IAM / IdAM / Single Sign-On (SSO) / Privileged Access Management (PAM) / Multi-Factor Authentication (MFA) / Identity Providers (IdP) / Identity Federation are all part of a program that enterprises should focus on these days. And, these programs need to be able to extend to multiple technologies: cloud, mobile, IoT, ERP, etc.
However, these endeavors are treated as one-offs.
As organizations wrestle with business transactions (merges, acquisitions, divestitures), the need to have a formal, organized IAM / IdAM program grows in need.
Monday, November 21, 2016
Saturday, October 29, 2016
Best Control Framework for HIPAA / HITECH Audits / Reviews
While many are adamant about using NIST SP 800-53a Rev 4~ for HIPAA / HITECH there is precedent for using alternatives.
Preference should be given to hybrid frameworks that use HITRUST CSF and / or ISF SOGP as they use a combination of 800-53, COBIT, and / or ISO.
The genesis for building on controls are the new technologies, new attack vectors / threats, and a renewed emphasis on deeper dives into the proper deployment of controls / safeguards.
Preference should be given to hybrid frameworks that use HITRUST CSF and / or ISF SOGP as they use a combination of 800-53, COBIT, and / or ISO.
The genesis for building on controls are the new technologies, new attack vectors / threats, and a renewed emphasis on deeper dives into the proper deployment of controls / safeguards.
Tuesday, October 18, 2016
Corporate IT & the Leadership Paradox
With over a decade of experience in consulting, one can see the leadership paradox, especially in corporate IT departments.
Corporate IT executives and managers often move into consulting to embrace their experience while negating the office politics, while many middle managers move into corporate IT from Big 4 consulting firms.
Furthermore, many corporate IT shops ship out work to consulting firms instead of training their own people, while many consulting firms leverage people more junior than their client's staff.
Add to that, the reticence for IT shops to send junior managers to leadership training, and we see a revolving door of poor leaders who focus on leveraging external parties to get the work done.
No wonder IT outsourcing is so strong.
Corporate IT executives and managers often move into consulting to embrace their experience while negating the office politics, while many middle managers move into corporate IT from Big 4 consulting firms.
Furthermore, many corporate IT shops ship out work to consulting firms instead of training their own people, while many consulting firms leverage people more junior than their client's staff.
Add to that, the reticence for IT shops to send junior managers to leadership training, and we see a revolving door of poor leaders who focus on leveraging external parties to get the work done.
No wonder IT outsourcing is so strong.
Monday, October 10, 2016
Data Breach Fatigue & Security Training
Apparently, there is "data breach fatigue" out there and recommendations on cutting down security education, training, & awareness (SETA) is gaining traction.
The question comes with to scale back SETA activities due to this fatigue?
The answer is based on the maturity of the information security (InfoSec) program, jurisdiction / market, industry, and the organization's culture. Frankly, a CISO / CIO / CTO should negotiate freedoms (e.g., local administrative access, open Internet / Web / email access) pursuant to SETA. Meaning, that if users have carte blanche then SETA is required, necessary, and regularly conducted.
Also, less SETA should equate to more budget for preventive / detective capabilities.
The question comes with to scale back SETA activities due to this fatigue?
The answer is based on the maturity of the information security (InfoSec) program, jurisdiction / market, industry, and the organization's culture. Frankly, a CISO / CIO / CTO should negotiate freedoms (e.g., local administrative access, open Internet / Web / email access) pursuant to SETA. Meaning, that if users have carte blanche then SETA is required, necessary, and regularly conducted.
Also, less SETA should equate to more budget for preventive / detective capabilities.
Monday, September 19, 2016
SaaS AI & Privacy
Salesforce's AI platform, Einstein (https://www.salesforce.com/products/einstein/overview/), may present some privacy concerns.
As a SaaS service the question begs on whether multi-tenancy data will be included in the analysis.
Will GDPR, U.S., Privacy Shield, HIPAA, PCI DSS requirements be included? If so, it would behoove Salesforce to include details on de-identification.
As a SaaS service the question begs on whether multi-tenancy data will be included in the analysis.
Will GDPR, U.S., Privacy Shield, HIPAA, PCI DSS requirements be included? If so, it would behoove Salesforce to include details on de-identification.
Labels:
AI,
Einstein,
GDPR,
HIPAA,
PCI DSS,
privacy,
Privacy Shield,
SaaS,
Salesforce
Friday, September 16, 2016
Leveraging ITIL PPT for GRC, TVM, & DevSecOps / InfoSecOps
Many orgs now have some form of ITIL investment (PPT) in place (e.g., ServiceNow: SNOW, ServiceDesk, SAP Ariba) these days.
Why not leverage that for PCI DSS / GPDR / HIPAA / Privacy Shield compliance, let alone for other purposes (e.g., TVM, DevSecOps / InfoSecOps)?
Many ITIL tools have workflows that can automate tracking, reporting, etc.
Leverage existing tools for data processing in your ecosystem, and your ROI will increase dramatically.
Why not leverage that for PCI DSS / GPDR / HIPAA / Privacy Shield compliance, let alone for other purposes (e.g., TVM, DevSecOps / InfoSecOps)?
Many ITIL tools have workflows that can automate tracking, reporting, etc.
Leverage existing tools for data processing in your ecosystem, and your ROI will increase dramatically.
Labels:
Ariba,
DevSecOps,
GPDR,
GRC,
HIPAA,
InfoSecOps,
ITIL,
PCI DSS,
Privacy Shield,
ROI,
ServiceDesk,
ServiceNow,
TVM
Wednesday, September 14, 2016
Incident Response vs Digital Forensics
When an incident / event has happened that may turn into a full-scale breach it is best to ascertain (via a defined process / guide like 800-61) whether or not to engage in digital forensics or not.
However, beyond firing up forensic kits / tools like Sleuth / Autopsy, forensic activities may have adverse consequences as operations may be affected.
Many orgs want to be safe vs sorry, so they engage in forensics to check if there was a breach, though this may be not needed and may even be construed as impetuous.
Predicated on a quick notification on the event due to proper security education, awareness, and training (SETA); initial, cursory actions may be all that is needed. At least, initially.
However, beyond firing up forensic kits / tools like Sleuth / Autopsy, forensic activities may have adverse consequences as operations may be affected.
Many orgs want to be safe vs sorry, so they engage in forensics to check if there was a breach, though this may be not needed and may even be construed as impetuous.
Predicated on a quick notification on the event due to proper security education, awareness, and training (SETA); initial, cursory actions may be all that is needed. At least, initially.
Subscribe to:
Posts (Atom)