Google “cyber risk management jobs”. In today’s world of “the robots are coming for our jobs” you will see an abundance of titles and descriptions. The titles are not the focus. The concept of the need for technical experts beyond our traditional IT personnel is critical. An essential element of any cyber risk management program is properly establishing roles and responsibilities within the organization. Absent this identification, your program is at risk for failure. The NIST cyber risk management framework outlines five activities that comprise a strong cyber program. Those activities include:
• Identify your assets
• Protect your assets
• Detect threats
• Respond to threats
• Recover from threats
Within each activity, the framework highlights the importance of properly identifying and assigning roles and responsibilities to ensure the activities are executed.
With technology such an important aspect of how business is conducted, the players that should be actively involved in a cyber program have expended. When it comes to cyber issues, many may relinquish the responsibilities to the office of the CIO. However, as outlined in various elements of the NIST Cyber Risk Management Framework, organizations must consider the need for assignments and roles beyond the office of the CIO. This course will cover various components of roles and responsibilities within a strong cyber risk management program.
Publication Date: April 2019
Designed For
Information Technology Specialists, Internal auditors, Professionals considering the role of internal audit, Chief Audit Executives, Accountants and Finance professionals, CFOs, CEOs,
Legal and Compliance professionals, Board members and Audit Committee members.
Topics Covered
- The concept of a cybersecurity program
- Various threats to be managed by individuals within CRM roles
- Actions professionals and organizations can take towards prevention of cyber incidents
- Types of cyber risk management roles and critical responsibilities
- Role categories via the NIST cyber framework
- Elements of the IT infrastructure that are critical for the various roles to manage
- Relevant policies, procedures and standards that are critical for professionals executing cyber risk management roles
Learning Objectives
- Identify the various threats that must be managed by individuals responsible for cyber risk management roles
- Recognize and explore actions professionals and organizations can take towards prevention of cyber incidents
- Identify types of cyber risk management roles and critical responsibilities to be executed within various cyber risk management roles
- Describe elements of the information technology infrastructure that are critical for the various roles to manage
- Differentiate relevant policies, procedures and standards that are critical for professionals executing cyber risk management roles
- Identify cyber-physical systems that society relies on
- Differentiate NIST Framework steps used to take action regarding a detected cybersecurity incident
- Recognize common policies describes how to account for IT resources and data
Level
Basic
Instructional Method
Self-Study
NASBA Field of Study
Information Technology (2 hours)
Program Prerequisites
None
Advance Preparation
None
Instructor
Lynn Fountain
Lynn Fountain has over 38 years of experience spanning public accounting, corporate accounting and consulting. 20 years of her experience has been working in the areas of internal and external auditing and risk management. She is a subject matter expert in multiple fields including internal audit, ethics, fraud evaluations, Sarbanes-Oxley, enterprise risk management, governance, financial management and compliance. Lynn has held two Chief Audit Executive (CAE) positions for international companies. In one of her roles as CAE, she assisted in the investigation of a multi-million-dollar fraud scheme perpetrated by a vendor that spanned 7 years and implicated 20 employees. The fraud was formally investigation by the FBI and resulted in 5 indictments estimating a $13M fraud loss.
Ms. Fountain is currently engaged in her own consulting and training practice. She is a highly sought-after trainer and international speaker. In addition, Ms. Fountain has assisted numerous companies with enterprise risk management frameworks, internal audit processes and financial accounting. She also serves as a discussion leader for the AICPA for numerous classes finance, accounting and risk management topics.
Ms. Fountain is the author of three separate technical books. Her first book released in 2015 by the Institute of Internal Auditors Foundation is entitled “Raise the Red Flag – The Internal Auditors Guide to Fraud Evaluations”. Her second book “Leading the Internal Audit Function” was released in October 2015 by Taylor & Francis Publications. This book serves as the initial launch for a series of leading practice internal audit and information technology publications. Her third book “Ethics and the Internal Auditor’s Dilemma” was released in December 2016.
Ms. Fountain obtained her BSBA from Pittsburg State University and her MBA from Washburn University in Kansas. She has her CPA, CGMA, CRMA credentials.