For those expecting a Terminator-esque diatribe warning you about the evils of ‘machine’ autonomy you’re in the wrong place. For a security professional, I am perhaps the least suspicious and prone-to-conspiracy person I know. Even my Sister and Brother-in-law are worse, but they are a lawyer and Scottish respectively so their paranoia is expected.

After reading Daniel Burrus’s articles ‘Big Data Is Already Producing Big Results‘ and ‘Create an Integrated Big Data Strategy To Increase Sales Now‘ it occurred to me that while Big Data has no place in security beyond forensics (in my opinion), the security OF the big data itself is critical. So is the integrity and availability of it.

The concept of Confidentiality, Integrity and Availability (CIA) has been around almost as long as I have, but only with the advent of big data and real-time analytics does it truly come into its own.

Everyone trying to sell you something – which is everyone – is looking at big data, or more specifically, how to collect the data in first place, and what to DO with it once they’ve got it.

Scenario: You’re out shopping with your wife when suddenly you are barraged by lingerie offers, as your spending habits over the last few months have been recorded and instantly regurgitated by hopeful vendors. Your wife has no lingerie…

Morality aside, this is a gross invasion of his privacy (loss of confidentiality). Now image if that data was actually inaccurate (loss of integrity), I’m sure his wife would be very understanding, right? As for availability, that’s the vendor’s problem so I don’t care much.

Now, let’s take this even further. In ‘The Internet of Things‘, soon everything from your home security to your dog will be online. Your location, your travel plans, your favourite everything will be known by someone, or someTHING, somewhere. The amount of information being collected is growing, quite literally, exponentially. The trend is also to automate as much as possible, so for example, if no-one’s home, the oven should not be on. Do we really want ALL of these decisions made without human interaction?

I personally love the way things are going. Instant access, always-on, functionality, convenience etc. But I am prepared to pay the price for this, the currency of which is measured in terms of the loss of both my privacy, and potentially, my personal safety. The data is online, if someone really wants it, they can get it, then do things with it I don’t even want to contemplate.

Big Data is not evil, data just is, it’s the use to which the data is put that defines good or bad. Businesses have been very quick off the block to define the profit-making contexts within real-time data analysis, but so far I haven’t seen much in the way determining what’s right and wrong. Or whether or not we even have a choice to take part in it.

The generations born prior to 1990 are most likely the ones holding this trend back, so we’re the one’s who’d better write the policies, and put the checks and balances in place, because the Millennials are too busy posting pictures of their junk.

This is not going to be about the legalities, policy, or privacy issues surrounding BYOD, that has been covered many times over in articles like this one; “Why almost everyone gets it wrong about BYOD” by Brian Katz.  I would hope that you are fully aware that regular information security policies do not cover the use of personal devices, and have established appropriate policies accordingly.

What I will be focusing on is a) the risks based approach, b) some musings on current ‘solutions’, and c) my thoughts on a possible technology solution.

A lot of these so-called BYOD solutions focus on the communication channels, secure browsing, malware protection, and/or Mobile Device Management.  All of them miss the major point, which is the risk to data at rest.  Do you really expect your employees to VPN into some kind of proxy just to browse the Internet?  Or how do you expect people to sign up to having their phone entirely erased if they loose it?

The issue is that not one mobile application, I repeat, not ONE, works at an Operating System (OS) layer that prevents jailbreaking.  Any encryption of either  the data channels or the data itself is performed by software running on top of the underlying OS.  Jailbreaks work AT the OS layer, meaning that any functionality of the application is immediately at risk, including any encryption keys.

Charles Henderson says it better than me; “Is Your Mobile App Safe?

So BYOD is not about keeping your data from being stolen, you can’t, it’s about agreeing on what you are prepared to loose, and what to do if (when) that happens. So instead of throwing ineffective technologies at the problem, you have go back to basics and look at Role Based Access Control, data classification, retention policies and so on.  You should even question whether or not the cost savings and assumed productivity enhancements associated with it are really worth the effort.

In other words, if you do decide to proceed, assume that whatever your employees are downloading on their phones and tablets is now available to everyone, and implement your BYOD solution accordingly.

I would argue that you are probably better off educating your employees to never put confidential information in emails than you are trying to control how they use / abuse their personal phones.

I believe that there is currently only one way to perform BYOD securely; in a hardware module.  If you accept that you cannot perform authentication / encryption safely at the application layer, and that you will likely never have access to the underlying OS (iOS for example), then you are left with hardware.

The hardware module would perform several functions;

1. Authentication – Once the module is plugged into the mobile device, it establishes a secure channel back to home base to perform whatever form of authentication you choose (LDAP, username/password, certificate, even biometrics).  All encryption keys are kept on the hardware device.

2. Encryption – Seeing as the keys are on the hardware device (some form of mini-HSM perhaps), you can leave the encrypted data on the mobile device when not used for work related applications.

3. Storage – The hardware module could also be used to store all work related data, and the mobile device provides nothing more than  a communications channel.

The form factor for the hardware module could be something that is already very common, the phone case / battery charger.  Like this for example;
Screen Shot 2013-07-08 at 16.43.01

Or it could be something like this that has many connection types;

Screen Shot 2013-07-08 at 16.46.01

There are many things to work through, and perhaps the most significant is that this module would literally have to jailbreak / hijack the mobile device before it could have the kind of control needed to enforce the BYOD policies.  Easy enough on Android/Windows, but I’m fairly sure Apple would have issues, they have already totally screwed the ancillary device market with their lightning adapter. I know Apple are also working on an secure embedded SIM technology, but I really don’t see how it can perform he above functions in something so small, and they haven’t even seen fit to add Near Field Communications (NFC) chips to their iPhones.

Thinking ahead, this may not be a viable solution for all businesses, you still have to purchase hardware, and the centralised management station would have to perform everything an MDM does, but for the hardware modules, not the mobile device.  However, for government, government contractors, military and so on, perhaps the encryption aspect alone would be of interest?

Who is currently best placed to corner this particular market?  I think POS / terminal manufacturers like Verifone, Ingenico, or Micros would be contenders.  They already have manufacturing capability, HSM technology, small-form storage modules, OS and mobile communications expertise etc.

All they would really need is deep expertise in the specific mobile technologies covering the majority of the smartphone / tablet market; Apple, Android, Samsung, maybe even BlackBerry.  I’m guessing those skill-sets are not too hard to find.

Clearly there is a lot more to it that I have mentioned here, I do want to keep something back for collaboration opportunities 🙂

What are your thoughts?  What have I missed?  Is this viable?

The answer, as any good consultant will tell you, is; “That depends.”

Usually that’s a our way of saying we don’t know the answer, but then again, we don’t have to, we’re consultants, and it’s up to you to tell us more so we can now go get the answer for you.

Like most things, GRC must start with a definition in order to apply context, and according to my old friend Wikipedia, GRC is “… the umbrella term covering an organization’s approach across these three areas.”

Which tells us absolutely nothing, so now we have to break it down:

  • Governance – Per my Security Core Concept 4: Governance & Change Control, governance is “…where the IT and business sides have conversations.”
    o
  • Risk [Management] – “…is the set of processes through which management identifies, analyses, and, where necessary, responds appropriately to risks that might adversely affect realisation of the organisation’s business objectives.”
    o
  • Compliance – “…means conforming with stated requirements (defined for example in laws, regulations, contracts, strategies and policies)

Hopefully you are asking yourself why these 3 things were ever apart in the first place for us to even need GRC to bring them together.  Done properly, Risk Management is owned by Governance, who have already taken compliance into account while designing their overarching security framework.  In other words, if Governance had been doing their job correctly, the way they approach risk management would spit compliance out the back end.

To understand why this is not the case in an overwhelming percentage of businesses, is to get back to how security is viewed in the first place; 1) Governance does not exist, or if it does, it has no authority,  2) Risk Management is woefully inadequate, and is certainly nowhere near the old Plan > Do > Check > Act (PDCA) cycle, and 3) Compliance is seen as an annual project and not part of  Business-as-Usual.

Despite the fact that GRC is a term that should be redundant, it is seen as a goal in and of itself, and in my view, may detract from the business’s true end goal; Staying in business responsibly, with IT/IS as enablers.  The 4 Foundations of Security, and the 6 Security Core Concepts lay down some of the groundwork necessary to design an effective security framework, but neither these, nor GRC really get to the detail of how you begin this process.

You should start with an inventory of your assets, ALL of them.  i.e. Asset Management.

There are a significant number of GRC tools and applications out there, and while I’m sure their intentions are good, they fall a long way short of providing the functionality necessary to do GRC well.

For a start, how can any GRC tool not begin with Asset Management, and I don’t just mean input from vulnerability scans, or network enumeration tools, which are only a small part of what asset management entails.  Assets are not just network devices and servers, assets are applications, processes, people, locations and so on, and without a good understanding of what these are, how can you perform a risk assessment, or monitoring, or incident response, or disaster recovery, or…..

True asset management will include all the following, and no GRC tool I know of can do it all;

  1. Front-End, Off-Line Audit and Data Collection Tool – inputting the information into the GRC tool is a laborious process, and not all information can be gathered while online. An offline assessment tool should be configured to run both your asset data collection processes, as well as any compliance process that you are subject to (PCI for example).  This offline tool can be used by external auditors, and internal auditors alike to build the full asset picture;
  2. Integration of System Settings Policies – your policies will dictate your minimum security standards; passwords, access control, logging etc.;
  3. Integration of Data Classification Policies – if your systems are to be configured differently for different data classification levels, this will need to be defined;
  4. Network Enumeration & Network Mapping –  accept feeds from network mapping and enumeration tools in order to a) find and make initial stab at node identification, and b) gather any other ad hoc information available;
  5. Vulnerability Scanning – accept feeds from scanning tools to ensure that a) all systems are covered in the scans, and b) systems meet both policy and security minimums.  Ideally, the GRC tool would also feed into the scanning tools to provide up-to-date scan profiles, and exception rules;
  6. Automated Collection of Validation Evidence – PCI requires an annual validation of compliance, and only against a sample of systems. Security done correctly will have continuous compliance (i.e. near real-time), and automated validation of requirements (access control, passwords, logging etc).  This could be achieved by either server based agents, or integration with AD/LDAP for credentialed remote procedure calls;
  7. Baselined System Profiles – it is not enough to know the OS, IP, Hostname, location, owner etc (the usual asset management minimums), you should have record of it’s patch level, running services, listening ports, disk space, memory, even temperature.  A baselined system can then report against ANY anomalies;
  8. Firewall & Router Ruleset Validation – if you can feed a firewall or router ruleset into this system, you can a) compare it to the known business justifications, but you can also compare it to the system profiles to ensure you have no rules without corresponding business processes, running services on systems without corresponding rules, insecure services and so on.  Ideally, you could even create and maintain your network diagrams from this;
  9. Change Control & Trouble Ticketing – The change control process should feed into the ‘GRC’ tool to ensure that all monitoring and alerting mechanisms are up to date, and not triggering false positives.  Alerts FROM the GRC tool should automatically create trouble tickets based on a the data classification, system ‘sensitivity’/priority;
  10. Ease of Use – there is no point have ANY system or process that is too difficult to set-up, or impossible to maintain.

There are two main ways GRC vendors get you to use their product; 1) they ‘give’ you the software to use as part of a consultancy engagement, then charge you licensing fees if you want to keep the product after the engagement is complete, and 2) sell you the product, set it up for free (or a nominal charge), then hope you need them to come back and engage them as a managed service provider for ongoing maintenance.

I’m not saying either of these is bad, you just need to decide EXACTLY what it is you want from your GRC tool and perform your due diligence accordingly.

No GRC tool can do everything I described, so you either must buy several different systems and integrate them yourselves, or forget the GRC tool and run the above functionality in an operations centre.

Call it GRC if you want, but it’s not security until it’s simple enough to implement, and cost-effective enough to add real business value.

Do your due diligence before you buy anything, and again, if you need help, ask.

[If you liked this article, please share! Want more like it, subscribe!]

As both a US and UK citizen who has spent his whole life almost equally between the two continents, it occurred that I might be well placed to comment on why a lot of US companies have such a hard time getting started over here. You be the judge 🙂

Maybe I shouldn’t comment on our “special relationship”, especially as my wife’s family are Irish-American, lawyers, ridiculously intelligent, and gigantic.

That’s me in the middle, and I’m 6’/220lbs (1.83m/100kg);

Irish Giant Lawyers

There’s your first difference right there; I actually wrote weights and measures both ways so that everyone understands. Europeans and Americans both tend to get rather upset when they have to do the conversions. And don’t get me started on Celsius vs Fahrenheit, miles vs kilometres, S vs Z, or the date (EU 04/07/13 vs US 07/04/13).

These are minor, and amusing differences, but when a business suffers for the reasons I lay out below, no-one’s laughing (except perhaps the Chinese):

  1. Annual Leave – Americans get 2 weeks, and maybe a 3rd after the first 1,000 years of good service, Europeans start out with 4 – 5 weeks. Don’t question it, don’t even comment on it, just accept it. Americans work longer hours than the people of any other country I’ve ever been to (42 at last count). Well, it may be that they are AT work more than any other country, but it’s a mistake to think they work harder. US companies work year round at a certain rate, European countries do very little in August/September, but make up for it in other months. I’m sure someone smarter than me can provide statistics.The European way is better, MUCH better, it’s also healthier and more sustainable;
    o
  2. The Personal Touch – I think because Americans are so busy, the face-to-face aspect of doing business has taken a back seat to email. Even a phone call is too much sometimes. This does not work in Europe, where business is conducted in person, and preferably with ‘friends’. The whole concept of “it’s business, nothing personal” does not fly here.
    For the Americans; go and see your clients, buy them coffee/tea/vodka, talk about football (not your kind), and let your client bring up business when THEY are ready.
    For the Europeans; help the Americans out, if you’re not getting the service / attention you need, just say so, they will not be offended in any way. Suffering in silence, while very British, is outdated and obsolete;
    o
  3. Culture – In the US, it’s pretty much one culture from Washington State to Florida, from Southern California to Maine. It’s one currency, and one language (unless you live in Miami), so there are no issues providing services from anywhere, to anywhere.
    Not so in Europe, where you can drive 5 minutes and find an ancient enemy, a NEW enemy, 15 different dialects, and barter in chickens. OK, slight exaggeration, sheep are the common currency, but you get the point. You have to be careful sending someone from Greece to FYROM (if they’ll go), from Russia to anywhere else in the Commonwealth of Independent States (CIS), from the UK to …well, anywhere else (hooliganism was invented here). And you want to do business in the Middle East too? Better have two passports.
    If you want to do business in France, hire a dedicated salesperson in France. If you want to do business in Germany, better hire a well known salesperson in Germany, and so on. I’ll translate a rather graphic US colloquialism into ‘Poo, or get off the potty.” i.e. commit local resources, or don’t even bother trying to do business there;
    o
  4. Stop With The Discounts! – The American sales process is the most aggressive, and pressure-filled anywhere in the world. End of month, end of quarter, and especially end of year targets force salespeople to almost throw their services away.  And what do European buyers do? They WAIT for the end of month, end of quarter and end of year to GET the discounts!
    Now combine that with selling multi-year deals AT the big discount, and you’ve just tied yourself into a never-ending spiral of price compression. Not smart;
    o
  5. Give Them Time! – Even more important than not discounting, is giving the European salespeople time to build up a pipeline. It takes a good salesperson a year (especially in security) or more to build up a decent client-base, and if you put too much pressure on too soon, they will quit, and you’ll start all over again. Have that happen too many times and you will ruin your reputation from both the client, and the hiring perspective.
    Don’t make the targets too high to reach, or the constant ‘failure’ will destroy their morale. Setting the bar high so they “don’t slack off the pace” is self-defeating, there are many other ways to motivate the sale-force towards excellence.
    Doing business in Europe is a long term investment, treat it as such. Unless of course you’re only out to make as much revenue as you can before you bail, and then by all means, carry on;
    o
  6. Devolve the P&L – No culture likes to be controlled by a foreign nation (yes, I’m biting my tongue), so devolve the P&L to the local country/region. By all means maintain the US control over the goals/KPIs/targets and so on, but leave HOW they get there to local reps. And no offence, make sure the local reps are LOCAL reps, not ex-pats, unless they’re prepared to stay long-term;
    o
  7. No Arbitrage – Nothing causes more consternation that two completely different bottom line reports because each side chose the most ‘favourable’ FX to make their point. Decide on EXACTLY which currency you will report with, and which FX you’re going to use, right from the beginning, and stick with it;
    o
  8. Visit, and Visit Often – America is so vast and so diverse, it’s understandable that coming over to Europe, with our even stranger languages / cultures, and foods, – black pudding anyone? – can seem a little daunting, but it’s absolutely worth it. Not just to see the sights. Again, Europe is a face-to-face culture, if you want to do business here, you must be seen to care. At the highest levels, do a road trip at least once a year to the more significant of your regional offices, to show not only the clients, but the employees that you’re serious, committed, and approachable.

The population of the EU alone exceeds that of America by almost 200 million, the GDP is on par, and if you throw Africa, the ME, and APAC into the mix, the potential is even more enormous (there are 50 countries within a 4 hour flight from London!).

The world is getting smaller, English is the language of business, and most of the planet really does want what the US has to offer.

It just won’t be on the US’s terms.

[If you liked this article, please share! Want more like it, subscribe!]

Remember when CheckPoint were just firewalls, Symantec were just AV, and security companies could just provide consultancy?

Neither do I, it’s been too long.

Security has now become too complex, and too important to play the mix-and-match game with individual vendors, it’s only integrated, multi-function, solutions that will now make the cut.  But there are so few of them out there.  Well, so few that actualy do what they say they do anyway.

As security became a multi-billion £/$/€ a year industry, hundreds of companies started up to bring us the silver bullet appliances that will end our problems forever.  Not only do silver bullets not exist in security – and you should be shot for using the phrase in any way that’s non-derogatory – but where are those companies now?

They either failed, or have been bought up by larger companies who have tried to duct-tape the disparate products into silver-bullet SOLUTIONS.

Which have also failed.

It’s not that the products don’t work, some of them actually do, it’s that;

  1. Businesses threw technology at problems without knowing WHY they were doing it
  2. The big companies that collected the smaller ones tried to integrate the individual products together under one GUI, instead of unifying the functionality under a single code base
  3. There has never been, and there never will be, a one-size-fits-all solution to security

But the market is still ripe for innovation, and there will continue to be companies starting up with the goal of bringing a single product to market that will catch the latest security hype/wave/buzz and make them their fortunes (MDM for example).  They may even succeed, but only if they make their impact in the first year or two, otherwise the market will have moved on.

If they’re VERY lucky, the larger companies that collect little ones will be naive / ignorant enough to buy them and save them the trouble.

I am not against combining single products into a larger solutions, in fact it’s the only way to go, but only if it’s done correctly.  Single product companies have 100% focus, which gives them drive, goals, and a dedication to making their one product the best. The second you absorb that company, every one of those attributed that put them on (or near) the top, is lost in the larger mix.  The functionality is diluted, innovation ceases, and the the whole thing quickly becomes obsolete.

True integration of functionality can only be accomplished with a single code base, and a single platform, which means that any organisation that absorbed the smaller companies better have a plan in mind to migrate not only the applications over to their growing solution, but they will need to consider all of the clients who bought the product prior to the M&A.  These guys often suffer from a total lack of customer service and support, and there’s no way they’ll buy into the larger programme.

From what I have heard, the due diligence necessary to combine product companies is not overly abundant, and until it is, we should all be VERY careful when we look to resolve our security issues with multi-function solutions.

That’s why I call these ‘collage companies’, as the picture might be pretty, but it’s in no way whole.

Here are a few questions you might want to ask your potential providers;

  1. Can your solution replace some / most of my current functionality?
  2. Do you provide a consultancy ‘wrapper’ around these solutions to help us manage them against our business goals?
  3. Will the output from your solution feed into my current collection mechanism, or can my current output feed into yours?
  4. Are the various aspects / functions of your solution ‘home grown’, or obtained through acquisition?  If acquisition, how have you unified the back end code and platforms?
  5. How do you ensure that the different functions of the solution receive a similar attention to what the single product vendors provide?
  6. Do you have a single customer support process to handle all functionality questions?

Regardless of the shenanigans going on in the security product market, your choice of vendor should only be driven by what your risk assessment and gap analysis said you need, and your due diligence should cover any requirements you may have regarding integration and ongoing maintenance.

If is doesn’t, don’t expect the collage companies to help, they have enough problems keeping their own houses in order.

Choose wisely.