Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia,...

40
A model for reducing information security risks due to human error By Anup Narayanan, Founder & CEO, ISQ World Security Policy Never share passwords Don’t tell anyone, my password is…..

description

A talk that is based on my methodology HIMIS (Human Impact Management for Information Security) for reducing information security risks due to human error. To know more about HIMIS, visit http://www.isqworld.com/himis

Transcript of Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia,...

Page 1: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

A model for reducing information security risks due to human error By Anup Narayanan,

Founder & CEO, ISQ World

Security

Policy

Never share

passwords

Don’t tell anyone, my password is…..

Page 2: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

Nelson Mandela offers you a glass of water….

Page 3: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

This man…. offers you a glass of water

Page 4: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

Question

Which water will you accept?Why?

Page 5: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

5

1. Objective: Describe a workable model for reducing information security risks due to human error

2. Talk Plan:I. Differentiate between

“Awareness” & “Behavior”II. Case studyIII. Solution modelIV. Resources

We are here

© First Legion Consulting

Page 6: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

6

Awareness?

Do not share passwords!© First Legion Consulting

Page 7: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

Shred

documents

before

disposing

7© First Legion Consulting

Behavior?

Page 8: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

8

Putting it together….

Awareness:

I know

Behavior:

I do

Culture:

We do

© First Legion Consulting

Page 9: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

9

1. Objective: Describe a workable model for reducing information security risks due to human error

2. Talk Plan:I. Differentiate between

“Awareness” & “Behavior”II. Case studyIII. Solution modelIV. Recap & Resources

We are here

© First Legion Consulting

Page 10: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

10

Case-study:

Client: One of the largest mobile service providers in the world

• What? Spent US$ 100, 000 on a security awareness campaign

• How? Screen Savers, Posters, Emailers

• Who? Target - Entire employees

© First Legion Consulting

Page 11: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

11

What did we do?

“Awareness vs. behavior” benchmarking and produced a scorecard

© First Legion Consulting

Page 12: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

12

The scorecard

© First Legion Consulting

Page 13: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

14

Reason 1: Operational issues ….

Message in the poster

Don’t share passwords

Response by HR Manager

If I don’t share my password, salaries won’t get processed here…including that of the

InfoSec manager.

© First Legion Consulting

Page 14: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

Reason 2: Confusion ... Too many rules

Which one do I follow?

15© First Legion Consulting

Page 15: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

16

Reason 3: Perception…

Which is safer?

© First Legion Consulting

Page 16: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

Reason 4: Attitude … influenced by cost…(peer pressure, top management behavior)

17

Nothing’s gonna happen to me if I violate the security policies?

Well, I saw her doing it …shall I?

© First Legion Consulting

Page 17: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

“Awareness” & “Behavior”: Independent but interdependent

Question : A person knows the traffic rules. Does that make the

person a good driver?

Answer: Not necessarily, “Knowing” and “Doing” are two

different things

Question: A person knows the “information security rules”. Does that make the person a responsible information security practitioner?Answer: Same as above

Knowing = AwarenessDoing = Behavior

18© First Legion Consulting

Page 18: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

19

1. Objective: Describe a workable model for reducing information security risks due to human error

2. Talk Plan:I. Differentiate between

“Awareness” & “Behavior”II. Case studyIII. Solution modelIV. Recap & Resources

We are here

© First Legion Consulting

Page 19: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

• HIMIS – Human Impact Management for Information Security

• Objective – To provide a model to reduce security risks due to human error

• Creative Commons License, free for non-commercial use

• Download –http://www.isqworld.com, click on the HIMIS link

20© First Legion Consulting

Page 20: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

21

Define Strategize Deliver Verify

Responsible

information

security

behavior

HIMIS solution model - Work backwards

© First Legion Consulting

Page 21: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

Define Strategize Deliver Verify

• Choose ESP's (Expected Security Practices) information security awareness and behaviour requirements valid for the business

• Review and approval of ESP’s

• Baseline ESP assessment

22© First Legion Consulting

Page 22: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

23

ESP: Information

Classification

Awareness Criterion

The employees must know the different

information classification criterion : "Confidential,

Internal, Public"

The employees must know how to specify the

classification, for example, in the footer of

each document

Behaviour criterion

The employees must actually classify

document in day-to-day work. The evidence of this classification must

be available.© First Legion Consulting

Page 23: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

Define Strategize Deliver Verify

• For awareness management– Coverage

– Format & visibility: Verbal, Paper and Electronic

– Frequency

– Quality of content • Impact visualization

• Clarity & ease of understanding

• Business relevance

• Consideration of cultural factors

– Retention measurement.

• For behavior management – Motivational strategies

– Enforcement/ disciplinary strategies24© First Legion Consulting

Page 24: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

Quality of content

• Impact visualization

• Clarity & ease of understanding

• Business relevance

• Consideration of cultural factors

25

Wow! This security awareness video is so cool!

Yup! Not the usual glorified power point

© First Legion Consulting

Page 25: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

A 120 minute training plan

• 120 minutes of training in a year

– 45 minutes classroom or e-learning

– 15 minutes screen saver (12 X 1 to 1.5 minutes)

– 15 minutes posters/ wallpaper (same as above)

– 30 minutes through short videos (6 x 5 minutes)

– 20 minutes through quizzes/ surveys (2 x 10 minutes)

Page 26: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

Behavior management: What works?

27

Let’s fire him

Let’s cut his email access

Let’s talk to him

© First Legion Consulting

Page 27: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

28

In-convenience

Poor security behavior

Poor Security behavior Vs. Inconvenience

© First Legion Consulting

Page 28: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

29

Cost (Enforcement)

Poor security behavior

Poor Security behavior Vs. Cost

© First Legion Consulting

Page 29: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

30

Case study 1: Changing behavior (IT Service Provider)

• What we did?– Quarterly “End-User

Desktop Audits”

– Findings were noted and “Signed and Agreed by Auditee”

– Disputes were noted and “Signed”

– Audit findings were submitted to InfoSec Team

© First Legion Consulting

Page 30: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

31

Case study 1: Changing behavior (Electronic Retail Store)

• Audit finding: Cash boxes are left open when unattended

• Cost attached: Branch manager will lose 25% of annual bonus for every violation

• Compliance today is above 98%© First Legion Consulting

Page 31: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

Define Strategize Deliver Verify

• Define tolerable deviation

• Efficiency

• Collection of feedback

• Confirmation of receipt

32© First Legion Consulting

Page 32: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

Define Strategize Deliver Verify

• Audit strategy– Selection of ESP’s

– Define sample size

– Audit methods

• For awareness: Interviews, Surveys, Quizzes, Mind-map sessions

• For behavior: Observation, data mining, Log review, Review of incident reports, Social engineering?

– Reasonable limitations

– Behavior may not always be visible

33© First Legion Consulting

Page 33: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

34© First Legion Consulting

Page 34: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

37

1. Objective: Describe a workable model for reducing information security risks due to human error

2. Talk Plan:I. Differentiate between

“Awareness” & “Behavior”II. Case studyIII. Solution modelIV. Recap & ResourcesWe are here

© First Legion Consulting

Page 35: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

3838

Define Strategize Deliver Verify

Responsible

information

security

behavior

Recap

© First Legion Consulting

Page 36: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

39

Tip! Get HR buy-in

InfoSec Manager

HR manager

People are my biggest asset!

People are my biggest threat!

You must talk the same thing!

© First Legion Consulting

Page 37: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

40

Conclusion

If you can influence perception, you can influence the way people choose or react (behavior)

Perception is influenced if there is a cost for an

action

© First Legion Consulting

Page 38: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

41

If I follow the information security rules will I gain

something. If I don’t follow, will I lose something?

When you get your users’ to think

this way, you are on your way to a

better information security

culture!

© First Legion Consulting

Page 39: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

Resources

• Free security awareness videos –www.isqworld.com

• Bruce Schneier – The Psychology of Security -http://www.schneier.com/essay-155.pdf

• The Information Security Management Maturity Model (ISM3) – www.ism3.com

42© First Legion Consulting

Page 40: Reducing Security Risks Due to Human Error - Information Security Summit, Kuala Lumpur, Malaysia, June, 2011

43

Anup Narayanan,Founder & Principal Architect

ISQ World, A First Legion Initiative

[email protected]

www.isqworld.com

© First Legion Consulting