Hiển thị các bài đăng có nhãn security governance. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn security governance. Hiển thị tất cả bài đăng

Calls for Enhanced Enterprise Security Governance Starting to Steamroll


Though I've been approaching this issue from a sector-specific perspective for years, lots of what's been in the news lately (and I mean lately) is intended for all technology-enabled sectors. Which pretty much means every business and every organization that intends to maintain consistent and reliable operations in the near and mid-term future.

First off, and with origins that predated the Target breach that's credited with generating most of this activity, was DOE's Energy Advisory Committee giving thumbs up in May to a paper on this topic on Security Governance. It proposes that DOE pursue potential upgrades to how energy companies organize and run themselves from a security perspective. Titled: EAC Recommendations for DOE Action Regarding Implementing Effective Enterprise Security Governance - Outline for Energy Sector Executives and Boards, among other things, this paper lists the following "Characteristics of Effective Security Governance":
  • Clearly defined responsibilities from the board of directors to senior leadership to employees 
  • Presence of an active Security Governance board comprised of senior stakeholders from across 
  • the company 
  • An executive owner of enterprise security: with purview over IT, OT and physical security policy designated CSO or similar 
  • Striving for 100% alignment with of security with business/mission 
  • Using measurement of key indicators to increase awareness and drive improvement (with 
  • maturity tools like DOE's ES-C2M2

Then there's this from Reuters in May: Exclusive: U.S. companies seek cyber experts for top jobs, board seats, which emphasizes the concept of getting the security chief out of IT:
While a CISO typically reports to a company's chief information officer (CIO), some of the hiring discussions now involve giving them a direct line to the chief executive and the board, consultants and executives said. After high-profile data breaches such as last year's attack on U.S. retailer Target Corp, there is now an expectation that CISOs understand not just technology but also a company's business and risk management.
The Securities and Exchange (SEC) commissioner recently added his voice as well. In SEC Commissioner Calls on Corporate Boards to Address Cybersecurity, Commissioner Luis Aguilar  expresses his hope for governance improvements this way: “One would expect that corporate boards and senior management universally would be proactively taking steps to confront these cyber-risks.”

Then, from the International Association of Privacy Professionals online journal, there was Cybersecurity in the Boardroom: The New Reality for Directors, which included a list of recommendations, some of which have particular relevance for security governance and culture:
  • Develop a high-level understanding of cyber-risks facing the company through briefings from senior management and others
  • Ensure that the company has at least one committee that is responsible for overseeing and understanding cybersecurity issues, controls and procedures
  • Facilitate a culture that views cybersecurity as a business issue that all employees should understand and participate in. As part of that, companies should consider employee training and awareness programs
  • Include a cyber-expert on the company’s board of directors or receive regulator reports from a cybersecurity expert that are discussed at board meetings
So, as you can see, what once felt like a voice in the wilderness is now becoming a chorus.  Or you could say a trickle is becoming a deluge.  No matter the metaphor, will a little help from the Federal Government, and a lot more from The Real World, enterprise security governance is beginning to get the attention it deserves.

Image credit: Peter Skelton



Security Governance Ripples from Target Breach


You know the saying, if you want a different result, best not to keep doing the same thing. In this case, the result was the massive data loss breach involving loss of the records of 40 million customers at mega retailer Target.

In its wake, CEO Gregg Steinhafel stated that he is "elevating the role" of its chief information security officer and hiring outside the company to fill the position.  According to this NY Times article from early March, bringing on a new CISO will help Target centralize the company's security responsibilities.

And while the timing is coincidental, I owe Schweitzer Engineering Laboratories' Sharla Artz thanks for pointing out that Wisconsin based electric utility Alliant Energy Corp just made a similar move. For me, there are several promising parts to Alliant's announcement at the recent EnergyBiz conference that it had just:
Created an executive-level opening ... for overseeing cyber and physical security. The position was designed to bring cyber issues out of the weeds of the IT shop, where CEOs generally don't tread.
What I like best about this is:
  • The company didn't have to endure a huge security incident to justify this change to the org chart
  • The position is clearly not going to be buried in an IT silo, so it should have authority to set security policy across IT and OT
  • Reflecting a convergence that's happening in many energy enterprises, this new security exec will oversee both cyber and physical security
Hopefully we'll see more utilities make similar moves ... and soon.

