creating a cybersecurity strategy for your organization’s data...1 •business •about the city...

10
1 •Business •About the City •Bienvenido •Election Creating a Cybersecurity Strategy for Your Organization’s Data Clayton Calvert Consultant 2 Agenda Set Expectations Organization Strategy Measures Examples Conclusion 1 2

Upload: others

Post on 07-Sep-2020

5 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Creating a Cybersecurity Strategy for Your Organization’s Data...1 •Business •About the City •Bienvenido •Election Creating a Cybersecurity Strategy for Your Organization’s

1

•Business•About the City•Bienvenido•Election

Creating a Cybersecurity Strategy for Your Organization’s Data

Clayton Calvert

Consultant

2

Agenda

Set Expectations

Organization

Strategy

Measures

Examples

Conclusion

1

2

Page 2: Creating a Cybersecurity Strategy for Your Organization’s Data...1 •Business •About the City •Bienvenido •Election Creating a Cybersecurity Strategy for Your Organization’s

2

3

Expectations

This talk will…

Provide strategies for orienting cybersecurity strategy with organizational goals

Help delineate the difference between measures and metrics

Provide examples of cybersecurity strategies in action

This talk will not…

Make you a risk expert

Make you a cybersecurity expert

4

Organization ‐ VMOSA

Vision Mission Objectives StrategyAction Plans

Organization

Handoff

Security

https://www.atlas101.ca/pm/concepts/vmosa-vision-mission-objectives-strategies-and-action-plans/

3

4

Page 3: Creating a Cybersecurity Strategy for Your Organization’s Data...1 •Business •About the City •Bienvenido •Election Creating a Cybersecurity Strategy for Your Organization’s

3

5

Organization – SWOT Analysis

Vision

Mission

Objectives

Strategy

Action Plans

6

Strategy

How you choose plans to meet your objectives, not what you choose

5

6

Page 4: Creating a Cybersecurity Strategy for Your Organization’s Data...1 •Business •About the City •Bienvenido •Election Creating a Cybersecurity Strategy for Your Organization’s

4

7

Measures

Three Questions to Ask:

1. What is my desired outcome?

2. Why is it the right outcome?

3. How do I know the measure predicts the outcome?

8

Observations in contextof desired Outcome

Orient

Decide

Act

Observe

Strategy

Action Plan

Measures

OODA Loop Mapping

VMOSAFactor from SWOT

VMOSA VMOSA

7

8

Page 5: Creating a Cybersecurity Strategy for Your Organization’s Data...1 •Business •About the City •Bienvenido •Election Creating a Cybersecurity Strategy for Your Organization’s

5

Example Strategies

10

SMART

Specific

Measurable

Achievable

Relevant

Timely

9

10

Page 6: Creating a Cybersecurity Strategy for Your Organization’s Data...1 •Business •About the City •Bienvenido •Election Creating a Cybersecurity Strategy for Your Organization’s

6

11

Reactive

Not a good strategy

https://www.pexels.com/photo/fire-orange-emergency-burning-1749/

12

Supporting Infosec Operations

Support infosec ops to minimize the likelihood of loss

https://www.pexels.com/photo/group-of-people-in-conference-room-1181304/

11

12

Page 7: Creating a Cybersecurity Strategy for Your Organization’s Data...1 •Business •About the City •Bienvenido •Election Creating a Cybersecurity Strategy for Your Organization’s

7

13

Economic Engineering

Decrease value proposition to attacker

https://www.pexels.com/photo/photography-of-one-us-dollar-banknotes-545064/

14

Reducing Infosec Risk

Set risk appetite over a given timeframe to work toward

https://www.pexels.com/photo/ace-card-game-cards-casino-297507/

13

14

Page 8: Creating a Cybersecurity Strategy for Your Organization’s Data...1 •Business •About the City •Bienvenido •Election Creating a Cybersecurity Strategy for Your Organization’s

8

15

Improve Compliance

Pass compliance standards

https://www.pexels.com/photo/auditorium-benches-chairs-class-207691/

16

Implement NIST Framework

Use NIST standards 

https://www.pexels.com/photo/gray-metal-building-structure-2308120/

15

16

Page 9: Creating a Cybersecurity Strategy for Your Organization’s Data...1 •Business •About the City •Bienvenido •Election Creating a Cybersecurity Strategy for Your Organization’s

9

17

Map Risks to Plans

DOTMLPF‐P

Doctrine

Organization

Training

Materiel

Leadership

Personnel

Facilities

Policy

https://web.archive.org/web/20070204073933/http://www.dtic.mil/cjcs_directives/cdata/unlimit/3170_01.pdf

18

Conclusion

Collect vision, mission, objectives, and strategy and make it data‐driven:

Document measures and where they come from Determine why they are the right measures

Use these measures to identify and choose plans

Continually monitor performance

17

18

Page 10: Creating a Cybersecurity Strategy for Your Organization’s Data...1 •Business •About the City •Bienvenido •Election Creating a Cybersecurity Strategy for Your Organization’s

10

•Business•About the City•Bienvenido•Election

Questions?

Clayton [email protected]://netlogx.com/

19