healthcaretechoutlook
| | May 201919HOW DO WE KNOW WE'RE SECURE?How do we know we're secure?"It's a question I've been asked by senior leadership at every organization I've been. I typically reply "how do you guarantee you won't get into an accident this year?" The answer is you don't. We assess risk everyday using our mental models of the world, then gauge items that deviate. When assessing information security, there is nothing different. One of the first things senior leadership should ask their information security leadership is "how" you measure risk, not "if" it exists. There is no right answer, as responses will vary based on the leaders' experience, industry vertical, and a variety of other factors such as geographic location. The point of the exercise is to ensure that a thoughtful approach is used. Some security experts may choose to assess risk solely leveraging their own experience. This is a mistake. As humans, we aren't as objective as we may con ourselves into believing and gaps aren't always where we think it is. This is where frameworks come into the picture.The purpose of a security framework is to help make cyber risk decisions, which pulls together a collective By Joshua Danielson, Chief Information Security Officer, Copart [NASDAQ:CPRT]CXO INSIGHTS
< Page 9 | Page 11 >