SlideShare ist ein Scribd-Unternehmen logo
1 von 19
#RSAC
SESSION ID:
Kevin McLaughlin Kody McLaughlin
Gamification of your Global
Information Security Operations
Center
HUM-R03
SOC Team Lead
Morphick
@InfoMoogle
Global Information Security Leader
Whirlpool
@mclaugkl
#RSAC
What is Gamification?
2
 Using game mechanics and rewards in a non-game setting to
increase engagement and drive desired behaviors
#RSAC
What Does it Take?
 Understanding of Gamification Methodology
 The Strategy
 Resource Time
 Budget
 Buy In
3
#RSAC
ISST Aces
4
Doug “Shiny” W.
Ben “Goose” O.
Kevin “Keystone” M.
Philip “Badger” B.
#RSAC
Benefits to an ISOC
 Speed up the analysis process
 Encourage knowledge sharing
 Accelerate the adoption of new technologies
 Improve training and education programs
 Raise morale
 Make it fun!
5
#RSAC
Goals of the Gamification Program
Goals
Define desirable behaviors
Encourage the performance of those behaviors
Measure that performance
Reward excellence
6
#RSAC
2014 Malware on Workstations Remediation
7
#RSAC
Desired Behaviors
 Quick initial response to a case
 Quick resolution of a case
 Accurate resolution of a case
 Quality documentation of a case
 Continued growth and learning of team
8
#RSAC
The Game Shall NOT:
 Be tied to a bonus or promotion in any way
 Be subject to performance reviews
 Add stress or pressure
9
#RSAC
The Game Shall
 Allow players to be creative
 Allow players to set their own pace
 Offer rewards that represent an achieved status
 Motivate growth and mastery
 Be designed specifically for your unique culture
 Have clearly defined progression and rewards
 Be fun!
10
#RSAC
How to be Creative
 Player personal identity
 Self expression
 Autonomy
11
Awesome ninja avatar
Awesome ninja name
Awesome ninja color
#RSAC
Zero Day Malware Wanted Posters
12
#RSAC
Reward Positive Behavior
 Titles
 Badges
 Knick-knacks
 Challenge Coin
 Plaque
 Levels
 Privilege
13
The sheriff of incident response
#RSAC
Motivate Growth and Mastery
14
Frequent
victories
Relevance
Reputation Recognition
#RSAC
Progression and Rewards
15
#RSAC
Game Types
16
Cooperative
Competitive Blended
Solo
#RSAC
Game Mechanics
Points Leaderboards Achievements Missions Contests Levels
17
#RSAC
Apply Slide
 Next week you should:
 Define business goals
 Define the behaviors that will meet those goals
 In the first three months following this presentation you should:
 Select your game type and mechanic
 Select your prizes
 Deploy
 Within six months you should:
 Evaluate program effectiveness
 Tweak and redesign as necessary
18
#RSAC
Thank You
Don’t Forget Your Coin
19

Weitere ähnliche Inhalte

Andere mochten auch

AlienVault MSSP Overview - A Different Approach to Security for MSSP's
AlienVault MSSP Overview - A Different Approach to Security for MSSP'sAlienVault MSSP Overview - A Different Approach to Security for MSSP's
AlienVault MSSP Overview - A Different Approach to Security for MSSP'sAlienVault
 
#ALSummit: Accenture - Making the Move: Enabling Security in the Cloud
#ALSummit: Accenture -  Making the Move: Enabling Security in the Cloud#ALSummit: Accenture -  Making the Move: Enabling Security in the Cloud
#ALSummit: Accenture - Making the Move: Enabling Security in the CloudAlert Logic
 
Tapping into the Growth Goldmine: Why MSPs Should Join Peer Groups
Tapping into the Growth Goldmine: Why MSPs Should Join Peer GroupsTapping into the Growth Goldmine: Why MSPs Should Join Peer Groups
Tapping into the Growth Goldmine: Why MSPs Should Join Peer GroupseFolder
 
