Tuesday, March 18, 2014

XP End of an Era or... Deja Vu All Over Again!

   Unless you just came back from time traveling, you know that Microsoft is ending support for the XP
operating system on April 8.  To be clear... April 8 is Patch Tuesday, so that will be the last set of updates for XP.  Sort of.

   XP has been one of Microsoft's most popular desktop operating systems and many organizations are dependent upon it.  Many organizations have not yet updated to Windows 7 or 8 and the clock is ticking.  I'd like to look at what that means and share a few ideas of what we can do to protect ourselves and our organizations.

   Microsoft will be stopping all patches, hotfixes and enhancements to XP after April 8.  Anti-virus signatures will continue to be made available.  This means that any vulnerabilities that are discovered or disclosed might not be fixed.  Organizations will need to figure out if they are vulnerable to any new threats and then weigh the risks associated with their options.

   There has been some speculation that online criminal organizations may be stocking up on new vulnerabilities so these can be released after the last patch date.  We can't know if this is true, but it is possible.

   So... if you are still running XP, and need to continue to run XP, what can you do?  Let's do a high-level threat analysis:

Tuesday, February 25, 2014

No, You Can't Have Local Admin!

   If you have responsibility for security and/or access management for an organization, then there is a "simple" request that you have received, and will always receive... Users request local admin access to systems.

   Most of you know what I mean.  I'm referring to the local administrator or root account on a system.  When a person has local admin, they can access any part of the system, change or disable settings (including deactivating anti-malware or other security software), and, perhaps most importantly, install and run any software.  This last item is probably the primary reason people request this level of access.

   We're talking about Minimum Necessary... the idea that everyone should have exactly the level of access needed to do their job, and no more.  In most, if not all, organizations, far more people have local admin than really need it.

   Security vendor Avecto recently released a new study showing that over 90% of the most serious vulnerabilities in Microsoft software products in 2013 could have been mitigated by simply removing administrator rights.  Put another way, this means that only your systems administrators were vulnerable to all of the most critical Microsoft software vulnerabilities!  And these are the people who have the most access on your systems!  Here are a two good articles on the subject and here is a link to the full report.

   Let's break this down...

Tuesday, February 11, 2014

Bad Policies = Bad Passwords

   It seems that passwords are in the news again.  In the past I've discussed a number of aspects of the password dilemma.  Among the key issues are:
  • good passwords are hard to remember, and;
  • passwords you can remember are easy for attackers to guess.
   Adding to this mess is that many organizations do a poor job of protecting their storage of your password.  And now we have some new information...
Many organizations allow you to pick poor passwords on their websites by enforcing few or weak password construction requirements.
   We call these password policies, and these specify things like: how long the password can be; the minimum length it must be; what kinds of characters can or must be used; if the password needs to change, and; if there are some passwords that can't be chosen.

Tuesday, January 28, 2014

Are You a "Target"? - Incident Managment (part 2)

   I'm calling this part 2, but it's really the third in a series covering the consumer and enterprise sides of incidents and breaches.  This is always an important infosec topic, but the recent highly publicized issues effecting Target, Neiman Marcus and, as we're told, 3 other organizations to be named later brings this to the forefront.

   Many say that it's not a question of if we will suffer a breach, but when and how we will suffer a breach.  And yet there are organizations that consider this an optional capability.

   Last time we talked about the first two parts of the Incident Management program: Prevention and Planning/Preparation.

   Next is:
Communication. So these groups know their roles:

Tuesday, January 14, 2014

Are You a "Target"? - Incident Managment (part 1)

   It seems that every few days we get additional news about the Target breach.  There has been plenty posted about this including articles here, here and here.  And, unfortunately for my colleagues at Target, I don't think we heard the last on this.

   Last time I talked about the consumer side of the issue, and how individuals should protect themselves from the effects of an information breach.  Today we'll look at the corporate side... Incident Management.

   Incident Management is a critical part of any information security program.  I don't think there's any governance framework that doesn't include this important topic.  I'm a fan of the way NIST lays this out in SP800-61, with a few modifications.

   In boxing and martial arts, the saying goes: the best way to avoid getting hit is to not be there.

Tuesday, December 24, 2013

Are You a "Target"?

   By now, most of you have probably heard about the Target credit card information breach.  This is very big here in Minneapolis, home of Target.  All the details aren't out yet but it appears that credit card information for brick-and-mortar stores between Friday Nov. 27 ("Black Friday") and Sunday Dec. 15.  Here are some articles covering the story.  Here's Target's response and an FAQ.

   I'd like to talk a bit about next steps.  If you've been the victim of a data breach... what next?

   First... for consumers.  Target is a retail company and the direct victims of the breach are those of us who shopped at a Target store during the dates in question.  Consumers have two concerns here: credit card fraud and identity fraud. (I don't like the term "identity theft" even though it is commonly used.  No one can steal your identity... you still have it.  They can improperly discover, and misuse, the details... a.k.a. fraud.)

Tuesday, December 17, 2013

f2f Still Rules

   It's definitely a digital world.  And with all the instant electronic communication methods available, it's easy to forget about good old-fashioned face-to-face.

   Many work places have gone to open seating, without cubes or offices, to promote collaboration.  There are "team spaces" and other kinds of open areas in which people can quickly get together to solve problems.

   I've been thinking about this topic for a couple reasons.  First, I've been talking with internal groups about Internet Safety for Families.  This is a great topic both for general information and for Security Awareness in the workplace.  One item we often discuss is communication methods.  Teens and young adults (as well as many high-tech workers) do a disproportional amount of their communication electronically.  Sometimes that works and sometimes it doesn't.