Showing posts with label 7 habits. Show all posts
Showing posts with label 7 habits. Show all posts

Friday, September 21, 2007

Seven Habits of Highly Effective Security Plans [Part 3]

In this post we deal with habit 1: Be Proactive

Please first read The Seven Habits of Highly Effective Security Plans [Part 1]
Please first read the Seven Habits of Highly Effective Security Plans [Part 2]

This is based on Stephen Covey's book The Seven Habits of Highly Effective People and in this post we look at how being proactive can help raise the general security of an organisation. This is applicable from a micro 1 person business to a multi-national company.

Being proactive really translates into taking ownership. There is a general feeling that Information Security is someone else's problem - usually IT. The thing is that even IT shelve the responsibility onto technology such as Firewalls, Antivirus and IDS boxes.

It has taken legislation in the United States and Europe (not so much in South Africa yet) to put Information Security risk back where it should be - the Business and by "Business" I mean non-IT people. Is this fair? Sure, it is their data and they must protect it from getting lost. Security is there to help and IT is there to make sure that the technology is there but at the end of the day if a spreadsheet with financial information goes missing - it is the department that owns the spreadsheet that is going to suffer.

Of course, all the three camps can be proactive. InfoSec can, should, must promote awareness of Security. They need Business and IT to understand what the dangers are and what is expected from a regulatory point of view. Posters, education, emails, etc etc can all be done.

IT can help by telling InfoSec of incidents that they may find, by making systems secure from the start, from being enthusiastic about patching and hardening servers and helping out with standards that are secure.

Business can be aware that it is information they use everyday that IT and InfoSec are protecting and the protection is for them so they can do their work more effectively which is what business is all about. They should strive to understand the tools that they use and how to use them securely. Strong passwords, clean desk policy, locking workstations, locking offices, thinking twice before opening strange files are all things that can be done for free and together are far more effective than anti virus, firewalls and NAC.

It is difficult to get the inertia going and people are reluctant to change but it is important to at least start working on a culture where information is seen as an important asset is protected as such.

I think this is lot more productive than playing each part of the business off against each other.

Friday, September 14, 2007

The Seven Habits of Highly Effective Security Plans [Part 2]

Please read The Seven Habits of Highly Effective Security Plans [Part 1] first.

Stephen starts his book with the idea of a paradigm and goes to great efforts to explain what it is and why one needs to understand it.

In terms of Information Security I think that the paradigm shift has been forced upon us on July 13, 2001 but it has taken until now for us to be able to understand and deal with the new understanding.

That was the date that the Code Red Worm struck. The darling of Security at the time - the firewall was no match for this worm and anti-virus was infective too.

Today the worm would be very much less effective because we now have more defenses. We have proper patch management, IDSs, deep packet inspection firewalls and application security. These were all around in the time of the Code Red Worm, they were just not being used effectively. We had the technology but the mind set was not right.

When the SQL Slammer Worm arrived it proved that we still hadn't learned our lesson. The paradigm shift had not happened yet but we are slowly getting there.

The fact that new worms are coming out all the time but we haven't had a global epidemic of Slammer proportions means that we are learning our lesson. The fact that the Storm worm is still being successful means that there is still some way to go.

Our first paradigm shift was from realising that:
  1. security has to be done all the time
  2. technology alone will not save us
I think the next one is that we can't tack on security. We need to think security from the beginning even if it means somethings need to be redesigned or abandoned totally.

To Be Continued.

Friday, September 7, 2007

The Seven Habits of Highly Effective Security Plans [Part 1]

I've been thinking about doing this for a while. I admire Stephen Covey and his book The Seven Habits of Highly Effective People. I have seen the book being used to manage huge companies and I think that the principals in the book are broad enough to be applied to pretty much anything including Information Security.

I think that the 7 Habits are already built into "Best Practice" already in most cases but this should allow us insight into why we need to do what we already do.

Do I run a highly effective Information Security Plan? I like to think that I am working on it. I also think I won't ever finish but going back to first principals is always a good idea.

I don't aim to rewrite the entire book, that would be pointless and quite illegal. I aim to use it merely as a guide.

Monday, March 12, 2007

[OT] 7 Habits of highly effective procrastinators

Sorry Mr Covey,

1. Be proactive - procrastinators don't have it easy. Its hard work doing nothing. Make sure you have a plan set up. What if someone discovers how little work you do? Make sure you have a messy desk so you look busy. Arrange false meetings, etc. Book your calendar full. Use your phone a lot. Browse website. Do a blog.

2. Begin with the end in mind - visualize how not to work, what you can be doing, how to get around obstacles like bosses and HR.

3. First things first - blah blah blah long term goals etc etc. You know the drill. Also delegate; if you have to do something make sure that its delegation.

4. Think win/win - if you don't work hard your company doesn't have to pay you much - win/win.

5. Seek First to Understand, Then to be Understood - make sure you understand your boss before you take advantage of the situation. Know his weak points, when he arrives and leaves, what time he takes lunch, etc. Those are the best times to read comics online.

6. Synergize - how to work in teams. Simple - the whole office has one big quake contest while one of you keeps a look out for the boss. Even better - use cameras. But the important thing is to work as a team!

7. Sharpen the saw - all work and no play make you dull - take some time off. Do some work even - shock everybody.

This is tongue in cheek - please do not think I do the above. 'Cept maybe Blog. Oops, theres the boss... until next time..