At what point does it make sense for the security lead to be directly reporting to the CEO and not a CIO/CTO?
CSO reporting directly to the CEO, allows the CSO to have a higher degree of influence in driving change. However, depending on the organization, the CSO may not have as much time with the CEO due to their range of responsibilities.
Ive seen the most success when the CSO is working directly with the CEO, it helps remove friction, barriers and align with the strategy of the business.
You bring up an interesting point about risk. Not all IT risk is related to security. Where do you feel IT Governance, Risk and Compliance needs to sit? I have seen this under security, i have seen it inside IT and I have seen it completely outside under an Enterprise Risk Management function. What works best in your opinion, and why?
I feel that security is everyone’s responsibility and it is unfair to say that the CISO is the single throat to choke. Ultimately, if the CISO is not able to articulate the threats and risks, and not able to get everyone to get to a level of shared understanding and shared accountability, then yes, that is a bad CISO. How does one make security an organization on its own yet still make it such that it’s everyone’s responsibility? Any thoughts there?
Content you might like
Yes - one person41%
Yes - multiple people46%
No12%
Team lead19%
Project lead58%
Domain lead8%
Architect15%
organized a virtual escape room via https://www.puzzlebreak.us/ - even though his team lost it was a fun subtitue for just a "virtual happy hour"
In the last few companies I've worked for, there wasn't a whole lot of debate about how things should roll up. It's like, hey you got this? Make this happen! But I think the best approach is to always be looking at what is right for the company at that given time.
Security is important to me. But I understand it only works if IT ops and security ops are willing to work together. Its all about people. A lot of times, everyone wants to spend a lot of time defining roles and responsibilities. Roles and responsibilities are important to understand but it all comes down to people and people behaving in the right way and understanding that there's actually value in us all working together to solve this problem.