<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NIST - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/nist-en/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/nist-en/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Tue, 19 Sep 2023 08:26:11 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>NIST - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/nist-en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cyber regulatory landscape: challenges and prospects</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/09/cyber-regulatory-landscape-challenges-and-prospects/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/09/cyber-regulatory-landscape-challenges-and-prospects/#respond</comments>
		
		<dc:creator><![CDATA[Perrine Viard]]></dc:creator>
		<pubDate>Mon, 18 Sep 2023 11:00:00 +0000</pubDate>
				<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[DORA]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[NIS]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[regulation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=21355</guid>

					<description><![CDATA[<p>A 38% increase of cyber-attacks was estimated in 2022[1]. As this figure illustrates, the cyber threat continues to grow, and has become a major concern for businesses worldwide. To counter this growing threat and maintain digital confidence, governments have long...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/09/cyber-regulatory-landscape-challenges-and-prospects/">Cyber regulatory landscape: challenges and prospects</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">A 38% increase of cyber-attacks was estimated in 2022<a href="#_ftn1" name="_ftnref1">[1]</a>. As this figure illustrates, the cyber threat continues to grow, and has become a major concern for businesses worldwide. To counter this growing threat and maintain digital confidence, governments have long been regulating cyberspace, and continue to do so to adapt to changing conditions. As a result, we have seen the gradual emergence of multiple regulations requiring the implementation of cybersecurity and data protection measures, accompanied by different levels of possible sanctions in the event of non-compliance. Companies are now faced with a complex regulatory landscape, requiring the implementation of compliance strategies with adapted organisational models.</p>
<p> </p>
<h2 style="text-align: left;">A denser and more complex cybersecurity regulatory landscape</h2>
<p style="text-align: justify;">The <strong>first attempts to regulate</strong> personal data protection and cybersecurity remained <strong>partial until the early 2000s</strong>, being driven mainly by the United States and the European Union.  Initially, they focused on the protection of personal data, in France with the <em><u>Loi Informatique et Libertés </u></em>(1978) and in the United States with sector-specific regulations: the <em><u>Privacy Act</u></em> (1974) for the public sector, the <em><u>Health Insurance Portability and Accountability Act</u></em> for the healthcare sector (1996) and the <em><u>Gramm-Leach-Bliley Act</u></em> (1999) for the financial sector.</p>
<p style="text-align: justify;">The <strong>first cybersecurity regulations</strong> were introduced in the <strong>financial sector</strong> in the <strong>early 2000s</strong>, with the aim of improving the security of the services provided. Notable regulations include the <em><u>Sarbanes-Oxley Act</u></em> (2002), in the USA, reinforcing corporate transparency in terms of internal control, and the <em><u>Payment Services Directive</u></em> (2007) in the European Union, regulating the security of online payments and transactions.</p>
<p style="text-align: justify;">Since the <strong>early 2010s</strong>, more structuring regulations have emerged to form an <strong>initial cyber regulatory base</strong> in the same regions. These regulations are mainly focused on critical infrastructure protection, with France&#8217;s <em><u>Loi de Programmation Militaire de 2013-2018</u></em> (2013), the USA&#8217;s <em><u>National Cyber Security and Critical Infrastructure Protection Act</u></em> (2014), but also the <em><u>Network and Information Security 1 Directive</u></em> (2016) enacted by the European Union.</p>
<p style="text-align: justify;">It wasn&#8217;t until the <strong>late 2010s that the desire to regulate the cyber space became more global</strong>. As many countries followed in the footsteps of the United States and the European Union, stricter cyber regulations began to emerge, with <strong>far-reaching impacts</strong> on information systems. This can be seen in the arrival of major <strong>personal data protection regulations</strong> around the world: the <em><u>General Data Protection Regulation</u></em> (GDPR, 2018) in Europe, the <em><u>California Consumer Privacy Act</u></em> (CCPA, 2020) in California, the <em><u>Personal Data Protection Law</u></em> (PDPL, 2020) in Brazil, the <em><u>Personal Information Protection Law</u></em> (PIPL, 2021) in China, or the <em><u>Personal Data Law </u></em>(2022) in Russia.</p>
<p style="text-align: justify;">Other regulations aimed at <strong>protecting information systems</strong> are multiplying, with the <em><u>Cybersecurity Law </u></em>in China (2017), the <em><u>NYCRR 500 Cybersecurity Regulations</u></em> for the State of New York (2017), or the new iteration of the <em><u>NIS Directive</u></em> (2023) and DORA in Europe.</p>
<p style="text-align: justify;"><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-21357" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture1.png" alt="" width="624" height="332" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture1.png 624w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture1-359x191.png 359w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture1-71x39.png 71w" sizes="(max-width: 624px) 100vw, 624px" /></p>
<p style="text-align: center;"><em>Evolution of cybersecurity regulatory landscape<a href="#_ftn2" name="_ftnref2"><strong>[2]</strong></a> </em></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Added to this complex cybersecurity regulatory landscape is a <strong>vast ecosystem of cybersecurity requirements and standards</strong>, with <strong>different levels of constraint</strong>: regulatory requirements stemming from cyber or other regulations, mandatory requirements, recommendations or even requirements with contractual value. In this context, it is essential to identify all applicable requirements and the level of constraint they impose.</p>
<p style="text-align: justify;"><img decoding="async" class="aligncenter size-full wp-image-21359" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture2.png" alt="" width="938" height="340" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture2.png 938w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture2-437x158.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture2-71x26.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture2-768x278.png 768w" sizes="(max-width: 938px) 100vw, 938px" /></p>
<p style="text-align: center;"><em>Types of cybersecurity requirements and standards, beyond cyber regulations</em></p>
<p> </p>
<h2 style="text-align: left;">A cybersecurity regulatory compliance strategy adapted to the new paradigm</h2>
<p style="text-align: justify;">With the global cybersecurity regulatory landscape becoming increasingly complex, compliance cannot be thought of solely as total compliance with all applicable regulatory requirements. Faced with detailed, costly and sometimes contradictory requirements, it is becoming necessary to implement <strong>risk-based cyber compliance strategies</strong>. The definition of these strategies will be based on a study of the existing level of regulatory compliance, an assessment of the effort and complexity of the measures required to comply with each regulation, and a consideration of the risks associated with potential non-compliance, both in terms of sanctions and IS protection. This analysis, far from seeking to escape the law, aims to identify the benefit/risk of activities, and may lead to redirecting activities, limiting their scope, or acting in concert with the ecosystem to evolve requirements.</p>
<p style="text-align: justify;">To implement such a strategy, it is first essential to <strong>identify all applicable regulations</strong>, and to set up a <strong>regulatory watch</strong> to keep alongside regulatory developments and related news. A two-tiered organisation must then be set up to <strong>manage cyber regulatory compliance</strong>.</p>
<p style="text-align: justify;"><strong>A first level of overall management</strong> aimed at providing a high-level overview: a global analysis of the level of cyber compliance must be carried out. This can be based on a recognised cybersecurity standard such as NIST or ISO 27001 for security requirements. For requirements relating to the protection of personal data, GDPR is a good foundation, since most international regulations on this topic are derived from it. The NIST privacy and ISO privacy standards are also solid references in this field. These benchmarks can be mapped onto the main applicable regulations, and advantage can be taken of existing synergies between regulations, as illustrated by the two examples below.</p>
<p style="text-align: justify;">To complete this analysis, an audit plan should be drawn up to assess compliance with key local regulations in greater detail.</p>
<p style="text-align: justify;"><span style="text-decoration: line-through;"><img decoding="async" class="wp-image-21361 alignleft" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture3.png" alt="" width="326" height="290" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture3.png 366w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture3-215x191.png 215w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture3-44x39.png 44w" sizes="(max-width: 326px) 100vw, 326px" /> <img loading="lazy" decoding="async" class="wp-image-21363 alignright" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture4.png" alt="" width="329" height="298" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture4.png 369w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture4-210x191.png 210w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture4-43x39.png 43w" sizes="auto, (max-width: 329px) 100vw, 329px" /></span>                                       </p>
<table style="height: 23px; width: 100%; border-collapse: collapse; border-style: solid; border-color: #ffffff;" border="0">
<tbody>
<tr style="height: 23px;">
<td style="width: 42.7381%; height: 23px; border-style: solid; border-color: #ffffff; text-align: center;">Analysis of synergies between the <u>NIS Directive</u> and the <u>LPM</u></td>
<td style="width: 13.9285%; height: 23px; border-style: solid; border-color: #ffffff;"> </td>
<td style="width: 43.3333%; height: 23px; border-style: solid; border-color: #ffffff; text-align: center;">Analysis of synergies between the <u>NIS</u> directive and<u> ISO2702</u></td>
</tr>
</tbody>
</table>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">A second level of <strong>&#8220;local&#8221; management</strong>, <strong>on a geographical or business line scale</strong>, aimed at ensuring local regulatory compliance in each of the regions where the Group is present. This requires first of all the implementation of a local watch to identify and know precisely the regulations and associated news. This is followed by a detailed analysis of the level of compliance with local regulations, the identification of specifics needed to ensure the right level of compliance, and the feedback of these elements to the Group to ensure the overall management of compliance actions.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: left;">Protection regulations call into question the need to separate information systems</h2>
<p style="text-align: justify;">Complying with a multitude of cybersecurity regulations is becoming a real challenge for companies with an international presence and centralised information systems. This is due to the stacking up of these regulations, sometimes with incompatible or contradictory provisions, but also to the emergence of requirements with <strong>far-reaching impacts</strong> on information systems.</p>
<p style="text-align: justify;">This is the case, for example, with <strong>China&#8217;s PIPL regulations</strong>, and in particular Article 40, which stipulates that the transfer of data outside China will only be authorized if processing complies with the security assessment established by the Chinese authorities. This regulation will apply above a certain volume of personal data (not yet specified by the Chinese authorities).</p>
<p style="text-align: justify;"><strong>Incompatibilities between regulations</strong> have also arisen between the United States and the European Union. This is illustrated by the invalidation of the U.S. <em><u>Privacy Shield</u></em><a href="#_ftn3" name="_ftnref3"><em><strong>[3]</strong></em></a> by the European Court of Justice, its <em>Schrems</em> rulings calling into question the ability of U.S. Cloud hosts to process the personal data of their European customers in line with European requirements.</p>
<p style="text-align: justify;">Against this backdrop of heightened cybersecurity and personal data protection requirements, emphasised by the protection intentions of certain countries, it may become necessary to study the <strong>need to separate globalised and centralised information systems</strong> by considering separation into several geographical zones, which could be:</p>
<ul style="text-align: justify;">
<li>A zone comprising the USA and the UK</li>
<li>A second zone centered on China</li>
<li>A third zone made up of the European Union and GDPR-relevant<a href="#_ftn4" name="_ftnref4">[4]</a></li>
</ul>
<p style="text-align: justify;">Depending on their regulatory reality and potential developments, other countries or regions could be attached to one or other of these three zones.</p>
<p style="text-align: justify;">In the future, the information systems of these different zones could rely more heavily on the <strong>sovereign clouds</strong> that are currently being developed.</p>
<p> </p>
<h2 style="text-align: left;">Constraints that can even lead to the closure of a region&#8217;s operations</h2>
<p style="text-align: justify;">We&#8217;re even seeing a number of companies halting or postponing the launch of activities in certain countries where the regulatory constraints and associated risks of sanctions are too great in relation to the business challenges and strategy of the company. This is particularly the case in certain US states, and in Europe, where some major players are putting the brakes on their development because of the RGPD (e.g. Google&#8217;s open AI/ Bard, or Meta&#8217;s launch of Thread).</p>
<p style="text-align: justify;"><em> </em></p>
<h2 style="text-align: left;">What&#8217;s next for 2023 and beyond?</h2>
<p style="text-align: justify;"><strong> <img loading="lazy" decoding="async" class="aligncenter size-full wp-image-21365" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture5.png" alt="" width="959" height="204" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture5.png 959w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture5-437x93.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture5-71x15.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture5-768x163.png 768w" sizes="auto, (max-width: 959px) 100vw, 959px" /></strong></p>
<p style="text-align: justify;">The complex regulatory landscape will continue to expand in the months and years ahead. Both in new areas (AI, product security) and in existing areas, such as critical infrastructure.</p>
<p style="text-align: justify;">On the &#8220;critical infrastructure&#8221; front, after the first phases of regulations focused on personal data protection, the authorities have been looking at critical infrastructure protection, which continues with the NIS2 directive in particular. Adopted on November 10, 2022 and soon to be implemented into French law, it aims to reduce disparities between member states, strengthen cybersecurity in a context of increasing digitalisation, and establish security measures to improve the level of security of critical infrastructures within EU member states.</p>
<p style="text-align: justify;">A new phase is now taking shape, during which regulations will focus on the safety of digital products, with in particular:</p>
<ul style="text-align: justify;">
<li>The <strong><u>AI Act</u></strong>, a European regulation aimed at defining a common frame of reference for the development and use of Artificial Intelligence (AI). Against a backdrop of lightning acceleration in the uses of AI, new regulations are also set to emerge around the world, and particularly in China, where measures have already been taken and led to the closure of 55 applications and 4,200 sites between January and March 2023<a href="#_ftn5" name="_ftnref5">[5]</a>.</li>
<li>The <strong><u>Cyber Resilience Act</u></strong> (C.R.A), another European regulation, which aims to strengthen the security of digital products by imposing measures to be respected by manufacturers right from the product design stage. Not to mention the recent announcement by the White House of the &#8220;Cyber trust mark&#8221; initiative, which targets the same objective but with a different approach<a href="#_ftn6" name="_ftnref6">[6]</a>.</li>
</ul>
<p style="text-align: justify;">The regulatory stakes are not about to diminish, and cyber teams need to be prepared. At the very least, it will be necessary to strengthen links with the business lines concerned, as well as with legal teams. The most mature companies in this field have set up legal departments within their cyber teams, to exchange information with the various legal departments. This may not necessarily be necessary, depending on the organization of each structure, but it can also be a guarantee of strong mobilization.</p>
<p style="text-align: justify;">In all cases, the challenge for companies will be to transform these often mandatory regulatory requirements into a competitive advantage for their business, not by punitive, minimal compliance, but rather by taking ownership of the subject and transforming these practices in a way that can be leveraged externally.</p>
<p> </p>
<p> </p>
<p style="text-align: justify;"><a href="#_ftnref1" name="_ftn1">[1]</a> <a href="https://blog.checkpoint.com/2023/01/05/38-increase-in-2022-global-cyberattacks/">https://blog.checkpoint.com/2023/01/05/38-increase-in-2022-global-cyberattacks/</a></p>
<p style="text-align: justify;"><a href="#_ftnref2" name="_ftn2">[2]</a> Non-exhaustive list of cybersecurity regulations</p>
<p style="text-align: justify;"><a href="#_ftnref3" name="_ftn3">[3]</a> <a href="https://www.cnil.fr/fr/invalidation-du-privacy-shield-les-suites-de-larret-de-la-cjue">https://www.cnil.fr/fr/invalidation-du-privacy-shield-les-suites-de-larret-de-la-cjue</a></p>
<p style="text-align: justify;"><a href="#_ftnref4" name="_ftn4">[4]</a> <em>Countries complying with the level of protection required by the EU </em><a href="https://www.cnil.fr/fr/la-protection-des-donnees-dans-le-monde">https://www.cnil.fr/fr/la-protection-des-donnees-dans-le-monde</a></p>
<p style="text-align: justify;"><a href="#_ftnref5" name="_ftn5">[5]</a> <a href="https://www.01net.com/actualites/comment-les-lois-chinoises-tres-strictes-risquent-de-nuire-a-lia-made-in-china.html">https://www.01net.com/actualites/comment-les-lois-chinoises-tres-strictes-risquent-de-nuire-a-lia-made-in-china.html</a>  </p>
<p style="text-align: justify;"><a href="#_ftnref6" name="_ftn6">[6]</a> <a href="https://arstechnica.com/information-technology/2023/07/the-cyber-trust-mark-is-a-voluntary-iot-label-coming-in-2024-what-does-it-mean/">https://arstechnica.com/information-technology/2023/07/the-cyber-trust-mark-is-a-voluntary-iot-label-coming-in-2024-what-does-it-mean/</a></p>
<p style="text-align: justify;"> </p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/09/cyber-regulatory-landscape-challenges-and-prospects/">Cyber regulatory landscape: challenges and prospects</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/09/cyber-regulatory-landscape-challenges-and-prospects/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Engaging the C-Suite on Information Security</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/06/engaging-the-c-suite-on-information-security/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/06/engaging-the-c-suite-on-information-security/#respond</comments>
		
		<dc:creator><![CDATA[Lloyd Barwood]]></dc:creator>
		<pubDate>Tue, 13 Jun 2023 13:00:00 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[How to]]></category>
		<category><![CDATA[C-Suite]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Framework]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Strategy]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=20710</guid>

					<description><![CDATA[<p>Introduction The ever-increasing threat of cyber-attacks on organisations around the world and their potentially devastating financial, reputational, or operational impact on the business means it has never been more important to position Cyber Security as a major issue in front...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/06/engaging-the-c-suite-on-information-security/">Engaging the C-Suite on Information Security</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h3 style="text-align: justify;"><strong>Introduction</strong></h3>
<p style="text-align: justify;">The ever-increasing threat of cyber-attacks on organisations around the world and their potentially devastating financial, reputational, or operational impact on the business means it has never been more important to position Cyber Security as a major issue in front of the C-Suite. The C-Suite holds ultimate accountability for an organisation’s approach to risk in both setting the appetite for Cyber risk for the business and ensuring sufficient budget &amp; resource is assigned to manage Cyber risk to within the appetite. If they are not appropriately informed of the risks associated with Information Security (IS), the organisation may not put in place the correct and appropriate mitigations to protect the organization from their top threats and risks.</p>
<p style="text-align: justify;">Failure to effectively protect against these cyber threats can have both organisational and personal consequences for executives. For example, The Senior Managers and Certification Regime (SMR) is an FCA enforced regulation that assigns responsibility for Information Security to executive level employees, making them liable for correct implementation of cyber protections for IS.</p>
<p style="text-align: justify;">This article will provide you with a 4-stage approach on how to better engage the C-Suite in your organisation on Information Security, to build a fruitful partnership between these executives who direct budget &amp; resource towards Information Security and the Cyber teams who are responsible for the oversight &amp; implementation of security.</p>
<h3 style="text-align: justify;"><strong>Stage 1: Introducing the Execs to Cyber Security</strong></h3>
<p style="text-align: justify;">In this first session with the C-Suite, it is imperative that you initiate the conversation by focusing on an introduction to Cyber Security that provides an overarching view of the organisation’s Cyber Security capabilities and operating model, that will encourage future more in-depth discussion.</p>
<p style="text-align: justify;">Outline the responsibilities the organisation and executives have towards Information Security and how these align with the strategic priorities of the organisation &amp; Cyber team. This should include a presentation of the top threats to the organization (both internal &amp; external), the risks that they expose the organisation to and the existing roadmap to mitigating these risks. This will provide a high-level overview of the organisation’s Cyber capability and will set the tone ready for future conversations with the C-Suite.</p>
<p style="text-align: justify;">Provide an overview showing the blueprint for Information Security and how security integrates and adds value to the rest of the business. It is important to include metrics that can be used to compare the organisation’s approach to Cyber Security against peers within the market. A difference in budget or team size compared to a competitor can provide guidance on whether the organisation is assigning adequate resources and budget to the issue. </p>
<h3 style="text-align: justify;"><strong>Stage 2: 360 Audit</strong></h3>
<p style="text-align: justify;">After successfully introducing the C-Suite to Information Security, it is now essential that you lock in that second session where you can provide a more granular breakdown of the organisation’s Cyber Security capability with a clear focus on where resources need to be focussed.</p>
<p style="text-align: justify;">Industry standard frameworks, such as ISO and NIST, should be deployed to measure an organisation’s Cyber Security maturity and provide analysis on potential improvements that can be presented to the C-Suite executives. These frameworks offer controls against which the organisation can be benchmarked, to identify areas that require maturing to mitigate risk from the organisation’s top threats. While these frameworks in their original state offer a good measurement of maturity, it is important to refine the controls so that the framework is tailored towards the organisation, taking into consideration the industry sector and regulatory environment. Wavestone recommends taking the NIST framework as a basis and fitting it to the specific stakes of the organisation to overcome any framework limitation and focus it on the businesses’ needs.</p>
<p style="text-align: justify;">Wavestone have built our own framework, called the Cyber Benchmark, that leverages the best of industry frameworks to provide a comprehensive approach to maturity assessment with organisational &amp; technological perspectives included. We recommend organisations follow a similar approach to accelerate their framework improvements to increasing their Cyber maturity.</p>
<p style="text-align: justify;">Capturing the attention of senior executives to invest time &amp; resources into developing a framework to improve Cyber maturity can be difficult. A good methodology is to provide real life evidence of their security vulnerabilities, for example by presenting evidence of how an internal ‘Red Team’ gained access to the mailboxes of the senior executives present, with an explanation of how few days it took. </p>
<h3 style="text-align: justify;"><strong>Stage 3: Programme and Framework</strong></h3>
<p style="text-align: justify;">Once this more granular breakdown has been presented, a key priority must be to ensure the C-Suite has bought into the Cyber Security strategy &amp; roadmap; developed using the maturity improvement opportunities identified through the framework assessment. Buy in from the C-Suite on the roadmap will guarantee the required funding &amp; resources required to implement these enhancements.</p>
<p style="text-align: justify;">Using the customised framework, develop a roadmap that focuses on maturing controls that will most effectively reduce the risk from the organisation’s top threats. This roadmap will become the building blocks for the security programme. The security programme should be defined so that it provides clear targets to be met to ensure compliance with the customised framework controls, beginning with a remediation approach that will guarantee a standard Cyber maturity across the organisation, and followed by steps to achieve the Cyber maturity goals. Ensuring a standard maturity across the organisation will alleviate the risk from current threats, while building on this to achieve maturity targets will reduce the potential risk from over-the-horizon threats.</p>
<p style="text-align: justify;">Programme support can be leveraged from a specialised Project Management Office (PMO) that will supervise the execution of the programme. It is important that this PMO curates a good relationship between IT who will implement the roadmap to maturity and the business, so that the benefits are understood and extracted across the organisation.</p>
<h3 style="text-align: justify;"><strong>Stage 4: Risk Quantification and Business Accelerators </strong></h3>
<p style="text-align: justify;">The final stage of engaging with the C-Suite requires you to demonstrate the return on investment (ROI) that Cyber Security can deliver, both through risk reduction from top threats and as a business enabler that encourages expansion into new territories and engaging new client relationships.</p>
<p style="text-align: justify;">Implementing the appropriate customised framework to the organisation and following the established roadmap to Cyber Security maturity will require an increased budget allocation. However, it is important to emphasise to the board that the return on this investment will far exceed the initial cost due to a dramatic decrease in the scale and severity of risk that the organisation is exposed to. Use calculations to demonstrate this Return on Investment (ROI) quantitively and link this to the efforts and changes delivered by the security programme. It should also be explained that this initial outlay required to deliver the security programme is far less than the potential financial, reputational, and personal (e.g., SMR) repercussions that would result from a failure to adequately protect information systems during a cyber-attack.</p>
<p style="text-align: justify;">As well as preventing the serious repercussions of failing to protect information systems in an attack, Cyber Security can also become an important business enabler. Effective Cyber Security will ensure that your customers are retained in the event of a properly managed security breach, as well as confirming your organisation as a secure manager of customer data &amp; details, increasing your attractiveness to new customers. A secure organisation can move swiftly into new business environments &amp; seize opportunities with confidence that their Cyber Security maturity will be able to resist potential additional threats that may arise from this expansion; opening the door for the organisation to safely engage a wider client base.</p>
<h3 style="text-align: justify;"><strong>Conclusion</strong></h3>
<p style="text-align: justify;">Following the 4-stages outlined in this article will allow you to foster a strong relationship with the C-Suite on Information Security, ensuring they are aware of their responsibilities for Cyber Security under the SMR and that they assign budget &amp; resources appropriately to deal with the top threats facing the organisation. The customised framework will allow these executives to understand the current Cyber Security posture of the organisation and buy in to the roadmap for future maturity. Once this vision of mature Cyber Security has been delivered, the business incentives can be leveraged to ensure the C-Suite continues to invest in developing Information Security within your organisation.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/06/engaging-the-c-suite-on-information-security/">Engaging the C-Suite on Information Security</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/06/engaging-the-c-suite-on-information-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The evolution of the NIST password complexity rules: a mandatory step before a passwordless world?</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/11/the-evolution-of-the-nist-password-complexity-rules-a-mandatory-step-before-a-passwordless-world/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2021/11/the-evolution-of-the-nist-password-complexity-rules-a-mandatory-step-before-a-passwordless-world/#respond</comments>
		
		<dc:creator><![CDATA[David Martinache]]></dc:creator>
		<pubDate>Mon, 08 Nov 2021 08:30:06 +0000</pubDate>
				<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[password]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=17317</guid>

					<description><![CDATA[<p>Using passwords introduces both a large attack surface (phishing, brute force, password spreading, rainbow table, etc.) and a poor user experience. As a result, passwords have been denounced in favour of passwordless technologies for several years. However, passwords remain commonly...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/11/the-evolution-of-the-nist-password-complexity-rules-a-mandatory-step-before-a-passwordless-world/">The evolution of the NIST password complexity rules: a mandatory step before a passwordless world?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">Using passwords introduces both a large attack surface (phishing, brute force, password spreading, rainbow table, etc.) and a poor user experience. As a result, passwords have been denounced in favour of passwordless technologies for several years. However, passwords remain commonly used due to both technical and human factors and are likely to remain so for the next few years.</p>
<p style="text-align: justify;">What should we do with passwords until they are no longer in use? How can we minimise the impact of what is the main sticking point in the user experience, whilst improving the security posture of our organisation?</p>
<p style="text-align: center;"><img loading="lazy" decoding="async" class="aligncenter wp-image-17323 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-1-2.png" alt="" width="624" height="616" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-1-2.png 624w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-1-2-193x191.png 193w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-1-2-40x39.png 40w" sizes="auto, (max-width: 624px) 100vw, 624px" /></p>
<h2> </h2>
<h2 style="text-align: justify;">Why are passwords so common?</h2>
<p style="text-align: justify;">Since ancient times, passwords have been used as the means of entry to secret clubs and underground factions. The historical access management system of “if I have the secret, then I have the right to entry” has since transformed into a way of proving one’s identity – “if I have the secret then I am who I say I am”. Inserting characters in a certain order known only to the user with right of access, thus has become the solution to allow them to prove their identity.</p>
<p style="text-align: justify;">Although the weaknesses of this system were quickly realised, if the computer systems were not connected and therefore, they required physical access, the attack surface remained limited in comparison. The password has therefore become a pillar of IT security and is used in almost all services requiring user management.</p>
<p style="text-align: justify;">However, the arrival of networks (the Internet, in particular) and the resulting growth in exposure has turned password-related security weaknesses into real vulnerabilities.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">How did we come to burden the user with such complexity?</h2>
<p style="text-align: center;"><img loading="lazy" decoding="async" class="aligncenter wp-image-17325 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-2-1.png" alt="" width="534" height="556" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-2-1.png 534w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-2-1-183x191.png 183w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-2-1-37x39.png 37w" sizes="auto, (max-width: 534px) 100vw, 534px" /></p>
<p style="text-align: justify;">The number of possible attacks on passwords has gradually led security experts to increase the number of safeguards designed to protect passwords.<br />As a result, a certain number of measures are now taken to secure passwords and their associated processes, making the user experience even more complex. For instance:</p>
<ul style="text-align: justify;">
<li>Minimum number of characters</li>
<li>Complexity (1 number, a letter, a special character, etc.)</li>
<li>List of forbidden words</li>
<li>Recommendation of password uniqueness between services</li>
<li>Periodic renewal &amp; history</li>
</ul>
<p style="text-align: justify;">These rules, largely based on past National Institute of Standards and Technology (NIST) recommendations, NIST.SP.800-63-2, 2015, and that could be found in most of framework (UK, French, etc.) negatively impact the user experience. Often unintuitive and different from one service to another, users sometimes find it challenging to understand them: lack of clear explanations on the expected complexity, no display of incorrect attempts remaining before the account is locked, or variations in access channels resulting in differing experiences (accessibility of some special characters different from one terminal to another, for example: the &#8220;§&#8221; character on an iPhone or an iPad).</p>
<p style="text-align: center;"><img loading="lazy" decoding="async" class="aligncenter wp-image-17327 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-3-1.png" alt="" width="2052" height="1051" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-3-1.png 2052w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-3-1-373x191.png 373w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-3-1-71x36.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-3-1-768x393.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-3-1-1536x787.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-3-1-2048x1049.png 2048w" sizes="auto, (max-width: 2052px) 100vw, 2052px" /></p>
<p> </p>
<h2 style="text-align: justify;">And is it effective?</h2>
<p style="text-align: justify;">Despite all these measures, the password is still criticized for its low level of security, because it is based on two principles that are not compatible with a high level of security.</p>
<p style="text-align: justify;">The very principle on which the password is based, the shared secret, leads to two attack vectors:</p>
<ul style="text-align: justify;">
<li>Data in transit – transmit the secret regularly: the password can then be leaked or stolen via a proxy that is too informative in its logs, caching in the shared memory of a smartphone, or keylogger-type malware, etc.</li>
<li>Data at rest – storing the enterprise password to verify it: the use of storage methods with low security levels is still too common (reversible encryption instead of non-reversible hash, old sha-1 type protocol, no salting, or worse, plain text storage).</li>
</ul>
<p style="text-align: justify;">And even more recent hash protocols remain potentially fallible in the face of current computing power. Thus, even with a recent hash protocol like sha256, retrieving an 8-character password from its hash will take&#8230; less than a day.</p>
<p style="text-align: justify;">Attackers can then directly retrieve the password, ignoring its complexity (except for the length for brute force and storage if using a recent, robust, and regularly updated hash protocol).</p>
<p style="text-align: justify;">The volume of human beings in the system and their capacity to make mistakes has an even greater impact:</p>
<ul style="text-align: justify;">
<li>We are bad generators of randomness: this explains the lists of the most common passwords that appear every year. And, with strong constraints on creation, the possibilities of variations are lower, making the level of entropy decrease. The imposed complexity is counterproductive.</li>
<li>We have a bad memory: encouraging practices that lower the level of security (use of a derivative or even the same password &#8211; 63% of users admit to this practice &#8211; post-it notes on the desktop, unencrypted .txt files, etc.)</li>
<li>We are easy to trick: phishing, spearphishing and social engineering are widespread attack vectors.</li>
</ul>
<p style="text-align: justify;">If the user provides his password to the attacker, it does not matter if it is 60 characters long or consists of letters from different alphabets.</p>
<p style="text-align: justify;">The complexity of the password has no influence on the most common types of attacks, and therefore only causes inconvenience to the user.</p>
<p style="text-align: justify;"><img loading="lazy" decoding="async" class="aligncenter wp-image-17329 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-4-1.png" alt="" width="938" height="705" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-4-1.png 938w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-4-1-254x191.png 254w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-4-1-52x39.png 52w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-4-1-768x577.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-4-1-600x450.png 600w" sizes="auto, (max-width: 938px) 100vw, 938px" /></p>
<p> </p>
<h2 style="text-align: justify;">What to do?</h2>
<p style="text-align: justify;">As password issues are not new, there are several possible solutions that can be used in conjunction to reduce the problems and their impacts. The delegation of authentication to third-party services (social login, enterprise IAM, etc.), and the implementation of Single Sign-On have facilitated user experience and limited password replay/transitions and places where the password is stored at rest.</p>
<p style="text-align: justify;">The development of second authentication factors (OTP SMS or mail, push notification, hard tokens, etc.), the most recent ones being less intrusive and less disruptive, ensures better security.</p>
<p style="text-align: justify;">In addition to these solutions, which are already proven and widely deployed, and in anticipation of being ready to enter the passwordless world, which alone is a huge project, NIST and other frameworks recently revised their recommendations regarding the required complexity around passwords (NIST.SP.800-63b, 2017, NCSC UK, Password policy: updating your approach, 2018 for example).</p>
<p style="text-align: justify;">So, from a user point of view, the constraints on passwords have been reduced to a minimum number of characters (8) and the rejection of common/compromised passwords. In exchange, user-facing measures offering more freedom to the user are often recommended:</p>
<ul style="text-align: justify;">
<li>All Unicode characters, including space, must be allowed, without being forced</li>
<li>The maximum size limit must be at least 64 characters</li>
<li>Rotations should no longer be time-based, but only in case of compromise</li>
<li>The user must have at least 10 attempts before being blocked</li>
<li>Different user experience improvers are to be considered (clear information on the expected complexity, ability to display the password during input, ability to paste values, etc.)</li>
</ul>
