A new company’s risk management function is developing its cybersecurity risk management program Which of the following actions should be the first priority when developing the program?
A.
Start building a cybersecurity culture and set the desired behavior using a bottom-up approach
B.
Determine the cybersecurity framework that will establish and report on the effectiveness of the program
C.
Define the cybersecurity risk appetite and perform a cost-benefit analysis of the program
D.
Raise cybersecurity awareness across various departments outside of the IT department
When developing a new cybersecurity risk management program, the first priority should be to define the cybersecurity risk appetite. This involves setting the acceptable level of risk the organization is willing to tolerate and is critical to guide the scope and focus of the cybersecurity initiatives. Performing a cost-benefit analysis of the program at this stage is also crucial to ensure that the planned measures are economically viable and align with the organization’s strategic objectives.
Best practices in cybersecurity risk management
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit