Showing posts with label Risk Management. Show all posts
Showing posts with label Risk Management. Show all posts

Sunday, September 13, 2015

Personal Threat Preparedness

If you're reading this blog, it's likely that you're involved or interested in security.  Security comes in many forms - Information Security, physical security, personal protection, etc.  This article will deal with what we need to do to be safe as we move through our daily lives.  With all the recent violence, it is important that we both understand the risks and have a threat preparedness mindset.

I know our special agents and law enforcement personnel are given some training on assessing threats, but where does that leave the average citizen?  I've searched "the Google" extensively but guidance for the private citizen on assessing and dealing with threats is very limited.  As a former law enforcement officer, hopefully I can share some important tips as we go through our daily lives.

If I go to the grocery store, I expect to go through each aisle, finding the items I need to complete my grocery list.  But how many of us keep an eye out for potential threats?  Do you really believe no active shooters, homicides or assaults happen at the grocery store, mall, theater or other public gathering?

If you are a law enforcement officer, a federal agent or a military operator, you're trained in threat assessment.  But what does that mean?  This article will deal with assessing and dealing with threats for the average citizen.

We are most likely not deployed to a foreign country - kicking down doors and looking for terrorists.  However, we do frequently enter rooms, situations where the unknown and surprise situation may happen.  If we are walking through life unaware of possible dangers, we will certainly miss the advance clues and most probably will be just another statistic.  If we are aware of both the possibilities of danger and the best ways to prepare, we may be able to spot things out of place.  We can develop a habit of identifying possible escape routes, improvised weapons, as well as spotting potential dangers.

So let's say I'm at the grocery store or gas station at 10 PM.  I can, 99.999999% of the time, just get my groceries or gas, oblivious to danger.  But that .00000001% of the time, danger will strike.  That danger will manifest in a robbery in progress, a deranged, suicidal maniac, even a drive-by shooting.  What habits should I develop to ensure that I am as prepared as I can be, without being paranoid?

The best plan is to avoid danger altogether.  The first thing I do is to look through the windows.  Is anything out of place?  Are people acting normally, or are they afraid, stressed, focused on one area?  Think about a scenario with a robbery in progress.  Everyone inside would be afraid and focused on one point - the robber.  Make sure you look first before entering, and if you spot the likelihood of a robbery in progress, don't go in.  DON'T be a hero...  call 911.. Give a description, location and direction of travel.  Those are the most critical things law enforcement needs.  Move away from the danger and ensure law enforcement has the most correct and up-to-date information.

Assuming no obvious threat exists, you enter the establishment.  Just because no obvious clue of threat was present doesn't mean a threat isn't there.  As you enter the establishment, do three things:
  1. Identify the location and description of all persons
  2. Identify all escape routes
  3. Identify all potential improvised weapons
When you enter the location, look around.  Note any persons present - note their demeanor.  Are they behaving normally or do they appear to be stressed?  Note the persons gender, approximate age, race, height, weight, hair color...  These things are difficult or impossible to change.  Additional factors to notice will be the clothes they are wearing - the color - any distinguishing marks like hairstyle, tattoos, scars...  Also if they leave the scene in a car, note the car's color, approximate age, make, model and license plate number and State, if you can.

If you walk in a room, take note of any persons present.  Certainly a person with a gun would stand out, but someone overly stressed should catch your attention.  Is the person wearing a heavy coat in the summer?  Do they appear to be under the influence of some substance?  Do they seem to be acting weird?  Mentally gauge each person's state - mental/physical.  Most times, you will assess the threat of each individual and determine that they are not a threat.  It's a quick mental exercise but worth the effort.

Occasionally you will encounter someone who appears out of place - who seems suspicious to you.  Note that person and if there are no further threats, proceed with your business while keeping an eye on that person, as well as #2 and #3 above.  Listen to your instinct - if you have a bad feeling, don't ignore it.  Head for the door and get the bread, milk and eggs tomorrow.  Get to a safe place and call the Police if needed.  Better to be safe and mistake the situation, than to be a victim.

As you enter any room, make sure you are aware of all possible escape routes.  Do they have fire escapes?  Are there exit signs posted?  If danger in any form manifests, can you get yourself and others out?  Or will you simply panic and freeze?

If that suspicious person pulls a gun or starts causing an issue, what will you do?  The purpose of the exercise is to think through all likely scenarios.  The truth is that, in a crisis, you will do whatever you've trained to do - even if that's just thinking through possibilities and at least having a game plan (however unlikely it is that you'll use it.)  If you haven't trained yourself in this way, you will again do exactly what you've trained to do - nothing.  You will panic and freeze.

If a danger arises, you will have already already identified escape routes and improvised weapons - move to exit the scene and call 911 with description and direction of travel, identifying marks, etc.  If you find yourself unable to leave or are directly engaged with the danger, you must act quickly and with certainty.

We have heard of several active shooter incidents over the last few years.  The police have targeted training for civilians, especially teachers - the core of this training is "run, hide, fight."  If you realize you're in such a situation, the best thing to do is run.  If you're responsible for your family or students, gather them together and run.  If you find that you cannot run without increasing the danger, or find yourself in a locked room or otherwise unable to get away from the danger, hide.  Hide everyone behind a locked door.  Get on the phone with 911 immediately.  And if the danger comes to you and you are unable to escape, you must fight.

If you cannot run and must hide, you must be prepared to fight should the shooter find you.  If that active shooter comes in the room, obviously intent to mow down everyone, you have little choice.  Get in a position where you can surprise the shooter - when he comes through the door, ambush him.  If you don't act, you're likely going to be shot anyway.  Grab the gun and point it away from everyone, then shove your fingers in the attacker's eye sockets as hard as you can.  Have a letter opener or scissors - shove that into the attacker with every ounce of strength and bravery you have.  You must mentally prepare yourself and decide that you'd be willing to do this, faced with such a situation.  It isn't a nice thing to think about but if you don't mentally prepare yourself, you will just be a victim.

If we have this mindset and diligence, we will be prepared should an attack occur.  Unless we're deployed to a wartime situation, the likelihood of occurrence is low.  However, the impact of this occurrence is so high that we must prepare ourselves both mentally and physically.

Be safe out there - keep your eyes open.  The most important thing we can do is to always be situationally-aware - be aware of our surroundings and don't walk into a dangerous situation.  Quickly identify and assess each person - note all possible escape routes.  If you find yourself in the midst of danger, run.  If you cannot run, hide.  And if you cannot run or hide, be prepared to identify anything that can help you fight and win.

Our agents of national security are trained to assess and deal with potential threats.  We can utilize this basic set of principles to ensure that we are prepared to spot a threat and, if needed, to properly deal with the threat.  A proper mindset and preparedness may avoid our being just another statistic.  If you have questions or comments, please let me know.

