Security Policy Evaluation Using Balanced Scorecards Mohamad El Osta MBA 737 April 29, 2008.

Slides:



Advertisements
Similar presentations
HR SCORECARD Presented By ADEEL TARIQ MOBASHIR ALI.
Advertisements

Paul R. Niven BALANCED SCORECARD STEP-BY-STEP
Strategic Control Chapter 13
Quality Management System SEETHARAM- Quality Assurance
Balanced Scorecard MBA © Rajiv D. Banker Do not reproduce without permission MBA.
Security Controls – What Works
Strategy, Balanced Scorecard, and Strategic Profitability Analysis
Strategy, Balanced Scorecard, and Strategic Profitability Analysis
Budgeting.
Business Performance Management (BPM)
Pittsburgh, PA Software Engineering Institute Carnegie Mellon University Pittsburgh, PA Sponsored by the U.S. Department of Defense.
Balanced Scorecard as a Performance Management Tool
Information Security Governance and Risk Chapter 2 Part 1 Pages 21 to 69.
THE BALANCED SCORECARD
Total Quality, Competitive Advantage, and Strategic Management
Balanced Scorecard Analysis Justin Haffey Caroline Myers Kelly Vacari.
Strategic Management BALANCED SCORECARD.
P e r f o r m a n c e Measuring Results of Organizational Performance Lesson 4 Performance Methodology: The Balanced Scorecard.
Strategy Maps Chapter One: Introduction
Based on Chapter 13, Cost Accounting, 12th ed. Horngren et al., Edited and Modified by C. Bailey 1.
Objective Explain What is the Balanced Scorecard
Managing Quality and Performance
ISO 9001 Auditing Practices Group
Consultancy.
KNOWLEDGE MANAGEMENT B S C [ Balanced Scorecard ] PROJECT 1 POWER POINT MATERIALS FOR BASIC CONCEPT Group #2 KANG A IN YOON JONG HUN YOON HYE RIM CHA MYUENG.
Prepared by: Rasha El Hagrassy Creating Cause-and-Effect Linkages 1. Develop objectives and measures for each of the four perspectives.  The business.
1 Module 4: Designing Performance Indicators for Environmental Compliance and Enforcement Programs.
EIN 5322 Engineering Management
The Adapted Balanced Scorecard. Kaplan’s Adaptation of the Balanced Scorecard Framework to Nonprofit Organizations Financial Perspective If we succeed,
Hossein Moradi IT Expert.ir December 2008.
TRANSFORMING CAPABILITY SUPPORT MATERIALS LEADING VISION CREATION Balanced Scorecard Introduction The balanced scorecard can be used for translating a.
Overview of the Balanced Scorecard Concept IDM 404 Spring 2014 Dr. Joan Burtner Associate Professor, Department of Industrial Engineering and Industrial.
M A N A G E M E N T M A N A G E M E N T 1 st E D I T I O N 1 st E D I T I O N Gulati | Mayo | Nohria Gulati | Mayo | Nohria Chapter 10 Chapter 10 PERFORMANCE.
Development of Evaluation Tool (KPI) for e-Gov Development Veselin Stoyanov Management consultant, ICB 11 Mar 20111BG-KR eGov Experts Workshop:
CSI - Introduction General Understanding. What is ITSM and what is its Value? ITSM is a set of specialized organizational capabilities for providing value.
Balanced Scorecard Introduction. What is the Balanced Scorecard? The balanced scorecard is a management system (not only a measurement system) that enables.
December 10, 2007 Denise Shields Shields Resource Group H&HS Performance Measurements Evaluating and Aligning Existing Metrics.
AFM The Balanced Scorecard By Isuru Manawadu B.Sc in Accounting Sp. (USJP), ACA.
Healthcare Process Improvement: Overview of The Balanced Scorecard ISE 468 ETM 568 Spring 2013 Dr. Joan Burtner Associate Professor, Department of Industrial.
The Balanced Score Card
“Look, who is the most successful in attracting and holding good people? The nonprofits. The satisfaction has to be greater than in business because there.
The Balanced Scorecard
Information, Analysis, and Knowledge Management in the Baldrige Criteria Examines how an organization selects, gathers, analyzes, manages, and improves.
Design, Development and Roll Out
Aligning Organizational Goals and Operations Strategy Oct , 2002.
The Second Annual Medical Device Regulatory, Reimbursement and Compliance Congress Presented by J. Glenn George Thursday, March 29, 2007 Day II – Track.
Balance Score Card. Balance score card The balanced scorecard is a strategic planning and management system that is used extensively in.
Balanced Scorecard in Business Practice Phasit K. 26 April 2002.
North Delhi Power Limited Balanced Scorecard (BSC) NITIN ROHILLA Head (IT-SAP) NORTH DELHI POWER LIMITED Balanced Scorecard (BSC) by NITIN ROHILLA Head.
Balanced Scorecard The University of Texas at El Paso Division of the Vice President for Business Affairs.
ERM and Information Risks July 2013 Advisory. 1 © KPMG, a partnership established under Ghanaian law and a member firm of the KPMG network of independent.
1 Balanced Scorecard Philosophy, Basics, Fundamentals, and Functions.
Strategy Evaluation and Control
The Adapted Balanced Scorecard. Kaplan’s Adaptation of the Balanced Scorecard Framework to Nonprofit Organizations Financial Perspective If we succeed,
BALANCED SCORECARD ANALYSIS. What Is a Balanced Scorecard? A Measurement System? A Management System? A Management Philosophy?
Human Resource Management 1 Performance Management Process.
Dr. Yeffry Handoko Putra, M.T
The Balanced Scorecard
Prof. Dr. Dan Dumitru Popescu
Faculty of Engineering at Shoubra Associate Prof. Hanan Eltobgy
Learn Your Information Security Management System
Lecture 11: BALANCE SCORE CARD
Contents A GENERIC IT BALANCED SCORECARD
Overview of the Balanced Scorecard Concept
Performance Measurement
The Balanced Scorecard
ISO 9001 Auditing Practices Group
ISO 9001 Auditing Practices Group
KEC Dhapakhel Lalitpur
ISO 9001 Auditing Practices Group
Presentation transcript:

Security Policy Evaluation Using Balanced Scorecards Mohamad El Osta MBA 737 April 29, 2008

Agenda Performance Evaluation Methodology Limitation Balanced Scorecards Perspectives and Methodology Security Metrics Conclusion

Performance Evaluation Managers and chief executives have to be proactive in tracking the operation of their business Organizations used to track their performance by relying solely on financial metrics like: Increase of revenue Increase of profit margin Return on assets (ROA) and investments (ROI)

Limitations Vital dimensions of the business can go unnoticed by time if financial metrics alone were used. Customers might be unsatisfied with the product and are waiting for the competition to switch products. Employees ’ emotions due to dissatisfaction might be running high, until “ crunch point ” suddenly arise.

Definition Balanced Scorecard (BSC) : “ is a strategic planning and management system that is used to align business activities to the vision and strategy of the organization, improve internal and external communications, and monitor organization performance against strategic goals.” 1 As defined by the Balanced Scorecard Institute /27/2008

History The “ Balanced Scorecard ” term was coined in 1992 by two authors: Robert S. Kaplan – Professor at Harvard Business School David P. Norton Harvard Business Review article titled: “ The Balanced Scorecard: Measures that Drive Performance.” Performance measurement reporting existed before since the 50s at General Electric.

Facts By 2006, 70% of organizations at least implemented partially a BSC. Private sector, public sector and non-profit organizations have successfully implemented BSC. French process engineers created “ Tableau de Bord ” – dashboard – for measuring performance in the early 1900s.

BSC Perspectives BSC translates the business strategy into four perspectives: 1.Customer 2.Financial 3.Business Processes 4.Learning and Growth Goal is to achieve a balance in the following: 1.Between internal and external measures 2.Between objective and subjective measures 3.Between performance and drivers of results

Diagram of the BSC

Comprehensive Measures PerspectiveMeasures Customer Customer satisfaction, retention, market share Financial Income, return on asset (ROA). Business Process Cost, throughput, quality. Learning and Growth Employee satisfaction, retention, skill sets.

Planning Areas There are four areas of planning for each perspective: 1.Objectives: The set of results that are needed by the business to sustain its vision based on its strategy. 2.Measures: Are the observable key performance indicators (KPI) that measures the progress of each objective.

Planning Areas 3.Targets: Are the set values of measures that the business wants to achieve by the objectives. 4.Initiatives: A set of action items for each objective created as a plan of how to reach the objective.

BSC Template

Source:

Implementation Process Implementing BSC is done through 4 steps: 1.Translation of Vision: Create strategic objectives from the vision. Setup quantifiable metrics to measure objectives. 2.Communicating Objectives: Create SMART goals from the strategic objectives. Communicate these goals through out the organization.

Implementation Process 3.Setting Targets and Aligning Initiatives: Create achievable targets for each perspective. Align initiatives to achieve specified targets. 4.Learning and Feedback: Get feedback on setup initiatives through metrics. Learn continuously from success/failure of strategy.

Benefits of BSC Enhance organizational focus on results and strategy. Improve business performance by tracking a comprehensive set of KPIs. Align the organizational strategy with the projects and work employees do. Concentrate on the drivers of future performance. Enhance the communication of vision and strategy throughout the organization. Prioritize the business projects based on the strategy.

Information Security Information Security (IS): “is protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction” 1 “The truth is that security is as much an issue of people and process as it is technology.” 2 Tracking the performance and compliance of a security policy is as important as having one! /27/2008

IS Components Information Security has 3 components – commonly known as the “ CIA triad ” : 1.Confidentiality : means that data can only be accessed by authorized personnel. 2.Integrity : means that data can not be created, changed, or deleted without authorization. 3.Availability : means that information and their systems are available and correctly functioning when needed.

IS Triad Diagram

IS and BSC BSC have been used in every function of the business. Recently organizations started to use BSC to manage the implementation of their security policy. ISO is a standard of security controls that can be implemented and monitored through the use of BSC.

Security Metrics Security Metric : “ For an entity (system, product, facility, asset or other) for which security is a meaningful concept, there are identifiable attributes that collectively characterize the security of that entity. A security metric, or combination of metrics, is a quantitative measure of much of that attribute the entity possesses. ” 1 1

Example Metrics Some example of security metrics used in the industry: 1.Intrusion attempts 2.Invalid logins 3.Admin violations 4.Spam detected 5.Viruses detected 6.Unauthorized access attempt 7.…

Proposed BSC for Security Dr. Lori L. DeLooze has created a BSC for computer security. 1 She has proposed this scorecard based on 4 perspectives: 1.Users 2.System Administrators 3.System Owners 4.Auditors 1

Security BSC Diagram* *

Security Strategy Vision: to have a secure information system that provides the “ CIA triad. ” Strategy has 2 components: 1.Provide cost-efficient security service 2.Reduce risk and damage from attacks Each perspective will be analyzed and evaluated based on those 2 strategic criteria.

Security BSC for S1 ObjectiveMeasureTarget Users Provide secure communications. % of users with access to service. 100% Owners Cost-effective security system. Return on investment (ROI) 200% Administrators Ensuring system up and running. System availability.99.9% Auditors Reporting on current system. % of identified vulnerable systems. 100%

Security BSC for S2 ObjectiveMeasureTarget Users Trained on security principles. % of users with certification. 100% Owners Monitoring and control of systems. % of reviewed audit logs. 80% Administrators Certified with latest practices. % of SA certified.100% Auditors Compliance with standard. % of systems complied 100%

Q&A