Monday, October 31, 2016

The Free Cyber Security Benchmark, increasing awareness of vulnerability for UK organisations

UK Government has been working to increase awareness of Cyber Security threats to organisations for years. It should be obvious why, almost 80% of UK GDP is services, and a significant portion of the non-services-based economy is just as dependant on intellectual property. While physical property, plant and equipment is difficult to steal or damage, most intellectual property is stored on computers and can be corrupted or stolen silently in a instant.

Back in 2013 the government announced a free cyber governance health check for the UK’s largest (FTSE350) firms. Large firms are important, but SMEs make up 50% of the economy by turnover and are among the most vulnerable to cyber attack, generally lacking dedicated teams of Information Security analysts or the apparatus to detect, repel, or analyse attacks.

To help these smaller organisations, and in concert with the UK Government Cyber Essentials scheme, 360is are announcing a Cyber Security Benchmark (CSB). Like the Government FTSE350 health check, the CSB is free of charge to qualifying organisations. It is designed to help medium sized companies. At the moment 360is is the only company providing this service.

The CSB will make you aware of the prevalence and seriousness of vulnerabilities in your Internet-facing infrastructure by providing you with a straightforward 1-page report all about you and your IT. You can then use that report to improve your cyber security posture and reduce the chances of you becoming one of the  organisations suffering from a breach this year. 

How To Obtain Your Free Cyber Security Benchmark
  • Take a look at the sample report for a fictional company and decide if it would be of use to you.
  • Complete the questionnaire and submit it to info@360is.com, a scan or picture of the completed form will do, don't forget to sign it.
  • We will verify that you are authorised to permit the assessment and that your organisation qualifies for the scheme.
  • Agree to the legal terms and conditions and await your results, they won’t take long.

The active phase of the exercise is non-disruptive and will not impact your IT operations.

Limitations

The CSB is not a full penetration test or vulnerability assessment and it is not a substitute for one. While accurate and evidence-based, the report is only a brief summary. The focus is on awareness, rather than the range of remediation activities. Once you are aware of the size and scale of your organisations vulnerability, you can take the next step in investigating, assessing, mitigating, and managing it. If you already know you need assistance with cyber security then get in touch

Tuesday, June 07, 2016

Open Source Application Security & Continuous Integration

Smoother App Security & Continuous Integration

Date: Thursday 7th July (8:30-11:00 AM)
Location: The Gherkin, Chivas Room 30 St Mary Axe, London, EC3A 8EP

360is consultants have been working-with and contributing-to Open Source Software projects for over 20 years. We helped build the worlds largest ISP using Open Source in the 1990s and today provide financial support to some of our favourite security projects.

We are holding a joint seminar with Black Duck and Forest Technologies for anyone who develops software and uses Open Source somewhere in their stack.

Attendees will learn how they can eliminate most common security vulnerabilities in their application or services at build-time, prior to deployment, long before their customers are put at risk.
Developers will learn how to screen source code against known security problems in an automated and accurate manner. Release managers will learn how to incorporate security testing into a continuous integration environment. 360is consultants will be on-hand to answer any questions you may have about Open Source Security, Testing, Secure Development, and Vulnerability Assessment & Remediation.

Attendance is free, but registration is required.

Agenda Overview:
8:30 - Buffet Breakfast

9:00 - Welcome.
Kevin Bland - Director Channel, EMEA, Black Duck Software

9:10 - The Application Security Continuum: From design to deployment, security must be considered at every stage of the software lifecycle if we are to minimize the risks of embarrassing and expensive failures.
Nick Hutton, 360is

9:40 - Continuous Delivery is the brain behind DevOps.
Jason Man, Forest Technologies

10:15 - Automating Open Source Security in Apps & Containers
Black Duck Software

10:45 - Conclusion & Wrap Up
Kevin Bland - Director Channel, EMEA, Black Duck Software

Monday, April 04, 2016

Mossack Fonseca Clients Awake To Find Themselves Adrift Offshore In A Leaky Boat

Today the executives of Panamanian-headquartered international legal and trust services firm Mossack Fonseca awoke to news that 11 million confidential documents spanning 40 years of the firms operation had been leaked to 107 media organisations in 78 countries. The documents purport to show how Mossack Fonseca has helped clients launder money, dodge sanctions and evade tax. Neither the identity of the leaker, nor the source material of documents itself have been publicly revealed. Instead, the source and his or her precise motivations remain secret, and we can expect a drip-feed of stories and revelations over the coming weeks and months as media organisations seek to maximise their commercial return from the 9-months of work we understand this investigation to have taken.

Putting to one side the moral and ethical arguments for and against the use of offshore tax havens, what do the Panama Papers tell us about the state of Information Security at Mossack Fonseca?

Back in 2010, we wrote about the US State Department leak of over a quarter of a million sensitive and secret cables spanning 35 years. We detailed ways in which an organisation, any organisation, can reduce the likelihood of sensitive confidential files (including personal and private information of its clients) escaping into the public domain. We described a framework that any organisation can use to reduce the likelihood of a catastrophic leak of company secret information. That article is here.

Let’s examine this latest leak, and consider whether or not Mossack Fonseca could have learned something from the events of 2010. We will take each consideration in our framework in-turn.

Recognise Where You Are Vulnerable
Given how little we know about who provided the confidential information and their motivations, it's hard to make many assumptions about whether or not the firm knew it was vulnerable to this particular person or the methods they may have used to steal information. The leak may have come from an insider, a longstanding employee, perhaps even a senior executive, he or she may have been acting alone or with help, and may even have been coerced into exfiltrating the documents by an as-yet unknown 3rd party. However given what little we do know it seems unlikely that the board of directors at Mossack Fonseca truly understood quite how vulnerable they were to such a leak. If they did then they would have done something about it.  According to public sources, the company has between 200 and 500 staff around the world, and 20 former members of staff. It is a relatively small firm where Information Security should have been a tractable problem. When considering your vulnerability to a leak, think about the following:

  • Where is confidential information kept in your organisation?
  • In how many different places can it currently be found?
  • Are multiple copies routinely created of confidential information?
  • How many different access methods are there to this information?
  • What size community of users have access to it?
  • What controls are there over who can access what, where, and when?

Know If You Are A Target
The company must have known it was a target, their entire industry relies on confidentiality and secrecy. With current and former politicians, powerful businessmen and celebrities as clients, that much should have been obvious. Political enemies, nation states, criminals, and blackmailers would all have liked to get their hands on their information. Mossack Fonseca should have been devoting significant effort to its Information Security programs.

"Some organisations attract leaks because they are repositories for particular confidential information, or because the information they hold is highly newsworthy, others find themselves subject to leaks because their employees sometimes struggle with difficult and conflicting concerns about the nature of their work. While your newsworthiness may fluctuate over time, certain sectors tend to experience a perennial popularity with leakers. If you are in the energy, pharmaceutical, government, or banking sectors, you should consider yourself a prime candidate for leakers at this time. Companies engaged in arms manufacture or doing any kind of business in troubled parts of the world are likewise a target. Are you an aggregator of sensitive information from several of the sources above? If you operate a law or consultancy firm, or other business where you are entrusted with sensitive information from clients in these industries or geographies, then you will be a target for leaks."
Diligence & Statutory Obligations (Compliance)
While offshore locations are often preferred because they are relatively light on controls and heavy on individual privacy protection, increasingly they are having compliance obligations forced upon them. Whether or not this leak lands Mossack Fonseca in violation of compliance will be academic if their clients desert them as a result of it.

Segment Your Data
Given that the information leaked covers such a long period of time (many decades) and appears to include files on a diverse range of clients from statesmen to self-help gurus, it appears that nobody at Mossack Fonseca was segmenting their data. It is as-if there was one huge shared drive, one Email system, and the whole lot was dumped out. Segmenting data helps to contain information security failures, losing one class of systems or documents does not expose the whole.

  • Segment by status: active client versus inactive/former clients.
  • Segment by “security level” of the information: secret, confidential, unclassified.
  • Segment by time: don’t keep files for completed projects with open client files.
  • Segment by user/group: litigation versus patent, analysts versus sales.

Although it can reduce staff productivity and increase cognitive load, encryption can be used to reinforce the segmentation process. Did Mossack Fonseca individually encrypt the most sensitive documents or indeed any document in their organisation? It seems unlikely. Encryption of individual documents, or individual client folders is another way of limiting widespread uncontrolled disclosure of confidential information. It is not difficult to imagine a regime of individual passwords for individual projects, clients, or business units.

The Human Element, Maturity & Common Sense

We may never learn who is behind the leak, or hear first hand exactly what motivated them. We may never know if they are a current or former employee, a state-level actor, or just a particularly thorough and successful activist. We don't know anything about the firm’s culture or leadership at this point. All these things make it hard to comment on whether or not there is anything the firm could have done to avert this situation. In most instances where a company has lost control of its confidential information, there are things that could have been done with respect to the human element, to significantly reduce the chance of such a disastrous disclosure.  Staff vetting, the establishment of an ethics committee, monitoring, and a strong internal audit function can all help reduce the likelihood of such a large and damaging loss of confidential information.

Handling A Leak
The story is only just beginning for Mossack Fonseca and their clients, thus far we haven't seen a response from them either publicly or have any idea what they are doing internally.  What is clear already though is that this story is far from over and that there will be a continuous drip-drip of disclosures over the next few weeks and months. It is interesting that rather than making the entire document archive available online, the media organisations involved are choosing to be very selective about who and what they choose to write about.

What Next?

As Information Security professionals we have probably learned as much as we can from this disclosure. We expect the majority of the disclosures to be politically-motivated in nature, with a focus on Russia, Syria, Zimbabwe, North Korea, and any of those “twitter revolution” countries that haven't quite come around to the wests way of thinking. We expect disclosures about leaders of EU member states with politicians whose views differ significantly to those of Germany and the US, such as the Visegrad group (Czech Republic, Hungary, Poland and Slovakia), and a sprinkling of celebrities, nobility, and more minor politicians or from countries that don't really matter very much. We expect the disclosures to almost entirely avoid large western corporations and the interests of those who own and operate them, which is interesting given that group probably makes up the majority of Mossack Fonseca’s clients.

360is are able to assist in improving your organisation’s Information Security posture, and in implementing the advice given in this article. While it may be impossible to guarantee that your confidential information will stay that way, you can significantly reduce the chances of the kind of widespread leak experienced by the Mossack Fonseca today, or the US State Department in December 2010. To speak to one of our consultants, visit our contact page and request a meeting.                                                                       

Monday, February 08, 2016

What does every UK Cyber Security startup need, that is worth more than gold?

It's not that I'm ungrateful George...
While compiling the next issue of Executive Intelligence, the Cyber Security briefing for UK decision makers, we came across an announcement from Chancellor George Osborne for a £250,000 programme to increase the rate of cyber security startup development in the UK. We aren't sure whether this announcement, made around the 27th January 2016 was something new or just an echo of a previous release from the 17th November last year, but we took the opportunity to study what was being announced more carefully this time.

The 'Cyber Safe' scheme, will offer advice and support to security startups, and will be open to applicants from March. The scheme is designed to increase the rate of new security startup development in the UK, identify new business ideas from the UK's leading security firms and provide support for security entrepreneurs.

While any assistance for startup and early stage technology companies in the UK is welcome, I'd argue that there are more directly beneficial things that could be done to stimulate and grow UK Cyber Security firms, things that would sustain such growth over 5 years, over 10, and beyond.

Startups, starting up, California style
It costs less than ever to move a software businesses from concept to prototype and on to minimum viable product. The UK is already arguably the best place in Europe to start a technology business. With professional social media, it is easy to connect with expertise and experience, to seek advice and assistance from those of us who have done it before in the UK market and abroad. While neither our climate nor the air quality around Silicon Roundabout is conducive to the kind of cafe-culture you'll find on Sand Hill road (come to think of it neither are the pavements) networking here is just as easy.
"Old Street is that way son"

Something less easy to achieve, and far more valuable to the Cyber Security entrepreneur, is the first customer. This is an area where UK Government has far to go.

According to a study last year by TechUK, only 20% of central government IT managers had "an appetite within their department to procure a higher percentage of technology services from SMEs". One can only imagine what percentage of them might be warm to startups. 5%? 2%? Zero?

The model that works in the US, is one where early stage companies can count on government in all its forms (military, intelligence, research, local, national, laboratories, and the rest) to be a customer of their service or product. That is the great thing about starting a Cyber Security firm in the US, long before specialist funding programs or affiliated venture firms appeared, someone, somewhere in US government was pretty much guaranteed to need your Cyber Security product, and to do business with a relatively small, relatively new, yes... relatively parochial firm who had cracked a tough problem. Contrast this with the TechUK study, or your own anecdotal experience.

"Present them with three options, two of which are,
on close inspection, exactly the same,
plus a third which is totally unacceptable.
I once attended a conference where a government procurement officer explained to the audience of his peers how they could carefully construct RFPs, RFIs, and tender documents for the specific purpose of excluding small firms, while staying within "SME friendly" guidelines issued by government. Never let it be said that the civil service is without ingenuity!

A pity, because government can be a great 1st customer and the benefits are not all one-way. The startup gets valuable feedback, real-life testing, requirements prioritisation, introduction to other potential early adopters, and (if all goes well) a reference customer, ignoring for one moment the financial benefit to the startup. The customer gets early access, the ability to shape the product to their needs, all the deployment assistance they could wish for, and more than likely the ability to cut the deal of a lifetime in terms of commercial arrangements.

But don't take my word for it, ask Black Duck, Aventail, Verid, Sanctum, E-Security, or any of the other successful Cyber Security companies that passed my desk at Fidelity Ventures looking for venture capital funding after the US government became an early customer.

Let's hope TechUK repeat their 2015 study this year and extend the survey to include attitudes to startups.

Wednesday, November 25, 2015

Social Engineering, Countering The Threat

Would You Buy A Used Monument From This Man?
"Count" Victor Lustig, con-man and Social Engineer, famously sold the Eiffel Tower. Twice.

Like accomplished Social Engineers of today, he was meticulous in his planning, thorough in his research, had an excellent understanding of human nature. He managed all of this without Google, FaceBook, Twitter, or his own printer back in 1925. Modern Social Engineers have it easy. What scams would Victor (real name Robert Miller) have to his name if he was around today? Which world leader, CEO, or politicians would be his victims?

360is have written a short guide to defending against modern social engineering attacks, and are now introducing our social engineering services to clients and partners by means of a presentation. If you are concerned that a modern day Lustig may find your organisation and its information assets easy prey, then we can help. Get in touch.

Social Engineering + Converged Communications = Bad For Security

John, I'm afraid I've got some very bad news for you.
We've recently learned that even the Director of the CIA can't keep hackers out of his e-mail. A teenager hacked into CIA Director John Brennan's AOL account. He says he did so by posing as a Verizon employee to other Verizon staff to get personal information about Brennan's account, as well as his bank card number and his AOL e-mail address. Then he called AOL and pretended to be Brennan. Armed with the information Verizon had just given him, he convinced AOL customer service to reset his password.

Brennan didn't have a bad password, he didn't e-mail it to anyone, he wasn't even tricked into entering it into a fake web page, the security failure here belonged to AOL and Verizon, and it wasn't even a technical failure at that. Now Brennan's e-mail is part of Wikileaks and a thousand articles.

Security experts including 360is have long since recommended 2 factor authentication systems for all of our clients, and yet still relatively few organisations have this kind of authentication. Their reasons? Cost, complexity, and (in)convenience. Over the last 20 years there have been a number of different companies attempting to tackle the three Cs, some of the more recent attempts make use of mobile devices and "soft tokens" on those devices, or they use instant messaging as a secure channel to convey some passcode or challenge/response.
Is there such a thing as too much convergence?

