158k views
0 votes
What are the first two lines of defense a company should take when addressing security risks? technology first, people second technology first, customers second innovation first, technology second people first, technology second?

User Ankit Raj
by
8.2k points

1 Answer

0 votes
technology second people first.

In the three line defense model, the owners/managers are the first line of defense. They are responsible for taking risk and function. They are responsible for accessing, controlling and mitigating risk.

The second lines of defense is responsible for functioning, implementing and monitoring of the operation plan to support the risk. This line of defense concern on compliance, ethics,IT, legal implementation and other various internal components of risk management.
User GeekOnCoffee
by
8.2k points