Please share your comments; critics make life meaningful!

Thursday, March 19, 2015

INFORMATION SECURITY STRATEGY AND MEASURING ITS EFFECTIVENESS THROUGH SECURITY METRICS

 
Introduction:
Enterprises have learnt to give Information Security (IS) the wide berth it deserves. However, the realization has not come any sooner. It has perhaps been accorded a little later in the day than it ought to have been. However, there is still the opportunity to make good the delay by adopting a pro-active and holistic approach while creating, maintaining and augmenting an Enterprise Information Security (EIS) program.  Key aspects of such a program are:
·         Formulating a customised EIS strategy and road map.
·         Its effective implementation in an integrated manner.
·         Measuring effectiveness through customised EIS metrics.
 
Plethora of technology platforms, voluminous processes and significant numbers of people are available and deployed in implementation of security programs in enterprises, while scant attention is paid to the other two elements of the spectrum. This paper focusses on the latter.
 
Security strategy and metrics go hand in hand, and both are very dynamic in nature owing to changing business requirements and threat landscape. Hence, there is a need to understand their dependence and symbiotic nature, from creation of the respective programs, to their execution and continuous improvement. It is also pertinent to note that EIS metrics is a facet of EIS strategy. Thus, although it is possible to create an EIS metrics program independently, it is best practised with an eye on the big picture and created as an indispensable part of a dynamic EIS strategy.
 
Why:
EIS strategy is of paramount importance to align the EIS program with enterprise business objectives and provide the necessary return on investments (RoI). In the absence of an EIS strategy, the program can flounder and would not be positioned to deliver the results that are expected of it; also there would be no accountability of the program, hence no productivity.
 
There are multiple reasons for measuring EIS metrics:
·         EIS metrics are vital to demonstrate EIS program effectiveness, provide accountability, justify past investments and seek future investments, and instil stakeholder confidence/assurance.
·         Federal agencies in US are mandated by a number of existing laws, and regulations such as Clinger-Cohen Act, Government Performance and Results Act (GPRA), Government Paperwork Elimination Act (GPEA), and Federal Information Security Management Act (FISMA) to undertake IT performance measurement in general, and IT security performance measurement in particular. IT Security metrics are a core component of EIS metrics.
·         Similar regulatory regimes are prevalent in most developed and developing economies globally.
  
How:
EIS strategy should be simple. It should take into account the industry sector, the size or revenue of the enterprise, its risk appetite, the business model and its unique business objectives or goals.
 
EIS metrics should be practical, standardised and scalable. They should evaluate security at the system level, and facilitate decision making as also aggregate all operational level metrics to produce dashboards at the enterprise level and business unit and/or geographical entity level. EIS metrics should also provide relevant trends over time; help track performance and direct resources to initiate performance improvement.
 
Development Process:
EIS strategy development process consists of following generic activities which would require to be customised for individual enterprises:
·         Enumeration of business objectives.
·         Identification of EIS drivers – Legal, Regulatory, Financial, Operational etc.
·         Stock taking of the current EIS program, if any.
·         Creation of a risk based and business aligned EIS program including:
o   IS Roles and responsibilities (both within IS as also outside of it)
o   IS Organization structure
o   IS Governance framework
o   IS Risk Assessment methodology and framework
o   IS Controls and Assessment framework
o   IS Architecture framework
o   IS Operations framework
o   Outline roadmap including major projects and initiatives
o   EIS Metrics framework
 
EIS metrics development process consists of following generic activities which would require to be customised for individual enterprises:
·         Definition/documentation of the current EIS program
·         Selection and development of metrics to measure implementation, efficiency, effectiveness, and impact of the EIS program
 
Detailed Considerations for EIS Strategy:
EIS strategy should be aligned to business strategy and corporate vision. It must leverage all existing strengths, tools, processes, people and frameworks of the enterprise. It should spell out the security organization structure, roles and responsibilities, catalogue of services provided, road map of security programs, projects, and initiatives, and define customised security policies/standards/procedures. It must work out the cross-functional collaboration framework and touch points with complimentary functions including Enterprise Risk Management, Compliance, Legal, BCP, DR, Privacy, Information Management, HR, IT Operations, and Physical Security etc.
 
Detailed Considerations for EIS Metrics:
EIS metrics should reflect security program maturity (status of all programs, projects, and initiatives) as also security control effectiveness (compliance to policies, standards and procedures). Both data types should be processed through a customized framework aligned to the risk appetite of the organization and the results of such processing should be demonstrated through multiple dashboards configured around the needs of specific target audiences. Generally, 3 levels should suffice; however, it could be either re-appropriated to two levels in case of smaller enterprises with lesser consumers for such dashboards or increased to additional levels to provide higher levels of granularity in case of large and global enterprises with higher complexity.
 
While adopting a 3 level representation, the highest level should be an overall indicator. The next level should be indicative of the component sub-domains that security has been carved out into for the enterprise, and each sub-domain should get an appropriate weightage with the total adding up to 100%. The sub-domains should be broken down to one more level of metrics which can come from security technology platforms or security processes, and have varying weight contribution to the sub-domain they comprise of. These last level metrics are real data from systems and processes while the above two levels would be abstractions based on this data as per a framework customised for a specific company.
 
Some options for level 1 dashboard are:
·         3 colours (Red/Yellow/Green) or 5
·         % of score out of 100
·         Levels 1 to 3 (or 5)
 
Suggested components of level 2 dashboards are:
·         Governance
·         Risk
·         Compliance
·         Architecture
·         Operations
 
Suggested components of level 3 dashboard with types of operational metrics for each are:
·         Asset Management metrics
·         Communication Security Metrics
·         Perimeter Security Metrics
·         End Point Security Metrics
·         Application Security metrics
·         Identity & Access Management metrics
·         Access Control metrics
·         Vulnerability Management metrics
·         Patch Management metrics
·         Malware Management metrics
·         Change Management metrics
·         Incident Management metrics
·         Business Continuity and Disaster Recovery metrics
 
Each of the suggested operational metrics domains comprise of multiple metrics elements and each applicable element need to be customised for a specific enterprise. Also, the list above does not cater to GRC metrics which need to be configured for an enterprise in a customised manner based on its EIS strategy and implementation roadmap.
 
Conclusion:
The above considerations are not sacrosanct or sequential. Rather, they provide a framework for envisioning EIS metrics, and their appropriate customization for a specific enterprise. The type of operational metrics depends on the status of enterprise processes and supporting technology platforms, as also evolution of the EIS program and its stage in the maturity life cycle.
 

Wednesday, January 28, 2015

WEF framework on Quantification of Cyber Threats

The World Economic Forum (WEF) proposed framework can be said to be a move in the right direction, albeit it stops short of being readily implementable.
 
After having a good look at the framework, here are some findings/observations:

1. The framework speaks of cyberrisk measurement akin to a financial risk measurement concept called 'Value at Risk' or VaR. It may take some time for someone not used to financial risk management to grasp the concept of VaR - essentially it’s about probability of a specific amount of loss in a specifictimeframe.

2. But the report clarifies that it does not specify how to compute cyber risk; it says “It is important to note that in this report we specify properties that VaR should have, but not specifically how to compute it.”

3. So essentially, it refers to these three Components of Cyber VaR, but leaves the computation of cyber risk to individual enterprises:

(a) Vulnerabilities: Vulnerabilities in existing systems, effectiveness of patching them, and successful incidents/breaches that have happened

(b) Assets: Tangible (costs of business interruption, regulatory fees etc.) and intangible assets (costs of lost IP, reputation loss etc.)

(c) Profile of attacker: Type of adversaries (nation-state, hacker, amateur etc.), their level of sophistication, and their tactics/motivation

4. Summary assessment:

(a) The framework is not definitive as regards how exactly we would compute cyber risk from the components. However, it points out to some key areas where each of us responsible for cyber risk management in an enterprise/entity may not have not focussed at all or not made much progress:

(i) Vulnerability management: our vulnerability and patch management efforts should be formalized and standardized, and data from them should be incorporated into a cyber-risk dashboard

(ii) Asset mapping: our understanding of IT assets (applications + related infrastructure) and their business aligned criticality should be comprehensively documented through a business aligned Risk assessment
(iii) Attacker profiling:  we should deliberate on the specific types of adversaries who would target us their tactics/motivations and their level of sophistication
5. What I was hoping to find is a linkage of these threee (and perhaps other key aspects such as key business risks, existing effective controls) into a dashboard/score card which could be readily used to measure our respective posture and benchmark ourselves against peers in industry/region etc. The framework stops short of any such attempts; but I can understand the wisdom in that.

Saturday, January 24, 2015

A Risk Based perspective on PCI-DSS Compliance

Compliance regimes usually make us do a lot of work towards demonstrating effectiveness of controls without justifying the risk perspective of such activities. As risk based approaches to cyber security management have gained favour over a compliance based approach in this next phase of Information (or Cyber) Security maturity, we need to look at a risk based approach even for implementing compliance frameworks. This essay is about a risk based approach for PCI compliance.

PCI-DSS is a framework espoused by the PCI industry body to help processors of credit card data adopt equivalent control implementation to safeguard secure storage and transmission of such data.
about  have recently engaged a company called to assist us with a review of our use of credit cards across the company and determination of our compliance with PCI standards. PCI = payment card industry and are standards required to be followed when a company uses credit cards. These include things like segregation and storage of credit card numbers for example.

--has worked through a review of our systems and is now looking at unstructured data (i.e. mail, over the phone, online, etc) where credit card information may have been captured. I have identified you as business SME’s that may know how and where credits cards are processed. Below are the processes areas that I have identified. This list is by no means complete and -- is working to develop a complete list.


Over the next couple weeks, -- will be reaching out to each of you to set up a quick meeting to discuss. Please share with him any information you have on the use of credit cards so that he can appropriately capture and investigate this for the Group of companies (this includes what systems they are processed into so that -- can cross reference back to the work he has already performed). 
 

Saturday, December 6, 2014

‘Incident’ Based Approach to Information (Cyber) Security and the critical role of Digital Forensics

  
'Risk Based Approach' (RBA) has been the recommended way to address Information Security as per the initial standards on the subject - BS 25999 which was subsequently incorporated into ISO 27001. It has been also recommended as a foundational principle by most standards on Information Security which have emerged subsequently such as the ones put forth by ISF, COBIT etc. Although it has been so for a while, actual adoption of the risk based approach has been a rather recent phenomenon. There are many good reasons for it, the primary ones being the lack of apparent cost benefit from Information Security investments and the growing body of compliance mandates around the subject leading to a predominantly compliance approach becoming in vogue.
 
But with the predominance of crippling breaches despite significant compliance oriented investments and acknowledgement of Information Risk (more fancifully referred to as Cyber Risk in recent times) as top 5 risks to global corporations, understanding of Information Security in corporations and adoption of a risk based approach has rapidly gained favour. Such an approach follows a cyclic pattern as under:
· Risks inherent in an enterprise entity (service, process, asset etc.) are assessed by discerning the probability and frequency of various types of threats exploiting vulnerabilities inherent in the service/process/asset
· Effectiveness of existing controls is evaluated and residual risk is computed by subtracting the control effectiveness from the inherent risk
· Residual risks are mitigated through various measures - avoidance, transference, acceptance or mitigation
· Once some progress is made in risk mitigation, the cycle is repeated all over again starting with risk assessment.
 
A similar cyclic patterned but 'Incident based approach' (IBA) can be taken of Cyber Security wherein incident prevention is intended as the primary objective of the existing Cyber Security framework. Once an incident occurs, as it always does despite all preventive controls, incident triage is undertaken, followed by incident investigation, doing root cause analysis (RCA), taking corrective and preventive action (CAPA), and controls are enhanced by ploughing the learnings back into the incident prevention oriented Cyber Security framework.

In this 'Incident based approach' to Cyber Security, Digital Forensics plays an anchoring role at all the stages of the process:
· It is essential at the triage stage to have an idea of Digital Forensics to be able to preserve incident parameters while taking down infected/compromised systems and getting back essential systems and services.
· During incident investigation, Digital Forensics is of central relevance and paramount importance as investigation relies primarily relies on forensics.
· It can contribute in no small manner during CAPA and RCA.
· And finally, Digital Forensics can provide insights into designing more effective controls.
 
Even during the times when it appears to be business as usual, Digital Forensics has several contributions to make in setting up and running the day to day operations of Cyber Security apparatus. It needs to be taken into consideration while deciding the type of access that administrators have to systems as this can be a vital factor to having the capability to pick up the trail of a hacker who assumes administrative privilege or a malicious insider who mis-utilizes the same. Digital Forensics considerations are also very important while considering remote investigations on systems.
 
For a Cyber Security function, it may not always make sense to create a very highly developed internal capability on Digital Forensics. While a minimum and potent capability such as disk imaging, limited Network packet capture and mining of logs and other data etc. would be deemed appropriate/necessary, advanced capabilities such as forensic analysis of disk images, pattern & link analysis, heuristics analysis of suspect logs and other data etc. could be planned for being availed as outsourced services. Such services should be identified as appropriate for the specific industry/ business segment an enterprise belongs to, pre-configured as per the management or regulatory specifications/ expectations and contractually negotiated and sanctified, so that they can be availed without any loss of time and within pre-set SLAs after the occurrence of an incident which requires Digital Forensic investigation. Return on investment would be a key consideration while configuring the above and each enterprise would need to find its own balance with due consideration to its unique impacting factors. An optimum model comprising of limited essential in-house capability and bulk outsourced capability often finds greater acceptance from management and brings maximum benefits as it leverages competence of Digital Forensic specialists for the detailed forensics investigations.

Thursday, September 6, 2012

Security TCO

1. Enterprise security costs need to be budgeted under by one cost centre to enable an enterprise level understanding of security TCO. In the absence of a centralised and single security budget (just to clarify again - utilization is by multiple entities), there is no executive appraisal of security TCO and multiple stake holders continue to spend on security without the enterprise security objectives addressed on a risk based criteria.


2. While in reality it may be fragmented, there is a huge potential to group all security spends under following key heads:

(a) Core Security Platforms including all elements of security oversight such as SIEM, VA, PT, AppSec tools etc (preferably under operational control of the security team and managed through a SOC) and also few other core security platforms such as DLP, IPS, Web filter etc (which may be under operational control of network/IT operations)

(b) Supporting Security Platforms including all security platforms deployed in the enterprise for end point security, infrastructure security, platform security, application security, and physical security

(c) Security Processes, Projects and Initiatives including implementation/enhancements costs and consulting engagements involving both Core & Supporting security platforms, as also GRC, DR, audits/assessments, security awareness etc.

(d) Security People including salaries of all full/part time employees and contractors/consultants working within the security team

3. During the process of the challenging migration from current security budgeting practices to the one outlined above, it may be necessary to continue budgeting one or more of the above heads outside of the security budget. However, there should be an exercise to create an enterprise inventory of such items, consolidate the budget figures, and tabulate them at the security steering committee with a view to appraise executive management of security TCO and create support for the need to have centralised security budgeting.

Wednesday, February 8, 2012

Information Security & Privacy: Why should it make sense to Higher Defence Management?

Technology is at the core of modern business. In the last decade or so, Computer Security or Data Security has emerged from within the IT function as an important element with business critical and even strategic ramifications. The base element in this domain is the ubiquitous entity referred to as Data or Information, which can take all sorts of digital and physical forms; hence, the domain is standardised as Information Security (IS). This domain has become standardised over time and is guided by an broad international Standard ISO-27001. The direct business relevance of IS has emerged over the years as central to the viability or even existence of the very enterprise; hence it has created a leadership role which has come to be known as the Chief Information Security Officer (CISO). International standards, IT frameworks and several regulations have also sanctified the criticality of IS and thus made the role of CISO even more relevant and legitimate.

Privacy is a complementary domain to IS pertaining specifically to Sensitive Personal Data of individuals and other entities. The basic premise is to protect such personal data from inappropriate use with a view to limit it's exposure to mis-use as also protect the life and liberty of the entities concerned. Information is again at the heart of Privacy, but of more specific variety, i.e Personal and Sensitive. The executive who leads the Privacy function is usually referred to as a Privacy Officer or Chief Privacy Officer (CPO), but it is only so in very large enterprises. In most others, CISO looks at Privacy as well.

In India, IS & Privacy compliance had been almost non existent prior to 1990s. With opening of Indian markets and development of intimate global market connect, IS found it's place first in the BFSI sector and then in the IT/ITES sectors. Business and operational needs for security drove the next wave of IS-isation in India which saw home grown sectors like Telecom, Pharma, Manufacturing, Retail etc create IS teams, primarily to protect IP and safeguard operations. As regards Privacy, the very culture of India is not Privacy oriented. However, globalisation and emergence of India as a top technology (hence information) player, has led to India being force to play catch-up in this mostly European and American concept.

