Showing posts with label masters. Show all posts
Showing posts with label masters. Show all posts

Monday, May 25, 2015

Security Systems Development Life Cycle (SecSDLC)



Security Systems Development Life Cycle

When designing information systems there are logical phases which must be considered in order to achieve maximum efficiency and effectiveness throughout the organization in every role. Throughout the six phases of the systems development life cycle (SDLC) it becomes imperative to ensure that security is integrated with each aspect of the platform. When building a security project, the same phases of the SDLC can be adapted to suite. The security systems development life cycle (SecSDLC) shares similarities with the SDLC, however the intent and activities are different. The purpose of this paper is to review and explain the phases of the SecSDLC, discussing the differences between the SDLC, and applicable certifications.

Investigation

In this phase, the project scope and goals are defined upper management. They provide the process methodologies, expected outcomes, project goals, the budget, and any other relevant constraints. “Frequently, this phase begins with an enterprise information security policy (EISP), which outlines the implementation of a security program within the organization.” (Whitman & Mattord, 2012, p. 26). Teams are organized, problems analyzed, and any additions to scope are defined, discussed, and integrated into the plan. The final stage is a feasibility study to determine if corporate resources are available to support the endeavor. The primary difference from the traditional SDLC is that management defines the project details. In the SDLC the business problems to be solved are researched and developed by the project team.

Analysis

In this phase, the documents gathers in phase one are studied and a preliminary analysis of the existing security polices is conducted. At the same time, the current threat landscape is evaluated and documented, as are the controls in place to manage or mitigate these threats. Included at this stage is a review of legal considerations that must be integrated into the security plan. The modern global threat landscape is such that any business, small or large, is susceptible to attack from a third party, whether it be directly or indirectly. Certain industries have strict requirements on how data is to be stored, shared, or manipulated. Standards such as HIPPA, NIST, PCI-DSS, the ISO27001 standard, and others provide guidelines for an organization to be certified as complaint with established processes and methods. Some industries require these certifications in order for a company to conduct business in that sector. Understanding state legislations with regards to what computer activities are deemed illegal is vital to the overall plan execution and sets the baseline for the types of security technologies that can be implemented across the enterprise. The risk assessment in this phase identifies, assesses, and evaluates the threats to the organization’s security and data. The final step in this phase is to document the findings and update the feasibility analysis. The main differences between the SDLC at this phase include the examination of legal issues, relevant standards based on the segment within which the company is situated, the completion of a formal risk analysis, and the review of the threat landscape and their underlying controls. Those aspects are specifically unique to the SecSDLC. While considering security within every phase of the SDLC is vital, the focus and scope of security considerations are vastly different compared to the SecSDLC which focuses solely on the security aspect of an information systems.

Logical Design

With the SecSDLC, this phase creates and develops the blueprints for information security across the enterprise. Key policies are examined and implemented, and an incident response plan is generated to ensure business continuity, define what steps are taken when an attack occurs, and what is done to recover from a disastrous event. Similar to the SDLC, applications, data support, and structures are selected considering multiple solutions in an approach to managing threats. Unique to the SecSDLC is the detail involved with securing the SDLC core concepts by analyzing the system security environment, functional security requirements, assurance that the security system developed will perform as expected, cost considerations with regards to hardware, software, personnel, and training, documentation of security controls that are planned or in place, security control development, use case tests and test evaluation methods. The concepts and best practices detailed by the NIST can be seen as a guide throughout this phase with regards to system hardening and expected security measures to be taken to ensure end-to-end security across the enterprise. Project documents are again updated, and as with previous phases, the feasibility study is revisited to determine whether or not to continue the project, and/or whether or not to outsource the project.

Physical Design

The fourth phase of the SecSDLC evaluates the information security technologies needed to support the created blueprint and generate alternative solutions, which dictate the final system design. Technologies evaluated in the logical design phase are the best are selected to support the solutions developed, whether they are custom built or off-the-shelf. A key component to this phase is developing a formal definition of what “success” means for the project implementation to be measured against. The design of physical security measures to support the proposed system are also included at this phase. Project documents are updated, refined, and a feasibility study is conducted to ensure the organization is prepared for system implementation. The final stage of this phase involves the presentation of the design to sponsors and stakeholders for review and final approval. If regulations such as HIPPA and/or PCI-DSS must be adhered to, the physical design the infrastructure components must be modeled after their specific requirements with regards to the machines data is stored on, how these machines are physically accessed, and how the data stored on these machines is disseminated to authorized parties. This is unique to the SecSDLC. While data access control is a standard consideration of any information system, HIPPA, for example, provides specific requirements in order to maintain the privacy of patient records and ensure that their data is only shared with specific authorized personnel within the medical industry. PCI-DSS covers how customer credit card details and identifiable data is stored, used, and accessed within a company’s network.

Implementation

This phase is similar to that of the SDLC. Selected solutions are purchased or developed, tested, implemented, and tested again. A penetration test could be conducted to ensure that the security measures installed perform as expected and the network resources are protected from third party intrusion. Personnel issues are revaluated, training and education programs conducted, and finally the complete package is presented to upper management for final sign off. The SDLC differs in this phase in that the system developed is rolled out to users for their daily use. The SecSDLC is implemented on the back end by network administrators, as approved by upper management. Aside from accessibility issues that are repaired during testing, the user has no involvement in this phase of the SecSDLC.

Maintenance and Change

This is the most important phase of the SecSDLC because of the evolving threat landscape. Older threats evolve and mature into more dangerous threats, and new threats aim for new attack vectors against system weaknesses. Active and constant monitoring, testing, modification, update, and repair must be conducted on information security systems in order to keep pace with maturing and emerging threats. Zero-day threats pose a significant threat to organizations at the cutting edge of their industry and their security plan must be flexible enough to be able to proactively prevent these threats while also integrating methods of recovery should an attack occur through an unknown vulnerability. This phase is the most different from the SDLC in that the SDLC framework is not designed to anticipate a software attack that requires a degree of application reconstruction. “In information security, the battle for stable, reliable systems is a defensive one” (Whitman & Mattord, 2012, p.29). The constant effort to repair damage and restore data against unseen attackers is a never ending process. Part of this phase includes the perpetual education of all personnel as new threats emerge and the security model is updated because an educated user is a powerful security tool.

Conclusion

The purpose of the SecSDLC is to provide the framework for designing and implementing a secure information system paradigm. Since it is based off the SDLC it shares many similarities in the processes and methods used to develop a comprehensive plan, but the intent and activities are different at each phase. While considering systems security is considered vital to every phase of the SDLC, the SecSDLC focuses solely on the implementation of technologies designed to protect an infrastructure from third party intrusion, data corruption, and data theft. The SDLC develops the systems used within a business, while the SecSDLC develops the system to protect these systems and an organization’s users.



ReferencesWhitman, M.E., & Mattord, H.J. (2012). Principles of Information Security (4th ed.). Retrieved from The University of Phoenix eBook Collection.

Thursday, November 13, 2014

Digital Security Discussion

Topic of discussion in my Enterprise Models class tonight: Digital Security.  Something I touched on earlier this year.

Our text postulated: "Increasingly opening up their networks and applications to customers, partners, and suppliers using an ever more diverse set of computing devices and networks, businesses can benefit from deploying the latest advances in security technologies."

My Professor said: "My thoughts on this are opposite: by opening up your network, you are inviting trouble and the more trouble you invite in, the more your data will be at risk. I understand what they are hinting at, with a cloud based network, the latest security technologies are always available, therefore, in theory, your data is more secure. Everyone needs to keep in mind though, that for every security patch developed, there are ways around them."

He went on to mention how viruses could affect the cloud as a whole and that companies and individuals moving to cloud-based platforms will become the next target for cyber attacks as the model continues to thrive.

