Everyone loves toys, and IT/IS administrators are no different. However, it’s a very different thing to buy a new PlayStation for yourself, than it is to spend a considerable amount of your company’s money chasing after yet another buzz-phrase or a vendor-induced panic.

Worse than this is to mis-interpret a regulatory compliance standard (like PCI) and spend all your IT budget on technology, when the vast majority of these standards revolve around policy, procedure and standards. Like security should. Behind every security control, in every regulatory standard, is an intent, and until you have examined what that intent entails for your business, you simply have no justification buying anything.

Both IT and IT Security departments have only one purpose; to enable the business’s goals. That’s it. However, it the business’s responsibility to make those goals VERY clear, and fully support IT/IS when required. This does not happen without robust Risk Management process(es) maintained by a Governance Committee of some sort.

In every organisation for whom I have provided security guidance, they had the exact same dynamic; IT/IS massively overestimated their budgetary needs knowing full well the business side will reduce it as much as possible. Usually to point of making a lot of departments ineffective in any way that matters. Then things like PCI come along and suddenly IT/IS departments have ammunition to up their budgets to meet a supposed business requirement.

The smartest managers used this money to do things properly knowing that PCI compliance will fall out the back end of a security program done well. The majority however line up behind the security vendors like sheep buying exactly what PCI says. Every vendor of firewalls, anti-virus, DLP, FIM, IDS and all the other acronyms have made fortunes while the actual security posture in most organisations has barely improved, if at all.

Any consultant worth his/her salt has stopped a client from buying technology until they are satisfied that the client has the necessary processes in place to determine the ACTUAL need, perform a gap analysis, and exhausted all other options. That consultant also had in mind that buying ANY technology comes with a whole series of post-purchase events that must be complete in order to obtain any benefit from that purchase;

  1. Can existing staff actually USE the technology, or does some / all aspects of it’s running require outsourcing?;
  2. Does the product integrate seamlessly with the existing infrastructure management systems?;
  3. Is the increased security posture in-line with its on-going cost of ownership (management metrics)?;
  4. Has any thought been given to the products life cycle and future-proofing?;
  5. Does the product scale with the business?

…and so on.

The ages old (but still completely relevant) concept of Confidentiality, Integrity, and Availability (C.I.A.) ensures that every security program follows the law of negative returns; the more you have of one, the less you have of the others. This is equally true of the complexity of your program; the more complex your program, the less secure you are.

Technology has its place, no arguing that, but only technology in a business context is sustainable.

[If you liked this article, please share! Want more like it, subscribe!]

First, let me be clear; I hate anti-virus. I guess more accurately, I hate anti-virus companies who are still making squillions peddling their no-longer-relevant wares (in my opinion).

Blacklisting (i.e. signature based) end-point protection is meaningless and almost completely ineffective against zero-day attacks. It’s a game of constant catch-up that can (and will) never be won. Yet here we are, still buying anti-virus software because we don’t know better, and standards like the PCI DSS still call for it by name instead of dealing with the actual underlying issue.

What is the INTENT of anti-virus?  According to the DSS, you should;

5.1 Deploy anti-virus software on all systems commonly affected by malicious software (particularly personal computers and servers).

…and;

5.1.1 Ensure that anti-virus programs are capable of detecting, removing, and protecting against all known types of malicious software.

Commonly affected? As defined by whom? Clearly they mean Windows but can’t just come out and say it. Yes, other OSs are becoming increasingly affected by viruses, but would you call them common? More to the point; if you had to install and maintain anti-virus on all of your *nix and Apple products would YOU classify them as ‘commonly affected’?

No, neither would I.

The intent of anti-virus is sound; do not let bad stuff run on your systems. However, if you were doing security properly, would this not be basically redundant? Even PCI includes the means by which anti-virus becomes [in my view] excessive;

