Sunday, March 27, 2016

Securing the Critical Infrastructure Enterprise

When we first discussed security as a critical component of Enterprise Architecture, it was in the context of the cyber attacks on the personal and financial information that hurts individuals and business brands, ultimately  translating into billions of dollars lost. This reflection however, even goes farther beyond this context, with larger losses, and presents the biggest scale of cyber security threats. 

Cyber Attack Vectors

On March 4, 2007, the Idaho National Laboratory demonstrated the so-called Aurora vulnerability, to show how an attack which gains access to a controller, can cause physical damage to components to critical infrastructure like the power grid. Although the Aurora exploit is essentially an electrical (physical) event, the current use of networked software controlled technologies allows the exploit to be caused by a cyber attack.  This Aurora type of attack should not be confused with the 2009 cyberattack on top silicon valley companies similarly called "Operation Aurora". Indeed in 2014, there was that confusion which inadvertently led to DHS records folks to release classified information on the 2007 Aurora Idaho experiments. But that is a completely different story.

Fast forward to December 23, 2015, when a significant portion of western Ukraine lost power for nearly 6 hours. ICS-CERT (US DHS) reports that power outages were caused by remote synchronized cyber intrusions at three regional electric power distribution companies (all from Oblenergo). Experts attribute the cyberattack to the Russian 'Sandworm' hacker group, enabled through email spear phishing and malware (BlackEnergy) as an initial access vector to acquire legitimate credentials. Extensive mapping of the system may have been done prior to actual attack, enabling shut down of the systems. Indications showed execution of the KillDisk malware towards the end, which erases selected files on target systems and corrupts the master boot record, rendering systems inoperable. The attack disabled company phone systems, blocking customer outage reports; disconnected backup power supplies, delaying recovery and restore procedures.   

Impact:  Close to 50%  of its 538,000 customers: Prykarpattya Oblenergo, reported 27 of its substations went dead, 103 cities were "completely blacked out," and another 186 cities were left partially in the dark. 

Cascade Effects:  Observers have placed a plausible assumption that this is a Russian retaliation for the anti-Russian attacks on the power grid supplies to the recently annexed Crimea (by Russia in 2014).  Interestingly, the Ukrainians may have been saved by the fact that their country relies on old technology and is still not as fully wired as many western nations. Oblenergo eventually switched to manual controls and dispatched teams around the region to manually flip switches back "on," ending the outage within a few hours. In retrospect, the attack may have been merely a signal warning. But  the crash adequately illustrated the potential damages to grid-dependent physical infrastructures, loss of economic production, environmental damages, theft and chaos, as well as significant deaths and casualties. Ultimately, the exploit shows that the power grid itself is a critical attack vector -- a conduit to disable other critical infrastructures, expose the state to more attacks, lead to a possible kinetic cyberwar, and dangerously heightened escalations of political conflicts in the region. This was the first time that a known Aurora type exploit was actually executed -- and executed by a nation-state.

More details at: https://ics-cert.us-cert.gov/alerts/IR-ALERT-H-16-056-01

Critical Infrastructure Sectors

The Department of Homeland Security has designated 16 critical infrastructure sectors and defines these as enterprises whose assets, systems, and networks, whether physical or virtual, are considered so vital to the United States that their incapacitation or destruction would have a debilitating effect on national security, economic stability, national public health or safety.  These includes key industry players in the following sectors:  1.) Chemical  2.) Commercial Facilities 3.) Communications 4.) Critical Manufacturing  5.) Dams  6.) Defense Industrial Base  7.) Emergency Services  8.) Energy  9.) Financial Services  10.) Food and Agriculture  11.) Government Facilities  12.) Healthcare and Public Health  13.) Nuclear Reactors, Materials, and Waste  14.) Transportation Systems  15.) Water and wastwater  16.) Information Technology. 

The Information Technology Sector includes those functions which produce and provide hardware, software, systems and services which in tandem and collaboration with the Communications Sector,  develops and operates the vital backbones of  the Internet. As the world and industries continue to form their dependencies on computer technologies and the internet, the IT infrastructure has become a significant part of critical infrastructure security. 

More details at: https://www.dhs.gov/critical-infrastructure-sectors

Enterprise Architecture Framework for Critical Infrastructure Enterprises

Given these discussions, it is clear that a Cyber Security Architecture for Critical Infrastructure should be a significant component of the enterprise architecture framework, if the discipline wants to maintain its relevance as a strategic tool.  Risk management and cyber security must be essential EA components  in order to emphasize and prioritize the development and management of a risk-based integration of compliance controls and technologies, aligned and balanced with business-driven requirements. As newer technologies are introduced to build business capabilities, the security assessment of these technologies need to be in place across the enterprise, to check for security gaps in their adoption policies, vetting procedures, and deployment practice. A Security Framework would enable a prioritized, flexible, repeatable, performance-based, cost-effective approach, ensuring effective deployment of information security measures and controls, in order to help owners and operators of critical infrastructure identify, assess, and manage cyber risk.

The NIST Resources

The NIST  is the forefront security standards body in the U.S. and globally collaborates closely with ISO.  The NIST-800 series provides ample references and frameworks that both public and private organizations can use to implement security architecture for the enterprise.

The mission of NIST's Computer Security Division is to improve information systems security via programs with the following goals:

The NIST site has a rich set of literature resources to assist on the following topics:


More details at:  http://www.nist.gov/itl/csd/

Resilience As a Capability

DHS defines "resilience" as the ability to adapt to changing conditions in order to withstand and rapidly recover from disruption due to emergencies from all hazards including cyber attacks. The development of resilience should include systems hardening, adaptive capabilities, readiness of facilities, and availability of contingency funds and supplies for business continuity and recovery operations. Resilience is operationalized by using systems-thinking within a framework based on the following principles: 1.) Adaptiveness to changing conditions using enhanced collaboration and coordination protocols. 2.) Better adoption of resilient systems with dynamic real-time situational awareness capabilities. 3.) Modernize systems to address industrial control system (ICS) component vulnerabilities.   4.) Rapid response assurance via preparedness programs that place significance on wide participation and public-private partnerships, particularly with other owners and operators of critical infrastructure and key resources.   5.) Improve incident response and reporting capabilities via enhanced sharing protocols for information on cyber threats, exploits, vectors, mitigations, and lessons learned.  6.)  Support and participate in large-scale real-world simulations to assess emergency communications. 7.) Support the adoption of national common industry standards, practices, policies, with compliance to legislative/regulatory provisions. 8.) Strengthen the cyber ecosystem via global networks, international collaborative communities and public-private partnerships to include research institutions and academia.

More details at: https://www.dhs.gov/sites/default/files/publications/qhsr/2014-QHSR.pdf

Conclusion

The attack vectors for cyber exploits can be blocked with better technologies and practices. While more so for critical infrastructure enterprises, regular business organizations should also establish solid security architectures because any enterprise connected to the internet, by default, becomes a potential conduit for attack vectors ultimately trailed towards critical infrastructure. This was sharply illustrated by how Stuxnet was spread.


The ICS Context Industrial Control Systems
A multilayer defense-in-depth architecture, protecting SCADA and PLC's (Programmable Logic Controllers)   Source: Security hardware for industrial networking,  http://www.iebmedia.com/


The Siemens Simatic S7-300 PLC,  Target of the Stuxnet Attack of 2010.

The sophisticated vector was specifically targeted not only for the Siemens PLC, but for that PLC in a specific environment configuration - the Iranian Nuclear Plant.

Source:  PBS video, Cyberwar Threat,
http://www.pbs.org/wgbh/nova/military/cyberwar-threat.html

What EA can do to help.   An effective and highly valuable EA initiative would be to help launch training, awareness, and education of organizations which include, for starters, sound patch management and practical security operations e.g. scanner updates, trojans in attachments, etc.  Moreover, while we revisit the set of presentation materials and toolkits that we have been inspecting from the Gartner sets, we will need to assess and update many of the EA discussions to ensure that we include a methodology for addressing the security gaps in our IT capabilities, and make security and resilience capabilities a development goal and part of the EA roadmaps that we provide.

The value proposition of Enterprise Architecture would have a gaping hole if Risk Management is not a key element in its discipline -- it is one vulnerability of the EA discipline itself that must be addressed.



Sunday, March 20, 2016

Keeping An EA Eye Out For Trends


Before we head out of Future State and dive into Current State discussions, I thought of asking one more thing: Did we remember to discuss trends convincingly in communicating future state vision? 

The list of mortal sins for the enterprise architect is hopefully not a long list, but I think that it would definitely include possession of a vague, if not cobwebbed, list of technology trends. After all, how can we show the best advisory posture to get organizational buy-in, if we're still selling old stuff? Porter reminds us that constant innovation is the key to competitive advantage. 

Gartner defines a strategic technology trend as one that can have a significant impact on the organization, and includes those with a high potential for disruption to the business, end users or IT, the need for a major investment, or the risk of being late to adopt. These are technologies which impact the organization's long-term plans, programs, and initiatives. In other words, these are the exciting stuff that can make enterprise architects look like rock stars.

Last year, Gartner wrote about the top 10 strategic technology trends for 2016 which they believe can shape business opportunities through 2020. I have incorporated my own small comments into the salient points of the listing.

1.) The Device Mesh. The device mesh promotes connectivity and collaboration, and refers to an expanding set of endpoints people use to access applications and information, or interact with people, social communities, governments and businesses. The device mesh includes mobile devices, wearable, consumer and home electronic devices, automotive devices and environmental devices — such as sensors in the Internet of Things (IoT).

2.) Ambient User Experience.  This pushes connectivity further by making it continuous. The device mesh creates the foundation for a new continuous and ambient user experience. Immersive environments delivering augmented and virtual reality hold significant potential but are only one aspect of the experience. The ambient user experience preserves continuity across boundaries of device mesh, time and space. The experience seamlessly flows across a shifting set of devices and interaction channels blending physical, virtual and electronic environment as the user moves from one place to another

3.) 3D Printing Materials. This trend will make us rethink the assembly line and supply chain processes. Advances in 3D printing have already enabled 3D printing to use a wide range of materials, including advanced nickel alloys, carbon fiber, glass, conductive ink, electronics, pharmaceuticals and biological materials. These innovations are driving user demand, as the practical applications for 3D printers expand to more sectors, including aerospace, medical, automotive, energy and the military. The growing range of 3D-printable materials will drive a compound annual growth rate of 64.1 percent for enterprise 3D-printer shipments through 2019.

4.) Information of Everything.  Aka Big Data. Everything in the digital mesh produces, uses, and transmits information. This information goes beyond textual, audio and video information to include sensory and contextual information. Information of everything addresses this influx with strategies and technologies to link data from all these different data sources. Information has always existed everywhere but has often been isolated, incomplete, unavailable or unintelligible. Advances in semantic tools such as graph databases as well as other emerging data classification and information analysis techniques will bring meaning to the often chaotic deluge of information.

5.) Advanced Machine Learning.  Combined with big data availability, machine learning can bring significant insights on what the customers want and will want. While data mining focuses on the discovery of properties in data, machine learning focuses on prediction based on known properties learned, and the discovery of patterns. In advanced machine learning, deep neural nets (DNNs) move beyond classic computing and information management to create systems that can autonomously learn to perceive the world, on their own. The explosion of data sources and complexity of information makes manual classification and analysis infeasible and uneconomic. DNNs automate these tasks and make it possible to address key challenges related to the information of everything trend.

6.) Autonomous Agents and Things.  This trend will change how we enter data into systems, including those for medical transcripts. Machine learning gives rise to a spectrum of smart machine implementations — including robots, autonomous vehicles, virtual personal assistants (VPAs) and smart advisors — that act in an autonomous (or at least semiautonomous) manner. While advances in physical smart machines such as robots get a great deal of attention, the software-based smart machines have a more near-term and broader impact. VPAs such as Google Now, Microsoft's Cortana and Apple's Siri are becoming smarter and are precursors to autonomous agents. The emerging notion of assistance feeds into the ambient user experience in which an autonomous agent becomes the main user interface. Instead of interacting with menus, forms and buttons on a smartphone, the user speaks to an app, which is really an intelligent agent.

7.) Adaptive Security Architecture.  Ignore risk management at your own career risk. The complexities of digital business and the algorithmic economy combined with an emerging "hacker industry" significantly increase the threat surface for an organization. Relying on perimeter defense and rule-based security is inadequate, especially as organizations exploit more cloud-based services and open APIs for customers and partners to integrate with their systems. IT leaders must focus on detecting and responding to threats, as well as more traditional blocking and other measures to prevent attacks. Application self-protection, as well as user and entity behavior analytics, will help fulfill the adaptive security architecture.

8. Advanced System Architecture. If you have convinced your organization to go big data, this trend can force your organization's hand to go cloud. The digital mesh and smart machines require intense computing architecture demands to make them viable for organizations. Providing this required boost are high-powered and ultra efficient neuromorphic architectures. Fueled by field-programmable gate arrays (FPGAs) as an underlining technology for neuromorphic architectures, there are significant gains to this architecture, such as being able to run at speeds of greater than a teraflop with high-energy efficiency.

9. Mesh App and Service Architecture. If you have not yet promoted SOA in your organization, you can't go to the next level. Monolithic, linear application designs (e.g., the three-tier architecture) are giving way to a more loosely coupled integrative approach: the apps and services architecture. Enabled by software-defined application services, this new approach enables Web-scale performance, flexibility and agility. Microservice architecture is an emerging pattern for building distributed applications that support agile delivery and scalable deployment, both on-premises and in the cloud. Containers are emerging as a critical technology for enabling agile development and microservice architectures. Bringing mobile and IoT elements into the app and service architecture creates a comprehensive model to address back-end cloud scalability and front-end device mesh experiences. Application teams must create new modern architectures to deliver agile, flexible and dynamic cloud-based applications with agile, flexible and dynamic user experiences that span the digital mesh.

10. Internet of Things Platforms. IoT platforms complement the mesh app and service architecture. The management, security, integration and other technologies and standards of the IoT platform are the base set of capabilities for building, managing and securing elements in the IoT. IoT platforms constitute the work IT does behind the scenes from an architectural and a technology standpoint to make the IoT a reality. The IoT is an integral part of the digital mesh and ambient user experience and the emerging and dynamic world of IoT platforms is what makes them possible.

Reference: Gartner (2015 October 6). Gartner Identifies the Top 10 Strategic Technology Trends for 2016. Press Release. Retrieved from http://www.gartner.com/newsroom/id/3143521

I was supposed to discuss a different set of trends but thought of sending this ahead instead. This should be a good segue to future blogs on more trends.

Cheers and please remember to keep it light.

/

Sunday, March 6, 2016

Viewpoints - Understanding Our Stakeholders


In my previous reflection, the notion of viewpoints was raised to make sure we mark that these are mechanisms which help us remember why we do what we do, as advocates of EA.

Viewpoints represent each group of stakeholders' interest on the architectures, i.e.  A particular viewpoint takes a focused slice through any or all of the 4 layers of the future state (Business, Information, Application, Technology) to make sure that IT initiatives are taking care of their concerns. 

I think Schekkerman provides one of the clearest explanations for views and viewpoints. Using ANSI/IEEE Std 1471- 2000, he shared the definitions from the standard, and I, in turn, share it here, and provide it verbatim:


A system is a collection of components organized to accomplish a specific function or set of functions.

The architecture of a system is the system's fundamental organization, embodied in its components, their relationships to each other and to the environment, and the principles guiding its design and evolution. An architecture description is a collection of artefacts that document an architecture.

Stakeholders are people who have key roles in, or concerns about, the system: for example, as users, developers, or managers. Different stakeholders with different roles in the system will have different concerns. Stakeholders can be individuals, teams, or organizations (or classes thereof).

Concerns are the key interests that are crucially important to the stakeholders in the system, and determine the acceptability of the system. Concerns may pertain to any aspect of the system’s functioning, development, or operation, including considerations such as performance, reliability, security, distribution, and evolvability.

A view is a representation of a whole system from the perspective of a related set of concerns. In capturing or representing the design of a system architecture, the architect will typically create one or more architecture models, possibly using different tools. A view will comprise selected parts of one or more models, chosen so as to demonstrate to a particular stakeholder or group of stakeholders that their  concerns are being adequately addressed in the design of the system  architecture.

A viewpoint defines the perspective from which a view is taken. More specifically, a viewpoint defines: how to construct and use a view (by means of an appropriate schema or template); the information that should appear in the view; the modeling techniques for expressing and analyzing the information; and a rationale for these choices (e.g., by describing the purpose and intended audience of the view).

Every view has an associated viewpoint that describes it, at least implicitly. ANSI/IEEE Std 1471-2000 encourages architects to define viewpoints explicitly. Making this distinction between the content and schema of a view may seem at first to be an unnecessary overhead, but it provides a mechanism for reusing viewpoints across different architectures.

--------------------------------------------------------------------------------------------------------
In his paper, Schekkerman continues to expand on these notions with his concept of extended viewpoints and viewpoint themes, which helps us understand that we can continue to define viewpoints as long as these help define stakeholder's concerns --  so we can make them happy with the EA which we create for the organization. His paper discusses economic, legal, ethical, and discretionary viewpoints as examples of viewpoint extensions.

From these discussions,  I think  we can simply say that a view is the object (say architecture) in front of us. In turn,  we can perhaps say that a viewpoint is a deliberate focus on specific things about the view which concerns us  - the vantage point or perspective that determines what we selectively see about the object.

This discussion can perhaps be assisted with an analogy -- again the car.  The following provides a singular notion of the car view (in this case, the total architecture). Using our definitions, we can think that different viewpoints project a specific "slice" that is significant to each different group of eyes (stakeholder group).

The brake system


The Cooling system










The Electrical system


The Transmission system






In conclusion,  we return to why viewpoints are important. These are the abstractions which allow us to stay clearly connected to the stakeholders who ultimately, our enterprise architecture needs to satisfy.

Springman's HBR article mentions research which shows that organizations who place stakeholders’ interests ahead of profits generate greater workforce engagement -- and thus deliver the superior financial results that they have made a secondary goal. This is indeed, counter-intuitive, but appears to hold true.

He argues for a strategy to engage stakeholders:  First, identify the stakeholder groups and their concerns. Next, create a value proposition for each stakeholder group.  This value creation for each stakeholder group needs to be balanced by what the business will gain in return -- the value it will extract from the relationship. The next step is to track the costs and benefits associated with each value proposition, including the investment necessary to complete the initiatives required to fill the capability gaps you’ve identified. And finally, determine a set of key performance indicators. These should track how effectively the business is creating value for each stakeholder group and how well you’re capturing value in return. 

"Defining the value created for and from each stakeholder group adds perspective, ensuring that you look at your business from all angles. And by focusing on value creation for all your different stakeholders, you will be a creating a business that is more sustainable -- in all senses of the word."

Helpful References:

Schekkerman, J. (2006 January ).  Extended Enterprise Architecture Viewpoints Support Guide.  White Paper. Institute For Enterprise Architecture Developments.  Retrieved from http://www.enterprise-architecture.info/Images/E2AF/Extended%20Enterprise%20Architecture%20ViewPoints%20Support%20Guide%20v18.pdf

Springman, J. (2011 July). Implementing a Stakeholder Strategy. Web Article. Harvard Business Review.  Retrieved from https://hbr.org/2011/07/implementing-a-stakeholder-str

The Open Group. (n.d.). Developing Architecture View. Online Documentation.  The Open Group. Some of the material is from The Command and Control System Target Architecture (C2STA), which was developed by the Electronic Systems Center (ESC) of the US Air Force between 1997 and 2000. Retrieved from http://pubs.opengroup.org/architecture/togaf8-doc/arch/chap31.html

Steen, M.W.A,  Akehurst, D.H., ter Doest, H.W.L.,  Lankhorst, M.M. (2004). Supporting Viewpoint-Oriented Enterprise Architecture. Research Paper. Proceedings of the 8th IEEE Intl Enterprise Distributed Object Computing Conf (EDOC 2004), 1541-7719/04. Retrieved from PSU Library Online.