digital risk is operational risk

21
1 Copyright 2013 EMC Corporation. All rights reserved. Digital Risk is Operational Risk Art Coviello, Jr. Chairman, RSA The Security Division of EMC Click icon to add picture Nov. 1, 2013

Upload: sherri

Post on 24-Feb-2016

44 views

Category:

Documents


7 download

DESCRIPTION

Digital Risk is Operational Risk. Art Coviello, Jr. Chairman, RSA The Security Division of EMC . Nov. 1, 2013. FEAR. MADAME MARIE CURIE. UNDERSTANDING. AWARENESS. ≠. PERSPECTIVE. THE ATTACK SURFACE. THE THREAT ENVIRONMENT. EVOLUTION OF SECURITY MODELS. BILLIONS OF USERS. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Digital Risk is Operational Risk

1© Copyright 2013 EMC Corporation. All rights reserved.

Digital Risk is Operational RiskArt Coviello, Jr. Chairman, RSAThe Security Division of EMC

Click icon to add picture

Nov. 1, 2013

Page 2: Digital Risk is Operational Risk

FEAR

Page 3: Digital Risk is Operational Risk

3© Copyright 2011 EMC Corporation. All rights reserved.

MADAMEMARIE CURIE

Page 4: Digital Risk is Operational Risk

≠UNDERSTANDINGAWARENESS

Page 5: Digital Risk is Operational Risk

• THE THREAT ENVIRONMENT

• THE ATTACK SURFACE

PERSPECTIVE

• EVOLUTION OF SECURITY MODELS

Page 6: Digital Risk is Operational Risk

6© Copyright 2013 EMC Corporation. All rights reserved.

Mainframe, Mini ComputerTerminals

LAN/Internet Client/ServerPC

Cloud Big Data SocialMobile Devices

1ST PLATFORM

2ND PLATFORM

3RD PLATFORM

MILLIONS OF USERS

THOUSANDS/TENS OF THOUSANDS

OF APPS

HUNDREDS OF MILLIONS OF USERS

TENS/HUNDREDS OF THOUSANDS

OF APPS

BILLIONSOF USERS

MILLIONS/BILLIONSOF APPS

Source: IDC, 2012

2010

1990

1970

Page 7: Digital Risk is Operational Risk

7© Copyright 2013 EMC Corporation. All rights reserved.

2007 20202013

Attack Surface

Social Media

Focus onmonetizing

Total Commercialization of social media:

absence of privacyMySpace

Page 8: Digital Risk is Operational Risk

8© Copyright 2013 EMC Corporation. All rights reserved.

2007 20202013

Attack Surface

Apps

Web Front Ended apps

There’s an “app” for that

Big Data Apps Everywhere!

Page 9: Digital Risk is Operational Risk

9© Copyright 2013 EMC Corporation. All rights reserved.

2007 20202013Digital Content

ZETTABYTE¼

ZETTABYTES2

ZETTABYTES40-60?

Attack Surface

Page 10: Digital Risk is Operational Risk

10© Copyright 2013 EMC Corporation. All rights reserved.

Attack Surface

2007 20202013Devices

Smartphones

Mobile Ubiquity smartphone/tablet

Not just PCsNot justmobile devices

Internetof things

Page 11: Digital Risk is Operational Risk

11© Copyright 2013 EMC Corporation. All rights reserved.

Invertedno real perimeter in age of

mobility and cloud

Porousnumerous portals, web

based ERP and CRM

Attack Surface

2007 20202013Perimeter

Virtualno control over physical

infrastructure

Page 12: Digital Risk is Operational Risk

12© Copyright 2013 EMC Corporation. All rights reserved.

TIME 2007 2013

ATTACK METHODS

Method

Worms/Viruses

SimpleDDoS

PhishingPharming

APTsMulti-Stage

HackerCollaboration

DisruptiveAttacks

2020

DestructiveAttacks

IntrusiveAttacks

AdvancedDDoS

SophisticatedMobileAttacks

The Unknown??

Page 13: Digital Risk is Operational Risk

DIGITALRISK

BUSINESS

Page 14: Digital Risk is Operational Risk

KNOWLEDGE

Page 15: Digital Risk is Operational Risk

15© Copyright 2013 EMC Corporation. All rights reserved.

Perimeter-based Static Controls Siloed Management

System

HistoricalReactive Intelligence Driven

Risk-based Dynamic/Agile Controls Contextual/Interactive

Management System

Security Models

New

Page 16: Digital Risk is Operational Risk

KNOWNUNUNKNOWNS

Page 17: Digital Risk is Operational Risk

17© Copyright 2013 EMC Corporation. All rights reserved.

Management Controls

Intelligence Driven Model

Page 18: Digital Risk is Operational Risk

Risk & Compliance Management Today

Page 19: Digital Risk is Operational Risk

Risk & Compliance Management in the Future

Visibility CollaborationAutomation AccountabilityEfficiency

Page 20: Digital Risk is Operational Risk

Integrating GRC Across the Organization

Enterprise RiskIT Business

• IT Audit• Availability (DR)• IT Security Risk• Security Operations

• 3rd Party Risk• Policy & Controls• Business Continuity• Incident & Response

• Regulatory Risk• Operational Risk• Corporate Governance• Audit & Compliance

Common Foundation

CIO/CISO

Board & CXOs LOB / Functional Executive

Practitioner

Page 21: Digital Risk is Operational Risk

21© Copyright 2013 EMC Corporation. All rights reserved.

Trust in theDigital World