You can almost feel it happening, can’t you? Every time there is an introduction of, or a change to some regulation or another, the vultures of the legal, security consulting, and even security product vendors spin up their marketing machines to invent new promises on how they will ‘guide you through the pending minefield’.

The thing is, I in no way blame them. I’ve likened selling security to selling insurance, in that no-one WANTS to buy something that seems to have absolutely no tangible benefit to the bottom line (it does though; How Information Security Enables Transformational Change). This results in a vast majority of organisations taking extreme liberties with the terms ‘reasonable’ and ‘appropriate’, which is as specific as most regulations go in terms of meeting their requirements.

Unfortunately, regulations are written by lawyers, who have a language all of their own. How is an IT Director supposed to translate legal-ese into geek-speak without some help? That’s where a PROPERLY run security program comes in; the translation become almost unnecessary.

I have made statements like this many times; “If an organisation was doing security properly, they would already be [enter regulation name here] compliant.”

Bold statement, but think about it this way:

  1. ALL information security and most compliance regimes relate [at least in part] to the protection of data
  2. The principles of information security have not, and will not ever change
  3. NOT doing these basics is the fault of the organisations, not the regulators (except PCI)

The only thing that’s different from one compliance regime to the next is how you report what you’re doing. PCI requires a very detailed (though mostly meaningless) controls-based Report on Compliance, SoX and HIPAA require something else, and the old Safe Harbor just required a SELF-assessment (and you wonder why it failed…).

Regardless, the underlying validation evidence is the same; policies, procedures, standards, operational integrity, incident response and so on. You are either doing these things or you’re not. And let’s be clear, you should be.

“But they’re moving the goal posts!” is a complaint I frequently hear, and is usually the foundation of an excuse to do nothing. Just because YOU don’t know where the goal posts are doesn’t mean they’ve moved. All that really happened is that every time a regulation comes out and they ask for more and more detail / accountability / transparency etc, it further exposes the fact that you weren’t doing things properly in the first place.

The General Data Protection Directive (GDPR) for example is freaking organisations out with its potentially enormous penalties. Penalties for what? Not using data for its original intent? Not obtaining explicit customer consent? Not LOSING the data in a breach? How is ANY of that unreasonable!?

OK, so the above is a gross simplification of the GDPR, but it’s not far off, and frankly, Privacy Shield will be even easier. If your organisation is not in a position to meet the intent of these data privacy regulations, then you are part of the reason they exist in the first place. And if your security program is in such a state that the vultures have easy picking over the carcass of your IT budget, that’s your fault too.

Non-compliance with any regulatory requirement relevant to data protection is just a symptom of the same underlying problem; a crap security program. Fix that, worry about the reporting afterwards.

In a recent article in SC Magazine; “An Inconvenient Truth: New Customer Data Regulations Coming” Jeremy King of the SSC suggests that Payment Card Industry (PCI) “provides the most complete set of data security standards available globally.” I can only assume he means that the PCI Data Security Standard (DSS) contains a list of basic security controls every organisation should have in place, and not that the PCI DSS in any way resembles real-world security.

Because it doesn’t, and you only have to look at the number of breaches involving ‘PCI compliant’ merchants and service providers to see that PCI, by itself, does little to prepare organisations against the challenges they face.

PCI compliance is a commercial obligation, nothing more, and any fines levied are only paid because the merchant or service provider who was breached wants to keep taking plastic. The Payments Services Directive 2 (PSD2) and the General Data Protection Regulation (GDPR) will be LAW in the 28 countries of the EU, and attract both legal and financial repercussions that could potentially cripple even the largest of businesses. No standard based on a bare minimum set of controls will ever protect personal data in a meaningful way.

Nor will any ISO standard, or COBIT, or any other information security framework for that matter. At least the PCI DSS puts its money where its mouth is and tells you what controls to implement, all security frameworks do is tell you something is a good idea, never how to do it a manner appropriate to your business.

Because they can’t, only the individual organisation can ever provide definition, and business justification, around the horribly inexact – but regulation standard – phrases; ‘appropriate’ and/or ‘reasonable security’.

The implementation of a security program that can meet the intent of ANY regulation includes very specific processes that the PCI DSS does not cover, and if they do, it’s in a very limited fashion with no-where near the emphasis required to express the importance. For example;

  1. The Risk Assessment (RA) is way down in section 12, when it should have been the very first thing performed before PCI compliance was even contemplated. An RA performed in-line with the PCI DSS would not be sufficient.
  2. The only nod to Disaster Recovery and Business Continuity Planning is a single bullet in 12.10.1, when these processes are absolutely central to any organisation staying in business responsibly.
  3. The requirements related to 3rd party due diligence are entirely inadequate relative to the risk involved.

…and so on. I have addressed the inadequacy of the actual PCI controls many times, so I won’t bother repeating them here. Suffice to say, the majority of the controls would be no-where near enough.

There are only 3 main ways to appropriately address the current and new tranche of regulations / directives:

  1. Make the CEO legally responsible for security breaches, and apply criminal penalties in-line with the egregiousness of the negligence – Clearly fines don’t worry CEOs enough, perhaps some jail time would.
  2. Ensure the policies, procedures, and standards are world-class – There is no security program without the application of accurate corporate knowledge
  3. Training & Education – This should be self-explanatory

Compliance with any of the upcoming regulations is no different from any regulation already in place. There is nothing outside of an appropriate security program that will ever be required, so just do the things you should have been doing from the very beginning.

Security is not easy, but it IS simple.

For security professionals, the role of Chief Information Security Officer (CISO) is often seen as the ultimate career objective. The pinnacle job after years of paying your dues in what is still a fairly rarefied industry sector.

And it should be, if that’s what you actually want. I can think of no other position outside of the CEO who should have a better grasp on how a business functions than a CISO doing their job well. In fact, while the CEO has the overarching strategy and direction in their remit, it’s the CISO who knows where the information needed to make the right decisions is.

If you accept that data in context is information, information in context is knowledge, and knowledge correctly applied is what makes organisations successful, then; a) Confidentiality of the base data is critical, b) if the data is safe, Integrity can be more reasonably assured and the resulting information is above all things, accurate, and c) the application of the information must be unhindered, suggesting that Availability of the data is the final piece of the puzzle.

You’ve all heard of C.I.A. in security, right? As far as I’m concerned it’s the CISO who is the guardian of it.

In a perfect world.

Unfortunately, far more prevalent is that the Board decides that a CISO is needed from an appearances perspectives – perhaps due to some regulatory pressures – and the person hired has no real authority, no understanding of the overarching corporate strategy, and probably reports into the CTO or someone equally unsuitable.

It’s a shame really, because a good CISO will have unparalleled input into the following:

  1.  The Security Program – From Risk Assessment all the way to Business Continuity Planning the CISO must be aware of every process related to the security life-cycle of the data under their care. Even the CTO won’t have their fingers in this many pies.
    o
  2. Asset Management – There is nothing in security that can be performed outside of robust and comprehensive asset management. This will be the CISO’s primary focus until it’s where it needs to be.
    o
  3. Mapping of Business Processes – If you don’t know how something works you can neither protect it nor fix it if it breaks. Business processes are the ultimate application of corporate knowledge and the CISO cannot do their job properly until they are all mapped, and preferably optimised.
    o
  4. Success Measurement – As Peter Drucker is so often mis-quoted as saying; “You can’t manage what you can’t measure.” In security, unless the CISO can determine which security controls are working and which are not, appropriate security will be impossible. As will staying within budget.
    o
  5. Regulatory Compliance – I cannot think of one regulatory compliance regime that does not have data at its core, so who better to report compliance status than the person who knows where it all is, and the controls around it?
    o
  6.  Change Control – In theory, if nothing can change on the inside without robust oversight, the only increase in risk to data assets will be from the changes to the external threat landscape. Which segues perfectly to;
    o
  7. Vulnerability Management – With asset management and business processes as their primary focus, who is better placed to feed into the vulnerability management process to help prioritise ongoing remediation efforts?
    o
  8. Business Transformation – In the 2000’s, competitive advantages last weeks, not years. No-one is better placed to help a business transform itself than the person who knows where everything is, and everyONE who manages it.

Prospective CISOs may go into their new job thinking they will get to do all of the above, and the CEO who hires them may think that’s what they’re getting.

Too often neither side asks the right questions, and the CISO role ends up an empty suit.

[If you liked this article, please share! Want more like it, subscribe!]

Easy enough to answer; if there was suddenly a security silver bullet we’d be attacked by hackers who are vampires, zombies, aliens, flesh eating bacteria, and everything else unaffected by silver, just not werewolves. Or maybe werewolves with bullet-proof vests, but I’ve about beaten this analogy to death.

The fact is, and I am probably the 100 millionth person to say it; THERE IS NO SILVER BULLET IN SECURITY! Never has been, and there NEVER will be. So don’t look for it, don’t believe anyone who says they have one (especially vendors) …in fact, don’t even use the phrase unless you’re telling someone else not to use it!

Technology is not the answer …alone. Process is not the answer …alone. Even people are not the answer, although they get the closest. It is a combination of all of these things that provide what every organisation should be looking for in their security program; something appropriate. Appropriate in cost, effectiveness, sustainability, manageability, measurability and every other relevant -ness and -ility out there.

Every organisation only needs security enough to cover the risk to their business. Period / full-stop.

So define appropriate? This is not like asking how long is a piece of string, this is actually very simple. It all falls roughly into 3 categories:

People

This starts with the CEO/BoD as the only foundation that matters. If they don’t care, no-one below them will care, and the organisation will never have the kind of security culture necessary to ever effect appropriate security. They will be breached, and they will deserve it.

But why should the CEO care about security, don’t they have better things to do? Let me answer that with a question; How many businesses are dependant on the correctly applied use of their data assets? Maybe the former CEOs of Target or Equifax have some insight?

Any CEO who has not been through a major breach is not equipped to lead an organisation in the 2000’s, but a CEO who cares about security will surround themselves with people who think securely.

Process

Everything a business does is a process of some sort. Either a good one, a bad one, or likely somewhere in between. Unfortunately, if you don’t write these processes down, you have no way of repeating them consistently enough to actually measure their effectiveness. In other words, your business processes are your corporate knowledge, your competitive advantage, and your ability to change all rolled into one.

Without documentation of your business processes, you have no baseline from which to measure your strengths and weaknesses, no way to develop a competitive advantage BASED on your strengths, or to transform your business in the face of competitive loss.

Technology

Purchase of new technology is the last resort of a security program run well, with adjustments to existing processes and reconfiguration of existing technology taking up the 1. and 2. positions respectively. No purchases should be made outside of a risk assessment, and MUST include all of these things or your kit will likely become yet another paperweight on the IT Director’s desk:

  1. Is the technology appropriate for the current needs, and the needs of the immediate future only? Anything more than that is excessive, and you were likely sold what you asked for, not what you needed:
    o
  2. Who is going to implement it / integrate it? Do you have the skill-set in-house?
    o
  3. Who is going to manage / maintain it? Patches? Upgrades? Base-lining / tuning?
    o
  4. Who is going to monitor it / perform initial incident response? In-house? Managed service?
    o
  5. How are you going to measure it? You’ve made the investment, how do you know if it’s provided a business benefit?

You implement technology to optimise the efficient output of a known business need, you don’t document processes to cover your new technology purchases.

In the end, security is difficult to do well, especially without senior management support, but it is nevertheless EASY to do if, and ONLY if you don’t try and cut corners.

Looking for a silver bullet is the very definition of cutting corners.

[If you liked this article, please share! Want more like it, subscribe!]

Feeling lazy, this is a re-blog, but the last few weeks at work has made this especially relevant;

I started when I was thinking about how superstitions begin; It’s bad luck to walk under ladders, or it’s 7 years of bad luck if you break a mirror for example.  And then it occurred to me that these superstitions were probably the only way to scare children into, or out of, certain behaviour.

Walking under ladders, well duh, things fall OFF ladders, so don’t walk under them. Mirrors used to be really, REALLY, expensive, so telling children that breaking them would have horrific consequences makes a lot of sense. I’m surprised that playing with matches didn’t become a superstition, but then again, household-use matches were not readily available until the 1800’s.

Unfortunately, these things have a way of sticking around long after the original cause is meaningless. Or worse, is twisted and perverted by those with a vested interest in the status quo. ‘Heretics’ were burned at the stake for suggesting that the Earth revolved around the Sun, and not the other way around. ‘Witches’ were similarly killed in horrific ways when they suggested that herbal remedies were better than leaches and other forms of bleeding. Priests and Doctors respectively were very protective of their power.

Human nature has changed very little since then, only societal laws and the more progressive ‘norms’ keep the peace.

I have for years likened information security to insurance, in that no-one wants to spend money on it. They just know it’s a cost of doing business. And more recently I have likened security to the law, because it’s becoming so complex in terms of regulation / legislation / standards etc, that’s it’s often out of reach for the organisations and individuals who need it most.

Now I find myself likening security to superstition, because from the way we’re going, it won’t be long before being in security will have the same stigma as being a tax auditor, a parking enforcer, or a lawyer. QSAs are almost there already because the entire concept of PCI is so limited. However, to me, there is no reason why true security professionals should not be seen in the same light as those responsible for driving revenue, growth, or competitive innovation.

Security departments are something people go out of their way to avoid, or to circumvent. They are seen as the department-who-says-no, who will stifle innovation and good ideas, and generally do the one thing that would label them heretics; get in the way of revenue.

Nothing could be further from the truth, as no other department has the knowledge and DESIRE to do the things that make staying is business possible:

  1. Innovation: It’s the 2000s, the vast majority of innovation now is in technology. Who else is best placed to pick the RIGHT technologies to ensure that innovation is implemented in a way that enhances the organisation and not just adds risk?
    o
  2. Business Transformation: Competitive advantage in the information age is now measure in weeks and months, not years or decades. Organisations without the ability to adjust critical business processes quickly and appropriately will be left behind. What other department has the knowledge of existing processes to enable the adjustments?
    o
  3. Revenue Protection: Can you think of anything worse than seeing all your revenue disappear into the hands of regulators because your focus on selling failed to take into account that your processes for doing so were completely inappropriate. I understand completely the pressures, but revenue generation is not about doing what it takes, it’s about doing what’s right.
    o
  4. Reputation Protection: I could have put this under revenue protection, but wanted to break this out as corporate reputation goes way beyond just revenue, and my OCD will not allow for an even number of bullet points. Damage of reputation through loss of data C.I.A. can have long-term negative effects on a business. Just ask CardSystems who went from $25M / annum to out of business in less than 1 year after their breach.
    o
  5. Infrastructure Investment Optimisation: OK, long title, but consider that the amount of money spent on PCI is already in the multi-billions, when a huge chunk of that could have been save by adjustments in PROCESS. Technology purchase is the last resort of a true security professional.

I really don’t have an answer to HOW we can ensure our reputations remain unsullied, and there are a lot of so called security experts out there giving the rest of us a bad name. But I think the worst thing to do is fall back one of the phrases I hate most in this world; “It is, what it is.”

Actions speak louder than words, and I will never stop trying to show my clients that security is something to be embraced, not avoided.

Forward this to all your friends or you’ll have 3 years of bad luck.

[If you liked this article, please share! Want more like it, subscribe!]