32
Matt Loeb ISACA CEO September 17, 2016 37WCARS

37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

MattLoebISACACEO

September17,201637WCARS

Page 2: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

Agenda

� ADisruptiveandChangingWorld� ImpactonAuditors� ImplicationsfortheFutureWorkforce

Page 3: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

ADisruptedWorld

� Digitaldisruptionisalreadyhere� World’sbiggesttaxiservice…hasnotaxis(Uber)� Popular‘banks’…don’thavevaults(Venmo,M-Pesa)� Mostpopular‘hotelservice’…doesn’townahotel(AirBnB)

� Transitioningfrom‘valuechain’businessmodelstodigital‘ecosystems’

Source:PeterWeillandStephanieWoerner:ThrivinginanIncreasinglyDigitalEcosystem;MITSloanManagementReview,Summer2015

Page 4: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

BusinessModelsfortheDigitalEconomy

Source:PeterWeillandStephanieWoerner:ThrivinginanIncreasinglyDigitalEcosystem;MITSloanManagementReview,Summer2015

Page 5: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

Towards21,000,000,000+Devices

� Gartnerpredictsthatby2020,20.8billiondeviceswillbeinuseworldwide.Thisincludes:• Connectedvehicles

• IndustrialandconsumerIoT

• Mobiledevices

• Operationaltechnology(e.g.biomedicalandindustrialcontrolsystems)

Source:www.gartner.com/newsroom/id/3165317

Page 6: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

IncreasingTechComplexity� Inadditiontothenumberofdevices,technologycomplexityisalsoincreasingwithintheinfrastructure

� Containers� Virtualization� Externalization(cloud)� Softwaredefinedinfrastructure

Source:Ruxit

Page 7: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s
Page 8: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

ImpactonPractitioners� Relativetobusinessandtechnologypeers,auditorsneedtodomore toevaluaterisk…andtheyhavelesstime todoitin.

� Tworeasonsaredrivingtheseconstraints:• Differentialinriskvs.usagedecisionmaking

• Adoptiondynamics

Source:F.Schettini;KeyLessonsfromtheITAuditDirectorForums;June14,2016

Page 9: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

DifferentialinRiskvs.UsageDecisionMaking

� Consideranautomobile…

Image:Source:commons.wikimedia.org/wiki/File:Citroen_concept_car_-_Flickr_-_Supermac1961.jpg

Answering“howdoIuseit?”:• Learnrulesoftheroad• Learntodrive• Understandvehiclemaintenancerequirements• Anythingelse?

Answering“isitsafe?”:• Learnrulesoftheroad• Learntodrive• Weather/trafficconditions• Seatbelts/safetyfeatures• Steeringanddrivecolumncondition• Route/stobetraveled• Tirecondition• Engineservicehistory• Roadmaintenance/condition

Source:F.Schettini;KeyLessonsfromtheITAuditDirectorForums;June14,2016

Page 10: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

AdoptionDynamics

� Askyourself:whendoestheauditorlearnaboutusage?� Insomecases,itmayonlybeafterusageisalreadyprevalent:

• ShadowIT

• Auditcycleplanning(typicallyannually)

• “Discoverygap”fornewapplicationsandusage

•Individualuse•Usedinisolation•Limitedusescenarios

“Solo”phase

•Usagebroadens•Smallteams•Usageintegratesintobroaderworkflow

Smallteamphase •Smallteamsjoinforces

asusagegrows•Usageintegratesbetweenteamsandotherapps

Integration

•Usagebecomesenterprise-wide•Partofnormativeoperations

Standardization

Source:F.Schettini;KeyLessonsfromtheITAuditDirectorForums;June14,2016

Page 11: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

TheImpact

• “…shorteneddeploymentlifecycle[s]willrequiremoreagileauditingtechniquessuchascontinuousauditingandauditautomation…Theprofessionmustbecometechnologicallyastute,notonlytounderstandit[technology]butalsothecapabilitytouseitinnovelmannerstosupporttheauditfunction aswellastheforesighttoproposenewtechnologyadvancementstosupporttheprofession.”

—ISACAFutureofITAuditReport

• Some“hardquestions”:� Isyourteam“technicallyastute”

enoughtofacewhat’scoming?

� Areyoustayingontopofthenewestadvancementsintechnology?

� Areyourauditingtechniquesagile,continuous,andautomated?

Source:F.Schettini;KeyLessonsfromtheITAuditDirectorForums;June14,2016

Page 12: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

TopTechnologyChallenges:YoYTrends

Source:Protiviti andISACAjointITauditsurvey,“AGlobalLookatITAuditBestPractices”

Page 13: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

TheRoadAhead

Source:F.Schettini;KeyLessonsfromtheITAuditDirectorForums;June14,2016

Page 14: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

DigitalSolutionsBringDigitalConcerns

� Increasedsystemscomplexityandrisk� GreaterBoard-levelinvolvementinIToperations,strategy,etc.� Fastercyclesofinnovation� RobustROIontechnologyinvestmentsexpected

� IncreasedandmoreprominentrolesforITRisk,Audit,andGovernance,aswellasCyberSecurity

Page 15: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

HolisticPerspective

• Rapidchangeisthenorm:organizationsmustevolvetheirpolicies,processes,people

• Agileandflexibleistheorderoftheday

• Technologyexpandingandmaturing• NewdevelopmentslikeIoT,mobile,cloud,changebusinessesandcanbenefitauditors

• What’syourplan toleveragethem?

• ChangesneedtobeassessedmorebroadlythanjustIT

• Doyouhaveaprocesstoidentifynewrisks?• Toupgradeagingtechnology?• Topreventsecurityandprivacybreakdowns?• Havingaplanmeansaddressingthesequestionsheadon.

Source:F.Schettini;KeyLessonsfromtheITAuditDirectorForums;June14,2016

Page 16: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

BestPractices:Actions� Keepbusinessinformedaboutemergingriskandperspectivesinstrategy

� Auditmustalwaysaskandanswer:Arewemakingprogress?Arewedoingwhatweneedtodotogetwherewewanttogo?

� Answeringmeansbothan“elevatorpitch”andsystemicmetrics

� CommunicatewithmanagementandtheauditcommitteeregularlytoemphasizetheimportanceofconductinganITriskassessment

� ConsiderlinkingyourITauditriskassessmentwiththeERMcatalogtoshowtheintegrationbetweenthetwo

� EnsurethatITandcybersecurityrisksareunderstoodandmonitoredasstrategic-levelrisks,whenwarranted,andasamatterfortheboardofdirectorsandauditcommitteetomonitorregularly

Source:F.Schettini;KeyLessonsfromtheITAuditDirectorForums;June14,2016

Page 17: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

BigData,Analytics,andVisualization:PotentialImpacttoITAudit� OrganizationalimpactIftheorganizationisusingbigdatatodrivedecisionmaking,ITAuditshouldaudithowbigdataismanaged.

� DataintegrityIftheorganizationreliesheavilyonbigdata,ITAuditshouldauditdataintegrity.

� ITauditexecutionITAuditcanusebigdatatoperforminternalauditsinnewways.

� VisualizationNewwaysoflookingatdatacanopenupopportunitiesforauditors

Source:F.Schettini;KeyLessonsfromtheITAuditDirectorForums;June14,2016

Page 18: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

BigData,Analytics,andVisualization:ActionItems� “Checkingthebox”isnotDataAnalytics

� Theorganizationmusthaveastrategytomanagethedatalifecycle– creation,integrity,normalization,destruction,etc.

� It’saprocess,notaproject� Don’tstopexpandingthescopeofdataanalytics.Startsmallandbuild.

� Visualization=opportunity� Investigatefreeorlow-costdatavisualizationtoolstofindvalue,proveworth.

Source:F.Schettini;KeyLessonsfromtheITAuditDirectorForums;June14,2016

Page 19: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

CloudandShadowIT:KeyCloudRisks

Source:F.Schettini;KeyLessonsfromtheITAuditDirectorForums;June14,2016

Page 20: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

CloudandShadowIT:MainConcerns

� ShadowIT� CloudServiceProviderOperations� PoorDueDiligenceandDecisionMaking� PoorVendorManagement� MultipleJurisdictions=MultipleRegulations� PoorGovernanceoverCloud� LegacyApplicationsarenotCloudReady� ROIErodesbyUnexpectedExpenses

Source:F.Schettini;KeyLessonsfromtheITAuditDirectorForums;June14,2016

Page 21: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

AuditingCyberSecurity:WhyCyberSecurityMatterstoAudit� Securityhasbecomeaboardandexecutivelevelissue.

� Mustensuretheenterprise’scybersecurityprogramisdefensibleincourt.

� ITandITSecurityhavetechnicalexperience,butauditunderstandsthatallriskisbusinessrisk.

� Thereisalotofinformationoncybersecurity.Butthereisnotanequivalentamountofinformationonhowauditshouldaddresseffortstodealwithcybersecurityrisk.

� Withinthenextfewyears,externalauditingfirmsmaycountcybersecuritycontrolsas“inscope”aspartoffinancialaudits.

� Theproblemisnotalackofexpertise;itisalackofdialogue.

Source:F.Schettini;KeyLessonsfromtheITAuditDirectorForums;June14,2016

Page 22: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

AuditingCyberSecurity:ActionItems� Ensurecybersecurityriskisintegratedformallyintotheauditplan.

� Leverageapplicablenationalcybersecurityframeworks(suchasNISTintheU.S.)toincreasedefensibilityandefficiency.

� Identifyandactonopportunitiestoimprovetheorganization’sabilitytoidentify,assess,andmitigatecybersecurityrisktoacceptablelevels.

� Recognizethatcybersecurityriskisnotonlyexternal;assessandmitigatepotentialthreatsthatcouldresultfromtheactionsofanemployeeorbusinesspartner.

Source:F.Schettini;KeyLessonsfromtheITAuditDirectorForums;June14,2016

Page 23: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s
Page 24: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

TalentAcquisitionandRetention:InternalAuditIncreasingExpectations

Source:PwC’s18thAnnualGlobalCEOSurvey(2015)

Page 25: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

TalentAcquisitionandRetention:InternalAuditIncreasingExpectations

Source:PwC’s18thAnnualGlobalCEOSurvey(2015)

Page 26: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

TalentAcquisitionandRetention:Modern-DayChallengesinRecruiting� Riseofthecontingentworkforce,growthoffreelanceeconomyAsmorepeopleseekflexibleworkopportunities,theyareturningtopart-timepositionsandfreelancework.

� TechnologicaladvancementsPeoplewanttowork,accessandshareinformationthewaytheylive—constantlyconnectedwithanybody,anytime,andanywhere.

� Multi-generationalworkforceFourgenerationscomprisetoday’sworkforce;eachonebringsuniqueperspectives,attitudesandcommunicationandworkingstyles.

Source:PwC’s18th AnnualGlobalCEOSurvey(2015)

Page 27: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

TalentAcquisitionandRetention:ActionItems� Usethemostmoderntechniques.

Ifanorganizationisusingoutdatedtechniques,andnotbecomingautomated,itwilllosemillennialsanddigitalnativesquickly.

� Buildanexperiencethatmatchesthetypeoftalentyouaretryingtoattract.

� Speaktheirlanguage.

� Sellwhatthebusinesshasratherthanonlythejobitself.

� Givethemmorethanjust“gruntwork”;focusonwhatmotivatesthem.

� Givethemexperiencesoutsideoftheoffice.

� Giveunexpected,surpriserecognition

� Offerflexibleworkarrangements

Source:F.Schettini;KeyLessonsfromtheITAuditDirectorForums;June14,2016

Page 28: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

FutureofWork� Thecoming“newnormal”:

• “On-demand”economyaschiefdriverofglobaleconomy

• “Mobile-first”workforcesutilizingSMACtechnologiestomaximizetheirorganizations’effortsasdigitalleaderswillbestandard,acrossallindustries,atalllevels

• Robustandcontinualupskillingandreskilling,withlearningdeliveredfromformal,informalsources

Source:2016,Volume2,McKinseyQuarterly:DigitalStrategy:TheEconomicsofDisruption;LearningattheSpeedofBusiness

Page 29: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

DigitalNatives:TheDriversofTomorrow’sDigitalEcosystemsAreAlreadyArriving� Digitalcompaniesthrivingasdriversofdigitalecosystemsarealready hiringdigitalnativesandcreatingdigitalworkplaces

� Fordigitalnatives:� Theworldison-demand,flexible,andborderless� Personal/organizationalinterfacesareexpectedtobedigital—liketherestoftheirworld

Source:2016EMC2 WhitePaper:CompetingforDigitalCustomers:WhyCompaniesMustEmbraceDigitalTransformationNow

Page 30: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

FutureofLearning� Corporatelearningexpectedtochangedramaticallyinfuture� Increasingpresenceofdigitalnativesintheworkforcewillbeaprimarydriverofthesechanges

� TheNewNormal:Contentinthecloud,accessedbymobiledevicesemployingmultiplelearningenvironments,andoftengenerated,sharedandcuratedbytheusercommunityitself

Source:2016,Volume2,McKinseyQuarterly:DigitalStrategy:TheEconomicsofDisruption;LearningattheSpeedofBusiness

Page 31: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s

NextGen LearningEnvironments:LearningattheSpeedofBusiness

Source:2016,Volume2,McKinseyQuarterly:DigitalStrategy:TheEconomicsofDisruption;LearningattheSpeedofBusiness

Page 32: 37WCARS-K 2 M Loeb - RAWraw.rutgers.edu/docs/wcars/37wcars/Presentations/...Security Matters to Audit Security has become a board and executive level issue. Must ensure the enterprise’s