News

Latest stories from POSTECH EE.

[Leaders Forum] Two Proposals for Responding to Information Security Incidents

Articles | 2014-03-07

Related article: Electronic Times. Two Proposals for Responding to Information Security Incidents — Pil Joong Lee, Professor of Electrical Engineering.

Hearing about privacy breaches such as the recent credit card crisis and how they have been handled, I find the situation regrettable and would like to make two proposals that I consider important.

When the maritime leader Jang Bogo established Cheonghaejin, his first step is said to have been to strengthen his naval forces and defeat pirates. He continued to involve those forces in regional maritime trade. Presumably, he did not put a trade specialist in charge of the navy. Yet Korean conglomerates and financial institutions often appoint people with no security expertise as chief information security officers (CISOs), in the name of job rotation. Such appointees reportedly feel sidelined or fear that they will have to leave the company if something goes wrong.

Under CEOs who assess investments in terms of returns, CISOs generate no direct revenue and are naturally undervalued; when problems arise, they commonly become scapegoats. We must change our perspective: security investment should be judged by the losses it prevents, rather than the profits it generates.

A recent report said financial firms struggle to find qualified CISOs and called for government and industry to develop concrete, sustained training measures from a medium- to long-term perspective. It is encouraging that firms are trying to appoint experts. But however much training is attempted, low pay and great responsibility discourage people from entering the field. Even those who become experts will move to better-paid, less burdensome jobs. Clear allocation of accountability, together with high compensation that makes people want to become security specialists, is the first step toward developing the profession properly.

Korea's resident registration number system has many strengths as well as weaknesses. Using the number for identification is not itself problematic apart from the disclosure of private information encoded within it. The real problem is using it for authentication. Authentication requires knowledge only the person possesses, something only they own, or unique physical or behavioral characteristics. Resident registration numbers ceased to function as private knowledge long ago. It is astonishing that they are still used for authentication even after substantial time has passed since massive personal data leaks.

Various alternatives have been proposed. We should promptly select an appropriate one, adopt it for authentication and legally prohibit resident registration numbers from serving that purpose. A database will need to connect resident registration numbers to the new authentication identifiers. But if both are stored together, a breach renders the new method useless. I therefore stress that the two must be separately encrypted and physically stored apart.

Original source link

j-v-a-s-c-r-i-p-t:;

969314_1_1394172701751.jpg
Back to list