the rational approach to disruptive information security

26
Information Information Security Security Juggernaut Juggernaut The Rational Approach to Disruptive Information Security By Ravila Helen White, CISSP, CISM, CISA, GCIH, ITIL v.3 ij ij Making it better without making it Making it better without making it complex complex

Upload: ravila-white

Post on 14-Apr-2017

225 views

Category:

Technology


3 download

TRANSCRIPT

Page 1: The Rational Approach to Disruptive Information Security

Information Security Information Security

JuggernautJuggernaut

The Rational Approach to Disruptive Information Security

By Ravila Helen White, CISSP, CISM, CISA, GCIH, ITIL v.3

ijijMaking it better without making Making it better without making it complexit complex

Page 2: The Rational Approach to Disruptive Information Security

DisclaimerDisclaimerThis presentation and the concepts

herein are my opinions through private research, practice and chatting with other professionals.

It is not the opinion of past, present or future employers.

Page 3: The Rational Approach to Disruptive Information Security

AgendaAgendaChecklist(s) – What is wrong

about them…Understanding Disruption– It’s

the driver behind technology we must secure…

How to be disruptive – NIST won’t help you but…

Page 4: The Rational Approach to Disruptive Information Security

Checklist(s)Checklist(s)What is wrong about them….

Page 5: The Rational Approach to Disruptive Information Security

Find a standardFind a best practicePerform a gap analysisTrain our usersAll the boxes for the auditors are

checked

Going down the wrong Going down the wrong path…path…

Page 6: The Rational Approach to Disruptive Information Security

Why?Why?The solution must meet the use

caseThe solution must protect against

real threatsSolutions must align to business

operations

Page 7: The Rational Approach to Disruptive Information Security

Appearance is Appearance is everything…everything…

Page 8: The Rational Approach to Disruptive Information Security

The reality is…The reality is…Business is not linearBusiness is driven by innovationBusiness is driven by disruption

Knowing is not understanding. There is a great difference between knowing and understanding: you can know a lot about something and not really understand it. [Charles Kettering]

Page 9: The Rational Approach to Disruptive Information Security

How we got here..How we got here..Not understand the mental

model of our organizationNot adjusting our mental modelImplementing mental models

based on checklists

Page 10: The Rational Approach to Disruptive Information Security

Understanding DisruptionUnderstanding DisruptionIt’s the driver behind technology

we must secure… …

Page 11: The Rational Approach to Disruptive Information Security

Disruptive Technology Disruptive Technology and/or Innovationand/or InnovationCreating a new market or value networkImprove a product or serviceDesigning for a different set of consumers

“It represents a mindset—a rebellious instinct to discard old business clichés and remake the market landscape. An eagerness to deliberately target situations where the competition is complacent and the customer has been consistently overlooked or under-served.” [Luke Wilson]

Page 12: The Rational Approach to Disruptive Information Security

“The potential for reinvention is all around us, and it’s an exciting time to be thinking about how to structure (or restructure) your business, your community, or your life in ways that create new value. Enjoy the possibilities.” [Richard Branson - 1998]

Innovation Disrupted MarketUSB Flash drivesDownloadable digital

mediaMinicomputersDigital photographySteamboatsAutomobilesLCDGPS Navigation

Floppy Disk drivesCDs, DVDsMainframesChemical photographySailing shipsRail transportCRTNavigational map

(paper)

Page 13: The Rational Approach to Disruptive Information Security

Harnessing DisruptionHarnessing Disruption

Page 14: The Rational Approach to Disruptive Information Security

Examining the Examining the Outcome…Outcome…

© Gene Bellinger, Durval Castro and Anthony Mills - systems-thinking.org

Page 15: The Rational Approach to Disruptive Information Security

How Mental Models How Mental Models InfluenceInfluenceA mental model is an image,

story, or an assumption that influences what we see in the world, determines the structures we put in place, and ultimately drives our behavior.

Page 16: The Rational Approach to Disruptive Information Security

How to be disruptiveHow to be disruptiveNIST won’t help you, but…

Page 17: The Rational Approach to Disruptive Information Security

Identify and remove the Identify and remove the inertia…inertia…Industry StandardsIndustry best practicesAudit ChecklistsIndustry jargon

Page 18: The Rational Approach to Disruptive Information Security

Reframe your approach…Reframe your approach…

Page 19: The Rational Approach to Disruptive Information Security

Reversal through Reversal through ISO7498ISO7498

Page 20: The Rational Approach to Disruptive Information Security

The principle of The principle of reapplication…reapplication…

Page 21: The Rational Approach to Disruptive Information Security

Patterns of behavior…Patterns of behavior…

Page 22: The Rational Approach to Disruptive Information Security

Structured RationalizationStructured Rationalization

Page 23: The Rational Approach to Disruptive Information Security

Value through disruption Value through disruption as…as…

Page 24: The Rational Approach to Disruptive Information Security

Credits & ReferencesCredits & References

General Professional Influencers Disrupt: Think the

Unthinkable to Spark Transformation in Your Business

Google: www.Google.com The Visual Miscellaneum Change by Design Threat Modeling Thinking Page:

www.thinking.net Wikipedia:

www.wikipedia.com

Colleen F. Ponto, Ed.D

Page 25: The Rational Approach to Disruptive Information Security

Copyright InformationCopyright InformationSome works in this presentation

have been licensed under the Creative Common license (CC). Please respect the license when using the concepts or adapting them.

For more information please go here:

www.creativecommons.org

Page 26: The Rational Approach to Disruptive Information Security

Thank you…Thank you…

Questions and Comments

Contact me via slidshare.net