0% found this document useful (0 votes)
4 views1 page

Selecting an Effective CISO for Cybersecurity

Organizations seek to protect information assets and minimize cyber attack risk by appointing a CISO and ensuring executives are informed of security status. The organization must be clear on the CISO's job and required attributes, as the CISO should communicate effectively with the board as a senior executive rather than technical expert. Suggestions aid effectiveness and efficiency, but organizations must consider cyber security in selecting board members.

Uploaded by

J lodhi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views1 page

Selecting an Effective CISO for Cybersecurity

Organizations seek to protect information assets and minimize cyber attack risk by appointing a CISO and ensuring executives are informed of security status. The organization must be clear on the CISO's job and required attributes, as the CISO should communicate effectively with the board as a senior executive rather than technical expert. Suggestions aid effectiveness and efficiency, but organizations must consider cyber security in selecting board members.

Uploaded by

J lodhi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

SUMMARY

Against a background of board-level concern for cyber security, organizations are seeking to ensure
the protection of their information assets and minimize the risk of a cyber security attack. These
objectives place two particular demands on organizations: to appoint a suitable official to head up
their information security operations, a CISO; and to ensure that the executive and board are
appropriately informed of the organization's security status. In exploring the challenges that confront
organizations in selecting a CISO, we drew on data from the U.S., Canada, and New Zealand. Two
main issues were addressed. First, the organization has to be very clear on what it wants in terms of
the job the CISO is expected to perform and the corresponding attributes that such an incumbent
would need to possess. The CISO is a senior-level executive and rather than being a specialized
technical expert, the CISO should be an excellent communicator. This will help address the second
issue, which is how effectively the CISO can communicate with the board. Some suggestions are
provided that serve to aid both effectiveness and efficiency. However, organizations need to
embrace their concern about cyber security and build it into their selection criteria for board
members.

You might also like