Κυριακή 20 Σεπτεμβρίου 2015

From Information Security to Digital Competitiveness


Information is the lifeblood of almost all businesses today. At the same time, not a week goes by without news of another big hack or security breach. The pressure on the security function is immense, and security professionals need a fine balance of skills to bring together risk, compliance, operations and technology in any large organization. Sadly, they rarely find time to grow their relationships and standing in the corporation. 

The role of CISO is difficult yet crucial. Not all organizations appoint an executive CISO; many have a security director report into the CIO or else into risk and compliance functions. A dedicated CISO role is crucial, both politically and culturally, for it sends a strong message about the priorities and commitments of the business.

The role of CISO is relatively new and by no means is it a universal position. Managers attain the title CISO by following any number of career paths, typically starting in an IT environment, then acquiring specialist security certifications and/or on-the-job experience. Information security is managed in many different ways from one business to another. Some firms see it as a part of security generally; it is common among banks, for example, for the safekeeping of cash, branches, staff and IT to all come under the one executive. Other organizations have information security report into legal or risk functions, as they can see it as a corporate governance matter. And some prefer operations or IT to take responsibility for information security, especially if technology in the sector is volatile or complex. Regardless of reporting line, an effective CISO must have influence inside IT and inside the business units. 

Whether a CISO comes with technical qualifications or has learned on the job, the classical CISO job description covers a basket of activities spanning network security, access management (for customers, staff and/or partners), standards compliance (particularly in regulated industries like banking, government and healthcare), policy development and implementation, internal IT audit, and sometimes privacy. The CISO’s position generally involves a lot of tech and a lot of compliance. 

Organizations tend to utilize the security department in a purely defensive capacity. However, in the digital age, an organization’s internally and externally collected information are valuable data sources. Security Officers archive, protect, and maintain the quality of an organization’s information, putting them in a unique position to implement strategic, information-driven business initiatives.

The security department must evolve from “the department of no” to a business unit that utilizes a company’s information to create a strategic advantage and value to internal and external customers alike.

In a market characterized by rapidly changing technology and increasing global competitive forces, it's no secret that companies can no longer afford to rely on the feature-set of their products or services alone. After all, today's innovation is rapidly becoming tomorrow's industry standard, so organisations must ensure they create value from the information they have and forge intimate connections with their customers, colleagues, suppliers and partners in order to stay ahead of their competition. The need for joined-up thinking in business cannot therefore be underestimated. This is not just about improving the flow of information within a business; rather it needs to be about unlocking consistent value and meaning from that information and extending collaboration across an organisation's entire ecosystem in order to put the customer at the center of the business and achieve real customer intimacy.

As the global economy starts to show signs of recovery, businesses can afford to look beyond short term survival and start planning for the anticipated upturn. The long-term value that collaboration brings to an organisation more than outweighs its perceived cost - it will help forge stronger relationships and happier workers as well as translate into more efficient operations company-wide. Clear visibility of business-critical information, improved insight into business performance and customer value are the cornerstones of successful, profitable business in any sector. Making these changes today will not only improve competitiveness and provide the operational clarity required to maximize corporate performance, but will also prepare the organisation to exploit future economic growth.

Digital disruption is not a new phenomenon. But the opportunities and risks it presents shift over time. Competitive advantage flows to the businesses that see and act on those shifts first. We are entering the third, and most consequential, wave of digital disruption. It has profound implications not only for strategy but also for the structures of companies and industries. Business leaders need a new map to guide them.

In the first wave of the commercial Internet, the dot-com era, falling transaction costs altered the traditional trade-off between richness and reach: rich information could suddenly be communicated broadly and cheaply, forever changing how products are made and sold. Strategists had to make hard choices about which pieces of their businesses to protect and which to abandon, and they learned that they could repurpose some assets to attack previously unrelated businesses. Incumbent value chains could be “deconstructed” by competitors focused on narrow slivers of added value. Traditional notions of who competes against whom were upended—Microsoft gave away Encarta on CDs to promote sales of PCs and incidentally destroyed the business model of the venerable Encyclopædia Britannica.

In the second wave, Web 2.0, the important strategic insight was that economies of mass evaporated for many activities.1 Small became beautiful. It was the era of the "long tail" and of collaborative production on a massive scale. Minuscule enterprises and self-organizing communities of autonomous individuals surprised us by performing certain tasks better and more cheaply than large corporations. Hence Linux, hence Wikipedia. Because these communities could grow and collaborate without geographic constraint, major work was done at significantly lower cost and often zero price.

Smart strategists adopted and adapted to these new business architectures. IBM embraced Open Source to challenge Microsoft's position in server software; Apple and Google curated communities of app developers so that they could compete in mobile; SAP recruited thousands of app developers from among its users; Facebook transformed marketing by turning a billion “friends” into advertisers, merchandisers, and customers.

Now we are on the cusp of the third wave: hyper-scaling. Big — really big — is becoming beautiful. At the extreme — where competitive mass is beyond the reach of the individual business unit or company — hyper-scaling demands a bold, new architecture for businesses.

It is fashionable (and correct) to assert that business leaders need to worry about disruption. But disruption takes very specific forms, and these forms are shifting. The disruptive impact of deconstruction—like that of low-cost technologies—is now widely understood, but the challenge of the very small, less so. And the challenge of the very large, hardly at all. Put them together and you pass from the familiar world of value chains to the world of platforms, ecosystems, and stacks. The role of CISO is mission critical in a world of digital disruption.



Πέμπτη 9 Απριλίου 2015

Does IT Security Fail?


RSA, the security division of EMC, with the contribution of Northeastern University, recently published a report on the reasons why the IT security sector fails to effectively address the modern cyber attacks. The report highlights the challenges faced by the industry, while deepening the best practices that can build an organization in order to achieve everything that managed to achieve so far in safety. It also includes practical advice for professionals from the field of IT security, which can help to improve the strategy and tactics with which face modern threats.

The main messages of the report:

The attacks on the IT infrastructure of an organization and multiply them increases and the economic damage that accompanies them.

The economic impact of these attacks are important and tend to expand.

According to The Global State of Information Security® Survey Research 2015, the number of established attacks worldwide increased by 48%, to 42,8 million, which is equivalent to 117339 per day attacks. Since 2009, the incidents of attacks are growing at 66 % annually. The economic losses due to detected attacks worldwide raised to US$ 2,7 million, about 34% higher than in 2013.

The report notes that the lack of awareness of risk is one of the most vulnerable points in terms of IT security in the US.

Amounts invested in cyber-attacks prevention technologies (prevention-based security) is disproportionately high in relation to expenditure for procurement solutions that can detect and adequately address these attacks. Moreover, the situation aggravated by a "skills shortage". It is important to note that IT security should be based on adequate preparation. One needs a thorough understanding of business processes and entire operation of an organization, as well as the ability to collect and analyze all information related to the security of IT infrastructure. Those organizations do not have adequate staff or experience to deal with such situations should consider whether they need to strengthen the internal IT security team, buying specialized cloud-based services to more fully protect their infrastructures.

Recommendations for better preparation against threats

The focus should now be focused not on what attacks are detected or how successful the effort to prevent several aspiring invaders, but who managed to escape, you may not be protected adequately and what attacks might not have been known.

Preparation - The vigilance and sustained attention should be an inherent feature of any plan to protect the IT infrastructure of an organization. The access control systems can not by themselves effectively against modern attackers who launch attacks at high speed, drawing more and more new weapons to exploit any weakness of protective systems.
Setting priorities - Every IT system and all information has the same value as another. Each organization should define what is critical for a particular function (mission critical) and what about all of the activity (business-critical). What attack would prevent the business development of the company in the future and what will lead many years back or out of the market.
Customization - Those professionally engaged in IT security should first understand the nature of the changes that have occurred in terms of infrastructure - cloud, mobility, BYOD etc. - And then prepare methodically defensive plan and the corresponding tactics to neutralization of new and sophisticated threats.
Light everywhere - There should be no 'dark' points in the IT infrastructure, which could be hidden or where they could escape the invaders. The use of the tools offered by modern technology as well as the examination of the behavior of each user and each device connected to the network infrastructures help to better equip an organization.
Flexibility - A business can not operate under a system of strict policing. The officials should be given freedom and flexibility, there is - to some extent - respect for private activity and sense of confidence. Education and communication with staff should be continuous, so that users can understand and be ready to properly react to attacks that occur through social networks (social engineering).

Τετάρτη 25 Μαρτίου 2015

Setup an Information Security Awareness Program


Protecting corporate data should be part of any organization-wide information security awareness program. The security awareness program should be delivered in a way that fits the overall culture of the organization and has the most impact to personnel. Security awareness should be conducted as an on-going program to ensure that training and knowledge is not just delivered as an annual activity, rather it is used to maintain a high level of security awareness on a daily basis. Ensuring staff is aware of the importance of data security is important to the success of a security awareness program and will assist in meeting various standards’ requirements.

The first step in the development of a formal security awareness program is assembling a security awareness team. This team is responsible for the development, delivery, and maintenance of the security awareness program. The size and membership of the security awareness team will depend on the specific needs of each organization and its culture.

Security awareness may be delivered in many ways, including formal training, computer-based training, e-mails, memos, notices, bulletins, posters, etc. It is important to target cyber security awareness notifications to the appropriate audience to ensure the information is read and understood. By disseminating security awareness training via multiple communication channels, the organization ensures that employees are exposed to the same information multiple times in different ways. By targeting the material and communication channel to relevant personnel, the security awareness team can improve adoption of the security awareness program. One key to an effective security awareness program is in targeting the delivery of relevant material to the appropriate audience in a timely and efficient manner.

