Showing posts with label resilience. Show all posts
Showing posts with label resilience. Show all posts

Wednesday, July 11, 2012

PREP: Value Chain - Climate Change Resilience

Leading companies from the food and beverage, insurance, investment, technology, and energy industries have jointly released a guide to climate change resiliency planning. ‘PREP Value Chain Climate Resilience’ includes a step-by-step tool, Business ADAPT, for businesses to assess and prepare for the risks and opportunities posed by climate change.

The Business ADAPT tool provides five simple steps to help companies understand and act on the climate related risks that they face.

The steps are targeted towards company executives and senior managers, and provide detailed guidance in sectors that are considered highly vulnerable including water and energy utilities and companies in the food, beverage, agriculture and general manufacturing industries.

The five steps are:
  1. Analyze the issues - Have you started thinking about the resilience of your business in the face of climate-related impacts?
  2. Develop an internal strategy - Have you mobilized the right team to address climate resilience?
  3. Assess risks and opportunities - Have you taken steps to assess the areas where opportunities to build climate resilience or invest in emerging market opportunities exist in your business value chain?
  4. Prioritize actions - Have you taken steps to identify and assess measures to build climate resilience in your value chain?
  5. Tackle actions, and evaluate progress - How will you successfully implement actions to build climate resilience in your value chain, and evaluate and monitor the effect of your actions over time?
PREP Value Chain Climate Resilience has been written by The Partnership for Resilience and Environmental Preparedness.

PREP is a one-year pilot partnership formed to address the risks and opportunities that climate change impacts pose to businesses and the communities on which they depend.

Members include Calvert Investments, Earth Networks, Entergy, Green Mountain Coffee Roasters, Inc., Levi Strauss and Co., Starbucks and Swiss Re. BSR and Ceres are also partners. Oxfam America serves as PREP's secretariat.

The firm Acclimatise served as lead authors of the report.

Read PREP Value Chain Climate Resilience.

Sunday, April 15, 2012

Risk and Business Continuity - Managing for the unknown

Do you have the right team in place to face a future filled with Unknown Risks?

While the perilous unknown may be the stuff of sci-fi and doomsday movies, the potential for more mundane or fiscal danger is always around us.

This should not provoke paranoia but rather a healthy sense of vigilance as well as skepticism. Executives need to be vigilant about what could happen next. By all means consider pandemics, earthquakes and wars, but also be skeptical about their effects on their organisations.

For example, if financial executives had been more vigilant and skeptical prior to the fiscal meltdown of 2008 some businesses may not have found their institutions so over-leveraged.

Clearly, we say this from the moral high ground of Hindsight, which is always 20/20.

So what is a savvy executive to do? Three questions come to mind.

What is the worst that could happen to us?
This question prompts many scenarios from a natural disaster to a market crash, or even the entry of a significant new competitor who changes the balance in the market place. What happens then? Executives need to keep their antennae up and do their Risk Assessments and sound Business Continuity Planning.

How would we react?
Very often companies do have BC or disaster plans but are they robust and up to date? Do they stipulate what happens when resources are not available or executives and employees are separated from each other?

Do we have the right people in place to recover?
This is perhaps the most important question. Very often members of a leadership team are equipped to manage when the going is good, but what happens when the bad gets into fear and panic?

The senior leader must ask if these people have the right mindset to adapt to evolving and changing circumstances.

Flexibility becomes an imperative, but so too does resilience. You need leaders who can cope with setback and maintain the discipline to persevere.

Big questions provoke big picture thinking. Very often such questions will cause real unease, or at least a sense of disruption and that is healthy.

If a catastrophe strikes disruption will be significant. So what will you do to survive?

Saturday, April 14, 2012

Project management lessons you can take from the Titanic disaster

One hundred years ago this month, RMS Titanic sank after striking an iceberg. More than fifteen hundred people died in that disaster.

The event has been the subject of books and movies, but it also provides a few stark illustrations regarding project management mistakes and oversights.

Here are seven lessons that relate to the sinking itself and three that involve the recovery of the victims.

1: You need to know what you’re measuring

The lack of lifeboats is a well-known matter, and it certainly played a role in the number of deaths. However, according to the regulations that applied at the time, the Titanic DID have “enough” lifeboats?

According to the standards in effect at the time, the WEIGHT of a ship, not the number of passengers, determined the number of required lifeboats. Needless to say, these standards changed as a result of the inquiries into the disaster.

This principle applies to your own projects. In his classic work The Mythical Man-Month, Frederick Brooks points out how far too often a project reaches the point of “coding 90% complete,” only to remain that way forever.

Brooks says, milestones should be objectively measurable. If you do not have valid measurements for your project, you will run into problems.

2: Assumptions will kill you

A few hours before the collision, wireless operator Jack Phillips received a message from a nearby ship, telling him of icebergs in the area.

However, Phillips at the time was taking care of messages to and from Titanic passengers and in doing so, was communicating with a lighthouse at Cape Race, Newfoundland.

Unhappy with what he considered a bothersome message, and assuming it was unimportant, Phillips replied brusquely, “Shut up, I am working Cape Race!”

As a result, Phillips never received the iceberg warning the ship was trying to send.

How often have you seen things blow up in your face because of assumptions? Maybe you assumed that a particular system was using a newer software release than it actually was.

Maybe you assumed that another department or someone else, would take care of ordering cable. Maybe you assumed that the vendor received our critical email message and didn't need you to call to check.

Assumptions are important in your work, but if you proceed on the basis of them, make sure everyone is clear about what assumptions you are making.

3: Distractions are dangerous

Of course, when we look back, we can always find fault with the actions of Titanic officers and crew.

Clearly, they must have known about the risks of traveling through “Iceberg Alley” so, they should have focused the wireless operators less on passenger messages and more on communication with other ships.

The Phillips incident, therefore, illustrates another hazard to project management: that of being distracted.

How often do you start your work with the best intentions of completing your to-do list, only to become sidetracked by chatting with co-workers or surfing the Web?

And you are not alone in facing distractions. If enough members of your team encounter enough distractions, your project will gradually wander of course and fall behind.

4: Little things add up

A number of small factors played a role in the Titanic disaster. Allegedly, the lookouts had no binoculars, because those binoculars had been left behind at Southampton, where she began her voyage.

Jack Phillips interrupted a ship trying to send him an iceberg warning and neglected to deliver an earlier warning.

While no one factor can be said to have “caused” the disaster, the effect of all of them made the disaster all the more likely.

Brooks asked rhetorically, “How does a software project get to be a year late? One day at a time.”

He explained that if a major event or problem occurs, a project team rallies and steps up its effort.

However, such a team can fail to appreciate the issues of small delays and how those small delays add up.

In other words, the small delays are just as critical as the large ones, meaning that adherence to milestones is critical to the success of a project.

5: Stakeholders should be kept informed

Following the iceberg collision, the nurse for the Allison family, in first class, took one-year-old Trevor Allison from the family stateroom without saying where she was going.

She and Trevor boarded a lifeboat and were rescued. However, because Trevor’s parents didn’t know about it, they spent the rest of the time looking for Trevor, turning down chances to escape in a lifeboat.

As a result, the parents and their other child, three-year-old Loraine, died when the ship sank.

Your own project might not be as critical as a sinking ship but your stakeholders need to know about the status and progress of your project. Keeping them informed will keep them happier.

6: Other people’s perspectives matter

One of the victims of Titanic was 23-year-old John Law Hume, a member of the band. A few weeks after the sinking, the company that managed the band sent a letter to his father, asking for payment for his son’s band uniform.

Even although such a request made financial sense from the company’s perspective, it almost certainly sounded insensitive to Mr. Hume.

In the same way, when explaining aspects of a project, especially by technical members of your project team, try to see things from the other person’s perspective.

If a client asks a question, try to see beyond the question itself to the motivation behind the question.

If a technical person is explaining a function of a system or program, make sure the explanation avoids jargon. Clear communication will lead to happier clients.

7: Moving targets can hurt you

The Titanic was one of three new ships the White Star Line had built, around that time. The company’s strategy was to emphasize luxury, not speed, as a selling point.

Yet during that maiden Titanic voyage, White Star chairman J. Bruce Ismay reportedly pressured Captain Edward Smith to increase speed.

This higher speed quite likely contributed to the collision, in preventing the ship and crew from reacting quickly enough.

In your projects, beware of “scope creep.” A typical customer, if there is such a thing, will say, “Can you make just this one small change please?”

The fact is, any change is rarely “small.” It typically involves making other changes to other parts of a system, results in greater complexity, and requires more testing.

Make sure that your customer knows that in a project world governed by quality, time, and budget, at least one will have to yield.

Be sure your customer understands the implications of a requested change, the need for change control and ensure that the customer’s expectations are appropriately set.

8: Traceability is essential

A few days after the sinking, rescue ships based in Halifax, Nova Scotia, set out to recover victims and to return them to Halifax.

As each victim was recovered, he or she was numbered accordingly. The recovery crew recorded information and a description of the victim in a ledger book and then bagged personal effects with that same victim number.

If that victim was later buried in Halifax, and 150 victims were buried in three cemeteries there, then that victim number was engraved on the grave marker.

