Google’s Gerhard Eschelbeck to Keynote at Cloud Security Alliance Congress US at Privacy.Security.Risk Conference

Registration Now Open for the Industry’s Premier Gathering for Cloud Education and Best Practices

San Jose, CA – July 6, 2016The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, today announced that Gerhard Eschelbeck, Vice President, Security & Privacy Engineering at Google will present the opening keynote at the upcoming CSA Congress USA at thePrivacy.Security.Risk 2016 (P.S.R.) conference taking place September 13-16th in San Jose, CA.

As Vice President of Security & Privacy Engineering at Google, Eschelbeck leads the teams that ensure data and systems security, as well as user privacy. Gerhard admittedly has a passion for championing new technologies and is a trusted advisor to a number of early stage startup companies. He has published the “Laws of Vulnerabilities” and is one of the inventors of the Common Vulnerability Scoring System (CVSS), and holds numerous patents in the field of managed network security.

“Google is a critical part of the cloud computing ecosystem and we are very excited to have Gerhard kick off this year’s event to share best practices, proven approaches and lessons learned with our conference attendees,” said Jim Reavis, CEO of the Cloud Security Alliance. “Whether you are a long time user of cloud technology or a relatively new adopter, this year’s conference is guaranteed to take your knowledge to a new level with new ideas that attendees can readily walk away with and apply to their own organization.”

Presented by the IAPP Privacy Academy and CSA Congress, the P.S.R. Conference, now in its third year, is expected to draw approximately 1,500 privacy and cloud security professionals. The event brings together two related fields—privacy and security – with important perspective to help practitioners excel in their role. The event aims to deliver the most thought-provoking speakers and sessions led by the foremost experts and provides invaluable opportunities to connect and share ideas. The join event will provide attendees with more than double the education and networking opportunities with the leading innovators and practitioners in technology, security and privacy for the price of a single conference.

Registration is now open and with an early registration discount of $200 available until August 19. The most current conference program can be found at https://iapp.org/conference/privacy-security-risk-2016/sessions-psr16/

WHAT: Cloud Security Alliance Congress US 2016 at P.S.R.
WHEN: Workshops: September 13-14
Conference: September 15-16
9:00 am – 5:00 pm
WHERE: San Jose Marriott and San Jose Convention Center
ATTENDEE REGISTRATION: https://my.iapp.org/nc__event?id=a0l1a000000nBgQAAU
MEDIA REGISTRATION: kari@zagcommunications.com

About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, certification, events and products. CSA’s activities, knowledge and extensive network benefit the entire community impacted by cloud — from providers and customers, to governments, entrepreneurs and the assurance industry — and provide a forum through which diverse parties can work together to create and maintain a trusted cloud ecosystem. CSA has developed the definitive best practices for the industry, such as the “Security Guidance for Critical Areas of Focus in Cloud Computing”, the “Cloud Controls Matrix”, “Top Threats to Cloud Computing” and 50 other cloud security research artifacts. For further information, visit us atwww.cloudsecurityalliance.org.

About the IAPP
The International Association of Privacy Professionals is the world’s largest association of privacy professionals with more than 20,000 members across 83 countries. The IAPP is a not-for-profit association that helps to define and support the privacy profession globally. More information about the IAPP is available at www.privacyassociation.org.

Media Contact
Kari Walker
ZAG Communications
703.928.9996
kari@zagcommunications.com

[Cloud Security Alliance Research News]

Life (and Your Career) Is Not a Spectator Sport

Jackie Robinson, the world-famous baseball star, once said, “Life is not a spectator sport. If you’re going to spend your whole life in the grandstand just watching what goes on, in my opinion, you’re wasting your life.”

Your career and mine may not have the cultural significance that Jackie’s did, but how many of us accidently, or metaphorically, spend our lives or careers in the comfort zone of the grandstands? Watching and waiting for something to happen. We turn and talk to our fellow grandstanders about what “woulda, shoulda, coulda” been. They silently concur and resume watching, waiting.

