International President: New ISACA Board of Directors Continue on Path of Agility and Innovation

The rate of change in our enterprises is racing faster than at any other time. New technologies are introduced nearly daily—and many of them are making their ways into our workplaces. These new realities mean that information flows instantly around the globe, and we need to be agile and prepared.

ISACA has long been respected for its foresight and innovation, and with the installation of the 2015-2016 board of directors recently in Brussels, this tradition continues. I am honored to serve as ISACA’s international president during this time of incredible innovation.

I would like to thank Immediate Past President Robert Stroud for his many years of dedicated service. During Rob’s tenure, ISACA experienced growth in many areas, including membership, chapters and revenue. ISACA launched the Cybersecurity Nexus (CSX) and the online version of COBIT 5. I look forward to Rob’s continued significant contributions throughout the year.

My sincere appreciation also goes out to the outgoing board members who have given so much of their time and expertise to ISACA over the years—Steven Babb (UK), Ramsés Gallego (Spain), Vittal Raj (India), Debbie Lew (USA), Frank Yam (Hong Kong), and Alexander Zapata Lenis (Colombia). You have helped lead ISACA and contributed to the growth of our global respect and reputation—thank you for your past and future contributions.

As our new and returning board members continue to move ISACA forward and focus on our refreshed strategy and goals, I am eager for you to collaborate closely with all of us:

  • International President Christos K. Dimitriadis, Ph.D., CISA, CISM, CRISC, group director of Information Security for INTRALOT, Greece
  • International Vice President Rosemary Amato, CISA, CMA, CPA, director, Deloitte, Amsterdam, The Netherlands, program director for Global Client Intelligence (GCI), The Netherlands
  • International Vice President Garry Barnes, CISA, CISM, CGEIT, CRISC, MAICD, practice lead, Governance Advisory at Vital Interacts, Australia
  • International Vice President Robert Clyde, CISM, managing director of Clyde Consulting LLC, USA
  • International Vice President Theresa Grafenstine, CISA, CGEIT, CRISC, CIA, CGAP, CGMA, CPA, inspector general of the U.S. House of Representatives, USA
  • International Vice President Leonard Ong, CISA, CISM, CRISC, CGEIT, CPP, CFE, PMP, CIPM, CIPT, CISSP ISSMP-ISSAP, CSSLP, CITBCM, GCIA, GCIH, GSNA, GCFA, COBIT 5 Implementer and Assessor, Singapore
  • International Vice President Andre Pitkowski, CGEIT, CRISC, OCTAVE, CRMA, ISO27kLA, ISO31kLA, COBIT 5 Foundations Trainer, principal consultant APIT Consultoria de Informática Ltd., Brazil
  • International Vice President Eddie Schwartz, CISA, CISM, CISSP-ISSEP, PMP, president and COO of WhiteOps, USA
  • International Director Zubin Chagpar, CISA, CISM, PMP, focuses on  Venture Capital Business Development in EMEA for Amazon Web Services, United Kingdom
  • International Director R.V. Raghu, CISA, director of Versatilist Consulting India Pvt. Ltd., India
  • International Director Jo Stewart-Rattray, CISA, CISM, CGEIT, CRISC, FACS CP, director of information security and IT assurance at BRM Holdich, Australia

For more than 45 years, ISACA has been a trusted global resource to help professionals transcend borders and collaborate. We recognize that the people we serve have rapidly evolving needs, and are focused on ensuring that ISACA continues on its path of becoming more flexible, responsive and enabled for a dynamic future.

Christos K. Dimitriadis, Ph.D., CISA, CISM, CRISC
ISACA International President

[ISACA]

Helping SMEs Thwart Cybercrime

The common perception among many in small and medium-sized enterprises (SMEs) is that cybercrime takes place only at large, multinational enterprises. Nothing could be further from the truth.

In fact, cybercriminals are aware of that perception and know that SMEs are easier targets. According to two new ISACA guides: Cybersecurity Guidance for Small and Medium-sized Enterprises andImplementing Cybersecurity Guidance for Small and Medium-sized Enterprises, another negative factor has been the cost and historically poor performance of cybersecurity programs.

These new guides are designed to help the typical SME achieve reasonable security at an affordable cost. They also help SMEs prepare for, and manage, typical cybersecurity issues, risks and threats.

Think of your cybersecurity strategy as the same one you would use to protect a private property. If the target is visibly protected and likely to offer resistance, most would-be attackers are likely to move on to the more vulnerable target.

Of course, no business enterprise can predict tomorrow’s cyber threat or attack—only the likelihood that they are lurking for the most vulnerable. However, even SMEs with limited resources can strengthen the enterprise from attacks if they adopt a sensible strategy.

Cyber security is a process and not an end result. SMEs need to continually improve their security programs to keep pace with technology and new risk and threats.

Cybersecurity Guidance for Small and Medium-sized Enterprises incorporates elements of continuous improvement toward increased sophistication. Implementing Cybersecurity Guidance for Small and Medium-sized Enterprises is a companion publication to this Cybersecurity Guidance and is available to users of the guidance. It provides practical advice on how to implement cybersecurity governance, risk management, assurance and compliance using the Cybersecurity Guidance for SMEs and its COBIT 5 foundation.

Jo Stewart-Rattray, CISA, CISM, CGEIT, CRISC, FACS CP
Director of information security and IT assurance at BRM Holdich

[ISACA]

An Innovative Approach to Identity Management Seen

In the future, more keys may be the answer to protecting your personal data. We need to separate a person’s persona from their online profile information. What is needed is a second key, a data key, to ensure the privacy and control of your online data. Banking online, LinkedIn and Facebook would all require this data key.

The US federal initiatives on stronger identities—the National Strategy for Trusted Identities in Cyberspace (NSTIC)—are helping individuals and organizations to develop secure and easy-to-use identity credentials to access online services in a manner that supports an innovative approach in protecting information and greater privacy. I support the notion of a federated identity that has been evolving from the idea of a user-centric “identity ecosystem.” The mechanism to create a method to obtain and authenticate digital identities is necessary to create an online environment where there is a trust between individuals and organizations.

Biometrics
Biometrics will probably play a part and that will certainly have a privacy impact. Part of it will be a demographic issue with those over age 65 having nothing to hide and those younger not necessarily caring that much and having little concern about accountability. It is the middle group, those between late 20s and 60 who view their privacy as valuable. Mobile applications are another area of concern. You have to allow cookies to have your applications work, even for banking. The user agreement terms and conditions on a mobile device throw your privacy out of the window. Most people, such as Tweeners, are more interested in convenience than their security, so it will take something catastrophic to move their needle from convenience to security. People want information at their convenience, but advertisers want to inundate them with a continuous stream of advertising. The consumer should be allowed to turn off that information stream. Privacy will be the key in the long term.

Internet Service Providers (ISP)
One area of improvement that could be made is in making ISPs accountable for bad actors in their environment. ISPs should be given a freer hand in regulating people using their networks. There needs to be more accountability. If you are an Internet offender, there should be a three-strike rule that is adjudicated by a board to take access away from repeat offenders.

Quality of Software
The market should regulate software quality, but it does not seem to be working. Competition is also an issue. Where you have a few dominant players such as Microsoft and Oracle—how can you compete when they have so much of the market share? There has to be a balance between quality and security just as there has to be a balance between security and convenience.

How to Build a Solid Organizational Staff
When building a staff, I recommend hiring well-rounded individuals. I have had better success getting people who are organizationally focused rather than taking security people and indoctrinating them into the business of the organization. I always begin my search within the company, someone who knows what is important to the organization. The key is that the person knows what the value of the data are to the organization. I prefer to find professionals who invest in themselves on their own dime, paid their way to a technology show so that they understand where the technology fits within the organization in the next five to 10 years—that is part of growing your workforce.

Changing Role for the CISO
I see the role of the chief information security officer (CISO) changing to that of a chief privacy officer or a chief digital officer. There is always contention between meeting the needs of the masses rather than the outliers, but you first have to address the masses needs before the outliers. Still, outliers cannot be ignored; otherwise they will be your problem. CISOs have to be broad-based and business and technology focused. They have a difficult position because they have to become all things to all people.

Education is the key to the future. Our society wants instant gratification and the security professional has to find a way to balance security, privacy and convenience.

Chuck McGann
Chief Cyber Strategist, CRGT

[ISACA]

CISSP: A Global Force at 100,000 Strong


Whenever we look toward the future, we have to first look back and think about where we came from. Back in 1989, (ISC)² was established by a handful of passionate volunteers who wanted to create a set of standards for a newer concept, not yet a full-fledged career field, called information security. In the minds of these volunteers, having the initial 500 applicants sign up to take the Certified Information Systems Security Professional (CISSP®) was considered quite a success. Little did they imagine that 26 years later, not only would those 500 applicants grow to a cadre of 100,000 CISSP credential holders across more than 160 countries, further, the CISSP would also become recognized as the standard certification for the information security industry.

(ISC)² was honored to be named ‘Best Professional Certification Program’ for the CISSP by SC Magazine US for the second year in a row, marking our fourth total SC Magazine Award for CISSP. And we’ve been named a finalist for the first ‘Best Professional Training or Certification Programme’ SC Magazine Award UK for CISSP. Those results are to be announced June 2.

As an organization, we certainly aren’t resting on our laurels, satisfied that the CISSP has “arrived.” We continue to actively maintain and enhance the credential, while also focusing on developing and raising awareness for our other credentials. A perfect example of this commitment occurred last month when we refreshed the domains of the SSCP and CISSP to ensure that the examinations and subsequent continuing professional education requirements encompass the topic areas relevant to the roles and responsibilities of today’s practicing information security professionals. We have an obligation to the (ISC)² membership and the industry to maintain the relevancy of our credentials.

Refreshed technical content has also been added to the Official (ISC)² CISSP CBK to reflect the most current topics in the information security industry today. Some topics have been expanded (e.g., asset security, security assessment and testing), while other topics have been realigned under different domains. The result is an exam that most accurately reflects the technical and managerial competence required from an experienced information security professional to effectively design, engineer, implement and manage an organization’s information security program within an ever-changing security landscape.

While we recognize this milestone achievement of 100,000 certified members and look toward the future of the CISSP within the industry, we also need to take into account that (ISC)² has an entire suite of credentials that encompass a holistic, programmatic approach to information security. The CISSP has a 25+ year history and is our most recognized credential; however, it is not necessarily the most appropriate certification for every security professional. (ISC)² has a portfolio of credentials appropriate for the entire security team comprised of information security professionals, software security professionals, IT practitioners, authorization professionals and those specializing in healthcare, forensics and cloud security. For those just starting in the field, we also offer an Associate of (ISC)² program.

As executive director, I’m committed to advancing our vision to inspire a safe and secure cyber world. Hopefully that vision is getting closer to becoming reality with our global force of 100,000 CISSPs and growing. I thank all of the current CISSPs for the great work they’re doing and wish the best of luck to aspiring CISSPs. Keep fighting the good fight.

David Shearer, CISSP, PMP, Executive Director, (ISC)²

[(ISC)² Blog]

APT and Social Engineering: With New Threats Come New Assessment Methodologies

During the last few years, companies have evolved exponentially through the adoption of new technologies, devices and habits that allow them to improve the business from one side, but also to be more vulnerable to cyberattacks from the other. As the attack surface expands and cyberattacks evolve using different techniques and vectors, companies need to adapt their assessment methodologies, going beyond the traditional vulnerability and malware identification or data loss prevention.

For example, consider advanced persistent threats (APT). They are probably the most dangerous threats. They target specific companies and rely on social engineering as the main vector to gain access to inner information and communications technology (ICT) systems. In order to face these threats, companies should start considering possible tools or methodologies to evaluate their risk and the real extent of their exposure. What makes a corporation an attractive target? Could the employees effectively face an advanced social engineering attack? How simple is it to perform a technological attack against workstations? What kind of information is reachable and which assets are exploitable from hidden backdoors?

In my recent Journal article, I talk about the social engineering threat and human factor vulnerabilities, describing a management approach that involves employees as the target of the assessment. It is aimed at measuring the actual related risk, ensuring compliance with laws and regulation.
This approach, called social-driven vulnerability assessment, attempts to go beyond the traditional security assessment, including both the social engineering factor and the related technological consequences as seen through a cyberattack simulation.

Results based on my work experience in the last 5 years show that social engineering attacks are often an underestimated risk. Employees can be deceived into performing dangerous behaviors, such as visiting a web site that could put the company at risk. Moreover, as found through a technological follow-up aimed at simulating a cyberattack enabled from these kinds of behaviors, it is usually possible to bypass the defense layers and obtain access to sensitive information.

The obtained results (i.e., the percentage of employees who fall for a phishing attack or evidence of critical projects or customer data accessed through an attack simulation) are quite impressive and have the advantage of being understandable to nontechnical people. Sharing these results with management could help IT officials obtain the necessary permission to implement countermeasures to social engineering threats, such as awareness initiatives.

Read Roberto Puricelli’s recent ISACA Journal article:
The Underestimated Social Engineering Threat in IT Security Governance and Management,” ISACA Journal, volume 3, 2015.

[ISACA]

English
Exit mobile version