Showing posts with label IT security function. Show all posts
Showing posts with label IT security function. Show all posts

The hedgehog's dilemma - Story of business and IT Security


In Summer 2011 a new security related conference series was started in Madrid. Or better said, a technology-based risk management and innovation event. I had the privilege to give the opening talk on the links between security and business to a wide and wise audience. I titled my talk the hedgehog's dilemma.
This post summarises the main points of the talk. They are still applicable (they are even more applicable now than in 2011!). Happy to start a discussion thread on your views on these macro topics. They are not closed to a command line but they certainly steer our professional future working with and at corporations.
Using wikipedia's description of the dilemma, "hedgehogs all seek to become close to one another to share heat during cold weather but they must remain apart, however, as they cannot avoid hurting one another with their sharp spines".
Security and business suffer exactly from the same dilemma. The objective will be to change the paradigm from hedgehogs to penguins. Penguins can stay together. Actually, they benefit from staying together every winter.
I proposed two dimensions to work with, a methodological dimension and a human one. Let's describe both of them:

From hedgehogs to penguins: A method
Firstly, we need to use traditional risk management concepts such as vulnerability, threat, risk, impact & probability and benefit to risk ratio, all of them explained in the first chapters of IT Securiteers.
Secondly, I propose the use of 1 + 3 + 1 filters. As a security professional, pay attention to elements that pass these five filters:
1. They are real and detected threats. This is why monitoring is key.
2. They cause a high impact to the organisation and they mean a low risk for the attacker.
3. Their treatment does not require massive resources and does not decrease customer usability. This filter is a though one to respect. However, it constitutes a mid-term survival guarantee for Infosec professionals at work.
4. They bring a positive reputation to the security team. This one is also challenging but worth considering in these times in which we need to market everything.
5. They comply with legal and governance requirements and they satisfy senior management's requests. Please do not forget the last part of this fifth filter.
Certainly this is easier said than done. Three additional tactical tips:
a. Plan not more than 40% of your security resources. They need to be available to deal with a great deal of unknown (and ad-hoc/unplanned) activities.
b. Follow a "baby-step" planning approach and celebrate (and sell!) every successful delta.
c. A useful way to structure your work is considering these layers: networks, systems, applications, data and identities. (Thanks to Jess Garcia for this point).

From hedgehogs to penguins: A passion
Security teams certainly need passionate and technically-savvy security professionals. Together with this statement, I would add that we need a multidisciplinary team. Non IT-savvy and non-security savvy players have also their place in a Security Team. These new players can come from fields as distinct as marketing, sociology, statistics, journalism, law and economics.
The number of interactions that some of the security team members need to have with the rest of the organisation is high. Public relations and marketing are essential for the previously presented 5-filter method to succeed.
How many active security teams do you know that already have this innovative composition? Probably not many. Two references to go deeper into this subject of security management: Try IT Security Management and Secure IT up!. I would be happy to present it to you if required.
These multidisciplinary teams will live the motto "share, respect and mobilise":
- Share the information you work with with your colleagues.
- Respect any personal and academic background from any player in the team.
- Mobilise your peers i.e. trigger their curiosity for your field of expertise.
Two models to help growing cohesive teams. Both models aim to find a balance in every team member:
- Find the sweet balanced spot among the skills they offer, their passions and market demands.
- Find the sweet balanced spot among they as individuals, they in their social dimension and finally they in their professional lives.

Multiple leadership and continuous learning
Security teams need more than one leader. Preferably three. At least two that get along well and complement each other. The role of the leader will be to look after team members while delivering the mandated value to the organisation.
In a two-dimensional graph, draw where your team members are in terms of valuable security skills and level of motivation. Those scoring high in both axis constitute your team's critical mass. The role of the leader will be to grow that critical mass i.e. encouraging everyone to sharpen their skills and letting motivation grow inside of them. Imagine a KPI on this!

Important ingredient not to oversee
Security team leaders need to be outward looking and multidisciplinary themselves. They need to act as security ambassadors specially with their reporting lines and customers. They'd better double check periodically whether they still have their senior management support.  

Security innovation: Five provocations
Some food for thought. Call it crazy ideas, call it security innovation:
- Conduct effective guerrilla marketing out of your CERT team.
- Design accurately (and smartly) the experience that a visitor to your facilities and a customer of your security services would leave with. End to end.
- Identify social connectors in your organisations and make them be your security marketing ambassadors, even if they do it unconsciously.
- Make the most of the "power of free" e.g. distribute free encrypted memory devices.
- Be constructive. Remember, life will always find a way!

