Businesses of various sizes are extremely worried about information security. On a daily basis, we hear news of banks and financial institutions losing customer records, confidential information and money due to cyberattacks. Cyberattacks have increased exponentially over the last 5 years, and attack methods are becoming more sophisticated each day. On average, enterprises take about 100 days to identify an attack. It takes even more time to investigate, plug the gaps and prevent similar incidents. The goal of my recent Journal article is to help enterprises and security leaders realign the strategy of their information security teams by empowering the chief information officer (CIO) and the chief information security officer (CISO).
Effective strategies by information security drivers, such as the CIO and CISO, can fine-tune information security and the compliance needs of an organization. Many industries have invested heavily in order to meet regulatory requirements, but being compliant and being secure are 2 different things. Many compliant enterprises have been breached.
Information security needs to be a priority at the board level. CEOs should take active roles in promoting information security, as most valuable information is stored electronically, all systems and databases are online, and mobile transactions occur every minute.
CIOs’ and CISOs’ priority is to identify where sensitive information resides and how can it be protected effectively at the lowest possible cost. The security team, guided by the CISO, should approach problems in a consulting mode to solve security-related challenges in the best way for the business. Outsourcing security operations is still one of the easiest options to reduce cost and reduce risk. These decisions should always be undertaken consciously, evaluating the risk and fallback options.
Information security teams are the walls of every enterprise. An empowered CIO and CISO can create a cost effective, consistent security culture across the enterprise with the right strategies.
After the subprime mortgage crisis and the Lehman Brothers collapse in the US, the Financial Services Agency of Japan (FSA) strengthened financial regulations. The FSA regulations introduced an IT governance perspective, which detailed the rules for information security enhancement and IT risk minimization. In response to this, the management of financial institutions have been struggling with a kind of “defensive” IT governance, or a risk minimization and compliance approach.
On the other hand, the Japan Revitalization Strategy was approved by the Abe Cabinet of Japan in 2013 and the FSA applied the Corporate Governance Code in 2015, in which listed companies are urged to achieve sustainable growth and increase corporate value over the mid- to long term. Under these circumstances, financial institutions are seeking aggressive or proactive IT governance aiming at value creation for stakeholders rather than defensive or reactive risk minimization and compliance.
The requirements that management teams of enterprises, especially financial institutions, need to satisfy are intended to transform their IT governance from defensive risk management and compliance to proactive IT governance. Figure 1 shows the relationship between defensive risk management and proactive IT governance as well as the related frameworks. Enterprise management teams are seeking a transformation that focuses on moving from the left to the right in the figure.
Figure 1—Relationship Between Defensive Risk Management and Proactive IT Governance
Source: Y. Inaba. Reprinted with permission.
This article presents an enterprise IT governance (EITG) implementation model derived from the following practical experiences using COBIT:
Implementation of a group IT governance system1 using the COBIT 4.1 process reference model and its Maturity Model at a global insurance group based in Japan
Implementation of a governance, risk management and compliance (GRC) system2 at an IT service subsidiary of the insurance group using COBIT 5
Practical experience as an employee of a major auditing firm in Japan, Deloitte Touche Tohmatsu LLC
The Proactive IT Governance Model
The core of the proactive IT governance model is value creation for stakeholders and fulfillment of the organization’s fiduciary duty and accountability. Figure 2 shows the concept of the proactive IT governance model developed and presented in this article.
Figure 2—IT Governance Implementation Model for Enterprise Seeking IT-enabled Value Creation View Large Graphic
Source: Y. Inaba. Reprinted with permission.
Goals Cascade From Stakeholder Needs to Enabler Goals
The left-hand side downstream flow of figure 2 or the enlarged chart in figure 3 shows the goals cascade from stakeholder needs to enabler goals. This follows the COBIT 5 principle, Meeting Stakeholder Needs.
Figure 3—Relationship Between Defensive Risk Management and Proactive IT Governance
Source: Y. Inaba. Reprinted with permission.
First, the governance team, consisting of the directors, evaluates the value creation needs for the stakeholders, comprising shareholders, customers, employees, regulatory agencies and social communities such as economic societies, and reports to the management team on what kind of value it should create. The report can be made by creating mission, vision and values (MVV) statements. This corresponds to the action of aligning the governance objective with value creation.
Then, the management team sets the enterprise goals from the results of the evaluation of the stakeholder needs, which consist of the 4 components of the balanced scorecard (BSC), i.e., financial, customer, internal, and learning and growth. The result of this step is the creation of the management strategy document. The next step is that the management team sets the IT-related goals from the enterprise goals, formatting according to the same 4 components of the IT BSC. The output of this step is an IT strategy document. Finally, the goals are cascaded down to the enabler goals, as described in COBIT 5. The result of the enabler goals setting is represented in the enabler strategies, i.e., the strategies for principles/policies, processes, organizational structures, culture, information, service/systems and human resources (HR). Usually, those enabler strategies are included in the IT strategy documentation.
These series of goals cascades can be supported by the mapping from stakeholder needs to enterprise goals described in the COBIT 5 framework3 and the mapping from enterprise goals to IT-related goals and then to process enabler goals described in COBIT 5: Enabling Processes.4
Implementation of the 7 Enablers with Plan-Build-Run-Monitor Cycle
The next step is management execution, which includes a series of practices on the Plan-Build-Run-Monitor (PBRM) Cycle. The management team executes by focusing on 7 enablers. The bottom part of figure 2 shows this cycle and it is further described in figure 4.
Figure 4—Implementation of the 7 Enablers
Source: Y. Inaba. Reprinted with permission.
For the process enabler, the enabler goal setting corresponds to the selection of the priority processes from the 37 processes defined by the COBIT 5 process reference model, each with its targeted capability level defined in theCOBIT 5 Process Assessment Model (PAM): Using COBIT 5. The selection of processes is driven by the goals cascade from stakeholder needs. The next step is to build enablers. The process capability assessment is made regarding the selected processes and following that, the improvement action plan is formulated to fill the gaps between the current capability level and the targeted level and the improvement is implemented. Then, the improved processes are operated to achieve the process enabler goals. Finally, the process performance or the process enabler goals are monitored.
Regarding the other enablers, the enterprise IT governance implementation model described in this article does not include detailed and concrete processes to follow because the focus is on the process enablers. The intent is to explore the other enablers after the completion of the process enabler implementation descriptions. This is supported by the fact that the detailed enabler guide5 for the process enabler already exists as do the process assessment model and the assessor guides.6, 7
Developing the information enabler can happen next because COBIT 5: Enabling Information gives the guidance needed to build that enabler. In addition, how to assess the current information enabler status and how to reach the targeted status for the information enabler needs to be described.
Experience would tend to indicate that implementation guidance for the service/system enabler and the HR enabler is in great demand because they seem to be the essential enablers for the era of disruptive innovations and digital transformations, where proactive IT governance is required. ISACA’s plans include issuing such guidance in the form of another 5 enabler guides to assist its members in implementing COBIT 5.
Monitoring Enabler Goals Up to Value Creation for the Stakeholders
The right-hand side upstream flow of figure 2 or the enlarged chart in figure 5 shows the goals monitoring from enabler goals up to value creation for the stakeholders.
Figure 5—Goals Monitoring
Source: Y. Inaba. Reprinted with permission.
First, the implementation and the operation of each enabler are monitored and the result of the monitoring is reported in an enabler monitoring report. The report is then summarized into an IT monitoring report, which describes the results of the monitoring of IT-related goals. Continuing the flow upstream, the IT monitoring report is integrated into a management monitoring report, which describes the monitoring results of not only IT, but also other governance areas.
Finally, the value created through the governance and management cycles is described in a value creation report, or the integrated monitoring report, and it is reported to the stakeholders as the fulfillment of accountability.
