Showing posts with label management. Show all posts
Showing posts with label management. Show all posts

Tuesday, July 1, 2014

CISOs are from Mars, CIOs are from Venus


   I recently had the opportunity to speak at the Argyle CIO Leadership Forum in Chicago.  I sat on a couple of panels and had some fun delivering a talk called "CISOs are from Mars, CIOs are from Venus" (slideshare).
   There was a clear theme of cloud, mobile and BYOD.  There were both CIOs and CISOs in attendance so there were different perspectives on these challenges.  That certainly tied into my closing keynote.

   After the conference I was interviewed by the conference organizer.  The interview will be posted on the conference website, but here is a copy:

Tuesday, April 1, 2014

What's a CISO Do?

   A while back I started a new job as a CISO.  It's the second time I've held that title at an organization.  What's interesting about that is that both time it was a new position to the organization.  I wrote about my initial thoughts and plans in a post here.  That was before I started the job!  I've been meaning to follow up on that post, both to provide more insight and list next steps.

   In this post I'll dive a bit into the execution of the plans I originally discussed.  In another post I'll get into what came next, including the weightier topics of strategic and tactical plans.

   And yes, I know it's April 1st, but I'm keepin' it real!

   For my first 90 days on the job I tried to keep focus toward three key accomplishments:
  • Learn the business;
  • Start to establish a Culture of Security, and;
  • Baseline the environment.
   Let's talk a bit about each of these areas.

Tuesday, December 17, 2013

f2f Still Rules

   It's definitely a digital world.  And with all the instant electronic communication methods available, it's easy to forget about good old-fashioned face-to-face.

   Many work places have gone to open seating, without cubes or offices, to promote collaboration.  There are "team spaces" and other kinds of open areas in which people can quickly get together to solve problems.

   I've been thinking about this topic for a couple reasons.  First, I've been talking with internal groups about Internet Safety for Families.  This is a great topic both for general information and for Security Awareness in the workplace.  One item we often discuss is communication methods.  Teens and young adults (as well as many high-tech workers) do a disproportional amount of their communication electronically.  Sometimes that works and sometimes it doesn't.

Tuesday, September 10, 2013

What Works in Tech #Leadership - Keep It Simple

   As I'm heading toward the end of my current job, and getting ready for the challenges of my next opportunity, I've been thinking and reflecting on a few things.  One of these is leadership.
   I've had the opportunity to lead some great programs and teams in my career so far.  I went directly from being a technical individual contributor to management without any formal managerial training.  Earlier in my career I had titles and responsibilities including: software developer/programmer, engineering support, systems administration, architect, systems support, web developer, email administrator, security administrator/architect.  All of these positions can offer leadership opportunities, but this is very different than formal management.

   When I was in purely technical positions I had no interest in management, and couldn't even imagine going in that direction.  But then an opportunity came my way and I started down the "dark path" of management!  And I figured it out as I went along, with some results better than others.

Tuesday, August 27, 2013

People and Process First!

   I've been reading, and hearing, lately about the ideas of client-centric or human-centric IT.  Here's a cool article and interactive infographic from GovLoop.com.  It describes a roadmap approach to get to a people-centric approach while showing examples of what some US federal agencies are doing to advance the cause.

   I like infographics!  They are fun, impactful, and this is a good one.  But, sometimes they are so busy that the simplest parts of the message gets obscured.

   It's not just infographics that obscure simple ideas.  Security and IT are experts at over-complicating things.  We get so caught up in the cool tools that we sometimes miss the main point.

   In the Security and IT world, we should always look at any project or program through the lenses of:
  1. People
  2. Process
  3. Technology
   And definitely in that order!

Tuesday, April 30, 2013

Stuff I Say - Iterative Improvement

   This is yet another in my "Stuff I Say" series of posts.  I like to think about concepts of security management, though these ideas can certainly be applied to IT management (and management in general).  The themes of these posts are both things I think about and things I actually say.

   We've all got an incredible amount of work to do.  Most organizations have too many projects and ongoing development work, as well as too many existing and legacy tech assets to secure.  There are not enough resources to go around and the shortage of talent has been discussed in the tech media.  Prioritization is always a challenge.

   Security professionals have a difficult job.  Protecting individual and corporate data, and systems and networks is complex and often not well defined.  We don't really know when we've got it "right" (if there is a right), but we often find out the hard way when we've got it wrong!

   So, when faced with a new project, some security groups want to try to do everything at once.  We can't boil the ocean... but we have to start somewhere.  Some call it baby steps. Some call it putting one foot in front of the other.  I call it Iterative Improvement.

Monday, April 22, 2013

Stuff I Say - Do What Makes Sense

   Today I'm continuing a set of posts I started last year.  These ideas are covered in a fun talk entitled #*%! My CISO Says, covering a range of security governance and management topics.  Slides are on my slideshare page.  The first two posts are here and here.

   The idea of doing what makes sense is central to my thinking (about many things).  In security, many people base their strategies and tactics on what they read or what others are doing.  But you can't provide useful information security based on what you read in a book.  One size does not fit all.

   When we don't do what makes sense, we end up with ineffective controls (like this ineffective control from one of my favorite security pictures).



   What works in one organization does not necessarily work in another.  This can be true for a variety of reasons including differing regulatory environments, organizational culture and kinds of assets/information.  This is why I've never liked the phrase, or idea of, "best practices".  I prefer "good practices" (more on that some other time...).

   It's easy to say we want to do what makes sense.  But how do we put that into practice in our organizations?

   Here are 2 considerations:

Risk Management approach.  Rather than using strategies and practices from a book, we need to understand a number of things about our organization including:
  • what "stuff" do we have?
  • what stuff do we need to protect?
  • what threats do we know of?
  • to what threats are we vulnerable?
  • what is the potential impact if these threats manifest?

   Asking these, and subsequent, questions can help lead to a better understanding of the environment

   Then... Seek out and destroy policies/practices that do not add value!  Consider:
  • ineffective controls - find them and get rid of them!  And, if you do remove a control, make sure that you let the users know!
  • annoyances that effect people's perception of security - convenience v. security is always a trade-off, but your controls must take into account people's work practices
  • what makes work harder - security and IT must support the business.  If complying with controls negatively impacts the business you may find your program overruled.
  • overly strict practices can cause people to try to circumvent controls to get things done.
   This doesn't mean that the security organization allows a free-for-all.  My point is that by considering how users need to use the systems, examining alternatives, and working with your business partners, you can come up with a set of controls that protect systems and data, meet regulatory requirements AND allow people to get their work done.

   Can you think of ineffective or unnecessary controls in place at your organization?  How have you partnered with business users to come up with controls that meet all needs?

Tuesday, April 9, 2013

Keeping Security Simple

   This week I did a national webcast with Capella University.  The topic was the Insider Threat.  But my take on this is a bit different than what's usually said on this subject.  I call it "The Accidental Insider".  You can see my slides here.

   I was talking about how I think that accidents are the major cause of breaches.  I've talked a bit about how important it is to keep things simple here.

   If you're an information security professional, hopefully you are familiar with the Verizon Data Breach Investigations Report (DBIR).  You can see their page for the latest report.

   One of the interesting things they point out in the report is summarized in this table:

Tuesday, January 8, 2013

3 Factors of Fail - The Authentication Problem

   Authentication is one of the biggest challenges in information security. We can have all kinds of technical security measures in our systems. There are various controls we can have at the data level. But we still need to allow people to use the systems and get to the data. I should say... we need to allow the right people to use the systems and get to the data! Authentication is how we decide who the right people are.

   Federal regulations like HIPAA, PCI, IRS 1075 and others have major focus on minimum necessary.  That is, giving a user the minimum access they need to do their job.

   Wikipedia defines authentication as: (from Greek: αὐθεντικός; real or genuine, from αὐθέντης authentes; author) is the act of confirming the truth of an attribute of a datum or entity. This might involve confirming the identity of a person or software program, tracing the origins of an artifact, or ensuring that a product is what its packaging and labeling claims to be.  And Webopedia has: The process of identifying an individual, usually based on a username and password.  Interesting that this latter definition directly refers to username and password.

   There has been plenty of news in the past couple of years of breaches involving theft of a password file (encrypted or unencrypted) and customer/citizen personal data. Example like: eHarmony, LinkedIn, South Carolina Dept. of Revenue, and Utah. Many of these attacks involved exploiting authentication.

Tuesday, November 6, 2012

Reputation Management 101

   In October and November I’ve had a number of opportunities to present to groups of parents about Internet Safety, Social Networks and kids.  I try to do this regularly.  It’s a great way to give back to the community and talk about subjects I enjoy.

   One of the themes I often cover is Reputation Management.

   Parents are concerned that their kids share too much information online.  So much of what our kids do is documented online.  Everyone is carrying a camera and video camera with them and it all gets posted online.  For those of you who are parents with kids… imagine if there were cameras everywhere when you were young and everything you did was photographed or videoed and available for anyone to see!

Tuesday, October 2, 2012

Stuff I Say - No One Has Ever "Read and Understood"

   Most organizations have policies.  Most medium-to-large sized organizations have security policies.  I hope that yours does!  Policies are a cornerstone to a security program.  People need to know what to do and policy is that high-level guidance.

   Of course, people need to read those policies!

   Many organizations will have staff sign a form that states they have read and understood the policies.  Sometimes this happens just once.  Sometimes it's annually, perhaps at the same time as an annual performance review.  Sometimes it's when a person joins the organization, or shortly thereafter.

   But does that work?  What is the goal?  I say that doesn't work!  No one has ever "read and understood"!

Tuesday, September 25, 2012

Stuff I Say - KISS - Keep It Simple Security

   This is the first of a series of posts covering themes I talk about all the time.  The theme today is keeping things simple.

   Last week I spoke at the Interface conference in St. Paul.  It was a fun talk entitled #*%! My CISO Says, covering a range of security governance and management topics.  Slides are on my slideshare page.  In that talk I frequently referenced keeping our security program simple.