Implement Level 3: High Adoption of Security Practices
mainLevel 3 is suitable for organizations where information security risk is treated as a core operational risk, typically requiring a dedicated security unit (e.g., 15-20 employees).
Key Security Services to Implement:
- Security Operation Center (SIEM, IRP, SOAR, SGRC)
- Data Leak Prevention (DLP)
- Phishing protection
- Sandbox
- Intrusion Prevention System (IPS)
- Vulnerability scanner
- Endpoint and ATP protection
- Web Application Firewall (WAF)
- Backup server
Disadvantages: High costs for security tools and specialized personnel.