How do CISOs get executive buy-in for security risks and requirements?
I think the whole agile approach applies in a lot of different ways, not just your product development or your tech development. We use it in strategy development where things come in and out as well. We have to be nimble with shifting priorities. What is most important can change on a weekly basis. We keep up on it. We meet religiously on a weekly basis, and if all the decision makers aren't there for each of those organizations, we don't make a decision to pull something in. But at least if something gets pulled in, something's got to go out. It's agile in that respect. I don't think you can really do much without being agile these days.
One way to avoid that is to use the factor analysis of information risk (FAIR) methodology. Enables you to speak to execs in a way that you can be understood and to empower them.
https://www.amazon.com/Measuring-Managing-Information-Risk-Approach/dp/0124202314/
Content you might like
Talent Retention33%
Talent Attraction48%
Upskilling talent to do more with less12%
Efficient Operations / Better Customer Service Delivery6%
Other – please specify0%
$300 - $400 Million30%
$401 - $500 Million45%
$501-$600 Million6%
$600 Million +7%
Unsure11%