Skip to Content
The Cybersecurity Control Playbook
book

The Cybersecurity Control Playbook

by Jason Edwards
April 2025
Intermediate to advanced
544 pages
20h 19m
English
Wiley
Content preview from The Cybersecurity Control Playbook

Appendix EDeveloping Process Maps

Process mapping and risk identification are critical steps in building a strong cybersecurity posture, especially for large enterprises where complexity can obscure vulnerabilities. This appendix is a practical guide and checklist for teams new to process mapping, helping them systematically identify risks, apply appropriate controls, and distinguish between key, non‐key, compensating, and common controls.

By following this guide, teams can comprehensively understand their organization's processes, identify risks, and ensure that appropriate controls are implemented to safeguard critical assets and comply with regulatory requirements. This structured approach improves security and enhances the efficiency and effectiveness of business operations.

Process Mapping and Risk Identification Guide

  1. Define the Process Scope
    • Objective: Clearly define the scope of the process being mapped. This could be a specific business function (e.g., accounts payable, customer data management) or interrelated activities.
      • Checklist:
        • Identify the business function or department responsible.
        • Define the start and end points of the process.
        • Specify key outputs (e.g., reports, services) and inputs (e.g., data, documents).
        • Establish the criticality of the process in relation to business operations.
  2. Document Each Step of the Process
    • Objective: Break down the process into individual steps, capturing how tasks are performed, who performs them, and the systems ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Emerging Threats and Countermeasures in Cybersecurity

Emerging Threats and Countermeasures in Cybersecurity

Gulshan Shrivastava, Rudra Pratap Ojha, Shashank Awasthi, Kavita Sharma, Himani Bansal

Publisher Resources

ISBN: 9781394331857