Showing posts with label Ten Dimensions of Cyber Security Performance. Show all posts
Showing posts with label Ten Dimensions of Cyber Security Performance. Show all posts

Wednesday, July 17, 2013

DHS ITF IdeaScale Cybersecurity Project – Two New Ideas

This is part of a continuing series of blog posts about the latest DHS-IdeaScale project to open a public dialog about homeland security topics. This dialog addresses the DHS Integrated Task Force project to help advance the DHS implementation of the President’s Cybersecurity Framework outlined in EO 13636. The earlier posts in this series were:


The last couple of days have seen the introduction of two new ideas that share one thing in common they propose complex new ideas that take more than a couple of paragraphs to explain. The first deals with cyber emergency incident management and the second cyber security performance measurement. And both rely on links to documents outside of the IdeaScale site to fully explain their suggestions.

Cyber Incident Management

On July 15th the idea by dgsweigert (Dan Sweigert) was moved to the site by moderators. There is a single sentence (“Here is my white paper”) on the IdeaScale site and a link to a 3 page SlideShare document. Dan eloquently makes the point that a proper response to a cyber emergency is probably more important than efforts to prevent such incidents. We are not going to be able to prevent 100% of the attacks on critical infrastructure cyber-systems, so we need to put plans in place to respond to successful attacks. He suggests that “serious consideration be given by CSF [Cybersecurity Framework] planners to incorporate a NFPA 1600 and/or NIMS response capability in the EO 13636 CSF” (pg 3).

As I noted in my IdeaScale comment to this idea, this is a good first pass review of a problem that has been grossly overlooked in our discussions of preventing cyber-attacks, particularly on control systems. Dan makes the argument for starting the emergency response planning process and we in the community need to flesh it out.

Performance Measurement

The second new idea will be familiar to readers of this blog; Russell Thomas offers up his Ten Dimensions of Cyber Security Performance that I described in an earlier blog post. Russell provides a little more meat to the introduction of his idea than did Dan, but he too has to rely on links to off-site writings (in this case his blog) to fully explain the idea.

Voting

I voted ‘Agreed’ to both ideas, not because I fully endorse them in every detail, but rather because I thing they are both important new ways of looking at the issues that the Cybersecurity Framework is supposed to address. As such they need to be shared with the community, examined, discussed and modified as necessary.

I doubt that either will make it directly into the Framework being developed. That is not due to lack of scholarship or innovation, but rather that the general game plan for the framework has already been established and there is not enough time remaining in the process to make the kinds of major changes that would be required by the incorporation either of these ideas.

Still, neither would interfere with implementation of the Framework, so just perhaps the cybersecurity community needs to address these ideas outside of the Framework. While we are currently focused on the development and implementation of the Framework, I doubt that anyone really assumes that it will be the final word on cybersecurity, particularly in control system realm.

Endorsing the IdeaScale Process


Once again, I would like to take the opportunity to urge everyone to visit this IdeaScale site and put in your two cents worth. If you have no more time available than to read a couple of the ideas that catch your fancy, please vote on whether or not you thing the idea has merit. If you have more time available, contribute a comment like Richard did; it will add to the discussion. But better yet, put one of your ideas down on paper and then post it to the site for others to read, vote upon and discuss. Be a real contributor to the development of national policy.

Tuesday, July 16, 2013

An Interesting Systems Look at Cybersecurity

This weekend I ran across an interesting blog about cybersecurity that has made me pause and re-think some things. Mainly it has reminded me of the classic story about a number of blind men examining an elephant; each describing the animal solely based upon the one body part that they touched. Just maybe we have been looking at cybersecurity that way.

Russell Thomas has taken a systems approach to looking at cybersecurity that brings a fresh perspective to the issue. I’m not talking system in just the hardware/software sense; he blends in organizational and personnel concerns as well as adding in adversaries into his system. To give you an idea about how involved this analysis gets here is his final system diagram representing the various interactions between what he calls the Ten Dimensions of Cyber Security Performance


Russell Thomas’ Ten Dimensions of Cyber Security Performance

His blog post is a tad bit lengthy (I know, pot calling kettle black) but this is a complex subject. Actually it is so complex that his post includes links to posts about specific details. For example, here are his 10 dimensions:
                  
Optimize Exposure: attack surface and vulnerabilities, including assets, people, processes, & technologies
Effective Threat Intelligence: understanding the threat agents 
Effective Design & Development: security & privacy by design 
Effective External Engagement: responsibilities and risk drivers
Effective Learning & Agility: OODA at an organization level
Responsibility & Accountability: including governance and compliance

In some ways his discussions are a little on the academic side, but it is probably time that we started to include some academic rigor in our discussions of this complex topic. Besides, it is obvious that Russell [name corrected, 7-16-13 23:20 CDT] also has significant amounts of practical experience working with computer systems and people. So, every time that you start to think that this is some disconnected academic discussion, he’ll zing you with a real world example that makes eminent sense.

I’m still working on what changes I would make to take this out of the IT side of the house and bring it to the plant floor. I haven’t seen anything that I would take out, but I might want to add some touches specific to control systems.

I highly recommend that anyone connected with control system security should take a look at this blog post. Thinking about how we can tie the entire enterprise into this cybersecurity thing just makes so much sense that it is about time we start to think about how our individual parts fit into the system in which we work. This is an interesting first step.
 
/* Use this with templates/template-twocol.html */