Jon King’s Post

View profile for Jon King, graphic

Learning by doing, leading, and coaching

A lot of system admins seem to either be asking or are being asked the question: "Why should we keep antivirus/EDR if it can cause the kind of damage we saw from the Crowdstrike incident?" We have to guide the conversation to the right questions, not the easy questions. This isn't a question about avoiding risk, it's a question about aligning risk posture to strategy. "What does our organization require for operations and competitive advantage?" "How do InfoSec capabilities support our ability to operate?" or "What will go wrong and how can we provide assurance?" "What requirements or limitations exist that can help inform our selection of technologies to deliver an InfoSec capability?" "Are our InfoSec capabilities enhancing our competitive advantage?" This aligns at a high level with the questions that frame the "Threat Modeling With ATT&CK" project. It's a good read and worth the time. https://lnkd.in/gGU3F8EX

To view or add a comment, sign in

Explore topics