Sunday, April 12, 2009

Risk Management; A mind set

To those who have not yet discovered it, security and risk management is a mind-set. When you go into a shop or restaurant, you may automatically check out the security and note where the exits are. If so, you will also check as to how secure the financial transactions are. How does the waitress handle the credit cards? How far the credit card machine is to staff and other customers. You will have noted the location of the security cameras, the lack of a security station or the location and the number of bouncers.

As a security and risk specialist, you will always be thinking about and assessing the security scenarios but not to exploit or take advantage of it but to be aware. You cannot switch it off, its the way you are. It is the same for members of the emergency services, never really off duty.

Security Compliance

If you have to consider a risk management approach to security compliance, as part of your many regulatory obligations, the best way to approach compliance is through risk. It is ineffective to focus on the bare minimum, just ensuring you are simply compliant. Threats and vulnerabilities are forever mutating, growing and changing. The bare minimum is not enough. This is the first principle of IT security and of risk-based IT management.

When looking at new applications, components, systems or architectures, check out the risks to your business and the risk to your core information. Those are the important things to note. You are concerned if it meets a line item associated with HIPAA and SOX.

Pattern recognition

The 'always on' risk management mind-set is always looking for patterns, checking out ways of doing rather than items on a regulatory checklist. You will look closely for items that pose a threat to your core assets, those that you are responsible for and have dedicated your reputation to protecting.

When somebody comes to you with a potential security problem, even if you know nothing about the particular system or application, you can assess it by the application of the risk framework and therefore formulate a validate set of pertinent and probing questions.

Secure games

Most security and risk managers live and breathe in a security mind-set, whether they are hardcore techies or recruits from the business side. The methodology they follow day by day at work is the methodology they live by, outside of work. Even at conferences, when they unwind afterwards with a soft drink, they invariably play a Where’s Waldo? version of security gaffes, competing to see who can spot the most security lapses. It can appear very weird and a little black, if you are outside the circle.

Nailed by the business

The mind-set can have its limitations and can be self-perpetuating. There is an old adage that says 'If you are a hammer, the whole world looks like a nail.' Indeed, when taken by surprise, the average security and risk manager is typically out manouvered by something that happens on the business side.

Good grief! Have they learned nothing? You can’t believe that the business would make such a decision. Just because you have a structured, risk averse and secure mind-set, you forget that 'normal' people don’t always think that way.

Damage control

What happens next is up to you. If the security has been jeopordised or the risks are too high then it is your task to get it back into line and put the geni back in the bottle. The fact is clear, you are dealing with consequences. The business has taken a chosen path and you have to control the damage, mitigate against it or make it right. After all, isn't that your job as security and risk 'support' person? In reality, you are seen by the business (suits) as being in the same category as the IT help desk and that is all you are.

Although it is accepted that the security and risk manager serves and protects the
organisation and its profits, until it can be unequivacally determined how you can directly make money and grow the profits for the organisation, you will always be considered as merely a supporting act. So, let's make up and get on with it! The show must go on!

Thursday, April 9, 2009

Zombies Ahead! Spooks in the machines!

An electronic road sign was hacked and changed, to alert drivers to the potential hazard of 'hoards of the undead' jaywalking. This provides a nice example of why the status of the security on the US Grid and associated infrastructure is such a “big deal”.

The hack itself is trivial: an intrepid individual discovered that electronic road signs shared a common default password. The good news is; that the default password would have been discovered and publicized years ago if the systems were connected to the internet. They were only left alone or overlooked, for years because very few people had the initiative or twisted interest, to walk up to one of the signs and attempt what is essentially a simple dictionary attack against the authentication mechanism.

Without the motivation and justification of protecting installations from sustained and multiple attack, engineers saw no reason to improve the security of their systems. Following the threat response reasoning, that defense is only required where attack is likely or where expenditure restrictions veto and supress security issues. (Discuss!) You could also argue that the lack of protection in certain areas forms part of the overall strategy of the threat and those that threaten.

It seems that everyone laughed off the hack as a simple prank, but failed to consider the serious implications and security problems that exist in systems that are legacy-based, semi-automated and semi-attached to the National grid.

There are a large class of systems that are semi-attached to the grid and they also have similar security problems and vulnerabilities. Known as SCADA (Supervisory Control And Data Acquisition) Systems, these computers are responsible for controlling electro-mechanical devices and physical plant as found in nuclear reactors and oil refineries.

Many of these systems were deployed years ago in simpler times, well before the information security industry fully understood code quality problems and how they can be and would be, exploited by attackers. These systems are only safe from exploitation for as long as you can guarantee a substantial air-gap or secure firewall between the control network and anything a human being can touch.

Serious Vulnerabilities

Spies and government sponsored hackers have already been probing the U.S. electrical grid for months and planting software that is intended to be activated at a future date, according to a Wall Street Journal. The report highlights the latest non-physical, indirect threats and vulnerabilities facing the U.S. power infrastructure.

The Journal notes that the spies are from China, Russia and other countries who are more openly threatening. While the news is very disturbing, it isn’t all that surprising. The vulnerabilities of the U.S. infrastructure are well documented. It is also notable that the electrical grids were initially thought to be somewhat hacker proof, until recently. Why? because the grids run on old legacy software, which is often proprietary. This it turns out is its greatest weakness, along with apathy and complacency.

The barbarians are not at the door but they may have remote access to your infrastructure and life support systems! Prepare to repel boarders!

Microsoft Security Intelligence Report - Extracts

Here’s a look at the five most important aspects from the full Microsoft Security Intelligence Report.

1. Vulnerabilities (the response and reaction to them) vary, depending on whether the target is at work or home.

Based on data provided by its enterprise Forefront Client Security and consumer Windows Live OneCare, Microsoft found that vulnerabilities are very different. Why? A corporate user may have email and Internet limitations that reduce the attack surface. A home user has more software tools to be infected but less critical data at risk.

Simply put, a home user is more likely to get hit with a Trojan attack to extract bank and credit card details, etc. In the enterprise, the weapon of choice is the Worm attack, which is primarily destructive and disruptive.

The greatest difference between enterprise and home vulnerabilities is social engineering. Microsoft explains:

  • The Windows Live OneCare list also includes several families associated with rogue security software, such as Win32/Renos, Win32/FakeXPA, and Win32/Antivirus2008.
  • The social engineering messages used in connection with rogue security software may be less effective in an enterprise environment, where malware protection is typically the responsibility of the IT department…
  • By contrast, the Forefront Client Security list is dominated by worms, like Win32/Autorun, Win32/Hamweq, and Win32/Taterf.
  • Worms rely less on social engineering to spread than categories like trojans and downloaders do, does and more on access to unsecured file shares and removable storage volumes, both of which are often plentiful in enterprise environments.

2. Users don’t always remove unwanted software: There’s great appeal to the procrastinator in the “ignore” button.

  • Microsoft explains one nuance of the malware issue:Software cannot always be classified in binary terms as “good” or “bad.”
  • Some software inhabits a gray area wherein the combination of behaviors and value propositions presented by the software is neither universally desired nor universally reviled.
  • This gray area includes a number of programs that do things like display advertisements to the user that may appear outside the context of the Web browser or other application and which may be difficult or impossible to control.

Microsoft’s scans allow users to ignore a security alert, allow software to remain, issue a prompt, quarantine or remove it.

If software is really malicious it is removed without user input. The gray areas appear when users have a choice.

Microsoft adds:
  • These decisions are influenced by a number of factors, such as the user’s level of expertise, how certain they feel about their judgment regarding the software in question, the context in which the software was obtained, societal considerations, and the benefit (if any) being delivered by the software or by other software that is bundled with it.
  • Users make choices about what to do about a piece of potentially unwanted software for different reasons, so it’s important not to draw unwarranted conclusions about their intent.

Moderate or Low threats are often ignored by users, who think that there’s value in the software. These threats are keepers based on user behaviour:

3. Rogue security software (Scareware) gains momentum.

The concept of rogue security software is pure genius. Malicious hackers prey on the fears of users, cook up bogus security software and extract payments to keep your PC running. Microsoft notes that rogue security software is becoming a hot category.

Microsoft reports:

  • Rogue security software authors have long attempted to exploit this trust by giving their programs generic, anodyne names, like “Antivirus 2009,” and making them resemble genuine security software in many ways.
  • Recently, many threats have taken this approach a step further, posing as components of the operating system itself or as a familiar search engine.
  • One of the first families observed to exhibit this behavior was Win32/FakeSecSen, which was added to the MSRT in November 2008 and was the eighth most prevalent family in 2H08 overall.
  • Win32/FakeSecSen adds an icon to the Control Panel named Vista AV or MS AV and fraudulently uses the same four-colour shield icon as the Windows Security Center. Double-clicking the icon launches the rogue software, which claims to detect a large number of nonexistent threats and urges the user to “activate” the software by paying for it.

Win32/Renos is a longtime threat that delivers rogue security software. It was the most prevalent threat in the second half of 2008. Two new trojans–Win32/FakeXPA and Win32/FakeSecSen were the seventh and eight most prevalent family class.

4. Social networking phishing attacks represented less than 1 percent of attacks, but yielded a big chunk of phishing impressions.

Translation: Social networking sites will remain a big phishing target.

Microsoft explains:
  • A typical social network phish is likely to trick an order of magnitude more users than a typical financial phish. There are a number of explanations for this discrepancy.
  • While financial institutions targeted by phishers can number in the hundreds, just a handful of popular sites account for the bulk of the social network usage on the Internet, so phishers can effectively target many more people per site.
  • In addition, phishers often use the messaging features of the sites themselves to distribute their attacks, typically by gaining control of a user’s account and using it to send phishing messages to the victim’s friends.
  • These attacks can be much more effective than e-mail–based attacks, because they exploit the considerable level of trust users place in their friends.

Take a look at:

And.

5. Malware is dominant in the U.S. and accounted for 67 percent of all infected computers.

Trojans—the miscellaneous variety–were detected on 29.4 percent of infected computers. Among other items:

  • Five of the top 20 families detected in the United States in Q3 and Q4 of 2008 (Win32/Renos, Win32/FakeXPA, Win32/FakeSecSen, Win32/Antivirus2008, and Win32/Winfixer) download rogue security software or display misleading warning messages to convince users to purchase a program that supposedly removes spyware.

Here are the top five individual threats:

Trojan downloaders and droppers were detected on 24.4 percent of all infected computers.

I trust this was of interest to you and you will see the sense of protecting your computer(s) with known and trusted anti Virus software as well as setting up a good Firewall and Intrusion detection. The rise and rise of Malware across the globe means that you will also need to protect your system(s) from this menace.

Do your research, read the reviews and never be the first to try any new protection software.

Tuesday, April 7, 2009

Should you be picking the low growing fruit

NOT SURE WHICH WAY TO TURN?

SHOULD YOU TAKE A LOWER PAID JOB?

When searching for a new job and the time starts to drag on and on, normally extending beyond three months, it is natural to begin to wonder if you should take a lower-level or lower paid job just to get some sort of paycheck again.

It's a sensible and an honest question but also a difficult one to answer. After working so hard to build a career and climb the corporate ladder, taking a step or two back, can affect more than your pride.

Some career experts will warn you against taking a lower-level job. They will advise you to hold out for a better offer that will better advance your career and not set you back a step, or three. Clearly, this is not an issue when you need a money to keep a roof over their head and food on the table. It doesn't matter what job you get, just as long as it's honest and helps pay the bills.

There is a strong argument that taking a lower-level job can be a smart career move, especially if it prevents you from being unemployed for more than 12 months, and with the economy as slow as it is, 12 months of unemployment is not unrealistic.

Its a simple but realistic outlook. You may want to consider positions at a level lower. You will increase your chances of getting a job sooner if you keep your options open and consider lower-level positions in addition to relocating and switching industries. This advice goes for executives too. There is an expression that says; 'A' class talent always rises to the top. Clearly, holding out for the perfect or even a comparable job opportunity in this economy may be even more risky than taking a step or two back.

Its OK to hold out for a perfect or promoted post for three to nine months. Even up to a year can be acceptable and justifiable, but if you're out of a job for 12 to 18 months, you're in danger of devaluing your skills and marketability. Today's business moves so fast and there are so many changes and new regulations, new laws and new competitors arriving on a 7-by-24 basis that being out of the market and out of touch for 12 or more months, is a big gap to jump.

The dilemma is; If you spent some of the time you were unemployed doing contract or short term consulting work would this mean that you were still in touch with the business world? Taking on short term and consulting projects definitely will help, for a number of reasons but it's important to take on projects that will help you gain the knowledge and experience that will help you get a promoted post. Also, employers tend to consider these projects as part of a job seeker's portfolio, if they are made aware of them by you.

