Faces of ISACA: Maria Divina C. Gregorio, CISA, CRISC, PCI-ISA, PCIP, internal audit manager, VSP Global

Editor’s note: The ISACA Now series titled “Faces of ISACA” highlights the contributions of ISACA members to our global professional community, as well as providing a sense of their lives outside of work. Today, we spotlight Maria Divina C. Gregorio, CISA, CRISC, PCI-ISA, PCIP, internal audit manager, VSP Global, a US resident from the state of California.

ISACA Now: What motivated you to pursue a career in audit?
I chose a career in audit because it allows me to have a comprehensive understanding of and exposure to all facets of the business. I am able to use my knowledge, analytical techniques and people skills to effectively contribute to the betterment of the organization. I was also influenced by a mentor early in my career who encouraged me to explore opportunities in this field and introduced me to ISACA’s CISA certification.

ISACA Now: How do you see technological advancements having the greatest impact on audit in the next 3-5 years?
I believe that technological advancements have and will pave the way for more efficient, more effective and more economical audits.

ISACA Now: What are a few professional achievements of which you’ve been most proud?
I am proud to have achieved my CISA, CRISC, PCI ISA and PCIP certifications. They allowed me to lead highly impactful audits that resulted in major cost savings to the organization. I am very proud to have authored our cyber crisis management plan, and I am now leading the global business continuity initiative in my organization.

ISACA Now: How long have you been an ISACA member, and what has that added to your professional development?
I have been a member of ISACA since October 2005 – 12 years! I believe that the benefits derived from my ISACA and other professional association membership, certifications, active participation in my local chapter, passion toward my profession and continued quest to educate myself have been a great formula for my professional development.

ISACA Now: You’ve been active in Habitat for Humanity – what have you taken from that experience?
I’ve always been guided by a personal commitment to leave this place a little better than I found it. I believe that serving with Habitat is my small contribution to that commitment.

ISACA Now: What is the most fun aspect of living in California?
Do I feel like having authentic dim sum breakfast in San Francisco this morning, then heading to a Napa vineyard for lunch and some wine? Or how about some honest to goodness mole in the Mission, then heading to the beach and gazing at migrating whales in Bodega Bay? Or maybe picking up my skis and hitting the slopes at South Lake Tahoe, or lounging in a houseboat in Shasta Lake? As you can see, there is something for everyone in California. I feel very blessed to have these choices – all within hours from each other!

ISACA Now: What are some of your favorite things to do outside work?
I read, go on hikes with my dog; tend my organic garden; feed the ducks, peacocks (yes, we have them “wild” around my neighborhood) and turkeys; swim; work out; and have lunch dates with my mom.

[ISACA Now Blog]

H1-B Visas Critical to Address Cybersecurity Professional Shortfall

Based on the findings of the 2017 Global Information Security Workforce Study, the world will face a deficit of 1.8 million information security professionals by 2022. With headlines dominated by breaches and cyber threats, we at (ISC)² need to be a strong voice and advocate for the global cybersecurity workforce.

It is for this reason that I sent a letter to White House Chief of Staff, Reince Priebus, on behalf of the (ISC)² organization and our members across the globe, to provide feedback on President Trump’s Executive Order, which directed the Department of Homeland Security to review how it issues H1-B visas.

Even after giving U.S. citizens priority consideration for open cybersecurity positions, we will still face a substantial talent shortfall, which can be mitigated with an H-1B visa program that helps bring skilled and trained workers from other countries to fill these roles.

(ISC)² suggests our Certified Information Systems Security Professional (CISSP) certification as one way to verify cybersecurity professionals for H-1B visas. The CISSP was the first credential in the field of information security to meet the stringent requirements of ISO/IEC Standard 17024, and is also Department of Defense 8140/8570 approved. Professionals with the CISSP have proven their knowledge and experience in the field. Our members also must abide by a standard code of ethics, which includes the following canon: “protect society, the common good, necessary public trust and confidence and the infrastructure.”

We do not want to prevent talented cybersecurity professionals, such as our global members, from offering their expertise to benefit the U.S. economy.

I recently testified in a Subcommittee on Information Technology on ways that the United States can improve the federal IT workforce. We also provided recommendations to the Trump administration on how to improve the current status of the federal cybersecurity workforce. Utilizing the expertise and experience of our membership, these recommendations were created following our 2016 federal CISO forum, which included members of the (ISC)² U.S. Government Advisory Council (USGAC) and other federal CISOs and executives who participated in discussions surrounding these critical considerations.

(ISC)² hopes to establish a constructive dialogue with the Trump administration as they strengthen cybersecurity for our country.

Dan Waddell, CISSP, CAP, PMP
Regional Managing Director, North America Region, (ISC)²

[(ISC)² Blog]

Tracking Members’ Progress with GDPR: Europe’s New Data Protection Regulation

Download the 12 Areas of Activity and their key supporting tasks

The (ISC)² EMEA Advisory Council is turning to its professional membership to measure the readiness of organizations and security departments for the General Data Protection Regulation (GDPR) and highlight the challenges they are facing in the effort to become compliant by May 2018. We are doing this by bringing people who are actively working on implementation projects together either on monthly international calls and, as of this month, in face-to-face workshops hosted at (ISC)²’s new two-day Secure Summits, five of which are being held across the EMEA region this year. The first such workshop staged a series of round table discussions at our Secure Benelux Summit in Amsterdam gathering over 120 information and cybersecurity professionals from various industries. Another is set for Stockholm at the end of May, and we’ll be in Zurich for the end of June.

