Top Banner
#*%! my CISO Says Barry Caplin Chief Information Security Official Fairview Health Services Argyle CISO Summit Wed. Nov. 19, 2014 [email protected] [email protected] @bcaplin http://about.me/barrycaplin http://securityandcoffee.blogspot.com
34
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: #%! My CISO Says

#*%! my CISO Says

Barry Caplin Chief Information Security Official

Fairview Health Services

Argyle CISO Summit Wed. Nov. 19, 2014 [email protected] [email protected] @bcaplin http://about.me/barrycaplin http://securityandcoffee.blogspot.com

Page 2: #%! My CISO Says

Barry Caplin Chief Information Security Official

Fairview Health Services

tuff

Argyle CISO Summit Wed. Nov. 19, 2014 [email protected] [email protected] @bcaplin http://about.me/barrycaplin http://securityandcoffee.blogspot.com

Page 3: #%! My CISO Says

Security Isn’t Easy…

We didn’t get into it for the…

Page 4: #%! My CISO Says

And how do we get their attention and support?

Nobody cares about Security… The Challenge of Security Awareness

Why?

Page 5: #%! My CISO Says

Stuff happens…

Page 6: #%! My CISO Says

• Security viewed as a negative • Avoidance v. “risk”

– Delays – Cost – Extra work – “Gotchas”

Issues

Page 7: #%! My CISO Says

It Can’t Be Just…

Page 8: #%! My CISO Says

We need sensible controls…

Page 9: #%! My CISO Says
Page 10: #%! My CISO Says

… early in the process…

Page 11: #%! My CISO Says
Page 12: #%! My CISO Says

Good CISO/Bad CISO

Page 13: #%! My CISO Says

Governance Governance… We don’t need no stinkin’ governance!

Bad CISO

“Badges?...”

Page 14: #%! My CISO Says

Governance Develop a clear strategy using an industry standard framework.

Page 15: #%! My CISO Says

Policy All Security Policy is the same. I got mine from a book.

“Hello Mr. Anderson”

Bad CISO

Page 16: #%! My CISO Says

Policy Policies are based on solid principles, but adapted to fit the organization.

“Fate, it seems, is not without a sense of irony.”

Page 17: #%! My CISO Says

Compliance We write the policies. We make people sign an oath. Done.

“So there is a point you will not go beyond.”

Bad CISO

Page 18: #%! My CISO Says

Compliance We must make (understandable) policies. We must teach. We must assess, measure and report.

“It's like a finger pointing away to the moon...”

Page 19: #%! My CISO Says

Awareness Users will know what they have to do or be eliminated. Bad CISO

“The successful criminal brain is always superior. It has to be.”

Page 20: #%! My CISO Says

Awareness Users can talk to Security. We teach. We answer questions.

“Shaken, not stirred”

Page 21: #%! My CISO Says

Senior Management I say what they want to hear. They’re not listening anyway.

Bad CISO

“Why make a trillion when we could make... billions?”

Page 22: #%! My CISO Says

Senior Management Give them the info they need and they will be an engaged partner.

“Smashing Baby!”

Page 23: #%! My CISO Says

Bad CISO

“Your lack of faith is disturbing”

Business Needs I buy the best known security products because they’ve got to be good.

Page 24: #%! My CISO Says

“The Force is strong with this one.”

Business Need Working together we find control- and cost-effective security products that work and are usable.

Page 25: #%! My CISO Says

Stuff I Say…

KISS

Page 26: #%! My CISO Says

Stuff I Say…

No one has “read and understood” • but definitely still responsible • Simple, direct language in policy • Compliance via education

Page 27: #%! My CISO Says

Stuff I Say…

You pay by the word • Keep policies short and sweet • If not, you’ll pay on the compliance-effort side

Page 28: #%! My CISO Says

Stuff I Say…

People want to do the right thing • but what is the right thing? • Understandable policy • Simple rules

Page 29: #%! My CISO Says

Stuff I Say…

Do What Makes Sense • Risk Management approach • Seek out and destroy meaningless policy/controls/practices

Page 30: #%! My CISO Says

Stuff I Say…

Iterative Improvement • Maturity model • CObIT, SEI CMMI

Page 31: #%! My CISO Says

Stuff I Say…

Automation! • Metrics • Tools • Reporting

Page 32: #%! My CISO Says

Stuff I Say…

What is the business need? • Find out business need in plain business language

Page 33: #%! My CISO Says

Stuff I Say…

Have Fun!

Page 34: #%! My CISO Says

about.me/barrycaplin

Securityandcoffee .blogspot.com

@bcaplin