Are Your IT and Strategic Business Goals Aligned?

Developing and using models to help represent relationships between business strategy and IT is an effective method to show the strategic effect of IT within the enterprise. As more and more business commerce becomes automated, the growing impact of IT on business strategy, such as the development of a sustained competitive advantage in a highly connected world, becomes increasingly evident.
Alignment of IT and business strategies is paramount for achieving and maintaining a leadership position. Today, the elements that differentiate one successful organization from another are difficult to observe and measure as the power of imitation levels the playing field, making a business-driven, information-centric and technology-supported strategy imperative.

How Does COBIT 5 Contribute to the Alignment of Goals?

COBIT 5 is an integrated framework that facilitates the achievement of the business’s strategic goals and solidifies value through an effective IT governance and management approach.
COBIT 5 provides for the governance and management of enterprise IT (GEIT) in a holistic way for the whole organization, taking into account the needs of business and functional area stakeholders and driving the business´s strategic goals in an end-to-end fashion throughout the enterprise. Because COBIT 5 aims to help organizations achieve balance in financial, customer, internal process, and learning and growth goal sets, the framework may be applied to public, private or nonprofit organizations.
Upon adopting COBIT 5, the organization will be able to identify strengths and weaknesses associated with its IT processes and environment. This, in turn, will identify areas where processes can be optimized to better support the organization’s goals and provide for safer, more dependable operations. Similarly, the organization will be able to ensure that IT has the correct direction, i.e., alignment with strategic business goals.

Implementation Stages

A successful strategy for implementing COBIT 5 always begins with identifying the drivers for developing the organization’s goals and the primary results the organization would like to achieve, whether it be realizing the benefits of a strategy or optimizing risk or resources. Once this is understood, an implementation of COBIT 5 should consider the stages shown in figure 1.

Figure 1—COBIT 5 Implementation Stages

Source: A. Zapata. Reprinted with permission.

ISACA provides some related COBIT 5 materials that can be used to obtain additional references to this suggested strategy, including the COBIT 5 Framework, COBIT 5: Enabling Processes, COBIT 5 Process Assessment Model (PAM): Using COBIT 5 and COBIT Self-Assessment Guide: Using COBIT 5.

Conclusion

COBIT 5 provides a powerful framework for the identification of enterprise goals. It also enables each critical process to be directly aligned to achievement of these goals in a way that can be easily measured and communicated. By applying the proven and efficient implementation strategy suggested, any organization can understand how effectively it is achieving these goals and ensure transparency across all functional areas.

Alexander Zapata, CISA, CGEIT, CRISC, COBIT 5 Implementation and Assessor, ISO 22301 LI, ISO 27001 and Foundations, PMP

Is an international consultant in IT governance and IT improvement with experience in Mexico, Colombia, Panama and Peru. He is also an expert instructor and COBIT 5 Accredited Trainer. He can be reached atazapatacolombia@yahoo.com.

Alexander Zapata, CISA, CGEIT, CRISC, COBIT 5 Implementation and Assessor, ISO 22301 LI, ISO 27001 and Foundations, PMP

[ISACA COBIT Focus]

DoD Updates Government Security Requirements for Cloud, But What Does That Really Mean?

IT officials from the Department of Defense (DoD) have released an update to the Cloud Computing Security Requirements Guide (CC SRG), which establishes security requirements and other criteria for commercial and non-Defense Department cloud providers to operate within DoD. These kinds of updates are not uncommon. In fact, they are encouraged through an interesting use of a DevOps type methodology – as the DoD explains:

DoD Cloud computing policy and the CC SRG is constantly evolving based on lessons learned with respect to the authorization of Cloud Service Offerings and their use by DoD Components. As such the CC SRG is following an “Agile Policy Development” strategy and will be updated quickly when necessary.

The DoD offers a continuous public review option and accepts comments on the current version of the CC SRG at all times, moving to update the document quickly and regularly to address the constantly changing concerns of an evolving technology like public and private cloud infrastructure. The most recent update includes administrative changes and corrections and some expanded guidance on previously instated requirements, with the main focus on the updates being to clarify standards set in version one and alleviate confusion and any potential inaccuracy.

If you are interested, you can read through the entire CC SRG revision history online.

What is particularly interesting here is the DoD’s acknowledgment that management of cloud environments is constantly evolving, security requirements and best practices need to be iterative, and updates need to be made regularly to ensure relevancy. It’s also important to note that the CC SRG is only one of many government policies put in place to help government agencies securely and effectively implement cloud infrastructures. There are also guidelines like NIST SP 800-37 Risk Management, NIST 800-53, FISMA and FedRAMP to consider. All of these provide a knowledge base for cloud computing security authorization processes and security requirements for government agencies.

What the DoD’s updates to the CC SRG should reinforce for agencies is that they need to have a clear cloud strategy in place in order to ensure compliance and success in the cloud. Determining the best implementation of these guidelines for your needs is difficult in and of itself. Add to that the ongoing management and updates required to keep up with ever-evolving guidelines and an IT team can find itself struggling.

By partnering with systems integrators and software vendors, or working directly with a managed service provider, like Datapipe, government agencies can more easily develop a long-term cloud strategy to architect, deploy, and manage high-security and high-performance cloud and hosted solutions, and stay on top of evolving government policies and guidelines.

For example, Microsoft Azure recently announced new accreditation for their Government Cloud, Amazon AWS has an isolated AWS region designed to host sensitive data and regulated workloads called AWS GovCloud, and you can learn more about our new Federal Community Cloud Platform (FCCP), which meets all FISMA controls and FedRAMP requirements, and all of our specific government cloud solutions on the Datapipe Government Solutions section of our site.

Brian Burns, Bid Response Manager/Government Affairs, Datapipe

[Cloud Security Alliance Blog]

Corporate Governance: Evaluating and Directing Value Creation

Organizations are contending with increasingly dynamic and demanding external and internal environments by making good corporate governance accessible and fit for application through the adoption of governance practices that sustain value creation. Governance and management systems are being designed to reinforce and govern a holistic, interrelated set of arrangements that can be understood and implemented in an integrated manner using organizational structures, processes, practices and ethical, conscious behavior.

Governance and Management
Corporate governance is the system that a governing body exercises ethical and effective leadership to establish:

  1. An ethical culture
  2. Sustainable performance and value creation
  3. Adequate and effective control by the governing body
  4. Trust in the organization, its reputation and its legitimacy

Putting corporate governance into practice requires a holistic and integrated set of arrangements that can be evaluated and directed to create the value stakeholders expect.

Organizations often use a wide variety of resources and governance mechanisms to achieve their purpose, strategic goals and to fulfill stakeholder needs. Leveraging resources requires the establishment of accountability, assignment of responsibility, and transparency and fairness in how work gets done.

The implementation of corporate governance starts with an examination of the roles and responsibilities for decision-making processes, specifically those that impact the achievement of strategic goals. This will reveal who is accountable and who is responsible for the practices and governance mechanisms required to achieve governance outcomes. A governance and management system institutionalizes the organizational structures, processes and ethical, conscious behavior.

Technology and Information Governance
While governing bodies are expected to be proactive in ensuring that information assets are leveraged for growth, there are few tools actually available that provide governing bodies with sufficient oversight. A governance and management system provides an integrated solution that brings the governors and the managers together and provides a holistic approach for them to effectively govern and manage the current and future use of technology and information.

Such a system provides the means to institutionalize the enablers of good corporate governance. People, process, technology and information come together in an integrated governance and management system that enables value creation and supports the achievement of strategic goals.

An organization’s capability to govern and manage is developed within a governance and management system and enhanced through the use of a suitable mix of enablers:

  • Principles, policies and frameworks
  • Processes, practices and activities
  • Organizational structures, roles and responsibilities
  • Skills and competencies
  • Culture and behavior
  • Service delivery components
  • Information management

Orchestration and Choreographing the Practices
Corporate governance is not accessible or actionable if the application of the underlying practices cannot be influenced. To achieve the organization’s purpose and strategic goals and deliver value to the stakeholders, the governing body and executive managers must evaluate and direct the regular and ad hoc daily activities of internal and external parties.

Leadership and organizational structures are of little benefit if they cannot influence the organization’s processes and practices, direct the alignment and prioritization of value delivery, govern risk management, optimize resource usage and track performance.

A governance and management system provides the functionality required to orchestrate those responsible and choreograph the implemented practices how the governing body and management want to direct operations, effectively manage risk, consume resources and comply with regulatory obligations.

