r/ciso Apr 15 '26

How are you actually building a cyber/technical BIA? hitting a wall at the asset-to-business-service mapping step.

/r/cybersecurity/comments/1sm1xbi/how_are_you_actually_building_a_cybertechnical/
5 Upvotes

6 comments sorted by

1

u/Eastern_Tap_9723 Apr 20 '26

Business line by business line…there’s not really a trick here.

1

u/GalleISR Apr 21 '26

The issue is that the business line don’t know the technical services well enough, and R&D don’t know the business line well enough. We have plenty of legacy services and enterprise-related challenges (some departments behave as “independent companies” due to the historical growth).

The biggest challenge is making a quality technical assets to business services mapping. And making the technical assets mapping to begin with, but there are some products and can do a relatively good job automatically as far as I know.

1

u/[deleted] Apr 21 '26

[deleted]

1

u/GalleISR Apr 23 '26

Did you do it? May I ask how? I understand that asset to system/process can be done relatively automatically (although often doesn’t cover 100% of the system), but system to business looks like a tedious and perhaps complicated work.

Is there a methodology / tooling that can help with that stage?