SlideShare a Scribd company logo
1 of 16
Download to read offline
25 tips & tricks




                                               25 Examples
                                         of what you should not do

                                                         March 2009


                                                         Mr. Marc Vael
                                                        Managing Director
                                                           Valuendo

            © 2009 Valuendo. All rights reserved.
                                                                                        1
        INFORMATION CLASSIFICATION = PUBLIC




                                                                               Agenda

         •       Introduction
         •       Concept
         •       25 Statements
         •       Conclusion




            © 2009 Valuendo. All rights reserved.
                                                                                        2
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                                   InfoSecurity 2009
Valuendo                                                                          March 2009
                                                                                                1
25 tips & tricks


                                                                  Introduction
            • Marc Vael
            • Managing Director Valuendo (“value & do”) since July 2001
            • Education
               – Master Applied Economics (UAntwerp)
               – Master Information Management (UHasselt)
               – Master+ Applied Economics & ICT (KUL)
            • Core Services
               – Enterprise Risk Management
               – IT Governance
               – Information Security Management
               – Data Privacy & Protection
               – Business Continuity / Disaster Recovery
               – Crisis Management
               – IT Audit & Compliance
            • Certifications in good standing
               – CISA / CISM / CISSP / ITIL Service Manager

            © 2009 Valuendo. All rights reserved.
                                                                                   3
        INFORMATION CLASSIFICATION = PUBLIC




                                                                         Concept




            • First :
              Statement

            • Second :
              Voting on your current experience

            © 2009 Valuendo. All rights reserved.
                                                                                   4
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                              InfoSecurity 2009
Valuendo                                                                     March 2009
                                                                                           2
25 tips & tricks

                  Test : The economic crisis has no impact
                            on the way we handle security



                                                    • Fully Agree
                                                    • Do not agree
                                                    • Don’t know really



            © 2009 Valuendo. All rights reserved.
                                                                                  5
        INFORMATION CLASSIFICATION = PUBLIC




                                 Lesson 1 : Security > Business needs



                                                     •Yes
                                                     •Not always
                                                     •No



            © 2009 Valuendo. All rights reserved.
                                                                                  6
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                              InfoSecurity 2009
Valuendo                                                                     March 2009
                                                                                           3
25 tips & tricks

                                             Lesson 2 : It is the CISO who is
                                         driving security in our organisation


                                                    •Of course.
                                                    •No, the real driver is
                                                     someone else
                                                    •I’m not sure


            © 2009 Valuendo. All rights reserved.
                                                                                   7
        INFORMATION CLASSIFICATION = PUBLIC




                                   Lesson 3 : Security budget is easy to
                                       calculate and to defend/present


                                             •Absolutely
                                             •Difficult to calculate,
                                              but easy to defend / present
                                             •Not really


            © 2009 Valuendo. All rights reserved.
                                                                                   8
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                               InfoSecurity 2009
Valuendo                                                                      March 2009
                                                                                            4
25 tips & tricks

                                                    Lesson 4 : The security vision is
                                                           understood by everyone


                                                      •Yes and we even
                                                       have checked this
                                                      •We hope so
                                                      •No


            © 2009 Valuendo. All rights reserved.
                                                                                        9
        INFORMATION CLASSIFICATION = PUBLIC




                                             Lesson 5 : Everybody understands
                                                     security terminology used


                                                    •Yes we know and
                                                     we even have a glossary
                                                    •We hope so
                                                    •No


            © 2009 Valuendo. All rights reserved.
                                                                                        10
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                                InfoSecurity 2009
Valuendo                                                                       March 2009
                                                                                             5
25 tips & tricks

              Lesson 6 : Security and risk management
                          are two different professions



                                                     •Yes
                                                     •No
                                                     •Don’t know really



            © 2009 Valuendo. All rights reserved.
                                                                                  11
        INFORMATION CLASSIFICATION = PUBLIC




                                    Lesson 7 : People recognize security
                                                               incidents


                                                    •Yes and we even
                                                     have tested this
                                                    •We hope so
                                                    •No


            © 2009 Valuendo. All rights reserved.
                                                                                  12
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                              InfoSecurity 2009
Valuendo                                                                     March 2009
                                                                                           6
25 tips & tricks

                                        Lesson 8 : People know how to
                                  classify and secure their information


                                                    •Yes and we even
                                                     have tested this
                                                    •We hope so
                                                    •No


            © 2009 Valuendo. All rights reserved.
                                                                                  13
        INFORMATION CLASSIFICATION = PUBLIC




                                         Lesson 9 : Security audits are
                                  essential to determine what’s wrong



                                                         •Yes
                                                         •We hope so
                                                         •No



            © 2009 Valuendo. All rights reserved.
                                                                                  14
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                              InfoSecurity 2009
Valuendo                                                                     March 2009
                                                                                           7
25 tips & tricks

                                               Lesson 10 : Security awareness
                                            posters are the most effective tool


                                                     •Yes and we even
                                                      have checked this
                                                     •We hope so
                                                     •No


            © 2009 Valuendo. All rights reserved.
                                                                                      15
        INFORMATION CLASSIFICATION = PUBLIC




                                                    Lesson 11 : People remember all
                                                             passwords & pin-codes


                                                     •Yes and we even
                                                      have checked this
                                                     •We hope so
                                                     •No


            © 2009 Valuendo. All rights reserved.
                                                                                      16
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                               InfoSecurity 2009
Valuendo                                                                      March 2009
                                                                                            8
25 tips & tricks

                                            Lesson 12 : People always select a
                                                             strong password


                                                       •Yes and we
                                                        even enforce this
                                                       •We hope so
                                                       •No


            © 2009 Valuendo. All rights reserved.
                                                                                       17
        INFORMATION CLASSIFICATION = PUBLIC




                                                    Lesson 13 : People lock their PC
                                                       information via screen saver


                                                     •Yes and we even
                                                      have checked this
                                                     •We hope so
                                                     •No


            © 2009 Valuendo. All rights reserved.
                                                                                       18
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                               InfoSecurity 2009
Valuendo                                                                      March 2009
                                                                                            9
25 tips & tricks

                                                    Lesson 14 : People respect clean
                                                                         desk policy


                                                     •Yes and we even
                                                      have checked this
                                                     •We hope so
                                                     •No


            © 2009 Valuendo. All rights reserved.
                                                                                       19
        INFORMATION CLASSIFICATION = PUBLIC




                                             Lesson 15 : People always use the
                                                   security tools we give them


                                                     •Yes and we even
                                                      have checked this
                                                     •We hope so
                                                     •No


            © 2009 Valuendo. All rights reserved.
                                                                                       20
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                                InfoSecurity 2009
Valuendo                                                                       March 2009
                                                                                             10
25 tips & tricks

                                    Lesson 16 : IT people give the good
                                   example of respecting security rules


                                                    •Yes and we even
                                                     have checked this
                                                    •We hope so
                                                    •No


            © 2009 Valuendo. All rights reserved.
                                                                                  21
        INFORMATION CLASSIFICATION = PUBLIC




                                         Lesson 17 : People only use official
                                                       authorized software


                                                    •Yes and we even
                                                     have tested this
                                                    •We hope so
                                                    •No


            © 2009 Valuendo. All rights reserved.
                                                                                  22
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                              InfoSecurity 2009
Valuendo                                                                     March 2009
                                                                                           11
25 tips & tricks

                                   Lesson 18 : Only naughty people get
                                                   naughty spam mails



                                                        •Yes
                                                        •No
                                                        •Don’t know really



            © 2009 Valuendo. All rights reserved.
                                                                                  23
        INFORMATION CLASSIFICATION = PUBLIC




                               Lesson 19 : Only dumb people fall for
                                             phishing scams / mails



                                                        •Yes
                                                        •No
                                                        •Don’t know really



            © 2009 Valuendo. All rights reserved.
                                                                                  24
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                              InfoSecurity 2009
Valuendo                                                                     March 2009
                                                                                           12
25 tips & tricks

                          Lesson 20 : People mention their
                     backups in their OOO when unavailable



                                                        •Yes
                                                        •No
                                                        •Don’t know really



            © 2009 Valuendo. All rights reserved.
                                                                                  25
        INFORMATION CLASSIFICATION = PUBLIC




                                Lesson 21 : People suggest alternative
                             communication channels when unavailable



                                                        •Yes
                                                        •No
                                                        •Don’t know really



            © 2009 Valuendo. All rights reserved.
                                                                                  26
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                              InfoSecurity 2009
Valuendo                                                                     March 2009
                                                                                           13
25 tips & tricks

                         Lesson 22 : People know & respect
                     security rules when at other companies



                                                        •Yes
                                                        •No
                                                        •Don’t know really



            © 2009 Valuendo. All rights reserved.
                                                                                  27
        INFORMATION CLASSIFICATION = PUBLIC




                                  Lesson 23 : People need full internet
                                       access for professional reasons



                                                        •Yes
                                                        •No
                                                        •Don’t know really



            © 2009 Valuendo. All rights reserved.
                                                                                  28
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                              InfoSecurity 2009
Valuendo                                                                     March 2009
                                                                                           14
25 tips & tricks

                      Lesson 24 : People know how to secure
                       their wired & wireless network access



                                                        •Yes
                                                        •No
                                                        •Don’t know really



            © 2009 Valuendo. All rights reserved.
                                                                                  29
        INFORMATION CLASSIFICATION = PUBLIC




                                   Lesson 25 : Security is still better on
                                           paper than on digital format



                                                        •Yes
                                                        •No
                                                        •Don’t know really



            © 2009 Valuendo. All rights reserved.
                                                                                  30
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                              InfoSecurity 2009
Valuendo                                                                     March 2009
                                                                                           15
25 tips & tricks


                                                                                   Conclusion




            © 2009 Valuendo. All rights reserved.
                                                                                                31
        INFORMATION CLASSIFICATION = PUBLIC




                                                                   Contact information
                                                      Mr. Marc Vael, CISA, CISM, CISSP, ITIL
                                                      Managing Director
                                                      Valuendo
                                                      Kriebrugstraat 33
                                                      1760 Roosdaal
                                                      Belgium
                                                      T: +32 5 433 61 93
                                                      M: +32 473 99 30 31
                                                      M: mvael@valuendo.com
                                                         mvael@valuendo.com
                                                      W: www.valuendo.com

            © 2009 Valuendo. All rights reserved.
                                                                                                32
        INFORMATION CLASSIFICATION = PUBLIC




Marc Vael                                                                          InfoSecurity 2009
Valuendo                                                                                 March 2009
                                                                                                       16

More Related Content

Similar to 25 tips & tricks document with security lessons

Tech Ed 2009 Practical Tips To Manage Projects Productively
Tech Ed 2009   Practical Tips To Manage Projects ProductivelyTech Ed 2009   Practical Tips To Manage Projects Productively
Tech Ed 2009 Practical Tips To Manage Projects Productivelyrsnarayanan
 
BCS (Isle of Man): Implications for Project Management in an uncertain Island...
BCS (Isle of Man): Implications for Project Management in an uncertain Island...BCS (Isle of Man): Implications for Project Management in an uncertain Island...
BCS (Isle of Man): Implications for Project Management in an uncertain Island...Owen Cutajar
 
Mobileye Focus 7 2010 Low
Mobileye Focus 7 2010 LowMobileye Focus 7 2010 Low
Mobileye Focus 7 2010 LowMobileye
 
Business Planning for Success - 5 Essential Steps
Business Planning for Success - 5 Essential StepsBusiness Planning for Success - 5 Essential Steps
Business Planning for Success - 5 Essential StepsWalter Adamson
 
Issa Charlotte 2009 Patching Your Users
Issa Charlotte 2009   Patching Your UsersIssa Charlotte 2009   Patching Your Users
Issa Charlotte 2009 Patching Your UsersMike Murray
 
Presentation Mi Retail Uk New
Presentation Mi Retail Uk NewPresentation Mi Retail Uk New
Presentation Mi Retail Uk NewMoupi
 
MI Retail *** our offer
MI Retail *** our offerMI Retail *** our offer
MI Retail *** our offerMoupi
 
how to secure web applications with owasp - isaca sep 2009 - for distribution
how to secure web applications  with owasp - isaca sep 2009 - for distributionhow to secure web applications  with owasp - isaca sep 2009 - for distribution
how to secure web applications with owasp - isaca sep 2009 - for distributionSantosh Satam
 
A Course Worth Staying?
A Course Worth Staying?A Course Worth Staying?
A Course Worth Staying?Jason Griffith
 
Valuendo Aiesec Importance Of Planning (2001) Handout
Valuendo Aiesec Importance Of Planning (2001) HandoutValuendo Aiesec Importance Of Planning (2001) Handout
Valuendo Aiesec Importance Of Planning (2001) HandoutMarc Vael
 
Cracking the Di Vinci Code of Professional Sales Excellence - FPA Conference...
Cracking the Di Vinci Code of Professional Sales Excellence  - FPA Conference...Cracking the Di Vinci Code of Professional Sales Excellence  - FPA Conference...
Cracking the Di Vinci Code of Professional Sales Excellence - FPA Conference...Warrick Pleash
 
Ideas to Income: Introduction to marketing (Part 2)
Ideas to Income: Introduction to marketing (Part 2)Ideas to Income: Introduction to marketing (Part 2)
Ideas to Income: Introduction to marketing (Part 2)MaRS Discovery District
 
CMMI Guide to the Perplexed
CMMI Guide to the PerplexedCMMI Guide to the Perplexed
CMMI Guide to the PerplexedHillel Glazer
 
5 Ingredients Of The EVM Secret Sauce V Final
5 Ingredients Of The EVM Secret Sauce V Final5 Ingredients Of The EVM Secret Sauce V Final
5 Ingredients Of The EVM Secret Sauce V Finalphlckb
 
10步选择正确CRM系统
10步选择正确CRM系统10步选择正确CRM系统
10步选择正确CRM系统Richard Qi
 
Rapid Cost Take Out
Rapid Cost Take OutRapid Cost Take Out
Rapid Cost Take Outfvalkenburg
 
Saudi emc today presentation
Saudi emc today presentationSaudi emc today presentation
Saudi emc today presentationadityapuri
 

Similar to 25 tips & tricks document with security lessons (20)

Tech Ed 2009 Practical Tips To Manage Projects Productively
Tech Ed 2009   Practical Tips To Manage Projects ProductivelyTech Ed 2009   Practical Tips To Manage Projects Productively
Tech Ed 2009 Practical Tips To Manage Projects Productively
 
BCS (Isle of Man): Implications for Project Management in an uncertain Island...
BCS (Isle of Man): Implications for Project Management in an uncertain Island...BCS (Isle of Man): Implications for Project Management in an uncertain Island...
BCS (Isle of Man): Implications for Project Management in an uncertain Island...
 
Mobileye Focus 7 2010 Low
Mobileye Focus 7 2010 LowMobileye Focus 7 2010 Low
Mobileye Focus 7 2010 Low
 
Business Planning for Success - 5 Essential Steps
Business Planning for Success - 5 Essential StepsBusiness Planning for Success - 5 Essential Steps
Business Planning for Success - 5 Essential Steps
 
Issa Charlotte 2009 Patching Your Users
Issa Charlotte 2009   Patching Your UsersIssa Charlotte 2009   Patching Your Users
Issa Charlotte 2009 Patching Your Users
 
Presentation Mi Retail Uk New
Presentation Mi Retail Uk NewPresentation Mi Retail Uk New
Presentation Mi Retail Uk New
 
MI Retail *** our offer
MI Retail *** our offerMI Retail *** our offer
MI Retail *** our offer
 
how to secure web applications with owasp - isaca sep 2009 - for distribution
how to secure web applications  with owasp - isaca sep 2009 - for distributionhow to secure web applications  with owasp - isaca sep 2009 - for distribution
how to secure web applications with owasp - isaca sep 2009 - for distribution
 
A Course Worth Staying?
A Course Worth Staying?A Course Worth Staying?
A Course Worth Staying?
 
Valuendo Aiesec Importance Of Planning (2001) Handout
Valuendo Aiesec Importance Of Planning (2001) HandoutValuendo Aiesec Importance Of Planning (2001) Handout
Valuendo Aiesec Importance Of Planning (2001) Handout
 
12 Clicks To Clarity
12 Clicks To Clarity12 Clicks To Clarity
12 Clicks To Clarity
 
Effective Risk Mgmt Kylucas (C) 2009 All Rights Reserved
Effective Risk Mgmt Kylucas (C) 2009 All Rights ReservedEffective Risk Mgmt Kylucas (C) 2009 All Rights Reserved
Effective Risk Mgmt Kylucas (C) 2009 All Rights Reserved
 
Cracking the Di Vinci Code of Professional Sales Excellence - FPA Conference...
Cracking the Di Vinci Code of Professional Sales Excellence  - FPA Conference...Cracking the Di Vinci Code of Professional Sales Excellence  - FPA Conference...
Cracking the Di Vinci Code of Professional Sales Excellence - FPA Conference...
 
Ideas to Income: Introduction to marketing (Part 2)
Ideas to Income: Introduction to marketing (Part 2)Ideas to Income: Introduction to marketing (Part 2)
Ideas to Income: Introduction to marketing (Part 2)
 
Welcome to E&C
Welcome to E&CWelcome to E&C
Welcome to E&C
 
CMMI Guide to the Perplexed
CMMI Guide to the PerplexedCMMI Guide to the Perplexed
CMMI Guide to the Perplexed
 
5 Ingredients Of The EVM Secret Sauce V Final
5 Ingredients Of The EVM Secret Sauce V Final5 Ingredients Of The EVM Secret Sauce V Final
5 Ingredients Of The EVM Secret Sauce V Final
 
10步选择正确CRM系统
10步选择正确CRM系统10步选择正确CRM系统
10步选择正确CRM系统
 
Rapid Cost Take Out
Rapid Cost Take OutRapid Cost Take Out
Rapid Cost Take Out
 
Saudi emc today presentation
Saudi emc today presentationSaudi emc today presentation
Saudi emc today presentation
 

More from Marc Vael

How secure are chat and webconf tools
How secure are chat and webconf toolsHow secure are chat and webconf tools
How secure are chat and webconf toolsMarc Vael
 
my experience as ciso
my experience as cisomy experience as ciso
my experience as cisoMarc Vael
 
Advantages of privacy by design in IoE
Advantages of privacy by design in IoEAdvantages of privacy by design in IoE
Advantages of privacy by design in IoEMarc Vael
 
Cybersecurity governance existing frameworks (nov 2015)
Cybersecurity governance existing frameworks (nov 2015)Cybersecurity governance existing frameworks (nov 2015)
Cybersecurity governance existing frameworks (nov 2015)Marc Vael
 
Cybersecurity nexus vision
Cybersecurity nexus visionCybersecurity nexus vision
Cybersecurity nexus visionMarc Vael
 
ISACA Reporting relevant IT risks to stakeholders
ISACA Reporting relevant IT risks to stakeholdersISACA Reporting relevant IT risks to stakeholders
ISACA Reporting relevant IT risks to stakeholdersMarc Vael
 
Cloud security lessons learned and audit
Cloud security lessons learned and auditCloud security lessons learned and audit
Cloud security lessons learned and auditMarc Vael
 
Value-added it auditing
Value-added it auditingValue-added it auditing
Value-added it auditingMarc Vael
 
ISACA Internet of Things open forum presentation
ISACA Internet of Things open forum presentationISACA Internet of Things open forum presentation
ISACA Internet of Things open forum presentationMarc Vael
 
hoe kan u vandaag informatie veiligheid realiseren op een praktische manier?
hoe kan u vandaag informatie veiligheid realiseren op een praktische manier?hoe kan u vandaag informatie veiligheid realiseren op een praktische manier?
hoe kan u vandaag informatie veiligheid realiseren op een praktische manier?Marc Vael
 
The value of big data analytics
The value of big data analyticsThe value of big data analytics
The value of big data analyticsMarc Vael
 
Social media risks and controls
Social media risks and controlsSocial media risks and controls
Social media risks and controlsMarc Vael
 
The view of auditor on cybercrime
The view of auditor on cybercrimeThe view of auditor on cybercrime
The view of auditor on cybercrimeMarc Vael
 
ISACA Mobile Payments Forum presentation
ISACA Mobile Payments Forum presentationISACA Mobile Payments Forum presentation
ISACA Mobile Payments Forum presentationMarc Vael
 
Belgian Data Protection Commission's new audit programme
Belgian Data Protection Commission's new audit programmeBelgian Data Protection Commission's new audit programme
Belgian Data Protection Commission's new audit programmeMarc Vael
 
ISACA Cloud Computing Risks
ISACA Cloud Computing RisksISACA Cloud Computing Risks
ISACA Cloud Computing RisksMarc Vael
 
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handoutInformation security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handoutMarc Vael
 
ISACA smart security for smart devices
ISACA smart security for smart devicesISACA smart security for smart devices
ISACA smart security for smart devicesMarc Vael
 
Securing big data (july 2012)
Securing big data (july 2012)Securing big data (july 2012)
Securing big data (july 2012)Marc Vael
 
Valuendo cyberwar and security (jan 2012) handout
Valuendo cyberwar and security (jan 2012) handoutValuendo cyberwar and security (jan 2012) handout
Valuendo cyberwar and security (jan 2012) handoutMarc Vael
 

More from Marc Vael (20)

How secure are chat and webconf tools
How secure are chat and webconf toolsHow secure are chat and webconf tools
How secure are chat and webconf tools
 
my experience as ciso
my experience as cisomy experience as ciso
my experience as ciso
 
Advantages of privacy by design in IoE
Advantages of privacy by design in IoEAdvantages of privacy by design in IoE
Advantages of privacy by design in IoE
 
Cybersecurity governance existing frameworks (nov 2015)
Cybersecurity governance existing frameworks (nov 2015)Cybersecurity governance existing frameworks (nov 2015)
Cybersecurity governance existing frameworks (nov 2015)
 
Cybersecurity nexus vision
Cybersecurity nexus visionCybersecurity nexus vision
Cybersecurity nexus vision
 
ISACA Reporting relevant IT risks to stakeholders
ISACA Reporting relevant IT risks to stakeholdersISACA Reporting relevant IT risks to stakeholders
ISACA Reporting relevant IT risks to stakeholders
 
Cloud security lessons learned and audit
Cloud security lessons learned and auditCloud security lessons learned and audit
Cloud security lessons learned and audit
 
Value-added it auditing
Value-added it auditingValue-added it auditing
Value-added it auditing
 
ISACA Internet of Things open forum presentation
ISACA Internet of Things open forum presentationISACA Internet of Things open forum presentation
ISACA Internet of Things open forum presentation
 
hoe kan u vandaag informatie veiligheid realiseren op een praktische manier?
hoe kan u vandaag informatie veiligheid realiseren op een praktische manier?hoe kan u vandaag informatie veiligheid realiseren op een praktische manier?
hoe kan u vandaag informatie veiligheid realiseren op een praktische manier?
 
The value of big data analytics
The value of big data analyticsThe value of big data analytics
The value of big data analytics
 
Social media risks and controls
Social media risks and controlsSocial media risks and controls
Social media risks and controls
 
The view of auditor on cybercrime
The view of auditor on cybercrimeThe view of auditor on cybercrime
The view of auditor on cybercrime
 
ISACA Mobile Payments Forum presentation
ISACA Mobile Payments Forum presentationISACA Mobile Payments Forum presentation
ISACA Mobile Payments Forum presentation
 
Belgian Data Protection Commission's new audit programme
Belgian Data Protection Commission's new audit programmeBelgian Data Protection Commission's new audit programme
Belgian Data Protection Commission's new audit programme
 
ISACA Cloud Computing Risks
ISACA Cloud Computing RisksISACA Cloud Computing Risks
ISACA Cloud Computing Risks
 
Information security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handoutInformation security awareness (sept 2012) bis handout
Information security awareness (sept 2012) bis handout
 
ISACA smart security for smart devices
ISACA smart security for smart devicesISACA smart security for smart devices
ISACA smart security for smart devices
 
Securing big data (july 2012)
Securing big data (july 2012)Securing big data (july 2012)
Securing big data (july 2012)
 
Valuendo cyberwar and security (jan 2012) handout
Valuendo cyberwar and security (jan 2012) handoutValuendo cyberwar and security (jan 2012) handout
Valuendo cyberwar and security (jan 2012) handout
 

Recently uploaded

NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdfKhaled Al Awadi
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCRashishs7044
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfRbc Rbcua
 
Chapter 9 PPT 4th edition.pdf internal audit
Chapter 9 PPT 4th edition.pdf internal auditChapter 9 PPT 4th edition.pdf internal audit
Chapter 9 PPT 4th edition.pdf internal auditNhtLNguyn9
 
8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCRashishs7044
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCRashishs7044
 
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort ServiceCall US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Servicecallgirls2057
 
Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Americas Got Grants
 
International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...ssuserf63bd7
 
Market Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMarket Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMintel Group
 
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCRashishs7044
 
Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Seta Wicaksana
 
Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Kirill Klimov
 
Memorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMMemorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMVoces Mineras
 
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCRashishs7044
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCRashishs7044
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03DallasHaselhorst
 

Recently uploaded (20)

NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdfNewBase  19 April  2024  Energy News issue - 1717 by Khaled Al Awadi.pdf
NewBase 19 April 2024 Energy News issue - 1717 by Khaled Al Awadi.pdf
 
Call Us ➥9319373153▻Call Girls In North Goa
Call Us ➥9319373153▻Call Girls In North GoaCall Us ➥9319373153▻Call Girls In North Goa
Call Us ➥9319373153▻Call Girls In North Goa
 
8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR8447779800, Low rate Call girls in Saket Delhi NCR
8447779800, Low rate Call girls in Saket Delhi NCR
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdf
 
Corporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information TechnologyCorporate Profile 47Billion Information Technology
Corporate Profile 47Billion Information Technology
 
Chapter 9 PPT 4th edition.pdf internal audit
Chapter 9 PPT 4th edition.pdf internal auditChapter 9 PPT 4th edition.pdf internal audit
Chapter 9 PPT 4th edition.pdf internal audit
 
8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR8447779800, Low rate Call girls in Rohini Delhi NCR
8447779800, Low rate Call girls in Rohini Delhi NCR
 
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
8447779800, Low rate Call girls in Kotla Mubarakpur Delhi NCR
 
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort ServiceCall US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
Call US-88OO1O2216 Call Girls In Mahipalpur Female Escort Service
 
Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...Church Building Grants To Assist With New Construction, Additions, And Restor...
Church Building Grants To Assist With New Construction, Additions, And Restor...
 
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCREnjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
Enjoy ➥8448380779▻ Call Girls In Sector 18 Noida Escorts Delhi NCR
 
International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...International Business Environments and Operations 16th Global Edition test b...
International Business Environments and Operations 16th Global Edition test b...
 
Market Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 EditionMarket Sizes Sample Report - 2024 Edition
Market Sizes Sample Report - 2024 Edition
 
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR8447779800, Low rate Call girls in Tughlakabad Delhi NCR
8447779800, Low rate Call girls in Tughlakabad Delhi NCR
 
Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...Ten Organizational Design Models to align structure and operations to busines...
Ten Organizational Design Models to align structure and operations to busines...
 
Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024Flow Your Strategy at Flight Levels Day 2024
Flow Your Strategy at Flight Levels Day 2024
 
Memorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMMemorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQM
 
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
8447779800, Low rate Call girls in Shivaji Enclave Delhi NCR
 
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
8447779800, Low rate Call girls in New Ashok Nagar Delhi NCR
 
Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03Cybersecurity Awareness Training Presentation v2024.03
Cybersecurity Awareness Training Presentation v2024.03
 

25 tips & tricks document with security lessons

  • 1. 25 tips & tricks 25 Examples of what you should not do March 2009 Mr. Marc Vael Managing Director Valuendo © 2009 Valuendo. All rights reserved. 1 INFORMATION CLASSIFICATION = PUBLIC Agenda • Introduction • Concept • 25 Statements • Conclusion © 2009 Valuendo. All rights reserved. 2 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 1
  • 2. 25 tips & tricks Introduction • Marc Vael • Managing Director Valuendo (“value & do”) since July 2001 • Education – Master Applied Economics (UAntwerp) – Master Information Management (UHasselt) – Master+ Applied Economics & ICT (KUL) • Core Services – Enterprise Risk Management – IT Governance – Information Security Management – Data Privacy & Protection – Business Continuity / Disaster Recovery – Crisis Management – IT Audit & Compliance • Certifications in good standing – CISA / CISM / CISSP / ITIL Service Manager © 2009 Valuendo. All rights reserved. 3 INFORMATION CLASSIFICATION = PUBLIC Concept • First : Statement • Second : Voting on your current experience © 2009 Valuendo. All rights reserved. 4 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 2
  • 3. 25 tips & tricks Test : The economic crisis has no impact on the way we handle security • Fully Agree • Do not agree • Don’t know really © 2009 Valuendo. All rights reserved. 5 INFORMATION CLASSIFICATION = PUBLIC Lesson 1 : Security > Business needs •Yes •Not always •No © 2009 Valuendo. All rights reserved. 6 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 3
  • 4. 25 tips & tricks Lesson 2 : It is the CISO who is driving security in our organisation •Of course. •No, the real driver is someone else •I’m not sure © 2009 Valuendo. All rights reserved. 7 INFORMATION CLASSIFICATION = PUBLIC Lesson 3 : Security budget is easy to calculate and to defend/present •Absolutely •Difficult to calculate, but easy to defend / present •Not really © 2009 Valuendo. All rights reserved. 8 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 4
  • 5. 25 tips & tricks Lesson 4 : The security vision is understood by everyone •Yes and we even have checked this •We hope so •No © 2009 Valuendo. All rights reserved. 9 INFORMATION CLASSIFICATION = PUBLIC Lesson 5 : Everybody understands security terminology used •Yes we know and we even have a glossary •We hope so •No © 2009 Valuendo. All rights reserved. 10 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 5
  • 6. 25 tips & tricks Lesson 6 : Security and risk management are two different professions •Yes •No •Don’t know really © 2009 Valuendo. All rights reserved. 11 INFORMATION CLASSIFICATION = PUBLIC Lesson 7 : People recognize security incidents •Yes and we even have tested this •We hope so •No © 2009 Valuendo. All rights reserved. 12 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 6
  • 7. 25 tips & tricks Lesson 8 : People know how to classify and secure their information •Yes and we even have tested this •We hope so •No © 2009 Valuendo. All rights reserved. 13 INFORMATION CLASSIFICATION = PUBLIC Lesson 9 : Security audits are essential to determine what’s wrong •Yes •We hope so •No © 2009 Valuendo. All rights reserved. 14 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 7
  • 8. 25 tips & tricks Lesson 10 : Security awareness posters are the most effective tool •Yes and we even have checked this •We hope so •No © 2009 Valuendo. All rights reserved. 15 INFORMATION CLASSIFICATION = PUBLIC Lesson 11 : People remember all passwords & pin-codes •Yes and we even have checked this •We hope so •No © 2009 Valuendo. All rights reserved. 16 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 8
  • 9. 25 tips & tricks Lesson 12 : People always select a strong password •Yes and we even enforce this •We hope so •No © 2009 Valuendo. All rights reserved. 17 INFORMATION CLASSIFICATION = PUBLIC Lesson 13 : People lock their PC information via screen saver •Yes and we even have checked this •We hope so •No © 2009 Valuendo. All rights reserved. 18 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 9
  • 10. 25 tips & tricks Lesson 14 : People respect clean desk policy •Yes and we even have checked this •We hope so •No © 2009 Valuendo. All rights reserved. 19 INFORMATION CLASSIFICATION = PUBLIC Lesson 15 : People always use the security tools we give them •Yes and we even have checked this •We hope so •No © 2009 Valuendo. All rights reserved. 20 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 10
  • 11. 25 tips & tricks Lesson 16 : IT people give the good example of respecting security rules •Yes and we even have checked this •We hope so •No © 2009 Valuendo. All rights reserved. 21 INFORMATION CLASSIFICATION = PUBLIC Lesson 17 : People only use official authorized software •Yes and we even have tested this •We hope so •No © 2009 Valuendo. All rights reserved. 22 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 11
  • 12. 25 tips & tricks Lesson 18 : Only naughty people get naughty spam mails •Yes •No •Don’t know really © 2009 Valuendo. All rights reserved. 23 INFORMATION CLASSIFICATION = PUBLIC Lesson 19 : Only dumb people fall for phishing scams / mails •Yes •No •Don’t know really © 2009 Valuendo. All rights reserved. 24 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 12
  • 13. 25 tips & tricks Lesson 20 : People mention their backups in their OOO when unavailable •Yes •No •Don’t know really © 2009 Valuendo. All rights reserved. 25 INFORMATION CLASSIFICATION = PUBLIC Lesson 21 : People suggest alternative communication channels when unavailable •Yes •No •Don’t know really © 2009 Valuendo. All rights reserved. 26 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 13
  • 14. 25 tips & tricks Lesson 22 : People know & respect security rules when at other companies •Yes •No •Don’t know really © 2009 Valuendo. All rights reserved. 27 INFORMATION CLASSIFICATION = PUBLIC Lesson 23 : People need full internet access for professional reasons •Yes •No •Don’t know really © 2009 Valuendo. All rights reserved. 28 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 14
  • 15. 25 tips & tricks Lesson 24 : People know how to secure their wired & wireless network access •Yes •No •Don’t know really © 2009 Valuendo. All rights reserved. 29 INFORMATION CLASSIFICATION = PUBLIC Lesson 25 : Security is still better on paper than on digital format •Yes •No •Don’t know really © 2009 Valuendo. All rights reserved. 30 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 15
  • 16. 25 tips & tricks Conclusion © 2009 Valuendo. All rights reserved. 31 INFORMATION CLASSIFICATION = PUBLIC Contact information Mr. Marc Vael, CISA, CISM, CISSP, ITIL Managing Director Valuendo Kriebrugstraat 33 1760 Roosdaal Belgium T: +32 5 433 61 93 M: +32 473 99 30 31 M: mvael@valuendo.com mvael@valuendo.com W: www.valuendo.com © 2009 Valuendo. All rights reserved. 32 INFORMATION CLASSIFICATION = PUBLIC Marc Vael InfoSecurity 2009 Valuendo March 2009 16