Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, August 25, 2011

資安管理十誡 - The 10 deadly sins of information security management

近日查閱資安管理(information security management)資料,不時看到 Ten Deadly Sin 字眼出現,今晨看過往Business Management 雜誌對現在公司所在領域的幾個原廠總字輩大佬的專訪,又看到文末列出這十宗罪(十宗罪好像是大陸習慣用法?)。

透過谷歌,很快就查到,原來這十誡典出學者 B. von Solms and R. von Solms 於 2004年7月發表在 Computer & Security 的文章。此十誡言簡意賅,強調資安管理不是技術部門獨有的責任,旨哉斯言,爰執鍵(盤)為之記。
  1. Not realizing that information security is a corporate governance responsibility (the buck stops right at the top)
  2.  Not realizing that information security is a business issue and not a technical issue
  3. Not realizing the fact that information security governance is a multi-dimensional discipline (information security governance is a complex issue, and there is no silver bullet or single ‘off the shelf’ solution)
  4. Not realizing that an information security plan must be based on identified risks
  5. Not realizing (and leveraging) the important role of international best practices for information security management
  6. Not realizing that a corporate information security policy is absolutely essential
  7. Not realizing that information security compliance enforcement and monitoring is absolutely essential
  8. Not realizing that a proper information security governance structure (organization) is absolutely essential
  9. Not realizing the core importance of information security awareness amongst users
  10. Not empowering information security managers with the infrastructure, tools and supporting mechanisms to properly perform their responsibilities
[書目資訊]

B. von Solms and R. von Solms, "The 10 deadly sins of information security management," Computers & Security, vol. 23, no. 5, pp. 371-376, Jul. 2004. [Online]. Available: http://dx.doi.org/10.1016/j.cose.2004.05.002

Tuesday, August 16, 2011

又一碗字母湯( Another Bowl of Alphabet Soup)

雖然走進資安領域,不在原本的規劃裏,但既然被機緣牽進這村徑,總要好好逛遍這山林,庶幾不負這不可言、不可測的緣法。既然要逛逛這原未涉足的土地,那就得認真閱讀此處的風土誌,要認懂這裡的地圖,就得認得這裡的方言俚語,於是得再服一碗字母湯

  • ACL - Access Control List
  • APWG - Anti-phishing Working Group
  • BASEL - Basel Accords
  • BSI - British Standards Institution
  • CA - Continuous Auditing
  • CA - Certificate Authority
  • CC - Common Criteria
  • CCM - Continuous Control Monitoring
  • CCM-AC - CCM for Application Configuration
  • CCM-MD - CCM for Master Data
  • CCM-T - CCM for Transaction
  • CEH - Certified Ethical Hacker
  • CERT - Community Emergency Response Team
  • CM - Continuous Monitoring
  • CME - Common Malware Enumeration
  • COBIT - Control Objectives for Information and related Technology
  • DAD - Database Access Descriptors
  • DAM - Database Activity Monitoring
  • DMZ - Demilitarized Zone
  • DLP - Data Loss Prevention
  • DOS - Denial of Service
  • DDoS - Distributed DOS
  • FERPA - Federal Educational Rights and Privacy Act
  • FGAC- Fine-Grained Access Control
  • GLBA - Gramm–Leach–Bliley Act
  • GPG - GNU Privacy Guard
  • GRC - Governance, Risk and Control
  • GTAG - Global Technology Audit Guide
  • HIPAA -Health Insurance Portability and Accountability Act
  • IDS - Intrusion Detection  System
  • IPS - Intrusion Prevention System
  • IIA - The Institute of Internal Auditors
  • ISACA - Information Systems Audit and Control Association
  • ISMS - Information Security Management System
  • ITIL - Information Technology Infrastructure  Library
  • KRI - Key Risk Indicator
  • MLS - Multi Level Security
  • NIST - National Institute of Standards and Technolog
  • PCI-DSS - Payment Card Industry Data Security Standard
  • PII - Personally Identifiable Information
  • SOAP - Simple Object Access Protocol
  • SOX - Sarbanes-Oxley Act
  • SSH - Secure Shell
  • SSO - Single Sign-On
  • VPD - Virtual Private Database
  • XSS - Cross Site Scripting


Saturday, January 15, 2011

只有更囧,沒有最囧

本以為這個月初 Vodafone Australia 泄露四百萬客戶資料的事已夠駭人聽聞,沒想到加拿大統計局 (Statistics Canada)諸君的豐功偉業才真是登峰造極令人髮指。

多倫多太陽報這個月10號在一份報導中整理過去五年 Stats Can 的犯行,在 2007年,他們把一個裝了敏感訊息的檔案櫃當作多餘的傢具賣掉,還有一次,統計局的幹員把某家公司的調查資料,留在其他的調查對象的辦公室,太陽報很客氣的說這只是 some examples of breaches.....


OCT. 2010: Purolator envelope containing 11 unencrypted, non-password-protected CDs for the Vital Statistics Program in Alberta addressed to Ottawa head office sent July 9, 2010 is discovered missing. It contains more than 21,000 electronic images of confidential information about individual birth, death, stillbirth and marriage registrations. It is found Nov. 30, 2010 locked in a rarely-used filing cabinet.
SEPT. 2009: Stats Can library's password access protocol constitutes "major security breach."
DEC. 2008: A briefcase with documents and personal notes is stolen from the car of an interviewer from Quebec. Confidential addresses of respondents were included.
JULY 2008: An error in transmission meant e-mails of 108 subscribers of Health Reports notifications were "inadvertently revealed" to all recipients of message - constituting a breach of Privacy Act and Stats Can policy.
JUNE 2008: Stats Can is informed that on Feb. 12, 2008 Surrey RCMP and Canada Post recovered completed 2006 census questionnaires from a private residence in a bust of a major identity theft ring. Other items included equipment related to credit card/ID theft, drivers' licences, 3,000 pieces of stolen mail, government-issued cheques, fake currency and more than 100 CDs with thousands of personal data profiles. Census questionnaires were not in the hands of census staff - it is believed they were obtained by tipping mailboxes or break-ins to homes and cars.
AUG. 2007: A laptop containing personal information about individuals who participated in the Labour Force Survey or Canadian Community Health Survey is stolen from the residence of an employee in Abbotsford, BC. Password was written on a sticky note stored in laptop case. Police called, affected people are informed and interviewer receives verbal reprimand.
JUNE 2007: Laptop with three completed household spending surveys stolen in home break-in in Delta, B.C.
MARCH 2007: Edmonton regional office reports two laptop thefts from field interviewers' vehicles. Staff are reminded about protocol for securing material.
MARCH 2007: Privacy Commissioner's office advised of inadvertent disclosure and loss of personal info after surplus filing cabinets with Records of Employment about 66 2006 census workers were sold at a Crown Assets Auction in Edmonton. Affected individuals are contacted and Stats Can implements more stringent procedures to avoid a recurrence.
JULY 2006: Enumerator leaves completed questionnaire instead of blank at Scarborough, Ont. respondent's home.
APRIL 2005: Blank forms faxed to a business include additional pages of confidential information related to two other businesses. Staff receive retraining and posters/notices are displayed as reminders.
FEB. 2005: Marketing information collected for one user is reviewed by another user and possibly four other unknown individuals in a Corporations Returns Act survey.
FEB. 2005: Laptop being shipped from Williams Lake, B.C. to Edmonton containing 23 Survey of Household Spending cases - including 11 completed ones - goes missing. A flurry of e-mails ensues among senior managers at Stats Can and officials "pester" Canada Post to find the lost item. Confidential statistical info is encrypted. Laptop is found two weeks later.

如果我的心是一朵蓮花

~ 林徽因 · 馬雁散文集 · 蓮燈 ~ 馬雁 在她的散文《高貴一種,有詩為證》裡,提到「十多年前,還不知道林女士的八卦及成就前,在期刊上讀到別人引用的《蓮燈》」 覺得非常喜歡,比之卞之琳、徐志摩,別說是毫不遜色,簡直是勝出一籌。前面的韻腳和平仄的處理顯然高於戴...