SlideShare una empresa de Scribd logo
1 de 25
Descargar para leer sin conexión
Information Security (Un)Awareness


              Information Security
                 (un)awareness




                        Marc Vael
                   International Vice-President




            “My management
            just does not “get”
                information
                 security!”
                   Anonymous CISO of a large financial institution




Marc Vael                                                 CONFENIS
ISACA                                                September 2012
                                                                      1
Information Security (Un)Awareness



             “I am overwhelmed with
             all the passwords I have
             to remember. I just write
            them down & leave them
                 with my executive
                     assistant.”
                 Anonymous manager working in an insurance company




               “Management has
            authorized acquisition of
            security monitoring tools,
            but they did not give me
            any budget for people to
              do this monitoring.”
                 Anonymous CISO of a multinational service organisation




Marc Vael                                                       CONFENIS
ISACA                                                      September 2012
                                                                            2
Information Security (Un)Awareness




                 “Sure, I support
              information security,
             but my people need to
            work and make money.”
                                     Anonymous CEO of a retailer




        “Our information security
        department keeps getting
         more tools, but I do not
         think we are any more
                 secure.”
                    Anonymous CRO of a large financial institution




Marc Vael                                                 CONFENIS
ISACA                                                September 2012
                                                                      3
Information Security (Un)Awareness




              “Security policy is one
            thing. Reality is another.”
                     Anonymous COO from a consulting company




              “All that information
             security people do is
                    say “No!”.
            They should learn how
                we really work.
                       Angry manager of a governmental agency




Marc Vael                                              CONFENIS
ISACA                                             September 2012
                                                                   4
Information Security (Un)Awareness




Marc Vael                             CONFENIS
ISACA                            September 2012
                                                  5
Information Security (Un)Awareness




Marc Vael                             CONFENIS
ISACA                            September 2012
                                                  6
Information Security (Un)Awareness




Marc Vael                             CONFENIS
ISACA                            September 2012
                                                  7
Information Security (Un)Awareness




                           Cyberwarfare is
                           "the fifth domain of
                           warfare“




Marc Vael                                 CONFENIS
ISACA                                September 2012
                                                      8
Information Security (Un)Awareness

        Impact of an attack on the business




Marc Vael                                    CONFENIS
ISACA                                   September 2012
                                                         9
Information Security (Un)Awareness




            People are the weakest link.
            You can have the best technology,
            firewalls, intrusion-detection systems,
            biometric devices - and somebody
            can call an unsuspecting employee.
            That's all she wrote, baby.
            They got everything.
                                 Kevin Mitnick, ex hacker, IT security consultant.




Marc Vael                                                          CONFENIS
ISACA                                                         September 2012
                                                                                     10
Information Security (Un)Awareness




        Business Model for Information Security




Marc Vael                                              CONFENIS
ISACA                                             September 2012
                                                                   11
Information Security (Un)Awareness




Marc Vael                             CONFENIS
ISACA                            September 2012
                                                  12
Information Security (Un)Awareness




Marc Vael                             CONFENIS
ISACA                            September 2012
                                                  13
Information Security (Un)Awareness




            Managing risks appropriately

Marc Vael                                CONFENIS
ISACA                               September 2012
                                                     14
Information Security (Un)Awareness



            Risk always exists!
             (whether or not it is
            detected / recognised
            by the organisation).




Marc Vael                             CONFENIS
ISACA                            September 2012
                                                  15
Information Security (Un)Awareness


                 EDUCATION!




Marc Vael                             CONFENIS
ISACA                            September 2012
                                                  16
Information Security (Un)Awareness




Marc Vael                             CONFENIS
ISACA                            September 2012
                                                  17
Information Security (Un)Awareness




        Corporate governance : ERM = COSO




            Support from Board of Directors &
                Executive Management


Marc Vael                                        CONFENIS
ISACA                                       September 2012
                                                             18
Information Security (Un)Awareness




               Policies & Standards




             Project Management
Marc Vael                                  CONFENIS
ISACA                                 September 2012
                                                       19
Information Security (Un)Awareness




            Providing proper funding




        Providing proper resources
Marc Vael                                   CONFENIS
ISACA                                  September 2012
                                                        20
Information Security (Un)Awareness




            Measuring performance




               Review / Audit
Marc Vael                             CONFENIS
ISACA                            September 2012
                                                  21
Information Security (Un)Awareness




            Your security solution
               is as strong …




                           … as its weakest link




Marc Vael                                        CONFENIS
ISACA                                       September 2012
                                                             22
Information Security (Un)Awareness




Marc Vael                             CONFENIS
ISACA                            September 2012
                                                  23
Information Security (Un)Awareness




       www.isaca.org/knowledgecenter




Marc Vael                                   CONFENIS
ISACA                                  September 2012
                                                        24
Information Security (Un)Awareness




       www.isaca.org/cobit




        For more information…
            Marc Vael
            International Vice-President
            Chairman of the Knowledge Board

            ISACA



            http://www.isaca.org/

                    marc@vael.net
                    http://www.linkedin.com/in/marcvael
                    @marcvael


Marc Vael                                              CONFENIS
ISACA                                             September 2012
                                                                   25

Más contenido relacionado

Más de CONFENIS 2012

A Decision Support System Based on RCM Approach to Define Maintenance Strategies
A Decision Support System Based on RCM Approach to Define Maintenance StrategiesA Decision Support System Based on RCM Approach to Define Maintenance Strategies
A Decision Support System Based on RCM Approach to Define Maintenance Strategies
CONFENIS 2012
 

Más de CONFENIS 2012 (20)

Understanding the role of knowledge management during the ERP implementation ...
Understanding the role of knowledge management during the ERP implementation ...Understanding the role of knowledge management during the ERP implementation ...
Understanding the role of knowledge management during the ERP implementation ...
 
Effect of ERP implementation on the company efficiency - A Macedonian case
Effect of ERP implementation on the company efficiency - A Macedonian caseEffect of ERP implementation on the company efficiency - A Macedonian case
Effect of ERP implementation on the company efficiency - A Macedonian case
 
User perceptions, motivations and implications on ERP usage: An Indian Higher...
User perceptions, motivations and implications on ERP usage: An Indian Higher...User perceptions, motivations and implications on ERP usage: An Indian Higher...
User perceptions, motivations and implications on ERP usage: An Indian Higher...
 
Enterprise Information Systems Security: A Case Study in the Banking Sector
Enterprise Information Systems Security: A Case Study in the Banking SectorEnterprise Information Systems Security: A Case Study in the Banking Sector
Enterprise Information Systems Security: A Case Study in the Banking Sector
 
[Dutch] ICT & Ryhove: een geslaagd huwelijk?
[Dutch] ICT & Ryhove: een geslaagd huwelijk?[Dutch] ICT & Ryhove: een geslaagd huwelijk?
[Dutch] ICT & Ryhove: een geslaagd huwelijk?
 
[Dutch] CRM en collaboration: een verstandshuwelijk of een LAT-relatie?
[Dutch] CRM en collaboration: een verstandshuwelijk of een LAT-relatie?[Dutch] CRM en collaboration: een verstandshuwelijk of een LAT-relatie?
[Dutch] CRM en collaboration: een verstandshuwelijk of een LAT-relatie?
 
[Dutch] E-commerce en ERP
[Dutch] E-commerce en ERP[Dutch] E-commerce en ERP
[Dutch] E-commerce en ERP
 
[Dutch] Sociale media en crisiscommunicatie
[Dutch] Sociale media en crisiscommunicatie[Dutch] Sociale media en crisiscommunicatie
[Dutch] Sociale media en crisiscommunicatie
 
[Dutch] Zelf opstellen van bedrijfsprocessen - BPM & DMS: nieuwe manier van d...
[Dutch] Zelf opstellen van bedrijfsprocessen - BPM & DMS: nieuwe manier van d...[Dutch] Zelf opstellen van bedrijfsprocessen - BPM & DMS: nieuwe manier van d...
[Dutch] Zelf opstellen van bedrijfsprocessen - BPM & DMS: nieuwe manier van d...
 
[Dutch] ICT-INSPIRATIEDAG - CONFENIS 2012
[Dutch] ICT-INSPIRATIEDAG - CONFENIS 2012[Dutch] ICT-INSPIRATIEDAG - CONFENIS 2012
[Dutch] ICT-INSPIRATIEDAG - CONFENIS 2012
 
[Dutch] Van Enterprise Resource Planning (ERP) voor kmo’s naar Collectief Res...
[Dutch] Van Enterprise Resource Planning (ERP) voor kmo’s naar Collectief Res...[Dutch] Van Enterprise Resource Planning (ERP) voor kmo’s naar Collectief Res...
[Dutch] Van Enterprise Resource Planning (ERP) voor kmo’s naar Collectief Res...
 
[Dutch] JIT 2.0. - een methode voor ondersteunen van proces-automatisatie en ...
[Dutch] JIT 2.0. - een methode voor ondersteunen van proces-automatisatie en ...[Dutch] JIT 2.0. - een methode voor ondersteunen van proces-automatisatie en ...
[Dutch] JIT 2.0. - een methode voor ondersteunen van proces-automatisatie en ...
 
[Dutch] Software is een middel, geen doel!
[Dutch] Software is een middel, geen doel![Dutch] Software is een middel, geen doel!
[Dutch] Software is een middel, geen doel!
 
What's beyond ERP? New normal ERP? by Ludo Van den Kerckhove
What's beyond ERP? New normal ERP? by Ludo Van den KerckhoveWhat's beyond ERP? New normal ERP? by Ludo Van den Kerckhove
What's beyond ERP? New normal ERP? by Ludo Van den Kerckhove
 
[Dutch] Wat zijn sociale mediagebruikers, melkkoeien of onbetaalde werknemers...
[Dutch] Wat zijn sociale mediagebruikers, melkkoeien of onbetaalde werknemers...[Dutch] Wat zijn sociale mediagebruikers, melkkoeien of onbetaalde werknemers...
[Dutch] Wat zijn sociale mediagebruikers, melkkoeien of onbetaalde werknemers...
 
Group preference aggregation based on ELECTRE methods for ERP system selection
Group preference aggregation based on ELECTRE methods for ERP system selectionGroup preference aggregation based on ELECTRE methods for ERP system selection
Group preference aggregation based on ELECTRE methods for ERP system selection
 
A Multicriteria Model for Strategic Implementation of Business Process Manage...
A Multicriteria Model for Strategic Implementation of Business Process Manage...A Multicriteria Model for Strategic Implementation of Business Process Manage...
A Multicriteria Model for Strategic Implementation of Business Process Manage...
 
Some Considerations on Contracts ERP Buyer-Seller perspective
Some Considerations on Contracts ERP Buyer-Seller perspectiveSome Considerations on Contracts ERP Buyer-Seller perspective
Some Considerations on Contracts ERP Buyer-Seller perspective
 
A Decision Support System Based on RCM Approach to Define Maintenance Strategies
A Decision Support System Based on RCM Approach to Define Maintenance StrategiesA Decision Support System Based on RCM Approach to Define Maintenance Strategies
A Decision Support System Based on RCM Approach to Define Maintenance Strategies
 
Evolutionary Approach for EIS Strategy Decision Making Framework and Efficien...
Evolutionary Approach for EIS Strategy Decision Making Framework and Efficien...Evolutionary Approach for EIS Strategy Decision Making Framework and Efficien...
Evolutionary Approach for EIS Strategy Decision Making Framework and Efficien...
 

Último

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 

Último (20)

Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Introduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDMIntroduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDM
 

Information security (un)awareness by Marc Vael