Showing posts with label ISO standards. Show all posts
Showing posts with label ISO standards. Show all posts

Wednesday, November 25, 2020

Metrics & CISO Series

How well are digital forensic laboratories coping and performing, whether accredited to ISO17025 or not, in a Covid-19 world? Is Metrics relevant to digital forensics? 

In the first instance it largely depends whether there is a need for Qualitative and Quantitative (Q&Q) process in place that requires measurement to understand Capex, RoI, the performance of people and systems (for test and measurement), security (detection and prevention), information security management and so on. Where labs are tax payer funded then of course they should be scrutinised irrespective whether they are law enforcement or not. This isn't a criticism about public funded labs, but there does need to be a distinction made where private labs use capital expenditure to drive their operation to gain a return on investment. For both public/private large organisation Metrics shines a spotlight on the operational performance of these organisations (successes/failures).

In the second instance the simple is Yes but subject to if (?) the requirement exists of course. The question mark arises as to whether any implementation has taken place. Talking about it is one thing. Acting upon it is another. If the second question is considered first, it may reveal what impact there has been since Covid-19 and where to target resources.

Back in 2013 when the rumblings about ISO17025 were gathering pace a book came out titled (ISBN: 978-1-59749-742-8)  David Watson & Andrew Jones Digital Forensics Processing and Procedures Meeting the Requirements of ISO17020, ISO17025, ISO27001 and Best Practice Requirements Copyright 2013 Elsevier, Inc. This book shed light on the processes and procedures to run an accredited laboratory under ISO17025 plus associated dependency standards ISO17020 and ISO27001.  

There are other books, but as starting point Digital Forensics Processing and Procedures Meeting the Requirements of ISO17020, ISO17025, ISO27001 and Best Practice Requirements has multiple landing points in the book dealing with the need for Metrics. Furthermore, ISO27001 concerning information security is a very important standard, as is ISO9001 regarding quality assurance. The detail in this book extended further to provide to the broadest extent possible various ISO standards having application to accredited laboratories.

In addition to the above International standards there are national standards to be considered and Guidance from authorised bodies to oversee compliance. In the UK the Forensic Science Regulator (FSR) over sees the requirement for accredited laboratories. The latest FSR publication titled 'Codes of Practice and Conduct for forensic science providers and practitioners in the Criminal Justice System FSR-C-100 Issue 5' can be downloaded using the weblink below :

https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/880708/Codes_of_Practice_and_Conduct_-_Issue_5.pdf 

The Codes of Practice and Conduct identify standards etc the FSR considers fundamental to be able to use to assess compliance. Moreover, the Codes come with dependency obligations and one notable one is 'Information Legal Obligations FSR-I-400 Issue 7'. There is contained in this document the express requirement for production of 'Metric' results as a legal obligation which FSR-I-400 takes its direction from European Union Directive 80/181/EEC that sets out obligations on Member States to implement legal requirements with regard to the use of units of measurement. The FSR makes express use of these legal obligations that create implied terms that Metrics equally form part of the Codes assessment for compliance. The latest FSR-I-400 can be downloaded using the weblink below :

https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/795995/FSR_Legal_Obligations_-_Issue_7.pdf

It is the above matters arising from earlier released documents from FSR and various digital forensic books that set my project path for the last 15-months to see how the Professionals in the information security management, cybersecurity, risk assessment etc sectors identify the indicators to be sampled and measured for Metrics and how quality and accuracy is defined in these sectors. I have slowly been publishing my findings in a series of discussion papers and these can be downloaded using the weblinks below :

Metrics papers for cyber security & CISO.pdf Colourful, glossy, high-quality imaged research publications can look really good, but ultimately it is the depth of knowledge that has been gained from researching is what pays off. Why? How do you know your Metrics criteria is relevant to your organisation if you weren't sure what questions to address at the get-go?!

https://www.dropbox.com/s/kqsdo3dpsu2k03k/Metrics%20papers%20for%20cyber%20security%20%26%20CISO.pdf  

Importance of Metrics - The opening 'Foreward' in George Campbell's book "Measuring and Communicating Security’s Value A Compendium of Metrics for Enterprise Protection" (2015) [Elsevier - ISBN: 978-0-12-802841-4] is by Dave Komendat, Chief Security Officer The Boeing Company. Dave refers to why it is compelling how important Metrics are to a CSO.

https://www.dropbox.com/s/94ek2jxtrwwt3um/Importance%20of%20Metrics.pdf

Metrics, CPS & CISO - This is my third byte-size posting on Metrics. The pdf is only a scoping documents discussing in an understated conversational/readable way dealing with a subject-matter that is far more convoluted, complex and complicated.

https://www.dropbox.com/s/4u3c8lyn2k1gxx1/Metrics%2C%20CPS%20%26%20CISO.pdf

Metrics - Quality, Accuracy & more and CISO Part1

https://www.dropbox.com/s/t9sk46grg2p7xi9/Metrics%20-%20Quality%2C%20Accuracy%20%26%20more%20and%20CISO%20Part1.pdf

This discussion will be updated with further discussion papers to download.

Thursday, May 19, 2011

Aggregated SIM

Aggregated SIM

Interesting news story out of  Reuters that has been posted by many website that states that Apple has proposed a standardized SIM card smaller than those it currently uses in the iPhone and iPAD in order to be able to produce thinner devices, an Orange executive told Reuters on Tuesday. The news story also mentions Apple having gone along the Standards path and approached ETSI (European Telecommunications Standards Institute) and a hint that something could be seen as early as next year.

http://www.reuters.com/article/2011/05/17/us-summit-orange-apple-idUSTRE74G4WY20110517

This is SIM card developmental news and fascinating to watch as SIM and the microprocessor electronic card (ICC/UICC) that it uses takes further steps on its evolutionary journey.  We already know some of the form factors for ICC/UICC:

The integrated and non-integrated examples
Photobucket

A closer look at an integrated example
Photobucket

When SIM (subscriber identity module) cards were introduced for GSM (global systems for mobile) communication devices (handset/terminal devices) ETSI standardised the ID-1 format which was an ISO-size card as defined in the international standard ISO-7816 and commonly referred to as a 'credit card' size. A plug-in size (the size of a 'postage stamp') was also introduced and these designs are commonly seen in the standard GSM11.11. Distinctively, the shape, size and operational performance of the card means that the card, called an ICC- integrated circuit card (or Universal ICC following the introduction of 3G-WCDMA cellular radio) - should be distinguished from the SIM module, which is itself a programmable area on the card.   However, a further card size emerged and was defined in the 2004-03 ETSI standard TS 102.221 as "mini-UICC". It should be noted that where I have mentioned GSM11.11 this standard refers to the use of SIM cards with GSM technology and services. The lineage of GSM SIM and its standards are linked to ETSI standards including TS 102.221 and, of course, ISO standards. A similar path can be trod when dealing with U-ICC/U-SIM.

As for Apple's suggested development, what we don't know at this stage is what the aggregated SIM (but I think I might want to read that as form factor and size) will look like or its content for that matter. We can only guess at this stage.

Sunday, November 07, 2010

ISO 17025 Toolkit

ISO 17025 Toolkit

Members at the Institute for Digital Forensics (IDF) Group at LinkedIn (http://www.linkedin.com/)  we are discussing the creation of an ISO 17025 Toolkit and assistance that might be offered by other QA standards.

You will need to be an approved but free to join participant of the Institute's IDF Group to gain access to the materials.

Tuesday, June 15, 2010

Evidence and Admissibility Part 2

Evidence and Admissibility Part 2
.
In the first discussion on Evidence and Admissibility that appeared in Part 1 there was reference made to the International standards ISO17025 and ISO17020 and their proposed use as laboratory standards suited to forensics and evidence - http://trewmte.blogspot.com/2010/06/evidence-and-admissibility-part-1.html . In Part 2 further reference is made to ISO17025, the Forensic Science Regulator and UKAS and the Diplomas and their potential future influence dealing with evidence and admissibility. The purpose of making reference to these matters allows comparison to made between past technical, forensics and evidential events and potentially where the future lies when dealing with mobile telephone evidence.
.
The FSR (Forensic Science Regulator) as we know has identified a standard for laboratories that is said to be directly applicable to the field of digital mobile telephony, which is ISO/IEC 17025. To recap on background information; this is the main standard used by testing and calibration laboratories. This standard was formally known as ISO/IEC Guide 25. This standard contains many commonalities with QA standard ISO9000. When the second release of ISO17025 occurred in 2005 it did so based upon the agreement that its quality system wording was closely aligned with IS09000 version 2000. Readers may remember I referred to adopted principles in ISO17025 and QA standards in my previous posting Evidence and Admissibility Part 1.
.
So why is ISO/IEC 17025 applicable to all experts and examiners? Significantly, unlike ISO9000 and BS5750, this standard introduces the concept of, and the requirement for, 'competence' of the individual to be included into the equation because the standard applies directly to those organisations that produce testing and calibration results. The fit for purpose requirement of tools is set out under a different requirement, which is 'validation'. In order for 'tools' to remain valid equally relies upon the individual's competence, and at minimum should be:
.
a) Possess the highest competencies or attain them if the organisation is to rely on the individual to work with a tool;
.
b) To have been independently assessed by long-term experienced and skilled individuals as opposed to tool suppliers merely approving to get the sale of a tool;
.
c) Know what the 'tool' does;
.
d) Have the skills to assess whether the 'tool' is technically failing or systemically flawed in its operation;
.
e) To be able to maintain the 'tool's' performance - equally means maintaining an individual's skills;
.
f) To know and understand the requirements of future-proofing and sustainability.
.
How can the above be achieved? For sometime there has been a call for Mobile Phone Forensics Degrees but the Universities failed to take up the proposition. From enquiries made into this matter, it became clear the Universities, despite producing MSCs with one or half of one module containing something on mobile phone examination, the Universities do not have the competencies and skillsets for the work, nor could they identify the materials needed for the degrees or have the ability to assess student competence. That arises because the area is a specialism, thus requires a specialist approach and therefore this is no poor reflection on the academic brillance of Universities. So in this regard it makes no criticism of the Universities for not offering every specialism in the marketplace. This is why the Diplomas (http://trewmte.blogspot.com/2010/05/diplomas-mobile-telephone-evidence.html) have been introduced to solve this particular dilemma in the marketplace given the tens of hundreds involved with this field of distinction. The Diplomas provide a stepping stone to recognising 'competence', which currently examiners are being denied. Moreover, the modules have been prepared in the Diplomas to follow a similar structure to the way in which a student would undertake an MSC.
.
Another area where the Diplomas assist is in relation to cost. Currently MSC degrees cost between £3K to £7k per annum. The latest reported news in the media is that these tuition fees are set to increase even higher, maybe even skyrocket. The Diplomas work the other way around, the more modules you undertake the lower the costs become due to the way the discounts work. The encouragement to undertake the Diplomas therefore doesn't just include imparting real-world knowledge and experience passed on by seasoned professionals, but incentive discounts offered by uptake of the modules enables the securing in-advance of the professionals time which otherwise wouldn't be possible. Furthermore, and at the same time, they offer affordability to students.
.
Why is the way forward given above a better way than the current status quo? Neither the Forensic Science Regulator (FSR) or UKAS can approve the 'competence' of individuals for each particular field of forensic /evidential distinction. Universities as we know do not have the skillsets necessary to rollout degree courses in mobile telephone evidence. Specific to our field of distinction, the Mobile Telephone Examination Board (MTEB) was set up specifically to address peer review; the Diplomas are one way to gain peer review leading to recognition through the MTEB. The foundation to each of the modules in each of the Diplomas map principles to be found in simulated annealing for deterministic and random events that are often understood to be the basis of how evidence from mobile telephone usage occurs. The Universities gain from Diplomas as they work in harmony with them to aid students find the academic path to follow for a specific subject rather than the current way of devaluing and diluting other sciences and forensic fields to build up modules introduced into hybrid technology degree courses. So we need to understand the influences and impact of the quality or state of existing in or assuming different educational forms (generically speaking, polymorphic).
.
The future of mobile communications and its impact on society will grow even more than hitherto it has. The driving forces for this can be traced as much to remarks on future Global economies by industry illuminaries such as the head of LM Ericsson, the largest telecommunications manufacturer, when he said the future is "wireless" as much to the growth in smartphones and wireless smart devices and the newer wireless transmission and protocols, functionality and applications introducing diversity in the wireless world that looks set to surpass the cable world. However, to meet those exciting and progressive markets, Business can no longer afford to wait for degree students to flock out from Uni after 3 years and then spend another 1-2 year/s bringing them up to speed in the fast-changing wireless environment.
.
An example of fast-changing wireless environment which identifies sustained regular change can be found in the wireless standards used nationally and globally:
.
_____________________________________________________________
3GPP specifications
The term "3GPP specification" covers all GSM (including GPRS and EDGE) and W-CDMA specifications. The following terms are also used to describe networks using the 3G specifications: UTRAN, UMTS (in Europe) and FOMA (in Japan).
.
Revised versions of many of these specifications are produced up to four times a year following the quarterly TSG plenary meetings (TSG GERAN meets five times a year.)
_____________________________________________________________
.
The Diplomas take all of those conditions above, turn them around and re-work them. Students pursue the business goals first, being effective and self-managed at work, and then use the academic route to refine and hone particular, finite skills to optimise the end result for the benefit of the business. This model can assist Universities to get students wanting to achieve the technical hardcore goals in order to develop products, systems and services tailored from the diversity of the business enterprise and working environment. This can be so because the student's constructive thought process is based upon real-world exposure, not school-to-university idealogical observations. Moroever, there are examiners already working in the field who (a) have not had a fair opportunity to have their competencies recognised by (b) their peers and in the community. The Diplomas remove that unfair stigma for those mobile phone examiners being treated as second class.
.
So what are some of the future evidence and admissibility issues to be considered?
.
1. Recognised competence so reliance is NOT solely placed upon the tool; thus the removal of "push-button forensics" used to side-step the need for competency
.
2. Validation of tools will come about (thus side-stepping compliance is unavoidable). Indeed one particular tool developer agrees validation is entirely achieveable. So this is a step forward for validation, but again does not of itself qualify the 'competency' of the individual if trained to use the tool beyond gaining exposure to the tool's operation and use, but not the detail of the subject matter of the science, the technology using the science or, indeed, interpretation of outcomes or data.
.
3. Item 2 (above) is really a further qualification as to why the FSR and UKAS do not appear as candidates to qualify/recognise individual 'competency' in the subject matter or science.
.
In the next part, Part 3, the discussion deals with specific technical issues and their impact on evidence and admissibility.