Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Tuesday, October 2, 2007

A Simple Incident Response to a Simple Oversight



Today may be the day you need to step up and respond to a breach involving someone else’s confidential information. Do the right thing and you will be OK. Assuming the breach is less than it really is can negatively impact your company, the victims, and your livelihood.

A Little Background
I write for this and The Breach Blog because I am passionate about information security and protecting people when dealing with confidential information. The Breach Blog was born out of this passion just a few months ago, and I have already written 69 articles (with a backlog of four) about breaches and the lessons they teach us. I believe that people can really learn from other people’s mistakes. Anyway, on to the story...

The Incident
This morning I received a phone call from one of the IT administrators at a company that I provide information security consulting for. He was in a panic.

He regularly receives email updates from his human resources department outlining terminations, new hires and management changes. He gets these updates so that he can update the company’s Active Directory. Today, he received his spreadsheets as normal, but this time there was an additional column that he did not recognize before. The column was titled “Assoc. ID”, and the spreadsheet contained information on about 50 company employees.

Can you guess what the “Assoc. ID” is?
If you guessed Social Security number, then you are correct! Oh boy.

On the surface, you may say this isn’t that big of a deal. We can just go to human resources and inform them that this is an unacceptable practice and be done with it. OK, but put yourself in the shoes of a person that was in the spreadsheet. Would you be OK if information security just went to human resources and told them to quit it? I am guessing that your answer may be the same as mine, NO!

If I was a victim, what kind of questions would I demand answers for? Let’s see:

  • I want to know where this information came from.
  • I want to know if this has been an acceptable practice by human resources in the past and if so, how long?
  • I want to know if there was anyone else that received this email.
  • I want to know that the email containing the spreadsheet was deleted. Not just from the “Inbox” either, but also “Sent Items” and “Deleted Items”.
  • I want to know if there were any copies stored locally on the sender’s computer.
  • I want to know if there are any copies on a network drive (i.e. is “My Documents” synchronized).
  • I want to know if this information may be in a backup anywhere that needs to be
    dealt with.
  • I want to know why this happened in the first place.
  • I want to know what human resources is going to do to make sure that this never happens again.
  • Are there any laws and/or regulations, i.e. do I need to disclose this breach to any state attorney generals?
You get the picture yet? I want to know everything there is to know about this breach and I want to take every possible action to contain the damage caused by it.

Victims and shareholders should expect demand no less!

As it turns out, this seemingly innocent mistake/training issue quickly escalated into a full-blown investigation that took away from other important tasks and cost the company money. It would have been easy to take the lazy approach and sweep this under the rug, but what service would I be providing to the victims, the company, or myself? Thank God this breach only affected 50 people and was relatively easy to contain and respond to. What would I have done if this breach affected 5000, 50000, or 500000 people? What if the human resources person sent the email outside of the company?

Tips I've Learned
An easy way to respond to an incident involving personally-identifiable information is to put yourself in the shoes of a victim. This may sound obvious, but too many times I have witnessed information security “experts” going the other way. Answer the questions that you would have as a victim. Take money, lost consumer confidence, stock price, etc. out of the equation and do the right thing. If we all did the right thing we would have less regulation and more time to do other “right things”.

The CIO of this company asked me a question on my way out the door once the investigation was complete. He asked me what makes an information security professional so good at what he (or she) does? My answer: 95% of what makes a good information security professional is common sense. The other 5% is skill.

Unfortunately, it is very difficult to teach someone common sense. Read more!

Monday, June 11, 2007

5 Essentials for CISO Success

Being a CISO ain’t that easy nowadays. Actually, I am not sure if it ever was. Besides the obvious attributes of a good employee; honesty, integrity, confidence, good staffing, etc., what makes a good CISO and what makes a great CISO?

Through conversations with other security professionals and my own observations, I noticed five essentials that great CISOs consistently do well.

DISCLAIMER: In case you thought otherwise, information security is a holistic discipline and this article is not intended to be all-inclusive. To do so would require volumes of books and experience.

Essential # 1: If you want someone to buy, you need to sell
This is always a challenge for me as deep down I am an introvert. I would be fine if all I had to do was work at my computer all day long, but I would make a much better analyst than I would a CISO. CISOs need to be visible and sell the programs they sponsor. CISOs need to sell everyone from the CEO to the backroom mail worker on how information security can help them conduct business better. People will buy into the concepts and ideas that make sense to them so spend time explaining how security benefits all stakeholders in the company.

My action item:
Each day I make it a point to talk to someone I have not talked to before in the company. Usually during casual conversations I find the opportunity to evangelize.

Essential #2: Align security initiatives with the business objectives
This seems simple enough, but unless a CISO actively seeks an understanding of the businesses goals and objectives they will not be known to him/her. Be careful not to make strategic decisions based on assumptions.

Too often security is viewed as a barrier to conducting business with no tangible benefits. As much as it is my job to protect the company’s information assets, it is equally my job to ensure that security does not get in the way of business and where possible enables it.

My action item:
Actively seek an understanding of the company I work for as each opportunity presents itself. Volunteer for committees, attend meetings on time, and ask questions regularly. When I ask questions I ask them in a manner that conveys my desire to understand and help.

Essential #3: Compliance is not the “end all”
Obviously compliance is very important and all companies face some type of regulation, rule, guidance, or law that they have to contend with in relation to the management of information. I have always viewed compliance as the things that a governing body makes us do because we were not doing the right things to begin with. If companies had adequately protected sensitive information all along, we would have much less red tape to deal with today.

The security program I am responsible for is not designed specifically for compliance but is built specifically for the business. If the security program I manage is managed well, then compliance will be mostly automatic. During audits, answer what is asked and provide what is requested, nothing more and nothing less. If there are deficiencies, attend to them and ask why it was not already designed into the program.

Essential #4: Train, inform, remind and reward
This cannot be underestimated, but in most companies it has been for a long time. How can you expect the users in your company to abide by the rules dictated in policy if they are unaware of the rules and/or do not know how to apply them to their work? In order for users to understand, they must be trained. In order for users to develop good habits, they must be consistently reminded. In order for users to care, they must be rewarded.

Believe it or not users believe they have more important things to think about than information security and in many cases they are right.

My action item
Create an information security training and awareness policy and obtain the approval of business executives. Develop an effective information security training and awareness program. Involve business unit leaders in the process of training and awareness program development.

Essential #5: Information will inevitably be compromised, detect and respond
Business information WILL be compromised through unauthorized disclosure, alteration, or destruction. This is an absolute fact. Prepare for detection and appropriate response.

My action items
Develop standards for various detection mechanisms and logging facilities throughout the organization. Detection and logging should overlap and be redundant in design and implementation. Develop incident response policy and procedures, then test them regularly.

Conclusion
These tips should only compliment what is already being done by an effective CISO. Wouldn’t it be nice if it were all this simple?
Read more!

Friday, April 13, 2007

Top 10 Free security-related programs for every home user

There are certain security-related programs that all home users should have installed on their computers. Installing, configuring, and maintaining programs from each category listed in this article will provide a good base of protection for most.

This list and accompanying suggestions are based with Windows 2000 and XP operating systems in mind. Many of the suggested programs in this article will not work with Vista.

Did I mention free? I like free. Don’t get me wrong I also like to do my part in supporting the economy, but why pay for something if I don’t have to (legally).

1. Anti-Virus Software
Effective, up-to-date anti-virus software is a critical cog in your home information security machine. I would not suggest anyone using a Windows (or Mac and maybe Linux) computer without it, unless you want to lose your information, have your computer participate in a “bot” network, or send not-so-nice emails to everyone in your contacts list.

Free Programs
My favorite is Grisoft’s AVG Anti-Virus Free. AVG has all of the options to ensure “good” virus protection, the performance is above-average, and it has a pretty good detection rate. The only beef I have with AVG is the clunky interface, but it IS free. Other free programs worth checking out include avast! 4 Home Edition and PC Tools AntiVirus Free Edition

2. Anti-Spyware Software
The question I get often is “If I am using anti-virus do I still need anti-spyware, and if so why?” The answer is always yes, and the reason is because of the difference in the way viruses and spyware (and adware) operate. Virus spreads, spyware imbeds. Your anti-virus software will not protect you adequately from spyware.

Free Programs
CRAWLER, LLC’s Spyware Terminator – Spyware and adware have evolved so much that I don’t think any of the free anti-spyware applications on the market should be relied upon solely. Although my favorite free anti-spyware application is Spyware Terminator, I would suggest that you supplement its protection with another (AVG Anti-Spyware Free, Spybot Search and Destroy, Ad-Aware SE Personal, etc.)

3. Personal Firewall
Personal firewalls are an important complement to your home computer information security. They are especially important if you have an “always on” cable or DSL connection at home. You should expect a “good” personal firewall to perform well in monitoring each connection into and out of your computer and tie it to the application (process) making the request.

Free Programs
Far and away, my favorite free personal firewall is Comodo Firewall Pro. Comodo performs well in leaktests, has all of the necessary options, and comes with good support in the form of updates, forums, and email. Other good free personal firewall products include ZoneAlarm Free, PC Tools Firewall Plus, and Jetico Personal Firewall (the best performer in leaktests).

4. Browser
There is always plenty of contention and discussion when talking about which browser is best. Whether you choose Internet Explorer, Mozilla Firefox, Opera, or any other browser, each will have its advantages and disadvantages. I can say one thing from experience; I am not at all pleased with IE7 on Windows XP SP2. The performance is horrendous.

Free Programs
All of the major browsers are free now and there are well over 100 available online. Trying to determine which one is the most secure is a very hotly debated topic. The most secure browser depends on the person using it. My favorite browser for security is Opera 9.20 for Windows. Opera is fast, can be made relatively secure, and has plenty of options. Other popular browsers include Internet Explorer, Mozilla Firefox and Netscape Browser 8.1.3.

5. Anti-Spam
Most home users use web-based email. Many of these web mail solutions employ some anti-spam technology. For home users that use an email client such as Outlook or Outlook Express, an anti-spam program is a very good idea. Convergence between spam, virus, and spyware is predicted in coming months and years (we have seen some already), which makes an anti-spyware solution that much more valuable.

Free Programs
My favorite anti-spam program for Windows is SPAMfighter. SPAMfighter does an admirable job of filtering spam and has features out its ears. Other good anti-spam programs include SpamAware V4.5 and Agnitum Spam Terrier. Spam Terrier looks very promising. I have not fully tested it yet.

6. Password Management (see “Passwords”)
I don’t know about you, but I have way too many passwords to keep track of! I won’t right them down (because you aren’t supposed to, duh). I use different passwords for different logins. In order to maintain control of my passwords securely, a password management program is absolutely necessary.

Free Programs
RoboForm has emerged as a market leader in easy-to-use, secure password management. I use RoboForm daily and I would be lost without it. Another good password management program that I use is PasswordSafe made by renowned crypto-expert Bruce Schneier

7. Anti-Phishing Software
As the number and sophistication of phishing attacks grow, so will the number of victims that fall prey. As the number of victims that fall prey grows, so will the number of phishing attacks. A vicious cycle. There are programs designed to help identify probable phishing attacks and it’s a good idea to check them out. Personally, I have received phishing emails that have gotten through both Internet Explorer’s and Gmail’s built-in protection.

Free Programs
Phishing is a social engineering attack, so the best free tool you can use is in your head (:o .

Using a browser and web-based email that provide built-in phishing protection is a good idea, but if you still want additional protection take a look at the Netcraft Anti-Phishing Toolbar or Phishing Detector v.1.0.

8. Backup Software
I am not going to suggest any free backup software other than what you already have on your computer. Use Microsoft’s backup program that was included with your operating system (assuming Windows 2000 or XP). Click Start, Run, type “ntbackup” (no quotes) and click OK.


9. File Recovery Tool
A case could be made whether or not a good file recovery tool is essential to the security of your computer. Too many times have I been called by someone in a panic because they had deleted their important information. The more time that passes between the time your files were deleted and the time you attempt to recover them, the less chance there is to recover them without a significant amount of expense. Having a tool “at the ready” will help to avoid confusion and diffuse the situation somewhat.

Free Programs
Be careful which file recovery tool you choose. Choosing the wrong one can make your problems worse. Also, install your program and test it out before a crisis. This way you will be that much more prepared. Convar’s PC Inspector File Recovery 4.x is one of my favorite free file recovery programs and their Smart Recovery program works well for flash media (i.e. photos from camera or video recorder).

WARNING: If your files are absolutely critical to you and you do not feel comfortable using a program on your own, call a professional.

10. Encryption Program
Being an information security guy, I do love me some good encryption! Encryption used properly will protect the confidentiality and integrity of your data. Essentially, your files will not be understood to anyone not authorized by you. If you store highly confidential data (i.e. tax documents, electronic bank statements, etc.), I would strongly suggest you encrypt it.

Free Programs
I have been using Axantum Software AB’s AxCrypt File Encryption Software for a long time and I have been very pleased with it. Another good free file encryption program is Cypherix Cryptainer LE. For those of you wanting to encrypt the entire drive for free, you can try CE-Infosys’ FREE CompuSec. If you are going to go for the “full disk” option, be sure to read the manual first (i.e. disable anti-virus during install)!

BONUS - Diagnostics
Sometimes a problem crops up and it gets misdiagnosed. In order to help determine what the root cause of a problem is, I need to gather as much pertinent information as I can about the problem. A good diagnostics tool helps accelerate this process.

Free Programs
There are hundreds of free diagnostic programs out there. Picking one as my favorite will surely draw some fire. Not being faint of heart, my favorite free diagnostic utility is System Information for Windows (SIW 1.67) written by Gabriel Topala. Much of what you will be looking for in a diagnostic program will be dependent upon your circumstances.


So there is my top ten, which is subject to change of course!

Keep in mind that this software is what I would recommend to a home computer user on a budget. The toolset I use in my work is more vast (i.e. audit tools, scanners, sniffers, compilers, etc.).

To the best of my knowledge, all of the software listed here is offered free to home users (i.e. non-commercial). Check with each individual developer to make sure you are using their software in compliance with their license.
Read more!