60
ISACA Webcram CISA & CISM Sean Hanna

ISACA Ireland Webcram - Sean Hanna

Embed Size (px)

Citation preview

Page 1: ISACA Ireland Webcram - Sean Hanna

ISACA WebcramCISA & CISM

Sean Hanna

Page 2: ISACA Ireland Webcram - Sean Hanna

Sean HannaGRC & Cyber Warfare Consultant

EC-Council Global Security Trainer of the Year 2007, 2008, 2010 and again in 2011

EC Council Circle of Excellence Member 2012

LPT, ECSA, CEH, CHFI, NSAGCIH, GCIA, GSEC, CISSPCISM, CISA, CGEIT, PRINCE2

Page 3: ISACA Ireland Webcram - Sean Hanna

Let Start !

Page 4: ISACA Ireland Webcram - Sean Hanna

CISA & CISM

• These are NOT that different !• They are two sides of the one coin.

• CISM– Is the IS Department Manager– Implements & Manages IS/IT GRC

• CISA– Provides the Assurance function on IS/IT GRC– Understands and Measures

Page 5: ISACA Ireland Webcram - Sean Hanna

The EXAMs

• You need to understand that both exams require the SAME basic knowledge:– Governance– Risk– Compliance– COBIT– ITAF– Business Management Tools & Technique– Controls

Page 6: ISACA Ireland Webcram - Sean Hanna

The Difference

• Once you know the common basics…

• Then and only then…

• You can move on to the unique requirements of each exam!

Page 7: ISACA Ireland Webcram - Sean Hanna

Information Security Governance

Page 8: ISACA Ireland Webcram - Sean Hanna

Governance

• What is Governance?

• Where does it comes from?

• Who owns it?

Page 9: ISACA Ireland Webcram - Sean Hanna

Risk

• What is Risk?

• Where does it comes from?

• Who owns it?

Page 10: ISACA Ireland Webcram - Sean Hanna

Compliance

• What is Compliance?

• Where does it comes from?

• Who owns it?

Page 11: ISACA Ireland Webcram - Sean Hanna

Governance, Risk and Compliance

• GRC make up the responsibilities of the SMT

• It is the duty of SMT to understand GRC within their environment

Page 12: ISACA Ireland Webcram - Sean Hanna

Information Security GRC

• Is but one form of GRC

• No more important…

• No less important

• Considers the Data, Data Systems and Data Infrastructure

• And everything that might impact DS&I

Page 13: ISACA Ireland Webcram - Sean Hanna

SMT’s Role

• To ensure the success of the business by

– Understanding the business requirements

– Understanding the business goals

– Understanding the business risks

• Provide the strategy and direction• Provide the sponsorship and budget• Provide the oversight and control

Page 14: ISACA Ireland Webcram - Sean Hanna

SMT owns all GRC

Page 15: ISACA Ireland Webcram - Sean Hanna

SMT owns IS GRC

Page 16: ISACA Ireland Webcram - Sean Hanna

A MODEL FOR OWNERSHIP

Page 17: ISACA Ireland Webcram - Sean Hanna

How does SMT own GRC?

SMT

Page 18: ISACA Ireland Webcram - Sean Hanna

How does SMT own GRC?

SMT

Policy

Page 19: ISACA Ireland Webcram - Sean Hanna

How does SMT own GRC?

SMT

Policy

Page 20: ISACA Ireland Webcram - Sean Hanna

How does SMT own GRC?

SMT

Policy

Page 21: ISACA Ireland Webcram - Sean Hanna

How does SMT own GRC?

SMT

Policy

Standards

Page 22: ISACA Ireland Webcram - Sean Hanna

How does SMT own GRC?

SMT

Policy

Standards

Page 23: ISACA Ireland Webcram - Sean Hanna

How does SMT own GRC?

SMT

Policy

Standards

Page 24: ISACA Ireland Webcram - Sean Hanna

How does SMT own GRC?

SMT

Policy

Standards

Guidelines

Page 25: ISACA Ireland Webcram - Sean Hanna

How does SMT own GRC?

SMT

Policy

Standards

Guidelines

Page 26: ISACA Ireland Webcram - Sean Hanna

How does SMT own GRC?

SMT

Policy

Standards

Guidelines

Page 27: ISACA Ireland Webcram - Sean Hanna

How does SMT own GRC?

SMT

Policy

Standards

Guidelines

Procedures

Page 28: ISACA Ireland Webcram - Sean Hanna

How does SMT own GRC?

SMT

Policy

Standards

Guidelines

Procedures

Page 29: ISACA Ireland Webcram - Sean Hanna

How does SMT own GRC?

SMT

Policy

Standards

Guidelines

Procedures

Page 30: ISACA Ireland Webcram - Sean Hanna

HOW DO YOU WIN?

Page 31: ISACA Ireland Webcram - Sean Hanna

How do you win?

• To succeed you must know what success looks like

• To succeed you must measure success

• To succeed you must verify your measures

Page 32: ISACA Ireland Webcram - Sean Hanna

How does SMT manage RISK?

SMT

Page 33: ISACA Ireland Webcram - Sean Hanna

SMT

Controls

How does SMT manage RISK?

Page 34: ISACA Ireland Webcram - Sean Hanna

SMT

Controls

How does SMT manage RISK?

Page 35: ISACA Ireland Webcram - Sean Hanna

SMT

Controls

Audits

How does SMT manage RISK?

Page 36: ISACA Ireland Webcram - Sean Hanna

SMT

Controls

Audits

How does SMT manage RISK?

Page 37: ISACA Ireland Webcram - Sean Hanna

SMT

Controls

Audits

Dashboards

How does SMT manage RISK?

Page 38: ISACA Ireland Webcram - Sean Hanna

SMT

Controls

Audits

Dashboards

How does SMT manage RISK?

Page 39: ISACA Ireland Webcram - Sean Hanna

SMT

Controls

Audits

Dashboards

Assurance

How does SMT manage RISK?

Page 40: ISACA Ireland Webcram - Sean Hanna

SMT

Controls

Audits

Dashboards

Assurance

How does SMT manage RISK?

Page 41: ISACA Ireland Webcram - Sean Hanna

SMT BPR

Page 42: ISACA Ireland Webcram - Sean Hanna

Re-engineering how SMT functions

• COBIT provides many tools

• It suggests a simple but effective structure

Page 43: ISACA Ireland Webcram - Sean Hanna

Structure

SMT

IS Steering IS Committee

Programme Management

IT Department Functional Business Units

Audit Function

Page 44: ISACA Ireland Webcram - Sean Hanna

CISA

Audit

Page 45: ISACA Ireland Webcram - Sean Hanna

CISA

• CISA is all about audit:– General audit principles– Using a Governance model for business management– Managing project risk during development and acquisition– Managing operational risk during operation life cycle– Understand the vast array of controls

Page 46: ISACA Ireland Webcram - Sean Hanna

CISA

• Audit is all about assurance• Delivering a repeatable, trusted service• The Auditor must be:

– Independent– Trustworthy– Subject matter expert on processes

Page 47: ISACA Ireland Webcram - Sean Hanna

The CISA Answer Rules

• Evidence is the bases of all audit results

• Everything should be based on risk principles

• The Business always wins

• Every process needs to be verified

• CSA and GAS help with reducing workload

Page 48: ISACA Ireland Webcram - Sean Hanna

The CISA Specials

• You really need to know the tools of the trade– Sampling techniques– Measuring techniques– Reporting techniques

• Technical details on Controls do come up:– Software development methods– Software testing methods– Audit controls

Page 49: ISACA Ireland Webcram - Sean Hanna

CISM

Management

Page 50: ISACA Ireland Webcram - Sean Hanna

CISM

• CISM is all about Management:– Setting up and running a department– Using a Governance model for business management– Managing project risk during development and acquisition– Managing operational risk during operation life cycle– BCP, BIA and DRP– Understanding the vast array of controls

Page 51: ISACA Ireland Webcram - Sean Hanna

CISM

• Management is about translating business requirements into measureable results while managing risk in cost-effective way

• Delivering a repeatable, trusted service• The Manager must be:

– A Business leader– A subject matter expert– Under the whole business and its goals and objectives– Be able to influence and deliver results

Page 52: ISACA Ireland Webcram - Sean Hanna

The CISM Answer Rules

• Strategy is at the heart of a governance led business

• Everything should be based on risk principles

• The Business always wins

• Don’t do anything unless it can be measured

• Your success is all about the audit report

Page 53: ISACA Ireland Webcram - Sean Hanna

The CISM Specials

• You really need to know the tools of the trade– Measuring techniques– Reporting techniques

• Technical details on Controls do come up:– Virtually any Control can, and come up !

Page 54: ISACA Ireland Webcram - Sean Hanna

The Exam Day

Page 55: ISACA Ireland Webcram - Sean Hanna

The Exam Day

• Doors close at 08:30, make sure you’re in!• You must have government issued, photographic ID• Don’t take much in to the room with you• Wear a jacket/fleece, something you can off and hang on the back

of your seat• Drink plenty of water before the start• Make sure to take a restroom break

Page 56: ISACA Ireland Webcram - Sean Hanna

How to answer the questions

• Start at the start• Work your way through• Get to the end• Walk out !

• There’s no magic method that will help!

Page 57: ISACA Ireland Webcram - Sean Hanna

One step at a time

• Take each question as it comes• Don’t try to pick the right answer• Eliminate the 2 wrong answers first• Re-read the question and the 2 answers• Use the basics prinicpals to help you choose• Pick, move on and…• What ever you do, don’t think back!• Always move forward.

Page 58: ISACA Ireland Webcram - Sean Hanna

At the end of the exam

• You will be leaving early• Its not really a 4 hour exam• Be prepared to not know how you’ve done• Whatever you do, don’t check your answers!!

• When you’re finished, leave

Page 59: ISACA Ireland Webcram - Sean Hanna

How to pass

1.UNDERSTAND2.LEARN3.PRACTICE

Page 60: ISACA Ireland Webcram - Sean Hanna

Thank Youand good luck!