Posts

Showing posts from March, 2021

Book review: Cyber Strategy

Image
Cyber Strategy Risk-driven Security and Resiliency Authors: Carol A. Siegel and Mark Sweeney Publisher: Auerbach/CRC Press ISBN: 978-0-367-45817-1 Price: ~ US$100 + shipping from Amazon Outline This book lays out a systematic process for developing corporate strategy in the area of cyber (meaning IT) security and resilience.   Pros An in-depth exposition on an extremely important topic It emphasises risks to the business, to its information, and to its IT systems and networks, in that order Systematic, well structured and well written, making it readable despite the fairly intense subject matter Lots of diagrams, example reports and checklists to help put the ideas into action Treating strategy development as a discrete project is an intriguing approach Cons Describes a fairly laborious, costly and inflexible approach, if taken literally and followed STEP-by-STEP Implies a large corporate setting, with entire departments of professionals specializing and willing to perform or help out