+ All Categories
Home > Documents > Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry...

Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry...

Date post: 27-Mar-2015
Category:
Upload: alex-guthrie
View: 214 times
Download: 1 times
Share this document with a friend
Popular Tags:
17
Nishidh, CISSP
Transcript
Page 1: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.

Nishidh, CISSP

Page 2: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.
Page 3: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.

To comply with Sarbanes oxley and other legislations

To comply with industry standards and business partner requirements

To protect customer information To protect employee data To detect fraud To identify and correct any manual errors To identify hardware or software errors To proactive monitoring infrastructure For business continuity

Page 4: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.
Page 5: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.

Because?

Page 6: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.

People who enjoy our services and products – our customers

People who give money to run business – our investors

People who run business – our employees

Page 7: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.

Easy security controls for customer applications.

Prevent unauthorized disclosure of customer data.

Prevent unintended destruction of customer data.

Promptly inform customers about security incidents

Help customers in taking corrective actions.

Page 8: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.

Protect customers Accurate financial reporting ( Sarbanes

Oxley Act ) Give good return on investment ( no over

investment on security and effective use of control )

Page 9: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.

Employees require open environment Security control should not reduce

productivity. Transparent monitoring Well informed Security Policies

Page 10: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.

We need to invest in security not to just comply with any legislation or meet any industry or partner requirements

ButWe need to invest in security to protect

customer, investor and employees. This is a TRUST business and if we loose TRUST, we will loose everything.

Page 11: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.

Top down approach Identify critical business goals Identify critical functions to meet

business goals Identify risk to critical functions Effective Risk management

Reduce Risk Transfer risk Accept Risk

Page 12: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.

Identify origin of risk ( 3Ps ) People Processes Products

Identify and implement controls Verify effectiveness of controls ( Audit )

Page 13: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.

People are weakest link in any security system.

People require policies, standards, guideline and procedure to react in predefined manner.

Security Awareness Programs are mandatory for implementation of policies and standards.

People should be able to report security incidents or threats and take guidance from incident response team.

Page 14: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.

Processes are key for smooth and secure business operations

Processes implements Policies and Standards. Processes implements “separation of duties”

and “need to know” concept to comply with any legislation requirements on security.

It is require to monitor process deviation in order to identify suspicious activities or Fraud

Continuous audit on processes is mandatory to verify compliance.

Page 15: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.

Products can be any hardware, third party package or custom applications.

Products provides platform to implement processes.

Products require to generate reports and audit trails to notify deviation in processes.

It is required to analyze product based on policies and standards before integrating in environment.

To develop applications, extra care of security reviews /testing are required.

If product use cryptography, then key protection and data recovery are equally important.

Page 16: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.
Page 17: Nishidh, CISSP. To comply with Sarbanes oxley and other legislations To comply with industry standards and business partner requirements To protect.

Recommended