Friday, August 27, 2010

Information Classification Like Creative Commons [Part 2]

[Part 2 - A picture is worth a thousand words]


Following on from my last post on Information Classification - I think that this concept would be better shown by using examples. I guess that the irony of the last Blog is that I was trying to say "Using pretty pictures is better than using text" but I tried to do that in a Blog post which lacked pictures totally. Still, I did get some good feedback on the post even though my coments don't work. 


I have done a little bit more research and tried to find some pictures to show what I am aiming toward. 


These pictures are all from an icon pack I found here but I'm not sure what pack I would use when it is finished or even if I should make my own. These are just for demonstration purposes. Please don't steal these graphics (they are free so just follow the link). 


*deep breath* Here goes:


If a document contains anything to do with someone's medical condition or some such - it gets labled "Medical" and has the following graphic printed on it: 

If a document is confidential - it gets labeled "Confidential" and has the following graphic:


Then what you can do with the document is listed - so you can copy it to CD, email it, move it on the network and take it home:




If you are not allowed to do any of these things then a little circle with a cross through it will be added to the image. 

Putting it all together again - you have a piece in the footer of the document that says:


This document is classified as "Medical-Confidential". You may do the following: burn to cd, transmit internally, email outside of the network, take the document home. 
Then under that, you have the images to re-enforce. The important thing is that the images must be a standard set so that users across companies, regions, businesses, etc all can look at them and at a glance know what is expected from them regarding the document. 


For bonus marks it would be nice to have a tool that can automate this process. 



Monday, June 21, 2010

Quick Thought: Information Classification Like Creative Commons

[Stealing the CC Ease of Use Icons for Info Classification]

When something is complicated then it usually is quite wrong. I learnt this lesson with Firewall Rules. Usually when something was twisted around and not easy to understand it was because the Firewall was being used for a purpose ti was not designed for.

Information Classification is usually pretty easy to understand. It is logical. There is stuff you want the public to know about, stuff you don't mind them knowing about, stuff that you don't quite want them to know about and stuff they most certainly shouldn't know about.

There is also stuff that can't be shared outside of the company with out breaking the law or some "governance" and stuff that can't be shared overseas.

Finally, there is stuff that shouldn't be shared outside of a department such as "strategy stuff" or "HR stuff".

What you call these is just semantics and what you do to keep these where they should be is where the fun comes in.

Information Security is accused of being overly complex and it really shouldn't be. Much like copyright is (generally) complex. So, the good people of the Creative Commons worked out just how to separate the tricky-to-understand bits from the easy-to-understand stuff and get people using CC without having to read law at Harvard or some such. You choose the pretty pictures that show you what you want and voila.

So, can we do the same with Information Classification?

Friday, May 21, 2010

I'm Cool Like That...

So, it seems that I am following the trend with Blogging which is somewhere I am not proud to be but it is interesting just how closely I have followed this trend.

Statistics (when they are not manipulated) are ugly things. Sometimes they tell the truth like a little kid with no idea of how to be "nice". So here goes - my statistics of Blogs published on my site:

2007 - 78
2008 - 32
2009 - 34
2010 - er... 3

I had a lot to say in 2007 and a lot of time to say it. I accept that. 32 posts a year is not great, but it is not bad... 3 is pathetic. 

Its not that I have been busy.. I have been busy but not way way way more busy than in 2008/2009. I haven't moved my online conversations onto Twitter either. Twitter has impacted on my time a bit... but not that much that 1 blog post a week would break me. 

I just haven't blogged. And other people have stopped too. Rich of Securosis seems to think that Twitter is the reason but I think it is more about two other things - 

  1. I belive Information Security Bloggers (maybe other blogs too) have just emerged from the Trough of Disillusionment (go, go Gartner, go).
  2. Blogs tend to be mostly a one-way conversation but really are about gathering the ideas of what is floating about in the world and forming an opinion about it then writing about it. So technically its like a general conversation and if everyone has left the conversation then there really is not very much to discuss.
But we are coming back and most of us (me included) are just really blogging about how we have stopped blogging and are now back. But we'll get there... it has been a bit of an awkward silence but its ended. 

Monday, May 17, 2010

I am a hacker - whether I like it or not

[... and not the bad cyber criminal type.]

For the latest ITWeb Security Summit (which was amazing) I was chosen as a speaker.

I had the following challenge -

  • talk about the different InfoSec Standards available
  • do it at 3:40pm 
  • do it straight after the tea break
  • make sure that the attendees don't fall asleep
Needless to say - it took a lot of thought but I eventually managed to keep them interested according to some positive reports I got after the talk.

I'm not going to go into the details of the talk here but after quite a bit of re-assessment I realised that I had basically "hacked" the standards. Hacked - in the good sense. There was no "piracy" involved (me maytee) and everything was above board. (and above plank.) 

But to keep the attendees interested in the talk I basically took the standards and applied them in ways they were just not designed to be used. And that is the true definition of hacking. 

In the past 4-ish years or so I have tried to model myself as a serious Information Security Professional. I have tried to put away the "hacking" part of me and concentrate on "working for the Man" but it seems that, without me trying, that part of my brain will find a way out. 

So, I will set my aim for the next year to nurture the "hacking" side of my brain and mold it into something I can use as an Information Security Professional. 

Friday, May 14, 2010

Back.

Someone (who shall remain anonymous) took me to task about not blogging. Which is fair enough since I haven't done a blog post since the end of last year - nearly 6 months ago. And it was my aim for the last few years to be the most prolific Information Security Blogger in South Africa (which really means writing more posts than that particular person). And I have been losing the race quite badly recently.

On the other hand that person fell asleep while chatting with me. Which is actually more a comment on how much sleep he had had the night before rather than how exciting the conversation was. I hope.

But.... that someone had an interesting point which I think is quite right - my excuse that I have nothing to blog about is wrong - I should blog and things to write about will come to me. Thats sounds very Zen. Or Xen.

So, I am starting up the blogging again and I hope that all my faithful readers will forgive the lack of posts and come back to be challenged again. (I'm watching you - both of you!)

So, see you soon.

Monday, December 7, 2009

I stand by Gears!

So, no sooner had I posted the last post on my blog when I saw that Google are seriously considering dropping Google Gears at all.

Google are dropping support for the most important piece of software in the last 10 years?
Yes, and no.

Google introduced the world to the idea of offline applications by creating Gears. But maintaining it in all the different browsers and all the different Operating Systems (and variations of each) is painful. And was necessary until HTML5.

But HTML5 is a standard way to implement offline applications, it will be implemented in all browsers soon enough and it will be implemented in a standard way. And Google doesn't need to maintain it.

Google gets what they want and they don't need to support it.

One of the new features in Chrome that separates it from other browsers is the speed that it runs javascript. This became a major feature and forced Mozilla to speed their javascript up to compete. IE will do the same. (Mozilla had a faster javascript engine but they released it sooner than they would have otherwise done.)

So Google don't need Gears but it has already changed the world.