Security Still an Issue in Cloud Development Projects
At a recent conference, IBM and Amazon executives debated one of the biggest issues around the cloud - the extent to which users can rely on security built into the services of the provider. Amazon made the point that users should recognize that they are moving into a platform with a lot of security already built into it. IBM countered with the point that you can't rely on that - that each user and each applications contains its own needs and issues.
Both are right. There is some security there, but users need to go some steps further in order to make sure the security meets their needs. This might involve obtaining SSAE 16 reports (the old SAS 70), but should probably go further than that and include a through review of the security structure to make sure that it is adequate. That means involving the auditors in the development process - an old saw, but still a true one.
Here's a report on the debate at the conference.
Technology, security, analytics and innovation in the world of audit and business.
Thursday, October 20, 2011
Thursday, October 13, 2011
Security Professionals Face Serious Challenges
Recently, the International Information Systems Security Certification Consortium, Inc., (ISC)² sponsored a study carried out by Frost & Sullivan of more than 10,000 security professionals around the world.
Some of the key findings of this study can be summarized as:
- Application vulnerabilities represent the number one threat to organizations.
- Mobile devices were the second highest security concern for the organization, despite an overwhelming number of professionals having policies and tools in place to defend against mobile threats.
- Professionals aren't ready for social media threats.
- A clear skills gap exists that jeopardizes professionals' ability to protect organizations in the near future.
- Information security professionals weathered the economic recession very well.
- Cloud computing illustrates a serious gap between technology implementation and the skills necessary to provide security.
- Developing countries illustrated opportunities for growth with an experienced and more educated workforce.
- The information security workforce continues to show signs of strong growth.
The study can be downloaded free of charge from this website.
Friday, October 7, 2011
Web Application Security: Business and Risk Considerations
ISACA has a White Paper on its website with the above title. The paper is an excellent resource for those interested in cloud risks and how to address them. That includes a lot of people!
One of the interesting parts of the paper is the table listing the various types of vulnerabilities encountered in the cloud. These include SQL Injection, Cross-site scripting and Insecure Direct Object Reference, among others. The paper goes on to list some areas of security to focus on, including some specific guidance on the old stand-by's of executive support, training and support.
The paper concludes with assurance considerations, including the use of Cobit to strengthen controls.
An excellent paper. You can download it through this link.
ISACA has a White Paper on its website with the above title. The paper is an excellent resource for those interested in cloud risks and how to address them. That includes a lot of people!
One of the interesting parts of the paper is the table listing the various types of vulnerabilities encountered in the cloud. These include SQL Injection, Cross-site scripting and Insecure Direct Object Reference, among others. The paper goes on to list some areas of security to focus on, including some specific guidance on the old stand-by's of executive support, training and support.
The paper concludes with assurance considerations, including the use of Cobit to strengthen controls.
An excellent paper. You can download it through this link.
Tuesday, October 4, 2011
Social Media's Growing use for Cyber Crime
The FBI recently issued a report pointing to the growing use if Social Networks for criminal purposes. The report points to the traditional techniques of Phishing and Data Mining of Social Media sites as continuing serious problems. The report also points to the use of false persons being used to attract honest site users and therefore gain access to information that could be sensitive. Examples are setting up phony Facebook accounts to attract military personnel and then extract information they might have or information about their location.
Of course, corporate information could be at risk in such scams, and it is important for companies to have tightly drawn policies on the use of social media by their employees. One of the difficulties in such policies is that a company cannot interfere in the personal life of their employees, yet they can be duped through their personal activities into revealing sensitive information. A clear demarcation between business and personal use of social media is nevertheless a critical element of a security policy.
For more on the FBI report, see this link.
The FBI recently issued a report pointing to the growing use if Social Networks for criminal purposes. The report points to the traditional techniques of Phishing and Data Mining of Social Media sites as continuing serious problems. The report also points to the use of false persons being used to attract honest site users and therefore gain access to information that could be sensitive. Examples are setting up phony Facebook accounts to attract military personnel and then extract information they might have or information about their location.
Of course, corporate information could be at risk in such scams, and it is important for companies to have tightly drawn policies on the use of social media by their employees. One of the difficulties in such policies is that a company cannot interfere in the personal life of their employees, yet they can be duped through their personal activities into revealing sensitive information. A clear demarcation between business and personal use of social media is nevertheless a critical element of a security policy.
For more on the FBI report, see this link.
Wednesday, September 28, 2011
Smart Phone Security
Now that smart phones are being used more often for sensitive uses, like making and paying for purchases, it is clear that hackers are going to focus more attention on smart phones. companies like McAfee are putting out security software to protect them. And the US Department of Defense is calling for more protection for them and in particular for the Android Operating system, which is on the largest number of phones.
Companies need to be concerned about this area, as some of their sensitive data is going to end up on smart phones, so their defences need to extend to the phones. This is not a new idea, but the new landscape means that the degree of protection now needs to be at a level comparable to that of the corporate data in the main system, which has not been the case to date.
For more on the new environment for smart phones, check this NY Times article.
Now that smart phones are being used more often for sensitive uses, like making and paying for purchases, it is clear that hackers are going to focus more attention on smart phones. companies like McAfee are putting out security software to protect them. And the US Department of Defense is calling for more protection for them and in particular for the Android Operating system, which is on the largest number of phones.
Companies need to be concerned about this area, as some of their sensitive data is going to end up on smart phones, so their defences need to extend to the phones. This is not a new idea, but the new landscape means that the degree of protection now needs to be at a level comparable to that of the corporate data in the main system, which has not been the case to date.
For more on the new environment for smart phones, check this NY Times article.
Thursday, September 22, 2011
Security Breaches are Becoming a Certainty
It has become clear, with the growth in use of the internet, mobile devices and social networking, that avoiding security incidents has become more difficult. Recent research, however, shows that they are a near certainty.
"A recent survey by the Ponemon Institute found that the threat from cyber attacks is nearing statistical certainty -- 90 percent of U.S. businesses were hit by at least one security breach in the last 12 months. Almost one in two said there was a significant increase in the frequency of cyber attacks over the past year, and 77 percent said attacks are more severe or difficult to contain."
For more, check this link.
It has become clear, with the growth in use of the internet, mobile devices and social networking, that avoiding security incidents has become more difficult. Recent research, however, shows that they are a near certainty.
"A recent survey by the Ponemon Institute found that the threat from cyber attacks is nearing statistical certainty -- 90 percent of U.S. businesses were hit by at least one security breach in the last 12 months. Almost one in two said there was a significant increase in the frequency of cyber attacks over the past year, and 77 percent said attacks are more severe or difficult to contain."
For more, check this link.
Friday, September 16, 2011
Persistent vs Intermittent Attacks
"Researchers at North Carolina State University examined two Wi-Fi attack types -- persistent attacks, in which the attack persists non-stop until it can be identified and disabled, and intermittent attacks, which block access on a periodic basis, making them harder to identify and stop. They were able to measure the impact of both attacks."
They concluded that all attacks cannot be prevented and that a sensible policy would be to target those that would cause the most damage, which often would be the persistent attacks.
for a release on this study, check this link.
"Researchers at North Carolina State University examined two Wi-Fi attack types -- persistent attacks, in which the attack persists non-stop until it can be identified and disabled, and intermittent attacks, which block access on a periodic basis, making them harder to identify and stop. They were able to measure the impact of both attacks."
They concluded that all attacks cannot be prevented and that a sensible policy would be to target those that would cause the most damage, which often would be the persistent attacks.
for a release on this study, check this link.
Subscribe to:
Posts (Atom)