Structuring the Chief Information Security Officer Organization

Autor: Allen, Julia H, Crabb, Gregory, Curtis, Pamela D, Fitzpatrick, Brendan, Mehravari, Nader, Tober, David
Rok vydání: 2015
Předmět:
DOI: 10.1184/r1/6584423
Popis: Chief Information Security Officers (CISOs) are increasingly finding that the tried-and-true, traditional information security strategies and functions are no longer adequate when dealing with today’s increasingly expanding and dynamic cyber risk environment. Many opinions and publications express a wide range of functions that a CISO organization should be responsible for governing, managing, and performing. How does a CISO make sense of these functions and select the ones that are most applicable for their business mission, vision, and objectives?This report describes how the authors defined a CISO team structure and functions for a large, diverse U.S. national organization using input from CISOs, policies, frameworks, maturity models, standards, codes of practice, and lessons learned from major cybersecurity incidents.
Databáze: OpenAIRE