Recruiting For Diversity: How IT Can Welcome New Leaders in 2016

It’s a great year for those with IT skills with the demand booming, but hiring managers are finding themselves up against a wall when it comes to the supply side of the equation – there just isn’t enough talent to go around. Or so it seems. So while those who fit the normal IT profile are likely to be snatched up immediately, there remain plenty of job openings just waiting to be filled. And they can be, but recruiters need to start thinking differently about what an IT professional looks like.

Reconsidering Qualifications
One of the fastest ways to increase the pool of IT talent is to start shifting the emphasis away from requiring four-year college degrees. Instead, IT recruiters should start accepting qualified candidateswith IT certificates. So many IT jobs are so specific that the broad knowledge base associated with a bachelor’s degree is unnecessary.

A quality certificate program will give candidates the specific skills they need without the huge time and money investments that come with a four-year degree. From there, companies can identify employees who show potential for further training, including possibly earning a degree, but first recruiters need to open the door to new talent.

Consider Bias
Not only are IT recruiters losing out on talented candidates by focusing on degree qualifications over concrete knowledge—many companies also have walled off their efforts by functioning from a preconceived notion of the IT professional. This image is too often white and male, leaving women and people of color out of the picture.

In many cases, IT companies have built bias into their hiring procedures, largely through networking and old boys’ clubs that readily exclude women and recent immigrants, anyone who isn’t tied to the current startup culture. If a female candidate walks in to interview with a panel of white men, for example, she may immediately feel excluded from the company environment. This can impact the interview quality, as the candidate loses confidence or preemptively accepts that she won’t be hired.

Dedicate Space
Because white men have already colonized so much of the tech industry, sometimes it is not only helpful, but necessary, to dedicate specific space to those historically excluded from the industry. Twitter tried this recently by focusing on bringing women to its Flight conference. This year 29% of attendees were women, compared to only 18% last year.

This success is likely linked to the taskforce of women and minorities in the IT field that Twitter created, a group that networked with Girls Who Code and TechWomen to start shifting the participation and employment demographics in IT. More companies should consider creating teams focused on diversifying the field – Twitter has shown that even a small effort can reap great success.

Train the Next Generation
Ultimately, it may not be possible to remediate the talent shortage in IT immediately – if there aren’t enough trained professionals, even among those with certificate training, then there aren’t enough candidates for the many jobs in IT. The only solution, then, is to start training the next generation, getting them interested in IT careers from a young age. While youth today may be very skilled with navigating the tech world, they often know little about the behind-the-scenes world. That needs to change.

Microsoft is making an effort in that direction, dedicating $75 million over the next three years to build up its YouthSpark program. This program focuses on exposing students to computer science at the primary and secondary school levels with the goal of increasing the number of computer science students at the university level.

With dedicated efforts from major companies like Twitter and Microsoft, the shortage of IT professionals may finally decline in the next few years, but their success won’t just be measured by job slots filled. Until the IT field begins to reflect the diversity of our communities, the field will have a talent shortage. It’s time for recruiters to open the doors and welcome qualified candidates.

Larry Alton
Writer, LarryAlton.com

[ISACA Now Blog]

Finding the Right External Audit Firm

In the Age of the Customer the pace of business innovation is accelerating, with technology now the primary customer interface for many business processes. Technologies including mobile, web and even smartwatches are now part of many business processes. This, combined with an ever growing, complex supply chain and expectations of immediacy, means technology is more critical than ever to drive and deliver accuracy and speed.

The customer centric evolution mandates skills many organizations may not possess. User experience based design and development, backend systems integration, and specific technical knowledge in conjunction with effective governance skills are required to ensure financial and process accountability. Given that the impact of technology is not simply joining technology stacks, it additionally requires process integration and governance, supplementing internal skills with proven industry experience is critical to B2B success.

All of that points to the importance of partnering with an exceptional external audit firm to provide those critical skills.

Identification and Vetting Potential Firms

Identification of an external audit firm can be as simple as an Internet search or as complex and involved as a large request for proposals (RFP) process. For instance, a quick web search will quickly find several trustworthy household names. There are, however, many lesser known firms that may be a better fit, depending on your organization’s size and industry.

A proven vetting process is key to your success.

  • Develop a short list of qualification questions relevant to your organization’s processes.
  • Does the firm have experience and references in the domain?
  • Can they point to successful initiatives similar to your undertaking?
  • What did the project look like and who were the critical people involved?
  • Demand references from within your industry and talk to those references.

Once you have found an organization, a critical component is the assurance that the correct skills are delivered to the project to assure its success. This will vary by vertical. If you are in manufacturing, for example, you should look for relevant skills within that sector. If the B2B initiative is in a highly regulated domain, such as healthcare, you need a consultant experienced in healthcare, with relevant certifications, in conjunction with certifications such as CISA (Certified Information Systems Auditor) in the IT Audit domain.

ISACA has excellent guidance to assist you.  Its audit guidelines using COBIT are particularly useful in this regard. The networking opportunities ISACA provides members can also offer insights on the audit profession and its players. Institute of Internal Auditors (IIA) certifications are helpful in identifying qualified firms, as well.

Additionally, in an era of disruption, where the technology is more relevant than ever, look for a combination of skills, including financial, technical and even compliance. This may require several external audit firm personnel participate in the process.

Skills Transfer Opportunity

Your external audit partner will give you some external independence; however, this also presents an excellent opportunity for skills transfer into your organization. I highly recommend that you take advantage of your investment. I suggest partnering the external auditor with an internal team member to whom the skills can be transferred. This will require an additional short-term investment in your people, one that will pay dividends in the longer-term as you develop these skills internally to support greater velocity in future initiatives.

The role of external auditor in many organizations is reactionary. In the new world it must become proactive, engaged and involved in the development of products and services that ensure critical audit trails are integrated into design and delivery. It’s simply too difficult to gather data after the fact.

Remember, external audit firms are trusted advisors, so once the choice is made their outcomes will probably be considered binding in the organization. That means a little diligence now will be rewarded later.

(FYI: The Public Company Accounting Oversight Board’s (PCAOB) recent discussion paper “Audit Quality Indicators for External Auditors” includes 28 helpful indicators to track, monitor and evaluate external auditors.)

Robert E Stroud CGEIT CRISC

Principal Analyst Forrester Research & Immediate Past President ISACA

[ISACA Now Blog]

Examining E-Commerce, Governance and Applied Certifications

ISACA hosted a free live webinar on how certifications and education get applied to real world e-commerce and governance cybersecurity issues titled “Cybersecurity: e-Commerce, Governance and Applied Certifications” on Tuesday,15 December 2015. We recently spoke with presenters Michelle Mikka-Van Der Stuyf, president and CEO of BizStrat Technology Corporation, Sally Smoczynski, CISSP, managing partner of Radian Compliance, and Diana Salazar, CISM, CISA,CRISC,CGEIT, executive security advisor (ESA) of Magellan Group, about cybersecurity: e-commerce, governance and applied certifications. Read the interview below.

Q: These are some big topics. How are they impacting organizations today, and what do companies need to know?

Michelle Mikka-Van Der Stuyf (MMV):  We shared real-experience information on how we practically apply cybersecurity solutions in business and government. To help attendees focus, we started off with some shocking cybersecurity stats. We also provided insight into just how encompassing cybersecurity is, how you can get a more strategic view of your greatest risks, and where companies should apply their security resources.

Sally Smoczynski (SS):  I reviewed the root causes of cybersecurity incidents—why did they happen and what could have been done to prevent or mitigate the impact? I’ll explore why information security governance outside of IT is essential for strong policy and procedures management. I also discussed making sense of regulatory frameworks. Which ones do you use, and how can they be better managed? Finally I discussed the value of a management system.

Diana Salazar (DS):  Regulations may fall behind as people continue toward bring your own devices (BYOD) and bring your own cloud (BYOC); therefore, organizations need to use a continuous assessment process of controls and a framework for information sharing, data movement and greater interoperability among legal and privacy bodies. They should review technology challenges (application, profiling, digital education and web tracking), remove data for right to be forgotten requirements, and increase transparency on the data organizations are collecting and required controls using comprehensive frameworks.

Q: How do you apply those points to your organization?

MMV:  Cybersecurity is as much about practice as it is solutions. Our business/technology solutions always integrate risk and risk mitigation to deliver a sound, safe and secure result. Often companies want to push security to the side to save time or cost, but we believe security is a must-have and won’t break those standards to deliver a solution that is not in the best interest of our client or their industry.

Education and certifications are keys to maintaining cybersecurity. Cybersecurity information is constantly changing, so it’s critical to stay current with industry news by following breach intelligence, attending conferences and other industry events, and collaborating with CISOs and other security professionals. We apply certifications and education in every solution. By being educated on risks and solutions, including practices that give you a leg up against the inevitable breech, you’ll be serving your customers’ cybersecurity needs well.

SS:  You have to practice what you preach. In Radian’s case we’re applying a strong security awareness program and practicing good data protection habits. We are an implementer of ISO 27001 so we focus on best practices and relevant risk mitigation to support our clients’ programs. We perform internal audits to many ISO standards and identify areas of improvements to reduce the threat of cybersecurity incidents and information security incidents.

Internally, we strengthened our security posture based on what we learn in the field. Organizations need to take a holistic governance structure to protect their information assets. Tools can help detect incoming threats, but people are the biggest threat, including their social media habits.

Information security governance outside of IT is essential for strong management of policy and procedures. Governance needs to include HR, physical security, training, marketing, legal and other departments. IT plays a very important role, but not the core.

DS:  Using a continuous assessment process organizations enable defensibility and resilience. Generally review controls fit into three categories: protective/preventative which enforces acceptable behaviors, detective/audit controls which perform a monitoring activity, and reactive controls which respond to a detective control providing an alert or corrects an unacceptable situation. When there is a breach one of these simple categories, preventative, detective or reactive control is missing. Applying these categories with a framework enables an organization to reduce an adversary’s ability to do harm. Frameworks provide the ability to determine which controls apply to the organization.

[ISACA Now Blog]

ISO/IEC 27001 Process Mapping to COBIT 4.1 to Derive a Balanced Scorecard for IT Governance

The balanced scorecard (BSC) initially developed by Kaplan and Norton1, 2, 3, 4 is a performance management system that should allow enterprises to drive their strategies on measurement and follow-up.
In recent years, the BSC has been applied to IT and, currently, the first real-life IT security governance application has been developed based on mapping International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 27001 control objectives to COBIT 4.1process areas and IT governance focus areas. As a further exercise, the relationships and similarities of COBIT 4.1 and COBIT 5 can be explored to create a mapping for COBIT 5 in future publications.
This article explains how an exercise in instituting controls can be used to establish the IT BSC, which can be linked to the business BSC and, in so doing, can support the IT/business governance and alignment processes as derived from mapping ISO/IEC 27001 and COBIT 4.1 controls.

Balanced Scorecard Introduction

Kaplan and Norton introduced the BSC at the enterprise level. Their basic idea is that the evaluation of an organization should not be restricted to a traditional financial evaluation, but should be supplemented with measures concerning customer satisfaction, internal processes and the ability to innovate. These additional measures should assure future financial results and drive the organization toward its strategic goals while keeping all 4 perspectives in balance. Kaplan and Norton proposed a triple-layered structure for the 4 perspectives: mission (e.g., to become the customers’ most preferred supplier), objectives (e.g., to provide the customers with new products) and measures (e.g., percentage of turnover generated by new products).
The BSC can be applied to the IT function and its processes.5, 6, 7, 8 This article transformed previous visions into actions that can be used to correct any lapses and reduce value in the BSC results. The use of the BSC can also be applied to IT risk management.9

IT Governance Through Controls

This article illustrates how a cascade of scorecards can be instrumental in the development of IT/business governance processes and how this hierarchy of scorecards can support the alignment of business and IT strategy. The IT development BSC and the IT controls/operational BSC are introduced as enablers for the strategic BSC, which, in turn, is the enabler of the business BSC (figure 1).
Governance is established through compliance to standards and control objectives.

Figure 1—IT Balanced Scorecard as a Business Enabler

Source: Christopher Oparaugo. Reprinted with permission.

Controls Through Compliance to Standards

IT governance is part of corporate governance and has to provide the organizational structures to enable the creation of business value through IT, the assurance that there are no IT investments in bad projects and that there are adequate IT control mechanisms established through compliance to the control objectives of COBIT and ISO/IEC 27001.
The methodology of the BSC is a measurement and management system that is suitable for supporting the IT governance process and the IT-business alignment process. Figure 2 shows sample cumulative average scores for the ISO/IEC 27001 control objectives and questions showing inputs for the security policy domain used in the exercise for mapping ISO/IEC 27001 to COBIT 4.1.

Figure 2—Sample Cumulative Average Scores for the ISO/IEC 27001 Control Objectives and Questions Showing Inputs for Security Policy Domain

Source: Christopher Oparaugo. Reprinted with permission.

Figure 3 shows sample cumulative domain scores for the ISO/IEC 27001 control objectives. These results are computed by domain as used in the exercise for mapping ISO/IEC 27001 to COBIT 4.1. The future state results are arbitrary figures that are being aspired to as targets for the exercise.

Figure 3—Resulting ISO/IEC 27001 Compliance Data by Domain

Source: Christopher Oparaugo. Reprinted with permission.

Figure 4 is the bar chart representation of the ISO/IEC 27001 results.

Figure 4—ISO/IEC 27001 Compliance Data by Domain Result in Bar Chart Format

Source: Christopher Oparaugo. Reprinted with permission.

The generic maturity model score was derived from the data of the assessment based on the values that are mapped to the COBIT 4.1 domains (figure 5). These scores are used to create the charts in figures 6 and 7 for maturity benchmark results by domains.

Figure 5—Compliance Output Data to Generic Future Desired State With Generic Maturity Model

Source: Christopher Oparaugo. Reprinted with permission.

Figure 6—ISO/IEC 27001 Compliance Data Results to Generic Future Desired State

Source: Christopher Oparaugo. Reprinted with permission.

Figure 7—COBIT Compliance to Generic Future Desired State

Source: Christopher Oparaugo. Reprinted with permission.

The value inputs of 0% to 100% from the ISO control objectives, sections and control questions are mapped to COBIT 4.1 domains and processes. These are linked to the IT focus areas as shown in figure 8.

Figure 8—Sample Results Showing Mapping of ISO/IEC 27001 Data to COBIT Processes

Source: ISACA, Mapping COBIT 4.1 to ISO /IEC 27001, USA, 2005

These resultant data from the exercise are further employed as COBIT information criteria for primary and secondary grouping. The resultant values of the ISO/IEC 27001 mapping into COBIT processes are linked with the defined IT goals. Exercise results showing the values from the data mapping outputs are shown in figure 9.

Figure 9—Linking COBIT Processes Data Results to IT Goals Showing the Information Criteria for Governance Activities

Source: Christopher Oparaugo. Reprinted with permission.

Based on the data values from the COBIT process linking to IT goals, the IT goals to business goals are derived and the elements of the BSC are developed. Figure 10 shows the results of these links.

Figure 10—Data Linking IT Goals to Business Goals

Source: ISACA, COBIT 4.1: Framework for IT Governance and Control and IT Governance Institute

Information Security Governance Balanced Scorecard

The BSC is a management system (not only a measurement system) that enables organizations to clarify their vision and strategy and translate those into action. It provides feedback around both the internal business processes and external outcomes in order to continuously improve strategic performance and results. When fully deployed, the BSC transforms strategic planning from an academic exercise into the nerve center of an enterprise.
The BSC uses 4 perspectives, develops metrics, collects data and analyzes the data relative to each of these perspectives:

  1. Financial—To succeed financially, how should we appear to our shareholders? 52.38%
  2. Customer—To achieve our vision, how should we appear to our customers? 59.40%
  3. Internal business—To satisfy our shareholders and customers, at what business process must we excel? 61.31%
  4. Learning and growth—To achieve our vision, how will we sustain our ability to change and improve? 55.54%

Conclusion

The vision and strategy driver scores are achieved from the mapping exercise of ISO/IEC 27001 to COBIT 4.1 and these can be used in determinig key permormance indicator (KPI) scores for a department and be drilled down to an individual’s contribution in the overall department success. The results from linking IT goals to business goals and reviewing with the COBIT information criteria helps form a better perspective of the BSC. The assessment results can be drilled and backward review of the mapping values used in determining the root cause of having low values from a set of mapped data in ISO/IEC 27001 control objectives and questions; this will form a basis for developing an action plan as needed by the business.
Successful enterprises understand the risk and exploit the benefits of IT, and find ways to deal with aligning IT strategy with the business strategy, cascading IT strategy and goals down into the enterprise and insisting that an IT control framework be adopted and implemented. IT governance is not an isolated discipline. It is an integral part of overall enterprise governance that drives the business in these days of the Internet of Things. The need to integrate IT governance with overall business governance is similar to the need for IT to be an integral part of the enterprise business.

Christopher Oparaugo, CISM, CGEIT, CRISC

Is the chief technology officer of KATEC Consulting Ltd. He has worked for IBM Global Business Services as an information security consultant. He has also worked in the telecommunication and banking industries in West Africa. Oparaugo has contributed to the ISACA CISM, CGEIT and CRISC Certification Project and Test Enhancement Committee since 2005, setting exam questions and reviewing the manuals.

