Information Security in the Real World. Confidentiality, Availability, Integrity, Practicality.

Wednesday, 16 February 2011

Information Wants to be Free 2.0.

It's a refrain from the early days of computer hacking. A rallying cry of hackers, anti-censorship activists and just plain anarchists it dates back at least to the mid-80s use by Stewart Brand, while the phrase "Information wants to be free" has been used by bloggers the world over to justify the current Wikileaks phenomenon. But the phrase has a new connotation, a new white paper from Intel quotes the old hackers mantra as one of five new "Irrefutable Laws of Information Security".

Intel's use of the phrase recognises the fact that employees, associates and outside agents regularly find ways around our efforts to contain our data and many do so without malice but in order to get their job done. We should therefore recognise this behaviour and manage it, instead of trying to limit or quash it. This is genuinely refreshing stuff from a big name, and is a timely response to David Lacey's call for new standards and security models. The five "laws" in Intel's model are:

  1. Information wants to be free
  2. Code wants to be wrong
  3. Services want to be on
  4. Users want to click
  5. Even a security feature can be used for harm.
The full article explains these laws and how Intel has devised new models to achieve security within them, including the "Trust Calculation" to provide an access control model flexible enough to support remote working with a variety of portable devices and locations. 

As someone who has been suggesting for a while that compliance does not equal security, and the human factor is much much bigger than most of us credit, I think this is genuinely forward-thinking stuff and I look forward to the Information Security industry's response.

Thursday, 13 January 2011

Mainframe Security, PCI-DSS and other docs

Sorry, I've been busy with my other blog for a while, about System z (IBM mainframe) security, which if you missed the announcement is over here on IBM's developerworks.
I'm delighted to be able to tell Practically Secure: readers that I've written an article for respected mainframe magazine z/Journal, discussing mainframe security. While it's mostly about System z, the general concepts (including the paragraph entitled "Secure for Compliance, Don’t Comply for Security" will be of interest to all. Some of you may be familiar with the content if you've been reading me long enough.
z/Journal is here, and my article in the Dec/Jan issue can be read online in HTML format here.
For completeness, here are my earlier white papers written for Pirean.com (all rights reserved by them) covering mainframe compliance, and PCI-DSS.

Wednesday, 29 September 2010

InfoReck blog, great minds etc...

I'm delighted to have found this blog, written by Robb Reck, because we share a common belief that Compliance does not equal Security, and worse, that Compliance efforts can make you less secure. This post summarises his position and is essential reading for Infosec professionals and CISOs.

InfoReck» Blog Archive » Security Leads to Compliance

Amusingly we both wrote mid-year on the subject of compliance regimes hindering security efforts. I swear I had not read Robb's column before writing mine. Enjoy.

Thursday, 26 August 2010

55% care about PCIDSS

41 of 74 respondents to a poll on Anton Chuvakin's Security Warrior blog put PCIDSS top of their list of concerns. Alright it was a leading question and unscientific, but I'm pleased to see such interest anyway. Maybe this reflects the looming Level 1 deadline for full compliance and regular audits. Maybe it's the fact that the PCI are now collecting fines at an alarming rate. Whatever, up to now we've seen a very slow uptake for a mandatory standard with tough penalties and this is good news. I guess the standard's arrival during a recession has caused a bit of a "wait and see" attitude in the boardroom. But this is risky. PCIDSS is not just another regulation. If you're not compliant, you're at risk of serious fraud, data loss and reputational damage.

You shouldn't comply with PCIDSS to get a tick in the box and a certificate for the lobby. You should do it to preserve your business.