Being fit for purpose is paramount. Every governance and management system should be crafted in accordance with size, available resources, and complexity of strategic objectives and operations so that it suits the organization and sustains value creation.

Maintaining a Framework for Governance
Regardless of any technical and organizational arrangements deployed by management, these arrangements will be fundamentally undermined if operated outside an effective risk management and governance regime. It is essential that the implemented corporate governance framework ensures procedures, personnel, physical, technical and organizational arrangements, and that controls:

  • Remain effective throughout the lifetime of service delivery and value creation
  • Are responsive to changes in the services and value delivery propositions, and
  • Change in accordance with threat and technology developments

A documented governance and management system ensures that corporate governance is understood and communicates which practices are required to support service delivery, performance standards, value creation, regulatory compliance and internal controls. Records of assigned responsibilities, current status, analysis, evaluation and completion demonstrate compliance with the selected principles, policies, frameworks, standards, and legal and regulatory requirements applicable to the practices assigned.

The governance and management system incorporates the priority, status, sequence and timing of actions; enables the monitoring of capability, progress and outcomes achieved; and coordinates continuous improvement.

Peter Hill will speak on Governance & Management at EuroCACS in Dublin 30 May-June 1 2016.

Peter Hill, CISA, CISM, CGEIT, IT Governance Network

[ISACA Now Blog]

Penetration Testing Part of an Effective Cyber Defense

With countless organizations falling victim to cyber breaches, it seems that security groups are often unprepared to defend against attacks. Being prepared means understanding which types of attacks to expect and being able to detect and withstand an attack.

Many organizations have implemented cyber controls, but they lack evidence their controls work. Implementing controls does assure that network or security operations can detect malicious attempts as they are launched, but controls cannot effectively block the attempts. Penetration testing, or pen testing, is effective for detecting cyberattacks, stopping malicious activities and initiating response activities as soon as possible.

Pen Testing is Offensive
Pen testers mimic cyber attackers in a controlled manner, using commonly available tools to gain information about networks, systems and applications. The tools provide a launching pad to circumvent controls or exploit vulnerabilities. The objective of pen testing—whether technical or social engineering—is to demonstrate that systems can be compromised and sensitive, confidential resources are at risk. While it provides information on the effectiveness of cyber defenses, pen testing is offensive.

Pen testing should be part of every cyber defense program because it demonstrates that system defenses can be defeated. It shows what effort is required to complete an attack, the attacker’s level of sophistication, the complexity of methods needed and the time required. Pen testing helps enterprises understand if security or network operations personnel are able to detect attacks and the level of noise required before an attack is evident.

These tests provide teachable moments when reviewing the techniques used in a simulated attack. System administrators who believe their protection mechanisms cannot be breached are often surprised when the mechanics of an attack are laid out to show how intruders moved from system to system, exploiting permissions on each hop, until they essentially owned the network.

Snapshots of Defenses
Pen testing, however, does not address the full range of activities required for an effective cyber defense. It provides useful, but limited, insights and should be considered within the context of a holistic approach to cyber defense. Like any testing, pen tests are snapshots of defenses that are limited by the tester’s capability, tools, methods and time. An ineffective attack method today may be more effective on another system or at another time. Effective defenses today may be ineffective tomorrow because of administrative errors or other factors.

Unlike attackers, pen testers work within the confines of an agreed-to scope, client budget, laws and ethics. Persistent, advanced attacks by nation-states, organized criminal bands and hacktivists don’t have those limitations. Effective cybersecurity programs must be able to identify the environment being protected, protect assets, detect anomalies and threatening events, respond to incidents as soon as possible, and finally recover.

Essential to Cyber Security
Pen testing—while still an essential part of an effective cybersecurity program— identifies the environment from a technical perspective only within the scope of the examination. It tests the ability to protect a system but does not determine security failure root causes. Operations and system administrators may learn from the tests to determine what should have been detected, but this is not often part of the scope.

It also does not help cyber incident response or recovery. Attackers have the time and opportunity to plan and launch multi-element attacks. They only have to find one method that works. Cyber defenders must be prepared for all attacks, all the time, and have 100 percent effective detection and deterrence mechanisms.

The NIST Cybersecurity Framework, however, does offer a holistic protection program that includes identification, protection, detection, response and recovery. As part of creating a cyber program, CISOs need to ensure those who build, deploy and manage technical infrastructure have the knowledge and tools to be part of this holistic, effective defense solution.

