| | July 2020ENTERPRISE SECURITY8IN MY OPINIONhe benefit of covering all of Asia Pacific (APAC) is that you get to see and experience how things are done broadly within the region. One of the things that has cropped up a few times is the apparent divide between risk and cybersecurity. And this is unfortunate as where I have seen this done well (risk and cybersecurity working together), the level of security maturity and awareness of cybersecurity risks with Boards and Executives seems to be greater. The obvious question that arises is why should risk and cybersecurity work closer? The short and simple answer is so that cybersecurity risks are appropriately understood, documented, prioritized and treated. How this happens is that risk will usually determine the cybersecurity risks that may impact an organization. Cybersecurity will then work with risk to help manage these risks at a controls level. The overall process though is a little more complex than that. I will try to highlight this within the rest of this paper.The first thing we have to explore are the roles that both areas play within an organization. These are as follows:· Risk the risk division manages all risks for the organization that may impact it in a detrimental manner. These will include cyber risk and its associated impacts. An effective risk management division will clearly quantify these risks and provide ways to manage these risks according to the organization's risk appetite. The risk appetite should be defined and agreed to by the Board and Executives· Cyber Security the function of the cybersecurity division should be to manage all cybersecurity related risks for the organization. The primary function should be understanding these risks, and implementing and managing controls to manage these risks so that the organization is not adversely impacted by a cybersecurity incident.TBy Ashwin Pal, Director Security Services APAC, UnisysNow is the time for Risk and Cyber Security to work closer together Ashwin PalIN MY OPINION
<
Page 7 |
Page 9 >