Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Monday, April 19, 2010

On Serving in Program Committees of International Conferences

In the last few months I served as a member of various Program Committees of International conferences, including: IEEE Policy 2010, SECRYPT 2010 and MobiSec 2010.

I have also acted as a reviewer of Journal articles, including: Journal of Systems and Software (JSS), ACM Transactions on the Web (TWEB) and Identity in the Information Society (IDIS).

I would encourage people to get involved in these activities. They help me to have a broader and up-to-date view of what is happening in the IAM and security space –as well as networking with peers in these fields.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Thursday, March 11, 2010

New HP Labs Technical Report – Job Design: Providing Strategic Decision Support for Risk Analysis and Policy Definition

A new HP Labs Technical Report has been published called “Job Design: Providing Strategic decision Support for Risk Analysis and Policy Definition” (authors: Marco Casassa Mont, Adrian Baldwin, Simon Shiu, Paul Collins):

“Strategic decision makers need to organize their workforce and define policies on how to allocate roles and rights to individuals allowing them to work effectively for the organization, whilst minimizing security risks. Many organizations have a separation of duty matrix specifying certain toxic combinations of access rights that they generally understand present an extreme risk. These matrices do not always contain some of the less understood or smaller risks. The flip side of the rights allocation problem is the need for an organization to keep systems running under various pressures including reducing headcounts. This tension often leads to a practice of providing skilled individuals with wide access rights to many systems. We describe this tension as the Job Design Problem. That is how to manage the trade-offs between allocating roles allowing for flexibility and the possible security impacts. It is not just a matter of technical "role engineering", access right allocation and Identity & Access Management (IAM) provisioning processes. Decision makers need tools that help them understand how to give guidance and set policies associated with role allocations and mechanisms to enable a debate between various stakeholders within the business, IT and Audit concerning the appropriate level of tradeoff and acceptable risk. In this paper, we aim at making progress in this field by presenting an approach and methodology to provide strategic decision support capabilities for the definition and assessment of policies in the context of Job Design. We focus on a problem provided by an IT department within a large organization, where employees (primarily IT admins and IT support staff) operate on sensitive and critical business systems and services. In this context, security risks are a major concern and need to be fully understood. Depending on the motivations and skills of the workforce, accidental or deliberate misuses of access rights and capabilities might take place and have huge economical and reputational consequences for the organizations. The decision makers (e.g. CIOs, CISOs) need to understand the implications and trade-offs of making job design decisions as wells as investing in additional/complementary controls, such as monitoring/auditing systems, IAM solutions, education or vetting/clearance programs. We describe a decision support solution based on modeling and simulation, to provide this kind of policy-decision support. This is work in progress. We present our current results and next steps.”

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

The First EnCoRe Technical Architecture for the Management of Consent and Revocation is Available Online

The first EnCoRe Technical Architecture for the explicit management of consent and revocation on personal data has been published and is available online:

“This document is a formal deliverable of the EnCoRe project. It contains the definition of the EnCoRe Technical Architecture for the first realized Case Study: an Enhanced Employee Data Scenario. It also describes that scenario – specifically the use, by employees of an organisation, of a Web2.0-style service for work-related and personal purposes – and its related requirements regarding consent management. These requirements were gathered and defined by legal and social science research within the EnCoRe project, and were influenced by its concept formalisation research.
The scope of the EnCoRe Technical Architecture for this first Case Study encompasses all the technical functions required for the management (including capture and revocation) and enforcement of individuals’ consents that are pertinent to the Case Study‟s scenario. The technical architecture is the block-level design of the necessary technical system, at the level of functional blocks (i.e., software and service components) and the data flows between them and to/from humans, other technical systems, compliance and other business processes and regulatory environments. Its goal is to provide the basis for an EnCoRe reference implementation that validates the approach and the technology. To that end this document’s approach is to start with contextual information and overviews, and incrementally refine the level of detail. Most of this detail is contained within Appendices.”

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

HP Labs 2009 Annual Report

The HP Labs 2009 Annual Report is now available online:

“In fiscal year 2009 -- from November 2008 through October 2009 -- HP Labs has focused its research agenda on fewer, larger projects that have the potential to change the future of the industry and shape the future of HP.
The HP Labs 2009 Annual Report highlights our research themes, significant inventions, open innovation activities and, most importantly, our research team.
Print copies of the report and its Appendix, which lists the year's publications, may be ordered through MagCloud.com, a new print-on-demand service created in HP Labs. To order copies, click here. “

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Friday, February 12, 2010

The Economics of IAM: On the need to move the focus of IAM from the Operational Level to the Strategic Level

I noticed that most of the discussions on IAM are really focused on the operational and functional aspects. As eventually decision makers (with a budget) need to make investment decisions in this space, the usual arguments about ROIs and business-level cost/benefit analysis are made by starting from this perspective.

But, is this really what CIOs/CISOs and related strategic decisions makers want to hear? After been exposed to various interactions with people covering these roles, I believe this is not really the type of message they are looking for.

In these days, strategic decision makers (that have a budget and make investment decisions …) need to balance a variety of aspects and constraints derived from the business, legislation, governance, IT, security, etc. They need to cope with various tension points and mediate different viewpoints within the organisation; as a consequence they need to explore the various trade-offs and identify the most suitable investment choices consistently with their ever shrinking budgets.

So, arguments made in the context of IAM should move away from a pure technological/IT viewpoint (that is anyway still very important …) to encompass an holistic view that takes into account the complexity of the business, legislative and IT world they operate on a daily basis.

I believe that the economics of IAM, in a wider context of the economics of security, is a discipline and area that really need to be explored.

I personally believe this is a fascinating area where various contributions can be made. The HP Labs work on Identity Analytics, Economics of IAM and Security Analytics is really meant to make progress in this direction.

I am currently carrying on various case studies with HP customers. They are extremely valuable to refine ideas and build decision strategic support solutions. I am very keen in getting any additional input/viewpoints and (unusual) case studies to make further progress in this space.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

HPL Technical Reports – Economics of Identity and Access Management: Providing Decision Support for Investments

I recently published (jointly with a few HPL colleagues) two HPL Technical Reports on the topic of “Economics of Identity and Access Management (IAM)”: HPL-TR-11 (executive summary) and HPL-TR-12 (detailed description of the case study)

These two documents discuss a case study aiming at integrating economics to security analytics methodologies, to provide strategic decision support in the IAM space:

“Identity and Access Management (IAM) is a key enabler of enterprise businesses: it supports automation, security enforcement and compliance. However, most enterprises struggle with their Identity and Access Management strategy. Discussions on IAM primarily focus at the IT operational level, rather than targeting strategic decision makers' issues, at the business level. Organisations are experiencing an increasing number of internal and external threats and risks: there is scarcity of resources and budget to address them all. Decision makers (e.g. CIOs, CISOs) need to prioritise their choices and motivate their requests for investments. This applies for investments in IAM vs. other possible security or business investments that could be made by the organisation. In this context, a range of possible IAM investment options has an effect on multiple strategic outcomes of interest, such as assurance, agility, security, compliance, productivity and empowerment. We have developed a repeatable approach and methodology to help organizations work through this complex problem space and determine an appropriate strategy, by providing them with decision support capabilities. The proposed approach, validated in collaboration with security and IAM experts, couples economic modeling (which explores decision makers' preferences between the different outcomes) with system modeling & simulations to predict the consequences (likely outcomes) associated with different investment choices and map them against decision makers' preferences, in order to identify the most suitable investment options. We illustrate how this methodology has been applied in an IAM case study, in a business-driven context with core enterprise services. This work is in progress. We discuss current results and next steps.”

A related paper discussing this work has recently been accepted at the 5th IEEE/IFIP Business Driven IT Management Workshop, BDIM 2010.

In addition to current engagements with HP customers, I am also looking for additional (interesting/unusual) case studies involving IAM aspects where to further refine this approach.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Friday, January 22, 2010

Looking for Case Studies and Documents about the Impact of Job Design on Enterprise Security Risks

I am looking for case studies, documents and statistics analysing the impact of job design choices on enterprise (security) risks.

Job design, in a nutshell, involves defining employee roles and related tasks associated for employees in an organisation.

Intuitively, job design decisions have an impact on the productivity of employees, number of accidental & deliberate incidents, exposure to security risks (e.g. by dealing/not dealing with separation of duties and/or empowering too much certain people/roles).

There are interesting studies tacking this issue from an economics perspective, such as the paper on “Limited Intertemporal Commitment and Job Design” (even if it is a little bit too abstract).

So far I have found very little in terms of studies and documents that scientifically analyse how changes in job design affect security risks in an organisation. Any link and reference would really be welcome.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

TSB EnCoRe Project – Sixth Quarter Summary and other News

The Sixth Quarter Summary of the TSB EnCoRe Project (Ensuring Consent and Revocation - http://www.encore-project.info/) has been released: http://www.encore-project.info/press_archive/Q6%20summary.pdf

The EnCoRe website has also extended to provide the latest news and EnCoRe tidbits, related to aspects of privacy, consent and revocation of preferences: http://www.encore-project.info/news.html#story1

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

CfP MobiSec 2010 – Submission deadline: 8 February 2010

The CfP of the 2nd International ICST Conference on Security and Privacy in Moblie Information and Communication Systems – MobiSec 2010 is now available online: http://www.mobisec.org/

Please consider submitting a paper. The deadline is 08 February 2010.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

CfP TrustBus 2010 – Submission deadline: 12 March 2010

The CfP of the 7th International Conference on Trust, Privacy & Security in Digital Business – TrustBus 2010 is now available online: http://www.isac.uma.es/trustbus10/

Please consider submitting a paper. The deadline is 12 March 2010.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

CfP IEEE Policy 2010 – Submission deadline: 15 February 2010

The CfP of the 11th International Conference on Policies for Distributed Systems and networks – IEEE Policy 2010 is now available online: http://www.policy-workshop.org/

Please consider submitting a paper. The deadline for submitting an abstract is 8 February 2010 whilst the full paper is due on 15 February 2010.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

CfP SeCrypt 2010 – Submission deadline: 03 February 2010

The CfP of the International Conference on Security and Cryptography – SeCrypt 2010 is now available online: http://www.secrypt.icete.org/

Please consider submitting a paper. The deadline is 03 February 2010.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Friday, December 4, 2009

W3C Policy Interest Group (PLING) Extended till Feb 2011

W3C has agreed to extend the W3C PLING Interest Group till February 2011.

I’ll keep co-chairing it along with Renato Iannella. Rigo Wenning and Thomas Roessler are the staff contacts.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: my original HP blog can be found here ---

Interesting article – What is a CSO?

Here is an interesting article discussing the role of the Chief Security Officer (CSO) within organisations.

The CISO/CSO role is going to dramatically change in the coming years, in particular considering current trends involving IT department shrinking, consumerization of IT and the adoption of cloud computing/services …


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: my original HP blog can be found here ---

New Study calling for Cyber Security Overhaul in US

Interesting article providing an overview of a new study that argues that:

“Government needs to focus on offering businesses incentives to fix security problems and educating corporate leaders about the benefits of enhanced cybersecurity …”


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: my original HP blog can be found here ---