Information Security Governance Overview

Video Activity

This lesson will cover information security governance within the role of the CISO. Information security governance is the set of responsibilities and practices implemented by the board and senior management for protecting the C-I-A of information. Information security governance should therefore: Provide long-term goals and short-term objectives I...

Join over 3 million cybersecurity professionals advancing their career
Sign up with
or

Already have an account? Sign In »

Time
3 hours 54 minutes
Difficulty
Advanced
CEU/CPE
4
Video Description

This lesson will cover information security governance within the role of the CISO. Information security governance is the set of responsibilities and practices implemented by the board and senior management for protecting the C-I-A of information. Information security governance should therefore:

  • Provide long-term goals and short-term objectives
  • Include metrics by which to determine success
  • Be based on sound risk management principals
  • Ensure that the enterprise's resources are used appropriately
  • Require an in-depth understanding of the value of an organization's information

Ultimately the responsibility for information security must rest upon the organization's executive level. Information security is an executive responsibility because: - If an organization's senior management, including the boards of directors, senior executives and all managers does not establish and reinforce the business need for effective enterprise security; the organizations desired state of security will not be articulated, achieved, or sustained

  • To achieve a sustainable capability, organizations must make enterprise security the responsibility of leaders at the governance level and not of other organizational roles that lack the authority, accountability and resources to act and enforce compliance

Security is a non-negotiable aspect of the business environment, because if you don't protect your information you will be out of business.

Video Transcription
00:04
all right, So in looking at the C I A Triad, how does that fit in with information, security? Governance? Well, that's where the ultimate responsibility of senior management comes in. So when we do talk about information, security, governance, it's all the total responsibilities,
00:22
the practices that policies
00:24
that air set out by the board and senior management, for which they will ultimately be held accountable
00:31
for the C I. A. The confidentiality, integrity and availability. And I know that we talked about access control in the I Triple A, and we'll talk more about that later, and that's an important idea. But really, when we talk about the fundamentals of security, it's the C I. A. Try it. Confidentiality,
00:49
integrity and availability
00:52
and
00:53
governments needs to specify are broad goals as well as our objectives that will help us meet those goals. We already, you know, again talk about the smart goals so you'll see they should be specific. We should have metrics so that we can measure whether or not we're being successful.
01:10
Um, one of the things that we'll talk about in the very next chapter is risk management.
01:15
Everything that we do is gonna be based on risk and risk is gonna help us understand what the potential for losses so that we can balance that up with the cost of a countermeasure and make good, responsible decisions based on security, governance
01:32
and again because we're looking at a cost benefit analysis that's gonna make sure that we use our resource is appropriately as well. Now this last bullet point is so very important. We have tohave an in depth understanding of the value of an organization's information.
01:52
How much is it worth? And let me tell you, the value of that information comes from so many different areas. For instance, do we have a legal responsibility to protect that information?
02:04
So is it P I? I personally identifiable information? Is that health information? Is it financial information?
02:13
Is it information that's critical to the success of our organization with compromise? If this information put human lives at stake
02:23
is their intellectual property? Does that property have value to my customers? So the value of information comes from a lot of different directions,
02:31
and sometimes that's very hard to quantitatively identify right to give a numeric value for so we do have to have a good understanding of the value of what we're protecting because ultimately,
02:45
uh, we're not gonna spend more money
02:46
than what we're protecting is worth. But we certainly want to make sure that we spend enough money toe adequately, adequately secure our information
02:55
Now from there just going back and re emphasizing because it's so important for chief information security officer to really understand why we need that executive level roll dealing with security. So if we look at this first sentence, governing security means viewing
03:15
adequate security as non negotiable.
03:19
It's a requirement of being in business and, you know, as an information security professional, that's just a given to me. If you don't protect your information, you're gonna be out of business. But you would be amazed at how many organizations look at information security as a necessary evil. And
03:38
when I say a necessary evil, it's only necessary
03:42
when it's required by law or it's only necessary when the board members dictated. And it's one of those things we've got to go through, Um,
03:53
but if you have anybody in executive leadership that is not on board with the security function than the company culture, the company's architecture the company strategy is going to suffer for it, and we're gonna wind up failing to precut to proactively protector assets.
04:12
Then we're gonna have a security compromise and then all of that. And then finally, my guess would be
04:17
those executives are now gonna be on board with security after suffering a tremendous loss. Let's avoid that. Let's go ahead and be practice. Let's be proactive in our approach to security. All right, So this thing, this chief information security officer we've talked about the C I A. Triad.
04:36
Well, it's a sister who's responsible
04:40
for assessing the risks associated with C i O and creating the policies designed to ah si eso assessing the risks with C I A. And then developing and implementing policies that will protect confidentiality, integrity and availability.
05:00
They also serve kind of as a go between because they work with the other elements within senior management,
05:05
Chief executive officer, chief operations officer, chief financial officer. All of those folks are very important in providing security for the organization. So I'm constantly is a sizzle, working with each of those other officers, and sometimes I'm playing, you know, the game of selling security to them,
05:26
but ultimately is about managing risks and understanding what those risks are. So that's my job.
05:33
I'm gonna establish those policies or certainly make my recommendations for policies. I'm gonna make sure that their measurements and that we have an auditing mechanism in place so that we can determine if the policies and procedures are working and it's they're being followed and find out any issues of noncompliance. I also
05:53
would stress that part of my role as well in a very significant part of my role,
05:58
is to make sure we maintain compliance and their numerous regulations and legislation pieces that are out there that really dictate how we have to protect our information, whether it's, um,
06:13
health information, personally identifiable information, financial information, whatever that may be.
06:19
There. We have to look to the industry regulations and make sure that we're in compliance. That's my job is a sizzle as well.
06:30
And then, of course, making sure that I'm aware of emerging threats. If my organization is prepared for the threats of today,
06:38
we're already a step behind because Attackers are very forward thinking as soon as one mechanisms been secured, they're looking to find another vulnerability that they can exploit. So I have to be very knowledgeable and well versed
06:51
in emerging trends within the security fields as well. So a lot of responsibilities go to This is, um
07:00
now there are other roles within the organization not be familiar with. You know, we talked about the CEO, the chief executive officer, Well, there, that individual that has. Or that's the individual that has the ultimate say on implementations within the organization. And if we're talking about selling security,
07:18
the CEO has to be on board. Of course,
07:23
now the chief financial officer signs the checks. So this is someone that you want in your corner, and this is someone that you want to understand and especially the need for talking in terms of risk management. Rather than throwing a whole lot of terminology and acronyms and
07:39
and cyber Burbage at them, we really have to just break it down and speak in terms of lost potential
07:46
and cost of mitigating strategies.
07:47
Hey, uh, it's not here. There's some organizations have a separate chief information officer, making sure that there's an alignment between technologies. A lot of times that gets rolled up or the scissors rolled up in the C I O Row. Sometimes they're separate and sometimes not. And then I didn't mention on the slide. But the chief
08:09
operating officer, of course, that oversees the ultimate operations of the organization. Ultimately, when we look at having security audits and a security team that's designed for the purpose of audit, that actually wind up answering to the chief
08:24
operating officer rather than answer necessarily to the information security officer, because as a scissors oh, my job is to develop the plans and make sure that they're implemented. But the auditing teams gonna make sure that I've done my job well. So obviously they wouldn't be answering
08:41
to me
08:41
other roles and responsibilities within the organization steering committee. Usually, this is ah, specific group. A lot of times you have steering committees directed towards solving a specific problem.
08:56
So you look a steering committee that's going to assess the possibility of opening a branch office in another location,
09:03
something like that. Auditors evaluate business processes. Of course, we've talked about them on Remember auditors, audit auditors don't fix problems, they document problems, and we return that to senior management to determine a means of correcting the problems they sound
09:22
are two additional rolls here. Data folders and data custodians. So when we talk about the older of the data, these are the folks that determine the classification of the dab It they determine the value of the data. They determine who should access the data.
09:39
So it's their data. Essentially, all those elements mean
09:41
they're the ones that evaluate the data. Okay, then it's the data custodian who is responsible for enforcing the security. So where is the data custodian May say, this should be classified as secret. I'm sorry. The data owner would say this should be classified as secret.
10:00
It's the custodian that implements the security controls that enforce that classification.
10:05
They're also responsible for backing up and being able to restore death. A lot of times, the custodian is a function of the I T department or the I s department. Okay. And then the final two rebels Network administrator in security administrator.
10:22
In many smaller organizations, the same individuals satisfied both these roles. That really is a problem from a round of separation of duties, because when we look at the network administrator there, specific function is availability to make network resource is available
10:39
now, the security administrator should be looking
10:43
to satisfy the security requirements first and foremost, so there's a little bit of a conflict of interest. But again, don't forget. Security administrators are there to make sure that security policies air being followed. We're gonna see audit is part of the security team. We want to make sure that someone's evaluating with the network administrator does,
11:03
so those two should really very much be separate Rose.
Up Next
Chief Information Security Officer (CISO)

In this CISO certification training, you will learn what other CISO's are focusing their time and attention on. Among the key topics, you will learn how to implement the proven best practices that make for successful cyber security leadership.

Instructed By