Lone Security Wolves Benefit From Expert Groups

The Lone Wolf
Some months ago I responded to a question in the ISACA forum posed by a person who described himself as a lone wolf security professional. In being alone, he was involved in all information security tasks, in every phase of the Deming circle—Plan, Do, Check and Act. The question asked if it was possible and ethical to check his own policy, plan and progress; this is a very good question, and a dilemma that is known by many information security professionals.

In 2010, the Dutch government forced all hospitals to implement information security. This resulted in the creation of my own job as information security officer in one of the larger hospitals in the south of The Netherlands. It was a huge challenge; I had a willing management, but very limited resources, and I was the only information security professional in the organization. In other words, I was a lone wolf. And I had, like the person on the forum, to check my own work. Not because nobody was willing to check my work, but the knowledge was simply not there. Like the person on the forum, I felt very uncomfortable with that situation.

The Lone Wolf Seeks a Pack; the Expert Group
I was lucky; I had a full-time position, although my duties were many. Many colleagues in other hospitals had part-time positions. Thus, a common pool of knowledge did not exist. That is why I started my CISM training, became an ISACA member and contacted security colleagues from the other Dutch hospitals. Not surprisingly, everybody found themselves in the same situation as I did:  limited resources and a deadly deadline set by the government. We decided to meet up. The first meeting with my fellow hospital information security colleagues numbered about 40 persons. A meeting room was kindly sponsored by the Dutch Hospital Association (NVZ). And so the expert group was born, and the lone wolf found himself a pack.

First, cooperation was limited to dividing work. Two of us looked into behavior training and a code of conduct, others wrote a security policy fit for hospitals, the third pair worked out a risk method, others took ICT security as their focus, etc. A digital forum was established to facilitate the cooperation of the group and the exchange of work.

After 2 meetings we started to discuss the inevitable experience in various hospitals with serious security incidents. But we needed a base of trust for discussing these sensitive topics. We agreed as a group to use the Chatham House Rule for discussions, supported by a signed agreement to do so. We learned from each other, and I dare say that 1 meeting with this expert group would have taken me at least 4 weeks to accomplish had I done the work myself. By the end of 2010 all participants to the expert group successfully passed the obligatory external audit.

Success!
The expert group decided to continue. The improvements to information security were made, but there were many other issues. One was how to continue with auditing. We agreed that the external audit process for hospitals was poor. The auditors had mostly no clinical experience, the audits were expensive, and audit approach used was so diverse that the results between hospitals had no base for comparison.

Together with a colleague I proposed to organize audits between hospitals that were to be carried out by members of our expert group. Within 2 years’ time we trained over 60 persons as CISA auditors, and within 1 year the first audits took place. A team of 2 auditors from different hospitals audited a third hospital. Thus we solved several problems at once. We no longer had to check our own work, and we got relevant feedback against low costs.

This system is currently still working, and about 70% of the Dutch hospitals are participating. I decided some years ago to leave the hospital and start my own company. Currently, I help health care organizations with information security. Building expert groups is still part of my strategy.

Gilbert van Zeijl, MSc, CISA, CISM, Clinical Informatician

[ISACA Now Blog]

Training: The Missing Ingredient for IT Success

Over the years, it has come to my attention that few industries innovate faster than IT. And while I am surrounded by many of these changes in my everyday life, I try not to underestimate the value of ongoing training and how it improves my skill set and could potentially open up new career opportunities.

Regular IT training is by far one of the single most valuable things I do on a regular basis.

Benefits of Ongoing Training
I will admit that I do not like the word “training.” It takes me back to being a student in a structured classroom setting. But training really is a positive thing. It is what gives us the knowledge and skills necessary to complete the tasks and objectives we face in our jobs.

With that being said, here are some of the biggest benefits that I have found in committing to ongoing training.

  • Less supervision. When you know what you are doing and have the knowledge to handle any issue, you no longer need someone looking over your shoulder. As a result, you will find that one of the direct benefits of training is less supervision.
  • Growth and salary opportunities. The more you train, the more skilled you will become. This ultimately will open up the door for new opportunities and career advancement. As a by-product, ongoing training can lead to higher salaries.
  • Increased satisfaction. If you are good at your job, you are more likely to enjoy it. This leads to more happiness and satisfaction in your daily job—benefits that cannot be purchased.

Invest in training and you are sure to reap positive and tangible rewards that will benefit your career for years to come.

How to Make Training a Habit
The occasional training session and brief seminar will not do you much good—at least it does not for me. In order for training to provide benefits, it needs to be a priority.

