Building a Security Function From Nothing
You are the first and only security person in the company. No budget, no team, and the people who own the systems do not report to you. This segment is the first ninety days: what exists, what you can prove, what you do first, who decides, what you refuse, and what you put in front of a board.
- trending_upAdvanced
- schedule7h 35m
- menu_book12 节课程
- publicEnglish
- workspace_premiumBasic
课程概述
Somebody has just made you responsible for security at a company that has never had anybody responsible for security. There is no team. There is no budget line yet. There is a list of things people believe are true, an insurer or a customer who triggered your hire, and roughly nine directors who each own a system and none of whom report to you. The hardest part of this job is not technical, and pretending otherwise is the most common way a first security hire fails in year one. You will spend more of the ninety days establishing what you are allowed to decide than you spend looking at anything. The technical work is not the constraint. The constraint is that you can recommend, and somebody else has to act, and they are busy. Across four modules you find out what the company actually has rather than what it says it has, and build an ownership register that starts completely empty and gets filled by asking humans, one row at a time. You write the one page that says what this function will do and what it will not do, and take it to your sponsor for one signature. You work out the three things worth buying with a first budget, the argument for hiring nobody yet, and how to survive forty-five minutes with a finance director. Then you build a ninety-day plan with real dates and write the first board update on one side of paper. You will also learn to distrust your own progress. The activities that demonstrate a security function exists are rarely the ones that reduce risk, and the quiet unglamorous fix that would have prevented the incident is invisible to everybody above you unless you deliberately make it visible. Nothing in this segment produces a policy, a risk register or a gap assessment. Those belong to the segments that own them, and this one tells you when to start them rather than doing them for you. Every figure in it is ranged and dated and is illustrative, because the real numbers depend on your industry, your country and your year.
课程大纲 · 4 个模块
lock解锁权限内容- 01 第一周,改变之前3 节课程·1h 45m
第一周的本能是修复某样东西,因为修复东西是你擅长的,也是让你在这个还没人认识你的地方感到有用的方式。第一周花在修复上的每一小时都是在没有地图的情况下度过的,你破坏的第一样东西将是第一个月里唯一有人记得的东西。
- 02 运营模式3 节课程·1h 41m
你拥有对任何事物的权限都没有,但需要对所有事都负责,再多的热情也弥补不了这个差距。弥补这个差距的是写下谁决定什么,找一个足够资深的人同意这个安排,然后坚持执行足够长的时间,直到人们停止询问。
- 03 第一笔预算3 节课程·1h 50m
第一笔预算很小,受到关注,你如何使用它决定了是否有第二笔预算。最常见的错误是购买需要一个人来运行的平台,这会将你唯一的预算转变为永久性的义务和一个没有人查看的仪表板。
- 04 九十天,向上汇报3 节课程·2h 19m
在第九十天,某人会悄悄地决定录用你是否是个好主意。这个决定是基于他们看到的东西,而不是你做过的东西,这两者是不同的集合。这个模块的工作是让幕后的工作可见,而不是把显眼的工作变成计划。
常见问题
- 我将在 Building a Security Function From Nothing 中学到什么?
- You are the first and only security person in the company. No budget, no team, and the people who own the systems do not report to you. This segment is the first ninety days: what exists, what you can prove, what you do first, who decides, what you refuse, and what you put in front of a board.
- 我需要有先前的经验吗?
- 建议在开始 Building a Security Function From Nothing 前具有一定的先前知识。
- Building a Security Function From Nothing 需要多长时间?
- Building a Security Function From Nothing 包含 4 个模块和 12 节课程。您可以按自己的速度学习。
- 我如何获得访问权限?
- Building a Security Function From Nothing 包含在任何付费订阅中。