the business of security is the strategy of the business...the panel brian tuskan chief security...

26
The Business of Security is the Strategy of the Business “What’s in your wallet?”

Upload: others

Post on 20-Aug-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

The Business of Security is the Strategyof the Business

“What’s in your wallet?”

Page 2: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

Moderator

Ron WormanManaging DirectorThe Sage Group Producer, The Great Conversation in Security

Page 3: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

The Panel

Brian TuskanChief Security Officer

Microsoft

Dr. Linda Florence, CPP

PresidentThe Florence Group

Tim Wenzel, CPPProgram Manager

Facebook

Jeff Slotnick, CPP, PSPPresident Setracon

Page 4: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

Learning objectives

• After attending this session, participants will be able to apply a strategy for change management

• After attending this session, participants will be able to understand the importance of developing and applying key performance indicators and metrics

• After attending this session, participants will be able to comprehend the importance of risk assessment and its role in strategic alignment

Page 5: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

Defining Terms

Page 6: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

Changing the Value Equation

• Traditional Definition of Risk• “exposure to danger, with potential for injury or

loss.”

• ISO31000’s New Definition of Risk• “the effect of uncertainty on objectives, whether

positive or negative.”

Page 7: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

ISO 31000

Page 8: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

Chief Security Officer

Page 9: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

What is a business model?

Page 10: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

Change Management

Kotter “Leading Change”

Page 11: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

Metrics that Matter to the Program

and to the Business

Page 12: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

Enterprise Security Risk Management

https://esrm.info/esrm/ https://COSO.ORG

Enterprise Risk Management

Page 13: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

Panel Questions

Page 14: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

Is it common or rare that security leaders are engaging the true owners of risk?

Page 15: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

What are the common obstacles in doing this?

Page 16: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

How do you engage the owners of risk?

Page 17: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

Are there accessible models in education or through associations like ASIS for doing this?

Page 18: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

Is there a core process you follow?

Page 19: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,
Page 20: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

How do you collaborate on the findings?

Page 21: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

How do you create a measurable action plan?

Page 22: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

Summary of Findings

Page 23: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

Resources

Page 24: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

https://www.iso.org/iso-31000-risk-management.html

https://www.theirm.org/ (Institute of Risk Management)

https://www.eosworldwide.com/what-is-eos

https://www.jimcollins.com/books/turning-the-flywheel.html#articletop

https://www.kotterinc.com/book/our-iceberg-is-melting/

https://www.innosight.com/insight/reinvent-your-business-model/

Competency Models for Enterprise Security and Cybersecurity (University of Phoenix)

https://www.asisonline.org/publications/sg-chief-security-officer-an-organizational-model/

Private Security Officer Selection and Training (ASIS)

https://www.amazon.com/Change-Management-including-featured-Leading/

Page 25: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,
Page 26: The Business of Security is the Strategy of the Business...The Panel Brian Tuskan Chief Security Officer Microsoft Dr. Linda Florence, CPP President The Florence Group Tim Wenzel,

*https://www.asisonline.org/publications--resources/news/blog/esrm-an-enduring-security-risk-model/