SlideShare a Scribd company logo
From Data Theft to …

Compliance & Risk Management!

           PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
… Agenda




2
      PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
…Agenda




3
      PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
…just a simple pricelist ?




4
        PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
…active measures against card fraud




5
        PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
PCI DSS, PA DSS, 27001, CoBiT, NERC, Basel
             II, SOX, ... … … …
Mounting External Compliance Regulations
3 out 4 organizations must comply with two or                                                                                                                         PII Security
                                                                                                                                                                      Standards
more regulations and corresponding audits.
                                                                                                                                                                      Sarbanes-Oxley,
                                                                                                                                                                      Section 404

43% of organizations comply with 3 or more                                                                                                        PCI Data Security   PCI Data Security
                                                                                                                                                  Standards (DSS)     Standards (DSS)
regulations.
                                                                                                                                                  Basel II            Basel II



                                                                                                                               SB1386             SB1386              SB1386
                                                                                                                               (CA Privacy Act)   (CA Privacy Act)    (CA Privacy Act)

                                                                                                             USA Patriot Act   USA Patriot Act    USA Patriot Act     USA Patriot Act



                                                                                           Gramm Leach       Gramm Leach       Gramm Leach        Gramm Leach         Gramm Leach
                                                                                           Bliley (GLBA)     Bliley (GLBA)     Bliley (GLBA)      Bliley (GLBA)       Bliley (GLBA)

                                                             21CFR11                       21CFR11           21CFR11           21CFR11            21CFR11             21CFR11


                              HIPAA                          HIPAA                         HIPAA             HIPAA             HIPAA              HIPAA               HIPAA


EU Directive                  EU Directive                   EU Directive                  EU Directive      EU Directive      EU Directive       EU Directive        EU Directive


*The Struggle to Manage Security Compliance for Multiple Regulations”..SecurityCompliance.com


                                                                                                           Time

  7
                                    PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
Today Organizations Spend 30-50%
More On Compliance Than They Should




   Our IT Networks Were Never Designed With
              Compliance In Mind
Compliance & IT Risk Management Challenges


                                     ry
                                ulato
                           f Reg
                    La ck o wledge
                         Kno


                                     HIPAA                             Excel



                                        SOX                 Database                      Business
       Security                                                                           Processes
        Policy
                                             PCI           Manual                        IT
                                                           Surveys                    Resources
            Password Length
            Special Characters
                                                   Non Standardized
                                                      Processes

                  Functional Silos                                               Disparate
                                                                               Data Collection




9
      PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
Challenges in Compliance and Risk Management

Business Interests




                                       Auditor




                     Stakeholders
Data Collection
Standardized Compliance & Control Framework [UCF]
Assess


                                                        Technical Controls:
                                                                Automatically assess technical
                                                                controls through integration to
                                                                Lumension and 3rd party tools




                                                        Procedural & Physical Controls:
                                                                Utilize automated workflow
                                                                based surveys




13
         PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
Standardized & IT Risk Mgmt. Framework
                                                                      Regulation Authority Documents
                                                                       GLBA PCI FISMA HIPAA NHS NERC SOX ISO/IEC…



Business Interests                 Corporate Policies

  Business Processes
  Revenue Streams
  Trade Secrets        IT Assets

                                                                              Profile Risk Attributes


                                                                                    Open to the Internet

                                                                                    Contains Credit Card
                                                                                    Information

                                                                                    Contains Customer Data



                               Applicable Controls      Pass/Fail Regulation Assessment

                                     Password Length

                                     Data Encryption

                                     Power Save

                                                        Corp-Policy   ISO 27001      PCI            NERC
                                                          100%          65%          65%             30%
Automation of Assessment Data
        Consolidated Assessment Data supports a holistic view of
                     compliance and IT risk posture




          Technical Controls                                        Procedural & Physical Controls

                      Automated Connectors                          Automated Assessment Workflow

      Lumension        Lumension         3rd Party
     Patch, Scan &    Application &                                     Web-Based    Auditor / Analyst
                                         Products                        Surveys       Attestation
     Configuration       Device
                        Control




15
             PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
Connector …




16
       PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
Connector …




17
       PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
Connector …




18
       PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
Connector …




19
       PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
Remediate




                                             Remediate: Prioritize remediation
                                             efforts based on impact to overall
                                             organizational IT risk &
                                             compliance posture




20
       PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
Manage




                                         Manage: Create operational and
                                         strategic visibility across
                                         compliance, IT risk postures




21
         PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
Identify…and it starts again
Adaptation
Lumension Risk Manager - summary



Give you better visibility into your
 compliance and risk posture.



Help you save time & money in your
 security management process.



24
       PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
Global Headquarters
15880 N. Greenway-Hayden Loop
Suite 100
Scottsdale, AZ 85260

1.888.725.7828
info@lumension.com



                       thomas.wendrich@lumension.com

               www.lumension.com/itgrc-software

More Related Content

PDF
Lumension Security - State of Endpoint and Security DSS @Vilnius 2010
PDF
Sunera Business & Technology Risk Consulting
PDF
Exemplo de política BYOD
PDF
Threat Detect Hipaa Compliance
PDF
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
PDF
GDPR Changing Mindset
PDF
Business Associate Assurance: What Covered Entities Need to Know
PDF
The Definitive GDPR Guide for Event Professionals
Lumension Security - State of Endpoint and Security DSS @Vilnius 2010
Sunera Business & Technology Risk Consulting
Exemplo de política BYOD
Threat Detect Hipaa Compliance
Richard Hogg & Dennis Waldron - #InfoGov17 - Cognitive Unified Governance & P...
GDPR Changing Mindset
Business Associate Assurance: What Covered Entities Need to Know
The Definitive GDPR Guide for Event Professionals

What's hot (6)

PDF
Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...
PPTX
eDiscovery and Records Oh...My!
PPTX
GDPR & digital strategy
PDF
Meaningful Use Risk Analysis Webinar
PPT
Data Security For Compliance 2
PDF
Data Protection Brochure
Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...
eDiscovery and Records Oh...My!
GDPR & digital strategy
Meaningful Use Risk Analysis Webinar
Data Security For Compliance 2
Data Protection Brochure
Ad

Similar to Lumension LCRM - DSS @Vilnius 2010 (20)

PDF
7 Mistakes of IT Security Compliance - and Steps to Avoid Them
PDF
DSS ITSEC CONFERENCE - Lumension Security - Real Time Risk & Compliance Man...
PDF
Enterprise Security Architecture: From Access to Audit
PDF
Sunera business & technology risk consulting services -slide share
PDF
2007 issa journal-building a comprehensive security control framework
PPT
Automating Policy Compliance and IT Governance
PPTX
Analyzing Your Government Contract Cybersecurity Compliance
PDF
Valiente Balancing It SecurityCompliance, Complexity & Cost
PDF
Automating security policies (compliance) with Rudder
PPTX
Cybersecurity Compliance in Government Contracts
PPTX
Analyzing Your GovCon Cybersecurity Compliance
PPTX
Information Security Management System ISO/IEC 27001:2005
PDF
DSS ITSEC Conference 2012 - RISK & COMPLIANCE
PPTX
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
PPT
Cybersecurity exchange briefing oct 2012 v2
PPTX
Big data security the perfect storm
PDF
Guide to hipaa compliance for containers
PDF
Information Security It's All About Compliance
PDF
Complying with Cybersecurity Regulations for IBM i Servers and Data
PPTX
The IT Analysis Paralysis
7 Mistakes of IT Security Compliance - and Steps to Avoid Them
DSS ITSEC CONFERENCE - Lumension Security - Real Time Risk & Compliance Man...
Enterprise Security Architecture: From Access to Audit
Sunera business & technology risk consulting services -slide share
2007 issa journal-building a comprehensive security control framework
Automating Policy Compliance and IT Governance
Analyzing Your Government Contract Cybersecurity Compliance
Valiente Balancing It SecurityCompliance, Complexity & Cost
Automating security policies (compliance) with Rudder
Cybersecurity Compliance in Government Contracts
Analyzing Your GovCon Cybersecurity Compliance
Information Security Management System ISO/IEC 27001:2005
DSS ITSEC Conference 2012 - RISK & COMPLIANCE
Vendor Management for PCI DSS; EI3PA; HIPAA and FFIEC
Cybersecurity exchange briefing oct 2012 v2
Big data security the perfect storm
Guide to hipaa compliance for containers
Information Security It's All About Compliance
Complying with Cybersecurity Regulations for IBM i Servers and Data
The IT Analysis Paralysis
Ad

More from Andris Soroka (20)

