Controls

Chris Moschovitis · 2018

This chapter explains broad types of controls: preventative, detective, corrective, and compensatory. The right way to use all of these controls is by deploying them across systems in a way that achieves defense in depth. New controls are developed almost daily as part of the constant arms race between hackers, cybersecurity vendors, developers, IT companies, end users, and governments. Of people, technology, and operations, the people component is the most critical element of a successful cybersecurity program. The more complex the operations, the more essential the need for proper change management, strong communications, and cross-departmental engagement. The chapter provides the definitions policies, standards, procedures, and guidelines. Specifics of compliance, metrics, and reward and penalty policies will vary from company to company, but ultimately one thing must be unambiguously clear to all. These cybersecurity policies are mandatory, and just like any human resource policy, are enforced rigorously across the board.

Read the paper · More papers on PaperTik