Risk the Business Will Act On
Risk to the business, not technical risk. How exposure is assessed, costed, owned, accepted and written down so that somebody with a budget actually does something about it — and how to tell when the loudest number on the page is the wrong one.
- trending_upIntermediate
- schedule7h 1m
- menu_book12 पाठ
- publicEnglish
- workspace_premiumBasic
ब्रीफ़िंग
There is a findings list somewhere in your organisation with the same three items on it that were on it two years ago. Nobody disputes them. Nobody has funded them. That is not a technical problem and no amount of further scanning will solve it. This segment is about the gap between a true statement and a decision. A vulnerability score describes a flaw in software; it was calculated by people who have never heard of your company and it cannot rank two of your systems against each other. What ranks them is what the business would lose, how likely that is, how long you would take to notice, and what the fix costs against what carrying it costs. All four of those are estimates, all four can be done honestly, and the honest version is more persuasive than the confident one. Across four modules you rank four competing risks on a fixed budget and defend the order, put ranges and a stated basis on likelihood instead of a five-by-five cell that quietly hides the thing that matters, cost a fix against a risk on one page with every assumption marked verified or not, separate inherent from residual and stop reporting one while meaning the other, place ownership where the consequence lands — which is never with the security team — and drill the one-sentence form until it is automatic: if X happens, Y is exposed, costing roughly Z, and we would find out W days later. You finish with three artefacts: three risks written so they can be funded, one costed comparison, and a written risk acceptance with a named owner, conditions and a review date. An acceptance nobody signed is not an acceptance, and a register with four hundred rows in it is a place where four serious risks are stored where nobody will find them. Every money figure in this segment is illustrative. The numbers are shaped so the arithmetic behaves realistically; none of them is a claim about what anything costs in the real world, and none of them should be quoted as one.
कोर्स रूपरेखा · 4 मॉड्यूल
lockएक्सेस के साथ अनलॉक होता है- 01 Risk to the Business, Not Technical Risk3 पाठ·1h 34m
Somebody calculated that score. They were describing a flaw in a piece of software, they had never heard of your company, and they had no way of finding out which of your systems is holding the thing…
- 02 Putting Numbers On It Honestly3 पाठ·1h 50m
You do not know how likely most of these things are. Nobody does. That is not a reason to stop estimating, it is a reason to estimate in a way that survives being wrong — which means ranges, a basis…
- 03 Residual Risk, Appetite and Ownership3 पाठ·1h 8m
The gap between the exposure before controls and the exposure after them is what your security spend bought. Nobody in most organisations has ever been shown that sentence, and it is the reason the…
- 04 Making It Fundable3 पाठ·2h 29m
Most of this job is narrative and persuasion, and that is a mechanism rather than an aside. A risk that is understood gets funded and a risk that is not understood does not, and the difference is…
अक्सर पूछे जाने वाले
- मैं Risk the Business Will Act On में क्या सीखूँगा?
- Risk to the business, not technical risk. How exposure is assessed, costed, owned, accepted and written down so that somebody with a budget actually does something about it — and how to tell when the loudest number on the page is the wrong one.
- क्या मुझे पूर्व अनुभव चाहिए?
- Risk the Business Will Act On शुरू करने से पहले कुछ पूर्व ज्ञान की सिफ़ारिश की जाती है।
- Risk the Business Will Act On में कितना समय लगता है?
- Risk the Business Will Act On में 4 मॉड्यूल और 12 पाठ शामिल हैं। आप अपनी गति से सीखते हैं।
- मुझे एक्सेस कैसे मिलता है?
- Risk the Business Will Act On किसी भी सशुल्क सब्सक्रिप्शन के साथ शामिल है।