How to Deal with Cyber Risk
Now that we have gotten past all the CSF functions, let us focus on how to deal with cyber risk. The NIST CSF provides the guidance that is needed to align yourself with best practices. It does this through the use of documentation, development of SLAs, responsibilities matrices, and communication. All of this is considered part of administrative control.
The administrative controls provided by the CSF are meant to drive down organizational cyber risk. They do not speak to the responsibilities of risk management, as in who is ultimately responsible for it. We have discussed risk, evaluated our administrative controls, and implemented policies. These are all meant to reduce risk; however, the who is still a little unclear.
You may say that the Chief Information Security Officer (CISO) is responsible for all cyber risks. Is that right? Does it go to the CISO’s boss, who might be the Chief Information Officer (CIO) or possibly the Chief Financial...