{"id":22309,"date":"2013-01-31T21:21:26","date_gmt":"2013-02-01T02:21:26","guid":{"rendered":"http:\/\/rbach.net\/blog\/index.php\/"},"modified":"2022-09-15T12:09:24","modified_gmt":"2022-09-15T16:09:24","slug":"are-human-firewalls-the-enterprise-info-sec-of-the-future","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/are-human-firewalls-the-enterprise-info-sec-of-the-future\/","title":{"rendered":"Are Users the Future of CyberSecurity?"},"content":{"rendered":"<p><a href=\"http:\/\/www.dailyblogtips.com\/10-crazy-online-ideas-that-actually-worked\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-108647 size-medium\" title=\"Are Users the Future of CyberSecurity?\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/kids_suprised.jpg?resize=150%2C100&#038;ssl=1\" alt=\"Are Users the Future of CyberSecurity?\" width=\"150\" height=\"100\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/kids_suprised.jpg?resize=150%2C100&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/kids_suprised.jpg?resize=75%2C50&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/kids_suprised.jpg?w=425&amp;ssl=1 425w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a>Gartner is shopping the idea that the people using IT systems and corporate data are perhaps the best ones to guard them. They are calling the People Centric Security (PCS). According to a <a title=\"ZDNet\" href=\"http:\/\/www.zdnet.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>ZDNet<\/em><\/a> <a title=\"Are human firewalls the enterprise info. sec of the future?\" href=\"https:\/\/web.archive.org\/web\/20140403233309\/http:\/\/www.zdnet.com\/are-human-firewalls-the-enterprise-info-sec-of-the-future-7000008497\/\" target=\"_blank\" rel=\"noopener noreferrer\">article<\/a>, People Centric Security loosens IT controls and relies on end-users to assume responsibilities for protecting IT systems and data.<\/p>\n<p><a href=\"https:\/\/www.gartner.com\/technology\/home.jsp\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-108650\" title=\"Gartner logo\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/gartner_logo-1.png?resize=121%2C28&#038;ssl=1\" alt=\"Gartner logo\" width=\"121\" height=\"28\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/gartner_logo-1.png?resize=150%2C35&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/gartner_logo-1.png?resize=75%2C17&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/gartner_logo-1.png?resize=768%2C178&amp;ssl=1 768w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/gartner_logo-1.png?resize=1024%2C237&amp;ssl=1 1024w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/gartner_logo-1.png?w=1166&amp;ssl=1 1166w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/gartner_logo-1.png?w=960&amp;ssl=1 960w\" sizes=\"auto, (max-width: 121px) 100vw, 121px\" \/><\/a><a title=\"Tom Scholtz\" href=\"https:\/\/www.gartner.com\/AnalystBiography?authorId=26004\" target=\"_blank\" rel=\"noopener noreferrer\">Tom Scholtz<\/a> at\u00a0<a title=\"Gartner\" href=\"https:\/\/www.gartner.com\/technology\/home.jsp\" target=\"_blank\" rel=\"noopener noreferrer\">Gartner<\/a> (<a title=\"NYSE : IT\" href=\"https:\/\/www.nyse.com\/quote\/XNYS:IT\" target=\"_blank\" rel=\"noopener noreferrer\">IT<\/a>) presented the idea at the recent <a title=\"Gartner Identity and Access Management conference\" href=\"https:\/\/www.gartner.com\/technology\/summits\/emea\/identity-access\/\" target=\"_blank\" rel=\"noopener noreferrer\">Gartner Identity and Access Management conference<\/a>. They explained it this way, empower users with responsibility for systems and data important to their work, sprinkle in consequences for breaching that responsibility, and users will do the right things to secure their environment.<\/p>\n<p>Gartner argues that the convergence of social, mobile, cloud and big data are eroding corporate boundaries and controls in many areas long thought to be state-of-the-art defenses. &#8220;<em>The current approach in developing policies and controls doesn&#8217;t scale to current realities<\/em>,&#8221; Mr. Schotlz said.<\/p>\n<p><a href=\"http:\/\/www.softaculous.com\/softaculous\/tour\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-108652\" title=\"users will do the right thing\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/secure.gif?resize=90%2C90&#038;ssl=1\" alt=\"users will do the right thing\" width=\"90\" height=\"90\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/secure.gif?resize=150%2C150&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/secure.gif?resize=75%2C75&amp;ssl=1 75w\" sizes=\"auto, (max-width: 90px) 100vw, 90px\" \/><\/a>Mr. Scholtz argues current information security policies and tools grind on productivity. He says the relationship between IT, the business, and workers has transformed and necessitates a change in regard to information security. &#8220;<em>In this brave new world, what we do as security people is viewed as negative. We are the people who slow things down.<\/em>&#8221;<\/p>\n<p>However, Gartner is not advocating losing all controls and policies only loosening them. Mr. Schotlz argues that taking away controls on data and replacing them with new user-based responsibilities, principles, and rights may just improve end-user focus and produce a more managed and secure environment.\u00a0 &#8220;<em>We cannot forget about the bad guys outside our enterprise; we do not get rid of all our defenses,<\/em>&#8221; he said.<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-108655\" title=\"We treat them like children\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/kids_school.jpg?resize=130%2C100&#038;ssl=1\" alt=\"We treat them like children\" width=\"130\" height=\"100\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/kids_school.jpg?resize=150%2C115&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/kids_school.jpg?resize=75%2C58&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/kids_school.jpg?w=600&amp;ssl=1 600w\" sizes=\"auto, (max-width: 130px) 100vw, 130px\" \/>&#8220;<em>One of the realities in the current approach to information security is we treat the 95% of people that want to do the right thing, we treat them like the bad people in order to protect against the bad things done by the 5% of people who have bad intentions,<\/em>&#8221; said Scholtz. &#8220;<em>We treat them like children, and if you treat people like children, they will act like children.<\/em>&#8221;<\/p>\n<p>The PCS goal is to implement a &#8220;trust space.&#8221; ZDNet explains that concepts surrounding &#8220;mutual trust&#8221; are not new, they have been used in traffic planning, Europe&#8217;s <a title=\"Schengen Agreement\" href=\"http:\/\/en.wikipedia.org\/wiki\/Schengen_Agreement\" target=\"_blank\" rel=\"noopener wikipedia noreferrer\">Schengen Agreement<\/a>, open source, and even cloud computing, where companies trust that large providers will protect their data as part and parcel of protecting their own valuable brands.<\/p>\n<p style=\"text-align: center;\"><a href=\"https:\/\/web.archive.org\/web\/20130724123552\/http:\/\/www.tripwire.com:80\/state-of-security\/it-security-data-protection\/killing-off-security-controls-to-reduce-risk\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-108657\" title=\"Gartners People Centric Security Principles\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PCS_Principles.png?resize=400%2C299&#038;ssl=1\" alt=\"Gartners People Centric Security Principles\" width=\"400\" height=\"299\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PCS_Principles.png?w=500&amp;ssl=1 500w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PCS_Principles.png?resize=75%2C56&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/PCS_Principles.png?resize=150%2C112&amp;ssl=1 150w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/a><\/p>\n<p>Such an environment &#8220;<em>makes it easier to monitor for exceptions, the good people are not trying to circumvent the controls,<\/em>&#8221; says Scholtz.<\/p>\n<p><a href=\"http:\/\/www.makeuseof.com\/tag\/read-choosing-online-backup-provider\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-108659\" title=\"Protect your data\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/harddrive_umbrella-e1570915302947-150x145.png?resize=103%2C100&#038;ssl=1\" alt=\"Protect your data\" width=\"103\" height=\"100\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/harddrive_umbrella-e1570915302947.png?resize=150%2C145&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/harddrive_umbrella-e1570915302947.png?resize=75%2C73&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/harddrive_umbrella-e1570915302947.png?w=163&amp;ssl=1 163w\" sizes=\"auto, (max-width: 103px) 100vw, 103px\" \/><\/a>Gartner&#8217;s Scholtz knows PCS is not for everyone and that implementation requires cultural and educational challenges. &#8220;<em>Maybe we could develop a situation where we have a set of underlying principles that underpin how people use data and how they access systems, and we link those with specific individual responsibilities,<\/em>&#8221; he said. &#8220;<em>Maybe we get a more collaborative and social environment.<\/em>&#8221;<\/p>\n<p>There are specific requirements if PCS is to prosper according to the article, the process has to be top-down and there have to be effective punishments for those that abuse their rights. Scholtz admits his concepts are in the embryonic stage, but that they will evolve in the coming months as he works with select enterprises. He noted that a European bank and a U.S.-based agricultural business are already adopting PCS concepts.<\/p>\n<p><strong><em>\u00a0rb-<\/em><\/strong><\/p>\n<p><em>How crazy do you think the PCS concept is? Can it work? Remember that just a couple of years ago, Gartner called BYOD, which I covered <a title=\"Bach Seat\" href=\"http:\/\/wp.me\/p2wgaW-rk\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a> in 2010.<\/em><\/p>\n<p><em>Are your users the future of cybersecurity?<\/em><\/p>\n<h6>Related articles<\/h6>\n<ul>\n<li><a href=\"https:\/\/web.archive.org\/web\/20130127202245\/http:\/\/www.networkworld.com\/news\/2013\/012513-employees-put-critical-infrastructure-security-266132.html?source=nww_rss\" target=\"_blank\" rel=\"noopener noreferrer\">Employees put critical infrastructure security at risk<\/a> (networkworld.com)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Gartner&#8217;s new idea is that users are the future of cybersecurity is called PCS that loosens IT controls and relies on end-users to protect IT systems and data.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3044,85,1822,847,1090,1834,4],"class_list":["post-22309","post","type-post","status-publish","format-standard","hentry","category-security","tag-3044","tag-gartner","tag-identity","tag-information-security","tag-information-technology","tag-management","tag-security"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/22309","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=22309"}],"version-history":[{"count":10,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/22309\/revisions"}],"predecessor-version":[{"id":130699,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/22309\/revisions\/130699"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=22309"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=22309"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=22309"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}