Online Exclusive Series Part 2: A Glimmer of Hope

Online Exclusive Series Part 2: A Glimmer of Hope

(Did you miss Part 1? Click here to catch up!)

All was not lost, as in stepped the International Information Systems Security Certification Consortium (ISC)² in 1988. “The Consortium” was formed among several professional organizations to create a global information security certification process for professionals and address the need for standardized curriculum for the burgeoning profession.

The goal was noble and the need certain; however, the execution might be considered less than particularly effective. In 1992, ISC² released the Common Book of Knowledge (CBK). The CBK established a common framework of information security terms and principles, which allowed information security professionals worldwide to discuss, debate, and resolve matters pertaining to the profession with a common understanding. The CBK exposes Information Security (InfoSec) professionals to a very broad landscape of InfoSec coverage and is an excellent resource. However, of the some thousand pages of content in the CBK I used for study, only two were devoted to Information Security Governance. In essence, we were still fixated on the nose-gear light, instead of business indicators.

Auditors — people InfoSec professionals know all too well — actually took a lead role in developing what is known as the Generally Accepted Accounting Principles (GAAP), a standard framework of guidelines for financial accounting. The need is almost too obvious for definition, but if GAAP did not exist, companies would not be able to provide accurate and consistent financial information to investors, creditors and stakeholders of a company.

Surely Information Security has a standard framework of Generally Accepted Information Security Principles — a GAISP if you will.  And of course, there is one. Or rather, there was one.  The Information Systems Security Association (ISSA) had a GAISP.  GAISP was the successor to the GASSP, the Generally Accepted System Security Principles.  The original GASSP project was formed in mid-1992 in response to Recommendation #1 of the report "Computers at Risk" (CAR), published by the United States of America's National Research Council in December of 1990.  The GAISP even had its own domain; both the framework and domain are now dead.

As near as I can tell, GAISP was dropped between 2004 and 2007.  I quote from the last version (emphasis added):

“Recognizing the hierarchic nature of principles, GAISP will be organized in three levels: The Pervasive Principles which target governance and describe the conceptual goals of information security; the Broad Functional Principles which target management and describe specific building blocks (what to do) that comprise the Pervasive Principles; and the Detailed Principles, which target the information security professional and include specific ‘how to’ guidance for implementation of optimal information security practices.”

InfoSec Governance…directing InfoSec Management…directing InfoSec Professionals’ actions:

“…the right target focus areas, and the right order of focus.  It’s as if someone lifted their head enough to recognize that the landing gear light might not be the only problem.  Unfortunately, something happened and all eyes were refocused back on the light, which was, in this case, is the “target information security professionals” and the descending glide slope is ‘target governance’ and ‘target management.’”

What We Need Here is a Good Framework

Michael Dell, founder of Dell Computers, was right when he said, “You don't have to be a genius or a visionary or even a college graduate to be successful. You just need a framework and a dream.”

Notice he didn’t say you need a cornucopia of frameworks, just a framework.

Frameworks are not perfect; they are living standards that get adjusted through growth and learning.  Nevertheless, having what I like to call a “littering of frameworks” is not helpful.  Some may see this as a great thing, because the professional can pick what fits best.  In some ways that is true, but Information Security should not be treated like a doughnut shop.

Why do I say this?

If you are in Information Security you have many choices, not only in how you will be defeated (and you will be — either by hackers, bad code, or management) but in the framework you elect to follow (if you actually pick a framework).  Some of my favorites are ISO/IEC 27002:2005, COBIT, COSO, Common Criteria, ITIL, FISMA, ISF, ISM, NIST SP800’s, PCIDSS, SABSA… just to name a few. You can imagine my joy when DHS teamed up with NIST to release yet another, the Cyber Security Framework. It stems from a couple of executive orders, which created the Critical Infrastructure Cyber Community (C3) Voluntary Program. There is a word in that title that should stick out to you as spelling impending doom. If you do not know which word, you should probably keep reading. If you do know the word, keep reading anyway…for the cathartic pleasure.

There is no framework I have read — from ISO27002 to Cobit to the Cyber Security Framework — for which I do not appreciate the amount of work invested or the completeness of vision. If you have never worked on a committee to develop one of these, you may find it hard to appreciate what a painful journey it can be, with a lot of emotional drain thrown in for good measure. However, as painful as putting a framework together can be, it pales in comparison with trying to implement one.

We are now getting very close to being able to take our eyes off the non-functioning landing gear light and take full appreciation of our glide path. Does anyone think we just do not have enough frameworks? Does anyone think the frameworks we have are pitifully unequal to the task? Maybe we need more certifications. I could list all of those but it would add another 200 pages. Maybe we just do not have enough schools offering Cyber Security curricula. Could it be the “compliancy based” versus “risk based” security paradigm?

About the Author

Martin Zinaich is the information security officer for the City of Tampa’s Technology and Innovation department. The insights in this article were shared at a Wisegate member event, where senior IT professionals discussed these pressing security issues.

Featured

  • Cloud Security Alliance Brings AI-Assisted Auditing to Cloud Computing

    The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today introduced an innovative addition to its suite of Security, Trust, Assurance and Risk (STAR) Registry assessments with the launch of Valid-AI-ted, an AI-powered, automated validation system. The new tool provides an automated quality check of assurance information of STAR Level 1 self-assessments using state-of-the-art LLM technology. Read Now

  • Report: Nearly 1 in 5 Healthcare Leaders Say Cyberattacks Have Impacted Patient Care

    Omega Systems, a provider of managed IT and security services, today released new research that reveals the growing impact of cybersecurity challenges on leading healthcare organizations and patient safety. According to the 2025 Healthcare IT Landscape Report, 19% of healthcare leaders say a cyberattack has already disrupted patient care, and more than half (52%) believe a fatal cyber-related incident is inevitable within the next five years. Read Now

  • AI Is Now the Leading Cybersecurity Concern for Security, IT Leaders

    Arctic Wolf recently published findings from its State of Cybersecurity: 2025 Trends Report, offering insights from a global survey of more than 1,200 senior IT and cybersecurity decision-makers across 15 countries. Conducted by Sapio Research, the report captures the realities, risks, and readiness strategies shaping the modern security landscape. Read Now

  • Analysis of AI Tools Shows 85 Percent Have Been Breached

    AI tools are becoming essential to modern work, but their fast, unmonitored adoption is creating a new kind of security risk. Recent surveys reveal a clear trend – employees are rapidly adopting consumer-facing AI tools without employer approval, IT oversight, or any clear security policies. According to Cybernews Business Digital Index, nearly 90% of analyzed AI tools have been exposed to data breaches, putting businesses at severe risk. Read Now

  • Software Vulnerabilities Surged 61 Percent in 2024, According to New Report

    Action1, a provider of autonomous endpoint management (AEM) solutions, today released its 2025 Software Vulnerability Ratings Report, revealing a 61% year-over-year surge in discovered software vulnerabilities and a 96% spike in exploited vulnerabilities throughout 2024, amid an increasingly aggressive threat landscape. Read Now

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.