Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

9/2/2019
10:00 AM
Jonathan Couch
Jonathan Couch
Commentary
Connect Directly
LinkedIn
Twitter
RSS
E-Mail vvv
100%
0%

ISAC 101: Unlocking the Power of Information

How information sharing and analysis centers provide contextual threat information by creating communities that helps security professionals and their organizations grow in maturity and capability.

The primary function of Information Sharing and Analysis Centers, or ISACs, as stated in their charters, is to reduce risk in member organizations through improvements to prevention, detection, and response. To do this effectively, they must serve as a trusted broker in the sharing of specific information on relevant threats. This definition is important because of their relationship with two critical factors: the quality of shared information and the active participation of members of the core groups. As a trusted broker, the ISAC is the steward of both quality and quantity.

Prior to ISACs, if you weren't part of an "inner circle" of security professionals, you couldn't benefit from information being exchanged. ISACs allow relative newcomers to become instantly trusted, to a degree, so that they can get insight into the threats and security issues their peers are seeing.

With respect to quality, one of the goals of ISACs is to create a community where everyone can learn from each other through the sharing of meaningful data. When one organization is hit with malware or targeted by an adversary, everyone else will know when someone else in the group has seen this threat. Because anonymity is provided by the trusted broker, specific information can be provided to allow others to look in their own networks to see if they have also been targeted.

Trusted Broker: Achieving Critical Mass
The role of trusted broker enables information-sharing groups to achieve critical mass, thus providing quantity. Previously, sharing was only done between individuals who knew each other and had an established relationship. But this model is naturally limited in scope. When tens and hundreds of organizations are brought together and people don't know each other, the ISAC acts as the trusted broker to protect the anonymity of each organization that is sharing information, and provides a mechanism through which the information being shared is specific and relevant to the industry sector.

Ideally, ISACs are in a position to answer some of the biggest questions that nag security professionals: "What kinds of things are my peers and competitors seeing?" and "What are they doing to improve security that I may be missing and should be doing?" Many ISACs hold annual, semi-annual, or even quarterly events for their members to meet and discuss current leading practices related to security, cyber threat intelligence and sharing. Some of the best information shared takes place at live events where members can interact to discuss programs they have started, what they are doing, and how they are communicating and marketing themselves within their own organizations.

PII, Proprietary & Cross-Sector Info
Outside of these in-person opportunities, digital sharing tends to be limited to indicators and rebroadcasts of general information. Even with a trusted broker in place, organizations can be hesitant to share specific information. For the most part, these restrictions are self-imposed by legal staff within companies. Concerns range from sharing personally identifiable information (PII) or corporate proprietary information, to sharing information that was part of a breach. In truth, the only legal restrictions to sharing cyber threat information are regulatory in nature when it comes to disclosing PII. A lot of value can be gained by sharing what you know about the external threat, how it operates, the tools it uses, and (if you're bold enough) how it was able to subvert your security to be successful. None of those items involve PII and the data can be genericized enough so as not to give anyone a competitive advantage.

Another important, yet sometimes overlooked, source for specific and relevant information is cross-sector information. In the real world, threats are rarely limited to a single sector, and the way security professionals think about threats is not necessarily the way the bad guys think about targeting us. For example, an attack that targets the financial sector may very well be used to target oil and gas or energy or retail or government. ISACs have an opportunity to provide better cross-sector information so that members can proactively monitor and even prepare for these threats, depending on their risk profile and other priorities.

ISACs provide the culture, technology, and processes by which organizations can share information with other organizations. They are actively working to provide more contextual threat information by creating a community that helps individuals and their organizations grow in maturity and capability. It will be interesting to see where things stand next year. I'm optimistic that with an unwavering commitment to the role of "trusted broker," information-sharing groups will be able to deliver value at scale.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "The Right to Be Patched: How Sentient Robots Will Change InfoSec Management."

As Senior VP of Strategy of ThreatQuotient, Jonathan Couch utilizes his 20+ years of experience in information security, information warfare, and intelligence collection to focus on the development of people, process, and technology within client organizations to assist in ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
JeffreyT450
100%
0%
JeffreyT450,
User Rank: Apprentice
9/6/2019 | 9:48:31 AM
Excellent Overview of the Power of ISACs
This is an excellent overview of the power of building a trusted community to share intelligence and best practices.
Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Ransomware Damage Hit $11.5B in 2019
Dark Reading Staff 2/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7914
PUBLISHED: 2020-02-21
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.
CVE-2016-4606
PUBLISHED: 2020-02-21
Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions. This may aid in other attacks.
CVE-2020-5243
PUBLISHED: 2020-02-21
uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent hea...
CVE-2019-14688
PUBLISHED: 2020-02-20
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial produc...
CVE-2019-19694
PUBLISHED: 2020-02-20
The Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a denial of service (DoS) attack in which a malicious actor could manipulate a key file at a certain time during the system startup process to disable the product's malware protection functions or the ...