Successful Mentoring Relationships for Career Development (166234967)

18
7/29/2019 Successful Mentoring Relationships for Career Development (166234967) http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 1/18 Information Security Mentoring Brian Basgen, Pima Community College  Assistant Vice Chancellor for IT David Seidl, University of Notre Dame Director, Information Security Theresa Semmens, North Dakota State University Chief Information Technology Security Officer EDUCAUSE SPC, April 16, 2013

Transcript of Successful Mentoring Relationships for Career Development (166234967)

Page 1: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 1/18

Information SecurityMentoring

Brian Basgen, Pima Community College

 Assistant Vice Chancellor for IT

David Seidl, University of Notre Dame

Director, Information Security

Theresa Semmens, North Dakota State University

Chief Information Technology Security Officer 

EDUCAUSE SPC, April 16, 2013

Page 2: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 2/18

• I am currently a mentor • I am currently being mentored

• I am seeking a mentor 

• I would like to mentor someone

Poll: 

Are you a mentor, being mentored,or searching for a mentor?

Page 3: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 3/18

 

Who do you want to be in 3 years?

Who do you want to be in 5 years?

Page 4: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 4/18

As a mentee, what do you expect

from a mentor?

How do you see yourself as a

mentor?

Educause provides information about mentoring at:

http://www.educause.edu/careers/special-topic-programs/mentoring/about-

mentoring/phases-relationships

Page 5: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 5/18

Challenge: Most ISO level security mentors aren't local,

particularly if you want one in higher education.

Challenge: Technical security mentoring sometimes exists,but how do you find new knowledge?

Challenge: How do you find advice and knowledge for 

issues that are not security based but related to your position?

Security Mentoring Challenges

Page 6: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 6/18

Security Mentoring Questions

Question: How do we build relationships for ISOs?

Question: How do we build trust and comfort?

Question: What makes a long distance mentoring

relationship work?

Question: What do we need to do when the mentoringrelationship has run its course and we want to continue

to move forward?

Page 7: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 7/18

1. Why did I take this job? Someone remind me! (How on earth do you all

sleep at night?)

2. Do I have appropriate management support and understanding?

3. Do I understand what the major risks to the institution are? What is the

most valuable data at the institution? Where is it, how is it controlled?

4. What are the institution’s policies that affect information security? Do the

policies I need to do my job effective exist? Are they honored?

5. Who owns the data? Is it classified? Is this defined in a policy?

6. Does my management have the same list in their heads?7. What does my management expect me to provide?

8. Do I have the skills, staff, technology, policy and procedures to meet those

expectations?

9. What technologies do I have deployed? Is it deployed in an effective

manner?

10 Things an ISO Needs to Ask

Themselves

Page 8: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 8/18

• Guidance and advice on how to mentor • I need help finding a mentor 

• FAQs and other documentation

• Ideas on topics•  An understanding person who listens

Poll:

What mentoring resources do youneed?

Page 9: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 9/18

When you can't find a mentor who does what

you do, who else can help?

Discussion Topic 2: Alternative Mentors

Page 10: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 10/18

•Development as an ISO

• Professional skills

• Career progression

•Something else?

Poll:

What type of mentoring do youneed?

Page 11: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 11/18

1. I've been given a project to implement and manage - how do I do that?

2. I need to update or develop new policy and procedure, who do I

involve?

3. My users are constantly being phished. How can I better educate

students, faculty, and staff?

4. I’m a new ISO and I just had a breach...what do I do next? 

5. Who can I call for forensic help?

6. Who do I engage on short notice to provide forensic help?

7. When do I call law enforcement?

8. What companies specialize in breach notification or post-breach

support?

9. I want to provide identity theft prevention, what’s the best way to do

that?

The Bad Day List: 

Do you know these?

Page 12: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 12/18

What makes a good mentor?

How do you know?

Who should you mentor?

What happens when you don't "click?"

What's in it for me?

Discussion Topic 3: 

Being a Mentor 

Page 13: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 13/18

Mentoring often follows a path:

New to the

career 

Seeking a

mentor Mentoring

new staff 

Seeking a

mentor 

Changing

careers

Page 14: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 14/18

1. Leadership

2. Governance groups

3. Counsel, Police, Audit

4. Data stewards

5. Risk, Compliance, Insurance

6. Privacy, Policy

7. Student Affairs

8. Academic Affairs

9. CFO, chief business officer 

10.IRB

10 People (or Roles) an ISO needs

to know

Page 15: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 15/18

1. What are your information security policies? Are they effective? Have you

tested them?

2. What incidents have occurred in the past year? The past five?

3. Do you have an Incident Response plan; does it work? Who is notified

first?

4. Are there risk management and disaster recovery plans in place? Have

they been tested?

5. What is your role in the above three items?

6. Do you have a current and evolving security awareness program?

7. What does management expect from you?8. What does your staff expect?

9. What mailing lists and professional groups should I be a member of?

10.How do you communicate and provide information effectively to leadership

and the campus community?

10 Things an ISO needs to know

Page 16: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 16/18

1. Don’t Panic 

2. Publicly or privately make the claim that the institution is secure

3.  Assume that there is some place on the internal network that is “secure” 

4. Make a service so inaccessible that it becomes insecure due to

workarounds

5. Consider any process, training, or device a silver bullet

6. Consider technology in isolation as a solution to security risk

7. Fight fires (okay, almost never)

8. Develop punitive measures for IT staff who make mistakes in securing

their systems

9. Compromise ethics for expedience, or at the direction of your management

10.Make decisions in isolation

10 things an ISO should not do

Page 17: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 17/18

 

Open response:

Suggestions and comments

for the Educause ISO/CISO

mentoring program

Page 18: Successful Mentoring Relationships for Career Development (166234967)

7/29/2019 Successful Mentoring Relationships for Career Development (166234967)

http://slidepdf.com/reader/full/successful-mentoring-relationships-for-career-development-166234967 18/18

Thank you!

Information Security

Mentoring