Saturday, March 13, 2010
The Smart Grid Privacy Smoke Screen
Wednesday, February 24, 2010
The Cyber Warrior Mentality - The Security Warrior
“The basic difference between an ordinary man and a warrior is that a warrior takes everything as a challenge while an ordinary man takes everything either as a blessing or a curse.”
-Carlos Casteneda, American author 1925-1998
I have been thinking about the warrior mentality a lot lately. It started several weeks ago when someone I was speaking to (yes you, Stewart) about cyber security referred to something I said as being indicative of having a warrior mentality. It struck me as interesting because my business partner talks about having a warrior mentality a lot, and as I had this discussion I was more than a little taken aback by the uncanny parallels between myself, my business partner, and this complete stranger I was discussing security with. Partway through our conversation I began predicting what he was going to say, based on my understanding of the situation, and it was dead on every time.
It was like he was reading my mind.
Yet this was not what I found strangest of all. As I began "gathering intelligence" in my attempt to better understand the vendor space in the cyber security landscape (needs, requirements, activities) as it relates to The Smart Grid, I consistently ran into two distinct types of people. One was the more marketing oriented type, who simply discussed security in a manner that was indeed befitting of the vendor (a security apologist if you will), and the other was the security contempory - or the "Security Warrior" as I now like to call it.
Okay, I know this may sound odd to some, but for those who fit into the category I am sure it makes perfect sense.
As a security professional who began his security career as an administrator who was thrown into the battle due to outside attacks on the company network, I was charged with fixing the problem, and I was given very few tools (and even less time) to do so. My boss did not want to hear anything about expensive firewall hardware, or outside consulting, or anything like that. I was in charge of IT, so it was my job to fix the problem, and to do so within the confines of the limited budget I had available to me.
Oddly enough, I did not view this directive with frustration or with disdain. I simply took it as my marching orders and did the best I could with it. I had been sent out to the jungle with a book of matches and a pocket knife, and it was my duty to survive with those tools, and my wits. Come to think of it, I loved it!
Having less to work with really makes some people think hard and "outside of the box". Not all people, however. Some people simply cannot cope with the situation, and give up. Others pretend that things are going to miraculously work out through some sort of cosmic intervention, and simply wait for things to change. Sometimes this inaction mentality works out for them, but it is not because of divine intervention (although I do believe in God, but that is another discussion), but it is often because someone else picks up the slack.
When given a limited toolset, the warrior does not fret. He (or she) simply takes inventory, and then begins studying the enemy, beginning with the enemy within. Fear, shame, guilt, doubt, and other such feelings and mental states are identified for what they are and dealt with promptly and effectively. The warrior studies the landscape and determines where the danger zones lie at every given moment (because they are always changing), and what to do to stay out of danger. The warrior immediately determines what threats are real, what threats are not real (but are actually more perceptions than real threats), and what threats may come, and prepares accordingly. If the threats come from other people (the biggest threat of all), then the warrior does all he can to study the perceived enemy to determine both the level of the threat and the mental state of the potential enemy. If the warrior determines that the enemy is indeed real, he does NOT rush to kill the enemy. The warrior then studies the enemy and determines if the enemy himself is indeed a true warrior as well.Monday, February 22, 2010
The Evolving Compliance Landscape Of Cyber Security
Monday, February 15, 2010
Coordinating Efforts In Cyber Security
Tuesday, February 9, 2010
As Goes California...
Monday, February 8, 2010
Smart Grid Security Performance Standards
Smart Grid Cyber Security Strategy and Requirements
which I found through Smart Grid News (http://www.smartgridnews.com/artman/uploads/1/nist_cyber_security.pdf).
Section 3.1 touches on crypto, and the general tone of the document would suggest that logical (software) security is the method of choice due to the performance hit a system must take when implementing more secure levels of crypto (i.e. secure microcontrollers). Since performance is so important, one would logically conclude that hardware based security introduces challenges. Correct me if I am wrong, but that is how I interpret this.
That being said, what seems to be lacking is any sort of reference for performance. Since hardware based security is, in many ways, superior to logic based security (not always, but the BEST hardware based security chips are far more secure than the best logic based counterparts), then we really need a frame of reference here. Granted, no hardware based security solution will ever be able to match the performance of a logic based system (in fact, you can get maximum performance by simply using buzz words to describe a part of the system - like 256 bit encryption), but the best secure IC's deliver some pretty good performance while offering some very solid security. After all, banks rely on hardware based security (i.e smart card based security) for their most critical systems, and system availability and reliability are directly tied to the very high performance requirements vendors must adhere to in order to sell to the banking industry.
The one issue that does come into focus, of course, is budgetary constraints. Vendors of AMI systems must compete to sell their products, and the increased cost of implementing secure microcontrollers that deliver the requisite level of performance cuts into everyone's bottom line (which ultimately is the TRUE deciding factor). Logic based security can be implemented for anywhere from $0 to fractions of a cent, while high performance and high security hardware costs more.
Nonetheless, if cyber security is such a major concern (as it should be) in the implementation of the Smart Grid, then we should perhaps seek to create some target objectives for vendors of hardware based security, including performance and cost. We should also view the total cost in a systemic manner, taking into account the risk of relying on logic based security, and the cost of failure.
After all, if we are building an infrastructure that is expected to remain a part of our critical energy infrastructure for MANY years to come before replacing it with the next best thing, we should probably create solid, tactical objectives as well as higher level objectives.
It really takes both to succeed.