Session: Security Risk Prioritization: Lessons Learned for making smarter security decisions
With the prevalence of specialized tools tailored to security monitoring and posture checking, there is an opportunity for organizations to automate the risk registry feeds and reporting structure.
A successful risk program enables the service owners to frequently act on and work towards addressing the identified risk. Security Risk Prioritization and Quantification matures the program and helps achieve this goal by enabling the decision-makers to allocate resources to activities with the most impact on the organization’s security posture.
Complexities in the realm of Technology may include tool selection, compatibility, and integration. Details relevant to these, coupled with data availability concerns, existing process inadequacies in a complex ecosystem, and logic and algorithm development, present challenges but also allow us to tailor the solution to an organization’s unique needs. In this presentation, we will review some of the commonly seen pitfalls and review options to avoid them.
Bio
Nas initially started in R&D and quickly found her way to the realm of information security and data protection when she noticed the gap in security practices in research environments. She has experience as the security architect for both large enterprise-wide solutions as well as client-focused product security solutions in different financial, research, telecommunications, and data services industries.
Nas lives in the Bay Area, is an avid camper and proud plant parent and also has a side interest in debates.