📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

CISM EXAM PREP - Domain 1B - Information Security Strategy

Inside Cloud and Security1:07:55

Transcription

In our last session, we learned that the most important objective of information security governance is to ensure that the information security strategy is in alignment with the strategic goals and objectives of the business. And in this session, that's exactly where we're headed. We're going to dive into Domain One, Part B, Information Security Strategy.

So, at the most basic level, strategy is the plan to achieve the objective. So, think of strategy as the bridge between governance and management, translating strategic objectives into a security road map with actionable plans the organization can implement. And today, we'll cross that bridge together.

Welcome, or welcome back, to the CISSM Exam Prep Series. In this session, we're diving into Domain One, Part B, where we'll cover Information Security Strategy. And we're going to go through every topic mentioned on the official exam syllabus.

And while you may know me for my exam prep content here on YouTube, in my 9-to-5, I'm a cybersecurity strategist and a VC. So, for a regional bank, where I'm exercising my cybersecurity knowledge every day, like that which you'll find here on the CISSM exam. More importantly, last year, I helped thousands achieve cybersecurity certifications like the CISSP, CCSP, and the Security Plus exams. And I'm bringing that proven formula to you here with the CISSM exam.

As with all my exam prep courses, you'll find a PDF copy of this presentation available for you in the video description to leverage in your exam preparation as you require. You'll also find a clickable table of contents available in the video description, and it should appear automatically on your YouTube video timeline.

So, we're still in Domain One in this session, working our way through the back half of Domain One. So, the exam itself, remember, consists of four domains. And the ISACA exam syllabus divides each domain into an A and a B, so two parts essentially. Today, we're focused on Part B of Domain One.

So, looking at the syllabus in a bit more depth, last week we covered Enterprise Governance and Domain 1A. Today, we're tackling Part B, Information Security Strategy, which is divided into three sections: strategy development, governance frameworks and standards that provide us templates in our development of strategy, and part three is strategic planning.

And the CISSM also includes 37 supporting tasks in the syllabus you're expected to be familiar with. I'm incorporating them where they're applicable throughout the series, so you're going to onboard that expected knowledge at no additional effort. You'll capture it in the process of this session.

So, the applicable tasks in this session are:

1. Identify internal and external influences to the organization that impact the information security strategy. This could include internal influences like budget, culture, risk appetite, or external influences like legal or regulatory, just to give you a few examples.

2. Establish or maintain an information security strategy in alignment with organization goals and objectives. This is the theme we're seeing throughout the series: security is not a silo, and it is designed to support business goals.

3. Establish or maintain an information security governance framework. This provides a structured approach for managing and protecting an organization's information assets.

Task 6, which is: Develop business cases to support investments in information security. Again, strategy takes guidance from business goals captured in the governance phase.

And 7. Gain ongoing commitment from senior leadership and other stakeholders to support the successful implementation of information security strategy. So, again, we see support from the top as a critical factor in development of our strategy, just as it is with governance, culture, etc. The top-down influence as an important factor is mentioned repeatedly throughout the CISSM.

So, let's jump into the first section of Domain 1B, Strategy Development. So, here we'll touch on business and strategy objectives. We'll look at the linkage between business objectives and strategy, that alignment we talked about so much last time, avoiding common pitfalls and bias in our thinking that may set us off target from the beginning. We'll look at the desired state and some frameworks that can help us get to the desired state, and finally, strategy development and the elements of that strategy.

So, let's talk responsibility for information security strategy. So, looking back to 1A, we'll remember that information security governance is the responsibility of the board of directors and senior management. So, it has to be integrated into the overall enterprise IT governance to facilitate transparent monitoring and effective compliance.

The strategy outlines how the information security manager will balance risk with resource optimization to provide a repeatable, mature approach, such as that that would be defined by a maturity model like CMMI, that promotes collaboration across business areas. So, governance guides strategy to ensure business alignment, and it's going to be that collaboration and looking back to the guidance we received from governance to ensure we set ourselves on the right course in strategy development.

And if you're not familiar with maturity models, no worries, we'll touch on CMMI in particular a bit later in this session. But corporate governance sets our strategic direction, ensuring objectives are met, risks are managed, and resources are used responsibly. And an effective security strategy has to support that business direction, aligning with business objectives, making sure that security enables and protects business processes, communicating purpose and protection.

So, organizations have to define what success means and also really how they're going to protect their very existence from threats. But we need to define what success means in a measurable way, and then integrating with IT architecture. So, once security requirements and outcomes are defined, a high-level security architecture guides the implementation of controls. And this security architecture, ideally, is developed in collaboration with our enterprise architecture. There are going to be a lot of resources we can take from our existing enterprise architecture, which may include deployment automation capabilities, for example. But we're going to tailor our security strategy to our enterprise architecture. Think of security architecture as an element of the broader enterprise architecture.

The prime directive of security strategy is to protect and enable the business. But on the technology side, we also want to make sure that we're well aligned with our enterprise architecture, so we're not swimming upstream or causing conflict there through a lack of integration.

So, according to ISACA, the first question that must be answered when an organization is developing their information security strategy is: What is the goal of the strategy and ultimately the program it enables? And that's where the six outcomes can be helpful.

