GRC Solution: Now More Than Ever After Brexit

Author’s note:  Whatever your political views on the United Kingdom’s recent “Brexit” from the European Union, I am writing this article to share some of my thinking on the need for a Governance, Risk and Compliance (GRC) solution in the aftermath of this decision. It’s just my opinion, but it has been formed after extensive discussions about the implications of the decision.

Thursday 23rd June was a most momentous day in Great Britain; the UK voted to leave the EU!

It was widely believe, before the Brexit vote, that leaving the EU was highly unlikely. Thus, when the Brexit referendum results were announced, the decision to leave the European Union was so unexpected that £120 billion was wiped off from FTSE 100 and value of the pound fell to its lowest since 1985. The Brexit decision has had global impact, creating a ripple effect across European Union referendums and the US presidential elections.

Brexit will have a long lasting and dramatic impact on international financial markets, investment, prices and jobs. Industries, both within the UK and globally, will feel the repercussions of this decision. As a result of these upheavals, it is likely that a post-Brexit global landscape will forcefully push organizations to fix their broken processes and siloed business approaches, while minimizing unnecessary interfaces and addressing the lack of linkage between corporate objectives and informed decisions.

Good Governance Desperately Needed
Now, more than ever, board and senior management will be desperate for ‘line of sight’ across all business functions, and better aligned resources that contribute to the delivery of desired outcomes.

Failure of good governance, a rising tide of cyber threats on the global risk landscape in both frequency and scale, a deluge of regulations, including the EU’s General Data Protection Regulation, to be complied with and the enormous headcount for the ‘eight eyes’1 control system, are keeping boards and senior management awake at night.

In our post-Brexit world, now is the best time for organizations around the world to act in aligning their three lines of defense by using automated governance, risk and compliance (GRC) solutions.

The current situation provides a compelling business case for formulating and investing in an automated GRC solution. I am convinced that organizations will benefit by integrating technology into their GRC activities.

Six Automated GRC Solutions
An automated GRC solution will provide an integrated and holistic approach to organization-wide governance, risk, and compliance efforts to ensure that the organization acts ethically and in accordance with its risk appetite, internal policies and external regulations through the alignment of strategy, processes, technology and people, thereby improving efficiency and effectiveness. More precisely, automated GRC solution will help organizations to:

  1. Manage third-party risk and compliance issues.
  2. Manage regulatory content and change management in dealing with regulatory proliferation.
  3. Develop risk analytics to support integration of risk management and performance management.
  4. Perform business performance audits as a key internal audit feature.
  5. Decide which business processes/assets are critical to their operations in term of confidentiality, integrity, availability ratings so they can prioritize and focus on critical applications.
  6. Create a risk culture by articulating the organization’s risk appetite.

In my view, the lessons generated from Brexit will give management the opportunity and ability to constructively challenge and help boards to develop robust GRC plans. The board needs a fine sense of risk appetite against which to judge investment decisions, allowing ‘line of sight’ for key objectives, from top to bottom, before making any decisions.

It is clear that, in the wake of Brexit, we will experience some choppy waters. As far as the political landscape is concerned, it is now a monumental challenge for those in power to figure out how this new world is going to actually work. As professionals working in governance, risk and compliance, we need to be ready for the economic surprises popping up around us.

1 Most organizations still have manual control testing, requiring nonessential headcounts due to the frequency of the control reviews in managing operational and compliance risk, so it is difficult to determine how effective these reviews are as failures can still occur.

Rehan Haque, CISA, CISM, CRISC, Academic Relations & Research Director, ISACA London Chapter Board

[ISACA Now Blog]

White House Strategy Proposes The Next Cyber Career Trend

In mid-July, the White House released its “first-ever”Cybersecurity Workforce Strategy, a directive under the Cybersecurity National Action Plan (CNAP) and the President’s 2017 budget. Its goal is to “…grow the pipeline of highly skilled cybersecurity talent entering federal service, and retain and better invest in the talent already in public service.” The government believes that by implementing this Strategy, it will elevate the attractiveness of public service to such a level that every private sector cybersecurity leader will ultimately deem it essential to his/her career to complete a tour of duty in federal service. How many cyber and IT professionals are they looking to attract? According to the White House blog, the magic number is 3,500. How long will it take? The goal is to reach its target number of new hires in six months’ time.

For those industry stakeholders who have evolved their corporate mission and dedicated significant organizational resources to solving this extremely complex cybersecurity workforce shortage, at first glance, this Strategy might appear to be lofty at best. On the other hand, it is extremely validating. This new Strategy demonstrates that the government is listening to the voice of (ISC)2 and to the many other organizations that have done the work to develop and provide sound recommendations, including those cited in the survey we just released in May. This Strategy demonstrates that those responsible for the government’s cybersecurity workforce challenge at least know what it’s going to take to fix the problem.

I am honored to participate in one of the sub working groups under the National Initiative for Cybersecurity Education (NICE) Working Group at large, which operates out of the National Institute of Standards and Technology (NIST). These subgroups provide a mechanism in which public and private sector participants can develop concepts, design strategies and pursue actions that advance cybersecurity education, training and workforce development. I am thrilled that NICE and its National Cybersecurity Workforce Framework was mentioned as part of the White House Strategy and will continue to be a key initiative moving forward.

Will the government successfully recruit, retain and train enough cyber candidates to meet its magic number by the start of 2017? Probably not, but it has to start somewhere. As (ISC)2 and our U.S. government members support the government in these efforts, we would encourage the following:

1) Shift the focus from quantity to quality. The government’s hiring process needs to be restructured to recruit qualified IT and security professionals. While it is tempting to throw bodies at the problem, if recruits are not properly vetted and have no proven track record, the government will have an even greater challenge on its hands than a workforce shortage.

2) Push the government to fund it. This Strategy is yet another unfunded requirement, a challenge magnified by the fact that the country is getting ready to enter a lame duck session. If we don’t do something to fund this Strategy quickly, we will find ourselves reading the next iteration of the same Strategy this time next year.

3) Keep relationships strong, communicate often. The White House Cybersecurity Workforce Strategy validates everything we have been saying about how to approach the global shortage of cyber personnel. Government is listening, industry needs to keep talking.

As to what it will realistically take to attract private sector leaders to federal service, we would like to hear from our members and the cybersecurity community at large. Are the Strategy’s proposed efforts to make federal service more attractive sufficient? If not, what will it take for our private sector members to view a stint in federal service an essential career move? Let us know in the comments below.

By Dan Waddell, CISSP, CAP, PMP, Managing Director, North America Region and Director of U.S. Government Affairs, (ISC)² 

(ISC)² Management

[(ISC)² Blog]

Cybersecurity Education—Starting Young and Making It Fun


Above are the developers of the CynjaSpace mobile app, which was created in partnership with ISACA.

To advance cyber education for children and families, CynjaTech and ISACA are partnering to create a new fully guided educational experience that teaches kids and their families about computer science, security and safety.

The collaboration combines ISACA’s industry-leading Cybersecurity Nexus (CSX)curriculum with the successful Cynja comic series inside the CynjaSpace mobile app to offer exciting interactive games and lessons that teach digital survival skills to children.

CynjaTech’s founders, Heather C. Dahl and Dr Chase Cunningham, started bringing cyberspace to life by publishing their first book, The Cynja® Volume 1, based on their professional experience in tech and cybersecurity. In the following question and answer session Dahl and Cunningham talk about their mission to educate kids on cyber safety.

ISACA Now:  Your book series The Cynja tells an action-packed story about malicious cyberattacks, which is an important topic for ISACA members. Why was it important to tell this story?
Dahl: The cyber world is filled with battles between good and evil—it’s as thrilling as any comic book—and yet it didn’t have its own superhero. So we started thinking, what would you call someone with super powers in cyberspace? What would they look like? They’d need to be smart and stealthy, wouldn’t they? And have awesome weapons? And before you could say “DDoS attack!” we had “the Cynja”—a cyber ninja!

The other thing was that the kids in our lives were reading stories about old-school bad guys like dragon slayers even as there were digital monsters invading their computers. It was time for an upgrade, one that could teach kids a really valuable life lesson as they grew into technology: There’s a whole new world of digital crime out there!

ISACA Now:  How did the writing of your book series lead to the creation of the CynjaSpace app?
Cunningham: Think of CynjaSpace as cyberspace with training wheels. The app combines the safety, controls and activity reports parents need, while allowing kids the fun and freedom of using the web and chatting with friends.

This isn’t a web search filter, a ho-hum tutorial, or even just a social network; CynjaSpace inspires kids to learn to be Internet savvy while interacting with our original comic characters and storylines. Ultimately, our Cynja characters are the role models for kids in cyberspace.

