Identify – Develop an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. The activities in the Identify Function are foundational for effective use of the Framework. Understanding the business context, the resources that support critical functions, and the related cybersecurity risks enables an organization to focus and prioritize its efforts, consistent with its risk management strategy and business needs. Examples of outcome Categories within this Function include Asset Management; Business Environment; Governance; Risk Assessment; and Risk Management Strategy.
Protect – Develop and implement appropriate safeguards to ensure delivery of critical services. The Protect Function supports the ability to limit or contain the impact of a potential cybersecurity event. Examples of outcome Categories within this Function include Identity Management and Access Control; Awareness and Training; Data Security; Information Protection Processes and Procedures; Maintenance; and Protective Technology.
Detect – Develop and implement appropriate activities to identify the occurrence of a cybersecurity event. The Detect Function enables the timely discovery of cybersecurity events. Examples of outcome Categories within this Function include Anomalies and Events; Security Continuous Monitoring; and Detection Processes.
Respond – Develop and implement appropriate activities to take action regarding a detected cybersecurity incident. The Respond Function supports the ability to contain the impact of a potential cybersecurity incident. Examples of outcome Categories within this Function include Response Planning; Communications; Analysis; Mitigation; and Improvements.
Recover – Develop and implement appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity incident. The Recover Function supports timely recovery to normal operations to reduce the impact of a cybersecurity incident. Examples of outcome Categories within this Function include Recovery Planning; Improvements; and Communications.
Legislation Related to Artificial Intelligence and the Lag in Ethics & Compliance Guidance for Implementation of Necessary Controls – Our (ISC)2 Training Journey for AI/ML with guest commentary from Jodi Masters-Gonzales, Brian Barnier, and Sean Lyons
Legislation Related to Artificial Intelligence and the Lag in Ethics & Compliance Guidance for Implementation of Necessary Controls – Our Training Journey for AI/ML
Owner EnterpriseGRC Solutions, President, ISC2 East Bay, Certified Information Systems Security (CISSP), Audit (CISA), Governance (CGEIT) and Risk (CRISC-NA), ICT GRC expert and early adopter in both certifying and offering certification programs for Cloud Security and Virtualization, with industry experience in the management of systems, controls and data for SaaS (IaaS and PaaS), Finance, Healthcare, Banking, Education, Defense, and High Tech. Positions held include Technology Officer at State Street Bank, Leading Process Engineering for a major New England CLEC, Sr. Director Enterprise Technology for multiple advisory firms, founding, engineering product, and running two governance software companies, and most recently Director Enterprise Compliance for a major player in the mortgage industry, Ellie Mae. Recently full-time at Cisco, Unified Compliance and ISMS Program Manager, Robin provides voluntary support to social platform security to further social democracy. Connect with Robin on LinkedIn
Cybersecurity professionals understand the many benefits and potential for Artificial intelligence (AI) security defense systems. The obvious concerns about potential misuse or unintended consequences of AI, however, have prompted efforts to examine and develop standards, such as the US National Institute of Standards and Technology (NIST) initiative involving workshops and discussions with the public and private sectors around the development of federal standards to create building blocks for reliable, robust, and trustworthy AI systems. State lawmakers must evaluate AI benefits against their potential for harm. This hour covers a summary of some of the State level initiatives, with emphasis on our State of California, and asks how we as cybersecurity professionals balance what we monitor, what we learn, and what we protect (CIA), and how we advise our clients as they acquire and implement increasingly AI dependent processes and technology.
EnterpriseGRC Solutions is a Governance Risk and Compliance company specializing in mapping cloud security and cyber security frameworks. We implement governance, ISMS, Risk Frameworks, and compliance automation products and programs. We emphasize system-based policies specific to security settings for secure configuration management. EnterpriseGRC is a women-owned small business offering compliance readiness, Security & GRC tools, Enterprise Security Architecture, Cybersecurity Risk Assessment, and a wide variety of resources for security and GRC technology support.
Reflexivity: The Cybersecurity Superpower You Haven’t Met Yet – Humble Science, PBLLC
Jodi Masters-Gonzales, FHCA Founder and Chief Futurist of Humble Science, PBLLC, Ph.D. researcher and board-certified Independent Auditor of AI Systems (IAAIS). Pending board certifications for Certified Expert In Cyber Investigations (CECI) (which includes Certified Cyber Intelligence Professional (CCIP), Certified Counterintelligence Threat Analyst (CCTA), Certified Organized Retail Crime Investigator (CORCI), Certified Social Media Intelligence Analyst (SMIA), Certified eCommerce Fraud Investigator (CEFI), Certified Forensic Hi-tech Investigator (CFHI)), and Certified All Source Intelligence Professional (CASIP). Recruited into InfraGard a few months ago, founding member and Vice Chair of the newly formed INMA Digital Exhaust Cross-Sector Council (announcement forthcoming.) One of ISC2’s newest members! Connect with Jodi on LinkedIn
Building upon industries’ general understanding of the current state of artificial intelligence, we explore indicators that reveal a wide range of algorithmic maturity throughout the entire ecosystem, including the cloud, IoT, supply chain, and the varied and various X-as-a-Service (Xaas) providers. As a result, the threat landscape is expanding exponentially into virtual and non-terrestrial spaces, forever blurring traditional protect surface boundaries. How did we get here and what are the critical skills required to build cybersecurity teams of the future? Learn the five key skillsets that will offset tomorrow’s threat landscape, and how to implement pragmatic solutions today to ensure agility and foresight capacities JIT.
About Humble Science, PBLLC
Pursuant to §§ 18-1202(a)-(b) of the Act, the LLC shall provide systemically, novel, and sustainable society-valued growth strategies and solutions to public and private stakeholders of the digital economy. In this era of data-driven intelligence, the LLC commits to approaching these uncharted areas of science with epistemic humility while striving to free the historically marginalized from unconquered systems of oppression. The LLC shall strive to strengthen the emerging digital economy—and its various markets—with checks and balances that incentivize positive-sum market innovation and a public return on public investments. The LLC shall have a positive effect on the centering of humanity in the exploration and discovery of sustainable artificial intelligence and quantum technologies capable of affecting the human condition at scale—with special emphasis on the economic, social and environmental challenges affecting the world’s poorest people.
Our Guest Moderators and Future Speakers – Future Topics involving Data Science, Critical Thinking and Predictive Analysis
Sean Lyons is the author of the influential book, “Corporate Defense and the Value Preservation Imperative: Bulletproof Your Corporate Defense Program”, which has been critically acclaimed by a host of distinguished corporate commentators. He has been internationally described as a value preservation activist, and a corporate defense author, pioneer, and thought leader. He is recognized as the first person to propose the umbrella term “Corporate Defense” to represent an organization’s collaborative program for self-defense. He is also acknowledged for being the first person to propose the extended “Five Lines of Defense” as a corporate oversight model which includes Executive Management and the Board of Directors as the all important 4th and 5th strategic lines of defense. As the architect of the cross-functional discipline of “Corporate Defense Management” (CDM), he is widely regarded as the foremost authority in this emerging field. Connect with Sean on LinkedIn
Brian Barnier is the co-founder of Think.Design.Cyber and the think-tank, CyberTheory Institute that bridges the gap between boards, business leaders, cybersecurity leaders and compliance. Brian has pioneered critical, systems and industrial design thinking in the cybersecurity discipline and the use of life-like scenario analysis to address critical issues of evolving threats/attacks, eliminate bad methods that cause breaches, waste money and resources and burnout cyber pros, affecting culture and retention. He is the author of The Operational Risk Handbook (Harriman House, Great Britain, 2011) used as a textbook by the London Institute of Banking & Finance. In 2020, Brian’s paper with expert Prachee Kale, “Cybersecurity: The Endgame — Part 1” was honored as the 2020 Article of the Year in the Taylor and Francis EDPACs journal. Brian has earned coveted achievement awards from two of ISACA’s most significant chapters. In 2021, he earned the highly distinguished Joseph J. Wasserman Award presented by ISACA New York Metro Chapter. In 2015, he received the V. Lee Conyers Award from ISACA Greater Washington DC. Deep in professional guidance, he is a co-author of ISACA’s Risk IT and COBIT, and the Shared Assessments Program. ISACA’s IT Audit Framework 2020 points to his work in risk assessment. He is one of the first three “Fellows” of OCEG — the Open Compliance & Ethics Group – the organization that created “Governance, Risk, and Compliance.” Connect with Brian on LinkedIn
ISC2 offers three Professional Development Institute courses on the topic of AI. After several months of collaborating together, Jodi Masters-Gonzalves and I (Robin Basham) decided that whatever we present to the ISC2 East Bay community should align with content authorized for study by our parent organization. To access the full courses, go to Cybersecurity Certification Training | Exam Prep (isc2.org)
Documentary Standards can specify the definition of terms; classifications of components; delineation of procedures; specification of dimensions, materials, processes, products, systems, services, or practices; test methods and sampling procedures; or descriptions of fit and measurements of size or strength. Under the National Technology Transfer and Advancement Act (NTTAA), NIST is assigned the responsibility to coordinate federal, state, and local documentary standards and conformity assessment activities.
Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics you need to know. (The Perils of Mount Must Read™ Confessions of a Cliff Note Junky) These resources go onto the "Mountain of Must Read". If you don't recognize the standard reference, you've missed critical understanding. As of 2022, this is the minimum NIST alphabet. All of these documents are found at https://csrc.nist.gov/publications/ Be very careful about static content. Look at links before you launch them. Never use alternate sites for the Computer Security Resource Center. Get the full list here <NIST Reading Extended>