Difference between revisions of "User:Shawndouglas/sandbox/sublevel3"

From LIMSWiki
Jump to navigationJump to search
Line 1: Line 1:
<blockquote>By seeking and blundering we learn. - Johann Wolfgang von Goethe</blockquote>
How often should you review and update this labor of love and sacrifice your organization has developed? Some may argue that an annual review of the cybersecurity plan is enough, while others may insist such a review be biannual. In the end, the time frame will largely be an organizational decision that also could be revised over time based upon the results of your performance indicators and monitoring activities. What's important is that you 1. decide how often to review it, 2. declare who will be in charge of the review, 3. determine how and what opinions and data from stakeholders will be incorporated, and 4. how any changes will be disseminated into documentation and training programs.
 
Your organization has sought out being more aware of cybersecurity issues and has enacted a plan and controls to fight against various cybersecurity threats. Yet during that process your organization has also hopefully learned that no one is 100 percent secure. Incidents happen. Control settings get overlooked. Attack vectors change. When these issues come up, it takes more than fixing the problem to improve a process or system. The incident, overlooked process, or new knowledge must be analyzed, documented, and disseminated in order for everyone to learn and improve. This is why the organization must—in addition to monitoring and assessing the plan's effectiveness—document occasions of "blundering" and incorporate any new observations or lessons (e.g., using an after-action report) back into the current plan.<ref name="NARUCCyber18">{{cite web |url=https://pubs.naruc.org/pub/8C1D5CDD-A2C8-DA11-6DF8-FCC89B5A3204 |format=PDF |title=Cybersecurity Strategy Development Guide |author=Cadmus Group, LLC |publisher=National Association of Regulatory Utility Commissioners |date=30 October 2018 |accessdate=23 July 2020}}</ref> Which leads to...
 
==References==
{{Reflist}}

Revision as of 20:19, 16 February 2022

How often should you review and update this labor of love and sacrifice your organization has developed? Some may argue that an annual review of the cybersecurity plan is enough, while others may insist such a review be biannual. In the end, the time frame will largely be an organizational decision that also could be revised over time based upon the results of your performance indicators and monitoring activities. What's important is that you 1. decide how often to review it, 2. declare who will be in charge of the review, 3. determine how and what opinions and data from stakeholders will be incorporated, and 4. how any changes will be disseminated into documentation and training programs.