Cybersecurity RoadMap
Cybersecurity RoadMap
- Details
- Written by: Robin Basham
- Parent Category: Services
- Category: Cybersecurity RoadMap
Why Risk Management? Enterprise Risk Management has become a mandated business function involving the security of the entire organization. If you are tasked with designing an ERM you may be wondering “is my goal to determine if we are secure or if we can enable a more secure enterprise? Am I expected to engage business partners, provide meaningful metrics, to inform choices and decisions? Does the organization expect me to account for security responsibilities or am I the provider of a business service?"
… “yes”
This presentation is the largest body of work that we've committed to training. It takes 6 hours to deliver and involves quite a bit of discussion and activities. We hope you get some great ideas and encouragement.
- Hits: 4842
- Details
- Written by: Robin Basham
- Parent Category: Services
- Category: Cybersecurity RoadMap
AICPA Cybersecurity Risk Management Examination Report
Now what? In the midst of GDPR, new PCI DSS 3.2 standards, and expanded controls for all privacy aspects of your SOC 2, things just got ratcheted up another notch. The AICPA has released its Descriptions Criteria for the examination of the Entity's Cybersecurity Risk Management Program. Needless to say, the evidence requirements are piling up. EnterpriseGRC Solutions has already loaded this standard to our existing SOC2 and other assessment and mapping programs. To help you assess where this new guidance will be sending your external auditors, we've included a summary of the text below.
- Hits: 1182
Read more: AICPA Cybersecurity Risk Management Examination...
- Details
- Written by: Robin Basham
- Parent Category: Services
- Category: Cybersecurity RoadMap
National Vulnerability Database - The National Vulnerability Database (NVD, http://nvd.nist.gov) has expanded its scope to enable organizations to automate and standardize vulnerability management, security measurement, and compliance reporting (e.g., FISMA). Thus, NVD now enables Federal agencies and other organizations to ensure that information technology assets are configured securely, automate technical control FISMA compliance checking, customize secure configuration requirements, standardize the measurement of low-level vulnerabilities, and integrate vulnerability and product databases using a standards-based approach.
- Hits: 565
- Details
- Written by: FIDO
- Parent Category: Services
- Category: Cybersecurity RoadMap
What is FIDO? FIDO is the World’s Largest Ecosystem for Standards-Based, Interoperable Authentication
BETTER SECURITY FOR ONLINE SERVICES, REDUCED COST FOR THE ENTERPRISE, SIMPLER AND SAFER FOR CONSUMERS
- Hits: 594
Read more: Usability, Security, ROI, and Privacy - Why FIDO...
- Accountability vs. Compliance in the Cloud
- FIDO IOT Authentication Experience
- Industry Requirements Drive Cyberthreat Resilience
- Catastrophic Becomes Routine - NIST Cybersecurity and Critical Infrastructure
- NIST SCAP & XCCDF
- Did I do That?
- RiskWatch
- Center For Internet Security Critical Security Controls V.8.1
- Networking and Security Topics for CISSP Study

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics