Sunday, April 26, 2015

Six must-have features when storing data in the cloud


Six must-have features when storing data in the cloud

By /    

Cloud storage prices are flirting with free, and capacity limits are on the rise. Just this past March, Google announced its Cloud Storage Nearline service that costs a penny a month for 1GB of storage. Service providers are dropping prices mainly because they can; technology advances – particularly for data that doesn’t need to be accessed often or quickly – has significantly increased storage efficiency, making it possible for providers to offer next-to-nothing prices. But if enterprises are going to take public cloud storage services seriously, they’ll need more than vast bins of low-priced storage to make it work.
“I think the biggest misperception we get when we talk to customers about cloud storage in particular is they view it as complete outsourcing,” said Henry Baltazar, senior analyst serving infrastructure and operation professionals with Forrester, in a webinar. “They think of it as `Okay, if I pull out my credit card, my problems are going to go away.’ And there’s really nothing farther from the truth. You still have a lot of things you have to care about.”
As such, many cloud service providers are offering value-add features, while add-on products such as cloud storage gateways, file sync and share, and hybrid backup are also becoming popular. These are the kinds of features and functions that differentiate one cloud from another. And enterprises should carefully evaluate them when making their decisions. Among the most important considerations are:
Security – Managed users access, authentication, and encryption are essential to protecting data regardless of where it’s stored; this is especially true when moving data outside the confines of the corporate data center. Reporting features for compliance are also necessary.
Redundancy – Having data stored at different geographical locations for redundancy just makes good sense, even if that means a hybrid approach where data is stored in the data center and backed up in the cloud.
Disaster recovery – Essential in case of natural, machine, or human-driven events. Enterprises can adjust these features based on their tolerance for downtime and data loss. If that tolerance is close to zero – for, say, financial services firms that execute trades for clients – those companies must be prepared to pay for advanced capabilities.
Collaboration tools – Employees and partners need fast, simple access to files. Tools that let them drag and drop files in folders, share files with simple links, and manage access to files keep them productive.
Administrative tools – For enterprises to maintain control over their data, they’ll want to be able to do things like manage permissions, set policies, and establish expiration dates for files.
Mobile access – With the explosion of mobility in the enterprise, providing fast, secure access to cloud-based storage from a variety of devices is essential.

Friday, April 24, 2015

High-profile data breaches made most CEOs re-exam security programs



Posted on 24 April 2015.
There has been increased board- and C-level interest in information security programs in light of recent high-profile data breaches such as those affecting Sony, Anthem and JP Morgan, the results of a Netskope survey have revealed.

As the severity and consequences of data breaches intensify, Netskope surveyed a hundred information security professionals attending RSA Conference 2015 and found the majority of respondents’ board of directors and CEOs have taken active interest in understanding and improving their company’s security programs.

“As more information is disclosed and media follow every detail of mega breaches, there’s an incredible amount to learn,” said Sanjay Beri, co-founder and CEO, Netskope. “But for all the information available, we were curious to know if the impact of those breaches was enough for board members and CEOs to move the needle in the boardroom. I’m encouraged knowing that recent high-profile data breaches have incited conversations between board-level decision-makers and security teams, and action is being taken to prevent similar breaches.”

The survey – which provides a snapshot of how security decisions are currently being made – offered up these conclusions:

Elevated executive interest
In light of recent data breaches, Netskope found 13.6 percent of cloud app users currently use compromised account credentials at work. The impact of breaches often linger beyond the immediate attack, and executives are increasingly looking to mitigate that risk. The survey revealed that 69 percent of respondents’ CEOs or boards of directors have asked their security teams about specific security policies in the wake of recent high-profile breaches.

All technology up for discussion
Of those 69 percent of respondents, 28 percent of boards and CEOs have asked specifically about security of Cloud or Software as a Service (SaaS) technologies. 27 percent have asked about mobile device security and network security, demonstrating executives are not focused solely on one area of security, rather, they aim to gain a holistic understanding of security programs in general.

Walking the walk
Enterprises use an average of 730 cloud apps, however 90 percent of those apps are not enterprise-ready, according to the Netskope Cloud Confidence Index. As cloud app adoption continues to skyrocket, enterprises must have the visibility into the cloud technologies in use by their organizations. 65 percent of respondents report they have changed, or plan to change cloud-specific security methods since the Anthem security breach. More than half (52 percent) of respondents confirmed that cloud-specific security methods have changed as a direct result of CEO or board-level conversations.

Wednesday, April 22, 2015

The Key that Unlocks Esperanto

   

The Key that Unlocks Esperanto

Posted by on in Smart Encryption
     
As any student or traveler can attest, learning a new language is hard. How about making one up?
Esperanto will take over Lille, France this summer. Esperanto will be the backbone of discussions, debates and entertainment at this event in the north of France, a place quite prideful of its own language. The linguistic oddity that is Esperanto was one person’s vision in the 1880s of a unifying, global language. It has survived world wars, mistrust and the era of “OMG”. Unlike the languages bubbling out of “Star Wars” or “Lord of the Rings”, it’s not propelled by an entertainment component. Esperanto is also spoken by a relatively small number of folks.
b2ap3_thumbnail_Flag_of_Esperanto.svg.png
Can encryption key management learn something from the seldom spoken language of Esperanto? (Esperanto flag image courtesy of Wikipedia.)
I was drawn to reading up on Esperanto from my unabashedly nerdy love of code and programming languages. (The broad appeal of code has teachers pushing for students to “speak” in terms of hardware and software as a language education imperative.) In an industry plagued by made up norms and half-baked standardization, the security side of coding and programming shouldn’t lose sight of its intentions in creating a computerized parallel to Esperanto.
In encryption key management, a “language” I feel fairly fluent in, I fear that for many users we’ve replaced flow and communicative elements with a whole bunch of ways to swear and confuse. There is an inherent problem with mass, single instances in the security field when it comes to encryption keys. To get around that, we create multiple, obscured copies of keys to encrypt and decrypt information that needs to be secured. That is starting to add up to a lot of keys for some businesses – and a lot of stress. In looking at how businesses in the U.K. were handling the avalanche of keys, Techworld wrote: “once the bedrock of security, keys and certificates now elicit anxiety. This is perhaps not surprising given the growing number of attacks in which they have been compromised or undermined in a more general way by vulnerabilities such as last year’s Heartbleed. The average U.K. organization in the survey tended 25,500 keys and certificates, with 4 percent of IT staff saying they had no idea where all of this was kept.”
When a key becomes easy to use, it sometimes becomes too easy, opening up security gaps like those exposed recently with one RSA key. When it’s too hard you get things like a product we recently saw advertised that touted so many keys that it comes with a feature for a key manager manager. Or, more likely, end users and knowledge workers avoiding encryption whenever possible, including when it’s necessary.
As much as people fret and flaunt the encryption side of security, it’s the keys which make that function intelligent. Tilt the equation in either direction and you’ll nullify the reason your company is using encryption in the first place. Right now, we’re coming across a lot of businesses big and medium-sized going the route of the Key Management Interoperability Protocol, or KMIP. It’s not a perfect communications standard, but it at least allows for secured options within encryption practices. Languages that thrive tend to create new ways to share without removing the backbone of communication. How many slang terms do we use in mainstream discussions?
While subtle, our key management dialect could benefit from strengthening what works and easing on the standardization of faulty or abused methods. And you know what they say: you can’t encrypt in Esperanto. At least I think that’s what they say. My Esperanto is rusty.
Last modified on

Compliance officer awarded $1.5 million under SEC whistleblower program

Compliance officer awarded $1.5 million under SEC whistleblower program

The Securities and Exchange Commission announced an award Wednesday of about $1.5 million to a compliance professional who provided information for an enforcement action against the whistleblower’s company.
The award went to a compliance officer "who had a reasonable basis to believe that disclosure to the SEC was necessary to prevent imminent misconduct from causing substantial financial harm to the company or investors," the SEC said.
The whistleblower will receive between $1.4 million and $1.6 million, the agency said.
Wednesday's award is the second the SEC has made to an employee with internal audit or compliance responsibilities.
In September last year, the SEC awarded about $300,000 to a company audit and compliance employee who complained to the SEC after the company didn't act on the same information.
After that award, Sean McKessy, chief of the SEC’s whistleblower office, said employees who perform internal audit, compliance, and legal functions can be eligible for an SEC whistleblower award "if their companies fail to take appropriate, timely action on information they first reported internally.”
Whistleblower awards can range from 10 percent to 30 percent of the money collected in a successful enforcement action with penalties of more than a $1 million.
By law, the SEC has to protect the confidentiality of whistleblowers and can't disclose information that might directly or indirectly reveal their identities.
Since the launch of its whistleblower award program in 2011, the SEC has paid more than $50 million to 16 whistleblowers who provided "unique and useful information that contributed to a successful enforcement action."
Andrew Ceresney, chief of the SEC’s enforcement division, said in a statement Wednesday: “This compliance officer reported misconduct after responsible management at the entity became aware of potentially impending harm to investors and failed to take steps to prevent it.”
*     *     *
The SEC's redacted Order Determining Whistleblower Award Claim (Securities Exchange Act of 1934 Release No. 74781 and Whistleblower Award Proceeding File No. 2015-2) dated April 22, 2015 is here (pdf).
________
Richard L. Cassin is the publisher and editor of the FCPA Blog. He can be contacted here.
- See more at: http://www.fcpablog.com/blog/2015/4/22/compliance-officer-awarded-15-million-under-sec-whistleblowe.html#sthash.dMXHchRM.dpuf

Tuesday, April 21, 2015

PCI DSS Version 3.1 - What's New?


PCI DSS Version 3.1 - What's New?

Troy Leach of PCI Council Explains New Version of Standard

By , April 17, 2015.
  
Troy Leach, PCI Security Standards Council
Troy Leach, PCI Security Standards Council

Listen Now

00:00
00:00
00:11
The PCI Security Standards Council has just published a new version of the Payment Card Industry Data Security Standard that calls for ending the use of the outdated Secure Sockets Layer encryption protocol that can put payment data at risk. What must security leaders know about PCI 3.1 and its supporting guidance? Troy Leach of the PCI Council offers insights.

The reality about PCI version 3.1? It primarily boils down to removing one cryptography example three times from the published standard. But that small step indeed signals a giant leap forward in payment card security.

The new guidance removes the Secure Socket Layer encryption protocol, and early versions of Transport Layer Security, as examples of strong cryptography, and calls for use of a current, secure version of TLS.
It's unusual for the PCI Council to issue a mid-year update, but this one is critical, Leach says.
"We recognize that since the last time we published our standard in November of 2013, NIST and other subject matter experts have come out and said that the [SSL] protocol itself has been deprecated," Leach says. "So, we recognized that there was a need to move away from that example."
The PCI Council is giving covered entities until June of 2016 to complete the migration, and Leach encourages these organizations to start their risk assessment process now.
"We're asking the community to have the due diligence to do proper risk management of the situation, make an assessment of whether they are at risk, and then make their strategy progressive, so that they identify the top risks first, eliminate those, and then move forward," Leach says.
In an exclusive interview about PCI DSS 3.1, Leach discusses:


Leach also will be discussing PCI DSS version 3.1 at RSA Conference 2015 in San Francisco.
In his role as CTO and lead security standards architect for the PCI Council, Leach has developed and implemented a comprehensive quality assurance program. Before joining the council, he led the incident response program at American Express, where he reviewed more than 300 cases of account data compromises. Over the past 18 years, he has held positions in systems administration, network engineering, IT management, security assessment and forensic analytics.
Follow Tom Field on Twitter: @SecurityEditor

Monday, April 20, 2015

Target, MasterCard Settle Over Breach

Target, MasterCard Settle Over Breach

Retailer Offers Issuers a Total of Up to $19 Million

By , April 16, 2015.                                                               
Target, MasterCard Settle Over Breach          
 

Target has agreed to pay a total of up to $19 million to issuers of MasterCard payment cards over losses and expenses they incurred as a result of the retailer's massive 2013 breach.
See Also: Breaking Down Ease-of-Use Barriers to Log Data Analysis for Security
The settlement announced April 15 is contingent on issuers of at least 90 percent of the eligible MasterCard accounts accepting their offers by May 20. If sufficient issuers accept the offer, Target says they'll be paid by the end of June.
   
"This settlement provides our issuers a reasonable resolution of the Target data breach event," says Eileen Simon, MasterCard chief franchise integrity officer. "The timely reimbursement of costs and losses under the agreement delivers MasterCard issuers a faster and more certain resolution to the event, while reinforcing our commitment to maintain the integrity of industry security standards."
MasterCard, in a statement, says issuers that choose not to accept this offer will have their claims determined by MasterCard internal processes and may receive more or less than the amounts offered in this settlement, depending on various factors. Those include MasterCard's final determinations of their claims and the outcome of any litigation that Target might file to challenge claim awards to issuers outside of this settlement.
Target also is in negotiations with Visa for a breach-related settlement. "Visa takes very seriously our responsibility to work closely with its acquiring clients and Target to resolve this event," Visa spokesman Jake Standish says. "Visa continues to analyze all relevant information to ensure we reach a resolution that is accurate and fair to all Visa clients and participants in the payments system and we are committed to addressing and resolving this case expeditiously."

Reaction to Settlement

William Murray, an information security and technology consultant, says everyone benefits from the MasterCard settlement, even consumers. "The cost to Target is much less than that of extended litigation," he says, adding that the length for the two sides to reach a settlement seems reasonable. "I am pleasantly surprised at how quickly it has been done," he says. "Just clarifying the issues is time consuming. Arriving at an agreement in this time demonstrates good will on the part of all parties."
But Jim Nussle, chief executive of the Credit Union National Association, contends the settlement took too long. "It is about time that Target steps up to its responsibilities in this breach," Nussle says. "And it is long overdue for merchants to start living up to their responsibilities in protecting customers' sensitive information by adopting higher security standards."
Dan Berger, chief executive of the National Association of Federal Credit Unions, says the size of the MasterCard settlement was disappointing. "While we appreciate that the settlement attempts to hold Target somewhat accountable, we were hoping it would be more than just pennies on the dollar," Berger says. "We believe that this demonstrates the reason why Congress must act to protect consumers' financial information by enacting stronger standards and holding retailers and merchants directly accountable for their data breaches."
As Target and MasterCard announced their settlement, the House Energy and Commerce Committee passed a data breach notification and security bill that calls on companies to take "reasonable security measures and practices" to secure the personally identifiable information of customers (see National Data Breach Notification Bill Advances).
Target says the 2013 breach compromised at least 40 million payment cards and might have caused the pilfering of personal information from as many as 110 million people. The retailer has reported that its breach costs have totaled at least $252 million so far, with $90 million covered by insurance.
The retailer last month announced a pending $10 million settlement of a consumer lawsuit. Target and MasterCard did not immediately respond to requests for further comment.
Follow Eric Chabrow on Twitter: @GovInfoSecurity

Sunday, April 19, 2015

CMS Administrator: ‘We Need to Adjust and Make Things Easier’


CMS Administrator: ‘We Need to Adjust and Make Things Easier’

APR 17, 2015
      
We’ve only scratched the service on using technology to improve care, access and quality, the acting administrator of the Centers for Medicare and Medicaid Services said Thursday at HIMSS15, and to continue along that path three main actions need to be accomplished.
Speaking in Chicago at the annual conference, Andy Slavitt also called for names of organizations setting up barriers to interoperability. He said care providers and patients should feel all of the investments made in technology, what he called a care dividend. “The taxpayer has invested billions…We have stages and rules and measures,” he said. “What matters is can technology produce more time and capacity for care providers to improve care to patients.”
Also See: Data Blocking Hampers Interoperability, ONC Says
“We have a great need for modern infrastructure with healthcare,” Slavitt added as the second action point. “For health care to be truly as great as we deserve, it needs far better infrastructure in critical places.”
He said the healthcare system needs to adapt and learn using technology. “We can do with a little less innovation in shareables and wearables,” he said to applause, “and more focus on opportunities to improve healthcare infrastructure.”
The final point, Slavitt told attendees, is one of the greatest concerns—interoperability. He recalled a visit earlier this week to a qualified healthcare center with some of the greatest electronic medical records and quality control in the country. Yet, physicians couldn’t follow patients who left to go to a specialist. It is “not acceptable for taxpayers, it is not acceptable to us,” he said. “I’m asking a great deal more of [the] innovation system. It’s time to get down to business and advance the gains of the last five years.” In return, Slavitt said the government will get better at listening and adapting and being a “more solution oriented partner.”
“As you implement, we need to adjust and make things easier for you,” he added, and pledged for CMS to be clearer in its goals and expectations so “you know where to invest based on how we will reimburse.”
Naming Names
Slavitt said CMS wants to know of every example, small and large, when someone willfully or in some way sets up barriers to interoperability. “We want to know about them,” he said. “I’d like to know about them and I’d like to have conversations with people participating in that and understand what is going on.”
It is not so much a matter of technology as it is a matter of commitment, he added. “I want to make sure we are happy as a team and it is a public service to hear about the issues and confront them.”
Slavitt concluded that the industry is moving to a level where as you walk the halls of a clinic people are feeling improvements being made and he looked to the HIMSS audience to help. “It is going to be this group of folks and companies you represent and how well you work together,” he said. “We have momentum, but I fear if we don’t get urgent about it, it won’t happen quickly enough