Here we are in 2020, and there are many updates to go over. I plan on further postings on several of these items, and need to get back into blogging here with more regularity.
Here are some of the new things that are out.
CCPA. Privacy as an issue just seems to get bigger and bigger. Even as a security professional I find myself being pulled into it. I wonder if I need to join IAPP, maybe even study and get one of their certs. We had the GDPR that came out last year. I really though more companies would address it, but just didn't see that. Now California came out with their CCPA law. CCPA is not quite "California's GDPR". Its not a broad privacy law, but aimed at consumer data. I've seen some companies be concerned about it, but not as many as I thought. But am sure I'll be getting more into it.
NIST Privacy Framework- NIST has been working on this for the last year and released v1 recently. I have a copy and am reading over it. I plan on giving a talk at an upcoming local meeting, and may do a conference talk about this as well. Am hoping I'll be able to attend NIST's upcoming cybersecurity conference, as I'm sure it will be a topic of discussion. We'll have to see how well this works in helping companies prepare for privacy regulations.
FISMA Updates- NIST is still working on the updates for the documents used for FISMA. The next one they are working on is SP 800-53 Release 5. We don't have a release date, but hope it will be soon as they've been working on it for so long. Once its out, we should see other documents that are relying on it, such as 53A and 53B, an new version of 800-171 and others. All we have so far on this is THIS page.
DoD CMMC- The DoD released this month the first version of their Cybersecurity Maturity Model Certification (CMMC). This is an interesting items, its a certification for vendors of the DoD. From a quick read, it combines the CMM/CMMI 5-level maturity model with the categories of the NIST SP 800-171, which is about protecting controlled unclassified data (CUI). SP800-171 based on the control set of SP 800-53. I plan on posting on this and may do a presentation as well.
PCI-DSS v4- yes, there is a new update of PCI-DSS. I first heard about this a couple of years ago. This should be a revamp of PCI-DSS. I just have no idea how it will look like until its released. Which I expect sometime this year. I don't have an inside track, I just know from reading here and there that its getting closer to release. Yes, I hope to posting on this as well.
There are several events coming up in my general area and will be posting in these soon.
Showing posts with label regulations. Show all posts
Showing posts with label regulations. Show all posts
Monday, February 10, 2020
Wednesday, February 20, 2019
2019 Update on frameworks, standards, and regulations for infosec
At the 2019 BSides Tampa Security conference I did a talk on 2019 Updates on frameworks, standards, and regulations for infosec. Over the last year several new and updated frameworks and regulations have come out, as well as are being updated.
Most of the information can be found on the Internet, but if you're not making an effort to stay up to date, you can miss something. So here I give links to much of the information I gave.
NIST is the National Institute of Standards and Technology, a non-regulatory part of the Department of Commerce. They are doing a lot of things that impact us in infosec. Most are hopefully familiar with the Special Publication 800 and 1800 series that are put out on a regular basis. Several are being developed, updated, and in a few cases retired. Go HERE to access all of them.
The NIST Cybersecurity Framework (CSF) was updated to version 1.1 last year, and they later had a cyber risk conference in October. It just had its 5th anniversary, too. For full info on the CSF, and any updates and the like, go HERE. One element I am looking forward to is an update to informative references that will add additional references (such as crosswalks to PCI-DSS, Standards of Good Controls, etc). Hopefully we'll start seeing these coming out.
NIST Privacy Framework. NIST has embarked on creating a privacy framework like they've done for cybersecurity. This work has just begun, and they are working on a preliminary framework which we should see soon. I would hope there will be further workshops and feedback before the final version is out. To see where they are, go HERE.
FISMA is the Federal Information Security Management Act. Basically sets down security standards for federal information systems. NIST has developed the materials for this, the Risk Management Framework (SP 800 37), the controls set (SP 800-53) and other materials. They are working on updating this, having just come out with the latest version of the RMF. The control set is next, with others to follow. Go HERE for their page on this work. The schedule is HERE.
Baldridge Cybersecurity Excellence Builder is a combination of NIST's Baldridge Excellence work crossed with their CSF. It was rolled out in 2017, and should get an update this Spring. You can download it for free HERE, and there is info on how others have used it successfully.
NIST OSCAL is an interesting project that attempts to create a common set of control assessment language. This is a project I want to spend more time looking into myself. More info on their website HERE.