Happy finding!




Finding a way

Book review: The Phoenix Project by Gene Kim, Kevin Behr and George Spafford

Every now and then I share with the readers my views on a specific IT or IT security related book. This time I start with a final statement: This is a must-read novel. Every IT and IT security professional will sleep much better after the reading of this The Phoenix Project. Why? Here you are some telegraphic arguments or tips extracted from its pages:

- Consider IT development and IT operations as elements in a production plant.
- Go and re-visit how you can use Kanban boards to protect your bottlenecks i.e. your highly overdemanded resources.
- There are 4 types of work: Business project work, IT project work, changes and unplanned work. The last two ones, if not properly managed, will destroy you.

This book is a tool to reflect on how you need to interact with core business areas and executives. Above all, this is a novel, a human story that you will find very close to your everyday live.

The special bonus in this book for those related to security? Read how the IT security officer goes from being hated to being a part of the solution to the problems the company is having. That is a great worth reading passage in this book.

An additional ingredient in the book is the role of a somehow distanced but experienced mento. One of the lessons of the book: do not despair and think simple!

And remember:
- IT is pervasive, like electricity, it is not just a support area.
- If IT wins, the business wins.
- IT and business in unsuccessful companies is a dysfunctional marriage.
- Interesting idea: A hedge fund betting on organisations with a great IT department. 
- A new? concept: devops (from development and operations).
- And even a newer proposal: organisations with no IT department, but rather IT inside the business areas. How does this sound?

Kudos to the authors Gene Kim, Kevin Behr and George Spafford!

Infosec people, build the tower but enjoy the tree!


Human intuition: What if we apply it to improve security?

Within the @Google Presents talk series, the Nobel Price and psychologist Daniel Kahneman gave a lecture on intuition that I summarise in this post, always looking at it through the information security lens to distill innovate knowledge.

He started with an enticing question:

Intuition, why do we magically know things without knowing we know?

Different authors have studied human intuition. Gary Klein in his book on "Sources of Power: How People Make Decisions" think that judgement biases are not so negative. Malcolm Gladwell, in his book "Blink: The Power of Thinking Without Thinking" has also dealt with the power of intuition.

Mr. Kahneman is sceptict about expert human intuition. For example, in fields like Medicine, when can you trust intuition? He identifies two modes of thinking that lead to the creation of judgements:

- Mode A, as something that happens to us, e.g. when we perceive through our senses, have impressions and intuitive thinking. This is the intuitive and automatic one.
- Mode B, as something that requires effort. This is the deliberate and 'effortful' one.

He shares some scientific results that can have an impact in social engineering: self control related to mode B is impaired if we are doing another activity at the same time. This means that it takes some effort to control our impulses. For example, we would pick chocolate more easily if we keep at the same time a 7 digit number in our head (minute 12 of the talk).

Would that mean that if we ask someone for their password while they are doing an 'effortful' activity we could be more successful than if we ask them when they are idle? Probably.

However, if we focus at mode B, for example, driving is a skill. In a mode A skill things begin to happen automatically: we can drive and talk, we would brake in a completely automatic manner. The same cannot be said, for example, if we drive on skids. This is a completely non-intuitive skill.

But then, when can you trust intuition? Mr Kahneman states that, if there are clear rules in the environment, especially if those rules can give us immediate feedback, we will acquire those rules and let mode A run. This is the reason why we are very good at immediate reinforced practice. This is what he calls intuitive expertise: the reason why, in Medicine, anesthesiologists, thanks to the quick and good feedback they receive from their actions, develop intuitive expertise and the reason why radiologists get the opposite case: they receive slow and not so good feedback from their actions so they have a difficult time to develop intuitive expertise.

Let's have this point in mind when we approach a user community to improve their security practices.

This expertise is not possible in chaotic scenarios. This is why the world is not predictable. For those cases when predictability is poor, it is better to follow pre-made scripts.

This thought is valuable when designing incident response actions. Build your formula and don't let intuition be the main driver. 


Peculiarities of our mind

Mr Kahneman mentioned that human memory is superb at remembering routes through space but rather poor at remembering a list. An practical example of this can be found in the book "Moonwalking with Einstein" by Joshua Foer.