Friday, March 27, 2015

The Umbrella of IT Risk Management

We are getting ready to go out.  We've showered, dressed, and are getting ready to leave.
 The forecast indicated a chance of rain.  Should we take that umbrella or not?  What is the likelihood it will rain, and what would the impact be, if we get caught without an umbrella in a downpour.  This eventuality may dampen our evening.  This decision is not unlike the decisions we make in Information Technology.
If we work in Information Technology, our job is to design, implement, test, support, upgrade or replace technology in some way.  This technology exists to support the business mission.  But we can get so involved with the execution of our job that we forget a critical fact - the infrastructure we work with is part of the foundation of our business.  Without that foundation, our business could not continue to operate as efficiently - it would not operate as profitably - it would not operate as securely.  Technology brings business some amazing capabilities, but if that foundation is not stable and secure, our business cannot continue to grow and strive toward its mission.  The business must have confidence in its technology foundation.  It does not want to get caught out in the rain.  We are confident in going out, knowing that umbrella is with us in the car.  Businesses must have that same confidence in the IT infrastructure.
IT Risk Management helps to provide the business with that confidence so critical for organizations today.  They must know that the money, time and resources they are investing is being properly managed.  A big part of that management is the management of IT risk.  IT risk management is all about ensuring that we have properly identified all the assets and data within our IT infrastructure.  Once identified, we classify that data in terms of sensitivity and importance to the business - how critical is that asset or data to keep the business going.  Then we assess those assets in order of criticality, against potential threats to the confidentiality, integrity and availability of the assets.  
Once we have identified the risks and the severity of those risks, we can document those risks in terms of the likelihood the risks will become a reality, and the impact to the business should those risks be manifested.  This methodology is detailed in the NIST Risk Management special publication 800-30.  Those two measurements allow the organization to rate the risk in terms of severity - from that rating the organization can derive a cost-benefit from efforts to remediate risks, as well as prioritize risk remediation efforts.  We can get as deep as needed into this process of defining risks - but we don't need to calculate the Annual Loss Expectancy of everything.  We start simply by seeing that many IT processes or functions fall under the umbrella of IT Risk Management.
IT Risk Management is like an umbrella for other IT security activities.  Vulnerability management is under this umbrella.  Vulnerability management allows the organization to identify and manage vulnerabilities - vulnerabilities are weaknesses or potential openings in the defenses protecting the infrastructure.  Those vulnerabilities are risks - the remediation of those vulnerabilities is a risk management activity.  And often the remediation of a vulnerability involves applying an operating system patch to a system.  Therefore patch management is a subset of vulnerability management.
This hierarchical relationship extends into other IT areas.  Configuration management is an important component of risk management.  In configuration management, we are identifying the configurations as they currently are on our devices, then having a process in place to review, approve and monitor those configurations going forward.  If a configuration changes and we aren't aware of that change, this issue directly impacts the integrity of our infrastructure - the configuration is different than it was before.  The business must be able to know what the configurations are, and that they can trust that this state won't change unless it is approved.  That change could potentially open up a weakness on that device.  Configuration management allows us to control and monitor those changes, thereby limiting the additional risk due to unapproved changes.
Since the changes to configurations can add risk, we can derive that any IT change can add additional risk to our enterprise.  A modified switch or router configuration can be a security issue.  A website change can bring in vulnerabilities.  The installation of an application on the network can open us up for malware.  If you've been working in IT for any length of time, it is likely you know of situations where a change caused an outage or another security issue.  Change Management is the process of documenting, reviewing and approving all changes to the infrastructure.  Proper change management allows us to vet the requested change to determine if it will add additional risk.  It allows us to make sure the change doesn't increase the possibility that the confidentiality of data can be violated.  It allows us to ensure that the change is documented, so that we maintain the integrity of the network.  And it also allows us to ensure that the change won't cause an unintended downtime (lack of availability) or outage in our infrastructure.  
As we can see, configuration management, change management, patch management, and vulnerability management are all under the umbrella of IT risk management.  Other areas under this umbrella are account management, vendor management, incident management, and many other IT general and IT security processes.  When desktop support installs antivirus on a PC, that's managing the risk of malware.  When helpdesk requires user validation for a password reset, that is a risk management activity.  When a developer tests code, he's not only validating functionality and error-free operation, he's also managing risk due to bugs or vulnerabilities.  
From this insight, we can start to see that just about everything we do is either a direct risk management activity, or could affect the IT risk within the organization.  As stewards of our business technical infrastructure, we must be able to see this hierarchical relationship and our part in contributing to the overall risk posture of the organization.  We are entrusted with a particular responsibility within the IT function - we must be sure we always keep the effort to minimize risks as a core part of our job, no matter what IT function we do.  This effort, if taken to heart as a critical component of our activity, allows the business to have confidence in the technology platform upon which they can grow the business and continue to strive toward fulfilling the mission of the organization.
Whether you know it or not, you help to hold up that IT risk management umbrella.  Make sure you always have a good grip in understanding your part - your business counts on it to protect itself against the rain.

Wednesday, January 14, 2015

What Condition Are You In?

The military and police are trained to be ready - their jobs inherently put them in circumstances which are dangerous.  But as we constantly see in the news, just going to the gas station can be dangerous today.  I see people all the time with their head in the clouds, their eyes on their smartphone - oblivious to their surroundings.  

A few years back, I knew someone who lived in a very upscale area of town.  His wife went to the gas station to fill up.  She was just filling up her tank - some guy in the next row of pumps came up behind her and shot her in the head.  He then went back in his car and shot himself.  She didn't do anything to him - he was just crazy and woke up that morning determined to die and take someone with him.  

We never know what the dangers are - all we can do is be prepared.  Preparedness isn't paranoia - it is just common sense.  We must know what is going on around us.  If we are at the gas station, we look around and see what everyone else is doing - do they have anything in their hands - are they getting something out of the trunk?  When we go inside the station to buy a soda, before we walk in we look through the windows.  Are the people inside acting normally?  Are the clerks acting normally?  Do they have their hands in the air?  Are people running?  Shouldn't you look before you go walking in, just in case?  Has there ever been a hold-up before?  How do you know there isn't one happening now?

As you're driving down the street, are you aware of the other vehicles around you?  Are the occupants of the vehicles acting normally?  Is there anything up ahead or coming up quickly behind of concern?  At the workplace, are you keeping an ear open for anything out of place?  Would you spot someone acting strange?  Workplace shootings are happening more frequently - have you thought about what you would do if that scenario manifested in your place of work?

As you can see, it is very important to be in a condition of relaxed preparedness and alertness, even as we're going about our mundane activities.  Depending on what neighborhood you're in or line of work, the risk of an attack or other danger is relatively low - however the impact is very high.  In risk management, we quantify risk in terms of likelihood and impact.  A tornado hitting your datacenter is a very low likelihood, however the impact of that event would be catastrophic.  Therefore companies plan for that contingency by building alternate sites, standing up standby servers and syncing their data to that disaster recovery facility.  The business understands that, even though it is highly unlikely that the event will occur, the impact to the business would so disastrous that they had better spend the money just in case.

We must think of ours and our family's safety in the same way.  The likelihood that you will walk into a hold-up in progress is very low.  The possibility that someone will invade your home is also pretty unlikely.  However if that should occur and you are not prepared, the risk to you and your family is dire.  It is vital that we understand the risk, and understand what we can do to be better prepared.

http://armeddefense.org/the-color-code-of-awareness
The military and police have a set of codes or conditions based on the mindset and level of preparedness.  They are color codes - Condition White is basically when your head is in the clouds - you are oblivious to your surroundings.  This is the condition most people are in all the time - if someone had a gun and began walking in your direction, you would never see them coming.  This is a very dangerous state to be in, however it's the most common mental condition.

Condition Yellow is a state of relaxed preparedness.  In Condition Yellow you are aware of your surroundings - you recognize that danger can arise at any time in any place - although it is highly unlikely you understand the impact such an event would be.  You watch everyone around you - you know what they are doing, you know what they have in their hands.  You are, almost subconsciously, looking for anything out of place or any activity that is abnormal for the place and time.  If you spot something that looks out of the ordinary, you are already one step ahead.  If that situation appears to be dangerous, you go into Condition Red.

Condition Red is a high suspicion of danger.  You see people in the gas station running - you spot someone pulling what looks like a rifle out of their trunk - you hear what sounded like a gunshot in your workplace or hear people screaming.  You go into a state of high alert - the hair on the back of your neck probably stands up - adrenaline begins pumping.  If unprepared, you will likely freeze and panic.  If prepared, you will do what you've trained yourself to do - picking up the phone to call 911, moving quickly to a safe location, exiting the building, stopping from going into the gas station, etc.  

Condition Black is confirmation of a threat - you see the active shooter in your workplace - you see the driver next to you pointing a gun.  All your training kicks in, or you are left unprepared and act from instinct and fear.  You will either die or you won't.  That depends both on luck and your state of alertness, preparedness and training.  The soldier and the police officer understand this - they have prepared for the worst and have a better chance of surviving.  There are many things we can do as well to be better prepared.

Think about the potential for danger as you go about your day - think about these mental states and conditions.  In future posts, I will go deeper into the things we can do to prepare - things we can do to train for possible threats in terms of your physical security and safety.  We don't have to walk around in a state of paranoia - we can operate in a way that allows us to be aware of our surroundings and potential dangers, and understand the things we can do if we find ourselves in Condition Red or Black.  Stay tuned!


Friday, April 18, 2014

Speaking of Mobile Security

I've been doing a fair amount of speaking about Mobile Security lately.  The audience has been financial operations - accounts payable and accounts receivable.  These folks are concerned with the evolution of mobile technology and how it is being progressively integrated into their operations.  They have found that the risks are pretty large, and no one seems to be paying attention to this.

We are racing headfirst into the mobile revolution, interweaving it into our everyday life.  I can check my bank account balance, transfer funds, make investment trades, take payments, even manage my company's finances all from a tablet device.  In healthcare, we have mobile apps which allow clinicians to check your chart, monitor your blood pressure, view x-rays, write prescriptions...  this increased mobility is a great thing - it adds productivity and mobility - but we have to balance the benefits with the risks.  In other words, we need to understand and control the risks as we continue to weave mobile technology into our world.

The risks of mobile technology are pretty scary.  I would bet that you have apps on your phone or iPad that have more permissions than you are aware of.  Most of the time, we install an app without checking the permissions.  It usually asks your permission to install and gives you a list of permissions you're giving the app.  But we don't really check those - we are in a hurry to get the benefits of the app!  But the rights you're giving this app may be excessive.  Do you want Angry Birds to be able to delete data off your iPad?  Do you want your fitness app to be able to read your contact list?  Do you want your travel app to be able to send emails in your name?  Can they do that now?  You had better check!

I will try to write more frequently - I'm going to do a series on Mobile Security, since that seems to be a really hot issue at the moment.  I just added a Speaking tab to the blog - you can check out where I've been speaking and also let me know if you'd like to have me out to speak at an event.  


Wednesday, December 26, 2012

Maintain the Combat Stance

Miyamoto Musashi was a great Samurai - born in 1584, he lived in the prime age of the Samurai warrior class.  Musashi was a ronin, a master-less warrior, who wandered the country, trained, fought other warriors and was undefeated in over 60 duels.  

