{"id":2081,"date":"2009-04-21T02:38:16","date_gmt":"2009-04-21T09:38:16","guid":{"rendered":"https:\/\/svapm.org\/?p=2081"},"modified":"2019-08-07T14:31:46","modified_gmt":"2019-08-07T21:31:46","slug":"infosec-101","status":"publish","type":"post","link":"https:\/\/svapm.org\/?p=2081","title":{"rendered":"InfoSec 101"},"content":{"rendered":"<figure id=\"attachment_2101\" aria-describedby=\"caption-attachment-2101\" style=\"width: 300px\" class=\"wp-caption alignright\"><a href=\"http:\/\/www.flickr.com\/photos\/carbonnyc\/2294144289\/\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-2101\" title=\"padlock\" src=\"https:\/\/svapm.org\/wp-content\/uploads\/padlock.jpg\" alt=\"Security via Flickr by CarbonNYC\" width=\"300\" height=\"200\" \/><\/a><figcaption id=\"caption-attachment-2101\" class=\"wp-caption-text\">Security via Flickr by CarbonNYC<\/figcaption><\/figure>\n<p>When teaching \u201cInfoSec 101,\u201d I reflect back on my early career as a reporter, and focus on answering the standard questions: who, what, why, where, when, and how.\u00a0 Since this is a Scrappy Book, let\u2019s throw caution to the wind and take them out of order:<\/p>\n<p>Why Do We Need InfoSec?<br \/>\nBecause our stuff is valuable.\u00a0 Sure, it\u2019s mostly invisible stuff, but so are integrity, justice, and love.\u00a0 Back when we made valuable stuff we could see, we locked the stuff up.\u00a0 Information?\u00a0 That simply supported the business.\u00a0 Today, information often is the business.\u00a0 In some sense, the challenge we face today is in the lack of \u201cstuff.\u201d\u00a0 My paycheck isn\u2019t \u201creal\u201d money.\u00a0 It is information transferred from my employer\u2019s bank account to mine.\u00a0 My 401K is just numbers in a book.\u00a0 The virtual world is becoming more \u201creal\u201d everyday.\u00a0 But how do I know if something \u201cun-real\u201d has been stolen?\u00a0 An even more unsettling question, how do I know if something un-real has been altered, or just copied without taking it?<\/p>\n<p>Who?<br \/>\nEverybody.<\/p>\n<p>A chain is only as strong as its weakest link.\u00a0 So everybody has to be a pillar of infosec strength!\u00a0 Executive management must enthusiastically support and adequately fund a security program.\u00a0 The tech guys must do their propeller-head things, such as implementing so-called foolproof technical controls wherever possible so that the majority of us simply cannot screw up.\u00a0 And last, but really really certainly not least, every single one of those gosh-darned end users must understand the threats, stop their running-with-scissors behavior, and implement good security practices that they maintain day after day.\u00a0 Just as Willie Sutton said that he robbed banks because \u201cthat\u2019s where the money is,\u201d attackers will go after end users because that\u2019s where the valuable information is.<\/p>\n<p>What?<br \/>\nWe\u2019ve all heard of the \u201celevator speech:\u201d explaining something in the time it takes an elevator to travel from the ground floor to the top of a reasonably tall building.\u00a0 For an information security professional, the elevator speech can be distilled down to three letters: the \u201cCIA triad.\u201d The components are:<\/p>\n<p>&#8211; Confidentiality: The assurance that information remains \u201csecret,\u201d or not accessible to those who should not see it, which usually includes most of the 1.5 billion people with Internet access.<br \/>\n&#8211; Integrity: The assurance that information has not been tampered with by any of those multi-billion peeps.<br \/>\n&#8211; Availability: The assurance that information and\/or systems can be accessed at all times, a criteria that pretty much guarantees that the first two criteria are almost impossible to meet with absolute certainty.<\/p>\n<p>Where?<br \/>\nEverywhere we possibly can, which often is referred to as \u201cdefense in depth,\u201d or DiD.\u00a0 The analogy used for years by information security professionals was that of a castle, surrounded by a deep moat and protected by thick stone walls.\u00a0 A less powerful, but tastier, metaphor is \u201cThe crunchy shell around the soft, chewy center.\u201d\u00a0 This logic is easily understood since it applies outside of the infoworld.\u00a0 In the real world we build fences around the compound, hire guards, and put locks on the doors.\u00a0 In the infoworld, we use logical access controls: PC login credentials, network login credentials, file access controls, and role-based access.<\/p>\n<p>When?<br \/>\nThe simple answer is always: 24 hours a day, 7 days a week, 365 days a year.\u00a0 The threats never sleep, and neither can the protection.<\/p>\n<p>How?<br \/>\n\u201cImpossible\u201d problems call for creative and innovative solutions.\u00a0\u00a0 A winning combination consists of physical, technical, and administrative (PTA \u2013 easy to remember if you\u2019ve ever had a kid in school) mechanisms:<\/p>\n<p>&#8211; Physical: locks, guards, doors, badges, alarms.<br \/>\n&#8211; Technical: hardware, software, network architecture, host hardening.<br \/>\n&#8211; Administrative: policies, passwords, file access control.<\/p>\n<p>We\u2019ll address common technical, physical, and administrative security techniques in the next three entries.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When teaching \u201cInfoSec 101,\u201d I reflect back on my early career as a reporter, and focus on answering the standard questions: who, what, why, where, when, and how.  Since this is a Scrappy Book, let\u2019s throw caution to the wind and take them out of order&#8230;<\/p>\n","protected":false},"author":1483,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"give_campaign_id":0,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[2,7,20,1],"tags":[573,574,572,571,261,570],"class_list":["post-2081","post","type-post","status-publish","format-standard","hentry","category-leadership","category-goals","category-quality","category-miscellaneous","tag-cia-triad","tag-defense-in-depth","tag-infosec","tag-michael-seese","tag-scrappy","tag-scrappy-information-security"],"aioseo_notices":[],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts\/2081","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/users\/1483"}],"replies":[{"embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2081"}],"version-history":[{"count":1,"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts\/2081\/revisions"}],"predecessor-version":[{"id":14210,"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts\/2081\/revisions\/14210"}],"wp:attachment":[{"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2081"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2081"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2081"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}