The victim number allowed researchers and others to link victim and property descriptions, to the cemetery location.

The same kind of traceability is important in your projects. How familiar are you with the strategic objectives of your company?

Can you find a logical connection between the requirements of your project and those strategic objectives?

Of course, the connection might be a distant one, but there should be a connection nonetheless but if you can find no such connection, you start asking yourself whether that requirement really is part of your system.

9: Methodology is more important than technology

When the recovery crews were recording victim information, they used regular ledger notebooks and pens, obviously, no one had iPads, computers, or barcode scanners in those times.

Nonetheless, the methodology they used had solid reasoning behind it, so it proved highly effective.

In the same way, you might want to use sophisticated planning and tracking software and tools.

More important, though, is that your plan be resilient. The best software in the world will not save a poorly designed plan.

10: Documentation may have lasting benefits

The documentation of the recovery records are still kept in Halifax, at the Public Archives. Researchers in Halifax and from around the world still visit and review this documentation, one hundred years after the fact.

A few years ago researchers made use of these records, and DNA analysis to identify the “Unknown Child of the Titanic.”

No one enjoys documenting a project or system but it is a necessary part of it. Documentation is often the 'most' important part of the project because it will exist long after the project team has been disbanded.

Documentation probably won't need to exist for a hundred years, but it should still serve the purpose of helping your customers understand their system and allow them to build on what you have already accomplished.

Thursday, October 27, 2011

Our security paradigm is out of date

At a recent Cloud Security event, the president of the UK & Ireland chapter of the Cloud Security Alliance (CSA UK & Ireland) said that the perception of security as a concept is out-dated.

According to Des Ward, the current focus on complying with the myriad of assurance frameworks is taking focus away from the obligations placed on organizations to identify and manage the risks to their information assets; which, in turn, places an inordinate and inappropriate burden on external service providers to satisfy the concerns of organizations with no common terms of reference.

“The discussion following my presentation was very interesting as it highlighted that, whilst security in the cloud services environment is clearly a concern for many IT security professionals, there is still a lack of assurance within the external supply chain as whole,” said Des Ward, President, CSA UK & Ireland.

“What this tells me is that, whilst the message on security is getting through to businesses, there is no consistent language to determine whether the service provider will operate the controls to a level that assures the client that their risks are managed appropriately.

This proves to me that the current security mindset is little more than managing risks to achieving compliance rather than empowering organizations to understand the controls required to manage the risks to their information.”

“It is important”, says Ward, “to understand that all organizations in the UK and Ireland, on both sides of the public/private sector divide, have an explicit obligation under law to ensure that personal and corporate information is managed in a safe manner.

“The current compliance overload over the past four or five years has led to an inordinate focus on managing risks to compliance rather than understanding the risks to information – and this focus has meant that we look to overuse of technical controls to show due diligence to ensure that when a breach occurs, that penalties will not be levied; it is not designed to reduce the likelihood of breaches themselves,” he adds.

“This approach is, in my humble opinion, unsustainable, as it does not look to the implementation of the controls and fails to address the business risk management issue that exists in most organizations.

This is turn has no more benefit to the business than placing money in the shredder.” he explained.

“A classic case of these issues”, he says, “was the ICO's recent engagement with Lush after the cosmetics retailer suffered a payment card breach; although the outcome was favourable for all concerned, the key lesson to be learnt is that the current compliance boundaries can now be crossed by another interested party.

What stops the ICO from looking beyond the compliance scope of PCI and entering its own jurisdiction which is the entire business?

“The current lack of corporate information governance in today's businesses will soon result in increased penalties and I feel that this case will be a tipping point; despite the clamour for more prescription from assurance frameworks, my own experience is that many implementations of the PCI DSS are tightly scoped and shows there is little appetite for additional level of prescription that comes with little more benefit than a licence to undertake business on the internet.

This proves to me that the current focus on compliance risk management as we know it is nearing an end, and something else is required to assist organizations to understand and manage the risks to their information going forward.”

The Financial Turmoil and Business Continuity

‘Eurozone at tipping point’, ‘Greece may be forced to default’, ‘Is the euro doomed?’ The headlines alone make you want to pull the covers over your head.

The Governor of the Bank of England, Mervyn King, tells the BBC: “This is the most serious financial crisis at least since the 1930s, if not ever.”

He then went on to call for a calm reaction to the crisis; which led to a few wry smiles!

If the financial crisis does get appreciably worse or, heaven forbid, the euro were to fail, what does this mean for business continuity professionals? Because, call the eurozone meltdown what you like, it’s certainly a crisis: and crisis is what we do isn’t it?

Contingency planning makes us all gaze into a crystal ball from time to time in an attempt to predict what might happen so we can plan accordingly and provide contingencies. But inevitably: ‘All plans imply an attempt to impose the values of the past...on the future.’

So it doesn’t mean we always get it right. But if the world’s economy or ‘just’ the eurozone does take a serious dive then at some point organizations are going to look to us to help get them out of this mess.

So what can we, as business continuity professionals, do to help: and how can our specialist knowledge be leveraged to help those trying to overcome the financial crisis?

We have a responsibility to understand as much as we can about the financial situation, but clearly it’s not our job to solve it.

For that there are leaders and governments; though some might argue it is just such people and institutions that got us into the crisis and of course within companies, particularly banks, there are experts assigned to investments, governance, auditing and PR who are trying to mitigate risk.

We stray into those fields at our peril. But what about the aftermath of a crisis? Many predict that inflation will go through the roof and this could spark further looting or civil unrest on the streets.

There could also be lengthy utility failures, fuel shortages, disruption to public transport and pressure on supply chains.

Perhaps staff won’t be able to travel to work or prefer to stay at home to look after their families. The fallout from these kinds of problems has our name written all over them.

The job of the business continuity professional is to identify risks and impacts to critical processes.

For each critical process we have to identify ways of providing a structure that enables these processes to be performed during or in the wake of a crisis.

Once the resources needed to perform these actions are identified this can form the basis of a plan, which can then be tested to see whether core critical processes really can continue to operate in extreme circumstances; and it doesn’t get more extreme than the uncharted territory that we would enter should the European banking system or the euro fail.

Unravelling a financial crisis may be way outside our skill set, but our business as usual is business as unusual and crisis our stock in trade.

Perhaps it’s a good time to review business continuity plans in the light of the societal impacts that could occur.

Tuesday, April 7, 2009

Re-thinking IT Security in tough times

The current economic downturn is forcing a corporate change and metamorphosis that, when combined with ever broadening security threats, presents information security groups with an opportunity to radically change their identity and add more value to the business.

To capitalise on the moment, security groups need to reassess their approach, add visibility and transform the very role of security.

It is good timing because maintaining security during tough economic times is critical. Besides external threats that evolve even more rapidly in economic downturns, business slumps increase the probability of disgruntled employees striking out using intimate knowledge of corporate systems.

Risk is further exacerbated by the fact that, since the last economic crisis of this magnitude, companies have become far more reliant on information technology systems, which are now highly complex and essential to sound operations.

Your current security path represents existing programs, capabilities, processes, etc. The goal is to create a parallel path that influences existing practices and allows you to refine a new strategy without disrupting current expectations. In time, the new path will become a dominating force and take you in a new direction.

Step 1: Tuning the Approach
During the last decade security has been virtually defined by compliance. For many companies, it has been less about security than it has been about ensuring that certain regulatory demands are being met. Unfortunately, compliance does not necessarily enable the business, align with core initiatives, and alone may not thwart debilitating attacks.

Understanding this, some security groups have strived to use compliance efforts to improve their security posture.

Unfortunately, not all companies see the value of such activities and instead simply see compliance as a cost of doing business.

You have to convert the security practices that fall under the banner of "mandated for compliance" into specific activities that resonate with the business. For example, a predominant force in business is time to market and the rapid conversion of investments to revenue generation. This can materialize as a new service, application, communication platform, network or alliance. The key to tuning your approach is to optimize security features to help the business move more quickly, reduce barriers or accommodate a requirement quickly.

Key to being able to accomplish this is institutional knowledge within the security group and leveraging and combining resources in ways that benefit the business as much as it does security, for example: supporting secure coding practices through collaboration with the development team, optimizing standard builds to stand up servers more quickly, security testing as part of performance testing, or utilization of directory services to support streamlining of access controls for a new partner.

Fundamentally, it is about operating in a risk/reward model. Prioritize activities based on risk as well as where the greatest opportunities are for the business. By becoming intimate with business goals and mapping against elements of risk, what begins to surface is a common thread that demonstrates a point where the business and security goals become more closely aligned.

A good place to start is within the project management arena, where risks to the initiative or life cycle will become apparent, in addition to helping identify critical paths and what is most important or critical to the business unit. By using information of this nature, combined with institutional knowledge that the security group possess, you can begin to interpret demands and risks in business initiatives and quickly find areas of common ground.

Step 2: Adding Visibility
Security groups typically make security efforts visible to executive management by presenting security metrics, risk dashboards, and the like. However, along the way, many encounter some key challenges.

The first challenge is that the measurements are only focused on security and typically do not provide insights to other aspects of security operations that demonstrate effectiveness. For example, a dashboard may present compliance risk, operational risk, technical risk and current threats. It is assumed that keeping the values in an optimal or desired range means that security is doing its job.

However, company executives are increasingly focused on efficiency, effectiveness and overall alignment to business initiatives. They want to know how well these objectives are being met, what influence they have had on other key business performance indicators (such as time to market, customer retention), and how resources and other valuable assets are being utilized.

Executives are concerned about inefficient or wasteful activities and want to ensure all activities focus on the bottom line. Presenting to the board a risk dashboard can be helpful to demonstrate your alignment to security concerns, but that's only one part of the equation in the eyes of executives. The more effectively security can reduce the need to translate security results into something meaningful for the business, the better.

The second challenge relates to the "gap" factor. The gap refers to the difference in what security is providing to executives as visibility and the ability for the security group to influence the system to enact change.

For example, a report may demonstrate that the number of vulnerabilities in Internet-facing applications is increasing significantly quarter over quarter. However, the security group may not have the capacity or capability to reduce that number to a reasonable value. As a result, some senior security managers find themselves tasked to correct an issue they simply do not have the ability to accomplish.

In short, information from the security program is misaligned with its ability. Some use this to justify investments that would address the gap. But unfortunately this pattern is growing increasingly ineffective as business owners demand more accountability. The solution is to create a security program that not only presents good and bad trends, but more importantly, has the ability to have a meaningful impact in changing them.

The challenges can be summarized as providing visibility into more than security in security terms, but also in a manner that is more readily digested by executives and easier to align to business goals. Secondly, build a security program that not only produces meaningful information relative to security and business metrics, but also has the inherent capability to institute change and thereby meet expectations.

Providing additional visibility to existing risk-based perspectives can be enormously valuable. To accomplish this, you need to become more intimate with what resonates with the executives -- the measurements they focus on day in and day out, the performance indicators they study beyond the financial ones. Each company is different and each business unit may have a different spin. Moreover, many may seem like the furthest thing from security, such as shipping metrics, warehousing, capacity indicators, system use or even collaboration indicators. You have to look behind these to begin to see where security can begin to mimic the same philosophies.

From a security perspective, look to report on areas within your domain of influence and help reflect how well you're running as a business. It can be as simple as resource utilization, project involvement or performance quality scores from your peers.

From there you can start tying to other reported information and trends, such as the planned decline in effort to perform regular vulnerability testing, but an incline in report quality and effectiveness, essentially demonstrating that you are meeting security and business objectives. Or show how, through collaboration activities (which have been measured) and modifications to technologies, you've helped reduce the number of security related helpdesk tickets. These are, of course very basic. Nevertheless, the point is to find related information between what you are doing for security and how well you are doing related to business expectations.

This approach helps form your new path for security, drawing from your original strategies and enhancing them. Start small, test the waters and seek mentorship within the organization. As more confidence grows in providing additional perspectives on activities, you can move into closing the gap.

Step 3: Service orientation
By this point you've learned how to orchestrate your core competencies to help the business reach its goals using a risk/reward method. And you've started experimenting with adding visibility to the executives on alignment. As a result, the identity of security is beginning to shift. It may not be obvious, but it's happening. However, this is a critical stage and the time to innovate. Once executives see something they like, they want more, expectations increase, and that "good job" turns into "what have you done for me lately?"

One of the common pitfalls is not following through to ensure a foundation exists to keep up with new expectations. As a result, massive ground is lost and you're back to square one.

Adopting a service orientation can help you continue to move forward. Service orientation has three primary objectives:

1) Convert tactical best practices that were once hidden within compliance efforts into business services that can be consistently utilized.

2) Close the gap between what you can control/influence and what you're reporting on.

3) Create a foundation for building a highly agile security approach.

The key is to learn from experimental practices in tuning activities and report on additional metrics and indicators relative to business goals. For the development of security services, it's the tuning of the approach that provides the information you need to get started.

In the most simple of definitions, a security service is a well-formed package of related processes, technologies and capabilities that has a predictable outcome that is needed or in demand by the business. What makes security services differ from traditional security activities is input.

Just about everything requires input to feed a process to produce an output. For security, the input is usually "self-assigned," meaning the business must meet a specific policy or some other documented requirement to have security perform an action. For example, a policy may read, "Any material change to an Internet-facing application requires a penetration test." That's a sound approach, but it's reactive and misses the opportunity to gain valuable insights to underlying business needs and goals.

While looking for risk/reward scenarios, you will see a pattern emerge and the tuning efforts outlined above should help you identify opportunities to incorporate specific business attributes into what you're performing.

