Author: Microsoft Security - Bewertung: 1x - Views:22
In this video, Stephanie Peterson, Senior Director of CISO GRC, walks through Microsoft’s end-to-end cybersecurity risk management program—covering governance, process, and how risk is surfaced, assessed, and mitigated across the enterprise.
This video breaks down:
- The risk management pyramid—from operational risks to board-level oversight
- The role of the Cybersecurity Governance Council and enterprise risk reporting
- How the centralized risk register connects signals across teams and systems
- Microsoft’s four-stage risk lifecycle: identification, assessment, mitigation, and monitoring
- How programs like the Secure Future Initiative (SFI) prioritize critical risks
- The roles of risk submitters, curators, owners, and reviewers in driving accountability
You’ll also see how Microsoft creates a continuous feedback loop—linking risk insights to executive decision-making, compliance frameworks, and long-term security strategy.
Whether you're building a risk program or refining governance, this overview provides a practical model for managing cybersecurity risk at scale.
For more guidance from the Office of the CISO, explore Office of the CISO Insights on the Microsoft Security Blog. → https://msft.it/6050v5zCa
#MicrosoftCybersecurity #GRCCybersecurity #CISORiskManagement