Every organization handles, in its everyday tasks, a large amount of data it needs both to run the business and to stay healthy. In Brazil there is legislation that must be followed so a company stays compliant and avoids penalties: the LGPD (General Data Protection Law), which governs how private entities, public bodies and regulators must handle personal data.
The penalties triggered a race for compliance. But it is a mistake to believe that following those rules alone guarantees a secure company when it comes to information security. That is a much broader subject, and compliance is only one of the areas under cybersecurity.
What cybersecurity actually covers
According to NIST, information security is the practice of managing and reducing the risks that affect systems, networks and data. Notice the definition revolves around risk, not compliance.
The NIST Cybersecurity Framework defines ways to catalog the organization's assets: understanding which data, systems, hardware, facilities, people and suppliers are involved. Only from that inventory is it possible to build strategies to manage the risk tied to each asset.
Without that inventory, what is left is guesswork. Knowing what you have is exactly what lets you decide what to protect first, with what priority and at what cost.
The CIA triad
Information security rests on three pillars, the CIA triad:
- Confidentiality: data is accessible only to those who should access it.
- Integrity: data is not altered improperly.
- Availability: data is available when the operation needs it.
Each function organized by the NIST framework exists to keep these three pillars intact in the organization. A compliance checklist alone cannot do that, because it merely verifies items on a list.
Without governance, there is no risk management
Meeting current regulations does not guarantee that the risks the organization is exposed to are being managed. That requires a strategy spanning the whole organization, with governance: defined owners and decision rituals.
That is the difference between a company that passes the audit and one that actually manages its cyber risk.
Comments
No comments yet. Start the conversation.