Daniel C.’s Post

The ‘Getting started at CYBER’ List When you go into a new org what do you need at a minimum? LOADS! But let’s give this a go at showing the world some of the key artefacts you are going to need when you start discovery (this might be as part of a job onboarding process or from a project perspective). This is both specific and general because the detailed list if organisational specific and contains a load of generic ITSM process areas etc. and if you want the long list either open excel or do a project with a friendly consultant ;) ! right onto a bit of a list! ·      An enterprise context statement ·      An organisational chart (Business and IT) ·      A copy of any relevant internal policies (e.g. security policies + more) ·      A copy of the key customer contractual requirements ·      A copy of the key suppliers’ contracts ·      A view of the financial landscape ·      A risk appetite statement ·      A security mission statement ·      Traceable goals and objectives ·      A view of the enterprise architecture at a reasonable level of abstraction ·      Network Diagrams ·      Previous security documentation (e.g. Audits, Vulnerability Reports, Pentest, Assessments, certifications etc.) ·      A high-level view of key supply chain interactions ·      A high-level view of key business processes ·      A crown jewels analysis ·      Zoomed in details on key business areas and services ·      Supplier registers ·      An asset register ·      Any relevant Polices, processes, procedures, SLAs/OLAs etc. ·      Public DNS Zone Exports ·      Lists of Public and Private Networks/Subnets etc. Anyway, I hope that gives people an idea of what the start of the world of discovering what the security posture of an organisation is like!

  • No alternative text description for this image

And if you don’t have this, you need to work to get it!

To view or add a comment, sign in

Explore topics