340 likes | 354 Views
Learn about the voluntary frameworks that provide standards, guidelines, and best practices for managing cybersecurity-related risks. The NIST Cybersecurity Framework is a flexible approach that prioritizes the protection and resilience of critical infrastructure and other sectors important to the economy and national security.
E N D
Frameworks, Standards, Guidelines, and Best Practices Dan Wagner, B.S., CISSP, CRISC, CISA, VCE-CIA Compliance Auditor, Cyber SecurityWECC Reliability & Security Workshop San Diego, CA – October 23–24, 2018 Western Electricity Coordinating Council
What frameworks teach us Western Electricity Coordinating Council
Early Stages Western Electricity Coordinating Council
Each of the above voluntary Frameworks present standards, guidelines, and best practices for managing cybersecurity-related risks. The NIST Cybersecurity Framework’s prioritized and flexible approach promotes the protection and resilience of critical infrastructure and other sectors important to the economy and national security. NIST, DRII, BCI, CSA, ISO, COBIT,VRMMM, SCRM, DAMA, ITIL, SDLC Western Electricity Coordinating Council
Constantly learning? Western Electricity Coordinating Council
Each of the above voluntary Frameworks integrate standards, guidelines, maturity models and best practices for managing cybersecurity-related risks. The NIST Cybersecurity Framework’s prioritized and flexible approach promotes the protection and resilience of critical infrastructure and other sectors important to the economy and national security. NIST, DRII, BCI, CSA, ISO, COBIT,VRMMM, SCRM, DAMA, ITIL, SDLC Western Electricity Coordinating Council
Disaster Recovery Institute International (DRII) • https://drii.org/ • The Business Continuity Institute (BCI) • https://www.thebci.org/ • The DAMA Guide to the Data Management Body of Knowledge (DAMA-DMBOK) • https://dama.org/content/body-knowledge • VENDOR RISK MANAGEMENT MATURITY MODEL (VRMMM) • https://sharedassessments.org/vrmmm/ • Supply-Chain Risk Management (SCRM) • http://www.scrlc.com/ Frameworks, Standards, Guidelines, and Best Practice - Examples Western Electricity Coordinating Council
Frameworks, Standards, Guidelines, and Best Practice - Examples • Framework for Improving Critical Infrastructure Cybersecurity and related news, information: • www.nist.gov/cyberframework • Additional cybersecurity resources: http://csrc.nist.gov/ • Questions, comments, ideas: cyberframework@nist.gov • COBIT (Control Objectives for Information and Related Technologies) • http://www.isaca.org/Knowledge-Center/COBIT/Pages/Overview.aspx • Capability Maturity Model Integration (CMMI) • https://cmmiinstitute.com/ Western Electricity Coordinating Council
The DAMA Guide to the Data Management Body of Knowledge (DAMA-DMBOK)
Professional Advice CannotPredict
What is significant to your role Western Electricity Coordinating Council
Questions? Dan Wagner B.S., CISSP, CRISC, CISA, VCE-CIA Compliance Auditor, Cyber Security Audits Western Electricity Coordinating Council 155 N 400 West Suite 200, Salt Lake City, UT 84103 dwagner@wecc.biz Western Electricity Coordinating Council