The Ultimate Goal of Organizational Cybersecurity

Cybersecurity experts agree: Governance, Risk and Compliance (GRC) are essential to successful cybersecurity programs. The sticky wicket is how to start and build a GRC program. The Cybersecurity Risk Foundation has developed a model to assist organizations with creating and growing their GRC program, with seven steps. The first step of the CRF Governance & Risk Model (CRF-GRM) is to define the goals of the organization’s cybersecurity program. Even with established programs, benefits of defining the program’s goals include establishing clear understanding among organizational leadership, cybersecurity staff, and operations and business lines. This first step (“Initiate”) answers questions such as: Why is a GRC program needed? Why is cybersecurity needed? What are the goals for this program? Who will make decisions related to this program? This step essential prompts to specifically define the organization’s goals for cybersecurity as well has how those goals will be translated into action.

A simple answer to the ultimate goal of a cybersecurity program for an organization might be to maintain the confidentiality, integrity, availability, and privacy of the organization’s data and services. This may answer the “Why?”, but this simple answer leaves out the “Who?” and “How?”. For example, consider the roles of cybersecurity staff and operations staff. Is it the cybersecurity staff’s role to determine which safeguards should be implemented and then require that the operations staff implement these safeguards? Or is it the business operation’s decision to determine which data/systems/services are threatened and need protection, with cybersecurity personel available to assist with the details of how to provide that protection? Or should a committee with representatives from business and cybersecurity roles make these decisons?

Additionally, how do legal requirements, ethical requirements, customer expectations and other “reasonable” cybersecurity expectations fit into the goals for the cybersecurity program? Defining the specific laws that apply to the organizations cybersecurity/GRC program in this initiate phase establishes a clear understanding that the program will be implemented to follow these laws and expectations.

Organizations often follow a cybersecurity framework such as the CIS Controls or NIST CSF as a roadmap for which safeguards to implement. Defining which framework will be uiltized and related goals provides clarity.

For organizations that already have a cybersecurity program in place, this initiate phase may seem unnecessary. But going back to these initial questions, writing down the ultimate goal(s) of the program and how those goals will be further definied and implemented can prevent future conflict and misunderstanding while improving the organization’s cybersecurity culture and compliance.

Here are questions to help get started with a Cybersecurity/GRC program charter document:

  • What are the goals of the program? Why is a program needed?
  • Who is responsible for implementation of the program? Who will be consulted or contribute to making program decisions?
  • Will a cybersecurity framework be utilized? If so, which framework? Include specifics such as implementation group.
  • How will compliance with safeguards be verified/audited? With what frequency?
  • What laws or guidlines apply to the program?

Resource

Cyberssecurity Risk Foundation Governance & Risk Model