0% found this document useful (0 votes)
70 views6 pages

Deloitte Cyber Strategy Framework Guide

Deloitte's Cyber Strategy Framework is a comprehensive platform designed to enhance cyber resilience for organizations through a business-driven and threat-based methodology. It includes a robust online platform with customizable dashboards for assessing cyber capabilities against industry standards, and a five-phase approach to develop actionable roadmaps for improvement. The framework emphasizes the importance of being secure, vigilant, and resilient in the face of cyber threats.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
70 views6 pages

Deloitte Cyber Strategy Framework Guide

Deloitte's Cyber Strategy Framework is a comprehensive platform designed to enhance cyber resilience for organizations through a business-driven and threat-based methodology. It includes a robust online platform with customizable dashboards for assessing cyber capabilities against industry standards, and a five-phase approach to develop actionable roadmaps for improvement. The framework emphasizes the importance of being secure, vigilant, and resilient in the face of cyber threats.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Cyber Strategy Framework

A unique platform for


managing your Cyber Strategy
Cyber Strategy Framework |
 A unique platform for managing your Cyber Strategy Cyber Strategy Framework |
 A unique platform for managing your Cyber Strategy

A unique framework for managing


your Cyber Strategy
Deloitte’s Cyber Strategy Framework • Infrastructure Protection
is a unique approach to creating • Vulnerability Management
Secure
a cybersecurity strategy - helping • Application Protection
organizations to manage cyber resilience • Identity and Access
Management
with confidence.
• Information Privacy and
Cyber Strategy Protection
Our Cyber Strategy Framework incorporates
• Transformation and • Advanced Threat
a business-driven and threat-based
Assessments Readiness and Preparation
methodology supported by an intuitive Vigilant
• Cyber Risk Management
online platform, which includes dashboards • Cyber Risk Analytics
and Compliance
• Security Operations Center
for reporting to an operational, managerial • Cyber Training, Education
and Awareness • Threat Intelligence and
and executive audience. The Cyber Strategy
Analysis
Framework is our global approach to
• Cyber Incident Response
conducting cyber strategy assessments • Cyber Wargaming
and is used by leading organizations across
numerous industries. • Cyber Incident Response
Resilient
• Cyber Wargaming

A unique framework for managing your


Cyber Strategy
Deloitte recognizes that no organization
Methodology
has unlimited resources to dedicate to
A proven methodology based
cybersecurity. Therefore, it is important that
around three components:
organizations invest in those cybersecurity
business, threats and capabilities.
capabilities that will contribute most to their
overall cyber resilience. The Cyber Strategy
Framework is the result of more than four Content Packs
years of research and investment in Cyber Content packs which enable
Strategy by Deloitte and incorporates a proven maturity assessments against
methodology to determine the current and particular standards.
target maturity of an organization’s cyber
capabilities and design a roadmap to improve
Platform
the overall cyber resilience of the organization
A versatile platform which
to internal and external threats.
supports our methodology
and includes an array of
Our framework also includes content packs,
customizable dashboards.
which enable maturity assessments to
be conducted against a range of industry
standards, including the ISO/IEC 27001, Deloitte
the NIST Cybersecurity Framework and the Underpinned by our
Deloitte Cyber Capability model. The Deloitte experience in cyber
Cyber Capability Model recognizes that while risk management and
being Secure is important, organizations must strategy.
also be Vigilant and Resilient against cyber
threats, and have a comprehensive Cyber
Strategy to ensure continued business value.

02 03
Cyber Strategy Framework |
 A unique platform for managing your Cyber Strategy Cyber Strategy Framework |
 A unique platform for managing your Cyber Strategy

Cyber Resilience delivered

Deloitte’s Cyber Strategy Framework Deloitte Cyber Strategy Framework Periodic Table
leverages our proven methodology and our Deloitte’s CSF Periodic tables encapsulates the fundamentals to our services 1 Capability #
unique insight and experience to deliver delivered in a manner that is concise and digestible for our clients.
improved cyber resilience and several St Symbol
other business benefits. Governance Strategy and Resilient
Capability name
operating
These include: 1 32
model
• Enhanced value from cyber investments
by focusing on the right priorities. St Ip
• Enhanced risk governance and
Strategy and
management. Incident
operating
• Improved communication with internal readiness
model
and external stakeholders, including Secure Vigilant
regulators.
• Create a common framework for
2 5 9 13 17 21 25 29 33
managing cyber resilience at an
operational, managerial and executive Pa Cs S Es Idm Dlp Cti Sp Ir
level.
Policies, Secure software End-user Identity Security
Cloud Data loss Cyber threat Incident
standars and development device lifecycle platform
Security prevention intelligence response
architecture lifecycle security management administration

3 6 10 14 18 22 26 30 34

Aw Tp Ap Pam Pvm Bc
Cyber Risk Post-
Am Privileged E Bp Patch and Business
Third-party Risk Asset Brand continuity
Culture and development acces Enryption Vulnerability
management management Protection Management
behaviour app protection management management
and resilience