Through this effort, we are helping our members realize expectations and requirements that they hadn’t anticipated. In January, for example, we raised the alarm around the lack of engagement and support from the business units which hold the key to assessing how and why personal data is collected, how it is processed and used, and therefore how much effort should be made to ensure the company can continue to work with it. Lack of engagement continues to be a challenge with many of our Summit workshop participants reporting that they are still working to motivate the stakeholders needed across various functions. Unfortunately, the work continues to be the domain of a few as most employees and their managers have yet to understand that GDPR is a task for everybody.

Work is progressing on the development of policies—legal departments are active in the review of contract clauses, plans are being made to communicate privacy notices to individuals—but there remain many practical gaps and a level of detail that many in the room admitted they had not yet considered. An example included employee awareness and the need to manage their downloading of data on laptops. It was clear training would be required, but the scope of such training has yet to be defined. In considering the need for an inventory of the personal data held, some very basic questions are still being asked, such as: How can you know when the task is complete?

There are also numerous uncertainties arising as requirements are translated into the processes needed for implementation. Discussions covered whether companies could rely on consent gathered decades ago, should a record of it be found.  Participants were unclear as whether privacy notices would have to be given in local languages—or all EU languages. To challenge things further, the role of the Data Protection Officer and parameters to conducting Data Protection Impact Assessments have not yet been fully defined by the EU Committee (Article 29 Working Group) working with and providing guidance to member states. And, as is currently the case for security practice in general, companies will continue to be challenged to gain the control needed over legacy systems and shadow IT to assure compliance. This is expected to, for example, frustrate the effort to document a process and efficiently fulfill data subject access requests, a new individual right that will come into force.

Overall, with just over a year to go to the compliance deadline, organizations remain in discovery mode. Plans are being put in place, but we are still developing our understanding of the scope of the task ahead, and our engagement with the organization. To address this concern, the EAC GDPR Task Force has worked with members’ input to define 12 Areas of Activity and their key supporting tasks, as well as some of the tips they shared for implementation. They can be tackled simultaneously, are easy to understand, and importantly, communicate to the people that will be responsible for achieving them:

  1. Stakeholder support: board and business units
  2. Inventory of the personal information you hold
  3. Privacy notice and information
  4. Individuals’ rights
  5. Data subjects’ access requests
  6. Data Protection Impact Assessments
  7. Consent
  8. Children
  9. Personal Data Breaches
  10. Security of data processing and Data Protection by Design
  11. Data Protection Governance
  12. International Data Transfers

We will continue to share what we learn from the upcoming opportunities to learn more about members’ experience as we progress. Workshops will be held at all the (ISC)² Secure Summits in the EMEA region this year, and an overview will be shared within the Strategy Theatre at Infosecurity Europe June 8th. Join us if you can and let us know how you are getting along.

Yves Le Roux, Co-Chair (ISC)² EMEA Advisory Council (EAC) and Chair of its GDPR Task Force.

[(ISC)² Blog]

Giving Thanks to Those Who Volunteer

It’s National Volunteer Week in the US. ISACA, however, is global in its reach, as is our corps of dedicated volunteers, and I want us to honor them all. So, I am choosing to declare this period as “ISACA Volunteer Appreciation Week.” In this spirit, I ask you, members of our professional community worldwide, to join me in thanking our organization’s over 4,000 members who provide us with their generous gifts of time and expertise to support advancing ISACA’s purpose to help realize the positive potential of technology.

Here, in their own words, are a few examples of volunteers’ contributions, and their motivations to give back to ISACA and our profession:

  • Hari Chede, president of the UAE chapter, speaks proudly of his impact on members’ career development and of skills he’s gained through his volunteer work conducting CISA and CISM review classes: “If you have a passion in assurance fields and you want to grow in that field, apart from having different assurance certifications and education, being a volunteer at ISACA can accelerate your career by learning various skills (event management, time management, project management, accounting and public speaking) and keeping you engaged with successful people in the assurance fields.”
  • Joe Cai helps position ISACA to expand its global impact by volunteering as a translator as a member of the CISA Certification Working Group: “I find ISACA is paying more and more attention to the market in China. ISACA is providing many Chinese Simplified materials to break the language barriers and engaging with the local community, both of which require lots of local volunteers. With their help, we can build a good ISACA ecosystem, gathering more and more IT control, security, risk and governance professionals in China. Participating also affords volunteers many benefits like building relationships with industry peers, acquiring more IT control and cyber security trend information and knowledge within China as well as ISACA global, and meeting other ISACA members from all over the world.”
  • Jo Stewart-Rattray serves as volunteer chair of ISACA’s Women’s Leadership Council which has developed and launched the Connecting Women Leaders in Technology program to address urgent challenges of women in the technology workforce: “Together with my HQ colleagues, we have brought together a group of influential women from across the world to build the resilience and confidence of our women leaders to seek the career they want and to provide the knowledge assets and connections that can guide them along the way. ‘Connecting Women Leaders in Technology’ is in response to a great want and need for such initiatives from our constituency base. Without women in the workforce, we simply won’t have the resources to continue to fuel the job economy and innovation.”

In 1969, it was a small group of volunteers in Los Angeles who had the foresight to see the need for our work as a result of companies investing in technology capability to support financial and business operations. They established the EDPAA, and sowed the seeds of opportunity that led to our current day ISACA. As we approach our 50th anniversary, volunteering has always been at the foundation of ISACA’s evolution. Increasing this engagement will be a hallmark of how we write the next 50 years of ISACA’s history.

On behalf of the entire ISACA family, we thank our chapter leaders who work tirelessly to increase ISACA’s visibility, influence and impact locally. We thank those who contribute to keeping our certifications and continuing education relevant in a constantly changing workplace as a result of a rapidly changing technology landscape and an increasingly complex legal, regulatory and compliance environment. We extend our gratitude to those volunteers committed to advocating for and strengthening our professions, creating opportunities for career growth and, perhaps most importantly, helping all of us to share the value of what we do to enable the organizations for which we work.

In a world where time is our most precious commodity, your willingness to give back inspires us all, especially knowing that you do so above and beyond your many other professional and personal responsibilities.

Editor’s note: To learn more about volunteering with ISACA, visit www.isaca.org/volunteer. To share your volunteer story, email mswartz@isaca.org.

Matt Loeb, CGEIT, FASAE, CAE, Director and CEO, ISACA

[ISACA Now Blog]

As CISOs’ Roles Evolve, So Do the Reporting Lines

Author’s note: This post was inspired by the discussions among CISOs attending ISACA’s 2016 CISO Forums, plus additional readings and personal experience. The opinions are my own. For more insights from the CISO Forums, read ISACA’s CISO Board Briefing 2017.

A study by K logix Research titled “CISO Trends” found that “53% of CISOs state that one of their main objectives is to align security with business goals while 46% want to partner with business leaders to help them solve problems.”

This will have implications that go far beyond resource allocation. The CISO’s contribution to the organization is fundamentally to enable growth and support the attainment of the strategic objectives. The CISO will achieve this by ensuring that the information security posture is commensurate with the risk appetite and compliant with industry requirements.

When a group of CISOs discuss reporting, you rapidly come to realize that there is not a unique global best practice. In fact, as indicated in ISACA’s CISO board briefing, “there is not one correct organizational map, not one universal title and not even one universally applicable job description for the information security executive.”

To best fulfill this role, a key success factor is having the CISO as close as possible to those who set the tone at the top. Direct reporting to the CEO is what first comes to mind. Working closely with the CEO helps ensure best alignment of security with business imperatives. This requires an excellent working relationship between the CISO and the CEO.

Being perceived as part of the inner circle has its ups and downs. Other executives and directors will want to display a collaborative attitude and deal with the CISO as a key player but might also see the CISO as a threat to their own agenda.

The same study by K logix points out that “more than half of CISOs report to the CIO, and just 15% report to the CEO, with the rest reporting to the COO, or Risk-related organizations. But when asked about the future of the security organization, 50% of CISOs responded that the role will report into the CEO.”

There are some public examples in which even the CEO had an agenda that made her avoid her CISO. Googling Yahoo’s Marissa Mayer will provide an example of a situation in which no CISO wants to be part.

A very prevalent option is reporting to the CIO. As information security gained recognition and started to be recognized as no longer a technical issue, the person in charge was promoted and reported directly to the CIO. At the time, this was a very positive enhancement of the role. But while may work well for some, it comes with some risk. The CIO is under heavy pressure to deliver the required projects on time and within budget. In this model, the CIO, who has a supervisory function for security and other matters, may also be influenced by personal financial considerations, such as a bonus – particularly in the private sector.

The CIO will eventually be confronted with conflicting objectives when the project does not meet the security requirements and is running out of time or budget.  Security is at risk of being sidetracked. There is a clear rationale for having the CISO function independent of IT.

Other reporting lines may be to the chief risk officer, chief financial officer, chief operations officer and even the chief audit executive.

In “Determining Whether the CISO Should Report Outside of IT, Refreshed” from research firm Gartner, it is noted that:

  • “Information security organization design is influenced by a host of factors specific to each enterprise that must be well understood before the adopted structure can work optimally.”
  • “The main trend has been a tendency to establish a corporate information security function outside of the IT organization.”

When the opportunity comes to revisit the reporting lines for the CISO, it’s no time to try to be idealistic. One must determine which is the best option within the context/culture/environment of his or her organization.

Among other considerations, one must assess the organization’s vision and strategic goals, culture, management style, security maturity, IT maturity, risk appetite and all relevant dynamics involving the current security posture and reporting lines.

Michel Lambert, CISA, CISM, CRISC, CGEIT, CISO, Québec Ministry of Agriculture, Fisheries and Food

[ISACA Now Blog]

English
Exit mobile version