We’re very excited to partner with ISACA to bring cyberpower education for kids into CynjaSpace. By adapting the CSX content for kids and including it in our app, we can start children on a path to a smart, safe digital life.

Our mission is personal—together with ISACA, we will develop the educational lessons that we as technology and security professionals want to teach kids, parents and our own families.

ISACA Now:  As information security professionals, what can we tell other non-tech parents about the online dangers that many of us see every day?
Dahl: Parents need to help their children understand cyberspace isn’t the Magic Kingdom, it’s the Wild West—only worse. Online you rarely see the bad guys before they attack, and it’s hard to see the white hats who serve as role models. No one gets to observe others as they make choices and experience the consequences.

Being a cyber hero for children is far more than being a successful Internet entrepreneur. It’s living a smart, ethical life online. It’s treating people and data with respect.

It sounds straightforward, but here’s the problem: It’s hard for many kids to see their parents as digital role models because parents don’t open up their online lives to their kids. Our kids aren’t riding tandem as we email, shop online, surf the web, and use social media, but that’s the view of the cyber world that kids need to experience. Just like daily life, digital life is not a fairytale; it’s a place where there are real consequences.

I’m here to tell you, all adults—techies or not—are role models for children. If we are concerned about our children’s digital welfare then we must fill this void.

ISACA Now:  ISACA members know firsthand that understanding the background behind a cyber-attack is quite technical. There are multiple layers and plenty of technical terms; however, the layout of your Cynja books and the way the stories takes shape, the process is broken down into a more simplified and easy-to-understand progression. How did you translate that process to your comic series and CynjaSpace app?
Cunningham: I provided insight into what it was like to fight real battles in cyberspace—in all their glorious, geeky detail. But we then had to turn this into something a kid would relate to—and so Heather spent a lot of time with her nephew trying to see the world through a six-year old’s imagination—and what it’s like to be the hero of your own magical battles against bad guys.

We wanted to illustrate The Cynja so that readers could understand the gravity of being stuck in an infected network or encountering malicious malware. Shirow Di Rosso, our illustrator, who we call the Artmaster, was an IT engineer, so he knew exactly what this world looked like and how to visualize it in an imaginative yet accurate way.

With CynjaSpace and our ISACA partnership, we move the story and technology lessons from the book, into a fully interactive digital learning experience for kids. With ISACA’s expertise and support, we are creating the next generation of cyber education for kids and their families.

It’s important for kids to know that it’s up to people like ISACA members to protect vital computer systems. We need to encourage kids to be safe online and to learn about the technology. Incredibly, we’re facing a shortage of cybersecurity professionals that is expected to last for years. My hope is that the CynjaSpace will inspire kids to in fighting bad guys online.

[ISACA Now Blog]

Modern Endpoint Backup Sees Data Leak Before It Hurts

Picture this: You’re enjoying a beautiful summer Saturday, watching your kid on the soccer field, when your phone rings. It’s work. Bummer. “Hi, this is Ben from the InfoSec team. It appears that John Doe, whose last day is next Friday, just downloaded the entire contents of his work hard drive to an external drive. Given his role, there’s a high probability that it includes confidential and sensitive employee data.”

There goes your Saturday.

It happened to us—it’s probably happened to you
This happened to us at Code42 a few months ago. A longtime employee was coming up on his last day, and innocently wanted to take years of work with him. We’ve all probably done this—grabbed some templates and examples of our work to use in our next chapter—and instead of sorting through years worth of work, it’s just easier to copy the whole drive. Unfortunately, this is against company policy and puts the company at risk. And in this case, there were confidential and sensitive files related to company personnel.

Not all data theft is malicious, but it’s still dangerous
Of the fifty percent of departing employees that take sensitive or confidential data—most are not malicious. Some don’t know the rules; some don’t follow the rules; and most see no harm in their small actions. At Code42, we’re fortunate to have great people, and they have good intentions. But even the best intentions can have terrible consequences, especially when it comes to enterprise data security.

Too often, “innocent” data taken by employees inadvertently includes sensitive corporate data such as financial information, employee data, trade secrets or even customer information. There are risks and costs associated with leaked data; but knowing what was leaked and where it is greatly reduces the risk and damages.

Code42 CrashPlan avenges data theft—saves the weekend
Back to the sunny soccer field, where I might have spent horrible moments dreading the fallout from this particular data pilfer, I make a single phone call and spend no time worrying about the cost of tracking down or trying to recreate lost files or deal with a potential breach.

With Code42 CrashPlan, I have complete certainty that all of this employee’s endpoint data is backed up, down to the minute. And I know our InfoSec team can tell me what the data is, what was copied and where it was copied to—down to the serial number of the external drive.

Modern endpoint backup: Sees what data you have, and it knows where it goes
From there, the resolution is quick and—while it sounds dramatic—painless. A company representative contacts the departing employee, explains that we observed the content of the hard drive has been copied to a drive and requests return of the drive to Code42 on Monday morning. The employee promptly returns the drive.

And the best part of the story, I enjoyed the rest of the weekend, without the threat of data theft clouding the summer sky.

This is the power of modern endpoint backup. No matter where insider threat comes from—malicious lone wolves, employees conspiring with external actors, or well-intentioned, accidental rule-breakers—modern endpoint backup sees it all, in real time.

Download The Guide to Modern Endpoint Backup and Data Visibility to learn more about selecting a modern endpoint backup solution in a dangerous world.

Ann Fellman, Vice President/Marketing and Enterprise Product Marketing Director, Code42

[Cloud Security Alliance Blog]

Effective Third-Party Risk Assessment – A Balancing Process

The vendor risk assessment is the lynchpin of every effective third-party risk management program. In theory, the essential components of an assessment are easily determined. However, in practice, the ability to effectively understand and assess third-party controls usually conflicts with the resources available to perform the assessments, and is further handicapped by the need to rapidly conclude assessments so contracts can be finalized and projects begun.

All too often this results in assessments that are performed based on resource availability and time rather than an appropriate review of required security controls.

Adding additional complexity is the growing pressure to expand third-party assessments. Regulatory agencies have significantly increased third-party assessment requirements. The U.S. Office of the Comptroller of the Currency (OCC) now requires companies to look at the entire vendor lifecycle when managing third-party risk (OCC 2013-29). The U.S. Federal Financial Institutions Examination Council (FFIEC) recently added the requirement that companies include an assessment of their vendors’ business continuity programs as part of the assessment process (FFIEC Examination Handbook, Exhibit J). Healthcare regulators have also joined in requiring a thorough security risk analysis as part of the HITECH Act/Omnibus rules.

Industry standards are also increasing the focus on third-party security. PCI DSS 3.0 (12.8.2) and the latest versions of ISO 27001/2 require a comprehensive assessment of third-party security controls. NIST also requires that third-party information security risk be evaluated for NIST compliance (SP 800-39).
The very practical need for thorough third-party assessments is the fact that third-parties are increasingly targeted by criminals, and continue to be the primary source of breach incidents. Rather than attempt to breach the systems of large and usually well protected company networks, criminals look for the weakest link in the chain, which is all too often a third-party.

The growing demand for more comprehensive third-party assessments necessarily requires expanded resources, budgets and timelines for completion. These needs run contrary to very real budget and staff constraints, and the pace at which business units need to bring new (often web/cloud based) products and services to market. So, how do you satisfy the growing demand for more comprehensive assessments of third-party risk controls without substantially increasing the cost and time for conducting assessments?

The first step is to fully understand your assessment workflow, and identify all of your information requirements, both internal and external. Then identify those activities that are extremely manual in nature. The simple truth is that it is difficult, if not impossible, to effectively manage assessments in a manual environment. From initiating and collecting assessment information, to managing your workflow and providing a centralized repository for all assessment-related activities, there are a number of industry applications that can automate the assessment process and provide significant relief for overburdened processes and resources.

Also, make sure that you don’t reinvent the wheel. There are a number of existing assessment frameworks you can use to refine or jumpstart your program. NIST, Health Information Trust Alliance (HITRUST), and PCI all have framework controls and questionnaires.

To learn more, join us on 26 July for an ISACA webinar, titled Effective Third-Party Risk Assessment – A Balancing Process, on how to manage all of these competing requirements and develop an effective program for third-party assessments. We will discuss how to find the best methods to balance these competing demands, and key ways to enhance your assessment process so you can do more comprehensive assessments without increasing the time and cost of assessment due diligence.

Brad Keller, Senior Director of Third-Party Practice Lead, Prevalent

[ISACA Now Blog]

English
Exit mobile version