If there are sufficient resources, pen testers can be part of the security staff providing ongoing assurance of technical controls. Where resources are more limited, pen testing can still be part of an ongoing cyber-assurance program. All organizations should recognize that while pen testing has value, they must embrace the more holistic model of defense. This provides the stable, attack-resistant infrastructures the digital age demands.

Hale will present Blockchain: Ensuring Confidence in Digital Transactions at the EuroCACS Conference 30 May-1 June 2016 in Dublin

Ron Hale Ph.D., CISM, ISACA, Chief Knowledge Officer

[ISACA Now Blog]

WIRED Editor David Rowan Predicts Future of Audit, Governance, Risk Management

ISACA Now recently interviewed David Rowan, editor of WIRED magazine and keynote speaker atEuroCACS 2016. He discussed the future of audit, governance and risk management, as well as what can be done to stop cybercriminals once and for all.

ISACA Now: What are some of the changes/innovations audit, governance and risk management professionals should expect in the next 5-10 years?
Rowan: 
We are in a networked world of ever increasing transparency, as well as increasing vulnerability to data breaches. Starting with transparency, the recent breaches of client confidentiality over Panamanian accounts, and the Snowden disclosures before that, are a stark reminder that every professional’s decisions could tomorrow be scrutinized on the front page of the New York Times. If you’re an auditor or a risk management professional, are you comfortable with your advice, your private emails, your entire work life being exposed to the twittersphere? I hope so. At the same time, we’ll find foreign states and criminal gangs investing ever greater efforts in breaching supposedly secure corporate networks to transfer funds or steal proprietary data. How well defended are you against these real and growing risks? Is your CEO taking personal responsibility?

ISACA Now:  Will the technology of cybersecurity ever catch up to or surpass the technology used by cybercriminals?
Rowan: 
The single biggest worry I have today is our growing reliance on networked connections to keep our economy moving—the satellites empowering communications, the servers running our utilities, the corporate decisions being made on supposedly safe internal networks. The bad guys are terrific innovators; they understand psychology as well as technology, so whether they’re spoofing the GPS signal of a satellite to put it out of orbit or hijacking your home computer with ransomware, they’re delivering nicely rising profits at our expense. I’m not sure we’ve seen the political will or the corporate education to confront these criminals with well-resourced defense systems that can scale and can keep up with the bad guys’ rate of innovation. They, after all, have a great incentive:  you used to rob a bank because that was where the money was; today the money is all over the network.

ISACA Now:  You’ve interviewed many global influencers over the years. What key characteristics have allowed them to be so influential? Any examples?
Rowan:  When it comes to entrepreneurs who really build something huge—the Facebooks, the WhatsApps, the Kickstarters—there tend to be a few common characteristics in many cases. Often they are motivated to solve a big problem, something that really makes a difference and not simply make money. That motivation keeps them going through the tough bits. They’re often very resilient personalities who don’t take it personally when things go wrong, so they can get up and push past the problem. They’re often outsiders in some way who don’t see the rules other people rely on:  maybe they had dyslexia at school, or were immigrants who didn’t easily fit in, or were misfits in some other way. They have tremendous self-belief, which lets them motivate their teams as well as attract investors and the media. And often I’ve found they had difficult relationships with their father—I can’t prove this scientifically, but perhaps it’s something that leads them to be driven beyond reason to prove themselves…

ISACA Now:  You will be speaking at the EuroCACS conference 30 May-1 June 2016 in Dublin. Give us a brief preview of what you’ll discuss and what attendees will take away.
Rowan: 
My life is spent travelling to meet the start-ups transforming industries and the investors betting big on them, as well as the research labs designing the way we will interact in the future with technology. So I’ll translate what I’m seeing in real fast-growth businesses to how it will impact successful existing businesses in the next five years—and how consumer behavior is being transformed by everything from mobile screens to virtual-reality headsets. The bottom line is the world will never move this slowly again, as exponential technologies create massive new opportunities to build businesses that could never have existed a couple of years ago. So there’s a risk that delegates will go back to the office with a rather big to-do list of urgent things they need to do to become as innovative as the start-ups…

David Rowan, Editor, WIRED

[ISACA Now Blog]

English
Exit mobile version