Cybersecurity Workforce Development: Takeaways From a NIST Workshop

I had the opportunity to serve as a panelist at the NIST Workshop on Cybersecurity Workforce Development held in Chicago earlier this month. Based on the day’s conversations, there is still much work to be done.

Representatives from academia, associations, private industry and government converged for discussions on this critical topic, and there remains broad consensus that several steps are critical to make progress on narrowing the cyber skills gap:

  1. A shift to skills-based training. Much of the conversation at the NIST workshop addressed the need for hands-on training that demonstrates real skill. ISACA has committed to helping enterprises, academia and individuals through its skills-based training courses and the CSX Practitioner (CSXP) credential.
  2. Retraining programs to make more progress in the near term. Look to programs like one in the UK, in which people from a number of fields (bartenders, morticians, barbers) were trained in cyber security positions. About half of the trainees now work in cyber security jobs.
  3. Inspiring an interest in tech among K-12 students to help solve the problem in the long term (with solutions on how to reach all schools, including rural schools that may not have the equipment they need to run strong technology programs). Engage mentors from the tech industry to teach courses that teachers may not have the necessary skill sets to teach.
  4. Creating a culture that increases cyber awareness and encourages diversity of those choosing to pursue cyber security professionally.
  5. More public-private partnerships. Too many organizations are operating in silos. Partnerships and strategic investment will make efforts more scalable and effective.

The good news is that discussions are taking place; the not-so-good news is that the required actions are not happening fast enough.

Government, nonprofits and industry need to make significant strategic investments to ensure scalable programs that begin to make a measurable difference in closing the skills gap.

ISACA looks forward to being an enabler of solutions. Over the next year, you’ll see us make significant progress in the following areas:

  1. Helping organizations assess and advance their cyber capabilities
  2. Bringing skills-based training to academic settings
  3. Equipping enterprises with on-demand, constantly updated skills-based cyber security training
  4. Building relationships with government institutions and industry partners to reach a wide audience with our cyber security training and guidance
  5. Building public will to invest in other worthwhile programs

The only solution is to work collaboratively and collectively for impact.

Matt Loeb, CGEIT, CAE, FASAE, Chief Executive Officer, ISACA

[ISACA Now Blog]

Data Analytics Maturity Models and the Control Environment

Organizations have recently raised concerns on their data analytics capabilities. There are several motivations for this increased interest in data analytics, such as fulfilling regulatory requirements, increasing efficiency and reducing cost. However, the primary reason is focused on the identification of business opportunities. The most typical questions include:

• Are we maximizing the value from the data we currently have?
• Are we missing business opportunities because we do not use our customer data?
• What is the competition doing?
• What are the best practices in the market?

It is difficult to answer these questions without a structured model that defines what is “basic” and what is “advanced.” It helps to provide a simple maturity model that is easy to understand.

The maturity levels below show a basic and summarized model based on the current situation in the financial services sector, and are based on what the industry wants to achieve.

  • Level 1: Basic data analytics capability. Systems and applications working in silos and analysis performed on individual databases on end-user computing tools (e.g., spreadsheets and access databases). Limited analysis can be done at this level due to the limitation of the tools and the data used.
  • Level 2: Specific analytics function. Interaction between systems (e.g., data warehouses or data lakes) and usage of data analysis tools that allow integration of different data sets. Analysis can be reused on those systems that combine different data sets. However, there is a gap between the business and its data analytics teams.
  • Level 3: Business intelligence capability. Adding a business intelligence platform (data visualization ledger) to the previous maturity level. This allows the end users to perform their own analysis through dynamic dashboards.
  • Level 4: Prediction Analytics (artificial intelligence). Adding to the previous maturity level the usage of statistical analysis that allows for the creation of prediction models and algorithms based on parameters or scenarios.

Some organizations want to achieve the best maturity level without having basic controls in place, which can create erroneous results due to the lack of quality in the data used. An appropriate level of control and data governance function is critical for the success of the data analytics function, and helps to progress through the maturity model.

Examples of basic controls that must be in place before progressing to the next level include:

  • Input controls on entry data systems and applications, such as range controls (e.g., age must be between 18 and 100), avoid zeros and blanks, invalid characters, etc.
  • Reconciliations (or equivalent) on interfaces and transfers of data between systems applications; sometimes totals on number of transactions and total value provides enough level of comfort.
  • Assurance that calculations performed on applications are correct. Reperform calculations in an independent environment in order to ensure that calculations are performed correctly.

