Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 |...

25
Compliance Security (But, we’re getting closer) Rich Banta, Co-Owner & CISO, Lifeline Data Centers, LLC

Transcript of Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 |...

Page 1: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Compliance ≠ Security

(But, we’re getting closer) Rich Banta, Co-Owner & CISO, Lifeline Data Centers, LLC

Page 2: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Page 3: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

•  FedRAMP-Ready •  HITRUST CSF

Certified •  PCI DSS AoC/RoC •  SOC2 •  IRS-1075

Page 4: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Rich Banta •  CISSP•  CCSP•  CISA•  CRISC•  CFCP•  CDCDP•  CTIA•  CTDC

Page 5: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security WhydoesCompliance≠Security?

Page 6: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security WhydoesCompliance≠Security?•  ComplianceisChecklist-Based

Page 7: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security WhydoesCompliance≠Security?•  ComplianceisChecklist-Based•  CompliancedependsonAudits

Page 8: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security WhydoesCompliance≠Security?•  ComplianceisChecklist-Based•  CompliancedependsonAudits•  AuditsassessapointinAme

Page 9: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security Whateffortsarebeingmadetoaddressthepoint-in-Ameshortcoming?

Page 10: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security Whateffortsarebeingmadetoaddressthepoint-in-Ameshortcoming?•  CMP:ConAnuousMonitoringProgram

Page 11: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security CMP:FedRAMP’sapproachtoConAnuousMonitoring

Page 12: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security TheFedRAMPModerateBaselinecontains326controls*.*AndanaddiAonal~70controlenhancements

Page 13: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security TheFedRAMPCMPcallsforconAnuousongoingmonitoringandreporAngon58ofthe326controls.

Page 14: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security NIST800-53R4ControlRA-5:•  VulnerabilityScanning

Page 15: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security NIST800-53R4ControlRA-5:•  VulnerabilityScanning– RA-5a:OS/infrastructure/webapplicaAon/databasescans– ScanresultsmustbesubmiYedinFedRAMP-specificdashboardformat

Page 16: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security NIST800-53R4ControlRA-5:•  VulnerabilityScanning– RA-5d:ProvidearAfactstoISSOshowinghigh-riskvulnerabiliAeshavebeenmiAgatedin30daysandmoderaterisk-vulnerabiliAeswithin90days

– POA&M

Page 17: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security NIST800-53R4ControlCM-7(1)a:•  LeastFuncAonality–  IdenAfyandeliminateunnecessaryfuncAons,ports,protocols,and/orservices

–  PPSM(Ports,Protocols,andServicesManagement)

Page 18: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security NIST800-53R4ControlCM-8(3)a:•  InformaAonSystemComponentInventory–  AutomateddetecAonofnewassets–  ReportssubmiYedmonthly–  Vulnerabilityscanmust=Inventoryscan=PPSM=NAC,etc.

Page 19: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security Lifelinehasnointernalwirelessnetworks.

(ThisincludestheDMZ)

Page 20: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security ThisprecludeshavinganIoT,orInternetofThings

Page 21: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security ThisprecludeshavinganIoT,orInternetofThingsIdiocy

Page 22: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org

Compliance ≠ Security ThisprecludeshavinganIoT,orInternetofThings

Page 23: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Compliance ≠ Security

(But, we’re getting closer)

Page 24: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Questions? Comments? Rich Banta, Co-Owner & CISO, Lifeline Data Centers, LLC

Page 25: Compliance Security - Cyber Security Summit...Cyber Security Summit | October 23-25, 2017 | Minneapolis, MN | cybersecuritysummit.org Compliance ≠ Security NIST 800-53 R4 Control

Thank you for your time and interest! Rich Banta, Co-Owner & CISO, Lifeline Data Centers, LLC