Saturday, March 27, 2010

iSEC recommendations following the Aurora attack on Google

I finally found some time to read the iSEC Partners recommendations about the attacks on Google and other companies, originated in China, in January this year.

This post is just to underline the very good reading it is for people in IT. I like it because:
  • It does not look for a silver bullet but lists several points that need be addressed.
  • It points out, as so many posts on this blog, that you first need to human understand and monitor what you do, before implementing costly solutions.
  • It also points out that you need to work on the security of the endpoints (users' machines), especially on updating regularly client software.
Well, just go and read it, it's six page long.

Wednesday, March 24, 2010

Tuesday, March 23, 2010

What is a CISO? [2/2]

Security is not about putting an appliance somewhere into the network, it's about mastering what you do. It means strictness, control, review, enhancement. That's not what the typical IT guy wants to do everyday. He wants to serve users with the lowest amount of personal work, which at first glance means without security. That's why security may primarily look like a constraint.

But it's not. Security is not only a constraint, it's an enabling mechanism. When you have good security you can do more things. A simple illustration is that you can drive very fast on a motorway because you have good brakes. If you didn't have them, you'd never allow yourself to drive faster than 60mph.

So, when I talk about giving staff a sense that security is not only a constraint, I mean underlining to them how much you can achieve with security that you couldn't without. Let me draw a few examples from live situations I've seen in companies or heard about on the Internet:
  • When you have precise inventory management over computers and printers, you may be able to recharge other services more equitably.
  • When you have a precise 1 identity for 1 account policy, strictly implemented, you may go one step further by implementing an SSO.
  • When you are able to tweak and audit the work of your contractors for remote maintenance, you may be more willing to ask for remote maintenance.
  • When you have backup systems, up to the task, for all of your main services, you can grant your admins an additional week off.
  • On the same level, when you don't spend hours running after viruses, you can spend those hours on implementing new things.
  • When you have a solid web proxy and a sound policy for it, you can grant Internet access to more employees.
  • When you have an automated RBAC system, you can ensure users are served in a shorter time at their arrival in the company.

The thing is, security guys know this way of thinking about security but they most often communicate around obligations, constraints and legal requirements. That's why it looks as if security is a constraint. (Think about Dilbert's preventer, Mordac!)

(
That way of thinking is something I didn't see in Bruce Schneier's book Beyond Fear, however interesting that book is. (See Scott Granneman's notes about the book.) Bruce suggests a five step method to assess the value of a security measure:
  1. What assets are you trying to protect?
  2. What are the risks to those assets?
  3. How well does the security solution mitigate those risks?
  4. What other risks does the security solution cause?
  5. What costs and trade-offs does the security solution impose?
But Bruce forgets about number 6: What do you get with that security measure besides protecting the assets?
That's why I think his view about a national ID card is flawed. When you live in a country with a national ID card as I do, you see that it allows businesses starting from the smallest shop to have a good idea about the identity of buyers, in case they would not pay. Sure the ID card is not impossible to fake, it's simply too hard for the passer-by
to fake.
)

Thursday, February 25, 2010

What is a CISO? [1/2]

What is a CISO? Saperlotte ! [in French in the original text, ed.]
People have tough questions sometimes. Or rather tough Google searches, as it seems that people often stumble across this blog when asking Google for an answer to this question.

CISO, Chief Information Security Officer, is a management and leadership position that often reports to the CIO or to the CEO. There are also CISO positions that report to the CSO, to the CCO or to the CQO. Even sometimes to the CFO. That's merely a hierarchical view of the question because, most of the time, the CISO has to work with all of these people and reports to several of them depending on the occasion. As a summary, the CISO is a C-level who reports to C-levels...

He's a manager because he handles projects, teams, planning and budgets. He's a leader because he needs to get things done that are of primary importance only to him. Said otherwise, most people in an organization can get very successful at their work without ever reading a security policy, let alone understand it, let alone help enforce it. So the CISO has to play his cards with some subtlety and some charisma to achieve results.

He's in charge of multiple things, but I summarize it this way:
  • Integrity of data in the information system,
  • Availability of services provided by the information system,
  • Availability of IT services provided by external partners,
  • Confidentiality of exchanges,
  • Elimination of recurrent problems to decrease operational costs,
  • Durability of services provided by the information system, in provision for changes in technologies or business needs,
  • Conformity of IT practices with legal constraints.

The CISO has to write corporate policies and directions that support the previous goals, that need be approved by the board of directors. One hard part (for any C-level, I should say) is to propose long-term, innovative yet efficient, realistic, goals. And to communicate around it, because such documents are definitely not written to remain on a shelf.

