Rational Cybersecurity for Business: The Security Leaders' Guide to Business Alignment
暫譯: 理性網絡安全:安全領導者的商業對齊指南
Blum, Dan
買這商品的人也買了...
-
$2,100$1,995 -
$1,33097 Things Every Engineering Manager Should Know
-
$301零信任網絡 在不可信網絡中構建安全系統 (Zero Trust Networks: Building Secure Systems in Untrusted Networks)
-
$2,670$2,537 -
$1,480Zero Trust Networks with Vmware Nsx: Build Highly Secure Network Architectures for Your Data Centers
相關主題
商品描述
Use the guidance in this comprehensive field guide to gain the support of your top executives for aligning a rational cybersecurity plan with your business. You will learn how to improve working relationships with stakeholders in complex digital businesses, IT, and development environments. You will know how to prioritize your security program, and motivate and retain your team.
Misalignment between security and your business can start at the top at the C-suite or happen at the line of business, IT, development, or user level. It has a corrosive effect on any security project it touches. But it does not have to be like this.
Author Dan Blum presents valuable lessons learned from interviews with over 70 security and business leaders. You will discover how to successfully solve issues related to: risk management, operational security, privacy protection, hybrid cloud management, security culture and user awareness, and communication challenges.
This book presents six priority areas to focus on to maximize the effectiveness of your cybersecurity program: risk management, control baseline, security culture, IT rationalization, access control, and cyber-resilience. Common challenges and good practices are provided for businesses of different types and sizes. And more than 50 specific keys to alignment are included.
What You Will Learn
- Improve your security culture: clarify security-related roles, communicate effectively to businesspeople, and hire, motivate, or retain outstanding security staff by creating a sense of efficacy
- Develop a consistent accountability model, information risk taxonomy, and risk management framework
- Adopt a security and risk governance model consistent with your business structure or culture, manage policy, and optimize security budgeting within the larger business unit and CIO organization IT spend
- Tailor a control baseline to your organization's maturity level, regulatory requirements, scale, circumstances, and critical assets
- Help CIOs, Chief Digital Officers, and other executives to develop an IT strategy for curating cloud solutions and reducing shadow IT, building up DevSecOps and Disciplined Agile, and more
- Balance access control and accountability approaches, leverage modern digital identity standards to improve digital relationships, and provide data governance and privacy-enhancing capabilities
- Plan for cyber-resilience: work with the SOC, IT, business groups, and external sources to coordinate incident response and to recover from outages and come back stronger
- Integrate your learnings from this book into a quick-hitting rational cybersecurity success plan
Who This Book Is For
Chief Information Security Officers (CISOs) and other heads of security, security directors and managers, security architects and project leads, and other team members providing security leadership to your business
商品描述(中文翻譯)
使用這本全面的實地指南中的指導,獲得高層主管的支持,以便將合理的網路安全計劃與您的業務對齊。您將學會如何改善與複雜數位業務、IT 和開發環境中的利益相關者的工作關係。您將知道如何優先考慮您的安全計劃,並激勵和留住您的團隊。
安全與業務之間的不對齊可能始於高層管理(C-suite),或發生在業務線、IT、開發或用戶層級。這對任何接觸到的安全項目都有腐蝕性影響。但情況不必如此。
作者 Dan Blum 從與 70 多位安全和商業領導者的訪談中總結了寶貴的經驗教訓。您將發現如何成功解決與風險管理、操作安全、隱私保護、混合雲管理、安全文化和用戶意識以及溝通挑戰相關的問題。
本書提出六個優先領域,以最大化您的網路安全計劃的有效性:風險管理、控制基準、安全文化、IT 理性化、訪問控制和網路韌性。針對不同類型和規模的企業提供了常見挑戰和良好實踐。此外,還包含了 50 多個具體的對齊關鍵要素。
您將學到什麼
- 改善您的安全文化:明確安全相關角色,與商業人士有效溝通,並通過創造效能感來招聘、激勵或留住優秀的安全人員
- 建立一致的問責模型、信息風險分類法和風險管理框架
- 採用與您的業務結構或文化一致的安全和風險治理模型,管理政策,並在更大的業務單位和 CIO 組織的 IT 支出中優化安全預算
- 根據組織的成熟度、法規要求、規模、情況和關鍵資產量身定制控制基準
- 幫助 CIO、首席數位官和其他高層主管制定 IT 策略,以策劃雲解決方案並減少影子 IT,建立 DevSecOps 和紀律性敏捷等
- 平衡訪問控制和問責方法,利用現代數位身份標準來改善數位關係,並提供數據治理和隱私增強能力
- 規劃網路韌性:與 SOC、IT、業務團隊和外部來源合作,協調事件響應,從故障中恢復並變得更強大
- 將您從本書中學到的知識整合成一個快速有效的合理網路安全成功計劃
本書適合誰
首席信息安全官(CISOs)及其他安全負責人、安全主管和經理、安全架構師和項目負責人,以及為您的業務提供安全領導的其他團隊成員。
作者簡介
Dan Blum is an internationally recognized cybersecurity and risk management strategist. He is a former Golden Quill Award-winning VP, Distinguished Analyst at Gartner, Inc., and has served as the de facto head of security for startups and consulting companies. He's advised hundreds of corporations, universities, and government organizations, and currently partners with top media, analyst firms, and clients to produce cybersecurity thought leadership research and to deliver cybersecurity workshops and coaching for security leaders.
作者簡介(中文翻譯)
丹·布盧姆(Dan Blum)是一位國際公認的網絡安全與風險管理策略專家。他曾擔任獲得金筆獎的副總裁、Gartner, Inc. 的傑出分析師,並且在多家初創公司和諮詢公司擔任事實上的安全負責人。他曾為數百家企業、大學和政府機構提供建議,目前與頂尖媒體、分析公司及客戶合作,製作網絡安全的思想領導研究,並為安全領導者提供網絡安全工作坊和指導。