IT Risk Management Assessor SPECTRIM Tool Training

Slides:



Advertisements
Similar presentations
Identification and Disposition of Official University Records University of Texas at Arlington Records Management.
Advertisements

CIP Cyber Security – Security Management Controls
Cleveland School District Gerald Finley, Property Manager Friday, July 27, 2012.
1 LBNL Enterprise Computing (EC) January 2003 LBNL Enterprise Computing.
Chapter 5: Project Scope Management
DITSCAP Phase 2 - Verification Pramod Jampala Christopher Swenson.
UNLV Data Governance Executive Sponsors Meeting Office of Institutional Analysis and Planning August 29, 2006.
Commercial Database Applications Testing. Test Plan Testing Strategy Testing Planning Testing Design (covered in other modules) Unit Testing (covered.
Developing an accessibility policy. In this talk we will discuss What is an accessibility policy Why do we need one? Getting started - steps to consult.
Developing an accessibility strategy. In this talk we will discuss an accessibility strategy an accessibility policy getting started - steps to consultation.
1 Records Inventory & Data Classification Workshop Data Classification Project Note: This is an example of one agency’s approach to meeting the state records.
Academic Year.  Still working well 17 reports submitted, 1 missing  9 of 18 departments expressed concerns about assessment 4 departments reported.
U.S. Department of Agriculture eGovernment Program August 14, 2003 eAuthentication Agency Application Pre-Design Meeting eGovernment Program.
State Program Review Process Presented by GSFC Compliance Team.
1.  Describe an overall framework for project integration management ◦ RelatIion to the other project management knowledge areas and the project life.
What is a Business Analyst? A Business Analyst is someone who works as a liaison among stakeholders in order to elicit, analyze, communicate and validate.
U.S. Department of Agriculture eGovernment Program July 15, 2003 eAuthentication Initiative Pre-Implementation Status eGovernment Program.
IT Project Management MIS 492/592, Fall 2013 CIS 1013.
TECHNOLOGY PLANNING FOR Mary Mehsikomer Division of School Improvement November 2006.
Updated: 08/10/07 Web Grades Overview MAIS The Office of the Registrar and Michigan Administrative Information Services.
The Government Recordkeeping Survey 2008 Natalie Dewson, Senior Advisor, Government Recordkeeping Programme, Archives New Zealand.
Compliance Monitoring and Enforcement Audit Program - The Audit Process.
Moving Title IA School Plans into Indistar ESEA Odyssey Summer 2015 Presented by Melinda Bessner Oregon Department of Education.
~ pertemuan 4 ~ Oleh: Ir. Abdul Hayat, MTI 20-Mar-2009 [Abdul Hayat, [4]Project Integration Management, Semester Genap 2008/2009] 1 PROJECT INTEGRATION.
BSBPMG501A Manage Project Integrative Processes Manage Project Integrative Processes Project Integration Processes – Part 2 Diploma of Project Management.
U.S. DEPARTMENT OF HEALTH AND HUMAN SERVICES, ADMINISTRATION FOR COMMUNITY LIVING, WASHINGTON DC PHONE | FAX | WEB
Info-Tech Research Group1 Info-Tech Research Group, Inc. Is a global leader in providing IT research and advice. Info-Tech’s products and services combine.
Project Management Finals Lesson 1 - Principles - Techniques - Tools.
Preparing for Title IIA Monitoring Review (FY15) November 9, 2015 Deborah Walker Meagan Steiner David LeBlanc.
Field Analyst Support Team (FAST) School Finance Division
Continuing Professional Development: Activities, outcomes and audit
Faculty Advisor Responsibilities
The Butterfly Effect: How Small Changes Improve the Big Picture
Accountability & Structured Privacy Management
Sample Fit-Gap Kick-off
Responsible District and School Codes
IT Project Management MIS419/576 Fall 2017.
Office 365 Security Assessment Workshop
Dawn Hendricks, Ph.D. Early Childhood Special Education Coordinator
Information Technology (IT) Audits
Unit Organization 1. Unit Organization. NC is comprised of one group and three squadrons. Each semester, the three flights will be established.
Please review these important Webinar Etiquette guidelines
Public School Monitoring Roadmap
Software and Systems Integration
JACKSON STATE UNIVERSITY ACADEMIC ASSESSMENT COMMITTEE WORKSHOP
Preparing for Systems Verification
Training for New District Test Coordinators
Description of Revision
CIS 349 Competitive Success/snaptutorial.com
CIS 349 Education for Service/snaptutorial.com
CIS 349 Teaching Effectively-- snaptutorial.com
FY18 IT Risk Assessment Process Overview
IT Development Initiative: Status and Next Steps
End of Year Performance Review Meetings and objective setting for 2018/19 This briefing pack is designed to be used by line managers to brief their teams.
Overview – Processes Overview Purpose Roles & Responsibilities
RECORDS AND INFORMATION
UNLV Data Governance Executive Sponsors Meeting
IS&T Project Reviews September 9, 2004.
FY18 IT Risk Assessment Process Reminder
Chapter 13: Systems Analysis and Design
FY19 Federal Grant Monitoring: Titles I, II, IV
2019 Meeting 1 Northern Ontario Safety Group.
The Process for Final Approval: Ongoing Monitoring
Using Data to Monitor Title I, Part D
Managing Federal grants
BCS Template Presentation February 22, 2018
{Project Name} Organizational Chart, Roles and Responsibilities
Process and Procedure Documentation
New Faculty Orientation
Starfish Training Erie Community College
Presentation transcript:

IT Risk Management Assessor SPECTRIM Tool Training FY 2017 Group email: ra@tamu.edu David Sustaita Zachary Cox Daniel Janecek Lead Senior IT Policy Analyst IT Policy Analyst IT Policy Analyst

Why you are here You have been identified as a potential Assessor by someone in your IT department Admin rights to individual workstation(s) Manage servers or domain workstations Maintain lab equipment This is the agenda for our meeting.

Objectives By the end of this training, you will be able to: Answer risk assessment questions Respond to findings – corrective actions / risk management decisions This is the agenda for our meeting.

Outline FY17 Timeline SPECTRIM Overview Process Overview Roles & Responsibilities Assessment Questions Findings Assessment Support This is the agenda for our meeting.

FY 2017 Timeline What everyone wants to know… when is it due.

SPECTRIM Replaced ISAAC as the IT risk assessment tool for the university SPECTRIM is: a web based tool provided by the state a self reporting tool – like tax software an auditable process NOT an inventory management system - don’t need to worry about duplicating efforts New Standard Administrative Procedure (SAP) 29.01.03.M0.03 Security of Electronic Information Resources (07-18-2016): Dean/VP must sign off on the college/division risk assessment report (GCE) Providing the training, guidance, and assistance by using open office hours, workshops, and scheduled lab-time We believe the process we have come up with will make the whole process as painless as possible

Roles and Responsibilities

Roles and Responsibilities Division Risk Assessment Coordinator (D-RAC): D-RAC is a liaison between his/her unit and Texas A&M IT concerning the annual IT risk assessment process. Each college and division may have up to two D-RACs. Assessor: The Assessor is a staff or faculty member who will answer the assessment questions and then be responsible for responding to Findings generated from the assessment results. Reviewer: The reviewer will be another person who reviews an assessment to help ensure its accuracy. The reviewer role is generally a secondary role for a D-RAC and/or Assessor. An individual cannot hold the Assessor and Reviewer roles for the same assessment.

Process Overview Guided collaborative effort with TAMU IT Risk Management and Policy (IT-RMP) Outside SPECTRIM Phase 1: Inventory Management/Resource Identification Phase 2: Grouping and Assessment Inside SPECTRIM Phase 3: Data Entry and Reporting (GCE) Providing the training, guidance, and assistance by using open office hours, workshops, and scheduled lab-time We believe the process we have come up with will make the whole process as painless as possible

Roles and Responsibilities Phase 1: Inventory Management/Resource Identification Division Risk Assessment Coordinator (D-RAC): Liaison to TAMU IT-RMP Monitor progress Ensure inventory list is accurate and up-to-date Canopy / FAMIS Unit IT inventory list Assessor: Assist D-RAC as needed

Roles and Responsibilities Phase 2: Grouping and Assessment Division Risk Assessment Coordinator: Liaison to TAMU IT-RMP Monitor progress Coordinate the scoping of groupings Assign assessor and reviewer roles Assessor: Assist D-RAC as needed Answer assigned assessment questions for groupings Respond to Findings that were generated

Roles and Responsibilities Phase 3: Data Entry and Reporting Division Risk Assessment Coordinator Monitor progress in SPECTRIM Input general information about the groupings created in Phase 2 Create and assign assessments One grouping to one assessment Add defined assessors and reviewers Launch assessments Approve/Reject assessments prior to submission to CISO and Dean/VP Assessor Input assessment answers and findings into SPECTRIM Reviewer Help ensure the data accuracy for assigned assessments Approve/Reject assessments and Findings submitted by the assessor RAU: *MAKE SURE TO SPELL OUT HERE AND EXPLAIN Applications: *Define what this is. These are basically the groupings generated in Phase 1 & 2 Application Assessments: *Define what this is*

Assessment Questions FY 2017: Questionnaire Type Low Questions relate to specific security controls Answer the question as it relates to Texas A&M security control or SAP Multiple choice (5 answer choices) Assessment Type The assessor has to be approved by the department head Application Location Network Low 42 35 38 Moderate 61 51 57 High 101 107 Questionnaire Type

Assessment Answer Choices Response Value Description Implemented The full extent of the requirement has been put into place, documented, and communicated; and is consistently applied. Partially Implemented -0.5 Some of the characteristics of the control requirement are being performed, but may not be documented and communicated, nor consistently applied. Not Implemented -1 The control requirement is not currently being performed or has not been put into practice. Unknown It cannot be determined whether the control requirement is being performed or has been put into practice. Not Applicable The specific control requirement is not applicable to the component being assessed. Define “security profile” and make sure that is the standardized name we want to use

Questionnaire Screenshot Define “security profile” and make sure that is the standardized name we want to use

Findings Assessors are responsible for responding to Findings that were generated based on how he/she answered the assessment questions. A Finding will be generated for every question that was answered as “Partially Implemented”, “Not Implemented”, or “Unknown”. These answer choices demonstrate noncompliance for the related control which then impacts the risk score. Response choices – “Accept Risk” or “Remediate Risk” Note: Findings should be discussed with IT staff to be sure they actively reflect the views of unit.

Finding Responses 1. Accept - nothing will be done to improve compliance from its current state in the following year(s); score will not change Describe why compliance is not met with current controls Justify the risk acceptance 2. Remediate - will do something to improve compliance from its current state in the following year(s); score will change Give tangible actions that will take place in order to work towards becoming compliant. A date of completion is required in SPECTRIM, and that date can go out further than the next risk assessment period.

SPECTRIM Flowchart

Assessment Support (don’t panic) Documents: Excel Spreadsheets – allows you to answer all assessment questions and potential Findings before getting into SPECTRIM SPECTRIM User Guide – give guidance on what each question is asking and how it may apply to the information resources you are assessing Some answers will be provided based on certain criteria Meetings: Office Hours (fall & spring semester) – Thursday 2:30-4:00pm @ TAES Annex, room 117 1 on 1 meetings – scheduled through your college/division D-RAC Group Email: ra@tamu.edu The assessor has to be approved by the department head