Or to put it another way; a life without trying much of anything new.

Just to clarify; I’m not saying it’s a bad thing to be content with your lot in life, and not wanting to try new things. In fact, I almost envy those people actually.

Almost.

But if you accept this as the definition;

REGRET
verb
1. feel sad, repentant, or disappointed over (something that one has done or failed to do).

…then it’s fairly clear – to me anyway – that if you don’t have any regrets, then you have either not done much, or you have no remorse for the bad things you did do. And we have ALL done something bad to someone at some point.

So the cliched advice to ‘live your life without regrets’ is frankly impossible if your existence is even remotely eventful. No-one is perfect, no-one gets everything they have ever wanted, and not every failure in life can be tacked up to a mere ‘disappointment’.

Not only have we all done things we wish we hadn’t (even if takes years to realise it), we have also likely had many instances of wishing we HAD done something but now it’s too late. If neither of these are true for you, what the Hell HAVE you been doing with your time? Living a perfect life? Lucky you, but for the other 99.9999…% of the population we are left dealing with consequences.

But here’s the rub; I’m not only glad I have regrets, but I actually look forward to collecting more, because it means I’ve put myself out there and I have been in positions to make decisions I can regret.  I have lived a relatively unspectacular life and have hundreds of regrets, all of which were experiences I would not trade for anything.

I am what I am now because of my mistakes and my successes, and am therefore defined not only by all of the good I’ve done, but by those regrets. Basically they make me human, they make me real.

For example; I’m at this moment happily married (my wife might not be), have a job that is ridiculously cool, loving family / friends, and enough money. But all of this was built on the foundations of countless train-wreck relationships, disastrous career moves, and a great deal of pain. My own, and the pain I’ve caused others.

To have no regrets now, or in the future, suggests that I have everything I want (I don’t), that I’m not sorry for some of the things I’ve done (I am), and that I will make no more mistakes for which I WILL be sorry down the road (I undoubtedly will). It means that I’m moving forward, I’m exercising my ‘…right to life, liberty and security of person.’ and that I will always accept responsibility for my mistakes.

But I’m proud to say that I have NO regrets based on unfulfilled wishes, mine are all based on things I didn’t do, did do, or on goals I have failed to reach [yet]. There is no room for fantasy or ‘if-onlys’ in a life of accountability and one well lived.

On the balance, I have a GREAT life, and I already know what my next regret is going to be; tomorrow’s hangover! 🙂

[If you liked this article, please share! Want more like it, subscribe!]

This is often where an assessment starts going truly pear-shaped. Mostly because of assumptions, but a large chunk of what makes validation of compliance so difficult is the lack of mechanisms to make it anything other than a manual process. There is no requirement for automation in PCI, so going beyond the standard is very simple.

First, let’s start out with the worst assumption; that sampling is a right. It’s not, it’s a privilege, and one you have to earn. Until you can show your assessor that you have ALL of the following in place, sampling isn’t even an option:

  1. Formalised, and Robust Configuration Management – Unless you can show that you have a VERY good handle on configuring ‘like systems’ in an identical fashion, sampling cannot be performed. All web servers, app servers, DB servers etc must start out exactly the same. From installation from a known-good base image, to configuration of applications, to testing through change control prior to promotion into production, there is no room for ad hoc here.
    o
  2. Centralised Management and Maintenance –  You must be able to show your QSA that you have the ability to KEEP your like-systems identical, so if you have a centralised console where this can be displayed, so much the better. WSUS for Windows, or CiscoWorks for Cisco network devices for example, can centrally display pretty much all you need to know about the systems. OS, version, patches and so on.
    o
  3. Centralised Logging and Monitoring – An extension to management, log baselines, like-system thresholds, and incident response etc. must be centralised or every different monitoring process must be examined individually.

Of the three facets above, PCI does not require any of them to be centralised, not even logging, so if none of these things are in place, there is no sampling.

An operating system has 12 validation points (access control, password setting, logging and so), applications have 9, and a DB has 7. In theory, a single system could require 28 separate pieces of evidence to validate its compliance.

What if you had a 100 of these systems?

I have expounded many times the concept of security being simple, not easy, but simple. Well, there is no simple without centralisation, and it’s VERY difficult to achieve simple without some form of automation.

For PCI, a screen shot of the AV [for example] settings will suffice, but this can involved the collection of MANY screenshots. How much better to have a centralised management station that shows these settings against all systems in one place? The same applies to logging, access control mechanisms, FIM, running services / listening ports (i.e. configuration standards) and almost every other validation requirement at the system level.

In the hundreds of assessment with which I have in some way been involved, I would estimate that between 25% and 40% of an assessment’s effort is related to gathering of validation evidence. That’s in year one, it’s actually greater in subsequent years, but the effort to get to the point of validation SHOULD have been less.

But that’s really the point here, and the point of the SSC’s recent supplemental on staying compliant; if you treat validation of compliance as a project, you are wasting a significant amount of resources AND you are no closer to actually being secure.

Compliance requires no automation, but without it you have no continuous compliance validation. PCI requires no centralisation, but without that you simply cannot manage what you have efficiently and effectively.

Validation is easy when your security program is simple, because the management of your program is simple. Spending weeks collecting evidence for compliance could not be a more ridiculous use of your time.

Simple is cheaper, more efficient, easier to manage and measure, and above all, more secure. Validation of compliance falls out of the back of a security program done well, so work on that first.

 

 

This is perhaps the most pointless concept I’ve written about to date, but hey, it’s my blog! 🙂

Premise: The ‘social ideal’ is clearly an average of all things, and therefore cannot be labelled one way or another. It’s neither good, nor bad, neither right, nor wrong. But no-one is average, and that’s where the challenges start. We humans need labels for context, and very, VERY few of us are perfectly content for things to just ‘be’. Too few to make a difference anyway.

Unless you’re a creationist, you believe in Darwin’s theories of evolution in some form; that of natural selection. It stands to reason – or at least argument – therefore that ANY human trait that provides a distinct advantage, should eventually become more common.

For most of human history, physical strength was the preferred trait, then cunning made its play, and now it seems to be a combination of intelligence and earning potential.

But what happens when new traits fall too far outside the socially acceptable norms? At our current level of evolution (I think we’re actually going backward now) we know what happens; we attack and destroy it because we fear what we don’t know.

Then there’s the law, which sets as many of the societal norms’ as they can lay their hands on. Yes, it’s for the common good, and yes, law should have replaced organised religion a long time ago as our moral barometer, but we still have both, and they are – in my opinion – mostly opposed in almost all facets except the biggie; a way to control the masses.

If those with a genetic pre-disposition to obey the societal norms (i.e. the laws) thrive, totally unhindered, should that trait not take precedence? Or from the other direction; if we lock up all the criminals thereby taking them out of the gene pool, would not those traits become less prevalent?

The thing with genetics is that you are always going to have vast differences between individuals, and you will never eradicate those genetically predisposed to rebel against ANY norm, no matter how good that norm is for society as a whole. I don’t think anyone will argue a case for convicted murderers or rapists, but what about those on the fringe? Where do we draw the line between acceptable and that which must be eradicated? More to the point; WHO can draw that line?

Religion had its place once (even the concept of marriage made sense by making men responsible for taking care of their offspring), but in my view, once religion BECAME man-made laws, there can be no higher purpose than that of the betterment of the species. If you read the news this is clearly not our current goal. The Matrix said it the best;

Every mammal on this planet instinctively develops a natural equilibrium with the surrounding environment but you humans do not. You move to an area and you multiply and multiply until every natural resource is consumed and the only way you can survive is to spread to another area. There is another organism on this planet that follows the same pattern. Do you know what it is?

A virus.

