24
CISOs are from Mars CIOs are from Venus [email protected] [email protected] @bcaplin http://about.me/barrycaplin http://securityandcoffee.blogspot.com Barry Caplin Chief Information Security Official Fairview Health Services

CISOs are from Mars, CIOs are from Venus

Embed Size (px)

DESCRIPTION

Most organizations have a CIO; many have a CISO. These key leadership positions often approach solutions differently and have different motivations. The CIO must deliver IT, automation, innovation and efficiency. The CISO is tasked with assuring adherence to security frameworks and regulatory standards, and protecting against, and responding to, vulnerabilities and incidents. These mandates can conflict. And often the CISO reports to the CIO. We will take a light-hearted look at questions including: What are the issues?; Are CISOs and CIOs from different planets?; Can we align to meet critical business needs, deliver value and protect the organization?

Citation preview

Page 1: CISOs are from Mars, CIOs are from Venus

CISOs are from Mars

CIOs are from Venus

[email protected]

[email protected] @bcaplin

http://about.me/barrycaplin

http://securityandcoffee.blogspot.com

Barry CaplinChief Information Security

OfficialFairview Health Services

Page 2: CISOs are from Mars, CIOs are from Venus

http://about.me/barrycaplin

securityandcoffee.blogspot.com

@bcaplin

Page 3: CISOs are from Mars, CIOs are from Venus

3

Different worlds

Page 4: CISOs are from Mars, CIOs are from Venus

The Sword of Anti-Virus

4

Page 5: CISOs are from Mars, CIOs are from Venus

The Light Saber of Endpoint Protection

5

Page 6: CISOs are from Mars, CIOs are from Venus

The Shield of Next-Gen Firewall

6

Next Gen

Firewall

Page 7: CISOs are from Mars, CIOs are from Venus

The Scepter of IT Budget

7

Page 8: CISOs are from Mars, CIOs are from Venus

The Cloud of…

8

Page 9: CISOs are from Mars, CIOs are from Venus

Different worlds – reporting structure

CISO reports to CIO

• Security overruled?

CISO reports to {CRO, CEO, CxO}

• Visibility into IT?

• Budget?

9

Page 10: CISOs are from Mars, CIOs are from Venus

Different languages

10

Page 11: CISOs are from Mars, CIOs are from Venus

• Nation States

• Hacktivists

Threats

• Malicious hackers

• Malware

11

• Over-time; over-budget

• Outsourcing

Page 12: CISOs are from Mars, CIOs are from Venus

Confidentiality

• Protection of Data

• Minimum Necessary

12

What happens in the boardroom, stays in the boardroom

Page 13: CISOs are from Mars, CIOs are from Venus

• Coherence of financial data

Integrity

• Data in correlates with data out

• Chain of custody of log and forensic data

13

• Transparency

• Coherence of financial data

Page 14: CISOs are from Mars, CIOs are from Venus

Risk

• Probability/Impact of Threats

• Data Breach

14

• Not meeting business needs

• Data Breach

Page 15: CISOs are from Mars, CIOs are from Venus

IO

15

CIO

C

onsidering

nterim

pportunities

Page 16: CISOs are from Mars, CIOs are from Venus

OSCI

16

CISOareers

veroon

Page 17: CISOs are from Mars, CIOs are from Venus
Page 18: CISOs are from Mars, CIOs are from Venus

Meet in the middle

18

Page 19: CISOs are from Mars, CIOs are from Venus

Unite Against theCommon Enemy

19

Page 20: CISOs are from Mars, CIOs are from Venus
Page 21: CISOs are from Mars, CIOs are from Venus

Key Opportunities

• Mobile/BYOD/Cloud

• “V”OI

• Management – Vendor; Configuration; Incident; Risk

• Lifecycle/SDLC

• Keep the auditors happy

• Keep the board happy

21

Page 22: CISOs are from Mars, CIOs are from Venus

Good Things are sure to follow

22

Page 23: CISOs are from Mars, CIOs are from Venus
Page 24: CISOs are from Mars, CIOs are from Venus

http://about.me/barrycaplin

securityandcoffee.blogspot.com

@bcaplin