Saturday, May 27, 2006

Security in Software applications

On Alert ..
Software applications developed are nowadays exposed to multitude of attacks. Try to match few of the attack strategies with their modus operandi.



Also read the article http://www.securitydocs.com/library/3314
Interested to know how Information security Management practices had its presence in 'The Ramayana".Read the post.http://osbalaji.blogspot.com/2005/10/relax.html

Labels: ,

Sunday, December 25, 2005

Just a Charla ..

‘Hi Tarun, you look very energetic today ?’

“Yes Linda , pretty much I just had a contract signed off for Process consulting for one of the IT services major”
‘That’s great news.. I presume in the present wave of offshoring
and outsourcing ,process consciousness has shot up a lot among organizations


Image :Darren Hester , http:://openphoto.net
“Very true. Now business demands it . Quality systems, processes and certifications are no more differentiators as they have become a necessity for survival in this hyper competitive world”
‘Ya Tarun…..By the way did you get a chance to look into the new ISO 27001:2005 standard ?How different it is from BS7799-2:2002 ?
“Not much . The key changes are
- 10 domains of BS7799 has been reshuffled into 11 domains with controls related to security incidents clubbed into a new ‘Information Security Incident Management’ domain
- Reallocation of few controls into more appropriate domains , to bring in more clarity
- New controls have been added and few sparsely used controls like Duress alarm, node authentication etc. have been removed
- The Clauses requirements are now more synchronized to ISO 9001:2000 , with rearrangement of Internal ISMS audits as a separate section
- Metrics is now a necessity even for ISMS
‘ Ok..That doesn’t seem to be much of change ‘
“ Sure..for companies already holding BS7799 certification it’s just a little extra effort to migrate to ISO 27001:2005 “
‘ Hope will all these standards bring back ROI in either tangible or intangible way …...
Ok Tarun , need to catch the 6o’clock train .So let me make a move ..’
“ Oh…fine ..its nearly time …trains service in our country work at six sigma levels .So better rush out to be on time ..”
‘Mm. Bye Tarun …’

Labels: ,

Sunday, October 16, 2005

Relax !!!

Prerequisite : Basic knowledge of Indian epic Ramayana

Security Management cues in Ramayana !

Not many had days passed since the grandiloquent inaugural ceremony, when Dasaratha , CEO of Ayodhya Inc unveiled the ambitious plans for its strategic startup, Ram Sita Interactive Technologies(RSIT ). When the CEO was sitting back and relaxing the prosperous growth of RSIT, things turned haywire . Political infighting had RSIT in troubled waters .

Due to pressure from various quarters, CEO was forced to demerge RSIT from its conglomerate .The key personnel in RSIT , Ram and Sita were asked to step out of Ayodhya Inc. They soon moved into a completely different business domain , full of trees and animals .They were bound by the separation agreement drafted by the Ayodha Inc, which stated the separation tenure to be 14 years . Lakshman, the trusted deputy of Ram, joined them in their pursuit .

Once they started of their operations , RSIT hardly realized the importance of Security Management system(SeMS) as they believed the individual prowess of Ram and Lakshman were good enough to tackle any attack from outsiders . However as time passed by , they were made to regret for their negligence over non implementation of a effective SeMS .

The Chief attacker , Ravan, of Lanka Pvt Ltd , had a clear goal in mind with his well crafted attack strategy . Ram , fell victim of identity theft , when Maricha masquerading his identity as a deer, grabbed Sita’s attention .As Ram set out to catch the deer , Ravan’s plan worked .Soon he had Lakshman parting away from Sita . When he moved in to abduct Sita , the effectiveness of Intrusion detection system , code named ‘Lakshman Rekha’ proved to be a shot in arm to Ravan .


But that did not deter Ravan , as he had his Plan B working for him. Being a virtuoso in social engineering attacks , he duped Sita , impersonating as a hermit . Once she had come out off the powerful line of defense protected by ‘Lakshman Rekha ‘Ravan had his task accomplished.
Jatayu came to Sita’s rescue but was overpowered by Ravan; however it had the tenacity and courage to report the security incident to Ram, Lakshman brothers.



It was disaster for RSIT, as the brand image of the company went for a toss. They were very badly in need of a Service provider who could take care of their SeMS and have them recover from the disaster.

Soon they found an effective Service provider in Vanara Sena (VS) headed by Sugriva. The mighty team had highly talented Hanuman in its line up. The two parties entered into an agreement -VS deciding to provide complete security solutions to RSIT and inturn wanted to utilize Ram’s skills to get rid of Vaali, business rivalry between Vaali and Sugriva being cited as reason.

Ram agreed to the ‘Terms and Conditions’ and the contract was signed. Sugriva donned the role of Security Officer and Hanuman was nominated as the Security Task force leader . A Security policy clearly spelling out the objectives of the alliance with RSIT was formulated . Other supporting policies were also put in place.

VS made a inventory of all its human assets and also entered into partnerships with smaller service providers in the VS community. They had their first taste of success when Hanuman traced the whereabouts of Sita in Lanka and made use of RXAP technique ( Ring Exchange Authentication protocol) for message authentication .

In due course, they also won over the support of Vibishan who provided them with critical information on Lanka Pvt.Ltd. Lakshman, however was opposed to the idea of Vibishan joining the RSIT-VS alliance; Ram was quick to react and pacified Lakshman, stating that, personnel screening was not required to verify the track record of Vibishan, as he felt Vibishan was a man of true conscience.. With their initial bout of success, VS-RSIT combine, drafted out their Disaster recovery plan.

The stage was set for the execution of Disaster recovery with all the critical resources drawn into fight the mighty force of the Lanka Pvt Ltd. The meticulous planning of the RSIT- VS combine brought them success and soon they had recovered from the awesome disaster .RSIT rolled back continuity in business to complete the 14 years tenure.

With RSIT, complying with its regulatory requirements of 14 years isolation from Ayodhya Inc., the time was ripe to merge the RSIT with its parent company. Everyone unanimously accepted the candidature of Ram for the post of CEO of Ayodhya Inc.
VS bagged the contract for maintaining the SeMS and Hanuman was dedicated as a full time resource to RSIT .

Ayodhya Inc was soon back into its profit making days, with the Confidentiality, Integrity and Availability of the organizational assets, protected by an effective security management system.

Labels: ,

Wednesday, October 12, 2005

Information Security

Read article on 'Security in Software applications' published in http://www.securitydocs.com/library/3314

Labels: ,