Thursday, January 13, 2011

2011 Information Security, Privacy and Compliance Soothsaying

By Rebecca Herold

Looking ahead to what will happen in the coming year is always an interesting exercise.  Just like within a great novel, foreshadowing occurs every day in our lives to drop the hints of things that are likely to come.  The trick is to separate out the valuable hints from the extraneous breadcrumbs that are dropped by dozens of other inconsequential sources that mislead us and cause us to fail in our predictions.   We shall see at the end of the year how close I am with the following predictions…

I try to keep up with all the latest information security, privacy and compliance issues, incidents and reports.  However, there are so many released on an almost daily basis that it is hard, actually impossible, to keep up with everything.  The past couple of years I’ve been immersed in the healthcare industry, in the energy industry leading the NIST Smart Grid privacy working group, in the education industry, and in all things related to social media, cloud computing and mobile computing.  As we move ever yet closer to truly living in an internet of things, where plasma and ether-based data become hard to distinguish between, these three issues will become inextricably intertwined.  And the component that brings the most vulnerability to all forms of information is still the same as it has been for not only the past few years, but also the past few centuries: humans.  But sadly, this component is woefully ignored and neglected when it comes to security and privacy in most organizations.

So, my opinions and viewpoints will skew towards those areas.  But, that’s okay; these areas will have pressing problems like they’ve never seen before, so it is good to reflect upon what is likely in those areas.  Here are just a few specifics for what I see as some of the most pressing issues and emerging trends: 

1.  There will be more emphasis on, and activities for, implementing security and privacy controls within healthcare covered entities (CEs) and business associates (BAs).
In the healthcare arena, there will be more active enforcement by the HHS/OCR of HIPAA/HITECH compliance.  For multiple reasons, including:
  1. Ever-increasing numbers of security incidents and privacy breaches,  
  2. HIPAA/HITECH compliance is becoming more important for the meaningful use (MU) funds (you must perform a risk assessment and then remediate identified risks, per HIPAA), as well as fighting against Medicare/Medicaid fraud, and
  3. The notice of proposed rulemaking (NPRM) will be enacted with the expansion of virtually all HIPAA/HITECH requirements to all business associates (BAs), and their subcontractors, which will encompass significantly many more (several millions more) more entities, and even larger numbers  (BAs to date have not done much for compliance, and their subcontractors have done nothing) of HIPAA/HITECH noncompliance.
I work with a large number of covered entities (CEs), and of all three categories of CEs, I see that providers are most likely the types of entities with the least amounts of controls and with the most significant HIPAA/HITECH compliance gaps.  And it’s not because the CISOs there are not trying.  They just have a very hard audience, the caregivers (doctors, nurses, etc.) to deal with, whose attention (understandably so) on is providing healthcare and not on security and privacy.  And then there are the literally millions of BAs who, to date, have done little more in their HIPAA and HITECH compliance activities than sign a BA Agreement.  So it will become more important than ever before for BAs and CEs to implement comprehensive, effective, HIPAA and HITECH compliance programs to not only meet the associated regulatory requirements, but also more important to those entities that are depending upon those MU funds, to even qualify to get those longed-for monies.

2.   PIAs will emerge as a corporate necessity, with utilities leading the way.
As utilities start converting their customers to smart meters and connecting to the Smart Grid, and as vendors create new types of smart appliances, meters and applications to use within the Smart Grid, they are going to find themselves faced with a large number of questions asking them to prove that their offerings are secure and protect the privacy of all consumers involved within the homes and personal electric vehicles (PEVs) being integrated within this vast new type of network.  As a result of this concern, as well as new federal requirements that will come to pass, we are going to see privacy impact assessments (PIAs) used more within the energy sector, and related vendor businesses, than we’ve seen to date in other industries, with the exception of federal agencies.  However, the PIAs performed will typically be at a greater depth than those performed to date within the federal offices.

The first thing I did when I started leading the NIST Smart Grid privacy group in the summer of 2009 was to do a PIA of the consumer-to-utility portion of the anticipated Smart Grid architecture.  It was the perfect first step; the results clearly revealed where privacy concerns existed.  The concepts were transferred to the rest of the Smart Grid.  Since this time the Smart Grid PIA has been referenced and pointed to many times by numerous government oversight agencies, such as the Department of Commerce, Department of Energy, Federal Trade Commission and others, as a model for entities involved with the Smart Grid to follow.  (See it within NISTIR 7628: “Guidelines for Smart Grid Cyber Security: Vol. 2, Privacy and the Smart Grid” http://csrc.nist.gov/publications/nistir/ir7628/nistir-7628_vol2.pdf.) As a result, PIAs are getting more support, and being recommended, by more government agencies than at any other time and in any other industry.  In the past five months, there has not been a week that has gone by without some entity involved, or who wants to be involved, in the Smart Grid that has contacted me asking to get more information about doing PIAs.  2011 will be the year that PIAs actually become an activity known by not only privacy professionals, but also by information security, compliance and business leaders alike.

3.  Organizations in all sectors must grapple with the mighty trifecta of information security and privacy risks: social media, mobile computing and cloud computing.
These three risks are hitting organizations all at once, from internal and external sources.  Information security, privacy and compliance pros have, to date, been addressing them one at a time, and typically separately from each other’s areas.  To be effective, all three areas must work together to address these issues in a unified, coordinated and collaborative manner.
  1. Cloud services: More organizations will be utilizing outsourced cloud services.  Specific to healthcare, more CEs and BAs, particularly those small and medium-sized organizations, will move their information security and IT functions to outsourced cloud services because they simply do not have the expertise internally do effectively manage security and privacy, and cannot afford to hire typically $200/hour (or even $100/hour) consultants to help them. This will also be the case within  education institutions that are currently struggling with cut budgets and making the hard choices to cut internal staff and go to comparatively less expensive cloud services to manage their systems and data storage and management activities.  More CEs and BAs, because of lack of internal expertise, resources, and funds, will outsource their information security, privacy and compliance activities to third party organizations that specialize in such services.  This will be especially true in small to medium-sized businesses.  These outsourced entities will be like virtual privacy officers and security officers to the CEs and BAs.
  2. Social media sites: Organizations will use social media sites even more to communicate about their services and practices, and as a result of human error, lack of knowledge/training, and malicious intent, there will be significant privacy breaches occur through the release of personal information through social media sites. There already have been many, and there will be many more.  In addition to the organizations actively using the social media sites to enhance and support their businesses, they also need to ensure they have policies and supporting procedures in place for their personnel to follow with regard to posting (and actually NOT posting) information about the business, co-workers, customers and clients.  Even when employees are away from work and using their own computers.  And, as always, the policies and procedures must be communicated using effective, regular training and ongoing awareness activities.  Organizations using social media sites MUST have such policies and training in place as soon as possible!  Their employees are already using social media, even if they don’t know where, how or when their using the sites.
  3. Mobile computing: It would be hard to find a company today where personnel were NOT using some type of mobile computer, smart phone or electronic storage device while doing work activities.  The use of mobile computers, and working away from the office, will continue to increase dramatically in 2011.  Large amounts of sensitive and confidential information can be, and often is, stored upon these devices.  These mobile computers and mobile storage devices are very easy to misplace, to lose or forget, and are also a favorite target of thieves. Appropriate security must be in place to protect them, and the information stored within them. A large portion of the over 200 business partner organizations’ information security and privacy programs I’ve reviewed did not have security or privacy policies or controls in place for these types of mobile computing devices, or for their employees who work from remote locations.  However, they often allowed client data to be stored on the mobile devices, or allowed personnel who used these types of computers to process client data. All without encrypting the data or securing the devices.  Organizations must address the increased use of mobile computing e sure appropriate security is in place for such situations. Most small organizations depend heavily on mobile computers and storage devices, so they too must be very diligent.
4.   Organizations will need to make more efforts and time for information security and privacy training and awareness activities.
The weakest link in information security and privacy is people.  Multiple studies show that most incidents and breaches occur because people simply didn’t know what they were doing, or they made a silly mistake because they were not told how to perform their job responsibilities while keeping information security in mind, or they maliciously did bad things because they knew that, with lack of awareness of their co-workers, they would likely not get caught.  Informed and aware personnel are countermeasures against security incidents and privacy breaches. Training and awareness is a prime factor in an organization’s successful security and privacy compliance program.  Many laws and regulations explicitly require formal, ongoing training and awareness.  Not only HIPAA, HITECH, and GLBA, but also many other federal, state and local level laws, regulations and industry standards.  Fines and penalties will become increasingly more significant for organizations that lack effective training and awareness activities.

A large number of the organizations whose programs I’ve reviewed have not had a formal training and awareness program.  And, the training and awareness activities that were in place have often not been effective.  For example, one organization simply copied and pasted the actual regulatory text of HIPAA into a few hundred PowerPoint slides, put it in a shared folder for their organization, sent a message telling personnel to look at it, and called that training.  This is not training!  In many other organizations I found absolutely no training and no awareness communications or events at all.  Not only does this put information at risk of incidents resulting from lack of knowledge and having more mistakes, it is also significant noncompliance infraction. HIPAA, HITECH and most other regulations require ongoing training and awareness to be occurring right now.  Organizations need to make training and awareness a priority in their information security, privacy and compliance programs.  No matter what some security technology vendor tries to tell you, training and awareness is the least expensive, and most effective, control that they can implement to prevent incidents and breaches.   I’ve seen the direct and measurable benefits many times; those who try to tell you otherwise have not done it effectively, likely because they didn’t believe it would work in the first place.  But, unless you want to have increasing incidents and breaches resulting from not only malicious intent, but also silly mistakes and simple lack of knowledge, you need to be more proactive in providing regular training and ongoing awareness communications and activities.

Last Quiz Question
In what year did Norwich University start the first Civil Engineering program in the US?

Answer: 1820
Winner: Ken Desforges

This Week’s Question
In what month and year was the great flood that devastated much of New England, and Vermont in particular?

Past winners
Andrey N. Chernyaev:  5 wins
Bill Lampe: 4 wins
Matt Bambrick: 3 wins
Ken Desforges: 3
Dianne Tarpy: 2 wins
Scott Madden: 2 wins
Sam Moore
Autumn Crossett
Gil Varney, Jr.
Glen Calvo
Thomas Reardon
Sherryl Fraser
Srinivas Chandrasekar
Marc Ariano
Linda Rosa
Joanna D'Aquanni
Srinivas Bedre
Christian Sandy
Joseph Puchalski
William Westwater

Saturday, November 27, 2010

Information Assurance in Estonia

David Haydter

After MSIA graduate David Haydter returned to his current home in Virginia after Residency 2010, he mentioned in an email that he’d received an award for his IT/IA work in Estonia.  We asked him for details, and here’s his story. 


As for the award, there were three parts to it.  As the Information Management Officer (IMO) at American Embassy Tallinn, Estonia, I supervised six people and was ultimately responsible for all IT, IT security, and communications at the Embassy.    The Department of State uses software to monitor all its subnets (over 400 of them), collect metrics, and to determine the overall network risk and health of each subnet.  Tallinn consistently ranked number one out of all the Department's domestic offices and foreign missions for its network risk score.  This means our patches are applied immediately, our virus definitions are up to date, our security templates are current, permissions, user accounts, registry settings, etc. are all exactly where they should be.  My staff deserves the credit, and I wrote them a separate award which was presented by our Ambassador.

The second part was for the installation of a new messaging (aka telegrams or cables) system which replaced our legacy system from the early 1990s.  Embassy Tallinn was the only mission to successfully install, learn and administer the application, and train its users without flying in outside support.  The third part of the award was not IT or IA related.  The award was a Superior Honor Award which had to be approved in Washington (as opposed to other awards which can be approved at the Embassy level) and signed by an assistant secretary.  Normally, it would then be presented by our Ambassador.  In this case, Secretary Clinton was in town for a NATO summit, and the Ambassador arranged for her to present it to me.

I was in Estonia for three years from 2007-2010.  It is a beautiful country and has come a long way since the fall of communism.  It sits against the Baltic Sea only 50 or so kilometers South of Finland and has a magical old town full of medieval castles.  The winters are very cold, but I know Vermont gets its fair share too!  Being so far north, the days are extremely short in the winter time (only about five hours of daylight) but long in the summer.  The sun doesn't set until around 11:00 p.m. in June and July and it doesn't get completely dark.  The song festival happens every five years - it just happened this year and was a great experience.  [ed. Learn more at http://www.estemb.org/estonia/estonian_song_and_dance_festival ].  There's also a lot of knitting.  There are several shops, mostly in old town, that sell knitted items to the many tourists that come to town.

There was no base - just the Embassy in the middle of the city.  We lived amongst the Estonians and were immersed in their culture.  Very few State Department Missions (Embassies, consulates, U.S. Missions) have a base-type setup.  Our neighbors are typically citizens of the host nation, and we eat, shop and play just as they do.  This is what makes the Foreign Service so interesting.  

Last Week’s Quiz Question
In what year was the Ticonderoga moved to the Shelburne Museum?
Answer: 1955

Winner: William R. Lampe

This Week’s Quiz Question
In what year did Norwich University start the first Civil Engineering program in the US?

Past winners
Andrey N. Chernyaev:  5 wins
Bill Lampe: 4 wins
Matt Bambrick: 3 wins
Dianne Tarpy: 2 wins
Scott Madden: 2 wins
Sam Moore
Autumn Crossett
Gil Varney, Jr.
Glen Calvo
Thomas Reardon
Sherryl Fraser
Srinivas Chandrasekar
Marc Ariano
Linda Rosa
Joanna D'Aquanni
Srinivas Bedre
Christian Sandy
Joseph Puchalski
Ken Desforges
William Westwater

Saturday, November 6, 2010

Business Continuity—Fact or Fiction?

John Orlando, Program Director

I’ve always been bothered by the nagging suspicion that the body of knowledge in the business continuity field is more fiction than fact.  Let me explain.

Think about people’s option on the shape of the world.  For most of human history people believed that the world was flat.  The view that the world was round didn’t come into vogue until relatively recently (OK, technically it’s more of a sphere, but you get the idea). 

We consider the change in belief from flat-earth to round-earth to constitute a move from ignorance to insight.  This is because we consider the belief that the world is round(ish) to better match the reality of the shape of the world than the belief that the world is flat.  Science is “world-guided” in this way—the objects that it studies are out there in the world--and so there is a fact of the matter against which its beliefs can be judged.

This does not mean that all scientific beliefs are true.  In fact, most scientific beliefs eventually turn out to be false.  Reference the aforementioned belief that the world was flat.  The fact that everyone believed that the world was flat at one time did not make the world flat, it just meant that a lot of people were wrong about the shape of the world. The truth or falsity of scientific beliefs is not determined by how many people who hold them, but rather by their match with reality.

But can the same be said for business continuity beliefs?  For instance, we are told that there are four parts to the emergency management process--mitigation, preparedness, response and recovery.  But does the four part division represent a real division in the emergency management process, or just an arbitrary categorization?  Does the emergency management process naturally fall into four parts, rather than five or three, or is it more like the birthday cake that is cut into eight parts because eight people happened to have shown up at the party?  Is there a sense in which we can say that someone who believes that the emergency management process has three, or five, steps is wrong, or are they just not buying into the categorization system that everyone else adopts? 

Now, even if business continuity concepts are created, rather than discovered, they would still have value.  Conventions facilitate discussion by giving everyone the same language.  But the absence of solid evidence supporting business continuity practice hampers the profession’s growth.  Years ago it was predicted that insurance companies would provide discounts to organizations with business continuity plans, thus creating incentives for developing continuity plans (and to hire continuity practitioners), but that did not materialize because insurance rates are dictated by actuarial tables.  An insurance company might provide you with a discount on your policy for not smoking because statistics show that by not smoking your total healthcare outlays will be X% lower than if you smoked, and they can pass the savings on to you.  But no similar statistics exist for business continuity programs.

Lacking evidence to support its practices, the BC profession is primarily intuition-driven rather than evidence-driven.  While intuition is not a bad thing if faced with a lack of evidence—after all, it’s all that you’ve got to go on--intuition can be misleading.  For instance, at one time doctors treated illnesses by the accepted method of blood-letting.  We may laugh today, but at the time this made more intuitive sense in their world-view than the belief in germs that were too small to see.  It was only after doctors actually compared the recovery rates of people treated with bloodletting with those treated without it that they discovered, much to their surprise, that this method didn’t work so well after all.   

I don’t think that business continuity practice is on par with blood-letting (at least I hope not), but proving that to others is another thing. If we can’t provide the evidence to prove that business continuity is a world-guided science, then it becomes hard to justify the expertise of practitioners to the outside world. 

This is why we are developing the Norwich University Business Continuity Research Institute.  The institute will sponsor research that puts the business continuity field onto a firm foundation.  Some of the research will compare different methodologies to determine which works the best.  Other research will try to simply establish that business continuity programs to pay off for an organization in the long run. 

Our plan is to contract with faculty, students, alumni to do much of the research, but also to commission outside investigators.  We will disseminate the results through face-to-face talks, online classes, social media, etc. 

Mostly we want to foster an atmosphere of open and critical investigation that will impart the foundations of evidence and reasoning to common beliefs of the field, and expose where those beliefs are mere conventions without firm backing. 

The goal is to put business continuity on par with other accepted professions in society.  Only then will the field gain legitimacy to the outside world. 

Please take this as an open invitation to join us in this journey.

Last week’s Quiz Question
Question: In what year did the current Norwich University library open?
Answer:  The Kreitzberg Library opened in 1993.
Winner: William R. Lampe

This week’s quiz question
In what year was the Ticonderoga moved to the Shelburne Museum?


Past winners
Andrey N. Chernyaev:  5 wins
Matt Bambrick: 3 wins
Bill Lampe: 3 wins
Dianne Tarpy: 2 wins
Scott Madden: 2 wins
Sam Moore
Autumn Crossett
Gil Varney, Jr.
Glen Calvo
Thomas Reardon
Sherryl Fraser
Srinivas Chandrasekar
Marc Ariano
Linda Rosa
Joanna D'Aquanni
Srinivas Bedre
Christian Sandy
Joseph Puchalski
Ken Desforges
William Westwater

Wednesday, October 20, 2010

Why do we make poor risk-based decisions?

By Donald Holden, CISSP-ISSMP 

 

Everybody makes decision about accepting risks, often without knowing the actual probability of an adverse outcome. In business, we talk about security being concerned with the management of risk. When we make critical decisions that affect the privacy, safety, or security of individuals or corporate assets, do we base these decisions on objectively determined probabilities or upon our perception of risk and rewards, in other words our gut feel? Our perception of risk can change when the adverse impact does not happen even though the actual probability has not changed. People who have been warned to evacuate due to a hurricane that then misses them, tend to minimize the risk of future hurricane warnings. Or if you own a house, have you installed a burglar and fire alarm? If so did you do so after a break-in or fire? The probability of a future break-in is the same before and after the event that may have caused you to install an alarm. Two academic studies provide valuable insight into how we react to perceived risk rather than calculated or statistical risk. 

The first study analyzed how we lower our perceived risk after we have successfully avoided a near-miss or had a close call. A near-miss is defined as an “event that could have been a failure but for luck or chance.”  The second study looked at how we postpone mitigating known critical risks based on short term optimizing goals. Or in the words of the authors, we have a “psychological bias toward short-term maximization instead of long-term planning—a psychological bias all humans share.”  Understanding and then overcoming these human biases in decision making is necessary to improving the safety and security of our corporate and personal environment. 

