Text Only Version
- Maximizing Investments in IT Security
- Agenda
- Security Wake Up Call!!
- ROSI Challenges
- Measuring ROSI
- Managing Risk and Security Investments
- Managing Risk; Managing Returns
- Defining Risk
- Can We Eliminate Risk?
- Managing Risk and Security Investments
- Choosing a Security Framework
- Federal Information Security Management Act (FISMA)
- FISMA’s Effect on State Agencies
- Getting More Bang for the Buck
- Key Area 1: Risk Assessment (RA)
- Key Area 2: Configuration Management (CM)
- Key Area 3: Access Control (AC)
- Building an Enterprise Security Program
- Defining an Enterprise Security Program
- Characteristics of an Effective ESP
- Implementing an Effective ESP
- NIST Resources (www.csrc.nist.gov)
- Measuring Success – Key Takeaways
- Questions?
- BearingPoint