Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, March 4, 2015

The CISOs evolving role in a cloud-first world

As cloud-first becomes more dominant in organizations looking to balance risk, cost and agility, the role of the CISO will change dramatically.  The CISO and their team will have to evolve from policy and compliance (P&C) to a model of policy and enablement (P&E).

Many CISOs have organizations today focused on the identification of threats or organizational security and violations or corporate security policy. Activities can include application scanning, penetration testing, event monitoring and identification of vulnerabilities in homegrown applications. 

As organizations move more applications to cloud platforms, the role of the CISO and staff will evolve to support the business units that are driving the migration and new application deployments.  The CISO support for the business units will come in the way of education and enablement to allow the business to be successful when using cloud resources. The CISOs role will become about engagement with lines of business to provide enablement and advisement.  The role of the CISO, to effectively enable the organization, will be about establishing habits and education about securely managing the business, picking vendors and implementing new technology.

The key with this shift in focus will be for the CISO to be seen as an enabler and partner to the business.  The primary driver for most business organizations leveraging cloud resources is the ability to quickly deploy new capabilities to enable staff to be successful.  The CISO can partner with the business with this goal in mind, realizing that security enablement can be done in parallel to deployment and enable, rather then prevent, new capabilities from being deployed.

Even in this world of change, there are roles and responsibilities that will continue to be the primary focus of the CISO; these include definition and execution of incident response policies.   Even as the role of the CISO changes in the cloud first world and areas of focus evolve, the need for centralized incident response will not be eliminated in an organization.  The CISO will continue to be the focal point for this responsibility.

As more and more organizations look to the cloud to enable rapid deployment of new capabilities and technologies for enabling business users, the organizational dynamic around security will evolve as well.  The CISO will lead this change through focusing on enablement and education across the organization through sharing of best practices, policies and knowledge on how to securely leverage cloud-resources.  The CISO will continue to play a primary role in policy creation, incident response and incident management, while leveraging staff for new roles like education and partnering with business leaders on organizational priorities.

Tuesday, February 17, 2015

Security as a business enabler

All organizations today are worried about the security of their data and systems.  As more data is collected, the requirements and expectations for proper access to data have grown.  This is magnified by the growing media coverage of many spectacular breaches and compromise of large amounts of personal information.  For an organization to be successful into this environment risk associated with data must be properly understood and managed.

Security is a difficult scope to define for most organizations because it varies widely based on industry-specific standards, regulation, cost components and local laws.  Many organizations create a budget for security and it is up to specific departments to manage to that budget.  Security should not be a budget, but rather a prioritization of exposure of the company and a balanced approach to each risk for the cost of incident response weighed against the cost of preventing an incident.

While the goal within all organizations should be zero incidents that cause data loss or compromise, this is a difficult goal because of an increasingly mobile and interconnected world.  Organizations should begin with defining what the consequences of lost data are.  Many organizations have data that falls on various places on a spectrum from no consequences, through reputation loss, all the way to legal consequences.  Security planning and implementation should focus on the data sets with the highest level of consequences first.

Once the data with the most severe consequences has been identified, an organization should define the threats and actors associated with that data set and creating a risk to the data.  By understanding these threats and actors, an organization can begin to define data protection standards and incident response plans that factor in organizational needs for business continuity and legal requirements for reporting to various agencies.

From these protection plans and incident response plans a cost can be identified to secure the data from compromise and respond to compromised systems.  This process can be followed iteratively for all data sets and applications within an organization, creating a financial impact plan that can be prioritized to ensure spending focuses on the highest risk data and applications.

This exercise will enable your organizations CISO to closely align with peers including the CMO, CFO and CIO on prioritization of risk management to the organization.  Alignment between the CISO and peers is critical to ensure that all parties understand the spending priorities, as well as how industry standards like privacy for their specific areas are affected by potential data loss.  Proactive engagement also enables the CISO to properly plan for systems that are purchased and managed through lines of business like Marketing and Sales operations.


The final goal of a CISO should be to properly prioritize spending against the items that pose the highest risk to an organization.  This risk comes from the cost of compromise and associated legal requirements for response.  By partnering with peers, the CISO can properly plan which data is of highest value to protect within an organization and ensure that line of business purchased systems and tools are included in this prioritization.

Thursday, February 12, 2015

Unlocking the value of Big data in the Cloud

Successful businesses today are data driven and focus on fast iteration.  The ability to quickly test new products, features and user experiences; while measuring the impact and adjusting user experiences in an iterative fashion.  Cloud based Big data solutions enable organizations to quickly deploy new technologies, integrate with existing business systems and iterate the solution as business needs change.

While most organizations have a cloud-first policy, many also still stick to traditional architectures for new systems because of experience and comfort by staff with on-premise based solutions. On-premise based solutions provide a level of comfort through experience with previous implementations, but can also insert unnecessary delays into delivery of capabilities to the business.  Struggles with current on-premise technologies can include:
  • Delays – The time necessary to deploy on-premise solutions is often measured in weeks and months.  This time is a combination of working with vendors, waiting for equipment to ship and finally installing and configuring new systems.
  • RiskIn todays environment of complex IT systems and changing business requirements, all new application deployments have risk associated with project failure, cost over runs or changes to business requirements.  On-premise solutions have a longer design cycle, because the cost of a failure project is much higher in resources, capital costs and recovery time.
  • Capital Costs – On-premise solutions have higher capital costs because of the initial hardware and data center space required to begin.  These capital costs are often difficult to absorb in organizations with tight budgets and limited cash flow.
  • Scalability – Scaling with on-premise solutions means keeping spare capacity around with the expectation that it will be needed.  Often this means over provisioning environments to ensure proper response time and hedge against delays in purchasing additional capacity.

There is a lot of comment in the technology community that Big Data in the Cloud has limited adoption, the reasons vary, but often include cost, security and compliance concerns, and performance.  While there were periods of time, that technology maturity did create these challenges, the speed of evolution with cloud based solutions has enabled Big data platforms to be efficient and effectively deployed today, speeding time to value for the business and new capability adoption.

With advances in technology, the ability to build Big data platforms in the cloud can speed adoption, lower risk and increase security through consistency in deployment methods.
  • Agility – Cloud providers like Amazon and Google have a variety of different tools for building Big data environments.  These tools span NoSQL capabilities, unstructured text processing and relational environments for supporting transaction processing.  Modern Big data environments require multiple tools for creating integrated pipelines for data ingest, analysis and presentation.  These cloud solutions enable users to quickly spin up new capabilities, one piece at a time, test them and either put them in production or turn them off.
  • Elasticity – The primary value of any public cloud environment is the ability to almost-immediately scale capacity up and down based on your specific user and workload demands.  This ability ensures prompt response on all workloads and minimizes expenses related to unused capacity.
  • Security – A key component to security is repeatability and ensuring that operations staff do not create security threats through misconfigurations.  Cloud environments create simple, easy to reproduce methods for deployment of systems, connectivity and access controls. 
  • Data Mashup – Many public cloud providers provide access to local, public data sets for combining with in-house data.  This data is locally accessible, eliminating transit costs, and often low cost to access for testing model creation or other analysis.
  • Optimization –Cloud based applications gain the performance advantages of optimization across thousands of users and varying workloads.  Each cloud provider works to ensure that queries on large data sets are optimized and provide rapid response to users, without specific tuning by the users.
  •  Risk –Cloud based solutions enable organizations to quickly change priorities and operational requirements.  Because cloud resources have no up front commitments or long term contracts, organizations can adjust or eliminate resources that are unneeded temporarily while business needs adjust and clarify.
  • Capital Costs – Cloud based solutions eliminate the large capital costs traditionally associated with data center builds outs and server purchases.  Organizations can begin projects small, with minimal budget impact until project success is proven.

With the continued rise of both capability and agility with cloud-based offerings, Big Data platforms can be successfully deployed, with minimal risk.  Cloud based Big data solutions give organizations the ability to quickly test new capabilities, minimize capital costs and scale the environment as needs change and grow.  Big data solutions enable organizations to quickly analyze complex data, make informed decisions and measure the impact of changes to their business model.  Cloud based solutions ensure that the features and capabilities needed to build these environments can iterate just as quickly.

Tuesday, January 13, 2015

Data security with highly nomadic users

There was a time when data was able to stay within an organization – servers were in the company owned data center, users were in their offices and laptops were a dream, tablets not even conceived.  Data security in this setting was easy, it stayed in the office and the office had physical controls of who could come and go and passwords on who could login.

Today, users need to work anywhere, this means that data, often confidential, must be circulated and shared so that these nomadic users can access it. This introduces lots of risk about data locality, lost devices, captured data in transit and prying eyes.

A highly nomadic user is one that needs the same access and capabilities, regardless of location to execute their job duties. Highly nomadic users may use a variety of devices, some company owned and others personally owned, but will require the same levels of access. Nomadic users will change behavior patterns based on projects, deliverables and end-customer requirements.

In the world of cloud-first IT, many organizations have to change their security posture to more closely align with a nomadic workforce and the behaviors that go along with it.  Cloud first for many organizations means quickly deploying applications or migrating applications to public cloud solutions.  While this can provide benefits for the financial aspect of IT operations, security must be considered because of the changes in application architecture, user profiles and data storage.

We know how to authenticate users and we know how to encrypt data. What we are still learning and developing is handling the social aspects of data.  Who accesses the data? How is it combined?  These are all solvable problems with today’s technology, but need to be thought of up front.  Security is only as good as the weakest link, policies for passwords are no use if the passwords become so complex the people write them down.  Encryption is of no use if key management is not handled in a consistency security and reliable fashion.

A few scenarios that affect nomadic users:
  • Imagine someone is checking an email in a bar, another individual casually peers over the first individuals shoulder and sees a confidential client name and M&A in the title.  That is a serious breach of confidentiality. How do you train staff to be vigilant? How do you protect from highly sensitive data being inadvertently seen in public locations?
  •  Imagine an employee that uses a personal device and has a habit of downloading everything locally.  This employee then resigns to work at a competitor and connects their personal device to that competitors network.  How do you track what information they had locally? How do you make sure they removed it when they left? How do you ensure it is labeled as confidential? How do you monitor public sites to ensure that information is not leaked?
  • Imagine a user that regularly accesses confidential information about M&A activity is working in a coffee shop and has his laptop stolen when he gets up to place an order. What information did he have on that laptop? What deals did he have info about? Encryption and passwords only solve part of the problem.

Security should always be part of initial application design, even for POCs.  There is often not enough time after a POC to go back and refactor to be secure before going into production.  Many organizations will forgo security design and feature development as part of rapid prototyping or POCs.  The struggle comes when that initial code becomes production, even when the initial expectations were to rewrite things for production, but expediency won out.  Even POCs and prototypes should include a framework and features for basic security like encryption and authentication, making addition of features simpler as time goes on.

The solutions are technical, procedural and habit driven. All three considerations are required to ensure secure environments with nomadic users. 
·      Technical – Every application should have a plan for how data will be handled end to end, with a risk assessment of how nomadic users will access the data, use the data and potential points that data could be compromised.  Technical architectures should then have design guidelines for how data is handled, encrypted, shared with other systems and audited in a reproducible way.
·      Procedural – Every organization should ensure that the processes used for development, collaboration and architecture include checkpoints for security.  These processes do not need to be heavyweight, but do need to have checkpoints to ensure that security of the data and users are accounted for in design and testing.
·      Habit – A lot of security posturing is about the habits of those developing and using specific applications.  A culture should be established of security-first for all IT work and reinforced for all staff.  These habits become the key to protecting the company as change in applications occurs and new features are brought online.


Often times with modern tools the data itself is not nomadic. The core information being used to generate the report is sitting safely in a datacenter far away.  The nomadic part is the discussion about it (email) and the results (graphs, reports, presentations). This nomadic aspect of data presentation, viewing and sharing should be a key component of all application and big data solution designs.  Design considerations should include where data is stored, how it is viewed, compliance and response to incidents.  This up front planning will lower the risk of compromise, and ensure a solid foundation for later growth of the application without expensive and complex refactoring.

Tuesday, September 18, 2012

Adopting Hadoop in the Enterprise


Apache Hadoop is one of the hottest technologies today, garnering attention from small startups to the largest corporations and government agencies.  Hadoop provides the middleware need to store and analyze very large data sets, while enabling businesses to make better data driven decisions.

Hadoop started as an internal project at Yahoo and was eventually released as an open source project called Apache Hadoop.  Other prominent technology companies including Facebook, eBay and Nokia quickly adopted Hadoop and began contributing back to the Hadoop community.

Because of the origin of Hadoop, many of its features and usage models are targeted at web scale companies with highly differentiated operational models like Facebook.  These features and design decisions, while worthwhile for these web scale firms, are not always a good fit for the varied operational models that are used in traditional enterprise IT environments.

Traditional enterprise IT environments are characterized by mixed environments of many different software packages, hardware platforms and storage platforms that must integrate and coexist.  Enterprise environments often have much different requirements for monitoring, lifecycle management and security then single, highly integrated platforms like Facebook and Amazon.

Many web scale firms have the luxury of building out internal monitoring and orchestration frameworks that are tightly coupled across the environment.  Compare that with the often fractured and legacy deployment struggles that are common with enterprise computing shops and you see that enterprise computing environments have a unique set of needs when deploying scalable, open source software.

To ensure Hadoop is successful in your enterprise, you should start by evaluating what features and functionality are a priority for your deployment; that can then be used to determine the optimal Hadoop distribution, additional tools or custom development that will be required for Hadoop deployment in a production environment.

Some common areas of consideration for running Hadoop within an integrated enterprise are:
  • Access Controls – With any consolidation of data, the access to that data becomes a primary concern for the organization.  Hadoop provides minimal capabilities for limited access to data, and does not come close to the cell-level granularity that is commonly expected within enterprise software.  There are several projects associated with Hadoop that look to overcome this category of problem, including Accumulo, Zettaset, Sqrrl.
  • IDM Integration – Integration with outside authentication mechanisms is important to ensure that a users’ identity is tracked across all interconnected applications.  Hadoop has the ability to leverage outside systems including LDAP and Kerberos for user authentication.
  • Monitoring/Auditing/Alerting – Understanding what is occurring within a Hadoop environment is key in ensuring stability, a managed lifecycle and the ability to take action to user feedback.  The tools that are deployed for managing Hadoop should encompass for the entire lifecycle of managing the cluster and provide an integrated view into the users, applications, Hadoop core and hardware to enable administrators to quickly make changes to the environment and assess there impact.
  •  Skills & Expertise – Hadoop is a new technology and as a result the market of job candidates has not caught up to the demand for Hadoop skills.  When developing a team a two-angle approach is recommended.  First, enable existing staff time to obtain training and hands on experience with Hadoop and it’s supporting technologies.  Second, leverage outside consulting expertise to help train, and assist the organization as they deploy new technologies.  These two methods balance the need to ensure skills are available in the organization long term, with the immediate need to deploy new technologies in a low-risk, proven architecture.
  • Legacy System Connectivity – Hadoop is rarely deployed as a standalone island within IT, more often it is a connection point between other data repositories, BI tools and user access technologies.  When defining Hadoop deployment strategies it is key to account for the end-to-end flow of the data in the organization to ensure the right tools are in place to facilitate this movement and any transformation of data.  Some proven tools for this are Pentaho Data Integration, Informatica and Syncsort.
  • Process Modification – As with any new technology, organizational changes are going to occur around how people execute daily tasks.  As Hadoop is deployed, it is important to plan for process changes across the organization to ensure that value is gained from this new tool and that the new types of information that can be gained from Hadoop help to drive decisions within the organization.
  • User Empowerment – As with any new technology, not all users will be able to utilize Hadoop on day one.  Some users will prefer more graphical interfaces, while others will prefer a software development interface.  As IT departments deploy Hadoop, all user types should be considered to ensure they have access to tools that meet their usage models, their skills sets and the flow of their daily jobs.  Some common tools to deploy along with Hadoop are Pentaho, Datameerand Karmasphere.


Hadoop is not easy.  That is a function of both new capabilities on the market that are still maturing, as well as the flexibility of Hadoop that enables the power it provides.  Both can be overcome by careful planning, slow, methodical rolls outs and the upfront investment in expertise to assist and drive Hadoop deployments in your environment.

Saturday, August 18, 2012

Vectors of Information Security


Within the realm of information security, a lot of focus is paid to the vectors of attack. Essentially how an attacker can go after your networks, systems, people and information. These vectors focus on how the attacks can occur, how to detect and respond to them. But they only hit on part of the challenge in securing todays complex information technology (IT) environments.
Vectors of Information Security start with a definition of what behavior is allowed and then monitor and react to anything outside of that defined criteria. Most information security policies state policies in the form of “Administrators will deny access to those not allowed”. In the form of VIS, we will say that “Active employees are allowed access” and respond to all access outside that form. This is a variation of the security models focused on policies based on denying access and is a change in mindset for many security professionals.
More critical then the vectors of attach, are the overarching Vectors of Information Security (VIS). These correlate to the overall usage of information and allow Architects, Administrators and IT Leadership to plan accordingly for information access and risk management around expected usage patterns. The three Vectors of Information Security are:
  • Paths of access – This category focuses on all the tools, technologies and applications that allow access to a corporation’s data. This includes both data in transit and data at rest.
  • Paths of change – This avenue is for documenting and understanding how information changes; information can include access logs, configurations, customer information and financial information, just to name a few.
  • Paths of risk – This is the category that vectors of attack will become part of. Path of risk is the likelihood that an unknown, unacceptable or unanticipated event will occur and the associated cost to the organization for the incident.

Information security is about risk management and mitigation. The Vectors of Information Security enable organizations to outline clear policies for understanding, managing and responding to the risk that is inherent with todays interconnected systems.