Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, June 13, 2013

ERM-BC-COOP:


Vendor security


Email Morphs into Corporate Espionage

 

An email just dropped into my electronic in-box with the subject “Should You Archive Email to the Cloud?

I suppose it’s a good question and I can think of many reasons to keep my emails “closer to home.”

But the query did trigger an off-the-wall thought, my forte’ it seems.

What about vendor security – all vendors, not just in the cloud.

When a person or organization signs up with a vendor, the vendor asks for, usually justifiably, a great deal of information. Granted, most of the information can be acquired from public resources, public records. But maybe not all, and some of the “not all” should be, at a minimum, “confidential.”

On a personal level, it seems almost everyone wants a client’s Social Security number which, as it happens, never was intended for identification beyond the needs of the Social Security Administration and the IRS. (The U.S. government is responsible for much of the abuse; a quick review of the Social Security timeline at http://www.ssa.gov/history/ssn/ssnchron.html bears this out.)

Organizations with smart people at the helm will ask prospective vendors if they have plans in place to assure that the vendor can meet Service Level Agreements (SLAs) “no matter what.”

That’s not enough.

Organizations need to know that information shared with vendors is safe, secure.

Consider the world of corporate espionage. If the competition knows a firm is ordering ZYX parts and ZXY is not used in any current products, the competition can rightly suspect the firm is bringing out a new product.

Perhaps the competition learns that a regular order for 100,000 #22 threaded fasteners has been doubled. Suggestion: A bigger production run that could translate into lowered prices to increase market share.

A reduction in a previously standard order could indicate the organization is winding down production of a certain product.

Corporate espionage, as with all other espionage “disciplines” most often finds success on connecting the dots of generally available, or loosely held, information.

An organization need not be part of what Dwight Eisenhower termed the “military-industrial complex” to have sensitive information a competitor might covet. Coca-Cola still locks up its formula and GM never willingly lets Ford get a look at its bound-for-the-production line drawings. Would Macy’s tell Kmart when it plans a sale of merchandise that sits on both stores shelves?

Checking on a vendor’s security – how it handles client information – may seem “out of scope” for a business continuity planner, but it IS very much “in scope” for an enterprise risk management practitioner, and a lack of vendor information security – both electronic and paper – should concern the vendor’s clients.

Consider it.

If I wrote it, you may quote it.


Tuesday, June 11, 2013

ERM-BC-COOP:

Y-12 . . . again

 

No performance checks?

Once again the Y-12 Tennessee nuclear arms facility's security has been breached.

This time by a little old lady who apparently was got lost.

According to an article on the KnoxNews Website (http://tinyurl.com/ksj8x6f), The security breach occurred less than a year after three protesters cut through a series of security fences and walked to the innermost sanctum of Y-12, the country’s largest repository of weapons-grade uranium.

“I’m not aware of any circumstances quite like this,” said Steven Wyatt, spokesman for the National Nuclear Security Administration and Y-12. He called Thursday’s incident a “security lapse.”

The woman who got onto the secure property told police she was searching for a new low-cost apartment complex she’d seen advertised. She followed a large throng of morning commuters shortly after 6 a.m. Thursday and was waved through Y-12’s main entrance off Scarboro Road, according to the report.

According to the Energy Department's Y-12 Web presence, "Y-12's core mission is to ensure a safe, secure, and reliable U.S. nuclear deterrent, which is essential to national security.

"Every weapon in the U.S. nuclear stockpile has components manufactured, maintained or ultimately dismantled by Y-12, the nation’s Uranium Center of Excellence. We employ only the most advanced and failsafe technologies to protect the stockpile."

Y-12 claims that "We train nuclear industry professionals, emergency responders and security forces from around the world to safeguard vulnerable materials; and the innovations engineered at Y 12 have applications for allies, other government agencies, and the private sector."

How successful Y-12 is at safeguarding its own "vulnerable materials" has to be questioned in light of a recent "invasion" by three protesters. A New York Times article headlined "The Nun Who Broke Into the Nuclear Sanctum" notes that on July 28, 2012, "Sister Megan Rice, 82, a Roman Catholic nun, and two male accomplices, one 63 and the other 57, carried out what nuclear experts call the biggest security breach in the history of the nation’s atomic complex, making their way to the inner sanctum of the site where the United States keeps crucial nuclear bomb parts and fuel." (http://tinyurl.com/bzdd7n6)

The KnoxNews article reported that "Guards at Y-12’s entrances are supposed to inspect and at least touch an employee’s Y-12 security badge before handing it back."

It would seem that the policy and procedure to prevent the latest excursion into the "secure" facility were in place, but they were never exercised, tested under stress - that is, rush hour at the gates.

While most practitioners don't have similar security concerns, the lesson to be learned from the on-going security fiasco at Y-12 is that resources on which the organization depends also are at risk during a "rush hour." Communications is a primary example.

Actually just getting people into work can be a risk. (Staggered start times can help, but keep in mind the roadway infrastructure leading to the facility; do the neighbors also have the same start times?)

It behooves practitioners to consider "weak links" and to test those links' robustness.

Are there work-arounds in place - off-site hoteling and home office when the roads are jammed, alternate phone options, especially if Internet services are carried over the same fibre as voice calls.

While you are at it, check to see just how secure is the facility.

If I wrote it, you may quote it