Today hundreds of small businesses experienced web site
outages. Go Daddy, the most popular domain registrar/web hosting company, saw
its DNS servers attacked after 10AM Pacific time. The alleged attacker claimed
to be working alone, to have taken down the entire Go Daddy DNS array and that
he wanted to test the cyber security. DNS servers on the web are what translate
the name of a web site (such as www.godaddy.com)
to the numerical address assigned to it. Find a more detailed explanation of
DNS here
Monday, September 10, 2012
Monday, August 13, 2012
You’ve Been Hacked?
Yes, it can happen. It’s almost inevitable. So what can you
do to prepare for the discovery that your systems have been successfully
compromised? What plans should you have in place for communicating with law
enforcement? Do you collect financial information from your customers? If you
do, you must have a plan in place for notifying them of a breach.
Tuesday, June 5, 2012
What The Heck is That?
So you decided to do an internet search on Business
Continuity – and the sites you came across spoke a language you’ve never heard!
As in any industry, the BC/DR community has its own jargon. Here’s a breakdown
of a few terms used in the early planning stages.
Business Impact
Analysis (BIA) is a term that is tossed around a whole bunch in reference
to business continuity planning. The BIA is generally done at the beginning of
the planning process and the plan is based around its information. During the information gathering phase of the
planning process, the Business Impact Analysis determines the processes,
resources and assets that are necessary to the health of the business, how they
depend on each other, and the criticality of each.
Recovery Time
Objective (RTO) is determined for each process – how soon do we need this
process up and running, and how soon do we need it at full capacity after an
incident. In some cases, the RTO can be a staged process that might include
temporary workarounds until all of the resources needed for the full process
are restored. Perhaps your organization has a sales process that utilizes a
rather large database. The database has an ordering system built into it so
sales personnel can track what a customer purchases, how often the purchases
are made, the quantities, and other information that assists them in the sales process.
The IT department needs to know from the sales department how quickly their
database needs to be back up if the servers hosting the database go down – and
the sales department needs to know from the IT department how quickly it can be
done. The gap between the two times then requires a plan to provide minimum
service to the customers while the database is being brought back to full
capacity.
Recovery Point
Objective (RPO) is determined for data – how much data can we afford to
lose? Is it one hour – or one week? The determination depends on how quickly
your organization can rebuild the data that is lost. If you have a process that
only gathers data once a week, then it will have a longer RPO than a process
that has thousands of lines of data entered every day. For example – though
your payroll process is important to getting the employees paid, it might only
need to be run twice a month, and doesn’t change often in between. However,
your sales staff communicates with 200 customers in a day, and places orders.
The reconstruction of the sales database would require calling all of those
customers in order to get their orders back. So a day’s data would set the
sales department back a lot more than it would the payroll department,
depending on when the failure occurred. Backups for the sales data would need
to be done daily or more often, where backups for payroll would only have to be
done as new data was entered.
An Incident is
any unplanned interruption that has the potential to affect any business process.
This can include anything from a major disaster to just a failed backup. Even
though the backup might not be needed at that precise moment, there is still
the possibility that it could affect a process.
These definitions will help sort out some of the information
found on the web, and perhaps in the event you decide to hire a consultant,
help you to begin to understand their explanation of their services.
Tuesday, May 15, 2012
The Living Plan
So you’ve put together a plan. Really. It’s that binder
sitting on the shelf above your credenza. If anybody asks if you have one, you
can point at it and say “yes, we have a plan!”
Saturday, May 5, 2012
Day Two, IVNUA
I spent the morning of the second IVNUA day in Loyal Moses’
sessions learning what he had to say about situational awareness. Having situational awareness in Information
Security is about being aware of the network, the users, the threats and the
tools. Loyal warns us to use caution to avoid information overload, overkill or
over-focus. All of those things reduce our situational awareness. Using
automated tools can help avoid overload, overkill and over-focus.
| I attended 2 of 3 sessions presented by Loyal Moses |
During a break, I asked Loyal what he thought about
Suricata, and he replied that Aanval is already written to work with Suricata,
and that most applications that are built around Snort can work with Suricata
with just a few tweaks.
My first afternoon session was a session on iBook publishing.
The instructor was Jerry Johansen, from the Rock Island Regional Office of
Education. Yeah – this isn’t an information security session… but I am working
on a book, and exploring possibilities for publishing. I’m thinking iBook is
not suited to my book. For teachers who have students using iPads in the
classroom, the iBook can be useful. But the books can only be read on Apple
products, and unless the book is to be distributed for free, it has to be sold
through the iTunes store. My audience should be able to view the book on any
product, and I would like to be able to sell it both as an ebook and as a hard
copy. But the session was informative – and I can see how iBooks can really
open new avenues in education.
The final session of the day was Kevin Remde’s “How I built my
Private, Private Cloud”.
Kevin gave a good (if not fast) run through of setting up a
virtual network using Windows server and Hyper-V. In fact, the entire private
cloud was built using available free evaluation software, and he used older
hardware for his builds. Of course, there are some minimum requirements for
virtualization, so the hardware can’t be super old… but it is possible to build
a virtual network for evaluation purposes from available free software, on
available hardware that is virtualization-capable.
This year’s IVNUA Spring conference was a huge success. The
sessions were amazing – I know I had a hard time deciding which to take there
were so many good choices. There were so many great presenters all under one
roof. The vendor hall was brimming with great information. Keynotes at mealtimes
rocked! The food and the casino night were stellar! I arrived home with a head
full of ideas, a computer full of notes and an exhausted body.
Let’s do it all again in October!
Thursday, May 3, 2012
The Day the Lights Went Out...
What happens when the power goes out at an IT conference? We
kick it old school!
Monday, April 30, 2012
Taking the Show on the Road
I’ll be in Utica,
Illinois this week for the
Illinois Valley Network Users Conference. Although this is a general IT
conference, this year things definitely have an Information Security ring to
them, as power hitting Information Security presenters Laura Chappell and Loyal Moses will both be
in attendance.
Subscribe to:
Posts (Atom)