The down side could be; If you, as an experienced executive, picked up a consulting contract managing a company's payroll, a prospective employer may not consider this as suitable experience, a diversion away from, and dilution of your normal key skill sets. Thus, they may look disfavourably upon your application as an IT executive. They may not think it was at a high enough level and would have preferred to see you working on a more strategic project.

In conclusion; Diversify by all means but be mindful of what contracts and consulting projects you take on. It may seem to contradict my earlier recommendation to seriously consider lower-level jobs, especially if money is tight but consider the circumstances well and do not forget the overall perception that may be given out by some positions, with respect to new employers. They may not see it as a positive move for your career.

Frustrated? Its not you, believe me!

Don't let it get you down! It's not you. It's the economy.

Remember, that what's happening in commerce and the world of employment in general, is a reflection of the overall slow economy and the safe measures being taken to reduce economic exposure and commercial risk. It's not a criticism or a commentary on you and your specific qualifications. You cannot stop the world going around each day, even if sometimes we get a bit dizzy from it. Don't take it personally.

Lots of highly qualified people are available on the job market and aren't getting responses to their résumés or callbacks for interviews, let alone job offers. It's not because you lack experience, good sense and credentials. It's not because you're doing something intrinsically wrong. It's the economy, so beating yourself up over the lack of progress you're making in your job search, is not going to help. In fact it will erode your confidence further.

Revitalize, don't reinvent. Job seekers may not need to "reinvent" themselves for today's job market. They may only need to "repackage" themself. A much more agreeable and achievable task.

Forget about the instant makeovers. These are for people who have something to hide. Companies need the experience and accomplishments you have earned over time. Leverage what you already have and focus on it, instead of what you fear you may lack.

This will go a long way toward helping you feel more confident about your experience, rather than makimg you feel old, tired and out-of-touch. (passed it and passed over)

Beware of getting suckered in by personality tuners and career coaches. When times get tough, the tough can be assailed by hype. There are good consultants out there that can offer to revise your résumé', put you in touch with the 'hidden job market' or coach you to become a newer, more marketable you but be cautious and keep your wallet closed.

Not all career coaches as snake-oil salesmen. They provide a worthwhile service, especially to people who have not been in the market for some time and need help with their communication and marketing skills. Good consultants' customers will vouch for them.

There is an old adage that says; Seduction trumps selling. The tight job market has made some job seekers overly aggressive. They think they need to hunt down and beat prospective employers over the head with their qualifications, and can resort to telling hiring managers that they are the "perfect candidate" rather than letting their experience speak for itself.

In business as in love, infatuation rarely develops into a long lasting relationship from being pushy or gushing out a soft schmoo routine. By all means explain and align, but resist the urge to exclaim and alarm. Let people reach their own conclusions about whether you are a potential world class employee or not, they will whether you like it or not.

Yes, by all means be different from the crowd. Stand out at the selection process but remember there is a narrow line between; very attentive and stalking, great enthusiasm and desperation, highly confidence and arrogance. As with meeting new friends and potential mates, do not be afraid to show some aspect of your vulnerable side and I don't mean walk with a limp.

Another big dilemma the job seeker faces is whether to take a lesser job that's a temporary fix, a stopgap. Some wil urge you to choose your next job wisely and not take stop-gap measures. In the real world, life and bills go on. People need to pay their mortgages and feed their families. I will cover some of this discussion in my next blog.

Re-thinking IT Security in tough times

The current economic downturn is forcing a corporate change and metamorphosis that, when combined with ever broadening security threats, presents information security groups with an opportunity to radically change their identity and add more value to the business.

To capitalise on the moment, security groups need to reassess their approach, add visibility and transform the very role of security.

It is good timing because maintaining security during tough economic times is critical. Besides external threats that evolve even more rapidly in economic downturns, business slumps increase the probability of disgruntled employees striking out using intimate knowledge of corporate systems.

Risk is further exacerbated by the fact that, since the last economic crisis of this magnitude, companies have become far more reliant on information technology systems, which are now highly complex and essential to sound operations.

Your current security path represents existing programs, capabilities, processes, etc. The goal is to create a parallel path that influences existing practices and allows you to refine a new strategy without disrupting current expectations. In time, the new path will become a dominating force and take you in a new direction.

Step 1: Tuning the Approach
During the last decade security has been virtually defined by compliance. For many companies, it has been less about security than it has been about ensuring that certain regulatory demands are being met. Unfortunately, compliance does not necessarily enable the business, align with core initiatives, and alone may not thwart debilitating attacks.

Understanding this, some security groups have strived to use compliance efforts to improve their security posture.

Unfortunately, not all companies see the value of such activities and instead simply see compliance as a cost of doing business.

You have to convert the security practices that fall under the banner of "mandated for compliance" into specific activities that resonate with the business. For example, a predominant force in business is time to market and the rapid conversion of investments to revenue generation. This can materialize as a new service, application, communication platform, network or alliance. The key to tuning your approach is to optimize security features to help the business move more quickly, reduce barriers or accommodate a requirement quickly.

Key to being able to accomplish this is institutional knowledge within the security group and leveraging and combining resources in ways that benefit the business as much as it does security, for example: supporting secure coding practices through collaboration with the development team, optimizing standard builds to stand up servers more quickly, security testing as part of performance testing, or utilization of directory services to support streamlining of access controls for a new partner.

Fundamentally, it is about operating in a risk/reward model. Prioritize activities based on risk as well as where the greatest opportunities are for the business. By becoming intimate with business goals and mapping against elements of risk, what begins to surface is a common thread that demonstrates a point where the business and security goals become more closely aligned.

A good place to start is within the project management arena, where risks to the initiative or life cycle will become apparent, in addition to helping identify critical paths and what is most important or critical to the business unit. By using information of this nature, combined with institutional knowledge that the security group possess, you can begin to interpret demands and risks in business initiatives and quickly find areas of common ground.

Step 2: Adding Visibility
Security groups typically make security efforts visible to executive management by presenting security metrics, risk dashboards, and the like. However, along the way, many encounter some key challenges.

The first challenge is that the measurements are only focused on security and typically do not provide insights to other aspects of security operations that demonstrate effectiveness. For example, a dashboard may present compliance risk, operational risk, technical risk and current threats. It is assumed that keeping the values in an optimal or desired range means that security is doing its job.

However, company executives are increasingly focused on efficiency, effectiveness and overall alignment to business initiatives. They want to know how well these objectives are being met, what influence they have had on other key business performance indicators (such as time to market, customer retention), and how resources and other valuable assets are being utilized.

Executives are concerned about inefficient or wasteful activities and want to ensure all activities focus on the bottom line. Presenting to the board a risk dashboard can be helpful to demonstrate your alignment to security concerns, but that's only one part of the equation in the eyes of executives. The more effectively security can reduce the need to translate security results into something meaningful for the business, the better.

The second challenge relates to the "gap" factor. The gap refers to the difference in what security is providing to executives as visibility and the ability for the security group to influence the system to enact change.

For example, a report may demonstrate that the number of vulnerabilities in Internet-facing applications is increasing significantly quarter over quarter. However, the security group may not have the capacity or capability to reduce that number to a reasonable value. As a result, some senior security managers find themselves tasked to correct an issue they simply do not have the ability to accomplish.

In short, information from the security program is misaligned with its ability. Some use this to justify investments that would address the gap. But unfortunately this pattern is growing increasingly ineffective as business owners demand more accountability. The solution is to create a security program that not only presents good and bad trends, but more importantly, has the ability to have a meaningful impact in changing them.

The challenges can be summarized as providing visibility into more than security in security terms, but also in a manner that is more readily digested by executives and easier to align to business goals. Secondly, build a security program that not only produces meaningful information relative to security and business metrics, but also has the inherent capability to institute change and thereby meet expectations.

Providing additional visibility to existing risk-based perspectives can be enormously valuable. To accomplish this, you need to become more intimate with what resonates with the executives -- the measurements they focus on day in and day out, the performance indicators they study beyond the financial ones. Each company is different and each business unit may have a different spin. Moreover, many may seem like the furthest thing from security, such as shipping metrics, warehousing, capacity indicators, system use or even collaboration indicators. You have to look behind these to begin to see where security can begin to mimic the same philosophies.

From a security perspective, look to report on areas within your domain of influence and help reflect how well you're running as a business. It can be as simple as resource utilization, project involvement or performance quality scores from your peers.

From there you can start tying to other reported information and trends, such as the planned decline in effort to perform regular vulnerability testing, but an incline in report quality and effectiveness, essentially demonstrating that you are meeting security and business objectives. Or show how, through collaboration activities (which have been measured) and modifications to technologies, you've helped reduce the number of security related helpdesk tickets. These are, of course very basic. Nevertheless, the point is to find related information between what you are doing for security and how well you are doing related to business expectations.

This approach helps form your new path for security, drawing from your original strategies and enhancing them. Start small, test the waters and seek mentorship within the organization. As more confidence grows in providing additional perspectives on activities, you can move into closing the gap.

Step 3: Service orientation
By this point you've learned how to orchestrate your core competencies to help the business reach its goals using a risk/reward method. And you've started experimenting with adding visibility to the executives on alignment. As a result, the identity of security is beginning to shift. It may not be obvious, but it's happening. However, this is a critical stage and the time to innovate. Once executives see something they like, they want more, expectations increase, and that "good job" turns into "what have you done for me lately?"

One of the common pitfalls is not following through to ensure a foundation exists to keep up with new expectations. As a result, massive ground is lost and you're back to square one.

Adopting a service orientation can help you continue to move forward. Service orientation has three primary objectives:

1) Convert tactical best practices that were once hidden within compliance efforts into business services that can be consistently utilized.

2) Close the gap between what you can control/influence and what you're reporting on.

3) Create a foundation for building a highly agile security approach.

The key is to learn from experimental practices in tuning activities and report on additional metrics and indicators relative to business goals. For the development of security services, it's the tuning of the approach that provides the information you need to get started.

In the most simple of definitions, a security service is a well-formed package of related processes, technologies and capabilities that has a predictable outcome that is needed or in demand by the business. What makes security services differ from traditional security activities is input.

Just about everything requires input to feed a process to produce an output. For security, the input is usually "self-assigned," meaning the business must meet a specific policy or some other documented requirement to have security perform an action. For example, a policy may read, "Any material change to an Internet-facing application requires a penetration test." That's a sound approach, but it's reactive and misses the opportunity to gain valuable insights to underlying business needs and goals.

While looking for risk/reward scenarios, you will see a pattern emerge and the tuning efforts outlined above should help you identify opportunities to incorporate specific business attributes into what you're performing.

The basis for security services is taking advantage of this pattern. In fact, you're doing this today to some degree. For example, an application is due for a test, but you've learned that the changes relate to one of several roles defined in the system. As a result, you may limit testing to that one area because of your knowledge and comfort with the application from previous tests. Now, extrapolate this to all things in security. It's less about simply doing what you do and more about giving the business additional opportunity to feed the process in order to refine the activity -- or service in this case -- to the business need.

The next important characteristic of security services is how people, processes, tools, methods and technology are architected to perform the service relative to input and output. This is a lot easier to say than to do. Organizations tend to approach these elements as independent or loosely coupled. Moreover, some security architectures and frameworks facilitate segmentation, making alignment of them seem alien and uncomfortable.

One challenge is internally developed standards that are either overly comprehensive or too granular. Successful implementation of security services typically starts with reviewing the standards and looking at them as a common foundation to services as opposed to specific elements for a given security function.

As with all things of this nature, a slow and methodical approach wins the race. Don't try to create a services model over night. Take what you've learned in tuning, couple it with something you're already doing today (such as vulnerability testing, patch management, identity management, data protection, monitoring), and then pilot a services approach with a friendly business unit.

As this approach begins to solidify, several interesting things start to happen. The identity of security and perceived value continues to shift in a positive direction. Nevertheless, you will quickly realize that you have far more capabilities to measure operational details of your organization, and more importantly -- you inherently have more influence over them as a result.

This essentially slams the door on the gap. Services facilitate the risk/reward model, they make it possible to organize activities specific to demand, provide the means to measure those activities more effectively, and allow for the controlled management of each element to ensure that what is being reported can be influenced. This can be a perfect storm, but you're not done. To truly transform, you have to close the loop with governance.

Step 4: Governance Loop
The "governance loop" is the final step and provides the opportunity to realize real transformation. To this point, you've tuned, experimented, tested and created the early stages of services and are beginning to rely on the new path and less on the old one.

