Chief enablers or compliance gatekeepers?
Compliance vs. Security?
Security doers vs. security paper pushers?
What if instead of managing those risks we start fixing them?
You can't be secure without being compliant vs. you can be compliant without being secure?
What good would a steering committee do us? We have holes everywhere to fix! Less talking, more doing.
Being ISO compliant does not mean you're secured, look at XXX company who got breached, they were compliant.
Security has been in the forefront for a decade or so.
Security GRC might have emerged some time ago, but has gained traction for the past couple of years only.
Ask legal what your job is. Ask HR what your job is. Ask Engineering Management what your job is. Ask Finance what your job is. Ask executives what your job is (asking for more budget?).
Everyone has a partial picture of your job, no one knows everything you're responsible for and for what you are accountable. Your job is to tell them.
领英推荐
This is where Security GRC shines.
Engineers love solving problems, designing, architecting solutions, implementing fixes, corrections and enhancements to improve the overall security posture of the company. Let me ask a couple of questions though:
Thinking of GRC as gatekeepers and paper pushers is short-sighted. They are often the closest to the other areas of the business. A lot of them have came from varied and diverse background which helps in building a wide net of relationships.
This should be treasured and built upon instead of seen as a profanation against the purity of information security/computer security/cybersecurity/etc.
Chief Enablers?
Security GRC plays a lot of roles for security overall but its main goal is to enable security to thrive in the company.
Of course GRC has to change for this. Not enough emphasis is put on understanding the specific layout of the infrastructure of the company and its architecture. So engineers can sometimes see GRC as just looking to fill spreadsheets and point out vague and sometimes irrelevant issues based on compliance standards.
This translation exercise from the standard to the specifics of the business has to be done by Security GRC. For it to be performed, you need to understand in-depth how the business works and how business value is delivered to customers from a functional and technical standpoint.
Then and then only we'll be the chief enablers we have to be for our companies and our customers.
Regards,
CISO | ISSA Hall of Fame | CTA CISO of the Year | Sheepdog
2 年I don't agree that fixing issues solves risk management. Risk management is the process of identifying issues. So how can you identify issues without doing risk management? Once you've identified them, then you can work to mitigate or create exceptions.
Senior Cyber Security Specialist, MEng. | CISA | CRISC | Security+ | AWS Cloud Practitioner. New Grads Mentor | Women in Tech Promoter.
2 年This is very well expressed. GRC teams must have a comprehensive understanding of business; that’s essential to drive a change in culture rather than just pointing out the risks.
CISSP, CISM, CISA, aC|CISO, ITIL | Cybersecurity Advisor
2 年Well said. Nice !
Septon Strategies | Pension Actuarial and Benefits Administration Consulting
2 年Looks great - just subscribed!
Well said