Thursday, 7 April 2011

Third Parties and Data Security

I have covered the business risks around third parties and data security from a PCI DSS compliance perspective in my previous post. The recent incidents of email and data losses by third parties (Play.com’s breach and Epsilon’s breach) have some key lessons for businesses using third parties to deliver their business.


Some of the key questions to be asked by the leadership of the businesses engaging with third parties are:


1.     Does an updated list of third parties exist?


2.     What data is transferred across or handled by these third parties? 


3.     Are there any preventive/detective/corrective controls in place at the third parties to avoid/identify/remediate data loss? 


4.     What level of preventive/detective/corrective controls are in place and how often are they reviewed? (SLAs/KPIs/Metrics)


5.     In the event of an incident, what process (Incident Response Plan) is in place between the business and the third parties?


6.     Are there appropriate contract clauses to protect the business from financial penalties and data losses?


Silverpop and Epsilon may have received their share of negative media coverage due to weak security controls in relation to the breaches, however it is the businesses engaging with such third party service providers that have to rigorously review the third party security and ensure that their reputation, operations and business are not impacted.

Wednesday, 2 February 2011

A day at CloudExpoEurope '11


Cloud_expo_europe_2011_bringin


 


I attended CloudExpoEurope '11 today in London and had high expectations for this event considering all the hype around the cloud. As expected, it was mainly a vendor led event. There were some new names (at least for me) that were exhibiting their services like OnApp, Onyx Group, Ping Identity, Cloudreach and Nlyte.


 


The mix of SaaS, PaaS and IaaS appeared to be slightly imbalanced on the floor. Interestingly, there were significantly more IaaS related vendors than SaaS and PaaS. The IaaS vendors exhibiting were Carrenza, Claranet, Savvis, Rackspace, Peer 1 and Redhat amongst others.


 


I discussed the impact of Open Source solutions like OpenStack with OnApp MD Carlos Rego and also understood the service model behind Ping Identity (Cloud SSO Solution Provider) from Travis Spencer of Ping Identity. Rik Ferguson's (Trend Micro) talk on securing cloud instances was interesting as well. SaaS solution on system monitoring by CA's recently acquired Nimsoft seemed robust.




There were exciting Open Source projects (OW2 Consortium, Open Nebula) that I would have liked to review but couldn't because of time constraints. The Open Source developments in cloud are of particular interest to me as the development in OpenStack project are steadily improving and shows promise at the moment to deliver the much required integration in this novell and rapidly changing ecosystem.


 


 


And, I also witnessed some IaaS 'cloud' providers selling virtualisation as a 'Cloud' service!


 


To summarise, the experience at CloudExpo could have been better with more variety of players from SaaS, PaaS and IaaS arena in Europe or Worldwide for the visitor to have a comprehensive view of the ‘Cloud’ ecosystem. It seems that the hype around Cloud is very real but so are the clear business benefits from utilising the various services in the Cloud ecosystem. 




Ideally, businesses going to such Cloud events should have a clear understanding of their requirements in terms of what their processes are, what systems they use and what software, platform and/or infrastructure of the business would they like to transfer to the cloud. As a bad analogy, the current cloud arena is like a phone app market with no recommendation/feedback system. There are too many apps but the user needs to know what suits their requirements. But with Cloud it may not be as easy as deleting the app!

Thursday, 13 January 2011

Challenges related to cloud computing data security

I recently started using Quora and find it quite useful. The idea of your thoughts to a particular question been voted up and down and the ability for community to challenge and contribute is inviting. I answered a question on Quora that I've cross posted on this blog that you may find useful. Feel free to comment.


 What are the challenges related to cloud computing data security? 


Of the five essential characteristics (On-demand self-service, broad network access, resource pooling, rapid elasticity, measured service), three service models (SaaS, PaaS, IaaS), and four deployment models (Private, Community, Public, Hybrid Clouds) of Cloud computing (as defined by NIST), organisational data security faces a variety of risks. The level of risk can be determined by what models organizations subscribe to or adopt and more importantly, what data they decide to move to the cloud. For example, a Private Cloud deployment model will reduce the risk compared to a Public Cloud or a Community Cloud generally, however will need to compromise on certain essential characteristics. 


Data, based on its classification, requires appropriate controls applied for its security. Whether it be a system configuration, IP (Intellectual Property) in the form of software, a database with PII/sensitive data or publicly available data, the hard part is identifying where this data is in the Organisation and what people, processes and technologies access and support it. Cloud computing, depending on the model and characteristics used, tends to abstract this even further.

For example, with the ‘resource pooling’ characteristic of the cloud, if sensitive data is stored in a Public cloud, as per the NIST definition ‘…customer generally has no control or knowledge over the exact location of the provided resources but may be able to specify location at a higher level of abstraction (e.g., country, state, or datacenter). Examples of resources include storage, processing, memory, network bandwidth, and virtual machines.’ This means that in case of a security breach or a follow-up investigation in a public cloud model, it will be hard or near impossible to find out exactly what the data loss impact is and where the data resides. This is an example for data at rest (storage). There are similar challenges for data in transit and in process.

The challenge is identifying what Cloud computing model and characteristics for what data will maximise efficiency and minimise the risks. 



 



 

Tuesday, 14 December 2010

#PCI-DSS and #Cloud Adventures - Fun!


Media_httpfrankitlabu_wpyvq

 

As per my earlier post, I mentioned that the publication on PCI DSS reference architecture for cloud is interesting.

It is interesting because PCI DSS v2.0 (I still find it difficult to write ‘v2.0’!) just included additional guidance for virtualisation in the standard as below:

“System components” also include any virtualization components such as virtual machines, virtual switches/routers, virtual appliances, virtual applications/desktops, and hypervisors

Requirement 2.2.1 Note: Where virtualization technologies are in use, implement only one primary function per virtual system component.

 

Testing Procedure 2.2.1.b If virtualization technologies are used, verify that only one primary function is implemented per virtual system component or device.

 

So when the SSC made ‘major’ revisions to the standard and released a revised version to ensure the PCI DSS is understood clearly, I was amused and surprised at the same time that the Service Providers and some QSAs went ahead to certify or approve the relatively new technologies. The SSC has plans to work on various areas like Point-to-point encryption, Tokenisation, Mobile Payments and probably cloud technologies.

The Service Provider and The QSA

It is understandable that the vendors that got together to publish this reference architecture are keen to offer this service as a Service Provider. There is nothing wrong with this. Following this publication, on Dec 7 Amazon’s AWS cloud offering announced that they’ve achieved PCI DSS compliance as a validated Service Provider as well. A couple of good posts assessing this can be found here and here. Hence, if Merchants want it, they’ve got it.

One point I would like to highlight before moving on though is that for a vendor trying to offer such a service (Cloud-based PCI Compliant infrastructure), it is very important to get the QSA onboard early. More important is to identify that the QSA is well-versed with the infrastructure complexities of the cloud world and the underlying technologies and challenges (e.g. multi-tenancy). With AWS, they already have SAS and ISO certifications that should have made their compliance journey a bit easier. I’ve heard many experiences of QSAs not ‘understanding’ the solution they’re assessing resulting in waste.

The Merchant / The Customer

<<http://www.gillette.com/en/us/Products/Razors.aspx>>

I believe the above link is a good start to make the point. I’m sure not all of us have or use the ‘Fusion ProGlide Power Razor’ (//if reader=female then apologies). Although we’d all love to, not all men upgrade to the best Razor when released just because Gillette says it gives ‘Best Shave’ whereas the ‘M3 Power Razor’ only provides a ‘Good Shave’! It does depend on a number of variables for a Merchant or a customer to move to a cloud based offering just because it has various benefits. AWS has recently started offering a 'Free Usage Tier' to increase the cloud adoption.

And as mentioned in the linked post earlier, the Merchants require to ensure their own compliance in addition to making sure the Service Providers they contract with are PCI DSS Compliant.

The PCI SSC

The PCI DSS and other suite of standards (PA/PED DSS) have done a great job in bringing security to the forefront for a particular kind of data in the relevant organisations. There is a lot to adapt from for other sensitive data stored, processed or transmitted in organisations. Certainly, the stick behind the success of PCI DSS is the potential of fines by the card brands and the potential of direct monetary impact from data loss. However, there is a danger that the SSC will end up working on ‘additional guidance’ for new technologies unveiled by zealous and innovative vendors over the years. It is all good as long as the data i.e. the containers are secyored!

Thank you.

 

Some recent developments


Untitled

 
I like this graphic in particular that shows the disruption over the weekend in the cloud. What it does not show is the impact it had on the businesses supported by AWS in the peak business season.
 
 

Tuesday, 9 November 2010

Cloud, virtualisation and PCI DSS v2.0

For readers who keep up-to-date with the industry, virtualisation and cloud technologies need no introduction. PCI DSS v2.0 includes guidance on virtualisation compliance and is well explained and assessed here and here.


 


Cisco, HyTrust, VMware, Savvis and Coalfire have collaborated to construct a cloud reference architecture (here) that aims to address some of the unique challenges of the PCI DSS.


 


This certainly is an interesting read. I’ll post my observations in the following post, however it will be useful to know what you think of this development.


 


Thank you for reading and subscribing to this feed. Your comments are always welcome.

Thursday, 4 November 2010

Approved Scanning Vendors (ASVs - PCI DSS) in the UK

PCI DSS requirement 11.2 mandates organisations to run internal and external vulnerability scans at least quarterly and after any significant change in the network (such as new system component installations, changes in network topology, firewall rule modifications, product upgrades).


 


Testing Procedure 11.2.1c requires the assessor to validate that the scan was performed by a qualified internal resource(s) or qualified external third party, and if applicable, organizational independence of the tester exists (not required to be a QSA or ASV).


 


Approved Scanning Vendors (ASVs) are organizations that validate adherence to certain DSS requirements by performing vulnerability scans of Internet facing environments of merchants and service providers. The Council has approved more than 130 ASVs. Complete list of these ASVs can be found here.


 


I received a request recently to provide some guidance on ASVs that offer their services in the UK. Below are the companies that are listed as ASVs today on PCI SSC website that offer vulnerability scanning service in the UK. To clarify, it is not required for an ASV to be local. There are a number of other ASVs on the website that offer a similar service baselined by PCI SSC.


 


Ambersail


Context Information Security


Digital Assurance Consulting


Integralis


Matta Consulting


MWR Infosecurity


NCC Group


Nettitude


ProCheckUp


Protiviti


RandomStorm


Trustwave


Westpoint


 


Again, this listing should only be taken as a reference for organisations seeking to engage an ASV locally. Please feel free to add any ASVs that have been unintentionally missed on this list but offer the service from the UK.


 


Disclaimer: I do not work for any of the above listed ASVs and do not intend to endorse their ASV services to that of other companies offering such services globally.

Thursday, 9 September 2010

PCI DSS - Ownership and Accountability

Accountability is a problem that I come across in PCI DSS time and time again. Recent challenges with ownership and accountability prompts me to write this post.


Complex systems require a complex set of controls to ensure that these systems work as intended. These controls aim to reduce the risk of disruptions in the intended operation. However, incidents do happen and not all controls are adequate the first time they’re put forward. Hence, the controls are revised to improve the relevance and reduce the likelihood Take an aircraft for example. Or a car.


Payment Cards are just one such complex creation. In order to provide customers convenience to pay for goods, banks created this complex system with input from entities such as the Cardholder, Merchants, Service Providers, Payment Gateways, Acquiring Banks, Card Brands, Issuing Banks and various other third parties.


J0422755


In the world of digital electronics, data passes from one system to another, which is owned and/or managed by one entity to another very quickly. In the case of payment cards, this data is very important as it translates into cash/goods with relatively less effort. With the increased complexity of business delivery models and the time to deliver new services to the customer, security of this data can take a back seat and with it, does the appropriate agreements between various entities delivering this service. It is when controls put forward in PCI DSS can help in order to secure the cardholder data.


It is very important that PCI DSS requirement 12.8 is given appropriate emphasis as a key control to ensure all relationships with various entities are clearly described in a written agreement with appropriate legal teams involved. As an example, where service providers, merchants and third parties are collectively delivering a service, they should review the data flow diagram of cardholder data collectively and ensure each requirement is owned and complied by the appropriate entity. This should drill down to each requirement preferably on the assessment sheet. Merchants can have reporting structures/metrics with service providers and their third parties to ensure compliance is maintained.


In absence of such rigor around Ownership and Accountability, the entity in question eventually will have a difficult time when a major incident happens. This may end up in review of liabilities, service contracts and SLAs and may severely effect the business eventually. Most of all, it effects the user confidence. The end user empowers the payment system and trusts that the system is securely handling their data. It is very important to ensure this trust is maintained. Surely, this is how this complex system was designed or was intended to operate. 

 

Friday, 20 August 2010

Just Check In, we'll sort out the rest!

With great power comes great responsibility but I guess Zuckerberg didn’t watch SpiderMan. Turning on features without appropriately (an email would be nice!) notifying the users (unless you follow their blog) is probably becoming a norm. It is assumed that all the users will get the news. But when the change, in this case a new feature, influences 500 million + users’ privacy, I believe there has to be some sort of notification mechanism. Well, tough luck Facebook users, it is not yet to be. This particular change is not as bad for those outside the US as Facebook Places feature is only active in the US. However, each user's the profile ‘Privacy Settings’ will show three new entries/settings that default to:

Things I share:

Places I check in = ‘Friends Only’

Include me in “People here now” after I check in = ‘Enable’ checked

Things others share:

Friends can check me in to places = ‘Select one’ (Enabled/Disabled)

Ideally, one would have liked the new features to be set as per the user’s preference but again, Facebook has set it for you. One would have preferred a notification to enable the Places feature on user’s permission and then asked the user to set the above three settings to their own liking. Anyway, if you don’t like Places, just disable it as below by going into Account>Privacy Settings>Customise Settings


Media_http1bpblogspot_dhict


Often in business, due to competition the end user benefits. With personal data at stake, in this particular case it seems the cost is privacy.

Personally, ‘Friends Only’ setting is quite generic and ‘Friends’ on Facebook does not really accurately reflect real life relationships. Facebook 'Friends' can be classed into acquaintances, friends and close friends in real world. One may not want all 'Friends' to see status updates, locations, photos, videos etc. In this case, the ‘lists’ functionality within Facebook can be used to group friends into appropriate lists and fine tune the privacy settings to restrict sharing. But things may get a little complicated there. The privacy update earlier this year didn’t do much for the user in this regard. It was a well presented screen/facade to the same behind the scene workings that enticed the users to ‘recommended’ settings and silence the critics. Prof. Ross Anderson sums it up very aptly in an OWASP podcast , Facebook is trying something extremely difficult here and it is going to have to face many challenges in the road ahead.

For the readers interested further in Facebook Privacy Settings, Sophos has a good basic guide to the settings here.

Tuesday, 17 August 2010

Security training - make the message stick!

Security training programs are boring. I don’t have the statistics to support this claim but surely there are other things that employees have to do or are rather interested in than attend a one hour session instructing them on security policies and best practices! Think about a security professional sitting in an accounting training class. It is done because it has to be done with varied level of interest, mostly low.

And the aim of a training program, albeit any presentation is to engage the audience and deliver a message that sticks, preferably for a long period of time. Going through slide after slide of bullet points is just another presentation that the audience will never remember.


Media_httpuploadwikim_bfagu



I recently delivered a PCI training session to a few DBAs. The slide deck was ready to take them through the whole nine yards of PCI DSS, ensure that they understood what it meant and that it has 12 requirements they should be aware of. Having sat in their chairs before, I thought maybe there is a better way of delivering it to make the training more interesting. An impromptu decision, I thought a real story is always a great start.

So I decided to tell them the story about one particular individual named Albert Gonzalez. Now, he should’ve been classed as one big APT by looking at number of ‘results’ he had under his belt! :) His was more of a joint effort but the story of several breaches he led sticks, and it sticks well. The events are also directly/indirectly responsible for the onus on QSAs to store evidence while performing an assessment. I’m sure many of the QSAs don’t like Mr Gonzalez for that but I must thank him for providing such an entertaining story for my audience.

I didn’t have this transcript during the training but the conversation excerpt is a good insight into one of the many threats the standard aims to protect against. I must mention that A Gonzalez bought a 0-day but let’s not go there.

This also is the key approach in Security - realise the threats.

Once a good DBA knows what is the threat and what is being protected, it usually helps them understand the rationale behind the rigor of controls, their responsibilities and help watch out for suspicious events better.

Chances are, it may help them avoid installing the Facebook Dislike Button!