Is having an information security management system equal to actual security?
Having an information security management system is not an indication
of quality of security controls. Management systems are easier way of
administration in a standard and systematic way, but they do not
necessarily an indication of security control effectiveness.
an example, ISO 27001 as one of the most popular information security
management system to date, has no effect on the quality of your
controls, as there is no judgement on implementation quality,
effectiveness and type of security controls. It is just the judgement of
is no surprise though comparing to any other management system like ISO
9001 famous Quality where you can find thousands of firms holding to
that certification with lowest quality of products. You will find same
number of firms holding tightly to their ISO 27001 certification as an
indication of “presence of quality security” but literally are at the lowest bracket of information security effectiveness in practice.
say one has a system to fully manage firewall within an enterprise, all
the rules are justified, reviewed and approved by head of your
technology department (which FYI you could barely find such a
well-managed system, but still let’s pretend it’s not a big deal). Does
it mean firewall rules are technically security and configured in a way that address organization concerns?!
an information security management system, whether globally recognized
like ISO 27001 or organically internally created by your organization
could be the best tool to approach your security program; it is all
about execution and understanding of information security elements
‘particularly in regards to your business’.
The simple sign is your Trust and Confidence: Do you have faith in your security program?
a moment be honest and ask yourself: am I confident with my company
security program? Do I have faith in our security team? Do they really
know what they are doing? Does my information security officer worth pay
300 grands? How can I say my IT department is really at the top of
security trends? Ami paying too much or less for security budget?
Why I Do Not Trust in My Security Program?
your answer to any of above questions is shaky, you hesitate to answer,
or just do not know that answer, or for any reason you are not sleeping
peacefully at night, then your security program already failed!
Has Your Security Program Stuck?
But that is not your fault directly, not even your team, no one to blame from your side! The only thing to blame is “market”. Unfortunately,
market pushes you and many top managers of security teams within big
corporations to spend money on things that would not improve the
security posture, otherwise you would sleep peacefully just like those
who do not have any online presence.
pushes us to spend and at the same time not have a peaceful mind; today
is about a new trend, tomorrow even before catching up with yesterday
“message” you attend a webinar and you face a new challenge, all true,
but all irrelevant.
Why with hundreds of thousands spending on my cybersecurity initiatives, still I do not feel confident?!
or your technology team do not have even enough time to catch up with
emails and whitepapers full of useful info, let alone choosing and
implementing what exactly you’re looking for. Even a week after
implementation you realize there was better solution or you wish you
would purchase another solution or just waited one week to buy the new
one just arrived at your mailbox!
familiar? Then you are not alone among majority of information security
managers, engineers and architectures. Simply blame the “market”!
Market is constantly pushing us to spend and still not being confident.
Does it sound like something wrong? There has to be a different way. It
does not make sense; it is not that much complicated!
The trick is simply getting
out of this sanity and leave the market flow and pass you! You won’t
lose anything, do not worry. Step back, stop, relax and research more.
There are very simple ways with less effort and less budget with more
confident outcome. Simpler than you could imagine!
Real hackers do not randomly find a flaw in a system. There is a systematic approach to hack a system!
Regardless of size and type of an online entity and its online presence, a giant company with ten thousand of employee, or a home user of the Net, the only reason a system (may) have not hacked or taste the bitter part of internet is because it has not been targeted!
Hack proof, and resistance…are you kidding? systems are mainly vulnerable to basic penetration testing! A system enough mature to resist targeted attacks is literally a piece of “Art of Security Management” rather than a collection of sophisticated security tools or staff.
Once you are targeted you could truly measure the strength of your security measures and experience shows that we could barely stay safe after being actively targeted. However, targeting process may take years but once a malicious actor put your name on the list, you need to find way to response and faster ways for recovery.
I am not considering persistent threats where you have been hacked for years before even you realize. Remember, not all malware activity is supposed to be noisy and obvious. Hence, targets remain totally open to adversaries for months and years before they could even detect anomaly so let’s talk about hidden-side of being victimized and APT later.
What does it mean to be targeted?
