際際滷

際際滷Share a Scribd company logo
American Security and Privacy, LLC Incident Handler Certification
Dr. Kevin F. Streff
Founder and Managing Partner
1
Incident Handler
Certification
American Security and Privacy, LLC Incident Handler Certification
American Security and Privacy, LLC Incident Handler Certification
Dr. Kevin Streff
American Security and Privacy, LLC
 Founder & Managing Partner
 www.americansecurityandprivacy.com
 Kevin.Streff@americansecurityandprivacy.com
 605.270.4427
2
American Security and Privacy, LLC Incident Handler Certification
American Security and Privacy, LLC Incident Handler Certification
Agenda
3
Module 1 Incident Response Overview
Module 2 Incident Response Laws and Regulations
Module 3 The Fit of Incident Response in Information Security and Privacy Programs
Module 4 Privacy Incidents
Module 5 Security Incidents
Module 6 Incident Response Program Overview
Module 7 Step 1 - Preparation
Module 8 Step 2 - Detection and Analysis
Module 9 Step 3 - Contain, Eradicate, and Recover
Module 10 Step 4 - Post Incident Activity
Module 11 Incident Response Testing
Module 12 Third Party Incident Response Requirements
Module 13 Incident Response Auditing
Module 14 Incident Response Metrics
American Security and Privacy, LLC Incident Handler Certification
Module 3
THE ROLE OF INCIDENT MANAGEMENT IN
INFORMATION SECURITY AND PRIVACY PROGRAMS
4
American Security and Privacy, LLC Incident Handler Certification
American Security and Privacy, LLC Incident Handler Certification
Gramm-
Leach-Bliley
Act of 1999
 Required financial
institutions to
implement an
Information
Security Program
5
American Security and Privacy, LLC Incident Handler Certification
American Security and Privacy, LLC Incident Handler Certification
Leading Security Frameworks
1.NIST Security Framework
2.OASIS Security Framework
3.APEC Security Framework
4.Nymity Security Management Accountability
Framework
5.HITRUST Security Framework
6.American Security and Privacy Information
Security Framework
7.ISO 2700x Framework
6
American Security and Privacy, LLC Incident Handler Certification
Information Security Program Blueprint
Inventories
Policies
Procedures
Standards
Guidelines
Plans
Audit/Test Results
Reports
SARS
Meeting Minutes
Committee Approvals
Previous Exams
Awareness/Training
Materials
Third Party Reports
Network Diagram
Organizational Chart
Process Flows
Incident Reports
Strategies
Budgets
Memos
FI
Processes
Documentation
Asset
Mgmt.
Physical
Security
Business
Continuity
Incident
Response
Developme
nt &
Acquisition
Operations
Security
Risk Mgmt. Network
Security
Auditing
Functions
Personnel
Security
Reporting
Remediation
Assessment Changes
Audit Recommendations
Exam Findings
Incident Reports
Policy Changes
Board
Committee
Operations
Third Party
Examiner
FI and
Technology
Strategy
ASP ISP v1.1
IT Audit
Soc. Eng.
Pen Test
Scans
Third Party Mgmt.
Soft. Dev.
Customer
Employee
Third Parties
Systems Inventory
Technology
BIA
AUP
Roles & Resp.
BCP
Pandemic Preparedness
7
American Security and Privacy, LLC Incident Handler Certification
American Security and Privacy, LLC Incident Handler Certification
CFPB 1033
 Required financial
institutions to
implement an
Information Privacy
Program
 Supports the Open
Banking concept
 Requires for security
and privacy
8
American Security and Privacy, LLC Incident Handler Certification
American Security and Privacy, LLC Incident Handler Certification
Leading Privacy
Frameworks
1. NIST Privacy
Framework
2. American Security
and Privacy (ASP)
Information Privacy
Framework (IPP)
3. ISO Privacy
Framework (27701)
9
American Security and Privacy, LLC Incident Handler Certification
Data
Mgmt
Consent
Mgmt
Vendor
Mgmt
DSAR
Mgmt
Web
Tracing
& Cookie
Mgmt
Privacy
Program
Mgmt
Privacy
Engineering
Emergency
Mgmt.
Information Privacy Program Blueprint
Assessments
Compliance Reporting
Remediation
Inventories
Policies
Procedures
Standards
Guidelines
Plans
Audit/Test Results
Reports
SARS
Meeting Minutes
Committee
Approvals
Previous Exams
Awareness/
Training Materials
Vendor Reports
Network Diagram
Organizational
Chart
Process Flows
Incident Reports
Data Flows
Privacy Audit
Consent Mgmt Audit
Id Mgmt Audit
Cookie Tracking Audit
Website Tracking Audit
Data Masking Audit
Pseudonymity Audit
Privacy/PIA
Cookie Tracking
Website Tracking
Data Masking
Pseudonymity
Assessment Changes
Compliance
Recommendations
Exam Findings
Regulatory Changes
Legal Changes
Board
Committees
Operations
Vendor
Examiner
Strategies/
Budgets
Training Logs
Memos
DSARS
ROPAS
Data Mappings
Functions
Processes
Documentation
Privacy Notices
Awareness
& Training
Mgmt
ETC.
User
Mgmt
10
American Security and Privacy, LLC Incident Handler Certification
American Security and Privacy, LLC Incident Handler Certification
Summary
 Need both an Information Security
Program (ISP) and Information Privacy
Program (IPP) which include Incident
Management
11
American Security and Privacy, LLC Incident Handler Certification
American Security and Privacy, LLC Incident Handler Certification
Dr. Kevin Streff
American Security and Privacy, LLC
 Founder & Managing Partner
 www.americansecurityandprivacy.com
 Kevin.Streff@americansecurityandprivacy.com
 605.270.4427
12
American Security and Privacy, LLC

More Related Content

More from trevor501353 (20)

Certified Banking Data Privacy Law and Regulation - Module 8.pptx
Certified Banking Data Privacy Law and Regulation - Module 8.pptxCertified Banking Data Privacy Law and Regulation - Module 8.pptx
Certified Banking Data Privacy Law and Regulation - Module 8.pptx
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 7.pptx
Certified Banking Data Privacy Law and Regulation - Module 7.pptxCertified Banking Data Privacy Law and Regulation - Module 7.pptx
Certified Banking Data Privacy Law and Regulation - Module 7.pptx
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 6.pptx
Certified Banking Data Privacy Law and Regulation - Module 6.pptxCertified Banking Data Privacy Law and Regulation - Module 6.pptx
Certified Banking Data Privacy Law and Regulation - Module 6.pptx
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 5.pptx
Certified Banking Data Privacy Law and Regulation - Module 5.pptxCertified Banking Data Privacy Law and Regulation - Module 5.pptx
Certified Banking Data Privacy Law and Regulation - Module 5.pptx
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 4.pptx
Certified Banking Data Privacy Law and Regulation - Module 4.pptxCertified Banking Data Privacy Law and Regulation - Module 4.pptx
Certified Banking Data Privacy Law and Regulation - Module 4.pptx
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 3.pptx
Certified Banking Data Privacy Law and Regulation - Module 3.pptxCertified Banking Data Privacy Law and Regulation - Module 3.pptx
Certified Banking Data Privacy Law and Regulation - Module 3.pptx
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 2.pptx
Certified Banking Data Privacy Law and Regulation - Module 2.pptxCertified Banking Data Privacy Law and Regulation - Module 2.pptx
Certified Banking Data Privacy Law and Regulation - Module 2.pptx
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 1.pptx
Certified Banking Data Privacy Law and Regulation - Module 1.pptxCertified Banking Data Privacy Law and Regulation - Module 1.pptx
Certified Banking Data Privacy Law and Regulation - Module 1.pptx
trevor501353
Privacy Frontline - Level 1 - Module 3.pptx
Privacy Frontline - Level 1 - Module 3.pptxPrivacy Frontline - Level 1 - Module 3.pptx
Privacy Frontline - Level 1 - Module 3.pptx
trevor501353
Privacy Frontline - Level 1 - Module 2.pptx
Privacy Frontline - Level 1 - Module 2.pptxPrivacy Frontline - Level 1 - Module 2.pptx
Privacy Frontline - Level 1 - Module 2.pptx
trevor501353
Privacy Frontline - Level 1 - Module 1.pptx
Privacy Frontline - Level 1 - Module 1.pptxPrivacy Frontline - Level 1 - Module 1.pptx
Privacy Frontline - Level 1 - Module 1.pptx
trevor501353
Certified Banking Board Member - Module 2 Powerpoint Presentation
Certified Banking Board Member - Module 2 Powerpoint PresentationCertified Banking Board Member - Module 2 Powerpoint Presentation
Certified Banking Board Member - Module 2 Powerpoint Presentation
trevor501353
Certified Banking Board Member - Module 1 Powerpoint Presentation
Certified Banking Board Member - Module 1 Powerpoint PresentationCertified Banking Board Member - Module 1 Powerpoint Presentation
Certified Banking Board Member - Module 1 Powerpoint Presentation
trevor501353
Security Manager - 際際滷s - Module 13 Powerpoint Presentation
Security Manager - 際際滷s - Module 13 Powerpoint PresentationSecurity Manager - 際際滷s - Module 13 Powerpoint Presentation
Security Manager - 際際滷s - Module 13 Powerpoint Presentation
trevor501353
Security Manager - 際際滷s - Module 12 Powerpoint Presentation
Security Manager - 際際滷s - Module 12 Powerpoint PresentationSecurity Manager - 際際滷s - Module 12 Powerpoint Presentation
Security Manager - 際際滷s - Module 12 Powerpoint Presentation
trevor501353
Security Manager - 際際滷s - Module 11 Powerpoint Presentation
Security Manager - 際際滷s - Module 11 Powerpoint PresentationSecurity Manager - 際際滷s - Module 11 Powerpoint Presentation
Security Manager - 際際滷s - Module 11 Powerpoint Presentation
trevor501353
Security Manager - 際際滷s - Module 10 Powerpoint Presentation
Security Manager - 際際滷s - Module 10 Powerpoint PresentationSecurity Manager - 際際滷s - Module 10 Powerpoint Presentation
Security Manager - 際際滷s - Module 10 Powerpoint Presentation
trevor501353
Security Manager - 際際滷s - Module 9 Powerpoint Presentation
Security Manager - 際際滷s - Module 9 Powerpoint PresentationSecurity Manager - 際際滷s - Module 9 Powerpoint Presentation
Security Manager - 際際滷s - Module 9 Powerpoint Presentation
trevor501353
Security Manager - 際際滷s - Module 8 Powerpoint Presentation
Security Manager - 際際滷s - Module 8 Powerpoint PresentationSecurity Manager - 際際滷s - Module 8 Powerpoint Presentation
Security Manager - 際際滷s - Module 8 Powerpoint Presentation
trevor501353
Security Manager - 際際滷s - Module 7 Powerpoint Presentation
Security Manager - 際際滷s - Module 7 Powerpoint PresentationSecurity Manager - 際際滷s - Module 7 Powerpoint Presentation
Security Manager - 際際滷s - Module 7 Powerpoint Presentation
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 8.pptx
Certified Banking Data Privacy Law and Regulation - Module 8.pptxCertified Banking Data Privacy Law and Regulation - Module 8.pptx
Certified Banking Data Privacy Law and Regulation - Module 8.pptx
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 7.pptx
Certified Banking Data Privacy Law and Regulation - Module 7.pptxCertified Banking Data Privacy Law and Regulation - Module 7.pptx
Certified Banking Data Privacy Law and Regulation - Module 7.pptx
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 6.pptx
Certified Banking Data Privacy Law and Regulation - Module 6.pptxCertified Banking Data Privacy Law and Regulation - Module 6.pptx
Certified Banking Data Privacy Law and Regulation - Module 6.pptx
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 5.pptx
Certified Banking Data Privacy Law and Regulation - Module 5.pptxCertified Banking Data Privacy Law and Regulation - Module 5.pptx
Certified Banking Data Privacy Law and Regulation - Module 5.pptx
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 4.pptx
Certified Banking Data Privacy Law and Regulation - Module 4.pptxCertified Banking Data Privacy Law and Regulation - Module 4.pptx
Certified Banking Data Privacy Law and Regulation - Module 4.pptx
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 3.pptx
Certified Banking Data Privacy Law and Regulation - Module 3.pptxCertified Banking Data Privacy Law and Regulation - Module 3.pptx
Certified Banking Data Privacy Law and Regulation - Module 3.pptx
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 2.pptx
Certified Banking Data Privacy Law and Regulation - Module 2.pptxCertified Banking Data Privacy Law and Regulation - Module 2.pptx
Certified Banking Data Privacy Law and Regulation - Module 2.pptx
trevor501353
Certified Banking Data Privacy Law and Regulation - Module 1.pptx
Certified Banking Data Privacy Law and Regulation - Module 1.pptxCertified Banking Data Privacy Law and Regulation - Module 1.pptx
Certified Banking Data Privacy Law and Regulation - Module 1.pptx
trevor501353
Privacy Frontline - Level 1 - Module 3.pptx
Privacy Frontline - Level 1 - Module 3.pptxPrivacy Frontline - Level 1 - Module 3.pptx
Privacy Frontline - Level 1 - Module 3.pptx
trevor501353
Privacy Frontline - Level 1 - Module 2.pptx
Privacy Frontline - Level 1 - Module 2.pptxPrivacy Frontline - Level 1 - Module 2.pptx
Privacy Frontline - Level 1 - Module 2.pptx
trevor501353
Privacy Frontline - Level 1 - Module 1.pptx
Privacy Frontline - Level 1 - Module 1.pptxPrivacy Frontline - Level 1 - Module 1.pptx
Privacy Frontline - Level 1 - Module 1.pptx
trevor501353
Certified Banking Board Member - Module 2 Powerpoint Presentation
Certified Banking Board Member - Module 2 Powerpoint PresentationCertified Banking Board Member - Module 2 Powerpoint Presentation
Certified Banking Board Member - Module 2 Powerpoint Presentation
trevor501353
Certified Banking Board Member - Module 1 Powerpoint Presentation
Certified Banking Board Member - Module 1 Powerpoint PresentationCertified Banking Board Member - Module 1 Powerpoint Presentation
Certified Banking Board Member - Module 1 Powerpoint Presentation
trevor501353
Security Manager - 際際滷s - Module 13 Powerpoint Presentation
Security Manager - 際際滷s - Module 13 Powerpoint PresentationSecurity Manager - 際際滷s - Module 13 Powerpoint Presentation
Security Manager - 際際滷s - Module 13 Powerpoint Presentation
trevor501353
Security Manager - 際際滷s - Module 12 Powerpoint Presentation
Security Manager - 際際滷s - Module 12 Powerpoint PresentationSecurity Manager - 際際滷s - Module 12 Powerpoint Presentation
Security Manager - 際際滷s - Module 12 Powerpoint Presentation
trevor501353
Security Manager - 際際滷s - Module 11 Powerpoint Presentation
Security Manager - 際際滷s - Module 11 Powerpoint PresentationSecurity Manager - 際際滷s - Module 11 Powerpoint Presentation
Security Manager - 際際滷s - Module 11 Powerpoint Presentation
trevor501353
Security Manager - 際際滷s - Module 10 Powerpoint Presentation
Security Manager - 際際滷s - Module 10 Powerpoint PresentationSecurity Manager - 際際滷s - Module 10 Powerpoint Presentation
Security Manager - 際際滷s - Module 10 Powerpoint Presentation
trevor501353
Security Manager - 際際滷s - Module 9 Powerpoint Presentation
Security Manager - 際際滷s - Module 9 Powerpoint PresentationSecurity Manager - 際際滷s - Module 9 Powerpoint Presentation
Security Manager - 際際滷s - Module 9 Powerpoint Presentation
trevor501353
Security Manager - 際際滷s - Module 8 Powerpoint Presentation
Security Manager - 際際滷s - Module 8 Powerpoint PresentationSecurity Manager - 際際滷s - Module 8 Powerpoint Presentation
Security Manager - 際際滷s - Module 8 Powerpoint Presentation
trevor501353
Security Manager - 際際滷s - Module 7 Powerpoint Presentation
Security Manager - 際際滷s - Module 7 Powerpoint PresentationSecurity Manager - 際際滷s - Module 7 Powerpoint Presentation
Security Manager - 際際滷s - Module 7 Powerpoint Presentation
trevor501353

Recently uploaded (20)

Mastering Influence-Strategies for Effective Leadership Without Authority.pptx
Mastering Influence-Strategies for Effective Leadership Without Authority.pptxMastering Influence-Strategies for Effective Leadership Without Authority.pptx
Mastering Influence-Strategies for Effective Leadership Without Authority.pptx
Career Communications Group
Management Principles on Small Scale Industries.
Management Principles on Small Scale Industries.Management Principles on Small Scale Industries.
Management Principles on Small Scale Industries.
CryptoMaster7
(Sent) IFI_Phan Th畛c Anh_Corporate Social Responsibility Strategy.pptx
(Sent) IFI_Phan Th畛c Anh_Corporate Social Responsibility Strategy.pptx(Sent) IFI_Phan Th畛c Anh_Corporate Social Responsibility Strategy.pptx
(Sent) IFI_Phan Th畛c Anh_Corporate Social Responsibility Strategy.pptx
tanhphan5
COMMUNICATION SKILLS Dr Akshay Shetty.pptx
COMMUNICATION SKILLS Dr Akshay Shetty.pptxCOMMUNICATION SKILLS Dr Akshay Shetty.pptx
COMMUNICATION SKILLS Dr Akshay Shetty.pptx
Akshay Shetty
Planning in Management,NATURE,CHARTACTERISTICS,STEPS,TYPES,POLICY,PROCEDURES,...
Planning in Management,NATURE,CHARTACTERISTICS,STEPS,TYPES,POLICY,PROCEDURES,...Planning in Management,NATURE,CHARTACTERISTICS,STEPS,TYPES,POLICY,PROCEDURES,...
Planning in Management,NATURE,CHARTACTERISTICS,STEPS,TYPES,POLICY,PROCEDURES,...
RaniT16
ISO-9001_2015 Transition Phase Checklist.pdf
ISO-9001_2015 Transition Phase Checklist.pdfISO-9001_2015 Transition Phase Checklist.pdf
ISO-9001_2015 Transition Phase Checklist.pdf
SilatCersil
Walmart Presentation - Siddhartha Chatterjee.pptx
Walmart Presentation - Siddhartha Chatterjee.pptxWalmart Presentation - Siddhartha Chatterjee.pptx
Walmart Presentation - Siddhartha Chatterjee.pptx
Siddhartha Chatterjee
Vietnam Investment Review - featuring Tran Quoc Bao A Visionary Leader Reshap...
Vietnam Investment Review - featuring Tran Quoc Bao A Visionary Leader Reshap...Vietnam Investment Review - featuring Tran Quoc Bao A Visionary Leader Reshap...
Vietnam Investment Review - featuring Tran Quoc Bao A Visionary Leader Reshap...
Ignite Capital
Traktor Pro Crack + License Key Free Download [2025]
Traktor Pro Crack + License Key Free Download [2025]Traktor Pro Crack + License Key Free Download [2025]
Traktor Pro Crack + License Key Free Download [2025]
xcfxghgfbvncvbhxcf
Lead the Way-Effective Teams in the Modern Workplace.pptx
Lead the Way-Effective Teams in the Modern Workplace.pptxLead the Way-Effective Teams in the Modern Workplace.pptx
Lead the Way-Effective Teams in the Modern Workplace.pptx
Career Communications Group
GetData Graph Digitizer With Crack Free Download [Latest]
GetData Graph Digitizer With Crack Free Download [Latest]GetData Graph Digitizer With Crack Free Download [Latest]
GetData Graph Digitizer With Crack Free Download [Latest]
wkmbwmnk
LESSON 10 STABLISHING VALIDITY AND REALBILITY OF RESEARCH INSTRUMENT- DAGAM...
LESSON  10 STABLISHING VALIDITY AND REALBILITY OF RESEARCH INSTRUMENT-  DAGAM...LESSON  10 STABLISHING VALIDITY AND REALBILITY OF RESEARCH INSTRUMENT-  DAGAM...
LESSON 10 STABLISHING VALIDITY AND REALBILITY OF RESEARCH INSTRUMENT- DAGAM...
dagamijessamaedagle
Employees Empowerment (Human Resource Management)
Employees Empowerment (Human Resource Management)Employees Empowerment (Human Resource Management)
Employees Empowerment (Human Resource Management)
Dr. Amar Nath Tiwari
DIGITAL TECH GUARD RECOVERY - THE BEST RECOVERY EXPERTS
DIGITAL TECH GUARD RECOVERY - THE BEST RECOVERY EXPERTSDIGITAL TECH GUARD RECOVERY - THE BEST RECOVERY EXPERTS
DIGITAL TECH GUARD RECOVERY - THE BEST RECOVERY EXPERTS
sherylmalek66
Exploring DesignOps as a Business Strategic Function
Exploring DesignOps as a Business Strategic FunctionExploring DesignOps as a Business Strategic Function
Exploring DesignOps as a Business Strategic Function
Patrizia Bertini
Gender Dynamics in Workplace Harassment.pdf
Gender Dynamics in Workplace Harassment.pdfGender Dynamics in Workplace Harassment.pdf
Gender Dynamics in Workplace Harassment.pdf
Lisa Bell
CHAPTER-1-TuwhwuwuwhwhwhO-5-GROUP-4.docx
CHAPTER-1-TuwhwuwuwhwhwhO-5-GROUP-4.docxCHAPTER-1-TuwhwuwuwhwhwhO-5-GROUP-4.docx
CHAPTER-1-TuwhwuwuwhwhwhO-5-GROUP-4.docx
GellaBenson1
Group Work Process in Rehabilitation PPT
Group Work Process in Rehabilitation PPTGroup Work Process in Rehabilitation PPT
Group Work Process in Rehabilitation PPT
SagayaBinoshini
Tran Quoc Bao: Revolutionizing Healthcare with Vision and Strategy
Tran Quoc Bao: Revolutionizing Healthcare with Vision and StrategyTran Quoc Bao: Revolutionizing Healthcare with Vision and Strategy
Tran Quoc Bao: Revolutionizing Healthcare with Vision and Strategy
Ignite Capital
Mastering Emotional Intelligence for Effective Leadership.pptx
Mastering Emotional Intelligence for Effective Leadership.pptxMastering Emotional Intelligence for Effective Leadership.pptx
Mastering Emotional Intelligence for Effective Leadership.pptx
Career Communications Group
Mastering Influence-Strategies for Effective Leadership Without Authority.pptx
Mastering Influence-Strategies for Effective Leadership Without Authority.pptxMastering Influence-Strategies for Effective Leadership Without Authority.pptx
Mastering Influence-Strategies for Effective Leadership Without Authority.pptx
Career Communications Group
Management Principles on Small Scale Industries.
Management Principles on Small Scale Industries.Management Principles on Small Scale Industries.
Management Principles on Small Scale Industries.
CryptoMaster7
(Sent) IFI_Phan Th畛c Anh_Corporate Social Responsibility Strategy.pptx
(Sent) IFI_Phan Th畛c Anh_Corporate Social Responsibility Strategy.pptx(Sent) IFI_Phan Th畛c Anh_Corporate Social Responsibility Strategy.pptx
(Sent) IFI_Phan Th畛c Anh_Corporate Social Responsibility Strategy.pptx
tanhphan5
COMMUNICATION SKILLS Dr Akshay Shetty.pptx
COMMUNICATION SKILLS Dr Akshay Shetty.pptxCOMMUNICATION SKILLS Dr Akshay Shetty.pptx
COMMUNICATION SKILLS Dr Akshay Shetty.pptx
Akshay Shetty
Planning in Management,NATURE,CHARTACTERISTICS,STEPS,TYPES,POLICY,PROCEDURES,...
Planning in Management,NATURE,CHARTACTERISTICS,STEPS,TYPES,POLICY,PROCEDURES,...Planning in Management,NATURE,CHARTACTERISTICS,STEPS,TYPES,POLICY,PROCEDURES,...
Planning in Management,NATURE,CHARTACTERISTICS,STEPS,TYPES,POLICY,PROCEDURES,...
RaniT16
ISO-9001_2015 Transition Phase Checklist.pdf
ISO-9001_2015 Transition Phase Checklist.pdfISO-9001_2015 Transition Phase Checklist.pdf
ISO-9001_2015 Transition Phase Checklist.pdf
SilatCersil
Walmart Presentation - Siddhartha Chatterjee.pptx
Walmart Presentation - Siddhartha Chatterjee.pptxWalmart Presentation - Siddhartha Chatterjee.pptx
Walmart Presentation - Siddhartha Chatterjee.pptx
Siddhartha Chatterjee
Vietnam Investment Review - featuring Tran Quoc Bao A Visionary Leader Reshap...
Vietnam Investment Review - featuring Tran Quoc Bao A Visionary Leader Reshap...Vietnam Investment Review - featuring Tran Quoc Bao A Visionary Leader Reshap...
Vietnam Investment Review - featuring Tran Quoc Bao A Visionary Leader Reshap...
Ignite Capital
Traktor Pro Crack + License Key Free Download [2025]
Traktor Pro Crack + License Key Free Download [2025]Traktor Pro Crack + License Key Free Download [2025]
Traktor Pro Crack + License Key Free Download [2025]
xcfxghgfbvncvbhxcf
Lead the Way-Effective Teams in the Modern Workplace.pptx
Lead the Way-Effective Teams in the Modern Workplace.pptxLead the Way-Effective Teams in the Modern Workplace.pptx
Lead the Way-Effective Teams in the Modern Workplace.pptx
Career Communications Group
GetData Graph Digitizer With Crack Free Download [Latest]
GetData Graph Digitizer With Crack Free Download [Latest]GetData Graph Digitizer With Crack Free Download [Latest]
GetData Graph Digitizer With Crack Free Download [Latest]
wkmbwmnk
LESSON 10 STABLISHING VALIDITY AND REALBILITY OF RESEARCH INSTRUMENT- DAGAM...
LESSON  10 STABLISHING VALIDITY AND REALBILITY OF RESEARCH INSTRUMENT-  DAGAM...LESSON  10 STABLISHING VALIDITY AND REALBILITY OF RESEARCH INSTRUMENT-  DAGAM...
LESSON 10 STABLISHING VALIDITY AND REALBILITY OF RESEARCH INSTRUMENT- DAGAM...
dagamijessamaedagle
Employees Empowerment (Human Resource Management)
Employees Empowerment (Human Resource Management)Employees Empowerment (Human Resource Management)
Employees Empowerment (Human Resource Management)
Dr. Amar Nath Tiwari
DIGITAL TECH GUARD RECOVERY - THE BEST RECOVERY EXPERTS
DIGITAL TECH GUARD RECOVERY - THE BEST RECOVERY EXPERTSDIGITAL TECH GUARD RECOVERY - THE BEST RECOVERY EXPERTS
DIGITAL TECH GUARD RECOVERY - THE BEST RECOVERY EXPERTS
sherylmalek66
Exploring DesignOps as a Business Strategic Function
Exploring DesignOps as a Business Strategic FunctionExploring DesignOps as a Business Strategic Function
Exploring DesignOps as a Business Strategic Function
Patrizia Bertini
Gender Dynamics in Workplace Harassment.pdf
Gender Dynamics in Workplace Harassment.pdfGender Dynamics in Workplace Harassment.pdf
Gender Dynamics in Workplace Harassment.pdf
Lisa Bell
CHAPTER-1-TuwhwuwuwhwhwhO-5-GROUP-4.docx
CHAPTER-1-TuwhwuwuwhwhwhO-5-GROUP-4.docxCHAPTER-1-TuwhwuwuwhwhwhO-5-GROUP-4.docx
CHAPTER-1-TuwhwuwuwhwhwhO-5-GROUP-4.docx
GellaBenson1
Group Work Process in Rehabilitation PPT
Group Work Process in Rehabilitation PPTGroup Work Process in Rehabilitation PPT
Group Work Process in Rehabilitation PPT
SagayaBinoshini
Tran Quoc Bao: Revolutionizing Healthcare with Vision and Strategy
Tran Quoc Bao: Revolutionizing Healthcare with Vision and StrategyTran Quoc Bao: Revolutionizing Healthcare with Vision and Strategy
Tran Quoc Bao: Revolutionizing Healthcare with Vision and Strategy
Ignite Capital
Mastering Emotional Intelligence for Effective Leadership.pptx
Mastering Emotional Intelligence for Effective Leadership.pptxMastering Emotional Intelligence for Effective Leadership.pptx
Mastering Emotional Intelligence for Effective Leadership.pptx
Career Communications Group

IH - Fit to ISP and IPP - Module 3 Powerpoint Presentation.pptx

  • 1. American Security and Privacy, LLC Incident Handler Certification Dr. Kevin F. Streff Founder and Managing Partner 1 Incident Handler Certification
  • 2. American Security and Privacy, LLC Incident Handler Certification American Security and Privacy, LLC Incident Handler Certification Dr. Kevin Streff American Security and Privacy, LLC Founder & Managing Partner www.americansecurityandprivacy.com Kevin.Streff@americansecurityandprivacy.com 605.270.4427 2
  • 3. American Security and Privacy, LLC Incident Handler Certification American Security and Privacy, LLC Incident Handler Certification Agenda 3 Module 1 Incident Response Overview Module 2 Incident Response Laws and Regulations Module 3 The Fit of Incident Response in Information Security and Privacy Programs Module 4 Privacy Incidents Module 5 Security Incidents Module 6 Incident Response Program Overview Module 7 Step 1 - Preparation Module 8 Step 2 - Detection and Analysis Module 9 Step 3 - Contain, Eradicate, and Recover Module 10 Step 4 - Post Incident Activity Module 11 Incident Response Testing Module 12 Third Party Incident Response Requirements Module 13 Incident Response Auditing Module 14 Incident Response Metrics
  • 4. American Security and Privacy, LLC Incident Handler Certification Module 3 THE ROLE OF INCIDENT MANAGEMENT IN INFORMATION SECURITY AND PRIVACY PROGRAMS 4
  • 5. American Security and Privacy, LLC Incident Handler Certification American Security and Privacy, LLC Incident Handler Certification Gramm- Leach-Bliley Act of 1999 Required financial institutions to implement an Information Security Program 5
  • 6. American Security and Privacy, LLC Incident Handler Certification American Security and Privacy, LLC Incident Handler Certification Leading Security Frameworks 1.NIST Security Framework 2.OASIS Security Framework 3.APEC Security Framework 4.Nymity Security Management Accountability Framework 5.HITRUST Security Framework 6.American Security and Privacy Information Security Framework 7.ISO 2700x Framework 6
  • 7. American Security and Privacy, LLC Incident Handler Certification Information Security Program Blueprint Inventories Policies Procedures Standards Guidelines Plans Audit/Test Results Reports SARS Meeting Minutes Committee Approvals Previous Exams Awareness/Training Materials Third Party Reports Network Diagram Organizational Chart Process Flows Incident Reports Strategies Budgets Memos FI Processes Documentation Asset Mgmt. Physical Security Business Continuity Incident Response Developme nt & Acquisition Operations Security Risk Mgmt. Network Security Auditing Functions Personnel Security Reporting Remediation Assessment Changes Audit Recommendations Exam Findings Incident Reports Policy Changes Board Committee Operations Third Party Examiner FI and Technology Strategy ASP ISP v1.1 IT Audit Soc. Eng. Pen Test Scans Third Party Mgmt. Soft. Dev. Customer Employee Third Parties Systems Inventory Technology BIA AUP Roles & Resp. BCP Pandemic Preparedness 7
  • 8. American Security and Privacy, LLC Incident Handler Certification American Security and Privacy, LLC Incident Handler Certification CFPB 1033 Required financial institutions to implement an Information Privacy Program Supports the Open Banking concept Requires for security and privacy 8
  • 9. American Security and Privacy, LLC Incident Handler Certification American Security and Privacy, LLC Incident Handler Certification Leading Privacy Frameworks 1. NIST Privacy Framework 2. American Security and Privacy (ASP) Information Privacy Framework (IPP) 3. ISO Privacy Framework (27701) 9
  • 10. American Security and Privacy, LLC Incident Handler Certification Data Mgmt Consent Mgmt Vendor Mgmt DSAR Mgmt Web Tracing & Cookie Mgmt Privacy Program Mgmt Privacy Engineering Emergency Mgmt. Information Privacy Program Blueprint Assessments Compliance Reporting Remediation Inventories Policies Procedures Standards Guidelines Plans Audit/Test Results Reports SARS Meeting Minutes Committee Approvals Previous Exams Awareness/ Training Materials Vendor Reports Network Diagram Organizational Chart Process Flows Incident Reports Data Flows Privacy Audit Consent Mgmt Audit Id Mgmt Audit Cookie Tracking Audit Website Tracking Audit Data Masking Audit Pseudonymity Audit Privacy/PIA Cookie Tracking Website Tracking Data Masking Pseudonymity Assessment Changes Compliance Recommendations Exam Findings Regulatory Changes Legal Changes Board Committees Operations Vendor Examiner Strategies/ Budgets Training Logs Memos DSARS ROPAS Data Mappings Functions Processes Documentation Privacy Notices Awareness & Training Mgmt ETC. User Mgmt 10
  • 11. American Security and Privacy, LLC Incident Handler Certification American Security and Privacy, LLC Incident Handler Certification Summary Need both an Information Security Program (ISP) and Information Privacy Program (IPP) which include Incident Management 11
  • 12. American Security and Privacy, LLC Incident Handler Certification American Security and Privacy, LLC Incident Handler Certification Dr. Kevin Streff American Security and Privacy, LLC Founder & Managing Partner www.americansecurityandprivacy.com Kevin.Streff@americansecurityandprivacy.com 605.270.4427 12 American Security and Privacy, LLC