Risk Frameworks
As we have continued to discuss throughout the book, the premise of the cybersecurity program is to manage and reduce risk related to cybersecurity for an organization. Essentially, our program can be thought of as a framework to an extent. If we take a step back from cybersecurity and look at risk from a broader perspective, it is critical that there is an overarching risk management program for the broader organization.
Your organization’s size may determine whether you have a dedicated risk management function with a Chief Risk Officer (CRO) or whether this function falls within another group being a smaller organization. For example, does risk management for the organization fall within the CISO responsibilities, since our primary role is to already manage risk? Or does it reside with the Legal team? Regardless of where it lives, it will be important that there is some form of a centralized approach to manage and track all risks for the organization...