Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, November 27, 2022

Your Robot ID


Until you understand the writer's ignorance, presume yourself ignorant of his understanding........(Samuel Taylor Coleridge, 1817)



Your ID is Yours, even as you move from provider to provider. Your ID protocol should be web scalable with a mechanism for a marketplace ranking systems where the service providers can choose.

What happens when an AI is able to discover new hacks against these general systems?

What happens when AIs find loopholes, or loopholes in financial regulations?

A “Hack” is something a system permits but is unanticipated and unwanted by its designers. It’s subversion, or exploitation.

It’s unplanned: a mistake in the system’s design or coding 

 We have systems in place to deal with these sorts of hacks, but they were invented when hackers were human and reflect the human pace of hack discovery. They simply would be overwhelmed with AI finding hundreds, of loopholes in financial regulations. 

What happens if AI hacks Your ID, persona bots (These are chatbots on a very small scale);

 They could participate in small forums around the Internet, hobbyist groups, book groups and more. In general, they would behave normally, participating in discussions like a person does. 

But occasionally they would say something partisan or political, depending on the desires of their owners.

With unique ID, it would be hard for existing bot detection techniques to find them. 

With replication by the millions across social media, they would affect what we think, and -- just as importantly -- what we think others think. 

A political discussion could be persona bots arguing with other persona bots.

See You at The Top

Friday, July 30, 2021

Cyber Risk Challenge

Terror.......often arises from a pervasive sense of disestablishment; that things are in the unmaking......(Stephen king, American writer, 1981)

Governments and Businesses are struggling to cope with the scale and complexity
of managing cyber risk. Over the last year, remote working, rapid digitalization and
the need for increased connectivity have emphasized the cyber security challenge. 








One tool that has gained traction is cyber insurance. If it can follow the path of
other insurance classes, it could play a significant role in managing digital risk.

However; across government and business they have consistently stated that the positive effects of 
cyber insurance on cyber security have yet to fully materialize. 

If the benefits are to be crystallized, the insurance industry must overcome significant challenges.

Some challenges include: 
  • The industry is struggling to collect and share reliable cyber risk data that can  inform underwriting and risk modelling. 
  • The insurers and reinsurers are unable to accurately assess organization's risk profile or price policy premium.
  •  The number of systemic incidents has limited the availability of capital for cyber insurance markets.

To overcome these challenges, a more coordinated action by government and regulators is necessary to help the industry reach its full potential.

Some coordination's include:
  •     Developing guidance for minimum security standards for underwriting
  •     Expanding data collection and data sharing
  •     Mandating cyber insurance for government suppliers
  •     Creating a new collaborative approach between insurers and law enforcement agencies 

Finally, It is important to note that a good cyber hygiene is still the responsibility of your organization, 
and the primary purpose of cyber insurance is to transfer residual risk
 

See You at The Top...

Saturday, May 09, 2020

Cyber Threat in Digital Market

How to succeed in business without really trying...…………...Shepherd Mead (Title of book, 1952)

The pandemic a Human virus (Covid19) is changing how we work, study, digest news, and entertain ourselves.



Social app usage is exploding, daily downloads of Houseparty have risen 25x.
Collaboration apps are now household names, worldwide daily downloads of Zoom's mobile app have increased by 14x

The virus has forced the entire office online, making companies reliant more than ever on their digital systems.

To stay competitive in the marketplace we have to work remotely and sometimes at home.

Effective Tips:

1. Start your day early
2. Structure your day as you would in the office
3. Choose a dedicated workspace

Zoom, having skyrocketed in popularity, has experienced such a surge in videoconference hijacking “Zoom-bombing.”

The stakes of protecting our digital systems from a cyberattack could not be higher.
Once a cyberattack occurs, companies and employess are largely on their own. They have to scramble to counteract the attack and eliminate the threat.

Effective Tips:

1. Stay up to date on current scams.
Make sure all employees are aware of the most current scams and that your information security program has prepared a defense.

2. Password-protect your videoconferences.
To protect your videoconferences, do not post the link publicly. Make sure to require a meeting password, share the link and password only with authorized guests, and lock the meeting after it begins

3. Enable multi-factor authentication everywhere.
Enabling MFA will stop all but the most sophisticated threat actors and it should be used on all accounts that are used by the company

4. Determine an alternative method for senior leadership to communicate.
If the unthinkable does happen and an attack brings down your company systems, how will senior leadership communicate among themselves and with employees?

5. Review your incident response plan.
Every company should have an up-to-date, written plan in the event of an attack. It should be crystal
clear as to who is to do what and who you will call for outside assistance.

6. Check your cyber-insurance policy.
Do you have good cyber-insurance? These policies have become more comprehensive and cover more than they did a few years ago.

7. Educate your employees.
Train your employees on cyber security awareness and special care is needed as hackers try to take advantage of the crisis and a disrupted workplace

Contact us for your Cooperate Training

See You at the Top


Friday, January 31, 2020

AI and CyberCrime

A citizen, first in war, first in peace and first to the hearts of his countrymen--------(Henry Lee on death of General Washington 1800)




In the ever-changing cyberthreat landscape, organizations will have to defend against increasingly complex and interconnected risk.

For example. 
The Ukraine power grid attack used spear phishing, industrial control, and disk wiping techniques that were all readily available on the black market, many of them previously stolen from NSA.

Checks and balances do not work as well for cyberwarfare where plausible deniability or even misdirecting the blame to someone else is common.

As organizations continue to grow, so do the size and complexity of their technology and data estates,
meaning attackers have more surfaces to explore and exploit.

AI has the potential to accelerate the volume of attacks as automation of tasks and enhancement of malicious services further reduce barriers of entry and execution of attacks.

The tools to accomplish attacks are increasingly available on the Dark Web at decreasing costs, including cyber weapons stolen from the NSA and CIA. 

Adversarial AI: 
Adversarial attacks involve manipulating AI systems by introducing carefully crafted inputs designed to deceive or mislead the algorithm. In the context of cybersecurity, adversarial AI techniques can be used to evade detection mechanisms, bypass security measures, or fool AI-powered defense systems. Researchers are exploring ways to develop robust AI algorithms that are resistant to adversarial attacks.

Deepfakes and Impersonation- Cyber attackers can use AI to create deepfake voices and impersonate high-ranking executives. A well-executed deepfake could deceive employees into authorizing large unauthorized fund transfers, exploiting human trust to circumvent security measures.

Data Tampering and Fabrication- Attackers can use AI to tamper with system data, creating an alluring yet entirely fabricated stock portfolio. The line between genuine and manipulated information blurs, posing risks to financial systems and investor confidence.

AI is not a single technology but a family of technologies. There are five broad categories of AI technologies: computer vision, natural language, virtual assistants, robotic process automation, and advanced machine learning. Hackers will likely use these tools to varying degrees.

Responsible AI Deployment:
Organizations must balance the benefits of AI with ethical considerations. Transparent algorithms, robust authentication mechanisms, and human oversight are crucial.

AI-Driven Defense: 
On the flip side, AI can also be used for cybersecurity purposes to detect, prevent, and respond to cyber threats more effectively. AI algorithms can analyze vast amounts of data to identify patterns, anomalies, and potential security breaches in real-time. AI-powered security solutions can enhance threat detection capabilities and help organizations stay one step ahead of cybercriminals.

Skills Gap: Addressing the cybersecurity challenges posed by AI requires a skilled workforce with expertise in both cybersecurity and AI technologies. However, there is a significant shortage of cybersecurity professionals with AI knowledge and vice versa. Closing this skills gap will be essential for developing effective AI-driven cybersecurity solutions and combating cyber threats effectively.


See You at The Top


Tuesday, November 26, 2019

Police the Machines

Machine harm, like any other vice, requires no motive outside itself. It only requires opportunity ............... Emmanuel.Sodipo



Technology is now deeply intertwined with our socio-technical systems at all levels. Software now constrains behavior with an efficiency that no law can match. Technology is literally creating a new world and policies can’t keep up.

Getting it wrong has become increasingly catastrophic and a growing constituency is starting to hold reckless tech businesses accountable.

Consider artificial intelligence (AI), the technology that has the potential to augment human decision making with something more scalable and faster. But also has the potential to entrench bias and codify undesirable acts. It can be hacked in new ways with new capabilities to disrupt and harm.

Cognitive Architectures:
These models simulate human cognition, including perception, memory, reasoning, and problem-solving. Examples include ACT-R (Adaptive Control of Thought-Rational) and Soar.

Evolutionary Algorithms:
Inspired by natural evolution, these algorithms optimize solutions by evolving a population of potential solutions over generations. Genetic algorithms and genetic programming fall into this category.

 Other technologies we should police are:
  • Critical Cybersecurity vulnerabilities 
  • Role of social media platforms in propaganda 
  • Bioengineering such as genome editing and synthetic biology.
  • Robotics as a common consumer technology

Ethics owners and policy makers must navigate between avoiding measurable downside risk and promoting the upside benefits. Arguing against releasing a product before it undergoes additional testing for racial or gender bias is one thing. Arguing that a more extensive test will lead to greater sales is another thing.

Both are important but one sits with compliance the other with marketing. 

We should aim to achieve a robust process rather than a substantive outcome.

See You at the Top


Monday, September 29, 2014

Espoinage on Business Trips

He who has never learned to obey cannot be a good commander. —Aristotle



While traveling for business, a professional carry a set of goals to expand to new markets, close out promising sales, or open up new opportunity with foreign partners. To obtain the data needed to support such efforts, a business professional typically travels with a device that includes contacts, presentations, and data sheets. While such information is valuable to the business professional and his or her organization, it is much more valuable to a competing organization, or authoritarian government, that would like to close the gap on research and development.

Case Studies:

Consider the customer of a security products company on a trip Abroad. The traveler brought with him his Android smartphone and, as a precaution, noted the version of the operating system that the device was running before leaving. When he woke up in his accommodations on site, he noticed that the version of the operating system had been changed due to an unauthorized update that had been pushed over the air. Such an unauthorized update could allow the device to be used as a microphone, listening in on conversations in any room the device was located. Such a compromised device could also siphon off data including emails, texts, and stored files.

An executive at a security technology company cleared the data on his phone before heading overseas and used the clean phone for voice calls only. Upon returning home, the device would not boot properly and needed the firmware loaded from scratch. Forensics were performed on the device to determine the root cause- which could only come from an unlikely, invisible update from the device manufacturer- or an attack against the device aimed at compromising it.

Many different types of devices can be the target of such attacks. Think of all the different devices you might take with you when you travel, whether for business or vacation:

·         Laptop
·         Smartphone
·         Tablet
·         Digital camera
·         Camcorder
·         Audio player
·         Flash drives
·         Memory cards

Each of the above devices contains some form of data or code that runs on the device. If the device has WiFi, mobile access, or active Bluetooth, there is a possibility of it being compromised through one of those wireless interfaces. If a device is left behind in a hotel room or other unsecured location, it could be tampered with, duplicated, or stolen.

There are several methods to secure, minimize, or even hide data. These methods include using encryption, making backups, traveling with reduced information- or “clean device” that has no data.
Other solutions include data that is only sent or made available remotely once the traveler has arrived and then revoked when returning. While these methods are geared toward border crossings that may subject the travel to additional scrutiny, they work equally well against espionage performed by competitors or authoritarian governments.

See You at the Top

Tuesday, June 25, 2013

The Business Illusion of Security by Government

Maintaining privacy from the powerful duo of government and business is basically an illusion. Any privacy we perceive is based on either ignorance or deception.




The "illusion of security" is the phenomenon where individuals or organizations perceive themselves 
as secure, but in reality, they are vulnerable. This false sense of security can stem from overreliance
 on certain measures, such as technology or external factors, without addressing all critical aspects 
of security. For example, in IT, it describes misplaced confidence in security tools while neglecting 
people and processes that are essential for real protection. Similarly, on a personal level, 
the illusion of security can manifest as believing job stability, education, or financial status 
guarantees safety, but these can be unstable or temporary, leading to a fragile sense of security

The Cloud of Things refers to a world where much more than our computers and mobile phones is Internet-enabled. A world where our cars, clothing and home appliances are equipped with Internet-connected modules.

Consider these Illusions:

If the government requested that we all carry tracking devices 24/7?
We would rebel. Yet we all carry mobile phones and drive our cars.

If the government requested that we deposit copies of all of our messages with the police?
We would declare their actions invasive and unconstitutional. Yet we all use Gmail and Facebook.

If the government requested that we give them access to our photographs, identify the people and tag them with locations?
We would refuse and call it a Police State. Yet we leave those details on our devices and applications while the updates on those devices and applications happen automatically, without our knowledge or consent.

Consider these Possibilities:

Today's cyber-issues involve systemic social, economic, organizational, and political components.

What if we decide to stay away from all these cloud technologies?
Our friends could tag, call or even visit us in their brand-new cars, and we would still be living in a world of illusion.

What happens when we are faced with a Rogue Business or Government?

Ultimately, true security goes beyond external conditions and requires building inner resilience 
and an awareness that the feeling of security is a state of being one cultivates within oneself, 
rather than something ensured by external factors alone.

In entrepreneurship, the illusion of security might relate to myths or misconceptions entrepreneurs 
hold about success factors, which can mislead and harm prospects if they act on false assumptions 
rather than reality.

This thought highlights the importance of vigilance, holistic approaches, and self-awareness in 
creating authentic security rather than a deceptive sense of safety

See You in Space..........


Tuesday, June 28, 2011

Securing the Digital Universe

The term "digital universe" refers to the vast and ever-expanding collection of digital data and information that exists in various digital formats, stored across numerous devices, systems, and platforms. It encompasses all the data generated, transmitted, and stored by individuals, organizations, and systems in the digital age. 

Here are some key aspects of the digital universe:

Data Types- The digital universe comprises a wide range of data types, including text, images, videos, 
audio, sensor data, structured and unstructured data, and more. This data is generated by humans, 
machines, and various digital devices and systems.

Data Sources- Data in the digital universe originates from various sources, including social media interactions, internet browsing, online transactions, mobile apps, IoT (Internet of Things) devices, 
sensors, scientific research, and business operations.

Data Growth- The digital universe is characterized by exponential data growth. Advances in technology, increased connectivity, and the proliferation of digital devices have contributed to the rapid expansion of this universe.

Big Data- Much of the digital universe falls under the category of "big data" due to its volume, velocity, variety, and complexity. Analyzing and extracting insights from this data can be challenging but also 
highly valuable.

Data Privacy and Security- With the vast amount of data in the digital universe, concerns about data privacy and security are paramount. Safeguarding personal and sensitive information from unauthorized access and breaches is a significant challenge.


Approximately 75% of the digital Universe is a copy, only 25% is unique, while enterprise account for 20% of the data generated, they are liable for 80% of the data created and by 2020 more of this data will live or pass through the cloud.

In terms of sheer volume of data to be protected from 2009 to 2020 the amount of data in the Digital Universe is expected to grow by a factor of 44times to 35 trillion gigabytes. Although identity, financial account and credit card data are the most sought after even surpassing illicit drugs as organized crime most desirable commodity.

The compromise of system data i.e. configurations, settings and log files can be the gateway for access to this data and needs continuous monitoring and protection.

I Wish You Great Success

Friday, May 27, 2011

Privacy Versus Secrecy


Privacy and secrecy are related concepts that involve controlling access to information, but they are distinct in terms of scope and context.

To the older generation privacy is about secrecy and once something is no longer secret it is no longer private.

To the younger generation privacy is about control, a lot of data is shared with government agencies, employers and social media, but when you can control the flow of your data and who is granted access then it is considered private

Privacy and secrecy are related concepts that deal with the protection of information, but they have distinct meanings and implications.

Privacy refers to an individual's right to control their personal information and data, as well as the freedom to keep certain aspects of their life or activities confidential from others.

The scope of Privacy encompasses a broad range of personal information, including but not limited to communication, financial details, medical records, and lifestyle choices.

Privacy often emphasizes giving individuals control over their personal information, allowing them to choose what information they share and with whom.

Secrecy, on the other hand, pertains to intentionally keeping information hidden or confidential from others. 
It is often a deliberate act of concealing specific information or knowledge.

The scope of Secrecy can apply to various types of information, including personal, organizational, 
or government-related details. It may involve trade secrets, classified information, or confidential business strategies.

Secrecy may require the implementation of security measures such as restricted access, encryption, and authentication to prevent unauthorized disclosure.

While privacy and secrecy share the common goal of controlling access to information, privacy is typically more concerned with protecting individual rights and personal data, while secrecy often extends to a broader context, including organizational and governmental matters. Both concepts, however, play crucial roles in maintaining trust, security, and ethical standards in various aspects of personal and collective life.

Friday, November 05, 2010

Bribery in a Security Perspective

“Security is mostly a superstition. It does not exist in nature, nor do the children of men as a whole experience it. Avoiding danger is no safer in the long run than outright exposure. Life is a daring adventure or nothing at all.”............ Helen Keller

Bribery from a security perspective is a form of corruption that severely undermines both public 
and national security. It often acts as a facilitator for insecurity by allowing illegal activities 
to flourish, such as smuggling, human trafficking, arms trading, and enabling terrorist movements. 
Bribery of security personnel at checkpoints or borders can provide safe passage for criminals 
and terrorists, compromising the safety of citizens and entire states.

The Bribery Act 2010 comes into force in April 2011 in UK, and it is important we are all well-informed about it. The Act creates offences of individuals or commercial organizations giving or receiving a bribe. If a commercial organisation has committed an offence, any senior officers who have consented or connived are also liable. 

The Act creates a new, separate offence of bribing a foreign official. It also creates an offence of failing to prevent bribery.
The offence of bribery can be committed by anyone associated with the company -- this will capture employees, subsidiaries, agents, joint venture partners and anyone who provides a service for the organization. The bribery can take place anywhere in the world and the Act specifically makes no allowance for local custom or practice in foreign jurisdictions. It is a strict liability offence, and a statutory defense is only available if the organization can show it had "adequate procedures" in place to prevent Bribery.

Consider the recent events in China.

GSK CORRUPTION

China has barred a GlaxoSmithKline executive from leaving the country as it turns up the heat on the drug maker over allegations of corruption.

Steve Nechelput, finance director for GlaxoSmithKline China, has been prevented from traveling outside China since June.

The U.K. drug maker has been accused by China of using a network of more than 700 travel agencies and other firms to channel bribes to health officials since 2007.

It would be an interesting terrain to observe.

Bribery also facilitates corruption within political, military, social, and economic systems, 
weakening institutions that uphold security and rule of law. This corruption creates 
vulnerabilities that criminal and insurgent groups exploit to further violence and instability. 
In many cases, the misuse of public funds and bribery in security sectors leads to diminished 
accountability and increases opportunities for organized crime and terrorism

I Wish You Great Success

Friday, September 24, 2010

Technological Trend

The trend here is for new technologies to be made available for the consumer market before they are available to the business market.

The consumer market and the business market (also known as the business-to-business or B2B market) 
represent two distinct segments of the economy with different characteristics, buying behaviors, 
and marketing approaches

Here are the key differences between the consumer market and the business market:

Target Audience.
Consumer Market- Targets individual consumers or households as end-users of products or services.
Business Market- Targets organizations, businesses, or institutions as customers.

Buying Decision.
Consumer Market- Typically involves individual or family decision-making units. Purchases are often made for personal use.
Business Market- Involves a more complex decision-making process with multiple stakeholders, including various departments and decision-makers within an organization.

Purchase Volume.
Consumer Market- Involves smaller, individual transactions. Purchases are usually made in smaller quantities.
Business Market- Involves larger, bulk transactions. Purchase volumes are often higher due to business needs.

Businesses are under pressure to use these new technologies. Younger employees simply are not satisfied with using outdated technology. They're either going to figure out ways around the corporate security rules or change jobs to a trendy company.

With cloud computing a lot more employee computing devices are nothing more than dumb terminals with a browser interface; When corporate e-mail is all webmail, corporate documents are all on Google Docs, and when all the specialized applications have a web interface, it's easier to allow employees to use any up-to-date browser.

Senior management may also pressure security out of the way, they may want to get to the company's databases from their brand-new iPad.

With these pressure from employees and senior management, it is going to be harder and harder to say no to consumer tech.
 
I wish You Great Success.

Thursday, August 26, 2010

Social Media Data

User data refers to the information collected from individuals while they interact with various online platforms, services, or devices. Here are some important facts about user data:

Types of User Data.
Personal Information- Includes names, addresses, phone numbers, and other identifiers.
Demographic Information- Age, gender, income, education level, etc.
Behavioral Data- User actions, preferences, browsing history, and interactions with content.

Collection Methods.
Explicit Data Collection- Users provide information willingly (e.g., filling out forms).
Implicit Data Collection- Data is collected without the user's direct input (e.g., cookies, tracking pixels).

Data Privacy.
Concerns- Users are increasingly concerned about how their data is collected, stored, and used.
Regulations- Various data protection laws, such as GDPR in Europe and CCPA in California, aim to protect user privacy and give individuals control over their data.

Data Security.
Encryption- Protects user data during transmission and storage.
Security Breaches- Incidents where unauthorized individuals gain access to user data, emphasizing the need for robust security measures.

Monetization.
Business Model- Many online platforms monetize user data by using it for targeted advertising and personalized services.
At the back end, social networking sites can monetize all of the data. Generally, by selling targeted advertising, users often do not mind if a site uses its data to target advertisements, but users are less appreciative when it sells that data to third parties.
Free Services- Users often exchange their data for free access to various online services.

There are different ways to look at user data.
Some of it you give to the social networking site in confidence, expecting the site to safeguard the data.
Some of it you publish openly, and others use it to search for you. 
some of it you share only within a circle of other users.

Different social networking sites give users different rights for each data type.
Some are always private,
some are always public.
Some can be edited or deleted. 
Some can be viewed, and some cannot.

It is fundamental that users should have different rights with respect to each data types. Users should be allowed to export, change, and delete disclosed data.

I Wish You Great Success

Monday, January 26, 2009

Biometric Security

Biometrics are the oldest form of identification. Fingerprints have been used to identify people at crime scenes for more than 100 years.

What is new about biometrics is that computers are now doing the analyzing: thumbprints, retinal scans, voiceprints, and typing patterns. There's a lot of technology involved, in trying to both limit the number of false positives (someone else being mistakenly recognized as you) and false negatives (you being mistakenly not recognized). Generally, a system can choose to have less of one or the other; less of both is very hard.

Biometrics can vastly improve security, especially when paired with another form of authentication such as passwords. But it's important to understand their limitations as well as their strengths. On the strength side, biometrics are hard to forge. 

On the negative side, biometrics are easy to steal. You leave your fingerprints everywhere you touch, your iris scan everywhere you look. Regularly, hackers copy prints from objects touched, and posted them on the Internet.

Passwords can be changed; Passwords can be backed up but if someone copies your thumbprint or you alter your thumbprint in an accident, you're stuck. Biometric systems need to be analyzed in light of these possibilities. 

Biometrics are unique identifiers, but they're not secrets.

A stolen biometric can fool some systems. Remote logins by fingerprint fail, if there's no way to verify the print came from an actual reader, not from a stored computer file.

A more secure system is to use a fingerprint to unlock your mobile phone or computer. Because there is a trusted path from the fingerprint reader to the stored fingerprint the system uses to compare, an attacker can't inject a previously stored print. 

However, researchers have made false fingers out of rubber or glycerin. Manufacturers have responded by building readers that also detect pores or a pulse. The lesson is that biometrics work best if the system can verify that the biometric came from the person at the time of verification. 

Biometrics are easy, convenient, and when used properly, very secure. Understanding how they work, and fail is critical to understanding when they improve security and when they don't.

I wish You Great Success.

Sunday, May 18, 2008

Secure your Data

Encrypting your entire hard drive, something you should certainly do for security in case your computer is lost or stolen, or even interborder travels.

The border agent is likely to start this whole process with a "please type in your password." Of course you can refuse, but the agent can search you further, detain you longer, refuse you entry into the country and otherwise ruin your day. You're going to have to hide your data. Set a portion of your hard drive to be encrypted with a different key and keep your sensitive data there.

Lots of programs allow you to do this. I use PGP Disk (from pgp.com).
TrueCrypt (truecrypt.org) is also good, and free.

While customs agents might poke around on your laptop, they're unlikely to find the encrypted partition. (You can make the icon invisible, for some added protection.) And if they download the contents of your hard drive to examine later, you won't care. Be sure to choose a strong encryption password. 

A customs agent can't read what you don't have.
You don't need four years' worth of email and client data.
You don't need your old photos and love letters.

Delete everything you don't absolutely need using a file erasure program. Delete your browser's cookies, cache and browsing history. Turn your computer off - don't just put it to sleep - that deletes other things.

Some organizations now give their employees forensically clean laptops for travel and have them download any sensitive data over a virtual private network once they've entered the country. 
They send any work back the same way and delete everything again before crossing the border to go home. 

Also, you can consider putting your sensitive data on a USB drive or a memory card: Encrypt it because it's easy to lose something that small. Slip it in your pocket, if custom discovers it, you can try saying: 
"I don't know what's on there. My boss told me to give it to the manager." With a strong encryption password, you won't care if he confiscates it.

Finally, don't forget your phone and PDA. Delete: emails, your phone book and your calendar. 

I wish You Great Success.

Tuesday, April 22, 2008

Threat Contest

When discussing "threat possibilities," it typically refers to potential risks or dangers that could negatively impact individuals, organizations, or systems. Threats can manifest in various forms and 
contexts. Here are some common threat possibilities:

Cyber Threats:
Malware: Viruses, ransomware, and other malicious software.
Phishing: Attempts to trick individuals into revealing sensitive information.
Hacking: Unauthorized access to computer systems or networks.

Physical Security Threats:
Burglary: Unauthorized entry with the intent to commit theft or vandalism.
Vandalism: Deliberate destruction or damage to property.
Terrorism: Acts of violence with the intention of causing fear or intimidation.

Natural Disasters:
Earthquakes, Floods, Hurricanes, Fires: Environmental events that can cause significant damage and disruption.

Financial Threats:
Fraud: Deceptive practices for financial gain.
Economic Downturn: Economic conditions that negatively impact businesses and individuals.

Health Threats:
Pandemics: Widespread outbreaks of infectious diseases.
Biological Threats: Deliberate use of biological agents for harm.

Supply Chain Disruptions:
Logistical Issues: Interruptions in the supply chain that affect the flow of goods and services.

Geopolitical Threats:
Political Instability: Unrest or political changes that can impact stability.
Trade Disputes: Conflicts affecting international trade relations.

Social Engineering:
Manipulation: Psychological tactics to deceive individuals into divulging confidential information.
Impersonation: Pretending to be someone else to gain access or trust.

Environmental Threats:
Pollution: Contamination of air, water, or soil.
Climate Change Impact: Long-term changes affecting ecosystems and communities.

Human Error:
Accidents: Unintentional actions that lead to negative consequences.
Misconfigurations: Errors in system configurations that may lead to vulnerabilities.

Legal and Regulatory Risks:
Non-compliance: Failure to adhere to laws and regulations, leading to legal consequences.

Understanding these threat possibilities is crucial for risk assessment and the development of 
mitigation strategies
For threat contest, the goal is to create fear that you can alleviate through the sale of your 
new product idea. There are lots of risks out there, some of them serious, some of them so unlikely that we shouldn't worry about them, and some of them completely made up. And there are lots of products out there that provide security against those risks. The task is to invent one.

First, find a risk or create one. It can be a terrorism risk, a criminal risk, a natural-disaster risk, a common household risk, whatever. The weirder the better. Then, create a product that everyone simply will buy to protect themselves from that risk. 

It's okay if the product you invent doesn't actually exist, but this isn't a science fiction contest. You will be judged on creativity, originality, persuasiveness, and plausibility.

Sample example products:
-Acoustical devices that estimate tiger proximity based on roar strength.
-GPS-enabled wallets for use when you've been pickpocketed.

Fear offers endless business opportunities.

I wish You Great Success.

Tuesday, February 19, 2008

Business Continuity Manangement

The BCM objectives as defined within the standard are “to counteract interruptions to business activities and to protect processes from the effects of major failures of information systems or disasters and to ensure timely resumption”. 
Usually, the better prepared you are, the more likely you will be to meet this objective, and the more effective will be your recovery.

Unfortunately, many organizations do not properly embrace risk assessment, and often start their business continuity project ill prepared.

PREPARATION: It is important at the outset to have the full commitment of the Board or Governing Body of the organization. Without this, problems downstream are inevitable. An awareness campaign should follow, to ensure that all staff are notified of that commitment. The business continuity project can then be initiated (central to which is the delivery of a business continuity plan). 
It is essential, however, that this project is formal and structured. Initial steps for the project itself will 
include defining scope and obtaining copies of all appropriate documents and information.

A formal risk assessment exercise must follow.

RISK ASSESSMENT: Initial emphasis on effective risk assessment will enable you to predict different types of incidents with more accuracy. It will help ensure that focus is applied to those areas to which it is most needed.
This aspect of BCM involves analyzing the business processes and identifying vulnerabilities through risk assessment and probability analysis. It includes the establishment of critical business timeframes including recovery time objectives (RTO) and maximum tolerable period of disruption (MTPD).

The RTO will represent the time interval between the incident occurring and the time when a measurable negative impact will result on the business whereas the MTPD will represent the time interval between the incident occurring and the time when the impact from the incident will become extremely serious for the business.

Following a detailed risk analysis of the business and its processes, suitable levels of safeguards and controls should be implemented that will protect the business processes and product delivery. It is important to understand that none of the above tasks can be short cut.

Proper planning and preparation may seem to be a burden, but the pay back could well be the survival of the organization itself. Fortunately, this is a well-trodden path, and specialist portals like the 
Disaster Recovery Planning Guide provide sound advice on how to take the initial steps described above.


I wish You Great Success.

Saturday, December 22, 2007

Secure your Disk

Computer security, including the security of hard disks, is crucial for protecting sensitive data and ensuring the integrity and confidentiality of information stored on computers. It is of utmost importance to safeguard your data and privacy.

Software, computer and network security are all ongoing battles between attacker and defender. Her Majesty's Revenue & Customs in the United Kingdom lost two disks with personal data on 25million British citizens, including dates of birth, addresses, bank-account information and national insurance numbers. A similar event occurred with The U.S. Veteran's Administration with the loss of 26 million personal data of American veterans.

When using an external hard drive or SSD, consider opting for one that offers strong encryption. These drives allow you to encrypt selected files and store them securely. Some hard drives are self-encrypted at the hardware level. 

Cryptography can solve the security of data when it's not in use. Encrypting files, archives and even entire disks. The defender has an inherent mathematical advantage: 
Longer keys increase the amount of work the defender has to do linearly, while geometrically increasing the amount of work the attacker has to do. Unfortunately, cryptography can't solve all computer-security problems.

The reason you should encrypt your entire disk, and not just key files, is so you don't have to worry about swap files, temp files, hibernation files, erased files or browser cookies. You don't need to enforce a complex policy about which files are important enough to be encrypted. And you have a quick answer to regulators and the press if the computer is stolen: "no problem; the laptop is encrypted."

Encrypt everything you don't need access to regularly, archived documents and old e-mails.
You should also encrypt external disks, which means you can secure USB memory device when travelling.

Properly disposing of old hard disks and securely wiping data before decommissioning or repurposing them helps prevent unauthorized access to sensitive information that may still be stored on the disks.

Implementing monitoring and auditing mechanisms allows organizations to track and analyze activities related to the hard disk, detect suspicious behavior, and investigate security incidents.

Although, you are not secure against the authorities telling you to decrypt your data for them.
You can try to convince the authorities that you don't have the encryption key. 

You're also not secure against someone at your unattended computer, a Trojan infected computer or 
someone snatching your laptop while at the local coffee shop. 
 
Computer security is hard; The best defense against data loss is to not have the data in the first place or to minimize the amount of data on your laptop.

Educating users about best practices for computer security, including safe browsing habits, password management, and recognizing phishing attempts, helps mitigate human-related security risks that could compromise the security of the hard disk.

I wish You Great Success.

Saturday, August 04, 2007

Security and Compliance 3

How to do BS7799/ISO17799 Projects

Who to Interview?
Security Management --------Sec Policy/Organization
Security Management -----------Asset Classification and Control
Typically, HR --------------------- Personnel Security
Site Security/IT manager------- Physical and Environmental Security
Business Manager/IT Manager--------------- Communications and
Operations Management
System Administration Staff---------------- Access Control
Development Staff-------------- System development
Business Continuity Manager---------- Business Continuity Management
Internal Audit/Legal-------------- Compliance
Appropriate staff/line Management----------- Business/Info Process
A Good Gap Analysis

Clearly defined scope
Clear findings against each control (good areas as well as gaps)
The ISMS
Clear practical and appropriate recommendations leading to compliance.
All recommendations reinforced and supported by findings.

Finalizing Resources

Resourcing:
Match actions with in-house resources and confirm availability.
Identify availability shortfalls.
Identify where specialist support is needed.
Obtain necessary approvals for SIP.
Ensure the group have access to the full
Gap Analysis Report for guidance
Establish the ISMS through the creation of the Information Security Forum

Risk Assessment and BS7799/ISO17799

Define a systematic approach to risk assessment.
Identify the risk.
Assess the risk.
Select control objectives and controls for the treatment of risk.
Identify and evaluate options for the treatment of risk.

Generic Steps

Identify assets.
Identify asset dependencies.
Business Impact Assessment (Asset Valuation)
Threat Assessment
Determine levels of risk (Risk Assessment)
Countermeasures Selection
Map to BS7799/ISO17799
Risk Treatment

Document Management

BS7799/ISO17799 section 4.3 calls for Distribution /Availability to staff as required.
Version/ Change control
Documents to be dated (Including previous versions)
By implications, uniquely identifiable and fully controlled.

ISO 9001 compliance is an advantage.

Appropriate change control is needed for intranet solution.

10 Tips for Success

1. Ensure senior management involvement
2. Recommend a realistic and useful scope
3. Develop a good risk assessment
4. Promote Active Risk management
5. Interpret the controls for the scope
6. Ensure early Security Forum creation
7. Ensure maximum use of the Statement of Applicability
8. Get internal third parties to sign up
9. Get audits underway to raise assurance
10. Take staff awareness seriously

I wish You Great Success.

Tuesday, July 31, 2007

Evaluating Security

The exact role of internal audit regarding information security varies widely among companies, but it always provides a significant opportunity for internal audit to deliver real value to the board and 
management. Internal auditors should play an important role in ensuring that information security efforts have a positive effect on an organization and protect the organization from harm.

Why worry so much about information security? Consider some reasons why organizations need to protect their information:

Availability. Can your organization ensure prompt access to information or systems to authorized users? 
Do you know if your critical information is regularly backed-up and can be easily restored?

Integrity of data and systems. Are your board and audit committee confident they can rest assured that this information has not been altered in an unauthorized manner and that systems are free from unauthorized manipulation that could compromise reliability?
Confidentiality of data. Can you tell your customers and employees that their nonpublic information is safe from unauthorized access, disclosure, or use? This is a significant reputational risk today!

Accountability. If information has been compromised, can you trace actions to their source?
An audit of information security can take many forms. At its simplest, the auditors will review the 
information security program’s plans, policies, procedures, and key new initiatives, plus hold some interviews with the key stakeholders. At its most complex, a large internal audit team will evaluate almost every aspect of the security program and even do intrusion testing.
This diversity depends on the risks involved, the assurance requirements of the board and executive management, and the skills and abilities of the auditors.

For example, if the organization is undergoing extensive change within its IT application portfolio or IT infrastructure, that would be a great time for a comprehensive assessment of the overall information security program (likely best just before or just after the changes). If last year’s security audit was positive, perhaps a specialized audit of a particular activity or an important e-commerce application would be useful. 

The audit evaluation can, and most times should, be part of a long-term (read: multi-year) audit assessment of security results.

I wish You Great Success.

Wednesday, July 25, 2007

Security and Compliance 2

BS7799 Contents of Part 1

• Scope
• Terms and definitions
• Security policy
• Security organisation
• Asset classification and control
• Personnel security
• Physical and environmental security
• Communications and operations management
• Access control
• Systems development and maintenance
• Business continuity management
• Compliance

BS7799 Contents of Part 2

• Scope
• Terms and definitions
• Information security management system requirements
• Detailed controls
1. Security policy
2. Security organisation
3. Asset classification and control
4. Personnel security
5. Physical and environmental security
6. Communications and environmental security
7. Communications and operations management
8. Access control
9. System development and maintenance
10. Business continuity management
11. Compliance

Critical Success Factors

• Policies, Objectives and Activities that reflect business objectives
• Appropriate resources
• Consistency with culture
• Visible support and commitment from management
• Clear understanding of the security requirements and risk
• Effective marketing of security to all employees
• Distribution of information to all partners, suppliers, employees and contractors
• Providing appropriate training and education
• Key performance indicators

Selecting Controls

• Identify business objectives
• Identify business strategy
• Identify security strategy
• Identify and implement controls

Key controls

1. Information security policy document
2. Allocation of security responsibilities
3. Information security education and training
4. Reporting of security incidents
5. Virus controls
6. Business continuity planning
7. Control of proprietary software copying
8. Safeguarding of company records
9. Compliance with data protection legislation
10. Compliance with the security policy

Certification requirements for BS7799 /ISO 17799

Organisation shall establish and maintain a document ISMS
• Management framework
1. Risk management approach
2. Identify control objectives and controls
3. Documented evidence: - evidence of the actions undertaken - a summary of the management frame
 work - the procedures adopted to implement the controls - the procedures covering the management 
and operation of the ISMS

In 2005 International Organization for Standardization released a specification, ISO 17799 in 2005
 which establishes guidelines and general principles for initiating, implementing, maintaining and 
improving information security in an organization. They intended to be implemented to meet the 
requirements identified by a risk assessment.

Management frame work

• Define the policy
• Define the scope of the information security management system
1. Characteristics of the organisation
2. Location
3. Assets
4. Technology
• Undertake risk assessment
1. Threats
2. Vulnerabilities
3. Impacts
4. Degree of risk
• Manage the risks
• Select control objectives & controls
• Prepare statement of applicability
1. Selected control objectives and rationale
2. Exclusion of controls and rationale

Applying BS7799/ISO17799

• A Practical Approach
• Gap Analysis
• Action Planning
• Risk Assessment and Treatment
• Developing an improvement programme
• Effective Statement of Applicability
• Planning and Costing a BS7799/ISO17799 project
• ISMS (Information Security Management System)
• Audit

I wish You Great Success.