Defining the Cybersecurity Organization
Before going into more detail on the organization’s structure, roles, and responsibilities, it is important that you spend some time creating a mission and vision for the cybersecurity organization. As we previously discussed, there will be (or should be) a mission and vision at the organization level and there is a high probability that other functions/units within the organization have their own. Having one for the cybersecurity organization will help the broader organization understand your purpose, values, and goals being delivered for the organization. This is something that can also be shared among other leaders within the organization and something that can be included in any presentations or materials being shared with the broader organization.
A simple cybersecurity mission and vision could look something like this:
Mission
Protect and secure the people, assets, and data at “your company” from the ongoing...