How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA,...

39
At It’s Heart today

description

This webinar was developed in response to new developments with PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA regs we reviewed important approaches to managing what I consider to be ground shaking changes with IT Security Processes, Capabilities, Communications, and Budgeting. The content focused on what our customers are getting from regulators and banks as the deleterious effects of IT Security events over the past 12 months start to percolate into the market. Topics : 1. How to Build Process Flows, Checklists, Reporting Structures, Assessment tools, to score IT Security risk for the CIO, CEO and Board. 2. How do you communicate risk across broad ranges of IT systems complexity accurately. 3. How to use a Scoreboard tool to communicate readiness of your IT Security Program from Tech staff, to CIO, to CEO and Board. 4. How do you balance IT Security risk and priorities so that decision makers can understand without losing them in the technical weeds. 5. How to simplify and manage your security architecture and design. 6. How to make managing security easily and simply when there is over lapping functionality? 7. How you can use these tools, processes, and risk scoring to build your IT Security Roadmap for 2015. 8. How to build a Data Governance and Risk communication plan for your IT Security portfolio.

Transcript of How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA,...

Page 1: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

At It’s Heart today

Page 2: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

IT Security & Risk Management

CEO

CIO

Happy Board

Managers

Technical

Do’ers

Page 3: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

IT Security & Risk Management

CEO

CIO

Happy Board

Managers

Technical

Do’ers

ENTERPRISE

RISK

Assessments

AUDITORS

Internal

Audit

Page 4: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

IT Security & Risk Management

CEO

CIO

Happy Board

Managers

Technical

Do’ers

MSP

Partners

Vendors

Consultants

Third

Parties

Cloud

Providors

ENTERPRISE

RISK

Assessments

AUDITORS

Internal

Audit

Page 5: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

IT Security & Risk Management

CEO

CIO

Happy Board

Managers

Technical

Do’ers

Page 6: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

What We Are Hearing

• From You• From Regulators

Page 7: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

What We Are HearingFrom You• CIO- “My Board and CEO still doesn’t care about IT security unless I can show them that loss if

they don’t do something.” The board and CEO of this public company are concerned about supply chain impact security concerns and what would happen if this were impacted.

• Director of IT – “The banks are pressing me for me for more IT Security details now. It used to be relatively easy to fill out but now it is hours and hour of work. I failed one line of the questionnaire. I was certain my answer was not a big deal, but it was. I don’t want to risk my companies business with these banks. Can you help me figure this out?” The pressure is mounting as credit card merchants and banks are going to pass the responsibilities down the food chain. They will be exposing the weakest link in the chain.

• CIO – “I really don’t have a problem talking to the CEO and board about justifying our IT Security spending, but I really do need better tools to present the IT Security Vision and Roadmap.” Essentially they trust her, but what if they could trust her plus really understand what IT Security spending is going towards.

• CIO – “I am looking for new and innovative approaches to presenting my IT security program to the Board. Sometimes they are so focused on whether they will pass the compliance audit that they lose the fact that we need great IT Technology security for a business of our size.”

Page 8: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

What We Are Hearing from You• I would like your opinion so I don’t overspend on my IT Security. • I have so many areas to secure and I have already spent quite a

bit on IT Security…. What do you think about it? Should I be concerned about these over lapping functions on systems?

• Strategy and architecture – I want to go this way and I am thinking of using these technologies what are your thoughts on my approach?

• Help me understand my current IT Security investments to see if they will pass an audit or some deep dive inspection.

• I have three main constituents that I need to sell my approach to: Auditors, CEO, and the Board. What is the best presentation approach?

Page 9: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

JP Morgan Chase

Page 10: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

StoryAn interesting story- this is not the most creative slide in the world I apologize, but I did mention that it’s a big project so we’re going to get the slides cleaned up at a different time – I was having coffee with the CEO of Unisys just recently, and he was explaining a story that he was at a security event and the ex-Mandiant CEO, or he might still be the CEO but I know that they were purchased and something’s going on with fireye, but he was talking and obviously many of you have listened to, I forget his first name, Mr. Mandiant talk. He asked the CEOs, ‘what do you want from your information security program?’ and they said I want the best. I want the best, best, best, best, just a real male ego type thing; I want to have a killer IT security program. Then when he (Mandiant) explained it, what’s needed, the CEOs dialed back their expectations and said, I just want to make sure I don’t end up on the cover of Wall Street Journal like the Target CEO. It’s an interesting story, the CEOs are sharing information now and it’s interesting to see that even though they want a very powerful program, there’s a reality that many of them are just concerned about their job security. There’s not only the Jamie Diamonds of the world but people that I’m seeing, that I talk to just having coffee and what they’re hearing as well. That’s what we’re hearing from you when we’re listening. What are we learning from regulators?

Page 11: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

What We Are Learning

From Regulators• FFIEC • NCUA• HIPAA /Omnibus• BAA (new mandates from Omnibus ruling)• PCI• EMV

Page 12: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

What We Are Learning - Themes

• IT Security is a Verb and not an Event• Risk is starting to flow downhill to the weakest link• Don’t just manage Compliance. Must have a great IT Security

program• Weak Passwords• Malware - APTs• 3rd party challenges • Manage the basics – Patching is not as easy as it might seem• Authentication challenges• Data Governance

Page 13: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

Proof Needed

• CEO and Boards and Auditors and Compliance• Want proof• What is your internal audit and reporting

process?

Page 15: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

FFIEC Webinar

• FFIEC members include: (http://www.ffiec.~ov)

• Board of Governors of the Federal Reserve• Consumer Financial Protection Bureau -CFPB• Federal Deposit Insurance Corporation -FDIC• National Credit Union Administration -NCUA• Office of the Comptroller of the Currency -OCC• State Liaison Committee

Page 16: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

What Every CEO Needs to Know about the Threats They Don’t See.

Executive Leadership of Cyber SecurityFinancial Institutions Examination Council

(FFIEC)Cybersecurity and Critical Infrastructure Working

Group

Page 17: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

Cyber Risk Management GOVERNANCE

Page 18: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

HIPAA – old rule• http://www.hhs.gov/ohrp/sachrp/mtgings/2013%20March%20Mtg/hipaa/hitechomnibus_finalrule.pdf• Page 13

Page 19: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

Omnibus HIPAA – New Rule• http://www.hhs.gov/ohrp/sachrp/mtgings/2013%20March%20Mtg/hipaa/hitechomnibus_finalrule.pdf• Page 14

Page 20: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

EMV

• New Tech Standard• Oct 2015 deadline• Liability for fraud will flow/shift to whichever

party has the lesser technology

Page 21: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

NCUA

• Cost breach• http://www.ncuareport.org/ncuareport/augus

t_2014#pg4• Top 10 things credit union auditors look for

Page 22: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

IT Security & Risk Management FLOW

CEO

CIO

Happy Board

Managers

Technical

Do’ersChecklists

CIO Scoreboard

CEO/Board

Page 23: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

IT Security System Management Checklist

Page 24: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

Admin Level to CIO Level40 Security Items

Page 25: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

IT Security & Risk Management FLOW

CEO

Happy Board

Security /Infrastructure/DRBy Sector/Category

40 Security Items

Investment Based on Risk

Page 26: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

Big PictureWhat is Happening

“Roughly 170 Quadrillion Computer chips wired into aMega-scale computing platformThe total number of transistorsIn this global network is now approximately the same # of neurons of the human brain”What Technology Wants – Kevin Kelly

Page 27: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

Complexity

Page 28: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

Interesting – The Word Privacy

Page 29: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

JWT – World Trends 2014 and Beyond

Page 30: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

JWT – World Trends 2014 and Beyond

Page 31: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

JWT – World Trends 2014 and Beyond

Page 32: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

JWT – World Trends 2014 and Beyond

Page 33: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

WE SIT IN THE MIDDLE AND MANAGE COMPLEXITY

Page 34: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

So What is a Security Leader Today?

Page 35: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

We Are Supposed to be Afraid Right?

Page 36: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

Changing the storyAdult Conversations….

Page 6Assume the BreachAssuming the breach requires a shiftOf mindset from prevention alone toContainment after the breach

Assumption of a breach requires a maturing of defenses to meet this realityAnd shifts the focus from ‘if’ to ‘when’

Page 37: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

What about changing the story or the way we talk about IT Security?

I like words like relentlessly proactive

Versus playing back on our heals

“IT Pros lack Confidence in protecting themselves”Computer weekly

Page 38: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

Show Me The Money

• Cuba Gooding• Tom Cruise

Page 39: How to Communicate the Actual Readiness of your IT Security Program for PCI 3.0, Omnibus HIPAA, BAAs, New Bank Regs, NCUA

Ponemon

• Cost of Loss