517-3 Yhtomit
WWW.IOMA.COM/SECURE MAY 2007ISSUE 07-05
In ThIS ISSUE
How a Scoring System Can Solve the What- Asset-to-Protect-First Dilemma ................. 1
How to Weed Out the New Insider Cybersecurity Threat. . 1
Is Your Dept. Doing Everything to Protect the Firm’s Brand? ..... 1
RETAIL SECURITY 10 Strategies to Maximize Value From Security Officers ....... 2
News Briefs .............. 8
l Workers passing drug tests like it’s 1988
l EAS systems can cause pacemaker malfunction
l And more...
SDR Calendar ........ 11
CONTINUED ON PAgE � CONTINUED ON PAgE 12
CONTINUED ON PAgE �
Random, Unannounced Drug Testing of Security Officers, by Industry ..................................................see story, page 8
(Source: IOMA)
how a Scoring System Can Solve the What-Asset-to-Protect-First Dilemma It would be nice if every facility was maximally protected—that is, if every major asset was certain to survive any assault and keep right on working as if nothing had happened. It would be nice, but it’s not realistic. That’s why executives charged with protecting facilities and assuring continuing operations need to know: If you had to choose, which facilities are you willing to lose? It’s a tough call, so it’s helpful to rely on a systematic strategy for scoring the importance of facilities and assets to the company mission.
The story of XYZ. XYZ Corporation is a large diversified company with several distinct business segments and operations spread out across the West
how to Weed Out the new Insider Cybersecurity Threat A recent face-off in Los Angeles between the city and union workers reflects how threats have evolved. A labor strike traditionally stokes fears that angry sign waving might deteriorate into verbal harassment, bottle or rock throwing, and property vandalism or assault.
But in August 2006, striking traf- fic engineers in Los Angeles alleg- edly voiced displeasure in a different way—by using their technical know- how to infiltrate the city’s traffic light system, fooling with programming codes and causing a dangerous traffic
Is Your Dept. Doing Everything to Protect the Firm’s Brand? As business has changed, so has the utmost critical function of security departments. For many, it is now protecting the company brand.
Luckily, the majority of what security depart- ments ordinarily do al- ready serves this goal. Keeping the company out of the headlines by pre- venting theft, violence, and lawsuits is central to protecting its good name. But not all aspects of brand protection flow
5.6%
23.1%
11.8%
34.8%
0% 10% 20% 30% 40% 50% 60% 70% 80%
Financial/Insurance
Energy/Utilities
Healthcare facility
Manufacturing
All
75.0%
www.ioma.com/SECURE �MAY 200�
SECURITY DIRECTOŔ S REPORT
Cybersecurity Threat CONTINUED FROM PAgE 1
efficiency of its traffic control system.
Luckily, the Carnegie Mellon study sug- gests that insiders who hack or sabotage IT systems usually tip their hand that they might do it. Its study showed that in 80% of cases, perpetra- tors appeared disgruntled, showed up late, argued with coworkers, and/or exhibited other performance problems before committing cyber- crimes against current or former employers.
The study found the cor- relation to be dramatic. “Insider disgruntlement con- tributes directly to the rate of inappropri- ate technical actions taken by the insider, especially actions that facilitate the attack.” In studying sabotage incidents, researchers found worker disgruntlement fell into three familiar categories. They are:
1. The insider expected certain technical freedoms using the organization’s com- puter and network systems, such as storing personal MP3 files, but was reprimanded by management for exercising those free- doms.
2. The insider expected to have control over the organization’s computer and net- work system, but control was revoked or never given.
3. The insider expected recognition or prestige from management but suffered some sort of rebuke instead, such as being passed over for a promotion.
SDR previously shared results from Carn- egie Mellon’s insider threat Study, but more recently its Management and Education of the Risk of Insider Threat (MERIT) project has developed and tested a learning model designed to make use of the information
CONTINUED ON PAgE 10
snarl around the city. This is the new insider threat, and companies can eliminate much of it by keeping a close eye on technical workers and those with system access, com- municating with managers who supervise them, and eliminating the easiest avenues for improper access.
Workers who have access to the purse strings have always presented an obvious insider threat, but in a technology-driven world, computer operators and specialists may be able to cause more damage via sabotage than any single employee could by stealing. That is one of the lessons from the Los Angeles traffic engineer strike, and it’s far from the only recent example. In the same month as the strike by Los Angeles traffic engineers, a former DuPont research scientist pleaded guilty to stealing secrets valued at $�00 million in an effort to give him a leg up in his new job.
