ERE Information Security Auditors
Home | Site Map | Contact Us | Blog
This text is replaced by the Flash movie.
Executive Strategies for Managing Risk
Audit Tactics for Managing Risk

Posts Tagged ‘IT Governance’

IT Security Micro Governance – A Practical Alternative Part 1

Tuesday, December 22nd, 2009

This week’s blog is the first of a three part series about my idea for an expedited method of implementing IT security Governance.  Your feed back would be most appreciated.

Executive Summary

IT Governance is difficult for most organizations to initiate and maintain as it is an ongoing process, particularly for medium and small institutions. There are many subject experts, vendors, and consultants that cater to implementation, but the inherent difficulties and complexities make the implementation of it an elusive goal for many.

Since Governance is, by definition, strategic and focused over long timeframes, it is not designed to deal with unexpected and potentially costly IT security threats. Threats which can evolve into costly security events.  A distraught client once described how a serious access breach within his organization could have been prevented if the senior management had evaluated and acted upon his impromptu but appropriate recommendations to harden access controls.  The author proposes a modified process to respond to mitigating threats that require funds exceeding the annual IT security budget. I call this micro Governance.

Definitions of IT Governance

IT Governance is a subset discipline of Corporate Governance focused on information technology (IT) systems and their performance and risk management.  Various bodies of authority on the subject publish similar definitions of IT Governance, each with its own emphasis of intent.  Four prominent authorities define IT governance on their web sites as follows:
1. ISACA: …provide the leadership, organizational structures and processes that ensure that the enterprise’s IT sustains and extends the enterprise’s strategies and objectives.
2. ITGI:… an effective IT governance framework that addresses strategic alignment, performance measurement, risk management, value delivery and resource management.
3. Forrester: … The act of establishing IT decision structures, processes, and communication mechanisms in support of the business objectives and tracking progress against fulfilling business obligations efficiently and consistently.
4. MIT Sloan School of Management:  IT governance is the process by which firms align actions with their performance goals and assign accountability for those actions and their outcomes.
The three predominant frameworks for implementing IT Governance are provided by ISACA, ITIL and ISO.  In a more granular view, the ISO 38500:2008 guiding principles are organized into three prime sections, specifically Scope, Framework and Guidance.  The framework comprises definitions, principles and a model. It sets out six principles for good corporate governance of IT:
* Responsibility
* Strategy
* Acquisition
* Performance
* Conformance
* Human behaviour
Significance of IT Security Governance for Compliance
Compliance violations may attract all manner of liability directly affecting a governance committee, such as fines and confinement for SOX, revocation of interconnection agreements with electrical utilities for NERC CIP, and violation notices from third party auditors for COBIT.

Examples of well known regulatory frameworks and compliance standards are as follows:
* Financial  -  SOX, Bill 109, Basel II, PCI, SAS 70
* Electrical Infrastructure for North America  -  NERC CIP
* Privacy  – PIPEDA, Red Flag, GLB
* Industry Best Practices -  COBIT, ITIL

Next week’s blog will cover the problems caused by insufficient Governance and the root causes of this problem.

Have a secure week.

Regards, Ron Lepofsky, B.A. SC. (Mech Eng), CISSP
ERE Information Security Auditors

www.ere-security.ca

Micro IT Governance to Really Achieve Compliance Part 2

Tuesday, December 8th, 2009

Last week I posted a rough draft of part 1 of 2 an article devoted to a concept I am creating called Micro-Governance. Next weeks’ post is part 2 of 2 would greatly appreciate your ideas / feedback / constructive criticism.  Thank you in advance for sharing your ideas with me.

Barriers to implementing IT Governance

  • All encompassing scope
  • Complex PPM Project Portfolio Management
  • Expensive
  • Time consuming
  • Risk is very difficult to quantify
  • False sense of security confuses cost justifying security budgets
  • Turf wars over accepting / relegating ownership of responsibilities
  • Maintaining longevity of the process

Micro – Governance a practical alternative

  • Minimize liability of executives / board
  • Facilitates communications between Governance and the Security Team regarding cost justification of budget
  • Provides a regular opportunity for the Security Team to convey top priorities with requests for executive authorization
  • Minimizes decision time and frustration levels by identifying bite sized issues
  • Quantify the few most threatening risks
  • Create a virtual team with responsibility to mitigate and report
  • Measure the results
  • Authorize / fund the virtual team

Call to Action

  • CEO and CIO discuss a few  top priority IT security risks that require immediate decisions / funding
  • Formally create a micro-Governance process to address each risk.
  • Engage a third party advisor to expedite the process.
  • Create a small virtual team to manage each risk management process.
  • Assign other management and employees as appropriate to the virtual team.
  • Identify a timeline to complete the project.
  • Identify a mechanism to test the degree of success of the mitigation
  • Identify a timeline to report the degree of success back to the IT Governance Committee.

Assess Financial Cost of Risk and Residual Risk

  • document the technical risks
  • Translate them into business risks
  • Utilize a straw poll for executives to estimate the cost of liability should the risks become realities.
  • Utilize a straw poll for technology experts to guestimate the % chance of a onetime occurrence both before and after mitigation steps are applied.
  • Compare the cost of risk vs. residual risk to the cost of mitigation

Create Longevity to the Micro- Governance Process(es)

  • Direct the virtual team(s) to continue monitoring and report according to a defined schedule Committee
  • Otherwise dissolve the virtual team(s)

Sources of Information – Governance Authorities

Have a secure week.

Regards, Ron Lepofsky, B.A. SC. (Mech Eng), CISSP

ERE Information Security Auditors

www.ere-security.ca

Micro IT Governance to Really Achieve Compliance Part 1

Tuesday, November 17th, 2009

This week I am sharing with you a rough draft of part 1 of 2 an article devoted to a concept I am creating called Micro-Governance.  I would greatly appreciate your ideas / feedback / constructive criticism.  Thank you in advance for sharing your ideas with me.

Executive Summary

IT Governance is difficult for most organizations, large and small, to initiate and to maintain as an ongoing process.  There are many organizations, vendors, and consultants that cater to the needs of IT governance.   Yet because of its inherent difficulties and complexities, IT Governance eludes most organizations.  The author proposes a dramatically scaled down approach to achieving and to successfully implementing bite sized pieces of critical elements of the Governance process, aptly named Micro-Governance.

Definitions of IT Governance

Various bodies of authority on the subject publish similar definitions of IT Governance, each with its own emphasis of intent.  Three prominent authorities say the following:

  1. ISACA: …provide the leadership, organizational structures and processes that ensure that the enterprise’s IT sustains and extends the enterprise’s strategies and objectives.
  2. ITGI:… an effective IT governance framework that addresses strategic alignment, performance measurement, risk management, value delivery and resource management.

Significance of IT Governance for Compliance

IT Governance deals with the following subjects:

However, the scope of this whitepaper is confined to IT Governance as it applies to compliance to standards and regulations imposed by statutes and by governing bodies.

Compliance violations may attracts all manner of liability directly affecting a governance committee, such as fines and confinement for SOX, revocation of interconnection agreements with electrical utilities for NERC CIP, and violation notices from third party auditors for COBIT.

Legal Counsel and external auditors recommend compliance with standards and regulations

  • Financial SOX, Bill 109, PCI, SAS 70
  • Electrical Infrastructure for North America NERC CIP
  • Privacy PIPEDA, Red Flag, GLB
  • Industry Best Practice Standards: COBIT, ITIL,

Insufficient Governance Impedes the Security Team

  • Slows decision making
  • Inhibits communication of risk and associated financial loss from IT Security Team
  • Inhibits attaining sufficient IT security budget

Have a secure week.

Regards, Ron Lepofsky, B.A. SC. (Mech Eng), CISSP

ERE Information Security Auditors

www.ere-security.ca

Sources of Information – Governance Authorities


Home | Point in Time Audit | Doc Audit/Authorship | 7x24 Monitoring | Knowledge Transfer | ERE Differentiators | About Us | Site map | Contact Us | Blog
Copyrights © 2007-2008. All rights reserved.  Non-security resources 1|2|3|4|5|6|7|8|9

   AddThis Social Bookmark Button