Embrace Your Inner Risk Adviser

  /     /     /  
Publicated : 22/11/2024   Category : security


Embrace Your Inner Risk Adviser


Bridging the gap between security and IT and the business side requires teamwork on building a risk profile



If youre a security professional whos regularly telling IT and the business side what theyre doing wrong with security, then youre doing it wrong.
Thats what John Pironti, president of IP Architects LLC, told attendees at Interop New York last week. They have no incentive to spend time with you if you [only] tell them what they are doing wrong, he said. Security pros should serve as risk advisers to the company, he said.
As security people, we are better at talking about threats and vulnerabilities than we are about risk, Pironti said. But its time to shift that mind-set, he said, and to embrace the security risk profile approach.
We need to differentiate between risk and security: Risk is part of enterprise risk management, and security is the enabler, he said. That will help remove the friction that often comes between security and IT, he said, where the security pro is all about protection, and the IT pro is all about availability and efficiency.
First, you must discern the organizations risk appetite, he said. Drill down on what they care most about and why. Security is the output, risk defines where you are going, and security determines how, he said.
If you dont know what the organizations key business processes are, he said, then take a look at the business continuity disaster recovery plan.
A risk profile entails deciding and agreeing on whats acceptable risk, and classifying data (public or confidential, for example). Whats the material business impact? Thats different for every organization -- some do it by revenue or reputation or regulatory, Pironti said. When does [a security incident] become material?
A security incident may not be material to a business if it only resulted in a few lost data records, for example. The cost to protect the data should not exceed the value of the data, Pironti said.
When security helps facilitate a risk profile, it then fits with the enterprise conversation, he said.
Ensure the business side physically signs off on the risk profile, too, Pironti said. If you want this thing to work, leadership has to buy in ...They have to understand we are not making decisions for them any longer. We are empowering them.
No longer are we the people they dont want to see ... now theyre asking us questions, he said.
Have a comment on this story? Please click Add Your Comment below. If youd like to contact
Dark Readings
editors directly,
send us a message
.

Last News

▸ Hack Your Hotel Room ◂
Discovered: 23/12/2024
Category: security

▸ Website hacks happened during World Cup final. ◂
Discovered: 23/12/2024
Category: security

▸ Criminal Possession of Government-Grade Stealth Malware ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Embrace Your Inner Risk Adviser