I’m continuing my long series of posts that describe how to implement an information security program. Currently, we’re in the section I call “How to Measure Cyber Risks.” Now it’s…
For each cyber risk you want to measure, you’ll need to set a target score. This score represents how well the organization needs to be able to perform the cybersecurity…
Using our semi-formal, semi-quantitative approach, we’ll need a way to measure cyber risk in order to use data to manage it. Managerial Approach Because we’re taking a managerial approach to…
An essential function of a cybersecurity program is the management of cyber risk. You’ll manage it on a daily basis as part of the operational functions and projects your team…
Over the next several posts on this blog, I’ll describe how to measure, understand, and manage cyber risks at an executive level. We’ll build on everything that we’ve covered so…