Ideas and field notes

Blog

Practical writing about cybersecurity, compliance, and sustainable security operations.

The risk assessment that should come first

A risk assessment tells the organization which risks it actually has. Nearly every other governance activity, the policy review included, is guesswork without it.