change s to the infor mation t e c hnology se c ur ity
play

Change s to the Infor mation T e c hnology Se c ur ity Wor kfor - PowerPoint PPT Presentation

Change s to the Infor mation T e c hnology Se c ur ity Wor kfor c e Offic e o f the Chie f Info rma tio n Offic e r Ca ro lyn Sc hmidt Ma rc h 2010 1 Outline Why c ha ng e ? Wha t c ha ng e s? Impa c t o f c ha ng e


  1. Change s to the Infor mation T e c hnology Se c ur ity Wor kfor c e Offic e o f the Chie f Info rma tio n Offic e r Ca ro lyn Sc hmidt Ma rc h 2010 1

  2. Outline • Why c ha ng e ? • Wha t c ha ng e s? • Impa c t o f c ha ng e s? • He lping with c ha ng e ? • Que stio ns a nd Answe rs? 2

  3. 3

  4. 4

  5. Why c hange ? • OI G re p o rts – Co mme rc e Sho uld T a ke Ste ps to Stre ng the n Its IT Se c urity Wo rkfo rc e (F ina l Audit Re po rt No . CAR-19569-1) – T o p Ma na g e me nt Cha lle ng e s F a c ing the De pa rtme nt o f Co mme rc e (F ina l Re po rt OIG-9884) • OCI O d id no t d isp ute • T hre a t e nviro nme nt wa rra nts • I nc o nsiste nt le ve ls o f e xp e rtise • E na b le sha ring o f e xp e rtise whe n re sp o nd ing to inc id e nt(s) 5

  6. What c hange s? • Po lic y • Pe rfo rma nc e me tric s • Cle a ra nc e s re q uire d fo r so me func tio ns • CIO/ IT SO • Re vie wing o the r func tio ns (Autho rizing Offic ia l, Info rma tio n Syste m Owne r, Info rma tio n Syste m Se c urity Offic e r, Ce rtific a tio n Ag e nc y, Inc ide nt Re spo nse Pe rso nne l, a nd ke y c o nting e nc y ro le s) • Ma nd a to ry a nnua l sp e c ia lize d tra ining • supple me nta l to g e ne ra l tra ining • Pro fe ssio na l c e rtific a tio ns re q uire d fo r IT SO, ISSO, IR ro le s • Inc lusio n o f re q uire me nts in ne w va c a nc ie s • Po sitio n Se nsitivity 6

  7. Pr ofe ssional Ce r tific ation • IT SO Ma p s to Do D 8570.01-M, Cha ng e 2, XX/XX/2009. I AM L e ve ls I , I I , a nd I I I • ISSO Ma p s to Do D 8570.01-M, Cha ng e 2, XX/XX/2009. I AM L e ve ls I , I I , a nd I I I • IR Ma p s to Do D 8570.01-M, Cha ng e 2, XX/XX/2009. CND I nc ide nt Re p o rte r 7

  8. Impac t of c hange s? • T o DOC – E sta b lishing minimum b a r fo r e xpe rtise a nd inc re a se s a c c o unta b ility – No rma lizing e xpe rtise a c ro ss DOC • T o sta ff – E nsure tra ining ne e d to do jo b – Po sitio ns a t risk if tra ining no t me t o r o the r re q uire me nts no t me t (i.e ., c le a ra nc e s) – E sta b lishe s pro fe ssio na l de ve lo pme nt pa th • T o Fe d e ra l c o mmunity – Use o f pro fe ssio na l c e rtific a tio ns – E sta b lishing c a pa b ility to sha re sta ff during inc ide nts 8

  9. How ar e we he lping with the se c hange s? • Ca re e rs in Mo tio n – Ca re e r c o unse ling • We b -b a se d c o urse a va ila b ility in CL C • De ve lo pme nt Pla n • Cyb e r Se c urity De ve lo p me nt Pro g ra m (CSDP) – Info rma tio n Syste m Se c urity Offic e rs 9

  10. 10

  11. Que stions and Answe r s? 11

Recommend


More recommend