<p style="text-align: justify;">These new recommendations aim to guide users towards the use of longer and more random passwords by reducing constraints. They can be accompanied by the raised awareness and usage of safe passwords, preventing the user having to remember too many passwords.</p>
<p style="text-align: justify;">The remaining recommendations, mandatory to ensure security levels are not reduced, reinforce some of the aspects mentioned above. Those measures also aim to strengthen transmission (encryption, etc.) and storage (hashing, salting) to increase the level of security of the company’s activities and to prevent the use of certain practices that lower security (use of secret questions for password reset, etc.).</p>
<p><img loading="lazy" decoding="async" class="wp-image-17365 size-full aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-1-3.png" alt="" width="1043" height="434" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-1-3.png 1043w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-1-3-437x182.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-1-3-71x30.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/11/Image-1-3-768x320.png 768w" sizes="auto, (max-width: 1043px) 100vw, 1043px" /></p>
<h2> </h2>
<h2 style="text-align: justify;">Conclusion</h2>
<p style="text-align: justify;">If the elimination of the password is a goal, its eradication is far from complete. It is necessary, before reaching this goal, to implement measures that aim to secure user data (for example by implementing multi-factor authentication on sensitive services) while facilitating the process and users to protect themselves. This includes the implementation of elements that prevent the user from logging in too often or creating too many passwords, but also by redesigning the complexity of passwords in order to increase the randomness, and by upgrading the technical means of transmission and storage.</p>
<p style="text-align: justify;">Using existing processes to prepare for future changes is also essential. For example, redesigning the password recovery path to move the user toward passwordless authentication can help make a smooth transition to greater security while improving the user experience.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/11/the-evolution-of-the-nist-password-complexity-rules-a-mandatory-step-before-a-passwordless-world/">The evolution of the NIST password complexity rules: a mandatory step before a passwordless world?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2021/11/the-evolution-of-the-nist-password-complexity-rules-a-mandatory-step-before-a-passwordless-world/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (1/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/07/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2/</link>
		
		<dc:creator><![CDATA[Raquel De Faria Cristas]]></dc:creator>
		<pubDate>Fri, 24 Jul 2020 12:55:38 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[IoT & Consumer goods]]></category>
		<category><![CDATA[connected device]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[NIST]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13959</guid>

					<description><![CDATA[<p>In 2010, the early hype-cycle of IoT (Ericsson and Cisco) predicted 50 billion devices by 2020. In reality, that figure was highly overestimated. Today, Gartner states that approximately 5.8 billion IoT terminals will be in use in 20201. Even if...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/07/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2/">&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In 2010, the early hype-cycle of IoT (Ericsson and Cisco) predicted 50 billion devices by 2020. In reality, that figure was highly overestimated. Today, Gartner states that approximately 5.8 billion IoT terminals will be in use in 2020<sup>1</sup>. Even if the market is not as developed as it was first predicted, it is still growing: those 5.8 billion of IoT devices represent <strong>an increase of 21%</strong> over 2019.</p>
<p>Despite their usefulness, introducing connected devices unfortunately brings <strong>new risks</strong> for companies. Indeed, according to the Palo Alto Networks report<sup>2</sup> published in March 2020, <strong>57% of the connected devices analyzed were vulnerable to medium or high severity attacks</strong>. This is not surprising. Securing connected devices is proving to be an arduous task that explains why Beecham Research<sup>3</sup> finds 62% of Industrial IoT transformations fail to scale because of a lack of trust.</p>
<p>Therefore, with this article we will try to ask ourselves about the security and trust issues of connected devices and how companies can deal with them.</p>
<p>&nbsp;</p>
<h2>What are the security and trust issues of connected devices?</h2>
<p style="text-align: justify;">In order to mitigate the security risks on connected devices, NIST recommends in its report<sup>4</sup> published in 2019 to focus on 6 main areas:</p>
<ul>
<li style="text-align: justify;"><strong>Inventory</strong>: Maintain an accurate inventory of all connected devices and their most relevant characteristics throughout their lifecycle (<a href="https://www.riskinsight-wavestone.com/en/2019/09/life-cycle-iot-security/">see the article</a> detailing the lifecycle of connected devices).</li>
</ul>
<p>&nbsp;</p>
<figure id="post-13960 media-13960" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-13960 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1.png" alt="" width="1479" height="755" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1.png 1479w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1-374x191.png 374w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1-71x36.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-1-1-768x392.png 768w" sizes="auto, (max-width: 1479px) 100vw, 1479px" /></figure>
<p style="text-align: center;">Figure 1 &#8211; Connected device lifecycle</p>
<ul>
<li style="text-align: justify;"><strong>Vulnerabilities</strong>: Identify and eliminate known vulnerabilities in the software and firmware of connected devices to reduce the likelihood and ease of exploitation and compromise.</li>
<li style="text-align: justify;"><strong>Access</strong>: Prevent unauthorized and inappropriate physical and logical access, use and administration of connected devices by people, processes and other computing devices.</li>
<li style="text-align: justify;"><strong>Detect security incidents of connected devices</strong>: Monitor and analyze connected device activity for signs of incidents involving the security of the device.</li>
<li style="text-align: justify;"><strong>Detect data security incidents</strong>: Monitor and analyze the activity of the connected device for signs of data security incidents.</li>
<li style="text-align: justify;"><strong>Protect data</strong>: Prevent access and alteration of data that could expose sensitive information or allow manipulation or disruption of the operation of connected devices.</li>
</ul>
<p style="text-align: justify;">However, current IoT platforms only partially meet these security requirements (<a href="https://www.wavestone.com/en/insight/iot-platforms-cornerstone-successful-iot-strategy/">see the article</a> detailing the usefulness of IoT platforms).</p>
<p>&nbsp;</p>
<p id="post-13962 media-13962" class="align-none" style="text-align: center;"><img loading="lazy" decoding="async" class="aligncenter wp-image-13962 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1.png" alt="" width="1073" height="329" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1.png 1073w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1-437x134.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1-71x22.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-2-1-768x235.png 768w" sizes="auto, (max-width: 1073px) 100vw, 1073px" />Figure 2 &#8211; The usefulness of IoT platforms</p>
<p>&nbsp;</p>
<p style="text-align: justify;">Indeed, traditional IoT architectures rely on a <strong>centralized cloud platform</strong>, operated by a third-party company and where most often the rules for data collection and storage are opaque. <strong>This is not the best solution to ensure the security of connected devices since</strong>:</p>
<ul>
<li>The use of a centralized cloud platform introduces the risk of &#8220;<strong>single point of failure</strong>&#8221; on the <strong>IoT architecture</strong> (although today this risk is mitigated with the implementation of a redundant architecture and backups).</li>
<li>It is entirely possible for an attacker to <strong>change the data stored in the cloud database</strong>. The decision making of the different stakeholders is therefore impacted.</li>
<li><strong>Collaboration</strong> between the different stakeholders of the IoT deployment (manufacturers, maintenance operators, &#8230;) becomes more <strong>difficult</strong> because access to the platform can be restricted to them.</li>
</ul>
<p style="text-align: justify;">The use of a <strong>decentralized management system</strong> for connected devices where all stakeholders would have the possibility to <strong>reliably consult or contribute information</strong> regarding connected devices (firmware version, maintenance operations, etc.) becomes essential to guarantee the security of those devices and the integrity of data they produce.</p>
<p>&nbsp;</p>
<h2 style="text-align: justify;">How do &#8220;Security Twins&#8221; help meet the security challenges of connected devices?</h2>
<p>In order to support IoT platforms and improve the security of IoT deployments, the notion of  <strong>&#8220;Security Twin&#8221; should be introduced in IoT deployments.</strong></p>
<p>The principle of a &#8220;Security Twin&#8221; is simple. It is a <strong>virtual representation</strong> of the connected device that <strong>contains all its security information</strong>, such as firmware version, vulnerabilities, etc. upon which all stakeholders involved in its upkeep can reach consensus (see figure 3).</p>
<p>&nbsp;</p>
<figure id="post-13966 media-13966" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-13966 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1.png" alt="" width="1012" height="459" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1.png 1012w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1-421x191.png 421w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1-71x32.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1-768x348.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/07/Figure-3-1-730x330.png 730w" sizes="auto, (max-width: 1012px) 100vw, 1012px" /></figure>
<p style="text-align: center;">Figure 3 &#8211; The &#8220;Security Twin&#8221; mechanism (from: Jitsuin)</p>
<p>&nbsp;</p>
<p>A &#8220;Security Twin&#8221; gains effectiveness when more <strong>stakeholders</strong> of the deployment <strong>can interact with it</strong> and reach consensus that the<strong> information provided/recorded is correct</strong>.</p>
<p>Therefore, solutions based on <strong>Distributed Ledger Technology (DLT)</strong> represent a logical first step in the creation of Security Twins, as they would allow the security information of the connected device to be gathered in <strong>a decentralized and immutable registry</strong> that would be accessible by all authorized stakeholders in the IoT deployment. The best well known distributed registry solution is the Blockchain (<a href="https://www.wavestone.com/en/insight/blockchain-practice/">see the article</a> on Blockchain’s uses and limitations).</p>
<p>Taking up the points raised earlier in the NIST report, one could say that the use of a &#8220;Security Twin&#8221; would therefore improve:</p>
<ul>
<li><strong>Device and access management</strong>: all stakeholders of the IoT deployment would have access to a decentralized and immutable register of all the connected devices with the corresponding security and trust information.</li>
<li><strong>Vulnerability management and the detection of device security incidents</strong>: the different stakeholders could share device security information and take the necessary actions (e.g. the manufacturer of a connected device could notify the other stakeholders of the availability of a new firmware update thanks to the &#8220;Security Twin&#8221;).</li>
<li><strong>Data protection and the detection of data related security incidents</strong>: The very foundation of a &#8220;Security Twin&#8221; is based on the use of a decentralized and immutable register to record data related to the security of connected devices. This makes it more difficult for attackers to change the data, which reduces the risk of a security incident.</li>
</ul>
<p>The use of &#8220;Security Twins&#8221; therefore offers the possibility of strengthening the security, integrity, trust and resilience of connected devices.</p>
<p>The start-up Jitsuin has developed &#8220;Jitsuin Archivist&#8221; a tool based on Distributed Ledger Technology (DLT) to overcome the lack of collaborative tools to secure connected devices. The purpose of this tool is not to replace IoT platforms but to allow the creation of &#8220;Security Twins&#8221;.</p>
<p>Together, Wavestone and <a href="https://jitsuin.com/">Jitsuin</a> sought to demonstrate the benefits of using a decentralized architecture with “Security Twins”. The two companies have therefore collaborated on the construction of a PoC (Proof of Concept) to tackle identity and access management of buildings using connected devices, which will be introduced in a future article.</p>
<p>&nbsp;</p>
<p>1 Gartner, 29th August 2019 : https://www.gartner.com/en/newsroom/press-releases/2019-08-29-gartner-says-5-8-billion-enterprise-and-automotive-io<br />
2 Palo Alto Networks, 10th March 2020, “Unit 42 IoT threat report”: https://unit42.paloaltonetworks.com/iot-threat-report-2020/<br />
3 Why IoT projects fail https://www.whyiotprojectsfail.com/?cs=br2<br />
4 NIST – “Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks” : https://csrc.nist.gov/publications/detail/nistir/8228/final</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/07/security-twins-a-new-security-trust-guarantee-for-connected-devices-2-2/">&#8220;Security Twins&#8221;: A new security &#038; trust guarantee for connected devices (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
