How CISOs can use risk assessments to drive security culture | TechTarget

https://www.techtarget.com/rms/onlineimages/security_a375027496.jpg

Organizations that take cybersecurity seriously conduct risk assessments to determine policies, practices and controls. Often, however, security teams keep the actual assessments to themselves, with their findings failing to reach a broader audience.

"A lot of times things communicated downstream are mistranslated; they get proxied through multiple layers of the organization," said TJ Patterson, vice president and information security officer at STAR Financial Bank. "It's like the telephone game."

When stakeholders on the business side never learn why security policies and controls exist, they see them as barriers to getting work done and take them less seriously. The result is often compliance failures and distrust of the security function.

That adds up to a significant missed opportunity, according to Patterson, who uses risk assessments to inform, drive and maintain the cybersecurity culture in his CISO role. Success, he said, lies in effectively framing and communicating risk assessments, translating them...

Copyright of this story solely belongs to techtarget.com. To see the full text click HERE

Read more