Role-based security awareness provides organizations a reference for training personnel at the appropriate levels based on their job functions. Establishing a minimum awareness level for all personnel (management and employees) can be the base of the security awareness program. The first task when scoping a role-based security awareness program is to group individuals according to their job functions within the organization. Having a team in place will help ensure the success of the security awareness program through assignment of responsibility for the program. A solid awareness program will help all personnel to recognize threats, see security as beneficial enough to make it a habit at work and at home, and feel comfortable reporting potential security issues.

Management leadership and support for the security awareness program is crucial to its successful adoption by staff. Managers are encouraged to:

  • Encourage personnel to actively participate and uphold the security awareness principles.
  • Model the appropriate security awareness approach to reinforce the learning obtained from the program.
  • Include security awareness metrics into management and staff performance reviews.

As stated above, it is recommended that training content be determined based on the role and the organization’s culture. The security awareness team may wish to coordinate with the appropriate business units to classify each role in order to determine the level of security awareness training required for those specific job duties. This is vital in development of content, to avoid “over-trainning” or “under-trainning” an employee. In addition to general security awareness training, it is recommended personnel be exposed to general concepts of data security, to promote proper data handling throughout the organization, according to their role in the organization.

Training materials should be available for all areas of the organization, such as the corporate intranet. Choosing which materials to use in a security awareness training program is highly dependent on the organization. Each organization should consider its culture when selecting the materials to use for the security awareness training. The following are examples of reference materials that may help in the development of a Security Awareness Program:

  • National Institute of Standards and Technology (NIST) Special Publication 800-50, Building an Information Technology Security Awareness and Training Program, www.nist.gov
  • International Standards Organization (ISO) 27002:2013, Information technology -- Security techniques -- Code of practice for information security controls, www.iso.org
  • International Standards Organization (ISO) 27001:2013, Information technology — Security techniques — Information security management systems, www.iso.org
  • COBIT 5 Appendix F.2, Detailed Guidance: Services, Infrastructure and Applications Enabler, Security Awareness, www.isaca.org/cobit
Additionally, due to the increased focus on cyber security awareness, many government agencies and industry bodies provide training materials to the public at no cost.

To ensure all personnel are engaged stakeholders in the security awareness program, the roles and responsibilities of all staff to protect corporate data should be outlined during all security awareness training, in accordance with organizational policy.
Because data is at risk both in electronic form and in non-electronic (paper) form, it is recommended that the different ways to safeguard information for different media be covered at a basic level for all personnel. For instance, considerations for protecting data in electronic format may include secure storage, transmission and disposal. Considerations for paper-based formats may also include secure storage and disposal as well as a “clear desk” policy. Without an understanding of how different media types need to be protected, personnel may inadvertently handle data in an insecure manner.
Another important consideration for inclusion in general security training is awareness of social engineering attacks. One way an attacker may use social engineering is to acquire a user’s credentials and work their way through the organization from a low-security area to a high security area. Tailoring this awareness to reflect the types of attacks that the organization may encounter provides the most effective results. Users should be aware of the common methods by which fraudsters, hackers or other malicious individuals might try to obtain credentials, payment card data, and other sensitive data, to minimize the risk of personnel unintentionally disseminating sensitive information to outsiders. Training in organizational policies and procedures that specify proper data handling, including sharing and transmission of sensitive data, is also recommended.
Feedback on training content and comprehension are key to ensuring personnel understand the content and the organization’s security policies.
In addition to content for all personnel, management training should include more detailed information regarding the consequences of a breach to management stakeholders. Management should understand not only the monetary penalties of failing to safeguard assets, but also the lasting harm to the organization due to reputational (brand) damage.
As previously discussed, management will need to understand security requirements enough to discuss and reinforce them, and encourage personnel to follow the requirements. It is recommended that management security awareness training include specific content relevant to the area of responsibility, particularly areas with access to sensitive data.
Management that is security-aware better understands the risk factors to the organization’s information. This knowledge helps them make well-informed decisions related to business operations. Managers who are security-aware can also assist with development of data security policies, secure procedures, and security awareness training.

Metrics can be an effective tool to measure the success of a security awareness program, and can also provide valuable information to keep the security awareness program up-to-date and effective. The particular metrics used to measure the success of a security awareness program will vary for each organization based on considerations such as size, industry, and type of training.

Δευτέρα 5 Ιανουαρίου 2015

COBIT5


COBIT is a framework served by ISACA for IT management and IT governance. It is a supporting toolset that allows managers to bridge the gap between control requirements, technical issues and business risks. The first release of COBIT dates back in 1996, then ISACA published the current version, COBIT 5.0, in 2012.

The business orientation of COBIT consists of aligning business goals to IT goals, providing metrics and maturity models to measure their achievement, and identifying the associated responsibilities of business along with IT process owners.

The COBIT components include:
  • Framework: Organize IT governance objectives and good practices by IT domains and processes, and links them to business requirements
  • Process descriptions: A reference process model and common language for everyone in an organization. The processes map to responsibility areas of plan, build, run and monitor.
  • Control objectives: Provide a complete set of high-level requirements to be considered by management for effective control of each IT process.
  • Management guidelines: Help assign responsibility, agree on objectives, measure performance, and illustrate interrelationship with other processes
  • Maturity models: Assess maturity and capability per process and helps to address gaps.
The Sarbanes-Oxley Act of 2002 (a.k.a SOX) strengthened COBIT’s presence in the enterprise. Prior to SOX, publicly traded organizations saw very little audit oversight of electronic data resource utilization and security. Security professionals instead relied heavily on standards of best practice, such as ISO 27002 and ITIL to safeguard resources. However, auditors chose to use the limited guidelines of COBIT 4 to govern SOX compliance. While COBIT 4 provided some guidance on information security, it lacked the comprehensive coverage of traditional standards. This changed with the release of COBIT 5.

With COBIT 5, ISACA introduced a framework for information security. It includes all aspects of ensuring reasonable and appropriate security for information resources. Its foundation is a set of principles upon which an organization should build and test security policies, standards, guidelines, processes, and controls.

Meeting stakeholder needs
A group of stakeholders includes any individual or group affected by the current state or future state of a process, system or policy. Failure to involve all stakeholders, including security and audit teams, usually results in less than optimum outcomes at best. Worst case outcomes include failed projects or material audit deficiencies.

Covering the enterprise end-to-end
General application of security and assurance best practices requires security reviews as part of all business processes and IT development and implementation activities. This is not just a horizontal integration. Rather, all levels of management must include information security in every business strategic and operational planning activity.

Applying a single integrated framework
Designing a complete framework includes all aspects of information storage, flow, and processing, providing a foundation for more efficient control implementation. A framework supports a holistic approach to securing an organization.

Enabling a holistic approach
As support for developing an integrated framework, it is important to see information security as a set of related components. Each component is driven by enablers and other factors affecting organization risk. COBIT 5 for Information Security provides a list of enablers and describes how they interrelate. Enablers help organizations integrate operations and security into the outcomes of all principles defined here. As always, this is done in a way to meet stakeholder requirements.

Separating governance from management
While governance and management are separate functions performed by designated teams, they must support each other. Governance defines outcomes and management implements technology and processes to meet those outcomes. Governance then determines if outcomes are met and provides feedback to help management make necessary adjustments.

The COBIT 5 processes are split into governance and management "areas". These two areas contain a total of five domains and 37 processes:
1. Governance of Enterprise IT
Evaluate, Direct and Monitor (EDM) – 5 processes
  • Ensure Governance Framework Setting and Maintenance
  • Ensure Benefits Delivery
  • Ensure Risk Optimization
  • Ensure Resource Optimization
  • Ensure Stakeholder Transparency
2. Management of Enterprise IT
Align, Plan and Organise (APO) – 13 processes
  • Manage the IT Management Framework
  • Manage Strategy
  • Manage Entreprise Architecture
  • Manage Innovation
  • Manage Portfolio
  • Manage Budget and Costs
  • Manage Human Relations
  • Manage Relationships
  • Manage Service Agreements
  • Manage Suppliers
  • Manage Quality
  • Manage Risk
  • Manage Security
Build, Acquire and Implement (BAI) – 10 processes
  • Manage Programs and Projects
  • Manage Requirements Definition
  • Manage Solutions Identification and Build
  • Manage Availability and Capacity
  • Manage Organisational Change Enablement
  • Manage Changes
  • Manage Changes Acceptance and Transitioning
  • Manage Knowledge
  • Manage Assets
  • Manage Configuration
Deliver, Service and Support (DSS) – 6 processes
  • Manage Operations
  • Manage Service Requests and Incidents
  • Manage Problems
  • Manage Continuity
  • Manage Security Services
  • Manage Business Process Controls
Monitor, Evaluate and Assess (MEA) - 3 processes
  • Monitor, Evaluate and Assess Performance and Conformance
  • Monitor, Evaluate and Asses the System of Internal Control
  • Evaluate and Assess Compliance with External Requirements
To summarize:
COBIT 5 for Information Security provides a comprehensive framework for integrating security into business processes.  It also provides a set of enablers that, when applied, help ensure stakeholder acceptance and efficient business operation.
Organizations must integrate security into every facet of management and operations. This begins with identifying all business processes and associated stakeholders, including audit and InfoSec teams.
Individual approaches to managing security will not achieve the best overall results. A holistic approach, one that defines a complete framework used to integrate new controls or vulnerability remediation, is necessary for both security and financial efficiency and effectiveness.

