Category: Governance, Risk and Compliance

  • Policy

    Policy

    A policy is not yet an operational control.

    Organisations invest considerable effort developing cybersecurity policies, standards and control frameworks.

    That is important. But approving a policy does not mean the risk is actually being controlled.

    A policy might state that security events must be monitored, suspicious activity investigated and incidents escalated.

    The operational questions are different:

    • Who monitors the environment?

    • What exactly is being monitored?

    • Which events require investigation?

    • What determines when an alert becomes an incident?

    • Who must be notified and when?

    • What happens outside normal working hours?

    • How are actions and decisions recorded?

    • How does management know the controls are actually working?

    This is where governance must connect with operations.

    A useful way to think about the control chain is:

    Policy → Process → Procedure → Execution → Evidence → Assurance

    A Security Operations Centre, for example, can provide sophisticated monitoring, detection and response capabilities.

    But technology and monitoring alone do not complete the chain.

    The SOC must operate within clearly defined processes, responsibilities, escalation requirements and governance—and produce evidence that allows the organisation to determine whether its security controls are effective.

    That distinction matters.

    A policy states the intention.

    Evidence shows whether it works.

    #CyberSecurity#SOC#SecurityOperations#GRC#InformationSecurity#Governance#Lapperra

  • Security tools

    Security tools

    More security tools do not automatically create better security.

    Modern Security Operations Centres can have access to an impressive technology stack.

    SIEM. EDR. NDR. Threat intelligence. Vulnerability management. SOAR. Cloud-security tools. Identity monitoring.

    Each can provide valuable capabilities.

    But adding another security tool also creates more alerts, more telemetry, more integrations and potentially more complexity for the people expected to make sense of it.

    That raises an important question:

    How should an organisation determine whether its SOC is actually effective?

    The answer shouldn’t simply be the number of tools deployed, alerts generated or events processed.

    Management should be asking questions such as:

    • Do we have visibility across the systems that matter?

    • Are meaningful threats being detected?

    • How quickly are alerts investigated and prioritised?

    • Are genuine incidents escalated to the right people?

    • Can threats be contained before significant damage occurs?

    • Are recurring weaknesses identified and addressed?

    • Does management receive useful evidence about security performance and risk?

    Automation and AI can increasingly help correlate information, prioritise alerts and reduce repetitive analyst work.

    But they do not eliminate the need for well-defined processes, competent people, clear escalation criteria and human judgement.

    An effective SOC isn’t defined by how much technology it has.

    It is defined by how effectively it can detect, understand, respond to and provide assurance about security threats.

    #CyberSecurity#SOC#SecurityOperations#GRC#CyberResilience#InformationSecurity#Lapperra