Another post has popped up. This time from The Hoff. I think general consensus is that you will probably disagree with him at some stage, but you have to read his blogs.
Anyhow, he posted a question from someone at a conference he was at:
Why can't you InfoSec folks quite simply come to your constituent customers -- the business -- and tell them that your efforts will make me x% more or less profitable?
My answer to this is the following: Please correct me if I am wrong because I am probably very biased.
A modern business is essentially a group of people who know how to do something. A doctor is a person who knows how to cure people. He has studied and has certificates and such but at the end of the day if he loses his memory - he is no longer able to cure people and is not worth very much.
A little larger - a company that makes car tyres. There are some people who handle the books of the business and manage the investments of the company, manage the money etc. There are engineers who design the tyres and make them the best way possible. There are the sales reps who sell the tyres in the best way possible. The real value of the business is not the tyres and buildings and such... it is the information that the people know. Some of it is in their heads, some of it is in databases. Some of it is just a culture. But take all of that information away and you have a bunch of useless people hanging about and some desks.
Business today is quick. A company can close down in a few months and a new one can be built up in days. It is relatively simple to get capital. It is fairly easy to get premises, phones, cars, etc . It is not easy to get staff who know what they are doing. That is where the real value of a business is.
So, essentially a business relies on its information to stay alive and to grow. If you lose information, a part of the business is lost.
Steve Ballmer knew this when he lost Mark Lukovsky to Google - he was losing some of Microsoft.
The American Government knows this which is why there is legislation making sure companies protect their systems. Information loss is business loss.
So, the answer to the question is - how much is your entire business worth? Take away the net value of the desks and coffee machines and that is how much information security is protecting. HR is involved in protecting the information inside the heads of the staff so you may want to minus that.
Everyone in the organisation is either creating information (this CEO, accountants, etc) or using information to build products or perform services (think craftspeople, packers, factory workers). Only Information Security is tasked with making sure that the information is available and stays inside the company.
Where is most of the information contained? What is most at risk? That is not so easy to answer but is important to us doing our jobs. Should business be concerned? I'm not sure, I don't think so. Should infosec be required to cough up figures so that we can do our jobs? I really don't think so.
But I could be wrong. What do you think?
Showing posts with label Information. Show all posts
Showing posts with label Information. Show all posts
Thursday, November 29, 2007
Friday, September 21, 2007
Seven Habits of Highly Effective Security Plans [Part 3]
In this post we deal with habit 1: Be Proactive
Please first read The Seven Habits of Highly Effective Security Plans [Part 1]
Please first read the Seven Habits of Highly Effective Security Plans [Part 2]
This is based on Stephen Covey's book The Seven Habits of Highly Effective People and in this post we look at how being proactive can help raise the general security of an organisation. This is applicable from a micro 1 person business to a multi-national company.
Being proactive really translates into taking ownership. There is a general feeling that Information Security is someone else's problem - usually IT. The thing is that even IT shelve the responsibility onto technology such as Firewalls, Antivirus and IDS boxes.
It has taken legislation in the United States and Europe (not so much in South Africa yet) to put Information Security risk back where it should be - the Business and by "Business" I mean non-IT people. Is this fair? Sure, it is their data and they must protect it from getting lost. Security is there to help and IT is there to make sure that the technology is there but at the end of the day if a spreadsheet with financial information goes missing - it is the department that owns the spreadsheet that is going to suffer.
Of course, all the three camps can be proactive. InfoSec can, should, must promote awareness of Security. They need Business and IT to understand what the dangers are and what is expected from a regulatory point of view. Posters, education, emails, etc etc can all be done.
IT can help by telling InfoSec of incidents that they may find, by making systems secure from the start, from being enthusiastic about patching and hardening servers and helping out with standards that are secure.
Business can be aware that it is information they use everyday that IT and InfoSec are protecting and the protection is for them so they can do their work more effectively which is what business is all about. They should strive to understand the tools that they use and how to use them securely. Strong passwords, clean desk policy, locking workstations, locking offices, thinking twice before opening strange files are all things that can be done for free and together are far more effective than anti virus, firewalls and NAC.
It is difficult to get the inertia going and people are reluctant to change but it is important to at least start working on a culture where information is seen as an important asset is protected as such.
I think this is lot more productive than playing each part of the business off against each other.
