CYBERSECURITY REVIEW8 NOVEMBER - 2022Cyber governance, risk, and compliance (Cyber GRC) is the core enabler of strategic cybersecurity. Cybersecurity exists to support the organization in achieving its business objectives by securing assets and minimizing cyber risk. The strategy outlines the goals and priorities, and determines actions and timelines, also stated as the roadmap. The cybersecurity strategy should be continuously updated as the organization's goals and operating environment change. A fundamental responsibility of Cyber GRC is to reflect the cybersecurity strategy in the cybersecurity policies, standards, and operating model. Policies are often the focus of governance and provide a foundation for GRC. The policies explain why programs are implemented and how they support the strategic goals defined for cybersecurity. Standards are also created for each policy to provide more specific requirements of what must be done. With clear strategic direction provided through documentation of policies and standards, the cybersecurity team and stakeholders are empowered to drive a security-conscious culture and proactive approach to security as new projects are implemented to achieve the business mission and objectives.CYBER GRC: CORE ENABLER OF STRATEGIC CYBERSECURITYBy Jamie Sanderson, Director of Cyber Governance, Risk, and Compliance,AESIN MY OPINIONJamie Sanderson
<
Page 7 |
Page 9 >