Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, April 11, 2012

Book Review: America the Vulnerable: Inside the New Threat Matrix of Digital Espionage, Crime, and Warfare

I guess I am in like a book posting series for now but since I had to do a book review to earn CPE credits for my CISSP certification I thought it would get a cheap blog entry this month with it.

This book was a great follow up to Fatal Systems Error for me. Joel Brenner, the author, is a former Inspector General of the National Security Agency, NSA, and was also the head of U.S. Counterintelligence for the director of National Intelligence.  This book explores both Cybercrime and Cyberwarfare with more emphasis in the latter. The author does give the reader a primer on Cybersecurity and how some attacks such as DDoS for example take place. However, because of Brenner’s insight into the US national intelligence system, the book focuses on what State-sponsored Cyberthreats represents to the international community, especially so to The US without going into much detail into how attacks happen. It describes how Cybercrime has evolved as a potential lethal weapon to a nation’s critical infrastructure (e.g. power, financial, communications, and military industries) by using the internet to disturb communications and information flow during warfare and references to how Serbians manipulated these tools during the Kosovo War; most recently you could probably relate to the Egypt Revolution and the critical role that communications and Social Media played there, and continues threats by the Iranian government to shut down communications in their country as a way to control and intimidate their opponents. When The People´s Republic of China, PRC, realized that they were too far behind from The US economics and military forces they identified an opportunity to explore other ways to build their technology and industries by exploiting the weaknesses of our current industries and military forces to steal classified information and intellectual property that they have used to catch up with the our technology and use it against us. Both government and the private sector are at fault here by not implementing the necessary security control and most importantly by failing to educate and create security awareness within their organizations. 

The moment of truth for me during this read was when I came acrros the excerpt below. The reason being that I work in a mid-size law firm and I couldn’t agree more with this statement which actually comes from a lawyer and partner in one of the largest 100 law firms in the US.

"The Chinese have other even subtler methods of stealing our know-how. Several years ago, while serving as the national counterintelligence executive, I sat with colleagues discussing how we would plan an espionage attack against an American business. And then a lightbulb went on: the law firms! Of course: A company’s outside intellectual property lawyers have its technical secrets, and their corporate law colleagues are privy to strategic business plans. And lawyers don’t like taking instructions from anybody, particularly their less well paid underlings who are responsible for network security. They’re impatient. In some firms the rainmakers have nixed even simple steps, like requiring a password on mobile devices that connect with the firm’s servers. They couldn't be bothered. Privileged with secrets, highly paid, often arrogant and usually impatient, lawyers are the perfect targets. I cannot disclose what I know because it's classified, but I can disclose that I know that my surmise was soon justified. U.S. law firms have been penetrated both here and abroad. Firms with offices in China and Russia are particularly vulnerable, because the foreign security services are likely to own the people who handle the firms' physical and electronic security. These services are not interested in stealing brilliant legal briefs; they want information about the firm's clients. Every law firm with offices in several continents holds privileged and sensitive electronic documents worth millions of dollars to a foreign service, ranging from investment plans to negotiating and business strategies, and much more." Think I got hooked up here? No kidding! This is what I am dealing with every day and is such a great challenge and opportunity for me as a professional. If you are in legal and have kept up with the news then you now know what Brenner knew. There are plenty of articles out there on how Chinese are attacking firmssecurity in law firms, or recent incidents such as Anonymous attacking law firms. Dear lawyers, this is a real issue for us and you guys need to pay attention.

Brenner also does a great job on identifying one of the most important problems that governments face: finding balance between transparency and privacy. While transparency says “Open Up”, privacy says “We are watching you and you are very restricted to what we want you to do.” Both transparency and privacy are about information which he refers to as being liquid. I love that analogy because information as liquid can take any form and be anywhere. The problem is that once liquid leaks, it is hard to figure out how, when and where it happened, not to mention that it is nearly impossible to recover it all. During this segment the author also references how organizations such as WikiLeaks operate by “turning the hose on” to let the precious liquid out. The appearance of WikiLeaks was a critical milestone to the proliferation of Hactivist groups such as Anonymous which supported them by launching DDoS to organizations such as PayPal and MasterCard that froze WikiLeaks funds in an attempt to stop their operations. It is important to note that WikiLeaks has a more organized structure governed by their decision maker Julian Assange, while hactivist groups do not have any type of hierarchy or governing entity and function as a group of people that support the same “values or ideas”.

