Faces of ISACA: Michael Thiessmeier, Senior Manager, Technology & Security Risk Management, Oportun

Editor’s note: The ISACA Now series titled “Faces of ISACA” highlights the contributions of ISACA members to our global professional community, as well as providing a sense of their lives outside of work. Today, we spotlight risk management professional and ISO delegate Michael Thiessmeier.

Perhaps owed to his military background, Michael Thiessmeier believes that knowing how to perform the duties of both his supervisors and subordinates is the best way to ensure success. He has put in the time to make sure that’s the case.

Thiessmeier has more than 20 certificates and certifications, including ISACA’s COBIT Foundation certificate.

“Think about it this way,” Thiessmeier said. “One person might go watch soccer on Sundays. I might sit on that same couch preparing for a certification exam and feel the same kind of joy and excitement if I pass that the other person feels when their home team scores a goal.”

Thiessmeier joined ISACA in 2012 when professors in Germany – where he was born and spent seven years performing military service – encouraged him to seek out professional organizations.

“I spent years looking for options and evaluating my career path,” Thiessmeier said. “Finally, I determined that ISACA was best aligned with the direction that my career was taking.”

His current role is Senior Manager, Technology & Security Risk Management, with Oportun in Redwood City, California, USA. He is especially interested in how trends like machine learning necessitate automating controls testing.

“Being situated at the intersect of fin-tech and financial services allows me to work on things that have not been done before,” Thiessmeier said. “There truly is no cookie-cutter approach to our industry, and that’s where the research I am doing with ISACA and other organizations turns out to be very helpful.”

Thiessmeier also is heavily involved with ISO as a delegate expert for ISACA, a relationship that came about when he saw an opening on the ISO liaison committee posted on ISACA’s website. He is active in the Security Controls and Services, and Identity Management and Privacy Technologies working groups, and recently was elected as project co-editor for the ISO standard pertaining to application security validation and verification.

Some of Thiessmeier’s career highlights include working on the largest gaming console launch in history – he was manager of consumer services technology with Sony PlayStation during the PS4 launch – while at the same time participating in a major customer relationship management (CRM) implementation that automated consumer service processes.

“During that time I was not only allowed to lead several teams of incredibly smart and caring individuals, but also designed and ran the ‘war room’ used to manage that console launch,” he said. “Thanks to everyone involved, the launch was a great success and beat our expectations.”

Going forward, Thiessmeier intends to learn more about penetration testing. Fitting his overarching approach, that objective isn’t for personal gain as much as to continue deepening his broad-based reservoir of knowledge.

“I do not plan on being a penetration tester at this point in my career, but I want to make sure that I am in the best position to empower them in their day-to-day duties,” he said.

Aside from his traditional career interests, Thiessmeier volunteers for Team Rubicon, an organization that provides disaster response and veteran integration services.

“The moment you see a community that went through a horrible disaster pull together and come out of it closer than ever – no words can describe that,” Thiessmeier said.

[ISACA Now Blog]

Cloud Security Alliance Announces “Grand Opening” of Its New Third-Party Global Consultancy Program

Selected Inaugural Providers BH Consulting, KPMG, Optiv and Securosis Ready to Help Organizations Ensure Secure Cloud Implementation Best Practices

SEATTLE, WA – June 5, 2017 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, today announced the launch and immediate availability of the CSA Global Consultancy Program (CSA-GCP). The new professional services program, developed and managed by the CSA, has been established to support the growing global demand from organizations in need of improved cloud security posture and high standards of compliance and assurance. The CSA-GCP is grounded with CSA’s industry-leading and widely accepted best practices in cloud security and is being offered by a highly-vetted, trusted network of organizations and professionals with the first being BH Consulting, KMPG, Optiv and Securosis.

“For many organizations, adopting the cloud can seem like a monumental task, and it can be difficult to know where to begin as there are too many and often too complex series of business and technology decisions that must be understood and weighted,” said Daniele Catteddu, CTO of the CSA. “The Cloud Security Alliance Global Consulting Program has been created with precisely this in mind and supports our ongoing mission of providing best practices and education for secure cloud computing. These first four program providers are among the most trusted and recognized in the industry and bring with them a broad understanding of the challenges organizations face when moving to the cloud. We are excited and fortunate to have them on board.”

The first four providers making up the initial program network are:

BH Consulting is an independent advisory firm, specializing in information security consulting, ISO 27001, cybersecurity, risk assessment, cloud security, incident response, cloud and digital forensics, and training.

KPMG is one of the largest professional services companies in the world, providing audit, tax and advisory services. KPMG works closely with their clients, helping them to mitigate risks and grasp opportunities.

Optiv is a provider of end-to-end cybersecurity solutions to help companies plan, build and run successful cybersecurity programs in any technology environment, whether on premise, cloud or a hybrid of both.

Securosis is an information security research and advisory firm that has the field-tested techniques, frameworks, and programs to be “more” secure in the cloud than in data-centers, without sacrificing agility.

The CSA-GCP will initially focus on consultancy support in the areas of secure cloud design, cloud architectures, secure cloud implementation, cloud information security programs, cloud assessment and compliance, risk management, and cloud security governance. The following CSA best practices will be included as a reference body of knowledge: CSA Security Guidance, Cloud Control Matrix, Consensus Assessment Initiative, Open Certification Framework and STAR Program, Enterprise Architecture, and Software-Defined Perimeter.

Only organizations with a broad understanding of CSA best practices and values are eligible to be recognized as a qualified source of professional services based on CSA best practices. Provider fees for consultancy work are set independently by each authorized partner and are based on the individual program scope and support required. Organizations interested in working with one of the CSA-GCP providers may visit https://cloudsecurityalliance.org/global-consultancy/#_contact.

For more information on the CSA Global Consultancy Program, please visit https://cloudsecurityalliance.org/global-consultancy/.

About Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, certification, events and products. CSA’s activities, knowledge and extensive network benefit the entire community impacted by cloud — from providers and customers, to governments, entrepreneurs and the assurance industry — and provide a forum through which diverse parties can work together to create and maintain a trusted cloud ecosystem.

Media Contact

Kari Walker for the CSA
ZAG Communications
703.928.9996
kari@zagcommunications.com

[Cloud Security Alliance Research News]

Threat Landscape Demands Action from Enterprise Leaders

In today’s climate, it is fully apparent organizations must treat cyber security as a central business priority.

While awareness about cyber security’s importance is spreading among enterprise leaders – and how could it not, given the way cyber threats have dominated many of our recent news cycles? – ISACA’s State of Cyber Security 2017: Current Trends in the Threat Landscape report suggests that the growing awareness must lead to addressing unsettling gaps in many organizations’ security programs.

The report shows that only 53 percent of organizations have a process in place to handle and recover from ransomware incidents – a very concerning statistic, but perhaps one that will change markedly in the aftermath of the massive WannaCry attacks. The enormous scope of those global attacks made it clear that any organization unprepared for ransomware is in need of “a rapid rethink,” as my ISACA colleague, Raef Meeuwisse, noted.

Concerns about the security of Internet of Things (IoT) devices also show no signs of abating. The majority of enterprises said they are concerned about IoT devices in the workplace, which surely factors into the 4 in 5 respondents who consider it likely or very likely that their enterprise will experience a cyberattack this year.

Not all is gloomy – there were some encouraging findings, as well. The State of Cyber Security 2017 report finds that exploits resulting from mobile device loss is down significantly, which aligns with the recent Study on Mobile Device Security from the US Department of Homeland Security, in conjunction with NIST. That report indicates that mobile device security is generally improving, noting, however, that “many communication paths remain unprotected and leave the overall ecosystem vulnerable to attacks.”

ISACA’s 2016 State of Cyber Security report showed that 50 percent of the responding organizations had CISOs. This year, 65 percent have them, which reinforces that executive leadership is making security a priority. Still, budgets are not keeping up with the rapidly expanding threat landscape; only half of organizations expect an increase in their security budgets in the coming year, 11 percentage points fewer than those who said they expected an increase in last year’s report.