This has helped increase visibility, initial alignment to the business and promotes effectiveness. Nevertheless, at this point, time becomes your enemy -- without governance, the services will eventually break down. Governance, interestingly, provides the mechanism to ensure expectations are being met, but also the means to promote adaptability, closing the loop with the business.

Governance acts as the bonding agent between ebbs and flows in the business, compliance, risk and security activities. More importantly, this is where risk/reward is measured and fed back into the system to instigate change. It is also important to realize that risk (management, assessments, reporting) has played a pivotal role throughout the journey, and governance is the means to realize full potential. Risk remains at the top of the pyramid, but now with services underlying it, supported by governance, it can move far closer to the business.

In short, governance is analogous to "inspect what you expect" and influence change. That means creating a set of responsibilities and practices with the goal of providing direction as well as ensuring objectives are achieved and resources are used responsibly. In so doing, measurements from the oversight of security not only ensure efficient and effective execution, but also facilitate change in the program through intimate connections with risk management and the business offering feedback into the system.

In some companies governance is associated with enforcement. Although partly true, a security group empowered by services and close interlinks with overall enterprise governance through risk management activities will be able to put governance to work for them. This is similar to how, over the last several years, many security organizations have changed their perspective of the audit group.

Historically seen as a regular and painful exposure of operational weakness in security, audit processes are now being seen as a way to strengthen security. It's turning what is usually thought of as a negative into a positive force. The same is true with governance processes that are outside of the control of the security group or where security is part of a governance committee.

Nevertheless, an important aspect is to understand that the security group is ultimately responsible for its activities -- good and bad. Therefore, it is recommended that governance be reflected in the security services and program owned and operated by management resources within the group. This is not a replacement for enterprise governance -- rather, it's an extension focused on the betterment of security.

Organizations need security more now than ever, and as a result, are more receptive to security as a community. What you do with that attention today could have enormous influences on the future of security within your company. Although times are tough, don't assume this means opportunities don't exist. The economy will correct itself and businesses will emerge stronger and with a new sense of determination and demands for operational maturity. Taking advantage of what appears to be short-term focus on security for long-term gains is the crux of the opportunity, and opportunity favors the prepared.

This article is by James Tiller, author of The Ethical Hack and Technical Guide to IPSec VPNs, and contributing author on several other books, including the Official (ISC)2 Guide to the CBK, is vice president of security services for BT in North America. He consults with organizations globally on how security can enable business. You can reach him at james.tiller@bt.com.

Wednesday, April 1, 2009

Doing Less With Less leads to less












Where do you stand in today's market? and who's standing there with you?


Now that your company has fashionably reduced its staffing levels and you have survived the axe, are you being asked to do more with less, in the wake of these layoffs?

Yes you say, but are you actually doing more? I'm sorry but the real answer is; probably not. According to a US survey conducted in December by Leadership IQ.

When the US research and training firm polled 4,172 workers at 318 companies that had recently laid off employees, 74% of the people who responded said their own productivity has declined. Other findings:
  • 87% of surviving workers said they are less likely to recommend their organisations as good places to work. (Quelle surpris! This is a sign of a badly handled layoff)
  • 64% of surviving workers said the productivity of their colleagues has also declined. (The bad layoff was indicative of poor management motivational skills in the company)
  • 81% of surviving workers said the quality of service that customers receive has declined. (This should have alarm bells ringing! This way, monsters lie!)7
  • 77% of surviving workers said they see more errors and mistakes being made. (Realistically, they may be looking closer, with a more critical and negative attitude or have access to more info through expanded roles)
  • 61% of surviving workers said they believe their companies' future prospects are worse.

This summary is probably correct, if their customers are sensing negative vibes and are experiencing reduced service, in today's buyer's market. Staff and management should be made aware that they have a vital role to play in convincing customers that there is value to be had by maintaining their loyalty.

Loyal customers and repeat business should be cherished, protected and sustained through innovation and strong management.

If the company has implemented reduced staffing levels without refreshing the management team, its motivation and its attitudes, then the only changes they will need to manage are the shrinkages of its customer base, the obsolescense of its products and services, with the subsequent failure of the whole lame duck enterprise.

Do not mistake Movement for Action