At Toreon, we recommend a quarterly, a half-year or annual assessment of critical assets with a higher impact and greater likelihood of compromise. Assessments for full environments (e.g., cloud, on-premises networks, developing environment, security & risk strategy) are minimally recommended to have an assessment yearly, implemented recommendations can be more easily followed up to finetune and manage outcomes.
Scenarios that also benefit from additional assessments:
- A new service, IT system or networkdeployment
- New available security controls
- Major update of an IT system or security component
- Switching or upgrading Operating System on a device/server
- New major business initiatives
- New major IT initiatives
- Merge or acquisition of an organization
Because IT and security change constantly, regular assessments matter——especially if you want security that protects and performs.