Managing Risks Through Taxonomies

No ratings

Presented at FirstConferenceKualaLumpur 2018 by

Communicating the value of Security practices and incident response capabilities is challenging. After all, Security only costs money, doesn't it? CISOs are interested in Risks, and mean things like reputation, outages, loss. Security professionals on the other hand talk about vulnerabilities, access vectors and the like, which is reflected in most of the available taxonomies.We try to combined the two worlds by creating a multi dimensional taxonomy, which relates the How to the what. The goal is to identify the largest risks to an organisation so resources can be properly allocated. The proposed mechanism helps creating bridges between technically oriented security staff and financially driven executives. It should, at the end of the day, help demonstrating the value of security.