Top Banner
CISO 90 Day Plan Nelson Chen, M.SC. IT CISSP, CISA, CISM
42

CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

Jul 18, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

CISO90DayPlan

NelsonChen,M.SC.ITCISSP,CISA,CISM

Page 2: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

Agenda

•  Whyarewehere?•  Days0–30•  Days31–60•  Days61–90•  Days90+•  Infinity&Beyond

Page 3: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

AvoidingReallyBadNews!

<Your Company Name Here>

Data Breach!

Page 4: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

Don’tbetheBlocker!

MAYBE

Page 5: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

Don’tbetheProphetofDoom

Page 6: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

ToughestPartoftheJob

Page 7: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

CISOPost-Breach

Page 8: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

0-30

EstablishingRelationships&Trust

Page 9: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

SellingCISOasaService

•  Businessenablement•  FUDisnottheonlypitch•  Education•  Sharedresponsibility•  Getsupportandbuy-in•  AddValue!

Page 10: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

TakingInitialInventory•  OrganizationalStructure-Who’swho– Execs,BULeaders,ITOps,InternalAudit

•  ExistingPolicies,Processes,etc.•  ExistingTechnologies•  Where’stheData?•  HistoricalSecurityIncidents•  ShadowIT

Page 11: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

LeadingTowardsBetterSecurity

Page 12: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

ServantLeadership

Page 13: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

SecuritySurroundsus,PenetratesusandBindsusTogether

Page 14: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

31-60

Prioritizing&ProjectKickoff

Page 15: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

BacktoBasics-CIATriad

Keepingitsecret

Keepingittogether

CentralOregonCommunityCollege

Keepingitup

Page 16: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

Fox-inorFox-out?

Page 17: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

TeamorCommittee?

Page 18: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

SecurityTeamBuilding•  BUInfoSecOfficers–Legal,Finance,Sales,Marketing,HR,Development,IT,etc

•  Committeedriven•  Executivesponsor•  Internalauditisyourfriend•  Wherearealltheresources?

KissPNG

Page 19: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

SecurityCommitteeGoals

•  BusinessSecurityMissionStatement•  AligningsecuritywitheachBU

-whatareweprotecting?

•  Takingdetailedinventory– Processes,Systems,Data,People

•  Budgetize,Prioritize,Projectize•  ReportingdirectlytoC-levels

KissPNG

Page 20: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

SecurityAssessment&GapAnalysis

•  CapabilityMaturityModel(CMMI)•  CybermaturityPlatform

Page 21: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

CMMIInstitute

Level5

Initial

Level1

Processesareunpredictable,poorlycontrolled,reactive.

Managed

Level2

Processesareplanned,documented,performed,monitored,andcontrolledattheprojectlevel.Oftenreactive.

Defined

Level3Processesarewellcharacterizedandunderstood.Processes,standards,procedures,tools,etc.aredefinedattheorganizational(OrganizationX)level.Proactive.

QuantitativelyManaged

Level4Processesarecontrolledusingstatisticalandotherquantitativetechniques.

Optimizing

Processperformancecontinuallyimprovedthroughincrementalandinnovativetechnologicalimprovements.

CMMI–5Levels

Page 22: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

WTF-OMGCompliance

Page 23: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

HowandWheretoFocus?

TheCybersecurityHubonTwitter

Page 24: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

CriticalBusinessProcesses

Apttus

Page 25: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

PatchManagementisParamount!

NationalLibraryofAustrailia

Page 26: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

DataInventory•  What,where,why,when&how•  Followthedatatrail•  Backups•  End-usercomputers•  Storagemedia•  Archivedapplications•  What’sintheCloud?

Page 27: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

DataClassification

•  Public,Internal,Confidential,Secret•  PII:Customer&Employee•  DefinedRepositories•  CommensurateSecurityLevels•  ManagedDataLifeCycle

Page 28: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

SecurityPolicy•  ComplianceDriven•  BusinessDriven•  Ownership•  3rdparty•  CustomerInput•  Training•  ControlsDesign&Mapping

–  CloudControlsMatrix(CCM)-CloudSecurityAlliance

Page 29: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

61-90

BuildingSecureFoundations

Page 30: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

SecurityvsSecurityOperations

SecOps

Wordpress

Page 31: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

SecurityAwarenessTraining

•  BusinessUnitRelevance•  JointdeliverywithBU-ISO•  Compliancedriven•  Sec-Dev-OpsTraining•  Relevant3rdPartytraining

Page 32: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

ApplicationSecurity•  Everycompanyisatechnologycompany

•  In-housevs3rdParty•  SecureSDLC•  Training•  yourWebapp!

Verizon2018DBIR

Page 33: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

BusinessContinuity

•  BusinessProcessDriven•  DisasterRecovery– DefinedRTOs&RPOs

•  BackupStrategy•  DenialofService•  Testing

StepupIT

Page 34: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

PreparefortheWorst

Page 35: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

DataBreachPreparedness•  BreachScenarioPlanning•  Table-topExercises•  DecisionTree•  Detection&Logging•  ContactLists•  Time-to-Notify•  Bitcoins?!

DataBreachResponse

Plan

INCASEOFEMERGENCYBREAKGLASS

Page 36: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

Customer-FacingSecurity

•  SecuringClientServices•  SupportingSales•  CustomerSecurityCompliance•  VendorSecurityQuestionnaires•  LegalAgreements–SecurityLanguage

Page 37: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

90+

Page 38: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

SecurityisaBoard-levelProblem

Page 39: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

Andamessagefromthe

•  OnNovember1,2018,DataBreachNotificationLawswillbeenforcedinCanada

Page 40: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

KEEPCALMDOTHE

RIGHTTHINGANDCYA

Page 41: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

TheTribeHasSpoken…

NOT ME

Page 42: CISO 90 Day Plan - owasp.org · 4/28/2018  · • Business Security Mission Statement • Aligning security with each BU - what are we protecting? • Taking detailed inventory –

ChiefI’mtheScapegoatOfficer

Questions?