Pages

Showing posts with label Information Security. Show all posts
Showing posts with label Information Security. Show all posts

Tuesday, March 24, 2015

Information Security Control Mapping

As any Information Security Professional will tell you, there are a multitude of regulation and security control frameworks out there to choose from.  Very often, an individual organization is subject to multiple regulations and must show compliance with them regularly.  This mandate sets up a situation where they have a choice between duplication of effort for compliance's sake, or to compare and contrast the multiple regulations and implement a single, unified solution.  Given that duplication of effort is not cost efficient, and smart organizations always track the bottom line, then a security control map is absolutely necessary.

Mapping of security controls between differing standards is not a task to be taken lightly, nor is it the most speedy process.  At best, an odd sized small team (5 or 7 individuals) takes months to come to an agreement between them.  Teams smaller than this run into a problem of less objectivity faced with a herculean task.  Larger teams run into the opposite problem of the more frequent disagreements in committee and too much input to be discussed in a timely fashion.  In the end, the map itself is always subjective to the nuances of the group that created it.

This subjectivity is the result of two factors, the interpretation of the control measures combined with the methodology used to form the map.  While the interpretation is subject to each individual making up the group along with their expertise, (which not only cannot be controlled, but is very often viewed with a contrasting opinion once the map is published) the methodology can at least be framed by a general consensus among the professional field.  This is accomplished by taking each control measure into consideration and finding one or more suitable equivalent controls from the other control set.

It is widely accepted that there are not one, but two maps to look at when comparing two sets of control measures, that of each set in the context of the other.  Adding more control sets makes the number of potential maps rise progressively using the formula <i>n * (n-1)</i> where <i>n</i> is equal to the number of control sets in play.  Therefore, 3 sets would produce 6 maps, 4 produces 12, and 5 produces 20 maps.

While a thorough exploration can be thought of to be complete by finishing all the maps, a simpler method presents itself, reducing the number of maps to just the number of control sets in play.  This methodology consists of choosing a primary control set among the multiples and only considering the maps to the other control sets in context of the prime.  Logically, this makes sense, but there is still something missing from this methodology, that of the usefulness of the "reverse" map.

Because differing control sets often have no equal between them, and many are far too focused in scope and content to be of any use to the other, holes in the map abound.  Compounding this is the fact that the regulations themselves are not enough for an effective security program, and an additional framework is necessary to achieve security effectiveness, increasing the number of maps by a proportional number.  Fortunately, there are several frameworks in the wild that are written from a far more general nature than the specific regulations.

When employing a framework into the mix of regulations, caution must be observed in the choice of framework.  Traditionally, individual regulations are married to particular frameworks (i.e. PCI-DSS to COBIT, SOX to COSO, HIPAA to ISO 27001, FISMA to NIST 800), but in reality, any framework could potentially contain any regulation depending on how flexible it's implementation is handled.  It stands to reason that not every pairing is a harmonious match, thus the traditional pairings have the most chance for success.  In the end, the framework dictates a common control set that will then have to be mapped to the applicable regulations.

This mapping, as discussed above <i>could</i> be achieved in the context of the framework, however, a more saturated method is to only consider the <i>reverse</i> maps instead of the "forward" maps.  This method takes each control measure from the regulation and fits one or more controls from the framework to achieve compliance.  This last method is by far the most beneficial from a compliance standpoint as every mandatory control measure is assured to be assessed and met as well as any holes from the framework control set will be identified and rectified.  This last situation is actually very rare as the framework used (as long as a harmonious "marriage" is observed) is most likely to be a super-set that envelops the regulation set.

So what happens when an organization needs to be compliant with multiple regulations?  Obviously the choice of framework becomes even more critical, requiring a much more general context to maximize the saturation and minimize the leftover controls from the individual regulations.  For this effort, two frameworks stand out, the NIST 800 series and the similar ISO 27001.  Both are formed by entities that produce common standards, one for the U.S. federal government and the other for an International community.  Which to choose depends upon the nature of the organization contemplating the adoption of either from the aspects of HQ location and global presence.

Friday, March 28, 2014

An Interpretation of HIPAA as it relates to Home Health Agencies

Many industries are subject to US government regulation regarding Information Security.  Aside from direct government contracting entities, the main three industries are now national infrastructure, financial, and healthcare.  Government contracting entities and the financial industry have had to deal with this type of regulation for a long time now, but the other two are fairly new to it.  The healthcare industry looks more like the financial sector, specifically the credit card processing model, in that even the smallest entities are impacted by the regulations.  With the passing of HIPAA, HITECH, and now what is commonly referred to as Obamacare, the healthcare industry is undergoing a transformation.  How it impacts individual entities is the subject of much concern.  The natural reaction is to get away from regulation as much as possible, but these acts leave very little room to breathe.  Other industries have already accepted the fate to which Information Security regulatory acts have imposed upon them, and it is time for healthcare to get serious about it.  In this article, I will attempt to break down the specifics and suggest a course of action.

