Chapter 46. Building a New Security Program
Lauren Zink
Building a new security program, no matter the focus, is not an easy task. Although it may be a heavy lift, there are several things one can do to help make the task a bit less daunting while ensuring overall prolonged success. Instead of thinking big picture, start by thinking a bit smaller, which is much less intimidating and easier to digest. This can be accomplished by developing a program that is broken down into smaller segments with short-term plans that will help organically develop a long-term plan and program.
A breakdown of some considerations when developing a new security program may include the following:
Understand your current foundation.
Develop a solid plan.
Engage stakeholders and employees.
Communicate and implement the program.
Develop metrics and measure the effectiveness of the program.
Be prepared for roadblocks and shifts in the initial plan.
Continually revisit and update the program plan and clearly communicate progress and changes.
Within the first 30 days, start by getting to know the teams, building relationships, and understanding the current state of affairs of the security program and the business. Meet with leadership and discuss the plan to ensure everyone is on the same page regarding their expectations for the program from day one. Make it a point to document everything, not only for ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access