Christopher Gregg
With nearly a decade of experience advising enterprise organizations, Christopher Gregg, CISSP, provides technical analysis for legal professionals and corporate stakeholders involved in cybersecurity matters.
Drawing on his experience supporting Fortune 500 organizations, Christopher specializes in enterprise network architecture, governance, third-party risk, and merger & acquisition integrations, alongside evaluating reasonable cybersecurity practices and standards of care.
He is known for delivering objective, practical, and defensible analysis while translating technical issues into clear insights.
Christopher holds both Bachelor's and Master's degrees in Cyber Security and maintains a Certified Information Systems Security Professional (CISSP) credential.
Session
In today’s landscape, Information Security professionals are battling the "Blinking Box Problem". For a long time, our industry has been focused on buying purpose built tools to address risks within our environment. However, we are now seeing that we have tool/vendor sprawl, bloated costs, and more tools than we know how to manage. Case in point: A blinking box isn't going to solve any of our problems without appropriate governance and strategic implementation of our tools.
To successfully approach tool and vendor consolidation, we need to go back to the basics. By leveraging the NIST Cybersecurity Framework (CSF) 2.0, we can realign with our core principles.
We’ll do an overview of the NIST CSF Framework, discuss profiling your business, explain the CSF Cores and Tiers, and then do a deep dive into the central Govern (GV) Function and its key categories.