This is my presentation on how to build an as secure as can be IT % IT security department - the "difficulty level" is novice so if you're already an expert, this probably will not help you much. I presented this at the 2013 Cyber Security summit in Prague
1 of 30
More Related Content
Css 2013 claushoumann Building comprehensively for IT Security
1. Building for IT security
Or what you can do with an unlimited
budget
Claus Cramon Houmann
Banque hman 2013-05-17
2. 2
hman
Preface
This is meant to provoke
Including everything is impossible
No vendor-specific products will be mentioned
Banque hman 2013-05-17
16. 16
hman
Governance/policies and controls
Information Security policy
Privacy policy
Outsourcing policy
Vendor & Audit management policy
Data breach policy
Security Incident response & Management policy
Incident Management policy
Problem Management policy
Access control policy
Logical access control policy
Change Management policy
Release Management policy
Acceptable use of Internet policy (and similar)
IT security guidelines and instructions
Project Management policy
Banque hman 2013-05-17
17. 17
hman
Governance/policies and controls
Controls (examples of the most critical manual or automated
controls):
User Access Controls on critical data
Identity Management
Privileged Account Management
Control & Audit Superuser Access
User Activity Monitoring
Monitor User Activities & System Access
Banque hman 2013-05-17
30. 30
hman
About me
Claus Cramon Houmann, 37, married to Tina and I have 3
lovely kids
You can contact me anytime:
Skype: Claushj0707
Twitter: @claushoumann or @improveitlux
Banque hman 2013-05-17