“And then one day you find ten years have got behind you. No one told you when to run, you missed the starting gun.” –“Time” from the 1973 album Dark Side of the Moon by Pink Floyd

Some of the best, most rewarding things in our lives and our careers come in unexpected ways. We are taught that success and winning are everything. However, which one of two equally talented individuals learns more and works harder to improve:  the person who makes the game-winning play or the person who fails? The winner is carried off on teammates’ shoulders. The non-winner walks alone. The winner may have been skilled, a good guesser or simply lucky, but the “learning moment” is lost in the jubilation. The driven non-winner will be reviewing video, talking to coaches and working on being better.

“Champions aren’t made in gyms. Champions are made from something they have deep inside them-a desire, a dream, a vision. They have to have the skill, and the will. But the will must be stronger than the skill.” –Muhammad Ali

My point is this:  Who do you think comes back stronger? Which one steps out of the grandstand and pushes harder? Delivers more? My second and more important point:  which one are you? Do you join an organization or company and then metaphorically sit in the safety of the grandstands? Or do you actively jump in with both feet and participate by stepping out of your comfort zone?

And Now, a Short, But Related Story
I joined ISACA because a friend, the chapter president, asked me to help him do more with the local chapter. As a chief technology evangelist/CIO, it was not at the top of my list of organizations to join, much less be on its board. In my time running large IT shops, I worked closely with a lot of internal and external auditors—some good, some not so good. In my head, my confirmation biasthe tendency to search for, interpret, focus on and remember information in a way that confirms one’s preconceptions—kicked in, and I still saw ISACA as simply an “IT auditing” organization. It is a reasonable assumption that auditors have a similar opinion or bias toward IT professionals.

Over the first few months, while I familiarized myself with the global ISACA organization, its offerings and its direction, a funny thing happened. The people were very giving and sharing. They freely talked about the challenges of being “perceived as a burden,” a “tax collector,” and as “paper tigers.” They wanted to do their jobs as well as they could for their companies and clients. They were very open to understanding the perspective of a “recovering CIO.” Constructively, I gave them both barrels from the IT perspective. Instead of wincing or recoiling defensively, they leaned in and said, “How can we (IT, info sec, the business, and audit) work better together?”

Well folks, I have to admit, I am a sucker for anyone attempting to focus on the business or people side of the equation and work together for the betterment of the business organization. So, I jumped out of the grandstands, gulped down the Kool-Aid, and said,“Put me in, coach!” I became much more involved in several areas beyond those assigned to me. The personal growth was incalculable. Not only did I get some very fresh perspectives on stale thoughts, but I also gained a renewed sense of adventure. Yes, adventure with auditors! This new sense of adventure culminated in March when our chosen delegate to the 2016 ISACA Global Leadership Summit was injured and the chapter turned to me. My old reaction would have sounded a little like, “Um, let’s see…um…400 auditors you say?… three days?…oh, yeah, I just remembered…”

Instead, I went to the Lisbon event and found 400 chapter leaders from over 80 countries, all attempting to “make things better.” It was three days of work, but I met some really extraordinary individuals from around the globe. Their insights and approaches to challenges, challenges the normal American would never face, were simply inspiring. That combined with a global organization attempting to reinvent itself and address the needs of the new era by reaching out to professionals, members, etc., made the experience a truly rewarding one.

NONE of these great experiences would have happened had I sat and watched from the grandstands.

The meta-message:
Changing up US President John F. Kennedy’s famous quote a little, my advice is this:

“Ask not what an organization can do for you, but rather what you can do for the organization.”

Pick one organization inside or outside your comfort zone. Join. Contribute. Expand. Excel!

Editor’s note:  Blair Baker serves as 1903 Solutions’ chief technology evangelist, ghost-executive, catalystic optimizer, interdepartmental liaison, speaker and coach.

Blair Baker, Chief Technology Evangelist /CIO, 1903 Solutions LLC

[ISACA Now Blog]

FedRAMP High Baseline Requirements Published

The Federal Risk and Authorization Management Program (FedRAMP) Project Management Office officially released its High baseline for High impact-level systems. This baseline is at the High/High/High categorization level for confidentiality, integrity, and availability in accordance with FIPS 199; and is mapped to the security controls from the NIST SP 800-53, Rev. 4 catalog of security controls. Previously, the FedRAMP authorization process was only designed for low and moderate impact systems. The number of controls for each of the FedRAMP defined impact system levels is presented below:

 

The release cumulates several months of work from the FedRAMP PMO, numerous agencies, cloud service providers and key stakeholders that established the draft baseline, collected industry and federal comments, and completed pilot programs.

FedRAMP High Baseline
The establishment of the FedRAMP High Security baseline is critical for federal agencies to migrate more high-impact level data to the cloud. The High baseline is the strongest FedRAMP level to date, covering sensitive, unclassified data. According to FedRAMP Director Matt Goodrich, most of the information to be covered under the High baseline will be law enforcement data and patient health records. This should cover the needs of several civilian agencies, the Department of Defense (DoD), and the Department of Veterans Affairs (VA).

FedRAMP High Baseline Authorized Cloud Service Providers
The three Infrastructure-as-a-Service (IaaS) providers who participated in the FedRAMP High baseline pilot program and achieved Authorization are:

  • Microsoft’s Azure GovCloud
  • Amazon Web Services GovCloud
  • CSRA / Autonomic Resources’ ARC-P

Federal agencies are able to review these vendor’s security packages, through OMB MAX, to begin to use these services immediately.

Coalfire was one of the earliest Third Party Assessment Organizations (3PAO) in FedRAMP, providingFedRAMP assessment or advisory services to cloud service providers in pursuit of their FedRAMP P-ATO or Agency ATO. If you’d like to talk to one of our staff about the new FedRAMP High baseline or have questions about the FedRAMP process, please contact us.

Abel Sussman, Director, TAAS–Public Sector and Cyber Risk Advisory, Coalfire

[Cloud Security Alliance Blog]

A Career Path That Leads From Economics to Data Analytics

When speaking to people who never considered a career in cyber or information security, we often find an audience put off by the perception that it is only for the technically minded. This couldn’t be further from the truth! Lucy Chaplin, a young consultant from the United Kingdom (U.K.) who became an Associate of (ISC)2 last year, demonstrates the possibilities.

Lucy considers herself lucky to have missed out on graduate programme schemes for management consulting. Coming out of Bristol University in 2012 with an honours degree in Economics and Politics, these programmes seemed to be the obvious choice at the time; and she made a concerted effort to contact The Big Four global consulting firms and small consultancies alike. Her research led to KPMG’s risk consultancy practice, which was a little bit more technical than the career she had imagined, but not daunting.

“I have never looked back. I asked for the opportunity to speak to as many people as I could around different practice areas and it became obvious that this was a high-growth industry that promised a lot of opportunity,” Chaplin says.

Celebrating her 25th birthday this year, Lucy is well aware that her choice has fast-tracked her career. She has worked on a variety of business, technical and strategic programmes examining technical risk, business resilience, infrastructure, cybersecurity and now Data Insight Services, where she helps clients take advantage of the volumes of data they have running through their systems to maximise the impact of their data and reporting. Her assignments have even included a stint on the McLaren Alliance, where she got a close-up view of the cars and met star Formula One driver Jenson Button.

Given the level of information and IT security required in the work she was doing, Lucy sought to solidify her knowledge in this area. Luckily, she was supported by her employer to pursue the Certified Information Systems Security Professional (CISSP®). She is now an Associate of (ISC)2 while she gains the five years’ experience required for full professional recognition.

“This was a great credential to work for because it really helped me get a broader view of the field, and the directions I could take in my career,” she says, adding, “As a young female who hadn’t studied the area, it also demonstrates that I understand the technical aspects of what I am working on. I continue to be very business-oriented, with a strong understanding of how technology works; but I have never had to be a technology expert. I work with others when such deep expertise is needed.”

What advice would Lucy give to graduates today?

