Rational Cybersecurity for Business Rational Cybersecurity for Business

Rational Cybersecurity for Business

The Security Leaders' Guide to Business Alignment

Publisher Description

Use the guidance in this comprehensive field guide to gain the support of your top executives for aligning a rational cybersecurity plan with your business. You will learn how to improve working relationships with stakeholders in complex digital businesses, IT, and development environments. You will know how to prioritize your security program, and motivate and retain your team.

Misalignment between security and your business can start at the top at the C-suite or happen at the line of business, IT, development, or user level. It has a corrosive effect on any security project it touches. But it does not have to be like this. 

Author Dan Blum presents valuable lessons learned from interviews with over 70 security and business leaders. You will discover how to successfully solve issues related to: risk management, operational security, privacy protection, hybrid cloud management, security culture and user awareness, and communication challenges.

This open access book presents six priority areas to focus on to maximize the effectiveness of your cybersecurity program: risk management, control baseline, security culture, IT rationalization, access control, and cyber-resilience. Common challenges and good practices are provided for businesses of different types and sizes. And more than 50 specific keys to alignment are included.

You will:Improve your security culture: clarify security-related roles, communicate effectively to businesspeople, and hire, motivate, or retain outstanding security staff by creating a sense of efficacy
Develop a consistent accountability model, information risk taxonomy, and risk management frameworkAdopt a security and risk governance model consistent with your business structure or culture, manage policy, and optimize security budgeting within the larger business unit and CIO organization IT spendTailor a control baseline to your organization’s maturity level, regulatory requirements, scale, circumstances, and critical assetsHelp CIOs, Chief Digital Officers, and other executives to develop an IT strategy for curating cloud solutions and reducing shadow IT, building up DevSecOps and Disciplined Agile, and moreBalance access control and accountability approaches, leverage modern digital identity standards to improve digital relationships, and provide data governance and privacy-enhancing capabilities
Plan for cyber-resilience: work with the SOC, IT, business groups, and external sources to coordinate incident response and to recover from outages and come back strongerIntegrate your learnings from this book into a quick-hitting rational cybersecurity success plan

GENRE
Computers & Internet
RELEASED
2020
August 12
LANGUAGE
EN
English
LENGTH
359
Pages
PUBLISHER
Apress
SELLER
Springer Nature B.V.
SIZE
18.2
MB

More Books Like This

CISM Certified Information Security Manager All-in-One Exam Guide CISM Certified Information Security Manager All-in-One Exam Guide
2018
Official (ISC)2  Guide to the CISSP CBK Official (ISC)2  Guide to the CISSP CBK
2012
Official (ISC)2 Guide to the CISSP - ISSMP CBK, Second Edition Official (ISC)2 Guide to the CISSP - ISSMP CBK, Second Edition
2014
The Secure Board The Secure Board
2021
Managing Risk and Information Security Managing Risk and Information Security
2013
Using the IBM Security Framework and IBM Security Blueprint to Realize Business-Driven Security Using the IBM Security Framework and IBM Security Blueprint to Realize Business-Driven Security
2014

More Books by Dan Blum

Customers Also Bought

The Ethics of Cybersecurity The Ethics of Cybersecurity
2020
Taxmann's Cyber Crimes & Laws -  4th Edition Taxmann's Cyber Crimes & Laws -  4th Edition
2021
The Future and Opportunities of Cybersecurity in the Workforce The Future and Opportunities of Cybersecurity in the Workforce
2020
Cyber-Security in Healthcare Cyber-Security in Healthcare
2015
Cyber-Terrorism Cyber-Terrorism
2014
Challenges in Cybersecurity and Privacy - the European Research Landscape Challenges in Cybersecurity and Privacy - the European Research Landscape
2022