thecybersecurityreview

MAY - AUG - 2020CYBERSECURITY REVIEW 19 Pre-Project PlanningComplete an initial risk questionnaire (IRQ). Ensure the questionnaire is broad enough to determine cyber risk and trigger information security work areas (hard or soft), leading to informal discussions around level of effort, dependencies, cost, etc. that will be used to SWAG the project. Project EvaluationsThe formal project package should include the IRQ, base cyber risk rating, and input from Security. This will give the business a transparent view into the risk of the project.Project is Green lighted Depending on the cyber risk rating, have different levels of involvement from Information Security. · Low ­ Consultation and reference to the various policies, procedures, control frameworks, and laws they are responsible for being compliant to.· Medium ­ Information security is possibly a stakeholder or at the least, a subject matter expert (SME) involved at strategic touch points and milestones, and mandatory workshops (discussed shortly). · High ­ Same as medium, plus information security become stakeholders. Project managers manage risk, with added awareness of security concerns (covered in the workshops). Does this change alter the security posture? Have you run that change by Information Security? Etc.WorkshopsThe resources and stakeholders go through workshops tailored to their roles (technical and non-technical). The material covered should include all the relevant company policies, procedures, frameworks, laws, and where to find them. This sets the tone, making resources responsible for baking in "Security" and establishing that information security's role is to help guide and verify compliance, not do it for them.In many cases, project resources are vulnerable to risks they thought were someone else's responsibility. For example: hard coded passwords, use of insecure protocols, using production data in non-production environments, etc. Workshops help close the gaps in security and privacy knowledge and provide resources the added benefit of awareness into controls that auditors validate against, making resources better able to "defend" their choices. In conclusion, information security, much like legal, privacy, and HR, is enabling the business to traverse muddy waters as quickly as possible while avoiding the rocky shores (breach, fines, sanctions, etc.). By ensuring information security is part of the pre- and ongoing project process, there will be minimal security surprises, thereby avoiding delays, reducing risk, and helping protect the company against liability.
< Page 9 | Page 11 >