Is it Time to Give Your Information Security Policies a Refresh?
Most organizations answer that question with: “examiners haven’t had any issues with them, they’re just fine.” In some cases, that may be true, but...
As institutions grow, examiners expect that their cybersecurity maturity will also grow. Unfortunately, many institutions learn this the hard way when they receive high-risk findings during an IT exam. The security practices that were acceptable before are suddenly not enough.
The key to acing an IT exam is for the institution to demonstrate that they are proactively pushing their cybersecurity program to the next maturity level. Each institution should have a strategic roadmap that ensures that this level keeps up with business growth. This week, we look at some of the things you can focus on to make sure you look good during your next exam.
Most organizations answer that question with: “examiners haven’t had any issues with them, they’re just fine.” In some cases, that may be true, but...
The National Institute for Standards and Technology released an update to its Cybersecurity Framework (CSF) late February. The CSF was originally...
We are seeing findings related to change management cropping up in several audit reports this year. Appropriately scoping change management can be...