By now, most of the people in the security field have become aware of near foolproof means of bypassing pin tumbler locks and the like using a special key and hammer. My naive thought was that once the new method would come to light, the art of lock picking would soon fall by the wayside.
Furthermore, particularly in information security circles, people mostly lose sight of the need to address physical security as a means of ethically penetrating a client's infrastructure. To this end, I encourage information security pratitioners to expose themselves to lock picking as a means of increasing concentration, and solving puzzles. Whether it be a door to a server room, or a lock protecting a rack of servers, having a basic understanding of how locks work and some general techniques to defeat them can make all the difference in the world.
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Thursday, April 8, 2010
Tuesday, April 6, 2010
Data Disclosure and Compensation
I was recently thinking about the data disclosure breach of 3.3 million from ECMC, and as I read the article, I was becoming increasing disturbed about the lengths that companies that sustain a data breach are taking to compensate the victim. It seems as it is customary to send a letter to the victim and offer one year of credit monitoring services. This is garbage in my opinion, as many of the victims are already under a credit monitoring service from some other company and their data breach.
We are quickly heading towards two unique tipping points:
1) Credit monitoring service is not retributive justice for the violation of one's private, personal data. Sure it stings the company bottom line, but chances are, this is in a cash account just waiting for the day it may need to be used. The real victims are the one's whose data is stolen, kicked around, and ends up who knows where. So we give the victim the equivilent of a carnival prize. "Thanks for playing."
2) It appears that the information security community places a high value on private (PII) information. We spends trillions of dollars protecting 9-digit SSNs because they can easily be paired with a name as the basis of identity theft. What if we devalued this information, instead of throwing everything but the kitchen sink at it to keep it secret. Maybe it is biometrics, or maybe it is some form of smart card. I don't claim to know the answer; however, we should consider all options to protect the identity of the victims and potential victims, not the random bits and bytes that identify us.
I would be interested in hearing others' perspective on these points.
We are quickly heading towards two unique tipping points:
1) Credit monitoring service is not retributive justice for the violation of one's private, personal data. Sure it stings the company bottom line, but chances are, this is in a cash account just waiting for the day it may need to be used. The real victims are the one's whose data is stolen, kicked around, and ends up who knows where. So we give the victim the equivilent of a carnival prize. "Thanks for playing."
2) It appears that the information security community places a high value on private (PII) information. We spends trillions of dollars protecting 9-digit SSNs because they can easily be paired with a name as the basis of identity theft. What if we devalued this information, instead of throwing everything but the kitchen sink at it to keep it secret. Maybe it is biometrics, or maybe it is some form of smart card. I don't claim to know the answer; however, we should consider all options to protect the identity of the victims and potential victims, not the random bits and bytes that identify us.
I would be interested in hearing others' perspective on these points.
Saturday, December 20, 2008
Security Metrics as a Process
Recently, I was presented with an interesting challenge within my organization. Quite honestly, the challenge is not anything new or specific to this organization; it is a systematic problem within the Information Security function. The concept of Information Security metrics is, in my opinion, largely based on snake oil sales. Unfortunately, it perpetuates as a nebulous science, complicated further by inconsistency and contention on resources that fail to see the value of the art.
If you had to read that last sentence multiple times to catch the meaning, well then you are at the same wavelength that our decision makers are at when it comes to the metrics that we define as a horizontal function. The statement is based on opinion, contains fancy words, and yet somehow dos not address the challenge in quantitative terms.
This is the crux of my challenge, and one that I hope can translate into my dissertation in organizational management. Metrics can be defined by nearly everyone; effective metrics cannot. The practice of arriving at effective security metrics will take many resources: human, financial, temporal, and technological.
Like the Information Security function itself, the effective metrics process is a process, not a product. Borrowing from Andrew Jaquith's book Security Metrics: Replacing Fear, Uncertainty, and Doubt, I believe he is correct when he defines the criteria for an effective metric:
Surprisingly to me at this point, is the noticable lack of material on the subject of Information Security Metrics. Outside of Andrew Jaquith's book and the works of ISO 27004, which is yet to be published, I have yet to find good material on the topic.
What I would be interested to see, is what practioners in the field use to measure their effectiveness in Information Security as a process.
If you had to read that last sentence multiple times to catch the meaning, well then you are at the same wavelength that our decision makers are at when it comes to the metrics that we define as a horizontal function. The statement is based on opinion, contains fancy words, and yet somehow dos not address the challenge in quantitative terms.
This is the crux of my challenge, and one that I hope can translate into my dissertation in organizational management. Metrics can be defined by nearly everyone; effective metrics cannot. The practice of arriving at effective security metrics will take many resources: human, financial, temporal, and technological.
Like the Information Security function itself, the effective metrics process is a process, not a product. Borrowing from Andrew Jaquith's book Security Metrics: Replacing Fear, Uncertainty, and Doubt, I believe he is correct when he defines the criteria for an effective metric:
- Consistently Measured
- Cheap to Gather
- Expressed as a Cardinal Number or Percentage
- Expressed using at least One Unit of Measure
- Contexually specific
Surprisingly to me at this point, is the noticable lack of material on the subject of Information Security Metrics. Outside of Andrew Jaquith's book and the works of ISO 27004, which is yet to be published, I have yet to find good material on the topic.
What I would be interested to see, is what practioners in the field use to measure their effectiveness in Information Security as a process.
Labels:
CISSP,
Information Security,
Metrics,
research,
security
Monday, October 20, 2008
Acronym Soup In Security Certifications
A few weeks ago, Shon Harris asked the White Hat Hacking group to comment on the state of the industry from a certification perspective, and in particular, how fractured the industry is with respects to certification bodies (including vendor-neutral versus vendor-heavy).
Here is the snip of my response at the time:
I wanted to throw it out to a wider audience to get some additional perspectives on the whole notion of requiring mentoring, teaching, or volunteer work as a condition of a security credential. It is one thing to have a bunch of acronyms after one's name, and I am not trying to diminish the accomplishments of those that are dedicated enough to obtain many certifications or advance their careers.
However, how would hiring managers feel about the merits of a technical certification(s), versus a more rounded certification which included charity work as a prerequisite?
I would love to hear opinions on this one.
Here is the snip of my response at the time:
Actually, I am skeptical that we will ever have a certification track that will effectively capture the industry. As you mention, vendor-concentrated certifications demonstrate knowledge on a particular platform or product; however, in my opinion, information security is so fluid and nebulous that it is similiar to trying to have an intelligence (adjective, not noun) certification.
From a personal perspective, I have always found it more impressive if someone can teach as well as simply speak facts. Therefore, I would hope that a measure of a practitioner's value to an organization could be viewed, not by a single or suite of certifications, but rather the lifelong pursuit of the advancement of the profession. I think there is a very good parallel to this in practice throughout history today with the various martial arts.
I think ISC(2) and others have dabbled in this approach, but in my opinion, it needs to be refined. If I was holding the "magic wand", I would suggest that everyone study, teach, and contribute to the community through volunteering or charitable contributions to maintain a credential. Ultimately, I believe this would do more for the industry than any certification can provide alone.
Thoughts?
I wanted to throw it out to a wider audience to get some additional perspectives on the whole notion of requiring mentoring, teaching, or volunteer work as a condition of a security credential. It is one thing to have a bunch of acronyms after one's name, and I am not trying to diminish the accomplishments of those that are dedicated enough to obtain many certifications or advance their careers.
However, how would hiring managers feel about the merits of a technical certification(s), versus a more rounded certification which included charity work as a prerequisite?
I would love to hear opinions on this one.
Labels:
certifications,
charity,
LinkedIn,
security,
Shon Harris
Subscribe to:
Posts (Atom)