Enterprise IT Governance Perspective in the Enterprise Governance Environment
To enhance the governance and management cycle described above, it would be valuable to view it from the standpoint of enterprise governance—in other words, a corporate governance model which is shown in figure 6. The top circle describes enterprise governance and the bottom circle indicates governance of enterprise IT (GEIT), which is referred to here as EITG.
Figure 6—Enterprise IT Governance
Source: Y. Inaba. Reprinted with permission.
Enterprise governance is performed by C-suite executives under the direction and oversight of the board of directors (BoD). According to the EITG implementation model, it consists of the 2 major governance areas: business governance, referred to here as business value creation governance (BVCG), and corporate governance, referred to here as valued service governance (VSG).
On the top side, BVCG includes the enterprise’s business (e.g., property and casualty insurance or life insurance, in the case of an insurance company) and/or functional unit (underwriting, claims handling) governance. It can be an IT service delivery business and/or a system development function as well as a system operation function for an IT service company.
On the bottom side, VSG is broken down to the so-called corporate governance areas, i.e., corporate planning, financial reporting, HR, risk, information security, compliance and audit/assurance. These area definitions are generally similar for all industries.
Once the governance team sets up the management goals and strategies from the stakeholder needs, they are allocated into the individual areas of enterprise governance. IT governance is one of them.
Focusing on IT governance, the chief information officer (CIO), the chief executive officer (CEO) and the chief operating officer (COO) execute the goals cascade into enabler goals setting in order to align with the enterprise business and create IT value for the stakeholders. This is depicted in the circle at the bottom of figure 6, where IT governance is put at the center of the chart and BVCG and VSG are located around IT governance with the overlapped areas labeled “Align.”
It is important to note that there are several similar circles behind the scenes. For each governance area, each C-suite executive in charge of it is executing a PBRM cycle under another circle where each governance area is put at the center, and the other governance areas, including IT governance, are located around it with the overlapped “Align” label (figure 7).
Figure 7—Enterprise IT Governance From Each Governance Area Perspective View Large Graphic
Source: Y. Inaba. Reprinted with permission.
In addition to cascading down to IT-related goals, the goals of each governance area are cascaded down in parallel. Then, the enabler goals are set for each governance area and the enabler implementations with the PBRM cycle for each governance area are executed.
For example, suppose there is a financial institution whose goals include the implementation of financial technologies (FinTech). Its HR management may plan to introduce an HR development program for FinTech and its IT management may plan to identify the skills for FinTech implementation and acquire people with the defined FinTech skills. Clearly, these 2 initiatives in these 2 departments should be aligned with each other.
Then the monitoring of the goals of each governance area is performed. And finally, working up to the enterprise governance chart (the top circle in figure 7), the governance team monitors the enterprise goals and integrates all the monitoring results from each governance area into a single management report.
Creating Value With the Enterprise IT Governance Implementation Model
COBIT 5 is a useful tool and guidance framework for EITG. Practitioners can create value for clients by combining the interpretation of service delivery from COBIT 5 guidance with the implementation practices outlined in the EITG implementation model described in this article.
By assuming this kind of advocacy role, practitioners can create value for clients as well as fulfill social responsibilities in Japan.
Yuichi (Rich) Inaba, CISA
Is a senior manager at Deloitte Touche Tohmatsu LLC where he developed an enterprise IT governance implementation model base on his COBIT experience. Previously, he was a manager at the holding company of a global insurance group based in Japan, where he had engaged in the implementation of a group IT governance system for the group by using COBIT 4.1. Subsequently, he was a senior consultant specialist in the areas of GRC, IT governance, risk management and information security at the IT service company of the group, where he implemented a GRC system for the IT service company of the group by using COBIT 5. He is a member of the Standards Committee of the ISACA Tokyo Chapter and currently working on the translation of COBIT 5 materials into Japanese as well as an advocacy of COBIT 5 in Japan.
Author’s Note
The content of this article is based on the author’s personal opinion and does not reflect an official position by Deloitte Touche Tohmatsu LLC.
Today’s cybersecurity students face a number of challenges as they learn their field of choice. Two areas my students find particularly challenging include understanding the difference between information security and cybersecurity, and gaining context of a digitally altered world. They are also learning to analyze and understand the technological convergence and challenges around security, safety and control.
My cybersecurity students now have significantly more information to help them address those challenges. One of them is ISACA’s new Cybersecurity Fundamentals Career Starter program. Through the program, college and university instructors and students can receive free access to the Cybersecurity Fundamentals Study Guide, which I, and other professors, can use to shape our academic courses or as a reference to help build our students’ foundational cybersecurity knowledge.
Access to these cybersecurity educational materials can help my students to contextualize the challenges of security and control in a hyper-connected world where the flow of information is the enterprise standard. This formal cybersecurity material provides an important resource for my students and me. And because these educational resources are provided by an international organization with global recognition, it creates a key academic element that students and instructors can use for review and guidance in the field of cybersecurity.
The Career Starter program also gives students the opportunity to take Cybersecurity Nexus’ (CSX) Fundamentals Certificate exam. The online exam covers foundational cybersecurity knowledge across five key areas:
Cybersecurity concepts
Cybersecurity architecture principles
Cybersecurity of networks, systems, applications and data
Incident response
Security implications of emerging technologies
A recent survey of ISACA student members found that a majority plan to work in a position that requires cybersecurity knowledge, yet most lack confidence that they will have sufficient knowledge upon graduation. I believe the Career Starter materials can help to fill that knowledge gap. The program’s reference documents will help anyone interested in exploring the different approaches to cyber risk. In that sense, this kind of educational resource can promote a critical revision in my students’ minds and an increased understanding of complex cybersecurity issues.
More information on the program can be obtained from local ISACA chapters. Contact information is available by clicking here.
Dr. Jeimy J. Cano M. is founder and member of GECTI (Universidad de los Andes, Law Faculty Research Group in Electronic Commerce, Telecommunications and Informatics). Since 1996, Cano has been a professor at Universidad de los Andes and many other Latin American universities in computer law, computer crime, digital forensic, information security governance and data privacy. Recently he was honored as a “Cybersecurity Educator of the Year 2016 – LATAM” by Cybersecurity Excellence Awards issued by Information Security Community in LinkedIn. He is an author of reference books in computer forensics and information security in Spanish: Computación Forense. Descubriendo los rastros informáticos and Inseguridad de la información. Una visión estratégica, published by AlfaOmega Publishing.
Businesses want to move to the cloud, they really do. And more than ever, they’re starting to make the switch: A Cloud Security Alliance (CSA) study that polled more than 200 IT professionals found that 71.2 percent of companies now have a formal process for users to request new cloud services.
That CSA study also found that nearly two-thirds of IT professionals trust the security of cloud computing equally or even more than their on-premise systems. About a third of respondents cited better security capabilities to be a benefit of the cloud. However, almost 68 percent of respondents noted the ability to enforce their corporate security policies remains a barrier to cloud adoption.
Companies know there’s top-notch security in the cloud, yet security remains the biggest hurdle in getting over to the cloud. Kind of a catch-22, huh? Fortunately, there are a few things you can do to help assuage these fears.
Cloud security is something everyone in a company should be concerned with, not just the IT department or decision-makers. And while the tools we use are improving and more people are starting to better understand cloud computing, people still play a big part in security. Your team of security professionals should get the correct training early on in their tenure, and constant training will allow them keep their skills sharp.
Outside of security professionals, all employees within a company should know their role in maintaining a secure environment. Having a proactive approach to security risks is the first step, which is something that 82.2 percent of companies have. However, fewer than half of the companies that responded have a complete incident response plan. With real concerns like loss of reputation or trust, financial loss, and destruction of data, it’s imperative to have a plan in place to combat any potential security issues head-on, rather than reacting after the fact.
To help with the development of that plan, some businesses have turned to a managed service provider (MSP). Naturally, there are concerns surrounding that, as well–the CSA report notes 87.3 percent of companies cite access control as an important asset of cloud security. Our Datapipe Access Control Model for AWS (DACMA) addresses this concern by letting a business stay in control by securely delegating access to Datapipe while retaining control of their credentials. DACMA’s role-based access and accountability elements also ensure the right people within an enterprise are accessing certain data. And with 24/7/365 security monitoring, you’ll be on top of the ball should an issue arise.
Whether or not you choose to partner with an MSP to assist with security, there are plenty of reasons to develop a cloud security strategy that works within your enterprise. There’s no one right method, but there is a wrong approach: not doing anything about it. To learn more about first steps you can take, visit our Managed Security page.
David Lucky, Director of Product Management, Datapipe
Cloud computing has probably been the most argued technological subject of the past 5-6 years. Throughout this period, cloud has evolved to become the top priority subject in organizations’ agendas, both in terms of governance (strategic decisions) and also as the unknown factor affecting the business.
The book, Controls and Assurance in the Cloud: Using COBIT 5, is a guide that addresses both issues.
More specifically, the book starts with a section outlining all of the business factors that make the transition to cloud an attractive business strategy. It then goes a step further by laying out cloud service and delivery (or deployment) models alongside the associated benefits and risks to an organization, whilst detailing cloud computing challenges that organizations need to address.
Having a deep understanding of the fact that any strategic decision needs to be accompanied by the relevant risk management approach, ISACA provides in the book a thorough risk assessment, coupling the impact of cloud migration with the associated cloud service model and deployment model being considered.
What makes this publication unique though is that it not only directly addresses major concerns regarding cloud migration and, more specifically, information security, it also provides a guide on the exact questions organizations need to ask before deciding on cloud service and deployment models.
As a cloud security officer, I have come across questions like “Are cloud infrastructures secure?” or “Will my data remain confidential in the cloud?” And what I have always tried to explain to organizations is that these questions cannot be answered without a point of reference. So, for example, the question “Are cloud infrastructures secure?” must be prefaced by, “In relation to my governance mandates, security strategy and security program currently in place,” for a chief information security officer (CISO) and upper management to obtain a clear view regarding what cloud migration entails. And this is exactly where the book succeeds and stands out from similar publications.
In a comprehensive section on governance and management in the cloud, the book puts into perspective and addresses major questions related to governance and the responsibilities of upper management. It then provides an overview of how the COBIT 5 framework can be leveraged to manage the migration to cloud, in strategic, as well as, tactical and operational terms. And, taking it even further, the book then proceeds to outline the path to a cloud decision and beyond, through practical guidance. A stepped approach, decision making models, considerations through the preparation phase, cloud provider selection, and assurance functions’ details are just few of the factors that are analyzed in an easy to read and follow manner.
Understanding that information security is the top consideration faced by organizations, the book then delivers an across-the-board threat matrix alongside mitigating actions and mapping to COBIT 5. It delivers an up-to-date list of cloud assurance frameworks and a detailed responsibility matrix for cloud service providers and potential customers.
The book could have concluded with mere notes and summaries of the issues addressed in its chapters. The uniqueness, however, of this publication is that it stands as a practical guidance, and as such it features seven appendices, full of ready to use information by organizations either wishing to migrate to the cloud or evaluating the offering they already have. The appendices provide COBIT 5 governance and management practices, the template of cloud computing assurance program, a process capability assessment, cloud risk scenarios, contractual provisions that need to be taken into account, a cloud enterprise risk management governance checklist, and a practical approach to measuring cloud return on investment (ROI).
All-in-all, Controls and Assurance in the Cloud: Using COBIT 5 is the most definitive guide addressing all aspects of cloud computing migration and evaluation.
The book was recently featured as the Book of the Month in ISACA’s Bookstore. For more information click here.
Editor’s Note: Dr. Stergiou, CISM, was an expert reviewer of Controls and Assurance in the Cloud: Using COBIT 5.