What if we are using multi-factor authentication, but thanks to the wonder of converged communications...all my factors converge upon 1 single device, normally a smartphone or tablet? What if that device were itself, compromised? Mobile devices can be cloned, rooted, or otherwise compromised just like any computer. How would that possibility change the level of trust you place in these kinds of multi-factor authentication? What if I am also trying to login to the secure service in question from that very same mobile device? If an attacker has my phone under his control, or has bamboozled me into doing something with it which help him, what happens to "defence in depth" and "fail safe"?

For these reasons, and because we don't think using 2 factor authentication should mean you have to trust a 3rd party organisation, we recommend keeping your factors as separate as possible for as long as possible. Talk to us if you want to harden your organisation against hackers, social engineers, and end users who sometimes make poor security choices.

Monday, October 19, 2015

High Performance, Low Latency, Hyper-Converged Computing


Recently 360is implemented several systems for clients who needed very high performance, within a stated budget, and had limited physical space and power to work with. For these clients we designed hyper-converged compute/storage units built from non-proprietary, commercial off the shelf components, supportable by their in-house IT team. Thanks to recent advances in storage technology it is now possible to obtain very high performance for a fraction of the cost of a traditional Server + SAN approach. Better still, these systems aren't subject to the vendor’s ideas of life-span (often artificially foreshortened), and can remain operational for 5, 10, or more years if required. You the customer, remains in control.
  • 70GB/sec streaming transfers, 4M IOPS, 4U of space, 5TB to 250TB raw capacity, 2.5PB per rack
  • 2GB/sec streaming transfers, 480TB raw capacity, 4U of space. 4.8PB per rack
  • 75% less power for a given performance level
  • 3X to 6X the performance when compared to similarly priced Server + SAN
  • On-site spares for instant access to replacement parts, forever
  • Scale-out capability with clustered filesystems like Lustre, GlusterFS, and Ceph
  • No chance the vendor can make the systems obsolete
If you are challenged to provide performance, either on-premise or in the cloud, then a hyper-converged system may be for you, and will certainly have a longer lifetime without vendor or service lock-in. For a fixed cost, a properly designed hyper-converged system will always deliver significantly more performance than Server/SAN systems. Let us know your constraints and we can give you an immediate indication of whether hyper-converged is for you.

About 360is
Our scientific approach to performance analysis and engineering has been proven in previous engagements. We work with top 5 Investment Banks, Telcos, and technology vendors. If you have an IT performance problem that is impacting your business, contact us to arrange a no-obligation meeting with one of our consultants.

Wednesday, September 23, 2015

Countering The Social Engineering Threat

An increased number of clients are experiencing social engineering attacks either directly against their finances and information assets, or the IT infrastructure upon which those assets depend for confidentiality and security.

Once only immediately saleable commodities such as credit card numbers were targeted. Now criminals are seeking medical records, credit history files, general personal identity information, significant cash funds, and online social media account information for purposes as diverse as blackmail, defamation, and identity or insurance fraud.

Highly targeted attacks often focus on uncovering commercial negotiating positions, cost-to-manufacture for orders, and in identifying holders of intellectual property or purchasing authority within an organisation. Those defending against such attacks now need to consider far more than simple monetary loss.

360is have prepared a short briefing for those tasked with defending their organisation and users from social engineering attacks including Phishing, Pharming, Vishing and SMishing. It is intended as an introduction to the technical, procedural, and human elements of a successful social engineering defence.

If you would like assistance in implementing any of the measures described in the document, or in understanding your own organisations vulnerability to social engineering attack, get in touch.

Download "Countering The Social Engineering Threat" here.

Thursday, June 11, 2015

City Security Magazine, How To Avoid Leaks


Leaks are news, whether they are about Governments, Corporations, or individuals. City Security Magazine, the print and digital magazine that promotes security issues across the UK, carries an article from 360is on how to reduce your chances of becoming the next SONY, NSA, US State Department, or celebrity to suffer a breach of Information Security and have private and confidential information leaked to the public domain.

360is are able to assist in improving your organisation’s Information Security posture, and in implementing the advice given in the article. While it may be impossible to guarantee that your confidential information will stay that way, you can significantly reduce the chances of the kind of widespread leak experienced by the US State Department, the NSA, or SONY.
To speak to one of our consultants, visit our contact page and request a meeting.

Wednesday, April 08, 2015

Meet 360is At InfoSecurity Europe 2015


Three Sixty Information Security Ltd will be at InfoSecurity Europe, Olympia, London, 2nd to 4th June 2015. We'll be meeting clients, partners, and friends among the 12000 expected visitors and 330 stands at the show this year.

If you want to discuss the results of a penetration test, arrange a confidential meeting about a  breach, or just need advice on how your organisation should handle the latest bug disclosures, get in touch. We will have technical consultants at the show.


Thursday, February 05, 2015

How do we validate a supplier has ISO 27001?

(c) Scott Adams
Most of the questions we get from our clients about ISO 27001, the standard for Information Security Management Systems, are about how they can implement this standard and possibly achieve certification.  We covered some of that in our previous blog.

The "other" question we get asked less often is "how do we validate a supplier or partner that claims to follow ISO27001 or claims to have been certified now or in the past?"
You may be surprised by the answer.


There is no such thing as a complete, current list of ISO 27001 certified companies.

That's right, it is impossible to obtain a definitive list of companies with ISO certification.

The creation of such a central list has been attempted in the past more than once, and for several ISO standards (notably ISO 9000) but such lists have always been incomplete and prone to going out of date. Part of the reason for this is that there is a competitive market between certification companies, they don't want to share their list of clients, or even indicate how many clients in total they might have, or how many might have once held certification which has since expired. Companies go out of business, get acquired, divested of, and restructured, and all these things mean that an ISO certificate issued in the past, may not count for much in the present unless the certified company has kept up with its maintenance audits (surveillance audits as we call them in ISO-speak).

Your best hope is to speak to the certification body the certificate holder used. For example, BSI allows you to query a certificate number against their database of clients to see if it was issued or is current here. Not all certification bodies have such an online service, and if you don't know who issued the certificate then you are out of luck.

360is is able to perform due diligence against your suppliers and partners to determine the strength of their information security, whether or not they have undergone any formal certification. If their technology, processes, or procedures do not provide adequate protection for your sensitive data, we are able to describe and implement improvements. If you are faced with meeting strict information security compliance targets yourself, we can help your formulate an appropriate response and program of improvements to meet expectations. Talk to one of our consultants.

Wednesday, February 04, 2015

ISO 27001, how do we prepare and what does it cost?

Need help preparing for ISO 27001? (c)Scott Adams
ISO/IEC 27001 is a standard providing requirements for an Information Security Management System (ISMS). It is part of the ISO 27000 family of standards, all of which help organisations keep information assets secure.

Like other ISO standards, some organisations choose purely to implement the standard in order to benefit from what it contains, while others decide they also want to get certified to reassure customers or clients that its recommendations have been followed. There are many Information Security standards out there (within specific industries, or for specific countries), ISO 27001 is one of the more widely recognised. 360is have been working to help companies implement the technical controls within ISO 27001 and its predecessors since the mid 90's. While we don't certify you against ISO 27001, we can help you prepare for your certification and pass your annual audits by having a strong Information Security posture.

What is an ISMS?
The Information Security Management System is a system in the broadest sense of the word. It is a mixture of people, processes, and IT systems (hardware, software, products and services) which allow you to manage risks relating to sensitive company information so that it remains secure. An ISMS isn't just a product you buy, or a configurational change you make. Rather like a religion with rites and ceremonies, it is something you must observe every day.

Control-Point Versus Procedural Standards
There are 2 kinds of IT Security standards in this world, there are those that are control-point based and there are those that are procedure-based.  ISO 27001 is control-point based, meaning that it tells you what controls need to be in place to ensure the right outcome. It is not a prescriptive "how-to" for the configuration of your IT. A control-point standard can be said to apply across a broad range of organisations with different sizes and operational patterns because the standard steers clear of the minutiae. Procedure-based standards can struggle to cater for such a broad range of organisations. However, IT staff find control-point standards harder to implement in technical configuration. 360is helps companies translate the control-point objectives of ISO 27001 into practical, technical configuration, procedures, and documentation.

How Much Does ISO 27001 Cost?

The cost of getting ISO 27001 certification depends on:
  • The size of your company and scope of the ISO 27001 certificate
  • The maturity level of your ISMS 
  • The gap between the current state and the desired state of the control environment
  • The in-house capability/capacity to develop the ISMS and close the gaps
  • How quickly the certificate is required
If you are a large organisation, wishing to certify the whole of your operations, and you have not previously invested much in ISMS, or people with the skills to build and operate such a system, then you are going to have to spend more getting ISO 27001. These costs come from 3 places:
  • The first is the cost of getting your ISMS up to scratch, "pre-certification"
  • The second is the certification process itself
  • The third is the cost of your annual certification audit in years 2 and beyond
Given the fact that there are so many variables, we will use a real client of ours as an example:
  • 50 staff, 1 office, in the UK
  • Processes sensitive data, some personally identifiable information, for medium sized banks
  • Co-locates at two UK data centers
  • Provides software (SaaS) at these data centers
  • Has a control environment that, while previously subject to external review, would still be best referred to as immature and non-fully documented
  • Has staff that are technical but not ISO 27001/ISO 27002 aware
  • Pressure from clients for independent attestation, some ask for ISO 27001
  • Need to achieve certificate (without great disruption to business) within 1 year
  • Requires a fair degree of ISO-27001 consulting to prep for the certification audit
The “external” costs to become ISO 27001 certified were:
  • Pre-certification Part 1: £15,000 (Scope Definition, Risk Assessment, Risk Treatment Plan, Gap Assessment, Part 2 Remediation Plan)
  • Pre-certification Part 2: £15,000 (Gap closure (collaboratively), registrar selection, ISMS Artifact development, Risk Management Committee, Incident Response, Internal ISMS Audit, On-site Certification Audit Support)
  • Certification Audit: £15,000
  • Total cost for ISO 27001 certificate: £45,000
To this one-time cost we can add the annual external audit in year 2 (£5000) and internal ISMS audit (£5000) in year 2.

Of these costs, the pre-certification is likely to be by far the greatest, unless you are already well prepared. It is also possible that pre-certification costs for your organisation could be significantly higher than those shown here. We have known organisations need up-to £50,000 of pre-certification work on their existing ISMS. Finally, you should also consider the omissions below carefully:

Omissions: We ignore other associated annual costs such as annual penetration testing, maintenance and support costs of the ISMS infrastructure, and the cost of any staff (new or existing) or training required to operate the ISMS. We ignore the costs of new products (hardware/software) or services which you may need to build an ISMS if you do not already have something suitable to work with. If your organisation is very large or very complex, you will have a lot of Information Security to manage. The cost of the management systems/software may be significant.

Concluding Remarks
ISO 27001 is not a one-time exam, it is more like a religion. It is a commitment to do things the right way every day, and to submit to regular audits to confirm you are observing the religions practices every day, not just when the vicar comes to tea. The total cost of ISO 27001 certification is dependent in large part on the status and strength of your existing ISMS, which should not come as a surprise.

If you would like help preparing for ISO 27001, straightforward advice on improving your Information Security posture, answering Information Security challenges from clients or the regulator, talk to us.

Tuesday, January 20, 2015

High Performance Computing Advisory Council Conference, CSCS Switzerland, March 23rd - 25th

Lugano, Location of the 2015 HPCAC Conference
Three Sixty will be attending the 2015 High Performance Computing conference held in Lugano, Switzerland from March 23rd to 25th.
The conference brings together system managers, researchers, developers, computational scientists, students and industry partners for cross-training and to discuss recent HPC developments and future advancements. This year the topics will be:
High Speed Networks
High Performance & Parallel I/O
Communication libraries: MPI, SHMEM, PGAS
GPU computing, CUDA, OpenCL
Big Data 
There will be practical workshops for clustering, networks, troubleshooting, tuning, and optimisation.

Will we see some British companies there this time?

Three Sixty helps UK organisations adopt new, high performance computing technologies and methods. To find out why it is vital that UK organisations do this, talk to us.


Wednesday, November 05, 2014

Join 360is at PETEX 2014

PETEX 2014
Come and meet 360is at PETEX where we will be talking about Virtualisation & Cloud, Cyber Security, and High Performance IT projects delivered to the Oil & Gas industries. If you are an IT manager or analyst working in the sector, the conference program will include sessions and seminars on a range of topics:

  • 3D workflows
  • Corporate data management
  • National data repositories
  • Modelling at continental scale
  • 4D data processing, storage, and visualisation

The Petroleum Exploration Technology Exhibition is in it’s 25th year and runs from Tuesday 18th November to Thursday 20th November this year at the ExCel, London. For more information and to register go to www.petex.info. If you'd like to chat about a project or requirement and are going to PETEX then let us know via info@360is.com, @three_sixty_is, or in the comments section below.

Thursday, September 11, 2014

360is Builds VDI for InnovateUK

UK Satellite and GIS Imagery
The UK Satellite Applications Catapult (The Catapult) was established to promote growth in commercial applications of satellite technology. Its mission is to accelerate the take-up of emerging technologies by businesses and in so doing, drive UK economic growth. The Catapult offers expertise and facilities that will bring strategic benefit to the community of industrial companies working in the sector.  

How did the project come about? 
Making facilities and information assets easily available to potential users of their services is part of the Catapult's mission. Satellite analysts routinely work with heavyweight applications like ESRI ArcGIS, GE Smallworld, and Raytheon VIIRS. The Catapult wanted to see how such applications performed on a modern, fluid, Virtual Desktop Infrastructure (VDI). 360is was challenged to build a system capable of multi-user, multi-screen VDI for satellite applications using thin clients while providing a dedicated workstation-like experience.

What did 360is do?
After interviewing end users, 360is built a VDI system using Citrix XenDesktop, XenServer, and NVIDIA GPU hardware and a suitable WYSE thin client. This combination of technologies allowed for maximum flexibility.
  • Physical GPUs may be partitioned into virtual GPUs Virtual Desktops are booted on demand.
  • Users are allocated VDI's with different vCPU/vGPU capabilities depending on a profile.
  • The platform may be optimised for user density or performance.
  • Server GPUs work with client GPUs to enable a high-quality end user experience.
  • Network bandwidth is minimised using caching and compression.
As this was a proof of concept demonstration, 360is chose components and settings for maximum stability. End users can quickly form a negative opinion if a new technology is not completely reliable and this system was to be used for live demonstration.

How successful was the platform in meeting the project goals?
Multi-screen multi-user GPU VDI was delivered. 0.5Mb/s to 1.0Mb/s of network bandwidth was required per client while running in excess of 60fps. Up-to 64 concurrent GPU-powered VDI's could be provided by the system, this could be increased to 128 with different choices of hardware. The thin client CPU (capable of driving up-to 6 monitors) proved to be the limiting factor. High-density, GPU VDI is now within the reach of most organisations. Specialist scientific applications no-longer need to be excluded from the virtual desktop projects.

About 360is
360is builds multi-user, multi-monitor, high-resolution and GPU-enabled Virtual Desktop Infrastructure for Scientific Technical and Creative Industry organisations. Our engineers can address all aspects of the project from storage, to networking, to hypervisor configuration and application performance tuning. If you would like to talk to one of our engineers about deploying scientific and GPU applications to demanding users, get in touch via our contact page, Email, or message us on twitter.

If you want to know more about the UK's Satellite Applications Catapult and the great work they are doing to help grow the £7B annual turnover of the UK space sector, take a few minutes to find out more:

Wednesday, July 16, 2014

360is deploys Schlumberger Petrel over Virtual Desktop Infrastructure

Canadian Natural Resources Inc (CNRI) are an energy company operating in the North Sea, Canada, and Africa. 360is designed and deployed a high-performance, GPU-accelerated, VDI platform for their geologists. It allowed staff to work remotely and CNRI to achieve a 2:1 ratio of analysts to Schlumberger Petrel licenses.

Schlumberger Petrel Delivered over VDI by 360is

How did the project come about?
CNRI was rolling out the latest Schlumberger Petrel reservoir modelling software. The company was increasing the number of Geologists/Geophysicists needing access to this software. With licenses between 100-150K per concurrent user, and some analysts only requiring access occasionally, CNRI wanted to broker that access. While hardware costs were not as important a factor as the software, a capable workstation can run to £10K. It makes sense to keep those workstation assets busy. The company had already considered and disregarded a number of technologies, and had contacted 360is to provide a new platform for their analysts who would return shortly from Petrel training.


What did 360is do?
A team from 360is determined the feasibility of the project, and any dependencies with other parts of the infrastructure (workstation, network, and SAN upgrades happened to coincide with the VDI project). A plan was agreed between the client and 360is and work started as soon as hardware became available. 360is selected Citrix XenDesktop VDI infrastructure on-top of VMware vSphere, with hardware supplied by NVIDIA, HP, and others. User acceptance testing and HDX3DPro performance tuning was carried out by 360is engineers with the assistance of Schlumberger and the infrastructure went live within a few weeks of the project start-date. 360is continued to support the client as his users began working with the new environment.

How successful has the platform been one year on?
CNRI continue to enjoy increased productivity from their investment in Petrel, NVIDIA, and XenDesktop. With Petrel 2014 launched this month, and XenDesktop 7.5 in March, CNRI's management can can be confident that their engineers and analysts have continued access to the latest technology. As an added bonus, moving to a VDI deployment also made remote access to the platform possible, even over relatively high latency connections. 


If you would like to talk to one of our engineers about deploying scientific and GPU applications to demanding users, get in touch via our contact page, Email, or message us on twitter.


For those of you unfamiliar with the Petrel, take a look at this fantastic video produced by the talented guys of The Mill.

Schlumberger @ The Mill from Nils Kloth.

Tuesday, July 15, 2014

XenServer Creedence Alpha 3, Disk I/O testing (part 2)

We did some more testing of XenServer Creedence Alpha (XSCA3) disk performance, and plotted large streaming reads for a variety of record sizes against both a physical and Brand-X Hypervisor.

Recap:
  • System is an AMD6176SE, 2 CPU, 192GB RAM 
  • Local storage, 3x 10Krpm SATA, LSI 9261-8i, RAID0, thick provisioned 
  • No special settings, tuning, or configuration 
  • Testing is with dd and iozone, with and without Direct I/O (dd iflag=direct, iozone -I)
  • CentOS 6 2 vCPU, 2GB vRAM (updated 3-07-2014) VM and physical 
  • The system was idle 

Physical achieves ~600MB/s transfer speed. 
Brand-X achieves a similar figure.
XSCA3 achieves less than 50% of that, unless Direct I/O is used.
Neither physical nor Brand-X are significantly affected by use (or not) of Direct I/O.


Results for physical without Direct I/O are excluded as with 192GB RAM and only 8GB of test data, transfer rates are in the 2500-1700 MB/s range due to the abundance of RAM for cache. We took no steps to limit the physical CentOS to 2 cores either.
  

We know the disappointing XenServer performance is only for asynchronous (not Direct I/O) disk access, and that the system behaves as expected when running physical or Brand-X hypervisor. The mystery deepens!

Monday, July 07, 2014

360is gets new shoes, jug, and knives!

New 360is Web Site
We don't sell coffee.
"But who is wurs shod, than the shoemakers wyfe, With shops full of newe shapen shoes all hir lyfe?" 
[1546 J. Heywood Dialogue of Proverbs i. xi. E1V] 

It seems everybody has a claim to this one.
 
There are only wooden knives in the blacksmith's house. Spanish Proverb
At the potter's house water is served in a broken jug.        Afghan Proverb
The lady who sells fans, fans herself with her hands.       Chinese Proverb

It has been almost 2 years since we last updated our web-site, and during that time we've acquired around 20 new clients, new technology expertise, and increased our pool of consulting engineers. We've been so busy delivering for our clients that our own shoes are looking a bit tatty.

The new 360is web site is quite different from the old one, products and vendors are out and successful client engagements are in. As an independent consultancy with our own library of intellectual property, we've always worked with all vendors and technologies to find the right solution for our clients. Or to put it simply, once you've seen 15 different firewall products, or 30 storage systems, or 20 application frameworks, you've pretty much seen them all. On those rare occasions where some element of a project is truly new, we don't expect our clients to pay for us to do the learning. So take it as read, if we aren't already experienced with a product or technology, it won't take us more than a couple of days to be all over it.

Our business is still all about helping clients solve their performance, security, and data centre challenges. We are still one of the few firms offering short-term (up-to 3 month) projects at a fixed price with no risk to the client of cost overrun. We still offer a complete service from helping you frame the problem, through design, technology/vendor selection, implementation, and support. We still enjoy working either with your own technology team, or directly with the business managers.

Over the next 12 months we'll be devoting more time to talking about our intellectual property, experiences, successful projects, and some of the platforms and applications we have developed for our clients. In the mean-time, please excuse any broken links.

Thursday, July 03, 2014

XenServer Creedence Alpha 2, Disk Performance


360is gets paid to make information technology go faster.

