Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts

Tuesday, September 10, 2013

Keeping the Bad Guys Out

This blog post has been written for the WIRED Innovation Insights blog where it was published on September 9, 2013. You can find the original post here.

Just as we thought the WikiLeaks problem had faded away, we got a little reminder recently through the Bradley Manning sentencing. As much as this issue is very polarizing and the public’s perception of Manning ranges from high treason to martyrdom, the fact remains that our information is not secure today.
What? The multi-billion dollar industry that produces all the security products has failed us? All those sophisticated encryption algorithms don’t protect our data? What about the firewalls, multi-factor authentication, VPN, and SSL that we have been deploying?
Sure, all those technologies are very powerful and they indeed do address some of the major information issues. Authentication ensures that the person accessing the information really is who he or she claims to be. Firewalls keep out everyone without authorization. Encryption tools such as VPN, SSL, or PGP prevent snooping on the data as it travels from system to system. All of this is great, but it has a major flaw!
The problem with most of our information security to date is that it has been designed to keep the bad actors out. When you keep the bad guys out, your information is safe. Right? Well, not exactly. As the WikiLeaks, and more recently, the Edward Snowden examples show, the critical information leaks can happen by the hand of the authorized personnel. The leaks occur by the people who have legitimate access to the information and who are not considered a security threat to the information that all these security measures are designed to protect.
This issue must be quite unsettling to any strategic CIO. They may not be telling their boss, but their data is only as secure as their employees can be trusted. On top of that, it’s not just the malicious information leaks that are a concern. Most information leaks happen through negligence, without any malicious intent. Have you ever sent an email accidentally to the wrong person? If you have (and let’s be honest, who hasn’t?), you were just lucky that the attachment didn’t contain any state secrets.
Such “authorized information leaks” become even more of an issue in the era of mobile devices and cloud based file sharing and synchronization. There is a plethora of services, such as Dropbox, Microsoft SkyDrive, and Google Drive, that make it very easy for people to share information across their accounts and devices -- corporate and privately owned. When the employees leave, they take those accounts with them -- together with all the confidential information. There may not be any malicious intend behind this but it is a worrisome information leak nevertheless.
So what can we do? Sure, we can intensify the background checks on our new hires, train employees, and test their loyalty through psychological tests but these methods are hardly practical outside the high security agencies. We can also employ some of the new breed of security solutions such as SIEM (security information and events management), which monitors the data traffic patterns and looks for anomalies to detect security breaches (albeit usually after the fact).
But we should also never underestimate the need to establish solid information governance across the organization -- a way to properly organize the information, to determine where the information should be stored and who has access to it. Information leaks are a much more frequent occurrence in a messy environment where nobody really knows what information they actually possess and where it lives.
Lastly, we should expect information security vendors to start focusing their innovation on areas beyond traditional perimeter security. Complete information security may not be a solved problem today, but let’s hope it won’t stay like that forever.

Monday, July 1, 2013

My Thoughts On PRISM

Front page of The Guardian on June 10
The British newspaper The Guardian published for the first time on June 7, 2013 information about a large-scale data surveillance program called PRISM. Based on the information obtained from the former CIA employee Edward Snowden, the US government has been collecting vast volumes of personal data from cloud based services provided by US companies that represent the who-is-who of the high-tech world: Google, Apple, Facebook, Microsoft, etc. Based on the recent news updates, it looks like other governments have been doing the same.

This is very worrisome.

I am not surprised that the government is collecting all this data. It is too easy and too tempting. With the USA PATRIOT Act of 2001, it is probably even legal - at least based on the intelligence agencies’ interpretation of the law. Comparisons of how the government respects our paper mail while snooping our email are complete nonsense. The government respects the paper mail because it has no ability to snoop it. US Mail is a highly distributed system that handles data that is hard to duplicate - paper letters. Intercepting them all is practically impossible and copying them is difficult. Even if they did, they would end up with warehouses full of paper that would be highly impractical to search through.

Compared to that, collecting our electronic data is rather easy. The data is highly centralized and accessible through a few central choke points called Google, Facebook, etc. It is very easy to copy, and when stored, it is relatively easy to search through - just search for your name on Google and you get the idea of what the government has to do. Sure, storage and organization of all that data represents a challenge - a real “Big Data” challenge - but nothing that can’t be solved today.

As for privacy, let’s not kid ourselves. The government, the intelligence agencies, and the law enforcement don’t have much regard for our privacy. Have you flown on a plane in the last decade? They make you take off your shoes, your sweater, and your belt. They capture a picture of your naked body. They look through your luggage and make you bare your toiletries. They have an extensive data profile on you with all the info from your passport and often also your fingerprints and retina scan. They keep a record of all your flights and border crossings. If they like, they give you a thorough pat down. What makes you think that they would hesitate to search through your email - your data that you are not even keeping on your own premises?

