Cybersecurity Where You Are (video)

Episode 146: What Security Looks Like for a Security Company


Listen Later

In episode 146 of Cybersecurity Where You Are, Tony Sager is joined by Angelo Marcotullio, Chief Information Officer at the Center for Internet Security®(CIS®); and Stephanie Gass, Sr. Director of Information Security at CIS. Together, they look back on periods of transition at CIS to discuss what security looks like for a security company. Here are some highlights from our episode:

  • 00:58. Introductions with Angelo and Stephanie
  • 02:07. A pro and a con of IT consulting work
  • 04:12. The importance of soft skills in bringing the Multi-State Information Sharing and Analysis Center® into CIS
  • 06:12. Looking at security from a corporate perspective with the CIS Critical Security Controls
  • 07:08. How IT and IT security are essential to corporate strategy
  • 07:45. The use of governance to support merging three business units into an integrated security company
  • 12:04. The value of security champions in adapting to regulatory and business changes
  • 15:15. What IT and Security teams can accomplish when they work as partners
  • 17:18. The use of data to inform Board decisions and conversations around risk
  • 20:38. How getting a seat at the table helps with understanding a Board's risk appetite and communicating that out to teams
  • 25:01. How infrastructure built for growth, not the smallest business case, produced a smooth transition to work from home in March 2020
  • 29:30. Advice for folks starting out in security
  • 31.28. The importance of collaboration and culture in implementing security as an organization

Resources

  • Episode 144: Carrying on the MS-ISAC's Character and Culture
  • The CIS Security Operations Center (SOC): The Key to Growing Your SLTT's Cyber Maturity
  • Guide to Implementation Groups (IG): CIS Critical Security Controls v8.1
  • CIS Controls v8.1 Mapping to ISO/IEC 27001:2022
  • CIS Controls v8.1 Mapping to SOC2
  • CIS Controls v8.1 Mapping to NIST SP 800-171 Rev 3
  • Reasonable Cybersecurity
  • Episode 110: How Security Culture and Corporate Culture Mesh

If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

...more
View all episodesView all episodes
Download on the App Store

Cybersecurity Where You Are (video)By Center for Internet Security

  • 5
  • 5
  • 5
  • 5
  • 5

5

13 ratings


More shows like Cybersecurity Where You Are (video)

View all
Hacked by Hacked

Hacked

190 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Patrick Gray

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

655 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,023 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

418 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,041 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

181 Listeners

Hacking Humans by N2K Networks

Hacking Humans

315 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

189 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

138 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

44 Listeners