Saturday, May 8, 2010

General Hayden - Words of Wisdom

I was privileged to listen to one of my all-time favorite presentations by retired General Michael Hayden, former director of NSA and CIA. The venue: TTI / Vanguard Conference on CyberInsecurity in Washington DC. He was reflecting on the current "bogey man" known as Cyber security. 

Now to most of us, Cyber space is a Hollywood (sci-fi genre) conjured term used synonymously with the Internet. It's origins are actually from a 1984 novel called Neuromancer.  In the National Security discourse the term cyber-space is the "5th domain" with implications far removed from a Hollywood set. There is complex language of "mutually assured dependence" and Cyber warfare. Why the 5th domain? Well the other four are: land, sea, air and space. General Hayden artfully distringuished cyber-space as the only domain that was created by man, the rest of which was "created by god" - and natural events. Adding: "we did not do such a good job". Simply-put the Internet is inherently untrusted, and was designed for anonimyity and information movement. Not for security.

In the US we are still grappling with the ownership of the "cyber thing" which Hayden points out is very much fractured. There are voices that seek to frame the problem as a matter of commerce to be shepherded along led with the private sector. On the other, cyber is a matter of national security with bills that promote a nation navigating both times of cyber peace .. and war. Clearly its not a trivial topic. The private sector owns a lot of critical infrastructure from our energy supplies, power grids and financial markets. And the networks and systems are not entirely isolated from this thing called cyber-space. For ill-doers this is a prize. 


The Internet was designed and engineered for friend not foe.


The growing voices that suggest cyber space should be regulated and done so by government, immediately starts to run chills down the spine of civil libertarians and privacy mavens. They fear as Hayden put it: that the US government will make the dubious offer that it cannot protect its citizens unless, it is allowed to monitor them on the Internet. A fear reinforced when General Hayden gave a wink to his own prior employers (NSA) "abridged sense of privacy".


His message was one of a sense of urgency and not alarmist. He encouraged industry to spend energy into thinking about security and privacy and not just the ease of use of the Internet. And the need for doctrine about what can and should not happen in cyber space. (think about the lack of norms against a a cyber attack on a hospital's patient management system).

As John Negroponte put it (also a presenter) in cyber space "proceed with caution"



Tuesday, April 6, 2010

In Cyber Space, It Pays ... To Pay Attention

The ability to imagine the future and do so rather inaccurately is a uniquely human quality. Lest we forget the faulty real-estate asset valuations and risky gambles some financial services firms undertook. That inability to "get it right" in the midst of plenty of relevant information saw us enter into one of the worst economic downturn. 

Now, while we do imagine creatively (flying machines, submarines, Internet, smart-phones and electric cars to name a few) it is still difficult for us humans to get the future right, because of some familiar limitations. First we are locked in the present as we try and predict the future, or in other words the future almost always looks like a different version of the present, at least for most of us. And second we are very subjective in our forecasts. We can get stuck into believing that our own point of view reigns supreme, and that when we evaluate our claims against those of others – we will doubt those of others. 

Let’s say you regularly drive your car down a route home-bound and we'd like to evaluate your driving behavior. For this test we've created 3 driver proficiency categories. You are either someone that drives in “auto-pilot”, you are a directionally challenged driver (and a lost cause) or you are an individual that is extremely in-tune with your surroundings. 

If you find yourselves in the last category – you are a near perfect driver.  You know the distance of your car to the next. You observe the erratic behavior of a truck 20 feet ahead and two lanes across. You are tracking the changing weather conditions. You are aware. Actually there is a term you don’t fall into: Driving Without awareness (DWA): someone in a state where there is no active attention to the task of driving. 

Congratulations, you’ve managed to free yourself of simply focusing on the precise task of driving. You are pretty good at making forecasts because you are not totally centered around your-self, and instead you are actively absorbing (and filtering) information from your environment. And in relationship to the introduction of this blog, you are someone that does not ignore subtle cues and signals.

If you were to program all those keen skills into a next generation drive-assist system it would have features such as defensive driving heuristics, map-based reasoning and use your own experience to predict traffic flows. Moreover it would be smart enough to respond to changing situations with more acuity with or with-out you in the loop. 

And so it is also true that the goal of better understanding our surroundings exists all around us: air-line traffic control, supply chain management, in the battle-field, doctors and other critical decision makers must all maintain some level of situational awareness in dynamic and tricky environments.

The process of raising that situational awareness barometer starts with differentiating status (of something) from events and thus relying heavily on surveillance (more passive monitoring) and reconnaissance (actively targeting someone or something) to recognize errant behavior, the terrain and environmental conditions, track targets and sense indicators and early warning signs. 

Think of an air traffic controller and the tools they need to get and maintain the right attention to track fast moving objects from colliding with each other in mid-air. 

It is increasingly apparent that in Cyber space (as in land, air and sea) there is virtual terrain and dimensions of time and space. To conduct commerce, serve citizens and communicate without some sort of handle on one’s surroundings is akin to walking in a dark alley with no perception whatsoever. It’s out of the question. 

Organizations of course rely on intrusion detection systems, event monitoring, incident response and readiness teams, anti-virus scanners and well managed applications and operating systems. Hopefully that pristine infrastructure or application is under a digital microscope where anything that is out of place or odd will be observed. 

The challenge is that observation or witnessing an event, is again different and harder than forecasting or predicting an outcome.

For example, consider an trusted insider that is observed downloading sensitive files for an extended period of time - after hours. On the surface there may have been no reason to doubt any misuse of privileges. There may have been no “rule-breaking" behavior. With some  projection and connection of the dots, there may be an opportunity to prevent a serious incident of data theft. Consider, if that same individual 4 months earlier was placed on administrative leave and 1 year earlier had visited a web site that is known to distribute malware. 

The point is that most of today’s IT security systems that help gleam what’s happening, what has happened and what is about to happen are either disconnected or most likely not in place at all. 

As we live, work and play in cyber space - organizations and all of us must raise our own situational awareness and in different ways. Whether it’s changing passwords on a regular basis, updating anti-virus definitions or avoiding that tempting link in our emails. 

Organizations and government agencies must also up the ante in terms of accurately detecting suspicious behavior, putting in place credible deterrents and automating responses that will minimize the impact of a potential threat actually occurring - whether that threat is known or unknown. They must also get better at working with a wider latitude of information that originates in cyber-space and must be correlated to the physical world.


Friday, February 26, 2010

US Federal agencies and cloud computing: Reason to be cautious

Cloud computing in the enterprise has generated plenty of hype – and plenty of eye-rolling among wary CIOs of federal government agencies. Federal IT leaders continue to express legitimate concerns about the effectiveness of cloud environments in securing sensitive government and consumer data. Many are also skeptical of the promised cost savings and service quality.

Amid the healthy skepticism, however, lies increasing pressure to give serious consideration to cloud computing initiatives. The Obama Administration is focused on lowering the cost of government operations while driving innovation. Many local, state and federal government agencies are evaluating cloud computing, though few are actually implementing cloud-based solutions at the federal level.

While there are no quick answers, there are some clear steps federal agencies – not just CIOs, but all senior decision-makers – can be taking now to prepare their organizations for cloud-based computing environments. Here are three key points federal agencies should consider in an effort to break through the hype and lay the groundwork for a clear, reasoned path to cloud computing.

1. It’s OK to say no.

Federal agencies under pressure to embrace cloud computing are fully justified to just say no. The fact is that most federal agencies should not venture into a “classic” public cloud any time soon, for a simple reason: Incumbent cloud service providers such as Google, Amazon and Microsoft do not comply with current Certification & Accreditation rules dictated by the Federal Information Security Management law. This makes the public cloud a non-starter for most federal organizations, while providing a clear litmus test for the future viability of cloud providers.

To their credit, commercial cloud providers are making some progress in regards to federal compliance. Both Microsoft and Google, for example, are close to receiving accreditation for FISMA compliance, and Google has reportedly completed a System Security Plan for its Google Apps platform.

Key issues around compliance involve where the data actually resides in a commercial or public cloud environment and how vulnerable it will be to cyber attacks. CIOs are rightly concerned that their data could be stolen by hackers, mixed with data from their cloud providers’ other customers, or inadvertently exposed. The recent cyber attacks on Google and other organizations emanating from China will do nothing to quell concerns around moving sensitive information into cloud environments.

As Robert Carey, CIO of the US Navy, noted at a federal executive forum in November 2009:  “Public clouds are not necessarily appropriate for Army or Navy information to be just sitting out there, and therefore the models that you would use to describe the security of that information might have to, and probably will have to change a great deal.”

2. Not all clouds are created equal.

Although the public cloud is not a near-term option for federal agencies, other options do exist to help federal and intelligence agencies gain more flexibility and achieve cost efficiencies for their IT infrastructures.

The basic technologies of a cloud environment – high speed Internet connections, browsers, grid computing and virtualization – are well established and can be duplicated by any organization.  This makes it possible for government agencies or departments to build “private clouds” – infrastructures that use cloud technologies but are more aligned with current security requirements.

Adopting virtualization and other cloud technologies, even in a closed environment, could increase efficiencies and reduce infrastructure costs by breaking down the silos created through the use of proprietary technologies. Consider the efficiencies of something as basic as a shared email system; these and other non-core applications are good candidates for early migration into private cloud environments.

The DoD’s Defense Information Systems Agency (DISA) is moving toward what arguably could be the world’s largest private cloud, as it looks to integrate the Defense Information Systems Network, its data centers, and its command and control applications. This cloud-based approach to sharing information could serve as a model for other agencies – and for commercial providers as well.

The type of information each agency handles will influence its approach to cloud solutions. Just as most governments tag data with different levels of sensitivity, from low level (published widely and no restrictions) to ultra secure (classified security information for top government leaders only), they can also begin to design cloud architectures for different levels of information. For example:

·         Any agency that deals in the public domain – such as the EPA, the Census Bureau, or the Department of Interior – could serve as a “canary in a coal mine” test case for a cloud infrastructure.
·         The GSA’s recent launch of apps.gov – a storefront for cloud-based business, productivity and other applications featuring non-sensitive data – is an example of where federal agencies can begin testing the waters.[iv] The GSA has already seen positive results from moving the USA.gov portal to the cloud. The transition significantly lowered GSA's costs, saving taxpayers an estimated $1.7 million annually.
·         New public programs that must launch quickly to meet legislative mandates – Cash for Clunkers is one recent example – are candidates for testing the ability of cloud solutions to scale quickly .

On the other hand, Homeland Security and other agencies that deal with ultra-secure data have little or no incentive to consider a cloud solution. In situations where data security presents an untenable risk, the government may choose to pursue other avenues, such as optimizing the infrastructure in place using traditional IT practices or decoupling data and processing to allow use of public or private cloud infrastructure without jeopardizing data security.

3. Who’s accountable?

The issue of governance is perhaps the biggest obstacle to federal agency adoption of cloud computing. Regulatory mandates require that an agency must know precisely who has access to data and where the data resides, both physically and logically. Some providers will guarantee the presence of data in the U.S., while others will not, or cannot, prove their ability to do so. In addition, agencies must have considerable transparency into the operations of the service provider. This raises two key questions:

·         Who will oversee the passage of data throughout a cloud environment?
·         Whose role is it to ensure that this data is continuously managed and protected?

Agencies will need to establish comprehensive policies for issues such as encryption key management along with network, application, and data-level mechanisms that enable the verification of data movement and storage in cloud-based environments.

The good news is that government agencies do have plenty of experience in establishing governance policies for external service providers. The same risk assessments used over the past decade to qualify third-party storage facilities or other service providers can be applied, at least in part, to cloud computing vendors.

Agencies can also rely on existing rules and structures that govern IT decision-making; these policies and processes can be adapted to determine the chain of command for decisions and activities related to cloud computing.




Wednesday, January 13, 2010

When a closed mind bears the standard, pity those who follow



Most cloud vendors are setting themselves up as the gold-standard in terms of everything from how thier product's are priced, labeled, serviced etc. They are patiently waiting for signs of a critical mass to declare victory over important matters that will influence customer defection rates and unbending loyalty. History is litered with examples of technology standards pitted against each other with the consumer watching the battle unfold. Most recently: Blu-Ray, HD DVD, USB, GSM, CDMA. The consumer cares about standards and those obscure protocols because they impact our wallet, our sanity and life-long experience with every day products. 

To pick and choose standards for cloud computing we need not look further than the ‘web services/SOA’ craze of the last 5 years. That hoopla spawned standards and vendor specifications to last us a life-time. All of us (tech savvy or not) will see XML as one of those unsung hero's and a saving grace that pulls us back from the brink of mass confusion. It is THE currency of data portability and like the electric socket in our home will force cloud vendors to conform in some fashion. I can pull out all my blog posts into a neat folded ‘XML’ file and take it where ever I want. I can do the same with iTunes.

On the flip side vendors still must be willing to cooperate and commit to that sort of openness, secure cloud integration, application portability and data portability. Will the US home developer actually put that 110 Volt electric socket and in all of the rooms?


Some would say that the higher you go up the cloud stack the more difficult it is to reclaim your content. The prevailing sentiment is that an infrastructure provider allows you to move in, and move out with all your belongings. Like a hotel room. A software-as-a-service provider gets to keep all that code – that it owns - and if you walk away you are down more than your data. Here is a blog I wrote about reclaiming your data and applications.

If salesforce.com confirmed to ideal standards it would allow an organization to export all that goodness and make it much easier as it hunts for a replacement. Standards have been around for thorny 'middle-ware' since 2004: interoperability and business process management. SaaS and PaaS vendor are in the drivers seat and will want to stay that way. If I can't increase stickiness, I will lock-you in. Telecom carriers along side COTS application vendors have long played the lock-in game. In the end they hold the shorter end of the stick. Instead they should focus on customer and brand loyalty, service-levels and building trust and legitimate interdependence.

The nuance that gets lost in the discourse: plenty of standards already exist. Yet vendors are avoiding adoption as others play into sound-bites until they get critical mass. Another simple example, all the standards for security are ready for prime-time cloud computing: SAML, XAXML, KEYPROV, ISO 15489, EDRM, PKCS, WS-Federation, Liberty ID-FF etc.)

There are a number of notorious topics that do deserve special attention. Service Level Agreements and contract terms and conditions are not uniform across service providers. Count on government bodies such as the US GSA to swiftly drive the convergence to common attributes around performance metrics, incident response details etc.

The National Institute of Standards and Technology (NIST) calls out customer on-boarding, service provisioning, inter-cloud interaction as prime topics that deserve attention:
  • VM image distribution (e.g., DMTF OVF)
  • VM provisioning and control (e.g., Amazon EC2 API)
  • Inter-cloud VM exchange
  • Persistent storage (e.g., Azure Storage, S3, EBS, GFS, Atmos)
  • VM SLAs that are machine readable
  • uptime, resource guarantees, storage redundancy
  • Secure VM configuration (e.g. NIST Security Content Automation Protocol)
  • Workflow and business rules import and export
In a world of constant motion and innovation we should expect to live with some degree of propriety and feature-loss or gain. What we should expect, is some sort minimum code of interoperability, ethics and portability.


Saturday, January 9, 2010

Trust Part I. "I'm not upset that you lied to me, I'm upset that from now on I can't believe you"

Trust, its role and significance to our society is obvious. I wanted to share some well-known research and opinions on the meaning, formation and attributes of trust. A discussion that will carry over into cloud computing.



First things first...do you trust your life-long friend to keep a life-long secret? Do you trust your car dealer to complete the schedule oil change, tire rotation and that oh so mandatory surprise problem by the promised 4:00 PM pick-up time? Do you trust your employer to give you the 10% raise the year after a recession?


Trust is a resource. You give it, you take it and you create something out of it. In almost all situations where trust comes into play there is uncertainty such as the role of emotion in the early stages of a relationship.


Why are some people a good judge of character, while others can make money even when the stock market is tanking, or millions of others are willing to buy and sell from each other without a face to face introduction? Its because each of these people are able to deal in varying outcomes with that resource called trust. 

So what is the definition of trust? There is little agreement about the exact, let alone conceptual, meaning of trust. Trust has been defined as:
  • a behavior (Zand, 1972)
  • an attitude (Kegan & Rubenstein, 1973)
  • a confidence (Cohen, 1966)
  • an expectancy (Rotter, 1980; Scanzoni, 1979)
  • a belief or set of beliefs (Barber, 1983; Bromiley & Cummings, 1995; Rotter, 1967)
  • a dispositional variable (Rosenberg, 1957; Rotter, 1967, 1980)
  • a situational variable (Johnson-George & Swap, 1982)
  • a structural variable (Fox, 1974; Lewis & Weigert, 1985a,b)
  • a social agency relationship variable ... you get the picture
Rousseu et.al. (1998) does a good job of boiling the meaning of trust into a receipe that is one part risk and one part interdependance:
  • Risk occurs where information is unavailable, the future outcome is unpredictable, and where
    there is a possibility of loss or harm (Chiles & McMackin, 1996; Lewis & Weigert,
    1985).
  • Interdependance: where one party relies on another, or perhaps many others, to achieve desired results
More in Part II


PS: the quote in the Title is by Friedrich Nietzsche.




Friday, November 20, 2009

Random Walk Down Cloud Street

An interview with a federal government journal:

1) We have heard many definitions of 'cloud computing'. How do you define it?We are headed towards a pay-per-view model for most (not all) of IT. So with that set-up: Cloud computing is any “IT” service that can be sold pay-as-you-go over the Internet. Ideally a cloud service should be available immediately. Click-to-buy. But also click-to-exit. Minimal hassle or contractual obligations.

Software-As-A-Service accounts for a lion’s share of the market (e-commerce suites, cloud storage and on-demand business software). But that’s part of the story. The other part is sourcing key aspects of your business processes that span both talent (or labor) + software.

NIST (National Institute of Standards and Technology) has an air-tight definition.

My take on definitions is, that it’s OK to bend a definition but not break it. For example: If a cloud provider charges you by the day, and bills you by the month. That is OK. It’s still metered – if not by the hour or minute. If the cloud does not switch on the power in a split second – that’s OK if they give you a better service-level agreement.

Note: Cloud Types
  • Not all cloud providers can compete on a low price point. So there will continue to be differentiation on value. In the future you will see software, and infrastructure and platform cloud services start to blur.
  • A cloud provider can create sub-divisions where it can dedicate a pool of resources for 1 customer. That structure is in opposition to multi-tenancy- where more than one customer shares the infrastructure or application. The cost to operate such a cloud will be higher. And the more 1-1 relationships the more we are bending the definition of cloud computing
  • It’s not all vanilla, there will be chocolate chip and mint. Organizations are actively looking at hybrid on-premise/off-premise hosting platform

2) Why, in your opinion, is the cloud getting so much attention right now? (It seems that no one was talking about it two years ago. Is this accurate?)
Every industry is rethinking how they get things done with a backdrop of scare resources–talent, budgets and energy. The stars happened to align the last 2 years for cloud computing. And the spotlight and vendor value proposition is squarely on Small/Medium Businesses, and now government agencies and the enterprise.

The appealing value is hard to ignore:

• Operating cost reduction (maintenance/support/upgrades)
• Better utilization of software licenses
• Any savings from replacing infrastructure CAPEX with subscription fee OPEX

Keep in mind that Salesforce.com was founded in 1999. And depending on how far you go in history we have been doing some sort of outsourced and time-shared computing for decades especially in the science community.

3) One of the challenges to cloud computing is security. What are the biggest things CIOs/IT managers should be wary of?
First, cloud computing introduces change. And change is the arch enemy of security. You add a window, you create a new way for someone to get in. So you need to understand all those things that change when moving an application or your data into the cloud. If you get these two rights right, you are on track: 1. can I tell what I own in the cloud, and 2. can I tell when something changes in the cloud?

Second, is your trust relationship. If a cloud provider won't let you see behind “their firewall”, won’t give you an audit of facilities (e.g. how they perform software upgrades, background checks for personnel), then you should look elsewhere. Mischief is inevitable. And you don’t know until you test, and you test because you want to verify, and you verify because you don't trust.

Third, you will have to ask yourself: how am I measured and what am I trying to protect? FISMA (Federal Information Security Management Act) makes it expensive for public cloud providers to meet Certification & Accreditation requirements. Enter the 1-1 cloud scenario’s (e.g. future Google Federal Cloud). Additionally, there are multiple Federal and State level Regulatory requirements, including HIPPA, GLBA, SOX, FFIEC, SEC, and PCI. Compliance is not security. You will need to keep the eye on the real issues: Cyber threats. Malware that morphs every 35 seconds, bot-nets that phone home and the active underground economy of cyber crime.

4) Another challenge sometimes has to do with a mindset. Some are worried about the cloud because . . . Well . . . It’s a new way of thinking. What do you suggest for CIOs/IT managers who might be timid about the cloud?
When a fixed enterprise mindset and the Internet collide, time and time again the Internet has won. This is no exception. Virtualization and cloud computing are here to stay. So why don’ you try before you buy? Get to know the technology, understand the Return on Investment and what you are giving up. There will be hidden costs. So it’s important to do your due-diligence and develop a business case for cloud services.

Wednesday, November 18, 2009

Its not rocket science to pick a cloud provider: Cut to the Chase.

Most of the vocal public cloud providers are "like a 5 year old, they run away" or start to babble when you open up a discussion on risk, compliance and security.

If a cloud provider won't let you model the network or get a full audit of servers (e.g. patching, virtual machine provisining, console activity), then one should choose another. If an organization can't understand the attack surface of the target operational environment nor identify vulnerabilities then they will likely be unable to access and accept the risk to operate (and meet fudicuary obligations).

Each industry will have its own set of impedence factors. The FDA imposes a set of critiera for a validated platform for healthcare/biotech. Federal agencies must deal with FISMA and the guidelines by NIST which I have have experience with. Government agencies start to ask tough questions when a provider builds their own hardware, let alone relying upon foreign supplied COTS components.

There are cloud providers that are making claims but security concerns will remain until there is an audit and verification. I would go with cloud providers that have had experience with enterprises and are able to offer a managed service components. The solution should be complemented with the right people that can speak to the issues.

A trusworthy cloud provider will transparent than not. They have to be willing to speak with you about their controls. In some cases, you need to exclude a provider if they can not provide a fully-managed offering - with physical server seperation. In other cases you mauy need a NOC with staff that has been thru back-ground checks. You will then have to assess and then select a cloud provider with say a separate NOC that is FISMA compliant. Some "cloud" provider are actually able to drop in a separate node for large Financial Services clients. But they still have to think about the economic costs, and unlikely to be "click-to-buy-to-provision". There is significant investment in the networking gear, patch panel, service management and capacity allocation where a public resource pool is adequately cut-off for private consumption. There would be contractual obligations to reserve and purchase resources e.g. 1000's of virtual / physical servers.

A check-list compliance appraoch with service providers will be necessary. Accenture has an assessment methdology and Cloud RFI survey that we've used with a number of cloud providers. The results would be verified with a site visit. Is the machine room isolated from other functions. Are there camera's on the peripheral of the building. Do they harden 'their" operating system before installing other applications.What is their process for applying patches/updates? Accenture is experienced in coordinating and supporting external security audits and can provide recommendations and guidance for security improvements and corrections.

Best practices carry over with cloud computing, especially with the concentration of high-value assets and the unknown threats of multi-tenancy and virtualization. Everything gets more fractrured and the operating picture (your understanding of cyber risks) change e.g. email traffic, user logins/behaviour, remote access traffic, building access, time reporting etc. If all types of customers (enterprise, small business and regualted) are using the same ingress and egress interfaces that may simply be unacceptable to some customers.

Its vital to understand the attack surface of the cloud and use an enterprise risk management framework to select security controls. Are there cloud providers and candidate for Financial services that make ssense in a cloud? It depends on your definition of a cloud and what they are providing. It will depend on what you are willing to give up. This starts with a risk assessment.