Now, let’s consider the other side of this coin. So, the government has a copy of all our emails, Facebook posts, tweets, and then some. That’s billions and billions of data records. There is no way that human eyes could possibly review all these records. In fact, when a human review is  needed, it can become pretty daunting - I wrote about this type of big challenge in my article The Only Hope for Privacy? The point is that only computer algorithms are looking at your personal data and they will only raise a flag if your data pattern suggests a behavior of interest - terrorist related activities, tax evasion, drug trafficking, etc. You could argue that if you are engaged in any such activity, the feds should be looking at your data. Right?

Well, no. This is exactly the type of an orwellian surveillance state that knows too much about its citizens and it doesn’t take long to start flagging any behavior the state deems adverse. It takes a frighteningly small step from snooping your data to killing your freedom of speech. That leads to the state telling citizens what to do and how to behave which is called dictatorship. That’s not what the US Constitution is about. That’s not what freedom, liberty, and justice are about. This is not the ideal upon which the United States have been founded. We must not allow this to happen. That’s what Edward Snowden was thinking when he decided to blow the whistle.

Now let’s be clear, there are some concerning questions about Edward Snowden that should be answered. I don’t blame him that he went public with classified information. While that is against the rules (against the law), he obviously didn’t have the option of blowing the whistle the proper way - by informing to his supervisor, HR department or Chief Legal Counsel. Those are the guys behind the mass surveillance. But he did have the option to disclose the information anonymously and I wonder why he didn’t. I also wonder why he ended up hiding in China and Russia which are officially friendly nations but, honestly, I’d feel better if he was hiding in the United Arab Emirates or Indonesia which are also non-extradition countries. Going public in his own name and doing it in China rings a little alarm bell for me. But still, Edward Snowden appears to have done the honorable thing, albeit illegal.

So, where do we go from here? Well, this is a tough one. Our technology has created a monster by making all of our data readily available to snooping. We have also created a climate of public paranoia that places security above privacy. At least perceived security as there is no real evidence that all those security measures such as airport security controls or cameras on city streets yielded any tangible security increase for the citizens. The number of terrorists that the TSA caught in the last 10+ years is exactly zero while the annual TSA budget is $8 billion (source: BusinessWeek). Both of these things are a genie that won’t easily go back into the bottle.

In the end, I hope that we will educate ourselves enough to better understand how to handle our information to keep at least some of it private. Maybe, not all the data should end up in the Cloud after all! I also hope that the security vs privacy pendulum swings back and finds some point of equilibrium that will make our lives more pleasurable. The excessive security that has become part of our daily lives is the kind of asymmetric response that I wrote about two years ago. Because every time I get a thorough pat down at the airport, I can’t help thinking that the bad guys might have won when they set out to make our lives miserable.

Monday, March 25, 2013

The Maslow's Hierarchy of a Strategic CIO

Not that long ago, IT departments were responsible mainly for making sure that knowledge workers got access to whatever information was available and for keeping the lights on. That latter responsibility was all consuming. PCs and enterprise systems were still going through their growing pains and varieties of system failures were all too common. The job of the chief information officer (CIO) was more about troubleshooting and firefighting than anything else. Information Technology (IT) was simply a cost center - just like travel or communication.

Well, things have changed. The systems we work with are, for the most part, reasonably reliable. We don't have to reboot our PCs twice a day just to flush out the memory leaks. 99.999% uptime is not that big of a differentiator for servers, routers, and switches anymore. Users don't call the help desk daily and access to information is not the challenge at hand. Today, we have information. We have a lot of information. In fact, we have way more information than we could ever consume.

Herein comes the change in the mission of IT departments. As organizations came to realize that information emerged as a key source of competitive advantage, they were increasingly looking at their IT departments as a key stakeholder in corporate strategy. All of the sudden, the CIOs got what they were always dreaming about. No longer the troubleshooter, no more the firefighter - the CIO is now the strategist.

What organizations need is the ability to make better decisions - using the right information. They need insight. They also need to apply information to create an impact on their business - to grow revenue, attract new customers, enter new markets, and generate innovation. And finally, they also need to drive productivity and continuously optimize their business processes.

Not to forget, enterprise information must also be secured. As it represents significant intellectual property, it has to be protected from intentional or unintentional misappropriation by internal or external actors. And let us not forget the need to address compliance and information governance requirements and to protect the company from legal exposure.

All these requirements reminded me of the Maslow's Hierarchy of Needs and so I have attempted to map the CIO needs into a similar model:

With all of this, the strategic CIOs have their hands full. They still need to keep the lights on but now, they are major stakeholders in defining corporate strategy. Combine that with all the new technology trends such as mobile devices, social software, and cloud computing and you get the picture of the magnitude of their challenge. But I guess that being strategic is way better than fighting fires all day long, right?