AmbassadorNaseem HalderHead of Information SecurityIndiaVerified Community AmbassadorJoin / Sign In to ConnectIdentified ExpertiseSecurity & GRC29Engineering8Threat & Vulnerability Management8Process Management7Applications & Platforms7View More (28)Content Naseem is FollowingDo you trust the data & reports from the big analysts?Strategy & ArchitectureYesNoSometimesView Results111.8k viewscircle iconLightbulb on123 Upvotescircle icon58 CommentsLightbulb offUpvoteConversationCommentSaveSaveShareShareAre you happy in your current role?People & LeadershipTalent Management & PerformanceYesNoUnsureView Results32.4k viewscircle iconLightbulb on18 Upvotescircle icon17 CommentsLightbulb offUpvoteConversationCommentSaveSaveShareShareThe recent MGM breach was made possible by a bad actor social engineering the help desk into providing them access. Does your organization take steps to authenticate callers to your help desk before the help desk performs any actions that may allow access (changing passwords, resetting/disabling/reconfiguring MFA etc.) If yes, how have these methods worked out? Were they effective and did you get any pushback from users?Naseem HalderHead of Information Security in Healthcare and Biotech2 years agoon a separate note, as an idea, have rules that will alert if people want to disable MFA. Lightbulb offUpvotereply-iconCommentRead More Comments2.5k viewscircle icon3 CommentsLightbulb offUpvoteConversationCommentSaveSaveShareShareAre there best practices or staffing models available to assist with setting up a team specific to the management, tracking, compliance and reporting of identified risks and issues. Ie What's the right ratio of people to identified issues to properly manage those items to completion?Security & GRCNaseem HalderHead of Information Security in Healthcare and Biotecha year agoratio of people to identified issues, depending on the size and complexity of the business, nature industry, and the level of risk appetite. Organizations should try to achieve a balance between resource requirements to attend ...read moreLightbulb offUpvotereply-iconCommentRead More Comments1.1k viewscircle icon2 CommentsLightbulb offUpvoteConversationCommentSaveSaveShareShare
on a separate note, as an idea, have rules that will alert if people want to disable MFA.