From the course: Building and Managing a Cybersecurity Program

Unlock the full course today

Join today to access over 24,700 courses taught by industry experts.

Solution: Optimize a cybersecurity program

Solution: Optimize a cybersecurity program

- [Instructor] So how did you do? Well, let me share with you my answers. As a reminder, here's the first question. I think audit professionals may view security first through a lens of a framework or a law, like Sarbanes-Oxley or the NIST Cybersecurity Framework. But cybersecurity professionals may start with a functional approach, such as emphasizing patch management or access management. So while they appear to be different on the surface, there's actually a lot of overlapping interests. Here's the second question. I think communication is the starting point, and developing a trusting relationship is the number one priority. Since there's an undersupply of audit professionals with tech and security skills, the CISO can be an educational resource and can deliver that through lunch and learns, technical demonstrations, and resource recommendations. In every organization I've worked at that had an internal audit team,…

Contents