Who should you fear? A Carnegie Mel- lon University study of insider cybersecurity breaches at critical industry companies discovered that a whopping 86% were committed by people in technical positions, and most of them had system administrator or privileged system access. In almost half of the incidents (�1%) involving IT system sabotage, the perpetrator was employed at the time; in the other 59%, the individual had been recently terminated.
What should you do? Los Angeles city officials acknowledged IT system sabotage is a tough security challenge, one they said they share with all companies that work in highly technical environments in which workers must be trusted enough to have access to important systems. The city said it could add additional security layers to improve protection against unauthorized insider activity, but that could hamper the
It’s possible that companies can cut insider incidents in half by simply making hackers at least work for them.
10 www.ioma.com/SECURE MAY 200�
SECURITY DIRECTOŔ S REPORT
Simulated Effects of Policy Levers to Mitigate the Insider Threat
Lever Description Effect
Employee intervention Positive interventions such as employee May not be effective if quality of assistance or counseling that attempt intervention is low. to lower disgruntlement directly and reduce inappropriate behavioral or technical actions by an insider.
Sanctioning Punitive measures that attempt to May have the opposite effect of motivate the insider to reduce his or increasing disgruntlement and her inappropriate behavioral or inappropriate actions. technical actions to avoid additional sanctioning.
Technical monitoring Real-time measures to track and If technical monitoring is not initiated analyze an insider’s online actions, or quality is low, management may not such as the use of access paths or have an accurate sense of the risk that information and resources accessed. an insider poses.
Training Education of employees on appropriate Training quality affects the rate of usage of computer and network inappropriate online actions and systems and the consequences if attacks by insiders. misused.
Tracking Efforts by management to keep track of Poor tracking leads to high rates of access paths. access paths unknown by management, making it more difficult to disable paths and easier for the insider to conceal his actions.
Auditing and disabling Efforts by management to discover, Facilitates discovery of access paths access paths understand, review, and disable access available to the insider. Poor audit paths available to the insider. Allows allows insiders to amass many comparing employees’ abilities and unknown access paths, making it efforts to access information, create easier to conceal actions and attack access paths, or use access paths after termination. against acceptable policies and procedures.
Termination threshold The threshold of risk posed by the Too high a threshold may give a insider to the organization above malicious insider additional time to which management fires the insider. attack the organization or take technical actions to set up an attack following termination. Too low a threshold may cause firing of valuable employees who just need a little intervention to solve their problems.
Termination time The time it takes the organization to If termination time is too long, the terminate an insider once the insider may maintain authorized access termination threshold is reached. to the system long enough to facilitate an attack. (Source: MERIT project, CERT Coordination Center)
www.ioma.com/SECURE 11MAY 200�
SECURITY DIRECTOŔ S REPORT
SDR Calendar:
Cybersecurity Threat CONTINUED FROM PAgE �
to reduce the risk from insiders. (“Manage- ment and Education of the Risk of Insider Threat (MERIT): System Dynamics Modeling of Computer System Sabotage,” CERT Pro- gram, Software Engineering Institute and CyLab at Carnegie Mellon University.)
In light of the finding that insiders are disgruntled first and strike later, the MERIT learning tool focuses on the connection between them. Within the gap, it suggests opportunity. If managers who supervise technical workers recognize performance and behavioral problems as a security threat—and report them as such—then companies may be able to prevent inci- dents.
It recommends: “Management should carefully consider concerning behavior by an employee who appears to be dis- gruntled following a negative work-related event, possibly increasing monitoring of the employee’s online activity.” It notes that a company can’t watch everyone online all the time, so it’s valuable to maintain awareness of employee dissatisfaction and troublesome behavior to target proactive system monitoring. “Targeted monitoring of online activity by employees of concern can prevent insider sabotage by detecting technical precursor activity immediately,” the report concludes.
The insider threat study pointed out an- other area in which defenses can be shored up. In 6�% of incidents, access involved virtual private networks and old passwords that the company had failed to terminate. It’s possible that companies can cut insider incidents in half by simply making hackers at least work for them.
However, the job is easier said than done. “Disabling access following termination is
important [but] in order to do so effectively, organizations must have full awareness of all access paths available to each of their employees.” An “access path” is a set of one or more access points leading to a critical system (such as employee badges, computer accounts, passwords, and Virtual Private Networks).