4 7 11 15 19 23 27 31 Incident management

Rm Hs Pvi Business resilience

Cyber Risk
Human Mp Ss Rbac Dp Td Penetration
Management, Malware System Role-based Data privacy Thread testing and
Resource
Metrics and protection security Acces control detection vulnerability
security
reporting identification

Cybersecurity 8 12 16 20 24 28 Vulnerability
management identification

Ps Nc Ua Ic Ilm Th
Physical Network User acces Information Information
Thread
security security control classification Lifecycle
hunting
management

Extended Application Infraestructure Identity and access Data security Threat intelligence
enterprise security security management Security operations
People and
workplace

04 05
Cyber Strategy Framework |
 A unique platform for managing your Cyber Strategy Cyber Strategy Framework |
 A unique platform for managing your Cyber Strategy

A comprehensive approach to managing


cyber resilience with confidence
Deloitte’s Cyber Strategy Framework Business
incorporates a proven methodology based What are your crown jewels?
around three core components: Business, Resilience
Threats and Capabilities. To define the How do you become secure,
right cyber strategy for an organization we vigilant and resilient
typically follow a five-phase approach to
Threats
asses the current and the targeted maturity
What are your cyber threats
level of cyber capabilities. We define an
and how exposed are you?
actionable roadmap which organizations
can immediately act upon and which aim to
improve their cyber resilience.
Capabilities
What cyber capabilities do
you need?

PHASE 1: Business PHASE 2: Threat PHASE 3: Current state PHASE 4: Target states PHASE 5: Reporting
profiling assessment assessment and recommendations and roadmap

We start with In this phase, we analyze We assess the maturity In this phase, we Finally, we report on
understanding the the organization’s of the organization’s define an appropriate the organization’s
organization’s business threat environment to existing cyber target maturity for the cyber resilience using
context, including its determine the most capabilities. Our organization’s cyber the customizable
operating model and relevant threat actors assessment is supported capabilities based on its dashboards available
strategy, in order to and techniques, and use by our platform, which speciic threat landscape. in our platform, and
identify its critical these to determine the can automatically Again, our platform can use the results o our
business assets (crown organization’s exposure calculate the current automatically calculate assessments to deine
jewels). to specific threat state maturity of each the most appropriate a structured roadmap
scenarios. capability based on the maturity based on the to improve the maturity
responses received to organization’s speciic of the organization’s
specific statements. threat exposure. capabilities and guide the
organization towards its
target state.

06 07
Contact us

Director, Risk Advisory

Dejan Perić
Director
Serbia

E-mail: deperic@[Link]
Tel.: +381 (0)11 3812 110
Mob.: +381 (0)65 224 6870

Manager, Risk Advisory

Borko Mijic
Manager
Serbia

E-mail: bmijic@[Link]
Tel.: +381 (0) 11 3812 218
Mob.: +381 (0) 65 222 55 90

Manager, Risk Advisory

Aleksandar Mirkovic
Manager
Serbia

E-mail: almirkovic@[Link]
Mob.: +382 (0)69 376 627
Deloitte is a leading global organization that provides audit and assurance services, business, financial, tax and legal
consulting, and risk management consulting. Deloitte supports the world's largest companies (four out of five
Fortune Global 500® companies) through a globally connected network of member firms in more than 150
countries. To learn more about how Deloitte's approximately 312,000 professionals contribute not only to the
success of clients, but to the entire community, visit [Link].

Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited (“DTTL”), its global network of member firms
and their related entities (collectively: the "Deloitte Organization"). DTTL (also known as: “Deloitte Global”) and all
its member companies and related entities are legally separate and independent entities, which cannot be
obligated to each other or liable to third parties. DTTL and each DTTL member company and related entity is
responsible only for its own acts and omissions, and is not responsible for the actions of others. Deloitte does not
provide services to clients. For more information, please visit [Link]/rs/en/about-us.

In the Republic of Serbia, services are provided by Deloitte Advisory d.o.o. Belgrade and Deloitte d.o.o. Belgrade
(hereinafter collectively: "Deloitte Serbia") which are members of Deloitte Central Europe Holdings Limited.
Deloitte Serbia is one of the leading companies for providing professional services in the field of audit, tax,
business, financial and consulting in risk management in Serbia, with over 250 experts from the country and
abroad.

This business communication contains general information only and accordingly, no member firm of the Deloitte
Touche Tohmatsu Limited ("DTTL") global network or any of its affiliates (collectively the "Deloitte Organization") is
rendering professional advice or services through this publication. . Before making any decision or taking any action
that may affect your finances or business, you should consult a qualified professional advisor.

No representations or warranties (express or implied) are made as to the accuracy or completeness of the
information in this communication, and DTTL, its member companies, affiliates, employees or agents shall not be
liable for any damages that may be suffered by any person directly or indirectly through the use of the information.
from this publication. DTTL and its member companies are legally separate and independent entities.

© 2022. For information, contact Deloitte Serbia.


© 2022. For information, contact Deloitte Central Europe.

You might also like