Question

Explain how an organization’s strategy relates to security. please answer in your own words. no copying and pasting

Explain how an organization’s strategy relates to security. please answer in your own words. no copying and pasting
0 0
Add a comment Improve this question Transcribed image text
Answer #1

In many organizations, security efforts are focused almost exclusively on deploying technologies, implementing “best practices,” or responding to a continuous stream of alerts and issues. The result is a reactive security organization, busy with activity and unable to answer the question, “Are we becoming more secure?” The result is friction and distrust between business leaders and the security organization. Security efforts are seen as expensive—doing more to slow rather than secure the business.

A more strategic approach is necessary. It acknowledges the reality that security needs will always exceed security capacity, provides direction to optimize security resource allocations, and demonstrates progress toward a more secure organization. This approach requires the security organization to transition from security performers to security leaders by:

  • Changing their focus from security controls to security risks: Risk is the basis for all security decision making and performance management
  • Transitioning ownership of security risks: The security organization does not own security risk decisions, the business does
  • Implementing a security operating model to govern this strategic approach: Establishing priorities, expectations, and oversight of risks and efforts to address them

The security organization’s focus is on identifying risks, recommending responses to these risks, facilitating the appropriate tradeoff decisions related to these risks, and providing line of sight to the execution of these risk responses.

A security operating model enables this approach. It provides governance and oversight of security for the entire organization, where the business is not only a recipient of the security services, but is also instrumental in the collaboration, implementation, and sustainability of security efforts. When viewed holistically, the operating model utilizes a risk-based approach to identify and prioritize risk mitigation efforts to appropriately secure the enterprise’s mission. The core of a security operating model is a collaborative continuous improvement process designed to sustain the controls that secure the enterprise.

A comprehensive security operating model includes the following components:

  • Clearly defined governance and oversight responsibilities, including scope of asset responsibilities
  • A risk-based planning process that engages business stakeholders in risk tradeoff decisions and prioritizes security investments and utilization of scarce resources
  • A security program that defines and documents security expectations of asset owners throughout the enterprise
  • Oversight mechanisms that provide an objective view of enterprise security risks and performance against the security controls, both implementation and sustaining performance
Add a comment
Know the answer?
Add Answer to:
Explain how an organization’s strategy relates to security. please answer in your own words. no copying and pasting
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT