Talk With an Expert

An Organic Approach to Implementing the Critical Security Controls

An Organic Approach to Implementing the Critical Security Controls (PDF, 3.27MB)Published: 12 Jan, 2016
Created by:
Jim Hendrick

This paper describes a method (almost a philosophy) for using the Critical Security Controls (CSCs) to drive long term improvement by carefully choosing specific metrics linked with operational processes. In contrast to formal process models, this method begins with identifying existing areas where (often small) changes can be used as starting points. Several examples are given using specific controls, concepts for driving change are presented, and the use of metrics as an underlying mechanism is discussed. The resulting organic approach promotes continuous improvement by taking advantage of natural behavioral tendencies of people and organizations.