“When you graduate, there is so much pressure on you from employers, family and peers to have a clear idea of what you want. But I got into a field that was changing too much to be able to build a five-year plan. In this organisation, my five-year plan changes with both the firm’s and my priorities. Take the time to talk to as many people as you can. Ask recruitment agents to refer you to people who can talk to you about their work. Attend events and ignore the pressure — let them tell you what is possible.”

Find out more about how you can become certified by (ISC)² here: https://www.isc2.org/associate/default.aspx

Find out more about (ISC)² : www.isc2.org

–Lyndsay Turley, director, Communications & Public Affairs, EMEA, (ISC)2

[(ISC)2  Blog]

The Quest for Leadership Presence: Finding Your Voice

When you listen to Indra Nooyi, PepsiCo CEO, you hear calm, measured confidence. When you listen to Sheryl Sandberg, Facebook COO, you hear upbeat, energized confidence. And when you listen to Mary Barra, GM CEO, you hear the concise messaging and confidence of a been-there-done-that leader.

Each of these women telegraphs leadership through her voice. When you listen, you don’t think, “I am listening to a woman leader.” You just know you are listening to a leader, a person with a passion for what she wants to convey and the utmost belief in her mission.

Our voices are one of the most powerful tools we can develop and leverage to convey leadership. By the same token, a weak voice lacking a passionate, well-defined, meaningful message will hinder our ability to grow and advance as leaders.

Sheryl Sandberg exhorts us to lean in. The most obvious way to do that is through what we say and how we say it.

One’s voice and the way one talks about their work is a powerful signal that we read instantly. We know leadership when we hear it.

Leaders Stand Out
As a recruiter and career coach for IT audit and IT governance, risk and compliance (GRC) professionals, I listen to a myriad of professional voices as people describe their jobs and careers. The leaders stand out from the moment they speak. They talk about their work with energy and intensity. Their thoughts are organized and they are clear about their contributions to their clients and teams. They communicate what they do by illustrating their work with specific examples.

An important point:  Leaders build credibility by demonstrating what they do and have done, not by talking in generalities.

Indra Nooyi, in an interview about her keys to success, says that excellent communication skills were her focus early on. She worked hard to present a genuine voice and clear messages of her vision.

One can read books about improving communication, but doing the scary work of practicing your leadership voice, making mistakes along the way, is the best way to hone your message and vocal presence. Networking at conferences is an outstanding training ground for trying out messages and getting immediate feedback.

While networking at your next meeting, conference or coffee break, offer something about the exciting work you and your team are doing to drive the enterprise and make it a great place. Your understanding of the bigger picture, and passion about the mission, are critical leadership elements of this communication. Craft your story into a concise one to one and a half minute presentation of the cool stuff you are doing. Leading means communicating a vision for the greater good. This simple act helps you do that.

Illustrate Your Leadership Competencies
I use the STAR (Situation – Task – Action – Result) technique to help candidates create examples for interviews. Behavioral interview questions, designed to help interviewers assess competencies and traits, not the least of which is leadership skills, demand examples that illustrate thought process, character, decision making, judgment, persuasion and conflict resolution. Using STAR as a framework to organize work examples and accomplishments will help you create interesting stories that differentiate you from the competition. Your goal is to be memorable—in a good way. This method will help you achieve that.

People get to know us through the stories we tell. Leaders illustrate their work through powerful stories.

Important tip:  When you acknowledge your team or describe how you fit into it, put the focus on your contributions. This is critical. I prep people for interviews every day. The most common interview mistake I hear—made by men, but even more so by women—is subsuming individual accomplishment under the mantel of “we” and being uncomfortable stepping up and saying this is what I am doing, this is what I bring to the table.

Leadership presence is something you can cultivate every day. Your work presents you with multiple opportunities to lean in and speak. Small changes in how you present yourself, your vision, your knowledge and your contributions will earn you greater recognition as a leader.

Editor’s note:  The ISACA Now Blog section is celebrating Women in Technology Month throughout June by featuring female bloggers. If you are a female blogger and would like to contribute a blog, please contact us at news@isaca.org.

Caitlin McGaw, President, Candor McGaw Inc.

[ISACA Now Blog]

English
Exit mobile version