Back to news

Taking AIM at “Reasonable” Cybersecurity

-

Gouvernance - Administrateurs & Dirigeants - Corporate Governance - Directors & Officers

09.25.2018

A good rule of thumb to ensure reasonable cybersecurity is to take AIM: Align, Implement and Measure.

 Align. Whether it’s the NIST Frame-work, the CIS Top 20, ISO, or any other standard, it is advisable to pick one. There may not be correct answers for cybersecurity, but aligning against industry standards helps organizations ensure they considered the right questions.

Implement. Having policies and assessing risk are necessary steps, but they are not sufficient. Organizations must then implement appropriate physical, administrative and technical controls to mitigate the highest ranked business and victim-centric risks, and should consider creating risk registers to accept, track and manage remaining material risks.

Measure. In addition to conducting periodic penetration tests and vulnerability assessments, organizations should monitor for emerging threats and perform routine program audits. If the cybersecurity program isn’t measured, does it reasonably exist?


https://www.securitymagazine.com/articles/89275-taking-aim-at-reasonable-cybersecurity?_lrsc=0bced36d-270c-4c1e-8355-5cdd3f9ce55f&trk=&utm_source=LinkedInElevate&utm_source=LinkedIn&utm_content=LinkedInElevate

Like
938 Views Visits
Share it on

comments0

Please log in to see or add a comment

Suggested Articles

Euronext lance une déclinaison responsable du CAC 40

profile photo of a member

Jean-François Phan Van Phi

March 30

UN AN APRÈS LA LOI PACTE, UNE VINGTAINE D'ENTREPRISES SONT DEVENUES DES SOCIÉTÉS À MISSION

profile photo of a member

Jean-François Phan Van Phi

March 18

La gouvernance, levier majeur de performance durable face à la crise - Appel

profile photo of a member

Jean-François Phan Van Phi

February 21