So what about if we associate places in our work facilities with secure behaviours?

Our mind likes to think about agents that have traits and behaviours. We are not good at remembering sentences with abstract subjects. Our behaviour is influenced by the signs and posters that we see around us. Especially by those that relate to something concrete. For example, when people are exposed to a threatening word, they move back. Symbolic threats have a real effect.

And what about if we place a poster with a pair of eyes watching us close to an Internet kiosk in a public place in a firm? Would users behave more securely?

Our mood is also influenced by our actions. If we make a smiling face, we are more likely to think that things are funny. If we place a pencil in our mouth, we will think that the cartoons we watch are funnier.

By partially activating ideas through these mechanisms e.g. by whispering words, then the threshold to feel emotions related to those ideas is lower and all this happen without us knowing it consciously.

This has a lot of potential at the time of designing a cultural change related to information security at workplaces.

Our associative memory is a repository of knowledge. We take very little time to create norms in our minds. Our reasoning flows along causal lines, this happens intuitively. The coherence that we experience can be turned into a judgement of probability. This is the reason why Mr Kahneman is not really a fan of human intuition: People have confidence in intuitions that are not essentially true.

This point is key for those applying risk management methodologies to their information security practice.

He mentions that, so far, all intelligence tests we have are for mode of thinking B. However, we are all influenced by our intuition. It's hard work for mode B to overturn what mode A tells us.

I finalise this summary with the 'security related' morale of the talk. When can we trust our intuition? Only when the environment is predictable and we have had the opportunity to learn its regularities.

Happy intuitive reading!

Were these the posters in the Middle Ages?



Surviving success in entrepreneurship and... in IT security?

Stanford University shares with everyone on the Internet a series of podcasts and videos related to entrepreneurship through their Entrepreneurship Corner. These pills of knowledge are not intentionally related to information security. However, I find that the learning points mentioned there are worth at least some reflection time by itsecuriteers. For instance, Mark Forchette presented his talk on how to survive success. I drew some lessons from his talk:

lesson 1 - know what you want, set your objectives, promise you will achieve it

lesson 2 - you must have passion

lesson 3 - no matter what you do, you must know how to sell, everybody sells

(proposal of a book to read : how to master the art of selling)

lesson 4 - there is no failure that you can't recover from (so enjoy failures)

lesson 5 - strategy and tactical implementation = success (if you cannot execute the plan, it's not worth the paper it is written in)

lesson 6 - the most dangerous thing in the world is a past success you are still in love with  - surviving success is one of the most difficult things - the best day has to be ahead of you

lesson 7 - do things other than just for money

lesson 8 - people do business with people they like - business is a contact sport - be likeable

lesson 9 - prepare, prepare, prepare

lesson 10 - make sure the right people are on the right seat

Look at these 10 lessons from the IT security practitioner viewpoint. They can provide you with value.

Happy entrepreneurial reading!

Learning to fly

IT Security Management book


IT Security Management
How to set up an IT Security function

After long months and long hours of research, writing and editorial work, there is a new book I recommend on the topic of IT Security Management and how to create, grow and develop an IT security team while providing business value.

There is an extensive bibliography delving into the field of IT Security, from very technical aspects to information governance. However, there are not so many titles with both a technical and a human vision on how to create an IT security team, a team of IT Securiteers.

It is published by Springer within their Lecture Notes in Electrical Engineering series. This book is a key component to build the syllabus of a Masters Degree in Information Security or IT Security Engineering.

Its title is "IT Securiteers: How to set up an IT Security function".

You can find it, together with a brief intro, in the publisher's site - Springer - and in Amazon, among other sites.

Happy reading!
(Certainly, any comment on the content, feel free to drop a comment here!)

You can also "follow the book" in twitter @itsecuriteer.


The following words come from the publisher's site:

IT securiteers - The human and technical dimension working for the organisation Current corporate governance regulations and international standards lead many organisations, big and small, to the creation of an information technology (IT) security function in their organisational chart or to the acquisition of services from the IT security industry. More often than desired, these teams are only useful for companies’ executives to tick the corresponding box in a certification process, be it ISO, ITIL, PCI, etc. Many IT security teams do not provide business value to their company. They fail to really protect the organisation from the increasing number of threats targeting its information systems. IT Security Management provides an insight into how to create and grow a team of passionate IT security professionals. We will call them “securiteers” . They will add value to the business, improving the information security stance of organisations.