Question

Reflect on accessibility to resources and information to build a Cyber Security program for State Farm....

Reflect on accessibility to resources and information to build a Cyber Security program for State Farm. (i.e easy access to a lot of info – or tough to get any info, etc)

0 0
Add a comment Improve this question Transcribed image text
Answer #1

1. Choose a Framework Over a Compliance Checklist

Many organizations are still heavily focused on beefing up their security to meet compliance requirements. Trust me, nobody wants to fail an audit. How can you best avoid an audit failure? Go beyond a simple checklist and develop a well-rounded, comprehensive security program based on a framework that helps you implement appropriate control measures.

There are plenty of framework comparison reference materials available online to help you understand commonalities and differences between NIST, ISO, CIS, Cobit, and other programs. According to the NIST Cybersecurity Framework (CSF), NIST has been adopted by about 30 percent of U.S. companies since its release three years ago, and that number could reach 50 percent by 2020. Keep in mind, you aren’t going to find a plug and play or off-the-shelf cyber security program. You need to roll up your sleeves and develop a program that suits the particular needs of your organization.

2. Network with Industry Peers

When it comes to developing a program, you shouldn’t be on an island. Your peers and industry colleagues can be your greatest resource. Networking is critical. If you are new to cyber security, consider joining regional networking groups affiliated with (ISC2), ISACA, InfraGard, and ISSA.

These professional organizations will give you plenty of opportunities to discuss shared challenges and best practices, and to get feedback on ideas. They also offer plenty of educational resources (webinars, training courses, symposiums, conferences) to get up to speed on cyber security program development. Many of these resources are free.

3. Collaborate with Other Departments to Document Policies and Procedures

Oftentimes, cyber security policies, procedures, and plans are written by a single person and put aside on a shelf. Meeting compliance requirements can turn into an exercise of marking the check boxes, especially if you adopt a security framework without weaving in specific security controls.

It’s important to get other business and technology leaders across departments involved in cyber policy creation. They’ll add a broader perspective that covers the necessary compliance requirements, business risk mitigation, and organizational culture factors that affect the entire company.

4. Assign Responsibilities and Hold Everyone Accountable

Cyber security is not any one person’s job – even if you are the only person with “cyber security” in your title or job description. It is in the organization’s best interest to identify responsibilities and accountabilities for various aspects of the cyber security program across the organization. Once you identify these responsibilities and accountabilities, it’s equally important that you have an actionable follow-up process to ensure that everyone is performing their respective tasks.

It’s easier to hold other individuals accountable when key leaders and decision-makers provide their buy-in on the cyber security program. They need to be involved and engaged in the program analysis and development process and hold themselves accountable as well.

5. Measure Program Metrics and Share Results

You will find that unlike other areas of IT, it’s often hard to show ROI for the resources you need to implement for a cyber security program. It’s not like putting together a business case for buying hardware or software. You will have to identify measurements for as many aspects of the program as you can and share that information with stakeholders on a frequent basis.

In addition, the types of metrics you share with business leaders should be reframed so they understand that building a cyber security program isn’t a cure-all for preventing attacks. Attacks will happen, but the ability to quickly contain those attacks is the measuring stick. As Alex Blau from Harvard Business Review stated, “Having the wrong mental model about what a cyber security program is supposed to do can be the difference between a thwarted attack and a significant breach.”

Summary

Implementing a cyber security program is a challenging process, but if you practice our tips, you can cut down on some of the uncertainty while prioritizing the policies, procedures, and controls that are most critical to your industry and organization.

Add a comment
Know the answer?
Add Answer to:
Reflect on accessibility to resources and information to build a Cyber Security program for State Farm....
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • Describe each phase of in Information Security Incident Response program. Describe the Cyber Kill Chain including...

    Describe each phase of in Information Security Incident Response program. Describe the Cyber Kill Chain including the impact each phase has in determining how to react to a cyber-attack. (Ctri)

  • Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around...

    Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...

  • This week's topic, information security policies, is perhaps the most important topic that a Business major...

    This week's topic, information security policies, is perhaps the most important topic that a Business major can take from this course. This is the governance layer that lays the bedrock for your organization's security posture. Sure, the technical folks are responsible for executing on that policy but this is where the leaders of a business get together, reach agreement, at times do a sanity check on what is enforceable in the organization, and draft the rules that will make sure...

  • When performing a gap analysis, one must have an understanding of the desired future or "to be" state. For cybersecurity focused gap analyses, we frequently use IT security controls as the mea...

    When performing a gap analysis, one must have an understanding of the desired future or "to be" state. For cybersecurity focused gap analyses, we frequently use IT security controls as the means by which we describe the "to be" (or "should be") state of IT systems and Information Security Management Programs. There are a variety of guidance documents which list and define sets of security controls. Each of these documents or sets of controls has an underlying framework. One of...

  • TRUE/FALSE QUESTIONS:  Foundations of Information Security and Assurance 1. There is a problem anticipating and testing for...

    TRUE/FALSE QUESTIONS:  Foundations of Information Security and Assurance 1. There is a problem anticipating and testing for all potential types of non-standard inputs that might be exploited by an attacker to subvert a program. 2. Without suitable synchronization of accesses it is possible that values may be corrupted, or changes lost, due to over-lapping access, use, and replacement of shared values. 3. The biggest change of the nature in Windows XP SP2 was to change all anonymous remote procedure call (RPC)...

  • Name MODULE 9 Worksheet 9A. In the space below, list factors that you think are most important wh...

    Name MODULE 9 Worksheet 9A. In the space below, list factors that you think are most important when deciding where to build your settlement. Worksheet 9B. In the space below, write a short justification for why you put your settlement, farm, water source and building materials where you did. Settlement: Farm: Water Source: Source of Building Materials: Worksheet 9C. In the space below, list which energy source you used, and then write a short justification for your choice and why...

  • The discussion: 150 -200 words. Auditing We know that computer security audits are important in business....

    The discussion: 150 -200 words. Auditing We know that computer security audits are important in business. However, let’s think about the types of audits that need to be performed and the frequency of these audits. Create a timeline that occurs during the fiscal year of audits that should occur and “who” should conduct the audits? Are they internal individuals, system administrators, internal accountants, external accountants, or others? Let me start you: (my timeline is wrong but you should use some...

  • In the original flashcard problem, a user can ask the program to show an entry picked...

    In the original flashcard problem, a user can ask the program to show an entry picked randomly from a glossary. When the user presses return, the program shows the definition corresponding to that entry. The user is then given the option of seeing another entry or quitting. A sample session might run as follows: Enter s to show a flashcard and q to quit: s Define: word1 Press return to see the definition definition1 Enter s to show a flashcard...

  • DQ1. What is an Audit Work Program (some call it Audit Program)? The audit work program...

    DQ1. What is an Audit Work Program (some call it Audit Program)? The audit work program - Email Surveillance Audit Program – What is the structure and contents including various audit steps. Find 1-2 steps in the audit program where the audit software can be used. How can audit software be used to gather evidence?. (the Audit program (Email Surveillance Audit Program details is attached). DQ3. Review the contents of the Audit Manual of Office of University Audits at University...

  • Activity: Writing Classes Page 1 of 10 Terminology attribute / state behavior class method header class...

    Activity: Writing Classes Page 1 of 10 Terminology attribute / state behavior class method header class header instance variable UML class diagram encapsulation client visibility (or access) modifier accessor method mutator method calling method method declaration method invocation return statement parameters constructor Goals By the end of this activity you should be able to do the following: > Create a class with methods that accept parameters and return a value Understand the constructor and the toString method of a class...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT