TRICO Retreat - Today’s Topics:
- What did we learn from the member assessments?
- Most common risks and gaps across membership
- How to read and understand my Security Assessment Report?
- Now that I have all this information… Where do I start?
TRICO Retreat - Todays Topics: What did we learn from the member - - PowerPoint PPT Presentation
TRICO Retreat - Todays Topics: What did we learn from the member assessments? Most common risks and gaps across membership How to read and understand my Security Assessment Report? Now that I have all this information Where do
37 members participated in the assessment:
don’t have a documented Business Continuity Plan in place
don’t encrypt sensitive information
59.5%
40.5%
5.4%
2.74%
2.7%
2.7%
40.5%
89.2%
78.4%
Initial web based survey:
effort to determine important controls required to reduce risks
locations, systems, etc.)
answers to the Risk Assessment Survey
Negative answers automatically change to red for further discussions
security controls are executed against “good practice” for your risks
the overall maturity level
in place
Fully Implemented Partially Implemented Not Implemented Not Applicable
14 Domains and 41 Controls were evaluated that are aligned with the ISO 27001 Framework:
We recommend each municipality take a “risk based” approach to their gap remediation efforts. We also recommend that you consider addressing each of the findings listed in section C “Identified Risk with Highest Priorities”. These will likely have the most notable impact on reducing the likelihood of your municipality experiencing a cyber incident and increasing the overall security posture Not to worry – You are not alone! The JIF is currently working on developing a strategy to address common deficiencies and guide you through the process