Overview
Join Bob Salmans as he dives into organizational governance.
Gain an understanding of strategies, goals, and objectives around enterprise risk. Learn about organizational structure, roles, and responsibilities.
Recommended Experience
- An understanding of concepts taught in CompTIA Security+ is recommended
Related Certification
- ISACA CRISC
Related Job Functions
- Security analysts
- Security managers
- Security architects
Bob Salmans has been a CBT Nuggets trainer since 2020. He has received certifications from Cisco, Microsoft, VMware, Offensive Security, and more. His expertise areas include networking, network security, cybersecurity, information security, systems administration, and virtualization.
Security Governance
In this video, we discuss what governance is, its primary objective and outcomes.
Knowledge Check
Which is the primary objective of IS governance?
Information Security Strategy
In this video, we're analyzing what a strategy is and how to come up with one.
Knowledge Check
Choosing a standard or framework is a good way to identify your objective or where you want to be. True or false?
Identifying and Managing Strategic Objectives
In this video, we're diving into the management of our strategies and objectives which includes using a SWOT analysis and CMM.
Knowledge Check
SWOT analysis focuses on strengths, weaknesses, opportunities, and threats. True or false?
Organizational Roles and Structure
In this video, we take a look at roles within risk management and how they fit into the organizational structure.
Knowledge Check
Which RACI role is going to be consulted for insight or information about certain areas of the organization?
Risk Culture
In this video, we're discussing the importance of culture when it comes to the success of information security and risk programs.
Knowledge Check
In order for a risk management program to succeed, leadership must show commitment and support for the program. True or false?
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Security Governance
0:06Within information security and IT in general
0:10we hear a lot of buzzwords and one of those buzzwords
0:13is governance.
0:15And if you ask 10 different people what governance is,
0:18you might end up with 10 different answers.
0:21So we are going to put this to rest right now, we're
0:24going to talk about what governance is, why we need it
0:27and how we do it.
0:29So come with me as we discuss governance.
0:33All right, governance here we go, what on Earth is it?
0:38Well, it really comes down to the oversight of something,
0:43and along with oversight of something
0:45comes some tasks and things that we do.
0:48And it really comes down to the efforts
0:50by our executive management via like strategy and oversight,
0:55which I just mentioned, over key business activities
0:58to make sure that they're doing what
0:59they're supposed to be doing.
1:01And that's where oversight comes into play.
1:03Now there are four activities we're
1:06going to mention right off the top here,
1:09such as defining objectives, because if we don't define
1:13objectives then we're not sure where
1:16we're headed because an objective is something
1:19we want to achieve.
1:21It's something that, as we look down the road,
1:25it's that pot of gold at the end of our rainbow.
1:29And that's an objective, it's where we want to go,
1:32where we want to get to.
1:34So if we don't have objectives then
1:36we really don't have anything we're trying to achieve
1:38and that's not good.
1:39So we need objectives.
1:41That's right, that's numero uno.
1:43Next up, we're going to have to have some policies.
1:46Policies are outlining the organization's stance
1:49on things.
1:50It lets people know what we want to do with,
1:53of course, our stance as I said but really how we
1:56want to do business, how we want to achieve it.
1:58And it helps us outline a path or different ways
2:02that we can achieve our objectives.
2:06Next up is delegate authority, and that's
2:09because we know that executive management can't do everything
2:13themselves, that's right.
2:15We need to delegate authority so other folks
2:18can do the day-to-day tasks because we've
2:22got executive management up here and they're
2:24saying this is our objectives over here,
2:26this is how we're going to do it,
2:28and then they delegate, of course, the authority
2:30down here to the other folks to make sure
2:33that our plans are carried out so
2:34that we can meet our objectives, absolutely.
2:38And lastly, we need to monitor our objectives or our controls,
2:44everything we put in place via metrics.
2:47So that means we need to create metrics
2:50so that we can monitor different processes and controls that we
2:54have in place because if we're not measuring something then
2:57we can't really tell for sure if it is succeeding
3:01or if it's failing.
3:03And that's why metrics are such an important piece
3:06of governance and overall, IT and IS strategies.
3:12Now when it comes to IS or information security
3:14governance, it has a main purpose,
3:19and that is to make sure that the information security
3:22efforts that we're putting into play, everything
3:25we're doing toward information security,
3:27all those efforts are in alignment
3:29with business objectives.
3:31So you'll see these here are in alignment with each other.
3:35And that is super important because everything
3:38we do when it comes to management,
3:41and that could be information security,
3:43information technology, risk management, all these things,
3:47everything we do here, needs to be in alignment
3:51with business objectives.
3:52And that means they need to be in support of the objectives.
3:55If our business objectives are here
3:59and we are working on risk management
4:01processes and objectives and our efforts,
4:04and they're going along like this
4:07and they start to veer off in a different direction,
4:10then we've got a problem and we need to stop.
4:12We need to go back and re-observe our business
4:15objectives and get this back in alignment with it.
4:19Because everything must be in alignment
4:21with business objectives.
4:23That is a very key takeaway from this lesson.
4:27Next up, the primary objective of information security
4:31governance.
4:32Now, we mentioned, the primary purpose
4:34was to be in alignment with business objectives,
4:36yes, we got to make sure it's in alignment
4:38but then our objective, that's our pot of gold
4:41at the end of the rainbow, what we're trying to get to,
4:43is to protect our CIA triad, that's
4:47our confidentiality, our integrity,
4:50and, of course, our availability.
4:52So we're protecting our assets in the CIA triad.
4:56And that is the primary objective
4:58of information security governance,
5:00protect our assets' confidentiality, integrity,
5:04and availability.
5:06Now, as we talk about governance,
5:08there's lots of different activities
5:11that are required for governance to happen.
5:15So let's talk about some of these activities.
5:18Now, first of all, we've already mentioned this once,
5:21and it was define objectives because again, we
5:24need to have someplace that we're headed to,
5:27we need objectives, something we're working towards.
5:30So an example of an objective would be maybe
5:33to protect the organization from unnecessary risk, that's
5:36one of our objectives.
5:37So then we'd be looking to see what is unnecessary risk?
5:41How do we identify it, so that we can protect from it?
5:43And that would be one of our objectives.
5:46Next up, we need a strategy.
5:48So we need to create a strategy.
5:51Now again, a strategy is let's say we are here, this is today,
5:57and we have an objective of where
5:59we want to be at a later date because we know
6:02it's going to take some time to get there,
6:04everything we need to do in between here and there,
6:07each one of these tasks that I'm putting on here,
6:09these are all tasks here, are our strategy.
6:14If we do this, and then this, and then all these, by the time
6:18we're done, we will have reached our objective
6:21and this whole plan that we've outlined here is our strategy.
6:26So we create a strategy.
6:28Next up, we're going to need to create some policies.
6:32Hey, we talked about this on the first slide
6:35as well, as one of the things we need
6:36to be doing because these policies are going to define
6:39the organization's stance on security and on risk
6:42and on all different types of things.
6:44But we need to have policies, because they are defining
6:47and they are communicating-- let's put comm down here--
6:50because really they are providing
6:52a way of communicating the organization's stance
6:55to everybody within the organization.
6:57So that is our policies.
6:59Next up, we need to look at adopting standards.
7:03And that's because if we pick a standard that we want
7:07to go with, that's going to help us to become consistent,
7:11let me put that down here consistent.
7:14So that everything we do in our organization
7:16as long as it's in alignment with this standard as far
7:19as policies and putting out controls and processes
7:22and such, well, if they're in alignment with the standard,
7:25they're going to be consistent across the organization.
7:28And that's what we want, consistency.
7:31Then we need to create something else,
7:33we need to create processes.
7:35And the processes are defining how
7:38activity should be performed.
7:40So if we want to do something, there
7:42is something that has to be done,
7:43we create a process that outlines how exactly that
7:46should be done.
7:47Do you know why?
7:48Well, it's because we want it to be repeatable,
7:50a repeatable process because if it is repeatable,
7:53guess what it goes back to?
7:55That's right, consistency, and that's
7:57what we're looking to achieve because if we can have
7:59consistency in everything we do throughout the organization,
8:02it's going to help governance and metrics and everything
8:04to work better because we're all in alignment
8:08with the business objectives.
8:10Then we need to define controls, that's
8:13something else we need to define.
8:15Now controls are something that's
8:16put in place to help detect or avoid or counteract
8:21something like a security risk to an organization.
8:25And that's really what we're looking at here
8:26is with controls, risk.
8:28Now some of these controls could be like firewalls,
8:30you could have antivirus, security guards, security
8:33cameras, fire suppression systems,
8:35there's a ton of different things
8:36that we can put in place that are controls
8:39and it helps to control risk.
8:42And then lastly, we need to define, and other than define,
8:47we need to analyze metrics, that is right.
8:53We need to, of course, collect metrics
8:55because if we want to be able to see if something
8:58is a success or a failure, like a control or a process
9:03or something, we have to measure it.
9:06And how do we measure things?
9:07Well, we do so via metrics.
9:09So you might say, well, what kind of metrics
9:11am I collecting?
9:12Well, depends on what you're trying to measure.
9:14So first of all, you have to define what do
9:16I want to measure or monitor?
9:19That would be like number one, that's your question one,
9:22and then you're going to say, well,
9:23how do I define a success or failure?
9:27So you say success or failure--
9:29and this is just a kind of a shorthand here--
9:32and then you're going to say three,
9:34all right, I have this list of success and failures
9:36of what would determine that.
9:38How do I monitor each one of those,
9:40what data do I need to collect?
9:41And then those are the metrics that we're
9:43going to start collecting so that we
9:45can define success or failure in something
9:49like a control or a process.
9:51And we can also, if we monitor those,
9:54over time we can see kind of a rise and fall,
9:59and we can catch things if they go out of our comfort zone
10:03really.
10:04So if we say we're willing to accept this amount of deviation
10:09from normal within our metrics that we're collecting,
10:14and if it goes outside that then we can be notified
10:17and we can go ahead and implement a corrective action
10:20and figure out what happened.
10:22So those are metrics.
10:23And these are some of the IS governance activities
10:26that we have to do in order to make sure governance
10:29is working properly.
10:30But there's still a couple more activities.
10:32And these are a little different.
10:34So let's take a look at these.
10:35Some additional IS governance activities.
10:38Now the first one is risk management, and heck yeah,
10:42you better believe it is an information security governance
10:45activity, risk management is rock star-level super cool
10:49stuff.
10:49And yeah, we've got to control our risk,
10:51we've got to manage it.
10:52Another thing we need to be concerned with is compliance.
10:56So when it comes to compliance if your organization has
10:59regulatory or legal or even contractual
11:02compliance requirements, well, we
11:04need to identify the requirements,
11:08and then we need to monitor those compliances.
11:12And how do we monitor something?
11:13That's right, back to our metrics.
11:15Metrics come back into play as we're monitoring something
11:18like compliance.
11:19So we can ensure that we stay within compliance
11:21because if you fall out of compliance well,
11:23there could be financial penalties
11:25and there's always the risk of losing business
11:28because of being out of compliance.
11:30So compliance is important.
11:33Next up, BC/DR planning, that's our business continuity
11:36and disaster recovery planning because, of course,
11:41business continuity, disaster recovery
11:43is all about, that's right, responding to risk.
11:47So if a risk event happens, how do we deal with it?
11:50Well, hopefully, our business continuity
11:52and disaster recovery plans will cover that because if not,
11:55then we didn't do a good job in creating them
11:57and we need to do better next time.
11:58So of course, business continuity
12:00and disaster recovery planning is a governance activity.
12:03And then lastly, resource management.
12:06Now in order to get things done, we have to have resources,
12:11we have to have people that will do the work,
12:13we have to have budgetary support.
12:16We have to have other things like supplies and such
12:19that may come into play.
12:21So basically, we have to have various resources.
12:25And that means we need to manage our resources,
12:27we need to make sure that we have enough resources but not
12:32too much, because the thing is, if we have too much,
12:35then we're wasting.
12:36So you need to find a balance here
12:38and that is what resource management is about,
12:41making sure we have enough to get the job done
12:43but not so much that we're wasting resources.
12:46So again, these are all activities
12:48that are part of IS governance.
12:51Now, effective IS governance has two--
12:54I'll put this little arrow in-- two primary outcomes, number
12:58one, is increased trust.
13:02Now, this is trust from inside the organization,
13:06this is trust from business partners and from customers
13:08but basically, it's increased trust.
13:11And this is because we're doing security the right way.
13:14Meaning, when a customer asks to see maybe our information
13:19security policy to make sure that we have one,
13:22hey here it is and it is an awesome policy.
13:25Maybe they want to take a look at some of the metrics
13:28we're using to verify that our controls are actually
13:32functioning.
13:32Guess what?
13:33We've got them, here you go, bada bing, bada bang.
13:36We can provide that information at a moment's request.
13:40And I'll tell you what, I have filled out
13:42a ton of questionnaires for clients
13:44who I provided security services to
13:46and they were a service organization
13:49or they provided services and their customers
13:53would send over questionnaires to fill out all about security,
13:57how are you doing this, how are you doing that?
13:59And if you can honestly answer all
14:02of those checkboxes in that questionnaire
14:04and provide things like copies of metrics or your policies
14:08or whatever, you know what, when that customer gets this back,
14:11they're like, holy cow, these folks are on top of it.
14:15That is where your trust comes from.
14:17And your internal personnel are going
14:18to see how things are being done, going to see things
14:20are done right and properly, there's documentation,
14:23there are policies, there's all the things
14:25and they're going to trust that the organization is on the up
14:29and up, so that is increased trust.
14:31And with that comes improved reputation.
14:36So within the industry, you will have an improved reputation
14:40and the organization will be known
14:41as someone who does security the right way
14:43and of course, can be trusted.
14:45So these are two of the outcomes of effective information
14:50security governance.
14:51And that covers our security governance lesson.
14:53I hope this has been informative for you,
14:55and I'd like to thank you for viewing.
Information Security Strategy
0:07If you've ever set out to achieve a specific goal
0:10and you're maybe talking with someone about it,
0:12they might ask you what's your strategy
0:14for achieving that goal?
0:16So maybe your goal is to start a new business
0:19or make the Olympic team or become an astronaut, who
0:22knows what it might be?
0:23But what is your strategy to achieve that goal?
0:28Now, this can be a little tricky because really I
0:30mean, what is a strategy?
0:32I mean, it could be a lot of different things.
0:34And in information technology, information security,
0:38risk management, governance, all these things,
0:41we use strategies.
0:43And if you're not sure what a strategy is well
0:45guess what, you're in the right place
0:47because right now we're going to talk about strategies, what
0:51they are, how to create them, and how they can benefit us
0:55in reaching our goals.
0:56So let's get started.
0:59So first off, we've got to define what in the heck
1:02a strategy is and it's as simple as a plan
1:05to get to where you want to be, it is a plan.
1:08OK, so a plan but how do I come up with this plan, right?
1:13Because just knowing what it is doesn't help me all that much.
1:17I need to know how do I create this plan.
1:21And that's what we're going to talk about.
1:22So cool, you're in the right place.
1:24So of course, we start off with a goal or an objective.
1:29We say a goal, sometimes we call it an objective,
1:32they're the same thing, right?
1:34It's something we want to achieve.
1:36So first of all, we need to define what this is.
1:39And then we need to figure out how do we get there.
1:44How do we get to this place?
1:45And this how is guess what?
1:49It's your strategy.
1:50It's that simple.
1:51So let's go ahead and let's outline a quick strategy.
1:54So steps to defining your overall strategy.
1:58Now, what was step one?
1:59It was defining our goal or objectives.
2:02So we've defined that, we'll say our goal
2:05in this strategy is to reduce the risk of let's say data loss
2:14from lost devices.
2:17That is our goal or our objective
2:20because we're trying to keep it focused in this example.
2:24So we have a very focused goal or objective,
2:27reduce the risk of data loss from lost devices.
2:30So like portable devices, cell phones, tablets,
2:34laptop computers, so on, so on, so on, and so forth.
2:37Now, we need to identify where we are in comparison to where
2:43we want to be.
2:43So here's where we are today, and when
2:46it comes to portable devices and such,
2:49do we have any policies, that would be the first question.
2:53And we say nope, there's no policies
2:55around portable devices.
2:58So all right, so this is where we are today.
3:00And where we want to be is we want to be in a place where
3:04we have reduced risk of data loss from lost or really--
3:08I'll put stolen-- lost or stolen devices.
3:12So what do we need to do to get from here all the way
3:15over to here?
3:17And what we're doing is performing a gap analysis.
3:21And this gap analysis is going to tell us
3:24what we need to do to get from here to here.
3:28And so let's start with this.
3:30Let's talk about this, we had no policy.
3:32So step one is probably going to be to create a policy.
3:36We need to create a policy.
3:38And this policy will be around the management
3:41of portable devices and what kind of data
3:44can be on these devices.
3:46Then we probably need some type of way
3:48to manage the devices themselves.
3:50So maybe a device management system.
3:55All right, cool.
3:56So that way we can manage devices, we can do remote wipes
4:00and we can reduce the lost or stolen data.
4:03OK, so that's going to be a step in it.
4:06So now we have policy around our devices
4:08and we have a way to manage the devices
4:11but here's a question for you, how
4:13do we know if we're succeeding or not?
4:15That's right, metrics.
4:17Now we need to include some type of metrics
4:20for monitoring devices.
4:22So how many devices do we have?
4:23How many of them are managed?
4:25So we can see if there is some that aren't managed or such.
4:29All right, there we go.
4:30So now we have metrics.
4:31So now we have a strategy because our strategy
4:34is going to be to first create a policy, then to implement
4:39some type of system that will help us manage these devices
4:42and maybe do like a remote wipe on them
4:44or encrypt the data on them so the data can't be stolen.
4:47And then lastly, of course, we need
4:48metrics to make sure everything's working
4:50like we hope it should.
4:52So there we go, we have just created a strategy and that
4:56is step three which was decide how we're going to get there,
5:02how to do it basically.
5:05So our goal was--
5:06so step one, was to establish a goal.
5:09Step two was to do basically a gap analysis to figure out
5:13what we need to do to get there, and then step three
5:15is put that into a plan.
5:17And that is our strategy right down here.
5:20There we go.
5:21That's defining a strategy.
5:22And this was a very simplified strategy, it was very focused.
5:27So if your strategy is to reduce risk,
5:29well, that's a pretty wide strategy.
5:30So you're going to have a big list of things
5:33to do in your gap analysis and a rather large strategy
5:37but you have a plan, that is your strategy.
5:39So now that we have the strategy there
5:42are some tools that will be part of this strategy or achieving
5:47our strategy such as policies and procedures.
5:51So we'll say policies and procedures, P&Ps.
5:54Because we're going to have to have policies in place
5:56to outline our stance on certain things like managing data
6:01that goes on mobile devices or the devices themselves.
6:03We have to have procedures around how
6:05to register new devices that come into the organization.
6:08So we make sure they get managed and procedures
6:11for reporting lost or stolen devices, things like that.
6:14So as we follow that example, you
6:15got policies and procedures.
6:17We're also going to need a risk assessment program.
6:22And risk assessment, that's going
6:25to be a tool that we use as part of the strategy
6:28so we can assess the risk associated
6:31with different activities.
6:33We're going to need to implement the security or risk
6:36framework because if we implement
6:39a framework or a standard that we're going to follow,
6:41that takes us back to our consistency
6:44that we talked about in the last video
6:46so that we can make sure we're all doing things the same way,
6:49there we go.
6:50We're also going to need asset management
6:53as part of our strategy because no matter what it is,
6:56there's assets involved and we need to make sure
6:58that we're able to identify those assets
7:00and track them and make sure that they are being managed
7:04properly.
7:04And then lastly, our business continuity
7:07and disaster recovery planning.
7:10And some of these tools are the same thing
7:12we saw with our governance, that is absolutely right.
7:16Thank you for pointing that out because that is very true.
7:19A lot of these things will overlap because they
7:22are such useful tools.
7:24Now, one question you might have is well, where do I want to be?
7:28I know where I am today kind of but I don't know where I really
7:31want to be.
7:32And this goes back to frameworks and standards.
7:37Now, these are going to help you decide where you want to be.
7:40So you may want to go ahead and pick a specific framework
7:44or standard like the ISO 27000 series,
7:47and that way you have something that's
7:50going to help you identify where you want to be.
7:53It's going to give you an outline of some best practices.
7:56And the thing is, there's lots of standards out there.
7:59So let's talk about some of those standards
8:01and different frameworks.
8:02So you have COBIT, that is by the folks over at ISACA.
8:07And COBIT is a framework around information security
8:10and risk as well as addressed in there.
8:12You got the ISO/IEC 27001, part of the ISO 27000 family.
8:20And this is all about information security
8:21management.
8:22There's the ITIL, of course, ITIL is a well-known framework.
8:26You've got HIPAA, and that's around patient data
8:29information.
8:31NIST, or National Institute for Standards and Technology,
8:34NIST has the SP 800-53, this is about your security and privacy
8:40controls.
8:41The CIS folks, CIS always put out a top 20,
8:45so the CIS top 20 is kind of a list of top 20 security
8:50controls that you should consider implementing.
8:52They are the top 20 controls that
8:54are going to give you the most bang for your buck.
8:57And then, of course, PCI-DSS as well
9:01for credit card-related information.
9:04There's all these.
9:04And there's a ton more out there.
9:07And the thing is, maybe you think,
9:09well, let's see, we do handle patient information, that's
9:13something we do because we're a medical clinic
9:16and we also process credit cards.
9:18So maybe we need to follow this one as well.
9:20So you may end up selecting more than one of these.
9:23Or it may be you don't process credit cards
9:27or patient information but you'd like
9:29to combine a couple of these to make them custom.
9:32You can make your own custom framework
9:33if you want to or standard.
9:35And that's OK, you can do that it's your decision.
9:38But what I want you to know is when
9:39trying to decide where you want to be,
9:41just remember you've got all these frameworks
9:43and standards out there that are industry-proven.
9:46And they're put together by some pretty smart people out there
9:50too who know what they're doing.
9:51So why not just choose one of these or another one
9:54and go from there?
9:56So now you figured out you're going
9:58to go with a specific framework or standard.
10:01Now how do you figure out where you're at today
10:03because remember, we have to figure out
10:05where we are today because now we
10:08have our standard or our framework,
10:09we know where we want to be.
10:11We want to be over here with our standard over here
10:14but how do I know where I am today?
10:19Well, there's a couple different things that we can do.
10:22We can perform some assessments.
10:24Number one, we can perform a risk assessment,
10:28and that will help us identify where
10:30we are with risks and our risk maturity program
10:34within our organization.
10:36Then we can also do a threat assessment
10:40so we can assess the threats to our organization,
10:44the likelihood that something would happen.
10:46Number three, we could perform a compliance assessment.
10:50So if there are some types of compliance,
10:53regulatory compliance, legal or contractual compliances
10:56that we have, well guess what?
10:58We need to assess those to see where we are today.
11:01And then lastly, a general security assessment
11:05so that we can identify what policies, procedures,
11:08standards, guidelines, controls, metrics,
11:12what all we have in place when it comes to security.
11:17And all of this information here will tell us
11:20where we are today.
11:21And that way we can go ahead and figure out
11:23how do I get from where I am today
11:25to where I want to be so that I can create my strategy.
11:29Now, once you define your strategy
11:32there are a couple of key points that you'll want to adhere to.
11:36Number one, strategic alignment.
11:41And this means that everything you do
11:42must be in line with, you guessed it,
11:46organizational goals.
11:48Because everything we do in the organization
11:50or in business needs to be in alignment
11:53with the organization's goals as well.
11:56Number two is manage risk.
12:00And that's because risk management
12:02is super important for something and that is decision making.
12:06So we have to be aware of risk, we have to be managing risk,
12:09we know what risks we're dealing with.
12:11So when it comes to making decisions about the business
12:14that we can provide senior management
12:16and the C-level execs the information
12:18they need to know about risk to make good decisions.
12:21Number three is manage resources.
12:26And again, this goes back to managing your personnel, making
12:29sure you have enough personnel, as well as managing
12:32your budgetary restrictions so that you're not
12:35wasting resources.
12:37So resource management.
12:39And lastly, number four, we need to measure.
12:43That's right, that comes down to our metrics.
12:45So we need to have metrics in place
12:47so we can measure what we're doing to make sure
12:50that we are succeeding on it.
12:52That we're making a forward and upward progress
12:55because if we're not collecting metrics,
12:57if we're not measuring something,
12:58we're not going to be able to tell if we
13:00are succeeding in that or not.
13:02And these are four key points to adhere to with your information
13:07security strategy.
13:08I hope this has been informative for you
13:10and I'd like to thank you for viewing.
Identifying and Managing Strategic Objectives
0:00[MUSIC PLAYING]
0:06Now that we've identified what a strategy is and we went through
0:10and we actually put a little strategy together
0:12as an exercise, now the question becomes,
0:15how do I manage my strategy and my objectives?
0:19That's what comes up next, because now we have it.
0:21We have our plan or a strategy, how do I manage that strategy?
0:25How do I manage my objectives?
0:27That is what we're going to talk about right now.
0:31So starting off.
0:32To manage a strategy or an objective, we can use the SWOT,
0:37S-W-O-T, that stands for strengths, weaknesses,
0:41opportunities, and threats.
0:43And that is our SWOT analysis.
0:46Now, the way this works it's an exercise,
0:49and allows us to identify what we're doing good,
0:51what we're not doing good, and where we can improve.
0:55And that's what this exercise is all about.
0:57Now, let's walk through this as an exercise,
1:00and let's say we're going to do SWOT analysis for cloud
1:05security in our organization, because we have recently
1:08moved to the cloud or move some of our applications
1:11to the cloud, and now we want to do a SWOT analysis on our cloud
1:15security.
1:16So let's walk through how this works.
1:18So now we're starting off with our strengths.
1:21So we'll put S, I'll put W over here,
1:24O over here, and T down here.
1:27That's our strengths, weaknesses, opportunities,
1:29and threats, and this way we can outline.
1:31Now, strengths.
1:32What are our strengths when it comes to cloud security
1:35as we sit around the table here and we discuss this as a group?
1:39And we find out that well we have cloud engineers.
1:43So we do have cloud know how on staff.
1:48So that's good, and we have off-cloud backups.
1:51Meaning, we have backups that are to another location
1:57other than the cloud.
1:58All right, that's good.
1:59So we have how here.
2:00We have brainpower about cloud.
2:02We're doing good backups for our cloud,
2:05because we got them onto another platform out of our cloud
2:07provider so that we have a second copy somewhere.
2:11So that is good.
2:11That is definitely strengths.
2:13But when it comes to weaknesses, we
2:15find out, as we discussed, that we really
2:17have no cloud security program.
2:22And that's very good to know, because we need one.
2:26So that is a weakness.
2:27We don't have a program.
2:28So that being said, what kind of opportunities
2:32do we have here to improve our weakness?
2:35Well, actually, ISO, international organization
2:40for standards, puts out the 27017
2:45which is security controls in the cloud.
2:49We'll put down here security controls in cloud
2:53just so we can have a reference there.
2:56There we go.
2:56Now we know that there is a standard out there
2:59that can help us implement a security program.
3:02So this is definitely an opportunity
3:04for improving our weaknesses.
3:06Excellent.
3:07Cool.
3:08So now lastly, what are our threats?
3:11Well, we could have misconfigurations.
3:14Yes, you're absolutely right.
3:16We sure could.
3:17We've got human error, and that really
3:19goes a long way, so human errors, and then lastly,
3:25how about a security problem?
3:26A security event, would say, security event could happen.
3:30That's definitely a threat.
3:31All these are threats.
3:33So what are some opportunities that we could have
3:36to improve on these threats?
3:38Well, misconfigurations in human error.
3:41How about we go through and make sure
3:44that we have a change management program in place?
3:47So let's put a cloud change management program.
3:51If we had one of those, that would help us
3:54with misconfigurations in human error,
3:56because every change that happens has to be approved,
3:59it has to be verified.
4:01Great.
4:01And what about a security event?
4:03Well, we've already covered that,
4:04because we're looking at implementing the ISO
4:0627017 into a new cloud security program up here.
4:11And that will actually take care of that.
4:13So now you see, we just talked through a SWOT analysis
4:16about our new cloud efforts and how we could do better
4:20with cloud security.
4:21And you see how the SWOT analysis actually works.
4:23So you get the folks around the senior management,
4:26around who manage this area of the organization,
4:29you do your analysis.
4:30So that you have all the right people at the table
4:33to provide the information and discuss this,
4:36and we had a great outcome.
4:38So we end up with two opportunities.
4:39We're going to work on our security problems
4:42by implementing the ISO standard here,
4:44and we're going to implement a cloud change management
4:47program to address misconfigurations
4:49and the human error.
4:51And there you go.
4:52That is SWOT in action.
4:54Now, is that the only way to manage things?
4:56Well, heck no.
4:57Absolutely not.
4:58Let's take a look at the next one.
4:59This is our CMM, our capability maturity model.
5:04And this is basically a scale of maturity.
5:06So we want to take a look at something,
5:08and that something could be a process, it could be a control,
5:11it could be a program that we have,
5:14it could be an application that we've developed.
5:17And the idea is we take whatever that is
5:20and we rank its maturity.
5:22And it starts down here at the bottom,
5:24and it works its way up as we can see.
5:26So if we have our thing down here,
5:28whatever it is that we're wanting to rank the maturity
5:31and see how mature it is and where we can improve,
5:34well, we start off with level 1.
5:36And that is initial.
5:37And initial means that the process is inconsistent,
5:41whatever it is we're dealing with the application,
5:43the process, the control consistent.
5:46We're not measuring it, so it's unpredictable as to
5:49whether or not it's succeeding or failing, but it is in place.
5:52So, of course, that's at the very bottom.
5:54So then as we move up to number 2, repeatable,
5:58then we start to see that we've got performing consistently,
6:03and we get the same outcome each time.
6:05So that's a good outcome.
6:07We're improving there.
6:08And as we move up to step 3 to defined, well,
6:11that's where we come out with a well-defined
6:13and well documented whatever it is,
6:15the process or the controller or application.
6:19We're moving up the scale.
6:21So we'll say, well documented over here.
6:24And then actually, number 2 was we're
6:27actually getting consistency.
6:29So let's put that in here.
6:30Consistency.
6:32There we go.
6:33So we get consistency in 2, then we get good documentation on 3.
6:38And as we get up to number 4, that's
6:41where we start to see metrics, and that's
6:44where we start gathering our metrics,
6:46because we have documentation, we know how everything works,
6:49we're doing it consistently, and now
6:52on step 4 of this maturity model,
6:55we're gathering metrics so that we can show success or failure.
7:00And we can work to improve on our failures.
7:02And then lastly, when we get up to number 5, that's where
7:06we have continuous improvement.
7:08Let me put that up here.
7:09Continuous improvement, and that is 5.
7:15So once you get to 5, you are at continuous improvement.
7:18Now, not all processes or controls
7:20are going to reach level 5, and that's OK.
7:23You might just get to 4.
7:24So you're collecting metrics and it's repeatable,
7:27you've got documentation, the metrics
7:29are there to help us identify if we fall out of variance.
7:32And that's OK.
7:34That's still a good place to be.
7:36And this model helps us to see where we're at
7:39and what we need to work on.
7:41So this is the capability maturity model.
7:44And lastly, we have roadmap development.
7:47And this is what we would use to help visualize our strategy,
7:53because we're going to list out the steps that we need
7:55to complete in order to meet our objective,
7:58and that, of course, is our strategy.
8:00And it's usually based on a timeline that we see down here,
8:04and it's much like a Gantt chart.
8:07And I guess you could actually use a Gantt chart to do this.
8:09But a Gantt chart, if you're not familiar with it, is over here.
8:12We list out all of our tasks that need to be done,
8:15and generally we would list who is responsible for that task.
8:19And we list according to a timeline,
8:22which we see across the top here, when
8:24those are going to be done.
8:25And that way we can see what's overlapping.
8:27And if there are prerequisites, we
8:29can make sure the prerequisites are
8:31done before the actual task, and we can lay things out
8:35in a visual perspective.
8:38And this helps us to track our progress
8:41and see where we're at in the strategy
8:45so that we can meet our objectives.
8:47And there you go, the roadmap development
8:49is our final tool for managing our strategic objectives
8:54along the path to success.
8:56I hope this has been informative for you,
8:58and I'd like to thank you for viewing.
Organizational Roles and Structure
0:06Within organizations, we've got lots of different roles.
0:09And when it comes to risk, there's
0:11lots of different roles in risk management as well,
0:14like, who's accountable for something?
0:16Who's responsible for something?
0:18Who should be informed when something happens?
0:21These are all great questions.
0:23And we're going to answer those right now as we
0:25dive into the roles associated with risk
0:28management in an organization.
0:31Now, the first thing is document, document, document.
0:34You're thinking, I thought we were
0:35talking about roles and responsibilities
0:38dealing with risk.
0:39Well, we are.
0:40And the thing is we need to document all the roles
0:44and responsibilities in an organization.
0:48That's because whenever there is a question about who's
0:52responsible for something, or who's
0:54accountable for something, well, we
0:56can go back to our documentation of roles and responsibilities.
1:01And that's why it's super important to get these
1:03in writing on paper.
1:05Now, let's talk about risk roles.
1:09Now, there's four main types of roles when it comes to risk,
1:12and they're known as RACI.
1:14That is Responsible, Accountable, Consulted,
1:17and Informed.
1:18So let's start with responsible.
1:22These are individuals responsible for getting
1:25the job done.
1:26So basically, we say, get the job done.
1:29These are those folks.
1:31So oftentimes these are the risk practitioners, right?
1:34These are the folks in the trenches
1:37that are getting the job done.
1:38These are the folks that are responsible
1:40for that specific task.
1:42Then we have accountable.
1:43That is next.
1:46And these are the folks who are assigning tasks.
1:49They're making sure the tasks are assigned out to someone,
1:55so that they can be performed.
1:58So that leads us to the next one, which is consulted.
2:03And these are generally subject matter experts.
2:07And we refer to them as SMEs, or S-M-Es.
2:13So these are the folks who know a lot about a particular area
2:16of the organization.
2:17It could be a specific type of system.
2:20It could be a process or something.
2:23But we are consulting the SMEs, asking them questions about,
2:26is this OK to do this?
2:28It won't break anything, right?
2:29And we're going to check in with them, right?
2:31We're consulting with them.
2:32We're asking for their advice or feedback.
2:35And then, lastly, we have informed.
2:38And these are the folks who when something
2:41is updated or something is done, who do we inform?
2:45So this is usually our senior management,
2:49as you could imagine.
2:50So down here in our responsible, these are generally
2:54our risk practitioners.
2:57Our accountable folks, oftentimes,
3:00are a committee of some sort who come up
3:02with the different tasks that need to be completed,
3:05and then they can assign those out.
3:06Our consulted, that's our SMEs down here, and then,
3:10our senior management are those who are usually informed.
3:13Now, this isn't set in stone.
3:15This is just kind of usually.
3:16So you definitely need to know your RACI, your Responsible,
3:19Accountable, Consulted, and Informed.
3:23Moving on, we have a RACI chart.
3:26Now, this is an example I pulled out of the CRISC Review Manual
3:307th Edition.
3:32And down here we have a little key
3:33of our RACI terms, our Responsible, Accountable,
3:36Consulted, and Informed.
3:38We're going to talk through this.
3:39So the tasks we have here, we have
3:42some different roles over here.
3:44So of course, these are roles within our organization.
3:47So our task, task number one was to collect some risk data.
3:52Now, as you can see, who's going to be doing the work?
3:55Who's the one responsible?
3:56Well, that ends up being our risk practitioner over here.
3:59Who's assigning this out?
4:01Well, that's the accountable folks.
4:03And that is our steering committee.
4:05And then, who is consulted about this?
4:08Our subject matter expert.
4:09Well, that actually, in this case,
4:11is our department managers.
4:13And then, lastly, who are we going to inform
4:15about the information we find?
4:17And as you see, senior management.
4:19And there we go.
4:20What about delivery of a risk report, number two here?
4:24Well, as you can see, it's a little bit different
4:28because our risk practitioners are still
4:30delivering the report.
4:31They're doing the work there.
4:32And our steering committee is kind of setting this in motion.
4:35But who are we informing?
4:36We're informing both senior management
4:38and department managers.
4:40There you go.
4:41What about prioritizing risks?
4:44Well, as you can imagine, this is going
4:46to be a little higher level.
4:47Our risk practitioners are not going to be prioritizing risk.
4:51Who's doing that?
4:52That's right.
4:52That's our department managers.
4:54And who are they consulting?
4:56You better believe it, the risk practitioners down there
4:59in the trenches who are working with risk every day.
5:01And then, who's being informed?
5:04Well, the steering committee is being informed.
5:07And who is setting this in motion?
5:09That's our senior management.
5:11And then, lastly, monitoring of risks, that's
5:13our monitoring to make sure that things are going OK.
5:17Who's setting this in motion?
5:18Who's accountable?
5:19Well, that's our steering committee.
5:21And then, who's actually doing the work?
5:23Who's responsible for this, the monitoring?
5:26Absolutely, that's our risk managers.
5:28Who are they consulting to make sure it's happening?
5:31And that is our risk practitioners.
5:32And then, of course, who's being informed?
5:34Senior management.
5:35And this is a RACI chart.
5:37This is kind of how it works.
5:38As we talked about the different RACI roles, now
5:41we can see those roles in action with different tasks.
5:44So that's pretty darn neat.
5:46Moving on, there are some key risk roles.
5:50Now, we've talked about some types of roles.
5:52That was our RACI, our Responsible, Accountable,
5:55Consulted, and Informed.
5:56Those were types.
5:57Now, we're going to look at the actual roles.
5:59And we're starting off with risk manager.
6:03Now, the risk manager is responsible for making sure
6:06that risk management happens, as you can imagine.
6:09So the risk manager is responsible-- we
6:11put an R. That's our RACI term-- responsible for making sure
6:15that, well, risk management happens, right?
6:18That's their whole job.
6:19Then we have a risk analyst.
6:22That is a risk analyst.
6:25And the risk analyst is responsible.
6:28There we go.
6:28It's a RACI term for analyzing, evaluating,
6:31and assessing threats.
6:33So the risk analyst is responsible for making
6:36sure risk is analyzed.
6:38It kind of works, right?
6:40These aren't too tricky of terms.
6:41Then we have risk owner.
6:44There we go.
6:45That's next up.
6:46And the risk owner is actually the person
6:49who has the authority, and RACI term, Accountability, to make
6:54risk-based decisions, and is also
6:57responsible for any loss that occurs
6:59based on a risk scenario.
