Data Analytics Cybersecurity IT Strategy & Business Alignment

Big Data, Bigger Security Challenges

Big Data in its early stages has opened up a world of new opportunities for businesses to derive value. And yet the unexpected consequence of that opportunity is that all the new insight that is now available to you is also available to those looking to do harm. This new data that is not secured in the same way as the rest of your organization could provide hackers deeper insight into when you are most vulnerable or susceptible to take a loss. So in what ways can we go about safeguarding against the loss of this information and enable security throughout the Big Data life cycle?

Contributor

Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More

Transcript 

Sanjog Aul [00:00:00]:
Welcome to CIO Talk Radio. To learn more about the show, please visit www.ciotalkradio.com. as always, we invite you to join our discussion on Twitter #Ctrlive and look for this show as #bigdata and #Security. Today’s topic is Big Data, Bigger Security Challenges, and our guest for Today’s show is Dr. Roger Schell, who is a Professor with University of Southern California. Morning, Roger. How are you?

Dr. Roger Schell [00:00:29]:
Well, good morning. I’m real fine, thank you.

Sanjog Aul [00:00:32]:
Great. Now the conversation about big data just seems to be all over the place, and of course, it keeps going and inevitably it was going to involve security because we had not covered it to that degree. This is part of one of the two shows we will actually be doing on big data and security, with our show next week focusing on how you can use big data to improve security, but this week we’ve discovered that in some instances, big data can open organizations up to even more vulnerabilities and we would like to explore what we can do about this.

Dr. Roger Schell [00:01:06]:
Yes, I think that’s certainly the case.

Sanjog Aul [00:01:08]:
Think of where people are saying, how is this coming about as a notion that big data, as soon as you start talking about it, where is it actually making it more us more vulnerable? And what type of security issues is it inducing into the system?

Dr. Roger Schell [00:01:24]:
Well, I think that part of our vulnerability is as we have more big data, we have more connectivity, and so the problem we have is the system is no more secure than its weakest link, and so if we introduce new weak links into the system, we’ve given the attackers new opportunities.

Sanjog Aul [00:01:44]:
Anything which is already not as secure, and on top of it, you bring big data. What has it truly done? Has it made the exact places where security could be the weakest?

Dr. Roger Schell [00:01:55]:
Well, the fundamental weakness that’s in most systems where the flaws occur are primarily the operating system platforms that the systems are running on, and so as you introduce more platforms, more servers, workstations, et cetera, into the environment, each of those becomes a part of the attack surface for an attacker.

Sanjog Aul [00:02:18]:
So when you’re looking at that particular instance where the operating systems, etc, there are many other things which people are trying to do, and yes, the hackers could on one end be trying to get into the system as someone tried to get some proprietary information, and another is that perhaps big data creates some sort of insight which otherwise was not available, and now the security is not primarily only at the operating system level, but also it could cause business loss. Is that one of the flavors that you think is possible, or are we just kind of imagining this?

Dr. Roger Schell [00:02:54]:
Well, I think there’s, at this point, big data is early enough that we don’t have a large volume of reported incidents based on big data, but that’s not a surprise. After all, people who may be stealing business data and other things of that nature are not likely to advertise that so widely. So it may take us a while to discover. I think we can see sort of indications of what can come about the items in the news, for example, about Mr. Snowden and the analysis by NSA. One could quarrel and ask that and suggest that the NSA is using essentially big data. They’re doing analytics over large amounts of data, and they’re taking data which previously taken individually would not have raised that much concern,

Dr. Roger Schell [00:03:47]:
but now taken all together, people understand this is an issue, and so I think that’s part of the problem that you were alluding to with big data. We are making it more attractive to attackers.

Sanjog Aul [00:04:00]:
So one thing is to say we have not enough reported incidents, and we really, in the world of security, always have been reactive and saying, okay, now we have a big problem. Let’s go and look for a solution. Do you think the security industry, as well as people who are working with big data, from a business standpoint, are now buying that fear, if you will, like somebody would sell insurance and ready to invest in proactively looking at where all big data can cause damage and start patching those holes proactively?