If enterprises are going to be prepared for the mounting challenges, investing in a strong cyber security workforce is a must. Security professionals must not only be trained, but have their skills developed and refreshed using hands-on technical training and performance-based assessment, which is why this year ISACA developed the Cybersecurity Nexus (CSX)™ Training Platform. This focus on skills development must occur while assuring that professionals understand the nature of the enterprises for which they work.

There is much that must be done – urgently – as ISACA’s State of Cyber Security 2017 makes clear. Consider that fewer than half of security leaders said they are confident in their team’s ability to handle anything beyond simple cyber incidents. In today’s threat landscape, that is unacceptable.

By now, the importance of bolstering cyber security capabilities is clear to all responsible enterprises. The ones who commit to developing a strong culture of cyber security – and providing the resources necessary to build skilled and well-trained security teams – are the ones that will thrive in today’s global economy.

Editor’s note: Current Trends in the Threat Landscape is the second installment in ISACA’s State of Cyber Security 2017 report. The first installment focused on workforce trends and challenges. Both reports are available at www.isaca.org/state-of-cyber-security-2017.

Christos K. Dimitriadis, Ph.D., CISA, CISM, CRISC, chair of ISACA’s Board of Directors and group director of Information Security for INTRALOT

[ISACA Now Blog]

COBIT 5 and the NIST Cybersecurity Framework – A Simplified Framework Solution

Picking the right frameworks to support your organization’s governance, risk, compliance and cyber security efforts is overwhelming. Do you pick the most popular framework for each area, or assemble a collection of applicable frameworks that all drive toward a common goal? There are literally dozens of frameworks to choose from, but the common underlying theme is this: create value for the enterprise.  A realistic solution is to create a common core governing model that can link to the myriad standards, models and best practices available while meeting stakeholder needs.

As a former CIO of a managed service provider in North America, I’ve experienced the above. Our company provided outsourced IT services to more than 100 client companies, and we experienced some major issues. Chief among those issues was navigating through the multitude of standards, requirements and compliance needs for each of our tenant organizations. Everyone had different needs, and our charter was to satisfy those needs. Enter the growing demand for a strong cyber security program, and the formula became even more complicated.

We had a gap in our framework architecture that was exposing vulnerabilities in our cyber security posture. At the enterprise level, we used the balanced scorecard and COSO to determine the correct balance of performance and conformance, which was good. Now, skip down to the operational level.  Here, we were haphazardly applying ‘checklists’ from the various popular frameworks and guidance.  These included NIST Special Publications, ISO/IEC 27001, and the CIS Critical Security Controls. As you can probably guess, this is where we became overwhelmed. We had duplicate controls, wasted resources and pressure to meet every part of every security checklist.

There was a gap between enterprise governance and operations; we were missing a vital link. This was the perfect spot to consider the governance of enterprise IT, or GEIT. We needed a mechanism to link the frameworks between the enterprise level and operational level. From our cyber security perspective, we needed this link to be a “framework to manage our frameworks,” and that solution was leveraging the COBIT 5 and NIST Cybersecurity frameworks. This was important because by using risk scenarios as a driver, we could use COBIT and the NIST framework as the critical link, or what I call ‘middleware’ between our enterprise drivers and operational tasks.

This solution allowed our organization to focus our cyber security practices that supported stakeholder needs based on key areas that created value by optimizing our risks and resources. By following the implementation guidance in both COBIT and NIST, we were able to effectively govern and manage our cyber security risks and resources. What were the key benefits to adopting these two frameworks together? Here are the three top reasons for our organization:

  1. Both have solid implementation guidance. Although each framework has a suggested implementation methodology, they are easily mapped to each other and would be best used together for cyber security adoption. The COBIT implementation method offers a step-by-step approach to adopting good governance practices, while the NIST Cybersecurity Framework implementation guidance focuses specifically on the cyber security-related practices.
  2. The frameworks reference each other. Each of these frameworks notes where the other complements them. COBIT refers to the appropriate NIST publications at the process level, and NIST refers to COBIT practices as informative references. This allows for better mapping, reduced duplication, and a broader view of a cyber security program as a part of an overall GEIT initiative.
  3. They both provide a holistic approach. One of the COBIT principles is called “Applying a Holistic Approach,” and focuses on a set of enablers. Think about these enablers as the ingredients to a holistic GEIT program. The NIST Cybersecurity Framework, on the other hand, is what I consider a holistic approach to a solid cyber security program by providing a framework core consisting of five functions (Identify, Protect, Detect, Respond and Recover), and includes activities, desired outcomes, and applicable references.

If you are overwhelmed with all of the cyber security options facing your organization and you’re not quite sure where to start, give this formula some thought. You may find that it is a great way to get a central governing model for your cyber security efforts.

Editor’s note: For more guidance on implementing the NIST Cybersecurity Framework using COBIT 5, view a new ISACA white paper here.

Mark Thomas, CGEIT, CRISC, President, Escoute LLC

[ISACA Now Blog]

Ransomware Do’s And Don’ts

A company I worked for was hit with the CryptoLocker ransomware last year. In the aftermath, we found that some security measures were in place and others were not. We all hear that we need “best practices” in place every day to mitigate risks for events such as these. Are we reviewing our best practices regularly to ensure they are in place and working as intended?

Implementing current patches is the key deterrent to events such as the recent WannaCry attacks. If timely patches are not accomplished, risk is elevated for any vulnerabilities in a company.

Let’s cover some ransomware Do’s and Don’t’s:

DO have a “good” backup you can rely upon. How do you know that it is good? You have tested the backups and can be confident the recovery is 100 percent. Relying on the backup itself is not considered a best practice. We were able to recover the encrypted files on a share drive to which the employee’s infected machine had access, and did not pay a ransom.

DO limit who has administrative rights on local machines. No one had administrative rights to their machine in the company I worked at. It is a special request and reserved mostly for developers.  We also used a tool that provides administrative rights when necessary, where the function was elevated at the time of need and was not tied continuously to the person or machine. This is an IT industry best practice standard that is not generally done in companies and could alleviate risk by 80% or more.

DO provide continuous cyber security awareness training, with training information posted on the company’s intranet site. Have employees take quizzes on the training to ensure understanding, and provide them as much explanation as possible. After all, this is not a secret – we are all subject to infections, vulnerabilities and risks in using both corporate and personal computers every day.

DO use filtering tools for both Internet use and email tools use. The filters will provide some level of mitigation.

DO patch all machines and devices regularly. Review the recommended updates, and then put them on to the appropriate devices at the earliest opportunity. We often hear of infection when patches have been out for years, yet are not applied. Have a monthly review board to study the patches, their outstanding application, and require a signed justification from the department or system owner if the patch is not applied in timely fashion.

Now a few DONT’S:

DON’T allow personnel to access personal email accounts from work machines. A former company had a setting turned on that enabled this, but virtually everyone has a smartphone now and can get to their personal email and information that way.

DON’T rely on the IT experts by default. Ask them the questions necessary to ensure they are doing their due diligence. That firewall setting allowing access to personal email accounts at my former company was in place for years; they would have been able to have that audited. Different teams in IT should all be discussing their configurations together and determining the best practices necessary, and then advising the CIO or director what needs to be put in place. I had to instruct the network people to turn off the setting NOW. I had no opportunity to review why it was on, whether it was necessary, etc. Just turn it off.

DON’T allow non-standard machines to connect to the network, unless IT can review them and determine their use, and are able to sandbox them, VLAN them, etc. You can’t manage what you don’t know about.

There are many measures that can be taken to mitigate risks. The best approach is to evaluate your environment, infrastructure, systems, and people minimally once a year – and sooner as circumstances dictate – to determine how to strengthen the tools and techniques used to minimize damage when an event occurs.

Yes, an attack at some level will happen to everyone, so being prepared, as a good Girl Scout would say, is the best line of defense.

Cheryl Santor, CGEIT, CISM, CISA, CISSP, former Information Security Manager of Metropolitan Water District of SoCal, Chief Compliance Officer of the ISACA Los Angeles Chapter

[ISACA Now Blog]

English
Exit mobile version