Rob Ashcraft
Chief Information Security Officer
- Role
- Chief Information Security Officer at Keystone Solutions
- Location
- Cleveland, TN, US
- LinkedIn followers
- 500 followers
About Rob Ashcraft
Cybersecurity Management and Strategist20+years Cybersecurity and Risk Management Experience, 6-years Cybersecurity and Compliance Assessments and GRC experience, 10-years management experience. I am proficient with NIST CSF, SOC 2, CIS CSC18, HIPAA law, PCI-DSS, GDPR, DFARS NIST 800-171 and GLBA frameworks and regulatory requirements. Experienced in writing system security plans (SSP), IT Security Policy / WISP / CIRP / BCDRP development and review, IRP and BCDRP TTX, conducting risk assessments, IT security audits and business impact analysis (BIA), risk register management, developing and maintaining security KPIs and metrics, data privacy impact analysis (DPIA), threat modeling, AI security, penetration test and NVA analysis, providing and managing vCISO services.
Experience
Chief Information Security Officer
Nov 2022 — Present · Cleveland, TN, US
Managing practitioner of the Cybersecurity, vCISO and GRC services at KeyStone Solutions. Initially tasked with development of the Cybersecurity Department, and now managing the department\'s internal and external services. My primary duties include; understanding my company\'s, and our customer\'s, unique operational, security, and compliance needs, developing sound security strategies that align with those needs, conducting risk and compliance assessments, development and review of IT Security Policy, WISP, CIRP, BCDRP. Conducting IRP and BCDRP review/testing/training, business impact analysis (BIA), threat management assessments, data management reviews (DMR), account access reviews (AAR), IT security audits, monitoring KPIs and metrics, data privacy impact analysis (DPIA), fraud management assessments, physical security reviews, threat modeling exercises, pen test / NVA report analysis, risk register management, creating and tracking remediation strategies, department budgeting, and establishing workable RTOs and RPOs.Experienced in the following frameworks, compliance standards and regulatory requirements:CIS CSC18, NIST CSF, ISO 27001 & 27002, NIST 800-53, NIST 800-171, IRS Security Six, CMMC 2.0, AICPA Cyber Guidelines, SOC 2 & SOC 3, DFARS, NIST RMF, PCI-DSS, HIPAA CE & BA, GLBA, FTC Privacy Rule, GDPR, UK DPA, DPF (EU-US, Swiss-US), SEC Disclosure Rules, PIPEDA and US State Privacy Laws.
Education
Illinois Wesleyan University
Computer Science
Indiana Christian University
Counseling
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.