Thursday, October 9, 2014

Every Company Must Be Able to Answer These Questions

I give a number of presentations on cyber security, cyber threats and cyber investigations each year.  And by a "number" I mean 50 in the last 14 months.

No matter the talk, the audience or the venue the follow on question is always the same; "What do you recommend we do?"

To that end, below are 9 questions that every company must be able to answer when addressing Cyber Security issues-

Who specifically is responsible for information security within you company?

Who decides who has access to what information within your company?

What company data is the most valuable, who has access to it and what are the threats against it?

Can you see what is coming in AND going out of your system?

When was the last cyber security audit conducted, by whom and where is the report?

Does your company have a threat awareness program for employees, management and day-to-day operations?

Who is responsible for monitoring social media and the internet for threats and attack information?

Do you have a cyber incident response, management, remediation and resiliency plan?

Are you willing to go public to stop a breach?

If you cant answer these questions you have a problem

No comments:

Post a Comment