may 7, 2019 innovative... · 2019-05-08 · alm's law journal newsletters. panelists: david...

13
May 7, 2019 5/7 1 Copyright 2019. Innovative Computing Systems, Inc.

Upload: others

Post on 18-May-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: May 7, 2019 Innovative... · 2019-05-08 · ALM's Law Journal Newsletters. Panelists: David Lam, CISSP, CPP. Vice President, Technology Management Services Citadel Information Group

May 7, 2019

5/7 1 Copyright 2019. Innovative Computing Systems, Inc.

Page 2: May 7, 2019 Innovative... · 2019-05-08 · ALM's Law Journal Newsletters. Panelists: David Lam, CISSP, CPP. Vice President, Technology Management Services Citadel Information Group

Moderator:

Steve Salkin, Esq.Managing EditorALM's Law Journal Newsletters

Panelists:

David Lam, CISSP, CPPVice President, Technology Management ServicesCitadel Information Group

Howard MillerSenior Vice PresidentLBW Insurance & Financial Services, Inc.

Michael KempsChief Executive Officer and FounderInnovative Computing Systems, Inc.

Debra GrayExecutive DirectorFrandzel Robins Bloom & Csato, L.C.President, Greater Los Angeles ALA

5/7 2 Copyright 2019. Innovative Computing Systems, Inc.

Page 3: May 7, 2019 Innovative... · 2019-05-08 · ALM's Law Journal Newsletters. Panelists: David Lam, CISSP, CPP. Vice President, Technology Management Services Citadel Information Group

• Phishing/Web Attacks

• Hacking

• Third-Party Vendors

• Regulation

5/7 3 Copyright 2019. Innovative Computing Systems, Inc.

Page 4: May 7, 2019 Innovative... · 2019-05-08 · ALM's Law Journal Newsletters. Panelists: David Lam, CISSP, CPP. Vice President, Technology Management Services Citadel Information Group

Risk ManagementA process of protectingorganizational assets

© 2019 Howard A. Miller. All rights reserved.5/7 4 Copyright 2019. Innovative Computing Systems, Inc.

Page 5: May 7, 2019 Innovative... · 2019-05-08 · ALM's Law Journal Newsletters. Panelists: David Lam, CISSP, CPP. Vice President, Technology Management Services Citadel Information Group

Logical Classes

© 2019 Howard A. Miller. All rights reserved.5/7 5 Copyright 2019. Innovative Computing Systems, Inc.

Page 6: May 7, 2019 Innovative... · 2019-05-08 · ALM's Law Journal Newsletters. Panelists: David Lam, CISSP, CPP. Vice President, Technology Management Services Citadel Information Group

Cyber Insurance – A PrimerTwo Sides of Cyber Insurance

1st Party

This Photo by Unknown Author is licensed under CC BY

3rd Party

© 2017 Howard A. Miller. All rights reserved. 65/7 6 Copyright 2019. Innovative Computing Systems, Inc.

Page 7: May 7, 2019 Innovative... · 2019-05-08 · ALM's Law Journal Newsletters. Panelists: David Lam, CISSP, CPP. Vice President, Technology Management Services Citadel Information Group

• Information Security Management System

• Vendors should have their own information security management system in

place

• Vendors must patch

• Vendors should be doing third-party due diligence

• Vendors need to maintain expertise, especially considering the cloud

5/7 7 Copyright 2019. Innovative Computing Systems, Inc.

Page 8: May 7, 2019 Innovative... · 2019-05-08 · ALM's Law Journal Newsletters. Panelists: David Lam, CISSP, CPP. Vice President, Technology Management Services Citadel Information Group

• Logging and monitoring

• Training = Vigilant users

• Advanced tools (Fortinet, Mimecast, Microsoft, etc.)

5/7 8 Copyright 2019. Innovative Computing Systems, Inc.

Page 9: May 7, 2019 Innovative... · 2019-05-08 · ALM's Law Journal Newsletters. Panelists: David Lam, CISSP, CPP. Vice President, Technology Management Services Citadel Information Group

• Increase in Security Audits

• Documented Information Security Policies

• Documented Incident Response Plan

• Documented Business Continuity Plan

• Conduct Quarterly Vulnerability Scans of Your IT Network

5/7 9 Copyright 2019. Innovative Computing Systems, Inc.

Page 10: May 7, 2019 Innovative... · 2019-05-08 · ALM's Law Journal Newsletters. Panelists: David Lam, CISSP, CPP. Vice President, Technology Management Services Citadel Information Group

• Security Awareness Training and Phishing Defense Training

• Classification and Inventory Controls

oPersonal and Financial Information

oBusiness and other Information Requiring Non-Disclosure

o Sensitive Information

5/7 10 Copyright 2019. Innovative Computing Systems, Inc.

Page 11: May 7, 2019 Innovative... · 2019-05-08 · ALM's Law Journal Newsletters. Panelists: David Lam, CISSP, CPP. Vice President, Technology Management Services Citadel Information Group

• Substantial Employee Background Checks

oCredit Check

oCriminal/Civil Check

oDrug Screening

oBankruptcy Check

oAll Schools Verified

5/7 11 Copyright 2019. Innovative Computing Systems, Inc.