Δευτέρα 8 Δεκεμβρίου 2014

Fraud, Corruption and Corporate Governance

Fraud and Corruption are like radiation. There are all around us, invisible, subtle and we usually aware of them, when irrevocable damage and sometimes total destruction arise. They use the “spider method”: Attract, Entrap, Devour.

In their essence are “asymmetric”. They exist in every socio-economic context, every evolutionary step of Mankind, all eras, people and Gods (in mythology); uncontained by any means, political system or leader. Perhaps they are unstoppable. Nevertheless, there are control measures to contain them, at least in an enterprise level, and one of them is “Corporate Governance”.

Though semantically fraud and corruption are used interchangeably they have different definitions. Fraud is the intentional deception made for personal gain or to damage other individuals and/or entities.
Corruption is, in a sense, a more general phenomenon, as expansion and consolidation of fraudulent practices, and is not defined uniquely, but depending on the country and the political and socio-economic situation that surrounds it. This is because it is really difficult to make a clear, unambiguous and commonly accepted distinction between legality and illegality, between corruption and reward, resulting in "gray areas" larger than the intervals distinctly black or white; thus leading everyone, to interpret and to assess corruption in his/her own unique way, depending on the environment in which he/she lives and moves.

However, it is commonly accepted that the corruption is associated with the use of one's official position for personal and/or group profit and making immoral/non-ethical actions. Indications of fraud are the: bribery, "kickbacks" suspicious transactions/exchanges of “favors”, “interlocking” interests, abuse of power, "protection", "black" labor, abuse/theft of public resources, money squandering, over invoicing/under invoicing, inventory notional costs, abuse, embezzlement, fraud, extortion, forgery, falsification of documents, nepotism, manipulation/deception (people, Authorities, Press), unfair competition, exploitation of "gray zones" and/or bureaucratic details ("loopholes") to cover illegalities.

In any case, corruption is in the orbit of a vicious cycle, which starts from corruption itself, which -due to the high spread degree- leads (up to “forcing” one could say) businesses to engage in unfair practices (e.g. corruption), expands itself, is strengthened by the prevailing perception of size, range and “necessity” corruption, swells -due to the aforementioned perception- and finally is fed back, making unfair practices even more uncontrollable. Corporate Governance could be a catalyst to break this vicious circle.
In general, Corporate Governance is a set of mechanisms and rules, which defines the relationship between all the stakeholders in a company, namely: Management, Directors, Shareholders, and other relevant parties (e.g. staff, providers, suppliers, business partners, customers, consumers, consultants, etc., including the Government, independent and Supervisory Authorities and the Public Administration of the country of operation).  More specifically:

  • Describes and defines their relationships,
  • Specifies the distribution of rights and responsibilities among them,
  • Identifies Principles, Methodologies and Procedures, needed to make corporate decisions,
  • Defines the way (framework and structure; organizational, administrative, etc.), through which the company objectives are set,
  • Describes the acceptable means, to be used both for the achievement of corporate goals and for monitoring of their effectiveness,
  • Specifies control mechanisms/measures to ensure transparency and accountability.
In conclusion, Corporate Governance is a "tool" for better allocation of resources and better enterprise management, ultimately improving business performance, in terms of efficiency and effectiveness, and this is "rewarding".

In fact, as shown by studies (e.g. McKinsey) international investors (institutional or not) prefer to invest more money in companies that have developed a good Corporate Governance framework, as they have higher value in the Market, which leads to higher growth prospects. This involves increasing the access of firms to external finance, and therefore lower capital costs. This may, in turn, lead to improved competitiveness in even greater investment, higher growth and more jobs. This whole "chain" creates "wealth" and closes the circle by “returning” this wealth to the society, since it contributes to reduce the risk of financial crises and the huge economic and social costs that result, the improvement of social and labor relations, as well as development in areas of "corporate social responsibility", such as protecting the environment, supporting common social needs (health, education, sports) through sponsorships, grants, etc.

Consider the issue in "economic" terms; that is "Supply" and "Demand": In the equation of "State- economic” Corruption, the "Demand" relates mainly to the ones "having any kind of relationship" with the State Sector, who endeavor to provide unfair advantages (e.g. “peculiar” rental arrangements) in exchange for" appropriate "payments” ("kickbacks" or “starters” in Greek”). The "Supply" refers to the ones "having any kind of relationship" with the Private Sector, who are looking for, and of course they are willing to pay, in order to get these benefits unduly from previous ones. In general, the Corporate Governance is one of the main tools for controlling the side of the "Supply" in the Corruption equation.
The "Private-economic" Corruption, on the other hand, is more complex and the two most common forms in which it can be found are: Bribery and Professional Fraud. These are located mainly in areas of significant business Functions, such as: Procurement (making contracts/arrangements), Budgeting/Accounting, Financial Transactions (mainly Treasury), Distribution chain, R & D (access to unique/proprietary technical/commercial data - industrial espionage), etc.

Corporate Governance aims to promote honest and responsible behavior to conduct a business, adopting practices that are consistent with the legislative and institutional framework of the country in which it operates, and applying commonly accepted social values. For this purpose, adopt best practices and mechanisms, such as: the International Accounting Standards, Regulations of the Financial Markets Operations, "Property" Audit Methodology, Corporate Disclosure Policy (e.g. for Financial data), Limited access to information, control of capital inflows, etc., so as to enhance the "transparency" and to fight corruption, while reducing negative impacts. The establishment of an independent, company-concerned, Control Council, is also important, so as to represent and genuinely interest of shareholders, anticipate and prevent potential opportunistic behavior of senior executives (and/or "internal" shareholders), who are theoretically more prone to be tempted by the immediate benefit of corruption practices, i.e. money (e.g. cash, bonus) that they bring.

In practice, the most successful way of implementing a sound Corporate Governance is to enhance Business Ethics, by consolidating strong corporate culture where corruption documented condemned as unacceptable moral behavior and not just another issue of Risk Management. In this way, the Corporate Governance marks the creation of a strategic corporate identity oriented to "moral values." In this context, it establishes robust "transparency of payments” mechanisms, so as any cause of corruption (such as bribery, extortion, unfair competition) is disclosed quickly, and becomes directly reprehensible, punishable (by activating mechanisms of accountability and transparency, and sanctions against "participants") and, therefore, "unsustainable".

The main problem in this approach is the universal social acceptance of the double game of risk factors, which may have two "persons", as Janus: to condemn corruption, on a personal level, for ethical reasons, but to supplant the "honor" and the moral, in business activity, justifying any practice for profit. This contributes to the creation of two new cross-powered vicious circles, which create alienation between Society and both Public and Private Sector as:

  1. The Society believes that most public functionaries participate in the dishonest practices of the private sector; mostly resulted from top-down pressures derived from common “understanding” between the heads of top management. This fosters corruption furthermore, since they all feel that the corrupt behavior ("all of them are bribed") is more or less given and any attempt to break this vicious cycle is impossible, "Don Quixotism" or "stupidity".
  2. The Society does not expect from a private company to be honest but just (dishonest) profit-oriented; mostly resulted from top-down pressures. Throughout this cycle, enterprises are trapped and multiply disadvantaged by being victims of a peculiar "double, two-way blackmailing"; both from Society (due to confidence loss, resulted by the expected corruption behavior) and the Company itself (mostly derived from heads of top management and/or powerful business associations, tapped in the “underground” aid of corruption).
All this contradictory nature of modular relations and interdependencies creates a dialectic, which not only causes corruption but also justifies it, deconstructing the moral-social identity business and neutralizing the effective participation of society, alienating it from the economic-social chain and alternating the scope and nature of its participation.
Of course, all these phenomena and behaviors are reinforced by impunity, which is the most common, in contrast to the occurrence of the related risk, i.e. the obvious economic and moral damage (up to destruction) of individuals and businesses involved in corruption practices compared with the benefits gained.
Could we ever break this perverse relationship between the Companies and the other sectors of the Society ???
The answer is "YES"; with the commitment of all institutional, social and economic factors, which could be performed in many alternative ways, such as:

  • Institutionalism: By amplifying the relevant international legal, political, institutional and regulatory framework, including both international and national strategies related to anti-corruption activities.
  • Accountability: By increasing the control of Corporate Boards of Directors and its accountability to shareholders; e.g. by the mandatory establishment of an independent Corporate Control Council, in any enterprise, so as to address Fraud and Corruption issues, and by activation of whistle-blowing facilitation mechanisms (including prompt “cover” of internal whistle-blowers).
  • Sociability: By obligatory linking of each and every company and/or economic entity with a real and measurable (by using specific metrics) Social Identity, as a metric of enterprise honesty and law-abiding, which would be a KPI (Key Performance Indicator) for State/Government funding and sponsorship. This would facilitate activities related to Corporate Social Responsibility (e.g. charity, promotion of outstanding ethical behavior, enhancement of Corporate Governance and Business Ethics), as essential corporate components.
  • Scientific: By sponsorship (not only financial) of an extended professional research, with regards to Fraud and Corruption diagnosis, problems, consequences and solutions. The research should be held by scientific methods and with direct and universal participation of the both private and public/government sector, so as to create sound scientific data to demonstrate that corruption is really harmful to business and their competitiveness and to facilitate the design of optimal solutions (including implementation of efficient Corporate Governance mechanisms).
In any case, perhaps the most important thing to be done is the development of an appropriate corporate culture, which would make clear that: despite the fact that the Board of Directors of each company faces, each and every day, a plethora of risks, especially those associated with corruption and fraud and their potential effects, trying to do the best to prevent them, how they will really react in an actual crisis is the only thing that can either improve or devastated the reputation of the company, as well as the company itself.
Good Corporate Governance is a stable and infallible compass in this way and the critical/determining factor in the creation of sound socio-economic relations between business and society. Enabling sound coordination mechanisms of anti-fraud and anti-corruption campaigns gives the appropriate signal, both to the government and the private sector (companies, firms and/or competitors) that satisfying the demands of corrupted functionaries (government and others) is not a solution, so the best strategy is the de facto condemnation of unfair practices, the honest and clear entrepreneurship, as well as the healthy competition. Otherwise, companies will always be doomed to “star” in an endless “enterprise series” so called "the Mafia methods"...


Τετάρτη 3 Δεκεμβρίου 2014

The Time Is Now for Information Governance. But Do You Even Know What It Is?


Information governance covers the entire spectrum of information management, but most people have a fuzzy notion of what it is. This must change, because the real value of information can't be fully realized unless it is properly governed.

Information governance is fast becoming a required competence for IT -- even though we've barely become conscious of what it is.

At a series of university-based research initiatives and industry conferences, I presented executives with the following aural Rorschach test: When you hear the phrase "information governance," what is the first thing that leaps to mind? I was surprised at the diversity of responses: analytics, business intelligence, compliance, data governance, data hygiene, defensible disposal, document management, e-discovery, enterprise architecture, enterprise content management, information life cycle, information risk (the risks associated with how employees handle information), machine learning, master data management, metadata, model management, privacy, records management, regulations, risk, Edward Snowden, structured/unstructured data, and famously breached retailer Target.

As that list suggests, information governance covers a lot of ground -- the entire spectrum of information management, in fact.

The real value of information cannot be fully realized unless data is properly governed. And yet, in many organizations, information governance is an amorphous, undefined concept. It needn't be. Here are three perfectly practicable definitions:
  1. The activities and technologies that organizations employ to maximize the value of their information while minimizing associated risks and costs.
  2. The practice of identifying the electronic content to be managed and how that will be done.
  3. All the processes, policies, standards and tools that consistently define and manage the critical data of an organization.
But definitions don't drive behavior. And the existing frameworks, vocabulary and practices for information governance are tragically immature.

One challenge is that many organizations have erroneously framed information governance as a compliance issue, as if it were all about managing the information they're required to store and make available to regulatory agencies. A compliance mindset, driven by the fear of prosecution, results in reactive tactical programs that don't engage the hearts and minds of employees.
You can get on the path to effective information governance by answering four basic questions:
  1. Who is responsible for information governance?
  2. What are the economics of it?
  3. What is being stored?
  4. What should we be doing?
But answering those questions can be surprisingly complicated.

Take the third question, "What is being stored?" Information storage is a veritable gold mine of opportunity. IDC predicts that enterprise data growth will average around 50% per year through 2016, with storage costs consuming nearly 20% of the typical IT budget in 2014.

But the Compliance, Governance and Oversight Council has found that 69% of information in companies has no business, legal or regulatory value. Now consider that analysts estimate that every gigabyte of data that can be justifiably removed from corporate databases saves an average of $18,000. That gives you an idea of the magnitude of the information governance opportunity. And that is just on the savings side.

Information governance is important high ground that must be mapped, monitored and managed. IT leaders need to step up to this important undertaking.

Futurist Thornton A. May is a speaker, educator and adviser and the author of The New Know: Innovation Powered by Analytics. You can visit his website and contact him.

This story, "The Time Is Now for Information Governance. But Do You Even Know What It Is?" was originally published by Computerworld.

Πέμπτη 25 Σεπτεμβρίου 2014

Information Security Strategy

An information security strategy is a plan to mitigate risks while complying with legal, statutory, contractual, and internally developed requirements.  Typical steps to building a strategy include the definition of control objectives, the identification and assessment of approaches to meet the objectives, the selection of controls, the establishment of benchmarks and metrics, and the preparation of implementation and testing plans.

The selection of controls is typically grounded in a cost comparison of different strategic approaches to risk mitigation.  The cost comparison typically contrasts the costs of various approaches with the potential gains a financial institution could realize in terms of increased confidentiality, availability, or integrity of systems and data.  Those gains could include reduced financial losses, increased customer confidence, positive audit findings, and regulatory compliance.  Any particular approach should consider:

  1. policies, standards, and procedures; 
  2. technology design; 
  3. resource dedication; 
  4. training; 
  5. testing.
For example, an institution's management may be assessing the proper strategic approach to the security monitoring of activities for an Internet environment.  Two potential approaches are identified for evaluation.  The first approach uses a combination of network and host sensors with a staffed monitoring center.  The second approach consists of daily access log review.  The former alternative is judged much more capable of detecting an attack in time to minimize any damage to the institution and its data, albeit at a much greater cost.  The added cost is entirely appropriate when customer data and institution processing capabilities are exposed to an attack, such as in an Internet banking environment.  The latter approach may be appropriate when the primary risk is reputational damage, such as when the only information being protected is an information-only Web site, and the Web site is not connected to other financial institution systems.

Governance
Governance is achieved through the management structure, assignment of responsibilities and authority, establishment of policies, standards and procedures, allocation of resources, monitoring, and accountability. Governance is required to ensure that tasks are completed appropriately, that accountability is maintained, and that risk is managed for the entire enterprise.  Although all aspects of institutional governance are important to the maintenance of a secure environment, this booklet will speak to those aspects that are unique to information security.  This section will address the management structure, responsibilities, and accountability.

Responsibility and Accountability
The board of directors, or an appropriate committee of the board, is responsible for overseeing the development, implementation, and maintenance of the institution's information security program, and making senior management accountable for its actions. Oversight requires the board to provide management with guidance; approve information security plans, policies and programs; and review reports on the effectiveness of the information security program. The board should provide management with its expectations and requirements and hold management accountable for

  • Central oversight and coordination,
  • Assignment of responsibility,
  • Risk assessment and measurement,
  • Monitoring and testing,
  • Reporting, and
  • Acceptable residual risk.
The board should approve written information security policies and the written report on the effectiveness of the information security program at least annually.  A written report to the board should describe the overall status of the information security program.  At a minimum, the report should address the results of the risk assessment process; risk management and control decisions; service provider arrangements; results of security monitoring and testing; security breaches or violations and management's responses; and recommendations for changes to the information security program. The annual approval should consider the results of management assessments and reviews, internal and external audit activity related to information security, third-party reviews of the information security program and information security measures, and other internal or external reviews designed to assess the adequacy of information security controls.

Senior management's attitude towards security affects the entire organization's commitment to security.  For example, the failure of a financial institution president to comply with security policies could undermine the entire organization's commitment to security.
Senior management should

  • Clearly support all aspects of the information security program;
  • Implement the information security program as approved by the board of directors;
  • Establish appropriate policies, procedures, and controls;
  • Participate in assessing the effect of security issues on the financial institution and its business lines and processes;
  • Delineate clear lines of responsibility and accountability for information security risk management decisions;
  • Define risk measurement definitions and criteria;
  • Establish acceptable levels of information security risks; and
  • Oversee risk mitigation activities.
Senior management should designate one or more individuals as information security officers. Security officers should be responsible and accountable for administration of the security program. At a minimum, they should directly manage or oversee the risk assessment process, development of policies, standards, and procedures, testing, and security reporting processes.  To ensure appropriate segregation of duties, the information security officers should report directly to the board or to senior management and have sufficient independence to perform their assigned tasks.  Typically, the security officers should be risk managers and not a production resource assigned to the information technology department.

Security officers should have the authority to respond to a security eventA security event occurs when the confidentiality, integrity, availability, or accountability of an information system is compromised. by ordering emergency actions to protect the financial institution and its customers from an imminent loss of information or value.  They should have sufficient knowledge, background, and training, as well as an organizational position, to enable them to perform their assigned tasks.
Senior management should enforce its security program by clearly communicating responsibilities and holding appropriate individuals accountable for complying with these requirements.  A central authority should be responsible for establishing and monitoring the security program.  Security management responsibilities, however, may be distributed to various lines of business depending on the institution's size, complexity, culture, nature of operations, and other factors.  The distribution of duties should ensure an appropriate segregation of duties between individuals or organizational groups.

Senior management also has the responsibility to ensure integration of security controls throughout the organization.  To support integration, senior management should

  • Ensure the security process is governed by organizational policies and practices that are consistently applied,
  • Require that data with similar criticality and sensitivity characteristics be protected consistently regardless of where in the organization it resides,
  • Enforce compliance with the security program in a balanced and consistent manner across the organization,
  • Coordinate information security with physical security, and
  • Ensure an effective information security awareness program has been implemented throughout the organization.
Senior management should make decisions regarding the acceptance of security risks and the performance of risk mitigation activities using guidance approved by the board of directors. Those decisions should be incorporated into the institution's policies, standards, and procedures.

Employees should know, understand, and be held accountable for fulfilling their security responsibilities. Institutions should define these responsibilities in their security policy. Job descriptions or contracts should specify any additional security responsibilities beyond the general policies.  Financial institutions can achieve effective employee awareness and understanding through security training and ongoing security-related communications, employee certifications of compliance, self-assessments, audits, and monitoring.

Internal auditors should pursue their risk-based audit program to ensure appropriate policies and procedures and the adequacy of implementation, and issue appropriate reports to the Board of Directors.

Management also should consider and monitor the roles and responsibilities of external parties.  The security responsibilities of technology service providers (TSPs), contractors, customers, and others who have access to the institution's systems and data should be clearly delineated and documented in contracts.  Appropriate reporting mechanisms should be in place to allow management to make judgments as to the fulfillment of those responsibilities.  Finally, sufficient controls should be included in the contract to enable management to enforce contractual requirements.