Showing posts with label Risk Quotient. Show all posts
Showing posts with label Risk Quotient. Show all posts

Monday, December 9, 2013

ERP Disaster Recovery

Today’s economy is no different than yesterdays.  There are plenty of pressures to keep current, catch up, and compete.  Add to that the lack of budget, compliance mandates and a false sense of security and you have all the ingredients that drive a disaster recovery situation into a financial meltdown. 

 


Many technology providers are changing their mantra from disaster recovery to business continuity.  The concept is good.  Do we want to recover or do we want to continue operating?  Failing to plan is planning to fail.

 

Many providers now have real, viable, and proven solutions for Microsoft Windows server technology.  What about solutions or applications that do not run on Windows?  They leave that up to your Enterprise Resource Planning (ERP) solution provider.  That may be the first bit of good news.  You ERP solution provider knows your system and has experience in recovery procedures that should include both hardware and software.  If your ERP selection was done right they have taken into account your risk quotient and have addressed your specific needs.  You did have that conversation, right?

 

A Disaster Recovery (DR) plan starts with the plan and that is little good unless the plan actually exists and it is practiced and takes into account the changes that are occurring almost daily.  Does the DR plan take into account the actual business requirements?  Sure you have backups, do you have a hot site that you can restore to?  Does the plan include a reverse recovery plan?  How do you transition back to your production environment? 

 

Does the plan take into account that during most testing it is under a controlled circumstances and the testing is planned in advance when in reality a real disaster is rarely a planned event.  Getting key people in place, getting needed resources to the recovery point is not so easy when everyone in your region is doing the same thing at the same time.   The problem with disasters is that they often affect a region at a time and not necessarily a single organization.

 

How much time will it take to actually restore your entire system?  Or, is it systems?  What interdependencies exist?  The priority is typically the ERP system, but what about user accounts, email, communications?  What about user data, spread sheets and documents?  Do you keep both sites in sync so that in a disaster situation only current data needs to be refreshed?  Do you try to do all of this yourself or do you hire a firm that has experience and resources to manage the process when you need it most. 

 

You might need help.  Think of a management organization like a paramedic when you have an accident.  As you are lying there, at that point in time you really do not care how much experience the help has or how much it costs, you just do not want to die.  What would be different if your own professionally trained and experienced healthcare team followed you around?

 

At this point we do know that we need a plan and we have to test it regularly.  Take into account that in a real emergency it will not go as you hope, but your contingency plans will help accommodate the chaos.  The DR plan cannot just scratch the surface.  The plan also needs to address the switch back to the normal production environment. 

 

On of the hardest things to address is the constant evolution of your processing.  Your team must have up to date run books.  A simple program change or update to increase operational efficiency can have a dramatic impact on documentation.  It is inevitable that documentation can lag behind.  The question is what impact it will have when you are in a recovery situation.  One of the best things to be done is to cross train personnel and periodically let a person from a different department run through the instructions to ensure that in a recovery situation the most critical operations will continue.

 

Remember, a backup tape is not a disaster recovery solution.  How long does it take to backup?  How long will it take to restore?  Where and what will you restore to?  It is the same hardware?

 

Are cloud solutions an exception to disaster recovery?  The data resources may be safe, but can you get to it and with what client?  What bandwidth will be available when power and communication lines are down?  In the case of a regional weather impact your people will be concerned about their families and homes.  Who will make your business a priority over their family?

  

Remember, just because you trained does not mean you are qualified.  Practice, practice and yes of course, practice.  Test, test and yes test.  Test not just one system, but your entire infrastructure.  Test the restoration to production.  Plan, plan, and plan.  In a real disaster recovery situation, there will be situations that you cannot plan for, but you can have contingency plans. 

 

At Dolvin Consulting, we would like to know what your organization doing in the area of disaster recovery and business continuity.  We would like to know, your colleagues would like to know.  Share your ideas, best practices and checklists.  The one you help will be yourself.  As you share, you validate your efforts and get much needed feedback.  Contact us today to see how we can help with your plans.

 

Monday, October 21, 2013

Hot, Warm and Cold

Hot, Warm and Cold ERP (Enterprise Resource Planning) responses.

What constitutes the need for an emergency response?  A system failure can range from an inconvenience to a failed business.  Length of down time and the amount of data loss will typically factor heavily in the business impact.

 


In planning for disaster, roles must be defined in conjunction with the recovery procedures.  Who will be in charge, who will determine the impact, which person will be responsible for status updates?  Has the notification chain been created and tested?

 

The Hot zone is where the incident occurred.  In an online, virtual world this may not be your place of business.  Disasters can occur to cloud or hosted providers as well.  Up time and available time are two separate categories of availability.  In cases of natural disaster does the affected operation have a disaster recovery site geographically separated from business operations and the point of failure or disaster?  Have key personnel been identified and do they have access to the alternate site?

 

The Warm zone is a transitional area between Hot and Cold sites.  This may be a physical area or virtual area.  It may be the same location in cases where there is a system down, but no physical damage.  In cases of natural disaster is often a safe place near the disaster where status can be checked, yet far enough away to not be in harm’s way. 

 

The Cold zone is either a neutral area or the remote area where responsible people can delegate recovery tasks and notify users, customers, suppliers when necessary of status updates.  This is where press releases can be issued, personnel and resources coordinated and delegated.

 

Priorities varry depending on the extent of the disaster.  In cases of physical or natural disasters first priorities should be to the health and well being of personnel, then protection and recovery of resources.  In cases consisting of physical or operational equipment failures these steps are typically not necessary.  The next priorities are to assess the problem, determine its impact and to estimate recovery times for partial and full recovery.

 

First thoughts.  What is/was the hazard, disaster or affected resource?  Have the responsible people been notified?  What resources are at risk, what resources are likely to become at risk?  What is being done to contain the risk?  Who is coordinating the emergency response?  Are there others that need to be notified? 

 

Support functions.  What resources can be notified to provide support and recovery? Are emergency response personnel to be notified?  How and which communications methods can be used to notify employees, customers and suppliers?  Who and how are facility and equipment repair and remediation personnel notified?  What other resources can be contacted for immediate or future response?

 

Public relations.  Does the disaster or incident require a public relations media expertise to notify the affected parties and mitigate the loss of reputation?

 

There are many aspects to any critical interruption in service.  There are many ways to prepare.  The point to first consider is if your organization has acknowledged the possibility and has consulted with others to create a recovery and continuity plan. 

 

Businesses come in all shapes and sizes as due risks.

 

1.       What are you doing now to prepare? 

2.       What can you do now to prepare? 

3.       What will you do to prepare? 

 

We would like to hear your thoughts.   Please share your comments in this blog.  We would love to hear your feedback.

 

Friday, January 20, 2012

Zappos customer data accessed in security breach

Zappos is apparently one of the latest data breach victims.  Or, perhaps their customers are the latest victims.  Zappos feels that that the information was limited in scope, because the entire credit card number was not exposed (that is what they believe).  Many data thieves compile information from many sources to build complete profiles on people.  It just takes some patience and time to put together information that can be sold to the highest bidder.  It is a volume business and the 24 million customers are just bigger targets now.



You may read the CNET article by clicking this link:


There is no perfect solution, the mice get smarter and the traps more complex, but in time unless there is a proactive approach, “they” will get in and the damage will be done.

Here is the big message in the article and it applies to everyone, not just Zappos:

"We've spent over 12 years building our reputation, brand, and trust with our customers. It's painful to see us take so many steps back due to a single incident" Hsieh wrote in the letter.

An organization builds their reputation one satisfied customer at a time.  It takes years of effort to ensure your customers are happy.  It is evidenced by the referrals you get.  Then, in an instant your well earned reputation is gone. 

The data breach notification is the tip of the ice berg.  The piracy may have actually been going on for a time and the breach turns on the lights.  Other times it may be a single event.  As far as your customer cares, it puts them in jeopardy.  The only thing slightly in your favor is that people not directly affected are becoming numb to these news stories.  Never thinking it would happen to them, until it does and your company gets the blame and loss of business.

The bad publicity comes. The regulators come.  The forensic people come.  The remediation comes.  Then you try to rebuild your business. 

What comes after an event like this is what should have been in place in the first place.  A Written Information Security Program (WISP) plan.  You may think of a WISP plan in these simple terms.  It is a fire drill for a data breach.  You plan, practice, and protect hoping that you will never use what you have learned, but in the case when it is needed, it saves your life. 

A WISP plan is not a static document that sits on a shelf collecting dust.  That is what makes it different and what satisfies and creates a defensible position with the regulators.  A WISP plan involves a risk analysis of your organization and appropriate, best practice, measures are implemented.  It is different and scales for each organization.  Every company has some exposure, some more than others.

No one can promise you anything, not even us, but you should contact Dolvin Consulting to determine your Risk Quotient.  You cannot hide your head in the sand.  It is your responsibility to find out what you can to protect yourself and your customers, supplier, and employees.  Contact us today to see how we can help you mitigate the risks associated with the private information you are responsible for.



Friday, December 16, 2011

Study: Hackers and IT pros share personal information online

A recent study found that tech-savvy people disclose sensitive information to strangers they meet online, even though they should know better and found that Hackers apparently can be just as careless as their victims.




This study focuses on the phenomenon of disclosing private information to online friends who appear to be sharing your interests.  The sample consisted of 100 persons, half of them working in the IT security industry (chosen from a professional network), while the other half dwelt on 'the other side of the fence' - the hacker’s clique (selected from specialized forums for 'bad guys').

Two experimental profiles were created, using the same information (age, sex, interests), but different jobs - corresponding to those of the respondents. After being contacted, the participants were interviewed in order to determine what kind of information they would be willing to disclose to a person working in the same industry, but still unknown to them.

The results suggest that, no matter what side of the fence they are on, people will behave the same: as though the virtual environment creates a second life, entirely different from the real one - they are willing not only to accept unknown persons inside their group just based on a nice profile, but also to reveal sensitive information (about their company, themselves and other persons) after a short online conversation.  This applies to both categories of respondents even though they are aware of the risks such information disclosure would pose in real life.


Well I guess you just cannot trust anyone anymore.  Perhaps with all the social media forums available today we are trying to connect more in an impersonal world.  We should be connected more, we should have a greater sense of community.  What seems to be happening is that we are becoming more and more disconnected, like islands.

Was the appeal of the “Tests” were really people wanting to be connected?  Offer what people seem to want and need and you can get just about anything you want.  Kind of reminds me of some stereotypical sales people that care more for the bottom line than the consumer.

Have we learned anything (yet)?  Well yes, if it is the fact that your private information, yours or someone you are responsible for, is a valuable commodity for the industry that deals with stolen identities and funds.  Yes, that we can all be fooled.  Yes, that we need to be more aware.  Yes, that we need to recognize there is no perfect solution that will protect us from ourselves.

What can we do?  First, think.  Second, before you reply to an invitation or anything online or even in person, think.  Third, hire experts to help you think, because it is a big bad world out there and we all need help. 

Sometimes it is hard to think outside of the box when you are in the box.  That is where Dolvin Consulting and Cyber Security Auditors & Administrators (CSA2) work best.  We work with your team to analyze your risk quotient and build a working Written Information Security Program (WISP) plan that addresses the volatile nature of information security.  Contact us today to see how we can help you sleep better at night.


Friday, December 9, 2011

HIPAA Dangers Lurk on Facebook; Ongoing Policy Revisions Are Advised | AIS Health

HIPAA Dangers Lurk on Facebook; Ongoing Policy Revisions Are Advised AIS Health

This is a well written article.  It identifies an ongoing issue that all organizations, not just those in healthcare struggle with on a daily basis.  How do we empower our employees, yet maintain control over social media to protect the private information for which we are responsible?



I support the premise of policies for employees as many do not take the time to think beyond the moment to consider the consequences of their actions.  Many postings as the article points out are innocently placed.  Most people do not realize that enterprising people can take these separate pieces of information and place them together.  In the wrong hands that information is sold to the highest bidder.

The article points out: “There are people who have grown up having everything posted on Facebook, and having no privacy,” Drummond says. “They are posting more” with little thought to the potential impact.

The solution is not to single out any specific social media forum, but rather to invest in education for all workers.  Many simply are ignorant of the consequences.  At the organizational level, the education becomes part of a Written Information Security Program (WISP) plan.

Think of a WISP plan as a fire drill for a data breaches.  It is not a static, shelf sitting, and dust collecting binder.  A working WISP plan is reviewed annually or at any change in business or organizational process.  A WISP plan provides the foundation for a secure environment.  There is no one perfect solution.  Any plan that incorporates humans has the potential to break down.  In the event of a breach, there are well documented procedures that will mitigate damages and help create a defensible position for the regulators that are sure to be involved.

Dolvin Consulting works with industry experts Cyber Security Auditors and Administrators (CSA2) to help companies of all sizes manage the risk associated with private information.  Those companies are typically concerned with the threat of lawsuits related to the loss of personal information as well as the loss of their customer base due to the degradation of their reputation.

We cannot promise you that you will never have any problems, but we will do our best to understand your challenges and help you create a working WISP plan that matches your risk quotient.   Contact us today to see how we can help you manage your risk.


Friday, November 25, 2011

Sample Business Associate Contract for HIPAA Compliance

There is no single document, web page, or resource that can provide you with a bullet proof contract that protects both the organization and a subcontractor or business partner.  The government has provided a sample that may cover a percentage of issues that should be addressed.



Click here for the government sample.


This plan is by definition only a guideline, but it is a place to start thinking.  What is missing is the Written Information Security Program (WISP) Plan.  A WISP plan is tailored to the risk quotient of an organization.  It is certainly not a one size fits all solution.  A comprehensive plan will address business partner access as well as the other risks associated with the business operations. 

A WSIP plan is a process not an event.  It is a living, breathing, changing set of documents that evolves with the growth and changes in your business.   Like the sample business partner it should not be done with a do-it-yourself process or attitude.  The idea of a doctor treating themselves should come to mind.  

A WISP plan should incorporate at a minimum Technology, Insurance, Legal, and most importantly Human Resources.  No internal person is likely to have enough expertise in all of these areas.  You need expert outside and objective eyes looking at your business operations.  That is where a resource like Cyber Security Auditors and Administrators (CSA2) helps. 

CSA2 is a resource of resources.  CSA2 has access to leading industry experts.  Experts that will help you prepare, plan and execute a real working WISP plan.  Think of a WISP plan as a fire drill for data breaches.  It may be painful to have to think about these things, but it will be a significantly less stressful exercise than a post breach forensic analysis, government regulated, fine levied eternity.

If you value the relationship and trust build over the years you have been in business with your employees, suppliers and customers, then plan now.  It will take a long time to rebuild trust that can be lost in an instant.  An instant that was preventable.  

There is no perfect  mouse trap and the mice keep getting smarter, so even a great WISP plan cannot prevent all disasters, but a good plan will allow quick response and create a defensible position.  Everyone needs a plan that is tailored to your level of risk.  Hopefully you will contact Dolvin Consulting to see how we can mitigate your risks.  Call now, the time invested is well worth the peace of mind. 

Friday, November 18, 2011

HIPPA Audits and Compliance

Alan Heyman, Managing Director of Cyber Security Auditors & Administrators LLC (CSA2) was contacted and quoted recently, because of his expertise in working with companies to help them determine their risk quotient. 

Automating HIPAA Compliance Tracking and Audit Preparation

The article is a quick read, but reading between the lines may take a bit longer.  Alan is of course talking about a Written Information Security Program (WISP) plan and a WISP-Vault which is a highly secured storage facility to keep the plan safe. 




There has never been a perfect mouse trap and the mice keep getting smarter.  You cannot engineer a perfectly secure environment when humans are involved.  A WISP plan is more than a fancy binder filled with out-of-date information sitting on a shelf in someone’s office collecting dust.  It is a process, not an event.  A real WISP plan is a living breathing environment which is kept up to date with the changes in your business.

Think of a WISP plan as a fire drill for data breaches.  You plan, prepare, and practice over and over so that in the case there is a data breach everyone stays calm and you implement the right corrective action in a timely manner.

You cannot keep the auditors away, but you can be prepared.  A working WISP plan creates a defensible position that will protect you and your business.  The preventative medicine might taste a little bitter, but is a lot less painful than cure.  You know the saying Ben Franklin made famous: “An ounce of prevention is worth a pound of cure”.  Ben made this observation long before there were computers or HIPPA concerns.

Every business has its own risk assessment and the solution is based on potential exposure.  You would prepare your home if you knew a storm was coming, so why not do the same with your business.  Start now by contacting us to see how we can help. 

Dolvin Consulting works with organizations that are worried about lawsuits related to the theft of personal information and are concerned about the loss of customers related to a data breach.

Friday, November 11, 2011

HIPPA Enforcement Promotes Compliance

Leon Rodriguez, the new director of the Department of Health and Human Services' Office for Civil Rights, describes his HIPAA enforcement agenda.


"As I've learned as a prosecutor and then as a defense lawyer, enforcement promotes compliance," Rodriguez says in an interview with HealthcareInfoSecurity's Howard Anderson. "The fact that covered entities out there know that they are at risk for penalties is something that, in fact, in many cases will promote compliance."


The full article can be found by clicking here.  Some excerpts are below. 


ANDERSON: In recent months, as you just alluded to, the Office for Civil Rights has significantly ramped up its HIPAA enforcement efforts.  Under your leadership can we expect to see your office announce more resolution agreements in civil monetary penalties and other enforcement actions?
RODRIGUEZ: I think you can expect that; absolutely you can expect that.

ANDERSON: The Office for Civil Rights recently hired KPMG to launch a HIPAA audit program. What would you like to see that program achieve, and is it possible that any of those audits will result in sanctions or penalties?
RODRIGUEZ: This is the first time we're doing it, so the first thing ... is for us to 'go to school' on how best we will run an audit program. In part, this is what you might call a pilot. We're going to look at it and learn: How do we use an audit program? How does an audit program best advance our enforcement goals?

The second purpose, and this is really different than enforcement, is to promote compliance among the covered entities that are subject to the audit.  Our first objective is not to go out there and start banging [organizations] with penalties; it's really to take a good look at them, find out where their opportunities for improvement are and help them improve.  Having said that, I think we know that there are cases where we're going to find some significant vulnerabilities and weaknesses.  And in those cases, we may be pursuing significant corrective action.  And in some of those cases, we may be actually pursuing civil monetary penalties.  But that's really not the primary goal of the audit program.



Rodriguez’s goal is to audit and learn, but even then he acknowledges they will pursue significant corrective action.  You can interpret the interview in several ways and they may all be correct to some extent.  What I suggest you walk away with is that the casual compliance days are over.  If you are found at-fault for a data breach, you will be subject to fines and other penalties.

In a post breach situation, there is no moderator.  Your organization will be held accountable.  Your client base will lose confidence in your operations and unless you are the only one performing that service, your clients will go elsewhere.  The publicity of the lawsuits will ensure a degradation of reputation and client base.

The only real course of action is to address your Risk Quotient in a pre breach environment.  Your organization will have the luxury of being able to take the time to plan and prevent data loss.  Preparation is like a fire drill for data security.  Plan and practice in the hopes you never need to use what you know.  But, if you do, then you will know what to do and when and the result will be a defensible position for the regulators.

Dolvin Consulting works with Cyber Security Auditors & Administrators (CSA2) and your organization to prepare, plan and implement a Written Information Security Program (WISP) plan.  The WISP plan is your key to sleeping well at night.  Contact us today to start a conversation that will help you connect with resources that can help with your compliance challenges.


Friday, October 28, 2011

Encryption 101


For many people, the word "encryption" invokes images of spies, clandestine operations and World War II code breakers feverishly working to decipher enemy messages. Actually, encryption is a priceless security tool that any business can easily use to keep sensitive information confidential and safe from prying eyes.



This article from IT Security highlights some important information about encryption.  As the article title implies, this is a basic overview of what encryption is and how and why you might want to take advantage of this technology. 

What would be nice is a link to an Encryption 202 article.  The article would cover corporate compliance and policies.  When the information we work on contains private information, information containing names, addresses, email addresses, social security, or credit card information we expose ourselves and our companies to global risk.  When the computer or storage device contains proprietary information that would benefit a competitor, then you have potential losses that mount quickly. 

These loses can encompass government intervention, audits, lawsuits, fines and the degradation of your customer base.  When the mix includes these loses, then the stakes are much higher.  The first thing the regulators will look for is a Written Information Security Plan (WISP).  A WISP plan is security fire drill to prevent data loss and a checklist resource to be used in post breach situations.

A WISP plan ensures that your devices are protected by encryption in addition numerous other attributes, including human resources, legal, and insurance compliance.  We are not trying to make it hard for you to sleep, we just want you to follow the best practices in the industry.  Dolvin Consulting works with industry experts Cyber Security Auditors and Administrators (CSA2) to help you to determine your risk quotient and build and maintain your WISP plan to match your risk.  Contact us today to see how we can help you.

Wednesday, October 19, 2011

BISD notifies parents of 15,000 students of data breach

BISD notifies parents of 15,000 students of data breach - KFDM-TV Channel Six

No one can really be sure that this information was not retrieved and will not be used for illegal activities.  How well will the parents and children sleep now, knowing that their private information was vulnerable. 



What confidence and creditability has been lost, because someone "thought" only principals could access the information.  Fortunately the student who discovered the breach notified the right people in a timely manner. 

If this was a business, would you want to want to do business with them?  Would you keep doing business with them?  It takes a long time to rebuild the trust lost in a few minutes, because someone thought they had a secure system.

It will be interesting to see if government regulators will now fine the school.  Most businesses will not have much choice.  You have to wonder if they have a Written Information Security Plan (WISP)? 

A WISP plan is more than a set of documents that sit on a shelf and collect dust.  It is a comprehensive plan to ensure data breaches do not happen.  Nothing is perfect and breaches do occur.  The WISP plan defines how to recognize a breach and what to do when one is discovered.  These plans must be updated every year and at any fundamental change in business operations.

If you are wondering what a WISP plan is and if you should have one, then you should and you should contact us as soon as possible.  Typically any organization that keeps private information about employees, suppliers, or customers is required to have a WISP plan.  Private information is a name, social security number, address, credit card number, or any personally identifiable piece of information.  To complicate matters more, each state has its own definition of what needs to be reported and how soon along with how much they are going to fine you.

Dolvin Consulting partners with industry experts Cyber Security Auditors & Administrators (CSA2) to determine your risk quotient and help you plan, develop, implement and secure a working WISP plan.  Contact us today to see how we can help you meet your compliance needs.  We are here to help.