Leading the IT transformation at NHIC to implement the information security strategy and model for Cyber Security defense, governance, Risk and Compliance:
Governance:
Strategy:
Build and define the cybersecurity strategy (vision, current/desired state, objectives, GAP analysis, initiatives, roadmap and budget)
Policies and procedures
Documented, communicated and compiled cybersecurity requirements
Departments involved (IT, HR, Legal, Purchasing and Auditing)
Create a workshop and raise the awareness of the policies and procedures
Create the standard so that all parties involved would know what exactly to do
Roles and responsibilities
Define roles and responsibilities for all parties participating in implementing the cybersecurity controls..
Parties are all employee, IT, HR, Legal, Purchasing, auditing and services and CEO.
Risk management
Managing cybersecurity risks in a methodological approach in order to protect the organization’s information and technology assets.
Define, document and approve Cybersecurity risk management methodology and procedures as per confidentiality, integrity and availability considerations of information and technology assets.
Implement cybersecurity risk management methodology and procedures by the cybersecurity function.
Technology and Project Management:
protect the confidentiality, integrity and availability of information and technology assets.
Compliance with cyber security standard, laws and regulations:
Comply the organization’s cybersecurity program with related laws and regulation.
Comply with National Cybersecurity Authority, and with related national laws and regulation
Comply with any regulation nationally-approved international agreements and commitments.
Periodical review and audit
Run by independent parties outside the cybersecurity function (e.g., Internal Audit function) to assess the compliance with the cybersecurity controls.
Ensure this does not result in a conflict of interest, as per the Generally Accepted Auditing Standards (GAAS).
Human Resources in Cyber Security:
Manage cybersecurity risks and requirements related to personnel (employees and contractors) efficiently.
Awareness and training program
Raise the awareness of personnel of their cybersecurity responsibilities and have the essential cybersecurity awareness. Also, ensure personnel are provided with the required cybersecurity training, skills and credentials needed to accomplish their cybersecurity
Security Operations Center (SOC) - Security Defense:
Security Defence, including all Security Operations Center (SOC) - Asset Management, IAM Identity and Access Management, Email protection, Network Security Management, Mobile device security and BYOD, Cryptography
Penetration Test, Vulnerability Assessment, Next Generation Firewall, Backup and Recovery Management and SIEM..
DevOps and DevSecOps
Plan and maintain Development Security Operations followings DevOps model
Define security architectures and patterns.
Design development processes combining flexibility and security.
Implement and automate Cloud security solutions and services.
Automate security: penetration tests and audits, and finally train teams and create DevSecOps communities within organizations.
- مجال الشركة:
- خدمات الرعاية الصحية الأخرى
- الدور الوظيفي:
-
تكنولوجيا المعلومات