Adjusting to the DevOps Mindset

There is no question about it, DevOps is coming to the forefront in enterprise. A 2014 survey from Rackspace found that 79 percent of those they surveyed plan to implement DevOps practices or approaches by the end of 2015. Meaning, most shops now are DevOps shops. For ISACA members, this can have a significant impact—security, assurance, risk, and governance impacts aplenty.

Security pros will need to understand how DevOps can impact existing security controls; some controls (automated static or dynamic application security testing controls—or even manual code reviews) may need to be adjusted in light of faster release cycles and new tools. There might also be hidden security advantages as the transition takes place. As tools like Puppet, Chef, Salt, and others allow them to better meet historical challenges: for example, by leveraging those tools to perform security hygiene tasks (e.g. patching, automated configuration validation, etc.).

Assurance pros likewise will need to understand the impacts of DevOps as it directly impacts them as well. In many DevOps shops, developers can affect changes to the production environment through the use of automated tools. To understand whether this undermines important goals like segregation of duties, assessors will need to understand the deployment model. Is segmentation of duties undermined? Or, is it improved by virtue of automated (and thereby non-repudiable) recordkeeping? The answer will depend on implementation, which is why it is important that practitioners know what questions to ask.

Risk professionals will need to understand how their organization’s overall risk equation is impacted by the move too: there might be new technical risks that arise and other existing ones that are mitigated. There are business risks to consider as well, like what the potential impact on competitiveness our organization should not adopt while the competitors do.

Lastly, there is an impact on governance. Folks who are responsible for overseeing the IT governance program for their organization will need to consider how existing governance structures will extend into DevOps processes and tools. How will DevOps impact those structures and what artifacts (like organizational policy) might need to change as a result?

The point is there are quite a few potential changes on the horizon that will impact all of the disciplines and professional areas that ISACA members inhabit. In order to help those practitioners navigate these potentially-complicated waters, ISACA has released a new whitepaper: DevOps Practitioner Considerations. This guide examines the impacts that DevOps can have on different practitioner communities and explores what those practitioners might choose to do in response.

As organizations start to more frequently move to DevOps, it becomes increasingly important that the “DevOps way” be understood by those with a stake in ensuring trust and value in information systems. Those who do not keep pace might find themselves unequipped to ensure the mission of their organization is protected. Those that adapt may find themselves able to use DevOps concepts to do their jobs even better.

Ed Moyle
Director of Emerging Business and Technology at ISACA

[ISACA]

CSXP: An Exciting New Career Resource for Cybersecurity Professionals

Today marks the launch of the CSX Practitioner (CSXP) certification exam. For the first time, cybersecurity professionals can now obtain a vendor-neutral, performance-based cyber certification.

With Cybersecurity Nexus (CSX), ISACA has made a commitment. Through training, guidance, education and credentialing, we will help develop a skilled cybersecurity workforce to reduce the global skills gap, and we will provide resources for cyber professionals at every level of their careers. CSXP is one way we are fulfilling that commitment.

Research shows that the majority of employers—nearly 7 in 10—are requiring cybersecurity job candidates to hold a certification. They are also looking for candidates with hands-on skills. When a prospective employee has CSXP, it indicates that they fulfill both of those criteria and that he or she has the skills needed to help protect the organization.

To earn CSXP, candidates must pass an exam in a state-of-the-art, adaptive, performance-based cyber laboratory environment. The exam measures skills and abilities in a virtual setting using real-world cyber security scenarios. Registration is now open for the exam, and a beta test rate is available for those who take the exam and complete a survey by 1 October 2015.

Very soon, ISACA’s CSX will offer cyber training and certifications for all skill levels and specialties:

  • Cybersecurity Fundamentals Certificate—Knowledge-based certificate that demonstrates a foundational understanding of cybersecurity (currently available)
  • CSX Practitioner—Demonstrates ability to be a first responder to cyber incidents, following established procedures and defined processes. CSXP indicates firewall, patching and anti-virus experience, as well as the ability to implement common security controls and perform vulnerability scans and analysis. (currently available)
  • CSX Specialist—Demonstrates effective skills and deep knowledge in one or more of the five areas based closely on the NIST Cybersecurity Framework: Identify, Detect, Protect, Respond and Recover (coming soon)
  • CSX Expert—Demonstrates ability of a master/expert-level cybersecurity professional who can identify, analyze, respond to and mitigate complex cybersecurity incidents (coming soon)
  • Certified Information Security Manager—Demonstrates the ability to manage, design, oversee and assess an enterprise’s information security program (currently available)

It is an exciting time of opportunity for cyber professionals. Companies and government organizations need you more than ever. As you grow your career in this area, know that we are here for you—we will help you stand out, grow your career and connect with a global community of cybersecurity experts.

Christos Dimitriadis, Ph.D., CISA, CISM, CRISC
2015-2016 ISACA International President

[ISACA]

To (ISC)² Global Academic Program (GAP) Instructor John Sands, the Next Generation is Everything

To GAP instructor John Sands, the next generation is everything. He has dedicated his career to teaching and creating programs that fill the cybersecurity education gap that persists today. His work has propelled the cybersecurity field forward by decades.

In addition to his role as GAP instructor, Sands is also the department chair for Computer Integrated Technologies at Moraine Valley Community College and co-founder for the National Center for Systems Security and Information Assurance (CSSIA), a GAP member since 2014. Early in his career, he recognized that schools and universities were lacking cybersecurity programs, let alone offering programs that could produce students who are equipped to meet the dynamic cybersecurity needs of the real world.

Nearly 20 years ago, Sands and his colleagues conducted studies to find out what was preventing schools from adopting security programs. They applied those findings to the curriculum at CSSIA and implemented hands-on labs throughout the program, and today, over 250 schools have duplicated their model. “To see the impact of our program is profound,” he reflects.

Despite all his impressive strategic work at the program level, he still loves teaching.  “I love watching the first time students recognize what can be done with the tools (such as penetration testing) to their systems. Most people have no idea as to the level of risk we’re actually at. To take over a machine and interpret the data and do forensics helps students appreciate the seriousness of the situation. Once students grasp that, their whole approach to the class changes.”

A vocal ambassador for experiential learning, Sands has made it a priority to incorporate this element into his programs. He is a believer in the blended education-certification approach and talks to students constantly about the benefits of this holistic view. His is also a big advocate of outside measures that validate skills and of common benchmarks that students must live up to. He feels these things better prepare students for real jobs and gives them an advantage in the workplace.”

Regarding advice for the next generation, Sands teaches an orientation course in which he exposes students to all of the kinds of jobs that exist and the requirements for each, and he believes this kind of introduction to the field is essential. Most organizations want practitioners who can hit the ground running, so he counsels students to get experience in their classes. He says, “You need to be able to do things – not just talk about them. You also need to be able to demonstrate your knowledge.”

At CSSIA, they conduct a third-year student survey, and many students report that the key to their success is the amount of hands-on experience they leave the program with.

Sands asserts, “This is an extremely important field to get into. This is an important message to get out, especially to high school students. The opportunities in this field are just as good as in the medical and legal fields, and while there are many more lawyers than jobs, information security is suffering from a dire shortage of qualified professionals. We need bright minds to help protect our critical assets.”

So, what’s left for someone so driven and accomplished to do? A member of the U.S. Navy for six years, John is passionate about reaching out to underrepresented groups in the industry, especially veterans. He has created a one-year intensive program for veterans returning from Iraq and Afghanistan. They work with local companies, such as Cisco and Linux, who offer free vouchers for exams and guarantee jobs after veterans complete the program.

Sands comments, “If we just invest in veterans, the profession will benefit immensely. They bring so much to the table. I am amazed by how quickly we’ve been able to bring them through advanced training. We work closely with the Illinois Department of Veterans Affairs, which provides additional services to help veterans transition to a civilian career. It’s my favorite project.”

Through the Global Academic Program (GAP), (ISC)²® collaborates with an ever-expanding network of university partners to establish a joint framework for delivering essential skills to support the growth of a qualified information security workforce. For more information on the (ISC)2 Global Academic Program, please visit https://www.isc2.org/global-academic-program/default.aspx.

(ISC)² Management

[(ISC)² Blog]

Guiding Auditors in an SAP Environment

Enterprise resource planning (ERP) systems automate and integrate the majority of a company’s business processes, producing consistency. They do this by sharing common data and practices across an organization, leveraging one-time data entry, and providing access to information in real time. To help in this working environment, ISACA recently released a go-to reference book for auditors that they can dog-ear with sticky note flags sticking out of the top and return to year after year.

Since the 1990s, businesses have been managing their operations with ERPs, which have enabled centralized control over operations by implementing a common data model and integrated business processes. SAP has been a leader in ERP systems from the beginning and uses a process-driven approach to match business processes with application processes.

SAP’s core product is SAP ERP (also called Enterprise Core Component [ECC] 6.0). SAP ERP is configurable and integrated across modules. This creates a system that is flexible but also complex. Because of the complexity and variability of configuration across industries, many companies are starting to use automated tools to assist in tracking and monitoring compliance. Systems such as SAP Governance, Risk, and Compliance (GRC) are common in large organizations to monitor and manage on-going compliance. Information technology auditors are also finding that it takes an SAP-specific skillset to audit these systems. This knowledge is required to understand the risks and the controls that mitigate those risks.

The ISACA Security, Audit and Controls Features of SAP ERP 4th Edition brings together detailed information related to SAP ERP-specific risks, controls, and testing procedures. The handbook is separated into modules that cover the risk and controls, followed by testing procedures for both configuration and security. The book was designed as a long-term reference guide for auditors working in an SAP environment—a handbook written by auditors for auditors.

The 4th Edition provides an update of previous sections and adds sections for Finance, Controlling, Human Resources, and Security with a focus on SAP ECC 6.0. The handbook walks through each of these new sections in detail with the same methodology used to cover the other areas (risk, mitigating controls, and testing procedures). In addition, this latest version also comes with downloadable audit plans that are COBIT 5 compliant. It is nearly a completely new book!

The 4th edition was a great opportunity for Deloitte Advisory and ISACA work jointly to rewrite and build upon a great foundation to produce a new edition that refreshes and expands the scope of the original book.

Ben Fitts
Deloitte Advisory

As used in this document, “Deloitte” means Deloitte & Touche LLP, a subsidiary of Deloitte LLP.
Please see www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. Certain services may not be available to attest clients under the rules and regulations of public accounting.

[ISACA]

Security Talent Management: Leveraging the “Cool”

When governments routinely address cybersecurity as part of their policy, you know that the topic is of national interest. When vulnerabilities are found in—and researchers demonstrate attacks against—computer systems in medical devices, automobiles and airplanes, you know that the significance extends even farther.

While that kind of recognition is important for the profession as a whole and is certainly impactful, there’s another area in which cybersecurity is gaining interest that is arguably more impactful to most practitioners on a day-to-day basis: increase in cultural interest.

TV shows (e.g., CSI: Cyber, Mr. Robot) and movies (e.g., Blackhat) that popularize the topic serve to guide younger professionals toward the discipline. You know that the cultural awareness has been firmly established when a movie like The Duff (a lighthearted teenage comedy) both features a hacker as a main character and incorporates security as a significant plot point.

When it comes to talent retention and acquisition for those in (or running) a security organization, understanding that this phenomenon exists – and knowing how to get it working in your favor – can be part of a security manager’s broader plans.

Leveraging cultural interest

Junior roles in any organization are the hardest to fill. Why? Because leaders tend to have more experience than the candidates they seek to hire; as a consequence, the folks in their virtual “rolodex” are those that they’ve worked with or collaborated with in the past – i.e., those with (most likely) a similar amount of work experience to their own.

Moreover, the folks moving into those junior roles are those more likely to be newer to the workforce.  A recent study from the Brookings Institution found that 64% of millennials (those born between 1980 and 2000) would prefer to make US $40,000 at a job they love (i.e., one they find interesting and engaging) vs. US $100,000 at a boring job. In other words, the work they value most is that which is most interesting. An increase in cultural interest on the topic of security means a corresponding uptick in the ability of security managers to find the best and brightest for their teams.  That said, it’s up to those same managers to retain them once they’re there.

This is where job rotation and cross-training within the organization can play a very beneficial role. Because, let’s face it, there are some jobs that are less interesting than others but still need to get done. Understanding that fulfillment and interest tie directly to employee satisfaction (and thereby attrition rate), periodically “refreshing” staff (sharing the load for those less interesting tasks) helps keep those folks from getting bored (and antsy to look outside the organization for more fulfilling work). Additionally, rotation of duties can help deepen internal understanding of the organization, cross-pollinate valuable skills and build a depth of experience for future leaders.

There’s a cultural phenomenon at work; at least for the moment, security has the interest of the media. The impact of this in the short term could mean an upcoming reduction in the pain we all feel as a result of the much-discussed security skills gap (an issue ISACA’s Cybersecurity Nexus [CSX] aims to address)—but for those thinking longer term, planning now for a way to hone, develop and retain those folks once they’re through the doors is time well spent.

Ed Moyle
Director of Emerging Business and Technology at ISACA

[ISACA]

English
Exit mobile version