SlideShare a Scribd company logo
BA
RRY
CA
PLIN
H
O
W
D
O
YO
U
SPELL
CISO
?
W
ED
. M
A
Y
14, 2014, 11A
Like what you hear? Tweet it using: #Sec360
How Do You
Spell CISO?
Secure360
Wed. May 14, 2014
bcaplin1@fairview.org
bc@bjb.org @bcaplin
http://about.me/barrycaplin
http://securityandcoffee.blogspot.com
Barry Caplin
Chief Information Security Official
Fairview Health Services
http://about.me/barrycaplin
securityandcoffee.blogspot.com
@bcaplin
Fairview Overview
• Not-for-profit established in 1906
• Academic Health System since 1997
partnership with University of Minnesota
• >22K employees
• >3,300 aligned physicians
 Employed, faculty, independent
• 7 hospitals/medical centers
(>2,500 staffed beds)
• 40-plus primary care clinics
• 55-plus specialty clinics
• 47 senior housing locations
• 30-plus retail pharmacies
4
2012 data
•5.7 million outpatient encounters
•74,649 inpatient admissions
•$2.8 billion total assets
•$3.2 billion total revenue
Who is Fairview?
A partnership of North Memorial and Fairview
Did you ever think about…Did you ever think about…
ChallengesChallenges
• Keep it simple
• Keep it High Level
• Don’t let ‘em pull
you in to the weeds
Game Time!Game Time!
First QuarterFirst Quarter
• Learn the Business
• Culture of Security
• Baseline the Organization
Learn the BusinessLearn the Business
Business/Ops lead – not Security or IT
•Do you know?
− Industry
− Niche
− Mission/Vision
− Why/What/How
− The Organization
Learn the BusinessLearn the Business
• Ask Questions
• Org Charts
• Get Out of the Building!
• 1:1’s; Divisional meetings;
Leaders; C-suite
Learn the BusinessLearn the Business
• Agenda
− Introduction
− learn about the business area,
− what works and what doesn't,
− partnership opportunities,
− what can I do for you?
• Establish your office; Create Champions
A Culture of SecurityA Culture of Security
A journey of a thousand miles begins with a
single step.
- Lao-tzu, The Way of Lao-tzu
Chinese philosopher (604 BC - 531 BC)
You gotta start somewhere.
- Me
A Culture of SecurityA Culture of Security
• Is there existing
training?
• Train for Compliance
• Awareness to
reinforce
• Create Evangelists
A Culture of SecurityA Culture of Security
• Be Relevant
• Connect to the
Business
• Seek out and Destroy
controls that add no
value
Baseline the OrganizationBaseline the Organization
Helps you:
•Know where things stand
•Show progress
Baseline the OrganizationBaseline the Organization
Methods:
•Compare against known
standard
•Maturity Model
CObIT Security Baseline
CObIT Maturity Assessment
Tool
Gartner IT Score
Homegrown
In your spare time…In your spare time…
• Low hanging fruit
• Other duties as assigned
Second QuarterSecond Quarter
• Strategic Planning
• Tactical Planning
• Roadmap
Security is not a Project….
It’s a Lifestyle!
20
Strategic PlanningStrategic Planning
Strategic PlanningStrategic Planning
• High-level
• Outcomes
• Framework
− NIST
− CObIT
− HITRUST
− ISO27001
Strategic PlanningStrategic Planning
• Business info +
• Baseline analysis +
• Risk Assessment +
− Threat Assessment
 Assets; Actors; Actions
• Vision =
− Time Travel
Threat Modeling/AssessmentThreat Modeling/Assessment
• Elevation of Privilege
http://www.microsoft.com/security/sdl/adopt/
• Cntl-Alt-Hack
http://www.controlalthack.com/
• UW Security Cards
http://securitycards.cs.washington.edu/
Tactical PlanningTactical Planning
• Tactics are “How?”
− Support each strategy
− More granular
− Shorter timeframe (1-3 yrs.)
Strategy/Tactics
RoadmapRoadmap
Third Quarter…Third Quarter…
• Execute!
• Metrics/KPIs/KRIs
• Communicating Risk
• BoD Reports
……And BeyondAnd Beyond
The “game” never ends.
•Iterative processes
•Support the “bridges”
•Living documents
•Review and refine
The CISO Guide – How Do You Spell CISO?

