Monday, January 11, 2016

Warrior Angels Foundation – Stories of Impact

This is outside the scope of this blog, but the reality is that we want to believe in something bigger than ourselves. Maybe this isn't true for everyone, but my experience has shown that the stronger the player, the more that they want to compete for something bigger than only themselves.

I had the opportunity to meet with the Warrior Angels Foundation cofounders Adam and Andrew Marr along with their father at Cracker Barrel for breakfast. My wife and I gave what we could because we believe in their cause.

The foundation was a glimmer in their eye, just getting off the ground, not even 2 years ago. Imagine my surprise and the tears I wept reading through the struggles and triumphs of 10 Warriors who fought the odds and the circumstances of a corrupt political system that wanted to use them while they still have value and then toss them to the curb. So you believe in the Wounded Warrior Project? Right. Go research how much money they consume as an organization before they spend any money on the people the foundation was created to help. Where do you think that money goes? This isn't a conspiracy theory. This is pure fact. Do the research.

I was in the military. I've been around hard men. Trust me when I tell you, the juxtaposition jumped at me between the resolution of Andrew's heart to overcome his own obstacles, driven desire to help others, contempt for the hundreds of inept programs, and something else… Something that reminded me of my own autistic little child. Hyper-aware. As if his fight-flight sympathetic response was on full-bore and he could not turn it off. Hundreds of nights I've sat with my bewildered little girl to calm her down and give her assurance that she can slip into silence and sleep. I would find out later that MRI brain scans of PTSD victims and autistic children look remarkably the same.

Here is Andrew's email in its entirety.

///

Chris,

I am a hard man but I wept as I put this together. I wept for the lives and families saved, I wept for the lives and families we have lost, I wept for the hundreds of thousands who still need support. The unseen wounds of combat have come at a great cost. There is hope, Warrior Angles Foundation (WAF) is only getting started.

Below you will find 10 stories containing a brief background and 2 candidly answered questions.

These life changing stories were made possible from your contributions. You can measure the value it has produced for yourself better then I could attempt to explain it. From the heart, thank you.

Please see WAF's 2015 year end review and future objectives after these heart warming stories.

1: I'm a married with four kids, a 24 year veteran of the US Army. I spent over half my career in the Special Operations community, and deployed in support of the war on terrorism and other overseas contingencies over 8 times. 

(Q) What was your quality of life like prior to starting your personalized protocols?

(A) Despicable, horrid, non-existent. I was just spinning my wheels and looking for a way out. Constantly fatigued, and lethargic, made me very depressed.

(Q) How has your quality of life improved since your personalized protocol was implemented?

(A) I feel better right now than I have in five years. I'm still going up hill, but I can see the top. I have the energy to make up for five years of physical and mental neglect. This protocol has put me in the appropriate mental state to get physical again and I am doing it! I am very grateful for the opportunity to receive this treatment. Before I knew that it existed (Joe Rogan Experience) I was literally loosing all hope, nothing I had tried was pushing me ahead. What I can attest to is that there are NO silver bullets out there; however, this protocol is the closest thing to it, because of the continued personal contact with Dr Gordon and Andrew Marr, I am a work in progress, yes, PROGRESS, which is more than I had been in the past five years. If it were not due to this protocol, I highly doubt I'd be here today, it has pushed me over the hump and got me going, saving my life! This is just a very small but meaningful thanks to all the supporters out there making a difference!

2: Just a regular special ops dude who now focuses on being a father.

(Q) What was your quality of life like prior to starting your personalized protocols?

(A) I didn't want to live. I was angered, depressed, and in pain. I had no quality of life.

(Q) How has your quality of life improved since your personalized protocol was implemented?

(A) I feel like me again. A person. Life is worth living. This foundation is amazing and I love that I received help and that they are helping others out there.

3: I'm 23 years old, I currently work in the Medical Marijuana Industry and compete in Brazilian Jiu Jitsu. I currently live in Orange County, CA. While in the military I was an 0311 Infantry Marine and stationed at Camp Pendleton.

(Q) What was your quality of life like prior to starting your personalized protocols?

(A) Terrible. I was constantly depressed, anxious, and had zero control over my thoughts. My mind would constantly wander and think about the craziest things that never happened. I would wake up every day with sweaty palms and had the hardest time falling asleep. Constant bouts of uncontrollable anger were the most common occurrence for myself.

(Q) How has your quality of life improved since your personalized protocol was implemented?

