• No results found

7.5 Measuring shadow security

7.5.2 Sources of measurement

In order to identify available information that could be used to develop shadow security metrics, the researcher worked closely with Company B, identifying a number of potential sources of behavioural indicators. Information on a number of different shadow security topics was readily available through various organisational systems: network access logs, access control data, leavers’ process statistics, data on usage and availability of organisational systems for information storage and sharing, logs from clear desk checks, and statistics from IT support and employee feedback mechanisms. All these can be used to identify elements of the security implementation that encourage shadow security development and quantify mechanism and process-specific behaviours. The remainder of this section combines the improved understanding of employee behaviours that emerged from shadow security and trust development, together with information that is readily available in large organisations (or can be easily

collected), to (1) devise a set of security metrics that accurately capture shadow security presence, and (2) drive organisational security risk management and decision making to more effectively manage employee security behaviours.

7.5.2.1 Information handling, flow, sharing and storage

For large organisations like the ones investigated in this research, it is common for employees to engage with colleagues situated in various locations around the country, or even overseas. Combined with the increasing prevalence of home working, remote collaboration results in sensitive organisational information being present at various locations and on many devices, increasing the potential points of failure that could lead to security compromises. Both the organisations studied had implemented internal file storage and sharing systems that employees could remotely access, so in theory, provision for secure behaviour was in place. But problems in capacity, slowdown in accessing the organisational systems and lack of flexibility (no access provisions for various types of devices) led to employees using other ad hoc practices to share information. Employees resorted to using third-party cloud storage solutions for sharing sensitive information, due to a perceived lack of organisational support for effective file sharing, thus exposing the organisation to potential security risks. To detect such behaviours, which also suggest problems in the usability, availability and effectiveness of the systems in place, an organisation’s security management needs to observe the following:

1. Metrics generated by agents on managed organisational computers (e.g. Data Loss Prevention agents - DLP). This software can provide quantitative data on the volume of information shared through emails or sensitive information stored locally on corporate machines, allowing deducing data handling information. Security managers can track the number of attachments or pattern-matched text excerpts being sent, or information sent to out-of-company email addresses. As Smetters and Good (2009) identified, email mailing lists (and the dynamic groups generated in the “to” and “cc” lists of each message) are in fact the most commonly used access control lists encountered by users.

2. Check volume of traffic to third-party cloud storage servers (from inside the corporate network and company computers). This aims to identify the use of third-party storage to store and share corporate information. It may be difficult to distinguish with absolute certainty on which parts of cloud storage traffic relate to corporate information, as opposed to employees accessing personal files while carrying out personal tasks on corporate machines, but extensive use of cloud providers can indicate a need to investigate current use of organisational systems.

3. Check utilisation of internal file-sharing systems. Does it make sense if an employee has not accessed their personal file space in two or three working days? If network storage provisions are not used, can the organisation identify organisational information stored locally on employee computers? If excessive use of and reliance on local storage is identified, the organisation should investigate organisational storage and connectivity problems, also gauging employee awareness of the existence of organisational storage provisions, together with feedback on usage experience.

4. Monitoring external drive use (encrypted and unencrypted). The results also suggested that some backups and sharing of information within the organisation was done using non-approved unencrypted hard drives and USB sticks. Monitoring the use of those (e.g. through the use of

locally-installed software) can also allow the organisation to identify potential issues with organisational provisions. It can also gauge potential employee policy awareness of the need to use encrypted drives.

5. Clear desk logs. Company B has clear desk checks that occur every night, after employees have left the office. Those currently record the number of documents found on employee desks and potential classification markings on those. By comparing the number of documents found during clear desk checks before and after clear-desk related communication has gone out, an organisation can assess its effectiveness. In addition, close examination of some of the documents can reveal the understanding amongst employees of the organisational classification scheme. This can drive both improvements in communication and training, but also attempts to improve the comprehensiveness and context-specific applicability of organisational data classification approaches.

The metrics defined above can raise a number of questions that security management will need to address through a risk-driven intervention process: (1) if staff avoid using organisational systems, consider sending files to personal accounts via email easier, share information through third parties and unencrypted drives, and avoid classifying the information they use, what does this mean for the organisation? Is the nature of the information mishandled sensitive? If yes, is the organisation willing to accept potential risks? If no, security management should then (2) consider where organisational information storage/sharing systems create problems in employee workflow (e.g. lack of adequate storage, problems in setting up file sharing mechanisms, problematic connectivity). Where related risks may be considered less threatening, security management may choose to (3) consider providing employees with more flexible solutions (e.g. encrypting laptops to allow local storage of information and providing easy to use encrypted email communications), while for more severe risks it should (4) invest in improvements to reduce those disruptions. In addition, security management should (5) investigate whether organisational training and communication effectively communicates the risks of identified practices and the presence of organisational mechanisms to mitigate those. Applying the measurement process defined in the previous section (7.5.1) for information handling practices27, the process in Figure 17 emerges.

27 This process should be applied to all the other measurement areas outlined in the remainder of this section. For space reasons I only include this one example on information handling

Figure 17: Risk-driven intervention process for information handling systems

7.5.2.2 Access Control - Provisioning of Accounts

Quick deactivation of a leaver’s account was reported as being very important by the information security managers of both participating organisations (in one of the two companies there was a target of a maximum of 48-hours for deactivation). But examination of organisational account control systems and discussions with account managers, revealed that in many cases leaver’s accounts are left active for much longer, either in case future need for system access emerges, or because accounts administrators were not informed about an employee having left the organisation. An interesting example came from contractor accounts: many people whose contract expires, often re-join the organisation after short periods of time, so their accounts were left untouched “just in case they come back”. Another example was the use by new starters of their supervisor’s accounts until their own account could be set up, while the supervisor remained close-by during use as a security precaution. In order to identify these, and other account misuse cases, an organisation can measure the following:

1. Mean time for leaver account deactivation: Measure mean time it takes for an employee that has left the company to have their access revoked and compare this to targets defined in the organisation’s security policy. If this time is higher than what organisational security risk management considers acceptable, improvements are required in access revoking process; either

No

better connection between accounts management teams and HR, or delegation of access revoking to line managers.

2. Mean time for new account creations: Measurement of account creation time is also important; if new accounts take long to create, teams will use what they already have: managers and teams use generic accounts, or accounts that are left active after people leave the company, or even share their passwords to provide access to new joiners. The time between an account creation request and successful account creation, can indicate the perceived lead-in time required so that the creation process is completed by the day a new employee has joined the organisation. In cases where emergency access is required, organisations should consider creating centrally-managed short term access provisions.

3. Prolonged account inactivity: If an account is showing no or limited activity, it could either be unused (and should be a candidate for deletion), or the owner has simply chosen to act outside of the access control system, accessing files in some other way. In such cases, what barriers do organisational access-granting processes create? Is there a way to mitigate this effect? This metric can also indicate to security managers that a provisioned system is seeing inconsistent use and may also provide inconsistent coverage and security.

These three metrics can allow security management evaluating the effectiveness of current account management provisions, taking actions to mitigate risks from account sharing. Reduced account sharing will also allow for accountability in conditions where further investigation of employee actions and subsequent enforcement are required.

7.5.2.3 IT support - Response to helpdesk requests

Security management should also aim to assess the effectiveness of organisational provisions, aiming to support employees in their primary tasks. As the results have shown, ineffective organisational support provisions can lead to employees distancing themselves from organisational security. Support should be assessed using a number of indicators:

1. Resolved/Not resolved problems and Time to fulfil request. Security managers should be able to identify whether support provisions can meet employee needs and assess the impact of potentially problematic support functions on employee ability to comply with security. Support processes may be appropriate, and employees instructed as to when to contact a helpdesk in specific circumstances, but then the response time becomes critical. If call response times are slow, employees with momentary pressures (e.g., deadlines, one-off meetings with associated deliverables) will have to adapt there and then using their own understanding of IT and security expectations.

2. Number of incidents responded to and time taken to respond. In some cases employee requests may not be fulfillable. Despite that, it is still important for support functions to communicate back to employees the reason for refusal. The time taken for this response is equally important.

Slow responses that lead to undesired outcomes can distance employees from security, reducing their willingness to request formal support in the future, which acts as a key driver for shadow security development. In addition, details of “unusual” requests need to be recorded, to allow identification of potential lack of organisational provisions for some primary task needs.

Unusual requests can also aid identification of employee misconceptions and unrealistic expectation from security support that can then be targeted through communication and training.

The above metrics can be useful for an organisation to assess the effectiveness of central security support provisions. Target performance values (e.g. time to respond, number of issues resolved etc.) may differ across organisations, even across organisational divisions, due to varying security risk appetite, so the above metrics need to be adapted to the specifics of the target environments. In addition, when support performs outside desired limits, helpdesk staffing and staff training may also need to be revisited.

7.5.2.4 Employee feedback and reports

The results from the interview and the survey analyses also showed that employees are willing to report security mechanisms that cause problems in primary task completion. Despite that, in a number of cases they believed the organisation did not respond appropriately to their reports. Security management needs to treat employee willingness to report as an opportunity to identify elements of security implementation that currently fail to serve the primary task purpose. In order to achieve this, employee reports should be:

1. Grouped based on related security implementation elements, combined with numerical metrics for each different element (e.g. remote access problems, password reset requests). Interventions should then be prioritised to address high primary task impact problems first.

2. Logged, in order to create an “end-to-end” story. Employees should be informed about the number of new issues security management identified and resolved using their help, stressing the importance of their participation to deliver effective security. The effectiveness of such an approach can be measured by logging employee reports and calculating the percentage of those where improvements were delivered and feedback was provided, with security management aiming to address as many of the reported problems as possible.

Successful implementation of the above can increase employee participation in security management.

The emerging participatory security environment can allow security management to create (or modify) solutions seamlessly integrated with employee primary tasks, thus reducing non-compliance and shadow security development. In addition, communication of the influence on security management of employee feedback and reports, can increase employees’ perceived contribution in protecting the organisation, improving their motivation for secure behaviour and reporting of security problems, reducing their reliance on shadow security practices.

7.5.2.5 Password behaviour

Employees having to deal with friction-inducing password policies and mechanisms, often resort to self-devised password management strategies, using their own risk awareness and the presence of inter-employee trust to reduce emerging primary task impact. In the interview analysis a number of practices were identified relating to password use: despite awareness of policy clauses on password selection, with writing down and sharing of those also not permitted, employees choose simple passwords to cope with frequent changes, write those down in password protected documents or notebooks they carry with them all the time, or share those with colleagues to ensure responsibility delegation or urgent access to systems is provided when access management is perceived as problematic. Employees often also recognise the risks associated with their practices as well. As discussed in section 7.2, security hygiene should be

security management’s priority in order to reduce emerging insecure practices; in this case realised through easy to use password managers compatible with all organisational systems and quick and effective access management procedures. In order to measure the effect of attempted improvements, a number of sources of information can be used (in addition to the adoption of password manager discussed in section 7.5.2.2):

1. Feedback and reports on password manager adoption. Measure employee report of problems with password management software. Line managers should also be probed to discuss the experience of their staff with the software at group meetings and communicate it back to security management. Problems with password manager should be addressed to avoid creating the need for employees to resort to other practices.

2. Abnormal access patterns. Employee sharing of passwords can be detected through the presence of abnormal access patterns from employee accounts. Those can be both geographic and machine-based mismatches, between subsequent log-in sessions or physical access control and attempts to access organisational systems. High frequency of abnormal access patterns indicates a need to examine the effectiveness and response times of organisational access granting processes (also discussed in section 7.5.2.3).

3. Password reset statistics. The number of password resets should also be measured (both through logs of calls to the security helpdesk and automatic reset mechanisms). High number of password resets can indicate excessive employee reliance on those, due to either forgetting their passwords, or resetting those after sharing with their colleagues to eliminate potential risks.

Frequent password resets can signal the need to increase timeframes for password expiry, again depending on organisational risk appetite, even considering providing one-time access tokens for infrequently used systems.

When security management implements changes in security mechanisms or processes driven by the above metrics, security communication should aim to draw employee attention on those, with line managers also communicating the potential benefits to employees.

7.5.2.6 Screen lock monitoring

Employees often do not lock their computer screens when they leave their computers unattended, despite their awareness of the need to do so. The main driver for this behaviour is the existence of inter-employee trust, with the belief that their colleagues can be trusted to behave securely acting as a risk mitigating factor by itself; consequently it reduces their perceived need for screen locking practices. For some organisations this may be acceptable, for example if the number of external people present in a specific environment is minimal, or when certain functions deal with non-critical data. In other cases security management may decide unlocked screens are risky and should be eliminated. In order to measure and influence such behaviour, organisations need to record the number of unlocked screens identified during regular checks, communicate the importance of screen lock policy clauses in mitigating security risks (through channels appropriate for each target organisational division), and eventually sanction violations. Follow-up measurements of unlocked screens can assess the effectiveness of the above approach. Contrary to other metrics presented in this section, the measurements required for screen lock behaviour monitoring cannot be easily collected from organisational systems or existing physical

processes, so investing some organisational resource for manual data gathering is required. But if security management believes that related risks justify the required time and effort for data collection, either for the whole organisation or for specific functions, cost-effective ways should be found (e.g.

security staff conducting random checks around organisational premises).

7.5.2.7 Actual adoption and use of organisational systems

The organisations examined implemented centrally managed systems to enable employee secure behaviour. Password managing tools were present in Company B for employees to store their passwords, while network storage was available in both companies to provide secure and backed up storage for organisational information. Shadow security practices emerged when those systems failed to meet employee productivity needs: (1) the password manager was incompatible with some systems, so employees had to find other ways to store their passwords, (2) network storage was limited, leading to local storage and ad-hoc backups, and (3) connectivity provisions were unreliable, leading to employees using self-procured approaches to transfer files. The above practices increase organisational security risks, but there is currently no mechanism in either of the two organisations to identify such practices and take appropriate risk-mitigating actions. Security management can identify potential disruption caused by such mechanisms by measuring:

1. Password manager adoption and usage statistics. Low adoption and usage of password manager can indicate that employees resort to other practices to manage the large number of organisational passwords they have (e.g. writing those down in documents).

2. Utilisation of network storage. Lack of usage of organisational storage provisions also indicates that employees resort to other practices (e.g. storing information locally and backing up to own drives).

In both the above cases, lack of use of organisational provisions should be seen as a need to examine the

In both the above cases, lack of use of organisational provisions should be seen as a need to examine the