AUGUST - 2019ENTERPRISE SECURITY| | 19ENTERPRISE SECURITY:WHAT DOES IT REALLY MEAN?hether you're at a cybersecurity conference, participating in a webinar, or reading an article like this one, you are often bombarded with these catchy sayings regarding enterprise security: "It's a team sport"; "It's about tech, people, and process"; or "It's not a tech issue, but a business issue." Then you are told that you need a compliant information security program, along with an incident response plan, that is certifiable to any one of the NIST, COBIT, ISO, or other popular frameworks, so you can avoid the wrath of the regulators. Okay, all true, but what does that really mean?To help clear things up, let's look at what the National Institute of Standards and Technology (NIST) has to say. According to NIST, an information security program is a "formal document that provides an overview of the security requirements for an organization-wide information security program and describes the program management controls and common controls in place or planned for meeting those requirements." NIST also recommends that you implement an incident response plan--"a predetermined set of instructions or procedures to detect, respond to, and limit consequences of a malicious cyber-attack against an organization's information systems." The NIST then points out in its framework for improving critical infrastructure cybersecurity that there's no one-size-fits-all approach to managing cybersecurity risk. Wait. What? Again, all true, but what does that really mean?To best help you get a sense of what an enterprise security program really is and provide you with some key takeaways in developing and implementing one, I've pulled in the experts to provide you with their thoughts. Here's what they had to say: Kevin J. Burns, Chief Information Security Officer, Draper Labs:The highest priority for any enterprise security program is that it aligns to the short and long-term business goals. It is immeasurably valuable to routinely (via an enterprise security board) include input from the business managers and line staff into security program technologies and processes. The enterprise security board truly drives adoption and ensures adherence to policies company-wide in so far as within the board, users, senior leadership, and decision makers are present and their input adopted, and then presented to the Board of Directors. The program should be built upon a hybrid model of bottom up, bi-directional in the middle, and most importantly top down adoption. These collaborations are a major shift from the siloes that previously existed and necessitate a change in attitude. Only when all within the business have bought into the program does it become successful.Etay Maor, Executive Security Advisor, IBM Security:Your enterprise security program should not be a "check mark" on the auditors' page. That approach trickles down and is manifested in the operational and tactical levels resulting in the minimum necessary investment in cybersecurity policies, procedures, tools, and training. For an effective enterprise By Kevin Powers, Founding Director, Boston CollegeWCXO INSIGHTS
<
Page 9 |
Page 11 >