Accountancy Magazine – Flirting with Disaster

I was quoted by Accountancy Magazine in an article covering Disaster Recovery. I was talking about the potential business impact for those that did not adequately plan and budget for disasters and how difficult, if not impossible, it would then be for them to survive one.

The article is available online at:

http://www.cch.co.uk/croner/editorialDetails/category/Magazines/Magazines/editorial/Flirting-with-disaster…

ISNow – Software Security

The following introduction was originally published in the BCS Information Security Now Magazine, Spring 2009 issue (Volume 3, Issue 3), which was on the topic of Software Security:

“Secure, stable and reliable software is a rare commodity, and one that most can’t actually buy. Although we may feel that those who profit from selling us software not up to the task should be held liable and sued, doing so could also expose open source developers to unacceptable risks when giving us their software.

Unreliable and insecure software is due to a variety of factors; from the lack of academic focus within software engineering and computer science courses, to the development approach that our IT professionals are expected to adopt when programming in-house systems or commercial applications.

Even the formal accreditation of systems, e.g. Common Criteria, may not detect or prevent software vulnerabilities from arising; it can even compound the issue by forcing a decision to be made between operating a vulnerable but accredited system and an upgraded but unaccredited system.

SANS and CWE have listed the Top 25 Most Dangerous Programming Errors (http://www.sans.org/top25errors/), which covers the actual programming errors made by developers that lead to the vulnerabilities that software may be susceptible to, and provides useful and authoritative information on mitigation.

Security software even provides ready examples of how to not do it and the formal methods of safety critical systems may be overkill for most commercial offerings. Something needs to be done to improve the security, stability and reliability of software where more features are delivered ever more rapidly.

We need a ‘secure by design’ approach, where we seek to minimise the existence and impact of vulnerabilities and other bugs. Secure applications can only come from a top-down design and development ethos, integrated with a robust software development life cycle (SDLC) that includes structured testing.”

A PDF version of the magazine is available online at:

http://www.bcs.org/upload/pdf/isnow-spring09.pdf

ISNow – Computer Forensics

The following introduction was originally published in the BCS Information Security Now Magazine, Winter 2009 issue (Volume 3, Issue 2), which was on the topic of Computer Forensics:

“Digital forensics is an area overlooked by many companies – until needed. When required it can touch upon many business areas, including IT, HR and Legal. Proper planning can help ensure that it is effective when called upon.

Forensic Readiness
Companies should have a formal forensic readiness plan in place, so that when an incident occurs the correct skills, processes and technology are available to ensure proper collection of reliable evidence. This may require external resources being brought in to perform activities beyond, say, seizure or quarantining of a system or storage medium.

It may also be sensible to limit untrained internal technical resources from engaging in digital forensics. They may overcompensate for having ‘permitted an incident to occur’ by being overly eager to respond and investigate, usually in a non-forensically sound manner. This would then undermine any disciplinary and legal proceedings.

As with any incident response and investigation, all those involved need to be skilled and knowledgeable practitioners in their field and follow clear procedures, such as the CPNI First Responder’s Guide and the ACPO Good Practice Guide for Computer-Based Electronic Evidence.

Future Forensics
I expect issues to develop with increasingly smart mobile devices, online / cloud / Web 2.0 services and storage, encryption, mass storage and anti-forensics tools. Emerging techniques such as live and remote forensics will continue to develop, to try and keep up with technology and the bad guys.”

A PDF version of the magazine is available online at:

http://www.bcs.org/upload/pdf/isnow-winter09.pdf

ISNow – Internet Security

The following introduction was originally published in the BCS Information Security Now Magazine, Autumn 2008 issue (Volume 3, Issue 1), which was on the topic of Internet Security:

“There is a lot of talk about the Internet being a lawless Wild West, but in reality much can be, and is being done, to address Internet security. So who are the players and what can they do to help?

  • Law Makers should draft laws and regulations in such a way that they can cope with rapid technology change and are applicable in an international context.
  • Law Enforcement should work in partnership with ISPs and security & safety initiatives and develop effective international co-operation with other jurisdictions.
  • Security & Safety Initiatives, such as Get Safe Online and the Internet Watch Foundation (IWF), should receive adequate funding & support and be promoted.
  • ISPs should apply good security practice, self-regulate, support law enforcement and security & safety initiatives and pro-actively deal with abuse reports.
  • Vendors should ensure that their products are developed robustly and securely, be responsive to vulnerability disclosures and educate their users on secure use.
  • Security Researchers should be responsible when disclosing information on critical vulnerabilities, especially when hard to fix or exploitation would have a significant impact.
  • Online Services, especially banking and e-commerce websites, should operate securely and educate their users as to online risks and secure use.
  • Users should comply with their ISP’s acceptable use policies and local laws along with paying attention to security & safety initiatives targeted them.

As can be seen above, there are many players involved in Internet security and safety – and no solution is possible without working with them all.”

A PDF version of the magazine is available online at:

http://www.bcs.org/upload/pdf/isnow-autumn08.pdf

ISNow – Identity Management

The following introduction was originally published in the BCS Information Security Now Magazine, Summer 2008 issue (Volume 2, Issue 4), which was on the topic of Identity Management:

“Is your identity simply based on your DNA, or is it more ephemeral and flexible? Is it limited to what is on a card or in a database? Can your identity be stolen, or merely assumed? There is no black and white with identity, merely shades of grey.

Someone may have multiple ‘identities’, to suit particular purposes – e.g. banking, dating, online (public / private), acting – with legitimate or criminal intentions. On the other hand, government and business often need to uniquely identify the people they interact with. This does not predicate a universal identity, but multiple John Smith’s have to be managed.

To authenticate someone’s (claimed) identity, there are four common methods:

  • something you know – e.g. password, PIN, mother’s maiden name
  • something you have – e.g. identification card, authentication token
  • something you are assigned – e.g. name, NI/NHS number, IP address
  • something you are – e.g. fingerprint, retina, DNA, voice, signature

The risk of misidentification is managed through the appropriate selection and application of these authentication methods and their associated data. Generally, the more factors that are used the stronger the authentication and greater the accountability, but this needs to be balanced against usability and failure rates.

If you’ve managed to get beyond (mis)identification then there needs to be a link to a level of authorisation for each user. These rights need to be properly maintained for each role or user, as this is the second step in identity and access management.”

A PDF version of the magazine is available online at:

http://www.bcs.org/upload/pdf/isnow-summer08.pdf

The Blog of Gareth Niblett