Book description
Use the guidance in this comprehensive field guide to gain the support of your top executives for aligning a rational cybersecurity plan with your business. You will learn how to improve working relationships with stakeholders in complex digital businesses, IT, and development environments. You will know how to prioritize your security program, and motivate and retain your team.
Misalignment between security and your business can start at the top at the C-suite or happen at the line of business, IT, development, or user level. It has a corrosive effect on any security project it touches. But it does not have to be like this.
Author Dan Blum presents valuable lessons learned from interviews with over 70 security and business leaders. You will discover how to successfully solve issues related to: risk management, operational security, privacy protection, hybrid cloud management, security culture and user awareness, and communication challenges.
What You Will Learn
- Improve your security culture: clarify security-related roles, communicate effectively to businesspeople, and hire, motivate, or retain outstanding security staff by creating a sense of efficacy
- Develop a consistent accountability model, information risk taxonomy, and risk management framework
- Adopt a security and risk governance model consistent with your business structure or culture, manage policy, and optimize security budgeting within the larger business unit and CIO organization IT spend
- Tailor a control baseline to your organization’s maturity level, regulatory requirements, scale, circumstances, and critical assets
- Help CIOs, Chief Digital Officers, and other executives to develop an IT strategy for curating cloud solutions and reducing shadow IT, building up DevSecOps and Disciplined Agile, and more
- Balance access control and accountability approaches, leverage modern digital identity standards to improve digital relationships, and provide data governance and privacy-enhancing capabilities
- Plan for cyber-resilience: work with the SOC, IT, business groups, and external sources to coordinate incident response and to recover from outages and come back stronger
- Integrate your learnings from this book into a quick-hitting rational cybersecurity success plan
Who This Book Is For
Chief Information Security Officers (CISOs) and other heads of security, security directors and managers, security architects and project leads, and other team members providing security leadership to your business
Table of contents
- Cover
- Front Matter
- 1. Executive Overview
- 2. Identify and Align Security-Related Roles
- 3. Put the Right Security Governance Model in Place
- 4. Strengthen Security Culture Through Communications and Awareness Programs
- 5. Manage Risk in the Language of Business
- 6. Establish a Control Baseline
- 7. Simplify and Rationalize IT and Security
- 8. Control Access with Minimal Drag on the Business
- 9. Institute Resilience Through Detection, Response, and Recovery
- 10. Create Your Rational Cybersecurity Success Plan
- Back Matter
Product information
- Title: Rational Cybersecurity for Business: The Security Leaders' Guide to Business Alignment
- Author(s):
- Release date: August 2020
- Publisher(s): Apress
- ISBN: 9781484259528
You might also like
book
IT Security Risk Control Management: An Audit Preparation Plan
Follow step-by-step guidance to craft a successful security program. You will identify with the paradoxes of …
book
Building a Cyber Risk Management Program
Cyber risk management is one of the most urgent issues facing enterprises today. This book presents …
book
Managing Risk and Information Security: Protect to Enable, Second Edition
Examine the evolving enterprise security landscape and discover how to manage and survive risk. While based …
book
Building an Information Security Awareness Program
The best defense against the increasing threat of social engineering attacks is Security Awareness Training to …