Image credit: Michael Durham at fineartamerica.com

Singer & Brookings on the Security Governance/Ownership Vacuum

Analyst and author Peter Singer of the Brookings Institute has a new book out intended for everyman. And everywoman. To include particularly those types who consider themselves non technical, or as I've heard cyber folks in DOD refer to them - tech immigrants (vs. typically younger tech natives).

The net he casts is wide enough to captures senior government and business leaders too.  Below are excerpts from a recent interview with CNN/Fortune that really resonated with me, with particular applicability to our sector:
"Stop looking for others to solve it for you, stop looking for silver bullet solutions, and stop ignoring it." 
"I would argue that there's no issue that's become more important that's less understood than cyber. You can see this gap in all sorts of areas, including on the business side." 
"Cybersecurity and cyberwar questions are going to be with us as long as we use the Internet, so we have to stop being scared and start figuring out how to manage it. And when I say "we," I mean it's not just for the IT crowd anymore." 
"First, the people that sit in the C-suite, the people sitting on the Supreme Court, the people who are generals -- they likely didn't use computers when they were in college." 
"It's about getting the human side of this right -- the people and the processes and the way they fit in with the technology." 
"Whether you're working in the IT department or you're a lawyer or you're working in operations or wherever, you're increasingly going to be dealing with cybersecurity questions, whether it's managing people who work on them or figuring out how to protect yourself and your company from threats to your intellectual property, to your services, to your contract negotiations, or deciding "how much should I spend on this in my budget? Who should I be hiring?"
And for me this is the biggest / best one, especially for energy sector execs and boards:
"Most worrisome to me is the notion that this is for the IT crowd. This is for the nerds to handle. That's how it's been treated before: 'I don't understand this stuff so I'm going to hand it over to the techies' First, that's an abdication of leadership. Secondly, the IT crowd understands the software and hardware, but they don't understand the wetware. They don't understand the humans and the organizations and the ripple effects around them that are equally, and in many cases more, important."
It's a great roll-up of many of the awareness, leadership and governance concepts you've seen on this blog, but in a more visible medium.  Hope it sells well and gets read by lots of folks.

Co-authored by Singer and Allan Friedman, the book is called Cybersecurity and Cyberwar: What EveryOne Needs to Know.

Moving Beyond Technical: Use Security Governance Strategies to Integrate Security with the Mission

If like me you've come to the conclusion that a tech-centric strategy can only get us so far in energy sector cyber risk management, then you might want to see some of the source materials I've come across in my explorations.

The two I'll point to in this post are from Carnegie Mellon University's CERT program and PricewaterhouseCoopers' cybersecurity consulting practice.  What they have in common is that they are both several years old.  This is not VC or DARPA-funded cutting edge stuff.  It's human behavior stuff, and as such, it's not on an upgrade path anything like iOS, Android, or "Next Generation" firewalls. But neither are these concepts rapidly deployable, as you'd be hard put to find them put into practice widely at many utilities in 2013.
Nevertheless, for those wanting to achieve and communicate improvement in ours and other critical infrastructure sectors, here are some excerpts I've pulled out for you to consume more quickly.

Starting with definitions, this come via the CERT work, citing NIST SP800-100 - Information Security Handbook: A Guide for Managers:
Security Governance is the process by with senior leaders direct and control an organization to establish and sustain a culture of security in the organization's conduct, including behaviors, capabilities and actions. It includes establishing and maintaining a framework and supporting management structure and processes to provide assurance that security strategies:
  • Are aligned with and support business objectives 
  • Adhere to policies, standards, and internal controls 
  • Provide assignment of authority and responsibility 
All of this with the objective of managing cyber risk to the tolerances desired by that organization.
Then from PwC, instructing CISOs to "Define business objectives"
Collectively, the organization’s business objectives form the single most important driver of the security strategy. They are the basis of the arguments you will be using to communicate the business case for change and will help you prioritize initiatives based on business need. When determining your security strategy planning process, take care that it is explicitly mapped to the business objectives you have identified and carefully defined in terms of the benefits that will be used to measure project success.
More from PwC, coaching CISOs, this one's attributed to the then-CISO of Radianz, Lloyed Hession, now at Bridgewater Associates: "If you can’t talk ROI, the boardroom isn’t listening"
There are two types of metrics used by the CISO: those based on security criteria and those based on business goals. Those based on security criteria are a useful intradepartmental tool for evaluating performance, but they do not translate to the boardroom. For example, knowing the number of attacks detected or thwarted may be useful in evaluating your incident response and detection processes, but they tell the executive nothing about the dollar return on his security investment. 
Core message I get from these sources: align, align, align ... security policy with business objectives, and always translate 1's and 0's bits to 1's and 0's dollars/euros/pesos, etc.  There's much more if you want to sink your teeth into this.

