Sun Tzu and The Art of Information Security

June 15, 2009 by ADMIN
Share |

By Steven Fox, Founder of SecureLexicon

This is the first installment of a weekly series exploring the Sun Tzu paradigm. I expect that some of you asked this question after reading the teaser headline.

While not the only treatise on military strategy, it does offer relevant insights that can be applied to our field. This week we will discuss the concepts of invincibility and vulnerability.

“Invincibility is in oneself, vulnerability is in the opponent” - Sun Tzu

Dictionary.com defines invincibility as being “incapable of being conquered, defeated, or subdued.” In the context of The Art of War, this is accomplished through self-defense.

Individual self-defense requires awareness of one’s tactical and strategic strengths and vulnerabilities.

Once this awareness is developed, one projects the image that reduces the risks created by potential opponents. While different in scope, this model is applicable to a corporation.

Dictionary.com defines vulnerability as being “capable of or susceptible to being wounded or hurt, as by a weapon.” Interestingly, this is viewed as being a function of the opponent.

This perspective seems inaccurate until you consider that vulnerabilities are discovered when a system is viewed from the perspective of an attacker. It is difficult to see the vulnerabilities in a process or system through the eyes of a user.

So how do I apply this to my environment?

In practice, it is unrealistic to build an invincible security plan for your organization.  However, there are things that can increase the attack costs for potential attackers:

  1. Give your employees a stake in the business. On 3/15 I will post a discuss on business-case centered security awareness training.  Your team must understand the value of security to the success of the business and know they are enabled to act to ensure that success.
  2. Understand the core competencies of the business and how your IT infrastructure supports them. This will allow you to connect securty investment to business goals.  Learn to view security risk from a business risk perspective.
  3. View the organization from an attacker’s perspective. Now that you understand the value of your assets, put yourself in the shoes of someone who wants to control or disrupt those assets.  This will allow you to identify process and IT vulnerabilities that could be exploited.
  4. Finally, encourage a movement towards tactical and strategic agility. The threats that face your organization are evolving. These threats may take the form of physical, cyber, or competitive threats that don’t currently exist.  You must be ready to identify and prepare for those threats.

In the next installment I will discuss how invincibility and vulnerability apply in the context of cyber warfare.

According to Sun Tzu, victory can not be manufactured, it can only be discerned.

Steven is an independent information security consultant. He holds a Masters in Business Information Technology from Walsh College, an NSA recognized Center of Excellence. He serves on the board of the Detroit ISSA chapter and is a columnist for the ISSA Journal. He is also the founder of SecureLexicon , a security advisory firm addressing the unique security concerns of nonprofit organizations.

He can be contacted at sfox@securelexicon.com
Follow him on Twitter -
@SecureLexicon
Join Steven’s LinkedIn Network

*   *   *

Stay Informed With ISR News Feeds and Email Alerts Here:

These icons link to social bookmarking sites where readers can share and discover new web pages.
  • TwitThis
  • LinkedIn
  • Google Bookmarks
  • Digg
  • StumbleUpon
  • YahooBuzz
  • del.icio.us
  • Wikio
  • Propeller
  • Facebook
  • MySpace
Share |


Filed under: Breach, D&O Liability, FEATURE ARTICLE, Financial, Government, Insider Threat, PCI, Sarbanes-Oxley, Steven Fox, Uncategorized, national security, privacy 

Comments

One Comment on Sun Tzu and The Art of Information Security

  1. Ben on Tue, 16th Jun 2009 7:08 pm
  2. This is a huge idea. What is war but only the lack of security… If everyone looked to the past for wisdom we would be much better off, don’t you think? Have you heard of the Cyber Tao… This reminded me of that. I’m lookin forward to reading more…

    Ben

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!