Featured

Incident Detection and Response Oriented Security Governance



Published
IT and security governance approaches are broad and hard to comprehend, especially for non technical executives. That is why they can not understand the gravity and importance of the information security issues. As a result the organizations struggle with obtaining the much needed human and financial resources even if they can afford to.

Here, we suggest a bottom up approach to security governance by first materializing the current cyber threats, listing current and real techniques used by the real attackers and then matching the threats to the relevant controls. Even though most of the cyber security attack techniques are extremely technical the consequences and attacker strategies can be understood by all layers of management.
Category
Management
Be the first to comment