Showing posts with label alignment. Show all posts
Showing posts with label alignment. Show all posts

Tuesday, July 1, 2014

CISOs are from Mars, CIOs are from Venus


   I recently had the opportunity to speak at the Argyle CIO Leadership Forum in Chicago.  I sat on a couple of panels and had some fun delivering a talk called "CISOs are from Mars, CIOs are from Venus" (slideshare).
   There was a clear theme of cloud, mobile and BYOD.  There were both CIOs and CISOs in attendance so there were different perspectives on these challenges.  That certainly tied into my closing keynote.

   After the conference I was interviewed by the conference organizer.  The interview will be posted on the conference website, but here is a copy:

Tuesday, April 1, 2014

What's a CISO Do?

   A while back I started a new job as a CISO.  It's the second time I've held that title at an organization.  What's interesting about that is that both time it was a new position to the organization.  I wrote about my initial thoughts and plans in a post here.  That was before I started the job!  I've been meaning to follow up on that post, both to provide more insight and list next steps.

   In this post I'll dive a bit into the execution of the plans I originally discussed.  In another post I'll get into what came next, including the weightier topics of strategic and tactical plans.

   And yes, I know it's April 1st, but I'm keepin' it real!

   For my first 90 days on the job I tried to keep focus toward three key accomplishments:
  • Learn the business;
  • Start to establish a Culture of Security, and;
  • Baseline the environment.
   Let's talk a bit about each of these areas.

Tuesday, December 17, 2013

f2f Still Rules

   It's definitely a digital world.  And with all the instant electronic communication methods available, it's easy to forget about good old-fashioned face-to-face.

   Many work places have gone to open seating, without cubes or offices, to promote collaboration.  There are "team spaces" and other kinds of open areas in which people can quickly get together to solve problems.

   I've been thinking about this topic for a couple reasons.  First, I've been talking with internal groups about Internet Safety for Families.  This is a great topic both for general information and for Security Awareness in the workplace.  One item we often discuss is communication methods.  Teens and young adults (as well as many high-tech workers) do a disproportional amount of their communication electronically.  Sometimes that works and sometimes it doesn't.

Tuesday, October 1, 2013

Things That Make Me Crazy: "We've Always Done it This Way"

   There aren't many things about our InfoSec and IT industry that really bug me.  There are certainly things we can do better.  We're really just starting to get the idea of connecting with the business and that business leads technology (not the other way around).  Or that security controls and technology have to work for people.  These ideas are part of our evolutionary process.

   But there are some things that do get to me.  Call them pet peeves (what a strange phrase!),
annoyances, complaints... whatever.

   Right at the top of the list is when someone says "We've always done it this way".

Tuesday, September 24, 2013

So You're a New CISO!?

   There are plenty of articles out there about becoming a new CISO.  And what elements you should have in an enterprise security program.

   I'm about to become a new CISO... again.  It's not an entirely unique situation.  I've been a CISO for over 10 years.  I'm starting as a new employee of an organization that has newly created the CISO position.  So I am new, and the CISO position is new, to this organization.

   I read this interesting article entitled 68 Great Ideas for Running the Security Department.  It's a great article, but even as a mathematician, I just can't count that high!  I also love top 10 lists.  But sometimes 10 is too high a number as well.

   Here are the 3 key things I'm going to do as a new CISO:

Tuesday, August 27, 2013

People and Process First!

   I've been reading, and hearing, lately about the ideas of client-centric or human-centric IT.  Here's a cool article and interactive infographic from GovLoop.com.  It describes a roadmap approach to get to a people-centric approach while showing examples of what some US federal agencies are doing to advance the cause.

   I like infographics!  They are fun, impactful, and this is a good one.  But, sometimes they are so busy that the simplest parts of the message gets obscured.

   It's not just infographics that obscure simple ideas.  Security and IT are experts at over-complicating things.  We get so caught up in the cool tools that we sometimes miss the main point.

   In the Security and IT world, we should always look at any project or program through the lenses of:
  1. People
  2. Process
  3. Technology
   And definitely in that order!

Tuesday, August 20, 2013

Beyond the Checklist - Compliance v. Security

   SC Magazine put out a good article last week entitled Beyond the Checkbox: PCI DSS.  The article cover new revisions in the Payment Card Industry (PCI) security standard (Data Security Standard DSS).

   The point of the article is something I've been saying for years... That we can simply treat security regulatory standards as checklists.  It's not about just meeting the minimum requirements.  It's about integrating the standards into your security program.

   Now, I'm not completely dismissing checklists.  In fact, I think they have some great places within your program.  For example: server build checklists; server hardening checklists, and; an SDLC checklist.  I'm a big fan of the CIS checklists for hardened configurations.  I also like a standardized secure engineering process (or SDLC) with specific steps.

   As I've discussed here in the past, one size does not fit all.  While we can all share our processes, it's critical to tailor any process or checklist to your environment.

   But here's my main point... Compliance does not equal Security!

Monday, April 22, 2013

Stuff I Say - Do What Makes Sense

   Today I'm continuing a set of posts I started last year.  These ideas are covered in a fun talk entitled #*%! My CISO Says, covering a range of security governance and management topics.  Slides are on my slideshare page.  The first two posts are here and here.

   The idea of doing what makes sense is central to my thinking (about many things).  In security, many people base their strategies and tactics on what they read or what others are doing.  But you can't provide useful information security based on what you read in a book.  One size does not fit all.

   When we don't do what makes sense, we end up with ineffective controls (like this ineffective control from one of my favorite security pictures).



   What works in one organization does not necessarily work in another.  This can be true for a variety of reasons including differing regulatory environments, organizational culture and kinds of assets/information.  This is why I've never liked the phrase, or idea of, "best practices".  I prefer "good practices" (more on that some other time...).

   It's easy to say we want to do what makes sense.  But how do we put that into practice in our organizations?

   Here are 2 considerations:

Risk Management approach.  Rather than using strategies and practices from a book, we need to understand a number of things about our organization including:
  • what "stuff" do we have?
  • what stuff do we need to protect?
  • what threats do we know of?
  • to what threats are we vulnerable?
  • what is the potential impact if these threats manifest?

   Asking these, and subsequent, questions can help lead to a better understanding of the environment

   Then... Seek out and destroy policies/practices that do not add value!  Consider:
  • ineffective controls - find them and get rid of them!  And, if you do remove a control, make sure that you let the users know!
  • annoyances that effect people's perception of security - convenience v. security is always a trade-off, but your controls must take into account people's work practices
  • what makes work harder - security and IT must support the business.  If complying with controls negatively impacts the business you may find your program overruled.
  • overly strict practices can cause people to try to circumvent controls to get things done.
   This doesn't mean that the security organization allows a free-for-all.  My point is that by considering how users need to use the systems, examining alternatives, and working with your business partners, you can come up with a set of controls that protect systems and data, meet regulatory requirements AND allow people to get their work done.

   Can you think of ineffective or unnecessary controls in place at your organization?  How have you partnered with business users to come up with controls that meet all needs?

Tuesday, September 18, 2012

Just Say No to "Just Say No"!

   Last week I spoke at The Security Standard conference put on by CSO Magazine.  While not the main point of my talk, one key theme that I addressed is that in Security and IT we cannot use "Just Say No" as an operating strategy.

   Five, Ten or more years ago, security and IT divisions were often considered to be roadblocks.  In many organizations, security and IT existed for self-fulfilling reasons... to support the technology they chose.  IT and security would dictate to the business.  But that's not the right way...