Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

5/9/2017
02:00 PM
John Brenberg
John Brenberg
Commentary
Connect Directly
LinkedIn
RSS
E-Mail vvv
50%
50%

Shining a Light on Security’s Grey Areas: Process, People, Technology

The changing distributed and mobile business landscape brings with it new security and privacy risks. Here's how to meet the challenge.

Security and privacy programs are best managed within the boundaries of a company’s people, processes and technologies. But now the lines that define those boundaries are changing – even disappearing.

Today’s workers aren’t isolated to fixed locations and routine schedules. They’re mobile, with virtually anytime, anywhere access to a growing abundance of sensitive information. And data can no longer be expected to be stored and transmitted on premise, but rather through cloud-based and virtual systems.

The transition from well-defined boundaries to these “grey areas” has created greater complexity and confusion when it comes to protecting data. But there are actions companies can take to better understand the risks, and ensure security and privacy programs keep pace with them.

Process: Refreshing Privacy and Security Efforts
Business is changing faster than ever in today’s connected, global economy through traditional means such as acquisitions, organic growth and new market opportunities, as well as more and better data, and connectivity. Both trends are dramatically upending business models, operations, products and services.

As companies change, so should their security and privacy efforts. For example, security and privacy professionals should continually monitor their company’s most valuable assets, such as intellectual property and customer data. From there, they can identify the risks that those assets face, and implement the appropriate safeguards.

People: Managing the Human Factor
The burden of information protection is shifting toward the workers as they become more mobile. Companies must be proactive about providing technology and training to help workers be mindful of their surroundings and the information they access in public places.

These efforts are important. But employee behavior can be hard to change - and will always be prone to human error. That’s why additional safeguards that provide an added level of protection and reduce the burden on the employee can be vital.

Visual hacking prevention is one key example. Visual hacking is the act of viewing or capturing private, sensitive or classified information for unauthorized use. It can be as simple as someone seeing and remembering your company network’s log-in details. Or it can involve using any number of modern technologies to record private organizational or customer information. Employees can – and should – use physical safeguards to block out views of onlookers, who might be looking to glean information from a quick glance or even by recording it with a smartphone camera.

Meanwhile, office workers face increasingly sophisticated attacks. This includes spearphishing, which use social engineering and knowledge about specific workers to target and trick them into clicking on malware-laced links and attachments.

Real-time training, such as with mock phishing services, can test employee performance against these schemes and help companies keep pace with fast-evolving threats. Data-loss prevention technologies can track and restrict employee actions when handling sensitive data, which can help prevent both unintentional and malicious data breaches.

Technology: Addressing New Risks
Security and privacy professionals should revisit their policies when making network and technology infrastructure changes, such as moving from traditional data centers to cloud computing. For instance, security teams will need to identify whether the log-monitoring technologies used in their corporate data centers can be extended to data in the cloud. They may discover they need to incorporate additional security, such as security incident and event management (SIEM) services.

Additionally, a number of security services, such as authentication, file-integrity management and vulnerability scanning, are available through the cloud. This may be more efficient and cost-effective than licensing, installing and managing such services at the company’s on-premise data center.

Either way, whether security services are managed through the cloud or in company-managed data centers, policies and standards should be updated to clearly define an approved approach.

Related Content:

 

John Brenberg has over 30 years of experience spanning new product introduction, system development, infrastructure management and information security and compliance across multiple business segments and processes. He is responsible for leading the IT programs for ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
7/31/2017 | 3:57:58 PM
Re: Agreed, process must be revisited
One process area that is in sore need of revision in InfoSec is Requirements Gathering.  While InfoSec should always be a DevOps environment (IMHO), when it isn't (security appliance industry) there must be a more expansive R&D process to fully understand the technology being used to penetrate large enterprises, especially where the most sensitive data is at risk.  We see so many large apps go to market with fancy tools that seem to entirely rely upon the user to configure and make successful.  InfoSec should not be in the business of selling widgets.  Instead, we need more proactive, intelligent and fully operational defenses for users where development keeps up with the underground and is constantly gathering requirements that lend to patches and point releases that can keep pace with the quickly evolving tools of cyber criminals.

 
LMaida
50%
50%
LMaida,
User Rank: Author
7/17/2017 | 3:51:13 PM
Agreed, process must be revisited
Great insights, John. I especailly agree with the idea that organizations need to revisit process, especially around security operations and incident response. Sometimes the process is the problem, and makes organizations reative instead of proactive. 
Commentary
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
Edge-DRsplash-11-edge-ask-the-experts
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
News
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-20733
PUBLISHED: 2021-06-22
Improper authorization in handler for custom URL scheme vulnerability in ????????? (asken diet) for Android versions from v.3.0.0 to v.4.2.x allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.
CVE-2021-20734
PUBLISHED: 2021-06-22
Cross-site scripting vulnerability in Welcart e-Commerce versions prior to 2.2.4 allows remote attackers to inject arbitrary script or HTML via unspecified vectors.
CVE-2021-20735
PUBLISHED: 2021-06-22
Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier, Delivery slip number csv bulk registration plugin (3.0 series) 1.0.8 and earlier, and Delivery slip number mail plugin (3.0 series) 1.0.8 and earlier) allows remote attackers to ...
CVE-2021-20736
PUBLISHED: 2021-06-22
NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors.
CVE-2021-20737
PUBLISHED: 2021-06-22
Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors.