Today, I attended a CISA Sector Risk Management Agency (SRMA) meeting to discuss next steps to implement NSM-22 and the ONCD implementation plan. Here are my takeaways ( I work with two SRMA's): - The US Government is working aggressively to address cyber and physical risk - NSM-22 Goals are driving goals and objectives; a major deliverable is due in Aug.2024 - The immediate focus is on Risk Identification, followed closely by Risk Mitigation - Cybersecurity harmonization will be a key driver across all 16 critical infrastructure sectors - Software, supply chain risk is a top concern - Physical and cyber risks are in scope, both man made and natural, including human error - Expect to see FAR changes in part 40 - cybersecurity that align with NSM-22 - All critical infrastructure sector SRMA's are aiming in the same direction, some are moving faster than others. Buckle up if you work with critical infrastructure.
Richard (Dick) Brooks’ Post
More Relevant Posts
-
Are ISO and NIST standards just meaningless letters to you? Don't worry, you're not alone. Many organizations struggle to implement risk management and compliance frameworks. At SciRisk, we are here to demystify it all. As trusted risk management experts, we specialize in providing tailored solutions to help businesses like yours strengthen resilience across three critical areas: ✔ Enterprise Risk Management (ERM) Our comprehensive ERM framework will ensure you're prepared for any challenge, from regulatory changes to market disruptions. ✔ Cyber Risk Management We'll assess your cybersecurity posture, implement robust controls, and equip your team to be the first line of defense against evolving cyber threats. ✔ Supply Chain Risk Management We'll help you map vulnerabilities, implement early warning systems, and collaborate with suppliers to build a resilient supply chain. Stop feeling overwhelmed by risk management frameworks! Connect with our team today and let us handle the complexities, so you can focus on growing your business. For more information please visit our web page: www.scirisk.com
SCIRISK - Know Your Risk
To view or add a comment, sign in
-
So many places to meet up in June. Don't miss out on the opportunity to connect with Onapsis experts at the Gartner Security & Risk Management Summit. Let's discuss how we can help evolve and optimize your SAP #cybersecurity and compliance initiatives. Reserve your meeting time below! #Gartner #Onapsis #SAPsecurity
To view or add a comment, sign in
-
Zero Trust: Transforming Cybersecurity – Aligning Risk Management Framework with Zero Trust Come join us as Ms. Farhat Shah shares information on how they extended the DoD Overlay document to align Risk Management Framework Processes and Zero Trust to benefit system owners. Zero Trust (ZT) transforms DoD Cybersecurity. ZT is a cybersecurity strategy wherein security policy is applied based on context established through least-privileged access controls and strict user authentication—not assumed trust. The DoD Zero Trust Security Control Overlay, published June 2024, provides standardized expectations on how to implement ZT across the Department and associate security controls with zero trust activities and outcomes. U.S. Army took the mapping a step further to provide implementation and validation strategies for Zero Trust based on existing RMF processes. Please see flyer for registration instructions or copy and paste the following link: https://lnkd.in/ewkSfyfF
To view or add a comment, sign in
-
Step into the thrilling world of risk management in this exclusive Inside the CISO’s Office from CBTS featuring experts John Bruggeman and Tom Siu! Get ready to dive into these topics: • The interplay between physical and cybersecurity risks. • Strategies for identifying and prioritizing risks in today's dynamic landscape. • The technology and human expertise to mitigate emerging threats. • The evolving role of the CISO in driving organizational resilience and security excellence. Don't miss out—secure your spot now: http://spr.ly/6046XvNGC
Inside the CISO's Office: Navigating risks in the modern landscape | LinkedIn
linkedin.com
To view or add a comment, sign in
-
Step into the thrilling world of risk management in this exclusive Inside the CISO’s Office from CBTS featuring experts John Bruggeman and Tom Siu! Get ready to dive into these topics: • The interplay between physical and cybersecurity risks. • Strategies for identifying and prioritizing risks in today's dynamic landscape. • The technology and human expertise to mitigate emerging threats. • The evolving role of the CISO in driving organizational resilience and security excellence. Don't miss out—secure your spot now: http://spr.ly/6047kMC4Z
Inside the CISO's Office: Navigating risks in the modern landscape | LinkedIn
linkedin.com
To view or add a comment, sign in
-
🚨 What is DORA? DORA- Digital Operational Resilience Act (DORA) is aiming to bolster cybersecurity across all financial sectors. Here are the top 5 components every vulnerability management professional should be aware of: Risk Management Requirements: Organisations must adopt advanced risk management capabilities to prevent, respond to, and recover from IT-related disruptions and threats. Incident Reporting: Mandatory incident reporting to national authorities enhances transparency and response strategies across the financial sector. Digital Operational Resilience Testing: Regular testing for critical IT systems ensures readiness and resilience against disruptions. IT Third-Party Risk: DORA emphasises stringent oversight and management of IT third-party service providers, crucial for maintaining service integrity. Compliance Benefits: Adhering to DORA not only aligns with EU regulations but significantly strengthens your cybersecurity posture, enhancing trust and reliability among clients and stakeholders. Stay ahead in managing vulnerabilities and ensure your strategies are DORA-compliant! #CyberSecurity #VulnerabilityManagement #InfoSec #Risk #DORA
To view or add a comment, sign in
-
Step into the thrilling world of risk management in this exclusive Inside the CISO’s Office from CBTS featuring experts John Bruggeman and Tom Siu! Get ready to dive into these topics: • The interplay between physical and cybersecurity risks. • Strategies for identifying and prioritizing risks in today's dynamic landscape. • The technology and human expertise to mitigate emerging threats. • The evolving role of the CISO in driving organizational resilience and security excellence. Don't miss out—secure your spot now: http://spr.ly/6040XQQcK
Inside the CISO's Office: Navigating risks in the modern landscape | LinkedIn
linkedin.com
To view or add a comment, sign in
-
🔒 Introducing RMF as a Service by NTS 🔒 Navigating the complexities of the Risk Management Framework (RMF) can be challenging. NexTech Solutions LLC, we simplify this process by offering RMF as-a-Service, ensuring your organization meets compliance and security standards with ease. 🔗 Learn More: https://bit.ly/47R4M93 ⚙️ What We Offer: ✔️ Comprehensive Risk Assessments: Identify and evaluate potential risks effectively. ✔️ Tailored Security Solutions: Implement strategies customized to your specific needs. ✔️ Continuous Monitoring: Maintain compliance with ongoing oversight and updates. ✔️ Expert Guidance: Leverage our team’s expertise to streamline your RMF journey. Ensure your organization's security and compliance with the trusted RMF solutions from NexTech Solutions. Let us handle the complexities so you can focus on your core mission. #NexTechSolutions #RMF #RiskManagement #CyberSecurity #Compliance #SecureOperations
To view or add a comment, sign in
-
Step into the thrilling world of risk management in this exclusive Inside the CISO’s Office from CBTS featuring experts John Bruggeman and Tom Siu! Get ready to dive into these topics: • The interplay between physical and cybersecurity risks. • Strategies for identifying and prioritizing risks in today's dynamic landscape. • The technology and human expertise to mitigate emerging threats. • The evolving role of the CISO in driving organizational resilience and security excellence. Don't miss out—secure your spot now: http://spr.ly/6040k8nk2
Inside the CISO's Office: Navigating risks in the modern landscape | LinkedIn
linkedin.com
To view or add a comment, sign in