• Complain

Ryan Leirvik - Understand, Manage, and Measure Cyber Risk: Practical Solutions for Creating a Sustainable Cyber Program

Here you can read online Ryan Leirvik - Understand, Manage, and Measure Cyber Risk: Practical Solutions for Creating a Sustainable Cyber Program full text of the book (entire story) in english for free. Download pdf and epub, get meaning, cover and reviews about this ebook. year: 2021, publisher: Apress, genre: Business. Description of the work, (preface) as well as reviews are available. Best literature library LitArk.com created for fans of good reading and offers a wide selection of genres:

Romance novel Science fiction Adventure Detective Science History Home and family Prose Art Politics Computer Non-fiction Religion Business Children Humor

Choose a favorite category and find really read worthwhile books. Enjoy immersion in the world of imagination, feel the emotions of the characters or learn something new for yourself, make an fascinating discovery.

Ryan Leirvik Understand, Manage, and Measure Cyber Risk: Practical Solutions for Creating a Sustainable Cyber Program
  • Book:
    Understand, Manage, and Measure Cyber Risk: Practical Solutions for Creating a Sustainable Cyber Program
  • Author:
  • Publisher:
    Apress
  • Genre:
  • Year:
    2021
  • Rating:
    3 / 5
  • Favourites:
    Add to favourites
  • Your mark:
    • 60
    • 1
    • 2
    • 3
    • 4
    • 5

Understand, Manage, and Measure Cyber Risk: Practical Solutions for Creating a Sustainable Cyber Program: summary, description and annotation

We offer to read an annotation, description, summary or preface (depends on what the author of the book "Understand, Manage, and Measure Cyber Risk: Practical Solutions for Creating a Sustainable Cyber Program" wrote himself). If you haven't found the necessary information about the book — write in the comments, we will try to find it.

When it comes to managing cybersecurity in an organization, most organizations tussle with basic foundational components. This practitioners guide lays down those foundational components, with real client examples and pitfalls to avoid.

A plethora of cybersecurity management resources are availablemany with sound advice, management approaches, and technical solutionsbut few with one common theme that pulls together management and technology, with a focus on executive oversight. Author Ryan Leirvik helps solve these common problems by providing a clear, easy-to-understand, and easy-to-deploy foundational cyber risk management approach applicable to your entire organization.

The book provides tools and methods in a straight-forward practical manner to guide the management of your cybersecurity program and helps practitioners pull cyber from a technical problem to a business risk management problem, equipping you with a simple approach to understand, manage, and measure cyber risk for your enterprise.


What You Will Learn

  • Educate the executives/board on what you are doing to reduce risk
  • Communicate the value of cybersecurity programs and investments through insightful risk-informative metrics
  • Know your key performance indicators (KPIs), key risk indicators (KRIs), and/or objectives and key results
  • Prioritize appropriate resources through identifying program-related gaps
  • Lay down the foundational components of a program based on real examples, including pitfalls to avoid

Who This Book Is For

CISOs, CROs, CIOs, directors of risk management, and anyone struggling to pull together frameworks or basic metrics to quantify uncertainty and address risk

Ryan Leirvik: author's other books


Who wrote Understand, Manage, and Measure Cyber Risk: Practical Solutions for Creating a Sustainable Cyber Program? Find out the surname, the name of the author of the book and a list of all author's works by series.

Understand, Manage, and Measure Cyber Risk: Practical Solutions for Creating a Sustainable Cyber Program — read online for free the complete book (whole text) full work

Below is the text of the book, divided by pages. System saving the place of the last page read, allows you to conveniently read the book "Understand, Manage, and Measure Cyber Risk: Practical Solutions for Creating a Sustainable Cyber Program" online for free, without having to search again every time where you left off. Put a bookmark, and you can go to the page where you finished reading at any time.

Light

Font size:

Reset

Interval:

Bookmark:

Make
Contents
Landmarks
Book cover of Understand Manage and Measure Cyber Risk Ryan Leirvik - photo 1
Book cover of Understand, Manage, and Measure Cyber Risk
Ryan Leirvik
Understand, Manage, and Measure Cyber Risk
Practical Solutions for Creating a Sustainable Cyber Program
Logo of the publisher Ryan Leirvik Arlington VA USA ISBN - photo 2
Logo of the publisher
Ryan Leirvik
Arlington, VA, USA
ISBN 978-1-4842-7820-8 e-ISBN 978-1-4842-7821-5
https://doi.org/10.1007/978-1-4842-7821-5
Ryan Leirvik 2022
This work is subject to copyright. All rights are solely and exclusively licensed by the Publisher, whether the whole or part of the material is concerned, specifically the rights of translation, reprinting, reuse of illustrations, recitation, broadcasting, reproduction on microfilms or in any other physical way, and transmission or information storage and retrieval, electronic adaptation, computer software, or by similar or dissimilar methodology now known or hereafter developed.
The use of general descriptive names, registered names, trademarks, service marks, etc. in this publication does not imply, even in the absence of a specific statement, that such names are exempt from the relevant protective laws and regulations and therefore free for general use.
The publisher, the authors and the editors are safe to assume that the advice and information in this book are believed to be true and accurate at the date of publication. Neither the publisher nor the authors or the editors give a warranty, expressed or implied, with respect to the material contained herein or for any errors or omissions that may have been made. The publisher remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.

This Apress imprint is published by the registered company APress Media, LLC part of Springer Nature.

The registered company address is: 1 New York Plaza, New York, NY 10004, U.S.A.

Foreword

Some of us love building from scratch. As children, we gather stones and sticks and construct little cities where our imaginations can roam. As apparent grownups, we often must build something from scratch, except there is no such thing as scratch. Everything has a history and a foundationsometimes of neatly pointed stone, sometimes of toothpicks and chewing gum.

Tasked with building/rebuilding a security organization, we are confronted with a formidable challenge that feels like building from scratch; however, be assured that the bits and pieces are thereonly strewn about in your organization.

After years as a scientist and research leader, my own security from scratch work ranged from building a product security organization, a privacy organization, and twice creating world-class information security organizations within Fortune 500 corporations. There was never a truly blank sheet. The foundations were there but ranged from sticks and stones to a few solid pillars.

In my story, I was three years into my teams great work in creating the first Philips information security organization when I began to appreciate how much I enjoyed the build phase and not so much the operational phase. So, after a change in CIO, I retired from Philips to start my own consulting company. My brief sojourn into private practice ended when I joined Beckton Dickinson to create another new CISO officeseeing a chance to build yet again and learn from a whole new set of mistakes. The new program at BD was firmly in place after four years, and I left to return to consulting, where I remain today.

Ryan Leirvik and I, for some time, have served as faculty at IANS Research (IANSResearch.com), a company providing its customers and the world with security insights from experienced practitioners. We did not meet there but were introduced by a colleague at McKinsey & Company and began a conversation about building InfoSec organizations. I quickly challenged Ryan to define risk. Although he looked a little startled, he did not hesitate to immediately provide a clear definition along with, By the way, I have just finished writing a book on building a strong security program that hinges on first defining risk. What followed was an exchange where each of us would make a statement or two about building a program, and the other would pause, wide-eyed, and say Exactly! It seems that I had found a kindred spirita builder who had worked with a wide variety of client CISOs on their programs, gaining a deep understanding of how a successful and sustainable program should be constructed. His cyber work at the US Department of Defense, his McKinsey consulting, and his advisory and survey work with IANS gave him a unique global view of our shared passion. My in-the-trenches build-work with Fortune 500 multinationals and my CISO advisory work had given me a similar pragmatic perspective.

I was delighted to read Ryans near-final copy of the book, and I jumped at the chance to provide this foreword. Ryan has assembled an extremely straightforward guide to building a strong risk-based cybersecurity program.

The world has significant problems with cybersecurity. We all appreciate the value provided by an ecosystem of pervasive, connected, smart things doing what we want and need. The problem is that while the complexity of hardware and software interconnection grows exponentially, so do the opportunities to exploit weaknesses. This can be quite rewarding for criminal and state actors seeking to illicitly profit or grow their power. On the cyber defense side, the complexity of what we must protect is astronomical. The landscape and its attack surface constantly grow, fold, and confound. This too often leads us to analysis (and solution) paralysis in addressing cybersecurity risk. Without due care, we can become reactive robots.

With an eye toward sustainable organizational success, Ryan begins his recipe with the development and propagation of shared definitions of risk, threat, critical, and other essential terms. This is the first of many step-by-step instructions on assembling the right elements, arranging them by priority, and establishing activities/projects to meet specific and measurable goals. Along the way, Ryan provides plenty of examples and small, simple rules, templates, and checklists to accelerate the first phases of the journey with emphasis on developing a short, meaningful list of targeted metrics. He provides a great way to start and grow your organizations risk management practice. Further, he emphasizes the takeaways by pointing out the pitfalls and providing meaningful examples of how a program might proceed.

I personally like to apply the Rumsfeldian lens to determine the completeness of a cybersecurity program, and this book hits all the marks. Ryans book addresses the known knowns by systematically creating an asset inventory using a simple top-down practice. The known unknowns materialize as articulated risks assembled into a simple risk registry that is used to build consensus on the potential for harm, thus driving the priority of activities and projects. The problematic unknown unknowns are addressed by creating an information security organization that adopts a framework like the NIST CSF, preparing for the unexpected by using frameworks to ensure we have skills across all the cyber disciplines. Holistically, the book emphasizes the need for balance, and Ryan lays out a discipline of regular top-down re-inspection to ensure the completeness of the program.

Next page
Light

Font size:

Reset

Interval:

Bookmark:

Make

Similar books «Understand, Manage, and Measure Cyber Risk: Practical Solutions for Creating a Sustainable Cyber Program»

Look at similar books to Understand, Manage, and Measure Cyber Risk: Practical Solutions for Creating a Sustainable Cyber Program. We have selected literature similar in name and meaning in the hope of providing readers with more options to find new, interesting, not yet read works.


Reviews about «Understand, Manage, and Measure Cyber Risk: Practical Solutions for Creating a Sustainable Cyber Program»

Discussion, reviews of the book Understand, Manage, and Measure Cyber Risk: Practical Solutions for Creating a Sustainable Cyber Program and just readers' own opinions. Leave your comments, write what you think about the work, its meaning or the main characters. Specify what exactly you liked and what you didn't like, and why you think so.