---
title: "Focus on What You CAN Manage: People, Process and Technology - SCA Security"
description: By adopting prudent information practices aligned with the size, complexity and culture of your organization, you have positioned the people, process and technology to best defend your network and data.
---

[727-571-1141 Talk to an Expert](tel:727-571-1141) [info@scasecurity.com Email Us](mailto:info@scasecurity.com) <https://www.facebook.com/Security-Compliance-Associates-170070577097300/?ref=br_rs> <https://twitter.com/scasecurity> <https://www.linkedin.com/company/security-compliance-associates/>

[![sca-logo-r](https://blog.scasecurity.com/hs-fs/hubfs/sca-logo-r.png?length=190&name=sca-logo-r.png)](https://scasecurity.com/)

☰

- [Home](https://scasecurity.com/)
- [Security](https://scasecurity.com/security/) 
    - [Email Phishing & Employee Training](https://scasecurity.com/anti-phishing-training-with-phished-io/)
    - [Vulnerability Assessments](https://scasecurity.com/security/vulnerability-assessments/)
    - [Penetration Testing](https://scasecurity.com/security/penetration-testing/)
    - [Applications](https://scasecurity.com/security/applications/)
    - [Controls](https://scasecurity.com/security/controls/)
    - [Centurion ESO](https://scasecurity.com/executive-security-officer/)
    - [Consulting](https://scasecurity.com/security/consulting/)
- [Risk & Compliance](https://scasecurity.com/compliance/) 
    - [CMMC](https://scasecurity.com/cybersecurity-maturity-model-certification/)
    - [HITRUST](https://scasecurity.com/hitrust/)
    - [Federal](https://scasecurity.com/compliance/federal/)
    - [State](https://scasecurity.com/compliance/state/)
    - [Industry](https://scasecurity.com/compliance/industry/)
    - [Cybersecurity Risk Assessment](https://scasecurity.com/security/risk-assessment/)
    - [NIST Cybersecurity Framework Assessment](https://scasecurity.com/compliance/nist-framework/)
    - [AI Risk Management Services](https://scasecurity.com/ai-risk-management-services/)
- [Governance](https://scasecurity.com/compliance/governance/)
- [Industries](https://scasecurity.com/industries/) 
    - [Financial Services](https://scasecurity.com/industries/financial-services/)
    - [Healthcare](https://scasecurity.com/industries/healthcare/)
    - [Government/Public Sector](https://scasecurity.com/industries/government-public-sector/)
    - [Title/Real Estate](https://scasecurity.com/industries/title-real-estate/)
    - [Technology](https://scasecurity.com/industries/technology/)
    - [Manufacturing](https://scasecurity.com/industries/manufacturing/)
    - [Professional Services](https://scasecurity.com/industries/professional-services/)
    - [Automotive](https://scasecurity.com/automotive/)
    - [Higher Education](https://scasecurity.com/higher-education/)
- News & Resources 
    - [Blog](https://blog.scasecurity.com)
    - [Events](https://scasecurity.com/event/)
    - [Case Studies](https://scasecurity.com/case-studies/)
    - [Recorded Webinars](https://scasecurity.com/recorded-webinars/)
    - [SCA Breach Notification Guide](https://scasecurity.com/breach-notification-guide/)
    - [HIPAA Security Audit Checklist](https://info.scasecurity.com/hipaa-audit-checklist)
    - [Cybersecurity Checklist for Insurance Providers](https://info.scasecurity.com/cybersecurity-checklist-for-insurance-providers)
- Company 
    - [About Us](https://scasecurity.com/about-us/)
    - [Leadership](https://scasecurity.com/leadership/)
    - [Affiliates](https://scasecurity.com/affiliates/)
    - [Career Opportunities](https://scasecurity.com/career-opportunities/)
    - [Testimonials](https://scasecurity.com/testimonials/)
- [Contact Us](https://scasecurity.com/contact-us/)

#### Menu

 Home

 Security ›

 Email Phishing & Employee Training

 Vulnerability Assessments

 Penetration Testing

 Applications

 Controls

 Centurion ESO

 Consulting

 Risk & Compliance ›

 CMMC

 HITRUST

 Federal

 State

 Industry

 Cybersecurity Risk Assessment

 NIST Cybersecurity Framework Assessment

 AI Risk Management Services

 Governance

 Industries ›

 Financial Services

 Healthcare

 Government/Public Sector

 Title/Real Estate

 Technology

 Manufacturing

 Professional Services

 Automotive

 Higher Education

 News & Resources ›

 Blog

 Events

 Case Studies

 Recorded Webinars

 SCA Breach Notification Guide

 HIPAA Security Audit Checklist

 Cybersecurity Checklist for Insurance Providers

 Company ›

 About Us

 Leadership

 Affiliates

 Career Opportunities

 Testimonials

 Contact Us

[727-571-1141 Talk to an Expert](tel:727-571-1141)

[info@scasecurity.com Email Us](mailto:info@scasecurity.com)

<https://www.facebook.com/Security-Compliance-Associates-170070577097300/?ref=br_rs>

<https://twitter.com/scasecurity>

<https://www.linkedin.com/company/security-compliance-associates/>

 October 01, 2018

# Focus on What You CAN Manage: People, Process and Technology

 By: SCA Editor

My father has always been a sage if wisdom throughout my life. One piece of advice he gave to help me focus and prioritize was “don’t worry about the things you can’t control and focus on what you can control”. This can be applied to many aspects of life, and I recently placed it in the context of cybersecurity. Too often we get caught up in what threat actors might do. We have no control over them. What we CAN control is how we mitigate and [manage cybersecurity risks](https://scasecurity.com/security/) through people, process and technology.

People are often the first line of defense. Most malware and ransomware enter an environment as a payload contained in an email message and accessed by opening an attachment or by clicking on a link. Email phishing is also used to harvest sensitive information to assist a hacker in gaining system access and/or committing fraudulent activity such as initiating a wire transfer. Employees also have the responsibility of abiding by your password, clean desk and workstation locking policies (among others) and reporting the presence of those who seem out of place. A formal employee information security awareness training program delivered at least annually and reinforced with social engineering scenarios such as email phishing exercises will arm employees with the knowledge needed for frontline defense.

Process relates to having a thoroughly defined information security program that is documented in policy, procedure and employee use guidelines. The starting point is an information security risk assessment to identify threats, vulnerabilities and risks to the organization. The results of a [risk assessment](https://scasecurity.com/security/risk-assessment/) will identify the adequacy or absence of controls, populate or revise your policy documents and allow management to make risk based, prioritized decisions about information security efforts. This process should be repeated at least annually to reflect changes in the people, process and technology of your organization. A well-defined process provides a repeatable, measurable and defensible information security program that addresses both security and compliance with regulatory and/or industry mandates.

What technologies are deployed to mitigate the threats identified in your risk assessment? A multi-layered approach is a fundamental information security practice. Attackers like the path of least resistance so the more layers present, the harder it is for them. Defense in depth by itself is an entire blog post. Some technology layers to defend, detect and respond include firewalls, email and content filtering, IDS/IPS, data encryption in transit and at rest, IAM and SIEM. There is a growing new group of detection technologies that identify unusual user or data behavior that greatly reduces the time to detect malicious activity and allowing rapid containment and response.

By adopting prudent information practices aligned with the size, complexity and culture of your organization, you have positioned the people, process and technology to best defend your network and data.

Contact Security Compliance Associates today, [schedule a free consultation](https://scasecurity.com/contact-us/), and begin securing your business.

#### Subscribe

Email\*

Notification Frequency

[Blog](https://blog.scasecurity.com/tag/blog)

[February 07, 2025 Preparing for 2025 HIPAA Changes: What Healthcare Organizations Need to Know](https://blog.scasecurity.com/preparing-for-2025-hipaa-changes-what-healthcare-organizations-need-to-know) [October 23, 2024 What is a Vulnerability Assessment (and Why You Need One)](https://blog.scasecurity.com/blog/what-is-a-vulnerability-assessment) [October 10, 2024 Understanding the Risks and Mitigation of Phishing Attacks](https://blog.scasecurity.com/understanding-the-risks-and-mitigation-of-phishing-attacks)

### Comments

© 2026 - All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SCA Editor",
    "url" : "https://blog.scasecurity.com/author/sca-editor"
  },
  "dateModified" : "2025-04-10T16:02:14.127Z",
  "datePublished" : "2018-10-01T04:00:00.000Z",
  "headline" : "Focus on What You CAN Manage: People, Process and Technology - SCA Security",
  "mainEntityOfPage" : {
    "@id" : "https://blog.scasecurity.com/people-process-technology",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.scasecurity.com/hubfs/sca-logo-r.png"
    },
    "name" : "Security Compliance Associates"
  }
}
```