The role of the Chief Information Security Officer (CISO) is becoming more strategic in nature. Some key drivers for this include fraud, hacking, insider theft, lack of monitoring and controls, and the rapid adoption of new technologies. The CISO's role has evolved over the last 12 years from a more technical, project-managing role to one that involves marketing security, quantifying benefits, and representing security at the senior management level. While CISOs still face roadblocks, there are tips they can use to enhance their value and reach within an organization, such as branding security, gaining CEO involvement, conducting security awareness activities, and collaborating with external agencies and other CISOs.
1 of 17
Downloaded 34 times
More Related Content
Pradeep menon how to influence people and win top management buy0in for ciso
1. SThe New CIO^SECURITYThe 3rd Kuwait InfoSecurityConferenceMay 26, 2011Pradeep MenonExecutive Vice President and DirectorQuadrant Risk Management>
3. The CISO The role of the Chief Information Security Officer (CISO) is becoming very strategic in nature
4. Some of the Key Drivers for this Strategic Visibility include:SCIO^3
5. Why should organizations have a CISO? FraudInsider TheftLack of single source of truthThird party exposure?SRate of Adoption of New TechnologiesCIOHacking^Evolving TechnologiesLack of monitoring and controls4
6. Evolution of the role for Information SecuritySince last 2-3 years5-8 years ago9-12 years agoSource: Forrester Research5
7. New ResponsibilitiesThe emerging role of the CISO and information security office calls for new skills and responsibilities to be undertaken including:
30. Tips for Enhancing CISO Value and ReachBranding SecurityForm Information Security sub committees in organization such as KITS (if not already in place)
33. ADSIC Information Security ProgramCEO InvolvementBusiness InvolvementSecurity Awareness DayExternal Agencies13
34. Tips for Enhancing CISO Value and ReachBranding SecurityPublishing annual reports on IS activities and developments for the year
35. Creating a web portal for users to view various reports on the metrics based on which their contribution to IS initiatives are rated CEO InvolvementBusiness InvolvementSecurity Awareness DayExternal AgenciesAnnual ISMS Reporting14
36. Tips for Enhancing CISO Value and ReachBranding SecurityExternal consultancies are SMEs
40. Look upon consultancies as partners or change agents, not as vendors or spendersCEO InvolvementBusiness InvolvementSecurity Awareness DayExternal AgenciesAnnual ISMS ReportingExternal Consultancies15
41. Tips for Enhancing CISO Value and ReachBranding SecurityInviting CISOs from other companies helps in knowledge exchange and gains on both sides
42. Forums such as LinkedIn and Facebook have been instrumental in generating Networking
43. Involvement in joint research initiatives through organizations such as CAIT (The Central Agency for Information technology) , KITS (Kuwait Information Technology Society), aeCERT, OCERT etc.CEO InvolvementBusiness InvolvementSecurity Awareness DayExternal AgenciesAnnual ISMS ReportingExternal ConsultantsOther CISO Involvement16
44. Tips for Enhancing CISO Value and ReachBranding SecurityIncentives for your IS team members to contribute and attend various eventssuch as conferences, trainings, seminars etc.
45. Encourage publishing of white papers on popular websites and journals, on behalf of the organizationCEO InvolvementBusiness InvolvementSecurity Awareness DayExternal AgenciesAnnual ISMS ReportingExternal ConsultantsOther CISO InvolvementExternal Involvement17
46. Thank YouPradeep MenonExecutive Vice President and DirectorQuadrant Risk Managementpradeep.menon@qrmi-me.comTel: +971-4-6091970Mob: +971-50-4815260