If you accept that we are VERY far from perfect, then surely the new genetic combinations that happen every day should be nurtured, not shunned? And I’m not saying it’s the law’s FAULT that we demand ‘normal’, but the constant striving for average / normal / acceptable will surely slow down our growth to a more advanced (and sustainable) species?

Of course I’m not saying that we should embrace violent criminals, but we should certainly embrace both the different, and the changes necessary to get where we need to go.

[Apologies for the blank post yesterday, here is the real one]

The timing for this part of the Going Beyond the Standard series is almost perfect given the SSC’s release of their ‘Information Supplement: Third-Party Security Assurance‘. Which, despite it’s gratuitous use of the word ‘may’, and the ongoing generic-ness of the SSC supplements, is actually pretty good.

It has always irritated me that the phrase ‘third parties’ is now the established norm in these scenarios, when it’s actually SECOND parties that create the most challenges;

third party
[noun]
1. a person or group besides the two primarily involved in a situation

So third parties are the service providers that YOUR service provider hires to do [part of] the work for which you (the first party) hired the original provider. Third parties are fairly common, but not as common as second parties, and while third parties ARE an issue, they should be addressed in the same way as any other outsourced service; with proper due diligence.

Unfortunately, this due diligence is almost universally performed badly, or there would be no need for the SSC to issue an information supplement in the first place. Or course, if the requirements in the PCI DSS were written better perhaps there would be less confusion, but it’s too late now.

Because the supplement is quite good, I’ll not go into the nitty gritty of vendor management, but it is important to realise that the choice of an outsourced service does not start with vendor due diligence, it starts with a business need that has been PROPERLY analysed, and a risk assessment performed.

PCI itself has driven an enormous growth in outsourcing, and not because there was suddenly a need for more services, but because so many organisation wanted PCI to just go away. The thought was if you outsourced, you could just point at them and shirk all further responsibility.

In reality, you can outsource almost every function relevant to PCI, but you can NEVER outsource the responsibility for the protection of the cardholder data. Yes, you can throw financial liabilities into the contract, you can buy cyber-insurance, you can even drag your service provider down with you if things go horribly wrong, but it’s going to be YOUR name in the papers.

The other big mistake organisations make at the beginning phases of outsourcing is, as always, asking the wrong questions. While a service provider does not have to BE PCI compliant for the service they are providing, their services have to SUPPORT yours. Not only that, if they do not have a Report on Compliance backing up their services, they will have to be fully assessed and validated against yours.

I’ve had small clients whose PCI assessment costs and effort increased FIVE fold because they had not performed the correct due diligence.

Even if I assumed you are outsourcing for the right reasons, CHOOSING vendors is next step where things go wrong. DSS v3.0 has built in the requirement for  ‘third parties’ to qualify their services with detailed analysis of EXACTLY what is being provided against the requirements themselves. This was always a requirement in my mind, but rarely followed, and has led to significant gaps based on assumptions.

However, if if your chosen service provider is PCI compliant for the services, there is surprisingly little they can do in terms of reducing your effort;

1. DSS Requirement 1.x – You can outsource management, but you will always own the policies, the final configuration standard(s), and of course, the ruleset(s). About the only things that can be 100% outsourced is stageful packet inspection.

2. DSS Requirement 2.x – Again, you can have a service provider put together configuration standards for you, but you will always own them, the business justifications for every available service and listening port is yours to document, and insecure protocols are yours to fix or compensate for.

3. DSS Requirement 6.x – Outsourced development is great, but unless their SDLC supports your compliance, YOU won’t be.

4. DSS Requirement 10.x – The most egregiously overstated service provider coverage of them all. The issue is rarely in the collection of the events, it’s what events should be logged in the first place and how. And how ANY service provider dares to say they can cover a daily review without establishing a baseling is beyond me.

5. …and so on.

I’m already ay 700 words and I’ve barely starched the surface, but that should be an indication of just how messy this topic can be. It deserves a white paper, but that will have to wait.

Bottom line; If you don’t have a program for vendor selection and vendor management, get one, and make it retroactive. Get help if you need it, but in the end, if your service providers fail, YOU fail, and deservedly so.

Read the SSC supplement, implement what it says, they have not missed much.

If you have not heard about the ALS (Amyotrophic Lateral Sclerosis) Ice Bucket Challenge (#IceBucketChallenge), you are not reading this blog, because you clearly have no phone, no computer, and no friends. It’s a viral sensation that has seen the contributions for ALS charities rise by over 1000% over last years numbers. And growing.

Before I begin, know that I am VERY much in favour of this, have done it myself (dedicated to a friend of mine who has ALS), and hope it continues until such times as ALS charities have enough money to finally buy a cure.

Now the down side, and the unfortunate point of this blog; The giving will not continue much longer, because the only thing faster than a viral topic, is its relegation into permanent obscurity.

This will not cause a fundamental shift in either our individual attitude towards charitable giving, or how charities do their fund-raising. This worked once, now it’s done, and ALS were the lucky recipients. It could have easily been Children With Cancer, or pretty much any other charity, because it’s not the disease that caught our attention, it was everyone else’s attention to the challenge that caught our attention.

But why?

Why does it take something like this to get us to give in the first place? I say US, because I absolutely include myself. I am one of the majority walking right by people holding charity buckets looking to help causes that I cannot be bothered to read. Headphones in, eyes down, my destination and my own problems effectively crowding out any thought of those less fortunate.

Does this make me a bad person? No, it makes me average, yet if you don’t do the Ice Bucket Challenge you are treated as a social leper. Our hypocrisy knows no bounds, it seems.

Yes, this is a cynical view, and I have absolutely no desire to dampen anyone’s enthusiasm, but I think it’s time for a little perspective before the true, more permanent advantage, is lost. However unattractive and un-charitable that advantage may seem, only the results count.

The truth is, unfortunately, an equally cynical proposition; that empathy is in short supply in the average human genome, but fear of being ostracised is not, nor is the need to avoid the feeling of guilt. This is why the ALS Ice Bucket Challenge went viral, and this is where most charities go wrong; they are simply not cynical – or smart – enough to manipulate either the right emotional drivers (which are seldom even approaching altruistic), or social media.

Perhaps this is the wake up call to realise that it’s really not about awareness of the disease itself, it’s about getting contributions. This is not only perfectly OK, but far more honest, and much like a homeless person’s sign”Will work for alcohol.”, when it comes to charitable giving, the end often justifies the means.

Think I’m being TOO cynical? Go and ask 10 people who have done the ALS challenge, what ALS is the acronym for, and I will be willing to bet at least half of them will not know. Ask again in a month and even fewer will.

But that’s OK too, as long as they gave, AND got 3 others to give, when prior to the challenge they had probably never heard of ALS (or its regional equivalents). This was the true genius of the ice bucket challenge, as ALS is no more deserving of either attention or money than a charity fighting children’s cancer. Just ask a friend of mine whose 5 year old daughter is fighting brain cancer where her priorities lay.

The fact is that most of us have a very limited capacity to focus on things that do not affect us directly, but when confronted in the right way, and hopefully with humour, we are ALL very generous. That we don’t give as much as we should the rest of the time does not make us bad people either, it just means those amazing individuals who have dedicated their lives to helping others need to make giving easier, and more in-line with what makes US feel good. More fun preferably, but at the very least, more interesting.

That’s sad, but inescapably true, and it’s time we embrace it.

In the end, it does not matter where the money comes from. Ask anyone with ALS if they care whether or not the cure came from someone who cared or someone who didn’t give a damn. Only getting better matters.

So if you did the challenge, that’s great, but keep your condemnation against those who didn’t to yourselves, your single act of generosity gives you no right to judge, and they may have other obligations of which you have no concept.

And charities, wake up, people will give a lot more if properly motivated, and I am more than happy to be taken [along] for the ride.