| |

Implementing Security in Los Angeles County

February 25, 2013, TCG Security Sessions, San Francisco—Robert Pittman, chief, information security office, Los Angeles County described their efforts in establishing trusted computing in the county.

Some statistics for the county include 102,000 employees, of which 90 percent are union, and 34 departments structured into 5 clusters. The clusters are health, child services, operations, legal, and public safety. The computer systems are managed by sets of security engineering teams which set standards and policies, and any security breaches are handled by a county computer response team which includes law enforcement, inter-department co-ordination, and remediation workers.

The top 10 priorities for the department are: to recognize security efforts through special recognition awards, best security ideas, and a competition for best security policy. Next, they are working on more server virtualization to increase security, despite the limited volume of standards available. Tied for third are socialization and BYOD programs.

The two programs are tied together to bring in the business units and help them work together. The programs encourage user feedback and involvement. For the BYOD efforts, they correlate the devices and the data allowed to go to those devices. This work requires mobile apps and overall security management, and the use of mobile trust modules, all of which lead to safeguarding data.

Safeguarding data calls for segmentation of data into three classes and the highest classification, confidential data, is allowed on iOS and Blackberry machines as long as they have remote wipe, pass code, multi-level authentication enabled.

The fifth area is incident response. The county averages about 21 incidents a year, with an incident identified as a loss of equipment, web defacement, etc. The response units are working on outreach and closer ties with federal agencies like the FBI, Secret Service, and Homeland Security. They share as much data with these and other agencies as possible, in the belief that sharing incident data helps improve overall security intelligence. They have found that most layer 7 attacks are from outside the US.

Area 6 is for the highly regulated areas like healthcare. The HIPPA and Hitech compliance requirements are required for 21 thousand workers in 7 of the business units. In addition, the paycard activities and other financial areas that the FTC oversees have to meet other strict security requirements. As a part of the healthcare initiatives, they are establishing a health information exchange.

Seventh, is an ongoing effort to implement encryption standards across the board. In ’07, the instituted full disk encryption in 12,000 laptops and added trusted processing modules (TPM) and are migrating to self-encrypted drives. Encryption is at AES 256 or higher, or in other proprietary algorithms.

Risk management is area 8, and each department has to run scans to check for vulnerabilities in workstations and servers. Next work will be in layer 7 apps and database security, and in phase three of network layer protection.

Web app firewalls is facet 9, and the last area of focus for security is the county board of supervisors. This group is tasked with overseeing IT policies and ensuring realistic update cycles. The first security policies were established in ’04, and revised for BYOD. The IT groups are expected to update policies with any change in resources and assets.

The available and applicable standards like FIPS and policies have to correlate. The upgrades to meet these requirements is easier with their economies of scale. The various departments are encouraged to include end users in issues of use and other areas where their feedback could affect security compliance.

They have found that policy influences behavior as do standards. The standards also influence the technologies, business areas, and technology models. Technical standards afford consistent operations, services, and risk architectures. Standards potentially can reduce costs and improve compliance in all areas. Developing standard operating procedures that acknowledge the users makes them easier to develop, maintain, and work.

Similar Posts