The current drive of IS and Privacy is mostly powered by regulations/laws as Indian Govt is carving out several laws/regulations with IS and Privacy intent and content in it's march to join the big league of powerful nations. However, all along IS and Privacy has not been treated as a core business need; rather as reactive measures to meet business realities (such as IT/ITES companies providing assurance to their international customers) or in response to high impact incidents (loss of business plan etc) or to comply with a law/regulation. While IS and Privacy think-tanks like ISACA, ISC2 and IAPPforecast the emergence of IS and Privacy as strategic functions and the move of CISO into the Corporate Boardroom, the scene in India is a little different with lack of clear management understanding of the business value of IS and it's strategic impact. There are also numerous other related/relevant functions (such as Risk Management, BCP, Privacy, Physical Security, Intellectual Property etc) some with different international standard for them which are vying for management attention and organisational acceptance. However, with landmark regulations in recent times, the domain has been highly energised and even transformed. Leading companies in almost all sectors (IT/ITES, BFSI, Telecom, Energy/Power/Infrastructure, Manufacturing etc) either already have a CISO or are in the process of getting one. And Indian subsidiaries of MNCs with international operations have started on-boarding Privacy Officers after the IT Act Privacy Rules were notified in April 2011.

Why is it important for higher defence management to know this? Security is a core competence of defence forces, However, they typically limit their connect with security to traditional domain of Physical Security which has reduced in relevance after the advent of the IT. The IT-isation of Govt sector has been sporadic and tangential due to several factors. And computer security (or data security or information security & privacy) which had initially not been a design prerogative even in the civilian technology world, was certainly not a high concern in the defence forces. In the last decade that has changed a great deal in the civilian world, security is a design criteria in manufacturing of IT platforms and a high priority item in technology operations. Defence forces can forgo the catch-up game in IT Security if higher defence management were to understand the strategic, operational and tactical benefits of designing security and privacy to defence IT plans, projects and operations.

Tuesday, February 7, 2012

Privacy & India

Privacy as a concept is far from being a part of the Indian culture. Our names reveal our state, our sect/caste, religion, and sometimes village and many times our father’s name:). We love to  boast about our salary, of course adding a 40% to the 20% bonus on our CTC. The list of examples is long, and sometimes not at all comprehensible. But that’s the way it is. Hence, in India, Regulation would have to drive cultural change as regards Privacy; and we have seen a first detailed and strong Regulation, with another more detailed and stronger one in the pipeline. But relying on regulation to change culture is too much to ask for, because Indian culture is very old, and consequently deep rooted. Govt. and corporation are primarily comprised of people, and in India, bulk of them being Indian and hence far from familiar with Privacy, we will not reach far in adoption of privacy practices in India, if we rely on regulation alone.
So who or what can help?

Most large international corporations see Privacy as a compliance burden, which is complied with just to be on the right side of law and as a regulatory risk mitigation exercise. With more and more of them having to do something or the other with new age business (cloud computing, social networking and mobility platforms), they are more and more inclined to give lip service to concepts like privacy which come in their way of exploiting and leveraging customer data, which is viewed as a pile of gold by marketers and sales folks.

Microsoft (MS) is uniquely placed in this regard. Having been one of the initial leaders of the computing industry and having been at the receiving end of security and privacy concerns of customers, corporates and regulators, MS decided very on to ingrain security, privacy and reliability as design pillars in all its products and platforms. In fact, 10 years ago in Jan 2002, Bill Gates himself wrote the now famous Trustworthy Computing (TwC) note, and focused MS’s developer community on building strong privacy and security protections into all of MS products and services as part of the TwC initiative. TwC still drives the ethos at MS today. There are numerous practical examples of how MS’s commitment to the concept of privacy by design protects consumers using several of MS products & platforms. Besides ensuring that Privacy principles are integral to all that it sells, MS also focuses on Privacy compliance in all its internal operations and that included its sales and marketing engines. There are more than 40 full time Privacy professional like me who are constantly maintaining strict vigil and oversight over all MS operations worldwide, and ensuring adherence to MS Privacy Policy and Standards which meet and better Privacy regulations in each and every country in the world. That’s why you will notice now that in the news when you find other big names being dragged into courtrooms around the world for Privacy violations, the only mention of Microsoft in the news is of how it contributed to spreading the message of Privacy during the DPD through awareness campaigns, primary research on consumer opinions around privacy and other such constructive activity.

I must mention that part of my role as the Privacy leader for MS in India is to be available as a subject matter expert and thought leader on data security & privacy, and make MS available as a partner committed to Privacy, in any venture that is undertaken on the domains connected to Privacy.

Wednesday, July 27, 2011

Governace, Risk & Compliance - a clear picture from the Infosec perspective

Wikipedia defines GRC or Governance, Risk Management, and Compliance as the "umbrella term covering an organization's approach across these three areas. Being closely related concerns, governance, risk and compliance activities are increasingly being integrated and aligned to some extent in order to avoid conflicts, wasteful overlaps and gaps. While interpreted differently in various organizations, GRC typically encompasses activities such as corporate governance, enterprise risk management (ERM) and corporate compliance with applicable laws and regulations."

"Governance describes the overall management approach through which senior executives direct and control the entire organization, using a combination of management information and hierarchical management control structures. Governance activities ensure that critical management information reaching the executive team is sufficiently complete, accurate and timely to enable appropriate management decision making, and provide the control mechanisms to ensure that strategies, directions and instructions from management are carried out systematically and effectively.

Risk management is the set of processes through which management identifies, analyses, and where necessary responds appropriately to risks that might adversely affect realization of the organization's business objectives. The response to risks typically depends on their perceived gravity, and involves controlling, avoiding, accepting or transferring them to a third party. Whereas organizations routinely manage a wide range of risks (e.g. technological risks, commercial/financial risks, information security risks etc.), external legal and regulatory compliance risks are arguably the key issue in GRC.

Compliance means conforming with stated requirements. At an organizational level, it is achieved through management processes which identify the applicable requirements (defined for example in laws, regulations, contracts, strategies and policies), assess the state of compliance, assess the risks and potential costs of non-compliance against the projected expenses to achieve compliance, and hence prioritize, fund and initiate any corrective actions deemed necessary.

Widespread interest in GRC was sparked by the US Sarbanes-Oxley Act and the need for US listed companies to design and implement suitable governance controls for SOX compliance, but the focus of GRC has since shifted towards adding business value through improving operational decision making and strategic planning. It therefore has relevance beyond the SOX world."

Now, we all know that there can be as many Governance frameworks as organisations - afterall it's a management driven approach and it will be hard to replicate it between two companies. And there are a plethora of of international standards pointing towards Governance frameworks, although these are in finite number. Risk Management frameworks are also a plenty and within each of them, one could adopt one or more out of several methodologies for a specific organisation, or a part of the organisation, be it a business process, or an installation or any other logical entity of the organisation. Compliance is about adherence to controls which are nothing but technology/process/people based procedures and they can be configured in any number of ways.

Thus, in normal times GRC is a huge challenge in itself. Now, to that we add technology complexity, outsourcing and mobility as also increasing regulatory stipulations and privacy concerns. The stage is thus set for a highly dynamic and complex environment with huge liability in case of non-compliance while there is little comfort from easy or even simple alternatives for compliance.
On top of this, GRC responsibles, who are often CISOs or CIOs, present this domain to their audiences in not a very simple manner; thus GRC becomes to enterprises what IT is to business - simply too much of jargon or machine language. It does not provide any comfort to management or stake holders when such a contentious subject is presented to them in such a complex manner. It is not for management or business to find meaning of the jargonic mumbo-jumbo that CISOs/CIOs use to address their audiences. It is rather the latter understand business needs on GRC from a 360 degree perspective and meet them by employing choice Governance and Risk methods deploying the right mix of people, process and technology controls to achieve the desired business objectives. Certain aspects to bear in mind are:
1. Garneringing management participation through a steering committee.
2. Ensuring creation of an asset and functionality inventory.
3. Defining and documenting the organisation's risk appetite and conducting a RA.
4. Mitigating risks and complying policies using Assets and functionalities.
5. Innovating business sensitive resolutions for uncovered areas.
Two aspects for key consideration are - experiences and perception. GRC is almost synonymous with Security and to make it an enabler, the audience must experience the wow from it and also perceive it positively. Security should not be seen or heard; it should be felt. And the approcah should focus on the strategic triads of Business focus, Revenue sensitivity and Cost consciousness. Ultimately Security should get ingrained in every. Product, every Project and every Process.
This can make a CISO the Chief Innovation Specialist Officer, instead of the Chief In-house Sadist Officer.

Monday, July 11, 2011

Enterprise Protection​, Assurance and Continuity (EPAC) - A Holistic and Risk Based Data Security, Privacy, Disaster Recovery Framework

Every enterprise has a plethora of these functions with overlapping domains and interdependent responsibilities. Governed by different (and sometimes non-complimentary though not necessarily conflicting) international standards, each of these functions provide adequate ammunition to their practicing professionals to conceive, plan and implement independent frameworks on their respective areas. Many a times these different frameworks are not aligned with each other and more importantly not aligned to business strategy and operational realities.

As a result, most of these important support functions often do not reach a position of direct business relevance. Thus, they fail to get mind share of business leadership and consequently never reach strategic relevance. In effect they never reach their ultimate destination of business enablement and remain relegated to a regulatory compliance mandated compulsion for the enterprise.

However, in the rapidly transforming business landscape in the ICT defined global markets, the reality is that these support functions, which comprise of the entire risk universe of an enterprise, can contribute directly to business objectives of most organisations, play the role of business differentiators and thus be of strategic relevance.

Thus, there is a scope in many enterprises to re-examine the construct, structure, role and functioning of all these support functions with a view to work out a holistic, business aligned, and uniquely positioned Enterprise Protection, Assurance and Continuity (EPAC) framework which provided integrated and Risk Based Data Security, Privacy, Disaster Recovery assurance to the organisation. As a result of this exercise, besides business enablement, there is a substantial scope of cost savings for enterprises in the form of removal of manning of overlapping domains, outsourcing of non-core function (those not contributing to business enablement) and overall reduction of head count owing to integration.

Hence, it would be worthwhile to undertake in-depth examination of enterprise framework of support functions and provide a holistic picture to executive management comprising of a current status snap shot, gap areas, scope of re-work towards an integrated and business enabled function, and suggested detailed implementation road map with milestones and deliverables. Also important would be handholding through out the implementation and helping the enterprise reach business specified integration targets with periodic reporting through suitable metrics and dashboards.

Emergence of Information Security & the role of CISO

In the last decade or so, Information Security has emerged from within the IT function as an important element with business critical and even strategic ramifications. The emerging direct business relevance of IS has created a leadership role which has come to be known as the CISO. International standards, IT frameworks and several regulations have also sanctified the criticality of IS and thus made the role of CISO even more relevant and legitimate.


In India, IS compliance had been almost non existent prior to 1990s. With opening of Indian markets and development of intimate global market connect, IS found it's place first in the BFSI sector and then in the IT/ITES sectors. Business and operational needs for security drove the next wave of IS-isation in India which saw home grown sectors like Telecom, Pharma, Manufactuing, Retail etc create IS teams, primarily to protect IP and safeguard operations.

The current drive of IS is mostly powered by regulations/laws as Indian Govt is carving out several laws/regulations with IS intent and content in it's march to join the big league of powerful nations. However, all along IS has not been treated as a core business need; rather as reactive measures to meet business realities (such as IT/ITES companies providing assurance to their international customers) or in response to high impact incidents (loss of business plan etc) or to comply with a law/regulation. While IS think-tanks like ISACA and ISC2 forecast the emergence of IS as a strategic function and the move of CISO into the Corporate Boardroom, the scene in India is a little different with lack of clear management understanding of the business value of IS and it's strategic impact. There are also numerous other related/relevant functions (such as Risk Management, BCP, Privacy, Physical Security, Intellectual Property etc) some with different international standard for them which are vying for management attention and organisational acceptance.

The contributing factors to this situation are:
1. Lack of a Security conscious and compliant culture in India.
2. Low levels of legal/regulatory enforcement.
3. Varying Security requirements and postures across different industry sectors.

In light of the above, it may be worthwhile to deliberate on the nuances of the CISO's role in an Indian enterprise and suggest measures to bring it at par with global standards and provide higher business value. It is also recommended to study industry/sector specific security requirements and suggest a sectoral security model as a best practice for adoption by Indian enterprises Pan-India.

Thursday, May 26, 2011

Idea of a Nation & it's impact on its Armies

The Armies (by which I mean Army, Navy, AF, SF, Seals et all) are mediocre-ly paid everywhere just as any other govt dept, with perks differing from country to country based on the influence of the Armies in that specific country - from accommodation with piped gas etc to management of PSUs (in Pakistan) to regularly manning public offices (in US/Europe). But there's a lot of difference in the role Armies play in different countries and I will try to group them in to three categories:


1. Cat 1: Armies in many countries play a legitimate role in national security which is an oxymoron of sorts - you create/maintain big & potent armies so that you avoid wars, thus never having to use the Armies. Thus they generally get a bad deal due to nil or insignificant/marginal representation in polity. Owing to this, such armies remain in the fringes of governance and suffer from diminishing value in protocol & perks; offset to some extent only by the occasional war or other high profile internal development. India falls in this category, so do most defensive democracies.

2. Cat 2: In handful of countries, their Armies besides fulfilling their national security role, go beyond the oxy-moronic context to use their defensive capabilities in an offensive manner (the best defense is offence, right!) and wage or participate in wars in other countries' backyards; thereby getting involved in polity and in effect get a much better deal. America leads this bandwagon which was till WW-II being led by UK. And you can very well guess that most offensive democracies fall in this category.

3. Cat 3: Then there are the lot of non-democratic countries where Armies are the central player in polity and have the last or lasting say in most matters of national importance. Obviously, since they make the rules, these folks tend to make the rules quite favourable to themselves; thus they enjoy a pretty good deal in all aspects. They even get a chance to participate in the wars waged by the Cat 2 guys in other countries (mostly Cat 1 or 3) backyards. And you guessed it right, our westerly neighbours belong here. And so does the other in the North/East.

But the issue is not which category a country's armies belong to. The bigger issue is how they landed there and what is in store for them in future. And for each country this is intricately connected to the idea of that country. Thus, what matters more than Pakistan is the idea of it and the idea of India is more important than India itself. Founded on the stark and unstable principles of monotheism, and carved out without natural defensibility, Pakistan needs its Armies to be involved in polity by design. And found with the values of non-violence co-existence guided by the all accepting Indian culture, there is almost no place for Armies in the Indian polity and civil supremacy rules. Going by how these prevalent ideas of Pakistan and India (and other countries in the world) are being shaped, it appears that ideas of these categories of nation states are solidifying more and more; defensive democracies getting more defensive, offensive ones getting more offensive and non-democratic ones resorting to be more non-democratic.
Change they say is the new constant.. but I would say, the more they change, the more they remain the same!

Monday, February 14, 2011

Mobile Malware: Is India Ready?

Q - Mobile Malware (MM) - How ready are Indian Enterprises to deal with them and why do you think so?


Ans - There is good awareness within the security community on delivery mechanisms of MM such as SMS, MMS, WAP push, GPRS, Mobile as Data Card etc. However, due to the large user base and in the absence of general user awareness on security, the instances of infections in India due to MM delivered on user handsets, and further communicated to user desktops/laptops and further to enterprise networks, is deemed to be very high.

However, enterprises do not perceive infections to be a major source of threat or a significant risk. This is because, on one hand management understanding on the subject is feeble, and on the other hand, the security community does not distinguish between MM and other malware while trying to deal with them primarily because they do not have any wherewithal to do the same. For example, a notable telecom fraud called PRS Fraud (Premium Rate Service) saps established operators of substantial revenues but operators have no inkling of what % of PRS frauds are caused by MM.

Moreover, there is no worthwhile research in industry and academia on MM or other related mobile security issues which can shed light on attacker patterns, preferred delivery channels, susceptible target groups, infection patterns, and post-infection prognosis. The trend is likely to remain the same unless there is demonstrable RoI from investing on such security research and deploying such security platforms.

Friday, January 21, 2011

Comments on Security Clauses in IT Act Amendments 2008

Q1. Prior to the amendments the IT act was perceived as a toothless tiger against the cyber criminals. Post amendments does the IT act give you a legal shield to battle the menace of cyber crimes?

A. It would not be correct to say that the IT Act was like a toothless tiger before the amendments. It was quite comprehensive even before the amendments. Every legislation has to evolve with time. The evolution process is faster in case of technology related legislations as technological advancements tend to be rapid.

The amendments have rationalized some sections and expanded the scope of the act. For example earlier Section 66 was a section which could be invoked against any crime that "Diminished the value of information residing inside a computer resource". This section has been clarified now with 10 subsections through an integration with Section 43. Sec 66A and 66F are new provisions that add new crimes to the act.

The only point of discussion regarding the dilution or otherwise is that most of the offences are now considered "Bailable". This however may be considered as an attempt to prevent misuse of the act against innocent persons rather than being treated as an attempt to make it easy for offenders to get bail.

Certain provisions in the amended Act will certainly make the fight easier. Allowing an Inspector to investigate crimes under the IT Act instead of a Deputy Superintendent of Police is one of those. In that sense, the amended Act is an improvement upon the original Act.

The biggest change however is that ITA 2008 attempts to create a "Security Culture" in the society with the creation of a "Security Management Infrastructure" by prescribing "Reasonable Security Practices" and expanding the concept of "Due Diligence" applicable to companies and Intermediaries. By assuming certain powers under Section 69, 69A,69B and 70B as well as imposing certain data retention obligations on the companies. In the long run this would provide a better cyber crime prevention mechanism than the deterrent effect of punishments.

Q2. What are some concerns that have not been addressed by the recent amendments in the act?

Ans. The main cause of lack of implementation of the regulations or faulty implementation of the law is the lack of awareness about law. The solution for better regulatory regime lies in strengthening the cyber law awareness amongst consumers. The law could have provided for incentivisation and obligations on creating a "Cyber Law Aware Cyber Society". In future also "Lack of Awareness" will continue to reduce the effectiveness of law.

Another deficiency which is apparent relates to data protection. Certain amended provisions do address data protection but the treatment could have been more comprehensive looking at existing EU Directives on Data Protection. This would however be corrected with the 'Data Protection & Privacy' law which the government is currently contemplating on.

Q3. What are some of the improvements that the amended act has brought about? Is there anything to thank for in the 2008 legislation?

Ans. Sections 43A, 72A and 67C are specific provisions that strengthen the Data Protection regime in India. This is a highly commendable aspect of the legislation.

Strengthening the organization of CERT-IN and enabling it to be a powerful regulator is another significant aspect.

One of the less recognized but more important change is in the revised structure of the Cyber Appellate Tribunal which has increased the effectiveness of the supporting judicial system.

Increase in the amount of compensation that can be claimed through adjudication from Rs 1 crore to Rs 5 crore is also another positive feature.

Introduction of the "Electronic Signature" has introduced new technical possibilities.

The amendments are an attempt to make the Act as technologically neutral as possible, which is a welcome step.

Also, there are new penal provisions addressing spam messages, trading in access codes and passwords, phishing attacks, identity thefts, unauthorized use of mobile phone cameras among others which have widened its scope.

The amended Act envisages appointment of experts for examining electronic evidence and delegates investigation to Inspectors.

All these are welcome improvements upon the earlier Act. Overall several good things have happened because of the amendments.

Q4. How closely should the IT and legal department work in order to build synergies? How can the IT- legal confluence help combat the scourge of cyber crime?

Ans. If the objective of law is to prevent occurrence of a crime, it has to address not only post offence punishment but also encourage proactive defense systems. Imposing legal obligations on information security practices is a step in this direction. This requires the IT and legal systems to work in close coordination.

Even at the post offence scenario, collection and presentation of evidence is an area where the IT and legal system should work in close coordination.

The amendments have attempted to bring such a synergy through the prescription of "Reasonable Securities" under Section 43A and due diligence under Sections 79 and 85.

To tackle cyber crimes, the need for the IT and legal departments to come together cannot be stressed enough. For any charge to be framed, evidence is important. In case of cyber crimes, the IT department becomes responsible to collect such evidence. Logically no other department would have such technical proficiency.

The legal department will, thus, need the help of the IT deparment to legally assess a particular incident and take appropriate action.

Q5. The rate of reporting, prosecution and conviction in cases of cyber crime is abysmally low in India. In such a scenarion how much trust do you repose in the investigation mechanism of our law enforcement agencies?

Ans. If victims do not understand the remedies available under law and seek remedies, we cannot blame the investigating officers that they have not prosecuted the offenders.

Everybody in the field including the Police, legal, judicial as well as the Information security community is in the learning phase and improvements can be expected over a period of time.

The enormous awareness on "Due Diligence" created by the recent verdict of the Adjudicator of Tamil Nadu against ICICI Bank in a Phishing Case which has resulted in a spurt of reporting of Phishing losses is an example of how better awareness leads to better implementation of laws.

As long as our criminal law functions upon the principle, ''let a thousand criminals go free but do not allow even one innocent man to go to jail", the rate of conviction will remain low.

Also, in many incidents the scene of crime due to ignorance would aleady have been disturbed before law enforcement agencies reach the scene.

This is especially true for corporate organizations, where they will typically try to retrieve and collect evidence before the law enforcement agencies enter the scene.

In many occasions, if the person collecting the evidence is not properly trained, such evidence is either lost or becomes inadmissible in a court. In such cases, conviction will naturally be difficult.

Capacity building to tackle such kind of criminal activity in a populous country such as ours will take time. We need to bear with them. With time things are sure to improve.