Hopefully most have heard of the "Critical Controls" or the "Critical Security Controls". Maybe you've heard it referred to as the "Top 20" or the "SANS20" or the like. While it was started by SANS, they no longer manage it. For the last few years its been handled by the Center for Internet Security, which has rolled out v6 and in early 2018 they rolled out v7. They have reorganized it into 3 groups: Basic, Foundational, Organizational. They have been putting out other resources for it, including the CSAT, a self assessment tool. They are working on a v7.1 and I expect more resources coming from CIS. So keep your eye out for them, as they just rolled out a companion guide for cloud (go HERE) and is working on another for IoT.
ISO/IEC 27000 is the international standard set for information security. This series is made up of about 50-60 documents in various states of work. Sadly, the documents are not free, and the cost is over $100 for each. Key documents is usually 27001 and 27002. 1 sets down the ISMS (Information Security Management System) and 2 is the control set (compare with SP800-53). As several of the documents are being worked on, its hard to keep up. ISO/IEC 27005 got updated. My go-to site to keep up to date on this is iso27002security.com.
Privacy regs (GDPR & California). Privacy is getting more and more important. While we work in security, we often get pulled into privacy work as well. GDPR (General Data Protection Regulation) of the EU was rolled out last year. And we've already seen some big companies get in trouble. While I see a lot of groups pushing GDPR training and the like, as a consultant I'm not seeing a lot of clients asking for help. Yet. California is rolling out their regulation, which isn't in effect yet. We'll see if other states will roll out or update their privacy regulations.
One I left out of my presentation is 23 NYCRR 500, which is the New York Department of Financial Services (NY DFS) regulations on cybersecurity. Rolled out a couple of years ago, the various elements of the regulation has been slowly rolled out with the last one required this March. This regulation expects companies do certain things to protect NPI (non-public information), such as have a security program, policies, doing pentesting and vulnerability scanning, have a CISO, do training, have an incident response plan, vendor management plan, etc. This may be a model for other state. You can read it all HERE.
Now, there are some other items that aren't pure infosec/cybersecurity, but do touch on it, so should be mentioned.
CMMI- The Capability Maturity Model Integrated, originally for assessing the maturity of software development, it was later expanded to others. Later merged into the CMMI, with Development, Service, and Acquisition versions. The Software Engineering Institute at CMU developed it, and it used to be available for free or via books. But they moved the CMMI to the CMMI Institute, which was recently bought by ISACA. They've rolled out CMMI v2, but its available as a SaaS product, and no longer free. The CMMI Institute has also rolled out a Cybermaturity Platform, again as a SaaS product. I'd like to learn more about it, but hard to do.
COBIT, which is ISACA framework for governance of enterprise IT has been updated to COBIT 2019. They've rolled out the new books, and hopefully other materials will be updated to COBIT 2019.
ITIL is a framework for IT Service Management, which includes infosec. The current version is ITIL v3 (updated in 2011). It's being updated to a new version, ITIL 4. So far only the foundation certification info have been updated. Hopefully they will update the 5 main books this year.
PCI-DSS is the standard for assessing credit card processing systems. Current version is 3.2.1, which was updated due to issues with SSL. Well, the next version, v4, is going to be coming out, but not for another year or so. It will be a very different version, but info on this is hard to find. Am sure as we move further along we'll learn more.
Hopefully this is useful for others. As I learn of new updates, I'll make further postings.
Most of the information can be found on the Internet, but if you're not making an effort to stay up to date, you can miss something. So here I give links to much of the information I gave.
NIST is the National Institute of Standards and Technology, a non-regulatory part of the Department of Commerce. They are doing a lot of things that impact us in infosec. Most are hopefully familiar with the Special Publication 800 and 1800 series that are put out on a regular basis. Several are being developed, updated, and in a few cases retired. Go HERE to access all of them.
The NIST Cybersecurity Framework (CSF) was updated to version 1.1 last year, and they later had a cyber risk conference in October. It just had its 5th anniversary, too. For full info on the CSF, and any updates and the like, go HERE. One element I am looking forward to is an update to informative references that will add additional references (such as crosswalks to PCI-DSS, Standards of Good Controls, etc). Hopefully we'll start seeing these coming out.
NIST Privacy Framework. NIST has embarked on creating a privacy framework like they've done for cybersecurity. This work has just begun, and they are working on a preliminary framework which we should see soon. I would hope there will be further workshops and feedback before the final version is out. To see where they are, go HERE.
FISMA is the Federal Information Security Management Act. Basically sets down security standards for federal information systems. NIST has developed the materials for this, the Risk Management Framework (SP 800 37), the controls set (SP 800-53) and other materials. They are working on updating this, having just come out with the latest version of the RMF. The control set is next, with others to follow. Go HERE for their page on this work. The schedule is HERE.
