1
00:00:06,420 --> 00:00:08,092
- Welcome to Lesson 23,

2
00:00:08,092 --> 00:00:12,060
Summarize Elements of
Effective Security Governance.

3
00:00:12,060 --> 00:00:13,830
Now, in Lesson 23.1,

4
00:00:13,830 --> 00:00:16,800
I'm gonna introduce you
to governance structures.

5
00:00:16,800 --> 00:00:18,930
Now, enterprise governance is the system

6
00:00:18,930 --> 00:00:21,979
by which entities are
directed, controlled,

7
00:00:21,979 --> 00:00:24,513
and critically held to account.

8
00:00:25,710 --> 00:00:29,280
Governance balances the
needs of various stakeholders

9
00:00:29,280 --> 00:00:31,650
in order to achieve our
enterprise objectives.

10
00:00:31,650 --> 00:00:33,600
And governance influences

11
00:00:33,600 --> 00:00:37,590
how an organization's
objectives are set and achieved,

12
00:00:37,590 --> 00:00:39,960
how risk is monitored and addressed,

13
00:00:39,960 --> 00:00:42,454
and how performance is optimized.

14
00:00:42,454 --> 00:00:45,180
Now, governance is a system and a process.

15
00:00:45,180 --> 00:00:47,610
It's not just a single activity,

16
00:00:47,610 --> 00:00:49,410
and successful implementation

17
00:00:49,410 --> 00:00:52,680
really does require a systematic approach

18
00:00:52,680 --> 00:00:55,680
that incorporates
stewardship and due care,

19
00:00:55,680 --> 00:00:58,290
strategic planning, risk managing,

20
00:00:58,290 --> 00:00:59,910
and performance management,

21
00:00:59,910 --> 00:01:02,610
which are all topics
we're gonna talk about.

22
00:01:02,610 --> 00:01:05,280
As applied to information
or cybersecurity,

23
00:01:05,280 --> 00:01:07,920
governance is the
responsibility of leadership

24
00:01:07,920 --> 00:01:11,820
to determine and articulate
the organization's desired,

25
00:01:11,820 --> 00:01:14,160
or future, state of security.

26
00:01:14,160 --> 00:01:15,600
So where do we want to be?

27
00:01:15,600 --> 00:01:16,848
And sometimes,

28
00:01:16,848 --> 00:01:17,820
you'll hear that referred
to as a desired state,

29
00:01:17,820 --> 00:01:18,720
but more often than not,

30
00:01:18,720 --> 00:01:21,363
you'll hear it referred
to as future state.

31
00:01:22,650 --> 00:01:25,170
So subsequently, they're also responsible

32
00:01:25,170 --> 00:01:29,010
for providing the strategic
direction, the resources,

33
00:01:29,010 --> 00:01:31,560
the funding, and the support

34
00:01:31,560 --> 00:01:34,590
to ensure that that
desired state of security

35
00:01:34,590 --> 00:01:39,060
can be achieved, and then once
achieved, can be sustained.

36
00:01:39,060 --> 00:01:40,140
Now, they want to codify

37
00:01:40,140 --> 00:01:43,110
the organization's commitment in policy.

38
00:01:43,110 --> 00:01:44,340
They're also responsible

39
00:01:44,340 --> 00:01:47,553
for risk management and for oversight.

40
00:01:49,890 --> 00:01:52,020
The governance structures and principles

41
00:01:52,020 --> 00:01:56,730
identify roles and responsibilities
within an organization.

42
00:01:56,730 --> 00:01:59,880
A role is a specific
position or a job title

43
00:01:59,880 --> 00:02:03,573
that an individual occupies
within an organization or group.

44
00:02:04,620 --> 00:02:09,030
Stewardship is the responsible
oversight and protection

45
00:02:09,030 --> 00:02:11,880
of something that's
entrusted to one's care.

46
00:02:11,880 --> 00:02:13,650
So very often in our roles,

47
00:02:13,650 --> 00:02:16,217
we are expected to also be stewards,

48
00:02:16,217 --> 00:02:20,040
being responsible for the
oversight and protection

49
00:02:20,040 --> 00:02:23,100
of something that is
entrusted to our care.

50
00:02:23,100 --> 00:02:27,120
Now, responsibility refers
to specific duties or tasks

51
00:02:27,120 --> 00:02:31,533
that an individual is expected
to fill within a given role.

52
00:02:34,140 --> 00:02:37,320
So, big picture of our
governance ecosystem, right?

53
00:02:37,320 --> 00:02:38,790
We have, all encompassing,

54
00:02:38,790 --> 00:02:40,740
the Board of Directors
or Board of Trustees,

55
00:02:40,740 --> 00:02:44,520
or in a government agency, that
might be agency leadership,

56
00:02:44,520 --> 00:02:45,420
or in the military,

57
00:02:45,420 --> 00:02:49,290
it would be the top of
the chain of command.

58
00:02:49,290 --> 00:02:51,390
Then we have Executive Management.

59
00:02:51,390 --> 00:02:53,880
Then we're going to have
Organizational Roles.

60
00:02:53,880 --> 00:02:56,160
And then lastly, we will
have Functional Roles.

61
00:02:56,160 --> 00:02:57,960
We're gonna talk through
the responsibilities

62
00:02:57,960 --> 00:02:59,040
of each of those groups,

63
00:02:59,040 --> 00:03:02,640
the Board of Directors or
equivalent, Executive Management,

64
00:03:02,640 --> 00:03:05,493
Organizational Roles,
and Functional Roles.

65
00:03:06,793 --> 00:03:10,230
So the Board of Directors,
or their equivalent, duties

66
00:03:10,230 --> 00:03:15,230
are strategy, due care, being
a fiduciary, and oversight.

67
00:03:16,200 --> 00:03:18,150
So they are responsible to determine

68
00:03:18,150 --> 00:03:22,290
the desired future state of
information or cybersecurity.

69
00:03:22,290 --> 00:03:23,970
Now, they're not gonna do the grunt work

70
00:03:23,970 --> 00:03:25,350
of figuring out what it is.

71
00:03:25,350 --> 00:03:26,700
That's gonna be done by management,

72
00:03:26,700 --> 00:03:28,800
but it's gonna be brought
to the Board of Directors,

73
00:03:28,800 --> 00:03:31,440
or equivalents, or Board of
Trustees, or agency leadership.

74
00:03:31,440 --> 00:03:33,127
And they will be the ones that say,

75
00:03:33,127 --> 00:03:36,330
"Yes, we are putting
our endorsement on it.

76
00:03:36,330 --> 00:03:38,640
That is our desired future state

77
00:03:38,640 --> 00:03:41,166
of information or cybersecurity."

78
00:03:41,166 --> 00:03:44,402
Codify it in strategy and policy,

79
00:03:44,402 --> 00:03:47,763
and to provide the funding,
approve the budget.

80
00:03:49,080 --> 00:03:51,960
They are also held to
the standard of due care,

81
00:03:51,960 --> 00:03:54,120
and due care is a legal construct

82
00:03:54,120 --> 00:03:56,970
defined as executing the standard of care

83
00:03:56,970 --> 00:03:59,640
that a prudent person would have exercised

84
00:03:59,640 --> 00:04:02,520
under the same or similar conditions.

85
00:04:02,520 --> 00:04:06,390
Now, if a situation arises
that ends up going to court,

86
00:04:06,390 --> 00:04:11,390
one of the criteria that will
be used in a civil suit is,

87
00:04:11,460 --> 00:04:14,133
was the standard of due care upheld?

88
00:04:15,221 --> 00:04:18,690
Now, the directors or
trustees, or equivalent,

89
00:04:18,690 --> 00:04:21,000
are also known as fiduciaries.

90
00:04:21,000 --> 00:04:23,760
A fiduciary is a person or organization

91
00:04:23,760 --> 00:04:26,370
who holds a position of trust.

92
00:04:26,370 --> 00:04:28,890
Now, being a fiduciary requires

93
00:04:28,890 --> 00:04:32,610
being bound both legally and ethically

94
00:04:32,610 --> 00:04:34,410
to act in the trustor's

95
00:04:34,410 --> 00:04:37,413
or in the organization's best interest.

96
00:04:39,390 --> 00:04:41,010
And then oversight, right?

97
00:04:41,010 --> 00:04:42,120
They are responsible

98
00:04:42,120 --> 00:04:45,390
for oversight and
authorization of everything,

99
00:04:45,390 --> 00:04:47,040
of organizational activities.

100
00:04:47,040 --> 00:04:49,020
Now, they're not gonna
get into the minutiae,

101
00:04:49,020 --> 00:04:52,290
but ultimately, they are the
ones that are responsible

102
00:04:52,290 --> 00:04:54,120
and will be held responsible,

103
00:04:54,120 --> 00:04:57,549
whether it's by shareholders,
or in a court of law,

104
00:04:57,549 --> 00:05:01,353
or from a regulatory
compliance perspective.

105
00:05:04,410 --> 00:05:06,360
Now, what about Executive Management?

106
00:05:06,360 --> 00:05:08,430
Well, Executive Management is responsible

107
00:05:08,430 --> 00:05:12,300
for strategic alignment, risk
management, value delivery,

108
00:05:12,300 --> 00:05:16,500
resource optimization, budgeting,
performance measurement,

109
00:05:16,500 --> 00:05:20,194
assurance processes, and compliance.

110
00:05:20,194 --> 00:05:23,460
So decision making, all
of their decision making

111
00:05:23,460 --> 00:05:25,530
should be informed by organizational goals

112
00:05:25,530 --> 00:05:27,720
and strategic objectives.

113
00:05:27,720 --> 00:05:29,310
They're responsible for mitigating risk

114
00:05:29,310 --> 00:05:30,240
to an acceptable level,

115
00:05:30,240 --> 00:05:33,870
and we'll be talking more about
risk in just a little bit.

116
00:05:33,870 --> 00:05:36,364
Value delivery is optimizing investments

117
00:05:36,364 --> 00:05:39,480
in support of business objectives.

118
00:05:39,480 --> 00:05:42,000
Resource optimization is
that they're responsible

119
00:05:42,000 --> 00:05:46,470
for managing resources
efficiently and effectively.

120
00:05:46,470 --> 00:05:47,460
Budgeting,

121
00:05:47,460 --> 00:05:49,890
they'll construct and
then they'll implement

122
00:05:49,890 --> 00:05:51,180
the organizational budget.

123
00:05:51,180 --> 00:05:53,820
Generally, that budget will be
approved at the higher level,

124
00:05:53,820 --> 00:05:54,750
at the Board of Directors,

125
00:05:54,750 --> 00:05:57,360
or Board of Trustees, or equivalent.

126
00:05:57,360 --> 00:05:58,680
They will be the ones responsible

127
00:05:58,680 --> 00:06:01,410
for evaluating performance measures.

128
00:06:01,410 --> 00:06:02,430
They will be responsible

129
00:06:02,430 --> 00:06:04,860
for implementing oversight processes,

130
00:06:04,860 --> 00:06:07,560
meaning that there are
assurance activities going on,

131
00:06:07,560 --> 00:06:10,290
that we are doing testing,
that we are doing auditing,

132
00:06:10,290 --> 00:06:12,720
we are having examinations.

133
00:06:12,720 --> 00:06:15,840
And lastly, they're
responsible for compliance,

134
00:06:15,840 --> 00:06:17,790
to comply with applicable laws,

135
00:06:17,790 --> 00:06:21,153
regulations, contracts, and customs.

136
00:06:24,960 --> 00:06:26,160
Now, many organizations

137
00:06:26,160 --> 00:06:28,890
will have an Information
Security Steering Committee,

138
00:06:28,890 --> 00:06:30,330
and the Steering Committee

139
00:06:30,330 --> 00:06:34,410
is senior representatives of
relevant stakeholder groups.

140
00:06:34,410 --> 00:06:36,330
So these will be senior representatives,

141
00:06:36,330 --> 00:06:38,250
people who are part of management,

142
00:06:38,250 --> 00:06:39,780
who will actually come together

143
00:06:39,780 --> 00:06:43,590
to specifically oversee
information security.

144
00:06:43,590 --> 00:06:46,230
Their authority is
generally decision making,

145
00:06:46,230 --> 00:06:47,910
and the objective of having

146
00:06:47,910 --> 00:06:51,390
a Information Security or
Cybersecurity Steering Committee

147
00:06:51,390 --> 00:06:55,110
is to achieve consensus on
strategies and priorities

148
00:06:55,110 --> 00:06:57,960
related to information or cybersecurity.

149
00:06:57,960 --> 00:06:59,910
So what are some common topics

150
00:06:59,910 --> 00:07:02,790
for the Information
Security Steering Committee?

151
00:07:02,790 --> 00:07:05,070
Well, the cybersecurity strategy,

152
00:07:05,070 --> 00:07:07,590
'cause they need to really
be sponsors of it, right?

153
00:07:07,590 --> 00:07:08,423
They need to say,

154
00:07:08,423 --> 00:07:10,680
"Yep, we're good on this
cybersecurity strategy,"

155
00:07:10,680 --> 00:07:11,970
before it goes up

156
00:07:11,970 --> 00:07:14,190
perhaps to the Board of
Directors for approval.

157
00:07:14,190 --> 00:07:16,260
They set the cybersecurity budget.

158
00:07:16,260 --> 00:07:18,300
Again, it gets approved at a higher level.

159
00:07:18,300 --> 00:07:20,070
They authorize risk decisions

160
00:07:20,070 --> 00:07:21,660
per the risk appetite statement.

161
00:07:21,660 --> 00:07:23,070
We'll be talking about risk

162
00:07:23,070 --> 00:07:24,930
and risk appetite in just a little bit.

163
00:07:24,930 --> 00:07:28,320
And they monitor the
organization's cyber risk position

164
00:07:28,320 --> 00:07:32,520
and they report that to the
Board or to a Board Committee.

165
00:07:32,520 --> 00:07:33,780
So what are the benefits

166
00:07:33,780 --> 00:07:36,120
of having this multidisciplinary

167
00:07:36,120 --> 00:07:38,400
Information Security Steering Committee?

168
00:07:38,400 --> 00:07:40,650
Again, remember, these
are senior representatives

169
00:07:40,650 --> 00:07:43,833
of relevant stakeholder groups,
so different business units.

170
00:07:44,970 --> 00:07:48,090
Well, that allows us to have
appropriate prioritization

171
00:07:48,090 --> 00:07:50,160
of information security objectives,

172
00:07:50,160 --> 00:07:52,110
because as cybersecurity folks,

173
00:07:52,110 --> 00:07:54,900
we might get a little
bit myopic in our area,

174
00:07:54,900 --> 00:07:57,570
but this allows us to
see the bigger picture,

175
00:07:57,570 --> 00:08:00,450
and it's a really effective
communication channel

176
00:08:00,450 --> 00:08:03,840
for assuring alignment
of the security program

177
00:08:03,840 --> 00:08:05,463
with business objectives.

178
00:08:08,010 --> 00:08:09,240
Now, a member of management

179
00:08:09,240 --> 00:08:11,970
is gonna be a Chief
Information Security Officer.

180
00:08:11,970 --> 00:08:13,500
Now, not every organization

181
00:08:13,500 --> 00:08:15,540
has a Chief Information Security Officer.

182
00:08:15,540 --> 00:08:17,160
They may have an equivalent officer,

183
00:08:17,160 --> 00:08:22,160
or this may be the responsibility
of the Chief Risk Officer.

184
00:08:22,645 --> 00:08:25,440
But for our purposes and for your exam,

185
00:08:25,440 --> 00:08:27,600
the Chief Information Security Officer

186
00:08:27,600 --> 00:08:29,340
or its equivalent role

187
00:08:29,340 --> 00:08:31,260
interprets the strategic direction

188
00:08:31,260 --> 00:08:35,040
and is generally held accountable
for the success or failure

189
00:08:35,040 --> 00:08:37,890
of the information security program.

190
00:08:37,890 --> 00:08:40,050
Now, the CISO should report up

191
00:08:40,050 --> 00:08:42,630
as high in the organization as possible

192
00:08:42,630 --> 00:08:46,830
to maintain visibility,
to limit distortion,

193
00:08:46,830 --> 00:08:49,230
and to minimize conflict of interest.

194
00:08:49,230 --> 00:08:52,830
So for example, if your CISO
is reporting to your CIO,

195
00:08:52,830 --> 00:08:56,400
well, potentially there's a
conflict of interest there.

196
00:08:56,400 --> 00:08:58,440
So we'd like them to have independence

197
00:08:58,440 --> 00:09:01,320
and be able to report
as high up as possible,

198
00:09:01,320 --> 00:09:03,120
hopefully directly to
the Board of Directors

199
00:09:03,120 --> 00:09:04,980
or Board of Trustees.

200
00:09:04,980 --> 00:09:06,150
Now, some supporting roles

201
00:09:06,150 --> 00:09:08,430
to the Chief Information Security Officer

202
00:09:08,430 --> 00:09:10,830
include an Information Assurance Officer,

203
00:09:10,830 --> 00:09:12,870
an Information Assurance Manager,

204
00:09:12,870 --> 00:09:15,063
and an Information Security Officer.

205
00:09:16,290 --> 00:09:18,693
So let's look at some of CISO duties.

206
00:09:20,152 --> 00:09:23,400
They're gonna be a subject matter expert,

207
00:09:23,400 --> 00:09:26,490
they're gonna be an advisor,
they're gonna be an educator,

208
00:09:26,490 --> 00:09:29,040
and they're gonna be an
information security champion.

209
00:09:29,040 --> 00:09:30,540
They're gonna be a cheerleader,

210
00:09:30,540 --> 00:09:31,980
and this is really important.

211
00:09:31,980 --> 00:09:32,813
They're the ones

212
00:09:32,813 --> 00:09:35,430
that are going to bring the
excitement and the enthusiasm

213
00:09:35,430 --> 00:09:38,313
about information security or
cybersecurity to the table.

214
00:09:39,690 --> 00:09:40,770
They will be responsible

215
00:09:40,770 --> 00:09:43,560
for managing the information
security program.

216
00:09:43,560 --> 00:09:45,960
They develop and maintained
governance documents.

217
00:09:45,960 --> 00:09:47,520
We'll talk about governance documents,

218
00:09:47,520 --> 00:09:50,100
policies, standards,
procedures, agreements

219
00:09:50,100 --> 00:09:51,150
in just a little bit.

220
00:09:52,260 --> 00:09:53,640
They're responsible for communicating

221
00:09:53,640 --> 00:09:56,310
with business process owners
and relevant stakeholders

222
00:09:56,310 --> 00:09:59,400
including our data and system owners.

223
00:09:59,400 --> 00:10:01,770
They're responsible for
recommending and managing

224
00:10:01,770 --> 00:10:03,603
the information security budget.

225
00:10:04,530 --> 00:10:07,560
They serve on relevant internal
and external committees,

226
00:10:07,560 --> 00:10:09,000
and often they'll serve as chair

227
00:10:09,000 --> 00:10:11,730
of the Information Security
Steering Committee,

228
00:10:11,730 --> 00:10:15,543
and they will report to and
advise the Board of Directors.

229
00:10:17,790 --> 00:10:20,550
Now, there are complimentary
roles in the organization

230
00:10:20,550 --> 00:10:22,380
to the Information Security Officer

231
00:10:22,380 --> 00:10:24,300
or Chief Information Security Officer.

232
00:10:24,300 --> 00:10:26,844
We have Privacy Officers,
Compliance Officers,

233
00:10:26,844 --> 00:10:31,260
Physical Security Officers,
and internal audit.

234
00:10:31,260 --> 00:10:34,350
The Privacy Officer in an
organization is responsible

235
00:10:34,350 --> 00:10:37,260
for developing, implementing,
and administering

236
00:10:37,260 --> 00:10:40,770
all aspects of an
organization's privacy program.

237
00:10:40,770 --> 00:10:44,190
The Compliance Officer is
responsible for identifying

238
00:10:44,190 --> 00:10:47,190
applicable statutory, regulatory,

239
00:10:47,190 --> 00:10:49,380
and contractual requirements,

240
00:10:49,380 --> 00:10:52,290
as well as ensuring
the compliance thereof,

241
00:10:52,290 --> 00:10:54,870
that we know what the
compliance requirements are

242
00:10:54,870 --> 00:10:56,620
and that we're complying with them.

243
00:10:58,020 --> 00:11:01,110
The Physical Security Officer
is responsible for ensuring

244
00:11:01,110 --> 00:11:03,360
that appropriate physical
security procedures

245
00:11:03,360 --> 00:11:06,600
have been established
and controls implemented.

246
00:11:06,600 --> 00:11:08,970
Now, these really are
very complimentary roles

247
00:11:08,970 --> 00:11:10,950
and very often have to work together

248
00:11:10,950 --> 00:11:12,660
with an Information Security Officer

249
00:11:12,660 --> 00:11:14,460
or a Chief Information Security Officer,

250
00:11:14,460 --> 00:11:16,290
and in the best of all worlds,

251
00:11:16,290 --> 00:11:20,340
they all report up to the
same executive management.

252
00:11:20,340 --> 00:11:22,620
And then lastly, we have internal audit.

253
00:11:22,620 --> 00:11:24,270
Internal audit is responsible

254
00:11:24,270 --> 00:11:27,930
for providing independent
objective assurance services.

255
00:11:27,930 --> 00:11:29,400
I love audit.

256
00:11:29,400 --> 00:11:31,980
Audit is really maligned
in so many organizations.

257
00:11:31,980 --> 00:11:33,420
People are like, "The auditor's coming.

258
00:11:33,420 --> 00:11:34,800
Don't say anything more."

259
00:11:34,800 --> 00:11:37,470
I think audit just has such an
important role and function,

260
00:11:37,470 --> 00:11:40,563
and should be really well
respected in an organization.

261
00:11:42,150 --> 00:11:44,100
And then there are some functional roles,

262
00:11:44,100 --> 00:11:45,960
and we've already discussed
these functional roles.

263
00:11:45,960 --> 00:11:48,670
Owners, custodians, and users.

264
00:11:48,670 --> 00:11:51,780
Owners are responsible for
oversight and decisions

265
00:11:51,780 --> 00:11:54,900
related to classifications,
access control,

266
00:11:54,900 --> 00:11:56,730
and protection mechanisms.

267
00:11:56,730 --> 00:11:59,490
Now, the carve out on that
was in a MAC environment,

268
00:11:59,490 --> 00:12:02,070
mandatory access control environment,

269
00:12:02,070 --> 00:12:05,490
the owners don't get to make
those classification decisions

270
00:12:05,490 --> 00:12:07,320
or the access control decisions.

271
00:12:07,320 --> 00:12:08,153
Those are done.

272
00:12:08,153 --> 00:12:10,290
That's done by classification officers,

273
00:12:10,290 --> 00:12:11,340
and the relationship

274
00:12:11,340 --> 00:12:13,940
between classification,
clearance, and need to know.

275
00:12:15,090 --> 00:12:16,440
Now, custodians are responsible

276
00:12:16,440 --> 00:12:18,480
for advising, implementing, managing,

277
00:12:18,480 --> 00:12:21,570
and monitoring those
data protection controls.

278
00:12:21,570 --> 00:12:23,700
And our users are responsible

279
00:12:23,700 --> 00:12:27,510
for treating data and interacting
with information systems

280
00:12:27,510 --> 00:12:31,592
in accordance with policy
and handling standards.

281
00:12:31,592 --> 00:12:34,530
And that brings us to a
three-second challenge.

282
00:12:34,530 --> 00:12:35,640
Five challenge questions.

283
00:12:35,640 --> 00:12:36,660
Three seconds each.

284
00:12:36,660 --> 00:12:38,670
You know how to do this.

285
00:12:38,670 --> 00:12:40,320
Question one, the term used to describe

286
00:12:40,320 --> 00:12:42,060
the responsibility of leadership

287
00:12:42,060 --> 00:12:45,570
to determine, articulate,
authorize, and fund

288
00:12:45,570 --> 00:12:48,153
the desired state of information security.

289
00:12:49,020 --> 00:12:50,463
One, two, three.

290
00:12:52,116 --> 00:12:54,363
It's gonna be security governance.

291
00:12:55,620 --> 00:12:58,470
Number two, this group has
a fiduciary responsibility

292
00:12:58,470 --> 00:13:01,320
to the organization and its stakeholders.

293
00:13:01,320 --> 00:13:02,673
One, two, three.

294
00:13:04,080 --> 00:13:06,513
It's the Board of
Directors, or equivalent.

295
00:13:10,140 --> 00:13:12,960
Number three, the group
of senior representatives

296
00:13:12,960 --> 00:13:15,270
that are tasked with achieving consensus

297
00:13:15,270 --> 00:13:17,883
on strategy and priorities.

298
00:13:18,870 --> 00:13:20,103
One, two, three.

299
00:13:21,600 --> 00:13:23,100
That's the steering committee.

300
00:13:25,620 --> 00:13:29,250
Number four, specific
position or job title

301
00:13:29,250 --> 00:13:33,123
that an individual occupies
within an organization or group.

302
00:13:34,800 --> 00:13:36,450
One, two, three.

303
00:13:36,450 --> 00:13:38,100
And that's a role.

304
00:13:38,100 --> 00:13:40,710
And lastly, number five,
a group or individual

305
00:13:40,710 --> 00:13:43,560
responsible for advising,
implementing, managing,

306
00:13:43,560 --> 00:13:46,980
and monitoring data protection controls.

307
00:13:46,980 --> 00:13:47,813
You better get this one.

308
00:13:47,813 --> 00:13:48,690
This is you and me.

309
00:13:48,690 --> 00:13:49,800
What is it?

310
00:13:49,800 --> 00:13:51,600
One, two, three.

311
00:13:51,600 --> 00:13:52,683
That's a custodian.

312
00:13:53,819 --> 00:13:56,850
All right, that brings us
to a security-in-action.

313
00:13:56,850 --> 00:13:59,160
We can apply our knowledge.

314
00:13:59,160 --> 00:14:01,380
It's about perception and support.

315
00:14:01,380 --> 00:14:02,430
You were recently hired

316
00:14:02,430 --> 00:14:04,920
to be the first Information
Security Officer

317
00:14:04,920 --> 00:14:06,810
of a pharmaceutical company.

318
00:14:06,810 --> 00:14:08,250
Prior to your arrival,

319
00:14:08,250 --> 00:14:11,160
the information security
initiatives and projects

320
00:14:11,160 --> 00:14:14,460
were the responsibility
of the IT Director.

321
00:14:14,460 --> 00:14:16,860
Now, you quickly learn
that throughout the company

322
00:14:16,860 --> 00:14:19,890
security is viewed in a
really negative light.

323
00:14:19,890 --> 00:14:24,663
It's seen as onerous, a
productivity inhibitor, and costly.

324
00:14:25,860 --> 00:14:27,150
So my question to you is,

325
00:14:27,150 --> 00:14:30,030
how would you go about addressing
this negative perception?

326
00:14:30,030 --> 00:14:33,030
And who in the organization
should you enlist

327
00:14:33,030 --> 00:14:34,413
to support your efforts?

328
00:14:35,490 --> 00:14:36,323
What are you gonna do?

329
00:14:36,323 --> 00:14:38,790
This is not that unusual a situation.

330
00:14:38,790 --> 00:14:41,793
So go ahead and put me on
pause and jot down some notes.

331
00:14:45,900 --> 00:14:47,100
I would suggest we begin

332
00:14:47,100 --> 00:14:49,350
with evaluating the current situation,

333
00:14:49,350 --> 00:14:53,730
specifically what's causing
this negative perception.

334
00:14:53,730 --> 00:14:56,220
And then it's all gonna
be about communication.

335
00:14:56,220 --> 00:14:57,810
You want to enlist the support

336
00:14:57,810 --> 00:15:00,423
of the Board of Directors
and Executive Management.

337
00:15:01,259 --> 00:15:04,020
You want to engage security champions

338
00:15:04,020 --> 00:15:06,420
throughout the organization,
really at all levels,

339
00:15:06,420 --> 00:15:08,970
people who get it, people
understand this is important,

340
00:15:08,970 --> 00:15:12,540
people who recognize that
protecting our assets,

341
00:15:12,540 --> 00:15:14,230
protecting our company,

342
00:15:14,230 --> 00:15:17,670
by extension is also
protecting our stakeholders

343
00:15:17,670 --> 00:15:20,190
and our customers and our investors,

344
00:15:20,190 --> 00:15:23,040
and ultimately our community,
and maybe even our country.

345
00:15:24,851 --> 00:15:28,140
And we should request that a
Steering Committee be formed

346
00:15:28,140 --> 00:15:32,280
to ensure strategic
alignment and prioritization.

347
00:15:32,280 --> 00:15:34,530
And then you want to lead
that Steering Committee

348
00:15:34,530 --> 00:15:37,470
with grace and with positivity.

349
00:15:37,470 --> 00:15:39,150
When they have those negative comments

350
00:15:39,150 --> 00:15:40,710
about things that have
happened in the past,

351
00:15:40,710 --> 00:15:42,300
let them just roll right over you, right?

352
00:15:42,300 --> 00:15:45,123
You want to lead with
grace and positivity.

353
00:15:46,050 --> 00:15:50,550
And engage your business process
owners in identifying ways

354
00:15:50,550 --> 00:15:54,210
that security will enhance
their desired outcomes.

355
00:15:54,210 --> 00:15:57,213
Doing all that, absolutely,
security-in-action.

356
00:15:58,500 --> 00:15:59,760
There's your word cloud.

357
00:15:59,760 --> 00:16:01,080
You know what to do.

358
00:16:01,080 --> 00:16:03,203
When you're ready, I'll
see you in the next lesson.