Endnotes

1 Kaplan, R.; D. Norton; “The Balanced Scorecard—Measures That Drive Performance,” Harvard Business Review. January-February 1992, p. 71-79
2 Kaplan, R.; D. Norton; “Putting the Balanced Scorecard to Work,” Harvard Business Review. September-October 1993, p. 134-142
3 Kaplan, R.;D. Norton; “Using the Balanced Scorecard as a Strategic Management System,” Harvard Business Review. January-February 1996, p. 75-85
4 Kaplan, R.; D. Norton; The Balanced Scorecard: Translating Vision Into Action, Harvard Business School Press, Boston, 1996.
5 Gold, C.; “Total Quality Management in Information Services—IS Measures: A Balancing Act,” research note, Ernst & Young Center for Information Technology and Strategy, USA, 1992
6 Gold, C.; “US Measures—A Balancing Act,” Ernst &Young Center for Business Innovation, USA, 1994.
7 Willcocks, L.; Information Management, The Evaluation of Information Systems Investments, Chapman & Hall, UK, 1995
8 Van Grembergen, W.; D. Timmerman; “Monitoring the IT Process Through the Balanced Scorecard,” Proceedings of the 9th Information Resources Management (IRMA) International Conference, USA, May 1998, p. 105-116
9 Van Grembergen, W.; ”The Balanced Scorecard and IT Governance,” Information Systems Control Journal, vol.2, 2000

[ISACA]

A Student’s Experience at the CSX North America Conference

As a student working to complete a master’s degree in IT Management and working to advance in my career path, I found many advantages to attending CSX 2015 North America. Exchanging ideas and opportunities, networking with professionals in the cybersecurity field, learning more about the industry, and increasing awareness of new trends are some of the greatest benefits of this professional conference.

I had the pleasure and the honor of being among the 50 students who were awarded ISACA’s CSX 2015 North America Student Scholarship to attend day two of this conference at the Marriott Wardham Park in Washington DC. My essay titled “Risk Assessment and Mitigation in Mobile Application Development” offered me the opportunity to address threats to critical infrastructure and set out recommendations for companies for future actions. I was also given the opportunity to attend day one and day three with the help and support of Affinity Plus Federal Credit Union, where I am currently employed as a Technical Analyst.

I was very happy and fortunate to attend ISACA’s CSX conference because, as anyone working in the field can attest, cyberattacks are fast becoming recognized in the US and globally as a top threat. I really enjoyed the keynote speakers, especially Mike Rogers, John Sileo and Robert Herjavec, and found their presentations to be extremely valuable in both my professional and academic work. The highlight at the opening session was the keynote address by Former US Congressman and CNN National Security Commentator Mike Rogers, who covered the subject of how defending US security is no longer about securing physical borders and increasingly about cyberspace. His words left a deep impression in my mind, most notably the statement “Data breach mitigation plan discussion should be a top priority in every company.”

Keynote speaker John Sileo covered his personal experience of being a victim of social engineering, which resonated strongly with me. I learned a lot of techniques for engaging people in security awareness so that we can better protect our enterprises and our personal identifiable information, and build effective fraud-fighting techniques against the “bad guys.” Each session I attended was informative and engaging, providing insights that are already benefitting me in my day-to-day work.

As a student scholarship recipient, I was welcomed to attend some great presentations such as the Personal Branding workshop covered by William Arruda. William took us through his proven three-step personal branding process “DITCH, DARE, DO” in order to stand out from the myriad others with similar career ambitions, attract the attention of hiring managers, ace the interview, and land our ideal jobs. I learned so much from this personal branding seminar; I was able to align who I am with what I do and where my ambitions are leading in the future. This was an important session for everyone, but especially students, because Arruda taught about how to market yourself and stand out in a labor market that has never been more competitive.

I also enjoyed observing the live CyberLympics World Finals. Congratulations to the “Hack.ERS” from The Netherlands for winning first place in the highly competitive ethical hacking computer network defense game. Being in the room and watching live as these teams from around the world were hacking the network, I knew immediately that this was an event not to be missed.

Lastly, in the exhibit hall I was able to experience the latest cybersecurity technologies, tools and services from the top companies in the IT audit, cybersecurity and governance industries. From a professional standpoint, the expo hall was the place to discover and learn more about the great tools and technologies a company might be looking for to address their cybersecurity challenges.

The three day trip to Washington, DC was meaningful for me, as it was my first time there—not only experiencing the city, but also attending a cybersecurity conference of such size and depth. The knowledge, connections and perspective I found at this conference continue to inform my thoughts and my work as a cyber defendant. It was wonderful to meet and network with new people promoting new ideas, vendors selling new products and experts teaching new cyber defense methods, and I am proud of being part of ISACA, which is such a great organization. The experience of attending this conference will be an invaluable, treasured memory, and the knowledge I have taken away will be useful throughout my career. For those seeking career advice and professional development in cybersecurity, CSX is the conference to attend. I look forward to meeting you in Las Vegas next year!

Yaro Sadek Tahirou
Technical Analyst, Affinity Plus Federal Credit Union

Registration is now open for CSX 2016 North America in Las Vegas. Visit www.isaca.org/cyber-con and click the CSX 2016 tab to reserve your space.

[ISACA Now Blog]

English
Exit mobile version