There are six outcomes of a clear information security strategy, according to ISACA:

1. Strategic alignment: Linking security objectives and controls to the organization's strategic plan and goals. We've talked about this over and over. Investments need to align to business strategy.

2. Risk management: Embedding processes to identify, assess, and address threats to our data's confidentiality, integrity, and availability, protecting the CIA triad. So, this keeps risk within our organization's risk tolerance level.

3. Value delivery: Ensuring that our security investments optimize resources and produce measurable benefits, not just costs. So, how do our security investments contribute to the bottom line?

4. Resource optimization: Making efficient use of our people, our budget, and our tools. That's always part of the strategy here, making sure we can demonstrate how we contribute to the bottom line.

5. Performance measurement: Using key performance and risk indicators and relevant metrics to track and demonstrate the program's effectiveness. You can't manage what you can't measure, and it's very difficult to communicate your value to senior management of your security investments if you don't have relevant metrics to quantify that value.

6. Assurance process integration: So, coordinating internal and external audits and compliance activities within the security program that ensure our program remains effective.

And as with governance, the approach seeks to eliminate silos. We're aligning closely with the business.

And there are some fundamental assumptions when it comes to our security strategy. So, information security strategy assumes that our information assets are known, an understanding of what it means to protect those is in place, and we have a data life cycle management process. So, we know the location of our assets and who owns and uses them. We have an understanding of data sensitivity, so how to protect them, and we have a data life cycle management process that involves access control and data retention by whatever mandate.

But because many enterprises lack a complete inventory of their information assets, it's essential to identify and value assets, understand what information exists and how important is that information, what is its value, what is its sensitivity, classify assets by sensitivity and criticality, so ensure that protection efforts are proportional and cost-effective, that we're spending our money on the sensitive, most valuable assets, assign clear ownership. Every asset must have a defined owner and someone who is accountable in that ownership role. If we don't have this information, aligning security into the business is nearly impossible.

But once we have this information, then we can aim to integrate our strategy to align our strategy with the business. Because a robust, a solid security strategy begins with long-term, well-defined objectives that are aligned to our business goals. This is going to prevent reliance on ad hoc solutions. It's going to ensure that risk mitigation supports business activities, that we have direct business-business linkages established. We're mapping specific business processes, so security initiatives can reduce errors, prevent disruptions to business processes, and as a result, add tangible value. But it's mapping to those business processes that's going to be key.

And regular dialogue with business owners needs to happen, involving our high-level representatives. It's going to foster that ongoing integration and bidirectional awareness. It's going to help us to tailor security measures to real business needs, and it ensures that we have support from the top and close alignment to the business.

So, let's shift gears and talk about decision-making biases that can distort our planning. This is really about common pitfalls from an ISACA perspective. So, the first is overconfidence. Individuals can often overestimate their ability to predict outcomes, and this results in overly precise estimates that may not be accurate. This is especially harmful when we're evaluating the organization's core capabilities, the foundational elements we're building upon.

Optimism. So, a natural tendency to forecast positive outcomes can lead to underestimating challenges and risks. Murphy's Law tells us that when problems can occur, they often will. So, when we combine optimism with overconfidence, it creates unrealistic projections that can entirely derail strategic planning and our timelines.

There's anchoring. When our initial figures or data unduly influence subsequent judgments and cause later estimates to be based on outdated or irrelevant information. This might lead to misaligned forecasts that fail to incorporate new variables and throw our budget off, and not just our budget, potentially our timelines as well.

The status quo bias. So, people tend to stick with familiar methods even when they're inadequate due to a reluctance to change and fear of loss. People don't love change. This discourages innovation and necessary shifts in strategy as threats evolve.

There's mental accounting. So, decision-makers often compartmentalize funds based on their source or purpose, leading to inconsistent and distorted financial decisions. So, this can result in spending practices that don't reflect the true financial picture.

The herding instinct. So, this is a desire for social validation that may drive groups to conform to popular trends rather than making independent assessments. So, strategies might be adopted simply because they're widely accepted. It's groupthink. They're not adopted because they are the best option. And that's why incorporating some independent thought and analysis into the process is so important.

And finally, false consensus, where people frequently assume that others share their opinions and views, which can lead to overlooking critical risks or weaknesses. So, this might cause strategic plans to persist even when they're fundamentally flawed. So, we need to look at multiple perspectives. Everyone has a unique perspective to bring to the table, and that may influence our target.

So, let's talk about the desired state. A complete future snapshot of security that encompasses principles, policies, and frameworks, processes, and our organization structure, culture, ethics, and employee behavior, information and technology, our people skills and competencies. So, at the end of the day, because security cannot be defined solely in quantitative terms, the desired state has to include some qualitative attributes and outcomes.

Two frameworks that can help us here are COBIT and Beis. An accurate description of your desired state is so important because it's much like a map to a destination. So, if we don't have an accurate description of our desired state that is clear and complete and measurable, our road map is going to take us to a very different place than we might expect, and the organization will be less efficient and less secure as a result.

So, let's talk about COBIT and Beis. And I'm going to spend a bit more time on these two frameworks than others for one very simple reason: COBIT and Beis are developed and maintained by ISACA. So, therefore, it's easy to guess that these are more likely to appear on the exam, certainly more often than other frameworks.

