Conversion

27
Leron Zinatullin www.zinatullin.com Convergence of Physical and Information Security @le_rond

Transcript of Conversion

Page 1: Conversion

Leron Zinatullinwww.zinatullin.com

Convergence of Physical and Information Security

@le_rond

Page 2: Conversion

Convergence

“a trend that involves development of managed business process solutions to address risks and interdependencies between business functions and processes within the enterprise ”

Alliance for Enterprise Security Risk Management “Convergence of Enterprise Security Organizations”, 2005http://www.asisonline.org/newsroom/alliance.pdf, Web retrieve on December 22, 2009

@le_rond

Page 3: Conversion
Page 4: Conversion

Protection measures

@le_rond

Page 5: Conversion

@le_rond

Page 6: Conversion

@le_rond

Page 7: Conversion

@le_rond

Page 8: Conversion

@le_rond

Page 9: Conversion

@le_rond

Page 10: Conversion

@le_rond

Page 11: Conversion
Page 12: Conversion

Risk reduction

Cost savings

Disaster Recovery efficiency

@le_rond

Benefits of Convergence

Page 13: Conversion

Security Incidents

@le_rondUS-CERT, "Cyber Security Trends, Metrics, and Security Indicators", June 16, 2009. Volume 4, Issue 1.http://www.us- cert.gov/press_room/trendsanalysisQ109.pdf, Web retrieve on December 22, 2009

Page 14: Conversion

Liu, Simon and Cheng, Bruce; "Cyberattacks: Why, What, Who, and How", IT Pro, IEEE Computer Society, May/June 2009

Attack tool trends

@le_rond

Attack sophistication

Skillsrequired

Page 15: Conversion

@le_rond

Page 16: Conversion

@le_rond

Page 17: Conversion

@le_rond

Page 18: Conversion

Background

Salary

Training

Culture

Challenges of Convergence

@le_rond

Page 19: Conversion

@le_rond

Page 20: Conversion

@le_rond

Page 21: Conversion

@le_rond

Page 22: Conversion

@le_rond

Page 23: Conversion

Benefits ChallengesCost savings CultureMore holistic view of risk Salary differencesReduction of risk profile Training requirementsStreamline process Lack of collaboration

Summary of Benefits and Challenges of Convergence

@le_rondAlliance for Enterprise Security Risk Management “Convergence of Enterprise Security Organizations”, 2005http://www.asisonline.org/newsroom/alliance.pdf, Web retrieve on December 22, 2009

Page 24: Conversion

Merge physical and information security

Separate with reporting to one CSO

Keep the functions completely separate

Beginning a Convergence Program: Organizational Structure

@le_rond

Page 25: Conversion
Page 26: Conversion

Benefits of Convergence

Challenges of Convergences

Beginning of Converged Program

Summary

@le_rond

Page 27: Conversion

Thank you!

@le_rond