Selasa, 19 Februari 2013

If PCI Is Your Whole Security Program, You’re Not Doing Your Job Right

For most CISOs, the pain of an audit is part of the job, but it doesn’t have to be the nightmare that most of the IT community envisions. While attending the SOURCE Boston conference last week, your faithful SecurityWeek correspondent attended a rather frank discussion centered on the pain of a PCI assessment, and why the said pain is completely unwarranted. Here’s a recap of the talk.

Presented by Michelle Klinger, a Sr. Consultant with EMC, and Martin Fisher, the Director of Information Security for WellStar Health System, the talk looked at the PCI assessment process from the perspective of a former QSA and an active security manager.

The goal was to highlight some basic processes that business leaders can follow in order to get through the assessment with as little stress as possible, a task that seems harder than it actually is.

Making the best of the situation
The talk started with a simple fact. Most of what those in the IT community think they know about PCI assessments is wrong.
PCI Assessment Strategies“Horror stories that you’ve heard about assessments are generally that – horror stories,” Fisher said, expanding on his statement.

“Like most stories there’s two sides to it. Most of the horror stories that I’ve personally experienced, eighty percent of the blame went on the CISO at the time, and with the way he tried to manipulate the situation.”
At the same time, when the experience is a positive one, this too can be placed at the feet of the executive that is leading it. No matter what, the general tone of the process is set before the assessment starts.

Before The Assessment
One of the first things that a QSA will look to accomplish is the establishment of an initial rapport with the organization’s leadership and their teams. The idea is to discover what it is that the company is looking for. Obviously, Klinger explained, they want a compliant ROC (Report on Compliance), but what if there’s more? Organizations that are clear on what it is they hope to accomplish, such as using the ROC to push various security initiatives, will be helping themselves as well as the QSA in the long run.

The other side to this helpfulness is documentation. Assessments can sometimes require lots of documentation. Having the proper documents in place can mean the difference between a useless assessment, and one that actually gets stuff done, Klinger explained.

It isn’t as if the documents a QSA needs or how the validate the PCI process are a secret, it’s well documented. Yet this area sometimes causes problems, as organizations come to the table unprepared, which in turn leads to issues further on.

With that said, prior to the QSA arriving onsite, make sure that an agenda has been discussed previously and make sure that all the people need for the meeting are available and documents are in order to prevent time being wasted, Klinger added. The documentation itself should have timestamps and dates whenever possible, especially if they are screenshots.

The documentation should be as close to real time as possible, as to show what is going on in the organization’s environment.

Even better, when the documentation is collected, present it to the QSA as a map. This will enable the organization to show the QSA that document X is looking to satisfy requirement Y. In the long run, the document map is a timesaver and will benefit both sides of the process.

“From a CISO perspective, if you don’t start this process well you’re going to be hosed,” Fisher said. “While as a CISO or a director, you might not be able to pick the QSA firm... you do have the ability to choose who the individual assessor is. This is a critical, key first step.”

CISOs should interview potential QSA candidates as if they were interviewing an employee. For example, Fisher added, use hypothetical questions and situations. “If their personality is one that will rub everybody on your team wrong, don’t use that person.”

Another thing for CISOs to consider is the truth.
“You need to be honest as a CISO. I’m not saying it’s like walking into a confession booth, ‘forgive me assessor for I have sinned,’ and just lay everything out. I’m not advocating that at all. But don’t lie. Because once you’ve lost your credibility with the QSA, their only recourse is to do a fishing expedition. It’s ugly and it’s painful, and you don’t want to be there,” Fisher explained.
“You also need to make sure that your team understands that lying to the QSA, is going to give them the opportunity to add value to other organizations – other than your own – very quickly. Don’t tolerate it from your staff.”

During the Assessment
One of the things a QSA will look for is inconsistencies. This isn’t that they are searching for lies, but they are looking for communication breakdowns between policy makers and those with “boots on the ground.”
This is why making sure that the documentation is prepared, and the correct people with the relevant information are available from the start. It’s also why honesty is important. Communication breakdowns happen, and often no one is aware of them, so this provides an opportunity to correct them and better strengthen the organization.

“I can’t tell you how many times I’ve been stood up for meetings,” Klinger said. “The QSA, you have to understand, as well as the people being interviewed, want this to be done.”