Which is all relevant, however I have a different perspective on digital security. My counter argument to that is user education is the key. I have debated this topic, security and system users, many times over the years. Like most of us in the industry information security is paramount. With the multiple terabytes of data we collect in our home systems, and even more in online interactions, keeping our data safe is really our last defense in privacy and security. As more companies and individuals implant their corporate and personal data upon cloud platforms there is an uneasy sense of comfort for many people, including some seasoned pros. Companies like Google and Microsoft whom both have highly successful cloud models across the board have taken responsibility for ensuring they have more than adequate digital and physical security in their data centers, which to an extent leaves it to assumption that the data and applications they warehouse and host are generally safe from intrusion. Users are the key to this whole ecosystem we have created. This is where user education becomes critical. As most seasoned techies know, in the beginning systems and system operations were highly technical in nature and only the most highly trained or technically creative individuals could initiate and manipulate computer systems. Viruses were something you caught from kids at school or coworkers, not a daily blitz of digital infections numbering in the hundreds of millions perpetually attacking in various forms. As systems got more complex in design but simpler in use the users technical ability level eventually became irrelevant. People ages 1 to 100, and even some very well trained animals, can all navigate systems and digital networks with very little effort. Our systems now do all the work for us, users simply need to provide basic instructions and gentle manipulations, instead of hard coding instruction sets and inventive on-the-fly program generation as was the status quo in the 70's, 80's, and 90's. This idle user perspective is the reason why criminal hackers are still traversing firewalls and breaking encryption algorithms, and they are growing in numbers as is evident by the number of new malware detections and infections quantified annually across all digital platforms and all continents. Educating users on general best practices for system use and maintenance, how to identify potential scams, how to detect spoofing and malformed websites, what to avoid when reading emails or reviewing search results, and which security software is functionally the best whether free or paid is critically important today more than it has ever been. The problem is that the industry has created the lazy user by essentially conveying that security is a given. Microsoft even made a concerted effort by including the Windows Firewall and Windows Defender as a part of its operating system by default so that there was some protection for their users out of the box. This was in response to a large number of users, whom had been infected by one or more viruses, that assumed they were protected because "it's from Microsoft, it has to be safe" which was further from the truth than they could understand. As an educated user that knows how to secure systems and networks, I take it upon myself to ensure that users appreciate they have to set a passwords when logging into various systems and services. I teach about the importance for digital security and how to be more security conscious with their every day interactions. I teach them how to correctly navigate Internet search results (avoiding "ads"), how to understand various security prompts and what they look like so they don't ignore them, what security solutions should be installed and how to identify them, etc. This improved knowledge has created a culture of awareness for my users both at work and at home. I am regularly consulted by my peers on how to secure their own families and how to explain it to their children. This creates a more intelligent user and thereby creates a more intelligent user community at large, making the Internet a bit more secure. All of that said, it only takes a single character missing from source code to give a programmer the ability to break the program and cause havoc, or a user inadvertently installing malware. Even the most seasoned users make these mistakes from time to time because we are all human, and as such we are fundamentally flawed, making no security solution 100% secure because they are developed and used by humans. Best you can do is make every effort to educate and secure, and hope no one targets you because if they want to get in bad enough, they will get in and you won't be able to stop them.

~Geek

Friday, August 22, 2014

Technology Roadmap - Wearables

Since I started working on my Masters in Information Systems, I have been learning a lot about many different aspects of IS.  Aside from it really helping me focus my perspective on what I want to end up researching for my post-grad work, I really have been enjoying all that I am learning, and this recent class (as of this post) is no exception.

The last paper I did in this class, CGMT557 Emerging Technologies & Issues, was to create a technology roadmap for an emerging technology.  While it is something I blogged on about a month ago, I chose wearables to extend the concept into a full plan.  Here's my 2 cents...~Geek


Technology Road Map: Wearables
Current State of Technology
            Wearables are extensions of our smart phones, tablets, and phablets offering a set amount of capabilities that are inferior to our smart devices but highly functional as they are currently designed.  With innovations through miniaturization and improved power efficiencies, curved glass high resolution screens, products like the various takes on the computerized watch accessory, Samsung Gear Fit bracelet accessory and other exercise monitors, Google Glass wearable computers, various applications of systems embedded into clothing for various purposes (muscular development, health monitoring, etc.), biological chips that hold medical conditions and history details embedded under the skin, are all wearable technologies that are already changing how a lot of services are being delivered.  Through improving miniaturization processes and improved manufacturing capabilities through more precision automation systems these wearable technologies will cause market disruption for various products that currently dominate the technology market such as laptop computers and other larger portable computing devices.
Business Initiatives and Drivers & Technology Landscape
            As the mobile workforce continues to expand through thinner and lighter computing devices with more available connections to high-speed access points, many businesses are able to follow their normal workflows without being physically tethered to their offices.  Currently there is a suite of devices that enable the mobile workforce, including smartphones, tablets, and laptop computers.  Their integrated devices, security feature sets, and in some instances rugged designs, lend themselves to providing a highly portable and productive work platform available from any location with a data connection.  As a sales person in a world of light speed communications and instant gratification, being able to access critical customer and product metrics with a couple taps of a fingertip are the difference between generating and landing opportunities versus potentially losing them completely.  Combined with back office line-of-business applications linked through the Internet, the mobile workforce is able to efficiently and effectively conduct business without geographic limitation.  Wearable technologies aim to revolutionize how business is conducting allowing for more efficient multitasking through wearable communication devices, powerful wearable computers, biological microprocessors that can use near field communications to interact with the environment and connect to wireless Internet devices to retrieve data from corporate data warehouses that then use the wearable computers to process and display said information for use and/or sharing.  Nanotech devices that can enable video and audio communications through cybernetic-like implants beaming high quality, high definition signals directly into the users sensory receptors providing for an immersive experience that functions at the speed of thought.  These same nanotech devices, once outfitted with artificial intelligence logic and processing, would become the next generation of executive or administrative assistant, able to recognize trends in a user’s usage patterns to help to anticipate potential reactions to situations and provide guidance on how to successfully navigate the landscape while providing useful data streams of relevant information enabling an intelligent and informed decision process.  When a worker is presented with all the relevant data pertaining to a situation and is able to perceive all the potential outcomes of reactions to interactions, with the assistance of intelligent nanotechnologies, they are able to make the best choice for a given situation resulting in improved satisfaction, a higher probability of positive outcomes, and in turn increased revenues. 

Gap Analysis & Migration Strategy
            In order for wearable technologies to successfully transition into the enterprise on a wide-spread basis, there are a few key gaps that need to be addressed as this emerging technology evolves.  The first gap to be addressed is the technologies themselves, as a majority of these capabilities are either in their early stages of development or are only partially implemented.  As mentioned, wearable technologies are currently used as accessories for their larger host devices integrating key functionality into said accessory, such as voice-to-text/text-to-voice capabilities, capturing of health data for monitoring purposes, both capable without the use of large or complex devices that may or may not be portable themselves.  In order for wearable devices to successfully evolve into independent computing systems, circuit, transistor, and storage technologies must continue to miniaturize to nano-scale form factors.  With the recent developments of carbon nanotubes and memristors these microscopic form factors are becoming reality.  There is a group out of Australia that has successfully created a nano-transistor that is a single phosphorus atom, whose atomic radii is 0.098 nanometers.  This is a direct step into nano-transistors that, once the research is complete, will result in sub-nano scale computing methods, and is should lead to quantum computing.  This would establish the foundation for very powerful systems that could be easily embedded into biological hosts to enable the advanced collaboration and communication methods necessary to conduct business in the next generation. The next gap to analyze would be embedding these systems into biological hosts, taking advantage of the bioelectricity generated to maintain continuous power states as well as neurologically connecting said bio-hosts to these nano systems to provide cohesive functionality that does not impede either entity.  Currently no solutions exist, however neural and material sciences have made advances creating technologies that can mimic such environments, and thus lead to an understanding on how to interface with them directly through biological and chemical processes.
Governance
            The Federal Communications Commission (n.d.) website states that they regulate interstate and international communications by radio, television, wire, satellite and cable in all 50 states, the District of Columbia and U.S. territories.  They are the primary authority for communications law, regulation and technological innovation.  As such, they would be responsible for mandating policy on how to manage the integration of nano devices into mainstream use and where their use is inappropriate.  As the industry evolves and technologies continue to shrink, the FCC will be at the forefront of determining how and when the use of these technologies is ultimately appropriate for public integration once the core infrastructure is in place.  Currently, there are no specific laws dictating how or when these devices can be used, only that they cannot actively interfere with other electronics, and must receive interference from other electronics, such as is the standard mandate of all consumer electronics based on the stamp shown on each device approved by the FCC for use.
Conclusion
            There has been a shift happening the past couple decades that the author has been tracking along with some peers.  As technology advances and devices continue to shrink in size while increasing in power users are following suit by moving from clunky desktop systems, to laptops, to ultra-books, to tablets, smart phones, and now wearables.  With as capable as wearable computing is commercially available today, combined with the research being done in nanotechnology and artificial intelligence and cloud-based service offerings and vast storage facilities, the future of wearable computers is already well in hand, with more innovations coming as we begin to fully understand how to manipulate and integrate such technologies as nanotubes and nanowires to allow us to take computing capabilities down to microscopic levels.  The potential is nearly limitless, with the ability to theoretically build nanomachines that are self-sufficient, self-reliant, and highly aware.  Wearable microprocessors that are embedded in a person’s skin could be the hub that enables personal interactions with our various devices and daily system interactions, also medical facilities, civil and government facilities, as well as large scale advertisements to provide a highly customized and personal experience not previously capable.  There are privacy and security considerations to be understood, which will require that regulations be put into place to protect the providers of these devices as much as it protects the users of wearable devices.  Those can only be realized as these technologies continue to be developed and infiltrate the professional realm.


References
98 Pm in nm. (2014). Retrieved from http://tejji.com/convert/length-metric.aspx?q=98-Pm-in-nm
Anthony, S. (2013). Killing silicon: Inside IBM’s carbon nanotube computer chip lab. Retrieved from http://www.extremetech.com/extreme/147596-killing-silicon-inside-ibms-carbon-nanotube-computer-chip-lab
Federal Communication Commission. (n.d.). What We Do. Retrieved from http://www.fcc.gov/what-we-do
University of Phoenix. (2014). Week three supporting activity: effect of emerging technologies on services. Retrieved from University of Phoenix, CMGT557 - Emerging Technologies and Issues website.
Size of phosphorus in several environments. (n.d.). Retrieved from http://www.webelements.com/phosphorus/atom_sizes.html
Smith, D. (2012). Nano-transistor breakthrough to offer billion times faster computer. Retrieved from http://www.smh.com.au/technology/sci-tech/nanotransistor-breakthrough-to-offer-billion-times-faster-computer-20120221-1thqk.html

Monday, June 16, 2014

Market Segmentation - A Geek's Perspective

So one of the "Applications" sections of one of my chapter readings this week about market segmentation, coupled with a conversation I had earlier today with a great friend, spawned this blob of words.

Is the World Coming Closer Together? Many social commentators maintain that youth and teens are becoming more alike across countries over time. Others, although not disputing the fact, point out that differences between cultures at even younger ages by far exceed the similarities.

Take a position: People are becoming more and more similar, versus, The differences between people of different cultures far outweigh their similarities.

My reply:
Learning about segmentation was interesting this week. What it made me think about is how different everyone's tastes are, but also similar the world has become from where it has been. There was a question at the end of one of the chapters that asked that exactly. "Take a position: People are becoming more and more  similar versus The differences between people of different cultures far outweigh their similarities." I think our world is in a transitional period where the older generations are being moved out of their positions of power and influence, and the next generation is moving in with different worldly perspectives. At the moment, Baby Boomers are in positions of power around the world, but the Gen X and Y groups are quickly climbing the corporate and political ranks as the Boomers start to retire younger and younger. Age is becoming a non issue for the most part in a lot of industries as skill sets become a commodity that only experience can make more attractive, but consumers seem to be preferring interactions with younger workers, which demonstrates a level of segmentation from the consumer perspective as the younger and more modern generations start to become consumers of luxury items as their disposable income increases also at younger ages. I asked a group of teenagers (13-15 year olds) the same question. They pretty much all agreed with my theory. They look to interact with service providers that they can better relate to, and communicate at higher and higher levels of technical expertise on modern conveniences, rather than someone who reminds them of their parents, grandparents, or great-grandparents whom constantly offer their displeasure of such interactions. Racial lines are being blurred to the point of nonexistence in the younger generations waiting for their chance to be in positions of power and influence so they can make their mark in the world and change its perspective. Good marketers are being more creative with establishing brand messages that span most age groups and demographic groups around the planet, channel guidelines are well established and generally followed, and the gray area of taboo marketing has a tendency to go viral with the technically affluent community regardless of their age. The Internet offers a platform that supports extreme freedoms of expression, open sharing of information, and has a connectivity factor that has more than 4+ billion users around the globe a few milliseconds (or less) from each other. As such, marketing campaigns that would not be seen as appropriate (taboo) for conventional marketing channels like TV and radio are finding their place online where segmentation does not technically exist. With as connected as everyone is today, it makes sense why every interaction with our devices and machines renders some ad for a product that specifically appeals to you and your friends. Marketers are good at what they do, and technology makes it a lot easier to shift marketing methods at the speed of progress.

What do you think? Am I on the right track or completely off base? ~Geek



Reference:
Kotler, P., & Keller, K. L. (2012). Marketing Management (14th ed.). Retrieved from http://www.coursesmart.com/SR/7147203/9780132103008/617?__hdv=6.8.