Before a suggested course of action, an examination of the government regulation is in order here. Specifically, whether the regulation is even applicable to a particular entity.  Currently, the HIPAA and HITECH acts apply only to healthcare clearinghouses, agencies that must work with the federal government for either Personal Identifiable Information or billing purposes, or professionals in the healthcare field such as doctors and hospital administration.  This seems to leave some entities out, but be very wary.  With the passing of Obamacare, this could be rapidly changing.  The observation here is that Obamacare mandates that everyone carry health insurance, and those that are not provided insurance through an employer must purchase it at the state level, funded by the federal government.  Although private industry insurance providers are still the carriers, the government oversight here cannot be ignored.  Obamacare impacted every man, woman, and child currently carrying insurance by enacting regulation over the industry.  Much like the financial industry, the healthcare insurance carriers now cannot ignore governmental regulation.  By extension, any entity doing business with the insurance carriers are similarly impacted, much like any business that accepts credit cards must be found to be in compliance with PCI-DSS.  This is the transformational event that is being addressed right now.  The implication here is that even the smallest agencies will have to consider HIPAA and HITECH compliance in the very near future.  Due to the heavy penalties of HIPAA non-compliance, and the ramifications stated above, it is in the best interests of any entity planning or operating any type of healthcare industry to budget and implement a security compliance effort whether they feel they are in scope or not.

HIPAA and HITECH generally go hand in hand, but compliance with one does not equate to compliance with the other as they have different focus areas.  They are complimentary, not conflicting though, so achieving compliance in one or the other makes it easier to become compliant in the second.  The problem with both of these is they do not state how compliancy is to be achieved, they simply lay out the objectives.  In order to meet the objectives, another tool must be adopted in order to move an entity through the design, planning, implementation, and assessment phases in order to prove compliance.  Many security frameworks are out there, some publically available, some through a small cost for licensing.  None of them are simple in scope, cost, or time.  Once a security framework is adopted, a software toolset is necessary as well to move the entity through the process.  So, to sum up, government regulation must be examined to see if it applies, a security framework compatible to the regulation must be chosen, and the corresponding toolset must be obtained.  These steps are relatively easy to achieve, and as stated above, it is in the best interests of a business to just simply submit to the regulation and make the effort to become compliant as doing otherwise may be the first death toll heard for them.

As many in other industries have pointed out, becoming compliant is very costly, both in capitol and labor.  Although there are a few shortcuts that can be done, the effort itself is the bulk of the cost and cannot be avoided.  As in other industries though, there is hope for entities that simply could not afford the compliance effort otherwise.  A new type of B2B entity is beginning to emerge, one that provides a service to small and mid sized businesses to take the responsibility of compliance out of their hands.  This is not a new concept for the financial industry, but it is much larger in scope as applied to the healthcare industry.  The healthcare industry cannot simply obtain an approved device and let the worry of compliancy fall upon the processor....or can it?  Such a model does not currently exist in the healthcare industry, but perhaps as the industry maturates, this could be possible.  Currently though, the headache is squarely on the entity performing transactional services for medical records or medical billing for Medicare or Medicaid reimbursement.  So what about private pay agencies?  Well, this is a very gray area, as discussed above in relation to Obamacare.  Now that everyone is mandated to carry insurance, and insurance will most likely carry some form of long term care clause, doesn't it follow that the pressure is already evident for private pay home care agencies to be compliant as well?  In my opinion, it is.

Monday, March 24, 2014

Job Hunting

Perhaps I'm getting older in an ever increasingly complex online world, but the job hunt has me all "a twitter" right now.  The last time I was on the hunt was three years ago, and the premier job board was still monster.com, although there were several offshoots that were getting much more specific to certain industries.  This time, I have found that things have changed yet again, and the best place to look is now firmly in the hands of a social media site, LinkedIn.  This led me down the road to examine my other social media accounts and connections.  Updating the information on them has been completed, and I have cross-linked them as much as they have allowed me to do, and where they don't inherently do this for me, I have done so manually by posting the links to the status updates fields on all of them.

While all the above is all great, in the end, it's rather like climbing to the highest tower in a city and shouting from the rooftops.  Not only will your words be drowned out by the din of the others, there is no expectation of a reply worth pursuing.  Is this really good networking?  Sure, the friends and followers on the social media sites have been picked carefully, or at least with an eye toward some personal gain, but it's a far cry from showing up at a company and handing your resume to them personally.

I have never been very comfortable with selling myself, nor being an active participant in social media in general.  My comfort zone is firmly on the right hand side of someone else as a trusted advisor, being an expert in my field, and my social circle is almost exclusively limited to my own wife and kids.  I truly envy people that can thrive in the limelight of the media, be the social butterfly at any event, or those that seem to have a natural ability to land a really great job.  I've learned what I needed to over the years, and followed the trends as much as I was able, but the one factor that has been the most useful over the years has been to be in the right place at the right time when the new job came along.

I only hope this factor comes my way this time as well.  In the end, I've done what I can to encourage this to happen, even extending myself outside of my normal comfort zone tremendously, yet I can't help but wonder if there is something I can be doing that will further this cause.  Get myself in front of more people who can see what my skillset may bring to them.  On LinkedIn, I could try to friend all the recruiters I can.  On Twitter, I could hashtag the popular trends with a link to my LinkedIn profile.  I can blog here.  I can spread the word on the other social networks.  Does this cross any boundaries or present me as an annoying person?  I am simply not sure about the perception such actions would be viewed.  That having been said, the end may justify the means here, all I can hope is that it does not tarnish my online reputation.

Thursday, May 31, 2012

Hazards of corporate takeovers in Information Security

The best practice taught by computer security experts everywhere is diversification across your security products.  This is different than the practice of establishing a common baseline and acquiring the same make and model of component equipment for that component function in the environment.  The idea is simple, but the explanation is complex.  Your security architecture is made up of many different components doing different things in order to accomplish a mission function.  In the same way a house is built, a computer system is built.  Many different components to make up the whole.  On the surface, you have a resilient barrier to keep the outside out (IT system: boundary protection, House: stucco, brick, weather-resistant wood, roofing material).  Inside of that, you have a buffer zone to insulate the interior from the impact of extreme penetrating elements (IT system: DMZ, honeypots, externally facing servers, House: wood framing, insulation).  Inside of that, you have another barrier between the buffer zone and the interior (IT system: internal firewalls, authentication servers, House: interior drywall).  At protected points, you have controlled access to the inside (IT system: VPN, privileged functions, House: locking doors and windows).  And at unprotected points, you have holes that can be used to gain access to the inside (IT system: weaknesses expressed as vulnerabilities, House: various vents and weak points such as the garage door).  Just as a house, an IT system should be fitted with security measures to mitigate the possibility that an intruder could gain access to the inside.  An alarm system is analogous to audit monitoring and reporting and IDS devices.  Additional reinforcements like window bars and sticks in the tracks of windows are comparable to IPS devices and two-factor authentication.
So, what is the problem?  It’s with those holes, the weak points.  A house built with the standard equipment used in all the rest of the houses in the neighborhood may experience a common fault, like a particularly weak locking mechanism, that if known, can be used again and again to gain access to any house using that mechanism.  Furthermore, if security devices bought from the same company are used for multiple layers for protection, they may experience a common weakness, making it that much easier for an intruder to penetrate to the warm comfort of the interior.  Business is business, and corporate policy dictates the way that business is conducted.  A corporate takeover may introduce a weaker policy structure than what existed previously, plus you have the possibility of layoffs that may introduce an out of work expert in the technology used that is now disgruntled.   This guy knows all your secrets, knows the back doors, and knows the products.  You’ve just made him mad and unemployed, and in an act of desperation, he could sell what he knows, or even take an active role in a penetration attempt.  At the very least, he is subject to a social engineering attempt that he is now more susceptible to because he is no longer subject to any sanctions that existed when he was employed.
Another aspect to consider is with the components themselves.  A single manufacturer supplying multiple levels of protection devices with a common vulnerability or method in the design poses significant risk to an intruder because the same exploit will work at multiple layers.  Take our house as an example again, it has a door with an added security door as the main entry point, but both doors are fitted with a lock from the same manufacturer.  It is well known that there exists a vulnerability in certain locks that a simple application of a hammer is able to break and allow the door to be opened.  Two swings, and the intruder gains access to the house.  In our IT system, let’s say that both the exterior and interior firewalls are made by the same company and have a back door installed in them from the vendor.  The same hard coded default password is able to open those firewalls and an intruder is in the network within seconds.
 

Tuesday, December 14, 2010

Repost: Initial Frustrations, a discussion of DoD shortcomings

Background:  I've been in the IT industry for well over 13 years now, and a computer enthusiast since my parents first put a Commodore VIC-20 in my hands as a child.  I avidly watched the industry grow up, mature, and start to diversify.  In my adult life, I continued to learn all I could about computers and their application in life.  Approximately 9 years ago, I got my first "real" IT job.  I had been working in a call center environment for 4 years at that point doing tech support work, but this new job was working for a contractor at a DOE facility.  This proved to be my first taste of what we now call Information Security (IS) or Information Assurance (IA).  I currently work for a DoD organization where my primary job responsibilities are IA.
Over the last 9 years, I became increasingly aware that the IT field was undergoing a split, or had split into two distinct areas, that of administration of computer systems, and securing computer systems.  They were integrated in such a way that it was very difficult to tell the two apart.  About four years ago, a program was implemented where I was working for at the time that led me into the IS field.  While there, I experience how IS should be implemented as far as personnel and policy.
I left that position in 2008 and re-entered the field in 2009 working as an IT Systems administrator for a different government agency.  At this new position, I found that although the regulations and policy were in place, and an implementation strategy was well thought out, that only existed at the root or direct subordinate level.  Below that level, especially for non-centralized sub-organizations, the structure fell apart and was very poorly implemented.
The incumbent in the position I held had been working towards getting the organization up to speed, and I began to assist him in this effort.  One would think that with the regulation in place, and pressure from members internal to the organization, that an effective IA shop would be instituted.  This did not happen.  After the incumbent left, the task fell to me to get this done.  It has now been over two years since this was brought to the attention of all levels of the organization and still, there is not a resolution in sight.
Problem:  The basic problem seems to be that of manpower denying critical billet positions.  That, and procrastination on the part of several parent organizations to dictate how an IA shop should be setup at a remote location.  In addition, there are some specific cases where this policy fails to clarify how an IA shop should be run.
Disclaimer:  In order to maintain some obscurity, I won't name specific organizations or people, but will try to define the problem in sufficient detail so that the community can recognize the problems and hopefully discuss possible solutions.  I ask that anyone posting comments please adhere to these stipulations and do not try to guess at names or organizations involved.
If you are familiar with regulations within the DoD branch specific to IA, you will know that in order to successfully execute a C&A package, you must have, at a minimum, the following roles:
  • DAA – Designated Accrediting Authority
  • SIAO – Senior Information Assurance Official
  • CA – Certifying Authority (or Certifying Agent) (typically the SIAO)
  • PM – Program Manager
  • IAM/IAO – Information Assurance Manager/Information Assurance Officer
  • UR – User Representative
In a typical organization of mid to large size (100+), these roles are very easy to fill, but for a smaller organization, two of these roles become increasingly difficult to fill.  Specifically, the DAA and SIAO/CA roles.  From the US Code down, these must be filled by government civilians or military personnel and both carry heavy responsibility and authority, meaning upper organization management positions.  The DAA is required to be at the GS-15/O-6 level while the SIAO is the single policy maker for the entire IA department.
What I have discovered, and inferred from multiple sources as well as my own experience, is that neither of these individuals would be comfortable signing off on a system that they cannot either virtually or physically see and touch.  This makes perfect sense to me as they are, in essence, assuming the risks and responsibility of any system they approve.
This wouldn't be a problem if a small organization is physically located at or near their parent organizations HQ, but, as is typical for DoD organizations, there are many sub-organizations that are physically separate from their parents.  Most of these sub-organizations are located on military installations where they get their network connectivity from.  While this isn't a problem if they are affiliated in some way to the military base/post/station that they are located at (as they would simply use the DAA/SIAO that services that location), it does pose a problem for MAJCOM organized units.  These units are typically not affiliated with a single branch of military service, therefore, the DAA/SIAO that services that location is not operationally aware of the mission of these outlying units.
In an ideal world, and I acknowledge that DISA is trying to effect this change, the hosting base would simply accept the systems that belong to the MAJCOMs as is, even though they might not be able to fully understand the mission, they can at least see and touch systems attached to their network.  This, at least, I have witnessed, and it seems to work.
There is one type of system though that this cannot work for and it is the hardest system to run through the C&A for.  Standalone Enclave systems are a bear to work with.  Many units ignore these systems, or fail to acknowledge DoD's specific instruction that "All DoD owned systems will be accredited."  The problem is that the only entities that can virtually or physically see and touch these systems exist within the sub-organization itself.  This, by inference, means that all DoD roles must exist within the sub-organization.
Well, I can tell you that simply can't happen for every organization out there.  Some organizations don't even have a GS-15/O-6 to throw a DAA appointment to, much less second position able to take on the SIAO/CA role.  The sticking point is not the DAA, interestingly enough, it is the SIAO/CA role.  This position, given the standalone enclave system, requires a CISSP or equivelent certification per DoD 8570-M. 
I've not found a person in a current position of authority to entertain the idea of obtaining a CISSP certification just to satisfy this requirement.  The most common answer I've gotten is that they are just too busy.  I can understand this stance, as we are talking small shops, and the workload is typically piled on deeper than a larger organization for each person.
So, where does that leave the situation?  A small shop, not co-located with their parent organization with a need to C&A a standalone system is left out in the cold.  DAA's don't want to touch these systems, and the small shop can't requisition the proper billet to get the right IA personnel into the organization to do it in house.

This is my frustration, as I know it needs to be done, but I can't change the minds of the people over my head.