22
Cover your Ass(ets) Security is Simple

Security is sim

Embed Size (px)

DESCRIPTION

 

Citation preview

Page 1: Security is sim

Cover your Ass(ets)

Security is Simple

Page 2: Security is sim

• Discuss diff in types of environments– Physical everyone can see people who do not belong– Digital you can need to do more inspection to see who

does not belong, in many cases.– Secretary knows where physical assets are but not

necessarily what they contain– IT has access to everything see what people have done,

and can change things, who watches the watch

Page 3: Security is sim

Common Aspects

• Proper defense involves layering.• Both employ security measures that block certain entry• Both require detection to be effective.

Page 4: Security is sim

Stacking == reactive addition/change

• Quick we need a firewall we were hacked• OMG we need Antivirus 2010 & Antivirus 360 we need

new antivirus programs• Security caught someone wandering in the secure fenced

in area we need to replace the barbed wire with razor wire.

Page 5: Security is sim

Layering == Planned addition/change

• Lets review our sec policy, TJX & Google were hacked• We got hit by AV2010 lets look at our user training &

policies• Lets look at where we need to be in 6 months to a year to

remain secure• Lets look at the trends in crime around out buildings and

make sure physical security is up to snuff.

Page 6: Security is sim

Know your ASSETS

• Gold• Chemicals• Livestock• Crops• Paper• Cars• Children• Family • House

• Personal Data?• SSN? Banking Info• Trade Secrets• Government Secrets• TOP SECRET?• Prisoners• Infrastructure• Airplanes

Page 7: Security is sim

How are they classified

• Confidential,• Secret, • top secret, • tssci • FOUO• Important• Normal• Business critical• etc

Page 8: Security is sim
Page 9: Security is sim

What are you protecting them from

• Thieves• Predators• Spills• Weather• Contamination• Fire/Ice/Water• Insider Threat• Assassins

• Hackers• War• Spies• Auditors• Criminals• Fraud• Piracy• Pirates

Page 10: Security is sim

Determine your priorities

Decide what you are protecting,

and what your protecting it from!

PRIORITIES

Page 11: Security is sim

How do you protect your priorities

• Determine who needs access and when• What level of risk are you going to accept• What is available

– Laws?– Technology?– Physical assets (fences, guards, …)

• Does it need to be monitored• Who is the responsible charge.

Page 12: Security is sim

Are there Legal requirements

• What do you need to comply with• SOX • HIPPA• PCI• PII• RED FLAG• Military regs?• State & Local Laws.

Page 13: Security is sim

RISK

• What level of risk is acceptable for each type of asset

• What is YOUR level of risk? Write SHIT DOWN! Mail/email it to your boss to CYA

Page 14: Security is sim

Developing the plan

• Time line, how long will it take to get from where you are now to where you need to go

• What is the cost estimate.• Where does that fall in priorities

Page 15: Security is sim

OMFG

• That costs too much• Re evaluate the levels of Acceptable Risk and the

associates costs

Page 16: Security is sim

Write the plan

• Review the requirements• Review the plan• Does it meet the goals?• Implement the plan.

Page 17: Security is sim

Proactive

Review

FutureRewrite

Implement

Page 18: Security is sim
Page 19: Security is sim
Page 20: Security is sim
Page 21: Security is sim

Physical & Virtual Security

• In many respects Physical & Virtual Security are similar.

Page 22: Security is sim

• Layering Vs Stacking (physical)• Layering Vs Stacking (Virtual )• Know what you are protecting?• What are you protecting it from?• What are the priorities?• What can you not lose?• What are the regulatory requirements?• What laws do you have to follow?• What is the acceptable level of risk• How long will it take to get there• how much is it going to cost• What is the true acceptable level of risk?• How long will it really take?• Determine a strategy.• How can you tell when something has gone

wrong• Come up with procedures & Policies • Put it together in a plan• review the plan• Send it for approval• "correct" the plan• test the plan• Fix the plan• Finalize the plan• implement the plan• Review it periodically. WHAT!! WHY? We did

it right