(A) There are no words to describe how positively my life has changed in less than a year. I have complete control of my anger now. I no longer live with anxiety or depression. I'm able to have healthy relationships & think thru situations clearly. Long story short, I'm a completely new person now. Thank you for everything. Because of this treatment I'm competing in Jiu Jitsu and operating one of the most successful MMJ deliveries in Orange County. I am forever grateful.

4: I'm a 30-year-old college student and former Army vet with 4 combat deployments. I left the Army after ten years as a SSG, I was an EOD team leader in a Special Ops unit.

(Q) What was your quality of life like prior to starting your personalized protocols?

(A) There was no quality of life before treatment, I simply no longer wanted to exist.

(Q) How has your quality of life improved since your personalized protocol was implemented?

(A) Quality of life has improved greatly, now I just struggle with regular day to day stresses. Whereas before I couldn't handle anything I was just numb to the world.

5: Served as a NCO through most of the 1980's in the 2nd Ranger Bn. and HQSTARC Texas National Guard. After 911 worked in the contracting world for the Department of State and private individuals. I currently work as an Estate Manager and Designer/Project manager. I have a fiance and son from a previous marriage.

(Q) What was your quality of life like prior to starting your personalized protocols?

(A) Difficult... as a highly focused and disciplined person I was forcing my mind and body to perform regardless of how I felt physically or mentally. Physically I was finding it hard to recover from exercise and seemed t be in a chronic state of fatigue. Mentally I was finding it hard to focus, multi-task and modulate my emotional response.

(Q) How has your quality of life improved since your personalized protocol was implemented?

(A) The above stated difficulties have greatly diminished or have gone completely away.

6: I was an Infantryman deployed to Afghanistan in 2009 and 2010. I am engaged and have a 1-year-old daughter and an 11 year old step son.

(Q) What was your quality of life like prior to starting your personalized protocols?

(A) Lack of energy and motivation. Headaches, inability to focus and concentrate. Mental fog. Loss of strength and ability to recover from workouts

(Q) How has your quality of life improved since your personalized protocol was implemented?

(A) I feel sharper mentally. My short term memory has improved.

7: Medically retired Senior Chief (SEAL) after 15 years of service in the Navy.

(Q) What was your quality of life like prior to starting your personalized protocols?

(A) Mentally, it was actually getting much better from the BTC (treatment via the Brain Treatment Center), but physically still dragging.  Low energy, lack of motivation.

(Q) How has your quality of life improved since your personalized protocol was implemented?

(A) Biggest improvement is the overall feel of being healthy again both physically and mentally.  I am currently off all medication I was taking upon exiting the military.

8:  I am a veteran, I have a family, infantry.

(Q) What was your quality of life like prior to starting your personalized protocols?

(A) Terrible

(Q) How has your quality of life improved since your personalized protocol was implemented?

(A) God bless you guys for all the help. Huge part in saving my life.

9: I served in the Marines from 1991 to 2001 as longshoreman and admin clerk.  My wife is prior Air Force and now works at the VA in Blind Rehab.  We have three kids; our oldest is in the Marines and is stationed in Okinawa.

(Q) What was your quality of life like prior to starting your personalized protocols?

(A) I was very irritable, anxious, unsocial, and I tended to internalize my anger and frustrations.  The internalization was meant to protect my family from hurtful comments.  I was getting intolerant of people and mistakes, which drove me father away from interacting with anyone. 

(Q) How has your quality of life improved since your personalized protocol was implemented?

(A) I'm a little more calm and resilient.  While traveling to new areas, I'm significantly less anxious.  I go to bed later and wake earlier ready to start my day, versus wanting to just lay in bed.  I have more good days than bad days, as I don't perseverate on issues during the day. I find myself wanting to do more activities, versus just wanting to relax.  I find myself wanting to listen to a variety of music, rather than just the same playlists or radio stations while working.  I stopped drinking, drinking alcohol, anything with caffeine, excess sugar, and medical cannabis, to ensure the results of being on Dr. Gordon's regimen were legit.  So far, so good--you need only ask my wife and kids.

10: I am Hispanic male and I came from single parent household. Growing up it was just my sister and I. My mother sacrificed much of her life to ensure my sister and I never struggled, and for the most part she has succeeded. Growing up, I was an active kid, riding my bike or roller blades around the city. In high school, I wrestled all four years and played football my last three years. In the Marines, I was a machine gunner and I was in a CAAT unit (combined anti-armor team) and MAT unit (mobile assault team). I served two tours in Iraq and one domestic deployment in the states.

(Q) What was your quality of life like prior to starting your personalized protocols?

(A) Before my treatment, I was struggling to maintain focus, develop and hold new memories, and I isolated myself much from the world. My sleep quality was poor and I felt drowsy the next day. The VA had me on medication, but that did more harm than good. To help myself sleep I resorted to medical marijuana.  

(Q) How has your quality of life improved since your personalized protocol was implemented?

(A) Since my treatment, I have seen a cognitive change for the better. I am more aware of my conscious decisions and abilities. My energy level, while slowly improving, is definitely more natural rather than consumed stimulation such as coffee. While overall improvement is slowly progress, I am satisfied to see and notice the improvements. Thank you for everything y’all do. I have struggled for years (since 2008/9) to get help. After years of fighting, I am happy I am receiving help, especially help away from the VA. Thank you.

REVIEW OF WAF'S 2015
In a relatively short time WAF has gone from 0 to 1, creating something where there was nothing. Our system allows us to treat Veterans anywhere taking personalized medicine to a level never before realized, separating WAF from the 40,000 plus other military/veteran support organizations (charitywatch.org).

This has allowed Dr. Gordon and WAF to converse with senior legislators, the secretary of the Veterans Administration, key agents with the Department of Defense, countless medical providers, and other military and veteran support organizations.

In WAF’s first year over $100,000 has been raised aiding in the treatment of over 30 service members and veterans, but its not time to celebrate. We have a combined waiting list with over 600 veterans. The VA does not offer this treatment nor will they pay for it, yet. There is still much to be done.

The Future:
We will continue to use disruptive technology and tactics to improve quality of life for Veterans with Traumatic Brain Injuries (TBI) and Post Traumatic Stress (PTS) while working to secure our endorsed evaluation and treatment process within the Department of Defense (DoD) and the Veterans Administration (VA) or until new technology dematerializes, demonetizes, and democratizes the current health care system.

To free the medically oppressed,

Because families can’t and the VA won’t.

Andrew Marr
Warrior Angels Foundation Co Founder and CEO

PS. If this compelled you in any way please share it with those who are unaware of our efforts.

\\\

Tuesday, January 5, 2016

Security vs.Compliance

Snippet from a recent exchange where I was having fun. Content was dictated... Forgive obvious errors.

Security
Compliance
Driven by fear, pain
Driven by fear, pain
Because of security operations, business management, customers
Because of auditors/Assessors, business management, customers
Because of news stories, threats, previous compromises, 60 Minutes, bogeyman, contract requirements
Because of assessments, legal requirements, contract requirements/agreements, organizational policy
Because no one wants to lose their job
Because of regulations and standards such as HIPAA, CJIS, FedRAMP, PCI DSS
PRIMARY OBJECTIVE: Protect Data.
WHO?: Similar stakeholders involved. They may not see it that way, but they are.
WHAT?: Same data involved. Financial information, Intellectual property, credit card data, electronic patient healthcare information, plans for the death Star version 2.0, rocket ships, music tracks for Adele’s next album.
WHEN?: All the time. Continuous compliance is the new black. Typically/traditionally annual review, but this is changing.
WHERE?: Primary focus and scope is always where data is stored, processed, or transmitted because these are the places that you have direct access. Includes everything layer 2 adjacent. Location doesn't matter. Public/private – don't care. Secondary focus is always on the supporting infrastructure and security/operations management infrastructure for the primary scope. Includes any system that directly accesses primary scope. There are some exceptions.
WHY?: Protect Data. Same objective.
FAQ
Compliance and security are different animals with completely different objectives. How can you say that if you meet compliance objectives then you are secure?
A vast majority of the regulations, standards, and best practice frameworks directly address the requirement of an active risk management program. Risk management is the identification of potential threats, prioritization, cost analysis, and threat mitigation through the use of safeguards. Another word for safeguards is controls. They are synonymous.
 
Therefore, you must effectively address all security risk (subjective qualitative and quantitative) before you can attest to meeting risk management control objectives for compliance.
No seriously. Compliance is not security.
That's correct. Security is an outcome of compliance executed properly. Compliance is how the football team executes the offense. Security represents the offensive linebackers. The Dallas Cowboys had arguably the best offensive line in football. Unfortunately, nothing else worked. We will not discuss the outcome of the season.
But my customer asked me a question that sounded a whole lot like a security question…
Perhaps it was.. Or perhaps if you dig a little bit deeper then you will find the security requirement is driven by a compliance requirement/objective.
My customer said they only care about security.
Sometimes this is true. Other times, you may find that management has a different viewpoint.
 
Healthcare, financials, anyone dealing with money, customer information, trading/reporting publicly, global operations, public sector, critical infrastructure, high risk operations looking for DOD equivalent, defense, federal, foreign governments, consumer transactions, B2B transactions, service providers, etc. Pretty sure that includes most of the Fortune Global 500. http://fortune.com/global500
Are you sure you know what you're talking about?
<Drop the mic..>

Friday, December 18, 2015

Cybersecurity Fundamentals – Top 3 Project Papers.

After reviewing roughly 30 projects, these are my top 3 for the semester. There's another one that also I absolutely love about insider threat anomaly detection. I've included the summaries below of each of these well-written papers.

First, Lance created a survey asking users about smartphone security. Population size 117, statistically significant with a +/-10% margin of error. Contains interesting findings highlighting differences between Apple and android users. Great writing style.

Next, Harrison decides he's interested in learning about the dark web. He also has a great writing style which made this a fun and interesting read. Check this one out.

Finally, Seyed dove into Amazon Web Services security. I'm well aware of the wealth of information he had to go through to put this together, and I'm proud of the outcome and effort.

Head on over to the documents tab to view!
https://sites.google.com/site/cloudauditcontrols/

Smartphone Security Assessment

Lance Giles

Summary
In 2014, my laptop fell victim to a Basic Input Output Operating System (BIOS) rootkit, which left it irreparable. My good friend who ran diagnostics on the laptop and discovered the rootkit recommended that I start shopping for a new computer. The news that my laptop was not responsive to repairs stunned me. My use of the internet was limited to emailing, banking, shopping occasionally, and monitoring my credit. I had active antivirus and antimalware software on my laptop. No unusual behavior was detected in my laptop until it seemed abnormally slow one day. How could my laptop be penetrated by a rootkit that nestled in the BIOS when my usage was low risk and security measures were in place? When I discussed my puzzlement with my friend, he highly recommended that I visit Security Investigative Reporter Brian Krebs’ blog at ‘https://krebsonsecurity.com/’ and learn more about malware, firewall, identify theft prevention, and mobile device security.

Since then, my interest in acquiring tips and techniques for securing information systems has accelerated. My interest drives me to evaluate the current practices of securing smartphones. To me, it seems that smartphones are rapidly becoming more commonly used than a laptop, desktop, or tablet. As of April of 2015, approximately 64 percent of “American adults now own a smartphone of some kind, up from 35% in the spring of 2011. Smartphone ownership is especially high among younger Americans, as well as those with relatively high income and education levels.”(3) Similar to laptops and desktops, smartphones are vulnerable to malware transmitted through emails, web traffic, and external media such as USB; however, unlike laptops and desktops, they are also vulnerable to malware transmitted by text messages, apps, and games. (6, page 40)
 

Into the Heart of Darknets

Harrison Van Riper

Summary
America has developed a fascination with the dark web. In the first season of House of Cards, one of the characters accesses the dark web to get in touch with a hacker. In dramatic fashion, he is introduced to the shady and covert services on the internet underbelly. Over the last couple of years, Silk Road has gained high media attention. The site provides an anonymous marketplace for drugs to be sold to its’ anonymous user base. The public perspective of the dark web is that it hosts all kinds of vile and illegal activities, like the aforementioned Silk Road or illegal pornography. I thought to myself, how can something so seemingly criminal exist? I’d never accessed it before or talked to anyone who had. Why not dig in and see what all the fuss is about?
 

Public Cloud Security (AWS)

Seyed Ahmadreza Amin

Summary
Information security is of paramount importance to Amazon Web Services (AWS) customers. Security is a core functional requirement that protects mission-critical information from accidental or deliberate theft, leakage, integrity compromise, and deletion.

Under the AWS shared responsibility model, AWS provides a global secure infrastructure and foundation compute, storage, networking and database services, as well as higher level services. AWS provides a range of security services and features that AWS customers can use to secure their assets. AWS customers are responsible for protecting the confidentiality, integrity, and availability of their data in the cloud, and for meeting specific business requirements for information protection.

This article describes best practices that customers can leverage to build and define an Information Security Management System (ISMS), that is, a collection of information security policies and processes for their organization’s assets on AWS. Although it is not required to build an ISMS to use AWS structured approach for managing information security that is built on basic building blocks of a widely adopted global security approach will help customers improve organization’s overall security posture.

 
 
 

Tuesday, December 15, 2015

IT Auditing – Mandarin Chinese Version

Thought this was really cool. Package came in the mail today with a book written in Mandarin Chinese... Thought at first it was a mistake! It's the last edition we wrote of IT Auditing: Using Controls to Protect Information Assets!! McGraw-Hill Education had the book translated and sent us a copy. Awesome!

Thursday, December 3, 2015

Wednesday, December 2, 2015

Asymmetric Defense Failures

No. I'm not talking about the cost of an attack vs. the cost of defending the network. I'm talking about traffic flows. Communications are bidirectional, ingress and egress, yet many still focus on only ingress protection mechanisms.

You need both. For example, your firewall and intrusion prevention system (malware, etc.) may do a fantastic job at identifying incoming attacks. However, you also need egress detective and protective controls. For example, your DLP system can help identify data exfiltration – egress – and your network behavior anomaly detection appliance can help identify potentially compromised hosts communicating to command and control servers.

There's actually much more to write about on this topic. But for now, suffice to say that intelligent context and control of communications are important from both perspectives.

Monday, November 23, 2015

NIST SP 800-53 r4 to CJIS v5.4 Control Mapping

Reverse mapped CJIS control set into NIST 800-53 controls as the new baseline.

Download here.

State Security Model Flaws – or… Assumptions

This is meant to be a short, simple post. Just capturing interesting discussion from our class the other night. The state security model is really simple, representing an easy way to describe the importance of governance. Provision, configure, validate to a known good state. Monitors state deviations. Known state deviations are good and mean that you are still in a known good state. Unknown state deviations must be investigated (response) to determine whether it is a new known state deviation or an incident.

However, some really good points were brought up during class. There's a lot of assumptions on external factors introducing the errors from the way that several people have presented and discussed the model. We learned this model in the military, and the source of the deviation could be assumed to be internal or external. It didn't matter.

The reality is that your definition of a known good state may or may not be absolute (100%). Your visibility into the system is almost certainly not absolute. Examples include running firmware, existing compromise, individual configurations, account access, authenticator systems, cipher code/implementation/system, source code, system interoperability/API configurations/capabilities/hidden capabilities...

If we presume that assurance of a known good state is based upon a selection of points that you can validate, then how many points are good enough to provide assurance of a known good state? What about the periodicity? Is there anything here we need to consider?

Systems themselves could *possibly* introduce errors within the bounds of allowed operations. People most certainly can. Component visibility can inhibit your view/understanding of actual state. Your view/understanding of actual state can change between timed points of inspection. External and/or internal actors may identify vulnerabilities in code and exploit that within the bounds of your controls.

The point of the discussion is that models can be very powerful, and certainly helpful for understanding systems through a particular lens. Think outside the box. Don't be afraid to ask questions. The person who initiated the discussion is perhaps one of the least technical people in the class, just asking innocent questions.

How do you address the concerns? Short answer. Build the system with enough introspection and visibility into critical processes/configurations that overcomes your risk tolerance. Make the assumption that the system is already compromised and build it so that you can identify an existing compromise to the extent possible. Strong emphasis on access controls, not repudiated auditing, visibility into communications including who/what/where/why/how/volume.

Spreadsheet: FBI Cloud Control Catalog – Appendix A

Here's the spreadsheet version, cleaned up, of the FBI Criminal Justice Information Systems (CJIS) Security Policy - CJIS Cloud Control Catalog.

► Download spreadsheet version here.

Friday, October 30, 2015

HIPAA Technical Control & Assessment Links

Go to the documents tab to find spreadsheet versions of the below.
Recent discussions… Capturing some of that here. Some of the more important links to technical assessment information is above. Services are actually easy to build, as long as you simplify the approach. Has everything to do with scope, stating assumptions, and setting expectations.

By the way – yes, I downloaded and reviewed the current version of the HITRUST framework.

On another note, HITECH  has nothing to do with technical controls and is an unfortunate name. It's confusing, but it's entire focus is enforcement – putting teeth into HIPAA using financial penalties as an incentive. Please do not use it out of context.