Showing posts with label risk. Show all posts
Showing posts with label risk. Show all posts

Saturday, November 11, 2017

Report from SecureWorld Seattle - Being an Effective CISO Speech

This past week I attended the Seattle edition of SecureWorld.  The first keynote speaker was Mr. Demetrios Lazarikos (aka Laz) (laz@blue-lava.net) and his talk really hit home to me as a security practitioner and former CISO.  He offered some excellent advice regarding the characteristics of a cybersecurity leader, where they should report in the organizational structure, and offered some succinct recommendations to be considered.

So, this is a trip report of sorts but I also thought his comments were "dead on" and I heartily endorse his opinions.

Characteristics of Today's Cyber Leader

His key points about today's successful cybersecurity leader included:

  • Curious and a life-learner
  • Critical thinker
  • Patient and able to influence
  • Understand the value of the cybersecurity  program
  • Understand and can articulate the risks to revenue and sales enablement (It's the Money!)
  • Works closely with IT audit and regulators
  • Is in it for the PASSION
  • Never lets a cybersecurity opportunity go to waste -- EVER!
  • Tries to remain vendor agnostic

Organizational Reporting

Laz explicitly said the "CISO NEEDS TO REPORT TO THE CEO!"

I heartily agree!  The CISO is a very, very key cog in the gears of the organization and without an unencumbered communication to the chief decision-maker, the CISO's hands are tied (which I know from experience).

Talking to the Board of Directors

Laz again offered some terrific advice on ways to report and communicate to the Board of Directors.  Because you usually only have 10-15 minutes for your discussion, his suggestions included:

  • Ensure the reports are in terms THEY understand.  Not technical gobbly-gook.
  • Be streamlined
  • Quantify risk and loss exposure in dollars - not bits/bytes
  • Provide specific recommendations for moving ahead and protecting the enterprise
  • Emphasize the risk to revenue and risk to the brand -- not what the best firewall is

Recommendations

In closing, Laz offered some terrific recommendations for consideration by current and future CISOs:

  • Incorporate cybersecurity in all areas of your business -- from the individual employee to the CEO; from the mundane janitorial services to the strategic planning
  • Be an enabler -- always consider risk to revenue and sales enablement
  • Meet and know the CEO --- don't meet them for the first time during a data breach
  • Understand and report to the business in "business terminology"
  • Collaborate, Collaborate, Collaborate!
Overall, Laz's speech was one I could understand and equate to due to my time in the trenches and my own experience.  Thanks to SecureWorld for inviting Laz to speak! 

### ###

Monday, January 4, 2016

Planning for Community Infrastructure Resilience - NIST Guidance


In 2015 the US National Institute of Standards and Technology (NIST)  began a process to produce guidance on approaches to aid communities in improving their resilience to prevailing natural and man made disasters that could affect their jurisdiction.  NIST began to produce various guides to offer some processes for community planners to follow including understanding and assessing their current risks as well as develop plans to implement to improve their resilience.  Using the "Guides" the community planners can better integrate their resilience efforts into their economic development, zoning, and other local planning activities impacting buildings, public utilities, and other infrastructure systems.



Currently there are three NIST Guide documents to be summarized below in this Blog:


Volume 1


The first document produced by NIST is Community Resilience Planning Guide for Buildings and Infrastructure Systems Volume 1.   (11MB Download, 125 pages).  Volume I describes the methodology and has an example illustrating the planning process for the fictional town of Riverbend, USA.



As part of this methodology, Volume 1 includes a "Six-Step" Process to Planning for Community Resilience." (Shown Below).  Although the graphic is offering an elementary project planning structure, the contents and discussion of Volume 1 on how to approach the challenges of assessing and improving the resilience of the community is useful.



Volume 1 continues to provide the basis for this approach and also ensures that the reader does not fall into the trap of looking exclusively at "THINGS" such as bridges, roads, public works facilities, but instead helps the reader realize that the THINGS are based on and affected by the social aspects.  A particularly good graphic showing this "cause and effect" so to speak is below:


Volume II


Volume II of this Guide provides details for the planners on issues ranging from Understanding and Characterizing the Social Community (Chapter 10) to Dependencies and Cascading Effects to detailed information for various Critical Infrastructure and Key Resources (CIKR) including:

  • Chapter 12 - Buildings
  • Chapter 13 - Transportation Systems
  • Chapter 14 - Energy Systems
  • Chapter 15 - Communications Systems
  • Chapter 16 - Water and Wastewater Systems
Each CIKR sector reviewed includes parallel analysis to include:
  • Introduction to the Sector
  • Infrastructure, Functions
  • Performance Goals for the Sector
  • Regulatory Environment
  • Standards and Codes for New Construction and Existing Construction
  • Strategies for Implementing Plans for Community Resilience
  • References for the Sector
Finally, Chapter 17 includes a discussion on "Community Resilience Metrics" to include such metrics as:
  • Time to Recover Function
  • Economic Vitality
  • Social Well-Being
  • Environmental Resilience
  • Hybrid Metrics

Economic Guide



The third Guide just issued in this series is focused on Economics and "Economic Decision Making."   Per the NIST announcement the Economic Guide "... provides a standard economic methodology for evaluating investment decisions aimed to improve the ability of communities to adapt to, withstand, and quickly recover from disasters."  The report is intended to frame the economic decision process by identifying and comparing the relevant present and future streams of costs and benefits with benefits realized through costs savings and damage loss avoidance.

As observed in the report benefits are primarily determined as the improvement in performance during a hazard event over the status quo, i.e., those obtained directly or indirectly by implementation of the new resilience strategy.

And for cost analysis, costs include all costs, including negative effects of implementing a resilience action. That specifically includes the initial costs, operation and maintenance costs, end-of-life costs, and replacement costs. In addition, any non-economic costs (e.g., deaths and injuries) and negative externalities need to be taken into account.

Who Are Served by These Reports?

These reports appear to be excellent resources for city, county, regional and national planners -- especially those examining disaster recovery and Continuity of Operations (COOP) policies, procedures and budgets.  Also, students of infrastructure management should find these reports to be very useful -- not only for their content but also for the references cited in the document and for each analyzed critical infrastructure in Volume II.

###


Monday, August 10, 2015

Pervasive Sensing and Risk Implications

For the past four years I have been talking one class a quarter towards a Masters in Infrastructure Planning and Management offered by the College of Built Environments at the University of Washington in Seattle.

This program is very unique, the classes are entirely online, and I've not seen one like it in my global travels.  It is a fantastic program covering a broad range of critical infrastructure issues (e.g., transportation, water systems, emergency management, etc.) and also offers supporting training in areas such as capital budgeting/finance for government.  Overall I was very impressed with the faculty and level of education.

Well, the end is in sight!  The final assignment due this week is to submit the final Capstone and also prepare a summary presentation on YouTube the  Capstone contents (in 10 minutes!).

The title of my Capstone is: Pervasive Sensing and Industrial Control System Risk Implications.

https://www.youtube.com/watch?v=yyQbUBIVWIo


The YouTube link for the 10-minute narrated PowerPoint is at:  https://www.youtube.com/watch?v=yyQbUBIVWIo

I hope you will find this presentation informative and though-provoking.

Lastly, apologies to those of you made aware of this presentation via a separate Twitter and LinkedIN announcement a few days ago.

Cheers!

###