Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft...

15
Culture Clash: Law, Culture Clash: Law, Business and Business and Technology Technology Mitch Dembin Mitch Dembin Chief Security Advisor (US) Chief Security Advisor (US) Microsoft Corporation Microsoft Corporation

description

What We Did Panic - Haphazard Frenzied Reaction to Security Incidents Perimeter Protection Pushed Data Security to IT Departments without funding/training or understanding of special skills required Allowed development of one-off security solutions throughout enterprise

Transcript of Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft...

Page 1: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

Culture Clash: Law, Culture Clash: Law, Business and TechnologyBusiness and Technology

Mitch DembinMitch DembinChief Security Advisor (US)Chief Security Advisor (US)Microsoft CorporationMicrosoft Corporation

Page 2: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

How We Got HereHow We Got HereComputer OS, Apps and Internet Computer OS, Apps and Internet Protocols not designed for Protocols not designed for securitysecurityCriminalsCriminals

Malicious HackersMalicious HackersCorrupt InsidersCorrupt InsidersVirus/Worm WritersVirus/Worm Writers

PublicityPublicityPrimarily Website DefacementsPrimarily Website DefacementsIdentity Theft Identity Theft

Page 3: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

What We DidWhat We DidPanic - Haphazard Frenzied Reaction to Panic - Haphazard Frenzied Reaction to Security IncidentsSecurity IncidentsPerimeter ProtectionPerimeter ProtectionPushed Data Security to IT Pushed Data Security to IT Departments without funding/training Departments without funding/training or understanding of special skills or understanding of special skills requiredrequiredAllowed development of one-off Allowed development of one-off security solutions throughout security solutions throughout enterpriseenterprise

Page 4: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

ResultsResultsSilosSilos

By acquisition, design or reaction to a By acquisition, design or reaction to a security eventsecurity event

Little attention to security architecture, Little attention to security architecture, writing secure code, strategic security writing secure code, strategic security planningplanningSome progress in infrastructure Some progress in infrastructure protection leading to attacks up the protection leading to attacks up the stackstack

Page 5: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

Consequences Consequences Here come the lawyersHere come the lawyersEEA, HIPAA, GLB, SarbanesEEA, HIPAA, GLB, SarbanesCommon Thread:Common Thread:

ReasonablenessReasonablenessAppropriatenessAppropriateness

Interpreted by lawyers after the factInterpreted by lawyers after the factAnd, on their heels, come the dreaded And, on their heels, come the dreaded AUDITORSAUDITORS

Page 6: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

Compliance – A Partial LandscapeCompliance – A Partial Landscape

COMPLIANCECOMPLIANCE

Sarbanes-OxleySarbanes-OxleyFiscal accountability for Fiscal accountability for

all public companiesall public companies

Basel II Basel II Capital assessment Capital assessment and reporting standards and reporting standards for global bankingfor global banking

USA PATRIOT ActUSA PATRIOT ActCustomer documentation Customer documentation requirements in order to requirements in order to “know your customer“know your customer””

DoD 5015.2 DoD 5015.2 and UK PROand UK PRO

Federal standards Federal standards of records managementof records management

Health Insurance Health Insurance Portability and Portability and

Accountability Act Accountability Act (HIPAA)(HIPAA)

NASD 3110NASD 3110 Written policies and Written policies and

procedures for review procedures for review of correspondence of correspondence

with the publicwith the public

All records related to All records related to securities transactions to be securities transactions to be

maintained for 3 yearsmaintained for 3 years

Gramm-Leach Bliley Gramm-Leach Bliley Act (GLBA)Act (GLBA)

Privacy of financial Privacy of financial informationinformation

Right to carry insurance Right to carry insurance between job; privacy of between job; privacy of patient Informationpatient Information

SEC Rules SEC Rules 17a-3 & 17a-417a-3 & 17a-4

Source: Microsoft Compliance Summit; October 2003

Page 7: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

The PlayersThe PlayersBusiness Decision MakersBusiness Decision Makers

Language = Brand Protection, Competitive Language = Brand Protection, Competitive Advantage, Value and ROIAdvantage, Value and ROI

IT SecurityIT SecurityLanguage = TechnologyLanguage = Technology

LawyersLawyersLanguage = ReasonablenessLanguage = Reasonableness

AuditorsAuditorsLanguage = ChecklistsLanguage = Checklists

Page 8: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

Guiding Principle No. 1Guiding Principle No. 1It is really difficult to make predictions, It is really difficult to make predictions, especially about the future (Y. Berra)especially about the future (Y. Berra)

Page 9: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

Problem 1: The SiloProblem 1: The SiloAssumptions:Assumptions:Different Data of relatively equal Different Data of relatively equal importanceimportanceWith different security solutions With different security solutions created, implemented and managed by created, implemented and managed by different technology, people and different technology, people and processesprocessesOf demonstrably different effectivenessOf demonstrably different effectiveness

Page 10: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

Problem 1: ContinuedProblem 1: ContinuedData in less secure silo compromisedData in less secure silo compromisedHow do you demonstrate to How do you demonstrate to lawyers/auditors/regulators/shareholders lawyers/auditors/regulators/shareholders that protection of the data was that protection of the data was reasonable/adequate when better reasonable/adequate when better solutions were employed for equally solutions were employed for equally important data elsewhere in the important data elsewhere in the enterprise?enterprise?

Page 11: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

Problem 2: Emerging Problem 2: Emerging TechnologiesTechnologies

Multiple Factor AuthenticationMultiple Factor AuthenticationRights ManagementRights ManagementNetwork SegmentationNetwork Segmentation

Page 12: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

Where We Need To GoWhere We Need To GoEnterprise-wide security planEnterprise-wide security plan

Combat silosCombat silosPeople, Process & TechnologyPeople, Process & Technology

Dissemination of best practicesDissemination of best practicesEmergency and Incident ResponseEmergency and Incident ResponseCommon LanguageCommon Language

Page 13: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

Common Ground?Common Ground?Risk AssessmentRisk AssessmentRisk MitigationRisk MitigationRisk ManagementRisk Management

Page 14: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

Guiding Principle No. 2Guiding Principle No. 2

In theory, there is no difference In theory, there is no difference between theory and practice. In between theory and practice. In practice, there is.practice, there is.

Y. BerraY. Berra

Page 15: Culture Clash: Law, Business and Technology Mitch Dembin Chief Security Advisor (US) Microsoft Corporation.

© 2004 Microsoft Corporation. All rights reserved.© 2004 Microsoft Corporation. All rights reserved.This presentation is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS SUMMARY.This presentation is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS SUMMARY.