2015 IIA-Orange County
Quali&es of an Effec&ve CISO
Miguel (Mike) O. Villegas
CISA, CISSP, GSEC, CEH, PCI QSA, PA-QSA
Vice President- K3DES LLC mike.villegas@k3des.com November 13, 2015
1
Quali&es of an Effec&ve CISO Miguel (Mike) O. Villegas - - PowerPoint PPT Presentation
Quali&es of an Effec&ve CISO Miguel (Mike) O. Villegas CISA, CISSP, GSEC, CEH, PCI QSA, PA-QSA Vice President- K3DES LLC mike.villegas@k3des.com November 13, 2015 2015 IIA-Orange County 1 Abstract Hiring a Chief Informa?on Security
2015 IIA-Orange County
CISA, CISSP, GSEC, CEH, PCI QSA, PA-QSA
1
2015 IIA-Orange County
Hiring a Chief Informa?on Security Officer (CISO) is a laudable goal. It implies execu?ve management realizes the value of having an execu?ve level posi?on for informa?on security. The CISO is an execu?ve who provides expert guidance to other c-level execu?ves on maOers of risk, compliance and informa?on protec?on from a strategic and tac?cal business objec?ves perspec?ve. Security prac??oners are typically technical in nature but do not generally have access to c-level execu?ves, so the CISO posi?on can help fill in this gap. This session will discuss the quali?es of an effec?ve CISO. This includes educa?on, background, repor?ng structure, focus, responsibili?es, personal quali?es, vision, leadership capabili?es, and technical background.
2
2015 IIA-Orange County
3
2015 IIA-Orange County
4
2015 IIA-Orange County
5
A survey conducted in July 2014, 203 US-based C-level execu?ves found a startling lack of respect for CISOs in the enterprise. Below are some interes?ng sta?s?cs:
and should not be part of an organiza?on's leadership team.
purchasing.
data breaches.
nega?vely impacted the organiza?on's financial health.
Source: hOp://www.threaOracksecurity.com/resources/the-role-of-the-ciso.aspx
2015 IIA-Orange County
6
Ideally, a CISO should have a combina?on of business and technical skills that allow for competent contribu?ons and guidance with both IT and execu?ve management. A successful CISO will be able to incisively translate technical challenges and strategies into business terms. Some specific recommended qualifica?ons for a CISO include:
Security;
engineer, or security consultant. Big 4 senior managers or partners from the systems assurance would be an added plus
2015 IIA-Orange County
7
2015 IIA-Orange County
8
2015 IIA-Orange County
9
2015 IIA-Orange County
10
2015 IIA-Orange County
11
2015 IIA-Orange County
12
2015 IIA-Orange County
13
Source: hOp://www.threaOracksecurity.com/resources/the-role-of-the-ciso.aspx
2015 IIA-Orange County
14
Pros:
the informa?on security func?on and CISO
empowerment to deploy the informa?on security program Cons:
empowerment to control the security of corporate assets.
influence to support the CISO.
2015 IIA-Orange County
15
2015 IIA-Orange County
16
2015 IIA-Orange County
17
2015 IIA-Orange County
18
2015 IIA-Orange County
within an organiza?on:
– Coopera?on precludes pernicious silos; – Communica?on is cri?cal but it must be incisive, relevant and done with aplomb; and – Counterbalance ensures contribu?ons are commensurate with business
contribu?ons and par?cipa?on. Befriend, educate, earn trust and provide him or her with insighpul informa?on that will also elevate his or her visibility and credibility.
informa?on security for your enterprise. Use graphics, red-yellow-green icons to highlight areas to focus, and communicate your message in business terms related to cost, ROI, risk, growth and compliance.
relate to your enterprise industry.
19
2015 IIA-Orange County
with key business managers to beOer understand their pain points as it relates to informa?on security, risk and compliance. Be a trusted business advisor.
management lifecycle and the informa?on governance process.
endeavors, not only from within, but from others outside your
Par?cipate in professional organiza?ons to gain insight of what works and what doesn't.
Cybersecurity Framework (used by Cybersecurity Nexus CSX)
20
2015 IIA-Orange County 21
2015 IIA-Orange County
22
2015 IIA-Orange County
23
strategic goals
stand toe-to-toe with IT
demanding aOen?on and respect
Board in terms they understand and support
argument all the ?me
2015 IIA-Orange County
24
2015 IIA-Orange County
25
2015 IIA-Orange County
26
2015 IIA-Orange County
27
2015 IIA-Orange County
28
2015 IIA-Orange County
29
2015 IIA-Orange County
30
2015 IIA-Orange County
Miguel (Mike) O. Villegas is a Vice President for K3DES LLC. He performs and QA’s PCI-DSS and PA-DSS assessments for K3DES clients. He also manages the K3DES ISO/ IEC 27001:2005 program. Mike was previously Director of Informa?on Security at Newegg, Inc. for five years. Mike currently a Contribu?ng Writer for SearchSecurity- TechTarget. Mike has over 30 years of Informa?on Systems security and IT audit experience. Mike was previously Vice President & Technology Risk Manager for Wells Fargo Services responsible for IT Regulatory Compliance and was previously a partner at Arthur Andersen and Ernst & Young for their informa?on systems security and IS audit groups
QSA and ASV as VP for K3DES. Mike was president of the LA ISACA Chapter during 2010-2012 and president of the SF ISACA Chapter during 2005-2006. He was the SF Fall Conference Co-Chair from 2002– 2007 and also served for two years as Vice President on the Board of Directors for ISACA Interna?onal. Mike has taught CISA review courses for over 18 years.
BIO
31