Chapter 79. Get Familiar with R&R (Risk and Resilience)
Shinesa Cambric
No matter where you are in your career journey, an area that all information security professionals should become familiar with is R&R. I don’t mean rest and relaxation (although those are extremely important too). The R&R all security professionals should be aware of is Risk and Resilience. These concepts are foundational to why companies hire security professionals and a key component to why our industry exists. If there isn’t a risk to an asset, there isn’t a need to secure it. Where risk does exist, processes need to be in place to protect against it. Those protections need to be multilayered and designed in such a way that a business can continue to operate despite exposure to risk. If it can’t, it ceases to exist. Risk is such an important area that there are certifications solely dedicated to understanding what risk is, calculating its effects, and determining the most cost-effective solutions for treating it.
For those who are new to information security, understanding which risks you are addressing will provide you with the high-level context for the value of the work you are performing and its importance to your company. We have to remember that security operations exist to support business objectives, and not the other way around. There are several questions you should frequently ask of yourself ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access