Tim LaPorta - Cyberagility: Using Agile to Improve Cybersecurity Value Delivery

Loading video…

Your viewing record

No viewing recorded yet. Press play; your position is saved about every 10 seconds.

Completion

Completion unavailable: the video duration is not known yet.

Based on 0:00 of unique watched video. Repeats and skipped parts do not increase it.

In today’s world, Cybersecurity is at the forefront of world news.

Some of our clients experience 12 million plus hacking attempts per month.

Given the magnitude of risk to an organization, traditional waterfall delivery methods for Cybersecurity solutions will put an organization way behind the 8 ball when it comes to fending off attacks; there is no way that they will be able to respond to threats fast enough.

To respond to these threats faster, companies can incorporate agile practices into their Information Security practices with great success. We call this combination of Agile and Information Security CyberAgility. Building CyberAgility practices into the culture of an organization can help strengthen its defenses at a much faster pace than traditional methods.

CyberAgility reduces company risk by decreasing time to value for tools and methodologies that protect the organization.

This includes the ability for a company to pro-actively defend itself against cybersecurity threats (denial of service attacks, data breach prevention), provide operational support (system access requests), complete audit requests (have we documented what we do, and do we do what we documented), as well as quickly responding to real-time events as they occur.

In this session, we'll discuss examples of how CyberAgilty has helped in several areas of Information Security:

Data Loss Prevention:

We helped create a dedicated team that could build, test, and implement enterprise policies that scanned for potential data loss. The team was able to identify a subset of potential threats in 25% of the time that it would have taken using waterfall methodologies.

Operational monitoring and alerting:

We helped establish a dedicated team that could create, test and implement monitoring and alerts, and the team was able to implement monitoring and alerts in about 1/3 the time compared to the previous methodology. Tying back to value, this means that we reduced organizational risk 67% faster.

Controls Testing:

Most organizations have a set of controls that need to be tested on a regular basis. Typically, there is an operational team responsible for managing the controls lifecycle for the enterprise.

By helping this team create a Kanban model, which included visualizing all work and clearly documenting the process each control follows, we were able to gain enterprise transparency so that all impacted groups and stakeholders understood where their specific control was in the testing and certification process.

This effort also helped us identify non-value added steps and roadblocks that could then be reconfigured to help with the flow of the controls.

Comments

No comments yet. Be the first to comment.

Log in to join the discussion.