Strategic Cybersecurity Governance
摘要
This chapter consolidates all the relevant literature, guidelines, concepts, standards, best practices, and material we have covered in the preceding nine chapters to propose a comprehensive and practical enterprise cybersecurity governance framework. The purpose is to offer a model, the “Strategic Enterprise Cybersecurity Governance Model” (ECyG-M), that incorporates the significant strategies, policies, systems, procedures, and preventative and corrective measures that firms can take to safeguard the CIA attributes of information system assets. A business’s strategies, policies, procedures, and actions to manage and protect its digital assets and customer data from cyber threats form part of the cybersecurity value chain. We incorporate the critical governance elements and capabilities presented in the preceding chapter into the strategic cybersecurity model. The ECyG-M approach can help reduce cyber risk exposure through a robust and comprehensive governance regime. The ECyG-M and its inherent value chain, created by adopting an ERM approach, offer a thorough and integrated method for cybersecurity risk management across the organization. Organizations can use the ECyG-M structured processes to identify, evaluate, prioritize, and manage cyber risks to accomplish their strategic goals.