Mobile

5/9/2017
02:00 PM
John Brenberg
John Brenberg
Commentary
Connect Directly
LinkedIn
RSS
E-Mail vvv
50%
50%

Shining a Light on Securitys Grey Areas: Process, People, Technology

The changing distributed and mobile business landscape brings with it new security and privacy risks. Here's how to meet the challenge.

Security and privacy programs are best managed within the boundaries of a company’s people, processes and technologies. But now the lines that define those boundaries are changing – even disappearing.

Today’s workers aren’t isolated to fixed locations and routine schedules. They’re mobile, with virtually anytime, anywhere access to a growing abundance of sensitive information. And data can no longer be expected to be stored and transmitted on premise, but rather through cloud-based and virtual systems.

The transition from well-defined boundaries to these “grey areas” has created greater complexity and confusion when it comes to protecting data. But there are actions companies can take to better understand the risks, and ensure security and privacy programs keep pace with them.

Process: Refreshing Privacy and Security Efforts
Business is changing faster than ever in today’s connected, global economy through traditional means such as acquisitions, organic growth and new market opportunities, as well as more and better data, and connectivity. Both trends are dramatically upending business models, operations, products and services.

As companies change, so should their security and privacy efforts. For example, security and privacy professionals should continually monitor their company’s most valuable assets, such as intellectual property and customer data. From there, they can identify the risks that those assets face, and implement the appropriate safeguards.

People: Managing the Human Factor
The burden of information protection is shifting toward the workers as they become more mobile. Companies must be proactive about providing technology and training to help workers be mindful of their surroundings and the information they access in public places.

These efforts are important. But employee behavior can be hard to change - and will always be prone to human error. That’s why additional safeguards that provide an added level of protection and reduce the burden on the employee can be vital.

Visual hacking prevention is one key example. Visual hacking is the act of viewing or capturing private, sensitive or classified information for unauthorized use. It can be as simple as someone seeing and remembering your company network’s log-in details. Or it can involve using any number of modern technologies to record private organizational or customer information. Employees can – and should – use physical safeguards to block out views of onlookers, who might be looking to glean information from a quick glance or even by recording it with a smartphone camera.

Meanwhile, office workers face increasingly sophisticated attacks. This includes spearphishing, which use social engineering and knowledge about specific workers to target and trick them into clicking on malware-laced links and attachments.

Real-time training, such as with mock phishing services, can test employee performance against these schemes and help companies keep pace with fast-evolving threats. Data-loss prevention technologies can track and restrict employee actions when handling sensitive data, which can help prevent both unintentional and malicious data breaches.

Technology: Addressing New Risks
Security and privacy professionals should revisit their policies when making network and technology infrastructure changes, such as moving from traditional data centers to cloud computing. For instance, security teams will need to identify whether the log-monitoring technologies used in their corporate data centers can be extended to data in the cloud. They may discover they need to incorporate additional security, such as security incident and event management (SIEM) services.

Additionally, a number of security services, such as authentication, file-integrity management and vulnerability scanning, are available through the cloud. This may be more efficient and cost-effective than licensing, installing and managing such services at the company’s on-premise data center.

Either way, whether security services are managed through the cloud or in company-managed data centers, policies and standards should be updated to clearly define an approved approach.

Related Content:

 

John Brenberg has over 30 years of experience spanning new product introduction, system development, infrastructure management and information security and compliance across multiple business segments and processes. He is responsible for leading the IT programs for ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Christian Bryant
50%
50%
Christian Bryant,
User Rank: Ninja
7/31/2017 | 3:57:58 PM
Re: Agreed, process must be revisited
One process area that is in sore need of revision in InfoSec is Requirements Gathering.  While InfoSec should always be a DevOps environment (IMHO), when it isn't (security appliance industry) there must be a more expansive R&D process to fully understand the technology being used to penetrate large enterprises, especially where the most sensitive data is at risk.  We see so many large apps go to market with fancy tools that seem to entirely rely upon the user to configure and make successful.  InfoSec should not be in the business of selling widgets.  Instead, we need more proactive, intelligent and fully operational defenses for users where development keeps up with the underground and is constantly gathering requirements that lend to patches and point releases that can keep pace with the quickly evolving tools of cyber criminals.

 
LMaida
50%
50%
LMaida,
User Rank: Author
7/17/2017 | 3:51:13 PM
Agreed, process must be revisited
Great insights, John. I especailly agree with the idea that organizations need to revisit process, especially around security operations and incident response. Sometimes the process is the problem, and makes organizations reative instead of proactive. 
Equifax CIO, CSO Step Down
Dark Reading Staff 9/15/2017
Cloud Security's Shared Responsibility Is Foggy
Ben Johnson, Co-founder and CTO, Obsidian Security,  9/14/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.