Women in Cybersecurity/IT: A Matter of Strategy

If an organization has a culture of diversity and inclusiveness, there is typically a strategy in place to hire more women in cybersecurity/IT. This is especially true in consulting, where there is a concerted effort to hire more women. From a recruiting perspective, there is a small talent pool of women in cyber/IT to hire from. But I am starting to see more effort/focus on pipeline development coming from schools and organizations.

A female CISO I recently spoke to said, “I am not seeing a lot of women enter the field, but I am seeing STEM (science, technology, engineering, and math) efforts, encouraging students in college to enter the technical fields where they may see an avenue toward cybersecurity.”

Bringing More Women into Cybersecurity/IT Careers
As I said, building that talent pipeline is key. More effort and investment need to be made at the high school level to encourage girls to take the cybersecurity/IT career path. We need to show that it is cool, that it is in demand, that Fortune 500 companies are looking for women in cybersecurity/IT, and that it is a rewarding career. This effort should underline the fact that the pay disparity between women and men in cyber/IT is significantly less than in other fields.

Unfortunately, studies show that girls are actually discouraged from STEM careers by their school counselors, who often lack the information needed to steer them toward nontraditional female roles. Girls also do not study for cybersecurity/IT careers, because they do not know anyone in these fields or what they do. Getting into the schools is critical to developing that pipeline.

I recently attended a career night at my daughter’s school. There were a lot of dads in IT and the students that stopped by were primarily boys. We need to change this. Girls need to know that this is a field for them too, and that it is a great way to make an impact on an organization and earn a great salary.

Engagements with cyber professionals allow students to have more knowledge and envision pathways for themselves to pursue cyber careers. It is critical that we give girls cyber experience so they can make their own discoveries and impacts. They are more likely to pursue cyber careers if they have had hands-on experience, so experiential learning is vital to generating interest.

Scholarships and Mentoring
Mentoring and coaching girls and women toward cybersecurity/IT careers is a must. When employees and employers make a commitment to positively impact the community by volunteering, everyone benefits. We need more scholarships for women studying cybersecurity/IT. There should also be a focus on under-represented students, such as those from low-income families or minority populations. We need male leaders to visibly support all of these efforts.

Another critical focus is retention. Even if women are in cyber/IT, most leave the profession after an average of 10 years, because there are so few female role models in senior leadership. A lack of sponsorship also contributes to this problem. Sponsorship differs from coaching/mentoring. Sponsors have authority and influence. They put their personal capital at stake to “talk up” women when they are not there at leadership meetings. Sponsors can put them in front of the right people and recommend them for leadership opportunities, experiences or promotions.

Fostering a Culture of Diversity
We need to have more women in cyber speak at conferences. I’m always amazed when I speak at a conference and women come up to me to say, “It’s nice to see a female speaker at these events.” It should not be so rare to see a woman cyber leader in a keynote speaker role.

Having a culture where diversity and inclusiveness are valued is crucial. A significant part of that is the recognition that diverse teams and perspectives enable organizations to be successful. Organizations need to set performance metrics related to hiring women in cyber/IT to affect executive bonuses and put succession plans in place that purposely provide for future female cyber leaders.

Editor’s note:  As part of ISACA’s celebration of Women in Technology Month this month, we have launched a pilot of theConnecting Women Leaders in Technology program, an effort to engage female professionals in the areas of education, awareness and advocacy. ISACA is seeking women in tech to guest blog on the subject of their choice. If you are interested in learning more, please contact news@isaca.org.

Debbie Lew, Executive Director, Ernst & Young LLP

[ISACA Now Blog]

Confident Endpoint Visibility Responds to Modern Data Protection Problems

Consumer tech adoption has outpaced tech evolution in business for more than ten years. SaaS and cloud solutions, new apps and devices are at the disposal of empowered workers, making it very easy for employees to get what they need to work anywhere or—despite policies forbidding it—take career-making IP as they exit one company for the next. Legacy backup can neither unlock nor disarm these threats.

At the same time, data has become the new currency: cyber-crime syndicates have boomed with new variations on stealing or disabling data, particularly spear phishing and ransomware targeted at employees. As for breach, the headlines say it’s not a matter of if. It’s when. Legacy backup, long rejected by workers, simply cannot address these threats.

Finally, encrypted data moving through the network has made the intelligence it houses opaque—even to its stewards. A CISO recently shared with us that more than 75% of his network traffic is encrypted, making it nearly impossible to identify the threats facing his organization.

While it’s safe to say encryption is a must, it also means the focus of security must shift to the endpoints to mitigate risk and regain control.

Modern endpoint backup sees what you can’t
Modern endpoint backup gives IT and InfoSec the ability to see, monitor movement of and recover data housed on every employee device.

It neutralizes the threat of ransomware by making up-to-the-minute data recovery simple and fast. It decreases the cost of litigation by leveraging a complete dataset for legal holds, and it supports rapid response and remediation of breach via data attribution—with or without the device. From a productivity perspective, modern endpoint backup makes everyday challenges like data migration a lighter lift for IT and end users.

In response to modern data security problems, more than 39,000 businesses—including ten of the most recognized brands in the world, the 7 of the top 10 technology brands, and 7 of the 8 Ivy League schools—have adopted Code42 to regain visibility and mitigate risk.

In 2008, Code42 launched its enterprise endpoint backup software—knowing it was time for backup to catch up. Now approaching its sixth-generation platform, Code42 provides visibility of all the data through a single console and the real-time recovery and security tools the enterprise needs to be more resilient, more accountable, and more defensible.

Modern endpoint backup imparts the right to “Be Certain” in the face of modern data protection and security problems. We invite you to find out how.

Joe Payne, President and CEO, Code42

[Cloud Security Alliance Blog]

More Than One-Fourth of Malware Files “Shared”

Last week, Netskope released its global Cloud Report as well as its Europe, Middle East and Africa version highlighting cloud activity from January through March of 2016. Each quarter we report on aggregated, anonymized findings such as top used apps, top activities, top policy violations, and other cloud security findings from across our customers using the Netskope Active Platform, including by industry.

This report took up where we last off last quarter on our cloud malware research, in which we found that 4.1 percent of enterprises had at least one sanctioned cloud app laced with malware. This quarter that number has risen to 11.0 percent, or nearly triple since last quarter. This is before counting unsanctioned apps, which we are researching and will incorporate into future reports. When we do, we expect these numbers to increase dramatically. Beyond sharing volume of detections, this quarter’s report breaks down those malware into the following observed categories, several of which are known to be used to distribute or propagate ransomware:

  1. JavaScript exploits and droppers
  2. MS Office macros
  3. Backdoors
  4. Mobile malware
  5. Spy- and Adware
  6. Mac malware

We also rated discovered malware in terms of its severity based on the extent to which it affects user privacy and computer security and causes damage to files, computers, or networks. 73.5 percent of detected malware this quarter ranks “high” in terms of severity, with 8.3 percent “medium,” and 18.2 percent “low.”

Perhaps the most shocking finding is that 26.2 percent of discovered malware files had been shared, either internally (with one or more people inside of the organization), externally (with one or more people outside of the organization), or publicly (with a publicly-accessible link). Sync and share, two important capabilities that characterize the cloud, are liabilities when it comes to malware because malware can use sync and share to propagate rapidly between users and devices, and the reason we dubbed this issue the cloud malware fan-out effect.

What do we recommend to combat the fan-out? Five things:

  1. Back up versions of your critical content in the cloud. Enable your app’s “trash” feature and set the default purge to a week or more. This is one of your best bets for preserving your data should you become infected with data destructing malware such as ransomware.
  2. Use your CASB to scan for and remediate cloud malware in your sanctioned apps. Make sure to check for infected users through sync and share. Integrate your CASB with, and share detections across, your existing security infrastructure such as your sandbox and endpoint detection and response (EDR) so you can stop malware wherever it’s propagating in your environment.
  3. Detect malware incoming via sanctioned and unsanctioned apps.
  4. Detect anomalies in your sanctioned and unsanctioned cloud apps, such as unusual file upload activity or other out-of-the-norm behaviors.
  5. Monitor uploads to sanctioned and unsanctioned cloud apps for sensitive data, which can indicate exfiltration in which malware is communicating with a cloud-based command and control server.

Krishna Narayanaswamy, Chief Scientist, Netskope

[Cloud Security Alliance Blog]

New COBIT 5 Book Helps Enterprises Realize IT Benefits

When a majority of enterprises report that less than half of their IT initiatives actually deliver the expected business benefits, it is time to take a closer look at what businesses can do to attain those sought after benefits.

Enterprises make investments in technology as part of their daily operations, so the need for business benefits realization from those investments is ongoing. That need—and the general failure of businesses to meet it consistently—is the driving idea behind the creation of COBIT 5 for Business Benefits Realization, a new book from ISACA.

The book details how the COBIT 5 framework can help businesses achieve the benefits from their technology investments as envisioned when those investment decisions were made.

Barriers to IT Benefits
So why are a majority of businesses seeing less than stellar returns from their IT initiatives? The answer lies in three common barriers to benefits realization. First, it is difficult to determine exactly which IT benefits are realized due to the significant lag between the decision to invest in technology and the realization of benefits. Next, common misperceptions can compromise benefits realization. For example, enterprises often believe benefits realization management is a simple, easy process. It is not. Lastly, a paradoxical gap arises between the knowledge of good management practices and the actual application of those practices. Business benefits realization management is no exception.

Drivers to Business Benefits Realization
What actually drives benefits realization? A study by John Ward and Elizabeth Daniel identified the following issues:

  • Complex, sophisticated IT systems and applications require increasing levels of skill to deliver/use effectively.
  • IT industry expectations for proven benefits and time to realize them are unrealistic.
  • Enterprise-wide applications impact a wide range of internal and external stakeholders, and rely on active cooperation to achieve benefits.
  • IS/IT benefits are increasingly diverse and difficult to identify, describe and measure.
  • It is difficult to relate business performance improvements to specific IS/IT projects because they are usually a combination of improved technology and other changes.
  • An increasing focus on short-term financial returns prevents many longer-term benefits of a coherent, sustained IS/IT investment strategy.
  • Benefit reviews are not consistently performed when projects end, so lessons learned are not transferred to future projects.

COBIT 5:  A Framework for Achieving Objectives
As a comprehensive framework that helps organizations achieve their objectives for the governance and management of enterprise IT, COBIT 5 enables businesses to optimize value by balancing benefits realization, risk optimization, and resource use.

COBIT 5 for Business Benefits Realization builds on COBIT 5 by focusing on governance and management of business benefits realization to provide contextualized guidance for consultants, experts in governance and business management, IT professionals, and other interested parties.

The book outlines the key characteristics of effective business benefits realization management, as identified by Steve Jenner and APMG International. They include:

  • Actively searching for benefits versus passively tracking against forecast.
  • Evidence-based forecasting and practices.
  • Transparent forecasting and reporting with a clear line of sight from strategic objectives to business benefits.
  • Forward-thinking that emphasizes learning and continuous improvement.
  • Managing across the full business change lifecycle, rather than as an add-on at the end of a project.

COBIT 5 enables these key success characteristics through its specific governance and management processes, practices and activities that contribute to benefits realization, and risk and resource optimization.

Benefits of COBIT 5 for Business Benefits Realization
COBIT 5 for Business Benefits Realization provides the following benefits:

  • Better understanding of increasingly complex but significant areas of business benefits realization
  • Better understanding of key links between business benefits realization and enterprise and IT strategy, and enterprise architecture
  • Clarity on the application of COBIT 5 governance and management principles to business benefits realization
  • Details on how each COBIT 5 enabler supports business benefits realization
  • Contextual references to industry best practices from leading benefits realization authors and researchers

Members can download the book here.

Peter Tessin, Technical Research Manager, ISACA

[ISACA Now Blog]

The Pervasiveness of COBIT

COBIT—which turned 20 this year— not only has technical value, but is also an enabler that can improve our careers and our networking opportunities.

ISACA offers IT professionals education, conferences and training to take our careers to a higher level. These activities allow us to create and maintain rich professional contacts and, of course, friendships. In my case, ISACA and COBIT allow me to participate in IT governance and management publications, audit conferences and sustainability events.

As a COBIT follower, I think its 20th birthday is a great moment to remember how many projects have been made better because of COBIT. Or, in other words, how pervasive is COBIT?

Assessing, Identifying Organizational Risks
When you are an auditor or information systems professional, you know very well that the use of IT creates risks for your organization. As an auditor, you must assess those risks and identify and review the effectiveness of the controls that are in place to mitigate them. For example, if your business is supported by IT, you must ensure service availability, accurate and timely information, reliable IT and applications controls, physical security, regulatory compliance, competent and motivated personnel, an appropriate decision-making structure, and well-implemented government and management practices.

But when you use COBIT to audit an accounting system, questions arise:  Why are you doing this audit? For what? For whom? Of course, you use it to benefit the company, because you need to know the financial and economic situation, value of their investment, and achieved profitability.

But there are also other stakeholders, including shareholders and banks that invest or lend money, employees and customers providing and receiving services, the state and its watchdogs that ensure transparency and, finally, society in general.

Considering Sustainability and Social Responsibility
At this point, sustainability and social responsibility considerations are added to the mix, and the field of enterprise IT comes to the forefront. What is the primary role of IT? What should it be? How do IT decisions impact the economic, social and environmental aspects of the enterprise? How does IT help in an earthquake? How much does it help children to study, communicate with others, or simply imagine a better future? Can we measure that? Probably, and COBIT can help. COBIT aligns IT with business needs, whatever the business’s mission or core values are. It evaluates, directs and monitors how IT is, and will be, used.

COBIT also allows enterprises to plan, build, run and monitor all IT resources. But its value increases when a life is saved or a planet is protected by specialized or green IT:  As the International Telecommunication Union’s (ITU) 5th Green Standards Week Declaration stated:

Think sustainable:  Bridge the gap between experts from the ICT, environment, urban planning, energy sectors and policy makers, to encourage the integration of ICTs into environmental, urban and energy policies in order to improve knowledge on the catalytic role that information and communication technologies (ICTs) can play in reducing energy consumption, increasing environmental resilience, tackling climate change impacts, and enhancing energy efficiency and promoting a circular economy.”

In other words, COBIT 5:

  • Improves governance:  COBIT 5 ensures that all stakeholders are identified and their needs are evaluated to determine the enterprise’s overall goals and its associated IT-related goals.
  • Improves measurement, monitoring and evaluation systems:  COBIT 5 uses indicators as management tools at various levels and in various sectors to improve monitoring and information systems at different scales.
  • Assesses the roles of public and private actors:  COBIT 5 recognizes different stakeholders with different needs and obligations.
  • Increases the resilience of human and natural systems:  COBIT 5 suggests stakeholder needs are related to sustainability and, thus, allows the use of its goals to cascade to ensure the identification of enterprise goals and the evaluation of possible risks that can hurt their achievement. So, the implemented

IT process will be capable of delivering outcomes even if the risk factors materialize and the conditions are not the best.

What has COBIT done for you and your organization? Please share your thoughts with ISACA’s online COBIT community.

Braga will present Using the COBIT 5 Assessment Program to Improve the Work Process Capability at the 2016 Governance Risk and Control Conference (GRC), 22-24 August 2016, in Fort Lauderdale, Florida USA.

Editor’s note:  The ISACA Now Blog section is celebrating Women in Technology Month throughout June by featuring female bloggers. If you are a female blogger and would like to contribute a blog, please contact us at news@isaca.org.

Graciela Braga, CGEIT, COBIT 5 Foundation Certificate, CSX Fundamentals Certificate

[ISACA Now Blog]

English
Exit mobile version