linking INTEGRITYIntegrity - use of values or principles to guide action in the situation at hand.Below are links and discussion related to the values of freedom, hope, trust, privacy, responsibility, safety, and well-being, within business and government situations arising in the areas of security, privacy, technology, corporate governance, sustainability, and CSR. Security as enabler, not insurance!, 29.6.06
IT Business
When it comes to implementing a security policy, Ricky Mehra, director of IT security and internal controls at Indigo, said businesses have to align IT with corporate objectives. “Don’t evangelize security as insurance,” said Mehra, who was one of five panelists at a Microsoft-sponsored roundtable Thursday. “Try to show an environment in security as a strategic enabler.” Likewise, Pat Kewin, director of Trend Micro, said businesses need to think about aligning security requirements with business goals. “Until that happens, organizations will have trouble getting funding,” said Kewin. Steve Lloyd, chief security advisor at Microsoft Canada, said security needs to be thought of as part of doing your day to day business. “Stop looking for ROI,” said Lloyd. “Security should be a part of your business plan . . . As soon as you start losing account numbers and passwords, you lose your customer’s trust.” (0) comments RFID in Ontario - New Guidelines, 20.6.06
IT Business
(0) comments Connecting the Corporate Dots: Social Networks Reveal How Employees and Companies Operate, 15.6.06
What do Wharton faculty members and the workers who spy for the National Security Agency have in common? More than you might think. The Wharton scholars aren't analyzing links among billions of telephone calls to identify terrorists, a controversial NSA activity that caused a stir after it was disclosed recently in news reports. But they, too, are interested in mapping social networks. Social networking is a hot topic. Ordinary Internet users take advantage of networks when they turn to well-known websites like MySpace and Friendster to link up with other people. But more serious interest in social networks can be found among academics, consultants and corporations seeking to deepen their knowledge of how companies operate; how employees and board members interact; how key employees can be identified; and how relationships can be better understood to improve productivity and the dissemination of ideas. Technically, social network research is an offshoot of graph theory in mathematics. Graphs -- a set of dots connected by links -- are used to map relationships. At its most basic, research on social networks underscores the veracity of some of the truisms one hears all the time: 'It's a small world.' 'It's not what you know, it's who you know.' 'Birds of a feather flock together.' [...] Mapping social networks can be useful in many ways, but Rosenkopf says there are at least two reasons why corporate interest in the subject is growing: Companies want to be able to identify key performers and get a better understanding of the nature of the interaction among employees. [...] Network maps may also unearth what are known as "cosmopolitans" -- the employees who are most critical to information flow in the company. "The formal organizational structure [in companies] does not necessarily describe who talks to whom," says Valery Yakubovich, a University of Chicago professor who will join Wharton's management department this summer. "Even if some jobs in an organization are designed to coordinate across different functional areas, it's difficult to figure out who coordinates where in reality. So you ask people directly whom they go to for advice and who gives them the most valuable information to get things done. Then you map the whole network. Often you find that people you might not even think of as very valuable turn out to be important links in the structure of the organization." [CLB: Fascinating article on how to best make use of these networks and mapping them. I you find social network research interesting, I recommend following through to the citations listed. Are most of the so-called discoveries really just stating the obvious? Yes. But the obvious has been easy to know in theory previously, and now we have tools to find the information in practice. And if the NSA et al can do it, so can you.] (0) comments CALEA and VoIP: Study Finds Wiretaps in Cyberspace Problematic, 14.6.06
Summary: Security Implications of Applying the Communications Assistance to Law Enforcement Act to Voice over IP Executive Summary
