Minimum Viable Security: Build It and Keep It Running
カートのアイテムが多すぎます
カートに追加できませんでした。
ウィッシュリストに追加できませんでした。
ほしい物リストの削除に失敗しました。
ポッドキャストのフォローに失敗しました
ポッドキャストのフォロー解除に失敗しました
-
ナレーター:
-
著者:
Antivirus, backups, and MFA are a start. They won't tell you how payroll runs when the check printer is inaccessible or keep your risk register current six months later. This week, Jared and Mike talk about what a small business actually needs and how to keep that work going.
- Identify the client's critical data and the processes that keep the business running.
- Check the less obvious dependencies, from break-glass accounts to the payroll check printer.
- Use CIS Implementation Group 1 as a starting point, then keep improving.
- Schedule user audits, policy reviews, and risk assessments as recurring work.
We answer:
- What should a 50-person company with antivirus, backups, and MFA be doing repeatedly to have a minimum viable security program?
- How do you keep that program alive when policies go stale, evidence goes missing, and nobody updates the risk register?
Make sure to follow the podcast or ask your own questions at: https://blacksmithinfosec.com/nisty/