Wednesday, February 10, 2016

Week 9--Who is responsible for IoT security?

I was reading Management of Information Security by Michael Whitman and Herbert Mattord recently. It's not pleasure reading by any means, but when one is in college one no longer reads just for pleasure. Anyway, I ran across this little tidbit that has interesting ramifications for the Internet of Things:

"Although it might seem counterintuitive, the goal of InfoSec is not to bring residual risk to zero; rather, it is to bring residual risk in line with an organization's risk appetite. If decision makers have been informed of uncontrolled risks and the proper authority groups... decide to leave residual risk in place, then the InfoSec program has accomplished its primary goal." (page 319)

Translated into English, this says information security's goal is to reduce the dangers posed to information to an acceptable level--not eliminate it completely. In other words, security's goal is to protect valuable things only as far as people think they need to be protected. 

In the real world, we can see this in department stores: electronics for sale are equipped with sensors that reduce the risk of shoplifting while packs of gum are not. This is because it's not worth management's time or money to eliminate the theft of low-dollar items like gum. It's the same way with buying stuff online: people don't have to buy online, and the likelihood of their credit card information being stolen goes up quite a bit when they purchase online. However, the sacrifice of not purchasing online is so great for most people that they continue purchasing online in spite of the risk. The risk outweighs the benefits.

How does this apply to the Internet of Things? Well, whose job is it to secure an IoT device? Manufacturers of IoT devices aren't very good at securing them, but is it their responsibility to secure them? No. It's the job of the people using IoT devices. It's the job of the users to determine how much risk they bring into their lives.

The security of IoT devices is deplorable, but it's because the people using them don't care about security. I've talked about Shodan, "A search engine for the Internet of Things," and how people can use it to access all sorts of Internet-connected things. And while it's scandalous that an IP-connected camera can be used to spy on it's owner, whose fault is it really? Who didn't change the default passwords or set passwords in the first place? Who doesn't take the time to shop for secure devices? 

Us.

The consumers.

We are the "decision makers" who decided to "leave... risk in place."

Manufacturers should be more careful about creating secure products. However, if nobody cares about security and doesn't shop for the most secure products, there is no reason for the manufacturers to make an effort to secure the devices. If people want them and people buy them, then who is the manufacturer to judge?

The person responsible to make sure your technology is secure is you. Sure, you can sue the hacker later, but you ultimately are responsible if the hacker took advantage of your negligence.

You are your own InfoSec department.

So, take this to heart: your security is your responsibility. Hackers can and will be prosecuted, and manufacturers can be sued. But if you determine, consciously or otherwise, that the blatant security risks of current IoT devices are acceptable to you, then you can't complain when the risks they bring come to fruition.

No comments:

Post a Comment