Continuous Improvement (Risk Maturity Modeling)

Continuous improvement and risk maturity models help organizations strengthen risk management practices by identifying gaps, tracking progress, and guiding measurable enhancements over time.

3 slides · 2 min read · Domain 1

Slide 1

As with anything an organization does, its risk management processes should be subject to measurement, analysis, and continuous improvement.

Whether this is done with a capabilities maturity modeling-style approach or some other technique is largely not an issue; what is important is the actual commitment to doing something that helps the security team answer the question, "Are we getting better at managing risk, or are we worse at it than we were before?"

This is another way of determining whether the investments the organization has made in information security improvements are paying off or whether they are just throwing good money after bad.

Data collection, monitoring, and analysis can be crucial to timely detection, characterization, and response to intrusions or other compromises. That same set of data, plus a bit more, ought to be able to reveal risk management key performance indicators (KPls) such as:

  • Time to detect user behaviors indicative of an evolving insider threat situation;
  • Time to detect indicators of an evolving or ongoing intrusion;
  • Time to detect and neutralize malware intrusions, installations, or activations;
  • Improvements in human team members' effective use of and compliance with security controls, procedures, and guidelines;
  • Number of endpoints connected to systems that have all required security updates and patches; or
  • Numbers of systems with known exploitable vulnerabilities awaiting patches, updates, or procedural workarounds as mitigations.

This is but a short sample of such risk management KPls.

Each organization needs to determine the improvement targets for its own risk management programs, start measuring them, and then use those measurements to improveto mature-those programs.

This is harder to do with a purely qualitative risk management approach. The more that you can do risk management "by the numbers," the easier it is to measure how good (or bad) you are at managing your risks.

Continuous improvement is an important concept within the entire ISO 27000 family of standards. There is no such thing as full implementation of the standard because the assumption is that no matter what you do and how much you invest in cybersecurity, you can always do more. And even if you feel that you invested enough, the external changes will need to be addressed.

Cybersecurity management is a neverending process that requires security professionals to always stay updated on the latest risks, threats, vulnerabilities, and technological updates.

Test this domain