Showing posts with label Technology Policy. Show all posts
Showing posts with label Technology Policy. Show all posts

Tuesday, July 28, 2009

A patch shrouded in mystery

Later today, Microsoft is expected to release a security patch that is believed to address vulnerabilities in Internet Explorer. I say "believed" because Microsoft has taken the highly unusual step of forbidding the development team from commenting on the measures until after the patch is released.

So right now, all we have are rumors, educated guesses, and our own imagination. I suspect that this could be a big problem with a signature problem. What other reason could cause this kind of behavior from the boys and girls in Redmond?

Tuesday, March 17, 2009

Cloud storage carries real risk

In February, Amazon.com's Simple Storage Service (S3) suffered an eight-hour failure on July 20, 2008. In February, the S3 system was down for two hours. For enterprises that have outsourced 100% of their data storage to services like this one, this is a nightmare scenario.

When you cannot get to any of your data, you are effectively out of business. Your customer-facing websites will not function. Your accounting systems and personnel applications are useless. Depending on how your email system is configured, you might have no ability to send or respond to electronic correspondence.

For most situations, one day in the grand scheme of things isn't the end of the world. It will likely become the subject of jokes within a few short weeks. Although health-care institutions and stock traders cannot afford that kind of downtime, a real estate firm, software development company, or consulting firm will quickly recover from losing less than 0.5% of a their annual productivity. Even web-based services, like Smug-Mug, can handle these kinds of reliability rates ... CEO Don MacAskill wrote in a blog post last month, "No customers reported issues, and our systems were all showing typically low and acceptable error rates."

Considering the ridiculous costs associated with in-house mass storage solutions, your firm may find that storing data with Amazon, Microsoft or some other cloud-based vendor is a good risk. You'll be paying far, far less for high-quality, high-capacity data storage than you would with just about any in-house SAN solution. And I believe you will have more-than-acceptable reliability over the long run.

But, be prepared for the "nightmare" scenario. Eventually, everyone will laugh about it. But it will be highly unpleasant while you're in the middle of it.

Don MacAskill's Blog: S3 outage - We weren’t affected

Tuesday, January 20, 2009

Virtualization requires security focus

As virtualization takes on greater significance in the data center, it's critical that your security measures keep up with the changes. The security challenges presented by virtualization are different from a traditional environment in several ways. For instance, if network traffic no longer needs to be transported through a switch, then monitoring the switch for suspicious activity will not be adequate.

IT leaders have been slow to recognize the need for solutions designed for a virtualized architecture. According to Nemertes Research, only 9.6% of participants in their recent Virtualization benchmark are currently deploying third-party tools focused on security in a virtualized environment. Since internal threats account for more than 15% of reported data breaches (see last week's post - Data Breaches on the Rise in 2008), this represents a significant gap in security execution. Why? Because internal staff are far more likely to discover the details of your data center architecture, and therefore are in a unique position to exploit any deficiencies.

Now is the time to review your security strategy. Contact Roig Consulting for a complimentary consultation.

Nemertes Impact Analysis

Thursday, January 15, 2009

Data breaches on the rise in 2008

The Identify Theft Resource Center (ITRC) published a report last week on data breaches in 2008. According to the report, published January 6, 2009, reports of data breaches are up significantly over 2007. Of course, this doesn't necessarily mean that there are more data breaches than before. Reports of breaches are bound to increase due to heightened awareness of the issues, laws and regulations enacted specifically to address the issue, and public pressure. Experts believe that the increase in the number of reported data breaches can be traced to these factors, as well as the likelihood that criminal activity in this area is, in fact, on the rise.

The information is sobering. For example, "only 2.4% of all breaches had encryption or other strong protection methods in use. Only 8.5% of reported breaches had password protection." This means that the vast majority of reported data breaches were of unprotected information. It is akin to leaving your car running and unattended in the grocery store parking lot. It's just too easy.

Another troubling piece of data is that nearly 16% of the breaches were traced back to malicious internal behavior (please see the nearby table). I believe this means that the work that IT leaders have done to protect their data against external threats has likely been reasonably successful. However, it also means that internal control is too weak. Companies need to invest in ensuring that employees have access to only the data they need to be successful in their work. Not all of will be accomplished by technology and at some point you will simply have to trust your people. But clearly there are improvements available.

Finally, the report tells me that institutions are not valuing their data. An element of the report indicates how much data was actually exposed. In the financial sector alone, over 18 million records were exposed in 2008. Of those, over 750,000 records exposed included password information. For a bit of perspective, that's more people than live in North Dakota.

The fallout from appearing in a report like this can be devastating. There are legal penalties and the potential for civil action, not to mention the damage done to a company's brand. Now is the time to implement firm data access guidelines. Roig Consulting can evaluate your needs and help you develop appropriate policies for your firm.

The ITRC report: 2008 Data Breaches Report
Additional Detailed Data: 2008 Data Breach Statistics
ITRC Home Page: The Identity Theft Resource Center