The FCC has issued an order for all ``interconnected'' and all broadband access VoIP services to comply with Communications Assistance for Law Enforcement Act (CALEA) --- without specific regulations on what compliance would mean. The FBI has suggested that CALEA should apply to all forms of VoIP, regardless of the technology involved in the VoIP implementation. Intercept against a VoIP call made from a fixed location with a fixed IP address directly to a big internet provider's access router is equivalent to wiretapping a normal phone call, and classical PSTN-style CALEA concepts can be applied directly. In fact, these intercept capabilities can be However, the network architectures of the Internet and the Public Switched Telephone Network (PSTN) are substantially different, and these differences lead to security risks in applying the CALEA to VoIP. VoIP, like most Internet communications, are communications for a mobile environment. The feasibility of applying CALEA to more decentralized VoIP services is Potential problems include the difficulty of determining where the traffic is coming from (the VoIP provider enables the connection but may not provide the services for the actual conversation), the difficulty of ensuring safe transport of the signals to the law-enforcement facility, the risk of introducing new vulnerabilities into Internet communications, and the difficulty of ensuring proper minimization. VOIP implementations vary substantially across the Internet making it impossible to implement CALEA uniformly. Mobility and the ease of creating new identities on the Internet exacerbate the problem. Building a comprehensive VoIP intercept capability into the Internet appears to require the cooperation of a very large portion of the routing infrastructure, and the fact that packets are carrying voice is largely irrelevant. Indeed, most of the provisions of the wiretap law do not distinguish among different types of electronic communications. Currently the FBI is focused on applying CALEA's design mandates to VoIP, but there is nothing in wiretapping law that would argue against the extension of intercept design mandates to all types of Internet communications. Indeed, the changes necessary to meet CALEA requirements for VoIP would likely have to be implemented in a way that covered all forms of Internet communication. In order to extend authorized interception much beyond the easy scenario, it is necessary either to eliminate the flexibility that Internet communications allow, or else introduce serious security risks to domestic VoIP implementations. The former would have significant negative effects on U.S. ability to innovate, while the latter is simply dangerous. The current FBI and FCC direction on CALEA applied to VoIP carries great risks. (0) comments Linking: Privacy as Contextual Integrity, 13.6.06
Schneier on Security
Interesting law review article (PDF) by Helen Nissenbaum:
(0) comments The Myths Of Information Security Reporting, 7.6.06
CSO Analyst Reports
By Khalid Kark with Laurie M. Orlov and Samuel Bright
KEY CONSIDERATIONS FOR REPORTING TO MANAGEMENT To provide meaningful reports that top executives can understand and use, successful information security managers underscored that it is critical to: Align with corporate goals. Security managers must be able to map their reporting to corporate goals and objectives, making it easy for the executives to grasp the context of the reports and see their value. For example, if the corporate goal is to increase profitability, then linking the increase in system availability to the need for better protection against denial of service will make sense to top executives. Communicate in their language. Senior executives do not care about the number of vulnerabilities you have patched or the amount of spam you have blocked. They want to know how these actions affect their organizations or business. So instead of reporting status, report on the business impact of these measures, and instead of providing operational metrics, give business-centric metrics. Report residual risk. Information security is primarily a business problem, not a technology one. When an organization goes through an assessment and identifies risks, management has the choice of mitigating, transferring, or accepting the risks. It is then the responsibility of the security management to ensure that top execs are periodically made aware of the residual risks — i.e., those that have not been completely mitigated and those that have been accepted as tolerable. Highlight significant trends and events. Management reporting must also include significant events and trends in the information security industry to help senior leaders make strategic security decisions. For example, management must be made aware of the proliferation of mobile devices in the enterprise and the risks that they pose. Any significant events, such as the security breaches in your industry, may also be helpful in crystallizing the security risks for management. The trends and news don’t always have to be negative: A new technology, product, or service that may have significant impact on the security industry may also be of interest. Read the complete article: CSO Analyst Reports (0) comments
Archives07.03 08.03 09.03 10.03 11.03 12.03 01.04 02.04 03.04 04.04 05.04 06.04 07.04 08.04 09.04 10.04 11.04 12.04 01.05 02.05 03.05 04.05 05.05 06.05 07.05 08.05 09.05 10.05 11.05 12.05 01.06 02.06 03.06 04.06 05.06 06.06 08.06 09.06 10.06 11.06 01.07 02.07 03.07 04.07 07.07 08.07 09.07 10.07 05.08 06.08 |