| | OCTOBER 2022ENTERPRISE SECURITY8Cyber governance, risk, and compliance (Cyber GRC) is the core enabler of strategic cybersecurity. Cybersecurity exists to support the organization in achieving its business objectives by securing assets and minimizing cyber risk. The strategy outlines the goals and priorities, and determines actions and timelines, also stated as the roadmap. The cybersecurity strategy should be continuously updated as the organization's goals and operating environment change. A fundamental responsibility of Cyber GRC is to reflect the cybersecurity strategy in the cybersecurity policies, standards, and operating model. Policies are often the focus of governance and provide a foundation for GRC. The policies explain why programs are implemented and how they support the strategic goals defined for cybersecurity. Standards are also created for each policy to provide more specific requirements of what must be done. With clear strategic direction provided through documentation of policies and standards, the cybersecurity team and stakeholders are empowered to drive a security-conscious culture and proactive approach to security as new projects are implemented to achieve the business mission and objectives.Risk management is central to keeping the cybersecurity strategy and documentation fit for purpose. Through implementing a process for identification of risks, threats, and vulnerabilities, Cyber GRC provides organization specific information regarding the operating environment which can be helpful in CYBER GRC: CORE ENABLER OF STRATEGIC CYBERSECURITYBy Jamie Sanderson, Director of Cyber Governance, Risk, and Compliance, AESCYBER GRC MUST BE DIRECTLY INTEGRATED IN ALL CYBERSECURITY PROGRAMS TO EFFECTIVELY ENABLE EXECUTION OF THE CYBERSECURITY STRATEGYIN MY OPINIONIN MY OPINION
<
Page 7 |
Page 9 >