The ESRM Evolution: From "No" to Strategic Risk Management

ResolverInc 277 views 30 slides Jun 05, 2017
Slide 1
Slide 1 of 30
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27
Slide 28
28
Slide 29
29
Slide 30
30

About This Presentation

With a career spanning over thirty years and two disciplines, Tim McCreight has adapted from his roots in physical security, to information security, and now his interest in enterprise security risk management (ESRM). Learn how Tim changed his approach from saying “no” to projects, to focusing o...


Slide Content

int:rsect

The ESRM Evolution:
From "No" to Strategic
Risk Management

Tim McCreight
MSc, CISSP CPP CISA
Director, Strategic Alliances
Above Security -
AHitachi Group Company

RESTRICTED

UNDER 17 DEA ACCOMPANYING
DEA OR ADULT GUARDIAN

The following seminar contains coarse
language, violent situations, personal
opinions, and partial speaker nudity.

Viewer discretion is advised.

I hone to God
that's Batman

Agenda

Quick Intro
Journey to ESRM:
- Before

- During

- Today

Benefits

Next Phase

BEFORE

The Clipboard Era

Security by survey...

What we knew...

- More rigid approach

« Binary response

+ Metrics were
"measurements"

- Able to say "no"
based on the
checklist...

Story time...

Reactive vs Proactive

Focused more on
identification
not prevention

Could "cancel" a
project if it was going
to "harm" our company

The story of the
turnstile and the
executive...

Hard Lessons

Look beyond the "rule"

Not everyone thinks like us

Get rid of "no"

DURING

New Ideas

SECURITY
CONVERGENCE &
Oiianaging LS «

Enterprise Security Risk

From this... To this...

Gaps Remained...

Looked at blending
security organizations,
but only touched on risk

Still "security" centric

TODAY

Changes at ASIS

1625 Prin
pr@sssonino og
INTERNATIONAL "00
Advancing Security Worldwide? tor J ONC CAE

NEWS RELEASE

ASIS International Makes Enterprise Security Risk
Management a Global Strategic Priority

Commission established to incorporate ESRM into all ASIS programs and
services

Alexandria, VA 201

(asis
unity Risk

ly manag

ds concepts into all progran

Both a philosophy and management system, ESRI cu
professionals manage the vario ganizations
ooking to shit the profession from a sibed ap curity managemen

a A ROTHSTEIN PUBLISHING COLLECTION eBOOK

The Manager's Guide to
Enterprise
Security Risk
Management

Essentials of Risk-Based Security
Brian J. Allen, Esq.

CISSP, CISM, CPP, CFE

Rachelle Loyear

Kristen Noakes-Fry, asc, ito

ET

Identify
& Prioritize

Incident
Response

Advance

Mitigate
Prioritized
Risks

Ongoing
Risk
Assessment,

Identify
& Prioritize
Risks

Figure 1-1. The ESRM Cycle

BENEFITS

Business focused

Builds relationships

New concepts:
- key stakeholders
- asset owners

- prototyping

Consistency in:
- risk management philosophy
- security roles/responsibilities

Objective vs. Reactive

Y
=
EE qa Y A

Asset centric

ie

Personal
Thoughts

Thank You!

Tim McCreight
MSc, CISSP CPP CISA
Director, Strategic Alliances

Above Security
A Hitachi Group Company

www.abovesecurity.com