RealSecurity

A Different Perspective of Information Security


PCI Security

Or lack thereof

not so smartI can’t really explain why this bothers me so much. Does it really matter in the big scope of things? Not really. In fact, not at all, but that doesn’t change how I feel about it. Recently, PCI Security Standards Council released an updated version of the PCI DSS making it now version 1.2.1. The date on the title page says July 2009, but the properties of the MS Word version say August 10th. The date is of no real consequence to my point, but the MS Word version is.

Friday 21 August 2009 at 08:58 am

Posted in compliance



Why Compliance Does Not Equal Security

It’s all about missing the intent of security and focusing on the audit

intent verses auditJust when you thought it was safe to go outside after SOX and PCI, ARRA’s HITECH regulation concerning privacy and security raises its head. And rest assured this is simply the tip of the iceberg of what is going to come. Security regulations are a fact of life. However, the implications and impacts of emerging regulations are becoming intense. HITECH provides teeth to HIPAA and introduces arguably the first nationwide breach notification law representing an evolutionary approach to regulations. How you deal with regulations moving forward need to be changed dramatically.

Tuesday 18 August 2009 at 10:21 am

Posted in compliance



ARRA’s HITECH Privacy and Security

Read the fine print

HITECH HIPAAOn Tuesday, February 17, 2009, 26 days after taking the presidential oath, President Obama signed the American Recovery and Reinvestment Act (ARRA) of 2009. A 407 page document containing no less than 23 titles in two major divisions. Needless to say there is a lot in this act. However, from an information security perspective, what really standards out is Title XIII, Health Information Technology, or more commonly known as the Health Information Technology for Economic and Clinical Health Act (HITECH).  Comprised of several parts, subtitles, and sections, this comparatively small part of ARRA adds serious teeth to HIPAA. We knew it was coming, so strap in, we’re going for a ride.

Monday 17 August 2009 at 09:22 am

Posted in compliance



Twitter and TinyURL

An Ode to Link

dnaThere are a lot of ways to get hacked (duh) and manipulating URLs a prevalent tool for hackers in facilitating an attack. It may not be “the” attack, but it’s a common stage in the attack vector. Links can be misleading, used in SPAM, and in XSS attacks. They can also help people legitimately make money through click-through warehouses and even by manipulating affiliate programs. Now, look at Twitter and TinyURL through these lenses and you sorta see where I’m going.

Thursday 13 August 2009 at 09:17 am

Posted in threats



R-e-s-p-e-c-t, Just a little bit

Find out what it means to you

matrixYou’re a CISO and you’ve just left an executive briefing explaining various compliance gaps and risk knowing full well you don’t have enough clout, control, or fairy dust to do anything about it. Well, rest assured you’re not alone and your CEO is not the only executive that can’t seem to connect the security dots. Security experts are dropping like flies in the government with virtually all the top spots being vacated due to lack of authority.

Tuesday 11 August 2009 at 09:30 am

Posted in perspective



Endpoint Appreciation

And you thought you only had to worry about servers and firewalls

laptopA number of technologies are available for endpoint security and rest assured more are coming. The move toward a “work anywhere from any device” strategy is quickly gaining speed. Add to this the adoption of cloud computing, specifically SaaS, and deperimeterization activities, endpoint security has all the characteristics of skyrocketing.

Monday 10 August 2009 at 10:58 am

Posted in perspective



Controls vs. Threats

There are a lot of security controls, but do you really know the threats they are addressing?

lockLet’s face it, security can be complex and the fact that attackers are always finding something new to test the industry’s capability make it difficult to know the real capacity for a control’s effectiveness. As an industry we tend to layer things on one another applying a defense-in-depth strategy, which is a proven strategy and makes perfect since. But, do we really look at various security controls through this lens or are we just putting something in because we think it will help?

Friday 07 August 2009 at 2:29 pm

Posted in threats



Big Security

Can really large companies truly be secure?

maskThere are a number of attributes within very large organizations that tend to put them at a disadvantage concerning security. Not that these corporate characteristics are unique to large companies, but rather that highly diverse and multi-layered environments act as enablers to those elements that may knowingly or unknowingly conspire against the company as a whole. Add to this the enormous dynamics occurring in the technology and security spaces, the lethargic nature of some organizations results in adopting technologies and facilitating initiatives that are outdated before the first box is plugged in.

Wednesday 05 August 2009 at 6:03 pm

Posted in perspective



Demonstrating Value

Tracking effectiveness of security as a program

moneyThere are a number of practices concerning metrics and measuring security activities, and I’ve written on the importance of capability maturity in the security program (look for more articles from me on the topic of CMM in security). An increasing activity, especially in the light of recent economic pressures, is managing, monitoring, tracking, and reporting on the effectiveness of the security program in the employment of resources and budget.

Monday 03 August 2009 at 9:34 pm

Posted in perspective