Lowest Common Denominator

High School math is not often listed as a “critical thinking” requirement. It should be.  Halfway through the ninth grade, most of us learned how to reduce miles of numbers to their lowest common denominator.  No matter how large, any equation could be reduced according to a few simple rules.  I wonder what our task would be like if IT audit had been planned by Socrates and Euclid[107]?  Every standard would have applicable rules for the factoring, reduction and calculated probability of its impact to any organization.

Committees for audit organizations produce a list of authors whose names can be placed at the scene of every significant law and standard affecting IT over the entire digital age. Given generations of cross pollination, our major standard bodies share expression of a mission to simplify, de-duplicate and align information controls to one common framework of standards.  In spite of differing charters, they are all concerned with efficiency and effective controls. For example, in recent interpretive documents, the PCAOB and the FASB ask that we make it easier, not harder, to meet audit requirements. ISACA and IIA publications consistently consider the FASB[108] and PCAOB concerns over cost and waste by offering tools and resources designed to support the process of audit, to measure, benchmark and report, and to guide the selection of critical controls using a risk based audit management approach.

All groups agree that frameworks are resources made available to our audit strategy. They are not laws in of themselves. All committees share a valid concern for the oversimplification and misinterpretation of laws governing business and systems. Unfortunately, Euclid and Socrates aren’t here to help us.  We rely, in their absence, on ethical judgment in selecting the fewest requirements necessary to the attestation of control. The better we are in selecting a lowest common denominator of standards, laws and frameworks, the more we benefit our clients while reducing escalating and burdensome compliance costs.

The true test of those ethics is maintaining the intent of the law and being certain our method of reducing the numbers also keep those numbers real. Our challenge is to remember, no matter how long and complicated the equation, when we've found that lowest common denominator, it must still be the same number.

Reduction versus oversimplification is the essence of detection risk.  It is a legitimate and driving fear that keeps us from proclaiming an algorithm to reduce regulatory requirements. We must not cross the line between standard of practice and code, as if a practice were a mathematic law.  We are not served by “dumming down” the information problem.  So we are left with a truly ethical challenge: How do we reduce complexity and verify that at the end of the day, we still have the same raw number?

The GTAG, references two works reflecting summary of larger security standards.  They reduce complexity define standards for secure technology for specific areas of industry.  Both standards are widely used by merchants and educators, primarily those in the United States.  The Payment Card Industry (PCI) Data Security Standard, produced by VISA, enforces the management of credit card data and the protection for an industry that is constantly under attack[109].

Cartoon Plan: Commercial: […] is everywhere you want to be Private Incorporation: $1200. Printing and Marketing: $15,000. Web Site Shopping Cart: $30,000. Over 40,000 Verified Credit Cards transactions per day: Priceless. VISA, PCI Data Standard, is everywhere your electronic business wants to be.

How low can you go?

I recall having seen the VISA standard as a single file pulled back by a Google search.  Out of surrounding context, I initially felt the standard served no purpose, seeming to paraphrase a number of standards in the public domain, and lacking attribution or recorded peer review.  The Global Technology Audit Guide (GTAG) only needed to make one point to inspire me to dig out the standards from the stack and re-prioritize its reading.  The GTAG simply stated that the PCI VISA Data Standard is in wide use.

Definition for a “good” standard clearly needed an adjustment.  Is it more important to represent every security detail, or prioritize a high level list of concepts?  What we see in the PCI CISP, (aka CISP V2.3), is that merchants and electronic markets get it.

Even if it looked to me like an ISO Light, anything extending critical security practice to businesses engaging in poor data security, is at the very least “spot on.”

Maybe it’s “spot on” for another reason.  A small amount of digging for contributors to the credit card standards revealed the chairman of ISO TC68 SC2 Security Management and General Banking Operations, Mike Versace and Secretary Cynthia L. Fuller.  With biographies published in English and French, their efforts to assure financial industry standards and automation reap results that go way beyond humbling.  Ms. Fuller’s name leads to the “ISO 20022 Universal Financial Industry message scheme”, which can be viewed at ISO 20022 Financial Repository: Business Process Catalogue & Data Dictionary.  Mike Versace, in addition to full time industry position, travels world wide in support of numerous financial security standards. ISO delegates representing: Canada, United Kingdom, United States, Germany, France, South Korea and Japan include organization and business representation from CLEARSTREAM, IBN, MasterCard, SWIFT, UN/ECE, and of course, VISA[110].

Reviewing current works and the 34 published and current standards used in security and banking, as produced by this single TC, did not lower the height of Mount Must Read™.   The study of the VISA standard, however, provided a means for quick demonstration of compliance evidence is specific areas of data and retention management. The PCI Visa Data standard test procedure check list is clean, clear and achievable.

“Good things, when short, are twice as good”

Baltasar Gracián y Morales (1601-1658)

The more you know, the less you have to say

The second “short and sweet” standard, also listed in the GTAG, is the "Fundamental Five.”  I first heard of it while reading posts in the ISACA information security list service.  Mike S. Hines, a frequent contributor within many substantial information security organizations, made no mention of working on the project[111].  He simply asked me if I had seen the ISG Tool and if I knew about the work of the Corporate Information Security Working Group: CISWG.  This was a humbling day.  As current as this 2005 writing, they work to introduce the ‘‘Corporate Information Security Accountability Act of 2003.’’  The bill will further amend the Securities Exchange Act of 1934 with bolder restrictions controlling IT products on a scale that many find to be excessive.  Stating the need for “Internet Service Providers and Operating Systems manufacturers to work more aggressively with other public and private stakeholders to provide consumers of all levels of sophistication with information about affordable and user-friendly tools that are available to help them protect themselves and immediately improve their cyber security hygiene.” this act has potential to impact technology manufacturing with force equal to the wallop of SOX[112].

Produced by the subcommittee on Technology, Information Policy, Intergovernmental Relations and the Census, chaired by Adam H. Putnam, few efforts compare with the CISWG’s elegance in considering all best and current contribution to security, and compiling them to a single list; Information Security Management References.

The ISG Tool gives cyber security what the home pregnancy instant strip test gave to medical practice.  The Fundamental Five concept answers tell us fairly quickly if information practice is healthy or having problems.  No pretense of an easy fix or exhaustive technical detail is made.  IT control is simply made accessible to education, affecting practice as witnessed by our youngest minds, and in protecting our country's most valuable asset; our intellectual capital.

Fundamental Five

The Consensus Benchmarks, from the Center for Internet Security (www.cisecurity.org), provide guidance on the “Fundamental Five” of basic security hygiene.  Use of these benchmarks typically results in an 80 percent to 95 percent reduction of known vulnerabilities.

  1. Identity and Access Management (including privilege assignment and authentication)
  2. Change Management (including patch management)
  3. Configuration Management
  4. Firewalls (workstation, host, sub-network, and perimeter)
  5. Malware protection (including worms and viruses)[113]

TV News

“Information on Massachusetts Seismic and magnetic phenomena warned geologists that Mount Must Read™ had become unstable.  Fearing volcanic eruption, investigators gathered evidence pointing to a completely unexpected source.  The rise in temperature appears due to radiated humiliation, believed to come from a single source in Massachusetts.  Investigative reporting claims they’ve identified the Dog, saying she simply became aware of her own ignorance.  Scientists fear the single outbreak in spontaneous humility may be first signs of an epidemic.  Secretary of Education refused to comment.  More at eleven.  “

A simpler selection criteria

High school graduates use either MLA or APA standard in submission of writing and research[114].  Not meaning to compare a writing standard to the ISO template, smaller standards still accomplish many of the same goals with infinitely less complexity.  Provided by Leslie Murtha, to support her Rutgers students, a simple common criteria for evaluation of information resources lends value to how we might organize a collection of rated sources[115].  The points simply reinforce that resources be reviewed for Authority, Accuracy, Currency, Clarity, Purpose, and Content.

The IIA GTAG for information technology controls lists types of control framework, as applied to technology practice and its assessment by information systems audit.  The suggested grouping of standards included:

  • Systems Development Processes
  • Systems Software Configuration
  • Application Controls
  • Data Structures
  • Documentation

Perhaps the bite size model won’t satisfy all appetites, but it certainly organizes a broad view of current thinking.  My experience using ITIL® Service and Infrastructure framework and COBIT’s 34 domains for IT control left me feeling this list is not going to carry me to lunch. Being a collector, I’ve squirreled away 200 process titles and flow diagrams in a Facilitated Compliance Management™ (FCM™) tool.  Normalizing process by aligning ITIL® functional domains and COBIT®y IT and application controls, provides a baseline for mapping process to standard, supporting visibility over process architecture, and documenting compliance in activities throughout business and systems management.  I’m part rescue Dog.  Like most rescue dogs, my mission has been bringing relief to one stranded victim at a time.  Maybe spending October through December of 2005 in “recovery” exposed me to a few too many FEMA failure and Katrina devastation news reels. Perhaps it was the night I stayed up to watch “Enron: The Smartest Guys in the Room” (see the Roger Ebert summary for more information), but my sense of personal contribution had shrunk to complete insignificance.  A feeling of utter urgency to push audit and standards to a stronger level of automation and implementation became paramount.

