Get a Pentest and security assessment of your IT network.

News

Self-Improvement Agenda for CISOs: Four Types of Business Value, Two Types of Risk

Security professionals are generally good at communicating the business value of things they do that are important but not necessarily strategic. For example, compliance and cost dont always communicate their strategic components, such as risk and enablement. Security risk is not synonymous with threats, vulnerabilities or exploits, as much as we love talking about those things. The proper definition of risk is the likelihood that some threat will exploit a vulnerability, along with the magnitude of the business impact if the event actually occurs. The goal is to manage security risks to an acceptable level, within the managements appetite for risk.”]

Source: https://securityintelligence.com/self-improvement-agenda-for-cisos-four-types-of-business-value-two-types-of-risk/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin