630-6 Yhtomit

profileabcity84
Computer_Security_Handbook_Set_----_INTRODUCTION_TO_PART_IV_PREVENTION_HUMAN_FACTORS.pdf

INTRODUCTION TO PART IV

PREVENTION: HUMAN FACTORS

Human factors underlie all the mechanisms invented by technical experts. Without human awareness, training, education, and motivation, technical defenses inevitably fail. This part details a number of valuable areas of knowledge for security practitioners, including these chapters and topics:

43. Ethical Decision Making and High Technology. A strategy for setting a high priority on ethical behavior and a framework for making ethical decisions

44. Security Policy Guidelines. Guidelines for how to express security policies effectively

45. Employment Practices and Policies. Policy guidelines on hiring, managing, and firing employees

46. Vulnerability Assessment. Methods for smoothly integrating vulnerability as- sessments into the corporate culture

47. Operations Security and Production Controls. Running computer operations securely, and controlling production for service levels and quality

48. E-Mail and Internet Use Policies. Guidelines for setting expectations about employee use of the Web and e-mail at work

49. Implementing a Security-Awareness Program. Methods for ensuring that all employees are aware of security requirements and policies

50. Using Social Psychology to Implement Security Policies. Drawing on the sci- ence of social psychology for effective implementation of security policies

51. Security Standards for Products. Established standards for evaluating the trust- worthiness and effectiveness of security products

IV · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

43CHAPTER

ETHICAL DECISION MAKING AND HIGH TECHNOLOGY

James Landon Linderman

43.1 INTRODUCTION: THE ABCs OF COMPUTER ETHICS 43 · 1 43.1.1 Why an Ethics

Chapter in a Computer Security Handbook? 43·1

43.1.2 How Much Time Do You Have for This Chapter? 43·2

43.2 AWARENESS 43 · 2 43.2.1 Principle 1: Ethics

Counts 43·2 43.2.2 Principle 2: Ethics Is

Everybody’s Business 43·2 43.2.3 A Test: Put Yourself

in Another’s Shoes 43·2 43.2.4 An Approach:

Disclose! 43·2

43.3 BASICS 43 · 3 43.3.1 Principle 3:

Stakeholders Dictate Ethics 43·3

43.3.2 Principle 4: Traditional Principles Still Apply 43·3

43.3.3 More Tests 43·3 43.3.4 A Guideline

Approach: Ask! 43·4 43.3.5 Another Guideline

Approach: An Ethics Officer 43·4

43.4 CONSIDERATIONS 43 · 4 43.4.1 Principle 5: Ethics

Need Not and Should Not Be a Hassle 43·4

43.4.2 Principle 6: Ethics Policies Deserve Formality 43·5

43.4.3 Principle 7: Ethics Policies Deserve Review 43·5

43.4.4 Principle 8: Anticipate 43·6

43.4.5 The Smell Test 43·6 43.4.6 An Approach:

Stocktaking 43·6

43.5 CONCLUDING REMARKS 43 · 7 43.5.1 How to Keep Up 43·7 43.5.2 Why to Keep Up 43·7

43.6 FURTHER READING 43 · 8

43.1 INTRODUCTION: THE ABCs OF COMPUTER ETHICS

43.1.1 Why an Ethics Chapter in a Computer Security Handbook? In an information age, many potential misuses and abuses of information create privacy and security problems. In addition to possible legal issues, ethical issues affect many groups and individuals—including employees and customers, vendors, consultants, bankers, and stockholders—who have enough at stake in the matter to confront and

43 · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

43 · 2 ETHICAL DECISION MAKING AND HIGH TECHNOLOGY

even destroy an organization over ethical lapses. As is so often the case, consciousness raising is at the heart of maintaining control.

In this chapter, the term “ethics” refers to a system of moral principles that relate to the benefits and harms of particular actions and to the rightness and wrongness of motives and ends of these actions. The major sections cover principles of ethics, tests to help recognize ethical and unethical behavior, and approaches to help ensure good ethical conduct.

43.1.2 How Much Time Do You Have for This Chapter? Section 43.2 requires only one minute to read, but it forms the foundation of this chapter and of a lifelong concern for one of the most important requisites of a valued career and of a civilized society. Ethics matters, and here are the ABCs:

Section 43.2 Awareness (a one-minute primer) Section 43.3 Basics (a 10-minute summary) Section 43.4 Considerations (a 100-minute study) Section 43.5 Details (a lifetime of ongoing commitment)

43.2 AWARENESS. The sections that follow distill some of the most important issues.

43.2.1 Principle 1: Ethics Counts. Increasingly, society is holding individuals and organizations to higher ethical standards than in the past; for example, in recent years, many countries have passed privacy legislation, conflict-of-interest restrictions for public officials, and full-disclosure laws for candidates for a variety of public offices. People, individually and collectively, really want to trust others. Two corollaries to the principle that ethics counts are:

1. Good ethical standards are usually good for business. 2. Violations of ethics are almost always bad for business.

In other words, good ethical behavior usually is appreciated by society, and bad ethical behavior almost always is frowned on and punished—sooner or later.

43.2.2 Principle 2: Ethics Is Everybody’s Business. A second important principle is that good ethics flourishes best when everyone works at it, both in practicing good ethics and in holding others to do so. The reverse of this is also true: Those who practice bad ethics, or choose to ignore the bad ethics of others, are truly part of the problem. Ethics is inescapably everybody’s business.

43.2.3 A Test: Put Yourself in Another’s Shoes. One of the best evaluators of whether certain behavior is ethical or not invites you to put yourself in the other person’s shoes and ask the role-reversal question: “What if I were on the receiving end of the behavior in question?” This variant of the time-honored golden rule translates to “If I wouldn’t like it done to me, I probably shouldn’t do it to others.”

43.2.4 An Approach: Disclose! One of the best guidelines to help ensure good ethical behavior is to let your stakeholders in on what you are doing or are about to do. Good ethics flourishes in the light of day; bad ethics ultimately relies on concealment.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

BASICS 43 · 3

Disclosure buys you two forms of peace of mind: First, you’re being openly honest; second, if others do not like it, you have at least given them the opportunity to express their concerns.

For example, consider organizational policy about managers reading employee email. Almost any policy (anywhere from aggressive intervention to complete hands off) is likely to be ethical if and only if employees are made aware of it.

43.3 BASICS. The expansion of Section 43.2 that follows elaborates on the basic principles enunciated there.

43.3.1 Principle 3: Stakeholders Dictate Ethics. Stakeholders are defined as any individuals or groups with something at stake in the outcome of a decision. In the world of business, stockholders are almost always stakeholders; employees, customers, suppliers, and even competitors are often stakeholders too. How a decision harms or benefits stakeholders is a major ethical consideration. Effects on stakeholders are so important that the best place to start looking at the ethics of a decision is to identify stakeholders and just what it is they have at stake. Decisions will invariably affect individuals and groups, often in opposite ways: Some may stand to gain, others to lose or suffer. The effects and trade-offs raise the principal ethics concerns.

43.3.2 Principle 4: Traditional Principles Still Apply. Recent generations are not the first to raise questions and develop ideas about ethics, although the concept of business ethics has been mocked as an oxymoron and only recently promoted in academia as a valuable area of study. High technology has complicated some issues, but these fundamental principles still apply:

� The Golden Rule (“Do unto others as you would have them do unto you”) and its variants have already been mentioned. These principles remain timeless and fundamental.

� Consideration of the interplay of duties, rights, and responsibilities remains impor- tant. When making ethical decisions, we normally examine the legal, professional, and customary constraints on behavior that apply to our situation.

� Traditional reasons for good ethical behavior, such as religious principles, egoism, utilitarianism, and altruism, still provide us with a useful taxonomy for discussions about ethics.

The point is that even though modern technology has created new opportunities for unethical behavior and new motivations for good ethical behavior, it has not been necessary to develop new principles to deal with ethics. For example, many of the principles (including politeness) governing the behavior of door-to-door sales still apply to Internet push technology.

43.3.3 More Tests. In Section 43.2.3, we suggested the “other’s shoes test” as an excellent evaluator of whether certain behavior is ethical or not. Here we introduce three other tests. The first two are negative in the sense of suggesting that behavior is inappropriate; the third is positive and suggests that the behavior in question is ethical.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

43 · 4 ETHICAL DECISION MAKING AND HIGH TECHNOLOGY

1. The “mom test” asks how your mom (spouse, children, best friend, etc.) would react if aware of your actions. If you would be embarrassed having someone close to you know what is going on, the odds are pretty good it is unethical.

2. The “eye-team test” takes this a step further and considers the results of exposing your actions to the whole world as part of an investigative team broadcast. Again, the more embarrassment, the more likely the unethical nature of the actions.

3. The “market test” asks you to think about openly publicizing your actions as a competitive customer relations strategy. Never mind whether such a marketing strategy is actually feasible; if such exposure could impress others favorably, chances are you are on solid ethical ground.

43.3.4 A Guideline Approach: Ask! Section 43.2.4 endorsed disclosure as one of the best guidelines to help ensure good ethical behavior. This simply means letting your stakeholders in on what you are doing, or about to do. Having done so, it then becomes an appropriate guideline to ask those stakeholders for their permission (or acquiescence, or at least acknowledgment) before you proceed. This can be in the form of allowing stakeholders to opt out of certain policies. Many stakeholders prefer an opt-in approach rather than a default assumption of acceptability, particularly if that assumption is nonintuitive or otherwise obscure.

An example of this approach to ethical behavior is the legally enforced requirement in many countries to ask customers for permission to use their personally identifiable information for purposes other than the original defined functions. Typically, customers have either to opt out of information sharing or opt in to such use of their information.

In other cases, stakeholders such as employees or shareholders may disagree with the ethical implications of proposed actions. They can then argue against the proposals to the extent possible. The ultimate option for such stakeholders is to withdraw; employees can resign and shareholders can sell their shares. If the proposed actions are perceived as illegal, critics can become whistle-blowers and report the suspected illegality to law enforcement and regulatory officials.

43.3.5 Another Guideline Approach: An Ethics Officer. Designating an individual to serve as a full- or part-time ethics officer in an enterprise is a powerful, proactive way to help ensure good ethical behavior. Many large organizations now consider this a position on the top management team. But even small organizations can formally delegate such responsibilities on a part-time basis; they need not require much time and energy of the individual involved. In all cases, the common objectives include:

� Clear management commitment to good business ethics, including adequate re- sources to support this position

� Organizational recognition that this individual has appropriate authority and re- sponsibility, and is a conduit of information into and within the organization

� Hassle-free avenues of access to this person

43.4 CONSIDERATIONS. This section discusses some issues of management style in promulgating and enforcing ethics.

43.4.1 Principle 5: Ethics Need Not and Should Not Be a Hassle. The last thing one wants with business ethics is hassle. An organization’s ethics policies

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

CONSIDERATIONS 43 · 5

should not be obscure, complicated, onerous, or an obstacle to getting things done. The keys to avoiding hassles include:

� Clear and straightforward articulation of ethics policies � Consciousness raising as a prime objective of ethics policies � Clear, comfortable, and safe access to interpretation, for example, by an ethics officer

� Consistency in promulgation, education, application, and enforcement

Employees should not have to guess what constitutes acceptable behavior, nor should they be encumbered by anxiety, guilt, or fear. Individuals should be able to gain clarification on matters before, during, or after events without delay and without fear of being considered a nuisance. Questions about ethics issues deserve unbiased answers, without the presumption that there has been a breach of ethical conduct or that ulterior motives are involved.

Whenever an individual is uncomfortable with a situation or a potential situation, whether he or she is directly involved or not, and particularly if “whistle-blowing” implicates others or even organizational policy, that discomfort needs to be addressed. Even if the individual is wrong and should not be concerned, the discomfort should be dispelled. If the individual is right and there is a legitimate concern, the organization should resolve the issue in a way that does not put the whistle-blower on the spot but rather indicates support for such disclosure.

43.4.2 Principle 6: Ethics Policies Deserve Formality. Like other impor- tant policies, an organization’s ethics policies deserve formality:

� Clear documentation � Clear motivation � Clear sanctions � Clear management support at every level, including the top

Anything less than the foregoing suggests confusion at best and lip service at worst. Formality should not mean bureaucracy or piles of manuals. Consistent with the fifth principle of avoiding hassles, documentation should be brief and clear, and directed at simplifying matters rather than complicating them. The preparation and presentation of policies should reflect a process of thoughtful, high-priority consideration.

A corollary of this principle is peer participation. Policies that ultimately rely on organizational support are best developed and disseminated with peer involvement.

43.4.3 Principle 7: Ethics Policies Deserve Review. Perhaps the only thing as dangerous as ignorance when it comes to policy is complacency. This is as true of ethics policies as it is of any other organizational policy. In particular, to assume everyone in an organization is on board with policy is naı̈ve at best. Review offers a type of preventive maintenance whereby policies and their promulgation are reconsidered with an eye to improvement.

Any organizational policy requires subscription on the part of the members of the organization. Understanding of and compliance with any policy suffers a dangerous tendency to lapse when a policy simply gathers dust. Even an occasional mention and

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

43 · 6 ETHICAL DECISION MAKING AND HIGH TECHNOLOGY

discussion of ethical issues or principles during meetings can breathe new life into old policy.

Just as a corollary of Principle 6 was peer participation in the formalization of policy, so is peer involvement a corollary of policy review. Such peer review not only facilitates fresh insights into policy, but the process itself represents a powerful educational opportunity.

43.4.4 Principle 8: Anticipate. Few people relish the prospect of a serious breach of organizational ethics, particularly if matters reach the point of embarrassing publicity or even legal action. It is better to contemplate the worst scenarios in advance rather than to deal with them without preparation and after the fact. Wishful thinking often deters an organization from including appropriate issues in formal policy. This must not be permitted to happen.

It is better to address tough issues head on than to take anything for granted. The two best ways of doing so are to:

1. Have comprehensive policies that cover any foreseeable eventuality. 2. Have a full- or part-time ethics officer in place to stay on top of things.

43.4.5 The Smell Test. Sometimes the other tests discussed (other’s shoes, mom, eye-team, market) can result in fuzzy or ambiguous analysis. It may be hard to put yourself in someone else’s shoes, especially if different individuals would have widely different reactions to your behavior. And sometimes your family and friends, the general public, or your customers could be neutral or divided in their reactions. The so-called smell test does not require quantitative or even qualitative estimations; it simply relies on your intuition as to whether the behavior in question “smells fishy.” In other words, if you catch yourself seeking justifications, or feel a bit uncomfortable even thinking about the implications, the ethics may be as bad or poor as they smell.

43.4.6 An Approach: Stocktaking. Where can an organization start with all this if it has not already done so? Things usually start with a concerned individual (you?) doing some stocktaking and consciousness raising. Questions for you and others in your organization to consider follow. If you like the answers, then your organization is ethically aware. If you do not like the answers, your organization must deal with the issues you have uncovered.

� If you felt that a fellow employee was misusing company resources or harassing someone, is it obvious what you should do? Is there someone in the organization you could comfortably talk with?

� Do you have the sense that top management in your organization is aware of ethics issues? Do you have the sense that they care?

� Do you know if your organization monitors employee email or computer usage? How much personal business, such as email and net surfing, is permissible on company time?

� How important is quality to your company’s products and services? Are marketing claims consistent with quality?

� What, if any, information does your company capture about customers, suppliers, or employees without their permission? Without even their knowledge? What, if

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

CONCLUDING REMARKS 43 · 7

any, information does your company provide to entities outside the organization about customers, suppliers, or employees without their permission? Without even their knowledge?

� Does your organization fully comply with license arrangements and payments for software and hardware?

� Are customers, suppliers, and employees always treated with dignity and respect? How would a stakeholder (e.g., a new employee) become aware of organizational ethics policies?

For each of these questions, the issue of how one knows must be raised. Ambiguous, confusing, or unreliable knowledge of what is or is not going on should raise red flags of concern. Discomfort with such knowledge may be symptomatic of underlying problems with ethics.

The stocktaking just suggested should translate into action steps for your organiza- tion. Here are a few suggested actions to get started.

� Ask some of your peers to consider the same stock-taking questions, and compare their thoughts with yours.

� Itemize and prioritize any concerns. � Make an appointment with someone fairly high up in management to discuss those concerns. If you are that someone, make an appointment with two or three peers and with subordinates who represent the staff.

� Examine the feasibility of appointing a full- or part-time ethics officer while considering the downside of not having one.

� Ask your internal or external auditors to consider an audit of your ethics policies the next time they do a financial or operational audit.

43.5 CONCLUDING REMARKS. As with security awareness, ethical aware- ness needs freshness and repetition.

43.5.1 How to Keep Up. One of the best ways for individuals and organiza- tions to keep up with matters of good ethics is to spread the job around. Do not try to shoulder the effort alone; it will likely overwhelm any one individual, and collective thinking is valuable in these matters. Without abrogating individual responsibilities, charging the right person with the job of ethics officer will certainly help to keep the enterprise on an appropriate ethical course. A growing number of periodicals, both professional and of general interest, include articles involving ethics. Reading and then discussing them with your peers can be invaluable. Additionally, there has been an increase in the number of Websites addressing ethical issues. See Section 43.6.

43.5.2 Why to Keep Up. Keeping on top of organizational ethics is important because it is the right thing to do. Contemporary business practice embraces the idea of an extended value chain where entities such as customers and suppliers, tradition- ally seen as outside organizational boundaries, are now viewed as partners. Strategic alliances are being formed with these entities, and keeping business partners satisfied and confident is now a strategic necessity. Souring the relationship by a breach of ethics is completely inconsistent with sound business practices. Even if customers and suppliers are not formally viewed as business partners, they are still essential to doing

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

43 · 8 ETHICAL DECISION MAKING AND HIGH TECHNOLOGY

business and are not to be taken for granted. At the very least, given the range of alternative choices available today, unfair exploitation and other forms of unethical practice expose an organization to outright abandonment.

Finally, in the spirit of total quality management, whereby everyone in the enterprise is seen to contribute to its success or failure, your enterprise can be said to be counting on you. The converse may also be true: Your job and your future career may well depend on the success of your enterprise. The good ethics of your organization reflect favorably on you and your colleagues, but bad ethics will have an opposite effect.

43.6 FURTHER READING. A list follows of some books and Websites that will be helpful to readers seeking further discussion of ethical decision making in general, and ethics in business and high technology.

Barger, R. N. “In Search of a Common Rationale for Computer Ethics,” 1994; www.nd.edu/∼rbarger/common-rat.html

Computer Ethics Institute. www.computerethicsinstitute.org Cavazos, E., and G. Morin. Cyberspace and the Law: Your Rights and Duties in the

On-Line World. Cambridge, MA: MIT Press, 1996. Computer & Information Ethics Resources on Center for Applied Ethics, University

of British Columbia. www.ethicsweb.ca/resources Vance, David (ed.). “Information System Ethics.” http://cyberethics.cbi.msstate.edu Cyber Citizen Partnership. Information Technology Association of America (ITAA) &

Department of Justice (DoJ). www.cybercitizenship.org Cyberangels. www.cyberangels.org Cyberspacers (kids’ site). www.cyberspacers.com/home.html EpistemeLinks. Philosophy Resources on the Internet—Computer Ethics. http://tinyurl

.com/33kduz (URL inactive). Ess, C. Digital Media Ethics. Polity, 2013. Ethics and Information Technology (journal). www.springer.com/computer/prog

ramming/journal/10676 Floridi, L. “Information Ethics: On the Philosophical Foundations of Computer

Ethics.” Version 2.0, 1998; www.philosophyofinformation.net/publications/pdf/ ieotpfoce2.pdf

Forester, T., and P. Morrison.ComputerEthics:CautionaryTalesandEthicalDilemmas in Computing. Cambridge, MA: MIT Press, 1990.

Gaskin, S., and A. Evans. GO! Ethics in Cyberspace: Getting Started 2nd Ed. Prentice- Hall, 2013.

Gotterbarn, D. K. W. Miller, J. Impagliazzo, and A. Z. B. A. Bakar. Computing Ethics: A Multicultural Approach. Chapman & Hall, 2013.

Institute for Global Ethics. www.globalethics.org Johnson, D. O. Computer Ethics, 3rd ed. New York: Prentice-Hall, 2000. Kabay, M. E. “Hacker Tips Published in Wall Street Journal.” Network World

Security Strategies, August 28, 2007; www.networkworld.com/newsletters/ sec/2007/0827sec1.html

Kabay, M. E. “Ethical Decision-Making: Identifying the Ethical Issue,” Net- work World Security Strategies, August 30, 2007; www.networkworld.com/ newsletters/sec/2007/0827sec2.html

Kabay, M. E. “Ethical Decision-Making: Using Formal and Informal Guidelines,” NetworkWorldSecurityStrategies, September 4, 2007; www.networkworld.com/ newsletters/sec/2007/0903sec1.html

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

FURTHER READING 43 · 9

Kabay, M. E. “Ethical Decision-Making: Principles, Rights and Duties, and Intuitive Cues,” Network World Security Strategies, September 6, 2007; www.networkworld.com/newsletters/sec/2007/0903sec2.html

Kabay, M. E. “Ethics.” Section of Website. www.mekabay.com/ethics/index.htm Kabay, M. E. “Incident Response: Don’t Lie,” Network World Security Strategies, Oc-

tober 23, 20/07; www.networkworld.com/newsletters/sec/2007/1022sec1.html Kallman, E. A., and J. P. Grillo. Ethical Decision Making and Information Technology:

An Introduction with Cases, 2nd ed. New York: McGraw-Hill, 1996. Kizza, M. Ethical and Social Issues in the Information Age, 5th ed. Springer, 2013. Lessig, L., D. Post, and E. Volokh. “Cyberspace Law for Non-Lawyers.” Published

via email, 1997; www.ssrn.com/update/lsn/cyberspace/csl lessons.html (URL inactive).

Online Ethics Center for Engineering and Science. http://onlineethics.org Orlando, J., and M. E. Kabay. “Social Engineering in Penetration Testing: Cases,”

Network World Security Strategies, October 25, 2007; www.networkworld .com/newsletters/2007/1022sec2.html

Pimple, K. EmergingPervasiveInformationandCommunicationTechnologies(PICT): Ethical Challenges, Opportunities and Safeguards. Springer, 2013.

Project NEThics at the University of Maryland. www.inform.umd.edu/CompRes/ NEThics/ethics (URL inactive).

Schumacher, P., and M. E. Kabay. “Social Engineering in Penetration Test- ing: Intimidation,” Network World Security Strategies, November 8, 2007; www.networkworld.com/newsletters/sec/2007/1105sec2.html

Schumacher, P., and M. E. Kabay. “Social Engineering in Penetration Testing: Over- load and Fascination,” Network World Security Strategies, November 13, 2007; www.networkworld.com/newsletters/sec/2007/1112sec1.html

Spinello, R. Cyberethics: Morality and Law in Cyberspace, 5th ed. Jones & Bartlett Learning, 2013

Tavani, H. T. Ethics and Technology: Controversies, Questions, and Strategies for Ethical Computing. 4th ed. Hoboken, NJ: Wiley, 2012.

Thies, C. Computer Law and Ethics. Mercury Learning & Information, 2013. Thinkquest. “Computer Ethics.” http://library.thinkquest.org/26658/?tqskip=1 University of British Columbia Centre for Applied Ethics. www.ethics.ubc.ca Web Wise Kids. www.webwisekids.com

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

44CHAPTER

SECURITY POLICY GUIDELINES

M. E. Kabay and Bridgitt Robertson

44.1 INTRODUCTION 44 · 1

44.2 TERMINOLOGY 44 · 2 44.2.1 Policy 44·2 44.2.2 Controls 44·2 44.2.3 Standards 44·2 44.2.4 Procedures 44·3

44.3 RESOURCES FOR POLICY WRITERS 44 · 3 44.3.1 ISO/IEC 27002:

2005 44·3 44.3.2 COBIT 44·5 44.3.3 Informal Security

Standards 44·5 44.3.4 Commercially

Available Policy Guides 44·9

44.4 WRITING THE POLICIES 44 · 10 44.4.1 Orientation:

Prescriptive and Proscriptive 44·10

44.4.2 Writing Style 44·11 44.4.3 Reasons 44·11

44.5 ORGANIZING THE POLICIES 44 · 11 44.5.1 Topical

Organization 44·11 44.5.2 Organizational 44·12

44.6 PRESENTING THE POLICIES 44 · 12 44.6.1 Printed Text 44·12 44.6.2 Electronic

One-Dimensional Text 44·13

44.6.3 Hypertext 44·13

44.7 MAINTAINING POLICIES 44 · 14 44.7.1 Review Process 44·15 44.7.2 Announcing

Changes 44·15

44.8 SUMMARY 44 · 15

44.9 FURTHER READING 44 · 16

44.10 NOTES 44 · 16

44.1 INTRODUCTION. This chapter reviews principles, topics, and resources for creating effective security policies. It does not propose specific guidelines except as examples. Many of the chapters in this Handbook discuss policy; examples include:

� Chapter 23 provides an extensive overview of physical security policies � Chapter 25 discusses local area network security issues and policies � Chapter 38 reviews software development policies � Chapter 39 surveys quality assurance policies � Chapter 43 discusses ethics � Chapter 45 provides guidance on employment policies from a security standpoint

44 · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

44 · 2 SECURITY POLICY GUIDELINES

� Chapter 47 includes policies for improving operations security and production � Chapter 48 reviews specific recommendations for email and Internet usage � Chapter 49 looks at methods for enhancing security awareness � Chapter 52 offers policies for secure application design � Chapters 56 through 59 deal with policies for emergency response, backup, and recovery

� Chapter 61 presents policies for working effectively with law enforcement � Chapter 66 discusses effective methods for developing security policies in specific organizations

44.2 TERMINOLOGY. One of the preeminent leaders in security policy devel- opment, Charles Cresson Wood, has emphasized that when developing policy, it helps to segregate information that has different purposes. Specifically, one should create different documents for policy, standards, and procedures.1

44.2.1 Policy. The term “policy” is defined as the rules and regulations set by the organization. Policies are laid down by management in compliance with applicable law, industry regulations, and the decisions of enterprise leaders. Policies are mandatory; they are expressed in definite language and require compliance. Failure to conform to policy can result in disciplinary action, termination of employment, and even legal action. Familiar examples of policy include requirements for background checks when hiring employees, the obligation to follow laws governing the duplication of proprietary software, and restrictions on the use of corporate vehicles for private purposes.

Security policy governs how an organization’s information is to be protected against breaches of security; examples include policies on identification and authentication, authorization for specific kinds of access to specific data, responsibilities for data protection, limitations on the use of corporate resources for email and Internet access, and restrictions on installation of programs on corporate systems. Policies are the basis for security awareness, training, and education; they are a necessary underpinning for security audits. Without policies, it is impossible to demonstrate due diligence in the protection of corporate assets.

Policies are focused on the desired results, not on the means for achieving those results. The methods for achieving policies are defined in the next sections on controls, standards, and procedures.

44.2.2 Controls. When developing a framework for implementing security poli- cies, controls are the measures used to protect systems against specific threats. For example, a policy might stipulate that all production systems must be protected against unauthorized modification of data by programmers; a specific control that could be named in the policy might be that test data extracted by programmers from the produc- tion databases must be anonymized to protect confidential data.

44.2.3 Standards. A standard in computing can be an accepted specification for hardware, software, or human actions. An example of a technical standard is the Transmission Control Protocol/Internet Protocol (TCP/IP) that governs how systems can be interconnected into the Internet.

Standards can be de facto when they are so widely used that new applications routinely respect their conventions; an example is the Hewlett-Packard interface bus

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

RESOURCES FOR POLICY WRITERS 44 · 3

(HP-IB), which became so popular that it was eventually turned into a de jure standard when the Institute of Electrical and Electronics Engineers (IEEE) based its formal IEEE-488 standard on the HP-IB. In contrast, the Centronix parallel interface, although equally popular and universally used, remained proprietary.

In a corporate environment, the term “standard” refers to specific technical choices for implementing particular policies. For example, a corporate policy might stipulate that strong identification and authentication, selected by the technical staff, must be used when gaining access to restricted data; the corresponding standard might specify that a particular brand and model of a microprocessor-equipped smart card should be used in satisfying access control restrictions. Typically, standards are of concern to those who must implement policies; not all standards need be made known to all personnel. Standards also must change in response to a changing technical environment; typically standards change much more rapidly than policies.

44.2.4 Procedures. Procedures prescribe how people are to behave in imple- menting policies. For example, a policy might stipulate that all confidential com- munications from employees traveling outside the enterprise must be encrypted; the corresponding standard might define the proprietary virtual private network (VPN) software and hardware needed to implement that policy; and the corresponding pro- cedure would explain in detail each step required to initiate a secure connection using that particular VPN.

44.3 RESOURCES FOR POLICY WRITERS. If one is setting out to create policy de novo (i.e., without a preexisting policy document), it is critically important to use an existing policy template. Creating policies without guidance from experienced policy writers is a time-consuming, frustrating job that can consume thousands of hours of time, cause dissension within the enterprise, and leave everyone so disgusted that the policies end up turning into shelfware: stored, but never used. There are several well- recognized resources for helping policy writers structure their work, avoid pitfalls, and save enormous amounts of time. In the review that follows, readers will find information about these resources:

� ISO 17799 � COBIT R©

� CERT-CC documentation � NSA Security Guidelines � U.S. Federal Best Security Practices � RFC 2196 � IT Baseline Protection Manual � Commercial policy guides

44.3.1 ISO/IEC 27002:2005. An increasingly popular standard for writing and implementing security policies, especially in Europe, is ISO/IEC 27002:2005, which is the current version of ISO/IEC 17799:2005, in turn based on the old BS7799.

The British Standard 7799 (BS7799) originated in the U.K. Department of Trade and Industry as a code of practice; it was formally renamed the BS7799 in February 1995. BS7799 was not adopted quickly in Great Britain because it was not flexible enough, it used a simplistic security model, and there were more pressing issues, such

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

44 · 4 SECURITY POLICY GUIDELINES

as the imminent arrival of the Y2K problem.2 In addition, BS7799 was a proprietary standard for which users had to pay the equivalent of several hundred dollars before accessing the full documentation.

Version 2 of BS7799 was published in May 1999, and that year also saw the establishment of formal certification and accreditation methods. At that point, the International Organization for Standardization (ISO) began the process of defining BS7799 as an international standard; ISO 17799 was published in 1999. In 2005, the standard was renamed as ISO/IEC 17799:2005 in collaboration with the International Electrochemical Commission (IEC). It was then renamed in 2007.3

With the increasing interest in security, ISO/IEC 27002:2005 certification has been established as a goal for many organizations throughout the world. Major consultancies have trained their auditing staff for compliance with ISO/IEC 27002:2005; e-commerce is also a driving force behind the push for certification. One possible motivation is the experience of the ISO 9000 (quality) certification process in the 1980s; certification soon became a competitive edge and then a competitive requirement to maintain and develop market share.

In the context of policy development, ISO/IEC 27002:2005 offers a convenient framework to help policy writers structure their project in accordance with an interna- tional standard. The abstract from the ISO follows.

ISO/IEC 27002:2005 comprises ISO/IEC 17799:2005 and ISO/IEC 17799:2005/Cor.1:2007. Its technical content is identical to that of ISO/IEC 17799:2005. ISO/IEC 17799:2005/Cor.1: 2007 changes the reference number of the standard from 17799 to 27002.

ISO/IEC 27002:2005 establishes guidelines and general principles for initiating, imple- menting, maintaining, and improving information security management in an organization. The objectives outlined provide general guidance on the commonly accepted goals of informa- tion security management. ISO/IEC 27002:2005 contains best practices of control objectives and controls in the following areas of information security management:

� security policy; � organization of information security; � asset management; � human resources security; � physical and environmental security; � communications and operations management; � access control; � information systems acquisition, development and maintenance; � information security incident management; � business continuity management; � compliance.

The control objectives and controls in ISO/IEC 27002:2005 are intended to be implemented to meet the requirements identified by a risk assessment. ISO/IEC 27002:2005 is intended as a common basis and practical guideline for developing organizational security standards and effective security management practices, and to help build confidence in inter-organizational activities.

The full text of ISO/IEC 27002:2005 is available in electronic format or on paper from the ISO. In addition, a variety of guides are available to help organizations to develop ISO/IEC 27002:2005–compliant policies with minimal rewriting.4

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

RESOURCES FOR POLICY WRITERS 44 · 5

44.3.2 COBIT. The Control Objectives for Information and related Technology (COBIT) provide a business-oriented set of standards for guiding management in the sound use of information technology.5 COBIT was developed by volunteers working under the aegis of the IT Governance Institute (ITGI), which was itself founded by the Information Systems Audit and Control Association (ISACA).

COBIT is an information technology (IT) governance framework and supporting tool set that allows managers to bridge the gap between control requirements, technical issues, and business risks. COBIT enables clear policy development and good prac- tice for IT control throughout organizations. COBIT was first published by ITGI in April 1996. ITGI’s latest update—COBIT 5, published in 2012—emphasizes regula- tory compliance, helps organizations to increase the value attained from IT, highlights links between business and IT goals, and simplifies implementation of the COBIT framework. COBIT 5 is a fine-tuning of the COBIT framework and can be used to enhance work already done based on earlier versions of COBIT. When major activi- ties are planned for IT governance initiatives, or when an overhaul of the enterprise control framework is anticipated, it is recommended to start fresh with COBIT 5. CO- BIT 5 presents activities in a more streamlined and practical manner so continuous improvement in IT governance is easier than ever to achieve.6

COBIT Case Studies provide specific examples of how the framework has been applied.7 The extensive Frequently Asked Questions provide detailed guidance for managers beginning their study of the standard.8 ISACA also provides an interactive, Web-enabled version of COBIT that allows registered users to “construct and download [their] own, personalized version of COBIT for use on the desktop in MS Word or Access format.”9 Different levels of detail are available for visitors, ISACA members, and purchasers. ISACA also offers training courses10 as shown:

� COBIT 5 Foundation � COBIT 5 Implementation � COBIT 5 Assessor Course

44.3.3 Informal Security Standards. In addition to the formal standards just discussed, several sets of guidelines have garnered a degree of acceptance as the basis for exercising due diligence in the protection of information systems. These informal standards include:

� CERT-CC security improvement modules � Security guidelines handbook from the U.S. National Security Agency (NSA) � RFC 2196 from the Internet Engineering Task Force � IT baseline protection manual from the German Information Security Department

44.3.3.1 CERT-CC R© Documentation. The Computer Emergency Response Team Coordination Center (CERT-CC) R© at the Software Engineering Institute (SEI) of Carnegie Mellon University (CMU) has compiled a series of security improvement modules (www.cert.org/certcc.html) on these topics:

Vulnerability Remediation � Current Vulnerability Work � Vulnerability Notes Database

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

44 · 6 SECURITY POLICY GUIDELINES

CSIRT Community � CSIRT Development � National CSIRTs

Secure Coding � Secure Coding Project Page � Secure Coding Standards

Artifact Analysis In addition, CERT expert Julia H. Allen published an excellent guide in 2001 that

has retained its value.11 Chapter headings for this 480-page text are listed next.

1. The CERT Guide to System and Network Security Practices 2. Securing Network Servers and User Workstations 3. Securing Public Web Servers 4. Deploying Firewalls 5. Setting Up Intrusion Detection and Response Preparation 6. Detecting Signs of Intrusion 7. Responding to Intrusions 8. Appendix A: Security Implementations 9. Appendix B: Practice-Level Policy Considerations

44.3.3.2 NSA Security Guidelines. The National Security Agency (NSA) of the United States has published a freely available Security Guidelines Handbook.12

The preface describes it in this way:

This handbook is designed to introduce you to some of the basic security principles and procedures with which all NSA employees must comply. It highlights some of your security responsibilities, and provides guidelines for answering questions you may be asked concerning your association with this Agency. Although you will be busy during the forthcoming weeks learning your job, meeting co-workers, and becoming accustomed to a new work environment, you are urged to become familiar with the security information contained in this handbook.

This set of employee policies is tailored to the needs of the high-security NSA, but it provides useful information that all organizations can adapt to their own requirements. According to the table of contents, these topics are included:

Initial Security Responsibilities � Anonymity � Answering Questions about Your Employment � Answering Questions about Your Agency Training � Verifying Your Employment � The Agency and Public News Media

General Responsibilities � Espionage and Terrorism � Classification

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

RESOURCES FOR POLICY WRITERS 44 · 7

� Need-to-Know � For Official Use Only � Prepublication Review � Personnel Security Responsibilities � Association with Foreign Nationals � Correspondence with Foreign Nationals � Embassy Visits � Amateur Radio Activities � Unofficial Foreign Travel � Membership in Organizations � Changes in Marital Status/Cohabitation/Names � Use and Abuse of Drugs � Physical Security Policies � The NSA Badge � Area Control � Items Treated as Classified � Prohibited Items � Exit Inspection � Removal of Material from NSA Spaces � External Protection of Classified Information � Reporting Loss or Disclosure of Classified Information � Use of Secure and Nonsecure Telephones

Helpful Information � Security Resources

44.3.3.3 U.S. Federal Best Security Practices. The United States Federal Chief Information Officers (CIO) Council has created a Best Practices Committee that provides extensive free documentation for policy makers.13 The committee is defined in this way:

The Best Practices Committee (BPC) is established by the CIO Council Charter to serve as a focal point for promoting information management/information technology (IM/IT) best practices within the federal government. The BPC brings together a team of IT professionals committed to identifying the most successful of IM/IT practices being implemented in industry, government, and academia, and sharing them with agency CIOs as best practices, to be considered for emulation throughout the Federal government. It is about sharing the successes of others, and not reinventing the wheel. It is about constantly learning and applying working models to reduce complexity and achieve results. It is also about cost avoidance and sound stewardship of the taxpayers’ dollars.

There is an extensive collection of documents freely available in PDF format for downloading.14 Some of the topics in the collection of particular interest for this chapter’s context include:

� Best Practices � Enterprise Architecture

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

44 · 8 SECURITY POLICY GUIDELINES

� IT Security/Privacy � GAO Reports � IT-Related Laws and Regulations

44.3.3.4 RFC 2196 (Site Security Handbook). The Internet Engineering Task Force (IETF) has an extensive list of informational documents called Requests for Comments (RFCs) governing all aspects of the Internet.15 One document of par- ticular value to any organization trying to improve its security practices is the classic Site Security Handbook, RFC 2196, edited by B. Fraser of the Software Engineering Institute at Carnegie Mellon University, the same body that hosts the CERT-CC.16 The Handbook has this structure:

Introduction � Purpose of this Work � Audience � Definitions � Related Work � Basic Approach � Risk Assessment

Security Policies � What Is a Security Policy and Why Have One? � What Makes a Good Security Policy? � Keeping the Policy Flexible

Architecture � Objectives � Network and Service Configuration � Firewalls

Security Services and Procedures � Authentication � Confidentiality � Integrity � Authorization � Access � Auditing � Securing Backups

Security Incident Handling � Preparing and Planning for Incident Handling � Notification and Points of Contact � Identifying an Incident

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

RESOURCES FOR POLICY WRITERS 44 · 9

� Handling an Incident � Aftermath of an Incident � Responsibilities

Ongoing Activities Tools and Locations Mailing Lists and Other Resources References

44.3.3.5 IT-Grundschutz Catalogues. The German government’s computer security arm, the Bundesamt für Sicherheit in der Informationstechnik, has published a useful set of guidelines since 1997, the IT-Grundschutzhandbuch. Originally known in English as the IT Baseline Protection Manual, the most recent version as of this writing was published in 2005 and is available free in English as the IT-Grundschutz Catalogues.17 The work is freely available in PDF in German, English, Swedish, and Estonian.

In general, each module presents concepts, threats and vulnerabilities, and coun- termeasures. This work is easy to understand and provides a sound basis for effective information security protection.

44.3.4 Commercially Available Policy Guides. There are several com- mercially available policy templates that save time when developing new policies or improving existing policies. Three of the particular values are discussed next.

44.3.4.1 Charles Cresson Wood’s ISPME. The most widely used com- mercially available collection of security standards is the work by Charles Cresson Wood, Information Security Policies Made Easy (ISPME). The text includes a CD- ROM for easy access to the text so that users can avoid tedious retyping of existing materials.

Wood integrates the perspectives of both management and technical staff when making recommendations. He was one of the original promoters of information security as a way to achieve a competitive advantage and a coauthor of the first computer crime investigation manual. He was one of the first to advocate and document integration of information resource management concepts with information security activities, use of head-count ratio analysis to determine appropriate levels of information security staffing, an information security document life cycle for planning and budgeting purposes, and network management tools to achieve consistent and centralized systems security. He has also developed and successfully marketed two unique software packages that automate information security administration activities. In addition, he evaluated and recommended U.S. Government policies on open versus classified cryptographic research for Frank Press, President Carter’s technology advisor.

One of the outstanding features of ISPME is that Wood explains every policy and sometimes provides opposing policies for use in different environments. His text is not only a set of templates but an excellent basis for teaching security principles by looking at the practice of security.

44.3.4.2 Tom Peltier’s Practitioner’s Reference. Tom Peltier is the Year 2001 Hall of Fame Award Recipient from the Information Systems Security Association

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

44 · 10 SECURITY POLICY GUIDELINES

(www.issa.org). The citation provides the background that explains why Peltier is so highly regarded in the field of security:

Tom Peltier is in his fifth decade working with computer technology. During this time he has garnered numerous industry honors for sharing his experiences with follow professionals. Because of his work he was given the 1993 Computer Security Institute’s (CSI) Lifetime Achievement Award. In 1999, the Information Systems Security Association (ISSA) bestowed on him its Individual Contribution to the Profession Award, and in 2001 he was inducted into the ISSA Hall of Fame. Tom was also awarded the CSI Lifetime Emeritus Membership Award.

Peltier’spolicytext isInformationSecurityPoliciesandProcedures.He providesyou with the tools you need to develop policies, procedures, and standards. He demonstrates the importance of a clear, concise, and well-written security program. His examination of recommended industry best practices illustrates how they can be customized to fit any organization’s needs.

44.3.4.3 SANS Resources. The System Administration and Network Security (SANS) Institute is well known for the excellent security resources it makes available to members and the general public.

44.3.4.3.1 Security Essentials Courses. The SANS Security Essentials Courses (www.sans.org) provide a solid foundation for understanding the issues underlying security policies. Level 524, Security Policy & Awareness (www.sans.org), highlights this objective:

This course is designed to offer an individual a comprehensive approach to understanding secu- rityawareness anddevelopingsecurity policy. Business needs change,thebusiness environment changes, and critical systems are continually exposed to new and developing vulnerabilities. Security awareness training is an effective business strategy that reduces the overall risk to an organization, therefore minimizing user-related faults and errors that lead to destructive and costly security incidents. Security awareness and policy development and assessment are a never-ending process.

44.3.4.3.2 Free Resources. The SANS Institute offers many free resources. For details, see www.sans.org/free resources.php?utm source=web-sans&utm medium =ImageReplace&utm content=Main resource button green&utm campaign=Home Page&ref=3601. Topics include:

� Reading Room: Over 1,600 computer security white papers in over 70 categories � Top 20: The Twenty Most Critical Internet Security Vulnerabilities � Newsletters: Latest Security News

44.4 WRITING THE POLICIES. How should one write security policies? Should they be suggestions? Orders? Positive? Negative? This section affirms that policies should be definite, unambiguous, and directive. In addition, all policies should have (preferably optional) explanations for the reasons behind them.

44.4.1 Orientation: Prescriptive and Proscriptive. Security policies should be written with clear indications that all employees are expected to conform to them. Language should be definite and unambiguous (e.g., “All employees must…” or “No employees shall…”). Some policies require people to do something—these

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

ORGANIZING THE POLICIES 44 · 11

are prescriptive (e.g., “Employees must follow the password procedures defined by the Information Protection Group at all times.”). Other policies prohibit certain actions—these are proscriptive (e.g., “No employee shall make or order illegal copies of proprietary software under any circumstances.”).

44.4.2 Writing Style. Each policy should be short. Simple declarative sentences are best; writersshouldavoidlongcompoundsentenceswithmultiple clauses. Detailsof implementation are appropriate for standards and procedures, not for policies. Policies can refer users to the appropriate documents for implementation details; for example, “Passwords shall be changed on a schedule defined in the Security Procedures from the Information Protection Group.”

For more details on developing policy, see Chapter 45 in this Handbook.

44.4.3 Reasons. Few people like to be ordered about with arbitrary rules. Try- ing to impose what appear to be senseless injunctions can generate a tide of rebellion among employees. It is far better to provide explanations of why policies make sense for the particular enterprise; however, such explanations can make the policies tedious to read for more experienced users. A solution is to provide optional explanations. One approach is to summarize policies in one part of the document and then to provide an extensive expansion of all the policies in a separate section or a separate document. Another approach is to use hypertext, as explained in Section 44.6.3 of this chapter.

44.5 ORGANIZING THE POLICIES. Policies are distinct from the sequence in which they are presented. It is useful to have two distinct presentation sequences for policies: topical and organizational.

44.5.1 Topical Organization. Security involves a multitude of details; how one organizes these details depends on the purpose of the policy document. The most common format puts policies in a sequence that corresponds to some reasonable model of how people perceive security. For example, employees can look at security with a rough correspondence to the physical world. Under this model, one might have a policy document with a table of contents that looks like this:

Principles Organizational Reporting Structure Physical Security

� Servers � Workstations � Portable computers

Hiring, Management, and Firing Data Protection

� Classifying information � Data access controls � Encryption � Countering industrial espionage

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

44 · 12 SECURITY POLICY GUIDELINES

Communications Security � Perimeter controls � Web usage and content filtering � Email usage and privacy � Telephone and fax usage

Software � Authorized products only � Proprietary (purchased) software � Development standards � Quality assurance and testing

Operating Systems � Access controls � Logging

Technical Support � Service-level agreements � Helpdesk functions

44.5.2 Organizational. The complete set of policies may be comprehensive, concise, and well written, but they will still likely be a daunting document, especially for nontechnical staff. To avoid distressing employees with huge tomes of incom- prehensible materials, it makes sense to create special-purpose documents aimed at particular groups. For example, one could have guides like these:

� General Guide for Protecting Corporate Information Assets � Guide for Users of Portable Computers � A Manager’s Guide to Security Policies � Human Resources and Security � Network Administration Security Policies � Programmer’s Guide to Security and Quality Assurance � The Operator’s Security Responsibilities � Security and the Helpdesk

Each of these volumes or files can present just enough information to be useful and interesting to the readers without overwhelming them with detail. Each can make reference to the full policy document.

44.6 PRESENTING THE POLICIES. What options do policy makers have for publishing their policies? This section discusses printing them on paper versus pub- lishing them electronically.

44.6.1 Printed Text. Policies are not inherently interesting. Large volumes full of policies quickly become shelfware. Short paper documents, however, are familiar

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

PRESENTING THE POLICIES 44 · 13

to people; they can be carried around, or placed at hand for easy reference anywhere. Reference cards, summary sheets, stickers, and posters are some of the printed media that can be useful in security awareness, training, and education programs. Printed text, like its electronic versions, provides the opportunity for typeface and color to be used in clarifying and emphasizing specific ideas. However, printed copies of policies share a universal disadvantage: They are difficult to update.

Updating dozens, hundreds, or thousands of individual copies of policy documents can be such a headache that organizations simply reprint the entire document rather than struggle with updates. Updates on individual sheets require the cooperation of every user to insert the new sheets and remove the old ones; experience teaches that many people simply defer such a task, sometimes indefinitely, and that others have an apparently limited understanding of the sequential nature of page numbers. Badly updated policy guides may be worse than none at all, especially from a legal standpoint. If an employee violates a new policy that has been promulgated verbally, but available manuals fail to reflect that new policy, it may be difficult to justify dismissal for wrongdoing.

44.6.2 Electronic One-Dimensional Text. Despite the familiarity and ubiq- uity of paper, in today’s world of near-universal access to computers in the work environment, there is a place for electronic documentation of policies. Such publi- cation has enormous advantages from an administrative standpoint. All access to the policies can be controlled centrally, at least in theory. Making the current version of the policies (and subsets of the policies, as explained in Section 44.5.2) available for reference on a server obviates the problem of updating countless independent copies and avoids the normal situation when using paper: chaotic differences among copies of different ages.

How can one cope with employees stubbornly determined to have their own local copies of the policies on their workstations? One solution to this problem of enforcing a single version is to alert every user to changes in the central copy, or to send every user copies of the appropriate documents by email, with a request to replace their copies of lower version number. Although this solution is not perfect, it does help to keep most people up to date.

44.6.3 Hypertext. Perhaps the most valuable contribution from electronic pub- lication of policies is the availability of hypertext. Hypertext allows a reader to jump to a different section of text and then come back to the original place easily. On paper, forward and backward references are cumbersome, and most readers do not follow such links unless they are particularly keen on the extra information promised in the reference. In electronic files, however, additional information may be as easy to obtain as placing the cursor over a link and clicking.

The most important function of hypertext for policy documents is to provide defini- tions of technical terms and explanations of the reasons for specific policies.

Some users are more comfortable with printed policies. Hypertext, like other formats of text, generally permits users to print out their own copies of all or part of their policy documentation. Many of the tools also allow annotations by users on their own copy of a file.

44.6.3.1 HTML and XML. The most widely used hypertext format today is Hy- pertext Markup Language (HTML). Its variant Extensible Markup Language (XML), provides additional functionality for programmers, but from the user’s perspective, the

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

44 · 14 SECURITY POLICY GUIDELINES

hyperlinks are the same. A simple click of the mouse in a Web browser (e.g., Microsoft Internet Explorer, Netscape Communicator, or Firefox) branches to a different page. More sophisticated programming allows the use of frames and, with Java or ActiveX, pop-up windows. Navigation buttons allow the user to move backward to a previous page or forward to another page. Links also can be used to open new windows so that several pages are visible at once. All of these techniques allow users to move freely through a text with full control over the degree of detail they wish to pursue.

44.6.3.2 Rich Text Format and Proprietary Word Processor Files. Some people prefer to use word processor files for hypertext. As long as everyone uses the same word processing software, this approach can work acceptably. For ex- ample, it is usually possible to insert a hyperlink to a section of a single document, to a location in a different file on disk, or to a page on the Web. Some word processors, such as Microsoft Word and Corel WordPerfect, allow one to insert pop-up comments; floating the cursor over highlighted text brings up a text box that can provide definitions and commentary.

In addition to explicit links, Microsoft Word and other modern word processing programs can display a table of headings that allows instant movement to any section of the document.

Rich text format (RTF) is a general format for interchanging documents among word processors, but the results are not always comparable. For example, a comment created using Microsoft Word shows up as a pop-up box with a word or phrase highlighted in the text; the same comment and marker read from an RTF file by Corel WordPerfect shows up as a balloon symbol in the left margin of the document.

44.6.3.3 Portable Document Format. Adobe Acrobat’s portable document format (PDF) provides all the hyperlinking that HTML offers, but it does so in a form that is universally readable and that can be controlled more easily. The free Acrobat reader is available for multiple operating systems from www.adobe.com. PDF documents can be locked easily, for example, so that no unauthorized changes can be made. In addition, unlike HTML and word processor documents, PDF files can be constructed to provide near-perfect reproduction of their original appearance, even if not all the fonts used by the author are present on the target computer system.

44.6.3.4 Help Files. Help files also provide hypertext capability. In the Win- dows environment, one can create help files using utilities such as Help & Manual from EC Software GmbH. Entering the search string “create help files” into an In- ternet search engine brings up many pages of such tools. Windows Help files can be distributed easily to any Windows user because they are relatively small, and they are loaded almost instantly by the Help subsystem. In addition, users are permitted to add their own notes to such documents and can easily print out sections if they wish.

44.7 MAINTAINING POLICIES. No fixed policy document can cover all even- tualities. The information security field changes constantly and so must policies. In- formation security is a process much like total quality management: For success, both require a thoroughgoing integration into corporate culture.

Above all, some named individuals must see maintaining security policies as an explicit part of their job descriptions. Hoping that someone will spontaneously maintain security policies is like hoping that someone will spontaneously maintain financial records. However, as explained in Chapter 45 of this Handbook, security policies

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

SUMMARY 44 · 15

should represent the best efforts of people from throughout the organization, not the arbitrary dictates of just one person.

44.7.1 Review Process. An information protection working group can meet regularly—quarterly is a good frequency to try—to review all or part of the policies. Employees can be encouraged to suggest improvements in policies or to propose new policies. The working group can identify key areas of greatest change and work on those first, leaving minor policy changes to subcommittees. Members of the work- ing group should discuss ideas with their colleagues from throughout the enterprise, not just with each other. Every effort should contribute to increasing the legitimate sense of involvement in security policy by all employees, including managers and executives.

44.7.2 Announcing Changes. Drafts of the new versions can be circulated to the people principally affected by changes, so that their responses can improve the new edition. Truly respectful inquiry will result in a greater sense of ownership of the policies by employees, although few of them will rejoice in the new policies. Some employees will see new security policies merely as a mild irritant, while others may view them as a tremendous obstacle to productivity and a general nuisance.

Ideally, major changes in policy should be described and explained in several ways. For example, a letter or email (digitally signed, for security) from the president, chair of the board of directors, chief officers, or chief information security officer can announce important changes in policy and the reasons for the changes. A brief article in the organization’s internal newsletter, or a spot on the intranet, can also provide channels for communicating the policy decisions to everyone involved.

Finally, the updated policies can be made available or distributed to all employees using some of the channels discussed in Section 44.6.

44.8 SUMMARY. These 10 recommendations will help in preparing to create and implement security policies:

1. Distinguish among policies, controls, standards, and procedures. 2. Use all resources from government, industry bodies, and commercial organiza-

tions in preparing to create policies.

3. Use unambiguous prose when defining policies: Tell people what to do and what not to do.

4. Use short sentences. 5. Give reasons for policies. 6. Provide different views of policies—topical and organizational. 7. Provide several ways of reading the policies, including printed text, electronic

text, and hypertext.

8. Review and improve or adapt policies regularly. 9. Circulate drafts showing changes in policies to interested participants before

publishing them.

10. Announce major changes using high-level authorities within the enterprise.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

44 · 16 SECURITY POLICY GUIDELINES

44.9 FURTHER READING Allen, J. H. The CERT R© Guide to System and Network Security Practices. Reading,

MA: Addison-Wesley, 2001. Atkinson, J. M. “NSA Security Guidelines Handbook,” National Security Agency

Central Security Service, 2002. www.tscm.com/NSAsecmanual1.html Barman, S. Writing Information Security Policies. Indianapolis: New Riders, 2001. Boran, S. “IT Security Cookbook.” 2009. www.boran.com/security/index.html Clarke, R. “Best Practice Guidelines: Controls over the Security of Personal Informa-

tion,” 1993, www.anu.edu.au/people/Roger.Clarke/DV/PDSecy.html Dubin, J. The Little Black Book of Computer Security, 2nd ed. 29th Street Press, 2008. Flynn, N. The E-Policy Handbook: Designing and Implementing Effective E-Mail,

Internet, and Software Policies, 2nd ed. AMACOM, 2009. Greene, S. Security Program and Policies: Principles and Practices, 2nd ed. Pearson

IT Certification, 2013. Peltier, T. R. InformationSecurityPoliciesandProcedures:APractitioner’sReference,

2nd ed. Auerbach, 2004. Portela, I. M., and F. Almeida, eds. Organizational, Legal, and Technological Dimen-

sions of Information System Administration. IGI Global, 2013. Wood, C. C. Information Security Policies Made Easy, version 12. Houston: Informa-

tion Shield, 2012. www.informationshield.com/ispmemain.htm

44.10 NOTES 1. C. C. Wood, Information Security Policies Made Easy, version 12 (Houston:

Information Shield, 2012), www.informationshield.com/ispmemain.htm 2. ISO 17799 Information Security Portal, www.computersecuritynow.com 3. ISO/IEC 27002:2005, “Information Technology—Security Techniques—Code of

Practice for Information Security Management,” www.iso.org/iso/home/store/ catalogue ics/catalogue detail ics.htm?csnumber=50297

4. Sites that provide free evaluation versions of policy guides include: “Information Security Policy World,” www.information-security-policies-and-standards.com, and “Computer Security Policy Directory,” www.computer-security-policies.com/ index.htm

5. ISACA, “COBIT 5 Product Family,” 2013, www.isaca.org/COBIT/Pages/Product- Family.aspx

6. ISACA, “COBIT 5: A Business Framework for the Governance and Management of Enterprise IT,” 2013, www.isaca.org/COBIT/Pages/default.aspx

7. ISACA, “COBIT Recognition,” 2013, www.isaca.org/COBIT/Pages/Recognition .aspx

8. ISACA, “COBIT FAQs,” 2013, www.isaca.org/Knowledge-Center/cobit/Pages/ FAQ.aspx

9. ISACA, COBIT Online: www.isaca.org/Template.cfm?Section=COBIT Online& Template=/ContentManagement/ContentDisplay.cfm&ContentID=15633

10. ISACA, “COBIT 5 Training,” 2013, www.isaca.org/Education/COBIT- Education/Pages/COBIT-Training.aspx

11. J. H. Allen, TheCERT R© GuidetoSystemandNetworkSecurityPractices(Reading, MA: Addison-Wesley, 2001).

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

NOTES 44 · 17

12. NSA, “NSA Security Guidelines Handbook” (Fort Meade, MD: National Security Agency Central Security Service, 2002), www.tscm.com/NSAsecmanual1.html

13. CIO Council BPC: https://cio.gov/about/committees/management-best-practices- committee (URL inactive).

14. CIO Council Documents: https://cio.gov/resources/document-library 15. IETF RFCs: www.ietf.org/rfc.html 16. B. Fraser, “Site Security Handbook,” IETF RFC 2196, 1997; www.ietf.org/rfc/

rfc2196.txt?number=2196 17. BSI, “IT-Grundschutz,” Bundesamt für Sicherheit in der Informationstechnik

(German Federal Office for Information Security), 2005; https://www.bsi.bund.de/ EN/Topics/ITGrundschutz/itgrundschutz.html

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

45CHAPTER

EMPLOYMENT PRACTICES AND POLICIES

M. E. Kabay and Bridgitt Robertson

45.1 INTRODUCTION 45 · 1

45.2 HIRING 45 · 1 45.2.1 Checking Candidate’s

Background 45·2 45.2.2 Employment

Agreements 45·3

45.3 MANAGEMENT 45 · 3 45.3.1 Identify Opportunities

for Abuse 45·3 45.3.2 Access Is Neither a

Privilege Nor a Right 45·4 45.3.3 The Indispensable

Employee 45·4 45.3.4 Career Advancement 45·6 45.3.5 Vacation Time 45·6

45.3.6 Responding to Changes in Behavior 45·7

45.3.7 Separation of Duties 45·8 45.3.8 The Capability and

Responsibility Matrices 45·10

45.3.9 No Unauthorized Security Probes 45·11

45.4 TERMINATION OF EMPLOYMENT 45 · 12 45.4.1 Resignations 45·12 45.4.2 Firings 45·12

45.5 SUMMARY 45 · 16

45.6 FURTHER READING 45 · 17

45.7 NOTES 45 · 17

45.1 INTRODUCTION. Crime is a human issue, not merely a technological one. True, technology can reduce the incidence of computer crimes, but the fundamental problem is that people can be tempted to take advantage of flaws in our information systems. The most spectacular biometric access control in the world will not stop someone from getting into the computer room if the janitor believes it is “just to pick up a listing.”

People are the key to effective information security, and disaffected employees and angry ex-employees are important threats according to many current studies. Chapter 13 in this Handbook provides detailed information about insider crime.

This chapter presents principles for integrating human resources (HR) management and information security into corporate culture.1

45.2 HIRING. The quality of employees is the foundation of success for all enterprises; it is also the basis for effective information security.

45 · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

45 · 2 EMPLOYMENT PRACTICES AND POLICIES

45.2.1 Checking Candidate’s Background. Hiring new employees poses a particular problem; growing evidence suggests that many people inflate their résumés with unfounded claims. According to Edward Andler, author of The Complete Refer- ence Checking Handbook, “cheating on résumés has become distressingly common. And many people are getting by with it, which appears to be making others follow suit.” His research shows that up to 10 percent “seriously misrepresent” their background or work histories. A research project run by the Port Authority of New York and New Jersey used an advertisement asking for electricians who were expert at using “Sontag Connectors.” They received 170 responses claiming such expertise, even though there was no such device.2

Reviewers should be especially careful of vague words such as “monitored” and “initiated.” During interviews or background checking, HR staff should find out what the candidate did in specific detail, if possible. All references should be followed up, at least to verify that the candidates really worked where the résumé claims they did.

Unfortunately, there is a civil liberties problem when considering someone’s crim- inal record. Once people have suffered the legally mandated punishment for a crime, whether fines, community service, or imprisonment, discriminating against them in hiring may be a violation of their civil rights. Can one exclude convicted felons from any job openings? From job openings similar to areas in which they abused their former employers’ trust? Are employers permitted in law to require that prospective employ- ees approve background checks? Can one legally require polygraph tests? Drug tests? Personality tests?

In some jurisdictions, “negligent hiring” that results in harm to third parties is being punished in civil litigation. Imagine, for example, that a firm were to hire an active criminal hacker as a system administrator without adequate background checking and interviews; if the hacker were then to use his position and corporate resources to break into or sabotage another organization’s systems, it is reasonable to suppose that the victim could claim damages from the criminal’s employer on the basis of negligent hiring. In addition, “negligent retention” could hold an employer liable when an employee, who may pose a risk to coworkers or the public, is not terminated immediately.

Employers should consult their corporate legal staffs to ensure that they know, and exercise, their rights and obligations in the specific legal context of their work.

Even checking references from previous employers is fraught with uncertainty. Employers may hesitate to give bad references for incompetent or unethical employees for fear of lawsuits if their comments become known, or if the employee fails to get a new job. Today, one cannot rely on getting an answer to the simple question “Would you rehire this employee?”

Ex-employers must also be careful not to inflate their evaluation of an ex-employee. Sterling praise for a scoundrel could lead to a lawsuit from the disgruntled new em- ployer.

For these reasons, a growing number of employers have corporate policies that forbid discussing a former employee’s performance in any way, positive or negative. All one gets from a contact in such cases is “Your candidate did work as an Engineer Class 3 from 1991 to 1992. I am forbidden to provide any further information.”

It is commonplace in the security field that some people who have successfully committed crimes have been rewarded by a “golden handshake” (a special payment in return for leaving), sometimes even with positive references. The criminals can then move on to victimize a new employer. However, no one knows how often this takes place.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

MANAGEMENT 45 · 3

To work around such distortions, interviewers should question candidates closely about details of their education and work experience. The answers can then be checked for internal consistency and compared with the candidate’s written submissions. Liars hate details: It is so much harder to remember which lie to repeat to which person than it is to tell the truth.

There are commercial services specializing in background checking (e.g., Achieve- ment Tec). They provide the necessary forms to allow employers to query credit records and other background information. Companies such as Kroll and Securitas Security Services also conduct extensive background checks.

Another way to conduct an employee background check can be done for free or at modest cost via Internet search engines. By entering someone’s name into one of these search engines, there is a good possibility that some aspect of the applicant’s life will be retrieved. Of particular interest might be a search of messages from a particular blog to see what information is being disseminated.

Experienced employees should interview the candidate and compare notes in meet- ings to spot inconsistencies. A director of technical support at a large computer service bureau questioned a new employee who claimed to have worked on a particular plat- form for several years—but did not know how to log on. Had he chatted with any of the programmers on staff before being hired, his deception would have been discovered quickly enough. Ironically, had he told the truth, he might have been hired anyway.

45.2.2 Employment Agreements. Before allowing new employees to start work, they should sign an employment agreement stipulating that they will not disclose confidential information or trade secrets of their previous employers. Another clause must state that they understand that the new employer is explicitly not requesting access to information misappropriated from their previous employer, or from any other source. The Uniform Trade Secrets Act, which is enforced in many jurisdictions in the United States, provides penalties that are up to triple the demonstrated financial damages, plus attorney’s fees, caused by such data leakage. One high-profile case involved three employees who were found guilty of stealing and trying to sell Coca-Cola secrets to its rival Pepsi.3

45.3 MANAGEMENT. Security is the result of corporate culture; therefore, man- agement practices are critically important for successful information protection. Ex- ternal attacks through Internet connections and damage from malicious software are certainly important threats; nonetheless, insider damage due to errors and omissions as well as through dishonesty or a desire for revenge are still major problems for information security.4 These problems are compounded when there are collaborative threats involving insiders working with those outside the enterprise.

45.3.1 Identify Opportunities for Abuse. Security managers do not have to be paranoid, they just have to act as if they are paranoid. Managers must treat people with scrupulously fair attention to written policies and procedures. Selective or capricious enforcement of procedures may constitute harassment. If some individuals are permitted to be alone in the printer room as salary checks are printed, while other employees of equivalent rank must be accompanied, the latter can justifiably interpret the inconsistency as an implicit indication of distrust. Such treatment may move certain employees to initiate grievances and civil lawsuits, to lay complaints under criminal statutes for discrimination, or even to commit vengeful acts.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

45 · 4 EMPLOYMENT PRACTICES AND POLICIES

45.3.2 Access Is Neither a Privilege Nor a Right. When management removes access rights to the network server room from a system analyst who has no reason to enter that area, the response may be resentment, sulking, and abuse. People sometimes treat access controls as status symbols; why else would a CEO who has no technical training demand that his access code include the tape library and the wiring closet? Managers can overcome these psychological barriers to better security by introducing a different way of looking at vulnerabilities and access. After identifying an opportunity for a particular employee to use the system in unauthorized ways, one should turn the discussion into a question of protecting the person who has unnecessary access against undue suspicion. For example, an employee having more access to secured files than is required is put at risk. If anything ever did go wrong with the secured files, that employee would be a suspect. There is no need to frame the problem in terms of suspicion and distrust.

With these principles in mind, managers should be alert to such dangers as permitting an employee to remain alone in a sensitive area, allowing unsupervised access to unencrypted backups, or having only one programmer who knows anything about the internals of the accounting package.

As for language, it would be better to stop referring to access privileges. The very word connotes superiority and status—the last things management should imply. Access is a function and a responsibility, not a privilege or a right; it should be referred to simply as access functions or access authorizations.

45.3.3 The Indispensable Employee. In many areas of information pro- cessing, redundancy is generally viewed as either a bad thing or an unavoidable but regrettable cost paid for specific advantages. For example, in a database, indexing may require identical fields (items, columns) to be placed in separate files (data sets, tables) for links (views, joins) to be established. However, in managing personnel for better security, redundancy is a requirement. Without shared knowledge, an organization is at constant risk of a breach of availability.

Redundancy in this context means having more than one person who can accomplish a given task. Another way of looking at it is that no knowledge should belong to only one person in an organization. Putting the keys to the kingdom in the hands of one employee invites disaster.

Unique resources always put systems at risk; that is why companies such as Tandem, Stratus, and others have so successfully provided redundant and fault-tolerant computer systems for critical task functions, such as stock exchanges and banking networks. These computer systems and networks have twin processors, channels, memory arrays, disk drives, and controllers. Similarly, a fault-tolerant organization will invest in cross- training of all its personnel. Every task should have at least one other person who knows how to do it—even if less well than the primary resource. This principle does not imply that managers have to create clones of all their employees; it is in fact preferable to have several people who can accomplish various parts of any one person’s job. Spreading knowledge throughout the organization makes it possible to reduce the damage caused by absence or unavailability of key people.

It is dangerous to allow a single employee to be the only person who knows about a critical function in the enterprise. Operations will suffer if the key person is away, and the enterprise will certainly suffer if this unique resource person decides to behave in unauthorized and harmful ways. Managers should ask themselves if there is anyone in their department whose absence they dread. Are there any critical yet undocumented procedures for which everyone has to ask a particular person?

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

MANAGEMENT 45 · 5

A client in a data center operations management class volunteered the following story. There was a programming wizard responsible for maintaining a key production program; unfortunately, he had poor communication skills and preferred to solve prob- lems himself rather than to train and involve his colleagues. “It’ll be faster for me to do it myself,” he used to say. During one of his rare vacations, something went wrong with “his” production program, shutting down the company’s operations. The wizard was in the north woods, out of reach of all communications; the disaster lasted until he returned.

Not only does the organization suffer, but also the indispensable persons suffer from the imbalance of knowledge and skill when no one else knows what they know. Some indispensable employees are dedicated to the welfare of their employer and of their colleagues. They may hesitate to take holidays. If their skills are needed from hour to hour, it becomes more difficult for them to participate in committee meetings. These are the people who wear beepers and cannot sit undisturbed even in a two-hour class. If the indispensable employees’ skills affect day-to-day operations, they may find it hard to go to offsite training courses, conferences, and conventions. Despite their suitability for promotion, indispensable people may be delayed in their career change because the organization finds it difficult or expensive to train their replacements. In extreme cases, newly promoted managers may find themselves continuing to perform specialized duties that ought to be done by their staff. Sometimes even a VP of Operations is the only person who can make the changes to a production system that should be performed by a programmer three or four levels down.

A particular kind of indispensability occurs when an employee becomes the de facto technical support resource for a particular software package or system. Without authorization from their managers, these employees can find themselves in difficulty. They may be fired because their productivity drops too low according to their job descriptions, which do not include providing undocumented technical support to other people. They may burn out and quit because of overwork and criticism. Or they may cause resentment among their colleagues and neighbors by declining to help them, or by complaining about overwork. Alternatively, they may enjoy the situation, and manage to meet all the demands on their time quite successfully, until others in the information technology department begin to feel threatened, and someone either complains to the higher-ups or begins spreading nasty comments about these unauthorized support technicians.

Looking at this situation from a management point of view, there are problems for the recipients of all this free aid. The longer they persist in getting apparently free help from their unofficial benefactor, the longer they can avoid letting upper management know they need help. Then when the bubble bursts and the expert becomes unavailable, managers are confronted with a sudden demand for unplanned resources. In most organizations, unexpected staffing requirements are difficult to satisfy. Managers have a hard time explaining how it is that they were unable to predict the need and to budget for it.

Sometimes persons continue to be indispensable because of fear that their value to their employers resides in their private knowledge. Such employees resent training others. The best way to change their counterproductive attitude is to set a good example; managers should share knowledge with them and with everyone else in their group. Education should be a normal part of the way everyone in the enterprise works. Managers can encourage cross-training by allocating time for it. Cross-training can be a factor in employee evaluations. Current topics from the trade press and academic journals, for example, can be discussed in a journal club, or at informal, scheduled

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

45 · 6 EMPLOYMENT PRACTICES AND POLICIES

meetings, where people take turns presenting the findings from recent research in areas of interest.

Reluctance to explain their jobs to someone else may also mask unauthorized or illegal activity. Take, for example, the case of Lloyd Benjamin Lewis, assistant operations officer at Wells Fargo Bank in Beverly Hills, California. He arranged with a confederate outside the bank to cash fraudulent checks for up to $250,000 each on selected legitimate accounts at Lewis’s branch. Using a secret code stolen from another branch, Lewis would scrupulously encode a credit for the exact amount of the theft, thus giving the illusion of correcting a transaction error. Lewis stole $21.3 million from his employer between September 1978 and January 1981, when he was caught by accident. For unknown reasons, a computer program flagged one of his fraudulent transactions so that another employee was notified of an irregularity. It did not take long to discover the fraud, and Lewis was convicted of embezzlement. He was sentenced to five years in a federal prison.5

Because Lewis was obliged to be physically present to trap the fraudulent checks as they came through the system, he could not afford to have anyone with him watching what he did. Lewis would have been less than enthusiastic about having to train a backup to do his job. If anyone had been cross-trained, the embezzlement would probably not have continued so long, or have become so serious.

