Monday, November 17, 2008

What is 201 CMR 17:00?

Question:
What is 201 CMR 17:00?

Answer:

201 CMR 17:00 is yet another bigger brother telling us to the right thing…

The requirements simply enforce security of state of Mass residents’personal information… You may presume that the data is already secure. Well, that is wrong, just listen to the complaints for the requirements,
If you have a business and you do carry “personal information” about a Massachusetts resident then you must take care of the requirements listed in 201 CMR 17:00

The Office of Consumer Affairs and Business Regulation (OCABR) issued a comprehensive set of final (yes it is always final :) regulations establishing standards for how businesses protect and store consumers’ personal information as of September 22 2008. There is an executive order signed by Mass governor Deval L, Patrick related with this regulation., the irony is that it ends with “God Save the Commonwealth of Massachusetts”


The 201 CMR 17:00 standard is related with the M.G.L c. 93H because with the "general law chapter 93H –security breaches" there comes the enforcement leg of the regulation.

Implementation deadline is January 1, 2009 but an extension to May 2009 is hughly expected. Companies will be required to conduct internal and external security reviews and complete employee training


Of course most the technology associations, CPAs oppose to the regulation. They all have their reasons (not enough time, slow investment , harsh economic times etc). Mass CPA web site states that the compliance deadlines have been extended to May 1, 2009 (Jan 1, 2010 for 3rs party verifications and encryption). It is scary to know that the personal information is staying “clear” until then.

So what is it? “Every person that owns, licenses, stores or maintains personal information about a resident of the Commonwealth shall develop, implement, maintain and monitor a comprehensive, written information security program applicable to any records containing such personal information”

Personal information is defined with the following:Resident’s first name and last name or first initial and last name in combination of the one or more of the following data elements:
1. Social Security number
2. Driver's License number
3. Financial Account number (credit card, debit card)
4. Any means of access information for personal financial information

After a quick read, I came up with the following short/dirty to-do list for the 201 CMR 17:00 requirements:

1. Verification of current information security management system or framework
2. Assessment of current asset inventory for customer owned systems
3. Assessment of current information security roles and workflow
4. Assessment of policy enforcement for existing policies.
5. Verification of an information security risk management framework. Review of internal and external risk assessments.
6. Assessment of risk mitigation plan
7. Assessment of options for employee awareness programs for information security
8. Delivery of required policies matrix
9. Assessment of current employee termination procedures. Verification of enforcement
10. Assessment 3rd party business partners’ access to customer owned personal information. Cross-verification of 3rd party privacy policies
11. Assessment of workflow for personal information data collection. Verification of need-to-know principle
12. Assessment of access to personal information at customer facilities. Verification of need-to-know principle
13. Assessment of data classification for personal information at customer facilities.
14. Assessment of access logging for personal information
15. Verification of annual audit plan for personal information
16. Assessment of incident management
17. Assessment of patch management
18. Assessment of desktop/server firewall agent management, and enforcement
19. Assessment of encryption for all transmitted records and files containing personal information
20. Assessment authentication and authorization controls for personal information
21. Assessment of unique identifiers for personal information access (e.g. usernames)
22. Assessment account (password) management policy
23. Assessment of antivirus and malware policies, controls and enforcement.

My recommendation is the follow a larger framework such as ISO 27001 since there will be more compliance requirements in the future. ISO 27001 covers almost all requirements of 201 CMR 17:00



let me know if you have any questions,
- yinal

Monday, October 13, 2008

Security in outsourcing deals: problem or solution?

Question:
Security in outsourcig deals: problem or solution?
It seems to be somekind of paradox. Outsourcing could lead to efficiency if processes are standardized. So implementing security as a part of standard governance should be part of some solution. At the same time every customer demands their own security standards implemented which often differ in approach and/or weight. Each line of industry (ofcourse) have their own standard. This makes it next to impossible to deliver according all those standards at the same time (according contract) and still reach efficiency goals. Or is the whole community silently agreeying to deliver uncompliant? Anyone have any thoughts about this matter which they would like to share with me in Dutch or in English?

Answer:
.......,
I have been evaluating/auditing security aspect of outsourcing operations for a while.

It is actually possible to find efficiency in delivering security requirements for outsourcing providers.

Security has a universal interpretation, regardless of the languages that it is spoken.

You are right that every customer/ every industry/ every information security framework brings some new obligations to the solution providers, and it is not possible to offer a standard cookie-cutter solution set for a broad customer base.

Here are the tested approaches to ease the pressure of never-ending customer security requirement on outsourcing providers:

1)- Map it : When analyzed thoroughly, you will find more common requirements than the exclusive ones. In my own projects I can tell that more than 80% of the security requirements are common. The first step is to form cross-industry requirement matrixes. Several organizations deliver these mapping matrixes (e.g. ISACA) Customer has requirement A, which matches your solution B. You can find mapping matrixes for COBIT, ITIL, ISO27001, PCI, etc. For example if you have an ISO 27001 compliant service and your customer is asking for HIPAA you may easily map your existing ISO controls to HIPAA.

2)- Offer Self-Service: Flexibility of the delivery infrastructure is the most effective answer for the diverse customer requirements: When we initially developed a reporting portal, we thought that having 100 reports would be sufficient for our customer base. It wasn’t. As you have indicated, it never ends, every day there is a new requirement. We ended up building a reporting engine so that the customers can build their own reports . Today if a customer has a new security report requirement, we tell them to go to the portal and build one. For the workflow we took the same approach. We could not enforce our own workflow for escalation to all customers so we ended up developing a business rules engine. Now incidents are escalated according to customer requirements on the backoffice system. If a customer requires sophisticated flow, they choose to pay for developing their own business rules on our rules engine. It is possible to increase the number of example but I assume the idea is clear

3- Get Modular: Even the mighty outsourcing providers are brought to their knees by weird customer requirements. Make sure that the operational flow and the compliance of the outsourcing operations can interface with 3rd party specialists. That is the beauty of multi-sourcing under single contract. I was working with a large TelCo where outsourcing provider had everything but the DNS appliances, introducing a 3rd party specialist under outsourcer’s umbrella fixed the problem. If the interface agreements are done, and if there is a structured framework for auditing outsourcing service partners this is a way to grow healthy operations (low on cost side as well).

4-Focus on Service Management: Usually service/outsourcing companies rely on generic service managers who are afraid to go outside the contract terms. That does not work well in information security world. If the service managers can understand customer requirements properly and relate to outsourcing backoffice operations, many of the problems can be fixed before escalation. I like to see all customer facing members of the team working at the delivery side in the operations for a while. It is the only way to learn to flip the burger before selling it.

At the end of the day, the whole community is silently following a darwinist path, the ones who are adapting the requirements intelligently without hurting the operations and the budgets survive… The old way of my way or the highway approach just hurts the whole service industry.

I would have written more since the topic requires more attention, but please let me know if you have a specific question.

regards,
- yinal ozkan

Sunday, October 12, 2008

IT Security Consultant Jr.

Question: How can I train myself in IT Security?
I've been a technical consultant, developer and other various SDLC-related roles for quite a while now. My goal is to move into IT Security, so how do I jump-start? What should I read, or do?
I would very much appreciate if anyone can clarify what skillsets an IT Security Consultant should/must have

Answer:......,
As discussed above you have the right foundation to kick-start an IT security career.
IT Security career is a broad term and it can be defined by the combination of several practice areas, and you need the fundamental skills to take the first step. Specializations like Network Security, Application Security, Penetration Testing, Database Security, Cryptology, Audit will come later with specific skill-set requirements.
First fundamental skills:
1- Have a solid understanding of TCP/IP for today’s interconnected world of digital assets.(if any other network technologies are used you need to understand them as well) You may either read one of the good books in the market, (e.g. TCP/IP Illustrated) or write a small socket application from the scratch. You should be able to pass Cisco CCNA cert with your development background without any detailed help/courses, just a few books... When you read a network capture file you must be confident.
2- Have solid understanding of the basic pillars of information security; authentication, authorization, integrity, encryption and non-repudiation. You should be able to relate all the applications you use, in a security perspective. Try evaluating the applications that you use daily in terms of the pillars I mentioned above. Understand approaches, methodologies and solution sets.
3- Have a solid understanding of risk. Make sure that you understand the full risk life-cycle. Assets, Threat, Vulnerabilities, Safeguards, Gaps etc. Once you understand the threats and the safeguards, your vision gets clearer. You can study risk management frameworks that are available publicly.
4- Have solid understanding of IT security specific initiatives like COBIT, ISO27001, NIST, PCI NSA, CERT, CVE etc...
If you want to be a consultant then you need some more basics:
1- Understand market requirements, trend, and solutions sets. Start reading. Start following the top 10 blogs, other interesting blogs for information security, set up your google alerts, subscribe to the mailing lists, start checking security research sites daily
2- Build up your jargon, study CISSP, GIAC, CISM, CISA etc… these certifications help you to speak the same jargon with the rest (the CIA triad, role-based management etc…) When you say web access blocking instead of URL filtering your interviews will be short.
3- Get familiar with common solution sets, vendors, methodologies. Name 3 alternative solutions for each security requirement.
Another shortcut is to focus on 1 area only, if you like any of the areas above (Network Security, Application Security, Penetration Testing, Database Security, Cryptology, Audit) I can provide different paths. You may also try getting a vendor certification first and then start practicing security (Check Point, Cisco etc) as a shortcut.
Again, these are basics, these things will open the door for you, and they will make you book smart... Being a consultant requires active projects and hands-on expertise. On the job training is priceless if you can get an opportunity. If you do not have a project, then you may join to one of the community projects like OWASP, Snort, OSSTMM et al.
I have seen many self starters choosing the security management path. Without genuine information security experience, security management claim will be fun material for the veterans. Baby steps recommended.
I think this is a good start but let me know if have any specific questions.
Cheers,
- yinal ozkan

Saturday, September 27, 2008

WAF over SSL VPN?

Question: When is it a good idea to add a Web Application Firewall (WAF) to an existing VPN/SSL connection ? Is it even necessary at all
Approximately 100 End-Users
Medium Security (No Cash Transactions)
Web Server IIS based
scalability


Answer:
The answer depends on your security requirements.

If you have a assessed requirement (e.g. PCI) to secure your applications with a front-end like a web application firewall (WAF), then you should have a web application firewall in front of your web applications.

In general SSL VPN adds the following features to the shops that require layer 7 web application firewalls (when configured properly):
1 - All users accessing your web applications using SSL VPN are authenticated when it is enforced. If authenticated users are considered trusted, then you do not need an extra WAF protection.
2- SSL VPN systems can bring pre-authentication posture checks like malicious software scans. If you consider scanned clean systems trusted then you do not need a web application firewall
3- Some SSL systems come with integrated security features like content security, layer 7 security, protocol checks, firewalls etc. If the security level offered by the SSL VPN vendor is good enough for your web application security requirements you do not need an additional layer for WAF.

Let me know if you have any specific questions,
Regards,
- yinal ozkan

Web Filtering for ISP's, who would you recommend?

Question: I'm working on a Regulation to allow the content Regulator to issue website blocking requests to ISP's in ......... Blocking of a few websites is not a problem, but blocking an entire category of websites on the other hand (such as "pornography", for example) should be made possible.

The regulation will specify technical solutions (whether software or hardware based) that are acceptable and recognized of being capable of complying with individual, and blanket, blocking requests. Most of the solutions I've found online are tailored towards enterprises for managing employee access to websites; what I'm looking for, however, must be capable of handling access requests from all users of a given ISP. Given the fact that a single URL could have multiple IP addresses, the recommended solution should robust enough to deal with such complexities.

What would you recommend? How was your experience with it? A brief summary would do just fine, there's no need to take a lot of your time in answering this question.


Answer: We have been deploying web filtering solutions for TELCOs for a while. In the TelCo world the requirements are different from the enterprise:
1- No authentication is required
2- Performance and scalability is a major decision criteria
3- Pricing is important when the userbase is over 100K.
4- URL categories must fit your requirements, when needed you should be able to apply more than 1 filter database.
5- Management should not require an army of engineers.
6- Not too many pie charts are required for reporting

http://mediaproducts.gartner.com/reprints/securecomputing/160130.html
Is a good start for checking vendors

Big enterprise appliance based solutions usually have a custom ISP product.
Blue Coat, Ironport, SecureComputing (Now McAfee) , MI5 Networks and Optenet are used commonly at TelCos.

I do work with Blue Coat appliances since it is stable, scaleable and it does support 3rd party URL databases like Websense. But this combination can burn your budget. Blue Coat is in use at several neighboring states for you. Blue Coat also offers its own URL database:
http://www.bluecoat.com/

I have seen large ISP deployments with Optenet (the pricing options were good)
http://www.optenet.com/en-us/ispproducts.asp

Load balancing is a key issue, I am not sure how these ISPs are interconnected to Internet backbone but you will need to load balance content filters. You can check F5, Cisco, Citrix, Radware etc for L4-7 load balancing switches.

And a few recommendations: Do not get ambitious stay away from content AV. It does not scale at ISP level.
DNS poisoning , TCP resets are not very effective go with the content gateway.
Because of you specific requirements, in the cloud services like webroot and Scansafe may not be the best option.
This is a commodity market you have so many alternatives like 8e6, Barracuda, Clearswift et al.

If you have a specific vendor or design question, please let me know,
Regards,
- yinal ozkan

Friday, September 19, 2008

IT-GRC and GRCM tools revisited

The line between IT-GRC and the old world GRC are getting thinner everyday. So I updated my list with old world GRC players.. As you can tell they all have IT-GRC solutions

It is difficult to say which sets of tools are exactly for IT-GRC, or GRC Management (GRCM) or enterprise governance, risk and compliance (EGRC).

IT controls are everywhere when you check the 4 pillars of GRCM:
1- Audit management
2- Compliance management
3- Risk management
4- Policy management

Tools do not fix the governance problem but they do help in shaping your project with fewer bodies (and probably for an exchange for good hard cash)

The new era of tools have a better message than the previous "We fix your compliance problems" motto. We all knew that compliance was just another step to achieve governance on Information Security. The new tools have better connections with legacy information security and risk management tools, they also come with several predefined policy frameworks like ISO 27001, COSO, COBIT, PCI etc..

Not there yet, but if you are interested here is a good start list of lists for googling and reading:

Governance, Risk and Compliance (GRC) Tools with IT Controls (IT-GRC)


Agiliance
http://www.agiliance.com/
Brabeion
http://www.brabeion.com/
Archer
http://www.archer-tech.com/solutions/index.html
Control Path
http://www.controlpath.com/solutions_advantage.php
Symantec (Control Compliance Suite)
http://eval.symantec.com/mktginfo/enterprise/fact_sheets/ent-datasheet_control_compliance_suite_05-2007.en-us.pdf
Compliance Spectrum -Spectra (Command Center)
http://www.compliancespectrum.com/
Modulo
http://www.modulo.com/
NeIQ Vigelent Policy center and other NetIQ tools
http://download.netiq.com/CMS/WHITEPAPER/NetIQ_CRM_Methodology_Feb_2007.pdf
eIQ Networks SecureVue
http://www.eiqnetworks.com/products/SecureVue.shtml
CA clarity (formerly NIKU)
http://www.niku.com/it-governance-47.html
IBM Tivoli Series
http://www-306.ibm.com/software/uk/itsolutions/governance/?ca=grm_Lnav&me=w
SAP
http://www.sap.com/solutions/grc/index.epx
Relational Security - RSAM
http://www.relsec.com/rsam_overview.htm
Iconium
http://www.iconium.co.uk/Solutions/overview.htm
Security Works - Visible Security
http://security-works.com/?page_id=27
Oracle (formerly Logical Apps and Oracle GRC Manager)
http://www.oracle.com/solutions/corporate_governance/governance-risk-compliance-manager.html
Proteus
http://www.infogov.co.uk/proteus_enterprise/index.php
Avedos
http://www.avedos.com/257-Home-EN.html
BWise
http://www.bwise.com/
Neupart
http://www.neupart.com/
Metric Stream
http://www.metricstream.com/
Nemea
http://www.nemea.us/
Favored Solutions
http://www.favoredsolutions.net/
Paisley
http://www.paisley.com/
OpenPages
http://www.openpages.com/Solutions/Technology_17.asp
Qumas
http://www.qumas.com/products/index.asp
IDS Scheer
http://www.ids-scheer.com/en/ARIS/ARIS_Solutions/Governance_Risk__Compliance_Management/88815.html
Axentis

http://www.axentis.com/axentis_solutions_5.aspx
Achiever
http://www.goachiever.com/ACHIEVERPLUS/aweb2.nsf
Methodware
http://www.methodware.com/products/oprisk/idx-oprisk.shtml
Protiviti
http://www.protiviti.com/portal/site/pro-us/menuitem.32f530ef9aa26f4acd230ef2f5ffbfa0/
Cura Software
http://www.curasoftware.com/pages/content.asp?SectionId=7&SubSectionID=48
Mega
http://www.mega.com/index.asp/l

Thursday, July 24, 2008

The Frequency for Security Report Reviews

Q: How often do you review your security reports? Often, sometimes or never?
Security requires a hands on aproach, monitoring, reviewing and patching. In the case where there is no dedicated security personal onsite, are you reviewing the reports on a weekly basis, (often), monthly, (sometimes), or never? If sometimes or never, why not?

A: ....,
As you know, on a broader picture security reports must be managed.

The frequency for the review (which is a part of security management) can be determined by the security management approach of the operation. The frequency of reviews depends on the risk level of the protected assets.

Calculation of the review frequency can be based on a simple logic: The cost of the review (people/time/other resources etc) should be justified by the cost of risk avoided.
If the cost is right, then perform the reviews as often as possible.

As an example real-time log monitoring, on-site information security team and daily security review of reports make sense for a financial or healthcare operation where lives, hard cash figures determine the risk. On the other side it might be ok to batch process logs and review the reports weekly for a mom & pop hardware store based on the information risk appetite taken.

Other management concerns for security report reviews (besides frequency) are:
1- Who reviews the reports
2- Who approves/signs-off the reviews
3- How is the review process documented
4- How are the reviews’ effectiveness measured
5- How are the reviews are improved

Let me know if you have a specific question.
regards,
- yinal ozkan

Monday, June 30, 2008

Managed CPE Services and Green Data Center

Data Center Energy Efficiency is the new buzz word. There are several creative solutions on the market from controlling HVAC to virtualizing physical servers.

One of the data center energy savings methods is very simple. Find the clusters that are not fully utilized (e.g proxy cluster) and then shutdown the idle servers in the cluster farm, monitor utilization on active servers and boot spares to join cluster when needed. You do not have to have hot cluster members in cluster where more than 2 members exist.(unless this is required by utilization)… Batch task servers can be shutdown as well.

This action requires 7x24 careful monitoring and usually a service solution that can pass turing test. Managed Service Providers and managed security services providers do carry the know-how to monitor every cluster member and interfere full device boot cycle as of today. That is why we are not far away from “energy saving” offerings from Managed CPE providers.

On the operational level, simple SNMP monitoring of cluster members or monitoring the monitor (F5 LTM / Citrix Netscaler) systems will do the gratious shutdowns and joins for the unused cluseter members at no cost.

Let’s wait and see more creative offerings from MSPs and MSSPs. On the other hand, I personally believe that the data centers are cutting the emissions regardless of their green image. Data centers deliver massive automation and they do eliminate the traditional emission sources such are vehicles. (and unfortunately sometimes people)