The first study concerning near-misses was published in Management Science[1] and discussed in the McDonough School of Business (Georgetown) Magazine[2]. Two professors, Robin Dillon-Merrill and Catherine Tinsley, from Georgetown’s McDonough School of Business looked at the impact of near-misses on how we make decisions using perceived risk rather than calculated or statistical risk. They looked at how the near-misses in the American Space Shuttle Program led to the Columbia Space Shuttle catastrophe.  Falling foam insulation during previous space shuttle had fallen during lift off; some had struck the heat tiles but caused no major damage. There had been a calculation of the risk that foam insulation could cause damage to tiles but the experience with near-misses affected the decisions that led to the Space Shuttle Columbia catastrophe in 2003 where the foam did cause major damage to the tiles. Basically, the professors’ research and subsequent experiments with people playing a simulation with near-misses showed that when people have a near-miss, they see it as successfully avoiding the adverse impact rather than a near failure that could happen again with an adverse outcome. Surprisingly, the researchers found that the participants in the experiments did not actually believe that there was a reduction in the calculated or statistical probability of the adverse impact. It was their perception of risk that was lowered; this was an emotional not a rational reaction to the near-misses. 

In an article Masters of Disasters[3] two professors at Wharton’s Risk Management and Decision Processes Center ran a computer simulation where participants are told that they have a house and a bank account with $20,000 which pays 10% interest and they were given a warning that an earthquake could occur at any moment and 3 to 5 mild to severe quakes will happen during the game. Players could spend money on structural improvements to the house or continue to earn interest on the money left in the bank. Although initially players spent some money on improvements, they postponed major improvements thinking that a severe quake would not happen in the next few minutes of the games. By taking these risks, all players lost everything when a quake did happen. Their initial perception of risk seems to change based on the non-occurrence of the quake and the opportunity to earn interest. The Quake players which included both students and then corporate executives found “a sense of security from observing the flimsiness of one another’s houses. If everyone around you has a house of straw, having a straw house yourself seems somehow safer.” Does this sound similar to how businesses look at security risks? 

The authors of the near-miss study recommend treating the near-miss events not as successes but as failures using counterfactual thinking; that is,  imagining how an outcome could have turned out differently, and how the antecedents that led to the event might have been different. Just as we try to learn from our mistakes and failures, we need to learn from the near-misses before they become failures. We should recognize that our experience with near-misses usually causes us to reduce our perception of risk. When we combine this tendency with our preferences for short term gain at the expense of longer term impacts, we can see how a range of risk-based decisions are more emotional than rational.  Recognizing this tendency in ourselves and others can help us make better and more rational risk-based decisions that affect safety and security. 

Last week’s quiz question
What fact about South Hall makes it unique among Norwich University buildings?

Answer: It is LEED certified as a “green” building.

You can learn what this means at:

Winner: William Westwater

This week’s quiz question
In what year did the current Norwich University library open?

Past winners
Andrey N. Chernyaev:  5 wins
Matt Bambrick: 3 wins
Dianne Tarpy: 2 wins
Bill Lampe: 2 wins
Scott Madden: 2 wins
Sam Moore
Autumn Crossett
Gil Varney, Jr.
Glen Calvo
Thomas Reardon
Sherryl Fraser
Srinivas Chandrasekar
Marc Ariano
Linda Rosa
Joanna D'Aquanni
Srinivas Bedre
Christian Sandy
Joseph Puchalski
Ken Desforges
William Westwater




[1] Dillon R, Tinsley C. “ How Near-misses influences decision making under risk.”  Management Science ,V54, 2008 Aug: 1425-40.
[2] Blose, Chris.  “Researching risky business.”, McDonough School of Business Magazine. 2009 June.
[3] Fagone J.  “Masters of disasters.”. Wharton Magazine. Summer 2010.