A Standards-Based Approach to Assessing Your Organization's Cybersecurity Maturity

No ratings

Presented at BSidesAustin 2019 by

We were tasked with creating a roadmap for the National Instruments Information Security Program. While we had previously used a Gartner Maturity Model to figure out how far along our organization was, we found their recommendations to be too high level to define a roadmap. After some discussion, we determined that we could use the NIST Cybersecurity Framework to not only assess our maturity, but define risk in our environment, and create a roadmap. This talk will not only show you how we did it, but how you can do it too!