Chapter 9. Cloud Security Governance and Risk Management
Topics covered in this chapter include:
-
Risk management
-
Compliance
-
Policies, standards, and procedures
-
Business continuity
-
Disaster recovery
A good security program requires oversight. Ultimately, information security serves at the pleasure of the business, if you will. The objective is to help the business achieve its objectives, regardless of what they are. If the information security program is not aligned with the business, it can get completely out of sync to the point where the information security function can become an obstacle, which may slow or hamper the business in achieving its expected outcomes.
This requires information security to follow the lead of the business rather than vice versa. Without insight from the business about what the overall objectives are, how can the security team know what they are protecting or why? This means the business needs to establish the overall vision for the security function and ensure there is sufficient interaction so both parts of the equation understand what the other is doing.
Fortunately, there are frameworks available to help ensure there is alignment between the business and the security function. To begin with, the business is generally going to want to understand how its information technology assets incur risk. This is an area where there may be misalignment unless the information security function clearly follows the business and they are using the same ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access