Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

9/2/2019
10:00 AM
Jonathan Couch
Jonathan Couch
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

ISAC 101: Unlocking the Power of Information

How information sharing and analysis centers provide contextual threat information by creating communities that helps security professionals and their organizations grow in maturity and capability.

The primary function of Information Sharing and Analysis Centers, or ISACs, as stated in their charters, is to reduce risk in member organizations through improvements to prevention, detection, and response. To do this effectively, they must serve as a trusted broker in the sharing of specific information on relevant threats. This definition is important because of their relationship with two critical factors: the quality of shared information and the active participation of members of the core groups. As a trusted broker, the ISAC is the steward of both quality and quantity.

Prior to ISACs, if you weren't part of an "inner circle" of security professionals, you couldn't benefit from information being exchanged. ISACs allow relative newcomers to become instantly trusted, to a degree, so that they can get insight into the threats and security issues their peers are seeing.

With respect to quality, one of the goals of ISACs is to create a community where everyone can learn from each other through the sharing of meaningful data. When one organization is hit with malware or targeted by an adversary, everyone else will know when someone else in the group has seen this threat. Because anonymity is provided by the trusted broker, specific information can be provided to allow others to look in their own networks to see if they have also been targeted.

Trusted Broker: Achieving Critical Mass
The role of trusted broker enables information-sharing groups to achieve critical mass, thus providing quantity. Previously, sharing was only done between individuals who knew each other and had an established relationship. But this model is naturally limited in scope. When tens and hundreds of organizations are brought together and people don't know each other, the ISAC acts as the trusted broker to protect the anonymity of each organization that is sharing information, and provides a mechanism through which the information being shared is specific and relevant to the industry sector.

Ideally, ISACs are in a position to answer some of the biggest questions that nag security professionals: "What kinds of things are my peers and competitors seeing?" and "What are they doing to improve security that I may be missing and should be doing?" Many ISACs hold annual, semi-annual, or even quarterly events for their members to meet and discuss current leading practices related to security, cyber threat intelligence and sharing. Some of the best information shared takes place at live events where members can interact to discuss programs they have started, what they are doing, and how they are communicating and marketing themselves within their own organizations.

PII, Proprietary & Cross-Sector Info
Outside of these in-person opportunities, digital sharing tends to be limited to indicators and rebroadcasts of general information. Even with a trusted broker in place, organizations can be hesitant to share specific information. For the most part, these restrictions are self-imposed by legal staff within companies. Concerns range from sharing personally identifiable information (PII) or corporate proprietary information, to sharing information that was part of a breach. In truth, the only legal restrictions to sharing cyber threat information are regulatory in nature when it comes to disclosing PII. A lot of value can be gained by sharing what you know about the external threat, how it operates, the tools it uses, and (if you're bold enough) how it was able to subvert your security to be successful. None of those items involve PII and the data can be genericized enough so as not to give anyone a competitive advantage.

Another important, yet sometimes overlooked, source for specific and relevant information is cross-sector information. In the real world, threats are rarely limited to a single sector, and the way security professionals think about threats is not necessarily the way the bad guys think about targeting us. For example, an attack that targets the financial sector may very well be used to target oil and gas or energy or retail or government. ISACs have an opportunity to provide better cross-sector information so that members can proactively monitor and even prepare for these threats, depending on their risk profile and other priorities.

ISACs provide the culture, technology, and processes by which organizations can share information with other organizations. They are actively working to provide more contextual threat information by creating a community that helps individuals and their organizations grow in maturity and capability. It will be interesting to see where things stand next year. I'm optimistic that with an unwavering commitment to the role of "trusted broker," information-sharing groups will be able to deliver value at scale.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "The Right to Be Patched: How Sentient Robots Will Change InfoSec Management."

As Senior VP of Strategy of ThreatQuotient, Jonathan Couch utilizes his 20+ years of experience in information security, information warfare, and intelligence collection to focus on the development of people, process, and technology within client organizations to assist in ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
White Papers
More White Papers
Comments
Newest First  |  Oldest First  |  Threaded View
JeffreyT450
100%
0%
JeffreyT450,
User Rank: Apprentice
9/6/2019 | 9:48:31 AM
Excellent Overview of the Power of ISACs
This is an excellent overview of the power of building a trusted community to share intelligence and best practices.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/14/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-10287
PUBLISHED: 2020-07-15
The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set up however, out of our research, we found multiple production systems running these exact default cre...
CVE-2020-10288
PUBLISHED: 2020-07-15
IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can input whatever you like. As long as the field isn't empty it will be accepted.
CVE-2020-15780
PUBLISHED: 2020-07-15
An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30.
CVE-2019-17639
PUBLISHED: 2020-07-15
In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in certain specially crafted code patterns, cause the current method to return prematurely with an undefined return value. This...
CVE-2019-20908
PUBLISHED: 2020-07-15
An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or secure boot restrictions, aka CID-1957a85b0032.