-
Book Overview & Buying
-
Table Of Contents
Executive's Cybersecurity Program Handbook
By :
As you can tell from this chapter, determining the current and future state of your cybersecurity program takes time. Using a common standard such as the NIST CSF or the CIS controls is just one way of getting you there. Performing the risk assessment described in this chapter for your organization not only fulfills your requirement for understanding the risk landscape and the overall security posture but also helps determine where you would like to be. This phase of your tenure as the head of security does take a while, but you will get there – just have faith in the process.
When performing the assessment, make sure you are also scoring yourself accordingly. It can be easy to massage the answer to a question to make it look like you have adequate protections in place when, in fact, you may not. To move yourself up from tier 2 to tier 3, the process must be documented and signed off by an executive at the company.
Therefore, the next chapter will discuss how to...