Tuesday, 8 November 2011

Commoditisation - exciting times for the industry


Espresso_beverages_-_starbucks_coffee_company


The biggest shift we are observing and we will observe in these few years is how IT is being commoditised.


This puts businesses of today and of the future in a great position. The ability to select the technology solution when they want it, how they want it and at a price they are willing to pay for the technologies of interest. It is like lunch time frenzy where businesses are the customers looking for commoditised food. Too many eateries trying to tailor their menu in the expectation to attract the right clients. Quality of service will play a key role here along with the commodity. Whether you want to have a simple coffee in your local cafe or you'd like to tailor the flavours of your Frappuccino in Starbucks or may be just make your own. It is the same for your afternoon lunch or your business's technology requirements. The choices will be there, the key will be deciding what works and fits best for the business.


Some interesting Rackspace Cloud Private Edition posts:


http://gigaom.com/cloud/rackspace-makes-good-on-private-openstack-cloud-vow/?utm_source=social&utm_medium=twitter&utm_campaign=gigaom


http://www.infoworld.com/d/open-source-software/why-openstack-will-falter-178038


http://www.readwriteweb.com/cloud/2011/11/infographic-the-state-of-opens.php


http://blog.theloosecouple.com/2011/11/08/cloud-spring/


 

Thursday, 3 November 2011

Thought Leaders in Information Security - Do they exist?

First things first - it's been a while since I last blogged so my sincere apologies.


I come across the word 'Thought Leader(s)' and 'Thought Leadership' quite a lot in discussions and reading. It has got me thinking at times as to 'What is it?'. With regards to Information Security industry, I think there hasn't been any Thought Leadership at all. This encompasses innovation around security management including but not limited to policies, procedures, standards, vulnerability assessments, penetration testing, patching, risk management, data loss, compliance, monitoring, incident response, security awareness et al. Same old, same old.


Good old Wikipedia says this for 'Thought Leader':


"The term was coined in 1994, by Joel Kurtzman, editor-in-chief of the Booz, Allen & Hamilton magazine, Strategy & Business. "Thought leader" was used to designate interview subjects for that magazine who had business ideas that merited attention."


According to commentators such as Elise Bauer, a distinguishing characteristic of a thought leader is "the recognition from the outside world that the company deeply understands its business, the needs of its customers, and the broader marketplace in which it operates."


So, it is 'ideas that merit attention' and 'recognition from the outside world that one gets it'.


I cannot think of an individual or a company in the security industry that has come up with ideas that merit attention or are recognised from the members of the security community for a while. Can you? Please enlighten and discuss.


PS: I don't class reactive discoveries for e.g. APTs, Cybercrime, surveys and point solutions as TL. I also believe there is a lot of TL going on in security offence than in defence. If there is a better definition, again - do post your thoughts.


 

Thursday, 7 April 2011

Third Parties and Data Security

I have covered the business risks around third parties and data security from a PCI DSS compliance perspective in my previous post. The recent incidents of email and data losses by third parties (Play.com’s breach and Epsilon’s breach) have some key lessons for businesses using third parties to deliver their business.


Some of the key questions to be asked by the leadership of the businesses engaging with third parties are:


1.     Does an updated list of third parties exist?


2.     What data is transferred across or handled by these third parties? 


3.     Are there any preventive/detective/corrective controls in place at the third parties to avoid/identify/remediate data loss? 


4.     What level of preventive/detective/corrective controls are in place and how often are they reviewed? (SLAs/KPIs/Metrics)


5.     In the event of an incident, what process (Incident Response Plan) is in place between the business and the third parties?


6.     Are there appropriate contract clauses to protect the business from financial penalties and data losses?


Silverpop and Epsilon may have received their share of negative media coverage due to weak security controls in relation to the breaches, however it is the businesses engaging with such third party service providers that have to rigorously review the third party security and ensure that their reputation, operations and business are not impacted.

Wednesday, 2 February 2011

A day at CloudExpoEurope '11


Cloud_expo_europe_2011_bringin


 


I attended CloudExpoEurope '11 today in London and had high expectations for this event considering all the hype around the cloud. As expected, it was mainly a vendor led event. There were some new names (at least for me) that were exhibiting their services like OnApp, Onyx Group, Ping Identity, Cloudreach and Nlyte.


 


The mix of SaaS, PaaS and IaaS appeared to be slightly imbalanced on the floor. Interestingly, there were significantly more IaaS related vendors than SaaS and PaaS. The IaaS vendors exhibiting were Carrenza, Claranet, Savvis, Rackspace, Peer 1 and Redhat amongst others.


 


I discussed the impact of Open Source solutions like OpenStack with OnApp MD Carlos Rego and also understood the service model behind Ping Identity (Cloud SSO Solution Provider) from Travis Spencer of Ping Identity. Rik Ferguson's (Trend Micro) talk on securing cloud instances was interesting as well. SaaS solution on system monitoring by CA's recently acquired Nimsoft seemed robust.




There were exciting Open Source projects (OW2 Consortium, Open Nebula) that I would have liked to review but couldn't because of time constraints. The Open Source developments in cloud are of particular interest to me as the development in OpenStack project are steadily improving and shows promise at the moment to deliver the much required integration in this novell and rapidly changing ecosystem.


 


 


And, I also witnessed some IaaS 'cloud' providers selling virtualisation as a 'Cloud' service!


 


To summarise, the experience at CloudExpo could have been better with more variety of players from SaaS, PaaS and IaaS arena in Europe or Worldwide for the visitor to have a comprehensive view of the ‘Cloud’ ecosystem. It seems that the hype around Cloud is very real but so are the clear business benefits from utilising the various services in the Cloud ecosystem. 




Ideally, businesses going to such Cloud events should have a clear understanding of their requirements in terms of what their processes are, what systems they use and what software, platform and/or infrastructure of the business would they like to transfer to the cloud. As a bad analogy, the current cloud arena is like a phone app market with no recommendation/feedback system. There are too many apps but the user needs to know what suits their requirements. But with Cloud it may not be as easy as deleting the app!

Thursday, 13 January 2011

Challenges related to cloud computing data security

I recently started using Quora and find it quite useful. The idea of your thoughts to a particular question been voted up and down and the ability for community to challenge and contribute is inviting. I answered a question on Quora that I've cross posted on this blog that you may find useful. Feel free to comment.


 What are the challenges related to cloud computing data security? 


Of the five essential characteristics (On-demand self-service, broad network access, resource pooling, rapid elasticity, measured service), three service models (SaaS, PaaS, IaaS), and four deployment models (Private, Community, Public, Hybrid Clouds) of Cloud computing (as defined by NIST), organisational data security faces a variety of risks. The level of risk can be determined by what models organizations subscribe to or adopt and more importantly, what data they decide to move to the cloud. For example, a Private Cloud deployment model will reduce the risk compared to a Public Cloud or a Community Cloud generally, however will need to compromise on certain essential characteristics. 


Data, based on its classification, requires appropriate controls applied for its security. Whether it be a system configuration, IP (Intellectual Property) in the form of software, a database with PII/sensitive data or publicly available data, the hard part is identifying where this data is in the Organisation and what people, processes and technologies access and support it. Cloud computing, depending on the model and characteristics used, tends to abstract this even further.

For example, with the ‘resource pooling’ characteristic of the cloud, if sensitive data is stored in a Public cloud, as per the NIST definition ‘…customer generally has no control or knowledge over the exact location of the provided resources but may be able to specify location at a higher level of abstraction (e.g., country, state, or datacenter). Examples of resources include storage, processing, memory, network bandwidth, and virtual machines.’ This means that in case of a security breach or a follow-up investigation in a public cloud model, it will be hard or near impossible to find out exactly what the data loss impact is and where the data resides. This is an example for data at rest (storage). There are similar challenges for data in transit and in process.

