Development, Sales, and Services Enablement

ITIL Service Lifecycle – Serving Business of Product

SERVICE TRANSITION

  • Change Management
  • Service Asset and Configuration Management
  • Release and Deployment
  • Validation and Testing
  • Evaluation
  • Knowledge Management
  • SERVICE DESIGN
  • Service Catalog Management
  • Service Level Management
  • Capacity Management
  • Availability Management
  • Continuity Management
  • Information Security Management
  • Supplier Management

GRC Contributes by using a Cyber Security Model

  1. Identify – CMDB, People, Process, Technology, relationships, alignment to controls
  2. Protect – Architecture, Infrastructure, Monitoring
  3. Detect – Defined Sources, Collection, Interpretation, Reporting Methods
  4. Respond – RCA, Corrective Action, Management Meetings, Plans, Optimization Targets
  5. Recover – Configuration baselines, response plans, lessons learned, Wiki, documentation, BIA

CSF domains

 

GRC Security Metrics inform control design effectiveness

  • Intrusion Detection Systems (IDS)
  • Virus Alerts - Help Desk cases
  • DLP events
  • Vulnerabilities Identified, risk ranking, remediation, status
  • Patch requirements and mean time to remediate MTTR
  • Daily Anti-Virus status (Red, Yellow, Green), # of events blocked, cleaned, definition updates
  • Daily endpoint patching, # of systems in and out of compliance
  • % Daily system backups
  • # of Volume created, # purged

GRC World

**Assessment methodologies in 2022 have come a long way since this graphic was first released. SOC 2, NIST Cybersecurity Framework CSF, CCM STAR, FedRAMP, PCI DSS 3.21, NIST 171 DFARS and CMMC, ISO/IEC 27001 plus Cloud Certification, Privacy Certification and Processing, CIS CSC (8.1) name only a few. 

Security Project Plans, Milestones, Issues, or Blockers

  • Infrastructure remediation
  • Post Implementation Effectiveness for corrected security problems (ROI)
  • Template Configurations v. distinct
  • Systems Monitored
  • Services per systems
  • Call Out to Configuration Management using Cobit® (check-in at https://isaca.org because Cobit is up to Revision 19 and the resources are out of this world.)
  • Leverage Secure Email to Take Action: Confirm Incident Definitions, Review, & Response
  • Scheduled outputs to the central mailbox (restrict delete)
  • Track incident notifications
  • Establish and RUN Rules for follow up
  • Set Flags to communicate closed corrective action
  • Only handle it once; make the message be the evidence
  • IAM - People and Access – Provide Integrated Reporting
  • PowerShell gathers local Admin accounts
  • ADManager pulls all members in all groups
  • Pearl Script flattens records
  • Query to Dashboard active HR System users and record allowed Roles granted based on Job Title
  • Grade effectiveness BY department (security roles and access grants)
  • Publish exception policy and have management sign off at least quarterly
  • Access Management – Program Management includes GRC, Systems, Security, and a Strategy
  • How can audit drive security? Manage Corrective Actions!

Fact v. Impact

Evolving Tools Framework – Enterprise Security Architecture (ESA)
Data System Relationships to Audit, Classification, Risk Model & Assess
Information Asset Management is a foundation Program

  • Asset Security – Data-Oriented Risks
  • Identify where PII, PHI, and CHD is housed and accessible; Label (Classify) according to your company ISMS
  • (Data Encryption) Protocol Governance has inputs and outputs to Enterprise Process and Risk Management
  • Assets must be understood down to the protocols, network and networking, and encryption
  • Document and Follow a Data Collection Practice
    Implement a meaningful output process
  • Data collection strategy
  • Source coverage – the architecture stack
  • Test mapping – a single collection to many controls
  • Validation process - independent
  • Imports, Reference Tables, Security & Audit Queries
  • Output to Corrective Actions tracking - Accountability
  • Enable Management to use Executive Strategy to determine and implement their Risk Response
  • The risks identified have actual probability – get the lessons learned
  • In addition to collecting the results of planned exercises, the organization should make use of real events that further validate the BCP plan.
  • Information Security and Enterprise Operations should work together to track and resolve known conditions that delayed reasonable recovery of service.

REMEMBER: Materiality

  • Financial statement audits measure materiality
  • Integrated Audit (Security and Internal Audit) provides IT assurance on non-financial items requiring alternative measures (maturity models and process assurance methodology).
  • Conversations tend to focus on the value, investment, impact, and opportunity - money
  • People may not remember your words, but they will always remember how you made them feel
Main Menu