Tracking Risk
As we covered in Chapter 13, Governance Oversight, tracking risk is one of the most important components of a cybersecurity program, especially as we look to bridge the gap between the cybersecurity team, the executive leadership team, and the board of directors. It is important that when the risk is identified, it is formally added to the risk register. Once tracked, you will need to ensure that the identified risk is addressed, based on one of the mitigation methods covered earlier in the chapter. Even more important is ensuring that any high and critical risk is reviewed and acknowledged at the executive leadership and board level. If any decision needs to be made around a high or critical risk, it will be important that the correct processes are in place to help address these risks. Whatever direction is determined, it will be important that all activity and documentation are efficiently tracked.
As we discussed in the previous chapter, the risk register needs...