42
The difference between the “Reality” and “Feeling” of Security Human Perception and it’s influence on Information Security She looks trustworthy I’m gonna steal your toys

The Difference Between the Reality and Feeling of Security by Thomas Kurian

Embed Size (px)

DESCRIPTION

The paper shall focus on the following: The paper shall focus on the following: 1) Introduction to the problem: Focus on “security awareness”, not “behavior” 2) Real life case study of why a US$100, 000 “security awareness” project failed a. Identifying the human component in information security risks b. Addressing the human component using “awareness” and “behavior” strategies 4) Sample real-life case studies where quantifiable change has been observed Original research and Publications The talk is modeled on the methodology HIMIS (Human Impact Management for Information Security) authored by Anup Narayanan and published under “Creative Commons,

Citation preview

Page 1: The Difference Between the Reality and Feeling of Security by Thomas Kurian

The difference between the “Reality” and “Feeling” of Security

Human Perception and it’s influence on Information Security

She looks

trustworthyI’m gonna steal

your toys

Page 2: The Difference Between the Reality and Feeling of Security by Thomas Kurian

The 3 pieces that makes up information security

2

Technology (Firewall)

ProcessPeople

Information

Technology and processes are only as good as the people that

use them

Page 3: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Focus of the talk

• The Human Factor in Information Security

• The difference between “Awareness and Competence”

• The power of perception

• Solution Model + Examples

3

Page 4: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Awareness

I know the traffic rules….

4

Page 5: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Competence?

Does it guarantee that I am a good driver?

5

Page 6: The Difference Between the Reality and Feeling of Security by Thomas Kurian

….even in Information Security!!!!

6

Security Security Security Security

PolicyPolicyPolicyPolicy

Never share

passwords

Don’t tell anyone,

my password is…..

Page 7: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Awareness >> Behaviour >> Culture

Awareness

• I know• I know

Behaviour (Competence)

• I do• I do

Culture

• We know and do

• We know and do

Aim for a responsible security culture

7

Page 8: The Difference Between the Reality and Feeling of Security by Thomas Kurian

What organizations need?

A system that periodically shows the current

Security Awareness and Competence Levels

LOW AWARENESS MEDIUM AWARENESS HIGH AWARENESS

Awareness score is 87%

Competence score is 65%

LOW COMPETENCE

MEDIUM

COMPETENCEHIGH COMPETENCE

8

A smart attacker will always try to influence the perception of the employee

Page 9: The Difference Between the Reality and Feeling of Security by Thomas Kurian

The power of perception

Why do people make security mistakes?

Page 10: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Imagine…

APJ Abdul Kalam walks into this room right

now and offers you this glass of water….

10

Page 11: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Now, imagine this…

This man walks into this room right now

and offers you this glass of water….

11

Page 12: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Question

Which water did

you accept?

Why?

12

Page 13: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Analysis

People decide what is good and what is bad based on “trust”

Perception is influenced by Trust

Were you checking the water or the person serving the water?

13

Page 14: The Difference Between the Reality and Feeling of Security by Thomas Kurian

How people make security decisions?

Influence of perception

14

Page 15: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Analysis

Of these two, which terrifies you the most?

15

More people die of heart attacks than by getting eaten by sharks

You may feel safe when you are actually not

Page 16: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Analysis

Of these two, which terrifies you the most?

16

More kids die choking on french fries than due to Adrenoleukodistrophy

People exaggerate risks that are uncommon

Adrenoleukodistrophy

Page 17: The Difference Between the Reality and Feeling of Security by Thomas Kurian

I hope now it is clear that we must address the human factor….

Let us summarize…

17

Page 18: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Reason 1: Security is both a “Reality” and “Feeling”

18

For security practitionerssecurity is a “Reality” based

on the mathematical

probability of risks

For the end user security is a

“feeling”

Success lies in influencing the “feeling” of security

Page 19: The Difference Between the Reality and Feeling of Security by Thomas Kurian

RSA Attack

19

Page 20: The Difference Between the Reality and Feeling of Security by Thomas Kurian

The Incident

In March 2011, RSA, one of the foremost security

companies in the world disclosed that cyber-attacks had

penetrated its internal networks and extracted information

from its systems.

The consequences were

• Financial Loss

• Reputational Loss

Page 21: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Attack

Employee clicked on the attachment of the mail

The embedded component exploited the

vulnerability

Page 22: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Analysis: Why did the attack happen?

Page 23: The Difference Between the Reality and Feeling of Security by Thomas Kurian

RSA must be having best-in-class firewalls, anti-viruses and other

security systems. So, how did this attack happen?

You may wonder…

Failed to address the Human Factor

Page 24: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Reason 2: Technology…yes, but humans…of course!

24

Aircrafts have become more advanced, but does it

mean that pilot training requirements have reduced?

Medical technology has become more advanced,

but will you choose a hospital for it’s machines or

the doctors?

Page 25: The Difference Between the Reality and Feeling of Security by Thomas Kurian

The Solution Model

Security Awareness and Competence Management

Page 26: The Difference Between the Reality and Feeling of Security by Thomas Kurian

The solution is based on HIMIS

• HIMIS – Human Impact

Management for

Information Security

• Released under Creative

Commons License

• Free for Non-Commercial

Use

http://www.isqworld.com/himis

26

Page 27: The Difference Between the Reality and Feeling of Security by Thomas Kurian

HIMIS Implementation Model

27

Define Strategize Deliver Verify

Responsible Information Security Behavior

Page 28: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Define

28

• Choose the ESPs

• Review and approval of ESPs

Page 29: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Strategize

29

For awareness management

• Coverage

• Format & visibility: Verbal, Paper and Electronic

• Frequency

• Quality of content

• Retention measurement.(surveys,quiz)

For behavior management

• Motivational strategies

• Enfoncement/ disciplinary stratégies

Page 30: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Deliver

30

• Define tolerable deviation

• Efficiency

• Collection of feedback

• Confirmation of receipt

Page 31: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Verify

31

• Audit strategy

• Selection of ESP’s

• Define sample size

• Audit methods

For awareness: Interviews, Surveys, Quizzes,

For behavior: Observation, Review of incident reports, Social

engineering?

Page 32: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Examples

• Deploy false emails seeking

information

• Tailgating into the facility

• Placing media labeled with

‘confidential information’ in

cafeteria or other places

32

Page 33: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Reporting model

33

LOW AWARENESS MEDIUM AWARENESS HIGH AWARENESS

Organization’s awareness score was 87%

Organization’s competence score was 65%

LOW COMPETENCE

MEDIUM

COMPETENCEHIGH COMPETENCE

Page 34: The Difference Between the Reality and Feeling of Security by Thomas Kurian

HIMIS Focus

Page 35: The Difference Between the Reality and Feeling of Security by Thomas Kurian

ESP

Awareness

Behaviour

(Competence)

Assess,

Improve, Re-

assess

ESP – Expected Security Practice

1. Differentiate between Awareness Vs. Competence

35

Consider both “Awareness” and “Competence” independently

Page 36: The Difference Between the Reality and Feeling of Security by Thomas Kurian

2. Visualize ….and influence perception

36

Page 37: The Difference Between the Reality and Feeling of Security by Thomas Kurian

3. Scenario based training (Make people solve challenges)

37

Page 38: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Example

38

Video (PLAY)

Page 39: The Difference Between the Reality and Feeling of Security by Thomas Kurian

4. Remember drip irrigation

Small doses, more frequent

Which is more effective – Drip irrigation or spraying a lot of water once a day?

39

Page 40: The Difference Between the Reality and Feeling of Security by Thomas Kurian

5.Re-measure frequently

40

LOW AWARENESS MEDIUM AWARENESS HIGH AWARENESS

Organization’s awareness score was 87%

Organization’s competence score was 65%

LOW COMPETENCE

MEDIUM

COMPETENCEHIGH COMPETENCE

?

?

Page 41: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Summary

41

“A smart user in front of

the computer is a good

security control and is

not that expensive.”

Page 42: The Difference Between the Reality and Feeling of Security by Thomas Kurian

Let’s switch ON the Human Layer of Information Security Defence

Thank You

http://www.isqworld.com/himis