While this started as a blog specifically for Information Security a.k.a. Information Assurance, Information System Risk Assessment, Computer Security Engineering, and sometimes Cyber Security, I have already expanded it, or at least have needed to post off-topic remarks related to my own life. Therefore, now this is simply a journal for my ramblings, questions I discuss out loud to the general public.
Wednesday, September 11, 2013
11 September 2013
Certainly a day to reflect upon the tragedy that is now 12 years in the past. Those that died upon U.S. soil in New York, Washington DC, and to the fated airliner that our countrymen managed to wrest control away from the terrorists. Today also marks a few other days to remember personally. My wife's mother's birthday, my own mother's birthday, and the day I met my current wife. Yes, today seems to be a focal point in the space time continuum that is a recurring theme in my life. It is not without some apprehension that I approach this day, one marked with so much significance. Most certainly a day of reflection.
Tuesday, September 10, 2013
Ruminations
So, I'm watching "The Real Story" on the Smithsonian channel where they are detailing the story behind the Bruce Willis movie, "Live Free Or Die Hard." As always, my curiosity is peaked for the truisms and sheer possibilities presented. One question keeps running through my head though. Why, in all my research, reading, and seeing shows, either fictional or reality, has the United States or it's citizens been portrayed as the victim of cybercrime? Surely other nations are targets and face the same problems from cyber criminals as the U.S., but for whatever reason, these other nations get secondary billing. I suppose if there were a story (fictional) about an American hacker attacking another nation, the impression would be far different. Would the impression be the top nation being a bully?
Saturday, June 22, 2013
New Hobby
So, my fingers are sore....but I'm not complaining. I decided to take up a new hobby lately, that of learning the guitar. I've had my eye on the RockSmith bundle package from Sam's Club which comes with the game, both cables, and a Les Paul Jr. electric guitar. For $80.00, this is a steal, really! Online reviews of the Les Paul are favorable, given it's a bargain basement beginners guitar, and the Jr designation is not because it's a smaller size, that's just to indicate the model, which is to say that it's a lesser, not as quality manufacture as the prime time Les Paul is. You may notice that it does not include an amp, more on that later.
I got the package home, unwrapped it all, popped the disk in the PS3, and a half hour later, I was hooked. I'm really a music person, as anyone who knows me can tell you, although I have not played an instrument in quite some time (about three decades, give or take a couple years). When I got done though, it wasn't because I wanted to, it was because my fingers on the fretting hand were well on their way to developing a set of bruises, especially the index finger as the game does nothing in the way of finger placement on the strings, so I used that one predominantly.
The next day, I downloaded a few apps to the iPhone and iPad, mainly guitar tuners and chord databases, but I got curious about making my Apple devices into an amp. Sure enough, a Google search got me to 90% of a solution, as there are plenty of apps as well as commercial cables out there to buy. Well, the wife put the brakes on my spending much, so I decided to get creative. A few more searches turned up a guy who described how to build a cable, and a free app for the Apple devices. After scrutinizing the instructions, I went to the local Radio Shack and picked up the parts I didn't have lying around for only $10.00. About an hour later, I had the "cable" constructed. Take a look at the picture below:
Now you see why the word cable above is in quotes...my design was purposeful and meant to be small as well as not have a lot of cables lying around. My engineers brain has already designed the next phase of the device, but I can't implement it yet. I did run into a snag, that of the instructions on the internet failed to work the first time. I enlisted the help of my father, who spent his career with a soldering iron in his hand working on electronics for communications. Two added components and the next test was successful, although there are still a few minor bugs to work out. Here are some other pictures, sorry for the blackout.
The idea here is the app provides the functions that an amplifier would normally have in the way of knobs and logic for distortion of the signal and simply takes the input from the guitar and outputs the product to the headphone jack. In this diagram, I have my computer speaker cord plugged into the speaker jack, but if you have a pair of bluetooth headphones, you can essentially jam out to your own tunes without disturbing anyone. Furthermore, you could connect to an external bluetooth speaker from the iPhone as well. In the future, I plan to go completely wireless and plug a wireless transmitter to the guitar jack and a receiver to the input side of this converter box, which will allow me the freedom to move without tripping over wires!
I got the package home, unwrapped it all, popped the disk in the PS3, and a half hour later, I was hooked. I'm really a music person, as anyone who knows me can tell you, although I have not played an instrument in quite some time (about three decades, give or take a couple years). When I got done though, it wasn't because I wanted to, it was because my fingers on the fretting hand were well on their way to developing a set of bruises, especially the index finger as the game does nothing in the way of finger placement on the strings, so I used that one predominantly.
The next day, I downloaded a few apps to the iPhone and iPad, mainly guitar tuners and chord databases, but I got curious about making my Apple devices into an amp. Sure enough, a Google search got me to 90% of a solution, as there are plenty of apps as well as commercial cables out there to buy. Well, the wife put the brakes on my spending much, so I decided to get creative. A few more searches turned up a guy who described how to build a cable, and a free app for the Apple devices. After scrutinizing the instructions, I went to the local Radio Shack and picked up the parts I didn't have lying around for only $10.00. About an hour later, I had the "cable" constructed. Take a look at the picture below:
Now you see why the word cable above is in quotes...my design was purposeful and meant to be small as well as not have a lot of cables lying around. My engineers brain has already designed the next phase of the device, but I can't implement it yet. I did run into a snag, that of the instructions on the internet failed to work the first time. I enlisted the help of my father, who spent his career with a soldering iron in his hand working on electronics for communications. Two added components and the next test was successful, although there are still a few minor bugs to work out. Here are some other pictures, sorry for the blackout.
The idea here is the app provides the functions that an amplifier would normally have in the way of knobs and logic for distortion of the signal and simply takes the input from the guitar and outputs the product to the headphone jack. In this diagram, I have my computer speaker cord plugged into the speaker jack, but if you have a pair of bluetooth headphones, you can essentially jam out to your own tunes without disturbing anyone. Furthermore, you could connect to an external bluetooth speaker from the iPhone as well. In the future, I plan to go completely wireless and plug a wireless transmitter to the guitar jack and a receiver to the input side of this converter box, which will allow me the freedom to move without tripping over wires!
Wednesday, November 21, 2012
Information Security/Cyber Security
http://finance.yahoo.com/news/threat-spectacular-cyberattack-looms-official-185505164.html;_ylt=AotMcHbqlggVcFMe.957QkaiuYdG;_ylu=X3oDMTQ2N2JvbjJxBG1pdANDTkJDIEZlYXR1cmUgMgRwa
Ok, so I put that link in a draft a few weeks ago, fully intending on writing something about it sooner. I haven't gotten back to it until now, in the midst of watching "Live Free or Die Hard" again. For those of you not familiar with this movie, there is plenty to find on the Internet, so I will only say that it's about my line of work. I also checked them out today, and I find something very alarming here. References to the movie, which came out in 2007, cite sources that are even older , some even predate 9/11, and detail concern over an attack vector similar in nature. Fast forward to today, and the article above, and you can clearly see that not much has really changed in the minds of those that have the power to make a difference. Sure, there are good things being done, new government agencies, regulation proposals and updates, but underneath all that is still the same skepticism that was present back then. I'm not as concerned about the government end here, they seem to be on board now, albeit typically slow in getting things moving, no, I'm very concerned about industry here. Within the last year, a cyber security bill has been put forth to protect the nations critical infrastructure, but it has failed to pass. I can only assume that lobbyists and special interest groups are purposely trying to make the bill fail, and that leads right back to the industries that the bill is trying to protect in the first place.
We can read headlines that are indicators that there is a growing threat, the nations leaders are actively saying this, yet the CEO's and senior management of the industries that most certainly will fall first are still resistant. Now let us suppose that the U.S. fails to protect this before an attack happens, what about the other nations? Once a successful attack happens, there is no way that the attacker would stop there. No, just like conventional warfare, they would then take the next step and take down another nation, then another, then another. We, the protectors of networks, have a global responsibility, not just a local one.
