No matter the industry that you work in or the maturity of your business, questions about the security of your systems and your users' data will always be present. If you are a leader in tech, you're probably sat somewhere between having a constant nagging feeling that you should be doing more, to having sleepless nights about missing something that could take the entire company down.
Security Frameworks can help you to both design and implement secure systems and illuminate your commitment to security. But when is the right time to start using a security framework, such as NIST CSF, SOC 2, or ISO 27001?
Stating risks in a clear, concise, and consistent manner enables more effective communication and risk prioritization.
The widely used phrase “strong opinions loosely held” (otherwise known as “strong opinions weakly held”) is just one approach for sharing your opinions, and carries risks of driving behavior and culture that you don’t want. So how else can we express our opinions, and when do different approaches work best?
Risks are everywhere, both known and unknown. Using the Cynefin framework can guide us in approaches to identifying different types of risks.