The Classification Framework
- A goal of this project was to produce a comprehensive document that evaluated all selected security guidance in the same manner, using the same criteria. The following approach was used to evaluate the guidance:
- Issuer
- Document taxonomy
- Circulation
- Goal(s)
- Information security drivers for implementing the guidance
- Related risks of not using or implementing
- Target audience
- Timeliness
- Certification opportunities
- Completeness
- Availability
- Recognition/reputation
- Usage
- CISM domain alignment
- Description
Instead, I took a step back to my ISO roots and chose to represent a common Entity Resource model for COBIT®, COSO, FISCAM, BS7799 Part 2 and the PCI VISA Data Standard CISP version 2. I reread an older document that offered reminder to the importance of common process and its language, the May 1998 NIST IR Process Specification Language[133]. What I did get from the exercise was a short list of standards worth normalizing in content.
The results were a leveled view of COBIT® 4.0, ITIL®2, FISCAM Appendix III, COSO – Internal Control Framework: Guidance for Small Business, CISP v.2.3 PCI Data Standard, NIST Special Publication 53, BS77992, ISO/IEC 17799:2000.
Here is my attempt to compare Apples and Apples. The snapshot is an interface used to establish best standard and mapped standards for design of security related assessments.
The database has evolved a long way since its early days. The list of source documents alone is incredibly long. All ERD and criterion referencing will be shared with the IIA’s AIC and the Standards Board of ISACA. There are a few more snapshots of the main interfaces in Appendix B. Using a rough schema, delivery to my organizations is slated for early next quarter and the results will exist under copyright to OASIS, ISACA and IIA.
Two men in suits on lunch break, reading newspaper, steps of legal building:
Man one: Did you hear Congress is amending Title 17 as a means to slow growth of “Mount Must Read™”
Man two: “It’s actually a two part ruling, first, “The New Idea Verification and Universal Encoding Act of 2006”, and a then lesser known “CFR 290-15a-b: Final Rule: On Maintaining Juice." The bite is in the Juice law.”
Man one: “Weird. I can’t believe I never heard of it?”
Man two “Juice makes it a federal crime to let batteries run dead in a Universal Translator."
Man one: “Those things run on batteries? My G-d, that’s insane!”
Man two: “Actually, this just amends ‘Dead Light Bulb in a Nuclear Research Facility Act of 1966’. You remember “don’t sit in the dark law." Congress had it tucked in some obscure chapter of Title 42, Public Health and Welfare.”
Naked without our tools
Auditors need to stay current in the proper use and deployment of applications, configurations and best practices in all aspects of technology. Technology management applications, agents and processes are a collective compliance toolbox, supporting evidence of best practice in enterprise frameworks and minimum networking and data management controls as legally required for Enterprise Management. We have to be current in benchmarks and standards defining all areas of IT best practice. Among the ocean of products claiming instant cures to every compliance ailment, are the very same invaluable resources that make it possible to perform the duties of technology management and audit.
Final thought, legal discussion among information auditors tends to over focus on three legal Acts, SOA, GLBA, and HIPAA. Our professional mandate includes knowledge of regulatory requirements as mandated in the context of our placement, be it industry, military, government or private sector. We are accountable to this requirement, not company Legal Staff. When the audit fails to consider legal requirements, the person on the hook is US.
Buyer beware
In Hollywood, national crisis quickly followed by high profile names filming six to ten versions of the same bad movie. They all release in the space of two or three months. No writers are called in response to the times, since these are just scripts in can, ready at any moment with a little hot water and crisis tweak. Executives start screaming “Tsunami sells”, “War is big”, “Get me a Corporate Villains” … and unfortunately, we all know they get what is demanded, and even worse these awful movies make money.
Good Movies don’t need popular crisis, and great products were great before SOX. Mature technology is born from engineering genius, business savvy, hard work and time. As for being a compliance product, just like the disaster movie outbreak, product vendors large and small, will use market opportunity to dress-up a failed idea, promise half baked solutions that never make it out of beta, and as IT auditors, we have to be the ones to recognize when it’s time to call fowl.
New Bait: Cartoon plan:
Two men in suits putting boxes on fishing pole hooks. Box says “All New SOX in Box”
One says to other “Why did you bother changing the box?”
The other answers, “We just do it to keep the fish from recognizing the same old bait?”
Second greatest hook of all time
In my opinion “Compliance” is the second greatest marketing hook of all time. Worsening the matter of articles lacking valid legal references is the marketing frenzy unleashed by the passing of Public Law 107-204, the Sarbanes-Oxley Act of 2002. Every technology product in the world can claim some form of “SOX remedy” with the greatest number of claims targeting Section 404. On its own, this is not a bad thing. Tools really do help companies comply with the need for internal controls. No matter the products original design, however, it became an all purpose “compliance hammer.” As for the target of advertising, every publicly traded company in the United States became a Sarbanes-Oxley “nail." A panicked public (whom I refer to as Fish, bait eaters and fish in a barrel) were undeniably hooked. Hopes for silver bullet compliance tool spawned even more legal babble and marketing hype.
Do these points have to contradict?
Standards and products created by public industry are equally as important as any created in audit organizations or government sanctioned research facilities. In fact, valid means for evidence in compliance often depends on the existence and proper implementation of every single one of these types of tools.
“People, Process and Technology” in today’s electronic economy is surpassed by the three T’s, “Techniques, Tools and Technologies[134]”. Organizations work to insure our ability to maintain credibility in markets, protect U.S. interests, safeguard our patents, but they would never be successful without business interests and substantial financial backing by both government and corporate funds. ISO, ANSI, NIST, IEC, BSA, OASIS, IIA, ISACA and AICPA work with and require corporate contributions, including the intellectual capital of their corporate sponsored private sector scientists and engineers. Simply stated, products don’t make a company compliant. Intelligent business models, however, include compliance requirements as part of any implementation, purchase and or product’s design.
COTS alone can’t save us
White papers explain design and use of product, and are meaningful components in the acquisition and control process. Solid IT companies invest heavily in research and design, giving priority to effective management of compliance requirements. The best companies care for their own compliance first, and that trickles down as a standard in service delivery. Understanding how products enforce compliance is what gives standards their power. We should applaud and support the use of BSA, OASIS, IEC and all efforts that remove U.S. barrier to trade. Understanding EMC, Oracle, Microsoft, HP, or IBM creates means for control in technology infrastructure is vital to our national strategy to secure cyberspace. Those are the critical white papers.
Tripwire for example, makes the automated change audit achievable in almost everything form PeopleSoft modules to instant alerts when a remote network devices is illegally added to an obscure branch office. The MKS toolkit, as another example, ensures via web interface rules based workflow and SDLC control for any type development practice. Serena adeptly manages financial roles and segregation of duties issues as a routine course of operations among shops using SAP. The issues of data retention are at the forefront of product offerings addressing many levels of compliance as cared for by such products as Centera, offered by EMC. Papers produced by, for and about EMC products offer insight to digital evidence, information retrieval and the consequence of violation when corporate practices fail to appreciate the complexity in the control of information.
You may be thinking this is where I sell out and slip you a bunch of infomercials. It is not.
Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics