Taking AIM at “Reasonable” Cybersecurity
Gouvernance - Administrateurs & Dirigeants - Corporate Governance - Directors & Officers
25/09/2018
A good rule of thumb to ensure reasonable cybersecurity is to take AIM: Align, Implement and Measure.
Align. Whether it’s the NIST Frame-work, the CIS Top 20, ISO, or any other standard, it is advisable to pick one. There may not be correct answers for cybersecurity, but aligning against industry standards helps organizations ensure they considered the right questions.
Implement. Having policies and assessing risk are necessary steps, but they are not sufficient. Organizations must then implement appropriate physical, administrative and technical controls to mitigate the highest ranked business and victim-centric risks, and should consider creating risk registers to accept, track and manage remaining material risks.
Measure. In addition to conducting periodic penetration tests and vulnerability assessments, organizations should monitor for emerging threats and perform routine program audits. If the cybersecurity program isn’t measured, does it reasonably exist?
Commentaires0
Vous n'avez pas les droits pour lire ou ajouter un commentaire.
Articles suggérés