Hiển thị các bài đăng có nhãn communications. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn communications. Hiển thị tất cả bài đăng

Calls for Enhanced Enterprise Security Governance Starting to Steamroll


Though I've been approaching this issue from a sector-specific perspective for years, lots of what's been in the news lately (and I mean lately) is intended for all technology-enabled sectors. Which pretty much means every business and every organization that intends to maintain consistent and reliable operations in the near and mid-term future.

First off, and with origins that predated the Target breach that's credited with generating most of this activity, was DOE's Energy Advisory Committee giving thumbs up in May to a paper on this topic on Security Governance. It proposes that DOE pursue potential upgrades to how energy companies organize and run themselves from a security perspective. Titled: EAC Recommendations for DOE Action Regarding Implementing Effective Enterprise Security Governance - Outline for Energy Sector Executives and Boards, among other things, this paper lists the following "Characteristics of Effective Security Governance":
  • Clearly defined responsibilities from the board of directors to senior leadership to employees 
  • Presence of an active Security Governance board comprised of senior stakeholders from across 
  • the company 
  • An executive owner of enterprise security: with purview over IT, OT and physical security policy designated CSO or similar 
  • Striving for 100% alignment with of security with business/mission 
  • Using measurement of key indicators to increase awareness and drive improvement (with 
  • maturity tools like DOE's ES-C2M2

Then there's this from Reuters in May: Exclusive: U.S. companies seek cyber experts for top jobs, board seats, which emphasizes the concept of getting the security chief out of IT:
While a CISO typically reports to a company's chief information officer (CIO), some of the hiring discussions now involve giving them a direct line to the chief executive and the board, consultants and executives said. After high-profile data breaches such as last year's attack on U.S. retailer Target Corp, there is now an expectation that CISOs understand not just technology but also a company's business and risk management.
The Securities and Exchange (SEC) commissioner recently added his voice as well. In SEC Commissioner Calls on Corporate Boards to Address Cybersecurity, Commissioner Luis Aguilar  expresses his hope for governance improvements this way: “One would expect that corporate boards and senior management universally would be proactively taking steps to confront these cyber-risks.”

Then, from the International Association of Privacy Professionals online journal, there was Cybersecurity in the Boardroom: The New Reality for Directors, which included a list of recommendations, some of which have particular relevance for security governance and culture:
  • Develop a high-level understanding of cyber-risks facing the company through briefings from senior management and others
  • Ensure that the company has at least one committee that is responsible for overseeing and understanding cybersecurity issues, controls and procedures
  • Facilitate a culture that views cybersecurity as a business issue that all employees should understand and participate in. As part of that, companies should consider employee training and awareness programs
  • Include a cyber-expert on the company’s board of directors or receive regulator reports from a cybersecurity expert that are discussed at board meetings
So, as you can see, what once felt like a voice in the wilderness is now becoming a chorus.  Or you could say a trickle is becoming a deluge.  No matter the metaphor, will a little help from the Federal Government, and a lot more from The Real World, enterprise security governance is beginning to get the attention it deserves.

Image credit: Peter Skelton



Declaration of Independence and Intent

I've been warming up and working in this space for years now, and if you've been a Smart Grid Security blog subscriber or an intermittent visitor, you may have noticed an evolution in cyber security thinking of sorts. Well, with changing the world as my goal, it's time to stop treading water and start swimming like I mean it. I just left IBM in order to bring a new type of security advisory service to energy sector organizations. Here’s a brief version of the concept:
You often hear that culture change is the hardest thing to accomplish in an organization. That may be, but to help put our sector’s cybersecurity preparations on a better course, I’m developing an approach focused on increasing organizational awareness and improving internal communications about the security issues that matter. It begins with senior leadership, extends throughout the enterprise and doesn’t stop until it reaches service providers and the supply chain. Most engagements will begin with an in-depth orientation briefing for senior stakeholders, followed by periodic meetings and dedicated hours of access so that I can be a resource whenever my input is needed.

You may already know how much I like measurement. Well, I also like forecasting the future, and when we're several years into this campaign, you'll be able to measure its success by the growing number of cybersecurity-engaged CEOs and Boards in our sector. You'll see them take steps to bridge the culture and communications gap with their increasingly senior security leadership, who themselves will be eschewing technical jargon for the lingua franca of business. You’ll also see more state regulators able to credibly fulfill their cybersecurity oversight roles and responsibilities.

You might ask: Is this a formula for guaranteed success? How hard will it be to to pull this off? To which I turn to Niccolo Machiavelli, a friendly Italian man to whom I was introduced during my professional military studies at the Air Force Academy long ago:
"There is nothing more difficult to take in hand, more perilous to conduct, or more uncertain in its success, than to take the lead in the introduction of a new order of things."
So in case I haven't made it perfectly clear yet, the bar by which to measure success for this enterprise is extraordinarily high: setting into motion a new order of things in utility cyber security awareness and communications, as well as in the organizations that regulate them.

I left IBM just over one week ago after a great four year run. We parted on good terms and I maintain excellent collaborative relations. I left to to pursue something I can only fully do with the freedom of being on my own. But of course I can't really do all of this by myself. I'm going to need all kinds of partners, helpers, advocates, and clients to sustain this mission. Improving cybersecurity awareness and communications in our sector promises to be difficult but immensely satisfying work. Please join me.

The Future of Naval Installation Energy

Posting this one for SGSB readers who might not otherwise see relevant content on the DOD Energy Blog. There's a lot to admire, and learn from what the Navy is doing in Washington DC and the surrounding region. Check it out ...
-----------------------
As projected several years ago in this great 5-minute video, paving the way for demand management, energy efficiency, microgrids, support for renewables and all manner of support-the-mission, energy security goals (with cybersecurity baked in).



From all accounts, the folks involved with this initiative are right on schedule and are meeting their objectives.  Recommend you keep an eye on this.

Supply Chain Security Awareness on Upswing for Energy and Comm Sectors

10/25/12 Update: Huawei just said it is ready to have all its source code tested for security. Would other vendors be so bold?

------------------

If you don't subscribe to the online version of the Wall Street Journal, you probably don't get its daily CIO feed, which provides a nice topical tapas-sized taste of what's on folk's minds every morning.

One of those folks is me, and I've been stirred up lately by all the press (The Economist, 60 Minutes, etc.) and Capitol Hill attention Chinese communications equipment maker Huawei has been getting. Personally, I haven't have any direct contact with Huawei or its products, but I have a gut-level response when a company gets pilloried solely on where it's headquartered or the nationality of the owner(s).

This comes from my prior experience in application security and some vetting procedures that give credit to applications built by companies with US ownership. The distance between owners, whose reputation and integrity may be stellar, and the products themselves, is vast. In the the software world, rule #1 is re-use. Components written all over the world are easy to find, buy or borrow these days. And security is often not in the decision tree of the developers on either side of the equation.

Of course, owners' reputations may be less or far less than stellar, but still, the distance remains and they have  little impact on the ultimate security characteristics of their wares. All that to say, Huawai's products need to be scrutinized carefully prior to purchase and deployment. But the same level of attention needs to be paid to ALL 3rd party products, IT and OT, hardware and software, regardless of country of  origin.

Take it away Michael Hickins (from The Morning Download: Beware Your IT Supply Chain):
Good morning. A White House report leaked Thursday exonerated Huawei of spying on behalf of the Chinese government. But that doesn't mean you can rest easy. The same report found vulnerabilities in the company’s networking equipment, which put customer data at risk.
Customers are unwittingly installing computing and networking equipment and software rife with back doors created by vendors who outsource parts of their production to partners in “politically hostile” areas of the world, according to Gartner analyst Neil McDonald, who just published a study on the topic. “Attackers use weaknesses in a supply chain to get a foothold on a system rather than attack a system in production, which is hard on a well-defended system,” McDonald told CIO Journal.
CIOs can reduce the risk of introducing trap-door-riddled IT by demanding proof of an explicit chain of custody from IT suppliers covering all third-party hardware and software they use in their products. They also should require their IT system providers to periodically sample and test their products; and they should procure the same equipment used by government agencies, which in some cases employ electron microscopes and chemicals to test IT components. McDonald says the spotlight on Huawei put IT supply chain risks “on the radar screen of every CIO.” Now it’s up to every CIO to act on this information.
Nicely said Neil McDonald.