15
Helping Leaders Make Informed Decisions IS LEADERSHIP PRESENTATION

CISM IS Leadership Presentation

Embed Size (px)

DESCRIPTION

Edited version of internal presentation on security risk management efforts.

Citation preview

Page 1: CISM IS Leadership Presentation

Helping Leaders Make Informed DecisionsIS LEADERSHIP PRESENTATION

Page 2: CISM IS Leadership Presentation

Agenda Review of CISM Background

Analysis Lifecycle

Current Analysis Products

Upcoming Products

Page 3: CISM IS Leadership Presentation

CISM Background

Page 4: CISM IS Leadership Presentation

Skill Sets Over 50 years of domain expertise

CIS/IA PhD, MBA, MSIM

20+ domain certifications

Average 30+ hours a month of outside outreach and training

Page 5: CISM IS Leadership Presentation

Analysis Lifecycle

Acquisition Storage and Processing Analysis Reporti

ng

Page 6: CISM IS Leadership Presentation

Acquisition Threat Intelligence

◦ REN-ISAC◦ NH-ISAC◦ VCDB◦ Subscription Services◦ Private Sources

Internal Data Sources◦ Orchestrate◦ Security Logs◦ Nessus◦ Interviews

Page 7: CISM IS Leadership Presentation

Storage and Processing SQL Server

NoSQL◦ MongoDB◦ Elasticsearch◦ Apache Pig (Hadoop)

PowerShell

Page 8: CISM IS Leadership Presentation

Analysis Simulation

◦ Rstats◦ Python

Page 9: CISM IS Leadership Presentation

Reporting Written Reports

◦ Compliance Analysis

Visualization◦ Tableau

Example Work Products◦ Policy◦ Audits◦ Security Findings◦ Data Loss Protection◦ Network Security Posture Analysis◦ Security Incident Management

Page 10: CISM IS Leadership Presentation

Current Analysis Products

Page 11: CISM IS Leadership Presentation

A Tale of Three Demonstrations1. Vulnerability Performance Management

2. PCI-DSS Compliance Tracking

3. Application Risk Overview

Page 12: CISM IS Leadership Presentation

Upcoming EffortsModelling Application Risk

Page 13: CISM IS Leadership Presentation

Application Risk Simulation

Which of the various options will provide the highest returns to the

safety, stability, and security of my application at the lowest cost?

Page 14: CISM IS Leadership Presentation

Project X Application Risk Simulation

Page 15: CISM IS Leadership Presentation

Questions? David F. Severski

Email

Phone