Dramatically lower the cyber risk posed by third-party software and vendors in your organization In Zero Trust and Third-Party Risk , veteran cybersecurity leader Gregory Rasner delivers an accessible and authoritative walkthrough of the fundamentals and finer points of the zero trust philosophy and its application to the mitigation of third-party cyber risk. In this book, you’ll explore how to build a zero trust program and nurture it to maturity. You will also learn how and why zero trust is so effective in reducing third-party cybersecurity risk. The author uses the story of a fictional organization―KC Enterprises―to illustrate the real-world application of zero trust principles. He takes you through a full zero trust implementation cycle, from initial breach to cybersecurity program maintenance and upkeep. You’ll also find: Explanations of the processes, controls, and programs that make up the zero trust doctrine - Descriptions of the five pillars of implementing zero trust with third-party vendors - Numerous examples, use-cases, and stories that highlight the real-world utility of zero trust An essential resource for board members, executives, managers, and other business leaders, Zero Trust and Third-Party Risk will also earn a place on the bookshelves of technical and cybersecurity practitioners, as well as compliance professionals seeking effective strategies to dramatically lower cyber risk. "A breach of your third and fourth parties is mathematically inevitable. This first line of the book is perhaps one of the most important for CISO's and those who work with them to understand and come to grips with. If it's inevitable, the question then becomes, what are you going to do about it? This book is a fantastic bridge between the world of compliance-heavy third party risk management activities and practitioner-focused zero trust frameworks. It moves the compliance work beyond box checking and into a true integrated security model. It also pushes the work and teams engaged in all things zero trust to expand their thinking to the places where third and fourth parties intersect with their organization's, their data, and their assets. CISO's should take this book, bring it to their teams, use it as a foundation for building an integrated security model across their organizations." - Robert Wood, CISO Medicare and Medicaid Services "I find this book to be incredibly timely and relevant given the threat landscape today and the increasing risk third parties pose to organizations. It is no longer enough to assess your third parties from a cyber perspective to ensure appropriate controls are in place, but we must now play on the 'defense' to further limit the impact a third party could have on an organization should an evaluated control fail. What I appreciate the most about this book is Greg's description of zero trust as a strategy (not a technology) and a journey that organizations must continually work towards. Greg provides valuable insight into the strategies and techniques for setting up an environment that works to reduce the impact a third party could pose to your network through strong access controls and continual validation of traffic and resources. This book is a must read for anyone wanting to further enhance their Third Party Risk Management programs." Julie Gaiaschi, CISM, CISA Chief Executive Officer & Co-Founder Third Party Risk Association "Rasner's Zero Trust and Cyber Third-Party Risk is essential reading for third-party risk analysts and security architects alike. At a strategic level, he raises the reality that zero-trust strategies and architectures are required to minimize vendor breach events and their impacts. At a tactical level, he lays out the zero-trust control requirements that should be foundational requirements for every high-risk vendor engagement. You can outsource your systems and services, but you cannot outsource your risks. Application of Rasner's concepts will enable you to better manage your third-party risks." Kelly White, Founder of RiskRecon "Choose your own adventure: Whether it's the Solar Winds attack or the fictional KC Enterprises, Greg's anecdotes are a welcomed ice-bucket challenge to the cybersecurity and third-party risk management communities. This book offers a practical approach to effectively guide both cyber AND business leaders toward the intersection of cyber third-party risk and zero trust, with a goal of increasing security for all. In the end, we are inherently stronger together - so we must ensure vendors and partners alike are aligned to create a stronger tomorrow." Clar Rosso, CEO of ISC2 Praise for ZERO TRUST AND THIRD-PARTY RISK "What I appreciate the most about this book is Greg's description of zero trust as a strategy (not a technology) and a journey that organizations must continually work towards. This book is a must read for anyone wanting to further enhance their Third Party Risk Management programs." ― Julie Gaiaschi,
| Gtin | 09781394203147 |
| Mpn | 9781394203147 |
| Age_group | ADULT |
| Condition | NEW |
| Gender | UNISEX |
| Product_category | Gl_book |
| Google_product_category | Media > Books |
| Product_type | Books > Subjects > Business & Money > Insurance > Risk Management |