MARCH - 2020ENTERPRISE SECURITY| | 9order to discover and remediate these new vulnerabilities in a timely manner, security leaders must ensure that they adapt their current vulnerability and risk assessment processes to reflect new environments, technologies, and other evolving factors.For some security teams, they are still working to develop these processes for cloud environments and other new technologies even though their companies have been doing business in the cloud and using these new systems for years at this point. We cannot wait this long to update our ability to automatically scan for new vulnerabilities and prioritize them based on the true risk each presents to the organization. Once we discover a vulnerability, we need to ensure that it is remediated in a timely manner and that we verify the issue was indeed addressed.4. Continuously Evaluate and ImproveAs the organization continues to evolve, the security team must evolve too--not only in its support of the company's mission but also in support of its employees. While most organizations are evolving, the members of the security team are not always. Leaders must encourage their team members to take training each year to grow their skills, both technical and non-technical, helping to build off of their existing strengths while helping to compensate for skills needing improvement. An organization's security posture is only as strong as its cybersecurity team. Training helps strengthen both at the same time.Training also helps the security team look outside of itself and the organization it supports. Too often, security team members can develop tunnel vision, focused on protecting their organization, but losing track of the world evolving around them including the latest tactics and techniques used by attackers. Team members should take the time to not only look at the current security landscape but also examine how other organizations, especially those similar to their own, are protecting themselves in today's world.It is essential that cybersecurity team members look to the growing cybersecurity community to develop a much more well-rounded approach and increase their own knowledge set and skills.5. Use Metrics to Communicate and Demonstrate"Not everything that counts can be counted, and not everything that can be counted counts." - Albert EinsteinOne of my favorite quotes attributed to Einstein helps demonstrate the struggle many security teams have in being able to effectively measure what they do and how they support the organization in doing so. It is essential that the security team gathers relevant metrics that demonstrate how it helps support the business and how it aligns with the company's business objectives. Any metrics that are gathered and reported on should demonstrate how the cybersecurity team helps the business succeed so that it can be seen as a business enabler--and ultimately be actively engaged in the future to help continue security the company and all of its latest endeavors. ESBuilding off of the idea of always being ready to adapt, we need to ensure that we are able to support the business in achieving its goals--as securely as possibleMike Holcomb
<
Page 8 |
Page 10 >