My 12 year old son asked me the other day what does data sound like. Being asked a computer science question, no, more like a networking based question caused me to break out the hanky I reserve for those times when I find out my backup copy was a incremental instead of a full. I thought about the whistles of the old modems of yester year, the whirl of 8mm backup tapes, 2600 MHz tone of a phone switch, the capacitor start fans in a large router or switch (I have Goosebumps…) So with sage like wisdom of my 18 years in Information Technology I said, “Go ask your Mom” Truthfully if data had a sound, I bet it sounds more like “ka-ching” the sound of a cash register draining my IT budget. This is certainly true in network security. Since I can not make a living fishing, network security is my real bread and butter. I have shown the value of security over and over in presentations, videos, radio, Morse code you name it. And it is easy! I can scare 8 lives out of cat with hacking tools and stats. Security is needed so badly needed and misunderstood in our industry. After a presentation I have always feared a street smart “C” level Executive would come up to me and say, make a business case for what you presented without the scare tactics. I would have turned into Barney Fife trying to load a pistol. So now that I have exposed a deep dark fear of mine (OK that and my Mother In Laws chili…who puts macaroni, beans and tators in chili??) Let’s look at how we will justify spending cash on network security. First understand that your data has value. Not just a little, but a whole lot. 67.2 Billion USD is lost annually on computer related crimes according to the FBI. As a reference, in today’s money, it cost approx 135 Billion USD for the entire Apollo Space Program. With that kinda of money at stake, folks are going to work hard to get access to your data, very hard. Security is needed, but we can not just figure that we have an unlimited budget for security. If that was true, we would have Sales Reps stalking us like a pitbull on a pork chop. To do these calculations, we need to look at two factors; Risk Aversion and Risk Tolerance. But even before I do that, I want to give a shout out to Warren Saxe. I interviewed Mr. Saxe for a BizWiseTV episode and he opened my eyes to the real understanding of this concept. I highly recommend his book from Cisco Press titled: “Business Case For Network Security” Risk Aversion and Risk Tolerance are based upon data points you fill out in a 100 question InfoSec Management Survey scored 0-5 with 0 being not applicable and 5 being grave effects. The benchmark most companies test this against is ISO 17799, “The Code of Practice for Information Security Management.” Now do not rush thru this survey or pass it down to someone else in your organization. This should be completed by a “C” level Exec. This not only gives it immediate buy in, but also helps the “C” level set the vision and understand the process. IT folks should work with the results of this survey and not the vision of the survey. Risk Aversion is really something we learned for our grandmothers, “Better to be safe then sorry” This is a of course very subjective since one network admins risk is another ones adventure. I did some work at a large United States Government facility and they were under consistent attack. They did not give it a second thought. The alarms would go of with a warning of a hacker from Asia, and they looked my straight in the face and said, “Are you ready for lunch?” Risk Aversion is something that should be based upon your response to the InfoSec survey. This is broken down to two scores; an InfoSec Management quotient (IM) and an InfoSec Operational quotient (IO). The IM score is really the true pulse of your company’s aversion to risk. Remember in college in those boring humanities classes when taking a test the saying was, “When in doubt, it’s the Greeks” Please do not do this on this survey or score everything as being a 5. This part of the survey is for the senior IT manager or CIO to complete. It has IT policy, personnel and data related questions. The IO score is all other departments’ view of IT data services. It gauges what they view as critical and important to their contribution to the overall accomplishment of the company’s goals. This is for all of your different departments to complete. The rule of thumb is if they have a department head and a budget, they get a survey. Now, with these two data points complied you can compute your Risk Aversion Quotient. For example it will look something like this: IM quotient + IO quotient ____________________ = Risk Aversion 2 Now with some real data we can look at our RA with just same quick calculations. IM = 74 and IO = 67 74+67/2=71 or 71% Risk Adverse. Like all good math, that is never the end of the story, kinda like a weekend at the in laws…it keeps on going forever. Now we need to collate the RA number (71%) to a Risk Tolerance chart. An RT chart, (as it is called in the cool circles that computer risk folks hang out in yo) looks something like this: Risk Aversion Quotient 1-20 High 21-40 Medium-high 41-60 Medium 61-80 Medium-low 81-100 Low In our example, 71% is medium-low, so our company has a real need for a solid security system because our Risk Aversion and Risk Tolerance is medium-low as determined by all department heads and “C” level execs. Now we have the data points we need to look at truly justifying a security solution. All too many times I have seen companies with the best intentions in mind, purchase more security then they actually need. It is like seeing an 80 year old man driving a F60 Ferrari around. Come on man! an RA of 71% is out of the realm of a basic security system (all in one device and few add ins), but most likely not into the realm of a comprehensive solution either (redundant everything, monitoring agreements, dedicated security staff), we at looking at a moderate solution here to solve the problem of security and meet the budget goals of our organization. Just like with anything else, there comes a point where you actually have a dimensioning return on the equipment you purchase if you over buy. Using RA and RT as a tool, you can easily determine the security model you fit into based upon solid data and not conjecture. Pick up Warren Saxes book and read it cover to cover. This will really help make you a well rounded engineer and an even better manager/executive in the future. Just remember more pieces and parts do not make your network more secure if you do not have the staff to maintain and manage this gear. Actually, it can open more holes in the network. And let’s face it; there is no need to put sales reps in F60 Ferrari’s before they are 80… Jimmy Ray
Security Tax
Analysis
Nov 3, 20087 mins




