<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How aware are local SMBS of Resources to assist them with Cybersecurity Policies/Practices? in Security for SMBs</title>
    <link>https://community.isc2.org/t5/Security-for-SMBs/How-aware-are-local-SMBS-of-Resources-to-assist-them-with/m-p/59118#M31</link>
    <description>&lt;P&gt;I worked for a private company that had grown into an IT infrastructure without properly knowing how to manage it.&amp;nbsp; And that speaks to technical administration and executive governance, in addition to protection and security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I started looking for cybersecurity guidance, two names kept coming up:&amp;nbsp; SANS, and Center for Internet Security.&amp;nbsp; Their documents were useful to me, and I downloaded a lot of their templates and benchmarks!&amp;nbsp; But neither the documents nor my use of them to frame the risk to our company were convincing enough for leadership to prioritize cybersecurity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SANS and CIS are highly valuable for entities who need a starting point.&amp;nbsp; SANS has great policy templates, and CIS has excellent build benchmarks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No matter what, though, you must convince your leadership for buy-in.&amp;nbsp; You must create a compelling argument which your leadership must address as a responsibility of governance and mission.&amp;nbsp; If you don't have that, then you might as well stop.&lt;/P&gt;</description>
    <pubDate>Tue, 16 May 2023 12:27:51 GMT</pubDate>
    <dc:creator>ericgeater</dc:creator>
    <dc:date>2023-05-16T12:27:51Z</dc:date>
    <item>
      <title>How aware are local SMBS of Resources to assist them with Cybersecurity Policies/Practices?</title>
      <link>https://community.isc2.org/t5/Security-for-SMBs/How-aware-are-local-SMBS-of-Resources-to-assist-them-with/m-p/59115#M30</link>
      <description>&lt;P&gt;Please share the "Common Resources," or lack thereof, that you hear frequently from SMBS. Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:31:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Security-for-SMBs/How-aware-are-local-SMBS-of-Resources-to-assist-them-with/m-p/59115#M30</guid>
      <dc:creator>WVBC23-BNetSec</dc:creator>
      <dc:date>2023-10-09T10:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: How aware are local SMBS of Resources to assist them with Cybersecurity Policies/Practices?</title>
      <link>https://community.isc2.org/t5/Security-for-SMBs/How-aware-are-local-SMBS-of-Resources-to-assist-them-with/m-p/59118#M31</link>
      <description>&lt;P&gt;I worked for a private company that had grown into an IT infrastructure without properly knowing how to manage it.&amp;nbsp; And that speaks to technical administration and executive governance, in addition to protection and security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I started looking for cybersecurity guidance, two names kept coming up:&amp;nbsp; SANS, and Center for Internet Security.&amp;nbsp; Their documents were useful to me, and I downloaded a lot of their templates and benchmarks!&amp;nbsp; But neither the documents nor my use of them to frame the risk to our company were convincing enough for leadership to prioritize cybersecurity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SANS and CIS are highly valuable for entities who need a starting point.&amp;nbsp; SANS has great policy templates, and CIS has excellent build benchmarks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No matter what, though, you must convince your leadership for buy-in.&amp;nbsp; You must create a compelling argument which your leadership must address as a responsibility of governance and mission.&amp;nbsp; If you don't have that, then you might as well stop.&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2023 12:27:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Security-for-SMBs/How-aware-are-local-SMBS-of-Resources-to-assist-them-with/m-p/59118#M31</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2023-05-16T12:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: How aware are local SMBS of Resources to assist them with Cybersecurity Policies/Practices?</title>
      <link>https://community.isc2.org/t5/Security-for-SMBs/How-aware-are-local-SMBS-of-Resources-to-assist-them-with/m-p/59246#M32</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;Common resources that SMBs frequently mention as lacking include access to affordable financing and capital, skilled labor and talent, technological infrastructure and IT support, marketing and advertising resources, and networking opportunities. Additionally, SMBs often express challenges in navigating complex regulations and compliance requirements, as well as difficulties in competing with larger businesses due to limited resources and economies of scale&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 06:26:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Security-for-SMBs/How-aware-are-local-SMBS-of-Resources-to-assist-them-with/m-p/59246#M32</guid>
      <dc:creator>Hannahchambers</dc:creator>
      <dc:date>2023-05-17T06:26:47Z</dc:date>
    </item>
  </channel>
</rss>

