Social Icons

Showing posts with label Dyman & Associates Risk Management Projects. Show all posts
Showing posts with label Dyman & Associates Risk Management Projects. Show all posts

Wednesday, May 13, 2015

US government grants $3 million to fight future cyberattacks

Algorithmic vulnerabilities, or the emerging hacking threat, can do a lot of damage on computer systems. It is considered as more complex, more challenging to detect and more effective at damaging different nation’s computer systems.

Additionally, it is extremely hard to detect with the existing security technology according to the Dyman & Associates Risk Management Projects.

These attacks can only be achieved by hackers hired by nation states which have resources essential to mount them, but perhaps not for very long.

Computer scientists at the University of Utah and University of California, Irvine are given $3 million by the U.S. Department of Defense to produce software that will detect or fight future cyberattacks.

The University of Utah team will be composed of 10 faculty members, postdoctoral and graduate students. Of the $3 million grant, which is over four years, $2 million will go to the Utah team and $1 million to the Irvine team.

The project is funded by the Defense Advanced Research Projects Agency (DARPA) in a new program called STAC, or Space/Time Analysis for Cybersecurity.

The team is tasked with creating an analyzer that can fight so-called algorithmic attacks that target the set of rules or calculations that a computer must follow to solve a problem.

The analyzer needs to perform a mathematical simulation to predict what’s going to happen in case there is an attack and it must conduct an examination of computer programs to detect algorithmic vulnerabilities or “hot spots” in the code. It is more like a spellcheck but for cybersecurity.

University of Utah’s associate professor of computer science and a co-leader on the team, Matt Might said that the military is looking ahead at what’s coming in regards of cybersecurity and it seems like they’re going to be algorithmic attacks. He also stated that the current state of computer security is a lot like doors unlocked into the house so there’s no point getting a ladder and scaling up to an unlocked window on the roof.

"But once all the doors get locked on the ground level, attackers are going to start buying ladders. That's what this next generation of vulnerabilities is all about."

Hackers will make use of programmers’ mistakes while creating their programs on the software. For instance, the software will get a programming input crafted by a hacker and use it without automatically validating it first which can result in a vulnerability giving the hacker access to the computer or causing it to leak information.

Algorithmic attacks are very different since they don’t need to find such conventional vulnerabilities. For instance, they can secretly track how much energy a computer is utilizing and use that information to gather sensitive data that the computer is processing, or they can secretly track how an algorithm is running within a computer. These attacks can also drive central processing unit (CPU) to overwork, or they can disable a computer by forcing it to use too much memory.

Suresh Venkatasubramanian, who is also a co-leader from the team, states that these algorithmic attacks are very devious because they could exploit weaknesses in how resources like space and time are utilized in the algorithm.


Algorithmic attacks are really complex, costly, and use the most amount of time, so most hackers these days are not using this kind of attacks however, they take the easier route of exploiting current vulnerabilities.

Monday, April 6, 2015

Dyman & Associates Risk Management Projects: New Chip can Turn Smartphone into 3D Scanner

With 3D printers all but widely-known now, it only remains to have an accurate and portable 3D scanner to practically produce anything on-the-go. The current 3D scanners are all bulky and very expensive but we may soon have that functionality installed in our smartphones.

A team of CalTech researchers led by Ali Hajimiri has designed a small camera chip that can enable a smartphone to do an accurate 3D scan of an object.

The tiny silicon chip called nanophotonic coherent imager (NCI) only measures one millimeter square and can conveniently be placed within smartphones. It uses a type of Light Detection and Ranging (LIDAR) technology in capturing an item's width, depth and height. Basically, a laser is shined on the object so the light waves that bounce off of it can serve as guide for the imager when capturing the measurement data.

The technology used on the chip is further explained by Caltech:

"Such high-res images and data provided by the NCI are made possible because of an optical concept known as 'coherence'. If two light waves are coherent, the waves have the same frequency, and the peaks and troughs of light waves are exactly aligned with one another. In the NCI, the object is illuminated with this coherent light. The light that is reflected off of the object is then picked up by on-chip detectors, called grating couplers, that serve as 'pixels', as the light detected from each coupler represents one pixel on the 3-D image."

According to Dyman & Associates Risk Management Projects, LIDAR technology is commonly used in self-driving cars, robots and precision missile systems due to its effectiveness in identifying locations and objects. Although the concept of LIDAR is not that new, their idea of having "an array of tiny LIDARs on our coherent imager can simultaneously image different parts of an object without the need for any mechanical movement" is a novel one.

Basically, every pixel on the sensor can separately assess the intensity, frequency and phase of the reflected waves, thereby creating a piece of 3D information. The combination of all those pieces of 3D data from all the pixels results in the full 3D scan.

Caltech's concept allows for the development of a tiny and relatively cheap scanner without sacrificing the accuracy. Dyman & Associates Risk Management Projects reported that the new chip can create scans that closely resemble the original within microns.

At present, the prototype Caltech has made only has 16 pixels on it, just enough to scan small objects such as coins, but they are reportedly working on scaling it up to thousands of pixels.

Tuesday, February 17, 2015

Dyman & Associates Risk Management Projects: 10M Passwords Publicized For Research

We've all heard of this before: a hacker releasing a certain number of passwords and usernames, presumably just for the lulz. But this time, we're talking about 10 million records posted by no less than a security specialist himself.

Security expert Mark Burnett has published 10 million sets of usernames and passwords online in an effort to equip the security sector with more information, while also getting himself potentially tagged as a criminal.

He clarified that his release of the username-password list is solely for white-hat purposes -- to aid research in making login authentications more effective and fraud-proof. Burnett insisted that he does not intend to help facilitate any illegal activity or defraud people by his actions.

"I could have released this data anonymously like everyone else does but why should I have to? I clearly have no criminal intent here. It is beyond all reason that any researcher, student, or journalist have to be afraid of law enforcement agencies that are supposed to be protecting us instead of trying to find ways to use the laws against us," he said in his post.

Leaking a massive amount of user data into the wild certainly does not sound like great help for most people but for security professionals, it's an important tool for research. For instance, how else would they know that online users are generally bad at choosing passwords?

In his post, he shared that he would often get requests for his password data from researchers but he would just decline them before. But since he also know its importance, he decided to publish a clean data set for the public.

"A carefully-selected set of data provides great insight into user behavior and is valuable for furthering password security. So I built a data set of ten million usernames and passwords that I am releasing to the public domain."

To be fair, Dyman & Associates Risk Management Projects confirms that analyzing a username-password set seems to be more helpful for the security researchers.

According to him, it was by no means an easy decision but he eventually posted it after weighing down a number of factors. And though Burnett said he believes most of the data are already expired and unused, the domain part of the logins and any keyword that could link it to a certain site were still removed to make it difficult for those with criminal intent.

Besides, Dyman & Associates Risk Management Projects experts agreed with him in saying that if a hacker would need such a list in order to attack someone, he's not going to be much of a threat.

Burnett has previously helped in collecting the recent list of worst passwords to alarm people into adopting better practices when it comes to their login credentials.

Lastly, he imparted the following warning for complacent users: "Be aware that if your password is not on this list that means nothing. This is a random sampling of thousands of dumps consisting of upwards to a billion passwords."

Sunday, December 28, 2014

Dyman & Associates Risk Management Projects: Boeing Black: the phone that 'self-destructs'

Another treat for sci-fi fans: a highly secure smartphone that 'self-destructs' is now being offered by BlackBerry and Boeing after 2 years of painstakingly developing the tech.

Well, it's not something that literally destroys itself or anything flashy like that -- it's more in the lines of scrubbing all data from the phone even when traces of tampering are detected. Does not sound too cool after all but you can be sure it does the work just fine.

Apparently, the phone dubbed as "Boeing Black" is capable of deleting all data it contains once it detects tampering or any attempt at disassembly. According to an expert from Dyman & Associates Risk Management Projects, "...any attempt to break open the casing of the device would trigger functions that would delete the data and software contained within the device and make the device inoperable."

The Boeing-BlackBerry collaboration which was announced last week is a pretty good partnership considering the mobile company's leading role when it comes to security and privacy features.

The announcement came from BlackBerry's CEO John Chen. He said, "We're pleased to announce that Boeing is collaborating with BlackBerry to provide a secure mobile solution for Android devices utilizing our BES12 (BlackBerry Enterprise Service 12) platform."

Aside from the so-called "self-destruct" feature, there are other useful features added on Boeing Black like biometric scanners and encryption programs for a more secure line that prevents eavesdropping. Also, it has dual SIM capability, presumably to accommodate easier switching between commercial and government networks. It can even connect to satellites via a modular expansion port.

According to an update from Dyman & Associates Risk Management Projects, it is going to use BES12, a security platform usually dedicated for businesses. It is also reported to run on Android OS with encrypted storage and data transmission. This is definitely welcome news for governments as it makes it easier to keep tabs on their staff's communication lines.

As of yet, it is not known when the said phone will be available though Boeing has reportedly started providing some to prospective customers. And knowing that Boeing has been a long-time space, weapons and jet provider to the government, it's obviously offering it first to staff of the Department of Homeland Security or Pentagon.

Though BlackBerry and Boeing apparently built the phone mainly for government use, it's not far fetch to think that they could bring the same tech to the public. Why should you care? Well, it's quite obvious that smartphone security is a big issue so its users are always on the lookout for options to secure their data. And a phone that can self-destruct sounds just about right.



Monday, November 17, 2014

Dyman & Associates Risk Management Projects: Google Lease Navy Base for 60 Yrs

Google has secured the lease of a NASA airbase in San Francisco for 60 years, possibly to house their upcoming space-exploration vehicles and robotics research.

The agency's press release at Dyman & Associates Risk Management Projects indicated that the lease, which will cost the tech giant $ 1.16 billion, is for " research, development, assembly and testing in the areas of space exploration, aviation, rover/robotics and other emerging technologies".

NASA Administrator Chris Bolden said, "As NASA expands its presence in space, we are making strides to reduce our footprint here on Earth."  He added that the agency wants "to invest taxpayer resources in scientific discovery, technology development and space exploration – not in maintaining infrastructure no longer needed."

According to the report, a real-estate offshoot of Google called Planetary Ventures will be managing the Moffett airbase and will take over the $200 million improvement to the site, which includes educational facilities to let the public "explore the site's legacy".

The 1,000 acres of airfield in the southern part of SF Bay  include two runways, a golf course, office space, NASA's Ames research center and three hangars, one of which is the iconic Hangar One. It's expected that the agency will save around $6 million worth of operation and maintenance expenses per year because of the lease.

Hangar One is one of the biggest freestanding edifice which covers 8 acres and was constructed in the 1930s for US naval airships. In 1966, it was recognized as a US Naval Historical Monument but has recently been placed as an endangered historic place according to a Dyman & Associates Risk Management Projects' press release.

“GSA was proud to support NASA in delivering the best value to taxpayers while restoring this historic facility and enhancing the surrounding community," said Dan Tangherlini of the US General Services Administration.

The Moffett lease shouldn't really come as a surprise as it's practically  just next to Googleplex HQ. In fact, it's already servicing private jets owned by the company's executives such as Sergey Brin, Larry Page and Eric Schmidt.

Both Brin and Page, the firm's co-founders, are evidently interested in space exploration and aviation as shown by their X Lab's Project Loon and Project Moonshot. Their company has also acquired satellite and robotics firms recently such as Meka Robotics and Redwood Robotics.


NASA and Google have also previously teamed up in 2005 when the latter made office at the agency's research facility and launch a new lab.

Saturday, June 7, 2014

Dyman & Associates Risk Management Projects: 75% of mobile security breaches will result from misuse

With use of smartphones and tablets on the rise and sales of traditional PCs on the decline, attacks on mobile devices are maturing, says IT research and advisory firm Gartner Inc.

By 2017, the focus of endpoint breaches will shift to tablets and smartphones. And, according to Gartner, 75 percent of mobile security breaches will be the result of mobile application misconfiguration and misuse.

Common examples of misuse are “jailbreaking” on iOS devices and “rooting” on Android devices. These procedures allow users to access certain device resources that are normally unavailable — and remove app-specific protections and the safe "sandbox" provided by the operating system, putting data at risk.

Jailbreaking and rooting can also allow malware to be downloaded to the device, enabling malicious exploits that include extraction of enterprise data. These mobile devices also become prone to brute force attacks on passcodes.

According to Dionisio Zumerle, principal research analyst at Gartner, a classic example of misconfiguration is improper use of personal cloud services through apps residing on smartphones and tablets. “When used to convey enterprise data, these apps lead to data leaks that the organization remains unaware of for the majority of devices," he said.

The best defense for an enterprise is to keep mobile devices fixed in a safe configuration by means of a mobile device management policy, supplemented by app shielding and "containers" that protect important data.

Gartner recommends that IT security leaders follow an MDM/enterprise mobility management baseline for Android and Apple devices as follows: ask users to opt in to basic enterprise policies, and be prepared to revoke access controls in the event of changes.
Users who are not able to bring their devices into basic compliance must be denied (or given extremely limited) access; require that device passcodes include length and complexity as well as strict retry and timeout standards; specify minimum and maximum versions of platforms and operating systems. Disallow models that cannot be updated or supported; enforce a "no jailbreaking/no rooting" rule, and restrict the use of unapproved third-party app stores.

Devices in violation should be disconnected from sources of business data, and potentially wiped, depending on policy choices; and require signed apps and certificates for access to business email, virtual private networks, Wi-Fi and shielded apps.
IT security leaders also need to use network access control methods to deny enterprise connections for devices that exhibit potentially suspicious activity.

"We also recommend that they favor mobile app reputation services and establish external malware control on content before it is delivered to the mobile device," said Zumerle.

Mobile security trends will be discussed at the Gartner IT Infrastructure & Operations Management Summit 2014, June 9–11 in Orlando, Fla.

Friday, June 6, 2014

Dyman & Associates Risk Management Projects Malware: How to Prioritize the Alerts

In late May, online security firm Trusteer, an IBM company, raised alarms about a new online banking Trojan it calls Zberp. According to Trusteer, more than 450 global banking institutions in the U.S., the United Kingdom and Australia have been targeted by this malware strain, which combines features from Zeus and Carberp, two well-documented banking Trojans.

Just days earlier, global cyber-intelligence firm IntelCrawler warned of new point-of-sale malware known as Nemanja, which had reportedly infected retailers in nearly 40 countries.

And news about recent evolutions in the mobile malware strain known as Svpeng also has caused concern. In May, Svpeng was found to have evolved from merely a banking Trojan to a malware strain equipped with a dual ransomware feature (see New Ransomware Targets Mobile).

But with so many alerts about new and emerging malware strains and attacks, how should banking institutions respond? It's a growing challenge for information and security risk officers because one of the keys to mitigating cyber-risks is differentiating new threats from older ones.

What's Real?

While banking institutions have to take all emerging threats seriously, they should take most alerts issued by security vendors in stride, says financial fraud expert Tom Wills, director of Ontrack Advisory, a consulting firm focused on payments innovations.

"It's mostly hype," he says. "Every time a new threat shows up in the media, this is the first filter I run. More often than not, there's a vendor or two behind all the excitement."

The influx of warnings from security firms about new malware strains has bred unnecessary concern for some banking institutions, says Andreas Baumhof, chief technology officer at malware research firm ThreatMetrix. In most cases, existing detection systems will raise flags, even when new variants of malware are detected on a network or believed to have infected an end-user's device, he says.

Pointing to the most recent announcement about Zberp, Baumhof says banks and credit unions should not rush out to invest in new detection and defensive technologies.

"There is nothing new for this Trojan," he says. Most banks' and credit unions' existing online defenses are equipped to detect Zberp and other Zeus variants, he contends.

Advice for Banking Institutions

Analysts recommend banking institutions maintain ongoing dialogues with their core service providers and vendors about the latest threats, and ensure they adequately vet new providers and vendors before signing on for service.

Among their other top recommendations:

Understand how existing detection and threat-mitigation solutions are equipped to defend the network. "There is no 100 percent solution, but banks need to understand their exposure and current capabilities before they rush to react," to alerts about new attacks, says Al Pascual, who heads up the fraud and security practice for consultancy Javelin Strategy & Research.

Put the onus on service providers and security vendors to send out notifications of possible risks, says Shirley Inscoe, a financial fraud expert and analyst for consultancy Aite.

Always get second and third opinions before revamping a system or solution. "Always get multiple bids, research the suppliers with independent parties, such as industry analysts and vendor-neutral consultants, and check with peers," Ontrack's Wills says.

Ensure the IT and security teams have strategies in place for comprehensive risk assessments. "Refresh it [the risk assessment] at least once or twice a year to keep it current - the more often, the better," Wills says. "That way, you can make sure that any solution you buy makes sense in the context of your own company's unique threat and vulnerability landscape, and not some generic landscape. It's quite easy to buy security products that you don't really need."

Thursday, June 5, 2014

Dyman & Associates Risk Management Projects on Threat intelligence versus risk

Security officers who view threat intelligence and risk management as the cornerstone of their security programs may have advantages over peers who face constraints when it comes to taking advantage of the available data.

CISOs are generally tasked with evaluating security controls and assessing their adequacy relative to potential threats to the organization, and its business objectives. Their role in cybersecurity risk management -- the conscious decisions about what the organization is going to do and what it is not going to do to protect assets beyond compliance -- is still hotly debated.

The transition towards risk management is more likely for the 42% enterprises whose security officers report to executives (the board of directors or chief risk officers) outside of the IT organization, according to Gartner. The firm's analysts advise security officers to achieve compliance as a result of a risk-based strategy, but admit that "organizations have not kept pace."

Equinix started to build a customized threat intelligence program about five years ago. The International Business Exchange data center provider uses threat intelligence along with risk assessment to do its "homework" before the company invests its resources in information security or agrees to IT requests from departments with different priorities.

"It doesn't make sense to go and buy a piece of [security] equipment because somebody in sales and marketing says, 'This is a big deal for the company,'" said George Do, global information security director of Equinix, which operates colocation centers in 15 countries. "We have to vet it, and we have to understand: Is this really a threat? What are the threat vectors?

"Sometimes, there is this black orbit, and we are just there for the ride," said Do. "I am always very conscious of that, and I want to make sure that whatever we are spending resources on is truly managing risk."

Metrics that Do reports up the chain of command, starting with the CIO, include data from the last quarter and year on the number of critical instances -- compromised data or critical servers, for example. Because Equinix employees frequently travel all over the world, security incidents, such as malware or backdoors, involving employees' mobile endpoints (laptops and mobile devices) are tracked, as well as employee acceptable-use policy violations.

In addition to capturing incident data, the security team tracks metrics around any attempted cyberattacks against the organization, especially around the perimeter from firewalls, VPN servers and mobile device gateways. "We have a Palo Alto firewall where I can see that [data] very clearly," said Do. "I can present a very simple dashboard to any executive that shows: Hey, at any given second of the day we are being attacked by literally thousands of threats and the firewall is doing its job so it's not like we invested in this for nothing."

While threat intelligence is the foundational piece of risk assessment at Equinix, the use of intelligence data in the security industry is often ad hoc. "It has either plateaued or actually decreased," said Do.

"There are always two sides of the spectrum," he continued. "The companies that are very good at doing SIEM [security information and event management] and all of these intelligence pieces so that the more intelligence or data points that they've added to their infrastructure, the smarter they become."

But the majority of the security teams don't do that. "They are either mired in compliance checkboxes or chasing down shadow IT services. Or there are so many things going on in their universe that there are no resources, or time, left to focus on threat intelligence."

Wednesday, June 4, 2014

Dyman & Associates Risk Management Projects on Top 20 mSecurity Companies 2014

Leaders in Software as a Service (SaaS), Mobile Device Management (MDM) & Bring Your Own Device (BYOD) Security

Mobile devices have become an intrinsic part of everyday life, for individual consumers and large organizations alike. Consequently, the popularity of smart devices is an increasingly attractive target for cybercriminals with regards the potential value of personal data found on a device.

The increasing demand for mobile security software is seeing the emergence of security specialists offering solutions aimed at mobile as well as PC.

Established market players in internet security are adapting their services to mobile, while a number of new companies are specializing specifically in smartphone and tablet security. Solutions including software, device management and security as a service are looking to answer this nascent security demand.

The complex nature of the mobile ecosystem and the close affinity to the broader cyber security market has made the mobile security sector a relatively fragmented market, with overlaps between the different submarkets. .

 As a result, vision gain has determined that the top 20 companies in the global mobile security market account for $2.06 billion, or 58.9% of annual market revenue which illustrates a highly competitive and fragmented market.

Why you should buy Top 20 Mobile Security (mSecurity) Companies 2014: Leaders in Software as a Service (SaaS), Mobile Device Management (MDM) & Bring Your Own Device (BYOD) Security

Who are the leading players in the mobile security market? Vision gain’s comprehensive analysis contains highly quantitative content delivering solid conclusions benefiting your analysis and illustrates new opportunities and potential revenue streams helping you to remain competitive. This definitive report will benefit your decision making and help to direct your future business strategy.

Avoid falling behind your competitors, missing critical business opportunities or losing industry influence. The report assesses technologies, competitive forces and expected product pipeline developments.

Discover key Information in this 139 page report:

• Explore the top 20 mobile security (mSecurity) companies to keep your knowledge ahead of your competition and ensure you exploit key business opportunities
- The report provides detailed market shares along with revenues for the leading mSecurity companies, including original critical analysis, revealing insight into commercial drivers and restraints allowing you to more effectively compete in the market.

- Find 70 tables, charts, and graphs
- Let our analysts guide you with a thorough assessment of the leading players in the mSecurity market. This analysis will achieve quicker, easier understanding. Also you will gain from our analyst's industry expertise allowing you to demonstrate your authority on the mSecurity sector.

• Read exclusive interviews from 3 market leading companies
- By reading the exclusive expert interviews contained in the report you will keep up to speed with what is really happening in the industry. Don't' fall behind. You will gain a thorough knowledge on the mSecurity sector finding strategic advantages for your work and will learn how your organization can benefit and allowing you to assess prospects for investments and sales
- Bullguard
- AVG Technologies
- Kaspersky

Monday, June 2, 2014

Q&A on Dyman & Associates Risk Management Projects’ Involvement in Project Management

One of the main involvements of Dyman & Associates is in the field of Project Management. Here is a brief Q&A that will provide essential information about this service:

Q: What particular aspects of Project Management does Dyman & Associates engage in?

A: Here is a list of Dyman’s involvement in project management:

Remediation Project Management – Dyman assists companies comply with audit-process requirements to make them stay viable.

Data Center Transfer – Dyman reduces downtime risks on clients’ systems and unmet goals during data-center relocation within one site.

Business Continuity – Dyman assures clients of unhampered delivery of their methods and materials during disruptions in vital operations.

Business Impact Analysis – By measuring the viability of each application through extensive interviews within the organization and analyzing the internal and external Service Level Agreements, Dyman can determine the overall health of a company and provide ways for improvement.

Big-scale Technology Resets – Dyman helps clients avoid non-delivery of committed materials by improving cable plant, routers, switches, desktops, Wide Area Network, and others.

Q: Do Dyman & Associates’ consultants have enough experience?

A: Dyman & Associates Risk Management Projects senior-leaders have started from very humble beginnings; however, through the years, they have undergone sacrifice and applied diligence to succeed in both private and public sectors. With all their successes, however, they have maintained their focus on doing well and right, not just for their clients but also for the community at-large, and have continued to possess this attitude in their business and personal profession.

Q: Why do we need Project Management?

A: Unpredictability is at the root of Project Management. Many people simply muddle through from crisis to crisis without resolving the root causes of problems that constantly arise to disrupt operations. Project Management allows organizations to predict with greater precision when and how such potential obstacles occur and to implement the necessary solutions or adaptive measures to minimize or remove all threats to the targeted results and achieve sustainability and viable development.

If efficient Project Management is the main ingredient missing in your organization’s operations, call Dyman & Associates Risk Management Projects for assistance.

Sunday, March 30, 2014

Dyman & Associates Risk Management Projects on Hughes: Digital spying casts chill on global trade



WASHINGTON - Revelations about U.S. digital eavesdropping have fanned concerns about Internet privacy and may complicate U.S. attempts to write rules enshrining the free flow of data into trade pacts with European and Pacific trading partners. As more and more consumers and businesses shop and sign up for services online, the IT industry is working to fend off rising digital protectionism it sees as threatening an e-commerce marketplace estimated at up to $8 trillion US a year. “Restrictions on information flows are trade barriers,” Google’s executive chairperson Eric Schmidt said at a Cato Institute event last month, warning that the worst possible outcome would be for the Internet to turn into “Splinter net.”

The unease of U.S. technology companies has mounted in lockstep with rising worries overseas about data privacy. German Chancellor Angela Merkel — a target of U.S. spying — has called for a European Internet protected from Washington’s snooping. Brazil and the European Union plan to lay their own undersea communications cable to reduce reliance on the United States. And other countries are showing a preference for storing data on local servers rather than in the United States.U.S. President Barack Obama acknowledged this week that it would take time to win back the trust of even friendly governments.
Trade experts predict the United States will have to make concessions on data privacy in the Transatlantic Trade and Investment Partnership talks (TTIP) with the EU, and will probably not get all it wants in Pacific Rim trade talks either. “It is unfortunate because there were some good nuanced conversations happening before the spying allegations,” said Adam Schlosser, director of the Center for Global Regulatory Co-operation at the U.S. Chamber of Commerce. “But there is now a tendency to inappropriately conflate national security and law enforcement with . . . commercial privacy practices, which has put a damper on rational debate.”

The TTIP and the Trans-Pacific Partnership (TPP) talks are billed as next-generation trade negotiations, covering not only tariffs and goods trade but also common standards and goals in areas ranging from labour standards and environmental protection to intellectual property and data flows.

The last two issues are key for digital trade, which encompasses everything from U.S. cherry farmers selling direct to Chinese families via Alibaba Group Holdings’ electronic shopping platform to plane maker Boeing monitoring in-flight diagnostic data on-line. A 2011 report by the McKinsey Global Institute found almost $8 trillion changed hands each year through e-commerce, something that explains the keen interest IT firms and industry associations are taking in the trade agreements. According to data compiled by the Sunlight Foundation, the computing and IT industry has been the second-biggest lobbyist on the TPP, after the pharmaceutical industry. Industry groups such as the Software & Information Industry Association say free exchange of data is the key focus.

“For SIIA and its members, the most crucial issue in the trade agreements under negotiation is to get provisions permitting cross-border data flows,” said Carl Schonander, international public policy director at SIIA, whose members include Reuters News parent Thomson Reuters. BSA The Software Alliance, an advocacy group for the software industry has warned that TPP partners Australia, Canada, Chile, Mexico, Peru and Vietnam are among countries adopting or proposing rules banning or limiting companies from transferring personal information off-shore. This might mean U.S. companies have to set up local servers in every country.

“Data flows are the life blood of the digital economy,” said BSA policy director David Ohrenstein. “Trade agreements (must) ensure borders are open to data flows.” In an ideal world for IT companies, countries signing the TPP would promise not to impede cross-border data flows or make companies set up local servers. U.S-based lobbyists expect those provisions to make it in, possibly with exceptions, but say work is still needed to convince trading partners to promise that any new regulations, including on privacy, will not restrict trade unnecessarily.

In Europe, where the backlash against U.S. spying has been the strongest, policymakers want changes by mid-2014 to the Safe Harbor Agreement, which allows U.S. companies with European-level privacy standards access to European data. An opinion poll by the Atlantic Council and the Bertelsmann Foundation found rules governing cross-border data flows and the alignment of privacy protections were among the most contentious and important, issues in the U.S.-Europe talks. Atlantic Council vice-president Fran Burwell said it would be hard to get support from the European Parliament or countries like Germany without an agreement on data protection.

“I think the big concession that (the U.S.) will have to make will be in the data privacy area,” she said.Tension is also brewing over intellectual property. U.S. music, book and software companies see piracy of copyright material as the biggest threat to their exports, while companies like Google worry about being held responsible for the actions of clients on their networks. Data privacy group Electronic Frontier Foundation said proposals in draft TPP chapters would restrict flexibility in allowing fair use of copyright materials and encourage low-quality software patents by setting the bar too low.

A group of 29 smaller tech companies wrote to U.S. Senate finance committee chairperson Ron Wyden last week and warned against including harsher criminal penalties for minor copyright infringements in the TPP. The committee has jurisdiction over trade issues in the U.S. Congress. “Reddit is a platform the same way that the telephone is a platform,” said Erik Martin, general manager of on-ine news hub Reddit, one of the signatories to the letter. “To put so much burden on the providers to deal with problems from individual users is just really going to put a chill on investment and put a chill on innovation.”

Friday, March 21, 2014

Dyman & Associates Risk Management Projects: The Weakest Link in Security?


Hardly a day goes by without news of another data breach. It's safe to say that we live and work in risky times. But there's a growing recognition that cybercriminals aren't the only threat—or even the primary threat to an enterprise. "There's a far greater need to educate and train employees about security issues and put controls and monitoring in place to increase the odds of compliance," says John Hunt, a principal in information security at consulting firm PwC.

It's a task that's easier said than done, particularly in an era of BYOD, consumer technology and personal clouds. According to Jonathan Gossels, president and CEO of security firm SystemsExperts, it's critical to construct policies and security protections around two basic areas: malicious insiders and those who inadvertently breach security. "The best security program in the world can be undermined by ill-advised behavior," Gossels explains.

Construct effective policies. Surveys indicate that many workers are not adhering to existing policies. In some cases, they simply disregard them. "The thing that you have to keep in mind," notes Hunt, "is that policies must be clear, understandable and not interfere with the ability of people to get their work done." If an organization is struggling with non-compliance and shadow IT, then it may be time to reexamine policies, as well as the underlying systems and tools the enterprise has in place. "Many organizations have older policies that don't take into account today's tech tools, such as iPads and other portable devices," says Hunt. The policies should also extend to contract workers and freelancers, he notes.

Educate and train employees. One of the biggest problems, says Gossels, is weak passwords and workers sharing passwords. He recommends educating employees about the use of strong passwords. It's also essential to teach employees about increasingly sophisticated phishing techniques. And executives, including CEOs, make the mistake of clicking bad links. "When you receive an e-mail from the Better Business Bureau or a fax that looks legitimate, it's very easy in the rush of the moment to click it," says Gossels. It's critical that employees learn to hover over links. Some organizations also use simulated phishing and spear phishing attacks to identify careless workers. Finally, employees must understand the risks of using personal clouds, USB drives, and other media to share and store sensitive data.

Develop controls that match policies. It's one thing to introduce a collection of security policies, it's another to build controls that effectively enforce them. According to Gossels, any time an organization introduces a policy, it should also consider how to build in technical controls, preferably automated ones. "The less you leave things to humans and chance, the better off you will be," he says. That means using mobile device management and media asset management tools, two-step verification, encryption, endpoint security, and other security measures. It also means looking for so-called low and slow approaches that frequently fly below the radar. But, more than anything else, it means mapping threats to policies and security systems—and ensuring that tools are in place to wipe lost or stolen smartphones and tablets, when necessary. Hunt adds that it's crucial to consider, when adopting policies, how long it will take to build the matching controls. He sees often companies lagging by nine to 12 months—or more.


Monitor activity and access from all endpoints. There's a growing focus on monitoring the network and endpoints for unusual activity and odd behavior, Hunt explains. "If you detect activity that doesn't fit the norm of a person's role, then it's a good idea to take a closer look at the situation," he points out. In fact, even if an organization embeds role-based policies and controls in its IT systems—something that's generally viewed as a best practice—it's wise to monitor activity and look for anomalies. Networks and systems are particularly vulnerable during mergers and acquisitions and during transitions to different or new systems.

Wednesday, March 19, 2014

Dyman & Associates Risk Management Projects: Information, Disinformation and the Credibility Crisis

A large percentage of the American population no longer trusts mainstream news outlets either on television or in print. A June 2013 Gallup poll indicates nearly 4 out of 5 Americans among younger generations from age 21-64 cannot trust the major news networks, not when the likes of NBC and MSNBC are owned by General Electric, Comcast and possibly Time Warner in this age of super-mergers. Both the circulation and very survival of America’s news print organizations have shriveled or dried up completely.

Amongst the nation’s largest cities, few traditional newspapers are still left today. Even the perennial powerhouse dailies like the New York Times, Washington Post and LA Times have gravely suffered, and in an attempt to keep up with the changing times, years ago moved to the internet as their mainstay means of surviving the computer age. Time Magazine and Newsweek similarly have been forced to downsize with Newsweek permanently suspending its print circulation. In recent years’ Time Magazine in print has been reduced in size to a mere skimpy little shadow of what it once was.

To a significant portion of Americans, all the mainstream news corporations have been rendered state propaganda and disinformation tools for the US government. Indeed their embedded (alias “in-bed”) news reporting has become a cynical joke amongst the populace. Entertainment fluff and filler space have come to obscure and replace real news and real issues that vitally affect the well being, safety and concerns of the American public. The controlling powers behind mainstream media outlets have made a concerted effort to keep American citizens the last to know especially when it comes to world events and developments.

According that that same Gallup poll from last year, this growing distrust that Americans have towards mainstream news is only exceeded by their distrust towards big business, HMO’s and US Congress. Even last month’s Gallup poll shows President Obama’s approval rating dipping to an all time low of just 39% with the majority of Americans now disapproving of his job performance. This negative, across-the-boards view reflects both a generalized discontent and disconnect with today’s status quo power structure. And as a result, a mass exodus of US citizens have switched viewing their world through the known distorted lens of traditional news coverage to that of the world wide web, currently celebrating its quarter century anniversary this week.

Hence, in recent years a growing number of people have been turning to online sources as their primary means for news information and current world events. Despite unlimited numbers to choose from of websites portending to depict accurate coverage of domestic and international events, in today’s world the notion of objective, unbiased news coverage becomes highly suspect. Thus, an informed public must be extremely discerning when it comes to believing what is the truth and what are the lies based on propagandist manipulation. Ultimately individuals will naturally gravitate toward whatever sources of news best fit their particular biases and beliefs based on their world paradigm. So one’s sense of reality and truth about the world becomes both highly elusive and subjective, if not impossible to tease out and grasp.

To compound this already perplexing, complex problem, the systematic dumbing-down of America has produced a mounting population that all too frequently gullibly accepts either the spoon-fed deception and lies of mainstream media or often equally biased non-mainstream news outlets. For decades now Americans have been conditioned to no longer think critically and discriminately to sort out facts from fiction.

Creative questioning, exploring curiosity or daring to challenge authority is entirely absent from the current US public education system bent on homogenized conformity and socialization toward robotic compliance. And as a consequence, too many Americans blindly accept as gospel truth anything they read, that is if they still read at all, naively assuming it would not be fit to print on the internet, in books, magazines or newspapers or seen on TV, if it were not all true.


Monday, March 17, 2014

Dyman & Associates Risk Management Projects: Application awareness using data inspection

Executive Summary

The modern enterprise presents numerous challenges to IT security leaders, as it requires a diverse array of applications, websites, protocols, and platforms. Mobile devices are changing the fundamental composition of network traffic and introducing new types of malware, while consumerization trends such as BYOD are introducing new devices over which IT has little control.

To organize the chaos, IT must look beyond a network packet’s site, port, or IP address and determine a security posture that relies on the complete context of data usage. A deep, thorough inspection of real-time network data can help provide the content awareness required for the granular management that a flexible, modern enterprise requires.

This report examines the shortcomings of traditional security and management processes exposed by device proliferation, an increasingly mobile workforce, and a movement toward cloud applications. It also demonstrates how a deeper understanding of application data in transit can help IT build more-flexible, business-friendly management procedures that continue to provide security and efficiency without disrupting productivity. The report concludes with best practices for testing application-aware network-security devices to gain a greater understanding of the value they will provide when deployed onto the enterprise network.

Consider the following:

·         Traditional security and access controls are no longer capable of protecting enterprise networks yet continue to serve a purpose within a defense-in-depth strategy.

·         BYOD and other consumerization trends bring new threats to the enterprise that must be addressed by innovating network-security and policy management.

·         IT security leaders must validate and test these new application-aware network-security devices and identity-based policy-management systems.


Saturday, March 8, 2014

Dyman & Associates Risk Management Projects Cartoon: the climate contrarian guide to managing risk

A new cartoon created by John Cook illustrates the failure of climate contrarians to manage global warming risks


Climate contrarians want us to bet everything on the best case global warming scenario. That's a failure of basic risk management. Photograph: Erik De Castro/Reuters

Climate change is fundamentally a risk management problem. Whether or not you agree with the 97 percent expert consensus on human-caused global warming, there is an undeniable risk that the consensus is correct and that we're causing dangerously rapid climate change.