Here are some of the ways I have made training a consistent habit in my life:

  • Carve out consistent time. The most important thing is that you make time for training. “Pick a consistent time and set a reminder,” suggests CBT Nuggets, a leader in online IT training. “Maybe it’s right after breakfast, during lunch, or right when you get home from work. Whatever time will work best for you, be consistent and set a reminder. By using multiple cues (time and sound), you will increase the motivators that will move you to train.”
  • Involve others. It is much easier to make training a priority when you have others involved. While you do not necessarily need to do the training with other people, consider launching your individual training at the same time as a friend or coworker’s training. This provides some accountability and keeps you on track.
  • Choose something interesting. Learning is always much more fun when you are actually interested in the topic at hand. When choosing different ongoing training programs and curriculum, go with topics that you like—or topics that you want to know more about. I know I am much more likely to stay on track if the subject intrigues me and holds my interest.

Anyone can make training a habit. The key is to set up a foundation in which success is more likely than failure.

Keep Moving Forward
As motivated people often say, “If you aren’t moving forward, you’re going backwards.” In other words, because technology advances so quickly, sitting still is the equivalent of backtracking.

Well, the good news is that it does not take much time or effort to move forward in the IT world. You already have most of the knowledge you need! All that is necessary is ongoing training on a consistent basis. It has taken time and effort, but I have made it a part of my weekly schedule. I am confident that you can do the same!

Editor’s note:  ISACA offers numerous training and education opportunities. For more information click here and click here for CSX training information.

Larry Alton, Writer, LarryAlton.com

[ISACA Now Blog]

Suggested Tips Auditors Need to Know About Cyber Security

We live in an age when social media, mobile devices and the Internet of things (IoT) dictate how we access, manage and communicate information. This technology is constantly changing and relatively complex in nature. Thus, it is essential that enterprises have a fully functional and effective information security program.

The responsibility to ensure such a program is properly implemented resides with senior management. The main objectives of such a program are to ensure the confidentiality, integrity and availability of the information assets and associated resources.

These overall objectives should be supported by safeguards known as controls, which are put in place to mitigate the risks associated with the use of the technology. If the controls are operating effectively and efficiently, the potential for loss and harm to enterprises assets should be reduced to an acceptable level. The question is who and/or what makes the determination of the effectiveness and efficiency of the controls.

This is where auditors come in. Their role is to review and perform tests to ultimately provide a level of assurance to management and the board of directors that the controls in place are appropriate, are in fact operating and are meeting the intended objectives. In many cases, this job function is relatively straightforward. However, many would argue that when it comes to cyber security technology, although the auditor’s role doesn’t change, the complexity of the audit does.

Auditors have an obligation to educate themselves on this powerful and evolving technology, and there is much to learn. Below are 10 things an auditor needs to know about cyber security. This list is not all-encompassing, nor is it ranked in any order.

  1. Everything is connected to everything. The primary function and objective of any cyber device is connectivity. Devices are like climbers roped together on the side of a mountain – if one falls, it can bring down anything connected to it. The Target hack (through an HVAC supplier connection) clearly demonstrates the need for a holistic cyber security view. With the arrival of the Internet of Things, it’s imperative that auditors understand and address the bigger picture.
  2. All risks are subjective. To qualify as a “risk,” a threat needs to be associated with a vulnerability that – if exploited – could negatively impact an information asset. If it does not, it is not a threat. Too many auditors worry about threats and vulnerabilities that pose no actual risk to an asset, prioritizing compliance over risk and wasting precious time and resources.
  3. Users are (and will always be) the biggest security risk. Our industry is led by vendors, and we continue to seek security through products (firewalls, IDS/IPS, DLP, etc.). We invest in product before people while real and measurable results can be achieved by investing in information security awareness. To contribute tangible results, auditors should prioritize people over product. Cyber security education is the silver bullet.
  4. Leverage existing frameworks/guidelines. Auditors should consider mapping of the NIST “Framework for Improving Critical Infrastructure Cybersecurity” to ISO 27001:2013 controls and COBIT 5 to reduce the scope of the audit, making the audit more manageable.
  5. Consider forthcoming legislation. Auditors should study how forthcoming and existing legislation like General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI-DSS) could potentially be incorporated into cyber security programs. Also, auditors need to understand the global regulatory environment and the differences that can exist between different geographic regions.
  6. Basic information security controls still hold true. As part of overall security (including cyber security), these controls provide a valid baseline of security controls that help create in-depth security, such as physical and logical access controls and application of “principle of least privilege.”
  7. Utilize a cyber incident response policy and plan that is fully tested. Auditors need to assess whether a proper crisis management and communication plan is in place, clearly communicated and tested as appropriate. This should enable sufficient business continuity in the event of a cyber security breach. Crisis management should include incident response and forensics, where warranted. Proactive monitoring and detection (with automated tools) should be in place.
  8. Cyber security strategy needs to be agile – the landscape is “mutating.” Strategy needs to be adaptable and scalable to handle new attack methods, such as ransomware and cloud-related risks. Auditors need to be aware that this is an area that is constantly changing and must not assume that what currently keeps your IT environment secure will continue to remain secure indefinitely.
  9. Cyber security awareness depends on the right training. Employees need sufficient and timely education and training to help combat ever-changing cyber security threat. Security needs to be interwoven into the fabric on an organization.  One-off, box-checking exercises are not sufficient. For example:
    • Do employees understand the implications of a cyber security breach?
    • Has any thought been given to insider threats from a cyber security perspective?
    • Is there clear guidance on the use of social media/shadow IT solutions/BYOD/how to respond to a phishing or ransomware attack?
    • Are employees rewarded/praised for promoting security in an organization? Are they incentivized?
  10. Be aware of credential theft techniques. Auditors should have knowledge of credential theft attack techniques. Typically, the Pass-the-Hash (PtH) attack and other credential theft attacks utilize an iterative, two-stage process. First, an attacker captures account logon credentials on one computer, and then uses those captured credentials to authenticate to other computers over the network.

Editor’s note: To learn more, register for ISACA’s 6 December webinar, “Suggested Tips Auditors Need to Know About Cyber Security.” Click on the link below to register:
www.isaca.org/Education/Online-Learning/Pages/Webinar-Suggested-Tips-Auditors-Need-to-Know-about-Cyber-Security.aspx

ISACA also is offering a one-day workshop entitled “Cyber Security for Auditors” immediately following the 2017 North America CACS conference in Las Vegas, Nevada. For more information and to register, click on the link below:
www.isaca.org/Education/Conferences/Pages/North-America-CACS-Presentations-and-Descriptions.aspx#ws7

Paul Phillips, Technical Research Manager, ISACA

[ISACA Now Blog]

Will Your Business Be Competitive in 10 Years?

For a moment think about these statements:

  • Technology has evolved and is evolving faster than ever before.
  • My enterprise is facing unknown competitive threats.

After considering these statements, how would you answer the question of whether your business will be competitive in 10 years?

With the countless factors that exist across every sector, the question is very difficult to answer. The pace of positive, negative and unclassified technological advancements is exponentially greater than ever before. How will your enterprise and IT governance structure survive these exciting times?

Consider Your Enterprise’s Risk Appetite
Information technology is now a core component in achieving business objectives. So if we look at it from a business growth point of view while anticipating current trends, your strategy may have to shift to focus on digital channels. What this means for your business is that you need a digital footprint that is both secure and user-friendly. With every new strategy you may have new risks, so your company’s risk appetite has to be considered.

What type of IT service and infrastructure would you need to deal with multiple types of digital connections that deliver standard functionality across these channels? How would this impact your resources and IT management options? Do you need to move to the cloud? Broadening the enterprise’s digital footprint can create the possibility of multiple connections to your services via numerous known hardware (e.g., tablet, watches, laptops, cell phones), along with anything that can be digitized. Your traditional business structures are now expanded with newer delivery options, so supporting demand now requires a rethinking of traditional network structure to handle the new scales. This can become an issue for many enterprises.

The security aspect of the future cannot be overlooked because you now have a wider attack surface and crippling ransomware to deal with. If your security fails, this affects customer perception, and you will not be able to honor the confidentiality and integrity of the user experience. Ransomware is quite destructive because not only does it affect the availability of the infected data, you also have to pay hefty sums to get back access to your data if there is no mitigation plan in place. Can your enterprise continue to meet the current industry regulations and maintain a secure infrastructure into the future?

GEIT Can Get You There
Within the next 10 years your enterprise will face the growing Internet of Things (IoT) landscape, with faster, more convenient delivery methods, harboring both increased risk and lucrative opportunities.

With a flexible governance of enterprise IT (GEIT) model, you could construct a relevant framework that looks at how the enterprise’s strategic plans and IT work together. You could look at continuous improvement actions and keep this alive within the enterprise. You could ensure IT risk management is aligned with the enterprise’s risk appetite and that security is considered at all points. You could consider various means to optimize your IT resources and capabilities required, as all these are key to helping your enterprise adapt and remain relevant in the future landscape.

Ammett Williams CCIE, CGEIT, Telecommunication Team Leader – First Citizens, TT

[ISACA Now Blog]

Tech Certifications Are Earning Cash Premiums, and Info/Cyber Security Certs Are the Hottest

Why would an employer pay its tech workers extra cash for a skill or certification if they’re already getting a salary and annual bonus?

There are a dozen good reasons why, and they all share one thing in common: None would be necessary if the company’s compensation structure and pay practices were agile enough to successfully compete for talent in volatile labor markets. The nature of the tech labor marketplace is exactly that, where the market value of a job or skill can move like a roller coaster depending on what’s hot and what’s not at any given moment. If your employer doesn’t have built-in flexibility to react quickly and correctly, it will struggle to find and keep people to execute tech-enabled business strategies.

Who Needs Skills Pay and Why
How do you know if your employer is a victim? Say, for instance, your company doesn’t normally have trouble retaining tech talent and suddenly the best people start walking out the door. Most likely your company wasn’t able to match competing salary offers. Then to make matters worse, it’s soon discovered that the competing offers were actually realistic average local market salaries for these positions – so your employer was underpaying these people from the start. It’s called ‘salary compression,’ when market-driven pay for talent is growing at a faster rate than the annual salary increases employers are able to offer their workers.

Compression is a widespread systemic reality that tends to be much worse in the tech workforce because of the rapid evolution of technology, skills and jobs. Every employer must decide whether to fix it permanently (very difficult) or patch it occasionally (less difficult and more practical).

If there is little leeway in the incumbent’s salary range to sweeten the pot on a counter-offer, and a promotion is not a viable option, paying workers extra cash for critical skills and certifications can be the perfect solution. That is especially true when workers possess the very hot certified or noncertified tech skills that other employers are aggressively targeting. The trick is to tie this extra cash directly to current market value for the hot skill or certification and guarantee that premium for some period of time, usually one year or more. When time’s up, the employer can check whether market value has changed and decide if it makes sense to continue to pay the skills premium and how much to pay, or to switch it out for another hot skill that has become more valuable to the organization.

What is the current cash market value for certifications?
Extra pay awarded to 69,900 U.S. and Canadian IT professionals for 880 certified and noncertified IT and business skills – also known as skills pay premiums – has been tracked and updated quarterly since 1999 in the IT Skills and Certifications Pay Index™(ITSCPI). About 3,000 private and public sector employers currently provide this data to Foote Partners, covering a total of 255,600 IT professionals at these companies.

ISACA certifications are doing extremely well. As a group they’ve gained 15.3 percent in cash market value in the last six months compared to nearly 8 percent growth in pay across all 80 security-related certifications in the ITSCPI. The Certified in Risk and Information Systems Control (CRISC) and Certified in the Governance of Enterprise IT (CGEIT) are the top gainers. The CSX Practitioner (CSXP) certification appeared for the first time in the latest ITSCPI, earning an average pay premium equivalent to 12 percent of base salary – a very strong number for a new certification.

The following security certifications are earning the highest pay premiums right now. They’re paying median cash premiums equivalent to 13 percent to 19 percent of base salary, typically paid out each pay period as a cash bonus in addition to salary, and are shown below in descending rank order of market value including ties, arranged alphabetically within each rank.

  1. Certified Cyber Forensics Professional
  2. (Tie) Certified Forensic Computer Examiner
    CyberSecurity Forensic Analyst
    GIAC Reverse Engineering Malware
  3. (Tie) EC-Council Certified Incident Handler
    EC-Council Computer Hacking Forensic Investigator
    GIAC Certified Forensics Examiner
    GIAC Certified Forensics Analyst
    GIAC Exploit Researcher and Advanced Penetration Tester
    GIAC Web Application Penetration Tester
  4. (Tie) GIAC Enterprise Defender
    GIAC Secure Software Programmer–Java
    InfoSys Security Architecture Professional (ISSAP/CISSP)
  5. (Tie) Certified Information Security Manager (CISM)
    Certified Information Systems Security Professional
    Certified in Risk and Information Systems Control (CRISC)
    EC-Council Licensed Penetration Tester
    InfoSys Security Engineering Professional (ISSEP/CISSP)

Market values for 412 tech certifications in the most recent ITSCPI data update are averaging the equivalent of a 7.7 percent of base salary and as a group recorded gains in 14 consecutive calendar quarters, unprecedented in the 18 years Foote Partners has been tracking and reporting compensation for certifications. Figuring prominently in this growth has been info/cyber security certifications.

Market values for 80 info/cyber security certifications have been on a slow and steady upward path for four years, up 10.7 percent in average cash value as a group in just the past 12 months and 15 percent during the past two years – the largest gain among all certification categories reported. Strong performing security certifications so far in 2016 cut a wide swath: cybersecurity, forensics, penetration testing, perimeter protection and enterprise defense, security analysis, risk and security software programming.

Editor’s note: Registration is open for the first testing window of 2017 for ISACA’s core certifications.

Exams for CISA, CISM, CGEIT and CRISC will be offered in 2017 at PSI testing locations worldwide during three, eight-week testing windows. The first testing window will be 1 May-30 June, with 28 February marking the early registration deadline. Exam registration via the ISACA website is available at www.isaca.org/examreg.

David Foote, Chief Analyst and co-founder, Foote Partners, LLC

[ISACA Now Blog]

English
Exit mobile version