Cyber Security Threat Classifications

 Read an interesting book where the usual Cyber Security Threat Classifications were listed as below:

Security Threat Supply

a) Internal Threats: It is usually internal to the organization because the results of worker action or failure of a company method.

b) External Threats: It arises from people or organizations operating outside of an organization. 

Threat Agents

a) Human Threats: This category includes threats caused by human actions like insiders or hackers that cause damage or risk in systems.

b) Environmental Factors: These are threats caused by non human agent. It comes, first, from natural disaster threats like earthquakes, flood, fire, lightning, wind or water and, also, as a result of animals and life that cause severe harm to data systems like floods, lightning and fireplace. 

c) Technological Threats: It can be physical or chemical process for technology. P

Threat Motivation

Attackers ordinarily have a particular goal or motive for an attack on a system. These goals are:

a) Malicious threats include within or outside attacks caused by staff or nonemployees to damage and disrupt a company like viruses, Trojan horses, or worms.

b) Non-malicious attacks occur as a result of poor security policies and controls that enable vulnerabilities and errors to require place. 

Threat Intent

Intentional Threats: It represents threats that are results of a harmful call. For instance laptop crimes, or once somebody by choice damages property or data. Laptop crimes embrace spying, fraud, pornography, and MasterCard crime.

Unintentional Threats: It represents threats that are introduced while not awareness. These threats primarily embrace the unauthorized or accidental modification of computer code. Accidental error includes corruption of knowledge caused by computer error, user or operator error.

Four Types of Security Threats

You need to be aware of the Four Types of Security Threats:


Disclosure: This involves leaking secrect information or data to the wrong guys. This can lead from exposure of personal information to devastating security impacts.


Theft: This is when something of value gets stolen. It can lead to huge harm to the organization.


Integrity: This happens when an asset being intentionally damaged. When a virus enters your computer or your compuater gets hacked, and this causes problems, that is an integrity threat.


Denial of Service: This is when some service is intentionally blocked. Some experts believe this to be the most difficult of all threats to deal with effectively.

Cyber Security

 Cyber Security is extremely important for an Organization of whatever size it might be. Cyber Security breaches can be so awful that it can shutdown a company. 

But one needs to remember that instead of "We" in cybersecurity, "I" is very important. Everybody in a organization should play a role in cyber security, and be cautious about what they do so as to protect their organization from attacks.

Indian Heathcare sector on the High


Interesting read on the healthcare special by Punita Jasrotia in SpiceRoute


Healthcare sector indeed on a high with government's encourage and private sector players making all the right moves.

Not surprising that India has become the Medical Tourism destination of choice!!

Lean IT vs Six Sigma

The confusions between the concept of Lean IT and Six Sigma still exist. Many I times, I get asked the same question, "Can you tell me how Lean IT differs from Six Sigma?"

Simply put, Lean IT is about waste reduction/removal and Six Sigma is about defects.

Cloud Changing the Tech Landscape

Read an interesting article on the wired: http://www.wired.com/2015/10/meet-walking-dead-hp-cisco-dell-emc-ibm-oracle/

It shows how cloud is changing the technology landscape. Smaller companies with focus on cloud are emerging stronger and better than the traditional tech majors.

It definitely makes sense to "Go Cloud".

Lean's aim

If we use Lean as a mean to employee reduction, it is not a right way to go. First focus on removing the waste - on quality and process improvement. Other benefits come in as by product.

But if you go ahead with the "by product" as your goal, you are on the wrong track.

Sanjna Kapoor's Junoon

Sanjna Kapoor is one personality I admire. Despite being from an iconic family, she is simple and innovative in her ways to make theatre popular.


Sanjna Kapoor’s Junoon – a rather interesting article. Good one Punita!!

Cloud provides Agility


Read somewhere recently the agility that cloud provides

"One of the most important benefits provided by cloud technologies is agility. The business and IT support are more agile. Users are able to connect to services more quickly, with fewer mistakes and greater consumption. IT is more flexible. Cloud solutions provide IT with the ability to support users from anywhere at any time, adapt to business and market demands, and manage projects with greater efficiency. Business owners can create and manage services they deem necessary. Business users can consume these services much more quickly. And IT is free to be more innovative. The speed of delivery and ease of use improves the business and enables self-sufficiency. Accessibility to knowledge is increased, and the process now adds value rather than a burden. Cloud solutions provide a more agile way to empower the business."

Lean IT is a culture change

I often get asked 'As per Lean IT, what the things that we should implement?'

But what people tend to forget is Lean IT is not a magic tool that can be implementeted and you begin reaping the benefits than after.

Lean IT is about analyzing your proces, your operations, your efforts, your work and people--and understanding what are waste in your process/operations/work/people and removing the waste.

Unless you analyze and understand the waste, you can not implement any improvements.

Please understand that Lean IT is about empowering the frontline resources and bringing in a change in the culture of your organization or operations that focuses on waste removal!!

What should be considered before adopting cloud?


Don’t you wonder what you should do before rolling out cloud solutions? Well, a wired article provides some few guiding principles as you start your cloud journey.

1.     Set clear objectives.

2.     Consider when (and whether) to integrate existing data and systems.

3.     Research solutions online and start for free.

4.     Consider all costs, not just initial purchase price.

Why adopt Cloud?

Read an interesting article. It listed the five reasons for which makes business decision makers feel the cloud is critical to their businesses’ success:

1.     Cloud offers better insight.

2.     Cloud helps collaboration.

3.     Cloud drives better engagement.

4.     Speed!

5.     Cloud benefits are measurable and pay for themselves.

 Please click on the link below for more information.

Process Improvement Methodologies---Organizations should decide

Very often, people tend to ask “which is the best improvement methodology to adopt?’

Though my bet lies with Lean, but I would say “it actually depends on what exactly does your organization need”. People are usually confused about the most spoken and used improvement methodologies – Lean, Six Sigma and Theory of Constraints (TOC).


I recently read an article which very interestingly differentiate the three as shown below:


Process Improvement Methodologies

Focus

Result

Six Sigma

focus on reducing variation and 
achieving uniform process results in less waste, less throughput time and less inventory

If we focus on reducing variation,  
then we will have more uniform process output.

Lean

focus on waste and flow time results in less variation, uniform output and less
inventory

If we focus on waste removal, then flow time will improve.

 

TOC

focus on constraints and increased
throughput results in less inventory and a different accounting system

If we focus on constraints, then throughput volume will improve.

 


 

Capacity Management Important for Private Cloud

Read an interesting article Top tips for calculating the cost of a private cloud. It highlights the importance of capacity management in private cloud.

Accordingly to Dr. Owen Rogers, digital economist at analyst firm 451 Research, one of the most important tasks is to consider how capacity will be added over time, and how much it will cost. However, this is also one of the least considered areas when weighing up the costs involved in moving to a private cloud, he warns.

“A private cloud is ultimately a fixed capacity, and its utilisation will vary depending on the behaviour of its applications and the end-users using it,” he says. “From a cost-efficiency point of view, the best situation is when the entire capacity of the private cloud is utilised, so the unit cost per virtual machine is the smallest.”

It is really surprising to see organizations going ahead without much focus on proper capacity management process or plans as they go ahead with private cloud. But issues arise when they scale up and operations become massive, and that’s when the cost and everything spirals out of control. That is the main reason why organization should first make a proper capacity management plan, look at current capacity and prepare for the capacity that would be required in the future. It is imperative to remember that capacity management is not a stop gap solution but an end-to-end process.

Cloud makes Knowledge Management easy

Knowledge Management is of extreme important for the organization. Gathering, collecting, storing, managing, monitoring and controlling the knowledge data is crucial for an organization’s success. Accessing the appropriate data assumes importance today’s scenario where the speed to market while maintaining the quality defines the success of a product or service. Easy access to those data is the key.

Today collaboration and sharing of knowledge data/content assumes importance. According to a new study by IDG Research, the vast majority of knowledge workers (86%) placed a very high level of importance on collaborating with internal coworkers and external stakeholders, and having access to the most up-to-date corporate information. This kind of collaboration as sharing of knowledge happens only when information can be easily accessed internally and externally. Hence, Cloud-based delivery models are vital as they enable highly scalable document storage and makes seamless collaboration a possibility. Once you store the data in a centralized storage server in cloud, users can easily access, manage, share, view and update the data; in addition, the organization can easily monitor and control those data and used the storage system as a knowledge management storage system enterprise-wise.

Latest Threats to Cloud

CSA (Computer Security Alliance) recently came out with 2013 Top Cloud Computing Security Threats. Cloud security has improved a lot, but threats still lurk; and as the ease to adopt the cloud applications becomes easier, vulnerabilities also increases as organizations might unknowingly expose themselves to malicious threats. Hence, it becomes extremely important for the organizations to keep an eye out for the threats mentioned by CSA. Following are the nine critical threats to cloud security (ranked in order of severity):


  1. Data Breaches 
  2. Data Loss 
  3. Account Hijacking 
  4. Insecure APIs 
  5. Denial of Service 
  6. Malicious Insiders 
  7. Abuse of Cloud Services 
  8. Insufficient Due Diligence 
  9. Shared Technology Issues 

To protect your organization, check out CSA’s best practices guides, “Security Guidance for Critical Areas in Cloud Computing V.3” and “Security as a Service Implementation Guidance.”


The permanent and official location for Cloud Security Alliance Top Threats research is http://www.cloudsecurityalliance.org/topthreats .

Reap ITaaS Benefits

The following excerpts, from “Don’t Get Stuck on Your Virtualization Journey: Where to Focus Next”, are to understand the ways to reap benefits from ITaaS:
 
Based on a collection of research from businesses that have reached the ITaaS phase of the virtualization journey, the following best practices emerge:
  •  Secure executive approval and funding for the IT-as-a-Service or cloud computing journey and transformation.
  • Develop a roadmap or strategy that covers: hardware, network, storage infrastructure, virtualization technology, and management of those moving pieces, as well as an outline of the service offerings for end users.
  • Shift IT’s focus from managing technology tasks to delivering services that align with business needs; service-centric IT organizations take the time to start first with the business requirements and the end-user point of view.
  • Reinvent your IT organization and processes to align with the technological changes of virtualization and cloud computing. 
  • Replace manual IT processes with automated ones; starting with a “managed virtualization” platform early can relieve the pain of integrating automation technologies later.
  • Create a self-service catalogue of IT services for users and lines of business.
• Give IT management control over third-party cloud service providers along with internal IT services.

Virtulization Phases

Read a rather interesting and valuable piece “Don’t Get Stuck on Your Virtualization Journey: Where to Focus Next
 
The following excerpts, from the above, provide a valuable insight:
 A typical virtualization journey consists of three distinct phases:
  • Phase I: IT Production. Virtualization is used primarily for server consolidation of IT-owned applications.
  • Phase II : Business Production. Businesses begin using virtualization for business-critical applications such as Microsoft Exchange Server, Oracle, or SAP, and deploy more advanced virtualization automation and management features.
  • Phase III: IT as a Service (ITaaS). All applications are eligible to run in virtual machines (VMs), advanced techniques are used to manage and monitor virtual servers, and IT organization and processes are updated to run efficiently within virtual infrastructure.

Points for successful Cloud adoption

A large number of cloud deployments seem to fail because it was not strategized properly, and was not done keeping the interests of both IT and Business. The following points seem to be popular and successful in the cloud adoption and integrating it with needs of the IT and business:
  •  Identify your target audience
  • Understand the customer’s requirements
  • Understand the Cloud and choose Cloud solutions accordingly as per your need and requirements of your customers.
  • Define your offerings
  • Update your processes as per the Cloud requirements & offerings
  • Never forget to create a dedicated Cloud team

Five Strategies for Cloud Adoption

If you are thinking about Cloud adoption but is apprehensive about its success, just follow the below listed strategies, as suggested by Gartner Inc, to weigh your option:
  • Build the business case
Link the Key Initiative (cloud) to the overall drivers or objectives of the business. Gain support from senior business leaders and senior stakeholders. Set a baseline for assessing the impact of the investigation. Estimate costs and resource requirements.
  • Develop the strategy
Align the investigation with the business strategy, and show how it can deliver business value. Show how the investigation might lead to changes that will affect your business environment. Work with key stakeholders to identify business needs.
  • Assess readiness
Identify the budgetary, staffing, technology and other requirements necessary to prepare the business for the investigation. Develop a total cost of ownership analysis framework. Review established policies for assessing risk and managing governance.
  • Pilot or prototype
Identify a group to pilot, or develop a prototype for the investigation. Develop and communicate detailed requirements. Manage the pilot/prototype. Assess and communicate the results.
  • Gain approval
Analyze findings of the readiness assessment and pilot or prototype effort, and revise the strategy and business case accordingly. Present findings of the investigation to senior stakeholders and business leaders.