SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsPolicies are only as good as the procedures used to implement them. When the procedures are too cumbersome or time-consuming, it is likely that policy compliance will suffer. Unrealistic procedures can lead to 'implemented policies' that are weaker than the stated policies. Conversely ensuring that procedures are easy to implement has the effect of making full policy compliance more likely. In this case study we will examine how automating information security audit procedures at a university had the effect of increasing security through increased policy compliance. We will discuss three stated policies their associated procedures and how poorly designed procedures led to weak 'implemented policies.' We will then discuss how the procedures were automated and finally discuss the effects of the automation on the university's overall security stance.
Clay holds a Bachelor’s and Master's in Computer Science from Southeastern OK State University, as well as a numerous certifications. The highlight of his career has been seeing his students graduate to jobs in software development and security.
Read more about Clay Risenhoover