Get a Pentest and security assessment of your IT network.

News

Self-Improvement Agenda for CISOs: Four Types of Business Value, Two Types of Risk

Security professionals are generally good at communicating the business value of things they do that are important but not necessarily strategic. For example, compliance and cost dont always communicate their strategic components, such as risk and enablement. Security risk is not synonymous with threats, vulnerabilities or exploits, as much as we love talking about those things. The proper definition of risk is the likelihood that some threat will exploit a vulnerability, along with the magnitude of the business impact if the event actually occurs. The goal is to manage security risks to an acceptable level, within the managements appetite for risk.”]

Source: https://securityintelligence.com/self-improvement-agenda-for-cisos-four-types-of-business-value-two-types-of-risk/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Thousands of Magento websites compromised to serve malware

News

Office 365 Secure Score: An Introduction