Security: BSI handbook for company management

B2B Cyber ​​Security ShortNews

Share post

The BSI distributes the new international manual "Management of Cyber ​​Risks" for company management. The Internet Security Alliance manual is intended to increase the resilience of companies through more cyber security knowledge in management.

Cyber ​​attacks on companies are the order of the day, and the threat level is higher than ever. Company management must be aware of this and make cyber security an integral part of risk management. The internationally published manual "Management of Cyber ​​Risks", which was developed by the Federal Office for Information Security (BSI) in cooperation with the Internet Security Alliance (ISA), is now receiving a far-reaching update. It is dedicated to a comprehensive corporate culture that takes cyber security into account at all times, thereby increasing the resilience of companies.

Updated edition for more resilience

The manual and toolkit are available for download in English and German (Image: BSI).

Cyber ​​security is a matter for the boss! Secure digitization succeeds when the company management develops a basic understanding of the risks in the area of ​​information security. This is the only way for the board of directors or the supervisory board to make an informed assessment of the potential economic damage caused by cyber incidents and to decide on the validity of IT security strategies.

The “Cyber ​​Risk Management” handbook is aimed at company management. It provides an overview and recommendations for dealing with and evaluating cyber risks. The handbook is based on the Cyber ​​Risk Oversight Handbook developed by the US Internet Security Alliance (ISA) on behalf of the National Association of Corporate Directors (NACD). In workshops and in close cooperation with experts from business, IT security research and the state, the manual was translated into German in the present, updated version and adapted to German and European framework conditions.

Six Basic Principles & Toolbox

It formulates six basic principles that support management and supervisory boards in considering cyber risks:

  • Cyber-Security not only as ITtopic, but rather as a building block of company-wide risk management.
  • Understand and closely examine the legal implications of cyber risks.
  • Ensure access to cyber security expertise and regular exchange.
  • Ensure the implementation of suitable framework conditions and resources for cyber risk management.
  • Prepare risk analysis and formulate a definition of risk appetite depending on business goals and strategies.
  • Encourage company-wide collaboration and sharing of best practices.

The manual is through a Toolbox supplemented, which provides management with methods and questions about management, including resources from the BSI for the economy.

More at BSI.Bund.de

 


About the Federal Office for Information Security (BSI)

The Federal Office for Information Security (BSI) is the federal cyber security authority and the creator of secure digitization in Germany. The guiding principle: As the federal cyber security authority, the BSI designs information security in digitization through prevention, detection and reaction for the state, economy and society.


 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more

HeadCrab 2.0 discovered

The HeadCrab campaign against Redis servers, which has been active since 2021, continues to successfully infect targets with the new version. The criminals' mini-blog ➡ Read more

[starbox id=USER_ID] <🔎> ff7f00