| | JUNE 2022ENTERPRISE SECURITY8One of the most common questions I answer is "How do I best secure my company from cyber attacks?" The seemingly-simply question does not have a simple answer, so I always begin with "It depends." Initially this answer can be disappointing because it dashes hopes of a cyber silver bullet, but as I explain further what "it depends" means, disappointment turns to understanding. Furthermore, understanding turns to urgency as I detail the area of cyber security that will have the most impact in securing their company: vulnerability management.Although other areas of cyber security should not be overlooked, vulnerability management has the most potential to lower risk. In other words, the best way for companies to prevent a cyber attacker from finding and exploiting vulnerabilities is to find their vulnerabilities first, and to remediate any weaknesses--before an attacker does. A successful vulnerability management program begins with five building blocks: scan, prioritize, remediate, verify,and monitor Because every company is unique, each building block should be customized to suit the company's specific needs most effectively. Thus, as I explain each building block, I will also provide important questions companies should be asking when customizing their own unique vulnerability management program.MAKING VULNERABILITY MANAGEMENT RELEVANT TO YOUR ORGANIZATION'S NEEDSBy Mike Holcomb, Director & Fellow of Cyber Security, Fluor Corporation (NYSE: FLR)1. ScanThe first step in vulnerability management is to scan for vulnerabilities using a vulnerability scanner. Although it might sound simple, answering just a few questions can help to ensure scanning is done efficiently and effectively.What gets scanned?Everything. Scan all internal and Internet-facing network segments for vulnerabilities.How often does a scan need to occur?Although scanning an entire network might seem like a challenge that takes considerable time, plan a schedule that more frequently scans the business's most important systems as well as those associated with the highest level of exposure. For example, Internet-facing systems might be scanned daily, mission-critical assets might be scanned weekly, and all other systems might be scanned monthly.2. PrioritizeThe second step in vulnerability management is to review the results of each vulnerability scan and prioritize any discovered vulnerabilities for remediation. Mike HolcombIN MY OPINIONIN MY OPINION
<
Page 7 |
Page 9 >