In chapter 7, the author presents a hypothetical scenario where he illustrates how China could potentially create serious damage and pretty much “own” The US on the verge of war using techniques such as shutting down entire power grids in the US, sending off undetectable submarines to face The US Navy crafts and disturbing the financial markets. He actually mentioned that while his scenario is fictional, some of the penetrations and techniques used by the PRC have actually already happened.

Finally, Brenner presents what he believes are good practices to get both the public and private sectors together. Many of them are widely known, yet not practiced much. Here they are in a nutshell:

Public Sector:
  1. Stronger trade regulations and contracting. Requiring higher security standards from its vendors.
  2. Make Service Providers accountable. For example require ISP to notify customers whose machines are infected by a botnet.
  3. Stronger Energy Standards. Limit connectivity to a public network.
  4.  Tax code. Use tax incentives to encourage investment in cybersecurity
  5. Encourage and found research.
  6. Securities regulations
  7. International relations. International community needs to come together in all of these efforts.
Private Sector:
  1. Clean up your act! Assume that you have been attacked so monitor and mitigate.
  2. Control WHAT is in your system.
  3. Control WHO is in your system.
  4. Protect what is valuable.
  5. Patch, patch, patch.
  6. Train, train, train.
  7. Audit for operational effect.
  8. Manage overseas travel behavior.

    Friday, December 30, 2011

    2011: A Year Of Learning

    Hello everyone. I feel like I have abandoned my blog but I have been quite busy lately working in a few projects. I have been writing though, with two blog entries and two articles for the International Legal Technology Association, ILTA.

    What I want to accomplish with this post is not only summarize the highlights of my year, in terms of my career, but also what I learned from each project and situation and how I grew as consequence of them. So here I go.

    Writing
    I thought it was appropriate to start with this blog. It was launched in February with a goal of posting at least once a month but most importantly adding value. I did pretty well until the end of the year, when I got busy with our Windows 7 Roll out which I actually blogged about here and here. I feel like I continued to improve and define my writing style, and I learned how powerful social networks could really be. I never thought that I would reach over 1ooo people in three different continents with just a few posts and I hope I am adding value. Furthermore, I confirmed something that I know and practice; not taking action in your ideas and projects is a bad habit. Keep posting is a commitment that I made to myself and I am happy with the results primarily because I also participated in our ILTA Connected Community blog, but there are a couple of entries that I started and I think that would have been great and timely but never finished. So the take away is that once we have an idea or commit to something we must take action and finish it.

    Many of you know that I serve as the Servers Operations & Security Peer Group VP for the International Legal Technology Association, ILTA and we launched a new blog which we hope will add value to our members. You can read not only our posts, but other formidable entries regarding Legal Technology here. In addition I wrote an article on Network Security for ILTA’s Risky Business White Paper and another for their Peer to Peer Magazine which describes how I work on strengthening my mind to achieve results and goals which you can read here. Again, I was reminded that I really need to make sure that I know and understand what I am writing about, which is the case, because of the impact that it could have in others. I re-affirmed that the goal is to add value.

    Technology
    I was pretty busy at Nexsen Pruet early in the year with infrastructure projects that included enhancing our dual MPLS network architecture by adding a second router to each location (formerly dual-homed in a single router). I learned more about BGP and EIGRP routing during this project and that while our network got more robust, it also did get more complicated. I also learned that Disaster Recovery and Business Continuity (DRBC) is an ongoing process that needs to be tested and adjusted properly as network and system topologies evolve. Besides, I again confirmed the importance of keeping good network and systems documentation up to date.

    Four other major projects took place: an upgrade to our Video Conference infrastructure (VC), which I posted about here, the introduction of Application Level Monitoring through Riverbed’s Cascade appliance, expansion of Mobile Device fleet by introducing iPhones and MobileIron as our MDM solution, and a merger. I learned that while our VC system was heavily used the quality of experience by both the participants and IT folks in our team was very poor. Yes the investment was hefty, but the user experience has improved dramatically and in the last 2-3 months the adoption of desktop video both internally and externally has grown and is already in demand for 2012. That in addition to the ease of management tools of the new systems has probed the investment worthy.

    We now have a better idea of what is going on in our network as far of traffic. We had been using Netflow collectors for a while which gave us a good picture of who was doing what, but I now personally have a much stronger understanding of how our applications interact with users and each other. Cascade gives us a great picture of all pieces interacting in a user action within our network and when there is a problem, it could tell us where it is, whether it is the network, servers, or clients. We are still on learning mode with this tool.

    The introduction of iPhones and a merger kept me busy for a while. Whereas I learned a lot about mobile technologies and enhanced my knowledge of general security practices, I also discovered one a new passion on these two projects: Project Management. I have been managing projects since I became the Network Manager at the firm especially around telephony and facilities having c0-managed the last office move from a technology standpoint. The reason I like PM and that I will make an effort to continue to learn about this topic is because it gives me skills outside IT that I feel I need in order to continue to advance my career, specially so Risk Management, an area of great interest to me at the moment. I am not at a PMP level yet but I think that I am doing well and in fact, I have been tasked with building our Technology Project Management practice at the firm and now have a very talented PM reporting to me.

    The rest of the year was dedicated to our Windows 7 and Office 2010 rollout. I learned so much that I don’t know where to start; from how many specialty applications we are running, to how attorneys and their staff work and use those apps, to how successful you could be when everyone is on board and rowing together towards the same goal. This was the most rewarding, and one of the most successful projects that I have been part of, and again, project management and planning was the key. My role during the project was of Deployment Manager in two different offices and Project Manager in two others. I learned a lot about how attorneys at different offices and practicing different laws work, and how unique their practices are. The most satisfying part of the project though, was seeing how so many talented people in our Technology Department grew during this project. This project also let me understand how important making adjustments while staying focus is; things go wrong, get delayed or even completely pushed out of the initial plan, but you must remain focused on the end goal and adjust as you go, which means that you must evaluate where you are constantly.

    Leadership
    I will never want to stop learning on this area, period. It is such a broad and complex, yet intriguing topic that I think evolution is the key to its mastering, if there is such thing. Anyway, as mentioned earlier I lead a group of legal technology professionals for ILTA. I got appointed as the VP for the Servers Operations Peer Group in August. One thing that I learned firsthand is how important succession is. My predecessor, Bob DuBois, did a great job getting me ready for the transition by assigning task with great visibility into both our team and the whole organization. Task that might seem trivial such as participating in calls with his peer officers or running our meetings really built confidence and got me ready to take it to the next level. This is something I have been doing since day one I became a manager but I had never seen in practice. I got promoted to a management role like many others because of achievements and results in the operations area without little management training or experience and it was a little tough at the beginning, but while adjusting and keeping focus made a difference then, I can now appreciate how much better it could’ve been if we planned ahead. I also learned how to deal with a larger team and building a new team, not to mention how different it is to manage your team at your company compared to managing a team of volunteers.

    I also learned that leadership is about value, communication and helping others grow. Bob did a great job helping me transition to my Officer role and I recognized that and will always try to apply it as a way to help other grow. As we were getting ready for full deployment of Win7 my director and other project leaders recognized that the 3rd party Project Management that we had hired for the project would not be a good fit going forward. He did a great job getting us to a point but things started to not go so well during the first office deployment. My Director approached me and asked me to take over as the Lead PM because we had discussed moving PM under me based on success in projects that I had led. Because of my passion for this area I was excited and honored by just being asked to take over such an important task. However, I also recognize an opportunity to build and help someone grow. We had hired our current PM a few years ago as a PM, but he never really had a chance to lead any project because of many different reasons. I saw this as his chance to grow into the role and gain credibility. He had just completed his Project+ certification and I ask my boss if he would be willing to let him lead the project instead. He hesitated a bit but I asked him to trust me, and most importantly, to trust him and he agreed with the condition that I stayed on top of it behind the scenes, which I did by mainly emphasizing communications. The rest of the project was a big success and I was greatly satisfied by seeing this person succeed when people doubted him.

    So what is it about value? This year, during some hard times when the dark side wanted to take over me, I really had to dig and rediscover my core values. I learned that if I stick to those my whole life will make more sense to me and my family anyway, and I will in turn, be able to add more value to those around me. I thank Randi Mayes, Executive Director of ILTA, for her wise words on this topic and continued commitment to helping ILTA's officers and volunteers to grow.

    My most precious take away about leadership, is that I am now learning how to apply all of these concepts to my personal life. While I think that friends and family have always looked up to me and willingly followed me, I never saw it as an opportunity to lead. Leading my family is my most important task and growing together as successful people is my most rewarding and precious treasure and I can now do it with a leadership approach which is enhancing our already strong relationship and making our core values stronger. It doesn’t get any better than that!


    That's it. It was a year of learning, and it will always be. I will soon post on what is ahead for the 2012 year. I hope that it bring energy, health and prosperity to all of you and your families.


    Here to a great 2011 and an even better 2012! Happy New Year!

    Wednesday, April 27, 2011

    Using Managed Services and SaaS in your Information Security Strategy Makes Sense.

    Over the last several weeks we’ve seen how big corporations have been hit by security incidents. Those who made the news were often because of incidents related to Data Loss, such as WikiLeaks or Episilon events. They show the need for security professionals in the enterprise is increasing. And there are other areas of concern like the current landscape of advance threats, internal threats from disgruntled employees or insider trading, or increase in usage of services like Dropbox, Skype, and mobile devices among others. And when solid Information Security vendors such as RSA and Ashampoo experience data security breaches, I just wonder if there is hope for the rest of us? I believe there is and it may not be inside your organization.


    When it comes to information security I believe that you must hire the best resources that you can. Whether internal or outsourced this group must have the skills, knowledge and access to do what they need in order to preserve your company’s data, which should be one of the most valuable assets of the organization. And hiring partners in the form of SaaS and Managed Service Providers, MSP, makes sense because hiring your own resources with those skills will certenly be very costly.


    We are a small team of two and half that is responsible for Network Infrastructure and Security for an eight offices, 400 employees law firm. None of us is a full time Security Professional dedicated to the area and that is why I have been making strategic alliances with our Security Vendors that can help us built a strong security team. For years we have partnered with DELL SecureWorks, one of the world’s strongest Security MSPs. Although all of us are very good security engineers with security certifications and strong skills, we just don’t have the manpower to dedicate a FTE to be watching firewall logs and alert us of possible incidents. The superior work that SecureWorks does led me to grow our relationship by also outsourcing two areas that are important to any security program, especially when regulations like HIPAA for example, are part of the conversation, such as IDS/IPS and Log Retention. They add value to our team by tackling the biggest challenges that these technologies present: keeping up with the logs and alerting when suspicious behavior is present. We still have to do our part, which is reacting to the alerts and mitigating the threat, but we have been able to react and pull machines out of the network or close a whole within minutes. Even if we had a dedicated resource for this area, I don’t think that we would be able to react and take action that quickly.


    We’ve also hire SaaS companies to help us secure other areas of our network perimeter, specifically email spam, malware, and DLP filtering, and also Web Content Filter. We are currently transitioning our email edge security to Proofpoint, which has immediately added value to our security program with its very strong DLP engine. There are two things I like in particular about this vendor; one is that we don’t have to maintain the DLP dictionaries, something that most vendors would defer to you. The other one is that the appliances which are not in our premises, would attempt to make a TLS connection to the peer email server(s) and if it can’t and there is sensitive information, then it would send a secure message to the recipient. We still need some folks to look through logs and take some actions but less is required from our team. This setup is becoming kind of the standard on today’s email security practice.


    At the web browsing edge we have merged from a complex in-house solution composed of three different vendors to another SaaS solution with ZScaler. Since merging to it, the Malware infection in our machines has decreased by 60%. We filter through many gateways in Zscaler’s private cloud by putting a PAC file in the machine’s web browser and the user then filters through the closest gateway to her. This is generally kind of pre-set when the user is in the office because we would always hit the closet gateway to our data center, and will fail over to the next closest one if the one goes down. Now we also have the ability to protect our laptop users when they are outside our offices. In that case, the Zscaler’s Geo-Location feature kicks in and the user browses through the closest node to her, whether she’s in her house, California, or Europe she will always hit the closest gateway available and proper security policies will be applied. The only time when we get involved is when a website is blocked and it someone needs access for business reasons. Many other capabilities are available with this engine, such as throttling bandwidth for media streaming or file transfer, which we use, DLP, which we are testing, or ability to prevent users from posting to media sites such as Facebook or Twitter. It can also block web access from pre-determined browsers, such as old IE, or Firefox for example.


    Our team is still responsible for managing areas such as Anti-Virus and Malware, securing network gear, Server and Workstation patching, some areas of physical security and soon HDD and Media encryption, which are all candidates for outsourcing as well. However, we are much more effective by working with trusted MSPs and Security SaaS vendors than if we did it all in-house because. First of all, proper staffing to achieve the same goals would be costly and today is simply out of reach, and second, they can help us keep up with the ever changing and developing threat landscape while reacting to real attacks in a much faster and effective way. In addition, I can now concentrate in developing Policies and Procedures, Incident Response, as well as the other operation areas that me and my team are responsible for. It just makes sense to go this route as opposed to investing on in-house skills.

    Monday, April 18, 2011

    ILTA Conference 2011. Server Ops and Security, and Tech Ops Teams will deliver great content

    2011 rev-elation Conference is approaching and our Server Ops and Security PG is bringing great educational content to it. Our fabulous Steering Committee team, led by Bob DuBois, and completed by myself, Tom Crowe, Mark Brophy, Nate Smith, Dave Nevala, and Toni Brester has done a great job developing sessions around topics often seen in the discussion boards around different technologies that support our demanding law firms. But first, a quick overview of the Conference Team.

    The journey began on Friday August 27th of 2010 while many of us where returning from the fantastic 2010 Strategic Unity in Las Vegas. Right then, our awesome Co-Chairs two-year veteran, Meredith Williams, first-year Co-Chair Kathy Lentini, BoD Liaison, Eric Anderson, along with ILTA’s TJ Johnson and Peggy Wechsler, began looking at their strategy to tackle this year’s conference. As for myself, I am on my 2nd year representing the SOSPG in the Technology Operations Track. Meredith and Kathy made a great choice by appointing Skip Lohmeyer as Tech Ops Team Leader and together they brought in an impressive group of Legal Technology Professionals that make up our team. The same is true for the other three teams that complete the whole Conference Committee, which are Information Management, Organization Management and Applications/Desktop. Together the committee has come up with almost 200 educational sessions. I thought that last year’s conference was the best that I had ever attended; today I realize that I will say that after each conference that I attend. It is just amazing how the team came up with this amazing content, and how ILTA does it every year. Last but not least, Gaylord Opryland Resort has made an impressive recovery work after being 8-10 ft. under water after the flood in Nashville last year and it is looking better than ever; what a gorgeous venue for our Conference. Oh, and they will tell us their recovery story in Conference. You can’t miss it.

    I can only give you a 10K ft. view of what we are bringing to conference as a Peer Group but I am very excited about our sessions and I know you will as well. The team tried to create good balance to bring relevant content that can have an immediate impact on technologies that you are currently evaluating from a servers operations and security perspective. In addition, the whole Tech Ops Team is delivering equally well balanced and amazing advanced sessions in areas of technology infrastructure that support our computing networks. Here is a quick view:

    IPv6. Yes is finally coming. And it will be at ILTA this year as well. We are teaming up with the Emerging Technologies PG to deliver two sessions that will unveil IPv6 for us and what it means to how will be running our networks soon. As a reminder, watch out for “World IPv6 Day “on June 8th. If you thought this is not relevant think again as Asia have ran out of IPv4 and Europe is next as reported by NetworkWorld here http://tinyurl.com/65e6d7v

    Endpoint and Media Encryption. Three different Law Firms will tell their story on why this technology is needed, what’s available, what to watch for. There will be content for all firm sizes here.

    VDI. We’ve done this one before, but never at this scale. See how two very large firms with global foot prints have delivered hundreds of Virtual Desktops effectively. An impressive session is being developed with equally impressive speakers.

    Securing the Virtual Environment. You have to come see this one because traditional security no longer applies to the virtualized world.

    Upgrading to Exchange 2010. How do you prepare for it? What challenges can you encounter when coming from different previous versions? Two firms and one of our great ILTA Sponsors will prepare you for it.

    Technology Operations Forecast. The way we design, implement, and manage technology will not be the same. This session is part of ILTA’s Law 2020 initiative.

    And there are other amazing sessions being delivered by the Tech Ops Team which include, a Disaster Recovery session where the Gaylord will tell their story after the flooding and a global firm with offices in Japan will do the same after the massive earthquake and Tsunami that hit them this year. Other Sessions include DLP, Exploring the Exchange 2010 Ecosystem, Hosted Communications (both voice and email), Securing Windows 7, Keeping Documents Secured in Mobile Devices, and Change Management Impact on Tech Ops.

    Go register for this year conference, and when you get there, check out the SOSPG group and Tech Ops sessions. You don’t want to miss this year’s conference! And please join me on thanking the amazing people behind our PG and Conference Committee teams for contributing with their time and knowledge to help ILTA make this great conference happen!

    About ILTA. For over three decades, the International Legal Technology Association has led the way in sharing knowledge and experience for those faced with challenges in their firms and legal departments. Through delivery of educational content and peer-networking opportunities, we provide members information resources in order to make technology work for the legal profession. Visit ILTA at www.iltanet.org

    Sunday, February 6, 2011

    Technical Safeguards for Legal regarding HIPAA

    In February 2010 the Legal Industry got hit with a pretty big compliance issue when the HI-TECH Act made changes affecting HIPAA Business Associates. The legal world gets directly affected by these changes because Law Firms that work with Covered Entities through their Health Care, Litigation, and perhaps other practices, become Business Associates. I will not go any further into details of the actual specifications of the law. Instead, I will focus on what you could do to implement Technical Safeguards to protect Electronic Protected Health Care Information, ePHI. Meanwhile, I will refer you to ILTA’s HIPAA Rules for Law Firms article enclosed in the Peer to Peer edition of March 2010. Notice that I am only dealing with Electronic PHI here, and hard copies of this form of data deserve attention as well.
    Protecting that pesky ePHI and THE FIRM
    HIPAA brings new Information Management and Information Security challenges to the legal industry and its technology practitioners but it is also a good opportunity to protect your firm as a whole, which I have been preaching since engaging in the HIPAA project because of my background on security. Any regulatory compliance requirement that your firm is going through is an opportunity for the Technology Department to build a strong security program around it. You may not need to apply specific HIPAA safeguards to the whole firm, but I can assure you that there are other regulations that you need to comply with, and if that is not the case, it is just common sense, especially with new regulations around Personal Identifiable Information around the nation.

