Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Security and digital: it's all about leadership

jystewart
October 31, 2017

Security and digital: it's all about leadership

Slides from my contribution to the digital leadership day at FWD50 2017 in Ottawa

jystewart

October 31, 2017
Tweet

More Decks by jystewart

Other Decks in Technology

Transcript

  1. @jystewart Can I put this data outside our borders? 


    What guarantees do we need to make about data?
  2. @jystewart It is unacceptable for a board to not understand

    financial risk. The same has to be true for cyber risk.
  3. @jystewart Data in transit protection - Data transiting networks should

    be protected against tampering and eavesdropping Asset protection and resilience - Data, and the assets that store/protect it, should be protected appropriately Separation between consumers - To prevent one compromised consumer from affecting the service of another Governance framework - To direct their overall approach to the management of the service and information Operational security - Processes and procedures need to be in place to ensure the operational security of the service Personnel security - Security service provider staff should be subject to personnel security screening Secure development - Services should be designed and developed to identify and mitigate threats to their security Supply chain security - The supply chain should support all of the security principles that the service Secure consumer management - Consumers should be provided with the tools required securely manage their service Identity and authentication - Access should be constrained to the authorised and authenticated users External interface protection - All external or less trusted interfaces of the service should have appropriate protections Secure service administration - All methods used by the service administrators should mitigate risk of exploitation Audit information provision to consumers -To help consumers monitor access to their service and their data Secure use of the service by the consumer - Consumers need to be trained and comply with guidance for use of cloud https://bit.ly/cloud-security-principles
  4. GDS

  5. @jystewart “If security doesn't work for people, it doesn't work”

    - Emma W from NCSC https://www.ncsc.gov.uk/blog-post/cyberuk-2017-people- strongest-link