The basis for security services is taking advantage of this pattern. In fact, you're doing this today to some degree. For example, an application is due for a test, but you've learned that the changes relate to one of several roles defined in the system. As a result, you may limit testing to that one area because of your knowledge and comfort with the application from previous tests. Now, extrapolate this to all things in security. It's less about simply doing what you do and more about giving the business additional opportunity to feed the process in order to refine the activity -- or service in this case -- to the business need.

The next important characteristic of security services is how people, processes, tools, methods and technology are architected to perform the service relative to input and output. This is a lot easier to say than to do. Organizations tend to approach these elements as independent or loosely coupled. Moreover, some security architectures and frameworks facilitate segmentation, making alignment of them seem alien and uncomfortable.

One challenge is internally developed standards that are either overly comprehensive or too granular. Successful implementation of security services typically starts with reviewing the standards and looking at them as a common foundation to services as opposed to specific elements for a given security function.

As with all things of this nature, a slow and methodical approach wins the race. Don't try to create a services model over night. Take what you've learned in tuning, couple it with something you're already doing today (such as vulnerability testing, patch management, identity management, data protection, monitoring), and then pilot a services approach with a friendly business unit.

As this approach begins to solidify, several interesting things start to happen. The identity of security and perceived value continues to shift in a positive direction. Nevertheless, you will quickly realize that you have far more capabilities to measure operational details of your organization, and more importantly -- you inherently have more influence over them as a result.

This essentially slams the door on the gap. Services facilitate the risk/reward model, they make it possible to organize activities specific to demand, provide the means to measure those activities more effectively, and allow for the controlled management of each element to ensure that what is being reported can be influenced. This can be a perfect storm, but you're not done. To truly transform, you have to close the loop with governance.

Step 4: Governance Loop
The "governance loop" is the final step and provides the opportunity to realize real transformation. To this point, you've tuned, experimented, tested and created the early stages of services and are beginning to rely on the new path and less on the old one.

This has helped increase visibility, initial alignment to the business and promotes effectiveness. Nevertheless, at this point, time becomes your enemy -- without governance, the services will eventually break down. Governance, interestingly, provides the mechanism to ensure expectations are being met, but also the means to promote adaptability, closing the loop with the business.

Governance acts as the bonding agent between ebbs and flows in the business, compliance, risk and security activities. More importantly, this is where risk/reward is measured and fed back into the system to instigate change. It is also important to realize that risk (management, assessments, reporting) has played a pivotal role throughout the journey, and governance is the means to realize full potential. Risk remains at the top of the pyramid, but now with services underlying it, supported by governance, it can move far closer to the business.

In short, governance is analogous to "inspect what you expect" and influence change. That means creating a set of responsibilities and practices with the goal of providing direction as well as ensuring objectives are achieved and resources are used responsibly. In so doing, measurements from the oversight of security not only ensure efficient and effective execution, but also facilitate change in the program through intimate connections with risk management and the business offering feedback into the system.

In some companies governance is associated with enforcement. Although partly true, a security group empowered by services and close interlinks with overall enterprise governance through risk management activities will be able to put governance to work for them. This is similar to how, over the last several years, many security organizations have changed their perspective of the audit group.

Historically seen as a regular and painful exposure of operational weakness in security, audit processes are now being seen as a way to strengthen security. It's turning what is usually thought of as a negative into a positive force. The same is true with governance processes that are outside of the control of the security group or where security is part of a governance committee.

Nevertheless, an important aspect is to understand that the security group is ultimately responsible for its activities -- good and bad. Therefore, it is recommended that governance be reflected in the security services and program owned and operated by management resources within the group. This is not a replacement for enterprise governance -- rather, it's an extension focused on the betterment of security.

Organizations need security more now than ever, and as a result, are more receptive to security as a community. What you do with that attention today could have enormous influences on the future of security within your company. Although times are tough, don't assume this means opportunities don't exist. The economy will correct itself and businesses will emerge stronger and with a new sense of determination and demands for operational maturity. Taking advantage of what appears to be short-term focus on security for long-term gains is the crux of the opportunity, and opportunity favors the prepared.

This article is by James Tiller, author of The Ethical Hack and Technical Guide to IPSec VPNs, and contributing author on several other books, including the Official (ISC)2 Guide to the CBK, is vice president of security services for BT in North America. He consults with organizations globally on how security can enable business. You can reach him at james.tiller@bt.com.

Sunday, March 8, 2009

Calculating the odds of being paid off - First step

"Will I still have a job tomorrow? and in the tomorrows after that"

With the world economy claiming to be in a far-reaching recession and companies announcing layoffs seemingly every day, the question of continuing employment looms large in every thinking person's mind.

Clearly, some employees feel that they are at greater risk of losing their jobs than others. What's not so clear is how to calculate that risk. So how do you become your own Risk Manager and carry out a risk assessment on yourself. Consider how you can devise a good method that would help, not only yourself but also other IT professionals, get a relatively objective handle on the odds of getting laid off.

You may be wondering why anyone would want to determine the likelihood of their losing a job. You may also believe that a 'layoff' risk assessment method could be a very helpful tool. Depending on your circumstances, outlook and character, many people worry unnecessarily about getting laid off and others who do get laid off, are often taken completely by surprise.

A risk assessment for layoffs could help IT professionals determine whether they are in the red zone (high) or the green zone (low) risk category, when job losses come around. Low-risk professionals will then be able to rest easy and carry on with their work and the high-risk employees can be proactively defend and entrench their positions, whilst actively preparing themselves emotionally, professionally and financially, for the moment when their jobs get cut.

As a first step, let us propose a list of possible variables that could indicate someone is likely to get laid off. Let us also propose another list of variables that could indicate someone is unlikely to get laid off.

Our goal is to develop an accurate and plausible assessment, one that will really help people get a grip on their futures. Coming up with such an assessment, can be difficult, for a whole variety of reasons. One of these reasons would be an incomplete or inappropriate list of variables.

If you examine the lists below and identify which of the variables are appropriate to your circumstances and discard those that are not. You can also weigh a certain number of the retained variables more heavily than others, because of their importance or criticality.

Examine also how the assessment is structured. Structuring it as a questionnaire would allow people to assign points for each negative variable (e.g. each strike against them) and subtract points for each positive variable. The conclusion would be easily calculated and greatly simplified. People with high scores are more likely to be laid off than people will lower scores.

Remember that the goal of this assessment is to help and support people, not to frighten them.

Variables that Could Indicate Someone Is Likely to Get Laid Off

1. Your employer is not meeting its financial plan. (he's broke!)
2. Your salary is at the high-end of the pay scale for your profession or function. (so much for ambition!)
3. A position or function you help support has been eliminated or restructured. (the horse died!)
4. You work on a project that has been cut or that you sense is going to be cut. (Zepellin restoration)
5. You gossip or complain a lot. (no wonder. Look at the previous options on this list)
6. The work you do is mundane or repetitive in nature (e.g. re-setting passwords or setting up routers) and could be outsourced to a third party. (or monkey with learning difficulties)
7. Your work is not customer-focused. (but I work in Security)
8. The function you work in is well/over-staffed (full of "fat" cats that need a trim)
9. You don't "fit in" with the 'culture' of your department. (You are sober)
10. Your company could find someone to replace you at a lower cost with relative ease (e.g. going to the bus stop line, rather than hiring a head hunter)

Variables That Could Indicate Someone Is Unlikely to Get Laid Off

1. You've demonstrated your ability to adapt to new strategies. (Flexible as Yoga)
2. You have good relationships with different people throughout your company. (married to the boss?)
3. Your position is cross-matrixed to different leaders. (you are a bigomist)
4. You have a good rapport with your boss, and your boss is regarded highly by senior management. (you still own the negatives from the office party)
5. You work on multiple projects that are critical to dealing with existing business conditions. (your wife sleeps around)
6. Your skills are up to date, in demand and align with the IT organization's current and future needs. (you have killed all the competition in the office)
7. Your company would have difficulty finding someone to fill your shoes. (you are overweight)

Sunday, January 18, 2009

Project failure starts at the begining

We are all familiar with countries, towns and destinations that are difficult to reach, either by road, rail or public transport and yet people exist there and thrive. It is not in another dimension or another planet, where predictable 'difficulties' are numerous e.g. expensive ad hoc rocket ship service, an atmosphere of sulphuric acid, temperature variations in the region of 'scorchingly off-the-scale', etc. No, our difficulties in reaching our earthly destinations are because we do not start from the correct location.

This is a lesson I learned when lost in Dublin and forced to ask for directions. It was made clear to me that to get to point B I should have started at point A and not the point that I was currently at, which was currently unknown and would henceforth be referred to as X. Thus, making the logic more mathematically predictive.

The start point and the end point, part of the defining structure of a project and thus lifting it away from the realms of a simple action or activity, are critical in the initiation and definition of the project and the associated project plan. You will never reach the end destination if the start is left to serendipitous happenstances.

  • Plan the beginning of your project meticulously
  • Involve as many of the stakeholders as possible
  • Hold a workshop with all the allocated resources
  • Seek out Subject Matter Experts (SMEs)
  • Do your research, technical, business, historical, etc
  • Assess the Risks (qualitative and quantitative) and
  • Look where you are going

The dark matter of Projects failing

IT projects suffer from a similar force to that of the astronomically evasive 'dark matter'. A force that is not so much negative in its manifestation as it is in its effect, especially on other matter. It has an ability to occupy space without contributing anything, interacting with 'light matter' only to drain its energy and restrict its ability to move freely.

'Dark matter', and its ability to absorb and retain energy without contribution, is a universal anomaly for physicists. A puzzle yet to be solved. A question unanswered but not for project managers and team leaders. We know this effect and understand the consequences very well. It is a similar force to the one that will cause your project to fail. It is your greatest adversary. Its invisible. It can be detected but not controlled, without the right tools and level of experience.

Corporate Defense Domain

The Corporate Defense Domain is a convenient way of describing the sum total of numerous secure approaches, tools, processes, etc. that incorporates the entire environment security of an organisation, from end to end or perimeter to perimeter.

The concept of Corporate Defensive Domain is an aid to perception evolving from a vision of Physical Risk through IT Risk, Operational Risk to Governance, Compliance, Legal and Reputation Risks.

Corporate defense
Corporate security is purely defensive. There is no moral imperative that allows positive attacking action against threats and those that attempt to, or unequivocally, inflict damage on your organisation. Some but not all, of these attacks can be very determined and sophisticated because they are goverment funded and are either commercially or politically motivated. Most are just motivated individuals that can be classed as intellectual vandals.

As with all the good guys, you must work within the framework of the law and this only allows vigilance, defensive action, and possibly post-event retribution and compensation. The subsequent capture and imprisonment of a perpetrator may become a public spectacle. An apparent show of the success of your strategy and hopefully it will act as an example to others but in reality it is of limited effect and brings little solace to the organisation.

Showing your hand
There is also a view that public trials act as a learning curve for other attackers. The attacker creates an action on your perimeter and you display a measured reaction. Thus revealing some of your defensive strategy, processes and tools.

Security realms
There are many realms that exist in the land of security e.g. physical, electronic, virtual, etc. and there are many ways to look at and examine security. It can be viewed as a) a physical obstacle b) a process inflicted on reluctant personnel without explanation or c) an acceptable mindset that is instilled in the environment with the full involvement of the personnel. This latter approach should produce the best results, giving staff a sense of involvement, empathy and a real feeling for the potential consequences.

Secure personnel
It is critically important that your staff buy into securing the corporate domain because they are typically, the weakest link in the security of organisations.

Staff issues
  • They are not so easily or reliably programmed,
  • They don't always retain or apply knowledge appropriately,
  • They are swayed and diverted by social engineering techniques,
  • They have good and bad days,
  • Their attention is inconsistent, etc.
  • Their human!
Threats & Vulnerabilities
There are many ways to examine Threats and Vulnerabilities in an organisation e.g. by geographical location, business type, resources used, historical or political instability, etc. Do you know and understand what criteria and imperatives are being used to drive changes in your defenses? Are they appropriate, operationally maintainable or cost effective.

Analyse the Risk

Organisations are are driven to respond to threats and are compelled to adopt more and more complex defense strategies to address and defend their security needs. Security policies and strategies dictate that a full gambit of approaches should be adopted, from standard process implementation to strict and intricate application frameworks but this has an operational and business cost implication.

The questions that are not always being asked are;
  • What is the real cost of defending your business?
  • How much are you likely to lose?
  • Where will the danger come from and in what form?
  • How will it impact us?
  • What is our response capability?
  • What is the overall Risk profile?
Feal the fear and hold your ground
With the constant threat of intrusion and compromise, regular and detailed testing and re-examination of all your defenses are necessary but before you can realistically and effectively apply what you have learned, you need to conduct a detailed analysis and assessment of the Risks, the potential business impact and your response options .

7 Points to build stronger, more secure Corporate Defenses
  • Create executive level authority and responsibility for Corporate Defense, policy and implementation
  • Assess your strengths and weaknesses using mature Risk management methodology
  • Examine the interdependencies between your tools, processes and defensive positions. Strengthen the perimeters and communications
  • Map and review your Corporate Defense Domain strategy, continuously, in a structured and determined manner.
  • Determine, test and examine areas of Convergence, for overlap and gaps. Establish strong boundary defenses and stringent hand-over criteria
  • Develop a single hardened core entity, an authoritative cross functional discipline, incorporating Governance, Compliance and Risk
  • Lock the perimeter gatesways, give the spare keys to your organisation to the central hardened core and prepare yourself for the next attack