{"id":19916,"date":"2019-02-22T15:58:13","date_gmt":"2019-02-22T20:58:13","guid":{"rendered":"http:\/\/www.bu.edu\/csmet\/?p=19916"},"modified":"2019-02-22T15:58:13","modified_gmt":"2019-02-22T20:58:13","slug":"joseph-burgoyne","status":"publish","type":"post","link":"https:\/\/www.bu.edu\/csmet\/2019\/02\/22\/joseph-burgoyne\/","title":{"rendered":"Joseph Burgoyne"},"content":{"rendered":"<p><strong><img loading=\"lazy\" src=\"\/csmet\/files\/2019\/02\/Joe-Burgoyne-240x300.jpg\" alt=\"\" class=\"alignleft size-medium wp-image-19917\" width=\"240\" height=\"300\" srcset=\"https:\/\/www.bu.edu\/csmet\/files\/2019\/02\/Joe-Burgoyne-240x300.jpg 240w, https:\/\/www.bu.edu\/csmet\/files\/2019\/02\/Joe-Burgoyne-768x960.jpg 768w, https:\/\/www.bu.edu\/csmet\/files\/2019\/02\/Joe-Burgoyne-819x1024.jpg 819w\" sizes=\"(max-width: 240px) 100vw, 240px\" \/>Joseph Burgoyne: Think Like a \u201cMalicious Actor\u201d When Assessing Security Risks<\/strong><\/p>\n<p><strong>Lecturer in Computer Science<br \/>\nSenior Director, Cyber Security at GE Healthcare<br \/>\n<\/strong><em>MBA, Southern New Hampshire University; BS, University of Massachusetts Lowell<\/em><br \/>\n<strong><br \/>\nWhat are your areas of expertise?<br \/>\n<\/strong>My areas of expertise include medical device cybersecurity, information security, risk management, data privacy, HIPAA, security architecture, audit and compliance (ECC, C-TPAT, ITAR, PCI), physical security, vulnerability and patch management, eDiscovery, litigation support, mergers and acquisitions, training, project management, and investigations.<strong><\/strong><\/p>\n<p>How does the subject you work in apply in practice? What is its application?<br \/>\nThe application of security is risk-based. We cannot eliminate risk, so we try to reduce it to an acceptable level in a cost-effective way. Every organization has a different risk tolerance. Our job is to manage risks across our organization. Security is not a technology, it\u2019s a process that\u2019s ongoing and needed to meet the changing cyber-threat landscape.<strong><\/strong><\/p>\n<p>Having a security leadership role requires a broad understanding of the business, stakeholders, and overall risk tolerance of the organization. Implementing the appropriate security policies and controls is necessary to protect the confidentiality, integrity, and availability of information.<strong><\/strong><\/p>\n<p>Even password policies require careful thought. For example, many organizations require password complexity with at least eight characters, and restrict the use of previous passwords. Password complexity includes at least three of the following four requirements: upper case letter, lower case letter, number, or special character. Passwords are typically set to expire every 90 days. These are all configurable settings within each organization.<strong><br \/>\n<\/strong><br \/>\nIf we configure more stringent rules, such as requiring employees to change their passwords every 30 days, are we more or less secure? In the password example, if frequent changes to complex passwords are difficult to remember, employees may start writing their passwords down on a piece of paper which defeats the entire purpose and is less secure. I have found the more difficult you make something for employees, the more likely they will find a way around it. Security shouldn\u2019t make things difficult. When evaluating controls, we need to understand the use cases and applications. If a sales person is making a 30-minute on-site customer presentation, we don\u2019t want them to spend half that time trying to get authenticated on their laptop\u2014we want them talking with customers and making sales.<strong><\/strong><\/p>\n<p>What courses do you teach in the program?<br \/>\nI am teaching <span><a href=\"https:\/\/www.bu.edu\/link\/bin\/uiscgi_studentlink.pl\/1536159289?ModuleName=course_desc\/start.pl&amp;CourseKey=MET%20CS%20684&amp;KeySem=20193&amp;BldgCd=CAS&amp;ClassCd=METCS684%20D1&amp;TopicCd=\">IT Security Policies and Procedures (MET CS 684)<\/a><\/span>. We look at security risks and learn to implement plans and solutions that support organizational goals.<strong><\/strong><\/p>\n<p>Can you highlight a particular project within this course that most interests your students?<br \/>\nIt\u2019s important to be able to think like a \u201cmalicious actor\u201d when you look for weaknesses in systems. In doing so, we can remediate those weaknesses and protect our assets. Within the course we look at security not only from the inside, but also from an outside attacker\u2019s perspective. When we talk about ways an attacker can compromise a system, it\u2019s interesting to watch the reactions in class. Part of being successful in security requires us to think about how systems and solutions can be compromised. When we know how they can be compromised, we can apply fixes and protect our systems.<br \/>\n<strong><br \/>\nWhat \u201creal-life\u201d exercises do you bring to classes?<br \/>\n<\/strong>At the beginning of each class we discuss current security events making the news. It\u2019s important to be objective and fact-based when trying to determine root cause. As security professionals we can\u2019t let our personal feelings influence our thought process and analysis. We review and examine current events to determine what went wrong and, if given the opportunity to do it again the \u201cright way,\u201d what would we do differently?<strong><\/strong><\/p>\n<p>I also talk about real-life scenarios and past experiences when appropriate, so the class understands the kind of situations we deal with daily. This helps supplement the class material and makes the topics more realistic. Security is never boring.<\/p>\n<p><strong>As a part-time faculty member, you straddle the professional and the academic worlds. What do you consider the unique value this brings to the classroom?<\/strong><strong><br \/>\n<\/strong>My career has been built upon supporting business strategy and implementing value-added initiatives that support the organization\u2019s long-term goals and objectives.<strong><\/strong><\/p>\n<p>Security isn\u2019t theoretical; we need to provide and deliver tangible solutions that lower risk and support business objectives. When asked questions, we offer answers and solutions. Security must be an enabler within our organizations, and in close collaboration with key business stakeholders.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Joseph Burgoyne: Think Like a \u201cMalicious Actor\u201d When Assessing Security Risks Lecturer in Computer Science Senior Director, Cyber Security at GE Healthcare MBA, Southern New Hampshire University; BS, University of Massachusetts Lowell What are your areas of expertise? My areas of expertise include medical device cybersecurity, information security, risk management, data privacy, HIPAA, security architecture, [&hellip;]<\/p>\n","protected":false},"author":2828,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[10838,10828],"tags":[],"_links":{"self":[{"href":"https:\/\/www.bu.edu\/csmet\/wp-json\/wp\/v2\/posts\/19916"}],"collection":[{"href":"https:\/\/www.bu.edu\/csmet\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bu.edu\/csmet\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/csmet\/wp-json\/wp\/v2\/users\/2828"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/csmet\/wp-json\/wp\/v2\/comments?post=19916"}],"version-history":[{"count":1,"href":"https:\/\/www.bu.edu\/csmet\/wp-json\/wp\/v2\/posts\/19916\/revisions"}],"predecessor-version":[{"id":19918,"href":"https:\/\/www.bu.edu\/csmet\/wp-json\/wp\/v2\/posts\/19916\/revisions\/19918"}],"wp:attachment":[{"href":"https:\/\/www.bu.edu\/csmet\/wp-json\/wp\/v2\/media?parent=19916"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bu.edu\/csmet\/wp-json\/wp\/v2\/categories?post=19916"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bu.edu\/csmet\/wp-json\/wp\/v2\/tags?post=19916"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}