http://about.me/barrycaplin
securityandcoffee.blogspot.com
Security Isn’t Easy…
We didn’t get into it for the…
The Challenge of Security Awareness
  Nobody cares about Security…



      Why?

      And how do we get their attention and
  support?
Issues
•   Security viewed as a negative
•   Avoidance v. “risk”
    – Delays
    – Cost
    – Extra work
    – “Gotchas”
It Can’t Be Just…
We need sensible controls…
… early in the process…
Bad CISO/Good CISO
Governance
Governance…
We don’t need
no stinkin’
governance!
                Bad CISO
Governance
Develop a clear
strategy using
an industry
standard
framework.
Policy
All Security
Policy is the
same. I got     Bad CISO
mine from a
book.
                  “Hello Mr. Anderson”
Policy
Policies are
based on solid
principles, but
adapted to fit
the
organization.
                  … and prophesies from the oracle
Compliance
We write the
policies. We
make people
sign an oath.   Bad CISO
Done.

                Compliance and consequences policy
Compliance
We must make
(understandable)
policies. We must
teach. We must
assess, measure
and report.
Awareness
Users will know
what they have
to do or be
eliminated.     Bad   CISO
Awareness
Users can talk to
Security. We
teach. We answer
questions.
Senior Management
I say what
they want to
hear.
They’re not    Bad CISO
listening
anyway.
Senior Management
Give them the info
they need and
they will be
engaged.
Projects and Dev
They can pay me
now or they can
pay me later.
              Bad CISO
Projects and Dev
We work together
with business to
finish on-time and
with needed
controls.
Business Needs
I buy the best
known security
products
because they’ve   Bad CISO
got to be good.
Business Need
Working together
we find control-
and cost-effective
security products
that work and are
usable.
Operations
We’ve always done
it this way.


             Bad CISO
Operations
We partner with
the business and
tailor the program
to meet the need.
Stuff I Say…

KISS
Stuff I Say…
No one has “read and
understood”
but definitely still responsible
Simple, direct language in policy
Compliance via education
Stuff I Say…
You pay by the word
Keep policies short and sweet
If not, you’ll pay on the
 compliance-effort side
Stuff I Say…
People want to do the right
thing
but what is the right thing?
Understandable policy
Simple rules
Stuff I Say…
Do What Makes Sense
Risk Management approach
Seek out and destroy meaningless
 policy/controls/practices
Stuff I Say…
Iterative Improvement
Maturity model
CObIT, SEI CMMI
Stuff I Say…
Automation!
Metrics
Tools
Reporting
Stuff I Say…
What is the business need?
Find out business need in plain
 business language
Stuff I Say…
Have Fun!
Discussion…
Slides at http://slideshare.net/bcaplin
       barry.caplin@state.mn.us
 bc@bjb.org, @bcaplin, +barry caplin
   securityandcoffee.blogspot.com

Stuff my ciso says

Editor's Notes