Including Corporate Secrets in Risk Analysis
Companies usually have secrets that are valuable to them. Coca Cola's recipe, for example. Or earnings projections. This can be distinguished from custodial information, such as payroll data. In a new RSA study, the relative worth of corporate secrets is examined and the attention given to them by corporate security programs is measured. It was found that companies pay less attention to secrets even though they are generally worth more to the company than private custodial data. The research points the way to a different focus on corporate risk analysis. For a download of the paper, click this link.
Technology, security, analytics and innovation in the world of audit and business.
Wednesday, June 16, 2010
Monday, June 14, 2010
Passwords May Actually Compromise Security
A new Study presented at Harvard's "Economics of Information Security" workshop last week shows how passwords can compromise security. They point out that people often re-use passwords and that hackers can obtain the passwords often kept in plain text for low value sites. Some users use the same passwords for their high value sites, like Paypal and internet banking.
The study also points out that there are better ways of securing data now, such as more-secure protocols or federated identity systems but that people expect passwords, so they have a psychological value. The study is an insightful look at passwords. Companies should be looking at better ways to establish security, as there is increasing evidence that passwords don't work well. For a summary of the paper, see this article.
A new Study presented at Harvard's "Economics of Information Security" workshop last week shows how passwords can compromise security. They point out that people often re-use passwords and that hackers can obtain the passwords often kept in plain text for low value sites. Some users use the same passwords for their high value sites, like Paypal and internet banking.
The study also points out that there are better ways of securing data now, such as more-secure protocols or federated identity systems but that people expect passwords, so they have a psychological value. The study is an insightful look at passwords. Companies should be looking at better ways to establish security, as there is increasing evidence that passwords don't work well. For a summary of the paper, see this article.
Thursday, June 10, 2010
Spreadsheet Risks
Everyone knows of the risks involved with the use of spreadsheets within information systems. Not only are there known risks but it is difficult to control them, since many spreadsheets are used by individuals who are operating outside of an established control structure - or to put it another way, established control structures usually don't cover spreadsheets.
There is a European site which addresses the risks of spreadshseet usage, and offers up some useful topics of discussion and useful tools. Its worth a look.
Everyone knows of the risks involved with the use of spreadsheets within information systems. Not only are there known risks but it is difficult to control them, since many spreadsheets are used by individuals who are operating outside of an established control structure - or to put it another way, established control structures usually don't cover spreadsheets.
There is a European site which addresses the risks of spreadshseet usage, and offers up some useful topics of discussion and useful tools. Its worth a look.
Tuesday, June 8, 2010
The Deepwater Horizon Disaster - Lessons for IT Risk Management
It is an understatement to say that the BP Deepwater oil spill is a major disaster, for the people in the area, for the environment and for BP itself. While we are a long way from having a clear understanding as to why it happened, there is growing evidence that it could have been prevented if more effective safeguards had been put into place in the beginning,. We see this happening often in the IT world, where major projects are taken on, management pushes for it to go live without adequate attention to the risk management aspects and then things go wrong.
There is a strong likelihood that the Disaster will bring down BP as it has already involved a loss of lives and brought down the economic futures of so many people.
It is a risk management failure of the first magnitude and it points, even this early, to several clear lessons for managements. For one thing, there is a need for a business to organize itself so as to give some clear clout to the risk management functions within its team. This means more than giving nominal titles to those people, but rather meaningful means of enforcing their will on overly keen managements when major projects are under way. Separate public risk management reports would be helpful. It also would be useful for companies to combine their risk management functions for IT and the rest of the organization. IT is getting increasingly difficult for many companies to separate them anyway. And the established expertise of IT risk management personnel would be a help. Some companies have done this, but many have not.
With the scale of major projects taking place in the world today, and the potentially disastrous effects of failure, there needs to be a substantial ramping up of the importance of the risk management function within businesses. The professionals are available for this purpose. We should use them. For an article on the BP Deepweather Risk Management click this link.
.
It is an understatement to say that the BP Deepwater oil spill is a major disaster, for the people in the area, for the environment and for BP itself. While we are a long way from having a clear understanding as to why it happened, there is growing evidence that it could have been prevented if more effective safeguards had been put into place in the beginning,. We see this happening often in the IT world, where major projects are taken on, management pushes for it to go live without adequate attention to the risk management aspects and then things go wrong.
There is a strong likelihood that the Disaster will bring down BP as it has already involved a loss of lives and brought down the economic futures of so many people.
It is a risk management failure of the first magnitude and it points, even this early, to several clear lessons for managements. For one thing, there is a need for a business to organize itself so as to give some clear clout to the risk management functions within its team. This means more than giving nominal titles to those people, but rather meaningful means of enforcing their will on overly keen managements when major projects are under way. Separate public risk management reports would be helpful. It also would be useful for companies to combine their risk management functions for IT and the rest of the organization. IT is getting increasingly difficult for many companies to separate them anyway. And the established expertise of IT risk management personnel would be a help. Some companies have done this, but many have not.
With the scale of major projects taking place in the world today, and the potentially disastrous effects of failure, there needs to be a substantial ramping up of the importance of the risk management function within businesses. The professionals are available for this purpose. We should use them. For an article on the BP Deepweather Risk Management click this link.
.
Friday, June 4, 2010
Attacking RFID Chips
There has been much attention given in recent years to the question of the security risks of RFID chips. The Canadain Privacy Commissioner has come down hard on them. Corporate IT Security personnel have been searching for ways to make them more secure.
The security of RFID chips is important because they are so pervasive and often contain private or sensitive information. Even information such as product prices can be critical to secure, because of the need for intregrity of the information used in processing sales.
So a thorough review of the security risks of RFID chips as well as the methods intruders might utilize in attacking them, is very timely.
Such a review is found in the article "Attacking RFID Systems" by Pedro Peris-Lopez, Julio Cesar Hernandez-Castro,Juan M. Estevez-Tapiador, and Arturo Ribagorda.
The article is comprehensive and covers a range of methods that could be used by hackers to attack RFID chips. Very useful.
There has been much attention given in recent years to the question of the security risks of RFID chips. The Canadain Privacy Commissioner has come down hard on them. Corporate IT Security personnel have been searching for ways to make them more secure.
The security of RFID chips is important because they are so pervasive and often contain private or sensitive information. Even information such as product prices can be critical to secure, because of the need for intregrity of the information used in processing sales.
So a thorough review of the security risks of RFID chips as well as the methods intruders might utilize in attacking them, is very timely.
Such a review is found in the article "Attacking RFID Systems" by Pedro Peris-Lopez, Julio Cesar Hernandez-Castro,Juan M. Estevez-Tapiador, and Arturo Ribagorda.
The article is comprehensive and covers a range of methods that could be used by hackers to attack RFID chips. Very useful.
Thursday, June 3, 2010
The Hazards of ERP Implementation Consulting
Marin County, California has launched a legal action against Deloitte, alleging that the latter misrepresented their knowledge of SAP and failed to deliver on their contractual obligations. Deloitte, on the other hand, says the system was working properly when they finished their assignment and that they met all their contractual obligations. Which one has the strongest case will be determined in the courts. However, the case points to the difficulties of ERP Consulting. Very complex, time consuming and difficult to measure the outcomes. The time and resources to complete the implementation are often under-estimated. Here's an article on the legal action.
Marin County, California has launched a legal action against Deloitte, alleging that the latter misrepresented their knowledge of SAP and failed to deliver on their contractual obligations. Deloitte, on the other hand, says the system was working properly when they finished their assignment and that they met all their contractual obligations. Which one has the strongest case will be determined in the courts. However, the case points to the difficulties of ERP Consulting. Very complex, time consuming and difficult to measure the outcomes. The time and resources to complete the implementation are often under-estimated. Here's an article on the legal action.
Wednesday, June 2, 2010
Learning From Service Failures
Not many professionals write about their failures, but Gene Marks does. He runs a small IT consulting and advisory company and is brutally honest about his client service failures. They are failures most IT professionals encounter from time to time, and - truth be known - a great many IT professionals have at one time or another been responsible for. Knowing when to speak out about such matters as putting the wrong person on a job in time to prevent the damage is a skill often born of experience. Same with knowing the value of firm quotes given up front to a client.
Marks' article, linked here, is good food for thought for all IT professionals out there. Learning from past mistakes, whether ones own or the mistakes of others is a necessary part of growing.
Not many professionals write about their failures, but Gene Marks does. He runs a small IT consulting and advisory company and is brutally honest about his client service failures. They are failures most IT professionals encounter from time to time, and - truth be known - a great many IT professionals have at one time or another been responsible for. Knowing when to speak out about such matters as putting the wrong person on a job in time to prevent the damage is a skill often born of experience. Same with knowing the value of firm quotes given up front to a client.
Marks' article, linked here, is good food for thought for all IT professionals out there. Learning from past mistakes, whether ones own or the mistakes of others is a necessary part of growing.
Subscribe to:
Posts (Atom)