To summarize, the use of data analytics techniques and expertise can increase the value from the data that organizations can obtain. However, it is important to maintain data quality and a management framework to ensure that the data used for the analysis is fit for purpose.

Angel Serrano, CISA, CISM, CRISC, Senior Manager, Advanced Risk & Compliance Analytics, PwC UK

[ISACA Now Blog]

Mobile Computing: Increasing Productivity and Risk

Motorola is credited with creating the first handheld mobile phone. A quick look around in any public place, however, is confirmation that Motorola is now only one of many players in the mobile phone market. Touted as a way for employees to be more productive, cellphones and other mobile devices such as notebooks, netbooks, ultrabooks or tablets are relied upon to provide employees with access to company resources regardless of the employee’s location and the time of day.

Mobile device use is viewed by some as a clear indicator that employees can be (and are) more productive. Others view mobile devices as distractions. After all, no one has ever been in a meeting where a colleague has ‘checked out’ of the discussion to respond to emails on a cellphone, right?

Whether the use of mobile devices directly increases productivity or not may be an ongoing question, but the increased risk associated with the use of mobile devices is not up for debate. Remember the proverbial lost laptop? The physical loss of a mobile device is not the only way that a company’s data can be compromised. As employees access their employers’ data anywhere and everywhere, bad actors are also trying to access that data. In addition to data compromised through physical loss of a mobile device, data can be compromised through unsecured network connections or malware, as examples.

By no means are mobile devices declining in popularity. So, it is reasonable to assume that mobile devices and the risks associated with their usage will remain part of most organizations’ risk universes. Given that, IT auditors have an opportunity to partner with their organizations to assess the state of mobile computing. Areas that are beneficial to address in mobile computing audits are:

  • Governance: policies and practices that address scope, responsibilities, and procedures around protection of data accessed by, transmitted by, and stored on mobile devices;
  • Remote access: practices ensuring that all users are uniquely identified when accessing company resources;
  • Data loss: security measures are adequate to address risks associated with removable media; disclosure, copying, or modification of enterprise data; and misalignment of position responsibilities and sensitive information;
  • Malware: protections are in place to prevent operational disruptions from malware introduced into the enterprise through mobile computing;
  • Incident response: incident response protocols exist for mobile device users from detection and reporting through recovery.

As employers continue to explore ways to increase employees’ productivity, it seems safe to say that data access through mobile devices will continue to play a role in meeting that objective. Given data privacy expectations (existing and emerging) as well as customer considerations, safeguarding data will remain a challenge for most organizations. This challenge can be mitigated by a collaborative partnership between IT auditors and management that is founded on a solid mobile computing audit program. The results of an audit can be used to gauge the effectiveness of the enterprise’s safeguards of data on mobile devices.

Editor’s note: For more guidance on this topic, download ISACA’s mobile computing security audit and assurance program.

Robin Lyons, Technical Research Manager, ISACA

[ISACA Now]

Top 10 Considerations for Securing Public Cloud Workloads

The shift to the public cloud has offered organizations increased agility, flexibility and scalability. However, as more and more organizations move critical workloads to the public cloud, the potential for attackers to steal data, intellectual property or computing resources also rises.

Below is a brief breakdown of three considerations for securing public cloud workloads. Download the white paper to view the detailed list of all 10 top considerations.

  1. Embrace the shared security model: The infrastructure is secured by the cloud service provider, but users are responsible for securing their own applications and data as it resides in the cloud. With this in mind, security practices must be implemented to secure workloads in the cloud as well as prevent loss of data and IP, just as if the workloads were on-premise.
  2. Engage with business groups and DevOps early: Security teams and respective business groups, such as DevOps, should work collectively – particularly during initial stages of public cloud projects – to ensure all development needs are met while still maintaining a healthy security posture.
  3. Know your potential exposure: Monitor public cloud usage, ensure proper configuration of the environment, enforce two-factor authentication, and properly lock down Secure Shell (SSH) access to gain visibility and minimize potential exposure through “shadow IT.”

Read the full list of our Top 10 Considerations for Securing Public Cloud Workloads.

[Palo Alto Networks Research Center] 

English
Exit mobile version