45.3.4 Career Advancement. In a topic related to avoiding indispensability, managers can improve the security climate through accepted principles of good human resources management, such as career advancement for all employees. By promoting individuals to new responsibilities, managers can also increase the number of people with expertise in critical functions. As managers carry out their regular employee performance reviews, they should include discussions of each person’s career goals. Here, based on a summary by employment expert Lee Kushner, are some practical questions to discuss with employees as part of their interviews.67

1. What are your long-term plans? 2. What are your strengths and weaknesses? 3. What skills do you need to develop? 4. Have you acquired a new skill in the past year? 5. What are your most significant career accomplishments, and will you soon

achieve another one?

6. Have you been promoted over the past three years? 7. What investments have you made in your own career?

When managers support individuals’ interests and aspirations, they foster a cli- mate of respect and appreciation and concurrently support positive feelings about the organization.

45.3.5 Vacation Time. In the example presented in Section 45.3.3, Lloyd Ben- jamin Lewis took his unauthorized duties (stealing money from his bank) so seriously that during the entire period of his embezzlement, about 850 days, he was never late, never absent, and never took a single vacation day in over two years. Any data center manager should have been quite alarmed at having an employee who had failed to be absent or late a single day in more than two years. The usual rule in companies is that

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

MANAGEMENT 45 · 7

unused vacation days can be carried over for only a limited time, and then they expire. This is intended to be an incentive to take vacation time; for normal, honest employees, it probably works fine. For dishonest employees who have to be present to control a scam, losing vacation days is intolerable.

Every employee should be required to take scheduled vacations within a definite—and short—time limit. No exceptions should be permitted. Excessive re- sistance to taking vacations should be investigated to find out why the employee insists on being at work all the time.

Unfortunately, this suspicious attitude toward perfect attendance can cause problems for the devoted, dedicated, and honest employee. An innocent person can get caught up in a web of suspicion precisely because of exceptional commitment. One may be able to avoid difficulties of this kind by:

1. Making the reasons for the policy well known to all employees so no one feels singled out;

2. Relying on the judgment, discretion, and goodwill of the investigating manager to avoid hurt feelings in their most loyal employees; and

3. Switching such an employee’s functions temporarily to see if anything breaks.

45.3.6 Responding to Changes in Behavior. Any kind of unusual behavior can pique the curiosity of a manager. Even more important from a security management standpoint, any consistent change in behavior should stimulate interest. Is a normally punctual person suddenly late, day after day? Did an employee start showing up regularly in hand-tailored suits? Why is a usually charming person snarling obscenities at subordinates these days? What accounts for someone’s suddenly working overtime every day, in the absence of any known special project? Is a competent person now producing obvious errors in simple reports? How is it that a formerly complacent staffer is now a demanding and bitter complainer?

With so much of the enterprise’s financial affairs controlled by information systems, it is not surprising that sudden wealth may be a clue that someone is committing a computer crime. A participant in an information systems security course reported that an accounting clerk at a government agency in Washington, DC, was arrested for massive embezzlement. The tip-off? He arrived at work one day in a Porsche sports car and boasted of the expensive real estate he was buying in a wealthy area of the capital region—all completely beyond any reasonable estimate of his income.

Not all thieves are that stupid. A healthy curiosity is perfectly justified if you see an employee sporting unusually expensive clothes, driving a sleek car after years with a rust bucket, and chatting pleasantly about the latest trip to Acapulco when that person’s salary does not appear to explain such expenditures. Unsolicited inquiries into people’s private lives, however, will usually win no friends. There is a delicate line to walk, but ignoring the issue does not make it disappear.

The other kind of change—toward the negative—also may indicate trouble. Why is the system manager looking both dejected and threadbare these days? Is he in the throes of a personal debt crisis? In the grip of a blackmailer? Beset with a family medical emergency? A compulsive gambler on a losing streak? On humane grounds alone, one would want to know what is up in order to help; however, a manager concerned with security would be compelled to investigate. In these days of explosive rage and ready access to weapons, ignoring employees with a dark cloud hovering over their heads may be irresponsible and dangerous.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

45 · 8 EMPLOYMENT PRACTICES AND POLICIES

Any radical change in personality should elicit concern. If the normally relaxed head accountant now has beads of sweat on her forehead whenever you discuss the audit trails, perhaps it is time to look into her work more closely. Why does a good family man begin returning from long lunches with whiskey on his breath? A formerly grim manager now waltzes through the office with a perpetual smile on his face. What happened? Or what is happening?

All of these changes should alert managers to the possibility of changes in the lives of their employees. Although these changes do indeed affect the security of an organization, they also concern managers as human beings who can help other human beings. Mood swings, irritability, depression, euphoria—these can be signs of psychological stress. Is an employee becoming alcoholic? A drug addict? Abused at home? Going through financial difficulties? Having trouble with teenagers? Falling in love with a colleague? Of course managers cannot help everyone, and in some cases, help should involve qualified mental health professionals; but at least everyone can express concern and support in a sensitive and gentle way. Such discussions should take place in private, and without alarming the subject or exciting other employees. At any time, a manager should feel free to involve the HR or personnel department. They will either have a psychologist or trained counselor on staff or be able to provide appropriate help in some other way, such as an employee crisis line.

There are sad cases in which employees have shown signs of stress but have been ignored, with disastrous consequences: suicides, murders, theft, and sabotage. Be alert to the indicators and take action quickly.

Australian human resources expert Laura Stack offers this analysis of signs of extreme stress:

People don’t normally all of a sudden flip out; they give off early warning signals. Luckily, managers can observe signs of stress in employee behaviour, beginning with milder signs and culminating in desk rage. Be observant for the following stress stages:

� Physical stage: Headaches, illness, fatigue. � Social stage: Negativity, blaming things on others, missed deadlines, working through lunch. � Cerebral stage: Clock-watching, errors in assignments, minor accidents, absentmindedness and indecisiveness.

� Emotional stage: Anger, sadness, crying, yelling, feelings of being overwhelmed, depression. � Spiritual stage: Brooding, crying, wanting to make drastic changes in life, not relating well with people, distancing themselves from personal relationships.7

The manager’s job in probing behavioral changes is difficult; one must walk the thin and possibly invisible line between laissez-faire uninvolvement, risking lifelong regrets or even prosecution for dereliction of duty, and overt interference in the private affairs of the staff, risking embarrassment and possible prosecution for harassment.

Written policies will help; so will a strong and ongoing working relationship with the HR staff. Making it clear to all employees that managers are available for support, but are also expected to investigate unusual behavior, will also help avoid misunder- standings.

45.3.7 Separation of Duties. The same principles that apply to the control of money should apply to control of data. Tellers at a bank, when someone deposits a large check, will always go to a supervisor and have that person look the check over and

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

MANAGEMENT 45 · 9

initial the transaction. When bank tellers empty the automatic teller machines at night and fill the cash hoppers, there are always two people present. In most organizations, the person who creates a check is not the person who signs it.

In well-run information systems departments, with good operations security, data entry is distinct from validation and verification.8 For example, a data entry supervisor can check on the accuracy of data entry but should not be allowed to enter a new transac- tion without having a direct supervisor check the work. There is no excuse for allowing the data entry supervisor to enter a transaction and then, effectively, to authorize it. What if the entry were in error—or fraudulent? Where would the control be?

In quality assurance for program development, the principles of separation of duty are well established. For example, the person who designs or codes a program must not be the only one to test the design or the code.9 Test systems are separate from production systems; programmers must not have access to confidential and critical data that are controlled by the production staff. Programmers must not enter the computer room if they have no authorized business there; operators must not modify production programs and batch jobs without authorization.10

Managers should consider giving up access to functions that have been delegated to two or more subordinates. Maintaining such access could cause more problems than it solves, but in an emergency, access and control could easily be restored. This attitude exemplifies the concept of separation of duties.

In early 1995, the financial world was rocked by the collapse of the Barings PLC investment banking firm. The Singapore office chief, Nicholas Leeson, was accused of having played the futures market with disastrous consequences.11 The significant point is that he managed to carry out all the orders without independent overview. Had there been effective separation of duties, the collapse would not have occurred.

Another shocking example occurred when a system administrator at UBS PaineWeb- ber, upset about the poor salary bonus he received, deployed malicious code on the company’s network. But before quitting his job, he wrote a program that would delete files and wreak havoc on the company’s network. By creating a logic bomb, he was able to impact over 1,000 servers and 17,000 individual workstations. Additionally, buying puts against UBS, he would profit from that attack.

A related approach is called dual control. As an example of dual control, consider the perennial problem of having secret passwords not known to managers who sometimes need emergency access to those passwords. This problem does not generally apply to ordinary users’ passwords, which normally can be reset by a security administrator without having to know the old password. This temporary password should be changed to a truly secret string by the user, after a single logon. However, to guard against the absence of the only person who has the root password for a system, possibly because the others are on vacation, it is advisable to arrange for dual-access to backup copies of the password. The principle of dual control dictates that such a copy of the root password should be accessible only if two officers of the organization simultaneously sign for it when taking it out of the secure storage:

� One can store a written copy of the root password in a truly opaque envelope, seal it, sign the seal, tape over the seal with nonremovable tape, and then store the envelope in a corporate safe or strongbox

� The password can be encrypted twice using the public keys of two officers; the dual encryption requires the officers to decrypt the ciphertext in the reverse order of encryption (see Chapter 7 in this Handbook).

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

45 · 10 EMPLOYMENT PRACTICES AND POLICIES

In conclusion, managers should think about the structure of control over information as they design security policies, so that the safeguards afforded by separation of duties or dual control are present throughout all systems.

45.3.8 The Capability and Responsibility Matrices. One of the tools that can help evaluate and improve the resilience of organizations is the capabilities matrix.12

One starts by listing (or brainstorming, perhaps using Computer-Aided ConsensusTM)13

all the critical functions that the organization requires and all the people in the team. The group then has to decide on a way of rating the capabilities of each person; the figure suggests one way to do it, but in no sense is this suggestion meant to constrain users. The group can come to a consensus on which of the team members can do which tasks at which level of competence and then examine the overall pattern of skills. Exhibit 45.1 shows such a matrix with made-up information.

Problems may be highlighted when no one has high-level capabilities or when too few people can effectively carry out those tasks. Another problem is that some people

CAPABILITIES MATRIX FOR UNTELECOM CORPORATION

Capabilities & Assignments

Total points ≤ 32101296310

EVALUATION EXCELLENTGOODIMPROVEURGENTDANGER!ACK!!! NOVICENO CAP. IS/CAN BE

BACKUP

CAN BE IN

CHARGE

Hur'dathGolamoFrannieEdwardDahflaCharlieBettyAlbertTask

application monitoring 2233 10 GOOD

application security vulnerabilities 2233 10 GOOD

business impact analysis 213 6 IMPROVE

computer security incident response team 233 8 IMPROVE

coordination with corporate counsel 22113 9 GOOD

coordination with human resources group 22113 9 GOOD

Database performance 3231 9 GOOD

Database support 2232 9 GOOD

denial-of-service monitoring 331 7 IMPROVE

denial-of-service response 231 6 IMPROVE

detect cyber-attacks 33 6 IMPROVE

enterprise antivirus 0 ACK!!!

governance decisions 22113 9 GOOD

identification and authentication 3222 9 GOOD

intellectual property protection 322 7 IMPROVE

intrusion detection systems 323 8 IMPROVE

intrusion prevention systems 2232 9 GOOD

log management systems 23321 11 GOOD

manage cyber-attacks 212312 11 GOOD

monitor dashboard 2322 9 GOOD

network behavior analysis 3231 9 GOOD

network discovery 2221 7 IMPROVE

penetration testing 3211 7 IMPROVE

quality of service measures 221331 12 EXCELLENT

respond to system alarms 33132 12 EXCELLENT

risk analysis and management 331 7 IMPROVE

security awareness 231 6 IMPROVE

security information and event management 323 8 IMPROVE

service level agreements 233132 14 EXCELLENT

system firewalls 2332 10 GOOD

training 231 6 IMPROVE

unified threat management 323 8 IMPROVE

vulnerability assessment 2132 8 IMPROVE

Web site assessment 212 5 URGENT

Web site monitoring 313 7 IMPROVE

wireless intrusion prevention 0 ACK!!!

TOTAL SCORE 8123245542282213

PERSONNEL CAPABILITIES NEEDTOTAL

EXHIBIT 45.1 Capabilities Matrix For Untelecom Corporation

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

MANAGEMENT 45 · 11

may have so much knowledge compared with others that the organization is in danger were they to be absent; such cases should lead to training efforts to bring others up to an appropriate level of knowledge and skill. Individuals may also be noticeably lacking in skills; again, training may help solve such problems.

A similar matrix should be developed showing the responsibilities of every team member, with indicators of who has primary responsibility and the names of two or more members who can serve as backups (in prioritized order). It is important that every team member fill out their matrix by themselves, because conflicts may be discovered that way.14

The responsibility matrix can identify problems in the management structure. For example

� Some tasks may have no one assigned formally or have nobody assigned primary responsibility, leading to breakdowns in response, especially in emergencies.

� There may be tasks where two or more people believe that they are primary decision makers or leaders for a task, leading to conflicts.

� Some people may be identified with far too many assigned tasks; others may have too few.

45.3.9 No Unauthorized Security Probes. In general, all managers—not just security officers—should always be looking for vulnerabilities and opportunities for improving security. However, no one should ever test production systems for vulnerabilities without the full cooperation of the corporate information protection group, and only with authorization of the right executives. Written approval for explicit tests of security are informally known as get-out-of-jail cards, because without them, employees can go to jail for unauthorized probes of system security.

The case of Randal Schwartz, a consultant to Intel Corporation in Beaverton, Oregon, is a salutary example for employees of the dangers of unauthorized security probes. He was convicted of hacking his way into Intel Corporation computer networks in what he claimed was an effort to point out security flaws while he was working there as a consultant. The would-be security expert failed to notify his employers of his intentions and forgot to get authorization for stealing passwords and making unauthorized changes in system software. He was convicted of three felony counts in July 1995 and was fined $68,000 in restitution as well as being put under five years of probation and having to perform 480 hours of community service.15

A counterexample to warn managers of misplaced zeal in suppressing cooperation with law enforcement is the case of Shawn Carpenter, a network intrusion detection security analyst at Sandia National Laboratories. He was fired by publicity-shy ad- ministrators when he worked with law enforcement officials to track down extensive penetrations of U.S. national security assets. An investigation code-named TITAN RAIN began in late 2003.16 Carpenter noted a flood of expert hacker activity focusing on data theft from a wide range of national security interests. Carpenter discovered that “the attacks emanated from just three Chinese routers that acted as the first con- nection point from a local network to the Internet.”17 Carpenter worked with U.S. Army Counterintelligence and FBI investigators to learn more about the attacks and the attackers. Carpenter never used Sandia’s or government-owned equipment or net- work resources in his investigations. Administrators applied Sandia Internal Directive 12 ISNL ID012, which “specifically prohibits employees from speaking with local,

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

45 · 12 EMPLOYMENT PRACTICES AND POLICIES

state, or Federally elected officials.” In 2007, Carpenter was awarded $4.3 million for wrongful termination.18

In February 2012, police and courthouse managers in Vienna, Austria, staged a theatrically convincing terrorist attack as a training exercise. The staging included “one simulated death, apparently by a gunshot to the head. Makeup was used to simulate injuries, and several officers were placed in the building as if they were injured persons. The supposed death was staged in front of courthouse staff who were evacuating offices.” Because none of the ordinary staff members was informed (and nothing was announced to the public), “By the next day 40 staff members were in treatment for severe trauma and an undisclosed number had taken sick leave. We must assume that some will suffer from post-traumatic stress disorder (PTSD) in the weeks and months to come.”19 See Chapter 46 in this Handbook for more discussion of how to prepare for tests of this sort.

45.4 TERMINATION OF EMPLOYMENT. Taking our security mandate in the widest sense, we have to protect our employer and ourselves against potential damage from unethical, disgruntled, or incompetent employees, and against the legal conse- quences of improper firing procedures. Common sense and common decency argue for humane and sensitive treatment of people being fired and those who are resigning. Fir- ing people is a stressful time for everyone concerned, and it usually leads to increased security risks.20 Managers should do everything in their power to ensure a courteous, respectful, and supportive experience when terminating employment.

45.4.1 Resignations. Potentially the most dangerous form of employment ter- mination is a resignation. The problem is summed up in the caption of a cartoon where a savage attack is in progress against a medieval town that is in flames; a clan war chieftain confronts a singed and dirty warrior. “No, no, Thor! Pillage, THEN burn!” Like the war chieftain, employees rarely resign without planning. An employee may have an indefinite period during which the action is imminent, while the employer may remain unaware of the situation. If the employee has bad feelings toward, or evil designs on, the current employer, there is a period of vulnerability frequently un- known to management. Dishonest or unbalanced employees could steal information or equipment, cause immediate or delayed damage using programmatic techniques, or introduce faulty data into the system.

The policies discussed in previous sections of this chapter should reduce the risks associated with resignations. The manager’s goal should be to make resignations rare and reasonable. By staying in touch with employees’ feelings, moods, and morale, managers can identify sources of strain and perhaps resolve problems before they lead to resignations and their associated security risks.

45.4.2 Firings. Firings appear to give the advantage to employers, but there may be complications.

45.4.2.1 Timing. One advantage is that the time of notification to a fired em- ployee can be controlled to minimize effects on the organization and its business. For example, employers might find it best to fire an incompetent, or no longer acceptable, employee before beginning an important new project or after a particular project has finished.

Some people argue that to reduce the psychological impact on other employees, they should fire people at the end of the day, perhaps even before a long weekend.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TERMINATION OF EMPLOYMENT 45 · 13

The theory is that the practice gives everyone a cooling-off period outside working hours. These managers say they do not want the buzz of conversation and speculation that often follow a firing to intrude on the workday. This policy fails to regard the psychological stress to employees who have a ruined weekend and no way of responding constructively to their potentially catastrophic loss of a regular income.

A better approach to this stressful task is to fire people early on Monday morning in order to provide an unrushed exit interview and, if appropriate, job counseling to help the employee prepare for job hunting. In this scenario, the regrettable necessity (from the manager’s point of view) of terminating employment is buffered by professionals in the HR department, who can give the departing employee a sense of hope and some practical as well as emotional support in this difficult time. A humane attitude is particularly important during downsizing, or when plants are closed, and many people are being fired—one of the worst experiences possible for both employees and managers, and an event that has serious security implications.

In one large company, the personnel department asked their information security staff to suspend the access codes for more than 100 people who were to be fired at 6:00 PM on Tuesday. On Wednesday at 8:00 AM, the security staff began receiving phone calls asking why the callers’ logon IDs no longer worked. It turned out that the personnel staff had failed to inform the terminated employees on time. The psychological trauma to both the employees who were fired and to the security staff was severe. Several security staff members were sent home in tears to recuperate from their unfortunate experience. The harm done to the fired employees was even more serious, and the effect on morale of the remaining employees was a disaster. There could well have been violence in that situation.

45.4.2.2 Procedures upon Termination. In both resignations and firings, security consultants unanimously advise instant action. Not for them the leisurely grace period during which employees wind down their projects, or hand them off to other staff members. Security officers are a hard lot, and they usually advise this scenario: In a formal exit interview, and in the presence of at least two managers, an officer of the employer informs the employee politely that his or her employment is at an end. During the exit interview, the officer explains the reasons for termination of employment. The officer gives the employee a check for the period of notification required by law or by contract, plus any severance pay due. Under supervision, preferably in the presence of at least one security guard, the employee is escorted to the accustomed work area and invited to remove all personal belongings and place them in a container provided by the employer. The employee returns all company badges, IDs, business cards, credit cards, and keys, and is then ushered politely outside the building.

At the same time all this is happening, all security arrangements must be changed to exclude the ex-employee from access to the building and to all information systems. Such restrictions can include:

� Striking the person’s name from all security post lists of authorized access � Explicitly informing guards that the ex-employee may not be allowed into the building, whether unaccompanied or accompanied by an employee, without spe- cial authorization by named authorities

� Changing the combinations, reprogramming access card systems, and replacing physical keys if necessary for all secure areas to which the individual used to have authorized access

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

45 · 14 EMPLOYMENT PRACTICES AND POLICIES

� Removing or changing all personal access codes known to have been used by the ex-employee on all secured computer systems, including microcomputers, networks, and mainframes

� Informing all outside agencies (e.g., tape storage facilities and outsourced func- tions) that the ex-employee is no longer authorized to access any of the employer’s information or to initiate security or disaster recovery procedures

� Requesting cooperation from outside agencies in informing the employer if ex- employees attempt to exercise unauthorized functions on behalf of their former employer

The task is made more difficult by seniority, or if the ex-employee played an important role in disaster recovery or security. The employer should be assiduous in searching out all possible avenues of entry resulting from the person’s position of responsibility and familiarity with security procedures.

In one story circulating in the security literature, an employee was fired without the safeguards just suggested. He returned to the workplace the next Saturday with his station wagon and greeted the security guard with the usual friendliness and confi- dence. The guard, who had known him for years, was unaware that the man had been fired. The ex-employee still had access codes and copies of keys to secure areas. He entered the unattended computer room, destroyed all the files on the system, and then opened the tape vault. He engaged the guard’s help in loading all the company’s backup tapes into his station wagon. The thief even complained about how he had to work on weekends. This criminal then tried to extort money from the company by threatening to destroy the backup tapes, but he was found by police and arrested in time to prevent a disaster for his ex-employer.

This story emphasizes the importance of reaching everyone who needs to know that an employee no longer works for the enterprise.

45.4.2.3 Support in Involuntary Terminations. Security does sometimes prevent a farewell party, one obvious sign of friendliness. The problem with a farewell party at work is that employees leaving under a cloud may feel humiliated when other people get a party but they do not. Generally, it makes sense to treat all departing employees the same, even if the termination is involuntary.

However, nothing stops a humane and sensitive employer from encouraging em- ployees to arrange an after-hours party even for people who have been fired. If a resignation is on good terms, however, the employer may even arrange a celebration, possibly during working hours and perhaps at company cost, without having to worry about possible negative repercussions.

A firing, or a resignation on poor terms, has two psychological dangers: effects on the individual concerned of embarrassment, shame, and anger, and effects on the remaining staff of rumors, resentment, and fear. Both kinds of problems can be mini- mized by publishing termination procedures in organization documents provided to all employees; by requiring all employees to sign a statement confirming that they have read and agreed to the termination procedures; and by consistent application of the termination procedures.

The personal shock of being fired can be reduced by politeness and consideration consistent with the nature of the reasons for being fired, although even nasty people should not be subject to verbal or physical abuse, no matter how bad their behavior. Their treatment should be consistent with that meted out to other fired employees, and there should be generous severance arrangements, if possible.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TERMINATION OF EMPLOYMENT 45 · 15

Organizational turmoil can be reduced by convening organization-wide or depart- mental meetings to brief remaining employees on the details of a significant termina- tion. Open discussions, including how people feel about the rupture of relationships, can be helpful. The remaining employees may have to suffer grief, as a process, not a state. Grief is a normal and healthy response to disruption of relationships (e.g., death of a loved one, divorce, and even the loss of a coworker). Some people value social relationships more than other aspects of their work, and they may be especially affected by firings. Grief involves stages of denial, anger, mourning, and recovery. Trying to forestall such responses by denying that people legitimately have feelings is foolish and counterproductive. It is far better to encourage those who are upset to voice their feelings, and to engage in constructive discussion, than to clamp down in a futile attempt to suppress discussion.

45.4.2.4 Style of Termination. The way an organization handles job termi- nation affects more than internal relations; it also influences its image in the outside world. Prospective employees will think twice about accepting job offers from an or- ganization that mistreats departing employees. Clients may form a negative impression of a company’s stability if it abuses its own people. Investors also may look askance at a firm that gets a reputation for shoddy treatment of employees. Bad relations among managers and employees are a warning sign of long-term difficulties.

45.4.2.5 Legal Issues. There is another dimension to employment termination that depends on local laws and the litigation environment. The United States, for example, is said to be one of the most litigious nations on the planet, perhaps because of the high number of lawyers compared with the total population.

The list that follows is not legal advice; for legal advice, consult an attorney. How- ever, simple experience does teach some principles, even without going to law school. Here are some pragmatic guidelines for preventing legal problems related to firings for cause:

� Build a solid, documented case for firing someone before acting. � Keep good records, be objective, and get the opinions of several trustworthy people on record.

� Offer the delinquent employee all reasonable chances to correct his or her behavior. � Give the employee clear feedback long before considering firing.

Timing is important in employee relations, as it is in almost everything else we do. In particular, if an employee is found to be behaving improperly or illegally, there must be no marked delay in dealing with the problem. Such persons could sue the employer and individual managers. They could argue in court that the very fact that there was a delay in firing them was proof that the firing was due to other factors such as personality conflicts, racism, or sexism. A well-defined procedure for progressing through the decision will minimize such problems.

The critical legal issue is consistency. If rules such as those just described for the day of the firing are applied haphazardly, there could easily be grounds for complaining of unfairness. Those to whom the rules were strictly applied would justifiably feel implicitly criticized. How would we feel if we were singled out by having guards check what we took home from our desk—if everyone else got a party and two weeks’ notice? Such inconsistency would be grounds for legal proceedings for defamation of character. The company might lose and it might win, but what nonlawyer wants to spend time in court?

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

45 · 16 EMPLOYMENT PRACTICES AND POLICIES

Another issue that arises in connection with firings and resignations involves nondis- closure agreements. All such agreements must be included in a contract signed before the prospective employee begins work; it is almost impossible to force an existing employee to sign such an agreement.

Managers, the legal department, and the personnel department should study the ne- cessity and feasibility of instituting a legally binding contractual obligation to protect their company’s confidential information for a specified period of time after leav- ing. One typically does not impose indefinite gags on people, as one year seems to be normal. (However, there are exceptions. Oprah Winfrey insists that all employees who work at Harpo sign a lifelong confidentiality agreement, which an Illinois ap- peals court upheld when a former employee tried to write a book about the media mogul.) For this measure to be meaningful, the initial employment contract should stipulate that departing employees must reveal their new employer, if there is one at that time.

Noncompetition agreements require the employee to refrain from working for di- rect competitors for perhaps a year after termination of employment. The key to a successful clause here is that there be a strict, operational definition of “direct competi- tors.” Because this limitation can be an onerous impediment to earning a living, many jurisdictions forbid such clauses.

45.5 SUMMARY. Some of the key recommendations from this chapter follow:

Hiring � Investigate the accuracy of every likely job candidate’s résumé. � Perform background investigations when hiring for sensitive positions. � Arrange for experienced staff members to interview candidates and discuss in- consistencies.

� Require signing of a legally appropriate employment contract.

Ongoing Management � Identify and resolve opportunities for abuse. � Assign access functions on the basis of need, not social status. � Identify indispensable employees, and arrange for cross-training of other staff. � Require employees to take their vacations, or to rotate their job functions peri- odically, so as to assure operational continuity and as a possible indication of fraud.

� Note and respond to sudden changes in behavior and mood; involve human re- sources as appropriate.

� Enforce separation of duties and dual control for sensitive functions. � Do not engage in, or tolerate, unauthorized probes of system security.

Termination of Employment � Provide an opportunity for fired employees to receive counseling and support. � Ensure that the HR department collaborates with the information technology group to take all appropriate security measures when anyone leaves the employment of the enterprise.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

NOTES 45 · 17

� Ensure that firings do not cause long-term morale problems. � Follow the guidance of corporate counsel to avoid wrongful dismissal suits. � Use legally appropriate nondisclosure and noncompetition clauses in employment contracts.

In summary, information security depends on coordination with HR personnel to ensure consistent policies for hiring, ongoing management, and termination of employment.

45.6 FURTHER READING Armstrong, M. Armstrong’s Handbook of Human Resource Management Practice,

12th ed. Kogan Page, 2012. Cascarino, R. E. Corporate Fraud and Internal Control + Software Demo: A Frame-

work for Prevention. Wiley, 2012. Dresang, D. L. Personnel Management in Government Agencies and Nonprofit Orga-

nizations, 5th ed. Pearson, 2009. Girgenti, R. H., and T. P. Hedley. ManagingtheRiskofFraudandMisconduct:Meeting

the Challenges of a Global, Regulated and Digital Environment. McGraw-Hill, 2011.

Mathis, R. L., and J. H. Jackson. Human Resources Management, 13th ed. South- Western Cengage Learning, 2010.

McNamara, C. “All About Human Resources and TalentManagement.” 2013, http://managementhelp.org/humanresources/index.htm

NAPA (National Academy of Public Administration). “Browse Publications by Cat- egory.” 2013. www.napawash.org/publications-reports/browse-publications-by- keyword

NOLO. “Human Resources.” 2013. www.nolo.com/info/human-resources SHRM (Society for Human Resource Management). “Publications.” 2013.

www.shrm.org/PUBLICATIONS/pages/default.aspx Wells, J. T. Corporate Fraud Handbook: Prevention and Detection. 3rd ed. Wiley,

2011.

45.7 NOTES 1. For guidance on setting policies, see Chapter 44 in this Handbook; for details of

email and Internet usage policies, see Chapter 48; for security awareness advice, see Chapter 49; and for applications of the principles of social psychology in reinforcing a culture of security, see Chapter 50 in this Handbook.

2. Peter Levine, quoted in www.virtualhrscreening.com/background/whybackground .htm (URL inactive).

3. Department of Justice Press Release, “Jury Finds Former Coke Employee Guilty in Conspiracy to Steal and sell Coca-Cola Trade Secrets,” February 2, 2007, http://atlanta.fbi.gov/dojpressrel/pressrel07/tradesecrets020207.htm (URL inactive).

4. See Chapter 10 in this Handbook for more details on understanding computer crime statistics.

5. “Around the Nation: 2d Man Pleads Guilty in Wells Fargo Case,” The New York Times, August 12, 1981, p A.10 (fee required), http://tinyurl.com/5byd6c

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

45 · 18 EMPLOYMENT PRACTICES AND POLICIES

6. L. J. Kushner, “Career Management 101 for Information Security Pros,” Search- Security Website, June 29, 2006, http://searchsecurity.techtarget.com/generic/ 0,295582,sid14 gci1196912,00.html

7. L. Stack, “Employees Behaving Badly: Combating Desk Rage,” HC On- line Website, October 5, 2004, www.hcamag.com/resources/learning-and- development/employees-behaving-badly-combating-desk-rage-110891.aspx

8. See Chapter 47 in this Handbook. 9. See Chapter 39 in this Handbook.

10. See Chapter 47 in this Handbook. 11. Nicholas Leeson’s official Website: www.nickleeson.com/biography/index.html 12. M. E. Kabay, “Continuity of Operations and the Capability Matrix,” In-

foSec Perception, February 1, 2013, http://resources.infosecskills.com/perception/ continuity-of-operations-and-the-capability-matrix (URL inactive).

13. M. E. Kabay, “Computer-Aided Consensus,” 2009, www.mekabay.com/ methodology/cac.pdf

14. M. Jacka, and P. Keller, Business Process Mapping: Improving Customer Satisfac- tion. Wiley, 2009.

15. S. Pacenka, “Computer Crime?” State of Oregon v. Randal Schwartz, Washington County Circuit Court C94-0322CR, 2007. Complaint brought by Mr. Schwart’s client, the Intel Corporation; www.lightlink.com/spacenka/fors

16. I. Winkler, “Guard against Titan Rain Hackers,”Computerworld, October 20, 2005, www.computerworld.com/securitytopics/security/story/0,10801,105585,00.html

17. N. Thornburgh, “The Invasion of the Chinese Cyberspies (and the Man Who Tried to Stop Them),” Time, August 29, 2005, www.time.com/time/magazine/ printout/0,8816,1098961,00.html (URL inactive).

18. J. Vijayan, “Reverse Hacker Wins $4.3M in suit against Sandia Labs: Shawn Carpenter used his own hacking techniques to probe outside breach,” Computerworld, February 14, 2007, www.computerworld.com/action/article.do? command=viewArticleBasic&articleId=9011283

19. M. Krausz, “Terrifying Your Employees: Not Recommended for Training,” InfoSec Perception Website, March 12, 2012, http://resources.infosecskills .com/perception/terrifying-your-employees-not-recommended-for-training (URL inactive).

20. S. Terlap and E. Morath, “Final Day at Ford Bittersweet for Scores of Salaried Workers,” Detroit News, March 1, 2007, http://detroitnews.com/apps/ pbcs.dll/article?AID=/20070301/AUTO01/703010359/1148

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

46CHAPTER

VULNERABILITY ASSESSMENT

Rebecca Gurley Bace and Jason Sinchak

46.1 THE SCOREKEEPER OF SECURITY MANAGEMENT 46 · 1 46.1.1 What Is Vulnerability

Management? 46·1 46.1.2 What Is Vulnerability

Assessment? 46·2 46.1.3 Where Does

Vulnerability Assessment Fit in Security Management? 46·3

46.1.4 Brief History of Vulnerability Assessment 46·3

46.2 A TAXONOMY OF VULNERABILITY ASSESSMENT TECHNOLOGIES 46 · 4 46.2.1 Vulnerability

Assessment Strategy and Techniques 46·4

46.2.2 Network Scanning 46·4 46.2.3 Vulnerability Scanning 46·5 46.2.4 Assessment Strategies 46·5 46.2.5 Strengths and

Weaknesses of VASs 46·6 46.2.6 Roles for Vulnerability

Assessment in System Security Management 46·7

46.3 PENETRATION TESTING 46 · 7 46.3.1 Testing Goals 46·8 46.3.2 Testing Perspectives 46·9 46.3.3 Testing Types 46·9 46.3.4 Social Engineering 46·10 46.3.5 Managing a

Penetration Assessment 46·11

46.4 FUTURE READING 46 · 12

46.5 NOTES 46 · 13

46.1 THE SCOREKEEPER OF SECURITY MANAGEMENT. Information se- curity has, over time, evolved from a collection of esoteric security issues and technical remedies to its current state, in which it is more tightly integrated with the area of enterprise risk management. One hallmark of this evolution from technology to management discipline is the emphasis placed on the deployment and use of vul- nerability management practices. Vulnerability management has three complementary functional components, vulnerability assessment (VA), penetration testing, and reme- diation. Vulnerability management is considered fundamental to modern information security practice, and its components have adapted in architecture, features, and inter- faces to accommodate the changing landscape of modern enterprises.

46.1.1 What Is Vulnerability Management? Vulnerability management is the process of assessing deployed IT systems in order to determine the security state of those systems. It includes the automated scanning of system attributes (vulnera- bility assessment), the manual testing and exploitation of systems in search of illicit

46 · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

46 · 2 VULNERABILITY ASSESSMENT

authorization or access (penetration testing), and the determination of corrective mea- sures to mitigate issues identified that represent exposures for the enterprise, as well as managing the application of those measures (remediation). Vulnerability assessment is considered by many the key technology component of vulnerability management. However, there is a synergy between VA and the other elements of vulnerability man- agement such that these elements drive what features are supported by VA technology (i.e., vulnerabilities that arise in the course of penetration testing may be reflected in future versions of VA scanners). Although early vulnerability management systems fo- cused on vulnerabilities in operating systems and network configuration of IT enterprise systems, over time, the scope of VM coverage has grown to include applications as well.

The vulnerabilitymanagement processisoftendefinedintermsof four keyfunctions. They are as follows:

� Inventory. Before an examiner can determine the extent of testing, she must identify all systems that are resident within the domain of interest. At this time, the operating system platforms and functions associated with each system are articulated and documented; furthermore any unauthorized or unmanaged systems are identified.

� Focus. Once an examiner has an idea of the systems that reside within the network, he must determine what information he (or his assessment tools) needs to see in order to find those vulnerabilities that are relevant to him and the enterprise. Some include the tuning of VA tools as a part of this step. When VA is driven by compliance requirements, such information is often specified in the regulations or policies in question.

� Assess.The examiner performsanytesting(bothautomatedandmanual) necessary to identify vulnerabilities resident on the systems. She then assesses the results of these tests. Finally, she evaluates (and ranks) the actual risk to her organization’s systems security, making that judgment guided by security policy and current risk management criteria.

� Respond. Finally, the examiner must execute procedures that act on the results of the assessment in order to address the problems identified. As much of current vulnerability management is performed as part of regulatory compliance, formal reporting of the results of VA, including remediation status, is an important part of this step.

Now that we’ve laid the cornerstones of the vulnerability management process, let’s proceed to the technology particulars of VA.

46.1.2 What Is Vulnerability Assessment? VA is the analysis of the se- curity state of a system on the basis of system information collected on demand. The four-step strategy for VA is as follows:

1. A predetermined set of target system attributes (for example, specific parameters for particular firewalls), are sampled.

2. The sampled information is placed in a data store. 3. The data store is organized and compared to a reference set of attributes. 4. The differences between the data store and the reference set are documented and

reported.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

THE SCOREKEEPER OF SECURITY MANAGEMENT 46 · 3

46.1.3 Where Does Vulnerability Assessment Fit in Security Manage- ment? Vulnerability assessment and its parent function, vulnerability management are key elements of virtually all modern system security management strategies. There are many reasons for the popularity and acceptance of these functions, including:

� When systems are first deployed, VA allows you to baseline the security state of those systems.

� When security breaches are suspected, VA may allow you to quickly identify likely paths of attack and furthermore, determine whether they have been exercised.

� When new vulnerabilities are reported, VA can allow you to identify systems that are subject to the vulnerabilities so that you can patch or otherwise address the exposures.

� The results of individual VAs can be archived and used to document the security state of systems at a specific time. This is often used to satisfy regulatory audit or other oversight requirements.

Although VA and vulnerability management are accepted as important system security functions, they are not sufficient to protect systems from all security threats. Such measures should be included in a more comprehensive security strategy that in- cludes security policy and procedural controls (see Chapters 44, 47, 50, 51, 52, and 53 in this Handbook), network firewalls and other perimeter defenses (Chapters 26 and 27), strong identification and authentication mechanisms (Chapters 28 and 29), access control mechanisms (Chapter 32), file and link encryption (Chapters 7, 32, and 33), file integrity checking (Chapters 7, 24, and 37), physical security measures (Chapters 22 and 23), and security training and education (Chapters 43, 45, 48, and 49). There are references and insight into building the rest of a comprehensive security strategy throughout this Handbook.

46.1.4 Brief History of Vulnerability Assessment. Early vulnerability as- sessment systems (VASs) include the COPS system, developed in the late 1980s by Eugene H. Spafford and Daniel Farmer at Purdue University.1 COPS was a UNIX- targeted credentialed VA product that gained wide acceptance in security circles. The initial freeware version of the Internet Security Scanner (ISS) was also released in the early 1990s, as was Farmer’s and Wietse Venema’s VA software, SATAN.2

Subsequent trends of note include the advent of open-source tools for performing various forms of VA (e.g., NESSUS,3 which provides vulnerability scanning capabil- ities, and NMAP,4 which provides an inventory of the systems on a specific network, along with the network services resident on those systems).

Also of note is the move of VA from individual systems to the network infrastructure (i.e., dedicated network-connected appliances) and to the cloud (i.e., the VA is actually performed over the network, controlled by the security administrator over a Web interface, with results stored offsite).

Finally, as endpoints have become more mobile and application-centric than classic workstations, VA coverage has grown to cover software applications. The solution provider market for VA has adapted to these trends, and modern VA practice usually involves a mix of application software, dedicated appliances, managed services, and expert professional services (especially in areas such as penetration testing.)

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

46 · 4 VULNERABILITY ASSESSMENT

46.2 A TAXONOMY OF VULNERABILITY ASSESSMENT TECHNOLO- GIES. VA products snapshot the security state of systems, diagnosing problems that indicate that the system is vulnerable to specific attacks.

VA performs an examination of key indicators within systems that are known to correspond to security vulnerabilities. Some consider some types of VAs a special case of a host-based, interval-based intrusion detection process and describe it in terms of the intrusion detection process model outlined in Chapter 27 in this Handbook.

46.2.1 Vulnerability Assessment Strategy and Techniques. As noted above, there is a four-stage high-level strategy for conducting VA: Sample, Store, Compare, and Report. This four-stage process becomes quite complex when fleshed out to cover the full range of vulnerabilities that are commonly exploited by modern adversaries. A standard VA process may involve the use of any or all of the following techniques:

� Network Scanning. Maps network nodes and associated services by use of a “port scanner.” This articulates issues at a network and network services layer of abstraction.

� Vulnerability Scanning. Takes the port scanning functions of network scanners to the next level by testing for operating system and application software system vulnerabilities resident on hosts connected to the network.

� Password Cracking. Identifies weak passwords. � Log Review. A feature rooted in the earliest production computing platforms, log review remains one of the most powerful means of identifying weaknesses in systems.

� Integrity Checking. Uses checksums, hash totals, and digital signatures to allow quick and reliable detection of tampered files and system objects.

� Virus Detection. Scans for known viruses infecting systems. � War Dialing. Scans enterprise systems for unauthorized modems. � War Driving. Scans enterprise systems for unauthorized wireless LAN connec- tions.

� Penetration Testing. Reenacts attackers’ behavior in order to gain access and thereby test technical and procedural security measures.5

As many of these techniques are complex enough to merit a full chapter of their own (and are covered in specific chapters in this Handbook), we focus on only three of them in this chapter: network scanning, vulnerability scanning, and penetration testing.

46.2.2 Network Scanning. Network scanners run a function called a port scanner, which uses a feature of ICMP, part of TCP/IP, in order to identify hosts available in a specified network address range. The port scanner then scans identified systems for open network ports and associated services.

Some network scanners use inference and other techniques to make intelligent guesses about the operating systems being run on open systems. These inferences are based on the combinations of active ports observed on a specific host (e.g., if Port 80 is open on a given host, it is likely running a Web server). Some scanners listen to ports for traffic that provides additional information about the system connected to that port.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

A TAXONOMY OF VULNERABILITY ASSESSMENT TECHNOLOGIES 46 · 5

One example of this type of surveillance is called banner grabbing, and can provide a great deal of detail about the connected system. The scanner collects information that is routinely sent to any process on connection; this banner often includes details of the name and version of the application.6

As a primary security policy decision involves specifying what systems are allowed on an enterprise network, network scanners provide a vital piece of information for VA. They also provide collateral information regarding the connected systems on a network, which is critical for tuning and refining the VA process. It is important, however, to understand that although the operation of a network scanner is automated, the identification of vulnerabilities discovered by network scanning is not. There is minimal, if any, decision support in network scanning products—some will identify certain port numbers as associated with a known Trojan attack. Therefore, it is important that the results from a network scanner be evaluated by someone familiar with the assessed network and associated security policy.

Increasingly, VA products include passive network scanning in addition to active net- work scanning. This involves placing passive network monitors to sniff traffic between target systems, inferring vulnerabilities from the traffic patterns observed between the target systems. This is useful in certain enterprise situations when protective mech- anisms interfere with more classic active scanning (e.g., personal firewall agents on endpoints) but provides insights versus actionable results.

46.2.3 Vulnerability Scanning. Vulnerability scanning is the heart of tradi- tional VA systems. In some ways vulnerability scanning appears to be the same as port scanning, but it differs in a critical way—it takes the additional step of not only collecting data regarding traffic, connections, and system attributes, but also analyzes the data to determine whether it matches a known vulnerability. Many systems (cre- dentialed; see below) also attempt to correct the vulnerabilities identified in the scan, either automatically or overseen by human operators.

As vulnerability scanning usually targets specific hosts, it often conducts a deeper inspection than network scanners, identifying software versions, specific software ap- plications, and configuration attributes of systems. The policy checks available to host-based vulnerability scanners can include usage patterns for software.

Perhaps the most valuable feature of vulnerability scanners is the current database of known vulnerabilities. Virtually all commercial offerings in this area include updates to these vulnerability databases as a core feature of the product. Many products offer features that assist security managers in configuring scanners to fit their environments, including a wide variety of configuration, reporting, and support features.

Vulnerability scanners can perform extremely fine-grained security assessment, in far more detail than network port scanners. However, this degree of detail comes at a price. Vulnerability scanners are typically slower and more resource greedy than network port scanners. The range of available assessment techniques is usually richer for vulnerability scanners; some (e.g., DDoS testing) can disrupt the normal operation of an enterprise network. False-positive rates (i.e., vulnerabilities spotted where none exist), can be high for many vulnerability scanners, requiring more human intervention. Finally as the value of the vulnerability scanner resides in its vulnerability database, it is critical that the database be updated frequently. A vulnerability scanner with a noncurrent database leaves users open to compromise.

46.2.4 Assessment Strategies. As in intrusion detection systems, VASs have features that allow differentiation between individual systems. The primary descriptors

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

46 · 6 VULNERABILITY ASSESSMENT

for VASs involve the information sources and how those information sources are generated.

46.2.4.1 Credentialed Monitoring. Credentialed monitoring approaches for VAs are those that utilize system data sources such as file contents, installed applica- tions, configuration information, and status information. This information is gained from nonintrusive sources; that is, it is gained by performing standard system status queries and inspection of system attributes. These sources are accessible only when the entity gathering them has legitimate access to the system (i.e., the entity pos- sesses access credentials). In UNIX systems, this information is gathered at the host or device level; therefore, credentialed approaches are also host-based approaches. As many modern operating systems (e.g., Windows) handle status information differ- ently, often providing it in the form of Application Programming Interfaces (APIs), the credentialed = host-based equivalence does not always apply in those environments.

46.2.4.2 Noncredentialed Monitors. Noncredentialed monitoring ap- proaches are those approaches that stage system attacks and record target system responses to the attacks. These approaches are much more intrusive than credentialed attacks and do not assume (nor do they require) any legitimate access to the target sys- tem; they are launched from an attacker’s perspective. Noncredentialed approaches are often called active approaches and have detection and monitoring features that comple- ment those of credentialed approaches. In particular, noncredentialed approaches are usually superior for diagnosing vulnerabilities associated with network services. As noted, in UNIX systems, noncredentialed assessments are usually considered network- based assessments. For instance, network scanning is a noncredentialed monitoring process. It bears repeating that here, as in credentialed approached, the equivalence relationship does not necessarily apply in Windows and other modern operating system environments that provide status information in API form.7

46.2.5 Strengths and Weaknesses of VASs. Knowing that security point products (e.g., firewalls, NIDS, and access-control systems) that defend particular features of a security perimeter cannot be perfect in the dynamic world of network and system attack, VASs serve an important function in the overall strategy for protecting information assets.

The benefits associated with vulnerability analysis are as follows:

� VASs conserve time and resources, as they allow even nonexpert personnel to check systems automatically for literally thousands of problems, any one of each might result in an intrusion.

� VASs can be extremely helpful in training security novices to make systems more secure.

� VASs can be updated to reflect new knowledge of vulnerabilities found by vendors and researchers.

� VASs can be configured to address specific vulnerabilities and configurations affected by regulatory requirements. They are a critical component in IT security regulatory compliance.

As VASs are used in more environments as a part of a risk-management regime, they are helpful for benchmarking the security state of systems in order to document progress toward a protection goal.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

PENETRATION TESTING 46 · 7

As security problems have become an item of broad interest to customer and reg- ulatory communities, the capabilities of VASs may be a fundamental requirement for operating in certain IT markets. This inclusion of VA as a requirement for doing business is likely to not only remain stable over time, but grow at an appreciable rate.

VASs are systematic and therefore consistent. These attributes allow them to be used as quality assurance measures for network or security managers. Many security professionals routinely recommend that operational security policies include provisions for using VASs to check systems for problems after major changes have occurred (as might be the case whenever software is updated or system recovery is required).

Weaknesses in VA include the following:

� Although VA is necessary for system security, it is not in and of itself sufficient to secure a system.

� Many VASs serve only to diagnose problems, not to correct them. They are part of a more comprehensive vulnerability management process. User follow-through is still required.

� If the VASs are not kept up to date, they may mislead users into underestimating the risk of penetration.

� VAS can negatively impact the performance of an operational network. It is critical to balance demand for the network with the performance hits associated with running some types of VAS.

As in many other knowledge-based security tools, VA can be used for either pro- ductive or malicious purposes. In the hands of a security manager, VA is a valuable diagnostic technique. In the hands of an attacker, VA may optimize efforts to iden- tify targets of attack and provide insight as to exactly how those targets might be compromised.

46.2.6 Roles for Vulnerability Assessment in System Security Man- agement. VA products can be used at several points in the system security man- agement life cycle.

First, when a new program is put into place, a VA can baseline the security state of the system. This application is particularly valuable in establishing the case for a security program, as it provides hard evidence that security problems exist.

Next, when an operational system changes (as might be the case when software updates are installed or new equipment is connected), a VA can help. It can find specific security vulnerabilities that occur as side effects of such changes.

Finally, when security incidents occur or are suspected, VA results can assist inves- tigators in diagnosing possible paths of entry for attackers, locating artifacts of attacks (such as back doors or Trojan horses), and identifying the system resources affected by an attack so that they may be restored to their original states.

46.3 PENETRATION TESTING. A penetration assessment is used to augment the vulnerability management program’s reoccurring and baseline VA by iteratively exploiting known and unknown vulnerabilities with the intent of demonstrating busi- ness impact and risk across technical, physical, and personnel environments. The goal of a VA and underlying automated vulnerability scanning activities is to identify and prioritize known technical vulnerabilities. A penetration assessment will test the effec- tiveness of the VA through the objective identification of vulnerabilities in the environ- ment and the ensuing exploitation of them. The exploitation of known vulnerabilities

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

46 · 8 VULNERABILITY ASSESSMENT

demonstrates the real-life impact and business risk associated with the VA’s ability to effectively identify known vulnerabilities and remediate them in the environment. The exploitation of unknown vulnerabilities or “stacked” known vulnerabilities will assess the organization’s ability to respond to an incident or mitigate the impact caused by unforeseen vulnerabilities. Exploitation is performed in a manner that closely simulates actions that a real-life attacker is capable of performing outside and within the targeted environment.

Penetration assessments are performed by professional, ethical hackers using auto- mated and manual techniques in conventional and unconventional ways. A penetration assessment should be leveraged to augment a VA and not as a replacement for the vulnerability scanning component. Assessments are performed by a team of qualified practitioners, ensuring well-rounded subject matter expertise in diverse areas.

Human penetration (“pen”) testers have several advantages over purely automated methods:

� Automated VA tools, such as vulnerability scanners, are incapable of leveraging a vulnerability, component, or specification through a sequence of iterative and adaptive actions which may produce a high-impact outcome.

� A VA is only capable of testing and assessing the organization’s susceptibility to known vulnerabilities; a penetration test is inclusive of unknown vulnerabilities and the exploitation of both.

� Pen testers possess an out-of-the-box mentality combined with a continuous strive to adapt circumvention efforts and pivot around preventative controls.

� Penetration tester activities are very difficult to mirror through automated means primarily due to human intuition.

� A pen tester thinks very differently than a traditional system or network admin- istrator, making a large effort to solve problems in an untraditional way using traditional tools or methods.

46.3.1 Testing Goals

46.3.1.1 Demonstration of Impact and Risk. As penetration testers, our hearts thrive on the ability to compromise a target and received the coveted command level access. Although this may appear successful in the short term, the ultimate goal of a penetration test is to determine, demonstrate, and explain the risk as it applies to the organization, with accompanying steps to mitigate it or adequately manage it in the future.

Management should discuss with the penetration team what the assessment’s end goal should be. Goal-oriented penetration testing aims to maximize value by demon- strating impact and risk appropriately for the organization’s unique business. Goals include things that are important to the organization outside of security controls, such as the theft of intellectual property, theft of client base information, or a reduction in availability for core business processes thereby affecting an organization’s bottom line.

46.3.1.2 Attestation and Compliance. The result of the penetration assess- ment can be provided to management, business partners, or regulators as an attestation to organizations point-in-time level of susceptibility to impact as a result of the current effectiveness of the vulnerability management program and underlying assessment capabilities.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

PENETRATION TESTING 46 · 9

A penetration assessment is a point-in-time assessment. Due to the fluid nature of information security advancement, a penetration testing team can never provide any level of assurance relating to the audit of vulnerabilities currently present in the environment. The primary goal of a penetration assessment is to demonstrate business impact and risk to management and business partners for the threats they face at a specific point in time.

46.3.2 Testing Perspectives. Penetration assessments provide a vehicle for evaluating the security of technical, physical, personnel, and procedural controls at a holistic level through the objective perspective of a third party mimicking the actions of an external attacker or malicious internal user. A VA is typically managed by an internal office and is therefore subject to bias during the assessment phase and compounded by resistance to the advancement in skillsets required to align with an advancing security field.

A malicious user and external attacker are different perspectives and approaches to the assessment which result in different perceived levels of impact and risk. It is important to understand the difference in order to properly develop the scope of the assessment to cover VA and management’s objective for the assessment.

External Attacker � An external attacker mimics the capabilities of an outsider with no internal knowl- edge of the target environment.

� The capabilities of an external attacker are greatly limited to publicly available resources.

� This type of test typically involves attacks against perimeter network devices and applications, which may result in internal connectivity.

Malicious User � A malicious user mimics the capabilities of an authenticated or authorized user who possesses knowledge of internal operations.

� The capabilities of a malicious user are only afforded to trusted employees or contractors inside the network perimeter or within an application’s authenticated or authorized zone.

� This type of test typically poses a greater risk of impact than an external attack, primarily due to the intricate knowledge pertaining to the location of and adequacy of preventive controls around sensitive data.

46.3.3 Testing Types. Penetration testing can be utilized to expand the scope of a technical VA to include the physical, personnel, and procedural controls that may be targeted by an adversary in an attack. Additionally, penetration tests can be used to increase focus on a particularly weak technical area within the over-arching assessment.

External Assessment: Penetration efforts originate from the Internet and target Internet-facing devices with the primary goal of gaining internal access to sys- tems and acquiring business trophies such as client information or intellectual property.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

46 · 10 VULNERABILITY ASSESSMENT

Application Assessment: Application level assessments are increasingly common as organizations continue to remove Internet-accessible external services and heavily leverage Web services. Application assessments involve user-based attacks such as manipulating user input or client-controlled parameters. Goals include accessing administrative panels, extracting sensitive database infor- mation, masquerading as authorized users, or compromising the underlying Web or backend database server.

Internal Assessment: Internal penetration assessments target vulnerabilities within the organization. This assessment assumes the role of an attacker or malicious users who has been provided access to a network port within the facility. Goals of this assessment mirror those of an external or application assessment with the inclusion of a reduced level of accessibility controls.

Wireless Assessment: Wireless penetration assessments involve internally and ex- ternally surveying the organization’s physical facilities for authorized and unauthorized wireless communications (e.g., 802.11) and attempting to cir- cumvent or exploit controls to gain access. The primary goal of this assessment is to gain internal access to resources. Secondary goals of a wireless assessment include those of an internal assessment on achieving connectivity.

Physical Assessment: Physical security assessments focus testing activities on by- passing controls designed to prevent access to the facility and access to physical electronic data such as computing areas or telecommunication closet.

Personnel and Social Engineering: Personnel and social engineering assessments aim to test an organization’s security awareness training and ability of person- nel to follow procedures designed to safeguard their interactions with external parties.

46.3.4 Social Engineering. Security depends on people; therefore, people are the single weakest link in any penetration assessment and overarching VA. People possess the power to assist an attacker in covertly bypassing any security control in the environment with a minimal amount of resources. Social engineering is defined as the use of persuasive techniques to abuse an inherent trust relationship and induce personnel to divulge information or perform an action used to gain illicit access to systems or data. Social engineering attacks can be performed through multiple mediums of communication, such as telephone conversations, convincing emails, or spoofed Websites.

Social engineering attacks have historically been leveraged in many high-profile security breaches involving Advanced Persistent Threats (APTs). This is primarily due to the level of effectiveness, covert nature, high impact of return, and ease of execution. Including social engineering as a component of a penetration assessment should be considered to evaluate policies, procedures, and security awareness programs designed to protect the business and inform personal of this particular threat.

Practical recommendations � The decision to include Social Engineering as part of the assessment should align with objectives and goals.

� Precautionary measures should be taken to protect the testing team from unnec- essary harm if they are identified; this can be provided through a “get-out-of-jail- free” document provided by upper management.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

PENETRATION TESTING 46 · 11

Common assessment scenarios The following are example scenarios commonly executed during penetration assessments inclusive of Social Engineering tests:

� USB/CD Drops: The testing team stages a series of USB thumb drives or CDs with an auto-run or convincing “click me” executable. This executable “calls home” to an Internet rendezvous point once executed. This test is benign and rudimentary but a valuable determination of the susceptibility of authorized personnel to executing attacker provided code on internal systems.

� Email Phishing/Pharming: Hoaxes or scams are sent to a subset of targeted per- sonal groups by an attacker masquerading as an internal employee or department with the intent of coercing them into responding, visiting a malicious Web page, or executing an attachment.

� Call Masquerading: The testing team contacts a provided list of phone numbers for a subset of personal groups within the organization to elicit information or perform an action by posing as an employee or contractor.

46.3.5 Managing a Penetration Assessment. Varying testing models can used to fine-tune the impact of the penetration assessment and align it with the vulner- ability management and assessment goals.

46.3.5.1 Announced versus Unannounced Testing. Announced testing introduces awareness to internal IT staff prior to the beginning of the assessment. The primary motivation behind announced testing is to reduce any perceived impact from testing activities.

� Due to heightened awareness, announced testing reduces the effectiveness of the assessment to accurately evaluate security monitoring and incident response processes.

� Announced testing can provide educational value by presenting a learning op- portunity to internal security staff through the real-time observation of controls, which are attacked or circumvented.

Unannounced testing involves the covert performance of testing activities under the sole knowledge and authorization from upper management to perform the agreed-upon assessment. Unannounced testing will deliver the most accurate assessment of all tested security controls.

Due to the covert nature of unannounced testing, activities are commonly focused on demonstrating impact through only exploiting vulnerabilities, which will quickly and covertly lead to a desired trophy.

46.3.5.2 Testing Scope. The penetration testing scope should be developed so that it aligns with the objectives of the assessment and its purpose within the vulnerability management program. It should be noted that regulatory requirements may dictate the scope to include specific network segments or applications (e.g., the Payment Card Industry Data Security Standard, or PCI DSS).

Penetration assessments can be scoped to allow social engineering attacks and specify to what degree these attacks will proceed, such as targets for phishing campaigns or locations for USB/CD drive drops.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

46 · 12 VULNERABILITY ASSESSMENT

Scope should ensure the assessment covers all intended areas within the VA, such as physical, personnel, and procedural controls.

� Scope should be reduced to a manageable number of targets within the envi- ronment for the allocated time period to ensure proper assessment of critical components.

� Scope reduction may eliminate a subset of vulnerabilities but may be necessary to ensure adequate time is available to test the environment and important assets using the provided methodology.

46.3.5.3 Testing Methodology. A penetration assessment should be per- formed under a consistent and repeatable methodology to ensure it can be operated in a repeatable manner for each VA.

Penetration testing activities involve a large variety of techniques and tools. The best way to harness and document the range of activities is through a vetted and documented methodology.

A structured methodology is crucial to accurately document the scope and depth for which testing activities should be performed.

� The assessment must be performed under a proven and structured methodology to be accepted by many third-party auditors or regulatory agencies.

� A structured methodology enables the ability to transition testing resources into and out of the assessment and provides results in a comparative manner between testing periods.

46.4 FUTURE READING Abraham, J. “Goal-Oriented Penetration Testing—The New Process for Penetration

Testing.” Personal Website, November 16, 2009. http://spl0it.wordpress.com/ 2009/11/16/goal-oriented-pentesting-the-new-process-for-penetration-testing

Abraham, J. “Goal-Oriented Penetration Testing (Part 2).” Personal Website, November 17, 2009. http://spl0it.wordpress.com/2009/11/17/goal-oriented-pentesting— the-new-process-for-penetration-testing-part-2/

Foster, J. C., and V. T. Liu. Writing Security Tools and Exploits. Syngress, 2006. Fischer, M., and Kabay, M. E. “Penetration Testing, Part 3,” Network World Security

Strategies, February 11, 2003, www.networkworld.com/newsletters/sec/2003/ 0210sec1.html

Faircloth, J. Penetration Tester’s Open Source Toolkit, 3rd ed. Syngress, 2011. Hurley, C., R. Rogers, F. Thornton, and B. Baker. Wardriving & Wireless Penetration

Testing. Syngress, 2007. Kabay, M. E. “Social Engineering in Penetration Testing: Cases.” Network World

Security Strategies Alert, October 25, 2007. www.networkworld.com/ newsletters/2007/1022sec2.html

Manzuik, S., A. Gold, and C. Gatford. Network Security Assessment: From Vulnera- bility to Patch. Syngress, 2006.

McGraw, G., “Is Penetration Testing a Good Idea?” Network Magazine, July 2005, www.cigital.com/papers/download/0507sec.penetration.pdf

Orlando, J., and Kabay, M. E., “Social Engineering in Penetration Testing: Analysis,” Network World Security Strategies, October 30, 2007, www.networkworld.com/ newsletters/sec/2007/1029sec1.html

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

NOTES 46 · 13

PCI Security Standards Council. Information Supplement: Requirement 11.3 Penetration Testing. 2008. https://www.pcisecuritystandards.org/pdfs/infosupp 11 3 penetration testing.pdf

Schumacher, P., and Kabay, M. E. “Social Engineering in Penetration Testing: In- timidation,” Network World Security Strategies, November 8, 2007, www. networkworld.com/newsletters/sec/2007/1105sec2.html

Siemens Insight Consulting, “Penetration Testing,” April 2006, www.insight. co.uk/files/datasheets/ Penetration%20Testing%20(Datasheet).pdf

Skoudis, E. “Maximizing Value in Pen Testing.” SANS Penetration Testing, February 9, 2012. http://pen-testing.sans.org/blog/2012/02/09/maximizing-value-in-pen- testing (URL inactive).

Van Der Walt, C., H. D. Moore, R. Temmingh, H. Meer, J. Long, C. Hurley, and J. Foster. Penetration Tester’s Open Source Toolkit. Norwell, MA: Syngress, 2005.

46.5 NOTES 1. D. Farmer and E. H. Spafford, “The COPS Security Checker System,” Proceedings of the Summer USENIX Conference, Anaheim, California, June 1990, pp. 165–170, http://docs.lib.purdue.edu/cgi/viewcontent.cgi?article=1844&context=cstech

2. D. Farmer and W. Venema, “Improving the Security of Your Site by Breaking into It,” Internet white paper, 1993, www.csm.ornl.gov/∼dunigan/cracking.html

3. Nessus Vulnerability Scanner. www.nessus.org 4. NMAP.ORG. http://nmap.org/ 5. J. Wack, M. Tracy, and M. Souppaya, “Guideline on Network Security Testing,”

NIST Special Publication 800-42, National Institute of Standards and Technol- ogy, October, 2003, http://csrc.nist.gov/publications/nistpubs/800-42/NIST-SP800- 42.pdf (URL inactive).

6. wiseGEEK, “What is Banner Grabbing?” wiseGeek Website, 2013, www.wisegeek. com/what-is-banner-grabbing.htm

7. A. Shostack and S. Blake, “Towards a Taxonomy of Network Security Assessment Techniques.” Proceedings of 1999 Black Hat Briefings, Las Vegas, NV, July 1999, www.blackhat.com/presentations/bh-usa-99/AdamS/shostack-blackhat.pdf

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

47CHAPTER

OPERATIONS SECURITY AND PRODUCTION CONTROLS

M. E. Kabay, Don Holden, and Myles Walsh

47.1 INTRODUCTION 47 · 2 47.1.1 What Are Production

Systems? 47·2 47.1.2 What Are Operations? 47·3 47.1.3 What Are Computer

Programs? 47·3 47.1.4 What Are

Procedures? 47·4 47.1.5 What Are Data Files? 47·4

47.2 OPERATIONS MANAGEMENT 47 · 4 47.2.1 Separation of Duties 47·4 47.2.2 Security Officer or

Security Administrator 47·5

47.2.3 Limit Access to Operations Center 47·5

47.2.4 Change-Control Procedures from the Operations Perspective 47·7

47.2.5 Using Externally Supplied Software 47·9

47.2.6 Quality Control versus Quality Assurance 47·10

47.3 PROVIDING A TRUSTED OPERATING SYSTEM 47 · 13 47.3.1 Creating Known-

Good Boot Medium 47·13

47.3.2 Installing a New Version of the Operating System 47·13

47.3.3 Patching the Operating System 47·13

47.4 PROTECTION OF DATA 47 · 14 47.4.1 Access to Production

Programs and Control Data 47·14

47.4.2 Separating Production, Development, and Test Data 47·15

47.4.3 Controlling User Access to Files and Databases 47·15

47.5 DATA VALIDATION 47 · 16 47.5.1 Edit Checks 47·16 47.5.2 Check Digits and

Log Files 47·17 47.5.3 Handling External

Data 47·18

47.6 CLOUD COMPUTING AND PRODUCTION SYSTEMS 47 · 18

47.7 CONCLUDING REMARKS 47 · 20

47.8 FURTHER READING 47 · 21

47.9 NOTES 47 · 21

47 · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

47 · 2 OPERATIONS SECURITY AND PRODUCTION CONTROLS

47.1 INTRODUCTION. Despite the enormous increase in individual computing on personal computers and workstations in the years since the first edition of this Handbook was published in 1975, centralized arrays of dozens, hundreds, or thousands of computersusedincomputational arraysandcloudservicesare still usedfor enterprise computing in applications devoted to the core business of the enterprise. This chapter focuses on how to run vital computers and networks safely and effectively.

Readers with a military background will note that operations security in the civilian sector is different from the OPSEC (a military acronym for “operational security”) designation used in military discourse. As defined by the Joint Chiefs of Staff of the United States military, “OPSEC seeks to deny real information to an adversary, and prevent correct deduction of friendly plans.”1

In determining what operations security and production controls are required for any system, a thorough risk analysis should be conducted; you will find references throughout this Handbook. For a quick analysis, it may be helpful to use a few other common military acronyms and list the threats from their perspectives.

EMPCOA—enemy’s most probable course of action. What is the most likely course of action an attacker will take against your systems?

EMDCOA—enemy’s most dangerous course of action. What is the worst possible thing an attacker could accomplish?

Weighing these as part of a risk analysis can help tremendously to decide how to employ limited resources. The acronym METT-TC, which is essentially a larger version of the engineering triad of cost, time, and quality, may help. There are various versions of the METT-TC acronym, but perhaps the most useful stands for

� Mission (what we need to do), � Equipment (what we have), � Time (by when we need to do it), � Troops (whom we have to do it), � Terrain (where are we doing it), and � Culture (the possible cultural considerations).

Each part of our METT-TC analysis should be self-evident, except for perhaps culture. Ignoring the management, political, and community cultures of the locations in which to install security controls is a frequent mistake, usually with dire consequences for both security and the careers of security professionals.

It is critical to be able to define precisely the terms associated with operations security and production controls before engaging in a discourse about them.

47.1.1 What Are Production Systems? A production system is one on which an enterprise depends for critically important functions. Examples include systems for handling accounts receivable, accounts payable, payroll, inventory, man- ufacturing systems, real-time process control, data-entry systems, Web-based client interfaces for e-commerce, critical information systems, portable data-handling sys- tems, and management information systems. What is defined as critical is a function of the mission, not a uniform prescription. Thus, the accounts receivable may be a critically important function for a manufacturing company working on a tight profit

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

INTRODUCTION 47 · 3

margin, with receivables needed to pay immediately for crucial supplies, but it may be less critical for a small group of successful partners running a consulting firm.

47.1.2 What Are Operations? Operations consist of the requirements for control, maintenance, and support of production systems. Operations staff are respon- sible for such functions as:

� Integrating new software systems into an existing configuration � Running programs and batch jobs to update databases and create reports � Installing new versions of production programs � Maintaining production databases for maximal efficiency � Managing backups (creation, labeling, storage, and disposal) � Responding to emergencies and recovering functionality � Mounting storage volumes of tapes, cartridges, or disks in response to user or program requests

� Handling special forms for particular printouts (e.g., check blanks) � Managing all aspects of production networks, such as configuring routers, bridges, gateways, wireless propagation, and firewalls

47.1.3 What Are Computer Programs? A computer program is a set of instructions that tells a computer what to do to perform a task. Computer programs may be acquired, or they may be internally developed.

Internally developed programs are stored in computer systems in two basic forms. Source programs are in the form in which they were written (coded) by computer programmers. The statements in source programs are in languages such as COBOL, Visual BASIC, C++, and Java. Source language programs are kept in files and stored on disk folders called source libraries or program libraries. Executable programs have been converted from source code, by compilation or

interpretation, into a program that the computer can execute. Executable programs may be maintained in two separate forms: object and load.

An object program is a partially executable module that must be linked to other executable modules, such as input/output modules, to become a load module. As load modules, the programs are said to be in executable form. Executable programs are kept in production libraries, from which they are called when needed. Acquired programs are generally in object and load form. The source code is proprietary to the organization that developed it and is rarely given to the acquiring enterprise.

When internally developed programs have to be changed, programmers work with copies of the source programs. The copies are stored in another type of library, referred to as programmer libraries. The programmers make changes to their copy of the source programs, and go through a process of recompiling and testing until the modified pro- gram is working properly. When acquired programs require changes, often a contract to make the modifications is issued to the organization from which the programs were acquired. In some situations, internal programmers generate new programs and inter- faces to the original acquired programs. The same libraries are used: source libraries for source code, production libraries for executable modules, and programmer libraries for work in progress. These libraries need to be protected. Loss or damage can entail huge costs and considerable inconvenience; recovering them can require a long time and great expense.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

47 · 4 OPERATIONS SECURITY AND PRODUCTION CONTROLS

47.1.4 What Are Procedures? Procedures are sets of statements that tell a computer what to do in certain situations. They are unlike programs in that they are not compiled. Stored in files or databases, they are invoked and interpreted as needed. Procedural statements are made up of operational commands and parameters. The operational commands tell the computer what to do, and the parameters tell the computer which entity to act upon. Job Control Language (JCL) is an example of a procedural language. Procedural language statements often are used in database management systems and in security software products. On personal computers, batch files (.BAT) are a form of simple procedure.

47.1.5 What Are Data Files? Almost everything stored and maintained in a computer system takes the form of a file.2 Programs, procedures, information, all are stored in files, using the concept of a file in its broadest sense; that is, a collection of related items. This usage has become most apparent with the ubiquitous personal computer (PC). Data files, as distinguished from program files and other types, are those that store information. In a PC environment, data files may be called documents. Documents are created by word processors, spreadsheet programs, graphics generators, and other application programs. In mainframe and midsize computer environments, data files are those created and maintained by applications such as payroll, accounting, inventory, order entry, and sales.

Some data files are transient; that is, they are created, used, and deleted within a short period of time. If lost or damaged, they can be reconstructed quickly, with little difficulty. There is usually no need to protect transient files. Other files, such as master files or organizational databases (groups of files that are linked to one another using a database management system or DBMS), contain information that is vital, confidential, or virtually irreplaceable. These files, generated by PCs, mainframes, and midsize computer systems, must be protected by security software and backup procedures to ensure against loss, destruction, theft, interference, and unauthorized disclosure.

47.2 OPERATIONS MANAGEMENT. The processes for effective and efficient management of operations have direct benefits on information assurance. In particu- lar, these aspects of operations management are of special value for improving and maintaining security:

� Separation of duties � Defining the role of the security officer or security administrator � Limiting access to the operations center � Defining secure change-control processes � Careful controls over externally supplied software � Managing quality assurance and quality control

47.2.1 Separation of Duties. Separation of duties (also discussed in Chap- ter 45 in this Handbook) is a key control that should be applied to development and modification of programs. In enterprises where there are systems and programming departments that create and maintain custom programs, each individual programmer is assigned a user ID and a password. In these enterprises, where programs are developed and maintained internally, changes are constantly made to programs in order to meet

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

OPERATIONS MANAGEMENT 47 · 5

changing business requirements. Modified executable programs, after recompilation and testing by programmers, are moved from their libraries into production libraries. Modified source programs are moved into source libraries. The programmers are re- sponsible for keeping the source libraries current, while computer operations, or some other functional group separated from programming, may be responsible for maintain- ing the production libraries. When an updated executable program is transferred from the programmer’s library to the production library, a transmittal is included, signed off by a manager in the programming department.

A particular consequence of the separation of duties is that a member of the op- erations staff should always be involved in the functional analysis and requirements definition phases for changes to production programs. The operations perspective is not always clear to programmers, and such issues as logging, backout, and recovery, as discussed later in this chapter, need to be brought to their attention early in the development and maintenance cycles.

It is critically important that programmers and operations staff understand that under no circumstances are programmers to install changes into production systems without adequate testing and authorization. Patch management is discussed in detail in Chapter 40 in this Handbook.

47.2.2 Security Officer or Security Administrator. Contemporary enter- prises typically include a mix of external cloud-computing services, mainframes, mid- size computers, and local area networks (LANs) comprising hundreds or thousands of workstations, PCs, terminals, and other devices, all interconnected with one another, and often connected with the same mix in other enterprises throughout the world via the Internet.

A department, or an individual or small group in smaller enterprises, has the respon- sibility for providing and maintaining the security of files, databases, and programs. The title that is often associated with this function is information security officer (ISO) or information systems security officer (ISSO). This individual or department has the mandate to carry out the security policy as set down by the senior management of the enterprise. The security officer is empowered to allow or to disallow access to files, databases, and programs. In the language of the security officer, procedures are set up and maintained that establish relationships among individuals, programs, and files. Users, programmers, and technicians are granted privileges for full access, update only, or even read only. The security officer has the power to change or to revoke privileges (see Chapter 24 in this Handbook for details of operating-system security mechanisms; see Chapters 28 and 29 for discussions of identification and authentication).

47.2.3 Limit Access to Operations Center. Physical access to the opera- tions center grants a person enormous power to disrupt production systems. Such access must be tightly controlled.

47.2.3.1 Need, Not Status, Determines Access. A fundamental principle for effective security is that access to restricted areas is granted on the basis of roles. Employees whose roles do not justify access should be excluded from autonomous ac- cess to production systems. In particular, high-placed executives, such as the president, chief executive officer, chief financial officer, chief operating officer, chief technical officer, and all vice presidents, should examine their own roles and determine if they should be able to enter the operations center unaccompanied; in most cases, such ac- cess is unjustified. Limiting their own access sets an important model for other aspects

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

47 · 6 OPERATIONS SECURITY AND PRODUCTION CONTROLS

of security policy and demonstrates that need, not social status or position within the corporate hierarchy, determines access to restricted areas. This issue is also discussed in Chapter 45 on employment practices and policies in this Handbook.

47.2.3.2 Basic Methods of Access Control. As explained in Chapters 28 and 29 in this Handbook, access control depends on identification and authentication (I&A). I&A can be based on:

� What one has that others lack (tokens such as physical keys or smart cards) � What one knows that others don’t know (user IDs and passwords or passphrases) � What one is that differs from what others are (static biometric attributes, such as fingerprints, iris patterns, retinal patterns, and facial features)

� What one does differently from how others do it (dynamic biometrics, such as voice patterns, typing patterns, and signature dynamics)

A typical arrangement for secure access to an operations center may involve keypads for entry of a particular code or card readers programmed to admit the holders of specific magnetic-stripe cards, smart cards, or radio-frequency identification (RFID) tokens. If the operations center is a 24-hour operation with full-time staffing, the presence of operators provides an additional layer of security to preclude unauthorized access. Remote monitoring of sensitive areas increases security by discouraging unauthorized access or unauthorized behavior and speeds up the response to possible sabotage. For extensive discussion of physical and facilities security, see Chapters 22 and 23 in this Handbook.

47.2.3.3 Log In and Badge Visitors. Visitors to a facility that houses sen- sitive systems should be logged in (that is, their identification checked and recorded in writing) at a controlled entrance and provided with visitor badges.

In high-security applications, an additional login may be required when entering the operations center itself. To encourage return of visitor badges, some security policies require the visitor to deposit a valuable document, such as a driver’s license, with the security guards at the main entrance.

The effectiveness of visitor badges as a means of identifying nonemployees depends entirely on the use of badges by all personnel at all times; if not wearing a badge is acceptable and common, a malicious visitor could simply hide a visitor badge to pass as an authorized employee.

The time of login and of logout can be valuable forensic evidence if malfeasance is detected. However, such records can be shown to be reliable only if the guards responsible for keeping the logs consistently verify the completeness and correctness of all information written into the logs. Video recordings of the entrance to capture the face of each visitor as well as the exact time of arrival and departure can be of great value both for identifying imposters and also for verifying that the security guards are doing their job properly.

47.2.3.4 Accompany Visitors. No unaccompanied visitors should be permit- ted to circulate in the operations center or in the facility housing such a center. In high-security facilities, someone must even accompany the visitor to the washroom and wait for the visitor outside the door.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

OPERATIONS MANAGEMENT 47 · 7

If a consultant or temporary employee is to work on a project for longer than a day, it may be acceptable to grant that person a restricted pass for low-security areas; however, high-security areas, such as the operations center, would still require such a person to be accompanied.

When one of the authors (Kabay) was director of technical services for a large service bureau in Montreal in the mid-1980s, the president of the company arrived unannounced on a Saturday evening at the door of the operations center with a visitor to show him around the computer center. The young operator explained with some trepidation that the president’s name was not on the list of approved solo visitors, and so he would not grant entry (although he offered to call his boss for authorization). To his credit, the president accepted the restriction gracefully—and wrote a letter of commendation for the operator on Monday morning.

47.2.4 Change-Control Procedures from the Operations Perspective. When programmers have made changes to production programs and all documentation and testing procedures are complete, the new versions are formally turned over to the operations staff for integration into production.

47.2.4.1 Moving New Versions of Software into Production. Oper- ations managers and staff must meet these demands when moving new versions of software into production:

� Identification—tracking which software is in use � Authorization—controlling changes � Scheduling—minimizing disruptions to production � Backups—ensuring that all requisite information is available to restore a prior state

� Logging—keeping track of data input for recovery, and of errors for diagnosis of problems

� Backout—returning to a prior production version in case of catastrophic errors

47.2.4.1.1 Identification. Knowing precisely which versions of all production software are in use is the basis of production controls. Every module must have a unique identification that allows immediate tracking between executable code and source code; all changes to a particular module must be fully documented by the pro- gramming group. Unique identifiers allow the quality assurance process to ensure that the only modules that go into production are those that have been properly tested.

Most production shops use a three-level numbering scheme to track versions. Typi- cally, version a.b.c (e.g., 7.13.201) is defined in this way:

� c changes every time anything at all—even a spelling mistake—is changed. � b changes when program managers decide to group a number of fixes to errors into a new version for release to production.

� a changes when significant new functions are added; often the source code is completely renumbered if the changes are great enough.

The version number of object code must match the number of its source code. All object code should include internal documentation of its version number so that

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

47 · 8 OPERATIONS SECURITY AND PRODUCTION CONTROLS

the version can be ascertained instantly, without having to consult possibly inaccurate external documentation.

47.2.4.1.2 Authorization. Strict procedures must be in place to preclude rogue programmers from introducing modified code into the production suite. In addition to the dangers of introducing untested or undocumented changes, allowing any individual to modify production processes without verification and authorization by an appropriate chain of responsibility can allow hostile code, such as Trojan horses and backdoors (see Chapters 13, 16, and 20 in this Handbook), to be introduced into the systems.

47.2.4.1.3 Scheduling. Implementing any new version of a production system requires careful planning and scheduling. Operations staff must prepare for changes in all aspects of production that depend on the system in question; for example, there may be requirements for new printer forms, additional magnetic tapes, and other supplies that must be ordered in advance. New requests for operator intervention, or changes in status and error messages during production, necessitate appropriate documentation and training. Effects on other programs may require special preparations that must take into account the scheduling requirements of the other systems that are affected. In addition, new versions of software often are implemented immediately after major production jobs, such as end-of-year or quarterly processing, to maintain consistency within an accounting period. For all these reasons, scheduling is critically important for trouble-free operations.

47.2.4.1.4 Backups. When modifying production systems, operations staffs usu- ally take one or more complete backups (see Chapter 57 in this Handbook) of the software and data to be modified. This procedure is essential to allow complete restora- tion of the previous working environment should there be catastrophic failure of the new software and data structures.

System managers and operators should be aware that if their proposed changes require reformatting disk drives on the production system, they must make at least two full backups to ensure that an error in one of the backups won’t cause a catastrophe when the entire system has to be restored.

47.2.4.1.5 Logging. To allow recovery or backout without losing the new data and changes to existing data that may have been carried out using new software and data structures, all production programs should include a logging facility. Logging keeps a journal of all information required to track changes in data and to regenerate a valid version of the data by applying all changes to an initial starting condition. Logging requires synchronization with backups to avoid data loss or data corruption. Special requirements may exist when a new version of the production system involves changes to data structures; in such cases, applying the information about changes to the older data structures may require special-purpose application programs. Since programmers sometimes forget about such possibilities, operations staff should be prepared to remind the programming staff about such requirements during the design phases for all changes.

47.2.4.1.6 Backout and Recovery. Sometimes a new version of production soft- ware is unacceptable and must be removed from the production environment. This decision may be made immediately, or it may occur after a significant amount of data entry and data manipulation has taken place. In either case, operations should be able

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

OPERATIONS MANAGEMENT 47 · 9

to return to the previous version of a production system without data loss. This process involves restoring the earlier complete operating environment, with software and data in synchrony, and then using log files to repeat the data input and data modifications from the moment of changeover to the moment of fallback (see Chapter 52 in this Handbook).

Not all of the changes that were made using a new version will necessarily be applicable to the previous data; for example, if new fields were added to a database, the data stored in those fields would not be usable for an older, simpler data structure. Similarly, if fields were removed in the newer database, recovery will involve providing values for those fields in the older database. All of these functions must be available in the recovery programs and backups that should accompany any version change in production systems.

47.2.4.2 Using Digital Signatures to Validate Production Programs. If an unauthorized intruder or a disgruntled employee were discovered to have gained access to the production libraries, it would be necessary to determine if there had been unauthorized modifications to the production programs.

Date and time stamps on programs can record the timing of changes, but many operating environments allow such information to be modified using system utilities that read and write directly to disk without passing through normal system calls. In those instances, there would be no time stamp or log entry.

One approach that has been used successfully is to apply checksums to all production components. Checksum software applies computations to programs as if the codes were simply numbers; the results can be sensitive to changes as small as a single bit. However, if the checksums are computed the same way for all programs, access to the checksum utility could allow a malefactor to change a module and then run the checksum utility to create the appropriate new checksum, thus concealing the evidence of change. To make such subterfuge harder, the checksums can be stored in a database. Naturally, this database of checksums itself must be protected against unauthorized changes, for example, using encryption. Storing checksums may make unauthorized changes more difficult to disguise, but it also extends the chain of vulnerabilities.

A better way of determining whether object code or source code has been modified is to use digital signatures. Digital signatures are similar to checksums, but they require input of a private key that can, and must, be protected against disclosure. Verifying the digital signature may be done using a corresponding public key that can be made available without compromising the secrecy of the private key. For more information on public and private keys, see Chapter 7 on encryption and Chapter 37 on PKI and certificate authorities in this Handbook.

When digital signatures are used to authenticate code, it may be possible to validate production systems routinely, provided that the process is not too arduous to be accom- plished as part of the normal production process. For example, it should be possible to validate all digital signatures in no more than a few minutes, before allowing the daily production cycle to start.

47.2.5 Using Externally Supplied Software. Production often uses soft- ware from outside the organization; such software may be commercial off-the-shelf (COTS) programs or it may consist of programs modified for, or written especially for, the organization by a software supplier. In any case, external software poses special problems of trust for the production team. There have been documented cases in which production versions of software from reputable software houses have contained viruses

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

47 · 10 OPERATIONS SECURITY AND PRODUCTION CONTROLS

or Easter eggs (undocumented features, such as the well-known flight simulator in MS- Excel 97, which popped up a graphic landscape that included a monitor showing the names of the Excel development team). In addition, some consultants have publicly admitted that they deliberately include Trojan horse code (undocumented malicious programming) that allows them to damage data or inactivate the programs they have installed at client sites if their fees are not paid.

In large data centers, it may be possible to run quality-assurance procedures on externally supplied code (see Chapter 39 in this Handbook). Such tests should include coverage monitoring, in which a test suite exercises all the compiled code corresponding to every line of source code. However, it is rare that an operations group has the resources necessary for such testing.

The trustworthiness of proprietary external software written or adapted especially for a client ultimately may depend on the legal contracts between supplier and user. Such legal constraints may not prevent a disgruntled or dishonest employee in the supplier organization from including harmful code, but at least they may offer a basis for compensation should there be trouble.

47.2.5.1 Verify Digital Signatures on Source Code If Possible. If ex- ternally supplied code is provided with its source library as well as with compiled modules, operations should try to have the supplier provide digital signatures for all such programs. Digital signatures will permit authentication of the code’s origins and may make it harder for malefactors to supply modified code to the user. In addition, the digital signatures can support nonrepudiation of the code (i.e., the supplier will be unable credibly to claim that it did not supply the code) and therefore the signatures may be useful in legal action, if necessary.

47.2.5.2 Compile from Source When Possible. Wherever possible, it is highly desirable to be able to compile executables from source code on the target machine. Compiling from source allows quality assurance processes to check the source for undocumented features that might be security violations and to couple the executables tightly to the verified source. In addition, compiling on the local system ensures that all calls to system routines will be satisfied by linking to executables such as dynamic link libraries (DLLs) supplied in the current version of the operating system.

However, compilation on a local system has additional implications that complicate implementation of new applications: Because the system routines being linked to the compiled code may not be identical to those used during the manufacturer’s quality assurance tests, the customer organization must plan for its own quality assurance testing.

Operations staff should express this preference for source code clearly to the person or group controlling acquisition of external software. For more information about writing secure code, see Chapter 38 in this Handbook; for information about secure software development and software quality assurance, see Chapter 39.

47.2.6 Quality Control versus Quality Assurance. Throughout this chapter, quality assurance has been mentioned as an essential underpinning for op- erations security. Quality assurance refers to the processes designed to ensure and to verify the validity of production programs. However, another aspect of quality concerns the operations group: the quality of output. The process of verifying and ensuring the quality of output is known as quality control.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

OPERATIONS MANAGEMENT 47 · 11

47.2.6.1 Service-Level Agreements. Unlike mathematical truth, there is no absolute standard of quality for computing operations. Every organization must define the level of quality that is suitable for a particular application. A commonly quoted principle in programming and operations is that there is a complex relationship among quality, cost, and development time: Increasing quality increases both cost and develop- ment time; shortening development time increases cost, if quality is to be maintained. It follows that every system should include a definition of acceptable performance; such definitions are known as service-level agreements (SLAs).

SLAs typically include minimum and maximum limits for performance, resource utilization, and output quality. The limits should be expressed in statistical terms; for example, “The response time measured as the time between pressing ENTER and seeing the completed response appear on screen shall be less than three seconds in 95 percent of all transactions and shall not exceed four seconds at any time.” SLAs may define different standards for different types of transactions if the business needs of the users so dictate.

47.2.6.2 Monitoring Performance. Computer-system performance depends on five elements:

1. Access time and speed of the central processing unit(s) (CPU) 2. Access time and speed of mass storage (disks) 3. Access time and speed of fast memory (RAM) 4. Application design 5. Available network bandwidth

Operations groups should monitor performance to ensure that the requirements of the SLAs are met. There are two approaches to such monitoring: (1) analysis of log files and (2) real-time data capture and analysis.

Log files that are designed with performance analysis in mind can capture the precise times of any events of interest; for example, one might have a record in the log file to show when a particular user initiated a read request for specific data and another record to show when the data were displayed on the user’s screen. Such level of detail is invaluable for performance analysis because the data permit analysts to look at any kind of transaction and compute statistics about the distribution of response times. In turn, these data may be used for trend analysis that sometimes can highlight problems in program or data structure, design, or maintenance. For example, an excessively long lookup time in a data table may indicate that the system is using serial data access because it had been designed without an appropriate index that would permit rapid random access to the needed records.

Another approach to performance monitoring and analysis is to use real-time moni- tors that can alert operations staff to abnormal performance. For example, an application program may be designed to calculate response times on the fly; the results may be displayed numerically or graphically on a dashboard for the operations staff. Values falling below a specified parameter may signal an abnormal condition, using color or sound to alert the operators to the drop in performance. Such integrated performance metrics allow the fastest possible response to performance problems. Extensive sets of real-time measures are sometimes called situational awareness tools.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

47 · 12 OPERATIONS SECURITY AND PRODUCTION CONTROLS

Eveniftheapplicationprogramslackintegratedperformancemetrics, it issometimes possible to use system-level online performance tools to analyze system activity. In one instance in the experience of one of the authors (Kabay), for example, a software supplier in the mid-1980s had promised a response time of 10 seconds or less for all transactions, but one particular operation was taking 43 minutes. Because the SLA was violated, the client was threatening to sue the supplier for the entire development cost and the three years of maintenance payments—a total of $3.8 million (about $12 million in 2013 dollars). Using an online performance tool, it quickly became obvious that the transaction in question was generating an enormous amount of disk I/O (read and write operations): 80,000 random-access reads in a particular data set to filter out a few target records using a nonindex field. Installing and using an appropriate index and compacting the data set on that field as the primary key to provide rapid access to blocks of related records reduced response time to 6 seconds.

47.2.6.3 Monitoring Resources. Consistent monitoring of resource utiliza- tion is one of the most valuable roles of the operations staff. Data center operations should include regular analysis of system log files to track changes in the number of files, amount of disk free space available, number of CPU cycles consumed, number of virtual memory swap operations, and less esoteric resource demands, such as numbers of lines or pages printed, number of tape mounts requested, number of backup tapes in use, and so on. These data should be graphed and subjected to trend analysis to project when particular resources will be saturated if the trend continues. Even a sim- ple spreadsheet program such as Excel can produce regression lines in graphs easily. Operations can then reduce demand either by improving aspects of production (e.g., optimizing programs to require fewer resources) or by increasing available resources (e.g., installing a memory upgrade).

Another level of analysis focuses on specific users and groups of users. Each func- tional group using the production systems should be analyzed separately to see if there are discontinuities in their trends of resource utilization. For example, a specific de- partment might show a relatively slow and stable rise in CPU cycles consumed per month—until the rate of increase suddenly increases tenfold. If such a rate of increase were to continue, it could surpass all the rest of the system demands combined; opera- tions therefore would investigate the situation before it caused problems. The cause of the discontinuity might be a programming error; for example, there might be a logical loop in one of the programs or a repeated computation that ought to have its result stored for reuse. However, the change in slope in CPU utilization might be due to in- troduction of new programs with a rapidly growing database; in such cases, operations would have to act to meet heavy new demands.

Disk space is often a key resource that can cause problems. If users fail to clean up unwanted files, disk space can disappear at an astounding rate. This problem is exacerbated by poor programming practices that allow temporary work files to re- main permanently in place. Systems have been designed with tens of thousands of sequentially numbered temporary work files that had no function whatsoever after a production run was completed but that were accumulated over several years.

One of the methods widely used to reduce resource waste is chargeback. Using system and application log files, system administration charges the users of particular systems a fee based on their use of various resources. Sometimes these chargebacks are viewed as funny money because they are an accounting fiction—no money actu- ally changes hands. However, requiring managers to budget carefully for computing resources can greatly improve attention to mundane housekeeping matters such as

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

PROVIDING A TRUSTED OPERATING SYSTEM 47 · 13

cleaning up useless files. If the chargeback system extends to aspects of program per- formance such as number of disk I/Os, it can even influence programmers to optimize their design and their code appropriately. Optimization is appropriate when the to- tal costs of optimization are less than the savings in resources and the increases in productivity that result from optimization efforts, measured over the lifetime of the application.

47.2.6.4 Monitoring Output Quality. The final component of quality con- trol is the meticulous monitoring of everything that is produced in the data center and sent to users or clients. Although much printing is now performed on local printers con- trolled by users, in many situations the operations group is responsible for documents such as payroll checks, invoices, and account status reports. Every operations group must explicitly assign responsibility for verifying the quality of such output before it leaves the data center. Operators should keep careful logs that record various types of error (e.g., torn paper, misaligned forms, or poor print quality) so that management can identify areas requiring explicit attention or repairs to improve quality.

47.3 PROVIDING A TRUSTED OPERATING SYSTEM. The operating sys- tem (OS) is usually the single biggest and most important example of externally supplied software in a data center. Because the OS affects everything that is done in production, it is essential to know that the software is trustworthy. To this effect, operations staff use procedures to ensure that known-good software is always avail- able to reinstall on the system. Systems with such software are known as trustworthy computing platforms.

47.3.1 Creating Known-Good Boot Medium. The simple principle that underlies known-good operating software is that there shall be an unbroken chain of copies of the OS that have never run any other software. That is, operations will create a boot medium (tape, cartridge, CD-ROM) immediately after installing known-good software.

For example, if boot-medium V1B0 is defined as version 1 of the OS as it is delivered from the manufacturer; its installation would require specific settings and parameters for the particular configuration of the system. Immediately after installing V1B0, but before running any other software, operations would create medium V1B1 and set it aside for later use if V1B0 had to be replaced.

47.3.2 Installing a New Version of the Operating System. Continuing this example of how to maintain known-good operating software, it might become necessary to install a new version of the operating system—say, version 2 on medium V2B0. Before using V2B0, operations would reinstall the current known-good OS, say from V1B1. Only then would V2B0 be installed, and the new boot medium V2B1 would be created immediately.

47.3.3 Patching the Operating System. Often, when it is necessary to modify a small part of the OS, rather than installing a whole new version, manufacturers ask users to patch the OS. The patch programs modify the compiled code in place. If checksums or digital signatures are in use to maintain OS integrity, these codes will

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

47 · 14 OPERATIONS SECURITY AND PRODUCTION CONTROLS

have to be regenerated after the patch is applied. However, to maintain a known-good status, applying a patch should follow a rigid sequence:

1. Load the current known-good software from the appropriate medium (e.g., V2B1).

2. Install the patch. 3. Immediately create a known-good boot medium before running any other soft-

ware (in our example, this medium would be V2B2).

For extensive discussion of managing patches for production systems, see Chapter 40 in this Handbook.

47.4 PROTECTION OF DATA

47.4.1 Access to Production Programs and Control Data. Just as the operations center needs restricted access, so do production programs and data. From a functional point of view, there are three categories of people who might be allowed access to programs and data on which the enterprise depends: users, programmers, and operations staff.

47.4.1.1 Users. The only people who should have read and write access to production data are those users assigned to the particular systems who have been granted specific access privileges. For example, normally only the human resources staff would have access to personnel records; only the finance department staff would have full access to all accounts payable and accounts receivable records. Managers and other executive users would have access to particular subsets of data, such as productivity records or budget figures. Of course, no user should ever have write access to production programs.

47.4.1.2 Programming Staff. Programmers create and maintain production programs; they naturally have to be able to access the versions of those programs on which they currently are working. However, programmers must not be able to modify the programs currently used in production. All changes to production programs must be documented, tested, and integrated into the production environment with the supervision of quality assurance, operations, and security personnel.

Programmers need to be able to use realistic data in their development, maintenance, and testing functions; however, programmers should not have privileged access to restricted data. For example, programmers should not be allowed to read confidential files from personnel or medical records or to modify production data in the accounts payable system. Programmers can use extracts from the production databases, but particular fields may have to be randomized to prevent breaches of confidentiality. Programmers generally resent such constraints, but usually an effective process of education can convince them that maintaining barriers between production systems and systems under development is a wise policy.

47.4.1.3 Operations Staff. Much as the programmers are responsible for de- veloping and maintaining systems, so the operations staff are responsible for using and controlling these systems. Operations staff perform tasks such as scheduling, er- ror handling, quality control, backups, recovery, and version management. However,

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

PROTECTION OF DATA 47 · 15

operations staff should not be able to modify production programs or to access sensitive data in production databases.

47.4.2 Separating Production, Development, and Test Data. For ob- vious reasons, testing with production data and production programs is an unacceptable practice, except in emergency situations. Therefore, programmers who develop new programs or modify existing programs must perform tests using their own libraries. These are frequently referred to as test libraries. Experienced programmers keep copies of the source programs for which they are responsible as well as copies of some of the data files that are used by the programs and subsets of others in their own test libraries. To avoid security violations, such copies and subsets of privileged data should be anonymized to the degree necessary to protect confidentiality. For example, a system using personnel data might substitute random numbers and strings for the employee identifiers, names, and addresses.

It is important to include time stamps on all files and programs, including both production and test versions. This practice serves to resolve problems that arise about program malfunctions. If all programs and files have time stamps, it can be helpful in determining whether the most current version of the load program is in the production library and whether test files and production files have been synchronized.

Final testing prior to production release may entail more formal review by an independent quality assurance section or department; the quality assurance group may also control transfers of programs to the production library.

47.4.3 Controlling User Access to Files and Databases. Access to files has to be controlled for two reasons:

1. There is confidential information in files that is not to be made accessible to everyone.

2. There are other files that are considered auditable.

The information in these files may be confidential, but that is not the reason for controlling access to them. The information in these files must be controlled because changing it is illegal. An example would be an enterprise’s general ledger file once the books have been closed. Changing the information in these files gave birth to the pejorative phrase cooking the books. The original copies of these files are developed on the computer that handles the day-to-day transactions of an enterprise. Some time after the month-end closing of the books, copies of these files are archived. In this form they are the recorded history of the enterprise and cannot be changed. Storing this chiseled-in-stone historical information, combining details and summaries in database format so as to be accessible for the purpose of analysis is known as data warehousing.

In most large enterprises, these files are created on mainframe and midsize comput- ers, although microcomputer database servers in LANs are increasingly in use today. In any event, controlling user access to files is performed in several ways depending on what types of access are allowed. Remote access to online production databases and files is often done over leased lines—dedicated communication facilities paid for on a monthly basis as opposed to dial-up or switched lines paid for on a when-used basis. Access control may be readily accomplished through the use of front-end security soft- ware modules, which in turn feed into database and file handling software and finally into the application software. For example, in an environment using a software product

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

47 · 16 OPERATIONS SECURITY AND PRODUCTION CONTROLS

for handling queries and updates of online databases and files, a number of different security software products could be installed. Such products use what are called rules or schemas to validate user IDs and passwords, to authorize types of transactions, and to allow access to files and databases.

Many information system installations allow remote communications for many kinds of transactions. Various individuals, including sales representatives entering order information and traveling executives wishing to access current information from databases or files, use public networks, such as wired or wireless Internet service providers at hotels, airports, and coffee shops. This type of access increases the potential for security breaches. The usual practice today is to use virtual private networks (VPNs), which consist of encrypted channels between the portable equipment and the enterprise networks. Even so, some inadequate implementations of VPNs allow cleartext transmission of the initial logon information, allowing the identification and authentication data to be captured and used for unauthorized access. Poorly secured network access also allows man-in-the-middle attacks on the user’s traffic.

For more information about encryption, see Chapters 7 and 37 in this Handbook; for more about network and communications security, see Chapters 5, 25, 32, 33, and 34.

47.5 DATA VALIDATION. Just as it is essential to have trusted operating sys- tems and application software for production, the operations group must be able to demonstrate that data used for production are valid.

Validation controls normally are carried out dynamically throughout data entry and other processing tasks. Some validity checks are carried out automatically by database software; for example, inconsistencies between header records and details may be reported as errors by the database subsystems. Bad pointers are usually flagged immediately as errors by the database software; examples include:

� Pointers from a particular master record to a detail record with the wrong key value or to a nonexistent location

� Forward or backward pointers from a detail record to records that have the wrong key value for the chain or that do not exist at all

However, many errors cannot be caught by database subsystems because they involve specific constraints particular to the application rather than errors in the database itself. For example, it may be improper to allow two chemical substances to be mixed in a processing vat, yet there is nothing in the data themselves that the database software would recognize as precluding those two values to be recorded in the input variables. The programmers must include such restrictions in edit checks; often these relations among variables can be coded in a data dictionary. If the programming environment does not allow such dependencies, the programmers must incorporate the restrictions in lookup tables or in initialization of variables.

From a production point of view, operations staff must run appropriate validation programs created by the database suppliers and by the application programmers to assure the quality of all production data. The next sections review in more detail what is involved in such validation programs.

47.5.1 Edit Checks. Operations should have access to diagnostic programs that scan entire databases looking for violations of edit criteria. For example, if a field is

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

DATA VALIDATION 47 · 17

designated as requiring only alphanumeric characters but not special characters such as “#” and “@,” then part of the diagnostic sweep should be checking every occurrence of the field for compliance with those rules. Similarly, range checks (greater than, less than, greater than or equal, equal, less than or equal, between) are a normal part of such scans. Lookup tables listing allowed and forbidden data and combinations of data provide further sophistication for more complex relations and restrictions. In any case, the role of operations staff is to run the diagnostics and identify errors; correction of the errors should fall to authorized personnel, such as the database administrators.

Diagnostic programs should provide detailed information about every error located in the production files. Such details include:

� Configurable view of the record or records constituting an error, showing some or all of the fields

� Unique identification of such records by file name or number, record number, and optionally by physical location (cylinder, sector) on disk

� Error code and optional full-text descriptions of the error, including exactly which constraints have been violated

A diagnostic program should, ideally, also allow for repair of the error. Such repair could be automatic, as, for example, insertion of the correct total in an order-header, or manual, by providing for the database administrator to correct a detail record known to be wrong.

47.5.2 Check Digits and Log Files. Another form of verification relies on check digits. Programs can add the numerical or alphanumeric results of data manipu- lations to each record or to groups of records when transactions are completed properly. Finding records with the wrong check digits will signal inconsistencies and potential errors in the processing. Check digits are particularly useful to identify changes in production databases and other files that have been accomplished through utilities that bypass the constraints of application programs. For example, most databases come with a relatively simple ad hoc query tool that permits lookups, serial searches, views, and simple reporting. However, such tools often include the power to modify records in compliance with database subsystem constraints, but completely free of application program constraints.

An even more powerful type of utility bypasses the file system entirely, and works by issuing commands directly to the low-level drivers or to the firmware responsible for memory and disk I/O. In the hands of the wrong people, both database and system utilities can damage data integrity. However, it is usually difficult for the users of these utilities to compute the correct checksums to hide evidence of their modifications. A diagnostic routine that recomputes checksums and compares the new values with the stored values can spot such unauthorized data manipulations immediately.

If possible, checksums in log files should be chained from one record to the next so that the checksum for every record is calculated using the checksum from the previous record in addition to the data in the current record. Changing, adding, or deleting any record in the log file then requires the criminal to modify all subsequent checksums, and comparison of the modified log file with the backup of the original log file may easily identify the tampering because there are so many discrepancies in evidence.

A similar technique for validating and repairing data uses database and application log files to record information such as before and after images of modified records.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

47 · 18 OPERATIONS SECURITY AND PRODUCTION CONTROLS

Such log files also can include special marker records to flag different steps in complex transactions; these flags can allow diagnostic programs to identify precisely when transactions have been interrupted or subjected to other forms of failure. Using these log files, it is often possible to identify which defective transactions need to be removed, repeated, or completed.

Commercial data-integrity software is available for a wide range of platforms and databases. Searching on “data integrity software” in the Google search engine (www.google.com) locates many references to such products.3

For more information on integrating security into application design, see Chapter 52 in this Handbook. For more about log files and other monitoring and control systems, see Chapter 53.

47.5.3 Handling External Data. Before using data provided by external or- ganizations, operations should routinely check for data purity. Diagnostic routines from the programming group should be available to check on all data before they are used in batch processing to update a production database. The same principles of data validation used in checking production databases should apply to all data received from clients, suppliers, governments, and any other organization. Special validation programs can and should be written or obtained to test the data received on any medium, includ- ing tapes, cartridges, removable discs, CD-ROMs, DVDs, and data communications channels.

47.6 CLOUD COMPUTING AND PRODUCTION SYSTEMS. The history of production computing is repeating itself: In the 1960s through the 1980s, computers were so physically large and hugely expensive that many smaller organizations con- tracted with service bureaus to access computing resources. Connections in physically close locations (e.g., city cores) were often through physical coaxial cable or twisted pair connections. For more distant connections, clients linked their dumb terminals to the mainframes through telephone lines using modems. Sometimes the switched telephone connections through the plain old telephone service (POTS) were fixed in place and dedicated to the connection—hence they were called dedicated lines.

Today, as we approach the middle of the 2010s, the speed of Internet connections is reaching 10 Gbps—an enormous bandwidth that facilitates remote access to banks of computing power of almost unimaginable power.4 Organizations are capitalizing on the possibility of creating virtual machines (virtualization) that insulate concurrent processes from each other, allowing far more efficient sharing of centralized resources than running processes on dedicated systems in-house. Inexpensive computers (thin clients) with relatively little application software and local disk storage can be used to access all the necessary programs and data required for the organization’s business through access to cloud services.

In March 2013, industry analysts said, “More than 60% of all enterprises will have adopted some form of cloud computing in 2013, according to Gartner Research. The cloud market is slated to grow to $131 billion worldwide this year, or 18.5% over the $111 billion last year. In its 2013 State of the Cloud Report that surveyed over 1200 IT professionals, IT-reseller CDW found 39% of organizations are already using some form of cloud solution, an 11% increase over 2011.”5

IDC reported that “In coming years, the economic impact of cloud computing will be vast. Each year a greater percentage of businesses IT budgets are earmarked for cloud. An expansive study by the International Data Corporation (IDC) … reported that, in 2011, businesses spent $28 billion on public cloud IT services. Amazingly, the

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

CLOUD COMPUTING AND PRODUCTION SYSTEMS 47 · 19

spending on public cloud expected to surpass $207 billion worldwide by 2016 … .” The researchers analyzed trends in specific industries:

� Banking: increasing use of cloud computing � Healthcare: slower adoption � Manufacturing: particularly strong growth for customer relationship management (CRM) and among smaller businesses

� Insurance: increasing use � Communications/media: particularly strong user of storage-on-demand6

Gartner also predicted that, “… by 2015, 10% of overall IT security enterprise capa- bilities will be delivered in the cloud, with the focus today clearly on messaging, Web security, and remote vulnerability assessment. However, there’s also the expectation there will be more on the way, such as data-loss prevention, encryption, authentication available too as technologies aimed to support cloud computing mature.”7

As with service bureaus of yesteryear, cloud computing poses special challenges for operations security and production controls.

� The reliability of employees hired to handle confidential and critically important data is out of the hands of the client organization.

� Management policies, monitoring, software maintenance, audits—all are poten- tially handled exclusively by employees of the cloud-computing provider.

� Bring-your-own-device (BYOD) practices are facilitated by access to remote cloud services.

� Quality of service (QOS) issues and details of the service-level agreements (SLAs) complicate the contractual relations between providers and customers.

Cloud computing, like service bureaus, can provide cost-effective growth paths for smaller business and can offload information technology used for IT functions that are not viewed as mission critical, allowing IT staff to concentrate on innovative, highly productive applications that can differentiate an organization in its marketplace. They allow for graded increases in computing power without forcing organizations to follow step-functions with large investments in much bigger equipment and increased oper- ational costs. However, extending one’s IT infrastructure into centers run by separate entities with their own profit motives requires careful attention to security. At a mini- mum, organizations should implement the following recommendations for maintaining adequate controls over their production environment when it is in a remote site using cloud computing:

1. During evaluations of multiple vendors, be sure to contact clients of each firm to have personal discussions of their experience with the providers’ service-level agreements and performance, openness of communications about production controls, cooperation in site visits, and adequacy and cooperation in resolving problems.

2. Examine the adequacy of encryption for all stored proprietary data. No cleartext data should be accessible to employees of the cloud-hosting company at any time—including while decrypted on the virtual machines running on their servers.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

47 · 20 OPERATIONS SECURITY AND PRODUCTION CONTROLS

3. Be sure that virtual private networks are in place for all Internet-based data transfers.

4. Explicitly discuss update standards for all the software your organization plans to run on the cloud service. Are you responsible for such updates or is the cloud vendor?

5. Be sure that all software running in the cloud on behalf of the customer orga- nization respects the terms of the vendors’ licenses. For example, be sure that a one-user license is not being applied to a thousand concurrent virtual machines on your behalf.

6. Understand and analyze the business-continuity planning (BCP) and disaster- recovery planning (DRP) in place to ensure continued operations on your behalf should there be problems at the cloud vendor’s site(s). Are the exact terms spelled out to your satisfaction in the contracts? Are there provisions for testing the adequacy of the BCP and DRP?

7. Ensure that the contract allows for external audits which can be initiated by the client. Independent evaluation of the security, QOS and continuity of operations (CoO) is essential for the protection of the client.

8. Discuss the vendors’ security policies and practices, including real-time moni- toring for breaches (situational awareness), handling malware, and vulnerability analysis, including penetration testing.

9. Evaluate the billing processes carefully: what determines the periodic invoicing— concurrent users? Total number of sessions? Detailed algorithms measuring such elements as disk I/O, CPU cycles, swapping to and from virtual memory, or bandwidth utilization? Model the costs if possible using detailed information from your own existing systems.

47.7 CONCLUDING REMARKS. Up until the mid-1980s, the world of main- frames and minicomputers differed from that of PCs. However, from the mid-1980s and into the millennium, these worlds have merged. LANs have proliferated, the Internet has changed the way business is conducted, and bridges, routers, and gateways make it possible for information to move among computer platforms, regardless of type. Security requirements are now universal in scope. Numerous layers of software and hardware separate the user and the technician from the information to which they re- quire access. These layers themselves contribute to security because they require some technical skill to get at the information. As this is being written in 2008, computer literacy is increasing rapidly. Children are taught to use computers in grade school, and tens of millions of workers routinely use PCs or workstations daily, so the security provided by the technology is not as significant as it once was.

Security is also an economic issue. If an individual with the requisite skill is deter- mined to gain access to online files or databases, it is extremely expensive to prevent such access. Even with high expenditures, success in achieving complete security is never guaranteed. Nevertheless, if the value of the information and its confidentiality justifies additional expense, there are software products available that employ complex schemes to support security. When necessary, information security can be extended down to the field level in records of online files and databases.

Other related security measures, such as physical protection, communication se- curity, encryption of data, auditing techniques, system application controls, and other topics, are covered in other chapters of this Handbook. No one measure can stand alone

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

NOTES 47 · 21

or provide the ultimate protection for security, but with a proper balance of measures, the exposures can be contained and managed.

47.8 FURTHER READING Baumann, W. J., J.T. Fritsch, and K. J. Dooley. Network Maturity Model: An Integrated

Process Framework for the Management, Development and Operation of High Quality Computer Networks. Outskirts Press, 2007.

Benyon, R., and R. Johnston Service Agreements: A Management Guide. Van Haren Publishing, 2006.

Blanding, S. Enterprise Operations Management Handbook, 2nd ed. Auerbach, 1999. Cisco. “Cisco on Cisco Best Practices: Data Center Operations Management.” White

paper, 2008. www.cisco.com/web/about/ciscoitatwork/downloads/ciscoitatwork/ pdf/Cisco IT Operational Overview Data Center Management.pdf

Erl, T., R. Puttini, and Z. Mahmood. Cloud Computing: Concepts, Technology & Architecture. Prentice-Hall, 2013.

Franklin, C., and B. Chee. Securing the Cloud: Security Strategies for the Ubiquitous Data Center. Auerbach, 2013.

Halpert, B. Auditing Cloud Computing: A Security and Privacy Guide. Wiley, 2011. Hoesing, M. T. Virtualization Security Audit and Assessment. Auerbach, 2014. Mather, T., S. Kumaraswamy, and S. Latif. Cloud Security and Privacy: An Enterprise

Perspective on Risks and Compliance. O’Reilly Media, 2009. McCrie, R. Security Operations Management, 2nd ed. Upper Saddle River, NJ:

Prentice-Hall, 2006. Nielsen, L. The Little Book of Cloud Computing Security, 2013 Edition. New Street

Communications, 2013. Rhoton, J., J. De Clercq, and D. Graves. Cloud Computing Protected: Security Assess-

ment Handbook. Recursive, 2013. Rosado, D. G., D. Mellado, E. Fernandez-Medina, and M. Piattini, eds. Security Engi-

neering for Cloud Computing: Approaches and Tools. IGI Global, 2012 Winkler, J. R. Securing the Cloud: Cloud Computer Security Techniques and Tactics.

Syngress, 2011.

47.9 NOTES 1. United States Joint Chiefs of Staff, “Information Operations,” Joint Publication

3–13, 2006, p. II-2, www.dtic.mil/doctrine/jel/new pubs/jp3 13.pdf (URL inactive). 2. There are some forms of data that don’t reside in files, but they are transient. For

example, memory buffers, stacks, and registers contain data used during execution of programs, but they are not normally accessible to users except through special tools such as privileged-mode debug utilities or special forensic programs.

3. The site http://dmoz.org/Computers/Software/Databases/Data Warehousing/Data Integrity and Cleansing Tools listed 38 such tools at the time of writing (May 2013).

4. L. Bandoim, “Growth of Cloud Computing and ERP Continues to Accelerate,” Technorati | Technology | Cloud Computing, May 4, 2013, http://technorati.com/ technology/cloud-computing/article/growth-of-cloud-computing-and-erp

5. A. Nain, “With The Cloud Market Set To Flirt With 20% Growth In 2013, How Can You Play It?” Seeking Alpha, March 20, 2013, http://seekingalpha.com/article/

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

47 · 22 OPERATIONS SECURITY AND PRODUCTION CONTROLS

1291461-with-the-cloud-market-set-to-flirt-with-20-growth-in-2013-how-can-you- play-it

6. J. Weeks, “Vertical Markets—2013 Growth Predictions for Cloud Computing,” US Signal Blog, January 16, 2013, http://ussignalcom.com/blog/vertical-markets-2013- growth-predictions-for-cloud-computing

7. E. Messmer, “Gartner: Growth in Cloud Computing To Shape 2013 Security Trends: Gartner Predicts by 2015, 10% of Overall IT Security Enterprise Capabilities Will Be Delivered in the Cloud,” Network World, December 6, 2012, www.networkworld .com/news/2012/120612-gartner-cloud-security-264873.html

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48CHAPTER

EMAIL AND INTERNET USE POLICIES

M. E. Kabay and Nicholas Takacs

48.1 INTRODUCTION 48 · 2

48.2 DAMAGING THE REPUTATION OF THE ENTERPRISE 48 · 2 48.2.1 Violating Laws 48·3 48.2.2 III-Advised Email 48·3 48.2.3 Inappropriate Use

of Corporate Identifiers 48·4

48.2.4 Blogs, Personal Websites, and Social Networking Sites 48·5

48.2.5 Disseminating and Using Incorrect Information 48·5

48.2.6 Hoaxes 48·6

48.3 THREATS TO PEOPLE AND SYSTEMS 48 · 12 48.3.1 Threats of

Physical Harm 48·12 48.3.2 Pedophiles Online 48·13 48.3.3 Viruses and Other

Malicious Code 48·13 48.3.4 Spyware and

Adware 48·14

48.4 THREATS TO PRODUCTIVITY 48 · 15 48.4.1 Inefficient Use of

Corporate Email 48·15 48.4.2 Mail Storms 48·22 48.4.3 Buying on the Web 48·24 48.4.4 Online Gambling 48·26 48.4.5 Internet Addiction 48·28

48.4.6 Online Dating and Cybersex 48·28

48.4.7 Games and Virtual Reality 48·29

48.4.8 Changing Email Addresses 48·30

48.5 LEGAL LIABILITY 48 · 31 48.5.1 Libel 48·31 48.5.2 Stolen Software,

Music, and Videos 48·31

48.5.3 Plagiarism 48·32 48.5.4 Criminal Hacking

and Hacktivism 48·33 48.5.5 Creating a Hostile

Work Environment 48·33

48.5.6 Archiving Email 48·36

48.6 RECOMMENDATIONS 48 · 36 48.6.1 Protecting

Children 48·37 48.6.2 Threats 48·37 48.6.3 Hate Sites 48·38 48.6.4 Pornography 48·38 48.6.5 Internet Addiction 48·38 48.6.6 Online Dating 48·39 48.6.7 Online Games 48·40 48.6.8 Online Purchases 48·40 48.6.9 Online Auctions 48·41 48.6.10 Online Gambling 48·41 48.6.11 Preventing

Malware Infections 48·42

48.6.12 Guarding against Spyware 48·42

48.6.13 Junk Email 48·43

48 · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 2 EMAIL AND INTERNET USE POLICIES

48.6.14 Mail Storms 48·43 48.6.15 Detecting Hoaxes 48·44 48.6.16 Get-Rich-Quick

Schemes 48·44 48.6.17 Hacking 48·45

48.7 CONCLUDING REMARKS 48 · 45

48.8 FURTHER READING 48 · 45

48.9 NOTES 48 · 46

48.1 INTRODUCTION.1 The Internet offers every enterprise exciting opportu- nities to find timely information and to reach potential clients. This very power brings with it risks of damaging corporate and professional reputations. Nontechnical prob- lems in cyberspace include bad information, fraud, loss of productivity, and violations of civil and criminal law as well as violations of the conventions of proper behavior established by custom in cyberspace.

In addition, widespread abuse of Internet access while at work is forcing recog- nition that clear policies are essential to guide employees in appropriate use of these corporate resources. The consensus in our profession—despite the dreadful lack of hard statistics—is that something like two-thirds of all the damage caused to our information systems is from insiders who are poorly trained, careless, or malicious. (For a detailed discussion of security statistics, see Chapter 10 in this Handbook.) For example, a study published in late 2005 reported that:

Sixty-nine percent of 110 senior executives at Fortune 1,000 companies say they are “very concerned” about insider network attacks or data theft, according to a study by Caymas Systems, a network security technology firm based in San Jose, Calif. And 25 percent say they are so concerned they can’t sleep at night, Sanjay Uppal, a vice president at Caymas Systems, told eSecurityPlanet.2

A McAfee-sponsored survey in Europe showed that (in the words of the Department of Homeland Security Daily Open Source Infrastructure Report3):

Workers across Europe are continuing to place their own companies at risk from information security attacks. This “threat from within” is undermining the investments organizations make to defend against security threats, according to a study by security firm McAfee. The survey, conducted by ICM Research, produced evidence of both ignorance and negligence over the use of company IT resources. One in five workers let family and friends use company laptops and PCs to access the Internet. More than half connect their own devices or gadgets to their work PC and a quarter of these do so every day. Around 60 percent admit to storing personal content on their work PC. One in ten confessed to downloading content at work they shouldn’t. Most errant workers put their firms at risk through either complacency or ignorance, but a small minority are believed to be actively seeking to damage the company from within. Five percent of those questioned say they have accessed areas of their IT system they shouldn’t have while a very small number admitted to stealing information from company servers.4

Another topic of growing significance is saturation by floods of email sent by well- intentioned employees who do not know how to use email effectively.

Finally, some of the information in this chapter may help security administrators involve their users in a more active role by giving them take-home messages that can help them protect their own families and friends. Getting employees to care about security for their families is a good step to involving them in corporate security.

For more information on effective security awareness and corporate culture change, see Chapters 49 and 50 in this Handbook.

48.2 DAMAGING THE REPUTATION OF THE ENTERPRISE. When some- one posts information to the ’Net, the message header normally indicates who the

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

DAMAGING THE REPUTATION OF THE ENTERPRISE 48 · 3

sender is. In particular, all employees using a corporate email account identify their employer in every posting. It follows that when an employee—for example, [email protected]—misbehaves on the ’Net, it is likely that everyone seeing the misbe- havior will associate it with the employer, regardless of futile attempts to dissociate the employee from the employer by statements such as “The opinions above are not necessarily those of my employer.”

Employees can embarrass their employers by using their corporate email identifiers in these ways:

� Flaming. Launching rude verbal attacks on others. � Spamming. Sending junk email (spam), unsolicited advertising, and sales promo- tions, to multiple, often unrelated, Usenet groups and mailing lists and to people’s email addresses without their permission.

� Mail-bombing. Sending many email messages to a single email address to annoy its user, or in extreme cases, to cause a denial of service.

In addition, employees can violate laws, send out embarrassing content via email, implicate their employers in personal affairs, and spread falsehoods with actionable consequences.

48.2.1 Violating Laws. Employees may engage in illegal activities that can seriously compromise their employer; examples include:

� Industrial espionage � Stock manipulation � Criminal hacking, unauthorized penetration of other systems � Sabotage, denial of service attacks � Vandalism, defacement of Websites � Creating, transmitting, or storing child pornography � Sending threats (e.g., of harm to the President of the United States) � Credit card fraud, using stolen or fraudulently generated credit card numbers for purchases made using corporate resources

Corporate Internet usage policies should explicitly forbid any of these actions.

48.2.2 III-Advised Email. There have been too many cases of foolish use of email in recent years. Employees have created a hostile working environment by sending internal email with lewd or hateful jokes and images; staff members have insulted their bosses or their employees in email that later became public; people have made libelous accusations about other workers or about competing companies. All of these uses are wholly inappropriate for a medium that takes control of distribution away from the originators and produces records that can be backed up and archived for indefinite periods of possible retrieval.

Common sense dictates that anything sent via email should not be illegal or even embarrassing if it were published in a newspaper.

Users should also be aware that it is a poor idea to insult people using email. Sending flames that belittle, ridicule, and demean other people is likely to generate more of the

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 4 EMAIL AND INTERNET USE POLICIES

same in response, and flaming is an ugly practice that distorts standards for public and private discourse. If a user or employee chooses to respond to a rude or demeaning email, he or she should refrain from replying with the same rude or demeaning tone. In one case reported in a security management class to author Kabay in 2013, an employee noted that a young intern responded to an email memorandum by hitting REPLY ALL and sending a contemptuous, arrogant, demeaning, and ungrammatical criticism of the message. That message had been sent to all employees by the CEO. The intern was fired that day.

Employees should work to maintain the moral high ground by refraining from obscenity, profanity, and vulgarity in written as well as in oral discourse. Not only is this a good habit in general, but it also avoids the possibility of enraging total strangers who may be physically or electronically dangerous.

These best practices also apply to the home and family life. Criminal hackers have been known to damage credit ratings, participate in identity theft to rack up large bills in the victims’ names, and even tamper with phone company accounts. In one notorious prank, hackers forwarded all incoming phone calls for the famous security expert Donn Parker, who is quite bald, to a hair restoration business.

Anonymizers are services that strip identifying information from email and then forward the text to the indicated targets. However, even anonymizers respond to sub- poenas demanding the identity of people involved in libel or threats. The Website called annoy.com consistently posts messages that will annoy a substantial number of people as an exercise of United States First Amendment rights; however, even that service once had a particularly clear message on its refusal to tolerate abuse:

WARNING

It has come to our attention that certain people have been using annoy.com to deliver what some might consider to be threats of physical violence or harm to others.

Do not mistake our commitment to freedom of speech for a license to abuse our service in this manner.

We plan to cooperate fully with law enforcement agencies in whatever efforts they make to find you and punish you—even if it’s some renegade authoritarian dictatorship … Free speech and annoy.com are not about harassment and definitely not about harm or violence. If you think for a second we will allow cowardly idiots to spoil our free speech party you are making a mistake. A huge mistake.

For both USENET, a global Internet discussion system, and for discussion groups on the Web, a message may be forever. There are archives of USENET messages stretching back for decades, and the Wayback Machine (named for a time machine run by Mr. Peabody [a scholarly dog] in Hanna-Barbara’s Rocky [a flying squirrel] and Bullwinkle [an engaging moose] TV cartoon show of the 1960s) for the Web has records back to 1996. Sending abusive or degrading messages online may not permanently damage the sender’s reputation, but it is not likely to improve anyone’s prospects for getting or keeping a good job, especially if the sender’s email address includes a corporate affiliation.

48.2.3 Inappropriate Use of Corporate Identifiers. Considerable con- troversy exists as to whether corporate policy should forbid corporate IDs for any personal use on the Internet. There is little reason for posting messages to news- groups in the .alt hierarchy, and especially not to groups catering to or sympathetic to criminal activity. If employees of an organization want to participate in vigorous

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

DAMAGING THE REPUTATION OF THE ENTERPRISE 48 · 5

political discussion, conversations about sexual activity, and any other topic unrelated to their work, they are free to do so using their own Internet identities. Employers pay for corporate email identities; people who want to post opinions—especially political opinions—about, say, basket-weaving techniques should pay for their own access and leave their employer out of the postings.

The risks of damaging an organization’s reputation by violating netiquette are high. Some abusers have themselves been abused by angry and unscrupulous Internauts. In one notorious early case, back in 1994, a naı̈ve executive spammed the ’Net—he posted messages in a couple of dozen newsgroups. In retaliation, his company’s 800-number was posted to phone-sex discussion groups in the .alt hierarchy, resulting in thousands of irate and expensive phone calls by seekers of aural sex. Regular customers were unable to get through, and some staff resigned because of the offensive calls. The executive nearly lost his job.

An additional risk is that employees will inadvertently post company-confidential information to what they erroneously perceive as closed, private groups. Competitors or troublemakers can then exploit the information for competitive advantage or publicize it to harm the enterprise. Even if a discussion group or mailing really is closed, nothing prevents a participant from using or disseminating confidential information without permission. By the time the breach of security is discovered, it can be too late for remediation. Such breaches are an invitation for spear-phishing attacks, as discussed in Chapter 20 in this Handbook.

48.2.4 Blogs, Personal Websites, and Social Networking Sites. Should employers be concerned about the creation of blogs, personal Websites, and social-networking pages by employees? There have been cases in which employees made unwise or frankly derogatory comments about their current employers, with pre- dictable consequences. It is much better to prevent such conflicts by establishing clear policies for employees that explicitly ban mention of the employer’s name in personal publications and media such as blogs and Websites. A variation can require corporate approval by the public relations or communications departments before material is published. Such policies are commonplace for control over what employees publish in interviews, newsletters, and other publications.

Some employees likely have personal pages in social-networking sites such as Facebook, Twitter, and Tumblr. The same issues arise when employees make reference to their employer by name as part of their profile: How would an employer feel about seeing an indecently dressed pictured on their Facebook page with the individual’s profile displaying their corporate name? Employment agreements can, and should, stipulate limitations on the use of corporate identity. There is nothing wrong with stipulating that social-networking pages not include the name of an employer.

Further complicating the matter is the growth of professional social networking sites such as LinkedIn. These sites encourage posting a digital resume, which includes basic information about an individual’s employment history. Much like personal networking sites, companies must set clear expectations on use and periodically monitor compliance through searches and visual inspection. In contrast with Facebook, though, LinkedIn tends not to have many users who post unprofessional information and comments on their own pages.

48.2.5 Disseminating and Using Incorrect Information. The Internet and in particular the World Wide Web are in some ways as great a change in infor- mation distribution as the invention of writing 6,000 years ago and the invention of

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 6 EMAIL AND INTERNET USE POLICIES

movable type 600 years ago. In all these cases, the inventions involved disinterme- diation: the elimination of intermediaries in the transmission of knowledge. Writing eliminated the oral historians; one could read information from far away and long ago without having to speak to a person who had personally memorized that knowl- edge. Print allowed a far greater distribution of knowledge than handwritten books and scrolls, eliminating an entire class of scribes who controlled access to the precious and rare records. The ’Net and the Web have continued this trend, with a radical increase in the number of people capable of being publishers. Where publishing once required printing presses, capital, and extensive administrative infrastructure, or at least rel- atively expensive mimeographs (1950s), photocopiers (1960s), and printers (1970s), today an individual can publish material relatively inexpensively, if not free. Many Internet Service Providers (ISPs) offer free Web-hosting services and places for people to join electronic communities of every imaginable type. Even if the individual does not have access to the Internet at home, and follows work policies on use, free access can be obtained from local libraries or the increasing number of free Internet hot spots.

Web pages can lead to visibility unheard of even a decade ago. For example, one young exhibitionist named Jennifer Kaye Ringley put up a Website to display images of her home taken through Web-enabled cameras (Webcams); this “jennycam.org” site received up to half a million hits per day while it was in operation. Another young woman decided to put up a Website devoted to one of her favorite literary characters, Nero Wolfe, in the mid-1990s. Within a few years, her site was so well respected that she was hired by a Hollywood filmmaker as a technical consultant on a series of Nero Wolfe movies. The fees she was paid, despite offering to help for free, helped her get through her Ph.D. studies in social psychology. It would have been virtually impossible for her to achieve this recognition by trying to publish her own hard-copy fan magazine; the paper might have reached a few hundred people, but the Website reached many thousands.

Unfortunately, all of this disintermediation has negative implications as well as positive ones. Freedom from publishers has liberated the independent thinker from corporate influence, editorial limitations, and standards for house style. However, this freedom also liberated many people from responsible reporting, adequate research, and even the rudimentary principles of spelling and grammar. The dictum “Don’t believe everything you read” is even more important when reading Web-based information. In- dividuals may publish incorrect versions of technical information (e.g., health sites that claim that massaging parts of the earlobe can cure many known diseases), unsubstanti- ated theories about historical and natural events (e.g., the Tungska Impact of 1908 was caused by an antimatter meteorite), and off-the-wall revisionist history (e.g., slavery in the United States was good for black people, and Hitler never persecuted Jews). Wikipedia, although it has become the first line of information for some users, suffers

from the possibility of temporary or even long-term modifications of content as pranks or for other purposes. For example, supporters of the failed right-wing candidate Sarah Palin are thought to have tried to alter the Wikipedia entry on Paul Revere to force it to conform to her incorrect statements about his famous ride.5 Because there is no guarantee that the content of a reference to Wikipedia is legitimate or will be legitimate or even the same the next time the reference is followed, academic institutions tend to reject references to Wikipedia in term papers.

48.2.6 Hoaxes. Pranksters have been using email to fool gullible people for years using a particular sort of incorrect information: deliberate hoaxes. A hoax is a mischievous trick based on a made-up story. There are two major kinds of hoaxes circulating on the Internet: urban myths and false information about viruses. The

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

DAMAGING THE REPUTATION OF THE ENTERPRISE 48 · 7

archives in the urban myths Websites are full of hilarious hoaxes, some of which have been circulating for years. Why don’t they die out?

The problem is the nature of the Internet. Information is not distributed solely from a centrally controlled site; on the contrary, anyone can broadcast, or rebroadcast, any kind of data at any time. There is neither reliable creation dates nor obligatory expiry dates on files, so those receiving a five-year-old document may have no obvious way of recognizing its age, and they almost certainly have no simple way of identifying obsolete or incorrect information. All they see is that the document has been sent to them recently, often by someone they know personally.

48.2.6.1 Urban Myths. Here are some notorious examples of the bizarre and sometimes disturbing urban myths that are thoroughly debunked on the Snopes.com Website:

� Expensive cookies. Someone claims that a Neiman-Marcus employee charged $250 to a credit card for the recipe to some good chocolate chip cookies. This story has been traced to a false claim dating back to 1948 in which a store was accused of charging $25 for the recipe to a fudge cake.

� Do not flash your car lights. In a gang-initiation ritual, hoodlums drive down a highway with their car lights off. Innocent drivers, flashing their lights as a reminder, would become the new target victims, usually resulting in their deaths by the gang.

� Watch out for poisoned needles. Insane, vengeful druggies leave needles tipped with HIV+ blood in movie theater seats, gas pump handles, and telephone change- return slots.

� Lose your kidneys. The victim visits a foreign city, goes drinking with strangers, and wakes up in the morning in a bathtub of ice with two neat incisions through which both kidneys have been removed. No one ever seems to explain why criminals who remove kidneys would bother packing the victim in ice.

� Poor little guy wants postcards. Craig Shergold is just one of the many real or imaginary children about whom well-meaning people circulate chain letters asking for postcards, business cards, prayers, and even money. Shergold was born in 1980; when he was nine, he was diagnosed with brain cancer, and friends started a project to cheer him up—they circulated messages asking people to send him postcards so he could be listed in the Guinness Book of World Records. By 1991, he had received 30 million cards and an American philanthropist arranged for brain surgery, which worked: Shergold went into remission. The postcard deluge did not. By 1997, the local post office had received over 250 million postcards for him, and he was long since sick of the whole project.

� Wish you would stop Making a Wish. Around the mid-1990s, some prankster inserted false information about the Make-a-Wish Foundation into the outdated chain letters concerning Shergold. The unfortunate organization was promptly inundated with email and postal mail, none of which was in any way useful or relevant to its work. They had to post disclaimers on the Website to try to dissociate themselves from the outdated information.

48.2.6.2 Virus Myths. One category of hoaxes has become a perennial nui- sance on the ’Net: virus myths. There is something wonderful about the willingness

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 8 EMAIL AND INTERNET USE POLICIES

of gullible, well-meaning people to pass on ridiculous news about nonexistent viruses with impossible effects. One of the most famous is the Good Times “virus,” which appeared around 1994. The myth and numerous variants have been circulating unin- terruptedly for years. Every few years, there is a new outburst as some newcomers to the Internet encounter an old copy of the warnings and send it to everyone they know.

The original very short warning was as follows, including the incorrect punctuation:

Here is some important information. Beware of a file called Goodtimes.

Happy Chanukah everyone, and be careful out there. There is a virus on America Online being sent by E-Mail. If you get anything called “Good Times”, DON’T read it or download it. It is a virus that will erase your hard drive. Forward this to all your friends. It may help them a lot.

The Good Times virus claimed that downloading a document or reading a document could cause harm; at that time, such a claim was impossible. Ironically, within a couple of years, it did in fact become possible to cause harm via documents because of the macro-language capabilities of Microsoft Word and other programs enabled for scripting. Over the rest of the 1990s, foolish people modified the name of the imaginary virus and added more details, sometimes claiming impossible effects such as destruction of computer hardware.

By 1997, the warnings were so ridiculous that an anonymous author distributed the following Monty Pythonesque satire:

It turns out that this so-called hoax virus is very dangerous after all. Goodtimes will re-write your hard drive. Not only that, it will scramble any disks that are even close to your computer. It will recalibrate your refrigerator’s coolness setting so all your ice cream goes melty. It will demagnetize the strips on all your credit cards, screw up the tracking on your television and use subspace field harmonics to scratch any CDs you try to play.

It will give your ex-girlfriend your new phone number. It will mix Kool-aid into your fish tank. It will drink all your beer and leave dirty socks on the coffee table when company comes over. It will put a dead kitten in the back pocket of your good suit pants and hide your car keys when you are late for work.

Goodtimes will make you fall in love with a penguin. It will give you nightmares about circus midgets. It will pour sugar in your gas tank and shave off both your eyebrows while dating your girlfriend behind your back and billing the dinner and hotel room to your Discover card.

It will seduce your grandmother. It does not matter if she is dead, such is the power of Goodtimes, it reaches out beyond the grave to sully those things we hold most dear.

It moves your car randomly around parking lots so you can’t find it. It will kick your dog. It will leave libidinous messages on your boss’s voice mail in your voice! It is insidious and subtle. It is dangerous and terrifying to behold. It is also a rather interesting shade of mauve.

Goodtimes will give you Dutch Elm disease. It will leave the toilet seat up. It will make a batch of Methamphetamine in your bathtub and then leave bacon cooking on the stove while it goes out to chase gradeschoolers with your new snowblower.

Unaware people circulate virus hoaxes because they receive the hoax from someone they know. Unfortunately, a personal friendship with a sender is no guarantee of the accuracy of their message. Some awfully nice people are gullible, well-meaning dupes of social engineers. Transmitting technical information about viruses (or any apprehended danger) without verifying that information’s legitimacy and accuracy is a disservice to everyone. It makes it harder for experts to reach the public with warnings of real dangers, and it clutters up recipients’ email in-baskets with alarming

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

DAMAGING THE REPUTATION OF THE ENTERPRISE 48 · 9

information of limited or no use whatever. Teach employees, family, and friends to consult snopes.com or an equivalent before forwarding alarming messages—and don’t forward any messages about malware: Make sure everyone you know uses up-to-date antimalware software.

48.2.6.3 Junk Email. Unsolicited commercial email (UCE) is derisively known as junk email and also as spam. Junk email is spawned by foolish (in the early days) or criminal (today) people who send out thousands or millions of identical messages to unwilling recipients. Junk email clogs victims’ in-baskets and wastes their time as they open these unwanted messages and take a few seconds to realize that they are junk. Junk email containing pornographic images or advertising pornography may be highly offensive to the recipients. Junk may even push people’s email systems over their server limits if they are not picking up their messages regularly; in such cases, wanted email may bounce because the mailbox is full. Today, junk email is the primary vector for social engineering attacks such as phishing designed to trick recipients into compromising their privacy or their identification and authentication codes. (See Chapter 20 in this Handbook for more details of spam, phishing, and other tricks.)

Most junk email uses forged headers; that is, the senders deliberately put misleading information in the FROM and REPLY fields to avoid receiving angry responses from the victims of their criminal behavior. Forging email headers is illegal in the states of Massachusetts, Virginia, and Washington. In these states, if the perpetrators are identified, it can lead to court cases and financial penalties for each message involved in the fraud.

In one famous, groundbreaking case, college student Craig Nowak sent out a few thousand junk email messages and followed the instructions in his spam kit by putting a made-up REPLY address using “@flowers.com” without checking to see if there really was such a domain. Indeed there was, and the owner of this reputable floral delivery service, Tracy LaQuey Parker, was none too pleased when her system was flooded with over 5,000 bounce messages and angry letters from customers saying that they would never do business with her again. She sued the student for damages and was awarded over $18,000 by a judge who said he wished he could have been even more punitive.6

In general, spam has become a mechanism for tricking unaware vendors into paying for illusory marketing services. It is sad to see email advertising for Chinese industrial piping being sent to North American university professors; the victims are the hard- working Chinese industrialists who have been cheated by assurances from criminals promising to send their advertising to willing and well-qualified recipients.

Much of the remaining junk is sent out in the hope that a tiny proportion of the recipients of the misspelled, absurd claims will be gulled into sending money—or their email addresses—to drop boxes. For more information about such social engineering attacks, see Chapters 19 and 20 in this Handbook.

If you are involved in an email discussion group, especially an unmoderated group, about a specific topic, do not post email to members of the list on a subject that is outside the topic area. A typical class of inappropriate posting is an appeal for support of a worthy cause that has no, or only a tenuous, relation to the subject area. For example, someone might appeal for support to save whales in a discussion group about gardening: bad idea. The reasoning is “They like plants; probably environmentally sensitive; likely to be interested in conservation; therefore they will be glad to hear about whales.” The problem is that such reasoning could be extended to practically any topic, disrupting the focus of the group. Such messages often cause angry retorts, which are typically sent by naı̈ve members to the entire list instead of only to the sender

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 10 EMAIL AND INTERNET USE POLICIES

of the inappropriate mail. Then the angry retorts cause further angry responses about burdening the list with useless messages and soon the gardening group is mired in dissension and wasted effort, generating bad feeling and distrust.

As suggested in the preceding paragraph, if you see inappropriate messages on an email list you care about, do not reply to the entire list; reply nicely and only to the sender, with possibly a copy to the moderator, if there is one. The reply should be temperate and polite.

48.2.6.4 Chain Letters and Ponzi Schemes. A particularly annoying form of junk email is the chain letter. Some chain letters include ridiculous stories about terrible diseases and accidents that have befallen people who refused to forward the message (ridiculous on the face of it, but apparently appealing to the irrational enough to keep the nonsense circulating). Others focus on getting victims to send money to someone at the top of a list of names, while adding their names to the bottom of the list, before sending it on to a specified number of recipients. Depending on the length of the list and the amount to be sent to the person on top, the theoretical return could be in the hundreds of thousands of dollars. In practice, only the originators of the scheme profit. After a while, all possible participants have been solicited with disappointing results, and the chains are broken in many places.

Another type of pyramid is known as a Ponzi scheme, which is an investment swindle in which high profits are promised and early investors are paid off with funds raised from later ones. The scam is named after Charles Ponzi (1882–1949), a speculator who organized such a scheme in 1919 and 1920. The Ponzi scheme tricked thousands of people in Boston when Ponzi guaranteed a 50 percent profit on contributions in 45 days and a doubling of value in 90 days. The con man claimed he was redeeming 1-cent Spanish postal certificates for 6-cent U.S. stamps—a claim ridiculed by financial analysts at the time. Nonetheless, Ponzi took in around $15 million in 1920 dollars and stole around $8 million, paying out the rest to the early participants in order to develop credibility. Six banks collapsed because they invested their depositors’ funds in the scheme. Ponzi eventually served over three years in jail but escaped in 1925.7

The modern-day email Ponzi scheme typically includes passionate assurances from vaguely identified people about how skeptical they were about the scheme, but how they succumbed to curiosity, participated in the scheme, and earned vast amounts of money (e.g., $50,000) within a couple of weeks. The letters often include assurances that everything is legal and point to nonexistent postal information phone lines or claim “As Seen on TV” at various points in the letter.

These letters instruct the victim to send a small amount of money (typically $1 or $2) to a short list of about four people to receive their “reports.” The victim is then instructed to add his or her name and address to the list, while removing the first one, before sending a copy of the new letter to as many people as possible. Some letters go through computations involving such assumptions as “Imagine you send out a hundred, a thousand, or ten thousand messages and get a mere 1%, 2%, or 10% response,” and then promise enormous returns. In fact, the “reports” are nothing but one-page, meaningless blurbs about chain letters. The scammers are trying to get around regulations such as the U.S. Post Office’s bar against fraudulent uses of the mail.

Here is the exact text of a letter sent on December 1, 2000, by V. J. Bellinger of the Operations Support Group of the United States Postal Inspection Service in Newark, New Jersey. It has some interesting information that should be helpful to

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

DAMAGING THE REPUTATION OF THE ENTERPRISE 48 · 11

readers attempting to convince employees (or family and friends) that such chain email involving postal addresses is illegal.

A chain letter or a multi-level marketing program is actionable under the Postal Lottery, False Representation, and/or Mail Fraud Statutes if it contains three elements: prize, consideration and chance. Prize is usually in the form of money, commissions, or something else of value that the solicitation claims you will receive. Consideration is the required payment to the sponsor in order to obtain the prize. Chance is determined by the activities of participants over whom the mailer has no control. These types of schemes constitute lotteries are barred from the mails because they violate the following statutes: Title 18, United States Code, Sections 1302 and 1341 and Title 39, United States Code, Section 3005.

In attempts to appear legal, many chain letter or multi-level marketing mailings offer, for a fee, a product, or “report.” However, since the success of the program is dependent on the number of people willing to participate, all three elements that constitute a violation continue to be present.

The promoter of this scheme has been advised of the potential violations involved and has been requested to discontinue this type of mailing activity. …

A superficially similar phenomenon is known as multilevel marketing. In this non- fraudulent, legitimate system of selling products and services, people are encouraged to recruit distributors from among their friends and acquaintances, but the emphasis is on the value of the products. No one claims that anyone is going to become wealthy without work, and there is no demand for investments. The products have an established market, and the company makes money through sales, not through recruitment.

Here are some practical guidelines for employees and individuals:

� Do not participate in any scheme that relies on forwarding large numbers of letters or email messages to everyone you know or to strangers.

� Differentiate between pyramid frauds and legitimate multilevel marketing sys- tems: The former emphasize enrolling participants, whereas the latter emphasize the value of products and services.

� Do not participate in alleged multilevel marketing systems if they require sub- stantial investments.

� If you are interested in a multilevel marketing operation: � Check out the owners and officers. � Talk to people who have bought the products to see if they are happy with their purchases.

� Contact your local Better Business Bureau to see if there have been any com- plaints.

� Do not send money to suspected pyramid frauds. � Work with your colleagues to demonstrate how a pyramid fraud takes money from a growing number of later victims and shifts it to people who participate earlier in the fraud. Reinforce the fact that fraud is illegal, even though the prospect of early participation might seem to yield results.

48.2.6.5 Get-Rich-Quick Schemes. Other get-rich-quick schemes on the ’Net play on the victims’ wishful thinking, their lack of skepticism, and usually on a lack of common sense. There have been claims that you can earn a quarter of a million dollars a year by grooming poodles in your home. Or that you can become a millionaire

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 12 EMAIL AND INTERNET USE POLICIES

by working four hours a week, sending out promotional literature for products you do not even have to sell. Often, dangerous people promulgate some such schemes; for example, some extremist militia groups have been charging people hundreds of dollars to learn how to defraud the government by claiming liens on government property and then pledging the nonsensical liens as collateral for loans. Other criminals circulate programs for generating fraudulent credit card numbers and using them to steal goods. In other cases, criminals charge money to teach victims how to falsify their bad credit records so they can obtain yet more fraudulent credit, all the while claiming that their criminal methods are 100 percent legal.

From a corporate standpoint, such chain letters and schemes waste bandwidth and pose a potential for serious embarrassment when enterprise resources are used to spread the nonsensical material. However, corporate security can win favor with users by helping them avoid the pitfalls of such fraud, even when using their own computer systems. The benefits are particularly strong when helping employees to teach their own children how to avoid this kind of trouble.

To illustrate the trouble kids can get into using these techniques, consider the case of Drew Henry Madden. In 1996, this 16-year-old Australian boy from Brisbane, just after leaving school, started defrauding businesses using stolen and forged credit card numbers. He stole $18,000 of goods and, in February 1997, pled guilty to 104 counts of fraud and was sentenced to a year in jail. However, investigators uncovered additional fraud, and it turned out that he had stolen an additional $100,000 in goods and services. In October 1997, he pled guilty to another 294 counts of fraud and was given an additional suspended sentence. His defense attorney blamed poor security for the losses: “Madden started with very minor credit card fraud, but it escalated alarmingly, because the safeguards were so inadequate.” Despite the youngster’s unusual revenue stream, his mother appeared to have accepted his globetrotting ways and massive purchases of lottery tickets without comment. At one point, she told reporters, “If we were a wealthy family he’d be at a private school, where his talents could be directed properly.”

A relatively new kind of fraud on the Internet is the diploma mill. These organiza- tions pretend to be educational institutions; actually, they are one or more fraudulent individuals who sell bogus diplomas purporting to represent recognized degrees but that fool no one but the purchaser. While diploma mills are not accredited, the lack of accreditation does not automatically implicate a school as a fraudulent entity.

48.3 THREATS TO PEOPLE AND SYSTEMS. One particular class of email deserves a special mention: threats. Threatening emails may target people, systems, organizations, or the processes that these entities rely on. As with the other types of illegal activity on the Internet, proper education, awareness, and response can limit the number of future victims.

48.3.1 Threats of Physical Harm. Anyone who receives threats through email has a right, and possibly a duty, to inform local law enforcements officials. In today’s climate of fear and violence, any threat warrants attention. In addition to the distress such messages can generate, they may be warning signs of serious trouble. In particular, threats about violence at work, at school, or against any definable group may be the early warning that allows authorities to step in to defuse a potentially explosive situation.

Sending threatening email is not an acceptable joke or a minor prank, especially if the threat involves violence. Some people, believing that they can mask their real identity,

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

THREATS TO PEOPLE AND SYSTEMS 48 · 13

have foolishly sent death threats to the White House; because the Secret Service is obligated by law to investigate all threats to the president and the first family, agents show up within a few hours to interrogate the miscreants. For example, youngsters in the tenth grade at Profile High School in Bethlehem, New Hampshire, sent death threats to the White House Website from their school computers. The messages were traced within minutes by the Secret Service, the children were suspended from school, and they lost their Internet privileges for the next two years.

48.3.2 Pedophiles Online. This section applies primarily to training users for protection of their children. Pedophilia is defined as sexual arousal in response to contact with or images of

prepubescent children. Some pedophiles misrepresent themselves as youngsters in chat rooms or via email and trick children into forming friendships with what they believe are peers. In one notorious case, Paul Brown Jr., a 47-year-old man, misrepresented himself as a 15-year-old boy in email to a 12-year-old girl in New Jersey. The victim’s mother stumbled onto the long-range relationship when she found sitting on her own doorstep a package from her daughter to a man she did not know; the child had put the wrong postage on it and the post office had sent it back. Opening the package, she found a videotape that showed her daughter cavorting naked in front of the family video camera. The distraught mother searched her daughter’s room and discovered a pair of size 44 men’s underpants in one of the child’s bureau drawers.

Brown was arrested in February 1997. Police found correspondence with at least 10 other teenage girls across the country, through which Brown convinced his young victims, some as young as 12, to perform various sexual acts in front of cameras and to send him the pictures and videotapes. He pleaded guilty in June to enticing a minor into making pornography. In August 1997, at his sentencing hearing, one of his many victims told the court that she had suffered ridicule and humiliation as a result of her entrapment and had left her school to escape the trauma. She accused Brown of emotional rape. Displaying an astonishing interpretation of his own behavior, Brown said at his sentencing hearing, “It was just bad judgment on my part.” Using good judgment, the court sentenced him to five years of incarceration.

In March 2000, Patrick Naughton, a former executive of the INFOSEEK online company, pled guilty to having crossed state lines to commit statutory rape of a child. In August, FBI officials said that Naughton had been providing help in law enforcement investigations of pedophilia on the ’Net. In return for his cooperation, prosecutors asked the court for five years of probation (instead of a possible 15 years in prison), counseling, a $20,000 fine (instead of the maximum $250,000), and an agreement not to have unapproved contact with children and to stay out of sex chat rooms online.

The problem of Internet-enabled pedophile stalking has reached international di- mensions. In January 1999, police forces around the world cooperated to track and close down a worldwide ring of pedophiles trafficking in child pornography through the ’Net. Child safety experts have warned the U.S. congressional committee on child online protection that with the average age of online users declining (children between the ages of two and seven are among the fastest-growing user cohorts on the Internet), children increasingly are put at risk by their careless or ignorant online activities.

48.3.3 Viruses and Other Malicious Code. As of 2008, the WildList (www.wildlist.org) reports over 2,000 distinct forms of malicious program code commonly circulating in cyberspace. There are many more types recorded by an- tivirus researchers, but they have not been seen infecting significant numbers of user

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 14 EMAIL AND INTERNET USE POLICIES

computers. Most of these harmful programs are limited to antivirus laboratories and to the computers of virus hobbyists—people who derive pleasure from playing with danger. For more information about viruses and other malware, see Chapters 16, 17, 18, and 41 in this Handbook.

Employers should have policies clearly forbidding the creation, exchange, and stor- age of malicious software on corporate systems.

48.3.4 Spyware and Adware. In December 1999, computer scientist, cyber- crime investigator, and writer Richard Smith became curious about a program called zBubbles that he had installed on his system to improve online shopping. Created by Alexa, a subsidiary of e-tailer Amazon.com, the program provided competitive infor- mation about alternative and possibly cheaper sources for particular products. However, Smith discovered that there was more going on than met the eye.

Smith monitored his own Internet traffic while he was using zBubbles by using a packet sniffer, a tool that displays details of every piece of information being transmitted through a network connection. He found that zBubbles was sending a steady stream of information about him and his surfing habits to Alexa, including his home address, the titles of DVDs he had browsed on Buy.com, and the details of an airline ticket he had verified online. In addition, the program even continued to send information regularly to Alexa’s servers even when Smith was not using his browser. It was learned that zBubbles was not the only program sending information back to its makers.

Many programs are available that, once installed, report on the Websites you visit, which banner advertisements you click, what products you search for, and any other information the programs have been designed to acquire. Even widely used download- ing software, such as NetZip, has been shown to report to its providers on the names of every file downloaded by each user.

Sometimes these programs are informally known as E.T. applications, in a reference to Steven Spielberg’s movie of that name, in which an extraterrestrial strives to “phone home”—exactly what the spyware programs are doing.

The term spyware is applied to any technology that transmits information without the knowledge of its user. Several programs distributed without charge through the Internet secretly collect information about the user, monitor user behavior, and then send those data to advertisers. The more general class of monitoring software that collects information for use by advertisers is known as advertising-supported software or adware. These programs allow freeware to make money for its creators by generating revenue based on how many users transmit information to the advertisers about their habits.

Although defenders of the advertising-supported programs claim that they are harm- less, privacy advocates argue that the issue is control: Do users know what these pro- grams are doing, or are they collecting and transmitting information covertly? Some adware comes with complicated contracts containing complex legal language to bury the fact that they will monitor and report user behavior. Worse yet, many such con- tracts explicitly authorize the software supplier to alter the privacy conditions without notification and, preposterously, instruct the user to check the contracts on the Web fre- quently. No one has the time to monitor countless suppliers to see if privacy conditions have been altered, especially if there is no attempt to highlight changes.

Another issue is that some spyware modules have used stealth technology charac- teristic of viruses, Trojan horses, and other malicious software. For example, some adware (e.g., TSADBOT) installs itself as a system process and is not listed in the Windows task list. Therefore, it cannot easily by aborted by a user. TSADBOT also

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

THREATS TO PRODUCTIVITY 48 · 15

resists removal; even if the carrier product is uninstalled, TSADBOT persists. If a user’s firewall blocks outbound transmission by the TSADBOT process, the spyware initiates attempts to reach its target at a rate of 10 per second, potentially leading to central processing unit (CPU) and network resource overload.

Spyware, like any software, can contain errors that cause system problems. In particular, components of the Aureate/Radiate spyware have been shown to cause system instability and crashes.

One of the most egregious cases of spyware erupted in 1999, when it was discovered that CometCursor, a supplier of cute cartoon-character cursors aimed at children, was sending information back to its servers about what the children were browsing on the ’Net. According to some attorneys, this kind of covert data gathering about children may be a violation of the U.S. Federal Child Online Privacy Protection Act.

Several free software programs have been written to help users identify and remove spyware. In addition, personal firewalls can usually identify and block unauthorized outbound communications; the free version of ZoneAlarm, for example, does so effec- tively. Today’s antimalware programs (e.g., Bitdefender) include antispyware functions. There are also many specialized programs (e.g., Lavasoft’s Ad-Aware) available that run in the background to monitor and thwart attempts to install spyware and adware.

48.4 THREATS TO PRODUCTIVITY. Some activities and phenomena are nui- sances to employers principally because of their noxious effects on productivity and their abuse of corporate resources. Junk email and mailstorms, for example, are a problem because they saturate resources, not because they cause specific harm to the organization or to its employees. However, chain letters, get-rich-quick schemes, on- line auctions, online gambling, excessive online shopping, and Internet addiction can be directly harmful to employees and others.

48.4.1 Inefficient Use of Corporate Email. The next sections focus on problems caused by mistakes in the use of email—mistakes that can cause annoy- ance, inefficiency, and potential disruption of critical business processes.

48.4.1.1 Forwarding Email to Personal Accounts. Employees may be tempted to forward their corporate email traffic to their personal email addresses for convenience, or when they have no convenient way of accessing their corporate email system from outside the office. Such forwarding should be forbidden by policy unless virtual private networks (VPNs) or other strongly encrypted channels are used for the employee’s private email.

Email and other traffic on the Internet have no inherent confidentiality. In theory, anyone capable of intercepting TCP/IP packets anywhere during transmission can breach confidentiality. Thus, again in theory, anyone with access to the equipment of ISPs, Internet backbone transmission lines, and even to the public switched telephone network can intercept packets. With downlink footprints from satellite relays amounting to square miles, practically anything can in theory be intercepted from much of the traffic circulating on the Internet.

However, in practice, reported breaches of confidentiality have almost all resulted from data access at the endpoints, not in transit. Insider attacks and breaches of server security have been responsible for most of the data interceptions that have reached the press and the courts.

A practical impediment to effective interception of meaningful data in transit is the datagram routing that underlies the Internet: Datagrams are packets of information

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 16 EMAIL AND INTERNET USE POLICIES

with origin and destination information; store-and-forward transmission allows these datagrams to be sent through the Internet via different routes from other packets in a message stream. Routing tables can be updated in real time to reflect changes in traffic density or availability of specific links to other destinations on the Internet, so there is no guarantee that packets from the same message will travel the same route or arrive in the proper sequence (sequence numbers allow reassembly of the original message). Therefore, seizing individual packets at random anywhere other than the origin and destination of packets is unlikely to result in very much result for the effort.

Nonetheless, best practices do recommend that encryption be used for communi- cation of sensitive data; therefore, many organizations install virtual private networks (VPN) for communication with established trading partners. VPN software is also available for tunneling through the Internet from a remote workstation over nonse- cure communications lines. A simple example of such a link-encryption function is the Web-based email services that use SSL to establish a secure link to the email server (i.e., they use https instead of just plain http). The user can pick up email from the corporate server without having it forwarded in the clear to an insecure external email service. Some of the email products include facilities for direct communication between a secure email server and the users’ email client.

Using VPN tunneling software as a search string in the Google search engine brings up almost half a million hits (in May 2013), many of them for specific products and data sheets, so readers will be able to find a solution that fits their needs.

48.4.1.2 Mislabeling the Subject Line. Many people make the mistake of creating new messages to a correspondent by finding any old message from that person and replying to it. The problem is that these people usually leave the old subject intact, resulting in ridiculous situations such as finding a critically important message in July in an email labeled “Birthday party 12 May.”

Not all email messages are created equal; some are destined for the trash heap, if not of history, at least of the email system. That decision is sometimes made automatically as a function of the subject line. For example, a user adds the subject line of a joke to an email filter, resulting in future messages with that subject ending up in the junk mail folder. Someone replies to the joke message with important information, and the mail filter sees the subject and automatically moves the message to the recipient’s junk mail folder. The recipient may never see the important information, as most people do not actively monitor their junk folders.

Another problem with mislabeled subjects occurs when someone embeds more than one distinct topic in an email message whose subject line implies otherwise. For example, suppose an email message subject reads “Next week’s meeting,” but the sender includes an urgent request for action today on some critical issue; there is a good chance the receiver may not open the message right away if other messages seem more important.

Employees should make their subject line as descriptive as possible without turning it into a paragraph. Some email systems truncate subject lines in the display of messages that a user sees; it makes sense to put keywords at the front of the subject. Encourage staff to use prefixes such as “MISA:” or “ABCv2.0.1:” to help organize their messages. Using standard formats in subject lines can help too. For example, faculty and staff in the MISA program at Norwich University refer to an issue in a particular seminar by using the form “MISA c.s” in their subject line, where c represents the class (e.g., 40 for students starting in December 2013) and s represents the seminar number (e.g., 1 through 6).

These simple suggestions can make email more effective as a communications tool.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

THREATS TO PRODUCTIVITY 48 · 17

48.4.1.3 First e-Impressions. When you receive an email message from a stranger, do you care whether it has spelling mistakes and grammar mistakes? What about offensive language and off-color humor? Does the context matter? For example, do you apply the same standards to email referring to business matters as to informal communications about a hobby?

Researchers at the University of Chicago have been investigating the effects of email on perceptions of character. Psychologist Nicholas Epley and colleagues examined oral exchanges on conversational topics by phone between randomly selected people using six assigned questions. They then transcribed the oral conversations and used exactly the same answers for the written, email version of the question and answer sessions.8

Their results were interesting. The questioners had been given false biographical sketches of the people they were communicating with, indicating substandard intel- ligence or normal intelligence, as well as different pictures showing neat people or slobs. Subjects who used the phone to listen to the prescribed responses had favorable impressions of their interlocutor’s intelligence, regardless of the bios and pictures. In contrast, “Via email, however, students held onto their first impressions, continuing to assume their partners had substandard intelligence, for example, if that’s what the biographical sketch indicated.”

If this research is confirmed, the lesson is that when using email, first impressions really do count. Professionals should carefully review email messages for acceptable writing, including word choice, punctuation, capitalization, and spelling.

48.4.1.4 Email Disclaimers. Author Kabay once received a 30-word email message from a very nice reader in Britain and noticed that his email system added the following astonishing disclaimer, which is quoted in its sonorous totality, including British spelling, after scrubbing it of identifying details:

This email, its contents and any files or attachments transmitted with it are intended solely for the addressee(s) and may be legally privileged and/or confidential. Access by any other party is unauthorised without the express written permission of the sender.

If you have received this email in error you may not copy or use the contents, files, attachments, or information in any way nor disclose the same to any other person. Please destroy it and contact the sender on the number printed above, via the <Name of Bank> switchboard on +44 (0) nnnn nnnnnn for <place1> and + 44 (0) nnnn nnnnnn for <place2> or via email by return. Internet communications are not secure unless protected using strong cryptography. This email has been prepared using information believed by the author to be reliable and accurate, but <Name of Bank> makes no warranty or representation, express or implied, as to its accuracy or completeness and is not liable to you or to anyone else for any loss or damage in connection with any transmission sent by the Bank to you over the Internet. <Name of Bank> makes no warranty that any information or material is free from any defects or viruses.

In particular <Name of Bank> does not accept responsibility for changes made to this email after it was sent. If you suspect that this email may have been amended or intercepted, please contact the sender in the manner stated above. If this transmission includes files or attachments, please ensure that they are opened within the relevant application to ensure full receipt. If you experience difficulties, please refer back to the sender in the manner stated above.

Any opinions expressed in this transmission are those of the author and do not necessarily reflect the opinions of the Bank and may be subject to change without notice.

Please note that for the purposes of this document all references to <Name of Bank> or the Bank shall be taken to mean <Name of Bank> (place) Limited or any other member of the <Bigger> Bank Group. Nothing in this transmission shall or shall be deemed to constitute an offer or acceptance of an offer or otherwise have the effect of forming a contract by electronic communication.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 18 EMAIL AND INTERNET USE POLICIES

Kabay commented in his response, “Did you know that your message has 30 words (152 bytes including spaces) whereas your disclaimer has 367 words (2,177 bytes)? That’sthe lowest signal-to-noise ratio(6.5percent useful informationout of the total and a 1:73 signal:noise ratio) I’ve ever seen outside a copy-of-copy-of-copy chain. Please congratulate your attorneys on using maximum of bandwidth for minimum content!”

Cluttering up email messages this way is a waste of bandwidth. It is worse in offices where people copy entire messages without editing the contents, resulting in copy-of-copy-of-copy chains that spread like cancerous eruptions through in-baskets throughout the organization. Some well-meaning folks even include the detailed headers in their copies.

As a matter of courtesy and good sense, when one replies to a message, it is a simple matter to strip nonessentials out of the copy of the original. Senders can use ellipses (… for cuts within a sentence, … . for cuts crossing sentence boundaries) to signal gaps, but usually one or two snips are enough to clean up the copy so that the reader can get the gist of the conversation without having to wade through reams of superfluous stuff. Unfortunately, this recommendation does not seem to be used much in practice.

48.4.1.5 Centralized Distribution Lists. Organizations may grow large enough that there is significant turnover among the staff. Not only do new staff mem- bers periodically join the group, but also staff members move from one functional group to another; for example, a staff member may change from being an assistant director in one program to being an administrative director in another. Occasionally, staff members may leave the group altogether.

A primitive way of maintaining distribution lists is to name a “Keeper-of-the-Lists” to maintain the list of all staff members; however, there is no link between the file and the mailing lists that each member of the group must maintain to be able to distribute email to appropriate individuals or groups. The independent files are almost certain to diverge from a centralized and accurate list. For example, a message that should be sent to all current employees may end up missing several new members and including staff members who no longer work in the target group.

Trying to make many people maintain their own copies of several distribution lists is a hopeless cause: Even with the best will in the world, people will inevitably forget to update their lists and therefore:

� Some mailings will miss legitimate recipients. � Some people will receive messages they have no business reading.

There are at least four solutions that would rectify such a problem.

1. One can implement a central email sever (e.g., Microsoft Exchange Server), switch all users to a centrally controlled email client (e.g., Microsoft Outlook), and define corporate distribution lists maintained by the Keeper-of-the-Lists. All users will automatically access the one and only distribution list for each group without manual intervention.

2. One can install widely available list-server software to allow centralized creation and maintenance of specific lists; for example, SGS-ALL, SGS-DIRECTORS, MSIA-STAFF, MSIA-INSTRUCTORS, and the like create lists that all employ- ees can use in addressing email.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

THREATS TO PRODUCTIVITY 48 · 19

3. One can switch all users to any email client that supports exportable mailing lists. Updated corporate distribution lists can then be sent to all users. However, this solution still requires manual intervention by users: Everyone has to replace an old list by the new list.

4. One can create a discussion group on a public server (e.g., Yahoo Groups) to define closed groups. These groups provide automatic access to mailing lists. Unfortunately, this approach has serious problems: � There are security concerns about using such groups for corporate communi- cations.

� It seems inappropriate to put a necessary production application on a free resource completely out of the control of the organization.

48.4.1.6 HTML Email. One of the six fundamental attributes of information that we protect is integrity, one aspect of which is consistency with the originally stored data (see Chapter 3 in this Handbook). When someone goes to the trouble of producing an elegantly formatted memorandum or other document and sends it out to recipients, everyone would like to preserve data integrity by seeing the same appearance on all the systems sharing that document.

Unfortunately, sending formatted messages as email messages (as distinct from attachments) does not guarantee preservation of the exact appearance of the source material.

Attractive, well-formatted email messages with boldface, italics, different point sizes, and the like usually get transmitted as HTML (hypertext markup language) to recipients’ mailboxes, where most people’s email clients (Eudora, Netscape, Outlook, etc.) allow the funny-looking code to be reconstituted into something similar to the original.

The word similar is mentioned rather than exactly like because HTML does not necessarily control the final appearance of text on a recipient’s system. The codes refer to types, not exact matches, of fonts; thus, a sender might want to use, say, 24-point Arial as a Heading 1 display but a particular recipient might have defined Heading 1 as, say, Times Roman 14 point. A two-page original document may appear to be a three-page document to one recipient and a one-page document to another.

More significantly, though, many people turn off HTML email for security reasons. All such formatted email gets converted automatically into plain ASCII text. A cor- respondent once sent author Kabay a message that read: “Note: The on-line course evaluation system may be used from room, lab, and home—anywhere Internet access is available. / Overview: … . Failure to complete a course evaluation will result in a ‘hold’ being placed on the student’s final grades.”

The fragment of message that follows shows the result of MS-Outlook auto- conversion of the original formatted HTML message to ASCII: “Note: The on-line course evaluation system may be used from room, lab, and home ? anywhere Internet access is available./Overview: … . Failure to complete a course evaluation will result in a ?hold? being placed on the student?s final grades.”

� In the conversion process, the original apostrophes turned into question marks (“?hold?”) because the sender was using “curly” quotation marks instead of the straight ones in the word-processing package or email editor. If one cares to prevent this peculiarity when using earlier versions of Microsoft Word, one has to turn off the option in the {Tools | AutoCorrect | AutoFormat As You Type}

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 20 EMAIL AND INTERNET USE POLICIES

screen by unchecking the box labeled {“Straight quotes” with “smart quotes”}. In later versions, turn off the option by clicking {Word Options} in the main menu, selecting {Proofing}, and then clicking the {AutoCorrect Options} button at the top of the box. {AutoFormat As You Type} is one of the available tabs, and you can then uncheck the box labeled {“Straight quotes” with “smart quotes”}.

� In addition, it looks like a dash character may have been in the text in the first section (labeled “Note”). One can turn that conversion off in the same menus by unchecking {Hyphens (–) with dash (—)}.

A much simpler solution to prevent the mess is simply to send unformatted ASCII text in all outbound messages by selecting that option in one’s email package.

Some people try to send files that should look the same on a recipient system and the originating system by attaching word processing documents: for example, Word (DOC) files, WordPerfect (WPD) files, or Rich Text Format (RTF) files (and so on). Unfortunately, even these attempts do not necessarily work as planned, since lack of shared fonts, different default paper sizes (different countries may use different sizes), and different printing margins (resulting from installation of different printers) may cause the documents not to look precisely the same on all systems.

So if the exact appearance of a message one is sending via email is critically important, one should send the content and its format in a way that is (largely) platform independent; for example, Acrobat PDF (Portable Document Format) files. Although even they do not necessarily result in perfect rendition of the author’s intentions across systems, PDF files are far more likely to succeed than the other methods mentioned. One can create PDF files in a number of ways; some systems have Adobe Acrobat installed so that one can either send to an Acrobat driver to create the PDF files or even just click a toolbar button to do so from within the word processor. Microsoft Office 2007 and later versions, for example, provide the ability to Save as PDF in all of its major components. Other packages exist that are less expensive (and generally less feature-rich) than the full Adobe Acrobat software, but nonetheless allow users to create PDF files easily. One can type “create PDF” into a Web search engine to find lots of choices.

48.4.1.7 Distribution Lists in Email. As for confidentiality, consider that using the To and CC (carbon copy—a bit of historical detritus) fields in email makes all recipient addresses visible to all recipients. This situation is usually helpful in internal email because team members can see who has gotten the message, but it can be annoying in external email. Why should a list of dozens, or even hundreds, of names of strangers be distributed freely among them, without the explicit permission of all concerned? Who knows where that information will end up? Use of the BCC (blind carbon copy) field eliminates the ability of recipients to see all of the intended recipients for the original message. This extra step is a good piece of email etiquette, whether the message is business or personal. The BCC field is also useful for internal email when the list of recipients is very large, but it is not important for people to know exactly who received the message.

In one case, a nice lady in the human resources (HR) department at a university sent out a note to a dozen people reminding recipients that they had not yet finished signing up for their new medical insurance coverage.

Unfortunately, she put all the email addresses into the CC (carbon copy) line where they were visible to everyone in the list. Predictably, someone on the list composed a

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

THREATS TO PRODUCTIVITY 48 · 21

response to her, hit REPLY ALL, and sent some mildly personal information about the state of her medical concerns to all the recipients on the original list, none of whom had any interest in her problems.

Luckily, there was not a lot of private information in that message, but it did prompt the realization that many people unthinkingly use the CC line for addresses to a distribution list and that many people unthinkingly use REPLY ALL for replies to every email message.

The combination can lead to embarrassing violations of confidentiality; when the HR department staff use CC instead of BCC (the Blind Carbon Copy function that conceals the distribution list), the REPLY ALL function can inadvertently violate privacy.

In this case, there was no particularly sensitive material revealed, but a different case could easily violate HIPAA (Health Information Portability and Accountability Act) and the university’s rules on employee confidentiality.

Once employees understand the issue, they will learn not to use CC for distribution lists when the intention is to communicate with individuals; by default, everyone should use the BCC list unless there is a need to stimulate group discussion of an issue or it is important for the members of the group to know who received the message.

It is important not to dismiss this issue as too easy or too obvious to bother with. “Against stupidity, the gods themselves contend in vain,” wrote Friedrich von Schiller in his Maid of Orleans (Die Jungfrau von Orleans) in 1801. Nonetheless, the CC + REPLY ALL habit becomes a covert channel for release of confidential information for people who refuse to keep an address book, and simply look up any old email and REPLY ALL to it as a lazy way of sending a new message.

If you doubt the seriousness of the problem, take some time to look through your own archives of email and count how many obvious cases there are of emails with inappropriate subject lines and inappropriate distribution lists sitting in your received folders. Unfortunately, you may be dismayed by the results of your research. If you look into your own SENT folder, you may be even more dismayed.

48.4.1.8 Effective Use of BCC. As discussed, the problems caused by CC are worse when the recipients do not know each other. One often receives messages from technically unsophisticated correspondents who put dozens of email addresses in the CC field even though many of the recipients are total strangers to each other. Such exposure of email addresses always makes security staff nervous; who knows whether everyone on the list is trustworthy? Even if the list is not misused for outright spam, people often REPLY ALL with useless information, effectively adding people to discussion lists that they never wanted to be on.

One particularly annoying habit is to REPLY ALL with a comment stemming from some initial message. People then generate a series of increasingly long messages including copies of all the previous copies of the ostensibly clever repartee, driving some users to generate an addition to their junk mail filters.

The habit of using REPLY ALL is annoying enough when a reply does not in fact have to go to everyone on the original distribution list. However, REPLY ALL is a positive menace if it is coupled with the abhorrent practice of using an existing email message as a shortcut to creating a new one with a completely different topic, as discussed in Section 48.4.1.2.

48.4.1.9 Managing Private Email at Work. What is wrong with using corporate email for jokes, invitations, and the like? One issue is the waste of bandwidth. Some people find the quality of the jokes, hoaxes, and cheering sessions low enough

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 22 EMAIL AND INTERNET USE POLICIES

to be irritating. Worst yet, the tolerance level for what is considered appropriate in the workplace may vary by individual, requiring the utmost care and consideration for everyone. Another problem arises with politically sensitive messages, such as announcements or viewpoints that some members of a group may find offensive. Why should everyone in the group be subjected to a barrage of unsolicited email just because they work somewhere?

The question also raises some valuable and instructive points about appropriate- use policies for email. Corporations must have a formal written policy on appropriate use of official email. Managers should frame clear written policies that any of the staff members can easily consult for guidance about suitable and unsuitable content for personal messages using corporate mailing addresses. Such policies will reduce possible disappointments and resentments resulting from decisions based on unwritten expectations. In addition, any hint of discrimination based on particular political or religious biases will have to be scrutinized to ensure that the organization is not subject to legal repercussions.

An easy tool that employees can develop is a voluntary mailing list of nonwork email addresses for nonwork email. A Yahoo! group (http://groups.yahoo.com/), for example, offers many benefits over an informal list in the CC: or To: field. Jokes and the like can thus be distributed only to willing recipients, since joining can be purely optional. However, employees must always remember that any activities occurring on company equipment, or using company computing resources, may be viewed by authorized parties and could potentially hurt their reputation or, even worse, set them up for legal problems.

48.4.2 Mail Storms. A peculiar kind of junk email is sent by accident. These flurries of unwanted messages are called mail storms.

Most of us belong to mailing lists; many of us have more than one email address; some of us use autoforwarding to shift email from one address to another automatically; and a few of us use automated responses on our email accounts to let correspondents know when we are out of the office or unable to respond quickly.

All of these factors can contribute to mail storms.

48.4.2.1 Autoforwarding. A mail storm occurs when computers begin send- ing mail to each other without human intervention. Sometimes mail storms can become a denial of service by saturating communications channels and other resources. The email-enabled worms such as Melissa, the I-love-you message, and others, are exam- ples of malicious software programs whose authors deliberately wrote them to create mail storms.

A simple situation occurred in the 1990s:

� An employee leaving on vacation decided to receive company email using a personal account on an ISP with a global presence. By setting an autoforward command on the company account, all incoming mail was sent to the personal email account.

� Unfortunately, on the remote tropical island where the vacationer spent two weeks, it was impossible to access the worldwide ISP without paying a surcharge of $6 a minute for long-distance service to the nearest dial-up node. This proved too expensive, and no emails were received or sent.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

THREATS TO PRODUCTIVITY 48 · 23

� Meanwhile, the company account dutifully forwarded every message it received to the proper personal account—which had a tiny storage limit of 250 messages. That limit was reached within a few days. At that point, every inbound message generated a bounce informing the sender that the recipient’s mailbox was full.

� The very first full-mailbox message sent to the company account was autofor- warded back to the vacationer’s personal mailbox.

� That copy of the full-mailbox message generated a second mailbox-full message, which then got bounced back to the company account, and so on without letup.

� Eventually, even the company mailbox filled up, and then the two email systems continued chattering at each other indefinitely. In this particular case, system administrators noticed the problem when the user’s mailbox reached 20,000 mes- sages and crashed the mail server.

The number of email messages that can be generated by this kind of infinite loop is a function of the latency of the positive feedback system that the user has accidentally created. For example, if it takes exactly one minute for a bounce message to be returned to the originating site, then each message causing an initial error can create 60 additional messages per hour. However, every new message from another sender that arrives at the originating mailbox will generate its own new set of bouncing messages in infinite loops. It is not uncommon to see tens of thousands of messages accumulating in the recipient’s mailbox if nobody notices the loops with traffic mounting steadily into hundreds or thousands of messages per hour bouncing between the accounts, potentially generating a denial of service on corporate email through bandwidth saturation alone. The mail servers may also crash because of the overwhelming traffic.

An out-of-office message can also inadvertently create mail storms through a race condition (see Chapter 39 in this Handbook). For example, two employees (Albert and Bob) both enable out-of-office messages, and Albert sends an email to Bob. Bob’s email service sends Albert back its out-of-office message, which in turn generates another out-of-office message from Albert to Bob. A mail storm results.

48.4.2.2 Poorly Configured List Servers. The user of an autoresponder may belong to a list where the FROM address is actually the broadcast address that sends a response to the entire list. The very first automated out-of-office response to the list will generate a message to everyone on that list, producing an infinite sequence of to-and-from messages. This situation is very embarrassing for the list administrator and intensely annoying for everyone else.

48.4.2.3 Human Error. Something analogous to a mail storm results from thoughtless behavior when using a public list. A typical instance occurs when a list member posts to an entire list comments relevant only to one individual. For example, a member asks for a reprint of an article and another answers on the list: “I’ll send you a reprint tomorrow.” Several thousand unwilling readers now know about this projected email message. One of these irritated people posts a message saying, “Did you really have to post that message to the entire list?” This second message is so irritating that at least one other person posts a third message to the entire list, criticizing the originator of the second letter for criticizing the writer of the first. This useless tempest of email continues via the public list, creating thousands of copies of useless information.

Another form of inconsiderate behavior is to quote entire messages when responding to email. Only the fragments of text that have elicited a response should be copied to the

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 24 EMAIL AND INTERNET USE POLICIES

new message. This principle is particularly important on public lists, where messages have been observed containing the entire text, including Internet headers, for up to seven levels of previous messages. Often, the amount of new information contained in messages posted to Usenet groups is extremely small; the rest was quotations of quotations of quotations.

48.4.3 Buying on the Web. Employers may decide to allow reasonable (how- ever they decide the term) use of corporate resources for non–work-related activities, including buying services and products through the Internet. However, it is in the in- terests of employers to educate employees to avoid becoming victims of criminals. An employee distraught over the loss of significant sums due to foolish credulity will not be as productive as usual; in any case, no one wants to see friends and colleagues cheated.

Buying from known merchants through the Web can be as satisfying as buying in their stores. If you know the organizations selling goods and services, there is no more reason to be worried about buying from them through a Web connection than buying from them over the phone or in person at a store. Websites belonging to recognized merchants or organizations, such as nonprofit charities, are trustworthy, especially if they show any of several symbols representing compliance with various standards of se- curity for customer data. Some of the safety seals in common use include SSL SiteSafe Certificates, TRUSTe, McAfee SECURE, and WhiteHat Security Certification.

48.4.3.1 Dynamic Pricing. One controversial technique that some firms have been studying is dynamicpricing. Dynamic pricing presents different prices to different customers. By building a profile of a specific customer’s buying habits, vendors can inflate prices for people who appear to be more willing to buy higher-priced goods and lower prices for those who are cost conscious. Many brick-and-mortar stores do the same, in that stores in some parts of town may cater to richer people than in other areas; similarly, some chains of stores have been documented as charging higher prices to poor people in ghettos than in suburbs, in part because there is less competition in poor neighborhoods and the cost of doing business may be higher there. A different kind of dynamic pricing occurs in the airline industry, where seats on planes vary in price according to when they are booked and how many seats are expected to be sold. However, unlike these examples, dynamic pricing on the Web resembles traditional automobile sales, where research confirms that women and racial minorities are consistently offered higher prices than the deals for white males. In both automobile sales and dynamic pricing on the Web, the fundamental difference from the normal free-market model is that the prices are varied secretly so that only the victim of the predatory pricing sees the offered price. Without mechanisms for sharing information among purchasers, this model of pricing seems to put the buyers at an immense disadvantage with respect to the seller. It will be interesting to see how it develops over time.

48.4.3.2 Privacy. Another key area of concern when buying products on the Web is privacy. Many consumers prefer their buying habits to remain their own business. Receiving unwanted paper mail or email, because of past purchases, seems intrusive and irritating to them; they classify all such promotions as junk mail. Other consumers appreciate the convenience of receiving targeted information about new products and special sale prices for items they have previously bought. In either case, it is important to pay attention to the privacy policies offered by online vendors.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

THREATS TO PRODUCTIVITY 48 · 25

Marketers must decide whether to set up their systems on an opt-in or opt-out basis. If marketers choose the former, then all individuals actually must agree to have information about themselves included on lists that may be used within the organization or sold to or traded with third parties. If the system is set up for opt-out, then everyone’s information may be freely disclosed, except for those who specifically state that they do not want the list keepers to do so. These are broad general outlines; the privacy policy of each organization must be spelled out in detail.

Some sites such as online bookstores and music services may keep detailed records of what each person buys from them and even what items are simply looked at. These Websites can then tailor their sales presentations to products that are appropriate to each customer’s interests. Amazon.com, for example, tries to be helpful to visitors by suggesting books that may interest the returning visitor based on previous behavior. However, one of the unexpected consequences of customer profiling is that the practice may reveal more than users would wish; if you watch one of your employees enter such a Website and discover that the predominant theme is, say, weapons and techniques of terrorism, you might want to have some serious discussions with your human resources staff. A less positive application of profiling caused a flurry of interest when information about the purchasing habits of employees of specific companies was accidentally made available to those companies’ competitors.

Another issue often raised in discussions of privacy involves cookies. Cookies are small text files that a site stores on a visitor’s hard disk to store information that can be used the next time the user visits the site. Properly defined cookies can be used only by the site that deposited them. The information stored can include the sequence of Web pages the visitor saw, or personal identifiers that allow the Web software to recognize the visitor so that the Website can build up a preference profile for each visitor or client and to enable those cheery greetings like “Welcome back, Bob! We have a special deal for you on the newest title in The Real Man’s Guide to Heavy Artillery series!” Cookies also may be used to accumulate items in a shopping cart; without cookies, each purchase would have to be concluded separately.

In general, cookies are harmless. If you do not like the idea of having identifiers stored on your system, you can block cookies in your browser settings, block them globally or on a site-by-site basis using a personal firewall, or install cookie sweepers that get rid of all cookies whenever you activate them.

For a review of legal aspects of privacy in cyberspace, see Chapter 69 in this Handbook.

48.4.3.3 Online Auctions. The theory behind an auction is that the competi- tion for an object or service helps participants determine a fair price. This process can be corrupted in a real-world, physical auction if the seller conspires with confederates to bid up the price artificially. Unfortunately, this is even easier online, where anyone can have as many identities as he or she wants. The ease with which browsers and email systems allow forged headers and forged identifiers means that sellers can inflate the price of their own offerings.

The Federal Trade Commission of the United States reports that online auctions cause the largest number of complaints they receive annually about fraud.

This theoretical discussion does not even begin to address such questions as whether the auctioned items really exist, are as described, or will ever be delivered. A case of such fraud occurred on eBay, where Robert Guest of Los Angeles admitted in court in July 1999 that he defrauded victims of about $37,000 by offering goods for auction via eBay but failed to deliver anything. The customers of Mr. Guest certainly found out the

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 26 EMAIL AND INTERNET USE POLICIES

hard way that they were being cheated, but it appears that they could not have known in advance that he was untrustworthy. Although eBay maintains a system whereby potential bidders can see reviews and comments posted by earlier customers of each seller, new sellers such as Mr. Guest have no record, and anyone with a bad record can assume a new identity.

eBay has further responded to these concerns by suggesting the use of escrow services and by warning its users that it does not guarantee the legitimacy of the transactions it facilitates.

There are also concerns about the legality of some of the items put up for auction. Someone offered items made from endangered species, in violation of the Convention on International Traffic in Endangered Species (CITES). The products included dried feet of elephants and gorillas caught in snares and allowed to die excruciating deaths before being hacked into pieces. In the United States, buying, selling, and possessing such contraband can lead to arrest, prosecution, fines, or imprisonment.

More ludicrously, someone put up a human kidney for sale through eBay in Septem- ber 1999 and received bids of up to $5.8 million. The auction service canceled the sale because selling human organs is a federal felony punishable by up to $250,000 in fines and at least five years in jail. A week later eBay had to shut down an auction for an unborn human baby. Prices for the supposed baby had risen into the $100,000 range before eBay shut down that auction. Finally, a fool or a prankster—it is unclear which—tried to sell 500 pounds of fresh marijuana online. The auction was shut down after 21 hours, during which prices offered had reached $10 million. In August 2001, a couple offered to name their baby in accordance with the wishes of a high bidder. That auction, too, was ended prematurely.

Most of the bids probably were not legitimate. It is unlikely that everyone who bid for kidneys, pot, and babies really expected to pay for what they were bidding on. They may have been treating the auction like a video game, with no element of reality. Situations such as these invite other abuses, and ordinary users are often at a loss as to how to proceed.

Even if the items being offered for sale online are ordinary things such as software or physical products, they may have been obtained illegally. Online auctions are a frequently used channel for fencing stolen goods.

Corporate users should probably not be using Internet auctions to buy or sell prod- ucts, except in those closely guarded, industry-specific sites that have proven their worth. Certainly, employees should not be using corporate Internet access to engage in such activities for their private purposes.

48.4.4 Online Gambling. It is hard to imagine that any enterprise would au- thorize employees to gamble online using corporate resources, but providing employees with the following guidance may be a valuable service.

48.4.4.1 Fraud and Error. In 1998, the Arizona lottery discovered that no winning number in its Pick 3 game had ever included even one numeral 9.9 It turned out that the pseudorandom number generator algorithm had an elementary programming error that generated only the digits 0 through 8. All those who had used a 9 in their lottery numbers felt justifiable anger—especially when they were told they could have a refund, but only if they had kept their old losing tickets.

The Arizona lottery used a simulated random process to provide the illusion to gamblers that they were betting on a physical process such as balls mixing together in a barrel and falling out of a tube. One of the problems with the Arizona simulation is similar to a genuine vulnerability in proprietary (i.e., secret) cryptographic algorithms.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

THREATS TO PRODUCTIVITY 48 · 27

As cryptographers have stressed over many decades, the security of an encryption scheme should not depend on the secrecy of its algorithm. Had the lottery algorithm been exposed to public scrutiny, its flaws would have been detected sooner. For example, in the 1980s, there was much excitement over a new encryption scheme called the knapsack algorithm; after extensive examination by cryptographers, it proved to be flawed. It is conceivable that someone detecting the flaw in the Arizona lottery might have made bets with a higher probability of winning than those of uninformed people, but exposing the algorithm and its implementation to scrutiny before it went into production would have made that less likely.

These examples demonstrate that electronic gambling, as in older, conventional types, is subject to more than the rules of chance. Lack of conformity to good security practices lays both the gambler and the house open to abuse and to inadvertent errors.

48.4.4.2 Lack of Control. Physical gaming devices are located in real-world establishments under the nominal control of regulatory and law enforcement officials. Even so, they are always adjusted for a certain predetermined payout. Gambling based on the results of actual sports events or contests is validated by external news reports, although the contests themselves can be rigged. But there is no basis for a gambler to trust the results of computer-generated pseudorandom numbers displayed on a browser screen.

Most individual gamblers will never know if a long-range analysis of the pseudo- random numbers would support their hopes for fairness in the odds. No one is keeping track of these data except the people making money from the participants, and they are not distributing the results.

The disclaimer at one Internet gambling portal, findinternetcasino.com, is not very encouraging:

Although every attempt has been made to ensure fairness and security toward the player at each of the links that can be found in the directories, FindInternetCASINO

R© cannot be held responsible if discrepancies occur between an Online Gambling operation and you, the player, after following a link from this WWW site. Consult your local authorities prior to registering with any online wagering service. U.S. Citizens: The information at this site is for entertainment and news purposes only. Use of this information in violation of any federal, state, or local laws is prohibited.

48.4.4.3 Legal Issues. In some jurisdictions, betting online is illegal. In the United States, for example, it is already illegal to use interstate telecommunications to place bets; in addition, Internet betting is illegal in the United States even if the host is outside the United States. At the same time, due to ambiguities in the current laws and the inability to clearly enforce them, the use of overseas betting sites has driven this business to a total of over $15.5 billion a year, over half of that income coming from the United States. The ambiguities stem from a lack of a clear definition on what constitutes illegal online gambling. This resulted in certain groups of individuals believing that they were exempt from the law, poker players being the most common. In addition, online horse racing receives a specific exemption from the law, but without accompanying clarification on whether the wagering process constitutes online gambling.

Unfortunately, in the United Kingdom and many other countries, online gambling is for the most part legal. This creates numerous conflicts of interest, and international tension, between various betting companies in legalized countries, all advertising to Americans eager to risk their money for a chance at a big payout. It appears that until clear definitions are included in the law, the blurred line between legal and illegal gambling activities using online resources will continue.10

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 28 EMAIL AND INTERNET USE POLICIES

48.4.5 Internet Addiction. Any activity can become the basis of compulsive exaggeration. A small proportion, around 5 percent, of Internet users may qualify as addicted to any of these computer-mediated activities:

� An uncontrollable desire to find and organize more and more information about an enormous range of topics

� Excessive involvement in games, gambling, and buying things on the Internet � Excessive concentration on relationships mediated through email and chat rooms, to the detriment of real-life relationships

� Involvement in long sessions of viewing pornography, or of being sexually stim- ulated via email, chat rooms, pornographic sites, or sexual-fantasy games

None of these activities is a suitable use of corporate computing resources, and employees should be alerted to the policies prohibiting such activities at work. In addition, everyone should be aware of the dangers of Internet addiction.

The issue here is what constitutes excessive involvement in these activities. Profes- sional psychologists such as Dr. Kimberly Young have identified some of the diagnostic criteria for these disorders, including these based on her Internet Addiction Test11:

� Regularly staying online longer than intended � Often neglecting obligations to spend more time online � Consistently preferring to spend time online instead of with one’s partner � Frequent complaints by friends and family about excessive Internet use � Suffering consequences at school or at work because of time spent online � Giving email a higher priority than other important issues � Concealing the extent of Internet usage � Turning to the Internet as a substitute for dealing with disturbing issues � Feeling that life without the Internet would be devoid of meaning and pleasure � Getting angry when disturbed during Internet usage � Losing sleep due to late-night Internet activity � Yearning to be back online

Those who feel uncomfortable about their level of involvement with the Internet would do well to take this test offered by Dr. Young, and, if several of their answers are positive, to seek counseling to prevent possibly tragic consequences of untreated addiction.

48.4.6 Online Dating and Cybersex. As in other topics in this chapter, it is unlikely that corporate policy would allow users to engage in online dating and cybersex. Nonetheless, in line with the overall orientation of this chapter, the next sections will help employees understand the issues in these online activities.

48.4.6.1 Dating Online. Thousands of sites on the Web specialize in helping people meet each other. In a sense, chat rooms and bulletin board systems are ways for people with similar interests to communicate about their hobbies and lifestyles. There are also sites that specialize in helping people find others who match particular profiles.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

THREATS TO PRODUCTIVITY 48 · 29

Some of these sites are free; others charge fees for participation. Dating service sites usually explicitly restrict participation to people over 18 years old, and most of them depend on possession of a credit card as their sole mechanism for authenticating age. It is very difficult to exclude teenagers, or even younger children, from such sites if they have access to credit card numbers.

Parents, teachers, and employers who want to get a sense of what is going on can type “online dating” in the search field of a search engine such as Google (www.google.com) and then visit a few of the sites. If children post information about themselves in such a cyberspace locale, even with false information claiming that they are adults, there is a real risk of attracting unsavory characters or perhaps ordinary people who can become angry at being tricked into exposing their feelings to an imposter.

48.4.6.2 Sex Talk Online. In addition to matchmaking, users of the Internet also can get involved in cybersex. People chatting online can describe themselves or each other in sexual interactions that are inappropriate for youngsters. Such online chat also has been implicated in a number of divorces, since many spouses find it wholly inappropriate that their beloved is getting sexually excited with a stranger via the Internet.

In August 2001, a 15-year-old girl from Massachusetts was alleged to have been kept captive for at least a week during which she was repeatedly sexually abused by the couple who had brought her to Long Island. According to the criminal complaint, she was also loaned out for two days to another man and further abused. The couple had met the teenager in an Internet chat room, where their conversation was explicitly sexual.

In the work environment, circulating sexually charged messages or outright pornog- raphy can justifiably be perceived and described as fostering a hostileworkenvironment and can lead to lawsuits by the affected employees.

Employers should promulgate policies to prevent such abuse and monitor corporate email and instant messaging to ensure that no one in their employ engage in these activities using corporate resources.

48.4.6.3 Traffic in Women. A number of sites on the Web, particularly some situated in the former Soviet bloc, advertise services for introducing men to willing candidates for marriage. The evidence is strong that much of the information com- municated about the supposedly nubile and marriage-oriented women is false. Many of the pictures are taken from public Websites and include actresses and people who have posted their photos on social networking groups. Sometimes the same picture has dozens of names associated with it. Much as in the phone-based sex-talk services, people claiming to be youthful, attractive, persons of marriageable age may be noth- ing of the sort, and may be copy/pasting responses from prepared scripts. When men travel to visit their potential mates, they can be charged high rates for the privilege of taking their dates to expensive restaurants. Some of the women who actually do go through with marriages later divorce their hapless victims once they are admitted to their husband’s country of residence in what appears to be systematic fraud.

48.4.7 Games and Virtual Reality. Some enterprises allow their employees to play games at various times during the day—usually low-usage times such as lunch, or before and after the normal workday. However, some Internet-enabled multiuser games can consume enormous bandwidth; the shoot-’em-up (first-person shooter, or FPS) game called Quake was notorious in its day for saturating all available connec- tivity.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 30 EMAIL AND INTERNET USE POLICIES

When helping employees understand how to negotiate the perils of the Internet, you might recommend that parents read reviews of video games before allowing their young children to play them. Some games have astonishing levels of graphic violence (“Brilliant Bleeding! Detailed Decapitations!”) and unusual values (“Win points by burning as many residents to death as possible!”). This latter example is based on a notorious case in which a video-game vendor was apparently surprised by the public wave of revulsion over a game that glorified arson. Some military and police shoot- ’em-up games explicitly take points off for hitting innocent bystanders; others do not. Some games use graphic nudity; others are more modest. The main point is that relying on the judgment of eight-year-olds to choose their own entertainment may be unwise.

From a corporate perspective, it would be unusual to find employers encouraging the use of local or networked games during working hours; however, some may allow use of their resources in off-hours, assuming the corporation does not maintain around-the- clock operations. However, issues of suitability persist; some games may contribute to a hostile work environment and lead to complaints and lawsuits from offended employees.

A development that started in the 1990s has become a potentially valuable tool in the first decades of the twenty-first century: virtual reality or virtual worlds, such as Second Life (http://secondlife.com). These services use controllable representations called avatars, which allow some degree of expressiveness when communicating. Participants see a representation of a three-dimensional world, complete with viewpoint and perspective, that includes their interlocutors in a shared virtual reality that can be creative and fun. Some companies are using resources in these virtual worlds for advertising, delivery of services (e.g., training and education), and internal remote meetings or training. Organizations must determine appropriate policies about the use of such services.

48.4.8 Changing Email Addresses. Employees may leave a company, change organizational units, or change their own names. All of these changes may result in new email addresses. Handling such changes poorly can lead to trouble.

One reaction to such a change is to delete the original email address without notifi- cation to anyone. Email sent to the original address is returned with an undeliverable (no such user) error. The sender must then find out what happened—or may simply drop the connection altogether, possibly losing a company a client or leaving important information undelivered.

If the disappearing email address is due to the user’s change of name (for example, resulting from marriage or divorce), it is even possible that the corporate directory will have the original name wiped, making it difficult for correspondents unaware of the new name to reach the person at all by email or by phone.

A wiser response to any such change is to autoforward the incoming mail to the correct address. For example, if Farid Hallings’s original email address was [email protected] and is now [email protected], any mail sent to the first address would automatically end up in the mailbox for the second address. If Farid no longer works for the company at all, the email can be forwarded to the appropriate replacement’s address. Such forwarding can be maintained for whatever period seems appropriate.

In addition to the autoforward, it may be helpful to send automatic notifications to the sender of the outdated email. “Farid Halling’s new email address is fmal- [email protected]; your message has automatically been forwarded. Please make a note of the change in your email address book.”

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

LEGAL LIABILITY 48 · 31

48.5 LEGAL LIABILITY. This section briefly reviews some of the legal issues that may arise as a result of misuse of email and Internet resources. For more detailed information, see Chapters 63, 64, 69, 70, 71, and 72 in this Handbook.

48.5.1 Libel. Some people have taken advantage of the freedom to publish what- ever they want by crossing the boundaries of libel. For example, the self-styled reporter Matt Drudge went too far in postings on his electronic scandal sheet in 1997, when he made unsubstantiated accusations about White House advisor Sidney Blumenthal’s marriage. Professional journalists pounced on him for shoddy journalism. Blumenthal and his wife filed a $30 million libel suit against Drudge even after he apologized for failing to verify the gossip he disseminated. Drudge then claimed that public White House support for Blumenthal amounted to a threat against free speech.

In another notorious case, Walter Cronkite, whom polls revealed to be the most respected man in the United States in the 1980s, was appalled to discover a page of lies about him on the Web in 1997. A 28-year-old programmer, Tim Hughes, invented and posted a scurrilous story about Cronkite’s becoming enraged at the author, shrieking imprecations at Hughes and his wife, boasting about his own infidelity, and spitting in their spice cake at a Florida restaurant. In addition, the anti-Cronkite Web page included falsified photographs purporting to show Cronkite at a Ku Klux Klan meeting. Cronkite threatened to sue for libel; Hughes took the page down and weakly protested that it was all a joke.

The effect of this kind of misinformation on children or immature employees, un- trained in critical thinking and lacking in skepticism about information on the Internet, can be damaging.

Another source of information is the Usenet—that collection of thousands of dis- cussion groups on every conceivable topic. These discussion groups fall into two major classes: moderated and unmoderated. In a moderated group, messages are passed through a moderator who decides either to post them for participants or to delete offensive or otherwise inappropriate messages. Not all moderated groups are reliable, and not all unmoderated groups are unreliable. However, many unmoderated groups distribute unsubstantiated information from people who appear to derive their major pleasure in life by insulting other participants and by making outrageous statements about any topic that comes up. Everyone should be trained to recognize emotional and inflammatory language, and should be encouraged to apply skeptical analysis to all statements, especially to those published in rants.

In the first decades of the twenty-first century, blogs—commentaries published on the Web by individuals or groups—have exploded into common awareness. The same principles of critical evaluation apply to blogs as to any other source of disintermediated information. In one case involving author Kabay, a lunatic conspiracy site illegally reposted the entire text of one of his columns describing InfraGard with pictures of victims of Nazi atrocities in concentration camps between each paragraph. A Digital Millennium Copyright Act (DMCA) takedown request was obeyed, but the incident was disgusting to the author.

48.5.2 Stolen Software, Music, and Videos. Organizations cannot permit employees to download and make illegal copies of intellectual property of any kind. Se- curity policies must explicitly address these issues; security monitoring must explicitly control for abuse of corporate resources in such activities. The risks to organizations by tolerating such violations of law are severe. For more details of intellectual property law, see Chapter 11 in this Handbook.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 32 EMAIL AND INTERNET USE POLICIES

48.5.3 Plagiarism. A different kind of fraud involving intellectual property occurs when people misrepresent someone else’s work as their own. Older students know intellectually that this is supposed to be bad, but for young children, the issue is completely abstract. The problem today is that plagiarism is easier than ever and harder for teachers to detect.

Academic guidelines try to make it clear to students that copying other people’s work without attribution is called plagiarism and is severely frowned on. Plagiarism includes not only direct quotation without indications of origin but also paraphrasing that merely shuffles the ideas around a little or substitutes synonyms for the original words. In many institutions, plagiarism is grounds for suspension or expulsion. In all cases, plagiarism defeats the purpose of writing assignments by eliminating the opportunity for critical thinking and creative expression. Few plagiarists remember what they have copied from others after they hand their material in.

Assuredly, students have traded term papers and other assignments for centuries. However, the availability of electronic documents and of the World Wide Web has enormously increased both the fund of material that can be plagiarized and the ease of copying. Worse still, some people are profiting from easy accessibility by selling papers specifically for plagiarism and even writing papers to order. In one study by Peggy Bates and Margaret Fain of the Kimbel Library at Coastal Carolina University, the authors easily located over 100 sites on the Web selling or donating papers to students for plagiarism.12

To combat this problem, science has come to the aid of beleaguered instructors by providing automated similarity analysis of any paper submitted electronically. The system uses a bank of more than 100,000 term papers and essays as well as documents located on the Web; analysis uses pattern recognition to measure similarities among different documents and to estimate the probability of plagiarism. According to the turnitin.com documentation:

Our system is now being used in the majority of universities in the United States and the U.K., as well as a large number of schools around the world. Many of these institutions, among them UC Berkeley and the fifty-eight member schools of the Consortium of Liberal Arts Colleges, an association of the most respected liberal arts schools in the US, have chosen to ensure the academic integrity of all their students by selecting institution-wide subscriptions to our service. Other universities, such as Harvard and Cornell, have elected to make use of our system on a departmental or single-instructor basis.

Plagiarism is also a risk to the enterprise; having employees misuse other people’s or other organization’s materials without attribution can lead to lawsuits, embarrassing publicity, and serious financial penalties. In one notorious case from 2003, a policy paper about Iraqi intelligence organizations distributed by the Prime Minister’s Office in the United Kingdom was discovered to include large swathes of verbatim material, including typographical errors, copied and pasted without quotation marks and without indication of its source.13

Practical guidelines: � Discuss plagiarism clearly at work, at home, and at school. � Use examples to illustrate the difference between plagiarism and a legitimate use of other people’s work.

� Encourage children to practice summarizing information in their own words. � Practice writing references to quoted material.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

LEGAL LIABILITY 48 · 33

� Have a student submit their term paper to one of the online services that verify originality.

� Discuss how antiplagiarism sites analyze documents to measure similarities and help teachers identify plagiarism.

48.5.4 Criminal Hacking and Hacktivism. As discussed in Chapter 45 in this Handbook, it is important that all employees understand and agree that using corporate systems for unauthorized access to computers and networks is grounds for dismissal, and possibly criminal prosecution. In particular, no employee should ever imagine that testing for security weaknesses in the enterprise’s systems without authorization is a contribution to security.

The motivation for illegal actions does not mitigate the seriousness of computer trespass. Employees should be informed explicitly that regardless of the excuse, no violations of law will be tolerated. For example, hacking into systems in another country to support a war effort is not excusable; nor is destroying child pornography sites a good idea. Cybervigilantes can destroy evidence needed for prosecution.

48.5.5 Creating a Hostile Work Environment. In today’s society, there are numerous activities and language constructs that individuals of a certain race, gen- der, sexual orientation, national origin, religious affiliation, or other legally protected characteristics may find offensive. Any type of harassment, most especially comments or actions based on these protected characteristics, toward another employee may cre- ate a hostile work environment. The two most common situations created by a hostile work environment are:

1. A reduction or loss of productivity due to the harassment, whether physical, verbal, or psychological

2. A reduction in salary, bonus, job level, responsibilities, or other components of compensation due to one or more of the legally protected characteristics

Although there are no formal laws barring hostile work environments, Title VII of the Civil Rights Act of 1964 covers these types of situations. These laws are written in such a way that an individual comment or action does not usually constitute harassment. Rather, a pattern of frequent, severe, and pervasive abuse may constitute a hostile work environment. It is important to distinguish between quid pro quo harassment, where an employee is required to tolerate such harassment in order to maintain job status or compensation levels, and a hostile work environment. Both are very serious and potentially illegal activities, but this section focuses on the hostile environment.14

Employers are obligated by law to set appropriate expectations around employee behavior, and confidentially and swiftly to investigate any complaint of harassment from an employee. Employees are granted some legal protections such that retaliation by an employer for sounding the alarm on a hostile environment is illegal.

These issues become even more important when office romances occur. Although many employers forbid couples from working together in the same department, in part to avoid any perception of favoritism or future harassment cases, should the romance fail, there is still the potential for romantically linked coworkers to create a hostile environment for others. In this case, employers have an obligation to define in policy that coworkers should maintain a professional relationship while on company business. Eventhoughtwoindividualsmayfeel that their wordsor actionsare seemingly

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 34 EMAIL AND INTERNET USE POLICIES

innocuous, it is the perception of others around them that creates the basis for a harassment complaint. The best solution is to keep personal lives out of the office, which is a difficult but appropriate recommendation for everyone.

48.5.5.1 Hate Groups. Another source of concern for employers and parents is the easy accessibility of hate literature on the Web. Hatemongers have taken full advantage of the largely unregulated nature of the ’Net to spread their pernicious mes- sages. One can find Websites devoted to hatred of every imaginable identifiable group. Race, ethnicity, religion, gender, sexual orientation, immigration status, and political ideology—anything can spark hatred in susceptible personalities. Unfortunately, some of the hate groups have been quite successful in recruiting young people through the Web; they publish propaganda such as pro-Nazi revisionist history that may fool un- critical people into believing their rants. Neo-Nazi and racist skinhead groups have formed hate-rock groups that take advantage of kids’ enthusiasm for very loud music with aggressive lyrics.

Employers cannot tolerate the slightest involvement of their employees in such activities using corporate resources. Aside from their possible personal revulsion at such hatemongering, managers also should be aware that toleration of intolerance can lead to a hostile work environment in which targets of hate or contempt can legitimately appeal to the courts for compensatory and punitive damages. Employees must understand and agree that using any corporate resources for participation in hate groups is a serious infraction of Internet usage policy.

According to the Simon Wiesenthal Center, there are over 2,300 Websites advocating hatred, of which over 500 are extremist sites hosted on American servers but authored by Europeans; most European countries have strict antihate laws. Using more stringent criteria, the Hate Watch group estimates more than 500 extremist hate sites on the Web; it distinguishes between hate propaganda and those pages that consist largely of racial epithets, dismissed as mere graffiti.

The Southern Poverty Law Center monitors 500 active hate organizations in the United States. It has regularly reported on the growing number and stridency of such sites. In comments about the center’s paper for the United Nations Commission on Human Rights, spokesperson Mark Potok said at a conference in 2000:

A few years ago, a Klansman needed to put out substantial effort and money to produce and distribute a shoddy pamphlet that might reach a few hundred people. Today, with a $500 computer and negligible other costs, that same Klansman can put up a slickly produced Web site with a potential audience in the millions.15

A fundamental reality is that human beings are gregarious. They find it very easy to affiliate with others to form in-groups, groups to which they feel entitled to belong. Unfortunately, defining in-groups naturally means it is equally easy to define out- groups: groups to which we do not want to belong. Grade school and high school cliques are examples of in- and out-groups. A wealth of study in social psychology confirms the validity of the universal impression that we tend to inflate our esteem for in-groups and to reduce our respect and liking for out-groups. However, research also shows that social norms against discrimination can reduce hostility toward out-groups; thus it seems likely that parental and teacher articulation of norms of tolerance can significantly reduce children’s susceptibility to the blandishments of hate groups.

48.5.5.2 Pornography. Pornography—even with the most restrictive definitions—is widespread on the Internet. Observers of ’Net culture have commented

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

LEGAL LIABILITY 48 · 35

that the sure-fire way of telling if new technology is going to be a success on the Inter- net is to see how quickly pornographers can apply it. For example, the appearance in July 2000 of the first WAP (wireless application protocol) pornography sites signaled the adoption of WAP technology into the mainstream. Although the sites offered only tiny grainy images of naked Japanese models, sociologists said that the same expected sequence of rapid technological advances had occurred with photography and video cameras.

48.5.5.2.1 Prevalence of Porn. Some studies of Internet traffic have claimed that more than half of the total ’Net bandwidth is used for transfer of pornography or solicitations for purchase of pornography.

48.5.5.2.2 Trickery. Pornographers use various tricks to get people onto their Web- sites:

� Using a different domain, like the old whitehouse.com, which used to take advan- tage of interest in “whitehouse.gov” by showing porn (it is now a directory with several paid links for dating).

� Misspellings, such as the now-inactive micosoft.com, which traded on the likeli- hood of mistyping “Microsoft.com.”

� Junk email invitations with innocent-looking labels for URLs that do not match the actual link but instead take the viewer to a pornography site.

� Padding porn-site metatags (normally invisible text used to describe a Website) with inoffensive keywords that place the site high on search engine lists where they can appeal to children.

� Disabling normal features of a browser to trap victims in the porn site. One perpetrator who was shut down by the Federal Trade Commission (FTC) actually ran Java applets that disabled the back arrow and defeated the ability to close the browsers. People trapped in porno-hell had to reboot their computers to get out.

Porn sites are notorious for using deceit to defraud their victims. One widely used scam is to demand a credit card number from a visitor as proof of their age (it is nothing of the sort), then to charge the card even though the site clearly states that there is a period of free use.

In 1996, viewers of pornographic pictures on the sexygirls.com site were in for a surprise when they got their next phone bills. Victims who downloaded a special viewer were actually installing a Trojan horse program that silently disconnected their connection to their normal ISP and reconnected them (with the modem speaker turned off) to a number in Moldova in central Europe. The long-distance charges then ratcheted up until the user disconnected the session—sometimes hours later, even when the victims switched to other, perhaps less prurient, sites. Some victims who stayed online for a long time paid more than $1,000 in long-distance charges. In February 1997 in New York City, a federal judge ordered the scam shut down. An interesting note is that AT&T staff spotted the scam because of unusually high volume of traffic to Moldova, not usually a destination for many U.S. phone calls. In November 1997, the FTC won $2.74 million from the Moldovan telephone company to refund to the cheated customers—or the ones willing to admit to having been cheated.

Both of the scams just described relied in part on the reluctance of porn-seeking victims to admit to their socially disapproved interest. Few victims were willing to pursue the matter until the damages mounted into the thousands of dollars.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 36 EMAIL AND INTERNET USE POLICIES

48.5.5.2.3 Filtering. An entire industry has grown up to try to shield (or block) children from seeing pornography or other materials deemed offensive by their parents or by the makers of the blocking software. The popular blocking systems are reviled by many free-speech advocates, and often ridiculed for what are described as clumsy, keyword-oriented algorithms. The classic examples of ludicrous blocking include trap- ping access to any site that uses the word breast—including even possibly this very page if you are reading it on the Web. Other simple-minded traps have blocked users from accessing information pages for geographical locations ending in the old British suffix -sex such as Wessex, Sussex, Middlesex, and so on. The village of Scunthorpe in England was blocked by software used by a major Internet service provider because its internal filters prevented anyone from using vulgar words in their mailing address.

Some of the blocking software products use hidden assumptions about the unsuitabil- ity of a wide range of topics, including abortion rights, civil rights, political ideology, and gay liberation. Any parent is entitled to express opinions about any topic; however, parents will want to check on whether a particular program is imposing its makers’ po- litical agenda by stealth. In the workplace, employers who use broad-spectrum blocking software may interfere with legitimate research by their employees.

48.5.5.2.4 Monitoring. A different approach to interfering with the nefarious deeds of pornographers is to install monitoring software on the computers that employ- ees use at work or that children will use at home. These products keep a log, or audit trail, that allows employers and parents to see exactly what users have been doing with their computers.

In the family context, most important, however, is the principle that machines and programs cannot by themselves teach values. Instead of relying only on passive barriers or on snoopware, parents would do well to make surfing the Internet a family activity rather than a private hobby. When kids express interest in pornography—because our popular culture is full of sexual innuendo that children read, hear, and see—it makes sense to discuss the issues rather than try to pretend that they do not exist. One approach for reducing the power of the forbidden fruit offered by pornographers is to explain to children in a supportive and nonpunitive way why sexual exploitation and degradation are bad for people. Children who stumble on porn sites by accident or at their friends’ houses may be better prepared to cope with the sometimes disturbing images and words if their parents have prepared them for this aspect of today’s world.

48.5.6 Archiving Email. Organizations must remember that email may be de- manded as evidence in court cases. There is a fiduciary duty to maintain business records appropriately for each type of business, and that obligation extends to elec- tronic records. Policies should stipulate how long email records should be maintained. Destruction of email should never be selective, especially if there is an anticipated threat of legal action. Selective destruction of particular records, or premature whole- sale destruction of email, may be interpreted by the courts as grounds for charges of interference with the judicial process.

For details of backup and archiving policies, see Chapter 57 in this Handbook.

48.6 RECOMMENDATIONS. This section summarizes some practical recom- mendations for employees and their families. Framing policies in a way that supports employees’ concern about their own families is a helpful way of increasing the per- ceived value of the guidelines.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

RECOMMENDATIONS 48 · 37

48.6.1 Protecting Children

� Explain the dangers of communicating with strangers via the ’Net in the same terms that you discuss the dangers of talking to strangers anywhere else.

� Alert children to the questionable identity of anyone they meet exclusively through the ’Net or via email. Discuss the possibility that people are not what they claim to be in their online persona.

� It is important that children feel confident of a supportive response from their parents when raising these issues. Establish a calm atmosphere so that children will not fear your reactions if they are troubled by what they encounter online. Worst of all would be to punish a child for reporting a disturbing incident.

� Tell children not to give their address to strangers they meet electronically. � Children should not send pictures of themselves to strangers. � Make a practice of discussing online relationships in a friendly and open way at home. Show interest in the new friends without expressing hostility or suspicion; ask to participate in some of the online chats and email correspondence. Invite your children to sit in with you during your own online interactions.

� If a child feels that another child met online is becoming a good friend, parents should contact the child’s parents by phone and, eventually, in person before allowing contacts.

� If a child wants to meet someone encountered on the Internet, be sure that a parent is involved at all stages. Never let a child meet anyone in the real world whom he or she has met only on the ’Net. Any attempt to induce a child to meet the correspondent alone or secretly should be reported to local police authorities for investigation.

� Make it clear that anyone who suggests hiding an online relationship from the child’s parents is already doing something wrong.

� Make it clear to your children that no one has the right to send them age- inappropriate, sexually suggestive, or frankly pornographic materials, whether written or pictorial. Suggestions on the Internet that children engage in virtual sex play or sexual fantasies should be reported to parents right away. Making, transmitting, and storing child pornography is a felony; report such cases to local police authorities at once.

� Children receiving a request for anything unusual (e.g., a request for a piece of clothing or for nude pictures) should immediately report the incident to their parents. Teachers and other caregivers can adapt these principles for the specific circumstances of their relationship with the children they are taking care of.

48.6.2 Threats

� Employers, parents, and teachers should clearly enunciate policies preventing anyone—including children—from uttering threats of violence or other harm, even in email messages or chat rooms.

� Employees should be instructed to report all threats directed at them, or at oth- ers, to the security officers in their organization; similarly, parents, teachers, or librarians should ensure that children know to report any threats immediately to the appropriate adult.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 38 EMAIL AND INTERNET USE POLICIES

48.6.3 Hate Sites

� To protect children against the wiles of these hateful people, the most important step is to discuss the issue of hate speech and hate groups with them openly. Parents may even want to visit some of the sites listed below with your kids to give them a sense of the problem and possible countermeasures.

� Discuss your children’s feelings about out-groups in their own lives; for example, encourage them to speak freely, without fear of punishment or reprimand, about whatever groups they do not like. Then pursue the discussion with explanations of such issues as cultural differences, history, or whatever else you feel will help your children gain perspective on their own feelings and behavior. Of course, this positive attitude cannot be applied to hate groups or similar outlaws.

� Provide positive social role models for children with respect to hate groups. Speak out firmly in opposition to intolerance rather than sit silently by when bigots display their hatred for other groups.

48.6.4 Pornography

� Place young children’s Internet-access computers in a family area of the home rather than in their bedrooms.

� Interact with your children while they are using the Internet; treat the Web browser like a window on the world, and be present to help your children interpret that world in a way consistent with your values.

� Talk with your children about the existence and nature of pornography; as they reach puberty, assure them that there is nothing wrong with being interested in sex, but that pornography is not a healthy way of learning about wholesome, loving relations.

� Warn your children about some of the tricks used by pornographers to get traffic on their Websites, such as telling them to download special readers. Tell them about the Moldovan porn scam.

� Discuss the issue of junk email that advertises porn sites. Warn children that no one should ever click on a URL from any kind of junk email because it can easily be a trick to get them into dangerous territory.

� Teach your children to keep an eye on the actual URL that appears in the browser window; any discrepancy between the visible URL shown on a page and the actual URL should alert them to the possibility of fraud.

� Explain that pornographers sometimes charge for access to their sites without permission; be sure your children understand how dangerous it would be to give your credit card number to these people for any reason.

48.6.5 Internet Addiction

� Know the warning signs of Internet addiction and self-monitor. � Discuss Internet addiction and its warning signs with your employees and your children.

� Encourage open discussion of feelings about the ’Net, so that children feel free to turn to you for help if they become uncomfortable or unhappy about their own experiences on the ’Net.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

RECOMMENDATIONS 48 · 39

48.6.6 Online Dating

� Do not build online profiles or give out addresses, phone numbers, or school names.

� Do share email accounts with your children, and oversee their messages. � Keep the computer in a family room where children’s activities can be monitored. � Remember that people may lie when describing themselves online. � Do not allow children to meet online users without permission, and make all meetings in public places with adult supervision.

� Forward copies of suggestive or obscene messages to your Internet service provider.

� Find ways to block objectionable material. � Discuss online dating with kids so they understand what is involved. � Ensure that kids understand why it is inappropriate and even dangerous for them to masquerade as adults in online dating services.

� Do not rush into face-to-face contact; you need to be sure that you are meeting someone who is on the level, not an imposter who has ulterior motives.

� You may want to take advantage of anonymizing services offered by some dating sites to avoid handing out your real email address to complete strangers.

� Be suspicious of anyone who tries to pressure you in any way, including demanding money or insisting on a meeting, before you feel confident of the person’s good intentions.

� As you are getting to know someone online, ask questions about lots of things you are interested in—for example, hobbies, politics, religion, education, birth date, family background, and marital history and status.

� Keep the answers you receive and beware of people who provide inconsistent or contradictory information as they are communicating with you—any lie is a danger signal.

� Be suspicious of anyone who seems to be too good to be true; if someone matches you on every single preference or interest you mention, try mentioning the very opposite of what you said earlier in the communications and see if the person agrees with that too. Trying too hard to please by lying may mark a manipulative and potentially dangerous personality.

� Be honest about yourself; state your own interests and characteristics fairly, in- cluding things you think might be less attractive than stereotypes and cultural norms dictate. A mature, good person will not necessarily be turned off if you do not look like a movie star, or if you do not play four musical instruments perfectly, or if you lisp.

� If you get to the point of exchanging pictures, be sure that you see the person in a wide variety of situations and with other people; some online daters send false pictures to misrepresent themselves.

� Talk to the person you are getting interested in over the phone; be suspicious if the person resists such a request for a long time or always has excuses for not being available when you have agreed to talk.

� Listen carefully to how the person sounds on the phone, and be suspicious if you now receive information that contradicts something the person wrote to you about. Any lie should alert you to potential problems.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 40 EMAIL AND INTERNET USE POLICIES

� Before you agree to meet, get your date’s full name, address, and telephone number. Be suspicious if the person refuses to give you a home number: Could he or her have a spouse or a current live-in friend that he or she is trying to deceive? Call the home number a couple of times to see if someone else answers.

� Give the person’s information, and the exact details of where and when you are going to meet, to friends and family. Do not ever accept a date with someone who wants to keep the location and time a secret. Be sure the meeting place is well lighted and in a public place such as a coffee shop.

� Do not allow a stranger to pick you up at your house, and be sure you can get home by yourself.

� Before considering further involvement, for safety’s sake think about having a background check done on the person you like, using a professional service.

48.6.7 Online Games

� Learn to play some of the games your kids are enthusiastic about. Take the time to immerse yourself in the imaginary worlds they play in, and study the underlying values that are being communicated by the game creators.

� Use published reviews from online or other media that reflect your own family’s values before allowing games into your home.

� Accompany your children to the stores when buying video games. Check for parental warning labels. Talk to the salespeople if you think they are reliable.

� Know the characteristics of your hardware and software before buying recently released games. Do not buy a new game only to discover that it does not run on your obsolescent system. A disappointed child can apply intense pressure to spend money on a new system. Some games are computationally intensive and require expensive, advanced computer hardware and modern sound systems, complete with a high-powered amplifier driving woofers and subwoofers.

� Try making game playing an opportunity for family fun or parent–child bonding instead of the isolating experience games can sometimes be. See if you can all have fun with puzzle- and exploration-oriented games such as Myst and Riven, neither of which involves violence, and both of which are visually beautiful.

48.6.8 Online Purchases

� Before spending a considerable amount of money on a new online merchant’s site, do some basic research into the site’s reliability. Check the company’s reputation; see if it belongs to the Better Business Bureau (BBB), and contact the appropriate chapter of the BBB to see if there have been complaints about the vendor.

� Do a Web search using a good search engine, such as Google, to see if there are any up-to-date reports about customer experience on the site you are interested in.

� Pretend that you already have a problem and look for the customer service pages. Are there clear instructions on how to communicate problems? Would you have the choice of email, letters, or phone communications? If you have the time, you may even want to try calling customer service and find out just how they handle calls. If you hit a company that hangs up on you when its lines are busy (“We are sorry, but all our agents are busy; please call back later.”), you might want to give serious thought as to whether it is safe doing business with them.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

RECOMMENDATIONS 48 · 41

� Read the company’s return policy; how does it handle breakage in transit, or defective goods? Does it offer guarantees on delivery time? What happens if the company is out of stock on a specific item—does it ship partial shipments or wait for everything to be ready? When out of stock, does it charge your credit card immediately, or only after the shipment is made? If it splits your shipment, does it charge extra for delivery of the later parts?

� Read the site’s privacy policy. If the text is practically invisible 6-point yellow on white, be suspicious. Look for weasel-words in the clauses that say, for instance, that their policies can be changed at any time without notice. You must check the site regularly to see if the policy has changed, but this is unrealistic. Instead, look for firm, clear assurances that your personal information will not be sold, traded, or given away without your permission. Usually, Website owners state that they may have to divulge information to partnering organizations that handle such normal functions as billing and order fulfillment. There can be little objection to this provided the partners are bound by acceptable security policies.

� Keep a detailed record of your transactions. Use the browser functions to save copies of, or print out, the relevant Web pages with descriptions of the products, prices, a summary of your order, the order number, promised delivery date, and method of shipment.

48.6.9 Online Auctions

� Before becoming involved with online auctions, research the value of goods you are interested in buying. Check bricks-and-mortar stores, online retail outlets, and comparative shopping sites that provide you with specific prices.

� Examine the policies and costs on shipping, warrantees, and refunds. � Set your upper limit before you get involved in an auction. Do not be influenced by the value other people appear to place on a particular product or service, and certainly do not be caught up in a bidding frenzy.

� Do not treat online auctions as a competition you have to win. � Look for auction services that provide a guarantee of support if you are cheated in a transaction. For example, check for language in the terms of service that covers losses up to a suitable limit. Check for insurance policies, costs, terms, and limits. Use search engines to evaluate the trustworthiness of the service you are thinking of using.

� If possible, use a service that provides an escrow function so that you pay money to the service and then release it only when the product is received in good condition.

� Use the browser functions to print documents, and save Web pages to disk at every stage of each transaction.

48.6.10 Online Gambling

� Do not gamble with money you cannot afford to lose. � Do not gamble online, except at well-known sites. � If you do gamble online, do not gamble with money at sites hosted outside your own country.

� Do not give your credit card number to online gambling centers that are outside your own country.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 42 EMAIL AND INTERNET USE POLICIES

� Before you gamble online, do some research to find out if there have been com- plaints about that casino. Contact your Better Business Bureau, or equivalent, and see if you can find friends or acquaintances who have played on the site you are considering.

48.6.11 Preventing Malware Infections

� Keep your virus strings up to date (automatic daily updates are good). � Do not download or use software that purports to help you break the law or cheat people and businesses.

� Do not download or use software that has been copied without permission or in violation of license restrictions. That is software piracy, copyright infringement, or plain theft.

� Do not execute software that anyone sends you through email even if you know and like the person who sent it to you. Just because the person is nice does not mean he or she is qualified to inspect programs for safety.

� Before sending someone an attachment such as a picture or any other kind of file by email, let your recipient know what to expect via a preliminary message; if you do not know the person personally, send an email requesting permission to send the attachment.

� Never open attachments you have received without advance notice, regardless of who sent them or what the subject line or text says. Be especially suspi- cious of generic subjects such as “FYI” without details or “You’ll like this.” If you are really curious about the attachment, phone or email the supposed sender to find out whether it is legitimate. However, remember that you should not run programs you receive as attachments, regardless of what the sender thinks.

� Do not forward programs, even reliable programs, to anyone; instead, tell your friends where to download useful programs from a trustworthy source, such as a legitimate Website.

� Before sending anyone a Microsoft Word document as an attachment, save the document as an RTF file instead of as the usual DOC file. RTF files do not include document macros and therefore cannot carry macroviruses.

� Disable macros in Microsoft Word. � Use the options offered by your email client to shut off automatic opening or execution of attachments.

� Do not circulate virus warnings; if you insist on doing so, personally check their validity on any of a number of virus-information and hoax sites on the Web.

48.6.12 Guarding against Spyware

� Before installing freeware or adware, read the terms and conditions carefully to see if they currently include language permitting automatic transfer of information to the supplier or to third parties. Be aware that these contracts often include language authorizing the supplier to change the terms and conditions at any time and without notifying you.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

RECOMMENDATIONS 48 · 43

� Install and use a spyware scanner and removal program, such as the free Ad-Aware program from Lavasoft, PestPatrol from Computer Associates, or ZoneAlarm firewall.

� If you are particularly irritated by spyware, install a real-time spyware monitor and blocker such as those just mentioned.

� Support legislative attempts to force software manufacturers to disclose their use of spyware.

48.6.13 Junk Email

� Do not buy products or services from anyone who has sent you junk email. If the company is unprofessional or inconsiderate enough to use such methods of advertising, it does not deserve either your business or your trust.

� Do not assume that the FROM address is correct, because often it is either nonex- istent or, worse, fraudulently misrepresents the origin by pointing to a legitimate business that is completely innocent of wrongdoing. Never bombard the owner of a FROM address with multiple copies, or even one copy, of abusive email. Such messages, known as mail-bombs, will probably reach the wrong target—some innocent addressee.

� Never respond to the address listed for removal from an email distribution list unless you initiated the contact or are confident that you know the organization that sent you the message (e.g., publications you already subscribe to). Since bounces (returned email due to bad addresses) never reach them and there is no incremental cost for sending out addresses to unwilling people, these operators really do not care how you feel about the junk they send. Therefore, the unethical people who send junk email use the REMOVE function primarily to harvest correct email addresses so they can sell them to someone else.

� Even if you trust the organization that sent you a junk email, never click on a link contained in the message. Instead, visit the company’s Website and request removal from their official contact address, which any reputable company has.

� Do not visit the URLs listed in junk email messages. Some of them are deliberately mislabeled and may bring you to offensive Websites.

� If you really feel angry about a particular email and it has a dropbox (a real address in the body of the message where you are supposed to reply), then if you have nothing better to do, you may want to send a copy of the spam to the appropriate address (usually in the form [email protected] where you have to fill in the variables ISPname and domain) address running the dropbox. However, the chances are high that your message will be one of hundreds or thousands of similar reports.

� Do not send any junk email yourself. Encourage those around you (friends, neigh- bors, children) not to send junk email either.

48.6.14 Mail Storms. Here are some simple suggestions for reducing the like- lihood of mail storms:

� Minimize the use of automated responses on your email accounts. � If you do autoforward your email, do not let your target mailbox fill up.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 44 EMAIL AND INTERNET USE POLICIES

� If you are receiving autoforwarded email from your primary mailbox, do not autoforward back to the original mailbox.

� Email system administrators should receive exception reports identifying accounts with excessive numbers of email messages or excessive traffic, so that they can investigate for mail storms.

� Firewalls that inspect the content of email messages should be able to react to an excessive number of bounce messages from a single originating address by deleting the traffic or informing the system administrator of a likely mail storm.

� Managers of unmoderated lists should configure a FROM address different from the address that participants use to post messages to the list.

� Users of list servers who want to send personal messages should reply to the sender, not to the entire list.

48.6.15 Detecting Hoaxes. Key indicators that a message is a hoax:

� Use of exclamation marks. No official warning uses them. � Use of lots of uppercase text, typical of youngsters. � Misspellings and bad grammar. � No date of origination or expiration. � Inclusion of words like “yesterday” when there is no date on the message. � References to official-sounding sources such as Microsoft, Computer Incident Advisory Capability (CIAC), Computer Emergency Response Team Coordination Center CERT-CC) but no specific document URLs for details. URLs for a site’s home page do not count.

� No valid digital signature from a known security organization. � Requests to circulate widely. No such request is ever made in official documents. � Claims that someone is counting the number of email messages containing copies of the hoax.

� Threats about dire consequences if someone breaks the chain by refusing to forward the message.

� Claims of monetary rewards that make no sense. For example, the Disney organi- zation will send you $5,000—for forwarding an email message.

� Use of complicated technical language such as “n-th dimensional infinite com- plexity control loops” that do not make sense.

� Claims of damage to computer hardware from viruses or other computer software.

48.6.16 Get-Rich-Quick Schemes

� Remind everyone to use common sense: Earning lots of money with little or no effort usually results in uncovering something impossible or illegal.

� Teach users the mantra of the skeptic: “If it sounds too good to be true, it usually is.”

� Explain how dangerous it is to get involved with criminal schemes like using stolen or falsified credit cards. Talk about the victims of such fraud: everyone who

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

FURTHER READING 48 · 45

pays higher interest rates on unpaid credit card bills and innocent shopkeepers who lose merchandise to e-commerce crooks.

� Especially when talking to children, discuss Internet-mediated theft in the same terms as you discuss shoplifting. Explain how commerce works; point out that everyone suffers from all kinds of theft, including electronic shoplifting.

48.6.17 Hacking

� Contact your local FBI office and find out if they can send a speaker to your com- pany or to a local meeting of a professional security association for a discussion of computer crime.

� If you or specific authorized staff (e.g., from the security group) do visit Websites that support criminal hacking, be sure to use a personal firewall and set the parameters to deny access to personal information and to refuse cookies and active code (ActiveX, Java) from such sites.

48.7 CONCLUDING REMARKS. This chapter focuses specifically on the use and abuse of Internet and email resources. However, it becomes clear that both of these technologies are simply extensions of the human being behind the computer. Whether it is pornography, online gambling, deceitful emails, or simply posting inappropriate material to a public Website, the potential for damage to an individual, family, or organization is high. Taking a proactive stance through education and awareness is one major tool to combat these deceptive and unethical practices.

Employers have an ethical, and in many cases legal, responsibility to develop and implement policies around the appropriate use of the Internet and email at work. Unfortunately, simply putting the policies out for employee consumption is not enough. Employers must continually remind employees about both the dangers of misuse and the potential consequences to their employment. And when an employee chooses to violate the policy, employers must have a clearly defined process for encouraging proper behavior.

The scope of impact for these issues does not simply end when the employees leaves the office. Because of the widespread use of Internet and email into nearly every facet of our lives, taking the message home to the family is an important responsibility for everyone. Child predators use the Internet to prey on unsuspecting or naı̈ve children, in an effort to exploit them for whatever immoral activity they wish. Parents then have an obligation to put their own family policies in place regarding what is, or is not, acceptable use of the Internet and email in the home.

Unfortunately, there is no easy answer to the problems described in this chapter. Both the Internet and email are neither good nor bad. They only become good or bad by the users and their actions. As technology continues to increase in speed, and in the ability to store more data in less space, everyone must take an active role in protecting each other at the corporate level and in the home.

48.8 FURTHER READING Blanpain, R., and M. Van Gestel. Use and Monitoring of Email, Intranet, and Internet

Facilities at Work: Law and Practice. The Hague: Kluwer Law International, 2004.

Cavanaugh, C. Managing Your E-Mail: Thinking Outside the Inbox. Hoboken, NJ: John Wiley & Sons, 2003.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

48 · 46 EMAIL AND INTERNET USE POLICIES

Criddle, L. Look Both Ways: Help Protect Your Family on the Internet. Redmond, WA: Microsoft Press, 2006.

Fraser, J. M. Email Etiquette for Business Success: Use Emotional Intelligence to Communicate Effectively in the Business World. [self-published], 2011.

Flynn, N., and R. Kahn.E-MailRules:ABusinessGuidetoManagingPolicies,Security, and Legal Issues for E-Mail and Digital Communication. New York: AMACOM, 2003.

Goldsmith, J., and T. Wu. Who Controls the Internet? Illusions of a Borderless World. New York: Oxford University Press, 2006.

Holtz, S. Corporate Communications: A Guide to Crafting Effective and Appropriate Internal Communication. New York: AMACOM, 2004.

Jovin, E. Email Etiquette for Business Professionals. New York: Syntaxis Press, 2007. Payne, T. P., and A. Proops. Employee Surveillance. Jordan Publishing, 2013. Spinello, R. A. Regulating Cyberspace: The Policies and Technologies of Control.

Westport, CT: Quorum Books, 2002. Stanton, J. M., and K. R. Stam.TheVisibleEmployee:UsingWorkplaceMonitoringand

Surveillance to Protect Information Assets—Without Compromising Employee Privacy or Trust. Information Today, 2006.

Willard, N. E. Cyberbullying and Cyberthreats: Responding to the Challenge of Online SocialAggression,Threats,andDistress, 2nd ed. Champaign, IL: Research Press, 2007.

48.9 NOTES 1. Parts of this article are based on materials originally published by M. E. Kabay

in a series of articles in his Network World Security Strategies column between 2001 and 2011 and in older writings. To avoid cluttering the text with nonessential endnotes, no quotation marks or references are provided for such material. A complete archive is available. www.mekabay.com/nwss

2. Gaudin, “Insider Threats Giving IT Execs Nightmares,” eSecurityplanet, Novem- ber 4, 2005, www.esecurityplanet.com/prevention/article.php/3561761

3. http://search.dhs.gov/search?query=daily+report&affiliate=dhs 4. J. Leyden, “The Enemy Within: Geeks, Squatters and Saboteurs Threaten Cor-

porate Security,” The Register, December 15, 2005, www.theregister.co.uk/2005/ 12/15/mcafee internal security survey

5. S. Gaudin, “Sarah Palin fans try to rewrite history on Wikipedia: Former governor’s supporters battle with Wikipedia editors over Paul Revere page,” Computerworld, June 6, 2011, www.computerworld.com/s/article/9217359/Sarah Palin fans try to rewrite history on Wikipedia

6. Parker v. C. N. Enterprises Order, District Court of Travis County, Texas. Final Judgment, www.loundy.com/CASES/Parker v CN Enterprises.html

7. Information on the Ponzi scheme is taken from James Trager, The People’s Chronology (Henry Holt & Co. 1995, 1996), made available through the Microsoft Encarta 2007 CD. All rights reserved.

8. C. Tran, “Reading Is Believing.” ScienceNow, July 19, 2005; http://news. sciencemag.org/sciencenow/2005/07/19-01.html

9. A. Hamilton, “Arizona Lottery Pick 3 Random Number Bug,” RISKS Forum Digest 19, No. 83 (1998); http://catless.ncl.ac.uk/Risks/19.83.html=subj5#subj5

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

NOTES 48 · 47

10. E. Werner, “Feds Say Vague Law Makes Ban on Internet Gambling Tough to Enforce,” Associated Press, April 2, 2008; www.sddt.com/News/article.cfm? SourceCode=20080402fac

11. K. Young, “Internet Addiction Test,” Center for Internet Addiction Re- covery, 2008, www.globaladdiction.org/dldocs/GLOBALADDICTION-Scales- InternetAddictionTest.pdf

12. P. Bates and M. Fain, “Cheating 101: Paper Mills and You,” Coastal Carolina University, 2000, www.coastal.edu/library/presentations/papermil.html

13. J. Rush, “Downing St Dossier Plagiarised,” Channel Four News, February 6, 2003, www.channel4.com/news/articles/politics/domestic politics/downing%2Bst%2 Bdossier%2Bplagiarised%2B%2B%2B/253293.html

14. A. Larson, “Sexual Harassment Law,” ExpertLaw, 2003, www.expertlaw.com/ library/employment/sexual harassment.html#FN1

15. M. Potok, “Internet Hate and the Law: The First Amendment Protects Most Hateful Speech on the World Wide Web, but There Are Exceptions,” Southern Poverty Law Center Intelligence Report 97 (Winter 2000), www.splcenter.org/get-informed/ intelligence-report/browse-all-issues/2000/winter/internet-hate-and-the-law

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49CHAPTER

IMPLEMENTING A SECURITY-AWARENESS PROGRAM

K. Rudolph

49.1 INTRODUCTION 49 · 2

49.2 KEY CONCEPTS 49 · 3 49.2.1 Learning Continuum 49·3 49.2.2 Awareness:

Common Sense or Common Knowledge? 49·5

49.2.3 Focus on Behavior 49·6

49.3 CRITICAL SUCCESS FACTORS 49 · 8 49.3.1 Information Security

Policy 49·9 49.3.2 Senior Level

Management Commitment 49·10

49.3.3 Resources with Security, Communications, and Training Expertise 49·11

49.3.4 Visibility, Audience Appeal, and Participation 49·12

49.3.5 Destination and Road Maps 49·13

49.3.6 Common Challenges and Mistakes 49·15

49.4 TOPICS 49 · 17

49.5 TECHNIQUES FOR GETTING AND HOLDING ATTENTION 49 · 18 49.5.1 Images 49·19

49.5.2 Video 49·19 49.5.3 Surprise, Novelty,

and Expectation Failure 49·21

49.5.4 Conversational Style 49·22

49.5.5 Analogies and Examples 49·22

49.5.6 Stories and Empathy 49·23

49.5.7 Currency 49·23 49.5.8 Credibility 49·24 49.5.9 Social Proof 49·25 49.5.10 Accessibility,

Diversity, and Culture 49·26

49.5.11 Spaced Repetition 49·27 49.5.12 Pretest and Refine

Messages and Methods Before Distributing Them 49·27

49.6 TOOLS 49 · 29 49.6.1 Intranet Website 49·29 49.6.2 Social Media and

Crowd Sourcing 49·30 49.6.3 Videos and

Podcasts 49·30 49.6.4 Compliance

Statements 49·30 49.6.5 Sign-on Messages,

Networked Screen Savers 49·31

49.6.6 Publications 49·31 49.6.7 Posters and Digital

Signage 49·31

49 · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 2 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

49.6.8 eLearning Courses 49·31 49.6.9 Classroom Training

and Clickers 49·32 49.6.10 People Penetration

Tests and Spear Phishing Exercises 49·33

49.6.11 Contests and Incentive Prizes 49·34

49.6.12 Awards and Recognition 49·36

49.6.13 Human Libraries 49·37 49.6.14 Volunteer

Activities 49·38

49.6.15 Inspections and Audits 49·38

49.7 EVALUATION AND METRICS 49 · 38 49.7.1 Baseline 49·39 49.7.2 Metrics 49·39

49.8 CONCLUDING REMARKS 49 · 41

49.9 GLOSSARY 49 · 42

49.10 NOTES 49 · 43

49.1 INTRODUCTION. An active security-awareness program is not a luxury: It is a business necessity. Losses from security failures are growing at an increasing rate. Some examples of such failures include:

� A 2012 New Year’s Eve California office building burglary led to the March collapse and bankruptcy of a national medical records firm because it allowed medical records and social security numbers of14,000 people to be exposed1;

� As of March 2012, BlueCross BlueShield had spent $18.5 million resolving a 2009 hard drive heist, not including the value of the data itself2; and

� An attack on Sony’s PlayStation Network exposed personal details of 90,000 customers, which analysts say will cost as much as $2 billion to fix.3

According to the Government Accountability Office, the number of reported security breaches increased from 5,503 in 2006 to 41,776 in 2010, an increase of 650 percent.4

The number of compromised records reported in 2011 was 174 million in Verizon’s 2012 data-breach report.5

Information security is the translation of the instinctive ability to recognize and react to physical threats into an ability to recognize and respond to threats to information assets (e.g., hardware, software, data, and information).

The purpose of an information-security awareness program is to prevent loss and to ensure compliance with laws and regulations. Security awareness helps to instan- tiate security policies—to convert theoretical advice and instructions on protecting information assets into observable, positive behavior.

Information-security awareness leads people to:

� Pay attention to what is happening around them; � Recognize suspicious circumstances that may be security violations; � Know the initial actions to take in response to their suspicions; and � Take the appropriate actions in response (people often know what they should do, but are reluctant to get involved).

Security awareness is the result of activities, tools, and techniques that help a target audience focus on identifying what in their environment has value that must be protected (physical assets such as a laptop or mobile phone and intangibles such as data/information) and what they can do to provide that protection. For a business, the target audience must include owners, employees, contractors, suppliers, partners,

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

KEY CONCEPTS 49 · 3

customers, and any other individuals who have or require access to the organization’s information or information systems. A well-trained workforce is inarguably the most cost-effective security control.

The most important security-awareness messages are:

� What must be protected and why should I care? � Why am I important to security? � What do security incidents look like? � What do I do about security?

Effective awareness programs motivate people, provide measurable benefits, and measure those benefits. Awareness materials must compete to gain people’s attention. They must also be tailored to an audience, their work environment, and the technologies they use to achieve maximum impact. This chapter outlines a practical approach for implementing an effective security-awareness program.

49.2 KEY CONCEPTS. Key concepts for this chapter are that security awareness is part of a learning continuum, awareness relates more to common knowledge than common sense, and effective security awareness focuses on behavior modification.

49.2.1 Learning Continuum. “Information Security Training Requirements: A Role- and Performance-Based Model (Draft),” National Institute of Standards and Technology (NIST) Special Publication (SP) 800-16 Revision 1, addresses security awareness and role-based training. This document defines an information-security learning continuum:

� Awareness, � Awareness training, � Role-based training, and � Education and professional development.6

Awareness applies to all employees whether or not they have access to information systems (e.g., a groundskeeper who notices someone carrying boxes out of the office after hours needs to recognize that he or she may be witnessing a security incident and must know how to report the potential incident). Awareness training addresses security basics and literacy, and serves as a transition from awareness to role-based training.

SP 800-16 REV1 states:

Awareness training strives to build in an organization’s information system user population a foundation of information-security terms and concepts upon which later role-based training, if required, can be based. Awareness training informs users of the threats and vulnerabilities that impact their organization and personal work environments by explaining the “what” but not the “how” of security, and communicating what is and what is not allowed. Awareness training not only communicates information-security policies and procedures that need to be followed, but also provides the foundation for any sanctions and disciplinary actions imposed for noncompliance. Awareness training is used to explain the rules of behavior for using a department’s or agency’s information systems and information and establishes a level of expectation on the acceptable use of the information and information systems.7

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 4 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

Awareness programs, as used in this chapter, include the first two levels of the continuum: awareness and basics and literacy. Awareness intends to focus attention on security. Awareness sets the stage for additional learning by changing individual perceptions and organizational culture so that security is recognized as critical and necessary. Security failures can keep individuals from successfully completing their work and can threaten organizational survival. Security-awareness activities have the following characteristics:

� Learning tends to be short term, immediate, and specific. � Learners are information recipients. � Learning can occur at the same time everywhere throughout an organization, and it can be continuous.

� Awareness activities are directed at broad audiences with attractive, attention- getting techniques, similar to those used in advertising and cause-marketing.

Basics and literacy applies to workers who use an organization’s computers or access nonpublic information. Basics and literacy should direct the workforce regarding compliance with security controls and appropriate responses to attacks in process. Characteristics of basics and literacy are:

� Basics and literacy activities are more formal than awareness activities. The pur- pose of basics and literacy is to build knowledge and to change attitudes. Specif- ically, these activities “promote personal responsibility and positive behavioral change throughout an organization’s information and information system user population, beyond what is disseminated in the organization’s basic awareness efforts.”8

� Basics and literacy activities use a variety of techniques to address different learning personalities and styles.

� Basics and literacy activities often include a course or presentation and a statement of acceptance of responsibilities.

� Basics and literacy activities typically start with an employee orientation, usually completed before the employee is placed in a work environment.

� Basics and literacy activities include periodic refresher activities on at least an annual schedule.

Awareness materials are generally broad in coverage, but limited in depth (that is, awareness covers a lot of ground, but does not dig very deep holes). Role-based training and education and professional development apply to staff with significant security-related roles or functions, including:

� Executives, such as the chief information officer (CIO) and the chief information security officer (CISO)

� Information system security officers (ISSOs) and staff � Program and functional managers (e.g., system owners, information owners, net- work administrators, system administrators, security administrators)

� Application designers and developers

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

KEY CONCEPTS 49 · 5

Role-based training takes longer than awareness, and involves establishing and enhancing skills and competency for those involved in functional specialties (e.g., management, systems design, and acquisition). Training is provided selectively based on an individual’s job functions (roles) and is most effective when tailored to the business environment. Education and professional development are appropriate for those pursuing a security career, and include college-level courses and professional certifications, such as the Certified Information Systems Security Professional (CISSP) and the Certified Data Protection (CDP) specialist. Role-based training and education and professional development are beyond the scope of this chapter.

49.2.2 Awareness: Common Sense or Common Knowledge? Ira Winkler, president of the Internet Security Advisors Group, writes, “The fundamental issue is that of common sense vs. common knowledge. You cannot expect people to behave with common sense if they do not have a common knowledge.”9 Consider the following security-awareness messages. Are the messages below common sense?

� Do not share your password � Do not discuss sensitive or protected information in public � Create long, strong passwords � Report actual or suspected incidents � Delete email chain messages

Some would say that these messages are nothing but common sense. If these se- curity messages are common sense, then why do we need to publish tips telling people not to share their passwords, not to let others tailgate into secure work areas, and not to talk about sensitive information in public? Perhaps these messages are “common sense waiting to happen.” Or, possibly, these are common-sense items only within a particular environment or background, such as individuals who are computer literate.

In 2007, IRS workers familiar with the policy of not sharing passwords, disclosed their passwords because they did not understand that changing their password to one provided by a caller was the same as disclosing it.10An IRS audit group, posing as computer help desk staff, called 102 IRS employees asking each to help them “correct a computer problem” by providing their user name and temporarily changing their password to one the caller suggested.

� Sixty-one of the 102 employees did as requested. � Managers were more lax than nonmanagers. � A follow-up survey asking why the employees gave up their passwords so easily found that about one-third believed what they had been told by the unknown caller.

� Ten percent believed that changing their password was not the same as disclosing it, which they knew was against the rules.11

The 10 percent of respondents who did not recognize their actions as disclosure demonstrate a need for improved security-awareness activities. While most (but un- fortunately not all) security professionals know to never change their password to one that someone else knows, this principle is not common knowledge among all computer

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 6 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

users. “When there are widespread problems, there is clearly a failure in how the se- curity community is delivering the message.”12 An awareness program should instill common knowledge, and by using material that grabs attention and maintains interest, transform that common knowledge into common sense.

49.2.3 Focus on Behavior. An organization’s workforce is generally among the first to be affected by a security incident. Their compliance with security policy can make or break a security program. A staff that is security-aware can detect and prevent many incidents and mitigate damage when incidents do occur. Thus, the need for awareness programs that focus on behaviors.

The need to focus on behaviors is critical, especially with younger workers. “Seven out of ten young employees who are aware of their companies’ IT policies acknowledge breaking those rules with varying regularity, according to a Cisco survey of more than 2,800 college students and young professionals in 14 countries.”13

The most common reasons for this are:

� The employees’ belief that they aren’t doing anything wrong (33 percent) � The need to access unauthorized applications for their jobs (22 percent) � Lack of enforcement (19 percent) � Lack of time to think about policies (18 percent) � Inconvenience of adhering to policies (16 percent) � Forgetting to follow policies (15 percent)

Nearly two-thirds (61 percent) said that the responsibility for protecting information and devices is on IT or service providers and not on individual employees. As this example illustrates, security is too important to sacrifice to the status quo.

Security-related behaviors can be classed as good, bad, or ugly14: Good behavior complies with the letter of the law or better, the spirit of the law; bad behavior in- cludes naı̈ve mistakes or dangerous tinkering for example, sharing a password, writing a packet-spoofing application to test one’s programming ability, or scanning the orga- nization network to see how it works; and ugly behavior consists of intentional misuse or destruction for example, building script that disables other users’ terminal sessions, forging email header information, using a file decryption program to access trade secrets without authorization, or introducing a Trojan horse program into the network.

Within an organization, good security behaviors include compliance with security policy, such as:

� Releasing nonpublic information only with appropriate authorization � Promptly reporting a potential security vulnerability such as a lost mobile device � Politely terminating and then reporting a suspected social engineering attempt � Creating and using strong, unique passwords for critical systems

Bad security typically experienced includes:

� Sharing passwords � Deploying a wireless network gateway that allows noncompany personnel to use the company’s network

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

KEY CONCEPTS 49 · 7

� Setting up a packet-spoofing application to test the user’s programming ability � Setting up a network monitoring scanner on the user’s PC

Ugly security behaviors include intentional misuse such as:

� Building a script to disable other users’ terminal sessions � Forging email header information � Intentionally introducing malicious code into the organization computing infras- tructure

� Using someone else’s email to send messages

Behaviors directly affect the ability of the organization to meet its business objec- tives. Good behaviors promote business objectives and allow resources to be focused on achieving organizational goals (e.g., improved profitability and reduced costs). Bad and ugly behaviors result in wasted resources and loss of workforce focus on business objectives (that is, increased costs and reduced performance). Bad and ugly behaviors, carried to their extreme, can result in organizational failure (e.g., intentionally compro- mising customer financial records could result in a financial liability so large that the company goes bankrupt). Exhibits 49.1 and 49.2 illustrate a table showing measurable end user security behaviors, whether the behaviors are good, bad, or ugly, and how they could be measured.

Effective security-awareness programs encourage people to treat mistakes as “portals of discovery” where they can learn how to avoid similar mistakes. Employees should recognize that it is in everyone’s best interest to limit damage from a mistake and, more importantly, to learn from it, and report it quickly rather than fixing it quietly. Mistakes often have side effects, and pretending that a mistake didn’t happen is dangerous. In a Harvard Business Review interview, former Toyota chairman Katsuaki Watanabe said, “Hidden problems are the ones that become serious threats eventually. If problems are revealed for everyone to see, I will feel reassured. Because once problems have been visualized, even if our people didn’t notice them earlier, they will rack their brains to find solutions to them.”15 Sharing what you learned can prevent loss. In her research on learning in hospitals, Amy Edmondson of Harvard University discovered that the highest-performing nursing units had reported the largest number of mistakes. Not because they made more mistakes, but because they felt safe to report and share the ones they did make.16 Learning the cause and how to avoid mistakes is vital to security.

Technologists typically try to control workforce behaviors by adding layers of technical controls. As demonstrated by the increasing number of reported information compromises, technological approaches alone cannot solve a people problem. The workforce needs access to data and computing functions to do their job. Technology cannot effectively distinguish between the instances when an individual employs a capability they are authorized to use to accommodate a good behavior versus a bad behavior. Technology cannot adequately address the human factor of intent.

The rise of mobile computing in the work environment has brought increased impor- tance to the human factor. The network perimeter now extends from a defined physical area to wherever data might be at any given time (e.g., an employee’s home, a laptop at an offsite meeting). Building good computing habits at home is as important, if not more important, than building those behaviors at work. Secure computing habits will

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 8 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

Security Awareness Program Metrics

Internal User Behaviors

Examples to be tailored should be based on goals and then questions. G

· B

· U

*

S u

rv e y

O b

s e

rv a

ti o

n

H e

lp d

e s

k

In c

id . R

p ts

M a

n u

a l T e

s ts

o r

A u

d it

s

S o

ft w

a re

(A u

to m

a te

d )

% of users recognizing a security event scenario G

B

B

B

BU

B

B

B

BU

B

B

B

B

B

B

B

B

G

B

% of users susceptible to social engineering (compare mid-week at mid-day to Friday afternoon)

% of users revealing their password when tested

% of users activating a “test virus”

% of security incidents having human behavior as a major factor/involving behaviors covered in awareness materials

Storage of unauthorized file content on desktop or network resources, such as audio, video, or other multimedia files

Number of attempts to access inappropriate/blocked Websites

Nonpublic information found in dumpsters outside of facilities

% of systems having unapproved software installed

% of systems having unapproved hardware installed

% of emails (random sample) with inappropriate content

% of passwords visible or in common locations (e.g., under lamp)

% of PCs logged on and unattended

% of laptops, portable devices/media, sensitive data unsecured

% of laptops, portable devices/media, stolen (office/travel)

Number of attempts to use unauthorized resources, e.g., VPN

% of emails sent via Internet containing nonpublic/sensitive data that are not encrypted

% of users wearing badges with picture facing out

% of monitors positioned to be easily seen from hallways, doors, or windows (especially on the ground floor)

EXHIBIT 49.1 Awareness Metrics, continued as Exhibit 49.2

transfer across environments, as individuals recognize good behaviors are beneficial to them regardless of whether they are at home or at work.

49.3 CRITICAL SUCCESS FACTORS. Critical success factors for implementing a security-awareness program include:

� An information security policy � Senior-level management commitment and buy-in, to demonstrate the importance of security

� Resources with subject matter, communications, and training expertise

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

CRITICAL SUCCESS FACTORS 49 · 9

Security Awareness Program Metrics

Internal User Behaviors

Examples to be tailored should be based on goals and then questions. S

u rv

e y

O b

s e

rv a

ti o

n

H e

lp d

e s

k

In c

id . R

p ts

M a

n u

a l T e

s ts

o r

A u

d it

s

S o

ft w

a re

(A u

to m

a te

d )

G

B

B

B

B

B

B

U

B

G

B

G

G

% of users activating a “test virus”

% of users who click a link in a test email (instead of typing the URL into their browsers)

% of users responding to a test email via an “unsubscribe” link

% of crackable user passwords

% of user systems having spyware or malware installed

Number of incidents of unauthorized use of administrator privileges

% of users sending Internet email to multiple recipients who do not use the BCC field

% who have actively acknowledged policies/security responsibilities

Number of major findings from internal and external security audits

% viewing optional security materials in online courses

% participating in contests, suggestion programs, bonus questions

*G·B·U = Good, Bad, or Ugly G: Good behavior complies with the ‘letter or the law’ or better, the ‘spirit of the law,’ e.g., not releasing nonpublic information inappropriately, discovering and reporting a security vulnerability. B: Bad behavior includes naïve mistakes or dangerous tinkering — e.g., sharing a password, deploying a wireless network gateway that allows noncompany personnel to use the company’s network, setting up a packet spoofing application to test one’s programming ability, or setting up a network monitoring scanner on one’s PC. U: Ugly behavior consists of detrimental mususe or intentional destruction — e.g., someone builds a special script that disabled other users’ terminal sessions, forges email header information to make it look like someone else sent a message, uses a file decryption program to discover the contents of a file containing trade secrets, or intentionally introduces a Trojan horse program into the network.

(Behavior categories inspired by “Analysis of End User Security Behaviors” - by Jeffrey M. Stanton, Kathryn R. Stam, Paul Mastrangelo, and Jeffrey Jolton, July 12, 2004.)

% of users who challenge unknown visitor with no access badge

% of users who open a test email with a questionable subject

G · B

· U

*

EXHIBIT 49.2 Awareness Metrics, continued from Exhibit 49.1

� Visibility, audience appeal, and participation to address all subgroups within the workforce

� Destinations and road maps to guide and monitor program activities

49.3.1 Information Security Policy. Effective information security policies are in-place, credible, comprehensive, and current. Security objectives must be em- bodied in policies that clarify and document management’s intentions and concerns. Policies are an organization’s laws. They set expectations for employee performance and guide behaviors. Information security policies include statements of goals and re- sponsibilities, and delineate what activities are allowed, what activities are not allowed, and what penalties may be imposed for failure to comply.

Effective information security policies show that management expects a focus on se- curity. Well-defined security policies show what is expected of the workforce and make

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 10 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

it easier to take disciplinary action against those who ignore policy and compromise security.

A cohesive security-awareness policy provides credibility and visibility to the information-security program. It shows that management recognizes that security is important and that individuals should and will be held accountable for their actions. As Daryl White, chief information officer for the U.S. Department of the Interior, said, “You can’t hold firewalls and intrusion detection systems accountable; you can only hold people accountable.”17 Credibility also requires that management back employees who do the right thing.

An awareness policy should address three basic concepts:

1. Participation in the awareness program is required for everyone, including senior management, part-time and full-time staff, new hires, contractors, and other outsiders who have access to the organization’s information systems. New hires might be required to receive a security-awareness orientation briefing within a specific time (e.g., 30 days after hire) or before being allowed system access. Existing employees might be required to attend an awareness activity or take a course within one month of program initiation, and periodically thereafter (e.g., semiannually or annually).

2. Everyone will be given sufficient time to participate in awareness activities. In many organizations, security policy also requires that employees sign a statement indicating that they understand the material presented and will comply with security policies.

3. Responsibility for conducting awareness program activities is assigned. The program might be created and implemented by one or a combination of: the training department, and the security staff, or an outside organization, consultant, or security-awareness specialist.

49.3.2 Senior Level Management Commitment. Senior management must be committed to information security and visibly demonstrate that commitment by example (e.g., signing the awareness program or activity launch announcement, par- ticipating in awareness activities), providing an adequate budget, and supporting the security staff. Saying security is important but failing to follow organizational policies will have negative consequences.

Executives set the standard for organizational behavior. For example, in Colombia, when there was a water shortage, the mayor of Bogotá, Antanas Mockus, appeared on television programs taking a shower and turning off the water as he soaped, asking his fellow citizens to do the same. In just two months people were using 14 percent less water, a savings that increased when people realized how much money they were also saving because of economic incentives approved by Mockus. Water use is now 40 percent less than before the shortage.18

Organizational leaders must understand and support the program as well as provide oversight. Program responsibility has shifted in recent years from a collateral duty of a compliance or information-security officer to the highest levels of the organization.

Poor security measures can be costly in damage to the organization’s brand or reputation, in impact on operations, and in actual and potential lawsuits. The media will not hesitate to report a security threat or breach. Such stories are a wake-up call and highlight the need for senior executive commitment to the security function.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

CRITICAL SUCCESS FACTORS 49 · 11

Wise senior managers know that security is not just about reducing risk, it’s also a tool to protect the organization’s reputation. It also builds customer confidence and market valuations, and delivers a competitive edge. In today’s e-commerce environ- ment, effective information security can increase business and profits. Top management should understand that security is not solely a risk avoidance measure and should see the security-awareness program as a business enabler.19

Senior-management compliance provides credibility. If security policy prohibits installation of personal software on organization infrastructure, even senior executives must comply. Doing otherwise undermines the policy and creates a perception of inconsistence, unfairness, or unimportance. Senior managers must stand behind the organization’s policies and the security staff charged with enforcing those policies. Consistent enforcement is especially important in areas where security and convenience conflict, such as changing passwords frequently or enforcing denial of system access for users who have not completed a required awareness refresher activity. In addition, human beings tend to imitate those with higher social status, so executives who see their superiors refusing to wear name badges will soon be doing the same—and the breach of security policy will propagate downward through the entire organization.20

Implementing an awareness program is always a management challenge. Senior managers generally appear to recognize the benefits of an awareness program, but are often still reluctant to allocate the financial and staff resources necessary to make it effective. Awareness programs must compete against other organizational needs. It is relatively easy to identify the cost of an awareness program, but it is difficult to quantify its benefits. Thus, awareness programs often lose when competing against programs where benefits are more tangible (e.g., programs that return a profit). The difficulty in quantifying benefits is a primary reason why the U.S. Government made maintenance of a computer security-awareness program mandatory for federal organizations21 and why security awareness is required by laws and regulation in specific industries such as finance and healthcare.

Management resistance is often tied to viewing security awareness as “nice to have” but not as important as other needs vying for limited funds. Although the time and effort to build a strong security program is not trivial, it is far less than the time and effort required to deal with just one serious incident. Some security professionals recommend equating awareness with insurance policies. Insurance policies require continuous funding but are not often used (and the hope is not to use them); however, few organizations choose to forego those costs.

When common sense and fiduciary responsibilities are not enough, legal require- ments provide another incentive for awareness programs. The Federal Information Security Management Act and the Computer Security Act require such programs for federal organizations. State and federal laws (e.g., the Sarbanes-Oxley Act and the Gramm-Leach-Bliley Act for financial information, and the Health Insurance Porta- bility and Accountability Act for healthcare information) require security-awareness components in information-security programs for state agencies and public companies. Requirements to maintain effective security programs are also included in state and federal contracts that impact critical infrastructures (e.g., healthcare, public safety) and contracts that require retention of sensitive customer information.22

49.3.3 Resources with Security, Communications, and Training Ex- pertise. Ideally, responsibility for an awareness program should be assigned to one individual who has a defined budget and has security subject matter expertise, com- munications skills (such as marketing), and knowledge of training principles. This

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 12 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

individual should be a member of senior management and performance of the aware- ness program should be a factor in his or her performance evaluation. Program activities and materials may be created and deployed by one or more individuals drawn from internal or external resources.

The mix of skills needed to successfully maintain a security-awareness program include:

1. Subject matter expertise—Individuals attempting to infuse security awareness into the business processes should be knowledgeable of those business processes. This ensures that awareness messages support the business and are delivered using terminology and content that are accurate and aligned with other organizational initiatives and activities (e.g., a professional security certification is valuable when working with a technical audience to establish credibility).

2. Communications expertise—Awareness activities often require translation of technical, security-oriented information into tips, discussions, presentations, posters, job aids, and other tools that average computer users can understand and apply in their daily work. Communications skills facilitate development of these awareness materials.

3. Training expertise—Training is its own discipline. People learn in different ways. Knowledge of training techniques, how people learn, and how to match training techniques to learning styles will improve the potential success of an awareness program.

The awareness team also needs to include an individual with deep information se- curity experience. This individual serves to validate material for the general workforce and to help avoid the curse of knowledge. Once we know something—say, the melody of a song—we find it hard to imagine not knowing it. Our knowledge has metaphor- ically cursed us. We have difficulty sharing our own knowledge because we cannot readily relate to our audience’s state of mind.23

The curse of knowledge was identified in a 1990 study by Elizabeth Newton, a graduate student at Stanford University. Study participants were divided into two groups: tappers and listeners. The experimenters chose 120 well-known songs such as “Happy Birthday” and the tappers tapped out the rhythm on a table while the listeners tried to guess the song. Before they started, the tappers were asked to predict listener success. Most predicted about 50 percent. The actual success ratio was 2.5 percent. The tappers conveyed the message successfully one time in 40, but thought that they would get the message across one time in two. This discrepancy resulted from the fact that the tappers hear the tune internally while they tap, but the listeners only hear what sounds like random taps.24

49.3.4 Visibility, Audience Appeal, and Participation. An effective awareness program cultivates a professional, positive, and visible image. A visible program demonstrates the value of the awareness activities, raises employee morale, and encourages the support of the general workforce. The more methods used to spread the message, the more visible the program. An awareness program that uses computer- based courses, videos, posters, acknowledgment statements, newsletters, contests, events, daily tips, and checklists will reach more people and have a greater impact than a program that consists of posting security policies to the organization’s intranet and sending a memo advising staff to read the policies.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

CRITICAL SUCCESS FACTORS 49 · 13

Everyone should receive sufficient time to participate in awareness activities; this includes those who are responsible for planning and developing awareness activities. These activities should occur on compensated time. Organizations that require em- ployees to only obtain or develop security awareness and training on their own time effectively state that security is not important.

Security-awareness programs that show the organization’s concern for employees’ IT security well-being at home (for telecommuters and others who use computers at home) and while traveling are better received than programs that ignore such issues. Practical topics that cross between home and office might include “what to do if your Twitter account is hacked,” “how to use Apple iOS5 securely,” or “how to protect your personal email account.” Whether the target audience is all end users or senior management, showing them how they will personally benefit from improved security awareness contributes to program success. Viewing security as a service, with the entire organization as a customer, highlights the importance of marketing security to management and staff.

Computer behaviors and habits from home transfer to work. Security professional Donna Mattick put it this way,

Just knowing that my elderly relatives are using the Internet causes me to stay up at night worrying, but it also drives me to find ways to protect them automatically. On the other end of the scale, I have a teenage daughter who has an iPad, cell phone, and exposure to computers at school. She can find a way around every protection measure I put in place. So I have to stay current to keep up with her. … Children, parents, and elders all need to be cyberaware and we security professionals need to step up and help. For every person we educate how to stay safe we chip away at the criminals’ ability to take advantage of us.25

49.3.5 Destination and Road Maps. When a psychologist was invited to give a talk at the Pentagon on managing time and resources, he decided to warm up the group of generals with a short exercise. He asked them all to write a summary of their strategic approach in no more than 25 words. The exercise stumped most of them. The only general who managed a response was one who had worked her way through the ranks and been wounded in combat in Iraq. Her approach was as follows: “First I make a list of priorities: one, two, three, and so on. Then I cross out everything from three down.”26

Create a security-awareness program plan that contains these elements:

� A description of the organization and its IT culture (culture is the instinctive behavior of individuals within an organization), including assigned roles and responsibilities

� Program goals and the status of the organization’s current efforts with a security baseline

� A determination of awareness needs by audience � A description of methods and materials to be acquired, created, and/or modified � A schedule showing actions to be completed and who is responsible for ensuring their completion (including program evaluation and updates)

49.3.5.1 Goals. A security-awareness program should have goals and a plan for achieving the goals that includes measureable criteria. The goals and objec- tives should be related to improvements in workforce performance and security

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 14 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

risk. For example, the following might be appropriate goals for a security-awareness program:

� Improve employees’ ability to recognize potential threats and vulnerabilities � Improve the level of compliance with company physical and computer security controls

� Reduce the occurrence of security failures resulting from employee action or inaction

� Reduce the severity of the security incidents that do occur

Specific, realistic, and measurable goals are best. If possible, establish a baseline prior to implementing your awareness program or launching a new campaign. A base- line defines where the organization stands with regard to its security-awareness efforts and program. It may be that the baseline is zero and a program has not been imple- mented. In that case, the organization may take a survey to find out how people in the organization view security and how familiar they are with security policies. The results of the survey would become the baseline. Where a program has been implemented, the organization may choose to document the level of awareness so that over time, other measurements can be taken to show changes.

Victor Basili of the University of Maryland developed an approach for metrics where the metric is created as the final step of a process called Goal-Question-Metric.27 He recommends defining a goal, for example: “Goal—decrease inappropriate Website visits.” Next, create a question that will indicate whether the goal is being met or not: “Are staff continuing to visit Websites that they should not?” Then, and only then, create a metric that will support the goal. The metric would be the number of attempts to access inappropriate Websites, such as illegal or pornographic material. This information can be extracted from Web filtering products. This approach offers several benefits:

� It leads to an automated metric � The information for the metric is easy to collect � The metric will give a constantly updated idea of what the organization’s users are doing

49.3.5.2 Audiences and Messages. Awareness programs need to be planned to ensure they address the intended target audience in the appropriate manner. If you are directing your message to your total workforce, then you should consider consultants, contractors, subcontractors, vendors, suppliers, and other third parties. When your audience is employees, don’t forget temporary hires and interns. If you divide your audience by technical skill, you can provide detailed information to your technical staff and less detail to your clerical staff.

Once you decide on your audience and how to segment that audience, you can develop messages and delivery methods specific to each segment. The following are audience breakdowns for a typical business:

� Executives—are generally interested in return on investment and risk reduction, have a moderate level of technical literacy, and are key targets for spear phishing and social engineering.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

CRITICAL SUCCESS FACTORS 49 · 15

� Information technology staff—should be interested in building security into applications, networks, and systems, should have specific security responsibilities, and are expected to have moderate to high computer literacy.

� Business users—primarily focus on getting the business process completed re- gardless of the security impact. They can be easily frustrated when security controls are time consuming or inhibit “real work,” but they can be motivated when they can see the benefits to themselves and their families, and will respond positively once they understand the value of security controls, especially if they handle sensitive or protected customer data.

� New hires—for those for whom this is their first “real” job, awareness will need to focus on the fundamentals (what needs protection, from whom or what, why they should care, and what is their role in the organization). For new hires who have been in the job market, awareness messages generally need to focus on how security is addressed in this organization.

� Mobile device and smart phone users—often associate risk with the smallness and low cost of the device instead of the adverse impact their compromise or loss could have on themselves as well as on the company.

� People who travel—whether they travel locally or abroad, travelers have removed themselves and their computer devices from the friendly surroundings of the office and home. An unattended device, in a hotel room, in the trunk of a car, or even at airport screening, is an invitation for theft and data compromise.

These messages should be delivered using a mix of tools (e.g., posters, screen savers, presentations, events, computer-based courseware, classroom training, and one-on-one training). The more times the same message is delivered using different approaches, the greater the likelihood the information will be retained.

49.3.5.3 Methods and Frequency. Some companies use a perpetual calen- dar for their security program. The calendar is used to create a communications plan that covers the type and frequency of message by audience. A calendar-oriented plan shows what security-awareness materials and activities are produced monthly, quar- terly, or annually. Calendars need to be periodically updated to add special events, such as security-awareness days or weeks.

A security-awareness program should be an ongoing effort. Some organizations offer a security-awareness orientation to new employees and regular reinforcement for all employees at various times throughout the year. Doing so provides spaced repetition of the material, and reinforces learning. Some organizations address security aware- ness on a monthly basis with newsletters, posters, screen savers, contests, surveys, and online modules. Other organizations offer awareness courses that are updated annually and provide reinforcement at various times, such as on November 30, International Computer Security Awareness Day. NIST SP 800-50, “Building an Information Tech- nology Security Awareness and Training Program”28 presents a detailed approach for establishing and maintaining a security-awareness program, including an appendix with a sample awareness program plan template.

49.3.6 Common Challenges and Mistakes. Awareness program planning should consider common obstacles and constraints such as keeping management in- formed, changing material language to relevant business terminology, gaining union support, and overcoming audience resistance. The program should also be structured

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 16 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

to address significant, but less recognized challenges of diffusion of responsibility (where a person is less likely to act when others are present because they assume that others will take action or have already done so); and attenuation (when a message loses its strength and the learners tune out, usually because the message has been reused, overused, or doesn’t capture the student’s interest). Wildlife managers describe attenuation as “getting used to something we shouldn’t.” They say: “A fed bear is a dead bear.”29 When bears in parks get used to campers and carelessly stored food, they adapt, resulting in dangerous encounters or mailings and the destruction of the bear. Bad things can happen when your awareness messages lose their signal strength.

A common mistake is not fitting the program to the environment. Build an awareness program around your business environment. If you take materials from other organi- zations, be sure to tailor the content to your environment and target audience. Free training materials can have significant costs in terms of wasted audience time and can increase security risks by providing a false sense of security if the training doesn’t meet your program objectives.

Security program planners often overlook the learners. This typically occurs because those charged with planning and building the program were selected for their technical competence, but have limited experience in selecting learning methods and techniques. Programs that don’t consider the learner often fail. Learners should be able to relate to the awareness materials and apply the materials to their jobs.30

Joseph A. Grau, former chief of the Information Security Division at the Depart- ment of Defense Security Institute, believed in the importance of marketing security and often stated that customers actually pay for security services. For example, man- agers pay for enforcing the requirement to lock a classified document in a safe rather than leaving it on a desk, with labor hours. Other methods of payment are in the form of energy, attention, and concern for security matters, such as taking time to identify and report a potential security incident. Even egos are part of the payment for security. There is an “ego cost” when “scientists, researchers, technical specialists, engineers, and management personnel must refrain from communicating their suc- cesses to friends, family, and peers to protect sensitive, company private or classified information.”31

Be sure that your awareness program plan clearly defines your objective (how to know when you are successful) and how you can monitor your progress toward your stated objective. Successful performance is always easier to achieve when you have a road map or plan that tells you where you are, where you are going, and how to tell that you have reached your destination. Abraham Lincoln related planning to sharpening an ax. If he was asked to cut down a tree in eight hours, he would spend the first six sharpening his ax. It takes great effort to chop down a tree with a dull ax, but cutting a tree down with a sharp ax goes much more quickly. Similarly it is much harder to create, manage, and measure the effect of an unplanned awareness program than a planned program with defined objectives, assigned responsibilities, and management direction.

Careful planning promotes awareness activities that elicit specific, positive re- sponses. Flexible plans allow timely changes to address changes in the organizational structure, objectives, new technologies, and applicable threats and vulnerabilities. Flex- ibility also allows incorporation of relevant current events, events that use external sources to emphasize your security message. Microsoft’s policy of issuing awards for help in capturing virus writers is evidence that security issues are now getting high-level attention.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TOPICS 49 · 17

49.4 TOPICS. In planning an awareness program, you should have an under- standing of the topics that you want to address. NIST SP 800-16, “Information Security Training Requirements: A Role- and Performance-Based Model (Draft),” identifies the following security-awareness topics:

� Roles and responsibilities in information security � Ways to protect shared data (e.g., encryption, backups) � Examples of internal and external threats (e.g., social engineering, hackers) � Malicious code (e.g., viruses, worms) � Security controls � Ways to recognize an information-security incident � Principles of information security � Passwords � Social engineering � Data backup and storage � Computer viruses and worms � Incident response � Personal use and gain � Privacy � Personally identifiable information (PII) � Identity theft � Internet surfing � Inventory control � Physical security � Spyware � Phishing � Scams and spam � Mobile devices (e.g., laptops, smartphones, tablet computers) � Portable storage devices (e.g., CDs, USB drives) � Remote access � Copyright infringement and software piracy � Use and abuse of email � Email do’s and don’ts � Peer-to-peer file sharing threats � National security information systems, where applicable32

Although these topics may not be directly relevant to a specific organization, they do provide a catalog to which you can add or subtract based on your industry, technology, and assets that need protection. For example, healthcare providers should address personal health information (PHI), both paper and electronic (ePHI); organizations that accept credit cards should include topics linked to the Payment Card Industry Data

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 18 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

Security Standards (PCI DSS); and organizations that deal extensively with intellectual property (IP) should consider adding topics that include advanced persistent threats (APT) and related social engineering techniques.

Exploiting technology weaknesses to gain financial reward is a significant threat, but less obvious data thefts can cause substantial harm to your organization’s reputation and require significant clean-up costs. Identity theft can affect organizations as well as individuals, and stealing the ideas for a new marketing program or product can damage a firm’s ability to effectively compete for new business.

Including the impact of data theft is a key topic in your awareness list. The impact of data theft was often not well understood, even though it could result in a firm’s bankruptcy. It wasn’t too long ago that a court held that a data theft could not be prosecuted because nothing was actually taken. Today’s judges are more knowledgeable and recognize that the knowledge the data conveys (e.g., a person’s identity) can be more damaging than stealing a person’s money. Linking your awareness messages to impact on the organization is an effective approach to explaining impact and increasing acceptance of your security message.

Another way to identify appropriate topics is to ask managers, helpdesk, and incident response personnel to identify recurring problems or review the problem reports to identify recurring issues. Awareness topics can then be structured to help resolve these problems by surfacing their cause and how to avoid them. Also, topics that are of personal relevance are good for gaining attention. Data mining, mobile device location awareness, cyberbullying, identity theft, travel precautions, and the latest frauds, scams, and malware are of interest to most computer users.

49.5 TECHNIQUES FOR GETTING AND HOLDING ATTENTION.

If you want to build a ship, don’t drum up the men to gather wood, divide the work, and give orders. Instead, teach them to yearn for the vast and endless sea.33

—Antoine de Saint-Exupery

If you want to secure information and computer systems, don’t dictate orders or make commandments for employees to follow. Teach them why they are crucial to the security process. Learning methods that are interactive, demonstrative, and rewarding get the most attention. Work with the brain to capture and maintain attention. Before you can teach your audience anything, you must have their attention. The strongest messages have a visual and visceral impact and use images, surprise, novelty, emotional involvement, and empathy.

Most of the events that predict whether something learned will also be remembered occur in the first few seconds of learning. The more elaborately we encode a memory during its initial moments, the stronger it will be.34

Emotional context plays a large role in memory retention. Emotional arousal helps the brain learn. People remember things that they feel, such as empathy when they learn about a person who accidentally reformatted a hard drive and did not have a backup. (Are my files backed up? Could I accidentally reformat my disk?) Other feelings that awareness program materials and events can convey include surprise, curiosity, and satisfaction (e.g., correctly answering a difficult quiz question or solving a security puzzle). Scenarios are a good way to create empathy because they allow choice of action to be directly associated with consequences.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TECHNIQUES FOR GETTING AND HOLDING ATTENTION 49 · 19

Anything that increases brain activity causes deeper learning. The more different types of brain activity involved, the better the results of the awareness program. In short, design and implement awareness activities and messages that use as much of the brain (especially both sides) as possible.

49.5.1 Images. “We do not see with our eyes. We see with our brains.”35 Half the brain is set up for visual processing. The more visual the input, the more likely it is to be remembered and recalled. This phenomenon is called the Pictorial Superiority Effect (PSE). The potency of the PSE was described definitively in 1976 by neuroscientist Douglas Nelson. “He and others have shown that our brains are essentially hard-wired for visuals—the very architecture of our visual cortex allows graphics a unique mainline into our consciousness.”36 People pay attention to color, size, and orientation. People pay special attention to objects that are moving. This is why animations (e.g., our computer game-oriented culture) are so effective.

Imagery stimulates both verbal and visual representations. Language is primarily processed through only the verbal channel. Experiments have shown that imagery activates multiple, powerful neural pathways of memory recall. While our access to raw information has grown, our time to process this information has declined (we are reduced to communicating in sound bites and 140 character Tweets). This places a premium on meaning-making. Given our brain’s preference for the visual and the current complexity of our world, “we’ve learned that the very best shortcuts usually come in graphical form … consequently, today’s visual storytellers have considerable power.”37

Graphics that incorporate the message in the image (e.g., speech boxes) are more effective than graphics that described the message or image in an accompanying narra- tive or that have the message as a caption or title below the image. Exhibit 49.3 shows two images of a vulnerability caused by a modem. Learners were observed to glance at the first one for a short period of time and many “tuned it out.” When the speech boxes were added, learners looked at the image longer and expressed excitement, saying, “Oh, I get it. The modem goes around the firewall and circumvents the control.”

49.5.2 Video. While some educational professionals say the future of online learning is gamification38 (learning through games), video is arguably the future of online security awareness. YouTube is the second most popular search engine online—today. Humanity watches more than 80 million hours of YouTube every day, according to Chris Anderson, TED39 founder. Our brains are wired for video more that print. Video offers a greater density of information. Anderson points out that print and reading are relatively new compared to face to face communication. Print was scalable, which was an advantage that has been overtaken by video. Anderson’s TED talk ad- dressed crowd-accelerated innovation and learning where cycles of improvement are driven by people watching Web video. He uses the examples of street dancers and TED talks. As a result of being able to see what others in their fields are doing, people are stepping up their game. Anderson identified three concepts that fuel accelerated learning and performance:

1. A crowd, such as a global Internet community—the bigger the crowd, the more potential innovators there are, as well as commenters, trendspotters, cheerleaders, skeptics, mavericks, and super-spreaders. These people are creating the ecosystem through which innovation emerges.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 20 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

EXHIBIT 49.3

2. Light, clear, open visibility of what the best are doing—this empowers others to participate. A light shines on the innovators, either directly through comments, ratings, email, Facebook, and Twitter, or indirectly through numbers of views and links (that point Google there).

3. Desire for social status—where the best walks tall and is recognized—“You might just be a kid with a Webcam, but if you can do something that goes viral, you can be seen by the equivalent of sports stadiums crammed with people.” This global recognition drives huge amounts of effort. The light and desire are self-fueling and attract new people to the crowd.40

Here’s an example of how well video can work for security awareness described by Chip and Dan Heath. Russ Berland was tasked with redesigning BearingPoint’s ethics and compliance training program. He inherited a code of conduct which might have

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TECHNIQUES FOR GETTING AND HOLDING ATTENTION 49 · 21

been repurposed from a law firm. A principal challenge was the need to influence the behavior of employees across the country, operating in different organizational cultures. Berland interviewed associates about real-world “gray areas” and uncovered dramatic stories of strained relationships and ethical quandaries. This inspired his team to create a humorous fictional series based on The Office featuring a fictional company designed to be the “evil doppelganger” of BearingPoint. The fictional company, Aggrieva, used the motto: “Aggrieva says yes when everyone else says no.” Berland hired a film maker and shot 10 short episodes over a weekend. The films included topics such as bosses “hitting on” subordinates, teams misrepresenting their expertise, and managers trying to pass along inappropriate expenses to the client.

The episodes created a sensation and employees said that this was the best train- ing they had ever had. The characters and situations became part of the company’s vocabulary. “New episodes debuted each Monday, but employees were so ravenous for the next episode that they started tracking them down on the company’s staging server, where the videos were posted on the preceding Friday. Thousands of employees watched the videos before they were released.”41

The videos started conversations about ethics and compliance, and after the videos aired more people called the hotline to discuss difficult topics and situations. The videos were so well-received that people chose to watch them. Awareness programs should aim to create or locate materials so engaging that people are eager to watch.

49.5.3 Surprise, Novelty, and Expectation Failure. Vital information about potential threats and resources is likelier to be identified from things that are new or unfamiliar. Nature ensures that all living creatures react to novelty and change because novelty and change often results in danger. A swerving car on the highway, a jump in your bad cholesterol, or a drop in a stock’s value rivets your attention and jangles your nerves, events which prime you to protect yourself from harm. Basically, our brains are surprise detectors.42

Use surprise and expectation failure to deepen security-awareness experiences. Hu- mans crave novelty from evolution and for survival and will respond to the unique and unusual. Anything that is counter-expectational will tweak the arousal–adaptation cycle.

Ask questions such as, “Did You Know?” Ask learners with mobile phones how long their data (multimedia pieces of communication like photos, videos, and texts) is stored by their cell phone network provider and if their data can be sold to third parties. Not many people know that nearly four years’ worth of their digital identity is stored by AT&T, which holds the data for 84 months. Verizon holds this data for 12 months, Sprint for 24 months, and T-Mobile for 60 months. “28,000 MMS messages are sent into the world every second, and cell phone companies record much of the metadata that travels with them, like location, receiver identity, amount of data transferred, and the cost of the transmission. The average user has 736 pieces of this personal data collected every day.”43

Another innovative idea from the mayor of Bogotá, Antanas Mockus, was to use mimes to improve both traffic and citizens’ behavior. Initially, 20 professional mimes shadowed pedestrians who didn’t follow crossing rules: A pedestrian running across the road would be tracked by a mime who mocked his every move. Mimes also poked fun at reckless drivers. The program was so popular that another 400 people were trained as mimes.44 What would happen if mimes followed people in your organization around their offices for a day and mocked people who talked about sensitive information in public areas or left their computers logged on while they were away from their desks?

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 22 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

Social psychologist Robert Cialdini states, “Mysteries are powerful because they create a need for closure.”45 Mysteries exist wherever there are questions without obvious answers. “Why do criminals attack personal home computers?” “How was the source of the cyberattacks on Estonia discovered?” “What does the encrypted message in this week’s security awareness contest say?”

Another way to maintain interest is to pose a question or puzzle that confronts people with a gap in their knowledge. As part of a security-awareness program, newsletters, an intranet site, posters, and online courses can ask challenging quiz questions. This creates two knowledge gaps: “What’s the correct answer?” and “Was I right?” Providing hints and clues for more difficult security-awareness questions or contests also helps to maintain interest. Remember, the objective is to make people think about the problem, not to guess a single right answer.

Note: Don’t expect people to remember much about security from an initiation day presentation when all stimuli are new.

49.5.4 Conversational Style. Use a conversational and personal style. A con- versational style is useful because “people tend to pay more attention when they per- ceive that they’re in conversation, since they’re expected to follow along and hold up their end.” The brain does this even when the learner is reading (e.g., the conversation is between the learner and a book, magazine, Website, or an eLearning module).46

First- and second-person constructions (involving “I,” “we,” and “you”) create a feeling of conversation between the content and the reader. In five out of five studies performed in 2000, students who received material with personalized, conversational text performed better on subsequent transfer tests than those who learned with formal text.47 Studies found that “students performed up to forty percent better on post-learning tests if the content spoke directly to the reader using a first person, conversational style rather than taking a formal tone.”48

In addition, Dr. Roger Schank, author and expert in workplace learning, states that conversation is a form of learning by doing.49

49.5.5 Analogies and Examples. To better engage people with a new topic, start by highlighting things that the audience already knows. As an example, your target audience may know that the Storm worm was widely spread malicious code, but they may not know that the controlling computer changes the malicious code it sends every 30 minutes, or that the Storm worm contained new defensive techniques that shut down the efforts of researchers who were attempting to learn more about it. Use analogies and examples to tie ideas your audience knows to what you want them to learn:

� Backups are like flossing—everyone knows it’s important, but few devote enough thought or energy to it.

� A dynamic IP address is like moving your house several times a day so that burglars can’t find it.

� Sensitive information is like prescription medicine: it should be used only by those who need it and are authorized to have it; it should not be transferred, sold, or given to people who are not authorized to have it (this is illegal and penalties apply); it can cause damage if given to people who are not authorized to have it.50

� Passwords are like bubble gum; strongest when fresh; should be used by an individual and not a group; and if laying around, will create a sticky mess.51

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TECHNIQUES FOR GETTING AND HOLDING ATTENTION 49 · 23

49.5.6 Stories and Empathy. The number-one story commandment, accord- ing to Pixar is: “Make me care.”52 Include stories in awareness materials to increase people’s attention and retention. Stories energize powers of recall and communicate priorities effectively. Stories are powerful because they provide the content missing from abstract prose. Stories captivate people. They survive the test of time, and they become part of the popular culture. Audiences are typically more receptive to someone who tells stories than to someone who lectures.

Relating a story is different from making a reasoned argument because the way the message is delivered determines how the audience will react. When the audience hears an argument, they evaluate it and usually argue back, even if only in their minds. Stories engage the audience and involve people with the idea. When an audience hears a story, they are likely to think of similar situations that they have experienced. Stories can suggest a course of action to someone who is at a decision-making point.

Stories should be about situations that are realistic and related to the lives of the learners; otherwise, stories may backfire and cause a loss of credibility. The stories should relate to situations and decisions the audience may face. Stories about hackers accessing medical records would be useful to organizations that process medical data, whereas stories about fraud or identity theft would be of interest to personnel involved in the financial industry or the accounting function of an organization.

Effective security-awareness stories are short (a few paragraphs), have two or three characters at the most, and have a singular message. Stories that show more than one point of view increase retention because the brain is tuned to learn more deeply when it is forced to make evaluations and judgments. Stories should contain a surprising element and they must be true. Lack of credibility in a story is a single point of failure.

Stories about real people and real consequences (people being praised, disciplined, or fired) are useful in presentations and courses. Sources of stories include individuals who have been with the organization for a long time and have a “corporate memory,” news events, Internet special interest bulletin boards, and security personnel who attend special interest group meetings and conferences.

Organizations should collect stories about security incidents, security heroes, mis- takes made, and lessons learned. Having a story collection prepared allows for quick response to trigger events, such as when an incident similar to ones from the story collection occurs at the organization. “The secret is to gather, gather, gather—and do it in advance of any pressing need. … Gather things that get a response in you. … Anything that displays or evokes energy. Storage is cheap.”53

49.5.7 Currency. Awareness material must be fresh and current. Chef Oscar Gizelt of Delmonico’s Restaurant in New York said, “Fish should smell like the tide. Once they smell like fish, it’s too late.” If awareness material is not changed frequently, it too begins to smell old and becomes boring.

Take advantage of circumstances. Prepare material to be ready to launch a campaign alerting people to respond quickly after a disaster or major news event. For example, after a disaster such as the tsunami in Japan there are always scams and malware that use sensational news headlines to entice potential victims to click on links to sites that contain drive-by malware.

Another idea is to prepare messages in advance for specific times of the year. Novem- ber 30 is International Computer Security Day. In October, educate about scareware. During the holiday season in November and December, laptop and mobile-device theft peaks, so offer tips on securing mobile devices. For tax time, offer tips about keeping

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 24 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

track of your credit and information regarding fraud resolution specialists to contact for victims of fraud (e.g., remind staff that if the IRS wants more information from them, they will receive a letter, not an email. When an email claims to be from the IRS, it’s best not to click on any links—and to report it to [email protected]).

Current events can be an excellent source of material and can add credibility to an awareness program. Review current news reports for events that can be used to emphasize security messages. For example, newscasters who make statements when they do not know that their microphones are live or a show on the impact of ID theft can provide good examples for use in an awareness program. Also, several Internet security and technology sites offer subscriptions to electronic security alerts and news clippings. One of the more useful newsletters reporting on information-security breaches is from INFOWAR.54 Some organizations have established a news-hawk program, in which rewards are given to the first employee to bring in a new relevant story that can be used as part of the awareness program. This is also a good technique to gain buy-in from the end user community.

One of the best times to raise awareness is right after a breach at the organization or at a similar organization (one in the same industry, in the same location, or using the same technology). The news is full of stories about information security and data breaches.

49.5.8 Credibility. Credibility is crucial for an awareness program. The message must be clear, relevant, and appropriate to the real world. If the audience is required to use 15 different passwords as a part of day-to-day functions, prohibiting them from writing their passwords may not be as realistic as providing strategies for protecting the written list.

Show consequences. Some organizations send memos to all staff that describe specific examples of personnel who have violated policy. The memos cover a set time period (e.g., the previous quarter) and include the number of individuals, the nature of the violations, and the penalties, such as loss of Internet privileges or leave without pay, displayed in dollars, and based on the average salary.

While all messages should have a call to action, credible messages avoid fear, uncertainty, and doubt (FUD). FUD isn’t the best choice for communication, and it will backfire if the material creates a scare and then doesn’t offer a practical solution.

Comedian Chris Bliss explains why FUD doesn’t work:

A great piece of comedy is a verbal magic trick… there’s this mental delight that’s followed by the physical response of laughter, which, not coincidentally, releases endorphins in the brain. And just like that, you’ve been seduced into a different way of looking at something because the endorphins have brought down your defenses. This is the exact opposite of the way that anger and fear and panic, all of the flight-or-fight responses, operate. Flight-or-fight releases adrenalin, which throws our walls up sky-high. And the comedy comes along, dealing with a lot of the same areas where our defenses are the strongest—race, religion, politics, sexuality—only by approaching them through humor instead of adrenalin, we get endorphins and the alchemy of laughter turns our walls into windows, revealing a fresh and unexpected point of view.55

The use of appropriate humor such as the advertising technique of exaggerated consequences works because humor is a door into the serious. To spoof the popular advertisements that show a chain reaction of consequences, you could do a similar ad that says:

1. If you don’t teach your employees about security awareness, they will post their vacation plans on social media sites.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TECHNIQUES FOR GETTING AND HOLDING ATTENTION 49 · 25

2. If your employees post their vacation plans on social media sites, the bad guys will know when your employees aren’t home.

3. If the bad guys know when your employees aren’t home, the bad guys will clean them out.

4. If your employees’ homes are cleaned out, they will come to work naked. 5. Don’t let your employees come to work naked.

Another point that Chris Bliss makes is that comedy is a powerful way to commu- nicate because it’s inherently viral; people can’t wait to pass along a great new joke. He adds, “But it’s when you put all of these elements together—when you get the viral appeal of a great joke with a powerful punch line that’s crafted from honesty and integrity, it can have a real world impact at changing a conversation.”56

49.5.9 Social Proof. Robert B. Cialdini is considered an expert on influence. He studies and writes about the science of persuasion. He describes a common mistake that causes messages to self-destruct. It’s the story of a former graduate student who had visited the Petrified Forest National Park in Arizona with his fiancée. At the park’s entrance a sign stated, “Your heritage is being vandalized every day by theft losses of petrified wood of 14 tons a year, mostly a small piece at a time.” The student was shocked when after reading the sign, his normally ultra-honest fiancée whispered, “We’d better get ours now.”57

This incident inspired Cialdini and his colleagues to design an experiment where they posted two different signs. One used the concept of “negative social proof.” It read, “Many past visitors have removed the petrified wood from the park, changing the natural state of the Petrified Forest.” That sign also showed a picture of several visitors taking pieces of wood. The experiments placed a second sign to simply convey that stealing wood was not appropriate. The second sign said, “Please don’t remove the petrified wood from the park, in order to preserve the natural state of the Petrified Forest.” The accompanying image showed a lone visitor stealing a piece of wood, covered by the universal “No” symbol of a red circle with a slash through it.

The experimenters placed marked pieces of wood along various pathways and observed how the signs affected the rate of theft. They switched the signs at the entrance to the pathways, and they also used pathways with no signs posted as a control condition. The results:

� Where there was no sign, 3 percent of the wood pieces were stolen. Where the social proof sign (stating that many visitors had removed wood) was posted, the theft rate increased to 8 percent. Where the sign asked people not to steal the wood and depicted a single thief, the theft rate decreased to 1.7 percent.

� Put simply, social proof refers to our tendency to go along with the crowd and follow the most popular course of action. We do things that we see other people like us doing.

� Using negative social proof, for example, communicating the popularity of an undesirable behavior, focuses the audience on the prevalence, rather than the undesirability, of the behavior.

� The authors recommended that the park management reframe the statistics to focus attention on the number of people who respect the park’s rules, which turned out to be more than 97 percent.58

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 26 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

Here’s an example of how to apply this to security awareness. Todd Snapp, President of RocketReady, speaks to audiences about the human side of security. He often asks the audience to guess the most common passwords that his team of penetration testers finds in organizations where the passwords requirements include using characters from at least three sets (e.g., uppercase, lowercase, and numbers) and the passwords had to be changed every 90 days.

Audience members usually call out with guesses, but they rarely guess the answer. When Todd tells them, there is usually a collective groan and head slap as audience wonders why such a simple and retrospectively obvious answer didn’t occur to them.

The answer? The season and the year: Fall2011, Winter2011, or Spring2012. One way to present this information would be to start with “Did You Know? The

most common passwords we find are…” This approach would catch attention, but it would also convey the wrong message. Despite the implied disapproval of choosing passwords that are easy to guess, the message is that such behavior is common. Putting the information out in a neutral way would act as strong social proof that many people just like the audience choose these easily guessed passwords.

A better way to present the information would be to advise people not to choose the season and year for passwords and to focus their attention on a positive behavior (e.g., use an image showing people who had chosen strong passwords speaking disapprov- ingly of a person in the organization who used the season and year). This makes it clear that people who use weak passwords are in the minority and have the disapproval of their co-workers. The take-away is that it’s more effective to emphasize the deviance, not the popularity, of insecure behavior.59

49.5.10 Accessibility, Diversity, and Culture. Effective awareness materi- als are accessible, diverse, and culture specific. Guidelines for creating Web pages that are accessible to people with vision or hearing impairments are published by the World Wide Web Consortium (W3C). To be accessible, the Web pages should not rely on vision or sound alone to impart meaning; for example, all graphics should be labeled with text that explains the graphic, and the contrast between the text and the background should be maximized.60 An alternative is to create and maintain two versions of an online course.

Accessible content is easy to understand. Check written program materials for ease of reading and understanding with Flesch–Kincaid readability levels or the Gunning Fog Index. Some word processors have the ability to perform two Flesch–Kincaid readability tests to indicate how difficult a passage is to read. The Flesch Reading Ease and the Flesch–Kincaid Grade Level use the same core measures (word length and sentence length), but different weighting factors. A text with a comparatively high score on the Reading Ease test should have a lower score on the Grade Level test.61

The Gunning Fog Index measures the readability of English writing. The index estimates the years of formal education needed to understand the text on a first reading. A Fog Index of 12 requires the reading level of a U.S. high school senior (around 18 years old). The Fog Index is commonly used to confirm that text can be read easily by the intended audience. Texts for a wide audience generally need a Fog Index less than 12. Awareness material requiring near-universal understanding should have an Index less than 8.62

Diversity is important to address cultural and other differences among staff. Aware- ness materials should suit the culture of the organization. Images of people in awareness materials should show different genders and races, with the subjects dressed similarly to the way that people within the organization dress. People relate to pictures of other

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TECHNIQUES FOR GETTING AND HOLDING ATTENTION 49 · 27

people who are similar to themselves. In a global awareness program, language and cultural differences should be addressed. Materials should avoid the use of local idioms such as (in the United States), “In a nutshell.”

Awareness materials designed for use in an Islamic country might address differences in techniques used by social engineers. For example, high-pressure techniques (as are often used in America) would likely be counterproductive in an Islamic culture. Instead, social engineers are likely to concentrate on the techniques that emphasize trust and relationship building. Also, since many social engineers are most active when they expect the target company to have fewer resources, instead of noting that an attack is most likely on a Friday afternoon (as in the United States), the materials should note that attacks are most likely on Thursday afternoons and that organizations might receive a higher volume of social engineering calls during Ramadan or around the Eids when the organization may have fewer staff available.

Awareness materials designed for Japan might address threats that are targeted to the Japanese culture, where privacy, reputation, family, and a desire to stay out of trouble, such as the “It’s me, It’s me” fraud where a young-sounding person calls a senior and claims to be in trouble and need money to avoid a scandal, and the “One click contract” fraud, where a Website visitor to a dating or pornography site receives the message that by clicking on the previous page they have entered a contract and must now deposit money into a specified account to avoid fines or scandal. By keeping the amount affordable (e.g., the equivalent of about $100 U.S. dollars), many Japanese people simply make the deposit to avoid the potential trouble.63

When designing material for a company in Qatar, which has a rich history and industry of pearl diving, a memorable approach is to use a pearl to illustrate the value of data. Exhibit 49.4 shows a poster image of an oyster with a data disc in place of the pearl with the caption, “How Valuable Is Your Data?”

49.5.11 Spaced Repetition. The technique of spaced repetition was identified by Hermann Ebbinghaus about a hundred years ago. He observed that learning and memory are the strongest if you spread the repetition of information over a long period of time—for example, days, weeks, and months. He also proposed a “forgetting curve,” which are like radioactive half-lives: Each review of the information to be learned increases memory in strength by about 50 percent, but immediate review does not increase memory very much because the memory hasn’t decayed much.64

A meta-analysis in 1999 suggested that those who learn information by spaced repetition will outperform 67 percent of those who learn by mass presentation given the same number of practice episodes. This varies according to the “nature of the task being practiced, the inter-trial time interval, and the interaction between these two variables.”65

For awareness, this means exposure to awareness once a year likely not enough to effect behavior changes. For awareness, a best practice is to follow John Medina’s Brain Rules: “Repeat to remember” and “Remember to repeat.”

49.5.12 Pretest and Refine Messages and Methods Before Distribut- ing Them. Pretest and refine materials before distributing them. Pretesting provides evidence that materials are reaching your target audience with the intended message. It can also avoid embarrassing situations, such as occur after distributing a poster on which punctuation or the lack of punctuation changes the message (e.g., “Slow Work Zone” instead of “Slow, Work Zone”).

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 28 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

EXHIBIT 49.4 “How Valuable Is Your Data?”

Pretesting may be accomplished using focus groups, providing materials to a single unit within the organization, or through group or individual interviews. All evaluations should include a set of multiple-choice or ranking questions with one or two open- ended questions. This analysis approach facilitates data comparison and aggregation. The question set should be structured to determine the message received and the level of experience (novice, beginner, user, power user) required to understand the material. The questions should also be structured to avoid leading the respondent. A

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TOOLS 49 · 29

useful approach for coordinating input from larger focus groups is Computer-Aided ConsensusTM, which uses a shared spreadsheet to identify hidden assumptions and divergent values among the respondents.66

49.6 TOOLS. When choosing tools to convey an awareness message, address these questions:

1. What tools are most appropriate for the message? 2. What methods are most likely to be credible to and accessible by the target

audience?

3. Which methods (and how many methods) are feasible, considering the available budget and the time frame?

4. How often should each method and messages be delivered?

Use as many methods and tools as possible, with a consistent message, to reinforce the material and increase the likelihood that the audience will be exposed to it often enough and long enough to absorb it. Some methods are suited to daily updates, such as tips or questions of the day. Some material, such as simplified policies, frequently asked questions (FAQs), and incident reporting information will be received best if it’s available on demand and just in time when needed. Newsletters are best received monthly or quarterly. Online courses can be provided monthly (short content pieces or modules), quarterly, biannually, or annually. Regular updates to content on an intranet Website, including contests, will drive repeat visits and increase awareness; stale information will lose viewers.

49.6.1 Intranet Website. An intranet Website focused on security can contain checklists (e.g., what to post on social media, how to protect mobile devices, how to manage privacy on Facebook), one-line policies (the most important concept of each policy distilled to a single line) linked to full policies, identify–react charts, and interactive technologies such as password visualizers that illustrate the relationships of your passwords and password strength meters.

Security-awareness activities that use the Internet or an intranet offer the advantages of ease of use, scalability (can be used for various audience sizes and in distributed locations), accountability (can capture use statistics, quiz or test scoring, and other metrics), accommodation of individual learning rates, and even interaction among members of a community or among students and instructors.

Websites (public or private) can be used in these ways:

� As a research tool for gathering information � To present policies and other documents � To post alerts � To collect data for security-awareness surveys or incident reporting � For self-assessments to identify at-risk security practices � For anonymous reporting of security concerns � For Webcasts of security conferences or presentations

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 30 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

49.6.2 Social Media and Crowd Sourcing. Use social marketing tech- niques such as Twitter and social networking, email, daily tips, questions, contests, surveys, and suggestion programs that help achieve buy-in. Your social media strategy can be used to push and pull. Use social media as a channel for delivering messages to an audience as a push. Use social media as a way to listen and learn and to create relationships as a pull. Test and learn. Focus on understanding, run experiments (for new benefits and services) and analyze the results (for audience engagement). Where traditional companies push out messages and products, these companies pull customers in. Instead of treating customers as passive targets, they treat them as active participants. Like the sun in a solar system, they create a gravitational field that pulls customers into their orbit. They go beyond customer loyalty to building customer gravity.67

If your organization is a nonprofit, you can use virtual volunteers to help with your awareness program. One example is Sparked.com, a micro-volunteering network, in which nonprofits post challenges to the network and volunteers respond with ideas. Challenges range from requesting user input on a logo to creating promotional materi- als. This brings together the talents and ideas of many to find a single solution, and gives nonprofits a way to get valuable work for free. Volunteers might design newsletters, illustrate online courses, or create Website pages. Volunteers search for opportunities by skill, interest area, development topic, or geographic region.

49.6.3 Videos and Podcasts. Videos can be delivered on DVDs, VHS tapes, CD-ROMs, or over the Web in various formats including podcasts (videos formatted to play on iPods or other portable media players). Most security-awareness videos are less than 20 minutes long. They can be used at orientation briefings and brown- bag lunches for staff where popcorn can be provided in bags preprinted with security messages. Videos are useful starting points for discussions and for briefings. They provide a consistent message throughout the organization and can be shown to staff at distributed locations, saving instructor travel time and costs. They can also be used to demonstrate cost effectively the impact of security failures, such as a fire at a data center or how sensitive data were found in the trash. Security-awareness videos are available commercially for various fees and from the U.S. Government often at no charge or for a nominal fee.

Produce awareness videos in digital format in segments that allow for updates as the environment or organizational needs change.

49.6.4 Compliance Statements. Compliance statements and policy reading sign-offs are among the most effective security-awareness offerings. After computer- based instruction, according to the Security-Awareness Index report, the most effective methods were:

� Tracking whether workers read policies or not � Requiring a compliance statement � Requiring full-time employees (FTEs) to read policies � Making policies available in electronic format � Require workers to read policies annually � Requiring a compliance statement prior to issuing a user ID68

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TOOLS 49 · 31

49.6.5 Sign-on Messages, Networked Screen Savers. With some sys- tems, it is possible to add a text message to the log-on or sign-on screen. These messages should be short, to the point, and changed frequently.

Screen savers are a graphic form of communication and should be eye-catching for maximum impact. Involving a professional artist will improve message delivery. Screen savers should contain contact information for the organization’s security and incident-handling functions. Animations or trivia questions and answers may make the screen saver more interesting. Screen savers should be updated periodically to keep the message fresh. Commercially produced security screen savers are available, as are screen savers that can be easily tailored to deliver a security message.

Software programs such as BroadcastIT offer a centrally managed screen saver that can show images and videos. This software updates in the background and doesn’t require much space.

49.6.6 Publications. Publications, such as newsletters, brochures, pamphlets, comic books, tip sheets, identify and react sheets (documents that list signs of an incident and steps for the end user to take), whitepapers, and checklists of behaviors organized by topic, can be targeted to specific audiences. They may be security focused or may be generalized publications that contain articles on security-related events or items of interest. Newsletters should be short, one to two pages, tailored to the organization’s industry or business. Newsletters should use attention-getting graphics, headlines, and white space to appeal to readers. Audience interaction can be generated by encouraging questions, answered in future newsletters, or by including contests, inviting readers to submit news items, tips, trivia, or reviews of security books or products.

49.6.7 Posters and Digital Signage. A poster series with themes or related designs can be used to highlight specific security issues. A poster should be colorful, present a single message or idea, and include a “call to action.” Using a professional artist to design the posters will increase their impact. Posters should be larger than standard letter size to stand out and gain attention. They should be changed or rotated regularly and placed at eye level in multiple locations. Posters can be printed on both sides of the paper, saving paper and shipping costs for organizations with multiple locations. Signs can make a difference in behavior. In Kenya, inexpensive messages urging minibus passengers to heckle and criticize their drivers for being reckless caused a 50–60 percent reduction in insurance claims involving injury or death. The stickers had messages such as “Don’t just sit there as he drives dangerously! Stand up. Speak up. Now!” and were illustrated with severed feet and legs. Drivers were given incentives to leave the stickers in place. The messages encouraging passengers to speak up were placed in a random sample of over 1,000 long-distance Kenyan minibuses. In those buses, insurance claims fell by a half to two-thirds, from 10 to less than 5 percent annually. “Results of a driver survey eight months into the intervention indicated that passenger heckling contributed to the safety”69 improvement.

49.6.8 eLearning Courses. Web-based awareness courses are useful for geo- graphically dispersed staff members and staff who need to take training at a time that is convenient for them (e.g., after normal work hours). Web-based courses are espe- cially well suited for use by individuals who have diverse backgrounds and different

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 32 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

technology experience levels. Online courses offer the following advantages over tra- ditional place-based, classroom training:

� Feedback—Feedback is essential to motivation and performance. Feedback is immediate, so learners do not build on early misunderstandings. Well-designed Web-based training takes cultural and personality differences into account and reassures timid trainees while allowing more confident ones to progress at a faster pace. “Why,” “How,” “Show me an example,” and “Give me an alternative” buttons or links can be used to let learners with different needs and personalities use the course to learn in ways that are comfortable for them.

� User convenience—Web-based awareness courses are convenient for the learners because they can be taken at any time. Those with variable or hectic schedules can arrange to take the course after hours or whenever they have a convenient time in their schedule.

� Nonthreatening—Web-based courses allow users to make mistakes and learn from them in a safe, nonthreatening environment.

� Flexibility—Web-based courses are flexible and can be customized to accommo- date learners with different levels of experience and different interests. By placing detailed information in subordinate, linked pages, users are able to choose between the “need-to-know” main pages and the “nice-to-know” hyperlinked pages.

� Web-based courses can reduce costs and training time. Placing updates to courses on the Web eliminates the work involved with distributing the current version and materials to multiple locations. This can be more efficient and consistent because the content has been reviewed, edited, and tested to make it clear and concise. Courseware can also be directly linked to specific organizational policies and procedures.

� Web-based courses are self-paced, so that more experienced users can race through without getting bored while novice users can ponder and explore.

A potential problem to watch for in Web-based courses is the tendency to get lost in the technology. Just because an awareness course could have three dozen animated, singing computers decorating the pages does not mean that it should. The technology must be used appropriately; bigger buildings do not make better scholars, and more impressive technology does not necessarily result in a better learning experience. A Web-based course that is overloaded with animations and graphics that do not relate to course content or that has a poorly designed user interface will lose user acceptance.

49.6.9 Classroom Training and Clickers. A study by the European Net- work and Information Security Agency (ENISA) found that:

The most effective technique has been face-to-face time with staff through workshops and training sessions. Being able to put a face to a name or function is more personable and people are more receptive to messages being face-to-face. The training is mandatory. Senior management actively supports the awareness schemes, making sure that training events are at convenient times for the business and promoting them to staff. There is good attendance at sessions since missing the events results in escalation to the employee’s manager. This senior management support across the business has proved to be critical to the success of the awareness program.70

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TOOLS 49 · 33

A downside to in-person, instructor-led training is cost. Instructor-led training must have an audience that is collocated. Instructor-led training is not cost effective for orga- nizations with a large, distributed workforce—unless they have an in-place audio/visual conference capability.

Use audience response systems (e.g., clickers) to enhance feedback and audience interaction. Audience response systems can be used to take attendance, instant polls, and multiple-choice tests. You can also use the devices to survey audience awareness of security topics and instantly show the correct answers and a response breakdown. Clickers allow online crowdsourcing for offline crowds. These devices have a fun factor and have been described as “efficient, eco-friendly and techno-tickling.” Clickers allow audiences to participate in the same way as TV game-show contestants and help shy people “speak up.” Professor James Katz, Director of the Center for Mobile Communication Studies at Rutgers said: “If people feel their opinions really count, they’ll be happy and likely to give more opinions.”71 With the prevalence of cell phones, text messages can now be used for in-class responses.

49.6.10 People Penetration Tests and Spear Phishing Exercises. Demonstrations of penetration tests and spear phishing exercises are a good way to generate interest in security among the technical staff and power users. You can also incorporate vendors and other business partners into internal tests to evaluate and strengthen your organization’s ability to respond to a cyberattack. Consulting firms may offer social engineering and penetration testing includes email phishing tests and phone calls from social engineers. The goals are to test employees’ awareness of fraud- ulent email messages and incident response effectiveness. It must be made clear that penetration tests are intended as training exercises, not as employee evaluations.

You can also test awareness by checking the strength of passwords or simulating social engineering attacks to gauge responses. You can develop penetration exercises internally or acquire external support. Products such as Metasploit, Core Impact, and Canvass can be used to simulate a wide range of vulnerability tests, including email and Web phishing exercises. Before conducting any phishing or other vulnerability exercise, obtain permission in writing (often termed Rules of Engagement). Without permission, such activities may be considered hacking, even when performed by security personnel as part of an awareness exercise.

All testing works best when in support of defined policies and procedures. The same is true of penetration exercises. A well-designed test will include techniques for recognizing an attack as well as remedial actions that “victims” of an attack should take (e.g., reporting spear phishing attacks to organization security).

Testing can provide an estimate of the likelihood that a member of your workforce will:

� Click on an embedded hyperlink in a suspect email message, � Enter Social Security numbers, � Open an attachment without checking to see if it might include malware, � Verify their network account, � Register at an unknown site to download a whitepaper and receive a free product, or

� Download a suspicious file.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 34 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

After the exercise, collect follow-up information by sending a message to recipients for feedback asking, “Why did you click or not click” or other questions to assess their thought processes.

Metrics to evaluate testing might include:

� Emails that were deleted and not read, � Email forwarded to security personnel, � Reports as spam, � Emails that were read, � Replies to email, � Forwards to colleagues, � “Victims” who clicked on the link, and � “Victims” who provided personal information.

Real-world simulation exercises add to but do not replace traditional awareness techniques. Classroom instruction can explain and describe attack approaches, but exercises provide students with a “touch, feel, and experience” that expands their understanding of security attack approaches and aids in content retention. The goal of a security-awareness exercise is to make security a natural concern within the organization, campus, or university. Periodic security-awareness exercises will help minimize network downtime and maximize network performance as students become more judicious about handling emails.72

49.6.11 Contests and Incentive Prizes. Contests, incentive prizes, rewards, and giveaways help achieve buy-in. People like to win and most love a good contest. A contest can be a simple prize draw or a competition with rules for entry and criteria for winning.

Contests can be used to ask questions, collect data, conduct research, inspire ideas, or drive traffic to your security Website. The 3 Ps of contests are:

� Planning. Decide on the goal of your contest, then create a theme. Establish clear rules, including entry procedures and criteria for judging competition entries. You may need to consider your country or state-specific regulations (e.g., some contests and competitions may require a permit, if open to the public and the competition is a random chance draw).

� Prizes. Prizes can be anything from bragging rights to security-themed DVDs (such as Catch Me If You Can or Swordfish) or books (such as The Cuckoos’ Egg by Clifford Stoll, Kingpin by Kevin Poulsen, or The Lure by Steve Schroeder) to cash awards, lunch with a senior executive, or time off. At presentations, speakers can tape prizes or awards under seats in the front row to encourage people to come early and sit up front.

Prizes don’t have to be expensive to be valuable to your audience. Time off, lunch with the boss, gift certificates, shredders, security-themed T-shirts, mugs, certificates, and trophies all work. Shiny prizes, such as the latest technology (e.g., an iPad) or money, have mass appeal. You may want to poll your audience to find out what would be valuable to them. The prize might be intangible (e.g., an honor, such as announcing the winner in the organization newsletter).

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TOOLS 49 · 35

� Promotion. Announce your contest with email, posts on the security intranet site, and posters. Also, if it’s a public contest, consider tweeting it, enlisting coworkers to help spread the word, putting links to the contest on the organization’s Facebook Page, and writing press releases.

If you run the contest on social media, such as Facebook, Twitter, or Google+, use applications (many are available) to help administer the contest. To win, people may simply have to follow, retweet, or answer trivia questions. This type of campaign is often successful because of the ease of entry. Your security “brand” will benefit from the increased engagement.

Here are some contest ideas:

� What’s That Number? Post a number that relates to security and have people guess how the number relates to security. The number might be the number of password reset requests the helpdesk receives in a week, the number of malware- infested sites blocked by the corporate firewall, or the number of records ex- posed or dollars lost as a result of a breach experienced by a company in your industry.

� Catch the Red Team. A red team is a group of individuals assigned to test the security of an organization. Staff are told that a red team will be testing security (e.g., making social engineering calls). Staff members who catch the red team and report the potential security violations win a prize. Often, these contests result in identifying security vulnerabilities and sometimes in catching intrusion attempts by cybercriminals and not just the attempts of the red team.

� Nooo Face! A security-awareness video or photo contest, such as the Annual Security Video Contest held by Educause or Trend Micro’s “Nooo! Face” Contest, provide awards for photos that capture the feeling one gets when they realize they are a cyber, victim: precious data has vanished, destroyed, or been taken by an attack.

� Awareness Materials Contests. Award prizes and recognition for awareness ma- terials, such as the annual contests held by the Federal Information Systems Secu- rity Educators’ Association (FISSEA) and the International Information Systems Security Certification Consortium, Inc., ((ISC)2)’s CyberExchange. FISSEA’s contest has categories: Awareness Posters, Motivational Items (trinkets—pens, stress relief items, T-shirts, etc.), Awareness Websites, Awareness Newsletters, and Role-Based Training & Education. The CyberExchange accepts posters, pre- sentations, best practices, flyers, white papers, and more.

� Security Song, Jingle, and Verse Contests. Contests could be for the best security haiku or six-word security stories. The six-word stories are based on the challenge issued to Ernest Hemingway to write an entire story in six words. His story: “For sale: baby shoes, never worn.” A security-related six-word story might be “I never checked my offsite backup…”

� Top Ten Lists. Award a prize for the best (funniest) Security Top Ten list. Exam- ples are the “Top Ten Places Not to Hide Your Password” (such as written with a permanent marker on a light bulb in the office lamp, on a white board, as a tattoo) and “Top Ten Security Headlines We’ll Never See” such as, “White House Painted Purple to Confuse Terrorists” or “Courts Close Due to Lack of Lawsuits over Security Breaches.”

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 36 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

� Security Stories. Invite people to share their security stories—for example, how a person was affected by identity theft, or how someone refused to share personal data when it wasn’t necessary to do so, such as when a healthcare provider’s form asks for a Social Security number. The emotional content makes stories prime material for sharing.

� Security Trivia. Ask security-related questions, such as: � “What color is Whitfield Diffie’s hair?” (or, “Who is Whitfield Diffie and why is he important to security?”)

� “What is the name of the 1983 movie where Mathew Broderick played a young hacker who gained access to a government nuclear war simulator?” (WarGames)

Or, for more technically advanced audiences, � “What type of attack against database-driven applications involves the intruder manipulating a site’s Web-based interfaces to force the database to execute undesirable code?” (SQL injection)

� “What hardware protocol caused the vulnerability where a Firewire device, when plugged in, can overwrite anywhere in memory?” (DMA or Direct Mem- ory Access)

� Security Fact or Fiction Contests. Contestants must decide if statements are true or not. For example: “In fiscal year 2011, the Electronic Crimes Special Agent program processed 1,066 terabytes of data on 8,525 units” (fact).73

Contests can boost morale, motivate people, and contribute to team spirit. Vince Lombardi, former head coach of the Green Bay Packers, understood this. He once said, “Winning isn’t everything. It’s the only thing.” After criticizing him for this statement, some of his critics put together a new kind of baseball league for children in a Texas community: “It was like the Little League—the same ball, same bat, same number of innings, same playing field—everything was the same except that they didn’t keep score. The idea was that there wouldn’t be any losers because nobody would know who won.” The game lasted one and a half innings. After that “the kids went across the street to play sand-lot ball where they could keep score.”74

49.6.12 Awards and Recognition. Rewarding good security behaviors con- tributes to good security. Security is part of everyone’s job and often management believes no special recognition or incentives should be provided. This approach does not work well because in a poorly managed organization, security tends to be outside the normal business process (i.e., security measures are often viewed as an impediment to getting a job done).

Security is a special concern that must be emphasized if assets are to be adequately protected. Security should be integrated with performance appraisals. “Personnel be- come motivated to actively support information security and privacy initiatives when they know that their job advancement, compensation, and benefits will be impacted. If this does not exist, then an organization is destined to depend only upon technology for information security assurance.”75

Awards can be given for extraordinary security behaviors, participation in secu- rity events, achieving a security certification, or providing a security service such as speaking to local groups about cybersecurity. Awards work best if they are publicized, support desired behaviors, and are immediate (close to the act for which the award is being given).

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TOOLS 49 · 37

49.6.13 Human Libraries. A Human Library is a technique to promote di- alogue, information interchange, reduce prejudices, and encourage understanding. A Human Library consists of a group of individuals (“books”) who have agreed to share their knowledge (i.e., the information that’s in their head) with others. Living Books are people you have recruited because they have experiences of interest to the audience. A Human Library can be established as a single event with defined start and end times or an ongoing activity (long-term resource), where the Living Books come and go much as books are checked in and out from a conventional library; it may be established in a single physical location where the “books” are available for a fixed time frame, or it may be a virtual library where the books may be checked out by accessing a database.76 For security awareness, a Human Library can serve as a resource where members of the workforce can learn about security from people who understand their work environment their specific policies and procedures.

Living Books should be volunteers who are recruited with care to ensure that they are committed and willing to talk with strangers about important and sometimes very personal issues. Interview book candidates to ensure the quality of books. Ask the book about its title (subject area) and motivation to be a book. This is to ensure that books are focused on supporting awareness. A reader can safely ask any question without fear of ridicule. A Human Library provides an opportunity to ask the information security questions you always wanted to ask, but were afraid that asking would make you appear naı̈ve.

The best sellers are defined as the books that have the most requests for loans. For metrics, ask books, readers, and librarians for their comments on their Human Library experience. Ask the books if they would be a book again. Ask if people felt that they benefited from the library. Ask the books if they learned anything from the readers.

The experiences that might increase security awareness in living books include:

� Victim of identity theft � Computer gaming addict � Computer Incident Response Team member � Penetration tester � Social engineer � Digital forensics expert � Hacker � Ethical hacker � Helpdesk staff member � Biometric expert � Reformed cyberbully � Someone who lost their job as a result of something posted on the Internet � Information system security officer � Senior executive responsible for security policy � Privacy expert � Electronic Frontier Foundation member � Information-security blogger

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 38 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

� HIPAA expert � Malware researcher � Computer programmer

49.6.14 Volunteer Activities. Strengthen your security-minded workforce through volunteer programs. Volunteerism increases engagement. Data from the Cen- ter for Talent Innovation (CTI) shows that the vast majority of college graduates want to amplify their commitment to good causes through their employer.77 According to the Deloitte Volunteer Impact Survey,78 Generation Ys who frequently participate in their company’s volunteer activities are more likely to be very proud to work for their company, feel very loyal, and be very satisfied with the progression of their careers. These sentiments hold true across generational cohorts—91 percent of Gen X women and 76 percent of Gen X men, and 90 percent of female and 79 percent of male Baby Boomers, feel it is important to contribute to their community or the wider world through work.79

There are many programs that allow individuals with security interests to give back to the community:

� Attending the FBI Citizens Academy, which shows how dedicated our FBI is to protecting our freedom. Most individuals not exposed to computer crime get a rude awakening of just how bad cybercrime is, especially when they see in real-time the innocent images of victims of pedophile activity in their own neighborhood.

� Individuals with CISSP certification can join the (ISC)2 Safe and Secure Online Program to teach children how to be cyberaware.

� Volunteering to be a living book at a Human Library event. � Participating in National Teach-In day to promote cyberawareness for elementary students.

� Cyberawareness training for seniors can be arranged through libraries, religious organizations, and other groups.

49.6.15 Inspections and Audits. Inspections and audits raise awareness among the staff being reviewed, at least for the duration of the inspection. Audits and inspections are typically viewed as negative events. However, there are approaches that can turn an audit/inspection from a negative to a positive experience. Using a tech- nique called “security by wandering around” (SBWA), a security staff member tours the work area, identifies staff members doing something correctly, and leaves certificates of congratulations, thank-you notes, or trinkets on their desks. One audit technique is to treat each encounter with a staff member as a training opportunity, explanations are provided as to “why” a policy is important instead of just rating compliance as pass or fail. Security personnel might periodically demonstrate social engineering by attempting to smooth-talk users into providing their passwords. The number of people who fall for the scheme might be used as an example for the next awareness session.

49.7 EVALUATION AND METRICS. Security consultant Gary Hinson com- pared security to the brakes on a car. The brakes slow you down, but they also make it possible for you to go a lot faster. A good metrics program takes time to set up, but once you have it set up and working well, it can save you time in the long run by making

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

EVALUATION AND METRICS 49 · 39

your program more effective. Metrics aid in decision making. Without a solid metrics program, it is hard to know whether the program is effective, or if the organization should spend more money on doing the same thing, or if the resources would be better used elsewhere.

49.7.1 Baseline. As with any tool, it is important to know how to use metrics. Metrics are best used when they compare measurements over time to a baseline. Defining appropriate metrics and immediately gathering data on the current state of those metrics is an essential first phase for all future evaluation of security-awareness programs.

49.7.2 Metrics. Security metrics are evolving, and different organizations have put forth different tools, different guidance, and different frameworks for evaluating IT security. For example, organizations may use metrics based on such standards as:

� COBIT80

� FISMA81

� FITSAF82

� GLBA83

� HIPAA84

� ISO 27002:200585

� NIST SP 800-5586

� PCI DSS87

� SANS88

� SOX89

or combinations of such guidance. Few organizations currently use security metrics or even a common vocabulary.

Also, many of the tools and guides for measuring IT security metrics only consider security awareness as a small portion of overall security program metrics. Metrics regarding security-awareness programs are high level and not specific. It is easy to collect quantitative measures of data, such as the number of virus infections, server patches performed, or program costs. It is difficult to measure behavioral change.

A commonly used metric is the number of people who participated in awareness orientations and refreshers. This figure can be determined through attendance sheets, course registrations, or completion notifications for online courses, and signed user “acceptance of responsibilities” statements. Another common metric is seat time—how long this person spent in front of a computer, clicking through the screens, soaking up the knowledge that was there. Attendance and seat time may indicate that a program is not effective, but they are not the best measures of awareness program effectiveness. Better measurements focus on the end users and measure behaviors that are a part of normal business operations, including user perceptions, activities, and response to anomalous occurrences.

An effective, measured awareness program can ensure that the workforce serves as a staff firewall, protecting the organization’s information assets, and ensuring that there exists a gold-standard or best-in-class security environment. It also provides

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 40 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

decision makers who are allocating resources with assurances that the security- awareness programs are cost-effective control measures. Also, using objectives such as “ensuring that 100 percent of employees take the awareness course” is a statement regarding the program process, not impact, and should be avoided. When it comes to making a decision between a business case supported by hard numbers and one based on subjective feelings and unsupported statements such as “workforce training is the most cost-effective security control,” the hard numbers will win.

Once the performance measures are adopted, the next step in building the business case solution is to establish at least one metric for each of the supporting goals and objectives. These metrics may be hard numbers (e.g., number of security incidents), estimates (e.g., the average cost per security incident), or the results of testing (e.g., annual testing of a sample of the workforce). Examples of metrics that might be used for the four awareness goals presented above include:

� Goal: The awareness program will improve employees’ ability to recognize and report potential threats and vulnerabilities. � Metric: The number of security events as measured by the number of incident reports.

� What to expect: When an awareness program is first introduced, the expectation is that the number of reported incidents will increase as employees become more aware of potential threats, vulnerabilities, and the need to report. Over time, the number of reported events should stabilize and decline as the security environment is strengthened.

� Goal: The awareness program will improve the level of compliance with company physical and computer security controls. � Metric: The number of sanctions of individuals for failure to comply with security policy.

� Metric: The number of incidents resulting from employee action or inaction as determined through incident analysis.

� What to expect: The number of employees sanctioned for compliance failures should decrease as the awareness program reaches more individuals. Similarly, the awareness program should make individuals more diligent in performing security-related responsibilities, thus resulting in a reduced number of incidents.

� Goal: The awareness program will reduce the occurrence of security failures resulting from employee action or inaction. � Metric: The number of incidents resulting from employee action or inaction as determined through incident analysis.

� Metric: The number of security incidents resulting from employee actions or inactions declines over time as individuals recognize the importance of fulfilling their security responsibilities.

� Goal: The awareness program will reduce the severity of the security incidents that do occur. � Metric: The cost per incident as determined through incident analysis. � What to expect: The cost per incident decreases as individuals react more quickly to identify a potential security incident and take action to mitigate its impact.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

CONCLUDING REMARKS 49 · 41

Two other issues should be addressed relative to an awareness program’s goals and metrics. First, an awareness program seeks to make a behavioral change in the workforce. Behavioral change takes time, so the metrics should have an established time frame where management should expect to see performance improvement. The time frame should be realistic (e.g., quarterly, semi-annual, annual), avoid immediate impacts (e.g., “After a course on viruses, the number of virus incidents should decrease within a week”) and avoid time frames that are too long (e.g., “The number of virus incidents should decrease over the next five years”).

Second, solicit and use employee feedback. Employee feedback should be analyzed because it provides indicators of the level of security awareness and the importance employees ascribe to information security. Analysis of employee feedback could be used to generate other performance metrics for an awareness program.

Automated metrics are useful to help measure changes in behavior.

� Filtering software that monitors content (e.g., 9- or 16-digit strings of numbers for Social Security numbers and credit card account numbers) or specific words can indicate how often people try to email this information;

� Web statistics and firewall monitoring software can indicate how often people visit or attempt to visit specific Websites, such as the security intranet page;

� Helpdesk call log summaries can identify problems related to security issues; and � Performance appraisals, participation in contests, and results of quizzes are indi- cators of interest in security-related behaviors.

49.8 CONCLUDING REMARKS. Awareness among an organization’s staff is vital to maintaining the integrity of data and systems. Although organizations often view computer security as a technological problem and use sophisticated hardware and software solutions to control access, detect potential security incidents, and pre- vent fraud, the reality is that computer security is as much a people problem as a technological problem. End users are closer to potential problems; therefore, they need to be aware of potential risks, threats, vulnerabilities, and their own security responsibilities.

People are major contributors to the IT security problem, and they are also crucial to its solution. People are perceptive and adaptive, and if trained and motivated to be aware, they can be the strongest and most effective security countermeasure. Individuals often are the first to detect security incidents. The actions they take or fail to take determine the level of damage. An aware workforce often can compensate for deficiencies in technical controls. The intent of the awareness program is to make recognition of and reaction to security threats a reflexive behavior.

Awareness takes time. It also requires the organization to have an in-place informa- tion security policy, the support of the senior-level managers, and clear goals and plans for achieving awareness. The importance of establishing measurable goals cannot be overestimated and is critical to obtaining support and funding.

The goal of an awareness program is often to change attitudes and behaviors that may be embedded in long-term procedures or habits. To effect awareness, the program must appeal to the audience and be tailored to the workforce and to the technology of the organization. The primary message of a security-awareness program should be that security is everyone’s responsibility. Actions taken by end users make a significant difference; thus, a well-trained and motivated workforce is a critical and necessary security control.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 42 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

49.9 GLOSSARY

Awareness—being conscious of what is going on around one; security awareness specifically focuses attention on security. Security awareness is the individual’s understanding that security is important and that everyone has a role in ensuring the security of information and information technology.

Awareness campaign—the activities associated with conveying a specific aware- ness message (e.g., telling people “log off when away from your computer”).

Awareness program—the planned implementation and control of a mix of aware- ness activities over a period of time, with measurable goals and multiple topics. An awareness program may encompass several campaigns.

Basics and literacy—a transitional stage between awareness and role-based train- ing.

Education—the process of integrating all security skills and competencies into a common body of knowledge, adding a multidisciplinary study of concepts, issues, and principles.

End user (also computer user or user)—any person who uses an information system.

Focus group—a small group of end users (or of individuals from the target audi- ence) who review and discuss awareness activities, courses, products, and the like, often under the guidance of an awareness material developer or training specialist.

FUD factor—the effects of fear, uncertainty, and doubt (FUD). Gamification—the concept of applying game-design thinking to nongame applica-

tions to make them more fun and engaging.

Malicious code (also malware)—hardware, software, or firmware that is intention- ally included in a system for an unauthorized purpose (e.g., a Trojan horse).

Orientation briefing—a presentation that provides new employees, contractors, and the like with basic security information and information on the organization’s security policies and programs. Usually these presentations are conducted on arrival or shortly thereafter.

Refresher—an awareness activity, such as a briefing, intended to reinforce and update awareness of security controls and policies and to remind individuals of their security responsibilities.

Role-based training—the process of producing relevant and needed security skills and competency. Security awareness is the “what.” Role-based training is the “how.”

Safe failure—the opportunity to learn from mistakes privately, such as with a computer simulation or course.

Social engineering—social methods (e.g., threats, misrepresentations) that deceive a victim so that the victim does what the attacker wants him or her to do. Often the goal is to get the victim to provide private or sensitive information, such as account numbers or passwords. An example of a social engineering attack is the use of “phishing” emails.

Social marketing—an approach to security awareness using attraction and persua- sion techniques designed to encourage a group of people to alter old ideas,

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

NOTES 49 · 43

understand and accept new ideas, and value their new awareness enough to change attitudes and take positive actions to improve IT security.

Target audience—a specified audience or demographic group for which a security- awareness message is designed.

Threat—anything that can potentially harm a system or its associated assets (hard- ware, software, data, operations). Threats may be man-made or natural occur- rences. Awareness programs do little to address threats; instead, they seek to reduce vulnerabilities.

Vulnerability—a weakness in automated system security procedures, administra- tive controls, physical layout, internal controls, and so forth, which could be exploited by a threat to gain unauthorized access to information or dis- rupt critical processing. A goal of security-awareness programs is to reduce behavior-related vulnerabilities.

49.10 NOTES 1. Katy Stech, “Burglary Triggers Medical Records Firm’s Collapse,” The Wall Street Journal, March 12, 2012, http://blogs.wsj.com/bankruptcy/2012/03/12/burglary- triggers-medical-records-firm%E2%80%99s-collapse

2. Ellis Smith, “BlueCross Burglary Could be Chattanooga’s Costliest Ca- per,” Times Free Press, March 13, 2012, http://timesfreepress.com/news/2012/ mar/13/bluecross-burglary-could-be-citys-costliest

3. Alex Pham, “Sony Expects Much Wider Annual Loss,” Los Angeles Times, Febru- ary 3, 2012, http://articles.latimes.com/2012/feb/03/business/la-fi-ct-sony-earns- 20120203

4. Tony Busseri, “It’s Time to Take Cybersecurity Seriously,” Wired, March 12, 2012, www.wired.com/threatlevel/2012/03/opinion-busseri-cybersecurity

5. “Verizon 2012 Data Breach Investigations Report,” p. 2, www.verizonbusiness .com/resources/reports/rp data-breach-investigations-report-2012-ebk en xg.pdf (url inactive).

6. Mark Wilson, Kevin Stine, and Pauline Bowen, “Information Security Training Requirements: A Role- and Performance-Based Model (Draft),” NIST Special Publication 800-16 Rev. 1 (Draft), March 2009, http://csrc.nist.gov/publications/ drafts/800-16-rev1/Draft-SP800-16-Rev1.pdf

7. Wilson et al., “Information Security Training Requirements,” NIST Special Publi- cation 800-16 Rev. 1 (Draft)

8. Wilson et al., “Information Security Training Requirements,” NIST Special Publi- cation 800-16 Rev. 1 (Draft)

9. Ira Winkler, Zen and the Art of Information Security (Rockland: Syngress, 2007). 10. Mary Kirwan, “Education May Not Be Enough to Ensure Compliance,” The

Globe and Mail, March 31, 2012, http://v1.theglobeandmail.com/servlet/story/ RTGAM.20070911.WBsecurityblog20070911120000/WBStory/WBsecurityblog

11. WebCPA staff, “IRS Security Still Lax,” Accounting Today, Washington, D.C., August 6, 2007, www.accountingtoday.com/news/25009-1.html

12. Winkler, Zen and the Art of Information Security. 13. “Many Young Workers Are IT Rule-Breakers,” Harvard Business Review | The

Daily Stat, January 10, 2012, http://web.hbr.org/email/archive/dailystat.php? date=011012

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 44 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

14. Jeffrey M. Stanton, Kathryn R. Stam, Paul Mastrangelo, and Jeffrey Jolton, “Anal- ysis of End User Security Behaviors,” Computers & Security 24, no. 2 (March 2005): 124–133, www.sciencedirect.com/science/article/pii/S0167404804001841

15. Thomas Steward and Anand Raman, “Lessons from Toyota’s Long Drive, An Interview with Katsuaki Watanabe,” Harvard Business Review, July 2007, http://hbr.org/2007/07/lessons-from-toyotas-long-drive/ar/1

16. John Caddell, “How to Bounce Back from a Big Mistake,” 99U, approxi- mately November 2011, http://99u.com/articles/7089/how-to-bounce-back-from- a-big-mistake

17. D. Verton, “Federal Agency Faces Judicial Ultimatum,” Computerworld, 2002, www.computerworld.com/securitytopics/security/story/0,10801,69937,00.html

18. Marı́a Cristina Caballero, “Academic Turns City into a Social Experiment: Mayor Mockus of Bogotá and His Spectacularly Applied Theory,” Harvard Uni- versity Gazette, March 11, 2004, www.news.harvard.edu/gazette/2004/03.11/01- mockus.html

19. M. E. Kabay, “The Net Present Value of Information Security: A Paradigm Shift for INFOSEC and E-commerce,” 2006, www.mekabay.com/infosecmgmt/npvsec.pdf

20. Additional note: See also Chapter 50, “Using Social Psychology to Implement Security Policies.”

21. The Federal InformationSecurityManagement Act of 2002, Section3544, “Federal Agency Responsibilities,” http://csrc.nist.gov/drivers/documents/FISMA-final.pdf

22. See Chapter 64, “U.S. Legal and Regulatory Security Issues” 23. Dan Heath and Chip Heath. Made to Stick (New York: Random House, 2007). 24. C. Heath and D. Heath, “The Curse of Knowledge.” Harvard Business Review,

December 2006, http://hbr.org/2006/12/the-curse-of-knowledge/ar/1 25. Donna Mattick, personal correspondence, March 2012. 26. John Tierney and Roy Baumeister, Willpower: Rediscovering the Greatest Human

Strength (The Penguin Press HC, 2011). 27. V. Basili, G. Caldiera, and H. D. Rombach, “The Goal Question Metric Approach,”

Encyclopedia of Software Engineering (New York: John Wiley & Sons, 1994), 528–532 www.cs.umd.edu/∼basili/publications/technical/T87.pdf (url inactive).

28. Mark Wilson and Joan Hash, “Building an Information Technology Secu- rity Awareness and Training Program,” NIST SP 800-50, October 2003, http://csrc.nist.gov/publications/nistpubs/800-50/NIST-SP800-50.pdf

29. K. Sanders, “Bears in Your Backyard? Guidelines for Bear-Proofing Your Property, and Living with Bears,” 2000, www.yellowstone-bearman.com/B housesafe.html

30. Rebecca Herold, Managing an Information Security and Privacy Awareness and Training Program, 2nd ed. (CRC Press, 2011).

31. K. Hall and the SE SIG Steering Committee, “A System for Gaining Man- agement Support for Your Safeguards and Security Awareness Program,” 2002, www.orau.gov/se/Products/SE%20SIG%20Gaining%20Mgmt%20Support.doc

32. Wilson et al., “Information Security Training Requirements,” NIST Special Publi- cation 800-16 Rev. 1 (Draft).

33. de Saint-Exupery, Antoine. The Wisdom of the Sands (Amereon Ltd., October 2003).

34. John Medina, Brain Rules (Pear Press, 2008).

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

NOTES 49 · 45

35. Medina, Brain Rules. 36. Reif Larson, “This Chart Is a Lonely Hunter: The Narrative Eros of the Info-

graphic,” The Millions, February 7, 2012, www.themillions.com/2012/02/this- chart-is-a-lonely-hunter-the-narrative-eros-of-the-infographic.html

37. Larson, “This Chart Is a Lonely Hunter.” 38. Brenda Oldfield, “Game-Changing Technologies for Cybersecurity Awareness and

Training” (presentation, FISSEA Conference, Gaithersburg, MD, March 29, 2012). 39. Anderson, Chris. “How Web Video Powers Global Innovation,” Technology,

Entertainment, Design (TED) Talks, TEDGlobal 2010, Filmed July 2010, Posted September 2010; www.ted.com/talks/chris anderson how web video powers global innovation.html

40. Anderson, “How Web Video Powers Global Innovation.” 41. Chip Heath and Dan Heath, The Myth of the Garage (Crown Business, 2011). 42. Winifred Gallagher, New: Understanding Our Need for Novelty and Change (Pen-

guin Press HC: 2011). 43. Maria Popova, “Network: The Secret Life of Your Personal Data,” January

10, 2012; www.brainpickings.org/index.php/2012/01/10/network-michael-rigley/ contains embedded video, “Network,” by Michael Rigley

44. Caballero, “Academic Turns City into a Social Experiment.” 45. Heath and Heath, Made to Stick. 46. Elisabeth Freeman and Eric Freeman, Head First HTML with CSS & XHTML

(O’Reilly Media, 2005). 47. Ruth Colvin Clark and Richard E. Mayer, eLearningandtheScienceofInstruction.

(San Francisco: Pfeiffer, 2003). 48. Freeman and Freeman, Head First HTML. 49. Roger, C. Schank, Lessons in Learning, e-Learning, and Training: Perspectives

and Guidance for the Enlightened Trainer (Pfeiffer, 2005). 50. Native Intelligence, Poster 153A, www.nativeintelligence.com/ni-posters/posters

.asp 51. Native Intelligence, Poster 115, www.nativeintelligence.com/ni-posters/posters

.asp 52. Andrew Stanton, “The Clues to a Great Story,” Technology, Entertainment,

Design (TED)Talks, TED2012, Filmed February 2012, Posted March 2012; www.ted.com/talks/andrew stanton the clues to a great story.html

53. Gerald Weinberg, Weinberg on Writing: The Fieldstone Method (Dorset House, 2005).

54. INFOWAR: The Nexus of Technology and Security in Cyberspace, www.infowar .com

55. Bliss, Chris. “Comedy Is Translation,” Technology, Entertainment, Design (TED)Talks, TEDX Talk, www.ted.com/talks/chris bliss comedy is translation .html

56. Bliss, “Comedy Is Translation.” 57. Robert B. Cialdini, Noah J. Goldstein, and Steve Martin, Yes!: 50 Scientifically

Proven Ways to Be Persuasive (Free Press, 2009). 58. R. B. Cialdini, Influence: The Psychology of Persuasion (HarperBusiness, 2006).

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

49 · 46 IMPLEMENTING A SECURITY-AWARENESS PROGRAM

59. M. E. Kabay, “Applying the Science of Persuasion to Security Awareness,” Network World Security Strategies Newsletters, 2009, www.mekabay.com/nwss/ 725 applying the science of persuasion to security awareness.pdf

60. W3C, “Accessibility,” 2012, www.w3.org/standards/webdesign/accessibility 61. Rudolph Flesch, The Art of Readable Writing (Wiley, 1994). 62. Robert Gunning, The Technique of Clear Writing (McGraw-Hill, 1952). 63. Carnegie Mellon University Information Networking Institute (INI) “Confronting

One-Click Fraud in Japan,” www.ini.cmu.edu/news/features/one-click.html 64. Gwern.net, “Spaced Repetition,” March 12, 2012, www.gwern.net/Spaced%20

repetition 65. J. J. Donovan and D. J. Radosevich, “A Meta-analytic Review of the Distribution of

Practice Effect: Now You See It, Now You Don’t.” Journal of Applied Psychology 84, no. 5 (1999): 795–805.

66. M. E. Kabay, “CAC: Computer-Aided ConsensusTM,” 2009, www.mekabay.com/ methodology/cac ppt.zip

67. Mark Bonchek, “How Top Brands Pull Customers into Orbit,” Harvard Business Review | Blogs, March 5, 2012, http://blogs.hbr.org/cs/2012/03/ how top brands pull customers.html

68. PentaSafe. “Security Awareness Index Report: Worldwide State of Security Aware- ness,” 2002.

69. James Habyarimana and William Jack, “Heckle and Chide: Results of a Ran- domized Road Safety Intervention in Kenya,” Center for Global Develop- ment, Working Paper No. 169, April 2009, http://www.cgdev.org/files/1421541 file Habyarimana Jack Heckle FINAL.pdf

70. The European Network and Information Security Agency (ENISA), “Information Security Awareness Initiatives: Current Practice and the Measurement of Success,” www.enisa.europa.eu/doc/pdf/deliverables/enisa measuring awareness.pdf

71. Jan Hoffman, “Speak Up? Raise Your Hand? That May No Longer Be Necessary,” The New York Times, March 30, 2012, www.nytimes.com/2012/03/31/us/clickers- offer-instant-interactions-in-more-venues.html

72. Aaron Ferguson, “Fostering E-Mail Security Awareness: The West Point Car- ronade,” EDUCAUSE, 2004, www.educause.edu/ir/library/pdf/EQM0517.pdf

73. United States Secret Service, “Fiscal Year 2011 Annual Report,” 2011, p. 40, www.secretservice.gov/USSS FY2011AR.pdf

74. C. Coonradt, The Game of Work (Park City, 1997). 75. Herold, Managing an Information Security and Privacy Awareness and Training

Program. 76. Human Library Website, 2012, http://humanlibrary.org 77. Sylvia Ann Hewlett, “Strengthen Your Workforce Through Volunteer Pro-

grams,” Harvard Business Review | Blogs, March 5, 2012, http://blogs.hbr .org/hbr/hewlett/2012/03/strengthen your workforce thro.html

78. Deloitte Website, “2011 Deloitte Volunteer Impact Survey,” 2011 www.deloitte .com/view/en US/us/About/Community-Involvement/volunteerism/impact- day/f98eec97e6650310VgnVCM2000001b56f00aRCRD.htm

79. Hewlett, Sylvia Ann. “Strengthen Your Workforce Through Volunteer Programs,” 2012; http://blogs.hbr.org/hbr/hewlett/2012/03/strengthen your workforce thro .html

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

NOTES 49 · 47

80. Information Systems Audit and Control Association (ISACA) “COBIT 5: A Busi- ness Framework for the Governance and Management of Enterprise IT,” ISACA Website, 2012, www.isaca.org/COBIT/Pages/default.aspx

81. National Institute of Standards and Technology (NIST), “FISMA FAQs,” NIST Website, 2012, http://csrc.nist.gov/groups/SMA/fisma/faqs.html

82. National Institute of Standards and Technology (NIST), “The Federal In- formation Technology Security Assessment Framework,” 2000, http://csrc .nist.gov/drivers/documents/Federal-IT-Security-Assessment-Framework.pdf

83. Bureau of Consumer Protection, “Gramm-Leach-Bliley Act,” 2012, http://business.ftc.gov/privacy-and-security/gramm-leach-bliley-act

84. U.S. Department of Health & Human Services, “Health Information Privacy,” 2012, www.hhs.gov/ocr/privacy

85. ISO/IEC 27002:2005, “Information Technology—Security Techniques—Code of Practice for Information Security Management,” 2005, www.iso.org/iso/ home/store/catalogue ics/catalogue detail ics.htm?csnumber=50297

86. E. Chew, M. Swanson, K. Stine, N. Bartol, A. Brown, and W. Robinson, “Per- formance Measurement Guide for Information Security,” NIST SP-800-55, rev. 1, 2008, http://csrc.nist.gov/publications/nistpubs/800-55-Rev1/SP800-55-rev1.pdf

87. VISA Data Security Bulletin, “Visa PCI DSS Compliance Validation Frame- work,” 2008, < http://usa.visa.com/download/merchants/cisp-bulletin-visa-pci- dss-framework-111808.pdf

88. SANS (2012). “Standards,” SANS | Reading Room, 2012 www.sans.org/ reading room/whitepapers/standards

89. U.S. Securities and Exchange Commission, “The Laws That Govern the Securities Industry,” U.S. SEC Website, 2012, www.sec.gov/about/laws.shtml

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

50CHAPTER

USING SOCIAL PSYCHOLOGY TO IMPLEMENT SECURITY POLICIES

M. E. Kabay, Bridgitt Robertson, Mani Akella, and D. T. Lang

50.1 INTRODUCTION 50 · 1

50.2 RATIONALITY IS NOT ENOUGH 50 · 2 50.2.1 Schema 50·3 50.2.2 Theories of

Personality 50·4 50.2.3 Explanations of

Behavior 50·7 50.2.4 Errors of Attribution 50·7 50.2.5 Intercultural

Differences 50·10 50.2.6 Framing Reality 50·11 50.2.7 Getting Your

Security Policies Across 50·12

50.2.8 Reward versus Punishment 50·13

50.3 BELIEFS AND ATTITUDES 50 · 13 50.3.1 Beliefs 50·14 50.3.2 Attitudes 50·14 50.3.3 Changing Attitudes

toward Security 50·14

50.4 ENCOURAGING INITIATIVE 50 · 16 50.4.1 Prosocial Behavior 50·16 50.4.2 Conformity,

Compliance, and Obedience 50·17

50.5 GROUP BEHAVIOR 50 · 20 50.5.1 Social Arousal 50·20 50.5.2 Locus of Control 50·20 50.5.3 Group Polarization 50·20 50.5.4 Groupthink 50·20

50.6 TECHNOLOGICAL GENERATION GAPS 50 · 21

50.7 SUMMARY OF RECOMMENDATIONS 50 · 22

50.8 FURTHER READING 50 · 24

50.9 NOTES 50 · 24

50.1 INTRODUCTION.1 Most security personnel have commiserated with col- leagues about the difficulty of getting people to pay attention to security policies—to comply with what seems like good common sense. They shake their heads in disbelief as they recount tales of employees who hold secured doors open for their workmates—or for total strangers, thereby rendering million-dollar card-access systems useless. In large organizations, upper managers who decline to wear their identification badges discover that soon no one else will either. In trying to implement security policies, practitioners sometimes feel that they are involved in turf wars and personal vendettas rather than rational discourse.

50 · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

50 · 2 USING SOCIAL PSYCHOLOGY TO IMPLEMENT SECURITY POLICIES

These problems reflect the social nature of human beings; however, they also reflect the fact that although people involved in information systems security and network management have a wide variety of backgrounds, many lack training in social or organizational psychology.

Security policies and procedures affect not only what people do, but also how they see themselves, their colleagues, and their world. Despite these psychosocial issues, security personnel pay little or no attention to what is known about social psychology. The established principles of human social behavior have much to teach in any attempts to improve corporate and institutional information assurance (IA).

IA specialists concur that security depends on people more than on technology. Another commonplace is that employees are a far greater threat to IA than outsiders (see Chapter 13 in this Handbook).

It follows from these observations that improving security necessarily involves changing beliefs, attitudes, and behavior, both of individuals and of groups. Social psychology can help us understand how best to work with human predilections and predispositions to achieve our goals of improving security:

� Research on social cognition looks at how people form impressions about reality. Knowing these principles, we can better teach our colleagues and clients about effective security.

� Work on attitude formation and beliefs helps to present information effectively and so convince employees and others to cooperate in improving security.

� Scientists studying persuasion and attitude change have learned how best to change people’s minds about unpopular views, such as those regarding the security com- munity.

� Studies of factors enhancing prosocial behavior provide insights on how to foster an environment where corporate information is willingly protected.

� Knowledge of the phenomena underlying conformity, compliance, and obedience can help to enhance security by encouraging compliance and by protecting staff against social pressure to breach security.

� Group psychology research provides warnings about group pathology and about hints for working better with groups in establishing and maintaining IA in the face of ingrained resistance.

This chapter reviews well-established principles of social psychology that help secu- rity and network management personnel implement security policies more effectively. Any recent introductory social psychology college textbook will provide ample ref- erences to the research underpinning the principles applied here to security policy implementation.2

50.2 RATIONALITY IS NOT ENOUGH. IA policies sometimes evoke strong emotions. People can get very angry about what they perceive as interference with their way of getting their work done. From the perspective of the traditional information security professional, information security is still perceived as a technical problem, but as recent research reveals, it is more of a management problem, and the prevalent security culture offers insight into how management handles this problem.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

RATIONALITY IS NOT ENOUGH 50 · 3

To put the discussion in context, here is a definition of rationality from a respected academic, Jonathan Baron: Rationality is “the kind of thinking we would all want to do, if we were aware of our own best interests, in order to achieve our goals.”3

Applying this definition to the concept of security, it seems to imply that rational thought would direct us to what appears to be the best compromise between what we perceive as our security needs and what appears to be the most convenient process.

50.2.1 Schema. Psychologists use the word schema to summarize the complex picture of reality on which we base our judgments. The schema is what social psychol- ogists call the way people make sense of their social interactions. IA practitioners must often change their colleagues’ schemata.

Schemata are self-consistent views of reality. They help us pay attention to what we expect to be important and to ignore irrelevant data. They also help us organize our behavior. For example, our schema for relations at the office includes polite greetings, civil discussions, written communications, and businesslike clothes. The schema ex- cludes obscene shrieks, abusive verbal attacks, spray-painted graffiti, and colleagues dressed in swimsuits. It is the schema that lets people know what is appropriate or inappropriate in a given situation.

Unfortunately, security policies and procedures conflict with most people’s schemata. Office workers’ schemata includes sharing office supplies (“Lend me your stapler, please?”), trusting their team members to share information (“Take a look at these figures, Sally”), and letting their papers stay openly visible when they leave their desks.

Sharing user IDs, showing sensitive information to someone who lacks the appropri- ate clearance, and leaving workstations logged on without protection are gross breaches of a different schema—that of the IAspecialist. Thinkabout accesscontrols: Normal po- liteness dictates that when a colleague approaches the door we have just opened, we hold the door open for the person; when we see a visitor, we smile politely—after all, it might be a customer. In contrast, access-control policies require that we refuse to let even well- liked colleagues piggyback their way through an access-card system; security policies insist that unbadged strangers be challenged or reported to security personnel. Common sense tells us that when the chief executive officer (CEO) of the company wants some- thing, we do not oppose it; yet good IA dictates that we train computer room operators to forbid entry to anyone without documented authorization—including the CEO.

Sometimes people subvert IA by systematically getting around the rules because their normal social schema supersedes the security schema. It is not uncommon for naı̈ve staff to give keys or the door lock combination for access into secured areas to regularly schedule outside delivery and maintenance persons. Such delivery people are rarely subjected to security checks, and yet their potential for intentional or inadvertent damage is great; nonetheless, the naı̈ve staff members are acting without authorization, subverting normal security controls, and entrusting the safety and security of corporate resources to relative unknowns: Why? Are they deliberately violating security policy with evil intent? Of course not: The employees are simply acting in a friendly fashion and extending trust that might be appropriate in other circumstances—but they are using the wrong schema for a high-security corporate environment. In contrast, an IA specialist’s schema in the same circumstances includes all the potentially untrustworthy friends of those outsiders. Until the security administration group alters the employees’ perception of the appropriateness of the security regulations, the conflict between different schemata will continue to cause security violations and fuel resentment on all sides.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

50 · 4 USING SOCIAL PSYCHOLOGY TO IMPLEMENT SECURITY POLICIES

Indeed, a common response to attempts at enforcing existing policies and procedures, or to new security rules, is a charge of paranoia leveled against security personnel. Other accusations include authoritarian behavior and undue interference with job functions. These responses usually indicate a conflict between accepted norms of behavior and the need to change behavior to conform to security principles. They imply that social and cultural needs and behavior were not accounted for in the design of the principles. They also indicate a need for security personnel to understand that basic social graces and accepted norms of social activity conflict with the basic needs of security—and that the employees violating security rules are not inherently bad people.

Some redesign might allow for better security by recognizing that security rules can violate accepted social norms. For example, in the case of security-locked doors, one could allow for relatively free access to common areas (thus allowing people to hold the door for colleagues following them) while forbidding such actions in secured locations. A posted explanation of both the reasons for, and consequences of, the policy explicitly addressing the difference between the needs of normal politeness and the needs of high security could lead to better adherence to stated policy. The text might read something like this:

This is a high-security area. Preventing anyone from entering without swiping their owned access card is not rude: it’s common sense. Entering secured areas without using each em- ployee’s access card could put employees who did not use their access cards to enter at risk in an emergency if security staff didn’t know that they were still in the secured areas. You are welcome to exercise normal politeness by holding the doors open for your colleagues and badge-wearing visitors in the nonsecured areas.

If we persist in assuming that we can influence our colleagues to change their perception of IA solely by informing, cajoling, nagging, or browbeating them, we will continue to fail. IA must be integrated into the corporate culture by changing our colleagues’ schemata, a process that needs to use all of the techniques that social psychology can teach us.

A simple measure of this reality is to be found in the persistent avoidance practiced by many U.S. Government agencies in applying the information security program requirements of the Federal Information Security Management Act of 2002 (FISMA). It took almost five years and a series of undesirable security incidents before the various agencies woke up to the reality of the need to implement appropriate protection.4

Another illustration of the reluctance to implement security policies is the Veterans Affairs debacle in the late 2000s involving loss of control over personally identifiable information on unencrypted disk drives.5

50.2.2 Theories of Personality. One of the most pervasive obstacles to co- operation in organizations is interpersonal conflict. Many conflicts are rooted in differ- ences of personalitystyle. For example, one widely used set of categories for describing people’s personalities uses this schema:

� Extroversion � High: active, assertive, energetic, outgoing, talkative � Low: quiet, reserved, shy, silent, withdrawn

� Agreeableness � High: affectionate, appreciative, kind, soft-hearted, sympathetic � Low: cold, fault-finding, hard-hearted, quarrelsome, unfriendly

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

RATIONALITY IS NOT ENOUGH 50 · 5

� Conscientiousness � High: efficient, organized, planful, responsible, thorough � Low: careless, disorderly, frivolous, irresponsible, slipshod

� Emotional stability � High: calm, contented, stable, unemotional � Low: anxious, moody, nervous, tense, worrying

� Openness or culturedness � High: imaginative, insightful, intelligent, original, wide interests � Low: commonplace, shallow, simple, narrow interests, unintelligent

The adjectives used in this summary are positive for the high side of each trait and negative for the low side. However, the assumption that different personality types are easily characterized as superior and inferior seriously interferes with respectful communications among colleagues. For example, people with low characteristics might view the preceding summary in this way:

� Extroversion � High: nervous, aggressive, excitable, pushy, chattering � Low: dignified, respectful, unassuming, attentive, self-sufficient

� Agreeableness � High: clinging, gushy, soft-headed, knee-jerk reactive, uncritical � Low: stately, analytical, rational, principled, reserved

� Conscientiousness � High: obsessive, compulsive, unspontaneous, pompous, slavish � Low: free, spontaneous, creative, fun, youthful, having perspective

� Emotional stability � High: frozen, ambitionless, boring, dead � Low: vibrant, romantic, alive, strong, sensible

� Openness or culturedness � High: flaky, theoretical, complicated, off-the-wall, dilettante � Low: earthy, smart, grounded, focused, practical

In discussing corporate culture change, leaders must be on guard to defuse conflicts based on the misperception that one particular response or view of an issue is necessar- ily good and another necessarily bad. The conflict may be rooted in personality styles rather than in problems of understanding. If the security working group proposes that all employees must challenge anyone in the secured areas who is not wearing a badge, some people—those who have low extroversion, for example—may have a great deal of difficulty with the concept that they should tell anyone else what to do, especially a manager of a higher rank than their own. Arguing only over the reasons why such a pol- icy would be useful would sidestep the fundamental problem: that the required behavior is in direct conflict with possibly lifelong and firmly held views on appropriate behavior.

Security personnel must remember that failure to comply with policy is not neces- sarily the result of a bad attitude. When it becomes obvious that conflicts are rooted in

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

50 · 6 USING SOCIAL PSYCHOLOGY TO IMPLEMENT SECURITY POLICIES

personality, security personnel will have to try to arrive at a useful compromise. Instead of requiring that everyone confront the unbadged individual personally, the security policies could include a proviso allowing for individuals to choose simply to inform security personnel immediately.

Role-playing exercises sometimes can defuse a problem in accepting security poli- cies by desensitizing resistant personnel. Going through the motions of what they fear or dislike sometimes can help them come to realize that the proposed change in behav- ior is not as bad as they originally thought. Returning to the example of confronting violations of security, many people have difficulty imagining that they could tell a superior in the management hierarchy not to piggyback. This term, like hitchhiking and tailgating, describes entering through a secured door that has been opened by someone else using a valid access code or token. Going through exercises in which each person pretends in turn to be the upper manager and then the challenger helps to break down resistance to this particular security policy. Trainers can emphasize that the challenge must be seen using a different schema from the normal situation:

� It is socially acceptable to apply security policies within the organization. � Higher-status employees can encourage lower-status employees by articulating their support for the policy and showing that they are not offended by the request.

� Participants of all hierarchical levels can introspect to see that they themselves do not feel offended when they are politely asked to use their badge during the role-playing exercise.

In general, leaders of the security team responsible for implementing security poli- cies should be on the lookout for conflicts of style that interfere with the central task of making the enterprise more secure. If an individual likes short, direct instructions without chitchat about nonessentials, the security team member should adapt and stick to essentials; if an individual is known to like getting to know a stranger and wants to spend a few minutes learning about family background, it should not be opposed. Communicating ideas in a way that is likely to be acceptable is more important than imposing one’s own interpersonal style preferences on others.

Above all, security personnel—and management in general—ought to be doing a great deal more listening and a great deal less commanding.

Some important psychological issues for security leaders to consider include:

� Digital security is extremely complicated, and the explanations can be very technical—both attributes that are unfavorable to fostering management atten- tion.

� Most security incidents stem from insiders rather than from outsiders, so pre- vention requires consistent nagging—not something management or anyone else normally regards favorably.

� Success in digital security (in fact, all of security) is best shown by having nothing happen, which is a tough thing to measure and tougher to sell. So the personal payoff for a well-executed security strategy is often little to nothing—and no management executive wants to put up nothing as a true measure of success.

The practical implications of these observations include:

� Discussions of IA should be down-to-earth and practical whenever possible. � Awareness can be achieved by more positive means than nagging.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

RATIONALITY IS NOT ENOUGH 50 · 7

� One can create metrics of success by using security games and competitions that are fun as well as informative and effective at maintaining security awareness.

Here is an abstract of an article on the general manager’s contribution to security:

Few senior executives pay much attention to computer security. They either hand off re- sponsibility to their technical people or bring in consultants. But given the stakes involved, an arm’s-length approach is extremely unwise. According to industry estimates, security breaches affect 90% of all businesses every year and cost some $17 billion. Fortunately … senior exec- utives don’t need to learn about the more arcane aspects of their company’s IT systems to take a hands-on approach. Instead, they should focus on the familiar task of managing risk. Their role should be to assess the business value of their information assets, determine the likelihood that those assets will be compromised, and then tailor a set of risk abatement processes to their company’s particular vulnerabilities. This approach, which views computer security as an operational rather than a technical challenge, is akin to a classic quality assurance program in that it attempts to avoid problems rather than fix them and involves all employees, not just IT staffers. The goal is not to make computer systems completely secure—that’s impossible—but to reduce the business risk to an acceptable level…6

We have italicized the key sentence in the quote to emphasize the critical role of changing corporate culture in successful security management.7

50.2.3 Explanations of Behavior. In practice, trying to change corporate culture can be a frustrating and long-drawn-out project. One aspect of this process that security group leaders should monitor closely is the interpretation of employee behavior (called attribution theory in the social psychology literature) by members of the security team. In general, people can be viewed as interpreting (i.e., explaining) other people’s behavior according to two independent dimensions: internal or external and stable or unstable. Here are some explanations of why Betty has failed to log off her session for the fourth time this week before leaving the office:

� Internal, stable. “That’s just the way she is—she never pays attention to these rules.”

� Internal, unstable. “She’s been under strain lately because her child is sick—that’s why she’s forgotten.”

� External, stable. “The system doesn’t respond properly to the logoff command.” � External, unstable. “This week, the system has not been responding properly to the logoff command.”

This simple four-way classification is useful for leaders in understanding and avoid- ing classic errors of attribution. Such attribution errors can cause conflicts between the security staff and other employees, or even among employees with different degrees of compliance to policy.

50.2.4 Errors of Attribution. Some well-established misinterpretations of oth- ers’ behavior can interfere with the acceptance of security policies. Such errors inter- fere with the ability of security personnel to communicate the value of security poli- cies. Security group leaders should sensitize their staff to the consequences of these errors.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

50 · 8 USING SOCIAL PSYCHOLOGY TO IMPLEMENT SECURITY POLICIES

50.2.4.1 Fundamental Attribution Error. The most important error people use when explaining other people’s behavior is to assume that a person’s actions are stable, internal features; a typical example of this error is the naı̈ve belief that an actor’s personality is essentially what that person portrays in performance. Anyone who has ever experienced surprise at the demeanor and speech of a favorite actor who is being interviewed has committed the fundamental attribution error. Some actors who play bad characters in fictional situations have even been verbally and physically assaulted by viewers who cannot resist the fundamental attribution error, and who genuinely believe that the actors are as bad as the nasty people they portray. The abstract of a conference presentation in 2008 summarized some significant findings illustrating this point:

Two studies attempted to document the occurrence of the psychological phenomenon known as the fundamental attribution error (FAE) in the audiovisual medium. The FAE refers to the human tendency to attribute people’s behavior to internal attributes more than external factors. In Study 1, we demonstrated that in the audiovisual medium, viewers tend to attribute an actor’s behavior in television dramas to the actor’s personality, ignoring the existence of a script dictating the actor’s behavior. Study 2 replicated this finding, and also demonstrated that the tendency to make the FAE is related to the degree to which the person reports being transported into the narrative of the TV drama. Furthermore, we showed that the tendency to attribute character traits to the actor is not diminished following exposure to the same actor playing two opposing roles. The last scene viewed was found to determine the evaluation of the actor’s characteristics.8

In security work, being on guard against the fundamental attribution error helps to smooth relations with other employees. For example, if a security group member sees an employee, Jill, who is not wearing her badge, it is easy to assume that she never wears her badge and is refusing to wear it because of a character flaw. The security officer may act according to these assumptions by being harsh or unfriendly in correcting Jill’s behavior. The harshness generates resentment, and Jill may come to associate security with unpleasant people, thus reducing the likelihood that she will comply with policy or encourage others to do so.

In fact, however, most people’s behavior is far less stable and internal than unstable and externally based. For example, if the security officer simply smiled and pointed gently to the lack of a badge instead of jumping to conclusions, he might discover that Jill’s lack of a badge today was due simply to her having taken her jacket off just before an urgent call from the vice president, interrupting her normal procedure of moving the badge from jacket to shirt pocket. Thus, her lack of a badge would not be stable behavior at all—it would be a temporary aberration of no longlasting significance. A solution would be to get used to clipping the badge to her trousers or her skirt instead of her jacket or her blouse. Similarly, just by asking nicely, the security officer might learn that Jill normally does wear her badge, but today her four-year-old son took it off her jacket to play with it, without his mother’s noticing the change. In this example, Jill’s behavior is externally based and has nothing to do with character. The kindly interactions between Jill and the security guard increase the sense of social relation and make it more likely that she will remember the incident positively and comply with the security policy in the future.

In summary, by being aware of the fundamental attribution error, security personnel can be trained to adopt a less judgmental, or quick-draw, mentality that can alienate other employees and damage security programs.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

RATIONALITY IS NOT ENOUGH 50 · 9

50.2.4.2 Actor-Observer Effect. The actor-observer effect consists of inter- preting one’s own behavior as appropriate unstable, externally motivated responses to environmental conditions, whereas other people’s behavior is viewed in the light of the fundamental attribution error as stable, internally motivated expressions of character traits. Becoming aware of this tendency helps security personnel resist the fundamental attribution error.

50.2.4.3 Self-Serving Bias. The counterpart of the actor-observer effect is the self-serving bias, which fools people into believing that their own behavior is due to stable, internal aspects of their character. Security officers who are unaware of this dangerous error may come to feel that they are in some sense superior to other people who do not know as much about security as they do or who do not comply as fully as they do with security policy. The officers may have failed to integrate the fact that hours of training and coaching by their security group leaders are at least as responsible for their own knowledge of, and compliance with, security policies as any innate superiority.

By bringing this kind of erroneous thinking to light during training and supervision of security staff, managers can help reduce the conflicts that naturally result from an air of assumed superiority.

50.2.4.4 Salience and Prejudice. When people are asked to guess which person in a group is the most influential (or least influential) person, social psychologists find that whichever person stands out the most, for whatever reason, is more often attributed with the special properties in question. Such effects apply to any characteristic that the psychologists ask about: most (or least) intelligent, aggressive, sympathetic, and so on. This phenomenon is known as the salience effect.

An application of the salience effect might occur if security officers see a group of employees who are violating security policies. A natural and counterproductive tendency is to leap to the conclusion that the tallest or shortest, the thinnest or fattest, the whitest or blackest person in the group must be to blame. This error can result in unfair treatment of perfectly innocent people.

This problem of misinterpreting salience is exacerbated by prejudice; for example, imagine there were an identifiable group called the Ogunians (as far as we can deter- mine, there is no such group) who traditionally wear, say, a seven-sided symbol of their identity. If an anti-Ogunian security officer sees a noncompliant group where one of the members is wearing the characteristic heptagon of Ogun, it may be hard for the officer to resist blaming the noncompliance on the Ogunian even if, in fact, the Ogunian was waiting to use a valid access card in full compliance with security policy.

Worse, people can be so strongly influenced by expectation—part of their schema—that they actually misperceive a situation altogether. For example, in some classic experiments studying prejudice in the 1950s, psychologists showed subjects a drawing of two people, one light-colored and the other dark-colored, standing in a tramway car. One was holding a knife. When questioned about the image afterward, white subjects consistently reported that the black figure had been holding the knife, but actually it was the white figure in the drawing who had the knife.

Thus, even observation itself can be twisted by prejudice and expectations; for example, if the anti-Ogunian security officer sees a group of people passing through an open doorway into a secured area without using their badges, the officer may incorrectly

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

50 · 10 USING SOCIAL PSYCHOLOGY TO IMPLEMENT SECURITY POLICIES

report that it was the fault of an Ogunian even if there was no Ogunian in the group. Such a mistaken report would not only infuriate innocent Ogunians and possibly cause general Ogunian resentment or hostility toward security efforts in general, but it also could mislead the security group itself into trying to correct the behavior of the wrong person or people.

Similarly, any minority—whether in terms of gender, gender orientation, religion, race, or disability—can be the focus of a prejudiced security officer’s blame when a group disobeys policy. Security leaders should make their staff aware of the danger of applying this erroneous method of explaining group behavior. In many organizations, such discrimination is a violation of corporate policy and may even be illegal. In any case, prejudice is not constructive and must be monitored and overcome.

50.2.5 Intercultural Differences. Many countries in the world are experienc- ing changes in their population due to immigration. Especially in areas where people have heretofore been largely homogeneous, cultural, religious, and racial diversity can lead to interpersonal and intergroup conflicts. Such conflicts may be based in part on prejudice, but they also may be the result of differing values and assumptions.

This definition of culture helps define the discussion:

Culture as Mental Programming Every person carries within him- or herself patterns of thinking, feeling, and potential acting that were learned throughout their lifetime. Much of it has been acquired in early childhood, because at that time a person is most susceptible to learning and assimilating. As soon as certain patterns of thinking, feeling, and acting have established themselves within a person’s mind, he or she must unlearn these before being able to learn something different, and unlearning is more difficult than learning for the first time.

Using the analogy of the way computers are programmed, this book will call such patterns of thinking, feeling and acting mental programs, or … software of the mind…

A customary term for such mental software is culture.9

Security personnel engaged in the process of corporate culture change should be sensitive to the possibility that people with different real-world cultural backgrounds can respond differently to proposed security policies. For example, in 2001 the fun- damentalist extremists of the Taliban in Afghanistan decreed that non-Muslim people would have to wear badges in public.10 One can imagine that a Hindu Afghan refugee in the United States who is told to wear a badge for security reasons might have an unexpectedly emotional response to the order. Before pressuring (or becoming hostile to) anyone who seems to be resisting a policy, it is valuable to inquire about the per- son’s beliefs and attitudes and to explain the foundation for the policies in question. Especially where there are intercultural differences, such inquiry and discussion can forestall difficulties and dissension and assuage unexpected, culturally rooted anxiety.

Security professionals need to be acutely aware of the cultural differences of individ- uals in their target audiences. For example, in some cultures (mostly the new world and western), reality is directly related to facts and verifiable calculations. Other cultures may put a stronger emphasis on personal feelings, intuition, and culturally ingrained beliefs into their comprehension of reality. Hence different people may not share the same understanding of reality or implement policies by the same principles unless they make their assumptions known and discuss them with the intention of coming to agreement.

When considering culture, the changing dynamics of modern society also need to be accounted for. Any modern city or leading public institution today is a complex

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

RATIONALITY IS NOT ENOUGH 50 · 11

combination of people from different cultural and social backgrounds. Working to- gether for large parts of their active days together as a group leads to a melting pot situation, with all the individual cultures and social leanings being added into the mix and emerging as a (mostly) different culture. The individuals then take this new culture back home, where it mixes in with their family and friends’ contributions, resulting in often more modifications and variation. The organization itself is constantly changing, as people join and leave. All of this leads to culture being a dynamic phenomenon, albeit not as rapidly changing as the technology front. Hence, any security policy or framework needs to be able to account for and accommodate this changing paradigm if it has to be successful in securing the enterprise.

50.2.6 Framing Reality. How can we make the corporate culture more sup- portive of IA?

Schemata influence what we perceive. For example, an employee refuses to take vacations, works late every night, is never late, and is never sick. A model employee? Perhaps, in one schema. From the security point of view, the employee’s behavior is suspect. There have been cases where such people have been embezzlers unable to leave their employment: Even a day away might result in discovery of their crimes. Saint or sinner? Our expectations determine what we see.11

Tochange the schema sothat people take IAseriously, we shouldprovide participants in training and security awareness with real-life examples of computer crime and security breaches, so that security policies make obvious sense rather than seeming to be arbitrary.

Schemata influence what we remember. When information inconsistent with our preconceptions is mixed with details that fit our existing schemata, we selectively retain what fits and discard what conflicts. When we have been fed a diet of movies and television shows illustrating the premise that information is most at risk from brilliant hackers, why should we remember the truth: that carelessness and incompetence by authorized users of information systems cause far more harm than evil intentions and outsiders ever do?

Instructors should emphasize the practical side of IA by showing how policies protect all employees against false accusations, prevent damage to the organization’s reputation and profits, and even play a role in national security. This is especially true where business touches the technical infrastructure on which we all depend.

Most important of all, teaching others about IA cannot be an occasional and hap- hazard affair. Before attempting to implement policies and procedures (aside from emergency measures that are needed at once), we should ensure that we build up a con- sistent view of IA among our colleagues. In light of the complexity of social cognition, our usual attempts to implement security policies and procedures seem pathetically inept. A couple of hours of lectures followed by a video, a yearly ritual of signing a security policy that seems to have been written by Martians—these are not methods that will improve security. These efforts merely pay lip service to the idea of security.

According to research on counterintuitive information, people’s judgment is influ- enced by the manner in which information is presented. For example, even information contrary to established schemata can be assimilated if people have enough time to inte- grate the new knowledge into their worldviews. It follows that nonemergency security policies should be introduced over a long time, not rushed into place.

An effective IA program includes frequent reminders of security. To change the corporate culture, practitioners should use methods such as a security corner in the corporate publication, security bulletins detailing the latest computer crime or security

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

50 · 12 USING SOCIAL PSYCHOLOGY TO IMPLEMENT SECURITY POLICIES

breach that has hit the news, contests for identifying the problems in realistic scenarios, and write-in columns to handle questions about policies. IA has to become part of the framework of reality, not just an imposition from management.

In every security course or awareness program, instructors and facilitators should explicitly address the question of corporate culture, expectations, and social schemata. Do not rely solely on intellectual discourse when addressing a question of complex perceptions and feelings. Use simulations, videos, and role-playing exercises to bridge the gap between intellect and emotion.

Address the feelings and perceptions of all participants as they learn about the counterintuitive behaviors that improved security will demand. Encourage learners to think about how they might feel and respond in various situations that can arise during the transition to a more secure environment. For example, ask participants to imagine:

� Asking colleagues not to step through a secured entrance without passing through the access-control system with their own identity

� Telling their boss that they will not copy software without a license to do so � Questioning a visitor or employee who is not wearing an identity badge12

50.2.7 Getting Your Security Policies Across. What are some ways to change our colleagues’ schemata so that they become more receptive to IA policies?

� Initial exposure. Preliminary information may influence people’s responses to information presented later. For example, merely exposing experimental subjects to words such as reckless or adventurous affects their judgment of risk-taking behavior in a later test.

It follows that when preparing to increase employee awareness of security issues, presenting case studies is likely to have a beneficial effect on participants’ readiness to examine security requirements.

� Counterexamples. Preexisting schemata can be challenged by several counterex- amples, each of which challenges a component of the schema. For example, prejudice about an ethnic group is more likely to be changed by contact with several people, each of whom contradicts a different aspect of the prejudiced schema.

It follows that security awareness programs should include many realistic examples of security requirements and breaches. In a counterexample, students in college IA courses have commented on the unrealistic scenario in a training video they were shown: a series of disastrous security breaches occurring in the same company. Based on the findings of cognitive social psychologists, the film would be more effective for training if the incidents had been dramatized as occurring in different companies.

In practical terms, practitioners should stay current and update their materials. Many IA publications provide useful case studies that will help make awareness and training more effective.

� Choice of wording. Perceptions of risks and benefits are profoundly influenced by the wording in which situations and options are presented. For example, experi- mental subjects responded far more positively to reports of a drug with “50 percent success” than to the same drug described as having “50 percent failure.”

It follows that practitioners should choose their language carefully during secu- rity awareness campaigns. Instead of focusing on reducing failure rates (violations

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

BELIEFS AND ATTITUDES 50 · 13

of policy), we should emphasize improvements in our success rates. Unfortunately, some rates cannot be expressed in positive terms; for example, it is not easy to measure the success rate of security measures designed to foil attacks on systems.

Judgments are easily distorted by the tendency to rely on personal anecdotes, small samples, easily available information, and faulty interpretation of statistical information. Basically, we humans are not always rational processors of factual information. If security awareness programs rely strictly on presentation of factual information about risks and proposed policies and procedures, they are likely to run up against a stubborn refusal to act logically. Security program implementation must engage more than the rational mind. We must appeal to our colleagues’ imagination and emotion as well. We must inspire a commitment to security rather than merely describing it.

50.2.8 Reward versus Punishment. When enforcing security policies, too many organizations focus entirely on punishing those who break the rules. However, everything we know about modifying behavior teaches us to use reward rather than punishment. Punishing people who do not comply with security rules often generates resentment and hostility that carry over into future interactions. Instead of seeing infor- mation assurance as a benefit to the organization and to their interests, victims of harsh treatment can resist even well-intentioned, sensible changes in security policies simply because of the emotional overlay associated with the embarrassment and frustration generated by criticism and penalties.

In addition to avoiding negativity and push-back, reward may simply work better than punishment at changing behavior. For example, a security officer from a large cor- poration experimented with reward and punishment in implementing security policies. Employees were supposed to log off their mainframe terminals when leaving the of- fice, but compliance rates were only around 40 percent. In one department, the security officer used the usual techniques recommended in the literature and common among security professionals; for example, she put up nasty notes on terminals that were not logged off, changed the passwords on delinquent accounts, and humiliated violators by forcing them to report to their bosses for authorization to obtain a new password. However, in a different department, she simply left a Hershey’s Chocolate Kiss on the keyboard of every terminal whose user had indeed logged off before leaving. After one month of these two strategies, compliance rates in the department subject to punishment had climbed to around 60 percent. Compliance in the department getting chocolates had reached around 80 percent—and their feelings toward security were much more favorable than the norm.

This case illustrates some of the benefits of reward:

� Compliance rates were significantly higher than in the group subjected to punishment.

� Attitudes (see Section 50.3) are more likely to be positive. � Costs can be lower because small rewards delivered en masse may be much cheaper and quicker to apply than administrative procedures applied one by one through management intervention.

50.3 BELIEFS AND ATTITUDES. Psychologists distinguish between beliefs and attitudes. A belief refers to cognitive information that need not have an emotional component. An attitude refers to an evaluation or emotional response. Thus, a person

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

50 · 14 USING SOCIAL PSYCHOLOGY TO IMPLEMENT SECURITY POLICIES

may believe correctly that copying a large number of proprietary software packages without authorization is a felony while nonetheless having the attitude that it does not matter to him. A rational employee may believe that malware can be downloaded onto company computers through unauthorized software available on unvetted Websites (and thus answer a questionnaire evaluating security awareness correctly) yet have the attitude that the risk is negligible—and cheerfully go on downloading unauthorized software at work.

50.3.1 Beliefs. Beliefs can change when contradictory information is presented, but some research suggests that it can take up to a week before significant shifts are measurable. Other studies suggest that when people hold contradictory beliefs, providing an opportunity to articulate and evaluate those beliefs may lead to changes that reduce inconsistency.

These findings imply that corporate security must explore the current structure of beliefs among employees and managers. Questionnaires, focus groups, and interviews may not only help the security practitioner, they actually may help move the corporate culture in the right direction. The Hawthorne Effect is the name given to improvements in measured behavior resulting simply from employee responses to being studied; done correctly, honestly, and nonpunitively, inquiring into employee beliefs and attitudes may communicate a genuine interest by management in improving security policy and practice with input from everyone involved.

50.3.2 Attitudes. An attitude, in the classical definition, is a learned evaluative response, directed at specific objects, which is relatively enduring and influences be- havior in a generally motivating way. The advertising industry spends over $50 billion yearly to influence public attitudes in the hope that these attitudes will lead to changes in spending habits—that is, in behavior.

Research on classical conditioning suggests that attitudes can be learned even through simple word association. If we wish to move our colleagues toward a more negative view of computer criminals, it is important not to portray computer crime us- ing positive images and words. Movies that show criminal hackers as pleasant, smart, physically attractive, and likable people may do harm by minimizing the seriousness of industrial espionage and cybervandalism. When teaching security, we should avoid praising the criminals we describe in case studies.

Studies of how attitudes are developed consistently show that rewards and punish- ments are important motivators of behavior. Studies show that even apparently minor encouragement can influence attitudes. A supervisor or instructor should praise any comments that are critical of computer crime or that support the established secu- rity policies. Employees who dismiss security concerns, or who flout the regulations, should be challenged on their attitudes, not ignored. Such challenges are best carried out in private to avoid causing embarrassment to the skeptics and possibly generating resistance due to pride or a sense of machismo.

50.3.3 Changing Attitudes toward Security. Persuasion—changing someone’s attitudes—has been described in terms of communications. The four ar- eas of research include:

1. Communicator variables. Who is trying to persuade? 2. Message variables. What is being presented?

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

BELIEFS AND ATTITUDES 50 · 15

3. Channel variables. By what means is the attempt taking place? 4. Audience variables. At whom is the persuasion aimed?

50.3.3.1 Communicator Variables. Attractiveness, credibility, and social status have strong effects immediately after the speaker or writer has communicated with the target audience; however, over a period of weeks to a month, the effects decline until the predominant issue is message content. We can use this phenomenon by identifying the senior executives most likely to succeed in setting a positive tone for subsequent security training. We should look for respected, likable people who understand the issues and sincerely believe in the policies they are advocating.

One personality style in particular can threaten the success of security policies: the authoritarian personality. A body of research suggests that some people, often those raised by punitive parents highly concerned with social status, become rigidly devoted to conventional beliefs, submit to authority, exercise authority harshly themselves, and are hostile to groups they perceive as unpopular. An authoritarian person might make a terrible security officer. Such an officer might derive more satisfaction from order- ing people around and punishing them than from long-term success in implementing security policies.

50.3.3.2 Message Variables. Fear can work to change attitudes only if ju- diciously applied. Excessive emphasis on the terrible results of poor security is likely to backfire, with participants in the awareness program rejecting the message alto- gether. Frightening consequences should be coupled immediately with effective and achievable security measures.

Some studies suggest that presenting a balanced argument helps convince those who initially disagree with a proposal. Presenting objections to a proposal and offering counterarguments is more effective than one-sided diatribes. Popular training videos from the Software & Information Industry Association use this technique: they show people such as “college students, college faculty and publishers of all types of media discuss[ing] the legal and ethical implications of copying other people’s works” and fairly present the arguments of copyright violators before rebutting them.13

Modest repetition of a message can help generate a more positive response. Thus, security awareness programs that include imaginative posters, mugs, special newslet- ters, audio and videotapes, and lectures are more likely to build and sustain support for security than occasional intense sessions of indoctrination. The use of multiple com- munications channels (discussed in the next section) also increases the effectiveness of the message.

50.3.3.3 Channel Variables. The channel through which we communicate has a strong effect on attitudes and on the importance of superficial attributes of the communicator. In modern organizations, most people assume that a meeting is the ideal way to communicate new information. However, the most effective medium for convincing someone to pay attention to any topic is face-to-face persuasion. Security training should include more than tapes and books; a charismatic teacher or leader can help generate enthusiasm for—or at least reduce resistance to—better security.

In addition, security educators should not introduce new ideas to decision makers in a meeting. There is too much danger of confounding responses to policy with nonpolicy matters rooted in relationships among the participants. It is not uncommon for one executive to oppose a new policy simply because another has supported it. A good way

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

50 · 16 USING SOCIAL PSYCHOLOGY TO IMPLEMENT SECURITY POLICIES

to introduce security policies is to have individual meetings with one executive at a time in order to explain the issues and proposals and to ask for support.

Psychologists testing cognitive response theory have studied many subtle aspects of persuasion. Experiments have shown that rhetorical questions, such as “Are we to accept invasions of our computer systems?” are effective when the arguments are solid but counterproductive when arguments are weak. Security officers should not ask rhetorical questions unless they are certain that almost everybody will inevitably have the same answer—the one the security officers are looking for.

Consideration of facts and logical arguments, as the central route to persuasion, has been found to lead to more lasting attitudes and attitude changes than the peripheral influences from logically unrelated factors, such as physical attractiveness of a speaker.

50.3.3.4 Audience Variables. As mentioned, questionnaires and interviews may help cement a favorable change in attitude by leading to commitment. Once employees have publicly avowed support for better security, some will begin to change their perception of themselves. Specific employees should be encouraged to take on various areas of public responsibility for IA within their work group. These roles should periodically be rotated among the employees to give everyone the experience of public commitment to improved security.

To keep up interest in security, regular meetings of enthusiasts to discuss recent security news can keep the subject fresh and interesting. New cases can help secu- rity officers explain policies with up-to-date references that will interest their fellow employees and motivate managers to pay attention to security policies.

50.4 ENCOURAGING INITIATIVE. The ideal situation would be for every- one actually to help enforce security policies. Actually, however, some people are cooperative and helpful whereas others—or even the same people in different circumstances—are reluctant and suspicious about new policies. What can we do to increase cooperation and reduce rejection?

50.4.1 Prosocial Behavior. Studies of people who have come to the aid of oth- ers can help to encourage everyone in an organization to do the right thing. Some people intervene to stop crimes; others ignore crimes or watch passively. Social psychologists have devised a schema that describes the steps leading to prosocial behavior:

1. People have to notice the emergency or the crime before they can act. Thus, security training has to include information on how to tell that someone may be engaging in computer crime.

2. The situation has to be defined as an emergency—something requiring action. Security training that provides facts about the effects of computer crime on society and solid information about the need for security within the organization can help employees recognize security violations as emergencies.

3. Everyone must take responsibility for acting, but the larger the number of people in a group confronted with an emergency, the slower the average response time. Larger groups seem to lead to a diffusion of responsibility; each person feels that someone else is more responsible for dealing with the emergency. Another possi- ble factor is uncertainty about the social climate; people fear appearing foolish or overly emotional in the eyes of those present. To overcome this effect, a corporate

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

ENCOURAGING INITIATIVE 50 · 17

culture must be established that rewards responsible individual behavior, such as reporting security violations.

4. Once responsibility for solving a problem has been accepted, appropriate deci- sions and actions must be taken. Clearly written security policies and procedures will make it more likely that employees act to improve security. In contrast, contradictory policies, poorly documented procedures, and inconsistent support from management will interfere with the decision to act.

Another analysis proposes that people implicitly analyze costs of helping and of not helping when deciding whether to act prosocially. The combination of factors most conducive to prosociality is low cost for helping and high cost for not helping.

Security procedures should make it easy to act in accordance with security policy. There should be a hotline for reporting security violations, and anonymity should be respected if desired. Psychological counseling and follow-up should be available if people feel upset about their involvement. Conversely, failing to act responsibly should be a serious matter; personnel policies should document clear and meaningful sanctions for failing to act when a security violation is observed. Penalties would include critical remarks in employment reviews and, where appropriate, even dismissal.

One method that does not work to increase prosocial behavior is exhortation; merely lecturing people in the abstract about what they ought to do has little or no positive effect.

Significantly, the general level of stress and pressure to focus on difficult tasks with seemingly impossible deadlines can greatly reduce the likelihood that people will act on their moral and ethical principles. Security is likely to flourish in an environment that provides sufficient time and support for employees to work professionally. Offices where everyone responds to a continuing series of apparent emergencies will not be likely to pay attention to security violations.

Some findings from research confirm common sense. For example, guilt motivates many people to act more prosocially. This effect works best when people are forced to assume responsibility. Thus, enforcing standards of security using reprimands and sanctions can indeed increase the likelihood that employees subsequently will act more cooperatively; however, as suggested earlier, punishment should not replace reward.

In addition, mood affects susceptibility to prosocial pressures. Bad moods make prosocial behavior less likely, whereas good moods increase prosociality. A working environment in which employees are respected is more conducive to good security than one that devalues and abuses them.

Even cursory acquaintance with other people makes it more likely that we will help them; it thus makes sense for security supervisors to get to know the staff from whom they need support. Encouraging social activities in an office (e.g., lunchtime discussion groups, occasional parties, and charitable projects) enhances interpersonal relationships and can improve the climate for effective security training. Management by walking around is an excellent practice at many levels, including fostering at least the first stage of interpersonal relationship among coworkers.14

50.4.2 Conformity, Compliance, and Obedience. Some people react negatively to the words conformity, compliance, and obedience, but ignoring social phenomena will not help security practitioners to attain their goals. Despite the unpop- ularity of this subject area, it is valuable to understand how people can work together in reinforcing security policies. The next sections look at how to increase conformity

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

50 · 18 USING SOCIAL PSYCHOLOGY TO IMPLEMENT SECURITY POLICIES

with a culture of cooperation for increased security, compliance with rational security rules, and a bias toward obedience to IA authorities in security matters.

50.4.2.1 Social Pressure and Behavior Change. Turning a group into a community provides a framework within which social pressures can operate to improve an organization’s IA. Most people respond to the opinions of others by shifting their own opinions, sometimes unconsciously, toward what statisticians call the mode—the most popular opinion. Security programs must aim to shift the normative values, the sense of what one should do, toward protecting confidentiality, possession or control, integrity, authenticity, availability, and utility of data.

According to an informal survey conducted by Mani Akella, a coauthor of this Chapter, at three leading financial firms on Wall Street, these inferences resulted from a test group of 80 respondents:

� Older employees prefer to model their reactions based on common group prefer- ences, even if some of the reactions go against their own gut feeling. The rationale here seems to be that the group provides anonymity and even insulates them from management reaction. Younger employees, however, tend to buck the group trend when they disagree with proposed concepts.

� Leadership has a large role to play—and the group modifies its reactions very quickly to adapt to leadership changes. If the leader likes to follow a specific path and not ask questions, the entire group tends to let issues lie and not disturb the even tenor of the organization for fear of disturbing the leader, even at the cost of risking serious potential security lapses (see Section 50.5.4 on groupthink). If the leader fosters a dynamic, open, and collaborative environment with a measured adaptability to evolving threats, however, the group enlivens itself with innovation and puts out additional effort to stay abreast (or even ahead) of the current threat landscape.

� When the leaders challenge the individuals to greater achievement without threats of punitive reaction, the group reacts with positive response. Leadership can create a security environment that can exceed the enterprise’s security expectations by encouraging the individual to increase productivity and to reward oneself with greater job satisfaction. Security, like most other organizational management efforts, is all about people. Responsible, satisfied, and aware personnel naturally lead to better overall security for the organization.

50.4.2.2 Changing Expectations. As has been evident in public campaigns aimed at eliminating drunken driving, it is possible to shift the mode. In the United States in the mid-twentieth century, many people believed that driving while intoxicated was amusing; today, a drunken driver is a social pariah. High school children used to kill themselves in large numbers on the nights of their high school proms; today, many children spontaneously are arranging for safe rides home. In much the same way, we must move toward making computer crime as distasteful as public drunkenness.

The trend toward similar behavior increases when people within the group like or admire each other. In addition, the social status of an individual within a group influences that individual’s willingness to conform to group standards. High-status people (those liked by most people in the group) and low-status people (those disliked by the group) both tend to be more autonomous and less compliant than people liked by some and disliked by others. Therefore, security officers should pay special attention

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

ENCOURAGING INITIATIVE 50 · 19

to those outliers during instruction programs. Managers should monitor compliance more closely at both ends of the popularity range. If security practices are currently poor, and allies are needed to change the norm, working with the outliers to resist the majority’s anti-security bias may be the most effective approach. The most popular people may be disastrous agents of rebellion if they do not sign on to the security program; paradoxically, the most unpopular people may be helpful if they can be persuaded to comply.

50.4.2.3 Norm of Reciprocity. According to social psychologists, the norm of reciprocity indicates that, in social relations, favors are usually returned. Even a small, unexpected, unsolicited, or even unwanted gift increases the likelihood that we will respond to requests. For example, members of various religious cults often hand out flowers or books at airports, knowing that the norm of reciprocity will increase the frequency and amount of donations from basically uninterested passersby.

A security awareness program that includes small gifts, such as an attractive mug labeled “SECURITY IS EVERYONE’S BUSINESS” or an inexpensive but useful booklet summarizing security policies, can help get people involved in security. The combination of such programs with rewards for compliance can be a powerful tool for improving security.

Combining a token of appreciation with direct personal contact starting with the statement “I need your help” followed by a frank exposition of the security situation can be positive at all levels. This approach works at multiple levels—establishing personal relations, building on the norm of reciprocity, and changing the schema.

50.4.2.4 Incremental Change. The foot-in-the-door technique suggests that a small initial request should be followed by an even larger second one. Political field workers, for example, know that they can start small by asking people to let them put candidate stickers in their window; then they ask to put a candidate’s poster on their lawn; eventually they can ask for volunteer time or money. Every compliance with a request increases the likelihood that the person will agree to the next step in an escalating series. It is as if agreeing to one step helps to change the targets’ sense of themselves. To reduce discomfort about their beliefs and their behavior (what psychologists call cognitive dissonance), people change their beliefs to conform with their behavior.

Employees can be asked personally to set a good example by blanking screens and locking terminals when leaving their desks. Later, once they have begun the process of redefining themselves (“I am a person who cares about computer security”), they can be asked for something more intense, such as participating in security training by asking others to blank their screens and lock their terminals—or rewarding those who do with the famous chocolate tidbit. By applying the same methods to various tasks, the corporate culture can change so that a majority of people feel personally committed to good security practices.

Some security specialists have proposed that we should not ask the audience to think. The reasoning is that each incremental policy step should not require the target audience to reason or explain behavior. Rather, focus on building conditioned reflexes to specific environmental and usage factors. The organization and the security team should be more assured of a common and predictable reaction to any security threat from each individual internal person. However, a countervailing view is that every behavior proposed to improve security must be grounded in an understandable schema. In other words, although one need not force the members of the audience to articulate

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

50 · 20 USING SOCIAL PSYCHOLOGY TO IMPLEMENT SECURITY POLICIES

the rationale, the rules must make sense if they are to be integrated, remembered, and applied in the long term.

50.5 GROUP BEHAVIOR. Some groups of people are referred to as teams, while others are called gangs. Social psychological insights into group behavior can improve success rates for IA policies.

50.5.1 Social Arousal. Studies on the behavioral effects of being in groups produced contradictory results; sometimes people did better at their tasks when there were other people around, and sometimes they did worse. Eventually, psychologists realized that the presence of other people is socially arousing; that is, people become more aware both of their own behavior and of social norms when they are in groups. Social arousal facilitateswell-learnedhabits,but it inhibitspoorlylearnedhabits. Thus, when trying to teach employees new habits to improve security, it is counterproductive to put them into large groups. Individualized learning (e.g., by means of computer- based training and videotapes) can overcome inhibitory effects of groups in the early stages of behavioral change.

50.5.2 Locus of Control. Another factor that interferes with implementation of security policies is the locus of control. People do not like feeling that they have no control over their environment. For example, in a classic experiment reported in social psychology textbooks, two equivalent teams of people were both subjected to loud and disruptive noise coming through a loudspeaker in their work area. One group had no control whatever over the noise, whereas the other had a large button with which they could stop the noise at once. The group with the stop button did noticeably better at their complex task than the other group—yet in no case did anyone actually press the button. Simply feeling that they could exert control, if they wanted to, significantly altered the performance of the experimental subjects.

Similarly, in studies of healing among older patients, three groups were defined: (1) controls, (2) people given a plant in a pot, and (3) people given a plant in a pot plus instructions to water it regularly. The third group did significantly better than the second in their recovery. Once again, the sense of control over the environment appeared to influence outcomes.

In security policy implementation, experience confirms that those organizations with the most participation and involvement by all sectors do best at developing and implementing information protection plans. A common phrase that refers to this phenomenon is buy-in, as in: “The different departmental representatives felt that they could genuinely buy into the new policies because they had fully participated in framing them.”15

50.5.3 Group Polarization. Another branch of research into group psychol- ogy deals with group polarization. Groups tend to take more extreme decisions than would individuals in the group acting alone. In group discussions of the need for se- curity, polarization can involve deciding to take more risks—by reducing or ignoring security concerns—than any individual would have judged reasonable. Again, one-on- one discussions of the need for security will generally be more effective in building a consensus that supports cost-effective security provisions than will large meetings.

50.5.4 Groupthink. In the extreme, a group can display groupthink, in which a consensus is reached because of strong desires for social cohesion. When groupthink prevails, evidence contrary to the received view is discounted; opposition is viewed

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TECHNOLOGICAL GENERATION GAPS 50 · 21

as disloyal; dissenters are discredited. Especially worrisome for security profession- als, those people in the grip of groupthink tend to ignore risks and contingencies. To prevent such aberrations, the leader must remain impartial and encourage open de- bate. Respected security consultants from the outside could be invited to address the group, bringing their own experiences to bear on the group’s requirements. After a consensus—not the imposition of a dominant person’s opinions—has been achieved, the group should meet again and focus on playing devil’s advocate to try to come up with additional challenges and alternatives.

In summary, security experts should pay attention to group dynamics and be pre- pared to counter possible dysfunctional responses that interfere with acceptance of IA policies.

50.6 TECHNOLOGICAL GENERATION GAPS. In our society there are grow- ing societal gaps between the social groups that grew up interacting in real-world com- munities (unwired), groups that grew up with the Internet (wired), and the newest group growing up with the always-on technology of our complex and content-rich wireless social networks.

� The unwired generation. In today’s always-on world of ubiquitous wireless communications, we sometimes forget about the unwired generation, those born in the early 1960s or before, who grew up actually playing outside with their friends and communicating face to face. For these older employees, online discussion groups, streaming video training, blogs, and email may not be as effective as with other, more technological groups. The unwired generation may see the use of impersonal technology in training as an indicator of management apathy toward a topic that is not worth taking the time for real-world interaction. To this generation, if security training is important, someone should take the time to deliver it face to face. The unwired generation is also the most susceptible to many of the social psychology techniques and pitfalls discussed in this chapter.

� The wired generation. Those born from the early 1960s to the late 1970s comprise the wired generation. This transitional generation grew up at the dawn of the Internet from 300 baud dial-up access to ISDN. From MS DOS to Windows 98 and from Cobol to C++, this generation is the bridge from the real world to the cyberworld. This generation is also the generation currently coming to power in both business and government. Although accustomed to meeting face to face for important business, the wired generation lives by email and cell phones, tolerating both the unwired and wired methods of communicating and learning.

� The always-on generation. Those born after 1980 comprise the always-on gener- ation. This generation grew up with high-speed Internet, cell phones, video games, portable electronics, and online virtual communities. This is the connected, net- worked, Facebook, video-game generation. It is this generation that seems to confound traditional security screening and implementation policy.

Although the unwired and wired generations shared psychological roots in the real world, the always-on generation has two homes: the real world and the cyberworld. With instant messaging (IM), texting (Short Message Service, or SMS), and cellular wireless, this generation moves in and out of cyberspace as the previous generation moved between the worlds of work and home. Moreover, like the previous generations, the always-on generation has different psychological and sociological frameworks for their worlds—a serious information assurance concern.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

50 · 22 USING SOCIAL PSYCHOLOGY TO IMPLEMENT SECURITY POLICIES

To the unwired and wired generations, personal communication meant face to face. To the always-on generation personal, communication means IM, email, and smart phones. In addition, social interaction often means social networking, blogs, Web pages, message boards, and wikis. Add to this the fact that the always-on generation has a keen ability to quickly transfer information between their tightly integrated worlds, and you have the ingredients for a security officer’s nightmare.

Recognizing these differences and reacting accordingly can pay sizable dividends in both security compliance and general management success. As a first step, one can ensure that security teams include members from more than the oldest generation in the enterprise; younger people may be able to act as intermediaries or translators between increasingly disparate cultures.

50.7 SUMMARY OF RECOMMENDATIONS. This chapter has reviewed the major findings of social psychology that can help to improve IA programs. These ideas can prove useful to readers who think about social psychology as they work to implement security policies:

� Recognize that IA policies often conflict with the schema for trusting, polite behavior in situations outside the work arena.

� Train IA personnel to recognize that failure to comply with security policies may be rooted in many other factors than simply bad attitude.

� Listen more than you command. � Teach security personnel to avoid the classic errors of attribution when trying to understand their colleagues’ motivations.

� Openly discuss and counter prejudice before it causes conflicts. � Take intercultural differences into account when setting and implementing security policies.

� Before attempting to implement policies and procedures, ensure a consistent view of IA among colleagues.

� Whenever possible, security policies should be introduced over a long time, not rushed into place.

� Presenting case studies is likely to have a beneficial effect on participants’ readi- ness to examine security requirements.

� Security awareness programs should include many realistic examples of security requirements and breaches.

� Attempt to inspire a commitment to security rather than merely describing it. � Emphasize improvements rather than reduction of failure. � Create a new concern for corporate security by exploring the current structure of beliefs among employees and managers.

� Never portray computer crime using positive images and words. � Praise any comments that are critical of computer crime or that support the established security policies.

� Employees who dismiss security concerns or flout the regulations should be challenged on their attitudes, not ignored.

� Identify the senior executives most likely to succeed in setting a positive tone for subsequent security training and engage their cooperation to act as role models.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

SUMMARY OF RECOMMENDATIONS 50 · 23

� Examples of frightening consequences used in awareness and training materials should be coupled immediately with descriptions of effective and achievable security measures to forestall such consequences.

� Presenting objections to a proposal and offering counterarguments is more effec- tive than one-sided diatribes.

� Security-awareness programs should include many, frequent, and preferably novel and entertaining reminders of security issues.

� In addition to tapes and books, rely on a charismatic teacher or leader to help generate enthusiasm for better security.

� Encourage specific employees to take on public responsibility for IA within their work groups.

� Rotate security roles periodically. � Security training should include information on how to tell that someone may be engaging in computer crime.

� Build a corporate culture that rewards responsible behavior, such as reporting security violations.

� Develop clearly written security policies and procedures. � Security procedures should make it easy to act in accordance with security policy. � Treat failures to act in accordance with security policies and procedures as very serious matters.

� Enforcing standards of security can increase the likelihood that employees will subsequently act more cooperatively.

� A working environment in which employees are respected is more conducive to good security than one that devalues and abuses them.

� Get to know the staff from whom you need support. � Encourage social activities in the office. � Pay special attention to social outliers during instruction programs. � Monitor compliance more closely at both ends of the popularity range. � Work with the outliers to resist a group’s antisecurity bias. � Include small gifts in your security-awareness program. � Start improving security a little at a time, and work up to more intrusive procedures. � Before discussing security at a meeting, have one-on-one discussions with the participants.

� Remain impartial, and encourage open debate in security meetings. � Bring in experts from the outside when faced with groupthink. � Meet again after a consensus has been built, and play devil’s advocate. � Recognize the generational technology gaps in our culture and communicate accordingly; therefore, include people from different generations in your security teams.

None of these suggestions is essential; none of them is appropriate in all situations. However, building on the accumulated experience and wisdom of social psychologists will support the smooth integration of information assurance into any corporate culture. We hope that readers will explore the literature of social and organizational psychology

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

50 · 24 USING SOCIAL PSYCHOLOGY TO IMPLEMENT SECURITY POLICIES

and will try out new ideas that will enrich the field of information assurance in years to come.

50.8 FURTHER READING Adler, N. J., and A. Gunderson. International Dimensions of Organizational Behavior,

5th ed. South-Western College Publications, 2007. Bik, O. The Behavior of Assurance Professionals: A Cross-Cultural Perspective.

Eburon Academic Publishers, 2010. Greenberg, J. Managing Behavior in Organizations, 6th ed. Prentice-Hall, 2012. Kreitner, R., and A. Kinicki. Organizational Behavior, 9th ed. McGraw-Hill, 2009. Kowert, P. Groupthink or Deadlock: When Do Leaders Learn from Their Advisors?

State University of New York Press, 2002. Lesko, W. A. ed. Readings in Social Psychology: General, Classic, and Contemporary

Selections, 8th ed. Pearson, 2011. Mills, J. H., K. Dye, and Al. J. Mills. Understanding Organizational Change. Rout-

ledge, 2008. Myers, D. G. Social Psychology, 11th ed. McGraw-Hill Humanities, 2012. Myers, D. G. Exploring Social Psychology, 7th ed. McGraw-Hill Higher Education,

2014. Prestwich, A., and M. Conner. Applied Social Psychology. Wiley-Blackwell, 2014. Senior, C., and M. Butler. Social Cognitive Neuroscience of Organizations. Wiley-

Blackwell, 2008. Smith, E. R., and D. M. Mackie. Social Psychology, 3rd ed. Psychology Press, 2007.

50.9 NOTES 1. This chapter is based on original work by M. E. Kabay as a contributed paper

at the Sixteenth National Computer Security Conference organized in 1993 by the National Computer Security Center. That work was updated over the years and became a chapter in the fourth edition of this Handbook. It was updated for the fifth edition with contributions from colleagues teaching and studying in the MSIA (now MISA) program at the School of Graduate and Continuing Studies at Norwich University. This version includes minor updates and new suggested readings.

2. Few specific references to the scholarly literature of social psychology research are included in this chapter except for quoted materials. For details of the information presented, consult any college-level introduction to social psychology.

3. J. Baron, Thinking and Deciding, 4th ed. Cambridge University Press, 2007 4. Government Accountability Office, “Information Security: Emerging Cybersecu-

rity Issues Threaten Federal Information Systems,” United States Government Accountability Office Report GAO-05-231 (May 2005); www.gao.gov/new.items/ d05231.pdf

5. M. E. Kabay, “The VA Data Insecurity Saga.” (2008), www.mekabay.com/ infosecmgmt/vasaga.pdf

6. R. D. Austin and C. A. R. Darby, “The Myth of Secure Computing,” Harvard Business Review (June 2003); http://cb.hbsp.harvard.edu/cb/web/product detail .seam;?E=71608&R=R0306J-PDF-ENG

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

NOTES 50 · 25

7. For an in-depth discussion of the manager’s role in IA, see Chapter 63 in this Handbook; for a discussion of the role of the chief information security officer, see Chapter 65.

8. N. Tal-Or and Y. Papirman, “The Fundamental Attribution Error in Attributing Fictional Figures’ Characteristics to the Actors.” Paper presented at the annual meeting of the International Communication Association, Sheraton New York, New York, NY, April 13, 2008; www.allacademic.com/meta/p13476 index.html

9. G. Hofstede, G. J. Hofstede, and M. Minkov, CulturesandOrganizations:Software of the Mind, 3rd ed., McGraw-Hill, 2010.

10. S. Salahuddin, “Taliban Defend Yellow Badges for Non-Muslim Afghans,” Reuters, May 23, 2001; www.afghanistannewscenter.com/news/2001/may/ may23c2001.html

11. See Chapter 45 in this Handbook for a discussion of such an example. 12. For more ideas on effective security-awareness programs, see Chapter 49. 13. SIIA Resource eStore: www.siia.net/estore/10browse.asp and choose Category=

Anti-piracy 14. See FUTURECents, “Management by Walking Around, www.futurecents.com/

mainmbwa.htm; and A. Fisher, “Management by Walking Around: 6 Tips to Make it Work,” CNNMoney, August 23, 2012, http://management.fortune.cnn.com/ 2012/08/23/management-by-walking-around-mbwa/

15. See Chapter 66 in this Handbook for a discussion of the importance of widespread participation in security-policy development.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51CHAPTER

SECURITY STANDARDS FOR PRODUCTS

Paul Brusil and Noel Zakin

51.1 INTRODUCTION 51 · 1

51.2 IMPORTANCE OF STANDARDS 51 · 2 51.2.1 Value of Standards 51·2 51.2.2 Motivation for

Establishing Trust and Managing Risk in Products 51·3

51.2.3 Motivation for Establishing Trust in Systems 51·4

51.3 TYPES, SOURCES, AND EXAMPLES OF STANDARDS 51 · 4 51.3.1 Types of Standards 51·5 51.3.2 Sources of Standards 51·5 51.3.3 Examples of Security

Standards 51·7

51.4 PRODUCT DEVELOPMENT AND ASSESSMENT APPROACHES 51 · 9 51.4.1 Historical,

Sunsetted Approaches 51·10

51.4.2 Consensus Security Specification Approaches 51·10

51.4.3 Standard Product Development Approaches 51·11

51.4.4 Informal Product Assessment Approaches 51·14

51.4.5 Security Assessment Standards for Products 51·22

51.5 STANDARD PRODUCT AND SERVICES ASSESSMENT APPROACHES 51 · 23 51.5.1 Government

Standard Cryptographic Validation Programs 51·23

51.5.2 FedRAMP 51·24 51.5.3 Common Criteria 51·26

51.6 NOTES 51 · 32

51.1 INTRODUCTION. Organizations, people, devices, tests, software, and products have defining characteristics. Standards are established for the purpose of providing uniformity of essential characteristics among different instantiations of such entities. Standards thus allow different parties to understand and to compare the defining characteristics of different entities.

There are many types of standards depending on the characteristic being addressed. There are also many different bodies or authorities that develop and issue standards.

A particular goal of standardization in the security arena is to evolve toward an information technology (IT)–driven economy where security products, and secured

51 · 1 Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 2 SECURITY STANDARDS FOR PRODUCTS

products, approach plug-and-play status. They should be comparably trusted, be avail- able for purchase from multiple competing vendors, and be able to be mixed, matched, and integrated to provide requisite secure, trusted IT infrastructures that reduce the risks of greatest concern.

In the U.S. Government sector, product security and software quality assurance has been important for years. However, security became of top concern to government agency chief information security officers as a result of theFederalInformationSecurity Management Act (FISMA).1 FISMA applies to the security of systems.

The security of systems such as those impacted by FISMA and other industry- specific standards applicable to secure systems is not considered in this chapter. But such standards have certainly increased the attention to security associated with an individual product.

Although several different categories of security-relevant standards exist, this chap- ter provides insights about the field of security standards by considering only a repre- sentative sample of the multitude of standards that pertain to product security. Standards associated with developing product trust are especially important in the electronically interwoven world. As such, the primary focus herein is on standards pertaining to product trust.

The chapter begins by providing a general introduction to standards. Section 51.2 addresses why standards are important. Section 51.3 summarizes what types of security- relevant standards exist, what bodies create standards, and what security characteristics, features, or capabilities are addressed in examples of different standards.

Then attention turns to considering examples of some of the many types of stan- dards that apply specifically to enhancing trust in products. Section 51.4 describes several standards-based product development approaches ranging (for example) from consensus-based standards for security specifications and product development pro- cesses to formal capability-based standards and ISO secure software development pro- cesses. Section 51.4 also summarizes several different product assessment approaches that rely on informal standards ranging from vendor self-declarations to third-party assessments via de jure methods.

In Section 51.5 three standards-based approaches for assessing the security of prod- ucts are described, for products ranging from cryptographic modules and products, to general classes of products, to cloud service offerings.

51.2 IMPORTANCE OF STANDARDS. The value of standards is considered in Section 51.2.1. The motivation for using standards to establish trust and to manage risks associated with products is discussed in Section 51.2.2. The difficulties of estab- lishing trust in systems consisting of many individual products are briefly examined in Section 51.2.3

51.2.1 Value of Standards. Many parties benefit from standards pertaining to security: customers, vendors, software developers, testing houses, product reviewers in the media, consultants, and more.

For example, customers find standards helpful in several ways. Standards help spec- ify their needs for various security functionalities and the degrees of assurance they require in the products they buy. Standards help customers understand what secu- rity functionality and assurances a product builder claims to provide. Standards help consumers select commercial off-the-shelf products that they can trust will conform to their security and assurance requirements and that, as needed, will interoperate with comparable products. Procurement standards help customers buy appropriately

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

IMPORTANCE OF STANDARDS 51 · 3

trusted products that meet customer requirements. Customers under the mandates of the security-relevant regulations imposed by federal regulations such as the Health Insurance Portability and Accountability Act (HIPAA) and the Sarbanes-Oxley Act (SOX) often look to establishing due diligence by leveraging products that have estab- lished trust in their security and assurance functionality in a standard way. Standard security certifications of customer staff and hired consultants help customers employ appropriately knowledgeable people to protect customers’ facilities and information or to help deal with certain vendors or regulators.

Vendors and service providers find standards helpful in several ways. Use of stan- dards provides evidence that vendors have migrated their product development to a paradigm wherein security is built in from the start. Use of standards provides ev- idence that security is not some afterthought that is patched or bolted on. Use of implementation-related standards and standard personnel certifications shows that se- curity is the foundation on which a vendor is building a product or a service provider is providing a service. Use of standards helps to open global marketplaces to vendors and service providers. By using standard, third-party verification of security capabilities, vendors are making their products (and service providers are making their services) either stand out from, or be comparable to, their competitors.

51.2.2 Motivation for Establishing Trust and Managing Risk in Prod- ucts. Trust in the electronic processing, storage, and interactions among customers, businesses, business partners, suppliers, service organizations, and governments is key to electronic economy, electronic healthcare, and electronic government models. The need for trust will only increase as new IT paradigms and technologies proliferate, mu- tate business and IT support models, and introduce new risks and vulnerabilities. For electronic service models to succeed, all e-business, e-health, and e-government play- ers need confidence in the IT products used by interacting players as well as products used in the intervening IT infrastructure.

Another key notion besides trust is the notion of risk management. When electronic relationships are established between parties, there are quantifiable risks associated with such relationships.

Risks are quantifiable in many ways. For example, they can be quantified in terms of the types of possible adverse events. They can be quantified in terms of the likelihood of different types of adverse events and by the value of what is to be protected by IT security solutions during an adverse event. They can be quantified in terms of the consequences of adverse events, such as the liability that may be exposed via compromises, or the entities that may be hurt by compromises.

Risks then can be mitigated in a number of possible ways. For example, risks can be mitigated by using products that reduce the occurrence or impacts of the adverse events of most concern. When assets of increasing value need to be protected, risks can be reduced by using products that have increased assurance. Risks also can be mitigated by using products that decrease the specific, deleterious liabilities and undesired consequences of greatest concern. Being able to specify the risks of concern and to identify security solutions that mitigate those risks is a powerful strategy used within certain standards-based approaches such as the Common Criteria (CC) paradigm.

Linking notions of trust together with notions of risk reduction makes for a powerful strategy. Establishing trust among interacting electronic parties that all parties are using products with appropriate security quality is akin to the role of face-to-face handshakes in older business models. In the e-business marketplace, trust, like the old handshake,

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 4 SECURITY STANDARDS FOR PRODUCTS

is key to increased revenues via increased business transaction volumes. Furthermore, by mitigating risks, business losses and costs can be reduced. When trust enhancement is coupled with risk management, the resulting increased revenues, combined with decreased losses and lower costs, make for significant profit multiplication.

The CC paradigm is an example of a standards-based product assessment strategy that provides for both establishing appropriate levels of trust in products and for specifying, managing, and mitigating risks of most concern.

Various standard-based ways have been developed and used over the years to build confidence about the quality of security implementations. The focus of such efforts includes establishing trust via one or both of two perspectives: (1) that a product performs its claimed security functionality completely and correctly and (2) that the product builder’s processes (from design, to development, to delivery, to maintenance) are sound. Typically, trust is established either by testing in a standard way just the implementation or by evaluating in a standard way both the product and its implementer.

Not all approaches to establishing trust via product assessment necessarily address trust via formal standards–based assessment of implemented security functionality as well as the assurance of the soundness of the builder’s abilities and processes. That is, many of the testing and evaluation approaches are based on informal, de facto or de jure standards2—not on formal, nationally recognized standards.

51.2.3 Motivation for Establishing Trust in Systems. Recent U.S. Gov- ernment administrations have recognized the importance of establishing trust in IT. They have issued directives and guidance to elevate awareness of the central, critical nature of IT and to help to preserve trust in national IT infrastructures.

National IT infrastructures are typically large IT systems often composed of many individual products. Standards-based methods for establishing trust in products do not necessarily work for establishing trust in systems. Standards-based methods of es- tablishing trust in IT systems exist. They include, for example, standards and testing activities associated with the original U.S. Department of Defense (DoD) Informa- tion Technology Security Certification and Accreditation Process (DITSCAP)3 and the Department of Defense Information Assurance Certification and Accreditation Pro- cess (DIACAP)4 which replaced it, the U.S Government’s FISMA, and the financial community’s Payment Card Industry Data Security Standard (PCI DSS).5

Such systems-focused, trust-development methods tend to be employed only by large enterprises. Furthermore, the problem of establishing a quantitative measure of trust in a very large, heterogeneous system like a national IT infrastructure is evolving. At a minimum, it requires coordination and cooperation among all who contribute to or use the infrastructure. Security requirements and security testing approaches applicable to IT systems, per se, are not considered herein.

Although still argued among security professionals, many believe a step in the right direction is to build IT systems with products and components that are individually assessed to be trustworthy, with some specified degree of confidence. What is most difficult, however, in a product assessment is to test the product’s security aspects in an environment that perfectly mimics the environment in which the product is to be used.

51.3 TYPES, SOURCES, AND EXAMPLES OF STANDARDS. In today’s heterogeneous, multidisciplinary, multitechnology, multiparty, interconnected IT envi- ronments, different types of security standards are essential for a variety of reasons. Several formal, informal, and ad hoc bodies develop and issue standards. The sig- nificance and acceptance of any given standard tends to depend on the notoriety of

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TYPES, SOURCES, AND EXAMPLES OF STANDARDS 51 · 5

the body that creates the standard. A high-level taxonomy for what types of security standards exist appears in Section 51.3.1. The various types of bodies involved with security standardization efforts are listed in Section 51.3.2. Examples of the standards developed and issued by various bodies are presented in Section 51.3.3

51.3.1 Types of Standards. In the security world, there are a many different types of standards. The types of standards pertinent to security include, for example, the following:

� Capability standards � Personnel certifications � Risk assessment criteria � Requirements specifications � Functional specifications � Assurance specifications � Performance criteria � Product development standards � Testing, evaluation, and assessment standards/criteria6

� Product review criteria � Interoperability standards � Procurement standards � Ancillary standards

51.3.2 Sources of Standards. Some of the bodies that issue formal nation- recognized standards, organizational standards, or proprietary standards, or that use de jure approaches pertinent to security, include the following:

� Recognized national bodies � International organizations � Governments � Military � Consortia � Like-minded communities � Vendors � Consulting houses � Trade press � Commercial testing houses � Private testing contractors

Formal standards relevant to information assurance (IA) are created, published, and maintained by recognized standards bodies. There are various recognized standards bodies including technology-specific working groups associated with professional or- ganizations like the IEEE (Institute of Electrical and Electronics Engineers) and the IETF (Internet Engineering Task Force). Standards are also created by working groups

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 6 SECURITY STANDARDS FOR PRODUCTS

associated with recognized, country-specific, national standards bodies, such as the ASC (American Standards Committee, formerly ANSI) in the United States, the BSI (British Standards Institute) in the United Kingdom, and the Bundesamt für Sicherheit in der Informationstechnik (also BSI) in Germany. Such national standards bodies cre- ate either country-specific standards or they collaborate and harmonize with other peer national standards bodies to create international, globally applicable standards, such as those associated with International Organization for Standardization (ISO).7

Recognized organizations within national governments also create standards. For example, the National Institute of Standards and Technology (NIST)—a U.S. federal agency under the U.S. Department of Commerce—creates and issues standards called Federal Information Processing Standards (FIPS). It also issues standards called SPs (Special Publications) that delineate security, privacy, and assurance best practices guidance. FIPS and SPs often apply not only to the U.S. Government but are widely used as references in other nongovernmental organizations and may even apply formally to some. For example, a 2005 amendment to the Federal Acquisition Regulation to implement the IT security provisions of FISMA requires all federal procurements to adhere to pertinent NIST standards and publications.

National governments also form bodies to collaborate and to harmonize international standards for use by governments within several nations. The CC Project is an example of such a cross-government standardization body. Standards developed by this particu- lar cross-government standards body are also fed to recognized international standards bodies such as the ISO to create even broader-reaching standards.

In the military area, the U.S. DoD publishes military standard directives such as Mil Standard 8500,8,9 that must be followed when procuring security-related products, as well as Department of Defense Directive 857010 that pertains to training, certification, and management of employees performing IA functions.

Technology-specific and industry-specific consortia have large, broad-based, inter- national membership; examples include

� Cloud Security Alliance (CSA)11

� Security Standards Council (SSC)12 of the Payment Card Industry (PCI) consor- tium

� Software Assurance Forum for Excellence in Code (SAFECode)13

� Object Management Group (OMG)14

� Web Application Security Consortium (WASC)15

� TM (formerly TeleManagement) Forum16

Often they are considered to be creators of informal, security-relevant standards for use within specific industries or technology sectors. Small consortia or individual entities also claim to create standards, but such efforts are generally not accepted by as broad constituencies as are the legitimate, recognized, formal, and informal standards.

Other like-minded communities like the SANS (formerly System Administration and Network Security) Institute17 promulgate de facto best-practices security standards, such as the 20 Critical Controls,18 claimed to reflect community consensus within a certain community of security practitioners.

Vendors such as Microsoft develop standard-like documents such as the PCI DSS Compliance Planning Guide19 or the Secure Development Lifecycle20 framework

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

TYPES, SOURCES, AND EXAMPLES OF STANDARDS 51 · 7

and strategy for secure coding that they presumably hope will be adopted by large communities.

Consulting houses such as Gartner, Forrester, and Frost & Sullivan develop private product review criteria pertaining to security and security features. They use such criteria to evaluate security-relevant products. Gartner and others also produce product reviews based on user interviews.

The trade press includes media outlets such as Computerworld, CSO, IT Business Edge, Network World, SC Magazine, and Security Management that create yet other private product review criteria that they use to examine security-relevant products.

Commercial testing houses such asICSALabs,NSSLabs, andWestCoastLabscreate and use private, independent, product-testing criteria and methodologies to evaluate product security and performance. Some of the commercial testing houses, such as AV-Test, develop private, independent, product-testing criteria and methods to certify tested products.

Private contractors conduct product security testing via a variety of informally standard techniques that rely on private criteria and test procedures. Such techniques include vulnerability scanning, vulnerability assessment, penetration testing, security auditing, ISO 27001 auditing, security reviews, ethical hacking, and more. Academic organizations are also beginning to establish security product-evaluation laboratories that rely on various published vulnerability and assurance test procedures and criteria.

51.3.3 Examples of Security Standards. Examples of the types of security- relevant standards issued by examples of the different standards issuing bodies are provided in this section below. Detailed summaries of a number of these standards are provided later in this chapter.

Capability standards such as the Capability Maturity Model (CMM) and ISO 9000 exist to measure the competency of organizations that build products—in particular, security-related products.

General personnel certifications such as the Certified Information Systems Security Professional (CISSP) from the International Information Systems Security Certifi- cation Consortium ((ISC)2) measure, among other things, the competency of staff specifying, building, procuring, installing, or maintaining security-related products. Other certifications like the IEEE Computer Society’s Certified Software Development Associate (or Professional) or the (ISC)2 Certified Secure Software Lifecycle Profes- sional (CSSLP) or the Electronic Commerce Council Certified Secure Programmer are examples of certifications more directly useful in certain product software devel- opment areas involving security. The Cloud Security Alliance’s Certificate of Cloud Security Knowledge assesses an individual’s competency in major matters related to cloud security.

Standards exist to provide consistent ways to stipulate security needs and require- ments in both security products and secured products. Some standards specify the security functionality appearing within products. Standards like IETF’s IPSec not only specify security functionality, but they also foster interoperability of separately built security implementations. Other standards specify security-related software interfaces, naming conventions, and data structures such as for Common Object Request Broker Architecture (CORBA) middleware products.

Standards like FIPS 140 can specify security requirements, evaluation methods, and validation concepts for a single specific type of security-relevant component or product. The CC series of standards can specify the security functionality and security assurance characteristics to be incorporated into any class of products.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 8 SECURITY STANDARDS FOR PRODUCTS

De jure standards like SANS 20 Critical Controls, which compete with certain national and international standards, specify a single, small, essential core of security functionality. This de jure, consensus-based standard may be growing in popularity.

Product development standards like ISO/IEC 27034-1 specify requirements for secure software development processes while the Building Security in Maturity Model (BSIMM) de facto industry standard provides an ability to compare secure coding environments and to identify best development practices.

Vendor standards like Microsoft’s Security Development Lifecycle also specify soft- ware development and assurance processes to increase reliability of software security.

Standards also exist to govern the testing of products. It is essential that vendors and buyers of security and security-enhanced products (a) verify that a product under test implements functionality that addresses the stipulated security functional requirements desired, and (b) demonstrate how well the product and the vendor’s product devel- opment processes meet stipulated requirements. There are national and international standards such as FIPS 140 and the CC that stipulate such conformance testing and that stipulate testing methods to accomplish such testing. The FedRAMP standard ap- proach applies to validation of the security capabilities associated with a specific class of service providers.

Conformance of different security-relevant products to the same functional standard, however, does not necessarily ensure that these products will interoperate. Interoper- ability of separately manufactured security solutions is possible if implementation standards can specify precise, interoperable profiles of selected security capabilities from within a security functional standard. Interoperability testing can assure secure interoperation between comparable products built by autonomous vendors and used between autonomous parties. Conformance implies only that interoperability is pos- sible; but interoperability needs to be verified by pair-wise testing. Standards exist to specify how to examine conformance of implementations to functional standards and how to assure the interoperability of implementations that must meet the same functional standard.

Interoperating, conformant, secured products and security products cannot neces- sarily be trusted to provide or to support sound security, or to mitigate the risks of greatest concern. Key to developing trust is to build confidence that products mitigate the risks of concern, that products are properly built and behave according to speci- fication, and that products do no more or no less than advertised. Standards like the CC exist for establishing and testing the degree to which risks and vulnerabilities are mitigated to a specified level of confidence. These standards specify implementation assurance requirements and associated tests and testing methods to verify the quality of implemented security within the products under test.

Regarding private, de jure standards, different trade press media and others develop private product review criteria and methodologies. These private standards are used to create reviews of specific security or security-enhanced products, or to develop buyer’s guides that compare the individual product reviews of several products within a class of products. Certain metrics created by such criteria can provide measures of security performance.

Some media outlets operate awards programs that use question-driven surveys for identifying readers’ choice picks of best products within certain classes of products. Popularity-based product leadership awards also exist.

In the area of procurement standards, standards like DoD’s 8500.1 and 8500.2 stipulate standard policy and policy implementation directives, respectively, for what types of products DoD must procure. These standards also specify what must be done

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

PRODUCT DEVELOPMENT AND ASSESSMENT APPROACHES 51 · 9

by DoD entities to meet a need or what constraints DoD organizations must follow when procuring IT products.

In the area of ancillary standards, standards such as companion standards within the suite of CC standards specify how to become a product tester and how to accredit organizations to conduct conformance, trust, or interoperability testing in a standard way.

Other ancillary standards—not considered in this chapter—like the DITSCAP21

(replaced by DIACAP in November 2007) for U.S. DoD, the National Information Assurance Certification and Accreditation Process (NIACAP),22 and the NIST Certifi- cation & Accreditation (C&A)23 methodologies for U.S. federal civilian departments and agencies specify how to certify and how to accredit systems composed of secure products and secure components. Standards like ISO 1779924 and NIST SP 800-5325

can specify guidelines or best practices for users assembling and using secure compo- nents.

In aggregate, standards promote consistent security, end-to-end as well as across different public and private domains and computing environments.

51.4 PRODUCT DEVELOPMENT AND ASSESSMENT APPROACHES. This chapter focuses on standards for enhancing trust in security-related products. There are two classes of products of interest: “security” products and “security-enabled” products. Security products directly provide security services or prevent penetrations. Security products include, for example, intrusion detection products and firewalls. Security-enabled products are secured products that do not exist solely to provide se- curity services; instead they provide other services that are protected. Examples include operating systems, database management systems, and virtual private networking gear that incorporate security functionality such as identification and authentication or IPSec to protect either the product or the services provided by the product.

The remainder of this chapter summarizes various approaches that support increas- ing trust in such products. The historical approaches for establishing trust in certain classes of products are summarized in Section 51.4.1. A sampling of community-based consensus standards that specify security controls are described in Section 51.4.2. The chapter then summarizes numerous other current approaches for developing product trust, including standard product development approaches used during the design and building of products (Section 51.4.3), informal product assessment criteria and ap- proaches (Section 51.4.4), and formal, internationally recognized, standard product assessment criteria and approaches (Sections 51.4.5 and 51.5).

The U.S. Government had hoped that all public sector and private-sector consumers, vendors, and testers of security-related products would rally around the formal, inter- nationally recognized standards that pertain to specification, development, and testing and evaluation of such products. With formal standards being produced by national and international standards bodies, it was anticipated that consumers could understand with greater certainty the security and assurance features offered by a product or a service provider. It was hoped that the confidence obtained by using universal, interna- tionally accepted standards would contrast sharply with nonstandard approaches that, because of their sheer numbers of competing approaches, would confront and befuddle consumers.

In today’s actuality, the government and military sectors frequently rely on the formal standards-based approaches. But, in contrast—despite the expectations associated with such formal standards-based approaches—the entire marketplace has not necessarily coalesced around the formal standards approach.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 10 SECURITY STANDARDS FOR PRODUCTS

Many informal private product assessment alternatives that do not rely on formal standards came into being and are being used with greater or less frequency than the alternatives based on formal standards. There is no shortage of alternative approaches and alternative frameworks on which such approaches are based. Correspondingly, there is no shortage in approaches stipulated in user procurement directives. The marketplace is fractured among many alternatives. A sampling of these alternatives is examined below.

51.4.1 Historical, Sunsetted Approaches. To introduce consistency in de- scribing the security features and levels of trust of a limited set of security-enhanced products, and to facilitate comprehensive testing and evaluation of such products, the U.S. DoD developed the Trusted Computer System Evaluation Criteria (TCSEC).26

The TCSEC—often called the Orange Book—defined a small set of classes (C1 to A1) of increasing security functionality and increasing assurance applying to operating systems. The TCSEC was extended to networking devices27 and database management systems.28 Government in-house evaluations were offered first, followed by compara- ble government-sponsored commercial evaluation services.

Partly because of large testing delays and costs, other countries developed other criteria that were more flexible and adaptable to accommodate rapidly evolving IT. The Information Technology Security Evaluation Criteria29 (ITSEC) arose from the combined inputs of earlier German criteria, French criteria, and U.K. confidence levels. The Canadian Trusted Computer Product Evaluation Criteria (CTCPEC) were then developed as a combination of the TCSEC and ITSEC approaches. The U.S. Federal Criteria development then attempted to combine the CTCPEC and ITSEC with the TCSEC.

With growth of the international market for trusted IT products, all these historical, competing, national criteria had the potential to fracture the marketplace. They were sunsetted after efforts were completed to harmonize the various criteria into common, standards-based, internationally accepted criteria.

The result of the harmonization effort was a single, wide-ranging CC program (Sec- tion 51.5.3). These standard criteria provide a fully flexible, highly tailorable approach to the standardization of security functionality, evaluation assurance requirements, specification, and testing of implementations of security-related products.

51.4.2 Consensus Security Specification Approaches

51.4.2.1 SANS Institute. The SANS Institute has issued a de jure standard30 that specifies what is believed to be the core set of the most critical, baseline security controls deemed essential for virtually any organization. These security controls are colloquially called the 20 Critical Controls. They provide a feasible, implementable, best-practice, security approach based on providing what is purported to be the greatest risk-reduction, the best protection against actual, in-the-field threats, and the best techniques to stop the most dangerous, common, regularly occurring attacks. The SANS approach provides for continuous, automated monitoring of key portions of an organization’s IT infrastructure to ensure security effectiveness.

SANS has published a guideline of the steps for how to implement these critical controls.31 The guideline provides a tabulation of many real attacks and provides a mapping that identifies which of the 20 Critical Controls provide the best defenses against each of these attacks.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

PRODUCT DEVELOPMENT AND ASSESSMENT APPROACHES 51 · 11

The SANS Critical Controls map to a certain subset of the security controls specified in NIST Special Publication 800-53, Revision 3 (see Appendix A of the SANS Critical Controls guidelines). In some sense, the SANS critical controls may be considered as a specific profile of the most essential security controls in NIST SP 800-53. Some security professionals feel the SANS 20 Critical Controls will provide the necessary (but not necessarily sufficient) due diligence to become the de facto yardstick for measuring the standard of care for security.

51.4.2.2 Cloud Security Alliance (CSA). The CSA has developed a guide- line explaining cloud computing and identifying the best risk-based practices for tran- sitioning to secure cloud operations provided by different cloud service models in cloud computing environments. Partitioning of security responsibilities between cloud customers and cloud service providers depends on the cloud service being offered, for example, cloud Software as a Service (SaaS), cloud Infrastructure as a Service (IaaS), cloud Platform as a Service (PaaS). The stipulated security controls and technologies apply to (a) protecting data migrating to clouds, (b) protecting data in transit to the cloud and in transit between different cloud providers/cloud environments, (c) protect- ing data within clouds, (d) privacy preservation, (e) application security, (f) data loss prevention, and more. The version 3 edition of this guideline is available at the time of this writing (July 2013).32

51.4.3 Standard Product Development Approaches. A key that can lead to a productive product assessment is for product builders to rely on high-quality, highly capable product developers and to use product development standards, such as soft- ware design and testing standards, during product design and creation. Such product developer capability standards that can apply to builders of security products include the Capability Maturity Model (Section 51.4.3.1) and the ISO 9000 series of stan- dards (Section 51.4.3.2). Standards and approaches used during product development to enhance the quality and inherent security offered by products are examined in Section 51.4.3.3.

51.4.3.1 Capability Maturity Model. The Systems Security Engineering Capability Maturity Model (SSE-CMM) has been standardized as ISO/IEC 21827. This standard provides a way to assess the soundness of a security product builder’s engineering practices, as well as a way for continuously improving such practices up a hierarchy of increasingly mature software process levels, during the many stages of product development, such as during:

� Product requirements capture and analysis � Product concept definition, including accurate translation of security requirements into product requirements

� Product architecting � Product design � Product implementation

A security product developer can demonstrate competence in building products by means of recognized, so-called capability maturity assessments of the developer’s software and security engineering processes. Security-enhanced products built by orga- nizations with demonstrated expertise and maturity can merit greater trust than products

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 12 SECURITY STANDARDS FOR PRODUCTS

built by organizations that do not demonstrate mature, competent, software design, and security engineering capabilities.

The SSE-CMM establishes a framework of generally accepted security engineering principles and a standard way of measuring (and improving) the effectiveness of an organization’s security engineering practices. The SSE-CMM describes the essential characteristics of, and provides tools for, assessing an organization’s security engineer- ing process that must exist to ensure good security engineering. These characteristics are graded by a set of security metrics that assess specific attributes about a vendor’s processes, and the security effectiveness of the results of vendor’s processes.

When the level of the SSE-CMM security metrics associated with a specific builder shows the builder to have mature security engineering capabilities and effective security engineering practices, then confidence is increased that the builder can build sound security products.

Trust in, and assurance about, a product can be inferred, to some degree, for mea- surably competent vendors that use sound security engineering processes as assessed by the SSE-CMM. The quantitative comparability of assurance developed via the SSE- CMM approach to the assurance developed via other approaches such as evaluation of assurance requirements stipulated from the CC paradigm is not well understood. For now, it appears possible to assess the assurance of a vendor’s capability to build quality products by both the SSE-CMM and CC approaches; but, perhaps both approaches should be integrated to form a more comprehensive assurance assessment model.

51.4.3.2 ISO 9000 Standards. The ISO 9000 standard33 is used as a guide to conduct a broad, high-level, horizontal assessment of the quality of systems and of the competence of an organization (typically a manufacturing or service organization) across all its facets. Although not specific to organizations that build security products, it does provide some amount of basic information about the potential for quality and repeatability in an organization’s ability to meet its mission. In fact, derivative standards such as in the CC, in part inspired by ISO 9000, are used to accredit the quality associated with security testing laboratories.

The ISO 9001 standard has applicability to software development. Although not specific to organizations that build security products, it nevertheless specifies in general an acceptable, minimum quality level for software processes.

51.4.3.3 Product Development Standards and Approaches. There is great need to focus on secure software development as new products are brought to market. The current situation for secure software development is not stellar. Annually, about 5,000 new software vulnerabilities—many exploitable by real-world threats and attacks—are discovered per year. Unfortunately, software sabotage also incorporates intentional, sinister flaws. Studies indicate that up to 99 percent of coded applica- tions contain vulnerabilities. Industrial control, so-called supervisory control and data acquisition (SCADA) software, is equally vulnerable. Indeed, while slightly better than these statics for general applications, even software within security appliances is not immune to software development flaws and is not—as many customers might believe—inherently secure.34

To overcome threats to software, security software scientists are trying to move secure software development practices from an art to a science based on standards. Common mitigation strategies include establishing appropriate and rather specific poli- cies and procedures (that should include coding examples) to govern secure software

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

PRODUCT DEVELOPMENT AND ASSESSMENT APPROACHES 51 · 13

development. Specific tactics include, for example, reliance on commonly available, standard, checks-and-balances–oriented technologies such as

� Code signing by developers, � Code check-in audit monitors and audit trails, � Multiparty mutually monitoring code reviews, � Automated code and vulnerability scanning with acceptable false-positive/ negative detection rates,

� Live attack scanning, and � Use of antitampering technology for code integrity checking.

Guidelines for secure software development exist.35,36 Commercial development testing tools such as static and dynamic code analyzers can also be used to find defects and vulnerabilities in code being developed.

The key to secure software development efforts37 is to establish standard corporate culture and appropriate policies that:

� Put software security developers at the table when software project requirements are established,

� Incorporate security into software by design, � Incorporate only vulnerability-scanned, third-party software components38 and use dynamically linked libraries so that the newest, less vulnerable, updated soft- ware components automatically replace older, outdated, more vulnerable software,

� Foster collaborative mutually cross-checking software development, � Incorporate better testing early in, and throughout, the software development life cycle so as to manage security and quality defects as the code is being written, and

� Establish formal processes for upstream feedback aimed at eliminating root causes of software vulnerabilities, defects, and flaws.

Such actions increase code quality before code is released for manufacturing. Higher quality code tends to have fewer security vulnerabilities, smaller attack surfaces, and fewer holes that need to be plugged after software reaches production status. If internal testing resources are limited, secure software testing services can be outsourced to external firms such as Coverity that provides a Development Testing Platform or the NCC Group that provides direct testing services.

Going even further than just focusing on software development science, many are looking toward more formal product development standards that provide repeat- able, proactive, product development and testing processes. Certain vendors such as Microsoft (in 2002), via its Trustworthy Computing Initiative, and Adobe (in 2009) initiated leading-edge, standard, internal initiatives to incorporate security into their software designs prior to mass production and sales of their software. Microsoft’s Secu- rityDevelopmentLifecycle39 (SDL) specifies processes for developing secure software.

More recently, the 2011 international standard ISO/IEC 27034-1 specifies require- ments for, and describes processes and practices for, secure software development. Several large software companies are starting to use this standard to start compre- hensive programs for necessarily incorporating security into their products right from

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 14 SECURITY STANDARDS FOR PRODUCTS

the start of the software design stage. This standard is valuable to both buyers and builders of security-related products. Software builders display due diligence in using the standard to create quality, secure code. Buyers understand that compliant software builders are committed to secure development processes.

The Software Assurance Forum for Excellence in Code (SAFECode) consortium’s training material allows product developers to stay current with the best practices, principles, and methods in secure software engineering and development. Other or- ganizations such as the Association for Software Testing are also trying to build a developer community knowledgeable in software development and testing sciences.

The Building Security in Maturity Model (BSIMM) program provides an ability for enterprises—as a combined community—to survey its members to discern a common core of secure software development best practices. The BSIMM has created a de facto secure software development standard by comparing the real-life secure coding envi- ronments and practices of its membership to identify best secure software development practices. The model is free under a Creative Commons license.

51.4.3.4 Problems in Development Practices. A disappointing observa- tion related to secure development practices is that a 2013 survey40 indicated that only about a third of product developers are focused on building security into their software; nearly two-thirds are not necessarily focused on security and do not consider using ap- plication attack mitigation standard technologies like Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR). The situation has the potential to worsen as

� New so-called agile software development and testing methodologies emerge, � Demands for more complex, cloud-based or mobile software rise—often with greater vulnerability densities, and

� Fielded software is upgraded—often by a patchwork of code created by different software developers with differing skills, with differing knowledge of the software being upgraded, and at differing points in times.

Consumers seem to want products with more features; and vendors seem to have little incentives or liability exposures to invest much time or resources into building solid products.

51.4.4 Informal Product Assessment Approaches. A variety of product assessment approaches are not dependent on formal, standard, internationally recog- nized, security testing and evaluation approaches. Indeed, most have not reached the status of even a de facto standard, but they are considered, nonetheless, for completeness purposes. Such approaches include:

� Vendor self-declarations (Section 51.4.4.1) � Consumer assessments (Section 51.4.4.2) � Consortium-based assessments (Section 51.4.4.3) � Implicit assessments via open-source code development (Section 51.4.4.4) � Implicit assessments via hacking (Section 51.4.4.5) � Assessments by magazines and trade press publications (Section 51.4.4.6) � Third-party commercial assessments using de jure methods (Section 51.4.4.7)

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

PRODUCT DEVELOPMENT AND ASSESSMENT APPROACHES 51 · 15

There are shortcomings to most of these approaches. Some are not considered to offer much value. One of the basic shortcomings is that lack of reliance on formal standards makes for difficulty in comparing the product assessment results:

� Of different products, � For products tested and evaluated via different approaches, and � For products tested and evaluated by different testing facilities that all purportedly use the same product assessment approach.

51.4.4.1 Vendor Self-Declarations. An approach to establishing trust is based on the notion of vendor self-declarations. A vendor can unilaterally claim that a specific product meets the security needs of a class of customers and that an appropriate amount of customer-desired confidence can be placed in the product’s implemented security features. In part, the confidence associated with this approach is implicitly tied to the past reputation of a vendor or to the customer’s past experience in dealing with the vendor. If the vendor’s reputation or customer’s experiences are good, there is some sense that the vendor may have again done an adequate job of implementing security. This approach, however, lacks measurable ways of quantifying the degree of trust that can be associated with a product. It also lacks measurable ways of comparing the relative degrees of trust that can be associated with different products.

An example of such a self-declaration was recently created by the consulting division of a large computer company.41 In this example, the vendor stipulated what were identified as the most important criteria in selecting a Managed Security Services Provider (MSSP) and revealed why the vendor’s services are the best in the marketplace.

This self-declaration approach may have some merit in establishing a sense of continuing confidence in products that have been updated since an earlier version of the product that has undergone rigorous, standards-based security testing and evaluation. If a vendor is known to have good security engineering capabilities—such as can be assessed, in part, by standard Capability Maturity Model approaches (see Section 51.4.2.1)—and if the vendor can provide reasonable evidence as to the nature of the upgrade or revision since the product version that underwent rigorous assessment, then there can be some qualitative (albeit, quantitatively unknown) degree of confidence about the upgraded or revised product. Under these conditions, customers who have innate trust in the vendor can believe that the quality of the changed product is similar to the quality of the version of the product that was formally assessed.

51.4.4.2 Consumer Assessments. It has been reported that less than 20 per- cent of software consumers are assessing the security attendant with the application software they buy. Product consumers can, however, develop the requisite substantial technical expertise in-house to test and to evaluate specific security-enhanced products directly.

Vendor standard tools are available to help consumers in specific security technology areas. For example, a GFI Software division has developed an Antivirus Evaluation Guide that stipulates a repeatable, readily deployable, testing criteria for customers to evaluate vendor antivirus products.42 For another example, Ixia has developed an attack simulator that a user of security products can run in a safe environment to emulate a range of attack or configuration scenarios so as to evaluate how well the security products in question detect and block certain attacks.43 For example, attacks by zombie botnets as well as the full life cycle of DDoS attack scenarios can be simulated.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 16 SECURITY STANDARDS FOR PRODUCTS

Alternatively, because of lack of in-house expertise or available staff, consumers may hire a consultant to perform limited security assessments via techniques such as penetra- tion testing or source code analysis or binary analysis when source code is not available. Consumers with more resources may contract a private third-party evaluator, such as a commercial security testing provider (such as Veracode, see Section 51.4.4.7.3) or one of the big consulting houses or systems integrators, to do third-party security testing and evaluation. Many of the third-party approaches are private and tend to be unique.

Some financial institutions have used the in-house assessment approach. Financial institutions as a whole are very careful to make sure that products they use are trust- worthy. The security, integrity, and soundness of all products and systems supporting financial institutions must be consistent and verifiable. These institutions fear that any breach of IT security anywhere within their systems will result in a loss of confidence in the entire institution, not just in the specific, subverted IT product.

Many financial institutions developed their own internal standard security specifi- cations and evaluation processes as well as an evaluation methodology to quantify, to compare, to approve, and to certify general security aspects of competing products. One of the consequences of this approach to the customer community at large is that it requires substantial, costly duplication of testing infrastructure across the financial industry as well as the costly duplication of testing support efforts by vendors for those products that are candidates for purchase by multiple customers. With each finan- cial entity funding the establishment of its own testing program, the aggregate testing expenses are raised across all entities within the financial industry.

Furthermore, as the volume of financial devices, such as credit card platforms, operating systems, and thousands of applications, continues to increase dramatically, in-house resources are finding it difficult to keep up. Product customers find this kind of do-it-yourself, in-house testing approach to be a tremendous undertaking in terms of development, implementation, legitimacy demonstration, maintenance, and rejustification. They have found it to be expensive, time consuming, resource intensive, hard to maintain, always open to interpretation and to debate, and always in need of justification to regulators and principals in new markets.

51.4.4.3 Consortium-Based Assessment Approaches. Many consortium-directed approaches exist, or have existed, to demonstrate product interoperability, or conformance of a product to stated security features or to specific security technology standards.

In the Internet world, the notion of implementation bake-offs among trial (pre- product) implementations of emerging IETF standards has been a mainstay in the community for quite some time. For example, the IETF initiated a series of IPSec VPN Interoperability Workshops upon culmination of the Internet Key Exchange Version 2 (IKEv2) standard. Vendors of IKEv2-based preproducts gathered in a common testing facility to test the functionality and interoperability of their preproducts against those of their competitors. Initial test scenarios focused on basic functionality and secure tunnel maintenance.

Other consortia use either their own or standard testing approaches. Examples of assessment efforts of an example set of consortia are summarized below. The consortia herein include the VPN Consortium (Section 51.4.4.3.1), the Cloud Security Alliance (Section 51.4.4.3.2), and the Smart Card Security Users Group (Section 51.4.4.3.3).

51.4.4.3.1 Virtual Private Network Consortium. The Virtual Private Network (VPN) Consortium developed an approach for demonstrating conformance of a product

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

PRODUCT DEVELOPMENT AND ASSESSMENT APPROACHES 51 · 17

to a specific security standard.44 The VPN Consortium conducts testing of the IPSec and Secure Sockets Layer (SSL) implementations built by its consortium members.

In the early 2000s, the consortium provided three specific profiles of conformance tests of VPN products implementing the IETF’s IPSec standard. For each type of test profile, predefined tasks had to be performed successfully against two different refer- ence test gateways. Due to the nonexhaustive set of tests, passing a VPN Consortium conformance test provided only indications that tested products conform, in limited part, to various standard parts of the IPSec standard. Such tests also provided indica- tions that interoperability may be possible with other products that pass the same tests under the same environmental situations.

The consortium has since focused on interoperability testing. It conducts several classes of IPSec interoperability tests: Basic Interoperability, AES Interoperability, IKEv2 Basic Interoperability, IPv6 Interoperability and Authentication with Certifi- cates Interoperability. The types of capabilities being tested, and the profiles by which tested systems are set up for each class of interoperability testing, are specified. The tests help assure VPN users that IPSec systems configured according to the specified profile are generally interoperable with other IPSec systems also configured according to the same profile.

The consortium also provides interoperability testing for profiles of a variety of SSL VPN features in SSL implementations.

The consortium issues logos for member company products that interoperate with at least 75 percent of the other products in an interoperability test. A list of member companies that offer products that pass any of the specific interoperability tests is maintained.45

51.4.4.3.2 Cloud Security Alliance. The CSA has established a publically avail- able Security, Trust & Assurance Registry.46 Any cloud provider can post self- assessments that document the cloud provider’s security practices and their compliance to CSA best practices. Cloud providers’ self-assessments are documented either (a) according to a CSA standard Cloud Assessment Initiative Questionnaire, or (c) via a CSA Cloud Controls Matrix that details a cloud provider’s security concepts and principles in accordance with the CSA’s security guidelines (as described in Section 51.4.2.2).

51.4.4.3.3 Smart Card Security Users Group. Although proprietary, in-house ap- proaches were originally used by individual financial institutions to assess thousands of financial IT products, components, and systems, the financial community banded together as a whole in the Smart Card Security Users Group. Through this group, financial institutions can use a single standard—the CC—for product assessments and avoid duplication of their individual product assessment efforts. Benefits of such an alliance included:

� Financial institutions can replace their internal, custom product assessment ap- proaches with a common, universally accepted approach.

� They can pool their resources to address common security testing and evaluation needs by using standards-based, CC security specification and testing schemes recognized across all major financial players.

� They can develop profiles of security requirements for the various common ele- ments of smart cards (e.g., chips, operating systems, applications, crypto engines).

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 18 SECURITY STANDARDS FOR PRODUCTS

� They can develop common test suites to unify the current hodgepodge of frag- mented customer-specific and vendor-specific testing of smart cards.

� They can outsource security testing and evaluation to competent, accredited testing laboratories whose expertise can be used by all financial institutions.

The alliance produced a CC profile—a so-called Smart Card Protection Profile—of standard security functional requirements and assurance requirements to be addressed by smart cards used in conjunction with sensitive applications such as those encoun- tered in banking industry payment systems. This standard requirements profile was validated and certified by the Canadian CC Scheme, and can be used across the fi- nancial community.47 Since then a UK smart card Protection Profile for dual-interface authentication cards was developed for uses such as passports.48

Consumers can reference such profiles to state their requirements. Vendors can reference such profiles to indicate what they built. Accredited testing laboratories use standard methods to test individual products once for the entire consumer community (not once per consumer institution). The standard tests assess a vendor’s claim that its product meets the standard requirements profile. With known confidence, a consumer can then purchase any assessed product that has been independently certified to comply with a specific Protection Profile.

51.4.4.4 Open Source Approach. One approach for software development is use of the Open Source model. According to this approach, software is made publicly available for inspection, for modification of flaws and inefficiencies, and for potential upgrading of capabilities and features. In theory, by the continuous and collective—but uncoordinated and seemingly semirandom—efforts of potentially thousands of au- tonomous software developers and testers, the public review will improve the quality of the software over time.

The downside of the open source approach is that the degree of trustworthiness achieved by the process is unmeasurable. In certain cases it has been observed that remediation of security flaws is pursued aggressively by major software contributors (especially those that have products that depend on the open source software being remediated); whereas, other software contributors are more inclined to expand open source software functionality rather than fixing discovered security flaws.49

To help identify security issues in open source code, the U.S. Department of Home- land Security initiated the Vulnerability Discovery and Remediation Open Source Hardening Project. In this project, new approaches for finding critical defects in com- plex software code sets were developed and used to test open source code to isolate defects and root causes.

In a more recent similar effort,50 the Eliminate Vulnerable Code (eVc) Project51

uses Internet crawler tools, as well as volunteer identification and/or submissions of bad code, to discover examples of, or citations to, vulnerable open source code. Such discoveries are added to a list shared with eVc members and with developers of the discovered flawed software. The eVc Project hopes that eVc members, sponsors, academia, and more might work with the developers of the discovered flawed software to remediate or to remove the flawed, vulnerable software. By eliminating faulty open source code, it will be easier for other open source projects to reuse higher-quality code that does not contain security flaws such as those identified in the Open Web Application Security Project (OWASP) Top 10 flaws list for Web application security flaws52 or in the SANS Top 25 flaws list.53

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

PRODUCT DEVELOPMENT AND ASSESSMENT APPROACHES 51 · 19

However, the trustworthiness of a product is more than just improved code. Although the open source code will have some degree of trustworthiness developed by the open source process, the incorporation of such code into a product still leads to other factors that influence trustworthiness in the product. Product trustworthiness also depends on vendor processes, such as the quality of design, the protection provided to security features during the delivery of a product from the vendor to the consumer, vendor strategies for maintaining or upgrading security in the face of new threats, and so on.

Several vendors have relied on the standard CC testing and evaluation approach to assess the security and assurance features of their Linux software products. A listing of evaluated Linux products that are certified according to the CC approach can be found online.54

51.4.4.5 Hacking. De facto assurance of the underlying security in a product can arise from those who actively probe new products for security flaws. Such probing mayarise frominternallysanctionedsecurityprobingor fromunsanctioned, unexpected probing by individuals of ill will. Hacking approaches (ethical or otherwise) do not necessarily follow a consistent or comprehensive approach to evaluating the quality of the security functions and services that are implemented. Hence, the level of assurance achieved is unknown and typically very low.

51.4.4.6 Trade Press. Many trade press publications and magazines conduct reviews of products that pertain to security. Products are tested in ad hoc environments and against private, ad hoc, de jure criteria that vary from product to product and magazine to magazine. Such magazines may rely on unaccredited consultants, staff, or private labs to review products. Some reviews may focus on examining quantitative product details other than security, such as performance or throughput of a product. Tests performed often fall short of assessing the real security aspects of a product. Some reviews rate qualitative parameters, such as product innovativeness. Because of the potential lack of quantified testing rigor and potential dissimilarity of evaluation metrics, comparisons of trade press reviews from different sources are difficult. Perhaps most important, no evaluations are made of the confidence (assurance) that can be associated with the soundness of the security implementation.

Examples of publications that provide reviews of security products include SC (for- merly Secure Computing) Magazine,55 Network Computing,56 Security Management magazine,57 InfoWorld,58 and many more. Some of these trade press initiatives are summarized below.

51.4.4.6.1 SC Magazine. In its general test process for individual security- relevant products, SC Magazine uses about 50 private criteria codeveloped by SC Lab and the Center for Regional and National Security at Eastern Michigan University. Tests of groups of products focus on operational characteristics. Test and evaluation methods are similar to those used for the CC’s lowest assurance levels. SC Magazine has also established overall ratings values to indicate how well a product has done against the test criteria and whether the product should be considered for purchase.

Examples of the types of products, or groups of products that have been reviewed by SC Magazine include: SIEM, network forensic appliances, multifactor authentication, unified threat managers, risk manager, network sentry, identity enforcement platform, application security manager, password manager, Web application firewall, database activity monitors, secure email gateway, and more. More complete lists of tested items are identified at the magazine’s Website.59

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 20 SECURITY STANDARDS FOR PRODUCTS

SC has also produced buyers’ guides for groups of products, such as Universal Single Sign-On solutions. SC Magazine also publishes privately created evaluations of products within certain

classes such as cloud identity and access control products, unified threat management solutions, next-generation firewalls, and more.

51.4.4.6.2 Other Publications. ComputerWorld and IT Business Edge obtain pri- vately created evaluations (often from the same evaluation house) of products from various classes of security-relevant products such as endpoint security products. In- dividual product evaluations are compared to other products in the same class of products. For security-enabled products, test criteria include performance metrics in- dicating how security-related processes may impact the overall performance of the system being security-enabled. NetworkWorld obtains privately created buyers’ guides for security-related technol-

ogy such as identity management in clouds, SSL/VPN tools, and more. Evaluation is based on (a) vendor self-declarations to private, evaluation survey questions in part oriented to security functionality, and (b) evaluator hands-on set up of products. InformationWeek creates buyers’ guides for technology such as gateway antimal-

ware products. Evaluation is based on vendor self-declarations in response to private, evaluation survey questions in part oriented to security functionality. IT Whitepapers obtains privately created comparisons of security-relevant prod-

ucts or services. Recent evaluation comparisons included, for example, (a) security provisions in major mobile platforms and (b) Managed Security Service Providers.

51.4.4.7 Third-Party Commercial De Jure Assessment Approaches. Early on in the security assessment arena, third-party, commercial, security assessment approaches were sometimes conducted by unaccredited testing houses or consulting houses. These third parties provided relatively low-confidence, so-called surface-level testing. Such testing resulted in vendors of security-relevant products receiving ei- ther a brand mark or an independent third-party white paper evaluation report that could be referenced in vendors’ product brochures and advertisements. Such com- mercial activities began at a time when there needed to be a lower-cost—albeit lower confidence—alternative toexpensive, lengthy, economicallyinappropriate, government evaluations such as the so-called Orange Book evaluations (see Section 51.4.1). These commercial assessment activities were also available to support trade press surveys and magazine reviews of products.

Such nonstandard, third-party approaches are still prevalent. There is a certain qualitative amount of risk reduction achievable by relying on such approaches. They are typically based on simple, one-size-fits-all testing that usually provides minimal, cursory checks of some of the implemented security functions. Some of these tests focus on product details other than security, such as performance or throughput. No evaluation is made of the confidence (assurance) that can be associated with the soundness of the security implementation. At best, these are black box approaches wherein products may be examined based only on their outputs relative to stimuli. These approaches have no assessment capabilities based on the fundamental design of the product, or of the engineering principles used by the vendor to build the product.

Many vendors, nonetheless, undergo these types of commercial testing because of the pressures from their competitors’ products being so tested. Testing costs are reasonable, but such testing provides no inputs (e.g., evaluation reports) to consumers that can be analyzed to differentiate products. More comprehensive products are not

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

PRODUCT DEVELOPMENT AND ASSESSMENT APPROACHES 51 · 21

examined for any of their differentiating capabilities. Instead, such check-mark testing programs merely provide a common-denominator assessment floor for products.

Typical vendor reaction to these types of these nonstandard third-party evaluations and branding programs is that they are often not very good and are often distracting nuisances. Vendors also indicate that unlike a more rigorous, standards-based testing paradigm, such as that based on the CC, these nonstandard, third-party programs do not have processes to help improve the quality of the product under test. Unlike CC testing labs, many vendors do not see these nonstandard testing labs as strategic partners looking to improve the product under test.

Examples of these types of product assessment approaches include the West Coast Labs Check Mark Program (Section 51.4.4.7.1), the ICSA Labs Certified Program (Section 51.4.4.7.2), and several others (Section 51.4.4.7.3).

51.4.4.7.1 Check Mark Program. The Check Mark program is a private testing service provided by West Coast Labs (www.westcoastlabs.org). Although touted to use standard testing criteria in a standard testing approach, the Check Mark program estab- lishes private criteria and a private testing methodology that are not recognized by legit- imate standards bodies such as ISO. West Coast’s private criteria and testing approaches apply to certain types of computer-security products, such as antivirus products, fire- wall products, and VPN products. The criteria are designed to achieve a basic level of protection against a number of common hostile attacks. West Coast Labs tests products against the applicable Check Mark criteria and, if successfully tested, produces a cer- tificate that shows that specific releases of products meet specific Check Mark criteria.

51.4.4.7.2 ICSA Labs Certified. Another well-known, commercial, security- relevant product branding service is the product certification program conducted by ICSA Labs.60

The ICSA approach is similar to the West Coast Labs testing approach. Product performance is tested against specified criteria to assess whether the product can resist the types of common threats and risks specified in the testing criteria. Product testing is typically a checklist-oriented approach geared for nonexpert testers. Testing criteria are developed for a number of classes of products, such as firewalls and antivirus (AV) software. While Check Mark uses private testing criteria, ICSA uses so-called public criteria. These public criteria are, however, nonstandard like those of Check Mark since they are created outside the recognized national or international standards-development communities. Instead, ICSA’s testing criteria are developed via invited participation.

Products that pass ICSA criteria are entitled to display the ICSA brand mark. Products that fail are reported to their vendors with detailed analysis of the criteria they failed.

Unlike the West Coast certificate, once products are awarded an ICSA certificate, vendors take on the obligation to self-check and to self-declare continued certification of evolutions of the specific version product that passed ICSA testing. Spot checks by ICSA are used to verify that currently shipping products still can pass the ICSA tests.61

51.4.4.7.3 Other Third-Party Assessments and Assessors. There are several other organizations that use private, informal methods to create third-party assessments of certain types of security products or security services. Examples follow.

� Gartner issues Magic Quadrant analyses that evaluate how well a product com- pares to other products in the same class of products and where a product is

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 22 SECURITY STANDARDS FOR PRODUCTS

positioned in the Magic Quadrant of characteristics. Examples of Magic Quad- rant analyses exist for product classes such as Unified Threat Management.

� Forrester issues evaluations of products as well as services in the same class of services. For example, a 15-criteria evaluation of 10 Managed Security Service Providers was conducted using private evaluation criteria.

� NSS Labs uses its own testing laboratory, rather than surveys and questionnaires, to produce best-practices guides, product reviews, comparative test reports, buyer’s guides, and more. Such materials pertain to security or security-enabled devices such as, for example, Web browsers, Web application firewalls, next-generation firewalls, endpoint solutions, breach detection systems, intrusion prevention sys- tems, antivirus products, and more. Test criteria are private and tailored to the evaluation to be performed. They may include tests that verify a device’s stability, performance, and security effectiveness (e.g., for a firewall not blocking legiti- mate traffic). Tests may determine the accuracy of a device’s security coverage, as well as the usability of the device. NSS Labs publishes its test methodologies for specific devices as well as its own research about security effectiveness. It also publishes vulnerability threat reports. NSS research materials are primarily available to subscription clients.

� Veracode is another third-party assessor available for consumers who are unable to operate a meaningful program for testing the security aspects of vendor products. To support consumer security testing needs, Veracode has established the Veracode Vendor Application Security Testing (VAST) program. In conjunction with a cloud-based testing platform, Veracode provides analysis of security worthiness of vendor application software and its compliance with the customer’s security policies and requirements for the application software they buy. It also provides de jure, standards-based, assurance level score requirements that dictate the minimal set of testing that is necessary to be performed. Like the CC paradigm, Veracode looks to establish a partnering relationship with vendors. It discloses its testing results to vendors and feeds remediation guidance back to the software developer. An excellent description of the security evaluation processes to be performed in conjunction with the VAST program is available.62

� The AV-Test Institute performs analyses of security products or constituent components.63 It also performs comparative tests or tests of beta software. Eval- uations use AV-Test’s own daily-expanding malicious and safe test data samples, and its own analysis tools, as well as private test criteria. The criteria are based on protection (including, e.g., protection against zero-day malware attacks), re- pair (e.g., in terms of performance in detecting and removing hidden malware), and usability (including, e.g., performance slow-downs of computers using tested products). Based on a scoring system that depends on test results, the Institute awards certification seals of approval. Recertification occurs periodically. Com- parative test results for different product classes often appear in the trade press. For example, test results for several Windows 8 virus scanners were recently summarized in the trade press.64

51.4.5 Security Assessment Standards for Products. In contrast to the informal, nonstandard product assessment approaches just discussed, formal standards exist for assessing various aspects of security associated with products or services. As detailed earlier, standards exist to assess the overall quality and soundness of product builders (Section 51.4.3.1) and their organization (Section 51.4.3.2) and to stipulate

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

STANDARD PRODUCT AND SERVICES ASSESSMENT APPROACHES 51 · 23

sound development methods for product builders (Section 51.4.3.3). A determination of security soundness based on these standards typically yield generalized conclusions such as “good” vendors build “good” products.

As detailed in the following sections, other standards can be followed to assess prod- uct quality, service quality, or a combination of both the quality of product builders as well as the quality of their products. The latter standards can be used to quantify how well “good” vendors build “good” products (with identifiable and demonstrable assurance levels), how much “better” specific vendors can build even “better” products (with identifiable and demonstrable, generally higher assurance levels), and how com- prehensive are the security functionalities within the specific classes of products these vendors build. Similarly, at least one standard exists for verifying that “good” service providers offer “good” services.

Examples of product assessment and service assessment approaches that rely on formal standards are described in Section 51.5 below.

51.5 STANDARD PRODUCT AND SERVICES ASSESSMENT APPROACHES

51.5.1 Government Standard Cryptographic Validation Programs. The evolving FIPS 140 series of standards65 specify requirements that are to be sat- isfied by cryptographic modules. In computer and telecommunications systems used or outsourced by the federal government, the U.S. Government mandates use of val- idated cryptographic modules for all uses of cryptography that protect “sensitive but unclassified” information. FISMA removes any possibility of receiving a waiver to the government FIPS 140 mandate. The Canadian government requires use of such mod- ules for protection of “designated information.” Other nongovernment organizations also look to use validated commercially available, crypto modules.

The FIPS 140 standards provide the basis for the long-standing, popular Crypto- graphic Module Validation Program (CMVP).66 This program is focused on testing, evaluating, validating, and certifying hardware and software cryptographic modules. A crypto module may be an embedded component within a product or application; or, it may be a standalone product in and of itself.

A prerequisite to cryptographic module validation is the validation of the cor- rect and complete implementation of the standard cryptographic algorithms used in cryptographic modules. The FIPS-approved standard symmetric key algorithms for encryption include the Advanced Encryption Standard which is the current algorithm of choice, Triple-DES and Skipjack. The Cryptographic Algorithm Validation Program (CAVP)67 uses CAVP-designed validation test suites for testing, evaluating, and vali- dating standard cryptographic algorithms using processes and methodologies similar to those described for the CMVP below. (Specific tests are described in companion NIST standards.) Details about the CAVP are not offered herein. Suffice it to indicate that thousands of cryptographic algorithm implementations have received algorithm validations to date.

FIPS 140-1 defines four increasing, qualitative levels of security assurance ranging from rock-bottom requirements stipulated in Level 1 to more, sequentially additive, security requirements in each of the subsequently higher levels. Security requirements address 11 different areas that pertain to the design and implementation of a crypto- graphic module.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 24 SECURITY STANDARDS FOR PRODUCTS

FIPS 140-2 and the emerging FIPS 140-3 apply to more contemporary cryptographic module implementations. They incorporate changes in crypto module technology, and in the case of FIPS 140-3 add new requirements and an additional assurance Level 5.

Special security testing laboratories conduct standard cryptographic module con- formance testing against requirements stated in FIPS 140-2 or FIPS 140-1. There are numerous such independent, commercial, third-party, so-called Cryptographic and Se- curity Testing laboratories—each individually accredited by NIST’s National Voluntary Laboratory Accreditation Program (NVLAP).

Entities that are looking to have crypto module validations performed must contract with any of these laboratories for the service of testing crypto modules and having such evaluations validated. Against the specific crypto module under test, these labs can perform appropriate, standardized conformance tests from a suite of standard conformance tests68 tailored to the four FIPS 140 security levels.

After validation that the test results from an accredited testing laboratory correctly and completely demonstrate that the crypto module under test conforms to either of the FIPS 140 standards, a CMVP certificate can be issued by either NIST or the Communications Security Establishment Canada (CSEC). The certificate includes an evaluation score determined from the above testing.

NIST maintains a repository list of cryptographic modules—past and present—that have been tested and validated.69 It should be noted that more products than appear in the repository of validated crypto modules may embed a validated module that is listed in the repository. NIST also maintains a list of crypto modules that are in the process of being evaluated.70

The FIPS 140 testing and validation scheme is not as broad, flexible and far-reaching as the CC scheme (Section 51.5.3) that is also used for product evaluation and certifi- cation. Why? Because the FIPS 140 scheme is focused on just one class of entities— cryptographic modules—whereas the CC scheme is applicable to any and every class of products as well as to a wider set of possible assurance requirements on the design, implementation, deployment, and maintenance of products. Furthermore, the FIPS 140 security requirements do not map directly to any specific CC security requirements. As such, when an FIPS 140 certificate is required, a CC certificate cannot be substituted.

51.5.2 FedRAMP. The FedRAMP program is a U.S. Government program that supports federal government agencies’ adoption of commercial or government cloud services.71 Such cloud services may be provided according to any one of several differ- ent service delivery models, such as Infrastructure as a Service (IaaS) or Platform as a Service (PaaS). FedRAMP is a different type of U.S. Government security assessment and certification program. It is not oriented specifically to security-relevant products. Instead, it is oriented to evaluating service providers and the systems they employ—in particular, cloud service providers.

FedRAMP’s standard processes benefit both cloud service providers and cloud ser- vice customers. A single, third-party assessment of a cloud service provider’s security claims reduces cloud service provider security evaluation costs by eliminating re- assessment for different cloud customers. Successful assessments receive government authorization that allows any or all government agencies to use the authorized cloud service provider’s offering.

FedRAMP uses a standards-based and risk-based approach that relies on:

1. Security Requirements Standards that require cloud providers to implement security capabilities that address standard FedRAMP security requirements.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

STANDARD PRODUCT AND SERVICES ASSESSMENT APPROACHES 51 · 25

2. Security Assessment Standards that require approved, independent, third par- ties to audit and to assess cloud service provider offerings and to develop a security assessment report.

3. Government Authorization Standards that are used by the FedRAMP Joint Authorization Board to review the security assessment reports and to achieve and to issue consistent standardized authorizations for government agencies to use approved cloud service provider offerings.

4. Continuous Monitoring Standards that require specified, standard “Ongoing Assessment & Authorization” activities that include ongoing, periodic reassess- ment of cloud service provider systems to reaffirm compliance with FedRAMP security requirements, to reaffirm that required security controls are still effective, and, therefore, to retain ongoing authorization.

5. Authorized Services Lists that identify cloud service providers that have achieved either an “Authority to Operate” certificate from the authorizing gov- ernment agency or a “Provisional Authority to Operate” certificate from the FedRAMP Joint Authorization Board and therefore are available for use by any government agency. (Lists of authorized cloud service providers are available at the GSA’s Website).72

FedRAMP security requirements to be addressed by cloud providers are compli- ant with FISMA. They are based on security controls enumerated in NITS Special Publication 800-53, Revision 3, which adds cloud-oriented security controls not found in earlier versions of this standard. FedRAMP security assessments add additional controls to FedRAMP assessments that are not included in FISMA assessments.

FedRAMP assessments are initiated either by individual cloud service providers or by government agencies that wish to use cloud services.

A cloud service provider (or the government agency interested in obtaining cloud services) hires a FedRAMP-accredited, commercial, third-party security assessment organization, a so-called Third Party Assessment Organization (3PAO). 3PAOs use FedRAMP standards:

(a) To develop a security assessment plan that is specific to the cloud service provider to be assessed and that specifies the security controls to be assessed, how the controls are implemented within the cloud service provider’s environment, se- curity and privacy behavior rules, the boundaries of the cloud service provider’s environment, and other security-related plans,

(b) To conduct a security assessment of the cloud service provider’s security controls to determine the effectiveness of the implementations of all security controls identified in the security assessment plan, and

(c) To develop a security assessment report to be submitted for authorization ap- proval of the cloud service provider being assessed.

If necessary, the cloud service provider will develop and execute a plan for correcting any weaknesses or flaws identified during the 3PAO security assessment.

If authorization is awarded, then according to FedRAMP’s continuous monitoring standard, a 3PAO may conduct annual, follow-up, security reassessments of the cloud service provider’s systems in order for the cloud service provider to maintain FedRAMP authorization to continue to be used by government agencies as an approved cloud service provider.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 26 SECURITY STANDARDS FOR PRODUCTS

Parties wishing to become FedRAMP 3PAOs must be rigorously evaluated according to FedRAMP standard quality and acceptability criteria used to ensure 3PAO security assessment competency as well as conformity among 3PAOs’ security assessment processes.

To leverage the benefits of using an assessed and authorized cloud service provider, government agencies are being encouraged to require, contractually, that their prospec- tive cloud service provider meets FedRAMP security requirements.

Details about FedRAMP, its processes and guidance on how to use the FedRAMP processes are available.73

In an effort to be watched, the Cloud Security Alliance is contemplating though its Open Certification Framework (OCF) and Security, Trust & Assurance Registry (STAR) efforts (Section 51.4.4.3.2) to develop what appears could be an international version of a FedRAMP style of cloud service provider assessment and certification.

51.5.3 Common Criteria. Out of the experiences gleaned from the Orange Book and other national criteria (Section 51.4.1), a new, commercially driven, stan- dard strategy emerged for testing products and for demonstrating confidence that their security features behave properly. This best-of-all-previous-breeds strategy is based on an international standard, ISO Standard 15408, the Common Criteria for Informa- tion Technology Security Evaluation, referred to colloquially as the Common Criteria (CC).74

The CC strategy offers a single, internationally recognized, approach for specifica- tion of consumer security requirements and for commercial evaluation of IT product security. Products can be built in any country, evaluated in any other country, and bought with confidence in yet any other country. This CC approach is useful within several international communities. In the United States, it is embraced by the DoD market sector and other communities such as the financial sector.

The CC paradigm presents a standard strategy that overcomes shortcomings of other approaches. It provides a standard way for stipulating (1) the risks of concern, (2) the security functional requirements that must be met in order to mitigate stated risks, and (3) the security assurance requirements that must be met to provide confidence that products are built with desired quality. It provides a recognized, reliable, maintained mechanism to develop trust that:

1. Security requirements are specified correctly, 2. Vendors do not misunderstand the requirements, and 3. Vendors design and manufacture products that address the requirements and

provide risk integrity.

The CC provides a flexible process for specifying and testing security requirements for any and all classes, and specific instances, of all existing or future IT products.

In the CC paradigm, consumers’ risks and protection requirements are stipulated so that product builders’ security solutions can be tested (in a standard way) so as to be able to verify (in a standard way) product compliance with stipulated standard security requirements. Testing is performed by any one of the testing laboratories that are accredited (in a standard way).

Unlike other approaches, the CC provides a way to specify assurance requirements and to evaluate how well they are met. Assurance requirements are extremely important and are typically not considered in other product assessment approaches. Assurance

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

STANDARD PRODUCT AND SERVICES ASSESSMENT APPROACHES 51 · 27

requirements are the essential ingredients in establishing confidence in implementations of security and in providing the level of trust necessary for economies and governments to rely on new e-business and e-government models.

Trust in products is established by gaining confidence that the security functionalities claimed to be implemented to address specific security functional requirements (1) are effective in satisfying specified security objectives and (2) are implemented correctly and completely and operate as expected. Through security assurance requirements, trust is further established by ensuring that product developers have sound processes and take specified actions to ensure specified quality throughout the life cycle of the product they build, test, deliver, and maintain.

The CC also establishes a standard method to develop common tests and evaluation methods and to use them to verify the security aspects of products via competent, accredited laboratories. CC-based testing helps manufacturers reduce costs by provid- ing a pool of private, licensed, competitive, security testing labs that have consistent, accredited testing quality and competence. Because testing is standardized and rec- ognized worldwide, testing costs are, in effect, capped because product vendors are spared costly country-specific or customer-specific retesting campaigns.

Assessments of products are composed of both analysis and testing of the product. Use of standard evaluation criteria and standard evaluation methodology leads to repeatable, objective test and evaluation results. To remedy assessment-discovered shortcomings and flaws in products, CC testing labs feed back testing results to product vendors and work collaboratively to resolve discovered flaws and shortcomings.

Independent review and validation of CC-based testing and evaluation by accred- ited, country-specific, national CC validation bodies boosts consumers’ confidence even further. Such CC validation bodies verify test results and certify that products were successfully assessed according to the standard testing and evaluation performed by accredited CC testing labs. These bodies are also responsible for maintaining na- tional security testing and evaluation infrastructures that include (a) correct, consistent, credible, competent, and commercial application of CC standards and methodologies by accredited CC testing labs within their country, (b) a government oversight body, and (c) a government security evaluation certificate issuing authority.

The CC specification and testing approach is equally applicable to any and all types of security-relevant products, such as:

(a) Products that implement security technologies (e.g., crypto boxes, intrusion detection/prevention systems, boundary protection devices and systems, audit tools, access control devices, digital signature products, and much more),

(b) Products that are security-enabled (e.g., messaging systems, database manage- ment systems, Web e-commerce packages, telecom switches, industrial control systems, and much more), or

(c) Products that support security (e.g., operating systems, certificate management systems, network management systems, smart cards, and more).

An ever-growing list of thousands of products that have been evaluated according to CC-based standard testing and that have received CC certifications is available online.75

In short, the CC paradigm grows the pool of better-engineered, more acceptable products.

As certified products are altered or upgraded, vendors of such products can pursue a standard assurance maintenance process to retain the assurance level associated

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 28 SECURITY STANDARDS FOR PRODUCTS

with initial certifications of such products. Information about this process appears elsewhere.76

The CC is today’s unified choice for developing trust in products. The use of standards tends to increase the product appeal to various nonrelated consumer con- stituencies. A product builder’s security culture is significantly improved because of the required verification of the builder’s meticulous and clear focus on security, as well as the builder’s security design, development, testing, and maintenance disciplines. Such culture improvement tends to benefit other products built by the vendor.

Some—especially proponents of the 20 Critical Controls paradigm (Section 51.4.2.1)—seem to feel that the CC approach is too flexible, requires too much exper- tise to capitalize on its flexibility, and would be better if it specified a small, mandatory set of “common-sense” controls of value in “most” situations.

Reciprocally, well-respected consulting houses have concluded that CC evaluation provides a substantial improvement over the nonstandard or informal testing approaches that typically result in seriously undertested software and that, as a group of inconsistent approaches, provide only “apples-to-oranges” comparisons of tested products. The CC paradigm provides an extra level of due diligence. It improves and differentiates products and allows buyers to compare products objectively. It is accepted by mutual agreement in most of the world’s largest IT-building and IT-buying countries.

More details about the CC paradigm are given in Section 51.5.3.1. An overview of the two types of security profiles that can be developed by product consumers and product vendors appears in Section 51.5.3.2. A summary for using the CC to document consumers’ security needs for products is given in Section 51.5.3.3. Section 51.5.3.4 provides a summary for using the CC to document the security features built into vendor products. More details about the CC testing and evaluation approach appear in Section 51.5.3.5. More detailed descriptions of the underlying CC standards and how to use them appear elsewhere.77

51.5.3.1 Common Criteria Paradigm Overview. The CC paradigm uses international standards, processes, and procedures to specify, to test, to validate, and to certify security-related products.

The CC paradigm is a multipurpose scheme for:

� Stipulating security requirements that can be used in product procurements, � Specifying companion security solutions in products, � Testing products according to product-tailored—but standard—criteria and testing methodologies using accredited, third-party, commercial testing laboratories,

� Independently validating test results, and � Providing certificates to tested and validated products that obviate any need for further product retesting for differing consumer constituencies or in all countries that mutually recognize each other’s commercial testing capabilities and testing results.

Consumers use a standard methodology, a standard language, and a catalog of stan- dard security requirements to develop security profiles (see Section 51.5.3.3) tailored to the types of products they want to purchase. The profiles stipulate the security func- tional needs. They also stipulate the confidence or assurance desired in products as well as in product builders’ processes from product design through maintenance.

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

STANDARD PRODUCT AND SERVICES ASSESSMENT APPROACHES 51 · 29

Product builders use the same standard methodology, language, and catalog to develop different types of security profiles (see Section 51.5.3.4) to define their prod- ucts’ security specifications. They define product security specifications in terms of both security functionality and security assurance about the product and the builders’ processes. The builders’ specifications show how their products meet stated consumer security functionality and assurance needs. Builders’ specifications may also show how their products meet any additional builder-claimed security features that go beyond the consumers’ stated needs.

51.5.3.2 Specification Elements of the CC Paradigm. The CC standard defines the language used within, the methodologies used to construct, and structures for two types of security profiles that specify security requirements: protection profiles (PPs) and security targets (STs).

PPs help consumers articulate what risks and vulnerabilities are important, while STs help vendors articulate what risks and vulnerabilities are addressed by their prod- ucts. PPs help consumers articulate what level of protection and confidence they want in products, while STs help vendors articulate what level of protection and confi- dence are provided by their products. PPs provide a standard and flexible way to transform consumers’ security needs and policies into unambiguous, product-neutral, security requirements for the desired security behavior and quality for any class of IT product.

Both security functional requirements and assurance requirements are included in these two types of profiles. Functional requirements define desired security behavior and are extracted from a standard CC catalog of hundreds of such requirements. As- surance requirements provide the basis for establishing trust by putting constraints on how well a product or a profile is built. Assurance requirements are also catalogued in a CC standard as requirements that pertain to, for example, (a) configuration manage- ment of the product, (b) design, development, delivery, and operation of the product, (c) maintaining assurance throughout the product’s life cycle, and (d) much more.

Assurance requirements are bundled into seven standard predefined packages called Evaluation Assurance Levels (EALs). Higher assurance level bundles (e.g., EAL4) contain more rigorous assurance requirements needing more rigorous methodologically design and testing than lower, entry-level bundles (e.g., EAL1) that need only functional testing. EALs are enumerated in a monotonically increasing scale that balances (a) the increasing levels of confidence that can be obtained, with (b) the increasing cost and decreasing feasibility of conducting the testing and evaluation necessary to develop a specific, higher level of confidence. The higher the assurance level, the more aspects of a vendor’s development process will need to be examined during product test and evaluation.

At the low end, EAL1 can be used, for example, to support the contention that baseline due care has been exercised with regard to protection of personal information and to establish some minimal degree of confidence in correct operation of a product in an environment where the threats to security are not considered very serious. At the highest extreme, EAL7 requires a formally verified design and extensive formal analysis. EAL7 may be applicable to certain highly specific, perhaps one-of-a-kind products, targeted for extremely high-risk situations or where the high value of the assets being protected justifies the extraordinary costs of an evaluation to this level of confidence. Typical commercial products fall in the range from EAL1 to EAL4.

When specifying assurance requirements, the desired level of assurance—and the cost to attain such assurance—should be balanced against factors, such as (1) the value

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 30 SECURITY STANDARDS FOR PRODUCTS

of the resources to be protected, (2) the risk and extent of possible losses, (3) the level of confidence desired, and (4) any reasonably expected cost and delay factors that may accompany the development, and any subsequent testing, evaluation, and validation of a product at a specific level of assurance.

While a PP stipulates generic, product-neutral, security functional and assurance requirements for some specific class of IT product that meets the needs of prospective buyers, an ST is a product-specific stipulation of the security functional and assurance requirements addressed by a single, specific product along with information as to how the implemented product meets the stated security requirements.

As stipulated in its accompanying ST, a specific product may claim conformance to one or more PPs as well as to additional product-specific security requirements enumerated within its ST.

Given the breadth, depth, and changeability of possible security requirements that can be stipulated within PPs or STs, the CC provides the ability to stipulate the user requirements and product requirements of virtually an unlimited number of ex- isting and yet-to-be-conceived consumer security needs (PPs) and security product solutions (STs).

The purpose of CC-based testing and evaluation of a product is to evaluate and to confirm that the product meets the product-specific requirements and evaluation criteria contained in the product’s ST. The STs’ assurance requirements impact the requisite depth and breadth of testing and evaluation.

Many products that are successfully tested and evaluated will go further and have their test and evaluation results validated by a formal, recognized, CC national valida- tion body. Products can then be certified by a government certificate issuing authority and added to the publicly viewable repository that lists CC-certified products.

51.5.3.3 Constructing Protection Profiles. PPs enumerate consumers’ se- curity functional and assurance needs that are appropriate and valuable for a specific type of product to mitigate specific risks in a specific threat environment. Each PP states the security problem that a PP-compliant product is intended to solve. It stipulates the security functional requirements that are known to be useful and effective in meeting specific security objectives. It also stipulates the security assurance requirements that provide the confidence desired that products are built with desired quality.

The main contents of a PP include statements about the:

1. Threats and Vulnerabilities to which a product will be exposed, 2. Security Environment within which a product is to reside, including (a) de-

scriptions of both the IT and non-IT aspects of the environment, (b) assumptions about the product’s usage, administration, and management, and (c) all policies, laws, regulations, and rules to which the product must comply within the intended environment,

3. Security Objectives to be met either by a product or the environment within which the product operates, including descriptions of which threats and poli- cies are to be addressed by the product and which are to be addressed by the environment,

4. Security Requirements, both functional and assurance requirements, selected and refined from the standard CC requirements catalogs, to meet each security objective and assumption, indicating which requirements are addressed by a product and which by the environment within which it operates, and

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

STANDARD PRODUCT AND SERVICES ASSESSMENT APPROACHES 51 · 31

5. Rationale that is provided to justify all decisions and choices made in developing the content within a PP. Rationale includes statements such as how selected security requirements are suitable to counter the enumerated threats, how they comply with enumerated policies and assumptions, and how they map back to the original, underlying, driving needs and threats.

Guidance for developing PPs is available.78 A list of PPs that were formally validated for correctness is maintained at the CC Website.79

51.5.3.4 Constructing Security Target Profiles. Product developers create STs to document detailed information about the security aspects of products they build and to specify how implemented security functions and assurance measures meet consumers’ needs.

A ST provides the basis and the evaluation criteria against which testing and evalua- tion of the product are performed. It also specifies the configuration in which a product is to be tested.

The contents of an ST are similar to a PP. The ST describes the environment within which the product described via an ST is intended to operate. The ST enumerates the (a) threats to the product, (b) policies, laws, and regulations with which the product is claimed to conform, and (c) assumptions about the security aspects of the IT and non-IT environment within which the product is intended to be used. STs delineate the security objectives that the builder of a specific product claims are addressed by the product. STs also enumerate the security requirements that the product builder claims are addressed by the product as well as those requirements to be addressed by the environment within which the product is intended to operate. Some of these requirements may be refinements of generic or product-neutral requirements stipulated in a PP to which the ST claims compliance; and some may be additional security requirements over and above those stipulated in any PPs to which the product claims to be conformant.

However, the ST goes beyond a PP because it also specifies the security functions offered by the product to meet each of the stated security requirements in the ST. It also specifies the assurance measures taken by the product builder to meet all the stated assurance requirements in the ST.

Rationale is also provided for all decisions and choices made in developing the ST content. Rationale justifies all claims made in an ST about the PPs with which the product conforms. In essence, the rationale provided demonstrates that the ST contains an effective and suitable set of countermeasures and that this set of countermeasures is consistent, complete, and cohesive.

By comparing the STs of different products, consumers are better able to compare the security features of competing products. Consumers are able to understand what types of tests and evaluations that a specific product underwent. They also are able to determine whether the configuration in which a product was tested is consistent with the environment into which the product will be deployed.

51.5.3.5 Common Testing of Products. Products characterized by asso- ciated product-specific STs can undergo standard CC testing and evaluation using standard testing methodology by any officially accredited/licensed CC testing and evaluation laboratory anywhere in the world. Testing assures that products are correct, complete, well built, and compliant to their security specifications. Testing is conducted under conditions appropriate to the intended normal operation of the product so as to

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 32 SECURITY STANDARDS FOR PRODUCTS

verify that the implemented security is correct, complete, and compliant under normal operations. Since CC-based testing can demonstrate the traceability of the security aspects of a product back to product user requirements as well as to applicable policies, laws, and regulations, such testing can reduce product users’ exposure to potential penalties for noncompliance to security-relevant laws or regulations.

Testing labs and their staff are accredited for their security assessment competence, as specified in a security-testing-laboratory extension80,81 to an ISO standard82 specify- ing general testing laboratory competency requirements. As defined in the CC’s Com- mon Evaluation Methodology (CEM)83 standard, evaluators use a standard methodol- ogy with structured, formal assessment processes and evaluation actions to carry out a series of standard testing and evaluation activities.

Since testing is done according to standards, consumers get a strong sense that testing is objective and not slanted to benefit the product that was tested. With the additional trust created by CC testing, customers reduce their product acquisition costs by minimizing acceptance testing that duplicates testing already performed on a product by an accredited CC testing lab. Studies indicate that CC testing improves products by eliminating exploitable security flaws and adding or extending necessary security features.

The CEM standard provides a common base for independent, autonomous CC test- ing laboratories to assess CC profiles and vendor products in the same ways, regardless of the CC testing lab being used. Use of the CEM by all CC testing labs provides a common floor of confidence in similar products that may have been assessed by different CC testing labs. Indeed, the Common Criteria Arrangement on the Mutual Recognition of the Common Criteria Certifications in the Field of Information Tech- nology Security, often called just the Mutual Recognition Arrangement (MRA), is the multicountry, treaty-level declaration that different countries will recognize the CEM/CC-based assessments that may be conducted by CC testing labs in each other’s jurisdictions.

Because the CEM is internationally recognized, the use of customer-unique or country-unique assessment is minimized, if not avoided all together. Assessment costs are minimized, since vendors need only prepare for one testing campaign rather than for a battery of different testing campaigns conducted against different customer-specific, consulting-house-specific, or country-specific, assessment criteria.

Although some consumers and vendors believe that the CC paradigm is complicated, inefficient, or costly, the many who do build and buy validated products see the CC paradigm as the best, proactive way to improve the security and assurance of products bought and sold in the marketplace.

51.6 NOTES 1. “Federal Information Security Management Act of 2002” (Title III of the E-

Government Act of 2002), U.S. Public Law 107-347, Section III, December 2002, http://csrc.nist.gov/drivers/documents/FISMA-final.pdf

2. In this chapter, de facto means accepted as a matter of common practice; de jure is used idiosyncratically to mean accepted under written standards (but not the usual meaning of according to law).

3. U.S. Department of Defense Instruction, “DoD Information Technology Secu- rity Certification and Accreditation Process (DITSCAP),” 5200.40, December 30, 1997, http://iase.disa.mil/ditscap/i520040.pdf (URL inactive).

4. www.diacap.org

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

NOTES 51 · 33

5. PCI Security Standards Council, PCI Standards & Documents, “PCI SSC Data Security Standards Overview,” see link for PCI Data Security Standard: https:// www.pcisecuritystandards.org/security standards/

6. The terms testing, evaluation, and assessment are a source of ambiguity and discrepancy in the community. In this chapter, these terms are used interchangeably.

7. ISO is not an acronym; it is a reference to the Greek prefix isos (equal) and ensures that the abbreviation for the organization is identical in all languages. See “Our name” in the page www.iso.org/iso/home/about.htm

8. U.S. Department of Defense Directive 8500.1, “Information Assurance (IA),” October 24, 2002, www.acq.osd.mil/ie/bei/pm/ref-library/dodd/d85001p.pdf

9. Department of Defense Instruction 8500.2, “Information Assurance (IA) Imple- mentation,” February 6, 2003, www.dtic.mil/whs/directives/corres/pdf/850002p .pdf

10. www.dtic.mil/whs/directives/corres/pdf/857001m.pdf 11. https://cloudsecurityalliance.org 12. https://www.pcisecuritystandards.org/ 13. www.safecode.org/index.php 14. http://omg.org 15. www.webappsec.org 16. www.tmforum.org 17. www.sans.org 18. www.sans.org/critical-security-controls 19. www.microsoft.com/en-us/download/details.aspx?id=18015 20. www.microsoft.com/security/sdl/default.aspx 21. U.S. Department of Defense Instruction, “DoD Information Technology Secu-

rity Certification and Accreditation Process (DITSCAP),” 5200.40, December 30, 1997, http://iase.disa.mil/ditscap/i520040.pdf (URL inactive).

22. National Security Telecommunications and Information Systems Security In- struction (NSTISSI) No. 1000, “National Information Assurance Certification and Accreditation Process (NIACAP)” (April 2000), www.cnss.gov/Assets/pdf/ nstissi 1000.pdf

23. NIST Special Publication 800-37, “Guide for the Security Certification and Accreditation of Federal Information Systems (May 2004), http://csrc.nist.gov/ publications/nistpubs/800-37/SP800-37-final.pdf

24. “Information Technology—Security Techniques—Code of Practice for Informa- tion Security Management,” ISO/IEC 17799 (2005), www.iso.org/iso/catalogue detail?csnumber=50297

25. Joint Task Force Transformation Initiative (Ron Ross, JTF Leader), “Secu- rity and Privacy Controls for Federal Information Systems and Organizations,” NIST Special Publication 800-53, Revision 4, April 2013, http://nvlpubs.nist.gov/ nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf

26. U.S. Department of Defense, “Trusted Computer System Evaluation Criteria,” (TCSEC or Orange Book), DOD5200.28-STD (December 1985), http://csrc .nist.gov/publications/history/dod85.pdf

27. National Computer Security Center, National Security Agency, “Trusted Net- work Interpretation of the Trusted Computer System Evaluation Criteria”

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 34 SECURITY STANDARDS FOR PRODUCTS

(TNI), 9800 Savage Rd., Ft. Meade, MD 20755, July 31, 1987, www.ntis.gov/ search/product.aspx?ABBR=ADA255422 See also “Trusted Network Interpreta- tion Environments Guideline,” www.fas.org/irp/nsa/rainbow/tg011.htm

28. National Computer Security Center, National Security Agency, “Trusted Database Management System Interpretation of the Trusted Computer System Evaluation Criteria,” NCSC-TG-021, 9800 Savage Rd., Ft. Meade, MD 20755, April 1991, www.ntis.gov/search/product.aspx?ABBR=ADA393253

29. Office for Official Publications of the European Communities, “Information Technology Security Evaluation Criteria” (ITSEC), Luxembourg (June 1991), www.ssi.gouv.fr/site documents/ITSEC/ITSEC-uk.pdf

30. www.sans.org/critical-security-controls/cag4.pdf 31. www.sans.org/critical-security-controls/guidelines.php 32. https://cloudsecurityalliance.org/guidance/csaguide.v3.0.pdf 33. ISO 9000—Quality Management, www.iso.org/iso/iso 9000 34. L. Constantin, “Security Appliances are Riddled with Serious Vulnerabili-

ties, Researcher Says,” PCWorld, March 15, 2013, www.pcworld.com/article/ 2030965/researcher-security-appliances-are-riddled-with-serious-vulnerabilities .html

35. for example, P. Wayner, “17 Security Tips for Developers to Safeguard Code,” CIO Newsletter, February 4, 2013, www.cio.com/article/728207/17 Security Tips for Developers to Safeguard Code?page=2&taxonomyId=3089

36. Mead, N., and B. Hawthorne, “Transitioning from Software to Software Assur- ance,” IEEEComputer Society,CNComputingNowNewsLetter, October 17, 2012, www.computer.org/portal/web/computingnow/security/content?g=53319&type= article&urlTitle=transitioning-from-software-to-software-assurance or http://tiny url.com/ld4fq5k

37. Summary guidelines for secure software design in cloud and Web environments are available in D. Radcliff, “Code Surety: Secure by Design,” SC Magazine, March 1, 2012, www.scmagazine.com//code-surety-secure-by-design/article/228646/4/

38. An ambitious Eliminate Vulnerable Code project (http://www.digitsec.com/ evc.htm) was initiated to crawl the Internet to find pieces of vulnerable, publi- cally available code and to work remove such vulnerable code from the public domain (see Section 51.4.4.4). It is not clear such an effort will succeed.

39. Microsoft, “Security Development Lifecycle,” www.microsoft.com/security/sdl/ default.aspx

40. K. J. Higgins, “Secure Software Standard In the Spotlight,” Security Dark Reading Applications News Letter, May 15, 2013, www.darkreading.com/ vulnerability/secure-software-standard-in-the-spotligh/240154983

41. IBM Global Technology Services, Thought Leadership White Paper, “Select- ing a Managed Security Services Provider: The 10 Most Important Criteria to Consider,” May 2011, http://www-03.ibm.com/innovation/us/engines/assets/ Selecting MSS provider whitepaper SEW03026-USEN-00.pdf

42. TechRepublic, “Antivirus Evaluation Guide” provided by GFI Software, January 2013, www.techrepublic.com/resource-library/whitepapers/antivirus-evaluation- guide/

43. L. Musthaler, “Ixia Models Attacks on Your Systems so You Can Test Your De- fenses,”NetworkWorldInfrastructureManagementNewsletter, February 28, 2013,

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

NOTES 51 · 35

www.networkworld.com/newsletters/techexec/2013/030113bestpractices.html? source=NWWNLE nlt it best practices 2013-03-04

44. www.vpnc.org 45. www.vpnc.org/testing.html 46. https://cloudsecurityalliance.org/star 47. www.cse-cst.gc.ca/its-sti/services/cc/smartcard-sug-v30-eng.html 48. www.commoncriteriaportal.org/files/ppfiles/UNKT-DO-0002%20v1-0.pdf 49. E. Messmer, “Security of Open-Source Software Again Being Scrutinized,”

Network World Security News Letter, March 13, 2013, www. networkworld.com/ news/2013/031313-opensource-security-267636.html?source=NWWNLE nlt compliance 2013-03-15

50. K. J. Higgins, “Project Finds, Purges Vulnerable Code Snippets From the NET,” Security Dark Reading Database Security News, May 23, 2012, www.dark reading.com/applications/project-finds-purges-vulnerable-code-sni/240000936

51. https://evc.digitsec.com 52. www.owasp.org/index.php/Category:OWASP Top Ten Project 53. www.sans.org/top25-software-errors 54. www.commoncriteriaportal.org/products 55. www.scmagazine.com 56. www.networkcomputing.com 57. www.securitymagazine.com/ 58. www.infoworld.com/ 59. www.scmagazine.com/group-tests/section/108/ 60. www.icsalabs.com 61. M. E. Kabay was the first Secretary of the Anti-virus Product Developers’ (AVPD)

Consortium created in the early 1990s by the NCSA (the National Computer Security Association, later renamed ICSA and then TruSecure). In a personal communication, he reported that anti-virus vendors were using radically differ- ent standards for their definition of anti-virus coverage; with a few thousand known viruses in the world, some vendors claimed to combat thousands and others only hundreds. When the NCSA told the new AVPD members that the first test would require them to identify and block only 75 percent of Joe Wells’ WildList, many of the technical staff from the companies laughed. They didn’t laugh so much when many of their products failed the initial round! Over the next rounds of testing (4 per year), the percentage of coverage of the WildList rose to 100 percent and then went on to include other viruses in the “zoo” of laboratory- identified viruses that had not yet spread to ordinary computer users’ computers. According to Kabay, the NCSA program led to major improvements in the qual- ity of anti-virus products and increased clarity. He argues that the insights and methods developed in the AVPD were then applied successfully to other security products.

62. Veracode, “Five Best Practices of Vendor Application Security Management,” White Paper, available in “The Secure Software Supply Chain Toolkit,” All Things Security Blog, September 20, 2012, www.veracode.com/blog/2012/09/the-secure- software-supply-chain-toolkit

63. www.av-test.org

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

51 · 36 SECURITY STANDARDS FOR PRODUCTS

64. “Ms. Smith,” “AV-Test issues first Windows 8 antivirus solution ratings,” Network World, April 8, 2013, www.networkworld.com/community/blog/av-test- issues-first-windows-8-antivirus-solution-ratings?source=NWWNLE nlt daily pm 2013-04-09 testA6

65. NIST, Computer Security Division, Computer Security Resource Center, CMVP, “Standards,” http://csrc.nist.gov/groups/STM/cmvp/standards.html

66. NIST, Computer Security Division, Computer Security Resource Center, CMVP, “Cryptographic Module Validation Program,” http://csrc.nist.gov/groups/STM/ cmvp/ index.html

67. NIST, Computer Security Division, Computer Security Resource Center, CAVP, “Cryptographic Algorithm Validation Program,” http://csrc.nist.gov/groups/STM/ cavp/ index.html

68. CMVP Program Staff, “Derived Test Requirements for FIPS PUB 140-2, Se- curity Requirements for Cryptographic Modules” (draft), published by NIST, January 4, 2011, http://csrc.nist.gov/groups/STM/cmvp/documents/fips140-2/ FIPS1402DTR.pdf

69. NIST, Computer Security Division, Computer Security Resource Center, CMVP, “Module Validation Lists,” updated periodically as new validations emerge, last updated August 27, 2013, http://csrc.nist.gov/groups/STM/cmvp/validation.html

70. http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140InProcess.pdf 71. www.gsa.gov/portal/category/102371 72. www.gsa.gov/portal/content/131931 73. U.S. DoD, DHS, GSA, NIST, “Guide to Understanding FedRAMP,” Version 1.2,

April 22, 2013 (and subsequent versions), www.gsa.gov/portal/category/102375 (“Key Documents” link on “About FedRAMP”)

74. The Common Criteria Portal, www.commoncriteriaportal.org 75. Common Criteria Certified Products, www.commoncriteriaportal.org/products 76. S. Amiri, “Significance of Common Criteria Assurance Maintenance (AMA),” SC

Magazine (September 22, 2004). www.scmagazine.com/significance-of-common- criteria-assurance-maintenance-ama/article/31385

77. P. Brusil, “Security Standards for Products,” Chapter 51 in Computer Security Handbook (5th ed.), ed. S. Bosworth, M. E. Kabay, and E. Whyne (Wiley, 2009).

78. Technical Report ISO/IEC TR 15446, “Information Technology—Security Techniques—Guide for the Production of Protection Profiles and Security Tar- gets” ISO/IEC TR 15446:2004, July 2004, http://standards.iso.org/ittf/Publicly AvailableStandards/c039690 ISO IEC TR 15446 2004(E).zip [Available in the extensive list of “Freely Available Standards” http://isotc.iso.org/livelink/livelink/ fetch/2000/2489/Ittf Home/PubliclyAvailableStandards.htm]

79. Common Criteria Certified Products, www.commoncriteriaportal.org/products 80. ISO/IEC Technical Report 13233, “Information Technology Interpretation of Ac-

creditation Requirements in Guide 25 Accreditation of Information Technol- ogy and Telecommunications Testing Laboratories for Software and Protocol Testing Services,” available for purchase online, www.iso.org/iso/iso catalogue/ catalogue tc/catalogue detail.htm?csnumber=21468

81. NIST Handbook 150-20, “Information Technology Security Testing—Common Criteria,” www.nist.gov/nvlap/upload/NIST-HB-150-20-2005-1.pdf—a techno logy-specific extension to J. L. Cigler and V. R. White, eds., NIST Handbook 150,

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

NOTES 51 · 37

“National Voluntary Laboratory Accreditation Program—Procedures and General Requirements,” U.S. Department of Commerce, Technology Administration, Na- tional Institute of Standards and Technology (Washington, DC: US Government Printing Office, 1994), www.nist.gov/nvlap/upload/nist-handbook-150.pdf

82. ISO/IEC/EN Guide 17025, “General Requirements for the Competence of Cali- bration and Testing Laboratories,” 2011, www.fasor.com/iso25

83. Common Evaluation Methodology Editorial Board, “Common Methodol- ogy for Information Technology Security Evaluation: Evaluation Methodol- ogy,” Version 3.1, Revision 3, July 2009, www.commoncriteriaportal.org/files/ ccfiles/CEMV3.1R3.pdf

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .

Bosworth, S., Kabay, M. E., & Whyne, E. (Eds.). (2014). Computer security handbook, set. Retrieved from http://ebookcentral.proquest.com Created from apus on 2018-04-09 22:37:14.

C o p yr

ig h t ©

2 0 1 4 . Jo

h n W

ile y

& S

o n s,

I n co

rp o ra

te d . A

ll ri g h ts

r e se

rv e d .