Top Banner
Brad Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue
20

Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

May 17, 2018

Download

Documents

ĐỗĐẳng
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Brad Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue

Page 2: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Governance is the strategic alignment of operations with the agency such that maximum business value is achieved though the development and maintenance of effective control and compliance, performance management, and risk management.

Risk Control Compliance Agency

Page 3: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Risk

Controllership

Compliance

Assess

Manage

Monitor

Page 4: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Risk

•  Comprehensive Risk Assessments •  Goals and Objectives •  The Agency/Business •  Consulting •  Acquisition and Integrations •  Vision / Forecasting

Charts the Course: •  Direction •  Speed •  Destination •  Finish

Page 5: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Controllership

•  Policy Management •  Access Management •  Core Technology Standards •  Project Services •  Change Management •  Data & Asset Management

•  Policies •  Standards •  Procedures

The Operation: •  Fuel •  Power •  Storage •  Alterations

Page 6: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Compliance

•  Measure •  Self Audit •  Reporting •  Adherence •  Investigations •  Discipline

Gauging & Monitoring: •  Performance •  Inspections •  Correction •  Evaluate

Page 7: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Risk Compliance Controllership

•  Strategy •  Prioritization •  Risk acceptance •  Executive

•  Operations •  Digitization / Tools •  Policy Management •  Control Implementation

•  Compliance/Disclosure •  Audit Staff •  Office of Compliance

Who:

What: •  Assess compliance •  Report adequacy •  Standardization •  Performance &

Metrics

•  Risk Council •  Risk Champion

•  Controller •  Global Security •  Project Services

Governance – Program Building

Page 8: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Vision

Assess

Policy Control

Monitor

Report

Risk

Controllership

Compliance RISK

Page 9: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Probability X Impact = Inherent Risk (No Controls Applied)

Inherent Risk X Controllership = Residual Risk (Controls Applied)

Definition of RISK (Merriam-Webster) 1: possibility of loss or injury : PERIL 2: someone or something that creates or suggests a hazard

Page 10: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Probability X Impact = Inherent Risk (No Controls Applied)

Inherent Risk X Controllership = Residual Risk (Controls Applied)

H=3 M=2 L=1

H=3 M=2 L=1

H=1 M=2 L=3

IR

IR RR

Page 11: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Probability X Impact = Inherent Risk (No Controls Applied)

3 x 3 = 9

Inherent Risk X Controllership = Residual Risk (Controls Applied)

9 x 2 = 18

Control Considerations: 1)  Good Policy 2)  Intrusion Detection 3)  Security Guards 4)  Physical Barriers 5)  Logical Barriers

Page 12: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Probability X Impact = Inherent Risk (No Controls Applied)

3 x 2 = 6

Inherent Risk X Controllership = Residual Risk (Controls Applied)

6 x 1 = 6

Control Considerations: 1)  Good Policy 2)  Comprehensive System 3)  Research 4)  Communication 5)  Operations

Page 13: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Probability X Impact = Inherent Risk (No Controls Applied)

? x ? =

Inherent Risk X Controllership = Residual Risk (Controls Applied)

? x ? = ?

Control Considerations:

Page 14: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

1)  ISO 27001 & ISO 27005 2)  Cobit 5.0 (includes ValRISK) 3)  SP 800-30

Page 15: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with
Page 16: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

  Top Ten List: 10) Legacy/Out of Date Processes

9) Rules and Regulations/Policy Management 8) Unauthorized Access (Internal)

7) Integration and Consolidation 6) Change Management

5) End User Controls or Ad-Hoc Solutions 4) Theft of Data

3) Industrial Espionage 2) Virus Attacks or Malware

1) Hacking/Cyber Security

Page 17: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

CISO

Risk &Policy

DR & Recovery Services

Security Operations

Access Admin

Infrastructure

Compliance and

Disclosure

Specialist

Page 18: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Investment: Time Acceptance Change Culture

Benefits Structure/Alignment Stability Sustainability Best Practices Effectiveness Auditability Demand Management Tool Optimization Visibility Centralization

Page 19: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Vision

Assess

Policy Control

Monitor

Report

Risk

Controllership

Compliance

Page 20: Brad Boroff, CISA CRISC - Tax Admin Boroff, CISA CRISC Chief Information Security Officer Illinois Department of Revenue . Governance is the strategic alignment of operations with

Establish IT Governance Program

Structure & Approach

Proposal  to  establish  Governance  Program  (12-­‐24  Months  to  Develop  and  Implement)  

CISO Internal Audit

• Management  Commitment  and  Sponsorship  • Establish  Appropriate  Program  Resourcing    • Business  Engagement  &  Inclusion  • Ensuring  Con=nuous  Improvement  Planning  and  Program  Maturity  • Program  Auditabili=y  

 Governance

Program Management

• Obtain  Senior  IT  Leadership  CommiCment  •   Determine  &  Engage  internal  resources  • Develop  and  Deliver  Risk  Assessment  • Perform  Risk  and  Control  Analysis  • Control  Framework  Ac=vi=es    

Ini>al  Ac>vi>es  

Success  Factors  

Risk Assessments and Analysis

Control Management and Framework

Activities

Sr. Management approval of

Governance Concept and Implementation

Sustainable Governance Program

Monitoring and Compliance Mechanisms