Development, Sales, and Services Enablement
ITIL Service Lifecycle – Serving Business of Product
SERVICE TRANSITION
- Change Management
- Service Asset and Configuration Management
- Release and Deployment
- Validation and Testing
- Evaluation
- Knowledge Management
- SERVICE DESIGN
- Service Catalog Management
- Service Level Management
- Capacity Management
- Availability Management
- Continuity Management
- Information Security Management
- Supplier Management
GRC Contributes by using a Cyber Security Model
- Identify – CMDB, People, Process, Technology, relationships, alignment to controls
- Protect – Architecture, Infrastructure, Monitoring
- Detect – Defined Sources, Collection, Interpretation, Reporting Methods
- Respond – RCA, Corrective Action, Management Meetings, Plans, Optimization Targets
- Recover – Configuration baselines, response plans, lessons learned, Wiki, documentation, BIA

GRC Security Metrics inform control design effectiveness
- Intrusion Detection Systems (IDS)
- Virus Alerts - Help Desk cases
- DLP events
- Vulnerabilities Identified, risk ranking, remediation, status
- Patch requirements and mean time to remediate MTTR
- Daily Anti-Virus status (Red, Yellow, Green), # of events blocked, cleaned, definition updates
- Daily endpoint patching, # of systems in and out of compliance
- % Daily system backups
- # of Volume created, # purged

**Assessment methodologies in 2022 have come a long way since this graphic was first released. SOC 2, NIST Cybersecurity Framework CSF, CCM STAR, FedRAMP, PCI DSS 3.21, NIST 171 DFARS and CMMC, ISO/IEC 27001 plus Cloud Certification, Privacy Certification and Processing, CIS CSC (8.1) name only a few.
Security Project Plans, Milestones, Issues, or Blockers
- Infrastructure remediation
- Post Implementation Effectiveness for corrected security problems (ROI)
- Template Configurations v. distinct
- Systems Monitored
- Services per systems
- Call Out to Configuration Management using Cobit® (check-in at https://isaca.org because Cobit is up to Revision 19 and the resources are out of this world.)
- Leverage Secure Email to Take Action: Confirm Incident Definitions, Review, & Response
- Scheduled outputs to the central mailbox (restrict delete)
- Track incident notifications
- Establish and RUN Rules for follow up
- Set Flags to communicate closed corrective action
- Only handle it once; make the message be the evidence
- IAM - People and Access – Provide Integrated Reporting
- PowerShell gathers local Admin accounts
- ADManager pulls all members in all groups
- Pearl Script flattens records
- Query to Dashboard active HR System users and record allowed Roles granted based on Job Title
- Grade effectiveness BY department (security roles and access grants)
- Publish exception policy and have management sign off at least quarterly
- Access Management – Program Management includes GRC, Systems, Security, and a Strategy
- How can audit drive security? Manage Corrective Actions!
Fact v. Impact
Evolving Tools Framework – Enterprise Security Architecture (ESA)
Data System Relationships to Audit, Classification, Risk Model & Assess
Information Asset Management is a foundation Program
- Asset Security – Data-Oriented Risks
- Identify where PII, PHI, and CHD is housed and accessible; Label (Classify) according to your company ISMS
- (Data Encryption) Protocol Governance has inputs and outputs to Enterprise Process and Risk Management
- Assets must be understood down to the protocols, network and networking, and encryption
- Document and Follow a Data Collection Practice
Implement a meaningful output process - Data collection strategy
- Source coverage – the architecture stack
- Test mapping – a single collection to many controls
- Validation process - independent
- Imports, Reference Tables, Security & Audit Queries
- Output to Corrective Actions tracking - Accountability
- Enable Management to use Executive Strategy to determine and implement their Risk Response
- The risks identified have actual probability – get the lessons learned
- In addition to collecting the results of planned exercises, the organization should make use of real events that further validate the BCP plan.
- Information Security and Enterprise Operations should work together to track and resolve known conditions that delayed reasonable recovery of service.
REMEMBER: Materiality
- Financial statement audits measure materiality
- Integrated Audit (Security and Internal Audit) provides IT assurance on non-financial items requiring alternative measures (maturity models and process assurance methodology).
- Conversations tend to focus on the value, investment, impact, and opportunity - money
- People may not remember your words, but they will always remember how you made them feel

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics