Get your CEO involved.

That’s it, you won’t need anything more than that, just get your CEO to take security seriously and everyone else beneath them will too. It does not matter if they actually CARE, but knowing that the CEO is watching you is usually enough to motivate every layer beneath them. Unfortunately, most CEOs either have no idea that they have this power, are too busy to give it a seconds’ thought, or are too arrogant to waste time on something so mundane.

You just have to look at human nature to understand why CEOs lack this particular vision; They ARE human, with all the usual faults, weaknesses, and insecurities. The only difference is that they happens to be in charge. They focus on what they know well and avoid the things with which they are either unfamiliar, or crap at doing.

Just like us.

What this means is that every organisation focuses on the things that mean most to the CEO. That’s fine, and the natural order of things, but it also means that the things that are equally important – sometimes even more so – get less attention. A CEO focused on innovation and not customer service will fail every bit as spectacularly as a CEO focused on profit and not the security of the data that is the foundation of it.

The thing that most people forget is that the majority cost of security is not capital (technology etc.), it’s the people who end up costing you more. From the wasted effort endemic to the reinvention of the wheel for every simple process, to the gross inefficiency of ‘Doing the way we’ve always done it.’, to the cleaning up of the mess after things have gone badly wrong, the people-element is where the good money is thrown after the bad.

And it’s all so simple. If you accept that it’s the CEO who sets the culture of an organisation, from the policies, to the priorities, to the direction, then they have the power, in a ridiculously easy way, to stop the waste. When the vast majority of security itself is also people and process driven, all the CEO has to do is pay a little more attention and these things become second nature to everyone within a remarkably short time.

Think of it this way; If your boss could not care less about something, how much do you care about it? Now imagine that from the very top down. Every time I’m at a new client the security program is a constant battle of middle-management trying to manage up. Unless the CEO manages down through his Executive Team (C-level), who in turn enforce culture at the department head level, no-one is going to do anything new.

So why not just title this blog; “Want to be Secure, Ask Your CEO to Help?” Be honest, would you have read this far, or, more likely, did the saving money aspect get your attention? You think the CEO is any different?

The greatest challenge we have in security is trying to talk the language of those in whose hands our success depends. Talk security or even compliance and you’ve already lost them, but talk increased efficiency, reputation protection, business transformation, or even financial control and you have a better chance of turning their heads.

But only from the top down.

I have already written on the myriad business benefits of a security program done well (How Information Security & Governance Enable Innovation, Security Done Well, The Ultimate ROI), but shockingly enough my 58 followers have not been able to change the industry as I had hoped. [embarrassed silence]

What I would like to see however, is every middle-manager in charge of a security program draft a email for their CEO to send out to the entire organisation, in which s/he stresses just how important security is to him/her. I think you’ll be amazed at just how much more receptive people will be to your security concepts.

IT and IT Security are here to enable the business, nothing more, but it’s usually the business that lets the side down.

Far too often, security is seen as a project, especially if PCI compliance is the goal. The requirements for vulnerability scanning and penetration testing are therefore seen as just another tick-in-a-box and their significant benefits lost.

External vulnerability scanning is the only requirement which must be outsourced and run by an approved scanning vendor (ASV, list here), the other requirements; internal vulnerability scanning, external penetration testing and internal penetration testing can by run by internal resources IF, and ONLY if, you can adequately demonstrate the requisite skill-sets in-house.

Of course, in order to save money, it is very tempting to skate by on the bare minimum, and unfortunately some security vendors (including QSAs) will allow you to do just that. Which is a shame, almost to the point of being irresponsible, as no other requirements give you a truer indication of your actual security posture than these.

Think of it this way; the bad guys use the EXACT same techniques to break into your systems that the good guys use to tell you what’s wrong. The ONLY differences between a hacker and an ethical hacker are intent and moral code, the skill-sets and mind-sets are the same.

Between vulnerability scanning and penetration testing, you have roughly 50% of your vulnerability management program sown up. Patch management management, risk management etc. make up the rest. However, the trick that’s almost always done poorly – if at all – is the integration of vulnerability management with asset management and change control. Any change to your environment should have appropriate vulnerability management processes around them, from a quick directed scan to a full blown credentialed penetration test, and all should be in-line with agreed configuration standards (as defined against each asset).

Going above and beyond PCI in scanning and pen. testing is relatively simple, but it’s not cheap in terms of resource cost. It also demands a maturity of process and a significant shift in culture to accept the ‘overhead’, but it’s more than worth it:

1. External Vulnerability Scanning – No choice but to use an ASV, but you should choose a vendor that provides 2 things at either no, or little, extra cost; Monthly scans (PCI requires quarterly), and unlimited directed scans (against single IPs, or subnets). Performed correctly, monthly scans and directed scans initiated by change control processes go significantly above and beyond. Note: For PCI do NOT open your external firewall/routing devices to your ASV’s IP addresses. Why would you decrease your security posture to test your security posture? Just run one scan for PCI, and THEN open your firewalls so that scanners can do a more thorough job. Keep these profiles separate, one for PCI only, one for your entire business.

2. Internal Vulnerability Scanning – You can do this yourself, and I’ve lost count of the number of clients running basic installations of Nessus, but unless you have significant expertise in how to configure it AND understand the results, don’t do it. For a start, any good QSA will fail you for lack of expertise, but do you really have the time to keep it up to date? Again, running internal scans monthly and as directed by change control goes above and beyond. Having two scan profiles is also a nice feature, but if the scan engine is capable of doing more than just rattle the windows (in the ubiquitous house analogy) and can actually perform a deeper scan / reconnaissance, then you have knocked this one out the park. PCI compliance is never security, do internal scanning as far above PCI minimums as you can afford.

3. External Penetration Testing – PCI requires that you attempt to break in (without breaking) via your Internet-facing presence, but poor guidance on what the test should consist of, combined with an enormous price-compression of pen. testing services means that this effort is usually more automated than I would consider appropriate. A pen. test is supposed to be a person with the necessary skills trying for days on end to discover ways into your systems. This is rarely the case now, but is EXACTLY what your should be doing. The Internet is where most breaches originate (used to be internal), so having a VERY robust security posture from the-outside-in is of paramount importance. Do NOT skimp on this one.

PCI calls for annual pen. tests, and to go above and beyond you need to perform these more frequently. This should not be an enormous cost, and most pen. test vendors can provide an infinitely scalable service based on scope and call-off days.

4. Internal Penetration Testing – Same premise as the external pen. test, but this time from the inside. PCI requires that this test simulate an attacker ‘plugging in’ where the admins sit and seeing what they can do from scratch. Above and beyond is therefore very simple; give the pen. tester FULL access to the environment, as well as credentials to go even further where appropriate. Like scanning, you have one test for PCI, then another test for your business.

There will be times when a simple vuln. scan of a system that has undergone change is not sufficient, so having a directed pen. test process available for critical business changes is very important.

None of the above processes should be stand-alone concepts, and should be very tightly integrated with risk assessment, change control and asset management processes to be truly effective. Vulnerability Management represents the end to each cycle of your security program (Plan > Do > Check > Act > Repeat), and ensures that your security posture always remain in-line with your business goals.

It bears repeating, do NOT skimp on this requirement, you will pay far more when you have to clean up the mess after a breach.

For those looking for a considered, well researched, and unbiased post on the ACTUAL evolution of privacy, you will be disappointed. This is an opinion piece based on my own theory of WHY people want privacy as much as they do, and whether or not they truly understand its implications. Well, my interpretation of those implications anyway.

I do not believe human beings to be either civilised, or that intelligent. We’re heading in that direction, but need to get out of our own way first. From a continued reliance on religious dogma, to a universally accepted misunderstanding that we are more than just another mammal, to the overwhelming prevalence of ignorance, we are no closer to any form of enlightenment than were the people ~1,000 years ago in what we call The Dark Ages. 1,000 years from NOW we will be seen as The Dark Ages – Part II, and you just have to read the news each day for a hundred examples of why.

So what are the benefits of privacy? Why did we evolve the concept of privacy to the point now where it’s a Human Right ratified by the UN as Article 12; “No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.”

As far as I’m concerned, the only reason for this is that NOT having privacy puts you or yours at some kind of risk. Regardless of our sentience, we ARE just animals, and subject to the exact same primal urges as every other mammal. The need for food, water, sex etc. are at the base of Maslow’s Hierarchy of Needs, but security of body, family and property is only just above them.

If we had truly evolved as a society to the point where these basic needs are provided, there would be little need for privacy. If we didn’t go through life knowing that our ‘secrets’ could be the cause of ridicule, alienation, resource loss, or even physical harm, then the requirement to keep-it-all-to-ourselves would be unnecessary. But we are still in the position where the bad outweighs the good, and the ignorance perpetuated through religion, sex / sexual orientation / colour biases, and political doctrines ensures that these fears are far from unfounded.

The challenge we face is that privacy is one of the biggest reasons we HAVE a perpetuation of ignorance. Human nature does not fall on the side of trust, what we don’t know scares us. At its mildest form, this mistrust keeps us from having as many friends as we’d like, at its extreme, we end up trying to destroy what don’t understand.

All human interaction is based on one thing; trust, and no-one trusts words, only actions. For example, if I was to open my life up to detailed scrutiny, then recorded the results of that scrutiny in a way that’s irrefutable, everyone who ever met me, for any reason, would know exactly with whom they were dealing. My values, level of integrity, likes, dislikes, aspirations, biases and so on would be my permanent and openly available CV/resume. Business partners, employers, potential friends, ANYONE would be able to make a fairly immediate decision as to whether they wanted to proceed. Even if they didn’t LIKE what they see, which is entirely possible, they’d still know enough about me not to be scared of the unknown.

If nothing else, it would save a great deal of time never talking to someone with whom we fundamentally disagree, or whose personality is one we would find offensive.

Finally, if we all have the right to privacy, then NO-ONE has the right to complain about those with bad intentions using it to cause harm. Until Human Rights are a currency – which they should be – our evolution as a species will be stunted by fear, uncertainty and ignorance.

[If you liked this article, please share! Want more like it, subscribe!]

Who has seen a “Zero Malware Guarantee“, or something like it?

More to the point; who saw this and thought what a load of bull$#@?

Anyone who knows even the most basic aspects of information security knows that the ONLY guarantee is that nothing is safe. Ever. To throw out a word like guarantee is nothing except the most despicable attempt to drive business in a field where the experts are SUPPOSED to be trusted!

What is the guarantee?; …to detect and stop 100 percent of malware that propagates over the web and is scanned by the [blah blah] Managed Anti-Malware Service“. Could this ‘guarantee’ be any more pointless? Who wrote this? Lawyers?

What’s worse, here’s what you get if they fail to detect and stop 100% of the malware; “…one-month extension of the service at no cost, up to four times per year.“.

Seriously? It didn’t work, but you get one more month for free? And why would you possibly need to do this FOUR times in a year? Would you seriously still pay for the service after a second failure, let alone a third?!

Doctor to dying patient: “The drugs we gave you aren’t working, but here, have some more on the house.”

Surely if the product is that good, this vendor and vendors like them (there are many) should WARRANTEE their products. “If we screw up we’ll pay for the fix AND give you your money back.” Now THAT’S something I can get behind!

You can guess how often that will happen.

The reason this is so offensive to me is that security is already seen as something to spend money on only because you have to. Like insurance. And this crass commercialisation of yet another security PRODUCT just makes everyone in the information security field look like ambulance chasers. Incompetent ones at that.

Eradication of malware (as in the above example) STARTS with policy and procedures, continues on with parallel efforts in security awareness training and control definition, and is maintained by a security program done well. Just like every other aspect of security. So the only reason security companies keep coming up with these snake oil ads is because people keep buying stuff from them.

Don’t. Do. It.

I can empathise with organisations struggling to understand security and buying what they think is the right thing for their business. What I cannot even begin to condone is any organisation selling something TO those organisations when the seller damned well DOES know better!

You never need guarantees in security, you only need appropriate security. You can start by avoiding any organisation that begins with making empty promises.

[If you liked this article, please share! Want more like it, subscribe!]

From everything I have seen in my many years performing PCI assessments, logging is not only one of the least understood of the requirements, it is the most under-utilised, and the one that gives/gave my clients the most pain.

Logging is the most important detective security control you have, bar none, and done correctly, logging is the foundation of your incident response program. Notice I didn’t say ‘disaster recovery’ as well, because if your incident response was where it should be you should not HAVE to recover from a disaster.

The confusion stems mostly from a lack of understanding of logging mechanisms themselves, even for Windows (for which PCI was clearly written). For example, do you think that Windows logs to the PCI requirements out of the box? I did too, but have been assured that it does not. Do you know HOW to get it to log appropriately? No, me either.

I have been further assured this if you WERE to turn logging on to cover the 10.2.X requirements, the logging would be so verbose as to render the device that’s doing the logging useless. Is that really the INTENT of logging? Of course not.

Also, can syslog EVER record the events required in 10.2.x, or even the event content as required in 10.3.x? Once again, I have been told no, but I am no expert.

Yes, you SHOULD have people who DO know this stuff, but how many organisations out there can truly afford that kind of deep expertise in-house? Yes you can outsource, but where is the guidance on EXACTLY how to configure operating systems to log to the PCI requirements? It probably exists, but in 10 years of doing PCI I have not found it, and I’ve even asked ‘experts’ in the field; Security Incident and Event Monitoring (SIEM) vendors. On that note, I have yet to see a SIEM vendor also be an expert in PCI, which to me is an absolute joke if that’s why they are selling it to their clients.

We have free hardening guides for Windows (CIS Security Benchmarks for example), but where is the guide that breaks down the Windows operating system into a mapping between the registry settings for logging and the PCI DSS? Or *nix flavours, or Cisco, or AS400, or Power Series? If you have them, please share?!

So let’s, for the sake of argument, assume that you cannot reasonably log to the letter of PCI, or more to the point, you do not WANT to for usability issues. Are you non-compliant? Let me answer that with another question; What’s more important, configuring your logging to record events for a forensics investigation, or configure your logging to help prevent a breach in the first place?

If you chose the second one, you are correct, and if you also choose to maximise your logging mechanisms, you will not only be PCI compliant to its intent, you will also be doing security properly.

First, logging is not about crunching masses of data through a correlation engine, its about the RIGHT data put into a base-lined context. There is no such thing as log event correlation without a deep understanding of what the end systems SHOULD look like, AND what your normal business processes are from start to finish. In other words, tell any vendor trying to sell you compliance though their SIEM, to put it where the sun don’t shine.

While we’re on the subject of SIEMs, how many of them do you think can accept Windows logs natively, or have to convert the logs to syslog via an agent (e.g. Snare)? Very few. What’s the point of buying a log mechanism that cannot even read WINDOWS events without butchering them DOWN to syslog?! You MUST ask the right questions before buying ANYTHING, especially a SIEM.

OK, so how DO you go above and beyond? Simple, in one way;

Do NOT perform your log reviews daily (10.6), because that’s just plain stupid, not to mention impossible to do adequately. Perform log reviews in real-time via some form of automation.

The automation you need is threefold;

  1. Events you should NEVER see: Each system admin, from OS, to network device to application SHOULD know which they events should never be seen under normal operating conditions. Look for these ‘strings’ and alert immediately.
    o
  2. Events you should not see in a certain quantity and velocity (i.e. thresholds): I don’t care if I see an admin fail to log in once, I do care if s/he fails 10 times in 2 seconds (for example).
    o
  3. Quantity of events over the course of time (i.e. trending): You have to save logs for 1 year (DSS 10.7), so why not put them to good use by trending events over time? Even if it’s just quantity of event (as opposed to quantity of type of event per device), the information you get can be extremely useful.

Perform all three of these things, and you have not only covered the ridiculous ‘daily reviews’ automatically, you now have input into your incident response mechanism that gives you real security.

Choosing the right centralised logging mechanism for your business is one of the most important decisions you can make, and it cannot be done ONLY for PCI. You must buy a system that can cover you enterprise-wide, and unless you have significant in-house expertise, you must build into the RFP the requirement for consulting support, and potentially some form of on-going managed service. Nothing stays the same, so your future state / needs will also need to be taken into account.

Do NOT penny-pinch here, but don’t buy anything that’s not appropriate. Your risk assessment process should tell you exactly what you need, and if you’ve not done one, start there.