So, COBIT is a framework that provides best practices for IT governance and management. It helps organizations align their IT activities with business goals. Two themes we've talked about throughout the series so far. It ensures that IT resources are used effectively and IT risks are managed appropriately.

Beis is a holistic framework that addresses security within four interrelated components. It helps organizations align information security with their overall business objectives. So, these have that in common, that business-technology, business-security alignment. But they're both developed by ISACA, so it's a bit more important that we dig into these versus other frameworks.

So, let's start with COBIT. So, COBIT includes six principles that describe the core requirements of a governance system: the end result of our efforts. Provide stakeholder value, so aligning security and IT with stakeholder needs. A holistic approach, viewing processes, structures, and information as an integrated system. Dynamic governance, so adapting to changes in technology, threats, and business. Governance as distinct from management, so separating strategic oversight from day-to-day operations. And tailored to meet enterprise needs, so customized to the organization's size, culture, and risk appetite. And end-to-end governance in the system, so it encompasses the entire enterprise, not just the IT function. So, these are the core requirements of that end result of a governance system.

And COBIT also includes three principles that describe desirable characteristics when building a governance framework. So, they convey these three items: that it's based on a conceptual model that identifies key relationships among components for consistency and automation. Open and flexible, incorporating new issues and content without losing integrity. So, our system is adaptable. And aligned to major standards, so conforming to recognized frameworks, regulations, and best practices. And that is to say, we're not using COBIT or Beis in a vacuum. It's certainly common that organizations will use multiple frameworks, including those not maintained by ISACA.

So, let's talk about Beis, the Business Model for Information Security. So, Beis consists of four core elements. It also includes six dynamic interconnections. We'll dig into that in a moment. But the four core elements of the model are:

1. Organization, design, and strategy: So, defining business goals, missions, and how resources and roles interact. And it has to be adaptable to internal and external factors. We need to think about influences inside the business and then external factors such as vendors in our supply chain.

2. People: The human element of strategy, HR, and security issues, roles, and responsibilities. It has to account for behaviors, biases, and training. For example, we talked about people not not liking change, right? So, that's going to be a bias that we need to account for.

3. Process: Formal and informal mechanisms to get work done, including risk and compliance processes. It has to align with business requirements and adapt to changing business needs. So, as the business evolves, the model has to adapt.

4. Technology: Tools, infrastructure, and applications that enhance processes. Always changing. It introduces its own risks and cultural acceptance issues every time we bring new tools, infrastructure, and apps into the environment, in part because of the human element, right?

So, here's what the Beis model looks like when pictured. You see the four core processes there: the organization, people, technology, and process. Now, let's talk about those elements that bind them, the six dynamic interconnections.

So, let's talk about those six dynamic interconnections. They're key tensions that push and pull on the core four elements, affecting our organization's security equilibrium, finding that comfortable blend. So, we have six dynamic interconnections. Let's talk through these one at a time, beginning with governance. And I expect you're going to hear some familiar information here based on what we've gone through back in Domain 1, Part A, in governance. So, governance is about strategic leadership, defining limits, monitoring performance, ensuring compliance, and adapting to change.

Culture: Shared attitudes, beliefs, and behaviors that influence how information is used and managed by people, right? This is a human element here.

Enabling and support: So, this is linking technology to processes via user-friendly security measures, policies, and procedures. These interconnections are a bit nuanced. This says linking technology to processes. So, this is a primary relationship between technology and process, but it says via user-friendly security measures, policies, and procedures. So, if we look at the diagram, the primary focus is on process and technology, but it says via user-friendly policies and procedures, right? So, it's actually secondarily also considering the people element of the core four.

So, let's look at the last three of the dynamic interconnections. Number four, we have emergence. And these speak to unpredictable changes or new developments, feedback loops, process improvements, unexpected threats. This is where being dynamic and adaptable comes into play.

The human factors: Interplay between people and technology, including training, cultural differences, and generational perspectives.

And finally, architecture: Formal encapsulation of how people, processes, policies, and technology all fit together. And considering people, processes, policies, and technology, that's where we'll get into concepts like enabling defense in depth and strategic security alignment.

But as you can see, there are a lot of moving parts here, and the CISSM exam is not going to test you on rote memorization of these frameworks. But you notice how when we walk through the frameworks here, you're hearing many of the same concepts and questions that we've been discussing here in Domain One, and that will continue on out through the rest of the series. So, I encourage you to spend a little bit of time with the explanations that I've provided here. This aligns very much with how ISACA themselves covers this material for the CISSM exam. I'm trying to distill this into a more easily digestible format for you. But if you walk through the framework here, just in these few slides, it's going to give you some perspective and will help you to, I believe, onboard the concepts a bit more effectively.

We can see that there's a lot of complexity in developing a security strategy, and how a framework would actually be really helpful in making sure that we are considering all the important areas, asking all the right questions. So, developing an information security strategy starts with a current state assessment. So, this involves a comprehensive evaluation of the organization's current security posture, including its assets, vulnerabilities, threats, existing security controls. You know, if you haven't identified assets, you can't evaluate threats and vulnerabilities, which means you also can't assess the effectiveness of your existing security controls. So, going back to those assumptions we talked about previously, we have to understand our assets, their value, their sensitivity, who owns them, who is ultimately accountable, all important elements.