More Related Content

PDF
From Cave Man to Business Man, the Evolution of the CISO to CIRO
PDF
Leveraging social media for pharmaceutical companies
PPTX
Trr ppt
PDF
Building security leaders ISSA Virtual CISO Series
PPTX
NTXISSACSC2 - Texas CISO Council - Information Security Program Essential Gui...
PPT
The CISO in 2020: Prepare for the Unexpected
PDF
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
PDF
Super CISO 2020: How to Keep Your Job
From Cave Man to Business Man, the Evolution of the CISO to CIRO
Leveraging social media for pharmaceutical companies
Trr ppt
Building security leaders ISSA Virtual CISO Series
NTXISSACSC2 - Texas CISO Council - Information Security Program Essential Gui...
The CISO in 2020: Prepare for the Unexpected
(Consulting) Couch to CISO: A Security Leader's First 100 Days and Beyond
Super CISO 2020: How to Keep Your Job

Viewers also liked (13)

PPTX
CIO-CTO 90 day plan 2017
DOCX
Impacto de las tic en las educacion
PDF
We can do Facebook marketing differently!
PPTX
Didactica.
PDF
الأستاذ والشيخ حسنين الديب
PPT
Sambit's quiz. Quiz meet 18th sept
PPTX
PPTX
10 ways big data will accelerate your marketing & sales pipeline performance
PDF
Market Research Finland - Biofuels Market in Finland 2009
PPTX
CE 150210107029 PRESENTATION
PDF
5 Reasons Why Small Businesses Fear Obamacare
DOC
Minder jaar voor firma van Marcel Vanthilt
PDF
An overview of Tapit.
CIO-CTO 90 day plan 2017
Impacto de las tic en las educacion
We can do Facebook marketing differently!
Didactica.
الأستاذ والشيخ حسنين الديب
Sambit's quiz. Quiz meet 18th sept
10 ways big data will accelerate your marketing & sales pipeline performance
Market Research Finland - Biofuels Market in Finland 2009
CE 150210107029 PRESENTATION
5 Reasons Why Small Businesses Fear Obamacare
Minder jaar voor firma van Marcel Vanthilt
An overview of Tapit.
Ad

Similar to The CISO Guide – How Do You Spell CISO? (20)

PPTX
Emerging Need of a Chief Information Security Officer (CISO)
PDF
#%! My CISO Says
PPTX
CISOs are from Mars, CIOs are from Venus
PPTX
Stuff my ciso says
PDF
Building an effective Information Security Roadmap
PPTX
Information Security for Business Leaders - Eric Vanderburg - JurInnov
PPTX
Ten Tenets of CISO Success
PPTX
CISO's first 100 days
PDF
my experience as ciso
PPTX
Information Security - Back to Basics - Own Your Vulnerabilities
PPTX
The Gathering Storm
PPTX
Dancyrityshy 1foundatioieh
PPTX
vCISO Overview Virtual CISO Chief Information Security Officer
PDF
CNIT 160: Ch 2b: Security Strategy Development
PPTX
COBIT Approach to Maintain Healthy Cyber Security Status Using NIST - CSF
PDF
Cisco Connect Vancouver 2017 - Embedding IR into the DNA of the business
PPT
Webinar 2 IT Security
PDF
Telling the InfoSec Story
PPTX
NIST IT Standards for Local Governments 2010
PDF
Emerging Need of a Chief Information Security Officer (CISO)
#%! My CISO Says
CISOs are from Mars, CIOs are from Venus
Stuff my ciso says
Building an effective Information Security Roadmap
Information Security for Business Leaders - Eric Vanderburg - JurInnov
Ten Tenets of CISO Success
CISO's first 100 days
my experience as ciso
Information Security - Back to Basics - Own Your Vulnerabilities
The Gathering Storm
Dancyrityshy 1foundatioieh
vCISO Overview Virtual CISO Chief Information Security Officer
CNIT 160: Ch 2b: Security Strategy Development
COBIT Approach to Maintain Healthy Cyber Security Status Using NIST - CSF
Cisco Connect Vancouver 2017 - Embedding IR into the DNA of the business
Webinar 2 IT Security
Telling the InfoSec Story
NIST IT Standards for Local Governments 2010
Ad

More from Barry Caplin (20)

PPTX
Healing healthcare security
PPTX
It’s not If but When 20160503
PPTX
Dreaded Embedded sec360 5-17-16
PPTX
It’s not if but when 20160503
PPT
Wearing Your Heart On Your Sleeve - Literally!
PPTX
Online Self Defense - Passwords
PPT
Bullying and Cyberbullying
PPT
3 factors of fail sec360 5-15-13
PPT
Tech smart preschool parent 2 13
PPT
Embracing the IT Consumerization Imperative NG Security
PPT
Online Self Defense
PPT
Embracing the IT Consumerization Imperitive
PPT
Embracing the IT Consumerization Imperitive
PPTX
IT Consumerization – iPad’ing the Enterprise or BYO Malware?
PPT
Toys in the office 11
PPT
Accidental Insider
PPT
Teens 2.0 - Teens and Social Networks
PPT
Laws of the Game For Valley United Soccer Club travel soccer refs
PPT
Laws of the Game for Valley Athletic Assn (VAA) Community Soccer refs
PPTX
How to be a Tech-Smart Parent
Healing healthcare security
It’s not If but When 20160503
Dreaded Embedded sec360 5-17-16
It’s not if but when 20160503
Wearing Your Heart On Your Sleeve - Literally!
Online Self Defense - Passwords
Bullying and Cyberbullying
3 factors of fail sec360 5-15-13
Tech smart preschool parent 2 13
Embracing the IT Consumerization Imperative NG Security
Online Self Defense
Embracing the IT Consumerization Imperitive
Embracing the IT Consumerization Imperitive
IT Consumerization – iPad’ing the Enterprise or BYO Malware?
Toys in the office 11
Accidental Insider
Teens 2.0 - Teens and Social Networks
Laws of the Game For Valley United Soccer Club travel soccer refs
Laws of the Game for Valley Athletic Assn (VAA) Community Soccer refs
How to be a Tech-Smart Parent

Recently uploaded (20)

PDF
Deliverable file - Regulatory guideline analysis.pdf
PDF
Chapter 5_Foreign Exchange Market in .pdf
PDF
Nidhal Samdaie CV - International Business Consultant
PPTX
Belch_12e_PPT_Ch18_Accessible_university.pptx
PDF
Tata consultancy services case study shri Sharda college, basrur
PPTX
Probability Distribution, binomial distribution, poisson distribution
DOCX
unit 2 cost accounting- Tender and Quotation & Reconciliation Statement
PPTX
svnfcksanfskjcsnvvjknsnvsdscnsncxasxa saccacxsax
PDF
Power and position in leadershipDOC-20250808-WA0011..pdf
PDF
Roadmap Map-digital Banking feature MB,IB,AB
PPTX
Dragon_Fruit_Cultivation_in Nepal ppt.pptx
PDF
Reconciliation AND MEMORANDUM RECONCILATION
PPTX
Lecture (1)-Introduction.pptx business communication
PDF
Solara Labs: Empowering Health through Innovative Nutraceutical Solutions
PDF
COST SHEET- Tender and Quotation unit 2.pdf
PDF
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
PDF
NISM Series V-A MFD Workbook v December 2024.khhhjtgvwevoypdnew one must use ...
PPTX
job Avenue by vinith.pptxvnbvnvnvbnvbnbmnbmbh
PDF
BsN 7th Sem Course GridNNNNNNNN CCN.pdf
PDF
Cours de Système d'information about ERP.pdf
Deliverable file - Regulatory guideline analysis.pdf
Chapter 5_Foreign Exchange Market in .pdf
Nidhal Samdaie CV - International Business Consultant
Belch_12e_PPT_Ch18_Accessible_university.pptx
Tata consultancy services case study shri Sharda college, basrur
Probability Distribution, binomial distribution, poisson distribution
unit 2 cost accounting- Tender and Quotation & Reconciliation Statement
svnfcksanfskjcsnvvjknsnvsdscnsncxasxa saccacxsax
Power and position in leadershipDOC-20250808-WA0011..pdf
Roadmap Map-digital Banking feature MB,IB,AB
Dragon_Fruit_Cultivation_in Nepal ppt.pptx
Reconciliation AND MEMORANDUM RECONCILATION
Lecture (1)-Introduction.pptx business communication
Solara Labs: Empowering Health through Innovative Nutraceutical Solutions
COST SHEET- Tender and Quotation unit 2.pdf
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
NISM Series V-A MFD Workbook v December 2024.khhhjtgvwevoypdnew one must use ...
job Avenue by vinith.pptxvnbvnvnvbnvbnbmnbmbh
BsN 7th Sem Course GridNNNNNNNN CCN.pdf
Cours de Système d'information about ERP.pdf

The CISO Guide – How Do You Spell CISO?

Editor's Notes

  • #4: Talk based on 7 parts of 5 part blog series (blog link, twitter link) Check out my about.me, with links to twitter feed and Security and Coffee blog.