enterprisesecuritymag

November 2016ENTERPRISE SECURITY| | 9StepDescriptionPerformed byDefineDefine the technologies and documentProcess owner & ISOCategorizeCategorize the risks and document. (Note: Do not use subjective High, Medium, Low classifications. Instead, use classic operations research questions that score/categorize the risk exposure objectively.)Process owner & ISOAssessMeet to communicate the likelihood of an occurrence, its potential magnitude, and discuss recommendations to reduce the risk.Process owner & implementerAction PlansImplement and communicate action plans with specified controls to lower the riskProcess owner & implementerCheckTest the controls to ensure the actual risk exposure matches the desired risk levelISOVerifyPrior to and following transition to production, monitor and track changes to the technology risks from internal and external sourcesISOto clampdown on networks, circuits, routers, servers, applications, desktops, laptops, phones, etc. This knee-jerk reaction reduces the effectiveness of the tool, limits productivity, and is often a one-size-fits-all policy that spends money in the wrong places, and establishes policies for areas that are not at risk. The policies become more restrictive, the procedures become more cumbersome, and before long, the policy becomes so stifling the business/enterprise suffers, the main security goal is not achieved, and the ISO gets a bad name. The reputation of the ISO suffers, and the high- level security goal that the ISO aspires to is not achieved.Now let's talk about risk-based security strategy in terms of steps, considerations, and challenges to implement a security risk-based strategy in the organization.Steps: Although there are many risk based frameworks that can be adopted, here are six simple steps for the risk based strategy based on Evan Wheeler's "Security Risk Management" book, ed. 2011: Based on an adaptation of Evan Wheeler's Security Risk Management book, 2011.Considerations: Do you have restrictive regulatory requirements that drive most of your security efforts? Would your internal audit function be opposed to a risk-based approach vs. traditional "mall cop" methods? Are you getting high security value from your security investment? Does your program already have deep acceptance by your business? If the answers are yes, you may want to keep your current program. If no, then you should consider adopting risk-based security strategies.Challenges: If this were easy, everyone would be doing it. Making the change requires persistence and common sense. For example, not all devices require the same protection. Not every department or business unit needs the same security. Role-based security is another example. There are more risks for an IT administrator than other administrators. Another challenge is that the security team needs expertise in developing a current state, a risk profile and an action plan to implement the risk-based strategy. Another hurdle to overcome is that project managers and engineers often want a security checklist as soon as possible, often before the risks are known. This requires a bit of change management and expectation setting. One final challenge might be how you help your internal auditors figure out how to do their jobs without relying solely on an ISO, COBIT, or PCI checklist. They need to understand risk profiles and how assessments were made. A risk-based security strategy is a cost-effective way to implement safeguards and ensure your organization is properly protected. ES A risk-based security strategy is a cost-effective way to implement safeguards and ensure your organization is properly protected
< Page 8 | Page 10 >