Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Friday, May 21, 2010

On Strategic Preference Elicitations from Security Decision Makers (Economics of Security and Identity Management)

In the context of my Security and Identity Analytics R&D work I am currently exploring various methodologies and approaches to elicit strategic preferences from decision makers.

Ideally, by understanding these strategic preferences, it is possible to create a framework where to investigate the implications of security (investment) decisions, from an economic perspective: in this context, analytic methods, leveraging modelling and simulation techniques, can also be used for what-if analysis.

Recent technical reports, HPL-2010-11 and HPL-2010-12, provide a more detailed description of some of the work done at HP Labs in Identity Analytics, in the space of Economics of Identity Management.

Of course I am well aware that different approaches and methodologies might apply and that the scientific community has different views and perceptions of how and when to use preference elicitation.

An interesting paper (among many) setting the context in this domain is “Survey of Preference Elicitation Methods” by Li Chen and Pearl Pu, EPFL, Losanne.

However, I wonder if anybody in the community is aware of current work and or documents describing methodologies and case studies in the specific area of preference elicitation, in the security domain.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Article: What CIOs need, how CISOs should deliver

An interesting article has been published by “ComputerWorlds UK” called “What CIOs need, how CISOs should deliver” and posted by Dan Turner, CTO, Vistorm (HP Company).

Our work at HP Labs on Security Analytics has been mentioned:

“My colleagues at HP Labs are looking to go further with their research into ‘Security Analytics’. Through the use of economic and mathematical techniques combined with predictive modelling, the research claims that it’s possible to measure the effectiveness of an organisation’s security controls and therefore guide better investment by understanding the trade-offs. Needless to say, it makes for interesting reading and this will certainly be an area to watch.”

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Update - Keynote Speaker at IEEE i-Society 2010

As mentioned in a previous blog post of mine, I have been invited to be a Keynote speakers at IEEE i-Society 2010, the International Conference on Information Society.

Thanks to those people that sent me their input and suggestions. I kept into account the input and feedback in the speech abstract that I sent to the organisers:

“We are living in interesting times. New trends affect the information society (organisations and people), such as: increased availability of services in the cloud; the adoption of web 2.0 and social networking for personal and business purposes; pervasive mobile computing; the consumerization of the enterprise.

Along with many new opportunities for people and organisations, we are also assisting to the raise of new security and privacy threats and an increased role played by the organised cybercrime.

People and organisations are going to be more and more impacted by these trends and threats. Organisations need to better understand the dynamic threat environment they are fighting against and where to effectively make their security investments. More assurance and trust is required on the Internet.

This keynote discusses these trends, briefly analyses emerging threats and provides an overview of the organised cybercrime ecosystem. It highlights a few needs and research opportunities in key areas, including: automation of security lifecycle management, economics of security, security analytics, trusted virtualisation, identity assurance and privacy management. Related work done by HP Labs in this space - in collaboration with the UK research community - is presented and discussed.”


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Monday, April 19, 2010

Keynote Speaker at IEEE i-Society 2010

I have recently been invited to be one of the Keynote speakers at IEEE i-Society 2010, the International Conference on Information Society.

I am currently evaluating different potential topics to present in my speech, including:
  • Recent trends affecting the Society, organisations and people, including Cloud Computing, Web 2.0, Consumerisation of enterprises, etc.
  • The increasing role that organised crime has on the digital society
  • The problem posed by privacy and privacy management in the digital world
  • Opportunities in the space of Security and IAM to address some of these issues
  • Role that various emerging R&D areas can have in this space: Trusted Virtualization, Economics of Security and IAM, Security and Identity Analytics, etc.
  • …

Please feel free to suggest/recommend any topic or aspect you believe it might be of relevance for this type of conference. I would be very interested in getting your input.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

An Update on HPL R&D Activities on Identity Analytics

At HP Labs, we are making good progress in our R&D activities in the space of IAM Analytics.

As a reminder, the goal of our Identity Analytics activity (aka IAM Analytics) is to provide strategic decision maker with decision support tools to make informed decisions by exploring available options and trade-offs by means of what-if analysis.

Our approach differs from common bottom-up approaches that are driven by data analysis and subsequent extrapolations of patterns. Based on a top-down approach, Identity Analytics at HP Labs takes into account strategic aspects of relevance to decision makers (business processes, IT systems, people behaviours, costs, etc.) as well as the implications of dynamic threat environments. Models are developed and simulations carried out to make predictions, by exploring different assumptions, investment options and decision makers’ viewpoints.

Recent developments of our research activity include the exploration of IAM Economics and how a better understanding of strategic preferences of decision makers can help the decision making process.

The updated HPL Identity Analytics web page providing an overview of the project and recent publications can be found here.


--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Identity Analytics and Economics of IAM – Presentation at IFIP/IEEE BDIM 2010

Due to recent “volcanic activities”, I could not attend the 5th IFIP/IEEE International Workshop on Business-driven IT Management 2010 - BDIM 2010, Osaka, Japan.

However, I have been able to give a remote presentation of the topic discussed in my accepted paper:

“Marco Casassa Mont, Yolanta Beres, David Pym, Simon Shiu - Economics of Identity and Access Management: Providing Decision Support for Investments”

My full presentation (MS .ppt) is available here. An abstract of the paper (and presentation) follows:

“Identity and Access Management (IAM) is a key enabler of enterprise businesses: it supports automation, security enforcement and compliance. However, most enterprises struggle with their Identity and Access Management strategy. Discussions on IAM primarily focus at the IT operational level, rather than targeting strategic decision makers' issues, at the business level. Organisations are experiencing an increasing number of internal and external threats and risks: there is scarcity of resources and budget to address them all. Decision makers (e.g. CIOs, CISOs) need to prioritise their choices and motivate their requests for investments. This applies for investments in IAM vs. other possible security or business investments that could be made by the organisation. In this context, a range of possible IAM investment options has an effect on multiple strategic outcomes of interest, such as assurance, agility, security, compliance, productivity and empowerment. We have developed a repeatable approach and methodology to help organisations work through this complex problem space and determine an appropriate strategy, by providing them with decision support capabilities. The proposed approach, validated in collaboration with security and IAM experts, couples economic modeling (which explores decision makers' preferences between the different outcomes) with system modeling & simulations to predict the consequences (likely outcomes) associated with different investment choices and map them against decision makers' preferences, in order to identify the most suitable investment options. We illustrate how this methodology has been applied in an IAM case study, in a business-driven context with core enterprise services. This work is in progress. We discuss current results and next steps.”

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

On Serving in Program Committees of International Conferences

In the last few months I served as a member of various Program Committees of International conferences, including: IEEE Policy 2010, SECRYPT 2010 and MobiSec 2010.

I have also acted as a reviewer of Journal articles, including: Journal of Systems and Software (JSS), ACM Transactions on the Web (TWEB) and Identity in the Information Society (IDIS).

I would encourage people to get involved in these activities. They help me to have a broader and up-to-date view of what is happening in the IAM and security space –as well as networking with peers in these fields.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Thursday, March 11, 2010

New HP Labs Technical Report – Job Design: Providing Strategic Decision Support for Risk Analysis and Policy Definition

A new HP Labs Technical Report has been published called “Job Design: Providing Strategic decision Support for Risk Analysis and Policy Definition” (authors: Marco Casassa Mont, Adrian Baldwin, Simon Shiu, Paul Collins):

“Strategic decision makers need to organize their workforce and define policies on how to allocate roles and rights to individuals allowing them to work effectively for the organization, whilst minimizing security risks. Many organizations have a separation of duty matrix specifying certain toxic combinations of access rights that they generally understand present an extreme risk. These matrices do not always contain some of the less understood or smaller risks. The flip side of the rights allocation problem is the need for an organization to keep systems running under various pressures including reducing headcounts. This tension often leads to a practice of providing skilled individuals with wide access rights to many systems. We describe this tension as the Job Design Problem. That is how to manage the trade-offs between allocating roles allowing for flexibility and the possible security impacts. It is not just a matter of technical "role engineering", access right allocation and Identity & Access Management (IAM) provisioning processes. Decision makers need tools that help them understand how to give guidance and set policies associated with role allocations and mechanisms to enable a debate between various stakeholders within the business, IT and Audit concerning the appropriate level of tradeoff and acceptable risk. In this paper, we aim at making progress in this field by presenting an approach and methodology to provide strategic decision support capabilities for the definition and assessment of policies in the context of Job Design. We focus on a problem provided by an IT department within a large organization, where employees (primarily IT admins and IT support staff) operate on sensitive and critical business systems and services. In this context, security risks are a major concern and need to be fully understood. Depending on the motivations and skills of the workforce, accidental or deliberate misuses of access rights and capabilities might take place and have huge economical and reputational consequences for the organizations. The decision makers (e.g. CIOs, CISOs) need to understand the implications and trade-offs of making job design decisions as wells as investing in additional/complementary controls, such as monitoring/auditing systems, IAM solutions, education or vetting/clearance programs. We describe a decision support solution based on modeling and simulation, to provide this kind of policy-decision support. This is work in progress. We present our current results and next steps.”

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

The First EnCoRe Technical Architecture for the Management of Consent and Revocation is Available Online

The first EnCoRe Technical Architecture for the explicit management of consent and revocation on personal data has been published and is available online:

“This document is a formal deliverable of the EnCoRe project. It contains the definition of the EnCoRe Technical Architecture for the first realized Case Study: an Enhanced Employee Data Scenario. It also describes that scenario – specifically the use, by employees of an organisation, of a Web2.0-style service for work-related and personal purposes – and its related requirements regarding consent management. These requirements were gathered and defined by legal and social science research within the EnCoRe project, and were influenced by its concept formalisation research.
The scope of the EnCoRe Technical Architecture for this first Case Study encompasses all the technical functions required for the management (including capture and revocation) and enforcement of individuals’ consents that are pertinent to the Case Study‟s scenario. The technical architecture is the block-level design of the necessary technical system, at the level of functional blocks (i.e., software and service components) and the data flows between them and to/from humans, other technical systems, compliance and other business processes and regulatory environments. Its goal is to provide the basis for an EnCoRe reference implementation that validates the approach and the technology. To that end this document’s approach is to start with contextual information and overviews, and incrementally refine the level of detail. Most of this detail is contained within Appendices.”

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

HP Labs 2009 Annual Report

The HP Labs 2009 Annual Report is now available online:

“In fiscal year 2009 -- from November 2008 through October 2009 -- HP Labs has focused its research agenda on fewer, larger projects that have the potential to change the future of the industry and shape the future of HP.
The HP Labs 2009 Annual Report highlights our research themes, significant inventions, open innovation activities and, most importantly, our research team.
Print copies of the report and its Appendix, which lists the year's publications, may be ordered through MagCloud.com, a new print-on-demand service created in HP Labs. To order copies, click here. “

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Friday, February 12, 2010

The Economics of IAM: On the need to move the focus of IAM from the Operational Level to the Strategic Level

I noticed that most of the discussions on IAM are really focused on the operational and functional aspects. As eventually decision makers (with a budget) need to make investment decisions in this space, the usual arguments about ROIs and business-level cost/benefit analysis are made by starting from this perspective.

But, is this really what CIOs/CISOs and related strategic decisions makers want to hear? After been exposed to various interactions with people covering these roles, I believe this is not really the type of message they are looking for.

In these days, strategic decision makers (that have a budget and make investment decisions …) need to balance a variety of aspects and constraints derived from the business, legislation, governance, IT, security, etc. They need to cope with various tension points and mediate different viewpoints within the organisation; as a consequence they need to explore the various trade-offs and identify the most suitable investment choices consistently with their ever shrinking budgets.

So, arguments made in the context of IAM should move away from a pure technological/IT viewpoint (that is anyway still very important …) to encompass an holistic view that takes into account the complexity of the business, legislative and IT world they operate on a daily basis.

I believe that the economics of IAM, in a wider context of the economics of security, is a discipline and area that really need to be explored.

I personally believe this is a fascinating area where various contributions can be made. The HP Labs work on Identity Analytics, Economics of IAM and Security Analytics is really meant to make progress in this direction.

I am currently carrying on various case studies with HP customers. They are extremely valuable to refine ideas and build decision strategic support solutions. I am very keen in getting any additional input/viewpoints and (unusual) case studies to make further progress in this space.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

HPL Technical Reports – Economics of Identity and Access Management: Providing Decision Support for Investments

I recently published (jointly with a few HPL colleagues) two HPL Technical Reports on the topic of “Economics of Identity and Access Management (IAM)”: HPL-TR-11 (executive summary) and HPL-TR-12 (detailed description of the case study)

These two documents discuss a case study aiming at integrating economics to security analytics methodologies, to provide strategic decision support in the IAM space:

“Identity and Access Management (IAM) is a key enabler of enterprise businesses: it supports automation, security enforcement and compliance. However, most enterprises struggle with their Identity and Access Management strategy. Discussions on IAM primarily focus at the IT operational level, rather than targeting strategic decision makers' issues, at the business level. Organisations are experiencing an increasing number of internal and external threats and risks: there is scarcity of resources and budget to address them all. Decision makers (e.g. CIOs, CISOs) need to prioritise their choices and motivate their requests for investments. This applies for investments in IAM vs. other possible security or business investments that could be made by the organisation. In this context, a range of possible IAM investment options has an effect on multiple strategic outcomes of interest, such as assurance, agility, security, compliance, productivity and empowerment. We have developed a repeatable approach and methodology to help organizations work through this complex problem space and determine an appropriate strategy, by providing them with decision support capabilities. The proposed approach, validated in collaboration with security and IAM experts, couples economic modeling (which explores decision makers' preferences between the different outcomes) with system modeling & simulations to predict the consequences (likely outcomes) associated with different investment choices and map them against decision makers' preferences, in order to identify the most suitable investment options. We illustrate how this methodology has been applied in an IAM case study, in a business-driven context with core enterprise services. This work is in progress. We discuss current results and next steps.”

A related paper discussing this work has recently been accepted at the 5th IEEE/IFIP Business Driven IT Management Workshop, BDIM 2010.

In addition to current engagements with HP customers, I am also looking for additional (interesting/unusual) case studies involving IAM aspects where to further refine this approach.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

Friday, January 22, 2010

Looking for Case Studies and Documents about the Impact of Job Design on Enterprise Security Risks

I am looking for case studies, documents and statistics analysing the impact of job design choices on enterprise (security) risks.

Job design, in a nutshell, involves defining employee roles and related tasks associated for employees in an organisation.

Intuitively, job design decisions have an impact on the productivity of employees, number of accidental & deliberate incidents, exposure to security risks (e.g. by dealing/not dealing with separation of duties and/or empowering too much certain people/roles).

There are interesting studies tacking this issue from an economics perspective, such as the paper on “Limited Intertemporal Commitment and Job Design” (even if it is a little bit too abstract).

So far I have found very little in terms of studies and documents that scientifically analyse how changes in job design affect security risks in an organisation. Any link and reference would really be welcome.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

TSB EnCoRe Project – Sixth Quarter Summary and other News

The Sixth Quarter Summary of the TSB EnCoRe Project (Ensuring Consent and Revocation - http://www.encore-project.info/) has been released: http://www.encore-project.info/press_archive/Q6%20summary.pdf

The EnCoRe website has also extended to provide the latest news and EnCoRe tidbits, related to aspects of privacy, consent and revocation of preferences: http://www.encore-project.info/news.html#story1

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---

CfP MobiSec 2010 – Submission deadline: 8 February 2010

The CfP of the 2nd International ICST Conference on Security and Privacy in Moblie Information and Communication Systems – MobiSec 2010 is now available online: http://www.mobisec.org/

Please consider submitting a paper. The deadline is 08 February 2010.

--- Posted by Marco Casassa Mont (here and here) ---

--- NOTE: use this mirror blog if you prefer posting on an external blog site ---

--- NOTE: my original HP blog can be found here ---