Integrated Security Operations Center (ISOC) for Cybersecurity Collaboration
Integrated Security Operations Center (ISOC) for Cybersecurity CollaborationIntegrated Security Operations Center (ISOC) for Cybersecurity Collaboration
Integrated Security Operations Center (ISOC) for Cybersecurity CollaborationPriyanka Aash
 
Key Ingredients for Your MSSP Offering
Key Ingredients for Your MSSP OfferingKey Ingredients for Your MSSP Offering
Key Ingredients for Your MSSP OfferingeFolder
 
Trustwave Cybersecurity Education Catalog
Trustwave Cybersecurity Education CatalogTrustwave Cybersecurity Education Catalog
Trustwave Cybersecurity Education CatalogTrustwave
 
Building a Cyber Security Operations Center for SCADA/ICS Environments
Building a Cyber Security Operations Center for SCADA/ICS EnvironmentsBuilding a Cyber Security Operations Center for SCADA/ICS Environments
Building a Cyber Security Operations Center for SCADA/ICS EnvironmentsShah Sheikh
 
Cognitive Security - Anatomy of Advanced Persistent Threats ('12)
Cognitive Security - Anatomy of Advanced Persistent Threats ('12)Cognitive Security - Anatomy of Advanced Persistent Threats ('12)
Cognitive Security - Anatomy of Advanced Persistent Threats ('12)Gabriel Dusil
 

Andere mochten auch (8)

AlienVault MSSP Overview - A Different Approach to Security for MSSP's
AlienVault MSSP Overview - A Different Approach to Security for MSSP'sAlienVault MSSP Overview - A Different Approach to Security for MSSP's
AlienVault MSSP Overview - A Different Approach to Security for MSSP's
 
#ALSummit: Accenture - Making the Move: Enabling Security in the Cloud
#ALSummit: Accenture -  Making the Move: Enabling Security in the Cloud#ALSummit: Accenture -  Making the Move: Enabling Security in the Cloud
#ALSummit: Accenture - Making the Move: Enabling Security in the Cloud
 
Tapping into the Growth Goldmine: Why MSPs Should Join Peer Groups
Tapping into the Growth Goldmine: Why MSPs Should Join Peer GroupsTapping into the Growth Goldmine: Why MSPs Should Join Peer Groups
Tapping into the Growth Goldmine: Why MSPs Should Join Peer Groups
 
Integrated Security Operations Center (ISOC) for Cybersecurity Collaboration
Integrated Security Operations Center (ISOC) for Cybersecurity CollaborationIntegrated Security Operations Center (ISOC) for Cybersecurity Collaboration
Integrated Security Operations Center (ISOC) for Cybersecurity Collaboration
 
Key Ingredients for Your MSSP Offering
Key Ingredients for Your MSSP OfferingKey Ingredients for Your MSSP Offering
Key Ingredients for Your MSSP Offering
 
Trustwave Cybersecurity Education Catalog
Trustwave Cybersecurity Education CatalogTrustwave Cybersecurity Education Catalog
Trustwave Cybersecurity Education Catalog
 
Building a Cyber Security Operations Center for SCADA/ICS Environments
Building a Cyber Security Operations Center for SCADA/ICS EnvironmentsBuilding a Cyber Security Operations Center for SCADA/ICS Environments
Building a Cyber Security Operations Center for SCADA/ICS Environments
 
Cognitive Security - Anatomy of Advanced Persistent Threats ('12)
Cognitive Security - Anatomy of Advanced Persistent Threats ('12)Cognitive Security - Anatomy of Advanced Persistent Threats ('12)
Cognitive Security - Anatomy of Advanced Persistent Threats ('12)
 

Ähnlich wie Gamification of your Global Information Security Operations Center - RSA 2015

The five secrets of high performing cisos
The five secrets of high performing cisosThe five secrets of high performing cisos
The five secrets of high performing cisosPriyanka Aash
 
