Tuesday, February 23, 2010

Tsunami Warning

Here is factoid from Hugh Penrie Williams session;

In Indonesia there is a tribe of Fisherfolk who claim that their Elders have always advised them to immediately run and t ake refuge in the hills if the Sea ever goes back for a long distance.

Another Plum:

Don't participate in the Rattle Sanke Kissing Contest because the Prize is $25 000. You might win it Posthumously!

:-)

Sharks and Coconuts Again!

It was a balmy evening in Balmbay as I made my way to the Airport, replete with all the learning for the past two days at the ISACA-CACS at Mumbai. The learning event was quite useful although my head is still heavy from all the Knowledge/Information/Data/Facts/Opinions that have been crammed into my little brain. Well, I suppose I have to digest it at leisure. After all Knowledge is not about Memory, its about Retrieval, right?

Hugh Penrie Williams began his session with a promise that he came to make us Think, Not Teach.

Surprisingly he used the Sharks and Coconuts example to talk about Risk. But his take is that we should be more worried about Pigs and not Coconuts. I think more people are going to be harmed by speakers giving the Sharks and Coconut analogy than both these hazards put together.

He rightly pointed out that there is no point in talking about Risk unless you "know" more about the "asset" being protected. In an Information Systems Security Concept the more valuable assets are the Data and Applications.

Instead of asking why a disater happened, we should be asking why it didn't happen more often. Then, the good systems and processes in place become obvious. Failures and vulnerabilities are seen with more clarity.

Another quote I loved in this session was,"The average is inconsequential or useless as we are forced to live with the constraints actually imposed on us."

Threats are in the Environment. Vulnerabilities are potential weaknesses in our protective measures. A threat that has exposed a vulnerability leads to an incident.

He mentioned that Risk need not have negative connotation. This is something I've always been telling students in my Securities Analysis programmes. In the last GMCS, a gentleman Mr. Prabhu vehemently argued otherwise. I wish he had been there to hear Penrie Williams!
Risk simply indicates that Anything can happen.

So, what we are really talking here is about degrees of uncertainty. A continuum that ranges from absolute certaintyof occurance of an event (Zero Risk) to to absolute uncertainty of an occurance. A probabilistic approach anchored in Business sense may be the solution.

The post lunch sessions on Cloud Computing and Wirelss Network DSecurity were quite technical thougfh the respective speakers Mardikar and Gibbs de-mystified much.

One unresolved issue in Cloud Computing seems to be the reason for including an entirely privately deployed system under cloud systems as a Private Cloud. Muti Tenancy of Infrastructure/Application seems to be a basic criterion in clouds. Take this away and where is the Cloud in Private Clouds.

A Final Thought:

I have a feeling that ultimately whether its Cloud Computing or IT Governance or Risk Management, or Wireless Network Security, the basic issue is Perimeter level security both at Physical as well as Logical levels. For example Nelson Gibbs on WiFi suggested we keep the Wireless Access Point (WAP) outside the Firewall.

Monday, February 22, 2010

Mumbai


The vigor and energy of the Mumbaikar is legendary. From morning to night they keep on moving around non-stop. Their resilience and toughness are not once-in-a-while as during the Mumbai Floods or the Taj Mahal Hotel Crisis. It is a day-to-day battle that they all fight everyday shoulder to shoulder for their livelihood.

This city, which is arguably India's Financial Capital does not have the poshness or richness that go with wealth. It is squalid and but for high value areas, everywhere else is a mix of old buildings and slums. Bengaluru possibly gives a more consistently affluent picture.

It rained during the day for a short while. But, if the monsoon fails this year too, Mumbai is in for water shortage.

I am now in my Wife's cousin's house in Chembur. In the evening I went for a walk to the nearby Srigeri Saradambal Temple.

Protecting ourselves from Sharks when the Danger is Falling Coconuts


The Afternoon Speaker at the ISACA-CACS, Eddie Schwartz began by pointing out that the number of people who die on the beach due to Sharks is far far lower than those who die due to falling Coconuts! In his frank and down-to-earth presentation on "Why some Organizations are winning the Cyber War?", he gave a lot of insights on the issues in IT Security due to Cloud Computing.

He says prevention is not really possible as the threats and vulnerabilities in Cloud Computing are too many. Moreover, it is difficult to identify the perpetrators. He suggests Continuous Controls Monitoring and Advanced Threat Detection Systems. We need to be always aware of threats and potential threats to our security systems.

Summary: The solution seems to be a proxyt based ATDS coupled with continuous session monitoring.

The next speaker on Data Loss Prevention and Digital Rights Management was Mark Ames, an Aussie. He put a lot of store by Identity Management which is just french for Encryption and Password Control. The real threat is still from outsiders then.

You are Remembered Only when You are Needed

Fact of Life. You are Remembered Only when You are Needed.
A Candle is remembered only during a Power failure.

So, What do you do?

Keep on pointing out situations when people will need you. Keep reminding them of this need.
This is the only way marketing can happen today.

Every advertiser presumes that somebody who needs his product or service will read his advertisement.

Some Advertisers try to create a need which is not felt now.

What is essential is to identify specifically people who need to have a need, tell them why the need it and help them understand why your product/service alone can fulfill that need effectively.

Delegating Accountability

"You can delegate tasks, but you cannot delegate accountability."
This is well known.
But cannot the person Delegating the Task build in an accountability framework within his jurisdiction. Not applicable outside his domain, nevertheless valid between him and the delegate?

This is a kind of Cadence of Accountability that is between the Job Owner and the Delegate.

Sunday, February 21, 2010

IT Governance Issues

I am now at the Hyatt Regency, Mumbai attending the Asia Pacific Control and Securities Conference (CACS) of ISACA. The sessions are on IT governance and security. This blog and the ones that follow do not attempt to report the proceedings but are rather an attempt to document my immediate reaction to what speakers were saying.

In the morning we had Robert E Stroud.

He was speaking about the five traps in IT governance.
He related real life anecdotes about his children and grand-children.
He describes a scene where his car has a microchip that sends a message to the dealer about a fault in the vehicle, who in return responds to the user's complaint. Well, in India we are not so seamlessly connected; Is that good or Bad?

He was also relating a situation where if the server fails on Thanksgiving day, the store fails. This is because all items are bar-coded and therefore not human-intelligible. Is this an IT incident or merely an inability to plan ahead? Why couldn't they have had someone staying over to handle glitches like this? This would have been automatic in India.

He also made the point that Governance is more than compliance. Governance is not a bottom up issue--it has to be top down.

Risk is not necessarily a bad word. You might want to take a risk to actualize a business opportunity. This is a positive acceptance of risk.

His quotations that he puts on Twitter were:

Perception is Reality.

Power Corrupts. PowerPoint Corrupts absolutely.

He also speaks about external consultants who are brought in as a "Solution". He calls it the "Outside-in-trap" and advocates solving the problem organizationally.

He suggests that we should have a Just Enough approach to Governance as over emphasis on Governance may curb innovation.

SUMMARY OF SESSION

The Deadly Sins in IT Governance are

Absence of 1. Definition, 2. Ownership, 3. Measurement, 4. Mutiple Governance System, 5. Automation. A last one, viz., Transparency was added by a participant which Robert agreed should be the First!

Questions were mainly on the Semantics of words like Security, Governanance and IT Governance. The speakers replies were possibly not the last word on this.





Murudeeshwar