digital self defense iia isaca it audit seminar

43
Rochester IIA & ISACA IT Audit Seminar December 10, 2015 Ben Woelk, CISSP ISO Program Manager Rochester Institute of Technology

Upload: ben-woelk-cissp

Post on 18-Feb-2017

412 views

Category:

Technology


3 download

TRANSCRIPT

Page 1: Digital self defense iia isaca it audit seminar

Rochester IIA & ISACA IT Audit SeminarDecember 10, 2015Ben Woelk, CISSP

ISO Program ManagerRochester Institute of Technology

Page 2: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Presentation Overview• Background• Communications Plan Basics• RIT Implementation• Success?• Discussion

Page 3: Digital self defense iia isaca it audit seminar

Copyright © 2014 Rochester Institute of Technology

BACKGROUND

Page 4: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

My Background• Corporate• Higher Education

– ISO Office– Adjunct

• Techcomm• Computing Security

Page 5: Digital self defense iia isaca it audit seminar

Copyright © 2014 Rochester Institute of Technology

Rochester Institute of Technology

• RIT Environment– 18,500 students– 3,500 faculty and

staff– International

Locations– ~40,000+ systems on

the network at any given time

– Very skilled IT security students

Page 6: Digital self defense iia isaca it audit seminar

Copyright © 2014 Rochester Institute of Technology

RIT Information Security • RIT ISO

– 3 full time• Information Security

Officer• Program Manager• Sr. Forensics Investigator

– 1-4 student employees• Mix of coop and part-time

• Risk Management, not Information Technology

Page 7: Digital self defense iia isaca it audit seminar

Copyright © 2014 Rochester Institute of Technology

COMMUNICATIONS PLAN BASICS

Page 8: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Communications Plan• Benefits

– Systematic approach– Repeatable– Set and achieve goals– Be proactive– Be strategy driven, not event driven– Strategic plan drives marketing/communications

plan

Page 9: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

TechComm 101• “We explain things” (R. J. Lippincott,

Intercom)• Characteristics

– Interactive and adaptable– Reader centered

• Personas– Contextualized– Concise– Visual– Cross cultural

Page 10: Digital self defense iia isaca it audit seminar

Copyright © 2014 Rochester Institute of Technology

RIT IMPLEMENTATION

Page 11: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Digital Self Defense Goals• Inform the entire population about threats.• Educate new members of the RIT community

on Information Security topics.• Maintain current information outputs and

engagement on Information Security topics.• Create new avenues for communication to

expand awareness of Information Security office.

• Inform community of new Infosec initiatives

Page 12: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Challenges• Multiple audiences• Messaging overload• 30% annual turnover• What, me worry?• Dry/technical subject

Page 13: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Security Awareness Plan• Components

– Audience analysis– Key messages– Communications channels– Calendar of promotions– Develop relationships

Page 14: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Target Audiences

Page 15: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Strategies• Consistent outreach• Creative/fun deliverables • New communication channels• “What’s in it for me?” fulfillment

– Emphasizing home use– Easy-to-implement best practices– Consequences of non-compliance– Interactive elements

Page 16: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Key Message• Short and Simple

Page 17: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Calendar of Promotions

Page 18: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Monthly TopicsMonth Topic

June, July, August Pre-Semester, Start of Semester

September New Students, New Semester, New Threats

October Cyber Security Awareness Month

November No Click November

December Scams and Hoaxes

January Data Privacy Month

February Ph(F)ebruary Phish

March Mobile Device Madness

April Spring Cleaning

May Graduating to Good Passwords

Page 19: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Pre-Semester/Start of Semester

Page 20: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Communications Channels• What’s the best vehicle?

Page 21: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Develop Relationships

Page 22: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

RIT Infosec Website

Page 23: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

RIT Social Media

Page 24: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Posters

Page 25: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Go Phish

https://www.pinterest.com/ritinfosec/playing-cards-by-rit-information-security/

Page 26: Digital self defense iia isaca it audit seminar

Copyright © 2014 Rochester Institute of Technology

Alerts and Advisories• Message Center

Portal/email• Ad hoc• ~20 per academic

year

Page 27: Digital self defense iia isaca it audit seminar

Copyright © 2014 Rochester Institute of Technology

Move-in

Page 28: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

New Student Orientation

Page 29: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Lightning Talks• Six minute presentations• Slides move every 18 seconds• Topics

– Online reputation management– Illegal file sharing– Safe use of social media– Securing mobile devices

Page 30: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

DSD Lightning Talk

• https://www.youtube.com/watch?v=-Yo8TV-ZLbE

Page 31: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

New vehicles this fall• Bus posters• Employee Benefits Fair• RIT Information Security

Field Guide to Identifying Phishing and Scams

Page 32: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

DSD 101 classes• Tips, Tricks, and Best Practices for staying

safe online– Monthly– Departmental presentations

Page 33: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

RIT Digital Self Defense Team• Launched 11/11/15

– Using internal survey tool to collect metrics and recruit team members

– 535 survey participants; 206 joined DSD Team

Page 34: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

In Development• Phishing exercises

Page 35: Digital self defense iia isaca it audit seminar

Copyright © 2014 Rochester Institute of Technology

SUCCESS?

Page 36: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Evaluation Tools• Internal survey tool

– Fall baseline (open now)– Spring progress

Page 37: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Social Media Evaluation

Page 38: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

External Evaluations• Use with care• Kred (2013)

– Influence (trust)– Outreach (propensity to share)

• Klout (2009)– Perceived social influence

Page 39: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Evaluate and Make Mid-Course Corrections

• You will make mistakes• Don’t be afraid to make a change• Did it make a difference?

• Ways to evaluate– Surveys– Analytics

From austinevan

Page 40: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Key Success Factors• What’s in it for them?• Relevant at home as well as at work• Reach them where they are

Page 41: Digital self defense iia isaca it audit seminar

Copyright © 2015 Rochester Institute of Technology

Resources• EDUCAUSE

– Cybersecurity Awareness Resource Library– Security Awareness Quick Start and Advanced

Guides• W. K. Kellogg Foundation

Template for Strategic Communications Plan• Richard Johnson-Sheehan Technical

Communication Today• Society for Technical Communication

Page 43: Digital self defense iia isaca it audit seminar

Copyright © 2014 Rochester Institute of Technology

DISCUSSION