In today’s tech environment it is critical that organizations be pro-active and prepared when considering cyber risk management. Because of the size, complexity, and constant evolution of attack vectors there is no one-size-fits-all way to respond. It is essential to begin somewhere to establish a baseline for identifying the critical components that must be incorporated into any cybersecurity risk management approach.
Multiple risk management frameworks exist including:
• NIST: National Institute of Standards and Technology (NIST) established by executive order in February 2013.
• ISO/IEC Security Control Standard: developed by the International Organization for Standardization and the International Electrotechnical Commission
• FFIEC Cybersecurity Assessment – developed for Financial institutions by the Federal Financial Institutions Examination Council
• SEC/OCIE Cybersecurity Initiative – developed for brokers by the U.S. Securities and Exchange Commission (SEC) Office of Compliance Inspections and Examinations
• FCC Cyber Security Planning Guide – developed by the Federal Communications Commission for small businesses
Although their organization and structures vary, all frameworks attempt to address the same basic functions designed by the NIST Cybersecurity Framework:
• Identify
• Protect
• Detect
• Respond
• Recover
In this course we evaluate several attributes critical to the proper establishment of a cyber risk management program. We delve into the concepts and apply thoughts as to how each component should be evaluated for your organization. The course utilizes the NIST framework as a guide for application.
Publication Date: May 2019
Designed For
Information technology specialists, Internal auditors, Professionals considering the role of internal audit, Chief Audit Executives, Accountants and Finance professionals, CFOs, CEOs, Legal and Compliance professionals, Board members and Audit Committee members.
Topics Covered
- Explore effective cyber frameworks
- ISO/IEC Security Control Standard
- FFIEC Cybersecurity Assessment
- SEC/OCIE Cybersecurity Initiative
- FCC Cyber Security Planning Guide
- NIST FRAMEWORK
- NIST CORE
- Framework Core Functions
Learning Objectives
- Recognize and apply effective cyber frameworks
- Identify the National Institute of Standards and Technology (NIST) cyber framework
- Describe components of the NIST cyber framework and their applicability to any framework
- Recognize the concept of framework tiers and profiles
- Identify steps to implement a framework
- Recognize how to apply the plan-do-check-act (PDCA) cycle
- Describe the five concurrent functions of the NIST Framework Core
- Differentiate the Implementation Tiers
- Differentiate types of cybersecurity frameworks and how they apply
Level
Basic
Instructional Method
Self-Study
NASBA Field of Study
Information Technology (2 hours)
Program Prerequisites
None
Advance Preparation
None
Instructor
Lynn Fountain
Lynn Fountain has over 38 years of experience spanning public accounting, corporate accounting and consulting. 20 years of her experience has been working in the areas of internal and external auditing and risk management. She is a subject matter expert in multiple fields including internal audit, ethics, fraud evaluations, Sarbanes-Oxley, enterprise risk management, governance, financial management and compliance. Lynn has held two Chief Audit Executive (CAE) positions for international companies. In one of her roles as CAE, she assisted in the investigation of a multi-million-dollar fraud scheme perpetrated by a vendor that spanned 7 years and implicated 20 employees. The fraud was formally investigation by the FBI and resulted in 5 indictments estimating a $13M fraud loss.
Ms. Fountain is currently engaged in her own consulting and training practice. She is a highly sought-after trainer and international speaker. In addition, Ms. Fountain has assisted numerous companies with enterprise risk management frameworks, internal audit processes and financial accounting. She also serves as a discussion leader for the AICPA for numerous classes finance, accounting and risk management topics.
Ms. Fountain is the author of three separate technical books. Her first book released in 2015 by the Institute of Internal Auditors Foundation is entitled “Raise the Red Flag – The Internal Auditors Guide to Fraud Evaluations”. Her second book “Leading the Internal Audit Function” was released in October 2015 by Taylor & Francis Publications. This book serves as the initial launch for a series of leading practice internal audit and information technology publications. Her third book “Ethics and the Internal Auditor’s Dilemma” was released in December 2016.
Ms. Fountain obtained her BSBA from Pittsburg State University and her MBA from Washburn University in Kansas. She has her CPA, CGMA, CRMA credentials.