Building a Security Function From Nothing
You are the first and only security person in the company. No budget, no team, and the people who own the systems do not report to you. This segment is the first ninety days: what exists, what you can prove, what you do first, who decides, what you refuse, and what you put in front of a board.
- trending_upAdvanced
- schedule7h 35m
- menu_book12 堂課程
- publicEnglish
- workspace_premiumBasic
課程簡介
Somebody has just made you responsible for security at a company that has never had anybody responsible for security. There is no team. There is no budget line yet. There is a list of things people believe are true, an insurer or a customer who triggered your hire, and roughly nine directors who each own a system and none of whom report to you. The hardest part of this job is not technical, and pretending otherwise is the most common way a first security hire fails in year one. You will spend more of the ninety days establishing what you are allowed to decide than you spend looking at anything. The technical work is not the constraint. The constraint is that you can recommend, and somebody else has to act, and they are busy. Across four modules you find out what the company actually has rather than what it says it has, and build an ownership register that starts completely empty and gets filled by asking humans, one row at a time. You write the one page that says what this function will do and what it will not do, and take it to your sponsor for one signature. You work out the three things worth buying with a first budget, the argument for hiring nobody yet, and how to survive forty-five minutes with a finance director. Then you build a ninety-day plan with real dates and write the first board update on one side of paper. You will also learn to distrust your own progress. The activities that demonstrate a security function exists are rarely the ones that reduce risk, and the quiet unglamorous fix that would have prevented the incident is invisible to everybody above you unless you deliberately make it visible. Nothing in this segment produces a policy, a risk register or a gap assessment. Those belong to the segments that own them, and this one tells you when to start them rather than doing them for you. Every figure in it is ranged and dated and is illustrative, because the real numbers depend on your industry, your country and your year.
課程大綱 · 4 個單元
lock隨存取權限解鎖- 01 Week One, Before You Change Anything3 堂課程·1h 45m
The instinct in week one is to fix something, because fixing things is what you are good at and what makes you feel useful in a building where nobody knows you yet. Every hour spent fixing in week…
- 02 The Operating Model3 堂課程·1h 41m
You have authority over nothing and responsibility for everything, and no amount of enthusiasm closes that gap. What closes it is writing down who decides what, getting one person senior enough to…
- 03 The First Budget3 堂課程·1h 50m
A first budget is small, it is watched, and what you do with it decides whether there is a second one. The most common mistake is buying a platform that needs a person to run it, which converts your…
- 04 Ninety Days, Reported Upward3 堂課程·2h 19m
At day ninety somebody will decide, quietly, whether hiring you was a good idea. That decision is made on what they have seen, not on what you have done, and the two are different sets. The job in…
常見問題
- 我將在 Building a Security Function From Nothing 中學到什麼?
- You are the first and only security person in the company. No budget, no team, and the people who own the systems do not report to you. This segment is the first ninety days: what exists, what you can prove, what you do first, who decides, what you refuse, and what you put in front of a board.
- 我需要事先具備經驗嗎?
- 建議在開始 Building a Security Function From Nothing 前具備一些先備知識。
- Building a Security Function From Nothing 需要多長時間?
- Building a Security Function From Nothing 包含 4 個單元和 12 堂課程。你可以按自己的進度學習。
- 我如何取得存取權限?
- Building a Security Function From Nothing 包含在任何付費訂閱方案中。