The CISO’s role is rapidly changing. A few years ago, the CISO for many midsize firms was the security operations manager, and the job then was to employ technical skills to keep desktops, servers, and networks protected. In larger firms, the CISO had the formal role but still was sharply focused on technical IT security issues. Now, with losses from cybercrime spiraling out control, Security & Risk Professionals need a broad cross-section of financial skills and tools to be an effective defender of the enterprise.
Security & Risk Professionals need to effectively analyze how they allocate security resources to maximize their value to the business. Using a tool like the balance sheet — an information security balance sheet — will help you understand your information posture better and account for the assets and liabilities you have as a Security & Risk Professional.
Agenda:
- Security Is A Question Of Balance
- We Live In The 21st Century Data Economy
- The Information Security Balance Sheet — Balance Assets Against Liabilities
- Information Assets — Defined
- Information Liabilities — Defined
- Balance The Program (Assets – Liabilities = VALUE)
- Create An Action Plan
Key takeaways:
Know Your Liabilities
Information can actually be a liability for a business. Toxic information represents a liability to the business if a cybercriminal steals this information. Keeping a clear line of sight on those liabilities and balancing them with information assets that produce value for your business is a method to determine information security program health.
Watch Your Assets
Information assets create value for the business. Monetizing the value this information creates is critical to fully understand security's financial impact. There are several methods to estimate information asset value, but regardless of the valuation method, estimating the value is critical to information security success.
Use The Information Security Balance Sheet To Balance Your Security Program
The information security balance sheet helps you judge how much value your security program protects. Using a tool to quantify and track your security assets and liabilities in financial terms will help explain your security program’s positive financial impact. Information security bankruptcy occurs when information liabilities exceed assets.
You'll receive an email with dialing and Webex instructions prior to the Webinar.