ciso 90 day plan - owasp

42
CISO 90 Day Plan Nelson Chen, M.SC. IT CISSP, CISA, CISM

Upload: others

Post on 16-Oct-2021

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: CISO 90 Day Plan - OWASP

CISO90DayPlan

NelsonChen,M.SC.ITCISSP,CISA,CISM

Page 2: CISO 90 Day Plan - OWASP

Agenda

•  Whyarewehere?•  Days0–30•  Days31–60•  Days61–90•  Days90+•  Infinity&Beyond

Page 3: CISO 90 Day Plan - OWASP

AvoidingReallyBadNews!

<Your Company Name Here>

Data Breach!

Page 4: CISO 90 Day Plan - OWASP

Don’tbetheBlocker!

MAYBE

Page 5: CISO 90 Day Plan - OWASP

Don’tbetheProphetofDoom

Page 6: CISO 90 Day Plan - OWASP

ToughestPartoftheJob

Page 7: CISO 90 Day Plan - OWASP

CISOPost-Breach

Page 8: CISO 90 Day Plan - OWASP

0-30

EstablishingRelationships&Trust

Page 9: CISO 90 Day Plan - OWASP

SellingCISOasaService

•  Businessenablement•  FUDisnottheonlypitch•  Education•  Sharedresponsibility•  Getsupportandbuy-in•  AddValue!

Page 10: CISO 90 Day Plan - OWASP

TakingInitialInventory•  OrganizationalStructure-Who’swho– Execs,BULeaders,ITOps,InternalAudit

•  ExistingPolicies,Processes,etc.•  ExistingTechnologies•  Where’stheData?•  HistoricalSecurityIncidents•  ShadowIT

Page 11: CISO 90 Day Plan - OWASP

LeadingTowardsBetterSecurity

Page 12: CISO 90 Day Plan - OWASP

ServantLeadership

Page 13: CISO 90 Day Plan - OWASP

SecuritySurroundsus,PenetratesusandBindsusTogether

Page 14: CISO 90 Day Plan - OWASP

31-60

Prioritizing&ProjectKickoff

Page 15: CISO 90 Day Plan - OWASP

BacktoBasics-CIATriad

Keepingitsecret

Keepingittogether

CentralOregonCommunityCollege

Keepingitup

Page 16: CISO 90 Day Plan - OWASP

Fox-inorFox-out?

Page 17: CISO 90 Day Plan - OWASP

TeamorCommittee?

Page 18: CISO 90 Day Plan - OWASP

SecurityTeamBuilding•  BUInfoSecOfficers–Legal,Finance,Sales,Marketing,HR,Development,IT,etc

•  Committeedriven•  Executivesponsor•  Internalauditisyourfriend•  Wherearealltheresources?

KissPNG

Page 19: CISO 90 Day Plan - OWASP

SecurityCommitteeGoals

•  BusinessSecurityMissionStatement•  AligningsecuritywitheachBU

-whatareweprotecting?

•  Takingdetailedinventory– Processes,Systems,Data,People

•  Budgetize,Prioritize,Projectize•  ReportingdirectlytoC-levels

KissPNG

Page 20: CISO 90 Day Plan - OWASP

SecurityAssessment&GapAnalysis

•  CapabilityMaturityModel(CMMI)•  CybermaturityPlatform

Page 21: CISO 90 Day Plan - OWASP

CMMIInstitute

Level5

Initial

Level1

Processesareunpredictable,poorlycontrolled,reactive.

Managed

Level2

Processesareplanned,documented,performed,monitored,andcontrolledattheprojectlevel.Oftenreactive.

Defined

Level3Processesarewellcharacterizedandunderstood.Processes,standards,procedures,tools,etc.aredefinedattheorganizational(OrganizationX)level.Proactive.

QuantitativelyManaged

Level4Processesarecontrolledusingstatisticalandotherquantitativetechniques.

Optimizing

Processperformancecontinuallyimprovedthroughincrementalandinnovativetechnologicalimprovements.

CMMI–5Levels

Page 22: CISO 90 Day Plan - OWASP

WTF-OMGCompliance

Page 23: CISO 90 Day Plan - OWASP

HowandWheretoFocus?

TheCybersecurityHubonTwitter

Page 24: CISO 90 Day Plan - OWASP

CriticalBusinessProcesses

Apttus

Page 25: CISO 90 Day Plan - OWASP

PatchManagementisParamount!

NationalLibraryofAustrailia

Page 26: CISO 90 Day Plan - OWASP

DataInventory•  What,where,why,when&how•  Followthedatatrail•  Backups•  End-usercomputers•  Storagemedia•  Archivedapplications•  What’sintheCloud?

Page 27: CISO 90 Day Plan - OWASP

DataClassification

•  Public,Internal,Confidential,Secret•  PII:Customer&Employee•  DefinedRepositories•  CommensurateSecurityLevels•  ManagedDataLifeCycle

Page 28: CISO 90 Day Plan - OWASP

SecurityPolicy•  ComplianceDriven•  BusinessDriven•  Ownership•  3rdparty•  CustomerInput•  Training•  ControlsDesign&Mapping

–  CloudControlsMatrix(CCM)-CloudSecurityAlliance

Page 29: CISO 90 Day Plan - OWASP

61-90

BuildingSecureFoundations

Page 30: CISO 90 Day Plan - OWASP

SecurityvsSecurityOperations

SecOps

Wordpress

Page 31: CISO 90 Day Plan - OWASP

SecurityAwarenessTraining

•  BusinessUnitRelevance•  JointdeliverywithBU-ISO•  Compliancedriven•  Sec-Dev-OpsTraining•  Relevant3rdPartytraining

Page 32: CISO 90 Day Plan - OWASP

ApplicationSecurity•  Everycompanyisatechnologycompany

•  In-housevs3rdParty•  SecureSDLC•  Training•  yourWebapp!

Verizon2018DBIR

Page 33: CISO 90 Day Plan - OWASP

BusinessContinuity

•  BusinessProcessDriven•  DisasterRecovery– DefinedRTOs&RPOs

•  BackupStrategy•  DenialofService•  Testing

StepupIT

Page 34: CISO 90 Day Plan - OWASP

PreparefortheWorst

Page 35: CISO 90 Day Plan - OWASP

DataBreachPreparedness•  BreachScenarioPlanning•  Table-topExercises•  DecisionTree•  Detection&Logging•  ContactLists•  Time-to-Notify•  Bitcoins?!

DataBreachResponse

Plan

INCASEOFEMERGENCYBREAKGLASS

Page 36: CISO 90 Day Plan - OWASP

Customer-FacingSecurity

•  SecuringClientServices•  SupportingSales•  CustomerSecurityCompliance•  VendorSecurityQuestionnaires•  LegalAgreements–SecurityLanguage

Page 37: CISO 90 Day Plan - OWASP

90+

Page 38: CISO 90 Day Plan - OWASP

SecurityisaBoard-levelProblem

Page 39: CISO 90 Day Plan - OWASP

Andamessagefromthe

•  OnNovember1,2018,DataBreachNotificationLawswillbeenforcedinCanada

Page 40: CISO 90 Day Plan - OWASP

KEEPCALMDOTHE

RIGHTTHINGANDCYA

Page 41: CISO 90 Day Plan - OWASP

TheTribeHasSpoken…

NOT ME

Page 42: CISO 90 Day Plan - OWASP

ChiefI’mtheScapegoatOfficer

Questions?