Frequently, climate contrarians argue against taking action to mitigate that risk by claiming the uncertainties are too large. One of the most visible figures to make this argument is climate scientist Judith Curry, who said in 2013,

"I can't say myself that [doing nothing] isn't the best solution."

This argument represents a failure to grasp the principles of basic risk management, as illustrated in the following cartoon.

The climate contrarian guide to managing risk. Created by John Cook

When it comes to managing risk, uncertainty is not our friend. Uncertainty means it's possible the outcome will be better than we expect, but it's also possible it will be much worse than we expect. In fact, continuing with business-as-usual would only be a reasonable option in the absolute best case scenario.

Doing nothing is betting the farm on a very low probability scenario.  It's an incredibly high-risk path that fails to reduce the threats posed by the worst case or even most likely case scenarios. This is a concept Judith Curry understood in 2007, when she wrote,

"The rationale for reducing emissions of carbon dioxide is to reduce the risk of the possibility of catastrophic outcomes. Making the transition to cleaner fuels has the added benefit of reducing the impact on public health and ecosystems and improving energy security ... I have yet to see any option that is worse than ignoring the risk of global warming and doing nothing."

Judith Curry of 2007 got it exactly right. Unfortunately she and her fellow climate contrarians no longer seem to grasp these fundamental principles of risk management.

Failing to mitigate global warming by significantly reducing greenhouse gas emissions is fundamentally equivalent to continuing to smoke cigarettes, driving without a seat belt, or refusing to buy homeowner's insurance. Each situation represents the failure to take action to reduce the risks of a very dangerous outcome.

Even if you personally have doubts about the 97 percent expert consensus on human-caused global warming and the threats it represents, there's a good chance you're wrong. You may also doubt the medical science consensus that smoking causes lung cancer, but acting on that doubt by continuing to smoke is a risky decision. The difference is that in the latter case, you're only risking the health of yourself and those in your proximity. In the case of global warming, you're risking the health of entire ecosystems and future generations.

From a risk management perspective, mitigating the undeniable threat of catastrophic climate change is a no-brainer. So let's stop delaying and denying and get to it.

To know more from Dyman & Associates Risk Management Projects, See:




Thursday, March 6, 2014

Dyman & Associates Risk Management Projects

Risk management is the identification, assessment, and prioritization of risks (defined in ISO 31000 as the effect of uncertainty on objectives, whether positive or negative) followed by coordinated and economical application of resources to minimize, monitor, and control the probability and/or impact of unfortunate events or to maximize the realization of opportunities. Risks can come from uncertainty in financial markets, threats from project failures (at any phase in design, development, production, or sustainment life-cycles), legal liabilities, credit risk, accidents, natural causes and disasters as well as deliberate attack from an adversary, or events of uncertain or unpredictable root-cause. Several risk management standards have been developed including the Project Management Institute, the National Institute of Standards and Technology, actuarial societies, and ISO standards.

Methods, definitions and goals vary widely according to whether the risk management method is in the context of project management, security, engineering, industrial processes, financial portfolios, actuarial assessments, or public health and safety.

The strategies to manage threats (uncertainties with negative consequences) typically include transferring the threat to another party, avoiding the threat, reducing the negative effect or probability of the threat, or even accepting some or all of the potential or actual consequences of a particular threat, and the opposites for opportunities (uncertain future states with benefits).

Certain aspects of many of the risk management standards have come under criticism for having no measurable improvement on risk, whether the confidence in estimates and decisions seem to increase. For example, it has been shown that one in six IT projects becomes a 'Black Swan', with cost overruns of 200% on average, and schedule overruns of 70%.

Introduction
A widely used vocabulary for risk management is defined by ISO Guide 73, "Risk management. Vocabulary."

In ideal risk management, a prioritization process is followed whereby the risks with the greatest loss (or impact) and the greatest probability of occurring are handled first, and risks with lower probability of occurrence and lower loss are handled in descending order. In practice the process of assessing overall risk can be difficult, and balancing resources used to mitigate between risks with a high probability of occurrence but lower loss versus a risk with high loss but lower probability of occurrence can often be mishandled.

Intangible risk management identifies a new type of a risk that has a 100% probability of occurring but is ignored by the organization due to a lack of identification ability. For example, when deficient knowledge is applied to a situation, a knowledge risk materializes. Relationship risk appears when ineffective collaboration occurs. Process-engagement risk may be an issue when ineffective operational procedures are applied. These risks directly reduce the productivity of knowledge workers, decrease cost-effectiveness, profitability, service, quality, reputation, brand value, and earnings quality. Intangible risk management allows risk management to create immediate value from the identification and reduction of risks that reduce productivity.

Risk management also faces difficulties in allocating resources. This is the idea of opportunity cost. Resources spent on risk management could have been spent on more profitable activities. Again, ideal risk management minimizes spending (or manpower or other resources) and also minimizes the negative effects of risks.

Method
·         For the most part, these methods consist of the following elements, performed, more or less, in the following order.
·         identify, characterize threats
·         assess the vulnerability of critical assets to specific threats
·         determine the risk (i.e. the expected likelihood and consequences of specific types of attacks on specific assets)
·         identify ways to reduce those risks
·         prioritize risk reduction measures based on a strategy


More from Dyman & Associates Risk Management Projects: