Topic 1 - Information Security Governance
Topic 1 - Information Security Governance
Topic 1 - Information Security Governance
Topic 1
Information Security Governance
Mentor Introduction
• Jeremy Koster
• 17 years in Information / Cyber Security
• Qualifications and Industry Certifications
• Experience
• Lecturing for IT Masters and CSU for 8 years
House Keeping
Webinars
• Zoom – Video Hop
• Thursday 8:30pm AEST
The Forum
• Lively and respectful discussions are encouraged
• Weekly readings
• Weekly discussion questions
The Exam
• 20 multiple choice questions
• 10 shorts answer questions
• 2 long answer questions
Management
• Risk management
• Process improvement
• Event identification
• Incident response
• Improved compliance
• Business continuity and disaster recovery planning
• Metrics
• Resource management
• Improved IT governance
Security governance activities and results
• Risk management
• Process improvement
ti o n
u ta
Rep Trust
• Event identification
• Incident response
• Improved compliance a nd
• Business continuity and disaster recovery planning
• Metrics
• Resource management
• Improved IT governance
Business alignment
• Mission
• Goals and objectives
• Strategy
• Culture
• Asset value
• Risk tolerance
• Legal obligations
• Market conditions
Roles and responsibilities
• Senior Management
– Strategic security objectives
– Functions, resources and supporting infrastructure
• Steering Committee
– Strategy delivery and integration efforts
– Emerging risk and compliance issues
Effective metrics
• Meaningful
• Accurate
• Cost-effective (automated)
• Repeatable
• Predictive
• Actionable
• Genuine
Metrics and standards
• People
• Process
• Technology
• ORGANISATION
• Culture
• Governing
• Architecture
Current Climate
Information Security Strategy
• Personnel
• Resources
• Capabilities
- Expertise and skills
• Time
• Risk acceptance and tolerance
• Management perception and urgency
Review / discussion questions
1. Why is executive engagement and buy-in crucial for addressing risk in an
organisation?
2. Why do we determine the desired state before analysing the current state?