Using vulnerability management data
For organizations that are just bootstrapping a cybersecurity program or for CISOs that have assumed leadership of a program that has been struggling to get traction in their organization, vulnerability management data can be a powerful tool. Even for well-established cybersecurity programs, vulnerability management data can help illustrate how the security team has been effectively managing risk for their organization and improving over time. Despite this, surprisingly, I’ve met some CISOs of large, well-established enterprises who do not aggregate and analyze or, otherwise, use data from their vulnerability management programs. This surprises me when I come across it, because this data represents one of the most straightforward ways available for CISOs to communicate the effectiveness of their cybersecurity programs.
A challenge for CISOs and IT executives is to develop a performance overview based on data that aligns with the way business...