  1. Security Awareness Training (Req. 12.6) – If users were properly educated, a huge chunck of malware outbreaks would not happen in the first place. If your organisation does not have a very robust program for ongoing security training, they have missed the cheapest, and most effective security control that has, and will, ever exist. Ignorance is a choice, never an excuse.
    o
  2. Configuration Standards (Req. 2.x) – In my continuing theme of never backing up bold statements with actual facts, I will pronounce that the majority of malware out there is ONLY effective because the systems on which the malware is loaded are not configured correctly. Either the hardening guides are absent or inadequate, or the ongoing maintenance of the configurations was neglected.
    o
  3. Vulnerability Management (Req. 6.1) – If all you are relying on is patch releases from your OS vendors, then you deserve what you get. Vulnerability Management is everything from Patching, to Vulnerability Scanning, to Penetration Testing, to Change Control and Incident Response. Done well, vulnerability management is the only way you stand even half a chance of keeping up with the bad guys, but something I have personally never seen done well.
    o
  4. File Integrity Monitoring (Req 11.5) – Don’t buy Tripwire (I hate them too), but figure out a way to detect if a known-good file changes in some way. I have seen a client write an MD5 recursive hash on system32 and write the results to event logs for monitoring. It was free, and effective, but required significant expertise. All you’re trying to do here is make sure things stay the same, and it almost begs the question; Why have AV at all if you have FIM? This question becomes far more relevant the more of these points you master, but I will never negate the concept / cliché of defence-in-depth.
    o
  5. Logging & Monitoring (Req. 10.x) – In my opinion, nothing in your detective security portfolio is as important as this control, and can be used to create the most effective and ‘blanket’ compensating control for PCI there is. If you know what every system SHOULD be doing, anything NOT that is something to investigate. Daily review of log files is a farce, only real-time alerts triggered by base-line deviations makes sense, and should be the top of any organisation priorities to get right. Few do, and the majority of Managed / Cloud Security Services don’t do this either.
    o
  6. Incident Response (Req. 12.9) – Why bother being in business if you don’t intend staying in business? Incident Response can prevent an event from becoming a business crippling disaster, yet, like Vulnerability Management, is almost universally neglected. Do this one badly and I for one have no sympathy.

You should notice one unifying theme across all 6 of these controls; they have a significant process component, not technology. Most security is process, and yet PCI has driven more technology spend than all other compliance / regulatory standards in history combined (yes, that’s another fact-less statement, but I would be amazed if it wasn’t true). Anti-virus vendors, FIM vendors, logging vendors (and QSAs of course) have all made multi-millions from PCI, and not one of these vendors (including the QSAs) has ever made the effort to put their products into the proper context; A business focused solution that provides true benefit. Staying is business  IS an ROI!

All 6 factors will be addressed in their own Beyond The Standard posts, that should give some indication to their importance.

OK [deep breath], end of rant (and my longest blog of the series yet)! I’m not saying don’t use anti-virus if you believe it provides true benefit, and is not a massive capital / resource drain. But do NOT do it just because PCI says you should, do NOT rely on it, and focus your efforts on the above 6 factors as they are the things that actually meet the intent.

If you are only doing PCI minimums your QSA probably has no choice but to insist on AV (especially for Windows), your job is to give them an alternative.

How much food do you throw away each year because it’s past the expiration date, or worse, you find it in the back of your fridge supporting a new furry ecosystem?

In my ever extending string of blogs based entirely on speculation, I would say that I throw away in the region of £400 – £600 worth per year. And I’m not saying it’s my wife’s fault (certainly not to her face anyway), although she does all the grocery shopping and cooking (don’t worry, it’s not like that, I do pretty much all the cleaning and jar opening). 🙂

There’s actually no blame here, it’s just that way WE are. We are not planners when it comes to our weekly meals, which would alleviate much of this issue. But, like everyone else in our brave new it’s-not-my-fault,-someone-else-should-do-something-about-it society, I want to have this take care of itself, automatically.

We can, and I believe we are not that far off, it just needs to be put together.

First, the actual growers of the produce need to take the first step by ensuring that their shipments are labelled with enough information to begin the countdown process. i.e. from ripe to rotten, we should by now have a pretty good idea how long a lettuce (for example) is going to last. I don’t care if it’s organic (which will clearly reduce its life cycle), with refrigeration, preservatives, and whatever else happens to our food without our knowledge, from farm, to supermarket shelf, to your fridge, to your plate, the lettuce has only x days to live (plus or minus).

Let’s say this is done with a QR tag, and each step in the logistics is added to the embedded information, by the time you scan the code in the supermarket you will have at your fingertips all the information you need to make an informed decision related to your purchase. These lettuces in this box are 2 days newer than those ones, but the older ones are half price and so on. Instant coupons is a given.

I won’t go into the payment method, I’ve written enough on the future of payments, but you will not only have an instant receipt, you have automatically added these items to a database of all the food in your house, along with its weight / quantity, expiration date, and so on.

Now everything edible in your house, from canned goods, to herbs & spices, to meats, to vegetables are all tracked in your database. All you need do now is set your alerts so that ANYTHING that is about to expire becomes an item in your next meal. Of course, you will need to tell this database whether or not you put something in the freezer, the fridge, to left it on the counter, but the smart-fridges or smart-cupboards of the very near future will be able to track this for you by scanning your groceries as you put them away. This will in turn be added to the database so you need never spend half an hour hunting for your Fingers of Fudge.

Not only that, because you have a complete record of everything, you can get immediate help on what to do with it. Every chef in the world will want to sign up to a service whereby they can apply their recipes to what you have available, or more importantly, what is about to expire. Yes, both the chefs and the providers of this service will try to get you to buy additional items to make an amazing meal, but you will always have a choice.

Also, if you DO choose a fancy menu, this can immediately alert your preferred supermarket who can tell you whether to not the items are available, then maybe even deliver them to you.

And we’re still not done. Beyond the immediate benefits of saving a butt-load of money, these are other advantages for every player in the cycle (in no particular order);

  1. You can have your weekly menus designed for you based on your preferences in terms of likes/dislikes, calorific intake, budget and so on.
  2. Growers will eventually be able to track global trends on food purchase, and possibly be able to adjust their supply to the demand.
  3. Supermarkets can automatically alert their customers to deals on soon-to-expire produce a hopefully reduce their waste. Maybe provide free delivery if you purchase enough of these items.
  4. You’ll learn to cook far more meals than you could have ever conceived yourself.
  5. You’ll be able to track your calorie intake if you follow the menus explicitly. Good for dieters, and excellent for diabetics.
  6. By having the ingredients of everything you buy available to you, you can ensure you never buy anything, or accept a recipe for meals that contain something, to which you or a loved one are allergic.
  7. You will undoubtedly stop buying things that sit in your cupboards for years on end, like that can of string beans that seemed like a good idea at the time.
  8. You can make your food database available to your friends so that you can create a meal together without having to buy everything yourself. Dinner party anyone?

I could go on all day, and I’m sure that if you have read this far you have had several ideas of your own.

All we need now is the supermarket chains to buy in …and the growers …and the name brand goods ….and …

 

This is one of my weakest subjects when it comes to the 12 Section of the PCI DSS, the only one at which I’m actually worse is coding stuff. That said, there are a few things I can touch on that should be self-explanatory, but for some reason are still tremendous pain-points for a lot of organisations.

In terms of cardholder data storage, what it really boils down to is one question; Is cardholder data core to your business?

This may sound like a stupid question, but unless your business IS the processing of cardholder data there’s a very good chance it’s not a core function of your business. For example, in ALL of retail, cardholder data is not core, it’s simply one means to an end. The end is receiving payment for your service / products, HOW you receive payment is not the important part.

If you accept the fact that credit cards in their current form will die over the next 5 – 10 years, any investment into your cardholder data infrastructure should match this end-of-life process. Outsource card payment if you can, if you can’t, encrypt the data from the point of interaction (POI, usually a PED / terminal of some sort) to your processor, and retain nothing except the first 6 / last 4 of the PAN post-auth. If that.

You simply don’t need to keep it for the myriad of reason you once did:

  1. Settlement – now handled by your third party processor or your acquirer
    o
  2. Fraud Investigation – There is enough information in a transaction to not require the ‘middle six’ digits of a card (this is not the same as anti-fraud processes)
    o
  3. Marketing – There was never a need for card numbers in marketing processes, and this should have been removed long ago
    o
  4. Finance – The card number is not part of any finance department reconciliation, and again, should have been removed long ago
    o
  5. Recurring Transactions – e.g. subscriptions, this can now be handled by your third-party processor or your acquirer

What you’re fighting against here is one of the worst phrases in history; “But we’ve always done it that way!” (Only “What are you thinking? and “Is that it?” are worse). Your Risk Assessment should have mapped your business needs to to your data flows, and any storage fully justified. And they should be RE-justified every year as part of the Top 5 risks to your business (just look at Target, and Michaels, and Neiman Marcus, I’ll bet they wish they had examined their business a little more closely).

Assuming you DO need to keep cardholder data, then here you should involve an encryption subject matter expert (SME), and if budget allows, a Host Security Module (HSM) to perform your key management. Unless you have significant in-house expertise, writing your own code and managing your keys manually is like pushing a car down the highway to save money on petrol.

As for encryption of data in transit, this is relatively simple. The cardholder data should never be seen on the wire outside of either data / file-level encryption, or an encrypted tunnel. SSL / VNP tunnels to / from every system in the process flow should be in place at a minimum.

However, does the PCI DSS require this for compliance? The answer is no, it doesn’t, it only says this; “4.1 Use strong cryptography and security protocols (for example, TLS, IPSEC, SSH, etc.) to safeguard sensitive cardholder data during transmission over open, public networks, including the following:…“.  I assume that you consider your internal subnets / VLANS behind the DMZ to be closed and private, thus negating the need for encryption.

Of course, this exposes the data to packet sniffers on those private networks, which automatically includes the majority of Intrusion Detection Systems (IDSs), so performing transport level encryption just makes sense if latency issues are manageable. This also adds yet another ‘blanket compensating control’ to your growing portfolio of above-and-beyond security measures.

This is as much as I can BS my through encryption, but in summary;

  1. Don’t keep it if you don’t need it, and be absolutely brutal in your examination of business processes
    o
  2. If you do need it, get expert help to minimise the complexity of all key management processes
    o
  3. Encrypt the connection between all systems in the CHD process flow, regardless of trust status

As always, if you need any help on this stuff, you need to find someone who can help you ask the right questions.

OK, so money isn’t irrelevant …yet, but it will be. Like so many things that are in existence, they are only still used because they have either achieved global ubiquity, or there is nothing better to replace them, or both.

Money, in all its forms, is probably the definitive example of this, but I can actually see a time in the not too distant future when it will be replaced with what it has always represented; Value.

Let me take a step back here and say that this subject is wayyy too complex for me to do true justice, and I have no intention of reading any books on economics to ensure it’s factually accurate, but by its very nature, money is limiting to the continuation of globalisation. Like it or not, the world is getting smaller and less unique across traditional borders both physical and political. People are starting to want the same things, and while not all of things they want are good, the common ground between them is once again driven by value.

Money simply cannot keep up with the changes, and the massive complexity of producing cash, providing debit and credit services, exchange rates, inflation, and a plethora of other things I have made it my goal to never understand, will eventually drive a requirement for something new;

I’m calling it ‘Digital Identity and Virtual Value Management’.

Errr, what?

Another step back; In the past, if you were a wheat farmer and needed meat, you would exchange wheat for meat at a ratio you agreed directly with the person standing right in front of you. You would then each go on your way happy that you have received fair value for your goods. However, if you wanted dairy products, carpentry skills, metal working skills or a whole host of services, you had to repeat this process, and of course, the representative values would always change depending on your immediate needs.

Now, in a massively over-simplification of history and probably fact, it was decided in the year [mumble-mumble] that it would make sense to replace the bartering system with a universally agreed (i.e. by the ‘government’) meaningless object (money), which would represent the VALUE of every commodity so that the holder of this meaningless object was owed the value of it in any commodity they chose.

Great, so now instead of carrying around huge quantities of wheat, our farmer can now walk up to any provider of goods and exchange their meaningless objects for whatever they want.

Eventually these meaningless objects became paper-based, then plastic, and now it’s digital, but it’s still meaningless. Only the VALUE of what it represents means anything, and you SHOULD be able to spend that any time, any place, anywhere, without the need for a meaningless object.

Your identity should replace the meaningless object, and your value should replace money in all it’s forms.

But who sets your value? Who is to say that the services of a lawyer are more valuable than those of a plumber?

You do.

Currently, if you accept £50,000 / year for your employment, YOU are the one who set that value, not your employer. If you think you’re worth more, go somewhere else, or, what you should do is increase your value by improving yourself in some way (education, experience, work harder, you name it). And herein lies one of the biggest mistakes people make their whole lives; focussing on money when what they SHOULD be focusing on is improving their own worth, their VALUE to others.

So, what is Digital Identity? It’s the unequivocal ability for you to prove that you are you, to anyone, anywhere. If everyone in the world KNEW that you were you, then you would not need money, passports, or any physical form of identity. Whether this is effected by biometrics and knowledge verification or [more likely] a combination of these and other yet-to-be invented factors is unclear, but the digitalisation of everything will continue until this form of Identity Management is commonplace.

And Virtual Value? This you can see happening already with Bitcoin and its brethren. What’s missing is the input of non-monetary value, or in other words, I have no way of entering my self-determined worth into a virtual environment, then have others validate it for my actual work in a way that I can spend on something else. But this is coming too, it almost has to.

I can imagine a time when I perform a piece of work for someone, immediately be ‘credited’ with the agreed virtual value, then be able to walk into a store, pick up what I want and walk out again without performing any manual payment transaction whatsoever. My Digital Identity will be confirmed the second I walk into the store, the value of the goods will be automatically calculated based on my choices, and the value of those good will be deducted from my virtual net-worth (or Internet-worth! :)) as soon as I step back out into the street.

Seems rather ridiculous that we still use credit cards, doesn’t it?