Tuesday, December 21, 2010

On Communication Interception & Privacy

As regards interception of data packets in the public medium i.e. Internet (whether at a cyber cafe or at the national/regional Internet gateway), I believe Indian Telegraph act 1885 still rules as there is no substitute to that yet. All other constitutional, statutory and regulatory references are inferential. So the only agencies who have any say are the Govt appointed and approved ones as per due process and even if it steps on citizens privacy. The new privacy regulation is likely to trample a little more on citizens' privacy than make the interference lesser. Similar Laws exist in most countries.

Monitoring with in organisations is not seen with the same light. Here privacy laws if any apply squarely; hence a variety of interpretations abound. While India, US and China permit unlimited monitoring of internal electronic communication after generic notification/intimation to employees, Australia, Japan, Canada and a few others permit the same after specific intimation. Europe on the other hand has a lot of variety; some countries require specific intimation to employees and individual acceptance by them, some exempt 'private'/'personal' marked mails/content within office mail communication and many such subtle variations.

Privacy Laws mandate such specific intimation to employees and the variations are almost as many as there are countries in Western Europe; the Russians and several East European countries have a much easier take on privacy. There are technological fixes that could identify whether employees are misusing the given facilities without necessarily singling out the perpetrator. However, there may not be possibility to serve individual notices without identifying offenders. Doing so would be a serious offence, in say Germany. Actually, in Germany, even general monitoring would be an offence without following laborious protocols to initiate the same.


But all in all, the very privacy regulations themselves are being re-looked or at least re-interpreted as is the failing welfare state concept prevalent in Western Europe for more than half a century. Enterprises which used to earlier leave alone data interceptions altogether are employing full time privacy officers and legal advisers not only to ensure compliance to the privacy regulations but see to it that the internal monitoring program is managed with in limits of the law. We are sure to hear more of this from Europe topic in coming times.
Back to the Govt monitoring, Govt agencies in poorly oversighted systems tend to go overboard with the use of power when consequences are not known to be severe. Same is the case with lawful monitoring. Excesses are rampant and law enforcement has pretty much a free hand, be it for tapping phones (land line/mobile) or track Internet communication..

Wednesday, December 8, 2010

On ROSI (Return on Security Investment)

One way to look at it is to calculate the actual cost of the people, platforms and services engaged full time or specifically security related projects; and compare it against Legal, Financial, Operational and Reputations costs. But that is a myopic exercise done from a perspective of weakness and insecurity. And there is never going to be a sure fire way of accurately computing legal and reputations costs.

A quasi-quantitative way is to take the following approach:
1. Identify in consultation with Management/business what all need protection/security and document items under groups - services, operations, systems, facilities, people and any other.
2. For each of the above items, document the business function/user who concurs that the protection/security is necessary
3. Assess the security risks to the above items and arrive at the ideal/best/cost effective means to provide protection/security
4. Discern what protection/security out of the above means has already been deployed as part of the initial architecture/design
5. Prepare a phased road map for deploying rest of the means and quantify their cost
6. Take a sign off from the user function(s) on whether they would like to bear the above documented costs or accept the documented security risks
7. If they would rather bear the cost, the benefit they derive out of the said security deployment can be then taken as the return on the security investment cost calculated above (point 5)

Another approach when CISO has strong management buy-in:
1. The very fact that a CISO has been hired is to meet an existing business need to provide security/protection
2. What we do with what we have - Just having security systems and processes does not ensure security. They have to be designed, configured, operated and reviewed efficiently and intelligently as per the organisations operating environment and business needs. Common examples are gaps in Access Control systems, Vulnerability Assessment platforms, SIEMs, Patching and AV infra etc
3. How we do, what we do - The approach should be business oriented, as business wants it and because it will facilitate/enable business not because the CISO wants it or because it's a security best practice. CISO's advisory and Security best practices are important but they have to be aligned to the business requirement and not vice-versa.

The inevitable CISO and the future ubiquitous CSO (under a pseudonym)

The CISO has come to be in the last one decade a position which can not be wished away. However, but for mature business houses, it finds itself being tossed about quite a lot - sometimes under the CIO, and other times under heads of Operations, Finance, HR, or some other corporate function. Rarely does it have access to the board and even less the board room. It's as if most people think he is required but most can not decide where he belongs.

This is connected to the evolution of the CISO function from IT Security to Information Security. While definitely it has come out or at least on the way of coming out of the IT function, the CISO has quite not been able to establish the domain spread it requires to fulfill the Information Security responsibility for an enterprise. From being a transactional security organ which ensures security of IT transactions, CISO has gathered steam to encompass the operational risk management, the security governance and audit framework as also the disaster recovery apparatus.

However, there are several other complementary and competing security and related domains which exist in penny pockets in other parts of the organisation which dilute the CISO and often are beyond his control, some times at cross purpose. These are Physical Security, Enterprise Risk, Business Continuity, Privacy, Fraud, Investigation and their ilk who masquerade with other names.

Organisations would eventually see the business benefit of integrating all these complementary functions and consolidate them under one head under some enterprise function or create a new function for it; if only to stop them from their never ending turf war and one-up-man ship . But it is unlikely to bear a designation with a S in it standing for Security. It's simply not sexy enough, especially when there are so many more hep sounding names in the stable. So CSO may never happen, as it also has not happened till date.

Physical security has become interesting and technical. There is increased room for convergence between PS and IS. But rarely, if ever, there has been an organisation where the two are under one head. And whenever they are or when they would be together under umbrella, it will not bear the name of CSO but something rather fancy and unrecognisable.

This is not necessarily a bad thing. It will bring security and all the complementary functions into the middle of business relevance, hopefully with the head of this heterogeneous entiry being from a business background but with a strong understanding of information security, and having a place in the boardroom - if not the board.