Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

URL has been copied successfully!
Is your enterprise ‘cyber resilient’? Probably not. Here’s how other boards fixed that
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Lockheed Martin: Lockheed Martin introduced its Cyber Resiliency Level (CRL) Framework and corresponding Scoreboard in 2018, illustrating a more formalized approach to measuring cyber resilience during this period. The company’s Cyber Resiliency Scoreboard includes tools like a questionnaire and dashboard for measuring the maturity levels of six categories, including Cyber Hygiene and Architecture.MIT: The Balanced Scorecard for Cyber Resilience (BSCR) provides insight into financial and operational performance by combining information about core activities that might otherwise be isolated from each other.USDA: The USDA Cybersecurity Scorecard created with the Farm Service Agency emphasizes a balanced scorecard approach aligned with the NIST framework, focusing on areas like compliance, vulnerability management, and incident response. Aligning with the NIST framework ensures that the USDA adopts a comprehensive, standardized approach to cybersecurity that is recognized and utilized across various industries. This alignment enhances the organization’s ability to manage and mitigate risks effectively while ensuring that all aspects of cybersecurity, from prevention to response, are systematically addressed.Malini Rao: Rao’s CISO Operational Balanced Scorecard distinguishes between transformational and operational aspects, offering a dual approach to align cybersecurity with strategic business objectives. She champions scorecards for helping CISOs “gain trust by proactively reporting metrics”¦ that can identify weaknesses and prioritize areas for improvement.”While there is no “one-size-fits-all” approach to a cyber resilience scorecard, there are certain elements that they typically have in common. Whether you’re considering an existing cyber resilience scorecard or designing your own, look for this basic framework:
Risk assessment: Evaluating potential cyber risks and their impact on the organizationSecurity controls: Reviewing the effectiveness of implemented security measuresIncident response: Assessing the readiness and response strategies for potential cyber incidentsRecovery capabilities: Measuring the ability to recover from a cyberattack with minimal disruptionBuild your own cyber resilience scorecardFollow these key steps to make a cyber resilience scorecard that’s effective for your particular situation:
Assessment and goal setting: Begin by assessing your current cybersecurity posture and defining what cyber resilience means for your organization. This could involve setting goals for recovery times, reducing the impact of breaches, or enhancing system redundancies.Framework development: Develop a scorecard that aligns with your cyber resilience goals. This should include a blend of quantitative and qualitative metrics, such as recovery time objectives, employee training levels, system backup frequency, and the integration of cybersecurity in business continuity planning.Regular monitoring and reporting: Establish a routine for monitoring performance against the scorecard metrics. This monitoring should be an integral part of the cybersecurity governance process, with regular reporting to key stakeholders, including the board of directors.Continuous improvement: Use insights gained from the scorecard to drive continuous improvement in your cyber resilience strategies. This could involve adjusting cybersecurity policies, investing in better incident response technologies, or enhancing employee training programs.Board involvement and oversight: Ensure that the board of directors is actively involved in overseeing the implementation of the scorecard. Their strategic insight and oversight will be crucial in aligning cyber resilience efforts with broader business objectives.By prioritizing cyber resilience and adopting tools like a scorecard, organizations can not only mitigate the impacts of cyber incidents but also bolster their competitiveness and sustainability. Rao recommends using AI and automation to enhance cyber resiliency reporting, like generating weekly and monthly scorecards. And don’t forget your supply chain, she stresses: Businesses should align their third-party partners to report scorecard metrics too.Learn how to protect your business-critical endpoints and cloud workloads with the Tanium platform.This article was written by Tony Bradley and originally appeared in Focal Point magazine.

First seen on csoonline.com

Jump to article: www.csoonline.com/article/3835902/is-your-enterprise-cyber-resilient-probably-not-heres-how-other-boards-fixed-that.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link