NIST CSF Implementation Tier 3 means the organization has “risk-informed” practices that are regularly updated and partially integrated across the enterprise. That is what the framework …
Sunshine Week is an annual journalism industry initiative held every March to celebrate freedom of information and open government. It was established in 2005 by the American Society of News Editors. …
After an incident, one of the first data sources an investigator wants is DNS query logs. What domains did this host reach out to? When? How often? Did the resolution pattern look like beaconing? Did …
The risk register that comes out of a mature GRC program should tell the board something true about the organization’s exposure. Too often it tells them something comfortable instead.
The most …
Your vendor completed the risk questionnaire. They answered yes to “do you have an information security policy,” yes to “do you encrypt data at rest,” and yes to “have …
Zero Trust is the right model. It is also reliably failing to take hold in most large enterprise environments. Those two things are not in conflict.
The model is correct: never trust the network, …
It’s Data Privacy Week. Or is it Data Privacy Day? The confusion isn’t accidental.
What started as a legitimate European observance on January 28 has expanded into a week-long American …
Your organization completed its annual security awareness training. Ninety-three percent of employees clicked through the phishing module and passed the quiz. The CISO has a number, compliance has a …
Model risk management has a well-documented history in financial services. SR 11-7, the Federal Reserve’s 2011 guidance on model risk management, established a framework that influenced how …