Showing posts with label security policy. Show all posts
Showing posts with label security policy. Show all posts

Wednesday, April 22, 2015

RSA2015 Partner Spotlight: FireEye Partnership

FireEye Director of Strategic Partners, Sam Ware, talks about the new technical partnership between F5 and FireEye. FireEye aims to provide automated threat forensics and dynamic malware protection against advanced cyber threats, such as advanced persistent threats and spear phishing. Sam shares how FireEye can detect zero day anomalies and pass that information to BIG-IP to enforce a policy. Sam gives a few examples of the types of attacks that are detected and the resulting action that’s enforced.


ps
Related
Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Monday, August 25, 2014

VMworld 2014 – Security Considerations for the SDDC (feat Frelich)

Brandon Frelich, our Marketing Services Architect for Cloud & Security, talks about some of the implications and considerations for organizations looking to move toward a Software Defined Data Center. Areas include DDoS protection, identity & access management and policy control. Delivering the Software Defined Data Center (pdf)

 

ps

Related

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, October 8, 2013

The Hacker Will See You Now

More than 1.8 million medical ID theft victims in 2013

That's a 19% increase over last year according to the 2013 Survey on Medical Identity Theft.  More than 300,000 new medical identity theft cases were reported during the one-year period, the study found.  The 4th annual survey, conducted by the Ponemon Institute, defined medical identity theft as a person using an individual's name or personal identity “to fraudulently receive medical service, prescription drugs and goods, including attempts to commit fraudulent billing.”

One of the biggest contributors to the increase was fake or spoofed medical websites and spam emails.  Medical identity theft victims who reported that a cyber schemes caused their troubles doubled from 4% in 2012 to 8% in 2013.  It is clear that the amount and frequency of spear phishing specifically targeting medical ID theft has gone up.  This is not the simple 'Buy this personal enhancement drug here' emails but authentic looking emails from a provider.  You click the malicious link and either malware is installed to your computer or you are directed to a website that looks exactly like your medical provider's and you enter (give away) your credentials there.  You might even be able to log into something that will request you update your personal information.  Perfect, I get your credentials along with some additional Rx information or mailing address or SSN or date of birth anything that I can use to impersonate you.

As far as data breaches as a cause, only 7% (up 1 tick from last year) felt a data breach by their insurer, health care provider or related was linked to the fraud.

A separate but related survey, a new Deloitte report says healthcare organizations are in various stages of mitigating the security risks of medical devices.  These include patient monitors, infusion pumps, ventilators, pacemakers and imaging devices.  Deloitte interviewed the medical device security leaders at nine large hospital systems and they indicated that their organizations have a long way to go and that they need more cooperation from device manufacturers. 

The Food and Drug Administration (FDA) recently released a guidance on the "content of premarket submissions for management of cyber security in medical devices."  The guidance suggested that device makers incorporate security features into their products to limit access to only trusted users, trusted content, and use fail-safe and recovery devices. They want manufacturers to consider threats like hacking, malware and other vulnerabilities of the device's software and to work with providers on addressable scenarios.  This is certainly an area of importance for both providers and the device manufactures.  Remember all the wrangling with PCI and those payment devices?  Granted, the FDA guidance is a recommendation and not a regulation like PCI so there is reluctance to include security measures in purchasing contracts.

The other issue healthcare organizations face is trying to secure older proprietary devices.  These closed systems make it almost impossible to scan for vulnerabilities but they are still in widespread use.  For other devices that run on well know commercial operating systems, they are vulnerable to the same threats that any device with that software has.

Deloitte also asked the medical device security heads where their organizations stood in several areas of cyber security.  These included: organizational leadership, risk framework, identification and evaluation, data flow, vulnerability management, vendor agreements and manufacturer engagement.   Ken Terry over at Information Week goes into detail of each.

So far there have been no documented instances of "intentional threats" to medical devices, according to the report but healthcare providers are not required to report security incidents to the FDA or the device manufacturer unless a death or serious injury has occurred.

ps

 

Related:

 

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, July 23, 2013

Big Data Getting Attention

According to IBM, we generate 2.5 quintillion (2.5 followed by 17 zeros) bytes of data every day.  In the last two years, we've created about 90% of the data we have today.  Almost everything that's 'connected' generates data.  Our mobile devices, social media interactions, online purchases, GPS navigators, digital media, climate sensors and even this blog to name a few, adds to the pile of big data that needs to be processed, analyzed, managed and stored.  And you think that saving all your movies, music and games is a challenge.

This data growth conundrum is 3 (or 4 - depending on who you talk to) dimensional with Volume (always increasing amount of data), Velocity (the speed back and forth) and Variety (all the different types - structured & unstructured).  Veracity (trust and accuracy) is also included in some circles.  With all this data churning, security and privacy only add to the concerns but traditional tactics might not be adequate.

Recently the Cloud Security Alliance (CSA) listed the top 10 security and privacy challenges big data poses to enterprises and what organizations can do about them.  After interviewing CSA members and security-practitioners to draft an initial list of high priority security and privacy problems, studying the published solutions and characterizing problems as challenges if the proposed solution(s) did not cover the problem scenarios, they arrived at the Top 10 Security & Privacy Challenges for Big Data.

They are:

  1. Secure computations in distributed programming frameworks
  2. Security best practices for non-relational data stores
  3. Secure data storage and transactions logs
  4. End-point input validation/filtering
  5. Real-Time Security Monitoring
  6. Scalable and composable privacy-preserving data mining and analytics
  7. Cryptographically enforced data centric security
  8. Granular access control
  9. Granular audits
  10. Data Provenance

The Expanded Top 10 Big Data challenges has evolved from the initial list of challenges to an expanded version that addresses new distinct issues.

  1. Modeling: formalizing a threat model that covers most of the cyber-attack or data-leakage scenarios
  2. Analysis: finding tractable solutions based on the threat model
  3. Implementation: implanting the solution in existing infrastructures

The idea of highlighting these challenges is to bring renewed focus on fortifying big data infrastructures.  The entire CSA Top 10 Big Data Security Challenges report can be downloaded here.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, May 21, 2013

50/50 Odds for BYOD

According to a ComputerWorld article citing a recent Gartner survey, about half the world's companies will stop providing computing devices to employees and embrace some form of BYOD by 2017.  They also noted that about 40% will offer a choice between employee owned or company issued while 15% say they will never support BYOD.  While most surveyed felt there were benefits to BYOD, only about a quarter (22%) felt they have made a strong business case for it.  This might have to do with the fact that many organizations are still in the exploratory process for BYOD and are looking for a mobile strategy.  In addition, many are still trying to figure out a reimbursement plan.  Employees often expense business travel and mileage, and personal smartphone use for work also falls into that category.  About half the companies provide some reimbursement with only 2% covering all costs associated with BYOD.  While removing the initial capital outlay for IT issued devices, there are still costs like security and management tools along with the support headcount for BYOD. 

In another survey, Lumension’s BYOD and Mobility Security Report conducted on LinkedIn, BYOD is widely supported in 20% of organizations with another 35% saying they are evaluating it and 40% still supporting company owned mobile devices.  70% said 'security' was a big concern and a top criteria for success.  They worry about loss of and unauthorized access to corporate data.  Almost in line with the Gartner results and interestingly, sounds a lot like the attitudes over cloud computing the past several years. 

Employee satisfaction and productivity were cited in both surveys as a direct benefit of BYOD and although not perfect, encryption, is the most used risk control measure.  Productivity tools like email, calendar and contact management are the most used by employees and some sort of centralized mobile management is the most used by IT.  Anywhere from a quarter to a third of respondents have no BYOD policy nor any tools to mange and govern mobile access.

Without digging deeply into the numbers, these BYOD feelings sound similar to the cloud adoption trends over the last few years.  It's happening and organizations see benefits but there is hesitancy over things like security and data protection.  Once the risk is assessed and policies are in place, organizations can manage and mitigate the potential damage of allowing personal mobile devices on the sensitive corporate network.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, March 5, 2013

Pulse2013 – BIG-IP ASM & IBM InfoSphere Guardium

I meet with F5 Solution Architect Nojan Moshiri to learn about the integration between BIG-IP ASM and IBM’s InfoSphere Guardium offering real time data security along with contextual meta data associated with the SQL data. Each enhances the other to provide both defense-in-depth protection and contextual security information. Powerful stuff.

 

ps

Related:

Technorati Tags: f5,ibm,pulse,ibmpulse,psilva,video,security, database,Guardium, sql,

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, January 8, 2013

Lost Records a Day Shows Doctors are Blasé

#HealthCare #Privacy Challenges

patient privacy usatoday I always wanted to write, 'In the USA Today, today' in the Life section snapshots sidebar there is an interesting stat from a December 2012 Ponemon Institute study of 80 health care organizations showing that the data lost or stolen most often are our medical records at 48% and billing/insurance records at 48% followed by payment details at 24%.  Multiple responses were allowed which is why the percentages break 100.  What is more alarming is that over the last two years, 94% of health care organizations have been breached at least once and 45% have had 5 or more incidents!  What is sad is that over half (54%) have little or no confidence that they can detect patient data loss.

I know many of us often delay or avoid the doctors for fear that we might get diagnosed with something terrible but maybe now we'll avoid with the notion, 'eh, I'm healthy and I don't want to be afflicted with identity theft disease.'  Ask your doctor about ITD - common side effects include increased heart rate, depression, headaches, loss of appetite and in some patients, bank account drainage.  Why risk it?  Heck, the last time my wife went to her now previous doctor and asker her about how she complies with HIPAA, the doctor didn't even know what that was!  How can that be?  How can a practicing physician be unaware of HIPAA?  That's like a bank unaware of PCI or the numerous other financial regulatory requirements.  But is it 'unaware' or 'just don't care.'

The primary causes of health care data breach include lost or stolen devices along with employee or 3rd party mistakes and they only learned of the breach because of an audit.  Data gets moved around amongst various parties for multiple reasons it is often hard to determine who and where leaked it.

Suggestions include appointing senior security roles reporting to the board, securing mobile devices, using encryption, develop breach plans that are ready and tested, education and as more health care organizations turn to the cloud, understand and control that risk - whatever it may be.

Oh, and have a seat, we'll be with you in a moment.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]