Even after ISO creates the classification schema for the catalogue of standards, we will still need a universal standards blood bank.  Highlighting all distinct types, as we do with our national blood bank, our standards would form a configuration database.  This standard CMDB would facilitate the baseline allowing us visibility over what we have and what we need, establishing status regarding our effort to keep current with other countries and reveal any potential for yet another moral and technology standards driven crisis.

A common criterion for evaluation frameworks of information standards and would have to operate independently of infrastructure or industry.  Its greatest challenge is simply the ability to correctly represent the problem.  All control assessment frameworks begin with a context, be it geographic, legal, technical or social, because there is no such thing as compliance unless it answers the question: “Compliance with what?”

The closest all encompassing framework, spanning tremendous size, considering enormous number of business and social conditions, leveraging centuries in contributed wisdom by the world's greatest minds, is the United States Code - Fifty volumes of Federal Regulation.

How did I miss the Common Criteria?

Any valid comparative technology standard points to work by NIST and CISWG, but even they are limited by the context of the United States legal parameters.  Leading the pack in attacking the picture are the collective members responsible for the ISO/IEC 15408 International Standard; Common Criteria for Information Technology Security Evaluations[116].  Seven government organizations, known as “Common Criteria Project Sponsoring Organizations” grant ISO/IEC a non-exclusive license to provide the standards for purchase:

ISO/IEC 15408-1:2005 Ed. 2 Current stage 60.60 JTC 1/SC 27

Information technology -- Security techniques -- Evaluation criteria for IT security -- Part 1: Introduction and general model

ISO/IEC 15408-2:2005 Ed. 2 Current stage 60.60 JTC 1/SC 27

Information technology -- Security techniques -- Evaluation criteria for IT security -- Part 2: Security functional requirements

ISO/IEC 15408-3:2005 Ed. 2 JTC 1/SC 27

Information technology Security techniques, Evaluation criteria for IT security -- Part 3: Security assurance requirements ISO/IEC 15408-3:2005

The standards are also available at the ITTF web site.  ITTF endeavors to supply a solution for the uniform evaluation and certification of technology products. ISO/IEC Information Technology Task Force (ITTF) web site provides a great deal of information.

With all the reading I’ve done in the area of SAS 70 and Systrust, I don’t understand how I missed product based certification.  Although the standard does not extend to all areas of technology, I would not use a network product in the future, unless it aligned to this certification.

How did we miss Common Criteria for Product Evaluation?  Feeling like a Dog caught drinking from the toilet bowl; I immediately began to explore everything on the site.  The write-ups on product testing provide unbiased simple assessments in a manner infinitely more impacting than the white papers primarily written for advertising.  Even if the words are exactly the same, reading it here means the study counts.  Organization of products provides an interesting ontology for the review of technology control resources.

  • Access Control Devices and Systems
  • Boundary Protection Devices and Systems
  • Databases
  • Data Protection
  • Detection Devices and Systems
  • ICs, Smart Cards and Smart Card related Devices and Systems
  • Key Management Systems
  • Network and Network related Devices and Systems
  • Operating systems
  • Other Devices and Systems[117]

I ‘d love to say that my addiction to reading Cliff Notes, saving files and printing is now conquered, but that would be a BIG FAT LIE.  Even as a Dog, I couldn’t swallow that I’d never seen this before.  A full text search showed the files had not been downloaded to my hard drive or network.  I marched over to Mount Must Read™ and began to take him down by chunks. “Why don’t you have these files?” I recall saying in a crazed stammer.  I had to touch these, feel them as paper and ink.

Realizing the potential for reams of new reading, it was clear I’d need two pots of coffee and a really good sponsor.  I medicated with 20 pages, the Introduction to Common Criteria, and uninstalled all the printers.

           

Main Menu