Showing posts with label Security Awareness. Show all posts
Showing posts with label Security Awareness. Show all posts

Wednesday, January 14, 2015

What Condition Are You In?

The military and police are trained to be ready - their jobs inherently put them in circumstances which are dangerous.  But as we constantly see in the news, just going to the gas station can be dangerous today.  I see people all the time with their head in the clouds, their eyes on their smartphone - oblivious to their surroundings.  

A few years back, I knew someone who lived in a very upscale area of town.  His wife went to the gas station to fill up.  She was just filling up her tank - some guy in the next row of pumps came up behind her and shot her in the head.  He then went back in his car and shot himself.  She didn't do anything to him - he was just crazy and woke up that morning determined to die and take someone with him.  

We never know what the dangers are - all we can do is be prepared.  Preparedness isn't paranoia - it is just common sense.  We must know what is going on around us.  If we are at the gas station, we look around and see what everyone else is doing - do they have anything in their hands - are they getting something out of the trunk?  When we go inside the station to buy a soda, before we walk in we look through the windows.  Are the people inside acting normally?  Are the clerks acting normally?  Do they have their hands in the air?  Are people running?  Shouldn't you look before you go walking in, just in case?  Has there ever been a hold-up before?  How do you know there isn't one happening now?

As you're driving down the street, are you aware of the other vehicles around you?  Are the occupants of the vehicles acting normally?  Is there anything up ahead or coming up quickly behind of concern?  At the workplace, are you keeping an ear open for anything out of place?  Would you spot someone acting strange?  Workplace shootings are happening more frequently - have you thought about what you would do if that scenario manifested in your place of work?

As you can see, it is very important to be in a condition of relaxed preparedness and alertness, even as we're going about our mundane activities.  Depending on what neighborhood you're in or line of work, the risk of an attack or other danger is relatively low - however the impact is very high.  In risk management, we quantify risk in terms of likelihood and impact.  A tornado hitting your datacenter is a very low likelihood, however the impact of that event would be catastrophic.  Therefore companies plan for that contingency by building alternate sites, standing up standby servers and syncing their data to that disaster recovery facility.  The business understands that, even though it is highly unlikely that the event will occur, the impact to the business would so disastrous that they had better spend the money just in case.

We must think of ours and our family's safety in the same way.  The likelihood that you will walk into a hold-up in progress is very low.  The possibility that someone will invade your home is also pretty unlikely.  However if that should occur and you are not prepared, the risk to you and your family is dire.  It is vital that we understand the risk, and understand what we can do to be better prepared.

http://armeddefense.org/the-color-code-of-awareness
The military and police have a set of codes or conditions based on the mindset and level of preparedness.  They are color codes - Condition White is basically when your head is in the clouds - you are oblivious to your surroundings.  This is the condition most people are in all the time - if someone had a gun and began walking in your direction, you would never see them coming.  This is a very dangerous state to be in, however it's the most common mental condition.

Condition Yellow is a state of relaxed preparedness.  In Condition Yellow you are aware of your surroundings - you recognize that danger can arise at any time in any place - although it is highly unlikely you understand the impact such an event would be.  You watch everyone around you - you know what they are doing, you know what they have in their hands.  You are, almost subconsciously, looking for anything out of place or any activity that is abnormal for the place and time.  If you spot something that looks out of the ordinary, you are already one step ahead.  If that situation appears to be dangerous, you go into Condition Red.

Condition Red is a high suspicion of danger.  You see people in the gas station running - you spot someone pulling what looks like a rifle out of their trunk - you hear what sounded like a gunshot in your workplace or hear people screaming.  You go into a state of high alert - the hair on the back of your neck probably stands up - adrenaline begins pumping.  If unprepared, you will likely freeze and panic.  If prepared, you will do what you've trained yourself to do - picking up the phone to call 911, moving quickly to a safe location, exiting the building, stopping from going into the gas station, etc.  

Condition Black is confirmation of a threat - you see the active shooter in your workplace - you see the driver next to you pointing a gun.  All your training kicks in, or you are left unprepared and act from instinct and fear.  You will either die or you won't.  That depends both on luck and your state of alertness, preparedness and training.  The soldier and the police officer understand this - they have prepared for the worst and have a better chance of surviving.  There are many things we can do as well to be better prepared.

Think about the potential for danger as you go about your day - think about these mental states and conditions.  In future posts, I will go deeper into the things we can do to prepare - things we can do to train for possible threats in terms of your physical security and safety.  We don't have to walk around in a state of paranoia - we can operate in a way that allows us to be aware of our surroundings and potential dangers, and understand the things we can do if we find ourselves in Condition Red or Black.  Stay tuned!


Wednesday, September 3, 2014

Guarding the Castle

Our network is our castle - we can never become complacent when trusted to protect our corporate assets, customer data or sensitive information.  All too often, we find ourselves asleep at the wheel, relying on all the security controls and processes we have implemented.  We must have a strong monitoring and auditing function built into our Information Security program.  Heathens are in the woods, watching our every move, waiting for the chance to storm the castle, slipping through a crack or blowing down the main gate, to invade, loot and pillage.

You have passed out administrative credentials to many employees.  How do you know those employees are not deviating from the expected and approved tasks?  This deviation could be malicious, or it could simply be a mistake.  Either way we face many risks when we allow employees to operate as an administrator on any system - we must have some oversight in place to detect and report on anomalous activity.  

How do you know your webserver is not under attack, right this very instant?  Webservers are notorious for being a primary target of attack while also being one area we find with the weakest security controls.  What if someone dropped some malicious code on your Linux webserver?  How would you know?

I suggest that, along with requirements definition around that latest firewall or antivirus platform, the coolest new email security product or the best-rated web filter, we include security monitoring, some form of configuration change detection, and the ability to capture, consolidate and filter logs from all our devices.  Many ways exist to do this properly, instead of just plugging in that shiny new firewall and then going back to sleep, we must remain diligent and on-guard - part of that is proper monitoring and mechanisms in place to quickly detect potential attacks.

If we utilize a Security Information and Event Monitoring solution, we can employ resources to review these logs, respond to alerts, and have some chance of catching an attack in progress, before it becomes a major emergency.  Those teams should be trained to know exactly what is suspicious and what is just noise.  The secops teams should be good enough to quickly scan the logs and anything out of place will catch their eye.  

In addition to active monitoring and review of logs, we must capture our configurations, whether that's a web server or a router, and then detect when that configuration has changed.  I've been in companies where they haven't made any updates or checked the configuration for years.  There are mechanisms or scripts you can write that will take a hash of the configuration of the router or the web server /var/www once a day.  The script does a compare of the hash from one day to the next.  If the hash value changes, something has changed in your config, or something has been modified in your web server.  

Once we've detected a change, we can inquire as to whether there was an approved change within the last 24 hours.  If there was, then the alert is simply a confirmation.  If there was no approved change, we must find out if an unapproved change was made, or if we've been compromised.  If the admin just forgot to send in a change control and added a line to the .conf file, then we just remind him of the policy and move on.  If no one knows of any internal change, we must suspect that we've been compromised in some way.  We must now go into Incident Response mode and try to find out what was changed and what that means.  From there, if we were compromised, we can quickly find it and kick them out of our server or our router.

Maintaining a secure network isn't rocket science but it does require expertise and diligence.  We must ensure we have the right tools, the right processes, and the right expertise to utilize those tools to the greatest effect.  The Information Security professional needs to understand how a router works, what a config looks like, what goes in the /var/www folder, how a Perl script works.  We must be able to quickly review logs and know what is normal and what is not.  It takes a while to get up to speed on all this, however your employer trusts that, in giving you the keys to the kingdom, that you have all the ports and moats covered properly.

Friday, April 18, 2014

Speaking of Mobile Security

I've been doing a fair amount of speaking about Mobile Security lately.  The audience has been financial operations - accounts payable and accounts receivable.  These folks are concerned with the evolution of mobile technology and how it is being progressively integrated into their operations.  They have found that the risks are pretty large, and no one seems to be paying attention to this.

We are racing headfirst into the mobile revolution, interweaving it into our everyday life.  I can check my bank account balance, transfer funds, make investment trades, take payments, even manage my company's finances all from a tablet device.  In healthcare, we have mobile apps which allow clinicians to check your chart, monitor your blood pressure, view x-rays, write prescriptions...  this increased mobility is a great thing - it adds productivity and mobility - but we have to balance the benefits with the risks.  In other words, we need to understand and control the risks as we continue to weave mobile technology into our world.