It is not as simple as it sounds but briefly, it means adversary simply profiles you/your business for a relatively longer time and uses every aspect of your online presence to have what I call BB or brighter blueprint of a cyber entity.
Attacker creates an enhanced “vision” of a cyber target and s/he uses every single direct or indirect possible object to picture the target. At the end, or somehow in the middle of this process, attackers know your system way better than yourself! And that’s where they land the attack. The result depends on the purpose and motivation, could be destructive or hidden with minimal impact which is scary because then they nest somewhere within your system as long as they need.
The truth is, if a system has not been hacked, that’s not because it has a solid security posture, it is only because it has not been targeted.
Sales pitch force us to worry about things that are not so important; Change your mindset to win the battle!
“Battle” would not be the right term if we didn’t have a market full of competition to sell cybersecurity products rather than focusing on the right and real way of defense. In other words, focusing of what really cyber criminals are up to, rather than pretending that we are securing our networks!
So let’s admit it is actually like a battle ground when sales guys reach out to you and want to convince you to accept a risk they are anticipating with your business and you have this relation with a dozen of firms out there and literally everyone says: all other products are crap, ours is so and so! And in the meantime, you are in a real unfair battle with cybercriminals where you’ve never been able to catch up.
We do not need to be part of this battle, but it is only possible by changing mindset and direction! I know it is so hard and even scary to go a different direction when all the market trends are pushing you to believe something else. I know it sounds insane to forget about EDR when all pros say it’s a panacea, it scary to uninstall Application control or whitelisting solution from your server. Should you avoid and ignore critical patches? Would it be madness to forget about dual-factor authentication and not having a PAM solution, especially when you have money and human resources to spend on these?
Any solution may or may not fit to your business but cybersecurity is not all about implementing new solutions, what if I tell you that you could still be incredibly secure with the same sort of security products in 90’s?!
The first step to win the battle with both sides of adversaries and sales is just to change the focus from being tools-oriented to rely on techniques, from implementation of new solutions to find the solution natively in your systems. I am not talking about native security tools of any OS necessarily; I am diverting your mind to a totally different world where understanding and picturing your cyber security posture automatically brings the solution with itself!
Real issues are not going to be solved bY any of those known internet applications!
Currently it does not but technology could solve our problems if two factors considered:
Definition of ‘Problem’
Justifying practical ‘Application’
The former seems so obvious but that is actually the root cause of why technology is not able to solve our problems. You see how major aspects of technology are focused on ‘things’ that are neither a problem, nor an issue, or even a basic consideration.
Internet does it really justified to solve our problems? The answer is no because first we are misleading ourselves with unreal problems and things that are more wanted than needed, and more a matter of convenience than a matter of reasonable living.
As an example, transportation, social media, advertising… even fast communication are not real issue. Comparing to other side of same stories like fossil fuel, introversion and lack of communication. When you do not have transportation, focusing on Uber and Lyft is more insulting than funny. When people are getting more and more introvert, talking about your virtual friends is ridiculous. When delivery of an important message to appropriate people is being distracted by many political and ethical issues, focusing so much on advertising is like ignoring the entire word of ‘humanity’.
internet does not really justified to solve our problems
You see that definition does matter because if the problem was really how you could faster load facebook pages, or how to have a video with more viewers on YouTube, then yes, all those internet trends and application would frankly be toward solving our issues. But the real deal is different, and that’s why most of internet applications are going wrong direction.
Real problems are food, drinking water, population, education, diseases…but not how many restaurants have online vitrines, or how fast and convenient you could order pizza online, or millions of recipes in a PDF…the problem is providing enough resources for a billion of people in lack of basic life resources.
Enough food for one in nine people on earth just to make sure that they can function. Fighting against global water and waste crisis. Eliminating the risk of malaria to half of the world’s population. Taking care of millions of people with at least one sort of dangerous addiction. You can name it.
After you believe in real problems of today’s human on the earth, you’ll see how technology is far from helping us to solve those issues. Thousands of scientists all over the world are committed to solve our real issues, but that number is way less than hundreds of millions of people focusing on unreal aspect of life.
Conquering space for search of what we call inevitable for life, H2O, while we do not have the basic water treatment and culture of consuming drinkable water sounds very naive. Every day we make thousands of chemicals and medications for weight loss while a billion of people do not have enough food to function. We develop all sort of online applications but it’s like all of us are blind and deaf, we can’t see, we can’t hear what is going on before our eyes.
Technology is actually so capable of resolving our real issues. Let’s define and review and digest today’s issues and force technology to handle them for us. Not a cybersecurity professional, or a programmer, but as a human, that is my career to help technology solve human real problems with practical cheap solutions.
Operations fail by focusing on tool rather than technique!
In context of information technology, with all primary operations like system administration, patching and updating, backup and replication, malware protection…and all related sub-tasks, focus on Tools is an enemy of the process!
Defining, developing or choosing a technique in advance is crucial to an IT operation. Then finding a tool to do whatever the technique is dictating, not vice versa. Techniques are also backed up and rationalize by objectives and policies but that is out of scope of this article.
Techniques → Tools
That is the right flow chart: reaching device, gadget, program, software, application, script…or anything like that only after knowing the method or routine. In other words, we need to define the way we want to do something (process) and what is required (features) and then go after shopping or writing a code to handle that.
Many IT operations fail due to doing this simply in reverse direction: finding a tool just by searching the Subject and then refine the “forced” process based on what tool is dictating, not what we were expecting. Well, sometimes there is no expectation at the first place which is sign of a immature IT practice but that is also behind this short article.
Everybody’s talking about importance of physical exercise and routine workouts these days, and of course that’s the result of 21st century life-style which is forced through technology but how about some technology exercises and routine practices which can help reduce the pressure on tech staff workload and leads us to a healthier IT environment?
It will be so easy documenting and actually using it as a powerful tool and a supportive factor in everyday IT dynamic environment. But Only once we realize the application and purpose behind it in addition to simple techniques.
Most of us see Documentation as a hassle, an extra useless job of writing some staff on paper or Word and Excel files, and give a version or revision number, control it (what does it mean exactly?)… and then live it dusty chest or even ends up with some nonconformity because it is not what a reflection of our real world processes…..what is the purpose? why people see this as a hassle and this way it is actually a negative workload. Rather than utilizing it, that utilizes our resources!
The reason task of “documenting” has seen and believed to be a bother for most of IT professionals or even business analysts, is that we are doing it wrong, so no doubt it utilizes resources without any value. The easiest way to describe what is right documentation is explaining what is not. first you should ask:
What is going to be documented and for what reason
If reason is justified as a “Management System”, or “Standard”, or “Certification” then the answer is wrong and you are going the wrong way. You should justify by reasons like: “part of manufacturing process”, “describing system of asset management”, “explaining why product X failed during evaluation”, “document of how an employee is hired”, and so on. But never have the Driver as the Reason.
Documentation is not complicated but just like any other skill, first we need to understand the concept, and then some practice. Mastering this skill would not take more than 1% of your daily duties so let’s see what is the heart of the matter:
Document the logic and purpose of a task or subject rather than describing details of a task. In other words, focus on goal rather than the task. This saves a lot of time wasting on useless information in documents. This is also one of the main reasons users later won’t refer to documents. So we waste time creating them and then force the audience to read but they won’t because content is boring, confusing and only waste of time; no added value or even negative value.
Screenshots and steps to do something is not usually what documentation is all about. That might be useful for a user manual (I would doubt!) but not as an option for an IT guideline or even procedure, work instruction or policy. Here’s an example:
Let’s say you want to document your backup process, Disaster Recovery Plan, malware response and handling procedure, or how a node is setup and connected to a system in another network segment, how anti-virus agent is deployed….and thousands of other scenarios. Now would you open a Word file and start capturing screenshots of each step?!
It means you might doing in right way if that sounds funny to you, but most IT personnel are so busy that they don’t have time to step back and think about the way things have been done Wrong in the past, and they just repeat the same tools and techniques
Benefits are endless, and the result which is an agile environment will be appealing!
Once documenting become a routine and as a regular exercise the benefits start to show off their positive effects in environment:
Less time spending on Documentation! More effective and useful documents!!
Effective corporate communication and team elaboration
Compliance management in a controller manner
Certainty and confidence in changes: an strong and original strong change management
Faster, accurate and more effective and meaningful evaluation of future solutions. In other words, re-born of R&D within IT operations which I believe it has been totally forgotten in the fast paced today’s tech world
Smooth transition among staffing, team leadership and general daily administration
Audit and being audited any time with zero nonconformity or noncompliance
Better understanding of current processes and natural automatic and constant training for tech staff and end-users
Trustworthy IT team with reasonable full support from top management
Smarter internal and external customer relation and interaction
Reduced or almost zero anxiety among help desks and system administrators
Supporting to any future or ongoing management system and any framework which seeks documentation: ISO standards, Security management systems…
Do you need technical people to compile documents?
You need people that understand the logic of the document Subject, so it is likely that you need technical expertise but not necessarily a technical writer. Of course technical writers can add value but those value are not certainly useful and inline with purpose of documentation. Again refer to User Manual example.
The moment you discover the power of documentation as an integral part of IT management model, you won’t let anything done without it (I have seen this also as an imbalanced approach). But the beauty of it, is more the fact that it is a useful tool for both management and staff, something that is so rare. Stay tuned for IT Documentation Workshop soon.
In practice, most of internet anonymous services are only exposing your net identity in a different manner, even more obvious and only in a noisier way!
Long story short, if your are concerned about so-called ‘Privacy‘, do Not rely on popular techniques and tools of net anonymity!
When you connect to a (Anonymous) VPN service to hide your real IP address, either free or paid, you just enter a private smaller, easier to monitor (of course does not necessary mean ‘eavesdropping’), easier to track part of the larger internet.
Do solutions like VPN really hide our net presence, or they only change our internet footprint exposure to an exclusive state?
That simply means, tracing back to you with each single element of your online movement bound and an integral part to your identity, aka ‘your unique online presence’ and your internet footprint or online signature, is much more easier and precise. Even not considering the fact, that no one can stay 100% hidden forever, or being naturally born hidden, which means you already have some (a lot of) footprint on larger public internet, and now with browsing for example via a private IP, you just consciously connect the dots for data brokers. This is not a fiction and it is actually happening practically when dealing with browser cache, cookies and many other server and client-side elements of your online activity.
Net Anonymity services simply change the scope of your identity exposure to a exclusive, limited and restricted environment which leads to a highly precise identification and a better, realistic version of your internet footprint!
The real Net anonymity is not achievable via popular online services. However, there are certain techniques which can be implemented via free simple tools on a paid dedicated hosting, within an small community, for example your family, or your friends. In a nutshell, it is technically possible to have practical and reasonable anonymous internet identity only via a private entity with a limited restricted ownership:
Get a dedicated physical server online, or set it up with dynamic DNS on your current home internet connection, setup a few application to mimic a fast HTTP and SOCK proxy and then route your peers via VPN or P2P protocols to real world. in this case, the footprint would belong to only that small community, and ‘retain’ and accessible only within that P2P network. With certain techniques, you can send and receive communication completely untraceable to individuals. This can be accomplished if you have an IT guru nearby.
How to utilize native Windows security features to get beyond all the tools in the market?!
Most of the times ‘extra tools’ are just for doing things in a different way, perhaps more convenient, but not necessary in a better way, or more effective, cheaper or faster way and Windows is not an exception. Speaking of Windows security features, all the features we need are already part of operating system, they are either initially included or later provided by Microsoft. There are exceptions, but only when we are looking for a totally different structure, a very unique extraordinary situation, and that is where what we want is behind the Windows native features and capabilities, so we have to add something to the kernel or expand the API.
Windows Firewall and power of Micro Segmentation, EFS and power of Windows native file-level encryption, basic Access Supervisory via powerful native to kernel, Windows Event Monitoring and Sysmon, Group Policy and world of unlimited capabilities, PowerShell and unexpected security administration possibilities… and many more unleashed Windows features are already there, you just need to utilize them before thinking of buying a new tool!
In following articles I will explain how to unleash Windows native security features before shopping for a tool. Even though tools might be free, why add anything to Windows when it is already packed with most of the necessities? Let’s get through the basics briefly:
Windows Firewall provides all you need as the cheapest and fastest host-based firewall for Windows. It does not matter if the target machine is part of a corporate network or small office or home computer. Most importantly, it is very easy to utilize it as part of your micro-segmentation and see how you can reach the effective filtering and totally eliminate lateral propagation of malware in a large scale network. But if you ask me why administrators ignore Windows Firewall, I have no explanation unless admitting that beauty of third-party firewalls totally blinds them!
Encrypting File System (EFS) is a powerful file encryption which surprisingly has been ignored among new generation of IT administrators. Perhaps ‘encryption’ is enough scarry for most of IT staff to deal with so they decide to rely on third-party colorful tools, but I will show you later how to use EFS as the integral part of ACL and take your access supervision to next level!
We will deep dive into one of the most effective monitoring extensions of Windows, Sysmon, and see how a couple of extra megabytes can change the scope of Windows Event audit trial, needless to say Windows event log is a quiet piece of intelligence where all those shinny system and network monitoring tools are relying on, and if we add a little bit of AI to it how a free SIEM could evolve from it!
The point is, Windows has enough native tools to touch almost anything you want in terms of security, and for some hidden tiny tweaks we could always get into Registry, at least we won’t be worried about extra security vulnerabilities result of introducing new tools to environment, so why not get more familiar with the operating system and get maximum benefit from its native security features and capabilities? Then some day if you had a very specific requirement which Windows was not capable of providing it, you could consider using third-party tools or even switching to a whole new operating system!
From struggling or hardly surviving, to a fully supervised and manageable security program…
Most companies are struggling with running an smooth security program. No matter how much they are spending on that, the difference is really not that much. From zero budget to million dollars security budgets, they still do not have enough trust in their security program. Regardless of how much they are spending on security initiatives, they never really have confidence and are not expected to see positive and reliable result of their investment.
Adversaries are finding new ways to hurt online businesses every single minutes while tech gurus are creating “solutions” to address today’s challenges within months, years and sometimes decades after the fact!
We simply are only trying to survive in cyberspace, but what could we do better to thrive, in a stronger position, where the security is not a hassle anymore, and it should not be the heart of the matter too. Let’s look at some practical countermeasures:
* stick to a
For a moment forget about technology and tools and get back to basics. A management system could totally fulfill whatever you need in terms of handling processes and not being worried about base of your operation. You can invent the wheel again or you can choose from thousands of management systems, but first ask experts which system fits your needs or bring professional on-board to implement a system fully customized to your work flow from scratch, also believe me, without a management system of any kind and approach, you will be still at the first step after years spending your precious time, which is that “surviving” approach.
* set objectives
any project has a
set of goals which are measurable and achievable. Objectives are
neither like: having a more secure network…or, setup RDP filtering
on firewalls…there are more like reducing current number of entry
points to network…or, assessing current remote protocol
objectives help you
better understand what are trying to get from your management system,
and where resources have to be focused. This topic is also related to
Risk approach which I think is the fundamental and background of the
* constantly measure
These are checkpoints where you can tell precisely and by evidence if you are on the track, and the more you measure and automate the process, the more you get close to a proactive system and faster accomplishing each of objectives. Through measurement you can tell of direction is write or wrong, or what is wrong or right.
* plan for
corrective and preventive actions
with each measurement you need to define corrective actions if the result is not expected or the pace is slow, and the plan to enforce these corrective actions is the key to a smooth security program, otherwise you will be struggling with past actions while new ones arrive.
* be responsive to
facts not fictions
computer security industry is full of fictions, and we mostly spend time and money on things which are either not important or can be tackled from root, so let me give you an example:
taking Advil when
you catch flu is just a pain killer, only for passing time without
suffering from flu symptoms, just to survive, because we do not know
how to handle flu virus in 21st century (or maybe we know
but we don’t want to disclose?!), and that is similar to running a
virus scan on your network when you get a virus infection!
Cyber security facts
have not been changed since the beginning of this subject in human
history, so once you know about the facts you see how it is easy to
address them without Advil!