So, the output of your current state assessment will help identify gaps in the organization's security measures today. It will provide a baseline for developing an effective information security strategy. This current state assessment tells the org the state of security today relative to that desired future state we defined.

So, once the current state is understood and the desired state is sufficiently defined, the security strategy outlines the path forward. And there are a few things the security strategy needs to do for us. It should address risk and compliance, so ensuring risks are mitigated to acceptable levels while meeting any legal or regulatory requirements that apply. Needs to support business objectives, that alignment of business and security we've talked about. Aligning security measures to protect and enable business processes. We want to incorporate a range of solutions. You want to use controls, process re-engineering, and architectural change to achieve a balance between security and operational efficiency. And one thing I see in organizations that tends to be a real problem is they are process inflexible. They will refuse to modify a process at all costs, resulting in the need to go out and buy expensive point solutions. And that's where we need to bring a range of solutions to the table. And if we can re-engineer a process in a way that it's still secure but better fits the controls we have at our avail, that's a good thing. It saves money and protects operational efficiency.

We need to include measurable checkpoints. Regular reviews and metrics allow for mid-course corrections, ensuring that strategies remain on track. Because in the journey that lasts for multiple months and years, you're going to have at least one project that doesn't go exactly to plan. So, regular reviews and metrics will give us an indicator when we've veered off track.

Now, the exam might ask how to secure buy-in from key stakeholders outside of IT, for example, to ensure broad coverage and alignment. So, right now, can you think of three ways that you would secure stakeholder buy-in? So, for example, communicate in business terms. Just translate the technical jargon into easily understood language. Focus on measurable benefits, cost savings, competitive advantage, and risk mitigation outcomes. Think about a security steering committee. Bring leaders in from different business units, walk them through the security strategy, get feedback, talk about their daily pain points, and get that business buying. Or even a champion program through executive support. Secure one high-level exec sponsor who advocates for the strategy. An executive endorsement can drive cross-departmental cooperation and even resource allocation. Lots of ideas, but something to think about.

So, let's move on and talk about the elements of our security strategy. So, a comprehensive strategy is built on a clear road map, an understanding of our resources, and an awareness of our constraints. So, starting with the road map. The road map is the path to our desired state. A road map provides a guide to achieve desired state, including people, processes, resources like tools and technologies. It outlines the short-term and long-term projects involving people, processes, and technology needed to transition from current state to desired state. It breaks down the overall goal into achievable, checkpoint-driven initiatives that allow for adjustments as conditions change. So, by maximizing the use of our existing assets and recognizing potential limitations, it's going to allow us to take a pragmatic view of the strategy and keep it effective and realistic.

At the end of the day, the path to desired state is going to be comprised of multiple projects with milestones along the way. And if we have periodic reviews and metric-based reporting on relevant metrics, we're going to identify when we've veered off course so we can right the ship.

Next, we have our resources. So, what we have to work with. These are the tools, the frameworks, and the organizational elements you can leverage to build and maintain your security posture. This includes policies, standards, procedures, guidelines, architectures, and controls, whether those are physical, technical, or procedural. And then to personnel skills, training, awareness, organizational structures, audits, compliance mechanisms, and all of our technological tools.

And then finally, we have our constraints. So, what limits our actions. So, these are the factors that restrict or influence how we can implement and maintain the security program. They can be internal, like budget, company culture, personnel resistance, we talked about people resisting change, organizational structure, or a risk appetite. They can be external factors, like legal and regulatory requirements.

So, we have a list of our resources and constraints in hand, as well as a good idea of our current state and a well-defined desired state. We can now develop our security strategy road map that's going to be achievable and pragmatic.

So, that brings us to the end of section one. I'd like to pause here and just go through a practice question with you quickly to apply our knowledge. So, what does an information security strategy document that includes specific links to an organization's business activities primarily indicate? Is it strategic alignment, value delivery, performance measurement, or assurance process integration?

So, let's look at what we're being asked here. A security strategy document that includes specific links to an organization's business activity. So, we have business linkage here. So, there are two pretty good options on the board here. I know value delivery is not one of them. This isn't a demonstration of delivering value yet. And this has nothing to do with performance measurement. We can take that off the board. So, strategic alignment makes sense as an option for me. Assurance process integration. So, if I have links to business activities and I'm going to apply assurance processes here, like an audit, I'm going to have a good idea of what I need to audit. But what is the primary indicator here? And the answer is A, strategic alignment. So, at the end of the day, a meaningful performance measurement or a meaningful assurance process integration will both rely on an understanding of business objectives, which is an outcome of strategic alignment.

All right, that brings us to section 1B2, Governance Frameworks and Standards. So, here, this section is a short one. We'll touch on the balanced scorecard, we'll talk about architecture approaches and architecture frameworks, enterprise risk management frameworks, and then we'll take a quick look at a number of Information Security Management Frameworks and models.

So, let's start with the balanced scorecard. The balanced scorecard is a strategic planning and management tool that's used to align organizational strategy and measure performance from a number of perspectives. In fact, it communicates priorities and monitors progress across four key perspectives: learning and growth, looking at things like employee skills, training, and organizational culture; from a customer perspective, looking at things like customer satisfaction and retention; business process, measuring efficiency and effectiveness of internal operations; and a financial perspective, looking at profitability, revenue growth, and shareholder value.

