Building a Cyber Risk Management Program: Evolving Security for the Digital Age


Building a Cyber Risk Management Program: Evolving Security for the Digital Age
Author: Brian Allen (Author), Brandon Bapst (Author), Terry Hicks (Author)
Publisher finelybook 出版社:‏ O’Reilly Media
Edition 版本:‏ 1st
Publication Date 出版日期:‏ 2024-01-09
Language 语言: English
Print Length 页数: 220 pages
ISBN-10: 1098147790
ISBN-13: 9781098147792

Book Description

Cyber risk management is one of the most urgent issues facing enterprises today. This book presents a detailed framework for designing, developing, and implementing a cyber risk management program that addresses your company’s specific needs. Ideal for corporate directors, senior executives, security risk practitioners, and auditors at many levels, this guide offers both the strategic insight and tactical guidance you’re looking for.

You’ll learn how to define and establish a sustainable, defendable, cyber risk management program, and the benefits associated with proper implementation. Cyber risk management experts Brian Allen and Brandon Bapst, working with writer Terry Allan Hicks, also provide advice that goes beyond risk management. You’ll discover ways to address your company’s oversight obligations as defined by international standards, case law, regulation, and board-level guidance.

This book helps you:

  • Understand the transformational changes digitalization is introducing, and new cyber risks that come with it
  • Learn the key legal and regulatory drivers that make cyber risk management a mission-critical priority for enterprises
  • Gain a complete understanding of four components that make up a formal cyber risk management program
  • Implement or provide guidance for a cyber risk management program within your enterprise

Review

“As a cyber practitioner who has spent the last decade building and evolving the cyber risk program at the world’s largest Fintech, I thoroughly enjoyed reading Building a Cyber Risk Management Program by Brian Allen and Brandon Bapst. Their program roadmap and insights will benefit cyber risk leaders working in any industry, companies of all sizes, and programs at all levels of maturity.”  – Greg Montana, Independent Board Member and former CRO, FIS Global 
“Building a Cyber Risk Management Program applies practical solutions to the ever evolving, complex, and technical cyber environment. It’s well thought-out and provides a structured risk-based governance approach with easy-to-follow concepts. This book is a must read for anyone with cyber risk management responsibilities.” John E. Turey, Chief Risk Officer – TE Connectivity

About the Author

Brian Allen was the Chief Security Officer for Time Warner Cable, a critical infrastructure, Fortune 130 enterprise. He worked for EY as the sub-competency lead for their cyber risk management program efforts, presenting to dozens of boards and c-suite executives at some of the largest global organizations. Today, Brian works at The Bank Policy institute as the SVP, Cybersecurity and Technology Risk Management, working with bank executives (CEO, GC, CRO, CISO), advocating for the industry in front of regulators, legislators, law enforcement agencies, and the intelligence communities. Mr. Allen has worked on several industry and government coordinated critical infrastructure groups including the executive committees of the Comm-ISAC and Comm-Sector Coordinating Council. He was appointed by the FCC Chairman to represent the communication industry in working with NIST on the development of the Cybersecurity Framework. Mr. Allen is an author of two enterprise security risk management books, an Adjunct Professor at the University of Connecticut’s MBA Financial Risk Management program, teaching cybersecurity risk and enterprise risk management concepts, and has spoken globally on the topic, including multiple keynote addresses. He holds multiple industry certifications and is a member of the New York State Bar Association.
 
Brandon Bapst is a Cyber Risk Advisor in EY’s Cybersecurity practice. He works closely with executives, CSOs and CISOs on developing mature cyber risk programs. He has worked with Global Fortune 500 companies to transform tactical security programs into holistic enterprise security risk management practices enabled through data driven insights and technology. Brandon is a Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), and Certified Information Systems Auditor (CISA).

Amazon page

下载地址 Download解决验证以访问链接!
打赏
未经允许不得转载:finelybook » Building a Cyber Risk Management Program: Evolving Security for the Digital Age

评论 抢沙发

觉得文章有用就打赏一下

您的打赏,我们将继续给力更多优质内容

支付宝扫一扫

微信扫一扫