Security Compliance and Management - Issues Faced by Organisations Today.

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    2 Favorites

    Security Compliance and Management - Issues Faced by Organisations Today. - Presentation Transcript

    1. Gilbert Verdian MBA, CISA, CISSP EMEA Security Architecture and Consulting Manager Security Compliance and Management - Issues Faced by Organisations Today. InfoSec 2007 - London
    2. Agenda
      • Security is Dynamic
      • Threats
      • Current Issues
      • Addressing Issues
    3. Security is Very Dynamic
      • The landscape is constantly changing:
        • New Technology
          • New Operating Systems
            • Vista, Apple Leopard
          • Ubiquitous Computing & Interconnectivity
        • Threats
          • Web Applications
          • Malware/Spyware
          • Botnets
        • Motivation
          • $, £, €
    4. Threats are Changing
      • Hacking Then
      • "Hacking was about learning how a computer operates. You always tried to push it to the edge. Kids these days, they just want to do any damage they can" - Val Koseroski
      • Hacking was about bragging rights
        • What skills you had
        • How you came up with the idea that beat the system
      • Fixing things
        • Frustration from restrictions (hardware/software)
        • Finding ways to push the limits
      • Sharing
        • Helping others to learn what you discovered
        • Helping to fix the problems in place
    5. Threats are Changing
      • Hacking Now
      • Now there is profit to gain
        • Black Market
        • Trade Vulnerabilities - 0 day
        • Trade accounts
          • Paypal
          • Credit Cards, Bank Account Details
        • Trade Servers
        • Trade Identities
      • Malicious Intent
        • Botnets
        • Malware/Spyware
        • DDoS
          • Root Servers in March
    6. Threats are Changing
    7. Threats are Changing
    8. Threats are Changing
    9. Threats are Changing
    10. What Affects Organisations
      • Statutory and regulatory compliance deadlines and stepped up enforcement and penalty actions
        • E.g., statutory - HIPAA, Sarbanes-Oxley, Patriot Act, Privacy Act, Gramm-Leach-Bliley (GLB), EU Privacy Directives
        • E.g., regulatory - SEC, OCC, FRB, Turnbull report, Basel II, ITAR/EAR and export control
      • Virus attacks and threats are increasing at a faster rate
      • A demand for ROI on security spend
      • No longer just about compliance - executives require business value
      • Public trust of brand and image is under attack
        • Privacy concerns
        • Continuity of operations fears
      • New and complex business models add risk
      • Typical Security functions in Organisations
      Segregated Security Management
      • Networks
      • Firewalls
      • IDS/IPS
      • Desktops
      • AV
      • Personal FWs
      • Malware/Spyware
      • Patching
      • Servers
      • User Provisioning
      • AV
      • Patching
      Security Department IT Functions Security Function
    11. Large amounts of Segregated Security Data Do not share information with each other
    12. Security Management
      • Help is on the way
      • Proper Risk Management
        • IT Risk is part of Business Risk
        • Risk goes to Board level
          • Criminal prosecution
        • Single view of Risk Level
      • Automation using tools and Methodologies
        • Bindview, Probity
        • OCTAVE, MORDA
        • Single view of IT Landscape (Dashboards)
        • Log collection and correlation - SIMs
    13. http://www.gilbertverdian.com

    + gverdiangverdian, 2 years ago

    custom

    2048 views, 2 favs, 3 embeds more stats

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 2048
      • 1997 on SlideShare
      • 51 from embeds
    • Comments 0
    • Favorites 2
    • Downloads 0
    Most viewed embeds
    • 48 views on http://www.gilbertverdian.com
    • 2 views on http://networks.feedburner.com
    • 1 views on http://127.0.0.1:8795

    more

    All embeds
    • 48 views on http://www.gilbertverdian.com
    • 2 views on http://networks.feedburner.com
    • 1 views on http://127.0.0.1:8795

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories