Are there best practices or staffing models available to assist with setting up a team specific to the management, tracking, compliance and reporting of identified risks and issues.  Ie What's the right ratio of people to identified issues to properly manage those items to completion?

1.1k viewscircle icon2 Comments
Sort by:
CIO in IT Services2 years ago

Typically, I'll use a 10-15% ratio against revenue for staffing needs (overall team size). Depending on the size of the company, the number of staff will adjust from this starting point. The CISO also needs to consider the organization's cyber maturity score, the tools that have been implemented, their compliance needs and their incident response rates. There is no hard fast rule here - it's a combination of people-process-technology that lends itself to obtaining the right answer on how to staff.

Chief Information Security Officer in Healthcare and Biotech2 years ago

ratio of people to identified issues, depending on the size and complexity of the business, nature industry, and the level of risk appetite. Organizations should try to achieve a balance between resource requirements to attend the identified problems timely with efficiency and cost-effectiveness.

Content you might like

Yes, we use Avast.11%

Yes, we use Norton.35%

Yes, we use both Norton and Avast.4%

We don't use either product.48%

View Results

The stages of an engagement21%

The hassle of writing a report50%

The value of the human expert53%

The need to get business buy-in27%

All of the above18%

None of the above

View Results