Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases...

26
ConSec'06 1 Information Assurance Information Assurance Combining Analyses William Tompkins, CISSP, CBCP September 2006

Transcript of Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases...

Page 1: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 1

Information AssuranceInformation AssuranceCombining Analyses

William Tompkins, CISSP, CBCPSeptember 2006

Page 2: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 2

William Tompkins is Information Security Officer at Teacher Retirement System of Texas. He has more than 23 years of technical, managerial and consulting experience in information technology and more than 15 in information security. He is a Certified Information Systems Security Professional and a Certified Business Continuity Professional.

He was the Manager of Texas Department of Transportation’s Information Security Section and Project Manager of the Information SecurityProgram which was selected as Computer Security Program of the Year Computer Security Program of the Year 19941994 by CSI (Computer Security Institute).

Mr. Tompkins holds two Bachelor of Science degrees, Psychology and Computer Information Science, from Troy State University in Alabama and Certification in Risk Management from University of Texas at Austin Division of Continuing Education.

William TompkinsWilliam TompkinsWilliam Tompkins

Page 3: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 3

By the end of this sessionBy the end of this sessionyou will be able to you will be able to ……

Describe assessment differences and similaritiesIdentify opportunities to combine SRA & BIA processes

Page 4: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 4

AgendaAgendaBasic phasesLeverage resourcesSimilaritiesDifferencesBusiness priorities

Page 5: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 5

PhasesPhases

AssessmentDevelopmentImplementationMaintenance/Testing

Page 6: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 6

Define/UpdateDefine/UpdateEnvironment & AssetsEnvironment & Assets

Impact/RiskImpact/RiskAnalysisAnalysis

Risk ManagementRisk Management

Policy, Guidelines,Policy, Guidelines,Standards & ProceduresStandards & Procedures

Design &Design &ImplementationImplementation

AdministrationAdministration

Monitoring,Monitoring,Testing & AuditsTesting & Audits

Page 7: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 7

AgendaAgendaBasic phasesLeverage resourcesSimilaritiesDifferencesBusiness priorities

Page 8: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 8

Leverage ResourcesLeverage Resources

Idea of ‘new’ analysisCombining identical tasksLarger _and_ smaller

Page 9: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 9

Business Impact Business Impact AssessmentAssessment

To identify impacts of losing organizational resources

InitialOver a period

of time

Page 10: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 10

Security Risk AnalysisSecurity Risk Analysis

ThreatsVulnerabilityImpactsCountermeasures

Page 11: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 11

AgendaAgendaBasic phasesLeverage resourcesSimilaritiesDifferencesBusiness priorities

Page 12: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 12

SimilaritiesSimilaritiesVulnerabilitiesLoss potentialRisk reduction/mitigationInformation sourcesOutside expertiseControls & safeguardsRaises awarenessProject Mngt & questionnaires

Page 13: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 13

AgendaAgendaBasic phasesLeverage resourcesSimilaritiesDifferencesBusiness priorities

Page 14: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

Security Risk Analysis(SRA)

“Hard” decisions

Security Risk Analysis(SRA)

“Hard” decisions

Business Impact Assessment

(BIA)

“Softer” decisions

Business Impact Assessment

(BIA)

“Softer” decisions

Conceptual Conceptual DifferencesDifferences

Page 15: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

To what lengths do we go to protect information resources?

How long can we tolerate not having access to IR?

DifferencesDifferences

SRASRA BIABIA

Page 16: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

Weighs the losses if IR in the absence of security controls against the cost of implementing the control.

Weighs the intolerable effects of the loss to the organization against the cost of reacting to the loss over time.

DifferencesDifferences

SRASRA BIABIA

Page 17: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

Evaluates vulnerabilities to an asset and probabilities of occurrence.

Evaluates the effect of an event over a period of time.

DifferencesDifferences

SRASRA BIABIA

Page 18: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

Specific threats and causes.

Cause of threat is irrelevant.

DifferencesDifferences

SRASRA BIABIA

Page 19: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

Protective and countermeasures.

Recovery strategy

DifferencesDifferences

SRASRA BIABIA

Page 20: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

How can we be proactive?

How are we going to react and recover?

DifferencesDifferences

SRASRA BIABIA

Page 21: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

Prevents and protects as much as is economical.

Provides information for an efficient and effective recovery plan.

DifferencesDifferences

SRASRA BIABIA

Page 22: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 22

AgendaAgendaBasic phasesLeverage resourcesSimilaritiesDifferencesBusiness priorities

Page 23: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 23

Business prioritiesBusiness priorities(BIA) business process focused -vs-(SRA) focus on individual applications ?Management review…re-prioritze‘New’ employee interview Buy-In

Senior managementBusiness process owners

Page 24: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 24

RememberRememberBe flexibleScopeCommunicationsResources

Page 25: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 25

Q U E S T I O N S ?Q U E S T I O N S ?Q U E S T I O N S ?

Page 26: Tompkins Information Assurance€¦ · SRA & BIA processes. ConSec'06 4 Agenda ¾Basic phases ¾Leverage resources ¾Similarities ¾Differences ¾Business priorities. ConSec'06 5

ConSec'06 26

Thank YouThank YouThank You

William A. Tompkins512 – 542 - 6787

[email protected]

William A. Tompkins512 – 542 - 6787

[email protected]

ConSec ‘06ConSec ConSec ‘‘0606