In its investigation of actual incidents, it discovered cases in which system admin- istrators created backdoor accounts with system administrator privileges, knowing that because account audits were not con- ducted, the account would not be detected and would facilitate the attack following termination.
An access path that is unknown to man- agement is not necessarily illegitimate, but organizations should reduce unknown ac- cess paths by identifying them, reviewing
emerging trends in Security and technology, San Antonio, May �-9. Contact: ASIS International, �03-519-6200; Web: www.asisonline.org
GoVSec 2007, Washington, DC, May 9-10. Contact: govSec, U.S. Law and Ready!, 800-68�-��69; Web: www. govsecinfo.com
17th Annual cardtech/Securtech conference and exhibition, San Francisco, May 15-1�. Contact: SourceMedia Confer- ences & Events, 800-803-3�2�; Web: www.ctst.com
Secure 360—Managing Risk in an unsecure World 2007 conference, St. Paul, MN, May 21-23. Contact: Upper Midwest Security Alliance, 952-893-1293; Web: www. secure360.org
Business continuity, Security, & crisis Management—Strat- egies to Limit Risk, control Damage, Sustain operations and effect Recovery, New York City, May 22-23. Contact: Conference Board, 212-339-03�5; Web: www.confer- ence-board.org
cpM 2007 West, Las Vegas, May 22-2�. Contact: CPM group, 609-39�-5500; Web: www.contingencyplanning. com/events/west
12 www.ioma.com/SECURE MAY 200�
SECURITY DIRECTOŔ S REPORT
each for validity, and disabling those without a justified business need. Other insiders configured a logic bomb (malicious code) to go off when they got fired, knowing that their employer didn’t have configuration management procedures to detect it. Finally, other technical insiders used passwords for shared accounts to get in because there was no formal tracking mechanism for ac- cess to those accounts and therefore, they were overlooked when the worker got fired. In short, it’s critical that companies don’t perceive removing access as a procedure to take after a worker is fired; rather, as an ongoing process. It needs to train workers to perform proactive, ongoing, rigorous access-management practices that make removing access when a worker is fired possible.
The MERIT project focuses on preventing insider sabotage of IT systems with adminis- trative and technical controls. The reason? In its study of actual cases, a problem with (or a lack of) physical controls typically wasn’t an issue. For a closer look at administra- tive and technical controls to mitigate the insider threat—and their limitations—see the accompanying sidebar. For more on the MERIT project and other valuable informa- tion, visit CERT’s insider threat Web page (www.cert.org/insider_threat). o
Coming in future issues of SDR:
Protecting the Firm’s Brand CONTINUED FROM PAgE 1
naturally from every day security activities. A security department must also take the steps below to give the company what it needs most.
What good is a security department any- way? For most big companies, the direct financial loss from security incidents is but a blip on the balance sheet. So it is worth reiterating a point we’ve made before: Surveys show that protecting the company brand is the number one reason that CEOs care about preventing security incidents. (see “What good Is Security? Here’s the View from the Top” in the May 2005 issue of SDR). Unfortunately, security gets only average marks from corporate executives on this score. Fewer than half think their security department is helping enhance the company’s brand value.
If you’re worried your department is be- hind the curve on this issue, you might take comfort in the fact that your whole company probably is too. As critical as brand protec- tion has become, many major corporations have yet to formulate a comprehensive plan for integrating reputation management into its risk management framework. So what are the issues? What should you be looking at? Here is a primer on how security and brand reputation intersect:
Why is brand equity now so impor- tant? It’s simple: A company’s brand and reputation—as a percentage of its market value—has grown and continues to grow. And, unlike other threats, risks to the com- pany brand and reputation are not some- thing it can insure against. Brand equity is also important because it’s fragile. It may only take a few days to wipe out favorable impressions that a company took years to cultivate, even if it doesn’t deserve the hit, notes a study by Perpetuity Research
l Are You Picking the System That Is Best for You? CCTV Procurement Step-by-Step
l Security Equipment—Are You Better Off Just Leasing?
l Security Executives Vote On Emerging Technologies: Which Are Must Have, Wait and See, and Overrated?
l What You Can Learn From the great HSPD-12 Experiment
l Now You Have a Plan—But Can Technology Take Your Emergency Program to the Next Level?
l How One Company Automated Physical Security SOX Compliance—Affordably