I'm calling this part 2, but it's really the third in a series covering the consumer and enterprise sides of incidents and breaches. This is always an important infosec topic, but the recent highly publicized issues effecting Target, Neiman Marcus and, as we're told, 3 other organizations to be named later brings this to the forefront.
Many say that it's not a question of if we will suffer a breach, but when and how we will suffer a breach. And yet there are organizations that consider this an optional capability.
Last time we talked about the first two parts of the Incident Management program: Prevention and Planning/Preparation.
Next is:
Communication. So these groups know their roles:
A place to talk about information security, Internet safety and, of course... coffee!
Thoughtful, sometimes controversial, but not following the crowd unless I'm in line at the coffee shop.
Showing posts with label customer. Show all posts
Showing posts with label customer. Show all posts
Tuesday, January 28, 2014
Are You a "Target"? - Incident Managment (part 2)
Labels:
accident,
assessment,
assets,
attack,
breach,
communication,
compliance,
customer,
cybersecurity,
enterprise,
framework,
improvement,
incident,
infosec,
iterative,
leadership,
NIST,
planning,
preparation,
risk
Tuesday, January 14, 2014
Are You a "Target"? - Incident Managment (part 1)
It seems that every few days we get additional news about the Target breach. There has been plenty posted about this including articles here, here and here. And, unfortunately for my colleagues at Target, I don't think we heard the last on this.
Last time I talked about the consumer side of the issue, and how individuals should protect themselves from the effects of an information breach. Today we'll look at the corporate side... Incident Management.
Incident Management is a critical part of any information security program. I don't think there's any governance framework that doesn't include this important topic. I'm a fan of the way NIST lays this out in SP800-61, with a few modifications.
In boxing and martial arts, the saying goes: the best way to avoid getting hit is to not be there.
Last time I talked about the consumer side of the issue, and how individuals should protect themselves from the effects of an information breach. Today we'll look at the corporate side... Incident Management.
Incident Management is a critical part of any information security program. I don't think there's any governance framework that doesn't include this important topic. I'm a fan of the way NIST lays this out in SP800-61, with a few modifications.
Labels:
accident,
assessment,
assets,
attack,
breach,
communication,
compliance,
customer,
cybersecurity,
enterprise,
framework,
improvement,
incident,
infosec,
iterative,
leadership,
NIST,
planning,
preparation,
risk
Tuesday, December 24, 2013
Are You a "Target"?
By now, most of you have probably heard about the Target credit card information breach. This is very big here in Minneapolis, home of Target. All the details aren't out yet but it appears that credit card information for brick-and-mortar stores between Friday Nov. 27 ("Black Friday") and Sunday Dec. 15. Here are some articles covering the story. Here's Target's response and an FAQ.
I'd like to talk a bit about next steps. If you've been the victim of a data breach... what next?
First... for consumers. Target is a retail company and the direct victims of the breach are those of us who shopped at a Target store during the dates in question. Consumers have two concerns here: credit card fraud and identity fraud. (I don't like the term "identity theft" even though it is commonly used. No one can steal your identity... you still have it. They can improperly discover, and misuse, the details... a.k.a. fraud.)
I'd like to talk a bit about next steps. If you've been the victim of a data breach... what next?
First... for consumers. Target is a retail company and the direct victims of the breach are those of us who shopped at a Target store during the dates in question. Consumers have two concerns here: credit card fraud and identity fraud. (I don't like the term "identity theft" even though it is commonly used. No one can steal your identity... you still have it. They can improperly discover, and misuse, the details... a.k.a. fraud.)
Labels:
access,
attack,
awareness,
breach,
consumer,
customer,
cybersecurity,
fraud,
identification,
identity,
identity fraud,
online,
PCI
Tuesday, December 17, 2013
f2f Still Rules
It's definitely a digital world. And with all the instant electronic communication methods available, it's easy to forget about good old-fashioned face-to-face.
Many work places have gone to open seating, without cubes or offices, to promote collaboration. There are "team spaces" and other kinds of open areas in which people can quickly get together to solve problems.
I've been thinking about this topic for a couple reasons. First, I've been talking with internal groups about Internet Safety for Families. This is a great topic both for general information and for Security Awareness in the workplace. One item we often discuss is communication methods. Teens and young adults (as well as many high-tech workers) do a disproportional amount of their communication electronically. Sometimes that works and sometimes it doesn't.
Many work places have gone to open seating, without cubes or offices, to promote collaboration. There are "team spaces" and other kinds of open areas in which people can quickly get together to solve problems.
I've been thinking about this topic for a couple reasons. First, I've been talking with internal groups about Internet Safety for Families. This is a great topic both for general information and for Security Awareness in the workplace. One item we often discuss is communication methods. Teens and young adults (as well as many high-tech workers) do a disproportional amount of their communication electronically. Sometimes that works and sometimes it doesn't.
Tuesday, August 27, 2013
People and Process First!
I've been reading, and hearing, lately about the ideas of client-centric or human-centric IT. Here's a cool article and interactive infographic from GovLoop.com. It describes a roadmap approach to get to a people-centric approach while showing examples of what some US federal agencies are doing to advance the cause.
I like infographics! They are fun, impactful, and this is a good one. But, sometimes they are so busy that the simplest parts of the message gets obscured.
It's not just infographics that obscure simple ideas. Security and IT are experts at over-complicating things. We get so caught up in the cool tools that we sometimes miss the main point.
In the Security and IT world, we should always look at any project or program through the lenses of:
I like infographics! They are fun, impactful, and this is a good one. But, sometimes they are so busy that the simplest parts of the message gets obscured.
It's not just infographics that obscure simple ideas. Security and IT are experts at over-complicating things. We get so caught up in the cool tools that we sometimes miss the main point.
- People
- Process
- Technology
Tuesday, July 16, 2013
Are You the Customer... or the Product?
I regularly speak with people about Internet/Online Safety. One message I frequently give about free online services is:
I'm a big fan of free online services, but it's important that people realize what's going on. It starts with the privacy policy, which explains how an online service intends to use your data and information about you.
But I want to talk about cloud storage services. These services allow you to backup files, sync files between systems and devices, and have files available from anywhere. How are your files protected?
You're not the Customer... You're the Product.We often see people upset about changes in social networks like Facebook. Folks complain about "customer service", not realizing that they are not the customer! It's often the advertisers, or other backers, who are the real customers. And what those customers want is information... about the users of the service.
I'm a big fan of free online services, but it's important that people realize what's going on. It starts with the privacy policy, which explains how an online service intends to use your data and information about you.
But I want to talk about cloud storage services. These services allow you to backup files, sync files between systems and devices, and have files available from anywhere. How are your files protected?
Tuesday, May 21, 2013
The Business (not Blind) Side
A Doctor, Lawyer, Salesperson and Systems Adminstrator walk into a bar...
As I mentioned last week, the Secure360 conference was in town. And as always, it was a great show. I was pretty busy and had 3 different talks. The first was a 4 hour pre-conference session on BYOD. (slides here)
After talking about the history of portable devices and framing the issues with which organizations struggle, we did something a bit different.
As I mentioned last week, the Secure360 conference was in town. And as always, it was a great show. I was pretty busy and had 3 different talks. The first was a 4 hour pre-conference session on BYOD. (slides here)
After talking about the history of portable devices and framing the issues with which organizations struggle, we did something a bit different.
Labels:
business,
BYOD,
conference,
consumer,
customer,
devices,
IT,
portable,
security,
technology
Subscribe to:
Posts (Atom)
