3 ms·
That exists, and it's already part of ISO: https://en.wikipedia.org/wiki/ISO/IEC_27001 https://en.wikipedia.org/wiki/ISO/IEC_27001 It's toothless, though. Due
by txcwpalpha 6y ago
That exists, and it's already part of ISO: https://en.wikipedia.org/wiki/ISO/IEC_27001 https://en.wikipedia.org/wiki/ISO/IEC_27001
It's toothless, though. Due to the nature of security moving so quickly, any certification or audit standard that actually prescribes specific security controls is inherently going to take so long to get approved by the standards organization that by the time it gets approved, it's already outdated.
The "fix" that has been attempted for this is to try and write security standards that are high level (read: vague) so that they have more "shelf life", but the result of that is that nearly anyone can pass the audit/certification because the requirements are so vague. See: NIST CSF, ISO 27001, HIPAA...
- bawolff 6y agoThe problem here doesn't seem to be require a specific security control, so much as "have access control". Any access control. And test that it works.
- txcwpalpha 6y agoI've worked on a couple of these NIST or ISO 27001 assessments and I would bet that even this company would meet some standard of "have access control". The audit/certification often won't care that the access control you have is "the bucket allows public access", it's still an access control! For that matter, it's entirely possible they had security testing "controls" too. But again, the audit/certification probably won't even care that the security testing team is one guy who sometimes tests the app login every couple of weeks. "Oh, Jim tested to make sure that the app only allows 3 password attempts? Security Testing: Check!" Don't get me wrong, the ISO/NIST frameworks are absolutely a good thing. For a lot of my work, they've been my bible. They are fantastic guides to help companies who want to be more secure focus their efforts and understand how they measure up. But that's only for companies that really want to be more secure. For all of the companies out there that just want to check a checkbox or pass an audit, these frameworks are way way too easy to give a "false positive".
- t0mas88 6y agoThe thing that ISO helps with is not so much requiring "must have access control", but much more the fact that it requires having specific people responsible for security and having processes to monitor and continuously improve the security practices. It's often frowned upon by engineers, because it's much more about processes and management structure than anything technical. But I've been involved in a few organizations that went from "technically good but unmanaged" to ISO certified. And I'm quite sure all of them got more secure and did more in terms of continuous improvement after certification.