Translating business goals into security requirements
Cybersecurity, as is the case with most Information Technology (IT), is thought of by the business as a necessary evil within the company and something that must be done. Therefore, a cybersecurity architect needs to be able to align the controls to protect the company with the business goals of the company.
Cyber attacks affect the company in different ways. These can be damage to the reputation of the company in the case of a high-profile attack, economic damage if important business documents or financial data are breached, and regulatory costs from potential fines if the breach is caused by inadequately addressing compliance standards.
Each of these business impacts needs to be addressed and presented to the company when building a cybersecurity architecture. A proper risk analysis should be done for threats to identify proper security controls and present them to the company to help them understand the security and business...