Annual CISO Update Ken Runyon, CISO
Session Outline: 1.Introduction 2.Annual Training Requirements 3.SANS Securing the Human 4.SAQ 2015 Review 5.Q&A
Annual Training and Assessment
ISO Training Requirements: NYS-S ISO or designated security representatives for State Entities Minimum of 37.5 CPE credits annually User Training Requirements: SUNY 6608 NYS P PCI-DSS
SANS Securing the Human
SANS Training: Expected Outcomes Provide standards based information security awareness training All system users (faculty or staff) should participate May be augmented with face to face training (Executives) Does not replace specific PCI or HIPAA required compliance training Current Situation 24 SUNY entities (campuses and other) participate in group program 4 have conducted training, running out of time for cycle
SAQ 2015 Review
ISEC Program Observations: Security Projects remain a top indicator to success Management/Executive are necessary Establishing Policies based on established standards is a requirement Cyber Security Framework v1.0 NIST ISO 27001/27002 COBIT
State Operated ISEC Program Scores
Community College ISEC Program Scores
State Operated ISEC Program Percentages
Community College ISEC Program Percentages
ISEC Controls Observations: IT has addressed the basics as can be seen in the scores Intrusion Prevention remains a stretch goal 1/3 of the campuses do not conduct vulnerability scans Content based filtering (i.e. DLP) is not being done
State Operated IT Controls Scores
Community College IT Controls Scores
State Operated IT Controls Percentages
Community College IT Controls Percentages
Questions