ENGLISH

Cybersecurity for Business: Organization-Wide Strategies to Ensure Cyber Risk Is Not Just an IT Issue

Book information

Publisher
Kogan Page
Year
2022
ISBN
1398606146, 9781398606142
Language
english
Format
PDF
Filesize
13 MB (14115732 bytes)
Edition
1
Pages
264\265
Time added
2023-06-02 03:15:37

Description

Balance the benefits of digital transformation with the associated risks with this guide to effectively managing cybersecurity as a strategic business issue. Important and cost-effective innovations can substantially increase cyber risk and the loss of intellectual property, corporate reputation and consumer confidence. Over the past several years, organizations around the world have increasingly come to appreciate the need to address cybersecurity issues from a business perspective, not just from a technical or risk angle. Cybersecurity for Business builds on a set of principles developed with international leaders from technology, government and the boardroom to lay out a clear roadmap of how to meet goals without creating undue cyber risk. This essential guide outlines the true nature of modern cyber risk, and how it can be assessed and managed using modern analytical tools to put cybersecurity in business terms. It then describes the roles and responsibilities each part of the organization has in implementing an effective enterprise-wide cyber risk management program, covering critical issues such as incident response, supply chain management and creating a culture of security. Bringing together a range of experts and senior leaders, this edited collection enables leaders and students to understand how to manage digital transformation and cybersecurity from a business perspective. Cover Contents Foreword by Peter Gleason Preface About the Authors 1 Cybersecurity is (Not) an IT Issue Five Key Ideas to Take Away from This Chapter Introduction Why we are not Making Progress in Securing Cyberspace Digital Transformation Makes Cybersecurity a Business Issue The New Frontier: Artificial Intelligence (AI) and Attacks that Learn Why Balancing Business Growth, Profitability and Cybersecurity is Difficult The COVID-19 Pandemic: Cyber-Enabled Business and Increased Risk The Cybersecurity Problem is Serious and Getting Worse Fast Technical Vulnerabilities are a Problem—but not the Only Problem Why Cyber Infrastructure is Attacked—Follow the Money The Economics of Cybersecurity is Upside Down The Economic Balance in Cyberspace Favors the Attackers Good Cyber Hygiene is not Enough Security vs. Compliance The Punitive Model of Compelling Reasonable Security What’s an Organization to do About Cybersecurity? Conclusion Endnotes 2 Effective Cybersecurity Principles for Boards of Directors Five Key Ideas to Take Away from This Chapter Introduction What Role Does the Board Play in Cybersecurity? The Evolution in Corporate Board Thinking on Cybersecurity Developing and Validating Board-Level Principles of Cybersecurity Process for Developing the International Principles for Boards and Cybersecurity Five Consensus Principles for Effective Cybersecurity at the Board Level Outlining the Board Cybersecurity Principles Conclusion Endnotes 3 Structuring for the Digital Age Five Key Ideas to Take Away from This Chapter Introduction The Move Away from Digital Silos Establishing a Management Framework for Cybersecurity We are not Integrated Yet Siloed Cybersecurity Systems are Counterproductive How Centralized Ought the Cybersecurity Function be? Who does the Cyber Leader Report to? Who is on the Cybersecurity Team? Finding the Right Structure for the Cybersecurity Team Adapting Enterprise Architecture Collaborative Models Initiated in the Financial Services Industry Conclusion Endnotes 4 A Modern Approach to Assessing Cyber Risk Five Key Ideas to Take Away from This Chapter Introduction What is Cyber Risk? Comparing Traditional Cyber Risk Methods A Better Approach The Modern Risk Assessment Simplify the Contemplation of Cyber Risk Translate Traditional Cybersecurity Metrics into Financial Details Provide a Means for a Standard and Repeatable Cyber Risk Evaluation Forecast Financial Exposure due to Cyber Risk Provide a Set of Prioritized Remediation and Transfer Guidance Align Cyber Risk with Enterprise-Wide Risk Management Reporting Conclusion 5 The Role of HR Functions in Scaling Cybersecurity and Building Trust Five Key Ideas to Take Away from This Chapter Introduction Insider Threat: The Achilles Heel Remote Work: The Newest Complication Developing a Security-Minded Culture Developing Process and Operational Controls The Value of HR in Cybersecurity Recruitment, Hiring and Retention Training: A Continuing Commitment to Security Off-boarding Conclusion Endnotes 6 Cybersecurity and the Office of the General Counsel Five Key Ideas to Take Away from This Chapter Introduction Why Cybersecurity Demands a Proactive Approach by the GC Key Responsibilities—The Basics Monitoring and Advising on Changes in Statutory, Regulatory and Sectoral Requirements Regulatory Requirements Advanced Risk Management Functions of the GC Conclusion Endnotes 7 Cybersecurity Audit and Compliance Considerations Five Key Ideas to Take Away from This Chapter Introduction The Current Landscape of Compliance and Audit Requirements Cybersecurity Compliance Within Enterprise Risk Management The Role of the Audit Function Three Lines of Defense Model The Role of External Auditors The Role of Technology in the Future State of Compliance and Audit Conclusion Endnotes 8 Cyber Supply Chain and Third-Party Risk Management Five Key Ideas to Take Away from This Chapter Introduction Approaching Cyber Supply Chain Risk Management Accounting for Cybersecurity Management and IT Governance in the Total Cost of Ownership Calculation Negotiation Strategies Inclusive of Cybersecurity Insurance Provisions Implementation of Inclusive Service Level Agreements Including Cybersecurity in Current Supply Chain Risk Management Training Supply Chain Personnel to Recognize Cybersecurity Risk and Enable Mitigation Activities Cyber Supply Chain Third-Party Due Diligence Including Cyber Requirements in the Third-Party Risk Management Program Ensuring Cyber Third-Party Agreements Provide Adequate Controls for Legal Risks and Compliance Conclusion Endnotes 9 Technical Operations Five Key Ideas to Take Away from This Chapter Introduction Technical Operations—The Need for Consistent Coordination of Defense-in-Depth Prevention—Technical Operations Detection—Technical Operations Response—Technical Operations Conclusion Endnotes 10 Crisis Management Five Key Ideas to Take Away from This Chapter Introduction What is an Incident Response Plan (IRP)? Why do you Need a Plan? Business Capabilities and Function Required to Support Incident Response Questions Senior Management Should Consider in Developing an IRP Third Parties to Notify Conclusion Endnotes 11 Cybersecurity Considerations During M and A Phases Five Key Ideas to Take Away from This Chapter Introduction When is the Best Time to Conduct the Risk Assessment in M and A? The Earlier, the Better Strategy and Target Identification Phase Due Diligence and Deal Execution Phases Integration Phase Conclusion Endnotes 12 Developing Relationships with the Cybersecurity Team Five Key Ideas to Take Away from This Chapter Introduction A Healthy Culture Empathy: Understanding Others’ Feelings is Part of Cybersecurity The CISO’s Role Relationships with the Cybersecurity Team Relationships Inside the Organization Relationships Outside the Organization Assess Performance Conclusion Endnotes Index

Similar books

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

2010 · PDF

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

1858 · PDF

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

2022 · PDF

The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians

The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians

1809 · PDF

Professional Linux kernel architecture ''Wrox programmer to programmer''--Cover. - ''What you are reading right now is the result of an evolution over more than seven years: After two years of writing, the first edition was published in German by Carl Hanser Verlag in 2003. It then described kernel 2.6.0. The test was used as a basis for the low-level design documentation for the EAL4+ security evaluation of Red Hat Enterprise Linux 5, requiring to update it to kernel 2.6.18 (if the EAL acronym does not mean anything to you, then Wikipedia is once more your friend). Hewlett-Packard sponsored the translation into English and has, thankfully, granted the rights to publish the result. Updates to kernel 2.6.24 were then performed specifically for this book''--P. ix

Professional Linux kernel architecture ''Wrox programmer to programmer''--Cover. - ''What you are reading right now is the result of an evolution over more than seven years: After two years of writing, the first edition was published in German by Carl Hanser Verlag in 2003. It then described kernel 2.6.0. The test was used as a basis for the low-level design documentation for the EAL4+ security evaluation of Red Hat Enterprise Linux 5, requiring to update it to kernel 2.6.18 (if the EAL acronym does not mean anything to you, then Wikipedia is once more your friend). Hewlett-Packard sponsored the translation into English and has, thankfully, granted the rights to publish the result. Updates to kernel 2.6.24 were then performed specifically for this book''--P. ix

2008 · PDF