7:01So the risk owner is accountable for managing--
7:07let's put it here--
7:08managing a risk.
7:11And it could be multiple risks, but they
7:13are the owner of that risk.
7:15They manage it, and they are accountable for it.
7:19Then we have a control owner.
7:22Now, a control owner is a person accountable--
7:25that's a RACI term there--
7:26for ensuring the controls are designed and implemented
7:33to keep risk under control.
7:35So that is a control owner.
7:37Now, a control could be a security control,
7:39like a firewall.
7:40It could be a policy.
7:41It could be lots of different things.
7:44But the control owner is accountable for making sure
7:49that controls are designed and implemented.
7:51But then, we have a control steward.
7:55And a control steward is responsible--
7:58and when it comes to-- remember, responsible, we'll say,
8:02equals work.
8:04And then the accountable equals delegation.
8:07We'll put it that way.
8:09They delegate the work.
8:10But they manage whatever that is.
8:15And they delegate the tasks to those responsible.
8:19But they also manage whatever they're over,
8:21and they're responsible for it.
8:23So the control steward was responsible
8:26for like routine maintenance on controls
8:28and making control changes.
8:29So we'll say control changes.
8:34There we go.
8:35And then, lastly, we have our subject matter experts,
8:40or our SMEs.
8:42And our SMEs were those that we consulted for their advice
8:46on certain things that we were working on
8:48as it pertains to risk, because our SMEs were
8:51those with specific knowledge about areas
8:54of the organization.
8:55And we wanted their input on decision making.
8:58And there we go.
8:59These are some key risk roles.
9:01That was our risk manager, a risk analyst, risk owner,
9:05control owner, control steward, and our SMEs,
9:09or Subject Matter Experts.
9:12And let's wrap up by actually taking
9:14a look at an organizational chart and some of these roles.
9:18All right, here we go.
9:19Here's an org chart.
9:20We've got our senior management at the top.
9:22And then, over here, we've got a risk management unit.
9:26Over on the far right, we've got our assurance unit
9:28for auditing.
9:30We've got IT here.
9:31And of course, business units or like departments.
9:34So starting off, you'll notice that some of the blocks
9:37are different colors.
9:38And that's because the green blocks, like this one here,
9:42are actual roles within risk, whereas the blue boxes are not
9:47necessarily.
9:49So what we have here is in our risk management area here,
9:52we have a risk manager and a risk analyst.
9:56So I'm going to put risk in here, and risk here.
9:59That way it kind of makes that pop a little bit-- risk manager
10:02and risk analyst that we talked about.
10:05When it comes to our business units,
10:07we have risk owners and control owners.
10:11But you don't see control stewards here.
10:13That's because most often those will fall under IT.
10:17And I'm going to put control.
10:19Actually, I don't need to, because we
10:20have stewards that work on the systems and stewards that
10:22work on controls.
10:24So these are our control stewards.
10:25Now, remember, the control owners
10:27were responsible for a specific control, making sure they
10:29we created and implemented.
10:31And the control stewards actually
10:32did the day to day work with the individual controls.
10:35So these are some of the different risk roles,
10:38as you see them in an organizational chart.
10:41I hope this has been informative for you.
10:43And I'd like to thank you for viewing.
Risk Culture
0:06When it comes to information security and risk management
0:10programs, what do you think the number
0:13one factor is in the success or failure of these programs?
0:18Well, I'm going to give you a hint.
0:20It's people.
0:21And it's actually comes down to the culture
0:23of the organization.
0:25So let's jump in and talk about risk culture.
0:29Now, culture within an organization
0:32is super important because people, that's right,
0:36people are the driving force of security and risk
0:41in the organization.
0:43So it is super important that leadership set the example.
0:48If we have our org chart here, and we've got our C level
0:52execs up here at the top, and then
0:54we've got senior management, guess
0:57who needs to be setting examples of risk in security awareness
1:03and practice?
1:04That's right, those folks at the top.
1:06This needs to be a top down effort.
1:10So we said people, that was number one.
1:13Secondly was top down support, that we just talked about.
1:19Then third is there accountability within security
1:25think back to our racey.
1:26Remember our RACI that we just talked about
1:28are responsible, accountable.
1:30There it is accountable, consulted, and informed.
1:33You have to have accountability because you
1:36need to ensure that folks are accountable for their roles
1:39because if they're not-- if there's
1:40no accountability, then hey, who cares if I don't do my job?
1:44There's no accountability.
1:46That's why we've got to have it.
1:48And then lastly, we need a great security and risk awareness
1:55program.
1:56That way, everyone, all those people,
1:59are aware of security practices and risk practices
2:03and what they need to be doing within the organization.
2:07And that is part of the organizational culture
2:10when it comes to risk.
2:11But we're not done.
2:13That's because decisions, decisions, decisions,
2:16are always being made in an organization.
2:18Any mature organization, let's put this down here.
2:21A mature organization will always include risk
2:27in their decision making to make sure
2:30that they see the whole picture, all the risk that's
2:34involved in it as well as the reward because oftentimes
2:38those making decisions get drawn towards the reward,
2:41and they focus on that, and they're not considering
2:44risk in the decision.
2:46So immature organization will always include risk
2:49in its decision making, and that is
2:52risk culture within an organization
2:54and why it is so important.
2:56I hope this has been informative for you,
2:58and I'd like to thank you for reviewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
Cybersecurity
Enterprise GRC
Assign the full course, track completion, and connect this skill to your team's readiness plan.
ISACA
CRISC
Assign the full course, track completion, and connect this skill to your team's readiness plan.
For teams
Build a path around this skill
See how courses, reporting, labs, and IT Trainerbot fit your rollout.
$708
seat / year