What are the first two lines of defense a company should take when addressing security risks? technology first, people second technology first, customers second innovation first, technology second people first, technology second?

Respuesta :

keu
technology second people first.

In the three line defense model, the owners/managers are the first line of defense. They are responsible for taking risk and function. They are responsible for accessing, controlling and  mitigating risk.

The second lines of defense is responsible for functioning, implementing and monitoring of the operation plan to support the risk. This line of defense concern on compliance, ethics,IT, legal implementation and other various internal components of risk management.