Sunday, October 26, 2014

I wanted to look more into what is known as the Octave Method as this was not the focus of my discussion board post, however, it did intrigue me.  “The original Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) Method was developed with large organizations in mind (300 employees or more), but size is not the only consideration” (CERT.org).  What OCTAVE does is allow an a company’s InfoSec department to evaluate and deal with risk in a way that allows it to balance the necessity to protect critical assets/data with the costs that it takes to do so. 
There are two other forms of OCTAVE, OCTAVE-S, which is intended for smaller organizations (about 100 users) and OCTAVE-Allegro, which can be described as a streamlined approach for InfoSec assessment and assurance (Whitman & Mattord, 2013). 

The OCTAVE Method is known to work in three phases:
·         Phase 1: Build Asset-Based Threat Profiles
·         Phase 2: Identify Infrastructure Vulnerabilities
·         Phase 3: Develop Security Strategy and Plans

Again according to CERT.org, The OCTAVE method utilizes the knowledge of risks from multiple levels within the organization and focuses on identifying critical assets and the threats that endanger them.  By identifying the vulnerabilities the organization develops protection strategies and risk mitigation plans to assist the organization's mission and priorities.  Please see the link below for further information regarding the OCTAVE Method as well as the training sessions that are offered by the Carnegie Mellon University and Software Engineers Institute.

Link:
http://www.cert.org/resilience/products-services/octave/octave-method.cfm? 

References:
Whitman, Michael E.; Mattord, Herbert J. (2013-10-07). Management of Information Security (Page 332). Cengage Learning. Kindle Edition.
http://www.cert.org/resilience/products-services/octave/octave-method.cfm?  

Thursday, October 16, 2014

Sun Tzu and the Connection to InfoSec

In my research efforts for this weeks discussion question I stumbled across quite an interesting post about Sun Tzu and its relation to the InfoSec world.  The author of the post discusses several of Tzu's quotes, which are hundreds of years old, and how they can be applied to today's technical world.  This was posted to The Security Pub by a fellow InfoSec blogger.

For example, the author made the following connection between a Tzu quote and today's cyber wars.  For more, see the link below.

Quote: Knowledge of the enemy’s disposition can only be obtained from other men. Knowledge of the spirit world is to be obtained by the divination; information in natural science may be sought by inductive reasoning; the laws of the universe can be verified by mathematical calculations; but the dispositions of the enemy are ascertainable through spies and spies alone.
My Thoughts: The cyber equivalent of spies is covert malware like Trojans and rootkits. The popularity of this type of code in spam attachments and on infected websiSun Tzu quotes from The Art of War

http://www.thesecuritypub.com/2013/10/29/sun-tzu-quotes-from-the-art-of-war-compared-to-information-security/

Sunday, October 12, 2014

I found a great video that describes the differences between Mandatory Access Control (MAC), Discretionary Access Control (DAC) and Rule/Roll-Based Access Control (RBAC).  Our text did not cover RBAC too extensively so I thought it was good information for that reason alone.

RBAC is similar to DAC in the sense that it is at the discretion of the IT department or manager chooses the access level for individual employees based on their role or company rules about the amount of information that are authorized to see/manipulate.

The video is a bit rudimentary since the presenter uses paint or a similar tool to hand write out the each items discussed but the content and explanations of each are spot on.  He even discusses the differences between each of the items.

Here is the video...

https://www.youtube.com/watch?v=kGpAdbBudOU

Sunday, October 5, 2014

I came across a very interesting article from the SANS Institute that provides so very insightful information about security awareness training.  There are some statistics, aspects of training, and other resources and links that can assist  companies looking to maybe roll out a new security awareness training program.

http://www.sans.org/reading-room/whitepapers/awareness/importance-security-awareness-training-33013

Saturday, September 27, 2014

Being that this week revolved around the development and implementation of information security policies, I came across an article earlier this week that helped me develop my issue-specific policy.  This article offers some useful advice and direction that can be taken into consideration when developing an information security policy for a business of almost any kind and size.  The first statement in the article is a powerful message that must be taken into serious consideration by any policy maker, "A security policy is the foundation of a secure network, but it must also balance security with business needs" (Information Week, 2014).  

If you are interested, copy and paste the following link into a web browser.

http://www.networkcomputing.com/secure-networks-how-to-develop-an-information-security-policy/a/d-id/1234642? 

Saturday, September 13, 2014

More Data Breach Information

I guess I was a little bit ahead of the curve last week with my post regarding data breaches as this was the main focus for this weeks readings and assignments.  I have found another interesting article during my research this week that discusses the top six data breach trends for 2014.  There are a few interesting hypotheses about upcoming data breach trends and events.  One of the more startling quotes from the article points out that the prevalence or data breaches has reached a level that it is almost expected.  "“The best advice that we give everybody is to have an incident response plan in place because it’s really not a question of if you’re going to have a data breach, but when will it occur,” (Griffin, 2014).

http://www.securityinfowatch.com/article/11292323/experian-data-breach-resolution-forecasts-data-breach-trends-to-watch-in-2014 

Friday, September 5, 2014

Data Breach Information

In the recent wake of the latest data breach that occurred at Home Depot, I decided to look into some of the statistics that are out there regarding these events.  I found some very shocking and interesting data at the link below which was posted on IBM's site.

Visit this article: http://www-935.ibm.com/services/us/en/it-services/security-services/data-breach/

The first stat that pops out right at the time is that in 2013 there were 1.5 million cyber attacks in the U.S. alone!  That is incredible.  There are links to some reports that provide further information about different aspects of security and information security. Some of these, however, require a fee which I was not willing to look into.

One of the study's that was available at the site revealed the following findings: