Showing posts with label CISO. Show all posts
Showing posts with label CISO. Show all posts

Monday, October 16, 2017

InfoSec Leadership: Initaitive = Enablement

Many CISOs & senior InfoSec leaders catch heat for slowing down processing or saying no to new initiatives due to risk.  

However, when InfoSec leadership takes initiative, embeds SMEs into other teams (at least part time), & partners with the business, then enablement will happen as InfoSec has assisted in the design from a grassroots level.


Now shadow IT will most certainly always be around, & projects / business lines need to be agile, but collaboration is possible via proaction.

Wednesday, September 27, 2017

Equifax: Case Study in Poor Leadership

The former CISO of Equifax has been criticized for her lack of STEM academic background but, forgetting anyone's college major(s), the real issue here is the leadership deficiency blatently running up and down Equifax's management team.

https://www.wired.com/story/equifax-breach-response/

Wired paints a grim picture of Euifax's team, and response, as the article should.  At the end of the day, no one wanted to fall on their sword, and now they all are.  Reminscint of the movie Margin Call, executives want to survive to fight another day, but there are ways to do things in the business world and Equifax did anything but that. 

Monday, October 10, 2016

Data Breach Fatigue & Security Training

Apparently, there is "data breach fatigue" out there and recommendations on cutting down security education, training, & awareness (SETA) is gaining traction.

The question comes with to scale back SETA activities due to this fatigue?

The answer is based on the maturity of the information security (InfoSec) program, jurisdiction / market, industry, and the organization's culture.  Frankly, a CISO / CIO / CTO should negotiate freedoms (e.g., local administrative access, open Internet / Web / email access) pursuant to SETA.  Meaning, that if users have carte blanche then SETA is required, necessary, and regularly conducted.

Also, less SETA should equate to more budget for preventive / detective capabilities.