Please first read The Seven Habits of Highly Effective Security Plans [Part 1]
Please first read the Seven Habits of Highly Effective Security Plans [Part 2]
This is based on Stephen Covey's book The Seven Habits of Highly Effective People and in this post we look at how being proactive can help raise the general security of an organisation. This is applicable from a micro 1 person business to a multi-national company.
Being proactive really translates into taking ownership. There is a general feeling that Information Security is someone else's problem - usually IT. The thing is that even IT shelve the responsibility onto technology such as Firewalls, Antivirus and IDS boxes.
It has taken legislation in the United States and Europe (not so much in South Africa yet) to put Information Security risk back where it should be - the Business and by "Business" I mean non-IT people. Is this fair? Sure, it is their data and they must protect it from getting lost. Security is there to help and IT is there to make sure that the technology is there but at the end of the day if a spreadsheet with financial information goes missing - it is the department that owns the spreadsheet that is going to suffer.
Of course, all the three camps can be proactive. InfoSec can, should, must promote awareness of Security. They need Business and IT to understand what the dangers are and what is expected from a regulatory point of view. Posters, education, emails, etc etc can all be done.
IT can help by telling InfoSec of incidents that they may find, by making systems secure from the start, from being enthusiastic about patching and hardening servers and helping out with standards that are secure.
Business can be aware that it is information they use everyday that IT and InfoSec are protecting and the protection is for them so they can do their work more effectively which is what business is all about. They should strive to understand the tools that they use and how to use them securely. Strong passwords, clean desk policy, locking workstations, locking offices, thinking twice before opening strange files are all things that can be done for free and together are far more effective than anti virus, firewalls and NAC.
It is difficult to get the inertia going and people are reluctant to change but it is important to at least start working on a culture where information is seen as an important asset is protected as such.
I think this is lot more productive than playing each part of the business off against each other.
Thursday, August 16, 2007
The Wall Street Journal Followup
Since my posting on the 7th, the Wall Street Journal has posted a follow-up article here
It is by the same author who obviously was not aware of my post because she gets most of it wrong again. She chose to ignore Andy's input too. I found out about this follow-up from his Blog,thank you Andy.
My original post basically pointed out the main problem in her article which is that the Information Security policies that she is showing how to bypass are not made up by IT but by the security department. More to the point, they are signed off by upper management and by breaking them you can get into serious trouble with the Boss. Failing that the Boss himself may get into serious trouble with the law.
The author writes in this article about how "IT workers said they get blamed both by employees who feel too restricted and by company executives who, when things go wrong, fume that policies must not have been restrictive enough."
At the end of the day its not the It Guys who should be enforcing security, they have enough on their plates. It is business people themselves who should be enforcing the rules.
The IT department is usually the least respected department, it hires young people who don't know the art of dealing with people, especially those in upper management. More importantly - they are enablers. They fix things and make things work and that is how they are rated. They are also clueless (or they should be anyhow) about what information is important anyhow.
What about the fools in the Information Security department I hear you ask. They are there to make sure that Information Security is done, yes. But, at the end of the day neither them nor the IT guys will be in big trouble if Information is lost or leaked. Or wrong decisions are made using altered documents. It will be Business that pays. So, why have these lazy Information Security guys around in the first place? Really, its to inform the business people and to help them with implementing security.
If your staff are knowingly breaking rules that you have put in place... well... no Firewall, IDS or Antivirus or amazing CISSP is going to save your data.
I think that the WSJ has missed an opportunity to push the idea that Information Security is important and that the rules are there for a reason and that breaking them will not only upset the guys in IT but can make an employee lose the respect of his/her employers and possibly even his/her job.
It is by the same author who obviously was not aware of my post because she gets most of it wrong again. She chose to ignore Andy's input too. I found out about this follow-up from his Blog,thank you Andy.
My original post basically pointed out the main problem in her article which is that the Information Security policies that she is showing how to bypass are not made up by IT but by the security department. More to the point, they are signed off by upper management and by breaking them you can get into serious trouble with the Boss. Failing that the Boss himself may get into serious trouble with the law.
The author writes in this article about how "IT workers said they get blamed both by employees who feel too restricted and by company executives who, when things go wrong, fume that policies must not have been restrictive enough."
At the end of the day its not the It Guys who should be enforcing security, they have enough on their plates. It is business people themselves who should be enforcing the rules.
The IT department is usually the least respected department, it hires young people who don't know the art of dealing with people, especially those in upper management. More importantly - they are enablers. They fix things and make things work and that is how they are rated. They are also clueless (or they should be anyhow) about what information is important anyhow.
What about the fools in the Information Security department I hear you ask. They are there to make sure that Information Security is done, yes. But, at the end of the day neither them nor the IT guys will be in big trouble if Information is lost or leaked. Or wrong decisions are made using altered documents. It will be Business that pays. So, why have these lazy Information Security guys around in the first place? Really, its to inform the business people and to help them with implementing security.
If your staff are knowingly breaking rules that you have put in place... well... no Firewall, IDS or Antivirus or amazing CISSP is going to save your data.
I think that the WSJ has missed an opportunity to push the idea that Information Security is important and that the rules are there for a reason and that breaking them will not only upset the guys in IT but can make an employee lose the respect of his/her employers and possibly even his/her job.
Thursday, June 14, 2007
Information security done wrong can kill!
...really.
This morning I took a look at an article in the New York Times about the Virginia Tech Report.
This report was requested by the American President after Seung Hui Cho shot 27 students and 5 faculty members to death at Virginia Tech’s Blacksburg campus on April 16.
His mental health was shown to be questionable and he had been ordered by a Judge to undergo a psychiatric evaluation. But due to privacy restrictions when he applied for a weapon there was no record of this and he was legally able to acquire one.
When I say "privacy restrictions" I actually mean "assumed privacy restrictions". According to the report (and as stated in an article on examiner.com) schools, doctors and police often do not share information about potentially dangerous students because they can't figure out complicated and overlapping privacy laws.
So, they would rather "fail safe" as such and not release any information. Even though, in this case it would have saved lives.
Rule number one when dealing with people who are trusted with information - they need to know what they can and can't do with it and rules have to be crystal clear.
Kudos to the American government for seeing the problem and reacting to it by proposing a Federal bill.
This morning I took a look at an article in the New York Times about the Virginia Tech Report.
This report was requested by the American President after Seung Hui Cho shot 27 students and 5 faculty members to death at Virginia Tech’s Blacksburg campus on April 16.
His mental health was shown to be questionable and he had been ordered by a Judge to undergo a psychiatric evaluation. But due to privacy restrictions when he applied for a weapon there was no record of this and he was legally able to acquire one.
When I say "privacy restrictions" I actually mean "assumed privacy restrictions". According to the report (and as stated in an article on examiner.com) schools, doctors and police often do not share information about potentially dangerous students because they can't figure out complicated and overlapping privacy laws.
So, they would rather "fail safe" as such and not release any information. Even though, in this case it would have saved lives.
Rule number one when dealing with people who are trusted with information - they need to know what they can and can't do with it and rules have to be crystal clear.
Kudos to the American government for seeing the problem and reacting to it by proposing a Federal bill.
Thursday, March 15, 2007
Instant Virtual Machines
We all agree that INFORMATION is the important stuff.
Computers are there to basically make the information look good. Networks are there to move it all about to where (in theory) it is most useful.
Computers are not just all about presentation, they also mold data into useful information and other neat things. But its the Information that is king. That is why the general term for people that work with computers is "Information Technology".
So, why is everything we do there to protect computers? And networks.
If a computer is compromised - kill it. Stick another in its place. Instantly.
The technology is available to do this. But I haven't seen people use it.
Is it being used?
The way to do this is to keep the data on a separate drive to the applications (like Unix has always advised - welcome to the 70s, again) and if there is any doubt - kill the machine. And pop a fresh install in its place.
My 2c.
Computers are there to basically make the information look good. Networks are there to move it all about to where (in theory) it is most useful.
Computers are not just all about presentation, they also mold data into useful information and other neat things. But its the Information that is king. That is why the general term for people that work with computers is "Information Technology".
So, why is everything we do there to protect computers? And networks.
If a computer is compromised - kill it. Stick another in its place. Instantly.
The technology is available to do this. But I haven't seen people use it.
Is it being used?
The way to do this is to keep the data on a separate drive to the applications (like Unix has always advised - welcome to the 70s, again) and if there is any doubt - kill the machine. And pop a fresh install in its place.
My 2c.
Subscribe to:
Posts (Atom)