Sometimes its hardware which doesn't hit the stated performance, or software which cant fully utilise the capability of modern hardware. Sometimes it's a lifetime extension for an old platform, squeezing in another 18 months growth before a replacement arrives. If we are really lucky we get to re-design an entire end-to-end process and make it more efficient. More layers and more abstraction means more scope for performance problems, so virtualisation has been a rich seam for us. With Citrix release of XenServer Creedence Alpha 2 (XSCA2) should we be worried? Is it time to throw in the towel on IT performance-tuning and setup that high-end bicycle-shop-come-espresso-bar we've always talked about?

We've been following XenServer performance from the start, and have a tome of magic spells to instrument and improve network, storage, and CPU performance. Without resorting to black-magic we were interested in seeing how XSCA2 performed straight out of the box.

Firstly let me say that all we have time for here is the most superficial of testing. Large sequential reads and writes are the 0-60 time of the storage world. That is to say, while they have some value, unless your use-case is an out-and-out drag race this test probably isn't a good approximation of the kind of performance you will see in your applications. Single VM large sequential read/writes are even more of a corner-case. If you only had a single VM to run you should probably run physical, just a suggestion...

Secondly, XSCA2 is alpha, and so it is slightly unfair subjecting it to a performance benchmark.

Finally, we used the equipment we had spare in the lab at the time. The storage back-end is puny. We had a handful of 10Krpm spindles and SSDs laying about. Out in the real world, 360is regularly deliver 1.5GB/sec to 2GB/sec of storage bandwidth (at high IOPS) to Hypervisors and physicals of one kind or another either over local or network storage.


The Goal
We were interested to see how XSCA2 performed against XenServer 6.2, against physical, and against "Brand-X" Hypervisor, all of which were "out of the box".

The Test
The test couldn't have been simpler. For a 2 vCPU VM, for each of 9 record sizes (64KB-16MB), we write (or read) 8GB of data and measure the performance in MB/sec for each record size. Why 2 vCPUs? Adding more doesn't change the results. Why 8GB? We can be sure 8GB blows through any caching that may be happening on disks, RAID controller, VM, or Hypervisor. Even at a 16MB record size, 8GB takes a lot of writes. For the physical test case we force direct IO to get around the fact that the physical system has much more RAM than 8GB. We use the same guest Operating System, installed in the same way for each of the VM tests. Everything is thick provisioned. This isn't a test of how fast each configuration can be made to go, it is a test of how fast each actually goes, straight out of the box on the lab system that was available at the time.

Tuning
None. No changes to the default install of XenServer, Brand-X Hypervisor, the CentOS VM or physical instance, with the exception of taking XSCA2 out of debug mode. No CPU pinning, no IO scheduler changes, no disk/virtual disk alignment, no IRQ balancing, no interrupt coalescing, no filesystem tweaking, no queue size alteration, no waving of dead chickens or reciting of incantations.

Results  
Enough talk, on with the results:

8GB Sequential Write At A Variety Of Record Sizes
8GB Streaming Write At A Variety Of Record Sizes


8GB Streaming Read At A Variety Of Record Sizes



On this system, for this test, XSCA2 is an improvement over XS61-SP1, but is still significantly behind the physical, and more disappointingly behind the other well known brand of Hypervisor. Besides the obvious, there are a few points from the chart which warrant further investigation for starters:
  • High jitter in all XS results.
  • Odd dip at the 512KB record size test on both XSCA2 and "Brand-X" hypervisor.
  • Slow start to the physical test at 64KB record size.
  The tests shown here were on a RAID0 of 3x 10Krpm spindles (maximum sustained transfer rate ~200MB/s each). Conducting the same test on a RAID0 of SSDs made little difference to the XenServer results, adding 20MB/s to the average write result and 40MB/s to the average read value.

Conclusions
  1. We aren't out of the performance tuning business just yet it seems!
  2. There is a significant difference in performance between the physical and "Brand-X" and XenServer.
  3. Read performance is particularly disappointing for XenServer in this test.

"It is easier to repair a bucket with a big hole, than an inner tube with a slow puncture." - Ancient 360is Engineer's Proverb.

For this system, for this test, the hole in the bucket is large, with a bit of further investigation it shouldn't be too hard to find. XenServer Dom0 (which strictly speaking we don't care about) comfortably achieves ~600MB/sec in read performance tested using "dd" with direct IO (no cache effect), so we know the problem is with the guest disk virtualisation IO path. First port of call will be instrumenting CPU consumption in the guest and Dom0, paying particular attention to XSCA2 susceptibility to numa-effects on the CPUs. We love a mystery. The game is afoot!


Further Information
Test VM Spec.
CentOS6 x86_64 Linux, default install from distribution, updated with "yum update" 3-07-2014, with the following additional packages: wget, openssh-clients, iozone (3.424-2 x86_64). 2 vCPUs, 1GB RAM, 20GB virtual hard disk.
Test Hardware Spec.
AMD 6176 CPUs (x2), 192GB 1066MHz RAM, LSI 9260-4i RAID, 3x WD1000DHTZ, 2x SSDSC2BW12.
Test Hardware OS.
CentOS6 x86_64 (same as VMs).
Brand-X Hypervisor.
Latest version, chose the PV SCSI device.

Benchmark.
We used the continuous benchmarking feature of VMCo Virtual Estate Manager (VEM). VEM's benchmarking alerts administrators to performance regressions in your XenServer or VMware estate, whether they be caused by bugs, patches, hardware problems, subtle interactions between network elements or administrator misconfiguration. VEM's continuous benchmarking shows you where the performance regression is, when it started, and it's impact is.