Baldridge Cybersecurity Excellence Builder is a combination of NIST's Baldridge Excellence work crossed with their CSF. It was rolled out in 2017, and should get an update this Spring. You can download it for free HERE, and there is info on how others have used it successfully.
NIST OSCAL is an interesting project that attempts to create a common set of control assessment language. This is a project I want to spend more time looking into myself. More info on their website HERE.
Hopefully most have heard of the "Critical Controls" or the "Critical Security Controls". Maybe you've heard it referred to as the "Top 20" or the "SANS20" or the like. While it was started by SANS, they no longer manage it. For the last few years its been handled by the Center for Internet Security, which has rolled out v6 and in early 2018 they rolled out v7. They have reorganized it into 3 groups: Basic, Foundational, Organizational. They have been putting out other resources for it, including the CSAT, a self assessment tool. They are working on a v7.1 and I expect more resources coming from CIS. So keep your eye out for them, as they just rolled out a companion guide for cloud (go HERE) and is working on another for IoT.
ISO/IEC 27000 is the international standard set for information security. This series is made up of about 50-60 documents in various states of work. Sadly, the documents are not free, and the cost is over $100 for each. Key documents is usually 27001 and 27002. 1 sets down the ISMS (Information Security Management System) and 2 is the control set (compare with SP800-53). As several of the documents are being worked on, its hard to keep up. ISO/IEC 27005 got updated. My go-to site to keep up to date on this is iso27002security.com.
Privacy regs (GDPR & California). Privacy is getting more and more important. While we work in security, we often get pulled into privacy work as well. GDPR (General Data Protection Regulation) of the EU was rolled out last year. And we've already seen some big companies get in trouble. While I see a lot of groups pushing GDPR training and the like, as a consultant I'm not seeing a lot of clients asking for help. Yet. California is rolling out their regulation, which isn't in effect yet. We'll see if other states will roll out or update their privacy regulations.
One I left out of my presentation is 23 NYCRR 500, which is the New York Department of Financial Services (NY DFS) regulations on cybersecurity. Rolled out a couple of years ago, the various elements of the regulation has been slowly rolled out with the last one required this March. This regulation expects companies do certain things to protect NPI (non-public information), such as have a security program, policies, doing pentesting and vulnerability scanning, have a CISO, do training, have an incident response plan, vendor management plan, etc. This may be a model for other state. You can read it all HERE.
Now, there are some other items that aren't pure infosec/cybersecurity, but do touch on it, so should be mentioned.
CMMI- The Capability Maturity Model Integrated, originally for assessing the maturity of software development, it was later expanded to others. Later merged into the CMMI, with Development, Service, and Acquisition versions. The Software Engineering Institute at CMU developed it, and it used to be available for free or via books. But they moved the CMMI to the CMMI Institute, which was recently bought by ISACA. They've rolled out CMMI v2, but its available as a SaaS product, and no longer free. The CMMI Institute has also rolled out a Cybermaturity Platform, again as a SaaS product. I'd like to learn more about it, but hard to do.
COBIT, which is ISACA framework for governance of enterprise IT has been updated to COBIT 2019. They've rolled out the new books, and hopefully other materials will be updated to COBIT 2019.
ITIL is a framework for IT Service Management, which includes infosec. The current version is ITIL v3 (updated in 2011). It's being updated to a new version, ITIL 4. So far only the foundation certification info have been updated. Hopefully they will update the 5 main books this year.
PCI-DSS is the standard for assessing credit card processing systems. Current version is 3.2.1, which was updated due to issues with SSL. Well, the next version, v4, is going to be coming out, but not for another year or so. It will be a very different version, but info on this is hard to find. Am sure as we move further along we'll learn more.
Hopefully this is useful for others. As I learn of new updates, I'll make further postings.
Monday, June 26, 2017
A look at the NYDFS requirements for Cybersecurity
Hopefully most people have heard of the new NY State regulations on cybersecurity, usually referred to as the NYDFS regs, or "23 NYCRR 500" or the like.
These went into effect on March 1, 2017 and you can read the regs HERE. Its just 15 pages.
Now, there are a lot of articles out there on the regs. So not so much interested in going over in deal what the regs say, but instead to comment on what it here.
These went into effect on March 1, 2017 and you can read the regs HERE. Its just 15 pages.
Now, there are a lot of articles out there on the regs. So not so much interested in going over in deal what the regs say, but instead to comment on what it here.
Friday, January 13, 2017
BSides Tampa 2017
I will be speaking at BSides Tampa 2017 this February.
The topic will be on "HIPAA for Security Professionals". My aim is to introduce to security professionals what HIPAA is and what they need to know about it. With the increased pressure on healthcare organizations and their third party vendors for information security, this is important. Especially with HHS doing random audits going forward.
Hope to see many of you there.
The topic will be on "HIPAA for Security Professionals". My aim is to introduce to security professionals what HIPAA is and what they need to know about it. With the increased pressure on healthcare organizations and their third party vendors for information security, this is important. Especially with HHS doing random audits going forward.
Hope to see many of you there.
Sunday, March 13, 2016
Resources for workshop on security standards/frameworks/regulations for information security professionals
At the 2016 Security BSides Orlando conference, I gave a workshop on security standards, frameworks, regulations for information security professionals. While not an exhaustive survey of such, I focused on the ones that seem the most known, and which I typically see on job descriptions.
Not covered were enterprise architecture models like Zachman or TOGAF. Left out are other security frameworks like SABSA or things like RESILIA, FedRAMP or Cloud Control Matrix, SSAE 16/SOC, Secure DevOps, or Maturity Models for security.
Covered were:
Not covered were enterprise architecture models like Zachman or TOGAF. Left out are other security frameworks like SABSA or things like RESILIA, FedRAMP or Cloud Control Matrix, SSAE 16/SOC, Secure DevOps, or Maturity Models for security.
Covered were:
- CIS CSC
- NIST CSF (plus FFIEC CAT)
- ISO/IEC 27001
- FISMA
- HIPAA
- GLBA
- SOX (plus COSO)
- PCI-DSS
- COBIT 5
- ITIL
Labels:
certification,
Cobit,
COSO,
Critical Security Controls,
CSC,
FFIEC,
FFIEC CAT,
FISMA,
frameworks,
GLBA,
HIPAA,
ITIL,
NIST,
NIST CSF,
PCI-DSS,
regulations,
SANS Top 20,
SoX,
training
Wednesday, June 26, 2013
SL Powers IT Security Lunch & Learn event
Tying in with my recent posting on getting involved with local security events, today I attending a "lunch and learn" event organized by one of our local IT services companies, SL Powers. They apparently do these events in our local area about once a month, in different locations. This one had two presentations, both were pretty good.
First up, we had Silka Gonzalez, President & CEO of Enterprise Risk Management, a local company focused on helping their clients with risk management and assessments. She gave a good overview of some of the various regulatory compliance standards out there that many of us have to deal with: GLBA, FACTA, SoX, HIPAA/HITECH, FERPA, FISMA, and PCI-DSS. What I particularly liked was how she pointed out the similarities among many of these, and what are the basic underlining concepts that are common in all of them.
The second talk was by Tom Leffingwell of Juniper Networks. Now, I have known Juniper as a competitor to Cisco in terms of networking equipment. What I wasn't aware of was their work in the area of network security. So it was good to learn more about what they do in this area. As with these kinds of presentations, you run the risk of being more a sales pitch then a technical overview, and I think he did a good job of staying more technical then sales.
I will keep my eye out for further sessions like these. SL Powers also has a series of sessions called "Tech on Tap", which also sounds interesting.
I found out about this event via Eventbrite. If you aren't familiar with this site, check it out. Great way to find out about events in your area, both free and fee. As IT people, we need to keep up our skills, so attending these events have multiple benefits.
First up, we had Silka Gonzalez, President & CEO of Enterprise Risk Management, a local company focused on helping their clients with risk management and assessments. She gave a good overview of some of the various regulatory compliance standards out there that many of us have to deal with: GLBA, FACTA, SoX, HIPAA/HITECH, FERPA, FISMA, and PCI-DSS. What I particularly liked was how she pointed out the similarities among many of these, and what are the basic underlining concepts that are common in all of them.
The second talk was by Tom Leffingwell of Juniper Networks. Now, I have known Juniper as a competitor to Cisco in terms of networking equipment. What I wasn't aware of was their work in the area of network security. So it was good to learn more about what they do in this area. As with these kinds of presentations, you run the risk of being more a sales pitch then a technical overview, and I think he did a good job of staying more technical then sales.
I will keep my eye out for further sessions like these. SL Powers also has a series of sessions called "Tech on Tap", which also sounds interesting.
I found out about this event via Eventbrite. If you aren't familiar with this site, check it out. Great way to find out about events in your area, both free and fee. As IT people, we need to keep up our skills, so attending these events have multiple benefits.
Subscribe to:
Posts (Atom)