Dr. Roger Schell [00:04:34]:
Well, you’re exactly right that the industry has been reactive and this has been the case for many years, and I think what we can see is that that reactive approach simply doesn’t work, but we continue to spend more and more money, billions of dollars, to provide security solutions, and yet, if you pick up the paper, it’s fairly evident that we’re not being that effective. So I don’t believe that the security industry is at this point particularly investing in providing proactive solutions. There are certainly things that can be done, even aside from big data, that we’ve known how to do for decades that are simply not being applied and to provide greater security, and I think that’s a serious problem that is not directly tied to big data, but big data gives us some opportunities to apply those proactive solutions if we chose.

Dr. Roger Schell [00:05:31]:
You say, is the industry a security industry, going out and proactively developing solutions and selling like a insurance? No, my experience is that that’s not the case really at all. I’ve been dealing with a number of people in that industry. The constant theme is that customers are not willing to significantly pay for strong security whether they’re right or wrong. I believe that’s generally held by the industry, and so the techniques, things that are called as verifiable protection, but it’s simply not available in any of the major offerings today.

Sanjog Aul [00:06:08]:
So where do you think organizations should even look at when trying to get started with this? Should they look up to someone like you who’s a thought leader and try to give them ideas or they should create a sandbox where they say if these are the areas in which vulnerabilities can happen and they try to get ethical hackers in the organization and see what they would do?

Dr. Roger Schell [00:06:28]:
Well, I think that the solution has to come from the people that provide the products, in other words, the hardware and software that is used in the actual operation of big data, individual users, the customers of those vendors are not in the position of developing the solutions themselves, and so they have to depend on the vendors. The vendors need to believe that there’s a market, and today, and I think for some time they haven’t seen that as a market.

Sanjog Aul [00:07:03]:
So where should an organization go with all these new things that you are trying to accomplish? Do you think the management is looking at this proposition or induction of fear within an organization or let’s be cautious before we go too crazy with big data is to look at the security aspect, and traditionally security has been seen to put a damper on innovation related initiative, and it’s not maybe the reality, it’s just perception that floats around.

Dr. Roger Schell [00:07:34]:
So what do you think the perception? Security generally does not generate revenue and as a result it is not going to be enthusiastically pursued unless people are informed and see it as important to their business success. I think the first step you ask what can businesses do? One of the most important steps is they need to identify what data is sensitive and who should have access to that data. One of the challenges in big data is that it encourages the management to provide even greater access to information than was previously the case. In order to get the benefits of big data, they need to be able to have access to lots of different information, and that provides an incentive to make connections that were not previously there. Now if you don’t have in your organization a policy that identifies, essentially categorizes your data, is that this is free accounts receivable, this is accounts payable, this is HR data. If those kind of labels for the data are not there, then you don’t have an easy way for people that are responsible for delivering it to say no, that we don’t really want to make that HR data available because that has sensitive privacy data in it. People like NIST have for years been advocating that we need to categorize the data and do this,

Dr. Roger Schell [00:09:03]:
but many enterprises just simply have not got to the level of actually formally writing down a policy, assigning a label to the data and say, this is HR data, this is engineering data, and without that there’s not a good guy.

Sanjog Aul [00:09:21]:
So if you were to ask the business to say, tell me which all types of data or which all patterns would you think we should be holding back or not try to put out there? Are they willing to do that though? Because they want to use it for business, but it also creates vulnerability. Who wins or who should win?

Dr. Roger Schell [00:09:42]:
Well, the should win. Who should win, of course, is a matter of individual business determination. I mean, what’s good for one business may not be for another. So that it is not just a philosophical discussion, it’s ultimately a business decision. The concern I think that I would have is that the businesses are not well informed today. One of the issues with the labeling is it allows us to provide rather strong solutions that says, okay, I can restrict the data flow from those that are authorized to have HR data to just and only those are the ones who are able to access the HR data without the labels. You can’t do that. Now going through that sort of a categorization and policy development does not itself generate any revenue,

Dr. Roger Schell [00:10:32]:
and so if the leaders are not informed of the value of security, then no, the security will not win.

Sanjog Aul [00:10:41]:
If you were to attribute this either perceived threat due to big data or it may be reality in some cases, maybe we don’t have enough proof. What do you attribute this to? Is it the policies which we may have in an organization, or the tools may not have the necessary finesse or the security built in, or the overall adoption of whatever that you’re offering to your user community which is using this big data and the responsibility portion is missing.

Dr. Roger Schell [00:11:12]:
Well, I think the first step, the foundation, is the question of a policy. If you don’t know what authorization you intend to give to data, then you can’t really expect the people in the organization that have to execute to properly control the flow of data. If the HR data is not identifiable, does not have a label on it, then it may well be included, even inadvertently in data that is to use for a big data analytics, and so I think the first step is to do what NIST is called, the categorization of data, actually assigning a label to data and say this is sensitive and that’s different than this sensitive data. That’s the first step and I think the most important step. Without a policy, you can’t know if you’re succeeding.

Sanjog Aul [00:11:58]:
But the adoption, what do you do about that?

Dr. Roger Schell [00:12:00]:
In terms of adoption? I think one of the places where the security industry and the practitioners have seriously let down the management is in the area of awareness. For example, one of the more serious threats, even that certainly applies to the big data situation is the problem of subversion of people actually getting in and building in trapdoors, building in backdoors into the system at various points during the life cycle, and if you talk to a security practitioner and you say, is this a problem? Can people actually do this? Well, there’s a thing called Easter eggs which represent hidden functions that are in prox, for example, Excel, several generations back, Microsoft Excel spreadsheet. If you were to hit four keys, you could suddenly be playing flight Simulator. Now that represented an Easter egg, as it is called, an additional functionality that was not put there by the product manager. Well, if you go on the Internet, you can find thousands of products that have those kind of Easter eggs in them. None of the ones that are listed, of course are malicious, but the point is that those same techniques of subversion can be used by attackers in the security community.

Dr. Roger Schell [00:13:18]:
People say, I talk to security officers and they say, yes, of course, we understand, and that’s a problem. You talk to executives otherwise in the organization and they largely have never heard of the problem of subversion, and the reason it is important why I single out that one. The area of subversion is essentially one that cannot be significantly addressed by the proactive or the reactive approach you’re talking about. You can’t necessarily easily spot that it’s being used and therefore you can’t provide a defense against it. So there’s a problem of the security professionals simply not making the management aware. I’ve talked to chief information security officers, say, have you told your boss and your boss’s boss about this? In general, the answer is no. You ask, why not? The essence of the answer is it’s not a career enhancing move to tell your boss you have a problem and say you don’t have a solution.

Sanjog Aul [00:14:15]:
Very interesting. Let’s take a quick break, Listers. We’ll be right back and continue this discussion, and then also look at that. Perhaps the CISO goes and tells the boss and the boss’s and the policies get drafted and then perhaps put out there for adoption, but adoption doesn’t happen because most of the time the very end user who should be having a responsibility to as a custodian of the data or the insights that they are gathering as part of big data initiative. What tells them to really not do it and what is the difference between them recognizing what is actually critical and that could be used against the security and other aspect of it is what they what they cannot really determine what is secure versus not. So how do you how do you go about this adoption challenge? Please stay tuned.

Sanjog Aul [00:15:05]:
We’ll go right back and explore.

Sanjog Aul [00:17:07]:
Welcome back. So Roger, as we were discussing and you interestingly mentioned about CISOs not going and divulging and or sharing with their boss and the boss’s boss that about this problem of big data could cause problems, potential issues, because they don’t have a solution, but does that really help the cause? Because they will definitely get fired if the problem gets out of hand and they have not kept people informed.

Dr. Roger Schell [00:17:32]:
Well, one of the beliefs that people have, and I think it’s well founded, is that if they are adopting what people call best practice, then they’re not probably going to get fired. In other words, if everybody is equally bad as long as they’re doing the best practice, then the CISOs are generally in pretty good shape. That’s regardless of whether or not the best practice is working. The situation we have today is that the best practice that we have simply doesn’t address the problem of subversion of anyone that is reasonably determined to get the data, and as long as everybody has codified this best practice, they’re relatively protected. In fact, the current activities my the government and including the legislature are focused on providing incentives for people to use best practice. what we see is best practice isn’t particularly working and isn’t going to work any better as we apply it in a big data context. So I think that there’s some reason for their choice not to discuss this with the senior management because indeed what they’re doing best practice saying, well, we’re all doing this together and yes, hackers do get in, they always get in.

Dr. Roger Schell [00:18:45]:
Security is not perfect and all that’s true, but it doesn’t. They also can rationalize the situation and say, well, what good does it do me to tell my boss that we have this problem when it really isn’t my problem, it’s a problem of the industry and why should I take the fall? Because the security vendors have not provided adequate solutions. So I think it’s very difficult to get people to do it at that level. The thing that can make a difference, I believe, is that there can be leadership to show the way to do it in a better fashion. The government for example, has in the past provided significant contributions in the security area by essentially being in a leadership position of demonstrating how to do it correctly. One of the things they can do is so called reference implementations. They can give an actual example of using these strong solutions, the verifiable protection. Unfortunately in recent years that has simply not been part of what is being done on any significant basis.

Sanjog Aul [00:19:50]:
Now you mentioned that CISOs may not take the responsibility or want to take the responsibility, but what should be then said about such security leaders to kind of say that this is not my problem. So I’m not going to inform the rest of the world.

Dr. Roger Schell [00:20:08]:
Well, I think there’s several levels of leadership in an individual organization. As I mentioned earlier, the individual CISO can’t do a great deal about providing more effective solutions. They can encourage the management to do the proper thing in terms of say, a policy. I mean, one of the things that a policy can tell you, if you identified and categorized your data, you can simply say, I’m not going to provide connectivity. We just simply will not allow a connection between point A and point B. There are certainly enterprises with sensitive data in which they apply a technique called Air Cap which says there ships no electrical connection from these servers to that servers. The ones that are, they’re not depending on firewalls, they’re not depending on any of the sort of typical solutions that are not all that effective. They simply just don’t connect it,

Dr. Roger Schell [00:21:00]:
and so the security folks can do that. They can encourage a policy which identifies when connection just simply shouldn’t be identified at all. I think that the, in fact, I’m currently in the process of talking to a group which is looking at a policy relating to data and what the organization reflects is that the people in the organization see security and see new rules in terms of policy as impeding their ability to do their job, and so it really takes senior management commitment to say, yes, we are going to engage in a data categorization policy and we’re going to apply it to our enterprise.

Sanjog Aul [00:21:44]:
So the way big data is expected to work, you collect data, you then try to sift through and try to identify patterns. Out of that you do analytics and then from there you do develop insights. So if you were to take these four processes, four steps in terms of being able to do that, where do you think the vulnerability gets introduced?

Dr. Roger Schell [00:22:10]:
Well, I think the most serious vulnerability gets introduced in the first place when you talk about collect data, and the reason is that you provide the incentive with big data to open up the connections to additional data so that you can get additional insights for your business advantage, and so as you make more connections, as you provide additional interconnections, that becomes the first place of a major introduction of vulnerabilities. From the attacker’s point of view, it’s easier. You’ve now made if I can attack a single place in the processing of that data, I can get access to the entire enterprise and all the things that are connected. So the first step of collecting the data, which implies the interconnection, is a very serious vulnerability that gets introduced.

Sanjog Aul [00:23:00]:
Now, if I were to go out and try to identify things I can do differently in terms of safeguarding the data and the corresponding or reduce the vulnerabilities at each of these steps, what would be my countermeasures which have proven to at least show signs of reducing the vulnerabilities that might otherwise exist?

Dr. Roger Schell [00:23:22]:
Well, I think that the issue of a policy has been proven to reduce the vulnerabilities rather significantly. If you take probably the most well known policy of that form is the US Government has an executive order which says that within the government it must be classified as to the damage that would result from exposing that data. Those classifications have name of top secret, secret, confidential and then unclassified of course. Well, those are four categories of data, and every piece of data that is generated inside the executive branch of the US Government has to bear either implicitly in the case of unclassified or explicitly in terms of the others, a label that says this is secret data and that’s proven quite effective in the large in protecting very sensitive data from being exposed. If you didn’t have that categorization, they’d have a massive additional kind of leak. So I think that that notion of a policy and the labeling of policy is one that has been demonstrated to work and has been demonstrated to be not free but not excessively costly to implement.

Sanjog Aul [00:24:35]:
Let’s take a quick break listeners. We will be right back and look at further. What is it that the environment that is required in in an organization for it to foster a better secure approach to handling big data? One is of course we look at specific steps in the process of using or generating the big data related insights. Another is the environment that we offer in which by design we are making sure that we have created a safe haven for the big data related insights. What would that look like? What’s the ideal state and how far are we from it? Please stay tuned. We’ll be right back and explain.

Sanjog Aul [00:27:14]:
Welcome back. So Roger, when you actually started the whole process of defining through the four steps of how big data takes shape in an organization, what do you do with data collection? Let’s finish the rest and then we will look at also the environmental factors which may play a part.

Dr. Roger Schell [00:27:30]:
The first step of course, the collection. I talked about the problem of the importance of policy and deciding to limit where you allow collection to occur from. The second is in terms of the defining the patterns and determining the relevance of the data, and that obviously involves processing of the data, and that processing has to occur in the context of data that in many cases is essentially real time or semi real time. In other words, your connect to your collection points at the time that you’re actually looking for the patterns as the data is available, and there the vulnerabilities come about from the platforms, the actual hardware and software that runs because this processing goes on on a computer, and if that computer is subverted, if those tools, those big data tools in fact have in them additional capabilities put there by an adversary, they can collect the data and send it off to the attacker in a hidden sort of way in many cases so that you don’t even know that.

Dr. Roger Schell [00:28:33]:
So the the value to the attacker of the Analysis, the pattern recognition is that there may be patterns that they would like to think, information they would like to learn, and they can in fact, by subversion, just as I might add a flight simulator in that side of Excel, I can add an additional criteria that the attacker would like to have addressed in looking for a pattern and send that information to the attacker. Then in terms of developing the insights as the third step after that, well, as you apply analytics and other tools to develop the insights about the data, in some cases your adversary may just simply not want you to know to determine the insights that are there for them. I suppose the limit case is the one that you’re going to talk about next week is if I’m using these tools to actually identify potential vulnerabilities in the system from a security point of view, I may in fact bias the analysis so that the insight never identifies the vulnerabilities that I’m responsible for as an attacker. So each of those bring with them a vulnerability, and those vulnerabilities can be responded to in many cases significantly by both policy, organizationally and technology.

Sanjog Aul [00:29:54]:
So if you were to look at all of those areas, when you talk about, and that’s what was one of the questions that I’d asked before we just went to break, is the environmental factors. So you go and look at each step and try to pinpoint where all things could happen which would be adversely impacting or introduce vulnerabilities. What other factors surrounding these four steps we need to be aware of and or work with in order for us to make it a secure, overall secure environment in which big data can go about doing its job in terms of providing business insights and also not introduce vulnerabilities.

Dr. Roger Schell [00:30:31]:
So in terms of what a sort of an ideal answer situation would be, first, of course, as I noted, is you have to have a policy. You have to say who has access to what data. The data is labeled, the users are authorized access to data that you have to start with. If you don’t have that, you don’t know whether you succeeded. Secondly, as you talk about organizing the way the collection is done, for big data, one of the techniques that can provide value is to isolate the points at which you have what you might call different security domains, different authorized data. So if the policy has identified HR data, has separated that from engineering data, then for big data, I may want to have access to both of those under some cases, but the access between them should be a well defined cross domain sort of points, and organizing my architecture so that the connection between security domains is at well known points is a very powerful tool. So in an ideal solution, the only connection between security domains should be at known and identified cross domain points as opposed to just letting it sort of happen in a spontaneous way in which, I’d like to get a that server, let me make a connection over there, let me make connection over here in an ad hoc way.

Dr. Roger Schell [00:31:50]:
So the second step after a policy is to have an architecture, security architecture which recognizes the points where failures are particularly significant, and that’s the point where domains meet. The third step that I need to do is when I’m doing the processing and I’m providing the outputs, I need to be concerned that that processing with the vulnerabilities in those tools not introduce new attack surfaces for the attacker, and that’s a matter of using strong technology, and this is where I think the industry is weakest, is that we simply haven’t used the kind of verifiable protection that that is available. I mean, things that again, the government as an example, has in the past had operating systems and platforms which have run for 15 years and never ever had a security patch, and they were confident never would have a security patch or they wouldn’t have done it because the consequences of compromising things like top secret data, those kind of techniques of the verifiable protection are available to the vendors, to people who are building security products. I talked to one of the very leading people in this space, in the internet space, and after going over this, their engineers agreed, yes, we could provide products would have that sort of verifiable protection.

Dr. Roger Schell [00:33:13]:
But their statement was, quote, we mean something different by security than you mean, unquote. What that meant was that when I talked about security, I wanted to have a fairly robust thing that significantly addressed the problem, including subversion. What they meant by security was one that made their products competitive as far as they saw it in the marketplace.

Sanjog Aul [00:33:37]:
So you explained what people should be doing. Do you have a current state, if you were to rank at each of those stages of how big data comes into creating value or creates value, do you have a current bencark that you could unofficially or based on your experience, could share that? Where do we stand with this?

Dr. Roger Schell [00:33:57]:
Well, my crystal ball is broken, but I’m afraid that I’m not very optimistic because one of the things I see in general as you introduce a new area of technology such as big data is the early choices tend to set the direction that you’re going to go in the future, and the current direction we have is we do not have a direction which is based on policy. We do not have a direction which is based on a security architecture that represents these things, and we do not have a direction which provides strong solutions, and so I think that the prospects are rather dismal. I think people have in the government have commented that the security area is potentially what they call an existential problem. In other words, the very basis for our society as we know it could be put at risk if we don’t do something about it, and we are not doing anything significant about it.

Dr. Roger Schell [00:34:53]:
So I’m afraid my answer is not the one I would like, but the crystal ball is that unless we take action soon, we’re likely to have a very serious problem as a result of lack of security and big data.

Sanjog Aul [00:35:04]:
So you painted not the most optimistic picture and totally understand that you’re being realistic. At the other hand, we have big data being utilized for literally people are betting their paychecks and their businesses on big data. If we are going to go ahead and try to bet our paychecks and really try to build a credible case for big data in the first place and then actually start using it, we are introducing a bug in the system because you mentioned that we don’t have a complete control and or even some cases idea of how we will go about reducing the vulnerabilities. So should we wait for success but at the same time disaster to happen for people to open up their eyes and invest more? Or is it actually, is it even the question of getting investment in or even though people would put millions of dollars to plug the holes, they don’t even know whether where the holes are or perhaps they will not be able to plug the holes.

Dr. Roger Schell [00:36:04]:
Well, I think that there are several things we can do. I mean, one of the issues is one of, as you’ve noted several times, the fact of making people informed, having them make informed decisions, and I think the key is to make informed decisions. It is unrealistic and not necessarily sound to say, well, I’m just not going to use big data until I have the answers in place. No, that isn’t going to happen. What you would like to have is that people make an informed decision. So there’s a couple of things that can contribute to that. One of the things is in terms of the practitioners, we need to have people that are familiar with the available technology and the industry at whole.

