Tuesday, June 20, 2017

MEPs Ready To Fight For End-To-End Encryption Across EU

Governement-ITLegalRegulationSecurity

MEPs Ready To Fight For End-To-End Encryption Across EU



Sam Pudwell joined Silicon UK as a reporter in December 2016. As well as being the resident Cloud aficionado, he covers areas such as cyber security, government IT and sports technology, with the aim of going to as many events as possible.




A European Parliament committee has called for end-to-end encryption to be enforced on all forms of digital communication
A European Parliament committee has called for end-to-end encryption to be enforced on all forms of digital communication in the latest development in the ongoing encryption debate.
The draft legislation argues that EU citizens are entitled to privacy online and wants to protect their sensitive data from being accessed by governments and cyber criminals.
A key factor being considered is a ban on the inclusion of ‘backdoors’ into apps such as WhatApp and Telegram, something which WhatApp has denied ever having.
houses of parliament

 Privacy boost

A backdoor ban would ensure end-to-end encryption where neither government agencies nor the company providing the service  are able to listen in on conversations, ensuring a significant boost to consumer privacy.
“The principle of confidentiality should apply to current and future means of communication, including calls, internet access, instant messaging applications, email, internet phone calls and personal messaging provided through social media,” a draft proposal from the European Parliament’s Committee on Civil Liberties, Justice, and Home Affairs says.
Any such rule change would require approval by both the European Parliament and the European Council.
The issue gained prominence in the UK after March’s Westminster terror attack which resulted in the deaths of six people.
In the wake of the attack, home secretary Amber Rudd publicly slammed WhatsApp for its “completely unacceptable” use of encryption which made the attackers messages inaccessible to third parties.
This was followed by Prime Minister Theresa May’s calls for increased internet regulation following the attack on London Bridge and the revelation of government plans to ask Parliament for more power over technology companies.
It is an issue which is being driven by horrific acts of terrorism, but many industry experts believe that the technical implications of encryption, or a lack thereof, are yet to be understood by the UK government.
It should also be noted that steps are being taken to combat the issue. The world’s biggest tech firms have pledged to work harder to tackle terrorist propaganda online, with many using technology such as artificial intelligence to do so.

Saturday, June 17, 2017

Swift CEO Says Hackers Can Unite Banks and Blockchain Disruptors

by Michael del Castillo

ADVERTISEMENT
When the CEO of Swift wants to learn about blockchain, he does it in style.
On stage yesterday in New York, Gottfried Leibbrandt gathered senior executives from some of the largest banks in the world – which also happened to be members of his interbank messaging platform – and put them on stage with the president of one of his own biggest (potential) competitors: blockchain startup Chain.
Speaking on stage in front of 500 senior financial institution leaders, Leibbrandt then deftly navigated his interrogation of representatives from the diverse group of financial institutions including JPMorgan, Citi and CLS.
While there was no doubt that members of the panel viewed one another as potential partners, potential customers and definite competitors, the Swift chief summarized what they all shared in his own closing comments: a common enemy, hackers.
Leibbrandt concluded:
"We have to be better than them."

Joining the 'dark side'

For his part, Leibbrandt seemed to be trying to establish a tone of camaraderie throughout his questioning, one that found an unlikely partner in Tom Jessop, the newly appointed president of Chain – a heavily funded blockchain startup ostensibly out to make middlemen (like Swift) unnecessary.
But Chain has struck a more conciliatory tone than some of its rivals such as Ripple, which has set Swift square in its sights as the incumbent to beat. By contrast, all three of Chain's first public clients – Citi, Nasdaq and Visa – are what would be considered legacy financial institutions.
Jessop came up through the ranks at Goldman Sachs as part of the bank's fintech investing team, and was hired by the blockchain firm last year specifically because of his ability to work with incumbents.
In spite of the friendly demeanor on stage, though, Jessop, alluded to criticism that his joining Chain has been perceived as a betrayal of the legacy financial institutions from which he came.
"People always say to me, 'Why did you go to the dark side?'" said Jessop. "Actually, I don't think it's the dark side. I think there’s a lot of work we can do together, and it only happens through partnership."

Fighting for the system

Leibbrandt's own comments on using blockchain technology to thwart criminal activities echoed earlier statements made by panelist David Puth, CEO of foreign exchange service CLS.
Puth drew laughs from the audience when, following Jessop’s first address to the audience, he described Chain's value proposition, saying: "You see what I’m up against?"
Puth also joked that running a "systemically important financial business" might not be the best business decision, with no pricing control and upstarts trying to take away "pieces" of what you offer and selling it to customers in a "different or simplified way".
To take on the technological upstarts head-on, Puth last year announced at Swift's Sibos conference that his firm had partnered with IBM to work on its own blockchain solution.
"When we're competing, when we're going at innovation against the likes of Tom Jessop, we have to think really hard about how we approach things," said Puth, who also indicated that his firm was looking for partners similar to Chain.

The enemy of my enemy...

However, the general consensus among the panelists was that whatever the differences between the participants, they were on the same side against criminal adversaries.
To stay one step ahead of bad actors, both the strengths of the legacy infrastructure providers and the innovation of blockchain startups need to be leveraged over the long haul, according to Emma Loftus, managing director and head of global payments at the US division of JPMorgan Treasury Services.
Also speaking at the event, Loftus, whose company recently joined the Enterprise Ethereum Alliance and open-sourced its ethereum-based private ledger called Quorum, positioned partnerships across borders and via consortia as crucial to fighting fraud.
But she went a step further, calling collaboration between blockchain startups and the legacy financial system one of the great challenges slowing widespread adoption.
"This traverse from traditional to blockchain and the requisite interoperability is why people are taking a very thoughtful approach before jumping in to replace everything," said Loftus.

Innovate or lose

For his part, Charles Blauner, global head of information security at Citi – another 'bulge bracket' bank adopting blockchain – had advice of a different sort for industry startups confident that their cryptography is the solution to every financial security problem.
Blauner cautioned blockchain startups that all cryptographic algorithms "degrade" over time, and that like the Roman cipher wheels of the past, even the most sophisticated encryption might eventually be hacked by quantum computers and more.
As fintech startups achieve wider adoption, he warned, the prize for successfully hacking them will increase and "the volume of attacks from potential adversaries will grow".
In addition to building platforms with easily upgradable cryptographic algorithms and intensely testing the protections, Blauner advocated for even closer collaboration between those who might otherwise be considered competitors.
"The bad guys, the adversaries … collaborate brilliantly, innovate rapidly," said Blauner. "If we can’t do the same thing, we’re going to lose and so we have to be better than them at innovation. We have to be better than them at collaboration."
He concluded:
"Otherwise, statistically speaking they win, we lose."
Disclosure: CoinDesk is a subsidiary of Digital Currency Group, which has an ownership stake in Chain.
Swift panel image via Michael del Castillo for CoinDesk
The leader in blockchain news, CoinDesk is an independent media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. Interested in offering your expertise or insights to our reporting? Contact us at news@coindesk.com.                        

Tuesday, June 13, 2017

Cybersecurity Is DeadCybersecurity Is Dead






Elite CIOs, CTOs & execs offer firsthand insights on tech & business.



Forbes Technology Council is an invitation-only organization comprised of elite CIOs, CTOs and technology executives. Members are hand-selected by the Council's selection committee. Find out if you qualify at forbestechcouncil.com/qualify.

Loading...
Loading...

Post written by
Mike Baukes
Co-founder and co-CEO of UpGuard, the world's first cyber resilience platform.



Well-known cybersecurity firm Crowdstrike greets travelers who arrive at San Francisco International Airport with a rather bold claim advertised throughout the terminals. The advertisements pose a pernicious yet seemingly tidy answer: "Yesterday’s Antivirus Can’t Stop Today’s Cyber Attacks. Crowdstrike Falcon Can."
Irresponsible hyperbole? Or is it a pitch made in good faith, albeit one as confident as it is ignorant? It doesn’t much matter. It is 2017, and we now have ample evidence proving that the false promise of so much cybersecurity -- that risk can be entirely eliminated with one simple program -- will, barring a technological revolution, never be realized.

Shutterstock
The data is in: Cybersecurity is dead. Even as global cybersecurity spending is expected to balloon to over $100 billion by 2020, the frequency and severity of cyberattacks continue to grow, with seemingly no end in sight. While exploits and hacking tools become even more widely available and simple to deploy, there has been little commensurate progress in beating back attackers, who continue to find success striking at persistent, common weak points. How is this possible?
The answer is one that must chagrin any CISO spending exorbitant amounts of money on cybersecurity programs: The entire conception upon which cybersecurity rests -- of constructing a castle, against which any marauding attackers stand little chance of breaching -- is barely of use.
It would be mildly amusing but for a simple fact: The integrity of sensitive data, ranging from your grandmother’s medical records to your personal financial information, relies on its secure storage by a dizzying array of institutions. It is no exaggeration to say that cyber risk -- the accumulated potential for the exposure of privileged data -- is a matter of life and death, as seen in the frightening effects of cyberattacks on the healthcare industry across the world. The existing conceptions of how IT systems can be secured and protected must be discarded in favor of a new and more diffuse understanding of cyber risk.
The concept embodied in the Crowdstrike ad -- that, at last, here is the program that will, like the little Dutch boy, plug the hole in the dam -- is insufficient for combating the real and growing threats looming across the digital landscape. Unsurprisingly, ransomware is exploding in popularity, as the low-cost, easily usable malware proves continually effective at extracting money. But there are grander threat vectors looming: crimes such as electronic bank robberies, digitally enabled high-seas piracy and cyberattacks against electrical grids are not science fiction premises; rather, they are real crimes that will only grow more common. The false promises of cybersecurity doctrines have been repeatedly laid bare over the course of the past few decades. Antivirus programs, once relentlessly promoted as an indelible part of any IT configuration, are now dead even to their creators, having proven thoroughly ineffective in combatting cyber risk -- indeed, even posing to be a liability at times. The “set it and forget it” model, with its focus on an endpoint solution to be instituted without much thought, typically relies upon an out-of-the-box program sold by a third-party vendor. If even the most seemingly impregnable of such barriers are laid down, hackers will be able, with time, to build a higher ladder.
Even more irresponsible is the suggestion that breaches can be forever prevented. Laying down firewalls or perimeter security measures, paying premium prices for executive intelligence on emerging threats, adhering to checkbox compliance regimens -- whatever benefits such measures bring, cyber resilience is not among them. For most consumers and enterprise customers, they believe cybersecurity programs will be able to protect systems against all hacks and breaches -- a belief more or less encouraged by such providers. The reality is no company can do that.
Such defenses, of course, assume that cyber risk is a matter of malicious hackers overcoming paltry defenses. According to Gartner (paywall), mere misconfigurations, not vulnerabilities waiting to be exploited by hackers, account for anywhere from 75-99% of all breaches depending on the platform. And as seen in the recent cyber assault on the United Kingdom’s National Health Service, in which badly outdated IT systems had not received critical updates, hackers rely less on their own (often limited) talents than upon the unfortunate fact that an overwhelming abundance of technologically degraded targets makes their nefarious business easy. Far too easy.

The latest antivirus software will not be the cure-all for this full-spectrum threat any more than the thousands of such programs that came before it. A better conception would involve viewing risk as an inescapable fact of doing business using any internet-facing devices. There is no such thing as a knockout blow that will ensure the integrity of systems; cyber resilience, the intelligent means of managing and mitigating cyber risk, requires best practices be followed every day.
Simply put, fostering cyber resilience is a full-time job, one that must be integrated into every layer of the toolchain when provisioning, configuring and managing IT systems. From documented processes to constant updating to automation, changes in management and visibility, true cyber resilience is the product of inviolable work -- the kind of critical IT management that can never be cast to one side as extraneous. Beyond these requirements of maintenance, IT administrators -- and their superiors, all the way up to the C-suite -- must understand that full visibility into their systems is a prerequisite for mitigating cyber risk.
Only by gaining full insight into the real state of IT systems can stakeholders ensure systemic integrity and, in the event of a breach, begin to quickly and adequately respond, as seen in the WannaCry contagion. That is the future of cyber resilience.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

How a Holistic Approach Supports Robust Website Security

How a Holistic Approach Supports Robust Website Security

With cybercrime on the rise, it is more important than ever for companies and organizations to invest in website security.







There are more than 1 billion websites on the internet. Just as that figure continues to grow at a dizzying rate, so, too, do concerns over website security.
Safeguarding digital assets is of central importance for virtually all global enterprises. Effective and secure websites are the lifeblood of the modern economy, but online payments and other forms of data sharing provide cyber criminals with lucrative targets at which to take aim.
Unfortunately, we have grown accustomed to the flood of data breaches and identity thefts in the news — and those are just the ones that become public. Business leaders determined to avoid falling prey to a potentially calamitous cyber event must make cybersecurity a core priority, rather than treating it as the information technology department’s concern. That starts with prioritizing a skilled, well-trained security workforce on the front lines of protecting enterprises’ precious information assets.

Investing in cybersecurity

Without clearly explaining a return on investment, investing in cybersecurity can be difficult for executives to accept. It is critical to make business-related arguments, addressing business continuity, customer trust and clearly linking investment to the organization’s business objectives.
“Security by design is more cost-effective than security that is patched around systems.”
Even for those organizations whose boards of directors recognize that cybersecurity investment is a business imperative, implementing a robust security program is an enormous challenge. Given the ever-growing number and sophistication of cyber threats, finding the right security professionals can prove an exasperating exercise. ISACA’s 2016 State of Cybersecurity Report showed that it takes 27 percent of organizations six months to fill a cybersecurity position — an unacceptable duration given the threats lurking in today’s landscape.
Simply waiting for qualified professionals to come knocking on the door is unrealistic. Enterprises should encourage upskilling from their current security workforce, either by offering training opportunities or encouraging employees to pursue pertinent industry certifications.
Enterprises also should be mindful that security by design is more cost-effective than security that is patched around systems. With the appropriate frameworks in place, taking into account response and recovery as seriously as prevention and detection, a robust and holistic security program can be put in place.

Technological advantages

Bear in mind, cyber criminals are not the only ones capable of taking advantage of improved technology. Enterprises also can benefit from new and evolving methods for keeping pace with threats.
Leveraging modern mobile payments is a worthwhile consideration for enterprises and consumers alike who are concerned about protecting data during transactions. Advancements in mobile payment security technology — specifically the use of tokenization, device-specific cryptograms and two-factor authentication — can provide important security benefits that result in decreased instances of identity fraud and lower costs.
While it is important to keep an eye on what is new, emphasizing tried-and-true security fundamentals also goes a long way. Ensuring appropriate design and effectiveness of controls to identify critical assets, to protect them with preventive controls around a web application, operating system, network and infrastructure layer — to detect attacks and to respond to them and eventually recover from breaches — are key for cyber-securing websites.
There is much that can and needs to be done to promote effective website security. The threat landscape may be daunting, but leaving an organization’s reputation and future viability to chance is not an option.

Monday, June 12, 2017

ISO 27001 can be implemented on your current Windows® system

ISO 27001 can be implemented on your current Windows® system


As highlighted in our blog last week, several supervisory authorities across Europe have already highlighted ISO 27001 as a model of best practice that will provide good evidence of intent and effort to comply with the GDPR.
ISO 27001 provides an excellent approach to complying with data protection and privacy legislation because it requires the business to recognise the “needs and expectations of interested parties”, which include customers, the public, partners and regulatory bodies, and “may include legal and regulatory requirements and contractual obligations”.
Certification to ISO 27001 can bring organisations a host of benefits, including:
  • Safeguarding their valuable data and intellectual property
  • Winning new business and retaining their existing customer base
  • Avoiding the financial penalties and losses associated with data breaches
  • Complying with business, legal, contractual and regulatory requirements
  • Improving their processes
  • And much more.

ISO 27001 is not the complicated standard it is made out to be

We recently caught up with Brian Honan, the author of June’s book of the month ISO27001 in a Windows® Environment, in one of our author podcasts. You can listen to the full podcast here.
Brian said that it “really struck him how complicated people seemed to think ISO 27001 was”.
Brian said that many people thought ISO 27001 would “require thousands of mandates, lots of money to invest in IT equipment and systems, and would take forever to get implemented”.
However, he highlighted that the Standard is not as complicated as you might think and that you may not have to buy new systems or security systems to comply with it.

ISO 27001 can be implemented on your current Windows® system

A lot of the technical controls in ISO 27001 can be addressed with the inbuilt functionality and tools in Windows.
ISO27001 in a Windows® Environment gives essential guidance for everyone involved in a ISO 27001 can be implemented on your current Windows® systemWindows-based ISO 27001 project.This book:
  • Details the various controls required under ISO 27001:2013, together with the relevant Microsoft products that can be used to implement them.
  • Explains how to make the most of Windows security features.
  • Is ideal for bridging the knowledge gap between ISO 27001 and Windows security.
https://www.itgovernance.eu/blog/iso-27001-can-be-implemented-on-your-current-windows-system/?utm_campaign=twitter&utm_source=social&utm_medium=twitter


Monday, May 22, 2017

CSSF Circular 17/654 on cloud computing

CSSF Circular 17/654 on cloud computing

18 May 2017

Regulatory News Alert






On 17 May 2017, the CSSF published Circular 17/654 (the circular) on IT outsourcing based on a cloud computing infrastructure. The circular intends to clarify the regulatory framework for recourse to cloud computing infrastructure supplied by an external service provider. Indeed, the circular reaffirms that CSSF considers that cloud computing is a form of outsourcing. The circular applies immediately to financial professionals, including credit institutions, investment firms, specialized PSFs, support PSFs, as well as payment institutions, and electronic money institutions.

PDF - 297kb




Defining cloud computing

In order to distinguish cloud computing from other forms of outsourcing, CSSF provides a definition of cloud computing based on those of authoritative international organizations (i.e., NIST and ENISA). As per this definition, cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.
This cloud model is composed of (i) five essential characteristics, (ii) three service models, and (iii) four deployment models:



Essential characteristics


On-demand self-service

A consumer can unilaterally provision computing capabilities, such as server time and network storage, as needed automatically without requiring human interaction with each service provider.

Broad network access

Capabilities are available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms (e.g. mobile phones, tablets, laptops, and workstations).

Resource pooling

The provider’s computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to consumer demand. There is a sense of location independence in that the customer generally has no control or knowledge over the exact location of the provided resources but may be able to specify location at a higher level of abstraction (e.g. country, state, or datacenter). Examples of resources include storage, processing, memory, and network bandwidth.

Rapid elasticity

Capabilities can be elastically provisioned and released, in some cases automatically, to scale rapidly outward and inward commensurate with demand. To the consumer, the capabilities available for provisioning often appear to be unlimited and can be appropriated in any quantity at any time.

Measured service

Cloud systems automatically control and optimize resource use by leveraging a metering capability at some level of abstraction appropriate to the type of service (e.g. storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency for both the provider and consumer of the utilized service.

${section1-title6}

${section1-content6}

${section1-title7}

${section1-content7}

${section1-title8}

${section1-content8}

${section1-title9}

${section1-content9}

${section1-title10}

${section1-content10}

Service Models


Infrastructure as a Service (IaaS)

The capability provided to the consumer is to provision processing, storage, networks, and other fundamental computing resources where the consumer is able to deploy and run arbitrary software, which can include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure but has control over operating systems, storage, and deployed applications; and possibly limited control of select networking components (e.g., host firewalls).

Platform as a Service (PaaS)

The capability provided to the consumer is to deploy consumer-created or acquired applications created using programming languages, libraries, services, and tools supported by the provider onto the cloud infrastructure. The consumer does not manage or control the underlying cloud infrastructure including the network, servers, operating systems, or storage, but has control over the deployed applications and possibly configuration settings for the application-hosting environment.

Software as a Service (SaaS)

The capability provided to the consumer is to use the provider’s applications running on a cloud infrastructure. The applications are accessible from various client devices through either a thin client interface, such as a web browser (e.g., web-based email), or a program interface. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings.

${section2-title4}

${section2-content4}

${section2-title5}

${section2-content5}

${section2-title6}

${section2-content6}

${section2-title7}

${section2-content7}

${section2-title8}

${section2-content8}

${section2-title9}

${section2-content9}

${section2-title10}

${section2-content10}

Deployment Models


Private cloud

The cloud infrastructure is provisioned for exclusive use by a single organization comprising multiple consumers (e.g., business units). It may be owned, managed, and operated by the organization, a third party, or some combination of them, and it may exist on or off premises.

Community cloud

The cloud infrastructure is provisioned for exclusive use by a specific community of consumers from organizations that have shared concerns (e.g., mission, security requirements, policy, and compliance considerations). It may be owned, managed, and operated by one or more of the organizations in the community, a third party, or some combination of them, and it may exist on or off premises.

Public cloud

The cloud infrastructure is provisioned for open use by the general public. It may be owned, managed, and operated by a business, academic, or government organization, or some combination of them. It exists on the premises of the cloud provider.

Hybrid cloud

The cloud infrastructure is a composition of two or more distinct cloud infrastructures (private, community, or public) that remain unique entities, but are bound together by standardized or proprietary technology that enables data and application portability (e.g., cloud bursting for load balancing between clouds).

${section3-title5}

${section3-content5}

${section3-title6}

${section3-content6}

${section3-title7}

${section3-content7}

${section3-title8}

${section3-content8}

${section3-title9}

${section3-content9}

${section3-title10}

${section3-content10}

${title-section4}


${section4-title1}

${section4-content1}

${section4-title2}

${section4-content2}

${section4-title3}

${section4-content3}

${section4-title4}

${section4-content4}

${section4-title5}

${section4-content5}

${section4-title6}

${section4-content6}

${section4-title7}

${section4-content7}

${section4-title8}

${section4-content8}

${section4-title9}

${section4-content9}

${section4-title10}

${section4-content10}

${title-section5}


${section5-title1}

${section5-content1}

${section5-title2}

${section5-content2}

${section5-title3}

${section5-content3}

${section5-title4}

${section5-content4}

${section5-title5}

${section5-content5}

${section5-title6}

${section5-content6}

${section5-title7}

${section5-content7}

${section5-title8}

${section5-content8}

${section5-title9}

${section5-content9}

${section5-title10}

${section5-content10}




Applicability of the circular

An outsourcing will be considered as IT outsourcing based on a cloud computing infrastructure if all of the following criteria are met:
1-5. All of the five essential characteristics of cloud defined above are satisfied
6. Apart from exceptional cases, the external service provider’s staff have no access to the data and the systems of their customers, unless the customers consent to access and the service provider provides monitoring mechanisms
7. The external service provider performs daily management of resources without manual interaction (i.e., an automated system provisions resources)
IT outsourcing arrangements satisfying all of these seven criteria will be subject to this circular rather than to Circular 05/178 as replaced by Circular 17/656, or to the sub-chapter 7.4 of Circular 12/552 as amended by Circular 17/655 (which remain applicable for other forms of IT outsourcing arrangements, as appropriate).