Ok, so I put that link in a draft a few weeks ago, fully intending on writing something about it sooner. I haven't gotten back to it until now, in the midst of watching "Live Free or Die Hard" again. For those of you not familiar with this movie, there is plenty to find on the Internet, so I will only say that it's about my line of work. I also checked them out today, and I find something very alarming here. References to the movie, which came out in 2007, cite sources that are even older , some even predate 9/11, and detail concern over an attack vector similar in nature. Fast forward to today, and the article above, and you can clearly see that not much has really changed in the minds of those that have the power to make a difference. Sure, there are good things being done, new government agencies, regulation proposals and updates, but underneath all that is still the same skepticism that was present back then. I'm not as concerned about the government end here, they seem to be on board now, albeit typically slow in getting things moving, no, I'm very concerned about industry here. Within the last year, a cyber security bill has been put forth to protect the nations critical infrastructure, but it has failed to pass. I can only assume that lobbyists and special interest groups are purposely trying to make the bill fail, and that leads right back to the industries that the bill is trying to protect in the first place.
We can read headlines that are indicators that there is a growing threat, the nations leaders are actively saying this, yet the CEO's and senior management of the industries that most certainly will fall first are still resistant. Now let us suppose that the U.S. fails to protect this before an attack happens, what about the other nations? Once a successful attack happens, there is no way that the attacker would stop there. No, just like conventional warfare, they would then take the next step and take down another nation, then another, then another. We, the protectors of networks, have a global responsibility, not just a local one.
Thursday, November 8, 2012
Air travel
I realized something today that I have missed for at least a year and a half. I get anxious about flying, to the point that I am highly sensitive to my emotions. Those that know me would say that I'm normally in control about my emotions. I will have to pay much closer attention to this in the future to see which emotions are most common. This trip I felt extremely lonely and missed my family before I even left the house for the airport.
TSA had their say again. No surprise this time, because I had forgotten about the new pocket knife that I had added to my right pocket with my companies logo on it. Not a big loss, and understandable this time, still, it seems that they are really picky. Maybe that is a sign that they are doing a good job?
Got to my destination, and my rental car company was short on cars, so I got the silver Ford Mustang 5.0 they had left. I've been dreaming about this for a while, because they often give me cars that are upgrades from what I've reserved, but it wasn't the experience I was expecting.
Day 2 was better, actually enjoyed the mustang, and had a productive day at work. Still missed the family, and tried hard not to stress about the flight home. Think it worked, even though the closer I got to flight time, I did notice some unusual behavior.
During the flight I had an episode that concerned me a bit. It had happened only once before, but not quite this bad. Once the plane reached altidute, the right side of my face went completely numb, to the point that I couldn't even close my right eye. I put my head back and tried to relax, but couldn't get any feeling back. I was starting to get a little anxious and concerned, when my stomach started to heave. I grabbed the air sickness bag and punched the attendant call button. It stopped shortly after I regained feeling in my face. After the plane landed, I called the wife and she was able to do a little research online. The most likely explanation is that my sinuses were blocked, causing the pressure to build up at altitude and compress a nerve, making my face numb. My ear had probably also not equalized either, causing the nausea. Throwing up may have caused both to equalize with the altitude and stop the problems, because it immediately got better and I gave no residual effects a day later. Bottom line is I should not ignore allergy medication during trips and be extremely cautious about flying with a stopped up nose.
TSA had their say again. No surprise this time, because I had forgotten about the new pocket knife that I had added to my right pocket with my companies logo on it. Not a big loss, and understandable this time, still, it seems that they are really picky. Maybe that is a sign that they are doing a good job?
Got to my destination, and my rental car company was short on cars, so I got the silver Ford Mustang 5.0 they had left. I've been dreaming about this for a while, because they often give me cars that are upgrades from what I've reserved, but it wasn't the experience I was expecting.
Day 2 was better, actually enjoyed the mustang, and had a productive day at work. Still missed the family, and tried hard not to stress about the flight home. Think it worked, even though the closer I got to flight time, I did notice some unusual behavior.
During the flight I had an episode that concerned me a bit. It had happened only once before, but not quite this bad. Once the plane reached altidute, the right side of my face went completely numb, to the point that I couldn't even close my right eye. I put my head back and tried to relax, but couldn't get any feeling back. I was starting to get a little anxious and concerned, when my stomach started to heave. I grabbed the air sickness bag and punched the attendant call button. It stopped shortly after I regained feeling in my face. After the plane landed, I called the wife and she was able to do a little research online. The most likely explanation is that my sinuses were blocked, causing the pressure to build up at altitude and compress a nerve, making my face numb. My ear had probably also not equalized either, causing the nausea. Throwing up may have caused both to equalize with the altitude and stop the problems, because it immediately got better and I gave no residual effects a day later. Bottom line is I should not ignore allergy medication during trips and be extremely cautious about flying with a stopped up nose.
Friday, September 21, 2012
Mapping Security Control Catalogs
So I have a new project underway in my spare time. My wife and I are going into business and, as it happens, must comply with not just one, but two sets of information system security control regulations, one industry, and one federal. Being intimately familiar with DoD 8500 and NIST, I welcomed the challenge that came with this in attempting to translate the other two into a framework that I understood better and immediately ran into an issue. The two regulations are PCI-DSS and HIPAA, which are not fully developed information system security programs, therefore, it doesn't make sense to show compliance just for compliances sake. I wanted to do this the right way and adopt a full program and then map the other two standards to it, so chose NIST as I have been impressed with it's flexibility in the control set. I am not happy with it's security categorization, so instead, chose the CNSSI-1253 to perform this function for my program.
So far, so good.
NIST has publised SP 800-66 that maps HIPAA to SP 800-53 Rev 2, but I'm wanting to be on the cutting edge, which meant that I had some updating to do with that map in order to get it into SP 800-53 Rev 3 (and soon Rev 4). Ok, not too bad, NIST markups and discrepancies aren't too bad to work with and I don't see a big problem with not being specific in the control enhancement area as HIPAA is rather vauge when it comes to stipulating requirements, so the base controls should do fine. So far, it's a little work to get the HIPAA map updated, but looks fairly easy.
Then I turned to PCI-DSS to look at that.
Drastic difference here, as this control set is more specific than the NIST control set in certain areas, and darn it all, no-one seems to have mapped this to NIST. I did find a few maps that I could reference, but not use or change directly, mainly using yet a third control set that I wasn't interested in at all (ISO 27000, COBIT, and CSA). In develing deeper into these maps, it seemed that the ISO and COBIT maps weren't all that useful to me, but the CSA seemed to do a wonderful job as it published a map between all the control sets mentioned in this post as well as a few more. So I grabbed that and really took a good look at it. Bottom line, it's a good effort on their part, but for my purposes, I can't use it.
The basic reason is that in order to map control sets, you have to start with a base set, then perform the map to the set you want to use. In my case, I have to do that twice, once with PCI-DSS, and once with HIPAA. Once you have it done that direction, you can reference the other two sets from the set you use to show compliance. Since the maps I had tried before had essentially done this against a set that I wasn't interested in, I was attempting to compare apples to oranges to get it back into the right framework. Sure, the maps are somewhat useful to narrow down the field, but only when the control set they use is nearly identical to the one you want to use.
Crap, I'm going to have to do this the hard way: map the sets manually.
Doing it this way has a huge drawback, in that you are entirely dependant upon your own subjectivity, which the entity that you are trying to show compliance with may not agree with. I didn't want to do this, but in the absence of publically avaliable or official maps, I really have no choice. Fortunately, I do carry the credentials to make my map more credible to anyone looking at it.
So, I'm just getting started, but already I see a pattern starting to form in that my subjective view is very granular and differs from the maps I've been able to find.
So far, so good.
NIST has publised SP 800-66 that maps HIPAA to SP 800-53 Rev 2, but I'm wanting to be on the cutting edge, which meant that I had some updating to do with that map in order to get it into SP 800-53 Rev 3 (and soon Rev 4). Ok, not too bad, NIST markups and discrepancies aren't too bad to work with and I don't see a big problem with not being specific in the control enhancement area as HIPAA is rather vauge when it comes to stipulating requirements, so the base controls should do fine. So far, it's a little work to get the HIPAA map updated, but looks fairly easy.
Then I turned to PCI-DSS to look at that.
Drastic difference here, as this control set is more specific than the NIST control set in certain areas, and darn it all, no-one seems to have mapped this to NIST. I did find a few maps that I could reference, but not use or change directly, mainly using yet a third control set that I wasn't interested in at all (ISO 27000, COBIT, and CSA). In develing deeper into these maps, it seemed that the ISO and COBIT maps weren't all that useful to me, but the CSA seemed to do a wonderful job as it published a map between all the control sets mentioned in this post as well as a few more. So I grabbed that and really took a good look at it. Bottom line, it's a good effort on their part, but for my purposes, I can't use it.
The basic reason is that in order to map control sets, you have to start with a base set, then perform the map to the set you want to use. In my case, I have to do that twice, once with PCI-DSS, and once with HIPAA. Once you have it done that direction, you can reference the other two sets from the set you use to show compliance. Since the maps I had tried before had essentially done this against a set that I wasn't interested in, I was attempting to compare apples to oranges to get it back into the right framework. Sure, the maps are somewhat useful to narrow down the field, but only when the control set they use is nearly identical to the one you want to use.
Crap, I'm going to have to do this the hard way: map the sets manually.
Doing it this way has a huge drawback, in that you are entirely dependant upon your own subjectivity, which the entity that you are trying to show compliance with may not agree with. I didn't want to do this, but in the absence of publically avaliable or official maps, I really have no choice. Fortunately, I do carry the credentials to make my map more credible to anyone looking at it.
So, I'm just getting started, but already I see a pattern starting to form in that my subjective view is very granular and differs from the maps I've been able to find.
Sunday, July 29, 2012
Political Happenings
So, I'm not sure if anyone has been following this ridiculous chain of events that has been flooding the news lately, but if you haven't, don't worry, I don't think you are missing much. Apparently it started with the CEO of the restaurant chain Chick-Fil-A being quoted as against gay marriage. There has been a flurry of support and a move to boycot since. The latest round apparently involved their Facebook page being shut down for twelve hours and a resurrection with a plea for support set for August 1. While I don't eat there, and won't be rushing to do so anytime soon, I'm finding it very hard to stay quiet on the issues, which is very out of character for me as I'm not usually for or against either politics or religion.
Let me try to break down the issues here. There are two main issues here, one political, one religious. Then there are the side issues, namely of free marketing and private industry terms of service. First, the political.
The first amendment of the Constitution of the United States grants the right of free speech. The CEO exercised that right by expressing his own opinion on a public matter. Somehow it got tied to the opinion of the company he runs, which is unfortunate, but ultimately happens when people in the public eye are linked to their affiliations. I'm not one to do this, but the CEO rolled with this one, so now it IS fact, where it probably wasn't initially. I'm not a lawyer, but I believe that the Constitution covers the company's rights in this regard as well, so any attempt at suppressing this right could lead to a challenge by the company in a court of law.
The second major issue is religious. Ok, so any formalized religion that names the specific verse in the Bible as the word of their deity and bans homosexual relationships would support the CEO. It follows that anyone against this position would be offended by his words. Both sides are exercising their first amendment rights here, and neither is more justified than the other in terms of a court case since no foul has been committed according to the law. There is separation of church and state here in the US, so the two sides can argue for as long as they have breath to do so, and neither should be disparaged in their right to do so, nor suppressed, forced to be silenced, or in any other way repressed. My view here on the specific issue is irrelevant as I stand on the right of free speech as well as the freedom of religion, thus so far, nothing has been said or done that violates these rights, I have remained silent.