    Since we are focused on HIPAA here, let’s take care of the Health Care practice and the HR area that deals with ePHI and problem solved you may be thinking. Wrong! Expect MANY folks outside the Health Care practice to be BAs because involvement in different Matters. I encourage you to conduct a survey asking who handles any type of PHI, whether electronic or not. I bet you will be astonished with the results.
    BUT WHERE IS THAT DATA? I mean, really. Do you know where all the ePHI is? If you do, then I salute you. Oh, and I know that you are thinking about your Document Management System, DMS, your Financial Systems, and your File and Print servers. Is that it? Can you probe it? How about laptops, desktops, and other servers? This is an ongoing process and the stepping stone of any implementation that follows. You can’t protect something that you are not aware of. It is important to understand that you must be able to log and audit your systems in order to probe compliance. Thus, my inclination for systems that meet that critical requirement.
    Today there are tools that can scan your network and leverage built-in dictionaries and rules that help you identify compliance specific data. They are often referred as DLP tools (Data Leak/Loss Prevention tools) however, don’t rely on them completely. Talk to the data owners and users as well. I have found over the years that users are the best resource that you can use while building your security program.
    We found the data, let’s build the Fort
    Let’s start with Access Control. Make sure you understand your network as a whole, especially your Active Directory (AD) Security Groups and other security elements of it. I am sure that you follow industry best practices, but can you audit and probe that? Implement a strong Security Information and Event Management tool, SIEM, which goes beyond traditional Log Aggregation. Products such as TriGeo, and LogRythim have built-in “intelligence” that not only can help you log and audit, but also aid your Change Management strategy, something I am big on as stated in my last post. You will gain visibility into any changes made into your security groups. There are also AD specific auditing tools that can aid on this area and may be more accessible such as ManageEngine products.
    Additionally, take a look at your Ethical Walls approach and see if you can extend it beyond your Records department. It is extremely important that there is ongoing communication and collaboration between IT and Records during this process so that you can expand your strategy to areas of IT such as DMS, and Financial systems through software like RBRO, WincWall or IntApp, in addition to Risk Management built-in features in your DMS or Financial systems.
    Data in Motion is not only email
    We often think of Data in Motion as email, so let’s start there. My background in Health Care taught me one thing: securing ePHI moving through your messaging system could become a nightmare if not thought thoroughly. In my experience I’ve found that the first thing to mind is TLS, which is a great encryption method, yet unmanageable in mid-size and large environments. The same applies to a Certificate based PKI approach. In both cases, the challenge is managing all those certificates and keys. Furthermore, you’ll have to deal with those smaller Health Care practices that don’t have an IT Department capable of setting up managing their end.
    A third solution includes full email encryption products that deliver encrypted messages to the recipient’s inbox. Products such as Cisco’s IronPort, ProofPoint, or the very well-known in the Legal vertical Mimecast deliver messages either as encrypted attachments or with a link that will redirect you to a secure site where you can read your messages and take action on them. I highly favor this approach because they are centrally managed, more scalable, and have stronger logging and reporting capabilities. However, be prepared to provide clients with the other two alternatives. You will come across end-users that will hate having to go through an extra step to “just read an email”.
    Then there is the new world of mobility, which includes Laptops in all forms, USB drives and other removable media, Smartphones, tablets and the list keeps growing.
    You can address issues around laptops and removable media with Encryption tools such as those offered by Check Point, PGP, or Credant, or the free, yet extremely strong TrueCrypt. You will have to pick “your pain” when it comes to encryption. If you choose to go with a Full Disk Encryption approach then you are going to have to deal with pre-boot authentication, which can become a pain when performing trivial tasks such as troubleshooting a system that needs to be rebooted, or deploying software upgrades (in addition to the adoption opposition). If you go with just File Level Encryption only, your devices may still be exposed to Brute Force attacks. And then, there’s Credant’s interesting approach, which encrypts at the file level, yet, it protects the machine’s registry that deal with AD Security database and swap files, which protects the device against access attacks. I really like this approach.
    Encryption tools also protect removable media such as USB drives and even SIM cards in Smartphones by deploying policies that can limit device access, white list them so that only approved devices are allowed, and encrypt data in a similar way as previously described. Just make sure that you are aware of what your mobile device float looks like and that you set expectations with regards to client involvement, meaning, what to do when you send data and devices to each other.
    Smartphones are also a concern, and although most people think of the problem in regards to email I think that we need to look further and create a strategy that address security concerns around it as a whole, just like you handle laptops. As stated in 2010 ILTA Conference session, Strategies for Managing Disparate Devices in Your Mobile Fleet, these devices are PLATFORMS, so you must threat them as such. I will dedicate a different post to this topic, but for now, know that there are tools that can help you manage these devices by separating corporate data from personal data and in turn, encrypt and control the business data and take action such as deny access or remote wipe the firm’s data. Examples include Good Technologies, MobileIron and Zenprise. McAfee and TrendMicro among others, are also coming up with AV Software for these devices, which in my opinion, will be a must have by the end of this year.

    If your firm is dealing with HIPAA, then take this an opportunity to enhance your Information Security program, which in my opinion, has been traditionally too loose in the Legal sector. I will be blogging later on Information Security Policies and Procedures, as well as Disaster Recovery, which are important areas to achieve HIPAA compliance.
    What is your firm doing to protect Electronic Protected Health Care Information? Moreover, what other regulations are hitting your firm?