This discussion is locked.
You cannot post a reply to this discussion. If you have a question start a new discussion

cybersecurity assurance

Hello all,

I am the newly appointed lead cyber authority for a large energy company.  I am interested in your thoughts on what an assurance framework or assurance model  might look like in providing an independent view on cyber risk. 


Thanks,


Mike Ramesar
Parents
  •   Hi Mike, I am sure you are enjoying your role so far and excited with the challenges you are facing on daily basis. I would be very much interested in understanding what happened to "your ask". Are you able to share some feedback within this group?

    A Security Framework is a massive topic to cover, without a clear understanding of the existing toolings and processes of the organisation + a good 360 view of all the available but market-standard practices, it will indeed a very tall order to work out the assumed model/framework.

    Yang

Reply
  •   Hi Mike, I am sure you are enjoying your role so far and excited with the challenges you are facing on daily basis. I would be very much interested in understanding what happened to "your ask". Are you able to share some feedback within this group?

    A Security Framework is a massive topic to cover, without a clear understanding of the existing toolings and processes of the organisation + a good 360 view of all the available but market-standard practices, it will indeed a very tall order to work out the assumed model/framework.

    Yang

Children
  •  A tall order indeed.  We do have a quite a lot of maturity in the space with many internal standards and processes for various parts, IT, OT, Suppliers, Regulatory, etc.