lnu.sePublikasjoner
Endre søk
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Solarwinds breach, a signal for a systemic enterprise view on Information Security
Linnéuniversitetet, Fakulteten för teknik (FTK), Institutionen för informatik (IK). (System Thinking)ORCID-id: 0009-0000-8265-0944
2021 (engelsk)Inngår i: The OR Society's 63rd Annual Conference, Operational Research Society, UK , 2021Konferansepaper, Oral presentation only (Fagfellevurdert)
Hållbar utveckling
Berör inget SDG
Abstract [en]

Once, system thinking was about singular systems. Today we exist in a far more complex world, with systems interacting with systems, directly or indirectly. Today's info security involves all systems in the chain; to use an old maxim, "No chain is stronger than its weakest link". The ICT world has become so interconnected that holistic system thinking is needed, with systems outside the organizational border to be involved and accounted for. ICT criminals are using increasingly sophisticated attack methods, often based on the victim's system architecture. In the Dec 2020 security breach at the network management firm Solarwinds in the US, an external party had added a trojan horse package to the Solarwinds management system. The hack gave the hackers stealth control of both Solarwinds as its 18.000 customers' internal system environments. Including high-security targets like the FBI, Homeland Security, and Microsoft. 

The attack was sophisticated, using the Solarwinds system knowledge, standards, and code layouts. Anyone not doing a deep survey would see Solarwinds code. The trojan was well-known but rewritten to the standards of the target. Solarwinds shows that we now entered a "new brave world", demanding a much more structural system discussion, how to protect our ICT. Based on this attack's sophistication, this was probably a 7- or 8-time successful attempt. We need solid enterprise-wide, system-coordinated security perspectives. But, how can we use system thinking to help plan a better and more cost-efficient security approach on an enterprise-level? For 14 years, this researcher worked with info security in a global automotive company, having the Viable System Model as its internal system model. When not "sabotage" by managers, yes, it happened; VSM worked fine. VSM also works fine with securing modern laws like GDPR when having an enterprise perspective. Info Security desperately needs enterprise system thinking.

sted, utgiver, år, opplag, sider
Operational Research Society, UK , 2021.
Emneord [en]
Data breaches, Info Security, Security Governance, System Thinking
HSV kategori
Forskningsprogram
Data- och informationsvetenskap, Informatik
Identifikatorer
URN: urn:nbn:se:lnu:diva-109132OAI: oai:DiVA.org:lnu-109132DiVA, id: diva2:1626733
Konferanse
The OR Society's 63rd Annual Conference, 14-16 september, 2021
Merknad

No conference abstracts or compilations was published from OR Society for the OR63 conference

Ej belagd 220121

Tilgjengelig fra: 2022-01-11 Laget: 2022-01-11 Sist oppdatert: 2024-08-28bibliografisk kontrollert

Open Access i DiVA

Fulltekst mangler i DiVA

Person

Magnusson, Lars

Søk i DiVA

Av forfatter/redaktør
Magnusson, Lars
Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric

urn-nbn
Totalt: 472 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf