Module1: Policy Overview © 2025 Butkovic 2 Agenda Agenda: ▪ Introductions ▪ Review of Syllabus ▪ Purpose of Policy ▪ Types of Policy ▪ Governance © 2025 Butkovic 3 Introductions-Matt Matthew Butkovic, CISSP, CISA, AIAA • Technical Director-Cyber Risk and Resilience (CERT Division-Software Engineering Institute-CMU-Carnegie Mellon University) • Adjunct Faculty-Heinz College (Policy and Governance) • Lecturer- CMU Institute for Strategy and Technology (CMIST) • Instructor-Heinz College CISO, CIO, and CRO Executive Education Certificate Program • Instructor- National Association of Corporate Directors • Private Industry Prior to CMU (Banking and Manufacturing) © 2025 Butkovic 4 Introductions-John John Haller, JD • Technical Manager-Cyber Assurance (CERT DivisionSoftware Engineering) • Financial industry - Information Security Governance, Policy Management and Enforcement, Cybersecurity Maturity and Program Assessment, Risk Management • U.S. Federal Law Enforcement • United States Army © 2025 Butkovic 5 Carnegie Mellon University | CERT Division • Software Engineering Institute (SEI) • Federally funded research and development center based at Carnegie Mellon University • Basic and applied research in partnership with government and private organizations • Helps organizations improve their development, operation, & management of software-intensive and networked systems • CERT Division – Anticipating and solving our nation’s cybersecurity challenges • Largest technical program at the SEI • Focused on information and cybersecurity, risk management, operational resilience, insider threat, governance, and security metrics © 2025 Butkovic 6 Our Objectives • Teach the fundamentals of policy and governance • Change you perception of the topics (hopefully) • Supply you with something useful (e.g., interview content) • Encourage critical thinking skills • Learn from the students • Have some fun © 2025 Butkovic 7 Introductions-You • Name • Career Objectives • Course Expectations • Fun Fact © 2025 Butkovic 8 Review of Syllabus • Writing Assignments • Class Participation • Final Exam © 2025 Butkovic 9 Syllabus Information-Grading I © 2025 Butkovic 10 Syllabus Information-Grading II © 2025 Butkovic 11 Important Dates: Assignments Individual Written Assignment Due Dates: • September 15th =Assignment 1 • September 22nd =Assignment 2 • November 06th = Assignment 3 © 2025 Butkovic 12 Important Dates: Final Exam Exam Date: • October 7th (In-Class) Format: • Multiple choice • Easy if you pay attention to the lectures…honestly © 2025 Butkovic 13 Assignment Requirements Format and Grading of Written Assignments: Writing assignments are structured to provide students with an opportunity to do research, apply critical thinking, and practice writing skills. Students are expected to submit papers that are well formatted, free of grammatical and spelling errors, and containing independent thought. For paper topics see the Writing Assignment document. Paper requirements: • MS Word document or PDF • Cover sheet with title and author name • Between 1000 and the specified limit word count • 1 inch margins; double spaced; 11-point font • Page numbers • Citations in APA format (http://www.apastyle.org/learn/tutorials/basics-tutorial.aspx) Grading rubric will vary based on topic, but in general: • Format and structure (grammar and spelling): 10% • Application of course concepts: 40% • Critical thinking and independent thought: 40% • References: 10% As a graduate level course at Carnegie Mellon University, we expect a high level of performance. If you feel that you need assistance with writing, please use the free services provided by the university at the Global Communications Center (www.cmu.edu/gcc) © 2025 Butkovic 14 Assignment Requirements-II ➢ Late assignments will not be accepted. ➢ One week after graded to discuss. No adjustments at the end of course. ➢ The paper shouldn’t be a list of bullets ➢Please include a cover sheet with your name, title of paper, course number, and your Andrew ID. © 2025 Butkovic 15 Use of Generative AI-This Course We expect that all work students submit for this course will be their own. We have carefully designed all assignments and class activities to support your learning. Doing your own work, without human or artificial intelligence assistance, is best for your achievement of the learning objectives in this course. In instances when collaborative work is assigned, We expect for the submitted work to list all team members who participated. We specifically forbid the use of ChatGPT or any other generative artificial intelligence (AI) tools at all stages of the work process, including brainstorming. Deviations from these guidelines will be considered violations of CMU’s academic integrity policy. Note that expectations for “plagiarism, cheating, and acceptable assistance” on student work may vary across your courses and instructors. Please ask us if you have questions regarding what is permissible and not for a particular course or assignment. © 2025 Butkovic 16 The Silver Thread of Cyber…. © 2025 Butkovic 17 Current State of Cybersecurity -1 Source: Verizon Source: Darktrace © 2025 Butkovic 18 Current State of Cybersecurity -2 • Phishing, malware, and social engineering are leading attack vectors • Attacks trends: ransomware and crypto-mining malware • 76% of breaches were financially motivated • Average time to detect a breach is 146 days • 44.2% of all disclosed vulnerabilities are found in applications other than web browsers and operating systems • More than half of data breaches blamed on negligent employee actions, but 1/3 cannot identify root cause Source(s): ISACA, Ponemon, FireEye, Gartner, and Verizon © 2025 Butkovic 19 Current State of Cybersecurity -3 • At 287 days, the entertainment industry takes the most time to detect a data breach in comparison to other industries-IBM • At 103 days, the healthcare industry takes the most time to contain a data breach compared to other industriesIBM • The average time to identify a breach across all industries is 197 days-IBM • The average time to contain a breach across all industries if 69 days-IBM Source: www.pwc.com © 2025 Butkovic 20 Current State of Cybersecurity -4 • Phishing, malware, and social engineering are leading attack vectors • Attacks trends: ransomware and crypto-mining malware • 76% of breaches were financially motivated • Average time to detect a breach is 146 days • 44.2% of all disclosed vulnerabilities are found in applications other than web browsers and operating systems • More than half of data breaches blamed on negligent employee actions, but 1/3 cannot identify root cause Source(s): ISACA, Ponemon, FireEye, Gartner, and Verizon © 2025 Butkovic 21 Critical Infrastructure Under Attack © 2025 Butkovic 22 LLMs…Beatlemania (2024) © 2025 Butkovic 23 AI For Everyone in 2025 © 2025 Butkovic 24 Why Information Security Policy Matters © 2025 Butkovic 25 Why Information Security Policy Matters-2 © 2025 Butkovic 26 Why Information Security Policy Matters-5 Cost of Consequences Amount Direct expenses related to breach $61,000,000 Less: Direct insurance ($44,000,000) Salary to ousted CEO $55,000,000 Indirect cost of reissuing credit cards (Target may reimburse this) $200,000,000 Indirect losses per stolen card @ $26.85/card * 3,000,000 cards $805,500,000 Potential Cost of Consequences $1,077,500,000 27 Why Information Security Policy Matters-6 28 Break 29 What is an Information Security Policy? “Information security policies are written instructions, provided by management, to inform employees and others in the workplace of the proper behavior regarding the use of information and information assets” -Whitman and Mattord 2014 © 2025 Butkovic 30 What is an Information Security Policy?-II What: written instructions From: provided by management To: to inform employees and others in the workplace About: proper behavior regarding the use of information and information assets © 2025 Butkovic 31 A Policy Must Be…. ▪ Properly administered and supported ▪ Able to stand up in court if challenged ▪ Never conflict with law. © 2025 Butkovic 32 Bullseye Model Applications Credit: Whitman and Mattord © 2025 Butkovic 33 Policies, Standards, and Practices Policies are sanctioned by senior management Policies Applications Standards are built on sound policy and carry the weight of policy Standards Practices, procedures, and guidelines include detailed steps required to meet the requirements of the standard Practices Procedures Guidelines © 2025 Butkovic 34 Policies, Standards, and Practices-II Policy -Formal statement of management philosophy Standard -Detailed statement explain what must be done to comply with policy © 2025 Butkovic 35 Policies, Standards, and Practices-III Practices, Procedures, and Guidelines -Explains how employees are to comply with policy © 2025 Butkovic 36 Strategy • Strategy is a special plan made to achieve an organization’s goals and objectives, gain customer’s trust, attain competitive advantage and to acquire a market position. It is a combination of well thought intent and actions which lead to the organization towards its desired position or destination. It is a unified and integrated plan made to achieve the basic objectives of the enterprise like: • Effectiveness • Handling events and problems • Taking advantage of opportunities • Full resource utilization • Coping with threats © 2025 Butkovic 37 Policy • • Policy is a set of rules made for rational decision-making that can lead to progress in strategic goals Policies are subordinate to Strategy Strategies can be modified as per the situation, so they are dynamic in nature. Conversely, Policies are uniform in nature, however relaxations can be made for unexpected situations. © 2025 Butkovic 38 Basic Types of InfoSec Policies ▪ Enterprise information security policy (EISP) ▪ Issue-specific security policies (ISSP) ▪ System-specific security policies (SysSP) © 2025 Butkovic 39 Basic Types of InfoSec Policies-II ▪ National Institute of Standards and Technology (NIST) defined the three basic types of information security policies ▪ Special Publication 800-14 “Generally Accepted Principles and Practices for Securing Information Technology Systems” ▪ Published in 1996 (Marianne Swanson and Barbara Guttman) © 2025 Butkovic 40 Enterprise Information Security Policy ▪ Also known as “IT security policy”, “security program policy”, and “general security policy” ▪ Establishes management intent and tone ▪ Shapes the philosophy of information security in the organization ▪ Should not contradict the organizational mission statement © 2025 Butkovic 41 Enterprise Information Security Policy-II Standard Elements of an EISP: ▪ Overview of security philosophy ▪ Description of information security organization and roles ▪ Assigned shared responsibilities for information security ▪ Assigned responsibilities for information security by role © 2025 Butkovic 42 EISP Example-I © 2025 Butkovic 43 EISP Example-II © 2025 Butkovic 44 Issue-Specific Security Policy ▪ Sets expectations about how technology should be used ▪ Documents how technology is controlled and establishes authority for controls ▪ Indemnifies the organization against the liability for an employee's inappropriate or illegal use of technology ▪ A good faith effort by the organization to prevent inappropriate use of technology © 2025 Butkovic 45 Issue-Specific Information Security Policy-II Standard Elements of an ISSP: ▪ Statement of purpose ▪ Authorized uses ▪ Prohibited uses ▪ Systems Management ▪ Violations of policy ▪ Policy review and modifications ▪ Limitations of liability © 2025 Butkovic 46 ISSP Example-I © 2025 Butkovic 47 ISSP Example-II © 2025 Butkovic 48 System-Specific Security Policy ▪ Two types of SysSPs: ➢ Managerial guidance ➢ Technical specification ▪ Often look and feel similar to procedures ▪ Not intended for technology end-users ▪ Must be detailed to be useful © 2025 Butkovic 49 SysSP Example-1 © 2025 Butkovic 50 SysSP Example-2 © 2025 Butkovic 51 Module 1-B: Governance Overview What is Governance? The word “governance” came from the Latin verb “gubernare,” or more originally from the Greek word “kubernaein,” which means “to steer.” Basing on its etymology, governance refers to the manner of steering or governing, or of directing and controlling, a group of people or a state. The Executive Office for Administration and Finance Governance is commonly defined as the exercise of power or authority by political leaders for the well-being of their country’s citizens or subjects. © 2025 Butkovic 53 What is IT Governance? “IT governance (ITG) is defined as the processes that ensure the effective and efficient use of IT in enabling an organization to achieve its goals. IT demand governance (ITDG—what IT should work on) is the process by which organizations ensure the effective evaluation, selection, prioritization, and funding of competing IT investments; oversee their implementation; and extract (measurable) business The Executive Office for Administration and Finance benefits. ITDG is a business investment decision-making and oversight process, and it is a business management responsibility. IT supply-side governance (ITSG—how IT should do what it does) is concerned with ensuring that the IT organization operates in an effective, efficient and compliant fashion, and it is primarily a CIO responsibility” Gartner © 2025 Butkovic 54 What is InfoSec Governance? “Information security governance can be defined as the process of establishing and maintaining a framework and supporting management structure and processes to provide assurance that information security strategies are aligned with and support business objectives, are consistent with applicable laws and regulations through adherence to policies and internal controls, and provide assignment of responsibility, all in an effort to manage risk." NIST SP 800-100 © 2025 Butkovic 55 The Importance of Infosec Governance Objective of information security • Protect the confidentiality, integrity and availability (CIA) of information, within reason! Effective information security governance offers many benefits: • Demonstrates “due care” to mitigate potential civil and legal liability • Ensures policy compliance • Lowers risks to defined and acceptable levels • Improves customer trust • Protects the organization’s reputation • Provides accountability during critical business operations © 2025 Butkovic 56 Who is Responsible for Governance? Executive-level management sets the tone and should take an active interest in cybersecurity. • All stakeholders, both internal and external, need to be moving in the same direction. Culture is key in helping an organization become focused on cybersecurity. • A cybersecurity-focused culture will help an organization recover from a cybersecurity incident. © 2025 Butkovic 57 Who is Responsible for Governance?-2 Board of Director responsibilities include: • Providing a level of oversight for the ongoing cybersecurity activities • Establishing the highest-level requirements and policies for risk management and compliance • Selecting and/or approving the organization’s auditors, reviewing findings and concerns, and ensuring that the organization’s management team addresses these issues in a timely manner • Establishing an ongoing means of visibility into the organization’s cybersecurity and risk management status © 2025 Butkovic 58 Four Essential Practices for Directors • Place information security of the board’s agenda. • Identify information security leaders, hold them accountable, and ensure support for them. • Ensure the effectiveness of the corporate information security policy through review and approval. • Assign information security to a key committee and ensure adequate support for the committee. National Association of Corporate Directors (NACD) © 2025 Butkovic 59 Who is Responsible for Governance?-3 Senior Management should have a commitment to • Treat cybersecurity as a critical business issue and create a positive environment regarding security • Demonstrate to third parties that the organization deals with cybersecurity in a professional manner • Apply fundamental principles such as — Assuming ultimate responsibility for cybersecurity — Implementing controls that are proportionate to risk — Achieving accountability © 2025 Butkovic 60 How It Fits Together The Executive Office for Administration and Finance ISACA © 2025 Butkovic 61 Cybersecurity Governance Goals 1.Strategic alignment 2. Risk management 3. Value delivery 4. Resource management 5. Performance management 6. Assurance integration Information Technology Governance Institute (ITGI) © 2025 Butkovic 62 1. Strategic Alignment Aligning cybersecurity with business strategy to support organizational objectives, such as: • Security requirements driven by enterprise objectives — Clearly defined to guide what must be done and how to measure it • Security solutions fit the enterprise — Take into account the culture, governance style, technology and structure of the organization • Investment in information security — Aligned with the enterprise operations strategy and risk management strategy © 2025 Butkovic 63 2. Risk Management Executing appropriate measures to mitigate risks and reduce potential impacts on information resources to an acceptable level, such as • Collective understanding of the organization’s threat, vulnerability, and risk profile • Understanding of risk exposure and potential consequences of compromise • Awareness of risk management priorities based on potential consequences • Risk mitigation sufficient to achieve acceptable consequences from residual risk • Risk acceptance/deference based on an understanding of the potential consequences of residual risk © 2025 Butkovic 64 3. Value Delivery Optimizing security investments in support of business objectives, such as • A standard set of security practices, i.e., baseline security requirements following adequate and sufficient practices proportionate to risk • A properly prioritized and distributed effort to areas with the greatest impact and business benefit • Institutionalized and commoditized standards-based solutions • Complete solutions, covering organization and processes with technology based on an understanding of the end-to-end business of the organization • A continuous improvement culture based on the understanding that security is a process, not an event © 2025 Butkovic 65 4. Resource Management Using information security knowledge and infrastructure efficiently and effectively to • Ensure that knowledge is captured and available • Document security processes and practices • Develop security architecture(s) to define and utilize infrastructure resources efficiently © 2025 Butkovic 66 5. Performance Management Monitoring and reporting on information security processes to ensure that objectives are achieved, including: • A defined, agreed-upon and meaningful set of metrics properly aligned with strategic objectives • Measurement process that helps identify shortcomings and provides feedback on progress made resolving issues • Independent assurance provided by external assessments and audits © 2025 Butkovic 67 6. Assurance Integration Reviewing all relevant security controls and strategies to ensure that processes operate as intended from end to end • Determine all organizational assurance functions • Develop formal relationships with other assurance functions • Coordinate all assurance functions for more complete security • Ensure that roles and responsibilities between assurance functions overlap © 2025 Butkovic 68 Developing a Governance Program The following should be included in a information security governance program: • An information security risk management methodology • • • • A comprehensive security strategy explicitly linked with business and IT objectives An effective security organizational structure A security strategy that talks about the value of information being protected and delivered Security policies that address each aspect of strategy, control, and regulation © 2025 Butkovic 69 Developing a Governance Program-2 The following should be included in a information security governance program (continued): • A complete set of security standards for each policy to ensure that procedures and guidelines comply with policy • Institutional monitoring process to ensure compliance and provide feedback on effectiveness and mitigation of risk • A process to ensure continued evaluation and updating of security policies, standards, procedures, and risks © 2025 Butkovic 70 Summary • Information security governance is a system of resources aligned to organizational objectives • Specific goals guide the creation and operation of an information security governance program • Senior leadership (including the Board of Directors) must support governance efforts to ensure success • Information security governance is a continuous improvement process built on metrics © 2025 Butkovic 71 Questions © 2025 Butkovic 72
0
You can add this document to your study collection(s)
Sign in Available only to authorized usersYou can add this document to your saved list
Sign in Available only to authorized users(For complaints, use another form )