Where are you taking me?

OASIS teams, such as the TC members of SAML, represent a vast array of business, government and industry contribution, with representation from W3C, ISO, IEC, ANSI, and BSA, just to start.  SAML is in use, is valuable and is current to the recent year.  The interpretation this or any standard, however, suffer common vulnerabilities.  As with any standards body or TC, it may miss adopting best criteria simply for a lack of correctly representing a problem, caused for example, by a lack of involvement with an outside organization.  While the OASIS processes for standards development is highly successful, it is by virtue of contributing members, commitment, consensus, and a broad distribution of stakeholders.  SAML is one of the best standards in our time.  OASIS is an amazing collection of people and thinkers.  It is not, however, immune to obsolescence, lost efficiency or redundancy.

OASIS is a model for standards evolution.   The following is a 2005 list of the technical committees:

  • Adoption Services
  • Computing Mgmt
  • Document-Centric
  • E-Commerce
  • Law & Government
  • Localization
  • Security
  • SOA
  • Standards Adoption
  • Supply Chain
  • Web Services
  • XML Processing

The standards adoption offers sound advice in the evaluation of newly developed standards, their use and quality.  There are no “buts” in my statement of support to OASIS. Unfortunately, we are left to stringing all these standards together and subject to the limits in each technical scope.  In the absence of a uniform ontology for the classification of all existing comparative and or potentially redundant standards, we are still facing the same challenge of recognizing apples for apples and oranges for oranges[125].

“Warning, The content you are about to read will soon expire. Content warranty for information pertaining to the classified #domain# is best consume by #date#, and set to expire in 30 days, 22 hours, 12 minutes, 35 seconds. Recommended sources for #domain# competency as required by your professional profile are [list]. Would you like to proceed?

Honest Doc, I looked everywhere.  No expiration date.

Like most dogs, anything I can chew and swallow, is labeled “food.”  I don’t generally confirm that a hyperlink is the best or most recent source for any type of information.  I’ve only recently made a habit of reading dates and source code on most web sites.  Even the most reputable sources, such as Common Criteria Portal and NIST, provide a few dead links.  No one organization is dedicated to or has the scope to recognize everyone else’s expiration date.  It’s not deliberate.  Most portals come with disclaimers.  The Common Criteria Evaluation Portal is under the NIST domain.  The disclaimer reads, “Any mention of commercial products within NIST web pages is for information only; it does not imply recommendation or endorsement by NIST.”

In the absence of distributed accountability and liability agents, everyone’s afraid of definitive answers.  As a result, there’s no mandate to label expiration by concepts.  Words like “to the best of my ability” and “not an endorsement” have become excuses to for even a few Human beings to slip back to the realm of sheep.

A universal schema to manage the expiration of ideas may sound like a Roddenberry plot.  Broadcasting over 80:80, a best practice validation algorithm, provides a warning beacon based in an authors or organizations current positional authority to claim guidance in any domain.  Wouldn’t it be great if we had an automated agent screening a document on launch and providing guidance on content relevance?  Imagine an agent that could say:

Darker and deeper

We have standards for submitting written works, research design, chemical and products, and even requirements that require creation of more standards[126].  I was starting think Mount Must Read™ had called in a ringer, a seedy underworld association from his days with snakes, pigs and rats.  I could sense all this reading taking me down a dark alley.

Sucked in by detail

There’s a reason that Eagles fly at a thousand feet in the air.  The choice is fly fast or fly low.   Try to do both and you slam against a wall.  This reality poses an interesting dilemma.  If Eagles can’t think on a scale of detail that is both miniscule and grand, how do the detail thinkers work with the visionaries, and vice versa?

Get to higher ground

We have consensus among nations that we need to use same standards.  The process of evaluating the quality of a standard, or a process to force repeal preventing use of an outdated standard, to date, doesn’t appear to exist.  We just have to stay sharp and pay attention the signals sent from Eagles.  To the extent that a number of industries staked claim in known standards, by spinning content and then enforcing their own version like law, this is probably not a bad thing[127].

