Showing posts with label Cyber Essentials Scheme. Show all posts
Showing posts with label Cyber Essentials Scheme. Show all posts

Wednesday, 13 August 2014

Cybersecurity: What the U.S. Can Teach Europe

Article originally published in FCW magazine.


By Edwin Bentley (Senior Software Developer, Titania) 

About the Author

Edwin joined Titania in 2011 and has since become a key member of development team, having primary involvement in advancement of both the Nipper Studio and Paws Studio software. He has a keen interest in Information Security and the role that the industry will play in the future advancement of technologies.


Having attended two reputable information security conferences this year, one on each side of the Atlantic, a few observations emerged on the differences and similarities of opinion on cybersecurity issues in the U.S. and Europe.

Although similar questions were raised at both conferences, the response manner was notably different. Europe took a reactive stance by signaling problems and bringing them to the attention of government agencies and legislators. The U.S., however, had a top-down approach, with industry searching for viable solutions in response to already adopted government directives.

The first event was Infosecurity Europe. The 2014 edition was hosted in London and attended by more than 11,000 information security professionals. With a 20-year tradition, the event is considered a reference point for the cybersecurity industry to find out about the latest trends and tools and keep up-to-date with European laws and compliance policies.

This year, the discussion focused on big data, the accelerated increase in organized cybercrime, the need to stay ahead of threats and an honest admission from Europol that cybercrime is best mitigated or disrupted because law enforcement lacks the resources to prosecute all crime. Staying ahead of threats was high on the agenda. Finally, there were comments on security issues in the cloud, which just like the bring-your-own-device trend, needs to be accommodated in its own right from a protection point of view.

Similar points were made at FOSE. (Editor's note: FOSE is owned and produced by FCW's parent company, 1105 Media.) As an industry event, FOSE is recognized as an official source for voicing the latest concerns in government IT. Among the issues discussed at the conference, cybercrime and cyber terrorism figured high on the agenda for defense and policy.


Continuous Diagnostics and Mitigation


In terms of security tools and trends, automation and continuous monitoring were held in high regard at the U.S. conference. The conversation on the FOSE floor focused on the Department of Homeland Security's Continuous Diagnostics and Mitigation (CDM) program. It comes on the heels of the National Institute of Standards and Technology's Cybersecurity Framework and is part of achieving the last step of that directive: monitoring security on an ongoing basis with the use of automation tools.

Released as a best-practice guidance document, the framework was embraced by the federal sector. After the latest high-profile breaches in the retail industry, a wide range of other companies have started to look at the framework as a template for assessing security practices.

In order to understand why CDM is seen as the best solution by IT professionals, below are a few well-debated problems it answers:

  • Top of the agenda for information security experts is how best to integrate security with business processes. Reducing user disruption and enabling business innovation will be more easily addressed with the introduction of automated security.
  • Although CDM does not guarantee that its users will stay ahead of threats, it does offer a near-real-time state of security with risk-based assessments reported and analyzed at network speed to ensure ongoing awareness and protection.
  • A challenge for chief information security officers and CIOs everywhere is the compliance versus security conundrum. CDM implies moving away from layer upon layer of compliance in favor of perpetual alertness and security.
  • The other issue in compliance is log aggregation and reporting. Continuous monitoring would produce automated event logs that can be filed for audits or analyzed for patterns in forensic investigations.
Continuous monitoring does not promise to answer every cybersecurity problem, but it offers a practical way forward. The voluntary adoption within the U.S. business community reflects that its advantages have been recognized.


Cyber directives in Europe and U.K.

Source: fcw.com
Meanwhile, that shift in security perception has yet to happen in Europe. The latest European Union cyber directive -- Network and Information Security (NIS) -- has been taken with a pinch of salt by the industry, and some organizations fear that the stick of compliance will come down hard on their budgets while doing very little for the state of their security.

In a similar way to the NIST framework, the U.K. government released a Cyber Essentials Scheme as a best-practice guide for organizations. Operating in a less intrusive manner with smaller, more practical steps, the scheme has been received with cautious but definite approval by the business spectrum.

Although a promising start, neither the Cyber Essentials Scheme nor the NIS directive alone is sufficient to bring forward the visionary changes the industry needs. The European efforts are moving in the right direction, but compared to the older, more experienced industry in the U.S., they need further development. The Cyber Essentials Scheme might be too small, while NIS could be seen as too complicated and faces an uncertain fate amid changes to the European Parliament.

If the cybersecurity industry is to address the issues raised at Infosecurity Europe 2014 such as staying ahead of threats, mitigating cyber crime, transforming security into a business enabler and dissipating the predicament of compliance versus security, then Europe needs to continue to move in the right direction and could be inspired by the top-down approach to security in the U.S.

Friday, 6 June 2014

Titania at the Official Cyber Essentials Scheme Launch

Andy Williams (Titania's CSO) was present yesterday, at the invite of the office of Rt. Hon. David Willetts MP, Minister of State for Universities and Science, for the official launch of the Cyber Essentials SchemeThe event was hosted by the ICAEW (Institute of Chartered Accountants for England and Wales) and it was aimed to educate companies on the benefits of adopting the scheme and how best to apply it to businesses. 


Cyber Essential Scheme Launch. Credits: @ICAEW

The scheme, which stands as a guidance and certification reference point, will work alongside other cyber security accreditation bodies (such as the Information Security Forum or British Standards Institution). As such, businesses will be granted the opportunity to qualify for badges that would display how security conscious they are. 

Although the government announced it does not intend to impose legal requirements, it has stated that starting on October 1st, all suppliers bidding for information that handles personal and sensitive contracts in the public sector will need to be Cyber Essentials certified. Early adoption by a few high-profile names such as BAE Systems, KPMG and Barclays show that the scheme was received with enthusiasm. Also, the insurance industry is keen to support the integration of the scheme into their standards.

The scheme is overseen by CREST, the not-for-profit organisation that represents and certifies the information security industry, who collaborated alongside CESG to develop the assessment framework for the scheme. For those interested, badges are already accessible: IASME offers self-assessment path and CREST has a 2-level accreditation available. 

Among information security professionals reactions were positive, but at times reserved. The general consensus was that while the scheme is great for getting the basis of cyber security into place, sustained efforts are needed. 

Peter Wood observes that this is certainly ‘better than nothing at all’ as it addresses the lack of cyber security education for small to mid-sized businesses, which could really benefit from governmental help. Other experts agree that while it is a good starting measure, it shouldn't be seen as a complete solution and as in order to achieve noticeable results, the scheme needs continuous refinement in the long-term. 

Andy Williams thinks that "building on the government's '10 Steps to Cyber Security' launched in 2012, the Cyber Essentials Scheme is an useful next step in raising awareness of basic cyber hygiene standards that, if met, can help businesses protect themselves against cyber attacks. It will be interesting to see how many companies pursue the certification. The government's stated intention to ultimately require all of its suppliers to be CES certified will certainly help to encourage the adoption of the scheme across the UK."

It has been reported that the framework does not yet include guidance around business orientated issues such as business management, IT governance or employee awareness. Organisations would find it useful to have one source that is trusted to be up to date and reliable in these areas to help curb confusion. 

The Cyber Essentials Scheme lays down a good basic foundation and the legislative side gives it a more determined approach, suggesting that the Government is starting to recognise cyber security as a major national issue. The Queen’s Speech in the Houses of Parliament saw the proposal of 11 new laws, including a ‘Serious Crime Bill’ which suggests appropriate jail sentences for cyber crime in order to fully reflect the damage inflicted by a cyber attack. 



Friday, 2 May 2014

Guide to the UK government cyber essentials scheme

First published in HelpNet magazine:

By Edwin Bentley (Senior Software Developer, Titania)
 
About the Author

Edwin joined Titania in 2011 and has since become a key member of development team, having primary involvement in advancement of both the Nipper Studio and Paws Studio software. He has a keen interest in Information Security and the role that the industry will play in the future advancement of technologies.

The results of the latest cyber threat reports and surveys have denominated 2013 as the year of major breaches. The media naturally focuses on the big stories of massive data breaches or coordinated state attacks which leave in their wake a trail of lawsuits, customer data losses and political conflicts. However that’s not the entire spectrum of the cyber security landscape, nor does it reflect the full damage of attacks in cyber space. The SME landscape has its own perils and it suffers just as much as the large corporate domain. The difference is you don’t often hear about it.

Security and compliance is a sore subject for most small and medium sized enterprises. PCI-DSS for example can be a long and painful process for small retailers that are left feeling understandably frustrated at the end of an 80 page document heavy with technical jargon. The next challenge to look forward to is the abundance of guidance and industry bodies, but with no single place to check against a simple number of guidelines. 

Currently the UK cyber security environment is not regulated by compulsory compliance policies. While industry specific frameworks are in place – PCI-DSS for retail, STIG for military, NERC for energy – no clear guidance exists for ensuring organizations operate in a cyber-safe manner for their benefit as well as for the benefit of their customers.

The Cyber Essential Scheme, the new best-practice guidance emitted by the UK government in response to industry demands of a better cyber security policy for the business landscape, was released on the 7th of April 2014. The project follows a call for evidence which concludes that cyber security standards should be internationally recognized, promote international trade, allow systems to exchange and use information efficiently and be auditable.

5 points of the cyber essentials scheme:

1. Boundary firewalls and internet gateways

The objective is to restrict unauthorized access from the internet by configuring firewall rules, internet gateways or other network devices.

What to look for?

Default admin passwords, firewall rules, blocking of vulnerable services (like NetBIOS, SMB, tftp, RPC etc), updates for firewall rules and restricted access to the admin interface for the boundary firewall should assist with securing inbound and outbound network traffic. 

Case in point

The Target breach was achieved through a third-party vendor. Limited access was not enabled on the POS network; hence the attackers gained access to the contractor’s credentials, which managed environmental controls remotely, and from there it was only a matter of time until the hackers infiltrated the payment processing systems across the entire network.

2. Secure configuration

Is default-mode safe-mode? Whether it’s a computer, a network, or a phone the “out-of-the-box” mode is never safe, which is why stronger authentication is required.

What to look for?

Removing unnecessary user accounts – especially any with special access privileges - and pre-installed unnecessary software, changing default passwords, disabling the auto-run feature to prevent code being executed without user knowledge and consent and installing a personal firewall. 

Case in point

When the Winter Olympics were taking place in Sochi, the NBC News’ ran a story on how the reporter’s phone and test computers were hijacked ‘before we even finished our coffee’. Later, the story was proved a hoax, as a combination of risky user behaviour (clicking unknown links, visiting suspicious websites) and default security settings left intentionally on the two test laptops.

3. User access control

User accounts with special access should be assigned only to authorised individuals and granted with only minimum level of access to applications, computers and networks. User privilege is essential to manage, in order to avoid abuse. Privilege abuse makes up for 88% of insider threat actions, according to the latest Verizon DBIR (Data Breaches Investigation Report).

What to look for?

Accounts should be subject to approval, restrict access to a need-to-know basis, details of special access clearance should be documented and reviewed, for a clean track record and auditing procedures. Admin accounts should be used only for administrative tasks and isolated from internet or email. Authentication should require a unique username and a strong password which should be changed on a regular basis. Updated removal or disabling of special privilege accounts when necessary. 

Case in point

Last year’s most prominent case of user privilege abuse was the U.S. government contractor Edward Snowden. With unauthorized SSH keys and falsified digital certificates, Snowden managed to access and steal NSA documents without setting off the alarms across the network, and the NSA is not an isolated case. These type of practices have already been reported in the wild. Under the context of trust abuse and special access threats, every enterprise is a sitting target. 

4. Malware protection

Viruses, worms, spyware can infect any device with an internet connection, thus any organization should have malware protection software. 

What to look for?

Malware protection software should be configured to scan files automatically upon access (downloading, opening files, or accessing web pages) as well as regular automatic scans. Regular updates should be installed, either through manual or centralized configuration. Website blacklisting should be employed to prevent suspicious connections. 

Case in point

The Google Drive scam was a very convincing phishing scam targeting Google Docs and Google Drive users. It consisted of a simple email with a request to view a shared document on Google Drive. The link led to a fake Google login page, which looked almost identical to a real one, because the fake page was hosted on Google’s servers and benefited from Google’s SSL certification, to make it look even more convincing. But once the user entered their credentials, a PHP script stored them on a compromised server. 

With a configured list of blacklisted websites and up to date detection software, this type of scam would not pose much a problem to an organization. 

5. Patch management

Any software is prone to technical vulnerabilities. Once discovered and shared publicly theses vulnerabilities are quickly exploited by cyber criminals, or organized groups. 

What to look for?

Ensuring that the software is licensed and supported in order to receive continuous updates. Updates and security patches should be installed in a timely manner. Software which is no longer supported should be removed from the computer or network. 

Case in point

The end of support for Windows XP announced as early as 2007 still came as an unpleasant surprise to dedicated users and cost-weary businesses. But loyal home-users and organizations will have to make the migration very soon, as security threats loom over the unprotected OS when the next patches are released for the other versions of Windows. 

A lifeline to SMEs

The butterfly effect in the cyber market can be even less than a delicate wing batting in Brazil; it can be a weak admin password to a third party vendor with peripheral access to a SCADA system powering the energy grid for a middle-sized country.

International affairs think-tank Atlantic Council in association with Zurich Insurance Group released recently a report which warns of parallels between the global cyber scene and the financial meltdown from 2008. It argues that ‘on the internet, it has been easier to attack than to defend’ because the internet was founded on trust, not security. However, as the internet became increasingly complex, highly interconnected and widely available the risks escalated rapidly.

Source: security-centre.lancs.ac.uk
The report ends with best practice recommendations resonating with the ones found in the Cyber Essentials program. As it stands the UK does not have any cyber security certification, no reference point to measure against and no single agreed guidance to look up to. The Cyber Scheme initiative is the first step to a one-for-all policy, with the only hope that it will not turn to represent yet another compliance headache for SMEs, but an actual support line for the business sector.

CREST, working with CESG the information security branch of GCHQ has developed an assessment framework which is now available for consultation. The full scheme along with the assessment framework and the accreditation badge will be available in summer 2014.