24
The Strengths & Limitations of Risk Management Standards TOG Baltimore, July 20, 2015 Ben Tomhave

The Strengths & Limitations of Risk Management Standards

Embed Size (px)

Citation preview

The Strengths & Limitations of Risk Management Standards

TOG Baltimore, July 20, 2015Ben Tomhave

Let’s be frank…

Frank Gehry responds to critics during a press conference in Oviedo, SpainPhoto via: Faro de Vigohttps://news.artnet.com/in-brief/frank-gehry-gives-spanish-critics-the-finger-143262

Standards, while useful, are no panacea.

The strength of standards is that they provide a reasonable,

common starting point.

Key Limitations

By virtue of being generalized to a relatively broad audience…

1. Standards, and their associated frameworks, require customization and are rarely directly implementable.

2. As a result, while standards do provide the starting point for an effort, they still require expending resources to achieve a desirable result.

What are we talking about?

• Standards related to cybersecurity and risk management. Not protocols.

• Typically large, general-purpose works.• Examples:– ISACA’s COBIT 5– ISO 31000 and 27000 series– NIST SP/FIPS/etc.– Standards from orgs like TOG (e.g, Open FAIR)

LET’S DRILL-DOWN…

ISACA’s COBIT 5

COBIT 5 Details…

• The primary standard is hundreds of pages long, and overall is a collection of several documents.

• “COBIT 5 for Risk” alone is 244 pages.• This is incredibly unwieldy!

COBIT 5 Risk Response Workflow

ISO 31000

ISO 27005

NIST RMF

NIST SP800-39“Managing Information Security Risk”

NIST SP800-39“Managing Information Security Risk”

NIST SP800-30“Guide for Conducting Risk Assessments”

NIST SP800-30“Guide for Conducting Risk Assessments”

NIST SP800-30 (3 of 3)“Guide for Conducting Risk Assessments”

Lessons from NIST?

• There’s a LOT to the standards.• There’s a lot of misunderstanding, too.• You still need to do “stuff”…• In fact, if under FISMA, you have a LOT to do.• In private industry, take time to understand.

TOG’s OpenFAIR

Closing thoughts

• Standards are useful, but no panacea.• Standards can reduce some planning efforts,

but still require work.• Semper Gumby!

Bonus Point!

Right-Sizing: Just how much do you need??

Is…

Data Value + System Value + Resilience/Defensibility

…generally adequate?

Q & A?

THANK YOU!

Ben Tomhave @falconsview [email protected]