24Cybersecurity Control Assessments and Cyber Risk

DOI: 10.4324/9781003052616-30

Security program design must start with a risk assessment: enterprise risk, business risk, regulatory risk, technology risk, industry risk. And you must keep looking at what's happening in the world right now that could heighten these.

Tim Callahan, SVP & Global CISO, Aflac

Nothing new here

A cybersecurity control assessment is a required as part of any organization's cyber risk management and compliance strategy. Cybersecurity control assessments are nothing new. They have been in place for decades in many different forms.

Various industries stipulate a legal obligation to perform a cybersecurity control assessment. For example, under HIPAA (Health Insurance ...

Get Enterprise Cybersecurity in Digital Business now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.