PPTX
Digitala Era 2017 - TransactPro - Normunds Aizstrauts - Maksājumu un finansu ...
PPTX
Digitala Era 2017 - Datu Valsts Inspekcija - Lauris Linabergs - Vispārīgā dau...
PPT
Digitala Era 2017 - PMLP - Vilnis Vītoliņš - Gaisa kuģu pasažieru datu apstrā...
PPTX
Digitala Era 2017 - BOD LAW - Līva Aleksejeva - LIELIE DATI un personas datu ...
PPTX
Digitala Era 2017 - Spridzans Law Office - Anna Vladimirova Krykova - Mobilo ...
PDF
Digitala Era 2017 - ZAB “BULLET” - Ivo Krievs - Vai uz valsti attiecināmi cit...
PPTX
Digitala Era 2017 - LSPDSA - Arnis Puksts - Datu aizsardzības speciālists (DPO)
PPTX
Digitala Era 2017 - IIZI - Lauris Kļaviņš - GDPR - Kādus izdevumus un riskus ...
PPTX
Digitala Era 2017 - E-Risinajumi - Māris Ruķers - Vai ar vienu datu aizsardzī...
PPTX
Digitala Era 2017 - Gints Puškundzis - Personas datu apstrādes līgumi
PDF
Digitala Era 2017 - DatuAizsardziba.LV - Agnese Boboviča - Datu aizsardzības ...
PPTX
Digitala Era 2017 - NotAKey - Janis Graubins - Mobile technologies for single...
PPTX
Digitala Era 2017 - Hermitage Solutions - Gatis Kaušs - Clearswift - Komunikā...
PDF
Digitala Era 2017 - Digital Mind - Leons Mednis - eDiscovery risinājums GDPR ...
PPTX
Digitala Era 2017 - ALSO - Artjoms Krūmiņš - Personas datu regulas (EU GDPR) ...
PPTX
Digitala Era 2017 - ZAB Skopiņa & Azanda - Jūlija Terjuhana - Tiesības uz dat...
PDF
Digitala Era 2017 - IT Centrs - Agris Krusts - Latvijas iedzīvotāju digitālo ...
PPTX
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Datu Aizsardzības Tehnoloģiskā...
PPTX
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Mobilitāte un Personas Datu Dr...
PPTX
Digitala Era 2017 - DSS.LV - Andris Soroka - Personas datu regulas tehnoloģis...
Digitala Era 2017 - TransactPro - Normunds Aizstrauts - Maksājumu un finansu ...
Digitala Era 2017 - Datu Valsts Inspekcija - Lauris Linabergs - Vispārīgā dau...
Digitala Era 2017 - PMLP - Vilnis Vītoliņš - Gaisa kuģu pasažieru datu apstrā...
Digitala Era 2017 - BOD LAW - Līva Aleksejeva - LIELIE DATI un personas datu ...
Digitala Era 2017 - Spridzans Law Office - Anna Vladimirova Krykova - Mobilo ...
Digitala Era 2017 - ZAB “BULLET” - Ivo Krievs - Vai uz valsti attiecināmi cit...
Digitala Era 2017 - LSPDSA - Arnis Puksts - Datu aizsardzības speciālists (DPO)
Digitala Era 2017 - IIZI - Lauris Kļaviņš - GDPR - Kādus izdevumus un riskus ...
Digitala Era 2017 - E-Risinajumi - Māris Ruķers - Vai ar vienu datu aizsardzī...
Digitala Era 2017 - Gints Puškundzis - Personas datu apstrādes līgumi
Digitala Era 2017 - DatuAizsardziba.LV - Agnese Boboviča - Datu aizsardzības ...
Digitala Era 2017 - NotAKey - Janis Graubins - Mobile technologies for single...
Digitala Era 2017 - Hermitage Solutions - Gatis Kaušs - Clearswift - Komunikā...
Digitala Era 2017 - Digital Mind - Leons Mednis - eDiscovery risinājums GDPR ...
Digitala Era 2017 - ALSO - Artjoms Krūmiņš - Personas datu regulas (EU GDPR) ...
Digitala Era 2017 - ZAB Skopiņa & Azanda - Jūlija Terjuhana - Tiesības uz dat...
Digitala Era 2017 - IT Centrs - Agris Krusts - Latvijas iedzīvotāju digitālo ...
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Datu Aizsardzības Tehnoloģiskā...
Digitala Era 2017 - DSS.LV - Arturs Filatovs - Mobilitāte un Personas Datu Dr...
Digitala Era 2017 - DSS.LV - Andris Soroka - Personas datu regulas tehnoloģis...

Recently uploaded (20)

PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Machine learning based COVID-19 study performance prediction
PDF
Modernizing your data center with Dell and AMD
PDF
Electronic commerce courselecture one. Pdf
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
KodekX | Application Modernization Development
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Unlocking AI with Model Context Protocol (MCP)
DOCX
The AUB Centre for AI in Media Proposal.docx
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PPTX
Cloud computing and distributed systems.
PDF
Network Security Unit 5.pdf for BCA BBA.
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Encapsulation_ Review paper, used for researhc scholars
Diabetes mellitus diagnosis method based random forest with bat algorithm
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Agricultural_Statistics_at_a_Glance_2022_0.pdf
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Machine learning based COVID-19 study performance prediction
Modernizing your data center with Dell and AMD
Electronic commerce courselecture one. Pdf
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
KodekX | Application Modernization Development
Building Integrated photovoltaic BIPV_UPV.pdf
Unlocking AI with Model Context Protocol (MCP)
The AUB Centre for AI in Media Proposal.docx
Digital-Transformation-Roadmap-for-Companies.pptx
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Cloud computing and distributed systems.
Network Security Unit 5.pdf for BCA BBA.

Lumension LCRM - DSS @Vilnius 2010

  • 1. From Data Theft to … Compliance & Risk Management! PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 2. … Agenda 2 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 3. …Agenda 3 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 4. …just a simple pricelist ? 4 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 5. …active measures against card fraud 5 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 6. PCI DSS, PA DSS, 27001, CoBiT, NERC, Basel II, SOX, ... … … …
  • 7. Mounting External Compliance Regulations 3 out 4 organizations must comply with two or PII Security Standards more regulations and corresponding audits. Sarbanes-Oxley, Section 404 43% of organizations comply with 3 or more PCI Data Security PCI Data Security Standards (DSS) Standards (DSS) regulations. Basel II Basel II SB1386 SB1386 SB1386 (CA Privacy Act) (CA Privacy Act) (CA Privacy Act) USA Patriot Act USA Patriot Act USA Patriot Act USA Patriot Act Gramm Leach Gramm Leach Gramm Leach Gramm Leach Gramm Leach Bliley (GLBA) Bliley (GLBA) Bliley (GLBA) Bliley (GLBA) Bliley (GLBA) 21CFR11 21CFR11 21CFR11 21CFR11 21CFR11 21CFR11 HIPAA HIPAA HIPAA HIPAA HIPAA HIPAA HIPAA EU Directive EU Directive EU Directive EU Directive EU Directive EU Directive EU Directive EU Directive *The Struggle to Manage Security Compliance for Multiple Regulations”..SecurityCompliance.com Time 7 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 8. Today Organizations Spend 30-50% More On Compliance Than They Should Our IT Networks Were Never Designed With Compliance In Mind
  • 9. Compliance & IT Risk Management Challenges ry ulato f Reg La ck o wledge Kno HIPAA Excel SOX Database Business Security Processes Policy PCI Manual IT Surveys Resources Password Length Special Characters Non Standardized Processes Functional Silos Disparate Data Collection 9 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 10. Challenges in Compliance and Risk Management Business Interests Auditor Stakeholders
  • 12. Standardized Compliance & Control Framework [UCF]
  • 13. Assess Technical Controls: Automatically assess technical controls through integration to Lumension and 3rd party tools Procedural & Physical Controls: Utilize automated workflow based surveys 13 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 14. Standardized & IT Risk Mgmt. Framework Regulation Authority Documents GLBA PCI FISMA HIPAA NHS NERC SOX ISO/IEC… Business Interests Corporate Policies Business Processes Revenue Streams Trade Secrets IT Assets Profile Risk Attributes Open to the Internet Contains Credit Card Information Contains Customer Data Applicable Controls Pass/Fail Regulation Assessment Password Length Data Encryption Power Save Corp-Policy ISO 27001 PCI NERC 100% 65% 65% 30%
  • 15. Automation of Assessment Data Consolidated Assessment Data supports a holistic view of compliance and IT risk posture Technical Controls Procedural & Physical Controls Automated Connectors Automated Assessment Workflow Lumension Lumension 3rd Party Patch, Scan & Application & Web-Based Auditor / Analyst Products Surveys Attestation Configuration Device Control 15 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 16. Connector … 16 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 17. Connector … 17 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 18. Connector … 18 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 19. Connector … 19 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 20. Remediate Remediate: Prioritize remediation efforts based on impact to overall organizational IT risk & compliance posture 20 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 21. Manage Manage: Create operational and strategic visibility across compliance, IT risk postures 21 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 24. Lumension Risk Manager - summary Give you better visibility into your compliance and risk posture. Help you save time & money in your security management process. 24 PROPRIETARY & CONFIDENTIAL - NOT FOR PUBLIC DISTRIBUTION
  • 25. Global Headquarters 15880 N. Greenway-Hayden Loop Suite 100 Scottsdale, AZ 85260 1.888.725.7828 info@lumension.com thomas.wendrich@lumension.com www.lumension.com/itgrc-software