<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Framework - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/framework-2/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/framework-2/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Tue, 13 Jun 2023 11:37:47 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Framework - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/framework-2/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Engaging the C-Suite on Information Security</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/06/engaging-the-c-suite-on-information-security/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/06/engaging-the-c-suite-on-information-security/#respond</comments>
		
		<dc:creator><![CDATA[Lloyd Barwood]]></dc:creator>
		<pubDate>Tue, 13 Jun 2023 13:00:00 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[How to]]></category>
		<category><![CDATA[C-Suite]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Framework]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Strategy]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=20710</guid>

					<description><![CDATA[<p>Introduction The ever-increasing threat of cyber-attacks on organisations around the world and their potentially devastating financial, reputational, or operational impact on the business means it has never been more important to position Cyber Security as a major issue in front...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/06/engaging-the-c-suite-on-information-security/">Engaging the C-Suite on Information Security</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h3 style="text-align: justify;"><strong>Introduction</strong></h3>
<p style="text-align: justify;">The ever-increasing threat of cyber-attacks on organisations around the world and their potentially devastating financial, reputational, or operational impact on the business means it has never been more important to position Cyber Security as a major issue in front of the C-Suite. The C-Suite holds ultimate accountability for an organisation’s approach to risk in both setting the appetite for Cyber risk for the business and ensuring sufficient budget &amp; resource is assigned to manage Cyber risk to within the appetite. If they are not appropriately informed of the risks associated with Information Security (IS), the organisation may not put in place the correct and appropriate mitigations to protect the organization from their top threats and risks.</p>
<p style="text-align: justify;">Failure to effectively protect against these cyber threats can have both organisational and personal consequences for executives. For example, The Senior Managers and Certification Regime (SMR) is an FCA enforced regulation that assigns responsibility for Information Security to executive level employees, making them liable for correct implementation of cyber protections for IS.</p>
<p style="text-align: justify;">This article will provide you with a 4-stage approach on how to better engage the C-Suite in your organisation on Information Security, to build a fruitful partnership between these executives who direct budget &amp; resource towards Information Security and the Cyber teams who are responsible for the oversight &amp; implementation of security.</p>
<h3 style="text-align: justify;"><strong>Stage 1: Introducing the Execs to Cyber Security</strong></h3>
<p style="text-align: justify;">In this first session with the C-Suite, it is imperative that you initiate the conversation by focusing on an introduction to Cyber Security that provides an overarching view of the organisation’s Cyber Security capabilities and operating model, that will encourage future more in-depth discussion.</p>
<p style="text-align: justify;">Outline the responsibilities the organisation and executives have towards Information Security and how these align with the strategic priorities of the organisation &amp; Cyber team. This should include a presentation of the top threats to the organization (both internal &amp; external), the risks that they expose the organisation to and the existing roadmap to mitigating these risks. This will provide a high-level overview of the organisation’s Cyber capability and will set the tone ready for future conversations with the C-Suite.</p>
<p style="text-align: justify;">Provide an overview showing the blueprint for Information Security and how security integrates and adds value to the rest of the business. It is important to include metrics that can be used to compare the organisation’s approach to Cyber Security against peers within the market. A difference in budget or team size compared to a competitor can provide guidance on whether the organisation is assigning adequate resources and budget to the issue. </p>
<h3 style="text-align: justify;"><strong>Stage 2: 360 Audit</strong></h3>
<p style="text-align: justify;">After successfully introducing the C-Suite to Information Security, it is now essential that you lock in that second session where you can provide a more granular breakdown of the organisation’s Cyber Security capability with a clear focus on where resources need to be focussed.</p>
<p style="text-align: justify;">Industry standard frameworks, such as ISO and NIST, should be deployed to measure an organisation’s Cyber Security maturity and provide analysis on potential improvements that can be presented to the C-Suite executives. These frameworks offer controls against which the organisation can be benchmarked, to identify areas that require maturing to mitigate risk from the organisation’s top threats. While these frameworks in their original state offer a good measurement of maturity, it is important to refine the controls so that the framework is tailored towards the organisation, taking into consideration the industry sector and regulatory environment. Wavestone recommends taking the NIST framework as a basis and fitting it to the specific stakes of the organisation to overcome any framework limitation and focus it on the businesses’ needs.</p>
<p style="text-align: justify;">Wavestone have built our own framework, called the Cyber Benchmark, that leverages the best of industry frameworks to provide a comprehensive approach to maturity assessment with organisational &amp; technological perspectives included. We recommend organisations follow a similar approach to accelerate their framework improvements to increasing their Cyber maturity.</p>
<p style="text-align: justify;">Capturing the attention of senior executives to invest time &amp; resources into developing a framework to improve Cyber maturity can be difficult. A good methodology is to provide real life evidence of their security vulnerabilities, for example by presenting evidence of how an internal ‘Red Team’ gained access to the mailboxes of the senior executives present, with an explanation of how few days it took. </p>
<h3 style="text-align: justify;"><strong>Stage 3: Programme and Framework</strong></h3>
<p style="text-align: justify;">Once this more granular breakdown has been presented, a key priority must be to ensure the C-Suite has bought into the Cyber Security strategy &amp; roadmap; developed using the maturity improvement opportunities identified through the framework assessment. Buy in from the C-Suite on the roadmap will guarantee the required funding &amp; resources required to implement these enhancements.</p>
<p style="text-align: justify;">Using the customised framework, develop a roadmap that focuses on maturing controls that will most effectively reduce the risk from the organisation’s top threats. This roadmap will become the building blocks for the security programme. The security programme should be defined so that it provides clear targets to be met to ensure compliance with the customised framework controls, beginning with a remediation approach that will guarantee a standard Cyber maturity across the organisation, and followed by steps to achieve the Cyber maturity goals. Ensuring a standard maturity across the organisation will alleviate the risk from current threats, while building on this to achieve maturity targets will reduce the potential risk from over-the-horizon threats.</p>
<p style="text-align: justify;">Programme support can be leveraged from a specialised Project Management Office (PMO) that will supervise the execution of the programme. It is important that this PMO curates a good relationship between IT who will implement the roadmap to maturity and the business, so that the benefits are understood and extracted across the organisation.</p>
<h3 style="text-align: justify;"><strong>Stage 4: Risk Quantification and Business Accelerators </strong></h3>
<p style="text-align: justify;">The final stage of engaging with the C-Suite requires you to demonstrate the return on investment (ROI) that Cyber Security can deliver, both through risk reduction from top threats and as a business enabler that encourages expansion into new territories and engaging new client relationships.</p>
<p style="text-align: justify;">Implementing the appropriate customised framework to the organisation and following the established roadmap to Cyber Security maturity will require an increased budget allocation. However, it is important to emphasise to the board that the return on this investment will far exceed the initial cost due to a dramatic decrease in the scale and severity of risk that the organisation is exposed to. Use calculations to demonstrate this Return on Investment (ROI) quantitively and link this to the efforts and changes delivered by the security programme. It should also be explained that this initial outlay required to deliver the security programme is far less than the potential financial, reputational, and personal (e.g., SMR) repercussions that would result from a failure to adequately protect information systems during a cyber-attack.</p>
<p style="text-align: justify;">As well as preventing the serious repercussions of failing to protect information systems in an attack, Cyber Security can also become an important business enabler. Effective Cyber Security will ensure that your customers are retained in the event of a properly managed security breach, as well as confirming your organisation as a secure manager of customer data &amp; details, increasing your attractiveness to new customers. A secure organisation can move swiftly into new business environments &amp; seize opportunities with confidence that their Cyber Security maturity will be able to resist potential additional threats that may arise from this expansion; opening the door for the organisation to safely engage a wider client base.</p>
<h3 style="text-align: justify;"><strong>Conclusion</strong></h3>
<p style="text-align: justify;">Following the 4-stages outlined in this article will allow you to foster a strong relationship with the C-Suite on Information Security, ensuring they are aware of their responsibilities for Cyber Security under the SMR and that they assign budget &amp; resources appropriately to deal with the top threats facing the organisation. The customised framework will allow these executives to understand the current Cyber Security posture of the organisation and buy in to the roadmap for future maturity. Once this vision of mature Cyber Security has been delivered, the business incentives can be leveraged to ensure the C-Suite continues to invest in developing Information Security within your organisation.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/06/engaging-the-c-suite-on-information-security/">Engaging the C-Suite on Information Security</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/06/engaging-the-c-suite-on-information-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[INTERVIEW] IAM Maturity Assessment &#8211; Where do you stand and why is it crucial?</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/05/interview-iam-will-no-longer-hold-any-secrets-for-you-thanks-to-the-iam-framework/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/05/interview-iam-will-no-longer-hold-any-secrets-for-you-thanks-to-the-iam-framework/#respond</comments>
		
		<dc:creator><![CDATA[Anatole Catherin]]></dc:creator>
		<pubDate>Mon, 22 May 2023 09:00:00 +0000</pubDate>
				<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[Framework]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[Maturity]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=20502</guid>

					<description><![CDATA[<p>For over twenty years, Wavestone has been supporting clients develop and strengthen their Identity and Access Management programs. Within this area, Wavestone has observed  that organizations do not always approach IAM in a comprehensive manner. While Security is an obvious...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/05/interview-iam-will-no-longer-hold-any-secrets-for-you-thanks-to-the-iam-framework/">[INTERVIEW] IAM Maturity Assessment &#8211; Where do you stand and why is it crucial?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">For over twenty years, Wavestone has been supporting clients develop and strengthen their Identity and Access Management programs. Within this area, Wavestone has observed  that organizations do not always approach IAM in a comprehensive manner. While Security is an obvious dimension covered by IAM, other dimensions (e.g. UX enhancement, internal procedures improvement, etc.) are often overlooked. Additionally, accurately assessing  maturity in IAM is complex &#8211; market standards, such as NIST, does not allow evaluation across all issues.</p>
<p style="text-align: justify;">To dive deeper into IAM, our experts have created an IAM maturity assessment tool.</p>
<p style="text-align: justify;">Interview with Anatole CATHERIN, Manager and IAM expert for almost 10 years at Wavestone.</p>
<p style="text-align: justify;"><strong> </strong></p>
<h1 style="text-align: justify;">Hi Anatole, thanks for your time! First of all, can you explain what IAM really is?</h1>
<p style="text-align: justify;">Identity and Access Management (IAM) is a discipline that sits at the crossroads of three worlds:</p>
<ol style="text-align: justify;">
<li>Cybersecurity strengthening: It comprises managing identities, the rights granted to these identities and user access to company resources. Each user has access confined to the limits of their role within an organization. To successfully achieve this, <strong>organizations need to know who, within their information system, can perform which actions and why</strong>. IAM is therefore an essential component of cybersecurity, especially during implementation of a Zero Trust policy.</li>
<li>Business enablement: Identity and Access Management is also a business enabler and a <strong>facilitator for successful digital transformation within organizations as it increases operational process efficiency to </strong>employees and customers. For example, IAM enables the control and fluidity of arrivals, departures or mobility by ensuring that new employee benefit from accurate accesses. In case of subsequent mobility or departure, the relevant accesses are removed and no information is lost.</li>
<li>UX enhancement: <strong>IAM facilitates a seamless user experience for employees</strong> within an organization. Moreover, the best IAM systems operate behind the scenes to enable work on arrival and enhanced connectivity based on security requirements.</li>
</ol>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">Why is it so difficult to build an IAM system that works?</h1>
<p style="text-align: justify;">As you can imagine, the challenge and complexity of IAM is striking (and maintaining) the balance between security and fluidity of navigation.</p>
<p style="text-align: justify;">To successfully implement IAM, it is important to assess the current state. With good reason, <strong>clients have difficulty measuring the effectiveness of their existing IAM system</strong>. There is no dedicated benchmark in the market evaluation.. The NIST pillars are high-level and do not cover all the challenges related to IAM; the existing benchmarks only deal with the cybersecurity aspect of IAM and ignores the impact on the operational efficiency of an organization&#8217;s internal procedures and the fluidity of the user experience.</p>
<p style="text-align: justify;">The goal in creating the IAM Framework was to create a <strong>framework that evaluates the entire discipline and that can be used to build an efficient roadmap.</strong></p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">Can you tell us a bit about the IAM maturity assessment tool?</h1>
<p style="text-align: justify;"><strong>More than a tool, it&#8217;s a framework and a tool-based methodology</strong> that supports customers and provides them an overview of their IAM maturity.</p>
<p style="text-align: justify;">The Framework enables the understanding of an<strong> organization’s current state (</strong>which IAM perimeters are deployed (or not), which IAM axes require further work, etc.). It provides an overview, with the right framework, the right angle and the right resolution to cover all IAM topics.</p>
<p style="text-align: justify;">The maturity assessment consequently <strong>allows the prioritization of workstreams that culminates in an IAM action</strong> <strong>plan</strong>!  Thanks to this framework, we can identify the main areas for improvement, while accounting for organizational nuances by introducing the notion of scope.</p>
<p style="text-align: justify;">In short, it meets <strong>three objectives: Evaluate, Improve and Extend </strong>IAM to other perimeters (beyond internal and service providers, with customers or partners). It was intended to be exhaustive to highlight our customers&#8217; shortcomings and subsequently measure their progress and the effectiveness of their transformation program.</p>
<p style="text-align: justify;">Our ambition is to make it <strong>the primary evaluation standard, entirely dedicated to IAM</strong>, with a sufficient level of granularity to cover all issues!</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">How is it structured?</h1>
<p style="text-align: justify;">Concretely, our tool is composed of about fifty questions that cover the <strong>6 IAM themes</strong>:</p>
<ol style="text-align: justify;">
<li>Governance</li>
<li>Identity management</li>
<li>Entitlement management</li>
<li>Access control</li>
<li>Privileged access management</li>
<li>Reporting and controls</li>
</ol>
<p style="text-align: justify;">It can be used in several cases, here are 2 examples:</p>
<table>
<tbody>
<tr>
<td style="background-color: #503078; width: 601px;" width="601">
<p><span style="color: #ffffff;"><u>Use case 1: </u></span></p>
<p><span style="color: #ffffff;">During an audit or (pre)scoping mission, i.e. when you do not know your level of maturity in terms of access and identity management.</span></p>
<p><span style="color: #ffffff;">In this case, the questions allow you to identify areas for improvement in order to launch IAM evolution projects.</span></p>
</td>
</tr>
</tbody>
</table>
<p style="text-align: justify;"> </p>
<table>
<tbody>
<tr>
<td style="background-color: #503078; width: 601px;" width="601">
<p><span style="color: #ffffff;"><u>Use Case 2: </u></span></p>
<p><span style="color: #ffffff;">As part of a transformation program (medium or long term). This type of maturity assessment can be relevant at the halfway point of a transformation program in order to determine the progress made and to redirect the strategy if necessary.</span></p>
</td>
</tr>
</tbody>
</table>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">Can you tell us about the last time you used it with a concrete example?</h1>
<p style="text-align: justify;">We tested the questionnaire in the field through several missions, during which the use of the IAM Framework helped accelerate the process. These missions comprised:</p>
<ul style="text-align: justify;">
<li>the definition of an IAM roadmap for a large energy company</li>
<li>the framing of a migration to an IAM tool for a banking group, which allowed the measurement of gaps between their existing solution and the new one</li>
<li>IAM maturity assessment for an insurance company, to identify friction points and areas for improvement and to establish a roadmap</li>
</ul>
<p style="text-align: justify;">For these three projects, the assessment grid made it possible to identify all addressable topics (regardless of whether the client was aware of them at the outset) in order to provide an actionable roadmap covering all IAM issues. In other words, the Framework can be used as an analysis framework for the implementation of a project.</p>
<p style="text-align: justify;">We plan to launch new missions on the subject and we are looking forward to supporting new customers in their journey to improve their IAM structure!</p>
<p> </p>
<h1 style="text-align: justify;">A final word?</h1>
<p style="text-align: justify;">I will end by reminding you of the key components of the Framework:</p>
<ul style="text-align: justify;">
<li><strong>It is “ready to use”</strong>: the fifty questions encompassed in the framework designed by Wavestone experts covers all IAM topics</li>
<li>It offers a <strong>standardized and formalized vision of its maturity</strong> on the subject of access and identity management: this assessment is also an opportunity to involve all the key players impacted by IAM: cyber teams, IT teams, internal audit teams and business teams,</li>
<li>It <strong>facilitates the prioritization of actions</strong> within a transformation program:as explained above, it can be used at different times and can therefore be used as a support for a broader reflection,</li>
<li>Finally, <strong>it is a flexible means of use:</strong> It can be used at a very high level (a strategic level) or to develop very specific actions.</li>
</ul>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><strong>Want to evaluate yourself? Please contact us!</strong></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/05/interview-iam-will-no-longer-hold-any-secrets-for-you-thanks-to-the-iam-framework/">[INTERVIEW] IAM Maturity Assessment &#8211; Where do you stand and why is it crucial?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/05/interview-iam-will-no-longer-hold-any-secrets-for-you-thanks-to-the-iam-framework/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
