Showing posts with label Mentor. Show all posts
Showing posts with label Mentor. Show all posts

Friday, May 15, 2020

The Common Criteria Framework

Do you struggle with Validation? I mean, within yourself, not others? How do you uphold yourself to your own set of standards? Do you have standards? Maybe you are athletic and as such it is required that you run every morning for at least 6.5 Miles. This is your own standard – that you set – and you uphold yourself to, as an athletic professional. When you stick to this criteria, you are then validating yourself – and you probably feel GREAT when you go to bed at night, because you upheld your own vision and values, you went for your run, and you are being your best self. Like my last 500 articles – what does this have to do with Cybersecurity?

First things first, we need to revert to the evaluation requirement. Referring to my former opening statement, ‘How do you uphold yourself to your own set of standards?’ – For me personally, my self evaluation is based on my own criteria- having met or unmet my standards- i.e, did I run my 6.5 or not?  This is the basis for the International Framework known as the Common Criteria. The Common Criteria is a Standard for Computer Security Certification – which is globally recognized and was developed with the involvement of 6 different countries.

The CC offers whats considered an Assurance Evaluation, which measures the parts of a computer system that are pertinent to it’s security aspects. InfoSec Pros are familiar with terms such as the TCB (Trusted Computing Base), Reference Monitor, Kernel, and Access Control & Protection Mechanisms. There used to be different processes and techniques to evaluate and assign an assurance level to a system. However, The Common Criteria is as globally known as the Coronavirus.

So, since this framework enables the User to specify security requirements, and the Vendor to exemplify how those requirements are satisfied, not to mention independent labs can be involved which will help to verify said claims, The product in question will be assigned an Evaluation Assurance Level (EAL) prior to having been evaluated. There are seven levels of assurance involved with the Common Criteria Framework, EAL 1-7.

I figured my readers would be less interested in the EAL levels, so I will leave it up to you to examine them if you are interested. Instead, I thought we would take a look at a real time example. Take a look at this list of Common Criteria-Certified Products. Don't be surprised if you see your phone or computer on it =).

About the Author - Ashley Oliver


About the Author - Ashley Oliver is an experienced Cybersecurity Consultant, Engineer, Mentor and Teacher based in the Central New York area. Ashley has over 10 years of experience. Ashley is a SME in several areas of security including Network Security Engineering, Architecture, Policy, Standards, and Compliance. Ashley's rare and unique experience is based on her love for the Shell, and perfect design. Ashley has knowledge of NIST, and is very proficient in Cybersecurity, Network Security, Next-Gen Firewalls, Layered Security, DLP, Encryption, IPSec, and more, and she is always more than willing to share and to teach.

Saturday, May 9, 2020

When you don't know what ya got til' it's gone

Do you ever feel like your partner won’t really appreciate you until you’re gone? Do you have Beyonce’ fever? I know I did when Lemonade came out – and I’m blissfully single - =D. Anyway, grab yourself a glass of wine because I’m getting ready to share with you the importance of one of the 3 Tenets of Cybersecurity CIA Triad – Availability. Lol, so you’re probably like what does CIA have to do with BEYONCE? Nothing. Lemonade is about lack of respect and appreciation from her partner, and ‘If you do that sh*t again, you gone lose your Wife.” How does this relate to Cybersecurity? What happens when I Pen Test myself into your system, disable your ports, and deny you access to the system you built? This is the importance of Availability. 

First and foremost – who is responsible for ensuring that systems are on the up/up? That would be the Network Admin, not the Security Admin. You would be surprised how often we work together yet keep our duties separate. Separation of Duties prevents what? Collusion. Back to the former – (this is literally how I think, one, to the next, back to the initial, and it goes on, lol). So, your Network Administrator is responsible for guaranteeing high availability as well as monitoring network performance. That being said, I too have checked my system’s CPU, Memory, Sessions, etc. I am anal, and I’ll be damned if I am working an extensive troubleshoot and then I get kicked off on the verge of a breakthrough. 

“It’s Always the Firewall.” The Network Security team takes a lot of heat, lol. While it is not true that it is always the firewall, it is true that we are responsible for potentially decreasing the performance in network transmission, and processing power mainly because we got a lot going on. I mean, a single Next-Gen Firewall unit can do a lot more now than simply processing an access control list (ACL). They can filter on content, detect intrusions (IDS), prevent intrusions (IPS), detect anomalies, etc. So, I mean yeah we (an our equipment) are high-maintenance, but with good intentions. 

One of my recent articles was on the Importance of Backups. You can see it tie in here as we move on to the next topic related to Availability. Make sure you have a great engineer and/or administrator on your Security team who understands and implements effective redundant (HA) systems as well as backup systems. This way, if and when something happens (COVID-19 much?), the productivity of your users will not be significantly affected. You don’t know what ya got til’ it’s gone. Protect yourself and your system. Reach out if you have any further questions on whether or not your current system architecture is HA capable, how to ensure availability, how to ensure your employees are upholding the standards of Availability, etc.

If you are interested in further reading, and want to know How to Get a Job& Kickstart a Career in the Field of Cybersecurity, click here. Disclaimer – not click bait – nothing erks me more than click bate. Serious inquiries only. =)


Cyber Prospects - Don't overthink HA - if Shon Harris were here I bet she would be telling me the same thing, about everything. I overthink, and overanalyze enough as it is (I used to deploy redundant Cisco Switches in a single-layered architecture for an Aerospace Corporation, I really liked HSRP to ensure redundancy, thus availability ensues). See my Technical Blog for more in-depth discussion on technical, protocols, policy, architecture, topology, encryption methods, API, and more. 

About the Author - Ashley Oliver is an experienced Cybersecurity Consultant, Engineer, Mentor and Teacher based in the Central New York area. Ashley has over 10 years of experience. Ashley is a SME in several areas of security including Network Security Engineering, Architecture, Policy, Standards, and Compliance. Ashley's rare and unique experience is based on her love for the Shell, and perfect design. Ashley has knowledge of NIST, and is very proficient in Cybersecurity, Network Security, Next-Gen Firewalls, Layered Security, DLP, Encryption, IPSec, and more, and she is always more than willing to share and to teach. Contact Ashley