Planning meetings with a QSA and then canceling them at the last moment or not showing up entirely wastes time, and time can translate into money. Cancelations are expected, but if a meeting has to be canceled, then there should be as much notice as possible and an alternative date and time proposed in order to reschedule.
It’s basic politeness in many cases, but it can go a long way towards keeping the assessment process smooth. The last thing an organization or its staff needs is a QSA hunting people down. Most times these meetings can be painful, which in some cases are why they’re avoided. But, Fisher added, the CISO should make it clear that the meetings are important and the pain from the meeting is nothing compared to the pain that could come from blowing them off or neglecting them.

Another thing for organizations to remember, particularly the CISO, is the importance of managerial support. CISOs need to be supportive of their teams during the process and encourage them to work with the QSA, not against them. Again, being honest and open will play a large role in this.

PCI Compliance Assessment
However, on the other side of support is influence. CISOs that try to strong arm the QSA, or improperly influence the process, will cause more harm than good. In short, this is a career-ending move in some business segments.

Never let the QSA to be in charge. They need scope and boundaries, and the CISO needs to enforce this. If the QSA doubts the CISO or his staff’s honestly, “you’re done,” Fisher explained.

“Their not going to believe anything you say. The assessment will take longer, and instead of giving you the benefit of the doubt on something that’s on the cusp – you’re toast.”

The bottom line is that given the fact that one cannot improperly influence the QSA or even appear as if they’re doing so, should there be a problem with the QSA, the CISO needs to address this with the QSA’s boss. However, if the QSA was interviewed previously, this shouldn’t be an issue.
After the Onsite Assessment
Before the QSA leaves, get a meeting with them to offer an overview of the major items that they’ve identified. This helps management get an idea on the level of effort needed for remediation. It also helps with identifying potential discrepancies.

In addition, the organization needs to make sure that outstanding items are delivered in a timely fashion. Outstanding items happen. This is part of the process, but it’s something that must be addressed sooner rather than later. Also, make sure that the QSA sends a list of findings is delivered.

CISOs should just expect this, but make sure that it’s clear to the QSA that this is to be delivered ASAP. The QSA is relying on the organization to review the findings and discuss them. As remediation begins, keep the QSA in the loop and communicate with them periodically as changes are made.

“The biggest mistake that too many CISOs make is they don’t realize the ROC is negotiable,” Fisher said.
“Now I’m not saying that you can bend reality. I’m not saying that at all. But for example, in certain industries, certain words [have different meanings]... If in your conversation with the assessor, if they keep using a word that to them is a middle sized problem, but in your world it means the four horsemen are saddling up, explain to them the cultural context of that word...”

Doing so, will the ROC to represent language that the organization’s board of directors and senior leadership understands. It also enables the CISO to ensure that the ROC is accurate.

From there, the CISO needs to use the ROC and determine where the organization “needs to go from here,” Fisher adds. However, while it is vital that the CISO form a plan, they cannot use the list of remediation items as their plan.

“If you do that, you suck,” he said. “PCI is not your whole program. If PCI is your whole program, you’re not doing your job right.”

In the end, assessments can be heaven or hell. “You either get a Scotch that’s warm and peaty or you get a warm bottle of Zima,” Fisher humorously concluded.

The quality of beverage (and the assessment) and the level of pain, is completely in the hands of the organization. With a little effort and some focus, it’s entirely possible for CISOs and their teams to not only survive a PCI assessment, but also survive it with their sanity intact.

6 Steps to Acing Your Next Firewall Audit

Certainly we are no strangers to increased regulations, standards and internal policies, and the resulting audits that impact most organizations – often multiple times per year. 

While regulations and ensuing IT audits go beyond firewalls and firewall policies, these devices are often a good place to start when it comes to becoming "audit-ready" and gaining continuous visibility of what's going on in your network. 

Here are six steps to ensure you ace your next firewall audit:
Step 1: Gathering Pertinent Information Before You Undergo an Audit
Firewalls in Data Center
Without understanding what’s in your network, you have no chance for success come audit time. So prior to undergoing an audit, make sure you can collect all relevant security policies and firewall logs (then you can analyze the logs against the firewall rule base to understand what is actually being used). Make sure you have a diagram of the current network and firewall topologies. Gather all documentation from previous audits, including firewall rules, objects and policy revisions. Review relevant firewall vendor information including OS version, latest patches and default configuration. Understand what servers and information repositories are in the network as well as their relative value to the company.
Once you’ve gathered this information, it is imperative that you can aggregate and update this information in something better than a spreadsheet because you're most likely going to have multiple audits per year and spreadsheet compliance usually ends up badly. 

Step 2: Review Your Firewall Change Management Process
Poor documentation of changes, including why the change is needed, who authorized the change, etc. and poor validation of the impact on the network are two of the most common issues when it comes to firewall change management. As time goes on, this challenge is exacerbated by staff turnover - that internal knowledgebase of why a change was made disappears and then you're left wondering what you should do – and poor documentation. Make sure you have regular reviews of the procedures for rule-base maintenance and that you can determine:
• If there is a formal and controlled process in place to request, review, approve and implement firewall changes.
• Whether or not all of the changes have been authorized. If you discover unauthorized rule changes, flag them for further investigation.
• If real-time monitoring of changes to the firewall is enabled and access to rule change notifications is granted to authorized personnel. Taking these recommendations into account will get you off to a good start with solidifying your firewall change management processes and ensuring continuous compliance. 

Step 3: Audit Your Firewalls' Physical and OS Security
Make sure you can define and enforce corporate baselines... and report against them so you know where you stand. By reporting against these baselines that you determine, you will always be "in the know" of your firewalls' configuration status and how they stack up to the policy. Ensure your firewalls and management servers are physically secured with controlled access and that the OS passes common hardening checklists. 

Step 4: Cleanup and Optimize Your Rule Base
Over time, firewall policies have more and more rules added, removed and changed, and oftentimes with little documentation for the what, why, who, etc. This creates unnecessary overhead in the audit process and slows down firewall performance. Identify and remove unused rules and objects as well as covered rules, consolidate similar rules and tighten overly permissive rules (i.e. “ANY” in the source address). 

Step 5: Conduct a Risk Assessment and Remediate Issues
When reviewing firewall rules and configurations, you want to be able to identify any potentially “risky” rules. What is “risky” can be different for each organization depending on the network and the level of acceptable risk, but there are many frameworks and standards you can leverage that provide a good reference point, in addition to your own definitions of course. Risky rules should be prioritized by severity. Once you've gone through your list of risk analysis questions, then it is time to document and assign an action plan for remediation of risks and compliance exceptions found in risk analysis. Once you've conducted remediation efforts, make sure you document those as well and verify that these efforts and any rule changes have been completed correctly. 

Network Security
Step 6: Ensure Ongoing Audit-Readiness
When it comes to your firewall configurations, building audit-readiness must be a business process that is maintained over time. "Manual" and "audits" just don’t mix. I've personally spoken to customers who prior to leveraging an automation tool spent 2-3 weeks to perform an audit of just ONE firewall, whereas with automation, that painstaking audit process was under a minute or as one customer told me "a push of a button". Additionally, proper documentation and a solid change process are instrumental pieces to ensuring audit-readiness at the drop of a hat. 

A final consideration is that while this article has focused on firewalls, there are different types of firewalls (traditional, next-generation, etc.) as well as secure web gateways, VPNs and other security devices typically found within an organization's network. Make sure that your audit process covers all of these devices as well. Good luck on your next audit.

Senin, 18 Februari 2013

zeus banking trojan targeting five

Zeus banking Trojan targeting five major banks in Japan
Zeus continues to strike online bank accounts and users, and technology designed to thwart these Trojan attacks continually fails to keep up. Symantec recently came across a new Zeus file targeting five major banks in Japan.
The malware, which has caused serious problems to banking customers in Europe and the U.S, now having maximum concentration on Japanese banks. Target information was reveled by Symantec after decryption of configuration file from new sample. The attacker uses Blackhole exploit kit in order to install Zeus.

target
Zeus, a financially aimed malware, comes in many different forms and flavors. It can be tweaked to hijack personal PCs, or come in the form of a keylogger that tracks keystrokes as users enter them.
But once installation over, Zeus malware aims to steal online-banking credentials, and phishing schemes and drive-by downloads are most often the avenues hackers use to spread this increasingly sophisticated and evolving Trojan.
In this case, the functionality is the same as that of other Zeus variants. Once infected, Zeus monitors the Web browser visiting the targeted banks and injects HTML code that displays a message in Japanese that states in English: "In order to provide a better service to our customers, we are updating our personal internet banking system. Please re-enter the information that you provided when you first registered.".

Zeus gained notoriety in 2006 as being the tool of choice for criminals stealing online banking credentials. If your are one of the victim of Zeus, we recommend that you change your passwords for your online accounts and if you have used your credit card while Zeus Trojan was on your computer, contact the bank and let them know that you might be be victim of a phishing attack.