Roles foreseen in the circular

The circular foresees four roles:
RoleDescription
Supervised Entity Consuming cloud Resources (SECR or Consumer)• An entity supervised by CSSF which consumes cloud resources for the conduct of its activities
Signatory• The entity signing the contract with the Cloud Service Provider
Resources Operator• Natural or legal person using the client interface allowing to manage cloud resources
Cloud Service Provider• The Cloud Service Provider delivering the cloud solution in scope of this circular

In addition, the resources operator shall name a cloud officer among its employees who will be mainly responsible for (i) use of the cloud solutions, and (ii) guaranteeing the competencies of the staff managing cloud resources. Thus, the cloud officer shall be qualified and understand the issues related to IT outsourcing in the cloud. The cloud officer function can be assigned to a person having other functions in the IT department.
The circular foresees certain authorized splits of these four roles and creates opportunities for Support PSFs to play a role in the recourse to cloud solutions:


Click on image to enlarge




Requirements set forth in the circular

In addition to the above requirements related to roles, the circular sets forth requirements in the following domains; whereas most of the requirements consist in instantiating existing requirements on outsourcing in the context of cloud computing (i.e., in a detailed and prescriptive manner), the circular also introduces new requirements to address certain risks that are specific to cloud solutions.
Governance• The circular instantiates existing requirements on outsourcing in the context of cloud computing (e.g., compliance with the consumer’s formal outsourcing policy, clear documentation on respective roles and responsibilities, etc.), but also introduces a cloud officer (as seen above)
Customers consent and notification• The circular refers to legal requirements and thus paves the way for the changes foreseen concerning the obligation of professional secrecy (i.e. Bill of Law 7024)
• The consumer ensures whether it is necessary or not to inform its customers and to obtain their consent
• The consumer complies with data protection regulations
Prior authorization from or notification to the CSSF• Entities in scope of the circular shall engage with the CSSF where they plan to recourse to the cloud. The nature of the communications will depend on the materiality of the activities outsourced in the cloud:

o Cloud solutions supporting material activities require prior authorization
o Other cloud solutions require notification

• The termination of a cloud computing outsourcing needs to be notified to the CSSF
• Support PSFs authorized as IT systems and communication networks operators shall obtain the prior authorization of the CSSF to offer cloud services
Outsourcing risk management• The resource operator and its Cloud Officer need to ensure that the staff in charge of operating cloud resources, the internal audit, and the staff in charge of information security have been duly trained with training on cloud resources operations and security
• The circular instantiates existing requirements on outsourcing in the context of cloud computing (e.g., prior and in-depth risk analysis), but also draws attention to specific risks, such as geopolitical risks where the cloud service provider hosts its systems abroad
• The consumer shall formally document its compliance with the requirements set forth in the circular (the CSSF may ask for this documentation at any time)
Business continuity• The circular instantiates existing requirements on outsourcing in the context of cloud computing (e.g., continuity aspects and the revocable nature of outsourcing), but also draws attention to specific risks, such as data portability
Systems security• The confidentiality and integrity of data and systems must be controlled throughout the IT outsourcing chain (i.e., at the consumer, the resources operator, and the cloud service provider)
• The circular explicitly requires access to data and systems to comply with the “need to know” and “least privilege” principles
Contractual terms• The contract signed with the cloud service provider shall normally be governed by the law of a EU member state and shall normally plan for resilience of cloud services in the EU
• In the event of contract termination, the CSP undertakes to permanently delete the data and systems within a reasonable time frame
• The CSSF must have an unconditional right to audit the cloud service provider in the context of the services used by the consumer and resources operator under its supervision
Outsourcing oversight• The cloud service provider regularly provides relevant indicators (i.e., KPIs) to the signatory (and by extension to the consumer)
• Proper isolation of consumer’s systems and data must be regularly controlled by the cloud service provider
Right to audit• The signatory may obtain sufficient assurance on the cloud service provider’s compliance to its contractual obligations and suitable risk management practices through the in-depth review of the cloud service provider’s audit reports or certifications
• The signatory shall have the contractual right to request reasonable adaptations in the scope of these audit reports or certifications to fulfil their essential needs, and should retain the contractual right to perform direct audits





How can Deloitte help?

Disrupt. Transform. Repeat. That’s the new normal. Done right, cloud not only drives that reality—it can turn it into your advantage. Deloitte’s end-to-end capabilities and understanding of your business and industry help amplify the transformative value of cloud.
Our broad array of services include:
  • Compliance Assessment – gap analysis of our client’s cloud projects compliance against laws and regulations and pragmatic recommendations for improvement
  • Assisting in Communications with the Regulator – preparation (or quality assurance) of application files and participation in meetings with the regulator, e.g.:
- Notifications and authorization requests for financial professionals wishing to use cloud solutions
- Authorization requests for Support PSFs wishing to offer cloud solutions
- Gap analysis of CSSF requirements for cloud service providers wishing to expand in the Luxembourg financial sector
  • Cloud Strategy and Readiness – your journey into the cloud must navigate pitfalls and opportunities that are unique to your business alone. That makes mapping out a clear strategy and preparing your organization essential to achieving your business goals
  • Cloud Package Implementation – multiple SaaS solutions exist on the market for every common business process. Each solution has its strengths and weaknesses, its best uses and fits. Knowing what those are and how they will affect your business is critical for success
  • Custom Migration Consulting Services – a simple “lift-and-shift” approach to moving your applications to the cloud often bypasses the key benefits associated with the cloud—cost savings, scalability, increased speed, and flexibility
  • IT Operating Model with Cloud – as the workload shifts to new and more business-aligned tasks, IT needs to adjust to a new reality. Governance, service delivery, integration architecture, supplier management, and service measurement are among the areas that require recalibration




 

Saturday, May 20, 2017

Cryptocurrency miner Adylkuzz attack could be bigger than WannaCry

Cryptocurrency miner Adylkuzz attack could be bigger than WannaCry

Cryptocurrency
Cryptocurrency
The attackers behind WanaCrypt0r/WannaCry were not the only cybercriminals putting DoublePulsar and EternalBlue to use this weekend, as Proofpoint spotted the stolen NSA tools being used with the cryptocurrency miner Adylkuzz.
The Adylkuzz attack may not only have been larger than WannaCry, but could have been one of the mitigating factors that helped shut down that ransomware attack, wrote a Proofpoint security researcher who goes by the alias Kafeine. The mining campaign was after the cryptocurrency Monero.
“Initial statistics suggest that this attack may be larger in scale than WannaCry, affecting hundreds of thousands of PCs and servers worldwide: because this attack shuts down SMB networking to prevent further infections with other malware (including the WannaCry worm) via that same vulnerability, it may have in fact limited the spread of last week's WannaCry infection,” he said.
The Adylkuzz campaign began sometime between April 24 and May 2. Because it started before WanaCryptor hit on May 12, Kafeine thinks some companies mistakenly believed they were being victimized by the ransomware when in fact it was Adylkuzz.
Some of the clues that a system is under attack by this malware include loss of access to shared Windows resources and slower PC and server performance. Like WannaCry, Adylkuzz takes advantage of Windows vulnerability MS17-010 on TCP port 445, Kafeine reported. The attack itself originates from several private servers that are scanning on port 445 for victims.
Once EternalBlue finds a target computer it installs the DoublePulsar backdoor which then injects Adylkuzz.
Proofpoint came across this attack when it was searching for WannaCry by setting up a computer vulnerable to EternalBlue.
“While we expected to see WannaCry, the lab machine was actually infected with an unexpected and less noisy guest: the cryptocurrency miner Adylkuzz. We repeated the operation several times with the same result: within 20 minutes of exposing a vulnerable machine to the open web, it was enrolled in an Adylkuzz mining botnet,” he wrote.
Proofpoint was able to find several web addresses that received Monero deposits starting on April 24. About $43,000 in Monero was tracked being deposited.

https://www.scmagazine.com/cryptocurrency-miner-adylkuzz-attack-could-be-bigger-than-wannacry/article/662128/