In his old age, Musashi retired to the hills as some Samurai were known to do, and composed poetry and other works of literature and art.  Musashi had mastered the art of combat - he composed a book called "The Book of Five Rings" - it is a treatise on combat.  The book is widely admired today in both martial arts circles and in business, as a way to know your enemy and improve your own tactics and strategy in war.

In this book, Musashi writes "The Way is in training. Become acquainted with every art." - This wise advice applies directly to our mission in Information Security.  We are faced with the constant threat of attack, just as Musashi was while walking the Japanese countryside.  Musashi advises us to know our enemy - know his skill.  Understand the threats.  

When I was studying for my CISSP, I had to either learn or become reacquainted with ten domains of information security.  Even though I may not use it on a daily basis, the CISSP exam would test me on my knowledge and understanding of all areas - I didn't need to be an expert but I needed to be acquainted with every art.  

Musashi lived a life of constant training - working to improve his physical skill and mental preparedness.  He learned to assess the opponent's skill and capabilities - in security we also must learn about the risks.  We scan for any vulnerabilities, we strive to understand the threats which might exploit those vulnerabilities, and we look for ways to plug those holes, remediate those risks - like Musashi we constantly try to improve, training and educating ourselves to the potential dangers to our data and learning to battle the attackers.

We must seek to constantly improve our skills and our defenses - tighten up our security while also increasing our ability to be alerted for anything which might be out of the ordinary. We never know how small of a clue we will get, if any at all, that an attack is coming.  We must learn the tools and tricks of our opponents so that we may understand what we need to defend against.  And we must use strategy to drive our stance - as Musashi also writes - "In all forms of strategy, it is necessary to maintain the combat stance in everyday life and to make your everyday stance your combat stance. You must research this well."

Musashi's words are very appropriate for us - how do we maintain the combat stance in our networks?  And what does he mean by - make your everyday stance your combat stance?  If we understand the threats and prepare our defenses well, we maintain a combat stance, ready to repel any attackers or be notified of a battle underway.  We must have our plan in place and ready to go - our security operations should be buzzing and our incident response program will be standing by.

Just don't go running out of your office with a headband, a samurai sword, yelling "BANZAI"!!!  HR would probably frown on that.

Monday, December 3, 2012

Risky Business

In the broad spectrum of activities which might be called Information Security, we must always first and foremost implement, execute and follow through with risk management.  Risk management is the backbone or foundation of any good information security program.

Risk management is really just going around, taking a look at the way things are set up, processes, policies, from what ports are open on the firewall to what rules are set on your antivirus client.  Risk management is a process of inventorying the existence or state of things, reviewing all this against your knowledge, expertise, research and maybe even some tools, to determine if we're doing things the right way or not.

Even if we're going along with best practices, we must understand that we still have some risk.  There is no such thing as 100% security  - the best practice in the world doesn't remove all risk - unless we want to unplug our infrastructures from the public Internet and never allow anyone to access anything.  This scenario basically shuts down our business - that means we must balance risk management with running the business.  This caveat should be posted on every security professional's desk to review constantly, as they attempt to implement or manage security controls.

We must define our existing controls and determine the gaps - then we define the present risk for it all.  Once this is done, we can begin to prioritize that risk - figure out strategies to reduce risk based on the priority or criticality of the asset or data or service or other resource we're trying to protect.  We can close unnecessary ports, change our A/V policy to restrict more, add language to our policies - we find ways to reduce that risk through the controls we have or the controls we implement based on our risk assessments and determination.

This strategy isn't new - I didn't invent it.  But in my experience many organizations have never heard of risk management, at least from an IT perspective.  We don't have to go down the rat hole and hire an accountant to calculate the ARO or SLE, but we should be familiar with these terms - with what they represent.  This makes us more prepared, so that when we identify a risk and need to implement a control, we can intelligently discuss the problem in terms the business understands - dollars.  

We learn to protect the business, not because we know how to SSH into a firewall and set up an access control list, but by providing expert counsel, by understanding what the business is trying to accomplish, by understanding the risks inherent in technology, and by offering wise solutions based on actual, prioritized risk and not Fear, Uncertainty and Doubt (FUD).  

If we can build our security programs upon a foundation of proper Risk Management, we have the groundwork for policy, process, technology - we can build teams dedicated to the correct task and eliminate or minimize time wasted on non-essential activity.  We can operate our security program as a function of risk management - prioritized to be laser-focused on the most critical maintaining a low risk profile for the organization's IT infrastructure.  

When I talk to many information security people about Risk Management, I see the deer in the headlights.  As an industry we must be able to walk in both worlds, technology and business.  Risk management is a language understood and appropriate for both.