The Circle of Cybersecurity: Leaders to Managers
A recent post of mine, The Circle of Cybersecurity , was a bit dense so I am expanding pieces of it in separate posts. This post examines the first downward arrow, what flows from Leaders to Managers. That arrow is labelled "Policies" but that is a bit of shorthand for the many related kinds of information that travel that path. In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF. Priorities In such a framework the first thing that leaders have to do is bless a list of digital assets to be protected. The managers may well provide a super set of all possible candidates, but the leaders need to impose priority on that super set. Almost no organization can protect every possible digital asset all the time. Resources Once the digital asset list is set for the time period--usually a year--then the organizati...