Showing posts with label policy. Show all posts
Showing posts with label policy. Show all posts

Tuesday, March 28, 2017

Big Problems, Small Packages (part 1)


    We're constantly hearing about data breaches in the news.  Many are due to external attacks as happened to Yahoo! or OPM.  Many others are caused by well-meaning staff or contractors who carry with them on laptops that then get lost or stolen.

   USB flash drives, often called thumb drives because they're about the size of your thumb, first hit the market in around 2000.  They had relatively little storage space and weren't cheap, but quickly became a security issue both for the potential to carry and load malware as well as taking data out of the office.  I remember discussions about this issue back in the early 2000s and some organizations were even thinking about using hot glue guns to fill in and block the USB ports on computers!  That would have been a mess!

   Before long the prices came down, the storage space went up and the problems multiplied.  Many organizations were not ready for how quickly these drives got integrated into every day work.

   Today we're going to focus on data that is copied on to USB flash drives and taken out of the office.

   The highest capacity USB flash drives we can find today are around 1 TB, though there are plans for 2 TB drives coming on the market before long.  Drives over 512 GB or larger are still pretty expensive.  But we know that prices of the high capacity drives will drop as new larger drives come out.

   To give you an idea of that size... 1 TB is about the size of 1500 CD-ROMs or 143,000,000 Word documents!  That's a lot of data potentially leaving your organization.

   So how do you combat this at your organization?  You don't!  We're not dealing with an adversary who's efforts need to be defeated.  These are well-meaning staff trying to get work done.  Always assume positive intent.

Tuesday, May 13, 2014

The Best (First Good) Password Policy Ever!



In the past I've discussed a number of aspects of the password dilemma.  Among the key issues are
  • good passwords are hard to remember, and;
  • passwords you can remember are easy for attackers to guess.
   But, maybe one of the key issues is that password policies are universally so bad that consumers can't do the right thing because they can't figure out what that is!  We've been living with that old dogma of.... say it with me...
  • 8 characters;
  • upper/lower case;
  • numbers;
  • special characters.
   That's been around since the 60's.  Perhaps it worked in a world when people had only one password, when systems weren't all networked together, and attacking systems wasn't the lucrative business it is now.

Tuesday, September 3, 2013

Putting the Face in Facebook

   As can happen in a month whose name contains an "a", "e" or "u" :-), Facebook has once again made
changes to its privacy policy and practices.  And, as always we all have two choices: accept the changes (and adjust our settings and practices appropriately), or; leave Facebook.

   Of course most people won't leave Facebook, and if anything they will add more users than those that leave.

   As I look through the changes (see Facebook's notice here with links to the details), I think there are three things to know...

Tuesday, April 9, 2013

Keeping Security Simple

   This week I did a national webcast with Capella University.  The topic was the Insider Threat.  But my take on this is a bit different than what's usually said on this subject.  I call it "The Accidental Insider".  You can see my slides here.

   I was talking about how I think that accidents are the major cause of breaches.  I've talked a bit about how important it is to keep things simple here.

   If you're an information security professional, hopefully you are familiar with the Verizon Data Breach Investigations Report (DBIR).  You can see their page for the latest report.

   One of the interesting things they point out in the report is summarized in this table:

Tuesday, March 19, 2013

The Accidental Insider

   This week I did a national webcast with Capella University.  The topic was the Insider Threat.  But my take on this is a bit different than what's usually said on this subject.  You can see my slides here.

   The typical story about insider threat is about theft or fraud.  Here are some recent articles.  This is a real and present danger.

   But there is another category of internal issues... accidents.

Tuesday, January 15, 2013

Something You Forgot - 3 Factors of Fail (part 2)

   Last week we started talking about authentication and listing the 3 factors of authentication.  This 2nd in the 5-part series will look at the 1st factor.

   The 1st factor of authentication is "something you know".  We usually think of this as passwords, but there can be other forms like: PINs; lock combinations; "secret" phrases (the phrase that pays!); picture identification; and secret pattern (like on your smartphone).

   There are a few fundamental problems here.  And they are mostly caused by something we can't change... we're trying to authenticate a human! (usually)  So, rather than something we know, these authentication methods rapidly deteriorate into something you forgot.  Here's why...

Tuesday, November 20, 2012

Stuff I Say - People Want To Do The Right Thing

   In the security field we hear a lot about the insider threat.  There have been plenty of well publicized incidents of internal employees, contractors or ex-employees stealing information, or deleting information or leaving some other kind of destruction before they leave an organization   I'll cover this topic in more detail in a future post.

   While this certainly does happen, it's not prevalent.  Call me an optimist... but I think that people generally want to do the right thing.

   And this is where the problems begin.  Sometimes those who make the rules and enforce the rules just make it too difficult to do the right thing!

Tuesday, November 13, 2012

Stuff I Say - You Pay by the Word

   This is a continuation of a series of posts on some of my philosophies about security strategy.  These ideas are covered in a fun talk entitled #*%! My CISO Says, covering a range of security governance and management topics.  Slides are on my slideshare page.  The first two posts are here and here.

   In that second post I was talking about policy.  Traditionally many organzations have staff sign a form that says that they have read and understood policy.  Perhaps the organization has some kind of new employee orientation at which policy is reviewed.  Among the problems is that policy is usually too long and too complicated.  It then becomes a TL;DR document (Too Long; Didn't Read).  I'm sure that both policy writers and policy readers/recipients can relate to this.
   So what to do?  I like to say that "you pay by the word", because you can pay now or pay later...

Tuesday, October 2, 2012

Stuff I Say - No One Has Ever "Read and Understood"

   Most organizations have policies.  Most medium-to-large sized organizations have security policies.  I hope that yours does!  Policies are a cornerstone to a security program.  People need to know what to do and policy is that high-level guidance.

   Of course, people need to read those policies!

   Many organizations will have staff sign a form that states they have read and understood the policies.  Sometimes this happens just once.  Sometimes it's annually, perhaps at the same time as an annual performance review.  Sometimes it's when a person joins the organization, or shortly thereafter.

   But does that work?  What is the goal?  I say that doesn't work!  No one has ever "read and understood"!

Tuesday, September 25, 2012

Stuff I Say - KISS - Keep It Simple Security

   This is the first of a series of posts covering themes I talk about all the time.  The theme today is keeping things simple.

   Last week I spoke at the Interface conference in St. Paul.  It was a fun talk entitled #*%! My CISO Says, covering a range of security governance and management topics.  Slides are on my slideshare page.  In that talk I frequently referenced keeping our security program simple.

Tuesday, September 4, 2012

Ineffective Security


   This is my 2nd favorite picture to use in a presentation. (I'll talk about my favorite picture in a future post!) It shows a classic security failure... the use of an ineffective security control.