Here's where it gets a bit tricky. The sub-issues have muddied the waters, and I do have an opinion here. Let's start with the free marketing. While I see that the CEO has the right to promote and support the planned show set for this Wednesday, I believe he is using it unduly to line his pockets. I don't even really blame him, I blame the people that are supposedly supporting him. Sure, they have the right to do so, but I just don't see how making this show of support means more than just giving him money, which would happen in the normal course anyway. To me, this has zero moral value, and no significant influence on the topic at all.
As for the fourth issue, Facebook, in it's terms of service, retains the right to perform any action it deems necessary including denial of service to any entity it sees as in violation to the terms it sets forth. While I don't know the specifics of why the page was shut down, nor the reasoning behind its resurrection, I can not find any fault with the action. Facebook, after all, is another private company, any their users are bound to its terms of service. Whether the action violated the first amendment or not is irrelevant because the terms of service prevail here, not the Constitution. Facebook is not a Government run institution, nor public forum, as such, the Constitution has no power to enforce the right of free speech to the users of this private service. Those that don't understand this need to go back to school and start reading all agreements that they sign.
So, bottom line here is that no law has been broken, and the debate has not been settled religiously, privately, or otherwise. Business as usual, and in my opinion, not worthy of so much media attention as has been given.
Let me try to break down the issues here. There are two main issues here, one political, one religious. Then there are the side issues, namely of free marketing and private industry terms of service. First, the political.
The first amendment of the Constitution of the United States grants the right of free speech. The CEO exercised that right by expressing his own opinion on a public matter. Somehow it got tied to the opinion of the company he runs, which is unfortunate, but ultimately happens when people in the public eye are linked to their affiliations. I'm not one to do this, but the CEO rolled with this one, so now it IS fact, where it probably wasn't initially. I'm not a lawyer, but I believe that the Constitution covers the company's rights in this regard as well, so any attempt at suppressing this right could lead to a challenge by the company in a court of law.
The second major issue is religious. Ok, so any formalized religion that names the specific verse in the Bible as the word of their deity and bans homosexual relationships would support the CEO. It follows that anyone against this position would be offended by his words. Both sides are exercising their first amendment rights here, and neither is more justified than the other in terms of a court case since no foul has been committed according to the law. There is separation of church and state here in the US, so the two sides can argue for as long as they have breath to do so, and neither should be disparaged in their right to do so, nor suppressed, forced to be silenced, or in any other way repressed. My view here on the specific issue is irrelevant as I stand on the right of free speech as well as the freedom of religion, thus so far, nothing has been said or done that violates these rights, I have remained silent.
Here's where it gets a bit tricky. The sub-issues have muddied the waters, and I do have an opinion here. Let's start with the free marketing. While I see that the CEO has the right to promote and support the planned show set for this Wednesday, I believe he is using it unduly to line his pockets. I don't even really blame him, I blame the people that are supposedly supporting him. Sure, they have the right to do so, but I just don't see how making this show of support means more than just giving him money, which would happen in the normal course anyway. To me, this has zero moral value, and no significant influence on the topic at all.
As for the fourth issue, Facebook, in it's terms of service, retains the right to perform any action it deems necessary including denial of service to any entity it sees as in violation to the terms it sets forth. While I don't know the specifics of why the page was shut down, nor the reasoning behind its resurrection, I can not find any fault with the action. Facebook, after all, is another private company, any their users are bound to its terms of service. Whether the action violated the first amendment or not is irrelevant because the terms of service prevail here, not the Constitution. Facebook is not a Government run institution, nor public forum, as such, the Constitution has no power to enforce the right of free speech to the users of this private service. Those that don't understand this need to go back to school and start reading all agreements that they sign.
So, bottom line here is that no law has been broken, and the debate has not been settled religiously, privately, or otherwise. Business as usual, and in my opinion, not worthy of so much media attention as has been given.
Subscribe to:
Posts (Atom)