For security professionals, the role of Chief Information Security Officer (CISO) is often seen as the ultimate career objective. The pinnacle job after years of paying your dues in what is still a fairly rarefied industry sector.
And it should be, if that’s what you actually want. I can think of no other position outside of the CEO who should have a better grasp on how a business functions than a CISO doing their job well. In fact, while the CEO has the overarching strategy and direction in their remit, it’s the CISO who knows where the information needed to make the right decisions is.
If you accept that data in context is information, information in context is knowledge, and knowledge correctly applied is what makes organisations successful, then; a) Confidentiality of the base data is critical, b) if the data is safe, Integrity can be more reasonably assured and the resulting information is above all things, accurate, and c) the application of the information must be unhindered, suggesting that Availability of the data is the final piece of the puzzle.
You’ve all heard of C.I.A. in security, right? As far as I’m concerned it’s the CISO who is the guardian of it.
In a perfect world.
Unfortunately, far more prevalent is that the Board decides that a CISO is needed from an appearances perspectives – perhaps due to some regulatory pressures – and the person hired has no real authority, no understanding of the overarching corporate strategy, and probably reports into the CTO or someone equally unsuitable.
It’s a shame really, because a good CISO will have unparalleled input into the following:
- The Security Program – From Risk Assessment all the way to Business Continuity Planning the CISO must be aware of every process related to the security life-cycle of the data under their care. Even the CTO won’t have their fingers in this many pies.
o - Asset Management – There is nothing in security that can be performed outside of robust and comprehensive asset management. This will be the CISO’s primary focus until it’s where it needs to be.
o - Mapping of Business Processes – If you don’t know how something works you can neither protect it nor fix it if it breaks. Business processes are the ultimate application of corporate knowledge and the CISO cannot do their job properly until they are all mapped, and preferably optimised.
o - Success Measurement – As Peter Drucker is so often mis-quoted as saying; “You can’t manage what you can’t measure.” In security, unless the CISO can determine which security controls are working and which are not, appropriate security will be impossible. As will staying within budget.
o - Regulatory Compliance – I cannot think of one regulatory compliance regime that does not have data at its core, so who better to report compliance status than the person who knows where it all is, and the controls around it?
o - Change Control – In theory, if nothing can change on the inside without robust oversight, the only increase in risk to data assets will be from the changes to the external threat landscape. Which segues perfectly to;
o - Vulnerability Management – With asset management and business processes as their primary focus, who is better placed to feed into the vulnerability management process to help prioritise ongoing remediation efforts?
o - Business Transformation – In the 2000’s, competitive advantages last weeks, not years. No-one is better placed to help a business transform itself than the person who knows where everything is, and everyONE who manages it.
Prospective CISOs may go into their new job thinking they will get to do all of the above, and the CEO who hires them may think that’s what they’re getting.
Too often neither side asks the right questions, and the CISO role ends up an empty suit.
[If you liked this article, please share! Want more like it, subscribe!]