The CISO has to deal with a number of "typical" phenomena about security questions, that happen in all organizations. Different CISOs react differently. Examples of such facts are:
  • Irrational fears and sudden irrational fears,
  • FUD used by vendors of security products,
  • What I call the "TV effect", with the words of the presenter having more influence on the final user than those of the CISO,
  • Over-enthusiastic users or managers,
  • "Security theatre", the use of illusions that give users a false feeling of security, very common in security products,
  • What I call the "side effect of security theatre", when users and, worse, managers ask for more security theatre because it feels great,
  • The 3rd of Clarke's laws, "any sufficiently advanced technology is indistinguishable from magic", which clearly applies to ITsec, which means that most people simply believe you're doing magic,
  • Managers rarely believing in magic as a profitable corporate asset,
  • Legal department of most organizations having no skill regarding IT laws[...]
Next article on insight, philosophy and giving staff a sense that security is not only a constraint.

Note: If you're any surprised that I wrote "he" and never "she", that's because I never met a woman in this position. But I'd be pleased to.

Sunday, February 21, 2010

The US destroying the Internet?

Every now and then I read or watch a scenario about the US destroying or dramatically altering the Internet, for security purposes or for commercial purposes. For me, even if that were feasible, that would be silly and I think that's never going to happen.
If the US were to destroy or reduce the availability of the Internet, others would rebuild it, anew, differently.
  1. The US would get a considerable loss of earnings from a worldwide project probably not developed in English (Chinese?), not developed by American companies.
  2. They would lose their technical skills. New skills would be required for the new technologies of the new network.
  3. They would lose the target of their current spying methods, quickly moving to the new network.
  4. They would not be able to create such spying methods for the new network, because they would not be the primary actor, centralizing infrastructure, skills and budget.

Saturday, February 20, 2010

RSS feeds for IT and ITsec

In bold characters those that I actually enjoy reading each and every time.

Security:

"General" IT:

Friends:

I also have my own feed Assaults on the Internet neutrality [*] gathering articles from all that I read on the web about governments and ISPs messing with the neutrality of the Internet.

Security predictions for 2010 and a few wishes

As usual, nothing posted on this blog is related to my job at my employer. These are merely thoughts gathered from readings on the web and personal considerations.

(If you're wondering why I didn't post this in January, think that holidays spent in Sicily, Romania, Hungary and Serbia are worth being late. I really love the Carpathians.)
  1. Linux systems will become an interesting target for hackers because of Google's OS.
    The free software community will react fast to vulnerabilities. If Google is up to the task, they will integrate the changes very fast and it will result in Linux systems being the most secure. Competitors will finally be forced to take vulnerabilities more seriously. That's the optimist hypothesis. The pessimist one is Google not being interested in building better security and not reacting faster than the others.
  2. Microsoft will (finally!) propose a centralized software installation and update manager, quickly adopted by the big software companies, reducing the number of heterogeneous installation modes, late updates and so on. Something apt-like, in a Microsoft-way, of course.
    It's either this or Microsoft platforms will be progressively abandoned for integrated products such as iPhone or platforms with that functionality such as Linux (servers) or Mac OSX (clients).
  3. Viruses will spread to Mac and iPhones up to the same level as that under Windows.
  4. Generalization of new authentication modes including smart cards with microchips, user/machine certificates, fingerprints on laptops, will happen.
    There will be a fashion for it and a lot of blunders will be made in the beginning.
  5. There will be reports about IT services clouding the wrong parts of themselves: critical infrastructure, already very profitable services, legally protected information...
  6. There will be an overflow of non-browser software using SSL.
    Each of them has its own libraries and each blunder or vulnerability in the use of SSL will have to be addressed in each of these libraries. This is not addressable in a correct time. For this reason, there will be new products or services around gathering all this SSL traffic and forwarding it in an actually secure way.
  7. Social harvesting will rise to unprecedented peaks. Because of poor legal harmonization (or even concern, for that matter!) in various countries, automated social harvesting services will be made available.
  8. Governments from developed countries will try to censor, filter and/or index the web. They will fail for two major reasons:
    • The web is too huge for any current government to master it, or even understand it.
    • The free software community will sidestep any technical measure towards censorship.
  9. There will be stories, news, rumours, about Google having connections with the US intelligence agencies. Google's business is a source of information just too much important nowadays for intelligence agencies to neglect it. I won't tempt any prediction about Google's reactions.
  10. PCI DSS-like standards (simple checklist, minimalist, technical, yet very efficient) will be published about various matters of ITsec. Or maybe I just read too many people interested in that.

And now a few wishes:
  • That people stop thinking I work on viruses when I say I work on ITsec.
  • That IT managers (non-security) stop thinking there is a fixed list of requirements for security and each of them requires purchasing a "security product" and each of these products works standalone.
  • That service managers start budgeting time for service reviews and corrections, not only service implementations.
  • That Adobe distinguishes between PDF designed for review and printing and PDF designed for automated administrative tasks in complex forms. This may prevent a lot of problems to come.
  • That my government stops being such a liberty killer about IT.
  • [...]
  • That my readers consider the strange situation of using an Excel-controlled Visual Basic script to interact with an AS/400 terminal emulator, written in Java, inside a Citrix session running on a Windows Server "cluster" inside a VMware architecture. (You can have screenshots and photos of the AS/400 on IBM's website, for instance, there.) That was my only nightmare these last years. Does virtualization never end?