Monday, 29 June 2009

UK Government Cloud?

So, it looks like the UK Government really may go for cloud. The Carter Report, "Digital Britain", includes a number of references to cloud computing and particularly the use of cloud computing in Government - the fabled G-Cloud. I've quoted a paragraph from the report below.

"The establishment of a G-Cloud will however require investment in
technical development and physical facilities, and the CIO Council and the
Intellect Public Sector Council are now developing the strategic business
case to justify funding the G-Cloud. Provided that this business case can be
properly developed, the adoption of the G-Cloud will be a priority for
Government investment to secure efficiencies, even within the very
constrained framework for public expenditure, over the next 3 years."

The nice thing about this paragraph is that they've even put some timelines in there - 3 years. I don't know about you, but I always feel that things are more likely to happen once people put numbers in timelines rather than aspirational references to the future.

The Carter Report, coupled with the well-publicised posting by John Suffolk to the Cloud Computing Interoperability Forum (CCIF) (see http://groups.google.com/group/cloudforum/browse_thread/thread/c75cde1d7c519363) is all very positive for the adoption of cloud within HMG. But what really makes me believe this is a serious initiative? Well, according to several reports in the IT press Martin Bellamy (formerly Head of Connecting for Health) has moved to the Cabinet Office primarily to look after the G-Cloud strategy - a significant investment by HMG at this time of budget cuts. Watch this space :-)

[Disclaimer: I am a small part of the CIO Council/Intellect Public Sector Council work referenced above so may well have an interest or two here].

Wednesday, 24 June 2009

Nessus web app tests

Well well well. For years now I've enjoyed laughing at pen test firms who answer the question "So what do you use to do your web app testing?" with "Nessus". But, looking at the blog post linked to below:

http://blog.tenablesecurity.com/2009/06/enhanced-web-application-attacks-added-to-nessus.html

it appears that Tenable have stepped up their game somewhat to deliver some useable web app security tests. I have to state that I haven't had chance to try out this new functionality but it certainly looks to be an improvement on the old cgi checks. Maybe I'll have to stop laughing now and just chortle a little instead... (it's still not the tool of choice for serious web app testing - as Tenable acknowledge. Horses for courses.)

Friday, 5 June 2009

Cloud proliferation

In some ways I believe that the adoption of cloud computing services within enterprises will take a very similar form to that which we saw for wireless networking a few years back. And for very similar reasons - convenience, cost and the lack of reliance on central, often unresponsive, IT departments.

So what should we do about it? Well, rather than let it get out of control which (let's be honest!) happened to a number of organisations with respect to wireless networking, organisations should be

i) adopting policies governing acceptable cloud usage and
ii) monitoring network traffic to ensure that no unauthorised cloud usage is occuring.

More to the point organisations should be doing this now - regardless of whether they have any organisational desire to embrace cloud services. Just because a central IT function does not fancy the prospect of cloud computing, there is no guarantee that projects and programmes will not strike out independently. Time to get a grip now, don't you think?

Saturday, 30 May 2009

Latest article

No posts for a couple of weeks now - mainly as I was on holiday for one of them :-)

As a gentle way back in to the blogosphere, my latest column was in Computer Weekly this week and it can also be found on-line at:

http://www.computerweekly.com/Articles/2009/05/13/236008/security-zone-penetration-testing-define-your-objectives.htm

My main thrust in the article is that penetration testing should not always be the first option with respect to obtaining a realistic view of the actual implemented and operated security posture of an organisation. I am of course aware that there are situations where nothing other than a full-blooded pen test will be appropriate but there are other times where a simple configuration review will provide more bang per buck. I'm expecting a bit of a bashing over the definition I provided for penetration testing but what's the point of writing articles if you can't have a bit of fun!

Friday, 15 May 2009

Talking to lawyers. For fun :-)

An interesting week.

I was fortunate enough to be invited along to present at the Society for Computers and Law conference on Information Governance which was held last Tuesday. I was part of a panel session discussing the current increased focus on data security - initial indications are that the session was well received. I think it's important that we security types occasionally step outside of our usual haunts and talk to those in related fields.

For example, Lorna Brazell's presentation on how Identity is defined within law was particularly enlightening. I think security professionals tend to view the law as something relatively fixed rather than something that is also evolving and finding its place in the modern information society. The final presentation of the day on the legal requirements related to cloud computing seemed a good example of where lawyers and security professionals could work together to the benefit of both parties. Overall, a good event and one I'm glad I attended - and not only because of the bottle of bubbly generously donated by the SCL to each of the speakers :-)

Thursday, 7 May 2009

Is CC evaluation worthwhile?

I had cause to read through the VMWare ESX Server 3.0.2 EAL4+ certification documentation earlier today and it has given me a bit of a problem. Not a real-world work problem, more of a general problem with the evaluation process and it's value.

Reading through the Security Target, the following assumption immediately jumped out at me (ok, it's a few pages in so immediately is a bit of an overstatement):

"The threat agents are assumed to:
  • have public knowledge of how the TOE operates
  • possess a low skill level
  • have limited resources to alter TOE configuration settings
  • have no physical access to the TOE
  • possess a low level of motivation
  • have a low attack potential"

Now let's pretend I'm working for a Government client with Foreign Intelligence Services as an attack source - low skill level? Low level of motivation? Low attack potential? I should be so lucky... Oh well, at least the evaluation included some penetration testing - let's take a look at the certification report:

"The evaluator conducted a port scan of the VMware® ESX Server and VirtualCenter. Only the ports required for operation of the TOE were found to be open. The evaluator used a publicly available tool to scan the VMware® ESX Server and VirtualCenter for generic vulnerabilities, and none were found. In addition, the evaluator performed direct attacks on the VMware® ESX Server and VirtualCenter, attempting to bypass or break the TOE’s access control security mechanisms."

Is it me, or is that a little light for a penetration test? I'm not particularly re-assured.

Of course, the big problem is this: organisations (private and public sector) looking to deploy EAL4+ certified products are usually those with highly skilled, highly motivated threat actors. If some EAL4+ certifications do not cater for these threat actors what is the real value of those certifications?

(At least here in the UK, HMG organisations can turn to the CTAS process for assurance of specific technical barriers.)

Friday, 24 April 2009

It's getting real now...

Well it's been an extremely interesting couple of weeks with respect to cloud security.

(Yes, I know there've been some other happenings in the wider world - Obama releasing TS documents, Darling admitting the UK will be broke for the next decade etc etc but let's concentrate on the really important stuff :-)

The Open Group's Jericho Forum released it's Cloud Cube paper on cloud security which describes possible cloud 'formations' according to four different dimensions - Internal/External, Proprietary/Open, Insourced/Outsourced and Perimeterised/De-Perimeterised. I don't believe that there's anything earth-shatteringly novel contained in the paper however the model itself will, I think, prove extremely valuable as a common reference point when discussing cloud computing.

The other major event has been the release of the first deliverable from the Cloud Security Alliance - a guidance paper on the critical security issues with respect to cloud computing. On first glance it looks like a fairly comprehensive paper that could perhaps be used to populate the framework provided by the Jericho Forum Cloud Cube model. And with names like Chris Hoff and Jeff Forristal (better known to some of you with memories longer than a goldfish as rfp) involved you can be sure that the content is going to be at least sensible and likely very good.

In conjunction, I think these two papers put the industry in a much better place to have sensible and informed discussions using a set of hopefully commonly understood definitions - something that's been sorely lacking in the past.