Links: 


Putting all our Cybersecurity Eggs in Technology Baskets


Attackers perform discovery, surveillance, intrusion, denial of service and exfiltration with software tools. Defenders defend with tools of their own in the domains of network security, system security, application security, data security. The "good guys" also:
  • Encrypt data in hopes it will remain secret in transit and at rest
  • Patch and patch and patch and patch applications ond OSs
  • Pen test to see if they can find and fix weaknesses before the attackers do
  • Monitor and inspect network traffic and analyze logs for abnormalities
  • And oh so much more ...
Organizations spend millions on defensive technologies, purchasing and/or subscribing, deploying, integrating, updating and yet CISOs still have no dependable process for demonstrating to senior utility leadership the amount of cyber protection they're adding, or put another way, the amount of business risk accepted.

Recently we've seen the DoE and NRECA announce seed grants to help suppliers perform R&D for new technological solutions to cybersecurity challenges facing utilities. Some of these may prove useful to utilities, suppliers, and their services organizations.

Now I almost never use bold, italics or underlining for emphasis. Prefer to let the right words do the work.

But none are likely to substantially address the fundamental issue that cybersecurity threats are a hard-to-quantify risk to business, have human origins, and that improved human awareness and behavior can drive better outcomes in ways everyone can see and understand.

NERC CIP-004: "Cybersecurity - Personnel and Training" calls for humans who have access to critical cyber assets (CCAs) to have appropriate security training and awareness. But the CIPS cover only a very small part of the grid, and as we've seen, it's not just the folks who touch CCAs who can cause significant damage to an organization through their wrong actions ... or wrong inactions.

There are technology products that aim to effect improvements in human behavior (e.g. PhishMe). And there are universities and training organizations galore, some of them even beginning to add industry-specific operational technology (OT) content to their cybersecurity instruction.

And yet many utilities and the government organizations that seek to guide them continue to look almost exclusively to technology to save the day.  Here are two things you can do to begin to flesh out the people pieces:

1) Look at the org chart.  Look at how involved and cyber-aware are the board, the CEO, CFO, GC, etc. You could certainly argue they have bigger (or at least other) fish to fry, but if they knew a little more they might well move cyber threats a bit higher up on their ladder of strategic risks to reliability.

2) See how the CISO is empowered, where he/she sits in the organization, how often he/she briefs the board and corporate officers, and whether he/she has authority to set and enforce security policy enterprise-wide.

There's a lot more of course, but the closing pedantic message of this post, before it sprawls too long, is: don't short the human part of the cybersecurity equation. Humans are the problem, and humans can and should be a  much bigger part of the solution.

Photo credit: JS @ Flickr.com

Cyber Achilles Heal Afflicts Electric Sector (and other) Senior Leaders


Just for fun, let's begin with a few quotes from an article in yesterday's Wall Street Journal of the mind-blower variety:
Executives are disconnected from reality when it comes to IT and security.
Top leaders seem particularly inclined to do things their IT departments warn against, such as opening email from unfamiliar senders, or clicking on links.
During ... simulated attacks, top executives are 25% more likely to click on the links that in a real attack could install malware. One reason ... is that most senior leaders skip company programs on developing cautious email habits.
You can visit this WSJ page below for the full article and attribution.

But wow. What a cyber Achilles Heal we've got if the folks with access to the most important, most sensitive info in our companies are the easiest to scam into coughing it up.

Now pair these statements (like pairing wine with food) with my own recent experience with a large North American electric sector organization. Security staff acknowledged they had self phished the company once and found a strong correlation with elevated rank and dangerous behavior. 

As in, senior management personnel were much more likely than others lower down in the organization to click on the dumbest things, and even fill out and submit forms requesting login credentials, etc. The results were so damning there weren't sure they'd do it again.

Let me repeat and underline that last part: execs were more likely to fill out and submit forms requesting login credentials, etc.

This is pretty alarming, even for a non-alarmist. Time to wake em up or throw in the towel. Let's go for the former. 

Full article here: http://online.wsj.com/article/SB10001424127887323463704578497592337997354.html?KEYWORDS=%22security%22

Image credit: v3im.com