Defense Federal Acquisition Regulation Supplement (DFARS)

NIST 800-171 – 12/31/2017 – Less than 90 days until the deadline!

Contracted information systems not part of an IT service or system operated on behalf of the Government must adhere to the following requirements:

Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012
. . . the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Non Federal Information Systems and Organizations. . .” The Contractor shall implement NIST SP 800-171, as soon as practical, but not later than December 31, 2017. . .

(more…)

0 Comments

Rotating Security Assessors

In order to protect valuable corporate assets and prove due diligence, security assessments and validation of controls are required on a regular basis. To adhere to regulatory compliance, these tasks are generally scheduled in advance and involve the repeated use of a single person or group of professional penetration testers. In this established routine lies a potential problem.

Penetration Testing is an art based on well-trained and highly creative individuals. Their most important task is to replicate attack strategies that many adversarial groups would launch against the corporate assets, defined as Physical Infrastructure or Intellectual Property. Threat Actors use widely different methods of attack plans, with an even more diverse range of tools, making it impossible to develop a “one size fits all” defense plan.

(more…)

0 Comments

Leveraging Social Networks and BYOD

The growth of social media, coupled with the increasing adoption of BYOD (Bring Your Own Device) present new challenges for network security. This paper provides proof of concept on how a carefully crafted Reverse Social Engineering (RSE) attack, using social media platforms such as Facebook or LinkedIn, can compromise mobile devices used by professionals. As a result of BYOD, these compromised devices are readily given network access. Access is likely just as high as the user’s normal access using a company provided workstation that stays in the environment at all times. This allows an attacker to establish a foothold within the network to launch further attacks. We will also examine the best practices to defend against this growing threat. Read More

0 Comments

The Evolution of Information Security

The adoption of cloud-based services has caused a rapid disruption that is changing the face of Information Technology. This leap forward comes with countless benefits but there is also a great cause for concern. The change is happening at a rate that isn’t properly allowing Information Security groups to properly gauge the security ramifications.

When I first entered this industry more than 20 years ago, networks were far easier to secure; they were largely flat with only a handful of entry points with all data and assets living in one or two physical environments with their own dedicated controls. Networks were very linear and far easier to scope and manage than the networks we support today.

Today, cloud connected services from tech giants like Amazon, Google, IBM and Microsoft offer low barriers to market entry, flexible costs, variable capacity, greater uptime, improved mobility and collaboration on robust network fabric. With so many benefits it’s easy to understand why there has been such a major push into the IaaS and SaaS space.

(more…)

0 Comments