting something which has become woven into the very fabric of our culture would only be ignored.  It's like prohibiting them from bringing in their shoes or wallet.  The key point here -  a large risk has become assimilated into the culture, so much so that we've crossed the point of prohibition.  We only stand in front of this fast-moving train at our peril.  If we are to be effective, we must learn how to jump on board this thing as it's moving and at least find some room in the driver's car to figure out a way of putting some controls in place.

As with anything else, our usual template of Information Security will suffice - we need a well-conceived set of administrative and technical controls - our policy, while still acknowledging that every living creature on the planet is organically attached to a smart device, must dictate that the user will follow the policy at risk of termination and permanent smart-phone-ectomy.  This policy sets the table firmly for other controls - but why is this piece so important?

I have a tool that I am permanently attached to, that I take home with me, I use in the car, in the bathroom, it's my alarm clock, the way I check the news and the weather, the way I talk to my 14-year old, the thing that tells me when my favorite cigar goes on sale and lets me take notes or dictate.  This list really can go on forever - just look through the app store and you'll find just about anything to meet your needs and help you make your day more efficient.

Because of the fact that this device is our constant companion, we tend to be more lax with it - we don't treat it like a work device.  So we must force users to understand the importance of turning on their brains with respect to using the device.  We must educate users on the risk of using the device and their responsibility to use it wisely.  And we must put in some common sense controls which, while not prohibiting the usage of these devices, controls exactly what we want to control.

Today's solution to this problem is mobile security- some tool or agent which is installed on the device and phones home - the console can force a passcode (which means forcing encryption of the device), it can alert on devices which are out of compliance, let me know when the devices moves from place to place.  It's a happy compromise - I can't prohibit it but I can restrict certain things and wipe the device if it's lost or stolen.  I can force the thing to encrypt the data.  And I can "sort-of" disable the device's camera.

As a security guy in charge of infosec for a hospital, that's really what I care most about.  We cannot stop the train of mobile devices - we have to learn to get on-board and help steer away from our most critical asset - patient data.

Monday, December 3, 2012

Risky Business

In the broad spectrum of activities which might be called Information Security, we must always first and foremost implement, execute and follow through with risk management.  Risk management is the backbone or foundation of any good information security program.

Risk management is really just going around, taking a look at the way things are set up, processes, policies, from what ports are open on the firewall to what rules are set on your antivirus client.  Risk management is a process of inventorying the existence or state of things, reviewing all this against your knowledge, expertise, research and maybe even some tools, to determine if we're doing things the right way or not.

Even if we're going along with best practices, we must understand that we still have some risk.  There is no such thing as 100% security  - the best practice in the world doesn't remove all risk - unless we want to unplug our infrastructures from the public Internet and never allow anyone to access anything.  This scenario basically shuts down our business - that means we must balance risk management with running the business.  This caveat should be posted on every security professional's desk to review constantly, as they attempt to implement or manage security controls.

We must define our existing controls and determine the gaps - then we define the present risk for it all.  Once this is done, we can begin to prioritize that risk - figure out strategies to reduce risk based on the priority or criticality of the asset or data or service or other resource we're trying to protect.  We can close unnecessary ports, change our A/V policy to restrict more, add language to our policies - we find ways to reduce that risk through the controls we have or the controls we implement based on our risk assessments and determination.

This strategy isn't new - I didn't invent it.  But in my experience many organizations have never heard of risk management, at least from an IT perspective.  We don't have to go down the rat hole and hire an accountant to calculate the ARO or SLE, but we should be familiar with these terms - with what they represent.  This makes us more prepared, so that when we identify a risk and need to implement a control, we can intelligently discuss the problem in terms the business understands - dollars.  

We learn to protect the business, not because we know how to SSH into a firewall and set up an access control list, but by providing expert counsel, by understanding what the business is trying to accomplish, by understanding the risks inherent in technology, and by offering wise solutions based on actual, prioritized risk and not Fear, Uncertainty and Doubt (FUD).  

If we can build our security programs upon a foundation of proper Risk Management, we have the groundwork for policy, process, technology - we can build teams dedicated to the correct task and eliminate or minimize time wasted on non-essential activity.  We can operate our security program as a function of risk management - prioritized to be laser-focused on the most critical maintaining a low risk profile for the organization's IT infrastructure.  

When I talk to many information security people about Risk Management, I see the deer in the headlights.  As an industry we must be able to walk in both worlds, technology and business.  Risk management is a language understood and appropriate for both.

Wednesday, September 12, 2012

The Best in Practice

If we are charged with designing, architecting, implementing, deploying, integrating, training and supporting security technology, processes and policies within our organization, we might discover that this work is really an art more than a science.

Anyone can go out and purchase a solution to provide anything from firewalls to antivirus.  Once those solutions are installed we might be tempted to sit back and be overwhelmed with a sense of security, knowing we've locked out all the potential intruders.  But I would caution anyone who might feel this way, and offer additional advice on how to best practice information security in your organization.

First of all, we can never be satisfied or comfortable with any one technology.  A firewall is simply a port-blocker.  If source-destination-allow-deny-port-whatever.  The firewall will either allow traffic on a port or block it.  If it's open, a standard firewall makes no further inquiry into the traffic - it's considered trusted at that point in your infrastructure.  

So if I allow inbound port 80 traffic to a web server, my firewall is basically opening the door from the Internet to my web server on that port.  All traffic is inspected - if it's knocking on the port-80 door it gets to come in, just like a visitor who knocks on my door - I just let them in.  I don't frisk them, I don't check their pockets, I don't ask them what they have in their bag or what intention they have.  I just let them walk right in.

The firewall does the exact same thing - so it might be "trusted" from the firewall's perspective however we must realize that "trusted" traffic through the firewall can also be malicious traffic.  Nothing says an attacker can't use port 80 to attack you - it happens all the time.  The point is that this isn't the job of the standard firewall - to determine if that traffic is malicious or not.  It is just a port-blocker - port 80 is open or closed.  That's all the firewall does.

When I give presentations to new hires at my organization, I ask them what information security is.  Many times someone will say - having a firewall.  The perception is that if you put a firewall in place, you're secure. That's as false as saying if I put a lock on my front door, no one can break in my house.  

What we must do is understand the function and purpose of our tools and solutions, understand the risks, and then fill in the blanks.  We must fully understand what a firewall is, what a firewall does and what it does not do, understand what sort of risks we are facing, then put other pieces in place to supplement that basic level of security - that front-line of protection.  We might implement an Intrusion Detection/Prevention solution to inspect the "trusted" traffic coming across port 80 into our network - the firewall's job is to allow it - malicious or not.  Then the IPS tries to determine if that "trusted" traffic is just web server traffic or a signature or behavior which indicates a high possibility that the traffic, while trusted, shouldn't be allowed.  Therefore the traffic will either be blocked and/or alerted on.

Once we get this holistic view of the threats and ways to protect our organization, the practice of information security goes all the way to the endpoints.  That is, we find ways to integrate all of our solutions into one organic concept.  Like layers of an onion, I don't look at my security infrastructure as 15 different pieces.  I look at it as a whole, a complex but interacting web of layers, each of which have a purpose in the big picture.  I might be able to see a botnet from my antivirus logs, my web filter logs, my intrusion detection logs - if I have everything set up correctly I will know about this sort of risky traffic, be able to respond in a timely manner and safely restrict or block that traffic without any disruptions.  

This is sort of an introductory piece - we can go so much deeper.  However I wanted to set the table properly - I would love comments on creative and effective ways you utilize your infrastructure to protect your organization.

Monday, August 13, 2012

Securing the C-Level - Michael Peters

I posted a review on Amazon.com but wanted to republish here.

After reading Securing the C Level, by Michael D. Peters, I found I could hardly put it down. This book is like a gold mine - like finding a little gold nugget after years of searching for some good advice, like having a private lunch with someone on that upper echelon and picking their brain about the ins and outs of how to get a job like that. Not only is it very insightful into the preparations needed to get to that level, but it also offers insight to anyone in a management position. Michael gives sage advice on navigating the cultural waters, how to spend your first 100 days for maximum benefit, how to groom your personal brand, and many other interesting and invaluable tidbits about achieving and maintaining that life at the top of the corporate ladder.

Parts of the book I found most interesting were dealing with planning your career - Michael provides some awesome and creative tips to chart the waters of executive career planning - especially if your career benefits from the achievement of credentials. Michael also talks in-depth about life as a C-level executive, the sometimes-treacherous waters, and how to successfully navigate them. As an MBA and a JD, Michael's background and experience allows him to provide a wealth of practical and insightful advice, advice which anyone can and should be following if they want to follow someone like Michael's footsteps.

Highly recommended book for career planning - a very interesting and actionable read!

If you aren't familiar with Michael Peters, have a look at his background and his blog.  He's a monster!  He sailed through the BS, MBA and now eJD degrees - he's a CISO, a member of the ISSA Hall of Fame, and he's one of our Keynote Speakers at the 10th Annual Louisville Metro InfoSec Conference!

