CIA Triangle eCrimes Congress PDF

advertisement
@thomlangford
use your CIA triangle
and improve your risk
management programme
the opinions expressed in
this presentation are my
own and do not
necessarily represent the
views of my employer
@thomlangford
the CIA triangle
@thomlangford
the CIA triangle
confidentiality
@thomlangford
availability
integrity
concerning
our
information
the CIA triangle
confidentiality
@thomlangford
availability
integrity
concerning
our
processes
integrity
or measure the same way, every time
poor risk assessments
poor findings
poor data
poor business information
poor decision making
@thomlangford
integrity
or measure the same way, every time
non-judgemental
collaborative
educational
risk
assessments
constructive
open
non-confrontational
@thomlangford
availability
or using the boards iPads
@thomlangford
availability
or using the boards iPads
vendor risk management
risk assessments
business continuity
risk management
penetration testing
vulnerability assessment
@thomlangford
disaster recovery
compliance
availability
or using the boards iPads
business continuity
enterprise risk
executive summary
business
impact
analysis
recovery
plans
tabletop
exercise
pci dss
iso
27001:2005
compliance
hipaa
@thomlangford
simulation
exercise
availability
or using the boards iPads
risk assessments
business
benefits
4 client assessments completed
potential pii breach 29 jan averted
23% overall reduction in insurance costs
32 client contracts assessed
disaster recovery
power outage 23 Feb - no impact
malware break out 12 Jan - no impact
29 feb facility outage - no impact to payroll run
no phoenix project outage march ’13
@thomlangford
confidentiality
or becoming a part of the illuminati
“this is what I need digital to do to
help me sell more beer”
steve mura, director of digital
marketing, millercoors
C
@thomlangford
I
A
confidentiality
or becoming a part of the illuminati
y
t
i
r
u
“this is what I need sec
to do to
help me sell more beer”
your board members
now
C
@thomlangford
I
A
What next?
• Look at the quality of your risk data
(and risk programme)
• Engage with your business in a way
that speaks to them, not you
• Provide the information needed to
"sell more beer"
C
@thomlangford
I
A
Thank You
@thomlangford
http://uk.linkedin.com/in/thomlangford
thom@thomlangford.com
C
I
A
Download