Showing posts with label Maturity Models. Show all posts
Showing posts with label Maturity Models. Show all posts

Monday, February 10, 2020

2020 Update

Here we are in 2020, and there are many updates to go over.  I plan on further postings on several of these items, and need to get back into blogging here with more regularity.

Here are some of the new things that are out.

CCPA.  Privacy as an issue just seems to get bigger and bigger.  Even as a security professional I find myself being pulled into it.  I wonder if I need to join IAPP, maybe even study and get one of their certs.  We had the GDPR that came out last year.  I really though more companies would address it, but just didn't see that.  Now California came out with their CCPA law.  CCPA is not quite "California's GDPR".  Its not a broad privacy law, but aimed at consumer data.  I've seen some companies be concerned about it, but not as many as I thought.  But am sure I'll be getting more into it.

NIST Privacy Framework- NIST has been working on this for the last year and released v1 recently.  I have a copy and am reading over it.  I plan on giving a talk at an upcoming local meeting, and may do a conference talk about this as well.  Am hoping I'll be able to attend NIST's upcoming cybersecurity conference, as I'm sure it will be a topic of discussion.  We'll have to see how well this works in helping companies prepare for privacy regulations.

FISMA Updates- NIST is still working on the updates for the documents used for FISMA.  The next one they are working on is SP 800-53 Release 5.  We don't have a release date, but hope it will be soon as they've been working on it for so long.  Once its out, we should see other documents that are relying on it, such as 53A and 53B, an new version of 800-171 and others.  All we have so far on this is THIS page.

DoD CMMC- The DoD released this month the first version of their Cybersecurity Maturity Model Certification (CMMC).  This is an interesting items, its a certification for vendors of the DoD.  From a quick read, it combines the CMM/CMMI 5-level maturity model with the categories of the NIST SP 800-171, which is about protecting controlled unclassified data (CUI).  SP800-171 based on the control set of SP 800-53.  I plan on posting on this and may do a presentation as well.

PCI-DSS v4- yes, there is a new update of PCI-DSS.  I first heard about this a couple of years ago.  This should be a revamp of PCI-DSS.  I just have no idea how it will look like until its released.  Which I expect sometime this year.  I don't have an inside track, I just know from reading here and there that its getting closer to release.  Yes, I hope to posting on this as well.

There are several events coming up in my general area and will be posting in these soon.

Monday, October 1, 2018

Security Maturity Models (Part 1 of 2)

At the 2018 BSides Miami conference I spoke on the topic of "Security Maturity Models".  In part, due to technical problems with the presentation, am presenting a lot of what I spoke on there.  This is a topic I continue to research and gather information on, so I may do an updated presentation at a future conference or possibly write an article for a journal.  Due to the amount of information, I'll be doing this as 2 postings.

What IS "maturity"?  We aren't talking about individuals (tho that's important), but about organizations.  From Wikipedia: "Maturity is a measurement of the ability of an organization for continuous improvement in a particular discipline."  Thus the higher the maturity, the higher will be the chances that incidents or errors will lead to improvements either in the quality or in the use of the resources of the discipline as implemented by the organization.  An 'immature' organization is often times in 'firefighter mode', they are a re-active organization.  Because they don't do things in a consistent manner, there is no "process", they often times cause many of the problems they later have to fix.  For instance, if an IT organization is building systems such that each is unique, this will make it harder for them to maintain those systems vs if they built systems in a consistent manner.

A mature organization would instead follow a process to build systems that enable them to be maintained.  A mature organization would be proactive.

We can see these principles in security when we build a information security management system or program.  Some security organizations are immature, being reactive.  Others are mature, being proactive.  And hopefully organizations are trying to work toward maturity.  If they understand this.

Many have created a variety of maturity models, in security and elsewhere.  Which is part of the problem.  Some models are focused on particular areas, such as security awareness or secure coding or endpoint protection.  Others are fairly high-level, others more detailed.  Many models are based on a widely used model, the Capability Maturity Model, developed by the Software Engineering Institute at Carnegie Mellon.

Let's start with this one from Blue Lava.  A fairly high level level model, ranging from reactive to proactive.  Immature/reactive organization are in the "blocking & tackling" level.  I think many can relate to that.  I did like how they have the next 2 levels.  Too often some will focus on compliance when the right target is to create a risk-based security program.  Compliance is NOT security.  Compliance should instead be seen as a measurement of security, an outcome of being risk-based, not the goal.


Moving on to another one, a little more complex.  Still 3 levels of organizations.  But here we assess orgs against 4 categories.  3 should be familiar: people, process, and technology.  People is who, both leadership and team members.  Process is how, how do we do what we do.  Technology is the means of doing those things.  I find the last (or is it first) category interesting: philosophy.  The why?  


A more complex model, here going with 5 levels of organization, which is something to be familiar with.  It builds off the 5 level Capability Maturity Model I mentioned.  We'll spend more time at the start of part 2 going into it.  But the names are pretty common to the CMM.  This one looks at the 3 categories of People, Process, and Technology.

And now we get an even more complex model, again using the 5-level maturity levels of the CMM.  But a difference here is the security aspect goes from basic to advanced.


Here is a high-level diagram of the CMMI, the Capability Maturity Model Integrated, which replaced the CMM.  It changed some of the level names.  I should point out that the 5th level is OptimizING. To often those who used the CMM as a basis overlook this and call it Optimized.  But that's wrong.  Its optimizing, as process improvement is ongoing, never stopping.


Now, some further overview of the CMM.  There is more to this model, as in levels 2 thru 5, there are various Key Process Areas that need to be met to be considered at that level.  Organizations usually start at level 1, then by completing these KPA they can move up the levels.  Some may never get past 3 or 4.  I was part of an IT organization that was formally access at Level 3.

So hopefully this has peaked some interest.  In the next part, I'll go into more depth on several maturity models in use:  CMM/CMMI, The Cybermaturity Platform, maturity models built into things like the NIST CSF and FFIEC CAT, and others.

Monday, June 19, 2017

FFIEC CAT v1.1

In June of 2015 the FFIEC (Federal Financial Institutions Examination Council) released the first version of their Cybersecurity Assessment Tool (CAT).  The FFIEC, for those not aware, is a formal interagency body empowered to prescribe uniform principles, standards, and report forms for the federal examination of financial institutions and is made up of 6 different agencies.

The FFIEC already has a set of works called the IT Examination Handbooks, about a dozen, which help set down standards for IT in several areas.  One of interest would be the Information Security one that was finally updated in 2016.

Monday, April 18, 2016

One of my slides from my NIST CSF presentation

When I did my recent presentation on the NIST CSF at BSides Tampa, I had some ask about the source of one of the pictures in my presentation.

All the pictures I got off Google Images, btw.

Here is the picture in question:


The source is this article on the ISACA website, in the section on "Information Security Management at HDFC Bank"

Hope this is of use to others.



Sunday, May 26, 2013

DevOps- a preliminary look

This is a posting I've been working a bit on for sometime.  I decided to at least get this out, as its a topic I will probably be visiting more in the future.

As a long time IT professional, I've had to deal with process and procedures.  These are needed to manage the systems we are responsible for and deliver the services we should be.  Even as security professionals, we need to understand that our job is to secure these systems to help ensure that the delivery of them is not interrupted.  And often times this means doing so in a consistent matter, which happens when we follow procedures.