30
Understand & Manage IT Risk Prometheus Yang CISA, CRISC, CFE, ISO27001 LA 3-May-15

Understand and manage it risk

Embed Size (px)

Citation preview

Page 1: Understand and manage it risk

Understand & Manage

IT Risk

Prometheus Yang CISA, CRISC, CFE, ISO27001 LA

3-May-15

Page 2: Understand and manage it risk
Page 3: Understand and manage it risk

人們害怕的不是改變 而是怕自己沒有做好萬全準備

Page 4: Understand and manage it risk
Page 5: Understand and manage it risk

Source: “The evolving IT risk landscape: The why and how of IT Risk Management today,” Ernst & Young, June 2011

Page 6: Understand and manage it risk
Page 7: Understand and manage it risk

Source: “IT Risk Management Report 2,” Symantec, 2007

Page 8: Understand and manage it risk
Page 9: Understand and manage it risk

If you throw me in the snake pit, the first thing I want to know is which ones are poisonous.

Page 10: Understand and manage it risk

3rd Party / Outsourcing

Information Security

Change Management

Data Loss / Leakage / Breach

Malware / Virus

Fraud & Theft

Privacy and Data Protection

Terrorist Attack

Availability of Skills

Security / System Patch

Business Continuity

Legal / Compliance

Asset Management

Data Quality

Offshoring

Program / Project Management

Data Center Operation

Staffing

Risks can appear in different forms

Page 11: Understand and manage it risk

Regulator fine UK Bank over IT Issues

£ 56 Million

Page 12: Understand and manage it risk

Legacy system that cost Comair

$20 Million(USD)

Page 13: Understand and manage it risk

3,522 employees of Morgan Stanley were

saved by effective BCP during 911

Page 14: Understand and manage it risk

AVOID SOCIAL

ENGINEERING

S C H E M E S

Page 15: Understand and manage it risk

Learn from

Wolf & seven young kids

Page 16: Understand and manage it risk

2013 Dark Seoul

THREE financial institutions THREE TV stations

48,700 computers are affected

Page 17: Understand and manage it risk

Loss of

110million

Customer Data

2013 Target

Page 18: Understand and manage it risk

Dark Hotel

Target on biz executives Attack via hotel Wi-Fi

Use backdoor software to collect data

Page 19: Understand and manage it risk

If you think compliance

expensive, try

NON -

COMPLIANCE

Page 20: Understand and manage it risk
Page 21: Understand and manage it risk
Page 22: Understand and manage it risk

趨吉 避凶

Risk Management

Page 23: Understand and manage it risk
Page 24: Understand and manage it risk

less

is

MORE

Page 25: Understand and manage it risk
Page 26: Understand and manage it risk

Together

Everyone

Achieves

More

Page 27: Understand and manage it risk
Page 28: Understand and manage it risk

COURAGEOUS

INTEGRITY

Page 29: Understand and manage it risk

Managing risks &

controls through

participation and

partnership

Page 30: Understand and manage it risk