Chapter 1. Creating a Security Program
Humans are allergic to change. They love to say, “We’ve always done it this way.” I try to fight that. That’s why I have a clock on my wall that runs counter-clockwise.
Grace Hopper, “The Wit and Wisdom of Grace Hopper” (1987)
Creating or improving upon a security program can be a daunting task. With so many facets to consider, the more initial thought and planning that is put into the creation of this program, the easier it will be to manage in the long run. In this chapter, we will cover the skeleton of a security program and initial administrative steps.
Do not fall into the habit of performing tasks, going through routines, or completing configuration with the mindset of “This is how we’ve always done it.” That type of thinking will only hinder progress and harm your security posture as time goes on.
We recommend that when creating your program, you follow the steps outlined in this chapter in order. While we’ve attempted to group the remaining chapters accordingly, they can be followed as best fits your organization.
Laying the Groundwork
There’s no need to reinvent the wheel when laying the initial groundwork for an information security program. There are a few standards that can be of great use, which we’ll cover in Chapter 8. The National Institute of Standards and Technology (NIST) has a risk-based cybersecurity framework that covers many aspects of such a program. The NIST Cybersecurity Framework (CSF) 2.0 consists of six concurrent ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access