Working with Your CISO
The Chief Information Security Officer (CISO) or Chief Security Officer (CSO) of an organization ensures the organization’s personnel, physical infrastructure, and digital assets are available to the business and protected from unauthorized access, loss, theft, or disruption and physical damage through appropriate cyber risk management.
Security breaches exploit people, processes, and technology. It is no longer a technical problem but a business risk and must be treated as such. Efficient recommendations need to be provided for controls across the elements of people, processes, and technology, mitigating cyber risk in alignment with the company’s risk appetite. This is the responsibility of the CISO in collaboration with their CxO peers.
The shift in focus on cybersecurity—integrating cyber risk into the overall enterprise risk management process—underpins the foundations of this chapter.
A good CISO should be a great communicator...