Friday, February 15, 2019

Basic understanding on ITSM

ITSM

Information Technology Service Management

ITSM is a process where IT teams/ organization manage the end to end delivery of IT services to customers. This includes all the processes and activities to design, create, deliver, and support IT services. 

The ITSM process is aligned with an international standard i.e. ISO/IEC 20000 and it can also be aligned with ITIL best practices. It helps organization to achieve business goals and to deliver the IT services more efficiently and effectively. It helps in improving the services in a continuous way. 

ISO: International Organization for Standardization

IEC: International Electrotechnical Commission

In fact the ISO/IEC Organization develops and publishes the standards which are globally accredited and followed. For more information please refer to https://www.iso.org/about-us.html

So, in the ISO/IEC 20000-1:2011 is a service management system (SMS) standard.  It specifies requirements for the service provider to plan, establish, implement, operate, monitor, review, maintain and improve an SMS. The requirements include the design, transition, delivery and improvement of services to fulfill agreed service requirements between the organization and customer. Later the standard has been revised to 2018 version i.e. ISO/IEC 20000-1:2018. We will know what the change occurred in 2018.

For effective service management system (SMS), ISO/IEC 20000 is designed based on PDCA (Plan, Do, Check & Act) methodology.

Plan: The SMS needs a proper plan before implementing. It should be established by agreeing and documenting the SMS. Also it includes policies, objectives, plans, processes and procedures to fulfill all service requirement.

Do: Do is nothing but a clear implementation of those policy, process and procedures. Implementing and operating the SMS for design, transition, delivery and improvements of the services.

Check: Here, the SMS needs to be monitored, reviewed, measured to report the outcomes or results.

Act: Taking appropriate action on the results to continually improve performance of the SMS and Services.

Using or implementing a standard based process gives many benefits as;

  • A standard helps in reducing risks in organizations.
  • It enhances productivities, quality of delivering services.
  • Helps in continual service without any disruption.

Below are the ITSM Processes mentioned just on a brief, as we cannot keep all the standard information here because those are copyrighted materials. So, lets look in to the 2011 edition standard for an overall understanding. Later 2018 edition changes will be bring in to the notice. 

The entire Service Management System mentioned below for reference describes primary clauses and sub clauses

Clause 4: Service Management System General Requirements

  • Management Responsibility
  • Governance of processes operated by other parties
  • Documentation Management
  • Resource Management
  • Establish & Improve SMS

Clause 5: Design and Transition of New or Changed Services

  • Plan new or changed services
  • Design and development of new or changed services
  • Transition of new or changed services

Clause 6: Service Delivery Process

  • Service level management
  • Service reporting
  • Service continuity and availability management
  • Budgeting and Accounting for Services
  • Capacity management
  • Information Security Management

Clause 7: Relationship Process

  • Business relationship management
  • Supplier management

Clause 8: Resolution Process

  • Incident and service request management
  • Problem management

Clause 9: Control Process

  • Configuration management
  • Change Management
  • Release and deployment management

We can cover some important sub clauses in later post. Although all the clauses and sub clauses are important and keeps the organization compliance to standards.

If you have any further questions and suggestions please feel free to post it below.

-DR




 



Thursday, February 14, 2019

Basic understanding of ITIL

Information Technology Infrastructure Library (ITIL)

Information Technology Infrastructure Library (ITIL) is a framework of practice for IT Service Management or to provide better IT service delivery. It describes all the processes, procedures, records, checklists which can be implemented and applied by organizations. The structured approach of ITIL can help in managing risk in a business or organization. As well it strengthens customer relationship and keeping the customer at their satisfactory limit.

There are individual ITIL Certifications available globally to proof your understanding, gain credits and working skill on ITIL process. The range of certification comes such as ITIL Foundation, ITIL Intermediate, ITIL Expert and ITIL Master.

The ITIL Foundation Certificate in IT Service Management is designed to certify the candidate upon his/ her understandings on ITIL terminology, basic concepts, practices on service management, service lifecycle.

Before going to learn the basics about ITIL, let me take you to understand some important terms which are essential to know.

Process: A process is a structured set of activities designed to accomplish a defined objective. These Processes are measurable, that provide results to customers or stakeholders, are continual and iterative and are always originating from a particular event. 

Process Owner: Process Owner is someone who is responsible for the result of output of the process and they manage the process models. 

Function: Functions can make use of one or more processes, activities.  

Service: A Service is nothing but delivering some value to customer.

Demand: Need and use of service is known as demand.

Service provider: Someone who provides service to its customers. The service provider can provide service by hiring external third party.

Customer: Organization or individual who receives a service offerings.

Service Management: Service Management is a set of capacity to deliver the service to the customers.

Service Life Cycle: The ITIL is based on the Service life cycle which is to describe the processes of how services are to be initiated and maintained. 

Service Portfolio: A Service portfolio is something that describes all the services of the service provider in terms of business and value. 

Service catalogue: A part of service portfolio which includes the list of services, capacity and other offerings of the service provider that is visible to customer. It can be shown on website or can be documented (We know it as business leaflets). This Service Catalogue can be Business or Technical.

Service Level Agreement: Service Level Agreement or SLA is an agreement mutually agreed between service provider and customer having their scope, goal and objectives defined. 

Now come to the ITIL processes.

The ITIL process basically focuses on service lifecycle. The service lifecycle consists of five phases as mentioned below.

  • Service Strategy
  • Service Design
  • Service Transition
  • Service Operation
  • Continual Service improvement 

Now here have a look in to the phases of service lifecycle on little details for a clear understanding.

Service Strategy:

The primary objective of Service Strategy is to help service providers to develop the ability to think and act in a strategic manner or market driven approach. It is important to align business in to services. So planning for business capability is essential. Processes come under strategy are Financial Management, Service Portfolio Management, demand management, Business relationship management, Strategy management.

There are four “P”s that guide the service strategy effectively i.e. Perspective, Position, Plan and Pattern. 

Service Design:

During the service designing phase, a product or service is being developed including it’s architecture, processes, policy and documents, business requirements. The processes come under designing phase are such as Service Catalogue Management, Service Level Management, Capacity Management, Availability Management, Information security management, Supplier management and IT service continuity management.

There are four fundamental “P” s in Service Design such as people, products, processes.

Service Transition:

Then here comes service Transition phase, where the product or service goes planning or designing from scratch to new (live) or modified or changed from old to new. 

The objective is to the new or changed service meets the expectations of the business. In this phase a transition strategy needs to be defined first. Then all the related processes needs to be reviewed and the plan for transition can be coordinated. Then the transition is supported for successful rollout. 

There should be guidelines and procedures defined and implemented for service transition. Implement all changes through change management or within service transition process. Test the changes prior to release and deploy. 

The processes and functions come under transition phase are such as Transition Planning & Support, Change Management, Configuration Management, Release & Deployment Management, Service testing, Service evaluation, Knowledge Management.

We will discuss each ahead in later posts.

Service Operation:

The Service Operation is fulfilling the effectiveness of the service offerings to ensure value for the customer and service provider. It emphasizes on the overall coordination and execution of activities that enable the ongoing service operation.

Generally during service operation phase many issues arises, complains raised, requests came and risks identified and incidents happen. 

The processes come under operation phase are such as Event Management, Incident Management, Request Management, Problem Management, Access Management, Monitoring and Control, IT Operation Management, Servicedesk Management.

Continual Service Improvement:

The primary objective of this phase is to measure and analyze service level achievements by comparing them to the requirements in the Service Level Agreement (SLA).

It helps service providers to identify their gaps and to bring improvements in all phases of the service lifecycle. It aims to operate more cost effective IT services/ services without sacrificing customer satisfaction. 

There is CSI improvement process and service reporting process to work in continual service improvement phase.

The CSI improvement process describes how to measure and report service improvement. The process is closely aligned to PDCA model (ITSM). 

The 7 step measurement for Service Improvement is mentioned below;

  1. What should you measure
  2. What Can you measure
  3. Measure all the gathered data
  4. Process data
  5. Analyze data
  6. Present and use information
  7. Implement corrective action

Further we can go to other ITSM part where many things will be covered including the PDCA model. 

If you have further question, feel free to share it. 

-DR

Sunday, January 27, 2019

All about Security Operation Centre

Security Operation Centre (SOC)

Security Operation Centre (SOC) also known as Cyber Security Operation Centre (CSOC) plays very crucial part in terms of preventing, detecting, monitoring, containing, and remediating Information Security threats and vulnerabilities from critical applications, device and systems in an organization.

It centralizes by integrating people, process and technology. SOC implementation has been started since 2015/ 2016 at various Banking sectors, enterprise sectors. 

It acts like a central command and control centre connected to all the Organization’s IT Infrastructure, network devices, applications, servers etc. Depending upon variety of technology, SOC team can depend on latest threat intelligence to identify whether the threat is active or not.

Many people have a simple misconception that I have a SIEM (Security Information and Event Management; one post is there in this blog on SIEM) so I am operating a SOC.  But this is not practically how SOC works. It is not an easy task in setting up a Security Operations Centre supported by multiple security monitoring technologies and real-time threat updates. But yes, SIEM is one prime critical device used at SOC. The SIEM is also combined with other components such as Logger, Connector and UBA (User Behaviour Analysis). Connector connects the devices. A Logger is used for collecting the logs by deploying loggers at end point network. Then these logs are being correlated and analyzed by UBA. So the key indicators of compromise can be found, may be it user activity or any system events.

An illustrative components of SOC, provided below

 


So to establish SOC, you need to identify the key processes. These include event classification, event prioritization, event analysis, Event remediation, Monitoring and reporting.

What makes a SOC unique is the ability to monitor all systems on an ongoing basis, as employees work in shifts, rotating and logging activity around the clock. In addition to monitoring activity, a SOC should do Vulnerability Assessment and Penetration Testing with all the network devices and applications integrated with it. In turn it will help a lot to finding the gaps and close those gaps in a preventive approach. The logs need to be analyzed such as;

  • The logs on which a SOC works;
  • Log from Firewall Device
  • Log from End point Devices
  • Log from proxy servers
  • Service Logs
  • Malwares

Earlier in my post I have provided the list of Security Incidents. Those security incidents can arise at any organization during the operation. Such as;

  • Targeted Scanning/Reconnaissance of network and IT infrastructure.
  • Large scale defacement and sematic attacks on websites.
  • Large scale spoofing
  • Malicious code attacks (virus/worm/Trojans/Botnets)
  • Large scale spam attacks
  • Ransomware attacks.
  • Identity theft and Phishing attacks
  • Social Engineering
  • Denial of Service attack (DoS) and Distributed Denial of Service attack (DDoS)
  • Application level attack
  • Infrastructure attack
  • Router level attack
  • Attacks on trusted infrastructure
  • Cyber Espionage and Advanced Persistent Threat

When building a SOC there are similar requirement of IT and Non-IT devices we use in Data Centre projects. We also need a large video wall system for centralized monitoring. There are multiple designing factors to be considered for effective design of the SOC.

So here the key IT components that will be required as mentioned below, however this list is just an indicative, it depends on the organization depending upon its network size and requirement. 

  • Web Application Firewall
  • Anti-Phishing Appliance
  • Anti-APT Appliance
  • SIEM
  • DDoS appliance
  • Log Management Appliance
  • Network Flow Analyzer
  • Network Switches/ Access Switches
  • Router
  • KVM devices
  • Storage Devices

Besides the above devices, orchestration can be done using SOAR application (Security Orchestration, Automation and Response) is the technology just introduced recently that allows an organization to define incident analysis and response procedures in automatic or digital way. 

As well there are probability of many false positive events that could be arise or logged through the incident management system automatically. That should be minimized while planning for the risk mitigation or report. 

False positive events are generally those are system information events and those have neither any impact on the system or network. Means it incorrectly indicates any vulnerability or malicious activity but not a legitimate security threat.

Therefore there are more depth in to its operation and resource requirements. Different cyber skilled people are required with segregated duty and defined roles and responsibility. The resources such as Security Analyst 1 (L1), L2 Analyst, SOC engineer, L3 Analyst, Threat Intelligent Expert, Forensic Analyst and SOC Manager etc. Everyone have their crucial role in operation of a Security Operation Centre.

So this is just a basic information about SOC and its operation concept. 


-DR

Network Scanning Tools

Network Scanning through Nmap and Nessus Network scanning is a process used to troubleshoot active devices on a network for vulnerabilities....