So, you could think of the balanced scorecard as a car's dashboard with different gauges or metrics. In this case, that together tell you how well the vehicle, the organization in this example, is performing. So, to look at it another way, we have the financial perspective with our goals and measures, telling us how we look to shareholders. And then the learning sector, where we have goals and measures to tell us where we can continue to learn and create value. And then from a process perspective, where must we excel or do better in business operations? And then the customer perspective, how do our customers see us?

And because it provides information from a number of perspectives, it's very useful in monitoring our progress on a security strategy road map. We can see the impact of our activities from a variety of perspectives here and let us know where we might need to course correct.

So, let's talk architecture approaches for a moment. So, enterprise information security architecture is part of the broader enterprise architecture. An architecture framework is much like a set of blueprints. It provides the structure needed to develop various architectures. So, it's going to provide guidance for a number of perspectives, from business process to conceptual, logical, physical, functional, and operational architecture perspectives. The early methods focused only on IT. The modern frameworks you'll find integrate business design and security requirements into their purview. The architecture should define a target or a desired state, which would also be called a reference architecture. But your architecture frameworks provide building blocks, policy templates, templates for various technologies that make up the architecture, ensuring they work together towards common goals.

And frameworks like COBIT, TOGAF, the Zachman Framework, and Extended Enterprise Architecture Framework link business processes with security needs. So, any of these would be a good starting point if you wanted to leverage an existing architecture framework. And while you should be familiar with the form and function of an architecture framework, I don't expect you're going to see much in the line of direct questions about these on the exam. In fact, if you look at the different study guides out there, you'll find that they don't all even mention all of these frameworks. I'm calling out specifically what's mentioned by ISACA in their review guide, which is not covered in any depth at all either.

So, let's talk Enterprise Risk Management Frameworks. These help organizations systematically plan and manage risks that could affect business objectives. So, the key frameworks in the ERM space include COSO ERM Integrated Framework, which defines key risk management components and principles while promoting a common risk language. What they mean by that is it includes standardized sets of definitions, terms, and concepts that everyone in an organization can use to talk about risk. ISO 31,000, which outlines principles, a framework, and a process for managing risk and helping identify opportunities and threats. Then there's the British Standard BS 31100, which provides a practical process that's aligned with ISO 31,000, but it's tailored for the UK context. It offers guidance on identifying, assessing, responding, reporting, and reviewing risks, but it would be specific to the UK context.

So, let's talk Information Security and Cyber Frameworks and Models. Starting with the NIST Risk Management Framework, commonly referred to as the NIST RMF. This is a systematic approach to integrating security into every phase of system development, ensuring that security evolves with the system. The audience for the RMF is federal government agencies, and the RMF is mandatory for those agencies to which it applies.

And then there's the NIST Cybersecurity Framework, commonly called the NIST CSF. It acts as a road map for improving cybersecurity, focusing on identifying gaps and aligning security. It's aimed at private or commercial businesses, and the CSF is purely optional guidance from NIST for non-government entities, though both do address cybersecurity risk management.

And there are other methodologies, ISO 9001 for quality management or Six Sigma, that can also complement security strategies. And each of these is going to bring their own unique perspectives and elements. Many organizations are going to use multiple frameworks to tailor the strategy of their security to their organization.

And then there's ISO 27001 and its companion ISO 27002. Very widely adopted. It outlines a framework for implementing, maintaining, and continually improving an Information Security Management System. So, an ISMS is a set of policies, processes, and controls that helps organizations protect their information assets. It guides organizations in identifying information assets and assessing their value and information security risks, and implementing mitigating security controls based on the companion standard ISO 27002. And then regularly monitoring and measuring effectiveness of and continuously improving the information security management system. But ISO 27001 lays out the set of policies, processes, and controls, and the guidance on mitigating security controls are laid out in ISO 27002, which is actually a much larger document. And in the 2022 update, they incorporated cloud security into the standard.

Now, I wanted to just touch again on the focus of the CISSM exam. Especially if you've come from the CISSP exam, you might think that you're going to see a lot of technical questions about these frameworks. The fact of the matter is, the CISSP leans more technical than CISSM. It's more tactical and operational than it is strategic. CISSM is going to be a bit more tactical and strategic, a bit more process, strategy, and governance focused. So, that being said, expect the exam to test on the application of frameworks, like when and where you'd use them, not to deeply test your memorization of phases. I don't think there's any need at all to dive deep into these frameworks and to memorize process phases.

And while I say not to worry too much about memorization of phases of these frameworks, if there's going to be coverage of a framework of any sort, my guess would be COBIT or Beis, since those were developed and maintained by ISACA. We're also going to talk about the Capability Maturity Model Integration a bit later in this chapter, which was not developed by ISACA, but it is maintained by them. That's a wrap on Section 1B2.

So, I'd like to go through a practice question so we can apply our knowledge. The question is: After implementing an information security governance framework, which solution or activity would best provide insights to develop an information security project plan? An internal audit, a review of the security strategy road map, a current state assessment, or a balanced scorecard?

So, a couple of these I could mark off right away. So, an internal audit is something we typically do to assess our readiness for an external audit. There are a number of flavors an internal audit could take, but giving us detailed insights for a specific security project plan would not be a typical scope. Reviewing the security strategy road map isn't going to give us details that's going to show us the projects and the milestones on our path to our desired state, so not a good source either.

Now, a current state assessment is going to tell us a lot about the current state of our security posture, so there could be some information there. And then the balanced scorecard provides information from a number of perspectives. So, one of these is going to have a few advantages over the other. So, which do you think it is?

So, the right answer here is the balanced scorecard, which gives us a comprehensive view of our organization's performance across various perspectives on demand. So, by using the balanced scorecard, the information security manager can identify key areas for improvement and prioritize projects that align with the organization's overall goals and objectives based on performance at that point in time. So, it's going to be effective and efficient, both in terms of time and effort and cost.

Okay, that brings us to section 1B3, which is Strategic Planning. So, here we're going to touch on workforce composition and skills, which will take us through a few people-centric aspects of strategic planning, organizational culture, centralized versus decentralized approaches to our security, employee roles, responsibilities, skills, and training. We'll touch on assurance provisions like audits, and then we'll look at risk assessment and management, business impact analysis at a high level, threat and vulnerability assessment, and we'll talk a bit about insurance, like cyber insurance, and then our action plan to implement strategy.

So, we're moving logically through the process, working our way from 1A and then through 1B, and finally, we'll take a look at information security program objectives.

So, let's take a look at workforce composition and skills, because personnel are our first line of defense when it comes to security, and it's important to understand that insider actions can potentially do the most damage. So, we have to ensure that both new and existing staff, including external service providers, perhaps we've outsourced our Security Operations Center, for example, we need to know that all of these employees are trustworthy and skilled. Addressing this need is certainly going to happen in our security program, but it should be included in the security strategy. It's a risk we need to address. Personnel security is important preventative measures intended to protect against insider threats, whether they are intentional or unintentional. For example, organizations will commonly implement data loss prevention and a Cloud Access Security Broker, or CASB, to detect or prevent data leaks that could be due to intentional or accidental oversharing or even mass file exfiltrations.

Organizational structure. So, a flexible structure facilitates security strategy development. Now, a constrained structure can perceive security efforts as a threat. So, when we see new security initiatives coming in, when we have a very strict org chart and a lack of collaboration, it can be something of a Game of Thrones, where new security efforts that are improving our posture aren't always appreciated. An increased focus on security-business alignment to reduce risk is very common now. In fact, this has led to an important change in the org chart. Typically, the CISO, the Chief Information Security Officer, in the past has typically reported to the CIO, and now we just as commonly see that CISO reporting to the CFO, and in some cases, even directly to the CEO.

Employee roles and responsibilities. So, our strategy needs to define security roles and responsibilities. They need to be incorporated into job descriptions that are formally documented and linked to performance evaluations. We need to coordinate this between the security manager and HR.

Skills. So, the strategy should leverage existing skills or possible, but also plan for developing new skills or procuring those skills externally, especially when we're dealing with a highly specialized skill set that's only needed occasionally. It may be more cost-effective to procure an expert for a limited period of time. But the org should maintain a skills inventory so they have a good idea of what skills they have in-house and what they need to develop or potentially procure externally.

And ongoing awareness and education. So, security awareness training should be an annual event at the very least. More often, it's a quarterly exercise that we use to minimize end-user vulnerabilities. The end user tends to be the weakest link, and a recurring awareness education session can pay huge dividends. I've seen this lead to perfect scores on phishing simulations for organizations over multiple years because they have trained their end users to where they are just bulletproof. But the recurring awareness programs are, in some cases, even legally mandated. But the training should be targeted, updated periodically for current threats. So, for example, organizations right now are evolving their security awareness training to include information on the latest generative AI updates to make sure that their users don't fall prey to AI-based deepfakes of any sort.

What are the pros and cons of centralized and decentralized security strategy and compliance? You'll want to know the difference for the exam. So, centralized security approaches offer standardization, but this may not suit all organizational structures. So, for example, standardization across the entire organization is going to be difficult for a multinational company with varying legal requirements or acquired subsidiaries that operate independently. Centralized security, on the other hand, is going to be easy for small organizations that operate in a single jurisdiction.

Decentralized security allows for local responsiveness, but can lead to inconsistent service quality, but it may be necessary to some degree in those large organizations where we don't have a single jurisdiction, a single standard, and a unified staff. So, let's just look at the characteristics of decentralized versus centralized security strategy and how they compare.

Consistency and standardization: It's going to be higher in a centralized structure where we're delivering everything from the home office. It's going to be lower in terms of its consistency when we're doing things differently at every branch office or in different subsidiaries.

Adaptability to local requirements: Here, decentralized structures have higher responsiveness and adaptability. They're going to be better off.

Resource efficiency: Is going to be higher in a centralized structure where we have potentially a single team that's delivering that strategy across the entire organization.

Response time to local issues: That's going to be slower in that centralized structure, typically, and faster in decentralized, simply because we're going to have resources right there in the local.

And service quality: Will tend to be more consistent in that centralized structure, where everything is coming from a central authority, and there is no autonomy at the branch.

But regardless of the approach, all security programs must do a few things: aligned with business goals, have senior management support, include monitoring and reporting, have crisis management procedures, maintain risk management over time, provide security awareness training on a recurring basis. But we need support from the top, right? That's a recurring theme we've heard all throughout these modules. And we need to make employees aware of security and get them on board. We need to make sure that employees are not our greatest weakness, our weakest link, but rather become a strength because they are well-informed.

Moving on to assurance provisions. An organization's information security strategy has to include methods for oversight. So, oversight ensures that the security plan is effectively implemented and maintained. So, what do assurance provisions enable, exactly? Well, they give us ongoing communication about the state of our security plan, periodic reporting, and confirming that compliant and security objectives continue to be met. So, think of assurance provisions as the manifestations of oversight, the activities that confirm the efficacy of our strategic plan and ensure that leadership remains informed.

A common activity that is an assurance provision is the audit. So, we have the internal audit, an audit conducted by someone from within the organization. Now, in larger organizations, we typically see a dedicated audit department reporting to a board or senior management, which generally means you're going to have a skilled individual, and we're reducing the odds that there's going to be bias in the auditor because they're reporting to a senior board or management, and that is their dedicated function. Smaller organizations may have a security officer who serves that function or maybe outsources that to a vendor.

Now, external audits are conducted by independent third parties, which will be good news in terms of the skills, typically, but also in terms of objectivity. Now, in regulated industries, external audits may be required by governing bodies, often annually, and that's certainly true in regulated industries like banking and healthcare.

So, compliance enforcement. These are procedures for handling security violations with senior management support being essential. We need to prioritize compliance based on risk and impact. So, high impact, high-risk areas is where we have to prioritize our enforcement. We can use self-reporting and voluntary compliance where possible in low-risk, low-impact scenarios, but have enforcement mechanisms for those high-risk areas, particularly where 100% compliance is an absolute must. So, for the exam, remember, leadership's commitment to compliance often sets the tone for the entire organization. Because at the end of the day, if employees know that leaders are not committed, they may simply not comply if they don't believe there are consequences behind it. That's why those enforcement mechanisms are indeed so important.

A thorough risk management plan is going to be important, and it should detail how the organization will identify, assess, and treat risks to enterprise assets and define risk tolerance, identification methodologies, and response strategies, and continuously monitor risks over time. The plan has to account for threats, both external and internal, known and emerging, as well as vulnerabilities that might be exploited. Remember that internal threats may do as much damage as external threats. We have to consider all.

So, let's take a look at some key considerations when we're thinking about risk management plans.

Business impact analysis: So, determining the consequences of losing confidentiality, integrity, or availability over our business-critical resources. This is often expressed financially, which helps in the prioritization. It provides insight for information classification and business continuity planning.

Resource dependency analysis: Which looks a bit like business impact analysis, but it's less granular and it focuses on systems and resources critical to operations. So, it may get over into the physical world.

Outsource services: Introducing risks due to differing standards and control levels. So, we want to make sure that we have a strategy that addresses single points of failure and ensures backup plans. So, for example, if our organization experiences a disaster that results in an extended power outage, we may have a diesel generator. We need to make sure that we have two sources of diesel fuel to keep that generator running. We would never want to rely on a single vendor that may be impacted by the same disaster we are. If they're not experiencing power issues of their own, they may be experiencing capacity issues because other organizations in our area are affected.

Risk assessment process: So, this involves identifying threats, physical, environmental, technological, assessing their likelihood and magnitude, and determining organizational vulnerabilities. We want to calculate the probable annual loss expectancy to determine acceptable risk. That's a quantitative risk analysis formula. We're going to dig into those in Domain 2.

Threat assessment: Which considers threats proactively, even without known vulnerabilities. So, policies like network access, data handling, incident response should map to a threat profile. This results in more cost-effective risk treatment because we're addressing it before compromise happens. We're addressing it earlier in the process.

And vulnerability assessment: Which goes beyond technical scans to include physical elements, procedures, practices, and legal requirements. Vulnerability assessments address systemic weaknesses proactively.

So, insurance is the last one on our list. And insurance is suitable for rare, high-impact events: flood, fire, embezzlement. We'll see cyber insurance for protection against ransomware. Types of insurance include first-party, which is enterprise coverage that covers business assets directly. It covers what you own. Third-party, which is liability for events like a data breach. And fidelity bonds. We get these for situations like employee theft. It protects the business from losses caused by the dishonest act of employees.

We can also potentially lean on other internal departments: legal, compliance, audit. And we want to make sure that our departments operate seamlessly to avoid gaps, as well as duplication of effort. And to avoid both of these things requires communication, collaboration, clear delineation of roles and responsibilities, well-documented response plans that have been adequately rehearsed.

Next, we need to consider our plans of action, our projects and initiatives that make our security strategy a reality. So, gap analysis will be a regular event. These are performed for various strategy components to identify current state versus desired state. These may be through maturity levels, using a model like the Capability Maturity Model Integration, which we'll talk about later, control objectives, or risk. These are going to be repeated regularly for performance metrics and for mid-course corrections for identifying when we've veered off course on our road map. And a gap analysis works backward from the endpoint, the desired state, back to the current state to see what the gap is between today and our desired state down the road.

Action plan metrics. So, we monitor progress and cost. We define key performance indicators, critical success factors, and key goal indicators. Relevant metrics, and we use methods like balanced scorecards or the CMMI for ongoing gap analysis. So, key goal indicators define clear, measurable objectives that describe what success looks like, for example, achieving Sarbanes-Oxley compliance. Key performance indicators measure progress towards those KGIs, like control effectiveness testing plans. Critical success factors are the

Essential elements required to achieve effective Information Security Management outcomes that are aligned with business goals. CSFs are monitored through KPIs, which quantitatively measure progress.

Now, General metrics considerations: we need to think about. We want to focus on relevant metrics that inform decision-making. We categorize a strategic, tactical, or operational, so basically long-term, midterm, short-term. We distill technical data into useful management information, and reporting should be consumable and actionable to recipients. That means the format and the language will depend on your audience. It's going to be more summary and business-focused for the C-level. It's going to be more detailed and technical at an engineering level.

Action plan: intermediate goals. We want to define near-term and midterm goals aligned with the overall strategy. We want to ensure integration of our tactical activities that have a midterm focus with our long-term goals and avoid the short-term point solutions and firefighting that can take away our focus from the long-term objectives.

So, let's talk about SWOT analysis. So, SWOT analysis can guide decision-making on where to invest in controls. Strengths: what characteristics of the organization or security program give it a strong advantage over others? Weaknesses: what characteristics of the security program create a disadvantage or gaps in controls? And then we can look at external factors. Opportunities: what external factors can be leveraged to improve or advance the security posture? And Threats: another external factor that could harm the organization or diminish our security efforts. And the SWOT analysis helps us examine the decision from multiple perspectives, and that can help ensure security alignment to business goals a little better than just examining it on its own in an unstructured way.

So, let's talk about capability maturity models, which are frameworks for assessing the maturity of an organization's processes. Perhaps the most widely recognized is the Capability Maturity Model Integration for Development, which was developed by the Software Engineering Institute at Carnegie Mellon University. However, it is now maintained by A.S.A.C.A. through an acquisition they made some years ago. Because it's maintained by A.S.A.C.A., it is more likely to appear on the exam. But by using maturity models, security managers can systematically evaluate the current state of each process or control, define target states, and plan continuous improvements that align with organizational goals. The CMMI is a model with five levels ranging from less mature to more mature. So, the initial level of maturity is a process that's poorly controlled and reactive, and it works its way up through repeatable, defined, managed, and optimizing.

So, to dig in a little deeper: Level 1, initial processes are ad hoc, inconsistent, unmeasured, and non-repeatable. Moving into Level 2, processes occur consistently with predictable results; they're repeatable. Level 3, defined processes are formally documented and standardized across projects or teams. Level 4, managed processes are measured and controlled through metrics or KPIs. And Level 5, optimizing, where continuous improvement is embedded in the process, guided by data and metrics.

A couple of important pieces of information to remember here. So, number one, maturity can vary by control or process, and each control or process should, in fact, be assigned a maturity level that aligns with its importance and with relevant risks. And that is to say that Level 5 is not always the goal due to cost, effort, and business objectives. So, we're going to save that Level 5 target for our most critical controls and processes. Many controls and processes are going to be just fine at Level 2 or 3.

So, let's talk about information security program objectives. There are some key information here that I've distilled for the exam. So, the information security program implements the strategy, and its primary objective is to protect information and related processes and systems from harm. So, once implemented, the strategy evolves into a program. Our core objectives here are confidentiality, integrity, and availability. The CIA Triad. For the exam, know what a security program does and its primary objective. It's worth just committing that to mind.

So, confidentiality, integrity, and availability are known as the CIA Triad. And confidentiality is about ensuring that private or sensitive information is accessible only to authorized individuals. So, for example, encrypting patient medical records so only doctors can access them. Integrity is safeguarding the accuracy and completeness of data to prevent unauthorized and improper modification. For example, using blockchain technology to create an immutable record of financial transactions. Availability: making sure that authorized users have timely and reliable access to information and associated assets when they're needed. Implementing redundancy and backup systems to minimize downtime for an e-commerce platform. Perfect example. What all three have in common is they focus on protecting data within systems. And that brings us to the tail end of Section 1B3.

So, let's tackle a practice question together to test your knowledge. Our question: What is a characteristic of decentralized Information Security Management across a geographically dispersed organization? Our options are: better adherence to policies, more cost-effective than centralized, better alignment to business unit needs, or more consistent quality of service.

So, let's break down what they're asking us here. So, a characteristic of decentralized management across a geographically dispersed organization. So, we spread management out across an organization that has many locations. Does that give us better adherence to policies when we have decentralized control? Absolutely not. So, if we have decentralized control where we're potentially duplicating effort, is that more cost-effective? Absolutely not. So, we have two options here: better alignment to business unit needs or more consistent quality of service. So, let's think about these two. Is there better alignment to business unit needs when we're decentralizing? When we're pushing support out to the different locations, does that mean that quality service is going to be more consistent? Which do you think it is?

The answer is C, better alignment to business unit needs. So, decentralization of Information Security Management generally results in better alignment to business unit needs because the support is right there locally. Consistency and quality of service tends to vary across units, so that's a negative. It's also going to be more expensive to manage due to lack of economies of scale. We're going to be duplicating some effort there.

My friends, that brings us to the end of Domain 1 Part B. I hope you're getting value out of the series. As always, if you have any questions, ping me in the comments below this video or reach out on LinkedIn. I'll look forward to seeing you in just a few days as we begin our journey into Domain 2. And until next time, take care and stay safe.