The challenge is identifying what Cloud computing model and characteristics for what data will maximise efficiency and minimise the risks. 



 



 

Tuesday, 14 December 2010

#PCI-DSS and #Cloud Adventures - Fun!


Media_httpfrankitlabu_wpyvq

 

As per my earlier post, I mentioned that the publication on PCI DSS reference architecture for cloud is interesting.

It is interesting because PCI DSS v2.0 (I still find it difficult to write ‘v2.0’!) just included additional guidance for virtualisation in the standard as below:

“System components” also include any virtualization components such as virtual machines, virtual switches/routers, virtual appliances, virtual applications/desktops, and hypervisors

Requirement 2.2.1 Note: Where virtualization technologies are in use, implement only one primary function per virtual system component.

 

Testing Procedure 2.2.1.b If virtualization technologies are used, verify that only one primary function is implemented per virtual system component or device.

 

So when the SSC made ‘major’ revisions to the standard and released a revised version to ensure the PCI DSS is understood clearly, I was amused and surprised at the same time that the Service Providers and some QSAs went ahead to certify or approve the relatively new technologies. The SSC has plans to work on various areas like Point-to-point encryption, Tokenisation, Mobile Payments and probably cloud technologies.

The Service Provider and The QSA

It is understandable that the vendors that got together to publish this reference architecture are keen to offer this service as a Service Provider. There is nothing wrong with this. Following this publication, on Dec 7 Amazon’s AWS cloud offering announced that they’ve achieved PCI DSS compliance as a validated Service Provider as well. A couple of good posts assessing this can be found here and here. Hence, if Merchants want it, they’ve got it.

One point I would like to highlight before moving on though is that for a vendor trying to offer such a service (Cloud-based PCI Compliant infrastructure), it is very important to get the QSA onboard early. More important is to identify that the QSA is well-versed with the infrastructure complexities of the cloud world and the underlying technologies and challenges (e.g. multi-tenancy). With AWS, they already have SAS and ISO certifications that should have made their compliance journey a bit easier. I’ve heard many experiences of QSAs not ‘understanding’ the solution they’re assessing resulting in waste.

The Merchant / The Customer

<<http://www.gillette.com/en/us/Products/Razors.aspx>>

I believe the above link is a good start to make the point. I’m sure not all of us have or use the ‘Fusion ProGlide Power Razor’ (//if reader=female then apologies). Although we’d all love to, not all men upgrade to the best Razor when released just because Gillette says it gives ‘Best Shave’ whereas the ‘M3 Power Razor’ only provides a ‘Good Shave’! It does depend on a number of variables for a Merchant or a customer to move to a cloud based offering just because it has various benefits. AWS has recently started offering a 'Free Usage Tier' to increase the cloud adoption.

And as mentioned in the linked post earlier, the Merchants require to ensure their own compliance in addition to making sure the Service Providers they contract with are PCI DSS Compliant.

The PCI SSC

The PCI DSS and other suite of standards (PA/PED DSS) have done a great job in bringing security to the forefront for a particular kind of data in the relevant organisations. There is a lot to adapt from for other sensitive data stored, processed or transmitted in organisations. Certainly, the stick behind the success of PCI DSS is the potential of fines by the card brands and the potential of direct monetary impact from data loss. However, there is a danger that the SSC will end up working on ‘additional guidance’ for new technologies unveiled by zealous and innovative vendors over the years. It is all good as long as the data i.e. the containers are secyored!

Thank you.

 

Some recent developments


Untitled

 
I like this graphic in particular that shows the disruption over the weekend in the cloud. What it does not show is the impact it had on the businesses supported by AWS in the peak business season.
 
 

Tuesday, 9 November 2010

Cloud, virtualisation and PCI DSS v2.0

For readers who keep up-to-date with the industry, virtualisation and cloud technologies need no introduction. PCI DSS v2.0 includes guidance on virtualisation compliance and is well explained and assessed here and here.


 


Cisco, HyTrust, VMware, Savvis and Coalfire have collaborated to construct a cloud reference architecture (here) that aims to address some of the unique challenges of the PCI DSS.


 


This certainly is an interesting read. I’ll post my observations in the following post, however it will be useful to know what you think of this development.


 


Thank you for reading and subscribing to this feed. Your comments are always welcome.

Thursday, 4 November 2010

Approved Scanning Vendors (ASVs - PCI DSS) in the UK

PCI DSS requirement 11.2 mandates organisations to run internal and external vulnerability scans at least quarterly and after any significant change in the network (such as new system component installations, changes in network topology, firewall rule modifications, product upgrades).


 


Testing Procedure 11.2.1c requires the assessor to validate that the scan was performed by a qualified internal resource(s) or qualified external third party, and if applicable, organizational independence of the tester exists (not required to be a QSA or ASV).


 


Approved Scanning Vendors (ASVs) are organizations that validate adherence to certain DSS requirements by performing vulnerability scans of Internet facing environments of merchants and service providers. The Council has approved more than 130 ASVs. Complete list of these ASVs can be found here.


 


I received a request recently to provide some guidance on ASVs that offer their services in the UK. Below are the companies that are listed as ASVs today on PCI SSC website that offer vulnerability scanning service in the UK. To clarify, it is not required for an ASV to be local. There are a number of other ASVs on the website that offer a similar service baselined by PCI SSC.


 


Ambersail


Context Information Security


Digital Assurance Consulting


Integralis


Matta Consulting


MWR Infosecurity


NCC Group


Nettitude


ProCheckUp


Protiviti


RandomStorm


Trustwave


Westpoint


 


Again, this listing should only be taken as a reference for organisations seeking to engage an ASV locally. Please feel free to add any ASVs that have been unintentionally missed on this list but offer the service from the UK.


 


Disclaimer: I do not work for any of the above listed ASVs and do not intend to endorse their ASV services to that of other companies offering such services globally.

Thursday, 9 September 2010

PCI DSS - Ownership and Accountability

Accountability is a problem that I come across in PCI DSS time and time again. Recent challenges with ownership and accountability prompts me to write this post.


Complex systems require a complex set of controls to ensure that these systems work as intended. These controls aim to reduce the risk of disruptions in the intended operation. However, incidents do happen and not all controls are adequate the first time they’re put forward. Hence, the controls are revised to improve the relevance and reduce the likelihood Take an aircraft for example. Or a car.


Payment Cards are just one such complex creation. In order to provide customers convenience to pay for goods, banks created this complex system with input from entities such as the Cardholder, Merchants, Service Providers, Payment Gateways, Acquiring Banks, Card Brands, Issuing Banks and various other third parties.


J0422755


In the world of digital electronics, data passes from one system to another, which is owned and/or managed by one entity to another very quickly. In the case of payment cards, this data is very important as it translates into cash/goods with relatively less effort. With the increased complexity of business delivery models and the time to deliver new services to the customer, security of this data can take a back seat and with it, does the appropriate agreements between various entities delivering this service. It is when controls put forward in PCI DSS can help in order to secure the cardholder data.


It is very important that PCI DSS requirement 12.8 is given appropriate emphasis as a key control to ensure all relationships with various entities are clearly described in a written agreement with appropriate legal teams involved. As an example, where service providers, merchants and third parties are collectively delivering a service, they should review the data flow diagram of cardholder data collectively and ensure each requirement is owned and complied by the appropriate entity. This should drill down to each requirement preferably on the assessment sheet. Merchants can have reporting structures/metrics with service providers and their third parties to ensure compliance is maintained.


In absence of such rigor around Ownership and Accountability, the entity in question eventually will have a difficult time when a major incident happens. This may end up in review of liabilities, service contracts and SLAs and may severely effect the business eventually. Most of all, it effects the user confidence. The end user empowers the payment system and trusts that the system is securely handling their data. It is very important to ensure this trust is maintained. Surely, this is how this complex system was designed or was intended to operate.