The risks of mobile technology are pretty scary.  I would bet that you have apps on your phone or iPad that have more permissions than you are aware of.  Most of the time, we install an app without checking the permissions.  It usually asks your permission to install and gives you a list of permissions you're giving the app.  But we don't really check those - we are in a hurry to get the benefits of the app!  But the rights you're giving this app may be excessive.  Do you want Angry Birds to be able to delete data off your iPad?  Do you want your fitness app to be able to read your contact list?  Do you want your travel app to be able to send emails in your name?  Can they do that now?  You had better check!

I will try to write more frequently - I'm going to do a series on Mobile Security, since that seems to be a really hot issue at the moment.  I just added a Speaking tab to the blog - you can check out where I've been speaking and also let me know if you'd like to have me out to speak at an event.  


Wednesday, December 26, 2012

Maintain the Combat Stance

Miyamoto Musashi was a great Samurai - born in 1584, he lived in the prime age of the Samurai warrior class.  Musashi was a ronin, a master-less warrior, who wandered the country, trained, fought other warriors and was undefeated in over 60 duels.  

In his old age, Musashi retired to the hills as some Samurai were known to do, and composed poetry and other works of literature and art.  Musashi had mastered the art of combat - he composed a book called "The Book of Five Rings" - it is a treatise on combat.  The book is widely admired today in both martial arts circles and in business, as a way to know your enemy and improve your own tactics and strategy in war.

In this book, Musashi writes "The Way is in training. Become acquainted with every art." - This wise advice applies directly to our mission in Information Security.  We are faced with the constant threat of attack, just as Musashi was while walking the Japanese countryside.  Musashi advises us to know our enemy - know his skill.  Understand the threats.  

When I was studying for my CISSP, I had to either learn or become reacquainted with ten domains of information security.  Even though I may not use it on a daily basis, the CISSP exam would test me on my knowledge and understanding of all areas - I didn't need to be an expert but I needed to be acquainted with every art.  

Musashi lived a life of constant training - working to improve his physical skill and mental preparedness.  He learned to assess the opponent's skill and capabilities - in security we also must learn about the risks.  We scan for any vulnerabilities, we strive to understand the threats which might exploit those vulnerabilities, and we look for ways to plug those holes, remediate those risks - like Musashi we constantly try to improve, training and educating ourselves to the potential dangers to our data and learning to battle the attackers.

We must seek to constantly improve our skills and our defenses - tighten up our security while also increasing our ability to be alerted for anything which might be out of the ordinary. We never know how small of a clue we will get, if any at all, that an attack is coming.  We must learn the tools and tricks of our opponents so that we may understand what we need to defend against.  And we must use strategy to drive our stance - as Musashi also writes - "In all forms of strategy, it is necessary to maintain the combat stance in everyday life and to make your everyday stance your combat stance. You must research this well."

Musashi's words are very appropriate for us - how do we maintain the combat stance in our networks?  And what does he mean by - make your everyday stance your combat stance?  If we understand the threats and prepare our defenses well, we maintain a combat stance, ready to repel any attackers or be notified of a battle underway.  We must have our plan in place and ready to go - our security operations should be buzzing and our incident response program will be standing by.

Just don't go running out of your office with a headband, a samurai sword, yelling "BANZAI"!!!  HR would probably frown on that.

Monday, December 17, 2012

All Aboard

Years ago, I worked for a large Fortune 500 healthcare company.  Obviously this company was concerned about it's requirements under HIPAA - at the time cell phones were being used but they were not the same as today.  Some had cameras, but many phones were simple flip phones without cameras.  Because a camera is a way in which you can gather, capture and move data, the company was rightly concerned about the new "camera-phones" and instituted a policy restricting their use and/or possession on company grounds.

Can you imagine what the compliance rate would be on that policy today?  I'm not certain you can purchase a new phone today without a camera.  We may have to revert to the vintage electronics section of eBay to find such a dinosaur of technology.  In today's healthcare environment, you have every single employee, from the doctor to the janitor, carrying not only one smart device, complete with camera, WIFI and the capability to instantly post the latest thought or photograph to Facebook, but it's likely some of these people have an iPad, some other tablet or small form factor laptop in their shirt pocket.  

We can no longer dictate that no one have these devices.  We have no effective administrative control that we can use to limit or restrict the presence of these devices - policies prohibiting something which has become woven into the very fabric of our culture would only be ignored.  It's like prohibiting them from bringing in their shoes or wallet.  The key point here -  a large risk has become assimilated into the culture, so much so that we've crossed the point of prohibition.  We only stand in front of this fast-moving train at our peril.  If we are to be effective, we must learn how to jump on board this thing as it's moving and at least find some room in the driver's car to figure out a way of putting some controls in place.

As with anything else, our usual template of Information Security will suffice - we need a well-conceived set of administrative and technical controls - our policy, while still acknowledging that every living creature on the planet is organically attached to a smart device, must dictate that the user will follow the policy at risk of termination and permanent smart-phone-ectomy.  This policy sets the table firmly for other controls - but why is this piece so important?

I have a tool that I am permanently attached to, that I take home with me, I use in the car, in the bathroom, it's my alarm clock, the way I check the news and the weather, the way I talk to my 14-year old, the thing that tells me when my favorite cigar goes on sale and lets me take notes or dictate.  This list really can go on forever - just look through the app store and you'll find just about anything to meet your needs and help you make your day more efficient.

Because of the fact that this device is our constant companion, we tend to be more lax with it - we don't treat it like a work device.  So we must force users to understand the importance of turning on their brains with respect to using the device.  We must educate users on the risk of using the device and their responsibility to use it wisely.  And we must put in some common sense controls which, while not prohibiting the usage of these devices, controls exactly what we want to control.

Today's solution to this problem is mobile security- some tool or agent which is installed on the device and phones home - the console can force a passcode (which means forcing encryption of the device), it can alert on devices which are out of compliance, let me know when the devices moves from place to place.  It's a happy compromise - I can't prohibit it but I can restrict certain things and wipe the device if it's lost or stolen.  I can force the thing to encrypt the data.  And I can "sort-of" disable the device's camera.

As a security guy in charge of infosec for a hospital, that's really what I care most about.  We cannot stop the train of mobile devices - we have to learn to get on-board and help steer away from our most critical asset - patient data.

Wednesday, August 1, 2012

Mind Your Data

As I sit and ponder what else to write about, it dawns on me that we are living in a world of technology.  If we look around our life, we would be hard-pressed to find an area that isn't affected by technology.  Technology has become so interwoven into the fabric of our lives that we hardly notice it any longer.

Consider your house - you probably make sure your doors and windows are locked.  You might have installed an alarm system to alert if a burglary or fire is happening.  You may own a firearm with the purpose of protecting your family in the event of emergency.  You install fire detectors in each room, and you may own a dog for both companionship and for it's deterrent value.

We also take similar precautions, if we're smart, outside of the home.  We generally lock our vehicle to prevent or deter theft.  We may have learned to keep our keys in our hands while we walk to the car, especially at night.  We are familiar with the fire exits at work, and we likely go through multiple security protocols throughout our day, from toll roads to access badges to locks on our desks.

The problem, I believe, is in the proliferation of technology in our lives.  We always have our cell phone on our belt, in our pocket or in a purse.  We might carry a laptop or tablet - we certainly have a PC at home and likely utilize one at work.  Our TV can now access the Internet, and even our fitness machines and refrigerators soon will be connected to the "Net".  This connectivity is very convenient but I think we have become unaware of the risks.

Any of these devices, connected to a network or the Internet, could present your personal information in ways you are not aware of.  Your credit card information, social security number, and a host of other interesting and useful bits of information could be seeping out the cracks in your technological collection.  There are many ways of helping to reduce the risk, however most people aren't even aware of the risks, not to mention the ways of reducing that risk.

It is imperative that we, as technology consumers and users, become aware of just how much of our personal information we're sharing, how much we're letting leak out.  It's fine if you know about it and are fine with sharing it.  The real concern happens when you don't know.  The number of Information Security professionals, sites, and books available is vast - make sure you are taking advantage of these resources, learning just what the risks are, and taking the necessary steps to help minimize the risks to your personal information, finances, health records, and anything else you wouldn't want to share with the world.

You lock your door each night - make sure you have a lock on your data also.