Showing posts with label compliance. Show all posts
Showing posts with label compliance. Show all posts

Tuesday, May 28, 2013

FedRAMP Federates Further

FedRAMP (Federal Risk and Authorization Management Program), the government’s cloud security assessment plan, announced late last week that Amazon Web Services (AWS) is the first agency-approved cloud service provider.  The accreditation covers all AWS data centers in the United States.  Amazon becomes the third vendor to meet the security requirements detailed by FedRAMP.  FedRAMP is the result of the US Government’s work to address security concerns related to the growing practice of cloud computing and establishes a standardized approach to security assessment, authorizations and continuous monitoring for cloud services and products.  By creating industry-wide security standards and focusing more on risk management, as opposed to strict compliance with reporting metrics, officials expect to improve data security as well as simplify the processes agencies use to purchase cloud services.  FedRAMP is looking toward full operational capability later this year.

As both the cloud and the government’s use of cloud services grow, officials found that there were many inconsistencies to requirements and approaches as each agency began to adopt the cloud.  Launched in 2012, FedRAMP’s goal is to bring consistency to the process but also give cloud vendors a standard way of providing services to the government.  And with the government’s cloud-first policy, which requires agencies to consider moving applications to the cloud as a first option for new IT projects, this should streamline the process of deploying to the cloud.  This is an ‘approve once, and use many’ approach, reducing the cost and time required to conduct redundant, individual agency security assessment.  AWS's certification is for 3 years.

FedRAMP provides an overall checklist for handling risks associated with Web services that would have a limited, or serious impact on government operations if disrupted.  Cloud providers must implement these security controls to be authorized to provide cloud services to federal agencies.  The government will forbid federal agencies from using a cloud service provider unless the vendor can prove that a FedRAMP-accredited third-party organization has verified and validated the security controls.  Once approved, the cloud vendor would not need to be ‘re-evaluated’ by every government entity that might be interested in their solution.  There may be instances where additional controls are added by agencies to address specific needs.

The BIG-IP Virtual Edition for AWS includes options for traffic management, global server load balancing, application firewall, web application acceleration, and other advanced application delivery functions.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, May 21, 2013

50/50 Odds for BYOD

According to a ComputerWorld article citing a recent Gartner survey, about half the world's companies will stop providing computing devices to employees and embrace some form of BYOD by 2017.  They also noted that about 40% will offer a choice between employee owned or company issued while 15% say they will never support BYOD.  While most surveyed felt there were benefits to BYOD, only about a quarter (22%) felt they have made a strong business case for it.  This might have to do with the fact that many organizations are still in the exploratory process for BYOD and are looking for a mobile strategy.  In addition, many are still trying to figure out a reimbursement plan.  Employees often expense business travel and mileage, and personal smartphone use for work also falls into that category.  About half the companies provide some reimbursement with only 2% covering all costs associated with BYOD.  While removing the initial capital outlay for IT issued devices, there are still costs like security and management tools along with the support headcount for BYOD. 

In another survey, Lumension’s BYOD and Mobility Security Report conducted on LinkedIn, BYOD is widely supported in 20% of organizations with another 35% saying they are evaluating it and 40% still supporting company owned mobile devices.  70% said 'security' was a big concern and a top criteria for success.  They worry about loss of and unauthorized access to corporate data.  Almost in line with the Gartner results and interestingly, sounds a lot like the attitudes over cloud computing the past several years. 

Employee satisfaction and productivity were cited in both surveys as a direct benefit of BYOD and although not perfect, encryption, is the most used risk control measure.  Productivity tools like email, calendar and contact management are the most used by employees and some sort of centralized mobile management is the most used by IT.  Anywhere from a quarter to a third of respondents have no BYOD policy nor any tools to mange and govern mobile access.

Without digging deeply into the numbers, these BYOD feelings sound similar to the cloud adoption trends over the last few years.  It's happening and organizations see benefits but there is hesitancy over things like security and data protection.  Once the risk is assessed and policies are in place, organizations can manage and mitigate the potential damage of allowing personal mobile devices on the sensitive corporate network.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, February 5, 2013

Is BYO Already D?

As in Done, Dead, Doomed...Defeated. 

About a year ago I wrote BYOD–The Hottest Trend or Just the Hottest Term just when #BYOD was burning up the #trendingtopics.  Since then, BYOD has become one of the most talked about IT challenges and at the top of many enterprise initiates for 2013.  Most industry pundits and analysts alike believe BYOD is here to stay and will have a major impact both on business and how we use our personal mobile devices.  Now, as more organizations investigate and deploy BYOD solutions, some unforeseen costs are starting to toss BYOD for a loop.

A number of recent surveys, research and analysis indicate that the perceived cost savings might be a mirage.  The Aberdeen Group says BYOD could cost organizations 33% more than a IT owned mobile device plan.  iPass' Q4 Mobile Workforce Report, suggests organizations are not considering long term costs of BYOD and Damovo UK's survey of 100 IT Directors, 73% feel that BYOD costs will 'spiral out of control,' with 69% skeptical that the BYOD shift will actually reduce support costs.  And Xigo, a provider of cloud-based expense management, reported that while cost savings is a top goal for BYOD programs, most respondents (67%) said their mobile expenditures had not changed with 25% saying their costs rose. Finally, in a survey by Lieberman Software, most respondents (67%) said BYOD would increase IT and security costs.

Why all the gloom?  Many of the cautions involved the basics: airtime, data plans, volume discounts, network capacity, support (staff & software) and ongoing compliance.

Obviously, if a mobile device has now added 'work productivity tool' to it's list of duties, it might need to move into a higher monthly service plan, which might be expensed back to the company (along with the cost to process that report).  The device itself was probably acquired at retail or discounted with a term contract verses part of some corporate volume discount.

Another area is pure bandwidth.  In essence, everyone gets to add another node to the network.  A powerful device at that.  Network usage, WiFi connections, access rules, overall access management and the rest, most likely will go up.

Support - in all areas - is yet another conundrum.  The devices and unique configuration of each; the software required to secure, manage and often license the device; AAA management; IT bodies focused on BYOD; policy & risk management; overall complexity; loss of data; enter your own challenge here _________.

As with all technology trends, there will be hiccups along the way.  Remember that thing called The Cloud?  We are in the BYOD 1.0 realm and need to move into the BYOD 2.0 era -  a shift from managing the entire device to only managing the corporate data and applications on the device.  My guess is that BYOD will go thru some growing pains but will eventually settle in as just another way we use our devices and access data.  While 'cost' might be the initial bait, over time the benefits will look more like productivity and flexibility rather than TCO/ROI.

What do you think?  BYO Done or Dawning?

ps

Related

 

Connect with Peter: Connect with F5:
o_linkedin[1]  o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, August 15, 2012

Parking Ticket Privacy

Imagine getting a $20 parking ticket and then filing suit against the issuing municipality for exposing too much personal information on that ticket.  That’s exactly what Jason Senne did after receiving a $20 parking ticket in 2010 for illegally parking his car overnight in the Chicago ‘burb of Palatine, Ill.  His name, address, driver's license number, date of birth, height and weight all appeared on the ticket, which was placed on his windshield in full public view.  Senne's complaint alleged that disclosure of his identity was in violation of the Driver’s Privacy Protection Act of 1994 (DPPA).  DPPA requires that all states protect a driver's name, address, phone number, Social Security number, driver identification number, photograph, height, weight, gender, age, and specific medical or disability information.  Congress passed the privacy legislation in response to the death of actress Rebecca Schaeffer.  She was killed by a stalker who had gotten her unlisted home address through the California DMV.  In Senne’s case, initially a federal judge found that an exception for law enforcement protected the village's actions, and a 3-judge panel of the 7th Circuit affirmed that last year.  Senne pushed and the full federal appeals court agreed to rehear the case.  Last week, the full federal appeals court decided Monday that ‘the parking ticket at issue here did constitute a disclosure regulated by the DPPA.’

In a 7-4 ruling, the appeals court said that it didn’t matter if someone walking by happened to notice the personal info – just the fact that it was exposed in such a public manner was enough.  The earlier district court decision, in favor of Palatine Village, was based on the notion that a ‘disclosure’ was when an entity turned over information to someone else without consent and was not considered disclosure.  In this case, there was no direct handoff, just the ticket flapping on the windshield/wiper blade in plain sight.  In the overturned ruling, the divided court  felt that there was real risk, safety and security concerns at stake.  A stalker looking for a target could just hang out where overnight parking is banned and collect a bunch of potential victim’s info for future harassment.  The recent court’s interpretation of the law might also expose Palatine to a hefty $80 million fine.  Since there is a 4 year statute of limitations on private lawsuits and each privacy violation carries a $2500 penalty, all those tickets issued during that time frame with the protected info could be in play.

It’s an interesting case about privacy and how others, without malicious intent, may expose personal, sensitive details about an individual.  While identity theft due to electronic means, like data breaches, is on the rise, stolen wallets or physical documents (dumpster diving) still account for a good percentage of ID theft crimes.  Back in 2009, a Javelin study indicated that stolen wallets and physical documents accounts for 43% of all identity theft (pdf) which means we still need to shred our printed materials. 

ps

References:

Technorati Tags: F5, smartphone, integration, byod, Pete Silva, security, business, education, technology, application delivery,ipad,mobile device, context-aware,android, iPhone, web, internet, security

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, June 5, 2012

FedRAMP Ramps Up

Tomorrow June 6th, the Federal Risk and Authorization Management Program, the government’s cloud security assessment plan known as FedRAMP will begin accepting security certification applications from companies that provide software services and data storage through the cloud.  On Monday, GSA issued a solicitation for cloud providers, both commercial and government, to apply for FedRAMP certification.  FedRAMP is the result of government’s work address security concerns related to the growing practice of cloud computing and  establishes a standardized approach to security assessment, authorizations and continuous monitoring for cloud services and products.  By creating industry-wide security standards and focusing more on risk management, as opposed to strict compliance with reporting metrics, officials expect to improve data security as well as simplify the processes agencies use to purchase cloud services, according to Katie Lewin, director of the federal cloud computing program at the General Services Administration.

As both the cloud and the government’s use of cloud services grew, officials found that there were many inconsistencies to requirements and approaches as each agency began to adopt the cloud.  FedRAMP’s goal is to bring consistency to the process but also give cloud vendors a standard way of providing services to the government.  And with the government’s cloud-first policy, which requires agencies to consider moving applications to the cloud as a first option for new IT projects, this should streamline the process of deploying to the cloud.  This is an ‘approve once, and use many’ approach, reducing the cost and time required to conduct redundant, individual agency security assessment.

Recently, the GSA released a list of nine accredited third-party assessment organizations—or 3PAOs—that will do the initial assessments and test the controls of providers per FedRAMP requirements. The 3PAOs will have an ongoing part in ensuring providers meet requirements.

FedRAMP provides an overall checklist for handling risks associated with Web services that would have a limited, or serious impact on government operations if disrupted.  Cloud providers must implement these security controls to be authorized to provide cloud services to federal agencies.  The government will forbid federal agencies from using a cloud service provider unless the vendor can prove that a FedRAMP-accredited third-party organization has verified and validated the security controls.  Once approved, the cloud vendor would not need to be ‘re-evaluated’ by every government entity that might be interested in their solution.  There may be instances where additional controls are added by agencies to address specific needs.

Independent, third-party auditors are tasked with testing each product/solution for compliance which is intended to save agencies from doing their own risk management assessment.  Details of the auditing process are expected early next month but includes a System Security Plan that clarifies how the requirements of each security control will be met within a cloud computing environment. Within the plan, each control must detail the solutions being deployed such as devices, documents and processes; the responsibilities of providers and government customer to implement the plan; the timing of implementation; and how solution satisfies controls. A Security Assessment Plan details how each control implementation will be assessed and tested to ensure it meets the requirements and the Security Assessment Report explains the issues, findings, and recommendations from the security control assessments detailed in the security assessment plan.  Ultimately, each provider must establish means of preventing unauthorized users from hacking the cloud service.

The regulations allow the contractor to determine which elements of the cloud must be backed up and how frequently. Three backups are required, one available online.  All government information stored on a provider's servers must be encrypted.  When the data is in transit, providers must use a "hardened or alarmed carrier protective distribution system," which detects intrusions, if not using encryption.  Since cloud services may span many geographic areas with various people in the mix, providers must develop measures to guard their operations against supply chain threats.  Also, vendors must disclose all the services they outsource and obtain the board's approval to contract out services in the future.

After receiving the initial applications, FedRAMP program officials will develop a queue order in which to review authorization packages.  Officials will prioritize secure Infrastructure as a Service (IaaS) solutions, contract vehicles for commodity services, and shared services that align with the administration’s Cloud First policy. 

F5 has an iApp template for NIST Special Publication 800-53 which aims to make compliance with NIST Special Publication 800-53 easier for administrators of BIG-IPs.  It does this by presenting a simplified list of configuration elements together in one place that are related to the security controls defined by the standard. This makes it easier for an administrator to configure a BIG-IP in a manner that complies with the organization's policies and procedures as defined by the standard.  This iApp does not take any actions to make applications being serviced through a BIG-IP compliant with NIST Special Publication 800-53 but focuses on the configuration of the management capabilities of BIG-IP and not on the traffic passing through it.

ps

Resources:

Technorati Tags: F5, federal government, integration, cloud computing, Pete Silva, security, business, fedramp, technology, nist, cloud, compliance, regulations, web,internet

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, May 9, 2012

Interop 2012 - Interview with Brian Monkman of ICSA Labs

I interview Brian Monkman, ICSA Labs' Technology Programs Manager, about ICSA certification, the importance of 3rd party tests, how ICSA conducts their certification testing along with Breaking News that the BIG-IP Family is now ICSA Certified for IPSec!!

Interop 2012 - Interview with Brian Monkman of ICSA Labs

ps

Related

Technorati Tags: F5, interop, Pete Silva, security, business, education, technology, internet, big-ip, ipsec, certification, icsa

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, April 25, 2012

Complying with PCI DSS–Part 6: Maintain an Information Security Policy

According to the PCI SSC, there are 12 PCI DSS requirements that satisfy a variety of security goals.  Areas of focus include building and maintaining a secure network, protecting stored cardholder data, maintaining a vulnerability management program, implementing strong access control measures, regularly monitoring and testing networks, and maintaining information security policies.  The essential framework of the PCI DSS encompasses assessment, remediation, and reporting.  We’re exploring how F5 can help organizations gain or maintain compliance and the last entry is Maintain an Information Security Policy which includes PCI Requirement 12To read Part 1, click: Complying with PCI DSS–Part 1: Build and Maintain a Secure Network, Part 2:Complying with PCI DSS–Part 2: Protect Cardholder Data, Part 3: Complying with PCI DSS–Part 3: Maintain a Vulnerability Management Program, Part 4: Complying with PCI DSS–Part 4: Implement Strong Access Control Measures and Part 5: Complying with PCI DSS–Part 5: Regularly Monitor and Test Networks.

Requirement 12: Maintain a policy that addresses information security for all personnel.

PCI DDS Quick Reference Guide description: A strong security policy sets the security tone for an entire organization’, and it informs employees of their expected duties related to security. All employees should be aware of the sensitivity of cardholder data and their responsibilities for protecting it.

Solution: The spirit of this requirement is to ensure the adoption of a Corporate Information Security Policy (CISP).  Although policy-based, F5 solutions don’t, by themselves, meet this requirement in context.  F5 products facilitate adherence to the CISP, but they do not actually comprise a CISP.  That said, F5 products can help organizations roll out business policies and security policies together.  Applications needn’t be built and deployed in a vacuum; F5 technologies can be implemented in conjunction with corporate policies that address information security.

 

Since the inception of the PCI DSS, organizations have been laboring to understand, implement, and comply with its guidelines.  Often, achieving that goal requires deploying and managing several different types of devices.  The BIG-IP platform enables organizations to understand inherent threats and take specific measures to protect their web application infrastructures and to satisfy many PCI DSS requirements.

ps

Related:

Technorati Tags: F5, PCI DSS, virtualization, cloud computing, Pete Silva, security, cloud, credit card, compliance, web, internet,cybercrime, holiday shopping, identity theft,

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]