{"id":37085,"date":"2022-06-27T03:00:00","date_gmt":"2022-06-27T03:00:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/37085"},"modified":"2022-06-27T03:00:00","modified_gmt":"2022-06-27T03:00:00","slug":"secure-everything-not-just-the-weakest-link","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=37085","title":{"rendered":"Secure everything, not just the weakest link"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/06\/secure-everything-not-just-the-weakest-link.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Security professionals recognise that the weakest link is the one most likely to be compromised by a hacker. But an organisation\u2019s security model should not fall apart just because a part of the business, or a business partner, has weak security.<\/p>\n<p><a href=\"https:\/\/www.computerweekly.com\/opinion\/Security-Think-Tank-Dont-trust-the-weakest-link-Dont-trust-any-link\">Tim Holman, CEO at 2-sec<\/a>, says the term \u201csecure as the weakest link\u201d implies that all parts of the business and everything that links each part together are on an equal footing and trust level to everything else. But this idea of securing the weakest link is not working.<\/p>\n<p>A survey conducted by the UK government recently reported that a lack of <a href=\"https:\/\/www.computerweekly.com\/feature\/Enterprises-shore-up-supply-chain-resilience-with-data\">visibility in supply chains<\/a> is one of the biggest barriers to effective supplier cyber risk management.<\/p>\n<p>Meanwhile, a <a href=\"\/\/www.isaca.org\/supply-chain-security\">study from ISACA<\/a> found that many cyber security professionals are concerned about the security of their organisation\u2019s supply chain. Two-thirds (66%) of respondents are worried about poor information security practices by suppliers.<\/p>\n<p>While business drives greater levels of technical development, security can sometimes be an afterthought, <a href=\"https:\/\/www.computerweekly.com\/opinion\/Security-Think-Tank-Understanding-attack-paths-is-a-question-of-training\">warns Mike Gillespie<\/a>, vice-president of the C3i Centre for Strategic Cyberspace and Security Science (CSCSS).<\/p>\n<p>\u201cExperience has taught me that when organisations head for technology to solve a range of issues, as well they should, they do not funnel anywhere near enough resource into protecting themselves from unintended consequences, or from the poorly informed users of this technology, in many cases not even training the users on the basic usage of it, let alone the safe and secure usage of it,\u201d he says.<\/p>\n<p>Over the past few weeks, GitHub revealed that the login details of about 100,000 accounts of a <a href=\"https:\/\/www.techtarget.com\/searchitoperations\/news\/252515031\/Pro-Ukraine-sabotage-renews-scrutiny-on-open-source-security\">third-party developer service called npm<\/a> were stolen using <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252516048\/Stolen-Oauth-tokens-lead-to-dozens-of-breached-GitHub-repos\">compromised OAuth user tokens<\/a> originating from two separate third-party integrators.<\/p>\n<p>When looking at the security of links between a company and its business partners, BCS volunteer Petra Wenham says: \u201cWe must include the company\u2019s IT in that statement and the security of a partner\u2019s IT system.\u201d<\/p>\n<p>Junade Ali, a technologist with an interest in software engineering management and computer security, points to the OAuth vulnerability as an example of the risks organisations face across their supply chains when they connect or make use of third-party systems.&nbsp;<\/p>\n<p>\u201cIn the recent past, I\u2019ve worked on changing practices across the industry when it comes to password security,\u201d he says. \u201cI developed the anonymity models used by <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252443978\/Have-I-Been-Pwned-integration-comes-to-Firefox-and-1Password\">Have I Been Pwned<\/a>, the developer tooling needed to improve password security practices and published scientific studies used to change the industry understanding of the best practice.\u201d<\/p>\n<p>What Ali learned was that the reuse of compromised credentials from one low-value website (say, a pizza restaurant) often cascades to compromising someone\u2019s online banking. He adds: \u201cThe message here is clear \u2013 security isn\u2019t purely within our fiefdom and we depend on others to keep our data safe.\u201d<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"Collaboration and automation\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Collaboration and automation<\/h3>\n<p>However, as Martin Tyley, head of cyber at KPMG UK, notes, budgets very rarely cover supply chain risk. He says business and IT leaders need to accept that their organisations will operate with some level of risk, and this is very hard to balance. \u201cRetailers and utilities have an acceptable level of loss,\u201d he says. \u201cWhat is your tolerance for losing a customer record?\u201d<\/p>\n<blockquote class=\"main-article-pullquote\">\n<p><figure> \u201cBeing honest with suppliers about security needs and expectations during the initial stages of procurement, and encouraging them to do the same, will help build stronger relationships and strengthen security\u201d <\/figure><figcaption> <strong>Francesca Williamson, Information Security Forum<\/strong> <\/figcaption><i class=\"icon\" data-icon=\"z\"><\/i> <\/p>\n<\/blockquote>\n<p>Tyley says organisations need to combine forces across their supply chain with collective interest to understand better what each partner can do to improve supply chain resilience. This, he says, involves all organisations in the supply chain being in a position where they are prepared to share risks with other partners in the supply chain, enabling those business partners to compensate for potential weaknesses in a way that hardens security across the supply chain for everyone.<\/p>\n<p>\u201cBeing honest with suppliers about security needs and expectations during the initial stages of procurement, and encouraging them to do the same, will help build stronger relationships and strengthen security,\u201d says Francesca Williamson, an analyst at Information Security Forum.<\/p>\n<p>She urges IT security chiefs and those responsible for the security of the supply chain to establish a security baseline that incorporates security requirements in the contract. This, she says, will help to establish a precedent for the entirety of the supply chain lifecycle.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Assessing risk in the supply chain\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Assessing risk in the supply chain<\/h3>\n<p>Brian Fletcher, a cyber assessment practices adviser at ISACA, recommends that organisations practise their response to a supply chain incident. \u201cThese initial exercises can help identify concerns and issues, especially with roles, responsibilities and the incident management chain of authority,\u201d he says.<\/p>\n<p>After completing several of these exercises, Fletcher says organisations should then conduct planned and unplanned walkthroughs of the shared incident playbooks. \u201cWalkthroughs help identify potential issues before an actual incident,\u201d he adds.<\/p>\n<p>Such issues include identifying the backup contacts if the primary contacts are not available or in what circumstances should the organisation and its suppliers switch to alternative means of communication.<\/p>\n<p>Incident scenario suppliers produce and facilitate training incidents, which, says Fletcher, enable organisations to increase the realism of their supply chain incident response exercises. \u201cIn these situations, clearly scoped and approved rules of engagement make the training as authentic as possible without impacting operations,\u201d he says. \u201cThe key output is a list of lessons learned to improve the resilience of your supply chain.\u201d<\/p>\n<p>When looking at the levels of security controls an organisation has across its supply chain, Wenham says companies should assess both the direct control and indirect control they have.<\/p>\n<p>\u201cDirect control would be where company assets are controlled by company policies, procedures, standards and work guides,\u201d she says. For instance, this may cover maintenance staff who are either employees or contractors who are legally required to follow company policies.<\/p>\n<p>Indirect control is where a third party provides services under a legal contract, says Wenham. \u201cThat contract would have clauses relating to security and annexes spelling out the security requirements in detail,\u201d she says. \u201cIt is no good just saying that the third party must be ISO 2701-compliant. The statement of applicability and the relevant clauses need to be identified together with any necessary expansion.\u201d<\/p>\n<p>Wenham adds that there may be company-specific policies covered by the contract, together with mechanisms to ensure that the security is being maintained regularly, such as independent audits or a copy of a standards renewal certificate.<\/p>\n<p>Automation is key to <a href=\"https:\/\/www.techtarget.com\/searchitoperations\/news\/252518401\/Citi-donates-software-supply-chain-security-kit-to-OpenSSF\">securing supply chains<\/a>, as they become ever more complex. Information Security Forum\u2019s Williamson says continuous monitoring is required to achieve the most accurate and reliable profile of a supplier\u2019s security posture, and this is only realistically achievable when automation is incorporated. There are a number of methods available for continuous monitoring, which include, but are not limited to, security ratings, supplier self-assessments and security certifications, says Williamson.<\/p>\n<p>\u201cThe greatest value from continuous monitoring is extracted from the outputs produced,\u201d she adds. \u201cMost assessment tools will present the findings in a dashboard which provides a visual representation of the security of suppliers, helping to increase the visibility of the status of the supply chain by providing the results in an easy-to-comprehend format.\u201d<\/p>\n<p>Williamson recommends that business leaders and security heads incorporate supplier assessment tools into the supply chain management process, pointing out that these tools help to achieve greater levels of visibility. \u201cThe technology can store, process and analyse a large quantity of data at a much quicker pace,\u201d she says.<\/p>\n<p>Williamson adds that the use of this technology during the evaluation stage of the process has the potential to identify trends or anomalies that may have previously gone unnoticed. \u201cIncreasing the level of visibility enables organisations to be better prepared and ready to respond to supply chain threats,\u201d she says.<\/p>\n<p>For 2-sec\u2019s Holman, businesses should probably operate under the assumption that they have already been compromised. As recent studies have found, many organisations are very likely to have been compromised by a supply chain incident. \u201cYou should do your utmost to protect what is critical to your business, at source,\u201d he says.&nbsp;<\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Security professionals recognise that the weakest link is the one most likely to be compromised by a hacker. But an organisation\u2019s security model should not fall apart just because a part of the business, or a business partner, has weak security. Tim Holman, CEO at 2-sec, says the term \u201csecure as the weakest link\u201d implies [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":37086,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-37085","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/37085","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=37085"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/37085\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/37086"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=37085"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=37085"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=37085"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}