Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Sunday, December 2, 2007

When is a Policy not a Policy?

Earlier postings on this Blog will tell you that I understand and support good security measures around information. As such, I am also "tuned in" to security measures don’t make sense.

Airline travel is a great example. This week I tried to change a flight with Jetstar, which I had booked and paid for, but I was not the passenger. I knew I could do this online, but as I was away from my PC, I thought I would try the phone. No go.

They have two policies – one for the telephone and for online. Why? Shouldn’t the level of identity security be the same? I would have thought so. If I know the flight details I can change them on the Web, but not on the telephone. Only the passenger, or someone who claims to be the passenger, can change the flight via the phone.

Security policy problem or just a ploy to get customers to use the Web? Hmmm

Saturday, November 3, 2007

How big is the Spam problem?

To start by showing my hand, I really dislike Spam. I could live without offers of pirate software, contact from someone pretending to be a young Russian woman, offers of all sorts of pills and potions and of course, the enhancements to my anatomy. 

My guess is that there must be a return on their effort - in other words enough people must click-through to make spam worthwhile.

On one level they are a nuisance, but if there are enough spam emails, they are clogging your Internet connection. So, are there enough? 

Here is real data from a Spam Filter here in Australia - you decide.
Total Emails received = 9.5 million
"Genuine" Emails = 2 million
Spam Emails = 7.5 million

This means more than 80% of the email arriving at this domain is spam. 

Having an absolute fix for spam is difficult, as it involves technical and legal remedies. That said,  I notice that Spam Filters are now doing a great job. For example, I have a Hotmail account and the Spam arriving in my inbox is zero. If more and more spam is blocked, then hopefully, the sources will diminish. 

Monday, September 17, 2007

Symantec, Dancers and Hot Issues

I had the pleasure of attending the Symantec Vision Event in Sydney last week.

The event followed a familiar path. A loud Corporate video to open proceedings, followed by a troop of tap dancers. What tap dancers have to do with Symantec remains a mystery to me, so all ideas are welcome.

Then a senior sales exec presented corporate motherhood, while the audience waited for the real content to arrive. And arrive it did, with interesting keynote speakers from Symantec and a superb business keynote.

Glitz and glamour aside, my overall take-out was that Symantec has products that are at the heart of many of the big IT issues.

In 2006 The Council of Australian University Directors of IT (www.caudit.edu.au) developed a list of their Top 10 issues. They have updated the list for 2007 and it is

1. Staffing and Workforce Planning - Skills Shortage, Retention and Recruitment
2. Service Management - Support and Delivery: Availability, Capacity, Change Management
3. Project, Portfolio and Risk Management
4. Governance and IT Strategic Planning
5. Business Continuity and Disaster Recovery
6. Identity Management: Authentication, Authorisation, Access
7. Security
8. Information Management: Storage, Archiving, Records Management
9. Funding and Resourcing
10. Administrative Systems - ERP Upgrades and Enterprise Architecture

I think that Symantec has products in 5 or maybe 6 of these 10 categories.

I preach that any selection process should begin with a detailed understanding of the need, and then should include considerations of the other technology inter-relationships – both technical and commercial.

When that work is done, I am sure that in many cases, Symantec products will be worthy of consideration.

Saturday, August 25, 2007

Who are you?

On my travel theme, a news article this week brought home to me the importance of thoroughly authenticating employees. Are they who they say they are? Do they the qualifications they claim?

The article that caught my attention stated that an allegedly unqualified Qantas mechanical engineer signed off on the safety of more than 1000 flights without having a licence to do so. It is alleged that the "impostor" forged his aircraft maintenance engineer's licence because he had not passed the Civil Aviation Safety Authority exams required.

True? I have no idea, but it reinforces the point that sadly, people are not always who they claim to be. Thorough checking of qualifications and employment background are vital processes and must form a key element of security management.

Do you have these processes?

Friday, August 24, 2007

Information Security? Not at the airport!

This week I found out that travel broadens the mind, in multiple ways!

I got a lesson in information security.

On a wet Monday morning, flights were delayed and the lounge was full. The section of the lounge with the work cubes was packed, and around me, people were busy on the phone.

I spend time working on information security to protect confidential data, and after 10 minutes, I has a lesson that information security is a company-wide issue, and not just IT.

Was it the gentleman on the other side of the cube who was on the phone, describing (in detail) the contracts that he was sending for approval? He described the market research services, and the issues with the contracts. Or was it the gent to the left who was chairing a meeting for a financial service company, or perhaps the lady behind me who was discussing issues with remote monitoring facilities.

All confidential information that they were sharing with a group of people they didn’t know.

Do they forget where they are, or just assume the other lounge guests won’t listen?

As I said, this just reinforced to me that Information Security is a 360-degree issue, and the policies must include when and where people talk about their business.

Friday, August 17, 2007

Is all Data created equal?

How many places do you have data stored? Excluding the data you have residing on servers, what about the data you have stored on your personal devices?

