Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Brian Allen, Brandon Bapst, Terry Allan Hicks

Rating No ratings yet

No description

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
# Building a Cyber Risk Management Program ## 【One-Line Pitch】 A practical framework for designing, implementing, and sustaining a cyber risk management program that satisfies regulatory obligations, board oversight demands, and real-world security needs. Essential reading for CISOs, risk practitioners, corporate directors, and auditors who need both strategic vision and tactical execution guidance. ## 【Book Arc】 - **Opening (~0%–20%)**: Establishes why cyber risk management has become an urgent enterprise priority in the age of digital transformation, introducing the book's core promise: a complete framework for building a defensible, sustainable program that addresses legal, regulatory, and board-level expectations. - **Early (~20%–40%)**: Defines the four components of a formal cyber risk management program and examines the key legal and regulatory drivers—including SEC disclosure rules and case law—that make this work mission-critical. Uses the Boeing 737 MAX disasters as a cautionary case study of what happens when risk management fails. - **Middle (~40%–60%)**: Introduces Agile Governance as the first program component, detailing seven principles covering policies, the "Three Lines Model," alignment with existing risk frameworks, board scope definition and oversight, auditing, and resource alignment. The Uber hack cover-up illustrates governance failures. - **Middle (~60%–80%)**: Covers the Risk-Informed System and Risk-Based Strategy and Execution components—establishing risk assessment frameworks, thresholds, reporting processes, and aligning strategy and budget with approved risk tolerances. Contemporary examples include ChatGPT's disruption and divergent AI risk approaches at major tech firms. - **Late (~80%–100%)**: Addresses Risk Escalation and Disclosure, including SEC materiality considerations, the Equifax scandal, and five principles for escalation and disclosure processes. Concludes with implementation guidance—how to actually build the program, sell it internally, and apply it to operational risk and resilience. ## 【Key Takeaways】 - **Cyber risk management is fundamentally a risk practice, not just a security concern** (Early): Digital transformation has made cyber risk a board-level enterprise issue requiring formal management programs, not isolated technical fixes. - **Four components form the complete program framework** (Early): Agile Governance, Risk-Informed System, Risk-Based Strategy and Execution, and Risk Escalation and Disclosure work together as a systematic—though not zero-risk—approach to managing cyber threats. - **Legal and regulatory drivers make cyber risk programs mandatory** (Early): SEC disclosure rules, international standards, and case law create concrete obligations and liability exposure for enterprises and their leaders, including CISOs personally. - **Agile governance requires seven specific principles** (Middle): From establishing policies and the Three Lines Model to board-defined scope, oversight, auditing, and resource alignment—governance must be systematic and continuously adapted. - **Risk information must flow to the highest levels** (Middle): A risk-informed system requires defined assessment frameworks, methodology for thresholds, agreed assessment intervals, and reporting processes that make risk visible to decision-makers. - **Strategy and budget must align with approved risk thresholds** (Middle): Risk-based execution means defining acceptable risk levels, aligning resources accordingly, monitoring continuously, auditing against thresholds, and including third parties in treatment plans. - **Escalation and disclosure are mandatory, not optional** (Late): The Equifax scandal and SEC materiality rules demonstrate that enterprises must establish, test, and audit escalation and disclosure processes—for public companies and all enterprises alike. - **Implementation is a journey requiring internal selling** (Late): Building the program involves practical steps across all four components, plus the crucial work of persuading stakeholders and embedding the program into operational risk and resilience functions. ## 【Reading Tips】 - **Deep-read Chapters 2–3** for the foundational framework and governance principles—these establish the mental model that everything else builds on. The Boeing and Uber case studies make abstract governance concepts concrete. - **Skim the regulatory history sections** if you're already familiar with SEC disclosure rules; focus instead on the practical principles at the end of each chapter, which are the actionable takeaways. - **Pay special attention to the "Bottom Line" summaries** at each chapter's end—they distill the essential points and work well as quick reference material after your first read. - **Read Chapter 7 (Implementation) with your own organization in mind**: the journey from beginning to selling the program internally is where theory meets practice, and it's most valuable when you map it to your context. - **Expect contemporary examples rather than timeless theory**: ChatGPT, Equifax, and the Boeing 737 MAX anchor the discussion in recent events, which helps but may date quickly. ## 【Coverage Limits】 The excerpts primarily cover the book's table of contents, chapter structure, and key principles; detailed explanations of each principle, specific implementation tactics, and the operational risk/resilience application in Chapter 8 are only partially visible in the source material. ##
Excerpt 1
书名: Building a Cyber Risk Management Program (Brian AllenBrandon BapstTerry Allan Hicks) (Z Library) 作者: Brian Allen, Brandon Bapst, Terry Allan Hicks Brian ...
View in text
Page 2
l standards, case law, regulation, and board-level guidance. This book helps you: • Understand the transformational changes digitalization is introducing and...
View in text
Page 3
nal sales department: 800-998-9938 or corporate@oreilly.com. Acquisitions Editor: Simina Calin Development Editor: Sara Hunter Production Editor: Katherine T...
View in text
Page 4
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1 The Fourth Industrial Revolution 3 Cybersecurity Is Fundamentally a Risk Practice 6 Cyber Risk ...
View in text
Page 5
e Uber Hack Cover-Up 43 What Does Good Governance Look Like? 44 Aligning with the Enterprise Governance Strategy 46 Seven Principles of Agile Governance 49 P...
View in text
Excerpt 6
to Meet Approved Risk Thresholds 93 iv | Table of Contents Principle 4: Monitor on an Ongoing Basis 95 Principle 5: Audit Against Risk Thresholds 96 Principl...
View in text
Tags
AI categories
CybersecurityBackendTechnology
Publisher: O'Reilly Media
Publish Year: 2024
Language: English
Pages: 222
File Format: PDF
File Size: 3.1 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…