Wednesday, August 1, 2012

Hey Fellow

I was recently honored and humbled to be notified of my acceptance and appointment as an ISSA Fellow.  

The ISSA rewards a small number of members each year with the Fellow designation - the ISSA Fellow is someone who has at least 8 years of ISSA Membership with 3 of those years spent as leaders - Board members, officers or President.  An ISSA Fellow has also demonstrated at least 5 years of noteworthy performance as an Information Security professional.

Of the 137 international chapters and over 10,000 members worldwide, ISSA Fellows number about 35 - less than 1% of the member population.  

As an ISSA Fellow, I would like to continue to participate, not only at the local level, but nationally and internationally, with the ISSA.  As a Fellow I plan on further facilitating educational and networking opportunities for Information Security professionals through the ISSA, ISACA, Infragard, OWASP and other related organizations and activities.

The ISSA is a fantastic organization for Information Security professionals and the companies they serve.  This organization provides direct support for local chapters - the chapters are the key.  When you join an ISSA chapter, you will likely be able to attend planned meetings, where interesting and informative speakers provide an educational presentation.  You may also be able to attend conferences, like the ISSA Kentuckiana Chapter's annual "Louisville Metro InfoSec Conference".  The chapters facilitate educational and networking opportunities for their members.  

I can tell you, from over 8 years as a member of the ISSA, that my career would not be what it is today, without my membership AND participation in my chapter.  I have met so many amazing people, learned a great deal, and have been exposed to many opportunities - both job opportunities and leadership opportunities.  If you are able and willing, you will have the opportunity to shine by volunteering with your local ISSA Chapter.  I wholeheartedly recommend it.

So as a newly minted ISSA Fellow, let me stand up and cheer for the ISSA - it's one of the best investments and activities you can make in yourself and your career.

Mind Your Data

As I sit and ponder what else to write about, it dawns on me that we are living in a world of technology.  If we look around our life, we would be hard-pressed to find an area that isn't affected by technology.  Technology has become so interwoven into the fabric of our lives that we hardly notice it any longer.

Consider your house - you probably make sure your doors and windows are locked.  You might have installed an alarm system to alert if a burglary or fire is happening.  You may own a firearm with the purpose of protecting your family in the event of emergency.  You install fire detectors in each room, and you may own a dog for both companionship and for it's deterrent value.

We also take similar precautions, if we're smart, outside of the home.  We generally lock our vehicle to prevent or deter theft.  We may have learned to keep our keys in our hands while we walk to the car, especially at night.  We are familiar with the fire exits at work, and we likely go through multiple security protocols throughout our day, from toll roads to access badges to locks on our desks.

The problem, I believe, is in the proliferation of technology in our lives.  We always have our cell phone on our belt, in our pocket or in a purse.  We might carry a laptop or tablet - we certainly have a PC at home and likely utilize one at work.  Our TV can now access the Internet, and even our fitness machines and refrigerators soon will be connected to the "Net".  This connectivity is very convenient but I think we have become unaware of the risks.

Any of these devices, connected to a network or the Internet, could present your personal information in ways you are not aware of.  Your credit card information, social security number, and a host of other interesting and useful bits of information could be seeping out the cracks in your technological collection.  There are many ways of helping to reduce the risk, however most people aren't even aware of the risks, not to mention the ways of reducing that risk.

It is imperative that we, as technology consumers and users, become aware of just how much of our personal information we're sharing, how much we're letting leak out.  It's fine if you know about it and are fine with sharing it.  The real concern happens when you don't know.  The number of Information Security professionals, sites, and books available is vast - make sure you are taking advantage of these resources, learning just what the risks are, and taking the necessary steps to help minimize the risks to your personal information, finances, health records, and anything else you wouldn't want to share with the world.

You lock your door each night - make sure you have a lock on your data also.

In the beginning...

Welcome to my new blog.

My name is Randall and I'm an InfoSec guy.  I am a CISSP, an ISSA Fellow, and have been working in the InfoSec field for a decade now.  I've always been a security guy - I started in private security, became a deputy sheriff, then went into IT and eventually InfoSec.

I am interested in all things security - computer security, personal security, risk management.

With this blog, I will collect my thoughts, put down insights, talk about funny and not-so-funny things that happen in my world, and share all the information I can on securing your business and also securing your life. One day it might be how to set up a firewall and the next it might be how to set up your home to be more secure.

I will propagate this blog via the wonderful social networking sites out there - including LinkedIN, Twitter, and maybe, someday....  dare I say it....  Facebook...

Drop me a comment if you're so inclined.  Stay tuned and I'll try to keep it interesting and informative.