Threat Intelligence Is Like Three Day Potty Training
Threat Intelligence Is Like Three Day Potty TrainingThreat Intelligence Is Like Three Day Potty Training
Threat Intelligence Is Like Three Day Potty TrainingPriyanka Aash
 
Gamification and Game Mechanics
Gamification and Game MechanicsGamification and Game Mechanics
Gamification and Game MechanicsJuliette Denny
 
Culture Hacker: How to Herd CATTs and Inspire Rebels to Change the World! - S...
Culture Hacker: How to Herd CATTs and Inspire Rebels to Change the World! - S...Culture Hacker: How to Herd CATTs and Inspire Rebels to Change the World! - S...
Culture Hacker: How to Herd CATTs and Inspire Rebels to Change the World! - S...SeniorStoryteller
 
Gamifying Agile project
Gamifying Agile project Gamifying Agile project
Gamifying Agile project Chandan Patary
 
Intro to gamification by tydus.it
Intro to gamification by tydus.itIntro to gamification by tydus.it
Intro to gamification by tydus.itVincent Richard
 
ChaoSlingr: Introducing Security-Based Chaos Testing
ChaoSlingr: Introducing Security-Based Chaos TestingChaoSlingr: Introducing Security-Based Chaos Testing
ChaoSlingr: Introducing Security-Based Chaos TestingPriyanka Aash
 
Keynote: The Bounty Conundrum: Incentives for Testing
Keynote: The Bounty Conundrum: Incentives for TestingKeynote: The Bounty Conundrum: Incentives for Testing
Keynote: The Bounty Conundrum: Incentives for TestingTechWell
 
Gamification Using “Science of Habit Cycle” to Transform User Behavior
Gamification Using “Science of Habit  Cycle” to Transform User BehaviorGamification Using “Science of Habit  Cycle” to Transform User Behavior
Gamification Using “Science of Habit Cycle” to Transform User BehaviorPriyanka Aash
 
How to transform developers into security people
How to transform developers into security peopleHow to transform developers into security people
How to transform developers into security peoplePriyanka Aash
 
Webinar - Find Your DNA: Keys to Building an Effective Competency Framework
Webinar - Find Your DNA: Keys to Building an Effective Competency FrameworkWebinar - Find Your DNA: Keys to Building an Effective Competency Framework
Webinar - Find Your DNA: Keys to Building an Effective Competency FrameworkTalentView
 
Reaching your true (email) potential
Reaching your true (email) potentialReaching your true (email) potential
Reaching your true (email) potentialAdestra
 
Fanatical By Design: How Rackspace Use Net Promoter to Build Customer Loyalty
Fanatical By Design: How Rackspace Use Net Promoter to Build Customer LoyaltyFanatical By Design: How Rackspace Use Net Promoter to Build Customer Loyalty
Fanatical By Design: How Rackspace Use Net Promoter to Build Customer LoyaltyDavid Mitzenmacher
 
What HR Practitioners Ought to Know About Employee Engagement Programs
What HR Practitioners Ought to Know About Employee Engagement ProgramsWhat HR Practitioners Ought to Know About Employee Engagement Programs
What HR Practitioners Ought to Know About Employee Engagement ProgramsHuman Capital Media
 
Sigmaflow Insights CMO
Sigmaflow Insights CMOSigmaflow Insights CMO
Sigmaflow Insights CMOservicecoach
 
How to interview and hire game changers webcast
How to interview and hire game changers webcastHow to interview and hire game changers webcast
How to interview and hire game changers webcastLinkedIn
 
Developing useful metrics
Developing useful metricsDeveloping useful metrics
Developing useful metricsPriyanka Aash
 
Gamification of Compliance Training
Gamification of Compliance TrainingGamification of Compliance Training
Gamification of Compliance TrainingInteractive Services
 

Ähnlich wie Gamification of your Global Information Security Operations Center - RSA 2015 (20)

The five secrets of high performing cisos
The five secrets of high performing cisosThe five secrets of high performing cisos
The five secrets of high performing cisos
 
Threat Intelligence Is Like Three Day Potty Training
Threat Intelligence Is Like Three Day Potty TrainingThreat Intelligence Is Like Three Day Potty Training
Threat Intelligence Is Like Three Day Potty Training
 
Gamification and Game Mechanics
Gamification and Game MechanicsGamification and Game Mechanics
Gamification and Game Mechanics
 
Culture Hacker: How to Herd CATTs and Inspire Rebels to Change the World! - S...
Culture Hacker: How to Herd CATTs and Inspire Rebels to Change the World! - S...Culture Hacker: How to Herd CATTs and Inspire Rebels to Change the World! - S...
Culture Hacker: How to Herd CATTs and Inspire Rebels to Change the World! - S...
 
Gamifying Agile project
Gamifying Agile project Gamifying Agile project
Gamifying Agile project
 
Skill Mapping
Skill MappingSkill Mapping
Skill Mapping
 
Introduction to Gamification
Introduction to GamificationIntroduction to Gamification
Introduction to Gamification
 
Intro to gamification by tydus.it
Intro to gamification by tydus.itIntro to gamification by tydus.it
Intro to gamification by tydus.it
 
ChaoSlingr: Introducing Security-Based Chaos Testing
ChaoSlingr: Introducing Security-Based Chaos TestingChaoSlingr: Introducing Security-Based Chaos Testing
ChaoSlingr: Introducing Security-Based Chaos Testing
 
Keynote: The Bounty Conundrum: Incentives for Testing
Keynote: The Bounty Conundrum: Incentives for TestingKeynote: The Bounty Conundrum: Incentives for Testing
Keynote: The Bounty Conundrum: Incentives for Testing
 
Gamification Using “Science of Habit Cycle” to Transform User Behavior
Gamification Using “Science of Habit  Cycle” to Transform User BehaviorGamification Using “Science of Habit  Cycle” to Transform User Behavior
Gamification Using “Science of Habit Cycle” to Transform User Behavior
 
How to transform developers into security people
How to transform developers into security peopleHow to transform developers into security people
How to transform developers into security people
 
Webinar - Find Your DNA: Keys to Building an Effective Competency Framework
Webinar - Find Your DNA: Keys to Building an Effective Competency FrameworkWebinar - Find Your DNA: Keys to Building an Effective Competency Framework
Webinar - Find Your DNA: Keys to Building an Effective Competency Framework
 
Reaching your true (email) potential
Reaching your true (email) potentialReaching your true (email) potential
Reaching your true (email) potential
 
Fanatical By Design: How Rackspace Use Net Promoter to Build Customer Loyalty
Fanatical By Design: How Rackspace Use Net Promoter to Build Customer LoyaltyFanatical By Design: How Rackspace Use Net Promoter to Build Customer Loyalty
Fanatical By Design: How Rackspace Use Net Promoter to Build Customer Loyalty
 
What HR Practitioners Ought to Know About Employee Engagement Programs
What HR Practitioners Ought to Know About Employee Engagement ProgramsWhat HR Practitioners Ought to Know About Employee Engagement Programs
What HR Practitioners Ought to Know About Employee Engagement Programs
 
Sigmaflow Insights CMO
Sigmaflow Insights CMOSigmaflow Insights CMO
Sigmaflow Insights CMO
 
How to interview and hire game changers webcast
How to interview and hire game changers webcastHow to interview and hire game changers webcast
How to interview and hire game changers webcast
 
Developing useful metrics
Developing useful metricsDeveloping useful metrics
Developing useful metrics
 
Gamification of Compliance Training
Gamification of Compliance TrainingGamification of Compliance Training
Gamification of Compliance Training
 

Kürzlich hochgeladen

The Psychology Of Motivation - Richard Brown
The Psychology Of Motivation - Richard BrownThe Psychology Of Motivation - Richard Brown
The Psychology Of Motivation - Richard BrownSandaliGurusinghe2
 
Safety T fire missions army field Artillery
Safety T fire missions army field ArtillerySafety T fire missions army field Artillery
Safety T fire missions army field ArtilleryKennethSwanberg
 
W.H.Bender Quote 62 - Always strive to be a Hospitality Service professional
W.H.Bender Quote 62 - Always strive to be a Hospitality Service professionalW.H.Bender Quote 62 - Always strive to be a Hospitality Service professional
W.H.Bender Quote 62 - Always strive to be a Hospitality Service professionalWilliam (Bill) H. Bender, FCSI
 
Dealing with Poor Performance - get the full picture from 3C Performance Mana...
Dealing with Poor Performance - get the full picture from 3C Performance Mana...Dealing with Poor Performance - get the full picture from 3C Performance Mana...
Dealing with Poor Performance - get the full picture from 3C Performance Mana...Hedda Bird
 
Beyond the Codes_Repositioning towards sustainable development
Beyond the Codes_Repositioning towards sustainable developmentBeyond the Codes_Repositioning towards sustainable development
Beyond the Codes_Repositioning towards sustainable developmentNimot Muili
 
Marketing Management 16th edition by Philip Kotler test bank.docx
Marketing Management 16th edition by Philip Kotler test bank.docxMarketing Management 16th edition by Philip Kotler test bank.docx
Marketing Management 16th edition by Philip Kotler test bank.docxssuserf63bd7
 
digital Human resource management presentation.pdf
digital Human resource management presentation.pdfdigital Human resource management presentation.pdf
digital Human resource management presentation.pdfArtiSrivastava23
 
Independent Escorts Vikaspuri / 9899900591 High Profile Escort Service in Delhi
Independent Escorts Vikaspuri  / 9899900591 High Profile Escort Service in DelhiIndependent Escorts Vikaspuri  / 9899900591 High Profile Escort Service in Delhi
Independent Escorts Vikaspuri / 9899900591 High Profile Escort Service in Delhiguptaswati8536
 
International Ocean Transportation p.pdf
International Ocean Transportation p.pdfInternational Ocean Transportation p.pdf
International Ocean Transportation p.pdfAlejandromexEspino
 
Leaders enhance communication by actively listening, providing constructive f...
Leaders enhance communication by actively listening, providing constructive f...Leaders enhance communication by actively listening, providing constructive f...
Leaders enhance communication by actively listening, providing constructive f...Ram V Chary
 
internship thesis pakistan aeronautical complex kamra
internship thesis pakistan aeronautical complex kamrainternship thesis pakistan aeronautical complex kamra
internship thesis pakistan aeronautical complex kamraAllTops
 
Reviewing and summarization of university ranking system to.pptx
Reviewing and summarization of university ranking system  to.pptxReviewing and summarization of university ranking system  to.pptx
Reviewing and summarization of university ranking system to.pptxAss.Prof. Dr. Mogeeb Mosleh
 
Agile Coaching Change Management Framework.pptx
Agile Coaching Change Management Framework.pptxAgile Coaching Change Management Framework.pptx
Agile Coaching Change Management Framework.pptxalinstan901
 
How Software Developers Destroy Business Value.pptx
How Software Developers Destroy Business Value.pptxHow Software Developers Destroy Business Value.pptx
How Software Developers Destroy Business Value.pptxAaron Stannard
 
Strategic Management, Vision Mission, Internal Analsysis
Strategic Management, Vision Mission, Internal AnalsysisStrategic Management, Vision Mission, Internal Analsysis
Strategic Management, Vision Mission, Internal Analsysistanmayarora45
 

Kürzlich hochgeladen (17)

The Psychology Of Motivation - Richard Brown
The Psychology Of Motivation - Richard BrownThe Psychology Of Motivation - Richard Brown
The Psychology Of Motivation - Richard Brown
 
Safety T fire missions army field Artillery
Safety T fire missions army field ArtillerySafety T fire missions army field Artillery
Safety T fire missions army field Artillery
 
W.H.Bender Quote 62 - Always strive to be a Hospitality Service professional
W.H.Bender Quote 62 - Always strive to be a Hospitality Service professionalW.H.Bender Quote 62 - Always strive to be a Hospitality Service professional
W.H.Bender Quote 62 - Always strive to be a Hospitality Service professional
 
Dealing with Poor Performance - get the full picture from 3C Performance Mana...
Dealing with Poor Performance - get the full picture from 3C Performance Mana...Dealing with Poor Performance - get the full picture from 3C Performance Mana...
Dealing with Poor Performance - get the full picture from 3C Performance Mana...
 
Beyond the Codes_Repositioning towards sustainable development
Beyond the Codes_Repositioning towards sustainable developmentBeyond the Codes_Repositioning towards sustainable development
Beyond the Codes_Repositioning towards sustainable development
 
Marketing Management 16th edition by Philip Kotler test bank.docx
Marketing Management 16th edition by Philip Kotler test bank.docxMarketing Management 16th edition by Philip Kotler test bank.docx
Marketing Management 16th edition by Philip Kotler test bank.docx
 
digital Human resource management presentation.pdf
digital Human resource management presentation.pdfdigital Human resource management presentation.pdf
digital Human resource management presentation.pdf
 
Independent Escorts Vikaspuri / 9899900591 High Profile Escort Service in Delhi
Independent Escorts Vikaspuri  / 9899900591 High Profile Escort Service in DelhiIndependent Escorts Vikaspuri  / 9899900591 High Profile Escort Service in Delhi
Independent Escorts Vikaspuri / 9899900591 High Profile Escort Service in Delhi
 
International Ocean Transportation p.pdf
International Ocean Transportation p.pdfInternational Ocean Transportation p.pdf
International Ocean Transportation p.pdf
 
Leaders enhance communication by actively listening, providing constructive f...
Leaders enhance communication by actively listening, providing constructive f...Leaders enhance communication by actively listening, providing constructive f...
Leaders enhance communication by actively listening, providing constructive f...
 
Abortion pills in Jeddah |• +966572737505 ] GET CYTOTEC
Abortion pills in Jeddah |• +966572737505 ] GET CYTOTECAbortion pills in Jeddah |• +966572737505 ] GET CYTOTEC
Abortion pills in Jeddah |• +966572737505 ] GET CYTOTEC
 
Intro_University_Ranking_Introduction.pptx
Intro_University_Ranking_Introduction.pptxIntro_University_Ranking_Introduction.pptx
Intro_University_Ranking_Introduction.pptx
 
internship thesis pakistan aeronautical complex kamra
internship thesis pakistan aeronautical complex kamrainternship thesis pakistan aeronautical complex kamra
internship thesis pakistan aeronautical complex kamra
 
Reviewing and summarization of university ranking system to.pptx
Reviewing and summarization of university ranking system  to.pptxReviewing and summarization of university ranking system  to.pptx
Reviewing and summarization of university ranking system to.pptx
 
Agile Coaching Change Management Framework.pptx
Agile Coaching Change Management Framework.pptxAgile Coaching Change Management Framework.pptx
Agile Coaching Change Management Framework.pptx
 
How Software Developers Destroy Business Value.pptx
How Software Developers Destroy Business Value.pptxHow Software Developers Destroy Business Value.pptx
How Software Developers Destroy Business Value.pptx
 
Strategic Management, Vision Mission, Internal Analsysis
Strategic Management, Vision Mission, Internal AnalsysisStrategic Management, Vision Mission, Internal Analsysis
Strategic Management, Vision Mission, Internal Analsysis
 

Gamification of your Global Information Security Operations Center - RSA 2015