You may have multiple data stores. Your laptop of course, your PDA, mobile phone, USB sticks and removable hard drives. Any more?

In most organisations, “corporate” data, such as accounting information and even email, is secured, protected and managed for back-up.

So, are your spreadsheets and presentations any less valuable to you? The business won't stop trading if they are lost, but what about your productivity? What would happen if they were all lost tomorrow? Are you relying on email as your archive?

This raises three questions
1. What is the security and protection for data on mobile devices, if they are lost or stolen?
2. What is the back-up process for this data?
3. Should this data (documents) be treated differently to other data (accounting)? If so, is that explicit in policy?

Monday, August 6, 2007

How Secure is your Network?

I have been trying to think of a good analogy for IT Security. Insurance? Not really because insurance doesn’t prevent an incident occurring.

How about IT Security being akin to a cricket box (or a cup for baseball)? A cricketer wears one because although he is unlikely to get hit in that area, if he does, the impact is severe.

As we move to a self-service world with web sites interfacing (directly or through middleware) into financial, logistics, reservation and other systems, the opportunity for a security breach increases. The threat from outside the firewall is matched by the threat from within, with security experts suggesting that the risk of an employee abusing the system is much higher than an external “hack”.

This isn’t new – most organisations are wearing a box. Most have invested in good technology supported by strong policies. Can you feel a “but” coming?

The “but” is how do you know it is working at the optimum level? Has the set-up been changed to address the new threats, which are always developing? Who is “checking the checker”?

Let me give you a simple example. What happens if a Firewall device fails in your network? Does it fail open or closed?

So, to make sure that the investment is working, and if the ball does hit that area, the box does it job (stretching the analogy too far), your IT Security requires regular, thorough and independent testing.

Thursday, July 26, 2007

Web 2.0 – Hype, Reality and Security

I have been reading a lot lately on Web 2.0. There are numerous articles and commentaries that range from “Its hype” to
“It’s changing the world” to “Its YouTube”.

There is no doubt that today, millions of people put content on the Web using sites such as Myspace, Facebook and Linkedin. There are numerous Blog sites such as this one, and then aggregation services like Technorati and Feedburner.

The scale is astounding. If I read it correctly, there are close to 8 million Blogs on Technorati, and on Myspace it says that more than 700,000 Blogs have been updated today!

These sites are much more than hype – they are phenomenally successful at attracting users.

So is there a security implication if they are used in a business environment?

Security company Sophos seem to argue that there is. Sophos publish a Security threat update, and if you haven’t read it, I recommend it.

www.sophos.com/pressoffice/news/articles/2007/07/securityrep.html

This Sophos report states that virus writers are placing malware on third-party web sites – and they suggest that about 80% of all web-based malware is being hosted on innocent, but compromised, sites.

Sadly, malicious code is also placed on the social networking sites. Sophos quote that in March 2007 the SpaceStalk spyware Trojan was discovered embedded in a QuickTime movie on a Myspace page.

So, how do you protect your users and resources from this malicious code? Do you block these sites?

Wednesday, July 18, 2007

Mobile Security

Mobile computing is important. The proliferation of notebook computers has changed the way we work, and that change has been accelerated by mobile-connected PDAs. They are great business tools, but are they opening a gap in your security?

Wireless mobile computing found popularity in real-time data collection, often customer-facing (sales order taking, delivery confirmation, logistic tracking) and at the senior executive level, with mobile email as the driver. We are now seeing more applications, often from a Web interface, being available to mobile devices, with an example being CRM.

So back to my original question – are these devices creating a hole in your security? I must declare my hand here – I am a big fan of mobility. Making information and functionality available at the point where it is of most benefit, is a good thing. So, this isn’t about slowing mobility, its about making mobile computing as secure as possible (within the risk parameters of the organisation), and working to review and improve that security on a very regular basis.

To state the obvious, these devices are computers even though they sit in your hand. They run operating systems and applications, so they should be secured like other computers. In addition, they are using wireless connectivity, which itself requires more security focus.

For example, devices retrieving email are virtually connected (through the outbound connection) to the internal network and will remain in an always on, always connected state. This is not how other remote access devices would connect, and this could create a vulnerability if a rogue user, wirelessly connecting to the PDA, used the PDA’s connections to enter the Corporate LAN.

The good news is that there are some innovative tools available to help; they just need to be deployed and managed.

This is a quick checklist to get started;
• Anti-Virus – would you have a Notebook without AV? Do you have AV on your mobile computing fleet?
• Firewall – is the device protected from wireless attack?
• Lost or Stolen – what can you do to protect the data if the device is lost or stolen? What process do you have in place?
• Encryption – is the data encrypted in transmission? Is it encrypted on the device?
• Authentication - is the data/access important enough to be protected by two-factor authentication?
• Device change – what process do you have in place to securely remove data when the device is returned, or passed on to another user?