As a virtual CISO and cybersecurity consultant, Gideon Rasmussen helps new CISOs and organizations that are bringing on a CISO for the first time build a program architecture, conduct budgetary assessments, and translate cybersecurity into business impact the board understands. Gideon and Joe discuss the importance of consistent process execution, QA, and automation to help teams avoid things slipping through the cracks and experiencing “compliance jitter.”
They dig into the latest update for the NIST Cybersecurity Framework, and share ways to use risk assessments and incident response exercises to improve cyber resilience. If you’ve got an upcoming board presentation and need to communicate risk to guide decisions, this episode has advice to help.
Chapters:
00:00 Introduction and Background
02:01 Virtual CISO and Consultancy Services
06:12 Overview of Governance, Risk, and Compliance (GRC)
11:24 Methodologies for Assessing Compliance
16:19 Moving from Reactive to Proactive Controls
17:15 Importance of Incident Response Exercises
21:11 Business Response to Security Incidents
23:23 Collaboration between Security and Finance
27:26 Frameworks and Resources for GRC
31:59 Addressing Fraud and Financial Risks
37:30 Getting Started in GRC
41:21 Preparing for the Year Ahead
42:35 Team Ownership and Collaboration
43:25 Connecting and Collaborating with Gideon
44:05 Valuable Insights and Learning
Check out all our cybersecurity podcasts: https://delinea.com/events/podcasts
Follow Joe:
/ josephcarson
/ joe_carson
Follow Gideon:
/ gideonrasmussen
/ gideonras
* *
Subscribe to never miss an episode!
Apple: https://podcasts.apple.com/us/podcast...
Spotify: https://open.spotify.com/show/3ZgT6fg...
Want to maximize your organization’s cybersecurity? Join us on LinkedIn and Twitter—we have many great resources for CISOs, BISOs and IT security teams:
/ delinea
/ delineainc
See what else we have coming down the pipeline—subscribe to our YouTube Channel:
https://www.youtube.com/c/delinea?sub...
#cybersecuritypodcast #cyberresilience #cisocybersecurity
コメント