How to Use Issue Management to Improve Cybersecurity

85 views
August 22, 2022
by
RSAC Cybersecurity
YouTube video player
How to Use Issue Management to Improve Cybersecurity

TL;DR

Build cybersecurity issue management around simple, risk-based controls, consistent processes, and clear business accountability. A purpose-built GRC operating model can expose control gaps, standardize escalation and exception handling, support informed decisions, and preserve cybersecurity investments by making governance sustainable across a global organization.

Transcript

Well, welcome everyone. We're so happy to have you here with us. Um, and we just applaud you for showing up at this time. You could, you could be on your flight home, but you chose to be here. We're really happy to have you. So think about your questions as we go, 'cause we can have a lot of time for interaction with the, uh, with, with this audien... Read More

Key Insights

  • Cyber GRC is an enabler of cybersecurity strategy when it helps the organization understand requirements, establish targets, coordinate work, and support transformation. Its purpose extends beyond compliance by connecting governance processes directly to cybersecurity programs and the wider digital organization.
  • A sustainable GRC program is purpose-built, right-sized, risk-based, and designed for low overhead. It should reflect the organization’s actual cybersecurity program and operating environment instead of presenting an aspirational framework containing thousands of requirements that the business cannot realistically implement.
  • A culture of cybersecurity accountability requires consistent processes, defined escalation paths, business-leader participation, and better decision support. Cybersecurity personnel should serve as stewards who provide reliable inputs, while appropriate business leaders make decisions according to the nature and level of the risk.
  • Issue management is positioned to drive broad improvement because it touches cyber defense, identity, data protection, risk management, exception handling, and other cybersecurity areas. A central process can facilitate and support these programs while creating a consolidated view of control gaps and required remediation.
  • Risk-based controls provide a practical foundation for cybersecurity governance. AES examined its own environment to identify the most important minimum requirements for sound cybersecurity hygiene rather than copying an extensive external control catalog without adapting it to the organization’s needs.
  • Standardized issue identification is necessary when business units and cybersecurity teams manage and communicate risks differently. A common process creates consistent treatment of known issues, improves global oversight, and gives business owners the information needed to make supported decisions about remediation, acceptance, or escalation.
  • Cybersecurity risk decisions belong with the business leaders who own the relevant operations or technology. The cybersecurity function supports those decisions with requirements, analysis, and escalation mechanisms, but should not automatically approve exceptions or become the sole owner of business risk.
  • Issue management focuses governance on actual conditions within the organization, including control gaps, defects, vulnerabilities, risks, and exceptions. This tactical emphasis improves visibility into the attack surface and connects policy requirements with specific actions that cybersecurity, technology, and business teams need to complete.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can issue management improve cybersecurity governance?

Issue management can improve governance by creating a consistent process for identifying, communicating, escalating, and resolving actual cybersecurity gaps. Because it touches cyber defense, identity, data protection, risk, and exceptions, it also connects otherwise separate programs. The resulting visibility helps leaders understand the organization’s cybersecurity posture and enables business owners to make informed decisions about required next steps.

Q: Why should cybersecurity GRC extend beyond compliance?

Cybersecurity GRC should extend beyond compliance because it can enable the organization’s broader security strategy. It helps teams understand cybersecurity requirements, set targets, coordinate across programs, and support digital transformation. When governance reflects the actual security program, it also protects prior investments by making improvements sustainable instead of forcing the organization to repeat the same work after processes deteriorate.

Q: How should a company design a sustainable cyber GRC program?

A sustainable cyber GRC program should be purpose-built, right-sized, risk-based, and simple enough to operate with low overhead. Its policies, standards, controls, measurements, and reporting should reflect the organization’s real environment. Rather than adopting thousands of requirements without adaptation, the organization should begin with its most important minimum cybersecurity requirements and build supporting processes around them.

Q: Who should make decisions about cybersecurity risk?

Appropriate business leaders should make cybersecurity risk decisions because the risks affect business operations, technology, and strategic objectives. Cybersecurity and GRC teams should act as stewards of the process by defining requirements, analyzing issues, supplying decision inputs, and providing escalation paths. This model replaces informal approvals from individual analysts with accountable, well-supported decisions made at the proper organizational level.

Q: Why are consistent cybersecurity processes important?

Consistent processes prevent security requirements, approvals, issues, and risks from being handled differently across business units or cybersecurity programs. They clarify what teams must do, establish predictable escalation paths, and support oversight at a global level. Consistency also reduces situations in which teams seek informal exceptions or rely on one cybersecurity analyst’s approval without a broader understanding of ownership and risk.

Q: How should an organization select cybersecurity controls?

An organization should select controls by evaluating its own environment and identifying the requirements most important for maintaining good cybersecurity hygiene. AES used risk-based controls tailored to its needs instead of copying an extensive external catalog. Beginning with practical minimum requirements gives business and technology teams a focused target, while measurement and reporting reveal where those requirements are not being met.

Q: What problems can a new cyber GRC function address?

A new cyber GRC function can address missing policies, fragmented request and approval processes, limited visibility into risks and issues, disconnected accountability, and weak global oversight. It can establish common policies, standards, controls, asset-management practices, reporting, issue identification, and decision processes. Together, these elements help replace unclear assurances that cybersecurity is acceptable with structured evidence and accountable decisions.

Q: How does issue management support informed business decisions?

Issue management supports informed decisions by documenting real conditions in the organization, including control gaps, defects, vulnerabilities, risks, and exceptions. It routes those conditions through a standardized process, provides analysis and reporting, and escalates them to the appropriate owners. Business leaders can then decide on next steps with clearer requirements, context, and accountability instead of relying on inconsistent communications or informal approvals.

Summary & Key Takeaways

  • AES began building its cyber GRC function after identifying inconsistent approval processes, limited visibility into issues and risks, no formal cybersecurity policy, and disconnected accountability. The goal was to create a sustainable governance model that supported the company’s cybersecurity strategy and digital transformation while reflecting its actual operating environment.

  • The operating model started with policies, standards, asset management, and risk-based cybersecurity controls tailored to AES. Instead of copying an extensive external control catalog, the team identified minimum requirements for cybersecurity hygiene, then established measurement and reporting processes to reveal control gaps, defects, vulnerabilities, risks, and exceptions across the organization.

  • Issue management became a central mechanism for improving cybersecurity programs and creating accountability. GRC facilitates consistent identification, communication, escalation, and decision-making while business leaders retain responsibility for risk decisions. This structure gives leadership better visibility into the organization’s cybersecurity posture and helps technology teams understand the requirements they must satisfy.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