Performance Management may hold the substance of all our answers.  Like many auditors and IT professional, my career has included time analyzing configurations, change logs, network traffic data, entity diagrams and rule based access schemes.  Attempts to explain, interpret, or validate the information resulted in wall charts far larger than my cube or office.  The focus in measuring trend and performance began as a means for product and network management, and became foundation material for security and technology controls audit.   Every network manager became marketing and audit’s best friend.  There was one problem.  No one could consistently articulate the problems needing to be measured and reporting queries grew out of control.  There was another problem.  As SNMP traps and MIB technology became increasingly mainstream, trend reporting became increasing efficient in piping and pushing virtually all that is digital and accessible from inside and even outside of any corporate WAN.  The tools became a liability and in some cases, poor implementation included storing confidential data in clear text, and unrestricted access to information causing damages at staggering costs.  Network managers became targets of disproportionate concern.  Surpassing the need to measure and trend information, both enterprise and business began to call for a common visible implementation of controls aligned to sustainable compliance architecture.  Engineers have been telling us this for years.  We can measure everything, but interpretation call for context.

Regulatory mandates have spawned more than a few pearls of wisdom.  One such jewel is the GRC model, introduced in 2004 by “Integrity Driven Performance; A New Strategy for Success through Integrated Governance, Risk and Compliance Management.”  The GRC, a trade mark of PricewaterhouseCoopers[128].

Bound and less than 50 articulate pages, the concept of GRC furthers definition and design model in a Governance Risk Compliance (GRC) framework.  Freely available and posted on line, the GRC deserves rank as a “Must Read™”, and I also  suggest that being well rounded include attention to all publications offered by PwC, as well as their newsletter option at CFO Direct[129].

The Emerging Role of Technology: Enabling GRC - an advanced level of deployment, technology can be likened to a central nervous system for the organization – the means to ascertain, in real time, that risk is being managed and events are being acted upon.  Organizations that achieve a real-time risk management, compliance, and monitoring environment enable the application of policies and standards at the time business processes are executed.  For compliance to be truly effective it must be not incremental, but integral to business processes – the essence of real-time risk and compliance.

Integrity-Driven Performance™ is a “Must read™.”

Open the computer bay, HAL[130]

Creating a catalog of standards such that elements can be organized by a single ontology will take a lot of vision and team work.  In spite of the outstanding efforts toward security and standards harmonization as coordinated by ITGI and the evolving common security frameworks as produced by teams including ISO/IEC, OGC, OECD, SEI, NIST and others, a single framework for comparison of all standards is still limited at least the following factors:

  • Team success tends to require and be limited by perception of specific technical context
  • Creation and adoption of standards and regulations tend to have basis in industry specific use case
  • We see both problems and solutions with the limits of existing vocabulary.
  • It is easier to solve a problem in isolation than to consider all the relevant and existing efforts completed by others to solve the same problem.

Maybe our next evolution will be automation and real time control information governed by independent “decoupled” authority.  Perhaps we will dynamically tie to ISO/IEC/ANSI classified objects and build the correct answer through consistent selection of rules for any item’s construction.  Best practice according to NIST, CERT, SANS may someday be delivered via BPEL compliant schema implementing business and legally verified terms of acceptable use.  Being neither Wolf, Eagle or even Human, all I can do is contribute to organizations like OASIS, itSMF, IIA and ISACA.  If I’m lucking this won’t distract real intelligence, and if we are all lucky, we will be solving the right problem.

After a month of frustrated attempts to use my Dog size brain to grasp a standards for IT audit ontology[131] the limits of my efforts took shape.  What can we offer in the area of best approach, without a framework database, normalized criteria, common process contents and updated legal and risk based audit requirements?  Given 270,000 registered standards, no one sees the entire picture but that shouldn’t keep us from using a system of placeholders aligned to best sources based in our audit context.

Until medical science establishes an Object Oriented brain chip that can transfers intelligence using such principles as inheritance, any single instance of vision is as good as any individual or teams best representation at any single point in time. Efforts observing how people solve a problem produce grains of goodness.  As for duplications of effort and papers that seem to overlap, I realize now that overlap is the greatest indication that we have found common wisdom so far.  Located in Appendix A, a screenshot shows the database and supporting tables that help me to see what’s important to audit competency and how I track sources across domains of technology, audit and law.  Since the content lacks formal body professional review, I make no claim of assurance that content is either comprehensive or complete.  It’s what I do to tackle my own ignorance, and maybe you will find its design useful.  Unfortunately, the greatest tools are the one’s we build.  The act of construction counts for almost all of our learning.  That’s why we have to let baby organizations live.

As a part of learning and a way to increase design clarity, I tried to fairly compares publications for a common elements (ontology), selecting for the study ten substantial contributions to current thinking in security and risk management.  Of course this failed.  It took several months to align NIST SP 800 53, FISCAM and COBIT®, and that was using freely provided templates and database[132].  It would take me at three months consume the Common Criteria and I’ve just now finished the PCI VISA standard (which I once thought small, and now view as a substantial undertaking).  Fortunately, the failure was in my arrogant belief that the problem had not already been solved by larger and more qualified teams.  I still got my answers.  They just didn’t come from me.

Produced in March 2005 by Information Systems Audit and Control Association®, Information Security Harmonization— Classification of Global Guidance is primarily authored by Leslie Ann Macartney, CISA, CISM, UK.  The publication includes all of the security and risk management documents I felt were critical to audit, and additionally involves a highly respected team and approach to their organization and comparison.

Scope

Selections based in common and generally accepted authority in security and risk management, included the following works.

  • BS 7799 Part 2:2002 Information Security Management Systems—Specification with Guidance for Use is a specification for an information security management system.
  • Control Objectives for Information and related Technology (COBIT®), published by the IT Governance Institute, represents a collection of documents that can be classified as generally accepted framework and standards for IT governance, security, control and assurance.
  • Systems Security Engineering—Capability Maturity Model (SSE-CMM) Model Description Document 3.0 is a guide to the concepts and application of a model to improve and assess security engineering capability.
  • Generally Accepted Information Security Principles (GAISP) is a collection of security principles that has been defined and produced as a collective effort by members of the organizations involved.
  • The Information Security Forum’s (ISF’s) Standard of Good Practice for Information Security is a collection of information security principles and practices.
  • ISO/IEC 13335 Information Technology—Guidelines for the Management of IT Security, released by the International Organization for Standardization and the International Electrotechnical Commission, is technical guidance subdivided into five parts which provide guidance on aspects of information security management.
  • ISO/TR 13569: 1997 Banking and Related Financial Services—Information Security Guidelines, released by the International Organization for Standardization, is a grouping of security concepts and suggested control objectives and solutions for financial sector organizations.
  • ISO/IEC 15408:1999 Security Techniques—Evaluation Criteria for IT Security is based on the Common Criteria for Information Technology Security Evaluation.
  • 0 (CC). ISO/IEC 15408:1999 is used as a reference to evaluate and certify the security of IT products and systems.
  • ISO/IEC 17799:2000 Information Technology—Code of Practice for Information Security Management is a collection of information security practices.
  • The IT Infrastructure Library’s (ITIL®’s) Security Management is a methodology describing how IT security management processes link into other IT infrastructure management processes.
  • NIST 800-12 An Introduction to Computer Security—The NIST Handbook, released by the US National Institute of Standards and Technology (NIST), describes the common requirements for managing and implementing a computer security program and some guidance on the types of controls that are required.
  • NIST 800-14 Generally Accepted Principles and Practices for Securing Information Technology Systems is a collection of principles and practices to establish and maintain system security.
  • NIST 800-18 Guide for Developing Security Plans for Information Technology Systems provides a format and guidance for developing a system security plan.
  • NIST 800-53 Recommended Security Controls for Federal Information Systems provides a set of baseline security controls.
  • Operationally Critical Threat, Asset, and Vulnerability Evaluation SM (OCTAVE) is a set of principles, attributes and outputs for risk assessment.
  • Organization for Economic Co-operation and Development (OECD) Guidelines for the Security of Information Systems and Networks provides a set of nine information security principles aimed at fostering a “culture of security”.
  • Open Group’s Manager’s Guide to Information Security is a booklet providing general guidance for IT managers on acquiring secure IT products and systems.
Main Menu