Tag: Frameworks
-
Creation of IT Asset Portfolio
An organization’s choice between using a spreadsheet, a purpose-built CMDB, or another GRC tool depends on present and future needs, asset information volume, and user/stakeholder access. A spreadsheet may suffice for initial asset management, but a purpose-built GRC tool is essential for long-term governance, offering robust information capture, user access control, and workflow automation.
-
Criticality of an IT Asset Portfolio
An IT Asset portfolio is crucial for IT governance, providing a clear understanding of an organization’s assets. Key information includes business owner, technology owner, location, platform, and business impact assessment results. Regular review and metadata inclusion enhance reliability. Commercial CMDB software caters to this, but it can be created with minimal resources if budget is…
-
COBIT 2019 for beginners
This content advocates for the use of frameworks in cybersecurity implementation and governance, particularly focusing on the COBIT 2019 Framework. It highlights the intricate nature of COBIT, the importance of executive sponsorship and continuous support, the need for simplification for beginners, and how COBIT aligns with industry standards like ISO 27001, ITIL, and NIST SP…
-
NIST Releases Version 2.0 of Landmark Cybersecurity Framework
The NIST has launched Cybersecurity Framework version 2.0, expanding its scope to cover all industry sectors and organization types, including governance controls. This update aims to cater to businesses of all sizes, from small enterprises to large agencies, regardless of their cybersecurity maturity. This comprehensive release marks a significant enhancement from version 1.2.
-
Ensuring that the Information Security policies are maintained and current
The main challenge in Information Security/Cybersecurity policy is keeping them current. Delegating responsibility to stakeholders, who need to stay updated on regulations and incidents, is vital. They must review exceptions, risks, and treatment activities, periodically revise the policy, and ensure its comprehensiveness. Driven by a GRC lead, overly vague or strict policies lead to non-conformance…
-
A Pragmatic approach to maturing Cyber Security program
Systematically maturing Cyber security program of your Organization
You must be logged in to post a comment.