Dr. Roger Schell [00:36:44]:
For example, one of the reasons we at University of Southern California have just this year introduced a Master’s in Cybersecurity as a fully accredited master’s program in cybersecurity. Now, having students that attend that and getting graduates of that area can help an organization be much better informed. In fact, in that area of making people available, one of the things we do at USC is we provide distance education opportunities so that students can in fact register and enroll in the program and take them while they’re maintaining the job and maybe take a course or two each semester as they’re going along on a part time basis. So those are things which can contribute to informing people. I think that’s an important step. You ask about, well, what kind of investments can I make in terms of if I had millions of dollars, would it make a difference? No, if I just throw millions of dollars at it, it won’t make a difference. What we can do, however, what I believe does make a difference and has worked in the past is what I mentioned before as reference implementations.

Dr. Roger Schell [00:37:55]:
I can actually build an example of using this sound technology to provide protection and then that can raise the bar. People can understand what to do, that can engage the vendors to do something. Now, those reference implementations take significant a few million dollars, not hundreds of millions of dollars, but several millions of dollars to build a significant reference implementation. So most enterprises are not going to do that for the benefit of the industry, and it’s one of the areas where I believe the government, for example, can serve in a leadership role, could actually spend a few million dollars and do some reference implementations to show how to do it, rather than just jawboning people with their cybersecurity direction.

Sanjog Aul [00:38:41]:
Discussed about this earlier in our conversation, that CISOs may not have a ready solution, but given their role and their experience as security professionals, are they actually going and looking under the hood a little bit to figure out where all things can be? Do they have a current state or at least some sort of an action plan to figure out what they’re going to do?

Dr. Roger Schell [00:39:04]:
I think that because of this pattern of trying to meet best practice and say that’s good enough, unfortunately, many CIOs do not have an action plan. They recognize that from a technology point of view, they do not build the hardware and software that they have to use, and so they’re depending on the industry to do this, and if the vendors are not providing those capabilities, they feel rather hopeless, and so the result in many cases is they sort of lock up and they say, well, okay, this is the best we can do. We’re just going to do what everybody else does, we’re going to do the best practice. So no, I don’t believe that most CISOs have an action plan, and the things that they can do, however, are, as I mentioned, they can stimulate a definition of the policy and they can stimulate in their organization the definition of a security architecture that actually identifies where information crosses the security domains.

Dr. Roger Schell [00:40:02]:
Those are things they can do, and I find that is not widely done by CISOs today.

Sanjog Aul [00:40:08]:
So if they are not doing it, is it something again preventing them? Or is it their mindset that why to fight a lost war or a war that they are not going to win?

Dr. Roger Schell [00:40:18]:
Well, I’m not a sociologist, so I don’t know what necessarily motivates people, but I do think there is a certain sense in which there is sort of a giving up that says I really don’t have a solution to the problem of subversion. The subversion of the platforms is probably the choice of attack of a serious adversary, and if I can’t address what’s the most likely effective attack, what am I supposed to do? And so I think they really do tend to hunker down, but that’s just observation. I am not a sociologist.

Sanjog Aul [00:40:52]:
Let’s take a quick break, Listers. We’ll be right back, and let’s look at the situation where we are today and then how this could perhaps get compounded in the future. So if we don’t have our act together, we don’t know what the approach is going to be. We don’t have any best practices. What is that going to do or how is it that going to get improved or worsen given that big data itself is evolving, we are trying to do new and bigger and better things with it in order to generate revenue, opportunities and innovation. So are we going to try to work with this moving target in the same fashion and always try to play catch up? Or is there going to be some light at the end of the tunnel? So please stay tuned. We’ll be right back and explore.

Sanjog Aul [00:43:35]:
Welcome back. So Roger, do you think we will keep chasing this moving target or if there is some light at the end of the tunnel?

Dr. Roger Schell [00:43:42]:
Well, I think there is a potential light at the end of the tunnel if we choose to continue and pursue better directions. I think there are things that can be done that enable us to take advantage of better solutions as they come about. The first and foremost one I mentioned is one of a categorization policy. I think in enterprise it’s just essential that they’re going to deal with big data that they provide essentially labeled categorizations of each of the components of data. This is HR data, this is engineering data, this is the financial accounts receivable data, and that data should be identified and labeled and they should establish a corporate wide policy that data will be labeled either implicitly or explicitly in terms of its sensitivity and impact on the organization. So that’s something that every organization can do that they can’t blame the vendors, they can’t blame the attackers for that. That’s their choice.

Dr. Roger Schell [00:44:43]:
Second thing they can do is they can construct a security architecture and say okay, how do I restrict the places where I have interfaces between domains, whether the domain is the internet on the outside and my intranet on that inside or wherever it is how do I know where those meet? And I can do an architecture which identifies those so that as better solutions are available, I can apply them where they matter most and that’s at those cross domain points. That’s an architectural thing, and again, they can do that. Third thing, they can take the opportunity to get themselves educated. They can recognize that there is science and places like USC and other universities provide that, and they can make it a priority to either add the education to their existing staff or to acquire staff that have that background, and so I think the educational community has an important role to play in that, and people need to show that they do that and that they care by requiring those kind of capabilities.

Dr. Roger Schell [00:45:46]:
Fourth, I think that since we do have such a sorry state of affairs in terms of the security of the products that are available, in particular the hardware and software platforms and their vulnerabilities, I think it’s since the industry people say, well, there’s no incentive, people won’t pay for security, they can begin as a group to encourage the vendors to do that by making strong security a purchase requirement for items that are critical. You don’t try and boil the ocean, but where you have these cross domain places, if you have an architecture that identifies that, you say, okay, if I’m going to connect between these places, that connection has to be done on a verifiably secure platform, one that is not going to have the weekly security patches after the horse is out of the barn. So those are all actions which people can take today and can in fact provide a light at the end of the tunnel. I see very few of those actually being acted on today, and if we don’t, the alternative is a sorry state of affairs.

Sanjog Aul [00:46:52]:
Now, finally, for the CISOs, what type of advice would you have for them to really stand up for what is right for the organization and be able to show the leadership that they are expected to in their, in their respective domains and make sure that whatever they are going to do, they will eventually make sure that big data is no longer going to be something that they left to live with and they cannot secure it.

Dr. Roger Schell [00:47:17]:
Well, I think I sympathize with the CISOs who are concerned about their job security, but I think that by engaging the executive suite in the question of a policy, they can then work together to solve the problem, because this is not something the CISO can do. This requires a corporate wide commitment to identify and categorize the data and identify who has access to which data. By going in that direction, they then have a shared responsibility and then it becomes more reasonable for them to talk about the flaws that exist, the threat of subversion, for example, to say we need to have this policy so we know where we can in fact are vulnerable to that sort of a threat and so we can look for products that do deal with that. So I think that the although they can’t do the policy, they can encourage those sort of a corporate wide direction. That’s an action they can take.

Sanjog Aul [00:48:09]:
On behalf of the show and our listeners, I’d really like to thank you, Roger, for sharing your thoughts on how organizations and the technology leaders as working with the security leaders like CISOs could work with big data and don’t let the security challenges get any bigger, and if they do, then they work together to make them more manageable. Thank you so much again.

Dr. Roger Schell [00:48:29]:
Well, you’re certainly welcome. It’s been a pleasure.

Sanjog Aul [00:48:31]:
Thank you and listeners. Hope you enjoyed the conversation. Please like us on Facebook, search for CIO Talk Radio and be sure to follow follow us on Twitter. Thank you again for listening to CIO Talk Radio. This is Sanjog Aul your talk show host till next week. Take care and God bless.

Contributors

Dr. Roger R. Schell

Dr. Roger R. Schell, Professor, USC/ISI, University of Southern California

Dr. Roger R. Schell recently joined USC/ISI supporting their Masters of Cyber Security degree program. He is internationally recognized for originating several key modern security design and evaluation techniques, and he holds patents in c... More   View all posts
Add Comment
Click here to post a comment

Advertisement

TECHM - GENAI - MPU06 - 300x300
Dr. Roger R. Schell