Top Banner
Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul . laurent @oracle.com http://delicious.com/paul.laurent
45

Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions [email protected]@oracle.com.

Dec 20, 2015

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Massachusetts Digital Government SummitNavigating Privacy and Security

Paul Laurent, J.D., M.S., CISSP – Security & Compliance [email protected] – http://delicious.com/paul.laurent

Page 2: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

An Introduction:

Page 3: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Why is it so difficult to balance security & privacy?

• The “Long Tail” of Cybercrime• Increased interest & exposure

• Complexity of IT• More attack vectors

• Governance Gone Wild!• Reading the Alphabet Soup

Page 4: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

The Strong Push for Internal Controls:Private Sector Woes

Page 5: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

The “Long Tail” of CyberCrime

Page 6: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

What Accounts for the Long Tail?

• Financial Incentives• Low Barriers to Entry• Automation

Page 7: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Financial Incentives• Commoditization of Human Identity…

Page 8: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Financial Incentives

• Inherent Value of Data• Lines of Credit (well…before October it was)• Prevalence of Online Transactions and

Processes• Data and Metadata Useful for Corroborating

Other Uses

Page 9: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Financial Incentives• Black sites & Underground Economy• Anonymous, Low-risk Outlets for Stolen

Credentials and Data• Communication and Networking Draw “Highest

Bidder” Prices• “DBA Training”

Page 10: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Low Barriers to Entry• Toolkits• No Coding, OS, Network Experience Needed• Configurable, Plug-n-Play• For Free, For Sale, For Recruiting• Jeanson James Ancheta

• “I learned some more VB, but I still suck @ it”

Page 11: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Low Barriers to Entry• Automation• Massive Infection Vectors Through

Vulnerability Searching• Leverage Google as an Infection Tool• “Security Through Obscurity” = Fatal

Page 12: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Low Barriers to Entry• CrimeWare-as-a-Service (ASP Model)• Primarily Relies On “Bulletproof Hosting”• Requires Far Less Tact and Covert Activity,

Relies More On Anonymous CrimeWare Servers Largely Unreachable By Law Enforcement*

Page 13: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Why is it so difficult to balance security/compliance?

• The “Long Tail” of Cybercrime• More reason to attack

• Complexity of IT• More attack vectors

• Governance Gone Wild!• Reading the Alphabet Soup

Page 14: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

An Evolution

Page 15: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.
Page 16: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Client-Server Architecture

Page 17: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Distributed System

Page 18: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

The Internet Cloud

Page 19: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.
Page 20: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Cloud’s Relation To “Web & E2.0”

• What Exactly IS Web/Enterprise 2.0???

• SLATES• Search• Links• Authoring• Tags• Extensions• Signals

• Web 2.0 is about “touch” and interaction

Page 21: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

So What?

Page 22: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Clausewitz Says:(Paul paraphrases)

COMPLEXITY IS BAD

Page 23: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Web Service/Web 2.0 Perspective:

Page 24: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Security Perspective:

Page 25: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

The Results

Page 26: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Why is it so difficult to balance security/compliance?

• The “Long Tail” of Cybercrime• More reason to attack

• Complexity of IT• More attack vectors

• Governance Gone Wild!• Reading the Alphabet Soup• The Good News!

Page 27: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Another Evolution:

Page 28: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.
Page 29: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

1386 Ramifications:• 44 Other states adopt in whole or in part• MGL 93H (SB 173)

• Game Changer• “Public Sector ROI”

• 3 Federal initiatives to codify• Personal Data Privacy & Security Act• Notification of Risk to Personal Data Act• Federal Agency Data Breach Protection Act

• Common Law• Bell v. Michigan Council

Page 30: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Evolution of Internal Controls:

• Role Based Provisioning• Separation of Duties• InfoSec Appointees• Risk Assessments

Governance:• Sarbanes-Oxley Act• Gramm-Leach-Bliley Act• Health Insurance Portability &

Accountability Act

Page 31: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

HIPAA into HITECH:• Increased auditing and enforcement• Before: Atlanta’s Piedmont Hospital• 42 questions• 10 days

• Before: Provident – First CAP & Fines• NOW: The HITECH factor

Page 32: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.
Page 33: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

About PCI:• Clarity• How-To’s for implementation/testing• Authoritative Source

• Accounts for Enterprise Realities• 12 Requirements or Domains• Differing levels of security

• PAN, CVV, internal/external, etc.• Protecting “Crown Jewels”

• Gaining Traction & Mindshare• v1.2 ~ 125 changes, almost all “clarifications”• Growing scope – attestation, OWASP, WEP

Page 34: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Client-Server Architecture

Page 35: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Distributed System

Page 36: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.
Page 37: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Good News:• We know where compliance is heading

Page 38: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

The Next 1386?

Page 39: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

NRS 597.970

Page 40: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Good News:• We know where compliance is heading• Leverage frameworks & best practices

Page 41: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

The Gravity of Governance Overlap in Frameworks & Compliance

• Compliance concerns• HIPAA• PCI• SB 1386 (HB 1633)• Industry Specific (SOX, IRS

1075, FERPA, CFR 28, etc…)

• Frameworks• ISO 27001/2• ITIL• COSO/COBIT• FISMA (NIST 800-53)• CMMI and others… No Security Governance

Most Laws (PCI, HIPAA, etc.) Written To Address Limited

Issues In This Range

Sec

uri

ty C

on

tro

ls S

op

his

tica

tio

n

Likely finding of legal negligence below this threshold

Most IT Shops Are Here (limited, informal controls)

Best Practice Framework

Most frameworks cover 75-85% of the same technology controls

Page 42: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

PCI DSS v1.2(Requirements)

NIST 800-53(Domains)

Build and Maintain a Secure Network (1, 2)

Sys/Svc Acquisition (SA)

Sys/Comm Protection (SC)

Protect Cardholder Data (3, 4)

Sys & Info Integrity (SI), Media Protection (MP)

Implement Strong Access Control Measures (7, 8, 9)

Access Controls (AC)

Ident/Authentication (IA)

Regularly Monitor & Test Networks (10, 11)

Audit & Accountability (AU)

Maintain an Information Security Policy (12)

Awareness and Training (AT)

Comparison:

Page 43: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

Good News:• We know where compliance is heading• Leverage frameworks & best practices• Utilize partnerships to our advantage

Page 44: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.

“Grassroots”

• People• Process• Partners• States/Agencies• Vendors• Thought Leaders

• NIST• PCI

Page 45: Massachusetts Digital Government Summit Navigating Privacy and Security Paul Laurent, J.D., M.S., CISSP – Security & Compliance Solutions paul.laurent@oracle.compaul.laurent@oracle.com.