<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
>

<channel>
	<title>The Security Catalyst<title>&#187; SDLC</title>
</title>
	<atom:link href="http://www.securitycatalyst.com/tag/sdlc/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitycatalyst.com</link>
	<description>Michael Santarcangelo delivers Awareness that Works™</description>
	<lastBuildDate>Wed, 01 Sep 2010 14:21:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<!-- podcast_generator="Blubrry PowerPress/1.0.9" mode="advanced" entry="normal" -->
	<itunes:summary>Michael J. Santarcangelo, II is a human catalyst. An expert who speaks on information protection â including compliance, privacy and awareness â Michael energizes and inspires his audiences to change the way they protect information. His passion and approach gets results that change behaviors. 

As the voice of optimism in an industry of doomsayers, Michael has recently completed his first book, Into the Breach (www.intothebreach.com), which provides the wisdom and answers executives need to defend their organization against breaches while discovering how to increase revenue, protect the bottom line and efficiently manage people, information and risk.

In this podcast series, Michael shares ideas, research and strategies for your success. 
</itunes:summary>
	<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
	<itunes:explicit>clean</itunes:explicit>
	<itunes:image href="http://www.securitycatalyst.com/tsc_icon.png" />
	<itunes:owner>
		<itunes:name>Michael Santarcangelo | The Security Catalyst</itunes:name>
		<itunes:email>michael@securitycatalyst.com</itunes:email>
	</itunes:owner>
	<managingEditor>michael@securitycatalyst.com (Michael Santarcangelo | The Security Catalyst)</managingEditor>
	<copyright>Copyright 2009 The Security Catalyst. All Rights Reserved. </copyright>
	<itunes:subtitle>A catalyst for engaging, empowering and enabling individuals; turn insiders into allies who reduce business risk!</itunes:subtitle>
	<itunes:keywords>security, risk, privacy, compliance, breach, awareness, training, catalyst, confidentiality, integrity, availability, cissp, cism, cisa, cpp</itunes:keywords>
	<image>
		<title>The Security Catalyst&lt;title&gt;&#187; SDLC&lt;/title&gt;
</title>
		<url>http://www.securitycatalyst.com/wp-content/plugins/powerpress/rss_default.jpg</url>
		<link>http://www.securitycatalyst.com</link>
	</image>
	<itunes:category text="Business">
		<itunes:category text="Management &amp; Marketing" />
	</itunes:category>
	<itunes:category text="Technology" />
	<itunes:category text="Education" />
		<item>
		<title>Driving Compliance:  What We Have versus What We Need</title>
		<link>http://www.securitycatalyst.com/driving-compliance-what-we-have-versus-what-we-need/</link>
		<comments>http://www.securitycatalyst.com/driving-compliance-what-we-have-versus-what-we-need/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 14:06:53 +0000</pubDate>
		<dc:creator>Jim McFee</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[SDLC]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2703</guid>
		<description><![CDATA[By Jim McFee A common statement an auditor hears is, “our IT department is mature; we have everything we need for an IT Audit.” A common thought an auditor thinks is, “yeah, right.” So which of these statements is more accurate? More importantly, which one increases or decreases risk? Without creating a laundry list, let’s [...]


Related posts:<ol><li><a href='http://www.securitycatalyst.com/getting-behind-the-wheel-driving-audit-and-compliance/' rel='bookmark' title='Permanent Link: Getting Behind the Wheel: Driving Audit and Compliance'>Getting Behind the Wheel: Driving Audit and Compliance</a></li>
<li><a href='http://www.securitycatalyst.com/amplifying-the-good-the-security-catalyst-online-experience-2010/' rel='bookmark' title='Permanent Link: Amplifying the Good: The Security Catalyst Online Experience 2010'>Amplifying the Good: The Security Catalyst Online Experience 2010</a></li>
<li><a href='http://www.securitycatalyst.com/the-first-brick-understanding-identity-management/' rel='bookmark' title='Permanent Link: The First Brick: Understanding Identity Management'>The First Brick: Understanding Identity Management</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fdriving-compliance-what-we-have-versus-what-we-need%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fdriving-compliance-what-we-have-versus-what-we-need%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>By Jim McFee</strong></p>
<blockquote><p>A common statement an auditor hears is, “our IT department is mature; we have everything we need for an IT Audit.”</p>
<p>A common thought an auditor thinks is, “yeah, right.”</p></blockquote>
<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2010/01/gears.jpg"><img class="alignright size-medium wp-image-2705" title="gears" src="http://www.securitycatalyst.com/wp-content/uploads/2010/01/gears-300x200.jpg" alt="" width="300" height="200" /></a>So which of these statements is more accurate? More importantly, which one increases or decreases risk?</p>
<p>Without creating a laundry list, let’s take a look from the auditors’ perspective by breaking down the components of compliance into five main domains:</p>
<ul>
<li>Logical Access</li>
<li>Physical Access</li>
<li>Operations</li>
<li>Change Management</li>
<li>System Development</li>
</ul>
<p>In my last article, I introduced the concept of developing a “Culture of Compliance”  &#8212; something to keep in mind as we delve deeper into each section.</p>
<h3>Logical Access</h3>
<p>Logical access is the way people (employees, contractors, partners) gain access to the systems that process information. An auditor looks for clearly defined and followed processes.</p>
<p>In my experience, this is where IT needs to work with the whole organization on the core of logical access: user provisioning (my fellow contributor Ioana Bazavan Justus is authoring a great series on Identity Management).</p>
<p>Once defined, logical access must be certified with established tools or a manual effort. The ideal approach is a preventive control that flags segregation of duty access across application systems. Few organizations use this today, but I strongly urge the consideration and adoption of this capability. The more common approach is a “detective” control that works, but requires a significant budget and hours to complete. To be clear, “complete” means re-testing!</p>
<p>Access reviews need to include identification of administrative accounts (including who has access to these accounts) and validation if the level of access is actually <strong><em><span style="text-decoration: underline;">required</span></em></strong>. I recommend not taking anyone’s <em>word</em> for this, test and document it. It is important to have a documented methodology of monitoring administrative accounts and logs to prove it.</p>
<h3>Physical Access</h3>
<p>Physical access covers access to buildings, data centers and other sensitive areas. The appropriate policies and reviews need to cover the entire process for new hire, transfers, terminations, contractors, vendors, etc. To be effective, this often requires cooperation with Human Resources (HR), Legal, and Compliance and possibly some business units.</p>
<p>Think like an auditor: once access to the data center is documented, reviewed (quarterly) and signed, the auditor(s) will generally pick a terminated IT staff member to audit.</p>
<p>This is where the “culture of compliance” comes in – rather than hoping the process works, it pays to establish an environment where employees take the right actions as a course of action. In this case, it means they log all entry by contractors, vendors and other guests and validate this list against an electronic record of entrance.</p>
<p>A quick sign of success is when even escorted coworkers are asked to sign a log file for entrance into the Data Center.</p>
<h3>Operations</h3>
<p>Operations are the lifeblood of the organization.</p>
<p>Many organizations have a facilities department separate from IT, which requires cooperation between teams. This is also a reason to have a single person drive the compliance and audit process – to streamline these connections and provide a measure of continuity.</p>
<p>Make sure vendor contracts are in order for the facilities/physical equipment such as fire suppression, heating/cooling and other support systems. When the culture understands the importance of protecting this information, each department will notify others of changes and work together to ensure updates and “coverage.”</p>
<p>Good auditors look to assess if the team has a handle on inventory or manages by incomplete spreadsheets with a hope of accuracy. This is an area where the use of automated discovery tools pays dividends.</p>
<p>Much ground to be covered here, and it must include the details of who, what, where and when of Job Scheduling. Changes to job scheduling is  a process, whether it is for changing frequencies, adding, deleting, and even emergency procedures.</p>
<p>Another area of focus: ensure backup processes are documented, reviewed,  and followed.</p>
<p>Think like an auditor: provide logging details, be ready to explain the job failures and how they are handled! If an auditor asks about failures and the response is “we have none,” it triggers (or should) a lot more questions.</p>
<h3>Change Management</h3>
<p>In general the key to change management/development is authorizations.</p>
<p>This starts from the top with project approval forums all the way down to and including authorization to put code into production. Each phase, QA, testing, and CM should define requirements, necessary documentations and authorizations. Where appropriate several levels of approvals is required. <strong></strong></p>
<p>Change control is not limited to applications.</p>
<p>Include network configuration (port address) changes and changes to OS configurations need to follow  the change control process. Emergency changes often fall through the cracks of standard procedures. Establish a process that allows flexibility to get the task completed but make sure you have post documentation, and verbal approvals documented after the fact.</p>
<h3>System Development</h3>
<p>Time to really consider, implement and/or follow SDLC documentation (need a starting point, check out:  <a href="http://www.shellmethod.com/refs/SDLC.pdf">http://www.shellmethod.com/refs/SDLC.pdf</a>). Pay close attention to the two primary parties, the end user and developer parties and their responsibilities.</p>
<p>A simple question to start the process: does the current process, what people are actually doing, match what is documented?</p>
<p>In many cases – maybe even most – the answer is either no, or worse, “documentation, we don’t have documentation!” Larger, more mature organizations tend to have a dedicated quality assurance (QA) department that often engages in auditing or assessing the system development process.</p>
<p>In general, workflow applications are great but avoid the concept of “assumed authorizations”. The workflow better meet the documented levels of authorization.</p>
<p>Some people may sneer at the concept of “culture of compliance,” but their personal experiences don’t diminish the importance of engaging people in every aspect of the process – to the point where it is ingrained in the very culture of the organization. The reality is that compliance becomes a process, and the organizations that are focused on engaging their people are able to meet compliance goals without imposing (too many) additional burdens.</p>
<p>Quite simply, this <strong><em>is</em></strong> establishing, nurturing and supporting a culture of compliance.</p>
<p>By considering these five areas, it is possible to provide some structure and ask good, probing questions that lead to conversations that ultimately inform the decisions and actions of others. Change the way people think when developing and making system changes and 85% of your challenges will gradually melt away.</p>
<p>This is simple to test:</p>
<p>1 – Have a manager ask an SE to grant him admin rights, completed with a bit of a story. If the result is a change in access on the fly, there is an immediate opportunity to educate. In my experience, the education might be better as a discussion with questions, as opposed to scolding and “gotcha.” Connecting the person to the consequences of their actions – in their words – goes much further.</p>
<p>2- Ask the customer if they do post implementation testing. Does it meet the initial scope of the project? Are “lessons-learned” documented and kept on file.</p>
<p>3 – Ask the Data Center manager when the next scheduled fire suppressant equipment inspection is due. Not needed instantly but they should be able to produce a copy of the contract and last maintenance records.</p>
<p>What do you think?</p>
<p>Share your challenges, successes or questions about how to effectively drive your audit and compliance program in the comments below.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fdriving-compliance-what-we-have-versus-what-we-need%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fdriving-compliance-what-we-have-versus-what-we-need%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<div id="facebook_like"><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.securitycatalyst.com%2Fdriving-compliance-what-we-have-versus-what-we-need%2F&amp;layout=standard&amp;show_faces=true&amp;width=450&amp;action=like&amp;colorscheme=light&amp;height=80" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:450px; height:80px;" allowTransparency="true"></iframe></div>

<p>Related posts:<ol><li><a href='http://www.securitycatalyst.com/getting-behind-the-wheel-driving-audit-and-compliance/' rel='bookmark' title='Permanent Link: Getting Behind the Wheel: Driving Audit and Compliance'>Getting Behind the Wheel: Driving Audit and Compliance</a></li>
<li><a href='http://www.securitycatalyst.com/amplifying-the-good-the-security-catalyst-online-experience-2010/' rel='bookmark' title='Permanent Link: Amplifying the Good: The Security Catalyst Online Experience 2010'>Amplifying the Good: The Security Catalyst Online Experience 2010</a></li>
<li><a href='http://www.securitycatalyst.com/the-first-brick-understanding-identity-management/' rel='bookmark' title='Permanent Link: The First Brick: Understanding Identity Management'>The First Brick: Understanding Identity Management</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/driving-compliance-what-we-have-versus-what-we-need/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
